syneok Публикувано Юни 17, 2011 Report Share Публикувано Юни 17, 2011 Widows-a е XP Pprofessional, версия 2002, SP3. Проблемът е, че пак не мога да инсталирам антивирусната програма. Когато отворя папката на анитивирусната, ми я затваря, а когато реша да я дръпна от нета ми затваря браузъра. Цитирай Link to comment Сподели другаде More sharing options...
Night_Raven Публикувано Юни 17, 2011 Report Share Публикувано Юни 17, 2011 Дал съм инструкции в първия ми отговор към теб. Изпълни ги. Цитирай Link to comment Сподели другаде More sharing options...
syneok Публикувано Юни 17, 2011 Report Share Публикувано Юни 17, 2011 Изкара ми само OTL файл. Ето го: OTL logfile created on: 6.17.2011 10:18:07 - Run 3OTL by OldTimer - Version 3.2.24.0 Folder = C:\Documents and Settings\YANEV\DesktopWindows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstationInternet Explorer (Version = 8.0.6001.18702)Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: M/d/yyyy 1,93 Gb Total Physical Memory | 1,40 Gb Available Physical Memory | 72,61% Memory free3,78 Gb Paging File | 3,25 Gb Available in Paging File | 85,92% Paging File freePaging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program FilesDrive C: | 19,53 Gb Total Space | 15,25 Gb Free Space | 78,09% Space Free | Partition Type: NTFSDrive D: | 146,48 Gb Total Space | 82,37 Gb Free Space | 56,23% Space Free | Partition Type: NTFSDrive E: | 132,07 Gb Total Space | 109,64 Gb Free Space | 83,02% Space Free | Partition Type: NTFS Computer Name: ET-BA44C4CE8262 | User Name: YANEV | Logged in as Administrator.Boot Mode: Normal | Scan Mode: All usersCompany Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Documents and Settings\YANEV\Desktop\OTL.exe (OldTimer Tools)PRC - C:\Program Files\Opera\opera.exe (Opera Software)PRC - C:\WINDOWS\system32\zicphzkfzhyseadr.exe ()PRC - C:\Documents and Settings\YANEV\Local Settings\Temp\RtkBtMnt.exe (Realtek Semiconductor Corp.)PRC - C:\Documents and Settings\YANEV\Local Settings\Temp\cajls.exe ()PRC - C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)PRC - C:\QUALCOMM\QDLService\QDLService.exe (QUALCOMM, Inc.)PRC - C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)PRC - C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe (Intel® Corporation)PRC - C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)PRC - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)PRC - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)PRC - C:\WINDOWS\PLFSetL.exe (sonix)PRC - C:\Program Files\Option\Acer 3G Connection Manager\GtDetectSc.exe (OptionNV)PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)PRC - C:\WINDOWS\system32\agrsmsvc.exe (Agere Systems)PRC - C:\Program Files\Datecs\FlexType 2K\FType2K.exe () ========== Modules (SafeList) ========== MOD - C:\Documents and Settings\YANEV\Desktop\OTL.exe (OldTimer Tools)MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll (Microsoft Corporation)MOD - C:\WINDOWS\system32\newdll.dll () ========== Win32 Services (SafeList) ========== SRV - (HidServ) -- File not foundSRV - (QDLService) -- C:\QUALCOMM\QDLService\QDLService.exe (QUALCOMM, Inc.)SRV - (EvtEng) -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)SRV - (S24EventMonitor) -- C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)SRV - (RegSrvc) -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)SRV - (GtDetectSc) -- C:\Program Files\Option\Acer 3G Connection Manager\GtDetectSc.exe (OptionNV)SRV - (AgereModemAudio) -- C:\WINDOWS\system32\agrsmsvc.exe (Agere Systems) ========== Driver Services (SafeList) ========== DRV - (AR5416) -- C:\WINDOWS\system32\drivers\athw.sys (Atheros Communications, Inc.)DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)DRV - (IntcHdmiAddService) Intel® -- C:\WINDOWS\system32\drivers\IntcHdmi.sys (Intel® Corporation)DRV - (SNP2UVC) USB2.0 PC Camera (SNP2UVC) -- C:\WINDOWS\system32\drivers\snp2uvc.sys ()DRV - (Ambfilt) -- C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)DRV - (s24trans) -- C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)DRV - (AgereSoftModem) -- C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)DRV - (Monfilt) -- C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)DRV - (PLCNDIS5) -- C:\Program Files\Acer Homeplug Ethernet Adapter Utilities 1.1\Configuration Utility\PLCNDIS5.SYS (Intellon, Inc.) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKU\S-1-5-21-1993962763-764733703-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 O1 HOSTS File: ([2008.04.14 04:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hostsO1 - Hosts: 127.0.0.1 localhostO4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe (Realtek Semiconductor Corp.)O4 - HKLM..\Run: [cajls] C:\WINDOWS\System32\amjzupdbyjdapoulpxb.exe ()O4 - HKLM..\Run: [intelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)O4 - HKLM..\Run: [intelZeroConfig] C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe (Intel® Corporation)O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)O4 - HKLM..\Run: [PLFSetL] C:\WINDOWS\PLFSetL.exe (sonix)O4 - HKLM..\Run: [uynvivbrgjv] C:\Documents and Settings\YANEV\Local Settings\Temp\zicphzkfzhyseadr.exe ()O4 - HKU\S-1-5-21-1993962763-764733703-1801674531-1003..\Run: [cajls] C:\Documents and Settings\YANEV\Local Settings\Temp\pawlfzmjfpiesqvlov.exe ()O4 - HKU\S-1-5-21-1993962763-764733703-1801674531-1003..\Run: [pqchrber] C:\WINDOWS\System32\nayplhwvtfayoovnsbga.exe ()O4 - HKLM..\RunOnce: [nmwzhp] C:\WINDOWS\System32\pawlfzmjfpiesqvlov.exe ()O4 - HKLM..\RunOnce: [zcqxjvapdf] C:\Documents and Settings\YANEV\Local Settings\Temp\nayplhwvtfayoovnsbga.exe ()O4 - HKU\S-1-5-21-1993962763-764733703-1801674531-1003..\RunOnce: [givbmxbpc] C:\WINDOWS\System32\pawlfzmjfpiesqvlov.exe ()O4 - HKU\S-1-5-21-1993962763-764733703-1801674531-1003..\RunOnce: [nmwzhp] C:\Documents and Settings\YANEV\Local Settings\Temp\zicphzkfzhyseadr.exe ()O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\FlexType 2K.lnk = C:\Program Files\Datecs\FlexType 2K\FType2K.exe ()O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 1O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: aalpyhj = nayplhwvtfayoovnsbga.exe ()O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: tqyz = C:\DOCUME~1\YANEV\LOCALS~1\Temp\amjzupdbyjdapoulpxb.exe ()O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 0O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 0O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 0O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 0O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145O7 - HKU\S-1-5-21-1993962763-764733703-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 1O7 - HKU\S-1-5-21-1993962763-764733703-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1O13 - gopher Prefix: missingO16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)O24 - Desktop Components:0 (Моята текуща начална страница) - About:HomeO24 - Desktop WallPaper: C:\Documents and Settings\YANEV\Local Settings\Application Data\Microsoft\Wallpaper1.bmpO24 - Desktop BackupWallPaper: C:\Documents and Settings\YANEV\Local Settings\Application Data\Microsoft\Wallpaper1.bmpO32 - HKLM CDRom: AutoRun - 1O32 - AutoRun File - [2011.06.15 20:04:24 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]O32 - AutoRun File - [2011.06.17 08:39:34 | 000,000,814 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]O32 - AutoRun File - [2011.06.17 08:39:34 | 000,000,810 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]O32 - AutoRun File - [2011.06.17 08:39:35 | 000,000,802 | RHS- | M] () - E:\autorun.inf -- [ NTFS ]O33 - MountPoints2\{9016fea1-97d1-11e0-bb89-fb8a64fba71b}\Shell\AutoRun\command - "" = G:\pqchrber.batO33 - MountPoints2\{9016fea1-97d1-11e0-bb89-fb8a64fba71b}\Shell\explore\Command - "" = G:\rwmvjxevlpcs.bat _O33 - MountPoints2\{9016fea1-97d1-11e0-bb89-fb8a64fba71b}\Shell\open\Command - "" = G:\zcqxjvapdf.bat _O33 - MountPoints2\{995e5d2a-9786-11e0-913a-806d6172696f}\Shell\AutoRun\command - "" = D:\pqchrber.bat -- [2009.04.10 18:06:38 | 000,917,504 | RHS- | M] ()O33 - MountPoints2\{995e5d2a-9786-11e0-913a-806d6172696f}\Shell\explore\Command - "" = D:\rwmvjxevlpcs.bat -- [2009.03.14 19:13:14 | 000,917,504 | RHS- | M] ()O33 - MountPoints2\{995e5d2a-9786-11e0-913a-806d6172696f}\Shell\open\Command - "" = D:\zcqxjvapdf.bat -- [2009.07.16 19:19:48 | 000,917,504 | RHS- | M] ()O33 - MountPoints2\{995e5d2b-9786-11e0-913a-806d6172696f}\Shell\AutoRun\command - "" = E:\pqchrber.bat -- [2009.03.20 01:10:06 | 000,917,504 | RHS- | M] ()O33 - MountPoints2\{995e5d2b-9786-11e0-913a-806d6172696f}\Shell\explore\Command - "" = E:\rwmvjxevlpcs.bat -- [2011.06.17 08:39:35 | 000,917,504 | RHS- | M] ()O33 - MountPoints2\{995e5d2b-9786-11e0-913a-806d6172696f}\Shell\open\Command - "" = E:\zcqxjvapdf.bat -- [2009.05.07 19:47:49 | 000,917,504 | RHS- | M] ()O33 - MountPoints2\{995e5d2d-9786-11e0-913a-806d6172696f}\Shell\AutoRun\command - "" = C:\pqchrber.bat -- [2009.06.06 20:04:11 | 000,917,504 | RHS- | M] ()O33 - MountPoints2\{995e5d2d-9786-11e0-913a-806d6172696f}\Shell\explore\Command - "" = C:\rwmvjxevlpcs.bat -- [2011.06.17 08:39:34 | 000,917,504 | RHS- | M] ()O33 - MountPoints2\{995e5d2d-9786-11e0-913a-806d6172696f}\Shell\open\Command - "" = C:\zcqxjvapdf.bat -- [2009.05.17 18:18:41 | 000,917,504 | RHS- | M] ()O34 - HKLM BootExecute: (autocheck autochk *) - File not foundO35 - HKLM\..comfile [open] -- "%1" %*O35 - HKLM\..exefile [open] -- "%1" %*O37 - HKLM\...com [@ = comfile] -- "%1" %*O37 - HKLM\...exe [@ = exefile] -- "%1" %* NetSvcs: 6to4 - File not foundNetSvcs: HidServ - File not foundNetSvcs: Ias - File not foundNetSvcs: Iprip - File not foundNetSvcs: Irmon - File not foundNetSvcs: NWCWorkstation - File not foundNetSvcs: Nwsapagent - File not foundNetSvcs: WmdmPmSp - File not found ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML)ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShowActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimationActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dllActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for JavaActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing PackActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - UniscribeActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced AuthoringActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /installActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NTActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShowActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawExActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer HelpActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java ClassesActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.8ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUserActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICWActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup ToolsActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing EnhancementsActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media PlayerActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site AccessActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /installActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dllActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettingsActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data BindingActiveX: {ACC563BC-4266-43f0-B6ED-9D38C4202C7E} - ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core FontsActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task SchedulerActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Macromedia Shockwave FlashActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML HelpActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service InterfaceActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exeActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMPActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfigActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - RunDLL32 IEDKCS32.DLL,BrandIEActiveSetup SIGNUPActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOEActiveX: >{99820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dllActiveX: Microsoft Base Smart Card Crypto Provider Package - Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation) ========== Files/Folders - Created Within 30 Days ========== [2011.06.16 16:11:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\YANEV\Application Data\skypePM[2011.06.16 14:09:39 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\YANEV\Desktop\OTL.exe[2011.06.16 13:59:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\YANEV\Application Data\Macromedia[2011.06.16 13:59:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\YANEV\Application Data\Adobe[2011.06.16 13:59:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun[2011.06.16 13:59:15 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java[2011.06.16 13:58:57 | 000,000,000 | ---D | C] -- C:\Program Files\Java[2011.06.16 13:58:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\YANEV\Application Data\Sun[2011.06.16 13:57:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Datecs Applications[2011.06.16 13:57:09 | 000,000,000 | ---D | C] -- C:\Program Files\Datecs[2011.06.16 13:53:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\YANEV\Application Data\Skype[2011.06.16 13:53:26 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype[2011.06.16 13:53:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Skype[2011.06.16 13:53:24 | 000,000,000 | R--D | C] -- C:\Program Files\Skype[2011.06.16 13:53:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Skype[2011.06.16 13:36:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\YANEV\Local Settings\Application Data\Opera[2011.06.16 13:36:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\YANEV\Application Data\Opera[2011.06.16 13:36:46 | 000,000,000 | ---D | C] -- C:\Program Files\Opera[2011.06.16 13:13:23 | 001,529,600 | ---- | C] (Atheros Communications, Inc.) -- C:\WINDOWS\System32\drivers\athw.sys[2011.06.16 13:13:23 | 001,529,600 | ---- | C] (Atheros Communications, Inc.) -- C:\WINDOWS\System32\athw.sys[2011.06.16 13:13:23 | 000,058,208 | ---- | C] (Atheros Communications, Inc.) -- C:\WINDOWS\System32\wsimd.sys[2011.06.16 11:25:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Broadcom[2011.06.16 11:03:32 | 000,000,000 | ---D | C] -- C:\Program Files\SereneScreen[2011.06.16 11:03:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\SereneScreen[2011.06.16 10:39:53 | 000,000,000 | ---D | C] -- C:\Program Files\Broadcom[2011.06.16 10:37:39 | 000,952,832 | ---- | C] (Atheros Communications, Inc.) -- C:\WINDOWS\System32\athr.sys[2011.06.16 10:37:39 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\zh-TW[2011.06.16 10:37:39 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\zh-CN[2011.06.16 10:37:39 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\tr-TR[2011.06.16 10:37:39 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\sv-SE[2011.06.16 10:37:39 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ru-RU[2011.06.16 10:37:39 | 000,000,000 | ---D | C] -- C:\Program Files\Atheros[2011.06.16 10:37:38 | 000,393,216 | ---- | C] (Atheros) -- C:\WINDOWS\System32\athihvs.dll[2011.06.16 10:37:38 | 000,053,248 | ---- | C] (Atheros) -- C:\WINDOWS\System32\athihvui.dll[2011.06.16 10:37:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\pt-PT[2011.06.16 10:37:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\pl-PL[2011.06.16 10:37:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\nn-NO[2011.06.16 10:37:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\nl-NL[2011.06.16 10:37:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ko-KR[2011.06.16 10:37:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ja-JP[2011.06.16 10:37:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\it-IT[2011.06.16 10:37:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\hu-HU[2011.06.16 10:37:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\fr-FR[2011.06.16 10:37:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\fi-FI[2011.06.16 10:37:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\es-ES[2011.06.16 10:37:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\el-GR[2011.06.16 10:37:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\de-DE[2011.06.16 10:37:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\da-DK[2011.06.16 10:37:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\cs-CZ[2011.06.16 10:37:30 | 000,000,000 | ---D | C] -- C:\Program Files\Cisco[2011.06.16 10:17:19 | 000,000,000 | ---D | C] -- C:\Program Files\Ralink[2011.06.16 10:17:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\Options[2011.06.16 10:16:36 | 000,000,000 | ---D | C] -- C:\temp[2011.06.16 09:49:28 | 000,317,952 | ---- | C] (Blue Sky Software Corporation.) -- C:\WINDOWS\System32\roboex32.dll[2011.06.16 09:49:28 | 000,000,000 | ---D | C] -- C:\Program Files\IEEE 802.11b AP Manager[2011.06.16 09:49:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\IEEE 802.11b AP Manager[2011.06.16 09:40:43 | 000,000,000 | ---D | C] -- C:\Program Files\Acer Homeplug Ethernet Adapter Utilities 1.1[2011.06.16 09:40:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Acer HomePlug Configuration Utility[2011.06.15 23:12:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\YANEV\Local Settings\Application Data\Help[2011.06.15 23:12:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\YANEV\Application Data\Help[2011.06.15 22:58:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\YANEV\Application Data\WinRAR[2011.06.15 22:57:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\YANEV\Start Menu\Programs\WinRAR[2011.06.15 22:57:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\WinRAR[2011.06.15 22:57:44 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR[2011.06.15 21:33:11 | 000,000,000 | -HSD | C] -- C:\RECYCLER[2011.06.15 21:06:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Adobe[2011.06.15 21:06:00 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe[2011.06.15 21:06:00 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe[2011.06.15 21:04:30 | 000,307,200 | ---- | C] (Sonix) -- C:\WINDOWS\System32\vsnp2uvc.dll[2011.06.15 21:04:30 | 000,176,128 | ---- | C] ( ) -- C:\WINDOWS\System32\csnp2uvc.dll[2011.06.15 21:04:30 | 000,094,208 | ---- | C] (sonix) -- C:\WINDOWS\PLFSetL.exe[2011.06.15 21:04:27 | 000,229,376 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnp2uvc.dll[2011.06.15 21:04:24 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SNP2UVC[2011.06.15 21:01:39 | 000,050,752 | ---- | C] (Agere Systems) -- C:\WINDOWS\System32\agrsmdel.exe[2011.06.15 21:01:36 | 001,163,616 | ---- | C] (Agere Systems) -- C:\WINDOWS\System32\drivers\AGRSM.sys[2011.06.15 21:01:36 | 000,050,752 | ---- | C] (Agere Systems) -- C:\WINDOWS\agrsmdel.exe[2011.06.15 21:01:36 | 000,013,312 | ---- | C] (Agere Systems) -- C:\WINDOWS\System32\agrscoin.dll[2011.06.15 21:01:36 | 000,009,216 | ---- | C] (Agere Systems) -- C:\WINDOWS\System32\agrsmsvc.exe[2011.06.15 