Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Мисля,че windows-а е заразен

Featured Replies

Проблема и в това,че нещо ми прави трафик от интернета и ми качва Upload на макс.Също така и отварянето на страниците ми се забавя много.Гледам,че и дърпа ресурси от процесора-20-30% а в таск манагера всички процеси са на 0 и ми показва system idle process 99.Програма Process Explorer ми показва,че 12-13% ми заема процеса Interrupts.Не знам дали е вирус,но ето логовете от DDS и attach:

DDS:

DDS (Ver_2011-09-30.01) - NTFS_x86

Internet Explorer: 8.0.6001.18702

Run by Krasimir at 20:46:36 on 2012-03-04

Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.1535.892 [GMT 2:00]

.

AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}

.

============== Running Processes ================

.

C:\WINDOWS\system32\nvsvc32.exe

C:\Program Files\AVAST Software\Avast\AvastSvc.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Application Updater\ApplicationUpdater.exe

C:\WINDOWS\RTHDCPL.EXE

C:\WINDOWS\system32\RUNDLL32.EXE

C:\Program Files\AVAST Software\Avast\avastUI.exe

C:\Program Files\SweetIM\Messenger\SweetIM.exe

C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\System32\alg.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Mozilla Firefox\plugin-container.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\system32\wbem\wmiprvse.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup

C:\WINDOWS\system32\svchost.exe -k NetworkService

C:\WINDOWS\system32\svchost.exe -k LocalService

C:\WINDOWS\system32\svchost.exe -k LocalService

C:\WINDOWS\system32\svchost.exe -k imgsvc

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://home.sweetim.com

mStart Page = hxxp://home.sweetim.com

uURLSearchHooks: YouTube Downloader Toolbar: {F3FEE66E-E034-436a-86E4-9690573BEE8A} - c:\program files\youtube downloader toolbar\ie\5.0\youtubedownloaderToolbarIE.dll

uURLSearchHooks: SweetIM ToolbarURLSearchHook Class: {EEE6C35D-6118-11DC-9C72-001320C79847} - c:\program files\sweetim\toolbars\internet explorer\mgHelper.dll

BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll

BHO: SweetIM Toolbar Helper: {EEE6C35C-6118-11DC-9C72-001320C79847} - c:\program files\sweetim\toolbars\internet explorer\mgToolbarIE.dll

BHO: YouTube Downloader Toolbar: {F3FEE66E-E034-436a-86E4-9690573BEE8A} - c:\program files\youtube downloader toolbar\ie\5.0\youtubedownloaderToolbarIE.dll

TB: SweetIM Toolbar for Internet Explorer: {EEE6C35B-6118-11DC-9C72-001320C79847} - c:\program files\sweetim\toolbars\internet explorer\mgToolbarIE.dll

TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll

TB: SweetIM Toolbar for Internet Explorer: {EEE6C35B-6118-11DC-9C72-001320C79847} - c:\program files\sweetim\toolbars\internet explorer\mgToolbarIE.dll

TB: YouTube Downloader Toolbar: {F3FEE66E-E034-436a-86E4-9690573BEE8A} - c:\program files\youtube downloader toolbar\ie\5.0\youtubedownloaderToolbarIE.dll

uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe

uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe" /MINIMIZED

uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun

uRun: [Google Update] "c:\documents and settings\krasimir\local settings\application data\google\update\GoogleUpdate.exe" /c

mRun: [RTHDCPL] RTHDCPL.EXE

mRun: [skyTel] SkyTel.EXE

mRun: [Alcmtr] ALCMTR.EXE

mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit

mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup

mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui

mRun: [sweetIM] c:\program files\sweetim\messenger\SweetIM.exe

mRun: [searchSettings] "c:\program files\common files\spigot\search settings\SearchSettings.exe"

dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE

uPolicies-Explorer: NoDriveTypeAutoRun = dword:145

mPolicies-Explorer: NoDriveTypeAutoRun = dword:145

IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000

IE: Search the Web - c:\program files\sweetim\toolbars\internet explorer\resources\menuext.html

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

TCP: NameServer = 88.80.96.4 88.80.96.7

TCP: Interfaces\{476D6673-47FE-47AC-B671-E206717320A1} : DHCPNameServer = 88.80.96.4 88.80.96.7

SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\wpdshserviceobj.dll

.

================= FIREFOX ===================

.

FF - ProfilePath - c:\documents and settings\krasimir\application data\mozilla\firefox\profiles\g6d3jk0y.default\

FF - prefs.js: browser.search.selectedEngine - Yahoo

FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=937811&p=

FF - plugin: c:\documents and settings\krasimir\local settings\application data\google\update\1.3.21.99\npGoogleUpdate3.dll

.

============= SERVICES / DRIVERS ===============

.

R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-11-21 610648]

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-11-21 337112]

R2 Application Updater;Application Updater;c:\program files\application updater\ApplicationUpdater.exe [2012-2-6 748440]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-11-21 20696]

R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-11-21 44768]

R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [2011-11-21 57248]

S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\krasimir\locals~1\temp\unc31e.tmp --> c:\docume~1\krasimir\locals~1\temp\UNC31E.tmp [?]

S3 GGSAFERDriver;GGSAFER Driver;\??\c:\program files\garena\safedrv.sys --> c:\program files\garena\safedrv.sys [?]

.

=============== Created Last 30 ================

.

