Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Профилактика на системата

Featured Replies

Ееееее...това не е прекъсване на скрипта.....Трябваше да оставите програмата да си свърши работата...което не става за 1-2 минути...!

  • Автор

Баш си прекъсва, колкото и да се чака

 

2c25a1b9297at.jpg

 

Между другото със същия червен Х не пуска и AVZGuard и AVZPM

 

ComboFix също не стига до края - заплесва се малко преди края във временната директория.

 

Разните глупости из временната директория също ги няма - чистилл съсм ги ръчно преди..

 

Прави ми впечатление че навсякъде са нацвъкани файлчета desktop.ini със следното съдържание

 

.ShellClassInfo]
[email protected],-21774
 
И във временната директория кой знае защо се беше появил Skype инсталатор с днешна дата. А карам на 3.8 със забранени упдейти.
 
И някъкъв странвен llibFNP_events.log си цъка из Temp
 
21:02:15 13-07-2015  [P:3064],[T:3180] Exception: 64, Module: 100000, Location: 1, Internal: 2147942487
21:02:15 13-07-2015  [P:3064],[T:3180] Exception: 64, Module: 100000, Location: 1, Internal: 2147942487
21:29:03 13-07-2015  [P:3268],[T:3304] Exception: 64, Module: 100000, Location: 1, Internal: 2147942487
21:29:03 13-07-2015  [P:3268],[T:3304] Exception: 64, Module: 100000, Location: 1, Internal: 2147942487
 
Успях да пусна AVZPM под Safe Mude и след това скан. Докато AVZ сканираше Dr.Web бастиса следните открити неща - временни файлове при сканиране.
 
BackDoor.Siggen.23493
Trojan.Click2.7410
Trojan.Siggen2.32330
Win32.HLLW.Autoruner.18981
 
Откъде ги измисли, не знам. Първото е предимно немски текст. Другите не съм ги глеедал. И уж имам сериозна програма и внимавам. Това само от C: и D: E: пропуснато, големите хардове F: и G: въобще съм ги откачил  Разгледах някои от описанията. Файл Autorun.inf няма на никое устройство. Поне под Total Commander, който е настроен да показва всички файлове.
 
И лога на AVZ
 
AVZ Antiviral Toolkit log; AVZ version is 4.43
Scanning started at 14.07.2015 00:54:07
Database loaded: signatures - 297605, NN profile(s) - 2, malware removal microprograms - 56, signature database released 02.07.2015 16:00
Heuristic microprograms loaded: 411
PVS microprograms loaded: 9
Digital signatures of system files loaded: 745363
Heuristic analyzer mode: Medium heuristics mode
Malware removal mode: disabled
Windows version is: 5.1.2600, Service Pack 3 "Microsoft Windows XP" ; AVZ is run with administrator rights
System Restore: enabled
1. Searching for Rootkits and other software intercepting API functions
1.1 Searching for user-mode API hooks
 Analysis: kernel32.dll, export table found in section .text
 Analysis: ntdll.dll, export table found in section .text
 Analysis: user32.dll, export table found in section .text
 Analysis: advapi32.dll, export table found in section .text
 Analysis: ws2_32.dll, export table found in section .text
Function ws2_32.dll:WSAConnect (33) intercepted, method - CodeHijack (not defined)
Function ws2_32.dll:connect (4) intercepted, method - CodeHijack (not defined)
Function ws2_32.dll:getpeername (5) intercepted, method - CodeHijack (not defined)
Function ws2_32.dll:getsockname (6) intercepted, method - CodeHijack (not defined)
 Analysis: wininet.dll, export table found in section .text
 Analysis: rasapi32.dll, export table found in section .text
 Analysis: urlmon.dll, export table found in section .text
 Analysis: netapi32.dll, export table found in section .text
1.2 Searching for kernel-mode API hooks
Anti-Rootkit error [Failed to set data for 'DisplayName'], step [14]
2. Scanning RAM
 Number of processes found: 55
 Number of modules loaded: 329
Scanning RAM - complete
3. Scanning disks
Direct reading: C:\WINDOWS\system32\drivers\atapi.sys
4. Checking  Winsock Layered Service Provider (SPI/LSP)
 LSP settings checked. No errors detected
5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs)
6. Searching for opened TCP/UDP ports used by malicious software
 Checking - disabled by user
7. Heuristic system check
Checking - complete
8. Searching for vulnerabilities
>> Services: potentially dangerous service allowed: RemoteRegistry (Remote Registry)
>> Services: potentially dangerous service allowed: TermService (Terminal Services)
>> Services: potentially dangerous service allowed: SSDPSRV (SSDP Discovery Service)
>> Services: potentially dangerous service allowed: TlntSvr (Telnet)
>> Services: potentially dangerous service allowed: Schedule (Task Scheduler)
>> Services: potentially dangerous service allowed: mnmsrvc (NetMeeting Remote Desktop Sharing)
>> Services: potentially dangerous service allowed: RDSessMgr (Remote Desktop Help Session Manager)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
>> Security: sending Remote Assistant queries is enabled
Checking - complete
9. Troubleshooting wizard
 >>  HDD autorun is allowed
 >>  Network drives autorun is allowed
 >>  Removable media autorun is allowed
Checking - complete
Files scanned: 77033, extracted from archives: 53329, malicious software found 0, suspicions - 0
Scanning finished at 14.07.2015 03:09:46
Time of scanning: 02:15:42
If you have a suspicion on presence of viruses or questions on the suspected objects,
For automatic scanning of files from the AVZ quarantine you can use the service http://virusdetector.ru/
 

