Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Featured Replies

не мога от скоро време да си ъпдейтна дефеницийте на антивирусната microsoft essentials, заедно с това не мога да си включа и Firewall-а

Публикувано изображение

Публикувано изображение

Дайте необходимите логове, за да могат да ви помогнат момчетата!

  • Автор

DDS.txt

DDS (Ver_2011-09-30.01) - NTFS_x86
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 10.5.1
Run by daka_kill at 9:37:20 on 2012-07-20
Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.959.328 [GMT 3:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
============== Running Processes ================
.
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Vista Rainbar\Rainmeter.exe
C:\Program Files\Skype\Phone\Skype.exe
E:\Programs\RocketDock\RocketDock.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k imgsvc
.
============== Pseudo HJT Report ===============
.
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\oracle\javafx 2.1 runtime\bin\ssv.dll
BHO: Skype add-on for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\oracle\javafx 2.1 runtime\bin\jp2ssv.dll
TB: DAEMON Tools Toolbar: {32099AAC-C132-4136-9E9A-4E364A424E17} - c:\program files\daemon tools toolbar\DTToolbar.dll
TB: DAEMON Tools Toolbar: {32099AAC-C132-4136-9E9A-4E364A424E17} - c:\program files\daemon tools toolbar\DTToolbar.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [Vista Rainbar] c:\program files\vista rainbar\Rainmeter.exe
uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe"
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [RocketDock] "e:\programs\rocketdock\RocketDock.exe"
uRun: [DAEMON Tools Lite] "e:\programs\daemon tools lite\DTLite.exe" -autorun
uRun: [Steam] "e:\steam\steam\Steam.exe" -silent
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [SkyTel] SkyTel.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [UnlockerAssistant] "c:\program files\unlocker\UnlockerAssistant.exe" -H
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [LogMeIn Hamachi Ui] "c:\program files\logmein hamachi\hamachi-2-ui.exe" --auto-start
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
StartupFolder: c:\docume~1\daka_k~1\startm~1\programs\startup\yowindow.lnk - e:\yowindow unlimited edition 3.0 build 85 final\yowindow.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
uPolicies-Explorer: NoSMMyPictures = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoSMMyPictures = dword:1
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
TCP: Interfaces\{82BA52F8-03CB-4738-960D-82BE7C80487D} : DHCPNameServer = 192.168.1.1
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\daka_kill\application data\mozilla\firefox\profiles\rdfjra4a.default\
FF - prefs.js: browser.search.selectedEngine - Vbox7.com
FF - prefs.js: browser.startup.homepage - hxxp://www.google.bg/
FF - plugin: c:\program files\google\update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre7\bin\npjpi170_05.dll
FF - plugin: c:\program files\oracle\javafx 2.1 runtime\bin\plugin2\npjp2.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_265.dll
FF - plugin: c:\windows\system32\npDeployJava1.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - Ext: BloodFire 3: [email protected] - %profile%\extensions\[email protected]
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2012-4-4 171064]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files\logmein hamachi\hamachi-2.exe [2012-6-27 1385896]
S2 gupdate;Услуга Google Update (gupdate);c:\program files\google\update\GoogleUpdate.exe [2012-6-19 136176]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-6-27 250056]
S3 gupdatem;Услуга на Google Актуализация (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2012-6-19 136176]
.
=============== Created Last 30 ================
.
2012-07-20 05:29:52 -------- d-----w- c:\documents and settings\daka_kill\application data\YoWindow
2012-07-20 05:29:50 -------- d-----w- c:\documents and settings\all users\application data\YoWindow
2012-07-20 05:29:10 -------- d-----w- c:\program files\YoWindow
2012-07-16 15:52:42 -------- d-----w- c:\documents and settings\daka_kill\application data\Mount&Blade
2012-07-16 11:24:26 -------- d-----w- c:\program files\common files\Steam
2012-07-16 05:58:06 6762896 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{17b2da57-d41c-4766-adce-d10f3de2a52e}\mpengine.dll
2012-07-14 18:02:59 -------- d-----w- c:\documents and settings\daka_kill\application data\mkvtoolnix
2012-07-14 09:18:24 -------- d-----w- c:\documents and settings\daka_kill\application data\Subtitle Edit
2012-07-14 09:18:20 -------- d-----w- c:\program files\Subtitle Edit
2012-07-09 18:07:07 6762896 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2012-07-01 14:07:10 -------- d-----w- c:\program files\KONAMI
2012-06-30 15:31:21 97848 ----a-w- c:\windows\system32\bass.dll
2012-06-27 15:54:28 -------- d-----w- c:\documents and settings\daka_kill\local settings\application data\LogMeIn Hamachi
2012-06-27 15:54:14 -------- d-----w- c:\program files\LogMeIn Hamachi
2012-06-27 06:07:09 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-06-26 18:38:26 -------- d-----w- c:\documents and settings\daka_kill\local settings\application data\Adobe
2012-06-26 18:37:58 -------- d-----w- c:\documents and settings\all users\application data\regid.1986-12.com.adobe
2012-06-26 16:54:02 -------- d-----w- c:\windows\system32\QuickTime
2012-06-26 16:53:04 -------- d-----w- c:\program files\common files\TechSmith Shared
2012-06-26 16:48:33 -------- d-----w- c:\documents and settings\daka_kill\local settings\application data\TechSmith
2012-06-25 22:06:31 -------- d-----w- c:\documents and settings\daka_kill\local settings\application data\Thinstall
2012-06-25 22:06:31 -------- d-----w- c:\documents and settings\daka_kill\application data\Thinstall
2012-06-25 16:12:45 -------- d-----w- c:\documents and settings\daka_kill\local settings\application data\Ubisoft
2012-06-25 15:38:15 26176 ---ha-w- c:\windows\system32\drivers\hamachi.sys
2012-06-25 11:06:03 -------- d-----w- c:\windows\system32\appmgmt
2012-06-24 13:56:14 -------- d-----w- c:\program files\JoWooD
2012-06-24 13:51:52 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2012-06-24 13:51:49 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2012-06-24 13:51:30 -------- d-----w- c:\documents and settings\daka_kill\application data\DAEMON Tools Lite
2012-06-24 13:51:24 -------- d-----w- c:\documents and settings\all users\application data\DAEMON Tools Lite
2012-06-22 15:35:21 -------- d-----w- c:\program files\SystemRequirementsLab
2012-06-22 15:34:46 -------- d-----w- c:\documents and settings\daka_kill\local settings\application data\Sun
2012-06-22 15:33:36 -------- d-----w- c:\program files\Oracle
2012-06-22 15:33:30 772504 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-06-22 15:33:30 687504 ----a-w- c:\windows\system32\deployJava1.dll
2012-06-22 15:33:30 143872 ----a-w- c:\windows\system32\javacpl.cpl
2012-06-22 08:53:59 -------- d-----w- c:\documents and settings\daka_kill\local settings\application data\Identities
2012-06-22 08:52:58 -------- d-----w- c:\documents and settings\daka_kill\application data\TeamViewer
2012-06-22 07:59:14 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2012-06-22 07:55:44 -------- d-----w- c:\documents and settings\daka_kill\local settings\application data\Microsoft Help
2012-06-22 07:55:34 -------- d-----w- c:\program files\Microsoft Exp[b][/b]ression
2012-06-21 09:14:00 -------- d-----w- c:\windows\system32\PreInstall
2012-06-21 09:13:59 22752 ----a-w- c:\windows\system32\spupdsvc.exe
2012-06-21 09:13:57 -------- d--h--w- c:\windows\$hf_mig$
2012-06-20 10:59:57 275696 ----a-w- c:\windows\system32\mucltui.dll
2012-06-20 10:59:57 214256 ----a-w- c:\windows\system32\muweb.dll
2012-06-20 10:59:57 17136 ----a-w- c:\windows\system32\mucltui.dll.mui
2012-06-20 10:04:39 26368 -c--a-w- c:\windows\system32\dllcache\usbstor.sys
2012-06-20 09:21:09 -------- d-----w- c:\documents and settings\daka_kill\dwhelper
.
==================== Find3M ====================
.
2012-07-12 08:33:21 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-19 13:28:44 14656 ----a-w- c:\windows\gdrv.sys
2012-06-19 13:26:46 315392 ----a-w- c:\windows\HideWin.exe
2012-06-02 12:19:44 22040 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 12:19:38 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 12:19:38 15384 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 12:19:34 15384 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 12:19:30 17944 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-04-26 18:07:50 841728 ----a-w- c:\windows\system32\yowindow.scr
.
============= FINISH: 9:37:51,71 ===============

