Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Компютъра ми забива, и работи отчайващо бавно...

Featured Replies

Здравейте отново, този път става въпрос за служебния компютър /стара машинка/. Работи много бавно, блокирани страници доста често. Знам, че има някакъв проблем, но какъв точно не ми е ясно. Разчитам с ваша помощ поне малко да го посъживим.

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.IF REQUESTED, ZIP IT UP & ATTACH IT.DDS (Ver_2011-09-30.01).Microsoft Windows XP ProfessionalBoot Device: DeviceHarddiskVolume1Install Date: 7/27/2008 3:28:55 PMSystem Uptime: 11/27/2013 8:03:07 AM (2 hours ago).Motherboard: Gigabyte Technology Co., Ltd. |  | 8I845GVMRZProcessor: Intel® Celeron® CPU 1.70GHz | Socket 478 | 1716/100mhz.==== Disk Partitions =========================.A: is RemovableC: is FIXED (NTFS) - 75 GiB total, 62.996 GiB free.D: is CDROM ()E: is CDROM ()N: is NetworkDisk (NTFS) - 194 GiB total, 98.003 GiB free..==== Disabled Device Manager Items =============.Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}Description: Multimedia Audio ControllerDevice ID: PCIVEN_8086&DEV_24C5&SUBSYS_A0021458&REV_023&13C0B0C5&0&FDManufacturer:Name: Multimedia Audio ControllerPNP Device ID: PCIVEN_8086&DEV_24C5&SUBSYS_A0021458&REV_023&13C0B0C5&0&FDService:.Class GUID: {50906CB8-BA12-11D1-BF5D-0000F805F530}Description:Device ID: ROOTMULTIPORTSERIAL0000Manufacturer:Name:PNP Device ID: ROOTMULTIPORTSERIAL0000Service:.==== System Restore Points ===================.RP1222: 11/18/2013 11:21:51 AM - Контролна точка на систематаRP1223: 11/19/2013 11:56:03 AM - Контролна точка на систематаRP1224: 11/20/2013 12:07:11 PM - Контролна точка на систематаRP1225: 11/21/2013 12:24:54 PM - Контролна точка на систематаRP1226: 11/22/2013 12:59:12 PM - Контролна точка на систематаRP1227: 11/25/2013 10:36:58 AM - Контролна точка на систематаRP1228: 11/26/2013 12:25:47 PM - Контролна точка на системата.==== Installed Programs ======================.ЗБУТ+ (Версия 2.11)Adobe Flash Player 11 ActiveXAdobe Flash Player 11 PluginAdobe Reader X (10.1.8)Avira Free AntivirusFar ManagerGoogle Toolbar for Internet ExplorerGoogle Update HelperHigh Definition Audio Driver Package - KB835221Hotfix for Windows Media Format 11 SDK (KB929399)Hotfix for Windows Media Player 11 (KB939683)Hotfix for Windows XP (KB952287)Hotfix for Windows XP (KB976002-v5)Intel® Extreme Graphics DriverMalwarebytes Anti-Malware, версия 1.75.0.1300Microsoft Base Smart Card Cryptographic Service Provider PackageMicrosoft Compression Client Pack 1.0 for Windows XPMicrosoft Internationalized Domain Names Mitigation APIsMicrosoft National Language Support Downlevel APIsMicrosoft Office Professional Edition 2003Microsoft User-Mode Driver Framework Feature Pack 1.0Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219Mozilla Firefox 25.0.1 (x86 bg)Mozilla Maintenance ServiceMSXML 4.0 SP2 (KB954430)MSXML 4.0 SP2 (KB973688)Pervasive System AnalyzerSecurity Update for Microsoft Windows (KB2564958)Security Update for Windows Internet Explorer 7 (KB2870699)Security Update for Windows Media Player (KB2378111)Security Update for Windows Media Player (KB2834904-v2)Security Update for Windows Media Player (KB952069)Security Update for Windows Media Player (KB954155)Security Update for Windows Media Player (KB973540)Security Update for Windows Media Player (KB975558)Security Update for Windows Media Player (KB978695)Security Update for Windows Media Player 11 (KB954154)Security Update for Windows XP (KB2115168)Security Update for Windows XP (KB2229593)Security Update for Windows XP (KB2296011)Security Update for Windows XP (KB2347290)Security Update for Windows XP (KB2387149)Security Update for Windows XP (KB2393802)Security Update for Windows XP (KB2419632)Security Update for Windows XP (KB2423089)Security Update for Windows XP (KB2440591)Security Update for Windows XP (KB2443105)Security Update for Windows XP (KB2478960)Security Update for Windows XP (KB2478971)Security Update for Windows XP (KB2479943)Security Update for Windows XP (KB2481109)Security Update for Windows XP (KB2483185)Security Update for Windows XP (KB2485663)Security Update for Windows XP (KB2506212)Security Update for Windows XP (KB2507938)Security Update for Windows XP (KB2508429)Security Update for Windows XP (KB2509553)Security Update for Windows XP (KB2510581)Security Update for Windows XP (KB2535512)Security Update for Windows XP (KB2536276-v2)Security Update for Windows XP (KB2544893-v2)Security Update for Windows XP (KB2566454)Security Update for Windows XP (KB2570947)Security Update for Windows XP (KB2584146)Security Update for Windows XP (KB2585542)Security Update for Windows XP (KB2592799)Security Update for Windows XP (KB2598479)Security Update for Windows XP (KB2603381)Security Update for Windows XP (KB2618451)Security Update for Windows XP (KB2619339)Security Update for Windows XP (KB2620712)Security Update for Windows XP (KB2631813)Security Update for Windows XP (KB2653956)Security Update for Windows XP (KB2655992)Security Update for Windows XP (KB2659262)Security Update for Windows XP (KB2661637)Security Update for Windows XP (KB2676562)Security Update for Windows XP (KB2686509)Security Update for Windows XP (KB2691442)Security Update for Windows XP (KB2698365)Security Update for Windows XP (KB2705219-v2)Security Update for Windows XP (KB2712808)Security Update for Windows XP (KB2719985)Security Update for Windows XP (KB2723135-v2)Security Update for Windows XP (KB2727528)Security Update for Windows XP (KB2753842-v2)Security Update for Windows XP (KB2757638)Security Update for Windows XP (KB2758857)Security Update for Windows XP (KB2770660)Security Update for Windows XP (KB2780091)Security Update for Windows XP (KB2802968)Security Update for Windows XP (KB2807986)Security Update for Windows XP (KB2813345)Security Update for Windows XP (KB2820197)Security Update for Windows XP (KB2820917)Security Update for Windows XP (KB2834886)Security Update for Windows XP (KB2845187)Security Update for Windows XP (KB2849470)Security Update for Windows XP (KB2850869)Security Update for Windows XP (KB2859537)Security Update for Windows XP (KB2864063)Security Update for Windows XP (KB2876217)Security Update for Windows XP (KB2876315)Security Update for Windows XP (KB923561)Security Update for Windows XP (KB941569)Security Update for Windows XP (KB946648)Security Update for Windows XP (KB950760)Security Update for Windows XP (KB950762)Security Update for Windows XP (KB950974)Security Update for Windows XP (KB951376-v2)Security Update for Windows XP (KB951698)Security Update for Windows XP (KB952004)Security Update for Windows XP (KB952954)Security Update for Windows XP (KB956572)Security Update for Windows XP (KB956802)Security Update for Windows XP (KB956844)Security Update for Windows XP (KB959426)Security Update for Windows XP (KB960803)Security Update for Windows XP (KB960859)Security Update for Windows XP (KB969059)Security Update for Windows XP (KB971657)Security Update for Windows XP (KB972270)Security Update for Windows XP (KB973507)Security Update for Windows XP (KB973869)Security Update for Windows XP (KB973904)Security Update for Windows XP (KB974112)Security Update for Windows XP (KB974318)Security Update for Windows XP (KB974392)Security Update for Windows XP (KB974571)Security Update for Windows XP (KB975025)Security Update for Windows XP (KB975560)Security Update for Windows XP (KB975713)Security Update for Windows XP (KB977816)Security Update for Windows XP (KB977914)Security Update for Windows XP (KB978338)Security Update for Windows XP (KB978542)Security Update for Windows XP (KB978706)Security Update for Windows XP (KB979309)Security Update for Windows XP (KB979482)Security Update for Windows XP (KB979687)Security Update for Windows XP (KB981997)Security Update for Windows XP (KB982132)Security Update for Windows XP (KB982665)Skype™ 6.0Update for Microsoft Windows (KB971513)Update for Windows XP (KB2492386)Update for Windows XP (KB2749655)Update for Windows XP (KB2808679)Update for Windows XP (KB2863058)Update for Windows XP (KB898461)Update for Windows XP (KB942763)Update for Windows XP (KB951978)Update for Windows XP (KB968389)Update for Windows XP (KB971029)Update for Windows XP (KB973815)WebFldrs XPWindows Internet Explorer 7Windows Internet Explorer 7 Language Interface Pack (BGR)Windows Media Format 11 runtimeWindows Media Player 11Xerox Phaser 3124Yahoo! Toolbar.==== Event Viewer Messages From Past Week ========.11/26/2013 8:24:07 AM, error: Service Control Manager [7031]  - The Avira Real-Time Protection service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 0 milliseconds: Restart the service.11/26/2013 8:24:05 AM, error: Service Control Manager [7006]  - The ScRegSetValueExW call failed for FailureActions with the following error:  Access is denied.11/21/2013 7:55:09 AM, error: Service Control Manager [7000]  - The SecureUpdate service failed to start due to the following error:  The system cannot find the file specified..==== End Of File ===========================Internet Explorer: 7.0.5730.13Run by Administrator at 10:14:27 on 2013-11-27Microsoft Windows XP Professional  5.1.2600.3.1251.359.1033.18.247.28 [GMT 2:00].AV: Avira Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}.============== Running Processes ================.C:WINDOWSsystem32spoolsv.exeC:Program FilesAviraAntiVir Desktopsched.exeC:Program FilesAviraAntiVir Desktopavguard.exeC:WINDOWSExplorer.EXEC:WINDOWSXeroxPanelMgrSSMMgr.exeC:WINDOWSsystem32igfxtray.exeC:WINDOWSsystem32hkcmd.exeC:Program FilesAviraAntiVir Desktopavgnt.exeC:WINDOWSsystem32ctfmon.exeC:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exeC:Program FilesAviraAntiVir Desktopavshadow.exeC:Program FilesAviraAntiVir DesktopAVWEBGRD.EXEC:Program FilesMozilla Firefoxfirefox.exeC:Program FilesMicrosoft OfficeOFFICE11WINWORD.EXEC:Program FilesMozilla Firefoxplugin-container.exeC:WINDOWSsystem32wbemwmiprvse.exeC:WINDOWSSystem32svchost.exe -k netsvcsC:WINDOWSsystem32svchost.exe -k NetworkServiceC:WINDOWSsystem32svchost.exe -k LocalService.============== Pseudo HJT Report ===============.uStart Page = hxxp://www.google.comuProxyServer = :0BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:program filesgooglegoogle toolbarGoogleToolbar_32.dllBHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:program filesgooglegoogletoolbarnotifier5.7.9012.1008swg.dllBHO: SingleInstance Class: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - c:program filesyahoo!companioninstallscpnYTSingleInstance.dllTB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:program filesgooglegoogle toolbarGoogleToolbar_32.dllTB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:program filesgooglegoogle toolbarGoogleToolbar_32.dlluRun: [CTFMON.EXE] c:windowssystem32ctfmon.exeuRun: [swg] "c:program filesgooglegoogletoolbarnotifierGoogleToolbarNotifier.exe"mRun: [Xerox PanelMgr] c:windowsxeroxpanelmgrSSMMgr.exe /autorunmRun: [igfxTray] c:windowssystem32igfxtray.exemRun: [HotKeysCmds] c:windowssystem32hkcmd.exemRun: [Adobe ARM] "c:program filescommon filesadobearm1.0AdobeARM.exe"mRun: [avgnt] "c:program filesaviraantivir desktopavgnt.exe" /mindRun: [CTFMON.EXE] c:windowssystem32CTFMON.EXEStartupFolder: c:docume~1admini~1startm~1programsstartuplogon~1.lnk - c:logon.batuPolicies-Explorer: NoDriveTypeAutoRun = dword:145mPolicies-System: EnableLUA = dword:0mPolicies-Explorer: NoDriveTypeAutoRun = dword:145IE: E&xport to Microsoft Excel - c:progra~1micros~2office11EXCEL.EXE/3000IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%Network Diagnosticxpnetdiag.exeIE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:program filesmessengermsmsgs.exeLSP: c:program filesaviraantivir desktopavsda.dll.INFO: HKCU has more than 50 listed domains.If you wish to scan all of them, select the 'Force scan all domains' option...INFO: HKLM has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option..DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabDPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cabTCP: Interfaces{CADD7416-CDF9-4569-8EF7-BF724102282C} : NameServer = 192.168.1.1Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:program filesskypetoolbarsinternet explorerskypeieplugin.dllHandler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:program filescommon filesskypeSkype4COM.dllNotify: igfxcui - igfxsrvc.dllNotify: winwrv32 - winwrv32.dllSSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:windowssystem32WPDShServiceObj.dll.================= FIREFOX ===================.FF - ProfilePath - c:documents and settingsadministratorapplication datamozillafirefoxprofilesh9uxtbey.defaultFF - prefs.js: browser.search.selectedEngine - Ask.comFF - prefs.js: browser.startup.homepage - hxxps://www.google.bg/FF - prefs.js: network.proxy.type - 0FF - plugin: c:program filesadobereader 10.0readerairnppdf32.dllFF - plugin: c:program filesgoogleupdate1.3.21.165npGoogleUpdate3.dllFF - plugin: c:windowssystem32macromedflashNPSWF32_11_9_900_117.dll.============= SERVICES / DRIVERS ===============.R1 avkmgr;avkmgr;c:windowssystem32driversavkmgr.sys [2013-5-29 37352]R2 AntiVirSchedulerService;Avira Scheduler;c:program filesaviraantivir desktopsched.exe [2013-5-29 440376]R2 AntiVirService;Avira Real-Time Protection;c:program filesaviraantivir desktopavguard.exe [2013-5-29 440376]R2 AntiVirWebService;Avira Web Protection;c:program filesaviraantivir desktopavwebgrd.exe [2013-5-29 1164360]R2 avgntflt;avgntflt;c:windowssystem32driversavgntflt.sys [2013-5-29 90400]S2 gupdate;Google Update Service (gupdate);c:program filesgoogleupdateGoogleUpdate.exe [2010-9-10 136176]S2 SecureUpdateSvc;SecureUpdate;c:program filessecure speed dialiesecureupdate.exe --> c:program filessecure speed dialieSecureUpdate.exe [?]S2 SkypeUpdate;Skype Updater;c:program filesskypeupdaterUpdater.exe [2012-11-9 160944]S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:windowssystem32macromedflashFlashPlayerUpdateService.exe [2012-8-17 257416]S3 AVPsys;AVPsys;??c:windowssystem32driverscdaudio.sys --> c:windowssystem32driverscdaudio.sys [?]S3 dac970nt;dac970nt;??c:windowssystem32driversvlsknl.sys --> c:windowssystem32driversvlsknl.sys [?]S3 DIGIRPS;Digi PortServer Driver;c:windowssystem32driversdigirlpt.sys [2012-6-4 42432]S3 gupdatem;Google Update Service (gupdatem);c:program filesgoogleupdateGoogleUpdate.exe [2010-9-10 136176]S3 MozillaMaintenance;Mozilla Maintenance Service;c:program filesmozilla maintenance servicemaintenanceservice.exe [2012-9-6 119408].=============== Created Last 30 ================..==================== Find3M  ====================.2013-11-19 12:23:41  90400  ----a-w-  c:windowssystem32driversavgntflt.sys2013-11-19 12:23:41  37352  ----a-w-  c:windowssystem32driversavkmgr.sys2013-10-28 06:02:56  356556  ----a-w-  c:windowssystem32PerfStringBackup.TMP2013-10-10 06:39:11  692616  ----a-w-  c:windowssystem32FlashPlayerApp.exe2013-10-10 06:39:08  71048  ----a-w-  c:windowssystem32FlashPlayerCPLApp.cpl.============= FINISH: 10:15:28.40 ===============