2012-02-29 14:48:34 -------- d-----w- c:\program files\Audacity 1.3 Beta (Unicode)

2012-02-28 17:01:23 -------- d-----w- c:\program files\common files\Macrovision Shared

2012-02-23 20:52:49 -------- d-----w- c:\documents and settings\krasimir\application data\Search Settings

2012-02-23 20:52:42 -------- d-----w- c:\program files\YouTube Downloader Toolbar

2012-02-23 20:52:42 -------- d-----w- c:\program files\common files\Spigot

2012-02-23 20:52:42 -------- d-----w- c:\program files\Application Updater

2012-02-21 18:17:25 -------- d-----w- c:\program files\LooksBuilder

2012-02-21 18:16:06 -------- d-----w- c:\documents and settings\krasimir\local settings\application data\Downloaded Installations

2012-02-20 23:48:01 -------- d-----w- C:\After Effects

2012-02-16 10:18:24 3072 -c----w- c:\windows\system32\dllcache\iacenc.dll

2012-02-16 10:18:24 3072 ------w- c:\windows\system32\iacenc.dll

2012-02-14 08:41:08 -------- d-----w- c:\documents and settings\krasimir\local settings\application data\ApplicationHistory

2012-02-13 13:21:54 -------- d-----w- c:\program files\killingfloor

2012-02-13 09:18:42 -------- d-----w- c:\documents and settings\krasimir\application data\NetMedia Providers

2012-02-13 09:18:35 -------- d-----w- c:\documents and settings\krasimir\application data\Sonic Foundry

2012-02-13 09:17:43 -------- d-----w- c:\program files\Sonic Foundry

2012-02-13 09:17:37 665424 ----a-w- c:\windows\system32\wmv8dmoe.dll

2012-02-13 09:17:37 566272 ----a-w- c:\windows\system32\wmvdmoe.dll

2012-02-13 09:17:37 438608 ----a-w- c:\windows\system32\wmv8dmod.dll

2012-02-13 09:17:36 285184 ----a-w- c:\windows\system32\wmidx2.ocx

2012-02-13 09:17:36 1683792 ----a-w- c:\windows\system32\wmvcore2.dll

2012-02-13 09:17:12 -------- d-----w- c:\program files\Sonic Foundry Setup

2012-02-13 09:05:26 -------- d-----w- c:\windows\system32\URTTEMP

2012-02-13 09:03:48 -------- d-----w- C:\NET

2012-02-12 20:46:24 -------- d-----w- c:\windows\system32\wbem\repository\FS

2012-02-12 20:46:24 -------- d-----w- c:\windows\system32\wbem\Repository

2012-02-12 20:45:35 -------- d-----w- c:\program files\Sony

2012-02-12 20:45:31 -------- d-----w- c:\program files\Sony Setup

2012-02-12 18:17:37 -------- d-----w- c:\program files\Vstplugins(2)

2012-02-12 18:17:23 -------- d-----w- c:\program files\Sony(2)

2012-02-12 18:16:34 -------- d-----w- c:\program files\Sony Setup(2)

2012-02-09 11:38:44 -------- d-----w- c:\documents and settings\krasimir\local settings\application data\TechSmith

2012-02-09 11:29:13 -------- d-----w- c:\windows\system32\QuickTime

2012-02-09 11:28:49 -------- d-----w- c:\program files\common files\TechSmith Shared

2012-02-07 17:01:48 5632 ----a-w- c:\windows\system32\ptpusb.dll

2012-02-07 17:01:48 159232 ----a-w- c:\windows\system32\ptpusd.dll

2012-02-07 17:01:48 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys

2012-02-07 17:01:48 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys

2012-02-04 13:17:36 299520 ----a-w- c:\windows\uninst.exe

2012-02-04 13:17:33 -------- d-----w- c:\documents and settings\krasimir\WINDOWS

.

==================== Find3M ====================

.

2012-02-23 16:23:26 41184 ----a-w- c:\windows\avastSS.scr

2012-02-23 16:12:28 610648 ----a-w- c:\windows\system32\drivers\aswSnx.sys

2012-02-20 11:45:29 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2012-01-12 16:54:47 1869056 ----a-w- c:\windows\system32\win32k.sys

2011-12-17 19:45:42 919552 ----a-w- c:\windows\system32\wininet.dll

2011-12-17 19:45:42 43520 ----a-w- c:\windows\system32\licmgr10.dll

2011-12-17 19:45:42 1469440 ----a-w- c:\windows\system32\inetcpl.cpl

2011-12-16 12:32:59 385024 ----a-w- c:\windows\system32\html.iec

.

============= FINISH: 20:46:55,85 ===============

Ето и от ATTACH:

.

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.

IF REQUESTED, ZIP IT UP & ATTACH IT

.

DDS (Ver_2011-09-30.01)

.

Microsoft Windows XP Professional

Boot Device: \Device\HarddiskVolume1

Install Date: 21.11.2011 г. 20:06:14

System Uptime: 04.3.2012 г. 10:08:10 (10 hours ago)

.

Motherboard: MSI | | MS-7252

Processor: AMD Athlon™ 64 Processor 3000+ | CPU 1 | 1808/200mhz

.

==== Disk Partitions =========================

.

A: is Removable

C: is FIXED (NTFS) - 78 GiB total, 15,192 GiB free.

D: is CDROM ()

E: is FIXED (NTFS) - 194 GiB total, 4,845 GiB free.

F: is FIXED (NTFS) - 194 GiB total, 52,381 GiB free.

G: is CDROM ()

.

==== Disabled Device Manager Items =============

.

Class GUID: {4D36E96F-E325-11CE-BFC1-08002BE10318}

Description: Microsoft PS/2 Mouse

Device ID: ACPI\PNP0F03\4&11A48330&0

Manufacturer: Microsoft

Name: Microsoft PS/2 Mouse

PNP Device ID: ACPI\PNP0F03\4&11A48330&0

Service: i8042prt

.

==== System Restore Points ===================

.