attach.txt

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-09-30.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 19.6.2012 г. 15:21:21
System Uptime: 20.7.2012 г. 07:43:16 (2 hours ago)
.
Motherboard: Gigabyte Technology Co., Ltd. |  | M61SME-S2
Processor: AMD Sempron(tm) Processor LE-1150 | Socket M2 | 2009/200mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 15 GiB total, 6,784 GiB free.
D: is FIXED (NTFS) - 59 GiB total, 3,076 GiB free.
E: is FIXED (NTFS) - 76 GiB total, 3,774 GiB free.
F: is CDROM ()
G: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP30: 03.7.2012 г. 13:14:52 - Контролна точка на системата
RP31: 04.7.2012 г. 12:46:07 - Software Distribution Service 3.0
RP32: 05.7.2012 г. 14:01:06 - Software Distribution Service 3.0
RP33: 05.7.2012 г. 17:54:12 - Software Distribution Service 3.0
RP34: 06.7.2012 г. 19:18:22 - Контролна точка на системата
RP35: 07.7.2012 г. 10:01:00 - Software Distribution Service 3.0
RP36: 08.7.2012 г. 14:08:51 - Контролна точка на системата
RP37: 09.7.2012 г. 14:50:46 - Software Distribution Service 3.0
RP38: 09.7.2012 г. 21:07:04 - Software Distribution Service 3.0
RP39: 10.7.2012 г. 21:38:59 - Контролна точка на системата
RP40: 12.7.2012 г. 12:57:27 - Контролна точка на системата
RP41: 13.7.2012 г. 13:13:32 - Контролна точка на системата
RP42: 14.7.2012 г. 17:06:17 - Контролна точка на системата
RP43: 15.7.2012 г. 21:50:05 - Контролна точка на системата
RP44: 16.7.2012 г. 14:24:22 - Installed Steam
RP45: 17.7.2012 г. 16:14:28 - Контролна точка на системата
RP46: 18.7.2012 г. 20:46:12 - Контролна точка на системата
.
==== Installed Programs ======================
.
µTorrent
Пакет за езиков интерфейс на Windows
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Aegisub 2.1.7
BS.Player PRO
Bulgarian (Phonetic) by Iliya Dankov
Camtasia Studio 7
DAEMON Tools Toolbar
Google Chrome
Google Update Helper
Java Auto Updater
Java(TM) 7 Update 5
JavaFX 2.1.1
K-Lite Codec Pack 7.2.0 (Full)
LogMeIn Hamachi
Microsoft .NET Framework 2.0
Microsoft Application Error Reporting
Microsoft Exp[b][/b]ression Web
Microsoft Exp[b][/b]ression Web MUI (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Security Client
Microsoft Security Essentials
Microsoft Software Update for Web Folders  (English) 12
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
MKVtoolnix 4.5.0
Mozilla Firefox (3.6.28)
Neighbours From Hell
NVIDIA Drivers
Realtek High Definition Audio Driver
Skype Toolbars
Skype™ 4.2
Steam
Subtitle Edit 3.2.8
System Requirements Lab CYRI
The KMPlayer 2.9.4.1434
Unlocker 1.9.1
Update for Windows XP (KB898461)
Vista Rainbar 4.3
WebFldrs XP
Windows Driver Package - Advanced Micro Devices (AmdK8) Processor  (05/27/2006 1.3.2.0)
WinRAR 4.10 (32-битова версия)
YoWindow
.
==== Event Viewer Messages From Past Week ========
.
15.7.2012 г. 09:32:33, error: Dhcp [1002]  - The IP address lease 192.168.1.2 for the Network Card with network address 001A4D9BAA7F has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
15.7.2012 г. 00:47:06, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
15.7.2012 г. 00:33:13, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
15.7.2012 г. 00:32:43, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
15.7.2012 г. 00:13:04, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
15.7.2012 г. 00:12:34, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 23:51:45, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 23:51:15, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 23:13:27, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 23:12:57, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 22:48:13, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 22:47:43, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 22:26:50, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 22:26:20, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 22:05:31, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 22:05:01, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 21:44:12, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 21:43:42, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 21:22:53, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 21:22:24, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 21:01:34, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 21:01:04, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 20:40:15, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 20:39:46, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 20:18:57, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 20:18:27, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 19:58:45, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 19:58:15, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 19:57:38, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 19:57:08, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 13:50:34, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 13:50:04, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 11:52:08, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 11:51:38, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 09:50:11, error: Microsoft Antimalware [2001]  - Microsoft Antimalware се натъкна на грешка при опит за актуализиране на сигнатурите.  Нова версия на сигнатурата:   Предишна версия на сигнатурата: 1.129.1298.0  Източник на актуализация: Сървър на Microsoft  Етап на актуализация: Търсене  Път към източник: Default URL  Тип на сигнатурата: AntiVirus  Тип на актуализация: Пълна  Потребител: NT AUTHORITY\SYSTEM  Текуща версия на ядрото:   Предишна версия на ядрото: 1.1.8502.0  Код на грешка: 0x80080005  Описание на грешката: Server execution failed
14.7.2012 г. 09:39:10, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 09:38:41, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 09:38:10, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 09:37:41, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 09:37:40, error: Service Control Manager [7022]  - The Automatic Updates service hung on starting.
14.7.2012 г. 09:36:16, error: Service Control Manager [7023]  - The Wireless Zero Configuration service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 09:36:16, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 09:36:16, error: Service Control Manager [7023]  - The Error Reporting Service service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 09:36:16, error: Service Control Manager [7023]  - The Cryptographic Services service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 09:36:16, error: Service Control Manager [7023]  - The COM+ Event System service terminated with the following error:  The specified module could not be found.
14.7.2012 г. 09:36:16, error: Service Control Manager [7001]  - The Windows Firewall/Internet Connection Sharing (ICS) service depends on the Network Connections service which failed to start because of the following error:  The specified module could not be found.
13.7.2012 г. 19:09:43, error: Dhcp [1002]  - The IP address lease 192.168.1.2 for the Network Card with network address 001A4D9BAA7F has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
13.7.2012 г. 17:45:41, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
13.7.2012 г. 17:45:11, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
13.7.2012 г. 17:24:22, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
13.7.2012 г. 17:23:52, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
13.7.2012 г. 17:03:03, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
13.7.2012 г. 17:02:33, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
13.7.2012 г. 16:41:44, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
13.7.2012 г. 16:41:14, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
13.7.2012 г. 16:20:25, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
13.7.2012 г. 16:19:55, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
13.7.2012 г. 15:59:06, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
13.7.2012 г. 15:58:36, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
13.7.2012 г. 15:37:47, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
13.7.2012 г. 15:37:17, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
13.7.2012 г. 15:16:26, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
13.7.2012 г. 15:15:56, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
13.7.2012 г. 15:10:47, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
13.7.2012 г. 15:10:17, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
13.7.2012 г. 14:49:41, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
13.7.2012 г. 14:49:11, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
13.7.2012 г. 14:28:14, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
13.7.2012 г. 14:27:44, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
13.7.2012 г. 14:07:11, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
13.7.2012 г. 14:06:41, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
13.7.2012 г. 07:24:03, error: Microsoft Antimalware [2001]  - Microsoft Antimalware се натъкна на грешка при опит за актуализиране на сигнатурите.  Нова версия на сигнатурата:   Предишна версия на сигнатурата: 1.129.1298.0  Източник на актуализация: Сървър на Microsoft  Етап на актуализация: Търсене  Път към източник: Default URL  Тип на сигнатурата: AntiVirus  Тип на актуализация: Пълна  Потребител: NT AUTHORITY\SYSTEM  Текуща версия на ядрото:   Предишна версия на ядрото: 1.1.8502.0  Код на грешка: 0x80080005  Описание на грешката: Server execution failed
13.7.2012 г. 07:12:32, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
13.7.2012 г. 07:12:02, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
13.7.2012 г. 07:11:33, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
13.7.2012 г. 07:11:31, error: Service Control Manager [7022]  - The Automatic Updates service hung on starting.
13.7.2012 г. 07:10:06, error: Service Control Manager [7023]  - The Wireless Zero Configuration service terminated with the following error:  The specified module could not be found.
13.7.2012 г. 07:10:06, error: Service Control Manager [7023]  - The Network Connections service terminated with the following error:  The specified module could not be found.
13.7.2012 г. 07:10:06, error: Service Control Manager [7023]  - The Error Reporting Service service terminated with the following error:  The specified module could not be found.
13.7.2012 г. 07:10:06, error: Service Control Manager [7023]  - The Cryptographic Services service terminated with the following error:  The specified module could not be found.
13.7.2012 г. 07:10:06, error: Service Control Manager [7023]  - The COM+ Event System service terminated with the following error:  The specified module could not be found.
13.7.2012 г. 07:10:06, error: Service Control Manager [7001]  - The Windows Firewall/Internet Connection Sharing (ICS) service depends on the Network Connections service which failed to start because of the following error:  The specified module could not be found.
13.7.2012 г. 07:10:06, error: Service Control Manager [7001]  - The System Event Notification service depends on the COM+ Event System service which failed to start because of the following error:  The specified module could not be found.
.
==== End Of File ===========================