 

 

 

И това съобщение се появява отскоро, защо ?

zaet sarvar.ppt

Редактирано от icotonev (преглед на промените)

Здравейте..!Страхувам се че системата ви е заразена ..! Но да ме бързаме със заключенията..!

 

Проверете на VirusTotal следните файлове:  

 

c:windowssystem32driversvlsknl.sys

c:windowssystem32driverscdaudio.sys

Публикувайте линкове към резултатите в следващия си пост..!

  • Автор
Извинете за това , че не разбирам, но какво точно трябва от горната стъпка ?

Извинете,но тук няма какво толкова да разбираш....!Просто следвайте инструкцията,нямам идея как по проста да я напиша..! ;)

  • Автор

Копирам и пействам файла, обаче ми изписва, че няма такъв намерен.

влизаш в VirusTotal,цъкаш на "избери",намираш файла vlsknl.sys,open,изчакваш да ти го провери и постваш линка към резултата.така и с другия файл.

  • Автор

Направих каквото трябва, но ми дава съобщение, че файла не е намерен, проверете името на фйла. То действително няма какво да се обърка обаче не се получава.

Редактирано от denito_vikito (преглед на промените)

Добрее..! Оставете тази стъпка..Да се надяваме че следващите инструкции няма да ви затруднят..!
 
Изтеглете SalityKiller и го запазете на десктопа.
Изключете интернет достъпа и след това сканирайте с него по описания по-надолу начин:

  • [*]Изтеглете
SalityKiller Версия 1.3.6.0 и запазете инструмента на десктопа. [*]Отворете Start => Run в полето въведете CMD => натиснете Enter => след това  с copy/paste копирайте командата и я поставете в черния прозорец на CMD с десен бутон на мишката => paste "%userprofile%desktopsalitykiller.exe" -n -r -x -a -j -k -l c:report.txt [*]Изчакайте проверката да завърши. [*]След като тя приключи, публикувайте съдържанието на лог файла C:report.txt в следващия си пост.

Забележка: Има вероятност вируса да не ви позволи да изтеглите и стартирате инструмента SalityKiller..Поради това ви прикачам програмата чрез форумната система:
 

  • Автор

14:40:50:750 3632  scanning  threads ...14:41:00:171 3632  14:41:00:187 3632  scanning  processes ...14:41:01:546 3632  14:41:01:546 3632  removing autorun.inf files ...14:41:12:343 3632  14:41:12:359 3632  Restoring show hidden and system files14:41:12:359 3780  Monitoring thread started14:41:12:671 3632  14:41:12:671 3632  Disabling autorun on all drive types14:41:14:250 3632  14:41:14:296 3632  restoring SafeBoot registry node14:41:14:296 3632  Restoring safe/network boot registry branches for windows XP14:41:16:703 3632  14:41:16:703 3632  fixing  registry ...14:41:16:796 3632  SalityRegCure: Restoring general registry keys14:41:16:890 3632  SalityRegCure: Fixing system.ini14:41:16:890 3632  14:41:16:890 3632  scanning  drives ...14:41:16:890 3632  scanning  C: ...15:11:39:140 3632  15:11:39:156 3780  Monitoring thread stopped15:11:39:250 3632  completed15:11:39:250 3632  Infected files:      015:11:39:250 3632  Infected processes:    015:11:39:265 3632  Infected threads:    015:11:39:265 3632  Cured files:      015:11:39:265 3632  Will be cured on reboot:  015:11:39:265 3632  Executed registry scripts:  11

Добре..! :)
 
Публикувано изображение Изтеглете Malwarebytes' Anti-Malware или от тук (не забравяйте да обновите програмата с нови дефиниции)
* Кликнете два пъти върху mbam-setup.exe, за да инсталирате програмата.
* Уверете се, че са поставени отметки на Update Malwarebytes' Anti-Malware и Launch Malwarebytes' Anti-Malware. След това кликнете на Finish.
* Ако има намерени обновявания, тя ще ги изтегли и инсталира.
* Стартирайте програмата и изберете "Perform Full Scan", след това кликнете на Scan.
* Сканирането ще отнеме малко време, затова моля да бъдете търпеливи.
* Когато сканирането завърши, кликнете на OK, след това Show Results, за да видите резултата
* Уверете се, че на всички редове има отметки, и кликнете на Remove Selected.
* Когато всичко бъде премахнато, в Notepad ще бъде отворен лог.
Копирайте този лог и го публикувайте в следващия си коментар по темата.
Забележка: Ако MalwareBytes' Anti-Malware се затрудни в премахването на откритите вируси/заплахи, той ще поиска да рестартира компютъра Ви и по време на рестартирането да премахне проблемните вируси/заплахи. Ако бъдете попитани, потвърдете че желаете вашия компютър да бъде рестартиран


Публикувано изображение

  • [*]Моля изтеглете
Farbar Recovery Scan Tool и го запазете на десктопа. [*]Стартирайте файла FRST.exe. [*]Програмата ще се стартира. Натиснете YES за да се съгласите с лицензионното споразумение. [*]Сложете всички отметки. [*]Натиснете бутона SCAN. [*]Ще се създадат два лог файл с името - FRST.txt и Addition.txt на десктопа. [*]Файлът FRST.txt копирайте в следващия си пост. Addition.txt прикачете в следващия си коментар (погледнете опцията Прикачени файлове, когато публикувате мнение).

Изтеглете прикачения файл и го запазете там, където сте свалили FRST.exe => Стартирайте отново FRST.exe и натиснете бутона Fix веднъж и изчакайте.Ще се създаде нов лог файла FixLog.txt. Прикачете съдържанието му в следващия си коментар.

  • Автор

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 27-11-2013 01Ran by Administrator at 2013-11-29 10:01:56 Run:1Running from C:Documents and SettingsAdministratorDesktopBoot Mode: Normal==============================================Content of fixlist:*****************startHKLM...Run: [] - [x]SearchScopes: HKLM - DefaultScope value is missing.DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cabDPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cabFF SearchEngineOrder.1: Ask.comFF SelectedSearchEngine: Ask.comS2 SecureUpdateSvc; C:Program FilesSecure Speed DialIESecureUpdate.exe [x]C:Program FilesSecure Speed DialIESecureUpdate.exeU3 a2p7rb7t; C:WindowsSystem32Driversa2p7rb7t.sys [0 ] (Microsoft Corporation)C:WindowsSystem32Driversa2p7rb7t.sysend*****************HKLMSoftwareMicrosoftWindowsCurrentVersionRun => Value deleted successfully.HKLMSOFTWAREMicrosoftInternet ExplorerSearchScopesDefaultScope => Value was restored successfully.HKLMSOFTWAREMicrosoftCode Store DatabaseDistribution Units{D27CDB6E-AE6D-11CF-96B8-444553540000} => Key deleted successfully.HKCRCLSID{D27CDB6E-AE6D-11CF-96B8-444553540000} => Key not found.HKLMSOFTWAREMicrosoftCode Store DatabaseDistribution Units{E2883E8F-472F-4FB0-9522-AC9BF37916A7} => Key deleted successfully.HKCRCLSID{E2883E8F-472F-4FB0-9522-AC9BF37916A7} => Key deleted successfully.Firefox SearchEngineOrder.1 deleted successfully.Firefox SelectedSearchEngine deleted successfully.SecureUpdateSvc => Service deleted successfully."C:Program FilesSecure Speed DialIESecureUpdate.exe" => File/Directory not found.a2p7rb7t => Service not found."C:WindowsSystem32Driversa2p7rb7t.sys" => File/Directory not found. 

След процедурите до тук, как е положението..? Наблюдавате ли промени от първоначалното състояние на системата ви..?

  • Автор

За съжаление, нещата не са се променили. Дори преди един час се опитах да публиувам коментар, но не се получи, почна да зарежда и до безкрай. Дава ми Сървърът не е намерен, опита пак. За да зареди някой сайт пробвам по 5-6 пъти.

Публикувано изображение

  • [*]Отворете
следния сайт и изтеглете RKill.exe и ги запазете на вашия десктоп. [*]Стартирате програмата с двоен клик върху файла и изчакайте търпеливо. [*]След приключване на проверката ще се генерира лог файл с извършените процедури. [*]Прикачете лог файла в следващия си пост.

 

Публикувано изображение Изтеглете ComboFix Публикувано изображение от тук и го запазете на десктопа си
Изключете вашата антивирусна и антишпионска програма, обикновено това става чрез натискане на десния бутон на мишката върху иконата на програма в системния трей.
Бележка: Ако не можете я спрете или не сте сигурни коя програма да изключите, моля прегледайте информацията от този линк: How to disable your security applications by amateur
Стартирайте Combo-Fix.com Публикувано изображение и следвайте инструкциите.
Бележка: ComboFix ще се стартира без инсталирана Recovery Console.
Като част от неговата работа, ComboFix ще провери дали Microsoft Windows Recovery Console е инсталирана. Предвид бързо развиващия се зловреден софтуер е силно препоръчително да бъде инсталирана преди премахването на зловредния софтуер. Това ще Ви позволи да влезете в специален recovery/repai режим, който ще ни позволи по-лесно да решите проблем, който би могъл да възникне при премахване на зловредния софтуер.