Редактирано от Филипов (преглед на промените)

  • Автор

Поиграх си с профилактика на хардуера. Смених захранващия блок и RAM - без резултат.  И един кондензатор до RAM. Ще го мъча още - някакви безпричинни запичания и рестартирания.

 

Лога от Combofix:

ComboFix 15-07-12.01 - SF 07.2015 г.  19:10:36.1.1 - x86
Microsoft Windows XP Professional  5.1.2600.3.1251.359.1033.18.3071.2125 [GMT 3:00]
Running from: c:\documents and settings\SF\Desktop\ComboFix.exe
AV: Dr.Web Security Space *Disabled/Updated* {3454C8F1-ECBC-4180-A6F4-04632FBA762B}
FW: Tiny Desktop Firewall 2005 Pro 6.5 *Enabled* {14CB4B80-8E52-45EA-905E-67C1267B4160}
 * Created a new restore point
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\ntuser.pol
c:\documents and settings\SF\Application Data\inst.exe
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\system32\AdobePDF.dll
c:\windows\system32\drivers\etc\hosts.txt
c:\windows\system32\sstray.exe
.
----- File Replicators -----
.
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{017DC594-01BD-487F-BF0B-A297DFA9F3F0}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{01841751-9C72-487F-BEC4-D10BBA03C2C5}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{026DC7CC-A3D5-4D27-8C16-DBB3BACFD29E}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{0A24A022-EFE6-4D58-9566-B7AE510E27BD}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{0D2BFAA2-610F-40E5-A2BF-33D4ECF0EF5B}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{0F254F00-A1DC-4F51-8140-2A37508DB009}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{1368346A-7CEE-474C-AB05-F55EC03242B1}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{13EC54FE-D04C-4C25-819B-94E5B9D2AFAC}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{14C9A602-CC05-41D6-A07C-BC493AA2818C}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{171CE7E1-A79E-4A9D-9350-C7278D2949A0}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{197F122B-9501-445B-8CF9-5D13A0847A30}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{1D9255E0-3514-4D50-B220-B78A4E30DEB9}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{20E03702-8628-43C9-A082-692A0D34AA50}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{23BF9166-5A8D-470C-8B8C-2A0DCCDC0348}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{24D93588-84CB-4D11-A9AB-FBAD5AC5B775}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{24D9AC94-4DDA-4C55-B632-63A479EDD82B}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{278F622B-DCE5-42F3-8108-D7D1EDD38ABE}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{29E06938-76FB-413F-900A-EEE2B8494C47}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{2CAF1E58-4755-4CF8-AC58-3DC9D5C2A0D2}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{2DB43023-F229-4AC9-8302-AE7219CC1EBC}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{341F87D7-DC01-4795-9D67-728A6379DE65}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{36734EDB-B0B3-48FA-84FB-0D02E1C807F9}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{36B36B05-53B9-4265-AC2C-926F0B6BE458}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{3AF2DD66-0AD0-40F8-A1E4-1150BBCD8250}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{3B6AE1BD-2CAB-457E-A735-7FB9A03DB56F}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{3CADEF91-64F9-44DB-B75D-1F01EDEF3E2C}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{3CF406AD-F7AE-4DBA-8E88-DD42AC656892}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{426BAFF0-354F-436B-AE9B-3ACD9E656CC8}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{44819A60-E616-4906-B20A-102426CDA376}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{464408AE-6764-4B5F-BD88-5BCFB98D3576}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{473EEECF-29AE-4F99-9A7D-21366BF15FA9}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{4B0DC1B1-AF96-4EB5-8015-DB22611863DA}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{4D1982E1-59C1-4AAE-9F34-E92B7710CC96}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{4F98CFBA-8394-4AB6-AA97-300E7A3BF9E9}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{4FB0D48B-AD96-472A-A261-CDC17BA37CA0}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{507B0C12-0AFF-42E1-8BEF-6627CCD983E1}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{5411294C-60B8-440E-8CFC-1A748B01566D}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{54283001-FD92-46D1-9B39-6E9AB7C151BB}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{56491B1C-5C2F-4790-9EF5-211BCD66BF6B}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{56CA0668-0CFD-4DD6-880B-C2EEBA63F7F1}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