20:53:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\YANEV\Application Data\Intel[2011.06.15 20:53:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Intel[2011.06.15 20:53:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Intel[2011.06.15 20:52:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Intel PROSet Wireless[2011.06.15 20:52:36 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Intel[2011.06.15 20:52:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Intel[2011.06.15 20:50:27 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\YANEV\PrivacIE[2011.06.15 20:46:37 | 000,637,824 | ---- | C] (Ralink Technology, Corp.) -- C:\WINDOWS\System32\rt2860.sys[2011.06.15 20:46:37 | 000,217,088 | ---- | C] (Ralink Technology, Inc.) -- C:\WINDOWS\System32\RaCoInst.dll[2011.06.15 20:46:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Ralink[2011.06.15 20:44:56 | 000,000,000 | ---D | C] -- C:\QUALCOMM[2011.06.15 20:44:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\QUALCOMM[2011.06.15 20:43:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Acer 3G Connection Manager[2011.06.15 20:43:55 | 000,000,000 | ---D | C] -- C:\Program Files\Option[2011.06.15 20:41:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Atheros[2011.06.15 20:39:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\YANEV\Application Data\InstallShield[2011.06.15 20:33:59 | 000,053,248 | ---- | C] (Windows XP Bundled build C-Centric Single User) -- C:\WINDOWS\System32\CSVer.dll[2011.06.15 20:33:59 | 000,000,000 | ---D | C] -- C:\Program Files\Intel[2011.06.15 20:29:39 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\RTCOM[2011.06.15 20:29:32 | 000,290,816 | ---- | C] (Realtek Semiconductor Crop.) -- C:\WINDOWS\vncutil.exe[2011.06.15 20:29:29 | 000,104,992 | ---- | C] (Realtek Semiconductor) -- C:\WINDOWS\RtkAudioService.exe[2011.06.15 20:29:23 | 001,684,736 | ---- | C] (Creative) -- C:\WINDOWS\System32\drivers\Ambfilt.sys[2011.06.15 20:29:22 | 002,808,832 | ---- | C] (RealTek Semicoductor Corp.) -- C:\WINDOWS\ALCWZRD.EXE[2011.06.15 20:29:22 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek[2011.06.15 20:29:20 | 000,000,000 | -H-D | C] -- C:\Program Files\InstallShield Installation Information[2011.06.15 20:29:02 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\InstallShield[2011.06.15 20:23:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Lang[2011.06.15 20:23:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DRVSTORE[2011.06.15 20:19:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ReinstallBackups[2011.06.15 20:19:09 | 000,005,120 | ---- | C] (Dritek System Inc.) -- C:\WINDOWS\System32\FILTRCOI.DLL[2011.06.15 20:19:07 | 000,207,368 | ---- | C] (Dritek System Inc.) -- C:\WINDOWS\UNINST32.EXE[2011.06.15 20:19:07 | 000,000,000 | ---D | C] -- C:\Program Files\Launch Manager[2011.06.15 20:11:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\YANEV\Application Data\Identities[2011.06.15 20:11:28 | 000,000,000 | R--D | C] -- C:\Documents and Settings\YANEV\My Documents\My Pictures[2011.06.15 20:11:28 | 000,000,000 | R--D | C] -- C:\Documents and Settings\YANEV\My Documents\My Music[2011.06.15 20:11:28 | 000,000,000 | -H-D | C] -- C:\Program Files\Uninstall Information[2011.06.15 20:11:22 | 000,000,000 | --SD | C] -- C:\Documents and Settings\YANEV\Local Settings\Application Data\Microsoft[2011.06.15 20:11:22 | 000,000,000 | --SD | C] -- C:\Documents and Settings\YANEV\Application Data\Microsoft[2011.06.15 20:11:22 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\YANEV\SendTo[2011.06.15 20:11:22 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\YANEV\Recent[2011.06.15 20:11:22 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\YANEV\Application Data[2011.06.15 20:11:22 | 000,000,000 | R--D | C] -- C:\Documents and Settings\YANEV\Start Menu\Programs\Startup[2011.06.15 20:11:22 | 000,000,000 | R--D | C] -- C:\Documents and Settings\YANEV\Start Menu[2011.06.15 20:11:22 | 000,000,000 | R--D | C] -- C:\Documents and Settings\YANEV\My Documents[2011.06.15 20:11:22 | 000,000,000 | R--D | C] -- C:\Documents and Settings\YANEV\Favorites[2011.06.15 20:11:22 | 000,000,000 | R--D | C] -- C:\Documents and Settings\YANEV\Start Menu\Programs\Accessories[2011.06.15 20:11:22 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\YANEV\IETldCache[2011.06.15 20:11:22 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\YANEV\Cookies[2011.06.15 20:11:22 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\YANEV\Templates[2011.06.15 20:11:22 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\YANEV\PrintHood[2011.06.15 20:11:22 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\YANEV\NetHood[2011.06.15 20:11:22 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\YANEV\Local Settings[2011.06.15 20:11:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\YANEV\Desktop[2011.06.15 20:09:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\SoftwareDistribution[2011.06.15 20:09:45 | 000,000,000 | --SD | C] -- C:\WINDOWS\System32\Microsoft[2011.06.15 20:09:45 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch[2011.06.15 20:09:44 | 000,000,000 | --SD | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft[2011.06.15 20:09:44 | 000,000,000 | --SD | C] -- C:\Documents and Settings\LocalService\Application Data\Microsoft[2011.06.15 20:09:20 | 000,000,000 | --SD | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft[2011.06.15 20:09:20 | 000,000,000 | --SD | C] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft[2011.06.15 20:08:05 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia330.dll[2011.06.15 20:08:05 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia001.dll[2011.06.15 20:08:05 | 000,029,184 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rw330ext.dll[2011.06.15 20:07:11 | 000,054,528 | ---- | C] (Philips Semiconductors GmbH) -- C:\WINDOWS\System32\dllcache\cap7146.sys[2011.06.15 20:06:49 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\xircom[2011.06.15 20:06:49 | 000,000,000 | ---D | C] -- C:\Program Files\xerox[2011.06.15 20:06:49 | 000,000,000 | ---D | C] -- C:\Program Files\microsoft frontpage[2011.06.15 20:06:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\bg-Bg[2011.06.15 20:05:10 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\LogFiles[2011.06.15 20:04:56 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\umdf[2011.06.15 20:04:41 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Media Connect 2[2011.06.15 20:03:31 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\DRM[2011.06.15 20:03:14 | 000,000,000 | -H-D | C] -- C:\Program Files\WindowsUpdate[2011.06.15 20:02:52 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DirectX[2011.06.15 20:02:31 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Services[2011.06.15 20:02:28 | 000,000,000 | --SD | C] -- C:\WINDOWS\Tasks[2011.06.15 20:02:27 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\MSSoap[2011.06.15 20:02:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\srchasst[2011.06.15 20:02:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Macromed[2011.06.15 20:02:11 | 000,000,000 | ---D | C] -- C:\Program Files\Movie Maker[2011.06.15 20:01:49 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Restore[2011.06.15 20:01:45 | 000,000,000 | ---D | C] -- C:\Program Files\NetMeeting[2011.06.15 20:01:41 | 000,000,000 | ---D | C] -- C:\Program Files\Outlook Express[2011.06.15 20:01:35 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\System[2011.06.15 20:01:32 | 000,000,000 | ---D | C] -- C:\Program Files\Internet Explorer[2011.06.15 20:01:31 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Pictures[2011.06.15 20:01:31 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Music[2011.06.15 20:01:10 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Games[2011.06.15 20:00:58 | 000,000,000 | ---D | C] -- C:\Program Files\ComPlus Applications[2011.06.15 20:00:51 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools[2011.06.15 20:00:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\Registration[2011.06.15 20:00:43 | 000,000,000 | ---D | C] -- C:\Program Files\Online Services[2011.06.15 20:00:42 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Media Player[2011.06.15 20:00:34 | 000,000,000 | ---D | C] -- C:\Program Files\Messenger[2011.06.15 20:00:31 | 000,000,000 | ---D | C] -- C:\Program Files\MSN Gaming Zone[2011.06.15 19:59:56 | 000,000,000 | ---D | C] -- C:\Program Files\MSN[2011.06.15 19:59:55 | 000,281,088 | ---- | C] (Cinematronics) -- C:\WINDOWS\System32\dllcache\pinball.exe[2011.06.15 19:59:54 | 000,000,000 | ---D | C] -- C:\Program Files\Windows NT[2011.06.15 19:59:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\MsDtc[2011.06.15 19:59:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Com[2011.06.15 19:59:35 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Videos[2011.06.15 19:59:13 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Accessories[2011.06.15 12:47:25 | 000,000,000 | -HSD | C] -- C:\WINDOWS\Installer[2011.06.15 12:47:24 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ODBC[2011.06.15 12:47:21 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SpeechEngines[2011.06.15 12:47:20 | 000,000,000 | R--D | C] -- C:\Program Files[2011.06.15 12:47:20 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Microsoft Shared[2011.06.15 12:47:20 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files[2011.06.15 12:46:48 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup[2011.06.15 