  • [*]Следвайте инструкциите, за да позволите на
ComboFix да изтегли и инсталира Microsoft Windows Recovery Console.В един момент ще бъдете попитани дали сте съгласни с лицензното споразумение. Необходимо е да потвърдите, че сте съгласни, за да инсталирате Microsoft Windows Recovery Console.

** Забележете: Ако Microsoft Windows Recovery Console е вече инсталирана, ComboFix ще продължи към процеса по премахване на зловредния софтуер.
Публикувано изображение
След като Microsoft Windows Recovery Console е инсталирана, използвайки ComboFix, Вие ще видите следното съобщение:
Публикувано изображение
Изберете Yes, за да продължи сканирането за зловреден софтуер.
Когато процесът приключи успешно, инструментът ще създаде лог файл. Моля, включете съдържанието на C:ComboFix.txt в следващия Ви коментар в тази тема.
Публикувано изображение Моля, не прикачвайте лог файла/овете от програмата, а го/ги копирайте и поставете в следващия Ви коментар в тази тема.
 
 
 
Публикувано изображение Моля, изтеглете Farbar Service Scanner и я стартирайте.

  • [*]Сложете
всички отметки и натиснете бутона "Scan". [*]Ще се създаде лог файл с името (FSS.txt) в папката откъдето стартирате инструмента. [*]Прикачете лог файла в следващия си пост.

 

Публикувано изображение

  • [*]Изтеглете
MiniToolBox.exe и го запазете на десктопа. [*]Сложете всички отметки и натиснете Go. [*]Прикачете лог файла Result.txt в следващия си пост.

  • Автор

Само да попитам, пуснах програмата ComboFix  в продължение на 3часа сканира, и все още не беше приключила, но аз я спрях, защото трябваше да се ходя от работа. Нормално ли е толкова време да сканира  или нещо е забила ? Утре ще я пусна пак. Сега на дом компютър за 15мин беше готова.

 

  • Автор

Здравей, лог от ComboFix  не мога да дам, защото програмата сканира цяла нощ повече от 12часа и нищо. Стои на едно положение и незнам защо така.

 

 

MiniToolBox by Farbar  Version: 13-07-2013Ran by Administrator (administrator) on 03-12-2013 at 08:49:26Running from "C:Documents and SettingsAdministratorDesktop"Microsoft Windows XP Professional Service Pack 3 (X86)Boot Mode: Normal***************************************************************************========================= Flush DNS: ===================================Windows IP ConfigurationSuccessfully flushed the DNS Resolver Cache.========================= IE Proxy Settings: ==============================Proxy is not enabled.ProxyServer: :0"Reset IE Proxy Settings": IE Proxy Settings were reset.========================= FF Proxy Settings: =============================="network.proxy.type", 0"Reset FF Proxy Settings": Firefox Proxy settings were reset.========================= Hosts content: =================================127.0.0.1 localhost========================= IP Configuration: ================================Realtek RTL8139 Family PCI Fast Ethernet NIC = Local Area Connection (Connected)# ----------------------------------# Interface IP Configuration    # ----------------------------------pushd interface ip# Interface IP Configuration for "Local Area Connection"set address name="Local Area Connection" source=static addr=192.168.1.34 mask=255.255.255.0set address name="Local Area Connection" gateway=192.168.1.1 gwmetric=0set dns name="Local Area Connection" source=static addr=192.168.1.1 register=PRIMARYset wins name="Local Area Connection" source=static addr=nonepopd# End of interface IP configurationWindows IP Configuration   Host Name . . . . . . . . . . . . : MAGI   Primary Dns Suffix  . . . . . . . :   Node Type . . . . . . . . . . . . : Unknown   IP Routing Enabled. . . . . . . . : No   WINS Proxy Enabled. . . . . . . . : NoEthernet adapter Local Area Connection:   Connection-specific DNS Suffix  . :   Description . . . . . . . . . . . : Realtek RTL8139 Family PCI Fast Ethernet NIC   Physical Address. . . . . . . . . : 00-0D-61-80-1C-A0   Dhcp Enabled. . . . . . . . . . . : No   IP Address. . . . . . . . . . . . : 192.168.1.34   Subnet Mask . . . . . . . . . . . : 255.255.255.0   Default Gateway . . . . . . . . . : 192.168.1.1   DNS Servers . . . . . . . . . . . : 192.168.1.1Server:  adslrouter.btc-adslAddress:  192.168.1.1Name:   google.comAddress:  173.194.39.231Pinging google.com [173.194.39.231] with 32 bytes of data:Reply from 173.194.39.231: bytes=32 time=24ms TTL=58Reply from 173.194.39.231: bytes=32 time=24ms TTL=58Ping statistics for 173.194.39.231:   Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),Approximate round trip times in milli-seconds:   Minimum = 24ms, Maximum = 24ms, Average = 24msServer:  adslrouter.btc-adslAddress:  192.168.1.1Name:   yahoo.comAddress:  206.190.36.45Pinging yahoo.com [206.190.36.45] with 32 bytes of data:Reply from 206.190.36.45: bytes=32 time=309ms TTL=47Reply from 206.190.36.45: bytes=32 time=228ms TTL=47Ping statistics for 206.190.36.45:   Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),Approximate round trip times in milli-seconds:   Minimum = 228ms, Maximum = 309ms, Average = 268msPinging 127.0.0.1 with 32 bytes of data:Reply from 127.0.0.1: bytes=32 time<1ms TTL=64Reply from 127.0.0.1: bytes=32 time<1ms TTL=64Ping statistics for 127.0.0.1:   Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),Approximate round trip times in milli-seconds:   Minimum = 0ms, Maximum = 0ms, Average = 0ms===========================================================================Interface List0x1 ........................... MS TCP Loopback interface0x2 ...00 0d 61 80 1c a0 ...... Realtek RTL8139 Family PCI Fast Ethernet NIC - Packet Scheduler Miniport======================================================================================================================================================Active Routes:Network Destination   Netmask   Gateway Interface  Metric   0.0.0.0   0.0.0.0   192.168.1.1   192.168.1.34 20   127.0.0.0   255.0.0.0   127.0.0.1 127.0.0.1 1   192.168.1.0   255.255.255.0 192.168.1.34   192.168.1.34 20 192.168.1.34  255.255.255.255   127.0.0.1 127.0.0.1 20   192.168.1.255  255.255.255.255 192.168.1.34   192.168.1.34 20   224.0.0.0   240.0.0.0 192.168.1.34   192.168.1.34 20  255.255.255.255  255.255.255.255 192.168.1.34   192.168.1.34 1Default Gateway: 192.168.1.1===========================================================================Persistent Routes:  None========================= Winsock entries =====================================Catalog5 01 C:WINDOWSsystem32mswsock.dll [245248] (Microsoft Corporation)Catalog5 02 C:WINDOWSsystem32winrnr.dll [16896] (Microsoft Corporation)Catalog5 03 C:WINDOWSsystem32mswsock.dll [245248] (Microsoft Corporation)Catalog9 01 C:Program FilesAviraAntiVir Desktopavsda.dll [257608] (Avira Operations GmbH & Co. KG)Catalog9 02 C:Program FilesAviraAntiVir Desktopavsda.dll [257608] (Avira Operations GmbH & Co. KG)Catalog9 03 C:WINDOWSsystem32mswsock.dll [245248] (Microsoft Corporation)Catalog9 04 C:WINDOWSsystem32mswsock.dll [245248] (Microsoft Corporation)Catalog9 05 C:WINDOWSsystem32mswsock.dll [245248] (Microsoft Corporation)Catalog9 06 C:WINDOWSsystem32rsvpsp.dll [92672] (Microsoft Corporation)Catalog9 07 C:WINDOWSsystem32rsvpsp.dll [92672] (Microsoft Corporation)Catalog9 08 C:WINDOWSsystem32mswsock.dll [245248] (Microsoft Corporation)Catalog9 09 C:WINDOWSsystem32mswsock.dll [245248] (Microsoft Corporation)Catalog9 10 C:WINDOWSsystem32mswsock.dll [245248] (Microsoft Corporation)Catalog9 11 C:WINDOWSsystem32mswsock.dll [245248] (Microsoft Corporation)Catalog9 12 C:WINDOWSsystem32mswsock.dll [245248] (Microsoft Corporation)Catalog9 13 C:WINDOWSsystem32mswsock.dll [245248] (Microsoft Corporation)Catalog9 14 C:Program FilesAviraAntiVir Desktopavsda.dll [257608] (Avira Operations GmbH & Co. KG)========================= Event log errors: ===============================Application errors:==================Error: (12/02/2013 07:11:18 PM) (Source: Application Error) (User: )Description: Faulting application ipmgui.exe, version 14.0.1.641, faulting module mfc100u.dll, version 10.0.40219.1, fault address 0x001ebd1a.Processing media-specific event for [ipmgui.exe!ws!]Error: (12/02/2013 08:28:43 AM) (Source: MSDTC) (User: )Description: MS DTC Tracing infrastructure : the initialization of the tracing infrastructure failed. Internal Information : msdtc_trace : File: d:comxp_sp3comcom1xdtcdtctracesrctracelib.cpp, Line: 1115, StartTrace Failed, hr=0x800700a1.Error: (11/26/2013 10:06:21 AM) (Source: Userenv) (User: NT AUTHORITY)Description: Windows завърши обработването на GPO, защото компютърът се е изключил или потребителят е излязъл.Error: (11/19/2013 08:14:03 AM) (Source: Application Error) (User: )Description: Faulting application avnotify.exe, version 13.6.20.2100, faulting module avnotify.exe, version 13.6.20.2100, fault address 0x00001487.Processing media-specific event for [avnotify.exe!ws!]Error: (11/18/2013 08:35:05 AM) (Source: MSDTC) (User: )Description: MS DTC Tracing infrastructure : the initialization of the tracing infrastructure failed. Internal Information : msdtc_trace : File: d:comxp_sp3comcom1xdtcdtctracesrctracelib.cpp, Line: 1115, StartTrace Failed, hr=0x800700a1.Error: (11/11/2013 08:32:41 AM) (Source: MSDTC) (User: )Description: MS DTC Tracing infrastructure : the initialization of the tracing infrastructure failed. Internal Information : msdtc_trace : File: d:comxp_sp3comcom1xdtcdtctracesrctracelib.cpp, Line: 1115, StartTrace Failed, hr=0x800700a1.Error: (11/11/2013 08:04:10 AM) (Source: Application Error) (User: )Description: Faulting application avnotify.exe, version 13.6.20.2100, faulting module avnotify.exe, version 13.6.20.2100, fault address 0x00001487.Processing media-specific event for [avnotify.exe!ws!]Error: (11/08/2013 01:40:20 PM) (Source: SkypeUpdate) (User: )Description: File C:WINDOWSTEMPSKY6C.tmp has invalid signature.Error: (11/04/2013 08:17:36 AM) (Source: Application Error) (User: )Description: Faulting application avnotify.exe, version 13.6.20.2100, faulting module avnotify.exe, version 13.6.20.2100, fault address 0x00001487.Processing media-specific event for [avnotify.exe!ws!]Error: (10/28/2013 08:02:56 AM) (Source: LoadPerf) (User: )Description: Installing the performance counter strings for service WmiApRpl (%2) failed. TheError code is the first DWORD in Data section.System errors:=============Error: (12/03/2013 08:22:02 AM) (Source: Service Control Manager) (User: )Description: The Avira Web Protection service depends on the Avira Real-Time Protection service which failed to start because of the following error:%%1070Error: (12/03/2013 08:22:01 AM) (Source: Service Control Manager) (User: )Description: The Avira Real-Time Protection service hung on starting.Error: (12/02/2013 03:17:44 PM) (Source: Service Control Manager) (User: )Description: The Avira Web Protection service depends on the Avira Real-Time Protection service which failed to start because of the following error:%%1070Error: (12/02/2013 03:17:44 PM) (Source: Service Control Manager) (User: )Description: The Avira Real-Time Protection service hung on starting.Error: (11/29/2013 08:07:54 AM) (Source: Service Control Manager) (User: )Description: The SecureUpdate service failed to start due to the following error:%%2Error: (11/28/2013 01:52:03 PM) (Source: Service Control Manager) (User: )Description: The SecureUpdate service failed to start due to the following error:%%2Error: (11/28/2013 07:58:24 AM) (Source: Service Control Manager) (User: )Description: The SecureUpdate service failed to start due to the following error:%%2Error: (11/27/2013 08:03:41 AM) (Source: Service Control Manager) (User: )Description: The SecureUpdate service failed to start due to the following error:%%2Error: (11/26/2013 10:07:21 AM) (Source: Service Control Manager) (User: )Description: The SecureUpdate service failed to start due to the following error:%%2Error: (11/26/2013 08:24:07 AM) (Source: Service Control Manager) (User: )Description: The Avira Real-Time Protection service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 0 milliseconds: Restart the service.Microsoft Office Sessions:=========================Error: (12/02/2013 07:11:18 PM) (Source: Application Error)(User: )Description: ipmgui.exe14.0.1.641mfc100u.dll10.0.40219.1001ebd1aError: (12/02/2013 08:28:43 AM) (Source: MSDTC)(User: )Description: msdtc_trace : File: d:comxp_sp3comcom1xdtcdtctracesrctracelib.cpp, Line: 1115, StartTrace Failed, hr=0x800700a1Error: (11/26/2013 10:06:21 AM) (Source: Userenv)(User: NT AUTHORITY)Description:Error: (11/19/2013 08:14:03 AM) (Source: Application Error)(User: )Description: avnotify.exe13.6.20.2100avnotify.exe13.6.20.210000001487Error: (11/18/2013 08:35:05 AM) (Source: MSDTC)(User: )Description: msdtc_trace : File: d:comxp_sp3comcom1xdtcdtctracesrctracelib.cpp, Line: 1115, StartTrace Failed, hr=0x800700a1Error: (11/11/2013 08:32:41 AM) (Source: MSDTC)(User: )Description: msdtc_trace : File: d:comxp_sp3comcom1xdtcdtctracesrctracelib.cpp, Line: 1115, StartTrace Failed, hr=0x800700a1Error: (11/11/2013 08:04:10 AM) (Source: Application Error)(User: )Description: avnotify.exe13.6.20.2100avnotify.exe13.6.20.210000001487Error: (11/08/2013 01:40:20 PM) (Source: SkypeUpdate)(User: )Description: C:WINDOWSTEMPSKY6C.tmpError: (11/04/2013 08:17:36 AM) (Source: Application Error)(User: )Description: avnotify.exe13.6.20.2100avnotify.exe13.6.20.210000001487Error: (10/28/2013 08:02:56 AM) (Source: LoadPerf)(User: )Description: WmiApRpl=========================== Installed Programs ============================Adobe Flash Player 11 ActiveX (Version: 11.9.900.117)Adobe Flash Player 11 Plugin (Version: 11.9.900.117)Adobe Reader X (10.1.8) (Version: 10.1.8)Avira Free Antivirus (Version: 14.0.1.749)Far Manager (Version: 1.75.2631)Google Toolbar for Internet Explorer (Version: 1.0.0)Google Toolbar for Internet Explorer (Version: 7.5.4601.54)Google Update Helper (Version: 1.3.21.165)High Definition Audio Driver Package - KB835221 (Version: 20040219.000000)Intel® Extreme Graphics DriverMalwarebytes Anti-Malware, версия 1.75.0.1300 (Version: 1.75.0.1300)Microsoft Base Smart Card Cryptographic Service Provider PackageMicrosoft Compression Client Pack 1.0 for Windows XP (Version: 1)Microsoft Internationalized Domain Names Mitigation APIsMicrosoft National Language Support Downlevel APIsMicrosoft Office Professional Edition 2003 (Version: 11.0.5614.0)Microsoft User-Mode Driver Framework Feature Pack 1.0Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (Version: 10.0.40219)Mozilla Firefox 25.0.1 (x86 bg) (Version: 25.0.1)Mozilla Maintenance Service (Version: 25.0.1)MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)Pervasive System AnalyzerSkype™ 6.0 (Version: 6.0.126)Update for Microsoft Windows (KB971513)Update for Windows XP (KB2492386) (Version: 1)Update for Windows XP (KB2749655) (Version: 1)Update for Windows XP (KB2808679) (Version: 1)Update for Windows XP (KB2863058) (Version: 1)Update for Windows XP (KB898461) (Version: 1)Update for Windows XP (KB942763) (Version: 1)Update for Windows XP (KB951978) (Version: 1)Update for Windows XP (KB968389) (Version: 1)Update for Windows XP (KB971029) (Version: 1)Update for Windows XP (KB973815) (Version: 1)WebFldrs XP (Version: 9.50.7523)Windows Internet Explorer 7 (Version: 20070813.185237)Windows Internet Explorer 7 Language Interface Pack (BGR) (Version: 20071019.120000)Windows Media Format 11 runtimeWindows Media Player 11Xerox Phaser 3124Yahoo! ToolbarЗБУТ+ (Версия 2.11) (Version: 2.11)========================= Devices: ================================Name: Multimedia Audio ControllerDescription: Multimedia Audio ControllerClass Guid: {4D36E97E-E325-11CE-BFC1-08002BE10318}Manufacturer:Service:Problem: : The drivers for this device are not installed. (Code 28)Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.Name:Description:Class Guid: {50906CB8-BA12-11D1-BF5D-0000F805F530}Manufacturer:Service:Problem: : The drivers for this device are not installed. (Code 28)Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.========================= Memory info: ===================================Percentage of memory in use: 47%Total physical RAM: 247.48 MBAvailable physical RAM: 131.1 MBTotal Pagefile: 933.98 MBAvailable Pagefile: 501.63 MBTotal Virtual: 2047.88 MBAvailable Virtual: 1973.58 MB========================= Partitions: =====================================2 Drive c: () (Fixed) (Total:74.52 GB) (Free:62.47 GB) NTFS5 Drive n: (DATA) (Network) (Total:193.82 GB) (Free:97.9 GB) NTFS========================= Users: ========================================User accounts for MAGIAdministrator   Guest   HelpAssistant  SUPPORT_388945a0    ========================= Minidump Files ==================================No minidump file found========================= Restore Points ==================================18-11-2013 09:21:51 Контролна точка на системата19-11-2013 09:56:03 Контролна точка на системата20-11-2013 10:07:11 Контролна точка на системата21-11-2013 10:24:54 Контролна точка на системата22-11-2013 10:59:12 Контролна точка на системата25-11-2013 08:36:58 Контролна точка на системата26-11-2013 10:25:47 Контролна точка на системата27-11-2013 11:20:22 Контролна точка на системата29-11-2013 10:28:29 Контролна точка на системата02-12-2013 07:47:50 ComboFix created restore point**** End of log ****Farbar Service Scanner Version: 23-11-2013Ran by Administrator (administrator) on 03-12-2013 at 08:47:48Running from "C:Documents and SettingsAdministratorDesktop"Microsoft Windows XP Professional Service Pack 3 (X86)Boot Mode: Normal****************************************************************Internet Services:============Connection Status:==============Localhost is accessible.LAN connected.Google IP is accessible.Google.com is accessible.Yahoo.com is accessible.Windows Firewall:=============Firewall Disabled Policy:==================System Restore:============System Restore Disabled Policy:========================Security Center:============Windows Update:============Windows Autoupdate Disabled Policy:============================Other Services:==============File Check:========C:WINDOWSsystem32dhcpcsvc.dll => MD5 is legitC:WINDOWSsystem32Driversafd.sys => MD5 is legitC:WINDOWSsystem32Driversnetbt.sys => MD5 is legitC:WINDOWSsystem32Driverstcpip.sys => MD5 is legitC:WINDOWSsystem32Driversipsec.sys => MD5 is legitC:WINDOWSsystem32dnsrslvr.dll => MD5 is legitC:WINDOWSsystem32ipnathlp.dll => MD5 is legitC:WINDOWSsystem32netman.dll => MD5 is legitC:WINDOWSsystem32wbemWMIsvc.dll => MD5 is legitC:WINDOWSsystem32srsvc.dll => MD5 is legitC:WINDOWSsystem32Driverssr.sys => MD5 is legitC:WINDOWSsystem32wscsvc.dll => MD5 is legitC:WINDOWSsystem32wbemWMIsvc.dll => MD5 is legitC:WINDOWSsystem32wuauserv.dll => MD5 is legitC:WINDOWSsystem32qmgr.dll => MD5 is legitC:WINDOWSsystem32es.dll => MD5 is legitC:WINDOWSsystem32cryptsvc.dll => MD5 is legitC:WINDOWSsystem32svchost.exe => MD5 is legitC:WINDOWSsystem32rpcss.dll => MD5 is legitC:WINDOWSsystem32services.exe => MD5 is legitExtra List:=======Gpc(6) IPSec(4) NetBT(5) PSched(7) Tcpip(3)0x0700000004000000010000000200000003000000050000000600000007000000IpSec Tag value is correct.**** End of log ****

