Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Trojan horse generic 27.PN [РЕШЕН]

Featured Replies

Здравейте. Преди два часа преди да сеи изключ компютъра ми се появи разрешение за инстралриане на Adobe flas player май беше 12 или 13. След което AVG подлудя през минути да ми дава, че на C/Windows/System съм заразен с някакъв вирус Trojan horse generic 27.PN. С Malwarebytes Anti-Malware пробвам и нущо не открива. Постояно трия или слагам в Virus Vault. Може ли помощ. Със Windows 7 съм, ако това ви е в помощ. DDS: DDS (Ver_2011-09-30.01) - NTFS_x86 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_29 Run by Martin at 1:38:10 on 2012-03-12 Microsoft Windows 7 Ultimate 6.1.7601.1.1251.359.1033.18.2038.716 [GMT 2:00] . AV: AVG Internet Security 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} SP: AVG Internet Security 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes ================ . C:\PROGRA~1\AVG\AVG10\avgchsvx.exe C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Windows\system32\FsUsbExService.Exe C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\system32\igfxsrvc.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Samsung\Kies\KiesTrayAgent.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\AVG Secure Search\vprot.exe C:\Program Files\DAEMON Tools Lite\DTLite.exe C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe C:\Program Files\Samsung\Kies\KiesHelper.exe C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe C:\Program Files\Datecs\FlexType 2K\FType2K.exe C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe C:\Program Files\AVG\AVG10\avgnsx.exe C:\Program Files\AVG\AVG10\avgcsrvx.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\taskhost.exe C:\Program Files\Samsung\Kies\External\DeviceModules\DeviceManager.exe C:\Program Files\Samsung\Kies\External\DeviceModules\ConnectionManager.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\PROGRA~1\AVG\AVG10\avgrsx.exe C:\Program Files\AVG\AVG10\avgcsrvx.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\svchost.exe -k imgsvc . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.bg/ uWindow Title = Windows Internet Explorer се предоставя от bTV сериали uDefault_Page_URL = hxxp://www.btv.bg/welcome uProxyOverride = <local> uURLSearchHooks: {A3BC75A2-1F87-4686-AA43-5347D756017C} - <orphaned> uURLSearchHooks: BS Player Toolbar: {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - c:\program files\bs_player\tbBS_P.dll mURLSearchHooks: BS Player Toolbar: {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - c:\program files\bs_player\tbBS_P.dll dURLSearchHooks: {A3BC75A2-1F87-4686-AA43-5347D756017C} - <orphaned> uWinlogon: Shell = c:\users\martin\appdata\local\917060d7\X BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - c:\program files\avg\avg10\avgssie.dll BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - c:\program files\avg secure search\10.0.0.7\AVG Secure Search_toolbar.dll BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: BS Player Toolbar: {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - c:\program files\bs_player\tbBS_P.dll TB: DAEMON Tools Toolbar: {32099AAC-C132-4136-9E9A-4E364A424E17} - c:\program files\daemon tools toolbar\DTToolbar.dll TB: BS Player Toolbar: {FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5} - c:\program files\bs_player\tbBS_P.dll TB: DAEMON Tools Toolbar: {32099AAC-C132-4136-9E9A-4E364A424E17} - c:\program files\daemon tools toolbar\DTToolbar.dll TB: BS Player Toolbar: {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - c:\program files\bs_player\tbBS_P.dll TB: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - c:\program files\avg secure search\10.0.0.7\AVG Secure Search_toolbar.dll uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun uRun: [OM2_Monitor] "c:\program files\olympus\olympus master 2\MMonitor.exe" uRun: [KiesHelper] c:\program files\samsung\kies\KiesHelper.exe /s uRun: [KiesTrayAgent] c:\program files\samsung\kies\KiesTrayAgent.exe uRun: [KiesPDLR] c:\program files\samsung\kies\external\firmwareupdate\KiesPDLR.exe mRun: [WinampAgent] "c:\program files\winamp\winampa.exe" mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [igfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [OM2_Monitor] "c:\program files\olympus\olympus master 2\FirstStart.exe" /OM mRun: [KiesTrayAgent] c:\program files\samsung\kies\KiesTrayAgent.exe mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mRun: [sunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [vProt] "c:\program files\avg secure search\vprot.exe" mRun: [ROC_roc_dec12] "c:\program files\avg secure search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12 mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\flexty~1.lnk - c:\program files\datecs\flextype 2k\FType2K.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\gogear~1.lnk - c:\program files\philips\gogear sa3mxx device manager\main.exe mPolicies-System: ConsentPromptBehaviorAdmin = dword:5 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableUIADesktopToggle = dword:0 IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll IE: {60237576-b24c-4ba9-9740-c9f3ec9db557} - {EAADF17C-B6EA-4511-8549-A67CFD406EAF} - c:\program files\skycode\webtrance30\wt2ie.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} LSP: mswsock.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab TCP: NameServer = 85.217.128.241 87.121.223.9 TCP: Interfaces\{2E8012C2-2100-42BB-B437-96D2A480657D} : DHCPNameServer = 85.217.128.241 87.121.223.9 Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\common files\avg secure search\viprotocolinstaller\10.0.6\ViProtocol.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll Notify: igfxcui - igfxdev.dll SSODL: WebCheck - <orphaned> SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg pku2u livessp . ================= FIREFOX =================== . FF - ProfilePath - c:\users\martin\appdata\roaming\mozilla\firefox\profiles\e72k9gu4.default\ FF - prefs.js: browser.startup.homepage - www.google.bg FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7Bc0749cf5-71d9-445c-914c-6855046c0e65%7D&mid=fa1492f26651b6517dbb7e738461ca3b-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&ds=AVG&v=10.0.0.7&lang=us&pr=pa&d=2011-12-07%2009%3A05%3A44&sap=ku&q= FF - component: c:\program files\avg\avg10\firefox\components\avgssff.dll FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll FF - component: c:\users\martin\appdata\roaming\mozilla\firefox\profiles\nozwtki4.default\extensions\[email protected]\components\DTToolbarFF.dll FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.3.21.99\npGoogleUpdate3.dll FF - plugin: c:\program files\inhatchteam\inhatch\npinhatch.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - plugin: c:\users\martin\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll . ============= SERVICES / DRIVERS =============== . R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-2-22 22992] R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-3-16 32592] R1 archlp;archlp;c:\windows\system32\drivers\ArcHlp.sys [2009-2-19 91264] R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-1-7 248656] R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-3-1 34896] R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-4-4 297168] R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2012-1-3 63928] R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2012-1-31 7391072] R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2011-2-8 269520] R2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-8-22 217088] R2 vToolbarUpdater;vToolbarUpdater;c:\program files\common files\avg secure search\vtoolbarupdater\10.0.6\ToolbarUpdater.exe [2012-1-18 909152] R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-5-27 134480] R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-2-10 24144] R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-2-10 21968] R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2010-8-22 36640] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-3-1 139776] S2 avg7rsxp;Sysaudio;c:\windows\system32\svchost.exe -k netsvcs [2009-7-14 20992] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 gupdate;Ус»уі° Google Update (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-7-27 136176] S2 mcpromgr;Mvdcodec;c:\windows\system32\svchost.exe -k netsvcs [2009-7-14 20992] S2 mfebopk;Sit_prt;c:\windows\system32\svchost.exe -k netsvcs [2009-7-14 20992] S2 mirrorv3;MTC0001_ESB;c:\windows\system32\svchost.exe -k netsvcs [2009-7-14 20992] S2 webrootenterpriseclientservice;SE27bus;c:\windows\system32\svchost.exe -k netsvcs [2009-7-14 20992] S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg10\toolbar\ToolbarBroker.exe [2010-11-25 167264] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888] S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files\common files\futuremark shared\futuremark systeminfo\FMSISvc.exe [2011-3-23 129440] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-7-27 136176] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2011-3-9 15872] S3 rockusb;Driver for rockusb Device;c:\windows\system32\drivers\rockusb.sys [2011-3-11 80680] S3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM);c:\windows\system32\drivers\sscebus.sys [2010-9-15 98560] S3 sscemdfl;SAMSUNG Mobile Modem V2 Filter;c:\windows\system32\drivers\sscemdfl.sys [2010-9-15 14848] S3 sscemdm;SAMSUNG Mobile Modem V2 Drivers;c:\windows\system32\drivers\sscemdm.sys [2010-9-15 123648] S3 ssceserd;SAMSUNG Mobile Modem Diagnostic Serial Port V2 (WDM);c:\windows\system32\drivers\ssceserd.sys [2010-9-15 100352] S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-3-9 52224] S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-7-27 1343400] . =============== File Associations =============== . FileExt: .txt: txtfile=c:\windows\system32\NOTEPAD.EXE %1 [userChoice] ShellExec: DigitalTheatre.exe: open="c:\program files\arcsoft\totalmedia theatre 3\uDTStart.exe" "%1" ShellExec: DVDXPlayer.exe: open=c:\program files\dvd x studios\dvd x player 4.0 professional\DVDXPlayer.exe" "%1 . =============== Created Last 30 ================ . 2012-03-11 22:05:19 -------- d-sh--w- c:\windows\system32\%APPDATA% 2012-03-11 22:01:48 0 --sha-w- c:\windows\system32\dds_log_ad13.cmd 2012-03-11 21:32:31 -------- d-sh--w- c:\users\martin\appdata\local\917060d7 2012-03-10 15:03:41 251672 ----a-w- c:\windows\system32\xactengine2_5.dll 2012-03-10 15:03:40 440080 ----a-w- c:\windows\system32\d3dx10.dll 2012-03-10 15:03:37 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll 2012-03-10 15:03:35 237848 ----a-w- c:\windows\system32\xactengine2_4.dll 2012-03-10 15:03:30 2414360 ----a-w- c:\windows\system32\d3dx9_31.dll 2012-03-10 15:03:29 236824 ----a-w- c:\windows\system32\xactengine2_3.dll 2012-03-10 15:03:27 62744 ----a-w- c:\windows\system32\xinput1_2.dll 2012-02-16 17:04:33 478720 ----a-w- c:\windows\system32\timedate.cpl 2012-02-16 17:04:23 690688 ----a-w- c:\windows\system32\msvcrt.dll 2012-02-16 17:04:16 442880 ----a-w- c:\windows\system32\ntshrui.dll 2012-02-16 17:04:15 2343424 ----a-w- c:\windows\system32\win32k.sys 2012-02-13 18:46:38 -------- d-----w- c:\users\martin\appdata\roaming\Temp . ==================== Find3M ==================== . 2012-03-11 22:01:08 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-12-14 03:04:54 1798656 ----a-w- c:\windows\system32\jscript9.dll 2011-12-14 02:57:18 1127424 ----a-w- c:\windows\system32\wininet.dll 2011-12-14 02:56:58 1427456 ----a-w- c:\windows\system32\inetcpl.cpl 2011-12-14 02:50:04 2382848 ----a-w- c:\windows\system32\mshtml.tlb . ============= FINISH: 1:39:09,87 =============== Attach: . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-09-30.01) . Microsoft Windows 7 Ultimate Boot Device: \Device\HarddiskVolume1 Install Date: 27.7.2010 г. 12:57:32 System Uptime: 12.3.2012 г. 01:21:44 (0 hours ago) . Motherboard: ASRock | | G31M-VS Processor: Intel® Celeron® CPU E3200 @ 2.40GHz | CPUSocket | 2393/200mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 58 GiB total, 30,128 GiB free. D: is FIXED (NTFS) - 195 GiB total, 10,458 GiB free. E: is FIXED (NTFS) - 212 GiB total, 9,724 GiB free. F: is CDROM () G: is CDROM () . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP378: 10.3.2012 г. 16:59:30 - Installed Iron Man. RP379: 10.3.2012 г. 17:55:13 - Removed Iron Man. . ==== Installed Programs ====================== . Update for Microsoft Office 2007 (KB2508958) Фѕтѕі°»µрёя Ѕ° Windows Live Adobe AIR Adobe Download Manager Adobe Flash Player 11 Plugin Adobe Reader X (10.1.2) Angry Birds Rio ArcSoft TotalMedia Theatre 3 Audacity 1.2.6 AVG 2011 BS.Player FREE BS_Player Toolbar CCleaner ConvertHelper 2.2 D3DX10 DAEMON Tools Toolbar DVD X Player 4.0 Professional Easy CD-DA Extractor 12 facebookJS FlexType 2K Futuremark SystemInfo GameSpy Arcade GoGear SA3MXX Device Manager Google Chrome Google Update Helper Google чµјя Hotfix for Microsoft .NET Framework 4 Client Profile (KB2461678) ImagXpress Inhatch web plugins Intel® Graphics Media Accelerator Driver Intel® TV Wizard Java Auto Updater Java 6 Update 29 K-Lite Mega Codec Pack 6.2.0 Malwarebytes Anti-Malware, Іµрсёя 1.60.1.1000 Microsoft .NET Framework 1.1 Microsoft .NET Framework 4 Client Profile Microsoft Application Error Reporting Microsoft Games for Windows - LIVE Redistributable Microsoft Office 2007 Primary Interop Assemblies Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office File Validation Add-In Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Professional Edition 2003 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Speech 5.1 Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual J# .NET Redistributable Package 1.1 Mozilla Firefox 10.0.2 (x86 bg) MSVCRT MSVCRT Redists MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 4.0 SP2 Parser and SDK NeroBurningROM NeroExpress neroxml NVIDIA PhysX v8.05.26 Octoshape add-in for Adobe Flash Player OLYMPUS Master 2 Opera 11.61 OutlookAddInNet3Setup SA Dictionary 2005 T2 Samsung Kies SAMSUNG USB Driver for Mobile Phones Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition Skype Click to Call SkypeLauncher SkypeTrance 1.0 (ґµёЅст°»ёр°Ѕµ) Skype™ 5.5 System Requirements Lab System Requirements Lab CYRI System Requirements Lab for Intel The KMPlayer (remove only) TreeSize Professional 5.3.4 Unity Web Player Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office 2007 suites (KB2596651) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596789) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2597998) 32-Bit Edition Update for Microsoft Office Access 2007 Help (KB963663) Update for Microsoft Office Excel 2007 (KB2596596) 32-Bit Edition Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office Infopath 2007 Help (KB963662) Update for Microsoft Office OneNote 2007 Help (KB963670) Update for Microsoft Office Outlook 2007 Help (KB963677) Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Publisher 2007 Help (KB963667) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 Help (KB963665) Visual Studio Tools for the Office system 3.0 Runtime Visual Studio Tools for the Office system 3.0 Runtime Service Pack 1 (KB949258) VLC media player 1.1.11 WebTrance3.0 (ґµёЅст°»ёр°Ѕµ) Westwood Shared Internet Components Winamp Winamp Detector Plug-in Windows Live Communications Platform Windows Live Essentials Windows Live ID Sign-in Assistant Windows Live Installer Windows Live Movie Maker Windows Live Photo Common Windows Live Photo Gallery Windows Live PIMT Platform Windows Live SOXE Windows Live SOXE Definitions Windows Live UX Platform Windows Live UX Platform Language Pack Windows Media Player Firefox Plugin WinRAR archiver µTorrent . ==== Event Viewer Messages From Past Week ======== . 9.3.2012 і. 14:11:07, Error: Service Control Manager [7000] - The atksgt service failed to start due to the following error: This driver has been blocked from loading 9.3.2012 і. 14:11:07, Error: Application Popup [875] - Driver atksgt.sys has been blocked from loading. 9.3.2012 і. 14:10:55, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 9.3.2012 і. 08:22:32, Error: Service Control Manager [7000] - The atksgt service failed to start due to the following error: This driver has been blocked from loading 9.3.2012 і. 08:22:32, Error: Application Popup [875] - Driver atksgt.sys has been blocked from loading. 9.3.2012 і. 08:22:15, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 8.3.2012 і. 14:30:56, Error: Service Control Manager [7000] - The atksgt service failed to start due to the following error: This driver has been blocked from loading 8.3.2012 і. 14:30:56, Error: Application Popup [875] - Driver atksgt.sys has been blocked from loading. 8.3.2012 і. 14:30:40, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 8.3.2012 і. 10:07:52, Error: Service Control Manager [7000] - The atksgt service failed to start due to the following error: This driver has been blocked from loading 8.3.2012 і. 10:07:52, Error: Application Popup [875] - Driver atksgt.sys has been blocked from loading. 8.3.2012 і. 10:07:42, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 7.3.2012 і. 19:04:19, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit. 7.3.2012 і. 14:56:59, Error: Service Control Manager [7000] - The atksgt service failed to start due to the following error: This driver has been blocked from loading 7.3.2012 і. 14:56:59, Error: Application Popup [875] - Driver atksgt.sys has been blocked from loading. 7.3.2012 і. 14:56:37, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 7.3.2012 і. 09:55:28, Error: Service Control Manager [7000] - The atksgt service failed to start due to the following error: This driver has been blocked from loading 7.3.2012 і. 09:55:28, Error: Application Popup [875] - Driver atksgt.sys has been blocked from loading. 7.3.2012 і. 09:55:08, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 6.3.2012 і. 13:56:53, Error: Service Control Manager [7000] - The atksgt service failed to start due to the following error: This driver has been blocked from loading 6.3.2012 і. 13:56:53, Error: Application Popup [875] - Driver atksgt.sys has been blocked from loading. 6.3.2012 і. 13:56:38, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 6.3.2012 і. 12:50:32, Error: Service Control Manager [7000] - The atksgt service failed to start due to the following error: This driver has been blocked from loading 6.3.2012 і. 12:50:32, Error: Application Popup [875] - Driver atksgt.sys has been blocked from loading. 6.3.2012 і. 12:50:20, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 6.3.2012 і. 07:28:27, Error: Service Control Manager [7000] - The atksgt service failed to start due to the following error: This driver has been blocked from loading 6.3.2012 і. 07:28:27, Error: Application Popup [875] - Driver atksgt.sys has been blocked from loading. 6.3.2012 і. 07:28:16, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 6.3.2012 і. 05:52:58, Error: Service Control Manager [7000] - The atksgt service failed to start due to the following error: This driver has been blocked from loading 6.3.2012 і. 05:52:58, Error: Application Popup [875] - Driver atksgt.sys has been blocked from loading. 6.3.2012 і. 05:52:37, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 5.3.2012 і. 15:49:40, Error: Service Control Manager [7000] - The atksgt service failed to start due to the following error: This driver has been blocked from loading 5.3.2012 і. 15:49:40, Error: Application Popup [875] - Driver atksgt.sys has been blocked from loading. 5.3.2012 і. 15:49:30, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 5.3.2012 і. 08:23:19, Error: Service Control Manager [7000] - The atksgt service failed to start due to the following error: This driver has been blocked from loading 5.3.2012 і. 08:23:19, Error: Application Popup [875] - Driver atksgt.sys has been blocked from loading. 5.3.2012 і. 08:23:09, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 12.3.2012 і. 01:38:15, Error: Service Control Manager [7023] - The _iomega_active_disk_service_ service terminated with the following error: Access is denied. 12.3.2012 і. 01:37:14, Error: Service Control Manager [7023] - The LCcfltr service terminated with the following error: Access is denied. 12.3.2012 і. 01:36:14, Error: Service Control Manager [7023] - The Iomegaaccess service terminated with the following error: Access is denied. 12.3.2012 і. 01:35:15, Error: Service Control Manager [7023] - The Imaservice service terminated with the following error: Access is denied. 12.3.2012 і. 01:34:14, Error: Service Control Manager [7023] - The Mpe service terminated with the following error: Access is denied. 12.3.2012 і. 01:33:15, Error: Service Control Manager [7023] - The SE27bus service terminated with the following error: Access is denied. 12.3.2012 і. 01:32:15, Error: Service Control Manager [7023] - The Svv service terminated with the following error: Access is denied. 12.3.2012 і. 01:31:14, Error: Service Control Manager [7023] - The Hsxhwazl service terminated with the following error: Access is denied. 12.3.2012 і. 01:30:15, Error: Service Control Manager [7023] - The U81xobex service terminated with the following error: Access is denied. 12.3.2012 і. 01:29:15, Error: Service Control Manager [7023] - The Inspect service terminated with the following error: Access is denied. 12.3.2012 і. 01:28:14, Error: Service Control Manager [7023] - The Richvideo service terminated with the following error: Access is denied. 12.3.2012 і. 01:27:15, Error: Service Control Manager [7023] - The Tones service terminated with the following error: Access is denied. 12.3.2012 і. 01:26:15, Error: Service Control Manager [7023] - The Sit_prt service terminated with the following error: Access is denied. 12.3.2012 і. 01:25:15, Error: Service Control Manager [7023] - The AppnApi service terminated with the following error: Access is denied. 12.3.2012 і. 01:24:14, Error: Service Control Manager [7023] - The Sysaudio service terminated with the following error: Access is denied. 12.3.2012 і. 01:23:15, Error: Service Control Manager [7023] - The Mvdcodec service terminated with the following error: Access is denied. 12.3.2012 і. 01:22:23, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The WaveEnrollmentService service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Wacommousefilter service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The W39n51 service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Vmusb service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The USBCCID service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The UBHelper service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Tsdhd service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Sysmgmthp service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Streamip service terminated with the following error: Access is denied. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The SrvcSSIOMngr service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Sr_service service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Smcservice service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Shockprf service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Se59unic service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Se58mgmt service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Se45obex service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Se2Cunic service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Se26unic service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The REVOSENS service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Remoterecord service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Raspti service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Penclass service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Pcidump service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Pageserver service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The NWUSBModem service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Nwlnknb service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Npkcusb service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The NICSer_WPC300N service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The MTC0001_ESB service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The MASPINT service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The MailService service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Lvcomser service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Keymaestro service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Jukebox service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The JL2005C service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Iteatapi service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The InCDsrvR service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Hpdskflt service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Hdthermal service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Enxpsvr service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Enum1394 service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Emupia service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Dmusic service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Dirms_defragmentation service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The DCFS2K service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Dbmanagerscheduler service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Cportclm service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Cmudau service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Cdudf_xp service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Brmfrmps service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Avgio service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Avc service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Atimtag service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Atierecord service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Askernel service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The Anbmservice service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The AmeLanPc service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7023] - The ABVPN2K service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed. 12.3.2012 і. 01:22:20, Error: Service Control Manager [7000] - The atksgt service failed to start due to the following error: This driver has been blocked from loading 12.3.2012 і. 01:22:20, Error: Application Popup [875] - Driver atksgt.sys has been blocked from loading. 12.3.2012 і. 01:21:58, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 12.3.2012 і. 01:20:25, Error: Service Control Manager [7023] - The Shockprf service terminated with the following error: Access is denied. 12.3.2012 і. 01:19:25, Error: Service Control Manager [7023] - The Enum1394 service terminated with the following error: Access is denied. 12.3.2012 і. 01:18:25, Error: Service Control Manager [7023] - The Se59unic service terminated with the following error: Access is denied. 12.3.2012 і. 01:17:25, Error: Service Control Manager [7023] - The Se2Cunic service terminated with the following error: Access is denied. 12.3.2012 і. 01:16:26, Error: Service Control Manager [7023] - The Atimtag service terminated with the following error: Access is denied. 12.3.2012 і. 01:06:11, Error: Service Control Manager [7023] - The Streamip service terminated with the following error: Access is denied. 12.3.2012 і. 01:06:11, Error: Service Control Manager [7023] - The Hdthermal service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:11, Error: Service Control Manager [7023] - The Emupia service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:11, Error: Service Control Manager [7023] - The Avc service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:11, Error: Service Control Manager [7023] - The Atierecord service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The WaveEnrollmentService service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The Wacommousefilter service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The W39n51 service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The Vmusb service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The USBCCID service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The UBHelper service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The Tsdhd service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The Sysmgmthp service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The SrvcSSIOMngr service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The Sr_service service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The Smcservice service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The Se58mgmt service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The Se45obex service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The Se26unic service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The REVOSENS service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The Remoterecord service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The Raspti service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The Penclass service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The Pcidump service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The Pageserver service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The NWUSBModem service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The Nwlnknb service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The Npkcusb service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The NICSer_WPC300N service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The MTC0001_ESB service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The MASPINT service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The MailService service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The Lvcomser service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The Keymaestro service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The Jukebox service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The JL2005C service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The Iteatapi service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The InCDsrvR service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The Hpdskflt service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The Enxpsvr service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The Dmusic service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The Dirms_defragmentation service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The DCFS2K service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The Dbmanagerscheduler service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The Cportclm service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The Cmudau service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The Cdudf_xp service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The Brmfrmps service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The Avgio service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The Askernel service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The Anbmservice service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The AmeLanPc service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7023] - The ABVPN2K service terminated with the following error: The specified module could not be found. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed. 12.3.2012 і. 01:06:10, Error: Service Control Manager [7000] - The atksgt service failed to start due to the following error: This driver has been blocked from loading 12.3.2012 і. 01:06:10, Error: Application Popup [875] - Driver atksgt.sys has been blocked from loading. 12.3.2012 і. 01:05:48, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 12.3.2012 і. 01:04:55, Error: Service Control Manager [7023] - The Streamip service terminated with the following error: Access is denied. 12.3.2012 і. 01:03:55, Error: Service Control Manager [7023] - The Remoterecord service terminated with the following error: Access is denied. 12.3.2012 і. 01:02:55, Error: Service Control Manager [7023] - The Smcservice service terminated with the following error: Access is denied. 12.3.2012 і. 01:01:55, Error: Service Control Manager [7023] - The Cdudf_xp service terminated with the following error: Access is denied. 12.3.2012 і. 01:00:55, Error: Service Control Manager [7023] - The REVOSENS service terminated with the following error: Access is denied. 12.3.2012 і. 00:59:55, Error: Service Control Manager [7023] - The Askernel service terminated with the following error: Access is denied. 12.3.2012 і. 00:58:55, Error: Service Control Manager [7023] - The MTC0001_ESB service terminated with the following error: Access is denied. 12.3.2012 і. 00:57:56, Error: Service Control Manager [7023] - The Cportclm service terminated with the following error: Access is denied. 12.3.2012 і. 00:56:56, Error: Service Control Manager [7023] - The Se26unic service terminated with the following error: Access is denied. 12.3.2012 і. 00:55:55, Error: Service Control Manager [7023] - The AmeLanPc service terminated with the following error: Access is denied. 12.3.2012 і. 00:54:56, Error: Service Control Manager [7023] - The USBCCID service terminated with the following error: Access is denied. 12.3.2012 і. 00:53:56, Error: Service Control Manager [7023] - The JL2005C service terminated with the following error: Access is denied. 12.3.2012 і. 00:52:57, Error: Service Control Manager [7023] - The Se58mgmt service terminated with the following error: Access is denied. 12.3.2012 і. 00:51:56, Error: Service Control Manager [7023] - The Hpdskflt service terminated with the following error: Access is denied. 12.3.2012 і. 00:50:56, Error: Service Control Manager [7023] - The Dmusic service terminated with the following error: Access is denied. 12.3.2012 і. 00:49:57, Error: Service Control Manager [7023] - The UBHelper service terminated with the following error: Access is denied. 12.3.2012 і. 00:48:56, Error: Service Control Manager [7023] - The Avc service terminated with the following error: Access is denied. 12.3.2012 і. 00:47:55, Error: Service Control Manager [7023] - The Raspti service terminated with the following error: Access is denied. 12.3.2012 і. 00:46:59, Error: Service Control Manager [7023] - The Nwlnknb service terminated with the following error: Access is denied. 12.3.2012 і. 00:43:58, Error: Service Control Manager [7023] - The WaveEnrollmentService service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:43:58, Error: Service Control Manager [7023] - The Wacommousefilter service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:43:58, Error: Service Control Manager [7023] - The Tsdhd service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:43:58, Error: Service Control Manager [7023] - The Sysmgmthp service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:43:58, Error: Service Control Manager [7023] - The Sr_service service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:43:58, Error: Service Control Manager [7023] - The Se45obex service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:43:58, Error: Service Control Manager [7023] - The Penclass service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:43:58, Error: Service Control Manager [7023] - The Pageserver service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:43:58, Error: Service Control Manager [7023] - The NWUSBModem service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:43:58, Error: Service Control Manager [7023] - The Npkcusb service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:43:58, Error: Service Control Manager [7023] - The NICSer_WPC300N service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:43:58, Error: Service Control Manager [7023] - The MailService service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:43:58, Error: Service Control Manager [7023] - The InCDsrvR service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:43:58, Error: Service Control Manager [7023] - The Hdthermal service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:43:58, Error: Service Control Manager [7023] - The Enxpsvr service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:43:58, Error: Service Control Manager [7023] - The Emupia service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:43:58, Error: Service Control Manager [7023] - The DCFS2K service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:43:58, Error: Service Control Manager [7023] - The Dbmanagerscheduler service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:43:58, Error: Service Control Manager [7023] - The Brmfrmps service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:43:58, Error: Service Control Manager [7023] - The Atierecord service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:43:58, Error: Service Control Manager [7023] - The Anbmservice service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:43:58, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed. 12.3.2012 і. 00:43:58, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed. 12.3.2012 і. 00:43:57, Error: Service Control Manager [7023] - The W39n51 service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:43:57, Error: Service Control Manager [7023] - The Vmusb service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:43:57, Error: Service Control Manager [7023] - The SrvcSSIOMngr service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:43:57, Error: Service Control Manager [7023] - The Pcidump service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:43:57, Error: Service Control Manager [7023] - The MASPINT service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:43:57, Error: Service Control Manager [7023] - The Lvcomser service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:43:57, Error: Service Control Manager [7023] - The Keymaestro service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:43:57, Error: Service Control Manager [7023] - The Jukebox service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:43:57, Error: Service Control Manager [7023] - The Iteatapi service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:43:57, Error: Service Control Manager [7023] - The Dirms_defragmentation service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:43:57, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service. 12.3.2012 і. 00:43:57, Error: Service Control Manager [7023] - The Cmudau service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:43:57, Error: Service Control Manager [7023] - The Avgio service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:43:57, Error: Service Control Manager [7023] - The ABVPN2K service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:43:57, Error: Service Control Manager [7000] - The atksgt service failed to start due to the following error: This driver has been blocked from loading 12.3.2012 і. 00:43:57, Error: Application Popup [875] - Driver atksgt.sys has been blocked from loading. 12.3.2012 і. 00:43:46, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 12.3.2012 і. 00:40:41, Error: Service Control Manager [7023] - The Npkcusb service terminated with the following error: Access is denied. 12.3.2012 і. 00:40:41, Error: Service Control Manager [7023] - The Hdthermal service terminated with the following error: Access is denied. 12.3.2012 і. 00:40:41, Error: Service Control Manager [7023] - The Emupia service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:40:41, Error: Service Control Manager [7023] - The Atierecord service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:40:40, Error: Service Control Manager [7023] - The WaveEnrollmentService service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:40:40, Error: Service Control Manager [7023] - The Wacommousefilter service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:40:40, Error: Service Control Manager [7023] - The W39n51 service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:40:40, Error: Service Control Manager [7023] - The Vmusb service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:40:40, Error: Service Control Manager [7023] - The Tsdhd service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:40:40, Error: Service Control Manager [7023] - The Sysmgmthp service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:40:40, Error: Service Control Manager [7023] - The SrvcSSIOMngr service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:40:40, Error: Service Control Manager [7023] - The Sr_service service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:40:40, Error: Service Control Manager [7023] - The Se45obex service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:40:40, Error: Service Control Manager [7023] - The Penclass service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:40:40, Error: Service Control Manager [7023] - The Pcidump service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:40:40, Error: Service Control Manager [7023] - The Pageserver service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:40:40, Error: Service Control Manager [7023] - The NWUSBModem service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:40:40, Error: Service Control Manager [7023] - The NICSer_WPC300N service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:40:40, Error: Service Control Manager [7023] - The MASPINT service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:40:40, Error: Service Control Manager [7023] - The MailService service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:40:40, Error: Service Control Manager [7023] - The Lvcomser service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:40:40, Error: Service Control Manager [7023] - The Keymaestro service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:40:40, Error: Service Control Manager [7023] - The Jukebox service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:40:40, Error: Service Control Manager [7023] - The Iteatapi service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:40:40, Error: Service Control Manager [7023] - The InCDsrvR service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:40:40, Error: Service Control Manager [7023] - The Enxpsvr service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:40:40, Error: Service Control Manager [7023] - The Dirms_defragmentation service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:40:40, Error: Service Control Manager [7023] - The DCFS2K service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:40:40, Error: Service Control Manager [7023] - The Dbmanagerscheduler service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:40:40, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service. 12.3.2012 і. 00:40:40, Error: Service Control Manager [7023] - The Cmudau service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:40:40, Error: Service Control Manager [7023] - The Brmfrmps service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:40:40, Error: Service Control Manager [7023] - The Avgio service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:40:40, Error: Service Control Manager [7023] - The Anbmservice service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:40:40, Error: Service Control Manager [7023] - The ABVPN2K service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:40:40, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed. 12.3.2012 і. 00:40:40, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed. 12.3.2012 і. 00:40:40, Error: Service Control Manager [7000] - The atksgt service failed to start due to the following error: This driver has been blocked from loading 12.3.2012 і. 00:40:40, Error: Application Popup [875] - Driver atksgt.sys has been blocked from loading. 12.3.2012 і. 00:40:23, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 12.3.2012 і. 00:38:25, Error: Service Control Manager [7023] - The Hdthermal service terminated with the following error: Access is denied. 12.3.2012 і. 00:37:32, Error: VDS Basic Provider [1] - Unexpected failure. Error code: 490@01010004 12.3.2012 і. 00:37:26, Error: Service Control Manager [7023] - The Npkcusb service terminated with the following error: Access is denied. 12.3.2012 і. 00:36:25, Error: Service Control Manager [7023] - The Anbmservice service terminated with the following error: Access is denied. 12.3.2012 і. 00:35:26, Error: Service Control Manager [7023] - The Lvcomser service terminated with the following error: Access is denied. 12.3.2012 і. 00:34:25, Error: Service Control Manager [7023] - The InCDsrvR service terminated with the following error: Access is denied. 12.3.2012 і. 00:33:27, Error: Service Control Manager [7023] - The Enxpsvr service terminated with the following error: Access is denied. 12.3.2012 і. 00:32:27, Error: Service Control Manager [7023] - The Sr_service service terminated with the following error: Access is denied. 12.3.2012 і. 00:30:27, Error: Service Control Manager [7023] - The ABVPN2K service terminated with the following error: Access is denied. 12.3.2012 і. 00:29:26, Error: Service Control Manager [7023] - The NICSer_WPC300N service terminated with the following error: Access is denied. 12.3.2012 і. 00:28:27, Error: Service Control Manager [7023] - The SrvcSSIOMngr service terminated with the following error: Access is denied. 12.3.2012 і. 00:26:26, Error: Service Control Manager [7023] - The Atierecord service terminated with the following error: Access is denied. 12.3.2012 і. 00:25:25, Error: Service Control Manager [7023] - The Brmfrmps service terminated with the following error: Access is denied. 12.3.2012 і. 00:24:25, Error: Service Control Manager [7023] - The Pcidump service terminated with the following error: Access is denied. 12.3.2012 і. 00:23:25, Error: Service Control Manager [7023] - The Sysmgmthp service terminated with the following error: Access is denied. 12.3.2012 і. 00:22:26, Error: Service Control Manager [7023] - The Wacommousefilter service terminated with the following error: Access is denied. 12.3.2012 і. 00:21:25, Error: Service Control Manager [7023] - The Pageserver service terminated with the following error: Access is denied. 12.3.2012 і. 00:20:25, Error: Service Control Manager [7023] - The Keymaestro service terminated with the following error: Access is denied. 12.3.2012 і. 00:19:26, Error: Service Control Manager [7023] - The Dbmanagerscheduler service terminated with the following error: Access is denied. 12.3.2012 і. 00:18:26, Error: Service Control Manager [7023] - The Vmusb service terminated with the following error: Access is denied. 12.3.2012 і. 00:17:27, Error: Service Control Manager [7023] - The MASPINT service terminated with the following error: Access is denied. 12.3.2012 і. 00:16:33, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service. 12.3.2012 і. 00:16:31, Error: Service Control Manager [7023] - The WaveEnrollmentService service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:16:31, Error: Service Control Manager [7023] - The W39n51 service terminated with the following error: Access is denied. 12.3.2012 і. 00:16:31, Error: Service Control Manager [7023] - The Tsdhd service terminated with the following error: Access is denied. 12.3.2012 і. 00:16:31, Error: Service Control Manager [7023] - The Se45obex service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:16:31, Error: Service Control Manager [7023] - The Penclass service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:16:31, Error: Service Control Manager [7023] - The NWUSBModem service terminated with the following error: Access is denied. 12.3.2012 і. 00:16:31, Error: Service Control Manager [7023] - The MailService service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:16:31, Error: Service Control Manager [7023] - The Jukebox service terminated with the following error: Access is denied. 12.3.2012 і. 00:16:31, Error: Service Control Manager [7023] - The Iteatapi service terminated with the following error: Access is denied. 12.3.2012 і. 00:16:31, Error: Service Control Manager [7023] - The Emupia service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:16:31, Error: Service Control Manager [7023] - The Dirms_defragmentation service terminated with the following error: Access is denied. 12.3.2012 і. 00:16:31, Error: Service Control Manager [7023] - The DCFS2K service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:16:31, Error: Service Control Manager [7023] - The Cmudau service terminated with the following error: The specified module could not be found. 12.3.2012 і. 00:16:31, Error: Service Control Manager [7023] - The Avgio service terminated with the following error: Access is denied. 12.3.2012 і. 00:16:31, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed. 12.3.2012 і. 00:16:31, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed. 12.3.2012 і. 00:16:30, Error: Service Control Manager [7000] - The atksgt service failed to start due to the following error: This driver has been blocked from loading 12.3.2012 і. 00:16:30, Error: Application Popup [875] - Driver atksgt.sys has been blocked from loading. 12.3.2012 і. 00:16:17, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 12.3.2012 і. 00:14:49, Error: Service Control Manager [7023] - The Dirms_defragmentation service terminated with the following error: Access is denied. 12.3.2012 і. 00:13:49, Error: Service Control Manager [7023] - The Iteatapi service terminated with the following error: Access is denied. 12.3.2012 і. 00:12:49, Error: Service Control Manager [7023] - The Jukebox service terminated with the following error: Access is denied. 12.3.2012 і. 00:11:49, Error: Service Control Manager [7023] - The NWUSBModem service terminated with the following error: Access is denied. 12.3.2012 і. 00:10:50, Error: Service Control Manager [7023] - The Avgio service terminated with the following error: Access is denied. 12.3.2012 і. 00:09:49, Error: Service Control Manager [7023] - The DCFS2K service terminated with the following error: Access is denied. 12.3.2012 і. 00:08:49, Error: Service Control Manager [7023] - The MailService service terminated with the following error: Access is denied. 12.3.2012 і. 00:07:49, Error: Service Control Manager [7023] - The WaveEnrollmentService service terminated with the following error: Access is denied. 12.3.2012 і. 00:06:49, Error: Service Control Manager [7023] - The Cmudau service terminated with the following error: Access is denied. 12.3.2012 і. 00:05:49, Error: Service Control Manager [7023] - The Se45obex service terminated with the following error: Access is denied. 12.3.2012 і. 00:04:49, Error: Service Control Manager [7023] - The Emupia service terminated with the following error: Access is denied. 12.3.2012 і. 00:03:49, Error: Service Control Manager [7023] - The Tsdhd service terminated with the following error: Access is denied. 12.3.2012 і. 00:02:49, Error: Service Control Manager [7023] - The W39n51 service terminated with the following error: Access is denied. 12.3.2012 і. 00:01:50, Error: Service Control Manager [7023] - The Penclass service terminated with the following error: Access is denied. 11.3.2012 і. 09:45:50, Error: Service Control Manager [7000] - The atksgt service failed to start due to the following error: This driver has been blocked from loading 11.3.2012 і. 09:45:50, Error: Application Popup [875] - Driver atksgt.sys has been blocked from loading. 11.3.2012 і. 09:45:37, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 10.3.2012 і. 15:56:35, Error: Service Control Manager [7000] - The atksgt service failed to start due to the following error: This driver has been blocked from loading 10.3.2012 і. 15:56:35, Error: Application Popup [875] - Driver atksgt.sys has been blocked from loading. 10.3.2012 і. 15:56:17, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 10.3.2012 і. 08:00:45, Error: Service Control Manager [7000] - The atksgt service failed to start due to the following error: This driver has been blocked from loading 10.3.2012 і. 08:00:45, Error: Application Popup [875] - Driver atksgt.sys has been blocked from loading. 10.3.2012 і. 08:00:27, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. . ==== End Of File ===========================

