Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Помощ за откриване и премахване на вируси, троянски коне и..

Featured Replies

Добре...за следните обекти...след изтриването на кеша и папките с временно съдържание нещата би трябвало да се оправят.Можеш да използваш ATF-CLEANER или CCLeaner за целта

*Trace.TrackingCookie

*Adware.Win32.OneStep.c

За троянеца...пробвай следните неща:

1.Спри System Restore

2.Почисти стартите точки за възстановяване:

3.Сега спри процеса от Task Manager (Ctrl + ALT + DEL) => Task Manager => Processes => wups32.dll => end process

Сега отвори My Computers => C:\Windows\System32 и изтрий файла wups32.dll

Ако не ти дава - пробвай под Safe Mode (припомпваш F8 по време на рестарт и избираш Safe Mode) или с помощта на програми от рода на:

*Unlocker 1.8.6

http://www.kaldata.com/comments.php?id=302...hlight=unlocker

*Pocket KillBox

http://download.bleepingcomputer.com/spyware/KillBox.exe

4.Ако искаш после пак можеш да дадеш един лог от HijackThis и този път от програмата Autoruns.

1) кликни File -> Save as;

2) запази файла някъде и след това го прикачи към темата или му копирай съдържанието.

5.Като се уверим че всичко е наред можеш отново да си пуснеш System Restore :P

Направих всичко както ми каза с изключение на Task Manager-а просто нямаше такъв процес в списъка.А ето и съдържанието на фаила.Малко е голямо ама....Благода ря ти за отзивчивостта!!HKLM\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\StartupPrograms

+ rdpclip RDP Clip Monitor Microsoft Corporation c:\windows\system32\rdpclip.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit

+ C:\WINDOWS\system32\userinit.exe Userinit Logon Application Microsoft Corporation c:\windows\system32\userinit.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell

+ Explorer.exe Windows Explorer Microsoft Corporation c:\windows\explorer.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ Adobe Photo Downloader Adobe Photoshop Album Starter Edition 3.0 component Adobe Systems Incorporated c:\program files\adobe\photoshop album starter edition\3.0\apps\apdproxy.exe

+ Adobe Reader Speed Launcher Adobe Acrobat SpeedLauncher Adobe Systems Incorporated c:\program files\adobe\reader 8.0\reader\reader_sl.exe

+ ATIPTA ATI Desktop Control Panel ATI Technologies, Inc. c:\program files\ati technologies\ati control panel\atiptaxx.exe

+ BigDog305 File not found: C:\WINDOWS\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)

+ DAEMON Tools Virtual DAEMON Manager DT Soft Ltd. c:\program files\daemon tools\daemon.exe

+ NBKeyScan File not found: C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe

+ NeroFilterCheck NeroCheck Ahead Software Gmbh c:\windows\system32\nerocheck.exe

+ nod32kui NOD32 Control Center GUI Eset c:\program files\eset\nod32kui.exe

+ RestartNeroSetup File not found: C:\Program Files\Common Files\Nero\Nero Web\SetupX.exe

+ Sony Ericsson PC Suite Application Launcher Sony Ericsson Mobile Communications AB c:\program files\sony ericsson\mobile2\application launcher\application launcher.exe

+ SoundMan Realtek Sound Manager Realtek Semiconductor Corp. C:\WINDOWS\soundman.exe

+ SunJavaUpdateSched Java Platform SE binary Sun Microsystems, Inc. c:\program files\java\jre1.6.0_05\bin\jusched.exe

+ {0228e555-4f9c-4e35-a3ec-b109a192b4c2} Gmail Notifier Google Inc. c:\program files\google\gmail notifier\gnotify.exe

C:\Documents and Settings\All Users\Start Menu\Programs\Startup

+ Adobe Reader Speed Launch.lnk Adobe Acrobat SpeedLauncher Adobe Systems Incorporated c:\program files\adobe\reader 8.0\reader\reader_sl.exe

+ hp psc 1000 series.lnk HP OfficeJet COM Device Objects Hewlett-Packard Co. c:\program files\hewlett-packard\digital imaging\bin\hpohmr08.exe

+ hpoddt01.exe.lnk hpotdd01 Hewlett-Packard c:\program files\hewlett-packard\digital imaging\bin\hpotdd01.exe

+ Microsoft Office.lnk Microsoft Office XP component Microsoft Corporation c:\program files\microsoft office\office10\osa.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run

+ BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} File not found: C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe

+ ctfmon.exe CTF Loader Microsoft Corporation c:\windows\system32\ctfmon.exe

+ Picasa Media Detector Picasa Google Inc. c:\program files\picasa2\picasamediadetector.exe

+ SkinClock c:\program files\atomic alarm clock\atomicalarmclock.exe

+ Skype Skype. Take a deep breath Skype Technologies S.A. c:\program files\skype\phone\skype.exe

+ SpybotSD TeaTimer System settings protector Safer Networking Limited c:\program files\spybot - search & destroy\teatimer.exe

HKLM\SOFTWARE\Classes\Protocols\Filter

+ application/octet-stream Microsoft .NET Runtime Execution Engine Microsoft Corporation c:\windows\system32\mscoree.dll

+ application/x-complus Microsoft .NET Runtime Execution Engine Microsoft Corporation c:\windows\system32\mscoree.dll

+ application/x-msdownload Microsoft .NET Runtime Execution Engine Microsoft Corporation c:\windows\system32\mscoree.dll

+ deflate OLE32 Extensions for Win32 Microsoft Corporation c:\windows\system32\urlmon.dll

+ gzip OLE32 Extensions for Win32 Microsoft Corporation c:\windows\system32\urlmon.dll

+ text/webviewhtml Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll

HKLM\SOFTWARE\Classes\Protocols\Handler

+ about Microsoft ® HTML Viewer Microsoft Corporation c:\windows\system32\mshtml.dll

+ cdl OLE32 Extensions for Win32 Microsoft Corporation c:\windows\system32\urlmon.dll

+ cdo Microsoft SharePoint Portal Server Object Model Microsoft Corporation c:\program files\common files\microsoft shared\web folders\pkmcdo.dll

+ dvd ActiveX control for streaming video Microsoft Corporation c:\windows\system32\msvidctl.dll

+ file OLE32 Extensions for Win32 Microsoft Corporation c:\windows\system32\urlmon.dll

+ ftp OLE32 Extensions for Win32 Microsoft Corporation c:\windows\system32\urlmon.dll

+ gopher OLE32 Extensions for Win32 Microsoft Corporation c:\windows\system32\urlmon.dll

+ http OLE32 Extensions for Win32 Microsoft Corporation c:\windows\system32\urlmon.dll

+ https OLE32 Extensions for Win32 Microsoft Corporation c:\windows\system32\urlmon.dll

+ its Microsoft® InfoTech Storage System Library Microsoft Corporation c:\windows\system32\itss.dll

+ javascript Microsoft ® HTML Viewer Microsoft Corporation c:\windows\system32\mshtml.dll

+ local OLE32 Extensions for Win32 Microsoft Corporation c:\windows\system32\urlmon.dll

+ mailto Microsoft ® HTML Viewer Microsoft Corporation c:\windows\system32\mshtml.dll

+ mhtml Microsoft Internet Messaging API Microsoft Corporation c:\windows\system32\inetcomm.dll

+ mk OLE32 Extensions for Win32 Microsoft Corporation c:\windows\system32\urlmon.dll

+ ms-its Microsoft® InfoTech Storage System Library Microsoft Corporation c:\windows\system32\itss.dll

+ mso-offdap Microsoft Office XP Web Components Microsoft Corporation c:\program files\common files\microsoft shared\web components\10\owc10.dll

+ res Microsoft ® HTML Viewer Microsoft Corporation c:\windows\system32\mshtml.dll

+ skype4com Skype for COM API Skype Technologies c:\program files\common files\skype\skype4com.dll

+ tv ActiveX control for streaming video Microsoft Corporation c:\windows\system32\msvidctl.dll

+ vbscript Microsoft ® HTML Viewer Microsoft Corporation c:\windows\system32\mshtml.dll

+ wia WIA Scripting Layer Microsoft Corporation c:\windows\system32\wiascr.dll

HKCU\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components

+ 0 File not found: About:Home

HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components

+ Address Book 6 Outlook Express Setup Library Microsoft Corporation c:\program files\outlook express\setup50.exe

+ Browser Customizations IEAK branding Microsoft Corporation c:\windows\system32\iedkcs32.dll

+ Browser Customizations IEAK branding Microsoft Corporation c:\windows\system32\iedkcs32.dll

+ IE7 Uninstall Stub IE Per User Active Setup Uninstall Utility Microsoft Corporation c:\windows\system32\ieudinit.exe

+ Internet Explorer IE Per-User Initialization Utility Microsoft Corporation c:\windows\system32\ie4uinit.exe

+ Internet Explorer IE Per-User Initialization Utility Microsoft Corporation c:\windows\system32\ie4uinit.exe

+ Microsoft Outlook Express 6 Outlook Express Setup Library Microsoft Corporation c:\program files\outlook express\setup50.exe

+ Microsoft Windows Media Player ADVPACK Microsoft Corporation c:\windows\system32\advpack.dll

+ n/a Microsoft .NET IE SECURITY REGISTRATION Microsoft Corporation c:\windows\system32\mscories.dll

+ NetMeeting 3.01 ADVPACK Microsoft Corporation c:\windows\system32\advpack.dll

+ Outlook Express Windows NT User Data Migration Tool Microsoft Corporation c:\windows\system32\shmgrate.exe

+ Themes Setup Microsoft© Register Server Microsoft Corporation c:\windows\system32\regsvr32.exe

+ Windows Desktop Update Microsoft© Register Server Microsoft Corporation c:\windows\system32\regsvr32.exe

+ Windows Media Player Microsoft Windows Media Player Setup Utility Microsoft Corporation c:\windows\inf\unregmp2.exe

+ Windows Messenger 4.7 ADVPACK Microsoft Corporation c:\windows\system32\advpack.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler

+ Browseui preloader Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Component Categories cache daemon Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad

+ CDBurn Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll

+ PostBootReminder Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll

+ SysTray Systray shell service object Microsoft Corporation c:\windows\system32\stobject.dll

+ WebCheck Web Site Monitor Microsoft Corporation c:\windows\system32\webcheck.dll

+ WPDShServiceObj Windows Portable Device Shell Service Object Microsoft Corporation c:\windows\system32\wpdshserviceobj.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks

+ URL Exec Hook Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll

HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers

+ NOD32 Context Menu Shell Extension c:\program files\eset\nodshex.dll

+ Offline Files Client Side Caching UI Microsoft Corporation c:\windows\system32\cscui.dll

+ Open With Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll

+ Open With EncryptionMenu Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll

+ Start Menu Pin Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll

+ WinRAR c:\program files\winrar\rarext.dll

HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers

+ a2FreeContMenu a-squared Free shell extension Emsi Software GmbH c:\program files\a-squared free\a2freecontmenu.dll

+ Send To Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll

HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers

+ a2FreeContMenu a-squared Free shell extension Emsi Software GmbH c:\program files\a-squared free\a2freecontmenu.dll

+ NOD32 Context Menu Shell Extension c:\program files\eset\nodshex.dll

+ WinRAR c:\program files\winrar\rarext.dll

HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers

+ EncryptionMenu Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll

+ Offline Files Client Side Caching UI Microsoft Corporation c:\windows\system32\cscui.dll

+ Sharing Shell extensions for sharing Microsoft Corporation c:\windows\system32\ntshrui.dll

+ WinRAR c:\program files\winrar\rarext.dll

HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers

+ New Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll

HKLM\Software\Classes\Folder\Shellex\ColumnHandlers

+ NeroDigitalColumnHandler Class File not found: C:\Program Files\Common Files\Nero\Lib\NeroDigitalExt.dll

+ PDF Shell Extension PDF Shell Extension Adobe Systems, Inc. c:\program files\common files\adobe\acrobat\activex\pdfshell.dll

+ {0D2E74C4-3C34-11d2-A27E-00C04FC30871} Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll

+ {24F14F01-7B1C-11d1-838f-0000F80461CF} Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll

+ {24F14F02-7B1C-11d1-838f-0000F80461CF} Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll

+ {66742402-F9B9-11D1-A202-0000F81FEDEE} Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers

+ Offline Files Client Side Caching UI Microsoft Corporation c:\windows\system32\cscui.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ %DESC_PublishDropTarget% Photo Printing Wizard Microsoft Corporation c:\windows\system32\photowiz.dll

+ &Address Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ &Links Internet Explorer Microsoft Corporation c:\windows\system32\ieframe.dll

+ .CAB file viewer Cabinet File Viewer Shell Extension Microsoft Corporation c:\windows\system32\cabview.dll

+ a-squared Free Context Menu Shell Extension a-squared Free shell extension Emsi Software GmbH c:\program files\a-squared free\a2freecontmenu.dll

+ Accessible Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ ActiveX Cache Folder Object Control Viewer Microsoft Corporation c:\windows\system32\occache.dll

+ Address EditBox Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Administrative Tools Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ Audio Media Properties Handler Media File Property Extractor Shell Extension Microsoft Corporation c:\windows\system32\shmedia.dll

+ Augmented Shell Folder Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Augmented Shell Folder 2 Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Auto Update Property Sheet Extension Automatic Updates Control Panel Microsoft Corporation c:\windows\system32\wuaucpl.cpl

+ Avi Properties Handler Media File Property Extractor Shell Extension Microsoft Corporation c:\windows\system32\shmedia.dll

+ BandProxy Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Briefcase Windows Briefcase Microsoft Corporation c:\windows\system32\syncui.dll

+ CDF Extension Copy Hook Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ Code Download Agent Web Site Monitor Microsoft Corporation c:\windows\system32\webcheck.dll

+ Compatibility Page Compatibility Tab Shell Extension DLL Microsoft Corporation c:\windows\system32\slayerxp.dll

+ Compressed (zipped) Folder Compressed (zipped) Folders Microsoft Corporation c:\windows\system32\zipfldr.dll

