Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

имам вируси

Featured Replies

отворих този файл-http://hotfile.com/dl/213772755/d1dd94e/IMG0593020493-JPG във facebook и антивирусната ми отчете 55 заразени файла. След като антивирусната ги блокира,се активират на ново и заразяват или по точно се изпращат на всичките ми абонати в skypeDDS (Ver_2011-09-30.01) - NTFS_AMD64
Internet Explorer: 9.10.9200.16453
Run by 1 at 17:40:06 on 2013-05-09
Microsoft Windows 8 Enterprise 6.2.9200.0.1251.359.2057.18.6042.4544 [GMT 3:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:Windowssystem32wininit.exe
C:Windowssystem32svchost.exe -k DcomLaunch
C:Windowssystem32svchost.exe -k RPCSS
C:Windowssystem32atiesrxx.exe
C:WindowsSystem32svchost.exe -k LocalServiceNetworkRestricted
C:Windowssystem32dwm.exe
C:Windowssystem32svchost.exe -k netsvcs
C:Windowssystem32svchost.exe -k LocalService
C:Windowssystem32atieclxx.exe
C:WindowsSystem32svchost.exe -k LocalSystemNetworkRestricted
C:Program FilesClassic ShellClassicShellService.exe
C:WindowsExplorer.EXE
C:Windowssystem32Hpservice.exe
C:Program FilesClassic ShellClassicStartMenu.exe
C:Windowssystem32svchost.exe -k NetworkService
C:Program FilesAVAST SoftwareAvastAvastSvc.exe
C:Windowssystem32DllHost.exe
C:WindowsSystem32spoolsv.exe
C:Windowssystem32svchost.exe -k LocalServiceNoNetwork
C:Windowssystem32taskhostex.exe
C:Program Files (x86)Application UpdaterApplicationUpdater.exe
C:Program FilesSynapticsSynTPSynTPEnh.exe
C:Program Files (x86)Ralink CorporationRalink Bluetooth StackBlueSoleilCS.exe
C:Windowssystem32dashost.exe
c:Program FilesInteliCLS ClientHeciServer.exe
C:Program Files (x86)IntelIntel® Management Engine ComponentsDALjhi_service.exe
C:Program Files (x86)Common FilesNeroNero BackItUp 4NBService.exe
C:WindowsSysWOW64PnkBstrA.exe
C:Windowssystem32svchost.exe -k imgsvc
C:Program Files (x86)TeamViewerVersion8TeamViewer_Service.exe
C:Windowssystem32wbemwmiprvse.exe
C:Program Files (x86)Ralink CorporationRalink Bluetooth StackBsHelpCS.exe
C:Windowssystem32svchost.exe -k LocalServiceAndNoImpersonation
C:Windowssystem32SearchIndexer.exe
C:Program FilesWindowsAppsmicrosoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbweLiveComm.exe
C:Windowssystem32svchost.exe -k NetworkServiceNetworkRestricted
C:WindowsSystem32hkcmd.exe
C:WindowsSystem32igfxpers.exe
C:WindowsSystem32RuntimeBroker.exe
C:PROGRAM FILESSYNAPTICSSYNTPSYNTPHELPER.EXE
C:Program Files (x86)Ralink CorporationRalink Bluetooth StackBtTray.exe
C:Program FilesAVAST SoftwareAvastAvastUI.exe
c:Program Files (x86)ATI TechnologiesATI.ACECore-StaticMOM.exe
C:Program Files (x86)IntelIntel® Rapid Storage TechnologyIAStorIcon.exe
C:Program Files (x86)ATI TechnologiesATI.ACECore-StaticCCC.exe
C:Program Files (x86)IntelIntel® Rapid Storage TechnologyIAStorDataMgrSvc.exe
C:Program Files (x86)RealtekRealtek PCIE Card ReaderRIconMan.exe
C:Program Files (x86)IntelIntel® Management Engine ComponentsFWServiceIntelMeFWService.exe
C:Program Files (x86)IntelIntel® Management Engine ComponentsLMSLMS.exe
C:Program Files (x86)IntelIntel® Management Engine ComponentsUNSUNS.exe
C:Program FilesWindows Media Playerwmpnetwk.exe
C:WindowsSystem32svchost.exe -k LocalServicePeerNet
C:Program Files (x86)Mozilla Firefoxfirefox.exe
C:Program Files (x86)Mozilla Firefoxplugin-container.exe
C:WindowsSysWOW64MacromedFlashFlashPlayerPlugin_11_6_602_180.exe
C:WindowsSysWOW64MacromedFlashFlashPlayerPlugin_11_6_602_180.exe
C:Windowssystem32taskhost.exe
C:Windowssystem32SearchProtocolHost.exe
C:Windowssystem32SearchFilterHost.exe
C:Windowssystem32conhost.exe
C:WindowsSystem32cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://tuvaro.com/ws/?source=4c3f95e5&tbp=homepage&toolbarid=base&u=70df0a84000000000000a417312b1658
mStart Page = hxxp://home.allgameshome.com/
uURLSearchHooks: SimilarWeb: {74198672-5F7D-4FE9-A611-4AC1D5A66A15} - C:Program Files (x86)SimilarWebSimilarWeb.dll
uURLSearchHooks: YTD Toolbar: {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:Program Files (x86)YTD ToolbarIE7.0ytdToolbarIE.dll
uURLSearchHooks: uTorrentControl_v2 Toolbar: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:Program Files (x86)uTorrentControl_v2prxtbuTor.dll
uURLSearchHooks: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - <orphaned>
uURLSearchHooks: <No Name>: {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:Program Files (x86)AskTBarSrchAstt1.binA5SRCHAS.DLL
uURLSearchHooks: <No Name>: - LocalServer32 - <no file>
mURLSearchHooks: <No Name>: - LocalServer32 - <no file>
mURLSearchHooks: SimilarWeb: {74198672-5F7D-4FE9-A611-4AC1D5A66A15} - C:Program Files (x86)SimilarWebSimilarWeb.dll
mWinlogon: Userinit = userinit.exe
BHO: Toolbar BHO: {1e91a655-bb4b-4693-a05e-2edebc4c9d89} -
BHO: ExplorerBHO Class: {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:Program FilesClassic ShellClassicExplorer32.dll
BHO: tuvaro Helper Object: {5CB02877-EFBC-4317-B608-9E24B11BAB40} - C:Program Files (x86)tuvarotuvaro1.8.17.1bhtuvaro.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:Program Files (x86)Microsoft OfficeOffice12GrooveShellExtensions.dll
BHO: uTorrentControl_v2 Toolbar: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:Program Files (x86)uTorrentControl_v2prxtbuTor.dll
BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:Program FilesAVAST SoftwareAvastaswWebRepIE.dll
BHO: Ask Search Assistant BHO: {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:Program Files (x86)AskTBarSrchAstt1.binA5SRCHAS.DLL
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:Program Files (x86)GoogleGoogle ToolbarGoogleToolbar_32.dll
BHO: ClassicIE9BHO Class: {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:Program FilesClassic ShellClassicIE9DLL_32.dll
BHO: YTD Toolbar: {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:Program Files (x86)YTD ToolbarIE7.0ytdToolbarIE.dll
BHO: Ask Toolbar BHO: {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:Program Files (x86)AskTBarbar1.binASKTBAR.DLL
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:Program Files (x86)GoogleGoogle ToolbarGoogleToolbar_32.dll
TB: Classic Explorer Bar: {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:Program FilesClassic ShellClassicExplorer32.dll
TB: uTorrentControl_v2 Toolbar: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:Program Files (x86)uTorrentControl_v2prxtbuTor.dll
TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:Program FilesAVAST SoftwareAvastaswWebRepIE.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:Program Files (x86)GoogleGoogle ToolbarGoogleToolbar_32.dll
TB: YTD Toolbar: {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:Program Files (x86)YTD ToolbarIE7.0ytdToolbarIE.dll
TB: Ask Toolbar: {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:Program Files (x86)AskTBarbar1.binASKTBAR.DLL
TB: MapsGalaxy: {364ea597-e728-4ce4-bb4a-ed846ef47970} -
TB: SimilarWeb: {74198672-5F7D-4FE9-A611-4AC1D5A66A15} - C:Program Files (x86)SimilarWebSimilarWeb.dll
TB: Tuvaro Toolbar: {6F001652-AF51-45C6-B029-86E0265A1851} - C:Program Files (x86)tuvarotuvaro1.8.17.1tuvaroTlbr.dll
EB: SimilarWeb: {74198672-5F7D-4FE9-A611-4AC1D5A66A15} - C:Program Files (x86)SimilarWebSimilarWeb.dll
uRun: [Pokki] "C:Users1AppDataLocalPokkiv0.260.10.204pokki.exe"
uRun: [indxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:Program Files (x86)Common FilesNeroLibNMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
uRun: [DW6] "C:Program Files (x86)The Weather Channel FWDesktopDesktopWeather.exe"
uRun: [Facebook Update] "C:Users1AppDataLocalFacebookUpdateFacebookUpdate.exe" /c /nocrashserver
uRun: [skype] "C:Program Files (x86)SkypePhoneSkype.exe" /minimized /regrun
mRun: [startCCC] "c:Program Files (x86)ATI TechnologiesATI.ACECore-StaticCLIStart.exe" MSRun
mRun: [btTray] "C:Program Files (x86)Ralink CorporationRalink Bluetooth StackBtTray.exe"
