Night_Raven Публикувано Януари 11, 2010 Report Share Публикувано Януари 11, 2010 Откакто нямаш интернет рестартирала ли си компютъра? Цитирай Link to comment Сподели другаде More sharing options...
Zdravec Публикувано Януари 11, 2010 Report Share Публикувано Януари 11, 2010 Проблемът с нета - е оправен - не касаеше вируси и т.н. - смених кабела свързващ рутера и кампа и всичко е наред...ето първият доклад Malwarebytes' Anti-Malware 1.44Версия на базата от данни: 3541Windows 5.1.2600 Service Pack 2Internet Explorer 6.0.2900.2180 2010-01-11 21:45:42mbam-log-2010-01-11 (21-45-42).txt Тип сканиране: Пълно сканиране (C:\|D:\|E:\|)Сканирани обекти: 72717Изминало време: 23 minute(s), 7 second(s) Заразени процеси в паметта: 0Заразени модули в паметта: 0Заразени ключове в регистратурата: 0Заразени стойности в регистратурата: 0Заразени информационни обекти в регистратурата: 0Заразени папки: 0Заразени файлове: 2 Заразени процеси в паметта:(Не бяха открити заплахи) Заразени модули в паметта:(Не бяха открити заплахи) Заразени ключове в регистратурата:(Не бяха открити заплахи) Заразени стойности в регистратурата:(Не бяха открити заплахи) Заразени информационни обекти в регистратурата:(Не бяха открити заплахи) Заразени папки:(Не бяха открити заплахи) Заразени файлове:C:\System Volume Information\_restore{98D17103-31FA-4C4C-A740-934E5D0DEBAA}\RP380\A0036714.sys (Malware.Trace) -> Quarantined and deleted successfully.C:\System Volume Information\_restore{98D17103-31FA-4C4C-A740-934E5D0DEBAA}\RP381\A0036972.sys (Malware.Trace) -> Quarantined and deleted successfully. Цитирай Link to comment Сподели другаде More sharing options...
Night_Raven Публикувано Януари 11, 2010 Report Share Публикувано Януари 11, 2010 Не съм казвал да правиш пълно сканиране. Казах да направиш бързо такова. Сега да не вземеш да направиш и бързо? Няма смисъл. Просто отбелязвам, че не следваш инструкциите както трябва и в някои ситуации своеволията могат да се окажат много опасни, ако гадинката е сериозна. Цитирай Link to comment Сподели другаде More sharing options...
Zdravec Публикувано Януари 11, 2010 Report Share Публикувано Януари 11, 2010 Втората пограма не засече никакви вредители.Предполагам че това е финалът на борбата. Дано с моят случай и твоят опит да се е обагатил и наистина да е било полезно и за теб - Night_Reven. Кажи ми обаче какво да правя с комбо фиксът - да го деинсталирам ли?... а конзолата - може би трябва да прочета нещо за нея - или ще ме посъветваш нещо... Цитирай Link to comment Сподели другаде More sharing options...
Night_Raven Публикувано Януари 11, 2010 Report Share Публикувано Януари 11, 2010 Отвори Start -> Run. В полето пейстни следния текст и кликни OK:"%userprofile%\Desktop\Combo-Fix.exe" /uninstallТова ще деинсталира ComboFix. Горещо ти препоръчвам да инсталираш възможно най-скоро Service Pack 3 за Windows XP и да обновиш Internet Explorer 6 до Internet Explorer 8, както и да инсталираш всички важни обновления за сигурността. Обновената операционна система и софтуер са грабнакът на компютърната сигурност. Ако не ги обновиш, шансът да се заразиш отново е много по-висок, отколкото ако ги обновиш. Допълнителен съвет: добра идея е да премахнеш/деинсталираш MemTurbo. Програмите за освобождаване на памет са пълни боклуци до една и в действителност влошават производителността в повечето случаи. За повече информация по този въпрос и други можеш да прочетеш в тази тема, което също ти препоръчвам да направиш. Цитирай Link to comment Сподели другаде More sharing options...
Zdravec Публикувано Януари 11, 2010 Report Share Публикувано Януари 11, 2010 БЛАГОДАРЯ! За всичко - и за професионализма и за доброто отношение и разбира се за навременната помощ! Желая ти спойна и успешна работа! Цитирай Link to comment Сподели другаде More sharing options...
krasimirson Публикувано Януари 14, 2010 Report Share Публикувано Януари 14, 2010 Здравейте ! Ще цитирам от друго място за проблема ми. "Преди няколко седмици отворих без да искам един линк от скайпа който най-вероятно е от онея спам глупости ,но се оказа много по-лошо ,нещо като някакъв сетъп ,започна да зарежда и го спрях на половината.Проблема е ,че след това много често ми се затварят различни програми сами ,когато съм в my computer и вляза в някой от хард дисковете ,отваря директно нов прозорец.Първата ми работа след това беше да върна системата на Уиндоуса назад ,но когато ми се отвори прозорчето стои точно 2 секунди и се затваря само ... и така всеки път.Също така когато изключвам лаптопа ми излиза ето този ерор "dll error , едикаквоси.exe и отдолу the application failed to initialize because the window station is shutting down".Също така не знам дали си въобразявам ,но скоро забелязах ,че откакто стана това ,нямам НОД 32 ,в папката Есет в програм файлс има някакви глупости ... " Сканирах с програмката "OTL.exe" ,както беше препоръчано по-назад и ето информацяита от двата лога. OTL Extras logfile created on: 14.01.2010 17:31:16 - Run 1OTL by OldTimer - Version 3.1.24.0 Folder = C:\Documents and Settings\user\DesktopWindows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstationInternet Explorer (Version = 8.0.6001.18702)Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.MM.yyyy 3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 80.00% Memory free5.00 Gb Paging File | 4.00 Gb Available in Paging File | 89.00% Paging File freePaging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program FilesDrive C: | 55.60 Gb Total Space | 36.77 Gb Free Space | 66.13% Space Free | Partition Type: NTFSDrive D: | 205.08 Gb Total Space | 146.38 Gb Free Space | 71.38% Space Free | Partition Type: NTFSDrive E: | 205.08 Gb Total Space | 205.01 Gb Free Space | 99.96% Space Free | Partition Type: NTFSDrive F: | 186.61 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFSG: Drive not present or media not loadedH: Drive not present or media not loadedI: Drive not present or media not loaded Computer Name: ACER5738Current User Name: userLogged in as Administrator. Current Boot Mode: NormalScan Mode: All usersCompany Name Whitelist: OnSkip Microsoft Files: OnFile Age = 30 DaysOutput = Minimal ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>].html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) [HKEY_USERS\S-1-5-21-1547161642-362288127-1801674531-1003\SOFTWARE\Classes\<extension>].html [@ = FirefoxHTML] -- Reg Error: Key error. File not found ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]batfile [open] -- "%1" %*cmdfile [open] -- "%1" %*comfile [open] -- "%1" %*exefile [open] -- "%1" %*htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)piffile [open] -- "%1" %*regfile [merge] -- Reg Error: Key error.scrfile [config] -- "%1"scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)scrfile [open] -- "%1" /Stxtfile [edit] -- Reg Error: Key error.Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]"FirstRunDisabled" = 1"AntiVirusDisableNotify" = 1"FirewallDisableNotify" = 1"UpdatesDisableNotify" = 1"AntiVirusOverride" = 0"FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]"EnableFirewall" = 0 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)"D:\Games\PES 2010\pes2010.exe" = D:\Games\PES 2010\pes2010.exe:*:Enabled:Pro Evolution Soccer 2010 -- (Konami Digital Entertainment Co., Ltd.)"D:\Games\PES 2010\PESEdit.exe" = D:\Games\PES 2010\PESEdit.exe:*:Enabled:Pro Evolution Soccer 2010 -- (Konami Digital Entertainment Co., Ltd.)"D:\Games\FM 2010\fm.exe" = D:\Games\FM 2010\fm.exe:*:Enabled:Football Manager 2010 -- (Sports Interactive)"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.) ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR"{055A5AF0-9FEB-440D-B00A-18935C7C171C}" = SA Dictionary 2008 Beta 4"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center"{11202615-E557-4ECF-9B86-F59C81E52909}" = FIFA 10"{164086E1-A5DD-3D64-06B1-186005030854}" = CCC Help Korean"{1800A397-53DF-4F2C-6115-FE2FA9EA69DA}" = ccc-core-static"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer"{18625255-5E1D-6BF1-8809-BE4CEE493D52}" = Catalyst Control Center Graphics Full Existing"{18CD3278-B87E-3026-D38F-38E0A67F2BA4}" = ccc-core-preinstall"{18D07AC5-417D-4735-BC99-C8E77A7A4195}" = Windows Live Messenger"{1F126EDC-DA29-4D5B-80DF-735252475FEE}" = Pro Evolution Soccer 2010 DEMO"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Инструмент за качване на Windows Live"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer"{232AAA95-AE60-46C7-9987-4E7139EA3554}" = Асистент за влизане на Windows Live"{283FFB23-8751-4B08-ACB8-5E0F8BCF7727}" = Pro Evolution Soccer 2010"{298F1470-17A2-124A-B615-9A58F90CDA57}" = CCC Help English"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP"{368B73EA-A46E-94B1-1B20-24D47B4760F3}" = CCC Help Portuguese"{3AD20171-A064-C9EC-0C11-5B036FA6F32C}" = CCC Help Dutch"{3F64C088-9A45-41B3-8B99-71AFAB720A56}" = Sherlock Holmes versus Jack the Ripper"{4A3EB326-F730-4A71-AEBF-3C7DF7ED716F}" = Тайната на сребърната обица"{4F0C7CCF-5666-474B-B02E-AC514A95EC93}" = NVIDIA GAME System Software 2.8.1"{51B83F5C-5660-4B73-AB18-C68993FEDEB3}" = Catalyst Control Center - Branding"{55A29068-F2CE-456C-9148-C869879E2357}" = TuneUp Utilities 2009"{5B78DFB0-0FFE-E76F-E51C-FBA53A01085E}" = CCC Help Polish"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.8"{6144C1EC-0F4E-6514-E633-85AC3724F082}" = CCC Help Spanish"{63686BEF-04CA-461C-B364-53BBC322F7BF}" = Sherlock Holmes Nemesis"{6D144E43-239B-657F-15C5-854EF2C4E55F}" = Catalyst Control Center Core Implementation"{70701602-56D7-64DF-150D-5459C547E058}" = CCC Help Chinese Traditional"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0"{731A3C00-8E73-7893-C15E-4FAFC5787EE5}" = CCC