+ Compressed (zipped) Folder Right Drag Handler Compressed (zipped) Folders Microsoft Corporation c:\windows\system32\zipfldr.dll

+ Compressed (zipped) Folder SendTo Target Compressed (zipped) Folders Microsoft Corporation c:\windows\system32\zipfldr.dll

+ Crypto PKO Extension Crypto Shell Extensions Microsoft Corporation c:\windows\system32\cryptext.dll

+ Crypto Sign Extension Crypto Shell Extensions Microsoft Corporation c:\windows\system32\cryptext.dll

+ Custom MRU AutoCompleted List Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Darwin App Publisher Shell Application Manager Microsoft Corporation c:\windows\system32\appwiz.cpl

+ DfsShell Distributed File System shell extension Microsoft Corporation c:\windows\system32\dfsshlex.dll

+ Directory Context Menu Verbs Directory Service Common UI Microsoft Corporation c:\windows\system32\dsuiext.dll

+ Directory Object Find Directory Service Find Microsoft Corporation c:\windows\system32\dsquery.dll

+ Directory Property UI Directory Service Common UI Microsoft Corporation c:\windows\system32\dsuiext.dll

+ Directory Query UI Directory Service Find Microsoft Corporation c:\windows\system32\dsquery.dll

+ Directory Start/Search Find Directory Service Find Microsoft Corporation c:\windows\system32\dsquery.dll

+ Disk Copy Extension Windows DiskCopy Microsoft Corporation c:\windows\system32\diskcopy.dll

+ Disk Quota UI Windows Shell Disk Quota UI DLL Microsoft Corporation c:\windows\system32\dskquoui.dll

+ Display Adapter CPL Extension Advanced display adapter properties Microsoft Corporation c:\windows\system32\deskadp.dll

+ Display Monitor CPL Extension Advanced display monitor properties Microsoft Corporation c:\windows\system32\deskmon.dll

+ Display Panning CPL Extension File not found: deskpan.dll

+ Display TroubleShoot CPL Extension Advanced display performance properties Microsoft Corporation c:\windows\system32\deskperf.dll

+ Download Status Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ DS Security Page Directory Service Security UI Microsoft Corporation c:\windows\system32\dssec.dll

+ E-mail Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ Explorer Band Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ Extensions Manager Folder Extensions Manager Microsoft Corporation c:\windows\system32\extmgr.dll

+ Favorites Band Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ Fonts Windows Font Folder Microsoft Corporation c:\windows\system32\fontext.dll

+ Fonts Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ For &People... Find People Microsoft Corporation c:\program files\outlook express\wabfind.dll

+ FTP Folders Webview Microsoft Internet Explorer FTP Folder Shell Extension Microsoft Corporation c:\windows\system32\msieftp.dll

+ Fusion Cache Microsoft .NET Runtime Execution Engine Microsoft Corporation c:\windows\system32\mscoree.dll

+ GDI+ file thumbnail extractor Windows Picture and Fax Viewer Microsoft Corporation c:\windows\system32\shimgvw.dll

+ Get a Passport Wizard Map Network Drives/Network Places Wizard Microsoft Corporation c:\windows\system32\netplwiz.dll

+ Global Folder Settings Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Help and Support Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ Help and Support Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ History Internet Explorer Microsoft Corporation c:\windows\system32\ieframe.dll

+ History Band Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ HTML Thumbnail Extractor Windows Picture and Fax Viewer Microsoft Corporation c:\windows\system32\shimgvw.dll

+ HyperTerminal Icon Ext HyperTerminal Applet Library Hilgraeve, Inc. c:\windows\system32\hticons.dll

+ ICC Profile Microsoft Color Matching System User Interface DLL Microsoft Corporation c:\windows\system32\icmui.dll

+ ICM Monitor Management Microsoft Color Matching System User Interface DLL Microsoft Corporation c:\windows\system32\icmui.dll

+ ICM Printer Management Microsoft Color Matching System User Interface DLL Microsoft Corporation c:\windows\system32\icmui.dll

+ ICM Scanner Management Microsoft Color Matching System User Interface DLL Microsoft Corporation c:\windows\system32\icmui.dll

+ IE AutoComplete Internet Explorer Microsoft Corporation c:\windows\system32\ieframe.dll

+ IE BandProxy Internet Explorer Microsoft Corporation c:\windows\system32\ieframe.dll

+ IE Custom MRU AutoCompleted List Internet Explorer Microsoft Corporation c:\windows\system32\ieframe.dll

+ IE Fade Task Internet Explorer Microsoft Corporation c:\windows\system32\ieframe.dll

+ IE IShellFolderBand Internet Explorer Microsoft Corporation c:\windows\system32\ieframe.dll

+ IE Menu Band Internet Explorer Microsoft Corporation c:\windows\system32\ieframe.dll

+ IE Menu Desk Bar Internet Explorer Microsoft Corporation c:\windows\system32\ieframe.dll

+ IE Menu Site Internet Explorer Microsoft Corporation c:\windows\system32\ieframe.dll

+ IE Microsoft BrowserBand Internet Explorer Microsoft Corporation c:\windows\system32\ieframe.dll

+ IE Microsoft History AutoComplete List Internet Explorer Microsoft Corporation c:\windows\system32\ieframe.dll

+ IE Microsoft Multiple AutoComplete List Container Internet Explorer Microsoft Corporation c:\windows\system32\ieframe.dll

+ IE Microsoft Shell Folder AutoComplete List Internet Explorer Microsoft Corporation c:\windows\system32\ieframe.dll

+ IE MRU AutoComplete List Internet Explorer Microsoft Corporation c:\windows\system32\ieframe.dll

+ IE Navigation Bar Internet Explorer Microsoft Corporation c:\windows\system32\ieframe.dll

+ IE Registry Tree Options Utility Internet Explorer Microsoft Corporation c:\windows\system32\ieframe.dll

+ IE RSS Feeder Folder Internet Explorer Microsoft Corporation c:\windows\system32\ieframe.dll

+ IE Search Band Internet Explorer Microsoft Corporation c:\windows\system32\ieframe.dll

+ IE Shell Band Site Menu Internet Explorer Microsoft Corporation c:\windows\system32\ieframe.dll

+ IE Shell Rebar BandSite Internet Explorer Microsoft Corporation c:\windows\system32\ieframe.dll

+ IE Tracking Shell Menu Internet Explorer Microsoft Corporation c:\windows\system32\ieframe.dll

+ IE User Assist Internet Explorer Microsoft Corporation c:\windows\system32\ieframe.dll

+ IE4 Suite Splash Screen Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ In-pane search Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Installed Apps Enumerator Shell Application Manager Microsoft Corporation c:\windows\system32\appwiz.cpl

+ Internet Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ Internet Name Space Internet Explorer Microsoft Corporation c:\windows\system32\ieframe.dll

+ InternetShortcut Internet Explorer Microsoft Corporation c:\windows\system32\ieframe.dll

+ ISFBand OC Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ Microsoft Agent Character Property Sheet Handler Microsoft Agent Property Sheet Handler Microsoft Corporation c:\windows\msagent\agentpsh.dll

+ Microsoft Browser Architecture Internet Explorer Microsoft Corporation c:\windows\system32\ieframe.dll

+ Microsoft Browser Architecture Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ Microsoft BrowserBand Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Microsoft Data Link Microsoft Data Access - OLE DB Core Services Microsoft Corporation c:\program files\common files\system\ole db\oledb32.dll

+ Microsoft DocProp Inplace Calendar Control Microsoft DocProp Shell Ext Microsoft Corporation c:\windows\system32\docprop2.dll

+ Microsoft DocProp Inplace Droplist Combo Control Microsoft DocProp Shell Ext Microsoft Corporation c:\windows\system32\docprop2.dll

+ Microsoft DocProp Inplace Edit Box Control Microsoft DocProp Shell Ext Microsoft Corporation c:\windows\system32\docprop2.dll

+ Microsoft DocProp Inplace ML Edit Box Control Microsoft DocProp Shell Ext Microsoft Corporation c:\windows\system32\docprop2.dll

+ Microsoft DocProp Inplace Time Control Microsoft DocProp Shell Ext Microsoft Corporation c:\windows\system32\docprop2.dll

+ Microsoft DocProp Shell Ext Microsoft DocProp Shell Ext Microsoft Corporation c:\windows\system32\docprop2.dll

+ Microsoft History AutoComplete List Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Microsoft Internet Toolbar Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Microsoft Multiple AutoComplete List Container Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Microsoft Office HTML Icon Handler Microsoft Office XP component Microsoft Corporation c:\program files\microsoft office\office10\msohev.dll

+ Microsoft Outlook Custom Icon Handler Outlook Shell Hook for Start/Find Microsoft Corporation c:\program files\microsoft office\office10\olkfstub.dll

+ Microsoft Shell Folder AutoComplete List Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Microsoft Url History Service Internet Explorer Microsoft Corporation c:\windows\system32\ieframe.dll

+ Microsoft Url Search Hook Internet Explorer Microsoft Corporation c:\windows\system32\ieframe.dll

+ Midi Properties Handler Media File Property Extractor Shell Extension Microsoft Corporation c:\windows\system32\shmedia.dll

+ MMC Icon Handler MMC Shell Extension DLL Microsoft Corporation c:\windows\system32\mmcshext.dll

+ MRU AutoComplete List Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Multimedia File Property Sheet Control Panel Drivers Applet Microsoft Corporation c:\windows\system32\mmsys.cpl

+ MyDocs Copy Hook My Documents Folder UI Microsoft Corporation c:\windows\system32\mydocs.dll

+ MyDocs Drop Target My Documents Folder UI Microsoft Corporation c:\windows\system32\mydocs.dll

+ MyDocs Properties My Documents Folder UI Microsoft Corporation c:\windows\system32\mydocs.dll

+ NeroDigitalIconHandler File not found: C:\Program Files\Common Files\Nero\Lib\NeroDigitalExt.dll

+ NeroDigitalPropSheetHandler File not found: C:\Program Files\Common Files\Nero\Lib\NeroDigitalExt.dll

+ Network Connections Network Connections Shell Microsoft Corporation c:\windows\system32\netshell.dll

+ Network Connections Network Connections Shell Microsoft Corporation c:\windows\system32\netshell.dll

+ NOD32 Context Menu Shell Extension c:\program files\eset\nodshex.dll

+ NTFS Security Page Security Shell Extension Microsoft Corporation c:\windows\system32\rshx32.dll

+ Offline Files Folder Client Side Caching UI Microsoft Corporation c:\windows\system32\cscui.dll

+ Offline Files Folder Options Client Side Caching UI Microsoft Corporation c:\windows\system32\cscui.dll

+ Offline Files Menu Client Side Caching UI Microsoft Corporation c:\windows\system32\cscui.dll

+ OLE Docfile Property Page OLE DocFile Property Page Microsoft Corporation c:\windows\system32\docprop.dll

+ PlusPack CPL Extension Windows Theme API Microsoft Corporation c:\windows\system32\themeui.dll

+ Portable Devices Portable Devices Shell Extension Microsoft Corporation c:\windows\system32\wpdshext.dll

+ Portable Devices Menu Portable Devices Shell Extension Microsoft Corporation c:\windows\system32\wpdshext.dll

+ Portable Media Devices Portable Media Devices Shell Extension Microsoft Corporation c:\windows\system32\audiodev.dll

+ Previous Versions Previous Versions property page Microsoft Corporation c:\windows\system32\twext.dll

+ Previous Versions Property Page Previous Versions property page Microsoft Corporation c:\windows\system32\twext.dll

+ Print Ordering via the Web Map Network Drives/Network Places Wizard Microsoft Corporation c:\windows\system32\netplwiz.dll

+ Printers Security Page Security Shell Extension Microsoft Corporation c:\windows\system32\rshx32.dll

+ Registry Tree Options Utility Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Remote Sessions CPL Extension Remote Sessions CPL Extension Microsoft Corporation c:\windows\system32\remotepg.dll

+ Run... Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ Scanners & Cameras Imaging Devices Shell Folder UI Microsoft Corporation c:\windows\system32\wiashext.dll

+ Scanners & Cameras Imaging Devices Shell Folder UI Microsoft Corporation c:\windows\system32\wiashext.dll

+ Scanners & Cameras Imaging Devices Shell Folder UI Microsoft Corporation c:\windows\system32\wiashext.dll

+ Scanners & Cameras Imaging Devices Shell Folder UI Microsoft Corporation c:\windows\system32\wiashext.dll

+ Scanners & Cameras Imaging Devices Shell Folder UI Microsoft Corporation c:\windows\system32\wiashext.dll

+ Scheduled Tasks Task Scheduler interface DLL Microsoft Corporation c:\windows\system32\mstask.dll

+ Search Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ Search Assistant OC Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ Sendmail service Send Mail Microsoft Corporation c:\windows\system32\sendmail.dll

+ Sendmail service Send Mail Microsoft Corporation c:\windows\system32\sendmail.dll

+ Set Program Access and Defaults Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ Shell Application Manager Shell Application Manager Microsoft Corporation c:\windows\system32\appwiz.cpl

+ Shell Automation Inproc Service Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ Shell Band Site Menu Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Shell DeskBar Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Shell DeskBarApp Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Shell DocObject Viewer Internet Explorer Microsoft Corporation c:\windows\system32\ieframe.dll

+ Shell extensions for Microsoft Windows Network objects Network object shell UI Microsoft Corporation c:\windows\system32\ntlanui2.dll

+ Shell extensions for sharing Shell extensions for sharing Microsoft Corporation c:\windows\system32\ntshrui.dll

+ Shell extensions for sharing Shell extensions for sharing Microsoft Corporation c:\windows\system32\ntshrui.dll

+ Shell extensions for Windows Script Host Microsoft ® Shell Extension for Windows Script Host Microsoft Corporation c:\windows\system32\wshext.dll

+ Shell Image Data Factory Windows Picture and Fax Viewer Microsoft Corporation c:\windows\system32\shimgvw.dll

+ Shell Image Property Handler Windows Picture and Fax Viewer Microsoft Corporation c:\windows\system32\shimgvw.dll

