Jump to content

Препоръчан пост

  • Отговори 131
  • Създадена
  • Последен отговор

ТОП потребители в тази тема

ТОП потребители в тази тема

Публикувани изображения

:) Проблемът с нета - е оправен - не касаеше вируси и т.н. - смених кабела свързващ рутера и кампа и всичко е наред...

ето първият доклад

Malwarebytes' Anti-Malware 1.44

Версия на базата от данни: 3541

Windows 5.1.2600 Service Pack 2

Internet Explorer 6.0.2900.2180

 

2010-01-11 21:45:42

mbam-log-2010-01-11 (21-45-42).txt

 

Тип сканиране: Пълно сканиране (C:\|D:\|E:\|)

Сканирани обекти: 72717

Изминало време: 23 minute(s), 7 second(s)

 

Заразени процеси в паметта: 0

Заразени модули в паметта: 0

Заразени ключове в регистратурата: 0

Заразени стойности в регистратурата: 0

Заразени информационни обекти в регистратурата: 0

Заразени папки: 0

Заразени файлове: 2

 

Заразени процеси в паметта:

(Не бяха открити заплахи)

 

Заразени модули в паметта:

(Не бяха открити заплахи)

 

Заразени ключове в регистратурата:

(Не бяха открити заплахи)

 

Заразени стойности в регистратурата:

(Не бяха открити заплахи)

 

Заразени информационни обекти в регистратурата:

(Не бяха открити заплахи)

 

Заразени папки:

(Не бяха открити заплахи)

 

Заразени файлове:

C:\System Volume Information\_restore{98D17103-31FA-4C4C-A740-934E5D0DEBAA}\RP380\A0036714.sys (Malware.Trace) -> Quarantined and deleted successfully.

C:\System Volume Information\_restore{98D17103-31FA-4C4C-A740-934E5D0DEBAA}\RP381\A0036972.sys (Malware.Trace) -> Quarantined and deleted successfully.

Link to comment
Сподели другаде

Не съм казвал да правиш пълно сканиране. Казах да направиш бързо такова. Сега да не вземеш да направиш и бързо? Няма смисъл. Просто отбелязвам, че не следваш инструкциите както трябва и в някои ситуации своеволията могат да се окажат много опасни, ако гадинката е сериозна.
Link to comment
Сподели другаде

:thumbsup: :bgflag: Втората пограма не засече никакви вредители.

Предполагам че това е финалът на борбата.

 

Дано с моят случай и твоят опит да се е обагатил и наистина да е било полезно и за теб - Night_Reven.

 

Кажи ми обаче какво да правя с комбо фиксът - да го деинсталирам ли?... а конзолата - може би трябва да прочета нещо за нея - или ще ме посъветваш нещо...

Link to comment
Сподели другаде

Отвори Start -> Run. В полето пейстни следния текст и кликни OK:

"%userprofile%\Desktop\Combo-Fix.exe" /uninstall

Това ще деинсталира ComboFix.

 

Горещо ти препоръчвам да инсталираш възможно най-скоро Service Pack 3 за Windows XP и да обновиш Internet Explorer 6 до Internet Explorer 8, както и да инсталираш всички важни обновления за сигурността. Обновената операционна система и софтуер са грабнакът на компютърната сигурност. Ако не ги обновиш, шансът да се заразиш отново е много по-висок, отколкото ако ги обновиш.

 

Допълнителен съвет: добра идея е да премахнеш/деинсталираш MemTurbo. Програмите за освобождаване на памет са пълни боклуци до една и в действителност влошават производителността в повечето случаи. За повече информация по този въпрос и други можеш да прочетеш в тази тема, което също ти препоръчвам да направиш.

Link to comment
Сподели другаде

Здравейте ! Ще цитирам от друго място за проблема ми.

 

"Преди няколко седмици отворих без да искам един линк от скайпа който най-вероятно е от онея спам глупости ,но се оказа много по-лошо ,нещо като някакъв сетъп ,започна да зарежда и го спрях на половината.Проблема е ,че след това много често ми се затварят различни програми сами ,когато съм в my computer и вляза в някой от хард дисковете ,отваря директно нов прозорец.Първата ми работа след това беше да върна системата на Уиндоуса назад ,но когато ми се отвори прозорчето стои точно 2 секунди и се затваря само ... и така всеки път.Също така когато изключвам лаптопа ми излиза ето този ерор "dll error , едикаквоси.exe и отдолу the application failed to initialize because the window station is shutting down".Също така не знам дали си въобразявам ,но скоро забелязах ,че откакто стана това ,нямам НОД 32 ,в папката Есет в програм файлс има някакви глупости ... "

 

Сканирах с програмката "OTL.exe" ,както беше препоръчано по-назад и ето информацяита от двата лога.

 

OTL Extras logfile created on: 14.01.2010 17:31:16 - Run 1

OTL by OldTimer - Version 3.1.24.0 Folder = C:\Documents and Settings\user\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.MM.yyyy

 

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 80.00% Memory free

5.00 Gb Paging File | 4.00 Gb Available in Paging File | 89.00% Paging File free

Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 55.60 Gb Total Space | 36.77 Gb Free Space | 66.13% Space Free | Partition Type: NTFS

Drive D: | 205.08 Gb Total Space | 146.38 Gb Free Space | 71.38% Space Free | Partition Type: NTFS

Drive E: | 205.08 Gb Total Space | 205.01 Gb Free Space | 99.96% Space Free | Partition Type: NTFS

Drive F: | 186.61 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

 

Computer Name: ACER5738

Current User Name: user

Logged in as Administrator.

 

Current Boot Mode: Normal

Scan Mode: All users

Company Name Whitelist: On

Skip Microsoft Files: On

File Age = 30 Days

Output = Minimal

 

========== Extra Registry (SafeList) ==========

 

 

========== File Associations ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

 

[HKEY_USERS\S-1-5-21-1547161642-362288127-1801674531-1003\SOFTWARE\Classes\<extension>]

.html [@ = FirefoxHTML] -- Reg Error: Key error. File not found

 

========== Shell Spawning ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

exefile [open] -- "%1" %*

htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)

htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)

htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)

http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)

https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)

Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)

Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)

Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)

CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

 

========== Security Center Settings ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"FirstRunDisabled" = 1

"AntiVirusDisableNotify" = 1

"FirewallDisableNotify" = 1

"UpdatesDisableNotify" = 1

"AntiVirusOverride" = 0

"FirewallOverride" = 0

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"EnableFirewall" = 0

 

========== Authorized Applications List ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)

"D:\Games\PES 2010\pes2010.exe" = D:\Games\PES 2010\pes2010.exe:*:Enabled:Pro Evolution Soccer 2010 -- (Konami Digital Entertainment Co., Ltd.)

"D:\Games\PES 2010\PESEdit.exe" = D:\Games\PES 2010\PESEdit.exe:*:Enabled:Pro Evolution Soccer 2010 -- (Konami Digital Entertainment Co., Ltd.)

"D:\Games\FM 2010\fm.exe" = D:\Games\FM 2010\fm.exe:*:Enabled:Football Manager 2010 -- (Sports Interactive)

"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.)

 

 

========== HKEY_LOCAL_MACHINE Uninstall List ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR

"{055A5AF0-9FEB-440D-B00A-18935C7C171C}" = SA Dictionary 2008 Beta 4

"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center

"{11202615-E557-4ECF-9B86-F59C81E52909}" = FIFA 10

"{164086E1-A5DD-3D64-06B1-186005030854}" = CCC Help Korean

"{1800A397-53DF-4F2C-6115-FE2FA9EA69DA}" = ccc-core-static

"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer

"{18625255-5E1D-6BF1-8809-BE4CEE493D52}" = Catalyst Control Center Graphics Full Existing

"{18CD3278-B87E-3026-D38F-38E0A67F2BA4}" = ccc-core-preinstall

"{18D07AC5-417D-4735-BC99-C8E77A7A4195}" = Windows Live Messenger

"{1F126EDC-DA29-4D5B-80DF-735252475FEE}" = Pro Evolution Soccer 2010 DEMO

"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Инструмент за качване на Windows Live

"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT

"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer

"{232AAA95-AE60-46C7-9987-4E7139EA3554}" = Асистент за влизане на Windows Live

"{283FFB23-8751-4B08-ACB8-5E0F8BCF7727}" = Pro Evolution Soccer 2010

"{298F1470-17A2-124A-B615-9A58F90CDA57}" = CCC Help English

"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP

"{368B73EA-A46E-94B1-1B20-24D47B4760F3}" = CCC Help Portuguese

"{3AD20171-A064-C9EC-0C11-5B036FA6F32C}" = CCC Help Dutch

"{3F64C088-9A45-41B3-8B99-71AFAB720A56}" = Sherlock Holmes versus Jack the Ripper

"{4A3EB326-F730-4A71-AEBF-3C7DF7ED716F}" = Тайната на сребърната обица

"{4F0C7CCF-5666-474B-B02E-AC514A95EC93}" = NVIDIA GAME System Software 2.8.1

"{51B83F5C-5660-4B73-AB18-C68993FEDEB3}" = Catalyst Control Center - Branding

"{55A29068-F2CE-456C-9148-C869879E2357}" = TuneUp Utilities 2009

"{5B78DFB0-0FFE-E76F-E51C-FBA53A01085E}" = CCC Help Polish

"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.8

"{6144C1EC-0F4E-6514-E633-85AC3724F082}" = CCC Help Spanish

"{63686BEF-04CA-461C-B364-53BBC322F7BF}" = Sherlock Holmes Nemesis

"{6D144E43-239B-657F-15C5-854EF2C4E55F}" = Catalyst Control Center Core Implementation

"{70701602-56D7-64DF-150D-5459C547E058}" = CCC Help Chinese Traditional

"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0

"{731A3C00-8E73-7893-C15E-4FAFC5787EE5}" = CCC Help Swedish

"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com

"{839011A6-DF28-4E21-00AE-83482775212B}" = NBA LIVE 07

"{84814E6B-2581-46EC-926A-823BD1C670F6}" = Lenovo Bluetooth with Enhanced Data Rate Software

"{8E371F04-9B92-42A0-A7AF-6678DDB688E1}" = Windows Live Essentials

"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003

"{91B323B5-A79C-4D23-BD6D-046C565F9BCF}" = MadOnion.com/3DMark2001 SE

"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting

"{95991299-E762-2AEA-077D-5DB75E7896C0}" = CCC Help Russian

"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = USB2.0 Card Reader Software

"{9E478F3F-7A7B-42C5-BE9C-40FC0E07665F}" = The Awakened

"{A01D832F-1227-EC5B-6A06-88D53753A789}" = CCC Help Hungarian

"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI

"{A23DD0F0-58E1-7453-9721-760062EF2369}" = CCC Help German

"{A45F3795-1527-47FA-BE1A-2DD242B439E5}_is1" = Need for Speed - Shift

"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable

"{A4F264EA-5851-4684-185F-83C09B678A9C}" = ccc-utility

"{A75C72CA-4D28-C419-5FBA-3762F2344D2F}" = Skins

"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9

"{B0C4DD22-7D91-E56C-F257-37781CC7FFC2}" = Catalyst Control Center Graphics Full New

"{B55E3E57-C706-CFFF-8170-635BB081B3AA}" = CCC Help Greek

"{B7BFA380-2559-B766-85FA-EA02218FD8E7}" = CCC Help Norwegian

"{B9DD8184-8040-1920-D771-3F77AA3131DB}" = CCC Help Chinese Standard

"{BF76EB61-33DA-BBE5-151F-0A1DE5D99A2B}" = CCC Help Japanese

"{C408D81A-CB17-4CDF-98AF-2E64036B3F32}" = Windows Bulgarian Interface Pack

"{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}" = NVIDIA PhysX

"{CC0BD204-465D-B512-E19F-866026F59326}" = CCC Help Italian

"{D02C0FA6-7512-5411-BC81-E910C8AF4A9F}" = CCC Help Thai

"{D1C8DCCF-790D-62AD-ED46-3E5E170B13B2}" = CCC Help Danish

"{D2777D85-7E63-402F-A5E7-2AF436C1C9D4}" = Intel® PROSet/Wireless WiFi Software

"{D27840CA-5F61-7CD3-CDF4-A6EB828CF5D7}" = Catalyst Control Center Localization All

"{D3F07123-C1BE-3BDE-7B29-C6647C3DCE98}" = Catalyst Control Center Graphics Light

"{D9237C88-448A-C1DE-6BA0-EF53462BB1FC}" = CCC Help French

"{E86766EB-5D72-ADFF-D2F0-DE0AB25174CF}" = CCC Help Turkish

"{EA913B24-ED12-1837-C52C-EA58D6ECDB2F}" = CCC Help Czech

"{EBB794ED-D282-4334-92FB-254481EFF514}" = Pro Evolution Soccer 6

"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform

"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard

"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver

"{F36547BF-7B05-1B15-E383-D42BFFD57796}" = CCC Help Finnish

"Adobe AIR" = Adobe AIR

"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX

"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin

"Agere Systems Soft Modem" = Agere Systems HDA Modem

"All ATI Software" = ATI - Software Uninstall Utility

"ATI Display Driver" = ATI Display Driver

"BFGC" = Big Fish Games Client

"BFL_FIFA_10" = BFL_FIFA_10

"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com

"Cool Edit Pro 2.0" = Cool Edit Pro 2.0

"DirectX10_is1" = DirectX10 RC2 Pre Fix 3

"EVEREST Ultimate Edition_is1" = EVEREST Ultimate Edition v5.00

"FIFA 10_is1" = FIFA 10 v1.0 R-E

"FlexType 2K" = FlexType 2K

"Football Manager 2010" = Football Manager 2010

"GOM Player" = GOM Player

"Hamachi" = Hamachi 0.9.9.9

"ie8" = Windows Internet Explorer 8

"InstallShield_{EBB794ED-D282-4334-92FB-254481EFF514}" = Pro Evolution Soccer 6

"KLiteCodecPack_is1" = K-Lite Codec Pack 5.0.0 (Full)

"LManager" = Launch Manager

"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0

"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition

"NOD32 v3.x FiX 1.1 by TemDono_is1" = NOD32 v3.x FiX 1.1 by TemDono (Free Updates - Expire in 2050)

"PESEdit.com 2010 Patch 0.3.1 with Chants" = PESEdit.com 2010 Patch 0.3.1 with Chants

"ProInst" = Intel PROSet Wireless

"SA Dictionary 2005 T2" = SA Dictionary 2005 T2

"Screen Shot Maker_is1" = Screen Shot Maker 2.5

"TVUPlayer" = TVUPlayer 2.3.4.1

"Veetle TV" = Veetle TV 0.9.15

"Winamp" = Winamp

"Windows Media Format Runtime" = Windows Media Format Runtime

"WinLiveSuite_Wave3" = Windows Live Essentials

"WinRAR archiver" = WinRAR archiver

"WinUHA_is1" = WinUHA 2.0 RC1 (2005.02.27)

 

========== HKEY_USERS Uninstall List ==========

 

[HKEY_USERS\S-1-5-21-1547161642-362288127-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"uTorrent" = µTorrent

 

========== Last 10 Event Log Errors ==========

 

[ Application Events ]

Error - 25.12.2009 11:41:18 | Computer Name = ACER5738 | Source = Application Hang | ID = 1002

Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module

hungapp, version 0.0.0.0, hang address 0x00000000.

