Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Съмнения за вирус

Featured Replies

Здравейте момци, От известно време компа започна да дава ядове, още преди да зареди уиндоуса, премигва и започват проблемите.Трудно влизам в интернет и се товари процесора.Съмнява ме, че е прихванал нещо,дано го излекуваме.Прилагам логовете: . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_29 Run by Vadim Kuzmenko at 11:55:52 on 2012-01-13 Microsoft Windows XP Home Edition 5.1.2600.3.1251.359.1033.18.2815.1909 [GMT 2:00] . AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D} FW: avast! Antivirus *Enabled* . ============== Running Processes =============== . C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe C:\WINDOWS\system32\Ati2evxx.exe svchost.exe C:\Program Files\Alwil Software\Avast5\AvastSvc.exe C:\WINDOWS\Explorer.EXE C:\Program Files\ASUS\ATK Media\DMedia.exe C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe C:\Program Files\ASUS\ATK Hotkey\HControl.exe C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe C:\Program Files\WebMoney Agent\wmagent.exe C:\Program Files\Alwil Software\Avast5\avastUI.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\uTorrent\uTorrent.exe C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Skype\Phone\Skype.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Datecs\FlexType 2K\FType2K.exe C:\Program Files\ASUS\ATK Hotkey\ATKOSD.exe svchost.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\SRS Labs\SRS Premium Sound\SRSPremiumSound_XP.exe C:\WINDOWS\system32\srvany.exe C:\Program Files\ASUS\ATK Hotkey\KBFiltr.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\KMService.exe C:\Program Files\ASUS\ATK Hotkey\WDC.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://webalta.ru uSearch Page = hxxp://webalta.ru/poisk uDefault_Page_URL = hxxp://webalta.ru uDefault_Search_URL = hxxp://webalta.ru/poisk uSearch Bar = hxxp://webalta.ru/poisk mDefault_Page_URL = hxxp://webalta.ru mDefault_Search_URL = hxxp://webalta.ru/poisk mSearch Page = hxxp://webalta.ru/poisk mStart Page = hxxp://webalta.ru mSearch Bar = hxxp://webalta.ru/poisk uInternet Settings,ProxyServer = http=https=ftp=gopher=socks= uInternet Settings,ProxyOverride = <local> uSearchAssistant = hxxp://webalta.ru/poisk mSearchAssistant = hxxp://webalta.ru/poisk uURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTo1.dll uURLSearchHooks: ToolbarURLSearchHook Class: {ca3eb689-8f09-4026-aa10-b9534c691ce0} - c:\program files\webmoney advisor\tbhelper.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\ConduitEngin0.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office14\GROOVEEX.DLL BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\alwil software\avast5\aswWebRepIE.dll BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~2\office14\URLREDIR.DLL BHO: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTo1.dll BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: WebMoneyAdvisorBHO: {e7d2cb77-6e2d-4c1f-b485-d50506b9fa6b} - c:\program files\webmoney advisor\2.2.4\wmadvisor.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: WebMoney Advisor - BHO Helper: {fcbccb87-9224-4b8d-b117-f56d924beb18} - c:\program files\webmoney advisor\tbcore3.dll TB: WebMoney Advisor: {3affd7f7-fd3d-4c9d-8f83-03296a1a8840} - c:\program files\webmoney advisor\tbcore3.dll TB: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTo1.dll TB: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\ConduitEngin0.dll TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\alwil software\avast5\aswWebRepIE.dll TB: WebMoney Advisor: {405dfeae-1d2f-4649-be08-c92313c3e1ce} - c:\program files\webmoney advisor\2.2.4\wmadvisor.dll TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe" uRun: [OfficeSyncProcess] "c:\program files\microsoft office\office14\MSOSYNC.EXE" uRun: [u36VRSFLG6] c:\docume~1\vadimk~1\locals~1\temp\Enr.exe uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun uRun: [VPetsPlayer] c:\program files\vpets\VPets.exe uRun: [skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [ATKMEDIA] c:\program files\asus\atk media\DMedia.exe mRun: [HControlUser] c:\program files\asus\atk hotkey\HControlUser.exe mRun: [ATKHOTKEY] c:\program files\asus\atk hotkey\HControl.exe mRun: [ATKOSD2] c:\program files\asus\atkosd2\ATKOSD2.exe mRun: [startCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun mRun: [HDAudDeck] c:\program files\via\viaudioi\hdadeck\HDeck.exe 1 mRun: [ATICustomerCare] "c:\program files\ati\aticustomercare\ATICustomerCare.exe" mRun: [bCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices mRun: [wmagent.exe] "c:\program files\webmoney agent\wmagent.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [avast] "c:\program files\alwil software\avast5\avastUI.exe" /nogui mRun: [sunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\flexty~1.lnk - c:\program files\datecs\flextype 2k\FType2K.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\srspre~1.lnk - c:\program files\srs labs\srs premium sound\SRSPremiumSound_XP.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~1\micros~2\office14\ONBttnIE.dll/105 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll IE: {3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840} - {3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840} - c:\program files\webmoney advisor\tbcore3.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab TCP: DhcpNameServer = 192.168.1.1 TCP: Interfaces\{354320AA-D1D0-4F26-9306-2D0AD9E265DC} : DhcpNameServer = 192.168.1.1 TCP: Interfaces\{A1470B2C-3654-47D9-B508-1BDC153AEF3A} : NameServer = 95.111.0.193,89.190.192.166 Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Notify: AtiExtEvent - Ati2evxx.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office14\GROOVEEX.DLL . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\vadim kuzmenko\application data\mozilla\firefox\profiles\v0xv99cn.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&q= FF - component: c:\documents and settings\vadim kuzmenko\application data\mozilla\firefox\profiles\v0xv99cn.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCoreGecko19.dll FF - component: c:\documents and settings\vadim kuzmenko\application data\mozilla\firefox\profiles\v0xv99cn.default\extensions\[email protected]\components\RadioWMPCoreGecko19.dll FF - plugin: c:\progra~1\micros~2\office14\NPAUTHZ.DLL FF - plugin: c:\progra~1\micros~2\office14\NPSPWRAP.DLL FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\plugins\npatgpc.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdjvu.dll FF - plugin: c:\program files\opera\program\plugins\nppl3260.dll FF - plugin: c:\program files\opera\program\plugins\nprpjplug.dll . ============= SERVICES / DRIVERS =============== . R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-3-22 435032] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-7-22 314456] R1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\elrawdsk.sys [2011-1-24 29768] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-7-22 20568] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-7-22 44768] R2 KMService;KMService;c:\windows\system32\srvany.exe [2010-10-5 8192] R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\tuneup utilities 2012\TuneUpUtilitiesService32.exe [2011-12-14 1514304] R3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000] R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2009-10-29 1605760] S3 EverestDriver;Lavalys EVEREST Kernel Driver;\??\c:\documents and settings\user\desktop\everest ultimate edition\kerneld.wnt --> c:\documents and settings\user\desktop\everest ultimate edition\kerneld.wnt [?] S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2011-6-12 31125880] S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;\??\c:\program files\tuneup utilities 2011\tuneuputilitiesdriver32.sys --> c:\program files\tuneup utilities 2011\TuneUpUtilitiesDriver32.sys [?] S3 XDva370;XDva370;\??\c:\windows\system32\xdva370.sys --> c:\windows\system32\XDva370.sys [?] S3 XDva380;XDva380;\??\c:\windows\system32\xdva380.sys --> c:\windows\system32\XDva380.sys [?] . =============== Created Last 30 ================ . 2012-01-13 07:11:28 479232 ----a-w- c:\program files\mozilla firefox\msvcm80.dll 2012-01-13 07:11:28 43992 ----a-w- c:\program files\mozilla firefox\mozutils.dll 2012-01-13 07:11:27 626688 ----a-w- c:\program files\mozilla firefox\msvcr80.dll 2012-01-13 07:11:27 548864 ----a-w- c:\program files\mozilla firefox\msvcp80.dll 2012-01-12 14:09:16 31552 ----a-w- c:\windows\system32\TURegOpt.exe 2012-01-12 14:09:02 -------- d-----w- c:\windows\pss 2012-01-12 14:08:53 -------- d-----w- c:\documents and settings\vadim kuzmenko\application data\TuneUp Software 2012-01-12 14:08:30 -------- d-----w- c:\program files\TuneUp Utilities 2012 2012-01-12 14:07:56 -------- d-----w- c:\documents and settings\all users\application data\TuneUp Software 2012-01-12 14:07:37 -------- d-sh--w- c:\documents and settings\all users\application data\{32364CEA-7855-4A3C-B674-53D8E9B97936} 2012-01-12 13:11:01 -------- d-----w- c:\windows\XSxS 2012-01-12 13:11:01 -------- d-----w- c:\program files\Xenocode 2012-01-11 11:06:39 5632 ----a-w- c:\windows\system32\ptpusb.dll 2012-01-11 11:06:38 159232 ----a-w- c:\windows\system32\ptpusd.dll 2012-01-11 11:06:38 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys 2012-01-11 11:06:38 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys 2012-01-11 05:56:28 -------- d-----w- c:\documents and settings\vadim kuzmenko\local settings\application data\My Games 2012-01-09 13:30:07 14592 -c--a-w- c:\windows\system32\dllcache\kbdhid.sys 2012-01-09 13:30:07 14592 ----a-w- c:\windows\system32\drivers\kbdhid.sys 2012-01-08 11:49:03 -------- d-----w- c:\program files\Rome. Total War - Gold Edition 2012-01-02 16:37:11 -------- d-----w- c:\program files\Sid Meiers Civilization V 2011-12-24 21:00:50 -------- d-----w- c:\documents and settings\vadim kuzmenko\application data\WebMoneyAdvisor 2011-12-19 08:12:32 6416 ----a-w- c:\windows\system32\kbdinori.Dll 2011-12-19 08:12:28 6928 ----a-w- c:\windows\system32\kbdhebx.Dll 2011-12-19 08:12:28 6416 ----a-w- c:\windows\system32\kbdinasa.Dll 2011-12-19 08:12:27 8992 ----a-w- c:\windows\system32\kbdbphz.dLL 2011-12-19 08:12:27 8992 ----a-w- c:\windows\system32\KBDBPH.dLL 2011-12-19 08:12:27 7440 ----a-w- c:\windows\system32\Kbddll.dll 2011-12-19 08:12:27 6416 ----a-w- c:\windows\system32\kbdbp.Dll 2011-12-19 08:12:26 6416 ----a-w- c:\windows\system32\kbdbds.Dll 2011-12-19 08:12:22 45056 ----a-w- c:\windows\system32\newdll.dll 2011-12-19 08:12:14 -------- d-----w- c:\program files\Datecs . ==================== Find3M ==================== . 2011-11-28 18:01:25 41184 ----a-w- c:\windows\avastSS.scr 2011-11-28 17:53:53 435032 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2011-11-25 21:57:19 293376 ----a-w- c:\windows\system32\winsrv.dll 2011-11-23 13:25:32 1859584 ----a-w- c:\windows\system32\win32k.sys 2011-11-18 12:35:08 60416 ----a-w- c:\windows\system32\packager.exe 2011-11-14 16:03:23 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-11-04 19:20:51 916992 ----a-w- c:\windows\system32\wininet.dll 2011-11-04 19:20:51 43520 ----a-w- c:\windows\system32\licmgr10.dll 2011-11-04 19:20:51 1469440 ----a-w- c:\windows\system32\inetcpl.cpl 2011-11-04 11:23:59 385024 ----a-w- c:\windows\system32\html.iec 2011-11-03 15:28:36 386048 ----a-w- c:\windows\system32\qdvd.dll 2011-11-03 15:28:36 1292288 ----a-w- c:\windows\system32\quartz.dll 2011-11-01 16:07:10 1288704 ----a-w- c:\windows\system32\ole32.dll 2011-10-28 05:31:48 33280 ----a-w- c:\windows\system32\csrsrv.dll 2011-10-25 13:37:08 2148864 ----a-w- c:\windows\system32\ntoskrnl.exe 2011-10-25 12:52:02 2027008 ----a-w- c:\windows\system32\ntkrnlpa.exe 2011-10-18 11:13:22 186880 ----a-w- c:\windows\system32\encdec.dll . ============= FINISH: 11:57:13,42 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume1 Install Date: 19.7.2010 г. 23:49:18 System Uptime: 13.1.2012 г. 10:13:07 (1 hours ago) . Motherboard: ASUSTeK Computer Inc. | | K51AE Processor: AMD Athlon II Dual-Core M320 | CPU 1 | 2100/200mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 238 GiB total, 87,293 GiB free. D: is CDROM () E: is CDROM () F: is FIXED (NTFS) - 60 GiB total, 15,792 GiB free. G: is CDROM () H: is CDROM () . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP423: 16.10.2011 г. 03:32:26 - System Checkpoint RP424: 17.10.2011 г. 04:32:26 - System Checkpoint RP425: 18.10.2011 г. 04:44:54 - System Checkpoint RP426: 19.10.2011 г. 05:06:27 - System Checkpoint RP427: 20.10.2011 г. 06:09:24 - System Checkpoint RP428: 21.10.2011 г. 06:48:38 - System Checkpoint RP429: 22.10.2011 г. 19:38:05 - System Checkpoint RP430: 24.10.2011 г. 01:34:40 - System Checkpoint RP431: 24.10.2011 г. 21:49:02 - Installed Java 6 Update 29 RP432: 25.10.2011 г. 22:05:08 - System Checkpoint RP433: 27.10.2011 г. 02:13:28 - System Checkpoint RP434: 28.10.2011 г. 02:13:43 - System Checkpoint RP435: 29.10.2011 г. 02:49:54 - System Checkpoint RP436: 31.10.2011 г. 02:31:19 - System Checkpoint RP437: 01.11.2011 г. 22:59:05 - System Checkpoint RP438: 02.11.2011 г. 03:00:24 - Software Distribution Service 3.0 RP439: 03.11.2011 г. 03:09:50 - System Checkpoint RP440: 04.11.2011 г. 04:09:54 - System Checkpoint RP441: 05.11.2011 г. 11:22:05 - System Checkpoint RP442: 06.11.2011 г. 17:04:25 - System Checkpoint RP443: 08.11.2011 г. 00:57:34 - System Checkpoint RP444: 09.11.2011 г. 01:02:24 - System Checkpoint RP445: 09.11.2011 г. 08:31:11 - Software Distribution Service 3.0 RP446: 10.11.2011 г. 16:50:53 - System Checkpoint RP447: 11.11.2011 г. 03:00:17 - Software Distribution Service 3.0 RP448: 12.11.2011 г. 03:44:46 - System Checkpoint RP449: 13.11.2011 г. 04:01:12 - System Checkpoint RP450: 14.11.2011 г. 20:32:23 - System Checkpoint RP451: 15.11.2011 г. 21:30:33 - System Checkpoint RP452: 17.11.2011 г. 01:20:55 - System Checkpoint RP453: 18.11.2011 г. 02:18:40 - System Checkpoint RP454: 19.11.2011 г. 02:33:36 - System Checkpoint RP455: 20.11.2011 г. 15:54:50 - System Checkpoint RP456: 20.11.2011 г. 18:26:39 - Removed Microsoft Visual C++ 2005 Redistributable RP457: 20.11.2011 г. 18:29:18 - Installed Microsoft Visual C++ 2005 Redistributable RP458: 22.11.2011 г. 00:48:57 - System Checkpoint RP459: 23.11.2011 г. 02:15:53 - System Checkpoint RP460: 24.11.2011 г. 03:05:08 - System Checkpoint RP461: 25.11.2011 г. 03:24:38 - System Checkpoint RP462: 26.11.2011 г. 03:50:37 - System Checkpoint RP463: 27.11.2011 г. 03:58:40 - System Checkpoint RP464: 28.11.2011 г. 04:23:29 - System Checkpoint RP465: 29.11.2011 г. 04:26:44 - System Checkpoint RP466: 30.11.2011 г. 05:06:12 - System Checkpoint RP467: 01.12.2011 г. 05:11:18 - System Checkpoint RP468: 02.12.2011 г. 05:31:57 - System Checkpoint RP469: 03.12.2011 г. 08:01:29 - System Checkpoint RP470: 04.12.2011 г. 08:04:01 - System Checkpoint RP471: 05.12.2011 г. 08:12:48 - System Checkpoint RP472: 06.12.2011 г. 08:52:44 - System Checkpoint RP473: 08.12.2011 г. 01:36:53 - System Checkpoint RP474: 09.12.2011 г. 00:29:46 - Removed Delta Trading RP475: 09.12.2011 г. 00:34:28 - Google Земя е премахнат. RP476: 10.12.2011 г. 01:10:28 - System Checkpoint RP477: 12.12.2011 г. 06:45:09 - System Checkpoint RP478: 13.12.2011 г. 07:37:16 - System Checkpoint RP479: 14.12.2011 г. 03:00:25 - Software Distribution Service 3.0 RP480: 15.12.2011 г. 03:31:29 - System Checkpoint RP481: 16.12.2011 г. 04:11:56 - System Checkpoint RP482: 17.12.2011 г. 04:32:37 - System Checkpoint RP483: 18.12.2011 г. 05:32:36 - System Checkpoint RP484: 19.12.2011 г. 12:55:08 - System Checkpoint RP485: 20.12.2011 г. 13:36:34 - System Checkpoint RP486: 21.12.2011 г. 13:40:14 - System Checkpoint RP487: 22.12.2011 г. 18:06:14 - System Checkpoint RP488: 24.12.2011 г. 01:11:06 - System Checkpoint RP489: 25.12.2011 г. 08:01:57 - System Checkpoint RP490: 26.12.2011 г. 08:44:42 - System Checkpoint RP491: 27.12.2011 г. 19:30:49 - System Checkpoint RP492: 29.12.2011 г. 03:06:01 - System Checkpoint RP493: 30.12.2011 г. 04:42:24 - System Checkpoint RP494: 31.12.2011 г. 08:26:55 - System Checkpoint RP495: 31.12.2011 г. 17:29:12 - Installed Windows Media Player Firefox Plugin RP496: 02.1.2012 г. 01:46:57 - System Checkpoint RP497: 02.1.2012 г. 15:57:27 - Installed DirectX RP498: 02.1.2012 г. 16:26:42 - Installed DirectX RP499: 04.1.2012 г. 02:35:46 - System Checkpoint RP500: 05.1.2012 г. 03:46:36 - System Checkpoint RP501: 06.1.2012 г. 04:09:32 - System Checkpoint RP502: 07.1.2012 г. 07:20:16 - System Checkpoint RP503: 08.1.2012 г. 07:49:35 - System Checkpoint RP504: 09.1.2012 г. 03:00:17 - Software Distribution Service 3.0 RP505: 10.1.2012 г. 03:24:46 - System Checkpoint RP506: 11.1.2012 г. 06:06:30 - System Checkpoint RP507: 11.1.2012 г. 09:03:34 - Software Distribution Service 3.0 RP508: 12.1.2012 г. 03:00:30 - Software Distribution Service 3.0 RP509: 12.1.2012 г. 16:08:25 - Installed TuneUp Utilities 2012 . ==== Installed Programs ====================== . П°трёцё№ IV 1.3 Кѕјј°Ѕґѕс 2 Я·ыє Ісї»ыІ°ющёх їѕґсє°·ѕє Microsoft Office 2010 - руссєё№ 25 To Life Online 888casino Acronis Disk Director Server Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 11 Plugin Adobe Reader 9.4.7 - Russian Anno 1404.чѕ»ѕтѕµ ё·ґ°Ѕёµ.v 1.02.2619(2.00.5008) Atheros Client Installation Program Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver ATI Catalyst Control Center ATI Catalyst Install Manager ATI Catalyst Registration ATI Display Driver ATK Hotkey ATK Media ATKOSD2 avast! Free Antivirus BenchMark BG Trader Catalyst Control Center Core Implementation Catalyst Control Center Graphics Full Existing Catalyst Control Center Graphics Full New Catalyst Control Center Graphics Light Catalyst Control Center Localization All ccc-core-preinstall ccc-core-static ccc-utility CCC Help Chinese Standard CCC Help Chinese Traditional CCC Help Czech CCC Help Danish CCC Help Dutch CCC Help English CCC Help Finnish CCC Help French CCC Help German CCC Help Greek CCC Help Hungarian CCC Help Italian CCC Help Japanese CCC Help Korean CCC Help Norwegian CCC Help Polish CCC Help Portuguese CCC Help Russian CCC Help Spanish CCC Help Swedish CCC Help Thai CCC Help Turkish CelebPoker Cisco WebEx Meeting Center for Firefox or Chrome Colin McRae Rally 04 Commando Compatibility Pack for the 2007 Office system Conduit Engine Counter-Strike 1.6 Definition update for Microsoft Office 2010 (KB982726) 32-Bit Edition Disk Checker EAX4 Unified Redist FlexType 2K GOM Player GTA San Andreas Heroes of Might and Magic® IV Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows XP (KB2158563) Hotfix for Windows XP (KB2443685) Hotfix for Windows XP (KB2570791) Hotfix for Windows XP (KB2633952) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB976002-v5) Hotfix for Windows XP (KB981793) Java Auto Updater Java 6 Update 29 K-Lite Mega Codec Pack 6.1.0 KKopy Lizardtech DjVu Control MetaTrader Admiral Markets AS 4.00 Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Games for Windows - LIVE Microsoft Games for Windows - LIVE Redistributable Microsoft Office 2010 Service Pack 1 (SP1) Microsoft Office Access MUI (English) 2010 Microsoft Office Access Setup Metadata MUI (English) 2010 Microsoft Office Excel MUI (English) 2010 Microsoft Office Groove MUI (English) 2010 Microsoft Office InfoPath MUI (English) 2010 Microsoft Office OneNote MUI (English) 2010 Microsoft Office Outlook MUI (English) 2010 Microsoft Office PowerPoint MUI (English) 2010 Microsoft Office Professional Plus 2010 Microsoft Office Proof (English) 2010 Microsoft Office Proof (French) 2010 Microsoft Office Proof (Spanish) 2010 Microsoft Office Proofing (English) 2010 Microsoft Office Publisher MUI (English) 2010 Microsoft Office Shared MUI (English) 2010 Microsoft Office Shared Setup Metadata MUI (English) 2010 Microsoft Office Word MUI (English) 2010 Microsoft Silverlight Microsoft Software Update for Web Folders (English) 14 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Windows Media Video 9 VCM MISCSOFTWARE.COM Product Key Viewer Demo Mozilla Firefox 9.0.1 (x86 bg) MSN MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Need for Speed Most Wanted v1.3 NVIDIA PhysX OpenAL Opera 10.60 Pcsx2 0.9.6 Platform Poker at bet365 PokerStars PunkBuster Services QuickTime Rome. Total War - Alexander Rome. Total War - Gold Edition Rome. Total War - Gold Edition (2004-05-06) S.T.A.L.K.E.R.ТµЅь ЧµрЅѕ±ы»я Eraser Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424) Security Update for Microsoft Office 2010 (KB2553091) Security Update for Microsoft Office 2010 (KB2553096) Security Update for Microsoft Office 2010 (KB2553353) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition Security Update for Microsoft PowerPoint 2010 (KB2553185) 32-Bit Edition Security Update for Microsoft SharePoint Workspace 2010 (KB2566445) Security Update for Microsoft Windows (KB2564958) Security Update for Windows Internet Explorer 8 (KB2183461) Security Update for Windows Internet Explorer 8 (KB2360131) Security Update for Windows Internet Explorer 8 (KB2416400) Security Update for Windows Internet Explorer 8 (KB2482017) Security Update for Windows Internet Explorer 8 (KB2497640) Security Update for Windows Internet Explorer 8 (KB2510531) Security Update for Windows Internet Explorer 8 (KB2530548) Security Update for Windows Internet Explorer 8 (KB2544521) Security Update for Windows Internet Explorer 8 (KB2559049) Security Update for Windows Internet Explorer 8 (KB2586448) Security Update for Windows Internet Explorer 8 (KB2618444) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player (KB979402) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2121546) Security Update for Windows XP (KB2160329) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2259922) Security Update for Windows XP (KB2279986) Security Update for Windows XP (KB2286198) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2296199) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2393802) Security Update for Windows XP (KB2412687) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2436673) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB2476490) Security Update for Windows XP (KB2476687) Security Update for Windows XP (KB2478960) Security Update for Windows XP (KB2478971) Security Update for Windows XP (KB2479628) Security Update for Windows XP (KB2479943) Security Update for Windows XP (KB2481109) Security Update for Windows XP (KB2483185) Security Update for Windows XP (KB2485376) Security Update for Windows XP (KB2485663) Security Update for Windows XP (KB2503658) Security Update for Windows XP (KB2503665) Security Update for Windows XP (KB2506212) Security Update for Windows XP (KB2506223) Security Update for Windows XP (KB2507618) Security Update for Windows XP (KB2507938) Security Update for Windows XP (KB2508272) Security Update for Windows XP (KB2508429) Security Update for Windows XP (KB2509553) Security Update for Windows XP (KB2511455) Security Update for Windows XP (KB2524375) Security Update for Windows XP (KB2535512) Security Update for Windows XP (KB2536276-v2) Security Update for Windows XP (KB2536276) Security Update for Windows XP (KB2544893-v2) Security Update for Windows XP (KB2544893) Security Update for Windows XP (KB2555917) Security Update for Windows XP (KB2562937) Security Update for Windows XP (KB2566454) Security Update for Windows XP (KB2567053) Security Update for Windows XP (KB2567680) Security Update for Windows XP (KB2570222) Security Update for Windows XP (KB2570947) Security Update for Windows XP (KB2584146) Security Update for Windows XP (KB2592799) Security Update for Windows XP (KB2598479) Security Update for Windows XP (KB2603381) Security Update for Windows XP (KB2618451) Security Update for Windows XP (KB2619339) Security Update for Windows XP (KB2620712) Security Update for Windows XP (KB2624667) Security Update for Windows XP (KB2631813) Security Update for Windows XP (KB2633171) Security Update for Windows XP (KB2639417) Security Update for Windows XP (KB2646524) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981349) Security Update for Windows XP (KB981852) Security Update for Windows XP (KB981957) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982214) Security Update for Windows XP (KB982381) Security Update for Windows XP (KB982665) Security Update for Windows XP (KB982802) Sid Meiers Civilization V 1.0.1.275 Skins Skype Toolbars Skype™ 5.3 SRS Premium Sound Control Panel The Lord of the Rings FREE Trial Titan Poker TuneUp Utilities 2012 TuneUp Utilities Language Pack (en-US) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Excel 2010 (KB2553439) 32-Bit Edition Update for Microsoft Office 2010 (KB2553065) Update for Microsoft Office 2010 (KB2553092) Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition Update for Microsoft Office 2010 (KB2553385) 32-Bit Edition Update for Microsoft Office 2010 (KB2553455) 32-Bit Edition Update for Microsoft Office 2010 (KB2566458) Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition Update for Microsoft Outlook 2010 (KB2553323) 32-Bit Edition Update for Microsoft Outlook Social Connector (KB2583935) Update for Windows Internet Explorer 8 (KB976662) Update for Windows XP (KB2141007) Update for Windows XP (KB2345886) Update for Windows XP (KB2467659) Update for Windows XP (KB2541763) Update for Windows XP (KB2616676-v2) Update for Windows XP (KB2641690) Update for Windows XP (KB898461) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971029) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) USB 2.0 UVC 1.3M WebCam uTorrentBar Toolbar VC80CRTRedist - 8.0.50727.4053 VIA ї»ї WebEx WebFldrs XP WebMoney Advisor WebMoney Agent WebMoney Keeper Classic 3.9.5.0 Windows Internet Explorer 8 Windows Media Player Firefox Plugin WinRAR archiver фµЅµ¶Ѕы№ їѕтѕє µTorrent . ==== Event Viewer Messages From Past Week ======== . 13.1.2012 і. 10:16:36, error: Service Control Manager [7000] - The TuneUpUtilitiesDrv service failed to start due to the following error: The system cannot find the path specified. 13.1.2012 і. 10:14:08, error: Dhcp [1002] - The IP address lease 192.168.1.3 for the Network Card with network address 1C4BD68EB9D4 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). 13.1.2012 і. 09:09:49, error: Service Control Manager [7000] - The TuneUpUtilitiesDrv service failed to start due to the following error: The system cannot find the path specified. 12.1.2012 і. 17:45:50, error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume C:. 12.1.2012 і. 16:09:22, error: Service Control Manager [7000] - The TuneUpUtilitiesDrv service failed to start due to the following error: The system cannot find the path specified. 12.1.2012 і. 15:59:23, error: Service Control Manager [7000] - The TuneUpUtilitiesDrv service failed to start due to the following error: The system cannot find the path specified. 12.1.2012 і. 15:11:11, error: Service Control Manager [7000] - The TuneUpUtilitiesDrv service failed to start due to the following error: The system cannot find the path specified. 12.1.2012 і. 09:30:22, error: Dhcp [1002] - The IP address lease 192.168.1.3 for the Network Card with network address 1C4BD68EB9D4 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). 11.1.2012 і. 05:38:53, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 11.1.2012 і. 05:38:53, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) . ==== End Of File ===========================

Здравейте..!:)

Публикувано изображение Изтеглете Malwarebytes' Anti-Malware или от тук

* Кликнете два пъти върху mbam-setup.exe, за да инсталирате програмата.

