Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Файл stdrt.exe (предполагам) ми изключва звука на саунд картата [РЕШЕН]

Featured Replies

Брее...мобилизирана е цялата гилдия на хелперите.....наистина нещата са много кофти..!

Я да проверим нещо:

  • Моля, изтеглете SystemLook и запазете програмата на десктопа.
  • Кликнете два пъти върху SystemLook.exe, за да стартирате програмата.
  • Копирайте съдържанието на следния код в текстовото поле на програмата
:regfind
stdrt.exe
  • Кликнете на бутона Look, за да започне сканирането.
  • Когато сканирането завърши ще Ви се отвори Notepad с резултата от сканирането. Моля, публикувайте лог файла в следващия си коментар.
  • Автор

ето лога SystemLook 30.07.11 by jpshortstuff Log created at 07:39 on 31/01/2012 by GR Administrator - Elevation successful ========== regfind ========== Searching for "stdrt.exe" [HKEY_CURRENT_USER\Software\Greatis\Regrun2\Black\Files\C:WINDOWSTEMPMRT1.TMPSTDRT.EXE] [HKEY_CURRENT_USER\Software\Greatis\Regrun2\Black\Files\C:WINDOWSTEMPMRT1.TMPSTDRT.EXE] @="C:\WINDOWS\TEMP\MRT1.TMP\STDRT.EXE" [HKEY_CURRENT_USER\Software\Greatis\Regrun2\Black\Files\C:WINDOWSTEMPMRT4.TMPSTDRT.EXE] [HKEY_CURRENT_USER\Software\Greatis\Regrun2\Black\Files\C:WINDOWSTEMPMRT4.TMPSTDRT.EXE] @="C:\WINDOWS\TEMP\MRT4.TMP\STDRT.EXE" [HKEY_CURRENT_USER\Software\Greatis\Regrun2\Black\Files\C:WINDOWSTEMPMRT6.TMPSTDRT.EXE] [HKEY_CURRENT_USER\Software\Greatis\Regrun2\Black\Files\C:WINDOWSTEMPMRT6.TMPSTDRT.EXE] @="C:\WINDOWS\TEMP\MRT6.TMP\STDRT.EXE" [HKEY_CURRENT_USER\Software\Greatis\Regrun2\Black\Files\C:WINDOWSTEMPMRT7.TMPSTDRT.EXE] [HKEY_CURRENT_USER\Software\Greatis\Regrun2\Black\Files\C:WINDOWSTEMPMRT7.TMPSTDRT.EXE] @="C:\WINDOWS\TEMP\MRT7.TMP\STDRT.EXE" [HKEY_CURRENT_USER\Software\Greatis\Regrun2\Black\Files\C:WINDOWSTEMPMRT8.TMPSTDRT.EXE] [HKEY_CURRENT_USER\Software\Greatis\Regrun2\Black\Files\C:WINDOWSTEMPMRT8.TMPSTDRT.EXE] @="C:\WINDOWS\TEMP\MRT8.TMP\STDRT.EXE" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\ApprovedByRegRun2\AntiRepl\0] "Target"="\??\C:\WINDOWS\TEMP\MRT1.TMP\STDRT.EXE" [HKEY_USERS\.DEFAULT\Software\Microsoft\Direct3D\MostRecentApplication] "Name"="stdrt.exe" [HKEY_USERS\S-1-5-21-1417001333-1767777339-725345543-1004\Software\Greatis\Regrun2\Black\Files\C:WINDOWSTEMPMRT1.TMPSTDRT.EXE] [HKEY_USERS\S-1-5-21-1417001333-1767777339-725345543-1004\Software\Greatis\Regrun2\Black\Files\C:WINDOWSTEMPMRT1.TMPSTDRT.EXE] @="C:\WINDOWS\TEMP\MRT1.TMP\STDRT.EXE" [HKEY_USERS\S-1-5-21-1417001333-1767777339-725345543-1004\Software\Greatis\Regrun2\Black\Files\C:WINDOWSTEMPMRT4.TMPSTDRT.EXE] [HKEY_USERS\S-1-5-21-1417001333-1767777339-725345543-1004\Software\Greatis\Regrun2\Black\Files\C:WINDOWSTEMPMRT4.TMPSTDRT.EXE] @="C:\WINDOWS\TEMP\MRT4.TMP\STDRT.EXE" [HKEY_USERS\S-1-5-21-1417001333-1767777339-725345543-1004\Software\Greatis\Regrun2\Black\Files\C:WINDOWSTEMPMRT6.TMPSTDRT.EXE] [HKEY_USERS\S-1-5-21-1417001333-1767777339-725345543-1004\Software\Greatis\Regrun2\Black\Files\C:WINDOWSTEMPMRT6.TMPSTDRT.EXE] @="C:\WINDOWS\TEMP\MRT6.TMP\STDRT.EXE" [HKEY_USERS\S-1-5-21-1417001333-1767777339-725345543-1004\Software\Greatis\Regrun2\Black\Files\C:WINDOWSTEMPMRT7.TMPSTDRT.EXE] [HKEY_USERS\S-1-5-21-1417001333-1767777339-725345543-1004\Software\Greatis\Regrun2\Black\Files\C:WINDOWSTEMPMRT7.TMPSTDRT.EXE] @="C:\WINDOWS\TEMP\MRT7.TMP\STDRT.EXE" [HKEY_USERS\S-1-5-21-1417001333-1767777339-725345543-1004\Software\Greatis\Regrun2\Black\Files\C:WINDOWSTEMPMRT8.TMPSTDRT.EXE] [HKEY_USERS\S-1-5-21-1417001333-1767777339-725345543-1004\Software\Greatis\Regrun2\Black\Files\C:WINDOWSTEMPMRT8.TMPSTDRT.EXE] @="C:\WINDOWS\TEMP\MRT8.TMP\STDRT.EXE" [HKEY_USERS\S-1-5-18\Software\Microsoft\Direct3D\MostRecentApplication] "Name"="stdrt.exe" -= EOF =- Благодаря на цялата гилдия на хелперите Междувременно рестартирах и тази гадина е изчезнала за пръв път от Task manager и за пръв път системата се зареди без изключена звукова карта .Може би все пак UnhackMe е подействала...? Не бързам да се радвам,,,

Сега ..трябва да изляза за малко по спешни задачи...съжалявам ....когато свърша ще пиша...Хем и вие да отдъхнете малко и после отново - борба...!:)

Публикувано изображение Моля, изтеглете aswMBR и го запазете на вашия десктоп.

  • Кликнете с двоен клин на мишката върху файла aswMBR.exe за да го стартирате.
  • Изчакайте да изтегли дефинициите на avast!
  • От падащото меню посочете дял C:\ както е на снимката:
Публикувано изображение
  • Изберете Scan бутона, за да започне проверката.
  • Когато проверката завърши, натиснете бутона save log, запазете съдържанието на лог файла на десктопа и публикувайте съдържанието му в следващия си коментар.
Публикувано изображение Моля, изтеглете последната версия на TDSSKiller - оттук и я запазете на вашия декстоп.
  • Стартирайте TDSSKiller.exe за да стартирате приложението. След това кликнете върху бутона Change parameters.

    Публикувано изображение

  • Сложете отметки пред Verify Driver Digital Signature и Detect TDLFS file system и натиснете ОК.

    Публикувано изображение

  • Натиснете бутона Start Scan.

    Публикувано изображение

  • Ако подозрителен обект бъде засечен, действието по подразбиране ще бъде Skip, кликнете върху Continue.

    Публикувано изображение

  • Ако зловредни обекти бъдат намерени, тогава от падащото меню ще имате три възможности.

    Бъдете сигурни, че избраното действие е Cure и натиснете върху Continue > Рестартирайте за да бъде завършена поправката.

    Публикувано изображение

    Забележка: Ако Cure бутона не е наличен от възможностите, тогава моля изберете Skip бутона, не избирайте Delete освен ако не сте инструктирани затова.

  • Лог файл ще бъде създаден в свободната директория на дял C:\ . Потърсете за лог с името "TDSSKiller.[Version]_[Date]_[Time]_log.txt" и копирайте съдържанието му в следващия си пост.

Изтеглете Gmer или от тук.

* Временно спрете Интернета си,всички работещи програми,както и антивирусната си програма.

* Стартирате програмата.

* След завършването на автомаичната експрес-проверка,махнете отметките от следните позиции:

- Sections

- IAT/EAT

- Show all

* От всички локални дискове маркирайте само системния дял (обикновенно това е C:\ )

Публикувано изображение

* Изчакайте програмата да завърши сканирането,след което натиснете бутона Save и запишете (save as) резултатите на десктопа с име Gmer.log.

* Включете Интернета си и прикачете Gmer.log в следващия си коментар.

Забележка:

* Ако бъде открит Rootkit, ще последва въпрос дали желаете пълно сканиране на системата. Изберете NO.

* Не предприемайте никакви действия върху редовете маркирани с "<--- ROOТKIT" ,защото това може да доведе до грешки.

* В десния панел на програмата ще видите какво е ще се провери от програмата, не променяйте нищо. Убедете се, че на Show All няма отметка.

Внимание:

Ако имате проблем с използването на GMER по по-горе описания начин,моля изпълнете сканирането,като маркирате следните позиции:

Публикувано изображение

Междувременно рестартирах и тази гадина е изчезнала за пръв път от Task manager и за пръв път системата се зареди без изключена звукова карта .Може би все пак UnhackMe е подействала...? Не бързам да се радвам,,,

Това е много добре...!Ще наблюдаваме....Направете горните сканирания за да проверим за рууткит.....!:)

  • Автор

Приятен ден ще се видим по-късно.Благодаря

  • Автор

Направих това което ми казахте,имам лог файловете на десктопа ,но не мога да ги отворя защото ми казва,че нямам достъп.Опитах да отворя логове от предишните постове,които са вече на десктопа и на които съм копирал вече веднъж съдържанието за да ги постна...същото нещо :ohmy:

Интересно...стана като ги отворих чрез Internet Explorer

aswMBR version 0.9.9.1532 Copyright© 2011 AVAST Software

Run date: 2012-01-31 08:15:47

-----------------------------

08:15:47.703 OS Version: Windows 5.1.2600 Service Pack 2

08:15:47.703 Number of processors: 1 586 0xD08

08:15:47.734 ComputerName: GR-E99077D3BD63 UserName: GR

08:15:48.359 Initialize success

08:15:49.593 AVAST engine defs: 12013100

08:16:30.890 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4

08:16:30.890 Disk 0 Vendor: WDC_WD1000VE-00KWT0 01.03K01 Size: 95396MB BusType: 3

08:16:30.890 Device \Driver\atapi -> MajorFunction 82d8b1f8

08:16:30.906 Disk 0 MBR read successfully

08:16:30.906 Disk 0 MBR scan

08:16:31.703 Disk 0 Windows XP default MBR code

08:16:31.734 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 95087 MB offset 63

08:16:32.421 Disk 0 Partition 2 00 88 Linux plaintext A Kárò'ó 203 MB offset 194739930

08:16:33.046 Disk 0 scanning sectors +195157620

08:16:33.546 Disk 0 scanning C:\WINDOWS\system32\drivers

08:16:58.625 Service scanning

08:16:59.500 Service sptd C:\WINDOWS\System32\Drivers\sptd.sys **LOCKED** 32

08:17:00.109 Modules scanning

08:17:09.671 Disk 0 trace - called modules:

08:17:09.703 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x82d8b1f8]<<

08:17:09.703 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x82d47030]

08:17:09.703 3 CLASSPNP.SYS[f8ed505b] -> nt!IofCallDriver -> \Device\00000079[0x82d77ae8]

08:17:09.718 5 ACPI.sys[f8c31620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-4[0x82d35218]

08:17:09.718 \Driver\atapi[0x82d35b60] -> IRP_MJ_CREATE -> 0x82d8b1f8

08:17:10.359 AVAST engine scan C:\

09:18:50.812 Scan finished successfully

10:54:54.234 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\GR\Bureau\MBR.dat"

10:54:54.265 The log file has been saved successfully to "C:\Documents and Settings\GR\Bureau\aswMBR.txt"

Втория

10:57:37.0250 0788 TDSS rootkit removing tool 2.7.8.0 Jan 30 2012 16:39:36

10:57:37.0750 0788 ============================================================

10:57:37.0750 0788 Current date / time: 2012/01/31 10:57:37.0750

10:57:37.0750 0788 SystemInfo:

10:57:37.0750 0788

10:57:37.0750 0788 OS Version: 5.1.2600 ServicePack: 2.0

10:57:37.0750 0788 Product type: Workstation

10:57:37.0750 0788 ComputerName: GR-E99077D3BD63

10:57:37.0765 0788 UserName: GR

10:57:37.0765 0788 Windows directory: C:\WINDOWS

10:57:37.0765 0788 System windows directory: C:\WINDOWS

10:57:37.0765 0788 Processor architecture: Intel x86

10:57:37.0765 0788 Number of processors: 1

10:57:37.0765 0788 Page size: 0x1000

10:57:37.0765 0788 Boot type: Normal boot

10:57:37.0765 0788 ============================================================

10:57:40.0234 0788 Drive \Device\Harddisk0\DR0 - Size: 0x174A446000 (93.16 Gb), SectorSize: 0x200, Cylinders: 0x2F81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054

10:57:40.0484 0788 \Device\Harddisk0\DR0:

10:57:40.0484 0788 MBR used

10:57:40.0484 0788 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0xB9B7E9B

10:57:40.0546 0788 Initialize success

10:57:40.0546 0788 ============================================================

10:58:52.0265 2260 ============================================================

10:58:52.0265 2260 Scan started

10:58:52.0265 2260 Mode: Manual; SigCheck; TDLFS;

10:58:52.0265 2260 ============================================================

10:58:52.0515 2260 Aavmker4 (b6de0336f9f4b687b4ff57939f7b657a) C:\WINDOWS\system32\drivers\Aavmker4.sys

10:58:52.0953 2260 Aavmker4 - ok

10:58:52.0968 2260 Abiosdsk - ok

10:58:53.0000 2260 abp480n5 - ok

10:58:53.0078 2260 ACPI (0bd94fbfc14ea3606cd6ca4c0255baa3) C:\WINDOWS\system32\DRIVERS\ACPI.sys

10:58:54.0390 2260 ACPI - ok

10:58:54.0515 2260 ACPIEC (e4abc1212b70bb03d35e60681c447210) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys

10:58:54.0750 2260 ACPIEC - ok

10:58:54.0765 2260 adpu160m - ok

10:58:54.0812 2260 aeaudio (f13d8e7e1faa31019c25eb17b5fb2662) C:\WINDOWS\system32\drivers\aeaudio.sys

10:58:54.0906 2260 aeaudio - ok

10:58:54.0953 2260 aec (841f385c6cfaf66b58fbd898722bb4f0) C:\WINDOWS\system32\drivers\aec.sys

10:58:55.0093 2260 aec - ok

10:58:55.0125 2260 AFD (5ac495f4cb807b2b98ad2ad591e6d92e) C:\WINDOWS\System32\drivers\afd.sys

10:58:55.0296 2260 AFD - ok

10:58:55.0484 2260 AgereSoftModem (593aefc67283d409f34cc1245d00a509) C:\WINDOWS\system32\DRIVERS\AGRSM.sys

10:58:55.0765 2260 AgereSoftModem - ok

10:58:56.0093 2260 Aha154x - ok

10:58:56.0156 2260 aic78u2 - ok

10:58:56.0250 2260 aic78xx - ok

10:58:56.0328 2260 AliIde - ok

10:58:56.0375 2260 amsint - ok

10:58:56.0484 2260 Arp1394 (f0d692b0bffb46e30eb3cea168bbc49f) C:\WINDOWS\system32\DRIVERS\arp1394.sys

10:58:56.0640 2260 Arp1394 - ok

10:58:57.0015 2260 ASAPIW2K (4f9cbbf95e8f7a0d4c0edcfe3b78102e) C:\WINDOWS\system32\Drivers\ASAPIW2K.sys

10:58:57.0031 2260 ASAPIW2K ( UnsignedFile.Multi.Generic ) - warning

10:58:57.0031 2260 ASAPIW2K - detected UnsignedFile.Multi.Generic (1)

10:58:57.0046 2260 asc - ok

10:58:57.0062 2260 asc3350p - ok

10:58:57.0078 2260 asc3550 - ok

10:58:57.0156 2260 aswFsBlk (054df24c92b55427e0757cfff160e4f2) C:\WINDOWS\system32\drivers\aswFsBlk.sys

10:58:57.0171 2260 aswFsBlk - ok

10:58:57.0203 2260 aswMon2 (ef0e9ad83380724bd6fbbb51d2d0f5b8) C:\WINDOWS\system32\drivers\aswMon2.sys

10:58:57.0234 2260 aswMon2 - ok

10:58:57.0250 2260 aswRdr (352d5a48ebab35a7693b048679304831) C:\WINDOWS\system32\drivers\aswRdr.sys

10:58:57.0296 2260 aswRdr - ok

10:58:57.0375 2260 aswSnx (8d34d2b24297e27d93e847319abfdec4) C:\WINDOWS\system32\drivers\aswSnx.sys

10:58:57.0484 2260 aswSnx - ok

10:58:57.0546 2260 aswSP (010012597333da1f46c3243f33f8409e) C:\WINDOWS\system32\drivers\aswSP.sys

10:58:57.0593 2260 aswSP - ok

10:58:57.0625 2260 aswTdi (f9f84364416658e9786235904d448d37) C:\WINDOWS\system32\drivers\aswTdi.sys

10:58:57.0640 2260 aswTdi - ok

10:58:57.0750 2260 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys

10:58:58.0031 2260 AsyncMac - ok

10:58:58.0093 2260 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys

10:58:58.0234 2260 atapi - ok

10:58:58.0265 2260 Atdisk - ok

10:58:58.0296 2260 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys

10:58:58.0421 2260 Atmarpc - ok

10:58:58.0468 2260 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys

10:58:58.0609 2260 audstub - ok

10:58:58.0671 2260 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys

10:58:58.0828 2260 Beep - ok

10:58:58.0937 2260 BrScnUsb (92a964547b96d697e5e9ed43b4297f5a) C:\WINDOWS\system32\DRIVERS\BrScnUsb.sys

10:58:59.0000 2260 BrScnUsb - ok

10:58:59.0109 2260 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys

10:58:59.0406 2260 cbidf2k - ok

10:58:59.0531 2260 CCDECODE (6163ed60b684bab19d3352ab22fc48b2) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys

10:58:59.0843 2260 CCDECODE - ok

10:58:59.0921 2260 cd20xrnt - ok

10:58:59.0984 2260 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys

10:59:00.0156 2260 Cdaudio - ok

10:59:00.0218 2260 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys

10:59:00.0406 2260 Cdfs - ok

10:59:00.0453 2260 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys

10:59:00.0625 2260 Cdrom - ok

10:59:01.0109 2260 Changer - ok

10:59:01.0171 2260 CLEDX (b53f9635457b56dcffef750e18aec6cb) C:\WINDOWS\system32\DRIVERS\cledx.sys

10:59:01.0187 2260 CLEDX ( UnsignedFile.Multi.Generic ) - warning

10:59:01.0187 2260 CLEDX - detected UnsignedFile.Multi.Generic (1)

