Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Windows-ът не се boot-ва.

Featured Replies

Здравейте, имам проблем с лаптопа - не успява да boot-не, освен в Safe Mode (и то невинаги), преди това излезе фалшива тревога за System Care Antivirus. Успях да пусна MBAM в Safe Mode, откри няколко заплахи и ги изтри, но нямаше резултат. Също така (не знам дали това е част от проблема), но батерията започна да се държи неадекватно (относно зареждането), стига до 0%, след това започва да се зарежда и отзарежда когато си поиска. Не разполагам с диск със ситемата.

 

 

 

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-09-30.01)
.
Microsoft Windows XP Professional
Boot Device: DeviceHarddiskVolume1
Install Date: 08.1.2009 г. 17:01:07
System Uptime: 29.5.2013 г. 16:33:00 (0 hours ago)
.
Motherboard: Hewlett-Packard |  | 30D5
Processor: Intel® Core Duo CPU   T2400  @ 1.83GHz | U10 | 1828/166mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 46 GiB total, 7,785 GiB free.
D: is FIXED (NTFS) - 66 GiB total, 1,391 GiB free.
E: is CDROM ()
G: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Intel® PRO/100 VE Network Connection
Device ID: PCIVEN_8086&DEV_1068&SUBSYS_30D5103C&REV_014&2EC23395&0&40F0
Manufacturer: Intel
Name: Intel® PRO/100 VE Network Connection
PNP Device ID: PCIVEN_8086&DEV_1068&SUBSYS_30D5103C&REV_014&2EC23395&0&40F0
Service: E100B
.
==== System Restore Points ===================
.
RP263: 11.3.2013 г. 11:19:42 - Installed Star Wars Republic Commando
RP264: 11.3.2013 г. 18:51:07 - Removed Star Wars Republic Commando
RP265: 11.3.2013 г. 18:59:03 - Software Distribution Service 3.0
RP266: 16.3.2013 г. 20:37:35 - Software Distribution Service 3.0
RP267: 18.3.2013 г. 11:11:50 - Software Distribution Service 3.0
RP268: 19.3.2013 г. 11:46:36 - Software Distribution Service 3.0
RP269: 20.3.2013 г. 12:14:32 - Software Distribution Service 3.0
RP270: 22.3.2013 г. 15:39:22 - System Checkpoint
RP271: 23.3.2013 г. 23:18:09 - Software Distribution Service 3.0
RP272: 25.3.2013 г. 15:06:58 - Software Distribution Service 3.0
RP273: 26.3.2013 г. 17:38:54 - Software Distribution Service 3.0
RP274: 27.3.2013 г. 17:48:22 - Software Distribution Service 3.0
RP275: 30.3.2013 г. 10:34:29 - Software Distribution Service 3.0
RP276: 31.3.2013 г. 16:21:26 - System Checkpoint
RP277: 02.4.2013 г. 08:48:53 - Software Distribution Service 3.0
RP278: 06.4.2013 г. 13:58:48 - Software Distribution Service 3.0
RP279: 07.4.2013 г. 19:54:50 - System Checkpoint
RP280: 08.4.2013 г. 20:05:51 - System Checkpoint
RP281: 09.4.2013 г. 08:25:18 - Software Distribution Service 3.0
RP282: 13.4.2013 г. 13:26:15 - Software Distribution Service 3.0
RP283: 13.4.2013 г. 23:03:07 - Restore Operation
RP284: 13.4.2013 г. 23:16:55 - Software Distribution Service 3.0
RP285: 14.4.2013 г. 22:02:39 - 16.04
RP286: 16.4.2013 г. 22:03:42 - Restore Operation
RP287: 16.4.2013 г. 22:34:27 - Software Distribution Service 3.0
RP288: 17.4.2013 г. 23:30:04 - Software Distribution Service 3.0
RP289: 22.4.2013 г. 10:49:59 - Software Distribution Service 3.0
RP290: 23.4.2013 г. 11:46:54 - Software Distribution Service 3.0
RP291: 24.4.2013 г. 15:55:32 - Software Distribution Service 3.0
RP292: 25.4.2013 г. 18:46:51 - Software Distribution Service 3.0
RP293: 26.4.2013 г. 21:45:59 - Software Distribution Service 3.0
RP294: 28.4.2013 г. 15:48:05 - Software Distribution Service 3.0
RP295: 29.4.2013 г. 18:30:27 - Software Distribution Service 3.0
RP296: 03.5.2013 г. 14:57:26 - Software Distribution Service 3.0
RP297: 05.5.2013 г. 08:31:54 - Software Distribution Service 3.0
RP298: 08.5.2013 г. 16:28:30 - System Checkpoint
RP299: 11.5.2013 г. 19:38:23 - Software Distribution Service 3.0
RP300: 12.5.2013 г. 20:32:02 - Software Distribution Service 3.0
RP301: 13.5.2013 г. 20:58:00 - System Checkpoint
RP302: 14.5.2013 г. 07:04:16 - Software Distribution Service 3.0
RP303: 15.5.2013 г. 09:11:04 - Software Distribution Service 3.0
RP304: 16.5.2013 г. 13:08:43 - Software Distribution Service 3.0
RP305: 18.5.2013 г. 22:06:34 - Software Distribution Service 3.0
RP306: 20.5.2013 г. 15:07:32 - System Checkpoint
RP307: 25.5.2013 г. 14:30:44 - System Checkpoint
RP308: 25.5.2013 г. 22:00:49 - Software Distribution Service 3.0
RP309: 28.5.2013 г. 10:54:56 - System Checkpoint
RP310: 28.5.2013 г. 19:15:39 - Software Distribution Service 3.0
RP311: 29.5.2013 г. 14:32:14 - Installed HP Battery Check
.
==== Installed Programs ======================
.
Архиватор WinRAR
µTorrent
2007 Microsoft Office Suite Service Pack 1 (SP1)
ABBYY FineReader 10 Professional Edition
Adobe Acrobat 6.0 Professional
Adobe Flash Player 10 ActiveX
Adobe Flash Player 11 Plugin
Akamai NetSession Interface
Akamai NetSession Interface Service
AlienGUIse
Any Video Converter 3.0.7
Babylon toolbar on IE
Bulgarian (Phonetic) by Iliya Dankov
Bulgarian Keyboards XP by G. Atanasov
CCleaner (remove only)
Conexant HD Audio
ConvertHelper 2.2
Counter-Strike 1.6
Counter-Strike 1.6 Version 29, Exe build: 3647
Critical Update for Windows Media Player 11 (KB959772)
Disc2Phone
Duke Nukem - Manhattan Project
GameRanger
Google Earth
Hard Disk Sentinel PRO
HDAUDIO Soft Data Fax Modem with SmartCP
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB2570791)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976002-v5)
HP Battery Check
HP Quick Launch Buttons 6.40 F1
IB Updater 2.0.0.110
IB Updater Service
Intel® Graphics Media Accelerator Driver
Intel® PRO Network Connections Drivers
IP-TV Player 0.28.1.8819
Java Auto Updater
Java 6 Update 27
K-Lite Codec Pack 4.1.7 (Full)
M-Tel NETAGENT
Malwarebytes Anti-Malware version 1.75.0.1300
Microsoft .NET Framework 1.1
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Age of Empires II
Microsoft Antimalware
Microsoft Antimalware Service BG-BG Language Pack
Microsoft Application Error Reporting
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
Microsoft Office Access MUI (Bulgarian) 2007
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (Bulgarian) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (Bulgarian) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office IME (Chinese (Simplified)) 2007
Microsoft Office IME (Chinese (Traditional)) 2007
Microsoft Office IME (Japanese) 2007
Microsoft Office IME (Korean) 2007
Microsoft Office InfoPath MUI (Bulgarian) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Language Pack 2007 - Bulgarian/български
Microsoft Office O MUI (Bulgarian) 2007
Microsoft Office OneNote MUI (Bulgarian) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (Bulgarian) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (Bulgarian) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (Arabic) 2007
Microsoft Office Proof (Basque) 2007
Microsoft Office Proof (Bulgarian) 2007
Microsoft Office Proof (Catalan) 2007
Microsoft Office Proof (Chinese (Simplified)) 2007
Microsoft Office Proof (Chinese (Traditional)) 2007
Microsoft Office Proof (Croatian) 2007
Microsoft Office Proof (Czech) 2007
Microsoft Office Proof (Danish) 2007
Microsoft Office Proof (Dutch) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (Estonian) 2007
Microsoft Office Proof (Finnish) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Galician) 2007
Microsoft Office Proof (German) 2007
Microsoft Office Proof (Greek) 2007
Microsoft Office Proof (Gujarati) 2007
Microsoft Office Proof (Hebrew) 2007
Microsoft Office Proof (Hindi) 2007
Microsoft Office Proof (Hungarian) 2007
Microsoft Office Proof (Italian) 2007
Microsoft Office Proof (Japanese) 2007
Microsoft Office Proof (Kannada) 2007
Microsoft Office Proof (Korean) 2007
Microsoft Office Proof (Latvian) 2007
Microsoft Office Proof (Lithuanian) 2007
Microsoft Office Proof (Marathi) 2007
Microsoft Office Proof (Norwegian (Bokmal)) 2007
Microsoft Office Proof (Norwegian (Nynorsk)) 2007
Microsoft Office Proof (Polish) 2007
Microsoft Office Proof (Portuguese (Brazil)) 2007
Microsoft Office Proof (Portuguese (Portugal)) 2007
Microsoft Office Proof (Punjabi) 2007
Microsoft Office Proof (Romanian) 2007
Microsoft Office Proof (Russian) 2007
Microsoft Office Proof (Serbian (Latin)) 2007
Microsoft Office Proof (Slovak) 2007
Microsoft Office Proof (Slovenian) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proof (Swedish) 2007
Microsoft Office Proof (Tamil) 2007
Microsoft Office Proof (Telugu) 2007
Microsoft Office Proof (Thai) 2007
Microsoft Office Proof (Turkish) 2007
Microsoft Office Proof (Ukrainian) 2007
Microsoft Office Proof (Urdu) 2007
Microsoft Office Proofing (Bulgarian) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Kit 2007
Microsoft Office Proofing Tools Kit 2007
Microsoft Office ProofMUI (English) 2007
Microsoft Office Publisher MUI (Bulgarian) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (Bulgarian) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office SharePoint Designer 2007
Microsoft Office SharePoint Designer 2007 Service Pack 1 (SP1)
Microsoft Office SharePoint Designer MUI (English) 2007
Microsoft Office Word MUI (Bulgarian) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Office X MUI (Bulgarian) 2007
Microsoft Security Client
Microsoft Security Client BG-BG Language Pack