RP83: 05.2.2012 г. 22:18:13 - System Checkpoint

RP84: 06.2.2012 г. 22:42:40 - System Checkpoint

RP85: 08.2.2012 г. 10:08:35 - System Checkpoint

RP86: 09.2.2012 г. 11:36:51 - System Checkpoint

RP87: 09.2.2012 г. 13:28:38 - Installed Camtasia Studio 7

RP88: 10.2.2012 г. 14:09:01 - System Checkpoint

RP89: 12.2.2012 г. 14:12:34 - System Checkpoint

RP90: 12.2.2012 г. 18:00:21 - Removed Vegas Pro 9.0e

RP91: 12.2.2012 г. 18:07:48 - Removed Sony Vegas Movie Studio 6.0b

RP92: 12.2.2012 г. 18:18:16 - Installed Sony Vegas 6.0d

RP93: 12.2.2012 г. 19:56:33 - Installed Microsoft .NET Framework (English) v1.0.3705

RP94: 12.2.2012 г. 19:57:48 - Installed Microsoft .NET Framework 1.1

RP95: 12.2.2012 г. 20:12:40 - Removed Sony Vegas 6.0d

RP96: 12.2.2012 г. 20:17:20 - Installed Sony Vegas 6.0d

RP97: 12.2.2012 г. 22:38:24 - Removed Sony Vegas 6.0d

RP98: 12.2.2012 г. 22:44:37 - Restore Operation

RP99: 13.2.2012 г. 10:56:41 - Removed Vegas Pro 9.0e

RP100: 13.2.2012 г. 11:02:23 - Removed Sony Vegas Movie Studio 6.0b

RP101: 13.2.2012 г. 11:04:06 - Installed Microsoft .NET Framework (English) v1.0.3705

RP102: 13.2.2012 г. 11:05:10 - Installed Microsoft .NET Framework 1.1

RP103: 13.2.2012 г. 11:17:32 - Installed Sonic Foundry Vegas 4.0

RP104: 13.2.2012 г. 22:31:40 - Software Distribution Service 3.0

RP105: 14.2.2012 г. 16:46:11 - Software Distribution Service 3.0

RP106: 15.2.2012 г. 20:28:11 - System Checkpoint

RP107: 16.2.2012 г. 17:39:11 - Software Distribution Service 3.0

RP108: 17.2.2012 г. 20:08:03 - System Checkpoint

RP109: 18.2.2012 г. 20:24:31 - System Checkpoint

RP110: 19.2.2012 г. 20:55:18 - System Checkpoint

RP111: 21.2.2012 г. 00:29:37 - System Checkpoint

RP112: 21.2.2012 г. 20:17:22 - Installed Magic Bullet Looks 32-bit

RP113: 23.2.2012 г. 17:42:51 - System Checkpoint

RP114: 24.2.2012 г. 19:20:19 - System Checkpoint

RP115: 25.2.2012 г. 20:09:23 - System Checkpoint

RP116: 26.2.2012 г. 22:43:52 - System Checkpoint

RP117: 28.2.2012 г. 14:02:18 - System Checkpoint

RP118: 28.2.2012 г. 18:39:23 - Removed Adobe Media Player

RP119: 29.2.2012 г. 20:29:48 - System Checkpoint

RP120: 01.3.2012 г. 21:12:18 - System Checkpoint

RP121: 02.3.2012 г. 21:19:00 - System Checkpoint

RP122: 04.3.2012 г. 13:45:44 - System Checkpoint

.

==== Installed Programs ======================

.

µTorrent

Adobe After Effects CS4

Adobe After Effects CS4 Presets

Adobe After Effects CS4 Third Party Content

Adobe AIR

Adobe Anchor Service CS4

Adobe Bridge CS4

Adobe CMaps CS4

Adobe Color Video Profiles AE CS4

Adobe Community Help

Adobe Default Language CS4

Adobe Device Central CS4

Adobe Dynamiclink Support

Adobe ExtendScript Toolkit CS4

Adobe Extension Manager CS4

Adobe Flash Player 11 Plugin

Adobe Fonts All

Adobe Media Encoder CS4

Adobe Media Encoder CS4 Additional Exporter

Adobe Media Encoder CS4 Exporter

Adobe Media Encoder CS4 Importer

Adobe Media Player

Adobe MotionPicture Color Files CS4

Adobe Output Module

Adobe PDF Library Files CS4

Adobe Setup

Adobe Type Support CS4

Adobe Update Manager CS4

Adobe XMP Panels CS4

AGEIA PhysX v7.07.09

AMX Mod X Installer 1.8.1

Audacity 1.3.14 (Unicode)

avast! Free Antivirus

Battlefield 2™

BS.Player PRO

Camtasia Studio 7

Counter-Strike 1.6

FileZilla Client 3.5.2

Foxit Reader 5.1

Fraps (remove only)

Google Chrome

Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)

Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)

Hotfix for Windows XP (KB2570791)

Hotfix for Windows XP (KB2633952)

Hotfix for Windows XP (KB954550-v5)

Hotfix for Windows XP (KB976002-v5)

IrfanView (remove only)

Killing Floor

Magic Bullet Looks 32-bit

Microsoft .NET Framework (English)

Microsoft .NET Framework (English) v1.0.3705

Microsoft .NET Framework 1.0 Hotfix (KB928367)

Microsoft .NET Framework 1.1

Microsoft .NET Framework 1.1 Security Update (KB2656353)

Microsoft .NET Framework 2.0 Service Pack 2

Microsoft .NET Framework 3.0 Service Pack 2

Microsoft .NET Framework 3.5 SP1

Microsoft Office Professional Edition 2003

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319

Microsoft_VC80_ATL_x86

Microsoft_VC80_CRT_x86

Microsoft_VC80_MFC_x86

Microsoft_VC80_MFCLOC_x86

Microsoft_VC90_ATL_x86

Microsoft_VC90_CRT_x86

Microsoft_VC90_MFC_x86

Microsoft_VC90_MFCLOC_x86

Mozilla Firefox 10.0.2 (x86 bg)