 

Error - 25.12.2009 15:20:53 | Computer Name = ACER5738 | Source = Application Error | ID = 1000

Description = Faulting application ati2evxx.exe, version 6.14.10.4220, faulting

module ntdll.dll, version 5.1.2600.5512, fault address 0x000108b3.

 

Error - 26.12.2009 06:35:13 | Computer Name = ACER5738 | Source = Application Hang | ID = 1002

Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module

hungapp, version 0.0.0.0, hang address 0x00000000.

 

Error - 30.12.2009 11:31:17 | Computer Name = ACER5738 | Source = Application Hang | ID = 1002

Description = Hanging application msiexec.exe, version 3.1.4001.5512, hang module

hungapp, version 0.0.0.0, hang address 0x00000000.

 

Error - 08.01.2010 12:57:38 | Computer Name = ACER5738 | Source = Application Error | ID = 1000

Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting

module flash10b.ocx, version 10.0.22.87, fault address 0x001ea9e1.

 

Error - 10.01.2010 12:36:36 | Computer Name = ACER5738 | Source = Application Error | ID = 1000

Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting

module mshtml.dll, version 8.0.6001.18702, fault address 0x0020fbd7.

 

Error - 10.01.2010 12:36:41 | Computer Name = ACER5738 | Source = Application Error | ID = 1000

Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting

module mshtml.dll, version 8.0.6001.18702, fault address 0x0020fbd7.

 

Error - 10.01.2010 12:36:43 | Computer Name = ACER5738 | Source = Application Error | ID = 1001

Description = Fault bucket 1192410865.

 

Error - 10.01.2010 12:37:03 | Computer Name = ACER5738 | Source = Application Error | ID = 1000

Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting

module mshtml.dll, version 8.0.6001.18702, fault address 0x0020fbd7.

 

Error - 10.01.2010 12:37:08 | Computer Name = ACER5738 | Source = Application Error | ID = 1000

Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting

module mshtml.dll, version 8.0.6001.18702, fault address 0x0020fbd7.

 

[ System Events ]

Error - 13.01.2010 13:53:18 | Computer Name = ACER5738 | Source = DCOM | ID = 10016

Description = The machine-default permission settings do not grant Local Activation

permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206}

 

to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission

can be modified using the Component Services administrative tool.

 

Error - 13.01.2010 13:53:19 | Computer Name = ACER5738 | Source = DCOM | ID = 10016

Description = The machine-default permission settings do not grant Local Activation

permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206}

 

to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission

can be modified using the Component Services administrative tool.

 

Error - 13.01.2010 13:53:19 | Computer Name = ACER5738 | Source = DCOM | ID = 10016

Description = The machine-default permission settings do not grant Local Activation

permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206}

 

to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission

can be modified using the Component Services administrative tool.

 

Error - 13.01.2010 14:08:10 | Computer Name = ACER5738 | Source = DCOM | ID = 10016

Description = The machine-default permission settings do not grant Local Activation

permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206}

 

to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission

can be modified using the Component Services administrative tool.

 

Error - 13.01.2010 14:08:10 | Computer Name = ACER5738 | Source = DCOM | ID = 10016

Description = The machine-default permission settings do not grant Local Activation

permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206}

 

to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission

can be modified using the Component Services administrative tool.

 

Error - 13.01.2010 14:08:10 | Computer Name = ACER5738 | Source = DCOM | ID = 10016

Description = The machine-default permission settings do not grant Local Activation

permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206}

 

to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission

can be modified using the Component Services administrative tool.

 

Error - 13.01.2010 14:08:18 | Computer Name = ACER5738 | Source = sr | ID = 1

Description = The System Restore filter encountered the unexpected error '0xC0000034'

while processing the file '_filelst.cfg' on the volume 'HarddiskVolume1'. It has

stopped monitoring the volume.

 

Error - 14.01.2010 11:23:04 | Computer Name = ACER5738 | Source = DCOM | ID = 10016

Description = The machine-default permission settings do not grant Local Activation

permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206}

 

to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission

can be modified using the Component Services administrative tool.

 

Error - 14.01.2010 11:23:04 | Computer Name = ACER5738 | Source = DCOM | ID = 10016

Description = The machine-default permission settings do not grant Local Activation

permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206}

 

to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission

can be modified using the Component Services administrative tool.

 

Error - 14.01.2010 11:23:04 | Computer Name = ACER5738 | Source = DCOM | ID = 10016

Description = The machine-default permission settings do not grant Local Activation

permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206}

 

to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission

can be modified using the Component Services administrative tool.

 

 

< End of report >

 

и

 

OTL logfile created on: 14.01.2010 17:31:16 - Run 1

OTL by OldTimer - Version 3.1.24.0 Folder = C:\Documents and Settings\user\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.MM.yyyy

 

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 80.00% Memory free

5.00 Gb Paging File | 4.00 Gb Available in Paging File | 89.00% Paging File free

Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 55.60 Gb Total Space | 36.77 Gb Free Space | 66.13% Space Free | Partition Type: NTFS

Drive D: | 205.08 Gb Total Space | 146.38 Gb Free Space | 71.38% Space Free | Partition Type: NTFS

Drive E: | 205.08 Gb Total Space | 205.01 Gb Free Space | 99.96% Space Free | Partition Type: NTFS

Drive F: | 186.61 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

 

Computer Name: ACER5738

Current User Name: user

Logged in as Administrator.

 

Current Boot Mode: Normal

Scan Mode: All users

Company Name Whitelist: On

Skip Microsoft Files: On

File Age = 30 Days

Output = Minimal

 

========== Processes (SafeList) ==========

 

PRC - C:\Documents and Settings\user\Desktop\o.exe (OldTimer Tools)

PRC - C:\WINDOWS\system32\eslztmbxfzvhcrlpe.exe ()

PRC - C:\Documents and Settings\user\Local Settings\Temp\lowziq.exe ()

PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)

PRC - C:\WINDOWS\system32\TUProgSt.exe (TuneUp Software)

PRC - C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)

PRC - C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)

PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

PRC - C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)

PRC - C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)

PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)

PRC - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)

PRC - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Advanced Micro Devices Inc.)

PRC - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (ATI Technologies Inc.)

PRC - C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)

PRC - C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe (Intel® Corporation)

PRC - C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)

PRC - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)

PRC - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)

PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)

PRC - C:\WINDOWS\system32\wbem\unsecapp.exe (Microsoft Corporation)

PRC - C:\WINDOWS\system32\agrsmsvc.exe (Agere Systems)

PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)

PRC - C:\Program Files\Datecs\FlexType 2K\FType2K.exe ()

 

 

========== Modules (SafeList) ==========

 

MOD - C:\Documents and Settings\user\Desktop\o.exe (OldTimer Tools)

MOD - C:\WINDOWS\system32\BtMmHook.dll (Broadcom Corporation.)

MOD - C:\WINDOWS\system32\NetProvCredMan.dll (Intel® Corporation)

MOD - C:\WINDOWS\system32\netui1.dll (Microsoft Corporation)

MOD - C:\WINDOWS\system32\netui0.dll (Microsoft Corporation)

MOD - C:\WINDOWS\system32\ntlanman.dll (Microsoft Corporation)

MOD - C:\WINDOWS\system32\davclnt.dll (Microsoft Corporation)

MOD - C:\WINDOWS\system32\linkinfo.dll (Microsoft Corporation)

MOD - C:\WINDOWS\system32\drprov.dll (Microsoft Corporation)

MOD - C:\WINDOWS\system32\netrap.dll (Microsoft Corporation)

MOD - C:\WINDOWS\system32\newdll.dll ()

 

 

========== Win32 Services (SafeList) ==========

 

SRV - (gusvc) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)

SRV - (TuneUp.ProgramStatisticsSvc) -- C:\WINDOWS\system32\TUProgSt.exe (TuneUp Software)

SRV - (TuneUp.Defrag) -- C:\WINDOWS\system32\TuneUpDefragService.exe (TuneUp Software)

SRV - (Ati HotKey Poller) -- C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)

SRV - (btwdins) -- C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)

SRV - (UxTuneUp) -- C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)

SRV - (EvtEng) -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)

SRV - (S24EventMonitor) -- C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)

SRV - (RegSrvc) -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)

SRV - (Irmon) -- C:\WINDOWS\system32\irmon.dll (Microsoft Corporation)

SRV - (AgereModemAudio) -- C:\WINDOWS\system32\agrsmsvc.exe (Agere Systems)

SRV - (ose) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)

 

 

========== Driver Services (SafeList) ==========

 

DRV - (atksgt) -- C:\WINDOWS\system32\drivers\atksgt.sys ()

DRV - (lirsgt) -- C:\WINDOWS\system32\drivers\lirsgt.sys ()

DRV - (hamachi) -- C:\WINDOWS\system32\drivers\hamachi.sys (Applied Networking Inc.)

DRV - (sptd) -- C:\WINDOWS\System32\Drivers\sptd.sys ()

DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)

DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)

DRV - (BTKRNL) -- C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)

DRV - (RTHDMIAzAudService) -- C:\WINDOWS\system32\drivers\RtHDMI.sys (Realtek Semiconductor Corp.)

DRV - (AtiHdmiService) -- C:\WINDOWS\system32\drivers\AtiHdmi.sys (ATI Research Inc.)

DRV - (BTWUSB) -- C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)

DRV - (NETw5x32) Intel® -- C:\WINDOWS\system32\drivers\NETw5x32.sys (Intel Corporation)

DRV - (k57w2k) Broadcom NetLink -- C:\WINDOWS\system32\drivers\k57xp32.sys (Broadcom Corporation)

DRV - (Ambfilt) -- C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)

DRV - (s24trans) -- C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)

DRV - (BTWDNDIS) -- C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)

DRV - (btaudio) -- C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)

DRV - (HDAudBus) -- C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)

DRV - (Secdrv) -- C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)

DRV - (Ptilink) -- C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)

DRV - (btwhid) -- C:\WINDOWS\system32\drivers\btwhid.sys (Broadcom Corporation.)

DRV - (BTDriver) -- C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)

DRV - (btwmodem) -- C:\WINDOWS\system32\drivers\btwmodem.sys (Broadcom Corporation.)

DRV - (AgereSoftModem) -- C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)

DRV - (PxHelp20) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)

DRV - (DKbFltr) -- C:\WINDOWS\system32\drivers\DKbFltr.SYS (Dritek System Inc.)

DRV - (Monfilt) -- C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)

DRV - (STIrUsb) -- C:\WINDOWS\system32\drivers\irstusb.sys (SigmaTel, Inc.)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

 

 

IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

 

 

IE - HKU\S-1-5-21-1547161642-362288127-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com

IE - HKU\S-1-5-21-1547161642-362288127-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.start.bg/

IE - HKU\S-1-5-21-1547161642-362288127-1801674531-1003\S-1-5-21-1547161642-362288127-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

========== FireFox ==========

 

 

 

[2009.09.30 15:33:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Mozilla\Extensions

[2009.09.30 15:33:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\ehe3y68v.default\extensions

[2009.12.30 17:46:18 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions

 

O1 HOSTS File: (734 bytes) - C:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)

O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)

O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)

O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O3 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)

O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe (Realtek Semiconductor Corp.)

O4 - HKLM..\Run: [Google Quick Search Box] C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)

O4 - HKLM..\Run: [intelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)

O4 - HKLM..\Run: [intelZeroConfig] C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe (Intel® Corporation)

O4 - HKLM..\Run: [iSUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)

O4 - HKLM..\Run: [iSUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)

O4 - HKLM..\Run: [KernelFaultCheck] File not found

O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)

O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)

O4 - HKLM..\Run: [oynxncnfjzrzq] C:\WINDOWS\System32\yojzvqhfpljxulhnevc.exe ()

O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)

O4 - HKLM..\Run: [startCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)

O4 - HKLM..\Run: [yojzvqhfpljxulhnevc] C:\Documents and Settings\user\Local Settings\Temp\asphfcvvhffvunltmfogd.exe ()

O4 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)

O4 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003..\Run: [oynxncnfjzrzq] C:\Documents and Settings\user\Local Settings\Temp\eslztmbxfzvhcrlpe.exe ()

O4 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003..\Run: [skype] C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)

O4 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)

O4 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003..\Run: [xkcpiaojqjepjxqt] C:\WINDOWS\System32\yojzvqhfpljxulhnevc.exe ()

O4 - HKLM..\RunOnce: [ncwlgaqnwrobxnindt] C:\Documents and Settings\user\Local Settings\Temp\xkcpiaojqjepjxqt.exe ()

O4 - HKLM..\RunOnce: [paqbsiunsjcldp] C:\WINDOWS\System32\yojzvqhfpljxulhnevc.exe ()

O4 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003..\RunOnce: [eslztmbxfzvhcrlpe] C:\WINDOWS\System32\xkcpiaojqjepjxqt.exe ()

O4 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003..\RunOnce: [paqbsiunsjcldp] C:\Documents and Settings\user\Local Settings\Temp\lcypmiazkhgvtliphzhy.exe ()

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\FlexType 2K.lnk = C:\Program Files\Datecs\FlexType 2K\FType2K.exe ()

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: sevhzqdxdvpzsfx = xkcpiaojqjepjxqt.exe ()

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: pymvkyizcrip = C:\DOCUME~1\user\LOCALS~1\Temp\eslztmbxfzvhcrlpe.exe ()

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 1

O7 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1

O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll (Google Inc.)

