Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Имам вируси

Featured Replies

Здравейте! Напоследък компютъра ми стартира много бавно ,а по време на работа CPU Usage постоянно се вдига на 40-90 % нормално би трябвало да бъде 0-10%.Предположих, че имам лоши сектори в хард диска ,но грешах програмата HD Tune Pro откри, че нямам лоши сектори. Бях със антивирусната програма AVG най-новата, но вчера реших да я премахна защото много товари компютъра ,а и освен това изобщо не помага на компютъра срещу вирусите.Когато я премахнах забелязах леки подобрения в производителността.Сложих си програмата Malwarebytes Anti-Malware и пуснах пълно сканиране.Резултата около 3 троянски и 3 червея.Останалите около 100 вируса не ги познавам.Уж ги изтрих но пак се появиха тия вируси. ето attach текста . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-09-30.01) . Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 7/25/2012 12:33:11 PM System Uptime: 8/28/2012 10:03:55 PM (11 hours ago) . Motherboard: MSI | | MS-7228 Processor: AMD Sempron™ Processor 2800+ | CPU 1 | 1607/200mhz . ==== Disk Partitions ========================= . A: is Removable C: is FIXED (NTFS) - 57 GiB total, 8.893 GiB free. D: is Removable E: is Removable F: is Removable G: is Removable H: is CDROM () . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP1: 7/25/2012 12:36:40 PM - System Checkpoint RP2: 7/25/2012 1:07:48 PM - Installed AVG 2012 RP3: 7/25/2012 1:08:13 PM - Installed AVG 2012 RP4: 7/25/2012 5:33:22 PM - Installed Windows XP KB958687. RP5: 7/25/2012 5:37:37 PM - Installed Windows XP KB957097. RP6: 7/25/2012 5:38:01 PM - Installed Windows XP KB958644. RP7: 7/25/2012 5:56:12 PM - Installed DirectX RP8: 7/25/2012 6:00:18 PM - Installed Windows Internet Explorer 8. RP9: 7/25/2012 6:10:30 PM - Installed FIFA 08 RP10: 7/25/2012 7:04:48 PM - Installed Diskeeper 2011. RP11: 7/25/2012 10:00:58 PM - Installed Windows Media Player Firefox Plugin RP12: 7/27/2012 10:58:26 PM - System Checkpoint RP13: 7/30/2012 12:39:09 AM - System Checkpoint RP14: 7/31/2012 10:46:17 AM - System Checkpoint RP15: 8/1/2012 10:57:25 AM - System Checkpoint RP16: 8/2/2012 3:49:57 PM - Installed Secret Files 2 - Puritas Cordis RP17: 8/2/2012 3:58:49 PM - Installed DirectX RP18: 8/3/2012 7:07:00 PM - Installed Orb Runtime libraries RP19: 8/5/2012 2:06:31 AM - System Checkpoint RP20: 8/5/2012 5:38:12 PM - Installed Adobe Reader 9.5.0 - Bulgarian. RP21: 8/5/2012 5:43:27 PM - Removed Diskeeper 2011 . RP22: 8/5/2012 5:44:22 PM - Removed Adobe Reader 9.5.0 - Bulgarian. RP23: 8/5/2012 5:44:45 PM - Removed Skype Click to Call RP24: 8/5/2012 5:45:18 PM - Removed Windows Media Player Firefox Plugin RP25: 8/6/2012 4:37:56 PM - Removed Secret Files 2 - Puritas Cordis RP26: 8/6/2012 5:07:30 PM - Installed Java™ 7 Update 5 RP27: 8/6/2012 5:08:45 PM - Installed JavaFX 2.1.1 RP28: 8/7/2012 6:21:37 PM - Installed DirectX RP29: 8/7/2012 7:15:57 PM - Installed Crazy Machines RP30: 8/9/2012 1:06:47 PM - Removed Crazy Machines RP31: 8/11/2012 10:06:32 AM - System Checkpoint RP32: 8/12/2012 7:31:40 PM - System Checkpoint RP33: 8/14/2012 12:20:45 AM - System Checkpoint RP34: 8/15/2012 1:43:41 AM - System Checkpoint RP35: 8/16/2012 2:26:52 PM - System Checkpoint RP36: 8/17/2012 6:00:52 PM - System Checkpoint RP37: 8/19/2012 12:10:53 AM - System Checkpoint RP38: 8/20/2012 2:54:30 PM - Installed Microsoft .NET Framework 2.0 Service Pack 2 RP39: 8/20/2012 3:03:25 PM - Installed Windows KB954550-v5. RP40: 8/20/2012 3:03:55 PM - Printer Driver Microsoft XPS Document Writer Installed RP41: 8/20/2012 3:04:13 PM - Printer Driver Microsoft XPS Document Writer Installed RP42: 8/20/2012 3:04:47 PM - Installed Microsoft .NET Framework 3.0 Service Pack 2 RP43: 8/20/2012 3:15:54 PM - Installed Microsoft .NET Framework 3.5 SP1 RP44: 8/21/2012 9:01:58 PM - System Checkpoint RP45: 8/22/2012 6:33:09 PM - Installed Rome - Total War™ RP46: 8/25/2012 12:06:39 AM - System Checkpoint RP47: 8/26/2012 11:57:08 AM - System Checkpoint RP48: 8/26/2012 10:13:55 PM - Деинстaлирай "JavaFX 2.1.1" RP49: 8/26/2012 10:15:07 PM - Removed JavaFX 2.1.1 RP50: 8/26/2012 10:16:18 PM - Деинстaлирай "JavaFX 2.1.1" RP51: 8/26/2012 10:17:43 PM - Деинстaлирай "Java™ Platform SE binary" RP52: 8/26/2012 10:18:03 PM - Removed Java™ 7 Update 5 RP53: 8/28/2012 1:14:07 AM - System Checkpoint RP54: 8/28/2012 11:18:08 AM - Премести файла в карантината.: smss.exe RP55: 8/28/2012 11:18:37 AM - Премести файла в карантината.: web2net.exe RP56: 8/28/2012 9:53:39 PM - Removed AVG 2012 RP57: 8/28/2012 9:57:00 PM - Removed AVG 2012 . ==== Installed Programs ====================== . µTorrent Adobe Anchor Service CS3 Adobe Asset Services CS3 Adobe Bridge CS3 Adobe Bridge Start Meeting Adobe Camera Raw 4.0 Adobe CMaps Adobe Color - Photoshop Specific Adobe Color Common Settings Adobe Color EU Extra Settings Adobe Color JA Extra Settings Adobe Color NA Recommended Settings Adobe Default Language CS3 Adobe Device Central CS3 Adobe ExtendScript Toolkit 2 Adobe Flash Player 11 ActiveX Adobe Fonts All Adobe Help Viewer CS3 Adobe Linguistics CS3 Adobe PDF Library Files Adobe Photoshop CS3 Adobe Setup Adobe Stock Photos CS3 Adobe Type Support Adobe Update Manager CS3 Adobe Version Cue CS3 Client Adobe WinSoft Linguistics Plugin Adobe XMP Panels CS3 CCleaner Cheat Engine 6.2 FIFA 08 Google Chrome HD Tune Pro 4.01 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Windows XP (KB954550-v5) ImgBurn Malwarebytes Anti-Malware version 1.62.0.1300 Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 NVIDIA Drivers Orb Runtime libraries PDF Settings PotPlayer 1.5.31934 BG PowerISO Sacra Terra - Angelic Night 1.00 Security Task Manager 1.8d Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Skype™ 5.10 SopCast 3.5.0 Subtitle Workshop 2.51 uGet, версия 2.0.2 WebFldrs XP Windows Internet Explorer 8 WinRAR 4.20 (32-битова версия) XviD Video Codec (remove only) «Заработало! Повелитель механизмов» . ==== Event Viewer Messages From Past Week ======== . 8/28/2012 9:45:58 PM, error: Service Control Manager [7000] - The IMAPI CD-Burning COM Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 8/28/2012 9:45:55 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM Service service to connect. 8/28/2012 9:29:47 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the HTTP SSL service to connect. 8/28/2012 9:29:47 PM, error: Service Control Manager [7000] - The HTTP SSL service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 8/26/2012 9:59:25 PM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s). 8/26/2012 10:00:37 PM, error: Service Control Manager [7034] - The ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## service terminated unexpectedly. It has done this 1 time(s). 8/24/2012 9:20:06 AM, error: System Error [1003] - Error code 0000007a, parameter1 c0709ea0, parameter2 c000000e, parameter3 e13d4fec, parameter4 0e9148c0. 8/23/2012 7:25:56 PM, error: atapi [11] - The driver detected a controller error on \Device\Ide\IdePort1. 8/23/2012 7:25:55 PM, error: atapi [9] - The device, \Device\Ide\IdePort1, did not respond within the timeout period. 8/23/2012 12:20:05 PM, error: Service Control Manager [7022] - The AVGIDSAgent service hung on starting. 8/22/2012 5:13:50 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Windows Presentation Foundation Font Cache 3.0.0.0 service to connect. 