Ето снощи я оставих в това положение и след 12 часа я намерих пак така.

windows.ppt

Редактирано от denito_vikito (преглед на промените)

От дневниците не виждам притеснителни неща от зловреден характер..!
 
Деинсталирайте ComboFix така:

  • [*]Натиснете Start ==> Run ==> въведете командата
Combofix /Uninstall ==> OK

  • [*]Публикувано изображение

  • [*]Моля, следвайте инструкциите, за да деинсталирате ComboFix. Ще получите съобщение, в което се казва ComboFix е деинсталиран успешно.

Публикувано изображениеИзтеглете OTL.exe и го запазете на десктопа

  • [*]Стартирайте
OTL.exe. [*]Направете следните настройки: [*]Сложете отметка пред Scan All Users [*]Под менюто File Age изберете 90 days [*]Под менюто Standard Registry променете на ALL [*]Сложете отметки пред LOP и Purity Check [*]Под Публикувано изображение с Copy/ Paste въведете изцяло следната текстова информация (само това, което е поставено в карето):

netsvcs%SYSTEMDRIVE%*.exe/md5startexplorer.exewinlogon.exeUserinit.exesvchost.exeservices.exe/md5stop%systemroot%*. /rp /s%systemdrive%$Recycle.Bin|@;true;true;true /fpDRIVESCREATERESTOREPOINT
[*]Натиснете маркираният в синьо бутон: Run Scan. [*]Като приключи проверката, ще се създадат два файла - OTL.Txt и Extras.Txt. Файлът OTL.Txt копирайте в следващия си пост. Extras.Txt прикачете в следващия си коментар (погледнете опцията Прикачени файлове, когато публикувате мнение).

  • Автор

OTL logfile created on: 12/3/2013 10:05:32 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:Documents and SettingsAdministratorDesktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
247.48 Mb Total Physical Memory | 26.84 Mb Available Physical Memory | 10.85% Memory free
769.32 Mb Paging File | 121.15 Mb Available in Paging File | 15.75% Paging File free
Paging file location(s): C:pagefile.sys 372 744 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:WINDOWS | %ProgramFiles% = C:Program Files
Drive C: | 74.52 Gb Total Space | 63.13 Gb Free Space | 84.71% Space Free | Partition Type: NTFS
Drive N: | 193.82 Gb Total Space | 97.90 Gb Free Space | 50.51% Space Free | Partition Type: NTFS
 
Computer Name: MAGI | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 90 Days
 
========== Processes (SafeList) ==========
 
PRC - [2013/12/03 09:58:52 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:Documents and SettingsAdministratorDesktopOTL.exe
PRC - [2013/11/19 14:23:38 | 000,440,376 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:Program FilesAviraAntiVir Desktopsched.exe
PRC - [2013/11/19 14:23:19 | 001,164,360 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:Program FilesAviraAntiVir Desktopavwebgrd.exe
PRC - [2013/11/19 14:23:17 | 000,431,672 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:Program FilesAviraAntiVir Desktopavshadow.exe
PRC - [2013/11/19 14:23:13 | 000,440,376 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:Program FilesAviraAntiVir Desktopavguard.exe
PRC - [2013/11/19 14:23:12 | 000,683,576 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:Program FilesAviraAntiVir Desktopavgnt.exe
PRC - [2013/11/13 05:39:05 | 000,275,568 | ---- | M] (Mozilla Corporation) -- C:Program FilesMozilla Firefoxfirefox.exe
PRC - [2008/04/14 04:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:WINDOWSexplorer.exe
PRC - [2006/12/01 13:13:20 | 000,520,192 | ---- | M] () -- C:WINDOWSXeroxPanelMgrSSMMgr.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2013/11/13 05:39:45 | 003,363,952 | ---- | M] () -- C:Program FilesMozilla Firefoxmozjs.dll
MOD - [2013/10/10 08:39:05 | 016,233,864 | ---- | M] () -- C:WINDOWSsystem32MacromedFlashNPSWF32_11_9_900_117.dll
MOD - [2013/08/15 16:31:14 | 000,268,968 | ---- | M] () -- C:WINDOWSsystem32sqlite3.dll
MOD - [2013/05/29 07:58:07 | 000,397,704 | ---- | M] () -- C:Program FilesAviraAntiVir Desktopsqlite3.dll
MOD - [2006/12/01 13:13:20 | 000,520,192 | ---- | M] () -- C:WINDOWSXeroxPanelMgrSSMMgr.exe
 