O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()

O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()

O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)

O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()

O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()

O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1

O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)

O24 - Desktop WallPaper: C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O24 - Desktop BackupWallPaper: C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2009.09.30 10:23:08 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O32 - AutoRun File - [2010.01.14 17:23:46 | 00,000,847 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]

O32 - AutoRun File - [2010.01.14 17:23:47 | 00,000,859 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]

O32 - AutoRun File - [2010.01.14 17:23:47 | 00,000,850 | RHS- | M] () - E:\autorun.inf -- [ NTFS ]

O32 - AutoRun File - [2009.08.29 22:59:46 | 00,000,199 | R--- | M] () - F:\autorun.inf -- [ CDFS ]

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35 - comfile [open] -- "%1" %*

O35 - exefile [open] -- "%1" %*

 

========== Files/Folders - Created Within 30 Days ==========

 

[2010.01.14 17:26:16 | 00,544,256 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\user\Desktop\o.exe

[2010.01.13 18:59:26 | 34,628,928 | ---- | C] (PC Tools ) -- C:\Documents and Settings\user\Desktop\sdsetup.exe

[2009.12.30 17:46:18 | 00,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox

[2009.12.30 17:46:17 | 00,000,000 | ---D | C] -- C:\Program Files\Skype

[2009.12.28 18:44:11 | 00,000,000 | ---D | C] -- C:\Program Files\WinUHA

[2009.12.28 00:40:29 | 00,000,000 | ---D | C] -- C:\Temp

[2009.12.28 00:40:22 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Syntrillium

[2009.12.28 00:38:54 | 00,000,000 | ---D | C] -- C:\Program Files\coolpro2

[2009.12.25 20:32:17 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\My Documents\NBA LIVE 07

[2009.11.22 20:36:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\ESET

[2009.09.30 14:23:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\Intel

[2009.09.30 14:23:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Intel

[2009.09.30 10:26:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft

[2009.09.30 10:25:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft

[2009.09.30 10:23:06 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft

[2009.09.30 10:23:06 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft

[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

 

========== Files - Modified Within 30 Days ==========

 

[2010.01.14 17:31:46 | 00,002,408 | -H-- | M] () -- C:\WINDOWS\System32\sanvjwfvxlbhwftrajiqdlzmvlnbrxmvj.qzy

[2010.01.14 17:31:46 | 00,002,408 | -H-- | M] () -- C:\WINDOWS\sanvjwfvxlbhwftrajiqdlzmvlnbrxmvj.qzy

[2010.01.14 17:31:46 | 00,002,408 | -H-- | M] () -- C:\Program Files\sanvjwfvxlbhwftrajiqdlzmvlnbrxmvj.qzy

[2010.01.14 17:31:46 | 00,002,408 | -H-- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\sanvjwfvxlbhwftrajiqdlzmvlnbrxmvj.qzy

[2010.01.14 17:31:46 | 00,000,280 | -H-- | M] () -- C:\WINDOWS\System32\cadbfihnfjplqpthgfusvtx.zfx

[2010.01.14 17:31:46 | 00,000,280 | -H-- | M] () -- C:\WINDOWS\cadbfihnfjplqpthgfusvtx.zfx

[2010.01.14 17:31:46 | 00,000,280 | -H-- | M] () -- C:\Program Files\cadbfihnfjplqpthgfusvtx.zfx

[2010.01.14 17:31:46 | 00,000,280 | -H-- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\cadbfihnfjplqpthgfusvtx.zfx

[2010.01.14 17:31:28 | 00,000,316 | -H-- | M] () -- C:\WINDOWS\System32\paqbsiunsjcldpghtfhsitkamfkbudvhyzlx.kal

[2010.01.14 17:31:28 | 00,000,316 | -H-- | M] () -- C:\WINDOWS\paqbsiunsjcldpghtfhsitkamfkbudvhyzlx.kal

[2010.01.14 17:31:28 | 00,000,316 | -H-- | M] () -- C:\Program Files\paqbsiunsjcldpghtfhsitkamfkbudvhyzlx.kal

[2010.01.14 17:31:28 | 00,000,316 | -H-- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\paqbsiunsjcldpghtfhsitkamfkbudvhyzlx.kal

[2010.01.14 17:31:04 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\yojzvqhfpljxulhnevc.exe

[2010.01.14 17:31:04 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\xkcpiaojqjepjxqt.exe

[2010.01.14 17:31:04 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\rkibaystgfgxxrqztnxqoh.exe

[2010.01.14 17:31:04 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\ncwlgaqnwrobxnindt.exe

[2010.01.14 17:31:04 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\lcypmiazkhgvtliphzhy.exe

[2010.01.14 17:31:04 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\eslztmbxfzvhcrlpe.exe

[2010.01.14 17:31:04 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\asphfcvvhffvunltmfogd.exe

[2010.01.14 17:27:48 | 03,932,160 | -H-- | M] () -- C:\Documents and Settings\user\NTUSER.DAT

[2010.01.14 17:27:05 | 00,462,344 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI

[2010.01.14 17:27:05 | 00,395,534 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat

[2010.01.14 17:27:05 | 00,059,774 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat

[2010.01.14 17:26:16 | 00,544,256 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\user\Desktop\o.exe

[2010.01.14 17:23:46 | 00,000,847 | RHS- | M] () -- C:\autorun.inf

[2010.01.14 17:23:14 | 00,121,808 | ---- | M] () -- C:\WINDOWS\System32\ativvaxx.cap

[2010.01.14 17:23:03 | 00,000,484 | ---- | M] () -- C:\WINDOWS\tasks\1-Click Maintenance.job

[2010.01.14 17:23:01 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\System32\rkibaystgfgxxrqztnxqoh.exe

[2010.01.14 17:23:01 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\System32\lcypmiazkhgvtliphzhy.exe

[2010.01.14 17:23:01 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\System32\asphfcvvhffvunltmfogd.exe

[2010.01.14 17:23:00 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\System32\yojzvqhfpljxulhnevc.exe

[2010.01.14 17:22:59 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\System32\xkcpiaojqjepjxqt.exe

[2010.01.14 17:22:59 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\System32\ncwlgaqnwrobxnindt.exe

[2010.01.14 17:22:56 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT

[2010.01.14 17:22:54 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2010.01.13 20:10:43 | 00,000,278 | -HS- | M] () -- C:\Documents and Settings\user\ntuser.ini

[2010.01.13 20:08:04 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\System32\eslztmbxfzvhcrlpe.exe

[2010.01.13 19:01:03 | 00,308,155 | ---- | M] () -- C:\Trojan Scanner.exe

[2010.01.13 18:59:58 | 34,628,928 | ---- | M] (PC Tools ) -- C:\Documents and Settings\user\Desktop\sdsetup.exe

[2010.01.13 18:59:28 | 00,003,901 | ---- | M] () -- C:\Documents and Settings\user\Desktop\gladrag_manhunt™.nfo

[2010.01.13 18:58:49 | 19,567,4112 | ---- | M] () -- C:\Documents and Settings\user\Desktop\Hiren's BootCD 10.0.iso

[2010.01.13 18:22:40 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2010.01.12 17:26:49 | 00,002,443 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SA Dictionary 2008 Beta 4.lnk

[2010.01.12 17:23:44 | 00,001,997 | ---- | M] () -- C:\WINDOWS\unins000.dat

[2010.01.12 17:23:23 | 00,685,358 | ---- | M] () -- C:\WINDOWS\unins000.exe

[2010.01.12 16:40:01 | 00,040,448 | ---- | M] () -- C:\Documents and Settings\user\Desktop\662_pomagalo_com.doc

[2010.01.12 16:32:07 | 00,017,408 | ---- | M] () -- C:\Documents and Settings\user\Desktop\3342_pomagalo_com.doc

[2010.01.10 20:55:20 | 02,106,622 | -H-- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\IconCache.db

[2010.01.08 19:36:17 | 03,148,854 | ---- | M] () -- C:\Documents and Settings\user\Desktop\без име.bmp

[2010.01.08 17:38:05 | 00,002,257 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk

[2009.12.30 19:04:35 | 00,000,333 | -H-- | M] () -- C:\WINDOWS\System32\sevhzqdxdvpzsfxzmzcofrjanhnfzjcphjwjm.pbt

[2009.12.30 19:04:35 | 00,000,333 | -H-- | M] () -- C:\WINDOWS\sevhzqdxdvpzsfxzmzcofrjanhnfzjcphjwjm.pbt

[2009.12.30 19:04:35 | 00,000,333 | -H-- | M] () -- C:\Program Files\sevhzqdxdvpzsfxzmzcofrjanhnfzjcphjwjm.pbt

[2009.12.30 19:04:35 | 00,000,333 | -H-- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\sevhzqdxdvpzsfxzmzcofrjanhnfzjcphjwjm.pbt

[2009.12.30 18:50:38 | 00,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini

[2009.12.30 17:35:01 | 00,004,248 | -H-- | M] () -- C:\WINDOWS\System32\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo

[2009.12.30 17:35:01 | 00,004,248 | -H-- | M] () -- C:\WINDOWS\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo

[2009.12.30 17:35:01 | 00,004,248 | -H-- | M] () -- C:\Program Files\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo

[2009.12.30 17:35:01 | 00,004,248 | -H-- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo

[2009.12.29 23:32:49 | 00,009,216 | ---- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2009.12.29 18:04:33 | 00,000,310 | ---- | M] () -- C:\Documents and Settings\user\My Documents\Моите документи.lnk

[2009.12.28 00:41:42 | 00,000,603 | ---- | M] () -- C:\WINDOWS\win.ini

[2009.12.28 00:41:42 | 00,000,259 | ---- | M] () -- C:\WINDOWS\system.ini

[2009.12.28 00:40:19 | 00,156,910 | ---- | M] () -- C:\WINDOWS\WMSysPr8.prx

[2009.12.28 00:40:16 | 00,000,682 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Cool Edit Pro 2.0.lnk

[2009.12.28 00:21:01 | 00,000,636 | ---- | M] () -- C:\Documents and Settings\user\Desktop\Пряк път до game.lnk

[2009.12.28 00:20:21 | 00,000,845 | ---- | M] () -- C:\Documents and Settings\user\Desktop\Пряк път до NeroStartSmart.lnk

[2009.12.25 23:42:30 | 00,383,646 | ---- | M] () -- C:\Documents and Settings\user\Desktop\ahhaa imeto.jpg

[2009.12.25 23:27:05 | 00,818,658 | ---- | M] () -- C:\Documents and Settings\user\Desktop\facepalming[1].gif

[2009.12.25 20:31:59 | 00,000,504 | ---- | M] () -- C:\Documents and Settings\user\Desktop\Пряк път до nbalive07.lnk

[2009.12.25 17:47:08 | 00,052,224 | ---- | M] () -- C:\Documents and Settings\user\Desktop\PK.xls

[2009.12.16 19:03:47 | 01,502,970 | ---- | M] () -- C:\Documents and Settings\user\Desktop\DogLegHumpPedoBear[1].gif

[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

 

========== Files Created - No Company Name ==========

 

[2010.01.13 19:01:02 | 00,308,155 | ---- | C] () -- C:\Trojan Scanner.exe

[2010.01.13 18:59:28 | 00,003,901 | ---- | C] () -- C:\Documents and Settings\user\Desktop\gladrag_manhunt™.nfo

[2010.01.13 18:58:39 | 19,567,4112 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Hiren's BootCD 10.0.iso

[2010.01.12 17:23:44 | 00,685,358 | ---- | C] () -- C:\WINDOWS\unins000.exe

[2010.01.12 17:23:44 | 00,001,997 | ---- | C] () -- C:\WINDOWS\unins000.dat

[2010.01.12 16:40:00 | 00,040,448 | ---- | C] () -- C:\Documents and Settings\user\Desktop\662_pomagalo_com.doc

[2010.01.12 16:32:07 | 00,017,408 | ---- | C] () -- C:\Documents and Settings\user\Desktop\3342_pomagalo_com.doc

[2010.01.08 19:36:17 | 03,148,854 | ---- | C] () -- C:\Documents and Settings\user\Desktop\без име.bmp

[2009.12.30 17:35:36 | 00,002,408 | -H-- | C] () -- C:\WINDOWS\System32\sanvjwfvxlbhwftrajiqdlzmvlnbrxmvj.qzy

[2009.12.30 17:35:36 | 00,002,408 | -H-- | C] () -- C:\WINDOWS\sanvjwfvxlbhwftrajiqdlzmvlnbrxmvj.qzy

[2009.12.30 17:35:36 | 00,002,408 | -H-- | C] () -- C:\Program Files\sanvjwfvxlbhwftrajiqdlzmvlnbrxmvj.qzy

[2009.12.30 17:35:36 | 00,002,408 | -H-- | C] () -- C:\Documents and Settings\user\Local Settings\Application Data\sanvjwfvxlbhwftrajiqdlzmvlnbrxmvj.qzy

[2009.12.30 17:35:20 | 00,000,847 | RHS- | C] () -- C:\autorun.inf

[2009.12.30 17:35:13 | 00,000,333 | -H-- | C] () -- C:\WINDOWS\System32\sevhzqdxdvpzsfxzmzcofrjanhnfzjcphjwjm.pbt

[2009.12.30 17:35:13 | 00,000,333 | -H-- | C] () -- C:\WINDOWS\sevhzqdxdvpzsfxzmzcofrjanhnfzjcphjwjm.pbt

[2009.12.30 17:35:13 | 00,000,333 | -H-- | C] () -- C:\Program Files\sevhzqdxdvpzsfxzmzcofrjanhnfzjcphjwjm.pbt

