Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Проблем с процесора.

Featured Replies

Здравейте.Стана вече няколко месеца процесора ми става на 100 %,това ми пречи в игри,клипове и т.н. Гледам да намаля процесите до колкото се може по малко,но полза няма. Сканирах компютъра с антивирусната,изчистих повечето програми и т,н пак файда няма.. Attach: . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-09-30.01) . Microsoft Windows XP Professional Boot Device: DeviceHarddiskVolume1 Install Date: 26.3.2012 г. 14:32:31 System Uptime: 31.10.2012 г. 18:19:35 (4 hours ago) . Motherboard: MICRO-STAR INTERNATIONAL CO., LTD | | MS-7312 Processor: AMD Sempron Processor 3000+ | Socket AM2 | 1599/200mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 39 GiB total, 17,69 GiB free. D: is FIXED (NTFS) - 194 GiB total, 159,46 GiB free. E: is CDROM () F: is CDROM () . ==== Disabled Device Manager Items ============= . Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318} Description: WAN Miniport (IPX) Device ID: ROOTMS_NDISWANIPX0001 Manufacturer: Microsoft Name: WAN Miniport (IPX) #2 PNP Device ID: ROOTMS_NDISWANIPX0001 Service: NdisWan . Class GUID: {EEC5AD98-8080-425F-922A-DABF3DE3F69A} Description: Nokia 2700 classic Device ID: ROOTWPD0000 Manufacturer: Nokia Name: Nokia 2700 classic PNP Device ID: ROOTWPD0000 Service: WUDFRd . ==== System Restore Points =================== . RP80: 11.10.2012 г. 23:10:41 - Контролна точка на системата RP81: 14.10.2012 г. 09:50:06 - Контролна точка на системата RP82: 16.10.2012 г. 22:17:26 - Контролна точка на системата RP83: 01.1.2006 г. 01:44:38 - Контролна точка на системата RP84: 18.10.2012 г. 20:19:57 - Контролна точка на системата RP85: 20.10.2012 г. 19:00:22 - Контролна точка на системата RP86: 23.10.2012 г. 18:57:31 - Контролна точка на системата RP87: 25.10.2012 г. 10:04:34 - Installed Java 6 Update 37 RP88: 27.10.2012 г. 10:16:39 - Removed Apple Software Update RP89: 27.10.2012 г. 10:22:57 - Removed GTA San Andreas RP90: 27.10.2012 г. 10:25:21 - Removed IMinent Toolbar RP91: 27.10.2012 г. 11:35:45 - Removed The Sims 3 RP92: 27.10.2012 г. 11:36:58 - Removed Tony Hawks Pro Skater 4 RP93: 28.10.2012 г. 19:34:47 - Контролна точка на системата RP94: 30.10.2012 г. 07:24:55 - Контролна точка на системата RP95: 31.10.2012 г. 10:13:40 - Контролна точка на системата . ==== Installed Programs ====================== . µTorrent Пакет за езиков интерфейс на Windows 50 FREE MP3s +1 Free Audiobook! 7-Zip 9.20 Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin Adobe Reader 9.5.2 - Bulgarian AIMP3 aTube Catcher avast! Free Antivirus AVG Security Toolbar Bulgarian (Phonetic) - Custom Bulgarian (Phonetic) by Iliya Dankov CCleaner Cheat Engine 6.1 Counter-Strike 1.0 Counter-Strike Non-Steam Cumulative Patch 24 DAEMON Tools Lite DiRT 3 Download Updater (AOL LLC) Euro Truck Simulator 2 EVEREST Ultimate Edition v5.50 FIFA 07 FormatFactory 2.95 GameRanger GOM Player Google Chrome Google Update Helper Hotfix for Windows XP (KB942288-v3) Java Auto Updater Java 6 Update 37 K-Lite Codec Pack 8.7.0 (Full) McAfee Security Scan Plus Microsoft .NET Framework 2.0 Service Pack 1 Microsoft .NET Framework 3.0 Service Pack 1 Microsoft .NET Framework 3.5 Microsoft .NET Framework 4 Client Profile Microsoft .NET Framework 4 Extended Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 Microsoft National Language Support Downlevel APIs Microsoft Office Professional Edition 2003 Microsoft User-Mode Driver Framework Feature Pack 1.9 Microsoft VC9 runtime libraries Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 Microsoft WSE 3.0 Runtime Mozilla Firefox (3.6) Mp3 Knife 3.2 MSVC90_x86 MSVCRT Redists MSXML 6.0 Parser (KB925673) Nero 6 Ultra Edition Nokia Connectivity Cable Driver Nokia PC Suite NVIDIA Display Control Panel NVIDIA Drivers NVIDIA PhysX OpenAL PC Connectivity Solution Recuva rgcAudio z3ta Plus v1.40 Shareaza Skype Click to Call Skype™ 5.10 SmartSound Quicktracks Plugin SVD System Requirements Lab CYRI The KMPlayer (remove only) Tunatic Unlocker 1.9.1 Vegas Pro 9.0 VIA Rhine-Family Fast-Ethernet Adapter VideoLAN VLC media player 0.8.6i vloader-bg Web Assistant 2.0.0.485 Web Optimizer WebFldrs XP Winamp Winamp Detector Plug-in Winamp Remote Winamp Toolbar Wincore MediaBar Windows Driver Package - Nokia Modem (02/25/2011 4.7) Windows Driver Package - Nokia Modem (02/25/2011 7.01.0.9) Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0) Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray Windows Media Format 11 runtime Windows Media Player Firefox Plugin Windows Presentation Foundation WinRAR archiver WM Recorder WRC 2 FIA World Rally Championship XML Paper Specification Shared Components Pack 1.0 YourFileDownloader YTD Video Downloader 3.9.3 . ==== Event Viewer Messages From Past Week ======== . 27.10.2012 г. 23:02:07, error: Service Control Manager [7034] - The vToolbarUpdater12.2.6 service terminated unexpectedly. It has done this 1 time(s). 27.10.2012 г. 23:01:58, error: Service Control Manager [7034] - The BlueSoleilCS service terminated unexpectedly. It has done this 1 time(s). 27.10.2012 г. 23:01:54, error: Service Control Manager [7034] - The BsHelpCS service terminated unexpectedly. It has done this 1 time(s). 27.10.2012 г. 23:01:50, error: Service Control Manager [7034] - The Web Assistant Updater service terminated unexpectedly. It has done this 1 time(s). 27.10.2012 г. 23:01:47, error: Service Control Manager [7034] - The BsMobileCS service terminated unexpectedly. It has done this 1 time(s). 27.10.2012 г. 12:29:04, error: Service Control Manager [7034] - The BlueSoleilCS service terminated unexpectedly. It has done this 1 time(s). 27.10.2012 г. 12:29:01, error: Service Control Manager [7034] - The BsMobileCS service terminated unexpectedly. It has done this 1 time(s). 27.10.2012 г. 12:28:54, error: Service Control Manager [7034] - The BsHelpCS service terminated unexpectedly. It has done this 1 time(s). 27.10.2012 г. 12:28:50, error: Service Control Manager [7034] - The vToolbarUpdater12.2.6 service terminated unexpectedly. It has done this 1 time(s). 27.10.2012 г. 12:28:47, error: Service Control Manager [7034] - The Web Assistant Updater service terminated unexpectedly. It has done this 1 time(s). 27.10.2012 г. 09:55:39, error: Service Control Manager [7031] - The WebOptimizer service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service. 27.10.2012 г. 09:52:55, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s). 27.10.2012 г. 09:52:49, error: Service Control Manager [7034] - The BsMobileCS service terminated unexpectedly. It has done this 1 time(s). 27.10.2012 г. 09:52:47, error: Service Control Manager [7034] - The BlueSoleilCS service terminated unexpectedly. It has done this 1 time(s). 27.10.2012 г. 09:52:45, error: Service Control Manager [7034] - The WebClient service terminated unexpectedly. It has done this 1 time(s). 27.10.2012 г. 09:52:45, error: Service Control Manager [7034] - The TCP/IP NetBIOS Helper service terminated unexpectedly. It has done this 1 time(s). 27.10.2012 г. 09:52:45, error: Service Control Manager [7034] - The SSDP Discovery Service service terminated unexpectedly. It has done this 1 time(s). 27.10.2012 г. 09:52:45, error: Service Control Manager [7031] - The Remote Registry service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service. 27.10.2012 г. 09:52:41, error: Service Control Manager [7034] - The Skype C2C Service service terminated unexpectedly. It has done this 1 time(s). 27.10.2012 г. 09:52:30, error: Service Control Manager [7034] - The Web Assistant Updater service terminated unexpectedly. It has done this 1 time(s). 27.10.2012 г. 09:52:28, error: Service Control Manager [7034] - The vToolbarUpdater12.2.6 service terminated unexpectedly. It has done this 1 time(s). 27.10.2012 г. 09:52:25, error: Service Control Manager [7034] - The BsHelpCS service terminated unexpectedly. It has done this 1 time(s). 26.10.2012 г. 20:23:27, error: Service Control Manager [7031] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 26.10.2012 г. 20:23:18, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s). 26.10.2012 г. 20:23:14, error: Service Control Manager [7034] - The BlueSoleilCS service terminated unexpectedly. It has done this 1 time(s). 26.10.2012 г. 20:23:12, error: Service Control Manager [7034] - The WebClient service terminated unexpectedly. It has done this 1 time(s). 26.10.2012 г. 20:23:12, error: Service Control Manager [7034] - The TCP/IP NetBIOS Helper service terminated unexpectedly. It has done this 1 time(s). 26.10.2012 г. 20:23:12, error: Service Control Manager [7034] - The SSDP Discovery Service service terminated unexpectedly. It has done this 1 time(s). 26.10.2012 г. 20:23:12, error: Service Control Manager [7031] - The Remote Registry service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service. 26.10.2012 г. 20:23:10, error: Service Control Manager [7034] - The BsMobileCS service terminated unexpectedly. It has done this 1 time(s). 26.10.2012 г. 20:23:04, error: Service Control Manager [7034] - The Skype C2C Service service terminated unexpectedly. It has done this 1 time(s). 26.10.2012 г. 20:23:02, error: Service Control Manager [7034] - The BsHelpCS service terminated unexpectedly. It has done this 1 time(s). 26.10.2012 г. 10:19:53, error: Service Control Manager [7034] - The Skype C2C Service service terminated unexpectedly. It has done this 1 time(s). 26.10.2012 г. 10:19:38, error: Service Control Manager [7034] - The BsMobileCS service terminated unexpectedly. It has done this 1 time(s). 26.10.2012 г. 10:19:27, error: Service Control Manager [7034] - The BlueSoleilCS service terminated unexpectedly. It has done this 1 time(s). 26.10.2012 г. 10:19:23, error: Service Control Manager [7034] - The Web Assistant Updater service terminated unexpectedly. It has done this 1 time(s). 26.10.2012 г. 10:19:21, error: Service Control Manager [7034] - The vToolbarUpdater12.2.6 service terminated unexpectedly. It has done this 1 time(s). 26.10.2012 г. 10:19:18, error: Service Control Manager [7034] - The BsHelpCS service terminated unexpectedly. It has done this 1 time(s). 26.10.2012 г. 10:19:13, error: Service Control Manager [7031] - The WebOptimizer service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service. 25.10.2012 г. 21:47:28, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s). 25.10.2012 г. 21:47:21, error: Service Control Manager [7034] - The BsMobileCS service terminated unexpectedly. It has done this 1 time(s). 25.10.2012 г. 21:47:13, error: Service Control Manager [7034] - The BsHelpCS service terminated unexpectedly. It has done this 1 time(s). 25.10.2012 г. 18:34:43, error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Management Instrumentation service, but this action failed with the following error: An instance of the service is already running. . ==== End Of File =========================== DDS: DDS (Ver_2011-09-30.01) - NTFS_x86 Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_37 Run by XP at 22:05:26 on 2012-10-31 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.2046.856 [GMT 2:00] . AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D} . ============== Running Processes ================ . C:WINDOWSsystem32nvsvc32.exe C:Program FilesAVAST SoftwareAvastAvastSvc.exe C:WINDOWSsystem32spoolsv.exe C:Program FilesIVT CorporationBlueSoleilBlueSoleilCS.exe C:Program FilesIVT CorporationBlueSoleilBsMobileCS.exe C:Program FilesGoogleUpdateGoogleUpdate.exe C:Program FilesJavajre6binjqs.exe C:Documents and SettingsAll UsersApplication DataSkypeToolbarsSkype C2C Servicec2c_service.exe C:WINDOWSExplorer.EXE C:Program FilesCommon FilesAVG Secure SearchvToolbarUpdater12.2.6ToolbarUpdater.exe C:Program FilesWeb AssistantExtensionUpdaterService.exe C:WINDOWSsystem32dmwu.exe C:Program FilesIVT CorporationBlueSoleilBsHelpCS.exe C:WINDOWSsystem32wbemwmiprvse.exe C:WINDOWSSystem32alg.exe C:Program FilesAVAST SoftwareAvastavastUI.exe C:WINDOWSsystem32RunDLL32.exe C:WINDOWSsystem32ctfmon.exe C:Program FilesGoogleChromeApplicationchrome.exe C:Program FilesGoogleChromeApplicationchrome.exe C:Program FilesGoogleChromeApplicationchrome.exe C:Program FilesGoogleChromeApplicationchrome.exe C:Program FilesGoogleChromeApplicationchrome.exe C:Program FilesSkypePhoneSkype.exe C:Program FilesGoogleChromeApplicationchrome.exe C:Program FilesGoogleChromeApplicationchrome.exe C:Program FilesGoogleChromeApplicationchrome.exe C:Program FilesGoogleChromeApplicationchrome.exe C:WINDOWSSystem32svchost.exe -k netsvcs C:WINDOWSsystem32svchost.exe -k WudfServiceGroup C:WINDOWSsystem32svchost.exe -k NetworkService C:WINDOWSsystem32svchost.exe -k LocalService C:WINDOWSsystem32svchost.exe -k imgsvc . ============== Pseudo HJT Report =============== . uStart Page = hxxp://isearch.avg.com/?cid={3AC615C6-7879-4254-B1A2-35D4BF2C4A46}&mid=11374672b22147d0b44bd1509d2034b9-06ce4fc639803a2e3563922518183d8e94088cb9&lang=en&ds=gm011&pr=sa&d=2012-04-01 20:47:44&v=11.1.0.12&sap=hp mDefault_Search_URL = hxxp://www.google.com/ie uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s uURLSearchHooks: Winamp Toolbar Search Class: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - c:program fileswinamp toolbarwinamptb.dll mURLSearchHooks: Winamp Toolbar Search Class: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - c:program fileswinamp toolbarwinamptb.dll BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:program filescommon filesadobeacrobatactivexAcroIEHelperShim.dll BHO: Winamp Toolbar Loader: {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - c:program fileswinamp toolbarwinamptb.dll BHO: Web Assistant: {336D0C35-8A85-403a-B9D2-65C292C39087} - c:program filesweb assistantExtension32.dll BHO: DataMngr: {64E2F96A-4FE4-4aa8-90B0-2A929AB6AA88} - c:program filesshareaza applicationsmediabardatamngrBrowserConnection.dll BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:program