Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Cryp1 (UltraCrypter) вирус

Featured Replies

Всички файлове са криптирани с разширение .cryp1

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:01-06-2016
Ran by user (administrator) on TSU-GRAFIKA (03-06-2016 10:04:57)
Running from \\admin\Sher-RW\software
Loaded Profiles: user (Available Profiles: user)
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) Language: English (United States)
Internet Explorer Version 8 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Portrait Displays, Inc) C:\Program Files\Philips Display\SmartControl II\dthtml.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
(Portrait Displays Inc.) C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe
() C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
Failed to access process -> FRST.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [PHIME2002ASync] => C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE [455168 2004-08-03] (Microsoft Corporation)
HKLM\...\Run: [PHIME2002A] => C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE [455168 2004-08-03] (Microsoft Corporation)
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
HKLM\...\Run: [nwiz] => nwiz.exe /install
HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
HKLM\...\Run: [DT PHL] => C:\Program Files\Philips Display\SmartControl II\DTHtml.exe [292352 2007-07-27] (Portrait Displays, Inc)
HKLM\...\Run: [UpdateReminder] => C:\Program Files\Eset\UpdateReminder.exe [425984 2011-09-14] (ESET, spol. s r.o.)
HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [14854144 2005-09-22] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Alcmtr] => C:\WINDOWS\ALCMTR.EXE [69632 2005-05-03] (Realtek Semiconductor Corp.)
HKLM\...\Run: [MSConfig] => C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe [169984 2008-04-14] (Microsoft Corporation)
HKU\S-1-5-21-329068152-57989841-839522115-1003\...\Run: [Magic Tree] => \\Kmet-pc1\Sher-RW\MagicTree.exe
HKU\S-1-5-21-329068152-57989841-839522115-1003\...\MountPoints2: {ab467713-5d7e-11e3-8b02-001bfcdd0fe9} - F:\LaunchU3.exe -a

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Winsock: Catalog9 01 C:\WINDOWS\System32\imon.dll [299392 2009-06-30] (Eset )
Winsock: Catalog9 02 C:\WINDOWS\System32\imon.dll [299392 2009-06-30] (Eset )
Winsock: Catalog9 03 C:\WINDOWS\System32\imon.dll [299392 2009-06-30] (Eset )
Winsock: Catalog9 04 C:\WINDOWS\System32\imon.dll [299392 2009-06-30] (Eset )
Winsock: Catalog9 05 C:\WINDOWS\System32\imon.dll [299392 2009-06-30] (Eset )
Winsock: Catalog9 26 C:\WINDOWS\System32\imon.dll [299392 2009-06-30] (Eset )
Tcpip\..\Interfaces\{8463637E-8F8F-48CF-BE2F-322DBE8C1655}: [NameServer] 192.168.1.254

Internet Explorer:
==================
HKU\S-1-5-21-329068152-57989841-839522115-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.devnia.bg/
HKU\S-1-5-21-329068152-57989841-839522115-1003\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
BHO: Adobe PDF Reader Link Helper -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-12-18] (Adobe Systems Incorporated)
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} hxxp://go.divx.com/plugin/DivXBrowserPlugin.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: lid - {5C135180-9973-46D9-ABF4-148267CBB8BF} - C:\WINDOWS\System32\msvidctl.dll [2008-04-14] (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL [2000-04-19] (Microsoft Corporation)