[2009.12.30 17:35:13 | 00,000,333 | -H-- | C] () -- C:\Documents and Settings\user\Local Settings\Application Data\sevhzqdxdvpzsfxzmzcofrjanhnfzjcphjwjm.pbt

[2009.12.30 17:35:13 | 00,000,316 | -H-- | C] () -- C:\WINDOWS\System32\paqbsiunsjcldpghtfhsitkamfkbudvhyzlx.kal

[2009.12.30 17:35:13 | 00,000,316 | -H-- | C] () -- C:\WINDOWS\paqbsiunsjcldpghtfhsitkamfkbudvhyzlx.kal

[2009.12.30 17:35:13 | 00,000,316 | -H-- | C] () -- C:\Program Files\paqbsiunsjcldpghtfhsitkamfkbudvhyzlx.kal

[2009.12.30 17:35:13 | 00,000,316 | -H-- | C] () -- C:\Documents and Settings\user\Local Settings\Application Data\paqbsiunsjcldpghtfhsitkamfkbudvhyzlx.kal

[2009.12.30 17:35:01 | 00,004,248 | -H-- | C] () -- C:\WINDOWS\System32\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo

[2009.12.30 17:35:01 | 00,004,248 | -H-- | C] () -- C:\WINDOWS\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo

[2009.12.30 17:35:01 | 00,004,248 | -H-- | C] () -- C:\Program Files\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo

[2009.12.30 17:35:01 | 00,004,248 | -H-- | C] () -- C:\Documents and Settings\user\Local Settings\Application Data\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo

[2009.12.30 17:35:01 | 00,000,280 | -H-- | C] () -- C:\WINDOWS\System32\cadbfihnfjplqpthgfusvtx.zfx

[2009.12.30 17:35:01 | 00,000,280 | -H-- | C] () -- C:\WINDOWS\cadbfihnfjplqpthgfusvtx.zfx

[2009.12.30 17:35:01 | 00,000,280 | -H-- | C] () -- C:\Program Files\cadbfihnfjplqpthgfusvtx.zfx

[2009.12.30 17:35:01 | 00,000,280 | -H-- | C] () -- C:\Documents and Settings\user\Local Settings\Application Data\cadbfihnfjplqpthgfusvtx.zfx

[2009.12.30 17:34:51 | 00,577,536 | RHS- | C] () -- C:\WINDOWS\rkibaystgfgxxrqztnxqoh.exe

[2009.12.30 17:34:51 | 00,577,536 | RHS- | C] () -- C:\WINDOWS\lcypmiazkhgvtliphzhy.exe

[2009.12.30 17:34:51 | 00,577,536 | RHS- | C] () -- C:\WINDOWS\asphfcvvhffvunltmfogd.exe

[2009.12.30 17:34:50 | 00,577,536 | RHS- | C] () -- C:\WINDOWS\yojzvqhfpljxulhnevc.exe

[2009.12.30 17:34:50 | 00,577,536 | RHS- | C] () -- C:\WINDOWS\System32\yojzvqhfpljxulhnevc.exe

[2009.12.30 17:34:50 | 00,577,536 | RHS- | C] () -- C:\WINDOWS\xkcpiaojqjepjxqt.exe

[2009.12.30 17:34:50 | 00,577,536 | RHS- | C] () -- C:\WINDOWS\System32\xkcpiaojqjepjxqt.exe

[2009.12.30 17:34:50 | 00,577,536 | RHS- | C] () -- C:\WINDOWS\System32\rkibaystgfgxxrqztnxqoh.exe

[2009.12.30 17:34:50 | 00,577,536 | RHS- | C] () -- C:\WINDOWS\System32\ncwlgaqnwrobxnindt.exe

[2009.12.30 17:34:50 | 00,577,536 | RHS- | C] () -- C:\WINDOWS\ncwlgaqnwrobxnindt.exe

[2009.12.30 17:34:50 | 00,577,536 | RHS- | C] () -- C:\WINDOWS\System32\lcypmiazkhgvtliphzhy.exe

[2009.12.30 17:34:50 | 00,577,536 | RHS- | C] () -- C:\WINDOWS\System32\eslztmbxfzvhcrlpe.exe

[2009.12.30 17:34:50 | 00,577,536 | RHS- | C] () -- C:\WINDOWS\eslztmbxfzvhcrlpe.exe

[2009.12.30 17:34:50 | 00,577,536 | RHS- | C] () -- C:\WINDOWS\System32\asphfcvvhffvunltmfogd.exe

[2009.12.29 18:04:33 | 00,000,310 | ---- | C] () -- C:\Documents and Settings\user\My Documents\Моите документи.lnk

[2009.12.28 00:40:19 | 00,156,910 | ---- | C] () -- C:\WINDOWS\WMSysPr8.prx

[2009.12.28 00:40:16 | 00,000,682 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Cool Edit Pro 2.0.lnk

[2009.12.28 00:21:01 | 00,000,636 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Пряк път до game.lnk

[2009.12.28 00:20:21 | 00,000,845 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Пряк път до NeroStartSmart.lnk

[2009.12.25 23:42:27 | 00,383,646 | ---- | C] () -- C:\Documents and Settings\user\Desktop\ahhaa imeto.jpg

[2009.12.25 23:27:27 | 00,818,658 | ---- | C] () -- C:\Documents and Settings\user\Desktop\facepalming[1].gif

[2009.12.25 20:31:59 | 00,000,504 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Пряк път до nbalive07.lnk

[2009.12.25 17:47:07 | 00,052,224 | ---- | C] () -- C:\Documents and Settings\user\Desktop\PK.xls

[2009.12.25 17:40:51 | 00,106,496 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Systems.xls

[2009.12.16 19:03:57 | 01,502,970 | ---- | C] () -- C:\Documents and Settings\user\Desktop\DogLegHumpPedoBear[1].gif

[2009.11.21 16:39:45 | 00,000,000 | ---- | C] () -- C:\Program Files\temp01

[2009.11.20 13:18:19 | 00,279,712 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys

[2009.11.20 13:18:18 | 00,025,888 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys

[2009.11.15 19:57:06 | 00,009,216 | ---- | C] () -- C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2009.11.07 22:52:28 | 00,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini

[2009.10.02 17:28:10 | 00,000,000 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI

[2009.10.01 16:50:55 | 00,721,904 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys

[2009.10.01 14:58:19 | 00,000,236 | ---- | C] () -- C:\Program Files\Common Files\dx.reg

[2009.10.01 14:58:18 | 01,029,126 | ---- | C] () -- C:\WINDOWS\System32\d3d10.dll

[2009.10.01 14:58:18 | 00,874,502 | ---- | C] () -- C:\WINDOWS\System32\kernel32new.dll

[2009.10.01 14:58:18 | 00,681,478 | ---- | C] () -- C:\WINDOWS\System32\msvcrtnew.dll

[2009.10.01 14:58:18 | 00,187,398 | ---- | C] () -- C:\WINDOWS\System32\d3d10core.dll

[2009.09.30 15:41:46 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI

[2009.09.30 15:40:14 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\newdll.dll

[2009.09.30 15:35:30 | 00,168,448 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll

[2009.09.30 15:35:30 | 00,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini

[2009.09.30 15:35:29 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll

[2009.09.30 15:35:29 | 00,881,664 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll

[2009.09.30 15:35:29 | 00,205,824 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll

[2009.09.30 15:35:27 | 00,085,504 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll

[2009.09.30 15:35:27 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest

[2009.08.03 00:21:54 | 00,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll

[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll

[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll

[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll

[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll

[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll

[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll

[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll

[2009.08.03 00:21:52 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll

[2009.08.03 00:21:52 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll

[2009.01.16 16:55:38 | 02,854,976 | ---- | C] () -- C:\WINDOWS\System32\btwicons.dll

[2005.02.17 10:41:32 | 00,000,603 | ---- | C] () -- C:\WINDOWS\System32\BTNeighborhood.dll.manifest

[2005.02.17 10:41:30 | 00,000,593 | ---- | C] () -- C:\WINDOWS\System32\btcss.dll.manifest

[2003.01.07 14:05:08 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI

[2001.11.14 11:56:00 | 01,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll

 

========== LOP Check ==========

 

[2009.10.01 16:54:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite

[2009.10.01 08:34:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET

[2009.10.20 14:58:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\KONAMI

[2009.10.14 19:44:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sports Interactive

[2009.11.21 16:53:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP

[2009.09.30 15:37:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TuneUp Software

[2009.09.30 15:37:37 | 00,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}

[2009.11.21 16:40:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Big Fish Games

[2009.10.02 21:47:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\DAEMON Tools Lite

[2009.11.20 13:26:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Games

[2009.10.02 21:57:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Leadertech

[2009.10.29 00:48:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Sports Interactive

[2009.09.30 15:38:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\TuneUp Software

[2010.01.13 19:37:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\uTorrent

[2010.01.14 17:23:03 | 00,000,484 | ---- | M] () -- C:\WINDOWS\Tasks\1-Click Maintenance.job

 

========== Purity Check ==========

 

 

 

========== Alternate Data Streams ==========

 

@Alternate Data Stream - 65 bytes -> C:\Documents and Settings\All Users\Desktop:$ES_DESCRIPTOR_MVPUV1PKSVXJKX69UK1CWPP0DTVNYKM1UVXPJCEPP4DMJ3K1XYE7LRJEM53EPPJCFPLP45168LPSB5PL0EM6REGXHCTVVVVVVVVVVVVV

@Alternate Data Stream - 65 bytes -> C:\Documents and Settings\All Users\Application Data\Sports Interactive:$ES_DESCRIPTOR_MVPUV1PKSVXJKX69UK1CWPP0DTVNYKM1UVXPJCEPP4DMJ3K1XYE7LRJEM53EPPJCFPLP45168LPSB5PL0EM6REGXHCTVVVVVVVVVVVVV

@Alternate Data Stream - 156 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:90D89144

< End of report >

 

Извинявам се за дългия пост.

Link to comment
Сподели другаде

СТЪПКА 1

 

Стартирайте OTL.exe и copy/paste под колонката "Custom Scans/Fixes" въведете това:

 

:OTL

PRC - C:\WINDOWS\system32\eslztmbxfzvhcrlpe.exe ()

PRC - C:\Documents and Settings\user\Local Settings\Temp\lowziq.exe ()

O4 - HKLM..\Run: [KernelFaultCheck] File not found

O4 - HKLM..\Run: [oynxncnfjzrzq] C:\WINDOWS\System32\yojzvqhfpljxulhnevc.exe ()

O4 - HKLM..\Run: [yojzvqhfpljxulhnevc] C:\Documents and Settings\user\Local Settings\Temp\asphfcvvhffvunltmfogd.exe ()

O4 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003..\Run: [oynxncnfjzrzq] C:\Documents and Settings\user\Local Settings\Temp\eslztmbxfzvhcrlpe.exe ()

O4 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003..\Run: [xkcpiaojqjepjxqt] C:\WINDOWS\System32\yojzvqhfpljxulhnevc.exe ()

O4 - HKLM..\RunOnce: [ncwlgaqnwrobxnindt] C:\Documents and Settings\user\Local Settings\Temp\xkcpiaojqjepjxqt.exe ()

O4 - HKLM..\RunOnce: [paqbsiunsjcldp] C:\WINDOWS\System32\yojzvqhfpljxulhnevc.exe ()

O4 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003..\RunOnce: [eslztmbxfzvhcrlpe] C:\WINDOWS\System32\xkcpiaojqjepjxqt.exe ()

O4 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003..\RunOnce: [paqbsiunsjcldp] C:\Documents and Settings\user\Local Settings\Temp\lcypmiazkhgvtliphzhy.exe ()

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: sevhzqdxdvpzsfx = xkcpiaojqjepjxqt.exe ()

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: pymvkyizcrip = C:\DOCUME~1\user\LOCALS~1\Temp\eslztmbxfzvhcrlpe.exe ()

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1

O7 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1

O32 - AutoRun File - [2009.09.30 10:23:08 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O32 - AutoRun File - [2010.01.14 17:23:46 | 00,000,847 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]

O32 - AutoRun File - [2010.01.14 17:23:47 | 00,000,859 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]

O32 - AutoRun File - [2010.01.14 17:23:47 | 00,000,850 | RHS- | M] () - E:\autorun.inf -- [ NTFS ]

O32 - AutoRun File - [2009.08.29 22:59:46 | 00,000,199 | R--- | M] () - F:\autorun.inf -- [ CDFS ]

[2010.01.14 17:31:46 | 00,002,408 | -H-- | M] () -- C:\WINDOWS\System32\sanvjwfvxlbhwftrajiqdlzmvlnbrxmvj.qzy

[2010.01.14 17:31:46 | 00,002,408 | -H-- | M] () -- C:\WINDOWS\sanvjwfvxlbhwftrajiqdlzmvlnbrxmvj.qzy

[2010.01.14 17:31:46 | 00,002,408 | -H-- | M] () -- C:\Program Files\sanvjwfvxlbhwftrajiqdlzmvlnbrxmvj.qzy

[2010.01.14 17:31:46 | 00,002,408 | -H-- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\sanvjwfvxlbhwftrajiqdlzmvlnbrxmvj.qzy

[2010.01.14 17:31:46 | 00,000,280 | -H-- | M] () -- C:\WINDOWS\System32\cadbfihnfjplqpthgfusvtx.zfx

[2010.01.14 17:31:46 | 00,000,280 | -H-- | M] () -- C:\WINDOWS\cadbfihnfjplqpthgfusvtx.zfx

[2010.01.14 17:31:46 | 00,000,280 | -H-- | M] () -- C:\Program Files\cadbfihnfjplqpthgfusvtx.zfx

[2010.01.14 17:31:46 | 00,000,280 | -H-- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\cadbfihnfjplqpthgfusvtx.zfx

[2010.01.14 17:31:28 | 00,000,316 | -H-- | M] () -- C:\WINDOWS\System32\paqbsiunsjcldpghtfhsitkamfkbudvhyzlx.kal

[2010.01.14 17:31:28 | 00,000,316 | -H-- | M] () -- C:\WINDOWS\paqbsiunsjcldpghtfhsitkamfkbudvhyzlx.kal

