Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

\Desktop\setup_ais.exe: Trojan.Generic.Bredolab-2 FOUND [РЕШЕН]

Featured Replies

Здравейте,след като установих странно поведение на моя компютър,сканирах с Аваст антивирус и нищо не се установи.сканирах после с ClamWin и тя намери този троянец.Как да се отърва от него?А ето и малко симптоми на заразата-картината на десктопа изчезна и сега е син екран,когато отворя браузерите ми се отварят безброй прозорци,иконата на кошчето отговаря на друга програма и мога да я стартирам от кошчето и оригиналната икона,когато искам да изтрия нещо то не отива в коша а по настроики първо отива там и след това го трия,някои файлове не мога да ги изтрия дори с Unlocker програми.Ето и лога от DDS . DDS (Ver_2011-08-26.01) - NTFSx86 NETWORK Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_24 Run by User1 at 10:50:48 on 2011-12-18 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.1791.1406 [GMT 2:00] . . ============== Running Processes =============== . C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\system32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe . ============== Pseudo HJT Report =============== . uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uDefault_Search_URL = hxxp://www.google.com/ie uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7PRFA_en uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mWinlogon: Userinit=c:\windows\system32\userinit.exe BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [sunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [tsnpstd3] c:\windows\tsnpstd3.exe mRun: [snpstd3] c:\windows\vsnpstd3.exe mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [bDAgent] "c:\program files\bitdefender\bitdefender 2009\bdagent.exe" dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000 IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab TCP: DhcpNameServer = 46.40.72.9 192.168.0.1 TCP: Interfaces\{0227FD86-8C54-4C88-8029-3F44137A8ADF} : DhcpNameServer = 46.40.72.9 192.168.0.1 Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll LSA: Notification Packages = scecli scecli scecli . ============= SERVICES / DRIVERS =============== . S3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [2009-4-15 146312] S3 PROCEXP150;PROCEXP150;\??\c:\windows\system32\drivers\procexp150.sys --> c:\windows\system32\drivers\PROCEXP150.SYS [?] S3 SysProtDrv.sys;SysProtDrv.sys;c:\documents and settings\user2\desktop\sysprot\SysProtDrv.sys [2011-11-11 44288] . =============== Created Last 30 ================ . 2011-12-16 12:09:28 81984 ----a-w- c:\windows\system32\bdod.bin 2011-12-16 11:58:24 -------- d-----w- c:\documents and settings\user1\application data\BitDefender 2011-12-16 11:58:15 -------- d-----w- c:\program files\BitDefender 2011-12-16 11:58:15 -------- d-----w- c:\documents and settings\all users\application data\BitDefender 2011-12-16 11:57:48 -------- d-----w- c:\program files\common files\BitDefender 2011-12-16 11:32:40 -------- d-----w- c:\documents and settings\user1\application data\QuickScan 2011-12-15 14:16:45 -------- d--h--w- c:\windows\PIF 2011-12-15 08:28:39 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys 2011-12-15 08:22:22 -------- d-----w- c:\program files\Lavasoft 2011-12-15 08:21:38 388096 ----a-r- c:\documents and settings\user1\application data\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe 2011-12-15 08:21:38 -------- d-----w- c:\program files\Trend Micro 2011-12-15 08:18:57 -------- d-----w- C:\HJT 2011-12-09 08:50:22 -------- d-----w- c:\windows\SxsCaPendDel 2011-12-06 08:57:39 111872 ----a-w- c:\windows\system32\drivers\TrueSight.sys 2011-11-29 10:36:37 -------- d-----w- c:\windows\system32\CatRoot2 2011-11-27 08:48:48 -------- d-----w- c:\program files\ESET 2011-11-26 11:22:15 -------- d-----w- c:\documents and settings\user1\application data\Malwarebytes 2011-11-26 11:22:07 -------- d-----w- C:\Malwarebytes' Anti-Malware . ==================== Find3M ==================== . 2011-12-16 12:09:17 146312 ----a-w- c:\windows\system32\drivers\bdfm.sys 2011-12-15 14:55:04 26112 ----a-w- c:\windows\system32\userinit.exe . ============= FINISH: 10:51:00,03 =============== и другия . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 5/2/2011 10:16:36 AM System Uptime: 12/18/2011 10:02:39 AM (0 hours ago) . Motherboard: | | ALiveNF6P-VSTA Processor: AMD Athlon 64 X2 Dual Core Processor 4200+ | CPUSocket | 2209/200mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 20 GiB total, 13.022 GiB free. D: is FIXED (NTFS) - 577 GiB total, 442.002 GiB free. E: is CDROM () F: is Removable . ==== Disabled Device Manager Items ============= . Class GUID: {4D36E96F-E325-11CE-BFC1-08002BE10318} Description: Microsoft PS/2 Mouse Device ID: ACPI\PNP0F03\4&38D79619&0 Manufacturer: Microsoft Name: Microsoft PS/2 Mouse PNP Device ID: ACPI\PNP0F03\4&38D79619&0 Service: i8042prt . ==== System Restore Points =================== . No restore point in system. . ==== Installed Programs ====================== . µTorrent 32 Bit HP CIO Components Installer 470_Help 470_Readme 7-Zip 9.20 Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader X (10.0.1) BitDefender Free Edition 2009 BPD_HPSU BPDSoftware BPDSoftware_Ini BufferChm Bulgarian (Phonetic) - REAL CCleaner CustomerResearchQFolder Defraggler DeviceDiscovery DeviceManagementQFolder ESET Online Scanner v3 eSupportQFolder Google Chrome Google Toolbar for Internet Explorer Google Update Helper H470 HiJackThis HP Customer Participation Program 9.0 HP Imaging Device Functions 9.0 HP Officejet H470 Series HP Solution Center 9.0 HPProductAssistant Java Auto Updater Java 6 Update 24 K-Lite Codec Pack 7.0.0 (Full) Malwarebytes' Anti-Malware version 1.51.2.1300 MarketResearch Microsoft .NET Framework 2.0 Client Service Pack 2 Microsoft .NET Framework 3.0 Client Service Pack 2 Microsoft .NET Framework 3.5 Client Service Pack 1 Microsoft .NET Framework Client Profile Microsoft Application Error Reporting Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office Professional Edition 2003 Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 MPM NVIDIA Drivers Opera 11.10 ProductContext Realtek High Definition Audio Driver Recuva SA Dictionary 2010 Beta 1 Skype Toolbars Skype™ 5.3 SolutionCenter StarCam Clip Status Toolbox Total Commander (Remove or Repair) TrayApp WebFldrs XP WebReg Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0) Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray Windows Internet Explorer 7 Windows Media Format 11 runtime Windows Media Player 11 WinRAR 4.00 (32-битова версия) . ==== Event Viewer Messages From Past Week ======== . 12/18/2011 10:04:39 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AmdK8 Fips 12/16/2011 9:24:29 AM, error: Service Control Manager [7023] - The avast! Antivirus service terminated with the following error: The specified procedure could not be found. 12/16/2011 12:29:51 PM, error: Service Control Manager [7034] - The Lavasoft Ad-Aware Service service terminated unexpectedly. It has done this 1 time(s). 12/16/2011 12:29:51 PM, error: Service Control Manager [7031] - The SAS Core Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service. 12/16/2011 1:46:14 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046} 12/16/2011 1:44:55 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AmdK8 Fips SASDIFSV SASKUTIL 12/15/2011 5:53:30 PM, error: Service Control Manager [7023] - The System Restore Service service terminated with the following error: The system cannot find the file specified. 12/15/2011 5:53:28 PM, error: SRService [104] - The System Restore initialization process failed. 12/15/2011 5:52:28 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 AmdK8 aswSnx aswSP aswTdi Fips SASDIFSV SASKUTIL 12/15/2011 5:51:40 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 12/15/2011 5:45:46 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} 12/15/2011 5:26:56 PM, error: atapi [9] - The device, \Device\Ide\IdePort5, did not respond within the timeout period. . ==== End Of File ===========================

Здравейте..!:)

Публикувано изображение Изтеглете ComboFix Публикувано изображение от тук или тук и го запазете на десктопа си.

  • Изключете вашата антивирусна и антишпионска програма, обикновено това става чрез натискане на десния бутон на мишката върху иконата на програма в системния трей.
Бележка: Ако не можете я спрете или не сте сигурни коя програма да изключите, моля прегледайте информацията от този линк: How to Disable your Security Programs
  • Стартирайте Combo-Fix.com Публикувано изображение и следвайте инструкциите.
Бележка: ComboFix ще се стартира без инсталирана Recovery Console.
  • Като част от неговата работа, ComboFix ще провери дали Microsoft Windows Recovery Console е инсталирана. Предвид бързо развиващия се зловреден софтуер е силно препоръчително да бъде инсталирана преди премахването на зловредния софтуер. Това ще Ви позволи да влезете в специален recovery/repair режим, който ще ни позволи по-лесно да решите проблем, който би могъл да възникне при премахване на зловредния софтуер.
  • Следвайте инструкциите, за да позволите на ComboFix да изтегли и инсталира Microsoft Windows Recovery Console. В един момент ще бъдете попитани дали сте съгласни с лицензното споразумение. Необходимо е да потвърдите, че сте съгласни, за да инсталирате Microsoft Windows Recovery Console.
** Забележете: Ако Microsoft Windows Recovery Console е вече инсталирана, ComboFix ще продължи към процеса по премахване на зловредния софтуер.

Публикувано изображение

След като Microsoft Windows Recovery Console е инсталирана, използвайки ComboFix, Вие ще видите следното съобщение:

Публикувано изображение

Изберете Yes, за да продължи сканирането за зловреден софтуер.

Когато процесът приключи успешно, инструментът ще създаде лог файл. Моля, включете съдържанието на C:\ComboFix.txt в следващия Ви коментар в тази тема.

Бележка:

  • Моля, не движете мишката, докато ComboFix работи. Това може да наруши процеса на работа.
  • ComboFix ще нулира всички настройки на Microsoft Internet Explorer, включително да направи IE браузър по подразбиране.
  • ComboFix ще изключи autorun функцията на ВСИЧКИ CD, Floppy и USB устройства, за да помогне при премахването на зловредния софтуер и Ви защити от бъдещи вируси/заплахи, които поразяват чрез autorun. Ако това е проблем за вас - моля, уведомете ме.
  • ComboFix ще изключи вашата интернет връзка. Интернет връзката ще се възстанови автоматично, преди ComboFix да завърши процеса на работа. При проблем, той ще прекрати интернет връзката. За да възстановите интернет връзката си, рестартирайте компютъра си.
  • В случай на проблем с ComboFix, той може да създаде лог файл. Моля, включете съдържанието на C:\BUG.txt в следващия Ви коментар в тази тема.
Публикувано изображение Моля, не прикачвайте лог файла/овете от програмата, а го/ги копирайте и поставете в следващия Ви коментар в тази тема.
  • Автор

Здравейте..! :)

Публикувано изображение Изтеглете ComboFix Публикувано изображение от тук или тук и го запазете на десктопа си.

  • Изключете вашата антивирусна и антишпионска програма, обикновено това става чрез натискане на десния бутон на мишката върху иконата на програма в системния трей.
Бележка: Ако не можете я спрете или не сте сигурни коя програма да изключите, моля прегледайте информацията от този линк: How to Disable your Security Programs
  • Стартирайте Combo-Fix.com Публикувано изображение и следвайте инструкциите.
Бележка: ComboFix ще се стартира без инсталирана Recovery Console.
  • Като част от неговата работа, ComboFix ще провери дали Microsoft Windows Recovery Console е инсталирана. Предвид бързо развиващия се зловреден софтуер е силно препоръчително да бъде инсталирана преди премахването на зловредния софтуер. Това ще Ви позволи да влезете в специален recovery/repair режим, който ще ни позволи по-лесно да решите проблем, който би могъл да възникне при премахване на зловредния софтуер.
  • Следвайте инструкциите, за да позволите на ComboFix да изтегли и инсталира Microsoft Windows Recovery Console. В един момент ще бъдете попитани дали сте съгласни с лицензното споразумение. Необходимо е да потвърдите, че сте съгласни, за да инсталирате Microsoft Windows Recovery Console.
** Забележете: Ако Microsoft Windows Recovery Console е вече инсталирана, ComboFix ще продължи към процеса по премахване на зловредния софтуер.

Публикувано изображение

След като Microsoft Windows Recovery Console е инсталирана, използвайки ComboFix, Вие ще видите следното съобщение:

Публикувано изображение

Изберете Yes, за да продължи сканирането за зловреден софтуер.

Когато процесът приключи успешно, инструментът ще създаде лог файл. Моля, включете съдържанието на C:\ComboFix.txt в следващия Ви коментар в тази тема.

Бележка:

  • Моля, не движете мишката, докато ComboFix работи. Това може да наруши процеса на работа.
  • ComboFix ще нулира всички настройки на Microsoft Internet Explorer, включително да направи IE браузър по подразбиране.
  • ComboFix ще изключи autorun функцията на ВСИЧКИ CD, Floppy и USB устройства, за да помогне при премахването на зловредния софтуер и Ви защити от бъдещи вируси/заплахи, които поразяват чрез autorun. Ако това е проблем за вас - моля, уведомете ме.
  • ComboFix ще изключи вашата интернет връзка. Интернет връзката ще се възстанови автоматично, преди ComboFix да завърши процеса на работа. При проблем, той ще прекрати интернет връзката. За да възстановите интернет връзката си, рестартирайте компютъра си.
  • В случай на проблем с ComboFix, той може да създаде лог файл. Моля, включете съдържанието на C:\BUG.txt в следващия Ви коментар в тази тема.
Публикувано изображение Моля, не прикачвайте лог файла/овете от програмата, а го/ги копирайте и поставете в следващия Ви коментар в тази тема.

ето го лога от ComboFix

ComboFix 11-12-17.05 - User1 12.2011 г. 12:06:35.1.2 - x86

Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.1791.1165 [GMT 2:00]

Running from: c:\documents and settings\User1\Desktop\ComboFix.exe

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\windows\pkunzip.pif

c:\windows\pkzip.pif

.

.

((((((((((((((((((((((((( Files Created from 2011-11-18 to 2011-12-18 )))))))))))))))))))))))))))))))

.

.

2011-12-16 12:09 . 2011-12-18 10:11 81984 ----a-w- c:\windows\system32\bdod.bin

2011-12-16 11:58 . 2011-12-16 11:58 -------- d-----w- c:\documents and settings\User1\Application Data\BitDefender

2011-12-16 11:58 . 2011-12-16 12:00 -------- d-----w- c:\documents and settings\All Users\Application Data\BitDefender

2011-12-16 11:58 . 2011-12-16 11:58 -------- d-----w- c:\program files\BitDefender

2011-12-16 11:57 . 2011-12-16 11:58 -------- d-----w- c:\program files\Common Files\BitDefender

2011-12-16 11:32 . 2011-12-16 11:32 -------- d-----w- c:\documents and settings\User1\Application Data\QuickScan

2011-12-15 14:16 . 2011-12-15 14:16 -------- d--h--w- c:\windows\PIF

2011-12-15 08:28 . 2011-12-15 08:28 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys

2011-12-15 08:22 . 2011-12-15 08:22 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\Sunbelt Software

2011-12-15 08:22 . 2011-12-15 08:22 -------- d-----w- c:\program files\Lavasoft

2011-12-15 08:22 . 2011-12-15 08:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft

2011-12-15 08:21 . 2011-12-15 08:21 388096 ----a-r- c:\documents and settings\User1\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2011-12-15 08:21 . 2011-12-15 08:21 -------- d-----w- c:\program files\Trend Micro

2011-12-15 08:18 . 2011-12-15 08:21 -------- d-----w- C:\HJT

2011-12-09 14:12 . 2011-12-16 11:49 -------- d-----w- c:\documents and settings\User1\Application Data\Media Player Classic

2011-12-09 08:50 . 2011-12-09 09:00 -------- d-----w- c:\windows\SxsCaPendDel

2011-12-06 08:57 . 2011-12-15 16:08 111872 ----a-w- c:\windows\system32\drivers\TrueSight.sys

2011-11-29 10:36 . 2011-12-18 10:05 -------- d-----w- c:\windows\system32\CatRoot2

2011-11-27 08:48 . 2011-11-27 08:48 -------- d-----w- c:\program files\ESET

2011-11-26 11:22 . 2011-11-26 11:22 -------- d-----w- c:\documents and settings\User1\Application Data\Malwarebytes

2011-11-26 11:22 . 2011-12-16 10:56 -------- d-----w- C:\Malwarebytes' Anti-Malware

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-12-16 12:09 . 2009-04-15 13:13 146312 ----a-w- c:\windows\system32\drivers\bdfm.sys

2011-12-15 14:55 . 2008-04-14 02:42 26112 ----a-w- c:\windows\system32\userinit.exe

.