Редактирано от mude (преглед на промените)

  • Автор

ZeroAccess.dr.gen.d- AVG също постоянно ми показва и това.

Временно деинсталирайте AVG от Control Panel => Uninstall a Program.

След това почистете след нея с това => AVG Remover(32bit) 2012

И после пробвайте да стартирате това:

1. Изтеглете ComboFix от BleepingComputer

и го запазете (бутон Save -> Save as) ComboFix на вашия десктоп:

Публикувано изображение

След приключване на изтеглянето на ComboFix, иконката на програмата би трябвало да изглежда така:

Публикувано изображение

2. Затворете всички работещи приложения, отворени прозорци и програми работещи във фонов режим. Спрете временно защитата в реално време на антивирусната програма и на другите програми за сигурност, ако има такива.

3. Стартирайте с двоен клик Combofix.exe. Изберете YES, за да се съгласите с условията за използване на програмата. Важно: По време на работата на ComboFix не бива да се движи мишката и да се натискат клавиши от клавиатурата. Просто търпеливо оставете ComboFix да си свърши работата, без да използвате компютъра за други цели.

4. Ако получите предупреждение от UAC, съгласете се.

5 ComboFix ще спре временно Интернет връзката, но след като приключи работата на програмата тази връзка ще бъде възстановена автоматично. ComboFix ще сканира за проблеми и за заразени файлове, като това може да отнеме известно време. Моля да бъдете търпеливи. Ако има проблем с Интернет връзката след приключване на работата на Combofix, моля да прочетете това: Manually restoring the Internet connection section.

6 Когато работата на ComboFix приключи, ще се появи текстов документ (log) в Notepad:

Публикувано изображение

Копирайте с (Copy) и поставете с (Paste) съдържанието на лога в следващия си коментар.