mRun: [iAStorIcon] C:Program Files (x86)IntelIntel® Rapid Storage TechnologyIAStorIconLaunch.exe "C:Program Files (x86)IntelIntel® Rapid Storage TechnologyIAStorIcon.exe" 60
mRun: [WinampAgent] "C:Program Files (x86)Winampwinampa.exe"
mRun: [GrooveMonitor] "C:Program Files (x86)Microsoft OfficeOffice12GrooveMonitor.exe"
mRun: [avast] "C:Program FilesAVAST SoftwareAvastavastUI.exe" /nogui
mRun: [searchSettings] "C:Program Files (x86)Common FilesSpigotSearch SettingsSearchSettings.exe"
mRun: [NBKeyScan] "C:Program Files (x86)NeroNero8Nero BackItUpNBKeyScan.exe"
mRun: [NeroFilterCheck] C:WindowsSystem32NeroCheck.exe
StartupFolder: C:Users1AppDataRoamingMICROS~1WindowsSTARTM~1ProgramsStartupONENOT~1.LNK - C:Program Files (x86)Microsoft OfficeOffice12ONENOTEM.EXE
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-System: PromptOnSecureDesktop = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: EnableCursorSuppression = dword:1
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: disablecad = dword:1
IE: E&xport to Microsoft Excel - C:PROGRA~2MICROS~1Office12EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:Program Files (x86)Microsoft OfficeOffice12ONBttnIE.dll
IE: {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:Program FilesClassic ShellClassicIE9_32.exe
IE: {5D06ED6E-DA78-4486-A246-B131A2C39807} - {74198672-5F7D-4FE9-A611-4AC1D5A66A15} - C:Program Files (x86)SimilarWebSimilarWeb.dll
IE: {64964764-1101-4bbd-8891-B56B1A53B9B3} - {553891B7-A0D5-4526-BE18-D3CE461D6310}
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
TCP: Interfaces{1A61BB5C-03CF-4F75-92CC-5ABAA9E3B677} : NameServer = 194.219.227.2,193.92.150.3
TCP: Interfaces{1C284493-4D0D-43CB-B995-1ED9BC305A5D} : NameServer = 194.219.227.1,193.92.150.3
TCP: Interfaces{1C284493-4D0D-43CB-B995-1ED9BC305A5D}4586F6D637F6E6438373738303 : DHCPNameServer = 192.168.1.254
TCP: Interfaces{1C284493-4D0D-43CB-B995-1ED9BC305A5D}64F6274786E65647543443141383 : DHCPNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces{1C284493-4D0D-43CB-B995-1ED9BC305A5D}D616279616 : DHCPNameServer = 192.168.1.254
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:Program Files (x86)Microsoft OfficeOffice12GrooveSystemServices.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:Program Files (x86)Common FilesSkypeSkype4COM.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:Program Files (x86)Microsoft OfficeOffice12GrooveShellExtensions.dll
LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg pku2u livessp
SubSystems: Windows = basesrv,1 winsrv:UserServerDllInitialization,3 sxssrv,4 %SystemRoot%system32csrss.exe ObjectDirectory=Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
x64-BHO: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:Program FilesAVAST SoftwareAvastaswWebRepIE64.dll
x64-BHO: ExplorerBHO Class: {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:Program FilesClassic ShellClassicExplorer64.dll
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:Program Files (x86)GoogleGoogle ToolbarGoogleToolbar_64.dll
x64-BHO: ClassicIE9BHO Class: {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:Program FilesClassic ShellClassicIE9DLL_64.dll
x64-TB: Classic Explorer Bar: {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:Program FilesClassic ShellClassicExplorer64.dll
x64-TB: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:Program FilesAVAST SoftwareAvastaswWebRepIE64.dll
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:Program Files (x86)GoogleGoogle ToolbarGoogleToolbar_64.dll
x64-Run: [igfxTray] C:WindowsSystem32igfxtray.exe
x64-Run: [HotKeysCmds] C:WindowsSystem32hkcmd.exe
x64-Run: [Persistence] C:WindowsSystem32igfxpers.exe
x64-IE: {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:Program FilesClassic ShellClassicIE9_32.exe
x64-IE: {64964764-1101-4bbd-8891-B56B1A53B9B3} - {553891B7-A0D5-4526-BE18-D3CE461D6310}
x64-Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - <orphaned>
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
x64-mASetup: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U C:WindowsSystem32shell32.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - C:Users1AppDataRoamingMozillaFirefoxProfilesfafs95p1.default-1358285078196
FF - prefs.js: Keyword.Enabled - true
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/
FF - prefs.js: keyword.URL - hxxp://tuvaro.com/ws/?source=4c3f95e5&tbp=url&toolbarid=base&u=70df0a84000000000000a417312b1658&q=
FF - plugin: C:Program Files (x86)GoogleUpdate1.3.21.135npGoogleUpdate3.dll
FF - plugin: C:Program Files (x86)IntelIntel® Management Engine ComponentsIPTnpIntelWebAPIIPT.dll
FF - plugin: C:Program Files (x86)IntelIntel® Management Engine ComponentsIPTnpIntelWebAPIUpdater.dll
FF - plugin: C:Program Files (x86)K-Lite Codec PackRealbrowserpluginsnppl3260.dll
FF - plugin: C:Program Files (x86)K-Lite Codec PackRealbrowserpluginsnprpjplug.dll
FF - plugin: C:Program Files (x86)UbisoftUbisoft Game Launchernpuplaypc.dll
FF - plugin: C:Program Files (x86)UbisoftUbisoft Game Launchernpuplaypchub.dll
FF - plugin: C:Users1AppDataLocalFacebookVideoSkypenpFacebookVideoCalling.dll
FF - plugin: C:WindowsSysWOW64MacromedFlashNPSWF32_11_6_602_180.dll
.
---- FIREFOX POLICIES ----
FF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp://search.babylon.com/?babsrc=TB_def&mntrId=70df0a84000000000000a417312b1658&q=
FF - user.js: extensions.BabylonToolbar.id - 70df0a84000000000000a417312b1658
FF - user.js: extensions.BabylonToolbar.appId - {BDB69379-802F-4eaf-B541-F8DE92DD98DB}
FF - user.js: extensions.BabylonToolbar.instlDay - 15739
FF - user.js: extensions.BabylonToolbar.vrsn - 1.8.11.10
FF - user.js: extensions.BabylonToolbar.vrsni - 1.8.11.10
FF - user.js: extensions.BabylonToolbar.vrsnTs - 1.8.11.1020:21:10
FF - user.js: extensions.BabylonToolbar.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar.aflt - babsst
FF - user.js: extensions.BabylonToolbar.smplGrp - none
FF - user.js: extensions.BabylonToolbar.tlbrId - uninst
FF - user.js: extensions.BabylonToolbar.instlRef - na
FF - user.js: extensions.BabylonToolbar.dfltLng - en
FF - user.js: extensions.BabylonToolbar.excTlbr - false
FF - user.js: extensions.BabylonToolbar.ffxUnstlRst - true
FF - user.js: extensions.BabylonToolbar.admin - false
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=10588&tl=gkn354482
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - def
FF - user.js: extensions.BabylonToolbar.autoRvrt - false
FF - user.js: extensions.BabylonToolbar.rvrt - false
FF - user.js: extensions.BabylonToolbar.newTab - false
FF - user.js: extensions.tuvaro.hpOld0 - hxxps://www.facebook.com/
FF - user.js: extensions.tuvaro.tlbrSrchUrl - hxxp://tuvaro.com/ws/?source=4c3f95e5&tbp=main&toolbarid=base&u=70df0a84000000000000a417312b1658&q=
FF - user.js: extensions.tuvaro.id - 70df0a84000000000000a417312b1658
FF - user.js: extensions.tuvaro.appId - {2768469C-717B-401F-8532-C6D88BAE0339}
FF - user.js: extensions.tuvaro.instlDay - 15802
FF - user.js: extensions.tuvaro.vrsn - 1.8.17.1
FF - user.js: extensions.tuvaro.vrsni - 1.8.17.1
FF - user.js: extensions.tuvaro.vrsnTs - 1.8.17.19:33:29
FF - user.js: extensions.tuvaro.prtnrId - tuvaro
FF - user.js: extensions.tuvaro.prdct - tuvaro
FF - user.js: extensions.tuvaro.aflt - orgnl
FF - user.js: extensions.tuvaro.smplGrp - none
FF - user.js: extensions.tuvaro.tlbrId - base
FF - user.js: extensions.tuvaro.instlRef - 4c3f95e5
FF - user.js: extensions.tuvaro.dfltLng -
FF - user.js: extensions.tuvaro.excTlbr - false
FF - user.js: extensions.tuvaro.ffxUnstlRst - false
FF - user.js: extensions.tuvaro.admin - false
FF - user.js: extensions.tuvaro.cam -
FF - user.js: extensions.tuvaro.autoRvrt - false
FF - user.js: extensions.tuvaro.rvrt - false
FF - user.js: extensions.tuvaro.hmpg - true
FF - user.js: extensions.tuvaro.hmpgUrl - hxxp://tuvaro.com/ws/?source=4c3f95e5&tbp=homepage&toolbarid=base&u=70df0a84000000000000a417312b1658