.

------- Sigcheck -------

Note: Unsigned files aren't necessarily malware.

.

[-] 2008-04-23 . 0484B919829B94B6EEC50D0AC607751A . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-16 7630848]

"nwiz"="nwiz.exe" [2006-08-16 1617920]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-16 86016]

"RTHDCPL"="RTHDCPL.EXE" [2006-08-14 16050176]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]

"tsnpstd3"="c:\windows\tsnpstd3.exe" [2006-06-19 262144]

"snpstd3"="c:\windows\vsnpstd3.exe" [2006-05-12 831488]

"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]

"BDAgent"="c:\program files\BitDefender\BitDefender 2009\bdagent.exe" [2011-12-16 782336]

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

.

c:\documents and settings\All Users\Start Menu\Programs\Startup\

HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]

2005-05-03 15:43 69632 ----a-w- c:\windows\Alcmtr.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]

2008-04-14 02:42 15360 ----a-w- c:\windows\system32\ctfmon.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]

2011-05-02 09:46 395640 ----a-w- c:\program files\uTorrent\uTorrent.exe

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\Opera\\opera.exe"=

"c:\\Program Files\\uTorrent\\uTorrent.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

"f:\\skype_portable\\13\\skype\\skype.exe"=

.

R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [4/15/2009 3:13 PM 146312]

S3 PROCEXP150;PROCEXP150;\??\c:\windows\system32\Drivers\PROCEXP150.SYS --> c:\windows\system32\Drivers\PROCEXP150.SYS [?]

S3 SysProtDrv.sys;SysProtDrv.sys;c:\documents and settings\User2\Desktop\SysProt\SysProtDrv.sys [11/11/2011 2:21 PM 44288]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

bdx REG_MULTI_SZ scan

.

Contents of the 'Scheduled Tasks' folder

.

2011-12-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2011-05-02 09:41]

.

2011-12-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2011-05-02 09:41]

.

.

------- Supplementary Scan -------

.

uDefault_Search_URL = hxxp://www.google.com/ie

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7PRFA_en

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000

IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html

TCP: DhcpNameServer = 46.40.72.9 192.168.0.1

.

- - - - ORPHANS REMOVED - - - -

.

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)

MSConfigStartUp-msnmsgr - c:\program files\Windows Live\Messenger\msnmsgr.exe

.

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2011-12-18 12:12

Windows 5.1.2600 Service Pack 3 NTFS

.

scanning hidden processes ...

.

scanning hidden autostart entries ...

.

scanning hidden files ...

.

scan completed successfully

hidden files: 0

.

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_USERS\S-1-5-21-220523388-412668190-1417001333-1003\Software\Microsoft\SystemCertificates\AddressBook*]

@Allowed: (Read) (RestrictedCode)

@Allowed: (Read) (RestrictedCode)

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\Shell\B20@O=5 *=0 *C*C*l*e*a*n*e*r*& \command]

@="c:\\Program Files\\CCleaner\\ccleaner.exe"

.

--------------------- DLLs Loaded Under Running Processes ---------------------

.

- - - - - - - > 'explorer.exe'(2284)

c:\windows\system32\ieframe.dll

c:\windows\system32\WPDShServiceObj.dll

c:\windows\system32\PortableDeviceTypes.dll

c:\windows\system32\PortableDeviceApi.dll

c:\windows\system32\OneX.DLL

c:\windows\system32\eappprxy.dll

.

------------------------ Other Running Processes ------------------------

.

c:\program files\Java\jre6\bin\jqs.exe

c:\windows\system32\nvsvc32.exe

c:\windows\system32\wscntfy.exe

c:\windows\RTHDCPL.EXE

c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe

.

**************************************************************************

.

Completion time: 2011-12-18 12:14:53 - machine was rebooted

ComboFix-quarantined-files.txt 2011-12-18 10:14

.

Pre-Run: 13 862 842 368 bytes free

Post-Run: 13 755 486 208 bytes free

.

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

UnsupportedDebug="do not select this" /debug

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer

.

- - End Of File - - 06FBB90A1B52B9B30F940B5180F3B96B

Копирайте текста в карето на notepad и го запазвате с име CFScript.txt на десктопа си:

KILLALL::

ClearJavaCache::

File::
c:\windows\system32\bdod.bin

FileLook::
c:\windows\system32\Drivers\PROCEXP150.SYS
c:\documents and settings\User2\Desktop\SysProt\SysProtDrv.sys

DirLook::
c:\windows\SxsCaPendDel

След съхранението преместете CFScript.txt на иконата на ComboFix.exe

Публикувано изображение

Генерирания рапорт прикачете в следващия си пост..!

  • Автор

ComboFix 11-12-17.05 - User1 12.2011 г. 13:04:39.3.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.1791.1222 [GMT 2:00] Running from: c:\documents and settings\User1\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\User1\Desktop\CFScript.txt.txt . FILE :: "c:\windows\system32\bdod.bin" . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\system32\bdod.bin . . ((((((((((((((((((((((((( Files Created from 2011-11-18 to 2011-12-18 ))))))))))))))))))))))))))))))) . . 2011-12-16 11:58 . 2011-12-16 12:00 -------- d-----w- c:\documents and settings\All Users\Application Data\BitDefender 2011-12-16 11:58 . 2011-12-16 11:58 -------- d-----w- c:\program files\BitDefender 2011-12-16 11:57 . 2011-12-16 11:58 -------- d-----w- c:\program files\Common Files\BitDefender 2011-12-16 11:32 . 2011-12-16 11:32 -------- d-----w- c:\documents and settings\User1\Application Data\QuickScan 2011-12-15 14:16 . 2011-12-15 14:16 -------- d--h--w- c:\windows\PIF 2011-12-15 08:28 . 2011-12-15 08:28 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys 2011-12-15 08:22 . 2011-12-15 08:22 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\Sunbelt Software 2011-12-15 08:22 . 2011-12-15 08:22 -------- d-----w- c:\program files\Lavasoft 2011-12-15 08:22 . 2011-12-15 08:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft 2011-12-15 08:21 . 2011-12-15 08:21 388096 ----a-r- c:\documents and settings\User1\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-12-15 08:21 . 2011-12-15 08:21 -------- d-----w- c:\program files\Trend Micro 2011-12-15 08:18 . 2011-12-15 08:21 -------- d-----w- C:\HJT 2011-12-09 14:12 . 2011-12-16 11:49 -------- d-----w- c:\documents and settings\User1\Application Data\Media Player Classic 2011-12-09 08:50 . 2011-12-09 09:00 -------- d-----w- c:\windows\SxsCaPendDel 2011-12-06 08:57 . 2011-12-15 16:08 111872 ----a-w- c:\windows\system32\drivers\TrueSight.sys 2011-11-29 10:36 . 2011-12-18 11:04 -------- d-----w- c:\windows\system32\CatRoot2 2011-11-27 08:48 . 2011-11-27 08:48 -------- d-----w- c:\program files\ESET 2011-11-26 11:22 . 2011-11-26 11:22 -------- d-----w- c:\documents and settings\User1\Application Data\Malwarebytes 2011-11-26 11:22 . 2011-12-16 10:56 -------- d-----w- C:\Malwarebytes' Anti-Malware . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-12-15 14:55 . 2008-04-14 02:42 26112 ----a-w- c:\windows\system32\userinit.exe . . (((((((((((((((((((((((((((((((((((((((((((( Look ))))))))))))))))))))))))))))))))))))))))))))))))))))))))) . . --- c:\documents and settings\User2\Desktop\SysProt\SysProtDrv.sys --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File size: 44288 Created time: 2011-11-11 12:21 Modified time: 2011-11-11 12:21 MD5: 7D5B6655442DBCF5E3B86A134AB90584 SHA1: 7F8C56C9337B389777CF1B9AC5F1431C7D0567AF . ---- Directory of c:\windows\SxsCaPendDel ---- . . . ------- Sigcheck ------- Note: Unsigned files aren't necessarily malware. . [-] 2008-04-23 . 0484B919829B94B6EEC50D0AC607751A . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll . ((((((((((((((((((((((((((((( SnapShot@2011-12-18_10.13.03 ))))))))))))))))))))))))))))))))))))))))) . + 2011-12-18 11:07 . 2011-12-18 11:07 16384 c:\windows\temp\Perflib_Perfdata_6dc.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-16 7630848] "nwiz"="nwiz.exe" [2006-08-16 1617920] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-16 86016] "RTHDCPL"="RTHDCPL.EXE" [2006-08-14 16050176] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064] "tsnpstd3"="c:\windows\tsnpstd3.exe" [2006-06-19 262144] "snpstd3"="c:\windows\vsnpstd3.exe" [2006-05-12 831488] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] . c:\documents and settings\All Users\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520] . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr] 2005-05-03 15:43 69632 ----a-w- c:\windows\Alcmtr.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE] 2008-04-14 02:42 15360 ----a-w- c:\windows\system32\ctfmon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent] 2011-05-02 09:46 395640 ----a-w- c:\program files\uTorrent\uTorrent.exe . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Opera\\opera.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= "f:\\skype_portable\\13\\skype\\skype.exe"= . S3 PROCEXP150;PROCEXP150;\??\c:\windows\system32\Drivers\PROCEXP150.SYS --> c:\windows\system32\Drivers\PROCEXP150.SYS [?] S3 SysProtDrv.sys;SysProtDrv.sys;c:\documents and settings\User2\Desktop\SysProt\SysProtDrv.sys [11/11/2011 2:21 PM 44288] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder . 2011-12-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-05-02 09:41] . 2011-12-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-05-02 09:41] . . ------- Supplementary Scan ------- . uDefault_Search_URL = hxxp://www.google.com/ie uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7PRFA_en uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html TCP: DhcpNameServer = 46.40.72.9 192.168.0.1 . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-12-18 13:07 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_USERS\S-1-5-21-220523388-412668190-1417001333-1003\Software\Microsoft\SystemCertificates\AddressBook*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\Shell\B20@O=5 *=0 *C*C*l*e*a*n*e*r*& \command] @="c:\\Program Files\\CCleaner\\ccleaner.exe" . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'explorer.exe'(2380) c:\windows\system32\ieframe.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll c:\windows\system32\OneX.DLL c:\windows\system32\eappprxy.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Java\jre6\bin\jqs.exe c:\windows\system32\nvsvc32.exe c:\windows\system32\wscntfy.exe c:\windows\RTHDCPL.EXE c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe . ************************************************************************** . Completion time: 2011-12-18 13:08:31 - machine was rebooted ComboFix-quarantined-files.txt 2011-12-18 11:08 ComboFix2.txt 2011-12-18 10:30 ComboFix3.txt 2011-12-18 10:14 . Pre-Run: 14 374 449 152 bytes free Post-Run: 14 362 357 760 bytes free . - - End Of File - - 4F779794B466DE75128961EB9220A318

Хм..не ми харесват нещата..!Да направим още сканирания:

Публикувано изображение Моля, изтеглете последната версия на TDSSKiller - оттук и я запазете на вашия декстоп.

  • Стартирайте TDSSKiller.exe за да стартирате приложението. След това кликнете върху бутона Change parameters.

    Публикувано изображение

  • Сложете отметки пред Verify Driver Digital Signature и Detect TDLFS file system и натиснете ОК.

    Публикувано изображение

  • Натиснете бутона Start Scan.

    Публикувано изображение

  • Ако подозрителен обект бъде засечен, действието по подразбиране ще бъде Skip, кликнете върху Continue.

    Публикувано изображение

  • Ако зловредни обекти бъдат намерени, тогава от падащото меню ще имате три възможности.

    Бъдете сигурни, че избраното действие е Cure и натиснете върху Continue > Рестартирайте за да бъде завършена поправката.

    Публикувано изображение

    Забележка: Ако Cure бутона не е наличен от възможностите, тогава моля изберете Skip бутона, не избирайте Delete освен ако не сте инструктирани затова.

  • Лог файл ще бъде създаден в свободната директория на дял C:\ . Потърсете за лог с името "TDSSKiller.[Version]_[Date]_[Time]_log.txt" и копирайте съдържанието му в следващия си пост.
Публикувано изображение Изтеглете Gmer или от тук.

* Временно спрете Интернета си,всички работещи програми,както и антивирусната си програма.

* Стартирате програмата.

* След завършването на автомаичната експрес-проверка,махнете отметките от следните позиции:

- IAT/EAT

- Show all

* От всички локални дискове маркирайте само системния дял (обикновенно това е C:\ )

Публикувано изображение

* Изчакайте програмата да завърши сканирането,след което натиснете бутона Save и запишете (save as) резултатите на десктопа с име Gmer.log.

* Включете Интернета си и прикачете Gmer.log в следващия си коментар.

Забележка:

* Ако бъде открит Rootkit, ще последва въпрос дали желаете пълно сканиране на системата. Изберете NO.

* Не предприемайте никакви действия върху редовете маркирани с "<--- ROOТKIT" ,защото това може да доведе до грешки.

* В десния панел на програмата ще видите какво е ще се провери от програмата, не променяйте нищо. Убедете се, че на Show All няма отметка.

Внимание:

Ако имате проблем с използването на GMER по по-горе описания начин,моля изпълнете сканирането,като маркирате следните позиции:

Публикувано изображение

  • Автор

13:29:22.0328 2300 TDSS rootkit removing tool 2.6.23.0 Dec 13 2011 10:39:31 13:29:22.0515 2300 ============================================================ 13:29:22.0515 2300 Current date / time: 2011/12/18 13:29:22.0515 13:29:22.0515 2300 SystemInfo: 13:29:22.0515 2300 13:29:22.0515 2300 OS Version: 5.1.2600 ServicePack: 3.0 13:29:22.0515 2300 Product type: Workstation 13:29:22.0515 2300 ComputerName: PC1 13:29:22.0515 2300 UserName: User1 13:29:22.0515 2300 Windows directory: C:\WINDOWS 13:29:22.0515 2300 System windows directory: C:\WINDOWS 13:29:22.0515 2300 Processor architecture: Intel x86 13:29:22.0515 2300 Number of processors: 2 13:29:22.0515 2300 Page size: 0x1000 13:29:22.0515 2300 Boot type: Normal boot 13:29:22.0515 2300 ============================================================ 13:29:23.0109 2300 Initialize success 13:29:28.0640 3772 ============================================================ 13:29:28.0640 3772 Scan started 13:29:28.0640 3772 Mode: Manual; SigCheck; TDLFS; 13:29:28.0640 3772 ============================================================ 13:29:28.0875 3772 Abiosdsk - ok 13:29:28.0875 3772 abp480n5 - ok 13:29:28.0921 3772 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 13:29:29.0375 3772 ACPI - ok 13:29:29.0437 3772 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 13:29:29.0562 3772 ACPIEC - ok 13:29:29.0578 3772 adpu160m - ok 13:29:29.0609 3772 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 13:29:29.0750 3772 aec - ok 13:29:29.0765 3772 AFD (322d0e36693d6e24a2398bee62a268cd) C:\WINDOWS\System32\drivers\afd.sys 13:29:29.0890 3772 AFD - ok 13:29:29.0906 3772 Aha154x - ok 13:29:29.0906 3772 aic78u2 - ok 13:29:29.0921 3772 aic78xx - ok 13:29:29.0937 3772 AliIde - ok 13:29:29.0953 3772 AmdK8 (0a4d13b388c814560bd69c3a496ecfa8) C:\WINDOWS\system32\DRIVERS\AmdK8.sys 13:29:29.0968 3772 AmdK8 - ok 13:29:29.0968 3772 amsint - ok 13:29:29.0984 3772 asc - ok 13:29:30.0000 3772 asc3350p - ok 13:29:30.0000 3772 asc3550 - ok 13:29:30.0015 3772 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 13:29:30.0140 3772 AsyncMac - ok 13:29:30.0156 3772 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 13:29:30.0281 3772 atapi - ok 13:29:30.0296 3772 Atdisk - ok 13:29:30.0312 3772 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 13:29:30.0437 3772 Atmarpc - ok 13:29:30.0468 3772 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 13:29:30.0578 3772 audstub - ok 13:29:30.0593 3772 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 13:29:30.0718 3772 Beep - ok 13:29:30.0734 3772 catchme - ok 13:29:30.0750 3772 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 13:29:30.0875 3772 cbidf2k - ok 13:29:30.0890 3772 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 13:29:31.0015 3772 CCDECODE - ok 13:29:31.0015 3772 cd20xrnt - ok 13:29:31.0031 3772 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 13:29:31.0156 3772 Cdaudio - ok 13:29:31.0171 3772 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 13:29:31.0296 3772 Cdfs - ok 13:29:31.0328 3772 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 13:29:31.0453 3772 Cdrom - ok 13:29:31.0453 3772 Changer - ok 13:29:31.0468 3772 CmdIde - ok 13:29:31.0484 3772 Cpqarray - ok 13:29:31.0500 3772 dac2w2k - ok 13:29:31.0500 3772 dac960nt - ok 13:29:31.0531 3772 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 13:29:31.0671 3772 Disk - ok 13:29:31.0703 3772 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 13:29:31.0875 3772 dmboot - ok 13:29:31.0875 3772 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 13:29:32.0000 3772 dmio - ok 13:29:32.0015 3772 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 13:29:32.0140 3772 dmload - ok 13:29:32.0171 3772 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 13:29:32.0312 3772 DMusic - ok 13:29:32.0328 3772 dpti2o - ok 13:29:32.0343 3772 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 13:29:32.0468 3772 drmkaud - ok 13:29:32.0484 3772 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 13:29:32.0625 3772 Fastfat - ok 13:29:32.0640 3772 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys 13:29:32.0765 3772 Fdc - ok 13:29:32.0781 3772 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 13:29:32.0906 3772 Fips - ok 13:29:32.0906 3772 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys 13:29:33.0046 3772 Flpydisk - ok 13:29:33.0078 3772 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys 13:29:33.0187 3772 FltMgr - ok 13:29:33.0218 3772 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 13:29:33.0343 3772 Fs_Rec - ok 13:29:33.0343 3772 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 13:29:33.0468 3772 Ftdisk - ok 13:29:33.0484 3772 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 13:29:33.0609 3772 Gpc - ok 13:29:33.0625 3772 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 13:29:33.0750 3772 HDAudBus - ok 13:29:33.0781 3772 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 13:29:33.0890 3772 HidUsb - ok 13:29:33.0906 3772 hpn - ok 13:29:33.0921 3772 HPZid412 (d03d10f7ded688fecf50f8fbf1ea9b8a) C:\WINDOWS\system32\DRIVERS\HPZid412.sys 13:29:33.0968 3772 HPZid412 - ok 13:29:33.0984 3772 HPZipr12 (89f41658929393487b6b7d13c8528ce3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys 13:29:34.0000 3772 HPZipr12 - ok 13:29:34.0031 3772 HPZius12 (abcb05ccdbf03000354b9553820e39f8) C:\WINDOWS\system32\DRIVERS\HPZius12.sys 13:29:34.0046 3772 HPZius12 - ok 13:29:34.0062 3772 HTTP (f6aacf5bce2893e0c1754afeb672e5c9) C:\WINDOWS\system32\Drivers\HTTP.sys 13:29:34.0187 3772 HTTP - ok 13:29:34.0203 3772 i2omgmt - ok 13:29:34.0203 3772 i2omp - ok 13:29:34.0234 3772 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 13:29:34.0484 3772 i8042prt - ok 13:29:34.0500 3772 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 13:29:34.0625 3772 Imapi - ok 13:29:34.0625 3772 ini910u - ok 13:29:34.0718 3772 IntcAzAudAddService (284bcb80391783d328a8d8163e97fd58) C:\WINDOWS\system32\drivers\RtkHDAud.sys 13:29:34.0843 3772 IntcAzAudAddService ( UnsignedFile.Multi.Generic ) - warning 13:29:34.0843 3772 IntcAzAudAddService - detected UnsignedFile.Multi.Generic (1) 13:29:34.0843 3772 IntelIde - ok 13:29:34.0875 3772 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 13:29:35.0000 3772 Ip6Fw - ok 13:29:35.0031 3772 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 13:29:35.0171 3772 IpFilterDriver - ok 13:29:35.0171 3772 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 13:29:35.0296 3772 IpInIp - ok 13:29:35.0328 3772 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 13:29:35.0437 3772 IpNat - ok 13:29:35.0453 3772 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 13:29:35.0593 3772 IPSec - ok 13:29:35.0609 3772 irda (aca5e7b54409f9cb5eed97ed0c81120e) C:\WINDOWS\system32\DRIVERS\irda.sys 13:29:35.0656 3772 irda - ok 13:29:35.0671 3772 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 13:29:35.0734 3772 IRENUM - ok 13:29:35.0734 3772 irsir (0501f0b9ab08425f8c0eacbdcc04aa32) C:\WINDOWS\system32\DRIVERS\irsir.sys 13:29:35.0781 3772 irsir - ok 13:29:35.0812 3772 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 13:29:35.0921 3772 isapnp - ok 13:29:35.0937 3772 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 13:29:36.0046 3772 Kbdclass - ok 13:29:36.0078 3772 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 13:29:36.0187 3772 kmixer - ok 13:29:36.0187 3772 KSecDD (1705745d900dabf2d89f90ebaddc7517) C:\WINDOWS\system32\drivers\KSecDD.sys 13:29:36.0312 3772 KSecDD - ok 13:29:36.0328 3772 lbrtfdc - ok 13:29:36.0359 3772 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 13:29:36.0484 3772 mnmdd - ok 13:29:36.0500 3772 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 13:29:36.0625 3772 Modem - ok 13:29:36.0640 3772 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 13:29:36.0750 3772 Mouclass - ok 13:29:36.0765 3772 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 13:29:36.0875 3772 mouhid - ok 13:29:36.0890 3772 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 13:29:37.0015 3772 MountMgr - ok 13:29:37.0031 3772 mraid35x - ok 13:29:37.0031 3772 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 13:29:37.0140 3772 MRxDAV - ok 13:29:37.0171 3772 MRxSmb (68755f0ff16070178b54674fe5b847b0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 13:29:37.0296 3772 MRxSmb - ok 13:29:37.0296 3772 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 13:29:37.0421 3772 Msfs - ok 13:29:37.0453 3772 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 13:29:37.0562 3772 MSKSSRV - ok 13:29:37.0578 3772 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 13:29:37.0687 3772 MSPCLOCK - ok 13:29:37.0703 3772 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 13:29:37.0812 3772 MSPQM - ok 13:29:37.0828 3772 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 13:29:37.0937 3772 mssmbios - ok 13:29:37.0968 3772 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys 13:29:38.0093 3772 MSTEE - ok 13:29:38.0109 3772 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys 13:29:38.0250 3772 Mup - ok 13:29:38.0265 3772 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 13:29:38.0390 3772 NABTSFEC - ok 13:29:38.0390 3772 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 13:29:38.0531 3772 NDIS - ok 13:29:38.0546 3772 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 13:29:38.0656 3772 NdisIP - ok 13:29:38.0671 3772 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 13:29:38.0781 3772 NdisTapi - ok 13:29:38.0796 3772 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 13:29:38.0921 3772 Ndisuio - ok 13:29:38.0937 3772 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 13:29:39.0046 3772 NdisWan - ok 13:29:39.0062 3772 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS\system32\drivers\NDProxy.sys 13:29:39.0187 3772 NDProxy - ok 13:29:39.0187 3772 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 13:29:39.0312 3772 NetBIOS - ok 13:29:39.0328 3772 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 13:29:39.0453 3772 NetBT - ok 13:29:39.0484 3772 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 13:29:39.0593 3772 Npfs - ok 13:29:39.0609 3772 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 13:29:39.0734 3772 Ntfs - ok 13:29:39.0750 3772 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 13:29:39.0859 3772 Null - ok 13:29:39.0937 3772 nv (15a6306a0b958bf60f09688d0ee70479) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 13:29:40.0109 3772 nv - ok 13:29:40.0125 3772 NVENETFD (4d6f0d3fb17c1ba64942f415c73adcdb) C:\WINDOWS\system32\DRIVERS\NVENETFD.sys 13:29:40.0140 3772 NVENETFD - ok 13:29:40.0156 3772 nvnetbus (921e63aa1e1a20302223d016acafb52b) C:\WINDOWS\system32\DRIVERS\nvnetbus.sys 13:29:40.0171 3772 nvnetbus - ok 13:29:40.0187 3772 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 13:29:40.0296 3772 NwlnkFlt - ok 13:29:40.0312 3772 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 13:29:40.0437 3772 NwlnkFwd - ok 13:29:40.0453 3772 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 13:29:40.0578 3772 Parport - ok 13:29:40.0593 3772 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 13:29:40.0703 3772 PartMgr - ok 13:29:40.0718 3772 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 13:29:40.0812 3772 ParVdm - ok 13:29:40.0828 3772 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 13:29:40.0953 3772 PCI - ok 13:29:40.0953 3772 PCIDump - ok 13:29:40.0968 3772 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 13:29:41.0062 3772 PCIIde - ok 13:29:41.0093 3772 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 13:29:41.0218 3772 Pcmcia - ok 13:29:41.0234 3772 PDCOMP - ok 13:29:41.0234 3772 PDFRAME - ok 13:29:41.0250 3772 PDRELI - ok 13:29:41.0250 3772 PDRFRAME - ok 13:29:41.0265 3772 perc2 - ok 13:29:41.0265 3772 perc2hib - ok 13:29:41.0296 3772 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 13:29:41.0406 3772 PptpMiniport - ok 13:29:41.0421 3772 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys 13:29:41.0515 3772 Processor - ok 13:29:41.0531 3772 PROCEXP150 - ok 13:29:41.0546 3772 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 13:29:41.0640 3772 PSched - ok 13:29:41.0656 3772 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 13:29:41.0765 3772 Ptilink - ok 13:29:41.0781 3772 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\WINDOWS\system32\Drivers\PxHelp20.sys 13:29:41.0812 3772 PxHelp20 - ok 13:29:41.0812 3772 ql1080 - ok 13:29:41.0828 3772 Ql10wnt - ok 13:29:41.0828 3772 ql12160 - ok 13:29:41.0843 3772 ql1240 - ok 13:29:41.0843 3772 ql1280 - ok 13:29:41.0859 3772 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 13:29:41.0968 3772 RasAcd - ok 13:29:41.0984 3772 Rasirda (0207d26ddf796a193ccd9f83047bb5fc) C:\WINDOWS\system32\DRIVERS\rasirda.sys 13:29:42.0031 3772 Rasirda - ok 13:29:42.0046 3772 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 13:29:42.0140 3772 Rasl2tp - ok 13:29:42.0156 3772 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 13:29:42.0265 3772 RasPppoe - ok 13:29:42.0265 3772 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 13:29:42.0375 3772 Raspti - ok 13:29:42.0390 3772 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 13:29:42.0500 3772 Rdbss - ok 13:29:42.0500 3772 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 13:29:42.0625 3772 RDPCDD - ok 13:29:42.0640 3772 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 13:29:42.0734 3772 rdpdr - ok 13:29:42.0765 3772 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys 13:29:42.0859 3772 RDPWD - ok 13:29:42.0890 3772 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 13:29:43.0000 3772 redbook - ok 13:29:43.0046 3772 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 13:29:43.0093 3772 Secdrv - ok 13:29:43.0109 3772 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 13:29:43.0218 3772 serenum - ok 13:29:43.0234 3772 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 13:29:43.0343 3772 Serial - ok 13:29:43.0359 3772 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 13:29:43.0468 3772 Sfloppy - ok 13:29:43.0484 3772 Simbad - ok 13:29:43.0500 3772 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys 13:29:43.0609 3772 SLIP - ok 13:29:43.0781 3772 SNPSTD3 (7bad0c53b3268226188f52702277a289) C:\WINDOWS\system32\DRIVERS\snpstd3.sys 13:29:44.0125 3772 SNPSTD3 ( UnsignedFile.Multi.Generic ) - warning 13:29:44.0125 3772 SNPSTD3 - detected UnsignedFile.Multi.Generic (1) 13:29:44.0125 3772 Sparrow - ok 13:29:44.0156 3772 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 13:29:44.0265 3772 splitter - ok 13:29:44.0281 3772 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 13:29:44.0328 3772 sr - ok 13:29:44.0343 3772 Srv (5252605079810904e31c332e241cd59b) C:\WINDOWS\system32\DRIVERS\srv.sys 13:29:44.0468 3772 Srv - ok 13:29:44.0484 3772 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 13:29:44.0609 3772 streamip - ok 13:29:44.0625 3772 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 13:29:44.0718 3772 swenum - ok 13:29:44.0734 3772 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 13:29:44.0843 3772 swmidi - ok 13:29:44.0859 3772 symc810 - ok 13:29:44.0859 3772 symc8xx - ok 13:29:44.0875 3772 sym_hi - ok 13:29:44.0890 3772 sym_u3 - ok 13:29:44.0890 3772 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 13:29:45.0000 3772 sysaudio - ok 13:29:45.0046 3772 SysProtDrv.sys (7d5b6655442dbcf5e3b86a134ab90584) C:\Documents and Settings\User2\Desktop\SysProt\SysProtDrv.sys 13:29:45.0062 3772 SysProtDrv.sys ( UnsignedFile.Multi.Generic ) - warning 13:29:45.0062 3772 SysProtDrv.sys - detected UnsignedFile.Multi.Generic (1) 13:29:45.0093 3772 Tcpip (93ea8d04ec73a85db02eb8805988f733) C:\WINDOWS\system32\DRIVERS\tcpip.sys 13:29:45.0187 3772 Tcpip - ok 13:29:45.0218 3772 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 13:29:45.0328 3772 TDPIPE - ok 13:29:45.0328 3772 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 13:29:45.0437 3772 TDTCP - ok 13:29:45.0453 3772 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 13:29:45.0578 3772 TermDD - ok 13:29:45.0593 3772 TosIde - ok 13:29:45.0625 3772 TrueSight (f69641efdb19acb4753b0155f7fdeed5) c:\windows\system32\drivers\TrueSight.sys 13:29:45.0625 3772 TrueSight ( UnsignedFile.Multi.Generic ) - warning 13:29:45.0625 3772 TrueSight - detected UnsignedFile.Multi.Generic (1) 13:29:45.0640 3772 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 13:29:45.0734 3772 Udfs - ok 13:29:45.0750 3772 ultra - ok 13:29:45.0765 3772 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 13:29:45.0875 3772 Update - ok 13:29:45.0906 3772 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys 13:29:46.0015 3772 usbaudio - ok 13:29:46.0031 3772 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 13:29:46.0140 3772 usbccgp - ok 13:29:46.0171 3772 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 13:29:46.0265 3772 usbehci - ok 13:29:46.0281 3772 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 13:29:46.0375 3772 usbhub - ok 13:29:46.0390 3772 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys 13:29:46.0484 3772 usbohci - ok 13:29:46.0484 3772 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 13:29:46.0578 3772 usbprint - ok 13:29:46.0609 3772 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 13:29:46.0703 3772 usbscan - ok 13:29:46.0718 3772 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 13:29:46.0828 3772 USBSTOR - ok 13:29:46.0843 3772 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 13:29:46.0937 3772 VgaSave - ok 13:29:46.0937 3772 ViaIde - ok 13:29:46.0968 3772 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 13:29:47.0062 3772 VolSnap - ok 13:29:47.0078 3772 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 13:29:47.0171 3772 Wanarp - ok 13:29:47.0187 3772 WDICA - ok 13:29:47.0203 3772 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 13:29:47.0312 3772 wdmaud - ok 13:29:47.0359 3772 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 13:29:47.0453 3772 WSTCODEC - ok 13:29:47.0468 3772 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 13:29:47.0500 3772 WudfPf - ok 13:29:47.0500 3772 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 13:29:47.0515 3772 WudfRd - ok 13:29:47.0546 3772 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0 13:29:47.0718 3772 \Device\Harddisk0\DR0 - ok 13:29:47.0718 3772 MBR (0x1B8) (ddae9d649db12f6aff24483f2c298989) \Device\Harddisk1\DR3 13:29:48.0375 3772 \Device\Harddisk1\DR3 - ok 13:29:48.0375 3772 Boot (0x1200) (9e6c268018559d4381edc6aea6b856f3) \Device\Harddisk0\DR0\Partition0 13:29:48.0375 3772 \Device\Harddisk0\DR0\Partition0 - ok 13:29:48.0390 3772 Boot (0x1200) (96c9f5612911e408a2ea40dc15aeb057) \Device\Harddisk0\DR0\Partition1 13:29:48.0390 3772 \Device\Harddisk0\DR0\Partition1 - ok 13:29:48.0390 3772 Boot (0x1200) (d316cc272bbafcd33d41b790fa7eafc5) \Device\Harddisk1\DR3\Partition0 13:29:48.0390 3772 \Device\Harddisk1\DR3\Partition0 - ok 13:29:48.0390 3772 ============================================================ 13:29:48.0390 3772 Scan finished 13:29:48.0390 3772 ============================================================ 13:29:48.0500 3420 Detected object count: 4 13:29:48.0500 3420 Actual detected object count: 4 13:30:00.0859 3420 IntcAzAudAddService ( UnsignedFile.Multi.Generic ) - skipped by user 13:30:00.0859 3420 IntcAzAudAddService ( UnsignedFile.Multi.Generic ) - User select action: Skip 13:30:00.0859 3420 SNPSTD3 ( UnsignedFile.Multi.Generic ) - skipped by user 13:30:00.0859 3420 SNPSTD3 ( UnsignedFile.Multi.Generic ) - User select action: Skip 13:30:00.0859 3420 SysProtDrv.sys ( UnsignedFile.Multi.Generic ) - skipped by user 13:30:00.0859 3420 SysProtDrv.sys ( UnsignedFile.Multi.Generic ) - User select action: Skip 13:30:00.0859 3420 TrueSight ( UnsignedFile.Multi.Generic ) - skipped by user 13:30:00.0859 3420 TrueSight ( UnsignedFile.Multi.Generic ) - User select action: Skip 13:31:10.0640 3740 Deinitialize success ne moga da pisha na kirilica,iz4ezna kirilizatora. Gmer ne nameri nikakvi modifikacii

