Премини към съдържанието

    Препоръчан отговор

    tangra_es    0

    здрасти,преди доста време ми се зараси системата със рууткит.в началото не обръщах внимание /поради заетост/ но с времето компа ставаше все по бавен и искам не искам трябва да направя нещо :)

    интересното /поне за мен/ е,че открих рууткита съвсем случайно.получи се някакъв бъг,компа се рестартира и после ми изписа,че имам руткит във скайп.и наистина бях забелязал преди това,че скайп работи мн по бавно от преди и пречи на цялата система.

    до преди няколко месеца използвах аваст,сега комодо драгон.ползвам сс клиинър.чрез аваст-а хващах мн троянци,когато го пусках да сканира извън ОС.с комодо не хваща никакви "престъпници" :)

    случват се и други странни неща със системата,постоянно спират да работят 2-3 плъгина,системата за контролиране на екрана по някога изключва.бях инсталирал на мозила имакрос и един скрипт заради една игра :) имакрос-а е изтрит,но скрипта си стои.

    имам огромен проблем с адобе системите,плъгини или каквото там е :) те ми се изключват постоянно и направо съм изнервен :)

    почнах да чета по форуми за различни темии в една жидях,че е възможно да се заменят с други,по леки.обаче ще моа ли сам да се справя с всичко?уча се бързо,но не ми се струва най лесно :)

    благодаря,че помагате на лаици като мен :)

     

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:19-12-2015
    Ran by rainbow (administrator) on RAINBOW-PC (20-12-2015 13:32:39)
    Running from C:\Users\rainbow\Desktop
    Loaded Profiles: rainbow (Available Profiles: rainbow)
    Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Español (España, internacional)
    Internet Explorer Version 11 (Default browser: FF)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe
    (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
    (AMD) C:\Windows\System32\atiesrxx.exe
    (AMD) C:\Windows\System32\atieclxx.exe
    (Microsoft Corporation) C:\Windows\System32\wlanext.exe
    (Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
    (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
    (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
    (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
    (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
    (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
    (Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe
    (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
    (Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
    (Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
    (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
    (NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
    (NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
    (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
    (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
    (AdTrustMedia) C:\Program Files (x86)\AdTrustMedia\PrivDog\1.8.0.15\trustedadssvc.exe
    (Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe
    (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
    (Skillbrains) C:\Program Files (x86)\Skillbrains\lightshot\5.3.0.0\Lightshot.exe
    (Comodo Security Solutions, Inc.) C:\Program Files\COMODO\GeekBuddy\unit_manager.exe
    (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
    (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
    (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
    (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
    (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
    (Comodo Security Solutions, Inc.) C:\Program Files\COMODO\GeekBuddy\unit.exe
    (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
    (Egis Technology Inc.) C:\Program Files\EgisTec IPS\PmmUpdate.exe
    (Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe
    (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
    (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_20_0_0_235.exe
    (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_20_0_0_235.exe
    (www.BitComet.com) C:\Program Files (x86)\BitComet\BitComet.exe
    (BrowserGameBots.com) C:\Users\rainbow\AppData\Local\BrowserGameBots\MosWar\MoswarAssist.exe


