B-boy/StyLe/ Публикувано Август 14, 2013 Report Share Публикувано Август 14, 2013 Здравейте, Дано не сте оплескали нещата при действията си на своя глава. 1. Изтеглете ComboFix от BleepingComputer и го запазете (бутон Save -> Save as) ComboFix на вашия десктоп:След приключване на изтеглянето на ComboFix, иконката на програмата би трябвало да изглежда така: Затворете всички работещи приложения, отворени прозорци и програми работещи във фонов режим. Спрете временно защитата в реално време на антивирусната програма и на другите програми за сигурност, ако има такива.3. Стартирайте с двоен клик Combofix.exe. Изберете YES, за да се съгласите с условията за използване на програмата. Важно: По време на работата на ComboFix не бива да се движи мишката и да се натискат клавиши от клавиатурата. Просто търпеливо оставете ComboFix да си свърши работата, без да използвате компютъра за други цели.4. ComboFix ще провери дали Windows Recovery Console e инсталиранa.*Ако Windows Recovery Console не е инсталирана, ще е необходимо да използвате YES за инсталация на Windows Recovery Console*Ако Windows Recovery Console е инсталирана, ComboFix ще продължи работата си.Забележка: Необходимо е да сте свързани към Интернет за да може Windows Recovery Console да се изтегли.След инсталация на Windows Recovery Console потвърдете с YES, за да продължите напред. Снимка: ComboFix ще спре временно Интернет връзката, но след като приключи работата на програмата тази връзка ще бъде възстановена автоматично. ComboFix ще сканира за проблеми и за заразени файлове, като това може да отнеме известно време. Моля да бъдете търпеливи. Ако има проблем с Интернет връзката след приключване на работата на Combofix, моля да прочетете това: Manually restoring the Internet connection section.6. След като работата на ComboFix приключи, компютъра ще се рестартира автоматично. След рестарта заредете отново в Safe Mode нарочно за да може Combofix да приключи своята работа. След това ще се появи текстов документ (log) в Notepad: 7. Копирайте лог файла в следващия си коментар. Цитирай Link to comment Сподели другаде More sharing options...
Matt_Ragan Публикувано Август 15, 2013 Author Report Share Публикувано Август 15, 2013 Благодаря ви за бързото отзоваване!Сигнах до т.3 вкл. и ми излезе съобщение:Warning!!ComboFix has detected the following real time scanner(s) to be active:antivirus:avast!Antivirus;antivirus:ESET Nod 32.Antivirus and intrusion prevention programs are known to interfere with ComboFix's running.This may lead to unpredictable results or possible machine damage.Please disable these scanners before clicking 'OK'.За ЕСЕТ незнаех как се спира в режим Safe Mode затова я деинсталирах,но avast въобще нямам на компютъра.Бях го деинсталирал преди с Revo Uninstaller.Проверих и сега.Рестартирах,тъй като ЕСЕТ искаше това,за да се конфигурират промените след деинсталацията.След рестарта повторих стъпките от т.3,но пак ми излезе съобщението по горе,сега само за avast.Какво да правя? Цитирай Link to comment Сподели другаде More sharing options...
B-boy/StyLe/ Публикувано Август 15, 2013 Report Share Публикувано Август 15, 2013 Игнорирайте съобщението и продължете нататък. Цитирай Link to comment Сподели другаде More sharing options...
Matt_Ragan Публикувано Август 15, 2013 Author Report Share Публикувано Август 15, 2013 дано не е станал някакъв гаф,но в т.6 изтървах времето за зареждане във safe mode и почна да ми се зарежда Windows.Спрях го и рестартирах във Safe Mod.Намерих лога в Notepad.Ето го:ComboFix 13-08-14.02 - zdrave 08.2013 г. 12:43:58.1.2 - x86 NETWORKMicrosoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.1919.1276 [GMT 3:00]Running from: C:\Documents and Settings\zdrave.CHANGEME1\Desktop\ComboFix.exeAV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}FW: avast! Antivirus *Enabled* {7591DB91-41F0-48A3-B128-1A293FD8233D} ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\Documents and Settings\All Users.WINDOWS.0\Application Data\pageC:\Documents and Settings\All Users.WINDOWS.0\Application Data\page\page.icoC:\Documents and Settings\All Users.WINDOWS.0\Application Data\page\page.URLC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMPC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\{8C20787A-7402-4FA7-BF25-6E5750930FDC}\PostBuild.exeC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}\PostBuild.exeC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}\Setup.exeC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\avgfinst.datC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\avi7.avgC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\crt_x64.msiC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\files.datC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\incavi.avmC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\license_cz.htmC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\license_da.htmC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\license_fr.htmC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\license_ge.htmC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\license_hu.htmC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\license_id.htmC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\license_in.htmC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\license_it.htmC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\license_jp.htmC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\license_ko.htmC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\license_ms.htmC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\license_nl.htmC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\license_pb.htmC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\license_pl.htmC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\license_pt.htmC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\license_ru.htmC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\license_sc.htmC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\license_sk.htmC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\license_sp.htmC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\license_tr.htmC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\license_us