FireFox:
========
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-10-18] [not signed]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 ATKKeyboardService; C:\WINDOWS\ATKKBService.exe [257024 2007-07-12] (ASUSTeK COMPUTER INC.) [File not signed]
R2 DTSRVC; C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe [73728 2007-07-27] () [File not signed]
R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [1982752 2016-04-13] (ESET)
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 Net Driver HPZ12; C:\WINDOWS\System32\HPZinw12.dll [44032 2010-01-18] (Hewlett-Packard) [File not signed]
S4 NOD32krn; C:\Program Files\Eset\nod32krn.exe [549256 2009-06-30] (Eset ) [File not signed]
R2 Pml Driver HPZ12; C:\WINDOWS\System32\HPZipm12.dll [53760 2010-01-18] (Hewlett-Packard) [File not signed]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMON; C:\WINDOWS\system32\drivers\amon.sys [512096 2009-06-30] (Eset )
R3 asusgsb; C:\WINDOWS\System32\drivers\asusgsb.sys [12416 2007-07-12] (ASUSTeK Computer Inc.) [File not signed]
R1 asuskbnt; C:\WINDOWS\System32\drivers\atkkbnt.sys [11136 2007-07-12] (ASUSTeK COMPUTER INC.) [File not signed]
R3 AtcL001; C:\WINDOWS\System32\DRIVERS\atl01_xp.sys [35840 2006-10-31] (Attansic Technology corporation.)
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [206312 2016-04-13] (ESET)
R1 ehdrv; C:\WINDOWS\System32\DRIVERS\ehdrv.sys [146024 2016-04-13] (ESET)
R1 EIO; C:\WINDOWS\system32\drivers\EIO.sys [12288 2007-07-12] (ASUSTeK Computer Inc.) [File not signed]
R1 epfwtdir; C:\WINDOWS\System32\DRIVERS\epfwtdir.sys [127496 2016-04-13] (ESET)
R1 eusk2par; C:\WINDOWS\System32\Drivers\eusk2par.sys [30656 2006-12-13] (Eutron)
R3 MTsensor; C:\WINDOWS\System32\DRIVERS\ASACPI.sys [5810 2004-08-13] ()
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
R1 nod32drv; C:\WINDOWS\system32\drivers\nod32drv.sys [15424 2009-06-30] ()
R2 NwlnkIpx; C:\WINDOWS\System32\DRIVERS\nwlnkipx.sys [88320 2008-04-14] (Microsoft Corporation)
R2 NwlnkNb; C:\WINDOWS\System32\DRIVERS\nwlnknb.sys [63232 2001-08-23] (Microsoft Corporation)
R2 NwlnkSpx; C:\WINDOWS\System32\DRIVERS\nwlnkspx.sys [55936 2001-08-23] (Microsoft Corporation)
R3 pdiddcci; C:\WINDOWS\System32\DRIVERS\pdiddcci.sys [11776 2007-06-12] (Portrait Displays, Inc.) [File not signed]
R3 PdiPorts; C:\WINDOWS\System32\Drivers\PdiPorts.sys [15920 2006-11-16] (Portrait Displays, Inc.)
R3 Video3D; C:\WINDOWS\System32\Drivers\Video3D32.sys [10752 2007-07-12] (ASUSTeK COMPUTER INC.) [File not signed]
S4 hpt3xx; no ImagePath
S4 IntelIde; no ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-06-03 09:37 - 2016-06-03 10:04 - 00000000 ____D C:\FRST
2016-06-01 13:35 - 2016-06-01 13:35 - 00000000 ____D C:\WINDOWS\system32\Obsoleteupdfiles
2016-06-01 13:23 - 2016-06-01 13:23 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\ESET
2016-06-01 11:59 - 2016-06-01 12:00 - 00170200 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-06-01 11:58 - 2016-06-01 11:58 - 00000777 _____ C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2016-06-01 11:57 - 2016-06-01 11:57 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2016-06-01 11:57 - 2016-06-01 11:57 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Malwarebytes
2016-06-01 11:57 - 2016-03-10 14:09 - 00123264 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-06-01 11:57 - 2016-03-10 14:08 - 00024448 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2016-06-01 11:48 - 2016-06-01 11:48 - 00081920 _____ C:\WINDOWS\Minidump\Mini060116-01.dmp
2016-06-01 11:43 - 2016-06-01 11:43 - 00000000 ____D C:\Program Files\Canon
2016-06-01 11:43 - 2016-06-01 11:43 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Color Network ScanGear
2016-06-01 11:42 - 2016-06-01 11:42 - 00000000 ____D C:\Documents and Settings\user\Desktop\ColorNetworkScanGear-v271_Win_uk_EN
2016-06-01 11:37 - 2016-06-01 11:38 - 25021536 _____ C:\Documents and Settings\user\Desktop\ColorNetworkScanGear-v271_Win_uk_EN.exe
2016-05-31 08:43 - 2016-05-31 08:43 - 00000000 ____D C:\Documents and Settings\user\Application Data\MSN6
2016-05-31 08:43 - 2016-05-31 08:43 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\MSN6
2016-05-31 08:42 - 2016-05-31 08:42 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy
2016-05-30 13:30 - 2016-06-01 12:55 - 00000000 ___HD C:\Documents and Settings\All Users\Application Data\{1DD34792-8E5C-40C1-9EFF-84AA7B6C503B}

