Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

премахване на PC PERFORMER

Featured Replies

Здравейте!Пускам тема и тук защото така ме посъветваха,ако е излишна се извинявам!За да не се повтарям ето линка към другата темаhttp://www.kaldata.com/forums/topic/211034-%D0%BF%D0%BE%D0%BC%D0%BE%D0%B3%D0%BD%D0%B5%D1%82%D0%B5-%D0%B4%D0%B0-%D0%B8%D0%B7%D1%82%D1%80%D0%B8%D1%8F-%D0%B4%D0%BE%D1%81%D0%B0%D0%B4%D0%BD%D0%BE%D1%82%D0%BE-pc-performer/,за да не се повтарям.Та моля да ми кажете дали съм изчистила всичко?Появи ми се само този файл,като следвах стъпките: DDS (Ver_2011-09-30.01) - NTFS_x86
Internet Explorer: 6.0.2900.5512
Run by CTX at 14:17:38 on 2013-05-14
Microsoft Windows XP Professional  5.1.2600.3.1251.359.1033.18.2047.1227 [GMT 3:00]
.
AV: AntiVir Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
AV: avast! Internet Security *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: avast! Internet Security *Disabled*
.
============== Running Processes ================
.
C:WINDOWSsystem32Ati2evxx.exe
C:Program FilesAVAST SoftwareAvastAvastSvc.exe
C:WINDOWSsystem32Ati2evxx.exe
C:Program FilesAVAST SoftwareAvastafwServ.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSExplorer.EXE
C:WINDOWSRTHDCPL.EXE
C:Program FilesAVAST SoftwareAvastavastUI.exe
C:Program FilesATI TechnologiesATI.ACECore-StaticMOM.exe
C:WINDOWSsystem32ctfmon.exe
C:Program FilesYahoo!WidgetsYahooWidgets.exe
C:Program FilesSUPERAntiSpywareSASCORE.EXE
C:Program FilesMalwarebytes' Anti-Malwarembamscheduler.exe
C:Program FilesYahoo!WidgetsYahooWidgets.exe
C:Program FilesYahoo!WidgetsYahooWidgets.exe
C:Program FilesYahoo!WidgetsYahooWidgets.exe
C:Program FilesYahoo!WidgetsYahooWidgets.exe
C:Program FilesMalwarebytes' Anti-Malwarembamservice.exe
C:Documents and SettingsAll UsersApplication DataSkypeToolbarsSkype C2C Servicec2c_service.exe
C:Program FilesMalwarebytes' Anti-Malwarembamgui.exe
C:Program FilesATI TechnologiesATI.ACECore-Staticccc.exe
C:Program FilesMozilla Firefoxfirefox.exe
C:WINDOWSsystem32wbemwmiprvse.exe
C:WINDOWSSystem32svchost.exe -k netsvcs
C:WINDOWSsystem32svchost.exe -k NetworkService
C:WINDOWSsystem32svchost.exe -k LocalService
C:WINDOWSsystem32svchost.exe -k LocalService
C:WINDOWSsystem32svchost.exe -k imgsvc
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.yahoo.com
uSearch Bar = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
uSearch Page = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.yahoo.com
mDefault_Page_URL = hxxp://www.yahoo.com
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
BHO: Помощник за връзки на Adobe PDF Reader: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:program filescommon filesadobeacrobatactivexAcroIEHelper.dll
BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - c:program filesskypetoolbarsinternet explorerskypeieplugin.dll
uRun: [ctfmon.exe] c:windowssystem32ctfmon.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [startCCC] "c:program filesati technologiesati.acecore-staticCLIStart.exe" MSRun
mRun: [avast] "c:program filesavast softwareavastavastUI.exe" /nogui
dRun: [CTFMON.EXE] c:windowssystem32CTFMON.EXE
dRun: [PC Performer43885.exe] "c:windowstemppc performer43885.exe" /xml="c:windowstempC.tmp" /STP=0:1
StartupFolder: c:docume~1ctxstartm~1programsstartupyahoo!~1.lnk - c:program filesyahoo!widgetsYahooWidgets.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:program filesskypetoolbarsinternet explorerskypeieplugin.dll
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%Network Diagnosticxpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:program filesmessengermsmsgs.exe
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:program filesyahoo!commonYinsthelper.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://windowsupdate.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1364372795984
TCP: NameServer = 192.168.0.1
TCP: Interfaces{D8528D76-52D4-4B4A-809A-EB27BBF6D710} : DHCPNameServer = 192.168.0.1
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:program filesskypetoolbarsinternet explorerskypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:program filescommon filesskypeSkype4COM.dll
Notify: AtiExtEvent - Ati2evxx.dll
SEH: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - c:program filessuperantispywareSASSEH.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:documents and settingsctxapplication datamozillafirefoxprofiles2elnnu1k.default
FF - prefs.js: browser.startup.homepage - hxxp://www.google.bg/
FF - plugin: c:documents and settingsctxlocal settingsapplication datagoogleupdate1.3.21.145npGoogleUpdate3.dll
FF - plugin: c:program filesgooglegoogle earthpluginnpgeplugin.dll
FF - plugin: c:windowssystem32macromedflashNPSWF32_11_6_602_180.dll
.
============= SERVICES / DRIVERS ===============
.
R0 aswKbd;aswKbd;c:windowssystem32driversaswKbd.sys [2012-11-7 21576]
R0 aswNdis;avast! Firewall NDIS Filter Service;c:windowssystem32driversaswNdis.sys [2013-5-11 12112]
R0 aswNdis2;avast! Firewall Core Firewall Service;c:windowssystem32driversaswNdis2.sys [2013-5-11 204784]
R0 aswRvrt;aswRvrt;c:windowssystem32driversaswRvrt.sys [2013-3-21 49376]
R0 aswVmm;aswVmm;c:windowssystem32driversaswVmm.sys [2013-3-21 174664]
R1 aswFW;avast! TDI Firewall Driver;c:windowssystem32driversaswFW.sys [2013-5-11 104752]
R1 aswSnx;aswSnx;c:windowssystem32driversaswSnx.sys [2012-8-10 765736]
R1 aswSP;aswSP;c:windowssystem32driversaswSP.sys [2012-8-10 368944]
R1 avgtp;avgtp;c:windowssystem32driversavgtpx86.sys [2012-10-7 33112]
R1 SASDIFSV;SASDIFSV;c:program filessuperantispywaresasdifsv.sys [2011-7-22 12880]
R1 SASKUTIL;SASKUTIL;c:program filessuperantispywareSASKUTIL.SYS [2011-7-13 67664]
R2 !SASCORE;SAS Core Service;c:program filessuperantispywareSASCORE.EXE [2011-8-12 116608]
R2 aswFsBlk;aswFsBlk;c:windowssystem32driversaswFsBlk.sys [2012-8-10 29816]
R2 aswMonFlt;aswMonFlt;c:windowssystem32driversaswMonFlt.sys [2013-3-21 66336]
R2 avast! Antivirus;avast! Antivirus;c:program filesavast softwareavastAvastSvc.exe [2012-8-10 46808]
R2 avast! Firewall;avast! Firewall;c:program filesavast softwareavastafwServ.exe [2013-5-11 137960]
R2 MBAMScheduler;MBAMScheduler;c:program filesmalwarebytes' anti-malwarembamscheduler.exe [2013-5-14 418376]
R2 MBAMService;MBAMService;c:program filesmalwarebytes' anti-malwarembamservice.exe [2013-5-14 701512]
R2 Skype C2C Service;Skype C2C Service;c:documents and settingsall usersapplication dataskypetoolbarsskype c2c servicec2c_service.exe [2013-4-15 3289208]
R3 MBAMProtector;MBAMProtector;c:windowssystem32driversmbam.sys [2013-5-14 22856]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:windowsmicrosoft.netframeworkv4.0.30319mscorsvw.exe [2010-3-18 130384]
S2 SkypeUpdate;Skype Updater;c:program filesskypeupdaterUpdater.exe [2013-2-28 161384]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:windowssystem32macromedflashFlashPlayerUpdateService.exe [2012-1-6 253656]
S3 Ambfilt;Ambfilt;c:windowssystem32driversAmbfilt.sys [2009-11-16 1691480]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:windowssystem32driversssadadb.sys [2012-3-10 30312]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:program filesmozilla maintenance servicemaintenanceservice.exe [2012-5-27 115608]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:windowssystem32driversssadbus.sys [2012-3-10 121064]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:windowssystem32driversssadmdfl.sys [2012-3-10 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:windowssystem32driversssadmdm.sys [2012-3-10 136808]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:windowssystem32driversssadserd.sys [2012-3-10 114280]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:windowsmicrosoft.netframeworkv4.0.30319wpfWPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2013-05-14 10:38:26  --------  d-----w-  c:documents and settingsctxapplication dataMalwarebytes
2013-05-14 10:38:17  22856  ----a-w-  c:windowssystem32driversmbam.sys
2013-05-14 10:38:16  --------  d-----w-  c:program filesMalwarebytes' Anti-Malware
2013-05-14 08:29:34  --------  d-----w-  c:documents and settingsctxlocal settingsapplication dataThe Weather Channel
2013-05-11 08:49:18  593920  ----a-w-  c:windowssystem32ati2sgag.exe
2013-05-11 08:39:10  204784  ----a-w-  c:windowssystem32driversaswNdis2.sys
2013-05-11 08:39:09  104752  ----a-w-  c:windowssystem32driversaswFW.sys
2013-05-11 08:39:02  12112  ----a-w-  c:windowssystem32driversaswNdis.sys
2013-04-15 12:32:30  6128760  ----a-w-  c:program filesmozilla firefoxextensions{82af8dca-6de9-405d-bd5e-43525bdad38a}componentsSkypeFfComponent.dll
2013-04-15 12:32:30  6128760  ----a-w-  c:program filesmozilla firefoxbrowserextensions{82af8dca-6de9-405d-bd5e-43525bdad38a}componentsSkypeFfComponent.dll
.
==================== Find3M  ====================
.
2013-05-09 08:59:10  765736  ----a-w-  c:windowssystem32driversaswSnx.sys
2013-05-09 08:59:10  49376  ----a-w-  c:windowssystem32driversaswRvrt.sys
2013-05-09 08:59:10  174664  ----a-w-  c:windowssystem32driversaswVmm.sys
2013-05-09 08:59:09  66336  ----a-w-  c:windowssystem32driversaswMonFlt.sys
2013-05-09 08:59:09  21576  ----a-w-  c:windowssystem32driversaswKbd.sys
2013-05-09 08:58:37  41664  ----a-w-  c:windowsavastSS.scr
2013-03-18 15:07:51  33112  ----a-w-  c:windowssystem32driversavgtpx86.sys
2013-03-13 14:00:12  73432  ----a-w-  c:windowssystem32FlashPlayerCPLApp.cpl
2013-03-13 14:00:12  693976  -c--a-w-  c:windowssystem32FlashPlayerApp.exe
.
============= FINISH: 14:17:58.75 ===============
 

