Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Featured Replies

Здравейте, Предварително се извинявам за глупавия въпрос. Вчера в скайпа се появи съобщение от един от контактите ми , което съдържаше следното: Hi,really nice pic of you ? Link По погрешка кликнах върху линка, но се появи грешка 404 page not found My be link is not copied correctly В последствие се разчетох ,че има такъв тип вируси , които се разпространяват чрез скайп,но след сваляне на снимков файл.Въпроса ми е може ли компютъра да се заразил с някакъв keylogger без да са сваляни файлове? Деинсталирах скайпа,изтрих съдържанието на папка %appdata%skype и сканирах с Malwarebytes и изтрих всичко намерено.Сканирах отново с Malware и не намери нищо. Благодаря предварително и се извинявам за дългото обяснение : )

Посети темата: Системата ми е инфектирана и следвай инструкциите там. Ако има вирус, колегите ще ти помогнат да го махнеш.

Редактирано от Emokostov (преглед на промените)

  • Автор

А дали може DDS да работи без да е изключена антивирусната , тъй като не мога да я спра?

  • Автор

Ето данните

Благодаря  предварително ! :)

 

DDS

 

DDS (Ver_2011-09-30.01) - NTFS_x86 Internet Explorer: 8.0.6001.18702  BrowserJavaVersion: 10.4.1 Run by user at 12:37:57 on 2013-04-01 Microsoft Windows XP Professional  5.1.2600.3.1251.359.1033.18.3327.2631 [GMT 3:00] . AV: ESET NOD32 Antivirus 4.0 *Enabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} . ============== Running Processes ================ . C:WINDOWSsystem32Ati2evxx.exe C:WINDOWSsystem32Ati2evxx.exe C:WINDOWSsystem32spoolsv.exe C:WINDOWSExplorer.EXE C:Program FilesESETESET NOD32 Antivirusegui.exe C:WINDOWSRTHDCPL.EXE C:Program FilesLogMeInx86LogMeInSystray.exe C:Program FilesATI TechnologiesATI.ACECore-StaticMOM.exe C:Program FilesAcronisTrueImageEnterpriseServerTrueImageMonitor.exe C:Program FilesAcronisTrueImageEnterpriseServerTimounterMonitor.exe C:Program FilesCommon FilesAcronisSchedule2schedhlp.exe C:Program FilesCommon FilesAcronisSchedule2schedul2.exe C:Program FilesCommon FilesAppleMobile Device SupportAppleMobileDeviceService.exe C:Program FilesCommon FilesJavaJava Updatejusched.exe C:Program FilesiTunesiTunesHelper.exe C:WINDOWSsystem32ctfmon.exe C:Program FilesBonjourmDNSResponder.exe C:Program FilesESETESET NOD32 Antivirusekrn.exe C:Program FilesFirebirdFirebird_2_0binfbguard.exe C:Program FilesOracleJavaFX 2.1 Runtimebinjqs.exe C:Program FilesLogMeInx86LMIGuardianSvc.exe C:Program FilesLogMeInx86RaMaint.exe C:Program FilesLogMeInx86LogMeIn.exe C:Program FilesATI TechnologiesATI.ACECore-Staticccc.exe C:Program FilesCDBurnerXPNMSAccessU.exe C:Program FilesPANDORA.TVPanServicePandoraService.exe C:Program FilesCommon FilesSafeNet SentinelSentinel Protection ServerWinNTspnsrvnt.exe C:WINDOWSSystem32StkASv2K.exe C:Program FilesFirebirdFirebird_2_0binfbserver.exe C:WINDOWSsystem32wscntfy.exe C:Program FilesiPodbiniPodService.exe C:WINDOWSsystem32igfxsrvc.exe C:WINDOWSSystem32alg.exe C:WINDOWSsystem32wbemwmiprvse.exe C:WINDOWSSystem32svchost.exe -k netsvcs C:WINDOWSsystem32svchost.exe -k WudfServiceGroup C:WINDOWSsystem32svchost.exe -k NetworkService C:WINDOWSsystem32svchost.exe -k LocalService C:WINDOWSsystem32svchost.exe -k LocalService C:WINDOWSsystem32svchost.exe -k imgsvc . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.ceramicbg.com/ uInternet Connection Wizard,ShellNext = hxxp://www.irfanview.net/faq.htm BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:program filescommon filesadobeacrobatactivexAcroIEHelperShim.dll BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:program filesoraclejavafx 2.1 runtimebinssv.dll BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:program filesoraclejavafx 2.1 runtimebinjp2ssv.dll uRun: [CTFMON.EXE] c:windowssystem32ctfmon.exe uRun: [Google Update] "c:documents and settingsuserlocal settingsapplication datagoogleupdateGoogleUpdate.exe" /c mRun: [igfxTray] c:windowssystem32igfxtray.exe mRun: [HotKeysCmds] c:windowssystem32hkcmd.exe mRun: [Persistence] c:windowssystem32igfxpers.exe mRun: [egui] "c:program fileseseteset nod32 antivirusegui.exe" /hide /waitservice mRun: [RTHDCPL] RTHDCPL.EXE mRun: [JMB36X IDE Setup] c:windowsraidtoolxInsIDE.exe mRun: [36X Raid Configurer] c:windowssystem32xRaidSetup.exe boot mRun: [startCCC] "c:program filesati technologiesati.acecore-staticCLIStart.exe" MSRun mRun: [LogMeIn GUI] "c:program fileslogmeinx86LogMeInSystray.exe" mRun: [TrueImageMonitor.exe] c:program filesacronistrueimageenterpriseserverTrueImageMonitor.exe mRun: [AcronisTimounterMonitor] c:program filesacronistrueimageenterpriseserverTimounterMonitor.exe mRun: [Acronis Scheduler2 Service] "c:program filescommon filesacronisschedule2schedhlp.exe" mRun: [Adobe Reader Speed Launcher] "c:program filesadobereader 9.0readerReader_sl.exe" mRun: [Adobe ARM] "c:program filescommon filesadobearm1.0AdobeARM.exe" mRun: [sunJavaUpdateSched] "c:program filescommon filesjavajava updatejusched.exe" mRun: [APSDaemon] "c:program filescommon filesappleapple application supportAPSDaemon.exe" mRun: [iTunesHelper] "c:program filesitunesiTunesHelper.exe" mRun: [NeroFilterCheck] c:windowssystem32NeroCheck.exe dRun: [CTFMON.EXE] c:windowssystem32CTFMON.EXE StartupFolder: c:docume~1alluse~1startm~1programsstartupadobeg~1.lnk - c:program filescommon filesadobecalibrationAdobe Gamma Loader.exe uPolicies-Explorer: NoDriveTypeAutoRun = dword:145 mPolicies-WindowsSystem: Allow-LogonScript-NetbiosDisabled = dword:1 mPolicies-Explorer: NoDriveTypeAutoRun = dword:145 IE: E&xport to Microsoft Excel - c:progra~1micros~2office11EXCEL.EXE/3000 IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%Network Diagnosticxpnetdiag.exe DPF: {05CA9FB0-3E3E-4b36-BF41-0E3A5CAA8CD8} - hxxp://go.microsoft.com/fwlink/?linkid=58813 DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1320148683031 DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: Interfaces{5542D3C9-2C0E-43A2-956F-2C5DFE821C11} : NameServer = 192.168.1.10 TCP: Interfaces{B7F51181-4F12-40C2-9655-B5E0643F8972} : DHCPNameServer = 94.26.50.7 94.26.50.8 Notify: AtiExtEvent - Ati2evxx.dll Notify: igfxcui - igfxdev.dll Notify: LMIinit - LMIinit.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:windowssystem32wpdshserviceobj.dll LSA: Authentication Packages =  msv1_0 relog_ap Hosts: 192.168.1.10  user-pc Hosts: 192.168.1.11  sirius-pc2 Hosts: 74.208.10.249 gs.apple.com . ================= FIREFOX =================== . FF - ProfilePath - c:documents and settingsuserapplication datamozillafirefoxprofilesajpd3v8j.default FF - prefs.js: browser.startup.homepage - ceramicbg.com FF - prefs.js: network.proxy.type - 0 FF - plugin: c:documents and settingsuserlocal settingsapplication datagoogleupdate1.3.21.135npGoogleUpdate3.dll FF - plugin: c:program filesadobereader 9.0readerairnppdf32.dll FF - plugin: c:program filesgoogleupdate1.3.21.135npGoogleUpdate3.dll FF - plugin: c:program filesmicrosoft silverlight4.1.10329.0npctrlui.dll FF - plugin: c:program filesoraclejavafx 2.1 runtimebinplugin2npjp2.dll FF - plugin: c:windowssystem32macromedflashNPSWF32_11_6_602_180.dll FF - plugin: c:windowssystem32npDeployJava1.dll FF - plugin: c:windowssystem32npptools.dll . ============= SERVICES / DRIVERS =============== . R0 Stealth;Stealth;c:windowssystem32driversstealth.sys [2002-5-13 77920] R1 ehdrv;ehdrv;c:windowssystem32driversehdrv.sys [2009-2-6 106208] R1 epfwtdir;epfwtdir;c:windowssystem32driversepfwtdir.sys [2009-2-6 93336] R2 ekrn;ESET Service;c:program fileseseteset nod32 antivirusekrn.exe [2009-2-6 727720] R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:program filesfirebirdfirebird_2_0binfbguard.exe -s --> c:program filesfirebirdfirebird_2_0binfbguard.exe -s [?] R2 LMIGuardianSvc;LMIGuardianSvc;c:program fileslogmeinx86LMIGuardianSvc.exe [2011-9-26 374704] R2 LMIInfo;LogMeIn Kernel Information Provider;c:program fileslogmeinx86rainfo.sys [2011-9-16 12856] R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:windowssystem32driversLMIRfsDriver.sys [2011-10-31 47640] R2 PanService;PandoraService;c:program filespandora.tvpanservicePandoraService.exe [2012-11-5 625816] R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:windowssystem32driversAtihdXP3.sys [2011-10-31 101904] R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:program filesfirebirdfirebird_2_0binfbserver.exe -s --> c:program filesfirebirdfirebird_2_0binfbserver.exe -s [?] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:windowsmicrosoft.netframeworkv4.0.30319mscorsvw.exe [2010-3-18 130384] S2 gupdate;Услуга Google Update (gupdate);c:program filesgoogleupdateGoogleUpdate.exe [2010-3-3 135664] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:windowssystem32macromedflashFlashPlayerUpdateService.exe [2012-12-19 253656] S3 Ambfilt;Ambfilt;c:windowssystem32driversAmbfilt.sys [2010-3-3 1684736] S3 gupdatem;Услуга на Google Актуализация (gupdatem);c:program filesgoogleupdateGoogleUpdate.exe [2010-3-3 135664] S3 MozillaMaintenance;Mozilla Maintenance Service;c:program filesmozilla maintenance servicemaintenanceservice.exe [2012-5-2 115608] S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:windowssystem32driversnmwcdnsu.sys [2012-8-27 137600] S3 nmwcdnsuc;Nokia USB Flashing Generic;c:windowssystem32driversnmwcdnsuc.sys [2012-8-27 8576] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:windowsmicrosoft.netframeworkv4.0.30319wpfWPFFontCache_v0400.exe [2010-3-18 753504] S4 LMIRfsClientNP;LMIRfsClientNP; [x] . =============== Created Last 30 ================ . . ==================== Find3M  ==================== . 2013-03-13 07:14:29  73432  ----a-w-  c:windowssystem32FlashPlayerCPLApp.cpl 2013-03-13 07:14:29  693976  ----a-w-  c:windowssystem32FlashPlayerApp.exe . ============= FINISH: 12:38:17.64 ===============  