.htmC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\license_zh.htmC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\license_zt.htmC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\microavi.avgC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\miniavi.avgC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\setup.datC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\setup.exeC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\setup.iniC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\setupcz.lnsC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\setupda.lnsC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\setupfr.lnsC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\setupge.lnsC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\setuphu.lnsC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\setupid.lnsC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\setupin.lnsC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\setupit.lnsC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\setupjp.lnsC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\setupko.lnsC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\setupms.lnsC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\setupnl.lnsC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\setuppb.lnsC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\setuppl.lnsC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\setuppt.lnsC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\setupru.lnsC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\setupsc.lnsC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\setupsk.lnsC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\setupsp.lnsC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\setuptr.lnsC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\setupus.lnsC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\setupzh.lnsC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\setupzt.lnsC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\vcredis1.cabC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\AVG\vcredist.msiC:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP\RAIDTestC:\Documents and Settings\zdrave.CHANGEME1\Application Data\2YourFaceC:\Documents and Settings\zdrave.CHANGEME1\Application Data\2YourFace\2YourFace.crxC:\Documents and Settings\zdrave.CHANGEME1\Application Data\2YourFace\bho.dllC:\Documents and Settings\zdrave.CHANGEME1\Application Data\2YourFace\FF8Installer.exeC:\Documents and Settings\zdrave.CHANGEME1\Application Data\2YourFace\ffextension\chrome.manifestC:\Documents and Settings\zdrave.CHANGEME1\Application Data\2YourFace\ffextension\chrome\content\ff-overlay.jsC:\Documents and Settings\zdrave.CHANGEME1\Application Data\2YourFace\ffextension\chrome\content\ff-overlay.xulC:\Documents and Settings\zdrave.CHANGEME1\Application Data\2YourFace\ffextension\chrome\content\overlay.jsC:\Documents and Settings\zdrave.CHANGEME1\Application Data\2YourFace\ffextension\chrome\locale\en-US\overlay.dtdC:\Documents and Settings\zdrave.CHANGEME1\Application Data\2YourFace\ffextension\chrome\locale\en-US\overlay.propertiesC:\Documents and Settings\zdrave.CHANGEME1\Application Data\2YourFace\ffextension\chrome\skin\overlay.cssC:\Documents and Settings\zdrave.CHANGEME1\Application Data\2YourFace\ffextension\defaults\preferences\prefs.jsC:\Documents and Settings\zdrave.CHANGEME1\Application Data\2YourFace\ffextension\install.rdfC:\Documents and Settings\zdrave.CHANGEME1\Application Data\2YourFace\uninst.exeC:\Documents and Settings\zdrave.CHANGEME1\Application Data\2YourFace\Updater.exeC:\Documents and Settings\zdrave.CHANGEME1\Application Data\2YourFace\version.exeC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}C:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome.manifestC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\bar.jsC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\bar.xulC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\buttons.jsC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\constants.jsC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\events.jsC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\globals.jsC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\hosts.jsC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\init.jsC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\injection_button.jsC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\popups.jsC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\printerExternalAccessFF.jsC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\images\engine_images.pngC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\images\engine_maps.pngC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\images\engine_news.pngC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\images\engine_videos.pngC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\images\engine_web.pngC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\images\icon_amazon.pngC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\images\icon_ebay.pngC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\images\icon_facebook.pngC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\images\icon_games.pngC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\images\icon_msn.pngC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\images\icon_shopping.pngC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\images\icon_travel.pngC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\images\icon_twitter.pngC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\images\startnow_logo.pngC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\installer.xmlC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\skin\chevron_button.pngC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\skin\searchbox_button_hover.pngC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\skin\searchbox_button_normal.pngC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\skin\searchbox_dropdown_button_normal.pngC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\skin\searchbox_input_background.pngC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