 

Здравейте,

 

Лично аз забелязвам само един ключ в регистрите остатък от програмата, но все пак да проверим за остатъци:

 

1. Можете ли да публикувате лог файловете от MBAM + Adwcleaner след като сте ги използвали? :)

 

2. Направете проверка със специализиран инструмент.

 

 

Изтеглете OTL.exe и го запазете на десктопа.

  • [*]Стартирайте
OTL (ако е необходимо, потвърдете през UAC). [*]Направете следните настройки: [*]Сложете отметка пред Scan All Users [*]Под менюто File Age изберете 90 days [*]Под менюто Standard Registry променете на ALL [*]Сложете отметки пред LOP и Purity Check

Под Публикувано изображение с Copy/ Paste въведете изцяло следната текстова информация (само това, което е поставено в карето):

 

 

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%SYSTEMDRIVE%*.*
%USERPROFILE%*.*
%USERPROFILE%Application Data*.*
%USERPROFILE%Application Data*.
%USERPROFILE%Local Settings*.*
%USERPROFILE%Local Settingstemp*.exe
%USERPROFILE%Local SettingsTemporary Internet Files*.exe
%USERPROFILE%Local SettingsApplication Data*.*
%AllUsersProfile%*.*
%AllUsersProfile%Application Data*.*
%AllUsersProfile%Application Data*.
%AllUsersProfile%Application DataLocal Settings*.*
%AllUsersProfile%Application DataLocal SettingsTemp*.exe
%ALLUSERSPROFILE%DocumentsMy Music*.exe
%ALLUSERSPROFILE%DocumentsMy Pictures*.exe
%ALLUSERSPROFILE%DocumentsMy Videos*.exe
%ALLUSERSPROFILE%Documents*.exe
%USERPROFILE%My Documents*.*
%CommonProgramFiles%*.*
%CommonProgramFiles%ComObjects*.*
%PROGRAMFILES%*.*
%PROGRAMFILES%*.
%systemroot%system32configsystemprofile*.*
%systemroot%system32configsystemprofileApplication Data*.*
%systemroot%system32configsystemprofileLocal Settings*.*
%systemroot%system32configsystemprofileLocal SettingsApplication Data*.*
%systemroot%system32configsystemprofileLocal SettingsTemp*.exe
%systemroot%system32configsystemprofileLocal SettingsTemporary Internet Files*.exe
C:Documents and SettingsLocalServiceApplication Data*.*
C:Documents and SettingsLocalServiceLocal SettingsApplication Data*.*
C:Documents and SettingsLocalServiceLocal Settingstemp*.exe
C:Documents and SettingsLocalServiceLocal SettingsTemporary Internet Files*.exe
C:Documents and SettingsLocalServiceLocal Settings*.*
C:Documents and SettingsLocalService*.*
C:Documents and SettingsNetworkServiceApplication Data*.*
C:Documents and SettingsNetworkServiceLocal SettingsApplication Data*.*
C:Documents and SettingsNetworkServiceLocal Settingstemp*.exe
C:Documents and SettingsNetworkServiceLocal SettingsTemporary Internet Files*.exe
C:Documents and SettingsNetworkServiceLocal Settings*.*
C:Documents and SettingsNetworkService*.*
%windir%temp*.exe
%windir%*.
%windir%installer*.
%windir%system32*.
%Temp%smtmp1*.*
%Temp%smtmp2*.*
%Temp%smtmp3*.*
%Temp%smtmp4*.*
%systemroot%system32*.dll /lockedfiles
%systemroot%Tasks*.job /lockedfiles
%systemroot%system32drivers*.sys /90
%systemroot%system32drivers*.sys /lockedfiles
%systemroot%system32Spoolprtprocsw32x86*.dll
%systemroot%*. /rp /s
%systemroot%assemblytmp*.* /S /MD5
%systemroot%assemblytemp*.* /S /MD5
%systemroot%assemblyGAC*.ini
%systemroot%assemblyGAC_32*.ini
%SystemRoot%assemblyGAC_MSIL*.ini
wsSystemRoot|l,n,u,@;True;False;True;$,{ /fn
%systemdrive%$Recycle.Bin|@;true;true;true /fp
HKEY_CLASSES_ROOTCLSID{7C857801-7381-11CF-884D-00AA004B2E24} /s
HKEY_CLASSES_ROOTCLSID{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1} /s
HKEY_CURRENT_USERSoftwareClassesCLSID{42aedc87-2188-41fd-b9a3-0c966feabec1} /s
HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1} /s
HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{42aedc87-2188-41fd-b9a3-0c966feabec1} /s
HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{a2a9545d-a0c2-42b4-9708-a0b2badd77c8} /s
HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{7C857801-7381-11CF-884D-00AA004B2E24} /s
HKEY_CLASSES_ROOTclsid{5839FCA9-774D-42A1-ACDA-D6A79037F57F} /s
HKEY_CLASSES_ROOTclsid{fbeb8a05-beee-4442-804e-409d6c4515e9} /s
HKEY_CURRENT_USERSoftwareClassesclsid{fbeb8a05-beee-4442-804e-409d6c4515e9} /s
HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{5839FCA9-774D-42A1-ACDA-D6A79037F57F} /s
HKEY_CURRENT_USERSoftwareClassesclsid{12d0253a-7c96-815c-11e0-3034bbd97cc0}] /s
HKEY_CLASSES_ROOTCLSID{312BFDCE-A901-4203-B4F2-ADCB957D1887} /s
HKEY_CLASSES_ROOTDirectoryShellexCopyHookHandlersMSCopy /s
HKEY_CURRENT_USERSoftwareMSOLoad /s
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
consrv.dll
services.exe
svchost.exe
explorer.exe
userinit.exe
winlogon.exe
smss.exe
lsass.exe
atapi.sys
iaStor.sys
serial.sys
disk.sys
volsnap.sys
redbook.sys
i8042prt.sys
afd.sys
netbt.sys
tcpip.sys
ipsec.sys
hlp.dat
str.sys
crexv.ocx
/md5stop

 

 

  • [*]Натиснете маркираният в синьо бутон:
Run Scan. [*]Като приключи проверката, ще се създадат два файла - OTL.Txt и Extras.Txt. Прикачете тези два файла в следващия си коментар (погледнете опцията Прикачени файлове, когато публикувате мнение).

Лога от Adwcleaner го видях в предишната ви тема.

Лога от MBAM можете да извлечете по-следния начин:

 

1.Стартирайте MBAM и отидете до табът Logs.

2.Отворете последния лог и просто копирайте съдържанието на текстовия файл в следващия си коментар.

 

Колкото до OTL - нека да разчистим още малко:

 

1. Деинсталирайте SUPERAntispyware (програмата е малко тромавичка и създава услуги работещи във фонов режим, макар да не предоставя защита в реално време за безплатната си версия). Имате два варианта:

 

а - да премахнете отметката за стартирането на програмата от Start Menu => Run => въведете msconfig => натиснете Enter => отидете до Startup и премахнете отметката на SUPERAntispyware.

След това пак от Start Menu => Run => въведете Services.msc => Натиснете Enter => от списъка с услугите намерете услугата на SUPERAntispyware (SASCORE.EXE) и я стартирайте с двукратен клик на мишката => от падащото меню на Startup Type изберете Manual.

 

b - да я деинсталирате от Control Panel => Add/remove programs и след това да почистите остатъците от нея със следния инструмент SUPERAntiSpyware Uninstaller Assistant (32-Bit)

 

2. Деинсталирайте MBAM и я инсталирайте наново, като не активирате тази отметка:

 

Публикувано изображение

 

3. Тъй като имате avast! и той разполага с WebRep модул, деинсталирайте AVG (ако е наличен в Control Panel-a) и след това почистете след него с този инструмент (за версия 2012 - AVG Remover(32bit) 2012 (avg_remover_stf_x86_2012_2125.exe) или за версия 2013 - AVG Remover(32bit) 2013 (avg_remover_stf_x86_2013_2706.exe)).

 

Рестартирайте компютъра.

 

След това отиваме до следващата точка:

 

4.