 
========== Services (SafeList) ==========
 
SRV - File not found [Disabled | Stopped] -- %SystemRoot%System32hidserv.dll -- (HidServ)
SRV - [2013/11/19 14:23:38 | 000,440,376 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:Program FilesAviraAntiVir Desktopsched.exe -- (AntiVirSchedulerService)
SRV - [2013/11/19 14:23:19 | 001,164,360 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:Program FilesAviraAntiVir Desktopavwebgrd.exe -- (AntiVirWebService)
SRV - [2013/11/19 14:23:13 | 000,440,376 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:Program FilesAviraAntiVir Desktopavguard.exe -- (AntiVirService)
SRV - [2013/11/18 10:24:05 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:Program FilesMozilla Maintenance Servicemaintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/10/10 08:40:28 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:WINDOWSsystem32MacromedFlashFlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/11/09 11:12:16 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:Program FilesSkypeUpdaterUpdater.exe -- (SkypeUpdate)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] --  -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] --  -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] --  -- (i2omgmt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32driversDMusic.sys -- (DMusic)
DRV - File not found [Kernel | System | Stopped] --  -- (Changer)
DRV - File not found [Kernel | System | Stopped] --  -- (Cdaudio)
DRV - File not found [Kernel | On_Demand | Unknown] --  -- (awvhlniq)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:WINDOWSsystem32driverscdaudio.sys -- (AVPsys)
DRV - [2013/11/19 14:23:41 | 000,137,208 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:WINDOWSsystem32driversavipbb.sys -- (avipbb)
DRV - [2013/11/19 14:23:41 | 000,090,400 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:WINDOWSsystem32driversavgntflt.sys -- (avgntflt)
DRV - [2013/11/19 14:23:41 | 000,037,352 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:WINDOWSsystem32driversavkmgr.sys -- (avkmgr)
DRV - [2013/05/29 07:58:19 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:WINDOWSsystem32driversssmdrv.sys -- (ssmdrv)
DRV - [2008/07/27 15:13:39 | 000,717,296 | ---- | M] () [Kernel | Boot | Running] -- C:WINDOWSsystem32driverssptd.sys -- (sptd)
DRV - [2008/04/14 02:15:30 | 000,010,624 | -H-- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:WINDOWSsystem32driversgameenum.sys -- (gameenum)
DRV - [2008/04/14 00:05:40 | 000,020,992 | -H-- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:WINDOWSsystem32driversRTL8139.sys -- (rtl8139)
DRV - [2004/08/11 08:39:38 | 000,041,984 | ---- | M] (Samsung Electronics Co., Ltd.) [Kernel | Auto | Running] -- C:WINDOWSsystem32driversDGIVECP.SYS -- (DgiVecp)
DRV - [2001/08/17 11:17:44 | 000,042,432 | ---- | M] (Digi International, Inc.) [Kernel | On_Demand | Stopped] -- C:WINDOWSsystem32driversdigirlpt.sys -- (DIGIRPS)
 
 
========== Standard Registry (All) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Default_Secondary_Page_URL =  [binary data]
IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Extensions Off Page = about:NoAdd-ons
IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Local Page = %SystemRoot%system32blank.htm
IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Security Risk Page = about:SecurityRisk
IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLMSOFTWAREMicrosoftInternet ExplorerSearch,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLMSOFTWAREMicrosoftInternet ExplorerSearch,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKLM..SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM..SearchScopes{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM..SearchScopes{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
 
 
IE - HKU.DEFAULT..SearchScopes,DefaultScope =
IE - HKU.DEFAULTSoftwareMicrosoftWindowsCurrentVersionInternet Settings: "ProxyEnable" = 0
 
IE - HKUS-1-5-18..SearchScopes,DefaultScope =
IE - HKUS-1-5-18SoftwareMicrosoftWindowsCurrentVersionInternet Settings: "ProxyEnable" = 0
 
IE - HKUS-1-5-19..SearchScopes,DefaultScope =
 
IE - HKUS-1-5-20..SearchScopes,DefaultScope =
 
IE - HKUS-1-5-21-796845957-823518204-842925246-500SOFTWAREMicrosoftInternet ExplorerMain,Local Page = C:WINDOWSsystem32blank.htm
IE - HKUS-1-5-21-796845957-823518204-842925246-500SOFTWAREMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKUS-1-5-21-796845957-823518204-842925246-500SOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://www.google.com
IE - HKUS-1-5-21-796845957-823518204-842925246-500..URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:WINDOWSsystem32ieframe.dll (Microsoft Corporation)
IE - HKUS-1-5-21-796845957-823518204-842925246-500..SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKUS-1-5-21-796845957-823518204-842925246-500..SearchScopes{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search
IE - HKUS-1-5-21-796845957-823518204-842925246-500..SearchScopes{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.bg/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7SKPT_bgBG396
IE - HKUS-1-5-21-796845957-823518204-842925246-500SoftwareMicrosoftWindowsCurrentVersionInternet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.startup.homepage: "https://www.google.bg/"
FF - prefs.js..extensions.enabledAddons: speeddial%40instair.net:1.3.1
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:25.0.1
FF - user.js - File not found
 
FF - [email protected]/FlashPlayer: C:WINDOWSsystem32MacromedFlashNPSWF32_11_9_900_117.dll ()
FF - [email protected]/Google Update;version=3: C:Program FilesGoogleUpdate1.3.21.165npGoogleUpdate3.dll (Google Inc.)
FF - [email protected]/Google Update;version=9: C:Program FilesGoogleUpdate1.3.21.165npGoogleUpdate3.dll (Google Inc.)
FF - HKLMSoftwareMozillaPluginsAdobe Reader: C:Program FilesAdobeReader 10.0ReaderAIRnppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINEsoftwaremozillaMozilla Firefox 25.0.1extensionsComponents: C:Program FilesMozilla Firefoxcomponents
FF - HKEY_LOCAL_MACHINEsoftwaremozillaMozilla Firefox 25.0.1extensionsPlugins: C:Program FilesMozilla Firefoxplugins
 
[2011/10/07 12:10:50 | 000,000,000 | ---D | M] (No name found) -- C:Documents and SettingsAdministratorApplication DataMozillaExtensions
[2013/10/21 07:34:54 | 000,000,000 | ---D | M] (No name found) -- C:Documents and SettingsAdministratorApplication DataMozillaFirefoxProfilesh9uxtbey.defaultextensions
[2013/09/04 13:12:47 | 000,000,000 | ---D | M] (AccelerateTab) -- C:Documents and SettingsAdministratorApplication DataMozillaFirefoxProfilesh9uxtbey.defaultextensionsspeeddial@instair.net
[2013/11/18 10:23:32 | 000,000,000 | ---D | M] (No name found) -- C:Program FilesMozilla Firefoxbrowserextensions
[2013/11/28 16:35:32 | 000,000,000 | ---D | M] (Default) -- C:Program FilesMozilla Firefoxbrowserextensions{972ce4c6-7e08-4474-a285-3208198ce6fd}
 