{59669A3D-5991-44E8-A79D-C8E9171D3CE6}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{5C46E8B7-8570-40C6-9394-B1310E802429}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{624FB695-2CD5-43BA-A236-FF7075F14042}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{693D3A68-F6A5-4FE4-A36D-C7AA0A2B0C3D}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{69C42A4A-49DF-44B8-B369-42BC0570B7AD}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{69EBB2C5-4DD2-4ADD-8A14-B3723BC8558E}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{6A4F33ED-A5F2-43AF-9EA7-EEF9BF354A4B}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{6C27C80F-14DA-4301-814E-83267A717CF9}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{6CFF6A9D-7901-426F-BD52-CF979189FFC2}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{71DA52FF-B585-4A21-9310-37664080E620}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{773836D9-EBE0-442C-92A2-0CFAE8E9BCA5}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{7B788D48-D2F3-43AC-A3B2-5F2B79A5A342}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{7E959E0E-71A0-4527-A71C-DC50331309F1}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{7F211EC2-CB10-40FE-9DC6-6069FD27D597}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{80847B2F-855A-4279-B264-64F8C8580305}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{87B857B3-9DA4-464A-B97F-562C10DDE497}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{87FED69E-F187-41C4-AC7F-E26A55AEF45D}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{89BAF436-78C4-4BE9-878D-D4931BC1E86B}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{8B1D92A6-DEFB-423F-86C2-4018D989EB71}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{93F9FB0D-8D5A-4AB6-9CC3-28D04F804512}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{963AA922-E459-4F51-8CEC-F16768A17FD1}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{96D3BAE6-5470-42A3-9D7E-51676A75C62F}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{96E8DA17-2810-4BFC-AFD1-3A1E2CCCFFAB}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{973F6784-FB85-4B1E-A2AE-BBF31A305C83}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{989DC312-A766-46CD-97BD-BCBE0876BCB5}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{9E043D0A-B974-4B1C-A1C2-A0B3A9D64DDA}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{A75E8F1E-6AC8-4354-9B3D-E8CE0F4BCAD1}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{A788FC29-C803-432F-82AB-B6F8C7D2F41A}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{AA52CCF2-0C4A-4935-A6FC-9C356AC00942}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{AC4E2406-AF14-44CB-8A50-D9E6B16A7DA9}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{AD6AE75B-632C-4F1D-8A87-8410D474A95B}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{AFF56D0D-BEA9-4A43-87F4-25808A97643C}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{B3FDDEAD-6EB1-49EB-8FDD-236B23574C0D}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{B5BD6433-AF75-4CF9-85DE-1DC0551DA4D4}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{B6B16879-2041-4490-B142-C8C5D1AFD6E0}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{B70216B2-F46A-46EC-A6AF-74361A66C460}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{B7626104-C085-4827-90C9-54D59921A1DC}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{C0325311-DFAB-4B66-81CA-EA97FD1CE90A}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{C35A04E3-6DC2-49CF-8431-ED6098CA5697}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{C3746E9F-4C8F-4FB5-BC1B-435B06ECF921}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{C3D1D9F9-0629-42CA-9C07-C896F4F32E80}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{C907561C-2B30-4CB7-8434-676EA4CA1031}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{D0454209-C73F-4C8E-BB04-BD879544ABD9}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{DB5CCC93-191F-46FE-BA66-0E28A7D026BC}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{DCABB799-8F5F-402D-8C93-AE07445C01B2}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{DDA2DEFC-753E-4FE6-845F-F3BAECFBBF0B}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{DFFFC6FD-0DEC-450E-972C-00355C3222E1}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{E1D0B97F-147B-46DC-A273-E5CFD3952206}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{E214EEF7-6647-4109-BA21-DA142E761D3F}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{E224DBE0-C387-44B2-9602-0E21EFF91489}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{E4396452-9C7B-4E45-99B9-BD2E03131234}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