filesjavajre6binssv.dll BHO: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - c:program filesavg secure search12.2.5.32AVG Secure Search_toolbar.dll BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - c:program filesskypetoolbarsinternet explorerskypeieplugin.dll BHO: Wincore MediaBar: {d48c9ead-f59f-4dea-ac97-7065fea79f42} - c:program filesshareaza applicationsmediabardatamngrtoolbarmediabarshX.dll BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:program filesjavajre6binjp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - c:program filesjavajre6libdeployjqsiejqs_plugin.dll TB: <No Name>: {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - LocalServer32 - <no file> TB: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - c:program filesavg secure search12.2.5.32AVG Secure Search_toolbar.dll TB: Wincore MediaBar: {d48c9ead-f59f-4dea-ac97-7065fea79f42} - c:program filesshareaza applicationsmediabardatamngrtoolbarmediabarshX.dll TB: Winamp Toolbar: {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - c:program fileswinamp toolbarwinamptb.dll uRun: [ctfmon.exe] c:windowssystem32ctfmon.exe uRun: [skype] "c:program filesskypephoneSkype.exe" /minimized /regrun uRun: [Orb] "c:program fileswinamp remotebinOrbTray.exe" /background mRun: [NeroFilterCheck] c:windowssystem32NeroCheck.exe mRun: [avast] "c:program filesavast softwareavastavastUI.exe" /nogui mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login mRun: [NvCplDaemon] RUNDLL32.EXE c:windowssystem32NvCpl.dll,NvStartup mRun: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent dRun: [CTFMON.EXE] c:windowssystem32CTFMON.EXE uPolicies-Explorer: NoDriveTypeAutoRun = dword:145 mPolicies-Explorer: NoDriveTypeAutoRun = dword:145 IE: E&xport to Microsoft Excel - c:progra~1micros~2office11EXCEL.EXE/3000 IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:program filesskypetoolbarsinternet explorerskypeieplugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%Network Diagnosticxpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:program filesmessengermsmsgs.exe DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab TCP: NameServer = 89.215.233.2 89.215.246.40 TCP: Interfaces{3032D039-1931-4EFF-8696-378E7F48A216} : DHCPNameServer = 89.215.233.2 89.215.246.40 Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:program filesskypetoolbarsinternet explorerskypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:program filescommon filesskypeSkype4COM.dll Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:program filescommon filesavg secure searchviprotocolinstaller12.2.6ViProtocol.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:windowssystem32WPDShServiceObj.dll LSA: Authentication Packages = msv1_0 nwprovau IFEO: epplauncher.exe - CMD /C>null IFEO: MsMpEng.exe - CMD /C>null IFEO: msseces.exe - CMD /C>null . ================= FIREFOX =================== . FF - ProfilePath - c:documents and settingsxpapplication datamozillafirefoxprofiles1dg72ijs.default FF - prefs.js: browser.search.defaulturl - hxxp://search.winamp.com/search/search?query={searchTerms}&invocationType=tb50-ff-winamp-chromesbox-en-us&tb_uuid=20121030124040296&tb_oid=31-10-2012&tb_mrud=31-10-2012&query= FF - prefs.js: browser.startup.homepage - hxxp://bg.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:bg:official FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/redirector/sredir?sredir=2685&invocationType=tb50-ff-winamp-ab-en-us&tb_uuid=20121030124040296&tb_oid=31-10-2012&tb_mrud=31-10-2012&query= FF - component: c:documents and settingsxpapplication datamozillafirefoxprofiles1dg72ijs.defaultextensions{0b38152b-1b20-484d-a11f-5e04a9b0661f}componentsMailUtil.dll FF - component: c:documents and settingsxpapplication datamozillafirefoxprofiles1dg72ijs.defaultextensions{0b38152b-1b20-484d-a11f-5e04a9b0661f}componentsWinampPlayer.dll FF - component: c:documents and settingsxpapplication datamozillafirefoxprofiles1dg72ijs.defaultextensions{d48c9ead-f59f-4dea-ac97-7065fea79f42}componentsdtTransparency.dll FF - component: c:documents and settingsxpapplication datamozillafirefoxprofiles1dg72ijs.defaultextensions{d48c9ead-f59f-4dea-ac97-7065fea79f42}componentsdtTransparency3.5.dll FF - component: c:documents and settingsxpapplication datamozillafirefoxprofiles1dg72ijs.defaultextensions{d48c9ead-f59f-4dea-ac97-7065fea79f42}componentsdtTransparency3.6.dll FF - component: c:program filesmozilla firefoxextensions{82af8dca-6de9-405d-bd5e-43525bdad38a}componentsSkypeFfComponent.dll FF - component: c:program filesshareaza applicationsmediabardatamngrfirefoxextensioncomponentsDataMngrHlpFF3.dll FF - plugin: c:program filesadobereader 9.0readerairnppdf32.dll FF - plugin: c:program filescommon filesavg secure searchsitesafetyinstaller12.2.6npsitesafety.dll FF - plugin: c:program filesgoogleupdate1.3.21.111npGoogleUpdate3.dll FF - plugin: c:program filesgoogleupdate1.3.21.115npGoogleUpdate3.dll FF - plugin: c:program filesgoogleupdate1.3.21.123npGoogleUpdate3.dll FF - plugin: c:program filesjavajre6binnpjpi160_37.dll FF - plugin: c:program filesjavajre6binplugin2npdeployJava1.dll FF - plugin: c:program filesjavajre6binplugin2npjp2.dll FF - plugin: c:program filesmozilla firefoxpluginsnpdnu.dll FF - plugin: c:program filesmozilla firefoxpluginsnpdnupdater2.dll FF - plugin: c:program filesmozilla firefoxpluginsnpwachk.dll FF - plugin: c:windowssystem32macromedflashNPSWF32_11_4_402_287.dll FF - plugin: c:windowssystem32npdeployJava1.dll FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:program filesmozilla firefoxextensions{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} - c:program filesmozilla firefoxextensions{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} - c:program filesmozilla firefoxextensions{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} - c:program filesmozilla firefoxextensions{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} FF - Ext: Skype Click to Call: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} - c:program filesmozilla firefoxextensions{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF - Ext: WincoreMediaBar: {d48c9ead-f59f-4dea-ac97-7065fea79f42} - %profile%extensions{d48c9ead-f59f-4dea-ac97-7065fea79f42} FF - Ext: Winamp Toolbar: {0b38152b-1b20-484d-a11f-5e04a9b0661f} - %profile%extensions{0b38152b-1b20-484d-a11f-5e04a9b0661f} FF - Ext: avast! WebRep: [email protected] - c:program filesavast softwareavastwebrepFF FF - Ext: Web Assistant: {336D0C35-8A85-403a-B9D2-65C292C39087} - c:program filesweb assistantFirefox FF - Ext: Java Quick Starter: [email protected] - c:program filesjavajre6libdeployjqsff . ---- FIREFOX POLICIES ---- FF - user.js: extensions.incredibar_i.newTab - false FF - user.js: extensions.incredibar_i.tlbrSrchUrl - hxxp://mystart.Incredibar.com/?a=6OyLPwp7C3&loc=IB_TB&i=26&search= FF - user.js: extensions.incredibar_i.id - 30407c1a00000000000000158315a310 FF - user.js: extensions.incredibar_i.instlDay - 15574 FF - user.js: extensions.incredibar_i.vrsn - 1.5.11.14 FF - user.js: extensions.incredibar_i.vrsni - 1.5.11.14 FF - user.js: extensions.incredibar_i.vrsnTs - 1.5.11.1422:19:43 FF - user.js: extensions.incredibar_i.prtnrId - Incredibar FF - user.js: extensions.incredibar_i.prdct - incredibar FF - user.js: extensions.incredibar_i.aflt - orgnl FF - user.js: extensions.incredibar_i.smplGrp - none FF - user.js: extensions.incredibar_i.tlbrId - base FF - user.js: extensions.incredibar_i.instlRef - FF - user.js: extensions.incredibar_i.dfltLng - FF - user.js: extensions.incredibar_i.excTlbr - false FF - user.js: extensions.incredibar_i.ms_url_id - FF - user.js: extensions.incredibar_i.upn2 - 6OyLPwp7C3 FF - user.js: extensions.incredibar_i.upn2n - 92261976266114283 FF - user.js: extensions.incredibar_i.productid - 26 FF - user.js: extensions.incredibar_i.installerproductid - 26 FF - user.js: extensions.incredibar_i.did - 10650 FF - user.js: extensions.incredibar_i.ppd - 21%5F5 FF - user.js: network.protocol-handler.warn-external.dnupdate - false ============= SERVICES / DRIVERS =============== . R0 BtHidBus;Bluetooth HID Bus Service;c:windowssystem32driversBtHidBus.sys [2009-1-7 20744] R1 aswSnx;aswSnx;c:windowssystem32driversaswSnx.sys [2012-3-26 435032] R1 aswSP;aswSP;c:windowssystem32driversaswSP.sys [2012-3-26 314456] R1 avgtp;avgtp;c:windowssystem32driversavgtpx86.sys [2012-9-3 27496] R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:windowssystem32driversdtsoftbus01.sys [2012-3-28 242240] R2 aswFsBlk;aswFsBlk;c:windowssystem32driversaswFsBlk.sys [2012-3-26 20568] R2 avast! Antivirus;avast! Antivirus;c:program filesavast softwareavastAvastSvc.exe [2012-3-26 44768] R2 BsMobileCS;BsMobileCS;c:program filesivt corporationbluesoleilBsMobileCS.exe [2009-2-27 143467] R2 Skype C2C Service;Skype C2C Service;c:documents and settingsall usersapplication dataskypetoolbarsskype c2c servicec2c_service.exe [2012-10-2 3064000] R2 vToolbarUpdater12.2.6;vToolbarUpdater12.2.6;c:program filescommon filesavg secure searchvtoolbarupdater12.2.6ToolbarUpdater.exe [2012-9-3 722528] R2 Web Assistant Updater;Web Assistant Updater;c:program filesweb assistantExtensionUpdaterService.exe [2012-8-22 188760] R2 WebOptimizer;WebOptimizer;c:windowssystem32dmwu.exe [2012-9-12 1006448] R3 als4k;Avance Audio Miniport Driver (WDM);c:windowssystem32driversals4000.sys [2012-3-26 28919] R3 btnetBUs;Bluetooth PAN Bus Service;c:windowssystem32driversbtnetBus.sys [2008-12-7 30088] R3 IvtBtBUs;IVT Bluetooth Bus Service;c:windowssystem32driversIvtBtBus.sys [2008-7-2 26248] R3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);c:windowssystem32driversvcsvad.sys [2012-10-14 17792] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:windowsmicrosoft.netframeworkv4.0.30319mscorsvw.exe [2010-3-18 130384] S2 gupdate;Услуга на Google Актуализация (gupdate);c:program filesgoogleupdateGoogleUpdate.exe [2012-3-26 136176] S2 SkypeUpdate;Skype Updater;c:program filesskypeupdaterUpdater.exe [2012-7-13 160944] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:windowssystem32macromedflashFlashPlayerUpdateService.exe [2012-4-9 250808] S3 gupdatem;Услуга на Google Актуализация (gupdatem);c:program filesgoogleupdateGoogleUpdate.exe [2012-3-26 136176] S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:windowssystem32driverstap0901t.sys [2012-7-29 27136] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:windowsmicrosoft.netframeworkv4.0.30319wpfWPFFontCache_v0400.exe [2010-3-18 753504] S4 McComponentHostService;McAfee Security Scan Component Host Service;c:program filesmcafee security scan3.0.207McCHSvc.exe [2011-6-17 237008] S4 xqkim;Microsoft Driver;c:windowssystem32svchost.exe -k netsvcs [2008-4-14 14336] . =============== Created Last 30 ================ . 2012-10-30 12:41:00 -------- d-----w- c:program filesWinamp Detect 2012-10-30 12:40:50 -------- d-----w- c:program filesWinamp Toolbar 2012-10-30 12:40:50 -------- d-----w- c:documents and settingsall usersapplication dataWinamp Toolbar 2012-10-30 12:40:41 -------- d-----w- c:program filescommon filesSoftware Update Utility 2012-10-30 12:40:29 -------- d-----w- c:documents and settingsall usersapplication dataOrbNetworks 2012-10-30 12:40:21 -------- d-----w- c:program filesWinamp Remote 2012-10-30 05:01:46 -------- d-----w- c:program filesUnlocker 2012-10-27 17:22:59 -------- d-----w- c:documents and settingsxpapplication dataOnLive App 2012-10-14 15:52:40 17792 ----a-w- c:windowssystem32driversvcsvad.sys 2012-10-05 09:35:38 -------- d-----w- c:documents and settingsall usersapplication dataYTD Video Downloader 2012-10-05 09:35:31 -------- d-----w- c:program filesGreenTree Applications 2012-10-04 16:53:33 -------- d-----w- c:program filesCCleaner 2012-10-02 10:17:58 5171904 ----a-w- c:program filesmozilla firefoxextensions{82af8dca-6de9-405d-bd5e-43525bdad38a}componentsSkypeFfComponent.dll . ==================== Find3M ==================== . 2012-10-09 09:22:23 73656 ----a-w- c:windowssystem32FlashPlayerCPLApp.cpl 2012-10-09 09:22:23 696760 ----a-w- c:windowssystem32FlashPlayerApp.exe 2012-09-24 12:32:24 477168 ----a-w- c:windowssystem32npdeployJava1.dll 2012-09-24 12:32:20 473072 ----a-w- c:windowssystem32deployJava1.dll 2012-09-24 10:51:47 73728 ----a-w- c:windowssystem32javacpl.cpl 2012-09-20 18:24:25 260748 ----a-w- c:windowssystem32nvdrsdb0.bin 2012-09-20 18:24:25 1 ----a-w- c:windowssystem32nvdrssel.bin 2012-09-20 18:23:28 260740 ----a-w- c:windowssystem32nvdrsdb1.bin 2012-09-13 13:26:52 1006448 ----a-w- c:windowssystem32dmwu.exe 2012-09-13 13:24:48 28160 ----a-w- c:windowssystem32ImHttpComm.dll 2012-09-03 20:25:35 27496 ----a-w- c:windowssystem32driversavgtpx86.sys 2012-08-10 19:48:49 444952 ----a-w- c:windowssystem32wrap_oal.dll 2012-08-10 19:48:49 109080 ----a-w- c:windowssystem32OpenAL32.dll 2012-08-03 16:02:23 720896 ----a-w- c:windowsiun6002.exe . =================== ROOTKIT ==================== . Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net Windows 5.1.2600 . CreateFile(".PHYSICALDRIVE0"): The process cannot access the file because it is being used by another process. device: opened successfully user: error reading MBR . Disk trace: called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll prosync1.sys SCSIPORT.SYS viamraid.sys c:windowssystem32driversprosync1.sys Protection Technology StarForce Protection System c:windowssystem32driversviamraid.sys VIA Technologies inc,.ltd VIA RAID driver 1 ntkrnlpa!IofCallDriver[0x804EE120] -> DeviceHarddisk0DR0[0x89DC2AB8] 3 CLASSPNP[0xB80E8FD7] -> ntkrnlpa!IofCallDriver[0x804EE120] -> Device00000073[0x89E09920] 5 ACPI[0xB7F7F620] -> ntkrnlpa!IofCallDriver[0x804EE120] -> DeviceScsiVIAMRAID1Port2Path0Target0Lun0[0x89DCCA38] kernel: MBR read successfully _asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [bP+0x0], CH; JL 0x2e; JNZ 0x3a; } user != kernel MBR !!! . ============= FINISH: 22:05:58,01 =============== Нов съм в форума,надявам се темата да е по образеца.