Help Swedish"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com"{839011A6-DF28-4E21-00AE-83482775212B}" = NBA LIVE 07"{84814E6B-2581-46EC-926A-823BD1C670F6}" = Lenovo Bluetooth with Enhanced Data Rate Software"{8E371F04-9B92-42A0-A7AF-6678DDB688E1}" = Windows Live Essentials"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003"{91B323B5-A79C-4D23-BD6D-046C565F9BCF}" = MadOnion.com/3DMark2001 SE"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting"{95991299-E762-2AEA-077D-5DB75E7896C0}" = CCC Help Russian"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = USB2.0 Card Reader Software"{9E478F3F-7A7B-42C5-BE9C-40FC0E07665F}" = The Awakened"{A01D832F-1227-EC5B-6A06-88D53753A789}" = CCC Help Hungarian"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI"{A23DD0F0-58E1-7453-9721-760062EF2369}" = CCC Help German"{A45F3795-1527-47FA-BE1A-2DD242B439E5}_is1" = Need for Speed - Shift"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable"{A4F264EA-5851-4684-185F-83C09B678A9C}" = ccc-utility"{A75C72CA-4D28-C419-5FBA-3762F2344D2F}" = Skins"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9"{B0C4DD22-7D91-E56C-F257-37781CC7FFC2}" = Catalyst Control Center Graphics Full New"{B55E3E57-C706-CFFF-8170-635BB081B3AA}" = CCC Help Greek"{B7BFA380-2559-B766-85FA-EA02218FD8E7}" = CCC Help Norwegian"{B9DD8184-8040-1920-D771-3F77AA3131DB}" = CCC Help Chinese Standard"{BF76EB61-33DA-BBE5-151F-0A1DE5D99A2B}" = CCC Help Japanese"{C408D81A-CB17-4CDF-98AF-2E64036B3F32}" = Windows Bulgarian Interface Pack"{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}" = NVIDIA PhysX"{CC0BD204-465D-B512-E19F-866026F59326}" = CCC Help Italian"{D02C0FA6-7512-5411-BC81-E910C8AF4A9F}" = CCC Help Thai"{D1C8DCCF-790D-62AD-ED46-3E5E170B13B2}" = CCC Help Danish"{D2777D85-7E63-402F-A5E7-2AF436C1C9D4}" = Intel® PROSet/Wireless WiFi Software"{D27840CA-5F61-7CD3-CDF4-A6EB828CF5D7}" = Catalyst Control Center Localization All"{D3F07123-C1BE-3BDE-7B29-C6647C3DCE98}" = Catalyst Control Center Graphics Light"{D9237C88-448A-C1DE-6BA0-EF53462BB1FC}" = CCC Help French"{E86766EB-5D72-ADFF-D2F0-DE0AB25174CF}" = CCC Help Turkish"{EA913B24-ED12-1837-C52C-EA58D6ECDB2F}" = CCC Help Czech"{EBB794ED-D282-4334-92FB-254481EFF514}" = Pro Evolution Soccer 6"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver"{F36547BF-7B05-1B15-E383-D42BFFD57796}" = CCC Help Finnish"Adobe AIR" = Adobe AIR"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin"Agere Systems Soft Modem" = Agere Systems HDA Modem"All ATI Software" = ATI - Software Uninstall Utility"ATI Display Driver" = ATI Display Driver"BFGC" = Big Fish Games Client"BFL_FIFA_10" = BFL_FIFA_10"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com"Cool Edit Pro 2.0" = Cool Edit Pro 2.0"DirectX10_is1" = DirectX10 RC2 Pre Fix 3"EVEREST Ultimate Edition_is1" = EVEREST Ultimate Edition v5.00"FIFA 10_is1" = FIFA 10 v1.0 R-E"FlexType 2K" = FlexType 2K"Football Manager 2010" = Football Manager 2010"GOM Player" = GOM Player"Hamachi" = Hamachi 0.9.9.9"ie8" = Windows Internet Explorer 8"InstallShield_{EBB794ED-D282-4334-92FB-254481EFF514}" = Pro Evolution Soccer 6"KLiteCodecPack_is1" = K-Lite Codec Pack 5.0.0 (Full)"LManager" = Launch Manager"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition"NOD32 v3.x FiX 1.1 by TemDono_is1" = NOD32 v3.x FiX 1.1 by TemDono (Free Updates - Expire in 2050)"PESEdit.com 2010 Patch 0.3.1 with Chants" = PESEdit.com 2010 Patch 0.3.1 with Chants"ProInst" = Intel PROSet Wireless"SA Dictionary 2005 T2" = SA Dictionary 2005 T2"Screen Shot Maker_is1" = Screen Shot Maker 2.5"TVUPlayer" = TVUPlayer 2.3.4.1"Veetle TV" = Veetle TV 0.9.15"Winamp" = Winamp"Windows Media Format Runtime" = Windows Media Format Runtime"WinLiveSuite_Wave3" = Windows Live Essentials"WinRAR archiver" = WinRAR archiver"WinUHA_is1" = WinUHA 2.0 RC1 (2005.02.27) ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-1547161642-362288127-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]"uTorrent" = µTorrent ========== Last 10 Event Log Errors ========== [ Application Events ]Error - 25.12.2009 11:41:18 | Computer Name = ACER5738 | Source = Application Hang | ID = 1002Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 25.12.2009 15:20:53 | Computer Name = ACER5738 | Source = Application Error | ID = 1000Description = Faulting application ati2evxx.exe, version 6.14.10.4220, faulting module ntdll.dll, version 5.1.2600.5512, fault address 0x000108b3. Error - 26.12.2009 06:35:13 | Computer Name = ACER5738 | Source = Application Hang | ID = 1002Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 30.12.2009 11:31:17 | Computer Name = ACER5738 | Source = Application Hang | ID = 1002Description = Hanging application msiexec.exe, version 3.1.4001.5512, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 08.01.2010 12:57:38 | Computer Name = ACER5738 | Source = Application Error | ID = 1000Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting module flash10b.ocx, version 10.0.22.87, fault address 0x001ea9e1. Error - 10.01.2010 12:36:36 | Computer Name = ACER5738 | Source = Application Error | ID = 1000Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting module mshtml.dll, version 8.0.6001.18702, fault address 0x0020fbd7. Error - 10.01.2010 12:36:41 | Computer Name = ACER5738 | Source = Application Error | ID = 1000Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting module mshtml.dll, version 8.0.6001.18702, fault address 0x0020fbd7. Error - 10.01.2010 12:36:43 | Computer Name = ACER5738 | Source = Application Error | ID = 1001Description = Fault bucket 1192410865. Error - 10.01.2010 12:37:03 | Computer Name = ACER5738 | Source = Application Error | ID = 1000Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting module mshtml.dll, version 8.0.6001.18702, fault address 0x0020fbd7. Error - 10.01.2010 12:37:08 | Computer Name = ACER5738 | Source = Application Error | ID = 1000Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting module mshtml.dll, version 8.0.6001.18702, fault address 0x0020fbd7. [ System Events ]Error - 13.01.2010 13:53:18 | Computer Name = ACER5738 | Source = DCOM | ID = 10016Description = The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206} to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission can be modified using the Component Services administrative tool. Error - 13.01.2010 13:53:19 | Computer Name = ACER5738 | Source = DCOM | ID = 10016Description = The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206} to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission can be modified using the Component Services administrative tool. Error - 13.01.2010 13:53:19 | Computer Name = ACER5738 | Source = DCOM | ID = 10016Description = The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206} to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission can be modified using the Component Services administrative tool. Error - 13.01.2010 14:08:10 | Computer Name = ACER5738 | Source = DCOM | ID = 10016Description = The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206} to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission can be modified using the Component Services administrative tool. Error - 13.01.2010 14:08:10 | Computer Name = ACER5738 | Source = DCOM | ID = 10016Description = The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206} to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission can be modified using the Component Services administrative tool. Error - 13.01.2010 14:08:10 | Computer Name = ACER5738 | Source = DCOM | ID = 10016Description = The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206} to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission can be modified using the Component Services administrative tool. Error - 13.01.2010 14:08:18 | Computer Name = ACER5738 | Source = sr | ID = 1Description = The System Restore filter encountered the unexpected error '0xC0000034' while processing the file '_filelst.cfg' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. Error - 14.01.2010 11:23:04 | Computer Name = ACER5738 | Source = DCOM | ID = 10016Description = The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206} to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission can be modified using the Component Services administrative tool. Error - 14.01.2010 11:23:04 | Computer Name = ACER5738 | Source = DCOM | ID = 10016Description = The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206} to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission can be modified using the Component Services administrative tool. Error - 14.01.2010 11:23:04 | Computer Name = ACER5738 | Source = DCOM | ID = 10016Description = The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206} to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission can be modified using the Component Services administrative tool. < End of report > и OTL logfile created on: 14.01.2010 17:31:16 - Run 1OTL by OldTimer - Version 3.1.24.0 Folder = C:\Documents and Settings\user\DesktopWindows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstationInternet Explorer (Version = 8.0.6001.18702)Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.MM.yyyy 3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 80.00% Memory free5.00 Gb Paging File | 4.00 Gb Available in Paging File | 89.00% Paging File freePaging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program FilesDrive C: | 55.60 Gb Total Space | 36.77 Gb Free Space | 66.13% Space Free | Partition Type: NTFSDrive D: | 205.08 Gb Total Space | 146.38 Gb Free Space | 71.38% Space