 

Attach

 

. UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-09-30.01) . Microsoft Windows XP Professional Boot Device: DeviceHarddiskVolume1 Install Date: 03-03-2010 11:27:03 System Uptime: 01-04-2013 08:23:46 (4 hours ago) . Motherboard: ASUSTeK Computer INC. |  | P5QL-E Processor: Intel Pentium III Xeon processor | LGA775 | 2333/333mhz . ==== Disk Partitions ========================= . A: is Removable C: is FIXED (NTFS) - 146 GiB total, 7.982 GiB free. D: is FIXED (NTFS) - 319 GiB total, 131.851 GiB free. E: is FIXED (NTFS) - 75 GiB total, 74.463 GiB free. F: is CDROM () G: is CDROM () . ==== Disabled Device Manager Items ============= . Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318} Description: Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller Device ID: PCIVEN_1969&DEV_1026&SUBSYS_83041043&REV_B04&20515DB1&0&00E5 Manufacturer: Atheros Name: Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller PNP Device ID: PCIVEN_1969&DEV_1026&SUBSYS_83041043&REV_B04&20515DB1&0&00E5 Service: L1e . Class GUID: Description: Device ID: ACPIATK01101010110 Manufacturer: Name: PNP Device ID: ACPIATK01101010110 Service: . Class GUID: {EEC5AD98-8080-425F-922A-DABF3DE3F69A} Description: Nokia E71 Device ID: ROOTWPD0000 Manufacturer: Nokia Name: Nokia E71 PNP Device ID: ROOTWPD0000 Service: WUDFRd . ==== System Restore Points =================== . No restore point in system. . ==== Installed Programs ====================== . Acronis True Image Enterprise Server Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 11 Plugin Adobe Photoshop 7.0 Adobe Reader 9.5.2 Ahead.Nero v9.4.13.2 Apple Application Support Apple Mobile Device Support Apple Software Update ATI Catalyst Install Manager Avanquest update BDE Bonjour Canon CanoScan Toolbox 4.9 Canon ScanGear Starter Catalyst Control Center - Branding Catalyst Control Center InstallProxy Catalyst Control Center Localization All ccc-core-static ccc-utility CCC Help Chinese Standard CCC Help Chinese Traditional CCC Help Czech CCC Help Danish CCC Help Dutch CCC Help English CCC Help Finnish CCC Help French CCC Help German CCC Help Greek CCC Help Hungarian CCC Help Italian CCC Help Japanese CCC Help Korean CCC Help Norwegian CCC Help Polish CCC Help Portuguese CCC Help Russian CCC Help Spanish CCC Help Swedish CCC Help Thai CCC Help Turkish CDBurnerXP Compatibility Pack for the 2007 Office system DAEMON Tools doPDF 7.3 printer ESET NOD32 Antivirus Firebird 2.0.3 Google Chrome Google Update Helper Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Windows Media Player 11 (KB935957) Hotfix for Windows Media Player 11 (KB950478) Hotfix for Windows XP (KB2443685) Hotfix for Windows XP (KB932716-v2) Hotfix for Windows XP (KB942288-v3) Hotfix for Windows XP (KB944043-v3) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB954708) Hotfix for Windows XP (KB958655-v2) Hotfix for Windows XP (KB969084) Hotfix for Windows XP (KB970653-v3) Intel® Graphics Media Accelerator Driver IrfanView (remove only) iTunes Java Auto Updater Java 7 Update 4 JavaFX 2.1.0 JMicron JMB36X Driver LogMeIn Malwarebytes Anti-Malware version 1.70.0.1100 Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 4 Client Profile Microsoft .NET Framework 4 Extended Microsoft Base Smart Card Cryptographic Service Provider Package Microsoft Kernel-Mode Driver Framework Feature Pack 1.9 Microsoft Office 2003 Proofing Tools Microsoft Office Professional Edition 2003 Microsoft Silverlight Microsoft Software Update for Web Folders  (English) 12 Microsoft User-Mode Driver Framework Feature Pack 1.9 Mozilla Firefox 19.0.2 (x86 bg) Mozilla Maintenance Service Mozilla Thunderbird 17.0.4 (x86 en-US) MSVC90_x86 MSXML 4.0 SP3 Parser (KB973685) MultiViewer Nero 7 Premium Nokia Connectivity Cable Driver Pandora Service PC Connectivity Solution Phonetic Cyrillic for Windows 2000 v1.0 PhotoScape Plan-IQ 2.6 REALTEK GbE & FE Ethernet PCI-E NIC Driver Realtek High Definition Audio Driver SA Dictionary 2008 Beta 4 Security Update for CAPICOM (KB931906) Security Update for Windows Internet Explorer 7 (KB938127-v2) Security Update for Windows Internet Explorer 7 (KB972260) Security Update for Windows Internet Explorer 8 (KB2416400) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2121546) Security Update for Windows XP (KB2124261) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2259922) Security Update for Windows XP (KB2286198) Security Update for Windows XP (KB2290570) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2296199) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2436673) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953155) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955417) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371-v2) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB970483) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975254) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981852) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982665) Sentinel Protection Installer 7.3.0 Skins Software Update for Web Folders Spelling Dictionaries Support For Adobe Reader 9 Update for Microsoft Windows (KB971513) Update for Windows Internet Explorer 8 (KB2447568) Update for Windows Internet Explorer 8 (KB976662) Update for Windows XP (KB2141007) Update for Windows XP (KB2345886) Update for Windows XP (KB2467659) Update for Windows XP (KB898461) Update for Windows XP (KB951618-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955704) Update for Windows XP (KB955759) Update for Windows XP (KB958752) Update for Windows XP (KB961503) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971029) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) USB2.0 Capture Device Windows Driver Package - Nokia pccsmcfd “LegacyDriver”  (05/31/2012 7.1.2.0) Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 8 Windows XP Service Pack 3 WinRAR archiver . ==== Event Viewer Messages From Past Week ======== . 30-03-2013 11:56:38, error: Service Control Manager [7038]  - The SSDPSRV service was unable to log on as NT AUTHORITYLocalService with the currently configured password due to the following error:  Access is denied. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC). 30-03-2013 11:56:38, error: Service Control Manager [7000]  - The SSDP Discovery Service service failed to start due to the following error:  The service did not start due to a logon failure. 01-04-2013 08:14:44, error: Service Control Manager [7034]  - The Firebird Guardian - DefaultInstance service terminated unexpectedly.  It has done this 1 time(s). 01-04-2013 08:14:44, error: Service Control Manager [7031]  - The Microsoft .NET Framework NGEN v4.0.30319_X86 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service. . ==== End Of File ===========================  

Здравейте..!От предоставените дневници не се виждат активни зарази..!
 
Публикувано изображение Изтеглете Malwarebytes' Anti-Malware или от тук (не забравяйте да обновите програмата с нови дефиниции)
* Кликнете два пъти върху mbam-setup.exe, за да инсталирате програмата.
* Уверете се, че са поставени отметки на Update Malwarebytes' Anti-Malware и Launch Malwarebytes' Anti-Malware. След това кликнете на Finish.
* Ако има намерени обновявания, тя ще ги изтегли и инсталира.
* Стартирайте програмата и изберете "Perform Full Scan", след това кликнете на Scan.
* Сканирането ще отнеме малко време, затова моля да бъдете търпеливи.
* Когато сканирането завърши, кликнете на OK, след това Show Results, за да видите резултата
* Уверете се, че на всички редове има отметки, и кликнете на Remove Selected.
* Когато всичко бъде премахнато, в Notepad ще бъде отворен лог.
Копирайте този лог и го публикувайте в следващия си коментар по темата.
 
  Забележка: Ако MalwareBytes' Anti-Malware се затрудни в премахването на откритите вируси/заплахи, той ще поиска да рестартира компютъра Ви и по време на рестартирането да премахне проблемните вируси/заплахи. Ако бъдете попитани, потвърдете че желаете вашия компютър да бъде рестартиран.

Извинявам се за забавянето, но имах лични ангажименти. Моля продължете с колегата до приключване на темата. Благодаря и се извинявам за причиненото неудобство. :)

  • Автор

Malwarebytes Anti-Malware 1.70.0.1100 www.malwarebytes.org Database version: v2013.04.02.04 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 user :: SIRIUS-PC1 [administrator] 02-04-2013 08:43 mbam-log-2013-04-02 (08-43-39).txt Scan type: Full scan (C:|D:|E:|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 828842 Time elapsed: 2 hour(s), 25 minute(s), 33 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)  

Ето данните от Malware , мисля че всичко е наред .

Ето данните от Malware , мисля че всичко е наред .

 

 

И аз така мисля... :) Да направим още нещо:

 

Публикувано изображение Изтеглете OTL (от OldTimer) и го запазете на вашия десктоп.

Кликнете два пъти върху OTL.exe, за да стартирате програмата.

Сложете отметки преди следните неща:

[*]Scan all users

[*]Lop check

[*]Purity check

Под секцията Extra Registry, изберете Use SafeList

Кликнете на Run Scan и изчакайте да завърши сканирането. (може да отнеме 10-15 минути)

Когато завърши, публикувайте следните два лог файла:

[*]OTL.txt (намира се на вашия десктоп)

[*]Extras.txt (ще Ви се отвори автоматично).

 

 

Публикувано изображение Изтеглете Security Check (автор: screen317) от тук или от тук и го запишете на десктопа.

[*]Кликнете два пъти върху SecurityCheck.exe и следвайте инструкциите.

[*]Когато програмата завърши работата си, ще се отвори един текстов документ: checkup.txt.

[*]Копирайте съдържанието на checkup.txt с Копирай (Copy) и с Постави (Paste) го поставете в следващия си коментар.