Моля изтеглете Farbar Service Scanner и я стартирайте.

  • Сложете всички отметки.
  • Натиснете бутона "Scan".
  • Ще се създаде лог файл с името (FSS.txt) в папката откъдето стартирате инструмента.
  • Копирайте съдържанието на лог файла в следващия си пост.

PS: MSE не е особено подходящ избор за XP. Някои от функциите му не бачкат под тази ОС. Отделно ако не е лицензирана може да са му прекъснали достъпа до ъпдейтите!

  • Автор

Farbar Service Scanner Version: 19-07-2012
Ran by daka_kill (administrator) on 20-07-2012 at 16:16:32
Running from "C:Documents and Settingsdaka_killDesktop"
Microsoft Windows XP Professional Service Pack 3 (X86)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.

Windows Firewall:
=============
sharedaccess Service is not running. Checking service configuration:
The start type of sharedaccess service is OK.
The ImagePath of sharedaccess service is OK.
The ServiceDll of sharedaccess service is OK.
netman Service is not running. Checking service configuration:
The start type of netman service is OK.
The ImagePath of netman service is OK.
The ServiceDll of netman service is OK.

Firewall Disabled Policy:
==================

System Restore:
============
System Restore Disabled Policy:
========================

Security Center:
============
Windows Update:
============
wuauserv Service is not running. Checking service configuration:
The start type of wuauserv service is OK.
The ImagePath of wuauserv service is OK.
The ServiceDll of wuauserv: "C:WINDOWSsystem32wuauserv.dll".
EventSystem Service is not running. Checking service configuration:
The start type of EventSystem service is OK.
The ImagePath of EventSystem: "C:WINDOWSsystem32svchost.exe -k netsvcs".
The ServiceDll of EventSystem: "C:WINDOWSsystem32es.dll".
cryptsvc Service is not running. Checking service configuration:
The start type of cryptsvc service is OK.
The ImagePath of cryptsvc service is OK.
The ServiceDll of cryptsvc service is OK.

Windows Autoupdate Disabled Policy:
============================

File Check:
========
C:WINDOWSsystem32dhcpcsvc.dll => MD5 is legit
C:WINDOWSsystem32Driversafd.sys => MD5 is legit
C:WINDOWSsystem32Driversnetbt.sys => MD5 is legit
C:WINDOWSsystem32Driverstcpip.sys => MD5 is legit
C:WINDOWSsystem32Driversipsec.sys => MD5 is legit
C:WINDOWSsystem32dnsrslvr.dll => MD5 is legit
C:WINDOWSsystem32ipnathlp.dll => MD5 is legit
C:WINDOWSsystem32netman.dll => MD5 is legit
C:WINDOWSsystem32wbemWMIsvc.dll => MD5 is legit
C:WINDOWSsystem32srsvc.dll => MD5 is legit
C:WINDOWSsystem32Driverssr.sys => MD5 is legit
C:WINDOWSsystem32wscsvc.dll => MD5 is legit
C:WINDOWSsystem32wbemWMIsvc.dll => MD5 is legit
C:WINDOWSsystem32wuauserv.dll => MD5 is legit
C:WINDOWSsystem32qmgr.dll => MD5 is legit
ATTENTION!=====> C:WINDOWSsystem32es.dll FILE IS MISSING AND SHOULD BE RESTORED.
C:WINDOWSsystem32cryptsvc.dll => MD5 is legit
C:WINDOWSsystem32svchost.exe => MD5 is legit
C:WINDOWSsystem32rpcss.dll => MD5 is legit
C:WINDOWSsystem32services.exe => MD5 is legit
Extra List:
=======
Gpc(6) IPSec(4) NetBT(5) PSched(7) Tcpip(3)
0x0700000004000000010000000200000003000000050000000600000007000000
IpSec Tag value is correct.
**** End of log ****

ето

Изтеглете и стартирайте следните два файла:

http://download.bleepingcomputer.com/win-services/xp/wuauserv.reg

http://download.bleepingcomputer.com/win-services/xp/EventSystem.reg

След това:

Изтеглете този инструмент - Windows Repair All in one

Инсталирайте приложението и го стартирайте.

От стъпка 2 => стартирайте Check Disk

Публикувано изображение

От стъпка 3 => стартирайте SFC

Публикувано изображение

от Start Repairs натиснете Start и оттук вече сложете всички отметки показани на снимката:

Публикувано изображение

Сложете отметка пред restart system when finished и натиснете Start.

Пишете после как е положението.

Стъпка 3 по-принцип изисква наличието на инсталационен диск с XP.

Нещо сериозно е омазан този Windows...Незнам от вирус или просто самия релийз е орязан, но нещо не е както трябва!

1. Изтеглете ComboFix от BleepingComputer

и го запазете (бутон Save -> Save as) ComboFix на вашия десктоп:

Публикувано изображение

След приключване на изтеглянето на ComboFix, иконката на програмата би трябвало да изглежда така:

Публикувано изображение

2. Затворете всички работещи приложения, отворени прозорци и програми работещи във фонов режим. Спрете временно защитата в реално време на антивирусната програма и на другите програми за сигурност, ако има такива.

3. Стартирайте с двоен клик Combofix.exe. Изберете YES, за да се съгласите с условията за използване на програмата. Важно: По време на работата на ComboFix не бива да се движи мишката и да се натискат клавиши от клавиатурата. Просто търпеливо оставете ComboFix да си свърши работата, без да използвате компютъра за други цели.