    ==================== Registry (Whitelisted) ===========================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
    HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2588968 2010-11-12] (ELAN Microelectronics Corp.)
    HKLM\...\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1831016 2011-08-02] (Acer Incorporated)
    HKLM\...\Run: [COMODO Internet Security] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1427648 2015-08-05] (COMODO)
    HKLM-x32\...\Run: [SuiteTray] => C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [341360 2011-06-21] (Egis Technology Inc.)
    HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [297280 2011-04-24] (NTI Corporation)
    HKLM-x32\...\Run: [OOTag] => C:\Program Files (x86)\Acer\OOBEOffer\OOTag.exe [13856 2010-02-23] (Microsoft)
    HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-02-08] (Advanced Micro Devices, Inc.)
    HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1103440 2011-07-01] (Dritek System Inc.)
    HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
    HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-04-18] (Apple Inc.)
    HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [226560 2014-11-18] ()
    HKLM-x32\...\Run: [PrivDogService] => C:\Program Files (x86)\AdTrustMedia\PrivDog\1.8.0.15\trustedadssvc.exe [525480 2013-11-15] (AdTrustMedia)
    HKLM-x32\...\Run: [tvncontrol] => C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2015-11-27] (Comodo Security Solutions, Inc.)
    HKU\S-1-5-19\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
    HKU\S-1-5-20\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
    HKU\S-1-5-21-682783902-3490664518-2871107328-1000\...\Run: [Facebook Update] => C:\Users\rainbow\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-12-02] (Facebook Inc.)
    HKU\S-1-5-21-682783902-3490664518-2871107328-1000\...\Run: [Google Update] => C:\Users\rainbow\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc.)
    HKU\S-1-5-21-682783902-3490664518-2871107328-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8591272 2015-11-26] (Piriform Ltd)
    HKU\S-1-5-21-682783902-3490664518-2871107328-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [50378880 2015-12-17] (Skype Technologies S.A.)
    HKU\S-1-5-21-682783902-3490664518-2871107328-1000\...\MountPoints2: {2f68ac7c-0f85-11e5-8518-dc0ea10d7285} - F:\startme.exe
    HKU\S-1-5-21-682783902-3490664518-2871107328-1000\...\MountPoints2: {8334b410-5ec7-11e2-bef6-dc0ea10d7285} - F:\Startme.exe
    HKU\S-1-5-21-682783902-3490664518-2871107328-1000\...\MountPoints2: {b1104139-5dbb-11e2-a01d-9439e5751637} - F:\Startme.exe
    HKU\S-1-5-21-682783902-3490664518-2871107328-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\System32\Acer.scr [450048 2011-09-13] ()
    HKU\S-1-5-18\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
    ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk [2015-11-27]
    ShortcutTarget: Start GeekBuddy.lnk -> C:\Program Files\COMODO\GeekBuddy\launcher.exe (Comodo Security Solutions, Inc.)

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
    Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
    Tcpip\..\Interfaces\{24D67366-E2F2-436B-B0D0-7C1951A1B46E}: [DhcpNameServer] 192.168.0.1

    Internet Explorer:
    ==================
    HKU\S-1-5-21-682783902-3490664518-2871107328-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://us.yahoo.com?fr=fp-comodo
    HKU\S-1-5-21-682783902-3490664518-2871107328-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com
    SearchScopes: HKU\S-1-5-21-682783902-3490664518-2871107328-1000 -> DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3323878&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SP9742052B-BFA5-422C-A5BB-A64943E86CCE&q={searchTerms}&SSPV=
    SearchScopes: HKU\S-1-5-21-682783902-3490664518-2871107328-1000 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3323878&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SP9742052B-BFA5-422C-A5BB-A64943E86CCE&q={searchTerms}&SSPV=
    SearchScopes: HKU\S-1-5-21-682783902-3490664518-2871107328-1000 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://search.babylon.com/?q={searchTerms}&affID=118565&tt=0113_8&babsrc=SP_ss&mntrId=88f75a300000000000009439e5751637
    SearchScopes: HKU\S-1-5-21-682783902-3490664518-2871107328-1000 -> {8EEAC88A-079B-4b2c-80C1-7836F79EB40A} URL = hxxp://us.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo
    SearchScopes: HKU\S-1-5-21-682783902-3490664518-2871107328-1000 -> {D5E820D6-7779-47CE-8ADD-CED0617CB15E} URL = hxxp://www.mysearchresults.com/search?c=2408&t=14&q={searchTerms}
    BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29] (Microsoft Corp.)
    BHO: PrivDog Extension -> {FB16E5C3-A9E2-47A2-8EFC-319E775E62CC} -> C:\Program Files\AdTrustMedia\PrivDog\1.8.0.15\trustedads.dll [2013-11-15] (AdTrustMedia)
    BHO-x32: BitComet Helper -> {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} -> C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.5.4.11.dll [2011-04-11] (BitComet)
    BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29] (Microsoft Corp.)
    BHO-x32: PrivDog Extension -> {FB16E5C3-A9E2-47A2-8EFC-319E775E62CC} -> C:\Program Files (x86)\AdTrustMedia\PrivDog\1.8.0.15\trustedads.dll [2013-11-15] (AdTrustMedia)
    Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File
    Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File

