Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Опитвам се да се преборя с вирус

Featured Replies

Значи вируса не дава да отварям сайтове за антивирусни също рядко дава да отворя дори интернет експлоера или които и да е браузер имах аваст показа вирус мисля че win32 win32:malware-gen четох теми тук и свалих програмата OTL.exe

OTL.txt

Extras.txt

Здравейте,

  • Стартирайте файла Публикувано изображение с двукратен клик на мишката.
  • Под Публикувано изображение с Copy/ Paste въведете изцяло следната текстова информация (само това, което е поставено в карето):
:OTL
PRC - [2012.05.25 01:19:54 | 002,983,472 | ---- | M] (TMRG, Inc.) -- C:Program FilesRelevantKnowledgerlvknlg.exe
DRV - File not found [Kernel | On_Demand | Stopped] -- C:DOCUME~1homeLOCALS~1Tempnjanfjnp.sys -- (Micorsoft Windows Service)
[2012.08.15 20:41:42 | 000,000,000 | ---D | M] (RelevantKnowledge) -- C:PROGRAM FILESRELEVANTKNOWLEDGE
O3 - HKLM..Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKUS-1-5-21-1390067357-926492609-1417001333-1003..Run: [{7DDC3BD4-9263-AD7F-52F3-841875A6A70A}] "C:Documents and SettingshomeApplication DataGulaunun.exe" File not found
O4 - HKUS-1-5-21-1390067357-926492609-1417001333-1003..Run: [GxyGfmud] C:Documents and SettingshomeLocal SettingsApplication Dataxrkqujlmgxygfmud.exe File not found
O20 - HKLM Winlogon: UserInit - (C:Documents and SettingshomeLocal SettingsApplication Dataxrkqujlmgxygfmud.exe) - C:Documents and SettingshomeLocal SettingsApplication Dataxrkqujlmgxygfmud.exe File not found
O20 - WinlogonNotifydimsntfy: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O20 - WinlogonNotifyRelevantKnowledge: DllName - (C:Program FilesRelevantKnowledgerlls.dll) - C:Program FilesRelevantKnowledgerlls.dll (TMRG, Inc.)
[2012.08.15 20:40:27 | 000,000,000 | ---D | C] -- C:Documents and SettingsAll UsersStart MenuProgramsRelevantKnowledge
[2010.09.23 15:35:55 | 000,000,000 | ---D | M] -- C:Documents and SettingsAll UsersApplication DataPanda Security
[2012.02.11 20:11:38 | 000,000,000 | ---D | M] -- C:Documents and SettingshomeApplication DataGula
:files
dir /s /a "C:Documents and SettingshomeApplication DataSefiza" /c
C:Program FilesRelevantKnowledge
:reg
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogon]
"Shell"="explorer.exe"
"Userinit"="C:WINDOWSsystem32Userinit.exe,"
:commands
[emptytemp]
След като въведете скрипта от цитата по-горе натиснете бутона, маркиран в червено: Run Fix

Windows ще се рестартира и ще се създаде лог файл - OTL fix log. Публикувайте съдържанието му с Copy/Paste в следващия си коментар.

  • Автор

All processes killed

========== OTL ==========

Process rlvknlg.exe killed successfully!

Service Micorsoft Windows Service stopped successfully!

Service Micorsoft Windows Service deleted successfully!

File C:DOCUME~1homeLOCALS~1Tempnjanfjnp.sys not found.

C:PROGRAM FILESRELEVANTKNOWLEDGEcomponents folder moved successfully.

C:PROGRAM FILESRELEVANTKNOWLEDGE folder moved successfully.

Registry value HKEY_LOCAL_MACHINESoftwareMicrosoftInternet ExplorerToolbarLocked deleted successfully.

Registry value HKEY_USERSS-1-5-21-1390067357-926492609-1417001333-1003SoftwareMicrosoftWindowsCurrentVersionRun{7DDC3BD4-9263-AD7F-52F3-841875A6A70A} deleted successfully.

Registry key HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{7DDC3BD4-9263-AD7F-52F3-841875A6A70A} not found.

Registry value HKEY_USERSS-1-5-21-1390067357-926492609-1417001333-1003SoftwareMicrosoftWindowsCurrentVersionRunGxyGfmud deleted successfully.

Registry value HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonUserInit:C:Documents and SettingshomeLocal SettingsApplication Dataxrkqujlmgxygfmud.exe deleted successfully.

Registry key HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonNotifydimsntfy deleted successfully.

Registry key HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonNotifyRelevantKnowledge deleted successfully.

File C:Program FilesRelevantKnowledgerlls.dll not found.

C:Documents and SettingsAll UsersStart MenuProgramsRelevantKnowledge folder moved successfully.

C:Documents and SettingsAll UsersApplication DataPanda Security folder moved successfully.

C:Documents and SettingshomeApplication DataGula folder moved successfully.

========== FILES ==========

< dir /s /a "C:Documents and SettingshomeApplication DataSefiza" /c >

Volume in drive C has no label.

Volume Serial Number is 6462-B25C

Directory of C:Documents and SettingshomeApplication DataSefiza

16.02.2012 Ј. 22:54 <DIR> .

16.02.2012 Ј. 22:54 <DIR> ..

0 File(s) 0 bytes

Total Files Listed:

0 File(s) 0 bytes

2 Dir(s) 6я391я668я736 bytes free

C:Documents and SettingshomeDesktopcmd.bat deleted successfully.

C:Documents and SettingshomeDesktopcmd.txt deleted successfully.

FileFolder C:Program FilesRelevantKnowledge not found.

========== REGISTRY ==========

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogon"Shell"|"explorer.exe" /E : value set successfully!

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogon"Userinit"|"C:WINDOWSsystem32Userinit.exe," /E : value set successfully!

========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 33170 bytes

User: home

->Temp folder emptied: 1620839438 bytes

->Temporary Internet Files folder emptied: 26045280 bytes

->FireFox cache emptied: 106887595 bytes

->Flash cache emptied: 121163 bytes

User: LocalService

->Temp folder emptied: 66016 bytes

->Temporary Internet Files folder emptied: 257444 bytes

User: MP3 Mixer & Recorder

User: NetworkService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 2402044 bytes

%systemroot%System32 .tmp files removed: 2577 bytes

%systemroot%System32dllcache .tmp files removed: 0 bytes

%systemroot%System32drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 36746620 bytes

%systemroot%system32configsystemprofileLocal SettingsTemp folder emptied: 13713358 bytes

%systemroot%system32configsystemprofileLocal SettingsTemporary Internet Files folder emptied: 33170 bytes

RecycleBin emptied: 529379167 bytes

Total Files Cleaned = 2 228,00 mb

OTL by OldTimer - Version 3.2.57.0 log created on 08162012_125206

FilesFolders moved on Reboot...

C:WINDOWStempPerflib_Perfdata_f78.dat moved successfully.

PendingFileRenameOperations files...

File C:WINDOWStempPerflib_Perfdata_f78.dat not found!

Registry entries deleted on Reboot...