4. ComboFix ще провери дали Windows Recovery Console e инсталиранa.

*Ако Windows Recovery Console не е инсталирана, ще е необходимо да използвате YES за инсталация на Windows Recovery Console

*Ако Windows Recovery Console е инсталирана, ComboFix ще продължи работата си.

Публикувано изображение

Забележка: Необходимо е да сте свързани към Интернет за да може Windows Recovery Console да се изтегли.

След инсталация на Windows Recovery Console потвърдете с YES, за да продължите напред. Снимка:

Публикувано изображение

5. ComboFix ще спре временно Интернет връзката, но след като приключи работата на програмата тази връзка ще бъде възстановена автоматично. ComboFix ще сканира за проблеми и за заразени файлове, като това може да отнеме известно време. Моля да бъдете търпеливи. Ако има проблем с Интернет връзката след приключване на работата на ComboFix, моля да прочетете това: Manually restoring the Internet connection section.

6. Когато работата на ComboFix приключи, ще се появи текстов документ (log) в Notepad:

Публикувано изображение

Копирайте с (Copy) и поставете с (Paste) съдържанието на лога в следващия си коментар.

Не го стартирайте втори път засега. Рестартирайте машината и вижте дали ще се генерира лог файл. Вижте и в C:Combofix.txt за такъв файл и ако има го публикувайте.

Това означава, че проверката не е завършила както трябва. Стартирайте Combofix отново като преди това затворите всички приложения и защитни продукти. Да видим дали сега ще създаде лог файл.

  • Автор

п.п. затворих скайпа браузърите (антивирусната сама се затвори и ми изписва, че има още някои неща, които трябва да се затворят, но въпреки това ще продължи ... ) кое друго трябва да затворя ?

Временно деинсталирайте антивирусната. После рестартирайте, затворете отново излишните приложения и стартирайте Combofix.

  • Автор

трудно, тъй като не ми зарежда програмите в "добавяне и премахване" зареди ми го, но много бавно -_-''

Редактирано от StAnBeTyYy (преглед на промените)

Как го ос*ахте толкова? :)

Пробвайте през Safe Mode!

За ADD/Remove programs пробвайте следното:

Start => Run => въведете командата regsvr32 appwiz.cpl и натиснете Enter

Вижте дали сега списъка се появява.

За деинсталация на антивирусната може да използвате и следните неща:

appremover

Microsoft FixIt

  • Автор

ComboFix 12-07-20.02 - daka_kill 07.2012 г.   0:24.5.1 - x86
Microsoft Windows XP Professional  5.1.2600.3.1251.359.1033.18.959.655 [GMT 3:00]
Running from: c:documents and settingsdaka_killDesktopComboFix.exe
.
.
(((((((((((((((((((((((((   Files Created from 2012-06-20 to 2012-07-20  )))))))))))))))))))))))))))))))
.
.
2012-07-20 16:01 . 2012-07-20 16:08 181064 ----a-w- c:windowsPSEXESVC.EXE
2012-07-20 16:00 . 2012-07-20 16:00 -------- d-----w- c:program filesTweaking.com
2012-07-20 05:29 . 2012-07-20 08:37 -------- d-----w- c:documents and settingsdaka_killApplication DataYoWindow
2012-07-20 05:29 . 2012-07-20 05:29 -------- d-----w- c:documents and settingsAll UsersApplication DataYoWindow
2012-07-20 05:29 . 2012-07-20 05:29 -------- d-----w- c:program filesYoWindow
2012-07-16 15:52 . 2012-07-16 16:04 -------- d-----w- c:documents and settingsdaka_killApplication DataMount&Blade
2012-07-16 11:24 . 2012-07-16 11:37 -------- d-----w- c:program filesCommon FilesSteam
2012-07-14 18:02 . 2012-07-14 18:02 -------- d-----w- c:documents and settingsdaka_killApplication Datamkvtoolnix
2012-07-14 09:18 . 2012-07-14 09:19 -------- d-----w- c:documents and settingsdaka_killApplication DataSubtitle Edit
2012-07-14 09:18 . 2012-07-14 09:18 -------- d-----w- c:program filesSubtitle Edit
2012-07-01 14:07 . 2012-07-01 14:25 -------- d-----w- c:program filesKONAMI
2012-06-30 15:31 . 2003-12-17 11:38 97848 ----a-w- c:windowssystem32bass.dll
2012-06-27 15:54 . 2012-07-20 22:12 -------- d-----w- c:documents and settingsLocalServiceLocal SettingsApplication DataLogMeIn Hamachi
2012-06-27 15:54 . 2012-07-20 21:03 -------- d-----w- c:documents and settingsdaka_killLocal SettingsApplication DataLogMeIn Hamachi
2012-06-27 15:54 . 2012-06-27 15:54 -------- d-----w- c:program filesLogMeIn Hamachi
2012-06-27 06:07 . 2012-07-12 08:33 426184 ----a-w- c:windowssystem32FlashPlayerApp.exe
2012-06-26 18:38 . 2012-06-26 18:39 -------- d-----w- c:documents and settingsdaka_killLocal SettingsApplication DataAdobe
2012-06-26 18:37 . 2012-06-26 18:37 -------- d-----w- c:documents and settingsAll UsersApplication Dataregid.1986-12.com.adobe
2012-06-26 18:37 . 2012-06-26 18:37 -------- d-----w- c:program filesCommon FilesAdobe
2012-06-26 16:54 . 2012-06-26 16:54 -------- d-----w- c:windowssystem32QuickTime
2012-06-26 16:53 . 2012-06-26 16:53 -------- d-----w- c:program filesQuickTime
2012-06-26 16:53 . 2012-06-26 16:53 -------- d-----w- c:program filesCommon FilesTechSmith Shared
2012-06-26 16:48 . 2012-06-26 16:48 -------- d-----w- c:documents and settingsdaka_killLocal SettingsApplication DataTechSmith
2012-06-26 16:48 . 2012-06-26 16:53 -------- d-----w- c:documents and settingsAll UsersApplication DataTechSmith
2012-06-25 22:06 . 2012-06-26 17:45 -------- d-----w- c:documents and settingsdaka_killApplication DataThinstall
2012-06-25 22:06 . 2012-06-25 22:06 -------- d-----w- c:documents and settingsdaka_killLocal SettingsApplication DataThinstall
2012-06-25 16:12 . 2012-06-25 16:12 -------- d-----w- c:documents and settingsdaka_killLocal SettingsApplication DataUbisoft
2012-06-25 16:12 . 2012-06-25 16:12 -------- d-----w- c:documents and settingsAll UsersApplication DataUbisoft
2012-06-25 15:38 . 2012-06-27 17:18 -------- d-----w- c:documents and settingsdaka_killApplication DataHamachi
2012-06-25 15:38 . 2009-03-18 14:35 26176 ---ha-w- c:windowssystem32drivershamachi.sys
2012-06-24 13:56 . 2012-06-24 13:56 -------- d-----w- c:program filesJoWooD
2012-06-24 13:51 . 2012-06-24 13:51 -------- d-----w- c:program filesDAEMON Tools Toolbar
2012-06-24 13:51 . 2012-06-24 13:51 691696 ----a-w- c:windowssystem32driverssptd.sys
2012-06-24 13:51 . 2012-06-24 13:55 -------- d-----w- c:documents and settingsdaka_killApplication DataDAEMON Tools Lite
2012-06-24 13:51 . 2012-06-24 13:51 -------- d-----w- c:documents and settingsAll UsersApplication DataDAEMON Tools Lite
2012-06-22 15:35 . 2012-06-22 15:35 -------- d-----w- c:program filesSystemRequirementsLab
2012-06-22 15:34 . 2012-06-22 15:34 -------- d-----w- c:documents and settingsdaka_killApplication DataSystemRequirementsLab
2012-06-22 15:34 . 2012-06-22 15:34 -------- d-----w- c:windowsSun
2012-06-22 15:34 . 2012-06-22 15:34 -------- d-----w- c:documents and settingsdaka_killLocal SettingsApplication DataSun
2012-06-22 15:33 . 2012-06-22 15:33 -------- d-----w- c:program filesCommon FilesJava
2012-06-22 15:33 . 2012-06-22 15:33 -------- d-----w- c:program filesOracle
2012-06-22 15:33 . 2012-06-22 15:33 -------- d-----w- c:documents and settingsdaka_killApplication DataOracle
2012-06-22 15:33 . 2012-05-04 16:29 143872 ----a-w- c:windowssystem32javacpl.cpl
2012-06-22 15:33 . 2012-05-04 16:29 772504 ----a-w- c:windowssystem32npDeployJava1.dll
2012-06-22 15:33 . 2012-05-04 16:29 687504 ----a-w- c:windowssystem32deployJava1.dll
2012-06-22 15:32 . 2012-06-22 15:32 -------- d-----w- c:program filesJava
2012-06-22 08:53 . 2012-06-22 08:53 -------- d-----w- c:documents and settingsdaka_killLocal SettingsApplication DataIdentities
2012-06-22 08:52 . 2012-06-27 11:17 -------- d-----w- c:documents and settingsdaka_killApplication DataTeamViewer
2012-06-22 07:59 . 2012-06-22 07:59 -------- d-----w- c:program filesMicrosoft Works
2012-06-22 07:59 . 2012-06-22 07:59 -------- d-----w- c:program filesMicrosoft Visual Studio 8
2012-06-22 07:55 . 2012-06-22 07:55 -------- d-----w- c:documents and settingsdaka_killLocal SettingsApplication DataMicrosoft Help
2012-06-22 07:55 . 2012-06-22 07:58 -------- d-----w- c:program filesMicrosoft Exp[b][/b]ression
2012-06-22 07:55 . 2012-06-22 07:59 -------- d-----w- c:documents and settingsAll UsersApplication DataMicrosoft Help
2012-06-21 09:13 . 2005-02-25 03:35 22752 ----a-w- c:windowssystem32spupdsvc.exe
2012-06-21 09:13 . 2012-06-21 09:23 -------- d--h--w- c:windows$hf_mig$
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-12 08:33 . 2012-06-19 13:40 70344 ----a-w- c:windowssystem32FlashPlayerCPLApp.cpl
2012-06-19 13:28 . 2012-06-19 13:22 14656 ----a-w- c:windowsgdrv.sys
2012-06-19 13:26 . 2012-06-19 13:26 315392 ----a-w- c:windowsHideWin.exe
2012-06-02 12:19 . 2012-06-02 12:19 22040 ----a-w- c:windowssystem32wucltui.dll.mui
2012-06-02 12:19 . 2012-06-19 12:17 329240 ----a-w- c:windowssystem32wucltui.dll
2012-06-02 12:19 . 2012-06-19 12:17 219160 ----a-w- c:windowssystem32wuaucpl.cpl
2012-06-02 12:19 . 2012-06-19 12:17 210968 ----a-w- c:windowssystem32wuweb.dll
2012-06-02 12:19 . 2012-06-02 12:19 15384 ----a-w- c:windowssystem32wuaucpl.cpl.mui
2012-06-02 12:19 . 2012-06-19 12:17 53784 ----a-w- c:windowssystem32wuauclt.exe
2012-06-02 12:19 . 2012-06-19 12:17 35864 ----a-w- c:windowssystem32wups.dll
2012-06-02 12:19 . 2012-06-02 12:19 45080 ----a-w- c:windowssystem32wups2.dll
2012-06-02 12:19 . 2012-06-02 12:19 15384 ----a-w- c:windowssystem32wuapi.dll.mui
2012-06-02 12:19 . 2008-04-14 02:41 97304 ----a-w- c:windowssystem32cdm.dll
2012-06-02 12:19 . 2012-06-02 12:19 17944 ----a-w- c:windowssystem32wuaueng.dll.mui
2012-06-02 12:19 . 2012-06-19 12:17 577048 ----a-w- c:windowssystem32wuapi.dll
2012-06-02 12:19 . 2012-06-19 12:17 1933848 ----a-w- c:windowssystem32wuaueng.dll
2012-06-02 12:18 . 2012-06-20 10:59 275696 ----a-w- c:windowssystem32mucltui.dll
2012-06-02 12:18 . 2012-06-20 10:59 214256 ----a-w- c:windowssystem32muweb.dll
2012-06-02 12:18 . 2012-06-20 10:59 17136 ----a-w- c:windowssystem32mucltui.dll.mui
2012-04-26 18:07 . 2012-04-26 18:07 841728 ----a-w- c:windowssystem32yowindow.scr
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
Cryptography Services Error !!
.
c:windowsSystem32es.dll ... is missing !!
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"Vista Rainbar"="c:program filesVista RainbarRainmeter.exe" [2006-01-21 118784]
"uTorrent"="c:program filesuTorrentuTorrent.exe" [2012-06-19 321328]
"Skype"="c:program filesSkypePhoneSkype.exe" [2010-09-02 13351304]
"RocketDock"="e:programsRocketDockRocketDock.exe" [2007-09-02 495616]
"DAEMON Tools Lite"="e:programsDaemon Tools LiteDTLite.exe" [2009-10-30 369200]
.
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"NvCplDaemon"="c:windowssystem32NvCpl.dll" [2006-10-31 7634944]
"nwiz"="nwiz.exe" [2006-10-31 1622016]
"NvMediaCenter"="c:windowssystem32NvMcTray.dll" [2006-10-31 86016]
"RTHDCPL"="RTHDCPL.EXE" [2007-01-30 16116224]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"UnlockerAssistant"="c:program filesUnlockerUnlockerAssistant.exe" [2010-07-04 17408]
"SunJavaUpdateSched"="c:program filesCommon FilesJavaJava Updatejusched.exe" [2012-01-17 252296]
"LogMeIn Hamachi Ui"="c:program filesLogMeIn Hamachihamachi-2-ui.exe" [2012-06-27 1996200]
.
[HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRun]
"CTFMON.EXE"="c:windowssystem32CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRunOnce]
"nltide_3"="advpack.dll" [2008-04-14 99840]
.
c:documents and settingsdaka_killStart MenuProgramsStartup
Yowindow.lnk - e:yowindow unlimited edition 3.0 build 85 finalyowindow.exe [2012-4-26 875008]
.
[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionpoliciesexplorer]
"NoSMMyPictures"= 1 (0x1)
.
[HKEY_USERS.defaultsoftwaremicrosoftwindowscurrentversionpoliciesexplorer]
"NoSMMyPictures"= 1 (0x1)
.
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]
"%windir%Network Diagnosticxpnetdiag.exe"=
"%windir%system32sessmgr.exe"=
"c:Program FilesuTorrentuTorrent.exe"=
"c:Program FilesSkypePlugin ManagerskypePM.exe"=
"e:ProgramsBittorrent v6.1.2 Build 13422 Portable By StingerSBittorrent v6.1.2 Build 13422 Portable By StingerSBitTorrent.exe"=
"d:GamesCounter-Strike 1.6hl.exe"=
"d:GamesTzarTzar.exe"=
"c:Program FilesSkypePhoneSkype.exe"=
.
R0 sptd;sptd;c:windowssystem32driverssptd.sys [24.6.2012 г. 16:51 691696]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:program filesLogMeIn Hamachihamachi-2.exe [27.6.2012 г. 12:29 1385896]
S2 gupdate;Услуга Google Update (gupdate);c:program filesGoogleUpdateGoogleUpdate.exe [19.6.2012 г. 19:25 136176]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:windowssystem32MacromedFlashFlashPlayerUpdateService.exe [27.6.2012 г. 09:07 250056]
S3 gupdatem;Услуга на Google Актуализация (gupdatem);c:program filesGoogleUpdateGoogleUpdate.exe [19.6.2012 г. 19:25 136176]
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-20 c:windowsTasksAdobe Flash Player Updater.job
- c:windowssystem32MacromedFlashFlashPlayerUpdateService.exe [2012-06-27 08:33]
.
2012-07-20 c:windowsTasksGoogleUpdateTaskMachineCore.job
- c:program filesGoogleUpdateGoogleUpdate.exe [2012-06-19 16:25]
.
2012-07-20 c:windowsTasksGoogleUpdateTaskMachineUA.job
- c:program filesGoogleUpdateGoogleUpdate.exe [2012-06-19 16:25]
.
2012-07-20 c:windowsTasksMicrosoft Antimalware Scheduled Scan.job
- c:program filesMicrosoft Security ClientMpCmdRun.exe [2012-05-02 06:59]
.
.
------- Supplementary Scan -------
.
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:documents and settingsdaka_killApplication DataMozillaFirefoxProfilesrdfjra4a.default
FF - prefs.js: browser.search.selectedEngine - Vbox7.com
FF - prefs.js: browser.startup.homepage - hxxp://www.google.bg/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:program filesMozilla Firefoxextensions{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%extensions{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - Ext: BloodFire 3: [email protected] - %profile%[email protected]
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%extensions{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-Beautiful Rain - c:program filesScreenSaverGiftBeautiful RainBeautiful RainUninstall Beautiful Rain Screensaver.exe
AddRemove-Fantastic Space Star - c:program filesScreenSaverGiftFantastic Space StarFantastic Space StarUninstall Fantastic Space Star Screensaver.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-07-21 01:22
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ... 
.
scanning hidden autostart entries ...
.
scanning hidden files ... 
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2012-07-21  01:25:17
ComboFix-quarantined-files.txt  2012-07-20 22:25
.
Pre-Run: 7 756 455 936 bytes free
Post-Run: 7 747 309 568 bytes free
.
- - End Of File - - 7A06CAC00DB569D7220C08843AE51E31