* Уверете се, че са поставени отметки на Update Malwarebytes' Anti-Malware и Launch Malwarebytes' Anti-Malware. След това кликнете на Finish.

* Ако има намерени обновявания, тя ще ги изтегли и инсталира.

* Стартирайте програмата и изберете "Perform Full Scan", след това кликнете на Scan.

* Сканирането ще отнеме малко време, затова моля да бъдете търпеливи.

* Когато сканирането завърши, кликнете на OK, след това Show Results, за да видите резултата.

* Уверете се, че на всички редове има отметки, и кликнете на Remove Selected.

* Когато всичко бъде премахнато, в Notepad ще бъде отворен лог. Копирайте този лог и го публикувайте в следващия си коментар по темата.

Забележка: Ако MalwareBytes' Anti-Malware се затрудни в премахването на откритите вируси/заплахи, той ще поиска да рестартира компютъра Ви и по време на рестартирането да премахне проблемните вируси/заплахи. Ако бъдете попитани, потвърдете че желаете вашия компютър да бъде рестартиран.

Публикувано изображение Моля, изтеглете aswMBR и го запазете на вашия десктоп.

  • Кликнете с двоен клин на мишката върху файла aswMBR.exe за да го стартирате.
  • Изчакайте да изтегли дефинициите на avast!
  • От падащото меню посочете дял C:\ както е на снимката:
Публикувано изображение
  • Изберете Scan бутона, за да започне проверката.
  • Когато проверката завърши, натиснете бутона save log, запазете съдържанието на лог файла на десктопа и публикувайте съдържанието му в следващия си коментар.
Публикувано изображение Моля, изтеглете последната версия на TDSSKiller - оттук и я запазете на вашия декстоп.
  • Стартирайте TDSSKiller.exe за да стартирате приложението. След това кликнете върху бутона Change parameters.

    Публикувано изображение

  • Сложете отметки пред Verify Driver Digital Signature и Detect TDLFS file system и натиснете ОК.

    Публикувано изображение

  • Натиснете бутона Start Scan.

    Публикувано изображение

  • Ако подозрителен обект бъде засечен, действието по подразбиране ще бъде Skip, кликнете върху Continue.

    Публикувано изображение

  • Ако зловредни обекти бъдат намерени, тогава от падащото меню ще имате три възможности.

    Бъдете сигурни, че избраното действие е Cure и натиснете върху Continue > Рестартирайте за да бъде завършена поправката.

    Публикувано изображение

    Забележка: Ако Cure бутона не е наличен от възможностите, тогава моля изберете Skip бутона, не избирайте Delete освен ако не сте инструктирани затова.

  • Лог файл ще бъде създаден в свободната директория на дял C:\ . Потърсете за лог с името "TDSSKiller.[Version]_[Date]_[Time]_log.txt" и копирайте съдържанието му в следващия си пост.
  • Автор

