b0nb0n4ence Публикувано Юли 26, 2011 Report Share Публикувано Юли 26, 2011 Амииии ето го файла. Онова за Clean up ми излезе само един прозорец сигурна ли съм, натиснах ДА и това беше, а функцията не е спряна вечеaswMBR2.txt Цитирай Link to comment Сподели другаде More sharing options...
B-boy/StyLe/ Публикувано Юли 26, 2011 Report Share Публикувано Юли 26, 2011 Спрете функцията по-описания по-назад начин... Сложете отметка пред "Turn off system restore on all drives" => Натиснете Apply. След това си инсталирайте някоя безплатна анвирусна програма по избор (като avast! 6.0.1203 или Avira AntiVir Personal 10.0.0.650, обновете им дефинициите и направете нова проверка за всеки случай. Изтрийте намерените паразити (ако антивирусната ви попита) и би трябвало да сме готови. Цитирай Link to comment Сподели другаде More sharing options...
FTotti Публикувано Юли 26, 2011 Report Share Публикувано Юли 26, 2011 Здравейте, надявам се този път да съм направил всичко според изискванията, като мисля, че е така, но все пак прилагам и един скрийншот на настройките на OTL. Знам, че сте обяснили всичко като за малоумни, но ей на - винаги ще се появи някой, който въпреки това е недоразбрал Иначе, ето резултатите (стискам палци - за последен път ) П.П Файлът "Extras" не ми излиза при всяко стартиране на програмата, качвам си все същия, който ми излезна първия път - надявам се - не е в това проблема.. Предварително благодаря OTL.TxtExtras.Txt Цитирай Link to comment Сподели другаде More sharing options...
b0nb0n4ence Публикувано Юли 26, 2011 Report Share Публикувано Юли 26, 2011 Аз съм готова А сега? Цитирай Link to comment Сподели другаде More sharing options...
B-boy/StyLe/ Публикувано Юли 26, 2011 Report Share Публикувано Юли 26, 2011 Аз съм готова А сега? Само да попитам, коя антивирусна избрахте, обновихте ли и дефинициите и сканирахте ли с нея ? И ако да, намери ли нещо ? След последното спиране на System Restore, той активирал ли се е пак сам ? Цитирай Link to comment Сподели другаде More sharing options...
Anastasiq Публикувано Юли 27, 2011 Report Share Публикувано Юли 27, 2011 Здравейте , От 2 дни лаптопа ми буквално се срина , не мога да влеза дори в интернет браузърите...Отначалото бях с антивирусна нортън , но тя изтече и докато се усетя да инсталирам нова компиютъра ми се напълни с вируси... Пробвах да ми пратят по скайпа антивирусна ,но като тръгна да я инсталирам все ми излизат разни ерори , грешки и др. Имам XP SECURIITY 2012 UNREGISTRED VERSION , която супер много ме изнервя, постоянно сканира и иска да я активирам , но срещу заплащане... Мислех да я махна ,но честно казано не смея да пипам нищоо вече :'( Наиситна много съжалявам за некомпетентността си , надявам се някой да ми помогне! Благодаря предварително!!! Цитирай Link to comment Сподели другаде More sharing options...
B-boy/StyLe/ Публикувано Юли 27, 2011 Report Share Публикувано Юли 27, 2011 Здраавейте anastasiq, Изтеглете http://www.sur-la-toile.com/RogueKiller/rendu2.png и го запазете на вашия десктоп. Стартирайте програмата и изберете 2. Натиснете Enter Ще се появи лог файл с името RKreport[1].txt на вашия десктоп. Копирайте съдържанието му в следващия си пост. Цитирай Link to comment Сподели другаде More sharing options...
Anastasiq Публикувано Юли 27, 2011 Report Share Публикувано Юли 27, 2011 Благодаря много за отговораааа и се извинявам , за забавянето , наистина не очаквах някой да се отзове толкова бързо ! обаче не мога да изтегля файла Цитирай Link to comment Сподели другаде More sharing options...
Night_Raven Публикувано Юли 27, 2011 Report Share Публикувано Юли 27, 2011 Линкът не беше коректен. Оправих го. Цитирай Link to comment Сподели другаде More sharing options...
FTotti Публикувано Юли 27, 2011 Report Share Публикувано Юли 27, 2011 Здравейте, надявам се този път да съм направил всичко според изискванията, като мисля, че е така, но все пак прилагам и един скрийншот на настройките на OTL. Знам, че сте обяснили всичко като за малоумни, но ей на - винаги ще се появи някой, който въпреки това е недоразбрал Иначе, ето резултатите (стискам палци - за последен път ) П.П Файлът "Extras" не ми излиза при всяко стартиране на програмата, качвам си все същия, който ми излезна първия път - надявам се - не е в това проблема.. Предварително благодаря Поствам го пак, ако случайно съм минал между капките Цитирай Link to comment Сподели другаде More sharing options...
Night_Raven Публикувано Юли 27, 2011 Report Share Публикувано Юли 27, 2011 Не, не си минал между капките. Просто чаках да забележиш, че не слагаш отметки на Company-Name WhiteList и Skip Microsoft Files. Цитирай Link to comment Сподели другаде More sharing options...
b0nb0n4ence Публикувано Юли 27, 2011 Report Share Публикувано Юли 27, 2011 Добро утро! Избрах Авира, сканирах и уж не намери нищо. А System Restore не се е активирало само Цитирай Link to comment Сподели другаде More sharing options...