  • Автор

OTL logfile created on: 03-04-2013 14:01:37 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:Documents and SettingsuserMy DocumentsDownloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd-MM-yyyy
 
3.25 Gb Total Physical Memory | 2.45 Gb Available Physical Memory | 75.32% Memory free
4.58 Gb Paging File | 3.93 Gb Available in Paging File | 85.88% Paging File free
Paging file location(s): C:pagefile.sys 1524 3048 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:WINDOWS | %ProgramFiles% = C:Program Files
Drive C: | 146.48 Gb Total Space | 7.02 Gb Free Space | 4.79% Space Free | Partition Type: NTFS
Drive D: | 319.28 Gb Total Space | 131.07 Gb Free Space | 41.05% Space Free | Partition Type: NTFS
Drive E: | 74.53 Gb Total Space | 74.46 Gb Free Space | 99.91% Space Free | Partition Type: NTFS
 
Computer Name: SIRIUS-PC1 | User Name: user | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2013-04-03 13:53:25 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:Documents and SettingsuserMy DocumentsDownloadsOTL.exe
PRC - [2013-03-08 14:27:55 | 000,917,400 | ---- | M] (Mozilla Corporation) -- C:Program FilesMozilla Firefoxfirefox.exe
PRC - [2012-11-09 09:34:23 | 000,137,136 | ---- | M] (LogMeIn, Inc.) -- C:Program FilesLogMeInx86ramaint.exe
PRC - [2012-11-09 09:33:54 | 000,374,704 | ---- | M] (LogMeIn, Inc.) -- C:Program FilesLogMeInx86LMIGuardianSvc.exe
PRC - [2012-06-22 11:32:12 | 000,625,816 | ---- | M] (Pandora.TV) -- C:Program FilesPANDORA.TVPanServicePandoraService.exe
PRC - [2012-04-04 18:47:32 | 000,161,664 | ---- | M] (Oracle Corporation) -- C:Program FilesOracleJavaFX 2.1 Runtimebinjqs.exe
PRC - [2011-09-16 16:10:50 | 000,390,528 | ---- | M] (LogMeIn, Inc.) -- C:Program FilesLogMeInx86LogMeIn.exe
PRC - [2011-09-16 16:10:50 | 000,063,048 | ---- | M] (LogMeIn, Inc.) -- C:Program FilesLogMeInx86LogMeInSystray.exe
PRC - [2010-03-04 23:38:00 | 000,071,096 | ---- | M] () -- C:Program FilesCDBurnerXPNMSAccessU.exe
PRC - [2009-02-06 15:23:36 | 000,727,720 | ---- | M] (ESET) -- C:Program FilesESETESET NOD32 Antivirusekrn.exe
PRC - [2009-02-06 15:23:12 | 002,021,400 | ---- | M] (ESET) -- C:Program FilesESETESET NOD32 Antivirusegui.exe
PRC - [2008-04-14 06:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:WINDOWSexplorer.exe
PRC - [2007-09-03 18:13:54 | 000,081,920 | ---- | M] (FirebirdSQL Project) -- C:Program FilesFirebirdFirebird_2_0binfbguard.exe
PRC - [2007-09-03 18:13:48 | 002,002,944 | ---- | M] (FirebirdSQL Project) -- C:Program FilesFirebirdFirebird_2_0binfbserver.exe
PRC - [2006-07-21 01:15:32 | 001,848,218 | ---- | M] (Acronis) -- C:Program FilesAcronisTrueImageEnterpriseServerTimounterMonitor.exe
PRC - [2006-07-21 01:13:48 | 000,126,976 | ---- | M] (Acronis) -- C:Program FilesCommon FilesAcronisSchedule2schedhlp.exe
PRC - [2006-07-21 01:13:42 | 000,204,800 | ---- | M] (Acronis) -- C:Program FilesCommon FilesAcronisSchedule2schedul2.exe
PRC - [2006-07-21 01:12:18 | 001,106,531 | ---- | M] (Acronis) -- C:Program FilesAcronisTrueImageEnterpriseServerTrueImageMonitor.exe
PRC - [2006-05-24 00:49:14 | 000,024,576 | ---- | M] (Syntek America Inc.) -- C:WINDOWSsystem32StkASv2K.exe
PRC - [2006-05-07 08:30:00 | 000,206,400 | ---- | M] (SafeNet, Inc) -- C:Program FilesCommon FilesSafeNet SentinelSentinel Protection ServerWinNTspnsrvnt.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2013-03-13 10:14:28 | 014,717,144 | ---- | M] () -- C:WINDOWSsystem32MacromedFlashNPSWF32_11_6_602_180.dll
MOD - [2013-03-08 14:27:54 | 003,069,848 | ---- | M] () -- C:Program FilesMozilla Firefoxmozjs.dll
MOD - [2012-07-31 04:08:04 | 000,016,872 | ---- | M] () -- C:Program FilesAdobeReader 9.0ReaderViewerPS.dll
MOD - [2012-07-09 18:59:06 | 001,277,952 | ---- | M] () -- C:Program FilesPANDORA.TVPanServiceavformat-53.dll
MOD - [2012-07-09 18:57:30 | 002,090,496 | ---- | M] () -- C:Program FilesPANDORA.TVPanServiceavcodec-53.dll
MOD - [2012-05-30 20:06:48 | 000,087,912 | ---- | M] () -- C:Program FilesCommon FilesAppleApple Application Supportzlib1.dll
MOD - [2012-05-30 20:06:30 | 001,242,512 | ---- | M] () -- C:Program FilesCommon FilesAppleApple Application Supportlibxml2.dll
MOD - [2012-03-23 11:07:34 | 000,224,768 | ---- | M] () -- C:Program FilesPANDORA.TVPanServicelibupnp.dll
MOD - [2011-12-06 17:19:48 | 000,133,632 | ---- | M] () -- C:Program FilesPANDORA.TVPanServiceavutil-51.dll
MOD - [2011-11-01 16:17:01 | 011,791,360 | ---- | M] () -- C:WINDOWSassemblyNativeImages_v2.0.50727_32System.Web50ea744ffc3cb7f09b027fd6c5c93b2bSystem.Web.ni.dll
MOD - [2011-11-01 16:15:57 | 000,970,752 | ---- | M] () -- C:WINDOWSassemblyNativeImages_v2.0.50727_32System.Configurationcb4cb21d14767292e079366a5d3d76cdSystem.Configuration.ni.dll
MOD - [2011-11-01 16:15:52 | 000,025,600 | ---- | M] () -- C:WINDOWSassemblyNativeImages_v2.0.50727_32Accessibilityc2af7cfbb47c077029a2645930b4eeacAccessibility.ni.dll
MOD - [2011-11-01 15:36:10 | 005,449,728 | ---- | M] () -- C:WINDOWSassemblyNativeImages_v2.0.50727_32System.Xml36f3953f24d4f0b767bf172331ad6f3eSystem.Xml.ni.dll
MOD - [2011-11-01 15:36:06 | 012,428,800 | ---- | M] () -- C:WINDOWSassemblyNativeImages_v2.0.50727_32System.Windows.Forms9a254c455892c02355ab0ab0f0727c5bSystem.Windows.Forms.ni.dll
MOD - [2011-11-01 15:35:56 | 001,587,200 | ---- | M] () -- C:WINDOWSassemblyNativeImages_v2.0.50727_32System.Drawing6978f2e90f13bc720d57fa6895c911e2System.Drawing.ni.dll
MOD - [2011-11-01 15:32:07 | 007,867,392 | ---- | M] () -- C:WINDOWSassemblyNativeImages_v2.0.50727_32Systemaa7926460a336408c8041330ad90929dSystem.ni.dll
MOD - [2011-11-01 15:32:00 | 011,485,184 | ---- | M] () -- C:WINDOWSassemblyNativeImages_v2.0.50727_32mscorlib9adb89fa22fd5b4ce433b5aca7fb1b07mscorlib.ni.dll
MOD - [2011-11-01 15:30:03 | 000,303,104 | ---- | M] () -- C:WINDOWSassemblyGAC_MSILSystem.Runtime.Remoting2.0.0.0__b77a5c561934e089System.Runtime.Remoting.dll
MOD - [2010-09-30 23:36:20 | 000,270,336 | ---- | M] () -- C:Program FilesATI TechnologiesATI.ACECore-StaticCLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
MOD - [2010-04-12 17:59:06 | 000,430,080 | R--- | M] () -- C:Program FilesATI TechnologiesATI.ACEBrandingBranding.dll
MOD - [2010-03-16 13:22:12 | 000,014,848 | ---- | M] () -- C:Program FilesATI TechnologiesATI.ACECore-StaticAxInterop.WBOCXLib.dll
MOD - [2010-03-04 23:38:00 | 000,071,096 | ---- | M] () -- C:Program FilesCDBurnerXPNMSAccessU.exe
MOD - [2008-04-14 06:42:00 | 000,014,336 | ---- | M] () -- C:WINDOWSsystem32msdmo.dll
MOD - [2006-07-21 01:11:52 | 000,045,056 | ---- | M] () -- C:Program FilesCommon FilesAcronisCommonrpc_client.dll
 
