Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Атака от хакер - как да го спрем

Featured Replies

Здравейте! Имам следния проблем: Компютъра на моя позната е атакуван от хакер от няколко дни насам! Предполагам, че е хлапе защото влиза след обяд - мести иконки, отваря и текстови файлове в които и пише съобщения. Интернет се ползва от лан мрежа, не ползва рутер. Операционната и система е XР, антивирусната програма е аваста. Проблема е, че компютара се ползва освен за домашен и за счетоводство и съдържа данни на фирми и лични данни. Въпросът ми е как да спрем атаките на хакера, и възможно ли е да го засечем кой е, примерно IP-то му - второто не е чак толкоз важно, по-важното как да го спрем - за сега видими поразии не е направил! Благодаря предварително!

Здравейте!

Имам следния проблем: Компютъра на моя позната е атакуван от хакер от няколко дни насам! Предполагам, че е хлапе защото влиза след обяд - мести иконки, отваря и текстови файлове в които и пише съобщения. Интернет се ползва от лан мрежа, не ползва рутер. Операционната и система е XР, антивирусната програма е аваста. Проблема е, че компютара се ползва освен за домашен и за счетоводство и съдържа данни на фирми и лични данни.

Въпросът ми е как да спрем атаките на хакера, и възможно ли е да го засечем кой е, примерно IP-то му - второто не е чак толкоз важно, по-важното как да го спрем - за сега видими поразии не е направил!

Благодаря предварително!

Като начало пълен ъпдейт на ОС, инсталиране на защитна стена, сериозна проверка за малуер
  • Автор

Ок благодаря за отговора. Ще ъпдейтвам ОС. Ако може да ми препоръчате защитна стена - доколкото знам тя ползва стената на авастата, но явно е минал през нея.

Кажете параметрите на компютъра.Предполагам десктоп.Да видим колко е бърз?И ако ще се прави проверка за вредоносен софтуер изпълнете инструкциите от най-горната тема в този раздел.

http://www.kaldata.com/forums/index.php?showtopic=132819

Редактирано от AleXxX&Vanko (преглед на промените)

  • Автор

В момента не мога да ги дам параметрите, пиша от собствения си комп, а не знам параметрите на атакувания компютър. След обяд ще отида до тях и ще ги напиша. Ще пусна и скрипта който сте посочили.

Огледай за инсталирани съмнителни програми.

  • Автор

Вече съм на заразения компютър. Компютъра е: AMD Sempron 2500+ 1.7 GHz, 1 Gb RAm XP profesional версия 2002 - сървис пак 2

Вече съм на заразения компютър.

Компютъра е:

AMD Sempron 2500+

1.7 GHz, 1 Gb RAm

XP profesional версия 2002 - сървис пак 2

ако версията е легална веднага инсталирайте SP3!!!

Сканирайте компютъра с Аваст с предстартова проверка и му укажете да проверява архиви ,системни файлове (за Аваст4 или 5)и да мести всичко намерено в клетка.