Microsoft Security Essentials
Microsoft Silverlight
Microsoft Software Update for Web Folders  (Bulgarian) 12
Microsoft Software Update for Web Folders  (English) 12
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Mozilla Firefox 21.0 (x86 bg)
Mozilla Maintenance Service
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Need for Speed™ Most Wanted
neroxml
NetWaiting
QuickTime
SA Dictionary 2005 T2
Security Update for 2007 Microsoft Office System (KB2277947)
Security Update for 2007 Microsoft Office System (KB951550)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for 2007 Microsoft Office System (KB982312)
Security Update for 2007 Microsoft Office System (KB982331)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft Office Access 2007 (KB979440)
Security Update for Microsoft Office Excel 2007 (KB982308)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office Outlook 2007 (KB980376)
Security Update for Microsoft Office PowerPoint 2007 (KB982158)
Security Update for Microsoft Office Publisher 2007 (KB982124)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2251419)
Security Update for Microsoft Windows (KB2564958)
Security Update for Windows Internet Explorer 7 (KB2544521)
Security Update for Windows Internet Explorer 7 (KB2586448)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2412687)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB2476490)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2479943)
Security Update for Windows XP (KB2481109)
Security Update for Windows XP (KB2483185)
Security Update for Windows XP (KB2485663)
Security Update for Windows XP (KB2506212)
Security Update for Windows XP (KB2507618)
Security Update for Windows XP (KB2507938)
Security Update for Windows XP (KB2508272)
Security Update for Windows XP (KB2508429)
Security Update for Windows XP (KB2509553)
Security Update for Windows XP (KB2510581)
Security Update for Windows XP (KB2535512)
Security Update for Windows XP (KB2536276-v2)
Security Update for Windows XP (KB2544893-v2)
Security Update for Windows XP (KB2562937)
Security Update for Windows XP (KB2566454)
Security Update for Windows XP (KB2567053)
Security Update for Windows XP (KB2567680)
Security Update for Windows XP (KB2570222)
Security Update for Windows XP (KB2570947)
Security Update for Windows XP (KB2592799)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982665)
Skype™ 3.8
Sony Ericsson PC Suite for Smartphones
Sony Ericsson Symbian 9 Drivers
Sony PC Companion 2.10.094
Spybot - Search & Destroy
Synaptics Pointing Device Driver
System Requirements Lab CYRI
The KMPlayer (remove only)
Theme Manager
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Outlook 2007 Junk Email Filter (KB2596560)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2541763)
Update for Windows XP (KB2616676-v2)
Update for Windows XP (KB898461)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971029)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Vodafone Mobile Connect Lite
Warcraft III: All Products
WebFldrs XP
Winamp (remove only)
Windows Driver Package - Ross-Tech USB Driver Package (05/19/2006 6.0.1.0)
Windows Genuine Advantage Notifications (KB905474)
Yu-Gi-Oh! Power of Chaos JOEY THE PASSION
.
==== Event Viewer Messages From Past Week ========
.
29.5.2013 г. 16:38:58, error: DCOM [10005]  - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
29.5.2013 г. 16:35:00, error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  Fips intelppm MpFilter
29.5.2013 г. 16:34:58, error: DCOM [10005]  - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
29.5.2013 г. 16:34:47, error: DCOM [10005]  - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
29.5.2013 г. 16:34:01, error: DCOM [10005]  - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
29.5.2013 г. 16:29:04, error: sptd [4]  - Driver detected an internal error in its data structures for .
29.5.2013 г. 16:20:00, error: DCOM [10005]  - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
29.5.2013 г. 15:40:40, error: DCOM [10005]  - DCOM got error "%1084" attempting to start the service hpqwmiex with arguments "" in order to run the server: {F5539356-2F02-40D4-999E-FA61F45FE12E}
29.5.2013 г. 15:38:13, error: DCOM [10005]  - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064}
29.5.2013 г. 15:38:05, error: DCOM [10005]  - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064}
29.5.2013 г. 15:37:44, error: DCOM [10005]  - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064}
29.5.2013 г. 15:37:08, error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  Fips intelppm MpFilter PCIIde
29.5.2013 г. 15:36:08, error: DCOM [10005]  - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
29.5.2013 г. 15:35:51, error: sr [1]  - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'.  It has stopped monitoring the volume.
29.5.2013 г. 15:31:48, error: DCOM [10005]  - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
29.5.2013 г. 15:25:00, error: DCOM [10005]  - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
29.5.2013 г. 15:13:42, error: DCOM [10005]  - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
29.5.2013 г. 15:13:35, error: DCOM [10005]  - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
29.5.2013 г. 15:13:14, error: DCOM [10005]  - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
29.5.2013 г. 15:13:10, error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  AFD Fips intelppm IPSec MpFilter MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip
29.5.2013 г. 15:13:10, error: Service Control Manager [7001]  - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error:  A device attached to the system is not functioning.
29.5.2013 г. 15:13:10, error: Service Control Manager [7001]  - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error:  A device attached to the system is not functioning.
29.5.2013 г. 15:13:10, error: Service Control Manager [7001]  - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error:  A device attached to the system is not functioning.
29.5.2013 г. 15:13:10, error: Service Control Manager [7001]  - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error:  A device attached to the system is not functioning.
29.5.2013 г. 15:08:58, error: Service Control Manager [7009]  - Timeout (30000 milliseconds) waiting for the Vodafone Mobile Connect Service service to connect.
29.5.2013 г. 15:08:13, error: Service Control Manager [7009]  - Timeout (30000 milliseconds) waiting for the Microsoft Antimalware Service service to connect.
29.5.2013 г. 15:08:13, error: Service Control Manager [7009]  - Timeout (30000 milliseconds) waiting for the IBUpdaterService service to connect.
29.5.2013 г. 15:08:13, error: Service Control Manager [7000]  - The Microsoft Antimalware Service service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
29.5.2013 г. 15:08:13, error: Service Control Manager [7000]  - The IBUpdaterService service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
29.5.2013 г. 15:08:08, error: Service Control Manager [7031]  - The IBUpdaterService service terminated unexpectedly.  It has done this 3 time(s).  The following corrective action will be taken in 5000 milliseconds: Restart the service.
29.5.2013 г. 15:08:03, error: Service Control Manager [7031]  - The IBUpdaterService service terminated unexpectedly.  It has done this 2 time(s).  The following corrective action will be taken in 5000 milliseconds: Restart the service.
29.5.2013 г. 15:07:58, error: Service Control Manager [7034]  - The Java Quick Starter service terminated unexpectedly.  It has done this 1 time(s).
29.5.2013 г. 15:07:58, error: Service Control Manager [7034]  - The HWDeviceService.exe service terminated unexpectedly.  It has done this 1 time(s).
29.5.2013 г. 15:07:58, error: Service Control Manager [7034]  - The hpqwmiex service terminated unexpectedly.  It has done this 1 time(s).
29.5.2013 г. 15:07:58, error: Service Control Manager [7031]  - The Microsoft Antimalware Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 15000 milliseconds: Restart the service.
29.5.2013 г. 15:07:58, error: Service Control Manager [7031]  - The IBUpdaterService service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 5000 milliseconds: Restart the service.
29.5.2013 г. 15:07:57, error: Service Control Manager [7034]  - The Machine Debug Manager service terminated unexpectedly.  It has done this 1 time(s).
29.5.2013 г. 15:07:57, error: Service Control Manager [7034]  - The Com4QLBEx service terminated unexpectedly.  It has done this 1 time(s).
29.5.2013 г. 15:07:57, error: Service Control Manager [7031]  - The Vodafone Mobile Connect Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
29.5.2013 г. 15:07:09, error: Service Control Manager [7009]  - Timeout (30000 milliseconds) waiting for the M-Tel NETAGENT. OUC service to connect.
29.5.2013 г. 15:07:09, error: Service Control Manager [7000]  - The M-Tel NETAGENT. OUC service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
29.5.2013 г. 15:03:19, error: Service Control Manager [7009]  - Timeout (30000 milliseconds) waiting for the M-Tel NETAGENT. OUC service to connect.