  • [*]Стартирайте файла
Публикувано изображение с двукратен клик на мишката. [*]Под Публикувано изображение с Copy/ Paste въведете изцяло следната текстова информация (само това, което е поставено в карето):

:OTL
DRV - File not found [Kernel | On_Demand | Unknown] -- C:DOCUME~1CTXLOCALS~1Tempmbr.sys -- (mbr)
DRV - File not found [Kernel | On_Demand | Unknown] --  -- (a1zowqcs)
DRV - [2013/03/18 18:07:51 | 000,033,112 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:WINDOWSsystem32driversavgtpx86.sys -- (avgtp)
FF - prefs.js..browser.search.useDBForOrder: "false"
[2013/02/09 15:49:25 | 000,000,000 | ---D | M] (Special Savings) -- C:Documents and SettingsCTXApplication [email protected]
[2013/02/09 15:48:34 | 000,000,000 | ---D | M] (Smiley Bar for Facebook) -- C:Documents and SettingsCTXApplication DataMozillaExtensionsstatuswinks@StatusWinks
CHR - homepage: http://start.myplaycity.com/
CHR - Extension: Smiley Bar for Facebook = C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionshgojaaaiddhmiiakpejiklijbalpckih1.0.0.5_0
CHR - Extension: AVG Security Toolbar = C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof14.2.0.1_0
O4 - HKLM..Run: []  File not found
O4 - HKU.DEFAULT..Run: [PC Performer43885.exe] C:WINDOWSTEMPPC Performer43885.exe ()
O4 - HKUS-1-5-18..Run: [PC Performer43885.exe] C:WINDOWSTEMPPC Performer43885.exe ()
[2013/03/18 18:07:51 | 000,033,112 | ---- | M] (AVG Technologies) -- C:WINDOWSSystem32driversavgtpx86.sys
[2009/02/09 12:56:35 | 000,002,048 | -HS- | M] () -- C:WINDOWSInstaller{79e3d2cc-5b15-5192-537e-9b4fb8e55b59}@
[2009/02/09 12:56:35 | 000,000,000 | -HSD | M] -- C:WINDOWSInstaller{79e3d2cc-5b15-5192-537e-9b4fb8e55b59}L
[2012/08/08 20:36:01 | 000,000,000 | -HSD | M] -- C:WINDOWSInstaller{79e3d2cc-5b15-5192-537e-9b4fb8e55b59}U
[2012/05/16 22:36:19 | 000,002,048 | -HS- | M] () -- C:Documents and SettingsCTXLocal SettingsApplication Data{79e3d2cc-5b15-5192-537e-9b4fb8e55b59}@
[2009/02/09 12:56:35 | 000,000,000 | -HSD | M] -- C:Documents and SettingsCTXLocal SettingsApplication Data{79e3d2cc-5b15-5192-537e-9b4fb8e55b59}L
[2012/08/08 20:36:01 | 000,000,000 | -HSD | M] -- C:Documents and SettingsCTXLocal SettingsApplication Data{79e3d2cc-5b15-5192-537e-9b4fb8e55b59}U
[2011/06/16 05:40:50 | 000,000,227 | RHS- | M] () -- C:WINDOWSassemblyDesktop.ini
[2010/05/24 11:02:12 | 002,028,112 | ---- | M] () -- C:Documents and SettingsCTXLocal SettingstempAlawarGameBoxSetup.exe
[2013/05/14 11:30:57 | 003,972,744 | ---- | M] (Ask) -- C:Documents and SettingsCTXLocal Settingstempask.exe
[2009/10/30 07:37:30 | 000,217,088 | ---- | M] (Gretech Corporation) -- C:Documents and SettingsCTXLocal SettingstempGomEncDnInstaller.exe
[2012/09/01 14:19:05 | 000,463,184 | ---- | M] () -- C:Documents and SettingsCTXLocal Settingstempincredibar_installer.exe
[2012/10/07 19:11:02 | 000,163,936 | ---- | M] () -- C:Documents and SettingsCTXLocal SettingstempMachineIdCreator.exe
[2012/09/01 14:19:04 | 000,899,224 | ---- | M] (Babylon Ltd.) -- C:Documents and SettingsCTXLocal SettingstempMyBabylonTB_google_20120807.exe
[2013/02/09 15:47:20 | 000,621,976 | ---- | M] () -- C:Documents and SettingsCTXLocal SettingstempPC Performer43885.exe
[2013/01/27 15:29:17 | 000,146,720 | ---- | M] (Somoto Ltd.) -- C:Documents and SettingsCTXLocal Settingstempsdpupdater.exe
[2013/05/14 11:31:00 | 000,628,376 | ---- | M] (Shop To Win, LLC   ) -- C:Documents and SettingsCTXLocal SettingstempSTWSetup.exe
[2013/05/14 11:29:40 | 005,090,456 | ---- | M] () -- C:Documents and SettingsCTXLocal SettingstempThe_Weather_Channel_Application.exe
[2012/09/01 14:19:06 | 000,259,512 | ---- | M] (Somoto Ltd.) -- C:Documents and SettingsCTXLocal SettingstempUpdateCheckerSetup.exe
[2012/08/08 20:48:42 | 000,000,000 | ---D | M] -- C:Documents and SettingsAll UsersApplication DataAvira
[2011/11/29 21:57:08 | 000,000,000 | ---D | M] -- C:Documents and SettingsAll UsersApplication DataMcAfee
[2012/08/10 13:07:57 | 000,000,000 | ---D | M] -- C:Documents and SettingsAll UsersApplication DataNorton
[2012/05/27 16:21:27 | 000,000,000 | ---D | M] -- C:Documents and SettingsAll UsersApplication DataNortonInstaller
[2013/02/09 15:47:20 | 000,621,976 | ---- | M] () -- C:WINDOWStempPC Performer43885.exe
[2013/02/06 23:09:26 | 003,065,424 | ---- | M] () -- C:WINDOWStemp{2A50A13C-2BB9-4390-AE72-48B8E14C3D64}.exe
[2013/01/23 14:20:49 | 003,142,736 | ---- | M] () -- C:WINDOWStemp{5B66B8BC-92B9-4E8F-B89F-71EC35C37C8B}.exe
[2012/11/05 16:52:03 | 002,785,888 | ---- | M] () -- C:WINDOWStemp{E28897BE-C710-44ED-8795-6C2F904B1981}.exe
[2013/03/18 18:07:45 | 003,085,904 | ---- | M] () -- C:WINDOWStemp{ECF8559E-806C-4ED2-8BED-4367D1646A37}.exe
[2012/10/08 19:57:25 | 000,245,856 | ---- | M] () -- C:WINDOWStemp{ED088FE5-0130-47D6-A8A5-2DA329D15FBC}.exe
[2009/02/09 12:56:35 | 000,000,000 | -HSD | M] -- C:WINDOWSinstaller{79e3d2cc-5b15-5192-537e-9b4fb8e55b59}
:files
C:Documents and SettingsCTXLocal SettingsApplication Data{79e3d2cc-5b15-5192-537e-9b4fb8e55b59}
netsh winsock reset catalog /c
ipconfig /flushdns /c
:commands
[resethosts]
[emptytemp]

 

[*]След като въведете скрипта от цитата по-горе натиснете бутона, маркиран в червено: Run Fix [*]Windows ще се рестартира и ще се създаде лог файл - OTL fix log. Публикувайте съдържанието му с Copy/Paste в следващия си коментар. [*]Виждат се остатъци и от ZeroAccess рууткит. Ще трябва да проверим системата за повреди по регистрите и услугите.

  • Автор

при повторното инсталиране на MBAM

 не ми се появява тази отметка от картинката(може би не е включен пробен период), AVG нямам при програмите

Редактирано от anitto (преглед на промените)

Деинсталирайте MBAM отново и почистете с това: mbam-clean.exe и след това я инсталирайте наново.

Колкото до AVG, ок продължете нататък - аз и без това съм включил компонентите на AVG в скрипта си за OTL за премахване. :)

  • Автор

А ето го и файла от MBAM:Malwarebytes Anti-Malware (Пробна версия) 1.75.0.1300

www.malwarebytes.org

 

Версия на базата от данни: v2013.05.14.02

 

Windows XP Service Pack 3 x86 NTFS

Internet Explorer 6.0.2900.5512

CTX :: CTX-C54A6A3A0B2 [администратор]

 

Защита: включена

 

5/14/2013 1:47:45 PM

mbam-log-2013-05-14 (13-47-45).txt

 

Тип сканиране: Бързо сканиране

Включени опции за сканиране: Памет | Автоматично зареждане | Системен регистър | Файлова система | Евристики/Допълнителни | Евристики/Shuriken | PUP | PUM

Изключени опции за сканиране: P2P

Сканирани обекти: 223581

Изминало време: 4 минута(и), 20 секунда(и)

 

Открити процеси в паметта: 0

(Не бяха открити зловредни обекти)

 

Открити модули в паметта: 0

(Не бяха открити зловредни обекти)

 

Открити ключове в системния регистър: 3

HKLMSYSTEMCurrentControlSetServicesIBUpdaterService (PUP.InstallBrain) -> Не беше предприето действие.

HKLMSOFTWAREMicrosoftWindowsCurrentVersionUninstallUpdater Service (PUP.InstallBrain) -> Не беше предприето действие.

HKCUSOFTWARECLASSESCLSID{42AEDC87-2188-41FD-B9A3-0C966FEABEC1}INPROCSERVER32 (Trojan.Zaccess) -> Поставен под карантина и изтрит успешно.

 

Открити стойности в системния регистър: 1

HKCUSOFTWARECLASSESCLSID{42aedc87-2188-41fd-b9a3-0c966feabec1}InprocServer32| (Trojan.Zaccess) -> Данни: C:Documents and SettingsCTXLocal SettingsApplication Data{79e3d2cc-5b15-5192-537e-9b4fb8e55b59}n. -> Поставен под карантина и изтрит успешно.