Malwarebytes Anti-Malware 1.60.0.1800 www.malwarebytes.org Database version: v2012.01.13.02 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Vadim Kuzmenko :: VADIM [administrator] 13.1.2012 г. 13:23:44 mbam-log-2012-01-13 (13-23-44).txt Scan type: Full scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 295519 Time elapsed: 1 hour(s), 37 minute(s), 48 second(s) Memory Processes Detected: 1 C:\WINDOWS\KMService.exe (RiskWare.Tool.CK) -> 3068 -> Delete on reboot. Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 8 HKCR\CLSID\{82184935-B894-4AB2-8590-603BA7D74B71} (Trojan.WebMoner) -> Quarantined and deleted successfully. HKCR\!!!Рекомендуемые форекс брокеры.eProtocol (Trojan.WebMoner) -> Quarantined and deleted successfully. HKCU\SOFTWARE\C8H1KKCTZV (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKCU\SOFTWARE\U36VRSFLG6 (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKCU\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) -> Quarantined and deleted successfully. HKLM\SOFTWARE\StimulProfit (Adware.Agent) -> Quarantined and deleted successfully. Registry Values Detected: 1 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|U36VRSFLG6 (Trojan.FakeAlert) -> Data: C:\DOCUME~1\VADIMK~1\LOCALS~1\Temp\Enr.exe -> Quarantined and deleted successfully. Registry Data Items Detected: 13 HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (Hijack.StartPage) -> Bad: (http://webalta.ru) Good: (http://www.google.com/) -> Quarantined and repaired successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Default_Page_URL (Hijack.StartPage) -> Bad: (http://webalta.ru) Good: (http://www.google.com/) -> Quarantined and repaired successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Default_Search_URL (Hijack.Homepage) -> Bad: (http://webalta.ru/poisk) Good: (http://www.Google.com) -> Quarantined and repaired successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Search Bar (Hijack.Search) -> Bad: (http://webalta.ru/poisk) Good: (http://www.google.com/) -> Quarantined and repaired successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\Search|SearchAssistant (Hijack.SearchPage) -> Bad: (http://webalta.ru/poisk) Good: (http://www.Google.com/) -> Quarantined and repaired successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Default_Page_URL (Hijack.StartPage) -> Bad: (http://webalta.ru) Good: (http://www.google.com/) -> Quarantined and repaired successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Default_Search_URL (Hijack.Homepage) -> Bad: (http://webalta.ru/poisk) Good: (http://www.Google.com) -> Quarantined and repaired successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (Hijack.StartPage) -> Bad: (http://webalta.ru) Good: (http://www.google.com/) -> Quarantined and repaired successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Search Bar (Hijack.Search) -> Bad: (http://webalta.ru/poisk) Good: (http://www.google.com/) -> Quarantined and repaired successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Search|SearchAssistant (Hijack.SearchPage) -> Bad: (http://webalta.ru/poisk) Good: (http://www.Google.com/) -> Quarantined and repaired successfully. HKLM\SOFTWARE\Microsoft\Security Center|AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully. HKLM\SOFTWARE\Microsoft\Security Center|FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully. HKLM\SOFTWARE\Microsoft\Security Center|UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully. Folders Detected: 0 (No malicious items detected) Files Detected: 8 C:\Documents and Settings\Vadim Kuzmenko\My Documents\Downloads\PLAYERTV2012.exe (PUP.SmsPay) -> No action taken. C:\WINDOWS\KMService.exe (RiskWare.Tool.CK) -> Delete on reboot. C:\Documents and Settings\Vadim Kuzmenko\My Documents\Downloads\TuneUp Utilities 2012 v12.0.2160.13\keygen.exe (Malware.Packer) -> Quarantined and deleted successfully. C:\Games\The First Templar (RUS-ENG) [RePack]\Redistributables\DirectX\dsetup.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully. C:\Program Files\Anno 1404.Золотое издание.v 1.02.2619(2.00.5008)\Key\keygen.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully. C:\Program Files\Datecs\FlexType 2K\Remove.exe (Trojan.FakeAlert.SecGen) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{6BB42A48-2823-402C-B554-9590E4E783B5}\RP484\A0106865.exe (Affiliate.Downloader) -> Quarantined and deleted successfully. C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Quarantined and deleted successfully. (end) aswMBR version 0.9.9.1297 Copyright© 2011 AVAST Software Run date: 2012-01-13 15:13:44 ----------------------------- 15:13:44.515 OS Version: Windows 5.1.2600 Service Pack 3 15:13:44.515 Number of processors: 2 586 0x602 15:13:44.515 ComputerName: VADIM UserName: 15:13:45.671 Initialize success 15:13:45.859 AVAST engine defs: 12011300 15:14:10.281 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 15:14:10.281 Disk 0 Vendor: WDC_WD3200BEVT-80A0RT0 01.01A01 Size: 305245MB BusType: 3 15:14:10.281 Disk 0 MBR read successfully 15:14:10.296 Disk 0 MBR scan 15:14:10.296 Disk 0 Windows XP default MBR code 15:14:10.296 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 243508 MB offset 63 15:14:10.296 Disk 0 Partition - 00 05 Extended 61734 MB offset 498705795 15:14:10.328 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 61734 MB offset 498705858 15:14:10.328 Disk 0 scanning sectors +625137345 15:14:10.390 Disk 0 scanning C:\WINDOWS\system32\drivers 15:14:19.968 Service scanning 15:14:20.359 Service sptd C:\WINDOWS\System32\Drivers\sptd.sys **LOCKED** 32 15:14:20.906 Modules scanning 15:14:56.703 Disk 0 trace - called modules: 15:14:56.734 15:14:57.421 AVAST engine scan C:\ 15:17:16.640 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Vadim Kuzmenko\Desktop\MBR.dat" 15:17:16.687 The log file has been saved successfully to "C:\Documents and Settings\Vadim Kuzmenko\Desktop\aswMBR.txt" 15:19:07.0437 3388 TDSS rootkit removing tool 2.7.1.0 Jan 13 2012 15:24:05 15:19:09.0437 3388 ============================================================ 15:19:09.0437 3388 Current date / time: 2012/01/13 15:19:09.0437 15:19:09.0437 3388 SystemInfo: 15:19:09.0437 3388 15:19:09.0437 3388 OS Version: 5.1.2600 ServicePack: 3.0 15:19:09.0437 3388 Product type: Workstation 15:19:09.0437 3388 ComputerName: VADIM 15:19:09.0437 3388 UserName: Vadim Kuzmenko 15:19:09.0437 3388 Windows directory: C:\WINDOWS 15:19:09.0437 3388 System windows directory: C:\WINDOWS 15:19:09.0437 3388 Processor architecture: Intel x86 15:19:09.0437 3388 Number of processors: 2 15:19:09.0437 3388 Page size: 0x1000 15:19:09.0437 3388 Boot type: Normal boot 15:19:09.0437 3388 ============================================================ 15:19:11.0078 3388 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000, SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K', Flags 0x00000054 15:19:11.0234 3388 Initialize success 15:19:27.0140 0672 ============================================================ 15:19:27.0140 0672 Scan started 15:19:27.0140 0672 Mode: Manual; SigCheck; TDLFS; 15:19:27.0140 0672 ============================================================ 15:19:27.0437 0672 Aavmker4 (b6de0336f9f4b687b4ff57939f7b657a) C:\WINDOWS\system32\drivers\Aavmker4.sys 15:19:27.0578 0672 Aavmker4 - ok 15:19:27.0593 0672 Abiosdsk - ok 15:19:27.0593 0672 abp480n5 - ok 15:19:27.0640 0672 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 15:19:27.0875 0672 ACPI - ok 15:19:27.0906 0672 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys 15:19:28.0015 0672 ACPIEC - ok 15:19:28.0015 0672 adpu160m - ok 15:19:28.0062 0672 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 15:19:28.0203 0672 aec - ok 15:19:28.0250 0672 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys 15:19:28.0296 0672 AFD - ok 15:19:28.0296 0672 Aha154x - ok 15:19:28.0312 0672 aic78u2 - ok 15:19:28.0312 0672 aic78xx - ok 15:19:28.0328 0672 AliIde - ok 15:19:28.0343 0672 amsint - ok 15:19:28.0421 0672 AR5416 (e0ee769d14128014965e03b433f5f46e) C:\WINDOWS\system32\DRIVERS\athw.sys 15:19:28.0546 0672 AR5416 - ok 15:19:28.0609 0672 asc - ok 15:19:28.0625 0672 asc3350p - ok 15:19:28.0640 0672 asc3550 - ok 15:19:28.0703 0672 aswFsBlk (054df24c92b55427e0757cfff160e4f2) C:\WINDOWS\system32\drivers\aswFsBlk.sys 15:19:28.0718 0672 aswFsBlk - ok 15:19:28.0750 0672 aswMon2 (ef0e9ad83380724bd6fbbb51d2d0f5b8) C:\WINDOWS\system32\drivers\aswMon2.sys 15:19:28.0765 0672 aswMon2 - ok 15:19:28.0781 0672 aswRdr (352d5a48ebab35a7693b048679304831) C:\WINDOWS\system32\drivers\aswRdr.sys 15:19:28.0781 0672 aswRdr - ok 15:19:28.0812 0672 aswSnx (8d34d2b24297e27d93e847319abfdec4) C:\WINDOWS\system32\drivers\aswSnx.sys 15:19:28.0828 0672 aswSnx - ok 15:19:28.0843 0672 aswSP (010012597333da1f46c3243f33f8409e) C:\WINDOWS\system32\drivers\aswSP.sys 15:19:28.0859 0672 aswSP - ok 15:19:28.0875 0672 aswTdi (f9f84364416658e9786235904d448d37) C:\WINDOWS\system32\drivers\aswTdi.sys 15:19:28.0890 0672 aswTdi - ok 15:19:28.0937 0672 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 15:19:29.0062 0672 AsyncMac - ok 15:19:29.0093 0672 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 15:19:29.0218 0672 atapi - ok 15:19:29.0218 0672 Atdisk - ok 15:19:29.0375 0672 ati2mtag (fb7f57835fb06c0aefbab38262709c1d) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 15:19:29.0640 0672 ati2mtag - ok 15:19:29.0750 0672 AtiHdmiService (eaece4a0d90d6e1fbe068cce9efd73a0) C:\WINDOWS\system32\drivers\AtiHdmi.sys 15:19:29.0765 0672 AtiHdmiService - ok 15:19:29.0812 0672 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 15:19:29.0937 0672 Atmarpc - ok 15:19:29.0968 0672 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 15:19:30.0109 0672 audstub - ok 15:19:30.0156 0672 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 15:19:30.0281 0672 Beep - ok 15:19:30.0343 0672 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 15:19:30.0484 0672 cbidf2k - ok 15:19:30.0531 0672 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 15:19:30.0640 0672 CCDECODE - ok 15:19:30.0656 0672 cd20xrnt - ok 15:19:30.0687 0672 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 15:19:30.0828 0672 Cdaudio - ok 15:19:30.0875 0672 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 15:19:31.0015 0672 Cdfs - ok 15:19:31.0046 0672 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 15:19:31.0203 0672 Cdrom - ok 15:19:31.0203 0672 Changer - ok 15:19:31.0250 0672 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys 15:19:31.0359 0672 CmBatt - ok 15:19:31.0375 0672 CmdIde - ok 15:19:31.0390 0672 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys 15:19:31.0515 0672 Compbatt - ok 15:19:31.0546 0672 Cpqarray - ok 15:19:31.0562 0672 dac2w2k - ok 15:19:31.0562 0672 dac960nt - ok 15:19:31.0609 0672 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 15:19:31.0734 0672 Disk - ok 15:19:31.0781 0672 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 15:19:31.0921 0672 dmboot - ok 15:19:31.0953 0672 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 15:19:32.0078 0672 dmio - ok 15:19:32.0109 0672 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 15:19:32.0234 0672 dmload - ok 15:19:32.0265 0672 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 15:19:32.0390 0672 DMusic - ok 15:19:32.0406 0672 dpti2o - ok 15:19:32.0437 0672 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 15:19:32.0562 0672 drmkaud - ok 15:19:32.0609 0672 dtscsi (6461e57bb51a848aae26f52427b7cf9e) C:\WINDOWS\System32\Drivers\dtscsi.sys 15:19:32.0640 0672 dtscsi - ok 15:19:32.0671 0672 ElRawDisk (9913ea82a935940d5dfec4a04ff54ce4) C:\WINDOWS\system32\drivers\elrawdsk.sys 15:19:32.0687 0672 ElRawDisk - ok 15:19:32.0718 0672 EverestDriver - ok 15:19:32.0765 0672 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 15:19:32.0906 0672 Fastfat - ok 15:19:32.0953 0672 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys 15:19:33.0078 0672 Fdc - ok 15:19:33.0109 0672 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 15:19:33.0250 0672 Fips - ok 15:19:33.0250 0672 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys 15:19:33.0375 0672 Flpydisk - ok 15:19:33.0406 0672 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys 15:19:33.0546 0672 FltMgr - ok 15:19:33.0578 0672 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 15:19:33.0718 0672 Fs_Rec - ok 15:19:33.0765 0672 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 15:19:33.0875 0672 Ftdisk - ok 15:19:33.0906 0672 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 15:19:34.0031 0672 Gpc - ok 15:19:34.0078 0672 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 15:19:34.0203 0672 HDAudBus - ok 15:19:34.0234 0672 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 15:19:34.0375 0672 hidusb - ok 15:19:34.0375 0672 hpn - ok 15:19:34.0453 0672 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 15:19:34.0468 0672 HTTP - ok 15:19:34.0484 0672 i2omgmt - ok 15:19:34.0500 0672 i2omp - ok 15:19:34.0531 0672 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 15:19:34.0671 0672 i8042prt - ok 15:19:34.0703 0672 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 15:19:34.0828 0672 Imapi - ok 15:19:34.0843 0672 ini910u - ok 15:19:34.0859 0672 IntelIde - ok 15:19:34.0890 0672 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 15:19:35.0015 0672 Ip6Fw - ok 15:19:35.0062 0672 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 15:19:35.0203 0672 IpFilterDriver - ok 15:19:35.0203 0672 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 15:19:35.0328 0672 IpInIp - ok 15:19:35.0343 0672 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 