MSXML 6.0 Parser (KB925673)

NVIDIA Drivers

Photoshop Camera Raw

Pixel Bender Toolkit

Project64 1.6

Realtek High Definition Audio Driver

Resident Evil 4 1.10

Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)

Security Update for Microsoft Windows (KB2564958)

Security Update for Windows Internet Explorer 8 (KB2586448)

Security Update for Windows Internet Explorer 8 (KB2618444)

Security Update for Windows Internet Explorer 8 (KB2647516)

Security Update for Windows Media Player (KB975558)

Security Update for Windows XP (KB2507938)

Security Update for Windows XP (KB2508272)

Security Update for Windows XP (KB2524375)

Security Update for Windows XP (KB2536276-v2)

Security Update for Windows XP (KB2544893-v2)

Security Update for Windows XP (KB2562937)

Security Update for Windows XP (KB2566454)

Security Update for Windows XP (KB2567053)

Security Update for Windows XP (KB2567680)

Security Update for Windows XP (KB2570222)

Security Update for Windows XP (KB2570947)

Security Update for Windows XP (KB2584146)

Security Update for Windows XP (KB2585542)

Security Update for Windows XP (KB2592799)

Security Update for Windows XP (KB2598479)

Security Update for Windows XP (KB2603381)

Security Update for Windows XP (KB2618451)

Security Update for Windows XP (KB2619339)

Security Update for Windows XP (KB2620712)

Security Update for Windows XP (KB2624667)

Security Update for Windows XP (KB2631813)

Security Update for Windows XP (KB2633171)

Security Update for Windows XP (KB2639417)

Security Update for Windows XP (KB2646524)

Security Update for Windows XP (KB2660465)

Security Update for Windows XP (KB2661637)

Security Update for Windows XP (KB923789)

Security Update for Windows XP (KB950760)

Security Update for Windows XP (KB980195)

Skype™ 5.5

Sonic Foundry Vegas 4.0

Suite Shared Configuration CS4

SweetIM for Messenger 3.6

SweetIM Toolbar for Internet Explorer 4.2

TeamViewer 6

Update for Microsoft .NET Framework 3.5 SP1 (KB963707)

Update for Microsoft Windows (KB971513)

Update for Windows XP (KB2467659)

Update for Windows XP (KB2541763)

Update for Windows XP (KB2641690)

Update for Windows XP (KB898461)

WebFldrs XP

Winamp (remove only)

Windows Presentation Foundation

WinRAR 4.10 beta 3 (32-bit)

XML Paper Specification Shared Components Pack 1.0

YouTube Downloader 3.4

YouTube Downloader Toolbar v5.0

.

==== Event Viewer Messages From Past Week ========

.

28.2.2012 г. 18:03:53, error: Dhcp [1002] - The IP address lease 77.77.17.239 for the Network Card with network address 54E6FC829267 has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).

27.2.2012 г. 13:54:19, error: Dhcp [1002] - The IP address lease 192.168.100.11 for the Network Card with network address 54E6FC829267 has been denied by the DHCP server 10.0.0.13 (The DHCP Server sent a DHCPNACK message).

27.2.2012 г. 13:54:03, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

02.3.2012 г. 20:12:23, error: Dhcp [1002] - The IP address lease 77.77.17.239 for the Network Card with network address 54E6FC829267 has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).

.

==== End Of File ===========================

Редактирано от FD GOD (преглед на промените)

Здравейте!

Вашата система е инфектирана, но също и торент клиента ви би могъл да допринася за влошаване на вашата интернет връзка.

Стъпка 1

Моля, деинсталирайте следните приложения:

  • SweetIM for Messenger 3.6
  • SweetIM Toolbar for Internet Explorer 4.2

Стъпка 2

Стартирайте µTorrent, отворете менюто Options и от там изберете Preferences. В General, махнете отметката пред Start µTorrent on system startup и изберете OK. Затворете приложението.

Стъпка 3

  • Изтеглете Malwarebytes' Anti-Malware оттук и я инсталирайте.
  • Стартирайте Malwarebytes' Anti-Malware и отидете на UPDATE и натиснете Check for updates.
  • След това се върнете на Scanner изберете Perform QUICK Scan, след това кликнете на Scan.
  • Сканирането ще отнеме малко време, затова моля бъдете търпеливи.
  • Когато сканирането завърши, кликнете на OK, след това Show Results, за да видите резултата.
  • Уверете се, че на всички редове има отметки, и кликнете Remove Selected.
  • Когато всичко бъде премахнато, логът ще бъде отворен в Notepad. Копирайте лога и го публикувайте в следващия си коментар в темата.

Забележка: Ако MalwareBytes' Anti-Malware се затрудни в премахването на откритите вируси/заплахи, той ще поиска да рестартира компютъра и по време на рестартирането да премахне проблемните вируси/заплахи. Ако бъдете попитани, потвърдете че желаете вашия компютър да бъде рестартиран.

Накрая, публикувайте лог файла от Malwarebytes' Anti-Malware и нов лог файл от DDS.

  • Автор

Здравейте!

Вашата система е инфектирана, но също и торент клиента ви би могъл да допринася за влошаване на вашата интернет връзка.

Стъпка 1

Моля, деинсталирайте следните приложения:

  • SweetIM for Messenger 3.6
  • SweetIM Toolbar for Internet Explorer 4.2

Стъпка 2

Стартирайте µTorrent, отворете менюто Options и от там изберете Preferences. В General, махнете отметката пред Start µTorrent on system startup и изберете OK. Затворете приложението.