  • Автор

ДДС файл: DDS (Ver_2011-09-30.01) - NTFS_x86 Internet Explorer: 8.0.6001.18702 Run by Administrator at 14:28:23 on 2012-03-06 Microsoft Windows XP Professional 5.1.2600.2.1251. 359.1033.18.1023.368 [GMT 2:00] . AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D} . ============== Running Processes ================ . C:\WINDOWS\Explorer.EXE C:\Program Files\Alwil Software\Avast5\AvastSvc.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\VMSnap23.exe C:\WINDOWS\Domino.exe C:\Program Files\Unlocker\UnlockerAssistant.exe C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\CNAP2LAK.EXE C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\WINDOWS\System32\SCardSvr.exe C:\Program Files\cv cryptovision\cv act sc interface\RegisterTool.exe C:\Program Files\charismathics\smart security interface 4.51\CSPregtool.exe C:\Program Files\VIA\RAID\raid_tool.exe C:\WINDOWS\system32\ntvdm.exe C:\WINDOWS\system32\ntvdm.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\CNAP2RPK.EXE C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\CNAB8SWK.EXE C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\wdfmgr.exe C:\WINDOWS\System32\alg.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\svchost.exe -k imgsvc . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ uInternet Connection Wizard,ShellNext = iexplore BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - <orphaned> BHO: Adobe PDF Reader Link Helper: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre6\bin\ssv.dll BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\alwil software\avast5\aswWebRepIE.dll BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:\program files\google\googletoolbarnotifier\5.7.7227.1100\swg.dll BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: Easy-WebPrint: {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - c:\program files\canon\easy-webprint\Toolband.dll TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\alwil software\avast5\aswWebRepIE.dll TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" mRun: [soundMan] SOUNDMAN.EXE mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe mRun: [bigDogPath323VMSnap] c:\windows\VMSnap23.exe mRun: [bigDogPath323Domino] c:\windows\Domino.exe mRun: [unlockerAssistant] "c:\program files\unlocker\UnlockerAssistant.exe" mRun: [OpwareSE2] "c:\program files\scansoft\omnipagese2.0\OpwareSE2.exe" mRun: [CNAP2 Launcher] c:\windows\system32\spool\drivers\w32x86\3\CNAP2LAK.EXE mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui mRun: [KernelFaultCheck] c:\windows\system32\dumprep 0 -k mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [sunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE dRunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\microi~1.lnk - d:\micro\ARCHI.EXE StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\microi~3.lnk - d:\micro\MST_UTIL.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\cvacts~1.lnk - c:\program files\cv cryptovision\cv act sc interface\RegisterTool.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\smarts~1.lnk - c:\program files\charismathics\smart security interface 4.51\CSPregtool.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\viarai~1.lnk - c:\program files\via\raid\raid_tool.exe uPolicies-Explorer: NoDriveTypeAutoRun = dword:145 mPolicies-System: EnableLUA = dword:0 mPolicies-Explorer: NoDriveTypeAutoRun = dword:145 IE: Easy-WebPrint Add To Print List - c:\program files\canon\easy-webprint\Resource.dll/RC_AddToList.html IE: Easy-WebPrint High Speed Print - c:\program files\canon\easy-webprint\Resource.dll/RC_HSPrint.html IE: Easy-WebPrint Preview - c:\program files\canon\easy-webprint\Resource.dll/RC_Preview.html IE: Easy-WebPrint Print - c:\program files\canon\easy-webprint\Resource.dll/RC_Print.html IE: Save Page As PDF ... - c:\program files\nitro pdf\pdf download\nitroweb.htm IE: Е&кспортирай в Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} IE: {96538116-AB8C-4879-9F21-BD2BFE22A414} - {DC6169B9-3397-4D01-8639-07F1A34BAF99} - <orphaned> IE: {AD9E6088-E00B-42f9-9F0C-8480525D234E} - {FF5073C0-28A0-4223-9BDF-59FF020FE77C} - <orphaned> IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {167248DA-0F88-4DE1-B4B1-45176751026D} - hxxps://aixbs.b-trust.org/wl-dl/bs/client_test2/js/renew/CertManX.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204 DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab DPF: {4DB62416-BC86-4439-B5BA-366948F47C8D} - hxxp://bs.b-trust.org/wl-dl/bs/js/sign/SCManagerX.cab DPF: {500A3316-5B0E-4253-BBE5-CE3F11A1AE71} - hxxps://inetdec.nra.bg/dds/InetVAT5Frm.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {97EA2A5E-A821-48A1-B0F9-DEDB5E0E62A2} - hxxps://inetdec.nra.bg/cabs/SignCOM.cab DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab TCP: Interfaces\{8227C0C2-5DC4-4324-8867-D61E4888BF79} : NameServer = 192.168.101.1 TCP: Interfaces\{CAA33A0C-E919-4715-8A10-603791FEB24E} : NameServer = 192.168.1.1 Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll . ============= SERVICES / DRIVERS =============== . R0 viasraid;viasraid;c:\windows\system32\drivers\viasraid.sys [2009-2-11 75904] R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-7-8 610648] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2009-10-17 337112] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-10-17 20696] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-6-19 44768] S2 gupdate1ca02145dd4da34;Услуга Google Update (gupdate1ca02145dd4da34);c:\program files\google\update\GoogleUpdate.exe [2009-7-11 133104] S2 SSPORT;SSPORT;\??