Забележка: Ако се появи следното съобщение при отварянето на различни програми след завършване на сканирането с Combofix - "illegal operation on a registry key that has been marked for deletion." просто рестартирайте компютъра още веднъж и то ще изчезне.

По време на сканирането не използвайте компютъра си !

  • Автор

Не става да изтрия АVG от Programs and Features.

  • Автор

ComboFix 12-03-11.01 - Martin 03.2012 г. 2:54.1.2 - x86

Microsoft Windows 7 Ultimate 6.1.7601.1.1251.359.1033.18.2038.1296 [GMT 2:00]

Running from: c:\users\Martin\Desktop\ComboFix.exe

AV: AVG Internet Security 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}

SP: AVG Internet Security 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

* Created a new restore point

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\users\Martin\AppData\Local\917060d7\U

c:\users\Martin\AppData\Local\917060d7\U\80000000.@

c:\users\Martin\AppData\Local\917060d7\U\800000cb.@

c:\users\Martin\AppData\Local\917060d7\U\800000cf.@

c:\users\Martin\AppData\Local\Minibar

c:\users\Martin\AppData\Local\Minibar\common.js

c:\users\Martin\AppData\Local\Minibar\ie_installer.js

c:\users\Martin\AppData\Roaming\cf.dll

c:\users\Martin\AppData\Roaming\Microsoft\Windows\Recent\everest.url

c:\users\Martin\AppData\Roaming\mIRC\logs\status.log

c:\windows\$NtUninstallKB3672$

c:\windows\$NtUninstallKB3672$\2440061143\@

c:\windows\$NtUninstallKB3672$\2440061143\L\xadqgnnk

c:\windows\$NtUninstallKB3672$\2440061143\loader.tlb

c:\windows\$NtUninstallKB3672$\2440061143\U\@00000001

c:\windows\$NtUninstallKB3672$\2440061143\U\@000000c0

c:\windows\$NtUninstallKB3672$\2440061143\U\@000000cb

c:\windows\$NtUninstallKB3672$\2440061143\U\@000000cf

c:\windows\$NtUninstallKB3672$\2440061143\U\@80000000

c:\windows\$NtUninstallKB3672$\2440061143\U\@800000c0

c:\windows\$NtUninstallKB3672$\2440061143\U\@800000cb

c:\windows\$NtUninstallKB3672$\2440061143\U\@800000cf

c:\windows\$NtUninstallKB3672$\3383086648

c:\windows\assembly\GAC_MSIL\desktop.ini

c:\windows\system32\muzapp.exe

c:\windows\system32\system32

c:\windows\system32\system32\3DAudio.ax

c:\windows\system32\system32\avrt.dll

c:\windows\system32\system32\cis-2.4.dll

c:\windows\system32\system32\issacapi_bs-2.3.dll

c:\windows\system32\system32\issacapi_pe-2.3.dll

c:\windows\system32\system32\issacapi_se-2.3.dll

c:\windows\system32\system32\MACXMLProto.dll

c:\windows\system32\system32\MaDRM.dll

c:\windows\system32\system32\MaJGUILib.dll

c:\windows\system32\system32\MAMACExtract.dll

c:\windows\system32\system32\MASetupCleaner.exe

c:\windows\system32\system32\MaXMLProto.dll

c:\windows\system32\system32\mfplat.dll

c:\windows\system32\system32\MK_Lyric.dll

c:\windows\system32\system32\MSCLib.dll

c:\windows\system32\system32\MSFLib.dll

c:\windows\system32\system32\MSLUR71.dll

c:\windows\system32\system32\msvcp60.dll

c:\windows\system32\system32\MTTELECHIP.dll

c:\windows\system32\system32\MTXSYNCICON.dll

c:\windows\system32\system32\muzaf1.dll

c:\windows\system32\system32\muzapp.dll

c:\windows\system32\system32\muzapp.exe

c:\windows\system32\system32\muzdecode.ax

c:\windows\system32\system32\muzeffect.ax

c:\windows\system32\system32\muzmp4sp.ax

c:\windows\system32\system32\muzmpgsp.ax

c:\windows\system32\system32\muzoggsp.ax

c:\windows\system32\system32\muzwmts.dll

c:\windows\system32\system32\psapi.dll

.

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

-------\Service_STEC3

.

.

((((((((((((((((((((((((( Files Created from 2012-02-12 to 2012-03-12 )))))))))))))))))))))))))))))))

.

.

2012-03-11 22:05 . 2012-03-11 22:05 -------- d-sh--w- c:\windows\system32\%APPDATA%

2012-03-11 22:01 . 2012-03-12 00:41 0 --sha-w- c:\windows\system32\dds_log_ad13.cmd

2012-03-11 21:32 . 2012-03-12 01:00 -------- d-sh--w- c:\users\Martin\AppData\Local\917060d7

2012-03-10 15:03 . 2006-12-08 10:02 251672 ----a-w- c:\windows\system32\xactengine2_5.dll

2012-03-10 15:03 . 2006-11-29 11:06 440080 ----a-w- c:\windows\system32\d3dx10.dll

2012-03-10 15:03 . 2006-11-29 11:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll

2012-03-10 15:03 . 2006-09-28 14:05 237848 ----a-w- c:\windows\system32\xactengine2_4.dll

2012-03-10 15:03 . 2006-09-28 14:05 2414360 ----a-w- c:\windows\system32\d3dx9_31.dll

2012-03-10 15:03 . 2006-07-28 07:30 236824 ----a-w- c:\windows\system32\xactengine2_3.dll

2012-03-10 15:03 . 2006-07-28 07:30 62744 ----a-w- c:\windows\system32\xinput1_2.dll

2012-02-16 17:04 . 2011-12-30 05:27 478720 ----a-w- c:\windows\system32\timedate.cpl

2012-02-16 17:04 . 2011-12-16 07:52 690688 ----a-w- c:\windows\system32\msvcrt.dll

2012-02-16 17:04 . 2012-01-04 08:58 442880 ----a-w- c:\windows\system32\ntshrui.dll

2012-02-16 17:04 . 2012-01-14 03:35 2343424 ----a-w- c:\windows\system32\win32k.sys

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-03-11 22:01 . 2011-06-01 17:39 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2012-02-18 03:56 . 2011-07-16 18:02 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]

"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\tbBS_P.dll" [2009-03-10 2079256]

.

[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

.

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

2009-03-10 08:47 2079256 ----a-w- c:\program files\BS_Player\tbBS_P.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\tbBS_P.dll" [2009-03-10 2079256]

.

[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

.

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]

"{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}"= "c:\program files\BS_Player\tbBS_P.dll" [2009-03-10 2079256]

.

[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]

"OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2009-04-17 95536]

"KiesHelper"="c:\program files\Samsung\Kies\KiesHelper.exe" [2012-02-03 943504]

"KiesTrayAgent"="c:\program files\Samsung\Kies\KiesTrayAgent.exe" [2012-02-03 3508624]

"KiesPDLR"="c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2012-02-03 21392]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"WinampAgent"="c:\program files\Winamp\winampa.exe" [2010-07-12 74752]

"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 173592]

"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 150552]

"OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" [2009-04-17 54576]

"KiesTrayAgent"="c:\program files\Samsung\Kies\KiesTrayAgent.exe" [2012-02-03 3508624]

"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2012-01-13 981680]

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

FlexType 2K.lnk - c:\program files\Datecs\FlexType 2K\FType2K.exe [2010-7-27 95232]

GoGear SA3MXX Device Manager.lnk - c:\program files\Philips\GoGear SA3MXX Device Manager\main.exe [2011-8-11 124880]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"aux"=wdmaud.drv

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

.

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

R2 gupdate;Ус»уі° Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-07-27 136176]

R3 cpuz135;cpuz135;c:\windows\TEMP\cpuz135\cpuz135_x32.sys [x]

R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [x]

R3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [2011-01-13 129440]

R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-07-27 136176]

R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]

R3 rockusb;Driver for rockusb Device;c:\windows\system32\DRIVERS\rockusb.sys [2010-03-09 80680]

R3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM);c:\windows\system32\DRIVERS\sscebus.sys [2010-04-27 98560]

R3 sscemdfl;SAMSUNG Mobile Modem V2 Filter;c:\windows\system32\DRIVERS\sscemdfl.sys [2010-04-27 14848]

R3 sscemdm;SAMSUNG Mobile Modem V2 Drivers;c:\windows\system32\DRIVERS\sscemdm.sys [2010-04-27 123648]

R3 ssceserd;SAMSUNG Mobile Modem Diagnostic Serial Port V2 (WDM);c:\windows\system32\DRIVERS\ssceserd.sys [2010-04-27 100352]

R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]

R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]

R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-07-27 1343400]

S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-07-27 691696]

S1 archlp;archlp;c:\windows\system32\drivers\archlp.sys [2009-08-13 91264]

S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]

S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-07-26 217088]

S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2010-07-26 36640]

S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-03-01 139776]

.

.

--- Other Services/Drivers In Memory ---

.

*NewlyCreated* - FSUSBEXDISK

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

getPlusHelper REG_MULTI_SZ getPlusHelper

.

NETSVCS REQUIRES REPAIRS - current entries shown

AeLookupSvc

CertPropSvc

SCPolicySvc

lanmanserver

gpsvc

IKEEXT

AudioSrv

FastUserSwitchingCompatibility

Ias

Irmon

Nla

Ntmssvc

NWCWorkstation

Nwsapagent

Rasauto

Rasman

Remoteaccess

SENS

Sharedaccess

SRService

Tapisrv

Wmi

WmdmPmSp

ltxred

rtport

mwstick

USB_NDIS_51

servicelayer

bcserver

agnwifi

hpci

gdihook5

upperdev

MobilePreInstallerService

NITaggerService

nnsvc

PCDCODEC

viaagp1

BCMWLNPF

VCIDRV

EL90X

adfs

i2omgmt

tme3srv

owstimer

omnidrv

iwebcal

ntlmssp

SbcpHid

WNIPROT5

IBM_LLC2

pktfilter

avg7rsxp

mfebopk

usbser

sysmgmthp

cpntsrv

zBackupAssistService

e100b

i2omp

nvax

qconsvc

Mtlmnt5

LRMINIPORT

dlcj_device

websensecamserver

rpcapd

BrSerIf

digisptiservice

acermemusagecheckservice

mi-raysat_3dsMax2008_32

NPPTNT

mhndrv

hsf_dpv

RMCAST

shuttleengine

symc810

cebdaldr

datasvr

cbidf

anbmservice

RivaTuner32

steamdvr

s117nd5

tmesbs32

meiudf

mod7700

p2pgasvc

mks_scan

tvalz

carboncopy32

dvd43llh

X4HSX32

arkbcfltr

gameenum

botcbs

LMouFilt

pdlnsx25

adiusbaw

hcwPVRP2

WmaCVideo32

telnet

advantage

id2scaps

cachemgr

z525bus

gtndis5

websenseusagemonitor

tsircsrv

Gernuwa

DXEC02

firelm01

webrootenterpriseclientservice

nvrd64

usbsermpt

taphss

upnp

mcpromgr

USB28xxBGA

SlNtHal

w200mdfl

ipsecmon

filemon701

mirrorv3

IntuitUpdateService

adsexpb

openldap-slapd

ownershipprotocol

zebrsce

W8100PCI

SNMP

iaimfp1

sf

CBN

eventclientmultiplexer

XFX_program

ARPolicy

SNPSTD3

eelsservice

ccdecode

ezplay

AtiHdmiService

acedrv05

lanusb

deventagent

WmUsbHid

acdservice

TermService

wuauserv

BITS

ShellHWDetection

LogonHours

PCAudit

helpsvc

uploadmgr

iphlpsvc

seclogon

AppInfo

msiscsi

MMCSS

wercplsupport

EapHost

ProfSvc

schedule

hkmsvc

SessionEnv

winmgmt

browser

Themes

BDESVC

AppMgmt

.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

.

.

Contents of the 'Scheduled Tasks' folder

.

2012-03-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-27 11:58]

.

2012-03-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-27 11:58]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.google.bg/

uInternet Settings,ProxyOverride = <local>

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

IE: {{60237576-b24c-4ba9-9740-c9f3ec9db557} - {EAADF17C-B6EA-4511-8549-A67CFD406EAF} - c:\progra~1\SkyCode\WEBTRA~1\wt2ie.dll

TCP: DhcpNameServer = 85.217.128.241 87.121.223.9

FF - ProfilePath - c:\users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\e72k9gu4.default\

FF - prefs.js: browser.startup.homepage - www.google.bg

FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7Bc0749cf5-71d9-445c-914c-6855046c0e65%7D&mid=fa1492f26651b6517dbb7e738461ca3b-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&ds=AVG&v=10.0.0.7&lang=us&pr=pa&d=2011-12-07%2009%3A05%3A44&sap=ku&q=

.

- - - - ORPHANS REMOVED - - - -

.

HKLM-Run-ROC_roc_dec12 - c:\program files\AVG Secure Search\ROC_roc_dec12.exe

AddRemove-01_Simmental - c:\program files\Samsung\USB Drivers\01_Simmental\Uninstall.exe

AddRemove-02_Siberian - c:\program files\Samsung\USB Drivers\02_Siberian\Uninstall.exe

AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe

AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe

AddRemove-05_Sloan - c:\program files\Samsung\USB Drivers\05_Sloan\Uninstall.exe

AddRemove-06_Spencer - c:\program files\Samsung\USB Drivers\06_Spencer\Uninstall.exe

AddRemove-07_Schorl - c:\program files\Samsung\USB Drivers\07_Schorl\Uninstall.exe

AddRemove-08_EMPChipset - c:\program files\Samsung\USB Drivers\08_EMPChipset\Uninstall.exe

AddRemove-09_Hsp - c:\program files\Samsung\USB Drivers\09_Hsp\Uninstall.exe

AddRemove-11_HSP_Plus_Default - c:\program files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe

AddRemove-12_Symbian_USB_Download_Driver - c:\program files\Samsung\USB Drivers\12_Symbian_USB_Download_Driver\Uninstall.exe

AddRemove-15_Symbian_Samsung_PC_DLC_Driver - c:\program files\Samsung\USB Drivers\15_Symbian_Samsung_PC_DLC_Driver\Uninstall.exe

AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe

AddRemove-17_EMP_Chipset2 - c:\program files\Samsung\USB Drivers\17_EMP_Chipset2\Uninstall.exe

AddRemove-18_Zinia_Serial_Driver - c:\program files\Samsung\USB Drivers\18_Zinia_Serial_Driver\Uninstall.exe

AddRemove-19_VIA_driver - c:\program files\Samsung\USB Drivers\19_VIA_driver\Uninstall.exe

AddRemove-20_NXP_Driver - c:\program files\Samsung\USB Drivers\20_NXP_Driver\Uninstall.exe

AddRemove-21_Searsburg - c:\program files\Samsung\USB Drivers\21_Searsburg\Uninstall.exe

AddRemove-22_WiBro_WiMAX - c:\program files\Samsung\USB Drivers\22_WiBro_WiMAX\Uninstall.exe

AddRemove-24_flashusbdriver - c:\program files\Samsung\USB Drivers\24_flashusbdriver\Uninstall.exe

AddRemove-25_escape - c:\program files\Samsung\USB Drivers\25_escape\Uninstall.exe

AddRemove-26_VIA_driver2 - c:\program files\Samsung\USB Drivers\26_VIA_driver2\Uninstall.exe

.

.

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

------------------------ Other Running Processes ------------------------

.

c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

c:\windows\system32\taskhost.exe

c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

c:\windows\system32\taskhost.exe

c:\windows\system32\conhost.exe

c:\windows\system32\sppsvc.exe

c:\program files\Windows Media Player\wmpnetwk.exe

c:\windows\system32\taskhost.exe

.

**************************************************************************

.

Completion time: 2012-03-12 03:06:04 - machine was rebooted

ComboFix-quarantined-files.txt 2012-03-12 01:06

.

Pre-Run: 33 265 348 608 bytes free

Post-Run: 33 823 481 856 bytes free

.

- - End Of File - - 5B87BA3E65743A5E42129253E33EF762

Това е от файла. Предполагам, че трябва да инсталирам наново AVG и да сканирам с AVG и със Malwarebytes Anti-Malware. Ама ще изчакам утре сутринта, какво ще кажете, че не искам да прецакам нещата.

Редактирано от mude (преглед на промените)

Тук имаме още малко работа:

Изтеглете и инсталирайте Erunt.

Оставете настройките по подразбиране и направете бекъп на регистрите.

  • Отворете notepad и с copy/paste въведете следната информация:

    Windows Registry Editor Version 5.00
    
    [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionSvchost]
    "netsvcs"=hex(7):41,00,65,00,4c,00,6f,00,6f,00,6b,00,75,00,70,00,53,00,76,00,
      63,00,00,00,43,00,65,00,72,00,74,00,50,00,72,00,6f,00,70,00,53,00,76,00,63,
      00,00,00,53,00,43,00,50,00,6f,00,6c,00,69,00,63,00,79,00,53,00,76,00,63,00,
      00,00,6c,00,61,00,6e,00,6d,00,61,00,6e,00,73,00,65,00,72,00,76,00,65,00,72,
      00,00,00,67,00,70,00,73,00,76,00,63,00,00,00,49,00,4b,00,45,00,45,00,58,00,
      54,00,00,00,41,00,75,00,64,00,69,00,6f,00,53,00,72,00,76,00,00,00,46,00,61,
      00,73,00,74,00,55,00,73,00,65,00,72,00,53,00,77,00,69,00,74,00,63,00,68,00,
      69,00,6e,00,67,00,43,00,6f,00,6d,00,70,00,61,00,74,00,69,00,62,00,69,00,6c,
      00,69,00,74,00,79,00,00,00,49,00,61,00,73,00,00,00,49,00,72,00,6d,00,6f,00,
      6e,00,00,00,4e,00,6c,00,61,00,00,00,4e,00,74,00,6d,00,73,00,73,00,76,00,63,
      00,00,00,4e,00,57,00,43,00,57,00,6f,00,72,00,6b,00,73,00,74,00,61,00,74,00,
      69,00,6f,00,6e,00,00,00,4e,00,77,00,73,00,61,00,70,00,61,00,67,00,65,00,6e,
      00,74,00,00,00,52,00,61,00,73,00,61,00,75,00,74,00,6f,00,00,00,52,00,61,00,
      73,00,6d,00,61,00,6e,00,00,00,52,00,65,00,6d,00,6f,00,74,00,65,00,61,00,63,
      00,63,00,65,00,73,00,73,00,00,00,53,00,45,00,4e,00,53,00,00,00,53,00,68,00,
      61,00,72,00,65,00,64,00,61,00,63,00,63,00,65,00,73,00,73,00,00,00,53,00,52,
      00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,00,00,54,00,61,00,70,00,69,00,
      73,00,72,00,76,00,00,00,57,00,6d,00,69,00,00,00,57,00,6d,00,64,00,6d,00,50,
      00,6d,00,53,00,70,00,00,00,54,00,65,00,72,00,6d,00,53,00,65,00,72,00,76,00,
      69,00,63,00,65,00,00,00,77,00,75,00,61,00,75,00,73,00,65,00,72,00,76,00,00,
      00,42,00,49,00,54,00,53,00,00,00,53,00,68,00,65,00,6c,00,6c,00,48,00,57,00,
      44,00,65,00,74,00,65,00,63,00,74,00,69,00,6f,00,6e,00,00,00,4c,00,6f,00,67,
      00,6f,00,6e,00,48,00,6f,00,75,00,72,00,73,00,00,00,50,00,43,00,41,00,75,00,
      64,00,69,00,74,00,00,00,68,00,65,00,6c,00,70,00,73,00,76,00,63,00,00,00,75,
      00,70,00,6c,00,6f,00,61,00,64,00,6d,00,67,00,72,00,00,00,69,00,70,00,68,00,
      6c,00,70,00,73,00,76,00,63,00,00,00,73,00,65,00,63,00,6c,00,6f,00,67,00,6f,
      00,6e,00,00,00,41,00,70,00,70,00,49,00,6e,00,66,00,6f,00,00,00,6d,00,73,00,
      69,00,73,00,63,00,73,00,69,00,00,00,4d,00,4d,00,43,00,53,00,53,00,00,00,77,
      00,65,00,72,00,63,00,70,00,6c,00,73,00,75,00,70,00,70,00,6f,00,72,00,74,00,
      00,00,45,00,61,00,70,00,48,00,6f,00,73,00,74,00,00,00,50,00,72,00,6f,00,66,
      00,53,00,76,00,63,00,00,00,73,00,63,00,68,00,65,00,64,00,75,00,6c,00,65,00,
      00,00,68,00,6b,00,6d,00,73,00,76,00,63,00,00,00,53,00,65,00,73,00,73,00,69,
      00,6f,00,6e,00,45,00,6e,00,76,00,00,00,77,00,69,00,6e,00,6d,00,67,00,6d,00,
      74,00,00,00,62,00,72,00,6f,00,77,00,73,00,65,00,72,00,00,00,54,00,68,00,65,
      00,6d,00,65,00,73,00,00,00,42,00,44,00,45,00,53,00,56,00,43,00,00,00,41,00,
      70,00,70,00,4d,00,67,00,6d,00,74,00,00,00,00,00
    
  • Запазете файла с името fix.reg.
  • Файла трябва да изглежда така - Публикувано изображение
  • Стартирайте го и изберете YES на диалоговия прозорец.