O1 HOSTS File: ([2001/08/23 11:00:00 | 000,000,734 | ---- | M]) - C:WINDOWSsystem32driversetchosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:Program FilesGoogleGoogleToolbarNotifier5.7.9012.1008swg.dll (Google Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:Program FilesYahoo!CompanionInstallscpnYTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM..Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll (Google Inc.)
O3 - HKUS-1-5-21-796845957-823518204-842925246-500..ToolbarShellBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:WINDOWSsystem32browseui.dll (Microsoft Corporation)
O3 - HKUS-1-5-21-796845957-823518204-842925246-500..ToolbarShellBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:WINDOWSsystem32shell32.dll (Microsoft Corporation)
O3 - HKUS-1-5-21-796845957-823518204-842925246-500..ToolbarWebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..Run: [Adobe ARM] C:Program FilesCommon FilesAdobeARM1.0AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..Run: [avgnt] C:Program FilesAviraAntiVir Desktopavgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..Run: [HotKeysCmds] C:WINDOWSsystem32hkcmd.exe (Intel Corporation)
O4 - HKLM..Run: [igfxTray] C:WINDOWSsystem32igfxtray.exe (Intel Corporation)
O4 - HKLM..Run: [Xerox PanelMgr] C:WINDOWSXeroxPanelMgrSSMMgr.exe ()
O4 - HKU.DEFAULT..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe (Microsoft Corporation)
O4 - HKUS-1-5-18..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe (Microsoft Corporation)
O4 - HKUS-1-5-21-796845957-823518204-842925246-500..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe (Microsoft Corporation)
O4 - HKUS-1-5-21-796845957-823518204-842925246-500..Run: [swg] C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:Documents and SettingsAdministratorStart MenuProgramsStartupПряк път до logon.lnk = C:logon.bat ()
O6 - HKLMSoftwarePoliciesMicrosoftInternet ExplorerInfodelivery present
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveTypeAutoRun = 323
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveAutoRun = 67108863
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: dontdisplaylastusername = 0
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: legalnoticecaption =
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: legalnoticetext =
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: shutdownwithoutlogon = 1
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: undockwithoutlogon = 1
O7 - HKU.DEFAULTSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveTypeAutoRun = 323
O7 - HKU.DEFAULTSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveAutoRun = 67108863
O7 - HKUS-1-5-18SOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveTypeAutoRun = 323
O7 - HKUS-1-5-18SOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveAutoRun = 67108863
O7 - HKUS-1-5-19SOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveTypeAutoRun = 145
O7 - HKUS-1-5-20SOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveTypeAutoRun = 145
O7 - HKUS-1-5-21-796845957-823518204-842925246-500SOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveTypeAutoRun = 323
O7 - HKUS-1-5-21-796845957-823518204-842925246-500SOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveAutoRun = 67108863
O7 - HKUS-1-5-21-796845957-823518204-842925246-500SOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: disableregistrytools = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:Program FilesMicrosoft OfficeOFFICE11EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:Program FilesMicrosoft OfficeOFFICE11REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5Catalog_Entries000000000001 [] - C:WINDOWSsystem32mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5Catalog_Entries000000000002 [] - C:WINDOWSsystem32winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5Catalog_Entries000000000003 [] - C:WINDOWSsystem32mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9Catalog_Entries000000000001 - C:Program FilesAviraAntiVir Desktopavsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9Catalog_Entries000000000002 - C:Program FilesAviraAntiVir Desktopavsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9Catalog_Entries000000000003 - C:WINDOWSsystem32mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9Catalog_Entries000000000004 - C:WINDOWSsystem32mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9Catalog_Entries000000000005 - C:WINDOWSsystem32mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9Catalog_Entries000000000006 - C:WINDOWSsystem32rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9Catalog_Entries000000000007 - C:WINDOWSsystem32rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9Catalog_Entries000000000008 - C:WINDOWSsystem32mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9Catalog_Entries000000000009 - C:WINDOWSsystem32mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9Catalog_Entries000000000010 - C:WINDOWSsystem32mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9Catalog_Entries000000000011 - C:WINDOWSsystem32mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9Catalog_Entries000000000012 - C:WINDOWSsystem32mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9Catalog_Entries000000000013 - C:WINDOWSsystem32mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9Catalog_Entries000000000014 - C:Program FilesAviraAntiVir Desktopavsda.dll (Avira Operations GmbH & Co. KG)
O17 - HKLMSystemCCSServicesTcpipParametersInterfaces{CADD7416-CDF9-4569-8EF7-BF724102282C}: NameServer = 192.168.1.1
O18 - ProtocolHandlerabout {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:WINDOWSsystem32mshtml.dll (Microsoft Corporation)
O18 - ProtocolHandlercdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:WINDOWSsystem32urlmon.dll (Microsoft Corporation)
O18 - ProtocolHandlerdvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:WINDOWSsystem32msvidctl.dll (Microsoft Corporation)
O18 - ProtocolHandlerfile {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:WINDOWSsystem32urlmon.dll (Microsoft Corporation)
O18 - ProtocolHandlerftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:WINDOWSsystem32urlmon.dll (Microsoft Corporation)
O18 - ProtocolHandlergopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:WINDOWSsystem32urlmon.dll (Microsoft Corporation)
O18 - ProtocolHandlerhttp {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:WINDOWSsystem32urlmon.dll (Microsoft Corporation)
O18 - ProtocolHandlerhttp0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:Program FilesCommon FilesSystemOle DBMSDAIPP.DLL (Microsoft Corporation)
O18 - ProtocolHandlerhttpoledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:Program FilesCommon FilesSystemOle DBMSDAIPP.DLL (Microsoft Corporation)
O18 - ProtocolHandlerhttps {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:WINDOWSsystem32urlmon.dll (Microsoft Corporation)
O18 - ProtocolHandlerhttps0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:Program FilesCommon FilesSystemOle DBMSDAIPP.DLL (Microsoft Corporation)
O18 - ProtocolHandlerhttpsoledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:Program FilesCommon FilesSystemOle DBMSDAIPP.DLL (Microsoft Corporation)
O18 - ProtocolHandleripp - No CLSID value found
O18 - ProtocolHandleripp0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:Program FilesCommon FilesSystemOle DBMSDAIPP.DLL (Microsoft Corporation)
O18 - ProtocolHandlerits {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:WINDOWSsystem32itss.dll (Microsoft Corporation)
O18 - ProtocolHandlerjavascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:WINDOWSsystem32mshtml.dll (Microsoft Corporation)
O18 - ProtocolHandlerlocal {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:WINDOWSsystem32urlmon.dll (Microsoft Corporation)
O18 - ProtocolHandlermailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:WINDOWSsystem32mshtml.dll (Microsoft Corporation)
O18 - ProtocolHandlermhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:WINDOWSsystem32inetcomm.dll (Microsoft Corporation)
O18 - ProtocolHandlermk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:WINDOWSsystem32urlmon.dll (Microsoft Corporation)
O18 - ProtocolHandlermsdaipp - No CLSID value found
O18 - ProtocolHandlermsdaipp0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:Program FilesCommon FilesSystemOle DBMSDAIPP.DLL (Microsoft Corporation)
O18 - ProtocolHandlermsdaippoledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:Program FilesCommon FilesSystemOle DBMSDAIPP.DLL (Microsoft Corporation)
O18 - ProtocolHandlerms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:WINDOWSsystem32itss.dll (Microsoft Corporation)
O18 - ProtocolHandlermso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:Program FilesCommon FilesMicrosoft SharedWeb Components10OWC10.DLL (Microsoft Corporation)
O18 - ProtocolHandlermso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:Program FilesCommon FilesMicrosoft SharedWeb Components11OWC11.DLL (Microsoft Corporation)
O18 - ProtocolHandlerres {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:WINDOWSsystem32mshtml.dll (Microsoft Corporation)
O18 - ProtocolHandlerskype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:Program FilesCommon FilesSkypeSkype4COM.dll (Skype Technologies)
O18 - ProtocolHandlerskype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:Program FilesSkypeToolbarsInternet Explorerskypeieplugin.dll (Skype Technologies S.A.)
O18 - ProtocolHandlersysimage {76E67A63-06E9-11D2-A840-006008059382} - C:WINDOWSsystem32mshtml.dll (Microsoft Corporation)
O18 - ProtocolHandlertv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:WINDOWSsystem32msvidctl.dll (Microsoft Corporation)
O18 - ProtocolHandlervbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:WINDOWSsystem32mshtml.dll (Microsoft Corporation)
O18 - ProtocolHandlerwia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:WINDOWSsystem32wiascr.dll (Microsoft Corporation)
O18 - ProtocolFilterClass Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:WINDOWSsystem32urlmon.dll (Microsoft Corporation)
O18 - ProtocolFilterdeflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:WINDOWSsystem32urlmon.dll (Microsoft Corporation)
O18 - ProtocolFiltergzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:WINDOWSsystem32urlmon.dll (Microsoft Corporation)
O18 - ProtocolFilterlzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:WINDOWSsystem32urlmon.dll (Microsoft Corporation)
O18 - ProtocolFiltertext/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:WINDOWSsystem32shell32.dll (Microsoft Corporation)
O18 - ProtocolFiltertext/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:Program FilesCommon FilesMicrosoft SharedOFFICE11MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:WINDOWSexplorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:WINDOWSsystem32userinit.exe) - C:WINDOWSsystem32userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:WINDOWSSystem32logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:WINDOWSSystem32shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:WINDOWSSystem32sysdm.cpl (Microsoft Corporation)
O20 - WinlogonNotifycrypt32chain: DllName - (crypt32.dll) - C:WINDOWSSystem32crypt32.dll (Microsoft Corporation)
O20 - WinlogonNotifycryptnet: DllName - (cryptnet.dll) - C:WINDOWSSystem32cryptnet.dll (Microsoft Corporation)
O20 - WinlogonNotifycscdll: DllName - (cscdll.dll) - C:WINDOWSSystem32cscdll.dll (Microsoft Corporation)
O20 - WinlogonNotifydimsntfy: DllName - (%SystemRoot%System32dimsntfy.dll) - C:WINDOWSsystem32dimsntfy.dll (Microsoft Corporation)
O20 - WinlogonNotifyigfxcui: DllName - (igfxsrvc.dll) - C:WINDOWSSystem32igfxsrvc.dll (Intel Corporation)
O20 - WinlogonNotifyScCertProp: DllName - (wlnotify.dll) - C:WINDOWSSystem32wlnotify.dll (Microsoft Corporation)
O20 - WinlogonNotifySchedule: DllName - (wlnotify.dll) - C:WINDOWSSystem32wlnotify.dll (Microsoft Corporation)
O20 - WinlogonNotifysclgntfy: DllName - (sclgntfy.dll) - C:WINDOWSSystem32sclgntfy.dll (Microsoft Corporation)
O20 - WinlogonNotifySensLogn: DllName - (WlNotify.dll) - C:WINDOWSSystem32wlnotify.dll (Microsoft Corporation)
O20 - WinlogonNotifytermsrv: DllName - (wlnotify.dll) - C:WINDOWSSystem32wlnotify.dll (Microsoft Corporation)
O20 - WinlogonNotifyWgaLogon: DllName - (WgaLogon.dll) - C:WINDOWSSystem32WgaLogon.dll (Microsoft Corporation)
O20 - WinlogonNotifywinwrv32: DllName - (winwrv32.dll) -  File not found
O20 - WinlogonNotifywlballoon: DllName - (wlnotify.dll) - C:WINDOWSSystem32wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:WINDOWSsystem32shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:WINDOWSsystem32shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:WINDOWSsystem32stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:WINDOWSsystem32webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:WINDOWSsystem32WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:WINDOWSsystem32browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:WINDOWSsystem32browseui.dll (Microsoft Corporation)
O24 - Desktop Components:0 (Моята текуща начална страница) - About:Home
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:WINDOWSSystem32shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:WINDOWSSystem32msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (schannel.dll) - C:WINDOWSSystem32schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (digest.dll) - C:WINDOWSSystem32digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll) - C:WINDOWSSystem32msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:WINDOWSSystem32msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:WINDOWSSystem32kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:WINDOWSSystem32msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:WINDOWSSystem32schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:WINDOWSSystem32wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 0
O32 - AutoRun File - [2013/09/11 10:23:29 | 000,000,000 | ---- | M] () - C:AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM..comfile [open] -- "%1" %*
O35 - HKLM..exefile [open] -- "%1" %*
O37 - HKLM...com [@ = comfile] -- "%1" %*
O37 - HKLM...exe [@ = exefile] -- "%1" %*
O38 - SubSystemsWindows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystemsWindows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
NetSvcs: 6to4 -  File not found
NetSvcs: HidServ - %SystemRoot%System32hidserv.dll File not found
NetSvcs: Ias -  File not found
NetSvcs: Iprip -  File not found
NetSvcs: Irmon -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: WmdmPmSp -  File not found
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 90 Days ==========
 
[2013/12/03 09:58:38 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:Documents and SettingsAdministratorDesktopOTL.exe
[2013/12/03 09:49:48 | 000,000,000 | --SD | C] -- C:ComboFix
[2013/12/03 08:48:50 | 000,760,937 | ---- | C] (Farbar) -- C:Documents and SettingsAdministratorDesktopMiniToolBox.exe
[2013/12/03 08:43:17 | 000,360,881 | ---- | C] (Farbar) -- C:Documents and SettingsAdministratorDesktopFSS.exe
[2013/12/02 10:17:01 | 000,000,000 | ---D | C] -- C:Documents and SettingsAdministratorMy DocumentsMIMA
[2013/11/29 14:42:08 | 000,000,000 | RHSD | C] -- C:cmdcons
[2013/11/29 14:35:48 | 000,000,000 | ---D | C] -- C:WINDOWSerdnt
[2013/11/29 14:19:11 | 001,937,144 | ---- | C] (Bleeping Computer, LLC) -- C:Documents and SettingsAdministratorDesktoprkill.com
[2013/11/28 09:47:06 | 000,000,000 | ---D | C] -- C:FRST
[2013/11/28 09:45:07 | 001,091,827 | ---- | C] (Farbar) -- C:Documents and SettingsAdministratorDesktopFRST.exe
[2013/11/27 14:32:25 | 000,171,344 | ---- | C] (Kaspersky Lab ZAO) -- C:Documents and SettingsAdministratorDesktopSalityKiller.exe
[2013/11/18 10:23:31 | 000,000,000 | ---D | C] -- C:Program FilesMozilla Firefox
[2013/10/21 08:20:23 | 000,000,000 | ---D | C] -- C:WINDOWSERUNT
[2013/10/21 07:35:59 | 000,000,000 | ---D | C] -- C:AdwCleaner
[2013/10/18 15:31:12 | 000,000,000 | RH-D | C] -- C:Documents and SettingsAdministratorRecent
[2013/10/18 14:48:17 | 000,000,000 | R--D | C] -- C:Documents and SettingsAdministratorMy DocumentsMy Videos
[2013/10/18 14:48:16 | 000,000,000 | R--D | C] -- C:Documents and SettingsAdministratorStart MenuProgramsAdministrative Tools
[2013/10/18 14:42:07 | 000,492,146 | R--- | C] (Swearware) -- C:Documents and SettingsAdministratorDesktopdds.exe
[2013/10/10 12:32:26 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:WINDOWSSystem32dllcacheieudinit.exe
[2013/10/10 12:32:25 | 000,380,928 | ---- | C] (Microsoft Corporation) -- C:WINDOWSSystem32dllcacheieapfltr.dll
[2013/10/10 12:32:24 | 000,268,288 | ---- | C] (Microsoft Corporation) -- C:WINDOWSSystem32dllcacheiertutil.dll
[2013/10/10 12:32:24 | 000,063,488 | ---- | C] (Microsoft Corporation) -- C:WINDOWSSystem32dllcacheicardie.dll
[2013/10/10 12:32:24 | 000,052,224 | ---- | C] (Microsoft Corporation) -- C:WINDOWSSystem32dllcachemsfeedsbs.dll
[2013/10/10 12:32:22 | 000,991,232 | ---- | C] (Microsoft Corporation) -- C:WINDOWSSystem32dllcacheieframe.dll.mui
[2013/10/10 12:32:21 | 002,452,872 | ---- | C] (Microsoft Corporation) -- C:WINDOWSSystem32dllcacheieapfltr.dat
[2013/10/10 12:32:19 | 000,496,128 | ---- | C] (Microsoft Corporation) -- C:WINDOWSSystem32dllcachemsfeeds.dll
[2013/10/10 12:32:17 | 006,108,672 | ---- | C] (Microsoft Corporation) -- C:WINDOWSSystem32dllcacheieframe.dll
[2013/10/10 12:13:47 | 000,012,928 | ---- | C] (Microsoft Corporation) -- C:WINDOWSSystem32dllcacheusb8023x.sys
[2013/10/10 11:31:24 | 000,456,320 | ---- | C] (Microsoft Corporation) -- C:WINDOWSSystem32dllcachemrxsmb.sys
[2013/10/10 11:29:44 | 000,000,000 | ---D | C] -- C:Program FilesMSXML 4.0
[2013/10/10 10:53:03 | 000,293,376 | ---- | C] (Microsoft Corporation) -- C:WINDOWSSystem32browserchoice.exe
[2013/10/10 10:48:22 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:WINDOWSSystem32dllcachetsbyuv.dll
[2013/10/10 10:48:21 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:WINDOWSSystem32dllcacheiyuv_32.dll
[2013/10/10 10:47:18 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:WINDOWSSystem32dllcachemsyuv.dll
[2013/10/10 09:53:13 | 002,149,888 | ---- | C] (Microsoft Corporation) -- C:WINDOWSSystem32dllcachentkrnlmp.exe
[2013/10/10 09:53:09 | 002,193,536 | ---- | C] (Microsoft Corporation) -- C:WINDOWSSystem32dllcachentoskrnl.exe
[2013/10/10 09:52:39 | 002,028,544 | ---- | C] (Microsoft Corporation) -- C:WINDOWSSystem32dllcachentkrpamp.exe
[2013/10/10 08:09:26 | 000,272,128 | ---- | C] (Microsoft Corporation) -- C:WINDOWSSystem32dllcachebthport.sys
[2013/09/19 12:03:25 | 000,023,360 | ---- | C] (IObit) -- C:WINDOWSSystem32RegistryDefragBootTime.exe
[2013/09/11 13:34:17 | 000,000,000 | ---D | C] -- C:Program FilesCommon FilesSkype
[2013/09/11 13:34:17 | 000,000,000 | ---D | C] -- C:Documents and SettingsAll UsersStart MenuProgramsSkype
[2013/09/04 13:10:14 | 000,000,000 | ---D | C] -- C:Documents and SettingsAll UsersApplication Data{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}
[2013/09/04 13:09:02 | 000,000,000 | ---D | C] -- C:Documents and SettingsAdministratorLocalLow
[2013/09/04 13:07:21 | 000,000,000 | ---D | C] -- C:Documents and SettingsAdministratorAppData
[2013/09/04 13:07:20 | 000,000,000 | ---D | C] -- C:Documents and SettingsAdministratorApplication DataApple Computer
[2013/09/04 13:06:17 | 000,000,000 | ---D | C] -- C:Documents and SettingsAll UsersApplication DataIObit
[2013/09/04 13:06:17 | 000,000,000 | ---D | C] -- C:Documents and SettingsAdministratorApplication DataIObit
[2013/09/04 13:03:43 | 000,000,000 | ---D | C] -- C:Program FilesIObit
[54 C:WINDOWSSystem32*.tmp files -> C:WINDOWSSystem32*.tmp -> ]
[2 C:WINDOWSSystem32dllcache*.tmp files -> C:WINDOWSSystem32dllcache*.tmp -> ]
 