\c:\windows\system32\drivers\ssport.sys --> c:\windows\system32\drivers\SSPORT.sys [?] S3 A38CCID;CCID USB Smart Card Reader;c:\windows\system32\drivers\a38ccid.sys [2009-12-16 38016] S3 gupdatem;Услуга на Google Актуализация (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-7-11 133104] S3 vmfilter323;323 filter service, Normal;c:\windows\system32\drivers\vmfilter323.sys [2009-2-13 420480] S3 ZSMC326;Vimicro USB2.0 PC Camera(VC0323);c:\windows\system32\drivers\usbvm323.sys [2009-2-13 260608] . =============== File Associations =============== . ShellExec: PDF Suite.exe: open="c:\program files\pdf suite 2010\PDF Suite.exe""%1" . =============== Created Last 30 ================ . 2012-03-02 07:54:26 73728 ----a-w- c:\windows\system32\javacpl.cpl . ==================== Find3M ==================== . 2012-03-02 07:54:12 472808 ----a-w- c:\windows\system32\deployJava1.dll 2012-02-23 16:23:26 41184 ----a-w- c:\windows\avastSS.scr 2012-02-23 16:12:28 610648 ----a-w- c:\windows\system32\drivers\aswSnx.sys . ============= FINISH: 14:28:49.96 =============== Attac.TXT . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-09-30.01) . Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 11.02.2009 18:39:00 System Uptime: 06.03.2012 14:06:04 (0 hours ago) . Motherboard: Gigabyte Technology Co., Ltd. | | 7VT600-P-RZ Processor: AMD Sempron 2500+ | Socket A | 1752/167mhz . ==== Disk Partitions ========================= . A: is Removable C: is FIXED (NTFS) - 20 GiB total, 8.816 GiB free. D: is FIXED (NTFS) - 92 GiB total, 78.346 GiB free. E: is CDROM () . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP595: 18.02.2012 10:13:54 - Контролна точка на системата RP596: 19.02.2012 10:56:55 - Контролна точка на системата RP597: 20.02.2012 12:05:52 - Контролна точка на системата RP598: 21.02.2012 15:34:42 - Контролна точка на системата RP599: 23.02.2012 11:38:44 - Контролна точка на системата RP600: 27.02.2012 16:21:34 - Контролна точка на системата RP601: 29.02.2012 13:11:05 - Контролна точка на системата RP602: 01.03.2012 14:07:52 - Контролна точка на системата RP603: 02.03.2012 09:53:46 - Removed Java 6 Update 23 RP604: 02.03.2012 09:54:03 - Installed Java 6 Update 31 RP605: 03.03.2012 11:41:23 - Контролна точка на системата RP606: 04.03.2012 21:13:37 - Контролна точка на системата . ==== Installed Programs ====================== . Декларация Обр.1 и 6 Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 8.3.1 Adobe Shockwave Player 11.6 ArcSoft PhotoStudio 5.5 avast! Free Antivirus BitComet 0.54 BSPlayer Canon LBP3010/LBP3018/LBP3050 Canon MP Drivers 7.0 Canon MP Navigator 1.1 Canon ScanGear Starter Canon Utilities Easy-PhotoPrint CANYON USB PC Camera Click to Call with Skype CSSI 4.51 REYCON - user edition cv act sc/interface 5.0.0 - user edition DSTool v1.5.1 (remove only) Easy-WebPrint Enable S3 for USB Device Google Chrome Google Toolbar for Internet Explorer Google Update Helper Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB976002-v5) Hotfix for Windows XP (KB981793) Java Auto Updater Java 6 Update 31 K-Lite Codec Pack 2.54 Full Malwarebytes' Anti-Malware Microinvest Офис Пакет със златен медал Microsoft Office Professional Edition 2003 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Nero 6 Enterprise Edition OmniPage SE 2.0 Opera 11.50 Realtek AC'97 Audio SA Dictionary 2008 Beta 4 Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB976325) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player (KB979402) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB944338-v2) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958215) Security Update for Windows XP (KB958470) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960714) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971032) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Skype™ 5.5 swMSM Unlocker 1.8.7 Update for Windows Internet Explorer 8 (KB975364) Update for Windows Internet Explorer 8 (KB976662) Update for Windows XP (KB898461) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) VIA Integrated Setup Wizard VIA Rhine-Family Fast Ethernet Adapter WebFldrs XP Winamp Windows Bulgarian Interface Pack Windows Genuine Advantage Notifications (KB905474) Windows Installer 3.1 (KB893803) Windows Internet Explorer 8 Windows Media Format Runtime WinRAR archiver . ==== Event Viewer Messages From Past Week ======== . 29.02.2012 09:44:47, error: Service Control Manager [7000] - The SSPORT service failed to start due to the following error: The system cannot find the file specified. 29.02.2012 09:44:47, error: Service Control Manager [7000] - The DgiVecp service failed to start due to the following error: The system cannot find the file specified. 