10:59:01.0234 2260 CmBatt (4266be808f85826aedf3c64c1e240203) C:\WINDOWS\system32\DRIVERS\CmBatt.sys

10:59:01.0359 2260 CmBatt - ok

10:59:01.0375 2260 CmdIde - ok

10:59:01.0390 2260 Compbatt (df1b1a24bf52d0ebc01ed4ece8979f50) C:\WINDOWS\system32\DRIVERS\compbatt.sys

10:59:01.0796 2260 Compbatt - ok

10:59:01.0828 2260 Cpqarray - ok

10:59:01.0843 2260 dac2w2k - ok

10:59:01.0890 2260 dac960nt - ok

10:59:01.0921 2260 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys

10:59:02.0046 2260 Disk - ok

10:59:02.0109 2260 dmboot (e2d3b7620310fe56685f9b15a6b404b3) C:\WINDOWS\system32\drivers\dmboot.sys

10:59:02.0328 2260 dmboot - ok

10:59:02.0421 2260 dmio (c77f5c20aa70197a69aa84baa9de43c8) C:\WINDOWS\system32\drivers\dmio.sys

10:59:02.0593 2260 dmio - ok

10:59:02.0640 2260 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys

10:59:02.0828 2260 dmload - ok

10:59:02.0953 2260 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys

10:59:03.0109 2260 DMusic - ok

10:59:03.0125 2260 dpti2o - ok

10:59:03.0156 2260 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys

10:59:03.0312 2260 drmkaud - ok

10:59:03.0375 2260 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys

10:59:03.0515 2260 Fastfat - ok

10:59:03.0562 2260 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\drivers\Fdc.sys

10:59:03.0703 2260 Fdc - ok

10:59:03.0734 2260 Fips (8b121ff880683607ab2aef0340721718) C:\WINDOWS\system32\drivers\Fips.sys

10:59:03.0875 2260 Fips - ok

10:59:03.0937 2260 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\drivers\Flpydisk.sys

10:59:04.0062 2260 Flpydisk - ok

10:59:04.0187 2260 FltMgr (157754f0df355a9e0a6f54721914f9c6) C:\WINDOWS\system32\DRIVERS\fltMgr.sys

10:59:04.0328 2260 FltMgr - ok

10:59:04.0375 2260 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys

10:59:04.0500 2260 Fs_Rec - ok

10:59:04.0562 2260 Ftdisk (a86859b77b908c18c2657f284aa29fe3) C:\WINDOWS\system32\DRIVERS\ftdisk.sys

10:59:04.0765 2260 Ftdisk - ok

10:59:04.0781 2260 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys

10:59:04.0921 2260 Gpc - ok

10:59:04.0968 2260 hidusb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys

10:59:05.0078 2260 hidusb - ok

10:59:05.0093 2260 hpn - ok

10:59:05.0156 2260 HTTP (c19b522a9ae0bbc3293397f3055e80a1) C:\WINDOWS\system32\Drivers\HTTP.sys

10:59:05.0312 2260 HTTP - ok

10:59:05.0343 2260 i2omgmt - ok

10:59:05.0343 2260 i2omp - ok

10:59:05.0406 2260 i8042prt (d1efcbd693b5ba21314d06368c471070) C:\WINDOWS\system32\DRIVERS\i8042prt.sys

10:59:05.0531 2260 i8042prt - ok

10:59:05.0609 2260 ialm (d4405bd2b6e95efdc8e674ed4032874f) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys

10:59:05.0781 2260 ialm - ok

10:59:05.0968 2260 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys

10:59:06.0125 2260 Imapi - ok

10:59:06.0156 2260 ini910u - ok

10:59:06.0203 2260 IntelIde (1367812f8a974e0c13a4888fa5e7ede6) C:\WINDOWS\system32\DRIVERS\intelide.sys

10:59:06.0375 2260 IntelIde - ok

10:59:06.0421 2260 intelppm (dd5ad1e79ac26d3f8d8828ad4627f160) C:\WINDOWS\system32\DRIVERS\intelppm.sys

10:59:06.0593 2260 intelppm - ok

10:59:06.0625 2260 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys

10:59:06.0796 2260 Ip6Fw - ok

10:59:06.0921 2260 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys

10:59:07.0046 2260 IpFilterDriver - ok

10:59:07.0078 2260 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys

10:59:07.0343 2260 IpInIp - ok

10:59:07.0468 2260 IpNat (b5a8e215ac29d24d60b4d1250ef05ace) C:\WINDOWS\system32\DRIVERS\ipnat.sys

10:59:07.0593 2260 IpNat - ok

10:59:07.0640 2260 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys

10:59:07.0781 2260 IPSec - ok

10:59:07.0843 2260 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys

10:59:07.0953 2260 IRENUM - ok

10:59:08.0046 2260 isapnp (54632f1a7de61dc3615d756f2a90fa72) C:\WINDOWS\system32\DRIVERS\isapnp.sys

10:59:08.0203 2260 isapnp - ok

10:59:08.0234 2260 Kbdclass (e798705e8dc7fab596ef6bfdf167e007) C:\WINDOWS\system32\DRIVERS\kbdclass.sys

10:59:08.0406 2260 Kbdclass - ok

10:59:08.0468 2260 kmixer (d93cad07c5683db066b0b2d2d3790ead) C:\WINDOWS\system32\drivers\kmixer.sys

10:59:08.0656 2260 kmixer - ok

10:59:08.0734 2260 KSecDD (eb7ffe87fd367ea8fca0506f74a87fbb) C:\WINDOWS\system32\drivers\KSecDD.sys

10:59:08.0953 2260 KSecDD - ok

10:59:08.0984 2260 lbrtfdc - ok

10:59:09.0046 2260 MidiSyn (63c34814492aa65fc517b002de77b191) C:\WINDOWS\system32\drivers\MidiSyn.sys

10:59:09.0078 2260 MidiSyn - ok

10:59:09.0125 2260 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys

10:59:09.0296 2260 mnmdd - ok

10:59:09.0453 2260 Modem (5ac7e16f5b40a6da14b5f2b3ada4693e) C:\WINDOWS\system32\drivers\Modem.sys

10:59:09.0578 2260 Modem - ok

10:59:09.0609 2260 Mouclass (7d4f19411bd941e1d432a99e24230386) C:\WINDOWS\system32\DRIVERS\mouclass.sys

10:59:09.0765 2260 Mouclass - ok

10:59:09.0812 2260 mouhid (124d6846040c79b9c997f78ef4b2a4e5) C:\WINDOWS\system32\DRIVERS\mouhid.sys

10:59:09.0953 2260 mouhid - ok

10:59:09.0984 2260 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys

10:59:10.0140 2260 MountMgr - ok

10:59:10.0156 2260 mraid35x - ok

10:59:10.0218 2260 MRxDAV (46edcc8f2db2f322c24f48785cb46366) C:\WINDOWS\system32\DRIVERS\mrxdav.sys

10:59:10.0343 2260 MRxDAV - ok

10:59:10.0406 2260 MRxSmb (1fd607fc67f7f7c633c3da65bfc53d18) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys

10:59:10.0578 2260 MRxSmb - ok

10:59:10.0609 2260 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys

10:59:10.0734 2260 Msfs - ok

10:59:10.0765 2260 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys

10:59:10.0875 2260 MSKSSRV - ok

10:59:10.0937 2260 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys

10:59:11.0062 2260 MSPCLOCK - ok

10:59:11.0109 2260 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys

10:59:11.0343 2260 MSPQM - ok

10:59:11.0468 2260 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys

10:59:11.0593 2260 mssmbios - ok

10:59:11.0640 2260 MSTEE (bf13612142995096ab084f2db7f40f77) C:\WINDOWS\system32\drivers\MSTEE.sys

10:59:11.0781 2260 MSTEE - ok

10:59:11.0812 2260 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys

10:59:12.0000 2260 Mup - ok

10:59:12.0046 2260 NABTSFEC (5c8dc6429c43dc6177c1fa5b76290d1a) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys

10:59:12.0171 2260 NABTSFEC - ok

10:59:12.0250 2260 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys

10:59:12.0390 2260 NDIS - ok

10:59:12.0406 2260 NdisIP (520ce427a8b298f54112857bcf6bde15) C:\WINDOWS\system32\DRIVERS\NdisIP.sys

10:59:12.0578 2260 NdisIP - ok

10:59:12.0625 2260 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys

10:59:12.0765 2260 NdisTapi - ok

10:59:12.0812 2260 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys

10:59:12.0953 2260 Ndisuio - ok

10:59:13.0046 2260 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys

10:59:13.0203 2260 NdisWan - ok

10:59:13.0234 2260 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys

10:59:13.0390 2260 NDProxy - ok

10:59:13.0406 2260 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys

10:59:13.0562 2260 NetBIOS - ok

10:59:13.0593 2260 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys

10:59:13.0750 2260 NetBT - ok

10:59:13.0812 2260 NIC1394 (5c5c53db4fef16cf87b9911c7e8c6fbc) C:\WINDOWS\system32\DRIVERS\nic1394.sys

10:59:14.0000 2260 NIC1394 - ok

10:59:14.0031 2260 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys

10:59:14.0156 2260 Npfs - ok

10:59:14.0203 2260 Nsynas32 (4b4a21e158c039ee0888741bfe1d24e0) C:\WINDOWS\system32\drivers\Nsynas32.sys

10:59:14.0218 2260 Nsynas32 ( UnsignedFile.Multi.Generic ) - warning

10:59:14.0218 2260 Nsynas32 - detected UnsignedFile.Multi.Generic (1)

10:59:14.0265 2260 Ntfs (b78be402c3f63dd55521f73876951cdd) C:\WINDOWS\system32\drivers\Ntfs.sys

10:59:14.0468 2260 Ntfs - ok

10:59:14.0515 2260 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys

10:59:14.0640 2260 Null - ok

10:59:14.0734 2260 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys

10:59:14.0859 2260 NwlnkFlt - ok

10:59:14.0953 2260 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys

10:59:15.0078 2260 NwlnkFwd - ok

10:59:15.0125 2260 ohci1394 (0951db8e5823ea366b0e408d71e1ba2a) C:\WINDOWS\system32\DRIVERS\ohci1394.sys

10:59:15.0234 2260 ohci1394 - ok

10:59:15.0281 2260 Parport (318696359ac7df48d1e51974ec527dd2) C:\WINDOWS\system32\drivers\Parport.sys

10:59:15.0453 2260 Parport - ok

10:59:15.0515 2260 Partizan (6ddcf3f801ec15fe698f6a215cf30a1f) C:\WINDOWS\system32\drivers\Partizan.sys

10:59:15.0562 2260 Partizan - ok

10:59:15.0593 2260 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys

10:59:15.0718 2260 PartMgr - ok

10:59:15.0765 2260 ParVdm (9575c5630db8fb804649a6959737154c) C:\WINDOWS\system32\drivers\ParVdm.sys

10:59:15.0906 2260 ParVdm - ok

10:59:15.0953 2260 PCI (7c5da5c1ed801ad8b0309d5514f0b75e) C:\WINDOWS\system32\DRIVERS\pci.sys

10:59:16.0140 2260 PCI - ok

10:59:16.0203 2260 PCIDump - ok

10:59:16.0218 2260 PCIIde (f4bfde7209c14a07aaa61e4d6ae69eac) C:\WINDOWS\system32\drivers\PCIIde.sys

10:59:16.0421 2260 PCIIde - ok

10:59:16.0468 2260 Pcmcia (641da274e163617ea7a33506bc6da8e3) C:\WINDOWS\system32\DRIVERS\pcmcia.sys

10:59:16.0656 2260 Pcmcia - ok

10:59:16.0671 2260 PDCOMP - ok

10:59:16.0687 2260 PDFRAME - ok

10:59:16.0703 2260 PDRELI - ok

10:59:16.0718 2260 PDRFRAME - ok

10:59:16.0734 2260 perc2 - ok

10:59:16.0750 2260 perc2hib - ok

10:59:16.0812 2260 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys

10:59:16.0984 2260 PptpMiniport - ok

10:59:17.0031 2260 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys

10:59:17.0218 2260 PSched - ok

10:59:17.0250 2260 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys

10:59:17.0421 2260 Ptilink - ok

10:59:17.0500 2260 QCMerced (b607f201293e884f36f9a2ac2c960853) C:\WINDOWS\system32\DRIVERS\LVCM.sys

10:59:17.0593 2260 QCMerced - ok

10:59:17.0609 2260 ql1080 - ok

10:59:17.0625 2260 Ql10wnt - ok

10:59:17.0640 2260 ql12160 - ok

10:59:17.0656 2260 ql1240 - ok

10:59:17.0671 2260 ql1280 - ok

10:59:17.0703 2260 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys

10:59:18.0140 2260 RasAcd - ok

10:59:18.0265 2260 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys

10:59:18.0421 2260 Rasl2tp - ok

10:59:18.0437 2260 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys

10:59:18.0578 2260 RasPppoe - ok

10:59:18.0625 2260 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys

10:59:18.0796 2260 Raspti - ok

10:59:18.0921 2260 Rdbss (29d66245adba878fff574cd66abd2884) C:\WINDOWS\system32\DRIVERS\rdbss.sys

10:59:19.0171 2260 Rdbss - ok

10:59:19.0234 2260 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys

10:59:19.0359 2260 RDPCDD - ok

10:59:19.0437 2260 RDPWD (d4f5643d7714ef499ae9527fdcd50894) C:\WINDOWS\system32\drivers\RDPWD.sys

10:59:19.0562 2260 RDPWD - ok

10:59:19.0609 2260 redbook (2cc30b68dd62b73d444a41322cd7fc4c) C:\WINDOWS\system32\DRIVERS\redbook.sys

10:59:19.0750 2260 redbook - ok

10:59:19.0828 2260 RegGuard (37ecebdd930395a9c399fb18a3c236d3) C:\WINDOWS\system32\Drivers\regguard.sys

10:59:19.0843 2260 RegGuard - ok

10:59:19.0984 2260 RTL8023xp (1e7978c5e355407efdfc7b7328ef13e7) C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys

10:59:20.0187 2260 RTL8023xp - ok

10:59:20.0218 2260 rtl8139 (d507c1400284176573224903819ffda3) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS

10:59:20.0375 2260 rtl8139 - ok

10:59:20.0453 2260 sdbus (02fc71b020ec8700ee8a46c58bc6f276) C:\WINDOWS\system32\DRIVERS\sdbus.sys

10:59:20.0640 2260 sdbus - ok

10:59:20.0703 2260 Secdrv (d26e26ea516450af9d072635c60387f4) C:\WINDOWS\system32\DRIVERS\secdrv.sys

10:59:20.0781 2260 Secdrv - ok

10:59:20.0921 2260 senfilt (9a4c4a4b191200f12085d188be70e4e3) C:\WINDOWS\system32\drivers\senfilt.sys

10:59:20.0984 2260 senfilt - ok

10:59:21.0078 2260 Serial (653201755ca96ab4aaa4131daf6da356) C:\WINDOWS\system32\drivers\Serial.sys

10:59:21.0250 2260 Serial - ok

10:59:21.0312 2260 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys

10:59:21.0500 2260 Sfloppy - ok

10:59:21.0531 2260 Simbad - ok

10:59:21.0578 2260 SLIP (5caeed86821fa2c6139e32e9e05ccdc9) C:\WINDOWS\system32\DRIVERS\SLIP.sys

10:59:21.0765 2260 SLIP - ok

10:59:21.0937 2260 smwdm (014ab093e6452ea88031bb6e22919bb5) C:\WINDOWS\system32\drivers\smwdm.sys

10:59:21.0953 2260 smwdm - ok

10:59:22.0046 2260 SOFTXG (b958ba970b5e623cd714824bc463ed2c) C:\WINDOWS\system32\drivers\sxgxgwdm.sys

10:59:22.0218 2260 SOFTXG - ok

10:59:22.0250 2260 Sparrow - ok

10:59:22.0296 2260 splitter (8e186b8f23295d1e42c573b82b80d548) C:\WINDOWS\system32\drivers\splitter.sys

10:59:22.0484 2260 splitter - ok

10:59:22.0625 2260 sptd (1a606a8d611816adc47d2b25dbedcb1f) C:\WINDOWS\system32\Drivers\sptd.sys

10:59:22.0625 2260 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: 1a606a8d611816adc47d2b25dbedcb1f

10:59:22.0625 2260 sptd ( LockedFile.Multi.Generic ) - warning

10:59:22.0625 2260 sptd - detected LockedFile.Multi.Generic (1)

10:59:22.0671 2260 sr (b52181023b827acda36c1b76751ebffd) C:\WINDOWS\system32\DRIVERS\sr.sys

10:59:22.0812 2260 sr - ok

10:59:22.0937 2260 Srv (20b7e396720353e4117d64d9dcb926ca) C:\WINDOWS\system32\DRIVERS\srv.sys

10:59:23.0093 2260 Srv - ok

10:59:23.0140 2260 streamip (284c57df5dc7abca656bc2b96a667afb) C:\WINDOWS\system32\DRIVERS\StreamIP.sys

10:59:23.0312 2260 streamip - ok

10:59:23.0390 2260 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys

10:59:23.0546 2260 swenum - ok

10:59:23.0625 2260 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys

10:59:23.0828 2260 swmidi - ok

10:59:23.0921 2260 symc810 - ok

10:59:23.0937 2260 symc8xx - ok

10:59:23.0953 2260 sym_hi - ok

10:59:23.0968 2260 sym_u3 - ok

10:59:24.0015 2260 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys

10:59:24.0281 2260 sysaudio - ok

10:59:24.0437 2260 Tcpip (9f4b36614a0fc234525ba224957de55c) C:\WINDOWS\system32\DRIVERS\tcpip.sys

10:59:24.0625 2260 Tcpip - ok

10:59:24.0671 2260 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys

10:59:24.0843 2260 TDPIPE - ok

10:59:24.0953 2260 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys

10:59:25.0218 2260 TDTCP - ok

10:59:25.0296 2260 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys

10:59:25.0609 2260 TermDD - ok

10:59:25.0765 2260 tifm21 (c1cb55968084ff62bf537423bbe0d8d3) C:\WINDOWS\system32\drivers\tifm21.sys

10:59:25.0812 2260 tifm21 - ok

10:59:26.0031 2260 TosIde - ok

10:59:26.0203 2260 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys

10:59:26.0687 2260 Udfs - ok

10:59:26.0750 2260 ultra - ok

10:59:26.0812 2260 Update (aff2e5045961bbc0a602bb6f95eb1345) C:\WINDOWS\system32\DRIVERS\update.sys

10:59:27.0062 2260 Update - ok

10:59:27.0125 2260 usbaudio (45a0d14b26c35497ad93bce7e15c9941) C:\WINDOWS\system32\drivers\usbaudio.sys

10:59:27.0281 2260 usbaudio - ok

10:59:27.0421 2260 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys

10:59:27.0593 2260 usbccgp - ok

10:59:27.0968 2260 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\WINDOWS\system32\DRIVERS\usbehci.sys

10:59:28.0125 2260 usbehci - ok

10:59:28.0171 2260 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys

10:59:28.0343 2260 usbhub - ok

10:59:28.0515 2260 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) C:\WINDOWS\system32\DRIVERS\usbprint.sys