12:46:48 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu[2011.06.15 12:46:48 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents[2011.06.15 12:46:48 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Templates[2011.06.15 12:46:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Favorites[2011.06.15 12:46:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Desktop[2011.06.15 12:46:34 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot2[2011.06.15 12:46:34 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot[2011.06.15 12:46:28 | 000,000,000 | --SD | C] -- C:\Documents and Settings\All Users\Application Data\Microsoft[2011.06.15 12:46:28 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\All Users\Application Data[2011.06.15 12:46:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings[2011.06.15 12:46:05 | 000,000,000 | -HSD | C] -- C:\System Volume Information[2011.06.15 12:41:51 | 000,000,000 | --SD | C] -- C:\WINDOWS\Offline Web Pages[2011.06.15 12:41:51 | 000,000,000 | --SD | C] -- C:\WINDOWS\Downloaded Program Files[2011.06.15 12:41:51 | 000,000,000 | R-SD | C] -- C:\WINDOWS\Fonts[2011.06.15 12:41:51 | 000,000,000 | RHSD | C] -- C:\WINDOWS\System32\dllcache[2011.06.15 12:41:51 | 000,000,000 | R--D | C] -- C:\WINDOWS\Web[2011.06.15 12:41:51 | 000,000,000 | -H-D | C] -- C:\WINDOWS\inf[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\WinSxS[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\wins[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\WBEM[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\wbem[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\usmt[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\twain_32[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\Temp[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\system32[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\system[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\spool[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ShellExt[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Setup[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\security[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\scripting[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\Resources[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\repair[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ras[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\Provisioning[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\PreInstall[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\PeerNet[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\pchealth[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\oobe[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\npp[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\Network Diagnostic[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\mui[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\mui[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\msapps[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\msagent[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\Media[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\L2Schemas[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\java[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\inetsrv[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\IME[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\ime[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\icsxml[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ias[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\Help[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\export[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\etc[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\en-US[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\en[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\ehome[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\Driver Cache[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\disdn[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\dhcp[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\Debug[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\Cursors[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\Connection Wizard[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\config[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\Config[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\AppPatch[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\addins[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\3com_dmi[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\3076[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\2052[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1054[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1042[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1041[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1037[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1033[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1031[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1028[2011.06.15 12:41:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1025[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ][1 C:\Documents and Settings\YANEV\*.tmp files -> C:\Documents and Settings\YANEV\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2011.06.17 10:19:19 | 000,000,280 | -H-- | M] () -- C:\WINDOWS\tqyzflktbxckkulncvkofktkzp.uvb[2011.06.17 10:19:19 | 000,000,280 | -H-- | M] () -- C:\WINDOWS\System32\tqyzflktbxckkulncvkofktkzp.uvb[2011.06.17 10:19:19 | 000,000,280 | -H-- | M] () -- C:\Program Files\tqyzflktbxckkulncvkofktkzp.uvb[2011.06.17 10:19:19 | 000,000,280 | -H-- | M] () -- C:\Documents and Settings\YANEV\Local Settings\Application Data\tqyzflktbxckkulncvkofktkzp.uvb[2011.06.17 10:17:33 | 000,917,504 | RHS- | M] () -- C:\WINDOWS\zicphzkfzhyseadr.exe[2011.06.17 10:17:33 | 000,917,504 | RHS- | M] () -- C:\WINDOWS\tiibzxoppdaasudxepwsby.exe[2011.06.17 10:17:33 | 000,917,504 | RHS- | M] () -- C:\WINDOWS\pawlfzmjfpiesqvlov.exe[2011.06.17 10:17:33 | 000,917,504 | RHS- | M] () -- C:\WINDOWS\nayplhwvtfayoovnsbga.exe[2011.06.17 10:17:33 | 000,917,504 | RHS- | M] () -- C:\WINDOWS\gqlzslxtoxpkxuynp.exe[2011.06.17 10:17:33 | 000,917,504 | RHS- | M] () -- C:\WINDOWS\cqphebrrqdzypqyrxhniq.exe[2011.06.17 10:17:33 | 000,917,504 | RHS- | M] () -- C:\WINDOWS\amjzupdbyjdapoulpxb.exe[2011.06.17 08:42:56 | 000,311,938 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat[2011.06.17 08:42:56 | 000,040,326 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat[2011.06.17 08:39:34 | 000,917,504 | RHS- | M] () -- C:\rwmvjxevlpcs.bat[2011.06.17 08:39:34 | 000,000,814 | RHS- | M] () -- C:\autorun.inf[2011.06.17 08:38:37 | 000,917,504 | RHS- | M] () -- C:\WINDOWS\System32\tiibzxoppdaasudxepwsby.exe[2011.06.17 08:38:37 | 000,917,504 | RHS- | M] () -- C:\WINDOWS\System32\nayplhwvtfayoovnsbga.exe[2011.06.17 08:38:37 | 000,917,504 | RHS- | M] () -- C:\WINDOWS\System32\cqphebrrqdzypqyrxhniq.exe[2011.06.17 08:38:37 | 000,917,504 | RHS- | M] () -- C:\WINDOWS\System32\amjzupdbyjdapoulpxb.exe[2011.06.17 08:38:36 | 000,917,504 | RHS- | M] () -- C:\WINDOWS\System32\pawlfzmjfpiesqvlov.exe[2011.06.17 08:38:36 | 000,917,504 | RHS- | M] () -- C:\WINDOWS\System32\gqlzslxtoxpkxuynp.exe[2011.06.17 08:38:32 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat[2011.06.16 21:18:59 | 000,000,402 | ---- | M] () -- C:\Documents and Settings\YANEV\Desktop\Пряк път до OFICE.lnk[2011.06.16 16:11:08 | 000,000,056 | -H-- | M] () -- C:\WINDOWS\System32\ezsidmv.dat[2011.06.16 14:09:39 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\YANEV\Desktop\OTL.exe[2011.06.16 13:57:15 | 000,000,729 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\FlexType 2K.lnk[2011.06.16 13:53:26 | 000,001,878 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk[2011.06.16 13:36:49 | 000,001,510 | ---- | M] () -- C:\Documents and Settings\YANEV\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk[2011.06.16 13:36:49 | 000,001,492 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Opera.lnk[2011.06.16 11:00:52 | 000,096,664 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT[2011.06.16 09:01:31 | 000,917,504 | RHS- | M] () -- C:\WINDOWS\System32\zicphzkfzhyseadr.exe[2011.06.15 21:36:19 | 000,004,566 | ---- | M] () -- C:\WINDOWS\imsins.BAK[2011.06.15 21:27:46 | 000,000,815 | ---- | M] () -- C:\Documents and Settings\YANEV\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk[2011.06.15 21:06:12 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk[2011.06.15 20:30:52 | 000,940,794 | ---- | M] () -- C:\WINDOWS\System32\LoopyMusic.wav[2011.06.15 20:30:52 | 000,146,650 | ---- | M] () -- C:\WINDOWS\System32\BuzzingBee.wav[2011.06.15 20:19:10 | 000,000,083 | ---- | M] () -- C:\WINDOWS\LManager.UNI[2011.06.15 20:12:23 | 000,004,248 | -H-- | M] () -- C:\WINDOWS\ucvhypztmtjcnikxxbbqsiceefngsjakexeun.tvi[2011.06.15 20:12:23 | 000,004,248 | -H-- | M] () -- C:\WINDOWS\System32\ucvhypztmtjcnikxxbbqsiceefngsjakexeun.tvi[2011.06.15 20:12:23 | 000,004,248 | -H-- | M] () -- C:\Program Files\ucvhypztmtjcnikxxbbqsiceefngsjakexeun.tvi[2011.06.15 20:12:23 | 000,004,248 | -H-- | M] () -- C:\Documents and Settings\YANEV\Local Settings\Application Data\ucvhypztmtjcnikxxbbqsiceefngsjakexeun.tvi[2011.06.15 20:11:42 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\YANEV\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf[2011.06.15 20:11:40 | 000,000,815 | ---- | M] () -- C:\Documents