8/22/2012 5:13:50 PM, error: Service Control Manager [7000] - The Windows Presentation Foundation Font Cache 3.0.0.0 service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 8/22/2012 5:13:49 PM, error: Service Control Manager [7031] - The Windows Presentation Foundation Font Cache 3.0.0.0 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 8/22/2012 10:51:17 AM, error: Dhcp [1002] - The IP address lease 192.168.0.100 for the Network Card with network address 00161785271E has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message). . ==== End Of File =========================== ето и DSS текста DDS (Ver_2011-09-30.01) - NTFS_x86 Internet Explorer: 8.0.6001.18702 Run by Petko at 9:58:28 on 2012-08-29 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.447.279 [GMT 3:00] . AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF} . ============== Running Processes ================ . C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\System32\svchost.exe -k HTTPFilter . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com uInternet Connection Wizard,ShellNext = iexplore uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSConfig.exe /auto mRunOnce: [Malwarebytes Anti-Malware (cleanup)] rundll32.exe "c:\documents and settings\all users\application data\malwarebytes\malwarebytes' anti-malware\cleanup.dll",ProcessCleanupScript uPolicies-Explorer: NoDriveTypeAutoRun = dword:145 mPolicies-Explorer: NoDriveTypeAutoRun = dword:145 mPolicies-Explorer: NoDriveTypeAutoRun = dword:145 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab TCP: NameServer = 178.254.216.1 178.254.216.2 TCP: Interfaces\{07048562-DD27-41BC-ADA5-A5440191A1B8} : DHCPNameServer = 178.254.216.1 178.254.216.2 Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll . ============= SERVICES / DRIVERS =============== . R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2012-8-28 40776] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-8-28 22344] S3 SetupNTGLM7X;SetupNTGLM7X;\??\h:\ntglm7x.sys --> h:\NTGLM7X.sys [?] S4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-8-5 250056] S4 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-8-28 655944] S4 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-6-7 160944] . =============== Created Last 30 ================ . 2012-08-29 06:46:07 54016 ----a-w- c:\windows\system32\drivers\mvrs.sys 2012-08-28 20:47:43 110100480 ----a-w- C:\TESTFILE.TMP 2012-08-28 20:40:38 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2012-08-28 19:12:23 -------- d-----w- c:\documents and settings\petko\application data\HD Tune Pro 2012-08-28 19:12:16 -------- d-----w- c:\program files\HD Tune Pro 2012-08-28 19:00:20 -------- d-----w- c:\windows\system32\LogFiles 2012-08-28 18:36:06 -------- d-----w- c:\program files\CCleaner 2012-08-28 18:05:21 -------- d-----w- c:\documents and settings\petko\application data\Malwarebytes 2012-08-28 18:05:00 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes 2012-08-28 18:04:59 22344 ----a-w- c:\windows\system32\drivers\mbam.sys 2012-08-28 18:04:59 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2012-08-26 19:21:36 -------- d-----w- c:\documents and settings\all users\application data\AlawarWrapper 2012-08-26 18:55:04 -------- d-----w- c:\documents and settings\all users\application data\SecTaskMan 2012-08-26 18:54:58 -------- d-----w- c:\program files\Security Task Manager 2012-08-26 18:22:35 -------- d-----w- c:\program files\Сакра Терра. Ночь ангела. Коллекционное издание 2012-08-26 18:03:10 -------- d-----w- c:\documents and settings\petko\application data\Alawar Entertainment 2012-08-23 10:08:42 -------- d-----w- c:\documents and settings\petko\local settings\application data\PackageAware 2012-08-22 15:34:01 -------- d-----w- c:\program files\Crazy Mashienes NFTL 2012-08-22 15:20:30 -------- d-----w- c:\documents and settings\petko\application data\NatGeoGames 2012-08-22 15:20:30 -------- d-----w- c:\documents and settings\all users\application data\NatGeoGames 2012-08-20 12:12:05 -------- d-----w- c:\windows\system32\XPSViewer 2012-08-20 12:04:07 89088 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll 2012-08-20 12:02:45 150808 ----a-w- c:\windows\system32\rgb9rast_2.dll 2012-08-20 11:54:10 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2012-08-20 11:54:10 597504 ------w- c:\windows\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe 2012-08-20 11:54:07 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll 2012-08-20 11:54:07 575488 ------w- c:\windows\system32\xpsshhdr.dll 2012-08-20 11:54:07 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll 2012-08-20 11:54:07 1676288 ------w- c:\windows\system32\xpssvcs.dll 2012-08-20 11:53:46 117760 ------w- c:\windows\system32\prntvpt.dll 2012-08-20 11:53:34 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll 2012-08-20 11:29:09 -------- d-----w- c:\program files\Allmyapps 2012-08-18 13:36:07 -------- d-----w- c:\program files\XviD 2012-08-18 13:30:58 -------- d-----w- c:\program files\URUSoft 2012-08-16 19:03:39 -------- d-----w- c:\program files\Cheat Engine 6.2 2012-08-16 09:13:40 -------- d-----w- c:\documents and settings\all users\application data\CrioGames 2012-08-15 19:11:52 -------- d-----w- c:\documents and settings\all users\application data\Fugazo 2012-08-15 16:13:48 0 ----a-w- c:\windows\DXT6F7.tmp 2012-08-15 16:13:48 0 ----a-w- c:\windows\DXT6F6.tmp 2012-08-15 16:13:48 0 ----a-w- c:\windows\DXT6F5.tmp 2012-08-15 16:13:48 0 ----a-w- c:\windows\DXT6F4.tmp 2012-08-15 16:13:48 0 ----a-w- c:\windows\DXT6F3.tmp 2012-08-15 16:13:48 0 ----a-w- c:\windows\DXT6F2.tmp 2012-08-15 16:12:19 306688 ----a-w- c:\windows\IsUninst.exe 2012-08-08 11:12:31 -------- d-----w- c:\documents and settings\petko\local settings\application data\Mozilla 2012-08-07 15:26:32 -------- d-----w- c:\documents and settings\petko\local settings\application data\Identities 2012-08-07 15:13:14 -------- d-----w- c:\program files\Oil Platform Simulator 2012-08-06 14:19:05 880640 ----a-w- c:\windows\system32\UniBox10.ocx 2012-08-06 14:19:05 212992 ----a-w- c:\windows\system32\UniBoxVB12.ocx 2012-08-06 14:19:05 108336 ----a-w- c:\windows\system32\MSWINSCK.OCX 2012-08-06 14:19:04 1101824 ----a-w- c:\windows\system32\UniBox210.ocx 2012-08-06 14:18:56 -------- d-----w- c:\program files\uGet VGI 2012-08-06 14:10:09 -------- d-----w- c:\documents and settings\petko\local settings\application data\Sun 2012-08-06 14:08:33 687544 ----a-w- c:\windows\system32\deployJava1.dll 2012-08-06 14:08:32 772544 ----a-w- c:\windows\system32\npDeployJava1.dll 2012-08-05 15:20:15 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-08-05 15:20:15 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2012-08-05 14:58:58 -------- d-----w- c:\windows\pss 2012-08-05 14:43:49 -------- d-----w- c:\windows\system32\appmgmt 2012-08-05 14:42:18 -------- d-sh--w- c:\documents and settings\petko\PrivacIE 2012-08-02 12:58:55 2297552 ----a-w- c:\windows\system32\d3dx9_26.dll 2012-08-02 12:57:00 278984 ----a-w- c:\windows\system32\drivers\atksgt.sys 2012-08-02 12:56:56 25416 ----a-w- c:\windows\system32\drivers\lirsgt.sys 2012-08-01 18:31:15 -------- d-----w- c:\documents and settings\petko\temp 2012-08-01 18:31:14 -------- d-----w- c:\documents and settings\petko\application data\TeamViewer . ==================== Find3M ==================== . 2012-07-29 18:08:06 98304 ----a-w- c:\windows\system32\CmdLineExt.dll 2012-07-26 17:31:31 90112 ----a-w- c:\windows\DUMPcc58.tmp 2012-07-19 09:38:52 113104 ----a-w- c:\windows\system32\drivers\scdemu.sys . ============= FINISH: 9:59:05,07 ===============