+ Shell Image Verbs Windows Picture and Fax Viewer Microsoft Corporation c:\windows\system32\shimgvw.dll

+ Shell Microsoft AutoComplete Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Shell properties for a DS object Directory Service Find Microsoft Corporation c:\windows\system32\dsquery.dll

+ Shell Publishing Wizard Object Map Network Drives/Network Places Wizard Microsoft Corporation c:\windows\system32\netplwiz.dll

+ Shell Rebar BandSite Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Shell Scrap DataHandler Shell scrap object handler Microsoft Corporation c:\windows\system32\shscrap.dll

+ Shell Search Band Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Sony Ericsson File Manager File Manager interface Sony Ericsson Mobile Communications AB c:\program files\sony ericsson\mobile2\file manager\fmgrgui.dll

+ Subscription Folder Web Site Monitor Microsoft Corporation c:\windows\system32\webcheck.dll

+ Subscription Mgr Web Site Monitor Microsoft Corporation c:\windows\system32\webcheck.dll

+ Summary Info Thumbnail handler (DOCFILES) Windows Picture and Fax Viewer Microsoft Corporation c:\windows\system32\shimgvw.dll

+ Taskbar and Start Menu Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll

+ Tasks Folder Icon Handler Task Scheduler interface DLL Microsoft Corporation c:\windows\system32\mstask.dll

+ Tasks Folder Shell Extension Task Scheduler interface DLL Microsoft Corporation c:\windows\system32\mstask.dll

+ Temporary Internet Files Internet Explorer Microsoft Corporation c:\windows\system32\ieframe.dll

+ Temporary Internet Files Internet Explorer Microsoft Corporation c:\windows\system32\ieframe.dll

+ The Internet Internet Explorer Microsoft Corporation c:\windows\system32\ieframe.dll

+ Track Popup Bar Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ TridentImageExtractor Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ User Accounts Map Network Drives/Network Places Wizard Microsoft Corporation c:\windows\system32\netplwiz.dll

+ User Assist Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Video Media Properties Handler Media File Property Extractor Shell Extension Microsoft Corporation c:\windows\system32\shmedia.dll

+ Video Thumbnail Extractor Media File Property Extractor Shell Extension Microsoft Corporation c:\windows\system32\shmedia.dll

+ Wav Properties Handler Media File Property Extractor Shell Extension Microsoft Corporation c:\windows\system32\shmedia.dll

+ Web Folders Microsoft Web Folders Microsoft Corporation c:\program files\common files\microsoft shared\web folders\msonsext.dll

+ Web Printer Shell Extension Print UI DLL Microsoft Corporation c:\windows\system32\printui.dll

+ Web Publishing Wizard Map Network Drives/Network Places Wizard Microsoft Corporation c:\windows\system32\netplwiz.dll

+ Web Search Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ WebCheck Web Site Monitor Microsoft Corporation c:\windows\system32\webcheck.dll

+ WebCheck SyncMgr Handler Web Site Monitor Microsoft Corporation c:\windows\system32\webcheck.dll

+ WebCheckWebCrawler Web Site Monitor Microsoft Corporation c:\windows\system32\webcheck.dll

+ Windows Media Player Add to Playlist Context Menu Handler Windows Media Player Launcher Microsoft Corporation c:\windows\system32\wmpshell.dll

+ Windows Media Player Burn Audio CD Context Menu Handler Windows Media Player Launcher Microsoft Corporation c:\windows\system32\wmpshell.dll

+ Windows Media Player Play as Playlist Context Menu Handler Windows Media Player Launcher Microsoft Corporation c:\windows\system32\wmpshell.dll

+ WinRAR shell extension c:\program files\winrar\rarext.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

+ Adobe PDF Reader Link Helper Adobe PDF Helper for Internet Explorer Adobe Systems Incorporated c:\program files\common files\adobe\acrobat\activex\acroiehelper.dll

+ FGCatchUrl Flashget CatchUrl Module www.flashget.com c:\program files\flashget\jccatch.dll

+ FlashGet GetFlash Class Flashget GetFlash Module www.flashget.com c:\program files\flashget\getflash.dll

+ Spybot-S&D IE Protection SBSD IE Protection Safer Networking Limited c:\program files\spybot - search & destroy\sdhelper.dll

+ SSVHelper Class Java Platform SE binary Sun Microsystems, Inc. c:\program files\java\jre1.6.0_05\bin\ssv.dll

HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks

+ Microsoft Url Search Hook Internet Explorer Microsoft Corporation c:\windows\system32\ieframe.dll

HKLM\Software\Microsoft\Internet Explorer\Extensions

+ Diagnose Connection Problems... Network Diagnostic for Windows XP Microsoft Corporation c:\windows\network diagnostic\xpnetdiag.exe

+ FlashGet FlashGet FlashGet.com c:\program files\flashget\flashget.exe

+ Windows Messenger Windows Messenger Microsoft Corporation c:\program files\messenger\msmsgs.exe

Task Scheduler

+ rpc.job File not found: C:\Program Files\Winferno\RegistryPowerCleaner\RegPowerClean.exe

HKLM\System\CurrentControlSet\Services

+ a2free Scans the PC for unwanted software and provides protection from malicious code Emsi Software GmbH c:\program files\a-squared free\a2service.exe

+ Ati HotKey Poller c:\windows\system32\ati2evxx.exe

+ ATI Smart ATI Smart c:\windows\system32\ati2sgag.exe

+ AudioSrv Manages audio devices for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\audiosrv.dll

+ BITS Transfers data between clients and servers in the background. If BITS is disabled, features such as Windows Update will not work correctly. Microsoft Corporation c:\windows\system32\qmgr.dll

+ Browser Maintains an updated list of computers on the network and supplies this list to computers designated as browsers. If this service is stopped, this list will not be updated or maintained. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\browser.dll

+ CryptSvc Provides three management services: Catalog Database Service, which confirms the signatures of Windows files; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Key Service, which helps enroll this computer for certificates. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\cryptsvc.dll

+ DcomLaunch Provides launch functionality for DCOM services. Microsoft Corporation c:\windows\system32\rpcss.dll

+ Dhcp Manages network configuration by registering and updating IP addresses and DNS names. Microsoft Corporation c:\windows\system32\dhcpcsvc.dll

+ dmserver Detects and monitors new hard disk drives and sends disk volume information to Logical Disk Manager Administrative Service for configuration. If this service is stopped, dynamic disk status and configuration information may become out of date. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corp. c:\windows\system32\dmserver.dll

+ Dnscache Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\dnsrslvr.dll

+ ERSvc Allows error reporting for services and applictions running in non-standard environments. Microsoft Corporation c:\windows\system32\ersvc.dll

+ Eventlog Enables event log messages issued by Windows-based programs and components to be viewed in Event Viewer. This service cannot be stopped. Microsoft Corporation c:\windows\system32\services.exe

+ helpsvc Enables Help and Support Center to run on this computer. If this service is stopped, Help and Support Center will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\pchealth\helpctr\binaries\pchsvc.dll

+ lanmanserver Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\srvsvc.dll

+ lanmanworkstation Creates and maintains client network connections to remote servers. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\wkssvc.dll

+ LmHosts Enables support for NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution. Microsoft Corporation c:\windows\system32\lmhsvc.dll

+ NOD32krn NOD32 Kernel Service Eset c:\program files\eset\nod32krn.exe

+ PlugPlay Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability. Microsoft Corporation c:\windows\system32\services.exe

+ PolicyAgent Manages IP security policy and starts the ISAKMP/Oakley (IKE) and the IP security driver. Microsoft Corporation c:\windows\system32\lsass.exe

+ ProtectedStorage Provides protected storage for sensitive data, such as private keys, to prevent access by unauthorized services, processes, or users. Microsoft Corporation c:\windows\system32\lsass.exe

+ RemoteRegistry Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\regsvc.dll

+ RpcSs Provides the endpoint mapper and other miscellaneous RPC services. Microsoft Corporation c:\windows\system32\rpcss.dll

+ SamSs Stores security information for local user accounts. Microsoft Corporation c:\windows\system32\lsass.exe

+ Schedule Enables a user to configure and schedule automated tasks on this computer. If this service is stopped, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\schedsvc.dll

+ seclogon Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\seclogon.dll

+ SENS Tracks system events such as Windows logon, network, and power events. Notifies COM+ Event System subscribers of these events. Microsoft Corporation c:\windows\system32\sens.dll

+ SharedAccess Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network. Microsoft Corporation c:\windows\system32\ipnathlp.dll

+ ShellHWDetection Provides notifications for AutoPlay hardware events. Microsoft Corporation c:\windows\system32\shsvcs.dll

+ Spooler Loads files to memory for later printing. Microsoft Corporation c:\windows\system32\spoolsv.exe

+ srservice Performs system restore functions. To stop service, turn off System Restore from the System Restore tab in My Computer->Properties Microsoft Corporation c:\windows\system32\srsvc.dll

+ stisvc Provides image acquisition services for scanners and cameras. Microsoft Corporation c:\windows\system32\wiaservc.dll

+ Themes Provides user experience theme management. Microsoft Corporation c:\windows\system32\shsvcs.dll

+ TrkWks Maintains links between NTFS files within a computer or across computers in a network domain. Microsoft Corporation c:\windows\system32\trkwks.dll

+ W32Time Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\w32time.dll

+ WebClient Enables Windows-based programs to create, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\webclnt.dll

+ winmgmt Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\wbem\wmisvc.dll

+ wscsvc Monitors system security settings and configurations. Microsoft Corporation c:\windows\system32\wscsvc.dll

+ wuauserv Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site. Microsoft Corporation c:\windows\system32\wuauserv.dll

+ WZCSVC Provides automatic configuration for the 802.11 adapters Microsoft Corporation c:\windows\system32\wzcsvc.dll

HKLM\System\CurrentControlSet\Services

+ ACPI ACPI Driver for NT Microsoft Corporation c:\windows\system32\drivers\acpi.sys

+ aec Microsoft Acoustic Echo Canceller Microsoft Corporation c:\windows\system32\drivers\aec.sys

+ AFD AFD Networking Support Environment Microsoft Corporation c:\windows\system32\drivers\afd.sys

+ AFS2K Audio File System Oak Technology Inc. c:\windows\system32\drivers\afs2k.sys

+ agp440 440 NT AGP Filter Microsoft Corporation c:\windows\system32\drivers\agp440.sys

+ ALCXSENS Sensaura WDM 3D Audio Driver Sensaura Ltd c:\windows\system32\drivers\alcxsens.sys

+ ALCXWDM Realtek AC'97 Audio Driver (WDM) Realtek Semiconductor Corp. c:\windows\system32\drivers\alcxwdm.sys

+ AMON Amon monitor Eset c:\windows\system32\drivers\amon.sys

+ AN983 ADMtek AN983/AN985/ADM951X NDIS5 Driver ADMtek Incorporated. c:\windows\system32\drivers\an983.sys

+ AsyncMac RAS Asynchronous Media Driver Microsoft Corporation c:\windows\system32\drivers\asyncmac.sys

+ atapi IDE/ATAPI Port Driver Microsoft Corporation c:\windows\system32\drivers\atapi.sys

+ ati2mtag ATI Radeon WindowsNT Miniport Driver ATI Technologies Inc. c:\windows\system32\drivers\ati2mtag.sys

+ Atmarpc ATM ARP Client Protocol Microsoft Corporation c:\windows\system32\drivers\atmarpc.sys

+ audstub AudStub Driver Microsoft Corporation c:\windows\system32\drivers\audstub.sys

+ avco1klo File not found: C:\WINDOWS\System32\Drivers\avco1klo.sys

+ Beep BEEP Driver Microsoft Corporation c:\windows\system32\drivers\beep.sys

+ CCDECODE WDM Closed Caption VBI Codec Microsoft Corporation c:\windows\system32\drivers\ccdecode.sys

+ Cdaudio CD-ROM Audio Filter Driver Microsoft Corporation c:\windows\system32\drivers\cdaudio.sys

+ Cdrom SCSI CD-ROM Driver Microsoft Corporation c:\windows\system32\drivers\cdrom.sys

+ Changer File not found: C:\WINDOWS\System32\Drivers\Changer.sys

+ Disk PnP Disk Driver Microsoft Corporation c:\windows\system32\drivers\disk.sys

+ dmio NT Disk Manager I/O Driver Microsoft Corp., Veritas Software c:\windows\system32\drivers\dmio.sys

+ dmload NT Disk Manager Startup Driver Microsoft Corp., Veritas Software. c:\windows\system32\drivers\dmload.sys

+ DMusic Microsoft Kernel DLS Synthesizer Microsoft Corporation c:\windows\system32\drivers\dmusic.sys

+ drmkaud Microsoft Kernel DRM Audio Descrambler Filter Microsoft Corporation c:\windows\system32\drivers\drmkaud.sys

+ Fdc Floppy Disk Controller Driver Microsoft Corporation c:\windows\system32\drivers\fdc.sys

+ Fips FIPS Crypto Driver Microsoft Corporation c:\windows\system32\drivers\fips.sys

+ Flpydisk Floppy Driver Microsoft Corporation c:\windows\system32\drivers\flpydisk.sys

+ FltMgr File System Filter Manager Driver Microsoft Corporation c:\windows\system32\drivers\fltmgr.sys

+ Ftdisk FT Disk Driver Microsoft Corporation c:\windows\system32\drivers\ftdisk.sys

+ gameenum Game Port Enumerator Microsoft Corporation c:\windows\system32\drivers\gameenum.sys

+ Gpc Generic Packet Classifier Microsoft Corporation c:\windows\system32\drivers\msgpc.sys

+ GVCplDrv c:\windows\system32\drivers\gvcpldrv.sys

+ HPZid412 IEEE-1284.4-1999 Driver (Windows 2000) HP c:\windows\system32\drivers\hpzid412.sys

+ HPZipr12 IEEE-1284.4-1999 Print Class Driver HP c:\windows\system32\drivers\hpzipr12.sys

+ HPZius12 1284.4<->Usb Datalink Driver (Windows 2000) HP c:\windows\system32\drivers\hpzius12.sys