attach.txt

dds.txt

Редактирано от Владислав (преглед на промените)

Здравейте!

Стъпка 1

Моля, деинсталирайте следните приложения:

50 FREE MP3s +1 Free Audiobook!

AVG Security Toolbar

Winamp Toolbar

Wincore MediaBar

Стъпка 2

Публикувано изображение Изтеглете Malwarebytes' Anti-Malware

* Кликнете два пъти върху mbam-setup.exe, за да инсталирате програмата.

* Уверете се, че са поставени отметки на Update Malwarebytes' Anti-Malware и Launch Malwarebytes' Anti-Malware. След това кликнете на Finish.

* Ако има намерени обновявания, тя ще ги изтегли и инсталира.

* Стартирайте програмата и изберете "Perform Quick Scan", след това кликнете на Scan.

* Сканирането ще отнеме малко време, затова моля да бъдете търпеливи.

* Когато сканирането завърши, кликнете на OK, след това Show Results, за да видите резултата.

* Уверете се, че на всички редове има отметки, и кликнете на Remove Selected.

* Когато всичко бъде премахнато, в Notepad ще бъде отворен лог.

* Копирайте този лог и го публикувайте в следващия си коментар по темата.

Забележка: Ако MalwareBytes' Anti-Malware се затрудни в премахването на откритите вируси/заплахи, той ще поиска да рестартира компютъра Ви и по време на рестартирането да премахне проблемните вируси/заплахи. Ако бъдете попитани, потвърдете че желаете вашия компютър да бъде рестартиран.

Стъпка 3

Публикувано изображение Стартирайте програмата AdwCleaner (by Xplode).

  • Затворете всички стартирани програми и браузъри
  • Кликнете два пъти върху adwcleaner.exe за да стартирате инструмента.
  • Този път маркирайте Delete
  • Вашият компютър ще се рестартира автоматично. Текстовия файл ще се отвори след рестарта.
  • Моля, да публикувате съдържанието на този лог в отговора си
  • Можете да намерите лога,който автоматично се запомня тук C:AdwCleaner[s1].txt.

Стъпка 4

Моля, изтеглете aswMBR и го запазете на вашия десктоп.

  • Кликнете с двоен клин на мишката върху файла aswMBR.exe за да го стартирате.
  • Изчакайте да изтегли дефинициите на avast!
  • От падащото меню посочете дял C: както е на снимката:
Публикувано изображение
  • Изберете Scan бутона, за да започне проверката.
  • Когато проверката завърши, натиснете бутона save log, запазете съдържанието на лог файла на десктопа и публикувайте съдържанието му в следващия си коментар.

В следващия си коментар, моля публикувайте следните лог файлове:

  • Лог файлът от Malwarebytes' Anti-Malware
  • Лог файлът от AdwCleaner
  • Лог файлът от aswMBR
  • Нов лог файл от DDS (накрая)

Моля, публикувайте лог файловете си директно във вашия пост, а не ги прикачвайте, защото е крайно неудобно и заблуждаващо.

  • Автор

1.

Malwarebytes Anti-Malware (Trial) 1.65.1.1000

www.malwarebytes.org

Database version: v2012.11.01.01

Windows XP Service Pack 3 x86 NTFS

Internet Explorer 6.0.2900.5512

XP :: XP-C64AA1E57223 [limited]

Protection: Disabled

01.11.2012 г. 11:40:15

mbam-log-2012-11-01 (11-40-15).txt

Scan type: Quick scan

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM

Scan options disabled: P2P

Objects scanned: 199745

Time elapsed: 8 minute(s), 45 second(s)

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 0

(No malicious items detected)

Registry Keys Detected: 2

HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsMsMpEng.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsmsseces.exe (Security.Hijack) -> Quarantined and deleted successfully.

Registry Values Detected: 0

(No malicious items detected)

Registry Data Items Detected: 3

HKLMSOFTWAREMicrosoftSecurity Center|AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.

HKLMSOFTWAREMicrosoftSecurity Center|FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.

HKLMSOFTWAREMicrosoftSecurity Center|UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.

Folders Detected: 0

(No malicious items detected)

Files Detected: 0

(No malicious items detected)

(end)

2.

# AdwCleaner v2.006 - Logfile created 11/01/2012 at 11:52:51

# Updated 30/10/2012 by Xplode

# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)

# User : XP - XP-C64AA1E57223

# Boot Mode : Normal

# Running from : D:Google chrome downloadadwcleaner.exe

# Option [Delete]

***** [services] *****

Stopped & Deleted : Web Assistant Updater

***** [Files / Folders] *****

File Deleted : C:DOCUME~1XPLOCALS~1TempUninstall.exe

File Deleted : C:Documents and SettingsXPApplication DataMozillaFirefoxProfiles1dg72ijs.defaultsearchpluginsaol-web-search.xml

File Deleted : C:Documents and SettingsXPApplication DataMozillaFirefoxProfiles1dg72ijs.defaultsearchpluginsAskcom.xml

File Deleted : C:Documents and SettingsXPApplication DataMozillaFirefoxProfiles1dg72ijs.defaultsearchpluginsMyStart Search.xml

File Deleted : C:Documents and SettingsXPApplication DataMozillaFirefoxProfiles1dg72ijs.defaultsearchpluginsSearch_Results.xml

File Deleted : C:Documents and SettingsXPApplication DataMozillaFirefoxProfiles1dg72ijs.defaultsearchpluginsyahoo-zugo.xml

File Deleted : C:Program FilesMozilla Firefoxpluginsnpdnu.dll

File Deleted : C:Program FilesMozilla Firefoxpluginsnpdnu.xpt

File Deleted : C:Program FilesMozilla Firefoxpluginsnpdnupdater2.dll

File Deleted : C:Program FilesMozilla Firefoxpluginsnpdnupdater2.xpt

File Deleted : C:Program FilesMozilla Firefoxsearchpluginsavg-secure-search.xml

File Deleted : C:Program FilesMozilla Firefoxsearchpluginsbabylon.xml

File Deleted : C:Program FilesMozilla FireFoxsearchpluginsSearch_Results.xml

File Deleted : C:user.js

Folder Deleted : C:Documents and SettingsAll UsersApplication DataAsk

Folder Deleted : C:Documents and SettingsAll UsersApplication DataBabylon

Folder Deleted : C:Documents and SettingsAll UsersApplication Databoost_interprocess

Folder Deleted : C:Documents and SettingsAll UsersApplication DataInstallMate

Folder Deleted : C:Documents and SettingsAll UsersApplication DataPremium

Folder Deleted : C:Documents and SettingsXPApplication DataAVG Secure Search

Folder Deleted : C:Documents and SettingsXPApplication DataBabylon

Folder Deleted : C:Documents and SettingsXPApplication DataMozillaFirefoxProfiles1dg72ijs.defaultextensions{0b38152b-1b20-484d-a11f-5e04a9b0661f}

Folder Deleted : C:Documents and SettingsXPApplication DataMozillaFirefoxProfiles1dg72ijs.defaultextensions{5911488E-9D1E-40ec-8CBB-06B231CC153F}

Folder Deleted : C:Documents and SettingsXPApplication DataMozillaFirefoxProfiles1dg72ijs.defaultWinampToolbarData

Folder Deleted : C:Documents and SettingsXPApplication DataOpenCandy

Folder Deleted : C:Documents and SettingsXPApplication DataToolbar4

Folder Deleted : C:Documents and SettingsXPLocal SettingsApplication DataAPN

Folder Deleted : C:Program FilesCommon FilesSoftware Update Utility

Folder Deleted : C:Program FilesWeb Assistant

***** [Registry] *****

Key Deleted : HKCUSoftwareAVG Secure Search

Key Deleted : HKCUSoftwareCrossrider

Key Deleted : HKCUSoftwareDataMngr

Key Deleted : HKCUSoftwareIGearSettings

Key Deleted : HKCUSoftwareIM

Key Deleted : HKCUSoftwareIminent

Key Deleted : HKCUSoftwareImInstaller

Key Deleted : HKCUSoftwareMicrosoftInternet ExplorerSearchScopes{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}

Key Deleted : HKCUSoftwareMicrosoftInternet ExplorerSearchScopes{95B7759C-8C7F-4BF1-B163-73684A933233}

Key Deleted : HKCUSoftwareMicrosoftInternet ExplorerSearchScopes{EEE7E0A3-AE64-4DC8-84D1-F5D7BAF2DB0C}

Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionApp ManagementARPCache{79A765E1-C399-405B-85AF-466F52E918B0}

Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{336D0C35-8A85-403a-B9D2-65C292C39087}

Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{64E2F96A-4FE4-4aa8-90B0-2A929AB6AA88}

Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{95B7759C-8C7F-4BF1-B163-73684A933233}

Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{977AE9CC-AF83-45E8-9E03-E2798216E2D5}

Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{98889811-442D-49DD-99D7-DC866BE87DBC}

Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{D4027C7F-154A-4066-A1AD-4243D8127440}

Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{D48C9EAD-F59F-4DEA-AC97-7065FEA79F42}

Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{F9639E4A-801B-4843-AEE3-03D9DA199E77}

Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20}

Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{2EECD738-5844-4A99-B4B6-146BF802613B}

Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{336D0C35-8A85-403a-B9D2-65C292C39087}

Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{58124A0B-DC32-4180-9BFF-E0E21AE34026}

Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{64E2F96A-4FE4-4aa8-90B0-2A929AB6AA88}

Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99}

Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{95B7759C-8C7F-4BF1-B163-73684A933233}

Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{977AE9CC-AF83-45E8-9E03-E2798216E2D5}

Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{98889811-442D-49DD-99D7-DC866BE87DBC}

Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}

Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{D4027C7F-154A-4066-A1AD-4243D8127440}

Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{D48C9EAD-F59F-4DEA-AC97-7065FEA79F42}

Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{F9639E4A-801B-4843-AEE3-03D9DA199E77}