29.5.2013 г. 15:03:19, error: Service Control Manager [7000]  - The M-Tel NETAGENT. OUC service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
29.5.2013 г. 14:27:15, error: Service Control Manager [7009]  - Timeout (30000 milliseconds) waiting for the M-Tel NETAGENT. OUC service to connect.
29.5.2013 г. 14:27:15, error: Service Control Manager [7000]  - The M-Tel NETAGENT. OUC service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
29.5.2013 г. 14:26:27, error: Ntfs [55]  - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume C:.
29.5.2013 г. 13:39:54, error: Dhcp [1001]  - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 001CBF7F5177.  The following error occurred:  The operation was canceled by the user. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.
28.5.2013 г. 19:05:18, error: Service Control Manager [7009]  - Timeout (30000 milliseconds) waiting for the M-Tel NETAGENT. OUC service to connect.
28.5.2013 г. 19:05:18, error: Service Control Manager [7000]  - The M-Tel NETAGENT. OUC service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
28.5.2013 г. 10:38:02, error: Microsoft Antimalware [2001]  - Microsoft Antimalware откри грешка при опит за актуализиране на сигнатурите.  Нова версия на сигнатурите:    Предишна версия на сигнатурите: 1.151.925.0  Източник на актуализиране: Сървър на Microsoft Update  Стадий на актуализиране: Търсене  Път на източника: http://www.microsoft.com  Тип сигнатури: Антивирусна защита  Тип актуализиране: Пълна  Потребител: NT AUTHORITYSYSTEM  Текуща версия на системата:    Предишна версия на системата: 1.1.9506.0  Код на грешката: 0x8024402c  Описание на грешката: Възникна неочакван проблем при проверка за актуализации. За информация относно инсталирането или отстраняването на неизправности на актуализации вж. "Помощ и поддръжка".
27.5.2013 г. 16:08:16, error: Microsoft Antimalware [2001]  - Microsoft Antimalware откри грешка при опит за актуализиране на сигнатурите.  Нова версия на сигнатурите:    Предишна версия на сигнатурите: 1.151.925.0  Източник на актуализиране: Сървър на Microsoft Update  Стадий на актуализиране: Търсене  Път на източника: http://www.microsoft.com  Тип сигнатури: Антивирусна защита  Тип актуализиране: Пълна  Потребител: NT AUTHORITYSYSTEM  Текуща версия на системата:    Предишна версия на системата: 1.1.9506.0  Код на грешката: 0x8024402c  Описание на грешката: Възникна неочакван проблем при проверка за актуализации. За информация относно инсталирането или отстраняването на неизправности на актуализации вж. "Помощ и поддръжка".
27.5.2013 г. 11:46:05, error: Microsoft Antimalware [2001]  - Microsoft Antimalware откри грешка при опит за актуализиране на сигнатурите.  Нова версия на сигнатурите:    Предишна версия на сигнатурите: 1.151.925.0  Източник на актуализиране: Сървър на Microsoft Update  Стадий на актуализиране: Търсене  Път на източника: http://www.microsoft.com  Тип сигнатури: Антивирусна защита  Тип актуализиране: Пълна  Потребител: NT AUTHORITYSYSTEM  Текуща версия на системата:    Предишна версия на системата: 1.1.9506.0  Код на грешката: 0x8024402c  Описание на грешката: Възникна неочакван проблем при проверка за актуализации. За информация относно инсталирането или отстраняването на неизправности на актуализации вж. "Помощ и поддръжка".
27.5.2013 г. 11:36:23, error: Service Control Manager [7009]  - Timeout (30000 milliseconds) waiting for the M-Tel NETAGENT. OUC service to connect.
27.5.2013 г. 11:36:23, error: Service Control Manager [7000]  - The M-Tel NETAGENT. OUC service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
25.5.2013 г. 21:46:19, error: Dhcp [1002]  - The IP address lease 10.176.18.71 for the Network Card with network address 582C80139263 has been denied by the DHCP server 10.176.20.193 (The DHCP Server sent a DHCPNACK message).
25.5.2013 г. 16:25:24, error: Dhcp [1002]  - The IP address lease 10.176.122.222 for the Network Card with network address 582C80139263 has been denied by the DHCP server 10.176.18.65 (The DHCP Server sent a DHCPNACK message).
25.5.2013 г. 14:33:24, error: W32Time [17]  - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
25.5.2013 г. 14:16:40, error: Microsoft Antimalware [2001]  - Microsoft Antimalware откри грешка при опит за актуализиране на сигнатурите.  Нова версия на сигнатурите:    Предишна версия на сигнатурите: 1.151.404.0  Източник на актуализиране: Център на Microsoft за защита от злонамерен софтуер  Стадий на актуализиране: Търсене  Път на източника: http://go.microsoft.com/fwlink/?LinkID=121721&clcid=0x409&arch=x86&eng=1.1.9506.0&avdelta=1.151.404.0&asdelta=1.151.404.0&prod=EDB4FA23-53B8-4AFA-8C5D-99752CCA7094  Тип сигнатури: AntiSpyware  Тип актуализиране: Пълна  Потребител: NT AUTHORITYNETWORK SERVICE  Текуща версия на системата:    Предишна версия на системата: 1.1.9506.0  Код на грешката: 0x80072ee7  Описание на грешката: The server name or address could not be resolved
25.5.2013 г. 14:16:40, error: Microsoft Antimalware [2001]  - Microsoft Antimalware откри грешка при опит за актуализиране на сигнатурите.  Нова версия на сигнатурите:    Предишна версия на сигнатурите: 1.151.404.0  Източник на актуализиране: Център на Microsoft за защита от злонамерен софтуер  Стадий на актуализиране: Търсене  Път на източника: http://go.microsoft.com/fwlink/?LinkID=121721&clcid=0x409&arch=x86&eng=1.1.9506.0&avdelta=1.151.404.0&asdelta=1.151.404.0&prod=EDB4FA23-53B8-4AFA-8C5D-99752CCA7094  Тип сигнатури: AntiSpyware  Тип актуализиране: Пълна  Потребител: NT AUTHORITYNETWORK SERVICE  Текуща версия на системата:    Предишна версия на системата: 1.1.9506.0  Код на грешката: 0x80072ee7  Описание на грешката: The server name or address could not be resolved
25.5.2013 г. 14:16:40, error: Microsoft Antimalware [2001]  - Microsoft Antimalware откри грешка при опит за актуализиране на сигнатурите.  Нова версия на сигнатурите:    Предишна версия на сигнатурите: 1.151.404.0  Източник на актуализиране: Център на Microsoft за защита от злонамерен софтуер  Стадий на актуализиране: Търсене  Път на източника: http://go.microsoft.com/fwlink/?LinkID=121721&clcid=0x409&arch=x86&eng=1.1.9506.0&avdelta=1.151.404.0&asdelta=1.151.404.0&prod=EDB4FA23-53B8-4AFA-8C5D-99752CCA7094  Тип сигнатури: Антивирусна защита  Тип актуализиране: Пълна  Потребител: NT AUTHORITYNETWORK SERVICE  Текуща версия на системата:    Предишна версия на системата: 1.1.9506.0  Код на грешката: 0x80072ee7  Описание на грешката: The server name or address could not be resolved
25.5.2013 г. 14:16:40, error: Microsoft Antimalware [2001]  - Microsoft Antimalware откри грешка при опит за актуализиране на сигнатурите.  Нова версия на сигнатурите:    Предишна версия на сигнатурите: 1.151.404.0  Източник на актуализиране: Център на Microsoft за защита от злонамерен софтуер  Стадий на актуализиране: Търсене  Път на източника: http://go.microsoft.com/fwlink/?LinkID=121721&clcid=0x409&arch=x86&eng=1.1.9506.0&avdelta=1.151.404.0&asdelta=1.151.404.0&prod=EDB4FA23-53B8-4AFA-8C5D-99752CCA7094  Тип сигнатури: Антивирусна защита  Тип актуализиране: Пълна  Потребител: NT AUTHORITYNETWORK SERVICE  Текуща версия на системата:    Предишна версия на системата: 1.1.9506.0  Код на грешката: 0x80072ee7  Описание на грешката: The server name or address could not be resolved
25.5.2013 г. 14:16:39, error: Microsoft Antimalware [2001]  - Microsoft Antimalware откри грешка при опит за актуализиране на сигнатурите.  Нова версия на сигнатурите:    Предишна версия на сигнатурите: 1.151.404.0  Източник на актуализиране: Сървър на Microsoft Update  Стадий на актуализиране: Търсене  Път на източника: http://www.microsoft.com  Тип сигнатури: Антивирусна защита  Тип актуализиране: Пълна  Потребител: NT AUTHORITYSYSTEM  Текуща версия на системата:    Предишна версия на системата: 1.1.9506.0  Код на грешката: 0x8024402c  Описание на грешката: Възникна неочакван проблем при проверка за актуализации. За информация относно инсталирането или отстраняването на неизправности на актуализации вж. "Помощ и поддръжка".
25.5.2013 г. 14:06:49, error: Service Control Manager [7009]  - Timeout (30000 milliseconds) waiting for the M-Tel NETAGENT. OUC service to connect.
25.5.2013 г. 14:06:49, error: Service Control Manager [7000]  - The M-Tel NETAGENT. OUC service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
23.5.2013 г. 16:53:41, error: Microsoft Antimalware [2001]  - Microsoft Antimalware откри грешка при опит за актуализиране на сигнатурите.  Нова версия на сигнатурите:    Предишна версия на сигнатурите: 1.151.404.0  Източник на актуализиране: Сървър на Microsoft Update  Стадий на актуализиране: Търсене  Път на източника: http://www.microsoft.com  Тип сигнатури: Антивирусна защита  Тип актуализиране: Пълна  Потребител: NT AUTHORITYSYSTEM  Текуща версия на системата:    Предишна версия на системата: 1.1.9506.0  Код на грешката: 0x8024402c  Описание на грешката: Възникна неочакван проблем при проверка за актуализации. За информация относно инсталирането или отстраняването на неизправности на актуализации вж. "Помощ и поддръжка".
.
==== End Of File ===========================