and Settings\YANEV\Application Data\Microsoft\Internet Explorer\Quick Launch\Стартиране на браузъра Internet Explorer.lnk[2011.06.15 20:11:21 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl[2011.06.15 20:09:24 | 000,008,192 | ---- | M] () -- C:\WINDOWS\REGLOCS.OLD[2011.06.15 20:08:37 | 000,000,261 | ---- | M] () -- C:\WINDOWS\System32\$winnt$.inf[2011.06.15 20:05:10 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\umdf\MsftWdf_user_01_00_00.Wdf[2011.06.15 20:04:46 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb[2011.06.15 20:04:46 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb[2011.06.15 20:04:24 | 000,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT[2011.06.15 20:04:24 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS[2011.06.15 20:04:24 | 000,000,000 | RHS- | M] () -- C:\IO.SYS[2011.06.15 20:04:24 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS[2011.06.15 20:04:24 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT[2011.06.15 20:04:18 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx[2011.06.15 20:04:09 | 000,004,161 | ---- | M] () -- C:\WINDOWS\ODBCINST.INI[2011.06.15 20:01:08 | 000,021,640 | ---- | M] () -- C:\WINDOWS\System32\emptyregdb.dat[2011.06.15 19:58:46 | 000,000,211 | -HS- | M] () -- C:\boot.ini[2011.06.15 12:57:39 | 000,004,444 | ---- | M] () -- C:\WINDOWS\System32\pid.PNF[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ][1 C:\Documents and Settings\YANEV\*.tmp files -> C:\Documents and Settings\YANEV\*.tmp -> ] ========== Files Created - No Company Name ========== [2011.06.16 16:11:08 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat[2011.06.16 13:57:15 | 000,000,729 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\FlexType 2K.lnk[2011.06.16 13:57:10 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\newdll.dll[2011.06.16 13:56:04 | 000,000,402 | ---- | C] () -- C:\Documents and Settings\YANEV\Desktop\Пряк път до OFICE.lnk[2011.06.16 13:53:26 | 000,001,878 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk[2011.06.16 13:36:49 | 000,001,510 | ---- | C] () -- C:\Documents and Settings\YANEV\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk[2011.06.16 13:36:49 | 000,001,498 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Opera.lnk[2011.06.16 13:36:49 | 000,001,492 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Opera.lnk[2011.06.16 13:13:23 | 000,167,843 | ---- | C] () -- C:\WINDOWS\System32\netathw.inf[2011.06.16 13:13:23 | 000,042,724 | ---- | C] () -- C:\WINDOWS\System32\netathw.cat[2011.06.16 13:13:23 | 000,042,303 | ---- | C] () -- C:\WINDOWS\System32\wsimdp.cat[2011.06.16 13:13:23 | 000,042,301 | ---- | C] () -- C:\WINDOWS\System32\wsimd.cat[2011.06.16 13:13:23 | 000,005,363 | ---- | C] () -- C:\WINDOWS\System32\wsimdp.inf[2011.06.16 13:13:23 | 000,002,179 | ---- | C] () -- C:\WINDOWS\System32\wsimd.inf[2011.06.16 11:25:14 | 000,680,436 | ---- | C] () -- C:\WINDOWS\System32\bcmwl5.inf[2011.06.16 11:25:14 | 000,010,283 | ---- | C] () -- C:\WINDOWS\System32\bcm43xx.cat[2011.06.16 11:25:14 | 000,000,072 | ---- | C] () -- C:\WINDOWS\System32\4357_Update32D.BAT[2011.06.16 11:25:14 | 000,000,072 | ---- | C] () -- C:\WINDOWS\System32\4357_Update32C.BAT[2011.06.16 11:25:14 | 000,000,072 | ---- | C] () -- C:\WINDOWS\System32\4328_Update32D.BAT[2011.06.16 11:25:14 | 000,000,072 | ---- | C] () -- C:\WINDOWS\System32\4328_Update32C.BAT[2011.06.16 11:25:14 | 000,000,072 | ---- | C] () -- C:\WINDOWS\System32\4318_0312_Update32D.BAT[2011.06.16 11:25:14 | 000,000,072 | ---- | C] () -- C:\WINDOWS\System32\4318_0312_Update32C.BAT[2011.06.16 11:25:14 | 000,000,072 | ---- | C] () -- C:\WINDOWS\System32\4318_0311_Update32D.BAT[2011.06.16 11:25:14 | 000,000,072 | ---- | C] () -- C:\WINDOWS\System32\4318_0311_Update32C.BAT[2011.06.16 11:25:14 | 000,000,072 | ---- | C] () -- C:\WINDOWS\System32\4315_Update32D.BAT[2011.06.16 11:25:14 | 000,000,072 | ---- | C] () -- C:\WINDOWS\System32\4315_Update32C.BAT[2011.06.16 11:25:14 | 000,000,072 | ---- | C] () -- C:\WINDOWS\System32\4312_Update32D.BAT[2011.06.16 11:25:14 | 000,000,072 | ---- | C] () -- C:\WINDOWS\System32\4312_Update32C.BAT[2011.06.16 11:25:14 | 000,000,072 | ---- | C] () -- C:\WINDOWS\System32\4311_Update32D.BAT[2011.06.16 11:25:14 | 000,000,072 | ---- | C] () -- C:\WINDOWS\System32\4311_Update32C.BAT[2011.06.16 11:25:14 | 000,000,061 | ---- | C] () -- C:\WINDOWS\System32\4357_Remove32D.BAT[2011.06.16 11:25:14 | 000,000,061 | ---- | C] () -- C:\WINDOWS\System32\4357_Remove32C.BAT[2011.06.16 11:25:14 | 000,000,061 | ---- | C] () -- C:\WINDOWS\System32\4328_Remove32D.BAT[2011.06.16 11:25:14 | 000,000,061 | ---- | C] () -- C:\WINDOWS\System32\4328_Remove32C.BAT[2011.06.16 11:25:14 | 000,000,061 | ---- | C] () -- C:\WINDOWS\System32\4318_0312_Remove32D.BAT[2011.06.16 11:25:14 | 000,000,061 | ---- | C] () -- C:\WINDOWS\System32\4318_0312_Remove32C.BAT[2011.06.16 11:25:14 | 000,000,061 | ---- | C] () -- C:\WINDOWS\System32\4318_0311_Remove32D.BAT[2011.06.16 11:25:14 | 000,000,061 | ---- | C] () -- C:\WINDOWS\System32\4318_0311_Remove32C.BAT[2011.06.16 11:25:14 | 000,000,061 | ---- | C] () -- C:\WINDOWS\System32\4315_Remove32D.BAT[2011.06.16 11:25:14 | 000,000,061 | ---- | C] () -- C:\WINDOWS\System32\4315_Remove32C.BAT[2011.06.16 11:25:14 | 000,000,061 | ---- | C] () -- C:\WINDOWS\System32\4312_Remove32D.BAT[2011.06.16 11:25:14 | 000,000,061 | ---- | C] () -- C:\WINDOWS\System32\4312_Remove32C.BAT[2011.06.16 11:25:14 | 000,000,061 | ---- | C] () -- C:\WINDOWS\System32\4311_Remove32D.BAT[2011.06.16 11:25:14 | 000,000,061 | ---- | C] () -- C:\WINDOWS\System32\4311_Remove32C.BAT[2011.06.16 11:25:14 | 000,000,008 | RHS- | C] () -- C:\WINDOWS\System32\Desktop_.ini[2011.06.16 10:37:39 | 000,127,978 | ---- | C] () -- C:\WINDOWS\System32\netathr.inf[2011.06.16 10:37:39 | 000,040,728 | ---- | C] () -- C:\WINDOWS\System32\athrext.cat[2011.06.16 09:49:28 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\wlbroadcast.dll[2011.06.15 21:27:46 | 000,000,815 | ---- | C] () -- C:\Documents and Settings\YANEV\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk[2011.06.15 21:06:12 | 000,001,804 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader 9.lnk[2011.06.15 21:06:12 | 000,001,729 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk[2011.06.15 21:04:30 | 001,754,368 | ---- | C] () -- C:\WINDOWS\System32\drivers\snp2uvc.sys[2011.06.15 21:04:30 | 000,028,800 | ---- | C] () -- C:\WINDOWS\System32\drivers\sncduvc.sys[2011.06.15 21:04:30 | 000,015,497 | ---- | C] () -- C:\WINDOWS\snp2uvc.ini[2011.06.15 21:04:30 | 000,013,022 | ---- | C] () -- C:\WINDOWS\snp2uvc.src[2011.06.15 21:04:30 | 000,000,055 | ---- | C] () -- C:\WINDOWS\PidList.ini[2011.06.15 20:51:32 | 000,000,814 | RHS- | C] () -- C:\autorun.inf[2011.06.15 20:46:37 | 000,027,925 | ---- | C] () -- C:\WINDOWS\System32\rt2860.inf[2011.06.15 20:46:37 | 000,014,028 | ---- | C] () -- C:\WINDOWS\System32\RaCoInst.dat[2011.06.15 20:46:37 | 000,011,789 | ---- | C] () -- C:\WINDOWS\System32\rt2860.cat[2011.06.15 20:30:52 | 000,940,794 | ---- | C] () -- C:\WINDOWS\System32\LoopyMusic.wav[2011.06.15 20:30:52 | 000,146,650 | ---- | C] () -- C:\WINDOWS\System32\BuzzingBee.wav[2011.06.15 20:29:34 | 000,090,772 | R--- | C] () -- C:\WINDOWS\System32\drivers\RtConvEQ.DAT[2011.06.15 20:29:34 | 000,000,536 | R--- | C] () -- C:\WINDOWS\System32\drivers\RtHdatEx.dat[2011.06.15 20:29:34 | 000,000,008 | R--- | C] () -- C:\WINDOWS\System32\drivers\rtkhdaud.dat[2011.06.15 20:23:57 | 000,147,456 | R--- | C] () -- C:\WINDOWS\System32\igfxCoIn_v5016.dll[2011.06.15 20:23:56 | 002,026,604 | R--- | C] () -- C:\WINDOWS\System32\igkrng500.bin[2011.06.15 20:23:56 | 000,442,964 | R--- | C] () -- C:\WINDOWS\System32\igcompkrng500.bin[2011.06.15 20:23:56 | 000,029,504 | R--- | C] () -- C:\WINDOWS\System32\igxpxs32.vp[2011.06.15 20:23:56 | 000,002,096 | R--- | C] () -- C:\WINDOWS\System32\igxpxk32.vp[2011.06.15 20:19:10 | 000,000,083 | ---- | C] () -- C:\WINDOWS\LManager.UNI[2011.06.15 20:12:23 | 000,004,248 | -H-- | C] () -- C:\WINDOWS\ucvhypztmtjcnikxxbbqsiceefngsjakexeun.tvi[2011.06.15 20:12:23 | 000,004,248 | -H-- | C] () -- C:\WINDOWS\System32\ucvhypztmtjcnikxxbbqsiceefngsjakexeun.tvi[2011.06.15 20:12:23 | 000,004,248 | -H-- | C] () -- C:\Program Files\ucvhypztmtjcnikxxbbqsiceefngsjakexeun.tvi[2011.06.15 20:12:23 | 000,004,248 | -H-- | C] () -- C:\Documents and Settings\YANEV\Local Settings\Application Data\ucvhypztmtjcnikxxbbqsiceefngsjakexeun.tvi[2011.06.15 20:12:23 | 000,000,280 | -H-- | C] () -- C:\WINDOWS\tqyzflktbxckkulncvkofktkzp.uvb[2011.06.15 20:12:23 | 000,000,280 | -H-- | C] () -- C:\WINDOWS\System32\tqyzflktbxckkulncvkofktkzp.uvb[2011.06.15 20:12:23 | 000,000,280 | -H-- | C] () -- C:\Program Files\tqyzflktbxckkulncvkofktkzp.uvb[2011.06.15 20:12:23 | 000,000,280 | -H-- | C] () -- C:\Documents and Settings\YANEV\Local Settings\Application Data\tqyzflktbxckkulncvkofktkzp.uvb[2011.06.15 20:12:13 | 000,917,504 | RHS- | C] () -- C:\WINDOWS\tiibzxoppdaasudxepwsby.exe[2011.06.15 20:12:13 | 000,917,504 | RHS- | C] () -- C:\WINDOWS\cqphebrrqdzypqyrxhniq.exe[2011.06.15 20:12:12 | 000,917,504 | RHS- | C] () -- C:\WINDOWS\zicphzkfzhyseadr.exe[2011.06.15 20:12:12 | 000,917,504 | RHS- | C] () -- C:\WINDOWS\pawlfzmjfpiesqvlov.exe[2011.06.15 20:12:12 | 000,917,504 | RHS- | C] () -- C:\WINDOWS\nayplhwvtfayoovnsbga.exe[2011.06.15 20:12:12 | 000,917,504 | RHS- | C] () -- C:\WINDOWS\gqlzslxtoxpkxuynp.exe[2011.06.15 20:12:12 | 000,917,504 | RHS- | C] () -- C:\WINDOWS\amjzupdbyjdapoulpxb.exe[2011.06.15 