Key Deleted : HKCUSoftwareWeb Assistant

Key Deleted : HKCUSoftwareZugo

Key Deleted : HKLMSoftwareAVG Secure Search

Key Deleted : HKLMSoftwareBabylon

Key Deleted : HKLMSOFTWAREClassesAppID{608D3067-77E8-463D-9084-908966806826}

Key Deleted : HKLMSOFTWAREClassesAppID{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1}

Key Deleted : HKLMSOFTWAREClassesAppID{B302A1BD-0157-49FA-90F1-4E94F22C7B4B}

Key Deleted : HKLMSOFTWAREClassesAppID{BDB69379-802F-4EAF-B541-F8DE92DD98DB}

Key Deleted : HKLMSOFTWAREClassesAppID{EA28B360-05E0-4F93-8150-02891F1D8D3C}

Key Deleted : HKLMSOFTWAREClassesAppIDdnu.EXE

Key Deleted : HKLMSOFTWAREClassesAppIDExtension.DLL

Key Deleted : HKLMSOFTWAREClassesAVG Secure Search.BrowserWndAPI

Key Deleted : HKLMSOFTWAREClassesAVG Secure Search.BrowserWndAPI.1

Key Deleted : HKLMSOFTWAREClassesAVG Secure Search.PugiObj

Key Deleted : HKLMSOFTWAREClassesAVG Secure Search.PugiObj.1

Key Deleted : HKLMSOFTWAREClassesCLSID{02054E11-5113-4BE3-8153-AA8DFB5D3761}

Key Deleted : HKLMSOFTWAREClassesCLSID{2D360201-FFF5-11D1-8D03-00A0C959BC0A}

Key Deleted : HKLMSOFTWAREClassesCLSID{336D0C35-8A85-403a-B9D2-65C292C39087}

Key Deleted : HKLMSOFTWAREClassesCLSID{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}

Key Deleted : HKLMSOFTWAREClassesCLSID{95B7759C-8C7F-4BF1-B163-73684A933233}

Key Deleted : HKLMSOFTWAREClassesCLSID{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}

Key Deleted : HKLMSOFTWAREClassesCLSID{D48C9EAD-F59F-4DEA-AC97-7065FEA79F42}

Key Deleted : HKLMSOFTWAREClassesCLSID{E1164984-B567-47BD-A7FF-240C2594404A}

Key Deleted : HKLMSOFTWAREClassesCLSID{E15A9BFD-D16D-496D-8222-44CADF316E70}

Key Deleted : HKLMSOFTWAREClassesCLSID{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}

Key Deleted : HKLMSOFTWAREClassesdnUpdate

Key Deleted : HKLMSOFTWAREClassesdnUpdater.DownloadUIBrowser

Key Deleted : HKLMSOFTWAREClassesdnUpdater.DownloadUIBrowser.1

Key Deleted : HKLMSOFTWAREClassesdnUpdater.DownloadUpdController

Key Deleted : HKLMSOFTWAREClassesdnUpdater.DownloadUpdController.1

Key Deleted : HKLMSOFTWAREClassesExtension.ExtensionhelperObject

Key Deleted : HKLMSOFTWAREClassesExtension.ExtensionhelperObject.1

Key Deleted : HKLMSOFTWAREClassesInterface{021B4049-F57D-4565-A693-FD3B04786BFA}

Key Deleted : HKLMSOFTWAREClassesInterface{0362AA09-808D-48E9-B360-FB51A8CBCE09}

Key Deleted : HKLMSOFTWAREClassesInterface{03E2A1F3-4402-4121-8B35-733216D61217}

Key Deleted : HKLMSOFTWAREClassesInterface{06844020-CD0B-3D3D-A7FE-371153013E49}

Key Deleted : HKLMSOFTWAREClassesInterface{0ADC01BB-303B-3F8E-93DA-12C140E85460}

Key Deleted : HKLMSOFTWAREClassesInterface{10D3722F-23E6-3901-B6C1-FF6567121920}

Key Deleted : HKLMSOFTWAREClassesInterface{1675E62B-F911-3B7B-A046-EB57261212F3}

Key Deleted : HKLMSOFTWAREClassesInterface{192929F2-9273-3894-91B0-F54671C4C861}

Key Deleted : HKLMSOFTWAREClassesInterface{2932897E-3036-43D9-8A64-B06447992065}

Key Deleted : HKLMSOFTWAREClassesInterface{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}

Key Deleted : HKLMSOFTWAREClassesInterface{32B80AD6-1214-45F4-994E-78A5D482C000}

Key Deleted : HKLMSOFTWAREClassesInterface{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}

Key Deleted : HKLMSOFTWAREClassesInterface{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}

Key Deleted : HKLMSOFTWAREClassesInterface{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}

Key Deleted : HKLMSOFTWAREClassesInterface{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}

Key Deleted : HKLMSOFTWAREClassesInterface{5D8C3CC3-3C05-38A1-B244-924A23115FE9}

Key Deleted : HKLMSOFTWAREClassesInterface{641593AF-D9FD-30F7-B783-36E16F7A2E08}

Key Deleted : HKLMSOFTWAREClassesInterface{660E6F4F-840D-436D-B668-433D9591BAC5}

Key Deleted : HKLMSOFTWAREClassesInterface{711FC48A-1356-3932-94D8-A8B733DBC7E4}

Key Deleted : HKLMSOFTWAREClassesInterface{72227B7F-1F02-3560-95F5-592E68BACC0C}

Key Deleted : HKLMSOFTWAREClassesInterface{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}

Key Deleted : HKLMSOFTWAREClassesInterface{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}

Key Deleted : HKLMSOFTWAREClassesInterface{8C68913C-AC3C-4494-8B9C-984D87C85003}

Key Deleted : HKLMSOFTWAREClassesInterface{8D019513-083F-4AA5-933F-7D43A6DA82C4}

Key Deleted : HKLMSOFTWAREClassesInterface{923F6FB8-A390-370E-A0D2-DD505432481D}

Key Deleted : HKLMSOFTWAREClassesInterface{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}

Key Deleted : HKLMSOFTWAREClassesInterface{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}

Key Deleted : HKLMSOFTWAREClassesInterface{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}

Key Deleted : HKLMSOFTWAREClassesInterface{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}

Key Deleted : HKLMSOFTWAREClassesInterface{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}

Key Deleted : HKLMSOFTWAREClassesInterface{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}

Key Deleted : HKLMSOFTWAREClassesInterface{B06D4521-D09C-3F41-8E39-9D784CCA2A75}

Key Deleted : HKLMSOFTWAREClassesInterface{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}

Key Deleted : HKLMSOFTWAREClassesInterface{C2E799D0-43A5-3477-8A98-FC5F3677F35C}

Key Deleted : HKLMSOFTWAREClassesInterface{D16107CD-2AD5-46A8-BA59-303B7C32C500}

Key Deleted : HKLMSOFTWAREClassesInterface{D25B101F-8188-3B43-9D85-201F372BC205}

Key Deleted : HKLMSOFTWAREClassesInterface{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}

Key Deleted : HKLMSOFTWAREClassesInterface{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}

Key Deleted : HKLMSOFTWAREClassesInterface{D8FA96CA-B250-312C-AF34-4FF1DD72589D}

Key Deleted : HKLMSOFTWAREClassesInterface{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}

Key Deleted : HKLMSOFTWAREClassesInterface{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}

Key Deleted : HKLMSOFTWAREClassesInterface{E1B4C9DE-D741-385F-981E-6745FACE6F01}

Key Deleted : HKLMSOFTWAREClassesInterface{E7435878-65B9-44D1-A443-81754E5DFC90}

Key Deleted : HKLMSOFTWAREClassesInterface{E7B623F5-9715-3F9F-A671-D1485A39F8A2}

Key Deleted : HKLMSOFTWAREClassesInterface{ED916A7B-7C68-3198-B87D-2DABC30A5587}

Key Deleted : HKLMSOFTWAREClassesInterface{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}

Key Deleted : HKLMSOFTWAREClassesInterface{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}

Key Deleted : HKLMSOFTWAREClassesInterface{FC32005D-E27C-32E0-ADFA-152F598B75E7}

Key Deleted : HKLMSOFTWAREClassesProd.cap

Key Deleted : HKLMSOFTWAREClassesTypeLib{1D5A4199-956E-49BC-B89F-6A35C57C0D13}

Key Deleted : HKLMSOFTWAREClassesTypeLib{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}

Key Deleted : HKLMSOFTWAREClassesTypeLib{92380354-381A-471F-BE2E-DD9ACD9777EA}

Key Deleted : HKLMSOFTWAREClassesTypeLib{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}

Key Deleted : HKLMSOFTWAREClassesTypeLib{DB538320-D3C5-433C-BCA9-C4081A054FCF}

Key Deleted : HKLMSOFTWAREGoogleChromeExtensionsdlnembnfbcpjnepmfjmngjenhhajpdfd

Key Deleted : HKLMSoftwareIminent

Key Deleted : HKLMSOFTWAREMicrosoftShared ToolsMSConfigstartupregDATAMNGR

Key Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionApp ManagementARPCache{336D0C35-8A85-403a-B9D2-65C292C39087}_is1

Key Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionApp ManagementARPCacheSoftwareUpdUtility

Key Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{336D0C35-8A85-403a-B9D2-65C292C39087}

Key Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{95B7759C-8C7F-4BF1-B163-73684A933233}

Key Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionExtPreApproved{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}

Key Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionExtPreApproved{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}

Key Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionUninstall{336D0C35-8A85-403a-B9D2-65C292C39087}_is1

Key Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionUninstall{4BD8E034-E0F4-4509-A753-467A8E854CD8}

Key Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionUninstallIMBoosterARP

Key Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionUninstallSearchTheWebARP

Key Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionUninstallSoftwareUpdUtility

Key Deleted : HKLMSoftwareWeb Assistant

Value Deleted : HKCUSoftwareMicrosoftInternet ExplorerToolbarWebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]

Value Deleted : HKLMSOFTWAREMicrosoftInternet ExplorerToolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]

Value Deleted : HKLMSOFTWAREMozillaFirefoxextensions [{336D0C35-8A85-403a-B9D2-65C292C39087}]

Value Deleted : HKLMSOFTWAREMozillaFirefoxExtensions [[email protected]]

Value Deleted : HKLMSYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList [C:Program FilesRelevantKnowledgerlvknlg.exe]

***** [internet Browsers] *****

- Internet Explorer v6.0.2900.5512

Replaced : [HKCUSoftwareMicrosoftInternet ExplorerMain - Start Page] = hxxp://isearch.avg.com/?cid={3AC615C6-7879-4254-B1A2-35D4BF2C4A46}&mid=11374672b22147d0b44bd1509d2034b9-06ce4fc639803a2e3563922518183d8e94088cb9&lang=en&ds=gm011&pr=sa&d=2012-04-01 20:47:44&v=11.1.0.12&sap=hp --> hxxp://www.google.com

Replaced : [HKCUSoftwareMicrosoftInternet ExplorerMain - Start Page Restore] = hxxp://isearch.avg.com/?cid={3AC615C6-7879-4254-B1A2-35D4BF2C4A46}&mid=11374672b22147d0b44bd1509d2034b9-06ce4fc639803a2e3563922518183d8e94088cb9&lang=en&ds=gm011&pr=sa&d=2012-04-01 20:47:44&v=10.2.0.3&sap=hp --> hxxp://www.google.com

- Mozilla Firefox v3.6 (bg)

Profile name : default

File : C:Documents and SettingsXPApplication DataMozillaFirefoxProfiles1dg72ijs.defaultprefs.js

C:Documents and SettingsXPApplication DataMozillaFirefoxProfiles1dg72ijs.defaultuser.js ... Deleted !

Deleted : user_pref("aol_toolbar.surf.date", "14");

Deleted : user_pref("aol_toolbar.surf.lastDate", "31");

Deleted : user_pref("aol_toolbar.surf.lastMonth", "9");

Deleted : user_pref("aol_toolbar.surf.lastYear", "2012");

Deleted : user_pref("aol_toolbar.surf.month", "14");

Deleted : user_pref("aol_toolbar.surf.prevMonth", "0");

Deleted : user_pref("aol_toolbar.surf.total", "14");

Deleted : user_pref("aol_toolbar.surf.week", "14");

Deleted : user_pref("aol_toolbar.surf.year", "14");

Deleted : user_pref("browser.babylon.HPOnNewTab", "search.babylon.com");

Deleted : user_pref("browser.newtab.url", "hxxp://mystart.incredibar.com/mb139?a=6OyLPwp7C3&loc=FF_NT");

Deleted : user_pref("browser.search.defaultengine", "Ask.com");

Deleted : user_pref("browser.search.defaultenginename", "AOL Web Search");

Deleted : user_pref("browser.search.defaulturl", "hxxp://search.winamp.com/search/search?query={searchTerms}&i[...]

Deleted : user_pref("browser.search.order.1", "Search the web (Babylon)");

Deleted : user_pref("extensions.BabylonToolbar.admin", false);

Deleted : user_pref("extensions.BabylonToolbar.aflt", "babsst");

Deleted : user_pref("extensions.BabylonToolbar.babExt", "");

Deleted : user_pref("extensions.BabylonToolbar.babTrack", "affID=112560&tt=2912_8");

Deleted : user_pref("extensions.BabylonToolbar.bbDpng", 28);

Deleted : user_pref("extensions.BabylonToolbar.dfltLng", "en");

Deleted : user_pref("extensions.BabylonToolbar.dfltSrch", true);

Deleted : user_pref("extensions.BabylonToolbar.hmpg", true);

Deleted : user_pref("extensions.BabylonToolbar.id", "30407c1a0000000000000019dbc4dd4a");

Deleted : user_pref("extensions.BabylonToolbar.instlDay", "15540");

Deleted : user_pref("extensions.BabylonToolbar.instlRef", "sst");

Deleted : user_pref("extensions.BabylonToolbar.keyWordUrl", "hxxp://search.babylon.com/?affID=112560&tt=2912_8[...]