[2010.01.14 17:31:28 | 00,000,316 | -H-- | M] () -- C:\Program Files\paqbsiunsjcldpghtfhsitkamfkbudvhyzlx.kal

[2010.01.14 17:31:28 | 00,000,316 | -H-- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\paqbsiunsjcldpghtfhsitkamfkbudvhyzlx.kal

[2010.01.14 17:31:04 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\yojzvqhfpljxulhnevc.exe

[2010.01.14 17:31:04 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\xkcpiaojqjepjxqt.exe

[2010.01.14 17:31:04 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\rkibaystgfgxxrqztnxqoh.exe

[2010.01.14 17:31:04 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\ncwlgaqnwrobxnindt.exe

[2010.01.14 17:31:04 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\lcypmiazkhgvtliphzhy.exe

[2010.01.14 17:31:04 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\eslztmbxfzvhcrlpe.exe

[2010.01.14 17:31:04 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\asphfcvvhffvunltmfogd.exe

[2010.01.14 17:23:01 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\System32\rkibaystgfgxxrqztnxqoh.exe

[2010.01.14 17:23:01 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\System32\lcypmiazkhgvtliphzhy.exe

[2010.01.14 17:23:01 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\System32\asphfcvvhffvunltmfogd.exe

[2010.01.14 17:23:00 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\System32\yojzvqhfpljxulhnevc.exe

[2010.01.14 17:22:59 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\System32\xkcpiaojqjepjxqt.exe

[2010.01.14 17:22:59 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\System32\ncwlgaqnwrobxnindt.exe

[2010.01.13 20:08:04 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\System32\eslztmbxfzvhcrlpe.exe

[2009.12.30 19:04:35 | 00,000,333 | -H-- | M] () -- C:\WINDOWS\System32\sevhzqdxdvpzsfxzmzcofrjanhnfzjcphjwjm.pbt

[2009.12.30 19:04:35 | 00,000,333 | -H-- | M] () -- C:\WINDOWS\sevhzqdxdvpzsfxzmzcofrjanhnfzjcphjwjm.pbt

[2009.12.30 19:04:35 | 00,000,333 | -H-- | M] () -- C:\Program Files\sevhzqdxdvpzsfxzmzcofrjanhnfzjcphjwjm.pbt

[2009.12.30 19:04:35 | 00,000,333 | -H-- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\sevhzqdxdvpzsfxzmzcofrjanhnfzjcphjwjm.pbt

[2009.12.30 17:35:01 | 00,004,248 | -H-- | M] () -- C:\WINDOWS\System32\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo

[2009.12.30 17:35:01 | 00,004,248 | -H-- | M] () -- C:\WINDOWS\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo

[2009.12.30 17:35:01 | 00,004,248 | -H-- | M] () -- C:\Program Files\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo

[2009.12.30 17:35:01 | 00,004,248 | -H-- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo

@Alternate Data Stream - 65 bytes -> C:\Documents and Settings\All Users\Desktop:$ES_DESCRIPTOR_MVPUV1PKSVXJKX69UK1CWPP0DTVNYKM1UVXPJCEPP4DMJ3K1XYE7LRJEM53EPPJCFPLP45168LPSB5PL0EM6REGXHCTVVVVVVVVVVVVV

@Alternate Data Stream - 65 bytes -> C:\Documents and Settings\All Users\Application Data\Sports Interactive:$ES_DESCRIPTOR_MVPUV1PKSVXJKX69UK1CWPP0DTVNYKM1UVXPJCEPP4DMJ3K1XYE7LRJEM53EPPJCFPLP45168LPSB5PL0EM6REGXHCTVVVVVVVVVVVVV

@Alternate Data Stream - 156 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:90D89144

:files

C:\WINDOWS\system32\eslztmbxfzvhcrlpe.exe

C:\Documents and Settings\user\Local Settings\Temp\lowziq.exe

C:\WINDOWS\*.tmp

C:\WINDOWS\System32\*.tmp

:Commands

[purity]

[emptytemp]

[Reboot]

 

Натиснете бутона Run Fix

 

Ще се създаде лог файл. Копирайте го в следващия си пост.

 

СТЪПКА 2

 

1) Изтеглете: ESET Online Scanner

2) Стартирайте esetsmartinstaller_enu.exe

3) Сложете отметка на YES, I accept the Terms of Use и изберете Start

4) Скенерът ще започне да изтегля компонентите, които са му необходими.

5) Уверете се, че има отметки на следните редове, включително и тези от менюто Advanced Settings:

 


  • Remove found threats
  • Scan archives
  • Scan for potentially unwanted applications
  • Scan for potentially unsafe applications
  • Enable Anti-Stealth technology

 

И накрая изберете Start

 

6) Скенерът ще започне да изтегля последните дефиниции.

7) След, като сканирането завърши изберете Finish.

8) Отидете в:

C:\Program Files\ESET\ESET Online Scanner

 

Отворете файла log.txt , копирайте съдържанието му и го поставете в следващия си пост тук.

Link to comment
Сподели другаде

All processes killed

========== OTL ==========

No active process named eslztmbxfzvhcrlpe.exe was found!

No active process named lowziq.exe was found!

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck deleted successfully.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\oynxncnfjzrzq deleted successfully.

C:\WINDOWS\system32\yojzvqhfpljxulhnevc.exe moved successfully.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\yojzvqhfpljxulhnevc deleted successfully.

C:\Documents and Settings\user\Local Settings\Temp\asphfcvvhffvunltmfogd.exe moved successfully.

Registry value HKEY_USERS\S-1-5-21-1547161642-362288127-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Run\\oynxncnfjzrzq deleted successfully.

C:\Documents and Settings\user\Local Settings\Temp\eslztmbxfzvhcrlpe.exe moved successfully.

Registry value HKEY_USERS\S-1-5-21-1547161642-362288127-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Run\\xkcpiaojqjepjxqt deleted successfully.

File C:\WINDOWS\System32\yojzvqhfpljxulhnevc.exe not found.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\ncwlgaqnwrobxnindt deleted successfully.

C:\Documents and Settings\user\Local Settings\Temp\xkcpiaojqjepjxqt.exe moved successfully.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\paqbsiunsjcldp deleted successfully.

File C:\WINDOWS\System32\yojzvqhfpljxulhnevc.exe not found.

Registry value HKEY_USERS\S-1-5-21-1547161642-362288127-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\RunOnce\\eslztmbxfzvhcrlpe deleted successfully.

C:\WINDOWS\system32\xkcpiaojqjepjxqt.exe moved successfully.

Registry value HKEY_USERS\S-1-5-21-1547161642-362288127-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\RunOnce\\paqbsiunsjcldp deleted successfully.

C:\Documents and Settings\user\Local Settings\Temp\lcypmiazkhgvtliphzhy.exe moved successfully.

Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\\sevhzqdxdvpzsfx deleted successfully.

C:\WINDOWS\xkcpiaojqjepjxqt.exe moved successfully.

Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\\pymvkyizcrip deleted successfully.

File C:\DOCUME~1\user\LOCALS~1\Temp\eslztmbxfzvhcrlpe.exe not found.

Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools deleted successfully.

Registry value HKEY_USERS\S-1-5-21-1547161642-362288127-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools deleted successfully.

C:\AUTOEXEC.BAT moved successfully.

C:\autorun.inf moved successfully.

D:\autorun.inf moved successfully.

E:\autorun.inf moved successfully.

File move failed. F:\autorun.inf scheduled to be moved on reboot.

C:\WINDOWS\system32\sanvjwfvxlbhwftrajiqdlzmvlnbrxmvj.qzy moved successfully.

C:\WINDOWS\sanvjwfvxlbhwftrajiqdlzmvlnbrxmvj.qzy moved successfully.

C:\Program Files\sanvjwfvxlbhwftrajiqdlzmvlnbrxmvj.qzy moved successfully.

C:\Documents and Settings\user\Local Settings\Application Data\sanvjwfvxlbhwftrajiqdlzmvlnbrxmvj.qzy moved successfully.

C:\WINDOWS\system32\cadbfihnfjplqpthgfusvtx.zfx moved successfully.

C:\WINDOWS\cadbfihnfjplqpthgfusvtx.zfx moved successfully.

C:\Program Files\cadbfihnfjplqpthgfusvtx.zfx moved successfully.

C:\Documents and Settings\user\Local Settings\Application Data\cadbfihnfjplqpthgfusvtx.zfx moved successfully.

C:\WINDOWS\system32\paqbsiunsjcldpghtfhsitkamfkbudvhyzlx.kal moved successfully.

C:\WINDOWS\paqbsiunsjcldpghtfhsitkamfkbudvhyzlx.kal moved successfully.

C:\Program Files\paqbsiunsjcldpghtfhsitkamfkbudvhyzlx.kal moved successfully.

C:\Documents and Settings\user\Local Settings\Application Data\paqbsiunsjcldpghtfhsitkamfkbudvhyzlx.kal moved successfully.

C:\WINDOWS\yojzvqhfpljxulhnevc.exe moved successfully.

File C:\WINDOWS\xkcpiaojqjepjxqt.exe not found.

C:\WINDOWS\rkibaystgfgxxrqztnxqoh.exe moved successfully.

C:\WINDOWS\ncwlgaqnwrobxnindt.exe moved successfully.

C:\WINDOWS\lcypmiazkhgvtliphzhy.exe moved successfully.

C:\WINDOWS\eslztmbxfzvhcrlpe.exe moved successfully.

C:\WINDOWS\asphfcvvhffvunltmfogd.exe moved successfully.

C:\WINDOWS\system32\rkibaystgfgxxrqztnxqoh.exe moved successfully.

C:\WINDOWS\system32\lcypmiazkhgvtliphzhy.exe moved successfully.

C:\WINDOWS\system32\asphfcvvhffvunltmfogd.exe moved successfully.

File C:\WINDOWS\System32\yojzvqhfpljxulhnevc.exe not found.

File C:\WINDOWS\System32\xkcpiaojqjepjxqt.exe not found.

C:\WINDOWS\system32\ncwlgaqnwrobxnindt.exe moved successfully.

C:\WINDOWS\system32\eslztmbxfzvhcrlpe.exe moved successfully.

C:\WINDOWS\system32\sevhzqdxdvpzsfxzmzcofrjanhnfzjcphjwjm.pbt moved successfully.

C:\WINDOWS\sevhzqdxdvpzsfxzmzcofrjanhnfzjcphjwjm.pbt moved successfully.

C:\Program Files\sevhzqdxdvpzsfxzmzcofrjanhnfzjcphjwjm.pbt moved successfully.

C:\Documents and Settings\user\Local Settings\Application Data\sevhzqdxdvpzsfxzmzcofrjanhnfzjcphjwjm.pbt moved successfully.

C:\WINDOWS\system32\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo moved successfully.

C:\WINDOWS\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo moved successfully.

C:\Program Files\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo moved successfully.

C:\Documents and Settings\user\Local Settings\Application Data\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo moved successfully.

ADS C:\Documents and Settings\All Users\Desktop:$ES_DESCRIPTOR_MVPUV1PKSVXJKX69UK1CWPP0DTVNYKM1UVXPJCEPP4DMJ3K1XYE7LRJEM53EPPJCFPLP45168LPSB5PL0EM6REGXHCTVVVVVVVVVVVVV deleted successfully.

ADS C:\Documents and Settings\All Users\Application Data\Sports Interactive:$ES_DESCRIPTOR_MVPUV1PKSVXJKX69UK1CWPP0DTVNYKM1UVXPJCEPP4DMJ3K1XYE7LRJEM53EPPJCFPLP45168LPSB5PL0EM6REGXHCTVVVVVVVVVVVVV deleted successfully.

ADS C:\Documents and Settings\All Users\Application Data\TEMP:90D89144 deleted successfully.

========== FILES ==========

File\Folder C:\WINDOWS\system32\eslztmbxfzvhcrlpe.exe not found.

C:\Documents and Settings\user\Local Settings\Temp\lowziq.exe moved successfully.

C:\WINDOWS\7032E73F68A048F98100E70E79169BAE.TMP folder moved successfully.

C:\WINDOWS\7104189AC5924A56AC9E7C0CA135DA3C.TMP folder moved successfully.

C:\WINDOWS\SET3.tmp moved successfully.

C:\WINDOWS\SET4.tmp moved successfully.

C:\WINDOWS\SET8.tmp moved successfully.

C:\WINDOWS\System32\CONFIG.TMP moved successfully.

========== COMMANDS ==========

 

[EMPTYTEMP]

 

User: All Users

 

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 33170 bytes

 

User: LocalService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 4228125 bytes

 

User: NetworkService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 33237 bytes

 

User: user

->Temp folder emptied: 37261509 bytes

->Temporary Internet Files folder emptied: 2059864104 bytes

->FireFox cache emptied: 84493669 bytes

 

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 0 bytes

%systemroot%\System32 .tmp files removed: 0 bytes

%systemroot%\System32\dllcache .tmp files removed: 0 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 0 bytes

%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes

%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes

RecycleBin emptied: 734835312 bytes

 

Total Files Cleaned = 2 785.00 mb

 

 

OTL by OldTimer - Version 3.1.24.0 log created on 01142010_183923

 

Files\Folders moved on Reboot...

File move failed. F:\autorun.inf scheduled to be moved on reboot.

C:\Documents and Settings\user\Local Settings\Temp\vbqznludfla.exe moved successfully.

 

Registry entries deleted on Reboot...