1. Изтеглете ComboFix от BleepingComputer

и го запазете (бутон Save -> Save as) ComboFix на вашия десктоп:

Публикувано изображение

След приключване на изтеглянето на ComboFix, иконката на програмата би трябвало да изглежда така:

Публикувано изображение

2. Затворете всички работещи приложения, отворени прозорци и програми работещи във фонов режим. Спрете временно защитата в реално време на антивирусната програма и на другите програми за сигурност, ако има такива.

3. Стартирайте с двоен клик Combofix.exe. Изберете YES, за да се съгласите с условията за използване на програмата. Важно: По време на работата на ComboFix не бива да се движи мишката и да се натискат клавиши от клавиатурата. Просто търпеливо оставете ComboFix да си свърши работата, без да използвате компютъра за други цели.

4. ComboFix ще провери дали Windows Recovery Console e инсталиранa.

*Ако Windows Recovery Console не е инсталирана, ще е необходимо да използвате YES за инсталация на Windows Recovery Console

*Ако Windows Recovery Console е инсталирана, ComboFix ще продължи работата си.

Публикувано изображение

Забележка: Необходимо е да сте свързани към Интернет за да може Windows Recovery Console да се изтегли.

След инсталация на Windows Recovery Console потвърдете с YES, за да продължите напред. Снимка:

Публикувано изображение

5. ComboFix ще спре временно Интернет връзката, но след като приключи работата на програмата тази връзка ще бъде възстановена автоматично. ComboFix ще сканира за проблеми и за заразени файлове, като това може да отнеме известно време. Моля да бъдете търпеливи. Ако има проблем с Интернет връзката след приключване на работата на ComboFix, моля да прочетете това: Manually restoring the Internet connection section.

6. Когато работата на ComboFix приключи, ще се появи текстов документ (log) в Notepad:

Публикувано изображение

Копирайте с (Copy) и поставете с (Paste) съдържанието на лога в следващия си коментар.