Anastasiq Публикувано Юли 27, 2011 Report Share Публикувано Юли 27, 2011 Благодаря Night_Raven Ето логът от документа RogueKiller V5.2.8 [07/23/2011] by Tigzycontact at http://www.sur-la-toile.commail: tigzyRK<at>gmail<dot>comFeedback: http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits versionStarted in : Normal modeUser: Anastasiq [Admin rights]Mode: Remove -- Date : 07/27/2011 15:11:04 Bad processes: 167[sUSP PATH] 99knoj0.exe -- c:\documents and settings\anastasiq\application data\99knoj0.exe -> KILLED[sUSP PATH] mdm.exe -- c:\windows\mdm.exe -> KILLED[sVCHOST] svchost.exe -- c:\docume~1\anasta~1\locals~1\temp\ncdgdnx\svchost.exe -> KILLED[sUSP PATH] drweb.exe -- c:\windows\drweb.exe -> KILLED[sUSP PATH] services.exe -- c:\docume~1\anasta~1\locals~1\temp\services.exe -> KILLED[sUSP PATH] iexplarer.exe -- c:\windows\iexplarer.exe -> KILLED[sUSP PATH] login.exe -- c:\docume~1\anasta~1\locals~1\temp\login.exe -> KILLED[sUSP PATH] msmgm.exe -- c:\docume~1\anasta~1\locals~1\temp\msmgm.exe -> KILLED[sUSP PATH] win32.exe -- c:\windows\win32.exe -> KILLED[sUSP PATH] user.exe -- c:\docume~1\anasta~1\locals~1\temp\user.exe -> KILLED[sUSP PATH] hexdump.exe -- c:\docume~1\anasta~1\locals~1\temp\hexdump.exe -> KILLED[sUSP PATH] login.exe -- c:\windows\login.exe -> KILLED[sUSP PATH] system.exe -- c:\windows\system.exe -> KILLED[sUSP PATH] debug.exe -- c:\windows\debug.exe -> KILLED[sUSP PATH] spoolsv.exe -- c:\windows\spoolsv.exe -> KILLED[sUSP PATH] avp32.exe -- c:\docume~1\anasta~1\locals~1\temp\avp32.exe -> KILLED[sUSP PATH] services.exe -- c:\windows\services.exe -> KILLED[sUSP PATH] sysedit.exe -- c:\docume~1\anasta~1\locals~1\temp\sysedit.exe -> KILLED[sUSP PATH] aom.exe -- c:\documents and settings\anastasiq\local settings\application data\aom.exe -> KILLED[sUSP PATH] xbdh2.exe -- c:\docume~1\anasta~1\locals~1\temp\xbdh2.exe -> KILLED[sUSP PATH] avp.exe -- c:\docume~1\anasta~1\locals~1\temp\avp.exe -> KILLED[sUSP PATH] mdm.exe -- c:\docume~1\anasta~1\locals~1\temp\mdm.exe -> KILLED[sUSP PATH] iexplarer.exe -- c:\docume~1\anasta~1\locals~1\temp\iexplarer.exe -> KILLED[sUSP PATH] drweb.exe -- c:\docume~1\anasta~1\locals~1\temp\drweb.exe -> KILLED[sUSP PATH] winlogon.exe -- c:\windows\winlogon.exe -> KILLED[sUSP PATH] win.exe -- c:\docume~1\anasta~1\locals~1\temp\win.exe -> KILLED[sVCHOST] svchost.exe -- c:\windows\svchost.exe -> KILLED[sUSP PATH] smss.exe -- c:\docume~1\anasta~1\locals~1\temp\smss.exe -> KILLED[sUSP PATH] sysedit.exe -- c:\windows\sysedit.exe -> KILLED[sUSP PATH] install.exe -- c:\windows\install.exe -> KILLED[sUSP PATH] nvsvc32.exe -- c:\docume~1\anasta~1\locals~1\temp\nvsvc32.exe -> KILLED[sUSP PATH] sysmgm.exe -- c:\docume~1\anasta~1\locals~1\temp\sysmgm.exe -> KILLED[sUSP PATH] taskmgr.exe -- c:\docume~1\anasta~1\locals~1\temp\taskmgr.exe -> KILLED[sUSP PATH] avp.exe -- c:\windows\avp.exe -> KILLED[sUSP PATH] csrss.exe -- c:\windows\csrss.exe -> KILLED[sUSP PATH] taskmgr.exe -- c:\windows\taskmgr.exe -> KILLED[sUSP PATH] winamp.exe -- c:\windows\winamp.exe -> KILLED[sUSP PATH] sysedit.exe -- c:\windows\temp\sysedit.exe -> KILLED[sUSP PATH] csrss.exe -- c:\docume~1\anasta~1\locals~1\temp\csrss.exe -> KILLED[sUSP PATH] win16.exe -- c:\docume~1\anasta~1\locals~1\temp\win16.exe -> KILLED[sUSP PATH] sysmgm.exe -- c:\windows\sysmgm.exe -> KILLED[sUSP PATH] smss.exe -- c:\windows\temp\smss.exe -> KILLED[sUSP PATH] user.exe -- c:\windows\user.exe -> KILLED[sUSP PATH] gdi32.exe -- c:\docume~1\anasta~1\locals~1\temp\gdi32.exe -> KILLED[sUSP PATH] winlogon.exe -- c:\docume~1\anasta~1\locals~1\temp\winlogon.exe -> KILLED[sUSP PATH] avp.exe -- c:\windows\temp\avp.exe -> KILLED[sUSP PATH] nvsvc32.exe -- c:\windows\nvsvc32.exe -> KILLED[sUSP PATH] gdi32.exe -- c:\windows\gdi32.exe -> KILLED[sUSP PATH] winlogon.exe -- c:\windows\temp\winlogon.exe -> KILLED[sUSP PATH] login.exe -- c:\windows\temp\login.exe -> KILLED[sUSP PATH] services.exe -- c:\windows\temp\services.exe -> KILLED[sUSP PATH] debug.exe -- c:\docume~1\anasta~1\locals~1\temp\debug.exe -> KILLED[sUSP PATH] win.exe -- c:\windows\win.exe -> KILLED[sUSP PATH] wininst.exe -- c:\windows\wininst.exe -> KILLED[sUSP PATH] lsass.exe -- c:\windows\lsass.exe -> KILLED[sUSP PATH] hexdump.exe -- c:\windows\hexdump.exe -> KILLED[sUSP PATH] dxxsetup.exe -- c:\windows\dxxsetup.exe -> KILLED[sUSP PATH] avp32.exe -- c:\windows\avp32.exe -> KILLED[sUSP PATH] smss.exe -- c:\windows\smss.exe -> KILLED[sUSP PATH] msmgm.exe -- c:\windows\msmgm.exe -> KILLED[sUSP PATH] wininst.exe -- c:\docume~1\anasta~1\locals~1\temp\wininst.exe -> KILLED[sUSP PATH] spoolsv.exe -- c:\docume~1\anasta~1\locals~1\temp\spoolsv.exe -> KILLED[sUSP PATH] lsass.exe -- c:\docume~1\anasta~1\locals~1\temp\lsass.exe -> KILLED[sUSP PATH] install.exe -- c:\docume~1\anasta~1\locals~1\temp\install.exe -> KILLED[sUSP PATH] dxxsetup.exe -- c:\windows\temp\dxxsetup.exe -> KILLED[sUSP PATH] winamp.exe -- c:\docume~1\anasta~1\locals~1\temp\winamp.exe -> KILLED[sUSP PATH] manager.exe -- c:\documents and settings\anastasiq\application data\manager.exe -> KILLED[sUSP PATH] dxxsetup.exe -- c:\docume~1\anasta~1\locals~1\temp\dxxsetup.exe -> KILLED[sUSP PATH] lssas.exe -- c:\documents and settings\anastasiq\application data\lssas.exe -> KILLED[sUSP PATH] system.exe -- c:\docume~1\anasta~1\locals~1\temp\system.exe -> KILLED[sUSP PATH] setup.exe -- c:\windows\setup.exe -> KILLED[sVCHOST] svchost.exe -- c:\docume~1\anasta~1\locals~1\temp\svchost.exe -> KILLED[sUSP PATH] winamp.exe -- c:\windows\temp\winamp.exe -> KILLED[sUSP PATH] gdi32.exe -- c:\windows\temp\gdi32.exe -> KILLED[sUSP PATH] iexplarer.exe -- c:\windows\temp\iexplarer.exe -> KILLED[sUSP PATH] avp32.exe -- c:\windows\temp\avp32.exe -> KILLED[sUSP PATH] mdm.exe -- c:\windows\temp\mdm.exe -> KILLED[sUSP PATH] setup.exe -- c:\docume~1\anasta~1\locals~1\temp\setup.exe -> KILLED[sUSP PATH] spoolsv.exe -- c:\windows\temp\spoolsv.exe -> KILLED[sUSP PATH] spoolsv.exe -- c:\windows\spoolsv.exe -> KILLED[sUSP PATH] mdm.exe -- c:\windows\mdm.exe -> KILLED[sUSP PATH] drweb.exe -- c:\windows\drweb.exe -> KILLED[sUSP PATH] iexplarer.exe -- c:\windows\iexplarer.exe -> KILLED[sUSP PATH] hexdump.exe -- c:\docume~1\anasta~1\locals~1\temp\hexdump.exe -> KILLED[sUSP PATH] debug.exe -- c:\windows\debug.exe -> KILLED[sUSP PATH] win32.exe -- c:\windows\win32.exe -> KILLED[sUSP PATH] msmgm.exe -- c:\docume~1\anasta~1\locals~1\temp\msmgm.exe -> KILLED[sUSP PATH] services.exe -- c:\docume~1\anasta~1\locals~1\temp\services.exe -> KILLED[sUSP PATH] user.exe -- c:\docume~1\anasta~1\locals~1\temp\user.exe -> KILLED[sUSP PATH] system.exe -- c:\windows\system.exe -> KILLED[sUSP PATH] services.exe -- c:\windows\services.exe -> KILLED[sUSP PATH] login.exe -- c:\docume~1\anasta~1\locals~1\temp\login.exe -> KILLED[sUSP PATH] login.exe -- c:\windows\login.exe -> KILLED[sUSP PATH] sysedit.exe -- c:\docume~1\anasta~1\locals~1\temp\sysedit.exe -> KILLED[sUSP PATH] avp32.exe -- c:\docume~1\anasta~1\locals~1\temp\avp32.exe -> KILLED[sUSP PATH] taskmgr.exe -- c:\docume~1\anasta~1\locals~1\temp\taskmgr.exe -> KILLED[sVCHOST] svchost.exe -- c:\windows\svchost.exe -> KILLED[sUSP PATH] winlogon.exe -- c:\windows\winlogon.exe -> KILLED[sUSP PATH] sysedit.exe -- c:\windows\sysedit.exe -> KILLED[sUSP PATH] xbdh2.exe -- c:\docume~1\anasta~1\locals~1\temp\xbdh2.exe -> KILLED[sUSP PATH] install.exe -- c:\windows\install.exe -> KILLED[sUSP PATH] avp.exe -- c:\docume~1\anasta~1\locals~1\temp\avp.exe -> KILLED[sUSP PATH] mdm.exe -- c:\docume~1\anasta~1\locals~1\temp\mdm.exe -> KILLED[sUSP PATH] iexplarer.exe -- c:\docume~1\anasta~1\locals~1\temp\iexplarer.exe -> KILLED[sUSP PATH] avp.exe -- c:\windows\avp.exe -> KILLED[sUSP PATH] csrss.exe -- c:\windows\csrss.exe -> KILLED[sUSP PATH] win.exe -- c:\docume~1\anasta~1\locals~1\temp\win.exe -> KILLED[sUSP PATH] nvsvc32.exe -- c:\docume~1\anasta~1\locals~1\temp\nvsvc32.exe -> KILLED[sUSP PATH] drweb.exe -- c:\docume~1\anasta~1\locals~1\temp\drweb.exe -> KILLED[sUSP PATH] sysmgm.exe -- c:\docume~1\anasta~1\locals~1\temp\sysmgm.exe -> KILLED[sUSP PATH] smss.exe -- c:\docume~1\anasta~1\locals~1\temp\smss.exe -> KILLED[sUSP PATH] taskmgr.exe -- c:\windows\taskmgr.exe -> KILLED[sUSP PATH] win16.exe -- c:\docume~1\anasta~1\locals~1\temp\win16.exe -> KILLED[sUSP PATH] winamp.exe -- c:\windows\winamp.exe -> KILLED[sUSP PATH] csrss.exe -- c:\docume~1\anasta~1\locals~1\temp\csrss.exe -> KILLED[sUSP PATH] sysedit.exe -- c:\windows\temp\sysedit.exe -> KILLED[sUSP PATH] smss.exe -- c:\windows\temp\smss.exe -> KILLED[sUSP PATH] gdi32.exe -- c:\docume~1\anasta~1\locals~1\temp\gdi32.exe -> KILLED[sUSP PATH] nvsvc32.exe -- c:\windows\nvsvc32.exe -> KILLED[sUSP PATH] user.exe -- c:\windows\user.exe -> KILLED[sUSP PATH] sysmgm.exe -- c:\windows\sysmgm.exe -> KILLED[sUSP PATH] login.exe -- c:\windows\temp\login.exe -> KILLED[sUSP PATH] avp.exe -- c:\windows\temp\avp.exe -> KILLED[sUSP PATH] gdi32.exe -- c:\windows\gdi32.exe -> KILLED[sUSP PATH] winlogon.exe -- c:\windows\temp\winlogon.exe -> KILLED[sUSP PATH] setup.exe -- c:\windows\setup.exe -> KILLED[sUSP PATH] services.exe -- c:\windows\temp\services.exe -> KILLED[sUSP PATH] debug.exe -- c:\docume~1\anasta~1\locals~1\temp\debug.exe -> KILLED[sUSP PATH] wininst.exe -- c:\docume~1\anasta~1\locals~1\temp\wininst.exe -> KILLED[sUSP PATH] wininst.exe -- c:\windows\wininst.exe -> KILLED[sUSP PATH] lsass.exe -- c:\windows\lsass.exe -> KILLED[sUSP PATH] win.exe -- c:\windows\win.exe -> KILLED[sUSP PATH] hexdump.exe -- c:\windows\hexdump.exe -> KILLED[sUSP PATH] install.exe -- c:\docume~1\anasta~1\locals~1\temp\install.exe -> KILLED[sUSP PATH] msmgm.exe -- c:\windows\msmgm.exe -> KILLED[sUSP PATH] avp32.exe -- c:\windows\avp32.exe -> KILLED[sUSP PATH] dxxsetup.exe -- c:\windows\dxxsetup.exe -> KILLED[sUSP PATH] smss.exe -- c:\windows\smss.exe -> KILLED[sUSP PATH] lsass.exe -- c:\docume~1\anasta~1\locals~1\temp\lsass.exe -> KILLED[sUSP PATH] updates.exe -- c:\documents and settings\anastasiq\application data\updates\updates.exe -> KILLED[sUSP PATH] spoolsv.exe -- c:\docume~1\anasta~1\locals~1\temp\spoolsv.exe -> KILLED[sUSP PATH] winamp.exe -- c:\docume~1\anasta~1\locals~1\temp\winamp.exe -> KILLED[sUSP PATH] dxxsetup.exe -- c:\windows\temp\dxxsetup.exe -> KILLED[sUSP PATH] WMPRWISE.EXE -- c:\documents and settings\anastasiq\application data\wmprwise.exe -> KILLED[sUSP PATH] avp32.exe -- c:\windows\temp\avp32.exe -> KILLED[sUSP PATH] winlogon.exe -- c:\docume~1\anasta~1\locals~1\temp\winlogon.exe -> KILLED[sUSP PATH] iexplarer.exe -- c:\windows\temp\iexplarer.exe -> KILLED[sUSP PATH] dxxsetup.exe -- c:\docume~1\anasta~1\locals~1\temp\dxxsetup.exe -> KILLED[sVCHOST] svchost.exe -- c:\docume~1\anasta~1\locals~1\temp\svchost.exe -> KILLED[sUSP PATH] winamp.exe -- c:\windows\temp\winamp.exe -> KILLED[sUSP PATH] system.exe -- c:\docume~1\anasta~1\locals~1\temp\system.exe -> KILLED[sUSP PATH] gdi32.exe -- c:\windows\temp\gdi32.exe -> KILLED[sUSP PATH] mdm.exe -- c:\windows\temp\mdm.exe -> KILLED[sUSP PATH] spoolsv.exe -- c:\windows\temp\spoolsv.exe -> KILLED[sUSP PATH] setup.exe -- c:\docume~1\anasta~1\locals~1\temp\setup.exe -> KILLED[sUSP PATH] VRTF.tmp -- c:\windows\temp\vrtf.tmp -> KILLED[sUSP PATH] qtfcyyp.exe -- c:\windows\temp\qtfcyyp.exe -> KILLED[sUSP PATH] qtfcyyp.exe -- c:\windows\temp\qtfcyyp.exe -> KILLED[sUSP PATH] VRT14.tmp -- c:\windows\temp\vrt14.tmp -> KILLED[sVCHOST] svchost.exe -- c:\docume~1\anasta~1\locals~1\temp\ncdgdnx\svchost.exe -> KILLED[sVCHOST] svchost.exe -- c:\windows\system32\svchost.exe -> KILLED[sUSP PATH] VRT16.tmp -- c:\windows\temp\vrt16.tmp -> KILLED[sUSP PATH] etuj4wjebe.exe -- c:\windows\temp\etuj4wjebe.exe -> KILLED[sVCHOST] svchost.exe -- c:\windows\system32\svchost.exe -> KILLED[ROGUE ST] 968.exe -- c:\windows\system32\drivers\968.exe -> KILLED[sVCHOST] svchost.exe -- c:\windows\temp\svchost.exe -> KILLED[sUSP PATH] etuj4wjebe.exe -- c:\windows\temp\etuj4wjebe.exe -> KILLED Registry Entries: 172[ROGUE ST] HKCU\[...]\Run : 3034267048 (C:\Documents and Settings\Anastasiq\Local Settings\Application Data\aom.exe) -> DELETED[bLACKLIST Value] HKCU\[...]\Run : MKeuf (C:\WINDOWS\spoolsv.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : HNUIROXRotc (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\hexdump.exe) -> DELETED[bLACKLIST Value] HKCU\[...]\Run : MKcZ (C:\WINDOWS\mdm.exe) -> DELETED[bLACKLIST Value] HKCU\[...]\Run : MKasc (C:\WINDOWS\drweb.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : HNUIROXRptc (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\msmgm.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : HNUIROXRre (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\user.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : HNUIROXRrta (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\services.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : HNUIROXRprc (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\login.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : MKbuqc (C:\WINDOWS\iexplarer.exe) -> DELETED[bLACKLIST Value] HKCU\[...]\Run : MKfPc (C:\WINDOWS\win32.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : HNUIROXRrtc (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\sysedit.exe) -> DELETED[bLACKLIST Value] HKCU\[...]\Run : MKaoc (C:\WINDOWS\debug.exe) -> DELETED[bLACKLIST Value] HKCU\[...]\Run : MKexe (C:\WINDOWS\system.exe) -> DELETED[bLACKLIST Value] HKCU\[...]\Run : MKcrc (C:\WINDOWS\login.exe) -> DELETED[bLACKLIST Value] HKCU\[...]\Run : MKeta (C:\WINDOWS\services.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : HNUIROXRsYc (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\xbdh2.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : HNUIROXRmSc (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\avp32.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : HNUIROXRrrb (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\taskmgr.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : HNUIROXRme (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\avp.