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-06-03 10:05 - 2008-05-14 15:08 - 00000000 ____D C:\Documents and Settings\user\Local Settings\Temp
2016-06-03 09:44 - 2008-05-14 15:08 - 00001599 _____ C:\Documents and Settings\user\Start Menu\Programs\Remote Assistance.lnk
2016-06-03 09:36 - 2008-06-27 13:13 - 00013030 _____ C:\PDOXUSRS.NET
2016-06-03 08:41 - 2001-08-23 15:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2016-06-03 08:40 - 2014-03-24 09:34 - 00000220 _____ C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job
2016-06-03 08:40 - 2013-10-04 10:48 - 00000000 ____D C:\WINDOWS\system32\Lang
2016-06-03 08:40 - 2008-05-14 15:05 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-06-02 16:51 - 2008-05-14 15:07 - 00032640 _____ C:\WINDOWS\SchedLgU.Txt
2016-06-02 16:24 - 2008-05-14 17:38 - 00004632 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-06-02 12:46 - 2009-10-22 15:22 - 00000000 ____D C:\Documents and Settings\user\Desktop\КП -ПЗЮ
2016-06-01 13:38 - 2008-07-14 10:58 - 00000000 ____D C:\WINDOWS\pss
2016-06-01 13:38 - 2008-05-14 17:35 - 00000211 __RSH C:\boot.ini
2016-06-01 13:38 - 2001-08-23 15:00 - 00000615 _____ C:\WINDOWS\win.ini
2016-06-01 13:38 - 2001-08-23 15:00 - 00000227 _____ C:\WINDOWS\system.ini
2016-06-01 13:24 - 2008-05-14 17:31 - 00000000 ___HD C:\WINDOWS\inf
2016-06-01 13:23 - 2009-06-30 11:35 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Eset
2016-06-01 13:22 - 2009-06-30 11:34 - 00000000 ____D C:\Program Files\ESET
2016-06-01 12:55 - 2011-04-14 16:54 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2485663$
2016-06-01 09:12 - 2013-12-02 14:39 - 00000000 ____D C:\Documents and Settings\user\Desktop\КК ВЗЕТА НА 27.11.2013
2016-06-01 09:02 - 2011-07-19 09:27 - 00000012 _____ C:\Documents and Settings\All Users\Application Data\ReminderNextRun
2016-06-01 08:45 - 2015-02-27 11:39 - 00000000 ____D C:\Documents and Settings\user\Desktop\KK 02.2015
2016-05-31 08:46 - 2012-01-12 12:14 - 00000000 ____D C:\je4ka
2016-05-31 08:44 - 2008-06-27 13:11 - 00002429 _____ C:\Documents and Settings\All Users\Desktop\Mkad for Windows.lnk
2016-05-30 13:39 - 2013-04-17 15:57 - 00000000 ____D C:\Documents and Settings\user\Desktop\okolovrysten
2016-05-30 13:38 - 2008-06-27 13:40 - 00000000 ____D C:\MKAD
2016-05-30 13:36 - 2015-07-08 10:59 - 00000000 ____D C:\Documents and Settings\user\Desktop\Стефан Димитров
2016-05-30 13:36 - 2014-06-18 10:01 - 00000000 ____D C:\Documents and Settings\user\My Documents\ПРЕПИСКИ ПУП
2016-05-30 13:36 - 2014-06-18 09:59 - 00000000 ____D C:\Documents and Settings\user\My Documents\АДМИНИСТРАТИВЕН СЪД
2016-05-30 13:36 - 2013-01-14 11:46 - 00000000 ____D C:\Documents and Settings\user\Desktop\формуляри ТСУ към Наредба-2009
2016-05-30 13:36 - 2012-08-14 13:44 - 00000000 ____D C:\Documents and Settings\user\My Documents\МАГИ
2016-05-30 13:36 - 2010-05-10 15:31 - 00000000 ____D C:\Documents and Settings\user\My Documents\удостоверения за адм.адрес
2016-05-30 13:36 - 2010-05-10 15:28 - 00000000 ____D C:\Documents and Settings\user\My Documents\отчуждителни преписки
2016-05-30 13:36 - 2009-12-10 14:24 - 00000000 ____D C:\Documents and Settings\user\My Documents\snimki kashta Panayot
2016-05-30 13:36 - 2009-03-20 12:05 - 00000000 ____D C:\Documents and Settings\user\My Documents\писма
2016-05-30 13:36 - 2008-11-24 11:36 - 00000000 ____D C:\Documents and Settings\user\Desktop\Технологични карти