  • Автор

ComboFix 12-08-16.01 - home 08.2012 г. 19:49:28.1.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.3067.2520 [GMT 3:00] Running from: c:documents and settingshomeDesktopcmf2.exe AV: Kaspersky Anti-Virus *Disabled/Outdated* {2C4D4BC6-0793-4956-A9F9-E252435469C0} FW: Kaspersky Anti-Virus *Disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0} . WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:documents and settingsAll UsersApplication DataTEMP c:documents and settingsAll UsersApplication DataTEMP{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}PostBuild.exe c:documents and settingshomeLocal SettingsApplication Dataabvmjjck.log c:documents and settingshomeLocal SettingsApplication Dataheoyxlpw.log c:documents and settingshomeLocal SettingsApplication Dataiusmtitt.log c:documents and settingshomeLocal SettingsApplication Datajricrpwn.log c:documents and settingshomeLocal SettingsApplication Datamkjtaegr.log c:documents and settingshomeLocal SettingsApplication Datashtynhrt.log c:documents and settingshomeLocal SettingsApplication Datattmarbxk.log c:documents and settingshomeLocal SettingsApplication Datavmdweacn.log c:documents and settingshomeLocal SettingsApplication Dataxrkqujlmgxygfmud.exe c:documents and settingshomems.exe c:program filesAutocompletePro c:program filesAutocompleteProAutocompletePro.dll c:program filesAutocompleteProchromeautocompleteprochrome.crx c:program filesAutocompleteProFireFoxExtension.exe c:program filesAutocompleteProInstTracker.exe c:program [email protected] c:program filesAutocompleteProsupport@predictad.comchromecontentbrowserOverlay.xul c:program [email protected] c:program filesAutocompleteProsupport@predictad.comchromecontentoptions.xul c:program [email protected] c:program filesAutocompleteProsupport@predictad.comdefaultspreferencespredictad.js c:program [email protected] c:program filesAutocompleteProunins000.dat c:program filesAutocompleteProunins000.exe . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------Legacy_MICORSOFT_WINDOWS_SERVICE -------Service_bord_007 -------Service_Micorsoft Windows Service . . ((((((((((((((((((((((((( Files Created from 2012-07-16 to 2012-08-16 ))))))))))))))))))))))))))))))) . . 2012-08-16 09:52 . 2012-08-16 09:52 -------- d-----w- C:_OTL 2012-08-15 17:50 . 2012-08-15 17:50 -------- d-----w- c:program filesESET 2012-08-15 17:13 . 2010-10-05 17:27 150200 ----a-w- c:program filesMozilla Firefoxextensionslinkfilter@kaspersky.rucomponentskavlinkfilter.dll 2012-08-15 17:13 . 2012-08-15 17:13 97859 ----a-w- c:windowssystem32driversklick.dat 2012-08-15 17:13 . 2012-08-15 17:13 114243 ----a-w- c:windowssystem32driversklin.dat 2012-08-15 17:12 . 2012-08-16 16:55 -------- d-----w- c:documents and settingsAll UsersApplication DataKaspersky Lab 2012-08-15 17:12 . 2012-08-15 17:12 -------- d-----w- c:program filesKaspersky Lab 2012-08-15 16:58 . 2012-08-15 16:58 -------- d-----w- c:documents and settingsAll UsersApplication DataKaspersky Lab Setup Files 2012-08-15 15:49 . 2012-08-15 15:49 -------- d-----w- c:documents and settingshomeLocal SettingsApplication DataDeployment 2012-08-15 15:46 . 2012-08-15 15:46 -------- d-----w- c:program filesCommon FilesSkype 2012-08-15 15:46 . 2012-08-15 15:46 -------- d-----r- c:program filesSkype 2012-08-14 15:21 . 2012-08-14 15:21 -------- d-----w- c:program filesTeamViewer 2012-08-14 14:03 . 2012-08-16 16:55 -------- d-----w- c:documents and settingshomeLocal SettingsApplication Dataxrkqujlm . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . . . ------- Sigcheck ------- Note: Unsigned files aren't necessarily malware. . [-] 2009-11-05 . 600D58665D16BFBB776EFEFB0E80532D . 1614848 . . [5.1.2600.5512] . . c:windowssystem32sfcfiles.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:program filesCommon FilesAheadlibNMBgMonitor.exe" [2005-09-03 94208] "GxyGfmud"="c:documents and settingshomeLocal SettingsApplication Dataxrkqujlmgxygfmud.exe" [2012-08-14 168047] . [HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRunOnce] "ShowDeskFix"="shell32" [X] "IE8"="advpack.dll" [2009-11-05 128512] . c:documents and settingshomeStart MenuProgramsStartup gxygfmud.exe [2012-8-14 168047] . c:documents and settingsAll UsersStart MenuProgramsStartup Bluetooth.lnk - c:program filesWIDCOMMBluetooth SoftwareBTTray.exe [2008-3-31 576104] FlexType 2K.lnk - c:windowsDatecsFlex2K.exe [2010-12-1 151552] . [HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionpoliciessystem] "EnableLUA"= 0 (0x0) . [HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionwinlogon] "Userinit"="c:windowssystem32userinit.exe,,c:documents and settingshomeLocal SettingsApplication Dataxrkqujlmgxygfmud.exe" . [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalWdf01000.sys] @="Driver" . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregAdobe Reader Speed Launcher] 2009-10-03 01:08 35696 ----a-w- c:program filesAdobeReader 9.0Readerreader_sl.exe . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregAVP] 2010-11-02 19:06 365336 ----a-w- c:program filesKaspersky LabKaspersky Anti-Virus 2011avp.exe . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregGameXN GO] 2012-05-12 16:00 348440 ----a-w- c:documents and settingsAll UsersApplication DataGameXNGameXNGO.exe . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregGoogle Update] 2012-08-15 15:49 116648 ----atw- c:documents and settingshomeLocal SettingsApplication DataGoogleUpdateGoogleUpdate.exe . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregNeroFilterCheck] 2001-07-09 08:50 155648 ----a-w- c:windowssystem32NeroCheck.exe . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregPC Suite Tray] 2009-03-20 12:32 1312256 ----a-w- c:documents and settingshomeDesktopNokia PC Suite 7PCSuite.exe . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregPDVD9LanguageShortcut] 2009-04-27 14:50 50472 ------w- c:program filesCyberLinkPowerDVD9LanguageLanguage.exe . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregSkype] 2012-07-13 10:33 17418928 ----a-r- c:program filesSkypePhoneSkype.exe . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupreguTorrent] 2012-08-15 16:10 1022352 ----a-w- c:program filesuTorrentuTorrent.exe . [HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity center] "AntiVirusOverride"=dword:00000001 . [HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity centerMonitoringKasperskyAntiVirus] "DisableMonitoring"=dword:00000001 . [HKLM~servicessharedaccessparametersfirewallpolicystandardprofile] "EnableFirewall"= 0 (0x0) . [HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList] "%windir%Network Diagnosticxpnetdiag.exe"= "%windir%system32sessmgr.exe"= "c:Program FilesuTorrentuTorrent.exe"= "c:Program FilesTeamViewerVersion5TeamViewer.exe"= "c:Program FilesSkypePhoneSkype.exe"= . [HKLM~servicessharedaccessparametersfirewallpolicystandardprofileGloballyOpenPortsList] "22551:UDP"= 22551:UDP:UDP 22551 "16348:TCP"= 16348:TCP:TCP 16348 . R0 SFAUDIO;Sonic Focus DSP Driver;c:windowssystem32driverssfaudio.sys [28.3.2008 і. 10:14 24064] R1 kl2;kl2;c:windowssystem32driverskl2.sys [09.6.2010 і. 16:43 11352] R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2010/09/23 13:50];c:program filesCyberLinkPowerDVD9000.fcl [07.5.2009 і. 21:05 87536] R2 ezGOSvc;Easybits GO Services for Windows;c:windowssystem32svchost.exe -k netsvcs [14.4.2008 і. 14:00 14336] R2 SkypeUpdate;Skype Updater;c:program filesSkypeUpdaterUpdater.exe [13.7.2012 і. 13:28 160944] R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:windowssystem32driversklim5.sys [07.5.2010 і. 11:06 32856] R3 klmouflt;Kaspersky Lab KLMOUFLT;c:windowssystem32driversklmouflt.sys [02.11.2009 і. 19:27 19472] R4 Micorsoft Windows Service;Micorsoft Windows Service;??c:docume~1homeLOCALS~1Tempnjanfjnp.sys --> c:docume~1homeLOCALS~1Tempnjanfjnp.sys [?] S3 Com4QLBEx;Com4QLBEx;c:program filesHewlett-PackardHP Quick Launch ButtonsCom4QLBEx.exe [23.9.2010 і. 13:21 228408] . --- Other Services/Drivers In Memory --- . *NewlyCreated* - MICORSOFT_WINDOWS_SERVICE *NewlyCreated* - WS2IFSL . HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionSvchost - NetSvcs ezGOSvc . Contents of the 'Scheduled Tasks' folder . 2012-08-16 c:windowsTasksGoogleUpdateTaskUserS-1-5-21-1390067357-926492609-1417001333-1003Core.job - c:documents and settingshomeLocal SettingsApplication DataGoogleUpdateGoogleUpdate.exe [2012-08-15 15:49] . 2012-08-16 c:windowsTasksGoogleUpdateTaskUserS-1-5-21-1390067357-926492609-1417001333-1003UA.job - c:documents and settingshomeLocal SettingsApplication DataGoogleUpdateGoogleUpdate.exe [2012-08-15 15:49] . . ------- Supplementary Scan ------- . uInternet Connection Wizard,ShellNext = iexplore TCP: DhcpNameServer = 192.168.0.1 FF - ProfilePath - c:documents and settingshomeApplication DataMozillaFirefoxProfiles6oe3gisu.default FF - prefs.js: browser.startup.homepage - hxxp://www.google.bg/firefox?client=firefox-a&rls=org.mozilla:bg:official FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:program filesMozilla Firefoxextensions{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: РњРѕРґСѓР» Р·Р° сканиране РЅР° уеб адреси: [email protected] - c:program filesMozilla [email protected] FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:windowsMicrosoft.NETFrameworkv3.5Windows Presentation FoundationDotNetAssistantExtension FF - Ext: PC Sync 2 Synchronisation Extension: [email protected] - c:documents and settingshomeDesktopNokia PC Suite 7bkmrksync FF - Ext: AutocompletePro - Your handy search suggestions tool: [email protected] - %profile%[email protected] FF - user.js: network.cookie.cookieBehavior - 0 FF - user.js: privacy.clearOnShutdown.cookies - false FF - user.js: security.warn_viewing_mixed - false FF - user.js: security.warn_viewing_mixed.show_once - false FF - user.js: security.warn_submit_insecure - false FF - user.js: security.warn_submit_insecure.show_once - false . - - - - ORPHANS REMOVED - - - - . AddRemove-AutocompletePro3_is1 - c:program filesAutocompleteProunins000.exe AddRemove-Easy MP3 Audio Mixer_is1 - c:program filesEasyMP3AudioMixerunins000.exe AddRemove-{d08d9f98-1c78-4704-87e6-368b0023d831} - c:program filesRelevantKnowledgerlvknlg.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2012-08-16 19:55 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . [HKEY_LOCAL_MACHINESystemControlSet001Services{B154377D-700F-42cc-9474-23858FBDF4BD}] "ImagePath"="??c:program filesCyberLinkPowerDVD9000.fcl" . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'winlogon.exe'(1540) c:windowssystem32Ati2evxx.dll . - - - - - - - > 'explorer.exe'(3880) c:windowssystem32WININET.dll c:windowssystem32newdll.dll c:windowssystem32btmmhook.dll c:windowssystem32ieframe.dll c:windowssystem32webcheck.dll c:windowssystem32wpdshserviceobj.dll c:windowssystem32btncopy.dll c:documents and settingshomeDesktopNokia PC Suite 7PhoneBrowser.dll c:documents and settingshomeDesktopNokia PC Suite 7NGSCM.DLL c:windowsWinSxSx86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8caMSVCR80.dll c:documents and settingshomeDesktopNokia PC Suite 7LangPhoneBrowser_eng.nlr c:documents and settingshomeDesktopNokia PC Suite 7ResourcePhoneBrowser_Nokia.ngr c:windowssystem32portabledevicetypes.dll c:windowssystem32portabledeviceapi.dll . ------------------------ Other Running Processes ------------------------ . c:windowssystem32Ati2evxx.exe c:program filesWIDCOMMBluetooth Softwarebinbtwdins.exe c:windowssystem32Ati2evxx.exe c:windowsSystem32SCardSvr.exe c:windowssystem32agrsmsvc.exe c:progra~1WIDCOMMBLUETO~1BTSTAC~1.EXE c:windowssystem32wscntfy.exe . ************************************************************************** . Completion time: 2012-08-16 19:57:21 - machine was rebooted ComboFix-quarantined-files.txt 2012-08-16 16:57 . Pre-Run: 8 383 750 144 bytes free Post-Run: 8 276 959 232 bytes free . - - End Of File - - ADC3CB57FC8AAAE286E7937833CFFB4A

Лошо...Имаме си работа с файлов инфектор - Ramnit.

