Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

WORM/Autorun.ffv [Решен]

Featured Replies

Здравейте ! Сканирах с Авира и тя намери вирус с това име. Ето и логовете :DDS (Ver_2011-09-30.01) - NTFS_x86 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_23 Run by keleminator at 19:06:25 on 2012-02-17 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.1535.766 [GMT 2:00] . AV: Avira Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7} . ============== Running Processes ================ . C:WINDOWSsystem32Ati2evxx.exe C:WINDOWSsystem32spoolsv.exe C:WINDOWSsystem32Ati2evxx.exe C:WINDOWSExplorer.EXE C:WINDOWSSOUNDMAN.EXE C:Program FilesATI TechnologiesATI.ACEcli.exe C:WINDOWSsystem32ctfmon.exe C:Program FilesuTorrentuTorrent.exe C:WINDOWSSystem32alg.exe C:Program FilesATI TechnologiesATI.ACEcli.exe C:Program FilesATI TechnologiesATI.ACEcli.exe C:Program FilesAviraAntiVir Desktopavguard.exe C:Program FilesAviraAntiVir Desktopavshadow.exe C:Program FilesAviraAntiVir Desktopsched.exe C:Program FilesAviraAntiVir Desktopavgnt.exe C:WINDOWSsystem32dllhost.exe C:WINDOWSsystem32msdtc.exe C:Program FilesMozilla Firefoxfirefox.exe C:Program FilesMozilla Firefoxplugin-container.exe C:WINDOWSsystem32rundll32.exe C:WINDOWSsystem32wscntfy.exe C:WINDOWSsystem32wbemwmiprvse.exe C:WINDOWSSystem32svchost.exe -k netsvcs C:WINDOWSsystem32svchost.exe -k NetworkService C:WINDOWSsystem32svchost.exe -k LocalService C:WINDOWSsystem32svchost.exe -k LocalService C:WINDOWSSystem32svchost.exe -k HTTPFilter . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:program filesjavajre6binjp2ssv.dll uRun: [CTFMON.EXE] c:windowssystem32CTFMON.EXE uRun: [uTorrent] "c:program filesutorrentuTorrent.exe" /MINIMIZED mRun: [LClock] c:program fileslclockLClock.exe mRun: [soundMan] SOUNDMAN.EXE mRun: [ATICCC] "c:program filesati technologiesati.acecli.exe" runtime -Delay mRun: [NeroFilterCheck] c:windowssystem32NeroCheck.exe mRun: [avgnt] "c:program filesaviraantivir desktopavgnt.exe" /min dRun: [CTFMON.EXE] c:windowssystem32CTFMON.EXE dRunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N uPolicies-Explorer: NoDriveTypeAutoRun = dword:145 mPolicies-Explorer: NoDriveTypeAutoRun = dword:28 mPolicies-Explorer: NoDriveTypeAutoRun = dword:145 mPolicies-Explorer: ForceClassicControlPanel = dword:1 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%Network Diagnosticxpnetdiag.exe DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab TCP: NameServer = 192.168.1.1 TCP: Interfaces{B08B1FD3-9624-4293-8089-5F8F4F89B73B} : DHCPNameServer = 192.168.1.1 Notify: AtiExtEvent - Ati2evxx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:windowssystem32WPDShServiceObj.dll mASetup: {FC88681F-4735-4f2f-9514-C21BAC737CF8} - rundll32.exe advpack.dll,LaunchINFSection MU.inf,MUWeb.Install . ================= FIREFOX =================== . FF - ProfilePath - c:documents and settingskeleminatorapplication datamozillafirefoxprofileszhwxx24w.default FF - prefs.js: network.proxy.type - 4 FF - component: c:documents and settingskeleminatorapplication datamozillafirefoxprofileszhwxx24w.defaultextensions{687578b9-7132-4a7a-80e4-30ee31099e03}componentsRadioWMPCoreGecko10.dll FF - component: c:documents and settingskeleminatorapplication datamozillafirefoxprofileszhwxx24w.defaultextensions{687578b9-7132-4a7a-80e4-30ee31099e03}componentsRadioWMPCoreGecko19.dll FF - component: c:documents and settingskeleminatorapplication datamozillafirefoxprofileszhwxx24w.defaultextensions{687578b9-7132-4a7a-80e4-30ee31099e03}componentsRadioWMPCoreGecko5.dll FF - component: c:documents and settingskeleminatorapplication datamozillafirefoxprofileszhwxx24w.defaultextensions{687578b9-7132-4a7a-80e4-30ee31099e03}componentsRadioWMPCoreGecko6.dll FF - component: c:documents and settingskeleminatorapplication datamozillafirefoxprofileszhwxx24w.defaultextensions{687578b9-7132-4a7a-80e4-30ee31099e03}componentsRadioWMPCoreGecko7.dll FF - component: c:documents and settingskeleminatorapplication datamozillafirefoxprofileszhwxx24w.defaultextensions{687578b9-7132-4a7a-80e4-30ee31099e03}componentsRadioWMPCoreGecko8.dll FF - component: c:documents and settingskeleminatorapplication datamozillafirefoxprofileszhwxx24w.defaultextensions{687578b9-7132-4a7a-80e4-30ee31099e03}componentsRadioWMPCoreGecko9.dll FF - plugin: c:program filesfoxit softwarefoxit readerpluginsnpFoxitReaderPlugin.dll FF - plugin: c:program filesjavajre6binnew_pluginnpdeployJava1.dll FF - plugin: c:program filesmozilla firefoxpluginsnpFoxitReaderPlugin.dll FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:program filesmozilla firefoxextensions{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:program filesmozilla firefoxextensions{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} FF - Ext: Better Facebook!: [email protected] - %profile%[email protected] FF - Ext: Add-on Compatibility Reporter: [email protected] - %profile%[email protected] FF - Ext: foof: [email protected] - %profile%[email protected] FF - Ext: AutocompletePro - Your handy search suggestions tool: [email protected] - %profile%[email protected] FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%extensions{20a82645-c095-46ed-80e3-08825760534b} FF - Ext: ShareTheFiles Menu: {36DB19D8-F9C7-494b-844D-1871FF108785} - %profile%extensions{36DB19D8-F9C7-494b-844D-1871FF108785} FF - Ext: Boost for Facebook: {47624dda-b77e-4feb-820a-e4f077d5d4ca} - %profile%extensions{47624dda-b77e-4feb-820a-e4f077d5d4ca} FF - Ext: FEBE: {4BBDD651-70CF-4821-84F8-2B918CF89CA3} - %profile%extensions{4BBDD651-70CF-4821-84F8-2B918CF89CA3} FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - %profile%extensions{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: ImTranslator: {9AA46F4F-4DC7-4c06-97AF-5035170634FE} - %profile%extensions{9AA46F4F-4DC7-4c06-97AF-5035170634FE} FF - Ext: Fasterfox: {c36177c0-224a-11da-8cd6-0800200c9a91} - %profile%extensions{c36177c0-224a-11da-8cd6-0800200c9a91} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - %profile%extensions{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} FF - Ext: FireMule: {D644F7E7-5141-4fac-A59C-21101C82C734} - %profile%extensions{D644F7E7-5141-4fac-A59C-21101C82C734} FF - Ext: Greasemonkey: {e4a8a97b-f2ed-450b-b12d-ee082ba24781} - %profile%extensions{e4a8a97b-f2ed-450b-b12d-ee082ba24781} FF - Ext: uTorrentControl2 