 

Открити информационни обекти в системния регистър: 1

HKCRCLSID{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}InProcServer32| (Trojan.Zaccess) -> Лош: (.globalrootsystemrootInstaller{79e3d2cc-5b15-5192-537e-9b4fb8e55b59}n.) Добър: (wbemess.dll) -> Поставен под карантина и поправен успешно.

 

Открити папки: 1

C:Documents and SettingsAll UsersApplication DataIBUpdaterService (PUP.InstallBrain) -> Не беше предприето действие.

 

Открити файлове: 2

C:Documents and SettingsAll UsersApplication DataIBUpdaterServicerepository.xml (PUP.InstallBrain) -> Не беше предприето действие.

C:WINDOWSsystem32dmwu.exe (PUP.InstallBrain) -> Не беше предприето действие.

 

(край)

 

Малко объркано стана,но както казах съм зле :D

Няма проблеми за объркването...затова съм тук.

Надявам се сте изтрили намерените неща с MBAM, защото пише "Не беше предприето действие."

А иначе не пропускайте и предишния ми пост, защото сме писали по едно и също време.

  • Автор

прочетох предния ви пост,изчистих програмата и сега ще я изтегля наново,но не знам защо пише"не е предприето действие",като че ли ги изтрих.Сега като я изтегля да я пусна ли пак и да ги изтрия?

инсталирах я,но пак я няма тази отметка :mad:

Не, не - щом сте ги изтрили няма проблеми. А и има начини да разбера дали са още там с друг инструмент, който ще приложа на по-късен етап. :)

  • Автор

All processes killed
========== OTL ==========
Error: No service named mbr was found to stop!
ServiceDriver key mbr not found.
File C:DOCUME~1CTXLOCALS~1Tempmbr.sys not found.
Error: No service named a1zowqcs was found to stop!
ServiceDriver key a1zowqcs not found.
Service avgtp stopped successfully!
Service avgtp deleted successfully!
C:WINDOWSsystem32driversavgtpx86.sys moved successfully.
Prefs.js: "false" removed from browser.search.useDBForOrder
C:Documents and SettingsCTXApplication DataMozillaExtensionsspecialsavings@vshsolutions.comdefaultspreferences folder moved successfully.
C:Documents and SettingsCTXApplication [email protected] folder moved successfully.
C:Documents and SettingsCTXApplication [email protected] folder moved successfully.
C:Documents and SettingsCTXApplication [email protected] folder moved successfully.
C:Documents and SettingsCTXApplication DataMozillaExtensionsstatuswinks@StatusWinkschromeskin folder moved successfully.
C:Documents and SettingsCTXApplication DataMozillaExtensionsstatuswinks@StatusWinkschromecontentmz folder moved successfully.
C:Documents and SettingsCTXApplication DataMozillaExtensionsstatuswinks@StatusWinkschromecontent folder moved successfully.
C:Documents and SettingsCTXApplication DataMozillaExtensionsstatuswinks@StatusWinkschrome folder moved successfully.
C:Documents and SettingsCTXApplication DataMozillaExtensionsstatuswinks@StatusWinks folder moved successfully.
Use Chrome's Settings page to change the HomePage.
C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionshgojaaaiddhmiiakpejiklijbalpckih1.0.0.5_0mz folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionshgojaaaiddhmiiakpejiklijbalpckih1.0.0.5_0 folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof14.2.0.1_0_localeszh_TW folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof14.2.0.1_0_localeszh_CN folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof14.2.0.1_0_localestr folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof14.2.0.1_0_localessr folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof14.2.0.1_0_localessk folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof14.2.0.1_0_localesru folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof14.2.0.1_0_localespt_PT folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof14.2.0.1_0_localespt_BR folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof14.2.0.1_0_localespl folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof14.2.0.1_0_localesnl folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof14.2.0.1_0_localesko folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof14.2.0.1_0_localesja folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof14.2.0.1_0_localesit folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof14.2.0.1_0_localesid folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof14.2.0.1_0_localeshu folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof14.2.0.1_0_localesfr folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof14.2.0.1_0_localeses_419 folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof14.2.0.1_0_localeses folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof14.2.0.1_0_localesen folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof14.2.0.1_0_localesde folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof14.2.0.1_0_localesda folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof14.2.0.1_0_localescs folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof14.2.0.1_0_locales folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof14.2.0.1_0contenttabs folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof14.2.0.1_0contentlib folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof14.2.0.1_0contentjs folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof14.2.0.1_0contenticonssearch_box folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof14.2.0.1_0contenticonsdnt_disabled folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof14.2.0.1_0contenticons folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof14.2.0.1_0contentcss folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof14.2.0.1_0content folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof14.2.0.1_0 folder moved successfully.
Registry value HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun deleted successfully.
Registry value HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRunPC Performer43885.exe deleted successfully.
C:WINDOWSTempPC Performer43885.exe moved successfully.
Registry value HKEY_USERSS-1-5-18SoftwareMicrosoftWindowsCurrentVersionRunPC Performer43885.exe not found.
File C:WINDOWSTEMPPC Performer43885.exe not found.
File C:WINDOWSSystem32driversavgtpx86.sys not found.
C:WINDOWSInstaller{79e3d2cc-5b15-5192-537e-9b4fb8e55b59}@ moved successfully.
C:WINDOWSInstaller{79e3d2cc-5b15-5192-537e-9b4fb8e55b59}L folder moved successfully.
C:WINDOWSInstaller{79e3d2cc-5b15-5192-537e-9b4fb8e55b59}U folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication Data{79e3d2cc-5b15-5192-537e-9b4fb8e55b59}@ moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication Data{79e3d2cc-5b15-5192-537e-9b4fb8e55b59}L folder moved successfully.
C:Documents and SettingsCTXLocal SettingsApplication Data{79e3d2cc-5b15-5192-537e-9b4fb8e55b59}U folder moved successfully.
C:WINDOWSassemblyDesktop.ini moved successfully.
C:Documents and SettingsCTXLocal SettingsTempAlawarGameBoxSetup.exe moved successfully.
C:Documents and SettingsCTXLocal SettingsTempask.exe moved successfully.
C:Documents and SettingsCTXLocal SettingsTempGomEncDnInstaller.exe moved successfully.
C:Documents and SettingsCTXLocal SettingsTempincredibar_installer.exe moved successfully.
C:Documents and SettingsCTXLocal SettingsTempMachineIdCreator.exe moved successfully.
C:Documents and SettingsCTXLocal SettingsTempMyBabylonTB_google_20120807.exe moved successfully.
C:Documents and SettingsCTXLocal SettingsTempPC Performer43885.exe moved successfully.
C:Documents and SettingsCTXLocal SettingsTempsdpupdater.exe moved successfully.
C:Documents and SettingsCTXLocal SettingsTempSTWSetup.exe moved successfully.
C:Documents and SettingsCTXLocal SettingsTempThe_Weather_Channel_Application.exe moved successfully.
C:Documents and SettingsCTXLocal SettingsTempUpdateCheckerSetup.exe moved successfully.
C:Documents and SettingsAll UsersApplication DataAvira folder moved successfully.
C:Documents and SettingsAll UsersApplication DataMcAfeeMCLOGSSecurityScannerMcUICnt folder moved successfully.
C:Documents and SettingsAll UsersApplication DataMcAfeeMCLOGSSecurityScanner folder moved successfully.
C:Documents and SettingsAll UsersApplication DataMcAfeeMCLOGSPartnerCustomSSScheduler folder moved successfully.
C:Documents and SettingsAll UsersApplication DataMcAfeeMCLOGSPartnerCustomMcUICnt folder moved successfully.
C:Documents and SettingsAll UsersApplication DataMcAfeeMCLOGSPartnerCustomMcCHSvc folder moved successfully.
C:Documents and SettingsAll UsersApplication DataMcAfeeMCLOGSPartnerCustom folder moved successfully.
C:Documents and SettingsAll UsersApplication DataMcAfeeMCLOGSMcUICntMcUICnt folder moved successfully.
C:Documents and SettingsAll UsersApplication DataMcAfeeMCLOGSMcUICnt folder moved successfully.
C:Documents and SettingsAll UsersApplication DataMcAfeeMCLOGSCommonMcUICnt folder moved successfully.
C:Documents and SettingsAll UsersApplication DataMcAfeeMCLOGSCommonMcCHSvc folder moved successfully.
C:Documents and SettingsAll UsersApplication DataMcAfeeMCLOGSCommon folder moved successfully.
C:Documents and SettingsAll UsersApplication DataMcAfeeMCLOGS folder moved successfully.
C:Documents and SettingsAll UsersApplication DataMcAfee folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNorton{086A63F0-6B13-4F29-9695-134E7A01E963} folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonLocalDumps folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNorton000000820000011a00000585 folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNorton000000820000011a folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNorton00000082 folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNorton folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-08-10-12h55m42s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-08-10-12h53m29s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-17h22m33s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h30m00s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h26m25s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h26m24s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h26m22s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h26m20s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h26m19s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h26m17s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h26m15s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h26m14s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h26m12s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h26m10s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h26m08s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h26m06s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h26m05s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h26m03s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h26m01s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h26m00s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m58s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m56s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m54s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m53s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m51s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m49s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m48s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m46s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m44s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m43s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m42s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m41s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m37s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m36s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m35s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m33s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m32s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m31s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m30s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m28s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m26s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m25s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m23s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m21s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m19s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m18s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m16s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m14s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m12s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m11s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m09s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m07s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m06s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m04s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m02s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m01s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h25m00s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h24m58s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h24m56s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h24m55s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h24m54s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h24m51s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h24m50s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h24m23s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs2012-05-27-16h21m13s folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstallerLogs folder moved successfully.
C:Documents and SettingsAll UsersApplication DataNortonInstaller folder moved successfully.
File C:WINDOWStempPC Performer43885.exe not found.
C:WINDOWSTemp{2A50A13C-2BB9-4390-AE72-48B8E14C3D64}.exe moved successfully.
C:WINDOWSTemp{5B66B8BC-92B9-4E8F-B89F-71EC35C37C8B}.exe moved successfully.
C:WINDOWSTemp{E28897BE-C710-44ED-8795-6C2F904B1981}.exe moved successfully.
C:WINDOWSTemp{ECF8559E-806C-4ED2-8BED-4367D1646A37}.exe moved successfully.
C:WINDOWSTemp{ED088FE5-0130-47D6-A8A5-2DA329D15FBC}.exe moved successfully.
C:WINDOWSinstaller{79e3d2cc-5b15-5192-537e-9b4fb8e55b59} folder moved successfully.
========== FILES ==========
C:Documents and SettingsCTXLocal SettingsApplication Data{79e3d2cc-5b15-5192-537e-9b4fb8e55b59} folder moved successfully.
< netsh winsock reset catalog /c >
Sucessfully reset the Winsock Catalog.
You must restart the machine in order to complete the reset.
C:Documents and SettingsCTXDesktopcmd.bat deleted successfully.
C:Documents and SettingsCTXDesktopcmd.txt deleted successfully.
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:Documents and SettingsCTXDesktopcmd.bat deleted successfully.
C:Documents and SettingsCTXDesktopcmd.txt deleted successfully.
========== COMMANDS ==========
C:WINDOWSSystem32driversetcHosts moved successfully.
HOSTS file reset successfully
 