 
========== Services (SafeList) ==========
 
SRV - [2013-03-13 10:14:29 | 000,253,656 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:WINDOWSsystem32MacromedFlashFlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013-03-08 14:27:55 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:Program FilesMozilla Maintenance Servicemaintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012-11-09 09:34:23 | 000,137,136 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:Program FilesLogMeInx86ramaint.exe -- (LMIMaint)
SRV - [2012-11-09 09:33:54 | 000,374,704 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:Program FilesLogMeInx86LMIGuardianSvc.exe -- (LMIGuardianSvc)
SRV - [2012-06-22 11:32:12 | 000,625,816 | ---- | M] (Pandora.TV) [Auto | Running] -- C:Program FilesPANDORA.TVPanServicePandoraService.exe -- (PanService)
SRV - [2012-06-11 11:33:26 | 000,724,376 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:Program FilesPC Connectivity SolutionServiceLayer.exe -- (ServiceLayer)
SRV - [2012-04-04 18:47:32 | 000,161,664 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:Program FilesOracleJavaFX 2.1 Runtimebinjqs.exe -- (JavaQuickStarterService)
SRV - [2011-09-16 16:10:50 | 000,390,528 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:Program FilesLogMeInx86LogMeIn.exe -- (LogMeIn)
SRV - [2010-03-04 23:38:00 | 000,071,096 | ---- | M] () [Auto | Running] -- C:Program FilesCDBurnerXPNMSAccessU.exe -- (NMSAccess)
SRV - [2009-02-06 15:27:06 | 000,020,680 | ---- | M] (ESET) [On_Demand | Stopped] -- C:Program FilesESETESET NOD32 AntivirusEHttpSrv.exe -- (EhttpSrv)
SRV - [2009-02-06 15:23:36 | 000,727,720 | ---- | M] (ESET) [Auto | Running] -- C:Program FilesESETESET NOD32 Antivirusekrn.exe -- (ekrn)
SRV - [2007-09-03 18:13:54 | 000,081,920 | ---- | M] (FirebirdSQL Project) [Auto | Running] -- C:Program FilesFirebirdFirebird_2_0binfbguard.exe -- (FirebirdGuardianDefaultInstance)
SRV - [2007-09-03 18:13:48 | 002,002,944 | ---- | M] (FirebirdSQL Project) [On_Demand | Running] -- C:Program FilesFirebirdFirebird_2_0binfbserver.exe -- (FirebirdServerDefaultInstance)
SRV - [2006-07-21 01:13:42 | 000,204,800 | ---- | M] (Acronis) [Auto | Running] -- C:Program FilesCommon FilesAcronisSchedule2schedul2.exe -- (AcrSch2Svc)
SRV - [2006-05-24 00:49:14 | 000,024,576 | ---- | M] (Syntek America Inc.) [Auto | Running] -- C:WINDOWSsystem32StkASv2K.exe -- (StkASSrv)
SRV - [2006-05-07 08:30:00 | 000,206,400 | ---- | M] (SafeNet, Inc) [Auto | Running] -- C:Program FilesCommon FilesSafeNet SentinelSentinel Protection ServerWinNTspnsrvnt.exe -- (SentinelProtectionServer)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] --  -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] --  -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- system32driversInCDRm.sys -- (InCDRm)
DRV - File not found [Kernel | System | Stopped] -- system32driversInCDPass.sys -- (InCDPass)
DRV - File not found [File_System | Disabled | Stopped] -- system32driversInCDFs.sys -- (InCDFs)
DRV - File not found [Kernel | System | Stopped] --  -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] --  -- (Changer)
DRV - [2012-11-09 09:33:55 | 000,083,912 | ---- | M] (LogMeIn, Inc.) [File_System | Disabled | Stopped] -- C:WINDOWSSystem32LMIRfsClientNP.dll -- (LMIRfsClientNP)
DRV - [2012-06-11 11:33:46 | 000,019,072 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:WINDOWSsystem32driverspccsmcfd.sys -- (pccsmcfd)
DRV - [2012-01-09 17:28:20 | 000,137,600 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:WINDOWSsystem32driversnmwcdnsu.sys -- (nmwcdnsu)
DRV - [2012-01-09 17:28:20 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:WINDOWSsystem32driversccdcmbo.sys -- (nmwcdc)
DRV - [2012-01-09 17:28:20 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:WINDOWSsystem32driversccdcmb.sys -- (nmwcd)
DRV - [2012-01-09 17:28:20 | 000,008,576 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:WINDOWSsystem32driversnmwcdnsuc.sys -- (nmwcdnsuc)
DRV - [2012-01-09 17:28:20 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:WINDOWSsystem32driversusbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2012-01-09 17:28:20 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:WINDOWSsystem32driversusbser_lowerflt.sys -- (upperdev)
DRV - [2011-11-01 15:40:43 | 000,388,000 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:WINDOWSsystem32driverstimntr.sys -- (timounter)
DRV - [2011-11-01 15:40:43 | 000,032,288 | ---- | M] (Acronis) [File_System | Auto | Running] -- C:WINDOWSsystem32driverstifsfilt.sys -- (tifsfilter)
DRV - [2011-11-01 15:40:39 | 000,099,776 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:WINDOWSsystem32driverssnapman.sys -- (snapman)
DRV - [2011-09-16 16:10:50 | 000,047,640 | ---- | M] (LogMeIn, Inc.) [File_System | Auto | Running] -- C:WINDOWSsystem32driversLMIRfsDriver.sys -- (LMIRfsDriver)
DRV - [2011-09-16 16:10:50 | 000,012,856 | ---- | M] (LogMeIn, Inc.) [Kernel | Auto | Running] -- C:Program FilesLogMeInx86rainfo.sys -- (LMIInfo)
DRV - [2010-09-28 23:23:40 | 005,425,152 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:WINDOWSsystem32driversati2mtag.sys -- (ati2mtag)
DRV - [2010-08-19 07:41:58 | 000,101,904 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] -- C:WINDOWSsystem32driversAtihdXP3.sys -- (AtiHDAudioService)
DRV - [2009-11-27 16:20:06 | 000,177,152 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:WINDOWSsystem32driversRtenicxp.sys -- (RTLE8023xp)
DRV - [2009-11-12 14:48:56 | 000,005,504 | ---- | M] () [File_System | Auto | Running] -- C:WINDOWSSystem32driversStarOpen.sys -- (StarOpen)
DRV - [2009-10-05 14:25:38 | 005,870,080 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:WINDOWSsystem32driversRtkHDAud.sys -- (IntcAzAudAddService)
DRV - [2009-10-05 14:24:38 | 001,389,056 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:WINDOWSsystem32driversMonfilt.sys -- (Monfilt)
DRV - [2009-10-05 14:24:04 | 001,684,736 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:WINDOWSsystem32driversAmbfilt.sys -- (Ambfilt)
DRV - [2009-08-05 07:16:44 | 000,039,424 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:WINDOWSsystem32driversl1e51x86.sys -- (L1e)
DRV - [2009-02-06 15:24:24 | 000,093,336 | ---- | M] (ESET) [Kernel | System | Running] -- C:WINDOWSsystem32driversepfwtdir.sys -- (epfwtdir)
DRV - [2009-02-06 15:23:18 | 000,106,208 | ---- | M] (ESET) [Kernel | System | Running] -- C:WINDOWSsystem32driversehdrv.sys -- (ehdrv)
DRV - [2009-02-06 15:19:52 | 000,113,448 | ---- | M] (ESET) [File_System | Auto | Running] -- C:WINDOWSsystem32driverseamon.sys -- (eamon)
DRV - [2008-11-22 00:10:40 | 000,082,784 | ---- | M] (JMicron Technology Corp.) [Kernel | Boot | Running] -- C:WINDOWSsystem32driversjraid.sys -- (JRAID)
DRV - [2008-04-13 23:05:40 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:WINDOWSsystem32driversRTL8139.sys -- (rtl8139)
DRV - [2007-07-20 19:40:10 | 000,084,992 | ---- | M] (ATI Research Inc.) [Kernel | On_Demand | Stopped] -- C:WINDOWSsystem32driversAtiHdmi.sys -- (AtiHdmiService)
DRV - [2006-11-15 17:32:44 | 000,242,139 | ---- | M] (Syntek America Inc.) [Kernel | On_Demand | Stopped] -- C:WINDOWSsystem32driversStkAMini.sys -- (StkAMini)
DRV - [2006-06-27 18:27:18 | 000,004,772 | ---- | M] (Syntek America Inc.) [Kernel | On_Demand | Stopped] -- C:WINDOWSsystem32driversStkScan.sys -- (StkScan)
DRV - [2006-05-07 08:30:00 | 000,090,688 | ---- | M] (SafeNet, Inc.) [Kernel | Auto | Running] -- C:WINDOWSsystem32driverssentinel.sys -- (Sentinel)
DRV - [2002-05-13 11:14:38 | 000,077,920 | ---- | M] (Generic) [Kernel | Boot | Running] -- C:WINDOWSsystem32driversstealth.sys -- (Stealth)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM..SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM..SearchScopes{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
 
 
IE - HKU.DEFAULTSOFTWAREMicrosoftInternet ExplorerMain,AlwaysUseDefaultPrinter = yes
IE - HKU.DEFAULTSoftwareMicrosoftWindowsCurrentVersionInternet Settings: "ProxyEnable" = 0
 
IE - HKUS-1-5-18SOFTWAREMicrosoftInternet ExplorerMain,AlwaysUseDefaultPrinter = yes
IE - HKUS-1-5-18SoftwareMicrosoftWindowsCurrentVersionInternet Settings: "ProxyEnable" = 0
 
IE - HKUS-1-5-19SOFTWAREMicrosoftInternet ExplorerMain,AlwaysUseDefaultPrinter = yes
 
IE - HKUS-1-5-20SOFTWAREMicrosoftInternet ExplorerMain,AlwaysUseDefaultPrinter = yes
 
IE - HKUS-1-5-21-725345543-1897051121-1801674531-1003SOFTWAREMicrosoftInternet ExplorerMain,AlwaysUseDefaultPrinter = yes
IE - HKUS-1-5-21-725345543-1897051121-1801674531-1003SOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://www.ceramicbg.com/
IE - HKUS-1-5-21-725345543-1897051121-1801674531-1003..SearchScopes,DefaultScope = {EE9A4D8B-B382-4F50-926B-7B5A35CD5B59}
IE - HKUS-1-5-21-725345543-1897051121-1801674531-1003..SearchScopes{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
IE - HKUS-1-5-21-725345543-1897051121-1801674531-1003..SearchScopes{EE9A4D8B-B382-4F50-926B-7B5A35CD5B59}: "URL" = http://www.google.co.uk/search?hl=en&q={searchTerms}&meta=
IE - HKUS-1-5-21-725345543-1897051121-1801674531-1003SoftwareMicrosoftWindowsCurrentVersionInternet Settings: "ProxyEnable" = 0
IE - HKUS-1-5-21-725345543-1897051121-1801674531-1003SoftwareMicrosoftWindowsCurrentVersionInternet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.startup.homepage: "ceramicbg.com"
FF - prefs.js..extensions.enabledAddons: %7B317B5128-0B0B-49b2-B2DB-1E7560E16C74%7D:2.8.8
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
 
FF - [email protected]/FlashPlayer: C:WINDOWSsystem32MacromedFlashNPSWF32_11_6_602_180.dll ()
FF - [email protected]/iTunes,version=:  File not found
FF - [email protected]/iTunes,version=1.0: C:Program FilesiTunesMozilla Pluginsnpitunes.dll ()
FF - [email protected]/DTPlugin,version=10.4.1: C:WINDOWSsystem32npDeployJava1.dll (Oracle Corporation)
FF - [email protected]/JavaPlugin,version=10.4.1: C:Program FilesOracleJavaFX 2.1 Runtimebinplugin2npjp2.dll (Oracle Corporation)
FF - [email protected]/NpCtrl,version=1.0: C:Program FilesMicrosoft Silverlight4.1.10329.0npctrl.dll ( Microsoft Corporation)
FF - [email protected]/WPF,version=3.5: C:WINDOWSMicrosoft.NETFrameworkv3.5Windows Presentation FoundationNPWPF.dll (Microsoft Corporation)
FF - [email protected]/Google Update;version=3: C:Program FilesGoogleUpdate1.3.21.135npGoogleUpdate3.dll (Google Inc.)
FF - [email protected]/Google Update;version=9: C:Program FilesGoogleUpdate1.3.21.135npGoogleUpdate3.dll (Google Inc.)
FF - HKLMSoftwareMozillaPluginsAdobe Reader: C:Program FilesAdobeReader 9.0ReaderAIRnppdf32.dll (Adobe Systems Inc.)
FF - [email protected]/Google Update;version=3: C:Documents and SettingsuserLocal SettingsApplication DataGoogleUpdate1.3.21.135npGoogleUpdate3.dll (Google Inc.)
FF - [email protected]/Google Update;version=9: C:Documents and SettingsuserLocal SettingsApplication DataGoogleUpdate1.3.21.135npGoogleUpdate3.dll (Google Inc.)
 