Стъпка 3

  • Изтеглете Malwarebytes' Anti-Malware оттук и я инсталирайте.
  • Стартирайте Malwarebytes' Anti-Malware и отидете на UPDATE и натиснете Check for updates.
  • След това се върнете на Scanner изберете Perform QUICK Scan, след това кликнете на Scan.
  • Сканирането ще отнеме малко време, затова моля бъдете търпеливи.
  • Когато сканирането завърши, кликнете на OK, след това Show Results, за да видите резултата.
  • Уверете се, че на всички редове има отметки, и кликнете Remove Selected.
  • Когато всичко бъде премахнато, логът ще бъде отворен в Notepad. Копирайте лога и го публикувайте в следващия си коментар в темата.
Забележка: Ако MalwareBytes' Anti-Malware се затрудни в премахването на откритите вируси/заплахи, той ще поиска да рестартира компютъра и по време на рестартирането да премахне проблемните вируси/заплахи. Ако бъдете попитани, потвърдете че желаете вашия компютър да бъде рестартиран.

Накрая, публикувайте лог файла от Malwarebytes' Anti-Malware и нов лог файл от DDS.

1-2 дена няма да имам достъп до моя компютър,но после ще направя нещата,които ми написахте горе и ще постна лог от DDS.Моля не заключвайте темата!

  • 4 седмици по-късно...
  • Автор

Malwarebytes Anti-Malware 1.60.1.1000 www.malwarebytes.org Версия на базата от данни: v2012.04.01.01 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Krasimir :: KRASI [администратор] 01.4.2012 г. 14:47:41 mbam-log-2012-04-01 (14-47-41).txt Тип сканиране: Бързо сканиране Включени опции за сканиране: Памет | Автоматично зареждане | Системен регистър | Файлова система | Евристики/Допълнителни | Евристики/Shuriken | PUP | PUM Изключени опции за сканиране: P2P Сканирани обекти: 177040 Изминало време: 6 минута(и), 57 секунда(и) Открити процеси в паметта: 0 (Не бяха открити зловредни обекти) Открити модули в паметта: 0 (Не бяха открити зловредни обекти) Открити ключове в системния регистър: 0 (Не бяха открити зловредни обекти) Открити стойности в системния регистър: 0 (Не бяха открити зловредни обекти) Открити информационни обекти в системния регистър: 0 (Не бяха открити зловредни обекти) Открити папки: 0 (Не бяха открити зловредни обекти) Открити файлове: 0 (Не бяха открити зловредни обекти) (край) Нищо не намери,а компютъра ми става все по-бавен и все повече зацикля и ми прави някакъв лаг без причина,като играя Online игри.

1. Изтеглете ComboFix от BleepingComputer

и го запазете (бутон Save -> Save as) ComboFix на вашия десктоп:

Публикувано изображение

След приключване на изтеглянето на ComboFix, иконката на програмата би трябвало да изглежда така:

Публикувано изображение

2. Затворете всички работещи приложения, отворени прозорци и програми работещи във фонов режим. Спрете временно защитата в реално време на антивирусната програма и на другите програми за сигурност, ако има такива.

3. Стартирайте с двоен клик Combofix.exe. Изберете YES, за да се съгласите с условията за използване на програмата. Важно: По време на работата на ComboFix не бива да се движи мишката и да се натискат клавиши от клавиатурата. Просто търпеливо оставете ComboFix да си свърши работата, без да използвате компютъра за други цели.

4. Ако получите предупреждение от UAC, съгласете се.

5 ComboFix ще спре временно Интернет връзката, но след като приключи работата на програмата тази връзка ще бъде възстановена автоматично. ComboFix ще сканира за проблеми и за заразени файлове, като това може да отнеме известно време. Моля да бъдете търпеливи. Ако има проблем с Интернет връзката след приключване на работата на Combofix, моля да прочетете това: Manually restoring the Internet connection section.

6 Когато работата на ComboFix приключи, ще се появи текстов документ (log) в Notepad:

Публикувано изображение

Копирайте с (Copy) и поставете с (Paste) съдържанието на лога в следващия си коментар.

Забележка: Ако се появи следното съобщение при отварянето на различни програми след завършване на сканирането с Combofix - "illegal operation on a registry key that has been marked for deletion." просто рестартирайте компютъра още веднъж и то ще изчезне.

По време на сканирането не използвайте компютъра си !