20:12:11 | 000,917,504 | RHS- | C] () -- C:\WINDOWS\System32\tiibzxoppdaasudxepwsby.exe[2011.06.15 20:12:11 | 000,917,504 | RHS- | C] () -- C:\WINDOWS\System32\pawlfzmjfpiesqvlov.exe[2011.06.15 20:12:11 | 000,917,504 | RHS- | C] () -- C:\WINDOWS\System32\nayplhwvtfayoovnsbga.exe[2011.06.15 20:12:11 | 000,917,504 | RHS- | C] () -- C:\WINDOWS\System32\gqlzslxtoxpkxuynp.exe[2011.06.15 20:12:11 | 000,917,504 | RHS- | C] () -- C:\WINDOWS\System32\cqphebrrqdzypqyrxhniq.exe[2011.06.15 20:12:11 | 000,917,504 | RHS- | C] () -- C:\WINDOWS\System32\amjzupdbyjdapoulpxb.exe[2011.06.15 20:12:10 | 000,917,504 | RHS- | C] () -- C:\WINDOWS\System32\zicphzkfzhyseadr.exe[2011.06.15 20:11:42 | 000,000,079 | ---- | C] () -- C:\Documents and Settings\YANEV\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf[2011.06.15 20:11:40 | 000,000,815 | ---- | C] () -- C:\Documents and Settings\YANEV\Application Data\Microsoft\Internet Explorer\Quick Launch\Стартиране на браузъра Internet Explorer.lnk[2011.06.15 20:11:40 | 000,000,803 | ---- | C] () -- C:\Documents and Settings\YANEV\Start Menu\Programs\Internet Explorer.lnk[2011.06.15 20:11:33 | 000,000,738 | ---- | C] () -- C:\Documents and Settings\YANEV\Start Menu\Programs\Outlook Express.lnk[2011.06.15 20:11:22 | 000,001,599 | ---- | C] () -- C:\Documents and Settings\YANEV\Start Menu\Programs\Remote Assistance.lnk[2011.06.15 20:11:22 | 000,000,788 | ---- | C] () -- C:\Documents and Settings\YANEV\Start Menu\Programs\Windows Media Player.lnk[2011.06.15 20:09:24 | 000,008,192 | ---- | C] () -- C:\WINDOWS\REGLOCS.OLD[2011.06.15 20:08:37 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat[2011.06.15 20:08:00 | 000,175,104 | ---- | C] () -- C:\WINDOWS\System32\dllcache\pintlcsa.dll[2011.06.15 20:07:46 | 001,158,818 | ---- | C] () -- C:\WINDOWS\System32\dllcache\korwbrkr.lex[2011.06.15 20:07:41 | 000,059,392 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imscinst.exe[2011.06.15 20:07:40 | 000,196,665 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imjpinst.exe[2011.06.15 20:07:39 | 000,134,339 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imekr.lex[2011.06.15 20:07:31 | 013,463,552 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hwxjpn.dll[2011.06.15 20:07:27 | 000,108,827 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hanja.lex[2011.06.15 20:07:23 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\dllcache\fpencode.dll[2011.06.15 20:07:13 | 000,173,568 | ---- | C] () -- C:\WINDOWS\System32\dllcache\chtskf.dll[2011.06.15 20:05:10 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\umdf\MsftWdf_user_01_00_00.Wdf[2011.06.15 20:04:24 | 000,002,577 | ---- | C] () -- C:\WINDOWS\System32\CONFIG.NT[2011.06.15 20:04:24 | 000,000,000 | RHS- | C] () -- C:\MSDOS.SYS[2011.06.15 20:04:24 | 000,000,000 | RHS- | C] () -- C:\IO.SYS[2011.06.15 20:04:24 | 000,000,000 | ---- | C] () -- C:\CONFIG.SYS[2011.06.15 20:04:24 | 000,000,000 | ---- | C] () -- C:\AUTOEXEC.BAT[2011.06.15 20:04:20 | 000,023,392 | ---- | C] () -- C:\WINDOWS\System32\nscompat.tlb[2011.06.15 20:04:20 | 000,016,832 | ---- | C] () -- C:\WINDOWS\System32\amcompat.tlb[2011.06.15 20:04:18 | 000,316,640 | ---- | C] () -- C:\WINDOWS\WMSysPr9.prx[2011.06.15 20:03:14 | 000,000,786 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Movie Maker.lnk[2011.06.15 20:02:59 | 004,399,505 | ---- | C] () -- C:\WINDOWS\System32\dllcache\nls302en.lex[2011.06.15 20:02:41 | 000,048,680 | -HS- | C] () -- C:\WINDOWS\winnt256.bmp[2011.06.15 20:02:41 | 000,048,680 | -HS- | C] () -- C:\WINDOWS\winnt.bmp[2011.06.15 20:02:34 | 000,000,984 | ---- | C] () -- C:\WINDOWS\System32\dllcache\srframe.mmf[2011.06.15 20:01:51 | 000,376,832 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msinfo.dll[2011.06.15 20:01:10 | 000,000,609 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Messenger.lnk[2011.06.15 20:01:08 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat[2011.06.15 20:00:17 | 000,009,522 | ---- | C] () -- C:\WINDOWS\Zapotec.bmp[2011.06.15 20:00:16 | 000,065,978 | ---- | C] () -- C:\WINDOWS\Soap Bubbles.bmp[2011.06.15 20:00:16 | 000,065,954 | ---- | C] () -- C:\WINDOWS\Prairie Wind.bmp[2011.06.15 20:00:16 | 000,065,832 | ---- | C] () -- C:\WINDOWS\Santa Fe Stucco.bmp[2011.06.15 20:00:16 | 000,026,680 | ---- | C] () -- C:\WINDOWS\River Sumida.bmp[2011.06.15 20:00:16 | 000,026,582 | ---- | C] () -- C:\WINDOWS\Greenstone.bmp[2011.06.15 20:00:16 | 000,017,362 | ---- | C] () -- C:\WINDOWS\Rhododendron.bmp[2011.06.15 20:00:16 | 000,017,336 | ---- | C] () -- C:\WINDOWS\Gone Fishing.bmp[2011.06.15 20:00:16 | 000,017,062 | ---- | C] () -- C:\WINDOWS\Coffee Bean.bmp[2011.06.15 20:00:16 | 000,016,730 | ---- | C] () -- C:\WINDOWS\FeatherTexture.bmp[2011.06.15 20:00:16 | 000,001,272 | ---- | C] () -- C:\WINDOWS\Blue Lace 16.bmp[2011.06.15 20:00:13 | 000,003,286 | ---- | C] () -- C:\WINDOWS\System32\tslabels.h[2011.06.15 20:00:13 | 000,001,161 | ---- | C] () -- C:\WINDOWS\System32\usrlogon.cmd[2011.06.15 20:00:12 | 000,000,768 | ---- | C] () -- C:\WINDOWS\System32\msdtcprf.h[2011.06.15 20:00:06 | 000,063,488 | ---- | C] () -- C:\WINDOWS\System32\wmimgmt.msc[2011.06.15 12:57:39 | 000,004,444 | ---- | C] () -- C:\WINDOWS\System32\pid.PNF[2011.06.15 12:47:28 | 000,004,566 | ---- | C] () -- C:\WINDOWS\imsins.BAK[2011.06.15 12:47:24 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI[2011.06.15 12:47:22 | 001,685,606 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.spd[2011.06.15 12:47:22 | 000,605,050 | ---- | C] () -- C:\WINDOWS\System32\dllcache\r1033tts.lxa[2011.06.15 12:47:22 | 000,000,888 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.sdf[2011.06.15 12:47:21 | 000,643,717 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ltts1033.lxa[2011.06.15 12:46:57 | 000,001,688 | ---- | C] () -- C:\WINDOWS\System32\AUTOEXEC.NT[2011.06.15 12:46:45 | 000,797,189 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5IIS.CAT[2011.06.15 12:46:45 | 000,399,645 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MAPIMIG.CAT[2011.06.15 12:46:45 | 000,144,484 | ---- | C] () -- C:\WINDOWS\System32\dllcache\netfx.cat[2011.06.15 12:46:45 | 000,112,918 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tabletpc.cat[2011.06.15 12:46:45 | 000,037,484 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MW770.CAT[2011.06.15 12:46:45 | 000,034,747 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mediactr.cat[2011.06.15 12:46:45 | 000,034,063 | ---- | C] () -- C:\WINDOWS\System32\dllcache\FP4.CAT[2011.06.15 12:46:45 | 000,026,991 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msn7.cat[2011.06.15 12:46:45 | 000,016,535 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IMS.CAT[2011.06.15 12:46:45 | 000,014,433 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msn9.cat[2011.06.15 12:46:45 | 000,013,472 | ---- | C] () -- C:\WINDOWS\System32\dllcache\HPCRDP.CAT[2011.06.15 12:46:45 | 000,012,363 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSMSGS.CAT[2011.06.15 12:46:45 | 000,010,027 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSTSWEB.CAT[2011.06.15 12:46:45 | 000,008,574 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IASNT4.CAT[2011.06.15 12:46:45 | 000,007,382 | ---- | C] () -- C:\WINDOWS\System32\dllcache\OEMBIOS.CAT[2011.06.15 12:46:45 | 000,007,334 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmerrenu.cat[2011.06.15 12:46:44 | 002,144,487 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5.CAT[2011.06.15 12:46:44 | 001,296,669 | ---- | C] () -- C:\WINDOWS\System32\dllcache\SP3.CAT[2011.06.15 12:46:44 | 000,522,220 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5INF.CAT[2011.06.15 12:46:05 | 000,096,664 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT[2011.06.15 12:45:22 | 000,000,211 | -HS- | C] () -- C:\boot.ini[2011.06.15 12:45:18 | 000,000,261 | ---- | C] () -- C:\WINDOWS\System32\$winnt$.inf[2008.04.14 04:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin[2008.04.14 04:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat[2008.04.14 04:00:00 | 000,311,938 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat[2008.04.14 04:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat[2008.04.14 04:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat[2008.04.14 04:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin[2008.04.14 04:00:00 | 000,040,326 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat[2008.04.14 04:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat[2008.04.14 04:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat[2008.04.14 04:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat[2008.04.14 04:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin[2008.04.14 04:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat[2002.12.11 14:00:00 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\kbdBF.dll ========== Custom Scans ========== < %SYSTEMDRIVE%\*.* >[2011.06.15 20:04:24 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT[2011.06.17 08:39:34 | 000,000,814 | RHS- | M] () -- C:\autorun.inf[2011.06.15 19:58:46 | 000,000,211 | -HS- | M] () -- C:\boot.ini[2011.06.15 20:04:24 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS[2011.06.15 20:04:24 | 000,000,000 | RHS- | M] () -- C:\IO.SYS[2011.06.15 20:04:24 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS[2008.04.14 04:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM[2008.04.14 04:00:00 | 000,250,048 | RHS- | M] () -- C:\ntldr[2011.06.17 08:38:29 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys[2009.06.06 20:04:11 | 000,917,504 | RHS- | M] () -- C:\pqchrber.bat[2011.06.17 08:39:34 | 000,917,504 | RHS- | M] () -- C:\rwmvjxevlpcs.bat[2009.05.17 18:18:41 | 000,917,504 | RHS- | M] () -- C:\zcqxjvapdf.bat < MD5 for: AGP440.SYS >[2010.03.12 11:26:00 | 017,778,412 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys < MD5 for: ATAPI.SYS >[2010.03.12 11:26:00 | 017,778,412 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys[2008.04.13 22:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\dllcache\atapi.sys[2008.04.13 22:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys[2008.04.14 04:00:00 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys[2008.04.13 22:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys < MD5 for: EVENTLOG.DLL >[2008.04.14 04:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\dllcache\eventlog.dll[2008.04.14 04:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll < MD5 for: NETLOGON.DLL >[2008.04.14 04:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\dllcache\netlogon.dll[2008.04.14 04:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll < MD5 for: SCECLI.DLL >[2008.04.14 04:00:00 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\dllcache\scecli.dll[2008.04.14 04:00:00 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll < End of report > Цитирай Link to comment Сподели другаде More sharing options...