\skin\searchbox_input_left.pngC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\skin\searchbox_input_middle.pngC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\skin\separator.pngC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\skin\splitter.pngC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\skin\toolbarbutton_ff_hover_c.pngC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\skin\toolbarbutton_ie_hover_c.pngC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\skin\toolbarbutton_ie_hover_l.pngC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\skin\toolbarbutton_ie_hover_r.pngC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\skin\toolbarbutton_ie_normal_c.pngC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\skin\toolbarbutton_ie_normal_l.pngC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\skin\toolbarbutton_ie_normal_r.pngC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\toolbar.xmlC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\locale\en-US\{5911488E-9D1E-40ec-8CBB-06B231CC153F}.dtdC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\skin\overlay.cssC:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\install.rdfC:\Documents and Settings\zdrave.CHANGEME1\Application Data\PriceGongC:\Documents and Settings\zdrave.CHANGEME1\Application Data\PriceGong\Data\1.xmlC:\Documents and Settings\zdrave.CHANGEME1\Application Data\PriceGong\Data\a.xmlC:\Documents and Settings\zdrave.CHANGEME1\Application Data\PriceGong\Data\b.xmlC:\Documents and Settings\zdrave.CHANGEME1\Application Data\PriceGong\Data\c.xmlC:\Documents and Settings\zdrave.CHANGEME1\Application Data\PriceGong\Data\d.xmlC:\Documents and Settings\zdrave.CHANGEME1\Application Data\PriceGong\Data\e.xmlC:\Documents and Settings\zdrave.CHANGEME1\Application Data\PriceGong\Data\f.xmlC:\Documents and Settings\zdrave.CHANGEME1\Application Data\PriceGong\Data\g.xmlC:\Documents and Settings\zdrave.CHANGEME1\Application Data\PriceGong\Data\h.xmlC:\Documents and Settings\zdrave.CHANGEME1\Application Data\PriceGong\Data\i.xmlC:\Documents and Settings\zdrave.CHANGEME1\Application Data\PriceGong\Data\J.xmlC:\Documents and Settings\zdrave.CHANGEME1\Application Data\PriceGong\Data\k.xmlC:\Documents and Settings\zdrave.CHANGEME1\Application Data\PriceGong\Data\l.xmlC:\Documents and Settings\zdrave.CHANGEME1\Application Data\PriceGong\Data\m.xmlC:\Documents and Settings\zdrave.CHANGEME1\Application Data\PriceGong\Data\mru.xmlC:\Documents and Settings\zdrave.CHANGEME1\Application Data\PriceGong\Data\n.xmlC:\Documents and Settings\zdrave.CHANGEME1\Application Data\PriceGong\Data\o.xmlC:\Documents and Settings\zdrave.CHANGEME1\Application Data\PriceGong\Data\p.xmlC:\Documents and Settings\zdrave.CHANGEME1\Application Data\PriceGong\Data\q.xmlC:\Documents and Settings\zdrave.CHANGEME1\Application Data\PriceGong\Data\r.xmlC:\Documents and Settings\zdrave.CHANGEME1\Application Data\PriceGong\Data\s.xmlC:\Documents and Settings\zdrave.CHANGEME1\Application Data\PriceGong\Data\t.xmlC:\Documents and Settings\zdrave.CHANGEME1\Application Data\PriceGong\Data\u.xmlC:\Documents and Settings\zdrave.CHANGEME1\Application Data\PriceGong\Data\v.xmlC:\Documents and Settings\zdrave.CHANGEME1\Application Data\PriceGong\Data\w.xmlC:\Documents and Settings\zdrave.CHANGEME1\Application Data\PriceGong\Data\x.xmlC:\Documents and Settings\zdrave.CHANGEME1\Application Data\PriceGong\Data\y.xmlC:\Documents and Settings\zdrave.CHANGEME1\Application Data\PriceGong\Data\z.xmlC:\Documents and Settings\zdrave.CHANGEME1\WINDOWSC:\Documents and Settings\zdrave\WINDOWSC:\WINDOWS.0\system32\CacheC:\WINDOWS.0\system32\Cache\0249532664c4b901.fbC:\WINDOWS.0\system32\Cache\1a82451ff0bb88d0.fbC:\WINDOWS.0\system32\Cache\272512937d9e61a4.fbC:\WINDOWS.0\system32\Cache\287204568329e189.fbC:\WINDOWS.0\system32\Cache\28bc8f716fd76a47.fbC:\WINDOWS.0\system32\Cache\2c53092c95605355.fbC:\WINDOWS.0\system32\Cache\31a0997e9a5b5eb3.fbC:\WINDOWS.0\system32\Cache\31f8b5a9957f9677.fbC:\WINDOWS.0\system32\Cache\32c84fe32bb74d60.fbC:\WINDOWS.0\system32\Cache\3917078cb68ec657.fbC:\WINDOWS.0\system32\Cache\590ba23ce359fd0c.fbC:\WINDOWS.0\system32\Cache\610289e025a3ee9a.fbC:\WINDOWS.0\system32\Cache\651c5d3cdbfb8bd1.fbC:\WINDOWS.0\system32\Cache\6c59ac5e7e7a3ad0.fbC:\WINDOWS.0\system32\Cache\6d03dad1035885d3.fbC:\WINDOWS.0\system32\Cache\8296dd0a263312bb.fbC:\WINDOWS.0\system32\Cache\a8556537add6dfc5.fbC:\WINDOWS.0\system32\Cache\ad10a52aff5e038d.fbC:\WINDOWS.0\system32\Cache\bf7dacc822afac26.fbC:\WINDOWS.0\system32\Cache\c1fa887b03019701.fbC:\WINDOWS.0\system32\Cache\c4d28dca2e7648be.fbC:\WINDOWS.0\system32\Cache\d201ef9910cd39de.fbC:\WINDOWS.0\system32\Cache\d2e94710a5708128.fbC:\WINDOWS.0\system32\Cache\d4bdeb58e0ae7111.fbC:\WINDOWS.0\system32\Cache\d79b9dfe81484ec4.fbC:\WINDOWS.0\system32\Cache\e0de16f883bea794.fbC:\WINDOWS.0\system32\Cache\f20ce3db0bb97036.fbC:\WINDOWS.0\system32\Cache\f998975c9cc711ee.fbC:\WINDOWS.0\system32\embeddedC:\WINDOWS.0\system32\embedded\regsvr.exeC:\WINDOWS.0\XSxSD:\AUTORUN.INF ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))). -------\Legacy_K-------\Service_K ((((((((((((((((((((((((( Files Created from 2013-07-15 to 2013-08-15 ))))))))))))))))))))))))))))))) 2013-08-15 02:38:20 . 2013-08-15 02:38:33 -------- d-----w- C:\WINDOWS.0\LastGood.Tmp2013-08-14 13:17:53 . 2013-08-14 13:18:09 -------- d-----w- C:\Program Files\Malwarebytes' Anti-Malware2013-08-14 13:17:53 . 2013-04-04 11:50:32 22856 ----a-w- C:\WINDOWS.0\system32\drivers\mbam.sys2013-08-09 03:05:32 . 2013-08-09 03:05:32 -------- d-----w- C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Panda Security2013-08-09 03:05:21 . 2013-08-09 03:05:22 -------- d-----w- C:\Program Files\Panda USB Vaccine2013-08-08 08:35:34 . 2013-08-08 20:43:32 181064 ----a-w- C:\WINDOWS.0\PSEXESVC.EXE2013-08-08 08:04:20 . 2010-04-27 08:04:06 381816 ----a-w- C:\PsExec.exe2013-08-03 17:08:15 . 2013-08-03 17:08:15 -------- d-----w- C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Comodo2013-08-03 17:08:02 . 2013-08-03 17:08:02 -------- d-----w- C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Comodo Downloader2013-08-03 15:27:24 . 