Community Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - %profile%extensions{687578b9-7132-4a7a-80e4-30ee31099e03} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:windowsmicrosoft.netframeworkv3.5windows presentation foundationDotNetAssistantExtension . ============= SERVICES / DRIVERS =============== . R0 mv61xxmm;mv61xxmm;c:windowssystem32driversmv61xxmm.sys [2010-12-1 5632] R0 mv64xxmm;mv64xxmm;c:windowssystem32driversmv64xxmm.sys [2010-12-1 5632] R0 mvxxmm;mvxxmm;c:windowssystem32driversmvxxmm.sys [2010-12-1 5632] R1 avkmgr;avkmgr;c:windowssystem32driversavkmgr.sys [2012-2-17 36000] R2 AntiVirSchedulerService;Avira Scheduler;c:program filesaviraantivir desktopsched.exe [2012-2-17 86224] R2 AntiVirService;Avira Realtime Protection;c:program filesaviraantivir desktopavguard.exe [2012-2-17 110032] R2 avgntflt;avgntflt;c:windowssystem32driversavgntflt.sys [2012-2-17 74640] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:windowsmicrosoft.netframeworkv4.0.30319mscorsvw.exe [2010-3-18 130384] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:windowsmicrosoft.netframeworkv4.0.30319wpfWPFFontCache_v0400.exe [2010-3-18 753504] . =============== Created Last 30 ================ . 2012-02-17 13:17:45 -------- d--h--w- c:windowsPIF 2012-02-17 12:19:20 -------- d-----w- c:documents and settingskeleminatorapplication dataAvira 2012-02-17 12:13:35 74640 ----a-w- c:windowssystem32driversavgntflt.sys 2012-02-17 12:13:35 36000 ----a-w- c:windowssystem32driversavkmgr.sys 2012-02-17 12:13:34 -------- d-----w- c:program filesAvira 2012-02-17 12:13:34 -------- d-----w- c:documents and settingsall usersapplication dataAvira 2012-02-17 12:01:39 -------- d-----w- c:windowssystem32wbemsnmp 2012-02-17 12:01:37 -------- d-----w- c:windowssystem32xircom 2012-02-17 11:51:24 -------- d-----w- c:documents and settingskeleminatorlocal settingsapplication dataSophos 2012-02-17 11:42:03 -------- d-----w- c:documents and settingsall usersapplication dataSophos 2012-02-17 11:38:19 -------- d-----w- C:escwsa 2012-02-17 10:05:19 -------- d-----w- c:windowssystem32LogFiles 2012-02-17 09:44:03 -------- d-----w- c:documents and settingskeleminatorlocal settingsapplication dataPCHealth 2012-02-17 01:55:13 -------- d-----w- C:70907fe430772ce981 2012-02-17 01:33:00 -------- d-----w- C:e1aa42c6c32589848480 2012-02-17 01:06:46 -------- d-----w- C:eebf251fee6435c114202fd5c79a68 2012-02-17 01:05:18 -------- d-----w- c:windowsSxsCaPendDel 2012-02-17 01:01:39 -------- d-----w- c:windowsie8updates 2012-02-17 01:00:21 -------- d--h--w- c:windows$hf_mig$ 2012-02-17 00:14:33 89184 ----a-w- c:windowssystem32driversimagedrv.sys 2012-02-17 00:14:33 57344 ----a-w- c:windowssystem32ImageDrive.cpl 2012-02-17 00:14:20 569344 ----a-w- c:windowssystem32imagr5.dll 2012-02-17 00:14:20 544768 ----a-w- c:windowssystem32imagx5.dll 2012-02-17 00:14:20 38912 ----a-w- c:windowssystem32picn20.dll 2012-02-17 00:14:20 283920 ----a-w- c:windowssystem32ImagXpr5.dll 2012-02-17 00:14:20 155648 ----a-w- c:windowssystem32NeroCheck.exe 2012-02-16 20:31:53 11085312 ------w- c:windowssystem32dllcacheieframe.dll 2012-02-16 20:30:38 3072 ------w- c:windowssystem32iacenc.dll 2012-02-16 20:30:38 3072 ------w- c:windowssystem32dllcacheiacenc.dll 2012-02-16 14:37:12 -------- d-----w- c:documents and settingskeleminatorapplication dataMalwarebytes 2012-02-16 14:37:09 -------- d-----w- c:documents and settingsall usersapplication dataMalwarebytes 2012-02-15 22:40:51 -------- d-----w- c:program filesConduit 2012-02-15 22:40:49 -------- d-----w- c:documents and settingskeleminatorlocal settingsapplication dataTemp 2012-02-15 22:40:49 -------- d-----w- c:documents and settingskeleminatorlocal settingsapplication dataConduit 2012-02-15 22:40:41 -------- d-----w- c:program filesuTorrent 2012-02-15 22:39:27 -------- d-----w- c:documents and settingskeleminatorapplication datauTorrent 2012-02-15 09:31:19 -------- d-----w- c:program filesDiskInternals 2012-02-15 07:58:06 -------- d-----w- c:windowspss 2012-02-15 06:10:34 -------- d-----w- c:program filesCCleaner 2012-02-14 22:02:32 -------- d-----w- c:program filesLavalys 2012-02-14 17:26:08 270848 ------w- c:windowssystem32dllcachesbe.dll 2012-02-14 17:26:02 301568 ------w- c:windowssystem32dllcachekerberos.dll 2012-02-14 17:24:45 290432 ------w- c:windowssystem32dllcacheatmfd.dll 2012-02-14 17:24:43 249856 ------w- c:windowssystem32dllcacheodbc32.dll 2012-02-14 17:24:43 143360 ------w- c:windowssystem32dllcachemsadco.dll 2012-02-14 17:24:42 536576 ------w- c:windowssystem32dllcachemsado15.dll 2012-02-14 17:24:42 200704 ------w- c:windowssystem32dllcachemsadox.dll 2012-02-14 17:24:42 180224 ------w- c:windowssystem32dllcachemsadomd.dll 2012-02-14 17:24:42 102400 ------w- c:windowssystem32dllcachemsjro.dll 2012-02-14 17:24:41 357888 ------w- c:windowssystem32dllcachesrv.sys 2012-02-14 17:24:38 135168 ------w- c:windowssystem32dllcacheshsvcs.dll 2012-02-14 17:24:31 8462336 ------w- c:windowssystem32dllcacheshell32.dll 2012-02-14 17:23:55 978944 ------w- c:windowssystem32dllcachemfc42.dll 2012-02-14 17:23:49 186880 ------w- c:windowssystem32dllcacheencdec.dll 2012-02-14 17:22:01 361600 ------w- c:windowssystem32dllcachetcpip.sys 2012-02-14 17:22:01 138496 ------w- c:windowssystem32dllcacheafd.sys 2012-02-14 17:22:00 45568 ------w- c:windowssystem32SET33C.tmp 2012-02-14 17:22:00 45568 ------w- c:windowssystem32dllcachednsrslvr.dll 2012-02-14 17:22:00 225856 ------w- c:windowssystem32dllcachetcpip6.sys 2012-02-14 17:22:00 149504 ------w- c:windowssystem32SET33D.tmp 2012-02-14 17:22:00 149504 ------w- c:windowssystem32dllcachednsapi.dll 2012-02-14 17:21:59 245248 ------w- c:windowssystem32SET33B.tmp 2012-02-14 17:21:59 245248 ------w- c:windowssystem32dllcachemswsock.dll 2012-02-14 17:14:27 456320 ------w- c:windowssystem32dllcachemrxsmb.sys 2012-02-14 17:13:54 730112 ------w- c:windowssystem32dllcachelsasrv.dll 2012-02-14 17:10:48 33280 ------w- c:windowssystem32dllcachecsrsrv.dll 2012-02-14 17:00:51 60416 ------w- c:windowssystem32dllcachepackager.exe 2012-02-14 17:00:08 139656 ------w- c:windowssystem32dllcacherdpwd.sys 2012-02-14 17:00:04 105472 ------w- c:windowssystem32dllcachemup.sys 2012-02-14 17:00:02 2148864 ------w- c:windowssystem32dllcachentkrnlmp.exe 2012-02-14 17:00:01 2192768 ------w- c:windowssystem32dllcachentoskrnl.exe 2012-02-14 17:00:00 2027008 ------w- c:windowssystem32dllcachentkrpamp.exe . ==================== Find3M ==================== .