FF - user.js: extensions.tuvaro.dfltSrch - true
FF - user.js: extensions.tuvaro.srchPrvdr - Tuvaro
FF - user.js: extensions.tuvaro.kw_url - hxxp://tuvaro.com/ws/?source=4c3f95e5&tbp=url&toolbarid=base&u=70df0a84000000000000a417312b1658&q=
FF - user.js: extensions.tuvaro.dnsErr - true
FF - user.js: extensions.tuvaro.newTab - true
FF - user.js: extensions.tuvaro.newTabUrl - chrome://tuvaro/content/new browser tab.html?source=4c3f95e5&tbp=tab&u=70df0a84000000000000a417312b1658
.
============= SERVICES / DRIVERS ===============
.
R0 acpiex;Microsoft ACPIEx Driver;C:WindowsSystem32Driversacpiex.sys [2012-7-26 77040]
R0 amdkmpfd;AMD PCI Root Bus Lower Filter;C:WindowsSystem32Driversamdkmpfd.sys [2012-7-9 35496]
R0 aswRvrt;aswRvrt;C:WindowsSystem32DriversaswRvrt.sys [2013-3-16 65336]
R0 EhStorClass;Enhanced Storage Filter Driver;C:WindowsSystem32DriversEhStorClass.sys [2012-7-26 81136]
R0 iaStorA;iaStorA;C:WindowsSystem32DriversiaStorA.sys [2012-9-28 650808]
R0 pdc;pdc;C:WindowsSystem32Driverspdc.sys [2013-1-16 69864]
R0 spaceport;Storage Spaces Driver;C:WindowsSystem32Driversspaceport.sys [2012-7-26 283888]
R0 WFPLWFS;Microsoft Windows Filtering Platform;C:WindowsSystem32Driverswfplwfs.sys [2012-7-26 96496]
R1 aswSnx;aswSnx;C:WindowsSystem32DriversaswSnx.sys [2013-1-5 1025808]
R1 aswSP;aswSP;C:WindowsSystem32DriversaswSP.sys [2013-1-5 377920]
R1 BasicDisplay;BasicDisplay;C:WindowsSystem32DriversBasicDisplay.sys [2012-7-26 48640]
R1 BasicRender;BasicRender;C:WindowsSystem32DriversBasicRender.sys [2012-7-26 29696]
R1 npsvctrig;Named pipe service trigger provider;C:WindowsSystem32Driversnpsvctrig.sys [2012-7-26 23552]
R1 vwififlt;Virtual WiFi Filter Driver;C:WindowsSystem32Driversvwififlt.sys [2012-7-26 64000]
R2 AMD External Events Utility;AMD External Events Utility;C:WindowsSystem32atiesrxx.exe [2012-11-4 239616]
R2 Application Updater;Application Updater;C:Program Files (x86)Application UpdaterApplicationUpdater.exe [2013-2-23 805752]
R2 aswFsBlk;aswFsBlk;C:WindowsSystem32DriversaswFsBlk.sys [2013-1-5 33400]
R2 aswMonFlt;aswMonFlt;C:WindowsSystem32DriversaswMonFlt.sys [2013-1-5 80816]
R2 avast! Antivirus;avast! Antivirus;C:Program FilesAVAST SoftwareAvastAvastSvc.exe [2013-3-16 45248]
R2 BrokerInfrastructure;Background Tasks Infrastructure Service;C:WindowsSystem32svchost.exe -k DcomLaunch [2013-1-16 29696]
R2 ClassicShellService;Classic Shell Service;C:Program FilesClassic ShellClassicShellService.exe [2012-12-29 68608]
R2 DeviceAssociationService;Device Association Service;C:WindowsSystem32svchost.exe -k LocalSystemNetworkRestricted [2013-1-16 29696]
R2 hpsrv;HP Service;C:WindowsSystem32hpservice.exe [2011-5-13 30520]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:Program Files (x86)IntelIntel® Rapid Storage TechnologyIAStorDataMgrSvc.exe [2013-1-2 14904]
R2 IconMan_R;IconMan_R;C:Program Files (x86)RealtekRealtek PCIE Card ReaderRIconMan.exe [2013-1-2 2451456]
R2 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface;C:Program FilesInteliCLS ClientHeciServer.exe [2012-4-20 635104]
R2 Intel® ME Service;Intel® ME Service;C:Program Files (x86)IntelIntel® Management Engine ComponentsFWServiceIntelMeFWService.exe [2013-1-2 128896]
R2 jhi_service;Intel® Dynamic Application Loader Host Interface Service;C:Program Files (x86)IntelIntel® Management Engine ComponentsDALJhi_service.exe [2013-1-2 165760]
R2 LSM;Local Session Manager;C:WindowsSystem32svchost.exe -k DcomLaunch [2013-1-16 29696]
R2 Ndu;Windows Network Data Usage Monitoring Driver;C:WindowsSystem32DriversNdu.sys [2012-7-26 97792]
R2 TeamViewer8;TeamViewer 8;C:Program Files (x86)TeamViewerVersion8TeamViewer_Service.exe [2013-1-21 3467768]
R2 UNS;Intel® Management and Security Application User Notification Service;C:Program Files (x86)IntelIntel® Management Engine ComponentsUNSUNS.exe [2013-1-2 364416]
R2 Wcmsvc;Windows Connection Manager;C:WindowsSystem32svchost.exe -k LocalServiceNetworkRestricted [2013-1-16 29696]
R3 amdkmdag;amdkmdag;C:WindowsSystem32Driversatikmdag.sys [2012-11-4 10316800]
R3 amdkmdap;amdkmdap;C:WindowsSystem32Driversatikmpag.sys [2012-11-4 370688]
R3 BtAudioBusSrv;Ralink Bluetooth Audio Bus Service;C:WindowsSystem32DriversBtAudioBus.sys [2012-6-15 23136]
R3 BthL2caScoIfSrv;Bluetooth Profile Interface Driver Service;C:WindowsSystem32DriversBtL2caScoIf.sys [2012-7-19 56904]
R3 BthLEEnum;Bluetooth Low Energy Driver;C:WindowsSystem32DriversBthLEEnum.sys [2012-7-26 202752]
R3 btUrbFilterDrv;IVT URB Bluetooth Filter Driver Service;C:WindowsSystem32DriversIvtUrbBtFlt.sys [2012-10-2 48608]
R3 condrv;Console Driver;C:WindowsSystem32Driverscondrv.sys [2012-7-26 33792]
R3 IntcDAud;Intel® Display Audio;C:WindowsSystem32DriversIntcDAud.sys [2012-6-19 342528]
R3 intelkmd;intelkmd;C:WindowsSystem32Driversigdpmd64.sys [2012-9-22 9004384]
R3 kdnic;Microsoft Kernel Debug Network Miniport (NDIS 6.20);C:WindowsSystem32Driverskdnic.sys [2012-7-26 18432]
R3 MEIx64;Intel® Management Engine Interface ;C:WindowsSystem32DriversHECIx64.sys [2012-7-17 62784]
R3 NcdAutoSetup;Network Connected Devices Auto-Setup;C:WindowsSystem32svchost.exe -k LocalServiceNoNetwork [2013-1-16 29696]
R3 netr28x;Ralink 802.11n Extensible Wireless Driver;C:WindowsSystem32Driversnetr28x.sys [2013-1-2 2042952]
R3 rtbth;RTBTH Bluetooth Device Driver;C:WindowsSystem32Driversrtbth.sys [2012-10-2 692832]
R3 RTL8168;Realtek 8168 NT Driver;C:WindowsSystem32DriversRt630x64.sys [2013-1-2 690832]
R3 SystemEventsBroker;System Events Broker;C:WindowsSystem32svchost.exe -k netsvcs [2013-1-16 29696]
R3 TimeBroker;Time Broker;C:WindowsSystem32svchost.exe -k LocalServiceAndNoImpersonation [2013-1-16 29696]
R3 UCX01000;USB Controller Extension;C:WindowsSystem32DriversUCX01000.SYS [2013-1-16 212200]
R3 USBHUB3;SuperSpeed Hub;C:WindowsSystem32DriversUSBHUB3.SYS [2013-1-16 445160]
R3 USBXHCI;USB xHCI Compliant Host Controller;C:WindowsSystem32DriversUSBXHCI.SYS [2013-1-16 337128]
R3 vwifimp;Virtual WiFi Miniport Service;C:WindowsSystem32Driversvwifimp.sys [2012-7-26 17920]
R3 WirelessButtonDriver;HP Wireless Button Driver Service;C:WindowsSystem32DriversWirelessButtonDriver64.sys [2012-8-3 20288]
S1 dam;Desktop Activity Moderator Driver;C:WindowsSystem32Driversdam.sys [2013-1-16 58088]
S2 gupdate;Услуга на Google Актуализация (gupdate);C:Program Files (x86)GoogleUpdateGoogleUpdate.exe [2013-1-5 136176]
S2 SkypeUpdate;Skype Updater;C:Program Files (x86)SkypeUpdaterUpdater.exe [2013-2-28 161384]
S3 3ware;3ware;C:WindowsSystem32Drivers3ware.sys [2012-7-25 106736]
S3 acpipagr;ACPI Processor Aggregator Driver;C:WindowsSystem32Driversacpipagr.sys [2012-7-26 10240]
S3 acpitime;ACPI Wake Alarm Driver;C:WindowsSystem32Driversacpitime.sys [2012-7-26 10752]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:WindowsSysWOW64MacromedFlashFlashPlayerUpdateService.exe [2013-1-2 253656]
S3 AllUserInstallAgent;Windows All-User Install Agent;C:WindowsSystem32svchost.exe -k LocalSystemNetworkRestricted [2013-1-16 29696]
S3 aswVmm;aswVmm;C:WindowsSystem32DriversaswVmm.sys [2013-3-16 178624]
S3 cphs;Intel® Content Protection HECI Service;C:WindowsSysWOW64IntelCpHeciSvc.exe [2012-9-22 277024]
S3 DeviceInstall;Device Install Service;C:WindowsSystem32svchost.exe -k DcomLaunch [2013-1-16 29696]
S3 dmvsc;dmvsc;C:WindowsSystem32Driversdmvsc.sys [2012-7-26 33280]
S3 DsmSvc;Device Setup Manager;C:WindowsSystem32svchost.exe -k netsvcs [2013-1-16 29696]
S3 EhStorTcgDrv;Microsoft driver for storage devices supporting IEEE 1667 and TCG protocols;C:WindowsSystem32DriversEhStorTcgDrv.sys [2012-7-26 113904]
S3 fhsvc;File History Service;C:WindowsSystem32svchost.exe -k LocalSystemNetworkRestricted [2013-1-16 29696]
S3 FxPPM;Power Framework Processor Driver;C:WindowsSystem32Driversfxppm.sys [2013-1-16 22528]
S3 gencounter;Microsoft Hyper-V Generation Counter;C:WindowsSystem32Driversvmgencounter.sys [2012-7-26 12288]