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : HNUIROXRpZ (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\mdm.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : HNUIROXRouqc (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\iexplarer.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : HNUIROXRnsc (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\drweb.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : HNUIROXRrg (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\smss.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : HNUIROXRsa (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\win.exe) -> DELETED[bLACKLIST Value] HKCU\[...]\Run : MKese (C:\WINDOWS\svchost.exe) -> DELETED[bLACKLIST Value] HKCU\[...]\Run : MKfsc (C:\WINDOWS\winlogon.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : HNUIROXRpw+ (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\nvsvc32.exe) -> DELETED[bLACKLIST Value] HKCU\[...]\Run : MKbta (C:\WINDOWS\install.exe) -> DELETED[bLACKLIST Value] HKCU\[...]\Run : MKetc (C:\WINDOWS\sysedit.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : HNUIROXRrwe (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\sysmgm.exe) -> DELETED[bLACKLIST Value] HKCU\[...]\Run : MKZe (C:\WINDOWS\avp.exe) -> DELETED[bLACKLIST Value] HKCU\[...]\Run : MKayc (C:\WINDOWS\csrss.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : HNUIROXRnyc (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\csrss.exe) -> DELETED[bLACKLIST Value] HKCU\[...]\Run : MKerb (C:\WINDOWS\taskmgr.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : HNUIROXRsPc (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\win16.exe) -> DELETED[bLACKLIST Value] HKCU\[...]\Run : MKfpe (C:\WINDOWS\winamp.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : HNUIROXRoMc (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\gdi32.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : MKWPxb (C:\WINDOWS\TEMP\sysedit.exe) -> DELETED[bLACKLIST Value] HKCU\[...]\Run : MKewe (C:\WINDOWS\sysmgm.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : MKWPxc (C:\WINDOWS\TEMP\smss.exe) -> DELETED[bLACKLIST Value] HKCU\[...]\Run : MKee (C:\WINDOWS\user.exe) -> DELETED[bLACKLIST Value] HKCU\[...]\Run : MKWPd (C:\WINDOWS\TEMP\avp.exe) -> DELETED[bLACKLIST Value] HKCU\[...]\Run : MKevc (C:\WINDOWS\setup.exe) -> DELETED[bLACKLIST Value] HKCU\[...]\Run : MKdw+ (C:\WINDOWS\nvsvc32.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : MKWPqe (C:\WINDOWS\TEMP\login.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : MKWPusc (C:\WINDOWS\TEMP\winlogon.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : MKWPwpc (C:\WINDOWS\TEMP\services.exe) -> DELETED[bLACKLIST Value] HKCU\[...]\Run : MKbMc (C:\WINDOWS\gdi32.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : HNUIROXRsre (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\wininst.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : HNUIROXRnoc (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\debug.exe) -> DELETED[bLACKLIST Value] HKCU\[...]\Run : MKcuc (C:\WINDOWS\lsass.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : HNUIROXRota (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\install.exe) -> DELETED[bLACKLIST Value] HKCU\[...]\Run : MKfre (C:\WINDOWS\wininst.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : HNUIROXRpuc (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\lsass.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : HNUIROXRspe (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\winamp.exe) -> DELETED[bLACKLIST Value] HKCU\[...]\Run : MKfa (C:\WINDOWS\win.exe) -> DELETED[bLACKLIST Value] HKCU\[...]\Run : MKbtc (C:\WINDOWS\hexdump.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : HNUIROXRruf (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\spoolsv.exe) -> DELETED[bLACKLIST Value] HKCU\[...]\Run : MKZSc (C:\WINDOWS\avp32.exe) -> DELETED[bLACKLIST Value] HKCU\[...]\Run : MKayh (C:\WINDOWS\dxxsetup.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : HNUIROXRssc (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\winlogon.exe) -> DELETED[bLACKLIST Value] HKCU\[...]\Run : MKctc (C:\WINDOWS\msmgm.exe) -> DELETED[bLACKLIST Value] HKCU\[...]\Run : MKeg (C:\WINDOWS\smss.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : HNUIROXRrse (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\svchost.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : HNUIROXRnyh (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\dxxsetup.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : engel (C:\Documents and Settings\Anastasiq\Application Data\updates\updates.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : HNUIROXRrvc (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\setup.