2013-08-14 18:24:07 40776 ----a-w- C:\WINDOWS.0\system32\drivers\mbamswissarmy.sys2013-08-03 14:25:08 . 2013-08-03 14:25:09 356408 ----a-w- C:\WINDOWS.0\system32\drivers\TrufosAlt.sys2013-08-02 05:32:44 . 2013-08-02 05:32:44 -------- d-----w- C:\Program Files\HitmanPro2013-08-02 05:31:34 . 2013-08-02 07:09:41 -------- d-----w- C:\Documents and Settings\All Users.WINDOWS.0\Application Data\HitmanPro2013-08-02 05:12:12 . 2013-08-02 05:13:40 -------- d-----w- C:\Documents and Settings\zdrave.CHANGEME1\Application Data\Web Cake2013-08-02 05:12:11 . 2013-08-02 05:13:39 -------- d-----w- C:\Program Files\Web Cake2013-08-02 05:12:06 . 2013-08-02 05:12:06 -------- d-----w- C:\Documents and Settings\zdrave.CHANGEME1\Local Settings\Application Data\Cool_Mirage2013-08-01 05:31:25 . 2013-08-01 05:31:25 -------- d-----w- C:\TDSSKiller_Quarantine2013-07-27 17:51:09 . 2013-07-27 17:51:31 -------- d-----w- C:\Program Files\Mozilla Maintenance Service2013-07-21 20:30:48 . 2013-07-21 20:31:15 -------- d-----w- C:\Documents and Settings\All Users.WINDOWS.0\Application Data\MCShield2013-07-21 20:30:47 . 2013-07-21 20:30:57 -------- d-----w- C:\Program Files\MCShield2013-07-21 18:54:35 . 2013-07-21 18:56:27 127899222 ----a-w- C:\руткит-бакъп на регистрите-21.07.2013.reg2013-07-20 19:49:22 . 2013-07-20 19:49:22 -------- d-----w- C:\Documents and Settings\zdrave.CHANGEME1\Application Data\Process Hacker 22013-07-20 19:44:15 . 2013-07-20 19:44:15 -------- d-----w- C:\Program Files\Process Hacker 22013-07-20 05:56:46 . 2013-07-20 05:56:46 -------- d-----w- C:\Documents and Settings\zdrave.CHANGEME1\Application Data\SUPERAntiSpyware.com2013-07-20 05:55:28 . 2013-08-12 05:10:46 -------- d-----w- C:\Program Files\SUPERAntiSpyware2013-07-20 05:55:28 . 2013-07-20 05:55:28 -------- d-----w- C:\Documents and Settings\All Users.WINDOWS.0\Application Data\SUPERAntiSpyware.com2013-07-19 19:35:01 . 2013-07-19 19:35:01 -------- d-----w- C:\Documents and Settings\zdrave.CHANGEME1\Local Settings\Application Data\ESET. (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2013-07-27 17:41:17 . 2013-01-24 20:42:58 692104 -c--a-w- C:\WINDOWS.0\system32\FlashPlayerApp.exe2013-07-27 17:41:16 . 2013-01-24 20:42:58 71048 -c--a-w- C:\WINDOWS.0\system32\FlashPlayerCPLApp.cpl2013-07-13 19:31:07 . 2013-03-16 13:46:46 175176 ----a-w- C:\WINDOWS.0\system32\drivers\aswVmm.sys2013-07-13 19:31:07 . 2012-12-02 13:24:08 369584 ----a-w- C:\WINDOWS.0\system32\drivers\aswSP.sys2013-07-13 19:31:07 . 2012-12-02 13:24:01 770344 ----a-w- C:\WINDOWS.0\system32\drivers\aswSnx.sys2013-07-06 16:56:27 . 2013-01-03 18:25:35 256904 -c--a-w- C:\WINDOWS.0\system32\drivers\tmcomm.sys2013-07-04 22:02:06 . 2013-07-04 22:01:54 22064 ----a-w- C:\WINDOWS.0\DCEBoot.exe2013-07-04 22:02:06 . 2013-07-04 22:01:54 181808 ----a-w- C:\WINDOWS.0\RegBootClean.exe2013-06-07 21:56:06 . 2009-11-05 12:54:33 920064 ----a-w- C:\WINDOWS.0\system32\wininet.dll2013-06-07 21:56:06 . 2009-11-05 12:53:55 43520 ----a-w- C:\WINDOWS.0\system32\licmgr10.dll2013-06-07 21:56:05 . 2009-11-05 12:54:28 1469440 ----a-w- C:\WINDOWS.0\system32\inetcpl.cpl2013-06-07 20:55:44 . 2009-11-05 12:53:51 385024 ----a-w- C:\WINDOWS.0\system32\html.iec2013-06-04 07:23:02 . 2008-04-14 11:00:00 562688 ----a-w- C:\WINDOWS.0\system32\qedit.dll2013-06-04 01:40:45 . 2009-11-10 16:54:13 1876736 ----a-w- C:\WINDOWS.0\system32\win32k.sys2010-06-02 03:22:02 . 2010-06-02 03:22:02 537432 -c--a-w- C:\Program Files\DXSETUP.exe ------- Sigcheck -------Note: Unsigned files aren't necessarily malware. [-] 2009-11-05 13:35:09 . 600D58665D16BFBB776EFEFB0E80532D . 1614848 . . [5.1.2600.5512 (xpsp.080413-2111)] . . C:\WINDOWS.0\system32\sfcfiles.dll ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]2013-06-06 20:57:26 578512 ----a-w- C:\Program Files\Google\Drive\googledrivesync32.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]2013-06-06 20:57:26 578512 ----a-w- C:\Program Files\Google\Drive\googledrivesync32.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]2013-06-06 20:57:26 578512 ----a-w- C:\Program Files\Google\Drive\googledrivesync32.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]2013-06-06 20:57:26 578512 ----a-w- C:\Program Files\Google\Drive\googledrivesync32.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]2013-06-06 20:57:26 578512 ----a-w- C:\Program Files\Google\Drive\googledrivesync32.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]2013-06-06 20:57:26 578512 ----a-w- C:\Program Files\Google\Drive\googledrivesync32.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"uTorrent"="C:\Program Files\uTorrent\uTorrent.exe" [2013-05-02 04:12:34 802136]"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2013-06-03 13:27:20 19603048]"KiesPreload"="C:\Program Files\Samsung\Kies\Kies.exe" [2013-05-23 06:16:52 1561968]"GoogleDriveSync"="C:\Program Files\Google\Drive\googledrivesync.exe" [2013-06-06 20:57:24 19676256]"MCShield Monitor"="C:\Program Files\MCShield\mcshieldrtm.exe" [2013-07-15 20:07:06 607744]"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2013-05-15 01:08:19 4760816] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"Wireless Console 2"="C:\Program Files\Wireless Console 2\wcourier.exe" [2007-07-05 15:53:44 1040384]"Power_Gear"="C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe" [2006-07-26 17:01:06 90112]"VirtualCloneDrive"="C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-06-17 11:44:11 85160]"RTHDCPL"="RTHDCPL.EXE" [2011-10-14 15:58:12 20064872]"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2011-03-31 16:30:48 2221352]"VolumeTray"="C:\Program Files\VolumeTray\VolumeTray.exe" [2003-02-19 05:45:08 180224]"OODefragTray"="C:\Program Files\OO Software\Defrag\oodtray.exe" [2013-04-19 15:09:16 5039408]"KiesTrayAgent"="C:\Program Files\Samsung\Kies\KiesTrayAgent.exe" [2013-05-23 06:16:56 311152]"Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 21:06:36 958576]"DivXMediaServer"="C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe" [2013-04-15 15:53:18 450560] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]"Malwarebytes Anti-Malware"="C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" [2013-04-04 11:50:32 