S3 GPIOClx0101;Microsoft GPIO Class Extension Driver;C:WindowsSystem32Driversmsgpioclx.sys [2013-1-16 120040]
S3 gupdatem;Услуга на Google Актуализация (gupdatem);C:Program Files (x86)GoogleUpdateGoogleUpdate.exe [2013-1-5 136176]
S3 hidi2c;Microsoft I2C HID Miniport Driver;C:WindowsSystem32Drivershidi2c.sys [2013-1-16 39936]
S3 hyperkbd;hyperkbd;C:WindowsSystem32Drivershyperkbd.sys [2012-7-26 11776]
S3 HyperVideo;HyperVideo;C:WindowsSystem32DriversHyperVideo.sys [2012-7-26 24576]
S3 LSI_SSS;LSI_SSS;C:WindowsSystem32Driverslsi_sss.sys [2012-7-25 81136]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:Program Files (x86)Mozilla Maintenance Servicemaintenanceservice.exe [2013-5-9 115608]
S3 MsBridge;Microsoft MAC Bridge;C:WindowsSystem32Driversbridge.sys [2012-7-26 129536]
S3 msgpiowin32;GPIO Buttons Driver;C:WindowsSystem32Driversmsgpiowin32.sys [2013-1-16 28392]
S3 mshidumdf;Pass-through HID to UMDF Driver;C:WindowsSystem32Driversmshidumdf.sys [2012-7-26 10752]
S3 MsLldp;Microsoft Link-Layer Discovery Protocol;C:WindowsSystem32Driversmslldp.sys [2012-7-26 68608]
S3 mvumis;mvumis;C:WindowsSystem32Driversmvumis.sys [2012-6-2 64240]
S3 NcaSvc;Network Connectivity Assistant;C:WindowsSystem32svchost.exe -k NetSvcs [2013-1-16 29696]
S3 NdisImPlatform;Microsoft Network Adapter Multiplexor Protocol;C:WindowsSystem32DriversNdisImPlatform.sys [2012-7-26 126464]
S3 NDISWANLEGACY;Remote Access LEGACY NDIS WAN Driver;C:WindowsSystem32Driversndiswan.sys [2012-7-26 174080]
S3 PrintNotify;Printer Extensions and Notifications;C:WindowsSystem32svchost.exe -k print [2013-1-16 29696]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:WindowsSystem32Driversrdpvideominiport.sys [2013-1-16 27880]
S3 RSP2STOR;Realtek PCIE CardReader Driver - P2;C:WindowsSystem32DriversRtsP2Stor.sys [2013-1-2 269968]
S3 sdstor;SD Storage Port Driver;C:WindowsSystem32Driverssdstor.sys [2013-1-16 56552]
S3 SerCx;Serial UART Support Library;C:WindowsSystem32DriversSerCx.sys [2012-7-26 62976]
S3 SpbCx;Simple Peripheral Bus Support Library;C:WindowsSystem32DriversSpbCx.sys [2012-7-26 59392]
S3 storahci;Microsoft Standard SATA AHCI Driver;C:WindowsSystem32Driversstorahci.sys [2012-7-26 77552]
S3 StorSvc;Storage Service;C:WindowsSystem32svchost.exe -k LocalSystemNetworkRestricted [2013-1-16 29696]
S3 storvsp;storvsp;C:WindowsSystem32Driversstorvsp.sys [2012-7-26 67584]
S3 svsvc;Spot Verifier;C:WindowsSystem32svchost.exe -k LocalSystemNetworkRestricted [2013-1-16 29696]
S3 Synth3dVsc;Microsoft Virtual 3D Video Transport Driver;C:WindowsSystem32DriversSynth3dVsc.sys [2012-7-26 53352]
S3 terminpt;Microsoft Remote Desktop Input Driver;C:WindowsSystem32Driversterminpt.sys [2012-7-26 36592]
S3 TsUsbFlt;TsUsbFlt;C:WindowsSystem32DriversTsUsbFlt.sys [2012-7-26 57344]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:WindowsSystem32DriversTsUsbGD.sys [2012-7-26 30208]
S3 tsusbhub;tsusbhub;C:WindowsSystem32Driverstsusbhub.sys [2012-7-26 115712]
S3 UASPStor;USB Attached SCSI (UAS) Driver;C:WindowsSystem32Driversuaspstor.sys [2012-7-26 97008]
S3 VerifierExt;VerifierExt;C:WindowsSystem32DriversVerifierExt.sys [2012-7-26 106224]
S3 Vid;Vid;C:WindowsSystem32DriversVid.sys [2012-7-26 203776]
S3 vmbusr;Virtual Machine Bus Provider;C:WindowsSystem32Driversvmbusr.sys [2012-7-26 117248]
S3 vmicheartbeat;Hyper-V Heartbeat Service;C:WindowsSystem32svchost.exe -k ICService [2013-1-16 29696]
S3 vmickvpexchange;Hyper-V Data Exchange Service;C:WindowsSystem32svchost.exe -k LocalSystemNetworkRestricted [2013-1-16 29696]
S3 vmicrdv;Hyper-V Remote Desktop Virtualization Service;C:WindowsSystem32svchost.exe -k ICService [2013-1-16 29696]
S3 vmicshutdown;Hyper-V Guest Shutdown Service;C:WindowsSystem32svchost.exe -k LocalSystemNetworkRestricted [2013-1-16 29696]
S3 vmictimesync;Hyper-V Time Synchronization Service;C:WindowsSystem32svchost.exe -k LocalServiceNetworkRestricted [2013-1-16 29696]
S3 vmicvss;Hyper-V Volume Shadow Copy Requestor;C:WindowsSystem32svchost.exe -k LocalSystemNetworkRestricted [2013-1-16 29696]
S3 vpci;Microsoft Hyper-V Virtual PCI Bus;C:WindowsSystem32Driversvpci.sys [2012-7-26 67824]
S3 vpcivsp;Microsoft Hyper-V PCI Server;C:WindowsSystem32Driversvpcivsp.sys [2012-7-26 66048]
S3 VSTXRAID;VIA StorX Storage Controller Windows Driver;C:WindowsSystem32DriversVSTXRAID.SYS [2012-7-25 322800]
S3 WdBoot;Windows Defender Boot Driver;C:WindowsSystem32DriversWdBoot.sys [2012-7-26 34216]
S3 WdFilter;Windows Defender Mini-Filter Driver;C:WindowsSystem32DriversWdFilter.sys [2012-7-26 258288]
S3 WiaRpc;Still Image Acquisition Events;C:WindowsSystem32svchost.exe -k LocalSystemNetworkRestricted [2013-1-16 29696]
S3 wpcfltr;Family Safety Filter Driver;C:WindowsSystem32Driverswpcfltr.sys [2012-7-26 45056]
S3 WpdUpFltr;WPD Upper Class Filter Driver;C:WindowsSystem32DriversWpdUpFltr.sys [2012-7-26 19968]
S3 WSDPrintDevice;WSD Print Support;C:WindowsSystem32DriversWSDPrint.sys [2012-7-26 21504]
S3 WSService;Windows Store Service (WSService);C:WindowsSystem32svchost.exe -k LocalServiceAndNoImpersonation [2013-1-16 29696]
S3 WUDFSensorLP;UMDF Reflector service for LocationProvider;C:WindowsSystem32DriversWUDFRd.sys [2012-7-26 198656]
S3 WUDFWpdFs;WUDFWpdFs;C:WindowsSystem32DriversWUDFRd.sys [2012-7-26 198656]
S3 WUDFWpdMtp;WUDFWpdMtp;C:WindowsSystem32DriversWUDFRd.sys [2012-7-26 198656]
.
=============== Created Last 30 ================
.
2013-05-09 07:16:36 -------- d-----r- C:Program Files (x86)Skype
2013-05-09 07:10:03 -------- d-----w- C:ProgramDataStarApp
2013-05-08 02:12:51 -------- d-sh--r- C:Users1M-5930-2984-5943-4434
2013-05-06 07:28:34 -------- d-sh--r- C:Users1M-100-1929-5830-4592
2013-05-06 05:28:31 -------- d-----w- C:Users1AppDataLocalFacebook
2013-04-21 11:15:19 -------- d-----w- C:Users1AppDataRoamingFrogwares
2013-04-21 11:14:23 44239872 ----a-r- C:ProgramDataMicrosoftWindowsStart MenuProgramsThe Testament of Sherlock Holmesgame.exe
2013-04-21 11:14:21 15872 ----a-r- C:ProgramDataMicrosoftWindowsStart MenuProgramsThe Testament of Sherlock Holmesbuddha.dll
2013-04-21 11:01:36 -------- d-----w- C:Program Files (x86)NVIDIA Corporation
2013-04-21 10:49:40 -------- d-----w- C:Program Files (x86)Focus
.
==================== Find3M ====================
.
2013-04-07 06:27:07 862704 ----a-w- C:WindowsSystem32driverssptd.sys
2013-03-06 23:33:21 70992 ----a-w- C:WindowsSystem32driversaswRdr2.sys
2013-03-06 23:33:21 65336 ----a-w- C:WindowsSystem32driversaswRvrt.sys
2013-03-06 23:33:21 178624 ----a-w- C:WindowsSystem32driversaswVmm.sys
2013-03-06 23:33:21 1025808 ----a-w- C:WindowsSystem32driversaswSnx.sys
2013-03-06 23:33:20 80816 ----a-w- C:WindowsSystem32driversaswMonFlt.sys
2013-03-06 23:32:51 41664 ----a-w- C:WindowsavastSS.scr
.
============= FINISH: 17:40:56,49 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-09-30.01)
.
Microsoft Windows 8 Enterprise
Boot Device: DeviceHarddiskVolume1
Install Date: 1.1.2013 г. 21:20:43
System Uptime: 9.5.2013 г. 15:41:45 (2 hours ago)
.
Motherboard: Hewlett-Packard | | 183E
Processor: Intel® Core i5-3210M CPU @ 2.50GHz | U3E1 | 1200/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 195 GiB total, 98,523 GiB free.
E: is FIXED (NTFS) - 503 GiB total, 350,094 GiB free.
F: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP26: 21.4.2013 г. 14:01:49 - Installed DirectX
RP27: 29.4.2013 г. 15:51:24 - Scheduled Checkpoint
RP28: 7.5.2013 г. 15:39:24 - Scheduled Checkpoint
RP29: 9.5.2013 г. 9:50:38 - Removed Skype™ 6.3
.
==== Installed Programs ======================
.
µTorrent
007 Legends
2007 Microsoft Office Suite Service Pack 2 (SP2)
Adobe Flash Player 11 Plugin
Advertising Center
AMD APP SDK Runtime
AMD Catalyst Install Manager
Ask Toolbar
Assassin's Creed® III v1.03
avast! Free Antivirus
Catalyst Control Center
Catalyst Control Center - Branding
Catalyst Control Center Graphics Previews Common
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
Catalyst Control Center Profiles Mobile