Сложих си програмата Malwarebytes Anti-Malware и пуснах пълно сканиране.Резултата около 3 троянски и 3 червея.Останалите около 100 вируса не ги познавам.Уж ги изтрих но пак се появиха тия вируси.

Здравейте..!А може ли да видя дневника от Malwarebytes Anti-Malware...?:)

  • Автор

Malwarebytes Anti-Malware (PRO) 1.62.0.1300 www.malwarebytes.org Database version: v2012.07.03.05 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Petko :: PETKO-0BEA8AEAA [administrator] Protection: Enabled 28.8.2012 г. 21:11:23 mbam-log-2012-08-28 (21-11-23).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 185331 Time elapsed: 10 minute(s), 11 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 155 HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Options360rpt.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Options360Safe.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Options360safebox.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Options360tray.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsadam.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsAgentSvr.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsAntiU.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsAoYun.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsappdllman.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsAppSvc32.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsArSwp.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsAST.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsauto.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsAutoRun.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsautoruns.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsav.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsAvastU3.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsavconsol.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsavgrssvc.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsAvMonitor.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsavp.com (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsAvU3Launcher.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsCCenter.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsccSvcHst.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionscross.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsDiscovery.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsEGHOST.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsFileDsty.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsFTCleanerShell.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsFYFireWall.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsghost.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsguangd.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsHijackThis.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsIceSword.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsiparmo.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsIparmor.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsirsetup.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsisPwdSvc.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionskabaload.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKaScrScn.SCR (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKASMain.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKASTask.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKAV32.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKAVDX.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKAVPF.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKAVPFW.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKAVSetup.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKAVStart.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionskernelwind32.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKISLnchr.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionskissvc.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKMailMon.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKMFilter.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKPFW32.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKPFW32X.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKPfwSvc.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKRegEx.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKRepair.com (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKsLoader.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKVCenter.kxp (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKvDetect.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKvfwMcl.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKVMonXP.kxp (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKVMonXP_1.kxp (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionskvol.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionskvolself.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKvReport.kxp (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKVScan.kxp (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKVSrvXP.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKVStub.kxp (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionskvupload.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionskvwsc.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKvXP.kxp (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKvXP_1.kxp (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKWatch.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKWatch9x.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKWatchX.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsloaddll.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionslogogo.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsMagicSet.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsmcconsol.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsmmqczj.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsmmsk.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsNavapsvc.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsNavapw32.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsNAVSetup.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsniu.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsnod32.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsnod32krn.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsnod32kui.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsNPFMntor.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionspagefile.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionspagefile.pif (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsPFW.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsPFWLiveUpdate.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsQHSET.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsQQDoctor.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsQQDoctorMain.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsQQKav.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsQQSC.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsRas.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsRav.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsRavMon.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsRavMonD.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsRavStub.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsRavTask.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsRegClean.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsregedit.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsregedit32.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsrfwcfg.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsrfwmain.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsrfwProxy.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsrfwsrv.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsRsAgent.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsRsaupd.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsrstrui.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsruniep.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionssafelive.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsscan32.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsScanU3.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsSDGames.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsSelfUpdate.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsservet.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsshcfg32.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsSmartUp.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionssos.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsSREng.EXE (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsSREngPS.EXE (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionssymlcsvc.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsSysSafe.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsTNT.Exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsTrojanDetector.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsTrojanwall.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsTrojDie.kxp (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsTxoMoU.Exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsUFO.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsUIHost.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsUmxAgent.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsUmxAttachment.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsUmxCfg.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsUmxFwHlp.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsUmxPol.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsupiea.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsUpLive.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsUSBCleaner.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsvsstat.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionswebscanx.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsWoptiClean.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsWsyscheck.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsXDelBox.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsXP.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionszjb.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionszxsweep.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Options~.exe (Security.Hijack) -> Quarantined and deleted successfully. HKLMSOFTWAREMICROSOFTWINDOWS NTCURRENTVERSIONIMAGE FILE EXECUTION OPTIONSAVP.EXE (Security.Hijack) -> Quarantined and deleted successfully. Registry Values Detected: 3 HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsautorun.exe|Debugger (Security.Hijack) -> Data: ntsd -d -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsavp.exe|Debugger (Security.Hijack) -> Data: ntsd -d -> Quarantined and deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionTerminal ServerInstallSoftwareMicrosoftWindowsCurrentVersionRun|Windows System Controler (Trojan.Agent) -> Data: c:windowssmss.exe -> Quarantined and deleted successfully. Registry Data Items Detected: 1 HKCUSOFTWAREMicrosoftInternet ExplorerMain|Start Page (Hijack.StartPage) -> Bad: (http://zonedirector.com/1/) Good: (http://www.google.com) -> Quarantined and repaired successfully. Folders Detected: 0 (No malicious items detected) Files Detected: 5 C:syemajo.exe (Trojan.Downloader) -> Quarantined and deleted successfully. C:Documents and SettingsAll UsersStart MenuProgramsStartupsyemajo.exe (Trojan.Downloader) -> Quarantined and deleted successfully. C:Documents and SettingsPetkoStart MenuProgramsStartupfuvhvdk.exe (Trojan.Downloader) -> Quarantined and deleted successfully. C:WINDOWSsystem32musz1s.dll (Worm.AutoRun) -> Quarantined and deleted successfully. C:WINDOWSsystem32musz2s.dll (Worm.AutoRun) -> Quarantined and deleted successfully. (end)

Публикувано изображение Изтеглете ComboFix Публикувано изображение от тук и го запазете на десктопа си.

  • Изключете вашата антивирусна и антишпионска програма, обикновено това става чрез натискане на десния бутон на мишката върху иконата на програма в системния трей.
Бележка: Ако не можете я спрете или не сте сигурни коя програма да изключите, моля прегледайте информацията от този линк: How to Disable your Security Programs
  • Стартирайте Combo-Fix.com Публикувано изображение и следвайте инструкциите.
Бележка: ComboFix ще се стартира без инсталирана Recovery Console.
  • Като част от неговата работа, ComboFix ще провери дали Microsoft Windows Recovery Console е инсталирана. Предвид бързо развиващия се зловреден софтуер е силно препоръчително да бъде инсталирана преди премахването на зловредния софтуер. Това ще Ви позволи да влезете в специален recovery/repair режим, който ще ни позволи по-лесно да решите проблем, който би могъл да възникне при премахване на зловредния софтуер.
  • Следвайте инструкциите, за да позволите на ComboFix да изтегли и инсталира Microsoft Windows Recovery Console. В един момент ще бъдете попитани дали сте съгласни с лицензното споразумение. Необходимо е да потвърдите, че сте съгласни, за да инсталирате Microsoft Windows Recovery Console.
** Забележете: Ако Microsoft Windows Recovery Console е вече инсталирана, ComboFix ще продължи към процеса по премахване на зловредния софтуер.

Публикувано изображение

След като Microsoft Windows Recovery Console е инсталирана, използвайки ComboFix, Вие ще видите следното съобщение:

Публикувано изображение

Изберете Yes, за да продължи сканирането за зловреден софтуер.

Когато процесът приключи успешно, инструментът ще създаде лог файл. Моля, включете съдържанието на C:ComboFix.txt в следващия Ви коментар в тази тема.

Бележка:

  • Моля, не движете мишката, докато ComboFix работи. Това може да наруши процеса на работа.
  • ComboFix ще нулира всички настройки на Microsoft Internet Explorer, включително да направи IE браузър по подразбиране.
  • ComboFix ще изключи autorun функцията на ВСИЧКИ CD, Floppy и USB устройства, за да помогне при премахването на зловредния софтуер и Ви защити от бъдещи вируси/заплахи, които поразяват чрез autorun. Ако това е проблем за вас - моля, уведомете ме.
  • ComboFix ще изключи вашата интернет връзка. Интернет връзката ще се възстанови автоматично, преди ComboFix да завърши процеса на работа. При проблем, той ще прекрати интернет връзката. За да възстановите интернет връзката си, рестартирайте компютъра си.
  • В случай на проблем с ComboFix, той може да създаде лог файл. Моля, включете съдържанието на C:BUG.txt в следващия Ви коментар в тази тема.
Публикувано изображение Моля, не прикачвайте лог файла/овете от програмата, а го/ги копирайте и поставете в следващия Ви коментар в тази тема.
  • Автор

И имам 6 "svchost.exe" процеси.В програмата Security Task Manager пише че процеса "smss.exe" представлява потенциална опасност и го преместих под карантина.И имам още един процес който не знам какво е "web2net.exe".

И имам 6 "svchost.exe" процеси.В програмата Security Task Manager пише че процеса "smss.exe" представлява потенциална опасност и го преместих под карантина.И имам още един процес който не знам какво е "web2net.exe".

Дал съм ви инструкции ..моля следвайте ги...!:)