 

 

 

DDS (Ver_2011-09-30.01) - NTFS_x86 NETWORK
Internet Explorer: 7.0.5730.13  BrowserJavaVersion: 1.6.0_27
Run by WORK at 16:57:41 on 2013-05-29
#Option MBR scan  is disabled.
Microsoft Windows XP Professional  5.1.2600.3.1251.359.1033.18.2039.1398 [GMT 3:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
============== Running Processes ================
.
c:Program FilesMicrosoft Security ClientAntimalwareMsMpEng.exe
C:WINDOWSExplorer.EXE
C:Program FilesMozilla Firefoxfirefox.exe
C:Program FilesMozilla Firefoxplugin-container.exe
C:WINDOWSsystem32wbemwmiprvse.exe
C:WINDOWSsystem32svchost.exe -k netsvcs
C:WINDOWSsystem32svchost.exe -k NetworkService
C:WINDOWSsystem32svchost.exe -k LocalService
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://mystart.incredibar.com/mb201?a=6PQPw9BI28&i=26
uProxyOverride = <local>
BHO: AcroIEHlprObj Class: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:program filesadobeacrobat 6.0acrobatactivexAcroIEHelper.dll
BHO: Skype add-on (mastermind): {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - c:program filesskypetoolbarsinternet explorerSkypeIEPlugin.dll
BHO: Babylon toolbar helper: {2EECD738-5844-4a99-B4B6-146BF802613B} - c:program filesbabylontoolbarbabylontoolbar1.4.31.2bhBabylonToolbar.dll
BHO: IB Updater: {336D0C35-8A85-403a-B9D2-65C292C39087} - c:program filesib updaterExtension32.dll
BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - c:program filesspybot - search & destroySDHelper.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:program filesmicrosoft officeoffice12GrooveShellExtensions.dll
BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:program filesjavajre6binjp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - c:program filesjavajre6libdeployjqsiejqs_plugin.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c:program filesadobeacrobat 6.0acrobatAcroIEFavClient.dll
TB: Babylon Toolbar: {98889811-442D-49dd-99D7-DC866BE87DBC} - c:program filesbabylontoolbarbabylontoolbar1.4.31.2BabylonToolbarTlbr.dll
EB: Adobe PDF: {182EC0BE-5110-49C8-A062-BEB1D02A220B} - c:program filesadobeacrobat 6.0acrobatAcroIEFavClient.dll
uRun: [CTFMON.EXE] c:windowssystem32ctfmon.exe
uRun: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:program filescommon filesaheadlibNMBgMonitor.exe"
uRun: [mRouterConfig] "c:program filesintuwavesharedmrouterruntimemRouterConfig.exe"
uRun: [DAEMON Tools Lite] "c:program filesdaemon tools litedaemon.exe" -autorun
uRun: [Akamai NetSession Interface] "c:documents and settingsworklocal settingsapplication dataakamainetsession_win.exe"
mRun: [igfxTray] c:windowssystem32igfxtray.exe
mRun: [HotKeysCmds] c:windowssystem32hkcmd.exe
mRun: [Persistence] c:windowssystem32igfxpers.exe
mRun: [synTPEnh] c:program filessynapticssyntpSynTPEnh.exe
mRun: [QlbCtrl.exe] c:program fileshewlett-packardhp quick launch buttonsQlbCtrl.exe /Start
mRun: [GrooveMonitor] "c:program filesmicrosoft officeoffice12GrooveMonitor.exe"
mRun: [PC Suite for Smartphones] "c:program filessony ericssonmobile4application launcherApplication Launcher.exe" /startoptions
mRun: [QuickTime Task] "c:program filesquicktimeqttask.exe" -atboottime
mRun: [iME JPN 2007 Migration] c:progra~1common~1micros~1ime12imejpIMJPKLMG.EXE /Preload
mRun: [Korean IME Migration] c:progra~1common~1micros~1ime12imekrIMKRMIG.EXE
mRun: [Microsoft Pinyin IME Migration] c:progra~1common~1micros~1ime12imescIMSCMIG.EXE /INSTALL
mRun: [KernelFaultCheck] c:windowssystem32dumprep 0 -k
mRun: [MobileConnect] c:program filesvodafonevodafone mobile connectbinMobileConnect.exe /silent
mRun: [sunJavaUpdateSched] "c:program filescommon filesjavajava updatejusched.exe"
mRun: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [MSC] "c:program filesmicrosoft security clientmsseces.exe" -hide -runkey
mRun: [Hard Disk Sentinel] "c:program fileshard disk sentinelHDSentinel.exe" /AUTORUN
mRun: [bonus.SSR.FR10] "c:program filesabbyy finereader 10Bonus.ScreenshotReader.exe" /autorun
mRunOnce: [Malwarebytes Anti-Malware (cleanup)] rundll32.exe "c:documents and settingsall usersapplication datamalwarebytesmalwarebytes' anti-malwarecleanup.dll",ProcessCleanupScript
mRunOnce: [Malwarebytes Anti-Malware] c:program filesmalwarebytes' anti-malwarembamgui.exe /install /silent
dRun: [CTFMON.EXE] c:windowssystem32CTFMON.EXE
dRun: [DWQueuedReporting] "c:progra~1common~1micros~1dwdwtrig20.exe" -t
dRunOnce: [nltide_2] regsvr32 /s /n /i:U shell32
StartupFolder: c:docume~1workstartm~1programsstartuponenot~1.lnk - c:program filesmicrosoft officeoffice12ONENOTEM.EXE
StartupFolder: c:docume~1alluse~1startm~1programsstartupacroba~1.lnk - c:program filesadobeacrobat 6.0distillracrotray.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: E&xport to Microsoft Excel - c:progra~1micros~2office12EXCEL.EXE/3000
IE: Е&кспортирай в Microsoft Excel - c:progra~1micros~2office11EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:program filesmicrosoft officeoffice12ONBttnIE.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:program filesskypetoolbarsinternet explorerSkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:program filesspybot - search & destroySDHelper.dll
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%Network Diagnosticxpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:program filesmessengermsmsgs.exe
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: NameServer = 192.168.0.1
TCP: Interfaces{39D58629-260F-46C1-BD3A-AF1FC775061C} : DHCPNameServer = 192.168.0.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:program filesmicrosoft officeoffice12GrooveSystemServices.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:program filescommon filesskypeSkype4COM.dll
Notify: igfxcui - igfxdev.dll
Notify: WB - c:program filesalienguisefastload.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:windowssystem32wpdshserviceobj.dll
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:program filesmicrosoft officeoffice12GrooveShellExtensions.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:documents and settingsworkapplication datamozillafirefoxprofilesfp2c9d5o.default
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.bg/firefox
FF - prefs.js: keyword.URL - hxxp://mystart.incredibar.com/mb201/?loc=IB_DS&a=6PQPw9BI28&&i=26&search=
FF - plugin: c:program filesjavajre6binnew_pluginnpdeployJava1.dll
FF - plugin: c:program filesmicrosoft silverlight4.1.10329.0npctrlui.dll
FF - plugin: c:windowssystem32macromedflashNPSWF32_11_7_700_202.dll
.
---- FIREFOX POLICIES ----
FF - user.js: extensions.incredibar_i.newTab - false
FF - user.js: extensions.incredibar_i.tlbrSrchUrl - hxxp://mystart.Incredibar.com/?a=6PQPw9BI28&loc=IB_TB&i=26&search=
FF - user.js: extensions.incredibar_i.id - 28a2c00e000000000000001cbf7f5177
FF - user.js: extensions.incredibar_i.instlDay - 15656
FF - user.js: extensions.incredibar_i.vrsn - 1.5.11.14
FF - user.js: extensions.incredibar_i.vrsni - 1.5.11.14
FF - user.js: extensions.incredibar_i.vrsnTs - 1.5.11.1419:30:58
FF - user.js: extensions.incredibar_i.prtnrId - Incredibar
FF - user.js: extensions.incredibar_i.prdct - incredibar
FF - user.js: extensions.incredibar_i.aflt - orgnl
FF - user.js: extensions.incredibar_i.smplGrp - none
FF - user.js: extensions.incredibar_i.tlbrId - base
FF - user.js: extensions.incredibar_i.instlRef -
FF - user.js: extensions.incredibar_i.dfltLng -
FF - user.js: extensions.incredibar_i.excTlbr - false
FF - user.js: extensions.incredibar_i.ms_url_id -
FF - user.js: extensions.incredibar_i.upn2 - 6PQPw9BI28
FF - user.js: extensions.incredibar_i.upn2n - 92543914892173660
FF - user.js: extensions.incredibar_i.productid - 26
FF - user.js: extensions.incredibar_i.installerproductid - 26
FF - user.js: extensions.incredibar_i.did - 10643
FF - user.js: extensions.incredibar_i.ppd - 77777212
.
============= SERVICES / DRIVERS ===============
.
R3 huawei_enumerator;huawei_enumerator;c:windowssystem32driversew_jubusenum.sys [2012-6-7 73984]
R3 NETwLx32;   Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit;c:windowssystem32driversNETwLx32.sys [2012-12-4 6609920]
S1 MpFilter;Microsoft Malware Protection Driver;c:windowssystem32driversMpFilter.sys [2011-4-18 165648]
S2 Akamai;Akamai NetSession Interface;c:windowssystem32svchost.exe -k Akamai [2008-4-14 14336]
S2 HWDeviceService.exe;HWDeviceService.exe;c:documents and settingsall usersapplication datadatacardserviceHWDeviceService.exe [2011-3-14 271712]
S2 M-Tel NETAGENT. RunOuc;M-Tel NETAGENT. OUC;c:program filesm-tel netagentupdatedogouc.exe [2012-6-7 655712]
S2 puougojpk;Update Microsoft;c:windowssystem32svchost.exe -k netsvcs [2008-4-14 14336]
S2 tjmko;Support Boot;c:windowssystem32svchost.exe -k netsvcs [2008-4-14 14336]
S2 VMCService;Vodafone Mobile Connect Service;c:program filesvodafonevodafone mobile connectbinVMCService.exe [2008-11-4 14336]
S3 Com4QLBEx;Com4QLBEx;c:program fileshewlett-packardhp quick launch buttonsCom4QLBEx.exe [2009-1-8 193840]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:windowssystem32driversew_hwusbdev.sys [2012-6-7 102784]
S3 ew_usbenumfilter;huawei_CompositeFilter;c:windowssystem32driversew_usbenumfilter.sys [2012-6-7 11136]
S3 ggflt;SEMC USB Flash Driver Filter;c:windowssystem32driversggflt.sys [2012-2-28 13224]
S3 GGSAFERDriver;GGSAFER Driver;??c:program filesgarena plusroomsafedrv.sys --> c:program filesgarena plusroomsafedrv.sys [?]
S3 huawei_cdcacm;huawei_cdcacm;c:windowssystem32driversew_jucdcacm.sys [2012-6-7 89856]
S3 huawei_cdcecm;huawei_cdcecm;c:windowssystem32driversew_jucdcecm.sys [2012-6-7 66688]
S3 huawei_ext_ctrl;huawei_ext_ctrl;c:windowssystem32driversew_juextctrl.sys [2012-6-7 26624]
S3 krxaau;krxaau;??c:windowssystem3201.tmp --> c:windowssystem3201.tmp [?]
S3 massfilter;ZTE Mass Storage Filter Driver;c:windowssystem32driversmassfilter.sys [2011-2-12 7680]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:program filesmozilla maintenance servicemaintenanceservice.exe [2012-10-25 117144]
S3 qutmzo;qutmzo;??c:windowssystem3201.tmp --> c:windowssystem3201.tmp [?]
S3 RT-USB;Ross-Tech USB driver;c:windowssystem32driversRT-USB.SYS [2009-6-16 54176]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:windowssystem32driverss0016bus.sys [2012-1-22 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:windowssystem32driverss0016mdfl.sys [2012-1-22 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:windowssystem32driverss0016mdm.sys [2012-1-22 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:windowssystem32driverss0016mgmt.sys [2012-1-22 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:windowssystem32driverss0016nd5.sys [2012-1-22 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:windowssystem32driverss0016obex.sys [2012-1-22 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:windowssystem32driverss0016unic.sys [2012-1-22 115752]
S3 s115bus;Sony Ericsson Device 115 driver (WDM);c:windowssystem32driverss115bus.sys [2007-4-23 83208]
S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;c:windowssystem32driverss115mdfl.sys [2007-4-23 15112]
S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;c:windowssystem32driverss115mdm.sys [2007-4-23 108680]
S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);c:windowssystem32driverss115mgmt.sys [2007-4-23 100488]
S3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;c:windowssystem32driverss115obex.sys [2007-4-23 98568]
S3 Sony PC Companion;Sony PC Companion;c:program filessonysony pc companionPCCService.exe [2012-1-22 155320]
S3 ZTEusbnet;ZTE USB-NDIS miniport;c:windowssystem32driversZTEusbnet.sys [2011-2-12 110080]
.
=============== Created Last 30 ================
.
2013-05-29 11:40:53  --------  d-----w-  c:documents and settingsall usersapplication data28A7B553AD62C00E000028A78CB0C4B2
2013-05-29 11:39:22  60872  ----a-w-  c:documents and settingsall usersapplication datamicrosoftmicrosoft antimalwaredefinition updates{5651ceb0-dd49-48d5-b5eb-09c9dc693a4b}offreg.dll
2013-05-29 11:32:15  --------  d-----w-  c:documents and settingsworkapplication datahpqLog
2013-05-28 17:37:41  262552  ----a-w-  c:program filesmozilla firefoxbrowsercomponentsbrowsercomps.dll
2013-05-28 16:15:46  7016152  ----a-w-  c:documents and settingsall usersapplication datamicrosoftmicrosoft antimalwaredefinition updates{5651ceb0-dd49-48d5-b5eb-09c9dc693a4b}mpengine.dll
.
==================== Find3M  ====================
.
2013-05-29 09:40:57  71048  ----a-w-  c:windowssystem32FlashPlayerCPLApp.cpl
2013-05-29 09:40:57  692104  ----a-w-  c:windowssystem32FlashPlayerApp.exe
2013-05-02 15:28:50  238872  ------w-  c:windowssystem32MpSigStub.exe
2013-04-07 08:52:34  27136  ----a-w-  c:windowssystem32ImHttpComm.dll
2013-04-04 11:50:32  22856  ----a-w-  c:windowssystem32driversmbam.sys
.
============= FINISH: 16:58:12,84 ===============
 

Редактирано от B-boy[StyLe] (преглед на промените)

Здравейте,

 

Имате активен червей - Conficker, но няма гаранция, че проблема с батерията се дължи на зловреден код...може да си е отишла батерията.