2016-05-30 13:36 - 2008-05-19 12:37 - 00000000 ____D C:\Documents and Settings\user\My Documents\YANI
2016-05-30 13:36 - 2008-05-14 15:08 - 00000000 ___RD C:\Documents and Settings\user\My Documents
2016-05-30 13:35 - 2015-06-22 15:43 - 00000000 ____D C:\Documents and Settings\user\Desktop\РД-2015
2016-05-30 13:35 - 2013-02-22 15:02 - 00000000 ____D C:\Documents and Settings\user\Desktop\ОБЕДИНЕНИ КК - официално взета 22.02.2013
2016-05-30 13:33 - 2015-11-12 14:10 - 00000000 ____D C:\Documents and Settings\user\Desktop\New Folder (6)
2016-05-30 13:33 - 2015-11-11 13:29 - 00000000 ____D C:\Documents and Settings\user\Desktop\New Folder (5)
2016-05-30 13:33 - 2015-11-09 11:41 - 00000000 ____D C:\Documents and Settings\user\Desktop\New Folder (4)
2016-05-30 13:33 - 2015-08-03 10:50 - 00000000 ____D C:\Documents and Settings\user\Desktop\New Folder (3)
2016-05-30 13:33 - 2015-07-03 09:31 - 00000000 ____D C:\Documents and Settings\user\Desktop\SEMINAR-17-19.06.2015
2016-05-30 13:33 - 2014-12-04 11:40 - 00000000 ____D C:\Documents and Settings\user\Desktop\lambeva
2016-05-30 13:33 - 2014-09-02 14:55 - 00000000 ____D C:\Documents and Settings\user\Desktop\Qni
2016-05-30 13:33 - 2012-02-07 10:14 - 00000000 ____D C:\Documents and Settings\user\Desktop\КА
2016-05-30 13:33 - 2011-07-06 15:43 - 00000000 ____D C:\Documents and Settings\user\Desktop\KK-HR. SMIRNENSKI
2016-05-30 13:33 - 2010-01-14 10:34 - 00000000 ____D C:\Documents and Settings\user\Desktop\Архив ТСУ
2016-05-30 13:33 - 2009-12-22 12:36 - 00000000 ____D C:\Documents and Settings\user\Desktop\архив
2016-05-30 13:33 - 2009-04-07 16:52 - 00000000 ____D C:\Documents and Settings\user\Desktop\Кадастрални планове
2016-05-30 13:33 - 2009-02-05 16:28 - 00000000 ____D C:\Documents and Settings\user\Desktop\snimki
2016-05-30 13:29 - 2014-07-24 13:15 - 00000000 ____D C:\Documents and Settings\user\Desktop\anton
2016-05-30 13:29 - 2012-03-30 14:48 - 00000000 ____D C:\Documents and Settings\user\Desktop\6lamootval
2016-05-30 13:29 - 2008-11-10 15:13 - 00000000 ____D C:\Cement_PUP
2016-05-11 16:54 - 2013-07-25 16:41 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-05-11 16:53 - 2008-05-14 15:07 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\Temp
2016-05-11 16:47 - 2008-12-09 16:11 - 136686448 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-05-09 08:33 - 2014-03-24 09:34 - 00000214 _____ C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job
2016-05-04 09:01 - 2016-03-23 11:21 - 00008192 _____ C:\Documents and Settings\user\Desktop\55110ss.MDX
2016-05-04 09:01 - 2016-03-23 11:21 - 00008192 _____ C:\Documents and Settings\user\Desktop\55110ot.MDX
2016-05-04 09:01 - 2016-03-23 11:21 - 00005429 ____R C:\Documents and Settings\user\Desktop\55110ot.DBF.cryp1
2016-05-04 09:01 - 2016-03-23 11:21 - 00004129 ____R C:\Documents and Settings\user\Desktop\55110ss.DBF.cryp1
2016-05-04 09:01 - 2016-03-23 11:21 - 00004096 _____ C:\Documents and Settings\user\Desktop\55110og.MDX
2016-05-04 09:01 - 2016-03-23 11:21 - 00001613 ____R C:\Documents and Settings\user\Desktop\55110og.DBF.cryp1
2016-05-04 09:01 - 2016-03-23 11:21 - 00000584 _____ C:\Documents and Settings\user\Desktop\UPI_47_59_33_45_Padina_2005 1.ini
2016-05-04 08:29 - 2009-06-15 14:43 - 00002545 _____ C:\Documents and Settings\All Users\Desktop\eProcess 2008 Client.lnk