  • Отворете notepad и с copy/paste въведете следната информация:

    KILLALL::
    File::
    c:windowssystem32dds_log_ad13.cmd
    c:program filesBS_PlayertbBS_P.dll
    Folder::
    c:usersMartinAppDataLocal917060d7
    DirLook::
    c:windowssystem32%APPDATA%
    Registry::
    [HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerURLSearchHooks]
    "{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"=-
    [-HKEY_CLASSES_ROOTclsid{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
    [-HKEY_LOCAL_MACHINE~Browser Helper Objects{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
    [HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolbar]
    "{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"=-
    [-HKEY_CLASSES_ROOTclsid{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
    [HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerToolbarWebbrowser]
    "{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}"=-
    [-HKEY_CLASSES_ROOTclsid{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
    RegLock::
    [HKEY_LOCAL_MACHINEsystemControlSet001ControlClass{4D36E96D-E325-11CE-BFC1-08002BE10318}0000AllUserSettings]
    [HKEY_LOCAL_MACHINEsystemControlSet001ControlClass{4D36E96D-E325-11CE-BFC1-08002BE10318}0001AllUserSettings]
    [HKEY_LOCAL_MACHINEsystemControlSet001ControlPCWSecurity]
    
  • Запазете файла с име CFScript и го провлачете и пуснете в Combofix (както е показано на картинката отдолу).

    Публикувано изображение

  • По време на сканиране от страна на ComboFix не стартирайте никакви други приложения, не натискайте клавиши от клавиатурата и не местете мишката !
  • Публикувайте лог файла, който ще се създаде след рестарта на компютъра в следващия си пост.
  • Автор

ComboFix 12-03-11.01 - Martin 03.2012 г. 9:56.2.2 - x86

Microsoft Windows 7 Ultimate 6.1.7601.1.1251.359.1033.18.2038.1014 [GMT 2:00]

Running from: c:\users\Martin\Desktop\ComboFix.exe

Command switches used :: c:\users\Martin\Desktop\CFScript.txt

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

FILE ::

"c:\program files\BS_Player\tbBS_P.dll"

"c:\windows\system32\dds_log_ad13.cmd"

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\program files\BS_Player\tbBS_P.dll

c:\users\Martin\AppData\Local\917060d7

c:\users\Martin\AppData\Local\917060d7\@

c:\users\Martin\AppData\Local\917060d7\loader.tlb

c:\users\Martin\AppData\Local\Temp\08f56ff6-864d-4a92-944a-57b870198cb2\CliSecureRT.dll

c:\windows\system32\dds_log_ad13.cmd

.

.

((((((((((((((((((((((((( Files Created from 2012-02-12 to 2012-03-12 )))))))))))))))))))))))))))))))

.

.

2012-03-12 08:01 . 2012-03-12 08:01 -------- d-----w- c:\users\Default\AppData\Local\temp

2012-03-12 07:47 . 2012-03-12 07:47 -------- d-----w- c:\program files\ERUNT

2012-03-12 01:01 . 2012-03-12 08:02 -------- d-----w- c:\users\Martin\AppData\Local\temp

2012-03-11 22:05 . 2012-03-11 22:05 -------- d-sh--w- c:\windows\system32\%APPDATA%

2012-03-10 15:03 . 2006-12-08 10:02 251672 ----a-w- c:\windows\system32\xactengine2_5.dll

2012-03-10 15:03 . 2006-11-29 11:06 440080 ----a-w- c:\windows\system32\d3dx10.dll

2012-03-10 15:03 . 2006-11-29 11:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll

2012-03-10 15:03 . 2006-09-28 14:05 237848 ----a-w- c:\windows\system32\xactengine2_4.dll

2012-03-10 15:03 . 2006-09-28 14:05 2414360 ----a-w- c:\windows\system32\d3dx9_31.dll

2012-03-10 15:03 . 2006-07-28 07:30 236824 ----a-w- c:\windows\system32\xactengine2_3.dll

2012-03-10 15:03 . 2006-07-28 07:30 62744 ----a-w- c:\windows\system32\xinput1_2.dll

2012-02-16 17:04 . 2011-12-30 05:27 478720 ----a-w- c:\windows\system32\timedate.cpl

2012-02-16 17:04 . 2011-12-16 07:52 690688 ----a-w- c:\windows\system32\msvcrt.dll

2012-02-16 17:04 . 2012-01-04 08:58 442880 ----a-w- c:\windows\system32\ntshrui.dll

2012-02-16 17:04 . 2012-01-14 03:35 2343424 ----a-w- c:\windows\system32\win32k.sys

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-03-11 22:01 . 2011-06-01 17:39 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2012-02-18 03:56 . 2011-07-16 18:02 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll

.

.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))

.

---- Directory of c:\windows\system32\%APPDATA% ----

.

2012-03-11 22:05 . 2012-03-11 23:25 262144 --sha-w- c:\windows\system32\%APPDATA%\Microsoft\Windows\IETldCache\index.dat

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]

"OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2009-04-17 95536]

"KiesHelper"="c:\program files\Samsung\Kies\KiesHelper.exe" [2012-02-03 943504]

"KiesTrayAgent"="c:\program files\Samsung\Kies\KiesTrayAgent.exe" [2012-02-03 3508624]

"KiesPDLR"="c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2012-02-03 21392]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"WinampAgent"="c:\program files\Winamp\winampa.exe" [2010-07-12 74752]

"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 173592]

"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 150552]

"OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" [2009-04-17 54576]

"KiesTrayAgent"="c:\program files\Samsung\Kies\KiesTrayAgent.exe" [2012-02-03 3508624]

"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2012-01-13 981680]

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]

.

c:\users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

FlexType 2K.lnk - c:\program files\Datecs\FlexType 2K\FType2K.exe [2010-7-27 95232]

GoGear SA3MXX Device Manager.lnk - c:\program files\Philips\GoGear SA3MXX Device Manager\main.exe [2011-8-11 124880]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"aux"=wdmaud.drv

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

.

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

R2 gupdate;Ус»уі° Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-07-27 136176]

R3 cpuz135;cpuz135;c:\windows\TEMP\cpuz135\cpuz135_x32.sys [x]

R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [x]

R3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [2011-01-13 129440]

R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-07-27 136176]

R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]

R3 rockusb;Driver for rockusb Device;c:\windows\system32\DRIVERS\rockusb.sys [2010-03-09 80680]

R3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM);c:\windows\system32\DRIVERS\sscebus.sys [2010-04-27 98560]

R3 sscemdfl;SAMSUNG Mobile Modem V2 Filter;c:\windows\system32\DRIVERS\sscemdfl.sys [2010-04-27 14848]

R3 sscemdm;SAMSUNG Mobile Modem V2 Drivers;c:\windows\system32\DRIVERS\sscemdm.sys [2010-04-27 123648]

R3 ssceserd;SAMSUNG Mobile Modem Diagnostic Serial Port V2 (WDM);c:\windows\system32\DRIVERS\ssceserd.sys [2010-04-27 100352]

R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]

R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]

R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-07-27 1343400]

S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-07-27 691696]

S1 archlp;archlp;c:\windows\system32\drivers\archlp.sys [2009-08-13 91264]

S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]

S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-07-26 217088]

S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2010-07-26 36640]

S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-03-01 139776]

.

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

getPlusHelper REG_MULTI_SZ getPlusHelper

.

Contents of the 'Scheduled Tasks' folder

.

2012-03-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-27 11:58]

.

2012-03-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-27 11:58]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.google.bg/

uInternet Settings,ProxyOverride = <local>

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

IE: {{60237576-b24c-4ba9-9740-c9f3ec9db557} - {EAADF17C-B6EA-4511-8549-A67CFD406EAF} - c:\progra~1\SkyCode\WEBTRA~1\wt2ie.dll

TCP: DhcpNameServer = 85.217.128.241 87.121.223.9

FF - ProfilePath - c:\users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\e72k9gu4.default\

FF - prefs.js: browser.startup.homepage - www.google.bg

FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7Bc0749cf5-71d9-445c-914c-6855046c0e65%7D&mid=fa1492f26651b6517dbb7e738461ca3b-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&ds=AVG&v=10.0.0.7&lang=us&pr=pa&d=2011-12-07%2009%3A05%3A44&sap=ku&q=

.

.

------------------------ Other Running Processes ------------------------

.

c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

c:\windows\system32\taskhost.exe

c:\windows\system32\taskhost.exe

c:\windows\system32\conhost.exe

c:\windows\system32\sppsvc.exe

c:\program files\Windows Media Player\wmpnetwk.exe

.

**************************************************************************

.

Completion time: 2012-03-12 10:05:23 - machine was rebooted

ComboFix-quarantined-files.txt 2012-03-12 08:05

.

Pre-Run: 33 734 844 416 bytes free

Post-Run: 33 641 578 496 bytes free

.

- - End Of File - - C474D066EB3FF37B215D86BF02B6EEC7

Понеже след края отново ми пишеше на всичко "illegal operation on a registry key that has been marked for deletion" и рестартиах компютъра и след като се стартира излезе прозорез, че регистрите на ERUNT май бяха 4,5,6 и 7 няма да се запаметят.

Няма проблеми. Той Erunt си свърши своята работа. Трябваше ми той да направи бекъп преди да стартирате fix.reg. :)

Сега да направим малко задължителни проверки:

СТЪПКА 1

Моля изтрийте вашата версия на TDSSKiller и изтеглете последната версия оттук и я запазете на вашия декстоп.

  • Стартирайте TDSSKiller.exe за да стартирате приложението. След това кликнете върху бутона Change parameters.

    Публикувано изображение

  • Сложете отметки пред Verify Driver Digital Signature и Detect TDLFS file system и натиснете ОК.

    Публикувано изображение

  • Натиснете бутона Start Scan.

    Публикувано изображение

  • Ако подозрителен обект бъде засечен, действието по подразбиране ще бъде Skip, кликнете върху Continue.

    Публикувано изображение

  • Ако зловредни обекти бъдат намерени, тогава от падащото меню ще имате три възможности.

    Бъдете сигурни, че избраното действие е Cure и натиснете върху Continue > Рестартирайте за да бъде завършена поправката.

    Публикувано изображение

    Забележка: Ако Cure бутона не е наличен от възможностите, тогава моля изберете Skip бутона, не избирайте Delete освен ако не сте инструктирани затова.

  • Лог файл ще бъде създаден в свободната директория на дял C: . Потърсете за лог с името "TDSSKiller.[Version]_[Date]_[Time]_log.txt" и копирайте съдържанието му в следващия си пост.

СТЪПКА 2

Моля, изтеглете aswMBR и го запазете на вашия десктоп.

  • Кликнете с двоен клин на мишката върху файла aswMBR.exe за да го стартирате.
  • Изчакайте да изтегли дефинициите на avast!
  • От падащото меню посочете дял C: както е на снимката:
Публикувано изображение
  • Изберете Scan бутона, за да започне проверката.
  • Когато проверката завърши, натиснете бутона save log, запазете съдържанието на лог файла на десктопа и публикувайте съдържанието му в следващия си коментар.

СТЪПКА 3

  • Изтеглете Malwarebytes' Anti-Malware Free от тук
  • Кликнете два пъти върху mbam-setup.exe, за да инсталирате програмата.
  • Уверете се, че са поставени отметки на Update Malwarebytes' Anti-Malware и Launch Malwarebytes' Anti-Malware. След това кликнете на Finish.
  • Ако има намерени обновявания, тя ще ги изтегли и инсталира.
  • Стартирайте програмата и изберете "Perform Quick Scan", след това кликнете на Scan.
  • Сканирането ще отнеме малко време, затова моля да бъдете търпеливи.
  • Когато сканирането завърши, кликнете на OK, след това Show Results, за да видите резултата.
  • Уверете се, че на всички редове има отметки, и кликнете на Remove Selected.
  • Когато всичко бъде премахнато, в Notepad ще бъде отворен лог. Копирайте този лог и го публикувайте в следващия си коментар по темата.
Забележка: Ако MalwareBytes' Anti-Malware се затрудни в премахването на откритите вируси/заплахи, той ще поиска да рестартира компютъра Ви и по време на рестартирането да премахне проблемните вируси/заплахи. Ако бъдете попитани, потвърдете че желаете вашия компютър да бъде рестартиран.

СТЪПКА 4

Моля изтеглете Farbar Service Scanner и я стартирайте.

  • Сложете всички отметки
  • Натиснете бутона "Scan".
  • Ще се създаде лог файл с името (FSS.txt) в папката откъдето стартирате инструмента.
  • Копирайте съдържанието на лог файла в следващия си пост.

Как е положението в момента ?

  • Автор

Стъпка 1:

12:06:49.0125 3136 TDSS rootkit removing tool 2.7.20.0 Mar 9 2012 17:10:43

12:06:49.0355 3136 ============================================================

12:06:49.0355 3136 Current date / time: 2012/03/12 12:06:49.0355

12:06:49.0355 3136 SystemInfo:

12:06:49.0355 3136

12:06:49.0355 3136 OS Version: 6.1.7601 ServicePack: 1.0

12:06:49.0355 3136 Product type: Workstation

12:06:49.0355 3136 ComputerName: MY-COMPTUER

12:06:49.0356 3136 UserName: Martin

12:06:49.0356 3136 Windows directory: C:\Windows

12:06:49.0356 3136 System windows directory: C:\Windows

12:06:49.0356 3136 Processor architecture: Intel x86

12:06:49.0356 3136 Number of processors: 2

12:06:49.0356 3136 Page size: 0x1000

12:06:49.0356 3136 Boot type: Normal boot

12:06:49.0356 3136 ============================================================

12:06:50.0040 3136 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0x38080, SectorsPerTrack: 0x13, TracksPerCylinder: 0xE0, Type 'K0', Flags 0x00000050

12:06:50.0041 3136 \Device\Harddisk0\DR0:

12:06:50.0041 3136 MBR used

12:06:50.0041 3136 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000

12:06:50.0041 3136 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x74FD800

12:06:50.0052 3136 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x75304E0, BlocksNum 0x1869E559

12:06:50.0073 3136 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x1FBCEA78, BlocksNum 0x1A7B2308

12:06:50.0178 3136 Initialize success

12:06:50.0209 3136 ============================================================

12:06:53.0840 3740 ============================================================

12:06:53.0840 3740 Scan started

12:06:53.0840 3740 Mode: Manual; SigCheck; TDLFS;

12:06:53.0840 3740 ============================================================

12:06:54.0390 3740 1394ohci (1b133875b8aa8ac48969bd3458afe9f5) C:\Windows\system32\drivers\1394ohci.sys

12:06:54.0442 3740 1394ohci - ok

12:06:54.0528 3740 ACPI (cea80c80bed809aa0da6febc04733349) C:\Windows\system32\drivers\ACPI.sys

12:06:54.0543 3740 ACPI - ok

12:06:54.0634 3740 AcpiPmi (1efbc664abff416d1d07db115dcb264f) C:\Windows\system32\drivers\acpipmi.sys

12:06:54.0648 3740 AcpiPmi - ok

12:06:54.0731 3740 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys

12:06:54.0750 3740 adp94xx - ok

12:06:54.0767 3740 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys

12:06:54.0782 3740 adpahci - ok

12:06:54.0843 3740 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys

12:06:54.0857 3740 adpu320 - ok

12:06:54.0916 3740 AFD (9ebbba55060f786f0fcaa3893bfa2806) C:\Windows\system32\drivers\afd.sys

12:06:54.0932 3740 AFD - ok

12:06:54.0979 3740 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\drivers\agp440.sys

12:06:54.0991 3740 agp440 - ok

12:06:55.0060 3740 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys

12:06:55.0073 3740 aic78xx - ok

12:06:55.0118 3740 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\drivers\aliide.sys

12:06:55.0127 3740 aliide - ok

12:06:55.0146 3740 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\drivers\amdagp.sys

12:06:55.0157 3740 amdagp - ok

12:06:55.0176 3740 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\drivers\amdide.sys

12:06:55.0189 3740 amdide - ok

12:06:55.0238 3740 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys

12:06:55.0284 3740 AmdK8 - ok

12:06:55.0352 3740 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys

12:06:55.0368 3740 AmdPPM - ok

12:06:55.0399 3740 amdsata (d320bf87125326f996d4904fe24300fc) C:\Windows\system32\drivers\amdsata.sys

12:06:55.0414 3740 amdsata - ok

12:06:55.0435 3740 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys

12:06:55.0456 3740 amdsbs - ok

12:06:55.0492 3740 amdxata (46387fb17b086d16dea267d5be23a2f2) C:\Windows\system32\drivers\amdxata.sys

12:06:55.0506 3740 amdxata - ok

12:06:55.0564 3740 AppID (aea177f783e20150ace5383ee368da19) C:\Windows\system32\drivers\appid.sys

12:06:55.0663 3740 AppID - ok

12:06:55.0822 3740 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys

12:06:55.0839 3740 arc - ok

12:06:55.0915 3740 archlp (dc80b26d4a398e71775f682a5ab88127) C:\Windows\system32\drivers\archlp.sys

12:06:55.0952 3740 archlp - ok

12:06:56.0052 3740 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys

12:06:56.0071 3740 arcsas - ok

12:06:56.0176 3740 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys

12:06:56.0204 3740 AsyncMac - ok

12:06:56.0238 3740 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\drivers\atapi.sys

12:06:56.0248 3740 atapi - ok

12:06:56.0344 3740 atksgt (5b80e84af6b02ecab72dae9afee06309) C:\Windows\system32\DRIVERS\atksgt.sys

12:06:56.0350 3740 atksgt ( UnsignedFile.Multi.Generic ) - warning

12:06:56.0350 3740 atksgt - detected UnsignedFile.Multi.Generic (1)

12:06:56.0408 3740 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys

12:06:56.0425 3740 b06bdrv - ok

12:06:56.0460 3740 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys

12:06:56.0474 3740 b57nd60x - ok

12:06:56.0557 3740 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys

12:06:56.0596 3740 Beep - ok

12:06:56.0653 3740 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys

12:06:56.0695 3740 blbdrive - ok

12:06:56.0764 3740 bowser (8f2da3028d5fcbd1a060a3de64cd6506) C:\Windows\system32\DRIVERS\bowser.sys

12:06:56.0777 3740 bowser - ok

12:06:56.0802 3740 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys

12:06:56.0816 3740 BrFiltLo - ok

12:06:56.0828 3740 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys

12:06:56.0845 3740 BrFiltUp - ok

12:06:56.0926 3740 BridgeMP (77361d72a04f18809d0efb6cceb74d4b) C:\Windows\system32\DRIVERS\bridge.sys

12:06:56.0958 3740 BridgeMP - ok

12:06:57.0025 3740 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys

12:06:57.0103 3740 Brserid - ok

12:06:57.0159 3740 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys

12:06:57.0175 3740 BrSerWdm - ok

12:06:57.0187 3740 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys

12:06:57.0201 3740 BrUsbMdm - ok

12:06:57.0214 3740 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys

12:06:57.0227 3740 BrUsbSer - ok

12:06:57.0240 3740 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys

12:06:57.0254 3740 BTHMODEM - ok

12:06:57.0291 3740 catchme - ok

12:06:57.0391 3740 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys

12:06:57.0416 3740 cdfs - ok

12:06:57.0465 3740 cdrom (be167ed0fdb9c1fa1133953c18d5a6c9) C:\Windows\system32\drivers\cdrom.sys

12:06:57.0479 3740 cdrom - ok

12:06:57.0511 3740 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys

12:06:57.0526 3740 circlass - ok

12:06:57.0564 3740 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys

12:06:57.0578 3740 CLFS - ok

12:06:57.0673 3740 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys

12:06:57.0685 3740 CmBatt - ok

12:06:57.0718 3740 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\drivers\cmdide.sys

12:06:57.0728 3740 cmdide - ok

12:06:57.0770 3740 CNG (6427525d76f61d0c519b008d3680e8e7) C:\Windows\system32\Drivers\cng.sys

12:06:57.0790 3740 CNG - ok

12:06:57.0804 3740 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys

12:06:57.0814 3740 Compbatt - ok

12:06:57.0853 3740 CompositeBus (cbe8c58a8579cfe5fccf809e6f114e89) C:\Windows\system32\drivers\CompositeBus.sys

12:06:57.0868 3740 CompositeBus - ok

12:06:57.0946 3740 cpuz135 - ok

12:06:58.0000 3740 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys

12:06:58.0009 3740 crcdisk - ok

12:06:58.0058 3740 CSC (3c2177a897b4ca2788c6fb0c3fd81d4b) C:\Windows\system32\drivers\csc.sys

12:06:58.0074 3740 CSC - ok

12:06:58.0129 3740 DfsC (f024449c97ec1e464aaffda18593db88) C:\Windows\system32\Drivers\dfsc.sys

12:06:58.0154 3740 DfsC - ok

12:06:58.0186 3740 dgderdrv - ok

12:06:58.0250 3740 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys

12:06:58.0276 3740 discache - ok

12:06:58.0302 3740 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys

12:06:58.0313 3740 Disk - ok

12:06:58.0352 3740 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys

12:06:58.0366 3740 drmkaud - ok

12:06:58.0421 3740 DXGKrnl (23f5d28378a160352ba8f817bd8c71cb) C:\Windows\System32\drivers\dxgkrnl.sys