  • Автор

prazen e,nqma ni6to napisano,samo prazen Notepad document skanirah o6te vednaj,sega ima nqkakaw log.Izpolzvah vtorata opciq ot instruktiraneto GMER 1.0.15.15641 - http://www.gmer.net Rootkit scan 2011-12-18 13:55:15 Windows 5.1.2600 Service Pack 3 Running: gmer.exe; Driver: C:\DOCUME~1\User1\LOCALS~1\Temp\pxtdapow.sys ---- Kernel code sections - GMER 1.0.15 ---- ? Combo-Fix.sys The system cannot find the file specified. ! .text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xBA040360, 0x2456AE, 0xE8000020] ? C:\ComboFix\catchme.sys The system cannot find the path specified. ! ? C:\WINDOWS\system32\Drivers\PROCEXP113.SYS The system cannot find the file specified. ! ---- User code sections - GMER 1.0.15 ---- .text C:\Program Files\Google\Chrome\Application\chrome.exe[1320] ntdll.dll!NtCreateFile + 6 7C90D096 4 Bytes [28, 00, 16, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[1320] ntdll.dll!NtCreateFile + B 7C90D09B 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[1320] ntdll.dll!NtMapViewOfSection + 6 7C90D506 1 Byte [28] .text C:\Program Files\Google\Chrome\Application\chrome.exe[1320] ntdll.dll!NtMapViewOfSection + 6 7C90D506 4 Bytes [28, 03, 16, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[1320] ntdll.dll!NtMapViewOfSection + B 7C90D50B 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[1320] ntdll.dll!NtOpenFile + 6 7C90D586 4 Bytes [68, 00, 16, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[1320] ntdll.dll!NtOpenFile + B 7C90D58B 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[1320] ntdll.dll!NtOpenProcess + 6 7C90D5E6 4 Bytes [A8, 01, 16, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[1320] ntdll.dll!NtOpenProcess + B 7C90D5EB 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[1320] ntdll.dll!NtOpenProcessToken + 6 7C90D5F6 4 Bytes CALL 7B90EBFC .text C:\Program Files\Google\Chrome\Application\chrome.exe[1320] ntdll.dll!NtOpenProcessToken + B 7C90D5FB 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[1320] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D606 4 Bytes [A8, 02, 16, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[1320] ntdll.dll!NtOpenProcessTokenEx + B 7C90D60B 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[1320] ntdll.dll!NtOpenThread + 6 7C90D646 4 Bytes [68, 01, 16, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[1320] ntdll.dll!NtOpenThread + B 7C90D64B 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[1320] ntdll.dll!NtOpenThreadToken + 6 7C90D656 4 Bytes [68, 02, 16, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[1320] ntdll.dll!NtOpenThreadToken + B 7C90D65B 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[1320] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D666 4 Bytes CALL 7B90EC6D .text C:\Program Files\Google\Chrome\Application\chrome.exe[1320] ntdll.dll!NtOpenThreadTokenEx + B 7C90D66B 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[1320] ntdll.dll!NtQueryAttributesFile + 6 7C90D6F6 4 Bytes [A8, 00, 16, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[1320] ntdll.dll!NtQueryAttributesFile + B 7C90D6FB 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[1320] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D796 4 Bytes CALL 7B90ED9B .text C:\Program Files\Google\Chrome\Application\chrome.exe[1320] ntdll.dll!NtQueryFullAttributesFile + B 7C90D79B 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[1320] ntdll.dll!NtSetInformationFile + 6 7C90DC46 4 Bytes [28, 01, 16, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[1320] ntdll.dll!NtSetInformationFile + B 7C90DC4B 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[1320] ntdll.dll!NtSetInformationThread + 6 7C90DC96 4 Bytes [28, 02, 16, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[1320] ntdll.dll!NtSetInformationThread + B 7C90DC9B 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[1320] ntdll.dll!NtUnmapViewOfSection + 6 7C90DEF6 1 Byte [68] .text C:\Program Files\Google\Chrome\Application\chrome.exe[1320] ntdll.dll!NtUnmapViewOfSection + 6 7C90DEF6 4 Bytes [68, 03, 16, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[1320] ntdll.dll!NtUnmapViewOfSection + B 7C90DEFB 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2640] ntdll.dll!NtCreateFile + 6 7C90D096 4 Bytes [28, 00, 16, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2640] ntdll.dll!NtCreateFile + B 7C90D09B 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2640] ntdll.dll!NtMapViewOfSection + 6 7C90D506 1 Byte [28] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2640] ntdll.dll!NtMapViewOfSection + 6 7C90D506 4 Bytes [28, 03, 16, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2640] ntdll.dll!NtMapViewOfSection + B 7C90D50B 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2640] ntdll.dll!NtOpenFile + 6 7C90D586 4 Bytes [68, 00, 16, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2640] ntdll.dll!NtOpenFile + B 7C90D58B 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2640] ntdll.dll!NtOpenProcess + 6 7C90D5E6 4 Bytes [A8, 01, 16, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2640] ntdll.dll!NtOpenProcess + B 7C90D5EB 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2640] ntdll.dll!NtOpenProcessToken + 6 7C90D5F6 4 Bytes CALL 7B90EBFC .text C:\Program Files\Google\Chrome\Application\chrome.exe[2640] ntdll.dll!NtOpenProcessToken + B 7C90D5FB 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2640] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D606 4 Bytes [A8, 02, 16, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2640] ntdll.dll!NtOpenProcessTokenEx + B 7C90D60B 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2640] ntdll.dll!NtOpenThread + 6 7C90D646 4 Bytes [68, 01, 16, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2640] ntdll.dll!NtOpenThread + B 7C90D64B 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2640] ntdll.dll!NtOpenThreadToken + 6 7C90D656 4 Bytes [68, 02, 16, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2640] ntdll.dll!NtOpenThreadToken + B 7C90D65B 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2640] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D666 4 Bytes CALL 7B90EC6D .text C:\Program Files\Google\Chrome\Application\chrome.exe[2640] ntdll.dll!NtOpenThreadTokenEx + B 7C90D66B 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2640] ntdll.dll!NtQueryAttributesFile + 6 7C90D6F6 4 Bytes [A8, 00, 16, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2640] ntdll.dll!NtQueryAttributesFile + B 7C90D6FB 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2640] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D796 4 Bytes CALL 7B90ED9B .text C:\Program Files\Google\Chrome\Application\chrome.exe[2640] ntdll.dll!NtQueryFullAttributesFile + B 7C90D79B 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2640] ntdll.dll!NtSetInformationFile + 6 7C90DC46 4 Bytes [28, 01, 16, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2640] ntdll.dll!NtSetInformationFile + B 7C90DC4B 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2640] ntdll.dll!NtSetInformationThread + 6 7C90DC96 4 Bytes [28, 02, 16, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2640] ntdll.dll!NtSetInformationThread + B 7C90DC9B 1 Byte [E2] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2640] ntdll.dll!NtUnmapViewOfSection + 6 7C90DEF6 1 Byte [68] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2640] ntdll.dll!NtUnmapViewOfSection + 6 7C90DEF6 4 Bytes [68, 03, 16, 00] .text C:\Program Files\Google\Chrome\Application\chrome.exe[2640] ntdll.dll!NtUnmapViewOfSection + B 7C90DEFB 1 Byte [E2] ---- EOF - GMER 1.0.15 ----

Добре, задръжте за сега..!

Копирайте текста в карето на notepad и го запазвате с име CFScript.txt на десктопа си:

KILLALL::

Folder::
c:\windows\SxsCaPendDel

След съхранението преместете CFScript.txt на иконата на ComboFix.exe

Публикувано изображение

Генерирания рапорт прикачете в следващия си пост..!

  • Автор

eto go noviq log ComboFix 11-12-17.05 - User1 12.2011 г. 14:01:13.4.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.1791.1283 [GMT 2:00] Running from: c:\documents and settings\User1\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\User1\Desktop\CFScript.txt.txt . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\SxsCaPendDel . . ((((((((((((((((((((((((( Files Created from 2011-11-18 to 2011-12-18 ))))))))))))))))))))))))))))))) . . 2011-12-16 11:58 . 2011-12-16 12:00 -------- d-----w- c:\documents and settings\All Users\Application Data\BitDefender 2011-12-16 11:58 . 2011-12-16 11:58 -------- d-----w- c:\program files\BitDefender 2011-12-16 11:57 . 2011-12-16 11:58 -------- d-----w- c:\program files\Common Files\BitDefender 2011-12-16 11:32 . 2011-12-16 11:32 -------- d-----w- c:\documents and settings\User1\Application Data\QuickScan 2011-12-15 14:16 . 2011-12-15 14:16 -------- d--h--w- c:\windows\PIF 2011-12-15 08:28 . 2011-12-15 08:28 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys 2011-12-15 08:22 . 2011-12-15 08:22 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\Sunbelt Software 2011-12-15 08:22 . 2011-12-15 08:22 -------- d-----w- c:\program files\Lavasoft 2011-12-15 08:22 . 2011-12-15 08:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft 2011-12-15 08:21 . 2011-12-15 08:21 388096 ----a-r- c:\documents and settings\User1\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-12-15 08:21 . 2011-12-15 08:21 -------- d-----w- c:\program files\Trend Micro 2011-12-15 08:18 . 2011-12-15 08:21 -------- d-----w- C:\HJT 2011-12-09 14:12 . 2011-12-16 11:49 -------- d-----w- c:\documents and settings\User1\Application Data\Media Player Classic 2011-12-06 08:57 . 2011-12-15 16:08 111872 ----a-w- c:\windows\system32\drivers\TrueSight.sys 2011-11-29 10:36 . 2011-12-18 12:00 -------- d-----w- c:\windows\system32\CatRoot2 2011-11-27 08:48 . 2011-11-27 08:48 -------- d-----w- c:\program files\ESET 2011-11-26 11:22 . 2011-11-26 11:22 -------- d-----w- c:\documents and settings\User1\Application Data\Malwarebytes 2011-11-26 11:22 . 2011-12-16 10:56 -------- d-----w- C:\Malwarebytes' Anti-Malware . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-12-15 14:55 . 2008-04-14 02:42 26112 ----a-w- c:\windows\system32\userinit.exe . . ------- Sigcheck ------- Note: Unsigned files aren't necessarily malware. . [-] 2008-04-23 . 0484B919829B94B6EEC50D0AC607751A . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll . ((((((((((((((((((((((((((((( SnapShot@2011-12-18_10.13.03 ))))))))))))))))))))))))))))))))))))))))) . + 2011-12-18 12:04 . 2011-12-18 12:04 16384 c:\windows\temp\Perflib_Perfdata_6f8.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-16 7630848] "nwiz"="nwiz.exe" [2006-08-16 1617920] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-16 86016] "RTHDCPL"="RTHDCPL.EXE" [2006-08-14 16050176] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064] "tsnpstd3"="c:\windows\tsnpstd3.exe" [2006-06-19 262144] "snpstd3"="c:\windows\vsnpstd3.exe" [2006-05-12 831488] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] . c:\documents and settings\All Users\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520] . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr] 2005-05-03 15:43 69632 ----a-w- c:\windows\Alcmtr.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE] 2008-04-14 02:42 15360 ----a-w- c:\windows\system32\ctfmon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent] 2011-05-02 09:46 395640 ----a-w- c:\program files\uTorrent\uTorrent.exe . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Opera\\opera.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= "f:\\skype_portable\\13\\skype\\skype.exe"= . S3 PROCEXP150;PROCEXP150;\??\c:\windows\system32\Drivers\PROCEXP150.SYS --> c:\windows\system32\Drivers\PROCEXP150.SYS [?] S3 SysProtDrv.sys;SysProtDrv.sys;c:\documents and settings\User2\Desktop\SysProt\SysProtDrv.sys [11/11/2011 2:21 PM 44288] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder . 2011-12-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-05-02 09:41] . 2011-12-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-05-02 09:41] . . ------- Supplementary Scan ------- . uDefault_Search_URL = hxxp://www.google.com/ie uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7PRFA_en uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html TCP: DhcpNameServer = 46.40.72.9 192.168.0.1 . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-12-18 14:04 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_USERS\S-1-5-21-220523388-412668190-1417001333-1003\Software\Microsoft\SystemCertificates\AddressBook*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\Shell\B20@O=5 *=0 *C*C*l*e*a*n*e*r*& \command] @="c:\\Program Files\\CCleaner\\ccleaner.exe" . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'explorer.exe'(2052) c:\windows\system32\ieframe.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\OneX.DLL c:\windows\system32\eappprxy.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Java\jre6\bin\jqs.exe c:\windows\system32\nvsvc32.exe c:\windows\system32\wscntfy.exe c:\windows\RTHDCPL.EXE c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe . ************************************************************************** . Completion time: 2011-12-18 14:05:07 - machine was rebooted ComboFix-quarantined-files.txt 2011-12-18 12:05 ComboFix2.txt 2011-12-18 11:08 ComboFix3.txt 2011-12-18 10:30 ComboFix4.txt 2011-12-18 10:14 . Pre-Run: 14 360 395 776 bytes free Post-Run: 14 348 603 392 bytes free . - - End Of File - - 4822E1981A95AAB84B4F4EE6B3DC2AE9

Какво е положението със системата ви..?Наблюдавате ли първоначалните проблеми..?

Да оправим кирилицата..!

Изтеглете lang.zip

http://www61.zippyshare.com/v/67647613/file.html и го запомнете на десктопа си,разархивирате и стартирате *reg файла с двоен клик.Задължително рестартирате компютъра си..!

  • Автор

napravih nujnoto ,no nqma promqna,samo malko po barzo zarejda-o6te e sin ekrana,bez kirilizator,i ne moga da otvorq kosh4eto- o6te ikonata mu otvarq CCleaner i kata go restartirah mi kazva 4e e nameren now hardware, a az ne sam dobawql nikawo nowo ustroistwo

o6te e sin ekrana,

Той и ще продължи да бъде син,до момента в който не си сложите нов тапет,защото ClamWin по някъкви нейни си причини е решила че стария ви тапет е вирус и го изтрива.

ne moga da otvorq kosh4eto- o6te ikonata mu otvarq CCleaner

Стартирайте CCleaner и в менюто настройки махнете отметките на следните позиции:

Публикувано изображение

  • Автор

napravih go,iz4isti 50 mb,no mnogo interesno ne6to se slu4va,kato pusnah CCleaner-a i toi si svar6i rabotata vlizam otnowo vav foruma i vijdam 4e drugo ime se polzva ot moq komputar i qvno sledi kakvo si korespondirame,imeto e greynight17 ,predpolagam 4e e distantcionno i moje bi zatowa ne moga de se iz4istq ako toi deistwa ednovremenno s nas

napravih go,iz4isti 50 mb,no mnogo interesno ne6to se slu4va,kato pusnah CCleaner-a i toi si svar6i rabotata vlizam otnowo vav foruma i vijdam 4e drugo ime se polzva ot moq komputar i qvno sledi kakvo si korespondirame,imeto e greyknight17 ,predpolagam 4e e distantcionno i moje bi zatowa ne moga de se iz4istq ako toi deistwa ednovremenno s nas

Деинсталирайте Комбофикс така:

1.Натиснете Start ==> Run ==> въведете командата Combofix /Uninstall ==> OK

Публикувано изображение

2.Изтеглете Публикувано изображениеOTCleanIt или от тук,стартирайте и натиснете Публикувано изображение

Отново изпълнете:

Изтеглете lang.zip

http://www61.zippysh...47613/file.html и го запомнете на десктопа си,разархивирате и стартирате *reg файла с двоен клик.Задължително рестартирате компютъра си..!