  • Автор

ComboFix 12-08-28.03 - Petko 08.2012 г. 11:13:41.1.1 - x86 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.447.224 [GMT 3:00] Running from: c:documents and settingsPetkoDesktopComboFix.exe AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . C:autorun.inf . . ((((((((((((((((((((((((( Files Created from 2012-07-28 to 2012-08-29 ))))))))))))))))))))))))))))))) . . 2012-08-28 20:47 . 2012-08-28 20:48 110100480 ----a-w- C:TESTFILE.TMP 2012-08-28 19:12 . 2012-08-28 19:12 -------- d-----w- c:documents and settingsPetkoApplication DataHD Tune Pro 2012-08-28 19:12 . 2012-08-28 19:12 -------- d-----w- c:program filesHD Tune Pro 2012-08-28 19:00 . 2012-08-28 19:00 -------- d-----w- c:windowssystem32LogFiles 2012-08-28 18:36 . 2012-08-28 18:36 -------- d-----w- c:program filesCCleaner 2012-08-28 18:05 . 2012-08-28 18:05 -------- d-----w- c:documents and settingsPetkoApplication DataMalwarebytes 2012-08-28 18:05 . 2012-08-28 18:05 -------- d-----w- c:documents and settingsAll UsersApplication DataMalwarebytes 2012-08-28 18:04 . 2012-08-28 18:05 -------- d-----w- c:program filesMalwarebytes' Anti-Malware 2012-08-28 18:04 . 2012-07-03 10:46 22344 ----a-w- c:windowssystem32driversmbam.sys 2012-08-26 19:21 . 2012-08-26 19:21 -------- d-----w- c:documents and settingsAll UsersApplication DataAlawarWrapper 2012-08-26 18:55 . 2012-08-29 07:59 -------- d-----w- c:documents and settingsAll UsersApplication DataSecTaskMan 2012-08-26 18:54 . 2012-08-26 19:12 -------- d-----w- c:program filesSecurity Task Manager 2012-08-26 18:22 . 2012-08-26 19:21 -------- d-----w- c:program filesСакра Терра. Ночь ангела. Коллекционное издание 2012-08-26 18:03 . 2012-08-26 18:03 -------- d-----w- c:documents and settingsPetkoApplication DataAlawar Entertainment 2012-08-23 10:08 . 2012-08-23 10:08 -------- d-----w- c:documents and settingsPetkoLocal SettingsApplication DataPackageAware 2012-08-22 15:34 . 2012-08-22 15:34 -------- d-----w- c:program filesCrazy Mashienes NFTL 2012-08-22 15:20 . 2012-08-22 15:20 -------- d-----w- c:documents and settingsPetkoApplication DataNatGeoGames 2012-08-22 15:20 . 2012-08-22 15:20 -------- d-----w- c:documents and settingsAll UsersApplication DataNatGeoGames 2012-08-20 12:12 . 2012-08-20 12:12 -------- d-----w- c:windowssystem32XPSViewer 2012-08-20 12:08 . 2012-08-20 12:08 -------- d-----w- c:program filesMSBuild 2012-08-20 12:04 . 2012-08-20 12:04 -------- d-----w- c:program filesReference Assemblies 2012-08-20 12:04 . 2008-07-06 12:06 89088 ----a-w- c:windowssystem32Spoolprtprocsw32x86filterpipelineprintproc.dll 2012-08-20 12:02 . 2006-08-24 13:15 150808 ----a-w- c:windowssystem32rgb9rast_2.dll 2012-08-20 11:54 . 2008-07-06 10:50 597504 -c----w- c:windowssystem32dllcacheprintfilterpipelinesvc.exe 2012-08-20 11:54 . 2008-07-06 10:50 597504 ------w- c:windowssystem32Spoolprtprocsw32x86printfilterpipelinesvc.exe 2012-08-20 11:54 . 2008-07-06 12:06 575488 -c----w- c:windowssystem32dllcachexpsshhdr.dll 2012-08-20 11:54 . 2008-07-06 12:06 575488 ------w- c:windowssystem32xpsshhdr.dll 2012-08-20 11:54 . 2008-07-06 12:06 1676288 -c----w- c:windowssystem32dllcachexpssvcs.dll 2012-08-20 11:54 . 2008-07-06 12:06 1676288 ------w- c:windowssystem32xpssvcs.dll 2012-08-20 11:53 . 2008-07-06 12:06 117760 ------w- c:windowssystem32prntvpt.dll 2012-08-20 11:53 . 2008-07-06 12:06 89088 -c----w- c:windowssystem32dllcachefilterpipelineprintproc.dll 2012-08-20 11:29 . 2012-08-22 08:12 -------- d-----w- c:program filesAllmyapps 2012-08-18 13:36 . 2012-08-18 13:36 -------- d-----w- c:program filesXviD 2012-08-18 13:30 . 2012-08-18 13:30 -------- d-----w- c:program filesURUSoft 2012-08-16 19:03 . 2012-08-16 19:03 -------- d-----w- c:program filesCheat Engine 6.2 2012-08-16 09:13 . 2012-08-16 09:13 -------- d-----w- c:documents and settingsAll UsersApplication DataCrioGames 2012-08-15 19:11 . 2012-08-15 19:11 -------- d-----w- c:documents and settingsAll UsersApplication DataFugazo 2012-08-15 16:13 . 2012-08-15 16:13 0 ----a-w- c:windowsDXT6F7.tmp 2012-08-15 16:13 . 2012-08-15 16:13 0 ----a-w- c:windowsDXT6F6.tmp 2012-08-15 16:13 . 2012-08-15 16:13 0 ----a-w- c:windowsDXT6F5.tmp 2012-08-15 16:13 . 2012-08-15 16:13 0 ----a-w- c:windowsDXT6F4.tmp 2012-08-15 16:13 . 2012-08-15 16:13 0 ----a-w- c:windowsDXT6F3.tmp 2012-08-15 16:13 . 2012-08-15 16:13 0 ----a-w- c:windowsDXT6F2.tmp 2012-08-15 16:12 . 1998-10-29 13:45 306688 ----a-w- c:windowsIsUninst.exe 2012-08-08 11:12 . 2012-08-08 11:12 -------- d-----w- c:documents and settingsPetkoLocal SettingsApplication DataMozilla 2012-08-07 15:26 . 2012-08-07 15:26 -------- d-----w- c:documents and settingsPetkoLocal SettingsApplication DataIdentities 2012-08-07 15:13 . 2012-08-07 15:31 -------- d-----w- c:program filesOil Platform Simulator 2012-08-06 14:19 . 2008-04-02 13:53 212992 ----a-w- c:windowssystem32UniBoxVB12.ocx 2012-08-06 14:19 . 2008-04-02 13:53 880640 ----a-w- c:windowssystem32UniBox10.ocx 2012-08-06 14:19 . 1998-06-24 07:00 108336 ----a-w- c:windowssystem32MSWINSCK.OCX 2012-08-06 14:19 . 2008-04-02 13:54 1101824 ----a-w- c:windowssystem32UniBox210.ocx 2012-08-06 14:18 . 2012-08-25 20:04 -------- d-----w- c:program filesuGet VGI 2012-08-06 14:10 . 2012-08-06 14:10 -------- d-----w- c:windowsSun 2012-08-06 14:10 . 2012-08-06 14:10 -------- d-----w- c:documents and settingsPetkoLocal SettingsApplication DataSun 2012-08-06 14:08 . 2012-08-06 14:08 -------- d-----w- c:documents and settingsPetkoApplication DataOracle 2012-08-06 14:08 . 2012-07-05 19:06 687544 ----a-w- c:windowssystem32deployJava1.dll 2012-08-06 14:08 . 2012-07-05 19:06 772544 ----a-w- c:windowssystem32npDeployJava1.dll 2012-08-05 15:20 . 2012-08-15 09:19 426184 ----a-w- c:windowssystem32FlashPlayerApp.exe 2012-08-05 15:20 . 2012-08-15 09:19 70344 ----a-w- c:windowssystem32FlashPlayerCPLApp.cpl 2012-08-05 15:20 . 2012-08-05 15:20 -------- d-----w- c:windowssystem32Macromed 2012-08-05 14:42 . 2012-08-05 14:42 -------- d-sh--w- c:documents and settingsPetkoPrivacIE 2012-08-02 17:40 . 2012-08-02 18:27 -------- d-----w- c:documents and settingsPetkoApplication DataImgBurn 2012-08-02 17:40 . 2012-08-02 17:40 -------- d-----w- c:program filesImgBurn 2012-08-02 12:58 . 2005-05-26 12:34 2297552 ----a-w- c:windowssystem32d3dx9_26.dll 2012-08-02 12:57 . 2012-08-02 12:57 278984 ----a-w- c:windowssystem32driversatksgt.sys 2012-08-02 12:56 . 2012-08-02 12:56 25416 ----a-w- c:windowssystem32driverslirsgt.sys 2012-08-01 18:31 . 2012-08-01 18:31 -------- d-----w- c:documents and settingsPetkotemp 2012-08-01 18:31 . 2012-08-01 19:04 -------- d-----w- c:documents and settingsPetkoApplication DataTeamViewer . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-07-29 18:08 . 2012-07-29 18:08 98304 ----a-w- c:windowssystem32CmdLineExt.dll 2012-07-26 17:31 . 2012-07-25 12:06 90112 ----a-w- c:windowsDUMPcc58.tmp 2012-07-19 09:38 . 2012-07-19 09:38 113104 ----a-w- c:windowssystem32driversscdemu.sys . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun] "NvCplDaemon"="c:windowssystem32NvCpl.dll" [2005-10-17 7307264] "nwiz"="nwiz.exe" [2005-10-17 1519616] "NvMediaCenter"="c:windowssystem32NvMcTray.dll" [2005-10-17 86016] "Malwarebytes' Anti-Malware"="c:program filesMalwarebytes' Anti-Malwarembamgui.exe" [2012-07-03 462920] . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregGoogle Update] 2012-07-25 09:59 116648 ----atw- c:documents and settingsPetkoLocal SettingsApplication DataGoogleUpdateGoogleUpdate.exe . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregMalwarebytes' Anti-Malware] 2012-07-03 10:46 462920 ----a-w- c:program filesMalwarebytes' Anti-Malwarembamgui.exe . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregPWRISOVM.EXE] 2012-07-19 09:38 336992 ----a-w- c:program filesPowerISOPWRISOVM.EXE . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigservices] "SkypeUpdate"=2 (0x2) "NVSvc"=2 (0x2) "AdobeFlashPlayerUpdateSvc"=3 (0x3) "idsvc"=3 (0x3) "FLEXnet Licensing Service"=3 (0x3) "Bonjour Service"=2 (0x2) "AudioSrv"=2 (0x2) "MBAMService"=2 (0x2) . [HKLM~servicessharedaccessparametersfirewallpolicystandardprofile] "EnableFirewall"= 0 (0x0) . [HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList] "%windir%Network Diagnosticxpnetdiag.exe"= "%windir%system32sessmgr.exe"= "c:Program FilesuTorrentuTorrent.exe"= "c:Program FilesSopCastSopCast.exe"= "c:Program FilesBonjourmDNSResponder.exe"= "c:Program FilesDAUMPotPlayerPotPlayerMini.exe"= "c:Program FilesSkypePhoneSkype.exe"= . R3 MBAMProtector;MBAMProtector;c:windowssystem32driversmbam.sys [8/28/2012 9:04 PM 22344] S3 SetupNTGLM7X;SetupNTGLM7X;??h:ntglm7x.sys --> h:NTGLM7X.sys [?] . Contents of the 'Scheduled Tasks' folder . 2012-08-29 c:windowsTasksAdobe Flash Player Updater.job - c:windowssystem32MacromedFlashFlashPlayerUpdateService.exe [2012-08-05 09:20] . 2012-08-28 c:windowsTasksGoogleUpdateTaskUserS-1-5-21-1123561945-1715567821-1801674531-1003Core.job - c:documents and settingsPetkoLocal SettingsApplication DataGoogleUpdateGoogleUpdate.exe [2012-07-25 09:59] . 2012-08-29 c:windowsTasksGoogleUpdateTaskUserS-1-5-21-1123561945-1715567821-1801674531-1003UA.job - c:documents and settingsPetkoLocal SettingsApplication DataGoogleUpdateGoogleUpdate.exe [2012-07-25 09:59] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.local TCP: DhcpNameServer = 178.254.216.1 178.254.216.2 . - - - - ORPHANS REMOVED - - - - . MSConfigStartUp-Windows System Controler - c:windowssmss.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2012-08-29 11:22 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . Completion time: 2012-08-29 11:30:00 ComboFix-quarantined-files.txt 2012-08-29 08:29 . Pre-Run: 9 621 733 376 bytes free Post-Run: 9 932 165 120 bytes free . WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)WINDOWS [operating systems] c:cmdconsBOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons UnsupportedDebug="do not select this" /debug multi(0)disk(0)rdisk(0)partition(1)WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect . - - End Of File - - F9B63EE1BBD963C5B9A1E3C454DF04FB