+ HTTP This service implements the hypertext transfer protocol (HTTP). If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\drivers\http.sys

+ i2omgmt File not found: C:\WINDOWS\System32\Drivers\i2omgmt.sys

+ i8042prt i8042 Port Driver Microsoft Corporation c:\windows\system32\drivers\i8042prt.sys

+ Imapi IMAPI Kernel Driver Microsoft Corporation c:\windows\system32\drivers\imapi.sys

+ InCDPass File not found: system32\drivers\InCDPass.sys

+ InCDRm File not found: system32\drivers\InCDRm.sys

+ IntelIde Intel PCI IDE Driver Microsoft Corporation c:\windows\system32\drivers\intelide.sys

+ intelppm Processor Device Driver Microsoft Corporation c:\windows\system32\drivers\intelppm.sys

+ Ip6Fw Provides intrusion prevention service for a home or small office network. Microsoft Corporation c:\windows\system32\drivers\ip6fw.sys

+ IpFilterDriver IP Traffic Filter Driver Microsoft Corporation c:\windows\system32\drivers\ipfltdrv.sys

+ IpInIp IP in IP Tunnel Driver Microsoft Corporation c:\windows\system32\drivers\ipinip.sys

+ IpNat IP Network Address Translator Microsoft Corporation c:\windows\system32\drivers\ipnat.sys

+ IPSec IPSEC driver Microsoft Corporation c:\windows\system32\drivers\ipsec.sys

+ IRENUM Infra-Red Bus Enumerator Microsoft Corporation c:\windows\system32\drivers\irenum.sys

+ isapnp PNP ISA Bus Driver Microsoft Corporation c:\windows\system32\drivers\isapnp.sys

+ Kbdclass Keyboard Class Driver Microsoft Corporation c:\windows\system32\drivers\kbdclass.sys

+ kmixer Kernel Mode Audio Mixer Microsoft Corporation c:\windows\system32\drivers\kmixer.sys

+ KSecDD Kernel Security Support Provider Interface Microsoft Corporation c:\windows\system32\drivers\ksecdd.sys

+ lbrtfdc File not found: C:\WINDOWS\System32\Drivers\lbrtfdc.sys

+ mnmdd Frame buffer simulator Microsoft Corporation c:\windows\system32\drivers\mnmdd.sys

+ Modem Modem Device Driver Microsoft Corporation c:\windows\system32\drivers\modem.sys

+ Mouclass Mouse Class Driver Microsoft Corporation c:\windows\system32\drivers\mouclass.sys

+ MountMgr Mount Manager Microsoft Corporation c:\windows\system32\drivers\mountmgr.sys

+ MRxDAV WebDav Client Redirector Microsoft Corporation c:\windows\system32\drivers\mrxdav.sys

+ MRxSmb MRXSMB Microsoft Corporation c:\windows\system32\drivers\mrxsmb.sys

+ Msfs Mailslot driver Microsoft Corporation c:\windows\system32\drivers\msfs.sys

+ MSKSSRV MS KS Server Microsoft Corporation c:\windows\system32\drivers\mskssrv.sys

+ MSPCLOCK MS Proxy Clock Microsoft Corporation c:\windows\system32\drivers\mspclock.sys

+ MSPQM MS Proxy Quality Manager Microsoft Corporation c:\windows\system32\drivers\mspqm.sys

+ mssmbios System Management BIOS Driver Microsoft Corporation c:\windows\system32\drivers\mssmbios.sys

+ MSTEE WDM Tee/Communication Transform Filter Microsoft Corporation c:\windows\system32\drivers\mstee.sys

+ Mup Multiple UNC Provider driver Microsoft Corporation c:\windows\system32\drivers\mup.sys

+ NABTSFEC WDM NABTS/FEC VBI Codec Microsoft Corporation c:\windows\system32\drivers\nabtsfec.sys

+ NDIS NDIS 5.1 wrapper driver Microsoft Corporation c:\windows\system32\drivers\ndis.sys

+ NdisIP Microsoft IP Driver Microsoft Corporation c:\windows\system32\drivers\ndisip.sys

+ NdisTapi Remote Access NDIS TAPI Driver Microsoft Corporation c:\windows\system32\drivers\ndistapi.sys

+ Ndisuio NDIS Usermode I/O Protocol Microsoft Corporation c:\windows\system32\drivers\ndisuio.sys

+ NdisWan Remote Access NDIS WAN Driver Microsoft Corporation c:\windows\system32\drivers\ndiswan.sys

+ NDProxy NDIS Proxy Microsoft Corporation c:\windows\system32\drivers\ndproxy.sys

+ NetBIOS NetBIOS Interface Microsoft Corporation c:\windows\system32\drivers\netbios.sys

+ NetBT NetBios over Tcpip Microsoft Corporation c:\windows\system32\drivers\netbt.sys

+ Npfs NPFS Driver Microsoft Corporation c:\windows\system32\drivers\npfs.sys

+ Null NULL Driver Microsoft Corporation c:\windows\system32\drivers\null.sys

+ NwlnkFlt IPX Traffic Filter Driver Microsoft Corporation c:\windows\system32\drivers\nwlnkflt.sys

+ NwlnkFwd IPX Traffic Forwarder Driver Microsoft Corporation c:\windows\system32\drivers\nwlnkfwd.sys

+ Parport Parallel Port Driver Microsoft Corporation c:\windows\system32\drivers\parport.sys

+ PartMgr Partition Manager Microsoft Corporation c:\windows\system32\drivers\partmgr.sys

+ ParVdm VDM Parallel Driver Microsoft Corporation c:\windows\system32\drivers\parvdm.sys

+ PCI NT Plug and Play PCI Enumerator Microsoft Corporation c:\windows\system32\drivers\pci.sys

+ PCIDump File not found: C:\WINDOWS\System32\Drivers\PCIDump.sys

+ PCIIde Generic PCI IDE Bus Driver Microsoft Corporation c:\windows\system32\drivers\pciide.sys

+ PDCOMP File not found: C:\WINDOWS\System32\Drivers\PDCOMP.sys

+ PDFRAME File not found: C:\WINDOWS\System32\Drivers\PDFRAME.sys

+ PDRELI File not found: C:\WINDOWS\System32\Drivers\PDRELI.sys

+ PDRFRAME File not found: C:\WINDOWS\System32\Drivers\PDRFRAME.sys

+ PptpMiniport WAN Miniport (PPTP) Microsoft Corporation c:\windows\system32\drivers\raspptp.sys

+ PSched QoS Packet Scheduler Microsoft Corporation c:\windows\system32\drivers\psched.sys

+ Ptilink Direct Parallel Link Driver Parallel Technologies, Inc. c:\windows\system32\drivers\ptilink.sys

+ PxHelp20 Px Engine Device Driver for Windows 2000/XP Sonic Solutions c:\windows\system32\drivers\pxhelp20.sys

+ RasAcd Remote Access Auto Connection Driver Microsoft Corporation c:\windows\system32\drivers\rasacd.sys

+ Rasl2tp WAN Miniport (L2TP) Microsoft Corporation c:\windows\system32\drivers\rasl2tp.sys

+ RasPppoe Remote Access PPPOE Driver Microsoft Corporation c:\windows\system32\drivers\raspppoe.sys

+ Raspti Direct Parallel Microsoft Corporation c:\windows\system32\drivers\raspti.sys

+ Rdbss Rdbss Microsoft Corporation c:\windows\system32\drivers\rdbss.sys

+ RDPCDD RDP Miniport Microsoft Corporation c:\windows\system32\drivers\rdpcdd.sys

+ rdpdr Microsoft RDP Device redirector Microsoft Corporation c:\windows\system32\drivers\rdpdr.sys

+ RDPWD RDP Terminal Stack Driver (US/Canada Only, Not for Export) Microsoft Corporation c:\windows\system32\drivers\rdpwd.sys

+ redbook Redbook Audio Filter Driver Microsoft Corporation c:\windows\system32\drivers\redbook.sys

+ rspndr Allows this PC to be discovered and located on the network. Microsoft Corporation c:\windows\system32\drivers\rspndr.sys

+ Secdrv SafeDisc driver Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K. c:\windows\system32\drivers\secdrv.sys

+ serenum Serial Port Enumerator Microsoft Corporation c:\windows\system32\drivers\serenum.sys

+ Serial Serial Device Driver Microsoft Corporation c:\windows\system32\drivers\serial.sys

+ Sfloppy SCSI Floppy Driver Microsoft Corporation c:\windows\system32\drivers\sfloppy.sys

+ SLIP Microsoft Slip Deframing Filter Minidriver Microsoft Corporation c:\windows\system32\drivers\slip.sys

+ splitter Microsoft Kernel Audio Splitter Microsoft Corporation c:\windows\system32\drivers\splitter.sys

+ sptd c:\windows\system32\drivers\sptd.sys

+ Srv Srv Microsoft Corporation c:\windows\system32\drivers\srv.sys

+ ss_bus SAMSUNG Mobile USB Device 1.0 Driver MCCI c:\windows\system32\drivers\ss_bus.sys

+ ss_mdfl SAMSUNG Mobile USB Modem 1.0 Filter MCCI c:\windows\system32\drivers\ss_mdfl.sys

+ ss_mdm SAMSUNG Mobile USB Modem 1.0 Drivers MCCI c:\windows\system32\drivers\ss_mdm.sys

+ StarOpen c:\windows\system32\drivers\staropen.sys

+ streamip Microsoft IP Test Driver Microsoft Corporation c:\windows\system32\drivers\streamip.sys

+ swenum Plug and Play Software Device Enumerator Microsoft Corporation c:\windows\system32\drivers\swenum.sys

+ swmidi Microsoft GS Wavetable Synthesizer Microsoft Corporation c:\windows\system32\drivers\swmidi.sys

+ sysaudio System Audio WDM Filter Microsoft Corporation c:\windows\system32\drivers\sysaudio.sys

+ Tcpip TCP/IP Protocol Driver Microsoft Corporation c:\windows\system32\drivers\tcpip.sys

+ TDPIPE Named Pipe Transport Driver Microsoft Corporation c:\windows\system32\drivers\tdpipe.sys

+ TDTCP TCP Transport Driver Microsoft Corporation c:\windows\system32\drivers\tdtcp.sys

+ TermDD Terminal Server Driver Microsoft Corporation c:\windows\system32\drivers\termdd.sys

+ Update Update Driver Microsoft Corporation c:\windows\system32\drivers\update.sys

+ usbccgp USB Common Class Generic Parent Driver Microsoft Corporation c:\windows\system32\drivers\usbccgp.sys

+ usbehci EHCI eUSB Miniport Driver Microsoft Corporation c:\windows\system32\drivers\usbehci.sys

+ usbhub Default Hub Driver for USB Microsoft Corporation c:\windows\system32\drivers\usbhub.sys

+ usbprint USB Printer driver Microsoft Corporation c:\windows\system32\drivers\usbprint.sys

+ usbscan USB Scanner Driver Microsoft Corporation c:\windows\system32\drivers\usbscan.sys

+ USBSTOR USB Mass Storage Class Driver Microsoft Corporation c:\windows\system32\drivers\usbstor.sys

+ usbuhci UHCI USB Miniport Driver Microsoft Corporation c:\windows\system32\drivers\usbuhci.sys

+ VgaSave VGA/Super VGA Video Driver Microsoft Corporation c:\windows\system32\drivers\vga.sys

+ VolSnap Volume Shadow Copy Driver Microsoft Corporation c:\windows\system32\drivers\volsnap.sys

+ w200bus Sony Ericsson W200 Driver MCCI c:\windows\system32\drivers\w200bus.sys

+ w200mdfl Sony Ericsson W200 USB WMC Modem Filter MCCI c:\windows\system32\drivers\w200mdfl.sys

+ w200mdm Sony Ericsson W200 USB WMC Modem Driver MCCI c:\windows\system32\drivers\w200mdm.sys

+ w200mgmt Sony Ericsson W200 USB WMC Device Management Drivers (WDM) MCCI c:\windows\system32\drivers\w200mgmt.sys

+ w200obex Sony Ericsson W200 USB WMC OBEX Interface MCCI c:\windows\system32\drivers\w200obex.sys

+ Wanarp Remote Access IP ARP Driver Microsoft Corporation c:\windows\system32\drivers\wanarp.sys

+ WDICA File not found: C:\WINDOWS\System32\Drivers\WDICA.sys

+ wdmaud MMSYSTEM Wave/Midi API mapper Microsoft Corporation c:\windows\system32\drivers\wdmaud.sys

+ WS2IFSL Winsock2 IFS Layer Microsoft Corporation c:\windows\system32\drivers\ws2ifsl.sys

+ WSTCODEC WDM WST Codec Driver Microsoft Corporation c:\windows\system32\drivers\wstcodec.sys

+ WudfPf Provide communciation services for UMDF components. Microsoft Corporation c:\windows\system32\drivers\wudfpf.sys

+ WudfRd Reflect device requests to user-mode driver drivers Microsoft Corporation c:\windows\system32\drivers\wudfrd.sys

+ yukonwxp NDIS5.1 Miniport Driver for Marvell Yukon Gigabit Ethernet Adapter Marvell Semiconductor Inc. c:\windows\system32\drivers\yukonwxp.sys

+ ZSMC0305 File not found: System32\Drivers\usbVM305.sys

HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute

+ autocheck autochk * Auto Check Utility Microsoft Corporation c:\windows\system32\autochk.exe

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options

+ Your Image File Name Here without a path Symbolic Debugger for Windows 2000 Microsoft Corporation c:\windows\system32\ntsd.exe

HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls

+ advapi32 Advanced Windows 32 Base API Microsoft Corporation c:\windows\system32\advapi32.dll

+ comdlg32 Common Dialogs DLL Microsoft Corporation c:\windows\system32\comdlg32.dll

+ gdi32 GDI Client DLL Microsoft Corporation c:\windows\system32\gdi32.dll

+ imagehlp Windows NT Image Helper Microsoft Corporation c:\windows\system32\imagehlp.dll