    FireFox:
    ========
    FF ProfilePath: C:\Users\rainbow\AppData\Roaming\Mozilla\Firefox\Profiles\co4kszya.default
    FF Homepage: hxxp://www.google.es/
    FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_20_0_0_235.dll [2015-12-09] ()
    FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation)
    FF Plugin: @videolan.org/vlc,version=2.2.0-git-20130801-0403 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2013-08-01] (VideoLAN)
    FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_235.dll [2015-12-09] ()
    FF Plugin-x32: @java.com/DTPlugin,version=10.4.1 -> C:\Windows\SysWOW64\npDeployJava1.dll [2012-04-04] (Oracle Corporation)
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-02] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-02] (Google Inc.)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
    FF Plugin HKU\S-1-5-21-682783902-3490664518-2871107328-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\rainbow\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
    FF Plugin HKU\S-1-5-21-682783902-3490664518-2871107328-1000: @talk.google.com/GoogleTalkPlugin -> C:\Users\rainbow\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
    FF Plugin HKU\S-1-5-21-682783902-3490664518-2871107328-1000: @talk.google.com/O1DPlugin -> C:\Users\rainbow\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-12-08] (Google)
    FF Plugin HKU\S-1-5-21-682783902-3490664518-2871107328-1000: @tools.google.com/Google Update;version=3 -> C:\Users\rainbow\AppData\Local\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-04] (Google Inc.)
    FF Plugin HKU\S-1-5-21-682783902-3490664518-2871107328-1000: @tools.google.com/Google Update;version=9 -> C:\Users\rainbow\AppData\Local\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-04] (Google Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npBitCometAgent.dll [2012-01-12] (BitComet)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll [2011-12-09] (Nullsoft, Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Users\rainbow\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
    FF Plugin ProgramFiles/Appdata: C:\Users\rainbow\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-12-08] (Google)
    FF Extension: Greasemonkey - C:\Users\rainbow\AppData\Roaming\Mozilla\Firefox\Profiles\co4kszya.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2015-12-15]
    FF Extension: Adblock Plus - C:\Users\rainbow\AppData\Roaming\Mozilla\Firefox\Profiles\co4kszya.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-12-16]
    FF HKLM-x32\...\Firefox\Extensions: [bubbledock@nosibay.com] - C:\Program Files (x86)\Nosibay\Bubble Dock\extensions\FFSurfMatch
    FF Extension: Bubble Dock - C:\Program Files (x86)\Nosibay\Bubble Dock\extensions\FFSurfMatch [2013-01-06] [not signed]

    Chrome:
    =======
    CHR HomePage: Default -> hxxps://es.search.yahoo.com/?type=198484&fr=yo-yhp-ch
    CHR StartupUrls: Default -> "hxxp://google.es/"
    CHR Profile: C:\Users\rainbow\AppData\Local\Google\Chrome\User Data\Default
    CHR Extension: (YouTube) - C:\Users\rainbow\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-29]
    CHR Extension: (PrivDog) - C:\Users\rainbow\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmaiofennmphjldldcpphcechfnnohja [2015-05-06] [UpdateUrl: hxxp://privdog.com/updates/865/googlechrome/update.xml] <==== ATTENTION
    CHR Extension: (Búsqueda de Google) - C:\Users\rainbow\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-02]
    CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\rainbow\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-30]
    CHR Extension: (Gmail) - C:\Users\rainbow\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-03]
    CHR HKLM-x32\...\Chrome\Extension: [cmaiofennmphjldldcpphcechfnnohja] - C:\Program Files (x86)\AdTrustMedia\PrivDog\PrivDog_chrome.crx [2015-05-05]
    CHR HKLM-x32\...\Chrome\Extension: [kbjlipmgfoamgjaogmbihaffnpkpjajp] - C:\Program Files (x86)\Nosibay\Bubble Dock\extensions\GCSurfMatch.crx [2012-11-06]