Копирайте текста в карето на notepad и го запазвате с име CFScript.txt на десктопа си:

KILLALL::

File::
c:windowsDXT6F7.tmp
c:windowsDXT6F6.tmp
c:windowsDXT6F5.tmp
c:windowsDXT6F4.tmp
c:windowsDXT6F3.tmp
c:windowsDXT6F2.tmp
c:windowsDUMPcc58.tmp

След съхранението преместете CFScript.txt на иконата на ComboFix.exe

Публикувано изображение

Генерирания рапорт копирайте и го поставете в следващия си коментар...!

  • Автор

ComboFix 12-08-28.03 - Petko 08.2012 г. 12:34:25.2.1 - x86 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.447.283 [GMT 3:00] Running from: c:documents and settingsPetkoDesktopComboFix.exe Command switches used :: c:documents and settingsPetkoDesktopCFScript.txt AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF} . FILE :: "c:windowsDUMPcc58.tmp" "c:windowsDXT6F2.tmp" "c:windowsDXT6F3.tmp" "c:windowsDXT6F4.tmp" "c:windowsDXT6F5.tmp" "c:windowsDXT6F6.tmp" "c:windowsDXT6F7.tmp" . . ((((((((((((((((((((((((( Files Created from 2012-07-28 to 2012-08-29 ))))))))))))))))))))))))))))))) . . 2012-08-28 20:47 . 2012-08-28 20:48 110100480 ----a-w- C:TESTFILE.TMP 2012-08-28 19:12 . 2012-08-28 19:12 -------- d-----w- c:documents and settingsPetkoApplication DataHD Tune Pro 2012-08-28 19:12 . 2012-08-28 19:12 -------- d-----w- c:program filesHD Tune Pro 2012-08-28 19:00 . 2012-08-28 19:00 -------- d-----w- c:windowssystem32LogFiles 2012-08-28 18:36 . 2012-08-28 18:36 -------- d-----w- c:program filesCCleaner 2012-08-28 18:05 . 2012-08-28 18:05 -------- d-----w- c:documents and settingsPetkoApplication DataMalwarebytes 2012-08-28 18:05 . 2012-08-28 18:05 -------- d-----w- c:documents and settingsAll UsersApplication DataMalwarebytes 2012-08-28 18:04 . 2012-08-28 18:05 -------- d-----w- c:program filesMalwarebytes' Anti-Malware 2012-08-28 18:04 . 2012-07-03 10:46 22344 ----a-w- c:windowssystem32driversmbam.sys 2012-08-26 19:21 . 2012-08-26 19:21 -------- d-----w- c:documents and settingsAll UsersApplication DataAlawarWrapper 2012-08-26 18:55 . 2012-08-29 07:59 -------- d-----w- c:documents and settingsAll UsersApplication DataSecTaskMan 2012-08-26 18:54 . 2012-08-26 19:12 -------- d-----w- c:program filesSecurity Task Manager 2012-08-26 18:22 . 2012-08-26 19:21 -------- d-----w- c:program filesСакра Терра. Ночь ангела. Коллекционное издание 2012-08-26 18:03 . 2012-08-26 18:03 -------- d-----w- c:documents and settingsPetkoApplication DataAlawar Entertainment 2012-08-23 10:08 . 2012-08-23 10:08 -------- d-----w- c:documents and settingsPetkoLocal SettingsApplication DataPackageAware 2012-08-22 15:34 . 2012-08-22 15:34 -------- d-----w- c:program filesCrazy Mashienes NFTL 2012-08-22 15:20 . 2012-08-22 15:20 -------- d-----w- c:documents and settingsPetkoApplication DataNatGeoGames 2012-08-22 15:20 . 2012-08-22 15:20 -------- d-----w- c:documents and settingsAll UsersApplication DataNatGeoGames 2012-08-20 12:12 . 2012-08-20 12:12 -------- d-----w- c:windowssystem32XPSViewer 2012-08-20 12:08 . 2012-08-20 12:08 -------- d-----w- c:program filesMSBuild 2012-08-20 12:04 . 2012-08-20 12:04 -------- d-----w- c:program filesReference Assemblies 2012-08-20 12:04 . 2008-07-06 12:06 89088 ----a-w- c:windowssystem32Spoolprtprocsw32x86filterpipelineprintproc.dll 2012-08-20 12:02 . 2006-08-24 13:15 150808 ----a-w- c:windowssystem32rgb9rast_2.dll 2012-08-20 11:54 . 2008-07-06 10:50 597504 -c----w- c:windowssystem32dllcacheprintfilterpipelinesvc.exe 2012-08-20 11:54 . 2008-07-06 10:50 597504 ------w- c:windowssystem32Spoolprtprocsw32x86printfilterpipelinesvc.exe 2012-08-20 11:54 . 2008-07-06 12:06 575488 -c----w- c:windowssystem32dllcachexpsshhdr.dll 2012-08-20 11:54 . 2008-07-06 12:06 575488 ------w- c:windowssystem32xpsshhdr.dll 2012-08-20 11:54 . 2008-07-06 12:06 1676288 -c----w- c:windowssystem32dllcachexpssvcs.dll 2012-08-20 11:54 . 2008-07-06 12:06 1676288 ------w- c:windowssystem32xpssvcs.dll 2012-08-20 11:53 . 2008-07-06 12:06 117760 ------w- c:windowssystem32prntvpt.dll 2012-08-20 11:53 . 2008-07-06 12:06 89088 -c----w- c:windowssystem32dllcachefilterpipelineprintproc.dll 2012-08-20 11:29 . 2012-08-22 08:12 -------- d-----w- c:program filesAllmyapps 2012-08-18 13:36 . 2012-08-18 13:36 -------- d-----w- c:program filesXviD 2012-08-18 13:30 . 2012-08-18 13:30 -------- d-----w- c:program filesURUSoft 2012-08-16 19:03 . 2012-08-16 19:03 -------- d-----w- c:program filesCheat Engine 6.2 2012-08-16 09:13 . 2012-08-16 09:13 -------- d-----w- c:documents and settingsAll UsersApplication DataCrioGames 2012-08-15 19:11 . 2012-08-15 19:11 -------- d-----w- c:documents and settingsAll UsersApplication DataFugazo 2012-08-15 16:13 . 2012-08-15 16:13 0 ----a-w- c:windowsDXT6F7.tmp 2012-08-15 16:13 . 2012-08-15 16:13 0 ----a-w- c:windowsDXT6F6.tmp 2012-08-15 16:13 . 2012-08-15 16:13 0 ----a-w- c:windowsDXT6F5.tmp 2012-08-15 16:13 . 2012-08-15 16:13 0 ----a-w- c:windowsDXT6F4.tmp 2012-08-15 16:13 . 2012-08-15 16:13 0 ----a-w- c:windowsDXT6F3.tmp 2012-08-15 16:13 . 2012-08-15 16:13 0 ----a-w- c:windowsDXT6F2.tmp 2012-08-15 16:12 . 1998-10-29 13:45 306688 ----a-w- c:windowsIsUninst.exe 2012-08-08 11:12 . 2012-08-08 11:12 -------- d-----w- c:documents and settingsPetkoLocal SettingsApplication DataMozilla 2012-08-07 15:26 . 2012-08-07 15:26 -------- d-----w- c:documents and settingsPetkoLocal SettingsApplication DataIdentities 2012-08-07 15:13 . 2012-08-07 15:31 -------- d-----w- c:program filesOil Platform Simulator 2012-08-06 14:19 . 2008-04-02 13:53 212992 ----a-w- c:windowssystem32UniBoxVB12.ocx 2012-08-06 14:19 . 2008-04-02 13:53 880640 ----a-w- c:windowssystem32UniBox10.ocx 2012-08-06 14:19 . 1998-06-24 07:00 108336 ----a-w- c:windowssystem32MSWINSCK.OCX 2012-08-06 14:19 . 2008-04-02 13:54 1101824 ----a-w- c:windowssystem32UniBox210.ocx 2012-08-06 14:18 . 2012-08-25 20:04 -------- d-----w- c:program filesuGet VGI 2012-08-06 14:10 . 2012-08-06 14:10 -------- d-----w- c:windowsSun 2012-08-06 14:10 . 2012-08-06 14:10 -------- d-----w- c:documents and settingsPetkoLocal SettingsApplication DataSun 2012-08-06 14:08 . 2012-08-06 14:08 -------- d-----w- c:documents and settingsPetkoApplication DataOracle 2012-08-06 14:08 . 2012-07-05 19:06 687544 ----a-w- c:windowssystem32deployJava1.dll 2012-08-06 14:08 . 2012-07-05 19:06 772544 ----a-w- c:windowssystem32npDeployJava1.dll 2012-08-05 15:20 . 2012-08-15 09:19 426184 ----a-w- c:windowssystem32FlashPlayerApp.exe 2012-08-05 15:20 . 2012-08-15 09:19 70344 ----a-w- c:windowssystem32FlashPlayerCPLApp.cpl 2012-08-05 15:20 . 2012-08-05 15:20 -------- d-----w- c:windowssystem32Macromed 2012-08-05 14:42 . 2012-08-05 14:42 -------- d-sh--w- c:documents and settingsPetkoPrivacIE 2012-08-02 17:40 . 2012-08-02 18:27 -------- d-----w- c:documents and settingsPetkoApplication DataImgBurn 2012-08-02 17:40 . 2012-08-02 17:40 -------- d-----w- c:program filesImgBurn 2012-08-02 12:58 . 2005-05-26 12:34 2297552 ----a-w- c:windowssystem32d3dx9_26.dll 2012-08-02 12:57 . 2012-08-02 12:57 278984 ----a-w- c:windowssystem32driversatksgt.sys 2012-08-02 12:56 . 2012-08-02 12:56 25416 ----a-w- c:windowssystem32driverslirsgt.sys 2012-08-01 18:31 . 2012-08-01 18:31 -------- d-----w- c:documents and settingsPetkotemp 2012-08-01 18:31 . 2012-08-01 19:04 -------- d-----w- c:documents and settingsPetkoApplication DataTeamViewer . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-07-29 18:08 . 2012-07-29 18:08 98304 ----a-w- c:windowssystem32CmdLineExt.dll 2012-07-26 17:31 . 2012-07-25 12:06 90112 ----a-w- c:windowsDUMPcc58.tmp 2012-07-19 09:38 . 2012-07-19 09:38 113104 ----a-w- c:windowssystem32driversscdemu.sys . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun] "NvCplDaemon"="c:windowssystem32NvCpl.dll" [2005-10-17 7307264] "nwiz"="nwiz.exe" [2005-10-17 1519616] "NvMediaCenter"="c:windowssystem32NvMcTray.dll" [2005-10-17 86016] "Malwarebytes' Anti-Malware"="c:program filesMalwarebytes' Anti-Malwarembamgui.exe" [2012-07-03 462920] . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregGoogle Update] 2012-07-25 09:59 116648 ----atw- c:documents and settingsPetkoLocal SettingsApplication DataGoogleUpdateGoogleUpdate.exe . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregMalwarebytes' Anti-Malware] 2012-07-03 10:46 462920 ----a-w- c:program filesMalwarebytes' Anti-Malwarembamgui.exe . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregPWRISOVM.EXE] 2012-07-19 09:38 336992 ----a-w- c:program filesPowerISOPWRISOVM.EXE . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigservices] "SkypeUpdate"=2 (0x2) "NVSvc"=2 (0x2) "AdobeFlashPlayerUpdateSvc"=3 (0x3) "idsvc"=3 (0x3) "FLEXnet Licensing Service"=3 (0x3) "Bonjour Service"=2 (0x2) "AudioSrv"=2 (0x2) "MBAMService"=2 (0x2) . [HKLM~servicessharedaccessparametersfirewallpolicystandardprofile] "EnableFirewall"= 0 (0x0) . [HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList] "%windir%Network Diagnosticxpnetdiag.exe"= "%windir%system32sessmgr.exe"= "c:Program FilesuTorrentuTorrent.exe"= "c:Program FilesSopCastSopCast.exe"= "c:Program FilesBonjourmDNSResponder.exe"= "c:Program FilesDAUMPotPlayerPotPlayerMini.exe"= "c:Program FilesSkypePhoneSkype.exe"= . R3 MBAMProtector;MBAMProtector;c:windowssystem32driversmbam.sys [8/28/2012 9:04 PM 22344] S2 MBAMService;MBAMService;c:program filesMalwarebytes' Anti-Malwarembamservice.exe [8/28/2012 9:05 PM 655944] S3 SetupNTGLM7X;SetupNTGLM7X;??h:ntglm7x.sys --> h:NTGLM7X.sys [?] S4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:windowssystem32MacromedFlashFlashPlayerUpdateService.exe [8/5/2012 6:20 PM 250056] S4 SkypeUpdate;Skype Updater;c:program filesSkypeUpdaterUpdater.exe [6/7/2012 7:12 PM 160944] . Contents of the 'Scheduled Tasks' folder . 2012-08-29 c:windowsTasksAdobe Flash Player Updater.job - c:windowssystem32MacromedFlashFlashPlayerUpdateService.exe [2012-08-05 09:20] . 2012-08-28 c:windowsTasksGoogleUpdateTaskUserS-1-5-21-1123561945-1715567821-1801674531-1003Core.job - c:documents and settingsPetkoLocal SettingsApplication DataGoogleUpdateGoogleUpdate.exe [2012-07-25 09:59] . 2012-08-29 c:windowsTasksGoogleUpdateTaskUserS-1-5-21-1123561945-1715567821-1801674531-1003UA.job - c:documents and settingsPetkoLocal SettingsApplication DataGoogleUpdateGoogleUpdate.exe [2012-07-25 09:59] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.local TCP: DhcpNameServer = 178.254.216.1 178.254.216.2 . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2012-08-29 12:44 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'explorer.exe'(3692) c:windowssystem32ieframe.dll c:windowssystem32OneX.DLL c:windowssystem32eappprxy.dll c:windowssystem32webcheck.dll . ------------------------ Other Running Processes ------------------------ . c:windowssystem32wscntfy.exe . ************************************************************************** . Completion time: 2012-08-29 12:47:23 - machine was rebooted ComboFix-quarantined-files.txt 2012-08-29 09:47 ComboFix2.txt 2012-08-29 08:30 . Pre-Run: 9 880 870 912 bytes free Post-Run: 9 874 132 992 bytes free . - - End Of File - - B39D919FFE169D2C92AB1DD8D25CA610