10:59:28.0671 2260 usbprint - ok

10:59:29.0031 2260 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys

10:59:29.0218 2260 usbscan - ok

10:59:29.0390 2260 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS

10:59:29.0609 2260 USBSTOR - ok

10:59:29.0750 2260 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys

10:59:29.0906 2260 usbuhci - ok

10:59:29.0968 2260 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys

10:59:30.0140 2260 VgaSave - ok

10:59:30.0156 2260 ViaIde - ok

10:59:30.0234 2260 vmfilter323 (303f1100f686453de134fe9debb431fc) C:\WINDOWS\system32\drivers\vmfilter323.sys

10:59:30.0281 2260 vmfilter323 ( UnsignedFile.Multi.Generic ) - warning

10:59:30.0281 2260 vmfilter323 - detected UnsignedFile.Multi.Generic (1)

10:59:30.0359 2260 VolSnap (313b1a0d5db26dfe1c34a6c13b2ce0a7) C:\WINDOWS\system32\drivers\VolSnap.sys

10:59:30.0515 2260 VolSnap - ok

10:59:30.0593 2260 vsc32 (f7035815c23df5dad8a686c1cda20f3e) C:\WINDOWS\system32\DRIVERS\vsc.sys

10:59:30.0750 2260 vsc32 ( UnsignedFile.Multi.Generic ) - warning

10:59:30.0750 2260 vsc32 - detected UnsignedFile.Multi.Generic (1)

10:59:31.0296 2260 w29n51 (960ce9b896750cc02fe5f1103cc23460) C:\WINDOWS\system32\DRIVERS\w29n51.sys

10:59:31.0578 2260 w29n51 - ok

10:59:31.0656 2260 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys

10:59:31.0906 2260 Wanarp - ok

10:59:31.0921 2260 WDICA - ok

10:59:32.0000 2260 wdmaud (2797f33ebf50466020c430ee4f037933) C:\WINDOWS\system32\drivers\wdmaud.sys

10:59:32.0140 2260 wdmaud - ok

10:59:32.0218 2260 WmiAcpi (ae2c8544e747c20062db27456ea2d67a) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys

10:59:32.0343 2260 WmiAcpi - ok

10:59:32.0468 2260 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys

10:59:32.0609 2260 WS2IFSL - ok

10:59:32.0656 2260 WSTCODEC (d5842484f05e12121c511aa93f6439ec) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS

10:59:32.0796 2260 WSTCODEC - ok

10:59:32.0921 2260 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys

10:59:32.0984 2260 WudfPf - ok

10:59:33.0031 2260 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys

10:59:33.0062 2260 WudfRd - ok

10:59:33.0125 2260 YFWBUS (54709f2d0c695e5d151e0a4d82391043) C:\WINDOWS\system32\Drivers\yfwbus.sys

10:59:33.0140 2260 YFWBUS ( UnsignedFile.Multi.Generic ) - warning

10:59:33.0140 2260 YFWBUS - detected UnsignedFile.Multi.Generic (1)

10:59:33.0203 2260 ZSMC326 (bb60b37b68385c288229ac5465ab0d4f) C:\WINDOWS\system32\Drivers\usbvm323.sys

10:59:33.0234 2260 ZSMC326 ( UnsignedFile.Multi.Generic ) - warning

10:59:33.0234 2260 ZSMC326 - detected UnsignedFile.Multi.Generic (1)

10:59:33.0281 2260 MBR (0x1B8) (c99c3199cfaa4cbdcd91493f6d113a50) \Device\Harddisk0\DR0

10:59:33.0703 2260 \Device\Harddisk0\DR0 - ok

10:59:33.0718 2260 Boot (0x1200) (57d283b17dbdcdf655e015d832c6acc8) \Device\Harddisk0\DR0\Partition0

10:59:33.0718 2260 \Device\Harddisk0\DR0\Partition0 - ok

10:59:33.0718 2260 ============================================================

10:59:33.0718 2260 Scan finished

10:59:33.0718 2260 ============================================================

10:59:33.0875 3696 Detected object count: 8

10:59:33.0875 3696 Actual detected object count: 8

11:04:07.0703 3696 ASAPIW2K ( UnsignedFile.Multi.Generic ) - skipped by user

11:04:07.0703 3696 ASAPIW2K ( UnsignedFile.Multi.Generic ) - User select action: Skip

11:04:07.0718 3696 CLEDX ( UnsignedFile.Multi.Generic ) - skipped by user

11:04:07.0718 3696 CLEDX ( UnsignedFile.Multi.Generic ) - User select action: Skip

11:04:07.0718 3696 Nsynas32 ( UnsignedFile.Multi.Generic ) - skipped by user

11:04:07.0718 3696 Nsynas32 ( UnsignedFile.Multi.Generic ) - User select action: Skip

11:04:07.0718 3696 sptd ( LockedFile.Multi.Generic ) - skipped by user

11:04:07.0750 3696 sptd ( LockedFile.Multi.Generic ) - User select action: Skip

11:04:07.0750 3696 vmfilter323 ( UnsignedFile.Multi.Generic ) - skipped by user

11:04:07.0750 3696 vmfilter323 ( UnsignedFile.Multi.Generic ) - User select action: Skip

11:04:07.0750 3696 vsc32 ( UnsignedFile.Multi.Generic ) - skipped by user

11:04:07.0750 3696 vsc32 ( UnsignedFile.Multi.Generic ) - User select action: Skip

11:04:07.0765 3696 YFWBUS ( UnsignedFile.Multi.Generic ) - skipped by user

11:04:07.0765 3696 YFWBUS ( UnsignedFile.Multi.Generic ) - User select action: Skip

11:04:07.0765 3696 ZSMC326 ( UnsignedFile.Multi.Generic ) - skipped by user

11:04:07.0765 3696 ZSMC326 ( UnsignedFile.Multi.Generic ) - User select action: Skip

11:04:22.0515 2892 ============================================================

11:04:22.0515 2892 Scan started

11:04:22.0515 2892 Mode: Manual; SigCheck; TDLFS;

11:04:22.0515 2892 ============================================================

11:04:22.0984 2892 Aavmker4 (b6de0336f9f4b687b4ff57939f7b657a) C:\WINDOWS\system32\drivers\Aavmker4.sys

11:04:23.0031 2892 Aavmker4 - ok

11:04:23.0062 2892 Abiosdsk - ok

11:04:23.0078 2892 abp480n5 - ok

11:04:23.0140 2892 ACPI (0bd94fbfc14ea3606cd6ca4c0255baa3) C:\WINDOWS\system32\DRIVERS\ACPI.sys

11:04:23.0500 2892 ACPI - ok

11:04:23.0546 2892 ACPIEC (e4abc1212b70bb03d35e60681c447210) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys

11:04:23.0718 2892 ACPIEC - ok

11:04:23.0734 2892 adpu160m - ok

11:04:23.0781 2892 aeaudio (f13d8e7e1faa31019c25eb17b5fb2662) C:\WINDOWS\system32\drivers\aeaudio.sys

11:04:23.0812 2892 aeaudio - ok

11:04:24.0000 2892 aec (841f385c6cfaf66b58fbd898722bb4f0) C:\WINDOWS\system32\drivers\aec.sys

11:04:24.0125 2892 aec - ok

11:04:24.0156 2892 AFD (5ac495f4cb807b2b98ad2ad591e6d92e) C:\WINDOWS\System32\drivers\afd.sys

11:04:24.0312 2892 AFD - ok

11:04:24.0421 2892 AgereSoftModem (593aefc67283d409f34cc1245d00a509) C:\WINDOWS\system32\DRIVERS\AGRSM.sys

11:04:24.0531 2892 AgereSoftModem - ok

11:04:24.0546 2892 Aha154x - ok

11:04:24.0562 2892 aic78u2 - ok

11:04:24.0578 2892 aic78xx - ok

11:04:24.0609 2892 AliIde - ok

11:04:24.0625 2892 amsint - ok

11:04:24.0671 2892 Arp1394 (f0d692b0bffb46e30eb3cea168bbc49f) C:\WINDOWS\system32\DRIVERS\arp1394.sys

11:04:24.0812 2892 Arp1394 - ok

11:04:24.0937 2892 ASAPIW2K (4f9cbbf95e8f7a0d4c0edcfe3b78102e) C:\WINDOWS\system32\Drivers\ASAPIW2K.sys

11:04:24.0937 2892 ASAPIW2K ( UnsignedFile.Multi.Generic ) - warning

11:04:24.0937 2892 ASAPIW2K - detected UnsignedFile.Multi.Generic (1)

11:04:24.0953 2892 asc - ok

11:04:24.0984 2892 asc3350p - ok

11:04:25.0000 2892 asc3550 - ok

11:04:25.0078 2892 aswFsBlk (054df24c92b55427e0757cfff160e4f2) C:\WINDOWS\system32\drivers\aswFsBlk.sys

11:04:25.0093 2892 aswFsBlk - ok

11:04:25.0125 2892 aswMon2 (ef0e9ad83380724bd6fbbb51d2d0f5b8) C:\WINDOWS\system32\drivers\aswMon2.sys

11:04:25.0140 2892 aswMon2 - ok

11:04:25.0171 2892 aswRdr (352d5a48ebab35a7693b048679304831) C:\WINDOWS\system32\drivers\aswRdr.sys

11:04:25.0187 2892 aswRdr - ok

11:04:25.0265 2892 aswSnx (8d34d2b24297e27d93e847319abfdec4) C:\WINDOWS\system32\drivers\aswSnx.sys

11:04:25.0312 2892 aswSnx - ok

11:04:25.0453 2892 aswSP (010012597333da1f46c3243f33f8409e) C:\WINDOWS\system32\drivers\aswSP.sys

11:04:25.0515 2892 aswSP - ok

11:04:25.0578 2892 aswTdi (f9f84364416658e9786235904d448d37) C:\WINDOWS\system32\drivers\aswTdi.sys

11:04:25.0593 2892 aswTdi - ok

11:04:25.0625 2892 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys

11:04:25.0859 2892 AsyncMac - ok

11:04:25.0937 2892 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys

11:04:26.0187 2892 atapi - ok

11:04:26.0218 2892 Atdisk - ok

11:04:26.0250 2892 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys

11:04:26.0578 2892 Atmarpc - ok

11:04:26.0625 2892 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys

11:04:26.0890 2892 audstub - ok

11:04:26.0984 2892 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys

11:04:27.0109 2892 Beep - ok

11:04:27.0218 2892 BrScnUsb (92a964547b96d697e5e9ed43b4297f5a) C:\WINDOWS\system32\DRIVERS\BrScnUsb.sys

11:04:27.0250 2892 BrScnUsb - ok

11:04:27.0296 2892 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys

11:04:27.0406 2892 cbidf2k - ok

11:04:27.0437 2892 CCDECODE (6163ed60b684bab19d3352ab22fc48b2) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys

11:04:27.0546 2892 CCDECODE - ok

11:04:27.0562 2892 cd20xrnt - ok

11:04:27.0625 2892 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys

11:04:27.0796 2892 Cdaudio - ok

11:04:27.0937 2892 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys

11:04:28.0125 2892 Cdfs - ok

11:04:28.0171 2892 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys

11:04:28.0343 2892 Cdrom - ok

11:04:28.0343 2892 Changer - ok

11:04:28.0390 2892 CLEDX (b53f9635457b56dcffef750e18aec6cb) C:\WINDOWS\system32\DRIVERS\cledx.sys

11:04:28.0421 2892 CLEDX ( UnsignedFile.Multi.Generic ) - warning

11:04:28.0421 2892 CLEDX - detected UnsignedFile.Multi.Generic (1)

11:04:28.0531 2892 CmBatt (4266be808f85826aedf3c64c1e240203) C:\WINDOWS\system32\DRIVERS\CmBatt.sys

11:04:28.0703 2892 CmBatt - ok

11:04:28.0718 2892 CmdIde - ok

11:04:28.0734 2892 Compbatt (df1b1a24bf52d0ebc01ed4ece8979f50) C:\WINDOWS\system32\DRIVERS\compbatt.sys

11:04:28.0921 2892 Compbatt - ok

11:04:28.0953 2892 Cpqarray - ok

11:04:28.0968 2892 dac2w2k - ok

11:04:28.0984 2892 dac960nt - ok

11:04:29.0031 2892 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys

11:04:29.0140 2892 Disk - ok

11:04:29.0203 2892 dmboot (e2d3b7620310fe56685f9b15a6b404b3) C:\WINDOWS\system32\drivers\dmboot.sys

11:04:29.0359 2892 dmboot - ok

11:04:29.0390 2892 dmio (c77f5c20aa70197a69aa84baa9de43c8) C:\WINDOWS\system32\drivers\dmio.sys

11:04:29.0531 2892 dmio - ok

11:04:29.0546 2892 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys

11:04:29.0687 2892 dmload - ok

11:04:29.0734 2892 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys

11:04:29.0859 2892 DMusic - ok

11:04:29.0921 2892 dpti2o - ok

11:04:29.0953 2892 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys

11:04:30.0078 2892 drmkaud - ok

11:04:30.0125 2892 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys

11:04:30.0234 2892 Fastfat - ok

11:04:30.0343 2892 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\drivers\Fdc.sys

11:04:30.0453 2892 Fdc - ok

11:04:30.0500 2892 Fips (8b121ff880683607ab2aef0340721718) C:\WINDOWS\system32\drivers\Fips.sys

11:04:30.0609 2892 Fips - ok

11:04:30.0640 2892 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\drivers\Flpydisk.sys

11:04:30.0984 2892 Flpydisk - ok

11:04:31.0046 2892 FltMgr (157754f0df355a9e0a6f54721914f9c6) C:\WINDOWS\system32\DRIVERS\fltMgr.sys

11:04:31.0203 2892 FltMgr - ok

11:04:31.0265 2892 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys

11:04:31.0468 2892 Fs_Rec - ok

11:04:31.0515 2892 Ftdisk (a86859b77b908c18c2657f284aa29fe3) C:\WINDOWS\system32\DRIVERS\ftdisk.sys

11:04:31.0656 2892 Ftdisk - ok

11:04:31.0671 2892 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys

11:04:31.0812 2892 Gpc - ok

11:04:31.0937 2892 hidusb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys

11:04:32.0046 2892 hidusb - ok

11:04:32.0062 2892 hpn - ok

11:04:32.0109 2892 HTTP (c19b522a9ae0bbc3293397f3055e80a1) C:\WINDOWS\system32\Drivers\HTTP.sys

11:04:32.0234 2892 HTTP - ok

11:04:32.0250 2892 i2omgmt - ok

11:04:32.0265 2892 i2omp - ok

11:04:32.0296 2892 i8042prt (d1efcbd693b5ba21314d06368c471070) C:\WINDOWS\system32\DRIVERS\i8042prt.sys

11:04:32.0421 2892 i8042prt - ok

11:04:32.0562 2892 ialm (d4405bd2b6e95efdc8e674ed4032874f) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys

11:04:32.0593 2892 ialm - ok

11:04:32.0656 2892 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys

11:04:32.0765 2892 Imapi - ok

11:04:32.0796 2892 ini910u - ok

11:04:32.0828 2892 IntelIde (1367812f8a974e0c13a4888fa5e7ede6) C:\WINDOWS\system32\DRIVERS\intelide.sys

11:04:32.0968 2892 IntelIde - ok

11:04:32.0984 2892 intelppm (dd5ad1e79ac26d3f8d8828ad4627f160) C:\WINDOWS\system32\DRIVERS\intelppm.sys

11:04:33.0125 2892 intelppm - ok

11:04:33.0140 2892 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys

11:04:33.0281 2892 Ip6Fw - ok

11:04:33.0312 2892 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys

11:04:33.0453 2892 IpFilterDriver - ok

11:04:33.0484 2892 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys

11:04:33.0593 2892 IpInIp - ok

11:04:33.0625 2892 IpNat (b5a8e215ac29d24d60b4d1250ef05ace) C:\WINDOWS\system32\DRIVERS\ipnat.sys

11:04:33.0796 2892 IpNat - ok

11:04:33.0828 2892 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys

11:04:33.0937 2892 IPSec - ok

11:04:33.0984 2892 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys

11:04:34.0031 2892 IRENUM - ok

11:04:34.0156 2892 isapnp (54632f1a7de61dc3615d756f2a90fa72) C:\WINDOWS\system32\DRIVERS\isapnp.sys

11:04:34.0281 2892 isapnp - ok

11:04:34.0328 2892 Kbdclass (e798705e8dc7fab596ef6bfdf167e007) C:\WINDOWS\system32\DRIVERS\kbdclass.sys

11:04:34.0468 2892 Kbdclass - ok

11:04:34.0515 2892 kmixer (d93cad07c5683db066b0b2d2d3790ead) C:\WINDOWS\system32\drivers\kmixer.sys

11:04:34.0640 2892 kmixer - ok

11:04:34.0687 2892 KSecDD (eb7ffe87fd367ea8fca0506f74a87fbb) C:\WINDOWS\system32\drivers\KSecDD.sys

11:04:34.0843 2892 KSecDD - ok

11:04:34.0921 2892 lbrtfdc - ok

11:04:34.0984 2892 MidiSyn (63c34814492aa65fc517b002de77b191) C:\WINDOWS\system32\drivers\MidiSyn.sys

11:04:35.0015 2892 MidiSyn - ok

11:04:35.0062 2892 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys

11:04:35.0203 2892 mnmdd - ok

11:04:35.0296 2892 Modem (5ac7e16f5b40a6da14b5f2b3ada4693e) C:\WINDOWS\system32\drivers\Modem.sys

11:04:35.0437 2892 Modem - ok

11:04:35.0468 2892 Mouclass (7d4f19411bd941e1d432a99e24230386) C:\WINDOWS\system32\DRIVERS\mouclass.sys

11:04:35.0593 2892 Mouclass - ok

11:04:35.0625 2892 mouhid (124d6846040c79b9c997f78ef4b2a4e5) C:\WINDOWS\system32\DRIVERS\mouhid.sys

11:04:35.0765 2892 mouhid - ok

11:04:35.0796 2892 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys

11:04:35.0921 2892 MountMgr - ok

11:04:35.0953 2892 mraid35x - ok

11:04:36.0031 2892 MRxDAV (46edcc8f2db2f322c24f48785cb46366) C:\WINDOWS\system32\DRIVERS\mrxdav.sys

11:04:36.0171 2892 MRxDAV - ok

11:04:36.0343 2892 MRxSmb (1fd607fc67f7f7c633c3da65bfc53d18) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys

11:04:36.0500 2892 MRxSmb - ok

11:04:36.0765 2892 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys

11:04:36.0921 2892 Msfs - ok

11:04:36.0968 2892 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys

11:04:37.0125 2892 MSKSSRV - ok

11:04:37.0171 2892 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys

11:04:37.0343 2892 MSPCLOCK - ok

11:04:37.0359 2892 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys

11:04:37.0515 2892 MSPQM - ok

11:04:37.0734 2892 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys

11:04:37.0859 2892 mssmbios - ok

11:04:38.0250 2892 MSTEE (bf13612142995096ab084f2db7f40f77) C:\WINDOWS\system32\drivers\MSTEE.sys