532040] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]"CTFMON.EXE"="C:\WINDOWS.0\system32\CTFMON.EXE" [2008-04-14 11:00:00 15360] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]"ShowDeskFix"="shell32" [X]"IE8"="advpack.dll" [2009-11-05 12:53:50 128512] C:\Documents and Settings\zdrave.CHANGEME1\Start Menu\Programs\Startup\PandaUSBVaccine.lnk - C:\Program Files\Panda USB Vaccine\USBVaccine.exe /resident /hidetray /autovaccinate /experimentalntfs /agreelicense [2013-8-9 1287176] C:\Documents and Settings\All Users.WINDOWS.0\Start Menu\Programs\Startup\O&O Defrag Tray.lnk - C:\WINDOWS.0\Installer\{D66100D4-640B-4AAC-82BA-0B6444FBA064}\DefragIcon.exe [2013-5-22 292878] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]"NoResolveTrack"= 1 (0x1) [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2013-05-07 22:36:36 115440] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]@="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]@="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]@="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37Crusader]@="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37CrusaderBoot]@="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]@="Driver" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]2013-02-13 02:37:16 1263952 ----a-w- C:\Program Files\DivX\DivX Update\DivXUpdate.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]"DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]"DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]"DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]"EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\system32\\sessmgr.exe"="D:\\Office12\\OUTLOOK.EXE"="D:\\Office12\\GROOVE.EXE"="D:\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\EA Games\\Need For Speed Hot Pursuit 2\\NfsHP2.ori"="C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\CyberLink\\PowerDVD10\\PowerDVD10.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\PANDORA.TV\\PanService\\PanProcess.exe"="C:\\Program Files\\PANDORA.TV\\PanService\\PandoraService.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]"1277:TCP"= 1277:TCP:messenger R0 aswKbd;aswKbd;C:\WINDOWS.0\system32\drivers\aswKbd.sys [18.12.2012 г. 08:08:54 21576]R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore.exe [23.5.2013 г. 23:11:42 119056]S0 10793436;10793436;C:\WINDOWS.0\system32\drivers\33345492.sys --> C:\WINDOWS.0\system32\drivers\33345492.sys [?]S0 aswRvrt;aswRvrt;C:\WINDOWS.0\system32\drivers\aswRvrt.sys [16.3.2013 г. 16:46:45 49376]S0 aswVmm;aswVmm;C:\WINDOWS.0\system32\drivers\aswVmm.sys [16.3.2013 г. 16:46:46 175176]S0 hitmanpro37duringboot;hitmanpro37duringboot;C:\WINDOWS.0\system32\drivers\hitmanpro37.sys --> C:\WINDOWS.0\system32\drivers\hitmanpro37.sys [?]S1 aswSnx;aswSnx;C:\WINDOWS.0\system32\drivers\aswSnx.sys [02.12.2012 г. 16:24:01 770344]S1 aswSP;aswSP;C:\WINDOWS.0\system32\drivers\aswSP.sys [02.12.2012 г. 16:24:08 369584]S1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv.sys [22.7.2011 г. 19:27:02 12880]S1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [13.7.2011 г. 00:55:22 67664]S2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2012/05/27 00:27:15];C:\Program Files\CyberLink\PowerDVD10\NavFilter\000.fcl [15.8.2012 г. 21:41:18 87536]S2 aswFsBlk;aswFsBlk;C:\WINDOWS.0\system32\drivers\aswFsBlk.sys [02.12.2012 г. 16:24:08 29816]S2 aswMonFlt;aswMonFlt;C:\WINDOWS.0\system32\drivers\aswMonFlt.sys [16.3.2013 г. 16:46:43 66336]S2 gupdate;Услуга Google Update (gupdate);C:\Program Files\Google\Update\GoogleUpdate.exe [07.3.2010 г. 01:55:04 135664]S2 HitmanProScheduler;HitmanPro Scheduler;C:\Program Files\HitmanPro\hmpsched.exe [02.8.2013 г. 08:32:44 106280]S2 LBeepKE;Logitech Beep Suppression Driver;C:\WINDOWS.0\system32\drivers\LBeepKE.sys [06.12.2012 г. 10:37:06 12184]S2 OODefragAgent;O&O Defrag;C:\Program Files\OO Software\Defrag\oodag.exe [19.4.2013 г. 18:09:10 2034480]S2 PanService;PandoraService;C:\Program Files\PANDORA.TV\PanService\PandoraService.exe [04.2.2013 г. 23:48:02 625304]S2 Skype C2C Service;Skype C2C Service;C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe [14.5.2013 г. 13:26:12 3289208]S2 SkypeUpdate;Skype Updater;C:\Program Files\Skype\Updater\Updater.exe [03.6.2013 г. 16:21:54 162408]S2 WebCakeUpdater;WebCakeUpdater;C:\Program Files\Web Cake\WebCakeDesktop.Updater.exe [02.8.2013 г. 08:12:13 51992]S3 Ambfilt;Ambfilt;C:\WINDOWS.0\system32\drivers\Ambfilt.sys [06.4.2011 г. 18:30:08 1691480]S3 BPNOFQ;BPNOFQ;C:\DOCUME~1\ZDRAVE~1.CHA\LOCALS~1\Temp\BPNOFQ.exe --> C:\DOCUME~1\ZDRAVE~1.CHA\LOCALS~1\Temp\BPNOFQ.exe [?]S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);C:\WINDOWS.0\system32\drivers\ssudbus.sys [25.4.2013 г. 07:41:07 83864]S3 dgderdrv;dgderdrv;C:\WINDOWS.0\system32\drivers\dgderdrv.sys [10.3.2013 г. 23:00:36 20032]S3 esgiguard;esgiguard;\??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys --> C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [?]S3 FUPYPF;FUPYPF;C:\DOCUME~1\ZDRAVE~1.CHA\LOCALS~1\Temp\FUPYPF.exe --> C:\DOCUME~1\ZDRAVE~1.CHA\LOCALS~1\Temp\FUPYPF.exe [?]S3 GGV;GGV;C:\DOCUME~1\ZDRAVE~1.CHA\LOCALS~1\Temp\GGV.exe --> C:\DOCUME~1\ZDRAVE~1.CHA\LOCALS~1\Temp\GGV.exe [?]S3 gupdatem;Услуга на Google Актуализация (gupdatem);C:\Program Files\Google\Update\GoogleUpdate.exe [07.3.2010 г. 01:55:04 135664]S3 MBAMSwissArmy;MBAMSwissArmy;C:\WINDOWS.0\system32\drivers\mbamswissarmy.sys [03.8.2013 г. 18:27:24 40776]S3 RDZYD;RDZYD;C:\DOCUME~1\ZDRAVE~1.CHA\LOCALS~1\Temp\RDZYD.exe --> C:\DOCUME~1\ZDRAVE~1.CHA\LOCALS~1\Temp\RDZYD.exe [?]S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);C:\WINDOWS.0\system32\drivers\ssudmdm.sys [25.4.2013 г. 07:41:11 181912]S3 ssudserd;SAMSUNG Mobile USB Diagnostic Serial Port(DEVGURU Ver.);C:\WINDOWS.0\system32\drivers\ssudserd.sys [25.4.2013 г. 07:41:21 181912]S3 SWDUMon;SWDUMon;C:\WINDOWS.0\system32\drivers\SWDUMon.sys [03.4.2011 г. 13:32:34 12984]S3 TOWYFF;TOWYFF;C:\DOCUME~1\ZDRAVE~1.CHA\LOCALS~1\Temp\TOWYFF.exe --> C:\DOCUME~1\ZDRAVE~1.CHA\LOCALS~1\Temp\TOWYFF.exe [?]S3 TrufosAlt;TrufosAlt;C:\WINDOWS.0\system32\drivers\TrufosAlt.sys [03.8.2013 г. 17:25:08 356408]S3 UNOQ;UNOQ;C:\DOCUME~1\ZDRAVE~1.CHA\LOCALS~1\Temp\UNOQ.exe --> C:\DOCUME~1\ZDRAVE~1.CHA\LOCALS~1\Temp\UNOQ.exe [?]S3 XPXWAZJ;XPXWAZJ;C:\DOCUME~1\ZDRAVE~1.CHA\LOCALS~1\Temp\XPXWAZJ.exe --> C:\DOCUME~1\ZDRAVE~1.CHA\LOCALS~1\Temp\XPXWAZJ.exe [?]S4 AdvancedSystemCareService5;Advanced SystemCare Service 5;C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe --> C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe [?]S4 avgtp;avgtp;C:\WINDOWS.0\system32\drivers\avgtpx86.sys [13.8.2012 г. 17:57:18 26984]S4 cpuz136;cpuz136;\??