  • Автор

Деинсталирайте Комбофикс така:

1.Натиснете Start ==> Run ==> въведете командата Combofix /Uninstall ==> OK

Публикувано изображение

2.Изтеглете Публикувано изображениеOTCleanIt или от тук,стартирайте и натиснете Публикувано изображение

Отново изпълнете:

Изтеглете lang.zip

http://www61.zippysh...47613/file.html и го запомнете на десктопа си,разархивирате и стартирате *reg файла с двоен клик.Задължително рестартирате компютъра си..!

4ak sega uspqh da pi6a,ne sam napravil poslednata instrukciq,6te q napravq utre.Mersi mnogo za otdelenoto vnimanie i vreme.Nadqvam se do produljim procesa na doo4istvane

Ако имате още малко време - Н е изпълнявайте последната инструкция..!А изпълнете следния скрипт...!

Копирайте текста в карето на notepad и го запазвате с име CFScript.txt на десктопа си:

KILLALL::


File::
c:\windows\system32\Drivers\PROCEXP150.SYS
c:\documents and settings\User2\Desktop\SysProt\SysProtDrv.sys

Driver::
PROCEXP150
SysProtDrv.sys


След съхранението преместете CFScript.txt на иконата на ComboFix.exe

Публикувано изображение

Генерирания рапорт прикачете в следващия си пост..!

  • Автор

interneta e mnogo lo6,i edvam uspqvam da se zadurja po dulgo vreme.O6te nqma da polzvam OTC sega ,a 6te pusna scripta vuv Combofix.Kato se polu4i log file 6te go pusna.Nadqvam se da uspeq dnes

  • Автор

eto go noviq log,popita me dali da instalira nove versiq na Combofix i az napravih update.Log-a e ot novata versiq: ComboFix 11-12-18.02 - User1 12.2011 г. 9:13.6.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.1791.1217 [GMT 2:00] Running from: c:\documents and settings\User1\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\User1\Desktop\CFScript.txt.txt . FILE :: "c:\documents and settings\User2\Desktop\SysProt\SysProtDrv.sys" "c:\windows\system32\Drivers\PROCEXP150.SYS" . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\documents and settings\User2\Desktop\SysProt\SysProtDrv.sys . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Service_PROCEXP150 -------\Service_SysProtDrv.sys . . ((((((((((((((((((((((((( Files Created from 2011-11-19 to 2011-12-19 ))))))))))))))))))))))))))))))) . . 2011-12-16 11:58 . 2011-12-16 12:00 -------- d-----w- c:\documents and settings\All Users\Application Data\BitDefender 2011-12-16 11:58 . 2011-12-16 11:58 -------- d-----w- c:\program files\BitDefender 2011-12-16 11:57 . 2011-12-16 11:58 -------- d-----w- c:\program files\Common Files\BitDefender 2011-12-16 11:32 . 2011-12-16 11:32 -------- d-----w- c:\documents and settings\User1\Application Data\QuickScan 2011-12-15 14:16 . 2011-12-15 14:16 -------- d--h--w- c:\windows\PIF 2011-12-15 08:28 . 2011-12-15 08:28 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys 2011-12-15 08:22 . 2011-12-15 08:22 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\Sunbelt Software 2011-12-15 08:22 . 2011-12-15 08:22 -------- d-----w- c:\program files\Lavasoft 2011-12-15 08:22 . 2011-12-15 08:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft 2011-12-15 08:21 . 2011-12-15 08:21 388096 ----a-r- c:\documents and settings\User1\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-12-15 08:21 . 2011-12-15 08:21 -------- d-----w- c:\program files\Trend Micro 2011-12-15 08:18 . 2011-12-15 08:21 -------- d-----w- C:\HJT 2011-12-09 14:12 . 2011-12-16 11:49 -------- d-----w- c:\documents and settings\User1\Application Data\Media Player Classic 2011-12-06 08:57 . 2011-12-15 16:08 111872 ----a-w- c:\windows\system32\drivers\TrueSight.sys 2011-11-29 10:36 . 2011-12-19 07:12 -------- d-----w- c:\windows\system32\CatRoot2 2011-11-27 08:48 . 2011-11-27 08:48 -------- d-----w- c:\program files\ESET 2011-11-26 11:22 . 2011-11-26 11:22 -------- d-----w- c:\documents and settings\User1\Application Data\Malwarebytes 2011-11-26 11:22 . 2011-12-16 10:56 -------- d-----w- C:\Malwarebytes' Anti-Malware . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-12-15 14:55 . 2008-04-14 02:42 26112 ----a-w- c:\windows\system32\userinit.exe . . ------- Sigcheck ------- Note: Unsigned files aren't necessarily malware. . [-] 2008-04-23 . 0484B919829B94B6EEC50D0AC607751A . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll . ((((((((((((((((((((((((((((( SnapShot@2011-12-18_10.13.03 ))))))))))))))))))))))))))))))))))))))))) . + 2011-12-19 07:16 . 2011-12-19 07:16 16384 c:\windows\temp\Perflib_Perfdata_6ec.dat + 2009-08-06 17:24 . 2009-08-06 17:24 44768 c:\windows\system32\wups2.dll + 2011-05-02 07:10 . 2009-08-06 17:24 35552 c:\windows\system32\wups.dll + 2011-05-02 07:10 . 2009-08-06 17:24 53472 c:\windows\system32\wuauclt.exe + 2011-12-18 12:44 . 2009-08-06 17:24 35552 c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.4.7600.226\wups.dll + 2011-05-02 07:10 . 2009-08-06 17:24 35552 c:\windows\system32\dllcache\wups.dll + 2011-05-02 07:10 . 2009-08-06 17:24 53472 c:\windows\system32\dllcache\wuauclt.exe + 2008-04-14 02:41 . 2009-08-06 17:24 96480 c:\windows\system32\dllcache\cdm.dll + 2008-04-14 02:41 . 2009-08-06 17:24 96480 c:\windows\system32\cdm.dll + 2011-05-02 07:10 . 2009-08-06 17:24 209632 c:\windows\system32\wuweb.dll + 2011-05-02 07:10 . 2009-08-06 17:24 327896 c:\windows\system32\wucltui.dll + 2011-05-02 07:10 . 2009-08-06 17:23 575704 c:\windows\system32\wuapi.dll + 2011-05-02 07:10 . 2009-08-06 17:24 209632 c:\windows\system32\dllcache\wuweb.dll + 2011-05-02 07:10 . 2009-08-06 17:24 327896 c:\windows\system32\dllcache\wucltui.dll + 2011-05-02 07:10 . 2009-08-06 17:23 575704 c:\windows\system32\dllcache\wuapi.dll + 2011-05-02 07:10 . 2009-08-06 17:23 1929952 c:\windows\system32\wuaueng.dll + 2011-05-02 07:10 . 2009-08-06 17:23 1929952 c:\windows\system32\dllcache\wuaueng.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-16 7630848] "nwiz"="nwiz.exe" [2006-08-16 1617920] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-16 86016] "RTHDCPL"="RTHDCPL.EXE" [2006-08-14 16050176] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064] "tsnpstd3"="c:\windows\tsnpstd3.exe" [2006-06-19 262144] "snpstd3"="c:\windows\vsnpstd3.exe" [2006-05-12 831488] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] . c:\documents and settings\All Users\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520] . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr] 2005-05-03 15:43 69632 ----a-w- c:\windows\Alcmtr.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE] 2008-04-14 02:42 15360 ----a-w- c:\windows\system32\ctfmon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent] 2011-05-02 09:46 395640 ----a-w- c:\program files\uTorrent\uTorrent.exe . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Opera\\opera.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= "f:\\skype_portable\\13\\skype\\skype.exe"= . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder . 2011-12-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-05-02 09:41] . 2011-12-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-05-02 09:41] . . ------- Supplementary Scan ------- . uDefault_Search_URL = hxxp://www.google.com/ie uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7PRFA_en uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html TCP: DhcpNameServer = 46.40.72.9 192.168.0.1 . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-12-19 09:16 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_USERS\S-1-5-21-220523388-412668190-1417001333-1003\Software\Microsoft\SystemCertificates\AddressBook*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\Shell\B20@O=5 *=0 *C*C*l*e*a*n*e*r*& \command] @="c:\\Program Files\\CCleaner\\ccleaner.exe" . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'explorer.exe'(3300) c:\windows\system32\ieframe.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll c:\windows\system32\OneX.DLL c:\windows\system32\eappprxy.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Java\jre6\bin\jqs.exe c:\windows\system32\nvsvc32.exe c:\windows\system32\wscntfy.exe c:\windows\RTHDCPL.EXE c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe . ************************************************************************** . Completion time: 2011-12-19 09:17:58 - machine was rebooted ComboFix-quarantined-files.txt 2011-12-19 07:17 ComboFix2.txt 2011-12-18 12:51 ComboFix3.txt 2011-12-18 12:05 ComboFix4.txt 2011-12-18 11:08 ComboFix5.txt 2011-12-19 07:12 . Pre-Run: 14 340 374 528 bytes free Post-Run: 14 310 309 888 bytes free . - - End Of File - - 1D383E538578F9153A18A5CA320EFEFE

  • Автор

eto go noviq log,popita me dali da instalira nove versiq na Combofix i az napravih update.Log-a e ot novata versiq:

ComboFix 11-12-18.02 - User1 12.2011 г. 9:13.6.2 - x86

Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.1791.1217 [GMT 2:00]

Running from: c:\documents and settings\User1\Desktop\ComboFix.exe

Command switches used :: c:\documents and settings\User1\Desktop\CFScript.txt.txt

.

FILE ::

"c:\documents and settings\User2\Desktop\SysProt\SysProtDrv.sys"

"c:\windows\system32\Drivers\PROCEXP150.SYS"

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\documents and settings\User2\Desktop\SysProt\SysProtDrv.sys

.

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

-------\Service_PROCEXP150

-------\Service_SysProtDrv.sys

.

.

((((((((((((((((((((((((( Files Created from 2011-11-19 to 2011-12-19 )))))))))))))))))))))))))))))))

.

.

2011-12-16 11:58 . 2011-12-16 12:00 -------- d-----w- c:\documents and settings\All Users\Application Data\BitDefender

2011-12-16 11:58 . 2011-12-16 11:58 -------- d-----w- c:\program files\BitDefender

2011-12-16 11:57 . 2011-12-16 11:58 -------- d-----w- c:\program files\Common Files\BitDefender

2011-12-16 11:32 . 2011-12-16 11:32 -------- d-----w- c:\documents and settings\User1\Application Data\QuickScan

2011-12-15 14:16 . 2011-12-15 14:16 -------- d--h--w- c:\windows\PIF

2011-12-15 08:28 . 2011-12-15 08:28 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys

2011-12-15 08:22 . 2011-12-15 08:22 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\Sunbelt Software

2011-12-15 08:22 . 2011-12-15 08:22 -------- d-----w- c:\program files\Lavasoft

2011-12-15 08:22 . 2011-12-15 08:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft

2011-12-15 08:21 . 2011-12-15 08:21 388096 ----a-r- c:\documents and settings\User1\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2011-12-15 08:21 . 2011-12-15 08:21 -------- d-----w- c:\program files\Trend Micro

2011-12-15 08:18 . 2011-12-15 08:21 -------- d-----w- C:\HJT

2011-12-09 14:12 . 2011-12-16 11:49 -------- d-----w- c:\documents and settings\User1\Application Data\Media Player Classic

2011-12-06 08:57 . 2011-12-15 16:08 111872 ----a-w- c:\windows\system32\drivers\TrueSight.sys

2011-11-29 10:36 . 2011-12-19 07:12 -------- d-----w- c:\windows\system32\CatRoot2

2011-11-27 08:48 . 2011-11-27 08:48 -------- d-----w- c:\program files\ESET

2011-11-26 11:22 . 2011-11-26 11:22 -------- d-----w- c:\documents and settings\User1\Application Data\Malwarebytes

2011-11-26 11:22 . 2011-12-16 10:56 -------- d-----w- C:\Malwarebytes' Anti-Malware

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-12-15 14:55 . 2008-04-14 02:42 26112 ----a-w- c:\windows\system32\userinit.exe

.

.

------- Sigcheck -------

Note: Unsigned files aren't necessarily malware.

.

[-] 2008-04-23 . 0484B919829B94B6EEC50D0AC607751A . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll

.

((((((((((((((((((((((((((((( SnapShot@2011-12-18_10.13.03 )))))))))))))))))))))))))))))))))))))))))

.

+ 2011-12-19 07:16 . 2011-12-19 07:16 16384 c:\windows\temp\Perflib_Perfdata_6ec.dat

+ 2009-08-06 17:24 . 2009-08-06 17:24 44768 c:\windows\system32\wups2.dll

+ 2011-05-02 07:10 . 2009-08-06 17:24 35552 c:\windows\system32\wups.dll

+ 2011-05-02 07:10 . 2009-08-06 17:24 53472 c:\windows\system32\wuauclt.exe

+ 2011-12-18 12:44 . 2009-08-06 17:24 35552 c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.4.7600.226\wups.dll

+ 2011-05-02 07:10 . 2009-08-06 17:24 35552 c:\windows\system32\dllcache\wups.dll

+ 2011-05-02 07:10 . 2009-08-06 17:24 53472 c:\windows\system32\dllcache\wuauclt.exe

+ 2008-04-14 02:41 . 2009-08-06 17:24 96480 c:\windows\system32\dllcache\cdm.dll

+ 2008-04-14 02:41 . 2009-08-06 17:24 96480 c:\windows\system32\cdm.dll

+ 2011-05-02 07:10 . 2009-08-06 17:24 209632 c:\windows\system32\wuweb.dll

+ 2011-05-02 07:10 . 2009-08-06 17:24 327896 c:\windows\system32\wucltui.dll

+ 2011-05-02 07:10 . 2009-08-06 17:23 575704 c:\windows\system32\wuapi.dll

+ 2011-05-02 07:10 . 2009-08-06 17:24 209632 c:\windows\system32\dllcache\wuweb.dll

+ 2011-05-02 07:10 . 2009-08-06 17:24 327896 c:\windows\system32\dllcache\wucltui.dll

+ 2011-05-02 07:10 . 2009-08-06 17:23 575704 c:\windows\system32\dllcache\wuapi.dll

+ 2011-05-02 07:10 . 2009-08-06 17:23 1929952 c:\windows\system32\wuaueng.dll

+ 2011-05-02 07:10 . 2009-08-06 17:23 1929952 c:\windows\system32\dllcache\wuaueng.dll

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-16 7630848]

"nwiz"="nwiz.exe" [2006-08-16 1617920]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-16 86016]

"RTHDCPL"="RTHDCPL.EXE" [2006-08-14 16050176]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]

"tsnpstd3"="c:\windows\tsnpstd3.exe" [2006-06-19 262144]

"snpstd3"="c:\windows\vsnpstd3.exe" [2006-05-12 831488]

"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

.

c:\documents and settings\All Users\Start Menu\Programs\Startup\

HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]

2005-05-03 15:43 69632 ----a-w- c:\windows\Alcmtr.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]

2008-04-14 02:42 15360 ----a-w- c:\windows\system32\ctfmon.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]

2011-05-02 09:46 395640 ----a-w- c:\program files\uTorrent\uTorrent.exe

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\Opera\\opera.exe"=

"c:\\Program Files\\uTorrent\\uTorrent.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

"f:\\skype_portable\\13\\skype\\skype.exe"=

.

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

.

Contents of the 'Scheduled Tasks' folder

.

2011-12-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2011-05-02 09:41]

.

2011-12-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2011-05-02 09:41]

.

.

------- Supplementary Scan -------

.

uDefault_Search_URL = hxxp://www.google.com/ie

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7PRFA_en

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000

IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html

TCP: DhcpNameServer = 46.40.72.9 192.168.0.1

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2011-12-19 09:16

Windows 5.1.2600 Service Pack 3 NTFS

.

scanning hidden processes ...

.

scanning hidden autostart entries ...

.

scanning hidden files ...

.

scan completed successfully

hidden files: 0

.

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_USERS\S-1-5-21-220523388-412668190-1417001333-1003\Software\Microsoft\SystemCertificates\AddressBook*]

@Allowed: (Read) (RestrictedCode)

@Allowed: (Read) (RestrictedCode)

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\Shell\B20@O=5 *=0 *C*C*l*e*a*n*e*r*& \command]

@="c:\\Program Files\\CCleaner\\ccleaner.exe"

.

--------------------- DLLs Loaded Under Running Processes ---------------------

.