Публикувано изображение Изтеглете Security Check (автор: screen317) от тук или от тук и го запишете на десктопа.

  • Кликнете два пъти върху SecurityCheck.exe и следвайте инструкциите.
  • Когато програмата завърши работата си, ще се отвори един текстов документ: checkup.txt.
  • Копирайте съдържанието на checkup.txt с Копирай (Copy) и с Постави (Paste) го поставете в следващия си коментар.

Публикувано изображение Изтеглете Malwarebytes' Anti-Malware или от тук

* Кликнете два пъти върху mbam-setup.exe, за да инсталирате програмата.

* Уверете се, че са поставени отметки на Update Malwarebytes' Anti-Malware и Launch Malwarebytes' Anti-Malware. След това кликнете на Finish.

* Ако има намерени обновявания, тя ще ги изтегли и инсталира.

* Стартирайте програмата и изберете "Perform Full Scan", след това кликнете на Scan.

* Сканирането ще отнеме малко време, затова моля да бъдете търпеливи.

* Когато сканирането завърши, кликнете на OK, след това Show Results, за да видите резултата.

* Уверете се, че на всички редове има отметки, и кликнете на Remove Selected.

* Когато всичко бъде премахнато, в Notepad ще бъде отворен лог. Копирайте този лог и го публикувайте в следващия си коментар по темата.

Забележка: Ако MalwareBytes' Anti-Malware се затрудни в премахването на откритите вируси/заплахи, той ще поиска да рестартира компютъра Ви и по време на рестартирането да премахне проблемните вируси/заплахи. Ако бъдете попитани, потвърдете че желаете вашия компютър да бъде рестартиран.

Публикувано изображение Изтеглете програмата: ESET Online Scanner

  • Стартирайте esetsmartinstaller_enu.exe Публикувано изображение
  • Сложете отметка на YES, I accept the Terms of Use и изберете Start:

    Публикувано изображение

  • Скенерът ще започне да изтегля компонентите, които са му необходими:

    Публикувано изображение

Уверете се, че е премахната отметката от:
  • Remove found threats
Уверете се че са маркирани следните позиции:
  • Scan Archives
Кликнете върху Advanced Settings и маркирайте следните опции:
  • Scan for potentially unwanted applications
  • Scan for potentially unsafe applications
  • Enable Anti-Stealth Technology
Накрая изберете Start
  • Скенерът ще започне да изтегля последните дефиниции.
  • След, като сканирането завърши изберете Finish.
  • Отидете в: C:Program FilesESETESET Online Scanner
  • Отворете файла log.txt , копирайте съдържанието му и го поставете в следващия си коментар.
  • Автор

Results of screen317's Security Check version 0.99.49

Windows XP Service Pack 3 x86

Internet Explorer 8

``````````````Antivirus/Firewall Check:``````````````

Windows Firewall Disabled!

AVG Anti-Virus Free Edition 2012

Antivirus up to date!