FF - HKEY_LOCAL_MACHINEsoftwaremozillaMozilla Firefox 19.0.2extensionsComponents: C:Program FilesMozilla Firefoxcomponents [2013-03-08 14:27:55 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINEsoftwaremozillaMozilla Firefox 19.0.2extensionsPlugins: C:Program FilesMozilla Firefoxplugins [2013-03-08 14:27:47 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINEsoftwaremozillaMozilla Thunderbird 17.0.4extensionsComponents: C:Program FilesMozilla Thunderbirdcomponents [2013-03-12 09:28:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINEsoftwaremozillaMozilla Thunderbird 17.0.4extensionsPlugins: C:Program FilesMozilla Thunderbirdplugins
FF - HKEY_LOCAL_MACHINEsoftwaremozillaThunderbirdExtensionseplgTb@eset.com: C:Program FilesESETESET NOD32 AntivirusMozilla Thunderbird [2010-03-03 14:53:24 | 000,000,000 | ---D | M]
 
[2011-12-06 20:24:18 | 000,000,000 | ---D | M] (No name found) -- C:Documents and SettingsuserApplication DataMozillaExtensions
[2013-02-19 19:17:22 | 000,000,000 | ---D | M] (No name found) -- C:Documents and SettingsuserApplication DataMozillaFirefoxProfilesajpd3v8j.defaultextensions
[2013-02-19 19:17:22 | 000,000,000 | ---D | M] (SeoQuake) -- C:Documents and SettingsuserApplication DataMozillaFirefoxProfilesajpd3v8j.defaultextensions{317B5128-0B0B-49b2-B2DB-1E7560E16C74}
[2013-03-29 19:04:28 | 000,000,000 | ---D | M] (No name found) -- C:Program FilesMozilla Firefoxextensions
[2013-03-08 14:27:55 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:Program Filesmozilla firefoxcomponentsbrowsercomps.dll
[2012-01-13 10:15:17 | 000,001,083 | ---- | M] () -- C:Program Filesmozilla firefoxsearchplugins911bg.xml
[2012-01-13 10:15:17 | 000,002,442 | ---- | M] () -- C:Program Filesmozilla firefoxsearchpluginsdiribg.xml
[2012-01-13 10:15:17 | 000,001,515 | ---- | M] () -- C:Program Filesmozilla firefoxsearchpluginspe-bg.xml
[2012-01-13 10:15:17 | 000,001,857 | ---- | M] () -- C:Program Filesmozilla firefoxsearchpluginsportalbgdict.xml
[2012-01-13 10:15:17 | 000,001,220 | ---- | M] () -- C:Program Filesmozilla firefoxsearchpluginswikipedia-bg.xml
 
========== Chrome  ==========
 
CHR - homepage: http://www.google.com
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter}
CHR - homepage: http://www.google.com
CHR - plugin: Shockwave Flash (Enabled) = C:Documents and SettingsuserLocal SettingsApplication DataGoogleChromeApplication24.0.1312.57gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:WINDOWSsystem32MacromedFlashNPSWF32.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:Program FilesAdobeReader 9.0ReaderBrowsernppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:Program FilesMicrosoft Silverlight4.0.60831.0npctrl.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:Program FilesWindows Media Playernpdsplay.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:Documents and SettingsuserLocal SettingsApplication DataGoogleChromeApplication24.0.1312.57ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:Documents and SettingsuserLocal SettingsApplication DataGoogleChromeApplication24.0.1312.57pdf.dll
CHR - plugin: Microsoftu00AE DRM (Enabled) = C:Program FilesWindows Media Playernpdrmv2.dll
CHR - plugin: Microsoftu00AE DRM (Enabled) = C:Program FilesWindows Media Playernpwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:Documents and SettingsuserLocal SettingsApplication DataGoogleUpdate1.3.21.79npGoogleUpdate3.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:Program FilesGoogleGoogle Earthpluginnpgeplugin.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:WINDOWSMicrosoft.NETFrameworkv3.5Windows Presentation FoundationNPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:Documents and SettingsuserLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsblpcfgokakmgnkcojhhkbfbldkacnbeo4.2.5_0
CHR - Extension: YouTube = C:Documents and SettingsuserLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsblpcfgokakmgnkcojhhkbfbldkacnbeo4.2.5_1
CHR - Extension: Google u0422u044Au0440u0441u0435u043Du0435 = C:Documents and SettingsuserLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionscoobgpohoikkiipiblmjeljniedjpjpf0.0.0.19_0
CHR - Extension: Google u0422u044Au0440u0441u0435u043Du0435 = C:Documents and SettingsuserLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionscoobgpohoikkiipiblmjeljniedjpjpf0.0.0.19_1
CHR - Extension: Gmail = C:Documents and SettingsuserLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionspjkljhegncpnkpknbcohdijeoejaedia7_0
CHR - Extension: Gmail = C:Documents and SettingsuserLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionspjkljhegncpnkpknbcohdijeoejaedia7_1
 
