Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Disabled.Cryptsvc [РЕШЕН]

Featured Replies

Здравейте ! Сканирах с МБАМ - тя откри Disabled.Cryptsvc, Backdoor.Trace - успешно ги изтри под карантина, криптографската услуга си стоеше принципно на ръчен режим, но реших да я изключа и в следващия рестарт - услугата сама се поставила на ръчен режим, преинсталирах Malwarebyte сканирах наново и отново откри Disabled.Cryptsvc - съответно пак го поставих под карантина ..... а Malwarebyte е направила криптографската услуга на автоматичен режим - направих сканирания с Нод32 и САС ... но те не откриват нищо .... ето логовете от ДДС а след тях поставям лога от МБАМ . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 8.0.6001.18702 Run by Rosen at 21:18:53 on 2012-02-03 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.511.198 [GMT 2:00] . AV: ESET NOD32 Antivirus 3.0 *Enabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} . ============== Running Processes =============== . C:\WINDOWS\system32\svchost.exe -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe C:\WINDOWS\Explorer.EXE C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe C:\Program Files\IObit\Advanced SystemCare 4\Suo10_SmartRAM.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\taskmgr.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\Mozilla Firefox\firefox.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://google.bg/ BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll uRun: [smartRAM] "c:\program files\iobit\advanced systemcare 4\Suo10_SmartRAM.exe" /m uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE uPolicies-explorer: NoInstrumentation = 1 (0x1) IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos-beta/OnlineScanner.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: Interfaces\{C2A023CD-E149-4041-B456-7F76BA5D7562} : NameServer = 93.155.228.1 Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\rosen\application data\mozilla\firefox\profiles\c717psmr.default\ FF - prefs.js: browser.startup.homepage - hxxp://google.bg FF - prefs.js: network.proxy.type - 0 FF - plugin: c:\program files\microsoft silverlight\4.0.50917.0\npctrlui.dll . ============= SERVICES / DRIVERS =============== . R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2007-10-25 30728] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656] R2 ekrn;Eset Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2007-10-25 455936] S3 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2004-8-4 14336] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] S4 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\iobit\advanced systemcare 4\ASCService.exe [2011-10-24 353168] S4 ASO3DiskOptimizer;ASO3DiskOptimizer;c:\program files\advanced system optimizer 3\ASO3DefragSrv.exe [2012-1-11 199400] S4 CachemanXPService;CachemanXP;c:\program files\cachemanxp\cachemanxp.exe --> c:\program files\cachemanxp\CachemanXP.exe [?] . =============== File Associations =============== . JSEFile=NOTEPAD.EXE %1 . =============== Created Last 30 ================ . 2012-02-03 18:56:33 20464 ----a-w- c:\windows\system32\drivers\mbam.sys 2012-02-02 17:32:28 -------- d-----w- c:\program files\Skype 2012-02-02 09:03:02 -------- d-----w- c:\program files\TuneXP 2012-01-30 12:23:22 -------- d-----w- c:\documents and settings\all users\application data\AltrixSoft 2012-01-25 09:37:15 -------- d-----w- c:\windows\XSxS 2012-01-24 18:36:50 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-01-24 08:28:33 -------- d-----w- c:\program files\ESET 2012-01-13 13:33:04 -------- d-----w- c:\documents and settings\rosen\local settings\application data\Mozilla 2012-01-11 21:40:49 17136 ----a-w- c:\windows\system32\sasnative32.exe 2012-01-11 21:40:35 -------- d-----w- c:\program files\Advanced System Optimizer 3 2012-01-07 14:12:58 -------- d-----w- c:\documents and settings\rosen\local settings\application data\Help . ==================== Find3M ==================== . 2011-11-11 11:33:00 162816 ----a-w- c:\windows\system32\drivers\netbt.sys . ============= FINISH: 21:19:42,98 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 10.12.2010 г. 23:37:09 System Uptime: 03.2.2012 г. 21:09:57 (0 hours ago) . Motherboard: | | i815-W83627 Processor: Intel® Celeron CPU 1300MHz | Socket 370 | 1302/100mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 19 GiB total, 11,148 GiB free. D: is FIXED (NTFS) - 20 GiB total, 8,24 GiB free. . ==== Disabled Device Manager Items ============= . Class GUID: {4D36E96A-E325-11CE-BFC1-08002BE10318} Description: Primary IDE Channel Device ID: PCIIDE\IDECHANNEL\4&176D7B6C&0&0 Manufacturer: (Standard IDE ATA/ATAPI controllers) Name: Primary IDE Channel PNP Device ID: PCIIDE\IDECHANNEL\4&176D7B6C&0&0 Service: atapi . Class GUID: {4D36E969-E325-11CE-BFC1-08002BE10318} Description: Standard floppy disk controller Device ID: ACPI\PNP0700\3&13C0B0C5&0 Manufacturer: (Standard floppy disk controllers) Name: Standard floppy disk controller PNP Device ID: ACPI\PNP0700\3&13C0B0C5&0 Service: fdc . Class GUID: {4D36E978-E325-11CE-BFC1-08002BE10318} Description: Communications Port Device ID: ACPI\PNP0501\1 Manufacturer: (Standard port types) Name: Communications Port (COM1) PNP Device ID: ACPI\PNP0501\1 Service: Serial . Class GUID: {4D36E978-E325-11CE-BFC1-08002BE10318} Description: Communications Port Device ID: ACPI\PNP0501\2 Manufacturer: (Standard port types) Name: Communications Port (COM2) PNP Device ID: ACPI\PNP0501\2 Service: Serial . Class GUID: {4D36E978-E325-11CE-BFC1-08002BE10318} Description: ECP Printer Port Device ID: ACPI\PNP0401\3&13C0B0C5&0 Manufacturer: (Standard port types) Name: ECP Printer Port (LPT1) PNP Device ID: ACPI\PNP0401\3&13C0B0C5&0 Service: Parport . ==== System Restore Points =================== . RP100: 15.1.2012 г. 08:51:35 - Before uninstalling Mozilla Firefox (3.6.9) RP101: 13.1.2012 г. 16:48:58 - Before uninstalling McAfee Security Scan Plus RP102: 13.1.2012 г. 16:49:02 - Before uninstalling Adobe Flash Player 10 Plugin RP103: 25.1.2012 г. 01:43:47 - Before uninstalling Mozilla Firefox 5.0 (x86 bg) RP104: 25.1.2012 г. 01:43:51 - Before uninstalling Mozilla Firefox 4.0.1 (x86 bg) RP105: 16.1.2012 г. 21:56:43 - Before uninstalling Mozilla Firefox (3.6.9) RP106: 15.1.2012 г. 08:52:27 - контролна точка на системата RP107: 02.2.2012 г. 17:55:57 - Before uninstalling ESET NOD32 Antivirus RP108: 25.1.2012 г. 01:44:05 - ESET NOD32 Antivirus е премахнат RP109: 25.1.2012 г. 01:44:00 - Installed ESET NOD32 Antivirus RP110: 25.1.2012 г. 01:44:11 - Before uninstalling Mozilla