\C:\WINDOWS.0\TEMP\cpuz136\cpuz136_x32.sys --> C:\WINDOWS.0\TEMP\cpuz136\cpuz136_x32.sys [?]S4 DKRtWrt;DKRtWrt;C:\WINDOWS.0\system32\drivers\DKRtWrt.sys [16.7.2012 г. 13:06:48 38608]S4 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;"C:\Program Files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe" --> C:\Program Files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [?]S4 Roxio Upnp Server 10;Roxio Upnp Server 10;"C:\Program Files\Roxio\Digital Home 10\RoxioUpnpService10.exe" --> C:\Program Files\Roxio\Digital Home 10\RoxioUpnpService10.exe [?]S4 RoxLiveShare10;LiveShare P2P Server 10;C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe [24.8.2007 г. 15:52:48 309744]S4 RoxMediaDB10;RoxMediaDB10;C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [24.8.2007 г. 15:52:38 1083888]S4 RoxWatch10;Roxio Hard Drive Watcher 10;C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe [24.8.2007 г. 15:52:46 166384]S4 SessionLauncher;SessionLauncher;C:\DOCUME~1\ZDRAVE~1.CHA\LOCALS~1\Temp\DX9\SessionLauncher.exe --> C:\DOCUME~1\ZDRAVE~1.CHA\LOCALS~1\Temp\DX9\SessionLauncher.exe [?] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]2013-07-19 08:10:23 1173456 ----a-w- C:\Program Files\Google\Chrome\Application\28.0.1500.72\Installer\chrmstp.exe Contents of the 'Scheduled Tasks' folder 2013-07-19 C:\WINDOWS.0\Tasks\GoogleUpdateTaskMachineCore.job- C:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-06 22:55:04 . 2010-03-06 22:54:56] 2013-07-19 C:\WINDOWS.0\Tasks\GoogleUpdateTaskMachineUA.job- C:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-06 22:55:04 . 2010-03-06 22:54:56] ------- Supplementary Scan ------- uStart Page = hxxp:// Page = hxxp:// Settings,ProxyOverride = <local>IE: &Експортиране към Microsoft Excel - D:\Office12\EXCEL.EXE/3000DPF: {70B410C0-11D4-BADA-8308-0080C8D7ED4A} - hxxp:// - ProfilePath - C:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\FF - prefs.js: - hxxp://{searchTerms}FF - ExtSQL: 2013-06-26 20:40;; C:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\ - ExtSQL: 2013-08-02 08:12;; C:\Documents and Settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\plugin@getwebcake.comuser_pref('extensions.autoDisableScopes', 0);user_pref('security.csp.enable', false);user_pref('security.OCSP.enabled', 0);FF - user.js: extensions.funmoods.hmpg - trueFF - user.js: extensions.funmoods.hmpgUrl - hxxp:// - user.js: extensions.funmoods.dfltSrch - trueFF - user.js: extensions.funmoods.srchPrvdr - SearchFF - user.js: extensions.funmoods.dnsErr - trueFF - user.js: extensions.funmoods_i.newTab - trueFF - user.js: extensions.funmoods.newTabUrl - hxxp:// - user.js: extensions.funmoods.tlbrSrchUrl - hxxp:// - user.js: - 00FF09E3136146E0FF - user.js: extensions.funmoods.instlDay - 15604FF - user.js: extensions.funmoods.vrsn - - user.js: extensions.funmoods.vrsni - - user.js: extensions.funmoods_i.vrsnTs - - user.js: extensions.funmoods.prtnrId - funmoodsFF - user.js: extensions.funmoods.prdct - funmoodsFF - user.js: extensions.funmoods.aflt - nv1FF - user.js: extensions.funmoods_i.smplGrp - noneFF - user.js: extensions.funmoods.tlbrId - baseFF - user.js: extensions.funmoods.instlRef - nv1FF - user.js: extensions.funmoods.dfltLng - FF - user.js: extensions.funmoods.excTlbr - falseFF - user.js: extensions.funmoods.autoRvrt - falseFF - user.js: extensions.funmoods.envrmnt - productionFF - user.js: extensions.funmoods.isdcmntcmplt - trueFF - user.js: extensions.funmoods.mntrvrsn - 1.3.0FF - user.js: extentions.y2layers.installId - 25d6df24-2b28-4838-991c-8a96bbecf796FF - user.js: extentions.y2layers.defaultEnableAppsList - twittube,ezLooker,pagerage,buzzdock,toprelatedtopics,YontooNewOffersFF - user.js: extensions.autoDisableScopes - 14FF - user.js: extensions.BabylonToolbar.autoRvrt - falseFF - user.js: extensions.BabylonToolbar_i.newTab - falseFF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp:// - user.js: - 480846e00000000000000015afae718fFF - user.js: extensions.BabylonToolbar.appId - {BDB69379-802F-4eaf-B541-F8DE92DD98DB}FF - user.js: extensions.BabylonToolbar.instlDay - 15627FF - user.js: extensions.BabylonToolbar.vrsn - - user.js: extensions.BabylonToolbar.vrsni - - user.js: extensions.BabylonToolbar_i.vrsnTs - - user.js: extensions.BabylonToolbar.prtnrId - babylonFF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbarFF - user.js: extensions.BabylonToolbar.aflt - babsstFF - user.js: extensions.BabylonToolbar_i.smplGrp - noneFF - user.js: extensions.BabylonToolbar.tlbrId - baseFF - user.js: extensions.BabylonToolbar.instlRef - sstFF - user.js: extensions.BabylonToolbar.dfltLng - enFF - user.js: extensions.BabylonToolbar.excTlbr - falseFF - user.js: extensions.BabylonToolbar.admin - falseFF - user.js: extensions.BabylonToolbar_i.babTrack - affID=116775&tt=101012_24_4112_2FF - user.js: extensions.BabylonToolbar_i.babExt - FF - user.js: extensions.BabylonToolbar_i.srcExt - ssFF - user.js: network.http.pipelining.maxrequests - 8FF - user.js: network.http.request.max-start-delay - 0FF - user.js: network.http.max-connections - 48FF - user.js: network.http.max-connections-per-server - 16FF - user.js: network.http.max-persistent-connections-per-proxy - 16FF - user.js: network.http.max-persistent-connections-per-server - 8FF - user.js: browser.turbo.enabled - trueFF - user.js: browser.display.show_image_placeholders - trueFF - user.js: - falseFF - user.js: browser.urlbar.autocomplete.enabled - trueFF - user.js: browser.cache.memory.capacity - 65536FF - user.js: content.notify.ontimer - trueFF - user.js: content.interrupt.parsing - trueFF - user.js: content.max.tokenizing.time - 2250000FF - user.js: content.switch.threshold - 750000FF - user.js: plugin.expose_full_path - trueFF - user.js: ui.submenuDelay - 0FF - user.js: extentions.y2layers.installId - 6e1cb162-63b3-43d9-9494-84a711b1219eFF - user.js: extentions.y2layers.defaultEnableAppsList - DropDownDeals,buzzdock,YontooNewOffersFF - user.js: extentions.webcake.installId - 0c90ef80-fc69-4b17-83d2-47e96b0ff380FF - user.js: extentions.webcake.defaultEnableAppsList - layers/banner,layers/inline,layers/search,layers/shopping,newOffers/wcFF - user.js: - FF - user.js: - 480846e0000000000000000400008d08FF - user.js: - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}FF - user.js: - 15919FF - user.js: - - user.js: - - user.js: - - user.js: - deltaFF - user.js: - deltaFF - user.js: - babsstFF - user.js: - noneFF - user.js: - baseFF - user.js: - sstFF - user.js: - enFF - user.js: - falseFF - user.js: - trueFF - user.js: - falseFF - user.js: extensions.delta_i.babTrack - affID=119776&tsp=4962FF - user.js: extensions.delta_i.babExt - FF - user.js: extensions.delta_i.srcExt - ssFF - user.js: - falseFF - user.js: - falseFF - user.js: - false - - - - ORPHANS REMOVED - - - - Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)WebBrowser-{687578B9-7132-4A7A-80E4-30EE31099E03} - (no file)ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)C:\Documents and Settings\zdrave.CHANGEME1\Start Menu\Programs\Startup\AutorunsDisabled\2YourFace_Updater.lnk - C:\Documents and Settings\zdrave.CHANGEME1\Application Data\2YourFace\Updater.exeSafeBoot-10793436.sysSafeBoot-18651178.sysSafeBoot-46610255.sysSafeBoot-66397349.sysSafeBoot-77081657.sysSafeBoot-95594599.sysAddRemove-01_Simmental - C:\Program Files\Samsung\USB Drivers\01_Simmental\Uninstall.exeAddRemove-02_Siberian - C:\Program Files\Samsung\USB Drivers\02_Siberian\Uninstall.exeAddRemove-03_Swallowtail - C:\Program Files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exeAddRemove-04_semseyite - C:\Program Files\Samsung\USB Drivers\04_semseyite\Uninstall.exeAddRemove-07_Schorl - C:\Program Files\Samsung\USB Drivers\07_Schorl\Uninstall.exeAddRemove-09_Hsp - C:\Program Files\Samsung\USB Drivers\09_Hsp\Uninstall.exeAddRemove-11_HSP_Plus_Default - C:\Program Files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exeAddRemove-16_Shrewsbury - C:\Program Files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exeAddRemove-20_NXP_Driver - C:\Program Files\Samsung\USB Drivers\20_NXP_Driver\Uninstall.exeAddRemove-24_flashusbdriver - C:\Program Files\Samsung\USB Drivers\24_flashusbdriver\Uninstall.exeAddRemove-25_escape - C:\Program Files\Samsung\USB Drivers\25_escape\Uninstall.exe Цитирай Link to comment Сподели другаде More sharing options...
B-boy/StyLe/ Публикувано Август 15, 2013 Report Share Публикувано Август 15, 2013 Това не е целия лог. Ако е дълъг просто го прикачете в коментара си. Цитирай Link to comment Сподели другаде More sharing options...
Matt_Ragan Публикувано Август 15, 2013 Author Report Share Публикувано Август 15, 2013 ComboFix.txt Цитирай Link to comment Сподели другаде More sharing options...
B-boy/StyLe/ Публикувано Август 15, 2013 Report Share Публикувано Август 15, 2013 Отново не е целия...или не сте го копирали или не се е довършил заради рестартирането от ваша страна.Затова направете нова проверка и публикувайте новия лог файл. В последната част на лога проста има важна информация, която не ми се иска да игнорирам. Поздрави! Цитирай Link to comment Сподели другаде More sharing options...
Matt_Ragan Публикувано Август 15, 2013 Author Report Share Публикувано Август 15, 2013 този път изглежда всичко е ОК,но компа ми не се рестартира,апък не посмях да го рестартирам ръчно...ето новият логComboFix.txt Цитирай Link to comment Сподели другаде More sharing options...
B-boy/StyLe/ Публикувано Август 15, 2013 Report Share Публикувано Август 15, 2013 Изтеглете този файл и го запазете на десктопа.Отворете Notepad.exe и се уверете, че пред Format => няма отметка пред Word Wrap (ако има я махнете).С copy/paste въведете следната информация: @echo Unpacking files ...@echo (This window will close when it's done)@echo offMKdir C:\SP3WindowsXP-KB936929-SP3-x86-ENU.exe -x: C:\SP3 /quietcd C:\SP3\i386expand sfcfiles.dl_ C:\SP3\sfcfiles.dll Запазете файла с името expand.bat и го стартирайте.Ще се създаде папка на C:\ с името SP3. След това отново отворете notepad и с copy/paste поставете следната информация: Fcopy::C:\SP3\sfcfiles.dll | c:\windows\system32\sfcfiles.dllDriver::10793436WebCakeUpdaterBPNOFQFUPYPFGGVRDZYDTOWYFFUNOQXPXWAZJFile::c:\windows.0\system32\drivers\33345492.sysc:\docume~1\ZDRAVE~1.CHA\LOCALS~1\Temp\BPNOFQ.exec:\docume~1\ZDRAVE~1.CHA\LOCALS~1\Temp\FUPYPF.exec:\docume~1\ZDRAVE~1.CHA\LOCALS~1\Temp\GGV.exec:\docume~1\ZDRAVE~1.CHA\LOCALS~1\Temp\RDZYD.exec:\docume~1\ZDRAVE~1.CHA\LOCALS~1\Temp\TOWYFF.exec:\docume~1\ZDRAVE~1.CHA\LOCALS~1\Temp\UNOQ.exec:\docume~1\ZDRAVE~1.CHA\LOCALS~1\Temp\XPXWAZJ.exec:\documents and settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\plugin@getwebcake.comc:\documents and settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\\documents and settings\zdrave.CHANGEME1\Application Data\Web Cakec:\program files\Web Cakec:\documents and settings\zdrave.CHANGEME1\Local Settings\Application Data\Cool_MirageRegistry::[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]"DisableMonitoring"=dword:00000000[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]"DisableMonitoring"=dword:00000000[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]"DisableMonitoring"=dword:00000000[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]"EnableFirewall"=dword:00000001DDS::mStart Page = hxxp:// - ProfilePath - c:\documents and settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\FF - prefs.js: - hxxp://{searchTerms}FF - ExtSQL: 2013-06-26 20:40;; c:\documents and settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\ - ExtSQL: 2013-08-02 08:12;; c:\documents and settings\zdrave.CHANGEME1\Application Data\Mozilla\Firefox\Profiles\mvnvfmzf.default\extensions\plugin@getwebcake.comuser_pref('extensions.autoDisableScopes', 0);user_pref('security.csp.enable', false);user_pref('security.OCSP.enabled', 0);FF - user.js: extensions.funmoods.hmpg - trueFF - user.js: extensions.funmoods.hmpgUrl - hxxp:// - user.js: extensions.funmoods.dfltSrch - trueFF - user.js: extensions.funmoods.srchPrvdr - SearchFF - user.js: extensions.funmoods.dnsErr - trueFF - user.js: extensions.funmoods_i.newTab - trueFF - user.js: extensions.funmoods.newTabUrl - hxxp:// - user.js: extensions.funmoods.tlbrSrchUrl - hxxp:// - user.js: - 00FF09E3136146E0FF - user.js: extensions.funmoods.instlDay - 15604FF - user.js: extensions.funmoods.vrsn - - user.js: extensions.funmoods.vrsni - - user.js: extensions.funmoods_i.vrsnTs - - user.js: extensions.funmoods.prtnrId - funmoodsFF - user.js: extensions.funmoods.prdct - funmoodsFF - user.js: extensions.funmoods.aflt - nv1FF - user.js: extensions.funmoods_i.smplGrp - noneFF - user.js: extensions.funmoods.tlbrId - baseFF - user.js: extensions.funmoods.instlRef - nv1FF - user.js: extensions.funmoods.dfltLng -FF - user.js: extensions.funmoods.excTlbr - falseFF - user.js: extensions.funmoods.autoRvrt - falseFF - user.js: extensions.funmoods.envrmnt - productionFF - user.js: extensions.funmoods.isdcmntcmplt - trueFF - user.js: extensions.funmoods.mntrvrsn - 1.3.0FF - user.js: extentions.y2layers.installId - 25d6df24-2b28-4838-991c-8a96bbecf796FF - user.js: extentions.y2layers.defaultEnableAppsList - twittube,ezLooker,pagerage,buzzdock,toprelatedtopics,YontooNewOffersFF - user.js: extensions.autoDisableScopes - 14FF - user.js: extensions.BabylonToolbar.autoRvrt - falseFF - user.js: extensions.BabylonToolbar_i.newTab - falseFF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp:// - user.js: - 480846e00000000000000015afae718fFF - user.js: extensions.BabylonToolbar.appId - {BDB69379-802F-4eaf-B541-F8DE92DD98DB}FF - user.js: extensions.BabylonToolbar.instlDay - 15627FF - user.js: extensions.BabylonToolbar.vrsn - - user.js: extensions.BabylonToolbar.vrsni - - user.js: extensions.BabylonToolbar_i.vrsnTs - - user.js: extensions.BabylonToolbar.prtnrId - babylonFF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbarFF - user.js: extensions.BabylonToolbar.aflt - babsstFF - user.js: extensions.BabylonToolbar_i.smplGrp - noneFF - user.js: extensions.BabylonToolbar.tlbrId - baseFF - user.js: extensions.BabylonToolbar.instlRef - sstFF - user.js: extensions.BabylonToolbar.dfltLng - enFF - user.js: extensions.BabylonToolbar.excTlbr - falseFF - user.js: extensions.BabylonToolbar.admin - falseFF - user.js: extensions.BabylonToolbar_i.babTrack - affID=116775&tt=101012_24_4112_2FF - user.js: extensions.BabylonToolbar_i.babExt -FF - user.js: extensions.BabylonToolbar_i.srcExt - ssFF - user.js: network.http.pipelining.maxrequests - 8FF - user.js: network.http.request.max-start-delay - 0FF - user.js: network.http.max-connections - 48FF - user.js: network.http.max-connections-per-server - 16FF - user.js: network.http.max-persistent-connections-per-proxy - 16FF - user.js: network.http.max-persistent-connections-per-server - 8FF - user.js: browser.turbo.enabled - trueFF - user.js: browser.display.show_image_placeholders - trueFF - user.js: - falseFF - user.js: browser.urlbar.autocomplete.enabled - trueFF - user.js: browser.cache.memory.capacity - 65536FF - user.js: content.notify.ontimer - trueFF - user.js: content.interrupt.parsing - trueFF - user.js: content.max.tokenizing.time - 2250000FF - user.js: content.switch.threshold - 750000FF - user.js: plugin.expose_full_path - trueFF - user.js: ui.submenuDelay - 0FF - user.js: extentions.y2layers.installId - 6e1cb162-63b3-43d9-9494-84a711b1219eFF - user.js: extentions.y2layers.defaultEnableAppsList - DropDownDeals,buzzdock,YontooNewOffersFF - user.js: extentions.webcake.installId - 0c90ef80-fc69-4b17-83d2-47e96b0ff380FF - user.js: extentions.webcake.defaultEnableAppsList - layers/banner,layers/inline,layers/search,layers/shopping,newOffers/wcFF - user.js: -FF - user.js: - 480846e0000000000000000400008d08FF - user.js: - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}FF - user.js: - 15919FF - user.js: - - user.js: - - user.js: - - user.js: - deltaFF - user.js: - deltaFF - user.js: - babsstFF - user.js: - noneFF - user.js: - baseFF - user.js: - sstFF - user.js: - enFF - user.js: - falseFF - user.js: - trueFF - user.js: - falseFF - user.js: extensions.delta_i.babTrack - affID=119776&tsp=4962FF - user.js: extensions.delta_i.babExt -FF - user.js: extensions.delta_i.srcExt - ssFF - user.js: - falseFF - user.js: - falseFF - user.js: - false Запазете файла с име CFScript и го провлачете и пуснете в Combofix (както на картинката отдолу):Публикувайте лог файл в следващия си пост. Цитирай Link to comment Сподели другаде More sharing options...
Matt_Ragan Публикувано Август 15, 2013 Author Report Share Публикувано Август 15, 2013 аз имам Notepad вграден в Windows-a ми.Windows ми е на български и Notepad ми е на български и в последният никъде не виждам отметки за каквото и да било...незнам дали поради тази причина или поради нещо друго и с copy/paste нещо не мога да се справя...изтеглих един друг Notepad(Untitled-Notepad2),който замени старият,но не виждам "Format" в него Цитирай Link to comment Сподели другаде More sharing options...
B-boy/StyLe/ Публикувано Август 15, 2013 Report Share Публикувано Август 15, 2013 Не искам да използвате друг Notepad, освен този на Windows-a иначе нищо няма да се получи!Това че е на бъгларски едва ли ще ви затрудни да откриете опцията...Колонката би трябвало да се намира до "Изглед" или както е там на български. Цитирай Link to comment Сподели другаде More sharing options...
Matt_Ragan Публикувано Август 15, 2013 Author Report Share Публикувано Август 15, 2013 добре...как да върна старият български Notepad,след като новият го замени...може би да рестартирам? Цитирай Link to comment Сподели другаде More sharing options...
B-boy/StyLe/ Публикувано Август 15, 2013 Report Share Публикувано Август 15, 2013 Просто го деинсталирайте... Цитирай Link to comment Сподели другаде More sharing options...
Matt_Ragan Публикувано Август 15, 2013 Author Report Share Публикувано Август 15, 2013 така,върна се...а как да копи пейстна това което сте поставили в каретода...сетих се как...извинете ме че ви занимавам с такива елементарни неща,но за 5 години сам го правил най-много веднъж Цитирай Link to comment Сподели другаде More sharing options...
Препоръчан пост
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.