Искам да видя дали си струва да се борим - в повечето случаи препоръчваме формат с изтриване на всички дялове...

Изтеглете този файл и го разархивирайте...Стартирайте проверката. Програмата ще иска да рестартира системата ви в Safe Mode.

Съгласете се. След като заредите в Safe Mode, стартирайте проверката отново и изчакайте да почисти.

След като приключи, заредете в Normal Mode, направете нова проверка с Combofix и публикувайте лог файла в следващия си пост.

  • Автор

ComboFix 12-08-16.01 - home 08.2012 г. 22:50:27.2.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.3067.2520 [GMT 3:00] Running from: c:documents and settingshomeDesktopcmf2.exe AV: Kaspersky Anti-Virus *Disabled/Outdated* {2C4D4BC6-0793-4956-A9F9-E252435469C0} . WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:documents and settingshomeLocal SettingsApplication Dataabvmjjck.log c:documents and settingshomeLocal SettingsApplication Dataheoyxlpw.log c:documents and settingshomeLocal SettingsApplication Dataiusmtitt.log c:documents and settingshomeLocal SettingsApplication Datajricrpwn.log c:documents and settingshomeLocal SettingsApplication Datamkjtaegr.log c:documents and settingshomeLocal SettingsApplication Datashtynhrt.log c:documents and settingshomeLocal SettingsApplication Datattmarbxk.log c:documents and settingshomeLocal SettingsApplication Datavmdweacn.log c:documents and settingshomeLocal SettingsApplication Dataxrkqujlmgxygfmud.exe . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------Legacy_KERNELMEMORY -------Legacy_MICORSOFT_WINDOWS_SERVICE -------Service_Micorsoft Windows Service . . ((((((((((((((((((((((((( Files Created from 2012-07-16 to 2012-08-16 ))))))))))))))))))))))))))))))) . . 2012-08-16 09:52 . 2012-08-16 09:52 -------- d-----w- C:_OTL 2012-08-15 17:50 . 2012-08-15 17:50 -------- d-----w- c:program filesESET 2012-08-15 17:13 . 2010-10-05 17:27 150200 ----a-w- c:program filesMozilla Firefoxextensionslinkfilter@kaspersky.rucomponentskavlinkfilter.dll 2012-08-15 17:13 . 2012-08-15 17:13 97859 ----a-w- c:windowssystem32driversklick.dat 2012-08-15 17:13 . 2012-08-15 17:13 114243 ----a-w- c:windowssystem32driversklin.dat 2012-08-15 17:12 . 2012-08-16 19:57 -------- d-----w- c:documents and settingsAll UsersApplication DataKaspersky Lab 2012-08-15 17:12 . 2012-08-15 17:12 -------- d-----w- c:program filesKaspersky Lab 2012-08-15 16:58 . 2012-08-15 16:58 -------- d-----w- c:documents and settingsAll UsersApplication DataKaspersky Lab Setup Files 2012-08-15 15:49 . 2012-08-15 15:49 -------- d-----w- c:documents and settingshomeLocal SettingsApplication DataDeployment 2012-08-15 15:46 . 2012-08-15 15:46 -------- d-----w- c:program filesCommon FilesSkype 2012-08-15 15:46 . 2012-08-15 15:46 -------- d-----r- c:program filesSkype 2012-08-14 15:21 . 2012-08-14 15:21 -------- d-----w- c:program filesTeamViewer 2012-08-14 14:03 . 2012-08-16 19:57 -------- d-----w- c:documents and settingshomeLocal SettingsApplication Dataxrkqujlm . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . . . ------- Sigcheck ------- Note: Unsigned files aren't necessarily malware. . [-] 2009-11-05 . 600D58665D16BFBB776EFEFB0E80532D . 1614848 . . [5.1.2600.5512] . . c:windowssystem32sfcfiles.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:program filesCommon FilesAheadlibNMBgMonitor.exe" [2005-09-03 94208] "GxyGfmud"="c:documents and settingshomeLocal SettingsApplication Dataxrkqujlmgxygfmud.exe" [2012-08-16 168047] . [HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRunOnce] "ShowDeskFix"="shell32" [X] "IE8"="advpack.dll" [2009-11-05 128512] . c:documents and settingshomeStart MenuProgramsStartup gxygfmud.exe [2012-8-14 168047] . c:documents and settingsAll UsersStart MenuProgramsStartup Bluetooth.lnk - c:program filesWIDCOMMBluetooth SoftwareBTTray.exe [2008-3-31 576104] FlexType 2K.lnk - c:windowsDatecsFlex2K.exe [2010-12-1 151552] . [HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionpoliciessystem] "EnableLUA"= 0 (0x0) . [HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionwinlogon] "Userinit"="c:windowssystem32userinit.exe,,c:documents and settingshomeLocal SettingsApplication Dataxrkqujlmgxygfmud.exe" . [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalWdf01000.sys] @="Driver" . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregAdobe Reader Speed Launcher] 2009-10-03 01:08 35696 ----a-w- c:program filesAdobeReader 9.0Readerreader_sl.exe . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregAVP] 2010-11-02 19:06 365336 ----a-w- c:program filesKaspersky LabKaspersky Anti-Virus 2011avp.exe . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregGameXN GO] 2012-05-12 16:00 348440 ----a-w- c:documents and settingsAll UsersApplication DataGameXNGameXNGO.exe . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregGoogle Update] 2012-08-15 15:49 116648 ----atw- c:documents and settingshomeLocal SettingsApplication DataGoogleUpdateGoogleUpdate.exe . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregNeroFilterCheck] 2001-07-09 08:50 155648 ----a-w- c:windowssystem32NeroCheck.exe . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregPC Suite Tray] 2009-03-20 12:32 1312256 ----a-w- c:documents and settingshomeDesktopNokia PC Suite 7PCSuite.exe . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregPDVD9LanguageShortcut] 2009-04-27 14:50 50472 ------w- c:program filesCyberLinkPowerDVD9LanguageLanguage.exe . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregSkype] 2012-07-13 10:33 17418928 ----a-r- c:program filesSkypePhoneSkype.exe . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupreguTorrent] 2012-08-15 16:10 1022352 ----a-w- c:program filesuTorrentuTorrent.exe . [HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity center] "AntiVirusOverride"=dword:00000001 . [HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity centerMonitoringKasperskyAntiVirus] "DisableMonitoring"=dword:00000001 . [HKLM~servicessharedaccessparametersfirewallpolicystandardprofile] "EnableFirewall"= 0 (0x0) . [HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList] "%windir%Network Diagnosticxpnetdiag.exe"= "%windir%system32sessmgr.exe"= "c:Program FilesuTorrentuTorrent.exe"= "c:Program FilesTeamViewerVersion5TeamViewer.exe"= "c:Program FilesSkypePhoneSkype.exe"= . [HKLM~servicessharedaccessparametersfirewallpolicystandardprofileGloballyOpenPortsList] "22551:UDP"= 22551:UDP:UDP 22551 "16348:TCP"= 16348:TCP:TCP 16348 . R0 SFAUDIO;Sonic Focus DSP Driver;c:windowssystem32driverssfaudio.sys [28.3.2008 і. 10:14 24064] R1 kl2;kl2;c:windowssystem32driverskl2.sys [09.6.2010 і. 16:43 11352] R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2010/09/23 13:50];c:program filesCyberLinkPowerDVD9000.fcl [07.5.2009 і. 21:05 87536] R2 ezGOSvc;Easybits GO Services for Windows;c:windowssystem32svchost.exe -k netsvcs [14.4.2008 і. 14:00 14336] R2 SkypeUpdate;Skype Updater;c:program filesSkypeUpdaterUpdater.exe [13.7.2012 і. 13:28 160944] R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:windowssystem32driversklim5.sys [07.5.2010 і. 11:06 32856] R3 klmouflt;Kaspersky Lab KLMOUFLT;c:windowssystem32driversklmouflt.sys [02.11.2009 і. 19:27 19472] R4 Micorsoft Windows Service;Micorsoft Windows Service;??c:docume~1homeLOCALS~1Tempnjanfjnp.sys --> c:docume~1homeLOCALS~1Tempnjanfjnp.sys [?] S3 Com4QLBEx;Com4QLBEx;c:program filesHewlett-PackardHP Quick Launch ButtonsCom4QLBEx.exe [23.9.2010 і. 13:21 228408] . --- Other Services/Drivers In Memory --- . *NewlyCreated* - MICORSOFT_WINDOWS_SERVICE . HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionSvchost - NetSvcs ezGOSvc . Contents of the 'Scheduled Tasks' folder . 2012-08-16 c:windowsTasksGoogleUpdateTaskUserS-1-5-21-1390067357-926492609-1417001333-1003Core.job - c:documents and settingshomeLocal SettingsApplication DataGoogleUpdateGoogleUpdate.exe [2012-08-15 15:49] . 2012-08-16 c:windowsTasksGoogleUpdateTaskUserS-1-5-21-1390067357-926492609-1417001333-1003UA.job - c:documents and settingshomeLocal SettingsApplication DataGoogleUpdateGoogleUpdate.exe [2012-08-15 15:49] . . ------- Supplementary Scan ------- . uInternet Connection Wizard,ShellNext = iexplore TCP: DhcpNameServer = 192.168.0.1 FF - ProfilePath - c:documents and settingshomeApplication DataMozillaFirefoxProfiles6oe3gisu.default FF - prefs.js: browser.startup.homepage - hxxp://www.google.bg/firefox?client=firefox-a&rls=org.mozilla:bg:official FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:program filesMozilla Firefoxextensions{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: РњРѕРґСѓР» Р·Р° сканиране РЅР° уеб адреси: [email protected] - c:program filesMozilla [email protected] FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:windowsMicrosoft.NETFrameworkv3.5Windows Presentation FoundationDotNetAssistantExtension FF - Ext: PC Sync 2 Synchronisation Extension: [email protected] - c:documents and settingshomeDesktopNokia PC Suite 7bkmrksync FF - Ext: AutocompletePro - Your handy search suggestions tool: [email protected] - %profile%[email protected] FF - user.js: network.cookie.cookieBehavior - 0 FF - user.js: privacy.clearOnShutdown.cookies - false FF - user.js: security.warn_viewing_mixed - false FF - user.js: security.warn_viewing_mixed.show_once - false FF - user.js: security.warn_submit_insecure - false FF - user.js: security.warn_submit_insecure.show_once - false . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2012-08-16 22:57 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . [HKEY_LOCAL_MACHINESystemControlSet001Services{B154377D-700F-42cc-9474-23858FBDF4BD}] "ImagePath"="??c:program filesCyberLinkPowerDVD9000.fcl" . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'winlogon.exe'(1540) c:windowssystem32Ati2evxx.dll . - - - - - - - > 'explorer.exe'(2552) c:windowssystem32WININET.dll c:windowssystem32newdll.dll c:windowssystem32btmmhook.dll c:windowssystem32ieframe.dll c:windowssystem32webcheck.dll c:windowssystem32wpdshserviceobj.dll c:windowssystem32btncopy.dll c:documents and settingshomeDesktopNokia PC Suite 7PhoneBrowser.dll c:documents and settingshomeDesktopNokia PC Suite 7NGSCM.DLL c:windowsWinSxSx86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8caMSVCR80.dll c:documents and settingshomeDesktopNokia PC Suite 7LangPhoneBrowser_eng.nlr c:documents and settingshomeDesktopNokia PC Suite 7ResourcePhoneBrowser_Nokia.ngr c:windowssystem32portabledevicetypes.dll c:windowssystem32portabledeviceapi.dll . ------------------------ Other Running Processes ------------------------ . c:windowssystem32Ati2evxx.exe c:program filesWIDCOMMBluetooth Softwarebinbtwdins.exe c:windowssystem32Ati2evxx.exe c:windowsSystem32SCardSvr.exe c:windowssystem32agrsmsvc.exe c:progra~1WIDCOMMBLUETO~1BTSTAC~1.EXE c:windowssystem32wscntfy.exe . ************************************************************************** . Completion time: 2012-08-16 22:59:02 - machine was rebooted ComboFix-quarantined-files.txt 2012-08-16 19:59 ComboFix2.txt 2012-08-16 16:57 . Pre-Run: 8 267 788 288 bytes free Post-Run: 8 095 649 792 bytes free . - - End Of File - - A00E82AE47564777A0765B3E47B990BA ATTENTION! For best result before starting the Scan & Clean process, please: 1) Run Windows in Safe Mode. 2) Close all GUI applications. 3) Disconnect LAN/Internet connection. Scanning memory... - Checking [system Process]; PID: 0; - Checking System; PID: 4; - Checking smss.exe; PID: 188; - Checking csrss.exe; PID: 236; - Checking winlogon.exe; PID: 260; - Checking services.exe; PID: 304; - Checking lsass.exe; PID: 316; - Checking svchost.exe; PID: 476; - Checking svchost.exe; PID: 536; - Checking svchost.exe; PID: 592; - Checking Explorer.EXE; PID: 864; - Checking RamnitKiller.exe; PID: 996; Scanning registry... Scanning all drives, please wait... - Scanning C: - Scanning D: System time: 16.8.2012 г. 22:43:33 Scan finished: 0:34:33.250 File scanned: 44753 File infected: 0 File cured: 0 File removed: 0 ATTENTION! For best result before starting the Scan & Clean process, please: 1) Run Windows in Safe Mode. 2) Close all GUI applications. 3) Disconnect LAN/Internet connection.