========== Files - Modified Within 90 Days ==========
 
[2013/12/03 10:36:06 | 000,000,830 | ---- | M] () -- C:WINDOWStasksAdobe Flash Player Updater.job
[2013/12/03 09:58:52 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:Documents and SettingsAdministratorDesktopOTL.exe
[2013/12/03 09:56:18 | 000,000,900 | ---- | M] () -- C:WINDOWStasksGoogleUpdateTaskMachineUA.job
[2013/12/03 09:28:50 | 000,000,896 | ---- | M] () -- C:WINDOWStasksGoogleUpdateTaskMachineCore.job
[2013/12/03 09:28:32 | 000,002,048 | --S- | M] () -- C:WINDOWSbootstat.dat
[2013/12/03 09:28:30 | 259,575,808 | -HS- | M] () -- C:hiberfil.sys
[2013/12/03 08:48:52 | 000,760,937 | ---- | M] (Farbar) -- C:Documents and SettingsAdministratorDesktopMiniToolBox.exe
[2013/12/03 08:43:29 | 000,360,881 | ---- | M] (Farbar) -- C:Documents and SettingsAdministratorDesktopFSS.exe
[2013/12/02 07:59:33 | 000,002,206 | -H-- | M] () -- C:WINDOWSSystem32wpa.dbl
[2013/11/29 14:42:20 | 000,000,327 | RHS- | M] () -- C:boot.ini
[2013/11/29 14:19:25 | 001,937,144 | ---- | M] (Bleeping Computer, LLC) -- C:Documents and SettingsAdministratorDesktoprkill.com
[2013/11/28 16:35:42 | 000,000,742 | ---- | M] () -- C:Documents and SettingsAdministratorApplication DataMicrosoftInternet ExplorerQuick LaunchMozilla Firefox.lnk
[2013/11/28 16:35:42 | 000,000,724 | ---- | M] () -- C:Documents and SettingsAll UsersDesktopMozilla Firefox.lnk
[2013/11/28 09:45:58 | 001,091,827 | ---- | M] (Farbar) -- C:Documents and SettingsAdministratorDesktopFRST.exe
[2013/11/27 08:32:30 | 000,002,497 | ---- | M] () -- C:Documents and SettingsAdministratorDesktopMicrosoft Office Word 2003.lnk
[2013/11/19 14:23:41 | 000,137,208 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:WINDOWSSystem32driversavipbb.sys
[2013/11/19 14:23:41 | 000,090,400 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:WINDOWSSystem32driversavgntflt.sys
[2013/11/19 14:23:41 | 000,037,352 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:WINDOWSSystem32driversavkmgr.sys
[2013/10/18 14:42:49 | 000,492,146 | R--- | M] (Swearware) -- C:Documents and SettingsAdministratorDesktopdds.exe
[2013/10/11 07:02:34 | 000,182,632 | -H-- | M] () -- C:WINDOWSSystem32FNTCACHE.DAT
[2013/10/11 07:01:48 | 000,000,000 | ---- | M] () -- C:asc_rdflag
[2013/10/10 08:39:11 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:WINDOWSSystem32FlashPlayerApp.exe
[2013/10/10 08:39:08 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:WINDOWSSystem32FlashPlayerCPLApp.cpl
[2013/09/16 12:48:04 | 000,000,104 | ---- | M] () -- C:Documents and SettingsAdministratorDesktopИнтернет.lnk
[2013/09/11 10:23:59 | 000,002,621 | ---- | M] () -- C:WINDOWSpsql.MIF
[2013/09/11 10:23:29 | 000,000,000 | ---- | M] () -- C:AUTOEXEC.BAT
[2013/09/11 10:23:28 | 000,002,580 | ---- | M] () -- C:WINDOWSSystem32CONFIG.NT
[2013/09/11 10:23:28 | 000,001,691 | ---- | M] () -- C:WINDOWSSystem32AUTOEXEC.NT
[2013/09/04 15:01:53 | 000,140,498 | ---- | M] () -- C:Documents and SettingsAdministratorMy Documentsмаратонки найк черни.JPG
[54 C:WINDOWSSystem32*.tmp files -> C:WINDOWSSystem32*.tmp -> ]
[2 C:WINDOWSSystem32dllcache*.tmp files -> C:WINDOWSSystem32dllcache*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2013/11/29 14:42:20 | 000,000,211 | ---- | C] () -- C:Boot.bak
[2013/11/29 14:42:13 | 000,260,272 | RHS- | C] () -- C:cmldr
[2013/11/28 16:35:42 | 000,000,742 | ---- | C] () -- C:Documents and SettingsAdministratorApplication DataMicrosoftInternet ExplorerQuick LaunchMozilla Firefox.lnk
[2013/11/28 16:35:42 | 000,000,724 | ---- | C] () -- C:Documents and SettingsAll UsersDesktopMozilla Firefox.lnk
[2013/10/11 07:01:48 | 000,000,000 | ---- | C] () -- C:asc_rdflag
[2013/10/10 11:46:31 | 000,003,072 | ---- | C] () -- C:WINDOWSSystem32iacenc.dll
[2013/10/10 11:46:31 | 000,003,072 | ---- | C] () -- C:WINDOWSSystem32dllcacheiacenc.dll
[2013/09/16 12:48:04 | 000,000,104 | ---- | C] () -- C:Documents and SettingsAdministratorDesktopИнтернет.lnk
[2013/09/11 10:23:28 | 000,001,801 | ---- | C] () -- C:WINDOWSSystem32autoexec.PU_
[2013/09/11 10:23:18 | 000,002,621 | ---- | C] () -- C:WINDOWSpsql.MIF
[2013/09/04 15:01:43 | 000,140,498 | ---- | C] () -- C:Documents and SettingsAdministratorMy Documentsмаратонки найк черни.JPG
[2013/09/04 13:09:42 | 000,268,968 | ---- | C] () -- C:WINDOWSSystem32sqlite3.dll
[2013/07/23 12:50:32 | 000,000,079 | ---- | C] () -- C:WINDOWSwininit.ini
[2010/02/26 10:42:08 | 000,005,632 | ---- | C] () -- C:Documents and SettingsAdministratorLocal SettingsApplication DataDCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
 
========== ZeroAccess Check ==========
 
 
[HKEY_CURRENT_USERSoftwareClassesclsid{42aedc87-2188-41fd-b9a3-0c966feabec1}InProcServer32]
 
[HKEY_CURRENT_USERSoftwareClassesclsid{fbeb8a05-beee-4442-804e-409d6c4515e9}InProcServer32]
 
[HKEY_LOCAL_MACHINESoftwareClassesclsid{42aedc87-2188-41fd-b9a3-0c966feabec1}InProcServer32]
"" = %SystemRoot%system32shdocvw.dll -- [2008/04/14 04:42:06 | 001,499,136 | -H-- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINESoftwareClassesclsid{5839FCA9-774D-42A1-ACDA-D6A79037F57F}InProcServer32]
"" = %systemroot%system32wbemfastprox.dll -- [2008/04/14 04:41:54 | 000,472,064 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINESoftwareClassesclsid{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}InProcServer32]
"" = %systemroot%system32wbemwbemess.dll -- [2008/04/14 04:42:10 | 000,273,920 | -H-- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
========== LOP Check ==========
 
[2013/06/24 14:17:35 | 000,000,000 | ---D | M] -- C:Documents and SettingsAdministratorApplication DataCallingID
[2008/07/27 15:13:35 | 000,000,000 | ---D | M] -- C:Documents and SettingsAdministratorApplication DataDAEMON Tools
[2013/09/19 12:20:34 | 000,000,000 | ---D | M] -- C:Documents and SettingsAdministratorApplication DataIObit
[2013/09/04 13:15:29 | 000,000,000 | ---D | M] -- C:Documents and SettingsAll UsersApplication DataIObit
[2013/09/04 13:10:14 | 000,000,000 | ---D | M] -- C:Documents and SettingsAll UsersApplication Data{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %SYSTEMDRIVE%*.exe >
 
< MD5 for: EXPLORER.EXE  >
[2008/04/14 04:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:WINDOWSexplorer.exe
[2008/04/14 04:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:WINDOWSsystem32dllcacheexplorer.exe
 
< MD5 for: SERVICES.EXE  >
[2009/02/06 13:06:24 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 -- C:WINDOWS$hf_mig$KB956572SP3QFEservices.exe
[2008/04/14 04:42:36 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 -- C:WINDOWS$NtUninstallKB956572$services.exe
[2009/02/06 13:11:05 | 000,110,592 | -H-- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 -- C:WINDOWSsystem32dllcacheservices.exe
[2009/02/06 13:11:05 | 000,110,592 | -H-- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 -- C:WINDOWSsystem32services.exe
 
< MD5 for: SVCHOST.EXE  >
[2008/04/14 04:42:38 | 000,014,336 | -H-- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:WINDOWSsystem32dllcachesvchost.exe
[2008/04/14 04:42:38 | 000,014,336 | -H-- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:WINDOWSsystem32svchost.exe
[2013/04/04 13:50:32 | 000,218,184 | ---- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC -- C:Program FilesMalwarebytes' Anti-MalwareChameleonsvchost.exe
 
< MD5 for: USERINIT.EXE  >
[2008/04/14 04:42:40 | 000,026,112 | -H-- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:WINDOWSsystem32dllcacheuserinit.exe
[2008/04/14 04:42:40 | 000,026,112 | -H-- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:WINDOWSsystem32userinit.exe
 
< MD5 for: WINLOGON.EXE  >
[2013/04/04 13:50:32 | 000,218,184 | ---- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC -- C:Program FilesMalwarebytes' Anti-MalwareChameleonwinlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | -H-- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:WINDOWSsystem32dllcachewinlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | -H-- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:WINDOWSsystem32winlogon.exe
 
< %systemroot%*. /rp /s >
 
< %systemdrive%$Recycle.Bin|@;true;true;true /fp >
 
========== Drive Information ==========
 
Physical Drives
---------------
 
Drive: .PHYSICALDRIVE0 - Fixedthard disk media
Interface type: IDE
Media Type: Fixedthard disk media
Model: ST380011A
Partitions: 1
Status: OK
Status Info: 0
 