`````````Anti-malware/Other Utilities Check:`````````

Malwarebytes Anti-Malware version 1.62.0.1300

CCleaner

````````Process Check: objlist.exe by Laurent````````

`````````````````System Health check`````````````````

Total Fragmentation on Drive C:: 29% Defragment your hard drive soon! (Do NOT defrag if SSD!)

````````````````````End of Log``````````````````````

  • Автор

Malwarebytes Anti-Malware 1.62.0.1300 www.malwarebytes.org Database version: v2012.08.29.03 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Petko :: PETKO-0BEA8AEAA [administrator] 29.8.2012 г. 13:00:27 mbam-log-2012-08-29 (13-00-27).txt Scan type: Full scan (C:|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 224575 Time elapsed: 1 hour(s), 19 minute(s), 37 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 4 C:Documents and SettingsAll UsersApplication DataSecTaskMansmss.exe.q_Quarantine_2CF4401_q (Backdoor.Bot) -> Quarantined and deleted successfully. C:Documents and SettingsAll UsersApplication DataSecTaskManweb2net.exe.q_Quarantine_282A4600_q (Backdoor.Bot) -> Quarantined and deleted successfully. C:System Volume Information_restore{47067530-913E-4904-B72F-C3B85B81523C}RP54A0023729.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:System Volume Information_restore{47067530-913E-4904-B72F-C3B85B81523C}RP55A0023730.exe (Backdoor.Bot) -> Quarantined and deleted successfully. (end)

  • Автор

ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=90d94a23013a3e4f934087ac7de7d61d # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2012-08-29 03:54:16 # local_time=2012-08-29 06:54:16 (+0200, FLE Standard Time) # country="Bulgaria" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=8192 67108863 100 0 259 259 0 0 # scanned=55513 # found=4 # cleaned=0 # scan_time=9815 C:Documents and SettingsPetkoDesktopСтефанПрограмиCheatEngine62.exe multiple threats (unable to clean) 00000000000000000000000000000000 I C:Program FilesCheat Engine 6.2cheatengine-i386.exe a variant of Win32/HackTool.CheatEngine.AB application (unable to clean) 00000000000000000000000000000000 I C:Program FilesCheat Engine 6.2standalonephase1.dat a variant of Win32/HackTool.CheatEngine.AF application (unable to clean) 00000000000000000000000000000000 I C:System Volume Information_restore{47067530-913E-4904-B72F-C3B85B81523C}RP29A0012488.exe Win32/Bundled.Toolbar.Ask application (unable to clean) 00000000000000000000000000000000 I

Редактирано от petko93 (преглед на промените)

Копирайте текста в карето на notepad и го запазвате с име CFScript.txt на десктопа си:

KILLALL::

File::
C:System Volume Information_restore{47067530-913E-4904-B72F-C3B85B81523C}RP29A0012488.exe

След съхранението преместете CFScript.txt на иконата на ComboFix.exe

Публикувано изображение

Генерирания рапорт копирайте и го поставете в следващия си коментар...!

  • Автор

ComboFix 12-08-28.03 - Petko 08.2012 г. 19:20:06.3.1 - x86 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.447.244 [GMT 3:00] Running from: c:documents and settingsPetkoDesktopComboFix.exe Command switches used :: c:documents and settingsPetkoDesktopCFScript.txt AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF} . FILE :: "c:system volume information_restore{47067530-913E-4904-B72F-C3B85B81523C}RP29A0012488.exe" . . ((((((((((((((((((((((((( Files Created from 2012-07-28 to 2012-08-29 ))))))))))))))))))))))))))))))) . . 2012-08-29 13:06 . 2012-08-29 13:06 -------- d-----w- c:program filesESET 2012-08-28 20:47 . 2012-08-28 20:48 110100480 ----a-w- C:TESTFILE.TMP 2012-08-28 19:12 . 2012-08-28 19:12 -------- d-----w- c:documents and settingsPetkoApplication DataHD Tune Pro 2012-08-28 19:12 . 2012-08-28 19:12 -------- d-----w- c:program filesHD Tune Pro 2012-08-28 19:00 . 2012-08-28 19:00 -------- d-----w- c:windowssystem32LogFiles 2012-08-28 18:36 . 2012-08-28 18:36 -------- d-----w- c:program filesCCleaner 2012-08-28 18:05 . 2012-08-28 18:05 -------- d-----w- c:documents and settingsPetkoApplication DataMalwarebytes 2012-08-28 18:05 . 2012-08-28 18:05 -------- d-----w- c:documents and settingsAll UsersApplication DataMalwarebytes 2012-08-28 18:04 . 2012-08-28 18:05 -------- d-----w- c:program filesMalwarebytes' Anti-Malware 2012-08-28 18:04 . 2012-07-03 10:46 22344 ----a-w- c:windowssystem32driversmbam.sys 2012-08-26 19:21 . 2012-08-26 19:21 -------- d-----w- c:documents and settingsAll UsersApplication DataAlawarWrapper 2012-08-26 18:55 . 2012-08-29 11:24 -------- d-----w- c:documents and settingsAll UsersApplication DataSecTaskMan 2012-08-26 18:54 . 2012-08-26 19:12 -------- d-----w- c:program filesSecurity Task Manager 2012-08-26 18:22 . 2012-08-26 19:21 -------- d-----w- c:program filesСакра Терра. Ночь ангела. Коллекционное издание 2012-08-26 18:03 . 2012-08-26 18:03 -------- d-----w- c:documents and settingsPetkoApplication DataAlawar Entertainment 2012-08-23 10:08 . 2012-08-23 10:08 -------- d-----w- c:documents and settingsPetkoLocal SettingsApplication DataPackageAware 2012-08-22 15:34 . 2012-08-22 15:34 -------- d-----w- c:program filesCrazy Mashienes NFTL 2012-08-22 15:20 . 2012-08-22 15:20 -------- d-----w- c:documents and settingsPetkoApplication DataNatGeoGames 2012-08-22 15:20 . 2012-08-22 15:20 -------- d-----w- c:documents and settingsAll UsersApplication DataNatGeoGames 2012-08-20 12:12 . 2012-08-20 12:12 -------- d-----w- c:windowssystem32XPSViewer 2012-08-20 12:08 . 2012-08-20 12:08 -------- d-----w- c:program filesMSBuild 2012-08-20 12:04 . 2012-08-20 12:04 -------- d-----w- c:program filesReference Assemblies 2012-08-20 12:04 . 2008-07-06 12:06 89088 ----a-w- c:windowssystem32Spoolprtprocsw32x86filterpipelineprintproc.dll 2012-08-20 12:02 . 2006-08-24 13:15 150808 ----a-w- c:windowssystem32rgb9rast_2.dll 2012-08-20 11:54 . 2008-07-06 10:50 597504 -c----w- c:windowssystem32dllcacheprintfilterpipelinesvc.exe 2012-08-20 11:54 . 2008-07-06 10:50 597504 ------w- c:windowssystem32Spoolprtprocsw32x86printfilterpipelinesvc.exe 2012-08-20 11:54 . 2008-07-06 12:06 575488 -c----w- c:windowssystem32dllcachexpsshhdr.dll 2012-08-20 11:54 . 2008-07-06 12:06 575488 ------w- c:windowssystem32xpsshhdr.dll 2012-08-20 11:54 . 2008-07-06 12:06 1676288 -c----w- c:windowssystem32dllcachexpssvcs.dll 2012-08-20 11:54 . 2008-07-06 12:06 1676288 ------w- c:windowssystem32xpssvcs.dll 2012-08-20 11:53 . 2008-07-06 12:06 117760 ------w- c:windowssystem32prntvpt.dll 2012-08-20 11:53 . 2008-07-06 12:06 89088 -c----w- c:windowssystem32dllcachefilterpipelineprintproc.dll 2012-08-20 11:29 . 2012-08-22 08:12 -------- d-----w- c:program filesAllmyapps 2012-08-18 13:36 . 2012-08-18 13:36 -------- d-----w- c:program filesXviD 2012-08-18 13:30 . 2012-08-18 13:30 -------- d-----w- c:program filesURUSoft 2012-08-16 09:13 . 2012-08-16 09:13 -------- d-----w- c:documents and settingsAll UsersApplication DataCrioGames 2012-08-15 19:11 . 2012-08-15 19:11 -------- d-----w- c:documents and settingsAll UsersApplication DataFugazo 2012-08-15 16:13 . 2012-08-15 16:13 0 ----a-w- c:windowsDXT6F7.tmp 2012-08-15 16:13 . 2012-08-15 16:13 0 ----a-w- c:windowsDXT6F6.tmp 2012-08-15 16:13 . 2012-08-15 16:13 0 ----a-w- c:windowsDXT6F5.tmp 2012-08-15 16:13 . 2012-08-15 16:13 0 ----a-w- c:windowsDXT6F4.tmp 2012-08-15 16:13 . 2012-08-15 16:13 0 ----a-w- c:windowsDXT6F3.tmp 2012-08-15 16:13 . 2012-08-15 16:13 0 ----a-w- c:windowsDXT6F2.tmp 2012-08-15 16:12 . 