[EMPTYTEMP]
 
User: Administrator
->Temp folder emptied: 180224 bytes
->Temporary Internet Files folder emptied: 134 bytes
 
User: All Users
 
User: CTX
->Temp folder emptied: 2820068499 bytes
->Temporary Internet Files folder emptied: 17418125 bytes
->FireFox cache emptied: 64689178 bytes
->Google Chrome cache emptied: 131307007 bytes
->Flash cache emptied: 2733226 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
 
User: LocalService
->Temp folder emptied: 65984 bytes
->Temporary Internet Files folder emptied: 32902 bytes
 
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 1046 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2402044 bytes
%systemroot%System32 .tmp files removed: 1790481 bytes
%systemroot%System32dllcache .tmp files removed: 0 bytes
%systemroot%System32drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 144765693 bytes
%systemroot%system32configsystemprofileLocal SettingsTemp folder emptied: 0 bytes
%systemroot%system32configsystemprofileLocal SettingsTemporary Internet Files folder emptied: 463264 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 3,038.00 mb
 
 
OTL by OldTimer - Version 3.2.69.0 log created on 05142013_200225

FilesFolders moved on Reboot...
File move failed. C:WINDOWStemp_avast_Webshlock.txt scheduled to be moved on reboot.
FileFolder C:WINDOWStempPerflib_Perfdata_ea0.dat not found!

PendingFileRenameOperations files...

Registry entries deleted on Reboot...


справих се и с отметката на програмата :)

И да проверим за остатъци: (макар че са много, проверките не би трябвало да отнемат повече от 3 минути всяка - не се плашате). :)

 

 

СТЪПКА 1

 

  • [*]Изтеглете
RogueKiller.exe и го запазете на десктопа. [*]Стартирайте приложението и натиснете бутона SCAN. [*]Ще се създаде лог файл на десктопа с името RKreport.txt на десктопа. [*]Публикувайте лог файла в следващия си пост.

 

 

СТЪПКА 2

 

 

Моля изтеглете последната версия на TDSSKiller оттук и я запазете на вашия декстоп.

  • [*]Стартирайте
TDSSKiller.exe за да стартирате приложението. След това кликнете върху бутона Change parameters.

Публикувано изображение [*]Сложете отметка през Loaded Modules.

Публикувано изображение [*]Необходим е рестарт за осъществяване на промените. Направете го! [*]TDSSKiller ще стартира автоматично след рестарта. Важно е да се отбележи, че вашия компютър може да изглежда по-бавен, на моменти неизползваем и с по-ниска производителност. Това е нормално и ще трае само един рестарт. Дайте му достатъчно време да зареди приложенията стартиращи с Операционната Система във фонов режим. [*]След това натиснете Change parameters в TDSSKiller отново. [*]Сложете всички отметки (този път рестарт не се изисква).

Публикувано изображение [*]Натиснете бутона Start Scan.

Публикувано изображение [*]Проверката не би трябвало да отмене повече от 2 minutes. [*]Ако подозрителен обект бъде засечен, действието по подразбиране ще бъде Skip, кликнете върху Continue.

Публикувано изображение [*]Ако зловредни обекти бъдат намерени, тогава от падащото меню ще имате три възможности.
Бъдете сигурни, че избраното действие е Cure и натиснете върху Continue > Рестартирайте за да бъде завършена поправката.

Публикувано изображение

Забележка: Ако Cure бутона не е наличен от възможностите, тогава моля изберете Skip бутона, не избирайте Delete освен ако не сте инструктирани затова. [*]Лог файл ще бъде създаден в свободната директория на дял C: . Потърсете за лог с името "TDSSKiller.[Version]_[Date]_[Time]_log.txt" и копирайте съдържанието му в следващия си пост.

 

 

СТЪПКА 3

 

 

 

Публикувано изображение
Моля изтеглете Farbar Service Scanner и я стартирайте.

 

  • [*]Сложете
всички отметки и натиснете бутона "Scan". [*]Ще се създаде лог файл с името (FSS.txt) в папката откъдето стартирате инструмента. [*]Прикачете лог файла в следващия си пост.

 

 

СТЪПКА 4

 

 

 

Публикувано изображение

  • [*]Изтеглете
MiniToolBox.exe и го запазете на десктопа. [*]Сложете всички отметки и натиснете Go. [*]Прикачете лог файла Result.txt в следващия си пост.

 

 

 

СТЪПКА 5

 

 

 

Публикувано изображение

  • [*]Отворете
следния сайт и изтеглете RKill.exe и ги запазете на вашия десктоп. [*]Стартирате програмата с двоен клик върху файла и изчакайте търпеливо. [*]След приключване на проверката ще се генерира лог файл с извършените процедури. [*]Прикачете лог файла в следващия си пост.

 

 

СТЪПКА 6

 

 

 

Публикувано изображение
Изтеглете Security Check от screen317 от този линк или и го запаметете на вашия десктоп.

  • [*]Кликнете два пъти върху
SecurityCheck.exe и следвайте инструкциите. [*]Накрая, автоматично ще се отвори текстов документ, наречен checkup.txt, моля прикачете го в следващия ви коментар в тази тема.

  • Автор

RogueKiller V8.5.4 [Mar 18 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : CTX [Admin rights]
Mode : Scan -- Date : 05/14/2013 20:40:07
| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 2 ¤¤¤
[HJ] HKLM[...]SystemRestore : DisableSR (1) -> FOUND
[HJ DESK] HKLM[...]NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [LOADED] ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
--> C:WINDOWSsystem32driversetchosts

ÿþ1

¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: Hitachi HDS721616PLA SCSI Disk Device +++++
--- User ---
[MBR] d3694deca4687a2897fe51fc1af2037b
[bSP] de9c268d7f0a5867e9312ab24dcc0700 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 20002 Mo
1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 40965750 | Size: 132622 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

Finished : << RKreport[1]_S_05142013_02d2040.txt >>
RKreport[1]_S_05142013_02d2040.txt

Този е чист - SystemRestore ще го включим с reg файл накрая. Можете да продължите с останалите стъпки и да ги публикувате наведнъж като сте готова. :)

  • Автор

Farbar Service Scanner Version: 14-04-2013
Ran by CTX (administrator) on 14-05-2013 at 20:55:15
Running from "C:Documents and SettingsCTXDesktop"
Microsoft Windows XP Service Pack 3 (X86)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Attempt to access Yahoo IP returned error. Yahoo IP is offline
Yahoo.com is accessible.


Windows Firewall:
=============
sharedaccess Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to retrieve start type of sharedaccess. The value does not exist.
Checking ImagePath: ATTENTION!=====> Unable to retrieve ImagePath of sharedaccess. The value does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open sharedaccess registry key. The service key does not exist.
Checking LEGACY_sharedaccess: ATTENTION!=====> Unable to open LEGACY_sharedaccess0000 registry key. The key does not exist.


Firewall Disabled Policy:
==================


System Restore:
============
Srservice Service is not running. Checking service configuration:
The start type of Srservice service is OK.
The ImagePath of Srservice service is OK.
The ServiceDll of Srservice: "C:WINDOWSsystem32srsvc.dll".

sr Service is not running. Checking service configuration:
The start type of sr service is set to Disabled. The default start type is Boot.
The ImagePath of sr: "SystemRootsystem32DRIVERSsr.sys".


System Restore Disabled Policy:
========================
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionSystemRestore]
"DisableSR"=DWORD:1


Security Center:
============
wscsvc Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist.
Checking LEGACY_wscsvc: ATTENTION!=====> Unable to open LEGACY_wscsvc0000 registry key. The key does not exist.


Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


File Check:
========
C:WINDOWSsystem32dhcpcsvc.dll => MD5 is legit
C:WINDOWSsystem32Driversafd.sys
[2009-11-08 12:35] - [2009-11-08 12:35] - 0138496 ____A (Microsoft Corporation) 4D43E74F2A1239D53929B82600F1971C

C:WINDOWSsystem32Driversnetbt.sys => MD5 is legit
C:WINDOWSsystem32Driverstcpip.sys => MD5 is legit
C:WINDOWSsystem32Driversipsec.sys => MD5 is legit
C:WINDOWSsystem32dnsrslvr.dll => MD5 is legit
C:WINDOWSsystem32ipnathlp.dll => MD5 is legit
C:WINDOWSsystem32netman.dll => MD5 is legit
C:WINDOWSsystem32wbemWMIsvc.dll => MD5 is legit
C:WINDOWSsystem32srsvc.dll => MD5 is legit
C:WINDOWSsystem32Driverssr.sys => MD5 is legit
C:WINDOWSsystem32wscsvc.dll => MD5 is legit
C:WINDOWSsystem32wbemWMIsvc.dll => MD5 is legit
C:WINDOWSsystem32wuauserv.dll => MD5 is legit
C:WINDOWSsystem32qmgr.dll => MD5 is legit
C:WINDOWSsystem32es.dll => MD5 is legit
C:WINDOWSsystem32cryptsvc.dll => MD5 is legit
C:WINDOWSsystem32svchost.exe => MD5 is legit
C:WINDOWSsystem32rpcss.dll => MD5 is legit
C:WINDOWSsystem32services.exe
[2009-11-08 12:34] - [2009-11-08 12:34] - 0110592 ____A (Microsoft Corporation) 020CEAAEDC8EB655B6506B8C70D53BB6


Extra List:
=======
aswFW(12) aswTdi(10) Gpc(3) IPSec(5) NetBT(6) PSched(7) Tcpip(4)
0x0C00000005000000010000000200000003000000040000000C0000000B0000000A00000009000000060000000700000008000000
IpSec Tag value is correct.

**** End of log ****

MiniToolBox by Farbar  Version:21-04-2013
Ran by CTX (administrator) on 14-05-2013 at 20:56:32
Running from "C:Documents and SettingsCTXDesktop"
Microsoft Windows XP Service Pack 3 (X86)
Boot Mode: Normal
***************************************************************************

========================= Flush DNS: ===================================


Windows IP Configuration



Successfully flushed the DNS Resolver Cache.


========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.

"Reset IE Proxy Settings": IE Proxy Settings were reset.

========================= FF Proxy Settings: ==============================


"Reset FF Proxy Settings": Firefox Proxy settings were reset.

========================= Hosts content: =================================
::1 localhost

127.0.0.1 localhost

========================= IP Configuration: ================================

NVIDIA nForce 10/100/1000 Mbps Ethernet  = Local Area Connection (Connected)


# ----------------------------------
# Interface IP Configuration    
# ----------------------------------
pushd interface ip


# Interface IP Configuration for "Local Area Connection"

set address name="Local Area Connection" source=dhcp
set dns name="Local Area Connection" source=dhcp register=PRIMARY
set wins name="Local Area Connection" source=dhcp


popd
# End of interface IP configuration




Windows IP Configuration



  Host Name . . . . . . . . . . . . : ctx-c54a6a3a0b2

  Primary Dns Suffix  . . . . . . . :

  Node Type . . . . . . . . . . . . : Unknown

  IP Routing Enabled. . . . . . . . : No

  WINS Proxy Enabled. . . . . . . . : No



Ethernet adapter Local Area Connection:



  Connection-specific DNS Suffix  . :

  Description . . . . . . . . . . . : NVIDIA nForce 10/100/1000 Mbps Ethernet

  Physical Address. . . . . . . . . : 6C-F0-49-D0-4A-56

  Dhcp Enabled. . . . . . . . . . . : Yes

  Autoconfiguration Enabled . . . . : Yes

  IP Address. . . . . . . . . . . . : 192.168.0.101

  Subnet Mask . . . . . . . . . . . : 255.255.255.0

  Default Gateway . . . . . . . . . : 192.168.0.1

  DHCP Server . . . . . . . . . . . : 192.168.0.1

  DNS Servers . . . . . . . . . . . : 192.168.0.1

  Lease Obtained. . . . . . . . . . : Tuesday, May 14, 2013 8:52:55 PM

  Lease Expires . . . . . . . . . . : Tuesday, May 14, 2013 10:52:55 PM

Server:  UnKnown
Address:  192.168.0.1

Name:   google.com
Addresses:  173.194.39.233, 173.194.39.224, 173.194.39.227, 173.194.39.229
173.194.39.232, 173.194.39.238, 173.194.39.231, 173.194.39.230, 173.194.39.225
173.194.39.228, 173.194.39.226



Pinging google.com [173.194.39.233] with 32 bytes of data:



Reply from 173.194.39.233: bytes=32 time=15ms TTL=60

Reply from 173.194.39.233: bytes=32 time=10ms TTL=60



Ping statistics for 173.194.39.233:

  Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

  Minimum = 10ms, Maximum = 15ms, Average = 12ms

Server:  UnKnown
Address:  192.168.0.1

Name:   yahoo.com
Addresses:  98.138.253.109, 206.190.36.45, 98.139.183.24



Pinging yahoo.com [98.138.253.109] with 32 bytes of data:



Reply from 98.138.253.109: bytes=32 time=194ms TTL=49

Reply from 98.138.253.109: bytes=32 time=190ms TTL=49



Ping statistics for 98.138.253.109:

  Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

  Minimum = 190ms, Maximum = 194ms, Average = 192ms



Pinging 127.0.0.1 with 32 bytes of data:



Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

Reply from 127.0.0.1: bytes=32 time<1ms TTL=128



Ping statistics for 127.0.0.1:

  Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

  Minimum = 0ms, Maximum = 0ms, Average = 0ms

===========================================================================
Interface List
0x1 ........................... MS TCP Loopback interface
0x2 ...6c f0 49 d0 4a 56 ...... NVIDIA nForce Networking Controller - Packet Scheduler Miniport
===========================================================================
===========================================================================
Active Routes:
Network Destination   Netmask   Gateway Interface  Metric
  0.0.0.0   0.0.0.0   192.168.0.1 192.168.0.101 20
  127.0.0.0   255.0.0.0   127.0.0.1 127.0.0.1 1
  192.168.0.0   255.255.255.0   192.168.0.101 192.168.0.101 20
  192.168.0.101  255.255.255.255   127.0.0.1 127.0.0.1 20
  192.168.0.255  255.255.255.255   192.168.0.101 192.168.0.101 20
  224.0.0.0   240.0.0.0   192.168.0.101 192.168.0.101 20
  255.255.255.255  255.255.255.255   192.168.0.101 192.168.0.101 1
Default Gateway: 192.168.0.1
===========================================================================
Persistent Routes:
  None
========================= Winsock entries =====================================

Catalog5 01 C:WINDOWSsystem32mswsock.dll [245248] (Microsoft Corporation)
Catalog5 02 C:WINDOWSsystem32winrnr.dll [16896] (Microsoft Corporation)
Catalog5 03 C:WINDOWSsystem32mswsock.dll [245248] (Microsoft Corporation)
Catalog9 01 C:WINDOWSsystem32mswsock.dll [245248] (Microsoft Corporation)
Catalog9 02 C:WINDOWSsystem32mswsock.dll [245248] (Microsoft Corporation)
Catalog9 03 C:WINDOWSsystem32mswsock.dll [245248] (Microsoft Corporation)
Catalog9 04 C:WINDOWSsystem32mswsock.dll [245248] (Microsoft Corporation)
Catalog9 05 C:WINDOWSsystem32mswsock.dll [245248] (Microsoft Corporation)
Catalog9 06 C:WINDOWSsystem32mswsock.dll [245248] (Microsoft Corporation)
Catalog9 07 C:WINDOWSsystem32mswsock.dll [245248] (Microsoft Corporation)
Catalog9 08 C:WINDOWSsystem32mswsock.dll [245248] (Microsoft Corporation)
Catalog9 09 C:WINDOWSsystem32mswsock.dll [245248] (Microsoft Corporation)
Catalog9 10 C:WINDOWSsystem32mswsock.dll [245248] (Microsoft Corporation)
Catalog9 11 C:WINDOWSsystem32mswsock.dll [245248] (Microsoft Corporation)
Catalog9 12 C:WINDOWSsystem32rsvpsp.dll [92672] (Microsoft Corporation)
Catalog9 13 C:WINDOWSsystem32rsvpsp.dll [92672] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================
Error: (05/14/2013 00:44:10 PM) (Source: WinMgmt) (User: )
Description: WinMgmt could not initialize the core parts.  This could be due to a badly installed version of WinMgmt, WinMgmt repository upgrade failure, insufficient disk space or insufficient memory.

Error: (05/14/2013 11:41:33 AM) (Source: WinMgmt) (User: )
Description: WinMgmt could not initialize the core parts.  This could be due to a badly installed version of WinMgmt, WinMgmt repository upgrade failure, insufficient disk space or insufficient memory.

Error: (05/14/2013 10:18:27 AM) (Source: WinMgmt) (User: )
Description: WinMgmt could not initialize the core parts.  This could be due to a badly installed version of WinMgmt, WinMgmt repository upgrade failure, insufficient disk space or insufficient memory.

Error: (05/14/2013 09:09:34 AM) (Source: WinMgmt) (User: )
Description: WinMgmt could not initialize the core parts.  This could be due to a badly installed version of WinMgmt, WinMgmt repository upgrade failure, insufficient disk space or insufficient memory.

Error: (05/13/2013 05:58:28 PM) (Source: WinMgmt) (User: )
Description: WinMgmt could not initialize the core parts.  This could be due to a badly installed version of WinMgmt, WinMgmt repository upgrade failure, insufficient disk space or insufficient memory.

Error: (05/13/2013 08:35:23 AM) (Source: WinMgmt) (User: )
Description: WinMgmt could not initialize the core parts.  This could be due to a badly installed version of WinMgmt, WinMgmt repository upgrade failure, insufficient disk space or insufficient memory.