05.03.2012 15:25:23, error: SCardSvr [610] - Smart Card Reader 'ACS CCID USB Reader 0' rejected IOCTL GET_STATE: The device has been removed. 05.03.2012 15:22:10, error: SCardSvr [610] - Smart Card Reader 'ACS CCID USB Reader 0' rejected IOCTL 0x313520: Incorrect function. 05.03.2012 15:22:10, error: A38CCID [0] - 04.03.2012 18:19:47, error: viasraid [9] - The device, \Device\Scsi\viasraid1, did not respond within the timeout period. 01.03.2012 21:03:38, error: MRxSmb [8003] - The master browser has received a server announcement from the computer HOME-F018981632 that believes that it is the master browser for the domain on transport NetBT_Tcpip_{8227C0C2-5DC. The master browser is stopping or an election is being forced. . ==== End Of File =========================== attach.txt . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-09-30.01) . Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 11.02.2009 18:39:00 System Uptime: 06.03.2012 14:06:04 (0 hours ago) . Motherboard: Gigabyte Technology Co., Ltd. | | 7VT600-P-RZ Processor: AMD Sempron 2500+ | Socket A | 1752/167mhz . ==== Disk Partitions ========================= . A: is Removable C: is FIXED (NTFS) - 20 GiB total, 8.816 GiB free. D: is FIXED (NTFS) - 92 GiB total, 78.346 GiB free. E: is CDROM () . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP595: 18.02.2012 10:13:54 - Контролна точка на системата RP596: 19.02.2012 10:56:55 - Контролна точка на системата RP597: 20.02.2012 12:05:52 - Контролна точка на системата RP598: 21.02.2012 15:34:42 - Контролна точка на системата RP599: 23.02.2012 11:38:44 - Контролна точка на системата RP600: 27.02.2012 16:21:34 - Контролна точка на системата RP601: 29.02.2012 13:11:05 - Контролна точка на системата RP602: 01.03.2012 14:07:52 - Контролна точка на системата RP603: 02.03.2012 09:53:46 - Removed Java 6 Update 23 RP604: 02.03.2012 09:54:03 - Installed Java 6 Update 31 RP605: 03.03.2012 11:41:23 - Контролна точка на системата RP606: 04.03.2012 21:13:37 - Контролна точка на системата . ==== Installed Programs ====================== . Декларация Обр.1 и 6 Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 8.3.1 Adobe Shockwave Player 11.6 ArcSoft PhotoStudio 5.5 avast! Free Antivirus BitComet 0.54 BSPlayer Canon LBP3010/LBP3018/LBP3050 Canon MP Drivers 7.0 Canon MP Navigator 1.1 Canon ScanGear Starter Canon Utilities Easy-PhotoPrint CANYON USB PC Camera Click to Call with Skype CSSI 4.51 REYCON - user edition cv act sc/interface 5.0.0 - user edition DSTool v1.5.1 (remove only) Easy-WebPrint Enable S3 for USB Device Google Chrome Google Toolbar for Internet Explorer Google Update Helper Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB976002-v5) Hotfix for Windows XP (KB981793) Java Auto Updater Java 6 Update 31 K-Lite Codec Pack 2.54 Full Malwarebytes' Anti-Malware Microinvest Офис Пакет със златен медал Microsoft Office Professional Edition 2003 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Nero 6 Enterprise Edition OmniPage SE 2.0 Opera 11.50 Realtek AC'97 Audio SA Dictionary 2008 Beta 4 Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB976325) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player (KB979402) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB944338-v2) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958215) Security Update for Windows XP (KB958470) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960714) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971032) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Skype™ 5.5 swMSM Unlocker 1.8.7 Update for Windows Internet Explorer 8 (KB975364) Update for Windows Internet Explorer 8 (KB976662) Update for Windows XP (KB898461) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) VIA Integrated Setup Wizard VIA Rhine-Family Fast Ethernet Adapter WebFldrs XP Winamp Windows Bulgarian Interface Pack Windows Genuine Advantage Notifications (KB905474) Windows Installer 3.1 (KB893803) Windows Internet Explorer 8 Windows Media Format Runtime WinRAR archiver . ==== Event Viewer Messages From Past Week ======== . 29.02.2012 09:44:47, error: Service Control Manager [7000] - The SSPORT service failed to start due to the following error: The system cannot find the file specified. 29.02.2012 09:44:47, error: Service Control Manager [7000] - The DgiVecp service failed to start due to the following error: The system cannot find the file specified. 05.03.2012 15:25:23, error: SCardSvr [610] - Smart Card Reader 'ACS CCID USB Reader 0' rejected IOCTL GET_STATE: The device has been removed. 05.03.2012 15:22:10, error: SCardSvr [610] - Smart Card Reader 'ACS CCID USB Reader 0' rejected IOCTL 0x313520: Incorrect function. 05.03.2012 15:22:10, error: A38CCID [0] - 04.03.2012 18:19:47, error: viasraid [9] - The device, \Device\Scsi\viasraid1, did not respond within the timeout period. 01.03.2012 21:03:38, error: MRxSmb [8003] - The master browser has received a server announcement from the computer HOME-F018981632 that believes that it is the master browser for the domain on transport NetBT_Tcpip_{8227C0C2-5DC. The master browser is stopping or an election is being forced. . ==== End Of File =========================== Пуснал съм антивирусната!