12:06:58.0442 3740 DXGKrnl - ok

12:06:58.0577 3740 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys

12:06:58.0634 3740 ebdrv - ok

12:06:58.0708 3740 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys

12:06:58.0724 3740 elxstor - ok

12:06:58.0798 3740 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\drivers\errdev.sys

12:06:58.0811 3740 ErrDev - ok

12:06:58.0854 3740 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys

12:06:58.0884 3740 exfat - ok

12:06:58.0931 3740 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys

12:06:58.0962 3740 fastfat - ok

12:06:59.0029 3740 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys

12:06:59.0043 3740 fdc - ok

12:06:59.0084 3740 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys

12:06:59.0098 3740 FileInfo - ok

12:06:59.0118 3740 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys

12:06:59.0166 3740 Filetrace - ok

12:06:59.0198 3740 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys

12:06:59.0209 3740 flpydisk - ok

12:06:59.0236 3740 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys

12:06:59.0249 3740 FltMgr - ok

12:06:59.0280 3740 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys

12:06:59.0291 3740 FsDepends - ok

12:06:59.0378 3740 FsUsbExDisk (b07663a810e861eebfd0eac7e82ca62d) C:\Windows\system32\FsUsbExDisk.SYS

12:06:59.0383 3740 FsUsbExDisk ( UnsignedFile.Multi.Generic ) - warning

12:06:59.0383 3740 FsUsbExDisk - detected UnsignedFile.Multi.Generic (1)

12:06:59.0430 3740 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys

12:06:59.0439 3740 Fs_Rec - ok

12:06:59.0498 3740 fvevol (8a73e79089b282100b9393b644cb853b) C:\Windows\system32\DRIVERS\fvevol.sys

12:06:59.0512 3740 fvevol - ok

12:06:59.0575 3740 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys

12:06:59.0585 3740 gagp30kx - ok

12:06:59.0679 3740 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys

12:06:59.0691 3740 hcw85cir - ok

12:06:59.0772 3740 HdAudAddService (a5ef29d5315111c80a5c1abad14c8972) C:\Windows\system32\drivers\HdAudio.sys

12:06:59.0790 3740 HdAudAddService - ok

12:06:59.0817 3740 HDAudBus (9036377b8a6c15dc2eec53e489d159b5) C:\Windows\system32\drivers\HDAudBus.sys

12:06:59.0831 3740 HDAudBus - ok

12:06:59.0859 3740 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys

12:06:59.0872 3740 HidBatt - ok

12:06:59.0902 3740 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys

12:06:59.0916 3740 HidBth - ok

12:06:59.0965 3740 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys

12:06:59.0980 3740 HidIr - ok

12:07:00.0027 3740 HidUsb (10c19f8290891af023eaec0832e1eb4d) C:\Windows\system32\drivers\hidusb.sys

12:07:00.0039 3740 HidUsb - ok

12:07:00.0097 3740 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\drivers\HpSAMD.sys

12:07:00.0108 3740 HpSAMD - ok

12:07:00.0196 3740 HTTP (871917b07a141bff43d76d8844d48106) C:\Windows\system32\drivers\HTTP.sys

12:07:00.0225 3740 HTTP - ok

12:07:00.0253 3740 hwpolicy (0c4e035c7f105f1299258c90886c64c5) C:\Windows\system32\drivers\hwpolicy.sys

12:07:00.0264 3740 hwpolicy - ok

12:07:00.0323 3740 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\drivers\i8042prt.sys

12:07:00.0335 3740 i8042prt - ok

12:07:00.0399 3740 iaStorV (5cd5f9a5444e6cdcb0ac89bd62d8b76e) C:\Windows\system32\drivers\iaStorV.sys

12:07:00.0415 3740 iaStorV - ok

12:07:00.0575 3740 igfx (9467514ea189475a6e7fdc5d7bde9d3f) C:\Windows\system32\DRIVERS\igdkmd32.sys

12:07:00.0665 3740 igfx - ok

12:07:00.0739 3740 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys

12:07:00.0750 3740 iirsp - ok

12:07:00.0792 3740 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\drivers\intelide.sys

12:07:00.0806 3740 intelide - ok

12:07:00.0834 3740 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys

12:07:00.0848 3740 intelppm - ok

12:07:00.0882 3740 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys

12:07:00.0919 3740 IpFilterDriver - ok

12:07:00.0971 3740 IPMIDRV (4bd7134618c1d2a27466a099062547bf) C:\Windows\system32\drivers\IPMIDrv.sys

12:07:00.0984 3740 IPMIDRV - ok

12:07:01.0038 3740 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys

12:07:01.0065 3740 IPNAT - ok

12:07:01.0096 3740 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys

12:07:01.0111 3740 IRENUM - ok

12:07:01.0147 3740 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\drivers\isapnp.sys

12:07:01.0157 3740 isapnp - ok

12:07:01.0170 3740 iScsiPrt (cb7a9abb12b8415bce5d74994c7ba3ae) C:\Windows\system32\drivers\msiscsi.sys

12:07:01.0184 3740 iScsiPrt - ok

12:07:01.0212 3740 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\drivers\kbdclass.sys

12:07:01.0222 3740 kbdclass - ok

12:07:01.0299 3740 kbdhid (9e3ced91863e6ee98c24794d05e27a71) C:\Windows\system32\drivers\kbdhid.sys

12:07:01.0311 3740 kbdhid - ok

12:07:01.0344 3740 KSecDD (f4647bb23db9038a7536cf6b68f4207f) C:\Windows\system32\Drivers\ksecdd.sys

12:07:01.0355 3740 KSecDD - ok

12:07:01.0385 3740 KSecPkg (e73cae53bbb72ba26918492c6b4c229d) C:\Windows\system32\Drivers\ksecpkg.sys

12:07:01.0397 3740 KSecPkg - ok

12:07:01.0462 3740 lirsgt (975b6cf65f44e95883f3855bae8cecaf) C:\Windows\system32\DRIVERS\lirsgt.sys

12:07:01.0466 3740 lirsgt ( UnsignedFile.Multi.Generic ) - warning

12:07:01.0466 3740 lirsgt - detected UnsignedFile.Multi.Generic (1)

12:07:01.0541 3740 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys

12:07:01.0567 3740 lltdio - ok

12:07:01.0607 3740 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys

12:07:01.0618 3740 LSI_FC - ok

12:07:01.0632 3740 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys

12:07:01.0643 3740 LSI_SAS - ok

12:07:01.0661 3740 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys

12:07:01.0672 3740 LSI_SAS2 - ok

12:07:01.0691 3740 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys

12:07:01.0702 3740 LSI_SCSI - ok

12:07:01.0728 3740 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys

12:07:01.0754 3740 luafv - ok

12:07:01.0826 3740 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys

12:07:01.0835 3740 megasas - ok

12:07:01.0870 3740 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys

12:07:01.0882 3740 MegaSR - ok

12:07:01.0963 3740 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys

12:07:01.0989 3740 Modem - ok

12:07:02.0059 3740 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys

12:07:02.0073 3740 monitor - ok

12:07:02.0108 3740 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\drivers\mouclass.sys

12:07:02.0118 3740 mouclass - ok

12:07:02.0135 3740 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys

12:07:02.0148 3740 mouhid - ok

12:07:02.0176 3740 mountmgr (fc8771f45ecccfd89684e38842539b9b) C:\Windows\system32\drivers\mountmgr.sys

12:07:02.0187 3740 mountmgr - ok

12:07:02.0215 3740 mpio (2d699fb6e89ce0d8da14ecc03b3edfe0) C:\Windows\system32\drivers\mpio.sys

12:07:02.0227 3740 mpio - ok

12:07:02.0279 3740 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys

12:07:02.0305 3740 mpsdrv - ok

12:07:02.0374 3740 MRxDAV (ceb46ab7c01c9f825f8cc6babc18166a) C:\Windows\system32\drivers\mrxdav.sys

12:07:02.0401 3740 MRxDAV - ok

12:07:02.0470 3740 mrxsmb (5d16c921e3671636c0eba3bbaac5fd25) C:\Windows\system32\DRIVERS\mrxsmb.sys

12:07:02.0488 3740 mrxsmb - ok

12:07:02.0600 3740 mrxsmb10 (6d17a4791aca19328c685d256349fefc) C:\Windows\system32\DRIVERS\mrxsmb10.sys

12:07:02.0639 3740 mrxsmb10 - ok

12:07:02.0664 3740 mrxsmb20 (b81f204d146000be76651a50670a5e9e) C:\Windows\system32\DRIVERS\mrxsmb20.sys

12:07:02.0681 3740 mrxsmb20 - ok

12:07:02.0711 3740 msahci (012c5f4e9349e711e11e0f19a8589f0a) C:\Windows\system32\drivers\msahci.sys

12:07:02.0728 3740 msahci - ok

12:07:02.0767 3740 msdsm (55055f8ad8be27a64c831322a780a228) C:\Windows\system32\drivers\msdsm.sys

12:07:02.0780 3740 msdsm - ok

12:07:02.0821 3740 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys

12:07:02.0858 3740 Msfs - ok

12:07:02.0907 3740 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys

12:07:02.0933 3740 mshidkmdf - ok

12:07:02.0946 3740 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\drivers\msisadrv.sys

12:07:02.0957 3740 msisadrv - ok

12:07:02.0987 3740 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys

12:07:03.0011 3740 MSKSSRV - ok

12:07:03.0025 3740 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys

12:07:03.0049 3740 MSPCLOCK - ok

12:07:03.0067 3740 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys

12:07:03.0092 3740 MSPQM - ok

12:07:03.0114 3740 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys

12:07:03.0125 3740 MsRPC - ok

12:07:03.0164 3740 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\drivers\mssmbios.sys

12:07:03.0174 3740 mssmbios - ok

12:07:03.0232 3740 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys

12:07:03.0257 3740 MSTEE - ok

12:07:03.0266 3740 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys

12:07:03.0280 3740 MTConfig - ok

12:07:03.0304 3740 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys

12:07:03.0314 3740 Mup - ok

12:07:03.0349 3740 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys

12:07:03.0367 3740 NativeWifiP - ok

12:07:03.0421 3740 NDIS (e7c54812a2aaf43316eb6930c1ffa108) C:\Windows\system32\drivers\ndis.sys

12:07:03.0442 3740 NDIS - ok

12:07:03.0465 3740 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys

12:07:03.0490 3740 NdisCap - ok

12:07:03.0554 3740 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys

12:07:03.0578 3740 NdisTapi - ok

12:07:03.0610 3740 Ndisuio (d8a65dafb3eb41cbb622745676fcd072) C:\Windows\system32\DRIVERS\ndisuio.sys

12:07:03.0633 3740 Ndisuio - ok

12:07:03.0664 3740 NdisWan (38fbe267e7e6983311179230facb1017) C:\Windows\system32\DRIVERS\ndiswan.sys

12:07:03.0687 3740 NdisWan - ok

12:07:03.0725 3740 NDProxy (a4bdc541e69674fbff1a8ff00be913f2) C:\Windows\system32\drivers\NDProxy.sys

12:07:03.0750 3740 NDProxy - ok

12:07:03.0831 3740 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys

12:07:03.0855 3740 NetBIOS - ok

12:07:03.0886 3740 NetBT (280122ddcf04b378edd1ad54d71c1e54) C:\Windows\system32\DRIVERS\netbt.sys

12:07:03.0913 3740 NetBT - ok

12:07:03.0958 3740 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys

12:07:03.0968 3740 nfrd960 - ok

12:07:04.0014 3740 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys

12:07:04.0040 3740 Npfs - ok

12:07:04.0098 3740 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys

12:07:04.0123 3740 nsiproxy - ok

12:07:04.0190 3740 Ntfs (81189c3d7763838e55c397759d49007a) C:\Windows\system32\drivers\Ntfs.sys

12:07:04.0218 3740 Ntfs - ok

12:07:04.0241 3740 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys

12:07:04.0266 3740 Null - ok

12:07:04.0340 3740 nvraid (b3e25ee28883877076e0e1ff877d02e0) C:\Windows\system32\drivers\nvraid.sys

12:07:04.0352 3740 nvraid - ok

12:07:04.0383 3740 nvstor (4380e59a170d88c4f1022eff6719a8a4) C:\Windows\system32\drivers\nvstor.sys

12:07:04.0396 3740 nvstor - ok

12:07:04.0450 3740 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\drivers\nv_agp.sys

12:07:04.0466 3740 nv_agp - ok

12:07:04.0496 3740 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\drivers\ohci1394.sys

12:07:04.0508 3740 ohci1394 - ok

12:07:04.0609 3740 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys

12:07:04.0625 3740 Parport - ok

12:07:04.0661 3740 partmgr (bf8f6af06da75b336f07e23aef97d93b) C:\Windows\system32\drivers\partmgr.sys

12:07:04.0672 3740 partmgr - ok

12:07:04.0705 3740 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys

12:07:04.0721 3740 Parvdm - ok

12:07:04.0767 3740 pci (673e55c3498eb970088e812ea820aa8f) C:\Windows\system32\drivers\pci.sys

12:07:04.0779 3740 pci - ok

12:07:04.0815 3740 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\drivers\pciide.sys

12:07:04.0825 3740 pciide - ok

12:07:04.0890 3740 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys

12:07:04.0903 3740 pcmcia - ok

12:07:04.0922 3740 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys

12:07:04.0933 3740 pcw - ok

12:07:04.0971 3740 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys

12:07:05.0003 3740 PEAUTH - ok

12:07:05.0071 3740 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys

12:07:05.0096 3740 PptpMiniport - ok

12:07:05.0121 3740 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys

12:07:05.0132 3740 Processor - ok

12:07:05.0166 3740 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys

12:07:05.0193 3740 Psched - ok

12:07:05.0241 3740 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys

12:07:05.0271 3740 ql2300 - ok

12:07:05.0325 3740 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys

12:07:05.0335 3740 ql40xx - ok

12:07:05.0370 3740 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys

12:07:05.0384 3740 QWAVEdrv - ok

12:07:05.0404 3740 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys

12:07:05.0428 3740 RasAcd - ok

12:07:05.0457 3740 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys

12:07:05.0481 3740 RasAgileVpn - ok

12:07:05.0500 3740 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys

12:07:05.0525 3740 Rasl2tp - ok

12:07:05.0560 3740 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys

12:07:05.0586 3740 RasPppoe - ok

12:07:05.0650 3740 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys

12:07:05.0674 3740 RasSstp - ok

12:07:05.0729 3740 rdbss (d528bc58a489409ba40334ebf96a311b) C:\Windows\system32\DRIVERS\rdbss.sys

12:07:05.0756 3740 rdbss - ok

12:07:05.0769 3740 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys

12:07:05.0785 3740 rdpbus - ok

12:07:05.0821 3740 RDPCDD (23dae03f29d253ae74c44f99e515f9a1) C:\Windows\system32\DRIVERS\RDPCDD.sys

12:07:05.0845 3740 RDPCDD - ok

12:07:05.0879 3740 RDPDR (b973fcfc50dc1434e1970a146f7e3885) C:\Windows\system32\drivers\rdpdr.sys

12:07:05.0893 3740 RDPDR - ok

12:07:05.0960 3740 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys

12:07:05.0987 3740 RDPENCDD - ok

12:07:06.0018 3740 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys

12:07:06.0045 3740 RDPREFMP - ok

12:07:06.0113 3740 RdpVideoMiniport (68a0387f58e226deee23d9715955572a) C:\Windows\system32\drivers\rdpvideominiport.sys

12:07:06.0126 3740 RdpVideoMiniport - ok

12:07:06.0164 3740 RDPWD (288b06960d78428ff89e811632684e20) C:\Windows\system32\drivers\RDPWD.sys

12:07:06.0195 3740 RDPWD - ok

12:07:06.0265 3740 rdyboost (518395321dc96fe2c9f0e96ac743b656) C:\Windows\system32\drivers\rdyboost.sys

12:07:06.0281 3740 rdyboost - ok

12:07:06.0323 3740 rockusb (07cf2d08a49d6aba475d00c7e7e4186b) C:\Windows\system32\DRIVERS\rockusb.sys

12:07:06.0335 3740 rockusb - ok

12:07:06.0411 3740 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys

12:07:06.0440 3740 rspndr - ok

12:07:06.0513 3740 RTL8167 (3983cea05bb855351d75f5482b6c42ce) C:\Windows\system32\DRIVERS\Rt86win7.sys

12:07:06.0548 3740 RTL8167 - ok

12:07:06.0620 3740 s3cap (7fa7f2e249a5dcbb7970630e15e1f482) C:\Windows\system32\drivers\vms3cap.sys

12:07:06.0645 3740 s3cap - ok

12:07:06.0720 3740 sbp2port (05d860da1040f111503ac416ccef2bca) C:\Windows\system32\drivers\sbp2port.sys

12:07:06.0734 3740 sbp2port - ok

12:07:06.0775 3740 scfilter (0693b5ec673e34dc147e195779a4dcf6) C:\Windows\system32\DRIVERS\scfilter.sys

12:07:06.0805 3740 scfilter - ok

12:07:06.0869 3740 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys

12:07:06.0895 3740 secdrv - ok

12:07:06.0966 3740 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys

12:07:06.0986 3740 Serenum - ok

12:07:07.0004 3740 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys

12:07:07.0027 3740 Serial - ok

12:07:07.0063 3740 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys

12:07:07.0085 3740 sermouse - ok

12:07:07.0152 3740 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\drivers\sffdisk.sys

12:07:07.0164 3740 sffdisk - ok

12:07:07.0175 3740 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\drivers\sffp_mmc.sys

12:07:07.0192 3740 sffp_mmc - ok

12:07:07.0217 3740 sffp_sd (6d4ccaedc018f1cf52866bbbaa235982) C:\Windows\system32\drivers\sffp_sd.sys

12:07:07.0237 3740 sffp_sd - ok

12:07:07.0259 3740 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys

12:07:07.0274 3740 sfloppy - ok

12:07:07.0337 3740 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\drivers\sisagp.sys

12:07:07.0349 3740 sisagp - ok

12:07:07.0375 3740 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys

12:07:07.0386 3740 SiSRaid2 - ok

12:07:07.0402 3740 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys

12:07:07.0415 3740 SiSRaid4 - ok

12:07:07.0435 3740 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys

12:07:07.0464 3740 Smb - ok

12:07:07.0533 3740 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys

12:07:07.0543 3740 spldr - ok

12:07:07.0656 3740 sptd (cdddec541bc3c96f91ecb48759673505) C:\Windows\system32\Drivers\sptd.sys

12:07:07.0656 3740 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505

12:07:07.0665 3740 sptd ( LockedFile.Multi.Generic ) - warning

12:07:07.0666 3740 sptd - detected LockedFile.Multi.Generic (1)

12:07:07.0706 3740 srv (e4c2764065d66ea1d2d3ebc28fe99c46) C:\Windows\system32\DRIVERS\srv.sys

12:07:07.0721 3740 srv - ok

12:07:07.0759 3740 srv2 (03f0545bd8d4c77fa0ae1ceedfcc71ab) C:\Windows\system32\DRIVERS\srv2.sys

12:07:07.0776 3740 srv2 - ok

12:07:07.0807 3740 srvnet (be6bd660caa6f291ae06a718a4fa8abc) C:\Windows\system32\DRIVERS\srvnet.sys

12:07:07.0823 3740 srvnet - ok

12:07:07.0882 3740 sscebus (b2063ce662af3ab20045121a5b716df6) C:\Windows\system32\DRIVERS\sscebus.sys

12:07:07.0896 3740 sscebus - ok

12:07:07.0937 3740 sscemdfl (66799dc0afe3dcaf8368cae17394a762) C:\Windows\system32\DRIVERS\sscemdfl.sys

12:07:07.0950 3740 sscemdfl - ok

12:07:07.0968 3740 sscemdm (cbf03ffc08f8db547bab2f79aa663d16) C:\Windows\system32\DRIVERS\sscemdm.sys

12:07:07.0982 3740 sscemdm - ok

12:07:08.0018 3740 ssceserd (60cd4ad33aa52e58faac3abad18cf8ef) C:\Windows\system32\DRIVERS\ssceserd.sys

12:07:08.0031 3740 ssceserd - ok

12:07:08.0129 3740 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys

12:07:08.0141 3740 stexstor - ok

12:07:08.0183 3740 storflt (472af0311073dceceaa8fa18ba2bdf89) C:\Windows\system32\drivers\vmstorfl.sys

12:07:08.0197 3740 storflt - ok

12:07:08.0214 3740 storvsc (dcaffd62259e0bdb433dd67b5bb37619) C:\Windows\system32\drivers\storvsc.sys

12:07:08.0227 3740 storvsc - ok

12:07:08.0248 3740 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\drivers\swenum.sys

12:07:08.0261 3740 swenum - ok

12:07:08.0289 3740 Synth3dVsc - ok

12:07:08.0389 3740 Tcpip (65d10b191c59c5501a1263fc33f6894b) C:\Windows\system32\drivers\tcpip.sys

12:07:08.0423 3740 Tcpip - ok

12:07:08.0515 3740 TCPIP6 (65d10b191c59c5501a1263fc33f6894b) C:\Windows\system32\DRIVERS\tcpip.sys