- - - - - - - > 'explorer.exe'(3300)

c:\windows\system32\ieframe.dll

c:\windows\system32\WPDShServiceObj.dll

c:\windows\system32\PortableDeviceTypes.dll

c:\windows\system32\PortableDeviceApi.dll

c:\windows\system32\OneX.DLL

c:\windows\system32\eappprxy.dll

.

------------------------ Other Running Processes ------------------------

.

c:\program files\Java\jre6\bin\jqs.exe

c:\windows\system32\nvsvc32.exe

c:\windows\system32\wscntfy.exe

c:\windows\RTHDCPL.EXE

c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe

.

**************************************************************************

.

Completion time: 2011-12-19 09:17:58 - machine was rebooted

ComboFix-quarantined-files.txt 2011-12-19 07:17

ComboFix2.txt 2011-12-18 12:51

ComboFix3.txt 2011-12-18 12:05

ComboFix4.txt 2011-12-18 11:08

ComboFix5.txt 2011-12-19 07:12

.

Pre-Run: 14 340 374 528 bytes free

Post-Run: 14 310 309 888 bytes free

.

- - End Of File - - 1D383E538578F9153A18A5CA320EFEFE

Eto i posledniq log ot Clamwin:

Scan Started Mon Dec 19 13:07:07 2011

-------------------------------------------------------------------------------

WARNING: Can't open file C:\Documents and Settings\User1\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache\data_0: Permission denied

WARNING: Can't open file C:\Documents and Settings\User1\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache\data_1: Permission denied

WARNING: Can't open file C:\Documents and Settings\User1\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache\data_2: Permission denied

WARNING: Can't open file C:\Documents and Settings\User1\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache\data_3: Permission denied

WARNING: Can't open file C:\Documents and Settings\User1\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache\index: Permission denied

WARNING: Can't open file C:\Documents and Settings\User1\Local Settings\Application Data\Google\Chrome\User Data\Default\Current Session: Permission denied

WARNING: Can't open file C:\Documents and Settings\User1\Local Settings\Application Data\Google\Chrome\User Data\Default\Current Tabs: Permission denied

WARNING: Can't open file C:\Documents and Settings\User1\Local Settings\temp\etilqs_CgBVIzunO3GTliS: Permission denied

WARNING: Can't open file C:\Documents and Settings\User1\Local Settings\temp\etilqs_NJVh4dUEzmCsAsc: Permission denied

WARNING: Can't open file C:\Documents and Settings\User1\Local Settings\temp\etilqs_p8i1SCidRDo76Tm: Permission denied

WARNING: Can't open file C:\Documents and Settings\User1\Local Settings\temp\nsgB7A8.tmp: Permission denied

WARNING: Can't open file C:\pagefile.sys: Permission denied

WARNING: Can't open file C:\WINDOWS\system32\CatRoot2\tmp.edb: Permission denied

WARNING: Can't open file C:\WINDOWS\system32\config\default: Permission denied

WARNING: Can't open file C:\WINDOWS\system32\config\SAM: Permission denied

WARNING: Can't open file C:\WINDOWS\system32\config\SECURITY: Permission denied

WARNING: Can't open file C:\WINDOWS\system32\config\software: Permission denied

WARNING: Can't open file C:\WINDOWS\system32\config\system: Permission denied

C:\Documents and Settings\User1\Desktop\iExplore.exe: Trojan.Hupigon-33703 FOUND

C:\Documents and Settings\User1\Desktop\rkill.scr: Trojan.Hupigon-33703 FOUND

C:\Documents and Settings\User2\Desktop\setup_ais.exe: Trojan.Generic.Bredolab-2 FOUND

----------- SCAN SUMMARY -----------

Known viruses: 1095409

Engine version: 0.97.2

Scanned directories: 3227

Scanned files: 20654

Infected files: 3

Data scanned: 4189.22 MB

Data read: 6175.09 MB (ratio 0.68:1)

Time: 1053.843 sec (17 m 33 s)

--------------------------------------

Completed

--------------------------------------

Здравейте..! ;) Първо да се извиня за закъснението..но имах служебни ангажименти....! :)

Публикувано изображение Изтеглете OTL.exe и го запазете на десктопа.

  • Стартирайте OTL (ако е необходимо, потвърдете през UAC).
  • Направете следните настройки:
  • Сложете отметка пред Scan All Users Публикувано изображение
  • Под менюто File Age => изберете 90 days
  • Под менюто Standard Registry => променете на ALL
  • Сложете отметки пред LOP и Purity Check
Публикувано изображение Под Публикувано изображение с Copy/ Paste въведете изцяло следната текстова информация (само това, което е поставено в карето):

netsvcs
msconfig
%SYSTEMDRIVE%\*.*
%USERPROFILE%\*.*
%USERPROFILE%\Application Data\*.*
%USERPROFILE%\Local Settings\Application Data\*.*
%AllUsersProfile%\*.*
%AllUsersProfile%\Application Data\*.*
%USERPROFILE%\My Documents\*.*
%CommonProgramFiles%\*.*
%PROGRAMFILES%\*.*
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /90
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\system32\Spool\prtprocs\w32x86\*.dll
/md5start
hlp.dat
winlogon.exe
wininit.exe
userinit.exe
explorer.exe
volsnap.sys
/md5stop
  • Натиснете маркираният в синьо бутон: Run Scan.
  • Като приключи проверката, ще се създадат два файла - OTL.Txt и Extras.Txt. Прикачете тези два файла в следващия си коментар (погледнете опцията "прикачени файлове", когато публикувате мнение).

И още нещо:

Публикувано изображение Изтеглете Security Check (автор: screen317) от тук или от тук и го запишете на десктопа.

  • Кликнете два пъти върху SecurityCheck.exe и следвайте инструкциите.
  • Когато програмата завърши работата си, ще се отвори един текстов документ: checkup.txt.
  • Копирайте съдържанието на checkup.txt с Копирай (Copy) и с Постави (Paste) го поставете в следващия си коментар.
  • Автор

Здравейте..! ;) Първо да се извиня за закъснението..но имах служебни ангажименти....! :)

Публикувано изображение Изтеглете OTL.exe и го запазете на десктопа.

  • Стартирайте OTL (ако е необходимо, потвърдете през UAC).
  • Направете следните настройки:
  • Сложете отметка пред Scan All Users Публикувано изображение
  • Под менюто File Age => изберете 90 days
  • Под менюто Standard Registry => променете на ALL
  • Сложете отметки пред LOP и Purity Check
Публикувано изображение Под Публикувано изображение с Copy/ Paste въведете изцяло следната текстова информация (само това, което е поставено в карето):

netsvcs
msconfig
%SYSTEMDRIVE%\*.*
%USERPROFILE%\*.*
%USERPROFILE%\Application Data\*.*
%USERPROFILE%\Local Settings\Application Data\*.*
%AllUsersProfile%\*.*
%AllUsersProfile%\Application Data\*.*
%USERPROFILE%\My Documents\*.*
%CommonProgramFiles%\*.*
%PROGRAMFILES%\*.*
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /90
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\system32\Spool\prtprocs\w32x86\*.dll
/md5start
hlp.dat
winlogon.exe
wininit.exe
userinit.exe
explorer.exe
volsnap.sys
/md5stop
  • Натиснете маркираният в синьо бутон: Run Scan.
  • Като приключи проверката, ще се създадат два файла - OTL.Txt и Extras.Txt. Прикачете тези два файла в следващия си коментар (погледнете опцията "прикачени файлове", когато публикувате мнение).
И още нещо:

Публикувано изображение Изтеглете Security Check (автор: screen317) от тук или от тук и го запишете на десктопа.

  • Кликнете два пъти върху SecurityCheck.exe и следвайте инструкциите.
  • Когато програмата завърши работата си, ще се отвори един текстов документ: checkup.txt.
  • Копирайте съдържанието на checkup.txt с Копирай (Copy) и с Постави (Paste) го поставете в следващия си коментар.

eto gi i log-ovete:

Results of screen317's Security Check version 0.99.29

Windows XP Service Pack 3 x86

Internet Explorer 7 Out of date!

``````````````````````````````

Antivirus/Firewall Check:

Windows Firewall Enabled!

ESET Online Scanner v3

WMI entry may not exist for antivirus; attempting automatic update.

```````````````````````````````

Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware

CCleaner

Java 6 Update 24

Java version out of date!

Adobe Flash Player 10.2.153.1 Flash Player out of Date!

Adobe Reader X 10.0.1 Adobe Reader out of Date!

````````````````````````````````

Process Check:

objlist.exe by Laurent

``````````End of Log````````````

OTL:

OTL Extras logfile created on: 20.12.2011 г. 10:59:22 - Run 1

OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\User1\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 7.0.5730.13)

Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.M.yyyy 'г.'

1,75 Gb Total Physical Memory | 1,24 Gb Available Physical Memory | 71,00% Memory free

3,60 Gb Paging File | 3,25 Gb Available in Paging File | 90,30% Paging File free

Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 19,53 Gb Total Space | 12,57 Gb Free Space | 64,34% Space Free | Partition Type: NTFS

Drive D: | 576,64 Gb Total Space | 442,00 Gb Free Space | 76,65% Space Free | Partition Type: NTFS

Drive F: | 7,46 Gb Total Space | 2,73 Gb Free Space | 36,62% Space Free | Partition Type: FAT32

Computer Name: PC1 | User Name: User1 | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 90 Days

========== Extra Registry (SafeList) ==========

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

.html [@ = Opera.HTML] -- C:\Program Files\Opera\Opera.exe (Opera Software)

.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l

[HKEY_USERS\S-1-5-21-220523388-412668190-1417001333-1003\SOFTWARE\Classes\<extension>]

.html [@ = Opera.HTML] -- C:\Program Files\Opera\Opera.exe (Opera Software)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

exefile [open] -- "%1" %*

htmlfile [edit] -- Reg Error: Key error.

https [open] -- "C:\Program Files\Opera\Opera.exe" "%1" (Opera Software)

InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"FirstRunDisabled" = 1

"AntiVirusDisableNotify" = 0

"FirewallDisableNotify" = 0

"UpdatesDisableNotify" = 0

"AntiVirusOverride" = 0

"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]

"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]

"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]

"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"EnableFirewall" = 1

"DoNotAllowExceptions" = 0

"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)

"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)

"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)

"C:\Program Files\Opera\opera.exe" = C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser -- (Opera Software)

"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)

"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.)

"F:\skype_portable\13\skype\skype.exe" = F:\skype_portable\13\skype\skype.exe:*:Enabled:skype -- (Skype Technologies S.A.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{00772F8B-37FF-4704-A47D-72B30BFAF126}" = MPM

"{0BC4864E-72C5-472D-8692-0E5971E0BD36}" = BPDSoftware_Ini

"{10829556-7C82-4a83-8C81-F2D98472C76B}" = H470

"{10E1E87C-656C-4D08-86D6-5443D28583BE}" = TrayApp

"{1185566F-12ED-3EF0-89CC-38866DCE1EEE}" = Microsoft .NET Framework 3.0 Client Service Pack 2

"{13F00518-807A-4B3A-83B0-A7CD90F3A398}" = MarketResearch

"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer

"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

"{21F9F066-D1C8-4727-84AE-83A2AB2DF9E6}" = SA Dictionary 2010 Beta 1

"{22466889-7642-488d-AA0E-F619704CF7AB}" = DeviceDiscovery

"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java 6 Update 24

"{29FA38B4-0AE4-4D0D-8A51-6165BB990BB0}" = WebReg

"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP

"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis

"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater

"{5335DADB-34BA-4AE8-A519-648D78498846}" = Skype™ 5.3

"{5A15F754-086E-4185-96F4-0BC31F1A2382}" = HP Officejet H470 Series

"{6673E0F4-D376-431b-A6F4-18D1B86B4A89}" = BPDSoftware

"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder

"{6B349DE1-590D-4506-B272-9115EC31F7D2}" = 470_Help

"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder

"{7AEF344E-DB20-4D76-9077-30BD339DFD99}" = StarCam Clip

"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003

"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting

"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper

"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder

"{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X (10.0.1)

"{AEA07F97-9088-497c-8821-0F36BD5DC251}" = HPProductAssistant

"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Toolbars

"{BA72A4E3-D2D0-4203-A17E-E53012B8807C}" = BPD_HPSU

"{BCD6CD1A-0DBE-412E-9F25-3B500D1E6BA1}" = SolutionCenter

"{CAAFB8F9-F8D1-3D27-9AAA-6301A4429440}" = Microsoft .NET Framework 2.0 Client Service Pack 2

"{D4DFFA1F-F20D-40AC-8617-D945FC2F87BE}" = Bulgarian (Phonetic) - REAL

"{D617A4DC-C915-3F25-BE43-57E5FD99B441}" = Microsoft .NET Framework 3.5 Client Service Pack 1

"{E022C318-BAC9-468D-8731-3C5EE63C7743}" = 470_Readme

"{E2662C24-B31E-4349-A084-32EB76E8B760}" = BufferChm

"{E9C18EBD-85BE-47D0-AA73-3FEDCC976B04}" = Toolbox

"{EE5F0136-2C7C-42a7-B1B0-5F12D107A0EE}" = ProductContext

"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver

"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer

"{FD8D8B04-BEAD-4A55-AA1D-62D2373E7DEA}" = Status

"53F13DB4D9611FD63BE580F06F0729BF236ABE68" = Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)

"7-Zip" = 7-Zip 9.20

"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX

"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin

"CCleaner" = CCleaner

"Defraggler" = Defraggler

"ESET Online Scanner" = ESET Online Scanner v3

"Google Chrome" = Google Chrome

"HP Imaging Device Functions" = HP Imaging Device Functions 9.0

"HP Solution Center & Imaging Support Tools" = HP Solution Center 9.0

"HPExtendedCapabilities" = HP Customer Participation Program 9.0

"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs

"ie7" = Windows Internet Explorer 7

"KLiteCodecPack_is1" = K-Lite Codec Pack 7.0.0 (Full)

"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300

"Microsoft.Net.Client.3.5" = Microsoft .NET Framework Client Profile

"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP

"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs

"NVIDIA Drivers" = NVIDIA Drivers

"Opera 11.10.2092" = Opera 11.10

"Recuva" = Recuva

"Totalcmd" = Total Commander (Remove or Repair)

"uTorrent" = µTorrent

"Windows Media Format Runtime" = Windows Media Format 11 runtime

"Windows Media Player" = Windows Media Player 11

"WinRAR archiver" = WinRAR 4.00 (32-битова версия)

"WMFDist11" = Windows Media Format 11 runtime

"wmp11" = Windows Media Player 11

"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-220523388-412668190-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 10 Event Log Errors ==========

[ Application Events ]

Error - 04.7.2011 г. 08:47:14 | Computer Name = PC1 | Source = Google Update | ID = 20

Description =

Error - 07.7.2011 г. 01:47:00 | Computer Name = PC1 | Source = Google Update | ID = 20

Description =

Error - 11.7.2011 г. 08:05:04 | Computer Name = PC1 | Source = MsiInstaller | ID = 11321

Description = Product: Skype™ 5.3 -- Error 1321. The Installer has insufficient

privileges to modify this file: C:\Program Files\Skype\Phone\Skype.exe.

Error - 21.7.2011 г. 01:50:36 | Computer Name = PC1 | Source = Google Update | ID = 20

Description =

Error - 21.7.2011 г. 02:50:37 | Computer Name = PC1 | Source = Google Update | ID = 20

Description =

Error - 21.7.2011 г. 03:50:38 | Computer Name = PC1 | Source = Google Update | ID = 20

Description =

Error - 21.7.2011 г. 04:50:39 | Computer Name = PC1 | Source = Google Update | ID = 20

Description =

Error - 22.7.2011 г. 09:20:47 | Computer Name = PC1 | Source = MsiInstaller | ID = 11321

Description = Product: Skype™ 5.3 -- Error 1321. The Installer has insufficient

privileges to modify this file: C:\Program Files\Skype\Phone\Skype.exe.

Error - 03.10.2011 г. 06:30:19 | Computer Name = PC1 | Source = Userenv | ID = 1068

Description = Windows ended GPO processing because the computer shut down or the

user logged off.

Error - 06.10.2011 г. 03:50:12 | Computer Name = PC1 | Source = Microsoft Management Console | ID = 1000

Description =

[ System Events ]

Error - 18.12.2011 г. 08:01:11 | Computer Name = PC1 | Source = Service Control Manager | ID = 7034

Description = The Print Spooler service terminated unexpectedly. It has done this

1 time(s).

Error - 18.12.2011 г. 08:01:11 | Computer Name = PC1 | Source = Service Control Manager | ID = 7034

Description = The Application Layer Gateway Service service terminated unexpectedly.

It has done this 1 time(s).