{E53E213E-CB1F-41C9-800C-BD45AE096A14}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{E69C9D9E-8DDD-4FCC-8BEF-E04E1E2AA64E}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{EC645DBD-209A-4581-9E9D-C1848953E241}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{F45D572B-D5D1-4FF2-B4E0-EF1F671D81ED}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{F466F0E0-F25F-4C33-B82A-91DD867D98B7}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{F5C68E09-7132-4497-800A-8E3565A93B75}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{F7768003-D9DC-4166-8C15-ACBB40C09BAF}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{FA428212-6DAB-4DA6-A9C1-B837FD2141BD}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{FDD40570-A260-4BE7-80AA-151C173AB3C7}\GoogleUpdateSetup.exe
c:\documents and settings\SF\Local Settings\Application Data\Google\Update\Install\{FED7D331-1835-4906-AACB-A0C9204F71E2}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{0859E1AB-DD6E-4736-BA8F-1BAE0007618D}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{09D8A367-73E1-4520-B298-89D9599F5C08}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{09EF2047-1E4E-4213-8752-4CD9D3A4F5DC}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{0F176C2A-DD5E-45AC-A732-2937F14B7AC2}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{10F53BB6-38A2-49B2-8F03-F37C5A68F426}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{11A2DB35-54BD-4357-88BD-9FFDD032F73B}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{1346F358-F9C5-4BA8-A0F3-FBBA05775688}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{179A8688-5725-406F-9638-431B59817B1B}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{1AD2A4C4-9B64-4730-B0C3-CC4113BBF1C8}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{1E63B1FA-9106-44EC-96E1-C26D061EC7F4}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{22C0511E-9125-4229-A590-01FF6E6A1E42}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{2717800B-2FB6-40D8-8427-18C6EF6CBB24}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{2B11A290-AE1B-4FF4-B724-A3FBE299DF27}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{2B6BE889-7CC5-426B-8298-FF0D25902807}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{34F29464-B3E4-4A55-8E34-C1B8B9E9E9B9}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{3500045E-7940-43CE-893F-EC464AA49780}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{35B8BAD4-C9DE-457B-9644-812DE1B8D8F9}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{37566C37-FAEF-43C8-9ADF-9AA7BD29A0E0}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{3980F327-A26C-4ABA-A300-9EDD0AF06251}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{3A6293B2-C2F2-4DC7-BA62-C30A1906304A}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{3B9A5CD5-03B6-49A6-8171-56628816AB8B}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{4304A734-FC91-4D13-918E-B7E30B50D0D2}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{47093379-1D43-4766-9795-5A70C2EE7AB9}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{4717D043-6869-424F-BEAF-27A63EDAE8E1}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{483F53F0-C743-4DB8-B972-59DE8EA60AF4}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{4941EF8D-3628-4AE9-86C8-9B0B2B3BC2A6}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{49A377D5-DF22-4085-95BB-2418346C9B5B}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{4B6C1AA3-CC7D-4748-9BD4-28A3661AD68D}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{4B95C560-8766-4EF6-BA07-2FDF5430E2A5}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{4D7BA8AB-E811-4D1C-BE5E-7AED9B7290AC}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{4EFCFCC5-4EDC-4A41-BA4E-F2958CD48352}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{50254D4F-6253-4FA0-B62B-6FD9C7BF06A5}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{50AF5BB3-7851-4CDF-B34B-C9232A9706A1}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{55D20EDA-D891-4365-BDC8-E548052C0A20}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{5694767F-2B59-446C-B6B9-6DED9E8C102E}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{57222E9E-F859-47ED-A892-9ED5A4A64515}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{5A0B66EA-B57E-4976-B193-640547909CA8}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{5A7646CF-2639-4808-AA76-45249A1C3556}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{5ACD360E-F881-437C-BE4D-17924629380A}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{5C2084AB-C8BF-4C4E-AFD9-4B3FF3F471B5}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{5F58BDBA-18CC-4559-B8EB-6069585B7CBC}