12:07:08.0555 3740 TCPIP6 - ok

12:07:08.0617 3740 tcpipreg (cca24162e055c3714ce5a88b100c64ed) C:\Windows\system32\drivers\tcpipreg.sys

12:07:08.0651 3740 tcpipreg - ok

12:07:08.0695 3740 TDPIPE (1cb91b2bd8f6dd367dfc2ef26fd751b2) C:\Windows\system32\drivers\tdpipe.sys

12:07:08.0727 3740 TDPIPE - ok

12:07:08.0765 3740 TDTCP (2c10395baa4847f83042813c515cc289) C:\Windows\system32\drivers\tdtcp.sys

12:07:08.0792 3740 TDTCP - ok

12:07:08.0822 3740 tdx (b459575348c20e8121d6039da063c704) C:\Windows\system32\DRIVERS\tdx.sys

12:07:08.0864 3740 tdx - ok

12:07:08.0913 3740 TermDD (04dbf4b01ea4bf25a9a3e84affac9b20) C:\Windows\system32\drivers\termdd.sys

12:07:08.0923 3740 TermDD - ok

12:07:09.0035 3740 tssecsrv (254bb140eee3c59d6114c1a86b636877) C:\Windows\system32\DRIVERS\tssecsrv.sys

12:07:09.0059 3740 tssecsrv - ok

12:07:09.0099 3740 TsUsbFlt (fd1d6c73e6333be727cbcc6054247654) C:\Windows\system32\drivers\tsusbflt.sys

12:07:09.0112 3740 TsUsbFlt - ok

12:07:09.0121 3740 tsusbhub - ok

12:07:09.0160 3740 tunnel (b2fa25d9b17a68bb93d58b0556e8c90d) C:\Windows\system32\DRIVERS\tunnel.sys

12:07:09.0184 3740 tunnel - ok

12:07:09.0212 3740 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys

12:07:09.0223 3740 uagp35 - ok

12:07:09.0264 3740 udfs (ee43346c7e4b5e63e54f927babbb32ff) C:\Windows\system32\DRIVERS\udfs.sys

12:07:09.0292 3740 udfs - ok

12:07:09.0388 3740 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\drivers\uliagpkx.sys

12:07:09.0400 3740 uliagpkx - ok

12:07:09.0435 3740 umbus (d295bed4b898f0fd999fcfa9b32b071b) C:\Windows\system32\drivers\umbus.sys

12:07:09.0451 3740 umbus - ok

12:07:09.0476 3740 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys

12:07:09.0491 3740 UmPass - ok

12:07:09.0541 3740 usbccgp (bd9c55d7023c5de374507acc7a14e2ac) C:\Windows\system32\drivers\usbccgp.sys

12:07:09.0555 3740 usbccgp - ok

12:07:09.0626 3740 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\drivers\usbcir.sys

12:07:09.0644 3740 usbcir - ok

12:07:09.0670 3740 usbehci (f92de757e4b7ce9c07c5e65423f3ae3b) C:\Windows\system32\DRIVERS\usbehci.sys

12:07:09.0683 3740 usbehci - ok

12:07:09.0715 3740 usbhub (8dc94aec6a7e644a06135ae7506dc2e9) C:\Windows\system32\DRIVERS\usbhub.sys

12:07:09.0730 3740 usbhub - ok

12:07:09.0750 3740 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\Windows\system32\DRIVERS\usbohci.sys

12:07:09.0761 3740 usbohci - ok

12:07:09.0780 3740 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys

12:07:09.0793 3740 usbprint - ok

12:07:09.0831 3740 USBSTOR (f991ab9cc6b908db552166768176896a) C:\Windows\system32\DRIVERS\USBSTOR.SYS

12:07:09.0843 3740 USBSTOR - ok

12:07:09.0933 3740 usbuhci (68df884cf41cdada664beb01daf67e3d) C:\Windows\system32\DRIVERS\usbuhci.sys

12:07:09.0949 3740 usbuhci - ok

12:07:10.0011 3740 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\drivers\vdrvroot.sys

12:07:10.0022 3740 vdrvroot - ok

12:07:10.0048 3740 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys

12:07:10.0062 3740 vga - ok

12:07:10.0084 3740 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys

12:07:10.0111 3740 VgaSave - ok

12:07:10.0174 3740 VGPU - ok

12:07:10.0212 3740 vhdmp (5461686cca2fda57b024547733ab42e3) C:\Windows\system32\drivers\vhdmp.sys

12:07:10.0224 3740 vhdmp - ok

12:07:10.0248 3740 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\drivers\viaagp.sys

12:07:10.0258 3740 viaagp - ok

12:07:10.0276 3740 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys

12:07:10.0289 3740 ViaC7 - ok

12:07:10.0320 3740 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\drivers\viaide.sys

12:07:10.0334 3740 viaide - ok

12:07:10.0358 3740 vmbus (c2f2911156fdc7817c52829c86da494e) C:\Windows\system32\drivers\vmbus.sys

12:07:10.0373 3740 vmbus - ok

12:07:10.0401 3740 VMBusHID (d4d77455211e204f370d08f4963063ce) C:\Windows\system32\drivers\VMBusHID.sys

12:07:10.0413 3740 VMBusHID - ok

12:07:10.0495 3740 volmgr (4c63e00f2f4b5f86ab48a58cd990f212) C:\Windows\system32\drivers\volmgr.sys

12:07:10.0504 3740 volmgr - ok

12:07:10.0534 3740 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys

12:07:10.0547 3740 volmgrx - ok

12:07:10.0582 3740 volsnap (f497f67932c6fa693d7de2780631cfe7) C:\Windows\system32\drivers\volsnap.sys

12:07:10.0595 3740 volsnap - ok

12:07:10.0624 3740 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys

12:07:10.0643 3740 vsmraid - ok

12:07:10.0683 3740 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys

12:07:10.0699 3740 vwifibus - ok

12:07:10.0783 3740 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys

12:07:10.0795 3740 WacomPen - ok

12:07:10.0838 3740 WANARP (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys

12:07:10.0865 3740 WANARP - ok

12:07:10.0870 3740 Wanarpv6 (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys

12:07:10.0894 3740 Wanarpv6 - ok

12:07:10.0958 3740 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys

12:07:10.0967 3740 Wd - ok

12:07:11.0000 3740 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys

12:07:11.0016 3740 Wdf01000 - ok

12:07:11.0093 3740 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys

12:07:11.0121 3740 WfpLwf - ok

12:07:11.0141 3740 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys

12:07:11.0152 3740 WIMMount - ok

12:07:11.0229 3740 WinUsb (a67e5f9a400f3bd1be3d80613b45f708) C:\Windows\system32\DRIVERS\WinUsb.sys

12:07:11.0243 3740 WinUsb - ok

12:07:11.0330 3740 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\drivers\wmiacpi.sys

12:07:11.0342 3740 WmiAcpi - ok

12:07:11.0397 3740 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys

12:07:11.0421 3740 ws2ifsl - ok

12:07:11.0486 3740 WudfPf (e714a1c0354636837e20ccbf00888ee7) C:\Windows\system32\drivers\WudfPf.sys

12:07:11.0511 3740 WudfPf - ok

12:07:11.0547 3740 WUDFRd (1023ee888c9b47178c5293ed5336ab69) C:\Windows\system32\DRIVERS\WUDFRd.sys

12:07:11.0574 3740 WUDFRd - ok

12:07:11.0628 3740 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0

12:07:11.0789 3740 \Device\Harddisk0\DR0 - ok

12:07:11.0793 3740 Boot (0x1200) (be531e378ff6a3a33a0790926649c778) \Device\Harddisk0\DR0\Partition0

12:07:11.0794 3740 \Device\Harddisk0\DR0\Partition0 - ok

12:07:11.0830 3740 Boot (0x1200) (6571c9a4c871db8f1419655d2fba1707) \Device\Harddisk0\DR0\Partition1

12:07:11.0831 3740 \Device\Harddisk0\DR0\Partition1 - ok

12:07:11.0834 3740 Boot (0x1200) (14e9e8a6cc2e7763b7569e976a542418) \Device\Harddisk0\DR0\Partition2

12:07:11.0835 3740 \Device\Harddisk0\DR0\Partition2 - ok

12:07:11.0862 3740 Boot (0x1200) (99a1d8058bedb15e04da1aaeab4f5891) \Device\Harddisk0\DR0\Partition3

12:07:11.0863 3740 \Device\Harddisk0\DR0\Partition3 - ok

12:07:11.0863 3740 ============================================================

12:07:11.0863 3740 Scan finished

12:07:11.0863 3740 ============================================================

12:07:11.0879 3724 Detected object count: 4

12:07:11.0879 3724 Actual detected object count: 4

12:07:27.0916 3724 atksgt ( UnsignedFile.Multi.Generic ) - skipped by user

12:07:27.0916 3724 atksgt ( UnsignedFile.Multi.Generic ) - User select action: Skip

12:07:27.0924 3724 FsUsbExDisk ( UnsignedFile.Multi.Generic ) - skipped by user

12:07:27.0924 3724 FsUsbExDisk ( UnsignedFile.Multi.Generic ) - User select action: Skip

12:07:27.0928 3724 lirsgt ( UnsignedFile.Multi.Generic ) - skipped by user

12:07:27.0928 3724 lirsgt ( UnsignedFile.Multi.Generic ) - User select action: Skip

12:07:27.0931 3724 sptd ( LockedFile.Multi.Generic ) - skipped by user

12:07:27.0931 3724 sptd ( LockedFile.Multi.Generic ) - User select action: Skip

Стъпка 2 :

aswMBR version 0.9.9.1649 Copyright© 2011 AVAST Software

Run date: 2012-03-12 12:12:27

-----------------------------

12:12:27.169 OS Version: Windows 6.1.7601 Service Pack 1

12:12:27.169 Number of processors: 2 586 0x170A

12:12:27.170 ComputerName: MY-COMPTUER UserName: Martin

12:12:27.344 Initialize success

12:13:13.736 AVAST engine defs: 12031200

12:14:12.829 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2

12:14:12.832 Disk 0 Vendor: Hitachi_HDP725050GLA360 GM4OA5CA Size: 476940MB BusType: 3

12:14:12.842 Disk 0 MBR read successfully

12:14:12.845 Disk 0 MBR scan

12:14:12.850 Disk 0 Windows 7 default MBR code

12:14:12.862 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048

12:14:12.876 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 59899 MB offset 206848

12:14:12.882 Disk 0 Partition - 00 0F Extended LBA 416929 MB offset 122881185

12:14:12.897 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 199996 MB offset 122881248

12:14:12.903 Disk 0 Partition - 00 05 Extended 216932 MB offset 532474425

12:14:12.925 Disk 0 Partition 4 00 07 HPFS/NTFS NTFS 216932 MB offset 532474488

12:14:12.933 Disk 0 scanning sectors +976752000

12:14:13.008 Disk 0 scanning C:\Windows\system32\drivers

12:14:21.084 Service scanning

12:14:34.965 Service sptd C:\Windows\System32\Drivers\sptd.sys **LOCKED** 32

12:14:40.784 Modules scanning

12:14:47.659 Disk 0 trace - called modules:

12:14:47.679 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll >>UNKNOWN [0x84c691f8]<<

12:14:47.686 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85aca030]

12:14:47.693 3 CLASSPNP.SYS[89ad359e] -> nt!IofCallDriver -> [0x859f6760]

12:14:47.701 5 ACPI.sys[8934d3d4] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-2[0x859e5338]

12:14:47.707 \Driver\atapi[0x859d0730] -> IRP_MJ_CREATE -> 0x84c691f8

12:14:48.130 AVAST engine scan C:\

12:22:02.895 File: C:\Qoobox\Quarantine\C\Users\Martin\AppData\Local\917060d7\U\[email protected] **INFECTED** Win64:Sirefef-A [Trj]

12:22:03.372 File: C:\Qoobox\Quarantine\C\Users\Martin\AppData\Local\917060d7\U\[email protected] **INFECTED** Win32:Sirefef-AO [Rtk]

12:22:03.459 File: C:\Qoobox\Quarantine\C\Users\Martin\AppData\Local\917060d7\U\[email protected] **INFECTED** Win32:Trojan-gen

12:54:27.482 Scan finished successfully

12:54:39.579 Disk 0 MBR has been saved successfully to "C:\Users\Martin\Desktop\MBR.dat"

12:54:39.588 The log file has been saved successfully to "C:\Users\Martin\Desktop\aswMBR.txt"

Стъпка 3 :

Malwarebytes Anti-Malware 1.60.1.1000

www.malwarebytes.org

Версия на базата от данни: v2012.03.12.01

Windows 7 Service Pack 1 x86 NTFS

Internet Explorer 9.0.8112.16421

Martin :: MY-COMPTUER [администратор]

12.3.2012 г. 12:57:08 ч.

mbam-log-2012-03-12 (12-57-08).txt

Тип сканиране: Бързо сканиране

Включени опции за сканиране: Памет | Автоматично зареждане | Системен регистър | Файлова система | Евристики/Допълнителни | Евристики/Shuriken | PUP | PUM

Изключени опции за сканиране: P2P

Сканирани обекти: 182435

Изминало време: 3 минута(и), 58 секунда(и)

Открити процеси в паметта: 0

(Не бяха открити зловредни обекти)

Открити модули в паметта: 0

(Не бяха открити зловредни обекти)

Открити ключове в системния регистър: 0

(Не бяха открити зловредни обекти)

Открити стойности в системния регистър: 0

(Не бяха открити зловредни обекти)

Открити информационни обекти в системния регистър: 0

(Не бяха открити зловредни обекти)

Открити папки: 0

(Не бяха открити зловредни обекти)

Открити файлове: 2

C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\{E9C1E1AC-C9B2-4c85-94DE-9C1518918D02}.tlb (Rootkit.Zeroaccess) -> Поставен под карантина и изтрит успешно.

C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\{E9C1E1AC-C9B2-4c85-94DE-9C1518918D02}.tlb (Rootkit.Zeroaccess) -> Поставен под карантина и изтрит успешно.

(край)

Стъпка 4:

arbar Service Scanner Version: 01-03-2012

Ran by Martin (administrator) on 12-03-2012 at 13:03:40

Running from "C:\Users\Martin\Desktop"

Microsoft Windows 7 Ultimate Service Pack 1 (X86)

Boot Mode: Normal

****************************************************************

Internet Services:

============

Connection Status:

==============

Localhost is accessible.

LAN connected.

Google IP is accessible.

Yahoo IP is accessible.

Windows Firewall:

=============

Firewall Disabled Policy:

==================

System Restore:

============

System Restore Disabled Policy:

========================

Action Center:

============

Windows Update:

============

Windows Defender:

==============

WinDefend Service is not running. Checking service configuration:

The start type of WinDefend service is set to Demand. The default start type is Auto.

The ImagePath of WinDefend service is OK.

The ServiceDll of WinDefend service is OK.

Windows Defender Disabled Policy:

==========================

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]

"DisableAntiSpyware"=DWORD:1

File Check:

========

C:\Windows\system32\nsisvc.dll => MD5 is legit

C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit

C:\Windows\system32\dhcpcore.dll => MD5 is legit

C:\Windows\system32\Drivers\afd.sys => MD5 is legit

C:\Windows\system32\Drivers\tdx.sys => MD5 is legit

C:\Windows\system32\Drivers\tcpip.sys => MD5 is legit

C:\Windows\system32\dnsrslvr.dll => MD5 is legit

C:\Windows\system32\mpssvc.dll => MD5 is legit

C:\Windows\system32\bfe.dll => MD5 is legit

C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit

C:\Windows\system32\SDRSVC.dll => MD5 is legit

C:\Windows\system32\vssvc.exe => MD5 is legit

C:\Windows\system32\wscsvc.dll => MD5 is legit

C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit

C:\Windows\system32\wuaueng.dll => MD5 is legit

C:\Windows\system32\qmgr.dll => MD5 is legit

C:\Windows\system32\es.dll => MD5 is legit

C:\Windows\system32\cryptsvc.dll => MD5 is legit

C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit

C:\Windows\system32\svchost.exe => MD5 is legit

C:\Windows\system32\rpcss.dll => MD5 is legit

**** End of log ****

На стъпка 3 дтидода в Карантина. Трябва ли да ги изтрия от там? Ако може да попитам, каква антивирусна програма може да ми препоръчате. Мисля си за Avast, Avira и kaspersky. Сега ще рестартирам компютъра и ще пуска пак Malwarebytes Anti-Malware този път на пълно сканиране. Ако няма други стъпки, може ли да се изтрият всичките логове и файлове, които трябваше да запазя на декстопа? Много благодаря за помоща, ще пиша дали Мalwarebytes е засякло нещо на пълно сканиране и ще мислим, коят антивирусна да сваля от торенти.

Искам само една финална проверка да направим и ще ви дам финалните инструкции:

Изтеглете OTL.exe и го запазете на десктопа.

  • Стартирайте OTL (ако е необходимо, потвърдете през UAC).
  • Направете следните настройки:
  • Сложете отметка пред Scan All Users Публикувано изображение
  • Под менюто File Age изберете 90 days
  • Под менюто Standard Registryпроменете на ALL
  • Сложете отметки пред LOP и Purity Check
Под Публикувано изображение с Copy/ Paste въведете изцяло следната текстова информация (само това, което е поставено в карето):

netsvcs
msconfig
safebootminimal
safebootnetwork
%SYSTEMDRIVE%\*.*
%USERPROFILE%\*.*
%USERPROFILE%\AppData\Local\*.*
%USERPROFILE%\AppData\Roaming\*.*
%ProgramData%\*.*
%CommonProgramFiles%\*.*
%PROGRAMFILES%\*.*
%systemroot%\system32\config\systemprofile\AppData\Local\*.*
%windir%\ServiceProfiles\LocalService\AppData\Local\Temp\*.*
%windir%\ServiceProfiles\NetworkService\AppData\Local\Temp\*.*
%windir%\temp\*.*
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /90
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\system32\Spool\prtprocs\w32x86\*.dll
%systemroot%\*. /rp /s
%systemroot%\assembly\temp\*.* /S /MD5
%systemroot%\assembly\tmp\*.* /S /MD5
%systemroot%\assembly\GAC_32\*.* /S /MD5
%systemroot%\assembly\GAC_64\*.* /S /MD5
%SystemRoot%\assembly\GAC_MSIL\*.* /S /MD5
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems /s
/md5start
explorer.exe
lsass.exe
svchost.exe
wininit.exe
winlogon.exe
userinit.exe
atapi.sys
iaStor.sys
serial.sys
volsnap.sys
disk.sys
redbook.sys
i8042prt.sys
afd.sys
netbt.sys
csc.sys
tcpip.sys
hlp.dat
/md5stop
  • Натиснете маркираният в синьо бутон: Run Scan.
  • Като приключи проверката, ще се създадат два файла - OTL.Txt и Extras.Txt. Прикачете тези два файла в следващия си коментар (погледнете опцията Прикачени файлове, когато публикувате мнение).
  • Автор

Не, след натискането на F8 ми излиза това: Windows 7/Vista/Server (Pointer) Windows 7/Vista/Server Windows 7/Vista/Server (Debug - pointer) Windows 7/Vista/Server (Debug ) Windows 7/Vista/Server (No SLIC - Pointer) Windows 7/Vista/Server (No SLIC) Windows NT/2000/XP Enter Command Line

Ок, няма значение.

СТЪПКА 1

Изтеглете Autoruns и:

1) стартирайте програмата;

2) изберете Options -> Hide Microsoft and Windows Entries;

3) меню File -> Refresh;

4) меню File -> Save...;

5) запазете файла някъде с желано от вас име (във формат txt), архивирайте го с програма по желание и го прикачете към темата.

СТЪПКА 2

Натиснете Windows бутона + R => в run менюто поставете следната команда:

cmd /c driverquery /v > C:\list.txt

В C:\ ще се появи лог файла с името list.txt

Прикачете лог файла в следващя си пост.

Ще продължим довечера, защото заминавам на работа, но сме на финалната права.

  • Автор
Стъпка 1 можах да я направя, но на стъпка 2, след като вкарам командата излиза за бързо черен прозорец и после на C\ не се появява лог list.txt.

AutoRuns.txt

Здравейте,

Извинявам се за забавянето, но имам доста работа тези дни и чак утре след 16.00 ще мога да продължа.

Все пак дотогава направете следното.

Отворете отново Autoruns => Services => изтрийте ръчно една по една следните услуги:

С описание => "New service would allow parents to control their children's online activity"

Само тях !

След това направете нова проверка с OTL и публикувайте лог файла - OTL.txt

  • Автор

Няма проблеми, когато стане. Ето и лога. Понеже не знам дали от това, че изтрих файловете с въпросното описание, но сега се появиха доста скрити файлове и папки. Примерно Documents and Settings нa C на иконата на папката има катинар и е скрита и когато се опитам да я отворя ми пише: C:\Documents and Settings is not accessible. Access is denied. Преди можех да вси влизам свободно .

OTL.Txt

Редактирано от mude (преглед на промените)

Не се притеснявайте за тези папки, те са създадени за писачите на софтуер с цел обратна съвместимост с Windows XP :) Прочетете този материал => http://www.svrops.com/svrops/articles/jpoints.htm По-късно ще прегледам и лог файла, защото съм на работа все още.