O1 HOSTS File: ([2013-02-26 16:03:34 | 000,000,809 | ---- | M]) - C:WINDOWSsystem32driversetchosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 192.168.1.10  user-pc
O1 - Hosts: 192.168.1.11  sirius-pc2
O1 - Hosts: 74.208.10.249 gs.apple.com
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesOracleJavaFX 2.1 Runtimebinssv.dll (Oracle Corporation)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:Program FilesOracleJavaFX 2.1 Runtimebinjp2ssv.dll (Oracle Corporation)
O4 - HKLM..Run: [36X Raid Configurer] C:WINDOWSSystem32xRaidSetup.exe (JMicron Technology Corp.)
O4 - HKLM..Run: [Acronis Scheduler2 Service] C:Program FilesCommon FilesAcronisSchedule2schedhlp.exe (Acronis)
O4 - HKLM..Run: [AcronisTimounterMonitor] C:Program FilesAcronisTrueImageEnterpriseServerTimounterMonitor.exe (Acronis)
O4 - HKLM..Run: [APSDaemon] C:Program FilesCommon FilesAppleApple Application SupportAPSDaemon.exe (Apple Inc.)
O4 - HKLM..Run: [egui] C:Program FilesESETESET NOD32 Antivirusegui.exe (ESET)
O4 - HKLM..Run: [JMB36X IDE Setup] C:WINDOWSRaidToolxInsIDE.exe ()
O4 - HKLM..Run: [LogMeIn GUI] C:Program FilesLogMeInx86LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..Run: [startCCC] C:Program FilesATI TechnologiesATI.ACECore-StaticCLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..Run: [TrueImageMonitor.exe] C:Program FilesAcronisTrueImageEnterpriseServerTrueImageMonitor.exe (Acronis)
O4 - Startup: C:Documents and SettingsAll UsersStart MenuProgramsStartupAdobe Gamma Loader.lnk = C:Program FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe (Adobe Systems, Inc.)
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: HonorAutoRunSetting = 1
O7 - HKU.DEFAULTSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveTypeAutoRun = 145
O7 - HKUS-1-5-18SOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveTypeAutoRun = 145
O7 - HKUS-1-5-19SOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveTypeAutoRun = 145
O7 - HKUS-1-5-20SOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveTypeAutoRun = 145
O7 - HKUS-1-5-21-725345543-1897051121-1801674531-1003SOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5Catalog_Entries000000000004 [] - C:Program FilesBonjourmdnsNSP.dll (Apple Inc.)
O16 - DPF: {05CA9FB0-3E3E-4b36-BF41-0E3A5CAA8CD8} http://go.microsoft.com/fwlink/?linkid=58813 (Office Genuine Advantage Validation Tool)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1320148683031 (MUWebControl Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLMSystemCCSServicesTcpipParametersInterfaces{5542D3C9-2C0E-43A2-956F-2C5DFE821C11}: NameServer = 192.168.1.10
O17 - HKLMSystemCCSServicesTcpipParametersInterfaces{B7F51181-4F12-40C2-9655-B5E0643F8972}: DhcpNameServer = 94.26.50.7 94.26.50.8
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:WINDOWSexplorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:WINDOWSsystem32userinit.exe) - C:WINDOWSsystem32userinit.exe (Microsoft Corporation)
O20 - WinlogonNotifyAtiExtEvent: DllName - (Ati2evxx.dll) - C:WINDOWSSystem32ati2evxx.dll (ATI Technologies Inc.)
O20 - WinlogonNotifyLMIinit: DllName - (LMIinit.dll) - C:WINDOWSSystem32LMIinit.dll (LogMeIn, Inc.)
O24 - Desktop WallPaper: C:Documents and SettingsuserLocal SettingsApplication DataMicrosoftWallpaper1.bmp
O24 - Desktop BackupWallPaper: C:Documents and SettingsuserLocal SettingsApplication DataMicrosoftWallpaper1.bmp
O30 - LSA: Authentication Packages - (relog_ap) - C:WINDOWSSystem32relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010-03-03 12:24:51 | 000,000,000 | ---- | M] () - C:AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM..comfile [open] -- "%1" %*
O35 - HKLM..exefile [open] -- "%1" %*
O37 - HKLM...com [@ = comfile] -- "%1" %*
O37 - HKLM...exe [@ = exefile] -- "%1" %*
O38 - SubSystemsWindows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystemsWindows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013-03-20 17:18:01 | 000,000,000 | ---D | C] -- C:Documents and SettingsuserDesktopcvetni vidima
[2013-03-15 16:58:15 | 000,000,000 | ---D | C] -- C:Documents and SettingsuserDesktopargo m bani
[2013-03-12 09:28:16 | 000,000,000 | ---D | C] -- C:Program FilesMozilla Thunderbird
[2013-03-08 14:27:45 | 000,000,000 | ---D | C] -- C:Program FilesMozilla Firefox
[7 C:WINDOWS*.tmp files -> C:WINDOWS*.tmp -> ]
[1 C:WINDOWSSystem32*.tmp files -> C:WINDOWSSystem32*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2013-04-03 13:46:00 | 000,000,982 | ---- | M] () -- C:WINDOWStasksGoogleUpdateTaskMachineUA.job
[2013-04-03 13:17:00 | 000,001,074 | ---- | M] () -- C:WINDOWStasksGoogleUpdateTaskUserS-1-5-21-725345543-1897051121-1801674531-1003UA.job
[2013-04-03 13:14:00 | 000,000,830 | ---- | M] () -- C:WINDOWStasksAdobe Flash Player Updater.job
[2013-04-03 09:46:00 | 000,000,978 | ---- | M] () -- C:WINDOWStasksGoogleUpdateTaskMachineCore.job
[2013-04-03 09:21:05 | 000,002,206 | ---- | M] () -- C:WINDOWSSystem32wpa.dbl
[2013-04-03 09:21:02 | 000,002,048 | --S- | M] () -- C:WINDOWSbootstat.dat
[2013-04-02 15:07:37 | 000,002,443 | ---- | M] () -- C:Documents and SettingsAll UsersDesktopSA Dictionary 2008 Beta 4.lnk
[2013-04-02 09:51:48 | 000,118,330 | ---- | M] () -- C:Documents and SettingsuserMy Documentsrazni.pdf
[2013-04-02 09:18:33 | 000,002,301 | ---- | M] () -- C:Documents and SettingsuserApplication DataMicrosoftInternet ExplorerQuick LaunchGoogle Chrome.lnk
[2013-04-02 09:18:32 | 000,002,283 | ---- | M] () -- C:Documents and SettingsuserDesktopGoogle Chrome.lnk
[2013-04-02 09:17:02 | 000,001,022 | ---- | M] () -- C:WINDOWStasksGoogleUpdateTaskUserS-1-5-21-725345543-1897051121-1801674531-1003Core.job
[2013-04-01 16:23:14 | 000,036,363 | ---- | M] () -- C:WINDOWSCSTBox.INI
[2013-04-01 13:06:36 | 000,065,562 | ---- | M] () -- C:Documents and SettingsuserMy DocumentsIMG_1213.jpg
[2013-04-01 13:06:36 | 000,064,593 | ---- | M] () -- C:Documents and SettingsuserMy DocumentsIMG_1214.jpg
[2013-04-01 13:06:36 | 000,063,779 | ---- | M] () -- C:Documents and SettingsuserMy DocumentsIMG_1215.jpg
[2013-04-01 13:06:36 | 000,063,748 | ---- | M] () -- C:Documents and SettingsuserMy DocumentsIMG_1216.jpg
[2013-04-01 11:24:01 | 000,000,284 | ---- | M] () -- C:WINDOWStasksAppleSoftwareUpdate.job
[2013-04-01 08:15:48 | 000,495,518 | ---- | M] () -- C:WINDOWSSystem32perfh009.dat
[2013-04-01 08:15:48 | 000,084,106 | ---- | M] () -- C:WINDOWSSystem32perfc009.dat
[2013-03-29 11:57:01 | 000,013,030 | ---- | M] () -- C:PDOXUSRS.NET
[2013-03-26 11:30:42 | 000,000,116 | ---- | M] () -- C:WINDOWSNeroDigital.ini
[2013-03-25 18:21:06 | 061,333,568 | ---- | M] () -- C:Documents and SettingsAll UsersDocumentsTalon korigiean.tif
[2013-03-22 16:28:21 | 002,248,846 | ---- | M] () -- C:Documents and SettingsAll UsersDocumentsUntitled-1 copy.gif
[2013-03-22 16:27:52 | 062,483,796 | ---- | M] () -- C:Documents and SettingsAll UsersDocumentsUntitled-1.tif
[2013-03-22 16:20:25 | 000,703,042 | ---- | M] () -- C:Documents and SettingsAll UsersDocumentsUntitled-7.tif
[2013-03-18 10:16:11 | 000,284,079 | ---- | M] () -- C:Documents and SettingsuserMy DocumentsCI for panel saw-Tracy.jpg
[2013-03-13 10:14:29 | 000,693,976 | ---- | M] (Adobe Systems Incorporated) -- C:WINDOWSSystem32FlashPlayerApp.exe
[2013-03-13 10:14:29 | 000,073,432 | ---- | M] (Adobe Systems Incorporated) -- C:WINDOWSSystem32FlashPlayerCPLApp.cpl
[2013-03-11 17:44:04 | 000,029,028 | ---- | M] () -- C:Documents and SettingsuserDesktopfaians sea of ibiza.jpg
[2013-03-11 17:40:23 | 000,046,146 | ---- | M] () -- C:Documents and SettingsuserDesktopfaians nero mar.jpg
[2013-03-07 12:18:50 | 000,913,909 | ---- | M] () -- C:Documents and SettingsuserMy DocumentsDsGr-listovka-Rodas-A5.pdf
[2013-03-07 09:47:09 | 007,738,261 | ---- | M] () -- C:Documents and SettingsuserMy DocumentsDogovor Eko Bul Pak 2009.pdf
[2013-03-05 11:11:17 | 008,397,808 | ---- | M] () -- C:Documents and SettingsuserMy DocumentsHan Omurtag 2012.pdf
[2013-03-05 10:54:33 | 012,087,794 | ---- | M] () -- C:Documents and SettingsuserMy DocumentsHan Asparuh 2012.pdf
[2013-03-04 15:20:18 | 000,179,686 | ---- | M] () -- C:Documents and SettingsuserMy DocumentsCred.pdf
[7 C:WINDOWS*.tmp files -> C:WINDOWS*.tmp -> ]
[1 C:WINDOWSSystem32*.tmp files -> C:WINDOWSSystem32*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2013-04-02 12:57:16 | 000,823,308 | ---- | C] () -- C:Documents and SettingsuserDesktopCatalog San porcelan.pdf
[2013-04-02 09:51:47 | 000,118,330 | ---- | C] () -- C:Documents and SettingsuserMy Documentsrazni.pdf
[2013-03-28 16:04:01 | 001,741,234 | ---- | C] () -- C:Documents and SettingsAll UsersDocumentsFaqns 4 ka4..pdf
[2013-03-28 14:51:06 | 000,063,748 | ---- | C] () -- C:Documents and SettingsuserMy DocumentsIMG_1216.jpg
[2013-03-28 14:50:58 | 000,063,779 | ---- | C] () -- C:Documents and SettingsuserMy DocumentsIMG_1215.jpg
[2013-03-28 13:55:16 | 000,064,593 | ---- | C] () -- C:Documents and SettingsuserMy DocumentsIMG_1214.jpg
[2013-03-28 13:55:06 | 000,065,562 | ---- | C] () -- C:Documents and SettingsuserMy DocumentsIMG_1213.jpg
[2013-03-25 13:24:47 | 061,333,568 | ---- | C] () -- C:Documents and SettingsAll UsersDocumentsTalon korigiean.tif
[2013-03-22 16:28:31 | 002,248,846 | ---- | C] () -- C:Documents and SettingsAll UsersDocumentsUntitled-1 copy.gif
[2013-03-22 16:28:30 | 062,483,796 | ---- | C] () -- C:Documents and SettingsAll UsersDocumentsUntitled-1.tif
[2013-03-22 16:13:26 | 000,703,042 | ---- | C] () -- C:Documents and SettingsAll UsersDocumentsUntitled-7.tif
[2013-03-18 10:15:59 | 000,284,079 | ---- | C] () -- C:Documents and SettingsuserMy DocumentsCI for panel saw-Tracy.jpg
[2013-03-11 17:44:04 | 000,029,028 | ---- | C] () -- C:Documents and SettingsuserDesktopfaians sea of ibiza.jpg
[2013-03-11 17:40:23 | 000,046,146 | ---- | C] () -- C:Documents and SettingsuserDesktopfaians nero mar.jpg
[2013-03-07 12:18:48 | 000,913,909 | ---- | C] () -- C:Documents and SettingsuserMy DocumentsDsGr-listovka-Rodas-A5.pdf
[2013-03-07 09:46:58 | 007,738,261 | ---- | C] () -- C:Documents and SettingsuserMy DocumentsDogovor Eko Bul Pak 2009.pdf
[2013-03-05 11:11:07 | 008,397,808 | ---- | C] () -- C:Documents and SettingsuserMy DocumentsHan Omurtag 2012.pdf
[2013-03-05 10:54:21 | 012,087,794 | ---- | C] () -- C:Documents and SettingsuserMy DocumentsHan Asparuh 2012.pdf
[2013-03-04 15:20:16 | 000,179,686 | ---- | C] () -- C:Documents and SettingsuserMy DocumentsCred.pdf
[2013-02-27 14:47:31 | 000,013,680 | ---- | C] () -- C:Documents and Settingsusercontacts joro
[2013-02-27 14:41:12 | 000,027,209 | ---- | C] () -- C:Documents and SettingsuserApplication DataPersonal Address Book.ADR
[2012-11-05 15:50:18 | 000,000,116 | ---- | C] () -- C:WINDOWSNeroDigital.ini
[2012-08-29 12:15:59 | 000,039,788 | -H-- | C] () -- C:WINDOWSSystem32mlfcache.dat
[2012-03-07 10:30:26 | 000,004,608 | ---- | C] () -- C:Documents and SettingsuserLocal SettingsApplication DataDCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011-12-08 09:55:15 | 000,000,113 | ---- | C] () -- C:WINDOWSMFCKINF.dll
[2011-12-08 09:55:15 | 000,000,026 | ---- | C] () -- C:WINDOWSMFCKSYS.dll
[2011-11-09 19:31:50 | 000,036,363 | ---- | C] () -- C:WINDOWSCSTBox.INI
[2011-11-02 09:20:46 | 000,000,056 | -H-- | C] () -- C:WINDOWSSystem32ezsidmv.dat
[2011-11-01 15:51:35 | 000,005,504 | ---- | C] () -- C:WINDOWSSystem32driversStarOpen.sys
[2011-11-01 15:30:54 | 000,356,824 | ---- | C] () -- C:Documents and SettingsLocalServiceLocal SettingsApplication DataFontCache3.0.0.0.dat
[2011-10-31 14:44:07 | 000,000,000 | ---- | C] () -- C:WINDOWSativpsrm.bin
[2011-10-31 14:04:47 | 000,887,724 | ---- | C] () -- C:WINDOWSSystem32ativva6x.dat
[2011-10-31 14:04:47 | 000,224,342 | ---- | C] () -- C:WINDOWSSystem32atiicdxx.dat
[2011-10-31 14:04:47 | 000,000,003 | ---- | C] () -- C:WINDOWSSystem32ativva5x.dat
[2011-10-31 13:29:35 | 000,001,769 | ---- | C] () -- C:WINDOWSLanguage_trs.ini
 
========== ZeroAccess Check ==========
 
[2011-11-01 15:30:01 | 000,000,227 | RHS- | M] () -- C:WINDOWSassemblyDesktop.ini
 
[HKEY_CURRENT_USERSoftwareClassesclsid{42aedc87-2188-41fd-b9a3-0c966feabec1}InProcServer32]
 
[HKEY_CURRENT_USERSoftwareClassesclsid{fbeb8a05-beee-4442-804e-409d6c4515e9}InProcServer32]
 
[HKEY_LOCAL_MACHINESoftwareClassesclsid{42aedc87-2188-41fd-b9a3-0c966feabec1}InProcServer32]
"" = %SystemRoot%system32shdocvw.dll -- [2008-04-14 06:42:06 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINESoftwareClassesclsid{5839FCA9-774D-42A1-ACDA-D6A79037F57F}InProcServer32]
"" = C:WINDOWSsystem32wbemfastprox.dll -- [2009-02-09 13:56:35 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINESoftwareClassesclsid{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}InProcServer32]
"" = C:WINDOWSsystem32wbemwbemess.dll -- [2008-04-14 06:42:10 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
========== LOP Check ==========
 