ccc-utility64
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
Classic Shell
Crysis®3
DolbyFiles
Facebook Video Calling 1.2.0.287
Google Toolbar for Internet Explorer
Google Update Helper
HP Wireless Button Driver
ImagXpress
Intel® Display Audio Driver
Intel® Management Engine Components
Intel® Rapid Storage Technology
Intel® Trusted Connect Service Client
IrfanView (remove only)
K-Lite Mega Codec Pack 3.4.5
Lord of the Rings - War in the North
MapsGalaxy Toolbar
Menu Templates - Starter Kit
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Office 64-bit Components 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared 64-bit MUI (English) 2007
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Movie Templates - Starter Kit
Mozilla Firefox 20.0.1 (x86 bg)
Mozilla Maintenance Service
Nero 9 Trial
Nero BurnRights
Nero ControlCenter
Nero CoverDesigner
Nero DiscSpeed
Nero DriveSpeed
Nero InfoTool
Nero Installer
Nero PhotoSnap
Nero Recode
Nero Rescue Agent
Nero ShowTime
Nero StartSmart
Nero Vision
Nero WaveEditor
NeroBurningROM
NeroExpress
neroxml
NVIDIA PhysX
Pokki
PunkBuster Services
PX Profile Update
Ralink Bluetooth Stack64
Ralink RT3290 802.11bgn Wi-Fi Adapter
Realtek Ethernet Controller Driver
Realtek PCIE Card Reader
SA Dictionary 2010 Beta 1
SimilarWeb
Skype™ 6.3
SoundTrax
Synaptics Pointing Device Driver
TeamViewer 8
The KMPlayer (remove only)
The Testament of Sherlock Holmes
The Weather Channel Desktop 6
Tuvaro toolbar
Uplay
uTorrentControl_v2 Toolbar
VCRedistSetup
WinRAR archiver
YTD Toolbar v7.0
YTD Video Downloader 3.9.6
.
==== Event Viewer Messages From Past Week ========
.
9.5.2013 г. 9:26:05, Error: Schannel [36888] - A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.
9.5.2013 г. 9:26:05, Error: Schannel [36888] - A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.
9.5.2013 г. 9:18:44, Error: Schannel [36888] - A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.
9.5.2013 г. 9:18:28, Error: Schannel [36888] - A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.
9.5.2013 г. 9:17:40, Error: Schannel [36888] - A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.
9.5.2013 г. 15:55:21, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with the following service-specific error: There are no more endpoints available from the endpoint mapper.
9.5.2013 г. 15:41:49, Error: Microsoft-Windows-Kernel-General [6] - An I/O operation initiated by the Registry failed unrecoverably.The Registry could not flush hive (file): ''.
9.5.2013 г. 15:41:46, Error: sptd [4] - Driver detected an internal error in its data structures for .
8.5.2013 г. 7:50:31, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with the following service-specific error: There are no more endpoints available from the endpoint mapper.
8.5.2013 г. 7:49:20, Error: Microsoft-Windows-Kernel-General [6] - An I/O operation initiated by the Registry failed unrecoverably.The Registry could not flush hive (file): ''.
8.5.2013 г. 7:49:12, Error: sptd [4] - Driver detected an internal error in its data structures for .
7.5.2013 г. 4:28:45, Error: Microsoft-Windows-Kernel-General [6] - An I/O operation initiated by the Registry failed unrecoverably.The Registry could not flush hive (file): ''.
7.5.2013 г. 4:28:42, Error: sptd [4] - Driver detected an internal error in its data structures for .
7.5.2013 г. 4:26:20, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with the following service-specific error: There are no more endpoints available from the endpoint mapper.
7.5.2013 г. 3:41:05, Error: Microsoft-Windows-Kernel-General [6] - An I/O operation initiated by the Registry failed unrecoverably.The Registry could not flush hive (file): ''.
7.5.2013 г. 3:41:02, Error: sptd [4] - Driver detected an internal error in its data structures for .
7.5.2013 г. 3:39:35, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with the following service-specific error: There are no more endpoints available from the endpoint mapper.
7.5.2013 г. 3:38:43, Error: Microsoft-Windows-Kernel-General [6] - An I/O operation initiated by the Registry failed unrecoverably.The Registry could not flush hive (file): ''.
7.5.2013 г. 3:38:40, Error: sptd [4] - Driver detected an internal error in its data structures for .
7.5.2013 г. 3:18:18, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with the following service-specific error: There are no more endpoints available from the endpoint mapper.
7.5.2013 г. 3:14:37, Error: Microsoft-Windows-Kernel-General [6] - An I/O operation initiated by the Registry failed unrecoverably.The Registry could not flush hive (file): ''.
7.5.2013 г. 3:14:33, Error: sptd [4] - Driver detected an internal error in its data structures for .
7.5.2013 г. 11:58:12, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with the following service-specific error: There are no more endpoints available from the endpoint mapper.
6.5.2013 г. 14:12:51, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with the following service-specific error: There are no more endpoints available from the endpoint mapper.
6.5.2013 г. 14:11:42, Error: Microsoft-Windows-Kernel-General [6] - An I/O operation initiated by the Registry failed unrecoverably.The Registry could not flush hive (file): ''.
6.5.2013 г. 14:11:37, Error: sptd [4] - Driver detected an internal error in its data structures for .
6.5.2013 г. 12:41:44, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with the following service-specific error: There are no more endpoints available from the endpoint mapper.
6.5.2013 г. 12:34:20, Error: Microsoft-Windows-Kernel-General [6] - An I/O operation initiated by the Registry failed unrecoverably.The Registry could not flush hive (file): ''.
6.5.2013 г. 12:34:15, Error: sptd [4] - Driver detected an internal error in its data structures for .
4.5.2013 г. 8:11:24, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with the following service-specific error: There are no more endpoints available from the endpoint mapper.
4.5.2013 г. 8:10:18, Error: Microsoft-Windows-Kernel-General [6] - An I/O operation initiated by the Registry failed unrecoverably.The Registry could not flush hive (file): ''.
4.5.2013 г. 8:10:10, Error: sptd [4] - Driver detected an internal error in its data structures for .
4.5.2013 г. 1:08:31, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with the following service-specific error: There are no more endpoints available from the endpoint mapper.
4.5.2013 г. 1:06:32, Error: Microsoft-Windows-Kernel-General [6] - An I/O operation initiated by the Registry failed unrecoverably.The Registry could not flush hive (file): ''.
4.5.2013 г. 1:06:24, Error: sptd [4] - Driver detected an internal error in its data structures for .
3.5.2013 г. 20:59:06, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user NT AUTHORITYSYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
3.5.2013 г. 12:05:58, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with the following service-specific error: There are no more endpoints available from the endpoint mapper.
3.5.2013 г. 12:03:58, Error: Microsoft-Windows-Kernel-General [6] - An I/O operation initiated by the Registry failed unrecoverably.The Registry could not flush hive (file): ''.
3.5.2013 г. 12:03:54, Error: sptd [4] - Driver detected an internal error in its data structures for .
2.5.2013 г. 8:53:59, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with the following service-specific error: There are no more endpoints available from the endpoint mapper.
2.5.2013 г. 8:51:10, Error: Microsoft-Windows-Kernel-General [6] - An I/O operation initiated by the Registry failed unrecoverably.The Registry could not flush hive (file): ''.
2.5.2013 г. 8:51:03, Error: sptd [4] - Driver detected an internal error in its data structures for .
.
==== End Of File ===========================