Firefox 5.0 (x86 bg) RP111: 25.1.2012 г. 01:43:56 - Before uninstalling Mozilla Firefox 7.0 (x86 bg) RP112: 02.2.2012 г. 17:55:59 - Advanced System Optimizer RP113: 25.1.2012 г. 01:44:16 - Before uninstalling Recover My Files RP114: 02.2.2012 г. 17:56:23 - Installed ESET NOD32 Antivirus RP115: 02.2.2012 г. 17:56:03 - Before uninstalling Adobe Flash Player 11 Plugin RP116: 02.2.2012 г. 17:56:18 - Before uninstalling Adobe Flash Player 10 Plugin RP117: 27.1.2012 г. 22:10:53 - System Checkpoint RP118: 02.2.2012 г. 17:56:26 - Before uninstalling Mozilla Firefox 5.0 (x86 bg) RP119: 02.2.2012 г. 17:19:48 - Before uninstalling Skype™ 3.8 RP120: 02.2.2012 г. 17:20:11 - Премахнат Skype™ 3.8 RP121: 02.2.2012 г. 19:28:12 - Премахнат Skype™ 3.8 RP122: 03.2.2012 г. 10:30:41 - Before uninstalling TuneXP 1.5 RP123: 03.2.2012 г. 20:52:44 - Before uninstalling Malwarebytes Anti-Malware, версия 1.60.0.1800 . ==== Installed Programs ====================== . µTorrent Adobe AIR Adobe Flash Player 11 Plugin Adobe Reader 9.4.0 Advanced System Optimizer Advanced SystemCare 4 Avance AC'97 Audio Bulgarian (Phonetic Traditional) C-Media WDM Audio Driver CCleaner Compatibility Pack for the 2007 Office system ESET NOD32 Antivirus ESET Online Scanner v3 Google Chrome HD Tune 2.55 HD Tune Pro 4.60 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) ItaEst - Taka e! K-Lite Codec Pack 7.2.0 (Standard) Malwarebytes Anti-Malware, версия 1.60.0.1800 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB2416447) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 4 Client Profile Microsoft Base Smart Card Cryptographic Service Provider Package Microsoft Office Professional Edition 2003 Microsoft Silverlight Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Mozilla Firefox 5.0 (x86 bg) Opera 11.50 PowerISO Recuva SA Dictionary 2008 Beta 4 Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) Security Update for Windows Internet Explorer 8 (KB2360131) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows XP (KB2360131) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB981349) Skype™ 3.8 Smart Defrag SUPERAntiSpyware SVD TeamViewer 4 TeamViewer 7 Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 8 (KB2447568) Update for Windows Internet Explorer 8 (KB976662) Update for Windows XP (KB951978) WebFldrs XP Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray Windows Internet Explorer 8 Windows Management Framework Core Windows Media Format 11 runtime Windows Media Format SDK Hotfix - KB891122 Windows Media Player 11 WinRAR archiver Your Uninstaller! 2010 . ==== Event Viewer Messages From Past Week ======== . 31.1.2012 г. 19:20:02, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 31.1.2012 г. 16:45:02, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 31.1.2012 г. 16:43:35, error: Service Control Manager [7034] - The MBAMService service terminated unexpectedly. It has done this 1 time(s). 31.1.2012 г. 15:58:38, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 31.1.2012 г. 14:52:34, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 31.1.2012 г. 14:45:13, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 31.1.2012 г. 14:11:20, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 31.1.2012 г. 12:33:06, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 31.1.2012 г. 12:32:45, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 31.1.2012 г. 10:42:41, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 31.1.2012 г. 10:40:13, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 31.1.2012 г. 08:28:57, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 30.1.2012 г. 23:29:44, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 30.1.2012 г. 20:56:38, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 30.1.2012 г. 20:36:49, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 30.1.2012 г. 19:54:36, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 30.1.2012 г. 14:35:51, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 30.1.2012 г. 14:23:22, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the HDD Information Service service to connect. 30.1.2012 г. 14:23:22, error: Service Control Manager [7000] - The HDD Information Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 30.1.2012 г. 14:23:22, error: Service Control Manager [7000] - The HDD Information Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 30.1.2012 г. 14:23:21, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the HDD Information Service service to connect. 30.1.2012 г. 14:03:57, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 30.1.2012 г. 13:16:06, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 30.1.2012 г. 12:44:16, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 30.1.2012 г. 12:44:08, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 30.1.2012 г. 12:43:18, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 30.1.2012 г. 12:16:20, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 30.1.2012 г. 08:13:23, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 29.1.2012 г. 23:20:39, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 29.1.2012 г. 21:51:37, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 29.1.2012 г. 21:49:53, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 29.1.2012 г. 19:04:18, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 29.1.2012 г. 17:16:36, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 29.1.2012 г. 08:57:47, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 29.1.2012 г. 08:54:23, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 29.1.2012 г. 08:20:36, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 29.1.2012 г. 08:20:21, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 29.1.2012 г. 08:13:52, error: Service Control Manager [7034] - The Windows Installer service terminated unexpectedly. It has done this 1 time(s). 