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : Microsoft Firewall 2.9 (C:\Documents and Settings\Anastasiq\Application Data\WMPRWISE.EXE) -> DELETED[sUSP PATH] HKCU\[...]\Run : HNUIROXRrxe (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\system.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : MKWPxvc (C:\WINDOWS\TEMP\dxxsetup.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : MKWPrc (C:\WINDOWS\TEMP\winamp.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : MKWPtpf (C:\WINDOWS\TEMP\iexplarer.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : MKWPZP (C:\WINDOWS\TEMP\gdi32.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : MKWPeP (C:\WINDOWS\TEMP\avp32.exe) -> DELETED[bLACKLIST Value] HKCU\[...]\Run : MKWPb (C:\WINDOWS\TEMP\mdm.exe) -> DELETED[sUSP PATH] HKCU\[...]\Run : MKWPwg (C:\WINDOWS\TEMP\spoolsv.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : mslivemsn (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\ncdgdnx\svchost.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : mqfaf (C:\Documents and Settings\Anastasiq\Application Data\99knoj0.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : Local Account Service (C:\Documents and Settings\Anastasiq\Application Data\lssas.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : Plug Manager (C:\Documents and Settings\Anastasiq\Application Data\manager.exe) -> DELETED[bLACKLIST Value] HKLM\[...]\Run : MKeuf (C:\WINDOWS\spoolsv.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : HNUIROXRotc (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\hexdump.exe) -> DELETED[bLACKLIST Value] HKLM\[...]\Run : MKcZ (C:\WINDOWS\mdm.exe) -> DELETED[bLACKLIST Value] HKLM\[...]\Run : MKasc (C:\WINDOWS\drweb.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : HNUIROXRptc (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\msmgm.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : HNUIROXRre (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\user.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : HNUIROXRrta (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\services.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : HNUIROXRprc (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\login.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : MKbuqc (C:\WINDOWS\iexplarer.exe) -> DELETED[bLACKLIST Value] HKLM\[...]\Run : MKfPc (C:\WINDOWS\win32.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : HNUIROXRrtc (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\sysedit.exe) -> DELETED[bLACKLIST Value] HKLM\[...]\Run : MKaoc (C:\WINDOWS\debug.exe) -> DELETED[bLACKLIST Value] HKLM\[...]\Run : MKexe (C:\WINDOWS\system.exe) -> DELETED[bLACKLIST Value] HKLM\[...]\Run : MKcrc (C:\WINDOWS\login.exe) -> DELETED[bLACKLIST Value] HKLM\[...]\Run : MKeta (C:\WINDOWS\services.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : HNUIROXRsYc (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\xbdh2.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : HNUIROXRmSc (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\avp32.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : HNUIROXRrrb (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\taskmgr.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : HNUIROXRme (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\avp.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : HNUIROXRpZ (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\mdm.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : HNUIROXRouqc (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\iexplarer.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : HNUIROXRnsc (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\drweb.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : HNUIROXRrg (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\smss.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : HNUIROXRsa (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\win.exe) -> DELETED[bLACKLIST Value] HKLM\[...]\Run : MKese (C:\WINDOWS\svchost.exe) -> DELETED[bLACKLIST Value] HKLM\[...]\Run : MKfsc (C:\WINDOWS\winlogon.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : HNUIROXRpw+ (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\nvsvc32.exe) -> DELETED[bLACKLIST Value] HKLM\[...]\Run : MKbta (C:\WINDOWS\install.exe) -> DELETED[bLACKLIST Value] HKLM\[...]\Run : MKetc (C:\WINDOWS\sysedit.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : HNUIROXRrwe (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\sysmgm.exe) -> DELETED[bLACKLIST Value] HKLM\[...]\Run : MKZe (C:\WINDOWS\avp.exe) -> DELETED[bLACKLIST Value] HKLM\[...]