Докато прегледам лог файла, ако използвате Samsung Kies, моля преинсталирайте програмата.

Тя е изтрита от Combofix и това се вижда във втори лог файл.

Днес говорих с автора на Combofix относно това - дали е фалшива тревога и той сподели, че дори да е легитимна няма място в c:\windows\system32\system32

И сигурно няма да я премахне от дефинициите си. Ако я използвате, я преинсталирайте, ако не можете - просто ще върнем част от изтритите от Combofix файлове.

Ако пък не я използвате ще почистим и остатъците от нея напълно наред с останалите файлове от бацила, преди да дам финалните наставления. :)

СТЪПКА 1

  • Моля, изтеглете SystemLook и запазете програмата на десктопа.
  • Кликнете два пъти върху SystemLook.exe, за да стартирате програмата.
  • Копирайте съдържанието на следния код в текстовото поле на програмата

    :filefind
    tsusbhub.sys
    synth3dvsc.sys
    rdvgkmd.sys
    wecsvc.dll
    WcsPlugInService.dll
    wbiosrvc.dll
    sppuinotify.dll
    sensrsvc.dll
    pcasvc.dll
    netman.dll
    dnsapi.dll
    
  • Кликнете на бутона Look, за да започне сканирането.
  • Когато сканирането завърши ще Ви се отвори Notepad с резултата от сканирането. Моля, публикувайте лог файла в следващия си коментар.

СТЪПКА 2

Стартирайте отново OTL, копирайте (Copy) и поставете (Paste) скриптовия текст от текстовото поле по-долу под колонката Custom Scans/Fixes, като не забравяте да копирате скрипта 1 към 1, както и двете точки преди първия ред на скрипта.

:OTL
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (dgderdrv)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (cpuz135)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (catchme)
DRV - File not found [Kernel | On_Demand | Unknown] --  -- (a34hk3te)
IE - HKLM\..\URLSearchHook: {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - No CLSID value found
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1750559
IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\S-1-5-21-3647674084-1809422857-42203086-1000\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={6A0E1181-AD43-4FA8-B429-BEAD47C85531}&mid=fa1492f26651b6517dbb7e738461ca3b-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&lang=us&ds=AVG&pr=pa&d=2011-12-07 09:05:44&v=10.0.0.7&sap=dsp&q={searchTerms}
IE - HKU\S-1-5-21-3647674084-1809422857-42203086-1000\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: "URL" = http://www.daemon-search.com/search/web?q={searchTerms}
IE - HKU\S-1-5-21-3647674084-1809422857-42203086-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1750559
IE - HKU\S-1-5-21-3647674084-1809422857-42203086-1000\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7
FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..extensions.enabledItems: [email protected]:1.1.2.0185
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:10.0.0.1178
FF - prefs.js..extensions.enabledItems: avg@igeared:6.011.025.001
FF - prefs.js..keyword.URL: "http://isearch.avg.com/search?cid=%7Bc0749cf5-71d9-445c-914c-6855046c0e65%7D&mid=fa1492f26651b6517dbb7e738461ca3b-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&ds=AVG&v=10.0.0.7&lang=us&pr=pa&d=2011-12-07%2009%3A05%3A44&sap=ku&q="
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\
[2012.01.18 14:37:32 | 000,003,766 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
CHR - default_search_provider: AVG Secure Search (Enabled)
CHR - default_search_provider: search_url = http://isearch.avg.com/search?cid={6A0E1181-AD43-4FA8-B429-BEAD47C85531}&mid=fa1492f26651b6517dbb7e738461ca3b-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&lang=us&ds=AVG&pr=pa&d=2011-12-07 09:05:44&v=10.0.0.7&sap=dsp&q={searchTerms}
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKU\S-1-5-21-3647674084-1809422857-42203086-1000\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
[2011.06.28 09:47:53 | 000,054,016 | ---- | C] () -- C:\Windows\System32\drivers\atmqjbj.sys
[2010.12.05 16:03:43 | 000,000,000 | ---- | C] () -- C:\Users\Martin\AppData\Local\prvlcl.dat
[2010.11.25 18:47:49 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\AVG10
[2010.07.27 12:09:55 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\OpenCandy
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:51394AA5
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:6B9ADB51
:commands
[emptytemp]

След като въведете скрипта от цитата по-горе натиснете бутона, маркиран в червено: Run Fix

Windows ще се рестартира и ще се създаде лог файл (ако не се създаде такъв, отворете C:\_OTL\MovedFiles - файла трябва да е там).

Публикувайте съдържанието му с Copy/Paste в следващия си коментар.

  • Автор

Стъпка 1: SystemLook 30.07.11 by jpshortstuff Log created at 09:03 on 14/03/2012 by Martin Administrator - Elevation successful ========== filefind ========== Searching for "tsusbhub.sys" C:\Windows\System32\DriverStore\FileRepository\tsusbhub.inf_x86_neutral_927afe150d9ff343\tsusbhub.sys --a---- 112640 bytes [17:39 09/03/2011] [10:24 20/11/2010] 045ACB987C650D8186C6B4A692223860 C:\Windows\winsxs\x86_tsusbhub.inf_31bf3856ad364e35_6.1.7601.17514_none_0bf80d28d3996dee\tsusbhub.sys --a---- 112640 bytes [17:39 09/03/2011] [10:24 20/11/2010] 045ACB987C650D8186C6B4A692223860 Searching for "synth3dvsc.sys" C:\Windows\System32\DriverStore\FileRepository\synth3dvsc.inf_x86_neutral_bccbc5fb46a05558\Synth3dVsc.sys --a---- 77184 bytes [17:39 09/03/2011] [12:30 20/11/2010] F2AD8960812FD111E20E84659EF19D43 C:\Windows\winsxs\x86_synth3dvsc.inf_31bf3856ad364e35_6.1.7601.17514_none_33bfee9049cf7897\Synth3dVsc.sys --a---- 77184 bytes [17:39 09/03/2011] [12:30 20/11/2010] F2AD8960812FD111E20E84659EF19D43 Searching for "rdvgkmd.sys" C:\Windows\System32\DriverStore\FileRepository\rdvgwddm.inf_x86_neutral_345f205da00aaad5\rdvgkmd.sys --a---- 93568 bytes [17:39 09/03/2011] [12:30 20/11/2010] 98F3C9CC6A660A0CAD14EF5A10765953 C:\Windows\winsxs\x86_rdvgwddm.inf_31bf3856ad364e35_6.1.7601.17514_none_71371a60b47f79ab\rdvgkmd.sys --a---- 93568 bytes [17:39 09/03/2011] [12:30 20/11/2010] 98F3C9CC6A660A0CAD14EF5A10765953 Searching for "wecsvc.dll" C:\Windows\System32\wecsvc.dll --a---- 147968 bytes [23:30 13/07/2009] [01:16 14/07/2009] 760F0AFE937A77CFF27153206534F275 C:\Windows\winsxs\x86_microsoft-windows-eventcollector_31bf3856ad364e35_6.1.7600.16385_none_fae3f90ad6068afa\wecsvc.dll --a---- 147968 bytes [23:30 13/07/2009] [01:16 14/07/2009] 760F0AFE937A77CFF27153206534F275 Searching for "WcsPlugInService.dll" C:\Windows\System32\WcsPlugInService.dll --a---- 32768 bytes [23:25 13/07/2009] [01:16 14/07/2009] 5D930B6357A6D2AF4D7653BDABBF352F C:\Windows\winsxs\x86_microsoft-windows-icm-base_31bf3856ad364e35_6.1.7600.16385_none_229e4077eab6ceb6\WcsPlugInService.dll --a---- 32768 bytes [23:25 13/07/2009] [01:16 14/07/2009] 5D930B6357A6D2AF4D7653BDABBF352F C:\Windows\winsxs\x86_microsoft-windows-icm-base_31bf3856ad364e35_6.1.7601.17514_none_24cf543fe7a55250\WcsPlugInService.dll --a---- 32768 bytes [23:25 13/07/2009] [01:16 14/07/2009] 5D930B6357A6D2AF4D7653BDABBF352F Searching for "wbiosrvc.dll" C:\Windows\System32\wbiosrvc.dll --a---- 151552 bytes [23:37 13/07/2009] [01:16 14/07/2009] 9614B5D29DC76AC3C29F6D2D3AA70E67 C:\Windows\winsxs\x86_microsoft-windows-wbiosrvc_31bf3856ad364e35_6.1.7600.16385_none_6b7668671d51657a\wbiosrvc.dll --a---- 151552 bytes [23:37 13/07/2009] [01:16 14/07/2009] 9614B5D29DC76AC3C29F6D2D3AA70E67 Searching for "sppuinotify.dll" C:\Windows\System32\sppuinotify.dll --a---- 53760 bytes [17:38 09/03/2011] [12:21 20/11/2010] B0180B20B065D89232A78A40FE56EAA6 C:\Windows\winsxs\x86_microsoft-windows-security-spp-ux_31bf3856ad364e35_6.1.7600.16385_none_5b97f4df0025c6e9\sppuinotify.dll --a---- 53760 bytes [23:36 13/07/2009] [01:16 14/07/2009] D8E3E19EEBDAB49DD4A8D3062EAD4EC7 C:\Windows\winsxs\x86_microsoft-windows-security-spp-ux_31bf3856ad364e35_6.1.7601.17514_none_5dc908a6fd144a83\sppuinotify.dll --a---- 53760 bytes [17:38 09/03/2011] [12:21 20/11/2010] B0180B20B065D89232A78A40FE56EAA6 Searching for "sensrsvc.dll" C:\Windows\System32\sensrsvc.dll --a---- 25088 bytes [23:45 13/07/2009] [01:16 14/07/2009] 50087FE1EE447009C9CC2997B90DE53F C:\Windows\winsxs\x86_microsoft-windows-m..epc-sensors-service_31bf3856ad364e35_6.1.7600.16385_none_11fa20dce8ce49e2\sensrsvc.dll --a---- 25088 bytes [23:45 13/07/2009] [01:16 14/07/2009] 50087FE1EE447009C9CC2997B90DE53F Searching for "pcasvc.dll" C:\Windows\System32\pcasvc.dll --a---- 154624 bytes [23:20 13/07/2009] [01:16 14/07/2009] 358AB7956D3160000726574083DFC8A6 C:\Windows\winsxs\x86_microsoft-windows-a..atibility-assistant_31bf3856ad364e35_6.1.7600.16385_none_339cdc37847a979b\pcasvc.dll --a---- 154624 bytes [23:20 13/07/2009] [01:16 14/07/2009] 358AB7956D3160000726574083DFC8A6 Searching for "netman.dll" C:\Windows\ERDNT\cache\netman.dll --a---- 280576 bytes [01:05 12/03/2012] [01:16 14/07/2009] 7CCCFCA7510684768DA22092D1FA4DB2 C:\Windows\System32\netman.dll --a---- 280576 bytes [23:52 13/07/2009] [01:16 14/07/2009] 7CCCFCA7510684768DA22092D1FA4DB2 C:\Windows\winsxs\x86_microsoft-windows-netman_31bf3856ad364e35_6.1.7600.16385_none_0f9371b9b32368a4\netman.dll --a---- 280576 bytes [23:52 13/07/2009] [01:16 14/07/2009] 7CCCFCA7510684768DA22092D1FA4DB2 Searching for "dnsapi.dll" C:\Windows\System32\dnsapi.dll --a---- 270336 bytes [07:07 13/04/2011] [05:38 03/03/2011] B40420876B9288E0A1C8CCA8A84E5DC9 C:\Windows\winsxs\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7600.16385_none_e1b8d300e3acf8dc\dnsapi.dll --a---- 269824 bytes [23:12 13/07/2009] [01:15 14/07/2009] 6D5A49D6479EB753C7879F73A4C35E0F C:\Windows\winsxs\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7600.16772_none_e1c0a9a6e3a78582\dnsapi.dll --a---- 269824 bytes [07:07 13/04/2011] [05:29 03/03/2011] 62390F4ACE9E2B63E3CA26B7F7497897 C:\Windows\winsxs\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7600.20914_none_e28d2873fc92ad7b\dnsapi.dll --a---- 270336 bytes [07:07 13/04/2011] [05:50 03/03/2011] 11DD7EB4446F25C132D0D8527DDCAF4D C:\Windows\winsxs\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7601.17514_none_e3e9e6c8e09b7c76\dnsapi.dll --a---- 270336 bytes [17:39 09/03/2011] [12:18 20/11/2010] 59DF156711A76BCB993253EC6C9BBF41 C:\Windows\winsxs\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7601.17570_none_e3a50618e0cfbec0\dnsapi.dll --a---- 270336 bytes [07:07 13/04/2011] [05:38 03/03/2011] B40420876B9288E0A1C8CCA8A84E5DC9 C:\Windows\winsxs\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7601.21673_none_e431a3c1f9eaaa8f\dnsapi.dll --a---- 270336 bytes [07:07 13/04/2011] [05:12 03/03/2011] 1F79F611109C2B97260B68FD6B4FC7DD -= EOF =- Стъпка 2: All processes killed ========== OTL ========== Service dgderdrv stopped successfully! Service dgderdrv deleted successfully! Service cpuz135 stopped successfully! Service cpuz135 deleted successfully! Service catchme stopped successfully! Service catchme deleted successfully! Error: No service named a34hk3te was found to stop! Service\Driver key a34hk3te not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found. Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\URLSearchHooks\\{A3BC75A2-1F87-4686-AA43-5347D756017C} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3BC75A2-1F87-4686-AA43-5347D756017C}\ not found. Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\URLSearchHooks\\{A3BC75A2-1F87-4686-AA43-5347D756017C} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3BC75A2-1F87-4686-AA43-5347D756017C}\ not found. Registry key HKEY_USERS\S-1-5-21-3647674084-1809422857-42203086-1000\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}\ not found. Registry key HKEY_USERS\S-1-5-21-3647674084-1809422857-42203086-1000\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}\ not found. Registry key HKEY_USERS\S-1-5-21-3647674084-1809422857-42203086-1000\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found. Registry key HKEY_USERS\S-1-5-21-3647674084-1809422857-42203086-1000\Software\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}\ not found. Prefs.js: "AVG Secure Search" removed from browser.search.defaultenginename Prefs.js: [email protected]:1.1.2.0185 removed from extensions.enabledItems Prefs.js: {3f963a5b-e555-4543-90e2-c3908898db71}:10.0.0.1178 removed from extensions.enabledItems Prefs.js: avg@igeared:6.011.025.001 removed from extensions.enabledItems Prefs.js: "http://isearch.avg.com/search?cid=%7Bc0749cf5-71d9-445c-914c-6855046c0e65%7D&mid=fa1492f26651b6517dbb7e738461ca3b-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&ds=AVG&v=10.0.0.7&lang=us&pr=pa&d=2011-12-07%2009%3A05%3A44&sap=ku&q=" removed from keyword.URL File HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4 not found. C:\Program Files\Mozilla Firefox\searchplugins\avg-secure-search.xml moved successfully. Unable to fix default_search_provider items. Unable to fix default_search_provider items. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ deleted successfully. C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll moved successfully. Registry value HKEY_USERS\S-1-5-21-3647674084-1809422857-42203086-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ not found. File C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll not found. C:\Windows\System32\drivers\atmqjbj.sys moved successfully. C:\Users\Martin\AppData\Local\prvlcl.dat moved successfully. C:\Users\Martin\AppData\Roaming\AVG10\cfgall folder moved successfully. C:\Users\Martin\AppData\Roaming\AVG10 folder moved successfully. C:\Users\Martin\AppData\Roaming\OpenCandy\OpenCandy_16336CE4D6054080ADC6AC65B71B0D40 folder moved successfully. C:\Users\Martin\AppData\Roaming\OpenCandy folder moved successfully. ADS C:\ProgramData\TEMP:51394AA5 deleted successfully. ADS C:\ProgramData\TEMP:6B9ADB51 deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->Flash cache emptied: 56475 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Martin ->Temp folder emptied: 85191123 bytes ->Temporary Internet Files folder emptied: 1438445102 bytes ->Java cache emptied: 27206570 bytes ->FireFox cache emptied: 75750887 bytes ->Google Chrome cache emptied: 184389485 bytes ->Opera cache emptied: 14729307 bytes ->Flash cache emptied: 1127902 bytes User: Public ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 5344 bytes RecycleBin emptied: 59133901 bytes Total Files Cleaned = 1 799,00 mb OTL by OldTimer - Version 3.2.36.3 log created on 03142012_090710 Files\Folders moved on Reboot... Registry entries deleted on Reboot... Да попитам понеже се появиха 9 ъпдейта за Windows 7 от менюто в контрол панела да ги направя ли или да изчакаш да свърши всичко. Понеже видях 4 файла за упдейт с име: Security Update for Windows 7.

Редактирано от mude (преглед на промените)

Да, можете да инсталирате обновленията.

Моля от Start => въведето в полето за търсене => CMD.exe => кликнете с десен бутон върху файла и натиснете Run as administrator.

В конзолата изпълнете командата sfc /scannow и натиснете Enter

След края на проверката изтрийте вашата версия на OTL и изтеглете нова оттук.

Натиснете Run Scan (без да сменяте настройките) и публикувайте лог файла в следващия си пост.

Ако ви дразнят и това, че виждате папките с Access is Denied (Junction) папките, можете да ги скритете или ако не знаете как, пишете за да ви обясня. :)

Поздрави !

  • Автор

Готово, иначе знам как се крият папки ;):

OTL logfile created on: 14.3.2012 г. 20:16:39 - Run 1

OTL by OldTimer - Version 3.2.37.0 Folder = C:\Users\Martin\Desktop

Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation

Internet Explorer (Version = 9.0.8112.16421)

Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: d.M.yyyy 'г.'

1,99 Gb Total Physical Memory | 1,16 Gb Available Physical Memory | 58,45% Memory free

3,98 Gb Paging File | 3,15 Gb Available in Paging File | 79,06% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files

Drive C: | 58,50 Gb Total Space | 32,12 Gb Free Space | 54,90% Space Free | Partition Type: NTFS

Drive D: | 195,31 Gb Total Space | 21,65 Gb Free Space | 11,08% Space Free | Partition Type: NTFS

Drive E: | 211,85 Gb Total Space | 10,59 Gb Free Space | 5,00% Space Free | Partition Type: NTFS

Computer Name: MY-COMPTUER | User Name: Martin | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012.03.14 20:16:07 | 000,594,432 | ---- | M] (OldTimer Tools) -- C:\Users\Martin\Desktop\OTL.exe

PRC - [2012.03.14 09:11:59 | 000,924,600 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe

PRC - [2012.01.03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe

PRC - [2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe

PRC - [2010.11.20 14:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe

PRC - [2010.07.26 15:15:26 | 000,217,088 | ---- | M] (Teruten) -- C:\Windows\System32\FsUsbExService.Exe

PRC - [2010.07.12 18:32:48 | 000,074,752 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Winamp\winampa.exe

PRC - [2010.04.01 11:16:20 | 000,357,696 | ---- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools Lite\DTLite.exe

PRC - [2009.04.17 13:33:36 | 000,095,536 | ---- | M] (OLYMPUS IMAGING CORP.) -- C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe

PRC - [2002.05.19 08:24:00 | 000,095,232 | ---- | M] () -- C:\Program Files\Datecs\FlexType 2K\FType2K.exe

========== Modules (No Company Name) ==========

MOD - [2012.03.14 09:11:59 | 001,969,080 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll

MOD - [2012.03.13 12:12:42 | 008,527,520 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32.dll

MOD - [2010.03.15 10:28:22 | 000,141,824 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll

MOD - [2002.05.19 08:24:00 | 000,095,232 | ---- | M] () -- C:\Program Files\Datecs\FlexType 2K\FType2K.exe

MOD - [2002.04.22 23:17:06 | 000,045,056 | ---- | M] () -- C:\Windows\System32\newdll.dll

========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] -- C:\Windows\system32\wpdbusenum.dllyer\ -- (WPDBusEnum)

SRV - File not found [On_Demand | Stopped] -- C:\Windows\System32\wlansvc.dlll -- (Wlansvc)

SRV - File not found [Auto | Running] -- C:\Windows\system32\wbem\WMIsvc.dlll -- (Winmgmt)

SRV - File not found [On_Demand | Stopped] -- C:\Windows\system32\wecsvc.dlll -- (Wecsvc)

SRV - File not found [On_Demand | Stopped] -- C:\Windows\System32\WcsPlugInService.dll1 -- (WcsPlugInService)

SRV - File not found [Auto | Running] -- C:\Windows\system32\sysmain.dlles\SysMain\Parameters -- (SysMain)

SRV - File not found [Disabled | Stopped] -- C:\Windows\System32\mprdim.dllces\RemoteAccess\Parameters -- (RemoteAccess)

SRV - File not found [On_Demand | Stopped] -- C:\Windows\system32\pnrpsvc.dlll -- (PNRPsvc)

SRV - File not found [Auto | Running] -- C:\Windows\system32\mmcss.dllfice\office12\ -- (MMCSS)

SRV - File not found [Auto | Running] -- C:\Windows\system32\es.dlltem... -- (EventSystem)

SRV - File not found [Auto | Running] -- C:\Windows\System32\Audiosrv.dlluilder... -- (Audiosrv)

SRV - [2012.01.03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)

SRV - [2011.06.02 09:50:38 | 000,403,240 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)