Free | Partition Type: NTFSDrive E: | 205.08 Gb Total Space | 205.01 Gb Free Space | 99.96% Space Free | Partition Type: NTFSDrive F: | 186.61 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFSG: Drive not present or media not loadedH: Drive not present or media not loadedI: Drive not present or media not loaded Computer Name: ACER5738Current User Name: userLogged in as Administrator. Current Boot Mode: NormalScan Mode: All usersCompany Name Whitelist: OnSkip Microsoft Files: OnFile Age = 30 DaysOutput = Minimal ========== Processes (SafeList) ========== PRC - C:\Documents and Settings\user\Desktop\o.exe (OldTimer Tools)PRC - C:\WINDOWS\system32\eslztmbxfzvhcrlpe.exe ()PRC - C:\Documents and Settings\user\Local Settings\Temp\lowziq.exe ()PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)PRC - C:\WINDOWS\system32\TUProgSt.exe (TuneUp Software)PRC - C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)PRC - C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)PRC - C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)PRC - C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)PRC - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)PRC - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Advanced Micro Devices Inc.)PRC - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (ATI Technologies Inc.)PRC - C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)PRC - C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe (Intel® Corporation)PRC - C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)PRC - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)PRC - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)PRC - C:\WINDOWS\system32\wbem\unsecapp.exe (Microsoft Corporation)PRC - C:\WINDOWS\system32\agrsmsvc.exe (Agere Systems)PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)PRC - C:\Program Files\Datecs\FlexType 2K\FType2K.exe () ========== Modules (SafeList) ========== MOD - C:\Documents and Settings\user\Desktop\o.exe (OldTimer Tools)MOD - C:\WINDOWS\system32\BtMmHook.dll (Broadcom Corporation.)MOD - C:\WINDOWS\system32\NetProvCredMan.dll (Intel® Corporation)MOD - C:\WINDOWS\system32\netui1.dll (Microsoft Corporation)MOD - C:\WINDOWS\system32\netui0.dll (Microsoft Corporation)MOD - C:\WINDOWS\system32\ntlanman.dll (Microsoft Corporation)MOD - C:\WINDOWS\system32\davclnt.dll (Microsoft Corporation)MOD - C:\WINDOWS\system32\linkinfo.dll (Microsoft Corporation)MOD - C:\WINDOWS\system32\drprov.dll (Microsoft Corporation)MOD - C:\WINDOWS\system32\netrap.dll (Microsoft Corporation)MOD - C:\WINDOWS\system32\newdll.dll () ========== Win32 Services (SafeList) ========== SRV - (gusvc) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)SRV - (TuneUp.ProgramStatisticsSvc) -- C:\WINDOWS\system32\TUProgSt.exe (TuneUp Software)SRV - (TuneUp.Defrag) -- C:\WINDOWS\system32\TuneUpDefragService.exe (TuneUp Software)SRV - (Ati HotKey Poller) -- C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)SRV - (btwdins) -- C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)SRV - (UxTuneUp) -- C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)SRV - (EvtEng) -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)SRV - (S24EventMonitor) -- C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)SRV - (RegSrvc) -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)SRV - (Irmon) -- C:\WINDOWS\system32\irmon.dll (Microsoft Corporation)SRV - (AgereModemAudio) -- C:\WINDOWS\system32\agrsmsvc.exe (Agere Systems)SRV - (ose) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV - (atksgt) -- C:\WINDOWS\system32\drivers\atksgt.sys ()DRV - (lirsgt) -- C:\WINDOWS\system32\drivers\lirsgt.sys ()DRV - (hamachi) -- C:\WINDOWS\system32\drivers\hamachi.sys (Applied Networking Inc.)DRV - (sptd) -- C:\WINDOWS\System32\Drivers\sptd.sys ()DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)DRV - (BTKRNL) -- C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)DRV - (RTHDMIAzAudService) -- C:\WINDOWS\system32\drivers\RtHDMI.sys (Realtek Semiconductor Corp.)DRV - (AtiHdmiService) -- C:\WINDOWS\system32\drivers\AtiHdmi.sys (ATI Research Inc.)DRV - (BTWUSB) -- C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)DRV - (NETw5x32) Intel® -- C:\WINDOWS\system32\drivers\NETw5x32.sys (Intel Corporation)DRV - (k57w2k) Broadcom NetLink -- C:\WINDOWS\system32\drivers\k57xp32.sys (Broadcom Corporation)DRV - (Ambfilt) -- C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)DRV - (s24trans) -- C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)DRV - (BTWDNDIS) -- C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)DRV - (btaudio) -- C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)DRV - (HDAudBus) -- C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)DRV - (Secdrv) -- C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)DRV - (Ptilink) -- C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)DRV - (btwhid) -- C:\WINDOWS\system32\drivers\btwhid.sys (Broadcom Corporation.)DRV - (BTDriver) -- C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)DRV - (btwmodem) -- C:\WINDOWS\system32\drivers\btwmodem.sys (Broadcom Corporation.)DRV - (AgereSoftModem) -- C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)DRV - (PxHelp20) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)DRV - (DKbFltr) -- C:\WINDOWS\system32\drivers\DKbFltr.SYS (Dritek System Inc.)DRV - (Monfilt) -- C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)DRV - (STIrUsb) -- C:\WINDOWS\system32\drivers\irstusb.sys (SigmaTel, Inc.) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1547161642-362288127-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.comIE - HKU\S-1-5-21-1547161642-362288127-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.start.bg/IE - HKU\S-1-5-21-1547161642-362288127-1801674531-1003\S-1-5-21-1547161642-362288127-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== [2009.09.30 15:33:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Mozilla\Extensions[2009.09.30 15:33:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\ehe3y68v.default\extensions[2009.12.30 17:46:18 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions O1 HOSTS File: (734 bytes) - C:\WINDOWS\system32\drivers\etc\hostsO1 - Hosts: 127.0.0.1 localhostO2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)O3 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe (Realtek Semiconductor Corp.)O4 - HKLM..\Run: [Google Quick Search Box] C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)O4 - HKLM..\Run: [intelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)O4 - HKLM..\Run: [intelZeroConfig] C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe (Intel® Corporation)O4 - HKLM..\Run: [iSUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)O4 - HKLM..\Run: [iSUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)O4 - HKLM..\Run: [KernelFaultCheck] File not foundO4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)O4 - HKLM..\Run: [oynxncnfjzrzq] C:\WINDOWS\System32\yojzvqhfpljxulhnevc.exe ()O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)O4 - HKLM..\Run: [startCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)O4 - HKLM..\Run: [yojzvqhfpljxulhnevc] C:\Documents and Settings\user\Local Settings\Temp\asphfcvvhffvunltmfogd.exe ()O4 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)O4 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003..\Run: [oynxncnfjzrzq] C:\Documents and Settings\user\Local Settings\Temp\eslztmbxfzvhcrlpe.exe ()O4 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003..\Run: [skype] C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)O4 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)O4 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003..\Run: [xkcpiaojqjepjxqt] C:\WINDOWS\System32\yojzvqhfpljxulhnevc.exe ()O4 - HKLM..\RunOnce: [ncwlgaqnwrobxnindt] C:\Documents and Settings\user\Local Settings\Temp\xkcpiaojqjepjxqt.exe ()O4 - HKLM..\RunOnce: [paqbsiunsjcldp] C:\WINDOWS\System32\yojzvqhfpljxulhnevc.exe ()O4 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003..\RunOnce: [eslztmbxfzvhcrlpe] C:\WINDOWS\System32\xkcpiaojqjepjxqt.exe ()O4 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003..