+ kernel32 Windows NT BASE API Client DLL Microsoft Corporation c:\windows\system32\kernel32.dll

+ lz32 LZ Expand/Compress API DLL Microsoft Corporation c:\windows\system32\lz32.dll

+ ole32 Microsoft OLE for Windows Microsoft Corporation c:\windows\system32\ole32.dll

+ oleaut32 Microsoft Corporation c:\windows\system32\oleaut32.dll

+ olecli32 Object Linking and Embedding Client Library Microsoft Corporation c:\windows\system32\olecli32.dll

+ olecnv32 Microsoft OLE for Windows Microsoft Corporation c:\windows\system32\olecnv32.dll

+ olesvr32 Object Linking and Embedding Server Library Microsoft Corporation c:\windows\system32\olesvr32.dll

+ olethk32 Microsoft OLE for Windows Microsoft Corporation c:\windows\system32\olethk32.dll

+ rpcrt4 Remote Procedure Call Runtime Microsoft Corporation c:\windows\system32\rpcrt4.dll

+ shell32 Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll

+ url Internet Shortcut Shell Extension DLL Microsoft Corporation c:\windows\system32\url.dll

+ urlmon OLE32 Extensions for Win32 Microsoft Corporation c:\windows\system32\urlmon.dll

+ user32 Windows XP USER API Client DLL Microsoft Corporation c:\windows\system32\user32.dll

+ version Version Checking and File Installation Libraries Microsoft Corporation c:\windows\system32\version.dll

+ wininet Internet Extensions for Win32 Microsoft Corporation c:\windows\system32\wininet.dll

+ wldap32 Win32 LDAP API DLL Microsoft Corporation c:\windows\system32\wldap32.dll

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UIHost

+ logonui.exe Windows Logon UI Microsoft Corporation c:\windows\system32\logonui.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify

+ AtiExtEvent c:\windows\system32\ati2evxx.dll

+ crypt32chain Crypto API32 Microsoft Corporation c:\windows\system32\crypt32.dll

+ cryptnet Crypto Network Related API Microsoft Corporation c:\windows\system32\cryptnet.dll

+ cscdll Offline Network Agent Microsoft Corporation c:\windows\system32\cscdll.dll

+ ScCertProp Common DLL to receive Winlogon notifications Microsoft Corporation c:\windows\system32\wlnotify.dll

+ Schedule Common DLL to receive Winlogon notifications Microsoft Corporation c:\windows\system32\wlnotify.dll

+ sclgntfy Secondary Logon Service Notification DLL Microsoft Corporation c:\windows\system32\sclgntfy.dll

+ SensLogn Common DLL to receive Winlogon notifications Microsoft Corporation c:\windows\system32\wlnotify.dll

+ termsrv Common DLL to receive Winlogon notifications Microsoft Corporation c:\windows\system32\wlnotify.dll

+ wlballoon Common DLL to receive Winlogon notifications Microsoft Corporation c:\windows\system32\wlnotify.dll

HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{14DD72BC-6637-462E-A947-AF14F41A1681}] DATAGRAM 4 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{14DD72BC-6637-462E-A947-AF14F41A1681}] SEQPACKET 4 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{371B0FE4-E83B-47C2-BDF8-A39BF8114D54}] DATAGRAM 1 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{371B0FE4-E83B-47C2-BDF8-A39BF8114D54}] SEQPACKET 1 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{493BC3B0-4809-45F5-B99F-B3827C0C8B53}] DATAGRAM 0 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{493BC3B0-4809-45F5-B99F-B3827C0C8B53}] SEQPACKET 0 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{79EF375E-572C-4AFC-B483-483200E5407D}] DATAGRAM 2 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{79EF375E-572C-4AFC-B483-483200E5407D}] SEQPACKET 2 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{D6C6F693-BEE9-41EC-899E-236BE674B093}] DATAGRAM 3 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{D6C6F693-BEE9-41EC-899E-236BE674B093}] SEQPACKET 3 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD Tcpip [RAW/IP] Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD Tcpip [TCP/IP] Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD Tcpip [uDP/IP] Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ NOD32 NOD32 IMON - Internet scanning support Eset c:\windows\system32\imon.dll

+ NOD32 protected [MSAFD Tcpip [RAW/IP]] NOD32 IMON - Internet scanning support Eset c:\windows\system32\imon.dll

+ NOD32 protected [MSAFD Tcpip [TCP/IP]] NOD32 IMON - Internet scanning support Eset c:\windows\system32\imon.dll

+ NOD32 protected [MSAFD Tcpip [uDP/IP]] NOD32 IMON - Internet scanning support Eset c:\windows\system32\imon.dll

+ NOD32 protected [RSVP TCP Service Provider] NOD32 IMON - Internet scanning support Eset c:\windows\system32\imon.dll

+ NOD32 protected [RSVP UDP Service Provider] NOD32 IMON - Internet scanning support Eset c:\windows\system32\imon.dll

+ RSVP TCP Service Provider Microsoft Windows Rsvp 1.0 Service Provider Microsoft Corporation c:\windows\system32\rsvpsp.dll

+ RSVP UDP Service Provider Microsoft Windows Rsvp 1.0 Service Provider Microsoft Corporation c:\windows\system32\rsvpsp.dll

HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors

+ BJ Language Monitor Langage Monitor for Canon Bubble-Jet Printer Microsoft Corporation c:\windows\system32\cnbjmon.dll

+ hpzsnt07 HP c:\windows\system32\hpzsnt07.dll

+ Local Port Local Spooler DLL Microsoft Corporation c:\windows\system32\localspl.dll

+ PJL Language Monitor PJL Language monitor Microsoft Corporation c:\windows\system32\pjlmon.dll

+ Standard TCP/IP Port Standard TCP/IP Port Monitor DLL Microsoft Corporation c:\windows\system32\tcpmon.dll

+ USB Monitor Standard Dynamic Printing Port Monitor DLL Microsoft Corporation c:\windows\system32\usbmon.dll

HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SecurityProviders

+ digest.dll Digest SSPI Authentication Package Microsoft Corporation c:\windows\system32\digest.dll

+ msapsspc.dll DPA Client for 32 bit platforms Microsoft Corporation c:\windows\system32\msapsspc.dll

+ msnsspc.dll MSN Internet Access Microsoft Corporation c:\windows\system32\msnsspc.dll

+ schannel.dll TLS / SSL Security Provider Microsoft Corporation c:\windows\system32\schannel.dll

HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages

+ msv1_0 Microsoft Authentication Package v1.0 Microsoft Corporation c:\windows\system32\msv1_0.dll

HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Notification Packages

+ scecli Windows Security Configuration Editor Client Engine Microsoft Corporation c:\windows\system32\scecli.dll

HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Security Packages

+ kerberos Kerberos Security Package Microsoft Corporation c:\windows\system32\kerberos.dll

+ msv1_0 Microsoft Authentication Package v1.0 Microsoft Corporation c:\windows\system32\msv1_0.dll

+ schannel TLS / SSL Security Provider Microsoft Corporation c:\windows\system32\schannel.dll

+ wdigest Microsoft Digest Access Microsoft Corporation c:\windows\system32\wdigest.dll

HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order

+ LanmanWorkstation Microsoft Windows Network Microsoft Corporation c:\windows\system32\ntlanman.dll

+ RDPNP Microsoft Terminal Services Microsoft Corporation c:\windows\system32\drprov.dll

+ WebClient Web Client Network Microsoft Corporation c:\windows\system32\davclnt.dll

  • Отговори 2,6k
  • Прегледи 174,8k
  • Създадено
  • Последен отговор

Потребители с най-много отговори

Най-популярни публикации

  • Логът вече беше искан, чети преди да пишеш. От HiJackThis, можеш да получиш само най-основната информация. Освен това ComboFix в случая е подходящ, затова вземи да прочетеш нещичко.

  • Avira те е почистила много добре. Вече може да се каже, че си чист. Браво на B-Boy

  • Благодаря б-бой :Р Сложих и WoT

Публикувани изображения

Хммм би трябвало автоматично версия 9.13 на Autoruns да има отметка

Options => Hide Microsoft Entries, но както и да е.

В програмата не се вижда вече процес стартиращ със системата от рода на wups32.dll.

Можеш да махнеш отметките в Autoruns все пак на тези липсващи обекти:

+ BigDog305 File not found: C:\WINDOWS\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)

+ NBKeyScan File not found: C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe

+ RestartNeroSetup File not found: C:\Program Files\Common Files\Nero\Nero Web\SetupX.exe

+ BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} File not found: C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe

+ 0 File not found: About:Home

+ NeroDigitalColumnHandler Class File not found: C:\Program Files\Common Files\Nero\Lib\NeroDigitalExt.dll

+ Display Panning CPL Extension File not found: deskpan.dll

+ NeroDigitalIconHandler File not found: C:\Program Files\Common Files\Nero\Lib\NeroDigitalExt.dll

+ NeroDigitalPropSheetHandler File not found: C:\Program Files\Common Files\Nero\Lib\NeroDigitalExt.dll

+ rpc.job File not found: C:\Program Files\Winferno\RegistryPowerCleaner\RegPowerClean.exe

HKLM\System\CurrentControlSet\Services

+ avco1klo File not found: C:\WINDOWS\System32\Drivers\avco1klo.sys

+ Changer File not found: C:\WINDOWS\System32\Drivers\Changer.sys

+ i2omgmt File not found: C:\WINDOWS\System32\Drivers\i2omgmt.sys

+ InCDPass File not found: system32\drivers\InCDPass.sys

+ InCDRm File not found: system32\drivers\InCDRm.sys

+ lbrtfdc File not found: C:\WINDOWS\System32\Drivers\lbrtfdc.sys

+ PCIDump File not found: C:\WINDOWS\System32\Drivers\PCIDump.sys

+ PDCOMP File not found: C:\WINDOWS\System32\Drivers\PDCOMP.sys

+ PDFRAME File not found: C:\WINDOWS\System32\Drivers\PDFRAME.sys

+ PDRELI File not found: C:\WINDOWS\System32\Drivers\PDRELI.sys

+ PDRFRAME File not found: C:\WINDOWS\System32\Drivers\PDRFRAME.sys

+ WDICA File not found: C:\WINDOWS\System32\Drivers\WDICA.sys

+ ZSMC0305 File not found: System32\Drivers\usbVM305.sys

Провери дали имаш такъв ключ в регистъра на Windows и го изтрий:

Start => run => regedit

HKEY_Current_User\Software\Microsoft\Internet Explorer\Extensions\(7713E8D2-850A-101B-AFC0-4210102A8DA7)

За да си сигурен, че вече всичко е наред можеш да провериш все пак и с тези два безплатни инструмента:

RemoveIt Pro

http://www.incodesolutions.com/downloads/removeit_pro.exe

Kaspersky Virus Removal Tool 7.0.0.180

http://dnl-eu11.kaspersky-labs.com/devbuil....2008_13-30.exe

После можеш да ги деинсталираш и да си стартираш отново System Restore.

Поздрави!

Хммм би трябвало автоматично версия 9.13 на Autoruns да има отметка

Options => Hide Microsoft Entries, но както и да е.

В програмата не се вижда вече процес стартиращ със системата от рода на wups32.dll.

Можеш да махнеш отметките в Autoruns все пак на тези липсващи обекти:

Провери дали имаш такъв ключ в регистъра на Windows и го изтрий:

Start => run => regedit

HKEY_Current_User\Software\Microsoft\Internet Explorer\Extensions\(7713E8D2-850A-101B-AFC0-4210102A8DA7)

За да си сигурен, че вече всичко е наред можеш да провериш все пак и с тези два безплатни инструмента:

RemoveIt Pro

http://www.incodesolutions.com/downloads/removeit_pro.exe

Kaspersky Virus Removal Tool 7.0.0.180

http://dnl-eu11.kaspersky-labs.com/devbuil....2008_13-30.exe

После можеш да ги деинсталираш и да си стартираш отново System Restore.

Поздрави!

ХИЛЯДИ БЛАГОДАРНОСТИ Сканирах с RemoveIt Pro и ми даде,че системата ми е чиста!! Още веднъж благодаря много!! ;)

HELP HELP HELP

Незнам как, откъде и защо, но започна всеки път когато отворя някоя папка на компютъра, или страница в интернет експорера, ми се появава съобщение което ми казва че компютъра ми е заразен със гореспоменатото нещо

Абсолютно същата идиотска история и при мен. Изчетох доста по темата и пробвах да го изчистя но не става.

Пробвах с:

spybot s&d

adaware

rogueremover

Microsoft Malicious Software Removal Tool 1.35

smitfraudfix

hijackthis

AVZ

не става и не става

дайте съвет pls

HELP HELP HELP

Абсолютно същата идиотска история и при мен. Изчетох доста по темата и пробвах да го изчистя но не става.

Пробвах с:

spybot s&d

adaware

rogueremover

Microsoft Malicious Software Removal Tool 1.35

smitfraudfix

hijackthis

AVZ

не става и не става

дайте съвет pls

Дай лог файла от HiJack This.

ето го

-----------------------------

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 5:37:02 PM, on 3/28/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

C:\Program Files\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

C:\WINDOWS\System32\svchost.exe

C:\PROGRA~1\MICROS~3\rapimgr.exe

C:\Program Files\Microsoft ActiveSync\wcescomm.exe

C:\WINDOWS\system32\taskmgr.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.bg/

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: Media Player Codec - {3084A75F-5350-4D8B-BC5F-6B378035C133} - C:\WINDOWS\dsaip32b.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll

O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll

O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1206640222859

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{B2C43DB5-69B6-46F9-B8BE-C79EFE8464CB}: NameServer = 192.168.0.1

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\WINDOWS\system32\drivers\pclepci.sys

--

End of file - 4167 bytes

Маркирай следния обект и избери Fix Cheched:

O2 - BHO: Media Player Codec - {3084A75F-5350-4D8B-BC5F-6B378035C133} - C:\WINDOWS\dsaip32b.dll

Сканирай с инструментите от този пост (особено VundoFix, Combofix, MalwareBytes Anti-malware, RemoveIt Pro)...После можеш да ги деинсталираш!

http://www.kaldata.com/forums/index.php?s=...st&p=739080

След като поразчистиш преименуваш програмата HijackThis на Analyse.exe и създай нов лог файл като копираш съдържанието му в следващия си пост.