Редактирано от Maniac (преглед на промените)

Здравейте!

WORM/Autorun.ffv означава, че червея идва най-често от някоя флаш памет. Имате ли някакъв спомен коя е била последно използваната? Под ръка ли ви е?

Моля, публикувайте и Attach.txt (генерира се от DDS).

  • Автор

Благодаряр че се отзовахте :)

Да зная коя е ,сканирах авира,не намери нищо

Имам проблеми с фонетика не работи изчезнар как да прекача файла Attach.txt

Редактирано от selzar (преглед на промените)

  • Автор

ето :. UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-09-30.01) . Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 14.2.2012 г. 16:54:37 System Uptime: 17.2.2012 г. 14:09:43 (5 hours ago) . Motherboard: Gigabyte Technology Co., Ltd. | | GA-7VA-A Processor: AMD Athlon™ XP 1900+ | Socket A | 1610/140mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 40 GiB total, 26,015 GiB free. D: is FIXED (NTFS) - 40 GiB total, 1,149 GiB free. E: is FIXED (NTFS) - 40 GiB total, 1,371 GiB free. F: is FIXED (NTFS) - 106 GiB total, 0,991 GiB free. G: is FIXED (NTFS) - 2 GiB total, 0,686 GiB free. H: is FIXED (NTFS) - 31 GiB total, 0,32 GiB free. I: is FIXED (NTFS) - 39 GiB total, 0,092 GiB free. J: is CDROM () K: is CDROM () . ==== Disabled Device Manager Items ============= . Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318} Description: 3Com EtherLink XL 10/100 PCI For Complete PC Management NIC (3C905C-TX) Device ID: PCI\VEN_10B7&DEV_9200&SUBSYS_100010B7&REV_74\3&13C0B0C5&0&60 Manufacturer: 3Com Name: 3Com EtherLink XL 10/100 PCI For Complete PC Management NIC (3C905C-TX) PNP Device ID: PCI\VEN_10B7&DEV_9200&SUBSYS_100010B7&REV_74\3&13C0B0C5&0&60 Service: EL90XBC . ==== System Restore Points =================== . No restore point in system. . ==== Installed Programs ====================== . µTorrent Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Shockwave Player 11.5 ATI - Software Uninstall Utility ATI Catalyst Control Center ATI Display Driver Avira Free Antivirus Bulgarian (Phonetic) by Iliya Dankov CCleaner Enable S3 for USB Device EVEREST Ultimate Edition v5.50 Foxit Reader Hotfix for Windows XP (KB2443685) Hotfix for Windows XP (KB2633952) Hotfix for Windows XP (KB971276-v3) Hotfix for Windows XP (KB976002-v5) Java™ 6 Update 23 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB2656353) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 4 Client Profile Microsoft .NET Framework 4 Extended Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.5054 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2008 Service Pack 1 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Mozilla Firefox (3.6.26) Nero 6 Ultra Edition Notepad++ Realtek AC'97 Audio RTLSetup Security Update for Microsoft Windows (KB2564958) Security Update for Windows Internet Explorer 8 (KB2510531) Security Update for Windows Internet Explorer 8 (KB2544521) Security Update for Windows Internet Explorer 8 (KB2647516) Security Update for Windows XP (KB2393802) Security Update for Windows XP (KB2412687) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2476490) Security Update for Windows XP (KB2478960) Security Update for Windows XP (KB2478971) Security Update for Windows XP (KB2479943) Security Update for Windows XP (KB2481109) Security Update for Windows XP (KB2483185) Security Update for Windows XP (KB2485663) Security Update for Windows XP (KB2506212) Security Update for Windows XP (KB2507618) Security Update for Windows XP (KB2507938) Security Update for Windows XP (KB2508429) Security Update for Windows XP (KB2509553) Security Update for Windows XP (KB2535512) Security Update for Windows XP (KB2536276-v2) Security Update for Windows XP (KB2544893-v2) Security Update for Windows XP (KB2566454) Security Update for Windows XP (KB2570222) Security Update for Windows XP (KB2570947) Security Update for Windows XP (KB2584146) Security Update for Windows XP (KB2585542) Security Update for Windows XP (KB2592799) Security Update for Windows XP (KB2598479) Security Update for Windows XP (KB2603381) Security Update for Windows XP (KB2618451) Security Update for Windows XP (KB2619339) Security Update for Windows XP (KB2620712) Security Update for Windows XP (KB2624667) Security Update for Windows XP (KB2631813) Security Update for Windows XP (KB2633171) Security Update for Windows XP (KB2646524) Security Update for Windows XP (KB2660465) Security Update for Windows XP (KB2661637) Update for Windows XP (KB2641690) Update for Windows XP (KB971029) VLC media player 1.1.5 WebFldrs XP WinRAR archiver . ==== Event Viewer Messages From Past Week ======== . 17.2.2012 г. 04:26:34, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 17.2.2012 г. 04:26:19, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 17.2.2012 г. 04:25:22, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 17.2.2012 г. 04:11:17, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 17.2.2012 г. 04:10:36, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AmdK7 Fips KLIF 17.2.2012 г. 04:05:39, error: Dhcp [1002] - The IP address lease 192.168.1.2 for the Network Card with network address 00409508DF6B has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). 17.2.2012 г. 03:30:01, error: sr [1] - The System Restore filter encountered the unexpected error '0xC000003A' while processing the file '_filelst.cfg' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. 16.2.2012 г. 00:14:00, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 16.2.2012 г. 00:13:27, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 16.2.2012 г. 00:12:14, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 15.2.2012 г. 23:59:48, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 15.2.2012 г. 23:57:22, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AmdK7 Fips KLIF 15.2.2012 г. 13:18:56, error: Service Control Manager [7034] - The Ati HotKey Poller service terminated unexpectedly. It has done this 1 time(s). 15.2.2012 г. 08:09:04, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 15.2.2012 г. 08:08:42, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 15.2.2012 г. 06:04:33, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: KLIF 15.2.2012 г. 05:24:18, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: uagp35 ViaIde 15.2.2012 г. 05:18:04, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 15.2.2012 г. 05:17:39, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046} 15.2.2012 г. 05:06:43, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 15.2.2012 г. 05:06:13, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 15.2.2012 г. 05:06:07, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} 15.2.2012 г. 05:00:33, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AmdK7 Fips IPSec kl2 KLIF MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip uagp35 ViaIde 15.2.2012 г. 05:00:33, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning. 15.2.2012 г. 05:00:33, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning. 15.2.2012 г. 05:00:33, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 15.2.2012 г. 05:00:33, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning. 15.2.2012 г. 05:00:25, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} 15.2.2012 г. 05:00:15, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 15.2.2012 г. 03:00:18, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: uagp35 ViaIde 14.2.2012 г. 18:49:22, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 14.2.2012 г. 18:49:21, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 14.2.2012 г. 18:07:47, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 14.2.2012 г. 17:38:22, error: ati2mtag [4] - 14.2.2012 г. 17:38:22, error: ati2mtag [4] - 14.2.2012 г. 17:37:56, error: ati2mtag [4] - 14.2.2012 г. 17:37:56, error: ati2mtag [4] - 14.2.2012 г. 17:37:56, error: ati2mtag [4] - 14.2.2012 г. 17:37:56, error: ati2mtag [4] - 14.2.2012 г. 17:37:56, error: ati2mtag [4] - 14.2.2012 г. 17:37:56, error: ati2mtag [4] - 14.2.2012 г. 17:37:56, error: ati2mtag [4] - 14.2.2012 г. 17:36:06, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 14.2.2012 г. 17:34:57, error: ati2mtag [4] - 14.2.2012 г. 17:34:57, error: ati2mtag [4] - 14.2.2012 г. 17:34:57, error: ati2mtag [4] - 14.2.2012 г. 17:34:57, error: ati2mtag [4] - 14.2.2012 г. 17:34:57, error: ati2mtag [4] - 14.2.2012 г. 17:34:57, error: ati2mtag [4] - 14.2.2012 г. 17:34:57, error: ati2mtag [4] - 14.2.2012 г. 17:34:57, error: ati2mtag [4] - 14.2.2012 г. 17:34:57, error: ati2mtag [4] - 14.2.2012 г. 17:34:57, error: ati2mtag [4] - 14.2.2012 г. 17:34:57, error: ati2mtag [4] - 14.2.2012 г. 17:34:57, error: ati2mtag [4] - 14.2.2012 г. 17:34:57, error: ati2mtag [4] - 14.2.2012 г. 17:34:57, error: ati2mtag [4] - 14.2.2012 г. 17:34:57, error: ati2mtag [4] - 14.2.2012 г. 16:55:07, error: Setup [60055] - Windows Setup encountered non-fatal errors during installation. Please check the setuperr.log found in your Windows directory for more information. . ==== End Of File =========================== Доста забива компа и почти не мога да пиша на кирилица.Така се омаза windows .

Редактирано от selzar (преглед на промените)

Благодаря!

  • Изтеглете Flash Disinfector и го запишете на десктопа.
  • Стартирайте Flash_Disinfector.exe с двоен клик. Програмата ще поиска да поставите флаш памети или подобни преносими устройства, включително мобилни телефони и камери. Следвайте инструкциите на Flash Disinfector, за да сканира и да почисти тези устройства.
  • След това рестартирайте компютъра.
  • Вече е безопасно да поставите флашката в компютъра си, но преди да я използвайте я сканирайте за вируси с Avira от контекстното меню с десен бутон върху нея).
  • Забележка: Flash_Desinfector ще създаде скрити папки с имената - autorun.inf (със съответните файлове в тях с имената lpt3.This folder was created by Flash_Disinfector) на всички дялове на компютъра - не ги трийте, защото те са създадени за да имунизират системата срещу бъдещи зарази пристигащи чрез flash устройствата.