[2012-09-19 11:11:20 | 000,000,000 | ---D | M] -- C:Documents and SettingsAll UsersApplication Data188F1432-103A-4ffb-80F1-36B633C5C9E1
[2011-11-01 15:54:16 | 000,000,000 | ---D | M] -- C:Documents and SettingsAll UsersApplication DataAcronis
[2012-08-28 09:12:53 | 000,000,000 | ---D | M] -- C:Documents and SettingsAll UsersApplication DataAvanquest
[2012-08-28 09:11:52 | 000,000,000 | ---D | M] -- C:Documents and SettingsAll UsersApplication DataBVRP Software
[2011-12-06 10:31:26 | 000,000,000 | ---D | M] -- C:Documents and SettingsAll UsersApplication DataCanneverbe Limited
[2012-08-28 09:37:54 | 000,000,000 | -H-D | M] -- C:Documents and SettingsAll UsersApplication DataCommon Files
[2010-03-03 14:53:23 | 000,000,000 | ---D | M] -- C:Documents and SettingsAll UsersApplication DataESET
[2012-08-27 17:53:57 | 000,000,000 | ---D | M] -- C:Documents and SettingsAll UsersApplication DataInstallations
[2013-04-03 09:21:30 | 000,000,000 | ---D | M] -- C:Documents and SettingsAll UsersApplication DataLogMeIn
[2012-08-27 17:56:17 | 000,000,000 | ---D | M] -- C:Documents and SettingsAll UsersApplication DataPC Suite
[2011-12-15 17:10:03 | 000,000,000 | ---D | M] -- C:Documents and SettingsAll UsersApplication DataTEMP
[2012-08-28 09:38:20 | 000,000,000 | ---D | M] -- C:Documents and SettingsAll UsersApplication DataTuneUp Software
[2012-08-28 09:37:54 | 000,000,000 | -HSD | M] -- C:Documents and SettingsAll UsersApplication Data{32364CEA-7855-4A3C-B674-53D8E9B97936}
[2012-08-27 17:33:47 | 000,000,000 | ---D | M] -- C:Documents and SettingsAll UsersApplication Data{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011-11-01 15:41:14 | 000,000,000 | ---D | M] -- C:Documents and SettingsLocalServiceApplication DataSoftland
[2011-12-06 10:31:26 | 000,000,000 | ---D | M] -- C:Documents and SettingsuserApplication DataCanneverbe Limited
[2011-11-04 15:43:25 | 000,000,000 | ---D | M] -- C:Documents and SettingsuserApplication DataCanon
[2011-12-09 10:23:58 | 000,000,000 | ---D | M] -- C:Documents and SettingsuserApplication DataCustomStartUp
[2012-08-28 11:20:48 | 000,000,000 | ---D | M] -- C:Documents and SettingsuserApplication DataMyPhoneExplorer
[2012-08-27 17:56:19 | 000,000,000 | ---D | M] -- C:Documents and SettingsuserApplication DataNokia
[2012-08-28 09:37:29 | 000,000,000 | ---D | M] -- C:Documents and SettingsuserApplication DataOpenCandy
[2012-05-17 18:18:24 | 000,000,000 | ---D | M] -- C:Documents and SettingsuserApplication DataOracle
[2012-08-27 17:56:20 | 000,000,000 | ---D | M] -- C:Documents and SettingsuserApplication DataPC Suite
[2012-09-13 11:33:10 | 000,000,000 | ---D | M] -- C:Documents and SettingsuserApplication DataPhotoScape
[2011-11-01 15:41:14 | 000,000,000 | ---D | M] -- C:Documents and SettingsuserApplication DataSoftland
[2011-10-31 15:18:45 | 000,000,000 | ---D | M] -- C:Documents and SettingsuserApplication DataThunderbird
[2012-08-28 09:38:05 | 000,000,000 | ---D | M] -- C:Documents and SettingsuserApplication DataTuneUp Software
 
========== Purity Check ==========
 
 

< End of report >
 


OTL Extras logfile created on: 03-04-2013 14:01:37 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:Documents and SettingsuserMy DocumentsDownloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd-MM-yyyy
 
3.25 Gb Total Physical Memory | 2.45 Gb Available Physical Memory | 75.32% Memory free
4.58 Gb Paging File | 3.93 Gb Available in Paging File | 85.88% Paging File free
Paging file location(s): C:pagefile.sys 1524 3048 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:WINDOWS | %ProgramFiles% = C:Program Files
Drive C: | 146.48 Gb Total Space | 7.02 Gb Free Space | 4.79% Space Free | Partition Type: NTFS
Drive D: | 319.28 Gb Total Space | 131.07 Gb Free Space | 41.05% Space Free | Partition Type: NTFS
Drive E: | 74.53 Gb Total Space | 74.46 Gb Free Space | 99.91% Space Free | Partition Type: NTFS
 
Computer Name: SIRIUS-PC1 | User Name: user | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINESOFTWAREClasses<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
 
[HKEY_USERSS-1-5-21-725345543-1897051121-1801674531-1003SOFTWAREClasses<extension>]
.html [@ = FirefoxHTML] -- C:Program FilesMozilla Firefoxfirefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINESOFTWAREClasses<key>shell[command]command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%system32rundll32.exe %SystemRoot%system32shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoring]
 
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringAhnlabAntiVirus]
 
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringComputerAssociatesAntiVirus]
 
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringKasperskyAntiVirus]
 
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringMcAfeeAntiVirus]
 
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringMcAfeeFirewall]
 
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringPandaAntiVirus]
 
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringPandaFirewall]
 
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringSophosAntiVirus]
 
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringSymantecAntiVirus]
 
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringSymantecFirewall]
 
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringTinyFirewall]
 
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringTrendAntiVirus]
 
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringTrendFirewall]
 
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringZoneLabsFirewall]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionSystemRestore]
"DisableSR" = 1
 
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSr]
"Start" = 4
 
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSrService]
"Start" = 2
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyDomainProfile]
 
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyDomainProfileGloballyOpenPortsList]
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
 
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileGloballyOpenPortsList]
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyDomainProfileAuthorizedApplicationsList]
"%windir%Network Diagnosticxpnetdiag.exe" = %windir%Network Diagnosticxpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"%windir%system32sessmgr.exe" = %windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList]
"%windir%Network Diagnosticxpnetdiag.exe" = %windir%Network Diagnosticxpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"%windir%system32sessmgr.exe" = %windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"C:Program FilesAcronisTrueImageEnterpriseServerTrueImage.exe" = C:Program FilesAcronisTrueImageEnterpriseServerTrueImage.exe:*:Enabled:TrueImage -- (Acronis)
"C:Program FilesSkypePlugin ManagerskypePM.exe" = C:Program FilesSkypePlugin ManagerskypePM.exe:*:Enabled:Skype Extras Manager
"C:Program FilestrademanagerAliIM.exe" = C:Program FilestrademanagerAliIM.exe:*:Enabled:AliIM
"C:Program FilesCommon FilesSafeNet SentinelSentinel Protection ServerWinNTspnsrvnt.exe" = C:Program FilesCommon FilesSafeNet SentinelSentinel Protection ServerWinNTspnsrvnt.exe:*:Disabled:Sentinel Protection Server -- (SafeNet, Inc)
"C:Program FilesBonjourmDNSResponder.exe" = C:Program FilesBonjourmDNSResponder.exe:*:Enabled:Bonjour Service -- (Apple Inc.)
"C:Program FilesCommon FilesAppleApple Application SupportWebKit2WebProcess.exe" = C:Program FilesCommon FilesAppleApple Application SupportWebKit2WebProcess.exe:*:Enabled:WebKit -- (Apple Inc.)
"C:Program FilesiTunesiTunes.exe" = C:Program FilesiTunesiTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
"C:Program FilesGenSoftSklad.exe" = C:Program FilesGenSoftSklad.exe:*:Enabled:Sklad.exe -- ()
"C:Program FilesPANDORA.TVPanServicePandoraService.exe" = C:Program FilesPANDORA.TVPanServicePandoraService.exe:*:Enabled:PandoraService -- (Pandora.TV)
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{02E24DA0-3CE5-E505-C47C-EDA70E236725}" = ccc-utility
"{055A5AF0-9FEB-440D-B00A-18935C7C171C}" = SA Dictionary 2008 Beta 4
"{05E3F75A-031A-D9BA-6043-8AA9296F2A9F}" = CCC Help Polish
"{061F4697-30D9-35A2-F0A9-80F26AC91F5D}" = CCC Help Russian
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0F5AFA78-4446-4B85-17A3-029AFC09B6D6}" = CCC Help Korean
"{0F6F6876-6334-4977-B5DD-CFC12E193420}" = iTunes
"{1111706F-666A-4037-7777-210328764D10}" = JavaFX 2.1.0
"{18A5DFF2-8A95-49F3-873F-743CB5549F3D}" = Canon ScanGear Starter
"{1B339913-4259-A059-8F62-3C43E72A1BAC}" = Catalyst Control Center Localization All
"{22A8C70A-ECE2-A355-E814-F1C50152B132}" = CCC Help Japanese
"{26A24AE4-039D-4CA4-87B4-2F83217004FF}" = Java 7 Update 4
"{378F9A62-061E-4368-AA0A-1BA004772E98}" = Acronis True Image Enterprise Server
"{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = JMicron JMB36X Driver
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{404C18ED-873A-4191-BA03-30F627445418}" = Sentinel Protection Installer 7.3.0
"{46CF6A90-7EFB-47E3-9B14-FBCEFA9F9982}" = Catalyst Control Center - Branding
"{4781569D-5404-1F26-4B2B-6DF444441031}" = Nero 7 Premium
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E0C8E5B-F6CF-F5CA-8925-E5E18C548AC1}" = CCC Help Italian
"{4FCA7FCE-F100-19C9-9026-D9FE7105EC10}" = CCC Help Hungarian
"{63EC2120-1742-4625-AA47-C6A8AEC9C64C}" = Apple Application Support
"{644F4910-E812-49AD-93EC-86828CB81A0D}" = PC Connectivity Solution
"{6F1C4640-81A4-1C28-9959-2ABDD97BBCC0}" = CCC Help Swedish
"{71D247DF-D472-1890-1256-A6D420874381}" = CCC Help Finnish
"{75ECCEE0-6A8A-D6EF-8BBE-EE5A2B3E9D37}" = CCC Help Danish
"{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}" = Avanquest update
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7A34F050-4ABE-8BDB-4ABE-F3B649173F34}" = ccc-core-static
"{7CCEBC24-62DB-4280-A8EC-BFA49F167920}" = Software Update for Web Folders
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{84FE7924-A218-4823-0AEC-6355EE253558}" = CCC Help Chinese Traditional
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D371E4E-9828-164F-8F5B-0213C3234502}" = CCC Help Turkish
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders  (English) 12
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{901F0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Proofing Tools
"{92F33F18-4387-58AB-7139-266A8FBD403A}" = CCC Help Greek
"{94A7D275-E658-4B29-8C7F-2AAEF6CF453F}" = DAEMON Tools
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A57025CC-5F2E-4D01-B387-06DB10500D43}" = Nokia Connectivity Cable Driver
"{A7F24C1E-9225-4A53-17DF-67E779CBB90F}" = CCC Help Dutch
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.2
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{B9C8276B-85AF-3DC1-1FF7-DB44C95C20AD}" = CCC Help Thai
"{BA7B13B2-D0A9-B4F8-CB34-C300C3AF843D}" = Skins
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C715F7E4-3979-B3FF-1376-0E49DB93104D}" = CCC Help Chinese Standard
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CA9BCD4D-B782-4637-8F1F-F9A328D3C244}" = Canon CanoScan Toolbox 4.9
"{CDF97135-7FD2-4289-96B8-DD4505267ACD}" = ESET NOD32 Antivirus
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE58CC8D-CCF4-8D4F-BD04-9AC4A32FA1DB}" = CCC Help English
"{D4DDFAA1-EC37-4529-AD5B-A433ADE68662}" = Apple Mobile Device Support
"{E217A3D4-2FF9-4D5F-9C20-1386E0FF9864}" = LogMeIn
"{E3058BA4-8B3B-412F-31DC-20808B72CFFF}" = CCC Help Spanish
"{E337B156-DF81-48D8-8977-B1574EE87BCF}" = USB2.0 Capture Device
"{E33F1EAC-7E12-E03F-5153-C2FD4FA12ADF}" = CCC Help Norwegian
"{E5DA9F4F-2469-6900-0B03-ED81A377C689}" = CCC Help Portuguese
"{E65A75EE-F973-FC6B-E2F8-8ABDAF17EB09}" = Catalyst Control Center InstallProxy
"{E92659F8-D1DD-C854-FEBC-457A28DAE81C}" = CCC Help French
"{F03B1E0E-9AC5-6913-0019-DB50B88523DD}" = ATI Catalyst Install Manager
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F8FE7AEA-0BF4-4116-A4E7-4229F6CB3DEA}" = CCC Help German
"{FC189B64-CDDA-D0B8-6731-780622D2F8FD}" = CCC Help Czech
"17D063A0A9F5D5A225B76B1D9BCB5ADBE85C8382" = Windows Driver Package - Nokia pccsmcfd “LegacyDriver”  (05/31/2012 7.1.2.0)
"4F6D5E84-5826-4394-9F40-3A9A19165651_is1" = Pandora Service
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Ahead.Nero_is1" = Ahead.Nero v9.4.13.2
"BDE" = BDE
"BGPHO-WIN2K_is1" = Phonetic Cyrillic for Windows 2000 v1.0
"doPDF 7 printer_is1" = doPDF 7.3 printer
"FBDBServer_2_0_is1" = Firebird 2.0.3
"HDMI" = Intel® Graphics Media Accelerator Driver
"ie8" = Windows Internet Explorer 8
"IrfanView" = IrfanView (remove only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Mozilla Firefox 19.0.2 (x86 bg)" = Mozilla Firefox 19.0.2 (x86 bg)
"Mozilla Thunderbird 17.0.4 (x86 en-US)" = Mozilla Thunderbird 17.0.4 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MultiViewer Ver 2.0_is1" = MultiViewer
"PhotoScape" = PhotoScape
"Plan-IQ 2.6" = Plan-IQ 2.6
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"Wudf01009" = Microsoft User-Mode Driver Framework Feature Pack 1.9
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERSS-1-5-21-725345543-1897051121-1801674531-1003SOFTWAREMicrosoftWindowsCurrentVersionUninstall]
"Google Chrome" = Google Chrome
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 08-03-2013 10:38:23 | Computer Name = SIRIUS-PC1 | Source = PandoraService.exe | ID = 0
Description =
 