Night_Raven Публикувано Юни 17, 2011 Report Share Публикувано Юни 17, 2011 Стартирай отново OTL. В празното поле "Custom Scans/Fixes" (в долната част на програмата) постави следния текст (маркирай го или натисни бутон Избери всичко, натисни Ctrl+C и после в полето на OTL натисни Ctrl+V): :processes zicphzkfzhyseadr.exe cajls.exe :OTL O4 - HKLM..\Run: [cajls] C:\WINDOWS\System32\amjzupdbyjdapoulpxb.exe () O4 - HKLM..\Run: [uynvivbrgjv] C:\Documents and Settings\YANEV\Local Settings\Temp\zicphzkfzhyseadr.exe () O4 - HKU\S-1-5-21-1993962763-764733703-1801674531-1003..\Run: [cajls] C:\Documents and Settings\YANEV\Local Settings\Temp\pawlfzmjfpiesqvlov.exe () O4 - HKU\S-1-5-21-1993962763-764733703-1801674531-1003..\Run: [pqchrber] C:\WINDOWS\System32\nayplhwvtfayoovnsbga.exe () O4 - HKLM..\RunOnce: [nmwzhp] C:\WINDOWS\System32\pawlfzmjfpiesqvlov.exe () O4 - HKLM..\RunOnce: [zcqxjvapdf] C:\Documents and Settings\YANEV\Local Settings\Temp\nayplhwvtfayoovnsbga.exe () O4 - HKU\S-1-5-21-1993962763-764733703-1801674531-1003..\RunOnce: [givbmxbpc] C:\WINDOWS\System32\pawlfzmjfpiesqvlov.exe () O4 - HKU\S-1-5-21-1993962763-764733703-1801674531-1003..\RunOnce: [nmwzhp] C:\Documents and Settings\YANEV\Local Settings\Temp\zicphzkfzhyseadr.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: aalpyhj = nayplhwvtfayoovnsbga.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: tqyz = C:\DOCUME~1\YANEV\LOCALS~1\Temp\amjzupdbyjdapoulpxb.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O7 - HKU\S-1-5-21-1993962763-764733703-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1 O32 - AutoRun File - [2011.06.17 08:39:34 | 000,000,814 | RHS- | M] () - C:\autorun.inf -- [ NTFS ] O32 - AutoRun File - [2011.06.17 08:39:34 | 000,000,810 | RHS- | M] () - D:\autorun.inf -- [ NTFS ] O32 - AutoRun File - [2011.06.17 08:39:35 | 000,000,802 | RHS- | M] () - E:\autorun.inf -- [ NTFS ] O33 - MountPoints2\{9016fea1-97d1-11e0-bb89-fb8a64fba71b}\Shell\AutoRun\command - "" = G:\pqchrber.bat O33 - MountPoints2\{9016fea1-97d1-11e0-bb89-fb8a64fba71b}\Shell\explore\Command - "" = G:\rwmvjxevlpcs.bat _ O33 - MountPoints2\{9016fea1-97d1-11e0-bb89-fb8a64fba71b}\Shell\open\Command - "" = G:\zcqxjvapdf.bat _ O33 - MountPoints2\{995e5d2a-9786-11e0-913a-806d6172696f}\Shell\AutoRun\command - "" = D:\pqchrber.bat -- [2009.04.10 18:06:38 | 000,917,504 | RHS- | M] () O33 - MountPoints2\{995e5d2a-9786-11e0-913a-806d6172696f}\Shell\explore\Command - "" = D:\rwmvjxevlpcs.bat -- [2009.03.14 19:13:14 | 000,917,504 | RHS- | M] () O33 - MountPoints2\{995e5d2a-9786-11e0-913a-806d6172696f}\Shell\open\Command - "" = D:\zcqxjvapdf.bat -- [2009.07.16 19:19:48 | 000,917,504 | RHS- | M] () O33 - MountPoints2\{995e5d2b-9786-11e0-913a-806d6172696f}\Shell\AutoRun\command - "" = E:\pqchrber.bat -- [2009.03.20 01:10:06 | 000,917,504 | RHS- | M] () O33 - MountPoints2\{995e5d2b-9786-11e0-913a-806d6172696f}\Shell\explore\Command - "" = E:\rwmvjxevlpcs.bat -- [2011.06.17 08:39:35 | 000,917,504 | RHS- | M] () O33 - MountPoints2\{995e5d2b-9786-11e0-913a-806d6172696f}\Shell\open\Command - "" = E:\zcqxjvapdf.bat -- [2009.05.07 19:47:49 | 000,917,504 | RHS- | M] () O33 - MountPoints2\{995e5d2d-9786-11e0-913a-806d6172696f}\Shell\AutoRun\command - "" = C:\pqchrber.bat -- [2009.06.06 20:04:11 | 000,917,504 | RHS- | M] () O33 - MountPoints2\{995e5d2d-9786-11e0-913a-806d6172696f}\Shell\explore\Command - "" = C:\rwmvjxevlpcs.bat -- [2011.06.17 08:39:34 | 000,917,504 | RHS- | M] () O33 - MountPoints2\{995e5d2d-9786-11e0-913a-806d6172696f}\Shell\open\Command - "" = C:\zcqxjvapdf.bat -- [2009.05.17 18:18:41 | 000,917,504 | RHS- | M] () [2011.06.17 10:19:19 | 000,000,280 | -H-- | M] () -- C:\WINDOWS\tqyzflktbxckkulncvkofktkzp.uvb [2011.06.17 10:19:19 | 000,000,280 | -H-- | M] () -- C:\WINDOWS\System32\tqyzflktbxckkulncvkofktkzp.uvb [2011.06.17 10:19:19 | 000,000,280 | -H-- | M] () -- C:\Program Files\tqyzflktbxckkulncvkofktkzp.uvb [2011.06.17 10:19:19 | 000,000,280 | -H-- | M] () -- C:\Documents and Settings\YANEV\Local Settings\Application Data\tqyzflktbxckkulncvkofktkzp.uvb [2011.06.17 10:17:33 | 000,917,504 | RHS- | M] () -- C:\WINDOWS\zicphzkfzhyseadr.exe [2011.06.17 10:17:33 | 000,917,504 | RHS- | M] () -- C:\WINDOWS\tiibzxoppdaasudxepwsby.exe [2011.06.17 10:17:33 | 000,917,504 | RHS- | M] () -- C:\WINDOWS\pawlfzmjfpiesqvlov.exe [2011.06.17 10:17:33 | 000,917,504 | RHS- | M] () -- C:\WINDOWS\nayplhwvtfayoovnsbga.exe [2011.06.17 10:17:33 | 000,917,504 | RHS- | M] () -- C:\WINDOWS\gqlzslxtoxpkxuynp.exe [2011.06.17 10:17:33 | 000,917,504 | RHS- | M] () -- C:\WINDOWS\cqphebrrqdzypqyrxhniq.exe [2011.06.17 10:17:33 | 000,917,504 | RHS- | M] () -- C:\WINDOWS\amjzupdbyjdapoulpxb.exe [2011.06.17 08:39:34 | 000,917,504 | RHS- | M] () -- C:\rwmvjxevlpcs.bat [2011.06.17 08:39:34 | 000,000,814 | RHS- | M] () -- C:\autorun.inf [2011.06.17 08:38:37 | 000,917,504 | RHS- | M] () -- C:\WINDOWS\System32\tiibzxoppdaasudxepwsby.exe [2011.06.17 08:38:37 | 000,917,504 | RHS- | M] () -- C:\WINDOWS\System32\nayplhwvtfayoovnsbga.exe [2011.06.17 08:38:37 | 000,917,504 | RHS- | M] () -- C:\WINDOWS\System32\cqphebrrqdzypqyrxhniq.exe [2011.06.17 08:38:37 | 000,917,504 | RHS- | M] () -- C:\WINDOWS\System32\amjzupdbyjdapoulpxb.exe [2011.06.17 08:38:36 | 000,917,504 | RHS- | M] () -- C:\WINDOWS\System32\pawlfzmjfpiesqvlov.exe [2011.06.17 08:38:36 | 000,917,504 | RHS- | M] () -- C:\WINDOWS\System32\gqlzslxtoxpkxuynp.exe [2011.06.16 09:01:31 | 000,917,504 | RHS- | M] () -- C:\WINDOWS\System32\zicphzkfzhyseadr.exe [2011.06.15 20:12:23 | 000,004,248 | -H-- | M] () -- C:\WINDOWS\ucvhypztmtjcnikxxbbqsiceefngsjakexeun.tvi [2011.06.15 20:12:23 | 000,004,248 | -H-- | M] () -- C:\WINDOWS\System32\ucvhypztmtjcnikxxbbqsiceefngsjakexeun.tvi [2011.06.15 20:12:23 | 000,004,248 | -H-- | M] () -- C:\Program Files\ucvhypztmtjcnikxxbbqsiceefngsjakexeun.tvi [2011.06.15 20:12:23 | 000,004,248 | -H-- | M] () -- C:\Documents and Settings\YANEV\Local Settings\Application Data\ucvhypztmtjcnikxxbbqsiceefngsjakexeun.tvi [2011.06.16 11:25:14 | 000,000,072 | ---- | C] () -- C:\WINDOWS\System32\4357_Update32D.BAT [2011.06.16 11:25:14 | 000,000,072 | ---- | C] () -- C:\WINDOWS\System32\4357_Update32C.BAT [2011.06.16 11:25:14 | 000,000,072 | ---- | C] () -- C:\WINDOWS\System32\4328_Update32D.BAT [2011.06.16 11:25:14 | 000,000,072 | ---- | C] () -- C:\WINDOWS\System32\4328_Update32C.BAT [2011.06.16 11:25:14 | 000,000,072 | ---- | C] () -- C:\WINDOWS\System32\4318_0312_Update32D.BAT [2011.06.16 11:25:14 | 000,000,072 | ---- | C] () -- C:\WINDOWS\System32\4318_0312_Update32C.BAT [2011.06.16 11:25:14 | 000,000,072 | ---- | C] () -- C:\WINDOWS\System32\4318_0311_Update32D.BAT [2011.06.16 11:25:14 | 000,000,072 | ---- | C] () -- C:\WINDOWS\System32\4318_0311_Update32C.BAT [2011.06.16 11:25:14 | 000,000,072 | ---- | C] () -- C:\WINDOWS\System32\4315_Update32D.BAT [2011.06.16 11:25:14 | 000,000,072 | ---- | C] () -- C:\WINDOWS\System32\4315_Update32C.BAT [2011.06.16 11:25:14 | 000,000,072 | ---- | C] () -- C:\WINDOWS\System32\4312_Update32D.BAT [2011.06.16 11:25:14 | 000,000,072 | ---- | C] () -- C:\WINDOWS\System32\4312_Update32C.BAT [2011.06.16 11:25:14 | 000,000,072 | ---- | C] () -- C:\WINDOWS\System32\4311_Update32D.BAT [2011.06.16 11:25:14 | 000,000,072 | ---- | C] () -- C:\WINDOWS\System32\4311_Update32C.BAT [2011.06.16 11:25:14 | 000,000,061 | ---- | C] () -- C:\WINDOWS\System32\4357_Remove32D.BAT [2011.06.16 11:25:14 | 000,000,061 | ---- | C] () -- C:\WINDOWS\System32\4357_Remove32C.BAT [2011.06.16 11:25:14 | 000,000,061 | ---- | C] () -- C:\WINDOWS\System32\4328_Remove32D.BAT [2011.06.16 11:25:14 | 000,000,061 | ---- | C] () -- C:\WINDOWS\System32\4328_Remove32C.BAT [2011.06.16 11:25:14 | 000,000,061 | ---- | C] () -- C:\WINDOWS\System32\4318_0312_Remove32D.BAT [2011.06.16 11:25:14 | 000,000,061 | ---- | C] () -- C:\WINDOWS\System32\4318_0312_Remove32C.BAT [2011.06.16 11:25:14 | 000,000,061 | ---- | C] () -- C:\WINDOWS\System32\4318_0311_Remove32D.BAT [2011.06.16 11:25:14 | 000,000,061 | ---- | C] () -- C:\WINDOWS\System32\4318_0311_Remove32C.BAT [2011.06.16 11:25:14 | 000,000,061 | ---- | C] () -- C:\WINDOWS\System32\4315_Remove32D.BAT [2011.06.16 