11:04:38.0546 2892 MSTEE - ok

11:04:38.0625 2892 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys

11:04:38.0765 2892 Mup - ok

11:04:38.0968 2892 NABTSFEC (5c8dc6429c43dc6177c1fa5b76290d1a) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys

11:04:39.0109 2892 NABTSFEC - ok

11:04:39.0437 2892 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys

11:04:39.0562 2892 NDIS - ok

11:04:39.0593 2892 NdisIP (520ce427a8b298f54112857bcf6bde15) C:\WINDOWS\system32\DRIVERS\NdisIP.sys

11:04:39.0750 2892 NdisIP - ok

11:04:39.0812 2892 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys

11:04:39.0968 2892 NdisTapi - ok

11:04:40.0015 2892 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys

11:04:40.0171 2892 Ndisuio - ok

11:04:40.0234 2892 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys

11:04:40.0359 2892 NdisWan - ok

11:04:40.0406 2892 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys

11:04:40.0546 2892 NDProxy - ok

11:04:40.0609 2892 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys

11:04:40.0734 2892 NetBIOS - ok

11:04:40.0796 2892 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys

11:04:40.0937 2892 NetBT - ok

11:04:41.0015 2892 NIC1394 (5c5c53db4fef16cf87b9911c7e8c6fbc) C:\WINDOWS\system32\DRIVERS\nic1394.sys

11:04:41.0171 2892 NIC1394 - ok

11:04:41.0187 2892 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys

11:04:41.0328 2892 Npfs - ok

11:04:41.0375 2892 Nsynas32 (4b4a21e158c039ee0888741bfe1d24e0) C:\WINDOWS\system32\drivers\Nsynas32.sys

11:04:41.0390 2892 Nsynas32 ( UnsignedFile.Multi.Generic ) - warning

11:04:41.0390 2892 Nsynas32 - detected UnsignedFile.Multi.Generic (1)

11:04:41.0453 2892 Ntfs (b78be402c3f63dd55521f73876951cdd) C:\WINDOWS\system32\drivers\Ntfs.sys

11:04:41.0609 2892 Ntfs - ok

11:04:41.0656 2892 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys

11:04:41.0796 2892 Null - ok

11:04:41.0828 2892 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys

11:04:42.0000 2892 NwlnkFlt - ok

11:04:42.0062 2892 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys

11:04:42.0218 2892 NwlnkFwd - ok

11:04:42.0250 2892 ohci1394 (0951db8e5823ea366b0e408d71e1ba2a) C:\WINDOWS\system32\DRIVERS\ohci1394.sys

11:04:42.0421 2892 ohci1394 - ok

11:04:42.0500 2892 Parport (318696359ac7df48d1e51974ec527dd2) C:\WINDOWS\system32\drivers\Parport.sys

11:04:42.0671 2892 Parport - ok

11:04:42.0750 2892 Partizan (6ddcf3f801ec15fe698f6a215cf30a1f) C:\WINDOWS\system32\drivers\Partizan.sys

11:04:42.0765 2892 Partizan - ok

11:04:42.0781 2892 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys

11:04:42.0937 2892 PartMgr - ok

11:04:42.0968 2892 ParVdm (9575c5630db8fb804649a6959737154c) C:\WINDOWS\system32\drivers\ParVdm.sys

11:04:43.0125 2892 ParVdm - ok

11:04:43.0203 2892 PCI (7c5da5c1ed801ad8b0309d5514f0b75e) C:\WINDOWS\system32\DRIVERS\pci.sys

11:04:43.0375 2892 PCI - ok

11:04:43.0390 2892 PCIDump - ok

11:04:43.0421 2892 PCIIde (f4bfde7209c14a07aaa61e4d6ae69eac) C:\WINDOWS\system32\drivers\PCIIde.sys

11:04:43.0578 2892 PCIIde - ok

11:04:43.0609 2892 Pcmcia (641da274e163617ea7a33506bc6da8e3) C:\WINDOWS\system32\DRIVERS\pcmcia.sys

11:04:43.0781 2892 Pcmcia - ok

11:04:43.0828 2892 PDCOMP - ok

11:04:43.0843 2892 PDFRAME - ok

11:04:43.0921 2892 PDRELI - ok

11:04:43.0937 2892 PDRFRAME - ok

11:04:43.0953 2892 perc2 - ok

11:04:43.0968 2892 perc2hib - ok

11:04:44.0015 2892 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys

11:04:44.0125 2892 PptpMiniport - ok

11:04:44.0171 2892 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys

11:04:44.0296 2892 PSched - ok

11:04:44.0328 2892 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys

11:04:44.0437 2892 Ptilink - ok

11:04:44.0531 2892 QCMerced (b607f201293e884f36f9a2ac2c960853) C:\WINDOWS\system32\DRIVERS\LVCM.sys

11:04:44.0578 2892 QCMerced - ok

11:04:44.0593 2892 ql1080 - ok

11:04:44.0609 2892 Ql10wnt - ok

11:04:44.0625 2892 ql12160 - ok

11:04:44.0656 2892 ql1240 - ok

11:04:44.0671 2892 ql1280 - ok

11:04:44.0687 2892 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys

11:04:44.0796 2892 RasAcd - ok

11:04:44.0921 2892 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys

11:04:45.0062 2892 Rasl2tp - ok

11:04:45.0109 2892 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys

11:04:45.0250 2892 RasPppoe - ok

11:04:45.0265 2892 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys

11:04:45.0390 2892 Raspti - ok

11:04:45.0421 2892 Rdbss (29d66245adba878fff574cd66abd2884) C:\WINDOWS\system32\DRIVERS\rdbss.sys

11:04:45.0562 2892 Rdbss - ok

11:04:45.0578 2892 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys

11:04:45.0718 2892 RDPCDD - ok

11:04:45.0812 2892 RDPWD (d4f5643d7714ef499ae9527fdcd50894) C:\WINDOWS\system32\drivers\RDPWD.sys

11:04:45.0921 2892 RDPWD - ok

11:04:45.0968 2892 redbook (2cc30b68dd62b73d444a41322cd7fc4c) C:\WINDOWS\system32\DRIVERS\redbook.sys

11:04:46.0078 2892 redbook - ok

11:04:46.0156 2892 RegGuard (37ecebdd930395a9c399fb18a3c236d3) C:\WINDOWS\system32\Drivers\regguard.sys

11:04:46.0156 2892 RegGuard - ok

11:04:46.0218 2892 RTL8023xp (1e7978c5e355407efdfc7b7328ef13e7) C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys

11:04:46.0265 2892 RTL8023xp - ok

11:04:46.0328 2892 rtl8139 (d507c1400284176573224903819ffda3) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS

11:04:46.0437 2892 rtl8139 - ok

11:04:46.0484 2892 sdbus (02fc71b020ec8700ee8a46c58bc6f276) C:\WINDOWS\system32\DRIVERS\sdbus.sys

11:04:46.0625 2892 sdbus - ok

11:04:46.0687 2892 Secdrv (d26e26ea516450af9d072635c60387f4) C:\WINDOWS\system32\DRIVERS\secdrv.sys

11:04:46.0750 2892 Secdrv - ok

11:04:46.0921 2892 senfilt (9a4c4a4b191200f12085d188be70e4e3) C:\WINDOWS\system32\drivers\senfilt.sys

11:04:46.0984 2892 senfilt - ok

11:04:47.0062 2892 Serial (653201755ca96ab4aaa4131daf6da356) C:\WINDOWS\system32\drivers\Serial.sys

11:04:47.0203 2892 Serial - ok

11:04:47.0250 2892 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys

11:04:47.0406 2892 Sfloppy - ok

11:04:47.0437 2892 Simbad - ok

11:04:47.0484 2892 SLIP (5caeed86821fa2c6139e32e9e05ccdc9) C:\WINDOWS\system32\DRIVERS\SLIP.sys

11:04:47.0640 2892 SLIP - ok

11:04:47.0718 2892 smwdm (014ab093e6452ea88031bb6e22919bb5) C:\WINDOWS\system32\drivers\smwdm.sys

11:04:47.0750 2892 smwdm - ok

11:04:47.0828 2892 SOFTXG (b958ba970b5e623cd714824bc463ed2c) C:\WINDOWS\system32\drivers\sxgxgwdm.sys

11:04:47.0968 2892 SOFTXG - ok

11:04:48.0015 2892 Sparrow - ok

11:04:48.0093 2892 splitter (8e186b8f23295d1e42c573b82b80d548) C:\WINDOWS\system32\drivers\splitter.sys

11:04:48.0265 2892 splitter - ok

11:04:48.0375 2892 sptd (1a606a8d611816adc47d2b25dbedcb1f) C:\WINDOWS\system32\Drivers\sptd.sys

11:04:48.0375 2892 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: 1a606a8d611816adc47d2b25dbedcb1f

11:04:48.0375 2892 sptd ( LockedFile.Multi.Generic ) - warning

11:04:48.0375 2892 sptd - detected LockedFile.Multi.Generic (1)

11:04:48.0453 2892 sr (b52181023b827acda36c1b76751ebffd) C:\WINDOWS\system32\DRIVERS\sr.sys

11:04:48.0562 2892 sr - ok

11:04:48.0609 2892 Srv (20b7e396720353e4117d64d9dcb926ca) C:\WINDOWS\system32\DRIVERS\srv.sys

11:04:48.0734 2892 Srv - ok

11:04:48.0812 2892 streamip (284c57df5dc7abca656bc2b96a667afb) C:\WINDOWS\system32\DRIVERS\StreamIP.sys

11:04:48.0937 2892 streamip - ok

11:04:48.0984 2892 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys

11:04:49.0109 2892 swenum - ok

11:04:49.0140 2892 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys

11:04:49.0281 2892 swmidi - ok

11:04:49.0359 2892 symc810 - ok

11:04:49.0375 2892 symc8xx - ok

11:04:49.0390 2892 sym_hi - ok

11:04:49.0406 2892 sym_u3 - ok

11:04:49.0453 2892 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys

11:04:49.0578 2892 sysaudio - ok

11:04:49.0656 2892 Tcpip (9f4b36614a0fc234525ba224957de55c) C:\WINDOWS\system32\DRIVERS\tcpip.sys

11:04:49.0781 2892 Tcpip - ok

11:04:49.0859 2892 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys

11:04:50.0000 2892 TDPIPE - ok

11:04:50.0046 2892 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys

11:04:50.0187 2892 TDTCP - ok

11:04:50.0234 2892 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys

11:04:50.0375 2892 TermDD - ok

11:04:50.0421 2892 tifm21 (c1cb55968084ff62bf537423bbe0d8d3) C:\WINDOWS\system32\drivers\tifm21.sys

11:04:50.0437 2892 tifm21 - ok

11:04:50.0468 2892 TosIde - ok

11:04:50.0515 2892 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys

11:04:50.0671 2892 Udfs - ok

11:04:50.0734 2892 ultra - ok

11:04:50.0765 2892 Update (aff2e5045961bbc0a602bb6f95eb1345) C:\WINDOWS\system32\DRIVERS\update.sys

11:04:50.0906 2892 Update - ok

11:04:50.0968 2892 usbaudio (45a0d14b26c35497ad93bce7e15c9941) C:\WINDOWS\system32\drivers\usbaudio.sys

11:04:51.0125 2892 usbaudio - ok

11:04:51.0171 2892 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys

11:04:51.0296 2892 usbccgp - ok

11:04:51.0359 2892 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\WINDOWS\system32\DRIVERS\usbehci.sys

11:04:51.0484 2892 usbehci - ok

11:04:51.0546 2892 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys

11:04:51.0687 2892 usbhub - ok

11:04:51.0734 2892 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) C:\WINDOWS\system32\DRIVERS\usbprint.sys

11:04:51.0859 2892 usbprint - ok

11:04:51.0953 2892 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys

11:04:52.0078 2892 usbscan - ok

11:04:52.0171 2892 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS

11:04:52.0312 2892 USBSTOR - ok

11:04:52.0343 2892 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys

11:04:52.0484 2892 usbuhci - ok

11:04:52.0515 2892 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys

11:04:52.0671 2892 VgaSave - ok

11:04:52.0718 2892 ViaIde - ok

11:04:52.0781 2892 vmfilter323 (303f1100f686453de134fe9debb431fc) C:\WINDOWS\system32\drivers\vmfilter323.sys

11:04:52.0812 2892 vmfilter323 ( UnsignedFile.Multi.Generic ) - warning

11:04:52.0812 2892 vmfilter323 - detected UnsignedFile.Multi.Generic (1)

11:04:52.0984 2892 VolSnap (313b1a0d5db26dfe1c34a6c13b2ce0a7) C:\WINDOWS\system32\drivers\VolSnap.sys

11:04:53.0109 2892 VolSnap - ok

11:04:53.0203 2892 vsc32 (f7035815c23df5dad8a686c1cda20f3e) C:\WINDOWS\system32\DRIVERS\vsc.sys

11:04:53.0296 2892 vsc32 ( UnsignedFile.Multi.Generic ) - warning

11:04:53.0296 2892 vsc32 - detected UnsignedFile.Multi.Generic (1)

11:04:53.0515 2892 w29n51 (960ce9b896750cc02fe5f1103cc23460) C:\WINDOWS\system32\DRIVERS\w29n51.sys

11:04:53.0750 2892 w29n51 - ok

11:04:53.0953 2892 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys

11:04:54.0171 2892 Wanarp - ok

11:04:54.0187 2892 WDICA - ok

11:04:54.0234 2892 wdmaud (2797f33ebf50466020c430ee4f037933) C:\WINDOWS\system32\drivers\wdmaud.sys

11:04:54.0359 2892 wdmaud - ok

11:04:54.0453 2892 WmiAcpi (ae2c8544e747c20062db27456ea2d67a) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys

11:04:54.0578 2892 WmiAcpi - ok

11:04:54.0640 2892 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys

11:04:54.0765 2892 WS2IFSL - ok

11:04:54.0812 2892 WSTCODEC (d5842484f05e12121c511aa93f6439ec) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS

11:04:54.0921 2892 WSTCODEC - ok

11:04:54.0968 2892 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys

11:04:55.0000 2892 WudfPf - ok

11:04:55.0078 2892 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys

11:04:55.0109 2892 WudfRd - ok

11:04:55.0171 2892 YFWBUS (54709f2d0c695e5d151e0a4d82391043) C:\WINDOWS\system32\Drivers\yfwbus.sys

11:04:55.0203 2892 YFWBUS ( UnsignedFile.Multi.Generic ) - warning

11:04:55.0203 2892 YFWBUS - detected UnsignedFile.Multi.Generic (1)

11:04:55.0250 2892 ZSMC326 (bb60b37b68385c288229ac5465ab0d4f) C:\WINDOWS\system32\Drivers\usbvm323.sys

11:04:55.0281 2892 ZSMC326 ( UnsignedFile.Multi.Generic ) - warning

11:04:55.0281 2892 ZSMC326 - detected UnsignedFile.Multi.Generic (1)

11:04:55.0328 2892 MBR (0x1B8) (c99c3199cfaa4cbdcd91493f6d113a50) \Device\Harddisk0\DR0

11:04:55.0703 2892 \Device\Harddisk0\DR0 - ok

11:04:55.0703 2892 Boot (0x1200) (57d283b17dbdcdf655e015d832c6acc8) \Device\Harddisk0\DR0\Partition0

11:04:55.0718 2892 \Device\Harddisk0\DR0\Partition0 - ok

11:04:55.0718 2892 ============================================================

11:04:55.0718 2892 Scan finished

11:04:55.0718 2892 ============================================================

11:04:55.0734 0936 Detected object count: 8

11:04:55.0750 0936 Actual detected object count: 8

11:05:14.0609 0936 ASAPIW2K ( UnsignedFile.Multi.Generic ) - skipped by user

11:05:14.0609 0936 ASAPIW2K ( UnsignedFile.Multi.Generic ) - User select action: Skip

11:05:14.0640 0936 CLEDX ( UnsignedFile.Multi.Generic ) - skipped by user

11:05:14.0640 0936 CLEDX ( UnsignedFile.Multi.Generic ) - User select action: Skip

11:05:14.0640 0936 Nsynas32 ( UnsignedFile.Multi.Generic ) - skipped by user

11:05:14.0640 0936 Nsynas32 ( UnsignedFile.Multi.Generic ) - User select action: Skip

11:05:14.0640 0936 sptd ( LockedFile.Multi.Generic ) - skipped by user

11:05:14.0640 0936 sptd ( LockedFile.Multi.Generic ) - User select action: Skip

11:05:14.0671 0936 vmfilter323 ( UnsignedFile.Multi.Generic ) - skipped by user

11:05:14.0671 0936 vmfilter323 ( UnsignedFile.Multi.Generic ) - User select action: Skip

11:05:14.0671 0936 vsc32 ( UnsignedFile.Multi.Generic ) - skipped by user

11:05:14.0671 0936 vsc32 ( UnsignedFile.Multi.Generic ) - User select action: Skip

11:05:14.0671 0936 YFWBUS ( UnsignedFile.Multi.Generic ) - skipped by user

11:05:14.0671 0936 YFWBUS ( UnsignedFile.Multi.Generic ) - User select action: Skip

11:05:14.0703 0936 ZSMC326 ( UnsignedFile.Multi.Generic ) - skipped by user

11:05:14.0703 0936 ZSMC326 ( UnsignedFile.Multi.Generic ) - User select action: Skip

11:05:26.0531 3076 Deinitialize success

Третия също го поствам защото ми дава грешка -такъв файл не може да бъде прикачван

GMER 1.0.15.15641 - http://www.gmer.net

Rootkit scan 2012-01-31 17:34:03

Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 WDC_WD1000VE-00KWT0 rev.01.03K01

Running: gmer.exe; Driver: C:\DOCUME~1\GR\LOCALS~1\Temp\pfdcqfod.sys

---- System - GMER 1.0.15 ----

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0xAA50AFC4]

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwAllocateVirtualMemory [0xAA56F510]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwClose [0xAA52E6A9]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0xAA50D456]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0xAA50D4AE]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0xAA50D5C4]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateKey [0xAA52E05D]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0xAA50D3AC]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSection [0xAA50D4FE]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0xAA50D400]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0xAA50D572]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0xAA50AFE8]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteKey [0xAA52ED6F]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteValueKey [0xAA52F025]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDuplicateObject [0xAA50D848]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwEnumerateKey [0xAA52EBDA]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwEnumerateValueKey [0xAA52EA45]

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwFreeVirtualMemory [0xAA56F5C0]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0xAA50ADB2]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0xAA50B00C]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0xAA50D9BC]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0xAA50BAA4]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0xAA50D486]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0xAA50D4D6]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0xAA50D5EE]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenKey [0xAA52E3B9]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0xAA50D3D8]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenProcess [0xAA50D680]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0xAA50D53E]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0xAA50D42E]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenThread [0xAA50D764]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0xAA50D59C]

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwProtectVirtualMemory [0xAA56F658]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryKey [0xAA52E8C0]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0xAA50B96A]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryValueKey [0xAA52E712]

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwRenameKey [0xAA5779E6]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwRestoreKey [0xAA52D6D0]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0xAA50B030]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0xAA50B054]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0xAA50AE0C]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0xAA50AF48]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetValueKey [0xAA52EE76]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0xAA50AF24]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSystemDebugControl [0xAA50AF6C]

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0xAA50B078]

INT 0x62 ? 82D8BBF8

INT 0x74 ? 82BEAF00

INT 0x84 ? 82BEAF00

INT 0x94 ? 82BEAF00

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Ntfs \Ntfs 82D891F8

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/AVAST Software)

AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)

Device \Driver\usbuhci \Device\USBPDO-0 82BED500

Device \Driver\usbuhci \Device\USBPDO-1 82BED500

Device \Driver\usbuhci \Device\USBPDO-2 82BED500

Device \Driver\usbuhci \Device\USBPDO-3 82BED500

Device \Driver\usbehci \Device\USBPDO-4 82C1E1F8

AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)

Device \Driver\Ftdisk \Device\HarddiskVolume1 82D8C1F8

Device \Driver\Cdrom \Device\CdRom0 82937500

Device \Driver\Ftdisk \Device\HarddiskVolume2 82D8C1F8

Device \Driver\atapi \Device\Ide\IdePort0 82D8B1F8

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 82D8B1F8

Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c 82D8B1F8

Device \Driver\NetBT \Device\NetBT_Tcpip_{AB035857-5293-4C67-8D41-8B8C1984C2FD} 820891F8

Device \Driver\NetBT \Device\NetBt_Wins_Export 820891F8

Device \Driver\NetBT \Device\NetbiosSmb 820891F8

AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)

AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)

Device \Driver\usbuhci \Device\USBFDO-0 82BED500

Device \Driver\usbuhci \Device\USBFDO-1 82BED500

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 81FE31F8

Device \Driver\usbuhci \Device\USBFDO-2 82BED500

Device \FileSystem\MRxSmb \Device\LanmanRedirector 81FE31F8

Device \Driver\usbuhci \Device\USBFDO-3 82BED500

Device \Driver\usbehci \Device\USBFDO-4 82C1E1F8

Device \Driver\Ftdisk \Device\FtControl 82D8C1F8

Device \FileSystem\Cdfs \Cdfs 82BA21F8

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792

---- EOF - GMER 1.0.15 ----

Благодаря

От предоставените логове не се виждат притеснителни неща...!Генералния въпрос е stdrt.exe и той още тормози ли системата ви..?