    ==================== Services (Whitelisted) ========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S3 BITCOMET_HELPER_SERVICE; C:\Program Files (x86)\BitComet\tools\BitCometService.exe [1296728 2010-12-28] (www.BitComet.com)
    R2 CLPSLauncher; C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe [70848 2015-11-27] (Comodo Security Solutions, Inc.)
    R2 cmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [5542472 2015-09-07] (COMODO)
    S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2265792 2015-08-05] (COMODO)
    R2 DragonUpdater; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [2056376 2015-11-26] (Comodo)
    R2 GeekBuddyRSP; C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2015-11-27] (Comodo Security Solutions, Inc.)
    R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [256832 2011-04-24] (NTI Corporation)
    R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-10-08] (TeamViewer GmbH)
    S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

    ===================== Drivers (Whitelisted) ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S3 AVerAF35; C:\Windows\System32\Drivers\AVerAF35.sys [511232 2009-10-19] (AVerMedia TECHNOLOGIES, Inc.) [File not signed]
    R1 CFRMD; C:\Windows\System32\DRIVERS\CFRMD.sys [37976 2015-10-20] (Windows (R) Win 7 DDK provider) [File not signed]
    R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [21184 2015-11-18] (COMODO)
    R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [806032 2015-11-18] (COMODO)
    R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [45856 2015-08-05] (COMODO)
    S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
    R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [105096 2015-08-05] (COMODO)
    S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited)
    S3 netr28ux; system32\DRIVERS\netr28ux.sys [X]