Error: (05/12/2013 10:38:42 AM) (Source: WinMgmt) (User: )
Description: WinMgmt could not initialize the core parts.  This could be due to a badly installed version of WinMgmt, WinMgmt repository upgrade failure, insufficient disk space or insufficient memory.

Error: (05/11/2013 00:32:31 PM) (Source: WinMgmt) (User: )
Description: WinMgmt could not initialize the core parts.  This could be due to a badly installed version of WinMgmt, WinMgmt repository upgrade failure, insufficient disk space or insufficient memory.

Error: (05/11/2013 11:53:38 AM) (Source: WinMgmt) (User: )
Description: WinMgmt could not initialize the core parts.  This could be due to a badly installed version of WinMgmt, WinMgmt repository upgrade failure, insufficient disk space or insufficient memory.

Error: (05/11/2013 11:41:59 AM) (Source: WinMgmt) (User: )
Description: WinMgmt could not initialize the core parts.  This could be due to a badly installed version of WinMgmt, WinMgmt repository upgrade failure, insufficient disk space or insufficient memory.


System errors:
=============
Error: (05/14/2013 08:54:18 PM) (Source: Service Control Manager) (User: )
Description: The Computer Browser service terminated with the following error:
%%1060

Error: (05/14/2013 08:45:26 PM) (Source: Service Control Manager) (User: )
Description: The Computer Browser service terminated with the following error:
%%1060

Error: (05/14/2013 08:07:10 PM) (Source: Service Control Manager) (User: )
Description: The Computer Browser service terminated with the following error:
%%1060

Error: (05/14/2013 08:02:25 PM) (Source: Service Control Manager) (User: )
Description: The Skype C2C Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (05/14/2013 08:02:25 PM) (Source: Service Control Manager) (User: )
Description: The Ati HotKey Poller service terminated unexpectedly.  It has done this 1 time(s).

Error: (05/14/2013 07:59:21 PM) (Source: Service Control Manager) (User: )
Description: The Computer Browser service terminated with the following error:
%%1060

Error: (05/14/2013 07:41:18 PM) (Source: Service Control Manager) (User: )
Description: The Computer Browser service terminated with the following error:
%%1060

Error: (05/14/2013 07:05:11 PM) (Source: Service Control Manager) (User: )
Description: The Computer Browser service terminated with the following error:
%%1060

Error: (05/14/2013 02:08:48 PM) (Source: Service Control Manager) (User: )
Description: The Computer Browser service terminated with the following error:
%%1060

Error: (05/14/2013 01:56:21 PM) (Source: Service Control Manager) (User: )
Description: The Computer Browser service terminated with the following error:
%%1060


Microsoft Office Sessions:
=========================
Error: (05/14/2013 00:44:10 PM) (Source: WinMgmt)(User: )
Description:

Error: (05/14/2013 11:41:33 AM) (Source: WinMgmt)(User: )
Description:

Error: (05/14/2013 10:18:27 AM) (Source: WinMgmt)(User: )
Description:

Error: (05/14/2013 09:09:34 AM) (Source: WinMgmt)(User: )
Description:

Error: (05/13/2013 05:58:28 PM) (Source: WinMgmt)(User: )
Description:

Error: (05/13/2013 08:35:23 AM) (Source: WinMgmt)(User: )
Description:

Error: (05/12/2013 10:38:42 AM) (Source: WinMgmt)(User: )
Description:

Error: (05/11/2013 00:32:31 PM) (Source: WinMgmt)(User: )
Description:

Error: (05/11/2013 11:53:38 AM) (Source: WinMgmt)(User: )
Description:

Error: (05/11/2013 11:41:59 AM) (Source: WinMgmt)(User: )
Description:


=========================== Installed Programs ============================

µTorrent (Version: 3.3.0.29625)
Adobe Flash Player 11 ActiveX (Version: 11.6.602.180)
Adobe Flash Player 11 Plugin (Version: 11.6.602.180)
Adobe Reader 8 - Bulgarian (Version: 8.1.3)
AMD Processor Driver (Version: 1.3.2.0053)
ATI - Software Uninstall Utility (Version: 6.14.10.1022)
ATI Catalyst Control Center (Version: 2.009.0427.2330)
ATI Display Driver (Version: 8.593.100.1-090427a-080420C-ATI)
avast! Internet Security (Version: 8.0.1489.0)
Ballistik
BS.Player FREE (Version: 2.64.1073)
Catalyst Control Center - Branding (Version: 1.00.0000)
Catalyst Control Center Core Implementation (Version: 2009.0427.2331.40409)
Catalyst Control Center Graphics Full Existing (Version: 2009.0427.2331.40409)
Catalyst Control Center Graphics Full New (Version: 2009.0427.2331.40409)
Catalyst Control Center Graphics Light (Version: 2009.0427.2331.40409)
Catalyst Control Center Graphics Previews Common (Version: 2009.0427.2331.40409)
Catalyst Control Center HydraVision Full (Version: 2009.0427.2331.40409)
Catalyst Control Center Localization All (Version: 2009.0427.2331.40409)
CCC Help Chinese Standard (Version: 2009.0427.2330.40409)
CCC Help Chinese Traditional (Version: 2009.0427.2330.40409)
CCC Help Czech (Version: 2009.0427.2330.40409)
CCC Help Danish (Version: 2009.0427.2330.40409)
CCC Help Dutch (Version: 2009.0427.2330.40409)
CCC Help English (Version: 2009.0427.2330.40409)
CCC Help Finnish (Version: 2009.0427.2330.40409)
CCC Help French (Version: 2009.0427.2330.40409)
CCC Help German (Version: 2009.0427.2330.40409)
CCC Help Greek (Version: 2009.0427.2330.40409)
CCC Help Hungarian (Version: 2009.0427.2330.40409)
CCC Help Italian (Version: 2009.0427.2330.40409)
CCC Help Japanese (Version: 2009.0427.2330.40409)
CCC Help Korean (Version: 2009.0427.2330.40409)
CCC Help Norwegian (Version: 2009.0427.2330.40409)
CCC Help Polish (Version: 2009.0427.2330.40409)
CCC Help Portuguese (Version: 2009.0427.2330.40409)
CCC Help Russian (Version: 2009.0427.2330.40409)
CCC Help Spanish (Version: 2009.0427.2330.40409)
CCC Help Swedish (Version: 2009.0427.2330.40409)
CCC Help Thai (Version: 2009.0427.2330.40409)
CCC Help Turkish (Version: 2009.0427.2330.40409)
ccc-core-preinstall (Version: 2009.0427.2331.40409)
ccc-core-static (Version: 2009.0427.2331.40409)
ccc-utility (Version: 2009.0427.2331.40409)
Combined Community Codec Pack 2008-09-21 16:18 (Version: 2008.09.21.0)
Dream Aquarium 1.234
Favorite-Games 5.19
Google Chrome (Version: 26.0.1410.64)
Google Земя (Version: 5.2.1.1588)
Luxor 4 - Quest for the Afterlife (Version: 1.0)
Malwarebytes Anti-Malware, версия 1.75.0.1300 (Version: 1.75.0.1300)
Microsoft .NET Framework 2.0
Microsoft .NET Framework 2.0 (Version: 2.0.50727)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320)
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Mozilla Firefox 20.0.1 (x86 bg) (Version: 20.0.1)
Mozilla Maintenance Service (Version: 20.0.1)
Nero 8 Lite 8.1.1.0 (Version: 8.1.1.0)
NVIDIA Drivers (Version: 1.5)
OpenOffice.org 3.0 (Version: 3.0.9379)
Phonetic Cyrillic for Windows 2000 v1.0 (Version: v1.0)
PhotoScape
Realtek High Definition Audio Driver (Version: 5.10.0.5998)
SA Dictionary 2002 Professional
Samsung Kies (Version: 2.2.0.12014_18)
SAMSUNG USB Driver for Mobile Phones (Version: 1.5.6.0)
Shrek 2 (Version: 1.00.0000)
Skins (Version: 2009.0427.2331.40409)
Skype Click to Call (Version: 6.8.12323)
Skype™ 6.3 (Version: 6.3.105)
Unix Utilities for Yahoo! Widgets
Update for Windows XP (KB898461) (Version: 1)
Update for Windows XP (KB943729)
WebFldrs XP (Version: 9.50.7523)
Winamp (Version: 5.55 )
Windows Bulgarian Interface Pack (Version: 1.0.0.2600)
Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray (Version: 1.0)
WinRAR archiver
Yahoo! Install Manager
Yahoo! Widgets (Version: 4.5.2.0)

========================= Devices: ================================


========================= Memory info: ===================================

Percentage of memory in use: 21%
Total physical RAM: 2047.48 MB
Available physical RAM: 1605.02 MB
Total Pagefile: 3939.5 MB
Available Pagefile: 3534.33 MB
Total Virtual: 2047.88 MB
Available Virtual: 1982.96 MB

========================= Partitions: =====================================

1 Drive c: () (Fixed) (Total:19.53 GB) (Free:5.76 GB) NTFS
2 Drive d: () (Fixed) (Total:129.51 GB) (Free:5.32 GB) NTFS

========================= Users: ========================================

User accounts for CTX-C54A6A3A0B2

Administrator   CTX   Guest  
HelpAssistant   SUPPORT_388945a0    

========================= Minidump Files ==================================

C:WINDOWSMinidumpMini030713-01.dmp
C:WINDOWSMinidumpMini030913-01.dmp
C:WINDOWSMinidumpMini092812-01.dmp
C:WINDOWSMinidumpMini110412-01.dmp
C:WINDOWSMinidumpMini121812-01.dmp
========================= Restore Points ==================================


**** End of log ****

Rkill 2.4.8 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2013 BleepingComputer.com
More Information about Rkill can be found at this link:
 http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 05/14/2013 09:00:27 PM in x86 mode.
Windows Version: Microsoft Windows XP Service Pack 3

Checking for Windows services to stop:

 * No malware services found to stop.