Стартирайте отново OTL и направете сканиране със същите настройки ...Този път обаче вместо Run Fix натиснете бутона Публикувано изображение...Ще се създаде лог файл. Публикувайте съдържанието му с Copy/Paste в следващия си коментар.

  • Автор

Не, наистина системата се зарежда нормално без саунд картата да е изключена и да не може да се включи,нито се появява в течение на работа

Ето искания лог -всъщност извади два лога,не знам защо-публикувам ги и двата

OTL.Txt

и втория

OTL Extras logfile created on: 01/02/2012 04:45:08 - Run 1

OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\GR\Bureau

Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy

502,42 Mb Total Physical Memory | 136,63 Mb Available Physical Memory | 27,19% Memory free

1,19 Gb Paging File | 0,84 Gb Available in Paging File | 71,03% Paging File free

Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 92,86 Gb Total Space | 77,27 Gb Free Space | 83,21% Space Free | Partition Type: NTFS

Computer Name: GR-E99077D3BD63 | User Name: GR | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users | Quick Scan

Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l

[HKEY_USERS\S-1-5-21-1417001333-1767777339-725345543-1004\SOFTWARE\Classes\<extension>]

.html [@ = htmlfile] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

exefile [open] -- "%1" %*

htmlfile [edit] -- Reg Error: Key error.

InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [Add to archive] -- "C:\Program Files\PeaZip\PEAZIP.EXE" "-add2multi" "%1" (Giorgio Tani)

Directory [browse path with PeaZip] -- "C:\Program Files\PeaZip\PEAZIP.EXE" "-ext2browsepath" "%1" (Giorgio Tani)

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"FirstRunDisabled" = 1

"AntiVirusDisableNotify" = 0

"FirewallDisableNotify" = 0

"UpdatesDisableNotify" = 0

"AntiVirusOverride" = 0

"FirewallOverride" = 0

"AntiSpywareOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

"AntiVirusOverride" = 0

"AntiSpywareOverride" = 0

"FirewallOverride" = 0

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]

"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]

"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]

"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"EnableFirewall" = 1

"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

"8000:UDP" = 8000:UDP:*:Enabled:Express Talk RTP Incoming Audio (UDP)

"8001:UDP" = 8001:UDP:*:Enabled:Express Talk RTP Incoming Audio (UDP)

"8002:UDP" = 8002:UDP:*:Enabled:Express Talk RTP Incoming Audio (UDP)

"8003:UDP" = 8003:UDP:*:Enabled:Express Talk RTP Incoming Audio (UDP)

"8004:UDP" = 8004:UDP:*:Enabled:Express Talk RTP Incoming Audio (UDP)

"8005:UDP" = 8005:UDP:*:Enabled:Express Talk RTP Incoming Audio (UDP)

"8006:UDP" = 8006:UDP:*:Enabled:Express Talk RTP Incoming Audio (UDP)

"8007:UDP" = 8007:UDP:*:Enabled:Express Talk RTP Incoming Audio (UDP)

"8008:UDP" = 8008:UDP:*:Enabled:Express Talk RTP Incoming Audio (UDP)

"8009:UDP" = 8009:UDP:*:Enabled:Express Talk RTP Incoming Audio (UDP)

"5070:UDP" = 5070:UDP:*:Enabled:Express Talk Sip Incoming Calls (UDP)

"10950:TCP" = 10950:TCP:*:Enabled:Inhatch P2P Streaming

"10951:TCP" = 10951:TCP:*:Enabled:Inhatch P2P Streaming

"10952:TCP" = 10952:TCP:*:Enabled:Inhatch P2P Streaming

"10953:TCP" = 10953:TCP:*:Enabled:Inhatch P2P Streaming

"49780:UDP" = 49780:UDP:*:Enabled:Inhatch P2P Streaming

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

"C:\Program Files\TVUPlayer\TVUPlayer.exe" = C:\Program Files\TVUPlayer\TVUPlayer.exe:*:Enabled:TVUPlayer Component -- (TVU networks)

"C:\Program Files\FreePhoneLine\FreePhoneLine.exe" = C:\Program Files\FreePhoneLine\FreePhoneLine.exe:*:Enabled:FreePhoneLine 3.0.1 © freephoneline.ca, Inc, 2007 -- (freephoneline.ca)

"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java Platform SE binary -- (Sun Microsystems, Inc.)

"C:\Documents and Settings\GR\Bureau\Whistle.exe" = C:\Documents and Settings\GR\Bureau\Whistle.exe:*:Enabled:Whistle -- (Vail Systems, Inc.)

"C:\Program Files\iCall\iCall.exe" = C:\Program Files\iCall\iCall.exe:*:Enabled:iCall Internet Phone -- ()

"C:\Program Files\SopCast\adv\SopAdver.exe" = C:\Program Files\SopCast\adv\SopAdver.exe:*:Enabled:SopCast Adver -- (www.sopcast.com)

"C:\Program Files\SopCast\SopCast.exe" = C:\Program Files\SopCast\SopCast.exe:*:Enabled:SopCast Main Application -- (www.sopcast.com)

"C:\Program Files\StreamTorrent 1.0\StreamTorrent.exe" = C:\Program Files\StreamTorrent 1.0\StreamTorrent.exe:*:Enabled:StreamTorrent Media Player -- (StreamTorrent)

"C:\Program Files\TVants\Tvants.exe" = C:\Program Files\TVants\Tvants.exe:*:Enabled:TVAnts -- (Zhejiang University)

"C:\Program Files\VoipBusterPro.com\VoipBusterPro\VoipBusterPro.exe" = C:\Program Files\VoipBusterPro.com\VoipBusterPro\VoipBusterPro.exe:*:Enabled:VoipBuster Pro -- (VoipBusterPro)

"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{02570AE0-BEE0-4A6C-BE3F-D806E9F2EA17}" = ScanSoft PaperPort 11

"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86

"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86

"{1E76EB6E-E390-11DF-95DB-005056C00008}" = MSVCRT Redists

"{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java 6 Update 24

"{2BC2781A-F7F6-452E-95EB-018A522F1B2C}" = PaperPort Image Printer

"{350C940c-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP

"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater

"{5A2BC38A-406C-4A5B-BF45-6991F9A05325}_is1" = PeaZip 4.2

"{5CF6EEE9-86B1-3DB6-A07C-8F6C079C39BA}" = Google Talk Plugin

"{5D074D7B-FDFB-4E82-8F7E-C8FE0BF9AAB2}" = Whistle

"{5EDDAC50-0D62-45CC-9605-93E996F1D181}" = Freephoneline

"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86

"{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}" = Brother MFL-Pro Suite MFC-295CN

"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver for Mobile

"{8A7E941F-2BB4-47D0-B732-8AE5F3513B68}" = ASAPI

"{94FB906A-CF42-4128-A509-D353026A607E}" = REALTEK Gigabit and Fast Ethernet NIC Driver

"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

"{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1" = PDF-Viewer

"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5

"{AC40B4EF-135F-4D3F-8D11-F47824680BBB}" = Bulgarian (Phonetic) - Custom

"{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86

"{B713000F-FBE3-11D3-9D91-0050DA5C3DCF}" = YAMAHA XG SoftSynthesizer S-YXG50

"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX

"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX

"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin

"Agere Systems Soft Modem" = Agere Systems AC'97 Modem

"ASIO4ALL" = ASIO4ALL

"avast" = avast! Free Antivirus

"Broadcom 802.11b Network Adapter" = Broadcom 802.11 Driver

"FL Studio 10" = FL Studio 10

"ie8" = Windows Internet Explorer 8

"IL Download Manager" = IL Download Manager

"Inhatch web plugins" = Inhatch web plugins

"Le Petit Robert" = Désinstaller Le Petit Robert de la langue française

"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.0.1800

"Mozilla Firefox 7.0 (x86 bg)" = Mozilla Firefox 7.0 (x86 bg)

"MuseScore" = MuseScore 1.1 MuseScore score typesetter

"Revo Uninstaller" = Revo Uninstaller 1.92

"SopCast" = SopCast 3.3.2

"StarBurn_is1" = StarBurn Version 13 (Build 0x20110818)

"StreamTorrent 1.0" = StreamTorrent 1.0

"TVAnts 1.0" = TVAnts 1.0

"UnHackMe_is1" = UnHackMe 5.99 release

"Unlocker" = Unlocker 1.9.1

"uTorrent" = µTorrent

"Veetle TV" = Veetle TV 0.9.18

"VoipBusterPro_is1" = VoipBusterPro

"VSC32" = Virtual Sound Canvas 3.2

"Waves Mercury Complete VST DX RTAS_is1" = Waves Mercury Complete VST DX RTAS v1.01

"Windows Media Format Runtime" = Windows Media Format 11 runtime

"WinRAR archiver" = WinRAR 4.00 (32 bits)

"Wise Disk Cleaner_is1" = Wise Disk Cleaner 6.31

"Wise Registry Cleaner_is1" = Wise Registry Cleaner 6.21

========== Last 10 Event Log Errors ==========

[ Application Events ]

Error - 27/01/2012 14:20:32 | Computer Name = GR-E99077D3BD63 | Source = VSC32 | ID = 327806

Description = This format is not supported by VSC WAVE device. [This is illegal

frequency]

Error - 27/01/2012 14:22:21 | Computer Name = GR-E99077D3BD63 | Source = VSC32 | ID = 327806

Description = This format is not supported by VSC WAVE device. [This is illegal

frequency]

Error - 27/01/2012 14:22:21 | Computer Name = GR-E99077D3BD63 | Source = VSC32 | ID = 327806

Description = This format is not supported by VSC WAVE device. [This is illegal

frequency]

Error - 27/01/2012 19:19:04 | Computer Name = GR-E99077D3BD63 | Source = VSC32 | ID = 327806

Description = This format is not supported by VSC WAVE device. [This is illegal

frequency]

Error - 27/01/2012 19:19:04 | Computer Name = GR-E99077D3BD63 | Source = VSC32 | ID = 327806

Description = This format is not supported by VSC WAVE device. [This is illegal

frequency]

Error - 28/01/2012 06:59:44 | Computer Name = GR-E99077D3BD63 | Source = VSC32 | ID = 327806

Description = This format is not supported by VSC WAVE device. [This is illegal

frequency]

Error - 28/01/2012 06:59:44 | Computer Name = GR-E99077D3BD63 | Source = VSC32 | ID = 327806

Description = This format is not supported by VSC WAVE device. [This is illegal

frequency]

Error - 28/01/2012 17:44:58 | Computer Name = GR-E99077D3BD63 | Source = VSC32 | ID = 327806

Description = This format is not supported by VSC WAVE device. [This is illegal

frequency]

Error - 28/01/2012 17:44:59 | Computer Name = GR-E99077D3BD63 | Source = VSC32 | ID = 327806

Description = This format is not supported by VSC WAVE device. [This is illegal

frequency]

Error - 30/01/2012 06:38:12 | Computer Name = GR-E99077D3BD63 | Source = Brother BrLog | ID = 1001

Description = STI BrtSTI: [2012/01/30 11:38:12.515]: [00000928]: CUsbScnDev: DeviceIoControl

Illegal response

[ System Events ]

Error - 31/01/2012 02:16:23 | Computer Name = GR-E99077D3BD63 | Source = Service Control Manager | ID = 7000

Description = Le service Adobe Licensing Console n'a pas pu démarrer en raison de

l'erreur : %%1053

Error - 31/01/2012 02:31:09 | Computer Name = GR-E99077D3BD63 | Source = Service Control Manager | ID = 7000

Description = Le service Nsynas32 n'a pas pu démarrer en raison de l'erreur : %%20

Error - 31/01/2012 02:48:30 | Computer Name = GR-E99077D3BD63 | Source = Service Control Manager | ID = 7000

Description = Le service Nsynas32 n'a pas pu démarrer en raison de l'erreur : %%20

Error - 31/01/2012 02:59:41 | Computer Name = GR-E99077D3BD63 | Source = Service Control Manager | ID = 7000

Description = Le service Nsynas32 n'a pas pu démarrer en raison de l'erreur : %%20

Error - 31/01/2012 03:25:40 | Computer Name = GR-E99077D3BD63 | Source = atapi | ID = 262153

Description = Le périphérique \Device\Ide\IdePort0 n'a pas répondu dans le délai

imparti.

Error - 31/01/2012 06:07:54 | Computer Name = GR-E99077D3BD63 | Source = atapi | ID = 262153

Description = Le périphérique \Device\Ide\IdePort0 n'a pas répondu dans le délai

imparti.

Error - 31/01/2012 12:34:32 | Computer Name = GR-E99077D3BD63 | Source = w29n51 | ID = 5005

Description = Intel® PRO/Wireless 2200BG Network Connection : a rencontré une

erreur interne et a échoué.

Error - 31/01/2012 12:38:29 | Computer Name = GR-E99077D3BD63 | Source = Service Control Manager | ID = 7000

Description = Le service Nsynas32 n'a pas pu démarrer en raison de l'erreur : %%20

Error - 31/01/2012 12:39:08 | Computer Name = GR-E99077D3BD63 | Source = Dhcp | ID = 1001

Description = Le réseau n'a attribué aucune adresse à votre ordinateur (par le serveur

DHCP)

pour la carte réseau avec l'adresse réseau 0012F000E315. Il s'est produit l'erreur

suivante : %%121. Votre ordinateur va continuer à essayer d'obtenir sa propre adresse

auprès du serveur d'adresse réseau (DHCP).

Error - 31/01/2012 23:37:52 | Computer Name = GR-E99077D3BD63 | Source = Service Control Manager | ID = 7000

Description = Le service Nsynas32 n'a pas pu démarrer en raison de l'erreur : %%20

< End of report >

Благодаря

Публикувано изображение Стартирайте отново OTL, копирайте (Copy) и поставете (Paste) скриптовия текст от текстовото поле по-долу под колонката Custom Scans/Fixes, като не забравяте да копирате скрипта 1 към 1, както и двете точки преди първия ред на скрипта.

:OTL
SRV - File not found [Disabled | Stopped] --  -- (HidServ)
SRV - File not found [On_Demand | Stopped] --  -- (AppMgmt)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.8:  File not found
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin:  File not found
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin:  File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3:  File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9:  File not found
O4 - HKU\.DEFAULT..\RunOnce: [aqcabhk] C:\Documents and Settings\LocalService.AUTORITE NT\Local Settings\Application Data\aqcabhk.exe ()
O4 - HKU\S-1-5-18..\RunOnce: [aqcabhk] C:\Documents and Settings\LocalService.AUTORITE NT\Local Settings\Application Data\aqcabhk.exe ()
O4 - HKLM..\RunOnceEx: [Flags] Reg Error: Invalid data type. File not found
O4 - HKLM..\RunOnceEx: [Title] UnHackMe Rootkit Check File not found


:Reg

:files
C:\Documents and Settings\LocalService.AUTORITE NT\Local Settings\Application Data\aqcabhk.exe

autorun.inf /alldrives
autorun.exe /alldrives
recycler /alldrives
ipconfig /flushdns /c

:Commands
[purity]
[emptytemp]
[resethosts]
[clearallrestorepoints]
[emptyflash]
[Reboot]

Публикувано изображение След като въведете скрипта от цитата по-горе натиснете бутона, маркиран в червено: Run Fix

Windows ще се рестартира и ще се създаде лог файл. Публикувайте съдържанието му с Copy/Paste в следващия си коментар.

  • Автор

Опитвам се да изпълня горния пост ,но след като OTL започне сканирането спира на -Processing SafeBootMin; AppMgmt- File not found и стои така с часове

  • Автор

Този път стана

All processes killed

========== OTL ==========

Error: No service named HidServ was found to stop!

Service\Driver key HidServ not found.

Error: No service named AppMgmt was found to stop!

Service\Driver key AppMgmt not found.

Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.8\ not found.

Registry key HKEY_CURRENT_USER\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin\ not found.

Registry key HKEY_CURRENT_USER\Software\MozillaPlugins\@talk.google.com/O3DPlugin\ not found.

Registry key HKEY_CURRENT_USER\Software\MozillaPlugins\@tools.google.com/Google Update;version=3\ not found.

Registry key HKEY_CURRENT_USER\Software\MozillaPlugins\@tools.google.com/Google Update;version=9\ not found.

Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce\\aqcabhk not found.

File C:\Documents and Settings\LocalService.AUTORITE NT\Local Settings\Application Data\aqcabhk.exe not found.

Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce\\aqcabhk not found.

File C:\Documents and Settings\LocalService.AUTORITE NT\Local Settings\Application Data\aqcabhk.exe not found.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx\\Flags deleted successfully.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx\\Title deleted successfully.

========== REGISTRY ==========

========== FILES ==========

File\Folder C:\Documents and Settings\LocalService.AUTORITE NT\Local Settings\Application Data\aqcabhk.exe not found.

autorun.inf not found in C:\

autorun.exe not found in C:\

C:\RECYCLER\S-1-5-21-1417001333-1767777339-725345543-1004 folder moved successfully.

C:\RECYCLER folder moved successfully.

< ipconfig /flushdns /c >

Configuration IP de Windows

Cache de résolution DNS vidé.