 

 

1. Изтеглете ComboFix от BleepingComputer
и го запазете (бутон Save -> Save as) ComboFix на вашия десктоп:
Публикувано изображение
След приключване на изтеглянето на ComboFix, иконката на програмата би трябвало да изглежда така:
Публикувано изображение


2. Затворете всички работещи приложения, отворени прозорци и програми работещи във фонов режим. Спрете временно защитата в реално време на антивирусната програма и на другите програми за сигурност, ако има такива.



3. Стартирайте с двоен клик Combofix.exe. Изберете YES, за да се съгласите с условията за използване на програмата. Важно: По време на работата на ComboFix не бива да се движи мишката и да се натискат клавиши от клавиатурата. Просто търпеливо оставете ComboFix да си свърши работата, без да използвате компютъра за други цели.



4. ComboFix ще провери дали Windows Recovery Console e инсталиранa.


*Ако Windows Recovery Console не е инсталирана, ще е необходимо да използвате YES за инсталация на Windows Recovery Console
*Ако Windows Recovery Console е инсталирана, ComboFix ще продължи работата си.
Публикувано изображение


Забележка: Необходимо е да сте свързани към Интернет за да може Windows Recovery Console да се изтегли.


След инсталация на Windows Recovery Console потвърдете с YES, за да продължите напред. Снимка:
Публикувано изображение


5. ComboFix ще спре временно Интернет връзката, но след като приключи работата на програмата тази връзка ще бъде възстановена автоматично. ComboFix ще сканира за проблеми и за заразени файлове, като това може да отнеме известно време. Моля да бъдете търпеливи. Ако има проблем с Интернет връзката след приключване на работата на Combofix, моля да прочетете това: Manually restoring the Internet connection section.


6. След като работата на ComboFix приключи, компютъра ще се рестартира автоматично. По-време на рестарта натискайте F8 и отново заредете в Safe Mode, за да може Combofix да приключи своята работа коректно. След това ще се появи текстов документ (log) в Notepad:
Публикувано изображение

 

7. Копирайте лог файла в следващия си коментар.