==================== Files in the root of some directories =======

2008-05-15 03:10 - 2012-12-14 16:20 - 0006144 _____ () C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
1899-12-30 00:00 - 1899-12-30 00:00 - 2592054 ____T () C:\Documents and Settings\All Users\Application Data\!13D214070068.bmp
1601-01-29 13:11 - 1601-01-29 13:11 - 0005718 _____ () C:\Documents and Settings\All Users\Application Data\!13D214070068.html
2011-07-19 09:27 - 2016-06-01 09:02 - 0000012 _____ () C:\Documents and Settings\All Users\Application Data\ReminderNextRun

Some files in TEMP:
====================
C:\Documents and Settings\user\Local Settings\Temp\DivXInstaller.exe
C:\Documents and Settings\user\Local Settings\Temp\WindowsInstaller-KB893803-v2-x86.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 

Addition.txt

Addition.txt е непълен.

Но като цяло Windows XP + кракнат NOD32 на работна система не е добра идея. Има какво да се почисти, но ми трябва и втория лог файл.

 

  • Автор

Ето на ново

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:05-06-2016 02
Ran by user (administrator) on TSU-GRAFIKA (06-06-2016 11:20:55)
Running from C:\Documents and Settings\user\Desktop
Loaded Profiles: user (Available Profiles: user)
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) Language: English (United States)
Internet Explorer Version 8 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Portrait Displays, Inc) C:\Program Files\Philips Display\SmartControl II\dthtml.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
(Eset ) C:\Program Files\ESET\nod32kui.exe
(ASUSTeK Computer Inc.) C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
(Portrait Displays Inc.) C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe
() C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
(Eset ) C:\Program Files\ESET\nod32krn.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
(Kolma) C:\Program Files\kolma\mkadwin\bin\Mkadwin.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [PHIME2002ASync] => C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE [455168 2004-08-03] (Microsoft Corporation)
HKLM\...\Run: [PHIME2002A] => C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE [455168 2004-08-03] (Microsoft Corporation)
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
HKLM\...\Run: [nwiz] => nwiz.exe /install
HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
HKLM\...\Run: [DT PHL] => C:\Program Files\Philips Display\SmartControl II\DTHtml.exe [292352 2007-07-27] (Portrait Displays, Inc)
HKLM\...\Run: [UpdateReminder] => C:\Program Files\Eset\UpdateReminder.exe [425984 2011-09-14] (ESET, spol. s r.o.)
HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [14854144 2005-09-22] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Alcmtr] => C:\WINDOWS\ALCMTR.EXE [69632 2005-05-03] (Realtek Semiconductor Corp.)
HKLM\...\Run: [nod32kui] => C:\Program Files\Eset\nod32kui.exe [950664 2009-06-30] (Eset )
HKLM\...\Run: [IMJPMIG8.1] => C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [208952 2004-08-03] (Microsoft Corporation)
HKLM\...\Run: [ASUSGamerOSD] => C:\Program Files\ASUS\GamerOSD\GamerOSD.exe [380928 2007-07-12] (ASUSTeK Computer Inc.)
HKU\S-1-5-21-329068152-57989841-839522115-1003\...\Run: [Magic Tree] => \\Kmet-pc1\Sher-RW\MagicTree.exe
HKU\S-1-5-21-329068152-57989841-839522115-1003\...\Run: [updateMgr] => C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe [313472 2006-03-30] (Adobe Systems Incorporated)
HKU\S-1-5-21-329068152-57989841-839522115-1003\...\MountPoints2: {ab467713-5d7e-11e3-8b02-001bfcdd0fe9} - F:\LaunchU3.exe -a
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk [2008-07-03]
ShortcutTarget: Adobe Reader Speed Launch.lnk -> C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
Startup: C:\Documents and Settings\user\Start Menu\Programs\Startup\!13D214070068B.lnk [1899-12-30]
ShortcutTarget: !13D214070068B.lnk -> C:\Documents and Settings\All Users\Application Data\!13D214070068.bmp ()
Startup: C:\Documents and Settings\user\Start Menu\Programs\Startup\!13D214070068H.lnk [1899-12-30]
ShortcutTarget: !13D214070068H.lnk -> C:\Documents and Settings\All Users\Application Data\!13D214070068.html ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Winsock: Catalog9 01 C:\WINDOWS\System32\imon.dll [299392 2009-06-30] (Eset )
Winsock: Catalog9 02 C:\WINDOWS\System32\imon.dll [299392 2009-06-30] (Eset )
Winsock: Catalog9 03 C:\WINDOWS\System32\imon.dll [299392 2009-06-30] (Eset )
Winsock: Catalog9 04 C:\WINDOWS\System32\imon.dll [299392 2009-06-30] (Eset )
Winsock: Catalog9 05 C:\WINDOWS\System32\imon.dll [299392 2009-06-30] (Eset )
Winsock: Catalog9 26 C:\WINDOWS\System32\imon.dll [299392 2009-06-30] (Eset )
Tcpip\..\Interfaces\{8463637E-8F8F-48CF-BE2F-322DBE8C1655}: [NameServer] 192.168.1.254

Internet Explorer:
==================
HKU\S-1-5-21-329068152-57989841-839522115-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.devnia.bg/
HKU\S-1-5-21-329068152-57989841-839522115-1003\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
BHO: Adobe PDF Reader Link Helper -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-12-18] (Adobe Systems Incorporated)
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} hxxp://go.divx.com/plugin/DivXBrowserPlugin.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: lid - {5C135180-9973-46D9-ABF4-148267CBB8BF} - C:\WINDOWS\System32\msvidctl.dll [2008-04-14] (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL [2000-04-19] (Microsoft Corporation)