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2015-12-20 13:32 - 2015-12-20 13:33 - 00018967 _____ C:\Users\rainbow\Desktop\FRST.txt
    2015-12-20 13:32 - 2015-12-20 13:32 - 00000000 ____D C:\FRST
    2015-12-20 13:27 - 2015-12-20 13:24 - 02370048 _____ (Farbar) C:\Users\rainbow\Desktop\FRST64.exe
    2015-12-20 13:24 - 2015-12-20 13:24 - 02370048 _____ (Farbar) C:\Users\rainbow\Downloads\FRST64.exe
    2015-12-19 03:14 - 2015-12-19 03:14 - 00002697 _____ C:\Users\Public\Desktop\Skype.lnk
    2015-12-19 03:14 - 2015-12-19 03:14 - 00000000 ___RD C:\Program Files (x86)\Skype
    2015-12-19 03:14 - 2015-12-19 03:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
    2015-12-19 01:20 - 2015-12-19 18:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
    2015-12-18 05:28 - 2015-12-18 05:28 - 00275840 _____ C:\Windows\Minidump\121815-29109-01.dmp
    2015-12-18 05:13 - 2015-12-18 05:28 - 422335240 _____ C:\Windows\MEMORY.DMP
    2015-12-18 05:13 - 2015-12-18 05:13 - 00275848 _____ C:\Windows\Minidump\121815-24850-01.dmp
    2015-12-18 05:02 - 2015-12-18 05:02 - 00380416 _____ C:\Users\rainbow\Downloads\8nz7zreq.exe
    2015-12-18 04:55 - 2015-12-18 04:56 - 00231390 _____ C:\Users\rainbow\Downloads\RootkitRevealer_1.71.zip
    2015-12-17 23:04 - 2015-12-17 23:04 - 00000000 ____D C:\Users\rainbow\AppData\Roaming\ATI
    2015-12-17 23:04 - 2015-12-17 23:04 - 00000000 ____D C:\Users\rainbow\AppData\Local\ATI
    2015-12-17 23:04 - 2015-12-17 23:04 - 00000000 ____D C:\ProgramData\ATI
    2015-12-13 18:50 - 2015-12-20 12:33 - 00238098 _____ C:\Windows\ntbtlog.txt
    2015-12-09 10:36 - 2015-12-09 10:36 - 09498816 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
    2015-12-09 07:14 - 2015-12-09 07:14 - 25837568 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 20366848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 14456832 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 12856832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 05923840 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 04514816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 02887168 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 02487808 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 02280448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 02123264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
    2015-12-09 07:14 - 2015-12-09 07:14 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2015-12-09 07:14 - 2015-12-09 07:14 - 02011136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 01546752 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
    2015-12-09 07:14 - 2015-12-09 07:14 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00718336 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
    2015-12-09 07:14 - 2015-12-09 07:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00687104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00571392 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00387792 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00341192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
    2015-12-09 07:14 - 2015-12-09 07:14 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2015-12-09 07:14 - 2015-12-09 07:14 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
    2015-12-09 07:14 - 2015-12-09 07:14 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
    2015-12-09 07:14 - 2015-12-09 07:14 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
    2015-12-09 07:14 - 2015-11-10 01:24 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2015-12-09 07:14 - 2015-11-10 01:12 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
    2015-12-09 07:14 - 2015-11-08 23:33 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
    2015-12-09 07:14 - 2015-11-08 23:15 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
    2015-12-09 07:12 - 2015-12-09 07:12 - 03170304 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
    2015-12-09 07:12 - 2015-12-09 07:12 - 02609152 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
    2015-12-09 07:12 - 2015-12-09 07:12 - 00802304 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
    2015-12-09 07:12 - 2015-12-09 07:12 - 00709632 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
    2015-12-09 07:12 - 2015-12-09 07:12 - 00627712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
    2015-12-09 07:12 - 2015-12-09 07:12 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
    2015-12-09 07:12 - 2015-12-09 07:12 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
    2015-12-09 07:12 - 2015-12-09 07:12 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
    2015-12-09 07:12 - 2015-12-09 07:12 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
    2015-12-09 07:12 - 2015-12-09 07:12 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
    2015-12-09 07:12 - 2015-12-09 07:12 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
    2015-12-09 07:12 - 2015-12-09 07:12 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
    2015-12-09 07:12 - 2015-12-09 07:12 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
    2015-12-09 07:12 - 2015-12-09 07:12 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
    2015-12-09 07:12 - 2015-12-09 07:12 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
    2015-12-09 07:12 - 2015-12-09 07:12 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
    2015-12-09 07:12 - 2015-12-09 07:12 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
    2015-12-09 07:12 - 2015-12-09 07:12 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
    2015-12-09 07:12 - 2015-12-09 07:12 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
    2015-12-09 07:12 - 2015-12-09 07:12 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
    2015-12-09 07:12 - 2015-10-08 20:13 - 00419928 _____ C:\Windows\SysWOW64\locale.nls
    2015-12-09 07:12 - 2015-10-08 19:52 - 00419928 _____ C:\Windows\system32\locale.nls
    2015-12-09 07:11 - 2015-12-09 07:11 - 03211264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
    2015-12-09 07:11 - 2015-12-09 07:11 - 01735680 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll
    2015-12-09 07:11 - 2015-12-09 07:11 - 01648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
    2015-12-09 07:11 - 2015-12-09 07:11 - 01251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
    2015-12-09 07:11 - 2015-12-09 07:11 - 01242624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comsvcs.dll
    2015-12-09 07:11 - 2015-12-09 07:11 - 01180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
    2015-12-09 07:11 - 2015-12-09 07:11 - 01008640 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
    2015-12-09 07:11 - 2015-12-09 07:11 - 00833024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
    2015-12-09 07:11 - 2015-12-09 07:11 - 00525312 _____ (Microsoft Corporation) C:\Windows\system32\catsrvut.dll
    2015-12-09 07:11 - 2015-12-09 07:11 - 00487936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\catsrvut.dll
    2015-12-09 07:11 - 2015-12-09 07:11 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys
    2015-12-09 07:11 - 2015-12-09 07:11 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlsbres.dll
    2015-12-09 07:11 - 2015-12-09 07:11 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\nlsbres.dll
    2015-12-09 07:11 - 2015-12-09 07:11 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\wshrm.dll
    2015-12-09 07:11 - 2015-12-09 07:11 - 00014848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshrm.dll
    2015-12-09 07:11 - 2015-12-09 07:11 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZE.DLL
    2015-12-09 07:11 - 2015-12-09 07:11 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\kbdgeoqw.dll
    2015-12-09 07:11 - 2015-12-09 07:11 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZEL.DLL
    2015-12-09 07:11 - 2015-12-09 07:11 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZE.DLL
    2015-12-09 07:11 - 2015-12-09 07:11 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kbdgeoqw.dll
    2015-12-09 07:11 - 2015-12-09 07:11 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZEL.DLL
    2015-12-09 07:06 - 2015-12-09 07:06 - 00241664 _____ (Microsoft Corporation) C:\Windows\system32\els.dll
    2015-12-09 07:06 - 2015-12-09 07:06 - 00179712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\els.dll
    2015-11-27 05:17 - 2015-11-27 05:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo Security Solutions Inc
    2015-11-26 13:17 - 2015-11-26 13:17 - 00000000 ____D C:\Program Files (x86)\Comodo