Пишете ми отново как е положението.

  • Автор

Благодаря ,ей сега ще пробвам и ще пиша :)

Ами готово но файловете ми изглеждат още странно -file:///L:/FOUND.000/

Това е папка, но тя няма нищо общо с този или някой от другите инструменти. Какво представлява и как да ги махнете от погледа си вижте тук: http://techsalsa.com/what-are-found000-folders-and-why-are-they-created/ Направете пълно сканиране на системата с Avira за всеки случай, но мисля че по този начин пресякохме този тип атаки към системата ви.

  • Автор

file:///L:/FOUND.000/FILE0000.CHK

Компа не е никак добре, пробвам да unинсталирам bg phonetic by iliya dqnkov и не се трие ...все още имам hiden folder с музика които не съм ги крил.Flash Disinfector как мога да го изтрия в случай че реша да не го ползвам. Ще мога ли да си ги поправя ето и лог от антивирусната :

Avira Free Antivirus

Report file date: 18 Февруари 2012 г. 00:59

Scanning for 3472827 virus strains and unwanted programs.

The program is running as an unrestricted full version.

Online services are available:

Licensee : Avira AntiVir Personal - Free Antivirus

Serial number : 0000149996-ADJIE-0000001

Platform : Windows XP

Windows version : (Service Pack 3) [5.1.2600]

Boot mode : Normally booted

Username : keleminator

Computer name : NAILON-3A70F369

Version information:

BUILD.DAT : 12.0.0.898 41963 Bytes 31.1.2012 г. 14:50:00

AVSCAN.EXE : 12.1.0.20 492496 Bytes 31.1.2012 г. 06:56:54

AVSCAN.DLL : 12.1.0.18 54224 Bytes 31.1.2012 г. 06:57:27

LUKE.DLL : 12.1.0.19 68304 Bytes 31.1.2012 г. 06:57:02

AVSCPLR.DLL : 12.1.0.22 100048 Bytes 31.1.2012 г. 06:56:54

AVREG.DLL : 12.1.0.29 228048 Bytes 31.1.2012 г. 06:56:53

VBASE000.VDF : 7.10.0.0 19875328 Bytes 06.11.2009 г. 07:05:36

VBASE001.VDF : 7.11.0.0 13342208 Bytes 14.12.2010 г. 06:57:15

VBASE002.VDF : 7.11.19.170 14374912 Bytes 20.12.2011 г. 06:57:20

VBASE003.VDF : 7.11.21.238 4472832 Bytes 01.2.2012 г. 12:14:34

VBASE004.VDF : 7.11.21.239 2048 Bytes 01.2.2012 г. 12:14:34

VBASE005.VDF : 7.11.21.240 2048 Bytes 01.2.2012 г. 12:14:34

VBASE006.VDF : 7.11.21.241 2048 Bytes 01.2.2012 г. 12:14:34

VBASE007.VDF : 7.11.21.242 2048 Bytes 01.2.2012 г. 12:14:34

VBASE008.VDF : 7.11.21.243 2048 Bytes 01.2.2012 г. 12:14:35

VBASE009.VDF : 7.11.21.244 2048 Bytes 01.2.2012 г. 12:14:35

VBASE010.VDF : 7.11.21.245 2048 Bytes 01.2.2012 г. 12:14:35

VBASE011.VDF : 7.11.21.246 2048 Bytes 01.2.2012 г. 12:14:36

VBASE012.VDF : 7.11.21.247 2048 Bytes 01.2.2012 г. 12:14:36

VBASE013.VDF : 7.11.22.33 1486848 Bytes 03.2.2012 г. 12:14:38

VBASE014.VDF : 7.11.22.56 687616 Bytes 03.2.2012 г. 12:14:40

VBASE015.VDF : 7.11.22.92 178176 Bytes 06.2.2012 г. 12:14:41

VBASE016.VDF : 7.11.22.154 144896 Bytes 08.2.2012 г. 12:14:41

VBASE017.VDF : 7.11.22.220 183296 Bytes 13.2.2012 г. 12:14:42

VBASE018.VDF : 7.11.23.34 202752 Bytes 15.2.2012 г. 12:14:44

VBASE019.VDF : 7.11.23.35 2048 Bytes 15.2.2012 г. 12:14:44

VBASE020.VDF : 7.11.23.36 2048 Bytes 15.2.2012 г. 12:14:44

VBASE021.VDF : 7.11.23.37 2048 Bytes 15.2.2012 г. 12:14:44

VBASE022.VDF : 7.11.23.38 2048 Bytes 15.2.2012 г. 12:14:44

VBASE023.VDF : 7.11.23.39 2048 Bytes 15.2.2012 г. 12:14:45

VBASE024.VDF : 7.11.23.40 2048 Bytes 15.2.2012 г. 12:14:45

VBASE025.VDF : 7.11.23.41 2048 Bytes 15.2.2012 г. 12:14:46

VBASE026.VDF : 7.11.23.42 2048 Bytes 15.2.2012 г. 12:14:46

VBASE027.VDF : 7.11.23.43 2048 Bytes 15.2.2012 г. 12:14:46

VBASE028.VDF : 7.11.23.44 2048 Bytes 15.2.2012 г. 12:14:46

VBASE029.VDF : 7.11.23.45 2048 Bytes 15.2.2012 г. 12:14:47

VBASE030.VDF : 7.11.23.46 2048 Bytes 15.2.2012 г. 12:14:47

VBASE031.VDF : 7.11.23.96 126464 Bytes 17.2.2012 г. 12:14:48

Engineversion : 8.2.10.4

AEVDF.DLL : 8.1.2.2 106868 Bytes 31.1.2012 г. 06:56:42

AESCRIPT.DLL : 8.1.4.5 442745 Bytes 17.2.2012 г. 12:14:58

AESCN.DLL : 8.1.8.2 131444 Bytes 17.2.2012 г. 12:14:57

AESBX.DLL : 8.2.4.5 434549 Bytes 31.1.2012 г. 06:56:42

AERDL.DLL : 8.1.9.15 639348 Bytes 31.1.2012 г. 06:56:42

AEPACK.DLL : 8.2.16.3 799094 Bytes 17.2.2012 г. 12:14:56

AEOFFICE.DLL : 8.1.2.25 201084 Bytes 31.1.2012 г. 06:56:41

AEHEUR.DLL : 8.1.3.31 4395383 Bytes 17.2.2012 г. 12:14:54

AEHELP.DLL : 8.1.19.0 254327 Bytes 17.2.2012 г. 12:14:51

AEGEN.DLL : 8.1.5.21 409971 Bytes 17.2.2012 г. 12:14:50

AEEXP.DLL : 8.1.0.22 70005 Bytes 17.2.2012 г. 12:15:04

AEEMU.DLL : 8.1.3.0 393589 Bytes 31.1.2012 г. 06:56:38

AECORE.DLL : 8.1.25.4 201079 Bytes 17.2.2012 г. 12:14:49

AEBB.DLL : 8.1.1.0 53618 Bytes 31.1.2012 г. 06:56:38

AVWINLL.DLL : 12.1.0.17 27344 Bytes 31.1.2012 г. 06:56:55

AVPREF.DLL : 12.1.0.17 51920 Bytes 31.1.2012 г. 06:56:53

AVREP.DLL : 12.1.0.17 179408 Bytes 31.1.2012 г. 06:56:53

AVARKT.DLL : 12.1.0.23 209360 Bytes 31.1.2012 г. 06:56:49

AVEVTLOG.DLL : 12.1.0.17 169168 Bytes 31.1.2012 г. 06:56:50

SQLITE3.DLL : 3.7.0.0 398288 Bytes 31.1.2012 г. 06:57:08

AVSMTP.DLL : 12.1.0.17 62928 Bytes 31.1.2012 г. 06:56:54

NETNT.DLL : 12.1.0.17 17104 Bytes 31.1.2012 г. 06:57:04

RCIMAGE.DLL : 12.1.0.17 4450000 Bytes 31.1.2012 г. 06:57:30