Поздрави!

Работата с програми за които не знаеш нищо, не е препоръчителна. Като имаш проблем който ти се опъва, вместо да губиш нерви и време, просто преинсталирай. Ако имаш важна имформация, особено фирмена викни специалист. Вече ако ти се занимава за спорта да ровичкаш с инструменти които не знаеш за да се научиш е друг въпрос.

Работата с програми за които не знаеш нищо, не е препоръчителна. Като имаш проблем който ти се опъва, вместо да губиш нерви и време, просто преинсталирай. Ако имаш важна имформация, особено фирмена викни специалист. Вече ако ти се занимава за спорта да ровичкаш с инструменти които не знаеш за да се научиш е друг въпрос.

Не споделям това становище - откъде си сигурен, че ще справи с преинсталирането? То не е чак толкова просто, колкото изглежда, особено за несвикнал човек. И ако смята, че няма да успее да се справи, то ще трябва да вика приятел на помощ (не се знае и той колко ще е вещ) или пък да носи компютъра в сервиз, където обикновено има 2 злини - чакане и плащане, като обикновено и двете са в сериозни размери.

Изходът - въпрос във форум, в който могат да ти помогнат или поне няма да ти навредят.

Конкретната тема е пусната отдавна, а в няколко поста има конкретни и изпитани методи за решаване на проблема.

Редактирано от hlevoust (преглед на промените)

Маркирай следния обект и избери Fix Cheched:

Сканирай с инструментите от този пост (особено VundoFix, Combofix, MalwareBytes Anti-malware, RemoveIt Pro)...После можеш да ги деинсталираш!

http://www.kaldata.com/forums/index.php?s=...st&p=739080

След като поразчистиш преименуваш програмата HijackThis на Analyse.exe и създай нов лог файл като копираш съдържанието му в следващия си пост.

Поздрави!

Направих всичко както каза

ето го лога

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 8:30:50 PM, on 3/28/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\ctfmon.exe

C:\PROGRA~1\MICROS~3\rapimgr.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Trend Micro\HijackThis\Analyse.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.bg/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll

O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll

O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1206640222859

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{B2C43DB5-69B6-46F9-B8BE-C79EFE8464CB}: NameServer = 192.168.0.1

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\WINDOWS\system32\drivers\pclepci.sys

--

End of file - 4121 bytes

-----------------------------------------------------------

как да разбера дали е чист

като спре да излиза изскачащия прозорец ли

Ами не само - трябва да не съдържа елементи като (nasty, unnessecery, missing и т.н.)

Може да се праща за анализ на http://www.hijackthis.de

Има много добри ръководства за работа с тази програма, но не я препоръчват за начинаещи.

Ами според мен лог-а е чист.

Имаш ли още проблеми?

Изтегли програмката AutoRuns:

http://www.www.kaldata.com/comments.php?catid=1&id=30190

1.Избери Options => Verify Code Signatures, Hide Signed Microsoft Entries

2.Избери бутона F5 или File => Refresh

3.Сега направи File => Save as

Копирай съдържанието на лог-а в следващия си пост!

Редактирано от B-boy[StyLe] (преглед на промените)

изскачащия прозорец спря да излиза

кой не трябва да съдържа тези елементи (nasty, unnessecery, missing )

ето го лога на autoruns

--------------------------------------------------

HKCU\Software\Microsoft\Windows\CurrentVersion\Run

+ H/PC Connection Agent ActiveSync Connection Manager (Not verified) Microsoft Corporation c:\program files\microsoft activesync\wcescomm.exe

HKLM\SOFTWARE\Classes\Protocols\Handler

+ cdo Microsoft SharePoint Portal Server Object Model (Not verified) Microsoft Corporation c:\program files\common files\microsoft shared\web folders\pkmcdo.dll

+ skype4com Skype for COM API (Verified) Skype Technologies SA c:\program files\common files\skype\skype4com.dll

HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers

+ avast avast! Shell Extension (Verified) ALWIL Software c:\program files\alwil software\avast4\ashshell.dll

+ WinRAR c:\program files\winrar\rarext.dll

HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers

+ avast avast! Shell Extension (Verified) ALWIL Software c:\program files\alwil software\avast4\ashshell.dll

+ WinRAR c:\program files\winrar\rarext.dll

HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers

+ WinRAR c:\program files\winrar\rarext.dll

HKLM\Software\Classes\Folder\Shellex\ColumnHandlers

+ PDF Shell Extension PDF Shell Extension (Not verified) Adobe Systems, Inc. c:\program files\adobe\acrobat 7.0\activex\pdfshell.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ avast avast! Shell Extension (Verified) ALWIL Software c:\program files\alwil software\avast4\ashshell.dll

+ blue.shell c:\program files\pinnacle\studio 11\programs\blueshellext.dll

+ Display Panning CPL Extension File not found: deskpan.dll

+ Microsoft Access Custom Icon Handler MSAPP Export Support for Microsoft Access (Not verified) Microsoft Corporation c:\program files\msaccrt\access 97\soa800.dll

+ Mobile Device Mobile Devices Shell Extension (Not verified) Microsoft Corporation c:\program files\microsoft activesync\wcesview.dll

+ Web Folders Microsoft Web Folders (Not verified) Microsoft Corporation c:\program files\common files\microsoft shared\web folders\msonsext.dll

+ WinRAR shell extension c:\program files\winrar\rarext.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

+ AcroIEHlprObj Class Adobe Acrobat IE Helper Version 7.0 for ActiveX (Verified) Adobe Systems, Incorporated c:\program files\adobe\acrobat 7.0\activex\acroiehelper.dll

+ Spybot-S&D IE Protection SBSD IE Protection (Verified) Safer Networking Ltd. c:\program files\spybot - search & destroy\sdhelper.dll

+ SSVHelper Class Java Platform SE binary (Verified) Sun Microsystems, Inc. c:\program files\java\jre1.6.0_03\bin\ssv.dll

HKLM\System\CurrentControlSet\Services

+ aawservice Protects your computer from spyware (Verified) Lavasoft AB c:\program files\lavasoft\ad-aware 2007\aawservice.exe

+ aswUpdSv Provides automatic updating for the avast! antivirus. (Verified) ALWIL Software c:\program files\alwil software\avast4\aswupdsv.exe

+ avast! Antivirus Manages and implements avast! antivirus services for this computer. This includes the resident protection, the virus chest and the scheduler. (Verified) ALWIL Software c:\program files\alwil software\avast4\ashserv.exe

+ PCLEPCI PCLEPCI (Not verified) Pinnacle Systems GmbH c:\windows\system32\drivers\pclepci.sys

HKLM\System\CurrentControlSet\Services

+ Aavmker4 avast! Base Kernel-Mode Device Driver for Windows NT/2000/XP (Verified) ALWIL Software c:\windows\system32\drivers\aavmker4.sys

+ AgereSoftModem SoftModem Device Driver (Not verified) Agere Systems c:\windows\system32\drivers\agrsm.sys

+ ASAPIW2k ASAPI (Not verified) Pinnacle Systems GmbH c:\windows\system32\drivers\asapiw2k.sys

+ aswMon2 avast! File System Filter Driver for Windows XP (Verified) ALWIL Software c:\windows\system32\drivers\aswmon2.sys

+ aswRdr avast! TDI RDR Driver (Verified) ALWIL Software c:\windows\system32\drivers\aswrdr.sys

+ aswTdi avast! TDI Filter Driver (Verified) ALWIL Software c:\windows\system32\drivers\aswtdi.sys

+ cg300 CG300 Video Capture WDM Driver (Not verified) Daheng Imavision Inc. c:\windows\system32\drivers\cg300vc.sys

+ cg300Au CG300 Video Capture WDM Driver (Not verified) Daheng Imavision Inc. c:\windows\system32\drivers\cg300au.sys

+ Changer File not found: C:\WINDOWS\System32\Drivers\Changer.sys

+ i2omgmt File not found: C:\WINDOWS\System32\Drivers\i2omgmt.sys

+ imagedrv NERO IMAGEDRIVE SCSI miniport (Not verified) Ahead Software AG c:\windows\system32\drivers\imagedrv.sys

+ imagesrv Nero Image Server (Not verified) Ahead Software AG c:\windows\system32\drivers\imagesrv.sys

+ lbrtfdc File not found: C:\WINDOWS\System32\Drivers\lbrtfdc.sys

+ MarvinBus Pinnacle Marvin Discrete Bus Enumerator (Not verified) Pinnacle Systems GmbH c:\windows\system32\drivers\marvinbus.sys

+ PCIDump File not found: C:\WINDOWS\System32\Drivers\PCIDump.sys

+ PDCOMP File not found: C:\WINDOWS\System32\Drivers\PDCOMP.sys

+ PDFRAME File not found: C:\WINDOWS\System32\Drivers\PDFRAME.sys

+ PDRELI File not found: C:\WINDOWS\System32\Drivers\PDRELI.sys

+ PDRFRAME File not found: C:\WINDOWS\System32\Drivers\PDRFRAME.sys

+ sw848b c:\windows\system32\drivers\sw848b.sys

+ sw878b c:\windows\system32\drivers\sw878b.sys

+ WDICA File not found: C:\WINDOWS\System32\Drivers\WDICA.sys

HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute

+ lsdelete (Verified) Lavasoft AB c:\windows\system32\lsdelete.exe

изскачащия прозорец спря да излиза

кой не трябва да съдържа тези елементи (nasty, unnessecery, missing )

Лога на HijackThis не трябва да съдържа такива елементи при анализа си например в http://www.HijackThis.de.

Както казах има още много ръководства за работа с програмата, едно от Night_Raven дори и на български!

Има и доста програми които помагат при разчитането на лог файловете.

За AutoRuns - можеш да махнеш следните отметки:

+ Display Panning CPL Extension File not found: deskpan.dll

+ Changer File not found: C:\WINDOWS\System32\Drivers\Changer.sys

+ i2omgmt File not found: C:\WINDOWS\System32\Drivers\i2omgmt.sys

+ lbrtfdc File not found: C:\WINDOWS\System32\Drivers\lbrtfdc.sys

+ PCIDump File not found: C:\WINDOWS\System32\Drivers\PCIDump.sys

+ PDCOMP File not found: C:\WINDOWS\System32\Drivers\PDCOMP.sys

+ PDFRAME File not found: C:\WINDOWS\System32\Drivers\PDFRAME.sys

+ PDRELI File not found: C:\WINDOWS\System32\Drivers\PDRELI.sys

+ PDRFRAME File not found: C:\WINDOWS\System32\Drivers\PDRFRAME.sys

+ WDICA File not found: C:\WINDOWS\System32\Drivers\WDICA.sys

Ако решиш да деинсталираш Ad-aware някой ден не забравяй да махнеш отметката и от:

+ lsdelete c:\windows\system32\lsdelete.exe

;)

Редактирано от B-boy[StyLe] (преглед на промените)

B-boy[styLe] Благодаря ти за отделеното време

мисля че засега успях да го разчистя без format:c

Привет на всички. Надявам се да ми помогнете. Имам някакъв вирус, който обаче антивирусната при сканиране не засича. Ползвам Symantec i Spy Doctor, но те не откриват проблем. Обаче в един момент както си цъкам на компа ми излизат двете снимки по долу.

Не мога да намеря това exe и не знам как дасе справя с вируса.

Edit заглавие.

post-123489-1206987946_thumb.jpg

post-123489-1206988025_thumb.jpg

Редактирано от dragozow (преглед на промените)

1.Спри System Restore

(десен бутон на My Computer => Properties => System Restore => сложи отметка пред Turn off System Restore...)

2.Изтегли програмата ATF-CLEANER (избери Select All => Empty Selected)

http://www.atribune.org/ccount/click.php?id=1

3.Изтегли тази програма и я запази на десктопа.

Стартирай я и изчакай да си свърши работата:

http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe

Накрая Combofix ще създаде лог файл.Копирай съдържанието му в следващия си пост!

4.Можеш да дадеш и един лог файл от AutoRuns и HijackThis

http://www.kaldata.com/comments.php?id=301...hlight=autoruns

1. Избери Options -> Hide Microsoft Entries и Verify Code Signatures.

2. Избери File -> Refresh или натисни F5.

3. Избери File -> Save as.

5.Изтегли програмата HijackThis

http://www.merijn.org/files/HiJackThis_v2.exe

=> преименувай я на hjt.exe

Стартирай я и избери Do a scan and save a log file

Копирай съдържанието му в следващия си пост

Редактирано от B-boy[StyLe] (преглед на промените)

ComboFix 08-03-30.4 - Evo 2008-03-31 22:06:58.1 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1251.1.1033.18.430 [GMT 3:00]

Running from: C:\Documents and Settings\Evo\Desktop\ComboFix.exe

* Resident AV is active

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

.

((((((((((((((((((((((((( Files Created from 2008-02-28 to 2008-03-31 )))))))))))))))))))))))))))))))

.