FireFox:
========
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-10-18] [not signed]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 ATKKeyboardService; C:\WINDOWS\ATKKBService.exe [257024 2007-07-12] (ASUSTeK COMPUTER INC.) [File not signed]
R2 DTSRVC; C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe [73728 2007-07-27] () [File not signed]
R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [1982752 2016-04-13] (ESET)
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 Net Driver HPZ12; C:\WINDOWS\System32\HPZinw12.dll [44032 2010-01-18] (Hewlett-Packard) [File not signed]
R2 NOD32krn; C:\Program Files\Eset\nod32krn.exe [549256 2009-06-30] (Eset ) [File not signed]
R2 Pml Driver HPZ12; C:\WINDOWS\System32\HPZipm12.dll [53760 2010-01-18] (Hewlett-Packard) [File not signed]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMON; C:\WINDOWS\system32\drivers\amon.sys [512096 2009-06-30] (Eset )
R3 asusgsb; C:\WINDOWS\System32\drivers\asusgsb.sys [12416 2007-07-12] (ASUSTeK Computer Inc.) [File not signed]
R1 asuskbnt; C:\WINDOWS\System32\drivers\atkkbnt.sys [11136 2007-07-12] (ASUSTeK COMPUTER INC.) [File not signed]
R3 AtcL001; C:\WINDOWS\System32\DRIVERS\atl01_xp.sys [35840 2006-10-31] (Attansic Technology corporation.)
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [206312 2016-04-13] (ESET)
R1 ehdrv; C:\WINDOWS\System32\DRIVERS\ehdrv.sys [146024 2016-04-13] (ESET)
R1 EIO; C:\WINDOWS\system32\drivers\EIO.sys [12288 2007-07-12] (ASUSTeK Computer Inc.) [File not signed]
R1 epfwtdir; C:\WINDOWS\System32\DRIVERS\epfwtdir.sys [127496 2016-04-13] (ESET)
R1 eusk2par; C:\WINDOWS\System32\Drivers\eusk2par.sys [30656 2006-12-13] (Eutron)
R3 MTsensor; C:\WINDOWS\System32\DRIVERS\ASACPI.sys [5810 2004-08-13] ()
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
R1 nod32drv; C:\WINDOWS\system32\drivers\nod32drv.sys [15424 2009-06-30] ()
R2 NwlnkIpx; C:\WINDOWS\System32\DRIVERS\nwlnkipx.sys [88320 2008-04-14] (Microsoft Corporation)
R2 NwlnkNb; C:\WINDOWS\System32\DRIVERS\nwlnknb.sys [63232 2001-08-23] (Microsoft Corporation)
R2 NwlnkSpx; C:\WINDOWS\System32\DRIVERS\nwlnkspx.sys [55936 2001-08-23] (Microsoft Corporation)
R3 pdiddcci; C:\WINDOWS\System32\DRIVERS\pdiddcci.sys [11776 2007-06-12] (Portrait Displays, Inc.) [File not signed]
R3 PdiPorts; C:\WINDOWS\System32\Drivers\PdiPorts.sys [15920 2006-11-16] (Portrait Displays, Inc.)
R3 Video3D; C:\WINDOWS\System32\Drivers\Video3D32.sys [10752 2007-07-12] (ASUSTeK COMPUTER INC.) [File not signed]
S4 hpt3xx; no ImagePath
S4 IntelIde; no ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-06-06 11:20 - 2016-06-06 11:21 - 00009851 _____ C:\Documents and Settings\user\Desktop\FRST.txt
2016-06-06 11:20 - 2016-06-06 11:20 - 00000000 ____D C:\Documents and Settings\user\Desktop\FRST-OlderVersion
2016-06-06 11:19 - 2016-06-06 11:20 - 01735680 _____ (Farbar) C:\Documents and Settings\user\Desktop\FRST.exe
2016-06-06 09:30 - 2016-06-06 09:30 - 00000000 _____ C:\Documents and Settings\user\Desktop\New Text Document.txt
2016-06-03 09:37 - 2016-06-06 11:20 - 00000000 ____D C:\FRST
2016-06-01 13:35 - 2016-06-06 10:50 - 00000000 ____D C:\WINDOWS\system32\Obsoleteupdfiles
2016-06-01 13:23 - 2016-06-01 13:23 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\ESET
2016-06-01 11:59 - 2016-06-01 12:00 - 00170200 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-06-01 11:58 - 2016-06-01 11:58 - 00000777 _____ C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2016-06-01 11:57 - 2016-06-01 11:57 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2016-06-01 11:57 - 2016-06-01 11:57 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Malwarebytes
2016-06-01 11:57 - 2016-03-10 14:09 - 00123264 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-06-01 11:57 - 2016-03-10 14:08 - 00024448 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2016-06-01 11:48 - 2016-06-01 11:48 - 00081920 _____ C:\WINDOWS\Minidump\Mini060116-01.dmp
2016-06-01 11:43 - 2016-06-01 11:43 - 00000000 ____D C:\Program Files\Canon
2016-06-01 11:43 - 2016-06-01 11:43 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Color Network ScanGear
2016-06-01 11:42 - 2016-06-01 11:42 - 00000000 ____D C:\Documents and Settings\user\Desktop\ColorNetworkScanGear-v271_Win_uk_EN
2016-06-01 11:37 - 2016-06-01 11:38 - 25021536 _____ C:\Documents and Settings\user\Desktop\ColorNetworkScanGear-v271_Win_uk_EN.exe
2016-05-31 08:43 - 2016-05-31 08:43 - 00000000 ____D C:\Documents and Settings\user\Application Data\MSN6
2016-05-31 08:43 - 2016-05-31 08:43 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\MSN6
2016-05-31 08:42 - 2016-05-31 08:42 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy
2016-05-30 13:30 - 2016-06-01 12:55 - 00000000 ___HD C:\Documents and Settings\All Users\Application Data\{1DD34792-8E5C-40C1-9EFF-84AA7B6C503B}