  • Автор

ComboFix 13-05-30.02 - WORK 05.2013 г.  13:42:51.1.2 - x86
Microsoft Windows XP Professional  5.1.2600.3.1251.359.1033.18.2039.1338 [GMT 3:00]
Running from: d:my documentsDownloadsComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:documents and settingsWORKWINDOWS
c:program filesIB UpdaterExTEnsion32.dll
c:windowsEventSystem.log
c:windowssystem32URTTemp
c:windowssystem32URTTempregtlib.exe
c:windowsXSxS
.
.
((((((((((((((((((((((((( Files Created from 2013-04-28 to 2013-05-30  )))))))))))))))))))))))))))))))
.
.
2013-05-30 10:37 . 2013-05-30 10:37  29904  ----a-w-  c:documents and settingsAll UsersApplication DataMicrosoftMicrosoft AntimalwareDefinition Updates{C386C073-5CC3-4F0C-8A18-DD9C07BB031D}MpKsl749d188d.sys
2013-05-29 21:40 . 2013-05-29 21:40  --------  d-----w-  c:documents and settingsWORKApplication DataGRETECH
2013-05-29 21:39 . 2013-05-29 21:39  --------  d-----w-  c:program filesGRETECH
2013-05-29 21:26 . 2013-05-13 06:19  7016152  ----a-w-  c:documents and settingsAll UsersApplication DataMicrosoftMicrosoft AntimalwareDefinition Updates{C386C073-5CC3-4F0C-8A18-DD9C07BB031D}mpengine.dll
2013-05-29 14:21 . 2013-05-29 14:21  --------  d-----w-  c:windowssystem32wbemFramework
2013-05-29 11:40 . 2013-05-29 12:07  --------  d-----w-  c:documents and settingsAll UsersApplication Data28A7B553AD62C00E000028A78CB0C4B2
2013-05-29 11:33 . 2013-05-29 11:33  --------  d-----w-  c:documents and settingsAll UsersApplication DataHewlett-Packard
2013-05-29 11:32 . 2013-05-29 11:32  --------  d-----w-  c:documents and settingsLocalServiceApplication DatahpqLog
2013-05-29 11:32 . 2013-05-29 11:32  --------  d-----w-  c:documents and settingsWORKApplication DatahpqLog
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-05-29 09:40 . 2013-04-13 19:56  692104  ----a-w-  c:windowssystem32FlashPlayerApp.exe
2013-05-29 09:40 . 2011-12-14 07:12  71048  ----a-w-  c:windowssystem32FlashPlayerCPLApp.cpl
2013-05-13 06:19 . 2011-11-10 09:05  7016152  ----a-w-  c:documents and settingsAll UsersApplication DataMicrosoftMicrosoft AntimalwareDefinition UpdatesBackupmpengine.dll
2013-05-02 15:28 . 2011-11-08 20:17  238872  ------w-  c:windowssystem32MpSigStub.exe
2013-04-07 08:52 . 2012-11-12 17:30  27136  ----a-w-  c:windowssystem32ImHttpComm.dll
2013-04-04 11:50 . 2011-03-17 13:30  22856  ----a-w-  c:windowssystem32driversmbam.sys
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2008-07-12 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:windowssystem32sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"mRouterConfig"="c:program filesIntuwaveSharedmRouterRuntimemRouterConfig.exe" [2006-03-02 290816]
"DAEMON Tools Lite"="c:program filesDAEMON Tools Litedaemon.exe" [2008-08-08 490952]
"Akamai NetSession Interface"="c:documents and settingsWORKLocal SettingsApplication DataAkamainetsession_win.exe" [2013-01-26 4480768]
.
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"IgfxTray"="c:windowssystem32igfxtray.exe" [2007-09-18 141848]
"HotKeysCmds"="c:windowssystem32hkcmd.exe" [2007-09-18 166424]
"Persistence"="c:windowssystem32igfxpers.exe" [2007-09-18 137752]
"SynTPEnh"="c:program filesSynapticsSynTPSynTPEnh.exe" [2008-01-18 1028096]
"QlbCtrl.exe"="c:program filesHewlett-PackardHP Quick Launch ButtonsQlbCtrl.exe" [2008-06-03 177456]
"GrooveMonitor"="c:program filesMicrosoft OfficeOffice12GrooveMonitor.exe" [2007-08-24 33648]
"PC Suite for Smartphones"="c:program filesSony EricssonMobile4Application LauncherApplication Launcher.exe" [2006-04-25 487424]
"QuickTime Task"="c:program filesQuickTimeqttask.exe" [2009-01-26 155648]
"IME JPN 2007 Migration"="c:progra~1COMMON~1MICROS~1IME12IMEJPIMJPKLMG.EXE" [2006-10-26 59184]
"Korean IME Migration"="c:progra~1COMMON~1MICROS~1IME12IMEKRIMKRMIG.EXE" [2006-10-26 26400]
"Microsoft Pinyin IME Migration"="c:progra~1COMMON~1MICROS~1IME12IMESCIMSCMIG.EXE" [2006-10-26 32560]
"MobileConnect"="c:program filesVodafoneVodafone Mobile ConnectBinMobileConnect.exe" [2008-11-04 2087424]
"SunJavaUpdateSched"="c:program filesCommon FilesJavaJava Updatejusched.exe" [2011-06-09 254696]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"MSC"="c:program filesMicrosoft Security Clientmsseces.exe" [2011-06-15 997920]
"Hard Disk Sentinel"="c:program filesHard Disk SentinelHDSentinel.exe" [2011-12-21 4060160]
"Bonus.SSR.FR10"="c:program filesABBYY FineReader 10Bonus.ScreenshotReader.exe" [2011-06-08 941320]
.
[HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRun]
"CTFMON.EXE"="c:windowssystem32CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:progra~1COMMON~1MICROS~1DWdwtrig20.exe" [2007-08-24 437160]
.
[HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRunOnce]
"nltide_2"="shell32" [X]
.
c:documents and settingsWORKStart MenuProgramsStartup
OneNote 2007 Screen Clipper and Launcher.lnk - c:program filesMicrosoft OfficeOffice12ONENOTEM.EXE [2009-2-26 97680]
.
c:documents and settingsAll UsersStart MenuProgramsStartup
Acrobat Assistant.lnk - c:program filesAdobeAcrobat 6.0Distillracrotray.exe [2003-5-15 217193]
.
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionwinlogonnotifyWB]
2001-12-20 19:34  24576  ----a-w-  c:program filesAlienGUIsefastload.dll
.
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionwindows]
"AppInit_DLLs"=c:windowssystem32wbsys.dll
.
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalMsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalWdf01000.sys]
@="Driver"
.
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]
"%windir%Network Diagnosticxpnetdiag.exe"=
"%windir%system32sessmgr.exe"=
"c:Program FilesMicrosoft OfficeOffice12OUTLOOK.EXE"=
"c:Program FilesMicrosoft OfficeOffice12GROOVE.EXE"=
"c:Program FilesMicrosoft OfficeOffice12ONENOTE.EXE"=
"c:Program FilesIntuwaveSharedmRouterRuntimemRouterRuntime.exe"=
"c:Program FilesSony EricssonMobile4Sync ManagerDXP SyncML.exe"=
"c:Program FilesuTorrentuTorrent.exe"=
"d:Age of EmpiresEMPIRES2.ICD"=
"c:WINDOWSsystem32dplaysvr.exe"=
"c:Documents and SettingsWORKDesktopDiablo IIGame.exe"=
"c:Documents and SettingsWORKApplication DataGameRangerGameRangerGameRanger.exe"=
"d:Yu-Gi-Oh! Power of Chaos Commonkfjadsjoey_pc.exe"=
"c:WINDOWSsystem32dpnsvr.exe"=
"d:StrongholdStronghold Crusader.exe"=
"c:Documents and SettingsWORKLocal SettingsApplication DataAkamainetsession_win.exe"=
"d:Warcraft IIIWar3.exe"=
"d:Warcraft IIIWarcraft III.exe"=
"c:Program FilesValveCounter-Strike 1.6 Sector Editioncstrike.exe"=
"c:WINDOWSsystem32ARFCwrtc.exe"=
"c:Program FilesValveCounter-Strike 1.6 Sector Editionhl.exe"=
"c:Program FilesIP-TV PlayerIpTvPlayer.exe"=
"c:Program FilesSkypePhoneSkype.exe"=
.
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileGloballyOpenPortsList]
"1388:TCP"= 1388:TCP:ocvmny
.
R0 sptd;sptd;c:windowssystem32driverssptd.sys [13.2.2009 г. 22:55 717296]
R1 MpKsl749d188d;MpKsl749d188d;c:documents and settingsAll UsersApplication DataMicrosoftMicrosoft AntimalwareDefinition Updates{C386C073-5CC3-4F0C-8A18-DD9C07BB031D}MpKsl749d188d.sys [30.5.2013 г. 13:37 29904]
R2 Akamai;Akamai NetSession Interface;c:windowsSystem32svchost.exe -k Akamai [14.4.2008 г. 11:00 14336]
R2 VMCService;Vodafone Mobile Connect Service;c:program filesVodafoneVodafone Mobile ConnectBinVMCService.exe [04.11.2008 г. 12:39 14336]
R3 Com4QLBEx;Com4QLBEx;c:program filesHewlett-PackardHP Quick Launch ButtonsCom4QLBEx.exe [08.1.2009 г. 18:32 193840]
R3 huawei_enumerator;huawei_enumerator;c:windowssystem32driversew_jubusenum.sys [07.6.2012 г. 00:05 73984]
R3 NETwLx32;   Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit;c:windowssystem32driversNETwLx32.sys [04.12.2012 г. 15:54 6609920]
S2 HWDeviceService.exe;HWDeviceService.exe;c:documents and settingsAll UsersApplication DataDatacardServiceHWDeviceService.exe [14.3.2011 г. 18:27 271712]
S2 M-Tel NETAGENT. RunOuc;M-Tel NETAGENT. OUC;c:program filesM-Tel NETAGENTUpdateDogouc.exe [07.6.2012 г. 00:05 655712]
S2 puougojpk;Update Microsoft;c:windowssystem32svchost.exe -k netsvcs [14.4.2008 г. 11:00 14336]
S2 tjmko;Support Boot;c:windowssystem32svchost.exe -k netsvcs [14.4.2008 г. 11:00 14336]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:windowssystem32driversew_hwusbdev.sys [07.6.2012 г. 00:05 102784]
S3 ew_usbenumfilter;huawei_CompositeFilter;c:windowssystem32driversew_usbenumfilter.sys [07.6.2012 г. 00:05 11136]
S3 ggflt;SEMC USB Flash Driver Filter;c:windowssystem32driversggflt.sys [28.2.2012 г. 23:19 13224]
S3 GGSAFERDriver;GGSAFER Driver;??c:program filesGarena PlusRoomsafedrv.sys --> c:program filesGarena PlusRoomsafedrv.sys [?]
S3 huawei_cdcacm;huawei_cdcacm;c:windowssystem32driversew_jucdcacm.sys [07.6.2012 г. 00:05 89856]
S3 huawei_cdcecm;huawei_cdcecm;c:windowssystem32driversew_jucdcecm.sys [07.6.2012 г. 00:05 66688]
S3 huawei_ext_ctrl;huawei_ext_ctrl;c:windowssystem32driversew_juextctrl.sys [07.6.2012 г. 00:05 26624]
S3 krxaau;krxaau;??c:windowssystem3201.tmp --> c:windowssystem3201.tmp [?]
S3 massfilter;ZTE Mass Storage Filter Driver;c:windowssystem32driversmassfilter.sys [12.2.2011 г. 21:48 7680]
S3 qutmzo;qutmzo;??c:windowssystem3201.tmp --> c:windowssystem3201.tmp [?]
S3 RT-USB;Ross-Tech USB driver;c:windowssystem32driversRT-USB.SYS [16.6.2009 г. 19:12 54176]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:windowssystem32driverss0016bus.sys [22.1.2012 г. 13:40 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:windowssystem32driverss0016mdfl.sys [22.1.2012 г. 13:40 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:windowssystem32driverss0016mdm.sys [22.1.2012 г. 13:40 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:windowssystem32driverss0016mgmt.sys [22.1.2012 г. 13:40 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:windowssystem32driverss0016nd5.sys [22.1.2012 г. 13:40 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:windowssystem32driverss0016obex.sys [22.1.2012 г. 13:40 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:windowssystem32driverss0016unic.sys [22.1.2012 г. 13:40 115752]
S3 s115bus;Sony Ericsson Device 115 driver (WDM);c:windowssystem32driverss115bus.sys [23.4.2007 г. 14:54 83208]
S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;c:windowssystem32driverss115mdfl.sys [23.4.2007 г. 14:54 15112]
S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;c:windowssystem32driverss115mdm.sys [23.4.2007 г. 14:54 108680]
S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);c:windowssystem32driverss115mgmt.sys [23.4.2007 г. 14:54 100488]
S3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;c:windowssystem32driverss115obex.sys [23.4.2007 г. 14:54 98568]
S3 Sony PC Companion;Sony PC Companion;c:program filesSonySony PC CompanionPCCService.exe [22.1.2012 г. 13:39 155320]
S3 ZTEusbnet;ZTE USB-NDIS miniport;c:windowssystem32driversZTEusbnet.sys [12.2.2011 г. 21:49 110080]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - EVERESTDRIVER
*NewlyCreated* - MPKSL749D188D
*NewlyCreated* - MPKSLC0ADE557
*Deregistered* - EverestDriver
*Deregistered* - MpKslc0ade557
.
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionsvchost]
Akamai  REG_MULTI_SZ     Akamai
.
Contents of the 'Scheduled Tasks' folder
.
2013-05-30 c:windowsTasksMP Scheduled Scan.job
- c:program filesMicrosoft Security ClientAntimalwareMpCmdRun.exe [2011-04-27 13:39]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://mystart.incredibar.com/mb201?a=6PQPw9BI28&i=26
uInternet Settings,ProxyOverride = <local>
IE: E&xport to Microsoft Excel - c:progra~1MICROS~2Office12EXCEL.EXE/3000
IE: Е&кспортирай в Microsoft Excel - c:progra~1MICROS~2OFFICE11EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:documents and settingsWORKApplication DataMozillaFirefoxProfilesfp2c9d5o.default
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.bg/firefox
FF - prefs.js: keyword.URL - hxxp://mystart.incredibar.com/mb201/?loc=IB_DS&a=6PQPw9BI28&&i=26&search=
FF - user.js: extensions.incredibar_i.newTab - false
FF - user.js: extensions.incredibar_i.tlbrSrchUrl - hxxp://mystart.Incredibar.com/?a=6PQPw9BI28&loc=IB_TB&i=26&search=
FF - user.js: extensions.incredibar_i.id - 28a2c00e000000000000001cbf7f5177
FF - user.js: extensions.incredibar_i.instlDay - 15656
FF - user.js: extensions.incredibar_i.vrsn - 1.5.11.14
FF - user.js: extensions.incredibar_i.vrsni - 1.5.11.14
FF - user.js: extensions.incredibar_i.vrsnTs - 1.5.11.1419:30
FF - user.js: extensions.incredibar_i.prtnrId - Incredibar
FF - user.js: extensions.incredibar_i.prdct - incredibar
FF - user.js: extensions.incredibar_i.aflt - orgnl
FF - user.js: extensions.incredibar_i.smplGrp - none
FF - user.js: extensions.incredibar_i.tlbrId - base
FF - user.js: extensions.incredibar_i.instlRef -
FF - user.js: extensions.incredibar_i.dfltLng -
FF - user.js: extensions.incredibar_i.excTlbr - false
FF - user.js: extensions.incredibar_i.ms_url_id -
FF - user.js: extensions.incredibar_i.upn2 - 6PQPw9BI28
FF - user.js: extensions.incredibar_i.upn2n - 92543914892173660
FF - user.js: extensions.incredibar_i.productid - 26
FF - user.js: extensions.incredibar_i.installerproductid - 26
FF - user.js: extensions.incredibar_i.did - 10643
FF - user.js: extensions.incredibar_i.ppd - 77777212
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:program filesCommon FilesAheadLibNMBgMonitor.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-05-30 13:48
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...  
.
scanning hidden autostart entries ...
.
scanning hidden files ...  
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINESystemControlSet001ServicesAkamai]
"ServiceDll"="c:program filescommon filesakamai/netsession_win_ca0e279.dll"
.
[HKEY_LOCAL_MACHINESystemControlSet001Serviceskrxaau]
"ImagePath"="??c:windowssystem3201.tmp"
.
[HKEY_LOCAL_MACHINESystemControlSet001Servicesqutmzo]
"ImagePath"="??c:windowssystem3201.tmp"
.
[HKEY_LOCAL_MACHINESystemControlSet001Servicespuougojpk]
"ServiceDll"="c:windowssystem32evunrpzb.dll"
--
.
[HKEY_LOCAL_MACHINESystemControlSet001Servicestjmko]
"ServiceDll"="c:windowssystem32evunrpzb.dll"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERSS-1-5-21-1229272821-1957994488-1801674531-1003SoftwareMicrosoftWindowsCurrentVersionExplorerCLSID]
@Denied: (Full) (LocalSystem)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(660)
c:program filesAlienGUIsefastload.dll
c:windowssystem32igfxdev.dll
.
Completion time: 2013-05-30  13:51:57
ComboFix-quarantined-files.txt  2013-05-30 10:51
.
Pre-Run: 9 109 245 952 bytes free
Post-Run: 9 517 228 032 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)WINDOWS
[operating systems]
c:cmdconsBOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - D111498403FB749F9DE22F0611D2B501
 

Отворете notepad и с copy/paste поставете следната информация:

 