 

и

 

ESETSmartInstaller@High as downloader log:

all ok

# version=7

# OnlineScannerApp.exe=1.0.0.1

# OnlineScanner.ocx=1.0.0.6211

# api_version=3.0.2

# EOSSerial=1344638c87bf62409ac2e0cdd989e129

# end=finished

# remove_checked=true

# archives_checked=true

# unwanted_checked=true

# unsafe_checked=true

# antistealth_checked=true

# utc_time=2010-01-14 05:30:13

# local_time=2010-01-14 07:30:13 (+0200, FLE Standard Time)

# country="Bulgaria"

# lang=1033

# osver=5.1.2600 NT Service Pack 3

# compatibility_mode=8192 67108863 100 0 3813 3813 0 0

# scanned=131529

# found=33

# cleaned=33

# scan_time=2447

C:\oynxncnfjzrzq.bat Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\sanvjwfvxlb.bat Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\sevhzqdxdvpzsfx.bat Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\Documents and Settings\user\Local Settings\Temp\lowziq.exe a variant of Win32/AutoRun.Agent.TG worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\_OTL\MovedFiles\01142010_183923\C_\autorun.inf INF/Autorun.Gen virus (deleted - quarantined) 00000000000000000000000000000000 C

C:\_OTL\MovedFiles\01142010_183923\C_Documents and Settings\user\Local Settings\Temp\asphfcvvhffvunltmfogd.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\_OTL\MovedFiles\01142010_183923\C_Documents and Settings\user\Local Settings\Temp\eslztmbxfzvhcrlpe.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\_OTL\MovedFiles\01142010_183923\C_Documents and Settings\user\Local Settings\Temp\lcypmiazkhgvtliphzhy.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\_OTL\MovedFiles\01142010_183923\C_Documents and Settings\user\Local Settings\Temp\lowziq.exe a variant of Win32/AutoRun.Agent.TG worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\_OTL\MovedFiles\01142010_183923\C_Documents and Settings\user\Local Settings\Temp\vbqznludfla.exe a variant of Win32/AutoRun.Agent.TG worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\_OTL\MovedFiles\01142010_183923\C_Documents and Settings\user\Local Settings\Temp\xkcpiaojqjepjxqt.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\_OTL\MovedFiles\01142010_183923\C_WINDOWS\asphfcvvhffvunltmfogd.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\_OTL\MovedFiles\01142010_183923\C_WINDOWS\eslztmbxfzvhcrlpe.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\_OTL\MovedFiles\01142010_183923\C_WINDOWS\lcypmiazkhgvtliphzhy.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\_OTL\MovedFiles\01142010_183923\C_WINDOWS\ncwlgaqnwrobxnindt.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\_OTL\MovedFiles\01142010_183923\C_WINDOWS\rkibaystgfgxxrqztnxqoh.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\_OTL\MovedFiles\01142010_183923\C_WINDOWS\xkcpiaojqjepjxqt.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\_OTL\MovedFiles\01142010_183923\C_WINDOWS\yojzvqhfpljxulhnevc.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\_OTL\MovedFiles\01142010_183923\C_WINDOWS\system32\asphfcvvhffvunltmfogd.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\_OTL\MovedFiles\01142010_183923\C_WINDOWS\system32\eslztmbxfzvhcrlpe.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\_OTL\MovedFiles\01142010_183923\C_WINDOWS\system32\lcypmiazkhgvtliphzhy.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\_OTL\MovedFiles\01142010_183923\C_WINDOWS\system32\ncwlgaqnwrobxnindt.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\_OTL\MovedFiles\01142010_183923\C_WINDOWS\system32\rkibaystgfgxxrqztnxqoh.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\_OTL\MovedFiles\01142010_183923\C_WINDOWS\system32\xkcpiaojqjepjxqt.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\_OTL\MovedFiles\01142010_183923\C_WINDOWS\system32\yojzvqhfpljxulhnevc.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\_OTL\MovedFiles\01142010_183923\D_\autorun.inf INF/Autorun.Gen virus (deleted - quarantined) 00000000000000000000000000000000 C

C:\_OTL\MovedFiles\01142010_183923\E_\autorun.inf INF/Autorun.Gen virus (deleted - quarantined) 00000000000000000000000000000000 C

D:\oynxncnfjzrzq.bat Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

D:\sanvjwfvxlb.bat Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

D:\sevhzqdxdvpzsfx.bat Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

E:\oynxncnfjzrzq.bat Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

E:\sanvjwfvxlb.bat Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

E:\sevhzqdxdvpzsfx.bat Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

Link to comment
Сподели другаде

:bravo:

 

СТЪПКА 1

 

Изтеглете SafeBootKeyRepair.exe и го стартирайте.

 

СТЪПКА 2

 

Стартирайт програмата OTL.exe => и натиснете бутона вдясно => CleanUp.

 

http://i47.tinypic.com/35hfp21.jpg

 

СТЪПКА 3

 

Временно спрете System Restore => Десен бутон на My Computer => Properties => System Restore => сложете отметка пред => Turn Off System Restore on all drives.

 

СТЪПКА 4

 

Изтеглете ATF Cleaner

 

* Запазете го на вашия десктоп.

* Кликнете два пъти върху ATF-Cleaner.exe , за да стартирате програмата.

* Кликнете на Select All, който се намира в най-долната част на списъка.

* Махнете отметката пред Prefetch.

* Кликнете на бутона Empty Selected.

 

http://i50.tinypic.com/2v1l0fq.jpg

 

СТЪПКА 5

 

За финал направете една проверка с това.

 

Изтеглете Malwarebytes' Anti-Malware от тук

 

Кликнете два пъти върху mbam-setup.exe за да инсталирате програмата.

 

  • * Уверете се, че има отметки на Update Malwarebytes' Anti-Malware и Launch Malwarebytes' Anti-Malware, след това кликнете на Finish.
    * Ако има намерени по-нови обновления, тя ще ги изтегли и инсталира.
    * Стартирайте програмата и изберете "Perform Quick Scan", след това кликнете на Scan.
    * Сканирането ще отнеме малко време, затова моля бъдете търпеливи.
    * Когато сканирането завърши, кликнете на OK, след това Show Results, за да видите резултата.
    * Уверете се, че на всички редове има отметки, и кликнете Remove Selected.
    * Когато всичко бъде премахнато, логът ще бъде отворен в Notepad. Копирайте лога и го публикувайте в следващия си коментар в темата.

 

Бележка: Ако MalwareBytes' Anti-Malware се затрудни в премахването на откритите вируси/заплахи, той ще поиска да рестартира компютъра Ви и по време на рестартирането да премахне проблемните вируси/заплахи. Ако бъдете попитани, потвърдете че желаете вашия компютър да бъде рестартиран.

 

Как да се предпазите занапред ?

1. Вижте коментар № 22

 

2. Забранене Autoplay/Autorun с Panda USB Vaccine.

 

* Изтеглете Panda USB Vaccine

 

* Натиснете бутона Vaccinate Computer.

 

* Не стартирайте съмнителни файлове получени по Скайп (дори от познати в контакт листата) без преди това да сте ги проверила с антивирусната си програма или на адрес:

 

http://www.virustotal.com

Link to comment
Сподели другаде

Много ти благодаря.Премахнах гадината успешно.Поздрави ! :)

 

Няма проблеми. :)

 

PS: Може ли все пак да публикуваш лог файла от Malwarebytes ?

 

Мерси !

Link to comment
Сподели другаде

Malwarebytes' Anti-Malware 1.44

Версия на базата от данни: 3510

Windows 5.1.2600 Service Pack 3

Internet Explorer 8.0.6001.18702

 

15.01.2010 00:04:05

mbam-log-2010-01-15 (00-04-05).txt

 

Тип сканиране: Бързо сканиране

Сканирани обекти: 107288

Изминало време: 2 minute(s), 59 second(s)

 

Заразени процеси в паметта: 0

Заразени модули в паметта: 0

Заразени ключове в регистратурата: 0

Заразени стойности в регистратурата: 0

Заразени информационни обекти в регистратурата: 0

Заразени папки: 0

Заразени файлове: 0

 

Заразени процеси в паметта:

(Не бяха открити заплахи)

 

Заразени модули в паметта:

(Не бяха открити заплахи)

 

Заразени ключове в регистратурата:

(Не бяха открити заплахи)

 

Заразени стойности в регистратурата:

(Не бяха открити заплахи)

 

Заразени информационни обекти в регистратурата:

(Не бяха открити заплахи)

 

Заразени папки:

(Не бяха открити заплахи)

 

Заразени файлове:

(Не бяха открити заплахи)

 

Заповядай !

Link to comment
Сподели другаде

Благодаря. Това ме интересуваше. Мисля, че системата е вече чиста.

Ако искаш да сме сигурни за финал пусни нов лог от OTL.exe.

При нови проблеми пиши отново.

Лека вечер. :)

Link to comment
Сподели другаде

Би трябвало всичко да е наред ,ето все пак ...

 

TL logfile created on: 15.01.2010 00:37:45 - Run 1

OTL by OldTimer - Version 3.1.24.0 Folder = C:\Documents and Settings\user\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.MM.yyyy

 

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 74.00% Memory free

5.00 Gb Paging File | 4.00 Gb Available in Paging File | 86.00% Paging File free

Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 55.60 Gb Total Space | 39.20 Gb Free Space | 70.51% Space Free | Partition Type: NTFS

Drive D: | 205.08 Gb Total Space | 146.13 Gb Free Space | 71.26% Space Free | Partition Type: NTFS

Drive E: | 205.08 Gb Total Space | 205.01 Gb Free Space | 99.96% Space Free | Partition Type: NTFS

Drive F: | 186.61 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

 

Computer Name: ACER5738

Current User Name: user

Logged in as Administrator.

 

Current Boot Mode: Normal

Scan Mode: All users

Company Name Whitelist: On

Skip Microsoft Files: On

File Age = 30 Days

Output = Minimal

 

========== Processes (SafeList) ==========

 

PRC - C:\Documents and Settings\user\Desktop\OTL.exe (OldTimer Tools)

PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)

PRC - C:\WINDOWS\system32\TUProgSt.exe (TuneUp Software)

PRC - C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)

PRC - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (ESET)

PRC - C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)

PRC - C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)

PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

PRC - C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)

PRC - C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)

PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)

PRC - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)

PRC - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Advanced Micro Devices Inc.)

PRC - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (ATI Technologies Inc.)

PRC - C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)

PRC - C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe (Intel® Corporation)

PRC - C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)

PRC - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)

PRC - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)

PRC - C:\Program Files\Skype\Plugin Manager\skypePM.exe (Skype Technologies)

PRC - C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)

PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)

PRC - C:\WINDOWS\system32\wbem\unsecapp.exe (Microsoft Corporation)

PRC - C:\Program Files\Winamp\winamp.exe (Nullsoft)

PRC - C:\WINDOWS\system32\agrsmsvc.exe (Agere Systems)

PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)

PRC - C:\Program Files\Datecs\FlexType 2K\FType2K.exe ()

 

 

========== Modules (SafeList) ==========

 

MOD - C:\Documents and Settings\user\Desktop\OTL.exe (OldTimer Tools)

MOD - C:\WINDOWS\system32\BtMmHook.dll (Broadcom Corporation.)

MOD - C:\WINDOWS\system32\newdll.dll ()

 

 

========== Win32 Services (SafeList) ==========

 

SRV - (gusvc) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)

SRV - (TuneUp.ProgramStatisticsSvc) -- C:\WINDOWS\system32\TUProgSt.exe (TuneUp Software)

SRV - (TuneUp.Defrag) -- C:\WINDOWS\system32\TuneUpDefragService.exe (TuneUp Software)

SRV - (EHttpSrv) -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe (ESET)

SRV - (ekrn) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (ESET)

SRV - (Ati HotKey Poller) -- C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)

SRV - (btwdins) -- C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)

SRV - (UxTuneUp) -- C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)

SRV - (EvtEng) -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)

SRV - (S24EventMonitor) -- C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)

SRV - (RegSrvc) -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)

SRV - (Irmon) -- C:\WINDOWS\system32\irmon.dll (Microsoft Corporation)

SRV - (AgereModemAudio) -- C:\WINDOWS\system32\agrsmsvc.exe (Agere Systems)

SRV - (ose) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)

 

 

========== Driver Services (SafeList) ==========

 

DRV - (atksgt) -- C:\WINDOWS\system32\drivers\atksgt.sys ()

DRV - (lirsgt) -- C:\WINDOWS\system32\drivers\lirsgt.sys ()

DRV - (hamachi) -- C:\WINDOWS\system32\drivers\hamachi.sys (Applied Networking Inc.)

DRV - (sptd) -- C:\WINDOWS\System32\Drivers\sptd.sys ()

DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)

DRV - (epfwtdir) -- C:\WINDOWS\system32\drivers\epfwtdir.sys (ESET)

DRV - (ehdrv) -- C:\WINDOWS\system32\drivers\ehdrv.sys (ESET)

DRV - (eamon) -- C:\WINDOWS\system32\drivers\eamon.sys (ESET)

DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)

DRV - (BTKRNL) -- C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)

DRV - (RTHDMIAzAudService) -- C:\WINDOWS\system32\drivers\RtHDMI.sys (Realtek Semiconductor Corp.)

DRV - (AtiHdmiService) -- C:\WINDOWS\system32\drivers\AtiHdmi.sys (ATI Research Inc.)

DRV - (BTWUSB) -- C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)

DRV - (NETw5x32) Intel® -- C:\WINDOWS\system32\drivers\NETw5x32.sys (Intel Corporation)

DRV - (k57w2k) Broadcom NetLink -- C:\WINDOWS\system32\drivers\k57xp32.sys (Broadcom Corporation)

DRV - (Ambfilt) -- C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)

DRV - (s24trans) -- C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)

DRV - (BTWDNDIS) -- C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)

DRV - (btaudio) -- C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)

DRV - (HDAudBus) -- C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)

DRV - (Secdrv) -- C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)

DRV - (Ptilink) -- C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)

DRV - (btwhid) -- C:\WINDOWS\system32\drivers\btwhid.sys (Broadcom Corporation.)

DRV - (BTDriver) -- C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)

DRV - (btwmodem) -- C:\WINDOWS\system32\drivers\btwmodem.sys (Broadcom Corporation.)

DRV - (AgereSoftModem) -- C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)

DRV - (PxHelp20) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)

DRV - (DKbFltr) -- C:\WINDOWS\system32\drivers\DKbFltr.SYS (Dritek System Inc.)

DRV - (Monfilt) -- C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)

DRV - (STIrUsb) -- C:\WINDOWS\system32\drivers\irstusb.sys (SigmaTel, Inc.)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

 

 

IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

 

 

IE - HKU\S-1-5-21-1547161642-362288127-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com

IE - HKU\S-1-5-21-1547161642-362288127-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.start.bg/

IE - HKU\S-1-5-21-1547161642-362288127-1801674531-1003\S-1-5-21-1547161642-362288127-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

========== FireFox ==========

 

 

FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2010.01.15 00:15:21 | 00,000,000 | ---D | M]

 

[2009.09.30 15:33:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Mozilla\Extensions

[2009.09.30 15:33:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\ehe3y68v.default\extensions

[2009.12.30 17:46:18 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions

 

O1 HOSTS File: (734 bytes) - C:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)

O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)

O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)

O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O3 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)

O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe (Realtek Semiconductor Corp.)