C:\Documents and Settings\GR\Bureau\cmd.bat deleted successfully.

C:\Documents and Settings\GR\Bureau\cmd.txt deleted successfully.

========== COMMANDS ==========

[EMPTYTEMP]

User: Administrateur

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

User: Administrateur.GR-E99077D3BD63

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 76135 bytes

User: All Users

User: All Users.WINDOWS

User: client

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

->Java cache emptied: 0 bytes

->FireFox cache emptied: 0 bytes

->Flash cache emptied: 0 bytes

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

User: Default User.WINDOWS

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

User: GR

->Temp folder emptied: 112983981 bytes

->Temporary Internet Files folder emptied: 196124626 bytes

->FireFox cache emptied: 23034876 bytes

->Flash cache emptied: 470 bytes

User: LocalService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

User: LocalService.AUTORITE NT

->Temp folder emptied: 66016 bytes

->Temporary Internet Files folder emptied: 119005436 bytes

->Java cache emptied: 14128 bytes

->Flash cache emptied: 14459 bytes

User: NetworkService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

User: NetworkService.AUTORITE NT

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 0 bytes

%systemroot%\System32 .tmp files removed: 0 bytes

%systemroot%\System32\dllcache .tmp files removed: 0 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 1412096 bytes

%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes

%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes

RecycleBin emptied: 0 bytes

Total Files Cleaned = 432,00 mb

C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.

HOSTS file reset successfully

Restore points cleared and new OTL Restore Point set!

[EMPTYFLASH]

User: Administrateur

User: Administrateur.GR-E99077D3BD63

User: All Users

User: All Users.WINDOWS

User: client

->Flash cache emptied: 0 bytes

User: Default User

User: Default User.WINDOWS

User: GR

->Flash cache emptied: 0 bytes

User: LocalService

User: LocalService.AUTORITE NT

->Flash cache emptied: 0 bytes

User: NetworkService

User: NetworkService.AUTORITE NT

Total Flash Files Cleaned = 0,00 mb

OTL by OldTimer - Version 3.2.31.0 log created on 02032012_111751

Files\Folders moved on Reboot...

File\Folder C:\Documents and Settings\GR\Local Settings\Temp\~DF477.tmp not found!

File\Folder C:\Documents and Settings\GR\Local Settings\Temp\~DFDCC3.tmp not found!

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\X6R3WL9D\ads[5].htm moved successfully.

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\X6R3WL9D\fb_iframe[1].html moved successfully.

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\X6R3WL9D\index[1].htm moved successfully.

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\X6R3WL9D\like[1].htm moved successfully.

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\X6R3WL9D\search[2].htm moved successfully.

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\IQNEFIP3\ads[4].htm moved successfully.

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\IQNEFIP3\login_status[1].htm moved successfully.

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\DQAIZIUA\ads[5].htm moved successfully.

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\DQAIZIUA\ads[6].htm moved successfully.

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\9KIGK0Q4\ads[4].htm moved successfully.

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\9KIGK0Q4\fastbutton[1].htm moved successfully.

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\9KIGK0Q4\xd_proxy[1].htm moved successfully.

File move failed. C:\WINDOWS\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot...

Благодаря

А ама той май бацила е премахнат още при предния опит....хм не съм сигурен..ще се наложи да проверим за да сме сигурни....:

Стартирайте отново OTL и направете сканиране със същите настройки ...Този път обаче вместо Run Fix натиснете бутона Публикувано изображение...Ще се създаде лог файл. Публикувайте съдържанието му с Copy/Paste в следващия си коментар.

Почти на финала сме..!:)

  • Автор

All processes killed

========== OTL ==========

Error: No service named HidServ was found to stop!

Service\Driver key HidServ not found.

Error: No service named AppMgmt was found to stop!

Service\Driver key AppMgmt not found.

Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.8\ not found.

Registry key HKEY_CURRENT_USER\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin\ not found.

Registry key HKEY_CURRENT_USER\Software\MozillaPlugins\@talk.google.com/O3DPlugin\ not found.

Registry key HKEY_CURRENT_USER\Software\MozillaPlugins\@tools.google.com/Google Update;version=3\ not found.

Registry key HKEY_CURRENT_USER\Software\MozillaPlugins\@tools.google.com/Google Update;version=9\ not found.

Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce\\aqcabhk not found.

File C:\Documents and Settings\LocalService.AUTORITE NT\Local Settings\Application Data\aqcabhk.exe not found.

Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce\\aqcabhk not found.

File C:\Documents and Settings\LocalService.AUTORITE NT\Local Settings\Application Data\aqcabhk.exe not found.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx\\Flags deleted successfully.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx\\Title deleted successfully.

========== REGISTRY ==========

========== FILES ==========

File\Folder C:\Documents and Settings\LocalService.AUTORITE NT\Local Settings\Application Data\aqcabhk.exe not found.

autorun.inf not found in C:\

autorun.exe not found in C:\

C:\RECYCLER\S-1-5-21-1417001333-1767777339-725345543-1004 folder moved successfully.

C:\RECYCLER folder moved successfully.

< ipconfig /flushdns /c >

Configuration IP de Windows

Cache de résolution DNS vidé.

C:\Documents and Settings\GR\Bureau\cmd.bat deleted successfully.

C:\Documents and Settings\GR\Bureau\cmd.txt deleted successfully.

========== COMMANDS ==========

[EMPTYTEMP]

User: Administrateur

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

User: Administrateur.GR-E99077D3BD63

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 76135 bytes

User: All Users

User: All Users.WINDOWS

User: client

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

->Java cache emptied: 0 bytes

->FireFox cache emptied: 0 bytes

->Flash cache emptied: 0 bytes

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

User: Default User.WINDOWS

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

User: GR

->Temp folder emptied: 112983981 bytes

->Temporary Internet Files folder emptied: 196124626 bytes

->FireFox cache emptied: 23034876 bytes

->Flash cache emptied: 470 bytes

User: LocalService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

User: LocalService.AUTORITE NT

->Temp folder emptied: 66016 bytes

->Temporary Internet Files folder emptied: 119005436 bytes

->Java cache emptied: 14128 bytes

->Flash cache emptied: 14459 bytes

User: NetworkService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

User: NetworkService.AUTORITE NT

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 0 bytes

%systemroot%\System32 .tmp files removed: 0 bytes

%systemroot%\System32\dllcache .tmp files removed: 0 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 1412096 bytes

%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes

%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes

RecycleBin emptied: 0 bytes

Total Files Cleaned = 432,00 mb

C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.

HOSTS file reset successfully

Restore points cleared and new OTL Restore Point set!

[EMPTYFLASH]

User: Administrateur

User: Administrateur.GR-E99077D3BD63

User: All Users

User: All Users.WINDOWS

User: client

->Flash cache emptied: 0 bytes

User: Default User

User: Default User.WINDOWS

User: GR

->Flash cache emptied: 0 bytes

User: LocalService

User: LocalService.AUTORITE NT

->Flash cache emptied: 0 bytes

User: NetworkService

User: NetworkService.AUTORITE NT

Total Flash Files Cleaned = 0,00 mb

OTL by OldTimer - Version 3.2.31.0 log created on 02032012_111751

Files\Folders moved on Reboot...

File\Folder C:\Documents and Settings\GR\Local Settings\Temp\~DF477.tmp not found!

File\Folder C:\Documents and Settings\GR\Local Settings\Temp\~DFDCC3.tmp not found!

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\X6R3WL9D\ads[5].htm moved successfully.

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\X6R3WL9D\fb_iframe[1].html moved successfully.

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\X6R3WL9D\index[1].htm moved successfully.

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\X6R3WL9D\like[1].htm moved successfully.

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\X6R3WL9D\search[2].htm moved successfully.

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\IQNEFIP3\ads[4].htm moved successfully.

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\IQNEFIP3\login_status[1].htm moved successfully.

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\DQAIZIUA\ads[5].htm moved successfully.

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\DQAIZIUA\ads[6].htm moved successfully.

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\9KIGK0Q4\ads[4].htm moved successfully.

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\9KIGK0Q4\fastbutton[1].htm moved successfully.

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\9KIGK0Q4\xd_proxy[1].htm moved successfully.

File move failed. C:\WINDOWS\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot...

Защо това ...допуснали сте грешка:

Стартирайте отново OTL и направете сканиране със същите настройки ...Този път обаче вместо Run Fix натиснете бутона Публикувано изображение...Ще се създаде лог файл. Публикувайте съдържанието му с Copy/Paste в следващия си коментар.

Просто ми трябва сканиране и лог....за да видя дали всичко е чисто..!

  • Автор

Дано това е верния лог този път...не знам какво съм направил преди

OTL logfile created on: 03/02/2012 13:49:54 - Run 3

OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\GR\Bureau

Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy

502,42 Mb Total Physical Memory | 128,02 Mb Available Physical Memory | 25,48% Memory free

1,19 Gb Paging File | 0,81 Gb Available in Paging File | 68,36% Paging File free

Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 92,86 Gb Total Space | 77,84 Gb Free Space | 83,83% Space Free | Partition Type: NTFS

Computer Name: GR-E99077D3BD63 | User Name: GR | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Quick Scan

Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/01/30 13:30:41 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\GR\Bureau\OTL.exe

PRC - [2012/01/23 17:01:04 | 000,594,192 | ---- | M] (Greatis Software) -- C:\Program Files\UnHackMe\hackmon.exe

PRC - [2011/11/28 19:01:23 | 000,044,768 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe

PRC - [2004/08/05 13:00:00 | 001,036,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe

PRC - [2002/09/20 15:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

========== Modules (No Company Name) ==========

MOD - [2012/02/03 09:39:21 | 001,688,576 | ---- | M] () -- C:\Program Files\Alwil Software\Avast5\defs\12020300\algo.dll

========== Win32 Services (SafeList) ==========

SRV - [2011/11/28 19:01:23 | 000,044,768 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)

SRV - [2002/09/20 15:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) [Auto | Running] -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe -- (SoundMAX Agent Service (default))

========== Driver Services (SafeList) ==========

DRV - [2012/01/31 07:26:17 | 000,024,416 | ---- | M] (Greatis Software) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\regguard.sys -- (RegGuard)

DRV - [2012/01/06 12:16:29 | 000,721,904 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)

DRV - [2011/11/28 18:53:53 | 000,435,032 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)

DRV - [2011/11/28 18:53:35 | 000,314,456 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)

DRV - [2011/11/28 18:52:19 | 000,034,392 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)

DRV - [2011/11/28 18:52:16 | 000,052,952 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)

DRV - [2011/11/28 18:52:02 | 000,111,320 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)

DRV - [2011/11/28 18:51:50 | 000,020,568 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)

DRV - [2011/11/28 18:48:49 | 000,030,808 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)

DRV - [2010/01/12 10:19:22 | 000,136,704 | ---- | M] (Yamaha Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\yfwbus.sys -- (YFWBUS)

DRV - [2007/01/04 11:24:26 | 000,260,096 | R--- | M] (Vimicro Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbvm323.sys -- (ZSMC326) VIMICRO USB2.0 PC Camera(VC0323)

DRV - [2006/08/08 04:25:40 | 000,476,672 | R--- | M] (Vimicro Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\vmfilter323.sys -- (vmfilter323)

DRV - [2005/05/09 20:08:40 | 000,033,792 | ---- | M] (Team H2O) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\cledx.sys -- (CLEDX)

DRV - [2004/11/17 11:30:40 | 000,147,840 | R--- | M] (Texas Instruments) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tifm21.sys -- (tifm21)

DRV - [2004/09/20 09:41:00 | 003,210,496 | R--- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\w29n51.sys -- (w29n51) Pilote de carte de connexion réseau Intel®

DRV - [2004/08/24 12:20:08 | 001,268,204 | R--- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)

DRV - [2004/08/03 23:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Pilote NT de carte Realtek PCI Fast Ethernet à base RTL8139(A/B/C)

DRV - [2004/06/28 11:35:24 | 000,069,760 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtlnicxp.sys -- (RTL8023xp)

DRV - [2004/04/26 10:49:56 | 000,381,056 | R--- | M] (Sensaura) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (senfilt)

DRV - [2003/11/28 17:34:40 | 000,011,264 | ---- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\asapiW2k.sys -- (ASAPIW2K)

DRV - [2003/06/27 04:05:38 | 000,472,332 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lvcm.sys -- (QCMerced)

DRV - [2002/09/20 11:53:34 | 000,235,100 | R--- | M] (Analog Devices Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\MidiSyn.sys -- (MidiSyn)

DRV - [2002/05/22 08:34:00 | 000,966,784 | ---- | M] (YAMAHA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sxgxgwdm.sys -- (SOFTXG)

DRV - [2001/04/16 09:16:58 | 000,951,284 | ---- | M] (Roland) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\vsc.sys -- (vsc32)

DRV - [2001/04/09 14:03:56 | 000,017,784 | ---- | M] (Syncrosoft Hard- und Software GmbH) [Kernel | Auto | Stopped] -- C:\WINDOWS\System32\drivers\NSynas32.sys -- (Nsynas32)

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.bg/

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()

FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)

FF - HKLM\Software\MozillaPlugins\@inhatch.com,version=0.7.61: C:\Program Files\InhatchTeam\Inhatch\npinhatch.dll (Inhatch)

FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)

FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)

FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)

FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)

FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/10/30 23:36:52 | 000,000,000 | ---D | M]

[2012/01/04 11:06:08 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\GR\Application Data\Mozilla\Extensions

[2012/01/04 11:09:15 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\GR\Application Data\Mozilla\Firefox\Profiles\tlrigj9b.default\extensions

[2012/01/04 11:09:15 | 000,000,000 | ---D | M] (FoxyProxy Standard) -- C:\Documents and Settings\GR\Application Data\Mozilla\Firefox\Profiles\tlrigj9b.default\extensions\[email protected]

[2011/11/14 14:37:48 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions

[2011/10/30 23:36:52 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll

[2011/10/30 23:36:46 | 000,001,083 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\911bg.xml

[2011/10/28 03:36:07 | 000,002,227 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml

[2011/10/30 23:36:46 | 000,002,442 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\diribg.xml

[2011/10/30 23:36:46 | 000,001,515 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pe-bg.xml

[2011/10/30 23:36:46 | 000,001,857 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\portalbgdict.xml

[2011/10/30 23:36:46 | 000,001,220 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-bg.xml

O1 HOSTS File: ([2012/02/03 11:19:07 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts

O1 - Hosts: 127.0.0.1 localhost

O1 - Hosts: ::1 localhost

O4 - HKCU..\Run: [unHackMe Monitor] C:\Program Files\UnHackMe\hackmon.exe (Greatis Software)

O4 - HKLM..\RunOnceEx: [Flags] Reg Error: Invalid data type. File not found

O4 - HKLM..\RunOnceEx: [Title] UnHackMe Rootkit Check File not found

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O15 - HKCU\..Trusted Domains: pps.tv ([]http in Trusted sites)

O15 - HKCU\..Trusted Domains: ppstream.com ([]http in Trusted sites)

O15 - HKCU\..Trusted Domains: webscache.com ([]http in Trusted sites)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)

O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.10.1 206.248.154.22 206.248.154.170

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{83342E28-BFDA-4B11-90FF-A0773132A277}: DhcpNameServer = 192.168.10.1 206.248.154.22 206.248.154.170

O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Fichiers communs\Skype\Skype4COM.dll (Skype Technologies)

O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)

O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)

O24 - Desktop Components:0 (Ma page d'accueil) - About:Home

O24 - Desktop WallPaper: C:\WINDOWS\Blue Sonic.bmp

O24 - Desktop BackupWallPaper: C:\WINDOWS\Blue Sonic.bmp

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2007/09/10 20:36:12 | 000,000,050 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O34 - HKLM BootExecute: (autocheck autochk *)

O34 - HKLM BootExecute: (Partizan)

O34 - HKLM BootExecute: (ootExecute settings...)

O34 - HKLM BootExecute: (on\E)

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/02/03 11:19:07 | 000,000,000 | -HSD | C] -- C:\RECYCLER

[2012/02/02 15:38:27 | 000,000,000 | ---D | C] -- C:\Program Files\Acoustica Mixcraft 5

[2012/02/01 13:22:02 | 000,000,000 | ---D | C] -- C:\_OTL

[2012/01/31 11:12:26 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\GR\Bureau\.ptmp635817

[2012/01/31 11:07:48 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\GR\Bureau\.ptmp174427

[2012/01/31 10:56:18 | 002,059,056 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\GR\Bureau\tdsskiller.exe

[2012/01/31 08:14:35 | 004,733,440 | ---- | C] (AVAST Software) -- C:\Documents and Settings\GR\Bureau\aswMBR.exe

[2012/01/31 06:07:38 | 000,000,000 | ---D | C] -- C:\RegRunInfo

[2012/01/31 05:44:17 | 000,024,416 | ---- | C] (Greatis Software) -- C:\WINDOWS\System32\drivers\regguard.sys

[2012/01/31 05:30:22 | 000,039,184 | ---- | C] (Greatis Software) -- C:\WINDOWS\System32\Partizan.exe

[2012/01/31 05:30:22 | 000,035,816 | ---- | C] (Greatis Software) -- C:\WINDOWS\System32\drivers\Partizan.sys

[2012/01/31 05:30:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GR\Mes documents\RegRun2

[2012/01/31 05:30:02 | 000,012,800 | ---- | C] (Greatis Software, LLC.) -- C:\WINDOWS\System32\drivers\UnHackMeDrv.sys

[2012/01/31 05:30:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\UnHackMe

[2012/01/31 05:30:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Documents\regruninfo

[2012/01/31 05:29:42 | 000,000,000 | ---D | C] -- C:\Program Files\UnHackMe

[2012/01/30 13:30:36 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\GR\Bureau\OTL.exe

[2012/01/29 14:21:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GR\Application Data\Malwarebytes

[2012/01/29 14:21:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\Malwarebytes' Anti-Malware

[2012/01/29 14:21:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes

[2012/01/29 14:16:16 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys

[2012/01/28 23:12:51 | 000,607,260 | R--- | C] (Swearware) -- C:\Documents and Settings\GR\Bureau\dds.scr

[2012/01/28 21:55:36 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp

[2012/01/28 21:13:44 | 000,000,000 | RHSD | C] -- C:\cmdcons

[2012/01/28 20:48:34 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT

[2012/01/28 15:53:40 | 000,000,000 | ---D | C] -- C:\Digidesign Databases

[2012/01/28 15:36:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump

[2012/01/28 15:19:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GR\Menu Démarrer\Programmes\NFOPad

[2012/01/28 13:04:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GR\Bureau\Nouveau dossier (2)

[2012/01/27 18:40:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GR\Bureau\Mixcraft

[2012/01/27 18:02:43 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\GR\Recent

[2012/01/26 16:27:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\Image-Line

[2012/01/26 16:20:12 | 000,000,000 | ---D | C] -- C:\Program Files\FL Studio 10

[2012/01/26 16:13:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GR\Application Data\MMFApplications

[2012/01/20 12:46:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GR\Application Data\TightVNC

[2012/01/19 15:35:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GR\Mes documents\Image-Line

[2012/01/19 15:33:59 | 000,000,000 | ---D | C] -- C:\Program Files\Outsim

[2012/01/18 05:18:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GR\Application Data\SynthMaker