Deleted : user_pref("extensions.BabylonToolbar.lastDP", 28);

Deleted : user_pref("extensions.BabylonToolbar.lastVrsnTs", "1.5.3.179:34:11");

Deleted : user_pref("extensions.BabylonToolbar.mntrFFxVrsn", "3.6");

Deleted : user_pref("extensions.BabylonToolbar.newTab", true);

Deleted : user_pref("extensions.BabylonToolbar.newTabUrl", "hxxp://search.babylon.com/?babsrc=NT_bb");

Deleted : user_pref("extensions.BabylonToolbar.noFFXTlbr", false);

Deleted : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");

Deleted : user_pref("extensions.BabylonToolbar.propectorlck", 89977061);

Deleted : user_pref("extensions.BabylonToolbar.prtkHmpg", 1);

Deleted : user_pref("extensions.BabylonToolbar.prtnrId", "babylon");

Deleted : user_pref("extensions.BabylonToolbar.ptch_0717", true);

Deleted : user_pref("extensions.BabylonToolbar.smplGrp", "azb");

Deleted : user_pref("extensions.BabylonToolbar.srcExt", "ss");

Deleted : user_pref("extensions.BabylonToolbar.tlbrId", "base");

Deleted : user_pref("extensions.BabylonToolbar.vrsn", "1.5.3.17");

Deleted : user_pref("extensions.BabylonToolbar.vrsnTs", "1.5.3.179:34:11");

Deleted : user_pref("extensions.BabylonToolbar.vrsni", "1.5.3.17");

Deleted : user_pref("extensions.BabylonToolbar_i.aflt", "babsst");

Deleted : user_pref("extensions.BabylonToolbar_i.babExt", "");

Deleted : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=112560&tt=2912_8");

Deleted : user_pref("extensions.BabylonToolbar_i.hardId", "30407c1a0000000000000019dbc4dd4a");

Deleted : user_pref("extensions.BabylonToolbar_i.id", "30407c1a0000000000000019dbc4dd4a");

Deleted : user_pref("extensions.BabylonToolbar_i.instlDay", "15540");

Deleted : user_pref("extensions.BabylonToolbar_i.instlRef", "sst");

Deleted : user_pref("extensions.BabylonToolbar_i.newTab", false);

Deleted : user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");

Deleted : user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");

Deleted : user_pref("extensions.BabylonToolbar_i.smplGrp", "none");

Deleted : user_pref("extensions.BabylonToolbar_i.srcExt", "ss");

Deleted : user_pref("extensions.BabylonToolbar_i.tlbrId", "base");

Deleted : user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");

Deleted : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.179:34:11");

Deleted : user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");

Deleted : user_pref("extensions.incredibar.admin", false);

Deleted : user_pref("extensions.incredibar.aflt", "orgnl");

Deleted : user_pref("extensions.incredibar.cntry", "BG");

Deleted : user_pref("extensions.incredibar.dfltLng", "");

Deleted : user_pref("extensions.incredibar.dfltSrch", false);

Deleted : user_pref("extensions.incredibar.did", "10650");

Deleted : user_pref("extensions.incredibar.envrmnt", "production");

Deleted : user_pref("extensions.incredibar.excTlbr", false);

Deleted : user_pref("extensions.incredibar.hdrMd5", "891871B21D7637E1BEACF4A7F120355D");

Deleted : user_pref("extensions.incredibar.hmpg", false);

Deleted : user_pref("extensions.incredibar.id", "30407c1a00000000000000158315a310");

Deleted : user_pref("extensions.incredibar.installerproductid", "26");

Deleted : user_pref("extensions.incredibar.instlDay", "15574");

Deleted : user_pref("extensions.incredibar.instlRef", "");

Deleted : user_pref("extensions.incredibar.lastVrsnTs", "1.5.11.1422:19:43");

Deleted : user_pref("extensions.incredibar.mntrvrsn", "1.2.0");

Deleted : user_pref("extensions.incredibar.newTab", false);

Deleted : user_pref("extensions.incredibar.noFFXTlbr", false);

Deleted : user_pref("extensions.incredibar.ppd", "21%5F5");

Deleted : user_pref("extensions.incredibar.prdct", "incredibar");

Deleted : user_pref("extensions.incredibar.productid", "26");

Deleted : user_pref("extensions.incredibar.prtnrId", "Incredibar");

Deleted : user_pref("extensions.incredibar.sg", "none");

Deleted : user_pref("extensions.incredibar.smplGrp", "none");

Deleted : user_pref("extensions.incredibar.tlbrId", "base");

Deleted : user_pref("extensions.incredibar.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6OyLPwp7C3&loc=IB_T[...]

Deleted : user_pref("extensions.incredibar.upn2", "6OyLPwp7C3");

Deleted : user_pref("extensions.incredibar.upn2n", "92261976266114283");

Deleted : user_pref("extensions.incredibar.vrsn", "1.5.11.14");

Deleted : user_pref("extensions.incredibar.vrsnTs", "1.5.11.1422:19:43");

Deleted : user_pref("extensions.incredibar.vrsni", "1.5.11.14");

Deleted : user_pref("extensions.incredibar_i.aflt", "orgnl");

Deleted : user_pref("extensions.incredibar_i.dfltLng", "");

Deleted : user_pref("extensions.incredibar_i.did", "10650");

Deleted : user_pref("extensions.incredibar_i.excTlbr", false);

Deleted : user_pref("extensions.incredibar_i.id", "30407c1a00000000000000158315a310");

Deleted : user_pref("extensions.incredibar_i.installerproductid", "26");

Deleted : user_pref("extensions.incredibar_i.instlDay", "15574");

Deleted : user_pref("extensions.incredibar_i.instlRef", "");

Deleted : user_pref("extensions.incredibar_i.ms_url_id", "");

Deleted : user_pref("extensions.incredibar_i.newTab", false);

Deleted : user_pref("extensions.incredibar_i.ppd", "21%5F5");

Deleted : user_pref("extensions.incredibar_i.prdct", "incredibar");

Deleted : user_pref("extensions.incredibar_i.productid", "26");

Deleted : user_pref("extensions.incredibar_i.prtnrId", "Incredibar");

Deleted : user_pref("extensions.incredibar_i.smplGrp", "none");

Deleted : user_pref("extensions.incredibar_i.tlbrId", "base");

Deleted : user_pref("extensions.incredibar_i.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6OyLPwp7C3&loc=IB[...]

Deleted : user_pref("extensions.incredibar_i.upn2", "6OyLPwp7C3");

Deleted : user_pref("extensions.incredibar_i.upn2n", "92261976266114283");

Deleted : user_pref("extensions.incredibar_i.vrsn", "1.5.11.14");

Deleted : user_pref("extensions.incredibar_i.vrsnTs", "1.5.11.1422:19:43");

Deleted : user_pref("extensions.incredibar_i.vrsni", "1.5.11.14");

Deleted : user_pref("keyword.URL", "hxxp://slirsredirect.search.aol.com/redirector/sredir?sredir=2685&invocati[...]

Deleted : user_pref("winamp_toolbar.buttons.layout", "shoutcast_30026;mobile/android_33522;post_to_twitter_335[...]

Deleted : user_pref("winamp_toolbar.firsttime.showwindow", false);

Deleted : user_pref("winamp_toolbar.guid", "{CA1CAD8F-FF93-46C7-FC83-DAAFCA845532}");

Deleted : user_pref("winamp_toolbar.install.lastTbVersion", "5.6.19.1");

Deleted : user_pref("winamp_toolbar.metrics.activestampdate", "31");

Deleted : user_pref("winamp_toolbar.metrics.activestampmonth", "9");

Deleted : user_pref("winamp_toolbar.metrics.activestampyear", "2012");

Deleted : user_pref("winamp_toolbar.metrics.originalDate", "31");

Deleted : user_pref("winamp_toolbar.metrics.originalHours", "16");

Deleted : user_pref("winamp_toolbar.metrics.originalMinutes", "22");

Deleted : user_pref("winamp_toolbar.metrics.originalMonth", "10");

Deleted : user_pref("winamp_toolbar.metrics.originalSeconds", "6");

Deleted : user_pref("winamp_toolbar.metrics.originalYear", "2012");

Deleted : user_pref("winamp_toolbar.remote.publish.xml", "1351700528004");

Deleted : user_pref("winamp_toolbar.search.cid", "31-10-2012");

Deleted : user_pref("winamp_toolbar.search.instd", "20121030124040296");

Deleted : user_pref("winamp_toolbar.search.oid", "31-10-2012");

Deleted : user_pref("winamp_toolbar.search.populateoncomplete", false);

Deleted : user_pref("winamp_toolbar.search.searchtype", "web");

Deleted : user_pref("winamp_toolbar.search.source", "tb50-ff-winamp");

Deleted : user_pref("winamp_toolbar.skin.custom", true);

Deleted : user_pref("winamp_toolbar.upgrade.showwindow", false);

Deleted : user_pref("winamp_toolbar.winamp.appversion", "1");

Deleted : user_pref("winamp_toolbar.winamp.artist", "");

Deleted : user_pref("winamp_toolbar.winamp.button.focus", true);

Deleted : user_pref("winamp_toolbar.winamp.button.forward", true);

Deleted : user_pref("winamp_toolbar.winamp.button.open", true);

Deleted : user_pref("winamp_toolbar.winamp.button.pause", true);

Deleted : user_pref("winamp_toolbar.winamp.button.play", true);

Deleted : user_pref("winamp_toolbar.winamp.button.rewind", true);

Deleted : user_pref("winamp_toolbar.winamp.button.stop", false);

Deleted : user_pref("winamp_toolbar.winamp.button.volume", true);

Deleted : user_pref("winamp_toolbar.winamp.info.url", "hxxp://music.aol.com/artist/{artist}");

Deleted : user_pref("winamp_toolbar.winamp.ticker.show", true);

Deleted : user_pref("winamp_toolbar.winamp.title", "-999999");

Deleted : user_pref("winamp_toolbar.winamp.tracklength", "-999999");

Deleted : user_pref("winamp_toolbar.winamp.tracktime", "-999999");

Deleted : user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_referrer", "hxxp://www.search-resul[...]

Deleted : user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_temp_referer", "hxxp://www.search-r[...]

Deleted : user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_whiteList", "{"search.babylon.com[...]

- Google Chrome v [unable to get version]

File : C:Documents and SettingsXPLocal SettingsApplication DataGoogleChromeUser DataDefaultPreferences

[OK] File is clean.

*************************

AdwCleaner[s1].txt - [27218 octets] - [01/11/2012 11:52:51]

########## EOF - C:AdwCleaner[s1].txt - [27279 octets] ##########

3.

aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software

Run date: 2012-11-01 12:06:52

-----------------------------

12:06:52.859 OS Version: Windows 5.1.2600 Service Pack 3

12:06:52.859 Number of processors: 1 586 0x4F02

12:06:52.859 ComputerName: XP-C64AA1E57223 UserName: XP

12:06:53.687 Initialize success

12:06:53.921 AVAST engine defs: 12103101

12:07:06.078 Disk 0 (boot) DeviceHarddisk0DR0 -> DeviceScsiVIAMRAID1Port2Path0Target0Lun0

12:07:06.078 Disk 0 Vendor: Size: 0MB BusType: 0

12:07:06.078 Disk 0 MBR read successfully

12:07:06.078 Disk 0 MBR scan

12:07:06.093 Disk 0 Windows XP default MBR code

12:07:06.093 Disk 0 MBR hidden

12:07:06.093 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 39997 MB offset 63

12:07:06.093 Disk 0 Partition - 00 0F Extended LBA 198467 MB offset 81915435

12:07:06.109 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 198467 MB offset 81915498

12:07:06.171 Disk 0 scanning C:WINDOWSsystem32drivers

12:07:12.953 Service scanning

12:07:26.796 Modules scanning

12:07:33.125 Disk 0 trace - called modules:

12:07:33.625 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll prosync1.sys SCSIPORT.SYS viamraid.sys

12:07:33.640 1 nt!IofCallDriver -> DeviceHarddisk0DR0[0x89dc2ab8]

12:07:33.640 3 CLASSPNP.SYS[b80e8fd7] -> nt!IofCallDriver -> Device00000073[0x89e09920]

12:07:33.640 5 ACPI.sys[b7f7f620] -> nt!IofCallDriver -> DeviceScsiVIAMRAID1Port2Path0Target0Lun0[0x89dcca38]

12:07:33.796 AVAST engine scan C:

12:09:25.578 Disk 0 MBR has been saved successfully to "C:Documents and SettingsXPDesktopMBR.dat"

12:09:25.578 The log file has been saved successfully to "C:Documents and SettingsXPDesktopaswMBR.txt"

4.

DDS (Ver_2011-09-30.01) - NTFS_x86

Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_37

Run by XP at 12:10:36 on 2012-11-01

Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.2046.1192 [GMT 2:00]

.

AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}

.

============== Running Processes ================

.