  • Автор

ComboFix 12-03-31.03 - Krasimir 04.2012 г. 15:46:47.1.1 - x86 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.1535.955 [GMT 3:00] Running from: c:\documents and settings\Krasimir\My Documents\Downloads\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\documents and settings\Krasimir\WINDOWS . . ((((((((((((((((((((((((( Files Created from 2012-03-01 to 2012-04-01 ))))))))))))))))))))))))))))))) . . 2012-04-01 11:46 . 2012-04-01 11:46 -------- d-----w- c:\documents and settings\Krasimir\Application Data\Malwarebytes 2012-04-01 11:45 . 2012-04-01 11:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2012-04-01 11:45 . 2012-04-01 11:45 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2012-04-01 11:45 . 2011-12-10 12:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys 2012-03-31 16:53 . 2012-03-31 16:56 -------- d-----w- C:\xampp 2012-03-20 15:31 . 2012-03-20 15:38 -------- d-----w- c:\program files\Valve 2012-03-20 15:30 . 2003-09-03 00:28 724992 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iKernel.dll 2012-03-20 15:30 . 2003-09-03 00:27 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\ctor.dll 2012-03-20 15:30 . 2003-09-03 00:26 266240 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iscript.dll 2012-03-20 15:30 . 2003-09-03 00:26 192512 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iuser.dll 2012-03-20 15:30 . 2003-09-03 00:25 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\DotNetInstaller.exe 2012-03-20 15:30 . 2012-03-20 15:30 311428 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\Setup.dll 2012-03-20 15:30 . 2012-03-20 15:30 184452 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iGdi.dll 2012-03-17 16:27 . 2012-03-17 16:27 592824 ----a-w- c:\program files\Mozilla Firefox\gkmedias.dll 2012-03-17 16:27 . 2012-03-17 16:27 44472 ----a-w- c:\program files\Mozilla Firefox\mozglue.dll 2012-03-15 17:48 . 2012-03-15 17:48 -------- d-----w- c:\documents and settings\Krasimir\Application Data\Search Settings 2012-03-15 17:48 . 2012-03-15 17:48 -------- d-----w- c:\program files\Application Updater 2012-03-15 17:48 . 2012-03-15 17:48 -------- d-----w- c:\program files\YouTube Downloader Toolbar 2012-03-15 17:48 . 2012-03-15 17:48 -------- d-----w- c:\program files\Common Files\Spigot . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-02-23 16:23 . 2011-11-21 19:27 41184 ----a-w- c:\windows\avastSS.scr 2012-02-23 16:23 . 2011-11-21 19:27 201352 ----a-w- c:\windows\system32\aswBoot.exe 2012-02-23 16:12 . 2011-11-21 19:28 610648 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2012-02-23 16:12 . 2011-11-21 19:28 337112 ----a-w- c:\windows\system32\drivers\aswSP.sys 2012-02-23 16:10 . 2011-11-21 19:28 35672 ----a-w- c:\windows\system32\drivers\aswRdr.sys 2012-02-23 16:10 . 2011-11-21 19:28 53848 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2012-02-23 16:10 . 2011-11-21 19:28 95704 ----a-w- c:\windows\system32\drivers\aswmon2.sys 2012-02-23 16:10 . 2011-11-21 19:28 89048 ----a-w- c:\windows\system32\drivers\aswmon.sys 2012-02-23 16:10 . 2011-11-21 19:28 20696 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2012-02-23 16:07 . 2011-11-21 19:28 24920 ----a-w- c:\windows\system32\drivers\aavmker4.sys 2012-02-20 11:45 . 2011-11-21 19:36 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-02-03 09:26 . 2008-11-05 14:19 1869184 ----a-w- c:\windows\system32\win32k.sys 2012-01-11 19:06 . 2012-02-16 10:18 3072 ------w- c:\windows\system32\iacenc.dll 2012-01-09 16:20 . 2011-11-21 17:56 139784 ----a-w- c:\windows\system32\drivers\rdpwd.sys 2012-03-17 16:27 . 2011-12-02 08:19 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2012-02-23 16:23 123536 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDCPL"="RTHDCPL.EXE" [2006-05-18 16207872] "SkyTel"="SkyTel.EXE" [2006-05-16 2879488] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-09-27 86016] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-27 13918208] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-02-23 4031368] "SearchSettings"="c:\program files\Common Files\Spigot\Search Settings\SearchSettings.exe" [2012-03-04 934752] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "Malwarebytes Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\xampp\\apache\\bin\\httpd.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= "c:\\Server\\hlds.exe"= "c:\\Program Files\\TeamViewer\\Version6\\TeamViewer.exe"= "c:\\Program Files\\TeamViewer\\Version6\\TeamViewer_Service.exe"= "c:\\xampp\\mysql\\bin\\mysqld.exe"= "c:\\xampp\\FileZillaFTP\\FileZilla Server.exe"= "c:\\Documents and Settings\\Krasimir\\My Documents\\Downloads\\Server2\\hlds.exe"= "e:\\Steam\\UndeadPatch333.exe"= "e:\\Server\\hlds.exe"= "c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"= "c:\\Program Files\\Valve\\hl.exe"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "2078:TCP"= 2078:TCP:SSL "2077:TCP"= 2077:TCP:SSL "2078:UDP"= 2078:UDP:ssl "2077:UDP"= 2077:UDP:ssl . R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [26.11.2011 г. 21:45 691696] R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [21.11.2011 г. 22:28 610648] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [21.11.2011 г. 22:28 337112] R2 Apache2.2;Apache2.2;c:\xampp\apache\bin\httpd.exe [10.9.2011 г. 12:43 18432] R2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [04.3.2012 г. 23:40 748440] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [21.11.2011 г. 22:28 20696] R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [21.11.2011 г. 21:29 57248] S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\Krasimir\LOCALS~1\Temp\UNC31E.tmp --> c:\docume~1\Krasimir\LOCALS~1\Temp\UNC31E.tmp [?] S3 GGSAFERDriver;GGSAFER Driver;\??\c:\program files\Garena\safedrv.sys --> c:\program files\Garena\safedrv.sys [?] . Contents of the 'Scheduled Tasks' folder . 2012-04-01 c:\windows\Tasks\WGASetup.job - c:\windows\system32\KB905474\wgasetup.exe [2011-11-23 20:18] . . ------- Supplementary Scan ------- . IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 IE: Search the Web - c:\program files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html TCP: DhcpNameServer = 88.80.96.4 88.80.96.7 FF - ProfilePath - c:\documents and settings\Krasimir\Application Data\Mozilla\Firefox\Profiles\g6d3jk0y.default\ FF - prefs.js: browser.search.selectedEngine - Yahoo FF - prefs.js: browser.startup.homepage - hxxps://www.google.bg/ FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=937811&p= . - - - - ORPHANS REMOVED - - - - . WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file) . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2012-04-01 15:51 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . [HKEY_LOCAL_MACHINE\System\ControlSet002\Services\GarenaPEngine] "ImagePath"="\??\c:\docume~1\Krasimir\LOCALS~1\Temp\UNC31E.tmp" . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'explorer.exe'(476) c:\windows\system32\WININET.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\wpdshserviceobj.dll c:\windows\system32\portabledevicetypes.dll c:\windows\system32\portabledeviceapi.dll . Completion time: 2012-04-01 15:52:52 ComboFix-quarantined-files.txt 2012-04-01 12:52 . Pre-Run: 11 743 092 736 bytes free Post-Run: 11 888 967 680 bytes free . WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot Loader] timeout=2 Default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [Operating Systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons UnsupportedDebug="do not select this" /debug multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect . - - End Of File - - 87CA4AC15B2614CC53264EE3FB39C5E8