28.1.2012 г. 15:43:12, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 28.1.2012 г. 14:31:28, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 28.1.2012 г. 13:23:07, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 28.1.2012 г. 12:48:56, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 28.1.2012 г. 08:28:41, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 27.1.2012 г. 18:25:49, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 27.1.2012 г. 18:02:45, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 27.1.2012 г. 15:11:57, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 27.1.2012 г. 13:37:09, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 27.1.2012 г. 13:36:06, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 27.1.2012 г. 13:23:54, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 27.1.2012 г. 12:55:57, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 27.1.2012 г. 08:22:43, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 03.2.2012 г. 20:58:16, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 03.2.2012 г. 20:53:00, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 03.2.2012 г. 20:50:22, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 03.2.2012 г. 20:49:59, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 03.2.2012 г. 19:08:40, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 03.2.2012 г. 16:52:42, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 03.2.2012 г. 16:51:55, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 03.2.2012 г. 15:46:37, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 03.2.2012 г. 14:51:02, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 03.2.2012 г. 14:03:02, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 03.2.2012 г. 14:00:58, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 03.2.2012 г. 13:59:56, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 03.2.2012 г. 12:13:17, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 03.2.2012 г. 10:35:17, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 03.2.2012 г. 09:23:14, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 03.2.2012 г. 09:02:04, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 03.2.2012 г. 08:33:16, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 02.2.2012 г. 21:01:43, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 02.2.2012 г. 20:56:06, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 02.2.2012 г. 19:27:41, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 02.2.2012 г. 19:17:06, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 02.2.2012 г. 17:55:17, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 02.2.2012 г. 17:53:44, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 02.2.2012 г. 17:32:52, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 02.2.2012 г. 16:19:49, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 02.2.2012 г. 16:00:20, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 02.2.2012 г. 12:51:43, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 02.2.2012 г. 12:50:59, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 02.2.2012 г. 12:48:18, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 02.2.2012 г. 12:25:11, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 02.2.2012 г. 11:48:42, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 02.2.2012 г. 11:40:38, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 02.2.2012 г. 11:18:00, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 02.2.2012 г. 09:53:59, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 02.2.2012 г. 09:41:38, error: Service Control Manager [7001] - The Remote Access Auto Connection Manager service depends on the Remote Access Connection Manager service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. 02.2.2012 г. 09:39:12, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 02.2.2012 г. 09:33:55, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 02.2.2012 г. 09:28:40, error: Service Control Manager [7001] - The Remote Access Auto Connection Manager service depends on the Remote Access Connection Manager service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. 02.2.2012 г. 09:04:12, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 02.2.2012 г. 08:15:19, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 02.2.2012 г. 08:12:56, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 01.2.2012 г. 21:55:47, error: Service Control Manager [7034] - The MBAMService service terminated unexpectedly. It has done this 1 time(s). 01.2.2012 г. 17:39:07, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 01.2.2012 г. 16:00:33, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service helpsvc with arguments "" in order to run the server: {833E4010-AFF7-4AC3-AAC2-9F24C1457BCE} 01.2.2012 г. 16:00:29, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service helpsvc with arguments "" in order to run the server: {833E4010-AFF7-4AC3-AAC2-9F24C1457BCE} 01.2.2012 г. 15:16:09, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 01.2.2012 г. 14:57:31, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 01.2.2012 г. 14:31:06, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 01.2.2012 г. 12:27:10, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 01.2.2012 г. 12:15:40, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 01.2.2012 г. 10:58:11, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 01.2.2012 г. 10:36:20, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 01.2.2012 г. 09:42:17, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 01.2.2012 г. 09:41:20, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 01.2.2012 г. 09:01:02, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 01.2.2012 г. 08:43:31, error: Service Control Manager [7034] - The MBAMService service terminated unexpectedly. It has done this 1 time(s). 01.2.2012 г. 08:21:09, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} . ==== End Of File =========================== ето и лога от МБАМ Malwarebytes Anti-Malware 1.60.0.1800 www.malwarebytes.org Версия на базата от данни: v2012.02.03.04 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Rosen :: MYPC [администратор] 03.2.2012 г. 10:46:37 mbam-log-2012-02-03 (10-46-37).txt Тип сканиране: Бързо сканиране Включени опции за сканиране: Памет | Автоматично зареждане | Системен регистър | Файлова система | Евристики/Допълнителни | Евристики/Shuriken | PUP | PUM Изключени опции за сканиране: P2P Сканирани обекти: 192707 Изминало време: 5 минута(и), 50 секунда(и) Открити процеси в паметта: 0 (Не бяха открити зловредни обекти) Открити модули в паметта: 0 (Не бяха открити зловредни обекти) Открити ключове в системния регистър: 1 HKCU\SOFTWARE\CYBER (Backdoor.Trace) -> Поставен под карантина и изтрит успешно. Открити стойности в системния регистър: 1 HKCU\Software\Cyber|FirstExecution (Backdoor.Trace) -> Данни: 08/11/2011 -- 23:31 -> Поставен под карантина и изтрит успешно. Открити информационни обекти в системния регистър: 1 HKLM\SYSTEM\CurrentControlSet\Services\CryptSvc|Start (Disabled.Cryptsvc) -> Лош: (4) Добър: (2) -> Поставен под карантина и поправен успешно. Открити папки: 0 (Не бяха открити зловредни обекти) Открити файлове: 0 (Не бяха открити зловредни обекти) (край)