RCTEXT.DLL : 12.1.1.16 96208 Bytes 31.1.2012 г. 06:57:30

Configuration settings for the scan:

Jobname.............................: Manual Selection

Configuration file..................: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\PROFILES\folder.avp

Logging.............................: default

Primary action......................: interactive

Secondary action....................: ignore

Scan master boot sector.............: on

Scan boot sector....................: on

Boot sectors........................: L:,

Process scan........................: on

Scan registry.......................: on

Search for rootkits.................: off

Integrity checking of system files..: off

Scan all files......................: Intelligent file selection

Scan archives.......................: on

Recursion depth.....................: 20

Smart extensions....................: on

Macro heuristic.....................: on

File heuristic......................: extended

Start of the scan: 18 Февруари 2012 г. 00:59

Starting master boot sector scan:

Master boot sector HD0

[iNFO] No virus was found!

Master boot sector HD1

[iNFO] No virus was found!

Start scanning boot sectors:

Boot sector 'L:\'

[iNFO] No virus was found!

The scan of running processes will be started

Scan process 'avscan.exe' - '1' Module(s) have been scanned

Scan process 'avcenter.exe' - '1' Module(s) have been scanned

Scan process 'CCleaner.exe' - '1' Module(s) have been scanned

Scan process 'plugin-container.exe' - '1' Module(s) have been scanned

Scan process 'firefox.exe' - '1' Module(s) have been scanned

Scan process 'cli.exe' - '1' Module(s) have been scanned

Scan process 'cli.exe' - '1' Module(s) have been scanned

Scan process 'alg.exe' - '1' Module(s) have been scanned

Scan process 'avshadow.exe' - '1' Module(s) have been scanned

Scan process 'avguard.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'uTorrent.exe' - '1' Module(s) have been scanned

Scan process 'CTFMON.EXE' - '1' Module(s) have been scanned

Scan process 'avgnt.exe' - '1' Module(s) have been scanned

Scan process 'cli.exe' - '1' Module(s) have been scanned

Scan process 'SOUNDMAN.EXE' - '1' Module(s) have been scanned

Scan process 'sched.exe' - '1' Module(s) have been scanned

Scan process 'spoolsv.exe' - '1' Module(s) have been scanned

Scan process 'Explorer.EXE' - '1' Module(s) have been scanned

Scan process 'Ati2evxx.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'Ati2evxx.exe' - '1' Module(s) have been scanned

Scan process 'lsass.exe' - '1' Module(s) have been scanned

Scan process 'services.exe' - '1' Module(s) have been scanned

Scan process 'winlogon.exe' - '1' Module(s) have been scanned

Scan process 'csrss.exe' - '1' Module(s) have been scanned

Scan process 'smss.exe' - '1' Module(s) have been scanned

Starting to scan executable files (registry).

The registry was scanned ( '347' files ).

Starting the file scan:

Begin scan in 'L:\' <KINGSTON>

End of the scan: 18 Февруари 2012 г. 01:02

Used time: 03:01 Minute(s)

The scan has been done completely.

84 Scanned directories

7085 Files were scanned

0 Viruses and/or unwanted programs were found

0 Files were classified as suspicious

0 Files were deleted

0 Viruses and unwanted programs were repaired

0 Files were moved to quarantine

0 Files were renamed

0 Files cannot be scanned

7085 Files not concerned

101 Archives were scanned

0 Warnings

0 Notes

А това вирус ли е

Avira Free Antivirus

Report file date: 17 Февруари 2012 г. 15:20

Scanning for 3472827 virus strains and unwanted programs.

The program is running as an unrestricted full version.