\RunOnce: [paqbsiunsjcldp] C:\Documents and Settings\user\Local Settings\Temp\lcypmiazkhgvtliphzhy.exe ()O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\FlexType 2K.lnk = C:\Program Files\Datecs\FlexType 2K\FType2K.exe ()O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 1O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: sevhzqdxdvpzsfx = xkcpiaojqjepjxqt.exe ()O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: pymvkyizcrip = C:\DOCUME~1\user\LOCALS~1\Temp\eslztmbxfzvhcrlpe.exe ()O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 0O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 0O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 0O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 0O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145O7 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 1O7 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll (Google Inc.)O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)O24 - Desktop WallPaper: C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Wallpaper1.bmpO24 - Desktop BackupWallPaper: C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Wallpaper1.bmpO32 - HKLM CDRom: AutoRun - 1O32 - AutoRun File - [2009.09.30 10:23:08 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]O32 - AutoRun File - [2010.01.14 17:23:46 | 00,000,847 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]O32 - AutoRun File - [2010.01.14 17:23:47 | 00,000,859 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]O32 - AutoRun File - [2010.01.14 17:23:47 | 00,000,850 | RHS- | M] () - E:\autorun.inf -- [ NTFS ]O32 - AutoRun File - [2009.08.29 22:59:46 | 00,000,199 | R--- | M] () - F:\autorun.inf -- [ CDFS ]O34 - HKLM BootExecute: (autocheck autochk *) - File not foundO35 - comfile [open] -- "%1" %*O35 - exefile [open] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2010.01.14 17:26:16 | 00,544,256 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\user\Desktop\o.exe[2010.01.13 18:59:26 | 34,628,928 | ---- | C] (PC Tools ) -- C:\Documents and Settings\user\Desktop\sdsetup.exe[2009.12.30 17:46:18 | 00,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox[2009.12.30 17:46:17 | 00,000,000 | ---D | C] -- C:\Program Files\Skype[2009.12.28 18:44:11 | 00,000,000 | ---D | C] -- C:\Program Files\WinUHA[2009.12.28 00:40:29 | 00,000,000 | ---D | C] -- C:\Temp[2009.12.28 00:40:22 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Syntrillium[2009.12.28 00:38:54 | 00,000,000 | ---D | C] -- C:\Program Files\coolpro2[2009.12.25 20:32:17 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\My Documents\NBA LIVE 07[2009.11.22 20:36:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\ESET[2009.09.30 14:23:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\Intel[2009.09.30 14:23:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Intel[2009.09.30 10:26:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft[2009.09.30 10:25:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft[2009.09.30 10:23:06 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft[2009.09.30 10:23:06 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ][1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2010.01.14 17:31:46 | 00,002,408 | -H-- | M] () -- C:\WINDOWS\System32\sanvjwfvxlbhwftrajiqdlzmvlnbrxmvj.qzy[2010.01.14 17:31:46 | 00,002,408 | -H-- | M] () -- C:\WINDOWS\sanvjwfvxlbhwftrajiqdlzmvlnbrxmvj.qzy[2010.01.14 17:31:46 | 00,002,408 | -H-- | M] () -- C:\Program Files\sanvjwfvxlbhwftrajiqdlzmvlnbrxmvj.qzy[2010.01.14 17:31:46 | 00,002,408 | -H-- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\sanvjwfvxlbhwftrajiqdlzmvlnbrxmvj.qzy[2010.01.14 17:31:46 | 00,000,280 | -H-- | M] () -- C:\WINDOWS\System32\cadbfihnfjplqpthgfusvtx.zfx[2010.01.14 17:31:46 | 00,000,280 | -H-- | M] () -- C:\WINDOWS\cadbfihnfjplqpthgfusvtx.zfx[2010.01.14 17:31:46 | 00,000,280 | -H-- | M] () -- C:\Program Files\cadbfihnfjplqpthgfusvtx.zfx[2010.01.14 17:31:46 | 00,000,280 | -H-- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\cadbfihnfjplqpthgfusvtx.zfx[2010.01.14 17:31:28 | 00,000,316 | -H-- | M] () -- C:\WINDOWS\System32\paqbsiunsjcldpghtfhsitkamfkbudvhyzlx.kal[2010.01.14 17:31:28 | 00,000,316 | -H-- | M] () -- C:\WINDOWS\paqbsiunsjcldpghtfhsitkamfkbudvhyzlx.kal[2010.01.14 17:31:28 | 00,000,316 | -H-- | M] () -- C:\Program Files\paqbsiunsjcldpghtfhsitkamfkbudvhyzlx.kal[2010.01.14 17:31:28 | 00,000,316 | -H-- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\paqbsiunsjcldpghtfhsitkamfkbudvhyzlx.kal[2010.01.14 17:31:04 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\yojzvqhfpljxulhnevc.exe[2010.01.14 17:31:04 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\xkcpiaojqjepjxqt.exe[2010.01.14 17:31:04 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\rkibaystgfgxxrqztnxqoh.exe[2010.01.14 17:31:04 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\ncwlgaqnwrobxnindt.exe[2010.01.14 17:31:04 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\lcypmiazkhgvtliphzhy.exe[2010.01.14 17:31:04 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\eslztmbxfzvhcrlpe.exe[2010.01.14 17:31:04 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\asphfcvvhffvunltmfogd.exe[2010.01.14 17:27:48 | 03,932,160 | -H-- | M] () -- C:\Documents and Settings\user\NTUSER.DAT[2010.01.14 17:27:05 | 00,462,344 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI[2010.01.14 17:27:05 | 00,395,534 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat[2010.01.14 17:27:05 | 00,059,774 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat[2010.01.14 17:26:16 | 00,544,256 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\user\Desktop\o.exe[2010.01.14 17:23:46 | 00,000,847 | RHS- | M] () -- C:\autorun.inf[2010.01.14 17:23:14 | 00,121,808 | ---- | M] () -- C:\WINDOWS\System32\ativvaxx.cap[2010.01.14 17:23:03 | 00,000,484 | ---- | M] () -- C:\WINDOWS\tasks\1-Click Maintenance.job[2010.01.14 17:23:01 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\System32\rkibaystgfgxxrqztnxqoh.exe[2010.01.14 17:23:01 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\System32\lcypmiazkhgvtliphzhy.exe[2010.01.14 17:23:01 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\System32\asphfcvvhffvunltmfogd.exe[2010.01.14 17:23:00 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\System32\yojzvqhfpljxulhnevc.exe[2010.01.14 17:22:59 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\System32\xkcpiaojqjepjxqt.exe[2010.01.14 17:22:59 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\System32\ncwlgaqnwrobxnindt.exe[2010.01.14 17:22:56 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT[2010.01.14 17:22:54 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat[2010.01.13 20:10:43 | 00,000,278 | -HS- | M] () -- C:\Documents and Settings\user\ntuser.ini[2010.01.13 20:08:04 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\System32\eslztmbxfzvhcrlpe.exe[2010.01.13 19:01:03 | 00,308,155 | ---- | M] () -- C:\Trojan Scanner.exe[2010.01.13 18:59:58 | 34,628,928 | ---- | M] (PC Tools ) -- C:\Documents and Settings\user\Desktop\sdsetup.exe[2010.01.13 18:59:28 | 00,003,901 | ---- | M] () -- C:\Documents and Settings\user\Desktop\gladrag_manhunt™.nfo[2010.01.13 18:58:49 | 19,567,4112 | ---- | M] () -- C:\Documents and Settings\user\Desktop\Hiren's BootCD 10.0.iso[2010.01.13 18:22:40 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl[2010.01.12 17:26:49 | 00,002,443 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SA Dictionary 2008 Beta 4.lnk[2010.01.12 17:23:44 | 00,001,997 | ---- | M] () -- C:\WINDOWS\unins000.dat[2010.01.12 17:23:23 | 00,685,358 | ---- | M] () -- C:\WINDOWS\unins000.exe[2010.01.12 16:40:01 | 00,040,448 | ---- | M] () -- C:\Documents and Settings\user\Desktop\662_pomagalo_com.doc[2010.01.12 16:32:07 | 00,017,408 | ---- | M] () -- C:\Documents and Settings\user\Desktop\3342_pomagalo_com.doc[2010.01.10 20:55:20 | 02,106,622 | -H-- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\IconCache.db[2010.01.08 19:36:17 | 03,148,854 | ---- | M] () -- C:\Documents and Settings\user\Desktop\без име.bmp[2010.01.08 17:38:05 | 00,002,257 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk[2009.12.30 19:04:35 | 00,000,333 | -H-- | M] () -- C:\WINDOWS\System32\sevhzqdxdvpzsfxzmzcofrjanhnfzjcphjwjm.pbt[2009.12.30 19:04:35 | 00,000,333 | -H-- | M] () -- C:\WINDOWS\sevhzqdxdvpzsfxzmzcofrjanhnfzjcphjwjm.pbt[2009.12.30 19:04:35 | 00,000,333 | -H-- | M] () -- C:\Program Files\sevhzqdxdvpzsfxzmzcofrjanhnfzjcphjwjm.pbt[2009.12.30 19:04:35 | 00,000,333 | -H-- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\sevhzqdxdvpzsfxzmzcofrjanhnfzjcphjwjm.pbt[2009.12.30 18:50:38 | 00,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini[2009.12.30 17:35:01 | 00,004,248 | -H-- | M] () -- C:\WINDOWS\System32\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo[2009.12.30 17:35:01 | 00,004,248 | -H-- | M] () -- C:\WINDOWS\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo[2009.12.30 17:35:01 | 00,004,248 | -H-- | M] () -- C:\Program Files\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo[2009.12.30 17:35:01 | 00,004,248 | -H-- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo[2009.12.29 23:32:49 | 00,009,216 | ---- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini[2009.12.29 18:04:33 | 00,000,310 | ---- | M] () -- C:\Documents and Settings\user\My Documents\Моите документи.lnk[2009.12.28 00:41:42 | 00,000,603 | ---- | M] () -- C:\WINDOWS\win.ini[2009.12.28 00:41:42 | 00,000,259 | ---- | M] () -- C:\WINDOWS\system.ini[2009.12.28 00:40:19 | 00,156,910 | ---- | M] () -- C:\WINDOWS\WMSysPr8.prx[2009.12.28 00:40:16 | 00,000,682 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Cool Edit Pro 2.0.lnk[2009.12.28 00:21:01 | 00,000,636 | ---- | M] () -- C:\Documents and Settings\user\Desktop\Пряк път до game.lnk[2009.12.28 00:20:21 | 00,000,845 | ---- | M] () -- C:\Documents and Settings\user\Desktop\Пряк път до NeroStartSmart.lnk[2009.12.25 23:42:30 | 00,383,646 | ---- | M] () -- C:\Documents and Settings\user\Desktop\ahhaa imeto.jpg[2009.12.25 23:27:05 | 00,818,658 | ---- | M] () -- C:\Documents and Settings\user\Desktop\facepalming[1].gif[2009.12.25 20:31:59 | 00,000,504 | ---- | M] () -- C:\Documents and Settings\user\Desktop\Пряк път до nbalive07.lnk[2009.12.25 17:47:08 | 00,052,224 | ---- | M] () -- C:\Documents and Settings\user\Desktop\PK.xls[2009.12.16 19:03:47 | 01,502,970 | ---- | M] () -- C:\Documents and Settings\user\Desktop\DogLegHumpPedoBear[1].gif[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ][1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files Created - No Company Name ========== [2010.01.13 19:01:02 | 00,308,155 | ---- | C] () -- C:\Trojan Scanner.exe[2010.01.13 18:59:28 | 00,003,901 | ---- | C] () -- C:\Documents and Settings\user\Desktop\gladrag_manhunt™.nfo[2010.01.13 18:58:39 | 19,567,4112 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Hiren's BootCD 10.0.iso[2010.01.12 17:23:44 | 00,685,358 | ---- | C] () -- C:\WINDOWS\unins000.exe[2010.01.12 17:23:44 | 00,001,997 | ---- | C] () -- C:\WINDOWS\unins000.dat[2010.01.12 16:40:00 | 00,040,448 | ---- | C] () -- C:\Documents and Settings\user\Desktop\662_pomagalo_com.doc[2010.01.12 16:32:07 | 00,017,408 | ---- | C] () -- C:\Documents and Settings\user\Desktop\3342_pomagalo_com.doc[2010.01.08 19:36:17 | 03,148,854 | ---- | C] () -- C:\Documents and Settings\user\Desktop\без име.bmp[2009.12.30 17:35:36 | 00,002,408 | -H-- | C] () -- C:\WINDOWS\System32\sanvjwfvxlbhwftrajiqdlzmvlnbrxmvj.qzy[2009.12.30 17:35:36 | 00,002,408 | -H-- | C] () -- C:\WINDOWS\sanvjwfvxlbhwftrajiqdlzmvlnbrxmvj.qzy[2009.12.30 17:35:36 | 00,002,408 | -H-- | C] () -- C:\Program Files\sanvjwfvxlbhwftrajiqdlzmvlnbrxmvj.qzy[2009.12.30 17:35:36 | 00,002,408 | -H-- | C] () -- C:\Documents and Settings\user\Local Settings\Application Data\sanvjwfvxlbhwftrajiqdlzmvlnbrxmvj.qzy[2009.12.30 17:35:20 | 00,000,847 | RHS- | C] () -- C:\autorun.inf[2009.12.30 17:35:13 | 00,000,333 | -H-- | C] () -- C:\WINDOWS\System32\sevhzqdxdvpzsfxzmzcofrjanhnfzjcphjwjm.pbt[2009.12.30 17:35:13 | 00,000,333 | -H-- | C] () -- C:\WINDOWS\sevhzqdxdvpzsfxzmzcofrjanhnfzjcphjwjm.pbt[2009.12.30 17:35:13 | 00,000,333 | -H-- | C] () -- C:\Program Files\sevhzqdxdvpzsfxzmzcofrjanhnfzjcphjwjm.pbt[2009.12.30 17:35:13 | 00,000,333 | -H-- | C] () -- C:\Documents and Settings\user\Local Settings\Application Data\sevhzqdxdvpzsfxzmzcofrjanhnfzjcphjwjm.pbt[2009.12.30 17:35:13 | 00,000,316 | -H-- | C] () -- C:\WINDOWS\System32\paqbsiunsjcldpghtfhsitkamfkbudvhyzlx.kal[2009.12.30 17:35:13 | 00,000,316 | -H-- | C] () -- C:\WINDOWS\paqbsiunsjcldpghtfhsitkamfkbudvhyzlx.kal[2009.12.30 17:35:13 | 00,000,316 | -H-- | C] () -- C:\Program Files\paqbsiunsjcldpghtfhsitkamfkbudvhyzlx.kal[2009.12.30 17:35:13 | 00,000,316 | -H-- | C] () -- C:\Documents and Settings\user\Local Settings\Application Data\paqbsiunsjcldpghtfhsitkamfkbudvhyzlx.kal[2009.12.30 17:35:01 | 00,004,248 | -H-- | C] () -- C:\WINDOWS\System32\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo[2009.12.30 17:35:01 | 00,004,248 | -H-- | C] () -- C:\WINDOWS\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo[2009.12.30 17:35:01 | 00,004,248 | -H-- | C] () -- C:\Program Files\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo[2009.12.30 17:35:01 | 00,004,248 | -H-- | C] () -- C:\Documents and Settings\user\Local Settings\Application Data\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo[2009.12.30 17:35:01 | 00,000,280 | -H-- | C] () -- C:\WINDOWS\System32\cadbfihnfjplqpthgfusvtx.zfx[2009.12.30 17:35:01 | 00,000,280 | -H-- | C] () -- C:\WINDOWS\cadbfihnfjplqpthgfusvtx.zfx[2009.12.30 17:35:01 | 00,000,280 | -H-- | C] () -- C:\Program Files\cadbfihnfjplqpthgfusvtx.zfx[2009.12.30 17:35:01 | 00,000,280 | -H-- | C] () -- C:\Documents and Settings\user\Local Settings\Application Data\cadbfihnfjplqpthgfusvtx.zfx[2009.12.30 17:34:51 | 00,577,536 | RHS- | C] () -- C:\WINDOWS\rkibaystgfgxxrqztnxqoh.exe[2009.12.30 17:34:51 | 00,577,536 | RHS- | C] () -- C:\WINDOWS\lcypmiazkhgvtliphzhy.exe[2009.12.30 17:34:51 | 00,577,536 | RHS- | C] () -- C:\WINDOWS\asphfcvvhffvunltmfogd.exe[2009.12.30 17:34:50 | 00,577,536 | RHS- | C] () -- C:\WINDOWS\yojzvqhfpljxulhnevc.exe[2009.12.30 17:34:50 | 00,577,536 | RHS- | C] () -- C:\WINDOWS\System32\yojzvqhfpljxulhnevc.exe[2009.12.30 17:34:50 | 00,577,536 | RHS- | C] () -- C:\WINDOWS\xkcpiaojqjepjxqt.exe[2009.12.30 17:34:50 | 00,577,536 | RHS- | C] () -- C:\WINDOWS\System32\xkcpiaojqjepjxqt.exe[2009.12.30 17:34:50 | 00,577,536 | RHS- | C] () -- C:\WINDOWS\System32\rkibaystgfgxxrqztnxqoh.exe[2009.12.30 17:34:50 | 00,577,536 | RHS- | C] () -- C:\WINDOWS\System32\ncwlgaqnwrobxnindt.exe[2009.12.30 17:34:50 | 00,577,536 | RHS- | C] () -- C:\WINDOWS\ncwlgaqnwrobxnindt.exe[2009.12.30 17:34:50 | 00,577,536 | RHS- | C] () -- C:\WINDOWS\System32\lcypmiazkhgvtliphzhy.exe[2009.12.30 17:34:50 | 00,577,536 | RHS- | C] () -- C:\WINDOWS\System32\eslztmbxfzvhcrlpe.exe[2009.12.30 17:34:50 | 00,577,536 | RHS- | C] () -- C:\WINDOWS\eslztmbxfzvhcrlpe.exe[2009.12.30 17:34:50 | 00,577,536 | RHS- | C] () -- C:\WINDOWS\System32\asphfcvvhffvunltmfogd.exe[2009.12.29 18:04:33 | 00,000,310 | ---- | C] () -- C:\Documents and Settings\user\My Documents\Моите документи.lnk[2009.12.28 00:40:19 | 00,156,910 | ---- | C] () -- C:\WINDOWS\WMSysPr8.prx[2009.12.28 00:40:16 | 00,000,682 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Cool Edit Pro 2.0.lnk[2009.12.28 00:21:01 | 00,000,636 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Пряк път до game.lnk[2009.12.28 00:20:21 | 00,000,845 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Пряк път до NeroStartSmart.lnk[2009.12.25 23:42:27 | 00,383,646 | ---- | C] () -- C:\Documents and Settings\user\Desktop\ahhaa imeto.jpg[2009.12.25 23:27:27 | 00,818,658 | ---- | C] () -- C:\Documents and Settings\user\Desktop\facepalming[1].gif[2009.12.25 20:31:59 | 00,000,504 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Пряк път до nbalive07.lnk[2009.12.25 17:47:07 | 00,052,224 | ---- | C] () -- C:\Documents and Settings\user\Desktop\PK.xls[2009.12.25 17:40:51 | 00,106,496 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Systems.xls[2009.12.16 19:03:57 | 01,502,970 | ---- | C] () -- C:\Documents and Settings\user\Desktop\DogLegHumpPedoBear[1].gif[2009.11.21 16:39:45 | 00,000,000 | ---- | C] () -- C:\Program Files\temp01[2009.11.20 13:18:19 | 00,279,712 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys[2009.11.20 13:18:18 | 00,025,888 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys[2009.11.15 19:57:06 | 00,009,216 | ---- | C] () -- C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini[2009.11.07 22:52:28 | 00,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini[2009.10.02 17:28:10 | 00,000,000 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI[2009.10.01 16:50:55 | 00,721,904 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys[2009.10.01 14:58:19 | 00,000,236 | ---- | C] () -- C:\Program Files\Common Files\dx.reg[2009.10.01 14:58:18 | 01,029,126 | ---- | C] () -- C:\WINDOWS\System32\d3d10.dll[2009.10.01 14:58:18 | 00,874,502 | ---- | C] () -- C:\WINDOWS\System32\kernel32new.dll[2009.10.01 14:58:18 | 00,681,478 | ---- | C] () -- C:\WINDOWS\System32\msvcrtnew.dll[2009.10.01 14:58:18 | 00,187,398 | ---- | C] () -- C:\WINDOWS\System32\d3d10core.dll[2009.09.30 15:41:46 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI[2009.09.30 15:40:14 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\newdll.dll[2009.09.30 15:35:30 | 00,168,448 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll[2009.09.30 15:35:30 | 00,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini[2009.09.30 15:35:29 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll[2009.09.30 15:35:29 | 00,881,664 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll[2009.09.30 15:35:29 | 00,205,824 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll[2009.09.30 15:35:27 | 00,085,504 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll[2009.09.30 15:35:27 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest[2009.08.03 00:21:54 | 00,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll[2009.08.03 00:21:52 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll[2009.08.03 00:21:52 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll[2009.01.16 16:55:38 | 02,854,976 | ---- | C] () -- C:\WINDOWS\System32\btwicons.dll[2005.02.17 10:41:32 | 00,000,603 | ---- | C] () -- C:\WINDOWS\System32\BTNeighborhood.dll.manifest[2005.02.17 10:41:30 | 00,000,593 | ---- | C] () -- C:\WINDOWS\System32\btcss.dll.manifest[2003.01.07 14:05:08 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI[2001.11.14 11:56:00 | 01,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll ========== LOP Check ========== [2009.10.01 16:54:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite[2009.10.01 08:34:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET[2009.10.20 14:58:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\KONAMI[2009.10.14 19:44:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sports Interactive[2009.11.21 16:53:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP[2009.09.30 15:37:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TuneUp Software[2009.09.30 15:37:37 | 00,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}[2009.11.21 16:40:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Big Fish Games[2009.10.02 21:47:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\DAEMON Tools Lite[2009.11.20 13:26:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Games[2009.10.02 21:57:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Leadertech[2009.10.29 00:48:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Sports Interactive[2009.09.30 15:38:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\TuneUp Software[2010.01.13 19:37:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\uTorrent[2010.01.14 17:23:03 | 00,000,484 | ---- | M] () -- C:\WINDOWS\Tasks\1-Click Maintenance.job ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 65 bytes -> C:\Documents and Settings\All Users\Desktop:$ES_DESCRIPTOR_MVPUV1PKSVXJKX69UK1CWPP0DTVNYKM1UVXPJCEPP4DMJ3K1XYE7LRJEM53EPPJCFPLP45168LPSB5PL0EM6REGXHCTVVVVVVVVVVVVV@Alternate Data Stream - 65 bytes -> C:\Documents and Settings\All Users\Application Data\Sports Interactive:$ES_DESCRIPTOR_MVPUV1PKSVXJKX69UK1CWPP0DTVNYKM1UVXPJCEPP4DMJ3K1XYE7LRJEM53EPPJCFPLP45168LPSB5PL0EM6REGXHCTVVVVVVVVVVVVV@Alternate Data Stream - 156 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:90D89144< End of report > Извинявам се за дългия пост. Цитирай Link to comment Сподели другаде More sharing options...