Ок...не се е получило.

Инструмента на MS го засича:

Сега направете една проверка с Microsoft Malicious Software Removal Tool. След като завърши проверката, намерете файла mrt.log, който се намира в папката C:Windowsdebug.

Прикачете го към следващия си коментар по темата. Ако отново не стане, можем да опитаме с някои LiveCD...но все пак ако нямате нищо ценно е препоръчително да се направи format.

  • Автор

Май и с тази програма не откри нищо а не дава да инсталирам антивирусна и сайтове на онлайн сканиране също не иска да отвори --------------------------------------------------------------------------------------- Microsoft Windows Malicious Software Removal Tool v3.1, November 2009 Started On Thu Sep 23 12:48:23 2010 -> Sysclean ERROR: Internal error, code = 8050800C Results Summary: ---------------- No infection found. Return code: 0 Microsoft Windows Malicious Software Removal Tool Finished On Thu Sep 23 12:48:25 2010 --------------------------------------------------------------------------------------- Microsoft Windows Malicious Software Removal Tool v3.11, September 2010 Started On Thu Sep 23 14:33:19 2010 WARNING: Security policy doesn't allow for all actions MSRT may require. Engine internal result code = 80508015 Results Summary: ---------------- No infection found. Microsoft Windows Malicious Software Removal Tool Finished On Thu Sep 23 14:34:13 2010 Return code: 0 (0x0) --------------------------------------------------------------------------------------- Microsoft Windows Malicious Software Removal Tool v3.13, November 2010 Started On Wed Dec 01 10:20:23 2010 Engine internal result code = 80508015 Results Summary: ---------------- No infection found. Microsoft Windows Malicious Software Removal Tool Finished On Wed Dec 01 10:22:00 2010 Return code: 0 (0x0) --------------------------------------------------------------------------------------- Microsoft Windows Malicious Software Removal Tool v4.11, August 2012 Started On Fri Aug 17 19:41:08 2012 Extended Scan Results ---------------- ->Scan ERROR: resource file://C:pagefile.sys (code 0x00000020 (32)) No infection found as part of the extended scan Results Summary: ---------------- No infection found. Microsoft Windows Malicious Software Removal Tool Finished On Fri Aug 17 20:36:29 2012 Return code: 0 (0x0)

Редактирано от Kiril Kostov (преглед на промените)

Ок, да пробваме така:

Изтеглете Avira AntiVir Rescue System (ако се наложи използвайте компютъра на приятел за целта).

Сложете празен диск в оптичното устройство и стартирайте файла с двоен клик на мишката.

Изберете модела на записвачката от падащото меню и натиснете BURN CD

Публикувано изображение

Сега рестартирайте машината си и според това каква е дънната Ви платка пробвайте различни клавиши (най-често F1, F2, F12, del) за да влезнете в BIOS менюто и да направите CD-ROM-а да е първо зареждащо устройство:

http://www.hiren.info/pages/bios-boot-cdrom

Поставете записания диск на Avira Rescue CD в CD ROM-a и заредете от него.

Щом се появи това меню изберете 1:

Публикувано изображение

Ако диска не зареди, върнете се в БИОС-а и забранене флопи дисковото устройство.

Ако зареди, но имате проблеми с визуализирането на менютата изберете 3 на картинката по-нагоре и пробвайте между различните резолюции и режими.

Сега вече би трябвало да се появи това меню:

Публикувано изображение

Диска ще зареди на английски език по-подразбиране. За други езици изберете флага на съответната страна.

Ако бъдете подканени да обновите диска, съгласете се. Изисква се наличие на активна интернет връзка.

Публикувано изображение

Сега натиснете Configuration и сложете отметки на следните опции:

All files

Extended threat categories - всички отметки

Repair infected files

Rename files, if repair is not possible

Публикувано изображение

След това отидете на Virus Scanner и изберете Start Scanner

Публикувано изображение

Изчакайте да завърши проверката и запазете лог файла, натискайки бутона Save и указвайки къде да го запазите.

Публикувано изображение

За да излезнете от скенера, натиснете Shutdown и после Restart.

Публикувано изображение

Публикувайте лог файла от проверката в следващия си коментар!