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{5FFE511F-B839-4CC7-9D5E-4D48F42C58E3}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{6336701F-28DE-48F1-A798-55C46ECB5400}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{638AAB02-110A-408E-B60D-05C3CB8367C9}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{64ED4359-2614-4C47-9D02-5C44F4AAE670}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{659B047B-475B-421A-9092-27C74101906D}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{668486E4-8312-4D4C-A6DA-FAB1193C03C5}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{6903F269-6283-4F47-A4B2-EA09394486F9}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{6AFD759C-2E59-46C1-9BCE-EFF9B1E029C5}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{6FAB73E8-5C77-4BD3-A95C-D3C1A6974B62}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{70CE94AF-84BD-4104-A399-A935CE8246B6}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{7511C2BD-4F17-42BA-84E9-BA71D2B7960E}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{7DED7C64-9575-4CD1-AFDC-A2B29BBC5F99}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{7E9DF783-8C2D-4641-8D74-2CE4FA84C1BA}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{7F756A22-D8DE-4414-B278-AE2302F01370}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{81908F4B-2CC6-43A4-858F-0B834DB3B087}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{821C59A6-7AD1-4DFF-8D58-B73EEAB1A3B1}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{914A76F5-2A27-40DE-9F7A-5089A56F8BAD}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{921049BB-76E3-4B8B-A1FF-2256B39CCAF5}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{94BB925F-F97F-4091-81BF-D60BD8F6D841}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{999CA00D-56F8-42B6-BEBE-D2B2A2349B99}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{9BAA651D-BB30-4485-86E3-B2884520CD0D}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{9BFAC0CA-CC6E-4647-B753-2182C2083BC5}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{9C298EAE-A1D9-47CE-9BB9-60E7523E4DD9}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{9C71D7CD-96D4-4B4E-895B-76F51FD622AA}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{9E851450-690B-443B-9730-6B8128D0B0B7}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{A483BA63-CCAC-4C44-9728-F777E2421F65}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{AB4CE922-1570-4E92-B8A5-5CF2DC2CC5B1}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{ABFBF808-7670-4CED-A3CD-BE774C635D2C}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{ACA7620B-1D04-4A9D-8BEA-0F65A9AF0869}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{ACB11C1A-9A3C-46A0-B597-CC4A218E5EE3}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{B43B3B98-C097-4581-BC3F-393BCDD4F7F6}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{B82E8341-C475-4659-B31F-C51A6E70A5C6}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{B8BAADDB-946A-419A-B5E4-1E596AE5C095}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{B8D944B1-E679-4494-843B-EDD13D910005}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{B9CE994C-88C0-4034-8141-0A6AA33DBC24}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{BBBAA45D-4A34-446A-92B8-1EBC9B5C157F}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{C20EE0C3-F116-4AB0-BDA0-C97683015800}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{C3D61E9E-9F1D-4F59-A969-2F2A12B24DDC}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{C4FA00D3-B538-4D65-BCC9-47F6054FDF06}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{C54C0595-5062-4F43-B8AF-479921B3F90F}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{C920545D-C742-4771-B8AA-6408395A2CF0}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{CB751673-1752-4893-8CC4-55879C303440}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{CE580417-C725-4BB3-85E8-9CD44303103F}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{CFAD0248-2C1C-4466-AAA8-09FF0D4ADA46}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{CFF4D0BA-44AA-40CC-B0F6-B0C2F07612D1}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{D18776EE-3D5D-4E2D-8692-D62BFEBEE3B4}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{D2CB050A-198B-4A79-9DFE-CCF50133CDD0}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{D5538D75-5385-46A1-BFDF-E6A578E22B70}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{D5FDD97B-7944-44AA-B581-6A8098E4A661}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{D903FC26-03BB-4429-A62D-BFD61BD3396C}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{D9783F7A-0921-4F76-9193-D06E3DBFB4B4}