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-06-06 11:21 - 2008-05-14 15:08 - 00000000 ____D C:\Documents and Settings\user\Local Settings\Temp
2016-06-06 11:10 - 2008-06-27 13:13 - 00013030 _____ C:\PDOXUSRS.NET
2016-06-06 11:10 - 2001-08-23 15:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2016-06-06 11:09 - 2014-03-24 09:34 - 00000220 _____ C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job
2016-06-06 11:09 - 2013-10-04 10:48 - 00000000 ____D C:\WINDOWS\system32\Lang
2016-06-06 11:09 - 2008-05-14 15:05 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-06-06 09:34 - 2008-05-14 15:07 - 00032434 _____ C:\WINDOWS\SchedLgU.Txt
2016-06-03 12:52 - 2008-05-14 17:35 - 00000211 __RSH C:\boot.ini
2016-06-03 12:52 - 2001-08-23 15:00 - 00000615 _____ C:\WINDOWS\win.ini
2016-06-03 12:52 - 2001-08-23 15:00 - 00000227 _____ C:\WINDOWS\system.ini
2016-06-03 11:34 - 2015-08-03 10:50 - 00000000 ____D C:\Documents and Settings\user\Desktop\New Folder (3)
2016-06-03 11:33 - 2009-06-15 14:43 - 00002545 _____ C:\Documents and Settings\All Users\Desktop\eProcess 2008 Client.lnk
2016-06-03 11:28 - 2015-11-11 13:29 - 00000000 ____D C:\Documents and Settings\user\Desktop\New Folder (5)
2016-06-03 09:44 - 2008-05-14 15:08 - 00001599 _____ C:\Documents and Settings\user\Start Menu\Programs\Remote Assistance.lnk
2016-06-02 16:24 - 2008-05-14 17:38 - 00004632 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-06-02 12:46 - 2009-10-22 15:22 - 00000000 ____D C:\Documents and Settings\user\Desktop\КП -ПЗЮ
2016-06-01 13:38 - 2008-07-14 10:58 - 00000000 ____D C:\WINDOWS\pss
2016-06-01 13:24 - 2008-05-14 17:31 - 00000000 ___HD C:\WINDOWS\inf
2016-06-01 13:23 - 2009-06-30 11:35 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Eset
2016-06-01 13:22 - 2009-06-30 11:34 - 00000000 ____D C:\Program Files\ESET
2016-06-01 12:55 - 2011-04-14 16:54 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2485663$
2016-06-01 09:12 - 2013-12-02 14:39 - 00000000 ____D C:\Documents and Settings\user\Desktop\КК ВЗЕТА НА 27.11.2013
2016-06-01 09:02 - 2011-07-19 09:27 - 00000012 _____ C:\Documents and Settings\All Users\Application Data\ReminderNextRun
2016-06-01 08:45 - 2015-02-27 11:39 - 00000000 ____D C:\Documents and Settings\user\Desktop\KK 02.2015
2016-05-31 08:46 - 2012-01-12 12:14 - 00000000 ____D C:\je4ka
2016-05-31 08:44 - 2008-06-27 13:11 - 00002429 _____ C:\Documents and Settings\All Users\Desktop\Mkad for Windows.lnk
2016-05-30 13:39 - 2013-04-17 15:57 - 00000000 ____D C:\Documents and Settings\user\Desktop\okolovrysten
2016-05-30 13:38 - 2008-06-27 13:40 - 00000000 ____D C:\MKAD
2016-05-30 13:36 - 2015-07-08 10:59 - 00000000 ____D C:\Documents and Settings\user\Desktop\Стефан Димитров
2016-05-30 13:36 - 2014-06-18 10:01 - 00000000 ____D C:\Documents and Settings\user\My Documents\ПРЕПИСКИ ПУП
2016-05-30 13:36 - 2014-06-18 09:59 - 00000000 ____D C:\Documents and Settings\user\My Documents\АДМИНИСТРАТИВЕН СЪД
2016-05-30 13:36 - 2013-01-14 11:46 - 00000000 ____D C:\Documents and Settings\user\Desktop\формуляри ТСУ към Наредба-2009
2016-05-30 13:36 - 2012-08-14 13:44 - 00000000 ____D C:\Documents and Settings\user\My Documents\МАГИ
2016-05-30 13:36 - 2010-05-10 15:31 - 00000000 ____D C:\Documents and Settings\user\My Documents\удостоверения за адм.адрес
2016-05-30 13:36 - 2010-05-10 15:28 - 00000000 ____D C:\Documents and Settings\user\My Documents\отчуждителни преписки
2016-05-30 13:36 - 2009-12-10 14:24 - 00000000 ____D C:\Documents and Settings\user\My Documents\snimki kashta Panayot
2016-05-30 13:36 - 2009-03-20 12:05 - 00000000 ____D C:\Documents and Settings\user\My Documents\писма
2016-05-30 13:36 - 2008-11-24 11:36 - 00000000 ____D C:\Documents and Settings\user\Desktop\Технологични карти
2016-05-30 13:36 - 2008-05-19 12:37 - 00000000 ____D C:\Documents and Settings\user\My Documents\YANI
2016-05-30 13:36 - 2008-05-14 15:08 - 00000000 ___RD C:\Documents and Settings\user\My Documents
2016-05-30 13:35 - 2015-06-22 15:43 - 00000000 ____D C:\Documents and Settings\user\Desktop\РД-2015
2016-05-30 13:35 - 2013-02-22 15:02 - 00000000 ____D C:\Documents and Settings\user\Desktop\ОБЕДИНЕНИ КК - официално взета 22.02.2013
2016-05-30 13:33 - 2015-11-12 14:10 - 00000000 ____D C:\Documents and Settings\user\Desktop\New Folder (6)
2016-05-30 13:33 - 2015-11-09 11:41 - 00000000 ____D C:\Documents and Settings\user\Desktop\New Folder (4)
2016-05-30 13:33 - 2015-07-03 09:31 - 00000000 ____D C:\Documents and Settings\user\Desktop\SEMINAR-17-19.06.2015
2016-05-30 13:33 - 2014-12-04 11:40 - 00000000 ____D C:\Documents and Settings\user\Desktop\lambeva
2016-05-30 13:33 - 2014-09-02 14:55 - 00000000 ____D C:\Documents and Settings\user\Desktop\Qni
2016-05-30 13:33 - 2012-02-07 10:14 - 00000000 ____D C:\Documents and Settings\user\Desktop\КА
2016-05-30 13:33 - 2011-07-06 15:43 - 00000000 ____D C:\Documents and Settings\user\Desktop\KK-HR. SMIRNENSKI
2016-05-30 13:33 - 2010-01-14 10:34 - 00000000 ____D C:\Documents and Settings\user\Desktop\Архив ТСУ
2016-05-30 13:33 - 2009-12-22 12:36 - 00000000 ____D C:\Documents and Settings\user\Desktop\архив
2016-05-30 13:33 - 2009-04-07 16:52 - 00000000 ____D C:\Documents and Settings\user\Desktop\Кадастрални планове
2016-05-30 13:33 - 2009-02-05 16:28 - 00000000 ____D C:\Documents and Settings\user\Desktop\snimki
2016-05-30 13:29 - 2014-07-24 13:15 - 00000000 ____D C:\Documents and Settings\user\Desktop\anton
2016-05-30 13:29 - 2012-03-30 14:48 - 00000000 ____D C:\Documents and Settings\user\Desktop\6lamootval
2016-05-30 13:29 - 2008-11-10 15:13 - 00000000 ____D C:\Cement_PUP
2016-05-11 16:54 - 2013-07-25 16:41 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-05-11 16:53 - 2008-05-14 15:07 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\Temp
2016-05-11 16:47 - 2008-12-09 16:11 - 136686448 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-05-09 08:33 - 2014-03-24 09:34 - 00000214 _____ C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job