15:19:35.0484 0672 IpNat - ok 15:19:35.0546 0672 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 15:19:35.0687 0672 IPSec - ok 15:19:35.0718 0672 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 15:19:35.0781 0672 IRENUM - ok 15:19:35.0828 0672 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 15:19:35.0953 0672 isapnp - ok 15:19:36.0000 0672 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 15:19:36.0125 0672 Kbdclass - ok 15:19:36.0156 0672 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 15:19:36.0281 0672 kbdhid - ok 15:19:36.0296 0672 kbfiltr (7f2b8d0b31fb4a797e5786ef124c5a80) C:\WINDOWS\system32\DRIVERS\kbfiltr.sys 15:19:36.0312 0672 kbfiltr - ok 15:19:36.0343 0672 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 15:19:36.0453 0672 kmixer - ok 15:19:36.0515 0672 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 15:19:36.0562 0672 KSecDD - ok 15:19:36.0593 0672 L1e (101457d884e3dd4636baefb9b7e7d3f3) C:\WINDOWS\system32\DRIVERS\l1e51x86.sys 15:19:36.0625 0672 L1e - ok 15:19:36.0640 0672 lbrtfdc - ok 15:19:36.0718 0672 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 15:19:36.0859 0672 mnmdd - ok 15:19:36.0906 0672 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 15:19:37.0031 0672 Modem - ok 15:19:37.0078 0672 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 15:19:37.0218 0672 Mouclass - ok 15:19:37.0265 0672 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 15:19:37.0406 0672 mouhid - ok 15:19:37.0437 0672 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 15:19:37.0562 0672 MountMgr - ok 15:19:37.0562 0672 mraid35x - ok 15:19:37.0578 0672 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 15:19:37.0937 0672 MRxDAV - ok 15:19:38.0000 0672 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 15:19:38.0015 0672 MRxSmb - ok 15:19:38.0046 0672 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 15:19:38.0187 0672 Msfs - ok 15:19:38.0234 0672 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 15:19:38.0343 0672 MSKSSRV - ok 15:19:38.0375 0672 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 15:19:38.0500 0672 MSPCLOCK - ok 15:19:38.0546 0672 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 15:19:38.0671 0672 MSPQM - ok 15:19:38.0718 0672 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 15:19:38.0828 0672 mssmbios - ok 15:19:38.0859 0672 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys 15:19:38.0984 0672 MSTEE - ok 15:19:39.0031 0672 MTsensor (1c0f480b7c6136ddb5fb909995af014a) C:\WINDOWS\system32\DRIVERS\ATKACPI.sys 15:19:39.0046 0672 MTsensor - ok 15:19:39.0078 0672 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys 15:19:39.0093 0672 Mup - ok 15:19:39.0093 0672 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 15:19:39.0250 0672 NABTSFEC - ok 15:19:39.0296 0672 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 15:19:39.0437 0672 NDIS - ok 15:19:39.0453 0672 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 15:19:39.0562 0672 NdisIP - ok 15:19:39.0593 0672 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 15:19:39.0609 0672 NdisTapi - ok 15:19:39.0625 0672 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 15:19:39.0781 0672 Ndisuio - ok 15:19:39.0796 0672 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 15:19:39.0921 0672 NdisWan - ok 15:19:39.0937 0672 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 15:19:39.0953 0672 NDProxy - ok 15:19:39.0984 0672 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 15:19:40.0093 0672 NetBIOS - ok 15:19:40.0125 0672 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 15:19:40.0250 0672 NetBT - ok 15:19:40.0296 0672 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 15:19:40.0421 0672 Npfs - ok 15:19:40.0453 0672 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 15:19:40.0609 0672 Ntfs - ok 15:19:40.0640 0672 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 15:19:40.0781 0672 Null - ok 15:19:40.0812 0672 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 15:19:40.0953 0672 NwlnkFlt - ok 15:19:40.0984 0672 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 15:19:41.0125 0672 NwlnkFwd - ok 15:19:41.0187 0672 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys 15:19:41.0296 0672 Parport - ok 15:19:41.0328 0672 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 15:19:41.0468 0672 PartMgr - ok 15:19:41.0531 0672 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 15:19:41.0656 0672 ParVdm - ok 15:19:41.0671 0672 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 15:19:41.0812 0672 PCI - ok 15:19:41.0812 0672 PCIDump - ok 15:19:41.0843 0672 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 15:19:41.0984 0672 PCIIde - ok 15:19:42.0031 0672 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 15:19:42.0171 0672 Pcmcia - ok 15:19:42.0171 0672 PDCOMP - ok 15:19:42.0187 0672 PDFRAME - ok 15:19:42.0187 0672 PDRELI - ok 15:19:42.0203 0672 PDRFRAME - ok 15:19:42.0218 0672 perc2 - ok 15:19:42.0218 0672 perc2hib - ok 15:19:42.0296 0672 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 15:19:42.0406 0672 PptpMiniport - ok 15:19:42.0437 0672 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys 15:19:42.0578 0672 Processor - ok 15:19:42.0593 0672 prodrv06 (18d9789a4664bf417eea944d2776091a) C:\WINDOWS\System32\drivers\prodrv06.sys 15:19:42.0625 0672 prodrv06 ( UnsignedFile.Multi.Generic ) - warning 15:19:42.0625 0672 prodrv06 - detected UnsignedFile.Multi.Generic (1) 15:19:42.0656 0672 prohlp02 (8cc9671a7ed2902e747ee0892e1c8575) C:\WINDOWS\system32\drivers\prohlp02.sys 15:19:42.0687 0672 prohlp02 ( UnsignedFile.Multi.Generic ) - warning 15:19:42.0687 0672 prohlp02 - detected UnsignedFile.Multi.Generic (1) 15:19:42.0718 0672 prosync1 (960bce3ed38761b446aabac06c76badf) C:\WINDOWS\system32\drivers\prosync1.sys 15:19:42.0718 0672 prosync1 ( UnsignedFile.Multi.Generic ) - warning 15:19:42.0718 0672 prosync1 - detected UnsignedFile.Multi.Generic (1) 15:19:42.0750 0672 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 15:19:42.0859 0672 PSched - ok 15:19:42.0890 0672 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 15:19:43.0015 0672 Ptilink - ok 15:19:43.0062 0672 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\WINDOWS\system32\Drivers\PxHelp20.sys 15:19:43.0062 0672 PxHelp20 - ok 15:19:43.0078 0672 ql1080 - ok 15:19:43.0078 0672 Ql10wnt - ok 15:19:43.0093 0672 ql12160 - ok 15:19:43.0109 0672 ql1240 - ok 15:19:43.0125 0672 ql1280 - ok 15:19:43.0140 0672 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 15:19:43.0250 0672 RasAcd - ok 15:19:43.0265 0672 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 15:19:43.0406 0672 Rasl2tp - ok 15:19:43.0421 0672 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 15:19:43.0531 0672 RasPppoe - ok 15:19:43.0562 0672 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 15:19:43.0703 0672 Raspti - ok 15:19:43.0734 0672 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 15:19:43.0843 0672 Rdbss - ok 15:19:43.0859 0672 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 15:19:44.0000 0672 RDPCDD - ok 15:19:44.0062 0672 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys 15:19:44.0093 0672 RDPWD - ok 15:19:44.0125 0672 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 15:19:44.0265 0672 redbook - ok 15:19:44.0343 0672 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 15:19:44.0390 0672 Secdrv - ok 15:19:44.0437 0672 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\drivers\Serial.sys 15:19:44.0562 0672 Serial - ok 15:19:44.0609 0672 sfhlp01 (462aee0ea0481ea8bd45cac876a4ccc4) C:\WINDOWS\system32\drivers\sfhlp01.sys 15:19:44.0640 0672 sfhlp01 ( UnsignedFile.Multi.Generic ) - warning 15:19:44.0640 0672 sfhlp01 - detected UnsignedFile.Multi.Generic (1) 15:19:44.0671 0672 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 15:19:44.0812 0672 Sfloppy - ok 15:19:44.0828 0672 Simbad - ok 15:19:44.0875 0672 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys 15:19:44.0984 0672 SLIP - ok 15:19:45.0015 0672 snapman (e78c98378a071ce4d48a7c514fa98fa1) C:\WINDOWS\system32\DRIVERS\snapman.sys 15:19:45.0031 0672 snapman - ok 15:19:45.0093 0672 SNP2UVC (4bda2240f0ba286159773831400e6ead) C:\WINDOWS\system32\DRIVERS\snp2uvc.sys 15:19:45.0250 0672 SNP2UVC - ok 15:19:45.0265 0672 Sparrow - ok 15:19:45.0328 0672 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 15:19:45.0437 0672 splitter - ok 15:19:45.0484 0672 sptd (a199171385be17973fd800fa91f8f78a) C:\WINDOWS\system32\Drivers\sptd.sys 15:19:45.0500 0672 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: a199171385be17973fd800fa91f8f78a 15:19:45.0500 0672 sptd ( LockedFile.Multi.Generic ) - warning 15:19:45.0500 0672 sptd - detected LockedFile.Multi.Generic (1) 15:19:45.0515 0672 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 15:19:45.0578 0672 sr - ok 15:19:45.0609 0672 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 15:19:45.0671 0672 Srv - ok 15:19:45.0718 0672 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 15:19:45.0859 0672 streamip - ok 15:19:45.0890 0672 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 15:19:46.0031 0672 swenum - ok 15:19:46.0062 0672 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 15:19:46.0187 0672 swmidi - ok 15:19:46.0203 0672 symc810 - ok 15:19:46.0218 0672 symc8xx - ok 15:19:46.0218 0672 sym_hi - ok 15:19:46.0234 0672 sym_u3 - ok 15:19:46.0281 0672 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 15:19:46.0390 0672 sysaudio - ok 15:19:46.0437 0672 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 15:19:46.0468 0672 Tcpip - ok 15:19:46.0515 0672 Tcpip6 (4e53bbcc4be37d7a4bd6ef1098c89ff7) C:\WINDOWS\system32\DRIVERS\tcpip6.sys 15:19:46.0546 0672 Tcpip6 - ok 15:19:46.0640 0672 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 15:19:46.0781 0672 TDPIPE - ok 15:19:46.0796 0672 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 15:19:46.0937 0672 TDTCP - ok 15:19:46.0984 0672 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 15:19:47.0125 0672 TermDD - ok 15:19:47.0140 0672 TosIde - ok 15:19:47.0187 0672 TuneUpUtilitiesDrv - ok 15:19:47.0218 0672 tunmp (8f861eda21c05857eb8197300a92501c) C:\WINDOWS\system32\DRIVERS\tunmp.sys 15:19:47.0359 0672 tunmp - ok 15:19:47.0390 0672 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 15:19:47.0546 0672 Udfs - ok 15:19:47.0546 0672 ultra - ok 15:19:47.0609 0672 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 15:19:47.0750 0672 Update - ok 15:19:47.0812 0672 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 15:19:47.0953 0672 usbccgp - ok 15:19:47.0968 0672 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 15:19:48.0093 0672 usbehci - ok 15:19:48.0109 0672 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 15:19:48.0234 0672 usbhub - ok 15:19:48.0250 0672 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys 15:19:48.0375 0672 usbohci - ok 15:19:48.0406 0672 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 15:19:48.0546 0672 usbscan - ok 15:19:48.0593 0672 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 15:19:48.0734 0672 USBSTOR - ok 15:19:48.0781 0672 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys 15:19:48.0906 0672 usbvideo - ok 15:19:48.0953 0672 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 15:19:49.0093 0672 VgaSave - ok 15:19:49.0171 0672 VIAHdAudAddService (8c78f0fc9f88609d15ca6d916454865a) C:\WINDOWS\system32\drivers\viahduaa.sys 15:19:49.0250 0672 VIAHdAudAddService - ok 15:19:49.0250 0672 ViaIde - ok 15:19:49.0296 0672 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 15:19:49.0437 0672 VolSnap - ok 15:19:49.0484 0672 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 15:19:49.0609 0672 Wanarp - ok 15:19:49.0625 0672 WDICA - ok 15:19:49.0656 0672 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 15:19:49.0796 0672 wdmaud - ok 15:19:49.0890 0672 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 15:19:50.0031 0672 WSTCODEC - ok 15:19:50.0046 0672 XDva370 - ok 15:19:50.0062 0672 XDva380 - ok 15:19:50.0109 0672 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0 15:19:50.0484 0672 \Device\Harddisk0\DR0 - ok 15:19:50.0484 0672 Boot (0x1200) (921da61f816bc5336100dfd27ade3152) \Device\Harddisk0\DR0\Partition0 15:19:50.0484 0672 \Device\Harddisk0\DR0\Partition0 - ok 15:19:50.0500 0672 Boot (0x1200) (eaed7dc195d8a07ec60a4d1a8f5b0f71) \Device\Harddisk0\DR0\Partition1 15:19:50.0500 0672 \Device\Harddisk0\DR0\Partition1 - ok 15:19:50.0500 0672 ============================================================ 15:19:50.0500 0672 Scan finished 15:19:50.0500 0672 ============================================================ 15:19:50.0609 2300 Detected object count: 5 15:19:50.0609 2300 Actual detected object count: 5 15:20:09.0484 2300 prodrv06 ( UnsignedFile.Multi.Generic ) - skipped by user 15:20:09.0484 2300 prodrv06 ( UnsignedFile.Multi.Generic ) - User select action: Skip 15:20:09.0484 2300 prohlp02 ( UnsignedFile.Multi.Generic ) - skipped by user 15:20:09.0500 2300 prohlp02 ( UnsignedFile.Multi.Generic ) - User select action: Skip 15:20:09.0500 2300 prosync1 ( UnsignedFile.Multi.Generic ) - skipped by user 15:20:09.0500 2300 prosync1 ( UnsignedFile.Multi.Generic ) - User select action: Skip 15:20:09.0500 2300 sfhlp01 ( UnsignedFile.Multi.Generic ) - skipped by user 15:20:09.0500 2300 sfhlp01 ( UnsignedFile.Multi.Generic ) - User select action: Skip 15:20:09.0500 2300 sptd ( LockedFile.Multi.Generic ) - skipped by user 15:20:09.0500 2300 sptd ( LockedFile.Multi.Generic ) - User select action: Skip 15:20:21.0265 1236 Deinitialize success