Checking for processes to terminate:

 * No malware processes found to kill.

Checking Registry for malware related settings:

 * No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

 * System Restore Disabled

[HKLMSOFTWAREMicrosoftWindows NTCurrentVersionSystemRestore]
"DisableSR" = dword:00000001

Checking Windows Service Integrity:

 * System Restore Service (srservice) is not Running.
Startup Type set to: Automatic

 * System Restore Filter Driver (sr) is not Running.
Startup Type set to: Disabled

 * wscsvc [Missing Service]

 * SharedAccess [Missing ImagePath]

Searching for Missing Digital Signatures:

 * No issues found.

Checking HOSTS File:

 * HOSTS file entries found:

  ÿþ1 2 7 . 0 . 0 . 1 l o c a l h o s t
 
: : 1 l o c a l h o s t
 
   

Program finished at: 05/14/2013 09:00:51 PM
Execution time: 0 hours(s), 0 minute(s), and 24 seconds(s)
 

 Results of screen317's Security Check version 0.99.63  
 Windows XP Service Pack 3 x86   
 Internet Explorer 6 Out of date!
``````````````Antivirus/Firewall Check:``````````````
 Windows Security Center service is not running! This report may not be accurate!
AntiVir Desktop  
avast! Internet Security   
 Antivirus up to date!  
`````````Anti-malware/Other Utilities Check:`````````
 Malwarebytes Anti-Malware, версия 1.75.0.1300  
 Adobe Flash Player  11.6.602.180  
 Adobe Reader 8 Adobe Reader out of Date!
 Mozilla Firefox (20.0.1)
````````Process Check: objlist.exe by Laurent````````  
 AVAST Software Avast AvastSvc.exe  
 AVAST Software Avast afwServ.exe  
 AVAST Software Avast avastUI.exe  
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C::  
````````````````````End of Log``````````````````````тези ще ги прикача,защото не мога да ги копна,много са дълги

TDSSKiller.2.8.16.0_14.05.2013_20.42.47_log.txt

TDSSKiller.2.8.16.0_14.05.2013_20.45.43_log.txt

Редактирано от anitto (преглед на промените)

  • Автор

да справих се с помощта на дъщеря ми и познанията и по англ. :) (само да попитам,какво ще правя със всички тия програми,които се наложи да изтегля? :shy11: )

За кои по-точно? За тези, които трябва да инсталирате или за инструментите, които използвахме за да закрепим положението? Ако е за тези които трябва да инсталирате - направете го и после можете да им изтриете инсталаторите (exe файловете), за останалите инструменти ще ви кажа как да ги почистите лесно и безопасно като приключим. :)

След като изпълните всичко очаквам да направите една последна проверка с Farbar Service Scanner и SecurityCheck и да публикувате логовете им и след това приключваме и ще ви кажа как да изтриете използваните от нас неща.

 

Дъмп файловете макар и старички показват тенденциозност да се повтарят...5 от 6 са заради scsiport.sys, който е легитимен драйвър на Windows.

Изчетох доста из интернет и може да се касае от доста неща - проблемен хардиск, кабела на хардиска, IRQ конфликт с други драйвъри и т.н...но да изчакаме да видим дали след всички тези процедури ще продължат да се появяват. Ако да...имаме няколко възможности и за тях, но ако няма проблеми мисля да не ви занимавам повече с излишни действия.

 

Поздрави! :)

  • Автор

Farbar Service Scanner Version: 14-04-2013
Ran by CTX (administrator) on 15-05-2013 at 15:05:53
Running from "C:Documents and SettingsCTXDesktop"
Microsoft Windows XP Service Pack 3 (X86)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Attempt to access Yahoo IP returned error. Yahoo IP is offline
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Security Center:
============

Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


File Check:
========
C:WINDOWSsystem32dhcpcsvc.dll => MD5 is legit
C:WINDOWSsystem32Driversafd.sys
[2009-11-08 12:35] - [2009-11-08 12:35] - 0138496 ____A (Microsoft Corporation) 4D43E74F2A1239D53929B82600F1971C

C:WINDOWSsystem32Driversnetbt.sys => MD5 is legit
C:WINDOWSsystem32Driverstcpip.sys => MD5 is legit
C:WINDOWSsystem32Driversipsec.sys => MD5 is legit
C:WINDOWSsystem32dnsrslvr.dll => MD5 is legit
C:WINDOWSsystem32ipnathlp.dll => MD5 is legit
C:WINDOWSsystem32netman.dll => MD5 is legit
C:WINDOWSsystem32wbemWMIsvc.dll => MD5 is legit
C:WINDOWSsystem32srsvc.dll => MD5 is legit
C:WINDOWSsystem32Driverssr.sys => MD5 is legit
C:WINDOWSsystem32wscsvc.dll => MD5 is legit
C:WINDOWSsystem32wbemWMIsvc.dll => MD5 is legit
C:WINDOWSsystem32wuauserv.dll => MD5 is legit
C:WINDOWSsystem32qmgr.dll => MD5 is legit
C:WINDOWSsystem32es.dll => MD5 is legit
C:WINDOWSsystem32cryptsvc.dll => MD5 is legit
C:WINDOWSsystem32svchost.exe => MD5 is legit
C:WINDOWSsystem32rpcss.dll => MD5 is legit
C:WINDOWSsystem32services.exe
[2009-11-08 12:34] - [2009-11-08 12:34] - 0110592 ____A (Microsoft Corporation) 020CEAAEDC8EB655B6506B8C70D53BB6


Extra List:
=======
aswFW(12) aswTdi(10) Gpc(3) IPSec(5) NetBT(6) PSched(7) Tcpip(4)
0x0C00000005000000010000000200000003000000040000000C0000000B0000000A00000009000000060000000700000008000000
IpSec Tag value is correct.

**** End of log **** Results of screen317's Security Check version 0.99.63  
 Windows XP Service Pack 3 x86   
 Internet Explorer 8  
``````````````Antivirus/Firewall Check:``````````````
 Windows Firewall Enabled!  
AntiVir Desktop  
avast! Internet Security   
 Antivirus up to date!  
`````````Anti-malware/Other Utilities Check:`````````
 Malwarebytes Anti-Malware, версия 1.75.0.1300  
 Adobe Flash Player  11.7.700.202  
 Adobe Reader XI  
 Mozilla Firefox (21.0)
````````Process Check: objlist.exe by Laurent````````  
 AVAST Software Avast AvastSvc.exe  
 AVAST Software Avast afwServ.exe  
 AVAST Software Avast avastUI.exe  
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C::  
````````````````````End of Log``````````````````````

 

БЛАГОДАРНОСТИ! :wors:

Остава само да почистим:

 

Изтеглете OTC.exe и го стартирайте. Натиснете бутона CleanUp!.
Рестартирайте компютъра, ако ви попита!

Изтеглете Delfix.exe и го стартирайте. Сложете отметка пред Remove disinfection tools => натиснете бутона Run

Инструмента ще се самоизтрие след като приключи своята задача!

 

Изтрийте всички останали инструменти, тяхните файлове, папки и логове, които не са се изтрили при гореспоменатите процедури.

 

Сменете всички пароли за акаунтите си особено ако се занимавате с чувствителни операции като онлайн банкиране например.

 

И сме готови...

 

 

Ако все пак решите, че ви се занимава да премахнем Avira от WMI записа ми пишете в следващия си коментар (не е проблем и да си остане така, защото процедурата не е от най-лесните).

 

Ако продължат да се появяват сини екрани е добре да проверите хардиска си за проблеми по следния начин:

 

Отворете Start => Run => напишете CMD => натиснете Enter => въведете командата chkdsk c: /x /f /r

 

Натиснете буквата Y и след това рестартирайте компютъра.

 

Изчакайте проверката да завърши (може да отнеме до 1 час) и след това отворете Start => Run => въведете eventvwr.msc => разпънете  Applications => Намерете събиетието с името Winlogon и event 1001 и го отворете с двукратен клик на мишката.

 

Публикувано изображение

 

След това копирайте съдържанието на информацията в следващия си пост.

 

Ами това беше от мен - хубав ден ви желая! :)

  • Автор

Хиляди благодарности!!!Ще се въздържа от почистването на AVIRA :) .Това с паролите е малко стряскащо :) (всички,които ползват този компютър ли да го направят?)А колкото до синия екран,аз като че ли не си спомням да ми се е появявал :shy11: ,но ако се случи непременно ще направя това,което казвате.Сега отивам да "почиствам" :)

За паролите това е стандартен съвет след зараза с бацил като ZeroAccess. Не е задължително, но силно препоръчително! :)

 

Що се отнася до синия екран за последно се е появил на 9-ти март ако съдя по датата на dmp файла, но може да е било заради конфликт с даден софтуер за защита - вие имахте остатъци от доста програми в тази насока, някои от които почистихме. Оставихме само една антивирусна програма + няколко антишпионски без защита в реално време и това би трябвало да се отрази благоприятно на производителността и стабилността на системата. :)

 

C:WINDOWSMinidumpMini030713-01.dmp
C:WINDOWSMinidumpMini030913-01.dmp
C:WINDOWSMinidumpMini092812-01.dmp
C:WINDOWSMinidumpMini110412-01.dmp
C:WINDOWSMinidumpMini121812-01.dmp

 

Поздрави! ;)

  • Автор

Още веднъж хиляди благодарности! :wors: :wors: :wors: Надявам се скоро да не търся помощ.И само още един последен въпрос-кои са антишпионските :)  и през какъв период е препоръчително да ги пускам да сканират?

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.