  • Автор

Здравей използвах Kaspersky rescue disk 10 намери няколко вируса изтри ги и в момента вече имам антивирусна инсталирам касперски сега ще пусна combo fix и ще пусна лога тук за да видя дали е излекуван Objects Scan: malfunction (events: 65, objects: 0, time: Unknown) 8/19/12 4:02 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055747.exe Postponed 8/19/12 4:02 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055747.exe 8/19/12 4:02 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055715.exe Postponed 8/19/12 4:02 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055715.exe 8/19/12 4:02 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055491.exe Postponed 8/19/12 4:02 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055491.exe 8/19/12 4:02 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055608.exe Postponed 8/19/12 4:02 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055608.exe 8/19/12 4:02 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055607.exe Postponed 8/19/12 4:02 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055607.exe 8/19/12 4:02 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055568.exe Postponed 8/19/12 4:02 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055568.exe 8/19/12 4:02 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055547.exe Postponed 8/19/12 4:02 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055547.exe 8/19/12 4:02 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055529.exe Postponed 8/19/12 4:02 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055529.exe 8/19/12 4:02 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055512.exe Postponed 8/19/12 4:02 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055512.exe 8/19/12 4:02 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0054496.exe Postponed 8/19/12 4:02 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0054496.exe 8/19/12 4:02 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0054365.exe Postponed 8/19/12 4:02 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0054365.exe 8/19/12 4:02 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0054263.exe Postponed 8/19/12 4:02 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0054263.exe 8/19/12 4:02 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0054128.exe Postponed 8/19/12 4:02 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0054128.exe 8/19/12 4:02 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP186/A0054049.exe Postponed 8/19/12 4:02 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP186/A0054049.exe 8/19/12 4:02 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053839.exe Postponed 8/19/12 4:02 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053839.exe 8/19/12 4:02 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053809.exe Postponed 8/19/12 4:02 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053809.exe 8/19/12 4:02 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053789.exe Postponed 8/19/12 4:02 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053789.exe 8/19/12 4:01 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053722.exe Postponed 8/19/12 4:01 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053722.exe 8/19/12 4:01 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053697.exe Postponed 8/19/12 4:01 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053697.exe 8/19/12 4:01 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053677.exe Postponed 8/19/12 4:01 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053677.exe 8/19/12 4:01 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053652.exe Postponed 8/19/12 4:01 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053652.exe 8/19/12 4:01 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053631.exe Postponed 8/19/12 4:01 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053631.exe 8/19/12 4:01 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053620.exe Postponed 8/19/12 4:01 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053620.exe 8/19/12 4:01 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053594.exe Postponed 8/19/12 4:01 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053594.exe 8/19/12 4:01 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053512.exe Postponed 8/19/12 4:01 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053512.exe 8/19/12 3:59 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/Qoobox/Quarantine/C/Documents and Settings/home/Local Settings/Application Data/xrkqujlm/_gxygfmud_.exe.zip/gxygfmud.exe Postponed 8/19/12 3:59 PM Detected: Backdoor.Win32.Azbreg.cxm C:/Qoobox/Quarantine/C/Documents and Settings/home/Local Settings/Application Data/xrkqujlm/_gxygfmud_.exe.zip/gxygfmud.exe 8/19/12 3:59 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/Qoobox/Quarantine/C/Documents and Settings/home/Local Settings/Application Data/xrkqujlm/gxygfmud.exe.vir Postponed 8/19/12 3:59 PM Detected: Backdoor.Win32.Azbreg.cxm C:/Qoobox/Quarantine/C/Documents and Settings/home/Local Settings/Application Data/xrkqujlm/gxygfmud.exe.vir 8/19/12 3:59 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/Qoobox/Quarantine/C/Documents and Settings/home/ms.exe.vir Postponed 8/19/12 3:59 PM Detected: Backdoor.Win32.Azbreg.cxm C:/Qoobox/Quarantine/C/Documents and Settings/home/ms.exe.vir 8/19/12 3:55 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/Documents and Settings/home/Start Menu/Programs/Startup/gxygfmud.exe Postponed 8/19/12 3:55 PM Detected: Backdoor.Win32.Azbreg.cxm C:/Documents and Settings/home/Start Menu/Programs/Startup/gxygfmud.exe 8/19/12 3:53 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/Documents and Settings/home/Local Settings/temp/xdwbhowj.exe Postponed 8/19/12 3:53 PM Detected: Backdoor.Win32.Azbreg.cxm C:/Documents and Settings/home/Local Settings/temp/xdwbhowj.exe 8/19/12 3:53 PM Untreated: Rootkit.Win32.Agent.bnex C:/Documents and Settings/home/Local Settings/temp/njanfjnp.sys Postponed 8/19/12 3:53 PM Detected: Rootkit.Win32.Agent.bnex C:/Documents and Settings/home/Local Settings/temp/njanfjnp.sys 8/19/12 3:53 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/Documents and Settings/home/Local Settings/Application Data/xrkqujlm/gxygfmud.exe Postponed 8/19/12 3:53 PM Detected: Backdoor.Win32.Azbreg.cxm C:/Documents and Settings/home/Local Settings/Application Data/xrkqujlm/gxygfmud.exe 8/19/12 3:44 PM Task started Objects Scan: completed <1 minute ago (events: 139, objects: 183137, time: 00:30:31) 8/19/12 4:41 PM Task completed 8/19/12 4:41 PM Deleted: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055747.exe 8/19/12 4:41 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055747.exe 8/19/12 4:41 PM Deleted: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055715.exe 8/19/12 4:41 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055715.exe 8/19/12 4:41 PM Deleted: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055608.exe 8/19/12 4:41 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055608.exe 8/19/12 4:41 PM Deleted: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055607.exe 8/19/12 4:41 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055607.exe 8/19/12 4:41 PM Deleted: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055568.exe 8/19/12 4:41 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055568.exe 8/19/12 4:41 PM Deleted: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055547.exe 8/19/12 4:41 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055547.exe 8/19/12 4:41 PM Deleted: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055529.exe 8/19/12 4:41 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055529.exe 8/19/12 4:41 PM Deleted: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055512.exe 8/19/12 4:41 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055512.exe 8/19/12 4:41 PM Deleted: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055491.exe 8/19/12 4:41 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055491.exe 8/19/12 4:41 PM Deleted: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0054496.exe 8/19/12 4:41 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0054496.exe 8/19/12 4:41 PM Deleted: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0054365.exe 8/19/12 4:41 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0054365.exe 8/19/12 4:41 PM Deleted: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0054263.exe 8/19/12 4:41 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0054263.exe 8/19/12 4:41 PM Deleted: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0054128.exe 8/19/12 4:41 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0054128.exe 8/19/12 4:41 PM Deleted: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP186/A0054049.exe 8/19/12 4:41 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP186/A0054049.exe 8/19/12 4:41 PM Deleted: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053839.exe 8/19/12 4:41 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053839.exe 8/19/12 4:41 PM Deleted: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053809.exe 8/19/12 4:41 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053809.exe 8/19/12 4:41 PM Deleted: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053789.exe 8/19/12 4:41 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053789.exe 8/19/12 4:41 PM Deleted: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053722.exe 8/19/12 4:41 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053722.exe 8/19/12 4:41 PM Deleted: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053697.exe 8/19/12 4:41 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053697.exe 8/19/12 4:41 PM Deleted: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053677.exe 8/19/12 4:41 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053677.exe 8/19/12 4:41 PM Deleted: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053652.exe 8/19/12 4:41 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053652.exe 8/19/12 4:41 PM