  • Автор

Ако не пипам криптографската услуга и не я спирам, Malwarebyte не открива зараза, но ако я сложа на disabled, и направя сканиране с МБАМ - пак открива disabled.cryptsvc - слагам го под карантина и това се повтаря всеки път..... заразен ли съм или е някаква грешка ?

Здравейте..!Въпросът е защо искате да изключите Cryptographic Services..?

По подразбиране тази служба трябва да е на автомат...!Една от важните служби за правилното функциониране на Windows.

Какво прави тя:

  • проверява цифровите подписи нс файловете на Windows
  • необходима е за обновления на Windows в автоматичен и ръчен режим.
  • за правилната инсталация и работа на Service Pack, DirectX , Windows Media Player и някой. NET приложения.
Или какво се случва - вие изключвате услугата ръчно и МБМА си мисли че има проблем и я поправя:

HKLM\SYSTEM\CurrentControlSet\Services\CryptSvc|Start (Disabled.Cryptsvc) -> Лош: (4) Добър: (2) -> Поставен под карантина и поправен успешно.

  • Автор

Спрял съм десетина услуги, за да спестя рам. За криптографския сървиз бях чел че отговарял само за ъпдейтите на Windows, но в свойствата на услугата видях че тя зависи от Remote procedure call, и затова я оставих на ръчен режим, да се включва когато има нужда от нея.... Предполагах че МБАМ - открива зараза при disabled криптографския сървиз, а не лоша настройка. След вашите пояснения оставям услугата на автоматичен режим P.S. Незнаех че е нужна за за правилната инсталация и работа на Service Pack, DirectX , Windows Media Player и някой. NET приложения. Благодаря !

Публикувано изображение Изтеглете ComboFix Публикувано изображение от тук или тук и го запазете на десктопа си.

  • Изключете вашата антивирусна и антишпионска програма, обикновено това става чрез натискане на десния бутон на мишката върху иконата на програма в системния трей.
Бележка: Ако не можете я спрете или не сте сигурни коя програма да изключите, моля прегледайте информацията от този линк: How to Disable your Security Programs
  • Стартирайте Combo-Fix.com Публикувано изображение и следвайте инструкциите.
Бележка: ComboFix ще се стартира без инсталирана Recovery Console.
  • Като част от неговата работа, ComboFix ще провери дали Microsoft Windows Recovery Console е инсталирана. Предвид бързо развиващия се зловреден софтуер е силно препоръчително да бъде инсталирана преди премахването на зловредния софтуер. Това ще Ви позволи да влезете в специален recovery/repair режим, който ще ни позволи по-лесно да решите проблем, който би могъл да възникне при премахване на зловредния софтуер.
  • Следвайте инструкциите, за да позволите на ComboFix да изтегли и инсталира Microsoft Windows Recovery Console. В един момент ще бъдете попитани дали сте съгласни с лицензното споразумение. Необходимо е да потвърдите, че сте съгласни, за да инсталирате Microsoft Windows Recovery Console.
** Забележете: Ако Microsoft Windows Recovery Console е вече инсталирана, ComboFix ще продължи към процеса по премахване на зловредния софтуер.

Публикувано изображение

След като Microsoft Windows Recovery Console е инсталирана, използвайки ComboFix, Вие ще видите следното съобщение:

Публикувано изображение

Изберете Yes, за да продължи сканирането за зловреден софтуер.

Когато процесът приключи успешно, инструментът ще създаде лог файл. Моля, включете съдържанието на C:\ComboFix.txt в следващия Ви коментар в тази тема.

Бележка:

  • Моля, не движете мишката, докато ComboFix работи. Това може да наруши процеса на работа.
  • ComboFix ще нулира всички настройки на Microsoft Internet Explorer, включително да направи IE браузър по подразбиране.
  • ComboFix ще изключи autorun функцията на ВСИЧКИ CD, Floppy и USB устройства, за да помогне при премахването на зловредния софтуер и Ви защити от бъдещи вируси/заплахи, които поразяват чрез autorun. Ако това е проблем за вас - моля, уведомете ме.
  • ComboFix ще изключи вашата интернет връзка. Интернет връзката ще се възстанови автоматично, преди ComboFix да завърши процеса на работа. При проблем, той ще прекрати интернет връзката. За да възстановите интернет връзката си, рестартирайте компютъра си.
  • В случай на проблем с ComboFix, той може да създаде лог файл. Моля, включете съдържанието на C:\BUG.txt в следващия Ви коментар в тази тема.
Публикувано изображение Моля, не прикачвайте лог файла/овете от програмата, а го/ги копирайте и поставете в следващия Ви коментар в тази тема.

Публикувано изображение Моля, изтеглете последната версия на TDSSKiller - оттук и я запазете на вашия декстоп.

  • Стартирайте TDSSKiller.exe за да стартирате приложението. След това кликнете върху бутона Change parameters.

    Публикувано изображение

  • Сложете отметки пред Verify Driver Digital Signature и Detect TDLFS file system и натиснете ОК.

    Публикувано изображение

  • Натиснете бутона Start Scan.

    Публикувано изображение

  • Ако подозрителен обект бъде засечен, действието по подразбиране ще бъде Skip, кликнете върху Continue.

    Публикувано изображение

  • Ако зловредни обекти бъдат намерени, тогава от падащото меню ще имате три възможности.

    Бъдете сигурни, че избраното действие е Cure и натиснете върху Continue > Рестартирайте за да бъде завършена поправката.

    Публикувано изображение

    Забележка: Ако Cure бутона не е наличен от възможностите, тогава моля изберете Skip бутона, не избирайте Delete освен ако не сте инструктирани затова.