Partitions
---------------
 
DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 75.00GB
Starting Offset: 32256
Hidden sectors: 0
 
 
========== Files - Unicode (All) ==========
[2013/11/18 14:16:54 | 104,927,322 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32朞咔6
[2013/11/18 14:16:54 | 104,927,322 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32朞咔6
[2013/11/14 14:13:23 | 104,200,551 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32傪슾咔6
[2013/11/14 14:13:23 | 104,200,551 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32傪슾咔6
[2013/11/13 08:19:22 | 104,004,073 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32厢뱤咔6
[2013/11/13 08:19:22 | 104,004,073 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32厢뱤咔6
[2013/11/12 08:17:13 | 103,716,811 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32䦇쎉咔6
[2013/11/12 08:17:13 | 103,716,811 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32䦇쎉咔6
[2013/11/11 14:07:13 | 103,682,728 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32뒍咔6
[2013/11/11 14:07:13 | 103,682,728 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32뒍咔6
[2013/11/08 08:07:45 | 103,075,526 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32䉯Შ咔6
[2013/11/08 08:07:45 | 103,075,526 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32䉯Შ咔6
[2013/11/06 15:09:45 | 102,722,523 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32됚ꋑ咔6
[2013/11/06 15:09:45 | 102,722,523 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32됚ꋑ咔6
[2013/10/30 14:13:48 | 104,098,187 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32䶝遏咔6
[2013/10/30 14:13:48 | 104,098,187 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32䶝遏咔6
[2013/10/29 08:06:26 | 103,917,820 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32貓苦咔6
[2013/10/29 08:06:26 | 103,917,820 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32貓苦咔6
[2013/10/28 08:06:17 | 103,622,390 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32볼ࣲ咔6
[2013/10/28 08:06:17 | 103,622,390 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32볼ࣲ咔6
[2013/10/25 07:08:55 | 102,837,954 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32惔�咔6
[2013/10/25 07:08:55 | 102,837,954 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32惔�咔6
[2013/10/24 13:16:34 | 102,787,172 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32쾋猳咔6
[2013/10/24 13:16:34 | 102,787,172 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32쾋猳咔6
[2013/10/22 08:57:36 | 102,303,549 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32㈖咔6
[2013/10/22 08:57:36 | 102,303,549 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32㈖咔6
[2013/10/21 07:14:54 | 102,118,912 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32⚬랕咔6
[2013/10/21 07:14:54 | 102,118,912 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32⚬랕咔6
[2013/10/18 13:25:12 | 101,760,430 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32廟ᛖ咔6
[2013/10/18 13:25:12 | 101,760,430 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32廟ᛖ咔6
[2013/10/17 13:21:37 | 101,413,064 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32㐥潑咔6
[2013/10/17 13:21:37 | 101,413,064 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32㐥潑咔6
[2013/10/15 07:38:46 | 101,076,544 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32ㅡ᧕咔6
[2013/10/15 07:38:46 | 101,076,544 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32ㅡ᧕咔6
[2013/10/14 07:54:01 | 100,838,232 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32获ꈣ咔6
[2013/10/14 07:54:01 | 100,838,232 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32获ꈣ咔6
[2013/10/11 13:17:52 | 100,470,597 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32䤁ⴾ咔6
[2013/10/11 13:17:52 | 100,470,597 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32䤁ⴾ咔6
[2013/10/10 13:15:15 | 100,267,706 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32煥㮣咔6
[2013/10/10 13:15:15 | 100,267,706 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32煥㮣咔6
[2013/10/04 10:55:52 | 099,176,917 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32戯봖咔6
[2013/10/04 10:55:52 | 099,176,917 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32戯봖咔6
[2013/10/03 08:21:17 | 098,878,632 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32蛄咔6
[2013/10/03 08:21:17 | 098,878,632 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32蛄咔6
[2013/10/02 10:21:11 | 098,712,514 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32떮捆咔6
[2013/10/02 10:21:11 | 098,712,514 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32떮捆咔6
[2013/10/01 07:42:32 | 098,602,865 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32䄥ꁟ咔6
[2013/10/01 07:42:32 | 098,602,865 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32䄥ꁟ咔6
[2013/09/30 07:20:37 | 098,466,785 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32寇큇咔6
[2013/09/30 07:20:37 | 098,466,785 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32寇큇咔6
[2013/09/27 08:48:57 | 098,009,570 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32辅艮咔6
[2013/09/27 08:48:57 | 098,009,570 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32辅艮咔6
[2013/09/26 13:35:08 | 097,927,968 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32ﳧ濿咔6
[2013/09/26 13:35:08 | 097,927,968 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32ﳧ濿咔6
[2013/09/25 13:48:06 | 097,729,025 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32놫햶咔6
[2013/09/25 13:48:06 | 097,729,025 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32놫햶咔6
[2013/09/24 13:59:49 | 097,531,747 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32逐乻咔6
[2013/09/24 13:59:49 | 097,531,747 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32逐乻咔6
[2013/09/23 13:33:02 | 098,646,441 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32�靥咔6
[2013/09/23 13:33:02 | 098,646,441 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32�靥咔6
[2013/09/20 07:09:32 | 098,443,620 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32쫘咔6
[2013/09/20 07:09:32 | 098,443,620 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32쫘咔6
[2013/09/19 13:20:57 | 098,352,290 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32仙਷咔6
[2013/09/19 13:20:57 | 098,352,290 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32仙਷咔6
[2013/09/18 13:25:40 | 098,123,923 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32咔6
[2013/09/18 13:25:40 | 098,123,923 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32咔6
[2013/09/18 07:22:13 | 098,106,403 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32娔驇咔6
[2013/09/18 07:22:13 | 098,106,403 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32娔驇咔6
[2013/09/12 13:18:34 | 097,238,077 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32캾咔6
[2013/09/12 07:18:32 | 097,238,077 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32캾咔6
[2013/09/10 13:17:16 | 096,922,344 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32荅筟啜6
[2013/09/10 13:17:16 | 096,922,344 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32荅筟啜6
[2013/09/09 15:10:05 | 096,665,497 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32㆕ꑦ啜6
[2013/09/09 15:10:05 | 096,665,497 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32㆕ꑦ啜6
[2013/08/30 07:18:50 | 094,712,498 | ---- | M] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32䝋壟啜6
[2013/08/30 07:18:50 | 094,712,498 | ---- | C] ()(C:WINDOWSSystem32???6) -- C:WINDOWSSystem32䝋壟啜6

< End of report >
 

.........

Extras.Txt

Публикувано изображение Стартирайте отново OTL, копирайте (Copy) и поставете (Paste) скриптовия текст от текстовото поле по-долу под колонката Custom Scans/Fixes, като не забравяте да копирате скрипта 1 към 1, както и двете точки преди първия ред на скрипта.

:Commands[CreateRestorePoint]:OTLDRV - File not found [Kernel | On_Demand | Unknown] --  -- (awvhlniq)O20 - WinlogonNotifywinwrv32: DllName - (winwrv32.dll) -  File not found[2013/12/03 09:49:48 | 000,000,000 | --SD | C] -- C:ComboFix[2013/09/04 13:06:17 | 000,000,000 | ---D | C] -- C:Documents and SettingsAll UsersApplication DataIObit[2013/09/04 13:06:17 | 000,000,000 | ---D | C] -- C:Documents and SettingsAdministratorApplication DataIObit[2013/09/04 13:03:43 | 000,000,000 | ---D | C] -- C:Program FilesIObitautorun.inf /alldrivesrecycler /alldrivesipconfig /flushdns /c:Commands[purity][emptytemp][clearallrestorepoints][Reboot]

Публикувано изображение След като въведете скрипта от цитата по-горе натиснете бутона, маркиран в червено: Run Fix
Windows ще се рестартира и ще се създаде лог файл. Публикувайте съдържанието му с Copy/Paste в следващия си коментар.
По време на фикса с инструмента, не използвайте компютъра си!

  • Автор

Eто най после .

Само да кажа, че днес цял ден в Мозилата ми дава, че не може да се зареди който и да е сайт / включително и вашият/. Един път ако зареди и край после дава, че сайта не може да бъде намерен. Това сега го качвам от домашния компютър.

 

All processes killed========== COMMANDS ==========Restore point Set: OTL Restore Point========== OTL ==========Error: No service named awvhlniq was found to stop!ServiceDriver key awvhlniq not found.Registry key HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonNotifywinwrv32 not found.Folder C:ComboFix not found.Folder C:Documents and SettingsAll UsersApplication DataIObit not found.Folder C:Documents and SettingsAdministratorApplication DataIObit not found.Folder C:Program FilesIObit not found.========== COMMANDS ========== [EMPTYTEMP] User: Administrator->Temp folder emptied: 771 bytes->Temporary Internet Files folder emptied: 33170 bytes->FireFox cache emptied: 14627685 bytes->Flash cache emptied: 492 bytes User: All Users User: Default User->Temp folder emptied: 0 bytes->Temporary Internet Files folder emptied: 0 bytes User: LocalService->Temp folder emptied: 0 bytes->Temporary Internet Files folder emptied: 0 bytes->Flash cache emptied: 0 bytes User: NetworkService->Temp folder emptied: 0 bytes->Temporary Internet Files folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes%systemroot% .tmp files removed: 0 bytes%systemroot%System32 .tmp files removed: 0 bytes%systemroot%System32dllcache .tmp files removed: 0 bytes%systemroot%System32drivers .tmp files removed: 0 bytesWindows Temp folder emptied: 255 bytes%systemroot%system32configsystemprofileLocal SettingsTemp folder emptied: 0 bytes%systemroot%system32configsystemprofileLocal SettingsTemporary Internet Files folder emptied: 0 bytesRecycleBin emptied: 104 bytes Total Files Cleaned = 14.00 mb Error creating restore point. OTL by OldTimer - Version 3.2.69.0 log created on 12092013_140119FilesFolders moved on Reboot...PendingFileRenameOperations files...Registry entries deleted on Reboot... 

Редактирано от denito_vikito (преглед на промените)

  • Автор

Здравей, :)  Успях да сканирам още веднъж и ето резултата. Надявам се да се включиш с напътствия. Благодаря !!!

 

 

Malwarebytes Anti-Malware 1.75.0.1300www.malwarebytes.orgВерсия на базата от данни: v2013.12.10.02Windows XP Service Pack 3 x86 NTFSInternet Explorer 7.0.5730.13Administrator :: MAGI [администратор]12/10/2013 10:31:38 AMMBAM-log-2013-12-10 (13-15-51).txtТип сканиране: Пълно сканиране (C:|D:|)Включени опции за сканиране: Памет | Автоматично зареждане | Системен регистър | Файлова система | Евристики/Допълнителни | Евристики/Shuriken | PUP | PUMИзключени опции за сканиране: P2PСканирани обекти: 212497Изминало време: 2 час(а), 8 минута(и), 54 секунда(и)Открити процеси в паметта: 0(Не бяха открити зловредни обекти)Открити модули в паметта: 0(Не бяха открити зловредни обекти)Открити ключове в системния регистър: 0

(Не бяха открити зловредни обекти)Открити стойности в системния регистър: 0(Не бяха открити зловредни обекти)Открити информационни обекти в системния регистър: 3HKLMSOFTWAREMicrosoftSecurity Center|AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Лош: (1) Добър: (0) -> Не беше предприето действие.HKLMSOFTWAREMicrosoftSecurity Center|FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Лош: (1) Добър: (0) -> Не беше предприето действие.HKLMSOFTWAREMicrosoftSecurity Center|UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Лош: (1) Добър: (0) -> Не беше предприето действие.Открити папки: 0(Не бяха открити зловредни обекти)Открити файлове: 0(Не бяха открити зловредни обекти)(край) 

 

Ами не виждам нищо притеснително...Само SecurityCenter ви е изключен и ако бяхте предприели действие  щеше да бъде всичко наред..!Активни зарази не виждам..!
 
Публикувано изображение Стартирайте OTL още веднъж и натиснете бутона CleanUp.

Публикувано изображение

Ще последва рестарт на компютъра ви..!

  • 4 седмици по-късно...
  • Автор

Здравейте и Честита Нова година, с пожелания да бъде много ползотворна.

Всъщност не беше активирана, защото антивирусната просто не се активираше. Аз  я деинсталирах и и итеглих отново. Понякога се случва пак да не се включва, незнам защо.

Сега системата работи малко по- бързо, най вероятно толкова са и възможностите щом няма вируси. Нещо друго трябва ли да направя ?

Благодаря за съдействието от сърце и ви желая много успешна работа.

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.