B-boy/StyLe/ Публикувано Януари 14, 2010 Report Share Публикувано Януари 14, 2010 СТЪПКА 1 Стартирайте OTL.exe и copy/paste под колонката "Custom Scans/Fixes" въведете това: :OTLPRC - C:\WINDOWS\system32\eslztmbxfzvhcrlpe.exe ()PRC - C:\Documents and Settings\user\Local Settings\Temp\lowziq.exe ()O4 - HKLM..\Run: [KernelFaultCheck] File not foundO4 - HKLM..\Run: [oynxncnfjzrzq] C:\WINDOWS\System32\yojzvqhfpljxulhnevc.exe ()O4 - HKLM..\Run: [yojzvqhfpljxulhnevc] C:\Documents and Settings\user\Local Settings\Temp\asphfcvvhffvunltmfogd.exe ()O4 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003..\Run: [oynxncnfjzrzq] C:\Documents and Settings\user\Local Settings\Temp\eslztmbxfzvhcrlpe.exe ()O4 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003..\Run: [xkcpiaojqjepjxqt] C:\WINDOWS\System32\yojzvqhfpljxulhnevc.exe ()O4 - HKLM..\RunOnce: [ncwlgaqnwrobxnindt] C:\Documents and Settings\user\Local Settings\Temp\xkcpiaojqjepjxqt.exe ()O4 - HKLM..\RunOnce: [paqbsiunsjcldp] C:\WINDOWS\System32\yojzvqhfpljxulhnevc.exe ()O4 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003..\RunOnce: [eslztmbxfzvhcrlpe] C:\WINDOWS\System32\xkcpiaojqjepjxqt.exe ()O4 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003..\RunOnce: [paqbsiunsjcldp] C:\Documents and Settings\user\Local Settings\Temp\lcypmiazkhgvtliphzhy.exe ()O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: sevhzqdxdvpzsfx = xkcpiaojqjepjxqt.exe ()O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: pymvkyizcrip = C:\DOCUME~1\user\LOCALS~1\Temp\eslztmbxfzvhcrlpe.exe ()O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1O7 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1O32 - AutoRun File - [2009.09.30 10:23:08 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]O32 - AutoRun File - [2010.01.14 17:23:46 | 00,000,847 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]O32 - AutoRun File - [2010.01.14 17:23:47 | 00,000,859 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]O32 - AutoRun File - [2010.01.14 17:23:47 | 00,000,850 | RHS- | M] () - E:\autorun.inf -- [ NTFS ]O32 - AutoRun File - [2009.08.29 22:59:46 | 00,000,199 | R--- | M] () - F:\autorun.inf -- [ CDFS ][2010.01.14 17:31:46 | 00,002,408 | -H-- | M] () -- C:\WINDOWS\System32\sanvjwfvxlbhwftrajiqdlzmvlnbrxmvj.qzy[2010.01.14 17:31:46 | 00,002,408 | -H-- | M] () -- C:\WINDOWS\sanvjwfvxlbhwftrajiqdlzmvlnbrxmvj.qzy[2010.01.14 17:31:46 | 00,002,408 | -H-- | M] () -- C:\Program Files\sanvjwfvxlbhwftrajiqdlzmvlnbrxmvj.qzy[2010.01.14 17:31:46 | 00,002,408 | -H-- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\sanvjwfvxlbhwftrajiqdlzmvlnbrxmvj.qzy[2010.01.14 17:31:46 | 00,000,280 | -H-- | M] () -- C:\WINDOWS\System32\cadbfihnfjplqpthgfusvtx.zfx[2010.01.14 17:31:46 | 00,000,280 | -H-- | M] () -- C:\WINDOWS\cadbfihnfjplqpthgfusvtx.zfx[2010.01.14 17:31:46 | 00,000,280 | -H-- | M] () -- C:\Program Files\cadbfihnfjplqpthgfusvtx.zfx[2010.01.14 17:31:46 | 00,000,280 | -H-- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\cadbfihnfjplqpthgfusvtx.zfx[2010.01.14 17:31:28 | 00,000,316 | -H-- | M] () -- C:\WINDOWS\System32\paqbsiunsjcldpghtfhsitkamfkbudvhyzlx.kal[2010.01.14 17:31:28 | 00,000,316 | -H-- | M] () -- C:\WINDOWS\paqbsiunsjcldpghtfhsitkamfkbudvhyzlx.kal[2010.01.14 17:31:28 | 00,000,316 | -H-- | M] () -- C:\Program Files\paqbsiunsjcldpghtfhsitkamfkbudvhyzlx.kal[2010.01.14 17:31:28 | 00,000,316 | -H-- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\paqbsiunsjcldpghtfhsitkamfkbudvhyzlx.kal[2010.01.14 17:31:04 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\yojzvqhfpljxulhnevc.exe[2010.01.14 17:31:04 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\xkcpiaojqjepjxqt.exe[2010.01.14 17:31:04 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\rkibaystgfgxxrqztnxqoh.exe[2010.01.14 17:31:04 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\ncwlgaqnwrobxnindt.exe[2010.01.14 17:31:04 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\lcypmiazkhgvtliphzhy.exe[2010.01.14 17:31:04 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\eslztmbxfzvhcrlpe.exe[2010.01.14 17:31:04 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\asphfcvvhffvunltmfogd.exe[2010.01.14 17:23:01 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\System32\rkibaystgfgxxrqztnxqoh.exe[2010.01.14 17:23:01 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\System32\lcypmiazkhgvtliphzhy.exe[2010.01.14 17:23:01 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\System32\asphfcvvhffvunltmfogd.exe[2010.01.14 17:23:00 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\System32\yojzvqhfpljxulhnevc.exe[2010.01.14 17:22:59 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\System32\xkcpiaojqjepjxqt.exe[2010.01.14 17:22:59 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\System32\ncwlgaqnwrobxnindt.exe[2010.01.13 20:08:04 | 00,577,536 | RHS- | M] () -- C:\WINDOWS\System32\eslztmbxfzvhcrlpe.exe[2009.12.30 19:04:35 | 00,000,333 | -H-- | M] () -- C:\WINDOWS\System32\sevhzqdxdvpzsfxzmzcofrjanhnfzjcphjwjm.pbt[2009.12.30 19:04:35 | 00,000,333 | -H-- | M] () -- C:\WINDOWS\sevhzqdxdvpzsfxzmzcofrjanhnfzjcphjwjm.pbt[2009.12.30 19:04:35 | 00,000,333 | -H-- | M] () -- C:\Program Files\sevhzqdxdvpzsfxzmzcofrjanhnfzjcphjwjm.pbt[2009.12.30 19:04:35 | 00,000,333 | -H-- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\sevhzqdxdvpzsfxzmzcofrjanhnfzjcphjwjm.pbt[2009.12.30 17:35:01 | 00,004,248 | -H-- | M] () -- C:\WINDOWS\System32\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo[2009.12.30 17:35:01 | 00,004,248 | -H-- | M] () -- C:\WINDOWS\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo[2009.12.30 17:35:01 | 00,004,248 | -H-- | M] () -- C:\Program Files\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo[2009.12.30 17:35:01 | 00,004,248 | -H-- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo@Alternate Data Stream - 65 bytes -> C:\Documents and Settings\All Users\Desktop:$ES_DESCRIPTOR_MVPUV1PKSVXJKX69UK1CWPP0DTVNYKM1UVXPJCEPP4DMJ3K1XYE7LRJEM53EPPJCFPLP45168LPSB5PL0EM6REGXHCTVVVVVVVVVVVVV@Alternate Data Stream - 65 bytes -> C:\Documents and Settings\All Users\Application Data\Sports Interactive:$ES_DESCRIPTOR_MVPUV1PKSVXJKX69UK1CWPP0DTVNYKM1UVXPJCEPP4DMJ3K1XYE7LRJEM53EPPJCFPLP45168LPSB5PL0EM6REGXHCTVVVVVVVVVVVVV@Alternate Data Stream - 156 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:90D89144:filesC:\WINDOWS\system32\eslztmbxfzvhcrlpe.exeC:\Documents and Settings\user\Local Settings\Temp\lowziq.exeC:\WINDOWS\*.tmpC:\WINDOWS\System32\*.tmp:Commands[purity][emptytemp][Reboot] Натиснете бутона Run Fix Ще се създаде лог файл. Копирайте го в следващия си пост. СТЪПКА 2 1) Изтеглете: ESET Online Scanner2) Стартирайте esetsmartinstaller_enu.exe3) Сложете отметка на YES, I accept the Terms of Use и изберете Start4) Скенерът ще започне да изтегля компонентите, които са му необходими.5) Уверете се, че има отметки на следните редове, включително и тези от менюто Advanced Settings: Remove found threatsScan archivesScan for potentially unwanted applicationsScan for potentially unsafe applicationsEnable Anti-Stealth technology И накрая изберете Start 6) Скенерът ще започне да изтегля последните дефиниции.7) След, като сканирането завърши изберете Finish.8) Отидете в:C:\Program Files\ESET\ESET Online Scanner Отворете файла log.txt , копирайте съдържанието му и го поставете в следващия си пост тук. Цитирай Link to comment Сподели другаде More sharing options...