Driver::
puougojpk
tjmko
krxaau
qutmzo
File::
c:windowssystem3201.tmp
c:windowssystem32evunrpzb.dll
Registry::
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileGloballyOpenPortsList]
"1388:TCP"=-
DDS::
uStart Page = hxxp://mystart.incredibar.com/mb201?a=6PQPw9BI28&i=26
Firefox::
FF - ProfilePath - c:documents and settingsWORKApplication DataMozillaFirefoxProfilesfp2c9d5o.default
FF - prefs.js: keyword.URL - hxxp://mystart.incredibar.com/mb201/?loc=IB_DS&a=6PQPw9BI28&&i=26&search=
FF - user.js: extensions.incredibar_i.newTab - false
FF - user.js: extensions.incredibar_i.tlbrSrchUrl - hxxp://mystart.Incredibar.com/?a=6PQPw9BI28&loc=IB_TB&i=26&search=
FF - user.js: extensions.incredibar_i.id - 28a2c00e000000000000001cbf7f5177
FF - user.js: extensions.incredibar_i.instlDay - 15656
FF - user.js: extensions.incredibar_i.vrsn - 1.5.11.14
FF - user.js: extensions.incredibar_i.vrsni - 1.5.11.14
FF - user.js: extensions.incredibar_i.vrsnTs - 1.5.11.1419:30
FF - user.js: extensions.incredibar_i.prtnrId - Incredibar
FF - user.js: extensions.incredibar_i.prdct - incredibar
FF - user.js: extensions.incredibar_i.aflt - orgnl
FF - user.js: extensions.incredibar_i.smplGrp - none
FF - user.js: extensions.incredibar_i.tlbrId - base
FF - user.js: extensions.incredibar_i.instlRef -
FF - user.js: extensions.incredibar_i.dfltLng -
FF - user.js: extensions.incredibar_i.excTlbr - false
FF - user.js: extensions.incredibar_i.ms_url_id -
FF - user.js: extensions.incredibar_i.upn2 - 6PQPw9BI28
FF - user.js: extensions.incredibar_i.upn2n - 92543914892173660
FF - user.js: extensions.incredibar_i.productid - 26
FF - user.js: extensions.incredibar_i.installerproductid - 26
FF - user.js: extensions.incredibar_i.did - 10643
FF - user.js: extensions.incredibar_i.ppd - 77777212

 

Запазете файла с име CFScript и го провлачете и пуснете в Combofix (както на картинката отдолу):

Публикувано изображение

Публикувайте лог файл в следващия си пост.

  • Автор

ComboFix 13-05-30.02 - WORK 05.2013 г.  14:56:43.2.2 - x86

Microsoft Windows XP Professional  5.1.2600.3.1251.359.1033.18.2039.1348 [GMT 3:00]

Running from: d:my documentsDownloadsComboFix.exe

Command switches used :: d:my documentsDownloadsCFScript.txt.txt

AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}

.

FILE ::

"c:windowssystem3201.tmp"

"c:windowssystem32evunrpzb.dll"

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

-------Legacy_PUOUGOJPK

-------Legacy_TJMKO

-------Service_krxaau

-------Service_puougojpk

-------Service_qutmzo

-------Service_tjmko

.

.

((((((((((((((((((((((((( Files Created from 2013-04-28 to 2013-05-30  )))))))))))))))))))))))))))))))

.

.

2013-05-30 10:56 . 2013-05-13 06:19  7016152  ----a-w-  c:documents and settingsAll UsersApplication DataMicrosoftMicrosoft AntimalwareDefinition Updates{11660610-D89A-49E1-A42B-6458D62DA70F}mpengine.dll

2013-05-29 21:40 . 2013-05-29 21:40  --------  d-----w-  c:documents and settingsWORKApplication DataGRETECH

2013-05-29 21:39 . 2013-05-29 21:39  --------  d-----w-  c:program filesGRETECH

2013-05-29 14:21 . 2013-05-29 14:21  --------  d-----w-  c:windowssystem32wbemFramework

2013-05-29 11:40 . 2013-05-29 12:07  --------  d-----w-  c:documents and settingsAll UsersApplication Data28A7B553AD62C00E000028A78CB0C4B2

2013-05-29 11:33 . 2013-05-29 11:33  --------  d-----w-  c:documents and settingsAll UsersApplication DataHewlett-Packard

2013-05-29 11:32 . 2013-05-29 11:32  --------  d-----w-  c:documents and settingsLocalServiceApplication DatahpqLog

2013-05-29 11:32 . 2013-05-29 11:32  --------  d-----w-  c:documents and settingsWORKApplication DatahpqLog

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2013-05-29 09:40 . 2013-04-13 19:56  692104  ----a-w-  c:windowssystem32FlashPlayerApp.exe

2013-05-29 09:40 . 2011-12-14 07:12  71048  ----a-w-  c:windowssystem32FlashPlayerCPLApp.cpl

2013-05-13 06:19 . 2011-11-10 09:05  7016152  ----a-w-  c:documents and settingsAll UsersApplication DataMicrosoftMicrosoft AntimalwareDefinition UpdatesBackupmpengine.dll

2013-05-02 15:28 . 2011-11-08 20:17  238872  ------w-  c:windowssystem32MpSigStub.exe

2013-04-07 08:52 . 2012-11-12 17:30  27136  ----a-w-  c:windowssystem32ImHttpComm.dll

2013-04-04 11:50 . 2011-03-17 13:30  22856  ----a-w-  c:windowssystem32driversmbam.sys

.

.

------- Sigcheck -------

Note: Unsigned files aren't necessarily malware.

.

[-] 2008-07-12 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:windowssystem32sfcfiles.dll

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]

"mRouterConfig"="c:program filesIntuwaveSharedmRouterRuntimemRouterConfig.exe" [2006-03-02 290816]

"DAEMON Tools Lite"="c:program filesDAEMON Tools Litedaemon.exe" [2008-08-08 490952]

"Akamai NetSession Interface"="c:documents and settingsWORKLocal SettingsApplication DataAkamainetsession_win.exe" [2013-01-26 4480768]

.

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]

"IgfxTray"="c:windowssystem32igfxtray.exe" [2007-09-18 141848]

"HotKeysCmds"="c:windowssystem32hkcmd.exe" [2007-09-18 166424]

"Persistence"="c:windowssystem32igfxpers.exe" [2007-09-18 137752]

"SynTPEnh"="c:program filesSynapticsSynTPSynTPEnh.exe" [2008-01-18 1028096]

"QlbCtrl.exe"="c:program filesHewlett-PackardHP Quick Launch ButtonsQlbCtrl.exe" [2008-06-03 177456]

"GrooveMonitor"="c:program filesMicrosoft OfficeOffice12GrooveMonitor.exe" [2007-08-24 33648]

"PC Suite for Smartphones"="c:program filesSony EricssonMobile4Application LauncherApplication Launcher.exe" [2006-04-25 487424]

"QuickTime Task"="c:program filesQuickTimeqttask.exe" [2009-01-26 155648]

"IME JPN 2007 Migration"="c:progra~1COMMON~1MICROS~1IME12IMEJPIMJPKLMG.EXE" [2006-10-26 59184]

"Korean IME Migration"="c:progra~1COMMON~1MICROS~1IME12IMEKRIMKRMIG.EXE" [2006-10-26 26400]

"Microsoft Pinyin IME Migration"="c:progra~1COMMON~1MICROS~1IME12IMESCIMSCMIG.EXE" [2006-10-26 32560]

"MobileConnect"="c:program filesVodafoneVodafone Mobile ConnectBinMobileConnect.exe" [2008-11-04 2087424]

"SunJavaUpdateSched"="c:program filesCommon FilesJavaJava Updatejusched.exe" [2011-06-09 254696]

"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]

"MSC"="c:program filesMicrosoft Security Clientmsseces.exe" [2011-06-15 997920]

"Hard Disk Sentinel"="c:program filesHard Disk SentinelHDSentinel.exe" [2011-12-21 4060160]

"Bonus.SSR.FR10"="c:program filesABBYY FineReader 10Bonus.ScreenshotReader.exe" [2011-06-08 941320]

.

[HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRun]

"CTFMON.EXE"="c:windowssystem32CTFMON.EXE" [2008-04-14 15360]

"DWQueuedReporting"="c:progra~1COMMON~1MICROS~1DWdwtrig20.exe" [2007-08-24 437160]

.

[HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRunOnce]

"nltide_2"="shell32" [X]

.

c:documents and settingsWORKStart MenuProgramsStartup

OneNote 2007 Screen Clipper and Launcher.lnk - c:program filesMicrosoft OfficeOffice12ONENOTEM.EXE [2009-2-26 97680]

.

c:documents and settingsAll UsersStart MenuProgramsStartup

Acrobat Assistant.lnk - c:program filesAdobeAcrobat 6.0Distillracrotray.exe [2003-5-15 217193]

.

[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionwinlogonnotifyWB]

2001-12-20 19:34  24576  ----a-w-  c:program filesAlienGUIsefastload.dll

.

[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionwindows]

"AppInit_DLLs"=c:windowssystem32wbsys.dll

.

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalMsMpSvc]

@="Service"

.

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalWdf01000.sys]

@="Driver"

.

[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]

"%windir%Network Diagnosticxpnetdiag.exe"=

"%windir%system32sessmgr.exe"=

"c:Program FilesMicrosoft OfficeOffice12OUTLOOK.EXE"=

"c:Program FilesMicrosoft OfficeOffice12GROOVE.EXE"=

"c:Program FilesMicrosoft OfficeOffice12ONENOTE.EXE"=

"c:Program FilesIntuwaveSharedmRouterRuntimemRouterRuntime.exe"=

"c:Program FilesSony EricssonMobile4Sync ManagerDXP SyncML.exe"=

"c:Program FilesuTorrentuTorrent.exe"=

"d:Age of EmpiresEMPIRES2.ICD"=

"c:WINDOWSsystem32dplaysvr.exe"=

"c:Documents and SettingsWORKDesktopDiablo IIGame.exe"=

"c:Documents and SettingsWORKApplication DataGameRangerGameRangerGameRanger.exe"=

"d:Yu-Gi-Oh! Power of Chaos Commonkfjadsjoey_pc.exe"=

"c:WINDOWSsystem32dpnsvr.exe"=

"d:StrongholdStronghold Crusader.exe"=

"c:Documents and SettingsWORKLocal SettingsApplication DataAkamainetsession_win.exe"=

"d:Warcraft IIIWar3.exe"=

"d:Warcraft IIIWarcraft III.exe"=

"c:Program FilesValveCounter-Strike 1.6 Sector Editioncstrike.exe"=

"c:WINDOWSsystem32ARFCwrtc.exe"=

"c:Program FilesValveCounter-Strike 1.6 Sector Editionhl.exe"=

"c:Program FilesIP-TV PlayerIpTvPlayer.exe"=

"c:Program FilesSkypePhoneSkype.exe"=

.