2008-03-31 01:14 . 2008-03-31 01:42 31,585 --a------ C:\MGlogs.zip

2008-03-31 01:13 . 2008-03-31 01:13 1,239,277 --a------ C:\MGtools.exe

2008-03-31 01:09 . 2005-01-14 06:41 11,254 --a------ C:\WINDOWS\system32\locate.com

2008-03-31 01:08 . 2008-03-31 01:42 <DIR> d-------- C:\MGTools

2008-03-31 00:35 . 2008-03-31 00:35 <DIR> d-------- C:\Program Files\PrevxCSI

2008-03-31 00:35 . 2008-03-31 21:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PrevxCSI

2008-03-31 00:35 . 2008-03-31 21:09 10,880 --a------ C:\WINDOWS\system32\drivers\pxark.sys

2008-03-30 17:40 . 2008-03-30 17:40 <DIR> d-------- C:\Program Files\InCode Solutions

2008-03-27 22:51 . 2008-03-28 00:48 <DIR> d-------- C:\The Return Of The Fabulous Hofner Blue Notes

2008-03-26 23:20 . 2008-03-26 23:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\GRETECH

2008-03-26 23:19 . 2008-03-26 23:19 <DIR> d-------- C:\Program Files\GRETECH

2008-03-26 23:19 . 2008-03-26 23:19 <DIR> d-------- C:\Documents and Settings\Evo\Application Data\GRETECH

2008-03-26 17:23 . 2008-03-26 17:31 <DIR> d-------- C:\Program Files\PC-Cleaner

2008-03-26 17:23 . 2008-03-26 17:26 <DIR> d-------- C:\Documents and Settings\Evo\Application Data\PC-Cleaner

2008-03-26 15:41 . 2008-03-26 15:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\lsfafgba

2008-03-26 15:41 . 2008-03-26 15:41 114,688 --a------ C:\WINDOWS\system32\lcpohwhy.exe

2008-03-25 23:20 . 2008-03-25 23:36 <DIR> d-------- C:\Jumper.R5.LiNE.XViD-mVs

2008-03-25 22:22 . 2008-03-25 22:22 <DIR> d-------- C:\Program Files\Common Files\DirectX

2008-03-25 22:20 . 2008-03-25 22:21 <DIR> d-------- C:\Program Files\Table Tennis Pro

2008-03-25 22:17 . 2008-03-28 18:57 <DIR> d-------- C:\Table.Tennis.Pro.v1.93-DELiGHT

2008-03-25 20:40 . 2008-03-25 21:13 43,520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll

2008-03-25 20:34 . 2008-03-25 20:34 <DIR> d-------- C:\Program Files\KONAMI

2008-03-25 20:28 . 2008-03-25 20:46 <DIR> d-------- C:\Program Files\DAEMON Tools

2008-03-25 20:25 . 2008-03-25 20:25 685,816 --a------ C:\WINDOWS\system32\drivers\sptd.sys

2008-03-24 02:25 . 2008-03-24 02:25 <DIR> d-------- C:\Program Files\myTouch

2008-03-23 21:35 . 2008-03-24 23:33 <DIR> d-------- C:\Federer - Cincy 2007

2008-03-17 00:35 . 2008-03-17 00:35 <DIR> d-------- C:\Program Files\TVUPlayer

2008-03-17 00:19 . 2008-03-17 00:19 <DIR> d-------- C:\ppmaterecord

2008-03-17 00:18 . 2008-03-17 00:18 <DIR> d-------- C:\Program Files\Common Files\Synacast

2008-03-17 00:18 . 2008-03-17 00:18 <DIR> d-------- C:\Documents and Settings\Evo\Application Data\PPMate

2008-03-16 23:43 . 2008-03-16 23:55 <DIR> d-------- C:\Program Files\SopCast

2008-03-16 21:12 . 2008-03-16 21:12 <DIR> d-------- C:\Documents and Settings\Evo\Application Data\K-Meleon

2008-03-16 21:10 . 2008-03-26 19:07 <DIR> d-------- C:\Program Files\K-Meleon

2008-03-16 02:02 . 2008-03-16 02:02 <DIR> d-------- C:\Program Files\Audacity

2008-03-15 23:37 . 2008-03-16 02:08 <DIR> d-------- C:\Program Files\VideoLAN

2008-03-09 16:54 . 2008-03-09 02:15 86,528 --a------ C:\WINDOWS\system32\VACFix.exe

2008-03-09 16:54 . 2008-03-05 23:29 82,432 --a------ C:\WINDOWS\system32\IEDFix.exe

2008-03-09 16:54 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe

2008-03-09 16:54 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe

2008-03-09 16:54 . 2008-03-30 17:44 802 --a------ C:\WINDOWS\system32\tmp.reg

2008-03-09 01:30 . 2008-03-09 01:30 <DIR> d-------- C:\Documents and Settings\Evo\DoctorWeb

2008-03-09 00:42 . 2008-03-09 01:04 <DIR> d-------- C:\Program Files\Spyware Doctor

2008-03-08 20:23 . 2008-03-08 20:23 0 --a------ C:\WINDOWS\vpc32.INI

2008-03-08 19:48 . 2008-03-08 19:48 <DIR> d-------- C:\Program Files\Symantec

2008-03-08 19:48 . 2005-05-13 20:50 123,488 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS

2008-03-08 19:48 . 2005-05-13 20:50 91,856 --a------ C:\WINDOWS\system32\S32EVNT1.DLL

2008-03-08 19:47 . 2008-03-31 20:10 <DIR> d-------- C:\Program Files\Symantec AntiVirus

2008-03-08 19:47 . 2008-03-08 19:53 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared

2008-03-08 19:47 . 2008-03-08 19:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Symantec

2008-03-06 00:24 . 2008-03-09 00:09 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP

2008-03-06 00:12 . 2008-03-06 00:12 <DIR> d-------- C:\Program Files\Common Files\Download Manager

2008-02-13 02:12 . 2008-03-15 23:30 <DIR> d-------- C:\Documents and Settings\Evo\Application Data\Thinstall

2008-02-13 00:18 . 2008-02-13 00:18 <DIR> d--h----- C:\WINDOWS\PIF

2008-02-10 20:55 . 2008-02-10 20:55 <DIR> d-------- C:\Program Files\BACL

2008-02-08 23:54 . 2008-02-09 03:09 <DIR> d-------- C:\Program Files\Opera

2008-02-07 12:30 . 2008-02-07 12:30 <DIR> d-------- C:\Documents and Settings\Evo\Application Data\Cool Record Edit Pro

2008-02-07 12:20 . 2008-02-07 12:21 <DIR> d-------- C:\Program Files\Free Sound Recorder

2008-02-05 19:11 . 2008-02-05 19:11 <DIR> d-------- C:\Downloads

2008-02-05 19:11 . 2008-02-05 20:11 <DIR> d-------- C:\Documents and Settings\Evo\Application Data\Download Master

2008-02-05 19:10 . 2008-02-05 19:10 <DIR> d-------- C:\Program Files\Download Master

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-03-31 18:54 --------- d-----w C:\Documents and Settings\Evo\Application Data\uTorrent

2008-03-31 17:51 --------- d-----w C:\Program Files\Foobar2000

2008-03-31 17:23 --------- d-----w C:\Program Files\StrongDC++

2008-03-31 16:36 --------- d-----w C:\Documents and Settings\Evo\Application Data\Skype

2008-03-25 18:59 --------- d--h--w C:\Program Files\InstallShield Installation Information

2008-03-25 17:33 --------- d-----w C:\Program Files\Common Files\InstallShield

2008-03-24 20:58 --------- d-----w C:\Documents and Settings\Evo\Application Data\OpenOffice.org2

2008-03-05 14:26 --------- d-----w C:\Program Files\ESET

2008-03-03 10:34 --------- d-----w C:\Program Files\KMplayer

2008-02-20 22:01 --------- d-----w C:\Program Files\MPlayer

2008-02-05 16:04 --------- d-----w C:\Documents and Settings\Evo\Application Data\DMCache

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]

"jeigzjze"="C:\WINDOWS\system32\lcpohwhy.exe" [2008-03-26 15:41 114688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-06-02 10:21 48752]

"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2005-06-23 20:27 85696]

"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2002-07-05 16:57 126976]

"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2002-07-05 16:55 557056]

"hffsrv"="c:\windows\hffext\hffsrv.exe" [2006-01-25 22:11 82432]

"PrevxCSI"=" /bootupreg" []

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 01:56 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"DisableTaskMgr0"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]

"TwbMFsg28N"= C:\Documents and Settings\All Users\Application Data\lsfafgba\pedkvalk.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]

"apdqnxp"= {FEA6A07A-D314-45D6-9261-10FA998E4771} - C:\WINDOWS\apdqnxp.dll [ ]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\FDCENT.SYS]

@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HideFilesAndFolders_S]

@=""

[HKLM\~\startupfolder\C:^Documents and Settings^Evo^Start Menu^Programs^Startup^Configure Bulgarian Speech.lnk]

path=C:\Documents and Settings\Evo\Start Menu\Programs\Startup\Configure Bulgarian Speech.lnk

backup=C:\WINDOWS\pss\Configure Bulgarian Speech.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]

--a------ 2004-05-15 21:00 335872 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eabconfg.cpl]

--a------ 2002-11-12 11:39 229376 C:\Program Files\Compaq\EAB\EABSERVR.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hffsrv]

--a------ 2006-01-25 22:11 82432 c:\windows\hffext\hffsrv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISTray]

C:\Program Files\Spyware Doctor\pctsTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]

--a------ 2006-09-29 21:58 49152 C:\Program Files\CyberLink\PowerDVD\Language\Language.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

--a------ 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nod32kui]

--a------ 2007-08-18 20:25 949376 C:\Program Files\Eset\nod32kui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]

--------- 2006-09-18 11:08 29696 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\spywareisolator]

C:\Program Files\SpywareIsolator\spywareisolator.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

--a------ 2007-09-25 02:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"sdCoreService"=2 (0x2)

"sdAuxService"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"D:\\c.s\\hl.exe"=

"D:\\AOE\\My Documents\\Downloads\\Programs\\utorrent.exe"=

"C:\\Program Files\\ICQ6\\ICQ.exe"=

"C:\\Program Files\\uTorrent\\uTorrent.exe"=

"C:\\Program Files\\StrongDC++\\StrongDC.exe"=

"C:\\WINDOWS\\system32\\dpvsetup.exe"=

"C:\\WINDOWS\\system32\\sessmgr.exe"=

"C:\\WINDOWS\\system32\\rundll32.exe"=

"C:\\Program Files\\SopCast\\adv\\SopAdver.exe"=

"C:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 pxark;pxark;C:\WINDOWS\system32\drivers\pxark.sys [2008-03-31 21:09]

R2 CSIScanner;CSIScanner;"C:\Program Files\PrevxCSI\\PrevxCSI.exe" /service []

.

**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-03-31 22:08:54

Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

Completion time: 2008-03-31 22:09:39

ComboFix-quarantined-files.txt 2008-03-31 19:09:28

Pre-Run: 3,799,019,520 bytes free

Post-Run: 3,786,743,808 bytes free

.

2007-11-15 01:14:10 --- E O F ---

Logfile of Trend Micro HijackThis v2.0.0 (BETA)

Scan saved at 22:21:13, on 31.3.2008 г.

Platform: Windows XP SP2 (WinNT 5.01.2600)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\PrevxCSI\PrevxCSI.exe

C:\Program Files\Symantec AntiVirus\DefWatch.exe

C:\Program Files\Eset\nod32krn.exe

C:\Program Files\CyberLink\Shared Files\RichVideo.exe

C:\Program Files\Symantec AntiVirus\Rtvscan.exe

C:\WINDOWS\system32\wscntfy.exe

C:\Documents and Settings\All Users\Application Data\lsfafgba\pedkvalk.exe

C:\Program Files\Common Files\Symantec Shared\ccApp.exe

C:\PROGRA~1\SYMANT~1\VPTray.exe

C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\windows\hffext\hffsrv.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\system32\lcpohwhy.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\explorer.exe

C:\Program Files\Opera\Opera.exe

C:\Program Files\K-Meleon\k-meleon.exe

D:\AOE\My Documents\hjt.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O2 - BHO: IE 4.x-6.x BHO for Download Master - {9961627E-4059-41B4-8E0E-A7D6B3854ADF} - C:\PROGRA~1\DOWNLO~1\dmiehlp.dll

O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll

O3 - Toolbar: DM Bar - {0E1230F8-EA50-42A9-983C-D22ABC2EED3C} - C:\Program Files\Download Master\dmbar.dll

O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe

O4 - HKLM\..\Run: [synTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [hffsrv] c:\windows\hffext\hffsrv.exe

O4 - HKLM\..\Run: [PrevxCSI] "" /bootupreg

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [jeigzjze] C:\WINDOWS\system32\lcpohwhy.exe

O4 - HKLM\..\Policies\Explorer\Run: [TwbMFsg28N] C:\Documents and Settings\All Users\Application Data\lsfafgba\pedkvalk.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: Закачать ВСЕ при помощи Download Master - C:\Program Files\Download Master\dmieall.htm

O8 - Extra context menu item: Закачать при помощи Download Master - C:\Program Files\Download Master\dmie.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll

O9 - Extra button: Download Master - {8DAE90AD-4583-4977-9DD4-4360F7A45C74} - C:\Program Files\Download Master\dmaster.exe

O9 - Extra 'Tools' menuitem: &Download Master - {8DAE90AD-4583-4977-9DD4-4360F7A45C74} - C:\Program Files\Download Master\dmaster.exe

O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe

O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O17 - HKLM\System\CCS\Services\Tcpip\..\{227D588D-DFAE-43C2-985F-5C00BBD5E5C0}: NameServer = 89.190.192.166 89.190.192.162

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O21 - SSODL: apdqnxp - {FEA6A07A-D314-45D6-9261-10FA998E4771} - C:\WINDOWS\apdqnxp.dll (file missing)

O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

O23 - Service: CSIScanner - Prevx - C:\Program Files\PrevxCSI\\PrevxCSI.exe

O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe

O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

--

End of file - 6636 bytes

Редактирано от ivaylo-85 (преглед на промените)

За Combofix после ще го разгледам по-обстойно...