Редактирано от icotonev (преглед на промените)

отворих този файл-http://hotfile.com/dl/213772755/d1dd94e/IMG0593020493-JPG във facebook и антивирусната ми отчете 55 заразени файла след като ги изтрива пак ги качва а skype го праща на всички абонати какво да направя

Като за начало научи правилата за пунктуация. И дай малко по-подробна информация - коя ОС използваш, коя антивирусна програма, кои са ти заразените файлове по-конкретно ако може?...

Наистина там е мястото където трябва да потърсиш помощ счетоводни услуги

Редактирано от toniproshkov (преглед на промените)

Здравейте..!
 
Публикувано изображение Изтеглете ComboFix Публикувано изображение от тук и го запазете на десктопа си
Изключете вашата антивирусна и антишпионска програма, обикновено това става чрез натискане на десния бутон на мишката върху иконата на програма в системния трей.
Бележка: Ако не можете я спрете или не сте сигурни коя програма да изключите, моля прегледайте информацията от този линк: How to Disable your Security Programs
Стартирайте Combo-Fix.com Публикувано изображение и следвайте инструкциите.
Бележка: ComboFix ще се стартира без инсталирана Recovery Console.
Като част от неговата работа, ComboFix ще провери дали Microsoft Windows Recovery Console е инсталирана. Предвид бързо развиващия се зловреден софтуер е силно препоръчително да бъде инсталирана преди премахването на зловредния софтуер. Това ще Ви позволи да влезете в специален recovery/repai режим, който ще ни позволи по-лесно да решите проблем, който би могъл да възникне при премахване на зловредния софтуер.

  • [*]Следвайте инструкциите, за да позволите на
ComboFix да изтегли и инсталира Microsoft Windows Recovery Console.В един момент ще бъдете попитани дали сте съгласни с лицензното споразумение. Необходимо е да потвърдите, че сте съгласни, за да инсталирате Microsoft Windows Recovery Console.

** Забележете: Ако Microsoft Windows Recovery Console е вече инсталирана, ComboFix ще продължи към процеса по премахване на зловредния софтуер.
Публикувано изображение
След като Microsoft Windows Recovery Console е инсталирана, използвайки ComboFix, Вие ще видите следното съобщение:
Публикувано изображение
Изберете Yes, за да продължи сканирането за зловреден софтуер.
Когато процесът приключи успешно, инструментът ще създаде лог файл. Моля, включете съдържанието на C:ComboFix.txt в следващия Ви коментар в тази тема.
Бележка:

  • [*]Моля, не движете мишката, докато ComboFix работи. Това може да наруши процеса на работа. [*]ComboFix ще нулира всички настройки на
Microsoft Internet Explorer, включително да направи IE браузър по подразбиране. [*]ComboFix ще изключи autorun функцията на ВСИЧКИ CD, Floppy и USB устройства, за да помогне при премахването на зловредния софтуер и Ви защити от бъдещи вируси/заплахи, които поразява чрез autorun. Ако това е проблем за вас - моля, уведомете ме. [*]ComboFix ще изключи вашата интернет връзка. Интернет връзката ще се възстанови автоматично, преди ComboFix да завърши процеса на работа. При проблем, той ще прекрати интернет връзката. За да възстановите интернет връзката си, рестартирайте компютъра си. [*]В случай на проблем с ComboFix, той може да създаде лог файл. Моля, включете съдържанието на C:BUG.txt в следващия Ви коментар в тази тема.

Публикувано изображение Моля, не прикачвайте лог файла/овете от програмата, а го/ги копирайте и поставете в следващия Ви коментар в тази тема.

  • Автор

Имали значение че съм със Windowс8 защото не се инсталира ComboFix

Чакай ,чакай......!Остави го Комбофикс....!
 
Публикувано изображениеМоля, изтеглете и стартирайте програмата AdwCleaner(by Xplode):

  • [*]Затворете всички стартирани програми и браузъри [*]Кликнете два пъти върху
adwcleaner.exe за да стартирате инструмента. [*]Този път маркирайте Delete [*]Вашият компютър ще се рестартира автоматично. Текстовия файл ще се отвори след рестарта. [*]Моля, да публикувате съдържанието на този лог в отговора си [*]Можете да намерите лога,който автоматично се запомня тук C:AdwCleaner[s1].txt.

Публикувано изображение
Публикувано изображение Моля, изтеглете Junkware Removal Tool (by Thisisu ) и запазете на вашия десктоп.

  • [*]Спрете временно работата на защитните програми. [*]Стартирайте инструмента
JRT.exe [*]Ще се отвори ДОС прозорец. Натиснете което и да е копче от клавиатурата. [*]Затворете излишните приложения и всички браузъри и изчакайте проверката да завърши. [*]Ще се появи лог файл (който можете да намерите и ръчно на десктопа с името JRT.txt). [*]Моля копирайте съдържанието на лог файла в следващия си пост.

Публикувано изображение


След като публикувате резултатите от сканиранията с двете програми продължете с:
 
 
Изтеглете OTL.exe и го запазете на десктопа.

  • [*]Стартирайте
OTL.exe. [*]Направете следните настройки: [*]Сложете отметка пред Scan All Users [*]Под менюто File Age изберете 90 days [*]Под менюто Standard Registry променете на ALL [*]Сложете отметки пред LOP и Purity Check

Под Публикувано изображение с Copy/ Paste въведете изцяло следната текстова информация (само това, което е поставено в карето):

netsvcs%SYSTEMDRIVE%*.exe/md5startexplorer.exewinlogon.exeUserinit.exesvchost.exeservices.exe/md5stop%systemroot%*. /rp /s%systemdrive%$Recycle.Bin|@;true;true;true /fpDRIVESCREATERESTOREPOINT
  • [*]Натиснете маркираният в синьо бутон:
Run Scan. [*]Като приключи проверката, ще се създадат два файла - OTL.Txt и Extras.Txt. Файлът OTL.Txt копирайте в следващия си пост. Extras.Txt прикачете в следващия си коментар (погледнете опцията Прикачени файлове, когато публикувате мнение).