[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileGloballyOpenPortsList]

"1046:TCP"= 1046:TCP:Akamai NetSession Interface

"5000:UDP"= 5000:UDP:Akamai NetSession Interface

.

R0 sptd;sptd;c:windowssystem32driverssptd.sys [13.2.2009 г. 22:55 717296]

R2 Akamai;Akamai NetSession Interface;c:windowsSystem32svchost.exe -k Akamai [14.4.2008 г. 11:00 14336]

R2 HWDeviceService.exe;HWDeviceService.exe;c:documents and settingsAll UsersApplication DataDatacardServiceHWDeviceService.exe [14.3.2011 г. 18:27 271712]

R2 VMCService;Vodafone Mobile Connect Service;c:program filesVodafoneVodafone Mobile ConnectBinVMCService.exe [04.11.2008 г. 12:39 14336]

R3 Com4QLBEx;Com4QLBEx;c:program filesHewlett-PackardHP Quick Launch ButtonsCom4QLBEx.exe [08.1.2009 г. 18:32 193840]

R3 huawei_enumerator;huawei_enumerator;c:windowssystem32driversew_jubusenum.sys [07.6.2012 г. 00:05 73984]

R3 NETwLx32;   Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit;c:windowssystem32driversNETwLx32.sys [04.12.2012 г. 15:54 6609920]

S1 MpKsl431d3c5f;MpKsl431d3c5f;??c:documents and settingsAll UsersApplication DataMicrosoftMicrosoft AntimalwareDefinition Updates{11660610-D89A-49E1-A42B-6458D62DA70F}MpKsl431d3c5f.sys --> c:documents and settingsAll UsersApplication DataMicrosoftMicrosoft AntimalwareDefinition Updates{11660610-D89A-49E1-A42B-6458D62DA70F}MpKsl431d3c5f.sys [?]

S2 M-Tel NETAGENT. RunOuc;M-Tel NETAGENT. OUC;c:program filesM-Tel NETAGENTUpdateDogouc.exe [07.6.2012 г. 00:05 655712]

S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:windowssystem32driversew_hwusbdev.sys [07.6.2012 г. 00:05 102784]

S3 ew_usbenumfilter;huawei_CompositeFilter;c:windowssystem32driversew_usbenumfilter.sys [07.6.2012 г. 00:05 11136]

S3 ggflt;SEMC USB Flash Driver Filter;c:windowssystem32driversggflt.sys [28.2.2012 г. 23:19 13224]

S3 GGSAFERDriver;GGSAFER Driver;??c:program filesGarena PlusRoomsafedrv.sys --> c:program filesGarena PlusRoomsafedrv.sys [?]

S3 huawei_cdcacm;huawei_cdcacm;c:windowssystem32driversew_jucdcacm.sys [07.6.2012 г. 00:05 89856]

S3 huawei_cdcecm;huawei_cdcecm;c:windowssystem32driversew_jucdcecm.sys [07.6.2012 г. 00:05 66688]

S3 huawei_ext_ctrl;huawei_ext_ctrl;c:windowssystem32driversew_juextctrl.sys [07.6.2012 г. 00:05 26624]

S3 massfilter;ZTE Mass Storage Filter Driver;c:windowssystem32driversmassfilter.sys [12.2.2011 г. 21:48 7680]

S3 RT-USB;Ross-Tech USB driver;c:windowssystem32driversRT-USB.SYS [16.6.2009 г. 19:12 54176]

S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:windowssystem32driverss0016bus.sys [22.1.2012 г. 13:40 89256]

S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:windowssystem32driverss0016mdfl.sys [22.1.2012 г. 13:40 15016]

S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:windowssystem32driverss0016mdm.sys [22.1.2012 г. 13:40 120744]

S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:windowssystem32driverss0016mgmt.sys [22.1.2012 г. 13:40 114216]

S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:windowssystem32driverss0016nd5.sys [22.1.2012 г. 13:40 25512]

S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:windowssystem32driverss0016obex.sys [22.1.2012 г. 13:40 110632]

S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:windowssystem32driverss0016unic.sys [22.1.2012 г. 13:40 115752]

S3 s115bus;Sony Ericsson Device 115 driver (WDM);c:windowssystem32driverss115bus.sys [23.4.2007 г. 14:54 83208]

S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;c:windowssystem32driverss115mdfl.sys [23.4.2007 г. 14:54 15112]

S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;c:windowssystem32driverss115mdm.sys [23.4.2007 г. 14:54 108680]

S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);c:windowssystem32driverss115mgmt.sys [23.4.2007 г. 14:54 100488]

S3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;c:windowssystem32driverss115obex.sys [23.4.2007 г. 14:54 98568]

S3 Sony PC Companion;Sony PC Companion;c:program filesSonySony PC CompanionPCCService.exe [22.1.2012 г. 13:39 155320]

S3 ZTEusbnet;ZTE USB-NDIS miniport;c:windowssystem32driversZTEusbnet.sys [12.2.2011 г. 21:49 110080]

.

[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionsvchost]

Akamai  REG_MULTI_SZ     Akamai

.

Contents of the 'Scheduled Tasks' folder

.

2013-05-30 c:windowsTasksMP Scheduled Scan.job

- c:program filesMicrosoft Security ClientAntimalwareMpCmdRun.exe [2011-04-27 13:39]

.

.

------- Supplementary Scan -------

.

uInternet Settings,ProxyOverride = <local>

IE: E&xport to Microsoft Excel - c:progra~1MICROS~2Office12EXCEL.EXE/3000

IE: Е&кспортирай в Microsoft Excel - c:progra~1MICROS~2OFFICE11EXCEL.EXE/3000

TCP: DhcpNameServer = 192.168.0.1

FF - ProfilePath - c:documents and settingsWORKApplication DataMozillaFirefoxProfilesfp2c9d5o.default

FF - prefs.js: browser.search.selectedEngine - Google

FF - prefs.js: browser.startup.homepage - hxxp://www.google.bg/firefox

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2013-05-30 15:06

Windows 5.1.2600 Service Pack 3 NTFS

.

scanning hidden processes ...  

.

scanning hidden autostart entries ...

.

scanning hidden files ...  

.

scan completed successfully

hidden files: 0

.

**************************************************************************

.

[HKEY_LOCAL_MACHINESystemControlSet001ServicesAkamai]

"ServiceDll"="c:program filescommon filesakamai/netsession_win_ca0e279.dll"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_USERSS-1-5-21-1229272821-1957994488-1801674531-1003SoftwareMicrosoftWindowsCurrentVersionExplorerCLSID]

@Denied: (Full) (LocalSystem)

.

--------------------- DLLs Loaded Under Running Processes ---------------------

.

- - - - - - - > 'winlogon.exe'(664)

c:program filesAlienGUIsefastload.dll

.

- - - - - - - > 'explorer.exe'(3776)

c:windowssystem32WININET.dll

c:windowssystem32ieframe.dll

c:windowssystem32wpdshserviceobj.dll

c:windowssystem32portabledevicetypes.dll

c:windowssystem32portabledeviceapi.dll

.

------------------------ Other Running Processes ------------------------

.

c:program filesMicrosoft Security ClientAntimalwareMsMpEng.exe

c:program filesJavajre6binjqs.exe

c:documents and settingsAll UsersApplication DataM-Tel NETAGENTOnlineUpdateouc.exe

c:program filesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE

c:windowssystem32wscntfy.exe

c:windowssystem32igfxsrvc.exe

c:program filesCommon FilesTeleca SharedCapabilityManager.exe

c:windowssystem32rundll32.exe

c:program filesIntuwaveSharedmRouterRuntimemRouterRuntime.exe

c:program filesHewlett-PackardSharedhpqwmiex.exe

c:program filesCommon FilesTeleca SharedGeneric.exe

c:progra~1SymbianSharedSYMBIA~1SYMBIA~1.EXE

c:progra~1SymbianSharedSYMBIA~1SCBAL.exe

.

**************************************************************************

.

Completion time: 2013-05-30  15:11:24 - machine was rebooted

ComboFix-quarantined-files.txt  2013-05-30 12:11

ComboFix2.txt  2013-05-30 10:51

.

Pre-Run: 9 754 058 752 bytes free

Post-Run: 9 634 623 488 bytes free

.

- - End Of File - - 77D3C506D1DF1FFFE2D57D4D281A4581

 

 

  • Автор

Да вече всико си е както трябва. Благодаря Ви!

Но проблема със захранването  остана и предполагам че е зарядното, понеже не винаги се зарежда както трябва или само се зарежда като  го оставя на  Stand By или го изключа.

Супер...сега малко по-превенцията:

 

СТЪПКА 1 - Спрете Autorun функцията.

Изтеглете и стартирайте следния файл Публикувано изображение
Стартирайте го и се съгласете с лицензионното споразумение.
Натиснете Next и изчакайте да си свърпи работата.
Рестартирайте системата ако се наложи.

Отворете и настройките на мрежовата карта и премахнете отметката пред File and Printer Sharing for Microsoft Networks, Client for Microsoft Networks и Qos Packet Scheduler и потвърдете с ОК.

Публикувано изображение



СТЪПКА 2


Добре е да инсталирате всички актуализации за Windows. особено следните 3 кръпки: KB958687, KB957097, KB958644.

След инсталирането им рестартирайте компютъра.



СТЪПКА 3


Изтеглете и разархивирайте следния файл - KidoKiller на десктопа.
Копирайте файла kk.exe в C:
Отворете Start => Run => въведете CMD => натиснете Enter
В конзолата въведете командата:

cd c:

Натиснете Enter

След това въведете:

kk.exe -f -n -y -l report.txt

Натиснете Enter

Публикувано изображение

Ще се генерира текст файл с името report.txt в C:

Копирайте съдържанието на лог файла в следващия си пост.



СТЪПКА 4

Изтеглете Security Check от screen317 от този линк или и го запаметете на вашия десктоп.

  • [*]Кликнете два пъти върху
SecurityCheck.exe и следвайте инструкциите. [*]Накрая, автоматично ще се отвори текстов документ, наречен checkup.txt, моля поставете съдържанието му в следващия Ви коментар в тази тема. [*]Направете и нова проверка с DDS и прикачете двата файла които ще се създадат.

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.