\Run : MKayc (C:\WINDOWS\csrss.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : HNUIROXRnyc (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\csrss.exe) -> DELETED[bLACKLIST Value] HKLM\[...]\Run : MKerb (C:\WINDOWS\taskmgr.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : HNUIROXRsPc (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\win16.exe) -> DELETED[bLACKLIST Value] HKLM\[...]\Run : MKfpe (C:\WINDOWS\winamp.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : HNUIROXRoMc (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\gdi32.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : MKWPxb (C:\WINDOWS\TEMP\sysedit.exe) -> DELETED[bLACKLIST Value] HKLM\[...]\Run : MKewe (C:\WINDOWS\sysmgm.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : MKWPxc (C:\WINDOWS\TEMP\smss.exe) -> DELETED[bLACKLIST Value] HKLM\[...]\Run : MKee (C:\WINDOWS\user.exe) -> DELETED[bLACKLIST Value] HKLM\[...]\Run : MKWPd (C:\WINDOWS\TEMP\avp.exe) -> DELETED[bLACKLIST Value] HKLM\[...]\Run : MKevc (C:\WINDOWS\setup.exe) -> DELETED[bLACKLIST Value] HKLM\[...]\Run : MKdw+ (C:\WINDOWS\nvsvc32.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : MKWPqe (C:\WINDOWS\TEMP\login.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : MKWPusc (C:\WINDOWS\TEMP\winlogon.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : MKWPwpc (C:\WINDOWS\TEMP\services.exe) -> DELETED[bLACKLIST Value] HKLM\[...]\Run : MKbMc (C:\WINDOWS\gdi32.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : HNUIROXRsre (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\wininst.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : HNUIROXRnoc (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\debug.exe) -> DELETED[bLACKLIST Value] HKLM\[...]\Run : MKcuc (C:\WINDOWS\lsass.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : HNUIROXRota (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\install.exe) -> DELETED[bLACKLIST Value] HKLM\[...]\Run : MKfre (C:\WINDOWS\wininst.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : HNUIROXRpuc (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\lsass.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : HNUIROXRspe (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\winamp.exe) -> DELETED[bLACKLIST Value] HKLM\[...]\Run : MKfa (C:\WINDOWS\win.exe) -> DELETED[bLACKLIST Value] HKLM\[...]\Run : MKbtc (C:\WINDOWS\hexdump.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : HNUIROXRruf (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\spoolsv.exe) -> DELETED[bLACKLIST Value] HKLM\[...]\Run : MKZSc (C:\WINDOWS\avp32.exe) -> DELETED[bLACKLIST Value] HKLM\[...]\Run : MKayh (C:\WINDOWS\dxxsetup.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : HNUIROXRssc (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\winlogon.exe) -> DELETED[bLACKLIST Value] HKLM\[...]\Run : MKctc (C:\WINDOWS\msmgm.exe) -> DELETED[bLACKLIST Value] HKLM\[...]\Run : MKeg (C:\WINDOWS\smss.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : HNUIROXRrse (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\svchost.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : HNUIROXRnyh (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\dxxsetup.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : HNUIROXRrvc (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\setup.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : HNUIROXRrxe (C:\DOCUME~1\ANASTA~1\LOCALS~1\Temp\system.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : MKWPxvc (C:\WINDOWS\TEMP\dxxsetup.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : MKWPrc (C:\WINDOWS\TEMP\winamp.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : MKWPtpf (C:\WINDOWS\TEMP\iexplarer.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : MKWPZP (C:\WINDOWS\TEMP\gdi32.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : MKWPeP (C:\WINDOWS\TEMP\avp32.exe) -> DELETED[bLACKLIST Value] HKLM\[...]\Run : MKWPb (C:\WINDOWS\TEMP\mdm.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : MKWPwg (C:\WINDOWS\TEMP\spoolsv.exe) -> DELETED[sUSP PATH] HKLM\[...]\Run : smwcore (C:\WINDOWS\TEMP\VRT14.tmp) -> DELETED[] HKUS\[...]\Run : () -> ACCESS DENIED[] HKUS\[...]\Run : () -> ACCESS DENIED[sUSP PATH] HKLM\[...]\Run : 60xu9 (C:\WINDOWS\TEMP\qtfcyyp.exe) -> DELETED[bLACKLIST] HKLM\[...]\Winlogon : Userinit (C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,) -> REPLACED (C:\WINDOWS\system32\userinit.exe,)[HJPOL] HKCU\[...]\System : DisableRegistryTools (1) -> DELETED[HJPOL] HKCU\[...]\Explorer : NoFolderOptions (1) -> DELETED[HJ] HKLM\[...]\SystemRestore : DisableSR (1) -> REPLACED (0)[HJ] HKLM\[...]