11:25:14 | 000,000,061 | ---- | C] () -- C:\WINDOWS\System32\4315_Remove32C.BAT [2011.06.16 11:25:14 | 000,000,061 | ---- | C] () -- C:\WINDOWS\System32\4312_Remove32D.BAT [2011.06.16 11:25:14 | 000,000,061 | ---- | C] () -- C:\WINDOWS\System32\4312_Remove32C.BAT [2011.06.16 11:25:14 | 000,000,061 | ---- | C] () -- C:\WINDOWS\System32\4311_Remove32D.BAT [2011.06.16 11:25:14 | 000,000,061 | ---- | C] () -- C:\WINDOWS\System32\4311_Remove32C.BAT [2011.06.15 20:51:32 | 000,000,814 | RHS- | C] () -- C:\autorun.inf [2011.06.15 20:12:23 | 000,004,248 | -H-- | C] () -- C:\WINDOWS\ucvhypztmtjcnikxxbbqsiceefngsjakexeun.tvi [2011.06.15 20:12:23 | 000,004,248 | -H-- | C] () -- C:\WINDOWS\System32\ucvhypztmtjcnikxxbbqsiceefngsjakexeun.tvi [2011.06.15 20:12:23 | 000,004,248 | -H-- | C] () -- C:\Program Files\ucvhypztmtjcnikxxbbqsiceefngsjakexeun.tvi [2011.06.15 20:12:23 | 000,004,248 | -H-- | C] () -- C:\Documents and Settings\YANEV\Local Settings\Application Data\ucvhypztmtjcnikxxbbqsiceefngsjakexeun.tvi [2011.06.15 20:12:23 | 000,000,280 | -H-- | C] () -- C:\WINDOWS\tqyzflktbxckkulncvkofktkzp.uvb [2011.06.15 20:12:23 | 000,000,280 | -H-- | C] () -- C:\WINDOWS\System32\tqyzflktbxckkulncvkofktkzp.uvb [2011.06.15 20:12:23 | 000,000,280 | -H-- | C] () -- C:\Program Files\tqyzflktbxckkulncvkofktkzp.uvb [2011.06.15 20:12:23 | 000,000,280 | -H-- | C] () -- C:\Documents and Settings\YANEV\Local Settings\Application Data\tqyzflktbxckkulncvkofktkzp.uvb [2011.06.15 20:12:13 | 000,917,504 | RHS- | C] () -- C:\WINDOWS\tiibzxoppdaasudxepwsby.exe [2011.06.15 20:12:13 | 000,917,504 | RHS- | C] () -- C:\WINDOWS\cqphebrrqdzypqyrxhniq.exe [2011.06.15 20:12:12 | 000,917,504 | RHS- | C] () -- C:\WINDOWS\zicphzkfzhyseadr.exe [2011.06.15 20:12:12 | 000,917,504 | RHS- | C] () -- C:\WINDOWS\pawlfzmjfpiesqvlov.exe [2011.06.15 20:12:12 | 000,917,504 | RHS- | C] () -- C:\WINDOWS\nayplhwvtfayoovnsbga.exe [2011.06.15 20:12:12 | 000,917,504 | RHS- | C] () -- C:\WINDOWS\gqlzslxtoxpkxuynp.exe [2011.06.15 20:12:12 | 000,917,504 | RHS- | C] () -- C:\WINDOWS\amjzupdbyjdapoulpxb.exe [2011.06.15 20:12:11 | 000,917,504 | RHS- | C] () -- C:\WINDOWS\System32\tiibzxoppdaasudxepwsby.exe [2011.06.15 20:12:11 | 000,917,504 | RHS- | C] () -- C:\WINDOWS\System32\pawlfzmjfpiesqvlov.exe [2011.06.15 20:12:11 | 000,917,504 | RHS- | C] () -- C:\WINDOWS\System32\nayplhwvtfayoovnsbga.exe [2011.06.15 20:12:11 | 000,917,504 | RHS- | C] () -- C:\WINDOWS\System32\gqlzslxtoxpkxuynp.exe [2011.06.15 20:12:11 | 000,917,504 | RHS- | C] () -- C:\WINDOWS\System32\cqphebrrqdzypqyrxhniq.exe [2011.06.15 20:12:11 | 000,917,504 | RHS- | C] () -- C:\WINDOWS\System32\amjzupdbyjdapoulpxb.exe [2011.06.15 20:12:10 | 000,917,504 | RHS- | C] () -- C:\WINDOWS\System32\zicphzkfzhyseadr.exe [2011.06.17 08:39:34 | 000,000,814 | RHS- | M] () -- C:\autorun.inf [2009.06.06 20:04:11 | 000,917,504 | RHS- | M] () -- C:\pqchrber.bat [2011.06.17 08:39:34 | 000,917,504 | RHS- | M] () -- C:\rwmvjxevlpcs.bat [2009.05.17 18:18:41 | 000,917,504 | RHS- | M] () -- C:\zcqxjvapdf.bat :Files C:\WINDOWS\*.tmp C:\WINDOWS\System32\*.tmp C:\WINDOWS\system32\zicphzkfzhyseadr.exe C:\Documents and Settings\YANEV\Local Settings\Temp\cajls.exe :Commands [emptytemp] [reboot]Ако маркираш текста ръчно, го копирай точно както е в полето. Внимавай да не изтървеш началното двуеточие и всяка команда да е на отделен ред, както е в полето. Кликни бутон Run Fix. Потвърди с OK на съобщението, че е нужен рестарт на системата. След рестарта ще се появи текстов дневник/лог. Същият файл се намира в C:\_OTL\MovedFiles. Моля, прикачи го към следващия си коментар. След това стартирай отново OTL, създай пресни дневници (както бях описал по-рано) и ги прикачи отново. Можеш да архивираш всичките файлове в един архив, а можеш и да ги прикачиш поотделно. Цитирай Link to comment Сподели другаде More sharing options...
syneok Публикувано Юни 17, 2011 Report Share Публикувано Юни 17, 2011 Да готово. Не мога да разбера как да прикача файлове тук във форума. Ориентирай ме моля те! Цитирай Link to comment Сподели другаде More sharing options...
Night_Raven Публикувано Юни 17, 2011 Report Share Публикувано Юни 17, 2011 Описание как се прикачат файлове:- кликни бутон Нов отговор;- долу в секция Прикрепени файлове посочи файла и кликни бутон Прикачи този файл;- накрая кликни Добавяне в мнението. Цитирай Link to comment Сподели другаде More sharing options...
syneok Публикувано Юни 17, 2011 Report Share Публикувано Юни 17, 2011 Ясно! Ето го.06172011_115048.rar Цитирай Link to comment Сподели другаде More sharing options...
Night_Raven Публикувано Юни 17, 2011 Report Share Публикувано Юни 17, 2011 Казах да направиш отново дневници и да ги прикачиш. Цитирай Link to comment Сподели другаде More sharing options...
syneok Публикувано Юни 17, 2011 Report Share Публикувано Юни 17, 2011 Ето пресният файл:OTL.Txt Цитирай Link to comment Сподели другаде More sharing options...
Night_Raven Публикувано Юни 17, 2011 Report Share Публикувано Юни 17, 2011 Стартирай отново OTL. В празното поле "Custom Scans/Fixes" (в долната част на програмата) постави следния текст (маркирай го или натисни бутон Избери всичко, натисни Ctrl+C и после в полето на OTL натисни Ctrl+V): :OTL O4 - HKLM..\Run: [cajls] File not found O4 - HKLM..\Run: [uynvivbrgjv] File not found O4 - HKCU..\Run: [cajls] File not found O4 - HKCU..\Run: [pqchrber] File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: aalpyhj = cqphebrrqdzypqyrxhniq.exe O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: tqyz = C:\DOCUME~1\YANEV\LOCALS~1\Temp\cqphebrrqdzypqyrxhniq.exe O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1 [2011.06.17 11:51:00 | 000,004,248 | -H-- | M] () -- C:\WINDOWS\ucvhypztmtjcnikxxbbqsiceefngsjakexeun.tvi [2011.06.17 11:51:00 | 000,004,248 | -H-- | M] () -- C:\WINDOWS\System32\ucvhypztmtjcnikxxbbqsiceefngsjakexeun.tvi [2011.06.17 11:51:00 | 000,004,248 | -H-- | M] () -- C:\Program Files\ucvhypztmtjcnikxxbbqsiceefngsjakexeun.tvi [2011.06.17 11:51:00 | 000,004,248 | -H-- | M] () -- C:\Documents and Settings\YANEV\Local Settings\Application Data\ucvhypztmtjcnikxxbbqsiceefngsjakexeun.tvi [2011.06.17 11:51:00 | 000,000,280 | -H-- | M] () -- C:\WINDOWS\tqyzflktbxckkulncvkofktkzp.uvb [2011.06.17 11:51:00 | 000,000,280 | -H-- | M] () -- C:\WINDOWS\System32\tqyzflktbxckkulncvkofktkzp.uvb [2011.06.17 11:51:00 | 000,000,280 | -H-- | M] () -- C:\Program Files\tqyzflktbxckkulncvkofktkzp.uvb [2011.06.17 11:51:00 | 000,000,280 | -H-- | M] () -- C:\Documents and Settings\YANEV\Local Settings\Application Data\tqyzflktbxckkulncvkofktkzp.uvb [2011.06.15 20:12:23 | 000,004,248 | -H-- | C] () -- C:\WINDOWS\ucvhypztmtjcnikxxbbqsiceefngsjakexeun.tvi [2011.06.15 20:12:23 | 000,004,248 | -H-- | C] () -- C:\WINDOWS\System32\ucvhypztmtjcnikxxbbqsiceefngsjakexeun.tvi [2011.06.15 20:12:23 | 000,004,248 | -H-- | C] () -- C:\Program Files\ucvhypztmtjcnikxxbbqsiceefngsjakexeun.tvi [2011.06.15 20:12:23 | 000,004,248 | -H-- | C] () -- C:\Documents and Settings\YANEV\Local Settings\Application Data\ucvhypztmtjcnikxxbbqsiceefngsjakexeun.tvi [2011.06.15 20:12:23 | 000,000,280 | -H-- | C] () -- C:\WINDOWS\tqyzflktbxckkulncvkofktkzp.uvb [2011.06.15 20:12:23 | 000,000,280 | -H-- | C] () -- C:\WINDOWS\System32\tqyzflktbxckkulncvkofktkzp.uvb [2011.06.15 20:12:23 | 000,000,280 | -H-- | C] () -- C:\Program Files\tqyzflktbxckkulncvkofktkzp.uvb [2011.06.15 20:12:23 | 000,000,280 | -H-- | C] () -- C:\Documents and Settings\YANEV\Local Settings\Application Data\tqyzflktbxckkulncvkofktkzp.uvb :Commands [emptytemp] [reboot]Ако маркираш текста ръчно, го копирай точно както е в полето. Внимавай да не изтървеш началното двуеточие и всяка команда да е на отделен ред, както е в полето. Кликни бутон Run Fix. Потвърди с OK на съобщението, че е нужен рестарт на системата. След рестарта ще се появи текстов дневник/лог. Същият файл се намира в C:\_OTL\MovedFiles. Моля, прикачи го към следващия си коментар. След това стартирай отново OTL, създай пресни дневници (както бях описал по-рано) и ги прикачи отново. Можеш да архивираш всичките файлове в един архив, а можеш и да ги прикачиш поотделно. И, моля, този път използвай инструкциите за създаване на дневници, които ти дадох първия път. Цитирай Link to comment Сподели другаде More sharing options...
syneok Публикувано Юни 17, 2011 Report Share Публикувано Юни 17, 2011 Ето и пресните файлове:06172011_133915.rar06172011_134626.rar Цитирай Link to comment Сподели другаде More sharing options...
Night_Raven Публикувано Юни 17, 2011 Report Share Публикувано Юни 17, 2011 Публикувай и пресен дневник. Цитирай Link to comment Сподели другаде More sharing options...
syneok Публикувано Юни 17, 2011 Report Share Публикувано Юни 17, 2011 Започнах да се обърквам вече. Нали последните които пуснах тук са пресни или аз се бъркам нещо? Цитирай Link to comment Сподели другаде More sharing options...
Night_Raven Публикувано Юни 17, 2011 Report Share Публикувано Юни 17, 2011 Те са информация за това как е протекъл процесът по почистване. На мен ми трябват нови пълни дневници, за да видя дали има останки/да не се върнала гадинката. Цитирай Link to comment Сподели другаде More sharing options...
syneok Публикувано Юни 17, 2011 Report Share Публикувано Юни 17, 2011 Аз между другото инсталирах AVG, ъпдейтнах я и сканирах за вируси. Нямаш си на представа колко съм ти благодарен за свършената работа!!! Ако мога да ти помогна с нешо...... Цитирай Link to comment Сподели другаде More sharing options...
Препоръчан пост
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.