[2012/01/17 15:25:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GR\Application Data\MusE

[2012/01/17 15:25:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GR\Local Settings\Application Data\MusE

[2012/01/16 16:01:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GR\Application Data\Waves Audio

[2012/01/16 15:39:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GR\Application Data\PACE Anti-Piracy

[2012/01/16 15:39:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\PACE Anti-Piracy

[2012/01/16 15:17:00 | 002,455,499 | ---- | C] (Digidesign) -- C:\WINDOWS\System32\pcifmdio.dll

[2012/01/16 15:16:59 | 002,453,423 | ---- | C] (Digidesign) -- C:\WINDOWS\System32\fwfmdio.dll

[2012/01/15 12:31:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\PDF-XChange PDF Viewer

[2012/01/15 11:34:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GR\Mes documents\Cubase Projects

[2012/01/15 10:51:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GR\Application Data\Wise Registry Cleaner

[2012/01/15 10:50:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\Wise Registry Cleaner

[2012/01/15 10:50:42 | 000,000,000 | ---D | C] -- C:\Program Files\Wise Registry Cleaner

[2012/01/15 10:38:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GR\Application Data\Wise Disk Cleaner

[2012/01/15 10:35:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\Wise Disk Cleaner

[2012/01/15 10:35:49 | 000,000,000 | ---D | C] -- C:\Program Files\Wise Disk Cleaner

[2012/01/15 09:39:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GR\Mes documents\My Recordings

[2012/01/14 15:21:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GR\Local Settings\Application Data\360Amigo

[2012/01/13 16:37:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GR\Application Data\Image-Line

[2012/01/11 14:17:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GR\Application Data\Waves

[2012/01/11 14:14:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GR\Application Data\Waves Preferences

[2012/01/10 16:08:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GR\Bureau\spaseni

[2012/01/09 17:06:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GR\Application Data\WinRAR

[2012/01/06 16:08:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GR\Local Settings\Application Data\uTorrent

[2012/01/06 16:08:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GR\Application Data\uTorrent

[2012/01/06 12:20:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GR\Application Data\StarBurn

[2012/01/06 12:16:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\StarBurn Software

[2012/01/06 12:15:45 | 000,000,000 | ---D | C] -- C:\Program Files\StarBurn Software

[2012/01/06 12:08:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\CyberLink

[2012/01/04 17:59:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\GR\Application Data\OpenOffice.org

========== Files - Modified Within 30 Days ==========

[2012/02/03 11:52:25 | 000,002,265 | ---- | M] () -- C:\Documents and Settings\GR\Bureau\Skype.lnk

[2012/02/03 11:22:09 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2012/02/03 11:19:07 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts

[2012/02/03 01:10:13 | 000,005,120 | ---- | M] () -- C:\Documents and Settings\GR\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2012/02/02 17:50:43 | 000,000,271 | ---- | M] () -- C:\WINDOWS\PR1V2.INI

[2012/02/02 17:50:43 | 000,000,226 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\NOTEBOOK.DBF

[2012/01/31 11:07:12 | 000,294,216 | ---- | M] () -- C:\Documents and Settings\GR\Bureau\gmer.zip

[2012/01/31 10:56:18 | 002,059,056 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\GR\Bureau\tdsskiller.exe

[2012/01/31 10:54:54 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\GR\Bureau\MBR.dat

[2012/01/31 08:14:35 | 004,733,440 | ---- | M] (AVAST Software) -- C:\Documents and Settings\GR\Bureau\aswMBR.exe

[2012/01/31 07:38:29 | 000,139,264 | ---- | M] () -- C:\Documents and Settings\GR\Bureau\SystemLook.exe

[2012/01/31 07:26:17 | 000,024,416 | ---- | M] (Greatis Software) -- C:\WINDOWS\System32\drivers\regguard.sys

[2012/01/31 07:26:12 | 000,000,031 | ---- | M] () -- C:\WINDOWS\System32\deck.ini

[2012/01/31 05:54:27 | 000,167,504 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2012/01/31 05:30:27 | 000,003,121 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT

[2012/01/31 05:30:27 | 000,001,896 | ---- | M] () -- C:\WINDOWS\System32\AUTOEXEC.NT

[2012/01/31 05:30:27 | 000,000,002 | RHS- | M] () -- C:\WINDOWS\winstart.bat

[2012/01/31 05:30:22 | 000,039,184 | ---- | M] (Greatis Software) -- C:\WINDOWS\System32\Partizan.exe

[2012/01/31 05:30:22 | 000,035,816 | ---- | M] (Greatis Software) -- C:\WINDOWS\System32\drivers\Partizan.sys

[2012/01/31 05:30:06 | 000,000,630 | ---- | M] () -- C:\Documents and Settings\GR\Bureau\UnHackMe.lnk

[2012/01/31 04:46:20 | 011,347,294 | ---- | M] () -- C:\Documents and Settings\GR\Bureau\unhackme.zip

[2012/01/30 13:30:41 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\GR\Bureau\OTL.exe

[2012/01/30 11:38:22 | 000,001,808 | -H-- | M] () -- C:\Documents and Settings\GR\Mes documents\PP11Thumbs.ptn2

[2012/01/30 11:38:21 | 000,002,505 | -H-- | M] () -- C:\Documents and Settings\GR\Mes documents\maxdesk.ini2

[2012/01/30 11:31:35 | 004,041,170 | -H-- | M] () -- C:\Documents and Settings\GR\Mes documents\PP11Thumbs.ptn

[2012/01/30 11:31:33 | 000,876,057 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (65).pdf

[2012/01/30 11:25:13 | 000,899,464 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (64).pdf

[2012/01/30 11:24:08 | 000,609,910 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (63).pdf

[2012/01/30 11:22:49 | 000,472,591 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (62).pdf

[2012/01/29 14:21:19 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Bureau\Malwarebytes Anti-Malware.lnk

[2012/01/29 09:32:00 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat

[2012/01/28 21:13:49 | 000,000,332 | RHS- | M] () -- C:\boot.ini

[2012/01/28 01:09:04 | 000,043,888 | ---- | M] () -- C:\Documents and Settings\GR\Bureau\stevie_wonder-overjoyed.mid

[2012/01/27 22:45:33 | 000,651,779 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (61).pdf

[2012/01/27 22:44:51 | 000,810,922 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (60).pdf

[2012/01/27 22:44:04 | 000,682,564 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (59).pdf

[2012/01/27 22:42:04 | 000,789,360 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (58).pdf

[2012/01/27 22:39:55 | 000,933,079 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (57).pdf

[2012/01/27 22:38:55 | 000,750,001 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (56).pdf

[2012/01/27 22:37:57 | 000,852,140 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (55).pdf

[2012/01/27 22:37:08 | 000,806,112 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (54).pdf

[2012/01/27 22:35:59 | 000,846,758 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (53).pdf

[2012/01/27 22:34:50 | 000,932,309 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (52).pdf

[2012/01/27 22:33:36 | 000,814,963 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (51).pdf

[2012/01/27 22:32:07 | 000,835,663 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (50).pdf

[2012/01/27 22:31:00 | 000,866,049 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (49).pdf

[2012/01/27 22:30:07 | 000,815,919 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (48).pdf

[2012/01/27 22:29:06 | 000,737,887 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (47).pdf

[2012/01/27 22:28:15 | 000,853,809 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (46).pdf

[2012/01/27 22:25:34 | 000,685,894 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (45).pdf

[2012/01/27 22:24:10 | 000,729,906 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (44).pdf

[2012/01/27 22:23:24 | 000,812,976 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (43).pdf

[2012/01/27 22:22:47 | 000,871,168 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (42).pdf

[2012/01/27 22:20:48 | 000,340,182 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (41).pdf

[2012/01/27 19:07:54 | 005,068,014 | ---- | M] () -- C:\Documents and Settings\GR\Bureau\drumaxx_install.exe

[2012/01/27 16:10:33 | 000,036,399 | ---- | M] () -- C:\Documents and Settings\GR\Bureau\France - Au chant de l'alouette[1].pdf

[2012/01/26 16:27:51 | 000,000,676 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Bureau\FL Studio 10.lnk

[2012/01/26 15:14:12 | 000,000,384 | ---- | M] () -- C:\WINDOWS\System32\checkOS.bat

[2012/01/24 14:11:52 | 000,029,096 | ---- | M] () -- C:\Documents and Settings\GR\Bureau\viva.mx5

[2012/01/24 13:33:36 | 000,002,000 | ---- | M] () -- C:\Documents and Settings\GR\Bureau\[Free-scores.com]_giardini-felice-viva-tutte-vezzose-8835.midi.mid

[2012/01/24 03:37:39 | 000,004,965 | ---- | M] () -- C:\Documents and Settings\GR\Bureau\[Free-scores.com]_giardini-felice-viva-tutte-vezzose-8835.midi

[2012/01/23 17:01:14 | 000,012,800 | ---- | M] (Greatis Software, LLC.) -- C:\WINDOWS\System32\drivers\UnHackMeDrv.sys

[2012/01/23 14:12:31 | 000,545,338 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (40).pdf

[2012/01/23 14:08:51 | 000,671,235 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (39).pdf

[2012/01/23 14:08:08 | 000,856,873 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (38).pdf

[2012/01/23 14:07:19 | 000,745,493 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (37).pdf

[2012/01/23 14:06:34 | 000,842,185 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (36).pdf

[2012/01/23 14:05:47 | 000,886,815 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (35).pdf

[2012/01/23 14:04:45 | 000,904,954 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (34).pdf

[2012/01/23 14:03:33 | 000,905,714 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (33).pdf

[2012/01/23 14:02:45 | 000,860,224 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (32).pdf

[2012/01/23 14:01:49 | 000,789,233 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (31).pdf

[2012/01/23 14:00:41 | 000,730,275 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (30).pdf

[2012/01/23 13:59:50 | 000,868,760 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (29).pdf

[2012/01/23 13:58:21 | 000,775,376 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (28).pdf

[2012/01/23 13:54:38 | 000,715,259 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (27).pdf

[2012/01/23 13:53:38 | 000,816,480 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (26).pdf

[2012/01/21 11:47:26 | 000,333,848 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\1 voix.mp3.zpa

[2012/01/18 14:50:15 | 000,518,285 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (25).pdf

[2012/01/18 14:47:44 | 000,457,526 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (24).pdf

[2012/01/18 14:46:57 | 000,607,885 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (23).pdf

[2012/01/18 14:46:14 | 000,699,335 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (22).pdf

[2012/01/18 14:44:44 | 000,772,209 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (21).pdf

[2012/01/18 04:25:50 | 000,470,248 | ---- | M] () -- C:\Documents and Settings\GR\Bureau\v'la 2 voix.mp3

[2012/01/18 04:25:15 | 000,453,948 | ---- | M] () -- C:\Documents and Settings\GR\Bureau\v'la 1 voix.mp3

[2012/01/17 17:48:49 | 000,462,725 | ---- | M] () -- C:\Documents and Settings\GR\Bureau\v'la 3 voix.mp3

[2012/01/17 17:38:58 | 000,003,544 | ---- | M] () -- C:\Documents and Settings\GR\Bureau\V'la le bon vent.mscz

[2012/01/17 16:36:10 | 000,023,816 | ---- | M] () -- C:\Documents and Settings\GR\Bureau\V'la le bon vent.pdf

[2012/01/17 15:24:11 | 000,001,103 | ---- | M] () -- C:\Documents and Settings\GR\Bureau\v'la.mid

[2012/01/16 14:02:27 | 000,660,665 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (20).pdf

[2012/01/16 14:01:18 | 000,844,938 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (19).pdf

[2012/01/16 13:58:22 | 000,908,863 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (18).pdf

[2012/01/16 13:55:53 | 000,926,900 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (17).pdf

[2012/01/16 13:54:35 | 000,727,823 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (16).pdf

[2012/01/16 13:53:10 | 000,769,025 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (15).pdf

[2012/01/15 12:31:50 | 000,000,866 | ---- | M] () -- C:\Documents and Settings\GR\Bureau\PDF-Viewer.lnk

[2012/01/15 10:50:46 | 000,000,803 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Bureau\Wise Registry Cleaner.lnk

[2012/01/15 10:35:54 | 000,000,780 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Bureau\Wise Disk Cleaner.lnk

[2012/01/12 22:28:32 | 000,032,279 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (14).pdf

[2012/01/12 22:27:55 | 000,033,051 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (13).pdf

[2012/01/12 22:27:18 | 000,036,053 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (12).pdf

[2012/01/12 22:26:23 | 000,031,339 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (11).pdf

[2012/01/12 22:10:16 | 000,037,882 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (10).pdf

[2012/01/09 15:44:36 | 037,864,081 | ---- | M] () -- C:\Documents and Settings\GR\Bureau\Communication Progressive du Francais (niveau intermediaire)_book.pdf

[2012/01/09 10:50:52 | 001,481,029 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (9).pdf

[2012/01/09 10:46:14 | 001,306,900 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (8).pdf

[2012/01/09 10:44:29 | 001,358,870 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (7).pdf

[2012/01/09 10:42:52 | 001,647,236 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (6).pdf

[2012/01/09 10:39:50 | 001,390,766 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (5).pdf

[2012/01/09 10:38:20 | 001,443,453 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (4).pdf

[2012/01/09 09:16:50 | 000,697,985 | ---- | M] () -- C:\Documents and Settings\GR\Mes documents\Document (3).pdf

[2012/01/06 12:16:07 | 000,000,954 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Bureau\StarBurn.lnk

========== Files Created - No Company Name ==========

[2012/01/31 11:07:09 | 000,294,216 | ---- | C] () -- C:\Documents and Settings\GR\Bureau\gmer.zip

[2012/01/31 10:54:54 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\GR\Bureau\MBR.dat

[2012/01/31 05:30:27 | 000,000,002 | RHS- | C] () -- C:\WINDOWS\winstart.bat

[2012/01/31 05:30:06 | 000,000,630 | ---- | C] () -- C:\Documents and Settings\GR\Bureau\UnHackMe.lnk

[2012/01/31 04:45:52 | 011,347,294 | ---- | C] () -- C:\Documents and Settings\GR\Bureau\unhackme.zip

[2012/01/30 12:23:38 | 000,139,264 | ---- | C] () -- C:\Documents and Settings\GR\Bureau\SystemLook.exe

[2012/01/30 11:31:31 | 000,876,057 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (65).pdf

[2012/01/30 11:25:11 | 000,899,464 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (64).pdf

[2012/01/30 11:24:06 | 000,609,910 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (63).pdf

[2012/01/30 11:22:47 | 000,472,591 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (62).pdf

[2012/01/29 14:21:19 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Bureau\Malwarebytes Anti-Malware.lnk

[2012/01/28 21:13:49 | 000,000,216 | ---- | C] () -- C:\Boot.bak

[2012/01/28 21:13:47 | 000,263,488 | RHS- | C] () -- C:\cmldr

[2012/01/28 01:09:02 | 000,043,888 | ---- | C] () -- C:\Documents and Settings\GR\Bureau\stevie_wonder-overjoyed.mid

[2012/01/27 22:45:32 | 000,651,779 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (61).pdf

[2012/01/27 22:44:50 | 000,810,922 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (60).pdf

[2012/01/27 22:44:03 | 000,682,564 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (59).pdf

[2012/01/27 22:42:02 | 000,789,360 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (58).pdf

[2012/01/27 22:39:53 | 000,933,079 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (57).pdf

[2012/01/27 22:38:53 | 000,750,001 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (56).pdf

[2012/01/27 22:37:56 | 000,852,140 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (55).pdf

[2012/01/27 22:37:07 | 000,806,112 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (54).pdf

[2012/01/27 22:35:57 | 000,846,758 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (53).pdf

[2012/01/27 22:34:49 | 000,932,309 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (52).pdf

[2012/01/27 22:33:34 | 000,814,963 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (51).pdf

[2012/01/27 22:32:05 | 000,835,663 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (50).pdf

[2012/01/27 22:30:59 | 000,866,049 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (49).pdf

[2012/01/27 22:30:06 | 000,815,919 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (48).pdf

[2012/01/27 22:29:04 | 000,737,887 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (47).pdf

[2012/01/27 22:28:14 | 000,853,809 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (46).pdf

[2012/01/27 22:25:33 | 000,685,894 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (45).pdf

[2012/01/27 22:24:09 | 000,729,906 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (44).pdf

[2012/01/27 22:23:23 | 000,812,976 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (43).pdf

[2012/01/27 22:22:46 | 000,871,168 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (42).pdf

[2012/01/27 22:20:47 | 000,340,182 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (41).pdf

[2012/01/27 19:07:50 | 005,068,014 | ---- | C] () -- C:\Documents and Settings\GR\Bureau\drumaxx_install.exe

[2012/01/27 16:10:32 | 000,036,399 | ---- | C] () -- C:\Documents and Settings\GR\Bureau\France - Au chant de l'alouette[1].pdf

[2012/01/26 16:27:52 | 000,000,676 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Bureau\FL Studio 10.lnk

[2012/01/26 15:14:46 | 000,000,031 | ---- | C] () -- C:\WINDOWS\System32\deck.ini

[2012/01/26 15:14:12 | 000,000,384 | ---- | C] () -- C:\WINDOWS\System32\checkOS.bat

[2012/01/24 13:51:47 | 000,029,096 | ---- | C] () -- C:\Documents and Settings\GR\Bureau\viva.mx5

[2012/01/24 13:32:07 | 000,002,000 | ---- | C] () -- C:\Documents and Settings\GR\Bureau\[Free-scores.com]_giardini-felice-viva-tutte-vezzose-8835.midi.mid

[2012/01/24 03:37:38 | 000,004,965 | ---- | C] () -- C:\Documents and Settings\GR\Bureau\[Free-scores.com]_giardini-felice-viva-tutte-vezzose-8835.midi

[2012/01/23 14:12:28 | 000,545,338 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (40).pdf

[2012/01/23 14:08:50 | 000,671,235 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (39).pdf

[2012/01/23 14:08:07 | 000,856,873 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (38).pdf

[2012/01/23 14:07:17 | 000,745,493 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (37).pdf

[2012/01/23 14:06:33 | 000,842,185 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (36).pdf

[2012/01/23 14:05:46 | 000,886,815 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (35).pdf

[2012/01/23 14:04:44 | 000,904,954 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (34).pdf

[2012/01/23 14:03:32 | 000,905,714 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (33).pdf

[2012/01/23 14:02:44 | 000,860,224 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (32).pdf

[2012/01/23 14:01:48 | 000,789,233 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (31).pdf

[2012/01/23 14:00:40 | 000,730,275 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (30).pdf

[2012/01/23 13:59:48 | 000,868,760 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (29).pdf

[2012/01/23 13:58:19 | 000,775,376 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (28).pdf

[2012/01/23 13:54:37 | 000,715,259 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (27).pdf

[2012/01/23 13:53:35 | 000,816,480 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (26).pdf

[2012/01/21 11:47:26 | 000,333,848 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\1 voix.mp3.zpa

[2012/01/18 14:50:14 | 000,518,285 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (25).pdf

[2012/01/18 14:49:25 | 000,005,120 | ---- | C] () -- C:\Documents and Settings\GR\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2012/01/18 14:47:43 | 000,457,526 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (24).pdf

[2012/01/18 14:46:56 | 000,607,885 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (23).pdf