Deleted: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053631.exe 8/19/12 4:41 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053631.exe 8/19/12 4:41 PM Deleted: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053620.exe 8/19/12 4:41 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053620.exe 8/19/12 4:41 PM Deleted: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053594.exe 8/19/12 4:41 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053594.exe 8/19/12 4:41 PM Deleted: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053512.exe 8/19/12 4:41 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053512.exe 8/19/12 4:41 PM Deleted: Backdoor.Win32.Azbreg.cxm C:/Qoobox/Quarantine/C/Documents and Settings/home/ms.exe.vir 8/19/12 4:41 PM Detected: Backdoor.Win32.Azbreg.cxm C:/Qoobox/Quarantine/C/Documents and Settings/home/ms.exe.vir 8/19/12 4:41 PM Deleted: Backdoor.Win32.Azbreg.cxm C:/Qoobox/Quarantine/C/Documents and Settings/home/Local Settings/Application Data/xrkqujlm/gxygfmud.exe.vir 8/19/12 4:41 PM Detected: Backdoor.Win32.Azbreg.cxm C:/Qoobox/Quarantine/C/Documents and Settings/home/Local Settings/Application Data/xrkqujlm/gxygfmud.exe.vir 8/19/12 4:41 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/Qoobox/Quarantine/C/Documents and Settings/home/Local Settings/Application Data/xrkqujlm/_gxygfmud_.exe.zip/gxygfmud.exe Write not supported 8/19/12 4:40 PM Detected: Backdoor.Win32.Azbreg.cxm C:/Qoobox/Quarantine/C/Documents and Settings/home/Local Settings/Application Data/xrkqujlm/_gxygfmud_.exe.zip/gxygfmud.exe 8/19/12 4:40 PM Deleted: Backdoor.Win32.Azbreg.cxm C:/Documents and Settings/home/Start Menu/Programs/Startup/gxygfmud.exe 8/19/12 4:40 PM Detected: Backdoor.Win32.Azbreg.cxm C:/Documents and Settings/home/Start Menu/Programs/Startup/gxygfmud.exe 8/19/12 4:40 PM Deleted: Backdoor.Win32.Azbreg.cxm C:/Documents and Settings/home/Local Settings/temp/xdwbhowj.exe 8/19/12 4:40 PM Detected: Backdoor.Win32.Azbreg.cxm C:/Documents and Settings/home/Local Settings/temp/xdwbhowj.exe 8/19/12 4:40 PM Deleted: Rootkit.Win32.Agent.bnex C:/Documents and Settings/home/Local Settings/temp/njanfjnp.sys 8/19/12 4:39 PM Deleted: Rootkit.Win32.Agent.bnex HKLMSystemControlSet001ServicesMicorsoft Windows Service/Micorsoft Windows Service 8/19/12 4:38 PM Detected: Rootkit.Win32.Agent.bnex C:/Documents and Settings/home/Local Settings/temp/njanfjnp.sys 8/19/12 4:38 PM Deleted: Backdoor.Win32.Azbreg.cxm C:/Documents and Settings/home/Local Settings/Application Data/xrkqujlm/gxygfmud.exe 8/19/12 4:38 PM Disinfected: Backdoor.Win32.Azbreg.cxm HKEY_USERSS-1-5-21-1390067357-926492609-1417001333-1003SoftwareMicrosoftWindowsCurrentVersionRun/GxyGfmud 8/19/12 4:38 PM Disinfected: Backdoor.Win32.Azbreg.cxm HKEY_LOCAL_MACHINESoftwareMicrosoftWindows NTCurrentVersionWinlogon/UserInit 8/19/12 4:38 PM Detected: Backdoor.Win32.Azbreg.cxm C:/Documents and Settings/home/Local Settings/Application Data/xrkqujlm/gxygfmud.exe 8/19/12 4:38 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/Documents and Settings/home/Start Menu/Programs/Startup/gxygfmud.exe Postponed 8/19/12 4:38 PM Detected: Backdoor.Win32.Azbreg.cxm C:/Documents and Settings/home/Start Menu/Programs/Startup/gxygfmud.exe 8/19/12 4:37 PM Untreated: Rootkit.Win32.Agent.bnex C:/Documents and Settings/home/Local Settings/temp/njanfjnp.sys Postponed 8/19/12 4:37 PM Detected: Rootkit.Win32.Agent.bnex C:/Documents and Settings/home/Local Settings/temp/njanfjnp.sys 8/19/12 4:36 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/Documents and Settings/home/Local Settings/Application Data/xrkqujlm/gxygfmud.exe Postponed 8/19/12 4:36 PM Detected: Backdoor.Win32.Azbreg.cxm C:/Documents and Settings/home/Local Settings/Application Data/xrkqujlm/gxygfmud.exe 8/19/12 4:29 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055747.exe Postponed 8/19/12 4:29 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055747.exe 8/19/12 4:29 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055715.exe Postponed 8/19/12 4:29 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055715.exe 8/19/12 4:29 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055491.exe Postponed 8/19/12 4:29 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055491.exe 8/19/12 4:29 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055608.exe Postponed 8/19/12 4:29 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055608.exe 8/19/12 4:29 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055607.exe Postponed 8/19/12 4:29 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055607.exe 8/19/12 4:29 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055568.exe Postponed 8/19/12 4:29 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055568.exe 8/19/12 4:29 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055547.exe Postponed 8/19/12 4:29 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055547.exe 8/19/12 4:29 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055529.exe Postponed 8/19/12 4:29 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055529.exe 8/19/12 4:29 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055512.exe Postponed 8/19/12 4:29 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0055512.exe 8/19/12 4:29 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0054496.exe Postponed 8/19/12 4:29 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0054496.exe 8/19/12 4:29 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0054365.exe Postponed 8/19/12 4:29 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0054365.exe 8/19/12 4:29 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0054263.exe Postponed 8/19/12 4:29 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0054263.exe 8/19/12 4:29 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0054128.exe Postponed 8/19/12 4:29 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP187/A0054128.exe 8/19/12 4:29 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP186/A0054049.exe Postponed 8/19/12 4:29 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP186/A0054049.exe 8/19/12 4:29 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053839.exe Postponed 8/19/12 4:28 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053839.exe 8/19/12 4:28 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053809.exe Postponed 8/19/12 4:28 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053809.exe 8/19/12 4:28 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053789.exe Postponed 8/19/12 4:28 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053789.exe 8/19/12 4:28 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053722.exe Postponed 8/19/12 4:28 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053722.exe 8/19/12 4:28 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053697.exe Postponed 8/19/12 4:28 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053697.exe 8/19/12 4:28 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053677.exe Postponed 8/19/12 4:28 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053677.exe 8/19/12 4:28 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053652.exe Postponed 8/19/12 4:28 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053652.exe 8/19/12 4:28 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053631.exe Postponed 8/19/12 4:28 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053631.exe 8/19/12 4:28 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053620.exe Postponed 8/19/12 4:28 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053620.exe 8/19/12 4:28 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053594.exe Postponed 8/19/12 4:28 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053594.exe 8/19/12 4:28 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053512.exe Postponed 8/19/12 4:28 PM Detected: Backdoor.Win32.Azbreg.cxm C:/System Volume Information/_restore{8B19227E-2B63-4BE2-A035-5ABE3F6A80B8}/RP185/A0053512.exe 8/19/12 4:26 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/Qoobox/Quarantine/C/Documents and Settings/home/Local Settings/Application Data/xrkqujlm/_gxygfmud_.exe.zip/gxygfmud.exe Postponed 8/19/12 4:26 PM Detected: Backdoor.Win32.Azbreg.cxm C:/Qoobox/Quarantine/C/Documents and Settings/home/Local Settings/Application Data/xrkqujlm/_gxygfmud_.exe.zip/gxygfmud.exe 8/19/12 4:26 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/Qoobox/Quarantine/C/Documents and Settings/home/Local Settings/Application Data/xrkqujlm/gxygfmud.exe.vir Postponed 8/19/12 4:26 PM Detected: Backdoor.Win32.Azbreg.cxm C:/Qoobox/Quarantine/C/Documents and Settings/home/Local Settings/Application Data/xrkqujlm/gxygfmud.exe.vir 8/19/12 4:26 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/Qoobox/Quarantine/C/Documents and Settings/home/ms.exe.vir Postponed 8/19/12 4:26 PM Detected: Backdoor.Win32.Azbreg.cxm C:/Qoobox/Quarantine/C/Documents and Settings/home/ms.exe.vir 8/19/12 4:22 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/Documents and Settings/home/Start Menu/Programs/Startup/gxygfmud.exe Postponed 8/19/12 4:22 PM Detected: Backdoor.Win32.Azbreg.cxm C:/Documents and Settings/home/Start Menu/Programs/Startup/gxygfmud.exe 8/19/12 4:20 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/Documents and Settings/home/Local Settings/temp/xdwbhowj.exe Postponed 8/19/12 4:20 PM Detected: Backdoor.Win32.Azbreg.cxm C:/Documents and Settings/home/Local Settings/temp/xdwbhowj.exe 8/19/12 4:20 PM Untreated: Rootkit.Win32.Agent.bnex C:/Documents and Settings/home/Local Settings/temp/njanfjnp.sys Postponed 8/19/12 4:20 PM Detected: Rootkit.Win32.Agent.bnex C:/Documents and Settings/home/Local Settings/temp/njanfjnp.sys 8/19/12 4:20 PM Untreated: Backdoor.Win32.Azbreg.cxm C:/Documents and Settings/home/Local Settings/Application Data/xrkqujlm/gxygfmud.exe Postponed 8/19/12 4:20 PM Detected: Backdoor.Win32.Azbreg.cxm C:/Documents and Settings/home/Local Settings/Application Data/xrkqujlm/gxygfmud.exe 8/19/12 4:11 PM Task started

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.