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2015-12-20 13:32 - 2007-07-12 02:48 - 00000000 ____D C:\Windows
    2015-12-20 13:31 - 2012-05-21 22:43 - 00000000 ____D C:\Users\rainbow\AppData\Roaming\BitComet
    2015-12-20 13:30 - 2015-08-12 00:26 - 01474832 _____ C:\Windows\system32\Drivers\sfi.dat
    2015-12-20 13:21 - 2012-05-21 22:18 - 00001100 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2015-12-20 13:20 - 2012-06-17 22:35 - 00000000 ____D C:\Users\rainbow\AppData\Roaming\Skype
    2015-12-20 13:11 - 2013-11-20 15:48 - 00000392 _____ C:\Windows\Tasks\update-sys.job
    2015-12-20 13:00 - 2013-03-29 15:57 - 00001118 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-682783902-3490664518-2871107328-1000UA.job
    2015-12-20 12:36 - 2012-10-25 07:34 - 00000838 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
    2015-12-20 12:02 - 2013-11-20 15:48 - 00000392 _____ C:\Windows\Tasks\update-S-1-5-21-682783902-3490664518-2871107328-1000.job
    2015-12-20 11:57 - 2012-12-02 20:52 - 00000936 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-682783902-3490664518-2871107328-1000UA.job
    2015-12-20 08:23 - 2009-07-14 05:45 - 00016976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2015-12-20 08:23 - 2009-07-14 05:45 - 00016976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2015-12-19 20:57 - 2012-12-02 20:52 - 00000914 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-682783902-3490664518-2871107328-1000Core.job
    2015-12-19 18:41 - 2012-05-21 22:18 - 00001096 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2015-12-19 18:41 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
    2015-12-19 18:40 - 2014-10-16 18:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
    2015-12-19 03:15 - 2013-01-06 23:34 - 00001511 _____ C:\Windows\wininit.ini
    2015-12-19 03:14 - 2014-02-28 07:28 - 00000000 ____D C:\Users\rainbow\AppData\Local\Skype
    2015-12-19 03:14 - 2011-08-12 08:43 - 00000000 ____D C:\ProgramData\Skype
    2015-12-18 18:00 - 2013-03-29 15:57 - 00001066 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-682783902-3490664518-2871107328-1000Core.job
    2015-12-18 05:45 - 2009-07-14 06:08 - 00032620 _____ C:\Windows\Tasks\SCHEDLGU.TXT
    2015-12-18 05:28 - 2012-12-04 02:36 - 00000000 ____D C:\Windows\Minidump
    2015-12-18 04:58 - 2014-02-05 06:08 - 00000000 ____D C:\Users\rainbow\Desktop\ботове
    2015-12-18 02:00 - 2015-04-04 18:07 - 00000000 ___SD C:\Windows\SysWOW64\GWX
    2015-12-18 02:00 - 2015-04-04 18:07 - 00000000 ___SD C:\Windows\system32\GWX
    2015-12-17 20:10 - 2012-05-22 00:54 - 00740672 _____ C:\Windows\system32\perfh00A.dat
    2015-12-17 20:10 - 2012-05-22 00:54 - 00160794 _____ C:\Windows\system32\perfc00A.dat
    2015-12-17 20:10 - 2009-07-14 06:13 - 01683856 _____ C:\Windows\system32\PerfStringBackup.INI
    2015-12-17 20:10 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf
    2015-12-16 22:25 - 2012-05-21 22:19 - 00002145 _____ C:\Users\Public\Desktop\Google Chrome.lnk
    2015-12-16 08:02 - 2014-02-08 13:54 - 00000000 ____D C:\Users\rainbow\AppData\Roaming\Mozilla
    2015-12-13 22:08 - 2012-05-22 03:45 - 00000000 ____D C:\Users\rainbow\AppData\Roaming\Media Player Classic
    2015-12-12 06:55 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
    2015-12-09 14:16 - 2009-07-14 05:45 - 00293288 _____ C:\Windows\system32\FNTCACHE.DAT
    2015-12-09 12:11 - 2013-03-13 17:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
    2015-12-09 12:10 - 2013-03-13 17:43 - 00000000 ____D C:\Program Files\Microsoft Silverlight
    2015-12-09 12:10 - 2013-03-13 17:43 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
    2015-12-09 12:08 - 2013-07-20 02:25 - 00000000 ____D C:\Windows\system32\MRT
    2015-12-09 11:58 - 2012-05-24 20:52 - 140158008 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
    2015-12-09 10:36 - 2012-10-25 07:34 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2015-12-09 10:36 - 2012-10-25 07:34 - 00003776 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
    2015-12-09 10:36 - 2012-07-22 00:40 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2015-12-07 20:39 - 2013-04-18 20:29 - 00000000 ____D C:\Program Files (x86)\TeamViewer
    2015-12-04 17:55 - 2013-03-29 15:57 - 00004092 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-682783902-3490664518-2871107328-1000UA
    2015-12-04 17:55 - 2013-03-29 15:57 - 00003696 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-682783902-3490664518-2871107328-1000Core
    2015-12-02 16:16 - 2012-05-21 22:18 - 00004096 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
    2015-12-02 16:16 - 2012-05-21 22:18 - 00003844 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
    2015-11-27 19:20 - 2015-11-18 13:34 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
    2015-11-27 05:17 - 2015-10-20 15:53 - 00001977 _____ C:\Users\Public\Desktop\GeekBuddy.lnk
    2015-11-27 05:17 - 2015-05-05 19:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
    2015-11-26 22:12 - 2012-05-21 22:26 - 00000000 ____D C:\Program Files\CCleaner