Error - 18.12.2011 г. 08:47:10 | Computer Name = PC1 | Source = Service Control Manager | ID = 7034

Description = The NVIDIA Display Driver Service service terminated unexpectedly.

It has done this 1 time(s).

Error - 18.12.2011 г. 08:47:10 | Computer Name = PC1 | Source = Service Control Manager | ID = 7034

Description = The Java Quick Starter service terminated unexpectedly. It has done

this 1 time(s).

Error - 18.12.2011 г. 08:47:10 | Computer Name = PC1 | Source = Service Control Manager | ID = 7034

Description = The Application Layer Gateway Service service terminated unexpectedly.

It has done this 1 time(s).

Error - 18.12.2011 г. 08:47:10 | Computer Name = PC1 | Source = Service Control Manager | ID = 7034

Description = The Print Spooler service terminated unexpectedly. It has done this

1 time(s).

Error - 19.12.2011 г. 03:13:10 | Computer Name = PC1 | Source = Service Control Manager | ID = 7034

Description = The Java Quick Starter service terminated unexpectedly. It has done

this 1 time(s).

Error - 19.12.2011 г. 03:13:10 | Computer Name = PC1 | Source = Service Control Manager | ID = 7034

Description = The NVIDIA Display Driver Service service terminated unexpectedly.

It has done this 1 time(s).

Error - 19.12.2011 г. 03:13:10 | Computer Name = PC1 | Source = Service Control Manager | ID = 7034

Description = The Application Layer Gateway Service service terminated unexpectedly.

It has done this 1 time(s).

Error - 19.12.2011 г. 03:13:10 | Computer Name = PC1 | Source = Service Control Manager | ID = 7034

Description = The Print Spooler service terminated unexpectedly. It has done this

1 time(s).

< End of report >

OTL logfile created on: 20.12.2011 г. 10:59:22 - Run 1

OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\User1\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 7.0.5730.13)

Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.M.yyyy 'г.'

1,75 Gb Total Physical Memory | 1,24 Gb Available Physical Memory | 71,00% Memory free

3,60 Gb Paging File | 3,25 Gb Available in Paging File | 90,30% Paging File free

Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 19,53 Gb Total Space | 12,57 Gb Free Space | 64,34% Space Free | Partition Type: NTFS

Drive D: | 576,64 Gb Total Space | 442,00 Gb Free Space | 76,65% Space Free | Partition Type: NTFS

Drive F: | 7,46 Gb Total Space | 2,73 Gb Free Space | 36,62% Space Free | Partition Type: FAT32

Computer Name: PC1 | User Name: User1 | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 90 Days

========== Processes (SafeList) ==========

PRC - [2011.12.20 10:55:57 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User1\Desktop\OTL.exe

PRC - [2011.12.07 13:16:29 | 001,047,096 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Chrome\Application\chrome.exe

PRC - [2010.10.29 13:49:28 | 000,505,064 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Common Files\Java\Java Update\jucheck.exe

PRC - [2008.04.14 04:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe

PRC - [2006.06.19 10:43:34 | 000,262,144 | ---- | M] () -- C:\WINDOWS\tsnpstd3.exe

PRC - [2006.05.12 10:27:04 | 000,831,488 | ---- | M] () -- C:\WINDOWS\vsnpstd3.exe

========== Modules (No Company Name) ==========

MOD - [2011.12.07 13:16:28 | 000,411,192 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\16.0.912.63\ppgooglenaclpluginchrome.dll

MOD - [2011.12.07 13:16:27 | 003,767,864 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\16.0.912.63\pdf.dll

MOD - [2011.12.07 13:14:56 | 000,122,952 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\16.0.912.63\avutil-51.dll

MOD - [2011.12.07 13:14:55 | 000,222,280 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\16.0.912.63\avformat-53.dll

MOD - [2011.12.07 13:14:53 | 001,746,504 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\16.0.912.63\avcodec-53.dll

MOD - [2011.12.07 09:22:33 | 008,593,056 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\16.0.912.63\gcswf32.dll

MOD - [2011.03.02 12:40:52 | 000,140,288 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll

MOD - [2006.08.16 09:35:00 | 000,466,944 | ---- | M] () -- C:\WINDOWS\system32\nvshell.dll

MOD - [2006.08.16 09:35:00 | 000,196,608 | ---- | M] () -- C:\WINDOWS\system32\nvapi.dll

MOD - [2006.06.19 10:43:34 | 000,262,144 | ---- | M] () -- C:\WINDOWS\tsnpstd3.exe

MOD - [2006.05.12 10:27:04 | 000,831,488 | ---- | M] () -- C:\WINDOWS\vsnpstd3.exe

========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- -- (HidServ)

========== Driver Services (SafeList) ==========

DRV - [2006.08.15 13:41:16 | 004,368,896 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)

DRV - [2006.07.11 15:38:30 | 000,020,480 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)

DRV - [2006.07.11 15:38:28 | 000,057,856 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)

DRV - [2006.06.27 12:50:36 | 010,148,480 | ---- | M] (Sonix Co. Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\snpstd3.sys -- (SNPSTD3)

DRV - [2006.06.18 22:37:34 | 000,036,864 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)

DRV - [2001.08.17 15:51:32 | 000,018,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\irsir.sys -- (irsir)

========== Standard Registry (All) ==========

========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome

IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-220523388-412668190-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie

IE - HKU\S-1-5-21-220523388-412668190-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

IE - HKU\S-1-5-21-220523388-412668190-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

IE - HKU\S-1-5-21-220523388-412668190-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google

IE - HKU\S-1-5-21-220523388-412668190-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7PRFA_en

IE - HKU\S-1-5-21-220523388-412668190-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKU\S-1-5-21-220523388-412668190-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKU\S-1-5-21-220523388-412668190-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKU\S-1-5-21-220523388-412668190-1417001333-1003\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)

IE - HKU\S-1-5-21-220523388-412668190-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()

FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2011.05.02 11:50:03 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[email protected]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2011.05.02 11:30:03 | 000,000,000 | ---D | M]

[2011.12.09 10:52:45 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions

[2011.05.02 11:46:16 | 000,000,000 | ---D | M] (Skype extension) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}

[2011.05.02 12:20:13 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}

[2011.02.02 20:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll

[2003.07.15 00:56:52 | 000,013,888 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)

CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}

CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}

CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.63\gcswf32.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll

CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll

CHR - plugin: Java Platform SE 6 U24 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll

CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll

CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll

CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL

CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer

CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.63\ppGoogleNaClPluginChrome.dll

CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.63\pdf.dll

CHR - plugin: Winamp Application Detector (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npwachk.dll

CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll

CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll

CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll

CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll

CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

CHR - plugin: Default Plug-in (Enabled) = default_plugin

CHR - Extension: YouTube = C:\Documents and Settings\User1\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.2_0\

CHR - Extension: Google Search = C:\Documents and Settings\User1\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0\

CHR - Extension: BitDefender QuickScan = C:\Documents and Settings\User1\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pdnkcidphdcakpkheohlhocaicfamjie\0.9.9.100_0\

CHR - Extension: Gmail = C:\Documents and Settings\User1\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0\

O1 HOSTS File: ([2011.12.19 09:16:47 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)

O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)

O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)

O3 - HKU\S-1-5-21-220523388-412668190-1417001333-1003\..\Toolbar\ShellBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)

O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)

O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)

O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)

O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)

O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)

O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()

O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.exe (Realtek Semiconductor Corp.)

O4 - HKLM..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe ()

O4 - HKLM..\Run: [sunJavaUpdateSched] C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)

O4 - HKLM..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe ()

O4 - HKU\.DEFAULT..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)

O4 - HKU\S-1-5-18..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)

O4 - HKU\S-1-5-21-220523388-412668190-1417001333-1003..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)

O4 - Startup: C:\Documents and Settings\User2\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = File not found

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0

O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-21-220523388-412668190-1417001333-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-21-220523388-412668190-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKU\S-1-5-21-220523388-412668190-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKU\S-1-5-21-220523388-412668190-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)

O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not found

O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)

O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)

O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 46.40.72.9 192.168.0.1

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0227FD86-8C54-4C88-8029-3F44137A8ADF}: DhcpNameServer = 46.40.72.9 192.168.0.1

O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)

O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ipp - No CLSID value found

O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)

O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)

O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp - No CLSID value found

O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)

O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)

O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)

O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)

O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)

O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)

O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)

O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)

O18 - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UIHost - (logonui.exe) -C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)

O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) -C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)

O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") -C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)

O20 - Winlogon\Notify\crypt32chain: DllName - (crypt32.dll) - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)

O20 - Winlogon\Notify\cryptnet: DllName - (cryptnet.dll) - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)

O20 - Winlogon\Notify\cscdll: DllName - (cscdll.dll) - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)

O20 - Winlogon\Notify\dimsntfy: DllName - (%SystemRoot%\System32\dimsntfy.dll) - C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)

O20 - Winlogon\Notify\ScCertProp: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O20 - Winlogon\Notify\Schedule: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O20 - Winlogon\Notify\sclgntfy: DllName - (sclgntfy.dll) - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)

O20 - Winlogon\Notify\SensLogn: DllName - (WlNotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O20 - Winlogon\Notify\termsrv: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O20 - Winlogon\Notify\wlballoon: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)

O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)

O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)

O24 - Desktop Components:0 (My Current Home Page) - About:Home

O24 - Desktop WallPaper: C:\Documents and Settings\User1\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O24 - Desktop BackupWallPaper: C:\Documents and Settings\User1\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)

O29 - HKLM SecurityProviders - (msapsspc.dll) -C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)

O29 - HKLM SecurityProviders - (schannel.dll) -C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)

O29 - HKLM SecurityProviders - (digest.dll) -C:\WINDOWS\System32\digest.dll (Microsoft Corporation)

O29 - HKLM SecurityProviders - (msnsspc.dll) -C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)

O30 - LSA: Authentication Packages - (msv1_0) -C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (kerberos) -C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (msv1_0) -C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (schannel) -C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (wdigest) -C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)

O31 - SafeBoot: AlternateShell - cmd.exe

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2011.05.02 09:12:01 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O34 - HKLM BootExecute: (autocheck autochk *)

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = ComFile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: 6to4 - File not found

NetSvcs: HidServ - File not found

NetSvcs: Ias - File not found

NetSvcs: Iprip - File not found

NetSvcs: NWCWorkstation - File not found

NetSvcs: Nwsapagent - File not found

NetSvcs: WmdmPmSp - File not found

MsConfig - StartUpReg: Alcmtr - hkey= - key= - C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)

MsConfig - StartUpReg: CTFMON.EXE - hkey= - key= - File not found

MsConfig - StartUpReg: uTorrent - hkey= - key= - C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)

========== Files/Folders - Created Within 90 Days ==========

[2011.12.20 10:55:50 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\User1\Desktop\OTL.exe

[2011.12.20 10:16:07 | 000,607,260 | R--- | C] (Swearware) -- C:\Documents and Settings\User1\Desktop\dds.scr

[2011.12.20 08:59:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood

[2011.12.19 13:33:35 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\PreInstall

[2011.12.19 12:12:46 | 000,000,000 | -HSD | C] -- C:\RECYCLER

[2011.12.19 09:18:06 | 000,293,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\browserchoice.exe

[2011.12.19 09:17:58 | 002,192,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntoskrnl.exe

[2011.12.19 09:17:58 | 002,148,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlmp.exe

[2011.12.19 09:17:58 | 002,069,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlpa.exe

[2011.12.19 09:17:58 | 002,027,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrpamp.exe

[2011.12.19 09:15:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp

[2011.12.18 14:55:42 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\User1\Recent

[2011.12.18 14:44:37 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\SoftwareDistribution

[2011.12.18 13:25:52 | 001,577,264 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\User1\Desktop\tdsskiller.exe

[2011.12.18 12:05:39 | 000,000,000 | RHSD | C] -- C:\cmdcons

[2011.12.18 12:04:31 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe

[2011.12.18 12:04:31 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe

[2011.12.18 12:04:31 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe

[2011.12.18 12:04:31 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe

[2011.12.18 12:04:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT

[2011.12.18 12:04:09 | 000,000,000 | ---D | C] -- C:\Qoobox

[2011.12.18 12:02:10 | 004,344,515 | R--- | C] (Swearware) -- C:\Documents and Settings\User1\Desktop\ComboFix.exe

[2011.12.18 10:50:48 | 000,000,000 | R--D | C] -- D:\My Documents\My Videos

[2011.12.16 13:58:15 | 000,000,000 | ---D | C] -- C:\Program Files\BitDefender

[2011.12.16 13:58:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\BitDefender

[2011.12.16 13:57:48 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\BitDefender

[2011.12.16 13:32:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Application Data\QuickScan

[2011.12.16 12:32:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Desktop\GooredFix Backups

[2011.12.16 12:16:58 | 000,071,398 | ---- | C] (jpshortstuff) -- C:\Documents and Settings\User1\Desktop\GooredFix.exe

[2011.12.16 12:13:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Desktop\New Folder

[2011.12.15 16:16:45 | 000,000,000 | -H-D | C] -- C:\WINDOWS\PIF

[2011.12.15 10:28:39 | 000,101,720 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys

[2011.12.15 10:22:22 | 000,000,000 | ---D | C] -- C:\Program Files\Lavasoft

[2011.12.15 10:22:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Lavasoft

[2011.12.15 10:21:38 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro

[2011.12.15 10:21:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Start Menu\Programs\HiJackThis

[2011.12.15 10:18:57 | 000,000,000 | ---D | C] -- C:\HJT

[2011.12.15 09:42:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Desktop\New Folder (2)

[2011.12.09 16:12:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Application Data\Media Player Classic

[2011.12.06 10:57:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Desktop\RK_Quarantine

[2011.11.29 12:36:37 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot2

[2011.11.27 10:48:48 | 000,000,000 | ---D | C] -- C:\Program Files\ESET

[2011.11.27 10:48:24 | 002,322,184 | ---- | C] (ESET) -- C:\Documents and Settings\User1\Desktop\esetsmartinstaller_enu.exe

[2011.11.26 13:22:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Application Data\Malwarebytes

[2011.11.26 13:22:07 | 000,000,000 | ---D | C] -- C:\Malwarebytes' Anti-Malware

[2011.05.18 19:09:42 | 000,147,456 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnpstd3.dll

[2011.05.18 19:09:41 | 000,061,440 | ---- | C] ( ) -- C:\WINDOWS\System32\vsnpstd3.dll

[2011.05.18 19:09:40 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\csnpstd3.dll

[1 C:\Documents and Settings\User1\*.tmp files -> C:\Documents and Settings\User1\*.tmp -> ]

========== Files - Modified Within 90 Days ==========

[2011.12.20 10:58:48 | 000,879,668 | ---- | M] () -- C:\Documents and Settings\User1\Desktop\SecurityCheck.exe

[2011.12.20 10:55:57 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User1\Desktop\OTL.exe

[2011.12.20 10:24:41 | 000,294,216 | ---- | M] () -- C:\Documents and Settings\User1\Desktop\gmer.zip

[2011.12.20 10:16:10 | 000,607,260 | R--- | M] (Swearware) -- C:\Documents and Settings\User1\Desktop\dds.scr

[2011.12.20 10:13:54 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\User1\defogger_reenable

[2011.12.20 10:13:12 | 000,050,477 | ---- | M] () -- C:\Documents and Settings\User1\Desktop\Defogger.exe

[2011.12.20 10:07:00 | 000,000,984 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

[2011.12.20 09:07:00 | 000,000,980 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job

[2011.12.20 08:58:28 | 000,081,191 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml

[2011.12.20 08:58:14 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2011.12.20 08:58:12 | 000,143,624 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2011.12.19 13:34:00 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK

[2011.12.19 11:07:13 | 000,002,447 | ---- | M] () -- C:\Documents and Settings\User1\Desktop\HiJackThis.lnk

[2011.12.19 09:16:47 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts

[2011.12.19 09:12:11 | 004,344,515 | R--- | M] (Swearware) -- C:\Documents and Settings\User1\Desktop\ComboFix.exe

[2011.12.18 13:25:56 | 001,577,264 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\User1\Desktop\tdsskiller.exe

[2011.12.18 12:05:42 | 000,000,339 | RHS- | M] () -- C:\boot.ini

[2011.12.16 13:43:45 | 000,000,002 | ---- | M] () -- C:\WINDOWS\System32\config.nt

[2011.12.16 12:56:12 | 000,000,624 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk

[2011.12.16 12:53:24 | 000,000,139 | ---- | M] () -- C:\Documents and Settings\User1\Desktop\rk-proxy.reg

[2011.12.16 12:52:32 | 001,008,141 | ---- | M] () -- C:\Documents and Settings\User1\Desktop\iExplore.exe