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{E0B735D7-C466-4763-8003-D95A81D3D9BC}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{E15F6612-D78C-4AE3-9912-DB835D2D355B}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{E35B0722-6A8D-4019-8717-A86FC7DE9771}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{E6B6C416-178D-4A36-B103-710B5170099D}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{E74CFF75-0A84-47D6-A65E-6E7D11E96FB2}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{ED6F09C1-D39B-4CBF-9B41-905D1AAAB735}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{EE495DD0-7C57-4E54-BBAC-C62332DC78A1}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{EF576C6B-7547-451A-9A48-2650622C8EDA}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{F1F30288-C1E4-42DE-9C9F-7AD35868328C}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{F2346D00-538D-4EF4-A166-5FB0098ADCD2}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{F6FE5BC2-C2D9-4ACD-834B-F88839D1D76C}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{FAC92321-3954-4673-9C92-F26A51455E10}\GoogleUpdateSetup.exe
c:\program files\GUMD.tmp\GoogleUpdateSetup.exe
.
.
(((((((((((((((((((((((((   Files Created from 2015-06-20 to 2015-07-20  )))))))))))))))))))))))))))))))
.
.
2015-07-20 15:35 . 2015-07-20 16:23 36 ----a-w- c:\windows\system32\drivers\Ids_cfg.dat
2015-07-14 22:40 . 2015-07-14 22:40 18524336 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2015-07-06 20:49 . 2015-07-06 20:51 -------- d-----w- c:\program files\trend micro
2015-07-06 20:48 . 2015-07-06 20:54 -------- d-----w- C:\rsit
2015-07-05 13:02 . 2015-07-05 13:02 -------- d-----w- C:\Device
2015-07-05 12:42 . 2015-07-05 12:44 -------- d-----w- C:\AdwCleaner
2015-07-05 12:30 . 2015-07-05 12:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2015-07-05 11:19 . 2015-07-04 15:21 2244096 ----a-w- C:\AC.exe
2015-07-05 09:19 . 2015-07-20 16:19 -------- d-----w- c:\program files\GUMD.tmp
2015-07-05 09:19 . 2015-07-05 09:19 6420480 ----a-w- c:\program files\GUTE.tmp
2015-07-04 05:10 . 2015-07-04 05:10 0 ----a-w- c:\program files\GUM6F.tmp
2015-07-03 19:56 . 2015-07-03 16:58 165539768 ----a-w- C:\81yjf7jc.exe
2015-07-03 04:10 . 2015-07-03 04:10 -------- d-----w- C:\RegBackup
2015-07-01 19:14 . 2015-07-01 19:14 -------- d-----w- c:\program files\GUM10.tmp
2015-06-25 19:42 . 2015-06-25 20:13 -------- d-----w- C:\FRST_
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-07-16 18:24 . 2015-05-06 17:19 292440 ----a-w- c:\windows\system32\drivers\dwprot.sys
2015-07-14 22:40 . 2012-03-31 19:12 778416 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2015-07-14 22:40 . 2011-05-15 07:38 142512 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2015-05-25 18:14 . 2015-05-06 17:19 73920 ----a-w- c:\windows\system32\drivers\dwdg.sys
2015-05-06 17:19 . 2015-05-06 17:19 65680 ----a-w- c:\windows\system32\drivers\dw_wfp.sys
2015-05-06 17:19 . 2015-05-06 17:19 181552 ----a-w- c:\windows\system32\drivers\spiderg3.sys
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2008-04-23 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys
[7] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\atapi.sys
[-] 2008-04-13 21:10 . !HASH: COULD NOT OPEN FILE !!!!! . 96512 . . [------] . . c:\windows\system32\drivers\atapi.sys
.
[-] 2012-08-21 . 2F8C2B6E052A4C6EC5575EA10F8E5191 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys
[-] 2012-08-21 . 2F8C2B6E052A4C6EC5575EA10F8E5191 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\MESSEN~1\YahooMessenger.exe" [2012-05-25 6595928]
"Skype"="c:\programs\Skype\Phone\Skype.exe" [2014-08-19 21633320]
"AdMuncher"="c:\programs\AdMuncher\Admunch.exe" [2015-05-06 926328]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\programs\ATI\atiptaxx.exe" [2003-06-05 335872]
"RemoteControl"="c:\programs\PowerDVD\PDVDServ.exe" [2007-03-14 71216]
"LanguageShortcut"="c:\programs\PowerDVD\Language\Language.exe" [2007-01-08 52256]
"Acrobat Assistant 8.0"="c:\programs\Adobe\Acrobat8\Acrobat\Acrotray.exe" [2011-08-30 624056]
"Adobe Acrobat Speed Launcher"="c:\programs\Adobe\Acrobat8\Acrobat\Acrobat_sl.exe" [2011-08-30 46520]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-29 937920]
"SpIDerAgent"="c:\program files\DrWeb\spideragent.exe" [2015-07-16 14281872]
"Ad Muncher"="c:\programs\AdMuncher\AdMunch.exe" [2015-05-06 926328]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-23 15360]
.
c:\documents and settings\SF\Start Menu\Programs\Startup\
PC-Telephone.lnk - c:\programs\PC-Telephone\PCTel.exe [2008-10-10 798720]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