До тук добре..!:)

Публикувано изображение Изтеглете ComboFix Публикувано изображение от тук или тук и го запазете на десктопа си.

  • Изключете вашата антивирусна и антишпионска програма, обикновено това става чрез натискане на десния бутон на мишката върху иконата на програма в системния трей.
Бележка: Ако не можете я спрете или не сте сигурни коя програма да изключите, моля прегледайте информацията от този линк: How to Disable your Security Programs
  • Стартирайте Combo-Fix.com Публикувано изображение и следвайте инструкциите.
Бележка: ComboFix ще се стартира без инсталирана Recovery Console.
  • Като част от неговата работа, ComboFix ще провери дали Microsoft Windows Recovery Console е инсталирана. Предвид бързо развиващия се зловреден софтуер е силно препоръчително да бъде инсталирана преди премахването на зловредния софтуер. Това ще Ви позволи да влезете в специален recovery/repair режим, който ще ни позволи по-лесно да решите проблем, който би могъл да възникне при премахване на зловредния софтуер.
  • Следвайте инструкциите, за да позволите на ComboFix да изтегли и инсталира Microsoft Windows Recovery Console. В един момент ще бъдете попитани дали сте съгласни с лицензното споразумение. Необходимо е да потвърдите, че сте съгласни, за да инсталирате Microsoft Windows Recovery Console.
** Забележете: Ако Microsoft Windows Recovery Console е вече инсталирана, ComboFix ще продължи към процеса по премахване на зловредния софтуер.

Публикувано изображение

След като Microsoft Windows Recovery Console е инсталирана, използвайки ComboFix, Вие ще видите следното съобщение:

Публикувано изображение

Изберете Yes, за да продължи сканирането за зловреден софтуер.

Когато процесът приключи успешно, инструментът ще създаде лог файл. Моля, включете съдържанието на C:\ComboFix.txt в следващия Ви коментар в тази тема.

Бележка:

  • Моля, не движете мишката, докато ComboFix работи. Това може да наруши процеса на работа.
  • ComboFix ще нулира всички настройки на Microsoft Internet Explorer, включително да направи IE браузър по подразбиране.
  • ComboFix ще изключи autorun функцията на ВСИЧКИ CD, Floppy и USB устройства, за да помогне при премахването на зловредния софтуер и Ви защити от бъдещи вируси/заплахи, които поразяват чрез autorun. Ако това е проблем за вас - моля, уведомете ме.
  • ComboFix ще изключи вашата интернет връзка. Интернет връзката ще се възстанови автоматично, преди ComboFix да завърши процеса на работа. При проблем, той ще прекрати интернет връзката. За да възстановите интернет връзката си, рестартирайте компютъра си.
  • В случай на проблем с ComboFix, той може да създаде лог файл. Моля, включете съдържанието на C:\BUG.txt в следващия Ви коментар в тази тема.
Публикувано изображение Моля, не прикачвайте лог файла/овете от програмата, а го/ги копирайте и поставете в следващия Ви коментар в тази тема.
  • Автор