C:WINDOWSsystem32nvsvc32.exe

C:Program FilesAVAST SoftwareAvastAvastSvc.exe

C:WINDOWSsystem32spoolsv.exe

C:Program FilesIVT CorporationBlueSoleilBlueSoleilCS.exe

C:Program FilesIVT CorporationBlueSoleilBsMobileCS.exe

C:Program FilesJavajre6binjqs.exe

C:Program FilesGoogleUpdateGoogleUpdate.exe

C:Program FilesMalwarebytes' Anti-Malwarembamscheduler.exe

C:WINDOWSExplorer.EXE

C:Documents and SettingsAll UsersApplication DataSkypeToolbarsSkype C2C Servicec2c_service.exe

C:WINDOWSsystem32dmwu.exe

C:Program FilesIVT CorporationBlueSoleilBsHelpCS.exe

C:WINDOWSsystem32wbemwmiprvse.exe

C:WINDOWSsystem32wscntfy.exe

C:WINDOWSSystem32alg.exe

C:Program FilesAVAST SoftwareAvastavastUI.exe

C:WINDOWSsystem32RunDLL32.exe

C:WINDOWSsystem32ctfmon.exe

C:Program FilesSkypePhoneSkype.exe

C:Program FilesWinamp RemotebinOrbTray.exe

C:Program FilesGoogleChromeApplicationchrome.exe

C:Program FilesGoogleChromeApplicationchrome.exe

C:Program FilesGoogleChromeApplicationchrome.exe

C:Program FilesGoogleChromeApplicationchrome.exe

C:Program FilesGoogleChromeApplicationchrome.exe

C:Program FilesGoogleChromeApplicationchrome.exe

C:WINDOWSsystem32wbemwmiprvse.exe

C:WINDOWSSystem32svchost.exe -k netsvcs

C:WINDOWSsystem32svchost.exe -k WudfServiceGroup

C:WINDOWSsystem32svchost.exe -k NetworkService

C:WINDOWSsystem32svchost.exe -k LocalService

C:WINDOWSsystem32svchost.exe -k imgsvc

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://www.google.com

mDefault_Search_URL = hxxp://www.google.com/ie

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:program filescommon filesadobeacrobatactivexAcroIEHelperShim.dll

BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:program filesjavajre6binssv.dll

BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - c:program filesskypetoolbarsinternet explorerskypeieplugin.dll

BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:program filesjavajre6binjp2ssv.dll

BHO: JQSIEStartDetectorImpl Class: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - c:program filesjavajre6libdeployjqsiejqs_plugin.dll

uRun: [ctfmon.exe] c:windowssystem32ctfmon.exe

uRun: [skype] "c:program filesskypephoneSkype.exe" /minimized /regrun

uRun: [Orb] "c:program fileswinamp remotebinOrbTray.exe" /background

mRun: [NeroFilterCheck] c:windowssystem32NeroCheck.exe

mRun: [avast] "c:program filesavast softwareavastavastUI.exe" /nogui

mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login

mRun: [NvCplDaemon] RUNDLL32.EXE c:windowssystem32NvCpl.dll,NvStartup

mRun: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

dRun: [CTFMON.EXE] c:windowssystem32CTFMON.EXE

uPolicies-Explorer: NoDriveTypeAutoRun = dword:145

mPolicies-Explorer: NoDriveTypeAutoRun = dword:145

IE: E&xport to Microsoft Excel - c:progra~1micros~2office11EXCEL.EXE/3000

IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:program filesskypetoolbarsinternet explorerskypeieplugin.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%Network Diagnosticxpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:program filesmessengermsmsgs.exe

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab

TCP: NameServer = 89.215.233.2 89.215.246.40

TCP: Interfaces{3032D039-1931-4EFF-8696-378E7F48A216} : DHCPNameServer = 89.215.233.2 89.215.246.40

Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:program filesskypetoolbarsinternet explorerskypeieplugin.dll

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:program filescommon filesskypeSkype4COM.dll

SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:windowssystem32WPDShServiceObj.dll

LSA: Authentication Packages = msv1_0 nwprovau

IFEO: epplauncher.exe - CMD /C>null

.

================= FIREFOX ===================

.

FF - ProfilePath - c:documents and settingsxpapplication datamozillafirefoxprofiles1dg72ijs.default

FF - prefs.js: browser.startup.homepage - hxxp://bg.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:bg:official

FF - component: c:documents and settingsxpapplication datamozillafirefoxprofiles1dg72ijs.defaultextensions{0b38152b-1b20-484d-a11f-5e04a9b0661f}componentsMailUtil.dll

FF - component: c:documents and settingsxpapplication datamozillafirefoxprofiles1dg72ijs.defaultextensions{0b38152b-1b20-484d-a11f-5e04a9b0661f}componentsWinampPlayer.dll

FF - component: c:documents and settingsxpapplication datamozillafirefoxprofiles1dg72ijs.defaultextensions{d48c9ead-f59f-4dea-ac97-7065fea79f42}componentsdtTransparency.dll

FF - component: c:documents and settingsxpapplication datamozillafirefoxprofiles1dg72ijs.defaultextensions{d48c9ead-f59f-4dea-ac97-7065fea79f42}componentsdtTransparency3.5.dll

FF - component: c:documents and settingsxpapplication datamozillafirefoxprofiles1dg72ijs.defaultextensions{d48c9ead-f59f-4dea-ac97-7065fea79f42}componentsdtTransparency3.6.dll

FF - component: c:program filesmozilla firefoxextensions{82af8dca-6de9-405d-bd5e-43525bdad38a}componentsSkypeFfComponent.dll

FF - component: c:program filesshareaza applicationsmediabardatamngrfirefoxextensioncomponentsDataMngrHlpFF3.dll

FF - plugin: c:program filesadobereader 9.0readerairnppdf32.dll

FF - plugin: c:program filescommon filesavg secure searchsitesafetyinstaller12.2.6npsitesafety.dll

FF - plugin: c:program filesgoogleupdate1.3.21.111npGoogleUpdate3.dll

FF - plugin: c:program filesgoogleupdate1.3.21.115npGoogleUpdate3.dll

FF - plugin: c:program filesgoogleupdate1.3.21.123npGoogleUpdate3.dll

FF - plugin: c:program filesjavajre6binnpjpi160_37.dll

FF - plugin: c:program filesjavajre6binplugin2npdeployJava1.dll

FF - plugin: c:program filesjavajre6binplugin2npjp2.dll

FF - plugin: c:program filesmozilla firefoxpluginsnpdnu.dll

FF - plugin: c:program filesmozilla firefoxpluginsnpdnupdater2.dll

FF - plugin: c:program filesmozilla firefoxpluginsnpwachk.dll

FF - plugin: c:windowssystem32macromedflashNPSWF32_11_4_402_287.dll

FF - plugin: c:windowssystem32npdeployJava1.dll

FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:program filesmozilla firefoxextensions{972ce4c6-7e08-4474-a285-3208198ce6fd}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} - c:program filesmozilla firefoxextensions{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} - c:program filesmozilla firefoxextensions{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} - c:program filesmozilla firefoxextensions{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}

FF - Ext: Skype Click to Call: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} - c:program filesmozilla firefoxextensions{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}

FF - Ext: avast! WebRep: [email protected] - c:program filesavast softwareavastwebrepFF

FF - Ext: Java Quick Starter: [email protected] - c:program filesjavajre6libdeployjqsff

.

============= SERVICES / DRIVERS ===============

.

R0 BtHidBus;Bluetooth HID Bus Service;c:windowssystem32driversBtHidBus.sys [2009-1-7 20744]

R1 aswSnx;aswSnx;c:windowssystem32driversaswSnx.sys [2012-3-26 435032]

R1 aswSP;aswSP;c:windowssystem32driversaswSP.sys [2012-3-26 314456]

R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:windowssystem32driversdtsoftbus01.sys [2012-3-28 242240]

R2 aswFsBlk;aswFsBlk;c:windowssystem32driversaswFsBlk.sys [2012-3-26 20568]

R2 avast! Antivirus;avast! Antivirus;c:program filesavast softwareavastAvastSvc.exe [2012-3-26 44768]

R2 BsMobileCS;BsMobileCS;c:program filesivt corporationbluesoleilBsMobileCS.exe [2009-2-27 143467]

R2 MBAMScheduler;MBAMScheduler;c:program filesmalwarebytes' anti-malwarembamscheduler.exe [2012-11-1 399432]

R2 Skype C2C Service;Skype C2C Service;c:documents and settingsall usersapplication dataskypetoolbarsskype c2c servicec2c_service.exe [2012-10-2 3064000]

R2 WebOptimizer;WebOptimizer;c:windowssystem32dmwu.exe [2012-9-12 1006448]

R3 als4k;Avance Audio Miniport Driver (WDM);c:windowssystem32driversals4000.sys [2012-3-26 28919]

R3 btnetBUs;Bluetooth PAN Bus Service;c:windowssystem32driversbtnetBus.sys [2008-12-7 30088]

R3 IvtBtBUs;IVT Bluetooth Bus Service;c:windowssystem32driversIvtBtBus.sys [2008-7-2 26248]

R3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);c:windowssystem32driversvcsvad.sys [2012-10-14 17792]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:windowsmicrosoft.netframeworkv4.0.30319mscorsvw.exe [2010-3-18 130384]

S2 gupdate;Услуга на Google Актуализация (gupdate);c:program filesgoogleupdateGoogleUpdate.exe [2012-3-26 136176]

S2 MBAMService;MBAMService;c:program filesmalwarebytes' anti-malwarembamservice.exe [2012-11-1 676936]

S2 SkypeUpdate;Skype Updater;c:program filesskypeupdaterUpdater.exe [2012-7-13 160944]

S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:windowssystem32macromedflashFlashPlayerUpdateService.exe [2012-4-9 250808]

S3 gupdatem;Услуга на Google Актуализация (gupdatem);c:program filesgoogleupdateGoogleUpdate.exe [2012-3-26 136176]

S3 MBAMProtector;MBAMProtector;c:windowssystem32driversmbam.sys [2012-11-1 22856]

S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:windowssystem32driverstap0901t.sys [2012-7-29 27136]

S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:windowsmicrosoft.netframeworkv4.0.30319wpfWPFFontCache_v0400.exe [2010-3-18 753504]

S4 McComponentHostService;McAfee Security Scan Component Host Service;c:program filesmcafee security scan3.0.207McCHSvc.exe [2011-6-17 237008]

S4 xqkim;Microsoft Driver;c:windowssystem32svchost.exe -k netsvcs [2008-4-14 14336]

.

=============== Created Last 30 ================

.

2012-11-01 09:25:12 -------- d-----w- c:documents and settingsxpapplication dataMalwarebytes

2012-11-01 09:24:56 -------- d-----w- c:documents and settingsall usersapplication dataMalwarebytes

2012-11-01 09:24:54 22856 ----a-w- c:windowssystem32driversmbam.sys

2012-11-01 09:24:53 -------- d-----w- c:program filesMalwarebytes' Anti-Malware

2012-10-30 12:41:00 -------- d-----w- c:program filesWinamp Detect

2012-10-30 12:40:29 -------- d-----w- c:documents and settingsall usersapplication dataOrbNetworks

2012-10-30 12:40:21 -------- d-----w- c:program filesWinamp Remote

2012-10-30 05:01:46 -------- d-----w- c:program filesUnlocker

2012-10-27 17:22:59 -------- d-----w- c:documents and settingsxpapplication dataOnLive App

2012-10-14 15:52:40 17792 ----a-w- c:windowssystem32driversvcsvad.sys

2012-10-05 09:35:38 -------- d-----w- c:documents and settingsall usersapplication dataYTD Video Downloader

2012-10-05 09:35:31 -------- d-----w- c:program filesGreenTree Applications

2012-10-04 16:53:33 -------- d-----w- c:program filesCCleaner

2012-10-02 10:17:58 5171904 ----a-w- c:program filesmozilla firefoxextensions{82af8dca-6de9-405d-bd5e-43525bdad38a}componentsSkypeFfComponent.dll

.

==================== Find3M ====================

.

2012-10-09 09:22:23 73656 ----a-w- c:windowssystem32FlashPlayerCPLApp.cpl

2012-10-09 09:22:23 696760 ----a-w- c:windowssystem32FlashPlayerApp.exe

2012-09-24 12:32:24 477168 ----a-w- c:windowssystem32npdeployJava1.dll

2012-09-24 12:32:20 473072 ----a-w- c:windowssystem32deployJava1.dll

2012-09-24 10:51:47 73728 ----a-w- c:windowssystem32javacpl.cpl

2012-09-20 18:24:25 260748 ----a-w- c:windowssystem32nvdrsdb0.bin

2012-09-20 18:24:25 1 ----a-w- c:windowssystem32nvdrssel.bin

2012-09-20 18:23:28 260740 ----a-w- c:windowssystem32nvdrsdb1.bin

2012-09-13 13:26:52 1006448 ----a-w- c:windowssystem32dmwu.exe

2012-09-13 13:24:48 28160 ----a-w- c:windowssystem32ImHttpComm.dll

2012-08-10 19:48:49 444952 ----a-w- c:windowssystem32wrap_oal.dll

2012-08-10 19:48:49 109080 ----a-w- c:windowssystem32OpenAL32.dll

2012-08-03 16:02:23 720896 ----a-w- c:windowsiun6002.exe

.

=================== ROOTKIT ====================

.

Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net

Windows 5.1.2600

.

CreateFile(".PHYSICALDRIVE0"): The process cannot access the file because it is being used by another process.

device: opened successfully

user: error reading MBR

.