  • Автор

Ми така беше по инструкция! След сканирането ще сложа сървис пак 3.

Ми така беше по инструкция! След сканирането ще сложа сървис пак 3.

Изчакайте инструкции от колегите!!!

До всички участници в дискусията: Моля прочетете правилата на раздела в който е темата и ги спазвайте!!!

  • Автор

Момчета и момичета, проблема се оказа по-серьозен от колкото го мислех! Хакера ми спира антивирусната програма, ако опитам да пусна форума Ви - пак ми го гаси! Ако упоствам ми гаси компа. Друго ако опитвам няма проблем. Сега Ви пиша от моя комп. Донесъл съм и другия компютър, но не знам ако го пусна през моето IР - дали ще го намерят пак. Чакам инструкции - не съм се сбъсквал с такъв проблем, не съм и аз толкоз на ти с компютрите, и аз съм счетоводител. Не знам какво да мисля - не съм виждал подобно нещо.

Слушай capnemo и изчакай изструкции как да си почистиш системата от вируси и malware. Ако ти се прави нещо докато чакаш за инструкции, може да си инстлираш в Save Mode един Malwarebyte и направиш проверка с него.

  • Автор

Ще го направя - но понеже съм донесъл другия компютър без монитор и . т.н. ще изключа тоз - за да включа другия. Другия за сега няма да го включвам в нета.

1. Изтеглете ComboFix от BleepingComputer

и го запазете (бутон Save -> Save as) ComboFix на вашия десктоп:

Публикувано изображение

След приключване на изтеглянето на ComboFix, иконката на програмата би трябвало да изглежда така:

Публикувано изображение

2. Затворете всички работещи приложения, отворени прозорци и програми работещи във фонов режим. Спрете временно защитата в реално време на антивирусната програма и на другите програми за сигурност, ако има такива.

3. Стартирайте с двоен клик Combofix.exe. Изберете YES, за да се съгласите с условията за използване на програмата. Важно: По време на работата на ComboFix не бива да се движи мишката и да се натискат клавиши от клавиатурата. Просто търпеливо оставете ComboFix да си свърши работата, без да използвате компютъра за други цели.

4. ComboFix ще провери дали Windows Recovery Console e инсталиранa.

*Ако Windows Recovery Console не е инсталирана, ще е необходимо да използвате YES за инсталация на Windows Recovery Console

*Ако Windows Recovery Console е инсталирана, ComboFix ще продължи работата си.

Публикувано изображение

Забележка: Необходимо е да сте свързани към Интернет за да може Windows Recovery Console да се изтегли.

След инсталация на Windows Recovery Console потвърдете с YES, за да продължите напред. Снимка:

Публикувано изображение

5. ComboFix ще спре временно Интернет връзката, но след като приключи работата на програмата тази връзка ще бъде възстановена автоматично. ComboFix ще сканира за проблеми и за заразени файлове, като това може да отнеме известно време. Моля да бъдете търпеливи. Ако има проблем с Интернет връзката след приключване на работата на Combofix, моля да прочетете това: Manually restoring the Internet connection section.