==================== Files in the root of some directories =======

2008-05-15 03:10 - 2012-12-14 16:20 - 0006144 _____ () C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
1899-12-30 00:00 - 1899-12-30 00:00 - 2592054 ____T () C:\Documents and Settings\All Users\Application Data\!13D214070068.bmp
1601-01-29 13:11 - 1601-01-29 13:11 - 0005718 _____ () C:\Documents and Settings\All Users\Application Data\!13D214070068.html
2011-07-19 09:27 - 2016-06-01 09:02 - 0000012 _____ () C:\Documents and Settings\All Users\Application Data\ReminderNextRun

Some files in TEMP:
====================
C:\Documents and Settings\user\Local Settings\Temp\DivXInstaller.exe
C:\Documents and Settings\user\Local Settings\Temp\WindowsInstaller-KB893803-v2-x86.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

==================== End of FRST.txt ============================

Addition.txt

Изтеглете edit-text.giffixlist.txt и го запазете на десктопа.
Стартирайте FRST.exe и натиснете бутона Fix веднъж!
След като приключи, ако ви поиска рестарт - съгласете се. След рестарта публикувайте лог файла - fixlog.txt, който ще се създаде след работата на програмата.
 
Внимание: Скрипта е създаден за текущата система. Да не се ползва за други системи с подобни проблеми!

При тази машина имаме по-малко работа:

Изтеглете edit-text.giffixlist.txt и го запазете на десктопа.
Стартирайте FRST.exe и натиснете бутона Fix веднъж!
След като приключи, ако ви поиска рестарт - съгласете се. След рестарта публикувайте лог файла - fixlog.txt, който ще се създаде след работата на програмата.
 
Внимание: Скрипта е създаден за текущата система. Да не се ползва за други системи с подобни проблеми!

След това пишете как е положението.

Поздрави!

Постоянно нещо се променя по вашите системи. Разбирам, че се работи, но в логовете ви постоянно има разминаване. Вчерашния лог показа само 10-тина файлове с името !13D214070068.txt, а днес изтритите файлове с това име са над 100 сигурно. Не може да се работи така.

Направете нова проверка с FRST като сложите отметка пред Addition.txt и след това публикувайте и двата файла.

Поздрави!

 

Логовете изглеждат наред. Аз лично бих обърнал внимание с WindBG или BlueScreenView на следния dmp файл => C:\WINDOWS\Minidump\Mini060116-01.dmp за да видя причината за синия екран.

Има и доста стари версии на програми, които е добре да се обновят. Може да се използва и PatchMyPC

Липсват и редица драйвери в Task Manager-a => за чипсета, за USB устройствата (предполагам след слагането на драйвера за чипсета ще се инсталират и USB драйверите сами),

Та, вижте модела на компютъра или дъното например с Hwinfo32 и след това свалете драйвер за чипсета от сайта на производителя на дъното и го инсталирайте.

След това ако нямате повече въпроси приключваме.

Поздрави!

  • 5 месеца по-късно...
  • Автор

Има ли вече излязал декриптор за файлове с разширение .cryp1? Трябва ми спешно! 

Има от доста време, който се обновява постоянно, но не е ефективен при всички потребители. Някои казват, че е и доста бавен, но може да се опита:

https://success.trendmicro.com/solution/1114221-downloading-and-using-the-trend-micro-ransomware-file-decryptor

Добре е да прочетете и карето в линка =>

Important Note about Decrypting CryptXXX V3

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.