Error - 08-03-2013 11:34:27 | Computer Name = SIRIUS-PC1 | Source = PandoraService.exe | ID = 0
Description =
 
Error - 09-03-2013 04:26:35 | Computer Name = SIRIUS-PC1 | Source = Application Error | ID = 1000
Description = Faulting application skype.exe, version 5.1.0.104, faulting module
 jscript.dll, version 5.8.6001.22960, fault address 0x000152c3.
 
Error - 12-03-2013 02:42:19 | Computer Name = SIRIUS-PC1 | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 19.0.2.4814, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
 
Error - 13-03-2013 02:22:11 | Computer Name = SIRIUS-PC1 | Source = PandoraService.exe | ID = 0
Description =
 
Error - 16-03-2013 07:50:48 | Computer Name = SIRIUS-PC1 | Source = Application Hang | ID = 1002
Description = Hanging application Sklad.exe, version 0.0.0.0, hang module hungapp,
 version 0.0.0.0, hang address 0x00000000.
 
Error - 16-03-2013 07:52:36 | Computer Name = SIRIUS-PC1 | Source = Application Hang | ID = 1002
Description = Hanging application Sklad.exe, version 0.0.0.0, hang module hungapp,
 version 0.0.0.0, hang address 0x00000000.
 
Error - 16-03-2013 07:52:37 | Computer Name = SIRIUS-PC1 | Source = Application Hang | ID = 1002
Description = Hanging application Sklad.exe, version 0.0.0.0, hang module hungapp,
 version 0.0.0.0, hang address 0x00000000.
 
Error - 20-03-2013 02:19:33 | Computer Name = SIRIUS-PC1 | Source = PandoraService.exe | ID = 0
Description =
 
Error - 01-04-2013 01:14:17 | Computer Name = SIRIUS-PC1 | Source = FirebirdGuardianDefaultInstance | ID = 0
Description =
 
[ System Events ]
Error - 30-03-2013 03:14:49 | Computer Name = SIRIUS-PC1 | Source = Cdrom | ID = 262151
Description = The device, DeviceCdRom1, has a bad block.
 
Error - 30-03-2013 05:55:51 | Computer Name = SIRIUS-PC1 | Source = Cdrom | ID = 262151
Description = The device, DeviceCdRom1, has a bad block.
 
Error - 30-03-2013 05:56:38 | Computer Name = SIRIUS-PC1 | Source = Service Control Manager | ID = 7038
Description = The SSDPSRV service was unable to log on as NT AUTHORITYLocalService
 with the currently configured  password due to the following error: %%5   To ensure
that the service is  configured properly, use the Services snap-in in Microsoft Management
Console
 (MMC).
 
Error - 30-03-2013 05:56:38 | Computer Name = SIRIUS-PC1 | Source = Service Control Manager | ID = 7000
Description = The SSDP Discovery Service service failed to start due to the following
 error: %%1069
 
Error - 01-04-2013 01:14:05 | Computer Name = SIRIUS-PC1 | Source = Cdrom | ID = 262151
Description = The device, DeviceCdRom1, has a bad block.
 
Error - 01-04-2013 01:14:44 | Computer Name = SIRIUS-PC1 | Source = Service Control Manager | ID = 7034
Description = The Firebird Guardian - DefaultInstance service terminated unexpectedly.
  It has done this 1 time(s).
 
Error - 01-04-2013 01:14:44 | Computer Name = SIRIUS-PC1 | Source = Service Control Manager | ID = 7031
Description = The Microsoft .NET Framework NGEN v4.0.30319_X86 service terminated
 unexpectedly.  It has done this 1 time(s).  The following corrective action will
 be taken in 60000 milliseconds: Restart the service.
 
Error - 01-04-2013 01:24:30 | Computer Name = SIRIUS-PC1 | Source = Cdrom | ID = 262151
Description = The device, DeviceCdRom1, has a bad block.
 
Error - 02-04-2013 01:26:05 | Computer Name = SIRIUS-PC1 | Source = Cdrom | ID = 262151
Description = The device, DeviceCdRom1, has a bad block.
 
Error - 03-04-2013 02:21:27 | Computer Name = SIRIUS-PC1 | Source = Cdrom | ID = 262151
Description = The device, DeviceCdRom1, has a bad block.
 
 
< End of report >
 


Ето данните  и от Security Check

 

 Results of screen317's Security Check version 0.99.61  
 Windows XP Service Pack 3 x86   
 Internet Explorer 8  
``````````````Antivirus/Firewall Check:``````````````
 Windows Firewall Disabled!  
Please wait while WMIC compiles updated MOF files.d
i
s
p
l
a
y
N
a
m
e
ECHO is off.
E
S
E
T
ECHO is off.
N
O
D
3
2
ECHO is off.
A
n
t
i
v
i
r
u
s
ECHO is off.
4
.
0
ECHO is off.
 Antivirus up to date!  
`````````Anti-malware/Other Utilities Check:`````````
 Malwarebytes Anti-Malware version 1.70.0.1100  
 JavaFX 2.1.0  
 Java 7 Update 4  
 Java version out of Date!
 Adobe Flash Player 10 Flash Player out of Date!
 Adobe Flash Player  11.6.602.180  
 Adobe Reader 9 Adobe Reader out of Date!
 Mozilla Firefox (19.0.2)
 Mozilla Thunderbird (17.0.4)
````````Process Check: objlist.exe by Laurent````````  
 ESET NOD32 Antivirus egui.exe  
 ESET NOD32 Antivirus ekrn.exe  
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C:: 9%
````````````````````End of Log``````````````````````
 

Здравейте...!Извинявам се за закъснелия отговор....но бях ангажиран служебно...!Още веднъж се потвърждава че в системата ви няма данни за зловреден софтуер...! :)
 

Results of screen317's Security Check version 0.99.61 
Windows XP Service Pack 3 x86
Internet Explorer 8 
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Disabled! 
Please wait while WMIC compiles updated MOF files.d
Antivirus up to date! 
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.70.0.1100 
JavaFX 2.1.0  
Java 7 Update 4 
Java version out of Date!
Adobe Flash Player 10 Flash Player out of Date!
Adobe Flash Player 11.6.602.180 
Adobe Reader 9 Adobe Reader out of Date!
Mozilla Firefox (19.0.2)
Mozilla Thunderbird (17.0.4)
````````Process Check: objlist.exe by Laurent```````` 
ESET NOD32 Antivirus egui.exe 
ESET NOD32 Antivirus ekrn.exe 
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 9%
````````````````````End of Log``````````````````````

 
 
Задължително обновете потенциално уязвимия софтуер ( всичко което е оцветено в червено)
 
Публикувано изображение Изтеглете Публикувано изображениеTFC (Temp File Cleaner) от тук и го запишете на десктопа.

  • [*]Стартирайте
TFC.exe [*]Имайте търпение и изчакайте програмата да завърши работата си [*]Ако е необходимо, потвърдете с OK за рестартиране на Windows

 

Публикувано изображение Изтеглете Публикувано изображениеOTCleanIt или от тук,стартирайте и натиснете Публикувано изображение


Публикувано изображение Изтеглете Delfix.exe и го стартирайте. Сложете отметка пред Remove disinfection tools => натиснете бутона Run Инструмента ще се самоизтрие след като приключи своята задача!
 

Публикувано изображение Изтрийте всичко друго което е останало след процедурите (използвано в лечението).Препоръчвам програмата Malwarebytes' Anti-Malware да остане на вашия компютър и периодично да сканирате системата си с нея (поне един -два пъти в седмицата),като не забравяйте да обновите дефинициите и преди всяко сканиране..!
 
 
Това е от мен...Пожелавам ви лек ден  и безопасен интернет..! :)

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.