ComboFix 12-01-13.03 - Vadim Kuzmenko 01.2012 г. 17:36:11.1.2 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1251.359.1033.18.2815.1887 [GMT 2:00] Running from: c:\documents and settings\Vadim Kuzmenko\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D} FW: avast! Antivirus *Enabled* {7591DB91-41F0-48A3-B128-1A293FD8233D} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\documents and settings\All Users\Application Data\TEMP c:\documents and settings\All Users\Application Data\Toolbar4 c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\16x16x32b.bmp c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\anim.gif c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\basis.xml c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\booble.html c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\favicon.ico c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\favicon.png c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\include_files\0182d928cdd654232788308747456c28 c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\include_files\04931d1d8094abdf22e911178f68b2c3 c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\include_files\09ff8819ee18322a0dd551c6c5191382 c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\include_files\1bd7401e3453299ebf2e61053d321f1a c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\include_files\1cf0150821fbc5812afcf6de93c5f387 c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\include_files\1fbf73fda10b88c2c5c4b442dcb05680 c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\include_files\4ce8fc6fead20a18d89579d48e7572fd c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\include_files\5c8243879a35ec1d4f1b7a04da008b32 c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\include_files\6637e75637690d3c3206fb16b38d2316 c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\include_files\71689e4a373f1c95fa702cbcb2a28c01 c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\include_files\7a12cba3357dae294226c73afd415e05 c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\include_files\7b947f6cb6134f98ef5430b8ee7c8dd1 c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\include_files\82a6ce3b45816b8842e4fa8f8368f48b c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\include_files\97ca33889c244fe6a3f748902001c1ca c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\include_files\9874572a042d462e2c4cb24c31cc18ca c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\include_files\992c1160462b41bbadf036ffde620766 c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\include_files\9e4b5c22ff3257054623679a85878571 c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\include_files\b6deb0f56680237bdee7acaec28e3aab c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\include_files\c4f8f24a11e49e68d3506365583592a5 c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\include_files\c5baa10d483516b1f5960d91ab596489 c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\include_files\c5ff89ef1501232a3e9db1fb9731b93a c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\include_files\d4cfcebe1749cd9c5ff8dc22f6bf4822 c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\include_files\ddab31deab20bbcaebd9747df6e9fe46 c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\include_files\ec3186001ce4c770e3862b46f38da1c4 c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\include_files\fbb14f9936a6476cd60b399071c8ab3e c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\info.txt c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\SecurityHelper.exe c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\tbs_include_script_statusbar.js c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\tbs_include_script_wmadvisor.js c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\uninstall.exe c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\update.exe c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\version.txt c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\wmadvisor.crc c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\wmadvisor.xpi c:\documents and settings\All Users\Application Data\Toolbar4\{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}\WMStatusbarSync.exe c:\documents and settings\Vadim Kuzmenko\Application Data\Mozilla\Firefox\Profiles\v0xv99cn.default\searchplugins\webalta-search.xml c:\documents and settings\Vadim Kuzmenko\Application Data\PriceGong c:\documents and settings\Vadim Kuzmenko\Application Data\PriceGong\Data\1.xml c:\documents and settings\Vadim Kuzmenko\Application Data\PriceGong\Data\a.xml c:\documents and settings\Vadim Kuzmenko\Application Data\PriceGong\Data\b.xml c:\documents and settings\Vadim Kuzmenko\Application Data\PriceGong\Data\c.xml c:\documents and settings\Vadim Kuzmenko\Application Data\PriceGong\Data\d.xml c:\documents and settings\Vadim Kuzmenko\Application Data\PriceGong\Data\e.xml c:\documents and settings\Vadim Kuzmenko\Application Data\PriceGong\Data\f.xml c:\documents and settings\Vadim Kuzmenko\Application Data\PriceGong\Data\g.xml c:\documents and settings\Vadim Kuzmenko\Application Data\PriceGong\Data\h.xml c:\documents and settings\Vadim Kuzmenko\Application Data\PriceGong\Data\i.xml c:\documents and settings\Vadim Kuzmenko\Application Data\PriceGong\Data\J.xml c:\documents and settings\Vadim Kuzmenko\Application Data\PriceGong\Data\k.xml c:\documents and settings\Vadim Kuzmenko\Application Data\PriceGong\Data\l.xml c:\documents and settings\Vadim Kuzmenko\Application Data\PriceGong\Data\m.xml c:\documents and settings\Vadim Kuzmenko\Application Data\PriceGong\Data\mru.xml c:\documents and settings\Vadim Kuzmenko\Application Data\PriceGong\Data\n.xml c:\documents and settings\Vadim Kuzmenko\Application Data\PriceGong\Data\o.xml c:\documents and settings\Vadim Kuzmenko\Application Data\PriceGong\Data\p.xml c:\documents and settings\Vadim Kuzmenko\Application Data\PriceGong\Data\q.xml c:\documents and settings\Vadim Kuzmenko\Application Data\PriceGong\Data\r.xml c:\documents and settings\Vadim Kuzmenko\Application Data\PriceGong\Data\s.xml c:\documents and settings\Vadim Kuzmenko\Application Data\PriceGong\Data\t.xml c:\documents and settings\Vadim Kuzmenko\Application Data\PriceGong\Data\u.xml c:\documents and settings\Vadim Kuzmenko\Application Data\PriceGong\Data\v.xml c:\documents and settings\Vadim Kuzmenko\Application Data\PriceGong\Data\w.xml c:\documents and settings\Vadim Kuzmenko\Application Data\PriceGong\Data\x.xml c:\documents and settings\Vadim Kuzmenko\Application Data\PriceGong\Data\y.xml c:\documents and settings\Vadim Kuzmenko\Application Data\PriceGong\Data\z.xml c:\documents and settings\Vadim Kuzmenko\WINDOWS c:\windows\system\MSVBVM60.DLL c:\windows\system32\tmp2BB.tmp c:\windows\system32\tmp2BC.tmp c:\windows\XSxS . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Legacy_SSHNAS . . ((((((((((((((((((((((((( Files Created from 2011-12-13 to 2012-01-13 ))))))))))))))))))))))))))))))) . . 2012-01-13 14:14 . 2012-01-13 14:30 -------- d-----w- c:\documents and settings\Vadim Kuzmenko\Local Settings\Application Data\NPE 2012-01-13 14:14 . 2012-01-13 14:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton 2012-01-13 13:53 . 2012-01-13 13:53 23624 ----a-w- c:\windows\system32\drivers\hitmanpro36.sys 2012-01-13 13:52 . 2012-01-13 13:52 -------- d-----w- c:\program files\HitmanPro 2012-01-13 13:52 . 2012-01-13 13:53 -------- d-----w- c:\documents and settings\All Users\Application Data\HitmanPro 2012-01-13 11:21 . 2012-01-13 11:21 -------- d-----w- c:\documents and settings\Vadim Kuzmenko\Application Data\Malwarebytes 2012-01-13 11:21 . 2012-01-13 11:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2012-01-13 11:21 . 2012-01-13 11:22 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2012-01-13 11:21 . 2011-12-10 13:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys 2012-01-13 10:06 . 2010-08-19 17:22 409600 ----a-w- c:\program files\Mozilla Firefox\Kaspersky Rescue2Usb\rescue2usb.exe 2012-01-13 10:06 . 2010-04-01 09:01 28160 ----a-w- c:\program files\Mozilla Firefox\Kaspersky Rescue2Usb\syslinux.exe 2012-01-13 10:06 . 2009-10-16 14:43 237849 ----a-w- c:\program files\Mozilla Firefox\Kaspersky Rescue2Usb\grub.exe 2012-01-13 07:20 . 2012-01-13 07:20 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache 2012-01-13 07:11 . 2012-01-13 07:11 479232 ----a-w- c:\program files\Mozilla Firefox\msvcm80.dll 2012-01-13 07:11 . 2012-01-13 07:11 43992 ----a-w- c:\program files\Mozilla Firefox\mozutils.dll 2012-01-13 07:11 . 2012-01-13 07:11 626688 ----a-w- c:\program files\Mozilla Firefox\msvcr80.dll 2012-01-13 07:11 . 2012-01-13 07:11 548864 ----a-w- c:\program files\Mozilla Firefox\msvcp80.dll 2012-01-12 14:12 . 2012-01-12 14:12 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache 2012-01-12 14:09 . 2011-12-14 10:47 31552 ----a-w- c:\windows\system32\TURegOpt.exe 2012-01-12 14:08 . 2012-01-12 14:08 -------- d-----w- c:\documents and settings\Vadim Kuzmenko\Application Data\TuneUp Software 2012-01-12 14:08 . 2012-01-12 14:10 -------- d-----w- c:\program files\TuneUp Utilities 2012 2012-01-12 14:07 . 2012-01-12 14:09 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software 2012-01-12 14:07 . 2012-01-12 14:07 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{32364CEA-7855-4A3C-B674-53D8E9B97936} 2012-01-12 13:11 . 2012-01-12 13:11 -------- d-----w- c:\program files\Xenocode 2012-01-11 11:06 . 2001-08-17 20:36 5632 ----a-w- c:\windows\system32\ptpusb.dll 2012-01-11 11:06 . 2008-04-14 03:42 159232 ----a-w- c:\windows\system32\ptpusd.dll 2012-01-11 11:06 . 2008-04-13 22:15 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys 2012-01-11 11:06 . 2008-04-13 22:15 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys 2012-01-11 05:56 . 2012-01-11 05:56 -------- d-----w- c:\documents and settings\Vadim Kuzmenko\Local Settings\Application Data\My Games 2012-01-09 13:30 . 2008-04-13 22:09 14592 -c--a-w- c:\windows\system32\dllcache\kbdhid.sys 2012-01-09 13:30 . 2008-04-13 22:09 14592 ----a-w- c:\windows\system32\drivers\kbdhid.sys 2012-01-02 16:37 . 2012-01-11 05:56 -------- d-----w- c:\program files\Sid Meiers Civilization V 2011-12-24 21:00 . 2011-12-24 21:00 -------- d-----w- c:\documents and settings\Vadim Kuzmenko\Application Data\WebMoneyAdvisor 2011-12-19 08:12 . 1999-11-11 11:47 6416 ----a-w- c:\windows\system32\kbdinori.Dll 2011-12-19 08:12 . 1999-11-11 11:47 6416 ----a-w- c:\windows\system32\kbdinasa.Dll 2011-12-19 08:12 . 1999-11-11 11:47 6928 ----a-w- c:\windows\system32\kbdhebx.Dll 2011-12-19 08:12 . 2000-11-17 06:47 8992 ----a-w- c:\windows\system32\kbdbphz.dLL 2011-12-19 08:12 . 1999-12-07 07:00 6416 ----a-w- c:\windows\system32\kbdbp.Dll 2011-12-19 08:12 . 1999-11-18 03:04 7440 ----a-w- c:\windows\system32\Kbddll.dll 2011-12-19 08:12 . 1997-04-03 19:00 8992 ----a-w- c:\windows\system32\KBDBPH.dLL 2011-12-19 08:12 . 2000-11-14 23:52 6416 ----a-w- c:\windows\system32\kbdbds.Dll 2011-12-19 08:12 . 2002-04-22 22:17 45056 ----a-w- c:\windows\system32\newdll.dll 2011-12-19 08:12 . 2011-12-19 08:12 -------- d-----w- c:\program files\Datecs . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-11-28 18:01 . 2010-07-22 10:23 41184 ----a-w- c:\windows\avastSS.scr 2011-11-28 18:01 . 2010-07-22 10:23 199816 ----a-w- c:\windows\system32\aswBoot.exe 2011-11-28 17:53 . 2011-03-22 21:08 435032 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2011-11-28 17:53 . 2010-07-22 10:23 314456 ----a-w- c:\windows\system32\drivers\aswSP.sys 2011-11-28 17:52 . 2010-07-22 10:23 34392 ----a-w- c:\windows\system32\drivers\aswRdr.sys 2011-11-28 17:52 . 2010-07-22 10:23 52952 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2011-11-28 17:52 . 2010-07-22 10:23 111320 ----a-w- c:\windows\system32\drivers\aswmon2.sys 2011-11-28 17:51 . 2010-07-22 10:23 105176 ----a-w- c:\windows\system32\drivers\aswmon.sys 2011-11-28 17:51 . 2010-07-22 10:23 20568 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2011-11-28 17:48 . 2010-07-22 10:23 30808 ----a-w- c:\windows\system32\drivers\aavmker4.sys 2011-11-25 21:57 . 2008-04-14 12:00 293376 ----a-w- c:\windows\system32\winsrv.dll 2011-11-23 13:25 . 2008-04-14 12:00 1859584 ----a-w- c:\windows\system32\win32k.sys 2011-11-18 12:35 . 2008-04-14 12:00 60416 ----a-w- c:\windows\system32\packager.exe 2011-11-14 16:03 . 2011-05-27 10:48 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-11-04 19:20 . 2008-04-14 12:00 916992 ----a-w- c:\windows\system32\wininet.dll 2011-11-04 19:20 . 2008-04-14 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll 2011-11-04 19:20 . 2008-04-14 12:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl 2011-11-04 11:23 . 2008-04-14 12:00 385024 ----a-w- c:\windows\system32\html.iec 2011-11-03 15:28 . 2008-04-14 12:00 386048 ----a-w- c:\windows\system32\qdvd.dll 2011-11-03 15:28 . 2008-04-14 12:00 1292288 ----a-w- c:\windows\system32\quartz.dll 2011-11-01 16:07 . 2008-04-14 12:00 1288704 ----a-w- c:\windows\system32\ole32.dll 2011-10-28 05:31 . 2008-04-14 12:00 33280 ----a-w- c:\windows\system32\csrsrv.dll 2011-10-25 13:37 . 2008-04-14 12:00 2148864 ----a-w- c:\windows\system32\ntoskrnl.exe 2011-10-25 12:52 . 2008-04-14 00:01 2027008 ----a-w- c:\windows\system32\ntkrnlpa.exe 2011-10-18 11:13 . 2008-04-14 12:00 186880 ----a-w- c:\windows\system32\encdec.dll 2010-02-25 10:11 . 2010-02-25 10:11 28472 ----a-w- c:\program files\mozilla firefox\plugins\atgpcdec.dll 2010-02-25 10:11 . 2010-02-25 10:11 185224 ----a-w- c:\program files\mozilla firefox\plugins\atgpcext.dll 2010-02-25 10:13 . 2010-02-25 10:13 46392 ----a-w- c:\program files\mozilla firefox\plugins\atmccli.dll 2010-02-25 10:11 . 2010-02-25 10:11 99208 ----a-w- c:\program files\mozilla firefox\plugins\ieatgpc.dll 2012-01-13 07:11 . 2011-05-07 18:08 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files\uTorrentBar\tbuTo1.dll" [2010-12-25 3911776] . [HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}] . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}] 2010-12-25 10:27 3911776 ----a-w- c:\program files\ConduitEngine\ConduitEngin0.dll . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}] 2010-12-25 10:27 3911776 ----a-w- c:\program files\uTorrentBar\tbuTo1.dll . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E7D2CB77-6E2D-4C1F-B485-D50506B9FA6B}] 2011-07-20 16:27 288224 ----a-w- c:\program files\WebMoney Advisor\2.2.4\wmadvisor.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}"= "c:\program files\WebMoney Advisor\tbcore3.dll" [2010-02-24 2559608] "{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files\uTorrentBar\tbuTo1.dll" [2010-12-25 3911776] "{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngin0.dll" [2010-12-25 3911776] "{405DFEAE-1D2F-4649-BE08-C92313C3E1CE}"= "c:\program files\WebMoney Advisor\2.2.4\wmadvisor.dll" [2011-07-20 288224] . [HKEY_CLASSES_ROOT\clsid\{3affd7f7-fd3d-4c9d-8f83-03296a1a8840}] [HKEY_CLASSES_ROOT\TBSB03374.TBSB03374.3] [HKEY_CLASSES_ROOT\TypeLib\{77AA25E8-6083-4949-A831-9CB11861DC10}] [HKEY_CLASSES_ROOT\TBSB03374.TBSB03374] . [HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}] . [HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}] . [HKEY_CLASSES_ROOT\clsid\{405dfeae-1d2f-4649-be08-c92313c3e1ce}] [HKEY_CLASSES_ROOT\TypeLib\{3B9F4DFC-44AF-45E0-A38D-0D35F70BB2B0}] . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}"= "c:\program files\WebMoney Advisor\tbcore3.dll" [2010-02-24 2559608] "{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}"= "c:\program files\uTorrentBar\tbuTo1.dll" [2010-12-25 3911776] "{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngin0.dll" [2010-12-25 3911776] "{405DFEAE-1D2F-4649-BE08-C92313C3E1CE}"= "c:\program files\WebMoney Advisor\2.2.4\wmadvisor.dll" [2011-07-20 288224] . [HKEY_CLASSES_ROOT\clsid\{3affd7f7-fd3d-4c9d-8f83-03296a1a8840}] [HKEY_CLASSES_ROOT\TBSB03374.TBSB03374.3] [HKEY_CLASSES_ROOT\TypeLib\{77AA25E8-6083-4949-A831-9CB11861DC10}] [HKEY_CLASSES_ROOT\TBSB03374.TBSB03374] . [HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}] . [HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}] . [HKEY_CLASSES_ROOT\clsid\{405dfeae-1d2f-4649-be08-c92313c3e1ce}] [HKEY_CLASSES_ROOT\TypeLib\{3B9F4DFC-44AF-45E0-A38D-0D35F70BB2B0}] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2011-11-28 18:01 122512 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2011-03-30 399736] "OfficeSyncProcess"="c:\program files\Microsoft Office\Office14\MSOSYNC.EXE" [2011-07-21 718720] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-06-15 15141768] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ATKMEDIA"="c:\program files\ASUS\ATK Media\DMedia.exe" [2009-08-19 170624] "HControlUser"="c:\program files\ASUS\ATK Hotkey\HControlUser.exe" [2009-06-19 105016] "ATKHOTKEY"="c:\program files\ASUS\ATK Hotkey\HControl.exe" [2009-10-26 174720] "ATKOSD2"="c:\program files\ASUS\ATKOSD2\ATKOSD2.exe" [2009-10-26 6998656] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-10-06 98304] "HDAudDeck"="c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe" [2009-11-17 33697792] "ATICustomerCare"="c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-03-04 311296] "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "wmagent.exe"="c:\program files\WebMoney Agent\wmagent.exe" [2009-10-19 210400] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712] "avast"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2011-11-28 3744552] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] . c:\documents and settings\All Users\Start Menu\Programs\Startup\ FlexType 2K.lnk - c:\program files\Datecs\FlexType 2K\FType2K.exe [2011-12-19 95232] SRS Premium Sound.lnk - c:\program files\SRS Labs\SRS Premium Sound\SRSPremiumSound_XP.exe [2009-10-28 3372336] . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk /r \??\c:\0autocheck autochk /r \??\C:\0autocheck autochk * . [HKLM\~\startupfolder\C:^Documents and Settings^Vadim Kuzmenko^Start Menu^Programs^Startup^Microsoft SharePoint Workspace.lnk] path=c:\documents and settings\Vadim Kuzmenko\Start Menu\Programs\Startup\Microsoft SharePoint Workspace.lnk backup=c:\windows\pss\Microsoft SharePoint Workspace.lnkStartup . [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\WINDOWS\\system32\\usmt\\migwiz.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"= "c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"= "c:\\Program Files\\WebMoney\\WebMoney.exe"= "c:\\WINDOWS\\system32\\PnkBstrA.exe"= "c:\\WINDOWS\\system32\\PnkBstrB.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= "c:\\Program Files\\Anno 1404.Золотое издание.v 1.02.2619(2.00.5008)\\tools\\Anno4Web.exe"= . R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [28.12.2010 і. 14:56 436792] R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [22.3.2011 і. 23:08 435032] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [22.7.2010 і. 12:23 314456] R1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\elrawdsk.sys [24.1.2011 і. 22:44 29768] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [22.7.2010 і. 12:23 20568] R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe [14.12.2011 і. 12:47 1514304] R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [29.10.2009 і. 15:11 1605760] S2 KMService;KMService;c:\windows\system32\srvany.exe [05.10.2010 і. 20:57 8192] S3 EverestDriver;Lavalys EVEREST Kernel Driver;\??\c:\documents and settings\user\Desktop\EVEREST Ultimate Edition\kerneld.wnt --> c:\documents and settings\user\Desktop\EVEREST Ultimate Edition\kerneld.wnt [?] S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [12.6.2011 і. 10:15 31125880] S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [09.1.2010 і. 20:37 4640000] S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;\??\c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys --> c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [?] S3 XDva370;XDva370;\??\c:\windows\system32\XDva370.sys --> c:\windows\system32\XDva370.sys [?] S3 XDva380;XDva380;\??\c:\windows\system32\XDva380.sys --> c:\windows\system32\XDva380.sys [?] . --- Other Services/Drivers In Memory --- . *NewlyCreated* - WS2IFSL . Contents of the 'Scheduled Tasks' folder . 2012-01-13 c:\windows\Tasks\User_Feed_Synchronization-{258042C4-A5B2-4E6A-BA47-D341300B5C63}.job - c:\windows\system32\msfeedssync.exe [2009-03-08 01:31] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com/ uDefault_Search_URL = hxxp://www.Google.com mStart Page = hxxp://www.google.com/ mSearch Bar = hxxp://www.google.com/ uSearchAssistant = hxxp://www.Google.com/ IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105 IE: {{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840} - {3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840} - c:\program files\WebMoney Advisor\tbcore3.dll TCP: DhcpNameServer = 192.168.1.1 TCP: Interfaces\{A1470B2C-3654-47D9-B508-1BDC153AEF3A}: NameServer = 95.111.0.193,89.190.192.166 FF - ProfilePath - c:\documents and settings\Vadim Kuzmenko\Application Data\Mozilla\Firefox\Profiles\v0xv99cn.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&q= FF - prefs.js: network.proxy.type - 0 . - - - - ORPHANS REMOVED - - - - . WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) HKCU-Run-VPetsPlayer - c:\program files\VPets\VPets.exe HKLM-Run-QuickTime Task - c:\program files\QuickTime\qttask.exe MSConfigStartUp-RegistryBooster - c:\program files\Uniblue\RegistryBooster\launcher.exe AddRemove-888casino - c:\progra~1\CASINO~1\UNWISE.EXE AddRemove-bet365poker - c:\poker\Poker at bet365\_SetupPoker_68e0.exe AddRemove-CelebPoker - c:\poker\CelebPoker\_SetupPoker_ac668b.exe AddRemove-ComandoDeinstKey - c:\program files\Eidos Interactive\Pyro\Commandos\DeIsL1.isu AddRemove-Disk Checker - c:\program files\Disk Checker\uninstall.exe AddRemove-Rome. Total War - Gold Edition_is1 - c:\program files\Rome. Total War - Gold Edition\Uninstall\unins000.exe AddRemove-Titan Poker - c:\poker\Titan Poker\_TitanPSetup_5c8b35.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2012-01-13 17:59 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . HKLM\Software\Microsoft\Windows\CurrentVersion\Run HDAudDeck = c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe 1???????????????????????????????????????????????? HKCU\Software\Microsoft\Windows\CurrentVersion\Run VPetsPlayer = c:\program files\VPets\VPets.exe?????????????????????<4Kp????????????????????????????????????=4K????H???????????????????????????????`P?q????p????????????????????????????????????????????????????????????????????????@?q????????????????????????????????????d@?q8?? . scanning hidden files ... . . C:\## aswSnx private storage . scan completed successfully hidden files: 1 . ************************************************************************** . [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EverestDriver] "ImagePath"="\??\c:\documents and settings\user\Desktop\EVEREST Ultimate Edition\kerneld.wnt" . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_USERS\S-1-5-21-2619899986-1885740954-1578026109-1006\Software\Microsoft\SystemCertificates\AddressBook*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) . [HKEY_USERS\S-1-5-21-2619899986-1885740954-1578026109-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\1*!] "Order"=hex:08,00,00,00,02,00,00,00,80,00,00,00,01,00,00,00,01,00,00,00,74,00, 00,00,00,00,00,00,66,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,54,00,31,\ . [HKEY_USERS\S-1-5-21-2619899986-1885740954-1578026109-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\1*!\Patrician 4] "Order"=hex:08,00,00,00,02,00,00,00,0c,01,00,00,01,00,00,00,02,00,00,00,80,00, 00,00,00,00,00,00,72,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,60,00,32,\ . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'winlogon.exe'(996) c:\windows\system32\Ati2evxx.dll . - - - - - - - > 'explorer.exe'(3732) c:\windows\system32\WININET.dll c:\windows\system32\newdll.dll c:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf c:\progra~1\MICROS~2\Office14\1033\GrooveIntlResource.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\Ati2evxx.exe c:\windows\system32\Ati2evxx.exe c:\program files\Alwil Software\Avast5\AvastSvc.exe c:\program files\Java\jre6\bin\jqs.exe c:\windows\system32\PnkBstrA.exe c:\windows\system32\wscntfy.exe c:\program files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe c:\program files\ASUS\ATK Hotkey\ATKOSD.exe c:\program files\ASUS\ATK Hotkey\KBFiltr.exe c:\program files\ASUS\ATK Hotkey\WDC.exe c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe . ************************************************************************** . Completion time: 2012-01-13 18:06:21 - machine was rebooted ComboFix-quarantined-files.txt 2012-01-13 16:06 . Pre-Run: 98 011 688 960 bytes free Post-Run: 98 492 821 504 bytes free . WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons UnsupportedDebug="do not select this" /debug multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect . - - End Of File - - 629F1651FF287C495F76D9D16ACDB97E Ще го бъде ли?