Online services are available:

Licensee : Avira AntiVir Personal - Free Antivirus

Serial number : 0000149996-ADJIE-0000001

Platform : Windows XP

Windows version : (Service Pack 3) [5.1.2600]

Boot mode : Normally booted

Username : SYSTEM

Computer name : NAILON-3A70F369

Version information:

BUILD.DAT : 12.0.0.898 41963 Bytes 31.1.2012 г. 14:50:00

AVSCAN.EXE : 12.1.0.20 492496 Bytes 31.1.2012 г. 06:56:54

AVSCAN.DLL : 12.1.0.18 54224 Bytes 31.1.2012 г. 06:57:27

LUKE.DLL : 12.1.0.19 68304 Bytes 31.1.2012 г. 06:57:02

AVSCPLR.DLL : 12.1.0.22 100048 Bytes 31.1.2012 г. 06:56:54

AVREG.DLL : 12.1.0.29 228048 Bytes 31.1.2012 г. 06:56:53

VBASE000.VDF : 7.10.0.0 19875328 Bytes 06.11.2009 г. 07:05:36

VBASE001.VDF : 7.11.0.0 13342208 Bytes 14.12.2010 г. 06:57:15

VBASE002.VDF : 7.11.19.170 14374912 Bytes 20.12.2011 г. 06:57:20

VBASE003.VDF : 7.11.21.238 4472832 Bytes 01.2.2012 г. 12:14:34

VBASE004.VDF : 7.11.21.239 2048 Bytes 01.2.2012 г. 12:14:34

VBASE005.VDF : 7.11.21.240 2048 Bytes 01.2.2012 г. 12:14:34

VBASE006.VDF : 7.11.21.241 2048 Bytes 01.2.2012 г. 12:14:34

VBASE007.VDF : 7.11.21.242 2048 Bytes 01.2.2012 г. 12:14:34

VBASE008.VDF : 7.11.21.243 2048 Bytes 01.2.2012 г. 12:14:35

VBASE009.VDF : 7.11.21.244 2048 Bytes 01.2.2012 г. 12:14:35

VBASE010.VDF : 7.11.21.245 2048 Bytes 01.2.2012 г. 12:14:35

VBASE011.VDF : 7.11.21.246 2048 Bytes 01.2.2012 г. 12:14:36

VBASE012.VDF : 7.11.21.247 2048 Bytes 01.2.2012 г. 12:14:36

VBASE013.VDF : 7.11.22.33 1486848 Bytes 03.2.2012 г. 12:14:38

VBASE014.VDF : 7.11.22.56 687616 Bytes 03.2.2012 г. 12:14:40

VBASE015.VDF : 7.11.22.92 178176 Bytes 06.2.2012 г. 12:14:41

VBASE016.VDF : 7.11.22.154 144896 Bytes 08.2.2012 г. 12:14:41

VBASE017.VDF : 7.11.22.220 183296 Bytes 13.2.2012 г. 12:14:42

VBASE018.VDF : 7.11.23.34 202752 Bytes 15.2.2012 г. 12:14:44

VBASE019.VDF : 7.11.23.35 2048 Bytes 15.2.2012 г. 12:14:44

VBASE020.VDF : 7.11.23.36 2048 Bytes 15.2.2012 г. 12:14:44

VBASE021.VDF : 7.11.23.37 2048 Bytes 15.2.2012 г. 12:14:44

VBASE022.VDF : 7.11.23.38 2048 Bytes 15.2.2012 г. 12:14:44

VBASE023.VDF : 7.11.23.39 2048 Bytes 15.2.2012 г. 12:14:45

VBASE024.VDF : 7.11.23.40 2048 Bytes 15.2.2012 г. 12:14:45

VBASE025.VDF : 7.11.23.41 2048 Bytes 15.2.2012 г. 12:14:46

VBASE026.VDF : 7.11.23.42 2048 Bytes 15.2.2012 г. 12:14:46

VBASE027.VDF : 7.11.23.43 2048 Bytes 15.2.2012 г. 12:14:46

VBASE028.VDF : 7.11.23.44 2048 Bytes 15.2.2012 г. 12:14:46

VBASE029.VDF : 7.11.23.45 2048 Bytes 15.2.2012 г. 12:14:47

VBASE030.VDF : 7.11.23.46 2048 Bytes 15.2.2012 г. 12:14:47

VBASE031.VDF : 7.11.23.96 126464 Bytes 17.2.2012 г. 12:14:48

Engineversion : 8.2.10.4

AEVDF.DLL : 8.1.2.2 106868 Bytes 31.1.2012 г. 06:56:42

AESCRIPT.DLL : 8.1.4.5 442745 Bytes 17.2.2012 г. 12:14:58

AESCN.DLL : 8.1.8.2 131444 Bytes 17.2.2012 г. 12:14:57

AESBX.DLL : 8.2.4.5 434549 Bytes 31.1.2012 г. 06:56:42

AERDL.DLL : 8.1.9.15 639348 Bytes 31.1.2012 г. 06:56:42

AEPACK.DLL : 8.2.16.3 799094 Bytes 17.2.2012 г. 12:14:56

AEOFFICE.DLL : 8.1.2.25 201084 Bytes 31.1.2012 г. 06:56:41

AEHEUR.DLL : 8.1.3.31 4395383 Bytes 17.2.2012 г. 12:14:54

AEHELP.DLL : 8.1.19.0 254327 Bytes 17.2.2012 г. 12:14:51

AEGEN.DLL : 8.1.5.21 409971 Bytes 17.2.2012 г. 12:14:50

AEEXP.DLL : 8.1.0.22 70005 Bytes 17.2.2012 г. 12:15:04

AEEMU.DLL : 8.1.3.0 393589 Bytes 31.1.2012 г. 06:56:38

AECORE.DLL : 8.1.25.4 201079 Bytes 17.2.2012 г. 12:14:49

AEBB.DLL : 8.1.1.0 53618 Bytes 31.1.2012 г. 06:56:38

AVWINLL.DLL : 12.1.0.17 27344 Bytes 31.1.2012 г. 06:56:55

AVPREF.DLL : 12.1.0.17 51920 Bytes 31.1.2012 г. 06:56:53

AVREP.DLL : 12.1.0.17 179408 Bytes 31.1.2012 г. 06:56:53

AVARKT.DLL : 12.1.0.23 209360 Bytes 31.1.2012 г. 06:56:49

AVEVTLOG.DLL : 12.1.0.17 169168 Bytes 31.1.2012 г. 06:56:50

SQLITE3.DLL : 3.7.0.0 398288 Bytes 31.1.2012 г. 06:57:08

AVSMTP.DLL : 12.1.0.17 62928 Bytes 31.1.2012 г. 06:56:54

NETNT.DLL : 12.1.0.17 17104 Bytes 31.1.2012 г. 06:57:04

RCIMAGE.DLL : 12.1.0.17 4450000 Bytes 31.1.2012 г. 06:57:30

RCTEXT.DLL : 12.1.1.16 96208 Bytes 31.1.2012 г. 06:57:30

Configuration settings for the scan:

Jobname.............................: AVGuardAsyncScan

Configuration file..................: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\AVGUARD_4f3e447d\guard_slideup.avp

Logging.............................: default

Primary action......................: interactive

Secondary action....................: quarantine

Scan master boot sector.............: on

Scan boot sector....................: off

Process scan........................: on

Scan registry.......................: off

Search for rootkits.................: off

Integrity checking of system files..: off

Scan all files......................: All files

Scan archives.......................: on

Recursion depth.....................: 20

Smart extensions....................: on

Macro heuristic.....................: on

File heuristic......................: Complete

Start of the scan: 17 Февруари 2012 г. 15:20

The scan of running processes will be started

Scan process 'avscan.exe' - '1' Module(s) have been scanned

Scan process 'msiexec.exe' - '1' Module(s) have been scanned

Scan process 'avscan.exe' - '1' Module(s) have been scanned

Scan process 'dllhost.exe' - '1' Module(s) have been scanned

Scan process 'vssvc.exe' - '1' Module(s) have been scanned

Scan process 'plugin-container.exe' - '1' Module(s) have been scanned

Scan process 'firefox.exe' - '1' Module(s) have been scanned

Scan process 'msdtc.exe' - '1' Module(s) have been scanned

Scan process 'dllhost.exe' - '1' Module(s) have been scanned

Scan process 'avcenter.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'avgnt.exe' - '1' Module(s) have been scanned

Scan process 'sched.exe' - '1' Module(s) have been scanned

Scan process 'avshadow.exe' - '1' Module(s) have been scanned

Scan process 'avguard.exe' - '1' Module(s) have been scanned

Scan process 'cli.exe' - '1' Module(s) have been scanned

Scan process 'cli.exe' - '1' Module(s) have been scanned

Scan process 'alg.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'uTorrent.exe' - '1' Module(s) have been scanned

Scan process 'ctfmon.exe' - '1' Module(s) have been scanned

Scan process 'cli.exe' - '1' Module(s) have been scanned

Scan process 'SOUNDMAN.EXE' - '1' Module(s) have been scanned

Scan process 'Explorer.EXE' - '1' Module(s) have been scanned

Scan process 'Ati2evxx.exe' - '1' Module(s) have been scanned

Scan process 'spoolsv.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'Ati2evxx.exe' - '1' Module(s) have been scanned

Scan process 'lsass.exe' - '1' Module(s) have been scanned

Scan process 'services.exe' - '1' Module(s) have been scanned

Scan process 'winlogon.exe' - '1' Module(s) have been scanned

Scan process 'csrss.exe' - '1' Module(s) have been scanned

Scan process 'smss.exe' - '1' Module(s) have been scanned

Starting the file scan:

Begin scan in 'I:\install\Z-Info.exe'

I:\install\Z-Info.exe

[DETECTION] Is the TR/Spy.ProAgent.EL Trojan

Beginning disinfection:

I:\install\Z-Info.exe

[DETECTION] Is the TR/Spy.ProAgent.EL Trojan

[NOTE] The file was moved to the quarantine directory under the name '4cd2fd82.qua'.

End of the scan: 17 Февруари 2012 г. 15:43

Used time: 00:01 Minute(s)

The scan has been done completely.

0 Scanned directories

38 Files were scanned

1 Viruses and/or unwanted programs were found

0 Files were classified as suspicious

0 Files were deleted

0 Viruses and unwanted programs were repaired

1 Files were moved to quarantine

0 Files were renamed

0 Files cannot be scanned

37 Files not concerned

0 Archives were scanned

0 Warnings

1 Notes

The scan results will be transferred to the Guard.

Благодаря :)

пробвам да unинсталирам bg phonetic by iliya dqnkov и не се трие

Какво точно се случва?

все още имам hiden folder с музика които не съм ги крил.

Изтеглете и стартирайте този файл: unhide.exe . Това трябва да ги открие.

Flash Disinfector как мога да го изтрия в случай че реша да не го ползвам.

За да премахнете само приложението е необходимо ръчно да го изтриете, но за да премахнете и защитата, която той добавя са необходими някои допълнителни стъпки. Моля, кажете ми, ако желаете това да стане.

Добрата новина е, че Avira вече не открива този червей, нито пък някакъв друг проблем.

  • Автор

1 .bg phonetic пробвам да го изтрия от ccleaner ,даде ми Fatal error during instalation. 2. червеят е на един от дяловете на харда в папка flash.А аз имах информация[филми и музика ; която се премести и такава която се скри из различни дялове на диска и едни филми и mp3 които свалях на флашката бъгнаха и не ги разпознава windows пише file 4kb в опции ми показва че са заети 5 гб на flash. Unhidе даде грешка .Avira засече още един файл :TR/Agent.13383546.1 3.какво е точно приложението на тази програма Flash Disinfector и ще се изтриели защото мисля да преинсталирам c:/format windows имам и backup може ли да го ползвам дали ще има ефект Благодаря за вниманието :)

1 .bg phonetic пробвам да го изтрия от ccleaner ,даде ми Fatal error during instalation.

Това ли е точното съобщение, което ви изписва?

Unhidе даде грешка .Avira засече още един файл :TR/Agent.13383546.1

Предполагам и софтуер, игри държите също там? Каква точно грешка изписа unhide.exe ?

3.какво е точно приложението на тази програма Flash Disinfector и ще се изтриели защото мисля да преинсталирам c:/format windows имам и backup може ли да го ползвам дали ще има ефект

Нейната цел е дезинфекциране на флаш памет и други преносими устройства, както и превенция срещу инфектирането му и това на системата.

  • Автор

1.да това е съобщението съвсем точно 2.след последната инсталацията на windows ,създадох back up мога ли да го ползвам -съвет 3.или ако си направя нова преинсталация с нов windows и после да сканирам за вируси дали ще ми изчезне информация от другите дялове на харда :) Благодаря ти :)

Редактирано от selzar (преглед на промените)

2.след последната инсталацията на windows ,създадох back up мога ли да го ползвам -съвет

Ако е създаден в точния момент т.е. сигурно е, че системата ви не е била компрометирана, може да се използва.

3.или ако си направя нова преинсталация с нов windows и после да сканирам за вируси дали ще ми изчезне информация от другите дялове на харда

Ако направите форматиране само на основния ви дял (т.е. този, на който е инсталиран Windows), останалите няма да бъдат засегнати.

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.