6. Когато работата на ComboFix приключи, ще се появи текстов документ (log) в Notepad:

Публикувано изображение

Копирайте с (Copy) и поставете с (Paste) съдържанието на лога в следващия си коментар.

  • Автор

ComboFix 12-03-04.02 - Administrator 06.03.2012 19:10:20.1.1 - x86 Microsoft Windows XP Professional 5.1.2600.2.1251. 359.1033.18.1023.413 [GMT 2:00] Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\documents and settings\Administrator\Application Data\Desktopicon c:\documents and settings\Administrator\Application Data\Desktopicon\config.ini c:\documents and settings\Administrator\WINDOWS c:\documents and settings\All Users\Application Data\TEMP c:\windows\EventSystem.log . . ((((((((((((((((((((((((( Files Created from 2012-02-06 to 2012-03-06 ))))))))))))))))))))))))))))))) . . 2012-03-02 07:54 . 2012-03-02 07:54 -------- d-----w- c:\program files\Common Files\Java 2012-03-02 07:54 . 2012-03-02 07:54 73728 ----a-w- c:\windows\system32\javacpl.cpl 2012-03-02 07:54 . 2012-03-02 07:54 -------- d-----w- c:\program files\Java 2012-02-08 06:56 . 2012-02-08 06:56 -------- d-----w- c:\windows\Sun . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-03-02 07:54 . 2011-08-08 15:35 472808 ----a-w- c:\windows\system32\deployJava1.dll 2012-02-23 16:23 . 2010-07-12 16:11 41184 ----a-w- c:\windows\avastSS.scr 2012-02-23 16:23 . 2009-10-17 11:51 201352 ----a-w- c:\windows\system32\aswBoot.exe 2012-02-23 16:12 . 2011-07-08 17:40 610648 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2012-02-23 16:12 . 2009-10-17 11:51 337112 ----a-w- c:\windows\system32\drivers\aswSP.sys 2012-02-23 16:10 . 2009-10-17 11:51 35672 ----a-w- c:\windows\system32\drivers\aswRdr.sys 2012-02-23 16:10 . 2009-10-17 11:51 53848 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2012-02-23 16:10 . 2009-10-17 11:51 95704 ----a-w- c:\windows\system32\drivers\aswmon2.sys 2012-02-23 16:10 . 2009-10-17 11:51 89048 ----a-w- c:\windows\system32\drivers\aswmon.sys 2012-02-23 16:10 . 2009-10-17 11:51 20696 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2012-02-23 16:07 . 2009-10-17 11:51 24920 ----a-w- c:\windows\system32\drivers\aavmker4.sys . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2012-02-23 16:23 123536 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-07-29 17361032] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-08-21 39408] "BrowserChoice"="c:\windows\system32\browserchoice.exe" [2010-02-12 293376] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SoundMan"="SOUNDMAN.EXE" [2004-01-08 65536] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "BigDogPath323VMSnap"="c:\windows\VMSnap23.exe" [2007-06-29 212992] "BigDogPath323Domino"="c:\windows\Domino.exe" [2007-06-29 49152] "UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2008-05-02 15872] "OpwareSE2"="c:\program files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152] "CNAP2 Launcher"="c:\windows\System32\spool\DRIVERS\W32X86\3\CNAP2LAK.EXE" [2007-09-05 406944] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2011-08-31 40368] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-29 937920] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "nltide_3"="advpack.dll" [2009-03-08 128512] . c:\documents and settings\Administrator\Start Menu\Programs\Startup\ Microinvest Архиватор.lnk - d:\micro\ARCHI.EXE [2009-10-19 704313] Microinvest Мениджър.lnk - d:\micro\MST_UTIL.EXE [2009-10-19 274713] . c:\documents and settings\All Users\Start Menu\Programs\Startup\ cv act sc interface RegisterTool.lnk - c:\program files\cv cryptovision\cv act sc interface\RegisterTool.exe [2010-12-15 4527616] smart security registration status.lnk - c:\program files\charismathics\smart security interface 4.51\CSPregtool.exe [2008-1-24 4317184] VIA RAID TOOL.lnk - c:\program files\VIA\RAID\raid_tool.exe [2009-2-11 561152] . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\BitComet\\BitComet.exe"= "c:\\downloads\\kaspersky\\KIS7.0\\English\\setup.exe"= "c:\\Program Files\\Opera\\opera.