Disk trace:

called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll prosync1.sys SCSIPORT.SYS viamraid.sys

c:windowssystem32driversprosync1.sys Protection Technology StarForce Protection System

c:windowssystem32driversviamraid.sys VIA Technologies inc,.ltd VIA RAID driver

1 ntkrnlpa!IofCallDriver[0x804EE120] -> DeviceHarddisk0DR0[0x89DC2AB8]

3 CLASSPNP[0xB80E8FD7] -> ntkrnlpa!IofCallDriver[0x804EE120] -> Device00000073[0x89E09920]

5 ACPI[0xB7F7F620] -> ntkrnlpa!IofCallDriver[0x804EE120] -> DeviceScsiVIAMRAID1Port2Path0Target0Lun0[0x89DCCA38]

kernel: MBR read successfully

_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [bP+0x0], CH; JL 0x2e; JNZ 0x3a; }

user != kernel MBR !!!

.

============= FINISH: 12:11:30,59 ===============

Редактирано от Владислав (преглед на промените)

Благодаря!

1. Изтеглете ComboFix от BleepingComputer

и го запазете (бутон Save -> Save as) ComboFix на вашия десктоп:

Публикувано изображение

След приключване на изтеглянето на ComboFix, иконката на програмата би трябвало да изглежда така:

Публикувано изображение

2. Затворете всички работещи приложения, отворени прозорци и програми работещи във фонов режим. Спрете временно защитата в реално време на антивирусната програма и на другите програми за сигурност, ако има такива.

3. Стартирайте с двоен клик Combofix.exe. Изберете YES, за да се съгласите с условията за използване на програмата. Важно: По време на работата на ComboFix не бива да се движи мишката и да се натискат клавиши от клавиатурата. Просто търпеливо оставете ComboFix да си свърши работата, без да използвате компютъра за други цели.

4. ComboFix ще провери дали Windows Recovery Console e инсталиранa.

*Ако Windows Recovery Console не е инсталирана, ще е необходимо да използвате YES за инсталация на Windows Recovery Console

*Ако Windows Recovery Console е инсталирана, ComboFix ще продължи работата си.

Публикувано изображение

Забележка: Необходимо е да сте свързани към Интернет за да може Windows Recovery Console да се изтегли.

След инсталация на Windows Recovery Console потвърдете с YES, за да продължите напред. Снимка:

Публикувано изображение

5. ComboFix ще спре временно Интернет връзката, но след като приключи работата на програмата тази връзка ще бъде възстановена автоматично. ComboFix ще сканира за проблеми и за заразени файлове, като това може да отнеме известно време. Моля да бъдете търпеливи. Ако има проблем с Интернет връзката след приключване на работата на ComboFix, моля да прочетете това: Manually restoring the Internet connection section.

6. Когато работата на ComboFix приключи, ще се появи текстов документ (log) в Notepad:

Публикувано изображение

Копирайте с (Copy) и поставете с (Paste) съдържанието на лога в следващия си коментар.

  • Автор

Пуснах я нали отне известно време накрая стигна до накякави Deleting изписа още нещо и се рестартира компа.. а после нямаше лог.. ако кажете ще го направя наново... :2 И ми изчезна таскбара..

Редактирано от Владислав (преглед на промените)

  • Автор

Намерих това в C/ComboFix/ComboFix.txt ComboFix 12-11-02.02 - XP 11.2012 г. 13:37:07.1.1 - x86 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.2046.1606 [GMT 2:00] Running from: D:Google chrome downloadComboFix.exe AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D} WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:Documents and SettingsAll UsersApplication DataTEMP C:Documents and SettingsAll UsersApplication DataTEMP{CB099890-1D5F-11D5-9EA9-0050BAE317E1}PostBuild.exe C:Documents and SettingsXPRecentThumbs.db C:Documents and SettingsXPWINDOWS C:Thumbs.db C:WINDOWSiun6002.exe C:WINDOWSsystem32_000116_.tmp.dll C:WINDOWSsystem32Cache C:WINDOWSsystem32Cache272512937d9e61a4.fb C:WINDOWSsystem32Cache287204568329e189.fb C:WINDOWSsystem32Cache28bc8f716fd76a47.fb C:WINDOWSsystem32Cache2c53092c95605355.fb C:WINDOWSsystem32Cache31a0997e9a5b5eb3.fb C:WINDOWSsystem32Cache32c84fe32bb74d60.fb C:WINDOWSsystem32Cache3917078cb68ec657.fb C:WINDOWSsystem32Cache533a2b71bfcc6b0e.fb C:WINDOWSsystem32Cache590ba23ce359fd0c.fb C:WINDOWSsystem32Cache610289e025a3ee9a.fb C:WINDOWSsystem32Cache651c5d3cdbfb8bd1.fb C:WINDOWSsystem32Cache6c59ac5e7e7a3ad0.fb C:WINDOWSsystem32Cache6d03dad1035885d3.fb C:WINDOWSsystem32Cache841be2afcf601e39.fb C:WINDOWSsystem32Cachea8556537add6dfc5.fb C:WINDOWSsystem32Cachead10a52aff5e038d.fb C:WINDOWSsystem32Cacheb19f3e84ab8a596a.fb C:WINDOWSsystem32Cachec1fa887b03019701.fb C:WINDOWSsystem32Cachec4d28dca2e7648be.fb C:WINDOWSsystem32Cached201ef9910cd39de.fb C:WINDOWSsystem32Cached2e94710a5708128.fb C:WINDOWSsystem32Cached79b9dfe81484ec4.fb C:WINDOWSsystem32Cachef998975c9cc711ee.fb C:WINDOWSsystem32DEBUG.log C:WINDOWSsystem32SET132.tmp C:WINDOWSsystem32SET136.tmp C:WINDOWSsystem32SET13E.tmp C:WINDOWSsystem32SET141.tmp C:WINDOWSsystem32tmp20.tmp C:WINDOWSsystem32tmp21.tmp ((((((((((((((((((((((((( Files Created from 2012-10-02 to 2012-11-02 ))))))))))))))))))))))))))))))) 2012-11-01 11:09:47 . 2008-04-02 14:53:50 212992 ----a-w- C:WINDOWSsystem32UniBoxVB12.ocx 2012-11-01 11:09:47 . 2008-04-02 14:53:36 880640 ----a-w- C:WINDOWSsystem32UniBox10.ocx 2012-11-01 11:09:47 . 1998-06-24 08:00:00 108336 ----a-w- C:WINDOWSsystem32MSWINSCK.OCX 2012-11-01 11:09:46 . 2008-04-02 14:54:20 1101824 ----a-w- C:WINDOWSsystem32UniBox210.ocx 2012-11-01 11:09:43 . 2012-11-02 10:51:11 -------- d-----w- C:Program FilesuGet VGI 2012-11-01 09:25:12 . 2012-11-01 09:25:12 -------- d-----w- C:Documents and SettingsXPApplication DataMalwarebytes 2012-11-01 09:24:56 . 2012-11-01 09:24:56 -------- d-----w- C:Documents and SettingsAll UsersApplication DataMalwarebytes 2012-11-01 09:24:54 . 2012-09-29 17:54:26 22856 ----a-w- C:WINDOWSsystem32driversmbam.sys 2012-11-01 09:24:53 . 2012-11-01 09:29:04 -------- d-----w- C:Program FilesMalwarebytes' Anti-Malware 2012-10-30 12:41:00 . 2012-10-30 12:41:00 -------- d-----w- C:Program FilesWinamp Detect 2012-10-30 12:40:29 . 2012-10-30 12:40:39 -------- d-----w- C:Documents and SettingsAll UsersApplication DataOrbNetworks 2012-10-30 12:40:21 . 2012-10-30 12:40:34 -------- d-----w- C:Program FilesWinamp Remote 2012-10-30 05:01:46 . 2012-10-30 05:02:00 -------- d-----w- C:Program FilesUnlocker 2012-10-27 17:22:59 . 2012-10-27 17:24:24 -------- d-----w- C:Documents and SettingsXPApplication DataOnLive App 2012-10-25 07:05:22 . 2012-10-25 07:05:22 -------- d-----w- C:Program FilesCommon FilesJava 2012-10-14 15:52:40 . 2008-12-26 09:56:04 17792 ----a-w- C:WINDOWSsystem32driversvcsvad.sys 2012-10-05 09:35:38 . 2012-10-05 09:35:38 -------- d-----w- C:Documents and SettingsAll UsersApplication DataYTD Video Downloader 2012-10-05 09:35:31 . 2012-10-05 09:35:31 -------- d-----w- C:Program FilesGreenTree Applications 2012-10-04 16:53:33 . 2012-10-04 16:53:42 -------- d-----w- C:Program FilesCCleaner . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2012-10-09 09:22:23 . 2012-04-09 05:44:29 696760 ----a-w- C:WINDOWSsystem32FlashPlayerApp.exe 2012-10-09 09:22:23 . 2012-03-28 19:07:11 73656 ----a-w- C:WINDOWSsystem32FlashPlayerCPLApp.cpl 2012-09-24 12:32:24 . 2012-07-24 14:39:21 477168 ----a-w- C:WINDOWSsystem32npdeployJava1.dll 2012-09-24 12:32:20 . 2012-04-01 09:29:16 473072 ----a-w- C:WINDOWSsystem32deployJava1.dll 2012-09-24 10:51:47 . 2012-07-24 14:39:21 73728 ----a-w- C:WINDOWSsystem32javacpl.cpl 2012-09-13 13:26:52 . 2012-09-12 06:57:42 1006448 ----a-w- C:WINDOWSsystem32dmwu.exe 2012-09-13 13:24:48 . 2012-09-12 06:57:42 28160 ----a-w- C:WINDOWSsystem32ImHttpComm.dll 2012-08-10 19:48:49 . 2012-08-10 19:48:49 444952 ----a-w- C:WINDOWSsystem32wrap_oal.dll 2012-08-10 19:48:49 . 2012-08-10 19:48:49 109080 ----a-w- C:WINDOWSsystem32OpenAL32.dll