  • Лог файл ще бъде създаден в свободната директория на дял C:\ . Потърсете за лог с името "TDSSKiller.[Version]_[Date]_[Time]_log.txt" и копирайте съдържанието му в следващия си пост.
  • Автор

ComboFix 12-02-07.01 - Rosen 02.2012 г. 13:21:27.4.1 - x86 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.511.223 [GMT 2:00] Running from: c:\documents and settings\Rosen\Desktop\ComboFix.exe AV: ESET NOD32 Antivirus 3.0 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\documents and settings\All Users\Application Data\TEMP c:\windows\XSxS . . ((((((((((((((((((((((((( Files Created from 2012-01-08 to 2012-02-08 ))))))))))))))))))))))))))))))) . . 2012-02-03 18:56 . 2011-12-10 13:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys 2012-02-02 17:32 . 2012-02-02 17:32 -------- d-----w- c:\program files\Skype 2012-02-02 17:32 . 2012-02-02 17:32 -------- d-----w- c:\program files\Common Files\Skype 2012-01-30 12:23 . 2012-01-30 12:23 -------- d-----w- c:\documents and settings\All Users\Application Data\AltrixSoft 2012-01-24 18:36 . 2012-01-24 18:36 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-01-24 08:28 . 2012-01-24 08:28 -------- d-----w- c:\program files\ESET 2012-01-24 08:28 . 2012-01-24 08:28 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET 2012-01-18 12:55 . 2012-01-18 12:55 -------- d-----w- c:\program files\Recuva 2012-01-13 13:33 . 2012-01-13 13:33 -------- d-----w- c:\documents and settings\Rosen\Local Settings\Application Data\Mozilla 2012-01-11 21:40 . 2009-08-19 14:49 17136 ----a-w- c:\windows\system32\sasnative32.exe 2012-01-11 21:40 . 2012-01-11 21:46 -------- d-----w- c:\program files\Advanced System Optimizer 3 2012-01-10 11:27 . 2012-02-08 11:12 -------- d-----w- c:\documents and settings\Rosen\Application Data\Skype . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-11-11 11:33 . 2004-08-03 21:14 162816 ----a-w- c:\windows\system32\drivers\netbt.sys 2011-06-16 04:28 . 2012-01-17 11:13 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SmartRAM"="c:\program files\IObit\Advanced SystemCare 4\Suo10_SmartRAM.exe" [2011-05-28 512400] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] . [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\egui] 2007-10-25 07:26 1410304 ----a-w- c:\program files\ESET\ESET NOD32 Antivirus\egui.exe . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Opera\\opera.exe"= "c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\TeamViewer\\Version7\\TeamViewer.exe"= "c:\\Program Files\\TeamViewer\\Version7\\TeamViewer_Service.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= . R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [25.10.2007 г. 09:27 30728] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [17.2.2010 г. 20:25 12872] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10.5.2010 г. 20:41 67656] S3 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 г. 13:16 130384] S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [04.8.2004 г. 00:56 14336] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 г. 13:16 753504] S4 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\IObit\Advanced SystemCare 4\ASCService.exe [24.10.2011 г. 10:49 353168] S4 ASO3DiskOptimizer;ASO3DiskOptimizer;c:\program files\Advanced System Optimizer 3\ASO3DefragSrv.exe [11.1.2012 г. 23:40 199400] S4 CachemanXPService;CachemanXP;c:\program files\CachemanXP\CachemanXP.exe --> c:\program files\CachemanXP\CachemanXP.exe [?] S4 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [25.10.2007 г. 09:26 455936] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] WINRM REG_MULTI_SZ WINRM . . ------- Supplementary Scan ------- . uStart Page = hxxp://google.bg/ IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 TCP: Interfaces\{C2A023CD-E149-4041-B456-7F76BA5D7562}: NameServer = 93.155.228.1 FF - ProfilePath - c:\documents and settings\Rosen\Application Data\Mozilla\Firefox\Profiles\c717psmr.default\ FF - prefs.js: browser.startup.homepage - hxxp://google.bg FF - prefs.js: network.proxy.type - 0 . . ------- File Associations ------- . JSEFile=NOTEPAD.EXE %1 . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2012-02-08 13:39 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'winlogon.exe'(676) c:\program files\SUPERAntiSpyware\SASWINLO.DLL c:\windows\system32\WININET.dll . - - - - - - - > 'explorer.exe'(3504) c:\windows\system32\WININET.dll c:\progra~1\WINDOW~2\wmpband.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . Completion time: 2012-02-08 13:42:21 ComboFix-quarantined-files.txt 2012-02-08 11:42 . Pre-Run: 12 050 710 528 bytes free Post-Run: 12 045 885 440 bytes free . - - End Of File - - 7931FD1E64ED2F658529802324341CB5 13:56:43.0549 0348 TDSS rootkit removing tool 2.7.10.0 Feb 7 2012 15:14:46 13:56:43.0689 0348 ============================================================ 13:56:43.0689 0348 Current date / time: 2012/02/08 13:56:43.0689 13:56:43.0689 0348 SystemInfo: 13:56:43.0689 0348 13:56:43.0689 0348 OS Version: 5.1.2600 ServicePack: 3.0 13:56:43.0689 0348 Product type: Workstation 13:56:43.0689 0348 ComputerName: MYPC 13:56:43.0689 0348 UserName: Rosen 13:56:43.0689 0348 Windows directory: C:\WINDOWS 13:56:43.0689 0348 System windows directory: C:\WINDOWS 13:56:43.0689 0348 Processor architecture: Intel x86 13:56:43.0689 0348 Number of processors: 1 13:56:43.0689 0348 Page size: 0x1000 13:56:43.0689 0348 Boot type: Normal boot 13:56:43.0689 0348 ============================================================ 13:56:46.0062 0348 Drive \Device\Harddisk0\DR0 - Size: 0x98ABA0000 (38.17 Gb), SectorSize: 0x200, Cylinders: 0x1376, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 13:56:46.0062 0348 \Device\Harddisk0\DR0: 13:56:46.0062 0348 MBR used 13:56:46.0062 0348 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x251B5B7 13:56:46.0082 0348 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x251B635, BlocksNum 0x2734B00 13:56:46.0172 0348 Initialize success 13:56:46.0172 0348 ============================================================ 13:59:25.0982 1144 ============================================================ 13:59:25.0982 1144 Scan started 13:59:25.0982 1144 Mode: Manual; SigCheck; TDLFS; 13:59:25.0982 1144 ============================================================ 13:59:26.0373 1144 Abiosdsk - ok 13:59:26.0443 1144 abp480n5 - ok 13:59:26.0563 1144 ac97intc (0f2d66d5f08ebe2f77bb904288dcf6f0) C:\WINDOWS\system32\drivers\ac97intc.sys 13:59:28.0806 1144 ac97intc - ok 13:59:29.0107 1144 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 13:59:29.0758 1144 ACPI - ok 13:59:29.0888 1144 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 13:59:30.0308 1144 ACPIEC - ok 13:59:30.0389 1144 adpu160m - ok 13:59:30.0489 1144 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 13:59:31.0100 1144 aec - ok 13:59:31.0280 1144 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys 13:59:31.0440 1144 AFD - ok 13:59:31.0580 1144 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys 13:59:32.0091 1144 agp440 - ok 13:59:32.0191 1144 Aha154x - ok 13:59:32.0241 1144 aic78u2 - ok 13:59:32.0301 1144 aic78xx - ok 13:59:32.0442 1144 ALCXWDM (bcd805eec4f621cbda15b33053d83ac7) C:\WINDOWS\system32\drivers\ALCXWDM.SYS 13:59:32.0552 1144 ALCXWDM ( UnsignedFile.Multi.Generic ) - warning 13:59:32.0552 1144 ALCXWDM - detected UnsignedFile.Multi.Generic (1) 13:59:32.0652 1144 AliIde - ok 13:59:32.0752 1144 amsint - ok 13:59:32.0862 1144 asc - ok 13:59:32.0902 1144 asc3350p - ok 13:59:32.0962 1144 asc3550 - ok 13:59:33.0173 1144 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 13:59:33.0543 1144 AsyncMac - ok 13:59:33.0643 1144 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 13:59:34.0044 1144 atapi - ok 13:59:34.0124 1144 Atdisk - ok 13:59:34.0204 1144 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 13:59:34.0615 1144 Atmarpc - ok 13:59:34.0815 1144 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 13:59:35.0276 1144 audstub - ok 13:59:35.0396 1144 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 13:59:35.0856 1144 Beep - ok 13:59:35.0947 1144 catchme - ok 13:59:36.0107 1144 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 13:59:36.0808 1144 cbidf2k - ok 13:59:36.0908 1144 cd20xrnt - ok 13:59:36.0988 1144 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 13:59:37.0519 1144 Cdaudio - ok 13:59:37.0749 1144 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 13:59:38.0160 1144 Cdfs - ok 13:59:38.0290 1144 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 13:59:38.0711 1144 Cdrom - ok 13:59:38.0871 1144 CmdIde - ok 13:59:39.0131 1144 cmuda (53f4cc55f3c255439c5973e31f0adce7) C:\WINDOWS\system32\drivers\cmuda.sys 13:59:39.0341 1144 cmuda ( UnsignedFile.Multi.Generic ) - warning 13:59:39.0341 1144 cmuda - detected UnsignedFile.Multi.Generic (1) 13:59:39.0452 1144 Cpqarray - ok 13:59:39.0502 1144 dac2w2k - ok 13:59:39.0562 1144 dac960nt - ok 13:59:39.0702 1144 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 13:59:40.0113 1144 Disk - ok 13:59:40.0313 1144 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 13:59:40.0834 1144 dmboot - ok 13:59:40.0964 1144 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 13:59:41.0404 1144 dmio - ok 13:59:41.0495 1144 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 13:59:41.0885 1144 dmload - ok 13:59:41.0995 1144 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 13:59:42.0426 1144 DMusic - ok 13:59:42.0516 1144 dpti2o - ok 13:59:42.0596 1144 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 13:59:43.0007 1144 drmkaud - ok 13:59:43.0097 1144 dwshd - ok 13:59:43.0167 1144 eamon (edd9c0eff764df3d56b12203d590f621) C:\WINDOWS\system32\DRIVERS\eamon.sys 13:59:43.0267 1144 eamon - ok 13:59:43.0327 1144 easdrv (ac23816ff2ebb110dedfba8a9b567601) C:\WINDOWS\system32\DRIVERS\easdrv.sys 13:59:43.0337 1144 easdrv - ok 13:59:43.0417 1144 epfwtdir (a68c4d6e795d972c90caea8b17397ed7) C:\WINDOWS\system32\DRIVERS\epfwtdir.sys 13:59:43.0427 1144 epfwtdir - ok 13:59:43.0588 1144 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 13:59:43.0998 1144 Fastfat - ok 13:59:44.0148 1144 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 13:59:44.0599 1144 Fdc - ok 13:59:44.0739 1144 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 13:59:45.0150 1144 Fips - ok 13:59:45.0260 1144 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 13:59:45.0681 1144 Flpydisk - ok 13:59:45.0821 1144 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 13:59:46.0442 1144 FltMgr - ok 13:59:46.0562 1144 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 13:59:46.0912 1144 Fs_Rec - ok 13:59:47.0002 1144 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 13:59:47.0413 1144 Ftdisk - ok 13:59:47.0543 1144 gameenum (065639773d8b03f33577f6cdaea21063) C:\WINDOWS\system32\DRIVERS\gameenum.sys 13:59:48.0134 1144 gameenum - ok 13:59:48.0304 1144 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 13:59:48.0705 1144 Gpc - ok 13:59:48.0825 1144 hpn - ok 13:59:48.0915 1144 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 13:59:49.0015 1144 HTTP - ok 13:59:49.0136 1144 i2omp - ok 13:59:49.0226 1144 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 13:59:49.0877 1144 i8042prt - ok 13:59:50.0017 1144 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 13:59:50.0487 1144 Imapi - ok 13:59:50.0598 1144 ini910u - ok 13:59:50.0718 1144 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys 13:59:51.0128 1144 IntelIde - ok 13:59:51.0309 1144 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 13:59:51.0709 1144 Ip6Fw - ok 13:59:51.0839 1144 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 13:59:52.0300 1144 IpFilterDriver - ok 13:59:52.0420 1144 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 13:59:52.0791 1144 IpInIp - ok 13:59:52.0891 1144 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 13:59:53.0302 1144 IpNat - ok 13:59:53.0432 1144 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 