[2012/01/18 14:46:13 | 000,699,335 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (22).pdf

[2012/01/18 14:44:41 | 000,772,209 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (21).pdf

[2012/01/17 17:46:36 | 000,462,725 | ---- | C] () -- C:\Documents and Settings\GR\Bureau\v'la 3 voix.mp3

[2012/01/17 17:27:04 | 000,470,248 | ---- | C] () -- C:\Documents and Settings\GR\Bureau\v'la 2 voix.mp3

[2012/01/17 17:10:08 | 000,453,948 | ---- | C] () -- C:\Documents and Settings\GR\Bureau\v'la 1 voix.mp3

[2012/01/17 16:36:09 | 000,023,816 | ---- | C] () -- C:\Documents and Settings\GR\Bureau\V'la le bon vent.pdf

[2012/01/17 15:50:44 | 000,003,544 | ---- | C] () -- C:\Documents and Settings\GR\Bureau\V'la le bon vent.mscz

[2012/01/17 15:24:11 | 000,001,103 | ---- | C] () -- C:\Documents and Settings\GR\Bureau\v'la.mid

[2012/01/16 15:16:59 | 000,217,088 | ---- | C] () -- C:\WINDOWS\System32\qtmlClient.dll

[2012/01/16 14:02:26 | 000,660,665 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (20).pdf

[2012/01/16 14:01:15 | 000,844,938 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (19).pdf

[2012/01/16 13:58:19 | 000,908,863 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (18).pdf

[2012/01/16 13:55:50 | 000,926,900 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (17).pdf

[2012/01/16 13:54:32 | 000,727,823 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (16).pdf

[2012/01/16 13:53:07 | 000,769,025 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (15).pdf

[2012/01/15 12:31:50 | 000,000,866 | ---- | C] () -- C:\Documents and Settings\GR\Bureau\PDF-Viewer.lnk

[2012/01/15 10:50:46 | 000,000,803 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Bureau\Wise Registry Cleaner.lnk

[2012/01/15 10:35:54 | 000,000,780 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Bureau\Wise Disk Cleaner.lnk

[2012/01/12 22:28:32 | 000,032,279 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (14).pdf

[2012/01/12 22:27:55 | 000,033,051 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (13).pdf

[2012/01/12 22:27:17 | 000,036,053 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (12).pdf

[2012/01/12 22:26:23 | 000,031,339 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (11).pdf

[2012/01/12 22:09:59 | 000,037,882 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (10).pdf

[2012/01/09 15:44:25 | 037,864,081 | ---- | C] () -- C:\Documents and Settings\GR\Bureau\Communication Progressive du Francais (niveau intermediaire)_book.pdf

[2012/01/09 10:50:47 | 001,481,029 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (9).pdf

[2012/01/09 10:46:01 | 001,306,900 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (8).pdf

[2012/01/09 10:44:25 | 001,358,870 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (7).pdf

[2012/01/09 10:42:50 | 001,647,236 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (6).pdf

[2012/01/09 10:39:48 | 001,390,766 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (5).pdf

[2012/01/09 10:38:18 | 001,443,453 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (4).pdf

[2012/01/09 09:16:48 | 000,697,985 | ---- | C] () -- C:\Documents and Settings\GR\Mes documents\Document (3).pdf

[2012/01/08 21:27:31 | 000,014,938 | R--- | C] () -- C:\WINDOWS\System32\lvcoinst.ini

[2012/01/08 10:30:41 | 000,212,992 | ---- | C] () -- C:\WINDOWS\VMSnap23.exe

[2012/01/06 12:16:07 | 000,000,954 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Bureau\StarBurn.lnk

[2012/01/04 15:20:54 | 000,002,265 | ---- | C] () -- C:\Documents and Settings\GR\Bureau\Skype.lnk

[2011/12/29 00:14:12 | 000,040,960 | ---- | C] () -- C:\WINDOWS\Reyalp99.dll

[2011/12/23 04:30:10 | 000,003,843 | ---- | C] () -- C:\WINDOWS\TWE.INI

[2011/12/03 00:35:38 | 002,275,328 | ---- | C] () -- C:\WINDOWS\System32\libsndfile-1.dll

[2011/12/02 23:46:07 | 000,000,029 | ---- | C] () -- C:\WINDOWS\sfbm.INI

[2011/11/20 00:22:55 | 000,000,016 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Application Data\autobk.inc

[2011/11/20 00:22:53 | 000,000,016 | ---- | C] () -- C:\WINDOWS\msocreg32.dat

[2011/11/12 11:24:59 | 000,000,744 | ---- | C] () -- C:\WINDOWS\_delis32.ini

[2011/08/28 17:59:28 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI

[2011/08/25 03:04:21 | 000,039,095 | ---- | C] () -- C:\WINDOWS\iccsigs.dat

[2011/08/25 03:04:19 | 000,112,688 | ---- | C] () -- C:\WINDOWS\System32\shw32.dll

[2011/05/10 12:55:34 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat

[2011/04/23 14:01:02 | 000,000,034 | ---- | C] () -- C:\WINDOWS\System32\BD2040.DAT

[2011/04/06 13:24:44 | 000,000,022 | -HS- | C] () -- C:\Documents and Settings\GR\Application Data\Sys2662.Config.Repository.bin

[2011/04/03 11:36:43 | 000,000,271 | ---- | C] () -- C:\WINDOWS\PR1V2.INI

[2011/04/03 00:29:47 | 000,000,086 | ---- | C] () -- C:\WINDOWS\robert.ini

[2011/03/04 00:12:49 | 000,000,072 | ---- | C] () -- C:\WINDOWS\wininit.ini

[2011/02/26 09:51:06 | 000,040,960 | R--- | C] () -- C:\WINDOWS\System32\setupfilter.exe

[2011/02/26 09:51:02 | 000,081,920 | R--- | C] () -- C:\WINDOWS\VMCap323.exe

[2011/02/23 02:18:38 | 000,000,242 | ---- | C] () -- C:\WINDOWS\Brpfx04a.ini

[2011/02/23 02:18:38 | 000,000,093 | ---- | C] () -- C:\WINDOWS\brpcfx.ini

[2011/02/23 02:18:07 | 000,000,824 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI

[2011/02/23 02:14:16 | 000,000,050 | ---- | C] () -- C:\WINDOWS\System32\bridf08b.dat

[2011/02/23 02:13:59 | 000,000,000 | ---- | C] () -- C:\WINDOWS\brdfxspd.dat

[2011/02/23 02:09:01 | 000,031,767 | ---- | C] () -- C:\WINDOWS\maxlink.ini

[2011/02/19 14:07:28 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat

[2011/02/19 13:48:37 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat

[2011/02/19 07:52:11 | 000,004,205 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI

[2011/02/19 07:48:48 | 000,167,504 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2011/02/19 07:12:57 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat

[2011/02/19 07:05:28 | 000,021,892 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat

[2009/05/29 23:42:20 | 000,309,248 | ---- | C] () -- C:\WINDOWS\System32\sqlite36_engine.dll

[2009/03/11 20:01:28 | 000,023,552 | ---- | C] () -- C:\WINDOWS\System32\DirectCOM.dll

[2008/12/01 17:53:34 | 005,607,424 | ---- | C] () -- C:\WINDOWS\System32\smh-qt-mt336.dll

[2006/09/13 12:06:10 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\gtapi.dll

[2005/01/25 02:00:00 | 000,016,857 | ---- | C] () -- C:\WINDOWS\System32\bh2040.ini

[2004/08/05 13:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat

[2004/08/05 13:00:00 | 000,542,728 | ---- | C] () -- C:\WINDOWS\System32\perfh00C.dat

[2004/08/05 13:00:00 | 000,472,478 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat

[2004/08/05 13:00:00 | 000,322,810 | ---- | C] () -- C:\WINDOWS\System32\perfi00C.dat

[2004/08/05 13:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat

[2004/08/05 13:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat

[2004/08/05 13:00:00 | 000,090,872 | ---- | C] () -- C:\WINDOWS\System32\perfc00C.dat

[2004/08/05 13:00:00 | 000,076,018 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat

[2004/08/05 13:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin

[2004/08/05 13:00:00 | 000,034,108 | ---- | C] () -- C:\WINDOWS\System32\perfd00C.dat

[2004/08/05 13:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat

[2004/08/05 13:00:00 | 000,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys

[2004/08/05 13:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat

[2004/08/05 13:00:00 | 000,001,788 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin

[2004/08/05 13:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat

[2004/08/03 02:00:00 | 000,000,411 | ---- | C] () -- C:\WINDOWS\System32\bw2040.ini

[2004/07/23 02:00:00 | 000,000,066 | ---- | C] () -- C:\WINDOWS\System32\be2040.dat

[2003/08/12 02:02:00 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\getuser.exe

[2002/05/28 18:55:42 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin

[2002/05/28 18:54:40 | 000,004,605 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat

[1999/10/27 02:00:00 | 000,000,050 | ---- | C] () -- C:\WINDOWS\System32\ba2040.dat

========== LOP Check ==========

[2011/02/19 13:54:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Acoustica

[2011/02/19 14:02:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Alwil Software

[2011/11/29 15:27:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Media Get LLC

[2011/04/10 09:54:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\NCH Swift Sound

[2012/01/16 15:39:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\PACE Anti-Piracy

[2011/02/23 02:47:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\ScanSoft

[2012/01/04 11:42:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Steinberg

[2011/12/28 01:01:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\VST XMLs

[2011/12/31 03:17:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\VST3 Presets

[2012/01/04 11:43:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Zeon

[2011/12/27 20:54:57 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\{00E0164B-B182-4800-96DA-F8D39B3A7189}

[2011/10/17 01:37:34 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\{32364CEA-7855-4A3C-B674-53D8E9B97936}

[2012/01/04 11:51:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GR\Application Data\Acoustica

[2012/01/04 12:47:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GR\Application Data\Applied Acoustics Systems

[2012/01/13 16:37:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GR\Application Data\Image-Line

[2012/01/26 16:14:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GR\Application Data\MMFApplications

[2012/01/17 15:25:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GR\Application Data\MusE

[2012/01/04 17:59:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GR\Application Data\OpenOffice.org

[2012/01/16 15:39:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GR\Application Data\PACE Anti-Piracy

[2012/01/04 02:15:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GR\Application Data\PeaZip

[2012/01/04 11:42:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GR\Application Data\ScanSoft

[2012/01/06 12:20:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GR\Application Data\StarBurn

[2012/01/04 11:42:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GR\Application Data\Steinberg

[2012/01/18 05:18:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GR\Application Data\SynthMaker

[2012/01/20 12:46:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GR\Application Data\TightVNC

[2012/01/28 14:04:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GR\Application Data\uTorrent

[2012/01/04 11:42:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GR\Application Data\VST3 Presets

[2012/01/11 14:17:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GR\Application Data\Waves

[2012/01/16 16:01:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GR\Application Data\Waves Audio

[2012/01/16 16:11:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GR\Application Data\Waves Preferences

[2012/01/15 11:59:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GR\Application Data\Wise Disk Cleaner

[2012/01/15 12:02:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GR\Application Data\Wise Registry Cleaner

[2012/01/04 11:43:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\GR\Application Data\Zeon

========== Purity Check ==========

========== Files - Unicode (All) ==========

[2011/05/03 18:50:26 | 000,013,824 | ---- | M] ()(C:\Documents and Settings\GR\Bureau\?????.odt) -- C:\Documents and Settings\GR\Bureau\пиано.odt

[2011/05/03 18:47:50 | 000,013,824 | ---- | C] ()(C:\Documents and Settings\GR\Bureau\?????.odt) -- C:\Documents and Settings\GR\Bureau\пиано.odt

[2011/05/03 14:23:35 | 000,014,205 | ---- | M] ()(C:\Documents and Settings\GR\Mes documents\?????.odt) -- C:\Documents and Settings\GR\Mes documents\пиано.odt

[2011/05/03 13:49:21 | 000,014,205 | ---- | C] ()(C:\Documents and Settings\GR\Mes documents\?????.odt) -- C:\Documents and Settings\GR\Mes documents\пиано.odt

< End of report >

Благодаря

Публикувано изображение Стартирайте отново OTL, копирайте (Copy) и поставете (Paste) скриптовия текст от текстовото поле по-долу под колонката Custom Scans/Fixes, като не забравяте да копирате скрипта 1 към 1, както и двете точки преди първия ред на скрипта.

:OTL
O4 - HKLM..\RunOnceEx: [Flags] Reg Error: Invalid data type. File not found
O4 - HKLM..\RunOnceEx: [Title] UnHackMe Rootkit Check File not found

:Reg

:files

autorun.inf /alldrives
autorun.exe /alldrives
recycler /alldrives
ipconfig /flushdns /c

:Commands
[purity]
[emptytemp]
[resethosts]
[clearallrestorepoints]
[emptyflash]
[Reboot]

Публикувано изображение След като въведете скрипта от цитата по-горе натиснете бутона, маркиран в червено: Run Fix

Windows ще се рестартира и ще се създаде лог файл. Публикувайте съдържанието му с Copy/Paste в следващия си коментар.

  • Автор

Ето това излезе след рестарта

All processes killed

========== OTL ==========

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx\\Flags deleted successfully.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx\\Title deleted successfully.

========== REGISTRY ==========

========== FILES ==========

autorun.inf not found in C:\

autorun.exe not found in C:\

C:\RECYCLER\S-1-5-21-1417001333-1767777339-725345543-1004 folder moved successfully.

C:\RECYCLER folder moved successfully.

< ipconfig /flushdns /c >

Configuration IP de Windows

Cache de résolution DNS vidé.

C:\Documents and Settings\GR\Bureau\cmd.bat deleted successfully.

C:\Documents and Settings\GR\Bureau\cmd.txt deleted successfully.

========== COMMANDS ==========

[EMPTYTEMP]

User: Administrateur

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

User: Administrateur.GR-E99077D3BD63

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: All Users.WINDOWS

User: client

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

->Java cache emptied: 0 bytes

->FireFox cache emptied: 0 bytes

->Flash cache emptied: 0 bytes

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

User: Default User.WINDOWS

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

User: GR

->Temp folder emptied: 1724416 bytes

->Temporary Internet Files folder emptied: 30258417 bytes

->FireFox cache emptied: 0 bytes

->Flash cache emptied: 904 bytes

User: LocalService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

User: LocalService.AUTORITE NT

->Temp folder emptied: 66016 bytes

->Temporary Internet Files folder emptied: 33170 bytes

->Java cache emptied: 0 bytes

->Flash cache emptied: 0 bytes

User: NetworkService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

User: NetworkService.AUTORITE NT

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 0 bytes

%systemroot%\System32 .tmp files removed: 0 bytes

%systemroot%\System32\dllcache .tmp files removed: 0 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 0 bytes

%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes

%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes

RecycleBin emptied: 0 bytes

Total Files Cleaned = 31,00 mb

C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.

HOSTS file reset successfully

Restore points cleared and new OTL Restore Point set!

[EMPTYFLASH]

User: Administrateur

User: Administrateur.GR-E99077D3BD63

User: All Users

User: All Users.WINDOWS

User: client

->Flash cache emptied: 0 bytes

User: Default User

User: Default User.WINDOWS

User: GR

->Flash cache emptied: 0 bytes

User: LocalService

User: LocalService.AUTORITE NT

->Flash cache emptied: 0 bytes

User: NetworkService

User: NetworkService.AUTORITE NT

Total Flash Files Cleaned = 0,00 mb

OTL by OldTimer - Version 3.2.31.0 log created on 02032012_143250

Files\Folders moved on Reboot...

File\Folder C:\Documents and Settings\GR\Local Settings\Temp\~DF249E.tmp not found!

File\Folder C:\Documents and Settings\GR\Local Settings\Temp\~DF6566.tmp not found!

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\VHPVFGR2\TCAMVBJ5VCAWRU19UCAOCYMH4CA5URRUQCA12KAGGCA5T7G3DCACWP8L2CAKJSOC2CANJ1SFPCAO5R6R8CALN0Z8KCAWFYDEWCAP1HUXKCAGIUZGQCASVP07NCAR2OW62CAWIE4JFCAY7DV9ICA6W6QUECAX6CPG6.htm moved successfully.

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\VHPVFGR2\xd_proxy[2].htm moved successfully.

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\G1TX45VR\DCA6OB5ABCAQ7VELMCABV0KL2CA5KZ4N3CAFLCUFHCAW1ONT7CAS5282SCAAKC52WCA57M23MCAZGMP6GCAKTHCCCCA6TLBZLCA7723V5CAM19ZX7CAYB8C6OCA8FQIC5CAKCZIDZCAYSPNCZCAXOT3MCCAIZDHGW.htm moved successfully.

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\G1TX45VR\QCAJM9DZTCAVU3A4YCA5N8NS0CAAM93U7CA4XUJF7CASE4LVOCAL3R3MHCAI1JO67CA7M3Q0ZCA3NV4YOCA0HQWUKCACUA4D1CA8D8HLICASVE34DCAN32A6UCA344ZG6CAWH4A3WCANF40GKCAMWUG3JCAUDUTY1.htm moved successfully.

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\G1TX45VR\search[3].htm moved successfully.

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\95AEIXGJ\fb_iframe[1].html moved successfully.

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\95AEIXGJ\index[2].htm moved successfully.

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\95AEIXGJ\login_status[1].htm moved successfully.

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\95AEIXGJ\RCADU22SYCAU5YL8HCAB76R89CAQS2WITCAI7TYX2CASZPBBFCAHZW0MJCANNT2RRCAEZ3NNVCAF3T6BNCA8F8E6NCANUYJ12CA3SNXF6CAZTN6K4CAJUQRH4CAMC4ALECAOSRCG4CAT2K5GVCAIWF70TCAR1I44G.htm moved successfully.

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\13RDR193\8CA3H2HKLCAA06CTJCALRMJU6CAY0A9Y4CA91M34LCA67J41GCA8Y5NQRCARRSE2DCAL96U6GCAA1QXRSCAR9N5SOCALU5DNXCA5XL2IWCAXKXYYRCA4ZDVMXCAC3L237CAW5SMF8CA73DFIZCA6MZYP7CAR63WRN.htm moved successfully.

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\13RDR193\fastbutton[1].htm moved successfully.

C:\Documents and Settings\GR\Local Settings\Temporary Internet Files\Content.IE5\13RDR193\like[1].htm moved successfully.

File move failed. C:\WINDOWS\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot...

Е, вече с чиста съвест мога да кажа че системата ви е чиста..! :)

Стартирайте OTL още веднъж и натиснете бутона CleanUp.

Публикувано изображение

Ще последва рестарт на компютъра ви..!

Сега е монента да деинсталирате/изтриете всички програмки, фиксове и логове които използвахме в темата (които са останали).Препоръчвам да си оставите Malwarebytes' Anti-Malware и перодически да сканирате с нея.Все пак не забравяйте че това не е антивирусна програма.

Остана нещо много важно и задължително за изпълнение...:Изтеглете Service Pack 3 и го запомнете на вашия десктоп.Затворете всички приложения и стартирайте файла с двоен клик..След като процедурата завърши рестартирайте компютъра си.

  • Автор

Е сега вече с чиста съвест и чиста система искам да ви кажа колко много ви благодаря за проявеното търпение и ентусиазъм. Ще направя последните инструкции .Благодаря

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.