  • Автор

# AdwCleaner v2.300 - Logfile created 05/10/2013 at 22:48:05 # Updated 28/04/2013 by Xplode # Operating system : Windows 8 Enterprise (64 bits) # User : 1 - FRITZ # Boot Mode : Normal # Running from : C:Users1Desktopadwcleaner.exe # Option [Delete] ***** [services] ***** Stopped & Deleted : Application Updater ***** [Files / Folders] ***** File Deleted : C:END File Deleted : C:Program Files (x86)Mozilla Firefoxsearchpluginsbabylon.xml File Deleted : C:user.js Folder Deleted : C:Program Files (x86)Application Updater Folder Deleted : C:Program Files (x86)AskTBar Folder Deleted : C:Program Files (x86)Babylon Folder Deleted : C:Program Files (x86)Common Filesspigot Folder Deleted : C:Program Files (x86)Conduit Folder Deleted : C:Program Files (x86)MapsGalaxy_39 Folder Deleted : C:Program Files (x86)SimilarSites Folder Deleted : C:Program Files (x86)uTorrentControl_v2 Folder Deleted : C:Program FilesBabylon Folder Deleted : C:ProgramDataBabylon Folder Deleted : C:ProgramDataInstallMate Folder Deleted : C:ProgramDataRightClick Folder Deleted : C:ProgramDataSoftSafe Folder Deleted : C:Users1AppDataLocalBabylon Folder Deleted : C:Users1AppDataLocalConduit Folder Deleted : C:Users1AppDataLocalGoogleChromeUser DataDefaultExtensionsejpbbhjlbipncjklfjjaedaieimbmdda Folder Deleted : C:Users1AppDataLocalIlivid Folder Deleted : C:Users1AppDataLocalLowConduit Folder Deleted : C:Users1AppDataLocalLowMapsGalaxy_39 Folder Deleted : C:Users1AppDataLocalLowSearch Settings Folder Deleted : C:Users1AppDataLocalLowuTorrentControl_v2 Folder Deleted : C:Users1AppDataRoamingBabylon Folder Deleted : C:Users1AppDataRoamingMozillaFirefoxProfilesfafs95p1.default-1358285078196extensions39ffxtbr@MapsGalaxy_39.com Folder Deleted : C:Users1AppDataRoamingMozillaFirefoxProfilesfafs95p1.default-1358285078196jetpack Folder Deleted : C:Users1AppDataRoamingNCdownloader Folder Deleted : C:Users1AppDataRoamingOpenCandy ***** [Registry] ***** Key Deleted : HKCUSoftwareAPN PIP Key Deleted : HKCUSoftwareAppDataLowSoftwareConduit Key Deleted : HKCUSoftwareAppDataLowSoftwareSearch Settings Key Deleted : HKCUSoftwareAppDataLowSoftwareSmartBar Key Deleted : HKCUSoftwareAppDataLowSoftwareuTorrentControl_v2 Key Deleted : HKCUSoftwareAppDataLowToolbar Key Deleted : HKCUSoftwareConduit Key Deleted : HKCUSoftwareGoogleChromeExtensionsejpbbhjlbipncjklfjjaedaieimbmdda Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{7473B6BD-4691-4744-A82B-7854EB3D70B6} Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{9CB65201-89C4-402C-BA80-02D8C59F9B1D} Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{F3FEE66E-E034-436A-86E4-9690573BEE8A} Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{FE063DB1-4EC0-403E-8DD8-394C54984B2C} Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{FE063DB9-4EC0-403E-8DD8-394C54984B2C} Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{7473B6BD-4691-4744-A82B-7854EB3D70B6} Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{9CB65201-89C4-402C-BA80-02D8C59F9B1D} Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{F3FEE66E-E034-436A-86E4-9690573BEE8A} Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{FE063DB1-4EC0-403E-8DD8-394C54984B2C} Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{FE063DB9-4EC0-403E-8DD8-394C54984B2C} Key Deleted : HKCUSoftwarePIP Key Deleted : HKCUSoftwareSearch Settings Key Deleted : HKCUSoftwareSoftonic Key Deleted : HKCUSoftwareuTorrentControl_v2 Key Deleted : HKCUSoftwareMicrosoftInternet ExplorerSearchScopes{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Key Deleted : HKCUSoftwareMicrosoftInternet ExplorerSearchScopes{96BD48DD-741B-41AE-AC4A-AFF96BA00F7E} Key Deleted : HKLMSoftwareApplication Updater Key Deleted : HKLMSoftwareBabylon Key Deleted : HKLMSoftwareBabylonToolbar Key Deleted : HKLMSOFTWAREClassesAppID{09C554C3-109B-483C-A06B-F14172F1A947} Key Deleted : HKLMSOFTWAREClassesAppID{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Key Deleted : HKLMSOFTWAREClassesAppID{6536801B-F50C-449B-9476-093DFD3789E3} Key Deleted : HKLMSOFTWAREClassesAppID{B12E99ED-69BD-437C-86BE-C862B9E5444D} Key Deleted : HKLMSOFTWAREClassesAppID{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Key Deleted : HKLMSOFTWAREClassesAppID{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Key Deleted : HKLMSOFTWAREClassesAppIDBabylonHelper.EXE Key Deleted : HKLMSOFTWAREClassesAppIDescort.DLL Key Deleted : HKLMSOFTWAREClassesAppIDescortApp.DLL Key Deleted : HKLMSOFTWAREClassesAppIDescortEng.DLL Key Deleted : HKLMSOFTWAREClassesAppIDescorTlbr.DLL Key Deleted : HKLMSOFTWAREClassesAppIDesrv.EXE Key Deleted : HKLMSOFTWAREClassesescort.escortIEPane Key Deleted : HKLMSOFTWAREClassesescort.escortIEPane.1 Key Deleted : HKLMSOFTWAREClassesProd.cap Key Deleted : HKLMSOFTWAREClassesToolbar.CT2269050 Key Deleted : HKLMSOFTWAREClassesToolbar.CT3220468 Key Deleted : HKLMSOFTWAREClassesTypeLib{03119103-0854-469D-807A-171568457991} Key Deleted : HKLMSOFTWAREClassesTypeLib{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Key Deleted : HKLMSOFTWAREClassesTypeLib{5C9A2304-70A5-11D5-AFB0-0050DAC67890} Key Deleted : HKLMSOFTWAREClassesTypeLib{AC329328-7EC4-4C34-B672-0A2B90CB9B00} Key Deleted : HKLMSOFTWAREClassesTypeLib{CCA8F2AB-BE4E-41F0-A289-4D960CEA58EA} Key Deleted : HKLMSOFTWAREClassesTypeLib{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Key Deleted : HKLMSoftwareConduit Key Deleted : HKLMSOFTWAREMicrosoftTracingBabylon_RASAPI32 Key Deleted : HKLMSOFTWAREMicrosoftTracingConduitInstaller_RASAPI32 Key Deleted : HKLMSOFTWAREMicrosoftTracingMyBabylontb_RASAPI32 Key Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionExtPreApproved{537F4F0B-3542-4C7D-A3E5-CF121482696C} Key Deleted : HKLMSoftwarePIP Key Deleted : HKLMSoftwareSearch Settings Key Deleted : HKLMSoftwareuTorrentControl_v2 Key Deleted : HKLMSOFTWAREWow6432NodeClassesCLSID{13119113-0854-469D-807A-171568457991} Key Deleted : HKLMSOFTWAREWow6432NodeClassesCLSID{147A976F-EEE1-4377-8EA7-4716E4CDD239} Key Deleted : HKLMSOFTWAREWow6432NodeClassesCLSID{14F35FFC-522A-4DD1-A07E-6B8B65C6891E} Key Deleted : HKLMSOFTWAREWow6432NodeClassesCLSID{33119133-0854-469D-807A-171568457991} Key Deleted : HKLMSOFTWAREWow6432NodeClassesCLSID{3C471948-F874-49F5-B338-4F214A2EE0B1} Key Deleted : HKLMSOFTWAREWow6432NodeClassesCLSID{537F4F0B-3542-4C7D-A3E5-CF121482696C} Key Deleted : HKLMSOFTWAREWow6432NodeClassesCLSID{7473B6BD-4691-4744-A82B-7854EB3D70B6} Key Deleted : HKLMSOFTWAREWow6432NodeClassesCLSID{9AFB8248-617F-460D-9366-D71CDEDA3179} Key Deleted : HKLMSOFTWAREWow6432NodeClassesCLSID{9CB65201-89C4-402C-BA80-02D8C59F9B1D} Key Deleted : HKLMSOFTWAREWow6432NodeClassesCLSID{9CB65206-89C4-402C-BA80-02D8C59F9B1D} Key Deleted : HKLMSOFTWAREWow6432NodeClassesCLSID{F3FEE66E-E034-436A-86E4-9690573BEE8A} Key Deleted : HKLMSOFTWAREWow6432NodeClassesCLSID{FE063DB1-4EC0-403E-8DD8-394C54984B2C} Key Deleted : HKLMSOFTWAREWow6432NodeClassesCLSID{FE063DB9-4EC0-403E-8DD8-394C54984B2C} Key Deleted : HKLMSOFTWAREWow6432NodeClassesInterface{0BF91075-F457-4A8B-99EF-140B52D2F22A} Key Deleted : HKLMSOFTWAREWow6432NodeClassesInterface{23119123-0854-469D-807A-171568457991} Key Deleted : HKLMSOFTWAREWow6432NodeClassesInterface{37425600-CB21-49A0-8659-476FBAB0F8E8} Key Deleted : HKLMSOFTWAREWow6432NodeClassesInterface{431FB0E5-2CBB-4602-9FE6-F1D64488ADD7} Key Deleted : HKLMSOFTWAREWow6432NodeClassesInterface{5C9A230D-70A5-11D5-AFB0-0050DAC67890} Key Deleted : HKLMSOFTWAREWow6432NodeClassesInterface{8911483C-C00A-4183-9FBC-6C9C00946C15} Key Deleted : HKLMSOFTWAREWow6432NodeClassesInterface{A36BCB13-778D-4A40-99C1-D686086D268F} Key Deleted : HKLMSOFTWAREWow6432NodeClassesInterface{C3F058A9-407D-4CD1-8F66-B75605B54B69} Key Deleted : HKLMSOFTWAREWow6432NodeClassesInterface{EFDCAF05-D29C-4D4D-9836-8CDCD606A6B2} Key Deleted : HKLMSOFTWAREWow6432NodeGoogleChromeExtensionsejpbbhjlbipncjklfjjaedaieimbmdda Key Deleted : HKLMSOFTWAREWow6432NodeMicrosoftInternet ExplorerLow RightsElevationPolicy{17DAEE8A-E00A-417D-A385-4441476F3142} Key Deleted : HKLMSOFTWAREWow6432NodeMicrosoftInternet ExplorerLow RightsElevationPolicy{4D28FD61-6579-4F42-AE13-06BEF362D70E} Key Deleted : HKLMSOFTWAREWow6432NodeMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{7473B6BD-4691-4744-A82B-7854EB3D70B6} Key Deleted : HKLMSOFTWAREWow6432NodeMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{9CB65201-89C4-402C-BA80-02D8C59F9B1D} Key Deleted : HKLMSOFTWAREWow6432NodeMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{F3FEE66E-E034-436A-86E4-9690573BEE8A} Key Deleted : HKLMSOFTWAREWow6432NodeMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{FE063DB1-4EC0-403E-8DD8-394C54984B2C} Key Deleted : HKLMSOFTWAREWow6432NodeMicrosoftWindowsCurrentVersionUninstalluTorrentControl_v2 Toolbar Key Deleted : HKLMSOFTWAREClassesInterface{0BF91075-F457-4A8B-99EF-140B52D2F22A} Key Deleted : HKLMSOFTWAREClassesInterface{23119123-0854-469D-807A-171568457991} Key Deleted : HKLMSOFTWAREClassesInterface{37425600-CB21-49A0-8659-476FBAB0F8E8} Key Deleted : HKLMSOFTWAREClassesInterface{431FB0E5-2CBB-4602-9FE6-F1D64488ADD7} Key Deleted : HKLMSOFTWAREClassesInterface{5C9A230D-70A5-11D5-AFB0-0050DAC67890} Key Deleted : HKLMSOFTWAREClassesInterface{8911483C-C00A-4183-9FBC-6C9C00946C15} Key Deleted : HKLMSOFTWAREClassesInterface{A36BCB13-778D-4A40-99C1-D686086D268F} Key Deleted : HKLMSOFTWAREClassesInterface{C3F058A9-407D-4CD1-8F66-B75605B54B69} Key Deleted : HKLMSOFTWAREClassesInterface{EFDCAF05-D29C-4D4D-9836-8CDCD606A6B2} Value Deleted : HKCUSoftwareMicrosoftInternet ExplorerURLSearchHooks [{7473B6BD-4691-4744-A82B-7854EB3D70B6}] Value Deleted : HKCUSoftwareMicrosoftInternet ExplorerURLSearchHooks [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}] Value Deleted : HKCUSoftwareMicrosoftInternet ExplorerURLSearchHooks [{9CB65206-89C4-402C-BA80-02D8C59F9B1D}] Value Deleted : HKCUSoftwareMicrosoftInternet ExplorerURLSearchHooks [{F3FEE66E-E034-436A-86E4-9690573BEE8A}] Value Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun [searchSettings] Value Deleted : HKLMSOFTWAREWow6432NodeMicrosoftInternet ExplorerToolbar [{7473B6BD-4691-4744-A82B-7854EB3D70B6}] Value Deleted : HKLMSOFTWAREWow6432NodeMicrosoftInternet ExplorerToolbar [{F3FEE66E-E034-436A-86E4-9690573BEE8A}] Value Deleted : HKLMSOFTWAREWow6432NodeMicrosoftInternet ExplorerToolbar [{FE063DB9-4EC0-403E-8DD8-394C54984B2C}] ***** [internet Browsers] ***** - Internet Explorer v10.0.9200.16453 [OK] Registry is clean. - Mozilla Firefox v20.0.1 (bg) File : C:Users1AppDataRoamingMozillaFirefoxProfilesfafs95p1.default-1358285078196prefs.js C:Users1AppDataRoamingMozillaFirefoxProfilesfafs95p1.default-1358285078196user.js ... Deleted ! Deleted : user_pref("extensions.512e009663211.scode", "(function(){try{if('aol.com,mail.google.com,premiumrepo[...] Deleted : user_pref("extensions.BabylonToolbar.admin", false); Deleted : user_pref("extensions.BabylonToolbar.aflt", "babsst"); Deleted : user_pref("extensions.BabylonToolbar.appId", "{BDB69379-802F-4eaf-B541-F8DE92DD98DB}"); Deleted : user_pref("extensions.BabylonToolbar.autoRvrt", "false"); Deleted : user_pref("extensions.BabylonToolbar.dfltLng", "en"); Deleted : user_pref("extensions.BabylonToolbar.excTlbr", false); Deleted : user_pref("extensions.BabylonToolbar.ffxUnstlRst", true); Deleted : user_pref("extensions.BabylonToolbar.id", "70df0a84000000000000a417312b1658"); Deleted : user_pref("extensions.BabylonToolbar.instlDay", "15739"); Deleted : user_pref("extensions.BabylonToolbar.instlRef", "na"); Deleted : user_pref("extensions.BabylonToolbar.newTab", false); Deleted : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar"); Deleted : user_pref("extensions.BabylonToolbar.prtnrId", "babylon"); Deleted : user_pref("extensions.BabylonToolbar.rvrt", "false"); Deleted : user_pref("extensions.BabylonToolbar.smplGrp", "none"); Deleted : user_pref("extensions.BabylonToolbar.tlbrId", "uninst"); Deleted : user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "hxxp://search.babylon.com/?babsrc=TB_def&mntrId=[...] Deleted : user_pref("extensions.BabylonToolbar.vrsn", "1.8.11.10"); Deleted : user_pref("extensions.BabylonToolbar.vrsnTs", "1.8.11.1020:21:10"); Deleted : user_pref("extensions.BabylonToolbar.vrsni", "1.8.11.10"); Deleted : user_pref("extensions.BabylonToolbar_i.babExt", ""); Deleted : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=10588&tl=gkn354482"); Deleted : user_pref("extensions.BabylonToolbar_i.srcExt", "def"); - Google Chrome v [unable to get version] File : C:Users1AppDataLocalGoogleChromeUser DataDefaultPreferences [OK] File is clean. ************************* AdwCleaner[s1].txt - [13493 octets] - [10/05/2013 22:48:05] ########## EOF - C:AdwCleaner[s1].txt - [13554 octets] ##########