[2011.12.16 12:16:58 | 000,071,398 | ---- | M] (jpshortstuff) -- C:\Documents and Settings\User1\Desktop\GooredFix.exe

[2011.12.16 09:15:27 | 000,001,813 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk

[2011.12.15 18:28:48 | 000,001,688 | ---- | M] () -- C:\WINDOWS\System32\AUTOEXEC.NT

[2011.12.15 18:14:11 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb

[2011.12.15 18:14:11 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb

[2011.12.15 18:08:11 | 000,111,872 | ---- | M] () -- C:\WINDOWS\System32\drivers\TrueSight.sys

[2011.12.15 16:55:04 | 000,026,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\userinit.exe

[2011.12.15 16:54:57 | 000,000,064 | ---- | M] () -- C:\WINDOWS\System32\rp_stats.dat

[2011.12.15 16:54:57 | 000,000,044 | ---- | M] () -- C:\WINDOWS\System32\rp_rules.dat

[2011.12.15 16:32:03 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\User1\Desktop\7eplg53x.reg

[2011.12.15 10:28:39 | 000,101,720 | ---- | M] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys

[2011.12.15 10:18:04 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2011.12.13 09:30:56 | 000,150,192 | ---- | M] () -- C:\Documents and Settings\User1\Desktop\tweakui.exe

[2011.12.13 09:30:24 | 000,109,238 | ---- | M] () -- C:\Documents and Settings\User1\Desktop\cmospwd.zip

[2011.12.13 09:30:21 | 000,162,728 | ---- | M] () -- C:\Documents and Settings\User1\Desktop\startuplist.zip

[2011.12.09 16:16:41 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat

[2011.12.09 16:13:58 | 000,011,776 | ---- | M] () -- C:\Documents and Settings\User1\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2011.11.29 12:21:04 | 000,335,992 | ---- | M] () -- C:\Documents and Settings\User1\Desktop\Dial-a-fix-v0.60.0.24.zip

[2011.11.27 10:48:35 | 002,322,184 | ---- | M] (ESET) -- C:\Documents and Settings\User1\Desktop\esetsmartinstaller_enu.exe

[2011.11.27 10:40:49 | 000,381,631 | ---- | M] () -- C:\Documents and Settings\User1\Desktop\MiniToolBox.exe

[2011.11.26 11:59:36 | 001,008,114 | ---- | M] () -- C:\Documents and Settings\User1\Desktop\rkill.scr

[2011.11.26 11:46:05 | 000,684,297 | ---- | M] () -- C:\Documents and Settings\User1\Desktop\unhide.exe

[2011.10.30 08:29:58 | 000,390,094 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat

[2011.10.30 08:29:58 | 000,049,198 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat

[2011.10.06 07:27:47 | 000,001,627 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk

[2011.10.03 13:03:15 | 000,000,376 | ---- | M] () -- C:\WINDOWS\ODBC.INI

[2011.09.28 09:06:50 | 000,599,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\crypt32.dll

[1 C:\Documents and Settings\User1\*.tmp files -> C:\Documents and Settings\User1\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011.12.20 10:58:45 | 000,879,668 | ---- | C] () -- C:\Documents and Settings\User1\Desktop\SecurityCheck.exe

[2011.12.20 10:24:39 | 000,294,216 | ---- | C] () -- C:\Documents and Settings\User1\Desktop\gmer.zip

[2011.12.20 10:13:54 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\User1\defogger_reenable

[2011.12.20 10:13:11 | 000,050,477 | ---- | C] () -- C:\Documents and Settings\User1\Desktop\Defogger.exe

[2011.12.19 13:33:20 | 000,001,393 | ---- | C] () -- C:\WINDOWS\imsins.BAK

[2011.12.18 12:05:42 | 000,000,223 | ---- | C] () -- C:\Boot.bak

[2011.12.18 12:05:40 | 000,260,272 | RHS- | C] () -- C:\cmldr

[2011.12.18 12:04:31 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe

[2011.12.18 12:04:31 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe

[2011.12.18 12:04:31 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe

[2011.12.18 12:04:31 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe

[2011.12.18 12:04:31 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe

[2011.12.16 12:53:24 | 000,000,139 | ---- | C] () -- C:\Documents and Settings\User1\Desktop\rk-proxy.reg

[2011.12.16 12:52:19 | 001,008,141 | ---- | C] () -- C:\Documents and Settings\User1\Desktop\iExplore.exe

[2011.12.16 09:24:20 | 000,000,002 | ---- | C] () -- C:\WINDOWS\System32\config.nt

[2011.12.15 18:28:48 | 000,001,688 | ---- | C] () -- C:\WINDOWS\System32\AUTOEXEC.NT

[2011.12.15 16:54:57 | 000,000,064 | ---- | C] () -- C:\WINDOWS\System32\rp_stats.dat

[2011.12.15 16:54:57 | 000,000,044 | ---- | C] () -- C:\WINDOWS\System32\rp_rules.dat

[2011.12.15 16:32:03 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\User1\Desktop\7eplg53x.reg

[2011.12.15 10:21:38 | 000,002,447 | ---- | C] () -- C:\Documents and Settings\User1\Desktop\HiJackThis.lnk

[2011.12.13 09:30:56 | 000,150,192 | ---- | C] () -- C:\Documents and Settings\User1\Desktop\tweakui.exe

[2011.12.13 09:30:23 | 000,109,238 | ---- | C] () -- C:\Documents and Settings\User1\Desktop\cmospwd.zip

[2011.12.13 09:30:20 | 000,162,728 | ---- | C] () -- C:\Documents and Settings\User1\Desktop\startuplist.zip

[2011.12.09 16:16:41 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat

[2011.12.06 10:57:39 | 000,111,872 | ---- | C] () -- C:\WINDOWS\System32\drivers\TrueSight.sys

[2011.11.29 12:35:47 | 000,335,992 | ---- | C] () -- C:\Documents and Settings\User1\Desktop\Dial-a-fix-v0.60.0.24.zip

[2011.11.27 10:40:45 | 000,381,631 | ---- | C] () -- C:\Documents and Settings\User1\Desktop\MiniToolBox.exe

[2011.11.26 13:22:10 | 000,000,624 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk

[2011.11.26 11:59:30 | 001,008,114 | ---- | C] () -- C:\Documents and Settings\User1\Desktop\rkill.scr

[2011.11.26 11:45:59 | 000,684,297 | ---- | C] () -- C:\Documents and Settings\User1\Desktop\unhide.exe

[2011.05.31 17:44:48 | 000,156,007 | ---- | C] () -- C:\WINDOWS\hpwins12.dat

[2011.05.31 17:43:19 | 000,002,066 | ---- | C] () -- C:\WINDOWS\hpdj3740.ini

[2011.05.20 16:50:44 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI

[2011.05.18 19:09:42 | 000,262,144 | ---- | C] () -- C:\WINDOWS\tsnpstd3.exe

[2011.05.18 19:09:41 | 000,831,488 | ---- | C] () -- C:\WINDOWS\vsnpstd3.exe

[2011.05.18 19:09:41 | 000,015,498 | ---- | C] () -- C:\WINDOWS\snpstd3.ini

[2011.05.15 12:35:42 | 000,000,056 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ezsidmv.dat

[2011.05.02 12:33:28 | 000,011,776 | ---- | C] () -- C:\Documents and Settings\User1\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2011.05.02 12:03:48 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI

[2011.05.02 12:02:50 | 000,143,624 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2011.05.02 11:56:25 | 000,165,376 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll

[2011.05.02 11:56:24 | 000,810,496 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll

[2011.05.02 11:56:24 | 000,183,808 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll

[2011.05.02 11:56:24 | 000,080,896 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll

[2011.05.02 11:56:24 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini

[2011.05.02 11:49:56 | 000,049,848 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat

[2011.05.02 11:16:51 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll

[2011.05.02 11:16:51 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe

[2011.05.02 09:16:41 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat

[2011.05.02 09:09:23 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat

[2008.04.14 04:55:28 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin

[2007.10.04 04:27:43 | 000,009,737 | ---- | C] () -- C:\WINDOWS\hpwscr12.dat

[2007.10.04 04:24:48 | 000,000,981 | ---- | C] () -- C:\WINDOWS\hpwmdl12.dat

[2006.12.31 06:57:08 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat

[2006.08.16 09:35:00 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll

[2006.08.16 09:35:00 | 001,617,920 | ---- | C] () -- C:\WINDOWS\System32\nwiz.exe

[2006.08.16 09:35:00 | 001,470,464 | ---- | C] () -- C:\WINDOWS\System32\nview.dll

[2006.08.16 09:35:00 | 001,339,392 | ---- | C] () -- C:\WINDOWS\System32\nvdspsch.exe

[2006.08.16 09:35:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll

[2006.08.16 09:35:00 | 000,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll

[2006.08.16 09:35:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll

[2006.08.16 09:35:00 | 000,442,368 | ---- | C] () -- C:\WINDOWS\System32\nvappbar.exe

[2006.08.16 09:35:00 | 000,425,984 | ---- | C] () -- C:\WINDOWS\System32\keystone.exe

[2006.08.16 09:35:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll

[2006.08.16 09:35:00 | 000,196,608 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll

[2003.01.07 17:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI

[2001.08.23 11:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin

[2001.08.23 11:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat

[2001.08.23 11:00:00 | 000,390,094 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat

[2001.08.23 11:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat

[2001.08.23 11:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat

[2001.08.23 11:00:00 | 000,049,198 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat

[2001.08.23 11:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin

[2001.08.23 11:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat

[2001.08.23 11:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat

[2001.08.23 11:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat

========== LOP Check ==========

[2011.09.09 16:38:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\GHISLER

[2011.12.16 13:43:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software

[2011.12.16 14:00:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BitDefender

[2011.05.02 11:55:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\BSplayer Pro

[2011.05.02 12:19:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\DeepBurner

[2011.05.02 11:39:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\GHISLER

[2011.05.02 11:31:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\OpenOffice.org

[2011.05.02 11:44:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Opera

[2011.12.16 13:32:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\QuickScan

[2011.05.16 12:00:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\uTorrent

[2011.12.18 12:23:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User2\Application Data\Bitdefender

[2011.05.04 08:24:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User2\Application Data\OpenOffice.org

[2011.05.03 11:16:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User2\Application Data\Opera

[2011.11.09 14:01:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User2\Application Data\uTorrent

========== Purity Check ==========

========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >

[2011.12.16 13:47:02 | 000,003,804 | ---- | M] () -- C:\aaw7boot.log

[2011.05.02 09:12:01 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT

[2011.05.02 11:16:01 | 000,000,223 | ---- | M] () -- C:\Boot.bak

[2011.12.18 12:05:42 | 000,000,339 | RHS- | M] () -- C:\boot.ini

[2004.08.03 23:00:00 | 000,260,272 | RHS- | M] () -- C:\cmldr

[2011.12.19 09:17:58 | 000,010,191 | ---- | M] () -- C:\ComboFix.txt

[2011.05.02 09:12:01 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS

[2011.05.02 09:12:01 | 000,000,000 | R-S- | M] () -- C:\IO.SYS

[2011.05.02 09:12:01 | 000,000,000 | R-S- | M] () -- C:\MSDOS.SYS

[2008.04.13 21:13:04 | 000,047,564 | R-S- | M] () -- C:\NTDETECT.COM

[2008.04.13 23:01:44 | 000,250,048 | RHS- | M] () -- C:\ntldr

[2011.12.20 08:58:12 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys

[2011.12.18 14:43:05 | 000,000,359 | ---- | M] () -- C:\rkill.log

[2011.12.18 13:31:10 | 000,049,344 | ---- | M] () -- C:\TDSSKiller.2.6.23.0_18.12.2011_13.29.22_log.txt

< %USERPROFILE%\*.* >

[2011.12.20 10:13:54 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\User1\defogger_reenable

[2011.12.19 13:33:09 | 003,932,160 | ---- | M] () -- C:\Documents and Settings\User1\NTUSER.DAT

[2011.12.20 11:00:42 | 000,001,024 | ---- | M] () -- C:\Documents and Settings\User1\ntuser.dat.LOG

[2011.12.19 13:33:09 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\User1\ntuser.ini

[1 C:\Documents and Settings\User1\*.tmp files -> C:\Documents and Settings\User1\*.tmp -> ]

< %USERPROFILE%\Application Data\*.* >

[2011.05.02 12:03:22 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\User1\Application Data\desktop.ini

< %USERPROFILE%\Local Settings\Application Data\*.* >

[2011.12.09 16:13:58 | 000,011,776 | ---- | M] () -- C:\Documents and Settings\User1\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2011.12.18 11:45:12 | 000,025,128 | ---- | M] () -- C:\Documents and Settings\User1\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

[2011.12.18 15:17:43 | 003,764,036 | -H-- | M] () -- C:\Documents and Settings\User1\Local Settings\Application Data\IconCache.db

< %AllUsersProfile%\*.* >

< %AllUsersProfile%\Application Data\*.* >

[2011.05.02 12:03:22 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\desktop.ini

[2011.05.15 12:35:42 | 000,000,056 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\ezsidmv.dat

[2011.05.31 17:48:45 | 000,001,078 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log

< %USERPROFILE%\My Documents\*.* >

< %CommonProgramFiles%\*.* >

< %PROGRAMFILES%\*.* >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /90 >

[2011.12.15 10:28:39 | 000,101,720 | ---- | M] (Sunbelt Software) -- C:\WINDOWS\system32\drivers\SBREDrv.sys

[2011.12.15 18:08:11 | 000,111,872 | ---- | M] () -- C:\WINDOWS\system32\drivers\TrueSight.sys

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >

[2007.06.27 11:04:44 | 000,274,944 | ---- | M] (Hewlett-Packard Corporation) -- C:\WINDOWS\system32\Spool\prtprocs\w32x86\hpzpp5k2.dll

< MD5 for: EXPLORER.EXE >

[2008.04.14 04:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\ERDNT\cache\explorer.exe

[2008.04.14 04:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe

[2008.04.14 04:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\system32\dllcache\explorer.exe

< MD5 for: USERINIT.EXE >

[2011.12.15 16:55:04 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\ERDNT\cache\userinit.exe

[2008.04.14 04:42:40 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\dllcache\userinit.exe

[2011.12.15 16:55:04 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\userinit.exe

< MD5 for: VOLSNAP.SYS >

[2008.04.13 23:11:02 | 000,052,352 | ---- | M] (Microsoft Corporation) MD5=4C8FCB5CC53AAB716D810740FE59D025 -- C:\WINDOWS\system32\dllcache\volsnap.sys

[2008.04.13 23:11:02 | 000,052,352 | ---- | M] (Microsoft Corporation) MD5=4C8FCB5CC53AAB716D810740FE59D025 -- C:\WINDOWS\system32\drivers\volsnap.sys

< MD5 for: WINLOGON.EXE >

[2008.04.14 04:42:40 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\ERDNT\cache\winlogon.exe

[2008.04.14 04:42:40 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\dllcache\winlogon.exe

[2008.04.14 04:42:40 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\winlogon.exe

< End of report >

Ама така няма да се разберем..!Вие сте се раззходили из раздела и сте използвали фиксове,програми и какво ли не още ..без да съм ви казвал и без да нямате ни най-малко понятие за какво се използват...!

GooredFix

unhide.exe

rkill

MiniToolBox

Dial-a-fix

Defogger.exe

Недей така бе човек...! ;)

Публикувано изображение Стартирайте отново OTL, копирайте (Copy) и поставете (Paste) скриптовия текст от текстовото поле по-долу под колонката Custom Scans/Fixes, като не забравяте да копирате скрипта 1 към 1, както и двете точки преди първия ред на скрипта.

:OTL
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
O4 - Startup: C:\Documents and Settings\User2\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = File not found
C:\Program Files\BitDefender
C:\Documents and Settings\All Users\Application Data\BitDefender
C:\Program Files\Common Files\BitDefender
C:\Program Files\Lavasoft
C:\Documents and Settings\All Users\Application Data\Lavasoft
C:\Documents and Settings\User1\Desktop\7eplg53x.reg
C:\Documents and Settings\All Users\Application Data\AVAST Software

:Reg

:files
C:\Documents and Settings\User1\*.tmp

autorun.inf /alldrives
autorun.exe /alldrives
recycler /alldrives
ipconfig /flushdns /c

:Commands
[purity]
[emptytemp]
[resethosts]
[clearallrestorepoints]
[emptyflash]
[Reboot]

Публикувано изображение След като въведете скрипта от цитата по-горе натиснете бутона, маркиран в червено: Run Fix

Windows ще се рестартира и ще се създаде лог файл. Публикувайте съдържанието му с Copy/Paste в следващия си коментар.

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.