krasimirson Публикувано Януари 14, 2010 Report Share Публикувано Януари 14, 2010 All processes killed========== OTL ==========No active process named eslztmbxfzvhcrlpe.exe was found!No active process named lowziq.exe was found!Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck deleted successfully.Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\oynxncnfjzrzq deleted successfully.C:\WINDOWS\system32\yojzvqhfpljxulhnevc.exe moved successfully.Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\yojzvqhfpljxulhnevc deleted successfully.C:\Documents and Settings\user\Local Settings\Temp\asphfcvvhffvunltmfogd.exe moved successfully.Registry value HKEY_USERS\S-1-5-21-1547161642-362288127-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Run\\oynxncnfjzrzq deleted successfully.C:\Documents and Settings\user\Local Settings\Temp\eslztmbxfzvhcrlpe.exe moved successfully.Registry value HKEY_USERS\S-1-5-21-1547161642-362288127-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Run\\xkcpiaojqjepjxqt deleted successfully.File C:\WINDOWS\System32\yojzvqhfpljxulhnevc.exe not found.Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\ncwlgaqnwrobxnindt deleted successfully.C:\Documents and Settings\user\Local Settings\Temp\xkcpiaojqjepjxqt.exe moved successfully.Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\paqbsiunsjcldp deleted successfully.File C:\WINDOWS\System32\yojzvqhfpljxulhnevc.exe not found.Registry value HKEY_USERS\S-1-5-21-1547161642-362288127-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\RunOnce\\eslztmbxfzvhcrlpe deleted successfully.C:\WINDOWS\system32\xkcpiaojqjepjxqt.exe moved successfully.Registry value HKEY_USERS\S-1-5-21-1547161642-362288127-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\RunOnce\\paqbsiunsjcldp deleted successfully.C:\Documents and Settings\user\Local Settings\Temp\lcypmiazkhgvtliphzhy.exe moved successfully.Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\\sevhzqdxdvpzsfx deleted successfully.C:\WINDOWS\xkcpiaojqjepjxqt.exe moved successfully.Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\\pymvkyizcrip deleted successfully.File C:\DOCUME~1\user\LOCALS~1\Temp\eslztmbxfzvhcrlpe.exe not found.Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools deleted successfully.Registry value HKEY_USERS\S-1-5-21-1547161642-362288127-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools deleted successfully.C:\AUTOEXEC.BAT moved successfully.C:\autorun.inf moved successfully.D:\autorun.inf moved successfully.E:\autorun.inf moved successfully.File move failed. F:\autorun.inf scheduled to be moved on reboot.C:\WINDOWS\system32\sanvjwfvxlbhwftrajiqdlzmvlnbrxmvj.qzy moved successfully.C:\WINDOWS\sanvjwfvxlbhwftrajiqdlzmvlnbrxmvj.qzy moved successfully.C:\Program Files\sanvjwfvxlbhwftrajiqdlzmvlnbrxmvj.qzy moved successfully.C:\Documents and Settings\user\Local Settings\Application Data\sanvjwfvxlbhwftrajiqdlzmvlnbrxmvj.qzy moved successfully.C:\WINDOWS\system32\cadbfihnfjplqpthgfusvtx.zfx moved successfully.C:\WINDOWS\cadbfihnfjplqpthgfusvtx.zfx moved successfully.C:\Program Files\cadbfihnfjplqpthgfusvtx.zfx moved successfully.C:\Documents and Settings\user\Local Settings\Application Data\cadbfihnfjplqpthgfusvtx.zfx moved successfully.C:\WINDOWS\system32\paqbsiunsjcldpghtfhsitkamfkbudvhyzlx.kal moved successfully.C:\WINDOWS\paqbsiunsjcldpghtfhsitkamfkbudvhyzlx.kal moved successfully.C:\Program Files\paqbsiunsjcldpghtfhsitkamfkbudvhyzlx.kal moved successfully.C:\Documents and Settings\user\Local Settings\Application Data\paqbsiunsjcldpghtfhsitkamfkbudvhyzlx.kal moved successfully.C:\WINDOWS\yojzvqhfpljxulhnevc.exe moved successfully.File C:\WINDOWS\xkcpiaojqjepjxqt.exe not found.C:\WINDOWS\rkibaystgfgxxrqztnxqoh.exe moved successfully.C:\WINDOWS\ncwlgaqnwrobxnindt.exe moved successfully.C:\WINDOWS\lcypmiazkhgvtliphzhy.exe moved successfully.C:\WINDOWS\eslztmbxfzvhcrlpe.exe moved successfully.C:\WINDOWS\asphfcvvhffvunltmfogd.exe moved successfully.C:\WINDOWS\system32\rkibaystgfgxxrqztnxqoh.exe moved successfully.C:\WINDOWS\system32\lcypmiazkhgvtliphzhy.exe moved successfully.C:\WINDOWS\system32\asphfcvvhffvunltmfogd.exe moved successfully.File C:\WINDOWS\System32\yojzvqhfpljxulhnevc.exe not found.File C:\WINDOWS\System32\xkcpiaojqjepjxqt.exe not found.C:\WINDOWS\system32\ncwlgaqnwrobxnindt.exe moved successfully.C:\WINDOWS\system32\eslztmbxfzvhcrlpe.exe moved successfully.C:\WINDOWS\system32\sevhzqdxdvpzsfxzmzcofrjanhnfzjcphjwjm.pbt moved successfully.C:\WINDOWS\sevhzqdxdvpzsfxzmzcofrjanhnfzjcphjwjm.pbt moved successfully.C:\Program Files\sevhzqdxdvpzsfxzmzcofrjanhnfzjcphjwjm.pbt moved successfully.C:\Documents and Settings\user\Local Settings\Application Data\sevhzqdxdvpzsfxzmzcofrjanhnfzjcphjwjm.pbt moved successfully.C:\WINDOWS\system32\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo moved successfully.C:\WINDOWS\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo moved successfully.C:\Program Files\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo moved successfully.C:\Documents and Settings\user\Local Settings\Application Data\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo moved successfully.ADS C:\Documents and Settings\All Users\Desktop:$ES_DESCRIPTOR_MVPUV1PKSVXJKX69UK1CWPP0DTVNYKM1UVXPJCEPP4DMJ3K1XYE7LRJEM53EPPJCFPLP45168LPSB5PL0EM6REGXHCTVVVVVVVVVVVVV deleted successfully.ADS C:\Documents and Settings\All Users\Application Data\Sports Interactive:$ES_DESCRIPTOR_MVPUV1PKSVXJKX69UK1CWPP0DTVNYKM1UVXPJCEPP4DMJ3K1XYE7LRJEM53EPPJCFPLP45168LPSB5PL0EM6REGXHCTVVVVVVVVVVVVV deleted successfully.ADS C:\Documents and Settings\All Users\Application Data\TEMP:90D89144 deleted successfully.========== FILES ==========File\Folder C:\WINDOWS\system32\eslztmbxfzvhcrlpe.exe not found.C:\Documents and Settings\user\Local Settings\Temp\lowziq.exe moved successfully.C:\WINDOWS\7032E73F68A048F98100E70E79169BAE.TMP folder moved successfully.C:\WINDOWS\7104189AC5924A56AC9E7C0CA135DA3C.TMP folder moved successfully.C:\WINDOWS\SET3.tmp moved successfully.C:\WINDOWS\SET4.tmp moved successfully.C:\WINDOWS\SET8.tmp moved successfully.C:\WINDOWS\System32\CONFIG.TMP moved successfully.========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User->Temp folder emptied: 0 bytes->Temporary Internet Files folder emptied: 33170 bytes User: LocalService->Temp folder emptied: 0 bytes->Temporary Internet Files folder emptied: 4228125 bytes User: NetworkService->Temp folder emptied: 0 bytes->Temporary Internet Files folder emptied: 33237 bytes User: user->Temp folder emptied: 37261509 bytes->Temporary Internet Files folder emptied: 2059864104 bytes->FireFox cache emptied: 84493669 bytes %systemdrive% .tmp files removed: 0 bytes%systemroot% .tmp files removed: 0 bytes%systemroot%\System32 .tmp files removed: 0 bytes%systemroot%\System32\dllcache .tmp files removed: 0 bytes%systemroot%\System32\drivers .tmp files removed: 0 bytesWindows Temp folder emptied: 0 bytes%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytesRecycleBin emptied: 734835312 bytes Total Files Cleaned = 2 785.00 mb OTL by OldTimer - Version 3.1.24.0 log created on 01142010_183923 Files\Folders moved on Reboot...File move failed. F:\autorun.inf scheduled to be moved on reboot.C:\Documents and Settings\user\Local Settings\Temp\vbqznludfla.exe moved successfully. Registry entries deleted on Reboot... и ESETSmartInstaller@High as downloader log:all ok# version=7# OnlineScannerApp.exe=1.0.0.1# OnlineScanner.ocx=1.0.0.6211# api_version=3.0.2# EOSSerial=1344638c87bf62409ac2e0cdd989e129# end=finished# remove_checked=true# archives_checked=true# unwanted_checked=true# unsafe_checked=true# antistealth_checked=true# utc_time=2010-01-14 05:30:13# local_time=2010-01-14 07:30:13 (+0200, FLE Standard Time)# country="Bulgaria"# lang=1033# osver=5.1.2600 NT Service Pack 3# compatibility_mode=8192 67108863 100 0 3813 3813 0 0# scanned=131529# found=33# cleaned=33# scan_time=2447C:\oynxncnfjzrzq.bat Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 CC:\sanvjwfvxlb.bat Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 CC:\sevhzqdxdvpzsfx.bat Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 CC:\Documents and Settings\user\Local Settings\Temp\lowziq.exe a variant of Win32/AutoRun.Agent.TG worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 CC:\_OTL\MovedFiles\01142010_183923\C_\autorun.inf INF/Autorun.Gen virus (deleted - quarantined) 00000000000000000000000000000000 CC:\_OTL\MovedFiles\01142010_183923\C_Documents and Settings\user\Local Settings\Temp\asphfcvvhffvunltmfogd.