Здравейте..!Малко сте съкратили инструкциите ми..!
 
Публикувано изображение Стартирайте отново OTL, копирайте (Copy) и поставете (Paste) скриптовия текст от текстовото поле по-долу под колонката Custom Scans/Fixes, като не забравяте да копирате скрипта 1 към 1, както и двете точки преди първия ред на скрипта.

:OTLFF - HKLMSoftwareMozillaPlugins@MapsGalaxy_39.com/Plugin: C:Program Files (x86)MapsGalaxy_39bar1.binNP39Stub.dll File not foundFF - HKEY_LOCAL_MACHINEsoftwaremozillaFirefoxExtensionsocr@babylon.com: C:Program Files (x86)[email protected] - BHO: (Toolbar BHO) - {1e91a655-bb4b-4693-a05e-2edebc4c9d89} - C:PROGRA~2MAPSGA~2bar1.bin39bar.dll File not foundO3 - HKLM..Toolbar: (MapsGalaxy) - {364ea597-e728-4ce4-bb4a-ed846ef47970} - C:Program Files (x86)MapsGalaxy_39bar1.bin39bar.dll File not foundO4 - HKLM..Run: []  File not foundO33 - MountPoints2{e29c6a21-9f4b-11e2-bef1-a417312b1658}Shell - "" = AutoRunO33 - MountPoints2{e29c6a21-9f4b-11e2-bef1-a417312b1658}ShellAutoRuncommand - "" = "D:setup.exe"@Alternate Data Stream - 122 bytes -> C:ProgramDataTEMP:373E1720@Alternate Data Stream - 112 bytes -> C:ProgramDataTEMP:D1B5B4F1autorun.inf /alldrivesrecycler /alldrivesipconfig /flushdns /c:Commands[purity][emptytemp][clearallrestorepoints][Reboot]

Публикувано изображение След като въведете скрипта от цитата по-горе натиснете бутона, маркиран в червено: Run Fix
Windows ще се рестартира и ще се създаде лог файл. Публикувайте съдържанието му с Copy/Paste в следващия си коментар.
По време на фикса с инструмента, не използвайте компютъра си!

  • Автор

All processes killed ========== OTL ========== Registry key HKEY_LOCAL_MACHINESoftwareMozillaPlugins@MapsGalaxy_39.com/Plugin deleted successfully. Registry value HKEY_LOCAL_MACHINEsoftwaremozillaFirefoxExtensionsocr@babylon.com deleted successfully. File C:Program Files (x86)[email protected] not found. Registry key HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{1e91a655-bb4b-4693-a05e-2edebc4c9d89} deleted successfully. Registry key HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{1e91a655-bb4b-4693-a05e-2edebc4c9d89} deleted successfully. Registry value HKEY_LOCAL_MACHINESoftwareMicrosoftInternet ExplorerToolbar{364ea597-e728-4ce4-bb4a-ed846ef47970} deleted successfully. Registry key HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{364ea597-e728-4ce4-bb4a-ed846ef47970} deleted successfully. Registry value HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun deleted successfully. Registry key HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionExplorerMountPoints2{e29c6a21-9f4b-11e2-bef1-a417312b1658} deleted successfully. Registry key HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{e29c6a21-9f4b-11e2-bef1-a417312b1658} not found. Registry key HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionExplorerMountPoints2{e29c6a21-9f4b-11e2-bef1-a417312b1658} not found. Registry key HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{e29c6a21-9f4b-11e2-bef1-a417312b1658} not found. File "D:setup.exe" not found. ADS C:ProgramDataTEMP:373E1720 deleted successfully. ADS C:ProgramDataTEMP:D1B5B4F1 deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: 1 ->Temp folder emptied: 3238418229 bytes ->Temporary Internet Files folder emptied: 169764327 bytes ->FireFox cache emptied: 423556011 bytes ->Google Chrome cache emptied: 13114734 bytes ->Flash cache emptied: 379888184 bytes User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%System32 .tmp files removed: 0 bytes %systemroot%System32 (64bit) .tmp files removed: 0 bytes %systemroot%System32drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 13067989 bytes %systemroot%sysnativeconfigsystemprofileAppDataLocalMicrosoftWindowsTemporary Internet Files folder emptied: 128 bytes RecycleBin emptied: 207194 bytes Total Files Cleaned = 4 042,00 mb Restore point Set: OTL Restore Point OTL by OldTimer - Version 3.2.69.0 log created on 05132013_165142 FilesFolders moved on Reboot... C:Users1AppDataLocalMicrosoftWindowsTemporary Internet Filescounters.dat moved successfully. File move failed. C:Windowstemp_avast_Webshlock.txt scheduled to be moved on reboot. PendingFileRenameOperations files... Registry entries deleted on Reboot...

Публикувано изображение Изтеглете Malwarebytes' Anti-Malware или от тук (не забравяйте да обновите програмата с нови дефиниции)
* Кликнете два пъти върху mbam-setup.exe, за да инсталирате програмата.
* Уверете се, че са поставени отметки на Update Malwarebytes' Anti-Malware и Launch Malwarebytes' Anti-Malware. След това кликнете на Finish.
* Ако има намерени обновявания, тя ще ги изтегли и инсталира.
* Стартирайте програмата и изберете "Perform Full Scan", след това кликнете на Scan.
* Сканирането ще отнеме малко време, затова моля да бъдете търпеливи.
* Когато сканирането завърши, кликнете на OK, след това Show Results, за да видите резултата
* Уверете се, че на всички редове има отметки, и кликнете на Remove Selected.
* Когато всичко бъде премахнато, в Notepad ще бъде отворен лог.
Копирайте този лог и го публикувайте в следващия си коментар по темата.

  Забележка: Ако MalwareBytes' Anti-Malware се затрудни в премахването на откритите вируси/заплахи, той ще поиска да рестартира компютъра Ви и по време на рестартирането да премахне проблемните вируси/заплахи. Ако бъдете попитани, потвърдете че желаете вашия компютър да бъде рестартиран.

  • Автор

Malwarebytes Anti-Malware (Trial) 1.75.0.1300 www.malwarebytes.org Database version: v2013.05.13.06 Windows 8 x64 NTFS Internet Explorer 10.0.9200.16466 1 :: FRITZ [administrator] Protection: Enabled 13.5.2013 г. 19:54:21 mbam-log-2013-05-13 (19-54-21).txt Scan type: Full scan (C:|E:|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 364084 Time elapsed: 38 minute(s), 32 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)

  • Автор

Няма ги тези неща които правеше. Благодаря много

Чудесно..!
 
Публикувано изображение Изтеглете Публикувано изображениеTFC (Temp File Cleaner) от тук и го запишете на десктопа.

  • [*]Стартирайте
TFC.exe [*]Имайте търпение и изчакайте програмата да завърши работата си [*]Ако е необходимо, потвърдете с OK за рестартиране на Windows

 

Публикувано изображение Изтеглете Публикувано изображениеOTCleanIt или от тук,стартирайте и натиснете Публикувано изображение

Публикувано изображение Изтеглете Delfix.exe и го стартирайте. Сложете отметка пред Remove disinfection tools => натиснете бутона Run Инструмента ще се самоизтрие след като приключи своята задача!

 

 

Публикувано изображение Изтрийте всичко друго което е останало след процедурите (използвано в лечението).Препоръчвам програмата Malwarebytes' Anti-Malware да остане на вашия компютър и периодично да сканирате системата си с нея (поне един -два пъти в седмицата),като не забравяйте да обновите дефинициите и преди всяко сканиране..!


Това е от мен...Пожелавам ви лек ден  и безопасен интернет..! :)

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.