1998-10-29 13:45 306688 ----a-w- c:windowsIsUninst.exe 2012-08-08 11:12 . 2012-08-08 11:12 -------- d-----w- c:documents and settingsPetkoLocal SettingsApplication DataMozilla 2012-08-07 15:26 . 2012-08-07 15:26 -------- d-----w- c:documents and settingsPetkoLocal SettingsApplication DataIdentities 2012-08-07 15:13 . 2012-08-07 15:31 -------- d-----w- c:program filesOil Platform Simulator 2012-08-06 14:19 . 2008-04-02 13:53 212992 ----a-w- c:windowssystem32UniBoxVB12.ocx 2012-08-06 14:19 . 2008-04-02 13:53 880640 ----a-w- c:windowssystem32UniBox10.ocx 2012-08-06 14:19 . 1998-06-24 07:00 108336 ----a-w- c:windowssystem32MSWINSCK.OCX 2012-08-06 14:19 . 2008-04-02 13:54 1101824 ----a-w- c:windowssystem32UniBox210.ocx 2012-08-06 14:18 . 2012-08-25 20:04 -------- d-----w- c:program filesuGet VGI 2012-08-06 14:10 . 2012-08-06 14:10 -------- d-----w- c:windowsSun 2012-08-06 14:10 . 2012-08-06 14:10 -------- d-----w- c:documents and settingsPetkoLocal SettingsApplication DataSun 2012-08-06 14:08 . 2012-08-06 14:08 -------- d-----w- c:documents and settingsPetkoApplication DataOracle 2012-08-06 14:08 . 2012-07-05 19:06 687544 ----a-w- c:windowssystem32deployJava1.dll 2012-08-06 14:08 . 2012-07-05 19:06 772544 ----a-w- c:windowssystem32npDeployJava1.dll 2012-08-05 15:20 . 2012-08-15 09:19 426184 ----a-w- c:windowssystem32FlashPlayerApp.exe 2012-08-05 15:20 . 2012-08-15 09:19 70344 ----a-w- c:windowssystem32FlashPlayerCPLApp.cpl 2012-08-05 15:20 . 2012-08-05 15:20 -------- d-----w- c:windowssystem32Macromed 2012-08-05 14:42 . 2012-08-05 14:42 -------- d-sh--w- c:documents and settingsPetkoPrivacIE 2012-08-02 17:40 . 2012-08-02 18:27 -------- d-----w- c:documents and settingsPetkoApplication DataImgBurn 2012-08-02 17:40 . 2012-08-02 17:40 -------- d-----w- c:program filesImgBurn 2012-08-02 12:58 . 2005-05-26 12:34 2297552 ----a-w- c:windowssystem32d3dx9_26.dll 2012-08-02 12:57 . 2012-08-02 12:57 278984 ----a-w- c:windowssystem32driversatksgt.sys 2012-08-02 12:56 . 2012-08-02 12:56 25416 ----a-w- c:windowssystem32driverslirsgt.sys 2012-08-01 18:31 . 2012-08-01 18:31 -------- d-----w- c:documents and settingsPetkotemp 2012-08-01 18:31 . 2012-08-01 19:04 -------- d-----w- c:documents and settingsPetkoApplication DataTeamViewer . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-07-29 18:08 . 2012-07-29 18:08 98304 ----a-w- c:windowssystem32CmdLineExt.dll 2012-07-26 17:31 . 2012-07-25 12:06 90112 ----a-w- c:windowsDUMPcc58.tmp 2012-07-19 09:38 . 2012-07-19 09:38 113104 ----a-w- c:windowssystem32driversscdemu.sys . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun] "NvCplDaemon"="c:windowssystem32NvCpl.dll" [2005-10-17 7307264] "nwiz"="nwiz.exe" [2005-10-17 1519616] "NvMediaCenter"="c:windowssystem32NvMcTray.dll" [2005-10-17 86016] "Malwarebytes' Anti-Malware"="c:program filesMalwarebytes' Anti-Malwarembamgui.exe" [2012-07-03 462920] . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregGoogle Update] 2012-07-25 09:59 116648 ----atw- c:documents and settingsPetkoLocal SettingsApplication DataGoogleUpdateGoogleUpdate.exe . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregMalwarebytes' Anti-Malware] 2012-07-03 10:46 462920 ----a-w- c:program filesMalwarebytes' Anti-Malwarembamgui.exe . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregPWRISOVM.EXE] 2012-07-19 09:38 336992 ----a-w- c:program filesPowerISOPWRISOVM.EXE . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigservices] "SkypeUpdate"=2 (0x2) "NVSvc"=2 (0x2) "AdobeFlashPlayerUpdateSvc"=3 (0x3) "idsvc"=3 (0x3) "FLEXnet Licensing Service"=3 (0x3) "Bonjour Service"=2 (0x2) "AudioSrv"=2 (0x2) "MBAMService"=2 (0x2) . [HKLM~servicessharedaccessparametersfirewallpolicystandardprofile] "EnableFirewall"= 0 (0x0) . [HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList] "%windir%Network Diagnosticxpnetdiag.exe"= "%windir%system32sessmgr.exe"= "c:Program FilesuTorrentuTorrent.exe"= "c:Program FilesSopCastSopCast.exe"= "c:Program FilesBonjourmDNSResponder.exe"= "c:Program FilesDAUMPotPlayerPotPlayerMini.exe"= "c:Program FilesSkypePhoneSkype.exe"= . R3 MBAMProtector;MBAMProtector;c:windowssystem32driversmbam.sys [8/28/2012 9:04 PM 22344] S2 MBAMService;MBAMService;c:program filesMalwarebytes' Anti-Malwarembamservice.exe [8/28/2012 9:05 PM 655944] S3 SetupNTGLM7X;SetupNTGLM7X;??h:ntglm7x.sys --> h:NTGLM7X.sys [?] S4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:windowssystem32MacromedFlashFlashPlayerUpdateService.exe [8/5/2012 6:20 PM 250056] S4 SkypeUpdate;Skype Updater;c:program filesSkypeUpdaterUpdater.exe [6/7/2012 7:12 PM 160944] . Contents of the 'Scheduled Tasks' folder . 2012-08-29 c:windowsTasksAdobe Flash Player Updater.job - c:windowssystem32MacromedFlashFlashPlayerUpdateService.exe [2012-08-05 09:20] . 2012-08-29 c:windowsTasksGoogleUpdateTaskUserS-1-5-21-1123561945-1715567821-1801674531-1003Core.job - c:documents and settingsPetkoLocal SettingsApplication DataGoogleUpdateGoogleUpdate.exe [2012-07-25 09:59] . 2012-08-29 c:windowsTasksGoogleUpdateTaskUserS-1-5-21-1123561945-1715567821-1801674531-1003UA.job - c:documents and settingsPetkoLocal SettingsApplication DataGoogleUpdateGoogleUpdate.exe [2012-07-25 09:59] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.local TCP: DhcpNameServer = 178.254.216.1 178.254.216.2 . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2012-08-29 19:30 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'explorer.exe'(1444) c:windowssystem32ieframe.dll c:windowssystem32OneX.DLL c:windowssystem32eappprxy.dll c:windowssystem32webcheck.dll . ------------------------ Other Running Processes ------------------------ . c:windowssystem32wscntfy.exe . ************************************************************************** . Completion time: 2012-08-29 19:33:19 - machine was rebooted ComboFix-quarantined-files.txt 2012-08-29 16:33 ComboFix2.txt 2012-08-29 09:47 ComboFix3.txt 2012-08-29 08:30 . Pre-Run: 9 660 669 952 bytes free Post-Run: 9 653 739 520 bytes free . - - End Of File - - 8D7DA576A3DC56325BB4CB04AB85FEAE

  • Автор

Не знам точно,но забелязвам леки подобрения в стартирането на системата.Обаче има един проблем със курсора на мишката като я плъзгам и на моменти забавя движението си сякаш засича.Може би проблема със вирусите е оправен така ,че считай тази тема за решена.Имам само един въпрос.В момента нямам никаква антивирусна програма, бихте ли ми препоръчали някоя антивирусна за компютър 512 РАМ, AMD sempron 2800+ , 1,6 Гхц. видео карта 256мб.Мерси много!

Защо..в логовете се вижда че AVG Anti-Virus Free Edition 2012 е активна....!

Деинсталирайте Комбофикс така:

1.Натиснете Start ==> Run ==> въведете командата Combofix /Uninstall ==> OK

Публикувано изображение

2.Изтеглете Публикувано изображениеOTCleanIt или от тук,стартирайте и натиснете Публикувано изображение

Изтрийте всички генерирани логове, програмки и фиксове,които използвахме в процедурата.Деинсталирайте ESET Online Scaner.

  • Автор

Странно.Аз я премахнах от добавяне премахване на програми.Как така още е активна?А и не ми отговори на въпроса.Дай съвет за някаква защита от вируси

За да я деинсталирате напълно използвайте AVG Remover

Относно въпроса ви....в раздела Сигурност и антивирусна защита има достатъчно добри и безплатни варианти.Въпрос на личен избор е..!

Лека вечер и безопасен интернет...!:)

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.