\Security Center : AntiVirusDisableNotify (1) -> REPLACED (0)[HJ] HKLM\[...]\Security Center : FirewallDisableNotify (1) -> REPLACED (0)[HJ] HKLM\[...]\Security Center : UpdatesDisableNotify (1) -> REPLACED (0)[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)[FILE ASSO] HKCU\[...]Software\Classes\.exe\shell\open\command : ("C:\Documents and Settings\Anastasiq\Local Settings\Application Data\aom.exe" -a "%1" %*) -> REPLACED : ("%1" %*)[FILE ASSO] HKCU\[...]Software\Classes\exefile\shell\open\command : ("C:\Documents and Settings\Anastasiq\Local Settings\Application Data\aom.exe" -a "%1" %*) -> REPLACED : ("%1" %*)[FILE ASSO] HKLM\[...]Software\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command : ("C:\Documents and Settings\Anastasiq\Local Settings\Application Data\aom.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe") -> REPLACED : ("C:\Program Files\mozilla firefox\firefox.exe")[FILE ASSO] HKLM\[...]Software\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command : ("C:\Documents and Settings\Anastasiq\Local Settings\Application Data\aom.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode) -> REPLACED : ("C:\Program Files\mozilla firefox\firefox.exe" -safe-mode)[FILE ASSO] HKLM\[...]Software\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command : ("C:\Documents and Settings\Anastasiq\Local Settings\Application Data\aom.exe" -a "C:\Program Files\Internet Explorer\iexplore.exe") -> REPLACED : ("C:\Program Files\internet explorer\iexplore.exe") HOSTS File:127.0.0.1 ZieF.pl127.0.0.1 localhost Finished : << RKreport[1].txt >>RKreport[1].txt Цитирай Link to comment Сподели другаде More sharing options...
FTotti Публикувано Юли 27, 2011 Report Share Публикувано Юли 27, 2011 Идеята, прикачвайки скрийншота беше, ако все пак съм допуснал грешка (което е много вероятно - както се и случи) - да ми обърнете внимание, за да се поправя. Сиреч - поради това не съм си я търсил сам, имайки предвид, че все още не знаех за съществуването й Иначе за отметките - смятах, че са напринципа "избери едно от трите", не съобразих, че са различни неща. За 10-ти път, тоя път няма да казвам, че се надявам всичко да ок, така или иначе поставих рекорд по бавно ориентиране OTL.Txt Цитирай Link to comment Сподели другаде More sharing options...
B-boy/StyLe/ Публикувано Юли 27, 2011 Report Share Публикувано Юли 27, 2011 Добро утро! Избрах Авира, сканирах и уж не намери нищо. А System Restore не се е активирало само Здравейте b0nb0n4ence, Супер...сега: 1. Отворете Start Menu => RUN => въведете командата Combofix /Uninstall (има празно място между Combofix и /Uninstall) => натиснете Enter . Това ще стартира Combofix отново и ще го деинсталира. Това ще изтрие всички файлове и папки асоциирани с инструмента. 2. Стартирайте OTL още веднъж и натиснете бутона CleanUp.http://i47.tinypic.com/35hfp21.jpgАко бъдете подканени да рестартирате, се съгласете. Изтрийте всички инструменти и логове на инструментите които сме използвали (и не са се изтрили след изпълнените досега процедури). Ако няма повече проблеми, мога да ви пожелая приятна вечер. Ако възникнат нови такива пишете отново. Безопасно сърфиране. Здравейте anastasiq, Добра работа...сега направете следното: Изтеглете Malwarebytes' Anti-Malware оттук и я инсталирайте.Стартирайте Malwarebytes' Anti-Malware и отидете на UPDATE и натиснете Check for updates.След това се върнете на Scanner изберете Perform QUICK Scan, след това кликнете на Scan.Сканирането ще отнеме малко време, затова моля бъдете търпеливи.Когато сканирането завърши, кликнете на OK, след това Show Results, за да видите резултата.Уверете се, че на всички редове има отметки, и кликнете Remove Selected.Когато всичко бъде премахнато, логът ще бъде отворен в Notepad. Копирайте лога и го публикувайте в следващия си коментар в темата. Забележка: Ако MalwareBytes' Anti-Malware се затрудни в премахването на откритите вируси/заплахи, той ще поиска да рестартира компютъра и по време на рестартирането да премахне проблемните вируси/заплахи. Ако бъдете попитани, потвърдете че желаете вашия компютър да бъде рестартиран. Моля, изтеглете aswMBR и го запазете на вашия десктоп.Кликнете с двоен клин на мишката върху файла aswMBR.exe за да го стартирате.Изчакайте да изтегли дефинициите на avast!От падащото меню посочете дял C: както е на снимката:http://img843.imageshack.us/img843/9021/unledyfm.pngИзберете Scan бутона, за да започне проверката.Когато проверката завърши, натиснете бутона save log, запазете съдържанието на лог файла на десктопа и публикувайте съдържанието му в следващия си коментар. Цитирай Link to comment Сподели другаде More sharing options...
Препоръчан пост
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.