O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)

O4 - HKLM..\Run: [Google Quick Search Box] C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)

O4 - HKLM..\Run: [intelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)

O4 - HKLM..\Run: [intelZeroConfig] C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe (Intel® Corporation)

O4 - HKLM..\Run: [iSUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)

O4 - HKLM..\Run: [iSUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)

O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)

O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)

O4 - HKLM..\Run: [oynxncnfjzrzq] File not found

O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)

O4 - HKLM..\Run: [startCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)

O4 - HKLM..\Run: [yojzvqhfpljxulhnevc] C:\DOCUME~1\user\LOCALS~1\Temp\xkcpiaojqjepjxqt.exe File not found

O4 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)

O4 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003..\Run: [oynxncnfjzrzq] C:\DOCUME~1\user\LOCALS~1\Temp\lcypmiazkhgvtliphzhy.exe File not found

O4 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003..\Run: [skype] C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)

O4 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)

O4 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003..\Run: [xkcpiaojqjepjxqt] File not found

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\FlexType 2K.lnk = C:\Program Files\Datecs\FlexType 2K\FType2K.exe ()

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: sevhzqdxdvpzsfx = ncwlgaqnwrobxnindt.exe

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: pymvkyizcrip = C:\DOCUME~1\user\LOCALS~1\Temp\xkcpiaojqjepjxqt.exe File not found

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 1

O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll (Google Inc.)

O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()

O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()

O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)

O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()

O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()

O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1

O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)

O24 - Desktop WallPaper: C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O24 - Desktop BackupWallPaper: C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2009.08.29 22:59:46 | 00,000,199 | R--- | M] () - F:\autorun.inf -- [ CDFS ]

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35 - comfile [open] -- "%1" %*

O35 - exefile [open] -- "%1" %*

 

========== Files/Folders - Created Within 30 Days ==========

 

[2010.01.15 00:37:23 | 00,544,256 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\user\Desktop\OTL.exe

[2010.01.15 00:15:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\LastGood

[2010.01.14 21:21:23 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Malwarebytes

[2010.01.14 21:21:20 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys

[2010.01.14 21:21:18 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys

[2010.01.14 21:21:18 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware

[2010.01.14 21:21:18 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes

[2009.12.30 17:46:18 | 00,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox

[2009.12.30 17:46:17 | 00,000,000 | ---D | C] -- C:\Program Files\Skype

[2009.12.28 18:44:11 | 00,000,000 | ---D | C] -- C:\Program Files\WinUHA

[2009.12.28 00:40:29 | 00,000,000 | ---D | C] -- C:\Temp

[2009.12.28 00:40:22 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Syntrillium

[2009.12.28 00:38:54 | 00,000,000 | ---D | C] -- C:\Program Files\coolpro2

[2009.12.25 20:32:17 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\My Documents\NBA LIVE 07

[2009.11.22 20:36:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\ESET

[2009.09.30 14:23:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\Intel

[2009.09.30 14:23:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Intel

[2009.09.30 10:26:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft

[2009.09.30 10:25:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft

[2009.09.30 10:23:06 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft

[2009.09.30 10:23:06 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft

 

========== Files - Modified Within 30 Days ==========

 

[2010.01.15 00:37:37 | 00,544,256 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\user\Desktop\OTL.exe

[2010.01.15 00:00:00 | 00,000,484 | ---- | M] () -- C:\WINDOWS\tasks\1-Click Maintenance.job

[2010.01.14 23:58:42 | 03,932,160 | -H-- | M] () -- C:\Documents and Settings\user\NTUSER.DAT

[2010.01.14 21:37:02 | 00,462,344 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI

[2010.01.14 21:37:02 | 00,395,534 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat

[2010.01.14 21:37:02 | 00,059,774 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat

[2010.01.14 21:33:09 | 00,121,808 | ---- | M] () -- C:\WINDOWS\System32\ativvaxx.cap

[2010.01.14 21:32:56 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT

[2010.01.14 21:32:55 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2010.01.14 21:32:13 | 00,000,278 | -HS- | M] () -- C:\Documents and Settings\user\ntuser.ini

[2010.01.14 21:21:22 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk

[2010.01.14 21:18:15 | 00,065,720 | ---- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

[2010.01.14 21:18:04 | 00,250,288 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2010.01.14 20:13:49 | 00,002,257 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk

[2010.01.14 20:12:52 | 00,002,443 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SA Dictionary 2008 Beta 4.lnk

[2010.01.14 18:41:35 | 00,000,280 | -H-- | M] () -- C:\WINDOWS\System32\cadbfihnfjplqpthgfusvtx.zfx

[2010.01.14 18:41:35 | 00,000,280 | -H-- | M] () -- C:\WINDOWS\cadbfihnfjplqpthgfusvtx.zfx

[2010.01.14 18:41:35 | 00,000,280 | -H-- | M] () -- C:\Program Files\cadbfihnfjplqpthgfusvtx.zfx

[2010.01.14 18:41:35 | 00,000,280 | -H-- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\cadbfihnfjplqpthgfusvtx.zfx

[2010.01.14 18:39:34 | 00,004,248 | -H-- | M] () -- C:\WINDOWS\System32\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo

[2010.01.14 18:39:34 | 00,004,248 | -H-- | M] () -- C:\WINDOWS\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo

[2010.01.14 18:39:34 | 00,004,248 | -H-- | M] () -- C:\Program Files\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo

[2010.01.14 18:39:34 | 00,004,248 | -H-- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo

[2010.01.13 19:01:03 | 00,308,155 | ---- | M] () -- C:\Trojan Scanner.exe

[2010.01.13 18:22:40 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2010.01.12 17:23:44 | 00,001,997 | ---- | M] () -- C:\WINDOWS\unins000.dat

[2010.01.12 17:23:23 | 00,685,358 | ---- | M] () -- C:\WINDOWS\unins000.exe

[2010.01.10 20:55:20 | 02,106,622 | -H-- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\IconCache.db

[2010.01.07 16:07:14 | 00,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys

[2010.01.07 16:07:04 | 00,019,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys

[2009.12.30 18:50:38 | 00,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini

[2009.12.29 23:32:49 | 00,009,216 | ---- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2009.12.29 18:04:33 | 00,000,310 | ---- | M] () -- C:\Documents and Settings\user\My Documents\Моите документи.lnk

[2009.12.28 00:41:42 | 00,000,603 | ---- | M] () -- C:\WINDOWS\win.ini

[2009.12.28 00:41:42 | 00,000,259 | ---- | M] () -- C:\WINDOWS\system.ini

[2009.12.28 00:40:19 | 00,156,910 | ---- | M] () -- C:\WINDOWS\WMSysPr8.prx

[2009.12.28 00:40:16 | 00,000,682 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Cool Edit Pro 2.0.lnk

[2009.12.28 00:20:21 | 00,000,845 | ---- | M] () -- C:\Documents and Settings\user\Desktop\Пряк път до NeroStartSmart.lnk

 

========== Files Created - No Company Name ==========

 

[2010.01.14 21:21:22 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk

[2010.01.14 18:39:34 | 00,004,248 | -H-- | C] () -- C:\WINDOWS\System32\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo

[2010.01.14 18:39:34 | 00,004,248 | -H-- | C] () -- C:\WINDOWS\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo

[2010.01.14 18:39:34 | 00,004,248 | -H-- | C] () -- C:\Program Files\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo

[2010.01.14 18:39:34 | 00,004,248 | -H-- | C] () -- C:\Documents and Settings\user\Local Settings\Application Data\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo

[2010.01.14 18:39:33 | 00,000,280 | -H-- | C] () -- C:\WINDOWS\System32\cadbfihnfjplqpthgfusvtx.zfx

[2010.01.14 18:39:33 | 00,000,280 | -H-- | C] () -- C:\WINDOWS\cadbfihnfjplqpthgfusvtx.zfx

[2010.01.14 18:39:33 | 00,000,280 | -H-- | C] () -- C:\Program Files\cadbfihnfjplqpthgfusvtx.zfx

[2010.01.14 18:39:33 | 00,000,280 | -H-- | C] () -- C:\Documents and Settings\user\Local Settings\Application Data\cadbfihnfjplqpthgfusvtx.zfx

[2010.01.13 19:01:02 | 00,308,155 | ---- | C] () -- C:\Trojan Scanner.exe

[2010.01.12 17:23:44 | 00,685,358 | ---- | C] () -- C:\WINDOWS\unins000.exe

[2010.01.12 17:23:44 | 00,001,997 | ---- | C] () -- C:\WINDOWS\unins000.dat

[2009.12.29 18:04:33 | 00,000,310 | ---- | C] () -- C:\Documents and Settings\user\My Documents\Моите документи.lnk

[2009.12.28 00:40:19 | 00,156,910 | ---- | C] () -- C:\WINDOWS\WMSysPr8.prx

[2009.12.28 00:40:16 | 00,000,682 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Cool Edit Pro 2.0.lnk

[2009.12.28 00:20:21 | 00,000,845 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Пряк път до NeroStartSmart.lnk

[2009.11.21 16:39:45 | 00,000,000 | ---- | C] () -- C:\Program Files\temp01

[2009.11.20 13:18:19 | 00,279,712 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys

[2009.11.20 13:18:18 | 00,025,888 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys

[2009.11.15 19:57:06 | 00,009,216 | ---- | C] () -- C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2009.11.07 22:52:28 | 00,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini

[2009.10.02 17:28:10 | 00,000,000 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI

[2009.10.01 16:50:55 | 00,721,904 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys

[2009.10.01 14:58:19 | 00,000,236 | ---- | C] () -- C:\Program Files\Common Files\dx.reg

[2009.10.01 14:58:18 | 01,029,126 | ---- | C] () -- C:\WINDOWS\System32\d3d10.dll

[2009.10.01 14:58:18 | 00,874,502 | ---- | C] () -- C:\WINDOWS\System32\kernel32new.dll

[2009.10.01 14:58:18 | 00,681,478 | ---- | C] () -- C:\WINDOWS\System32\msvcrtnew.dll

[2009.10.01 14:58:18 | 00,187,398 | ---- | C] () -- C:\WINDOWS\System32\d3d10core.dll

[2009.09.30 15:41:46 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI

[2009.09.30 15:40:14 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\newdll.dll

[2009.09.30 15:35:30 | 00,168,448 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll

[2009.09.30 15:35:30 | 00,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini

[2009.09.30 15:35:29 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll

[2009.09.30 15:35:29 | 00,881,664 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll

[2009.09.30 15:35:29 | 00,205,824 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll

[2009.09.30 15:35:27 | 00,085,504 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll

[2009.09.30 15:35:27 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest

[2009.08.03 00:21:54 | 00,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll

[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll

[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll

[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll

[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll

[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll

[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll

[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll

[2009.08.03 00:21:52 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll

[2009.08.03 00:21:52 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll

[2009.01.16 16:55:38 | 02,854,976 | ---- | C] () -- C:\WINDOWS\System32\btwicons.dll

[2005.02.17 10:41:32 | 00,000,603 | ---- | C] () -- C:\WINDOWS\System32\BTNeighborhood.dll.manifest

[2005.02.17 10:41:30 | 00,000,593 | ---- | C] () -- C:\WINDOWS\System32\btcss.dll.manifest

[2003.01.07 14:05:08 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI

[2001.11.14 11:56:00 | 01,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll

< End of report >

 

OTL Extras logfile created on: 15.01.2010 00:37:45 - Run 1

OTL by OldTimer - Version 3.1.24.0 Folder = C:\Documents and Settings\user\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.MM.yyyy

 

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 74.00% Memory free

5.00 Gb Paging File | 4.00 Gb Available in Paging File | 86.00% Paging File free

Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 55.60 Gb Total Space | 39.20 Gb Free Space | 70.51% Space Free | Partition Type: NTFS

Drive D: | 205.08 Gb Total Space | 146.13 Gb Free Space | 71.26% Space Free | Partition Type: NTFS

Drive E: | 205.08 Gb Total Space | 205.01 Gb Free Space | 99.96% Space Free | Partition Type: NTFS

Drive F: | 186.61 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

 

Computer Name: ACER5738

Current User Name: user

Logged in as Administrator.

 

Current Boot Mode: Normal

Scan Mode: All users

Company Name Whitelist: On

Skip Microsoft Files: On

File Age = 30 Days

Output = Minimal

 

========== Extra Registry (SafeList) ==========

 

 

========== File Associations ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

 

[HKEY_USERS\S-1-5-21-1547161642-362288127-1801674531-1003\SOFTWARE\Classes\<extension>]

.html [@ = FirefoxHTML] -- Reg Error: Key error. File not found

 

========== Shell Spawning ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

exefile [open] -- "%1" %*

htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)

htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)

htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)

http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)

https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)

Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)

Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)

Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)

CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

 

========== Security Center Settings ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"FirstRunDisabled" = 1

"AntiVirusOverride" = 0

"FirewallOverride" = 0

"AntiVirusDisableNotify" = 0

"FirewallDisableNotify" = 0

"UpdatesDisableNotify" = 0

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"EnableFirewall" = 0

 

========== Authorized Applications List ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)

"D:\Games\PES 2010\pes2010.exe" = D:\Games\PES 2010\pes2010.exe:*:Enabled:Pro Evolution Soccer 2010 -- (Konami Digital Entertainment Co., Ltd.)

"D:\Games\PES 2010\PESEdit.exe" = D:\Games\PES 2010\PESEdit.exe:*:Enabled:Pro Evolution Soccer 2010 -- (Konami Digital Entertainment Co., Ltd.)

"D:\Games\FM 2010\fm.exe" = D:\Games\FM 2010\fm.exe:*:Enabled:Football Manager 2010 -- (Sports Interactive)

"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.)