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= . R0 viasraid;viasraid;c:\windows\system32\drivers\viasraid.sys [11.02.2009 20:18 75904] R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [08.07.2011 19:40 610648] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [17.10.2009 13:51 337112] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [17.10.2009 13:51 20696] S2 gupdate1ca02145dd4da34;Услуга Google Update (gupdate1ca02145dd4da34);c:\program files\Google\Update\GoogleUpdate.exe [11.07.2009 12:43 133104] S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys --> c:\windows\system32\Drivers\SSPORT.sys [?] S3 A38CCID;CCID USB Smart Card Reader;c:\windows\system32\drivers\a38ccid.sys [16.12.2009 06:37 38016] S3 gupdatem;Услуга на Google Актуализация (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [11.07.2009 12:43 133104] S3 vmfilter323;323 filter service, Normal;c:\windows\system32\drivers\vmfilter323.sys [13.02.2009 21:14 420480] S3 ZSMC326;Vimicro USB2.0 PC Camera(VC0323);c:\windows\system32\drivers\usbvm323.sys [13.02.2009 21:14 260608] . Contents of the 'Scheduled Tasks' folder . 2012-03-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-07-11 10:42] . 2012-03-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-07-11 10:42] . 2012-03-06 c:\windows\Tasks\WGASetup.job - c:\windows\system32\KB905474\wgasetup.exe [2011-01-13 20:18] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com/ uInternet Connection Wizard,ShellNext = iexplore IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html IE: Save Page As PDF ... - file://c:\program files\Nitro PDF\PDF Download\nitroweb.htm IE: Е&кспортирай в Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 TCP: DhcpNameServer = 10.10.0.1 77.76.144.129 TCP: Interfaces\{8227C0C2-5DC4-4324-8867-D61E4888BF79}: NameServer = 192.168.101.1 DPF: {167248DA-0F88-4DE1-B4B1-45176751026D} - hxxps://aixbs.b-trust.org/wl-dl/bs/client_test2/js/renew/CertManX.cab DPF: {4DB62416-BC86-4439-B5BA-366948F47C8D} - hxxp://bs.b-trust.org/wl-dl/bs/js/sign/SCManagerX.cab DPF: {500A3316-5B0E-4253-BBE5-CE3F11A1AE71} - hxxps://inetdec.nra.bg/dds/InetVAT5Frm.cab DPF: {97EA2A5E-A821-48A1-B0F9-DEDB5E0E62A2} - hxxps://inetdec.nra.bg/cabs/SignCOM.cab . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2012-03-06 19:16 Windows 5.1.2600 Service Pack 2 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . . C:\avast! sandbox . scan completed successfully hidden files: 1 . ************************************************************************** . Completion time: 2012-03-06 19:18:06 ComboFix-quarantined-files.txt 2012-03-06 17:17 . Pre-Run: 9 510 207 488 bytes free Post-Run: 10 541 928 448 bytes free . WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons UnsupportedDebug="do not select this" /debug multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect . - - End Of File - - B581E6B9EBA73D4B4D60B9B3AE6E5B64

Изтеглете AVZ 4.37 и разархивирайте програмата в папка на десктопа.

Стартирайте файла AVZ.exe

Отидете на File => Database update => натиснете Start

Когато ъпдейта приключи, натиснете OK.

Отидете до менюто AVZPM => натиснете Install Extended Monitoring Driver.

Рестартирайте компютъра.

Стартирайте отново AVZ.exe

Направете настройките от снимките:

Публикувано изображение

Публикувано изображение

Публикувано изображение

Натиснете бутона Start

Когато проверката завърши натиснете бутона, който изглежда като дискета.

Запазете лог файла на десктопа и го прикачете в следващия си коментар.

  • Автор

Благодаря на всички отзовали се. Ще продължа по всяка вероятност в четвъртък. До тогава няма да включвам заразения компютър, в четвъртак ще продължа по инсрукциите които ми давате. Моля да бъда извинен, все пак аз посках помощ. Пак благодаря, и извинявайте за прекъсването.

Редактирано от ruci_bo (преглед на промените)

  • Автор

Съжалявам, но загина приятел, утре ще го изпращаме и вече не ми е до това. Пак благодаря и държа да продължим започнатото, но за сега толкоз.

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.