оставих го цяла вечер, докато бъде готово ...

Изтеглете SystemLook и запазете програмата на десктопа.

  • Кликнете два пъти върху SystemLook.exe, за да стартирате програмата.
  • Копирайте съдържанието от цитата по-долу в текстовото поле на програмата:

    :reg

    HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesCryptsvc /s

  • Кликнете на бутона Look, за да започне сканирането.
  • Когато сканирането завърши ще се отвори Notepad с резултата от сканирането. После публикувайте лог файла в следващия си коментар.

Също така отворете notepad.exe и с copy/paste въведете:

net stop wuauserv

cd %systemroot%SoftwareDistribution

ren Download Download.old

net start wuauserv

net stop bits

net start bits

net stop cryptsvc

cd %systemroot%system32

ren catroot2 catroot2old

net start cryptsvc

Запазете филма с името fix.bat и го стартирайте.

Рестартирайте машинатa.

Изтеглете този файл и го запазете на десктопа.

Отворете notepad и с copy/paste въведете следната информация:

@echo Unpacking files ...

@echo (This window will close when it's done)

@echo off

MKdir C:SP3

WindowsXP-KB936929-SP3-x86-ENU.exe -x: C:SP3 /quiet

cd C:SP3i386

expand es.dl_ C:SP3es.dll

Запазете файла с името expand.bat и го стартирайте.

Ще се създаде папка на C: с името SP3.

След това:

  • Отворете notepad и с copy/paste въведете следната информация.

    Fcopy::

    C:SP3es.dll | c:windowsSystem32es.dll

  • Запазете файла с име CFScript и го провлачете и пуснете в Combofix (както е показано на картинката отдолу).

    Публикувано изображение

  • По време на сканиране от страна на ComboFix не стартирайте никакви други приложения, не натискайте клавиши от клавиатурата и не местете мишката !
  • Публикувайте лог файла, който ще се създаде след рестарта на компютъра в следващия си пост.
  • Автор

ето за SystemLook - много бързо зареди (нямаше и 3 секунди)

SystemLook 30.07.11 by jpshortstuff
Log created at 19:16 on 21/07/2012 by daka_kill
Administrator - Elevation successful
========== reg ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cryptsvc]
"DependOnService"="RpcSs"
"Description"="Provides three management services: Catalog Database Service, which confirms the signatures of Windows files; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Key Service, which helps enroll this computer for certificates. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start."
"DisplayName"="CryptSvc"
"ErrorControl"= 0x0000000001 (1)
"ImagePath"="%SystemRoot%\system32\svchost.exe -k netsvcs"
"ObjectName"="LocalSystem"
"Start"= 0x0000000002 (2)
"Type"= 0x0000000020 (32)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cryptsvc\Parameters]
"ServiceDll"="%SystemRoot%\System32\cryptsvc.dll"
"ServiceMain"="CryptServiceMain"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cryptsvc\Security]
"Security"=00 00 0e 00 01  (REG_BINARY)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cryptsvc\Enum]
"0"="Root\LEGACY_CRYPTSVC\0000"
"Count"= 0x0000000001 (1)
"NextInstance"= 0x0000000001 (1)

-= EOF =-

а за 2-рото с комбофикс снимката не ми я показва и не знам къде точно да я сложа

  • Автор

поставих това, което си дал горе, записах го както горе си писал, драгвам го по същия начин, но направо ми я стартира програмата, изчаках да зареди докрай (както при обикновенното сканиране на комбофикс) и 1 час по-късно ми излезе този Log файл:

ComboFix 12-07-20.02 - daka_kill 07.2012 г.  20:09:30.6.1 - x86
Microsoft Windows XP Professional  5.1.2600.3.1251.359.1033.18.959.493 [GMT 3:00]
Running from: c:documents and settingsdaka_killDesktopComboFix.exe
Command switches used :: c:documents and settingsdaka_killDesktopCFScript.txt
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
--------------- FCopy ---------------
.
c:sp3es.dll --> c:windowsSystem32es.dll
.
(((((((((((((((((((((((((   Files Created from 2012-06-21 to 2012-07-21  )))))))))))))))))))))))))))))))
.
.
2012-07-21 17:09 . 2008-04-14 02:41 246272 ----a-w- c:windowssystem32es.dll
2012-07-21 17:07 . 2012-07-21 17:09 -------- d-----w- c:windowssystem32CatRoot2
2012-07-21 16:57 . 2012-07-21 16:58 -------- d-----w- C:SP3
2012-07-21 10:15 . 2012-07-21 10:24 -------- d-----w- c:documents and settingsdaka_killApplication DataMount&Blade Warband
2012-07-21 10:10 . 2012-07-21 10:10 -------- d-----w- c:windowsLogs
2012-07-20 16:01 . 2012-07-20 16:08 181064 ----a-w- c:windowsPSEXESVC.EXE
2012-07-20 16:00 . 2012-07-20 16:00 -------- d-----w- c:program filesTweaking.com
2012-07-20 05:29 . 2012-07-20 08:37 -------- d-----w- c:documents and settingsdaka_killApplication DataYoWindow
2012-07-20 05:29 . 2012-07-20 05:29 -------- d-----w- c:documents and settingsAll UsersApplication DataYoWindow
2012-07-20 05:29 . 2012-07-20 05:29 -------- d-----w- c:program filesYoWindow
2012-07-16 15:52 . 2012-07-16 16:04 -------- d-----w- c:documents and settingsdaka_killApplication DataMount&Blade
2012-07-16 11:24 . 2012-07-16 11:37 -------- d-----w- c:program filesCommon FilesSteam
2012-07-14 18:02 . 2012-07-14 18:02 -------- d-----w- c:documents and settingsdaka_killApplication Datamkvtoolnix
2012-07-14 09:18 . 2012-07-14 09:19 -------- d-----w- c:documents and settingsdaka_killApplication DataSubtitle Edit
2012-07-14 09:18 . 2012-07-14 09:18 -------- d-----w- c:program filesSubtitle Edit
2012-07-01 14:07 . 2012-07-01 14:25 -------- d-----w- c:program filesKONAMI
2012-06-30 15:31 . 2003-12-17 11:38 97848 ----a-w- c:windowssystem32bass.dll
2012-06-27 15:54 . 2012-07-21 18:07 -------- d-----w- c:documents and settingsLocalServiceLocal SettingsApplication DataLogMeIn Hamachi
2012-06-27 15:54 . 2012-07-21 16:48 -------- d-----w- c:documents and settingsdaka_killLocal SettingsApplication DataLogMeIn Hamachi
2012-06-27 15:54 . 2012-06-27 15:54 -------- d-----w- c:program filesLogMeIn Hamachi
2012-06-27 06:07 . 2012-07-12 08:33 426184 ----a-w- c:windowssystem32FlashPlayerApp.exe
2012-06-26 18:38 . 2012-06-26 18:39 -------- d-----w- c:documents and settingsdaka_killLocal SettingsApplication DataAdobe
2012-06-26 18:37 . 2012-06-26 18:37 -------- d-----w- c:documents and settingsAll UsersApplication Dataregid.1986-12.com.adobe
2012-06-26 18:37 . 2012-06-26 18:37 -------- d-----w- c:program filesCommon FilesAdobe
2012-06-26 16:54 . 2012-06-26 16:54 -------- d-----w- c:windowssystem32QuickTime
2012-06-26 16:53 . 2012-06-26 16:53 -------- d-----w- c:program filesQuickTime
2012-06-26 16:53 . 2012-06-26 16:53 -------- d-----w- c:program filesCommon FilesTechSmith Shared
2012-06-26 16:48 . 2012-06-26 16:48 -------- d-----w- c:documents and settingsdaka_killLocal SettingsApplication DataTechSmith
2012-06-26 16:48 . 2012-06-26 16:53 -------- d-----w- c:documents and settingsAll UsersApplication DataTechSmith
2012-06-25 22:06 . 2012-06-26 17:45 -------- d-----w- c:documents and settingsdaka_killApplication DataThinstall
2012-06-25 22:06 . 2012-06-25 22:06 -------- d-----w- c:documents and settingsdaka_killLocal SettingsApplication DataThinstall
2012-06-25 16:12 . 2012-06-25 16:12 -------- d-----w- c:documents and settingsdaka_killLocal SettingsApplication DataUbisoft
2012-06-25 16:12 . 2012-06-25 16:12 -------- d-----w- c:documents and settingsAll UsersApplication DataUbisoft
2012-06-25 15:38 . 2012-06-27 17:18 -------- d-----w- c:documents and settingsdaka_killApplication DataHamachi
2012-06-25 15:38 . 2009-03-18 14:35 26176 ---ha-w- c:windowssystem32drivershamachi.sys
2012-06-24 13:56 . 2012-06-24 13:56 -------- d-----w- c:program filesJoWooD
2012-06-24 13:51 . 2012-06-24 13:51 -------- d-----w- c:program filesDAEMON Tools Toolbar
2012-06-24 13:51 . 2012-06-24 13:51 691696 ----a-w- c:windowssystem32driverssptd.sys
2012-06-24 13:51 . 2012-06-24 13:55 -------- d-----w- c:documents and settingsdaka_killApplication DataDAEMON Tools Lite
2012-06-24 13:51 . 2012-06-24 13:51 -------- d-----w- c:documents and settingsAll UsersApplication DataDAEMON Tools Lite
2012-06-22 15:35 . 2012-06-22 15:35 -------- d-----w- c:program filesSystemRequirementsLab
2012-06-22 15:34 . 2012-06-22 15:34 -------- d-----w- c:documents and settingsdaka_killApplication DataSystemRequirementsLab
2012-06-22 15:34 . 2012-06-22 15:34 -------- d-----w- c:windowsSun
2012-06-22 15:34 . 2012-06-22 15:34 -------- d-----w- c:documents and settingsdaka_killLocal SettingsApplication DataSun
2012-06-22 15:33 . 2012-06-22 15:33 -------- d-----w- c:program filesCommon FilesJava
2012-06-22 15:33 . 2012-06-22 15:33 -------- d-----w- c:program filesOracle
2012-06-22 15:33 . 2012-06-22 15:33 -------- d-----w- c:documents and settingsdaka_killApplication DataOracle
2012-06-22 15:33 . 2012-05-04 16:29 143872 ----a-w- c:windowssystem32javacpl.cpl
2012-06-22 15:33 . 2012-05-04 16:29 772504 ----a-w- c:windowssystem32npDeployJava1.dll
2012-06-22 15:33 . 2012-05-04 16:29 687504 ----a-w- c:windowssystem32deployJava1.dll
2012-06-22 15:32 . 2012-06-22 15:32 -------- d-----w- c:program filesJava
2012-06-22 08:53 . 2012-06-22 08:53 -------- d-----w- c:documents and settingsdaka_killLocal SettingsApplication DataIdentities
2012-06-22 08:52 . 2012-06-27 11:17 -------- d-----w- c:documents and settingsdaka_killApplication DataTeamViewer
2012-06-22 07:59 . 2012-06-22 07:59 -------- d-----w- c:program filesMicrosoft Works
2012-06-22 07:59 . 2012-06-22 07:59 -------- d-----w- c:program filesMicrosoft Visual Studio 8
2012-06-22 07:55 . 2012-06-22 07:55 -------- d-----w- c:documents and settingsdaka_killLocal SettingsApplication DataMicrosoft Help
2012-06-22 07:55 . 2012-06-22 07:58 -------- d-----w- c:program filesMicrosoft Exp[b][/b]ression
2012-06-22 07:55 . 2012-06-22 07:59 -------- d-----w- c:documents and settingsAll UsersApplication DataMicrosoft Help
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-12 08:33 . 2012-06-19 13:40 70344 ----a-w- c:windowssystem32FlashPlayerCPLApp.cpl
2012-06-19 13:28 . 2012-06-19 13:22 14656 ----a-w- c:windowsgdrv.sys
2012-06-19 13:26 . 2012-06-19 13:26 315392 ----a-w- c:windowsHideWin.exe
2012-06-02 12:19 . 2012-06-02 12:19 22040 ----a-w- c:windowssystem32wucltui.dll.mui
2012-06-02 12:19 . 2012-06-19 12:17 329240 ----a-w- c:windowssystem32wucltui.dll
2012-06-02 12:19 . 2012-06-19 12:17 219160 ----a-w- c:windowssystem32wuaucpl.cpl