2005-07-11 20:26 73728 ----a-w- c:\windows\system32\UmxWNP.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\UmxSbxExw.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DrWebEngine]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TinyFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programs\\AdMuncher\\AdMunch.exe"=
"c:\\Programs\\BitComet\\BitComet.exe"=
"c:\\Programs\\PC-Telephone\\PCTel.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Programs\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Programs\\TotalCmd\\TOTALCMD.EXE"=
"c:\\Programs\\eMule\\emule.exe"=
"c:\\Program Files\\DrWeb\\spideragent.exe"=
"c:\\Program Files\\DrWeb\\dwservice.exe"=
"c:\\Program Files\\DrWeb\\dwnetfilter.exe"=
"c:\\Programs\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"20699:TCP"= 20699:TCP:BitComet 20699 TCP
"20699:UDP"= 20699:UDP:BitComet 20699 UDP
"14470:TCP"= 14470:TCP:BitComet 14470 TCP(ED2K)
"14470:UDP"= 14470:UDP:BitComet 14470 UDP(ED2K)
.
R0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [08.1.2010 г. 00:31 160640]
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [08.1.2010 г. 00:31 5248]
R0 DwDevGuard;Dr.Web Device Guard;c:\windows\system32\drivers\dwdg.sys [06.5.2015 г. 20:19 73920]
R0 DwProt;DrWeb Protection;c:\windows\system32\drivers\dwprot.sys [06.5.2015 г. 20:19 292440]
R0 KmxNdis;KmxNdis;c:\windows\system32\drivers\KmxNdis.sys [16.8.2005 г. 11:42 90624]
R0 PzWDM;PzWDM;c:\windows\system32\drivers\PzWDM.sys [10.10.2008 г. 08:27 15172]
R0 SI3112r;Silicon Image SiI 3512 SATARaid Controller;c:\windows\system32\drivers\SI3112r.sys [23.10.2009 г. 14:10 110128]
R0 SpiderG3;DrWeb file system scanner;c:\windows\system32\drivers\spiderg3.sys [06.5.2015 г. 20:19 181552]
R1 DrWebWfp;DrWebWfp;c:\windows\system32\drivers\dw_wfp.sys [06.5.2015 г. 20:19 65680]
R1 KmxAgent;KmxAgent;c:\windows\system32\drivers\KmxAgent.sys [11.7.2005 г. 18:39 65536]
R1 KmxFile;KmxFile;c:\windows\system32\drivers\KmxFile.sys [11.7.2005 г. 23:20 44544]
R1 KmxFw;KmxFw;c:\windows\system32\drivers\KmxFw.sys [16.8.2005 г. 11:42 98816]
R1 KmxIds;KmxIds;c:\windows\system32\drivers\KmxIds.sys [11.8.2005 г. 14:31 95744]
R2 DrWebAVService;Dr.Web Control Service;c:\program files\DrWeb\dwservice.exe [06.5.2015 г. 20:18 10054288]
R2 KmxBiG;KmxBiG;c:\windows\system32\drivers\KmxBiG.sys [11.7.2005 г. 23:21 15872]
R2 KmxSbx;KmxSbx;c:\windows\system32\drivers\KmxSbx.sys [23.8.2005 г. 22:50 54272]
R2 UmxCfg;FW Configuration Interpreter;c:\program files\Common Files\PFShared\UmxCfg.exe [12.7.2005 г. 16:57 516096]
R2 UmxPol;FW Policy Manager;c:\program files\Common Files\PFShared\UmxPol.exe [12.7.2005 г. 00:21 196679]
R3 DrWebEngine;Dr.Web Scanning Engine (DrWebEngine);c:\program files\Common Files\Doctor Web\Scanning Engine\dwengine.exe [06.5.2015 г. 20:18 2128784]
R3 DrWebNetFilter;Dr.Web Net Filtering Service;c:\program files\DrWeb\dwnetfilter.exe [06.5.2015 г. 20:19 4435088]
R3 KmxCfg;KmxCfg;c:\windows\system32\drivers\KmxCfg.sys [23.8.2005 г. 12:41 64896]
R3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [16.7.2009 г. 21:46 47360]
S1 aswKbd;aswKbd; [x]
S1 uzi2mtc1;AVZ-RK Kernel Driver;\??\c:\windows\system32\Drivers\uzi2mtc1.sys --> c:\windows\system32\Drivers\uzi2mtc1.sys [?]
S2 UmxAgent;FW Event Manager;c:\programs\Tiny\UmxAgent.exe [22.8.2005 г. 09:51 405504]
S3 4F97EEDD1F9ACC88;4F97EEDD1F9ACC88;\??\c:\windows\TEMP\96ADDF9.sys --> c:\windows\TEMP\96ADDF9.sys [?]
S3 4F97EEDDCFCBF488;4F97EEDDCFCBF488;\??\c:\windows\TEMP\9B2F093.sys --> c:\windows\TEMP\9B2F093.sys [?]
S3 B5D43D8;B5D43D8;\??\c:\windows\TEMP\B5D43D8.sys --> c:\windows\TEMP\B5D43D8.sys [?]
S3 B882E31;B882E31;\??\c:\windows\TEMP\B882E31.sys --> c:\windows\TEMP\B882E31.sys [?]
S3 BA1094D;BA1094D;\??\c:\windows\TEMP\BA1094D.sys --> c:\windows\TEMP\BA1094D.sys [?]
S3 BCEFE0D;BCEFE0D;\??\c:\windows\TEMP\BCEFE0D.sys --> c:\windows\TEMP\BCEFE0D.sys [?]
S3 BD506A8;BD506A8;\??\c:\windows\TEMP\BD506A8.sys --> c:\windows\TEMP\BD506A8.sys [?]
S3 BDFBB86;BDFBB86;\??\c:\windows\TEMP\BDFBB86.sys --> c:\windows\TEMP\BDFBB86.sys [?]
S3 C6CD702;C6CD702;\??\c:\windows\TEMP\C6CD702.sys --> c:\windows\TEMP\C6CD702.sys [?]
S3 CAB1A63;CAB1A63;\??\c:\windows\TEMP\CAB1A63.sys --> c:\windows\TEMP\CAB1A63.sys [?]
S3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\System32\svchost.exe -k nosGetPlusHelper [23.4.2008 г. 09:36 14336]
S3 UmxLU;FW Live Update;c:\program files\Common Files\PFShared\umxlu.exe [12.7.2005 г. 12:24 98304]
S3 W840ND;Winbond W89C840 Based PCI Fast Ethernet Adapter;c:\windows\system32\drivers\W840ND.sys [17.10.2003 г. 03:25 19528]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - 4F97904018EC8288
*Deregistered* - 4F97904018EC8288