Копирайте текста в карето на notepad и го запазвате с име CFScript.txt на десктопа си:

KILLALL::

ClearJavaCache::

File::
c:\windows\system32\msfeedssync.exe

AtJob::

DDS::
TB: {D4027C7F-154A-4066-A1AD-4243D8127440}


RegNull::
[HKEY_USERS\S-1-5-21-2619899986-1885740954-1578026109-1006\Software\Microsoft\SystemCertificates\AddressBook*]
[HKEY_USERS\S-1-5-21-2619899986-1885740954-1578026109-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\1*!]
[HKEY_USERS\S-1-5-21-2619899986-1885740954-1578026109-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\1*!\Patrician 4]


След съхранението преместете CFScript.txt на иконата на ComboFix.exe

Публикувано изображение

Генерирания рапорт прикачете в следващия си пост..!

  • Автор

Ице, за сега нищо в положителна посока,прилагам лога: ComboFix 12-01-13.03 - Vadim Kuzmenko 01.2012 г. 18:58:25.2.2 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1251.359.1033.18.2815.2199 [GMT 2:00] Running from: c:\documents and settings\Vadim Kuzmenko\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Vadim Kuzmenko\Desktop\CFScript.txt AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D} FW: avast! Antivirus *Enabled* {7591DB91-41F0-48A3-B128-1A293FD8233D} . FILE :: "c:\windows\system32\msfeedssync.exe" . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\documents and settings\Vadim Kuzmenko\Application Data\defaults.cfg . Infected copy of c:\windows\system32\drivers\ntfs.sys was found and disinfected Restored copy from - c:\windows\ERDNT\cache\ntfs.sys . . ((((((((((((((((((((((((( Files Created from 2011-12-13 to 2012-01-13 ))))))))))))))))))))))))))))))) . . 2012-01-13 14:14 . 2012-01-13 14:30 -------- d-----w- c:\documents and settings\Vadim Kuzmenko\Local Settings\Application Data\NPE 2012-01-13 14:14 . 2012-01-13 14:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton 2012-01-13 13:53 . 2012-01-13 13:53 23624 ----a-w- c:\windows\system32\drivers\hitmanpro36.sys 2012-01-13 13:52 . 2012-01-13 13:52 -------- d-----w- c:\program files\HitmanPro 2012-01-13 13:52 . 2012-01-13 13:53 -------- d-----w- c:\documents and settings\All Users\Application Data\HitmanPro 2012-01-13 11:21 . 2012-01-13 11:21 -------- d-----w- c:\documents and settings\Vadim Kuzmenko\Application Data\Malwarebytes 2012-01-13 11:21 . 2012-01-13 11:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2012-01-13 11:21 . 2012-01-13 11:22 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2012-01-13 11:21 . 2011-12-10 13:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys 2012-01-13 10:06 . 2010-08-19 17:22 409600 ----a-w- c:\program files\Mozilla Firefox\Kaspersky Rescue2Usb\rescue2usb.exe 2012-01-13 10:06 . 2010-04-01 09:01 28160 ----a-w- c:\program files\Mozilla Firefox\Kaspersky Rescue2Usb\syslinux.exe 2012-01-13 10:06 . 2009-10-16 14:43 237849 ----a-w- c:\program files\Mozilla Firefox\Kaspersky Rescue2Usb\grub.exe 2012-01-13 07:20 . 2012-01-13 07:20 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache 2012-01-13 07:11 . 2012-01-13 07:11 479232 ----a-w- c:\program files\Mozilla Firefox\msvcm80.dll 2012-01-13 07:11 . 2012-01-13 07:11 43992 ----a-w- c:\program files\Mozilla Firefox\mozutils.dll 2012-01-13 07:11 . 2012-01-13 07:11 626688 ----a-w- c:\program files\Mozilla Firefox\msvcr80.dll 2012-01-13 07:11 . 2012-01-13 07:11 548864 ----a-w- c:\program files\Mozilla Firefox\msvcp80.dll 2012-01-12 14:12 . 2012-01-12 14:12 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache 2012-01-12 14:09 . 2011-12-14 10:47 31552 ----a-w- c:\windows\system32\TURegOpt.exe 2012-01-12 14:08 . 2012-01-12 14:08 -------- d-----w- c:\documents and settings\Vadim Kuzmenko\Application Data\TuneUp Software 2012-01-12 14:08 . 2012-01-12 14:10 -------- d-----w- c:\program files\TuneUp Utilities 2012 2012-01-12 14:07 . 2012-01-12 14:09 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software 2012-01-12 14:07 . 2012-01-12 14:07 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{32364CEA-7855-4A3C-B674-53D8E9B97936} 2012-01-12 13:11 . 2012-01-12 13:11 -------- d-----w- c:\program files\Xenocode 2012-01-11 11:06 . 2001-08-17 20:36 5632 ----a-w- c:\windows\system32\ptpusb.dll 2012-01-11 11:06 . 2008-04-14 03:42 159232 ----a-w- c:\windows\system32\ptpusd.dll 2012-01-11 11:06 . 2008-04-13 22:15 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys 2012-01-11 11:06 . 2008-04-13 22:15 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys 2012-01-11 05:56 . 2012-01-11 05:56 -------- d-----w- c:\documents and settings\Vadim Kuzmenko\Local Settings\Application Data\My Games 2012-01-09 13:30 . 2008-04-13 22:09 14592 -c--a-w- c:\windows\system32\dllcache\kbdhid.sys 2012-01-09 13:30 . 2008-04-13 22:09 14592 ----a-w- c:\windows\system32\drivers\kbdhid.sys 2012-01-02 16:37 . 2012-01-11 05:56 -------- d-----w- c:\program files\Sid Meiers Civilization V 2011-12-24 21:00 . 2011-12-24 21:00 -------- d-----w- c:\documents and settings\Vadim Kuzmenko\Application Data\WebMoneyAdvisor 2011-12-19 08:12 . 1999-11-11 11:47 6416 ----a-w- c:\windows\system32\kbdinori.Dll 2011-12-19 08:12 . 1999-11-11 11:47 6416 ----a-w- c:\windows\system32\kbdinasa.Dll 2011-12-19 08:12 . 1999-11-11 11:47 6928 ----a-w- c:\windows\system32\kbdhebx.Dll 2011-12-19 08:12 . 2000-11-17 06:47 8992 ----a-w- c:\windows\system32\kbdbphz.dLL 2011-12-19 08:12 . 1999-12-07 07:00 6416 ----a-w- c:\windows\system32\kbdbp.Dll 2011-12-19 08:12 . 1999-11-18 03:04 7440 ----a-w- c:\windows\system32\Kbddll.dll 2011-12-19 08:12 . 1997-04-03 19:00 8992 ----a-w- c:\windows\system32\KBDBPH.dLL 2011-12-19 08:12 . 2000-11-14 23:52 6416 ----a-w- c:\windows\system32\kbdbds.Dll 2011-12-19 08:12 . 2002-04-22 22:17 45056 ----a-w- c:\windows\system32\newdll.dll 2011-12-19 08:12 . 2011-12-19 08:12 -------- d-----w- c:\program files\Datecs . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-11-28 18:01 . 2010-07-22 10:23 41184 ----a-w- c:\windows\avastSS.scr 2011-11-28 18:01 . 2010-07-22 10:23 199816 ----a-w- c:\windows\system32\aswBoot.exe 2011-11-28 17:53 . 2011-03-22 21:08 435032 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2011-11-28 17:53 . 2010-07-22 10:23 314456 ----a-w- c:\windows\system32\drivers\aswSP.sys 2011-11-28 17:52 . 2010-07-22 10:23 34392 ----a-w- c:\windows\system32\drivers\aswRdr.sys 2011-11-28 17:52 . 2010-07-22 10:23 52952 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2011-11-28 17:52 . 2010-07-22 10:23 111320 ----a-w- c:\windows\system32\drivers\aswmon2.sys 2011-11-28 17:51 . 2010-07-22 10:23 105176 ----a-w- c:\windows\system32\drivers\aswmon.sys 2011-11-28 17:51 . 2010-07-22 10:23 20568 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2011-11-28 17:48 . 2010-07-22 10:23 30808 ----a-w- c:\windows\system32\drivers\aavmker4.sys 2011-11-25 21:57 . 2008-04-14 12:00 293376 ----a-w- c:\windows\system32\winsrv.dll 2011-11-23 13:25 . 2008-04-14 12:00 1859584 ----a-w- c:\windows\system32\win32k.sys 2011-11-18 12:35 . 2008-04-14 12:00 60416 ----a-w- c:\windows\system32\packager.exe 2011-11-14 16:03 . 2011-05-27 10:48 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-11-04 19:20 . 2008-04-14 12:00 916992 ----a-w- c:\windows\system32\wininet.dll 2011-11-04 19:20 . 2008-04-14 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll 2011-11-04 19:20 . 2008-04-14 12:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl 2011-11-04 11:23 . 2008-04-14 12:00 385024 ----a-w- c:\windows\system32\html.iec 2011-11-03 15:28 . 2008-04-14 12:00 386048 ----a-w- c:\windows\system32\qdvd.dll 2011-11-03 15:28 . 2008-04-14 12:00 1292288 ----a-w- c:\windows\system32\quartz.dll 2011-11-01 16:07 . 2008-04-14 12:00 1288704 ----a-w- c:\windows\system32\ole32.dll 2011-10-28 05:31 . 2008-04-14 12:00 33280 ----a-w- c:\windows\system32\csrsrv.dll 2011-10-25 13:37 . 2008-04-14 12:00 2148864 ----a-w- c:\windows\system32\ntoskrnl.exe 2011-10-25 12:52 . 2008-04-14 00:01 2027008 ----a-w- c:\windows\system32\ntkrnlpa.exe 2011-10-18 11:13 . 2008-04-14 12:00 186880 ----a-w- c:\windows\system32\encdec.dll 2010-02-25 10:11 . 2010-02-25 10:11 28472 ----a-w- c:\program files\mozilla firefox\plugins\atgpcdec.dll 2010-02-25 10:11 . 2010-02-25 10:11 185224 ----a-w- c:\program files\mozilla firefox\plugins\atgpcext.dll 2010-02-25 10:13 . 2010-02-25 10:13 46392 ----a-w- c:\program files\mozilla firefox\plugins\atmccli.dll 2010-02-25 10:11 . 2010-02-25 10:11 99208 ----a-w- c:\program files\mozilla firefox\plugins\ieatgpc.dll 2012-01-13 07:11 . 2011-05-07 18:08 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((( SnapShot@2012-01-13_16.01.06 ))))))))))))))))))))))))))))))))))))))))) . + 2012-01-13 17:13 . 2012-01-13 17:13 16384 c:\windows\Temp\Perflib_Perfdata_6c8.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files\uTorrentBar\tbuTo1.dll" [2010-12-25 3911776] . [HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}] . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}] 2010-12-25 10:27 3911776 ----a-w- c:\program files\ConduitEngine\ConduitEngin0.dll . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}] 2010-12-25 10:27 3911776 ----a-w- c:\program files\uTorrentBar\tbuTo1.dll . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E7D2CB77-6E2D-4C1F-B485-D50506B9FA6B}] 2011-07-20 16:27 288224 ----a-w- c:\program files\WebMoney Advisor\2.2.4\wmadvisor.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}"= "c:\program files\WebMoney Advisor\tbcore3.dll" [2010-02-24 2559608] "{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files\uTorrentBar\tbuTo1.dll" [2010-12-25 3911776] "{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngin0.dll" [2010-12-25 3911776] "{405DFEAE-1D2F-4649-BE08-C92313C3E1CE}"= "c:\program files\WebMoney Advisor\2.2.4\wmadvisor.dll" [2011-07-20 288224] . [HKEY_CLASSES_ROOT\clsid\{3affd7f7-fd3d-4c9d-8f83-03296a1a8840}] [HKEY_CLASSES_ROOT\TBSB03374.TBSB03374.3] [HKEY_CLASSES_ROOT\TypeLib\{77AA25E8-6083-4949-A831-9CB11861DC10}] [HKEY_CLASSES_ROOT\TBSB03374.TBSB03374] . [HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}] . [HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}] . [HKEY_CLASSES_ROOT\clsid\{405dfeae-1d2f-4649-be08-c92313c3e1ce}] [HKEY_CLASSES_ROOT\TypeLib\{3B9F4DFC-44AF-45E0-A38D-0D35F70BB2B0}] . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840}"= "c:\program files\WebMoney Advisor\tbcore3.dll" [2010-02-24 2559608] "{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}"= "c:\program files\uTorrentBar\tbuTo1.dll" [2010-12-25 3911776] "{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngin0.dll" [2010-12-25 3911776] "{405DFEAE-1D2F-4649-BE08-C92313C3E1CE}"= "c:\program files\WebMoney Advisor\2.2.4\wmadvisor.dll" [2011-07-20 288224] . [HKEY_CLASSES_ROOT\clsid\{3affd7f7-fd3d-4c9d-8f83-03296a1a8840}] [HKEY_CLASSES_ROOT\TBSB03374.TBSB03374.3] [HKEY_CLASSES_ROOT\TypeLib\{77AA25E8-6083-4949-A831-9CB11861DC10}] [HKEY_CLASSES_ROOT\TBSB03374.TBSB03374] . [HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}] . [HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}] . [HKEY_CLASSES_ROOT\clsid\{405dfeae-1d2f-4649-be08-c92313c3e1ce}] [HKEY_CLASSES_ROOT\TypeLib\{3B9F4DFC-44AF-45E0-A38D-0D35F70BB2B0}] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2011-11-28 18:01 122512 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2011-03-30 399736] "OfficeSyncProcess"="c:\program files\Microsoft Office\Office14\MSOSYNC.EXE" [2011-07-21 718720] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-06-15 15141768] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ATKMEDIA"="c:\program files\ASUS\ATK Media\DMedia.exe" [2009-08-19 170624] "HControlUser"="c:\program files\ASUS\ATK Hotkey\HControlUser.exe" [2009-06-19 105016] "ATKHOTKEY"="c:\program files\ASUS\ATK Hotkey\HControl.exe" [2009-10-26 174720] "ATKOSD2"="c:\program files\ASUS\ATKOSD2\ATKOSD2.exe" [2009-10-26 6998656] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-10-06 98304] "HDAudDeck"="c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe" [2009-11-17 33697792] "ATICustomerCare"="c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-03-04 311296] "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "wmagent.exe"="c:\program files\WebMoney Agent\wmagent.exe" [2009-10-19 210400] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712] "avast"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2011-11-28 3744552] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] . c:\documents and settings\All Users\Start Menu\Programs\Startup\ FlexType 2K.lnk - c:\program files\Datecs\FlexType 2K\FType2K.exe [2011-12-19 95232] SRS Premium Sound.lnk - c:\program files\SRS Labs\SRS Premium Sound\SRSPremiumSound_XP.exe [2009-10-28 3372336] . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk /r \??\c:\0autocheck autochk /r \??\C:\0autocheck autochk * . [HKLM\~\startupfolder\C:^Documents and Settings^Vadim Kuzmenko^Start Menu^Programs^Startup^Microsoft SharePoint Workspace.lnk] path=c:\documents and settings\Vadim Kuzmenko\Start Menu\Programs\Startup\Microsoft SharePoint Workspace.lnk backup=c:\windows\pss\Microsoft SharePoint Workspace.lnkStartup . [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\WINDOWS\\system32\\usmt\\migwiz.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"= "c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"= "c:\\Program Files\\WebMoney\\WebMoney.exe"= "c:\\WINDOWS\\system32\\PnkBstrA.exe"= "c:\\WINDOWS\\system32\\PnkBstrB.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= "c:\\Program Files\\Anno 1404.Золотое издание.v 1.02.2619(2.00.5008)\\tools\\Anno4Web.exe"= . R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [28.12.2010 і. 14:56 436792] R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [22.3.2011 і. 23:08 435032] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [22.7.2010 і. 12:23 314456] R1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\elrawdsk.sys [24.1.2011 і. 22:44 29768] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [22.7.2010 і. 12:23 20568] R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe [14.12.2011 і. 12:47 1514304] R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [29.10.2009 і. 15:11 1605760] S2 KMService;KMService;c:\windows\system32\srvany.exe [05.10.2010 і. 20:57 8192] S3 EverestDriver;Lavalys EVEREST Kernel Driver;\??\c:\documents and settings\user\Desktop\EVEREST Ultimate Edition\kerneld.wnt --> c:\documents and settings\user\Desktop\EVEREST Ultimate Edition\kerneld.wnt [?] S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [12.6.2011 і. 10:15 31125880] S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [09.1.2010 і. 20:37 4640000] S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;\??\c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys --> c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [?] S3 XDva370;XDva370;\??\c:\windows\system32\XDva370.sys --> c:\windows\system32\XDva370.sys [?] S3 XDva380;XDva380;\??\c:\windows\system32\XDva380.sys --> c:\windows\system32\XDva380.sys [?] . Contents of the 'Scheduled Tasks' folder . 2012-01-13 c:\windows\Tasks\User_Feed_Synchronization-{258042C4-A5B2-4E6A-BA47-D341300B5C63}.job - c:\windows\system32\msfeedssync.exe [2009-03-08 01:31] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com/ uDefault_Search_URL = hxxp://www.Google.com mStart Page = hxxp://www.google.com/ mSearch Bar = hxxp://www.google.com/ uSearchAssistant = hxxp://www.Google.com/ IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105 IE: {{3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840} - {3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840} - c:\program files\WebMoney Advisor\tbcore3.dll TCP: DhcpNameServer = 192.168.1.1 TCP: Interfaces\{A1470B2C-3654-47D9-B508-1BDC153AEF3A}: NameServer = 95.111.0.193,89.190.192.166 FF - ProfilePath - c:\documents and settings\Vadim Kuzmenko\Application Data\Mozilla\Firefox\Profiles\v0xv99cn.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&q= FF - prefs.js: network.proxy.type - 0 . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2012-01-13 19:14 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . HKLM\Software\Microsoft\Windows\CurrentVersion\Run HDAudDeck = c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe 1???????????????????????????????????????????????? . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EverestDriver] "ImagePath"="\??\c:\documents and settings\user\Desktop\EVEREST Ultimate Edition\kerneld.wnt" . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_USERS\S-1-5-21-2619899986-1885740954-1578026109-1006\Software\Microsoft\SystemCertificates\AddressBook*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) . [HKEY_USERS\S-1-5-21-2619899986-1885740954-1578026109-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\1*!] "Order"=hex:08,00,00,00,02,00,00,00,80,00,00,00,01,00,00,00,01,00,00,00,74,00, 00,00,00,00,00,00,66,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,54,00,31,\ . [HKEY_USERS\S-1-5-21-2619899986-1885740954-1578026109-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\1*!\Patrician 4] "Order"=hex:08,00,00,00,02,00,00,00,0c,01,00,00,01,00,00,00,02,00,00,00,80,00, 00,00,00,00,00,00,72,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,60,00,32,\ . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'winlogon.exe'(980) c:\windows\system32\Ati2evxx.dll . - - - - - - - > 'explorer.exe'(3404) c:\windows\system32\WININET.dll c:\windows\system32\newdll.dll c:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf c:\progra~1\MICROS~2\Office14\1033\GrooveIntlResource.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\Ati2evxx.exe c:\windows\system32\Ati2evxx.exe c:\program files\Alwil Software\Avast5\AvastSvc.exe c:\program files\Java\jre6\bin\jqs.exe c:\windows\system32\PnkBstrA.exe c:\program files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe c:\windows\system32\wscntfy.exe c:\program files\ASUS\ATK Hotkey\ATKOSD.exe c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe c:\program files\ASUS\ATK Hotkey\KBFiltr.exe c:\program files\ASUS\ATK Hotkey\WDC.exe c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe . ************************************************************************** . Completion time: 2012-01-13 19:19:47 - machine was rebooted ComboFix-quarantined-files.txt 2012-01-13 17:19 ComboFix2.txt 2012-01-13 16:06 . Pre-Run: 98 493 685 760 bytes free Post-Run: 98 480 963 584 bytes free . - - End Of File - - 6689F6D8EFF4E43C111179F93B4DB88A

Следвайте следната инструкция за работа с Rootkit UnHooker:
  • Изтеглете този файл на десктопа.
  • Разархивирайте архива и стартирайте RkU3.8.388.590.exe, отидете на Report и сложете всички отметки. Натиснете OK.
  • Изчакайте програмата да завърши работа. След това кликнете на File, после Save Report. Запазете (Save as) файла с име report.txt на десктопа.
  • Публикувайте съдържанието на файла report.txt в следващия си коментар.

Деинсталирайте Комбофикс така:

1.Натиснете Start ==> Run ==> въведете командата Combofix /Uninstall ==> OK

Публикувано изображение

2.Изтеглете Публикувано изображениеOTCleanIt или от тук,стартирайте и натиснете Публикувано изображение

Публикувано изображение Изтеглете програмата: ESET Online Scanner

  • Стартирайте esetsmartinstaller_enu.exe Публикувано изображение
  • Сложете отметка на YES, I accept the Terms of Use и изберете Start:

    Публикувано изображение

  • Скенерът ще започне да изтегля компонентите, които са му необходими:

    Публикувано изображение

  • Уверете се, че има отметки на следните редове:

    Публикувано изображение

    Накрая изберете Start

  • Скенерът ще започне да изтегля последните дефиниции.
  • След, като сканирането завърши изберете Finish.
  • Отидете в: C:\Program Files\ESET\ESET Online Scanner
  • Отворете файла log.txt , копирайте съдържанието му и го поставете в следващия си коментар.
  • Автор

Никакъв ефект, проклетия екран продължава да премигва, както и chkdsk продължава да се стартира ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=9ce6e27cb2fe1f4fbdb410b899487d47 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2012-01-14 01:17:42 # local_time=2012-01-14 03:17:42 (+0200, FLE Standard Time) # country="Bulgaria" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=768 16777215 100 0 46745308 46745308 0 0 # compatibility_mode=8192 67108863 100 0 315 315 0 0 # scanned=94374 # found=1 # cleaned=1 # scan_time=4009 C:\Documents and Settings\Vadim Kuzmenko\My Documents\Downloads\TuneUp Utilities 2012 v12.0.2160.13\TuneUp Utilities 2012 v12.0.2160.13.rar Win32/Keygen.CD application (deleted - quarantined) 00000000000000000000000000000000 C

Редактирано от SvetoslavSt (преглед на промените)

  • Автор

Споделете, ако знаете поне как да изключа автоматичното старатиране за дефрагментиране в уина.Въпреки че дефрагментирах всички дискове, при всяко стартиране автоматично се включва функцията.

  • Автор

Ами както казах при самото стартиране на уиндоуса, още преди да е заредил започва автоматична проверка на диска.Сещаш се...

My Computer => десен бутон на системния дял (Local Disk (C:) => Propeerties => Tools => Check Now => махате двете отметки и рестартирате компютъра...!

  • Автор

След като ги махна трябва ли да му дам Start?

  • Автор

В момента нямам достъп достъп до машината, но обезателно ще го пробвам.Надявам се поне това досадно стартиране да успеем да прекратим. Благодаря, и ще пиша с резултати! ;)

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.