  • Отворете notepad и с copy/paste въведете следната информация:

    Folder::
    c:documents and settingsKrasimirApplication DataSearch Settings
    c:program filesCommon FilesSpigot
    
    Registry::
    [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
    "SearchSettings"=-
    
    DDS::
    IE: Search the Web - c:program filesSweetIMToolbarsInternet Explorerresourcesmenuext.html
  • Запазете файла с име CFScript и го провлачете и пуснете в Combofix (както е показано на картинката отдолу).

    Публикувано изображение

  • По време на сканиране от страна на ComboFix не стартирайте никакви други приложения, не натискайте клавиши от клавиатурата и не местете мишката !
  • Публикувайте лог файла, който ще се създаде след рестарта на компютъра в следващия си пост.
  • Автор

Windows-а не се рестартира след приключване на Combo fix,а направо ми изкара log файла:

ComboFix 12-03-31.03 - Krasimir 04.2012 г. 16:16:03.2.1 - x86

Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.1535.790 [GMT 3:00]

Running from: c:\documents and settings\Krasimir\My Documents\Downloads\ComboFix.exe

Command switches used :: c:\documents and settings\Krasimir\My Documents\Downloads\CFScript.txt

AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\documents and settings\Krasimir\Application Data\Search Settings

c:\program files\Common Files\Spigot

c:\program files\Common Files\Spigot\Search Settings\baidu_ff.xml

c:\program files\Common Files\Spigot\Search Settings\baidu_ie.xml

c:\program files\Common Files\Spigot\Search Settings\config.ini

c:\program files\Common Files\Spigot\Search Settings\Lang\res1031.ini

c:\program files\Common Files\Spigot\Search Settings\Lang\res1033.ini

c:\program files\Common Files\Spigot\Search Settings\Lang\res1034.ini

c:\program files\Common Files\Spigot\Search Settings\Lang\res1036.ini

c:\program files\Common Files\Spigot\Search Settings\Lang\res1040.ini

c:\program files\Common Files\Spigot\Search Settings\SearchSettings.exe

c:\program files\Common Files\Spigot\Search Settings\wth.dll

c:\program files\Common Files\Spigot\Search Settings\yahoo_ff.xml

c:\program files\Common Files\Spigot\Search Settings\yahoo_ie.xml

c:\program files\Common Files\Spigot\Search Settings\yandex_ff.xml

c:\program files\Common Files\Spigot\Search Settings\yandex_ie.xml

c:\program files\Common Files\Spigot\wtxpcom\chrome.manifest

c:\program files\Common Files\Spigot\wtxpcom\components\chrome.manifest

c:\program files\Common Files\Spigot\wtxpcom\components\IFBHOHelperWidgiToolbar.xpt

c:\program files\Common Files\Spigot\wtxpcom\components\IFBHOWidgiToolbar.xpt

c:\program files\Common Files\Spigot\wtxpcom\components\install.rdf

c:\program files\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll

c:\program files\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.10

c:\program files\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.11

c:\program files\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.12

c:\program files\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.5

c:\program files\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.6

c:\program files\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.7

c:\program files\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.8

c:\program files\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.9

c:\program files\Common Files\Spigot\wtxpcom\install.rdf

.

.

((((((((((((((((((((((((( Files Created from 2012-03-01 to 2012-04-01 )))))))))))))))))))))))))))))))

.

.

2012-04-01 11:46 . 2012-04-01 11:46 -------- d-----w- c:\documents and settings\Krasimir\Application Data\Malwarebytes

2012-04-01 11:45 . 2012-04-01 11:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2012-04-01 11:45 . 2012-04-01 11:45 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2012-04-01 11:45 . 2011-12-10 12:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-03-31 16:53 . 2012-03-31 16:56 -------- d-----w- C:\xampp

2012-03-20 15:31 . 2012-03-20 15:38 -------- d-----w- c:\program files\Valve

2012-03-20 15:30 . 2003-09-03 00:28 724992 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iKernel.dll

2012-03-20 15:30 . 2003-09-03 00:27 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\ctor.dll

2012-03-20 15:30 . 2003-09-03 00:26 266240 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iscript.dll

2012-03-20 15:30 . 2003-09-03 00:26 192512 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iuser.dll

2012-03-20 15:30 . 2003-09-03 00:25 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\DotNetInstaller.exe

2012-03-20 15:30 . 2012-03-20 15:30 311428 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\Setup.dll

2012-03-20 15:30 . 2012-03-20 15:30 184452 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iGdi.dll

2012-03-17 16:27 . 2012-03-17 16:27 592824 ----a-w- c:\program files\Mozilla Firefox\gkmedias.dll

2012-03-17 16:27 . 2012-03-17 16:27 44472 ----a-w- c:\program files\Mozilla Firefox\mozglue.dll

2012-03-15 17:48 . 2012-03-15 17:48 -------- d-----w- c:\program files\Application Updater