    ==================== Files in the root of some directories =======

    2013-01-06 23:33 - 2013-01-06 23:35 - 0001247 _____ () C:\Users\rainbow\AppData\Roaming\Bubble Dock.boostrap.log
    2013-01-06 23:34 - 2013-01-06 23:36 - 0015443 _____ () C:\Users\rainbow\AppData\Roaming\Bubble Dock.installation.log
    2013-11-20 15:48 - 2013-11-20 15:48 - 0000003 _____ () C:\Users\rainbow\AppData\Local\updater.log
    2013-11-20 15:48 - 2015-10-02 11:23 - 0000424 _____ () C:\Users\rainbow\AppData\Local\UserProducts.xml
    2012-05-21 15:27 - 2012-05-21 15:28 - 0015223 _____ () C:\ProgramData\ArcadeDeluxe5.log
    2012-06-07 11:41 - 2012-06-07 11:41 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
    2012-05-25 23:28 - 2012-05-25 23:28 - 0000032 _____ () C:\ProgramData\PS.log
    2013-01-07 00:27 - 2013-01-07 00:27 - 0001534 _____ () C:\ProgramData\ss.ini

    Some files in TEMP:
    ====================
    C:\Users\rainbow\AppData\Local\Temp\LOSRT.exe
    C:\Users\rainbow\AppData\Local\Temp\MNCRCZ.exe
    C:\Users\rainbow\AppData\Local\Temp\NETBXJL.exe
    C:\Users\rainbow\AppData\Local\Temp\OSAOQDWO.exe
    C:\Users\rainbow\AppData\Local\Temp\SWHBY.exe
    C:\Users\rainbow\AppData\Local\Temp\WSVLRI.exe
    C:\Users\rainbow\AppData\Local\Temp\XEPH.exe


    ==================== Bamital & volsnap =================

    (There is no automatic fix for files that do not pass verification.)