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
nosGetPlusHelper REG_MULTI_SZ   nosGetPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
2015-07-20 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-31 22:40]
.
2015-05-06 c:\windows\Tasks\Dr.Web Daily scan.job
- c:\program files\DrWeb\dwscanner.exe [2015-05-06 17:27]
.
2015-07-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2014-10-14 19:51]
.
2015-07-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2014-10-14 19:51]
.
2015-07-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1214440339-1454471165-1417001333-1003Core.job
- c:\documents and settings\SF\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2014-10-20 19:06]
.
2015-07-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1214440339-1454471165-1417001333-1003UA.job
- c:\documents and settings\SF\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2014-10-20 19:06]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://forum.eshop.bg/
uInternet Connection Wizard,ShellNext = iexplore
IE: Append to existing PDF - c:\programs\Adobe\Acrobat8\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\programs\Adobe\Acrobat8\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\programs\Adobe\Acrobat8\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\programs\Adobe\Acrobat8\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\programs\Adobe\Acrobat8\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\programs\Adobe\Acrobat8\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\programs\Adobe\Acrobat8\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\programs\Adobe\Acrobat8\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Закачать ВСЕ при помощи Download Master - c:\programs\Download Master\dmieall.htm
IE: Закачать при помощи Download Master - c:\programs\Download Master\dmie.htm
IE: Передать на удаленную закачку DM - c:\programs\Download Master\remdown.htm
TCP: Interfaces\{1BAE07C3-3704-4C9C-933F-0FA4115822D2}: NameServer = 8.8.4.4
TCP: Interfaces\{9952F822-DF51-4F38-8234-72E948E98242}: NameServer = 8.8.8.8
TCP: Interfaces\{A6AAA78F-D1FE-4032-B010-39355BAA711F}: NameServer = 8.8.8.8
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
HKLM-Run-nForce Tray Options - sstray.exe
AddRemove-1Click DVD to Divx Avi 2.12_is1 - c:\programs\1Click DVD to Divx Avi\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2015-07-20 19:24
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...  
.
scanning hidden autostart entries ... 
.
scanning hidden files ...  
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_18_0_0_209_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_18_0_0_209_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(612)
c:\windows\system32\UmxWnp.Dll
.
- - - - - - - > 'explorer.exe'(3788)
c:\windows\system32\WININET.dll
c:\programs\AdMuncher\AM32-34121.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
- - - - - - - > 'explorer.exe'(2384)
c:\windows\system32\WININET.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\jscript.dll
.
------------------------ Other Running Processes ------------------------
.
c:\programs\Tiny\UmxFwHlp.exe
c:\programs\Tiny\UmxTray.exe
c:\windows\system32\bgsvcgen.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\msdtc.exe
c:\windows\system32\msiexec.exe
c:\windows\notepad.exe
c:\windows\system32\msiexec.exe
c:\programs\TotalCmd\TOTALCMD.EXE
c:\windows\system32\dllhost.exe
c:\windows\system32\dllhost.exe
.
**************************************************************************
.
Completion time: 2015-07-20  19:35:27 - machine was rebooted
ComboFix-quarantined-files.txt  2015-07-20 16:33
.
Pre-Run: 10 081 513 472 bytes free
Post-Run: 10 178 170 880 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 974970161E995F44F2442A724F03B1D7
8F558EB6672622401DA993E1E865C861

На първо четене ми е махнал няколкото стартови страници.
  • Автор

Скед като го минах с Combofix почнаха едни рестартирания, успивания и какво ли не още. Скъсах се да ровя хардуера. Дори и при опит да напиша нещо в този форум директен рестарт като хардуерен ресет. Предния ми пост е от другия компютър.

 

Закачих друг хард с инстаслирана ОС, който е работил преди на компютъра - всичко е наред.

Майната му - нямам нерви. Формат и инсталация - всичко си е наред. Жалко за загубеното време - и мое, и на HJT.

 

Бахта в гадинката злобна че и не я разбрах как се казва. Нито откъде е дошла. Че и нищо не я хваща. А уж внимавам и не ходя по съмнителни места.

 

Не знам защо постовете са с премодерация, дори и след размаркиране на темата. Вероятно бъг във форумния софтуер.

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.