2012-03-15 17:48 . 2012-03-15 17:48 -------- d-----w- c:\program files\YouTube Downloader Toolbar

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-02-23 16:23 . 2011-11-21 19:27 41184 ----a-w- c:\windows\avastSS.scr

2012-02-23 16:23 . 2011-11-21 19:27 201352 ----a-w- c:\windows\system32\aswBoot.exe

2012-02-23 16:12 . 2011-11-21 19:28 610648 ----a-w- c:\windows\system32\drivers\aswSnx.sys

2012-02-23 16:12 . 2011-11-21 19:28 337112 ----a-w- c:\windows\system32\drivers\aswSP.sys

2012-02-23 16:10 . 2011-11-21 19:28 35672 ----a-w- c:\windows\system32\drivers\aswRdr.sys

2012-02-23 16:10 . 2011-11-21 19:28 53848 ----a-w- c:\windows\system32\drivers\aswTdi.sys

2012-02-23 16:10 . 2011-11-21 19:28 95704 ----a-w- c:\windows\system32\drivers\aswmon2.sys

2012-02-23 16:10 . 2011-11-21 19:28 89048 ----a-w- c:\windows\system32\drivers\aswmon.sys

2012-02-23 16:10 . 2011-11-21 19:28 20696 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys

2012-02-23 16:07 . 2011-11-21 19:28 24920 ----a-w- c:\windows\system32\drivers\aavmker4.sys

2012-02-20 11:45 . 2011-11-21 19:36 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2012-02-03 09:26 . 2008-11-05 14:19 1869184 ----a-w- c:\windows\system32\win32k.sys

2012-01-11 19:06 . 2012-02-16 10:18 3072 ------w- c:\windows\system32\iacenc.dll

2012-01-09 16:20 . 2011-11-21 17:56 139784 ----a-w- c:\windows\system32\drivers\rdpwd.sys

2012-03-17 16:27 . 2011-12-02 08:19 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]

@="{472083B0-C522-11CF-8763-00608CC02F24}"

[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]

2012-02-23 16:23 123536 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"RTHDCPL"="RTHDCPL.EXE" [2006-05-18 16207872]

"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-09-27 86016]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-27 13918208]

"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-02-23 4031368]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

"Malwarebytes Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872]

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\uTorrent\\uTorrent.exe"=

"c:\\xampp\\apache\\bin\\httpd.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

"c:\\Server\\hlds.exe"=

"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer.exe"=

"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer_Service.exe"=

"c:\\xampp\\mysql\\bin\\mysqld.exe"=

"c:\\xampp\\FileZillaFTP\\FileZilla Server.exe"=

"c:\\Documents and Settings\\Krasimir\\My Documents\\Downloads\\Server2\\hlds.exe"=

"e:\\Steam\\UndeadPatch333.exe"=

"e:\\Server\\hlds.exe"=

"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=

"c:\\Program Files\\Valve\\hl.exe"=

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"2078:TCP"= 2078:TCP:SSL

"2077:TCP"= 2077:TCP:SSL

"2078:UDP"= 2078:UDP:ssl

"2077:UDP"= 2077:UDP:ssl

.

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [26.11.2011 г. 21:45 691696]

R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [21.11.2011 г. 22:28 610648]

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [21.11.2011 г. 22:28 337112]

R2 Apache2.2;Apache2.2;c:\xampp\apache\bin\httpd.exe [10.9.2011 г. 12:43 18432]

R2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [04.3.2012 г. 23:40 748440]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [21.11.2011 г. 22:28 20696]

R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [21.11.2011 г. 21:29 57248]

S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\Krasimir\LOCALS~1\Temp\UNC31E.tmp --> c:\docume~1\Krasimir\LOCALS~1\Temp\UNC31E.tmp [?]

S3 GGSAFERDriver;GGSAFER Driver;\??\c:\program files\Garena\safedrv.sys --> c:\program files\Garena\safedrv.sys [?]

.

Contents of the 'Scheduled Tasks' folder

.

2012-04-01 c:\windows\Tasks\WGASetup.job

- c:\windows\system32\KB905474\wgasetup.exe [2011-11-23 20:18]

.

.

------- Supplementary Scan -------

.

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

TCP: DhcpNameServer = 88.80.96.4 88.80.96.7

FF - ProfilePath - c:\documents and settings\Krasimir\Application Data\Mozilla\Firefox\Profiles\g6d3jk0y.default\

FF - prefs.js: browser.search.selectedEngine - Yahoo

FF - prefs.js: browser.startup.homepage - hxxps://www.google.bg/

FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=937811&p=

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2012-04-01 16:21

Windows 5.1.2600 Service Pack 3 NTFS

.

scanning hidden processes ...

.

scanning hidden autostart entries ...

.

scanning hidden files ...

.

scan completed successfully

hidden files: 0

.

**************************************************************************

.

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\GarenaPEngine]

"ImagePath"="\??\c:\docume~1\Krasimir\LOCALS~1\Temp\UNC31E.tmp"

.

Completion time: 2012-04-01 16:22:22

ComboFix-quarantined-files.txt 2012-04-01 13:22

ComboFix2.txt 2012-04-01 12:52

.

Pre-Run: 11 897 057 280 bytes free

Post-Run: 11 879 026 688 bytes free

.

- - End Of File - - 073DAD0567F5AC5E5A6D9B5AB2C6C0F3

  • Автор

Обновете и направете пълно сканиране на системата с Avast. Как е положенито?

Изчезна ми Language бара и не се показва.В смисъл сменям си пак езиците с клавишна комбинация,но не се показва langugage бара.Махнах отметката и я сложих пак,но пак не се показва.

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.