Доста антивирусни си накачулил: деинсталирай Symentac или NOD32 (по-избор)

Деинсталирай и допълнителните инструменти за проверка като RemoveIt Pro и PrevX (и каквото още там си качил)

Сега маркирай следните неща с HijackThis и избери Fix Checked:

C:\Documents and Settings\All Users\Application Data\lsfafgba\pedkvalk.exe

C:\WINDOWS\system32\lcpohwhy.exe

O4 - HKLM\..\Run: [PrevxCSI] "" /bootupreg

O4 - HKCU\..\Run: [jeigzjze] C:\WINDOWS\system32\lcpohwhy.exe

O4 - HKLM\..\Policies\Explorer\Run: [TwbMFsg28N] C:\Documents and Settings\All Users\Application Data\lsfafgba\pedkvalk.exe

O21 - SSODL: apdqnxp - {FEA6A07A-D314-45D6-9261-10FA998E4771} - C:\WINDOWS\apdqnxp.dll (file missing)

Лог от Autoruns все още не е лоша идея, както и проверка с тези програми:

http://www.besttechie.net/tools/mbam-setup.exe

http://downloads2.superantispyware.com/dow...AntiSpyware.exe

Редактирано от B-boy[StyLe] (преглед на промените)

Благодарен съм на B-boy[styLe] за съветите (както и на всеки друг, който вземе отношение по темата) и му се извинявам че не му отговорих веднага.

Нека хвърли един поглед :hush: :

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ ccApp Symantec User Session (Verified) Symantec Corporation c:\program files\common files\symantec shared\ccapp.exe

+ hffsrv c:\windows\hffext\hffsrv.exe

+ vptray Symantec AntiVirus (Verified) Symantec Corporation c:\program files\symantec antivirus\vptray.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run

+ SUPERAntiSpyware SUPERAntiSpyware (Verified) SuperAdBlocker.com c:\program files\superantispyware\superantispyware.exe

HKLM\SOFTWARE\Classes\Protocols\Handler

+ skype4com Skype for COM API (Verified) Skype Technologies SA c:\program files\common files\skype\skype4com.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks

+ SABShellExecuteHook Class ShellExecuteHook (Not verified) SuperAdBlocker.com c:\program files\superantispyware\sasseh.dll

HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers

+ Hide Files and Folders c:\windows\hffext\hffext.dll

+ LDVPMenu Symantec AntiVirus (Verified) Symantec Corporation c:\program files\common files\symantec shared\ssc\vpshell2.dll

+ SASContextMenu Class SUPERAntiSpyware Context Menu Extension (Not verified) SUPERAntiSpyware.com c:\program files\superantispyware\sasctxmn.dll

+ WinRAR c:\program files\winrar\rarext.dll

HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers

+ MBAMShlExt Malwarebytes' Anti-Malware shell extension (Verified) Malwarebytes c:\program files\malwarebytes' anti-malware\mbamext.dll

+ pcsd File not found: C:\Program Files\PC-Cleaner\com\pcsd.dll

HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers

+ Hide Files and Folders c:\windows\hffext\hffext.dll

+ LDVPMenu Symantec AntiVirus (Verified) Symantec Corporation c:\program files\common files\symantec shared\ssc\vpshell2.dll

+ MBAMShlExt Malwarebytes' Anti-Malware shell extension (Verified) Malwarebytes c:\program files\malwarebytes' anti-malware\mbamext.dll

+ WinRAR c:\program files\winrar\rarext.dll

HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers

+ Hide Files and Folders c:\windows\hffext\hffext.dll

+ SASContextMenu Class SUPERAntiSpyware Context Menu Extension (Not verified) SUPERAntiSpyware.com c:\program files\superantispyware\sasctxmn.dll

+ WinRAR c:\program files\winrar\rarext.dll

HKLM\Software\Classes\Folder\Shellex\ColumnHandlers

+ {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} (Not verified) Sun Microsystems, Inc. c:\program files\openoffice.org 2.3\program\shlxthdl.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ Display Panning CPL Extension File not found: deskpan.dll

+ Hide Files and Folders Context Menu Handler c:\windows\hffext\hffext.dll

+ LDVP Shell Extensions Symantec AntiVirus (Verified) Symantec Corporation c:\program files\common files\symantec shared\ssc\vpshell2.dll

+ OpenOffice.org Column Handler (Not verified) Sun Microsystems, Inc. c:\program files\openoffice.org 2.3\program\shlxthdl.dll

+ OpenOffice.org Infotip Handler (Not verified) Sun Microsystems, Inc. c:\program files\openoffice.org 2.3\program\shlxthdl.dll

+ OpenOffice.org Property Sheet Handler (Not verified) Sun Microsystems, Inc. c:\program files\openoffice.org 2.3\program\shlxthdl.dll

+ OpenOffice.org Thumbnail Viewer (Not verified) Sun Microsystems, Inc. c:\program files\openoffice.org 2.3\program\shlxthdl.dll

+ pcsd File not found: C:\Program Files\PC-Cleaner\com\pcsd.dll

+ WinRAR shell extension c:\program files\winrar\rarext.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

+ IE 4.x-6.x BHO for Download Master (Not verified) WestByte c:\program files\download master\dmiehlp.dll

+ PCTools Browser Monitor iesdpb.dll (Not verified) GuideWorks Pty. Ltd. c:\program files\spyware doctor\tools\iesdpb.dll

+ PCTools Site Guard c:\program files\spyware doctor\tools\iesdsg.dll

+ SSVHelper Class Java Platform SE binary (Verified) Sun Microsystems, Inc. c:\program files\java\jre1.6.0_03\bin\ssv.dll

HKLM\Software\Microsoft\Internet Explorer\Toolbar

+ DM Bar DMBar (Not verified) WestByte Software c:\program files\download master\dmbar.dll

HKLM\Software\Microsoft\Internet Explorer\Extensions

+ &Download Master Download Master (Not verified) WestByte c:\program files\download master\dmaster.exe

+ ICQ6 ICQ Library (Verified) ICQ c:\program files\icq6\icq.exe

HKLM\System\CurrentControlSet\Services

+ ccEvtMgr Event propagation and logging service (Verified) Symantec Corporation c:\program files\common files\symantec shared\ccevtmgr.exe

+ ccSetMgr Settings storage and management service (Verified) Symantec Corporation c:\program files\common files\symantec shared\ccsetmgr.exe

+ DefWatch Monitors and maintains virus definitions. (Verified) Symantec Corporation c:\program files\symantec antivirus\defwatch.exe

+ RichVideo RichVideo Module c:\program files\cyberlink\shared files\richvideo.exe

+ Symantec AntiVirus Provides real-time virus scanning, reporting, and management functionality for Symantec AntiVirus. (Verified) Symantec Corporation c:\program files\symantec antivirus\rtvscan.exe

HKLM\System\CurrentControlSet\Services

+ a9cdhyvk File not found: C:\WINDOWS\System32\Drivers\a9cdhyvk.sys

+ Changer File not found: C:\WINDOWS\System32\Drivers\Changer.sys

+ EABFiltr EAB-II PS/2 Keyboard filter driver (Not verified) Compaq Computer Corp. c:\windows\system32\drivers\eabfiltr.sys

+ eabusb EAB-II USB Keyboard filter driver (Not verified) Compaq Computer Corp. c:\windows\system32\drivers\eabusb.sys

+ eeCtrl Symantec Eraser Control Driver (Verified) Symantec Corporation c:\program files\common files\symantec shared\eengine\eectrl.sys

+ EraserUtilDrv10741 Symantec Eraser Utility Driver (Verified) Symantec Corporation c:\program files\common files\symantec shared\eengine\eraserutildrv10741.sys

+ FDCENT c:\windows\system32\drivers\fdcent.sys

+ i2omgmt File not found: C:\WINDOWS\System32\Drivers\i2omgmt.sys

+ lbrtfdc File not found: C:\WINDOWS\System32\Drivers\lbrtfdc.sys

+ NAVENG AV Engine (Verified) Symantec Corporation c:\program files\common files\symantec shared\virusdefs\20080328.003\naveng.sys

+ NAVEX15 AV Engine (Verified) Symantec Corporation c:\program files\common files\symantec shared\virusdefs\20080328.003\navex15.sys

+ PCIDump File not found: C:\WINDOWS\System32\Drivers\PCIDump.sys

+ PDCOMP File not found: C:\WINDOWS\System32\Drivers\PDCOMP.sys

+ PDFRAME File not found: C:\WINDOWS\System32\Drivers\PDFRAME.sys

+ PDRELI File not found: C:\WINDOWS\System32\Drivers\PDRELI.sys

+ PDRFRAME File not found: C:\WINDOWS\System32\Drivers\PDRFRAME.sys

+ SASDIFSV SASDIFSV (Verified) SuperAdBlocker.com c:\program files\superantispyware\sasdifsv.sys

+ SASENUM SuperAntiSpyware (Not verified) SuperAdBlocker, Inc. c:\program files\superantispyware\sasenum.sys

+ SASKUTIL SASKUTIL.SYS (Verified) SuperAdBlocker.com c:\program files\superantispyware\saskutil.sys

+ SAVRT AutoProtect (Verified) Symantec Corporation c:\program files\symantec antivirus\savrt.sys

+ SAVRTPEL SAVRTPEL (Verified) Symantec Corporation c:\program files\symantec antivirus\savrtpel.sys

+ SPBBCDrv SPBBC Driver (Verified) Symantec Corporation c:\program files\common files\symantec shared\spbbc\spbbcdrv.sys

+ sptd c:\windows\system32\drivers\sptd.sys

+ SymEvent Symantec Event Library (Verified) Symantec Corporation c:\program files\symantec\symevent.sys

+ SYMREDRV Redirector Filter Driver (Verified) Symantec Corporation c:\windows\system32\drivers\symredrv.sys

+ SYMTDI Network Dispatch Driver (Verified) Symantec Corporation c:\windows\system32\drivers\symtdi.sys

+ WDICA File not found: C:\WINDOWS\System32\Drivers\WDICA.sys

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify

+ !SASWinLogon SUPERAntiSpyware WinLogon Processor (Not verified) SUPERAntiSpyware.com c:\program files\superantispyware\saswinlo.dll

+ NavLogon Symantec AntiVirus Logon Notification (Verified) Symantec Corporation c:\windows\system32\navlogon.dll

Като сканирам с SUPERAntispyware не открива нищо, а с Malwarebytes' Anti-Malware това :

post-123489-1207066655_thumb.png

Редактирано от tigertron (преглед на промените)

Аз сърдит? (нема такова нещо).

Премахни намереното с MalwareBytes' Anti-Malware (надявам се преди сканиране си я обновил и си направил пълно {FULL} сканиране на системата).

Надявам се, че си обновил и SUPERAntispyware преди проверката на системата.

В Autoruns изтрий следните неща (или им махни птметките)

+ pcsd File not found: C:\Program Files\PC-Cleaner\com\pcsd.dll

+ Display Panning CPL Extension File not found: deskpan.dll

+ pcsd File not found: C:\Program Files\PC-Cleaner\com\pcsd.dll

+ a9cdhyvk File not found: C:\WINDOWS\System32\Drivers\a9cdhyvk.sys

+ Changer File not found: C:\WINDOWS\System32\Drivers\Changer.sys

+ i2omgmt File not found: C:\WINDOWS\System32\Drivers\i2omgmt.sys

+ lbrtfdc File not found: C:\WINDOWS\System32\Drivers\lbrtfdc.sys

+ PCIDump File not found: C:\WINDOWS\System32\Drivers\PCIDump.sys

+ PDCOMP File not found: C:\WINDOWS\System32\Drivers\PDCOMP.sys

+ PDFRAME File not found: C:\WINDOWS\System32\Drivers\PDFRAME.sys

+ PDRELI File not found: C:\WINDOWS\System32\Drivers\PDRELI.sys

+ PDRFRAME File not found: C:\WINDOWS\System32\Drivers\PDRFRAME.sys

+ WDICA File not found: C:\WINDOWS\System32\Drivers\WDICA.sys

Започнах да тегля rapidshare неща, които да ми помогнат да тегля без ограничение. Ама то такова нещо нема и в момента съм пълен с вирус и ми трябва помощ как да ги махна. Ето това са следните сканирани с HiJack.

C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\bbnew.exe

C:\WINDOWS\system32\mgmrwmrv.exe

C:\Program Files\Bat\X_Bat.exe

O2 - BHO: (no name) - {00000250-0320-4dd4-be4f-7566d2314352} - (no file)

O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)

O2 - BHO: (no name) - {15651c7c-e812-44a2-a9ac-b467a2233e7d} - (no file)

O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file)

O2 - BHO: (no name) - {4e7bd74f-2b8d-469e-92c6-ce7eb590a94d} - (no file)

O2 - BHO: (no name) - {5929cd6e-2062-44a4-b2c5-2c7e78fbab38} - (no file)

O2 - BHO: (no name) - {5dafd089-24b1-4c5e-bd42-8ca72550717b} - (no file)

O2 - BHO: (no name) - {5fa6752a-c4a0-4222-88c2-928ae5ab4966} - (no file)

O2 - BHO: (no name) - {622cc208-b014-4fe0-801b-874a5e5e403a} - (no file)

O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)

O2 - BHO: (no name) - {965a592f-8efa-4250-8630-7960230792f1} - (no file)

O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)

O2 - BHO: (no name) - {fc3a74e5-f281-4f10-ae1e-733078684f3c} - (no file)

O2 - BHO: (no name) - {ffff0001-0002-101a-a3c9-08002b2f49fb} - (no file)

Редактирано от stanley56 (преглед на промените)

1.Дай цялостен лог файл от HijackThis...Ако си сигурен, че това са всичките обекти просто ги маркирай в програмата и избери бутончето Fix Checked!

2.Виж и този пост:

http://www.kaldata.com/forums/index.php?s=...st&p=877249

Значи започнах с Ad-aware, намери 4 вируса уж ги изтри. После проверих пак HiJack тези файлове си стоят, пробвах с копчето Fix Checked и при следващото сканиране те си стояха пак. След това почнах със Spyware Doctor намери ми учудващите 1896 вируса ohmy.gif , но пак не ги изтри.

Сега продължавам с тея 2 програми от първия пост. Инсталирах 2рата програма намери ми 5 вируса, но иска лиценз, а мога ли направо със Shift + Del да ги изтрия ?

Едит: 2 Постоянно ми изкача от Windows Security Centur, че е намерен вирус TrojanDownloader.XS как мога да го изтрия него ?

Редактирано от MaRCHiaNo (преглед на промените)

Гост
Тази тема е заключена за нови отговори.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.