13:59:53.0832 1144 IPSec - ok 13:59:53.0942 1144 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 13:59:54.0083 1144 IRENUM - ok 13:59:54.0163 1144 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 13:59:54.0623 1144 isapnp - ok 13:59:54.0714 1144 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 13:59:55.0134 1144 Kbdclass - ok 13:59:55.0224 1144 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 13:59:55.0645 1144 kmixer - ok 13:59:55.0805 1144 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 13:59:55.0895 1144 KSecDD - ok 13:59:56.0126 1144 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 13:59:56.0556 1144 mnmdd - ok 13:59:56.0736 1144 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 13:59:57.0127 1144 Modem - ok 13:59:57.0247 1144 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 13:59:57.0998 1144 Mouclass - ok 13:59:58.0179 1144 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 13:59:58.0779 1144 MountMgr - ok 13:59:58.0870 1144 mraid35x - ok 13:59:58.0960 1144 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 13:59:59.0340 1144 MRxDAV - ok 13:59:59.0500 1144 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 13:59:59.0631 1144 MRxSmb - ok 13:59:59.0821 1144 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 14:00:00.0252 1144 Msfs - ok 14:00:00.0372 1144 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 14:00:00.0782 1144 MSKSSRV - ok 14:00:00.0902 1144 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 14:00:01.0413 1144 MSPCLOCK - ok 14:00:01.0533 1144 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 14:00:02.0695 1144 MSPQM - ok 14:00:02.0815 1144 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 14:00:03.0226 1144 mssmbios - ok 14:00:03.0286 1144 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys 14:00:03.0656 1144 Mup - ok 14:00:03.0767 1144 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 14:00:04.0147 1144 NDIS - ok 14:00:04.0277 1144 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 14:00:04.0678 1144 NdisTapi - ok 14:00:04.0818 1144 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 14:00:05.0199 1144 Ndisuio - ok 14:00:05.0339 1144 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 14:00:05.0759 1144 NdisWan - ok 14:00:05.0900 1144 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS\system32\drivers\NDProxy.sys 14:00:06.0280 1144 NDProxy - ok 14:00:06.0410 1144 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 14:00:06.0791 1144 NetBIOS - ok 14:00:06.0911 1144 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 14:00:07.0302 1144 NetBT - ok 14:00:07.0552 1144 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 14:00:08.0033 1144 Npfs - ok 14:00:08.0143 1144 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 14:00:08.0744 1144 Ntfs - ok 14:00:08.0924 1144 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 14:00:09.0495 1144 Null - ok 14:00:09.0815 1144 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 14:00:10.0386 1144 nv - ok 14:00:10.0516 1144 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 14:00:11.0307 1144 NwlnkFlt - ok 14:00:11.0428 1144 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 14:00:11.0848 1144 NwlnkFwd - ok 14:00:11.0998 1144 P3 (c90018bafdc7098619a4a95b046b30f3) C:\WINDOWS\system32\DRIVERS\p3.sys 14:00:12.0509 1144 P3 - ok 14:00:12.0619 1144 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 14:00:13.0010 1144 Parport - ok 14:00:13.0140 1144 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 14:00:13.0521 1144 PartMgr - ok 14:00:13.0631 1144 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 14:00:13.0981 1144 ParVdm - ok 14:00:14.0121 1144 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 14:00:14.0532 1144 PCI - ok 14:00:14.0602 1144 PCIDump - ok 14:00:14.0672 1144 PCIIde - ok 14:00:14.0802 1144 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 14:00:15.0133 1144 Pcmcia - ok 14:00:15.0243 1144 perc2 - ok 14:00:15.0323 1144 perc2hib - ok 14:00:15.0533 1144 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 14:00:15.0934 1144 PptpMiniport - ok 14:00:16.0084 1144 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 14:00:16.0465 1144 PSched - ok 14:00:16.0605 1144 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 14:00:16.0956 1144 Ptilink - ok 14:00:17.0056 1144 ql1080 - ok 14:00:17.0116 1144 Ql10wnt - ok 14:00:17.0186 1144 ql12160 - ok 14:00:17.0266 1144 ql1240 - ok 14:00:17.0326 1144 ql1280 - ok 14:00:17.0436 1144 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 14:00:17.0777 1144 RasAcd - ok 14:00:17.0937 1144 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 14:00:18.0317 1144 Rasl2tp - ok 14:00:18.0468 1144 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 14:00:18.0828 1144 RasPppoe - ok 14:00:18.0958 1144 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 14:00:19.0309 1144 Raspti - ok 14:00:19.0419 1144 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 14:00:19.0780 1144 Rdbss - ok 14:00:19.0910 1144 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 14:00:20.0280 1144 RDPCDD - ok 14:00:20.0400 1144 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 14:00:20.0781 1144 rdpdr - ok 14:00:20.0931 1144 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys 14:00:21.0272 1144 RDPWD - ok 14:00:21.0412 1144 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 14:00:21.0792 1144 redbook - ok 14:00:21.0993 1144 RTL8023xp (3529828ec571fb2f64f6b142f9109993) C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys 14:00:22.0163 1144 RTL8023xp - ok 14:00:22.0273 1144 rtl8139 (d507c1400284176573224903819ffda3) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS 14:00:22.0714 1144 rtl8139 - ok 14:00:22.0884 1144 SASDIFSV (a3281aec37e0720a2bc28034c2df2a56) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 14:00:22.0904 1144 SASDIFSV - ok 14:00:22.0994 1144 SASKUTIL (61db0d0756a99506207fd724e3692b25) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 14:00:23.0054 