2012-06-02 12:19 . 2012-06-19 12:17 210968 ----a-w- c:windowssystem32wuweb.dll
2012-06-02 12:19 . 2012-06-02 12:19 15384 ----a-w- c:windowssystem32wuaucpl.cpl.mui
2012-06-02 12:19 . 2012-06-19 12:17 53784 ----a-w- c:windowssystem32wuauclt.exe
2012-06-02 12:19 . 2012-06-19 12:17 35864 ----a-w- c:windowssystem32wups.dll
2012-06-02 12:19 . 2012-06-02 12:19 45080 ----a-w- c:windowssystem32wups2.dll
2012-06-02 12:19 . 2012-06-02 12:19 15384 ----a-w- c:windowssystem32wuapi.dll.mui
2012-06-02 12:19 . 2008-04-14 02:41 97304 ----a-w- c:windowssystem32cdm.dll
2012-06-02 12:19 . 2012-06-02 12:19 17944 ----a-w- c:windowssystem32wuaueng.dll.mui
2012-06-02 12:19 . 2012-06-19 12:17 577048 ----a-w- c:windowssystem32wuapi.dll
2012-06-02 12:19 . 2012-06-19 12:17 1933848 ----a-w- c:windowssystem32wuaueng.dll
2012-06-02 12:18 . 2012-06-20 10:59 275696 ----a-w- c:windowssystem32mucltui.dll
2012-06-02 12:18 . 2012-06-20 10:59 214256 ----a-w- c:windowssystem32muweb.dll
2012-06-02 12:18 . 2012-06-20 10:59 17136 ----a-w- c:windowssystem32mucltui.dll.mui
2012-04-26 18:07 . 2012-04-26 18:07 841728 ----a-w- c:windowssystem32yowindow.scr
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
Cryptography Services Error !!
.
(((((((((((((((((((((((((((((   SnapShot@2012-07-20_22.22.34   )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-07-21 16:48 . 2012-07-21 16:48 16384			  c:windowsTempPerflib_Perfdata_210.dat
+ 2012-07-21 10:17 . 2009-09-04 14:36 80896			  c:windowssystem32DirectXDX15C.tmpdxdllreg.exe
+ 2012-07-21 10:10 . 2009-09-04 14:36 80896			  c:windowssystem32DirectXDX157.tmpdxdllreg.exe
+ 2012-07-21 10:17 . 2009-09-04 14:36 173568			  c:windowssystem32DirectXDX15C.tmpdxupdate.dll
+ 2012-07-21 10:10 . 2009-09-04 14:36 173568			  c:windowssystem32DirectXDX157.tmpdxupdate.dll
+ 2012-07-21 10:17 . 2009-03-09 12:27 4178264			  c:windowssystem32DirectXDX15C.tmpd3dx9_41.dll
+ 2012-07-21 10:10 . 2009-03-09 12:27 4178264			  c:windowssystem32DirectXDX157.tmpd3dx9_41.dll
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"Vista Rainbar"="c:program filesVista RainbarRainmeter.exe" [2006-01-21 118784]
"uTorrent"="c:program filesuTorrentuTorrent.exe" [2012-06-19 321328]
"Skype"="c:program filesSkypePhoneSkype.exe" [2010-09-02 13351304]
"RocketDock"="e:programsRocketDockRocketDock.exe" [2007-09-02 495616]
"DAEMON Tools Lite"="e:programsDaemon Tools LiteDTLite.exe" [2009-10-30 369200]
.
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"NvCplDaemon"="c:windowssystem32NvCpl.dll" [2006-10-31 7634944]
"nwiz"="nwiz.exe" [2006-10-31 1622016]
"NvMediaCenter"="c:windowssystem32NvMcTray.dll" [2006-10-31 86016]
"RTHDCPL"="RTHDCPL.EXE" [2007-01-30 16116224]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"UnlockerAssistant"="c:program filesUnlockerUnlockerAssistant.exe" [2010-07-04 17408]
"SunJavaUpdateSched"="c:program filesCommon FilesJavaJava Updatejusched.exe" [2012-01-17 252296]
"LogMeIn Hamachi Ui"="c:program filesLogMeIn Hamachihamachi-2-ui.exe" [2012-06-27 1996200]
.
[HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRun]
"CTFMON.EXE"="c:windowssystem32CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRunOnce]
"nltide_3"="advpack.dll" [2008-04-14 99840]
.
c:documents and settingsdaka_killStart MenuProgramsStartup
Yowindow.lnk - e:yowindow unlimited edition 3.0 build 85 finalyowindow.exe [2012-4-26 875008]
.
[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionpoliciesexplorer]
"NoSMMyPictures"= 1 (0x1)
.
[HKEY_USERS.defaultsoftwaremicrosoftwindowscurrentversionpoliciesexplorer]
"NoSMMyPictures"= 1 (0x1)
.
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]
"%windir%Network Diagnosticxpnetdiag.exe"=
"%windir%system32sessmgr.exe"=
"c:Program FilesuTorrentuTorrent.exe"=
"c:Program FilesSkypePlugin ManagerskypePM.exe"=
"e:ProgramsBittorrent v6.1.2 Build 13422 Portable By StingerSBittorrent v6.1.2 Build 13422 Portable By StingerSBitTorrent.exe"=
"d:GamesCounter-Strike 1.6hl.exe"=
"d:GamesTzarTzar.exe"=
"c:Program FilesSkypePhoneSkype.exe"=
.
R0 sptd;sptd;c:windowssystem32driverssptd.sys [24.6.2012 г. 16:51 691696]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:program filesLogMeIn Hamachihamachi-2.exe [27.6.2012 г. 12:29 1385896]
S2 gupdate;Услуга Google Update (gupdate);c:program filesGoogleUpdateGoogleUpdate.exe [19.6.2012 г. 19:25 136176]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:windowssystem32MacromedFlashFlashPlayerUpdateService.exe [27.6.2012 г. 09:07 250056]
S3 gupdatem;Услуга на Google Актуализация (gupdatem);c:program filesGoogleUpdateGoogleUpdate.exe [19.6.2012 г. 19:25 136176]
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-21 c:windowsTasksAdobe Flash Player Updater.job
- c:windowssystem32MacromedFlashFlashPlayerUpdateService.exe [2012-06-27 08:33]
.
2012-07-21 c:windowsTasksGoogleUpdateTaskMachineCore.job
- c:program filesGoogleUpdateGoogleUpdate.exe [2012-06-19 16:25]
.
2012-07-21 c:windowsTasksGoogleUpdateTaskMachineUA.job
- c:program filesGoogleUpdateGoogleUpdate.exe [2012-06-19 16:25]
.
2012-07-20 c:windowsTasksMicrosoft Antimalware Scheduled Scan.job
- c:program filesMicrosoft Security ClientMpCmdRun.exe [2012-05-02 06:59]
.
.
------- Supplementary Scan -------
.
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:documents and settingsdaka_killApplication DataMozillaFirefoxProfilesrdfjra4a.default
FF - prefs.js: browser.search.selectedEngine - Vbox7.com
FF - prefs.js: browser.startup.homepage - hxxp://www.google.bg/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:program filesMozilla Firefoxextensions{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%extensions{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - Ext: BloodFire 3: [email protected] - %profile%[email protected]
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%extensions{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-07-21 21:10
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ... 
.
scanning hidden autostart entries ...
.
scanning hidden files ... 
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(2980)
e:programsRocketDockRocketDock.dll
.
Completion time: 2012-07-21  21:10:54
ComboFix-quarantined-files.txt  2012-07-21 18:10
.
Pre-Run: 6 911 860 736 bytes free
Post-Run: 6 902 902 784 bytes free
.
- - End Of File - - 620140FA9C2C4055D8330017851E45DA

Като изключим проблема с Cryptographic услугата, лог файла вече изглежда доста по-добре.

Тази услуга е много важна, защото отговаря за проверката на цифрови подписи на файловете.

Пробвайте да изтеглите и стартирате този файл - Мicrosoft Fixit и след това отидете на Start Repairs от този пост и пуснете фиксовете.

След това направете нова проверка с Combofix (знам, че е неприятно, но няма начин).

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.