 

 

========== HKEY_LOCAL_MACHINE Uninstall List ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR

"{055A5AF0-9FEB-440D-B00A-18935C7C171C}" = SA Dictionary 2008 Beta 4

"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center

"{11202615-E557-4ECF-9B86-F59C81E52909}" = FIFA 10

"{164086E1-A5DD-3D64-06B1-186005030854}" = CCC Help Korean

"{1800A397-53DF-4F2C-6115-FE2FA9EA69DA}" = ccc-core-static

"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer

"{18625255-5E1D-6BF1-8809-BE4CEE493D52}" = Catalyst Control Center Graphics Full Existing

"{18CD3278-B87E-3026-D38F-38E0A67F2BA4}" = ccc-core-preinstall

"{18D07AC5-417D-4735-BC99-C8E77A7A4195}" = Windows Live Messenger

"{1F126EDC-DA29-4D5B-80DF-735252475FEE}" = Pro Evolution Soccer 2010 DEMO

"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Инструмент за качване на Windows Live

"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT

"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer

"{232AAA95-AE60-46C7-9987-4E7139EA3554}" = Асистент за влизане на Windows Live

"{283FFB23-8751-4B08-ACB8-5E0F8BCF7727}" = Pro Evolution Soccer 2010

"{298F1470-17A2-124A-B615-9A58F90CDA57}" = CCC Help English

"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP

"{368B73EA-A46E-94B1-1B20-24D47B4760F3}" = CCC Help Portuguese

"{3AD20171-A064-C9EC-0C11-5B036FA6F32C}" = CCC Help Dutch

"{3F64C088-9A45-41B3-8B99-71AFAB720A56}" = Sherlock Holmes versus Jack the Ripper

"{4A3EB326-F730-4A71-AEBF-3C7DF7ED716F}" = Тайната на сребърната обица

"{4F0C7CCF-5666-474B-B02E-AC514A95EC93}" = NVIDIA GAME System Software 2.8.1

"{51B83F5C-5660-4B73-AB18-C68993FEDEB3}" = Catalyst Control Center - Branding

"{55A29068-F2CE-456C-9148-C869879E2357}" = TuneUp Utilities 2009

"{5B78DFB0-0FFE-E76F-E51C-FBA53A01085E}" = CCC Help Polish

"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.8

"{6144C1EC-0F4E-6514-E633-85AC3724F082}" = CCC Help Spanish

"{63686BEF-04CA-461C-B364-53BBC322F7BF}" = Sherlock Holmes Nemesis

"{6D144E43-239B-657F-15C5-854EF2C4E55F}" = Catalyst Control Center Core Implementation

"{70701602-56D7-64DF-150D-5459C547E058}" = CCC Help Chinese Traditional

"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0

"{731A3C00-8E73-7893-C15E-4FAFC5787EE5}" = CCC Help Swedish

"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com

"{839011A6-DF28-4E21-00AE-83482775212B}" = NBA LIVE 07

"{84814E6B-2581-46EC-926A-823BD1C670F6}" = Lenovo Bluetooth with Enhanced Data Rate Software

"{875FC2BF-BF34-4F26-B579-CFC7CE2FFAEA}" = ESET NOD32 Antivirus

"{8E371F04-9B92-42A0-A7AF-6678DDB688E1}" = Windows Live Essentials

"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003

"{91B323B5-A79C-4D23-BD6D-046C565F9BCF}" = MadOnion.com/3DMark2001 SE

"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting

"{95991299-E762-2AEA-077D-5DB75E7896C0}" = CCC Help Russian

"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = USB2.0 Card Reader Software

"{9E478F3F-7A7B-42C5-BE9C-40FC0E07665F}" = The Awakened

"{A01D832F-1227-EC5B-6A06-88D53753A789}" = CCC Help Hungarian

"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI

"{A23DD0F0-58E1-7453-9721-760062EF2369}" = CCC Help German

"{A45F3795-1527-47FA-BE1A-2DD242B439E5}_is1" = Need for Speed - Shift

"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable

"{A4F264EA-5851-4684-185F-83C09B678A9C}" = ccc-utility

"{A75C72CA-4D28-C419-5FBA-3762F2344D2F}" = Skins

"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9

"{B0C4DD22-7D91-E56C-F257-37781CC7FFC2}" = Catalyst Control Center Graphics Full New

"{B55E3E57-C706-CFFF-8170-635BB081B3AA}" = CCC Help Greek

"{B7BFA380-2559-B766-85FA-EA02218FD8E7}" = CCC Help Norwegian

"{B9DD8184-8040-1920-D771-3F77AA3131DB}" = CCC Help Chinese Standard

"{BF76EB61-33DA-BBE5-151F-0A1DE5D99A2B}" = CCC Help Japanese

"{C408D81A-CB17-4CDF-98AF-2E64036B3F32}" = Windows Bulgarian Interface Pack

"{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}" = NVIDIA PhysX

"{CC0BD204-465D-B512-E19F-866026F59326}" = CCC Help Italian

"{D02C0FA6-7512-5411-BC81-E910C8AF4A9F}" = CCC Help Thai

"{D1C8DCCF-790D-62AD-ED46-3E5E170B13B2}" = CCC Help Danish

"{D2777D85-7E63-402F-A5E7-2AF436C1C9D4}" = Intel® PROSet/Wireless WiFi Software

"{D27840CA-5F61-7CD3-CDF4-A6EB828CF5D7}" = Catalyst Control Center Localization All

"{D3F07123-C1BE-3BDE-7B29-C6647C3DCE98}" = Catalyst Control Center Graphics Light

"{D9237C88-448A-C1DE-6BA0-EF53462BB1FC}" = CCC Help French

"{E86766EB-5D72-ADFF-D2F0-DE0AB25174CF}" = CCC Help Turkish

"{EA913B24-ED12-1837-C52C-EA58D6ECDB2F}" = CCC Help Czech

"{EBB794ED-D282-4334-92FB-254481EFF514}" = Pro Evolution Soccer 6

"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform

"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard

"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver

"{F36547BF-7B05-1B15-E383-D42BFFD57796}" = CCC Help Finnish

"Adobe AIR" = Adobe AIR

"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX

"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin

"Agere Systems Soft Modem" = Agere Systems HDA Modem

"All ATI Software" = ATI - Software Uninstall Utility

"ATI Display Driver" = ATI Display Driver

"BFGC" = Big Fish Games Client

"BFL_FIFA_10" = BFL_FIFA_10

"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com

"Cool Edit Pro 2.0" = Cool Edit Pro 2.0

"DirectX10_is1" = DirectX10 RC2 Pre Fix 3

"ESET Online Scanner" = ESET Online Scanner v3

"EVEREST Ultimate Edition_is1" = EVEREST Ultimate Edition v5.00

"FIFA 10_is1" = FIFA 10 v1.0 R-E

"FlexType 2K" = FlexType 2K

"Football Manager 2010" = Football Manager 2010

"GOM Player" = GOM Player

"Hamachi" = Hamachi 0.9.9.9

"ie8" = Windows Internet Explorer 8

"InstallShield_{EBB794ED-D282-4334-92FB-254481EFF514}" = Pro Evolution Soccer 6

"KLiteCodecPack_is1" = K-Lite Codec Pack 5.0.0 (Full)

"LManager" = Launch Manager

"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware

"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0

"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition

"NOD32 v3.x FiX 1.1 by TemDono_is1" = NOD32 v3.x FiX 1.1 by TemDono (Free Updates - Expire in 2050)

"PESEdit.com 2010 Patch 0.3.1 with Chants" = PESEdit.com 2010 Patch 0.3.1 with Chants

"ProInst" = Intel PROSet Wireless

"SA Dictionary 2005 T2" = SA Dictionary 2005 T2

"Screen Shot Maker_is1" = Screen Shot Maker 2.5

"TVUPlayer" = TVUPlayer 2.3.4.1

"Veetle TV" = Veetle TV 0.9.15

"Winamp" = Winamp

"Windows Media Format Runtime" = Windows Media Format Runtime

"WinLiveSuite_Wave3" = Windows Live Essentials

"WinRAR archiver" = WinRAR archiver

"WinUHA_is1" = WinUHA 2.0 RC1 (2005.02.27)

 

========== HKEY_USERS Uninstall List ==========

 

[HKEY_USERS\S-1-5-21-1547161642-362288127-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"uTorrent" = µTorrent

 

========== Last 10 Event Log Errors ==========

 

[ Application Events ]

Error - 25.12.2009 11:41:18 | Computer Name = ACER5738 | Source = Application Hang | ID = 1002

Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module

hungapp, version 0.0.0.0, hang address 0x00000000.

 

Error - 25.12.2009 15:20:53 | Computer Name = ACER5738 | Source = Application Error | ID = 1000

Description = Faulting application ati2evxx.exe, version 6.14.10.4220, faulting

module ntdll.dll, version 5.1.2600.5512, fault address 0x000108b3.

 

Error - 26.12.2009 06:35:13 | Computer Name = ACER5738 | Source = Application Hang | ID = 1002

Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module

hungapp, version 0.0.0.0, hang address 0x00000000.

 

Error - 30.12.2009 11:31:17 | Computer Name = ACER5738 | Source = Application Hang | ID = 1002

Description = Hanging application msiexec.exe, version 3.1.4001.5512, hang module

hungapp, version 0.0.0.0, hang address 0x00000000.

 

Error - 08.01.2010 12:57:38 | Computer Name = ACER5738 | Source = Application Error | ID = 1000

Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting

module flash10b.ocx, version 10.0.22.87, fault address 0x001ea9e1.

 

Error - 10.01.2010 12:36:36 | Computer Name = ACER5738 | Source = Application Error | ID = 1000

Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting

module mshtml.dll, version 8.0.6001.18702, fault address 0x0020fbd7.

 

Error - 10.01.2010 12:36:41 | Computer Name = ACER5738 | Source = Application Error | ID = 1000

Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting

module mshtml.dll, version 8.0.6001.18702, fault address 0x0020fbd7.

 

Error - 10.01.2010 12:36:43 | Computer Name = ACER5738 | Source = Application Error | ID = 1001

Description = Fault bucket 1192410865.

 

Error - 10.01.2010 12:37:03 | Computer Name = ACER5738 | Source = Application Error | ID = 1000

Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting

module mshtml.dll, version 8.0.6001.18702, fault address 0x0020fbd7.

 

Error - 10.01.2010 12:37:08 | Computer Name = ACER5738 | Source = Application Error | ID = 1000

Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting

module mshtml.dll, version 8.0.6001.18702, fault address 0x0020fbd7.

 

[ System Events ]

Error - 14.01.2010 12:39:23 | Computer Name = ACER5738 | Source = Service Control Manager | ID = 7034

Description = The Intel® PROSet/Wireless Event Log service terminated unexpectedly.

It has done this 1 time(s).

 

Error - 14.01.2010 12:39:23 | Computer Name = ACER5738 | Source = Service Control Manager | ID = 7034

Description = The Intel® PROSet/Wireless Registry Service service terminated unexpectedly.

It has done this 1 time(s).

 

Error - 14.01.2010 12:39:23 | Computer Name = ACER5738 | Source = Service Control Manager | ID = 7034

Description = The TuneUp Program Statistics Service service terminated unexpectedly.

It has done this 1 time(s).

 

Error - 14.01.2010 12:39:23 | Computer Name = ACER5738 | Source = Service Control Manager | ID = 7034

Description = The Intel® PROSet/Wireless WiFi Service service terminated unexpectedly.

It has done this 1 time(s).

 

Error - 14.01.2010 12:39:23 | Computer Name = ACER5738 | Source = Service Control Manager | ID = 7031

Description = The Bluetooth Service service terminated unexpectedly. It has done

this 1 time(s). The following corrective action will be taken in 60000 milliseconds:

Restart the service.

 

Error - 14.01.2010 12:43:02 | Computer Name = ACER5738 | Source = sr | ID = 1

Description = The System Restore filter encountered the unexpected error '0xC0000034'

while processing the file '_filelst.cfg' on the volume 'HarddiskVolume1'. It has

stopped monitoring the volume.

 

Error - 14.01.2010 12:43:57 | Computer Name = ACER5738 | Source = DCOM | ID = 10016

Description = The machine-default permission settings do not grant Local Activation

permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206}

 

to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission

can be modified using the Component Services administrative tool.

 

Error - 14.01.2010 12:43:57 | Computer Name = ACER5738 | Source = DCOM | ID = 10016

Description = The machine-default permission settings do not grant Local Activation

permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206}

 

to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission

can be modified using the Component Services administrative tool.

 

Error - 14.01.2010 12:43:57 | Computer Name = ACER5738 | Source = DCOM | ID = 10016

Description = The machine-default permission settings do not grant Local Activation

permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206}

 

to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission

can be modified using the Component Services administrative tool.

 

Error - 14.01.2010 15:18:33 | Computer Name = ACER5738 | Source = System Error | ID = 1003

Description = Error code 1000007e, parameter1 c0000005, parameter2 ae3c323a, parameter3

f7042ae0, parameter4 f70427dc.

 

[ TuneUp Events ]

Error - 14.01.2010 15:21:57 | Computer Name = ACER5738 | Source = TuneUp Program Statistics | ID = 131840

Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO

ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-01-14 21:21:57', '\device\harddiskvolume1\program

files\malwarebytes' anti-malware\mbam.exe','3992',0)

 

Error - 14.01.2010 15:33:03 | Computer Name = ACER5738 | Source = TuneUp Program Statistics | ID = 131840

Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO

ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-01-14 21:33:03', '\device\harddiskvolume1\program

files\malwarebytes' anti-malware\mbam.exe','2216',0)

 

Error - 14.01.2010 18:00:21 | Computer Name = ACER5738 | Source = TuneUp Program Statistics | ID = 131840

Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO

ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-01-15 00:00:21', '\device\harddiskvolume1\program

files\malwarebytes' anti-malware\mbam.exe','2344',0)

 

 

< End of report >

 

 

Айде лека вечер !

Link to comment
Сподели другаде

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Гост
Отговори на тази тема

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   Не можете да качите директно снимка. Качете или добавете изображението от линк (URL)

Loading...

×
×
  • Създай ново...