    C:\Windows\system32\winlogon.exe => File is digitally signed
    C:\Windows\system32\wininit.exe => File is digitally signed
    C:\Windows\SysWOW64\wininit.exe => File is digitally signed
    C:\Windows\explorer.exe => File is digitally signed
    C:\Windows\SysWOW64\explorer.exe => File is digitally signed
    C:\Windows\system32\svchost.exe => File is digitally signed
    C:\Windows\SysWOW64\svchost.exe => File is digitally signed
    C:\Windows\system32\services.exe => File is digitally signed
    C:\Windows\system32\User32.dll => File is digitally signed
    C:\Windows\SysWOW64\User32.dll => File is digitally signed
    C:\Windows\system32\userinit.exe => File is digitally signed
    C:\Windows\SysWOW64\userinit.exe => File is digitally signed
    C:\Windows\system32\rpcss.dll => File is digitally signed
    C:\Windows\system32\dnsapi.dll => File is digitally signed
    C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
    C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


    LastRegBack: 2015-12-12 06:46

    ==================== End of FRST.txt ============================

    Addition.txt

    FRST.txt

    Редактирано от tangra_es (преглед на промените)

    Сподели този отговор


    Линк към този отговор
    Сподели в други сайтове

    B-boy/StyLe/    19544

    Здравейте,

    Как установихте, че системата е заразена с рууткит? Обясненията ви ми се струват несериозни.

    Изтеглете последната версия на TDSSKiller оттук и я запазете на вашия декстоп.

    Стартирайте TDSSKiller.exe за да стартирате приложението. След това кликнете върху бутона Change parameters.
    Сложете отметка през Loaded Modules.

    Sbf88.png
    Необходим е рестарт за осъществяване на промените. Направете го!
    TDSSKiller ще стартира автоматично след рестарта. Важно е да се отбележи, че вашия компютър може да изглежда по-бавен, на моменти неизползваем и с по-ниска производителност. Това е нормално и ще трае само един рестарт. Дайте му достатъчно време да зареди приложенията стартиращи с Операционната Система във фонов режим.
    След това натиснете Change parameters в TDSSKiller отново.
    Сложете всички отметки (този път рестарт не се изисква).
    Натиснете бутона Start Scan.
    Проверката не би трябвало да отмене повече от 5 minutes.
    Ако подозрителен обект бъде засечен, действието по подразбиране ще бъде Skip, кликнете върху Continue.
    Ако зловредни обекти бъдат намерени, тогава от падащото меню ще имате три възможности.
    Бъдете сигурни, че избраното действие е Cure и натиснете върху Continue > Рестартирайте за да бъде завършена поправката.

    Забележка: Ако Cure бутона не е наличен от възможностите, тогава моля изберете Skip бутона, не избирайте Delete освен ако не сте инструктирани затова.
    Лог файл ще бъде създаден в свободната директория на дял C:\ . Потърсете за лог с името "TDSSKiller.[Version]_[Date]_[Time]_log.txt" и копирайте съдържанието му в следващия си пост.

    • Харесва ми 1

    Сподели този отговор


    Линк към този отговор
    Сподели в други сайтове

    Регистрирайте се или влезете в профила си за да коментирате

    Трябва да имате регистрация за да може да коментирате това

    Регистрирайте се

    Създайте нова регистрация в нашия форум. Лесно е!

    Нова регистрация

    Вход

    Имате регистрация? Влезте от тук.

    Вход


    ×

    Информация

    Този сайт използва бисквитки (cookies), за най-доброто потребителско изживяване. С използването му, вие приемате нашите Условия за ползване.