1144 SASKUTIL - ok 14:00:23.0194 1144 SCDEmu (f441ba47bd8610cb9536965bd7d1f943) C:\WINDOWS\system32\drivers\SCDEmu.sys 14:00:23.0245 1144 SCDEmu ( UnsignedFile.Multi.Generic ) - warning 14:00:23.0245 1144 SCDEmu - detected UnsignedFile.Multi.Generic (1) 14:00:23.0395 1144 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 14:00:23.0545 1144 Secdrv - ok 14:00:23.0795 1144 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 14:00:24.0486 1144 serenum - ok 14:00:24.0627 1144 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 14:00:25.0127 1144 Serial - ok 14:00:25.0388 1144 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 14:00:26.0009 1144 Sfloppy - ok 14:00:26.0139 1144 Simbad - ok 14:00:26.0249 1144 Sparrow - ok 14:00:26.0359 1144 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 14:00:26.0760 1144 splitter - ok 14:00:26.0900 1144 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 14:00:27.0060 1144 sr - ok 14:00:27.0210 1144 Srv (0f6aefad3641a657e18081f52d0c15af) C:\WINDOWS\system32\DRIVERS\srv.sys 14:00:27.0360 1144 Srv - ok 14:00:27.0481 1144 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 14:00:27.0861 1144 swenum - ok 14:00:27.0991 1144 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 14:00:28.0342 1144 swmidi - ok 14:00:28.0442 1144 symc810 - ok 14:00:28.0482 1144 symc8xx - ok 14:00:28.0552 1144 sym_hi - ok 14:00:28.0602 1144 sym_u3 - ok 14:00:28.0702 1144 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 14:00:29.0103 1144 sysaudio - ok 14:00:29.0273 1144 Tcpip (93ea8d04ec73a85db02eb8805988f733) C:\WINDOWS\system32\DRIVERS\tcpip.sys 14:00:29.0724 1144 Tcpip - ok 14:00:29.0884 1144 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 14:00:30.0285 1144 TDPIPE - ok 14:00:30.0395 1144 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 14:00:30.0735 1144 TDTCP - ok 14:00:30.0825 1144 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 14:00:31.0266 1144 TermDD - ok 14:00:31.0416 1144 TosIde - ok 14:00:31.0526 1144 TVICHW32 (e266683fc95abdec17cd378564e1b54b) C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS 14:00:31.0557 1144 TVICHW32 ( UnsignedFile.Multi.Generic ) - warning 14:00:31.0557 1144 TVICHW32 - detected UnsignedFile.Multi.Generic (1) 14:00:31.0687 1144 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 14:00:32.0037 1144 Udfs - ok 14:00:32.0127 1144 ultra - ok 14:00:32.0238 1144 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 14:00:32.0698 1144 Update - ok 14:00:32.0868 1144 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 14:00:33.0209 1144 usbhub - ok 14:00:33.0339 1144 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 14:00:33.0700 1144 USBSTOR - ok 14:00:33.0880 1144 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 14:00:34.0260 1144 usbuhci - ok 14:00:34.0371 1144 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 14:00:34.0721 1144 VgaSave - ok 14:00:34.0831 1144 ViaIde - ok 14:00:34.0941 1144 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 14:00:35.0352 1144 VolSnap - ok 14:00:35.0512 1144 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 14:00:35.0893 1144 Wanarp - ok 14:00:36.0033 1144 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 14:00:36.0414 1144 wdmaud - ok 14:00:36.0704 1144 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys 14:00:37.0084 1144 WS2IFSL - ok 14:00:37.0225 1144 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 14:00:37.0295 1144 WudfPf - ok 14:00:37.0395 1144 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 14:00:37.0445 1144 WudfRd - ok 14:00:37.0515 1144 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0 14:00:37.0846 1144 \Device\Harddisk0\DR0 - ok 14:00:37.0856 1144 Boot (0x1200) (e6908ff26ef72ff56d90ea3970eaba59) \Device\Harddisk0\DR0\Partition0 14:00:37.0856 1144 \Device\Harddisk0\DR0\Partition0 - ok 14:00:37.0896 1144 Boot (0x1200) (2faa4b49a9c9f5b7b2f995edf3c034ff) \Device\Harddisk0\DR0\Partition1 14:00:37.0896 1144 \Device\Harddisk0\DR0\Partition1 - ok 14:00:37.0906 1144 ============================================================ 14:00:37.0906 1144 Scan finished 14:00:37.0906 1144 ============================================================ 14:00:38.0056 1644 Detected object count: 4 14:00:38.0056 1644 Actual detected object count: 4 14:01:03.0603 1644 ALCXWDM ( UnsignedFile.Multi.Generic ) - skipped by user 14:01:03.0603 1644 ALCXWDM ( UnsignedFile.Multi.Generic ) - User select action: Skip 14:01:03.0603 1644 cmuda ( UnsignedFile.Multi.Generic ) - skipped by user 14:01:03.0603 1644 cmuda ( UnsignedFile.Multi.Generic ) - User select action: Skip 14:01:03.0603 1644 SCDEmu ( UnsignedFile.Multi.Generic ) - skipped by user 14:01:03.0603 1644 SCDEmu ( UnsignedFile.Multi.Generic ) - User select action: Skip 14:01:03.0603 1644 TVICHW32 ( UnsignedFile.Multi.Generic ) - skipped by user 14:01:03.0603 1644 TVICHW32 ( UnsignedFile.Multi.Generic ) - User select action: Skip

Моля, изпратете на VirusTotal следните файлове:

c:\windows\system32\drivers\netbt.sys
c:\windows\system32\sasnative32.exe

След като анализа приключи,публикувайте резултата в следващия си пост.

  • Автор

ето резултатите File name: netbt.sys Detection ratio: 0 / 43 Analysis date: 2012-02-08 16:53:31 UTC ( 0 минути ago ) File name: sasnative32.exe Detection ratio: 0 / 43 Analysis date: 2012-02-08 16:56:51 UTC ( 0 минути ago ) В момента не чатя по скайп ...... участвам в няколко конферентни връзки, но никой не е писал повече от час нещо ....но интернет връзката ми е активна - над сто заявки sent i received

  • Автор

Щом е така обяснението е някъде в самия скайп предполагам .......... да премахвам ли Комбофикс ?

Деинсталирайте Комбофикс така:

1.Натиснете Start ==> Run ==> въведете командата Combofix /Uninstall ==> OK

Публикувано изображение

2.Изтеглете Публикувано изображениеOTCleanIt или от тук,стартирайте и натиснете Публикувано изображение

Лек ден и безопасен интернет от мен..!:)

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.