  • Автор

ComboFix 12-11-02.02 - XP 11.2012 г. 16:33:37.2.1 - x86 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.2046.1544 [GMT 2:00] Running from: d:google chrome downloadComboFix.exe AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . ---- Previous Run ------- . c:documents and settingsAll UsersApplication DataTEMP c:documents and settingsAll UsersApplication DataTEMP{CB099890-1D5F-11D5-9EA9-0050BAE317E1}PostBuild.exe c:documents and settingsXPRecentThumbs.db c:documents and settingsXPWINDOWS C:Thumbs.db c:windowsiun6002.exe c:windowssystem32_000116_.tmp.dll c:windowssystem32Cache c:windowssystem32Cache272512937d9e61a4.fb c:windowssystem32Cache287204568329e189.fb c:windowssystem32Cache28bc8f716fd76a47.fb c:windowssystem32Cache2c53092c95605355.fb c:windowssystem32Cache31a0997e9a5b5eb3.fb c:windowssystem32Cache32c84fe32bb74d60.fb c:windowssystem32Cache3917078cb68ec657.fb c:windowssystem32Cache533a2b71bfcc6b0e.fb c:windowssystem32Cache590ba23ce359fd0c.fb c:windowssystem32Cache610289e025a3ee9a.fb c:windowssystem32Cache651c5d3cdbfb8bd1.fb c:windowssystem32Cache6c59ac5e7e7a3ad0.fb c:windowssystem32Cache6d03dad1035885d3.fb c:windowssystem32Cache841be2afcf601e39.fb c:windowssystem32Cachea8556537add6dfc5.fb c:windowssystem32Cachead10a52aff5e038d.fb c:windowssystem32Cacheb19f3e84ab8a596a.fb c:windowssystem32Cachec1fa887b03019701.fb c:windowssystem32Cachec4d28dca2e7648be.fb c:windowssystem32Cached201ef9910cd39de.fb c:windowssystem32Cached2e94710a5708128.fb c:windowssystem32Cached79b9dfe81484ec4.fb c:windowssystem32Cachef998975c9cc711ee.fb c:windowssystem32DEBUG.log c:windowssystem32SET132.tmp c:windowssystem32SET136.tmp c:windowssystem32SET13E.tmp c:windowssystem32SET141.tmp c:windowssystem32tmp20.tmp c:windowssystem32tmp21.tmp . . ((((((((((((((((((((((((( Files Created from 2012-10-02 to 2012-11-02 ))))))))))))))))))))))))))))))) . . 2012-11-02 12:13 . 2012-11-02 14:09 -------- d--h--w- c:windows$hf_mig$ 2012-11-02 12:04 . 2012-11-02 14:08 -------- d-----w- c:windowsLastGood 2012-11-01 11:09 . 2008-04-02 14:53 212992 ----a-w- c:windowssystem32UniBoxVB12.ocx 2012-11-01 11:09 . 2008-04-02 14:53 880640 ----a-w- c:windowssystem32UniBox10.ocx 2012-11-01 11:09 . 1998-06-24 08:00 108336 ----a-w- c:windowssystem32MSWINSCK.OCX 2012-11-01 11:09 . 2008-04-02 14:54 1101824 ----a-w- c:windowssystem32UniBox210.ocx 2012-11-01 11:09 . 2012-11-02 10:51 -------- d-----w- c:program filesuGet VGI 2012-11-01 09:25 . 2012-11-01 09:25 -------- d-----w- c:documents and settingsXPApplication DataMalwarebytes 2012-11-01 09:24 . 2012-11-01 09:24 -------- d-----w- c:documents and settingsAll UsersApplication DataMalwarebytes 2012-11-01 09:24 . 2012-09-29 17:54 22856 ----a-w- c:windowssystem32driversmbam.sys 2012-11-01 09:24 . 2012-11-01 09:29 -------- d-----w- c:program filesMalwarebytes' Anti-Malware 2012-10-30 12:41 . 2012-10-30 12:41 -------- d-----w- c:program filesWinamp Detect 2012-10-30 12:40 . 2012-10-30 12:40 -------- d-----w- c:documents and settingsAll UsersApplication DataOrbNetworks 2012-10-30 12:40 . 2012-10-30 12:40 -------- d-----w- c:program filesWinamp Remote 2012-10-30 05:01 . 2012-10-30 05:02 -------- d-----w- c:program filesUnlocker 2012-10-27 17:22 . 2012-10-27 17:24 -------- d-----w- c:documents and settingsXPApplication DataOnLive App 2012-10-25 07:05 . 2012-10-25 07:05 -------- d-----w- c:program filesCommon FilesJava 2012-10-14 15:52 . 2008-12-26 09:56 17792 ----a-w- c:windowssystem32driversvcsvad.sys 2012-10-05 09:35 . 2012-10-05 09:35 -------- d-----w- c:documents and settingsAll UsersApplication DataYTD Video Downloader 2012-10-05 09:35 . 2012-10-05 09:35 -------- d-----w- c:program filesGreenTree Applications 2012-10-04 16:53 . 2012-10-04 16:53 -------- d-----w- c:program filesCCleaner . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-10-09 09:22 . 2012-04-09 05:44 696760 ----a-w- c:windowssystem32FlashPlayerApp.exe 2012-10-09 09:22 . 2012-03-28 19:07 73656 ----a-w- c:windowssystem32FlashPlayerCPLApp.cpl 2012-09-24 12:32 . 2012-07-24 14:39 477168 ----a-w- c:windowssystem32npdeployJava1.dll 2012-09-24 12:32 . 2012-04-01 09:29 473072 ----a-w- c:windowssystem32deployJava1.dll 2012-09-24 10:51 . 2012-07-24 14:39 73728 ----a-w- c:windowssystem32javacpl.cpl 2012-09-13 13:26 . 2012-09-12 06:57 1006448 ----a-w- c:windowssystem32dmwu.exe 2012-09-13 13:24 . 2012-09-12 06:57 28160 ----a-w- c:windowssystem32ImHttpComm.dll 2012-08-10 19:48 . 2012-08-10 19:48 444952 ----a-w- c:windowssystem32wrap_oal.dll 2012-08-10 19:48 . 2012-08-10 19:48 109080 ----a-w- c:windowssystem32OpenAL32.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionexplorershelliconoverlayidentifiers00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOTCLSID{472083B0-C522-11CF-8763-00608CC02F24}] 2011-11-28 17:01 122512 ----a-w- c:program filesAVAST SoftwareAvastashShell.dll . [HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun] "Skype"="c:program filesSkypePhoneSkype.exe" [2012-07-13 17418928] "Orb"="c:program filesWinamp RemotebinOrbTray.exe" [2008-04-01 507904] . [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun] "NeroFilterCheck"="c:windowssystem32NeroCheck.exe" [2006-01-12 155648] "avast"="c:program filesAVAST SoftwareAvastavastUI.exe" [2011-11-28 3744552] "NvMediaCenter"="NvMCTray.dll" [2011-04-07 111208] "NvCplDaemon"="c:windowssystem32NvCpl.dll" [2011-04-07 13891176] "BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592] . [HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRun] "CTFMON.EXE"="c:windowssystem32CTFMON.EXE" [2008-04-14 15360] . [HKEY_LOCAL_MACHINEsystemcurrentcontrolsetcontrollsa] Authentication Packages REG_MULTI_SZ msv1_0 nwprovau . [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalWudfSvc] @="Service" . [HKLM~startupfolderC:^Documents and Settings^All Users^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk] path=c:documents and settingsAll UsersStart MenuProgramsStartupMcAfee Security Scan Plus.lnk backup=c:windowspssMcAfee Security Scan Plus.lnkCommon Startup . [HKLM~startupfolderC:^Documents and Settings^XP^Start Menu^Programs^Startup^Facebook Messenger.lnk] path=c:documents and settingsXPStart MenuProgramsStartupFacebook Messenger.lnk backup=c:windowspssFacebook Messenger.lnkStartup . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregAdobe ARM] 2012-07-11 19:00 919008 ----a-r- c:program filesCommon FilesAdobeARM1.0AdobeARM.exe . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregAdobe Reader Speed Launcher] 2012-07-31 11:20 38872 ----a-w- c:program filesAdobeReader 9.0Readerreader_sl.exe . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregDAEMON Tools Lite] 2012-02-13 08:06 3481408 ----a-w- c:program filesDAEMON Tools LiteDTLite.exe . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregSunJavaUpdateSched] 2012-09-17 09:41 254896 ----a-w- c:program filesCommon FilesJavaJava Updatejusched.exe . [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigservices] "McComponentHostService"=3 (0x3) "LanmanWorkstation"=2 (0x2) . [HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList] "%windir%Network Diagnosticxpnetdiag.exe"= "%windir%system32sessmgr.exe"= "c:Program FilesuTorrentuTorrent.exe"= "c:Program FilesIVT CorporationBlueSoleilBlueSoleil.exe"= "c:Program FilesIVT CorporationBlueSoleilBlueSoleilCS.exe"= "c:Program FilesSkypePhoneSkype.exe"= "c:WINDOWSsystem32dmwu.exe"= "c:WINDOWSsystem32ARFCwrtc.exe"= "c:Program FilesWinamp RemotebinOrb.exe"= "c:Program FilesWinamp RemotebinOrbTray.exe"= "c:Program FilesWinamp RemotebinOrbStreamerClient.exe"= "d:CSCounter-Strikehl.exe"= . R0 BtHidBus;Bluetooth HID Bus Service;c:windowssystem32driversBtHidBus.sys [07.1.2009 г. 22:39 20744] R1 aswSnx;aswSnx;c:windowssystem32driversaswSnx.sys [26.3.2012 г. 13:33 435032] R1 aswSP;aswSP;c:windowssystem32driversaswSP.sys [26.3.2012 г. 13:33 314456] R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:windowssystem32driversdtsoftbus01.sys [28.3.2012 г. 20:36 242240] R2 aswFsBlk;aswFsBlk;c:windowssystem32driversaswFsBlk.sys [26.3.2012 г. 13:33 20568] R2 BsMobileCS;BsMobileCS;c:program filesIVT CorporationBlueSoleilBsMobileCS.exe [27.2.2009 г. 15:40 143467] R2 MBAMScheduler;MBAMScheduler;c:program filesMalwarebytes' Anti-Malwarembamscheduler.exe [01.11.2012 г. 11:24 399432] R2 WebOptimizer;WebOptimizer;c:windowssystem32dmwu.exe [12.9.2012 г. 08:57 1006448] R3 als4k;Avance Audio Miniport Driver (WDM);c:windowssystem32driversals4000.sys [26.3.2012 г. 16:17 28919] R3 btnetBUs;Bluetooth PAN Bus Service;c:windowssystem32driversbtnetBus.sys [07.12.2008 г. 11:44 30088] R3 IvtBtBUs;IVT Bluetooth Bus Service;c:windowssystem32driversIvtBtBus.sys [02.7.2008 г. 13:58 26248] R3 MBAMProtector;MBAMProtector;c:windowssystem32driversmbam.sys [01.11.2012 г. 11:24 22856] R3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);c:windowssystem32driversvcsvad.sys [14.10.2012 г. 17:52 17792] S2 MBAMService;MBAMService;c:program filesMalwarebytes' Anti-Malwarembamservice.exe [01.11.2012 г. 11:24 676936] S2 Skype C2C Service;Skype C2C Service;c:documents and settingsAll UsersApplication DataSkypeToolbarsSkype C2C Servicec2c_service.exe [02.10.2012 г. 12:13 3064000] S2 SkypeUpdate;Skype Updater;c:program filesSkypeUpdaterUpdater.exe [13.7.2012 г. 12:28 160944] S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:windowssystem32driverstap0901t.sys [29.7.2012 г. 09:34 27136] S4 McComponentHostService;McAfee Security Scan Component Host Service;c:program filesMcAfee Security Scan3.0.207McCHSvc.exe [17.6.2011 г. 19:33 237008] S4 xqkim;Microsoft Driver;c:windowssystem32svchost.exe -k netsvcs [14.4.2008 г. 11:00 14336] . HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionSvchost - NetSvcs xqkim . Contents of the 'Scheduled Tasks' folder . 2012-11-02 c:windowsTasksAdobe Flash Player Updater.job - c:windowssystem32MacromedFlashFlashPlayerUpdateService.exe [2012-04-09 09:22] . 2012-10-28 c:windowsTasksGoogleUpdateTaskMachineCore.job - c:program filesGoogleUpdateGoogleUpdate.exe [2012-03-26 11:33] . 2012-10-28 c:windowsTasksGoogleUpdateTaskMachineUA.job - c:program filesGoogleUpdateGoogleUpdate.exe [2012-03-26 11:33] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: E&xport to Microsoft Excel - c:progra~1MICROS~2OFFICE11EXCEL.EXE/3000 TCP: DhcpNameServer = 89.215.233.2 89.215.246.40 FF - ProfilePath - c:documents and settingsXPApplication DataMozillaFirefoxProfiles1dg72ijs.default FF - prefs.js: browser.startup.homepage - hxxp://bg.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:bg:official . - - - - ORPHANS REMOVED - - - - . Toolbar-10 - (no file) Toolbar-!{977AE9CC-AF83-45E8-9E03-E2798216E2D5} - (no file) SafeBoot-WudfPf SafeBoot-WudfRd MSConfigStartUp-Facebook Update - c:documents and settingsXPLocal SettingsApplication DataFacebookUpdateFacebookUpdate.exe MSConfigStartUp-ROC_ROC_JULY_P1 - c:program filesAVG Secure SearchROC_ROC_JULY_P1.exe MSConfigStartUp-vProt - c:program filesAVG Secure Searchvprot.exe AddRemove-{4956225B-6763-4944-9B70-E31403D1DFC9} - c:documents and settingsAll UsersApplication Data{CA19C67B-273A-466C-A67A-E9467606540F}Shareaza_V8_en_Setup.exe AddRemove-{E4BB976A-A6E5-49A4-9885-A58B519C2705} - c:program files (x86)InstallShield Installation Information{E4BB976A-A6E5-49A4-9885-A58B519C2705}setup.exe AddRemove-YourFileDownloader - c:program filesYourFileDownloaderuninstall.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2012-11-02 16:43 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net Windows 5.1.2600 . CreateFile(".PHYSICALDRIVE0"): The process cannot access the file because it is being used by another process. device: opened successfully user: error reading MBR kernel: MBR read successfully user != kernel MBR !!! . ************************************************************************** . [HKEY_LOCAL_MACHINESystemControlSet001Servicesxqkim] "ServiceDll"="c:windowssystem32hwocn.dll" . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINEsoftwareClassesCLSID{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:WINDOWSsystem32MacromedFlashFlashUtil32_11_4_402_287_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINEsoftwareClassesCLSID{73C9DFA0-750D-11E1-B0C4-0800200C9A66}Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINEsoftwareClassesCLSID{73C9DFA0-750D-11E1-B0C4-0800200C9A66}LocalServer32] @="c:WINDOWSsystem32MacromedFlashFlashUtil32_11_4_402_287_ActiveX.exe" . [HKEY_LOCAL_MACHINEsoftwareClassesCLSID{73C9DFA0-750D-11E1-B0C4-0800200C9A66}TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINEsoftwareClassesInterface{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINEsoftwareClassesInterface{6AE38AE0-750C-11E1-B0C4-0800200C9A66}ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINEsoftwareClassesInterface{6AE38AE0-750C-11E1-B0C4-0800200C9A66}TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'explorer.exe'(972) c:windowssystem32msi.dll c:windowssystem32WPDShServiceObj.dll c:windowssystem32PortableDeviceTypes.dll c:windowssystem32PortableDeviceApi.dll . Completion time: 2012-11-02 16:47:36 ComboFix-quarantined-files.txt 2012-11-02 14:47 . Pre-Run: 19 332 919 296 bytes free Post-Run: 19 293 667 328 bytes free . WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)WINDOWS [operating systems] c:cmdconsBOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons UnsupportedDebug="do not select this" /debug multi(0)disk(0)rdisk(0)partition(1)WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect . - - End Of File - - 0E4FB1330E0CC76EBFF75797543E5DB3 Ето го целия тоя път не се ресна и стана :)

Супер!

Моля, влезте в www.virustotal.com и качете следния файл:

c:WINDOWSsystem32ARFCwrtc.exe

Изчакайте да се довърши анализа и публикувайте линка в следващия си пост тук.

  • Отворете notepad и с copy/paste въведете следната информация.

    KillAll::

    NetSvc::

    xqkim

    File::

    c:WINDOWSsystem32dmwu.exe

    c:windowssystem32hwocn.dll

    Registry::

    [-HKEY_LOCAL_MACHINESystemControlSet001Servicesxqkim]

    [HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]

    "c:WINDOWSsystem32dmwu.exe"=-

    JavaClearCache::

  • Запазете файла с име CFScript и го провлачете и пуснете в Combofix (както е показано на картинката отдолу).

    Публикувано изображение

  • По време на сканиране от страна на ComboFix не стартирайте никакви други приложения, не натискайте клавиши от клавиатурата и не местете мишката !
  • Публикувайте лог файла, който ще се създаде след рестарта на компютъра в следващия си пост.
  • Автор

Добре ще пиша в темата. Как трябва да изглежда сканирането както преди с тая програма защото пак почва по същия начин пита ме за онова Recovery и т.н :)

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.