SRV - [2011.01.13 18:23:02 | 000,129,440 | ---- | M] (Futuremark Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe -- (Futuremark SystemInfo Service)

SRV - [2010.07.27 15:20:14 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)

SRV - [2010.07.26 15:15:26 | 000,217,088 | ---- | M] (Teruten) [Auto | Running] -- C:\Windows\System32\FsUsbExService.Exe -- (FsUsbExService)

SRV - [2010.03.29 07:53:22 | 000,068,000 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper.dll -- (getPlusHelper)

SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)

SRV - [2009.07.14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)

SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WINDEFEND)

========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\tsusbhub.sys -- (tsusbhub)

DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\synth3dvsc.sys -- (Synth3dVsc)

DRV - File not found [Kernel | On_Demand | Unknown] -- -- (avg2aizz)

DRV - [2010.11.20 14:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)

DRV - [2010.11.20 14:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)

DRV - [2010.11.20 14:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)

DRV - [2010.11.20 12:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)

DRV - [2010.11.20 12:21:14 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)

DRV - [2010.11.20 11:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)

DRV - [2010.11.20 11:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)

DRV - [2010.11.20 11:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)

DRV - [2010.08.07 17:07:50 | 000,165,376 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\atksgt.sys -- (atksgt)

DRV - [2010.08.07 17:07:41 | 000,018,048 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\lirsgt.sys -- (lirsgt)

DRV - [2010.07.27 15:18:46 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)

DRV - [2010.07.26 15:15:26 | 000,036,640 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\FsUsbExDisk.Sys -- (FsUsbExDisk)

DRV - [2010.04.27 04:25:20 | 000,123,648 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscemdm.sys -- (sscemdm)

DRV - [2010.04.27 04:25:20 | 000,100,352 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssceserd.sys -- (ssceserd) SAMSUNG Mobile Modem Diagnostic Serial Port V2 (WDM)

DRV - [2010.04.27 04:25:20 | 000,098,560 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscebus.sys -- (sscebus) SAMSUNG USB Composite Device V2 driver (WDM)

DRV - [2010.04.27 04:25:20 | 000,014,848 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscemdfl.sys -- (sscemdfl)

DRV - [2010.03.09 15:36:18 | 000,080,680 | ---- | M] (Fuzhou Rockchip Electronics Co,Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rockusb.sys -- (rockusb)

DRV - [2009.08.13 10:45:56 | 000,091,264 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\ArcHlp.sys -- (archlp)

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}

IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT1750559

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = bg

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = C7 2D 8D 9A 2C DC CB 01 [binary data]

IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}

IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: ""

FF - prefs.js..browser.startup.homepage: "www.google.bg"

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()

FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)

FF - HKLM\Software\MozillaPlugins\@inhatch.com,version=0.7.61: C:\Program Files\InhatchTeam\Inhatch\npinhatch.dll (Inhatch)

FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)

FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)

FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Martin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.03.14 09:11:59 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.01.22 20:52:05 | 000,000,000 | ---D | M]

[2011.07.16 20:02:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Martin\AppData\Roaming\Mozilla\Extensions

[2012.02.28 23:05:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\e72k9gu4.default\extensions

[2012.02.13 20:21:29 | 000,000,000 | ---D | M] (Flagfox) -- C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\e72k9gu4.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}

[2011.12.24 16:50:18 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\e72k9gu4.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}

[2010.07.27 15:19:04 | 000,002,059 | ---- | M] () -- C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\e72k9gu4.default\searchplugins\daemon-search.xml

[2011.12.21 11:11:33 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions

[2011.11.01 18:11:19 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}

() (No name found) -- C:\USERS\MARTIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\E72K9GU4.DEFAULT\EXTENSIONS\{C4D362EC-1CFF-4CA0-9031-99A8FAD7995A}.XPI

() (No name found) -- C:\USERS\MARTIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\E72K9GU4.DEFAULT\EXTENSIONS\[email protected]

[2012.03.14 09:11:59 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll

[2011.10.03 05:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll

[2012.02.12 00:07:21 | 000,001,083 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\911bg.xml

[2012.02.12 00:07:21 | 000,002,442 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\diribg.xml

[2012.02.12 00:07:21 | 000,001,515 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pe-bg.xml

[2012.02.12 00:07:21 | 000,001,857 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\portalbgdict.xml

[2012.02.12 00:07:21 | 000,001,220 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-bg.xml

========== Chrome ==========

CHR - default_search_provider: AVG Secure Search (Enabled)

CHR - default_search_provider: search_url = http://isearch.avg.com/search?cid={6A0E1181-AD43-4FA8-B429-BEAD47C85531}&mid=fa1492f26651b6517dbb7e738461ca3b-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&lang=us&ds=AVG&pr=pa&d=2011-12-07 09:05:44&v=10.0.0.7&sap=dsp&q={searchTerms}

CHR - default_search_provider: suggest_url = http://clients5.google.com/complete/search?hl={language}&q={searchTerms}&client=ie8&inputencoding={inputEncoding}&outputencoding={outputEncoding}

CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Martin\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.79\gcswf32.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll

CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer

CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.79\ppGoogleNaClPluginChrome.dll

CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.79\pdf.dll

CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll

CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll

CHR - plugin: Java Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll

CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll

CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL

CHR - plugin: getPlusPlus for Adobe 16263 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np_gp.dll

CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll

CHR - plugin: Inhatch Plug-in (Enabled) = C:\Program Files\InhatchTeam\Inhatch\npinhatch.dll

CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll

CHR - plugin: Unity Player (Enabled) = C:\Users\Martin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll

CHR - plugin: Default Plug-in (Enabled) = default_plugin

CHR - Extension: YouTube = C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\

CHR - Extension: Google \u0422\u044A\u0440\u0441\u0435\u043D\u0435 = C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.17_0\

CHR - Extension: Skype Click to Call = C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\

CHR - Extension: Gmail = C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012.03.12 10:02:44 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O4 - HKLM..\Run: [KiesTrayAgent] C:\Program Files\Samsung\Kies\KiesTrayAgent.exe File not found

O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)

O4 - HKLM..\Run: [OM2_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe (OLYMPUS IMAGING CORP.)

O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)

O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)

O4 - HKCU..\Run: [KiesPDLR] C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe File not found

O4 - HKCU..\Run: [OM2_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe (OLYMPUS IMAGING CORP.)

O4 - Startup: C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3

O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O9 - Extra Button: Преведи - {60237576-b24c-4ba9-9740-c9f3ec9db557} - C:\Program Files\SkyCode\WebTrance30\wt2ie.dll ()

O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)

O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 85.217.128.241 87.121.223.9

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2E8012C2-2100-42BB-B437-96D2A480657D}: DhcpNameServer = 85.217.128.241 87.121.223.9

O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)

O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]

O34 - HKLM BootExecute: (autocheck autochk *)

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = ComFile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012.03.14 20:16:06 | 000,594,432 | ---- | C] (OldTimer Tools) -- C:\Users\Martin\Desktop\OTL.exe

[2012.03.14 12:07:23 | 003,968,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe

[2012.03.14 12:07:22 | 003,913,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe

[2012.03.14 09:00:15 | 002,343,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys

[2012.03.14 09:00:15 | 001,077,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll

[2012.03.14 08:59:53 | 000,919,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcorets.dll

[2012.03.14 08:59:53 | 000,826,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcore.dll

[2012.03.14 08:59:52 | 000,129,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcorekmts.dll

[2012.03.14 08:59:52 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpwsx.dll

[2012.03.14 08:59:52 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdrmemptylst.exe

[2012.03.13 16:11:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BS.Player

[2012.03.13 16:10:51 | 000,000,000 | ---D | C] -- C:\Program Files\Webteh

[2012.03.12 15:42:37 | 000,000,000 | ---D | C] -- C:\Users\Martin\Desktop\Autoruns

[2012.03.12 12:56:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware

[2012.03.12 12:56:36 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys

[2012.03.12 12:11:07 | 004,730,880 | ---- | C] (AVAST Software) -- C:\Users\Martin\Desktop\aswMBR.exe

[2012.03.12 10:05:25 | 000,000,000 | ---D | C] -- C:\Windows\temp

[2012.03.12 10:05:03 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN

[2012.03.12 09:47:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT

[2012.03.12 09:47:35 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT

[2012.03.12 09:44:23 | 000,791,393 | ---- | C] (Lars Hederer ) -- C:\Users\Martin\Desktop\erunt-setup.exe

[2012.03.12 03:01:13 | 000,000,000 | ---D | C] -- C:\Users\Martin\AppData\Local\temp

[2012.03.12 02:47:12 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT

[2012.03.12 02:42:49 | 001,692,968 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Users\Martin\Desktop\avg_remover_stf_x86_2012_1796.exe

[2012.03.12 00:05:19 | 000,000,000 | -HSD | C] -- C:\Windows\System32\%APPDATA%

[2012.03.10 17:15:07 | 000,000,000 | ---D | C] -- C:\Users\Martin\Documents\Sega

[2012.03.10 17:03:41 | 000,251,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_5.dll

[2012.03.10 17:03:40 | 000,440,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10.dll

[2012.03.10 17:03:37 | 003,426,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_32.dll

[2012.03.10 17:03:35 | 000,237,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_4.dll

[2012.03.10 17:03:30 | 002,414,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_31.dll

[2012.03.10 17:03:29 | 000,236,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_3.dll

[2012.03.10 17:03:27 | 000,062,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_2.dll

[2012.02.23 21:27:28 | 000,000,000 | ---D | C] -- C:\Users\Martin\Documents\NFS Carbon

[2012.02.23 21:21:15 | 000,230,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_2.dll

[2012.02.16 23:40:29 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb

[2012.02.16 23:40:28 | 001,798,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll

[2012.02.16 23:40:28 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll

[2012.02.16 23:40:27 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll

[2012.02.16 23:40:27 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll

[2012.02.16 23:40:25 | 001,427,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl

[2012.02.16 19:04:33 | 000,478,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\timedate.cpl

[2012.02.13 20:46:38 | 000,000,000 | ---D | C] -- C:\Users\Martin\AppData\Roaming\Temp

========== Files - Modified Within 30 Days ==========

[2012.03.14 20:16:07 | 000,594,432 | ---- | M] (OldTimer Tools) -- C:\Users\Martin\Desktop\OTL.exe

[2012.03.14 20:14:53 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job

[2012.03.14 20:14:44 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat

[2012.03.14 20:14:41 | 1602,985,984 | -HS- | M] () -- C:\hiberfil.sys

[2012.03.14 19:44:00 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

[2012.03.14 16:06:33 | 000,014,224 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

[2012.03.14 16:06:33 | 000,014,224 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

[2012.03.14 15:59:19 | 000,419,072 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT

[2012.03.13 16:11:09 | 000,001,104 | ---- | M] () -- C:\Users\Martin\Application Data\Microsoft\Internet Explorer\Quick Launch\BS.Player FREE.lnk

[2012.03.13 16:11:09 | 000,001,080 | ---- | M] () -- C:\Users\Public\Desktop\BS.Player FREE.lnk

[2012.03.13 15:34:18 | 000,104,319 | ---- | M] () -- C:\Users\Martin\Desktop\2673_vul4an_petko_print.jpg

[2012.03.13 14:20:38 | 000,624,578 | ---- | M] () -- C:\Windows\System32\perfh009.dat

[2012.03.13 14:20:38 | 000,110,216 | ---- | M] () -- C:\Windows\System32\perfc009.dat

[2012.03.13 13:45:10 | 000,002,286 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk

[2012.03.13 12:12:42 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl

[2012.03.13 08:37:04 | 001,943,503 | ---- | M] () -- C:\Users\Martin\Desktop\Снимки0367.jpg

[2012.03.12 13:03:12 | 000,337,137 | ---- | M] () -- C:\Users\Martin\Desktop\FSS.exe

[2012.03.12 12:56:37 | 000,001,067 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

[2012.03.12 12:54:39 | 000,000,512 | ---- | M] () -- C:\Users\Martin\Desktop\MBR.dat

[2012.03.12 12:11:19 | 004,730,880 | ---- | M] (AVAST Software) -- C:\Users\Martin\Desktop\aswMBR.exe

[2012.03.12 10:02:44 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts

[2012.03.12 09:50:12 | 000,002,964 | ---- | M] () -- C:\Users\Martin\Desktop\fix.reg

[2012.03.12 09:47:42 | 000,001,074 | ---- | M] () -- C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk

[2012.03.12 09:47:35 | 000,000,894 | ---- | M] () -- C:\Users\Martin\Desktop\NTREGOPT.lnk

[2012.03.12 09:47:35 | 000,000,875 | ---- | M] () -- C:\Users\Martin\Desktop\ERUNT.lnk

[2012.03.12 09:44:25 | 000,791,393 | ---- | M] (Lars Hederer ) -- C:\Users\Martin\Desktop\erunt-setup.exe

[2012.03.12 02:42:50 | 001,692,968 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Users\Martin\Desktop\avg_remover_stf_x86_2012_1796.exe

[2012.03.11 21:48:22 | 000,183,170 | ---- | M] () -- C:\Users\Martin\Desktop\telefona-dimitrova.jpg

[2012.03.09 15:28:17 | 000,056,456 | ---- | M] () -- C:\Users\Martin\Desktop\09_games_1a.jpg

[2012.03.07 08:21:06 | 001,687,979 | ---- | M] () -- C:\Users\Martin\Desktop\аз.jpg

[2012.03.05 20:15:44 | 000,070,597 | ---- | M] () -- C:\Users\Martin\Desktop\430603_3032262163039_1157442833_32363838_1230399428_n.jpg

[2012.03.01 16:01:08 | 000,042,870 | ---- | M] () -- C:\Users\Martin\Desktop\kiss_of_the_dragon_2001(subsunacs.net).rar

[2012.02.22 13:57:26 | 001,790,761 | ---- | M] () -- C:\Users\Martin\Desktop\Снимки0365.jpg

[2012.02.22 13:57:23 | 001,730,079 | ---- | M] () -- C:\Users\Martin\Desktop\Снимки0366.jpg

[2012.02.22 13:57:21 | 001,569,094 | ---- | M] () -- C:\Users\Martin\Desktop\Снимки0364.jpg

[2012.02.22 13:57:20 | 001,805,399 | ---- | M] () -- C:\Users\Martin\Desktop\Снимки0363.jpg

[2012.02.17 07:34:22 | 000,919,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rdpcorets.dll

[2012.02.17 07:34:22 | 000,826,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rdpcore.dll

========== Files Created - No Company Name ==========

[2012.03.13 16:11:09 | 000,001,104 | ---- | C] () -- C:\Users\Martin\Application Data\Microsoft\Internet Explorer\Quick Launch\BS.Player FREE.lnk

[2012.03.13 16:11:09 | 000,001,080 | ---- | C] () -- C:\Users\Public\Desktop\BS.Player FREE.lnk

[2012.03.12 13:03:11 | 000,337,137 | ---- | C] () -- C:\Users\Martin\Desktop\FSS.exe

[2012.03.12 12:56:37 | 000,001,067 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

[2012.03.12 12:54:39 | 000,000,512 | ---- | C] () -- C:\Users\Martin\Desktop\MBR.dat

[2012.03.12 09:50:12 | 000,002,964 | ---- | C] () -- C:\Users\Martin\Desktop\fix.reg

[2012.03.12 09:47:42 | 000,001,074 | ---- | C] () -- C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk

[2012.03.12 09:47:35 | 000,000,894 | ---- | C] () -- C:\Users\Martin\Desktop\NTREGOPT.lnk

[2012.03.12 09:47:35 | 000,000,875 | ---- | C] () -- C:\Users\Martin\Desktop\ERUNT.lnk

[2012.03.11 21:48:21 | 000,183,170 | ---- | C] () -- C:\Users\Martin\Desktop\telefona-dimitrova.jpg

[2012.03.09 15:28:12 | 000,056,456 | ---- | C] () -- C:\Users\Martin\Desktop\09_games_1a.jpg

[2012.03.07 21:02:20 | 001,687,979 | ---- | C] () -- C:\Users\Martin\Desktop\аз.jpg

[2012.03.05 20:15:36 | 000,070,597 | ---- | C] () -- C:\Users\Martin\Desktop\430603_3032262163039_1157442833_32363838_1230399428_n.jpg

[2012.02.22 13:56:02 | 001,569,094 | ---- | C] () -- C:\Users\Martin\Desktop\Снимки0364.jpg

[2012.02.22 13:56:01 | 001,805,399 | ---- | C] () -- C:\Users\Martin\Desktop\Снимки0363.jpg

[2012.02.22 13:56:01 | 001,730,079 | ---- | C] () -- C:\Users\Martin\Desktop\Снимки0366.jpg

[2012.02.22 13:56:00 | 001,943,503 | ---- | C] () -- C:\Users\Martin\Desktop\Снимки0367.jpg

[2012.02.22 13:55:58 | 001,790,761 | ---- | C] () -- C:\Users\Martin\Desktop\Снимки0365.jpg

[2011.12.29 21:05:39 | 000,000,619 | ---- | C] () -- C:\Windows\eReg.dat

[2011.12.11 05:53:30 | 000,000,000 | ---- | C] () -- C:\Users\Martin\AppData\Local\{0269DC9D-1C04-49BD-BBDC-8B0EA28DCBBD}

[2011.10.26 16:39:06 | 000,000,000 | ---- | C] () -- C:\Users\Martin\AppData\Local\{229D19BD-14B2-401F-90BE-407E06C38DD6}

[2011.10.15 06:52:11 | 000,000,000 | ---- | C] () -- C:\Users\Martin\AppData\Local\{55B8A775-5661-479B-8A65-FFEB16523B3A}

[2011.05.30 22:09:59 | 000,003,584 | ---- | C] () -- C:\Users\Martin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2011.05.18 19:20:19 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI

[2011.05.15 17:06:29 | 000,000,148 | ---- | C] () -- C:\Windows\QIII.INI

[2011.04.10 20:03:48 | 000,000,014 | ---- | C] () -- C:\Windows\System32\SystemInfo32.sys

[2011.04.09 17:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat

[2011.03.18 18:04:48 | 000,000,990 | -HS- | C] () -- C:\Users\Martin\AppData\Roaming\systemfl.$dk

[2011.03.11 18:28:29 | 000,011,264 | ---- | C] () -- C:\Windows\System32\rockusbCoInstaller.dll

[2011.03.09 19:39:42 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe

[2011.03.09 19:38:34 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe

[2011.01.29 17:00:22 | 000,974,848 | ---- | C] () -- C:\Windows\System32\cis-2.4.dll

[2011.01.29 17:00:22 | 000,081,920 | ---- | C] () -- C:\Windows\System32\issacapi_bs-2.3.dll

[2011.01.29 17:00:22 | 000,065,536 | ---- | C] () -- C:\Windows\System32\issacapi_pe-2.3.dll

[2011.01.29 17:00:22 | 000,057,344 | ---- | C] () -- C:\Windows\System32\issacapi_se-2.3.dll

[2011.01.22 20:48:15 | 000,000,000 | ---- | C] () -- C:\Windows\PowerReg.dat

[2010.09.15 20:25:36 | 000,002,560 | ---- | C] () -- C:\Windows\_MSRSTRT.EXE

[2010.08.22 17:20:40 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll

[2010.08.22 17:20:40 | 000,036,640 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys

[2010.08.14 14:36:00 | 000,140,288 | ---- | C] () -- C:\Windows\System32\igfxtvcx.dll

[2010.08.07 17:07:50 | 000,165,376 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys

[2010.08.07 17:07:41 | 000,018,048 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys

[2010.07.27 20:02:57 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CmdLineExt03.dll

[2010.07.27 16:18:30 | 000,007,605 | ---- | C] () -- C:\Users\Martin\AppData\Local\Resmon.ResmonCfg

[2010.07.27 15:10:10 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll

[2010.07.27 15:10:09 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini

[2010.07.27 15:10:08 | 000,790,528 | ---- | C] () -- C:\Windows\System32\xvidcore.dll

[2010.07.27 15:10:08 | 000,134,144 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll

[2010.07.27 15:10:08 | 000,108,032 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll

[2010.07.27 14:08:54 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat

[2010.07.27 13:49:54 | 000,045,056 | ---- | C] () -- C:\Windows\System32\newdll.dll

[2010.07.27 12:28:59 | 000,000,000 | ---- | C] () -- C:\Windows\PROTOCOL.INI

< End of report >

  • Изтеглете PsExec и разархивирайте архива на десктопа.
  • Копирайте файла psexec.exe в свободната директория на дял C:\
  • Изтеглете SWreg.exe и го копирайте в C:\Windows
  • В старт менюто в полето за търсене напишете CMD.exe => кликнете с десен бутон върху файла CMD.exe => натиснете Run as administrator.
  • Въведете командата cd c:\ и натиснете Enter
  • Въведете командата psexec -s swreg.exe ACL "HKLM\SYSTEM\CurrentControlSet\Enum\Root" /GE:F и натиснете Enter
  • Сега вече сме готови за следващата стъпка...Изтеглете този файл и го запазете на десктопа.
  • Разархивирайте архива в папка на десктопа и стартирайте 1 по 1 всеки файл с двукратен клик върху него и изберете YES на диалоговия прозорец.
  • Пуснете нов лог от OTL в следващия си пост.

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.