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 CC:\_OTL\MovedFiles\01142010_183923\C_Documents and Settings\user\Local Settings\Temp\eslztmbxfzvhcrlpe.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 CC:\_OTL\MovedFiles\01142010_183923\C_Documents and Settings\user\Local Settings\Temp\lcypmiazkhgvtliphzhy.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 CC:\_OTL\MovedFiles\01142010_183923\C_Documents and Settings\user\Local Settings\Temp\lowziq.exe a variant of Win32/AutoRun.Agent.TG worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 CC:\_OTL\MovedFiles\01142010_183923\C_Documents and Settings\user\Local Settings\Temp\vbqznludfla.exe a variant of Win32/AutoRun.Agent.TG worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 CC:\_OTL\MovedFiles\01142010_183923\C_Documents and Settings\user\Local Settings\Temp\xkcpiaojqjepjxqt.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 CC:\_OTL\MovedFiles\01142010_183923\C_WINDOWS\asphfcvvhffvunltmfogd.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 CC:\_OTL\MovedFiles\01142010_183923\C_WINDOWS\eslztmbxfzvhcrlpe.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 CC:\_OTL\MovedFiles\01142010_183923\C_WINDOWS\lcypmiazkhgvtliphzhy.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 CC:\_OTL\MovedFiles\01142010_183923\C_WINDOWS\ncwlgaqnwrobxnindt.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 CC:\_OTL\MovedFiles\01142010_183923\C_WINDOWS\rkibaystgfgxxrqztnxqoh.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 CC:\_OTL\MovedFiles\01142010_183923\C_WINDOWS\xkcpiaojqjepjxqt.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 CC:\_OTL\MovedFiles\01142010_183923\C_WINDOWS\yojzvqhfpljxulhnevc.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 CC:\_OTL\MovedFiles\01142010_183923\C_WINDOWS\system32\asphfcvvhffvunltmfogd.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 CC:\_OTL\MovedFiles\01142010_183923\C_WINDOWS\system32\eslztmbxfzvhcrlpe.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 CC:\_OTL\MovedFiles\01142010_183923\C_WINDOWS\system32\lcypmiazkhgvtliphzhy.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 CC:\_OTL\MovedFiles\01142010_183923\C_WINDOWS\system32\ncwlgaqnwrobxnindt.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 CC:\_OTL\MovedFiles\01142010_183923\C_WINDOWS\system32\rkibaystgfgxxrqztnxqoh.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 CC:\_OTL\MovedFiles\01142010_183923\C_WINDOWS\system32\xkcpiaojqjepjxqt.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 CC:\_OTL\MovedFiles\01142010_183923\C_WINDOWS\system32\yojzvqhfpljxulhnevc.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 CC:\_OTL\MovedFiles\01142010_183923\D_\autorun.inf INF/Autorun.Gen virus (deleted - quarantined) 00000000000000000000000000000000 CC:\_OTL\MovedFiles\01142010_183923\E_\autorun.inf INF/Autorun.Gen virus (deleted - quarantined) 00000000000000000000000000000000 CD:\oynxncnfjzrzq.bat Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 CD:\sanvjwfvxlb.bat Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 CD:\sevhzqdxdvpzsfx.bat Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 CE:\oynxncnfjzrzq.bat Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 CE:\sanvjwfvxlb.bat Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 CE:\sevhzqdxdvpzsfx.bat Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C Цитирай Link to comment Сподели другаде More sharing options...
B-boy/StyLe/ Публикувано Януари 14, 2010 Report Share Публикувано Януари 14, 2010 СТЪПКА 1 Изтеглете SafeBootKeyRepair.exe и го стартирайте. СТЪПКА 2 Стартирайт програмата OTL.exe => и натиснете бутона вдясно => CleanUp. http://i47.tinypic.com/35hfp21.jpg СТЪПКА 3 Временно спрете System Restore => Десен бутон на My Computer => Properties => System Restore => сложете отметка пред => Turn Off System Restore on all drives. СТЪПКА 4 Изтеглете ATF Cleaner * Запазете го на вашия десктоп.* Кликнете два пъти върху ATF-Cleaner.exe , за да стартирате програмата.* Кликнете на Select All, който се намира в най-долната част на списъка.* Махнете отметката пред Prefetch.* Кликнете на бутона Empty Selected. http://i50.tinypic.com/2v1l0fq.jpg СТЪПКА 5 За финал направете една проверка с това. Изтеглете Malwarebytes' Anti-Malware от тук Кликнете два пъти върху mbam-setup.exe за да инсталирате програмата. * Уверете се, че има отметки на Update Malwarebytes' Anti-Malware и Launch Malwarebytes' Anti-Malware, след това кликнете на Finish.* Ако има намерени по-нови обновления, тя ще ги изтегли и инсталира.* Стартирайте програмата и изберете "Perform Quick Scan", след това кликнете на Scan.* Сканирането ще отнеме малко време, затова моля бъдете търпеливи.* Когато сканирането завърши, кликнете на OK, след това Show Results, за да видите резултата.* Уверете се, че на всички редове има отметки, и кликнете Remove Selected.* Когато всичко бъде премахнато, логът ще бъде отворен в Notepad. Копирайте лога и го публикувайте в следващия си коментар в темата. Бележка: Ако MalwareBytes' Anti-Malware се затрудни в премахването на откритите вируси/заплахи, той ще поиска да рестартира компютъра Ви и по време на рестартирането да премахне проблемните вируси/заплахи. Ако бъдете попитани, потвърдете че желаете вашия компютър да бъде рестартиран. Как да се предпазите занапред ?1. Вижте коментар № 22 2. Забранене Autoplay/Autorun с Panda USB Vaccine. * Изтеглете Panda USB Vaccine * Натиснете бутона Vaccinate Computer. * Не стартирайте съмнителни файлове получени по Скайп (дори от познати в контакт листата) без преди това да сте ги проверила с антивирусната си програма или на адрес: http://www.virustotal.com Цитирай Link to comment Сподели другаде More sharing options...
krasimirson Публикувано Януари 14, 2010 Report Share Публикувано Януари 14, 2010 Много ти благодаря.Премахнах гадината успешно.Поздрави ! Цитирай Link to comment Сподели другаде More sharing options...
B-boy/StyLe/ Публикувано Януари 14, 2010 Report Share Публикувано Януари 14, 2010 Много ти благодаря.Премахнах гадината успешно.Поздрави ! Няма проблеми. PS: Може ли все пак да публикуваш лог файла от Malwarebytes ? Мерси ! Цитирай Link to comment Сподели другаде More sharing options...
krasimirson Публикувано Януари 14, 2010 Report Share Публикувано Януари 14, 2010 Malwarebytes' Anti-Malware 1.44Версия на базата от данни: 3510Windows 5.1.2600 Service Pack 3Internet Explorer 8.0.6001.18702 15.01.2010 00:04:05mbam-log-2010-01-15 (00-04-05).txt Тип сканиране: Бързо сканиранеСканирани обекти: 107288Изминало време: 2 minute(s), 59 second(s) Заразени процеси в паметта: 0Заразени модули в паметта: 0Заразени ключове в регистратурата: 0Заразени стойности в регистратурата: 0Заразени информационни обекти в регистратурата: 0Заразени папки: 0Заразени файлове: 0 Заразени процеси в паметта:(Не бяха открити заплахи) Заразени модули в паметта:(Не бяха открити заплахи) Заразени ключове в регистратурата:(Не бяха открити заплахи) Заразени стойности в регистратурата:(Не бяха открити заплахи) Заразени информационни обекти в регистратурата:(Не бяха открити заплахи) Заразени папки:(Не бяха открити заплахи) Заразени файлове:(Не бяха открити заплахи) Заповядай ! Цитирай Link to comment Сподели другаде More sharing options...
B-boy/StyLe/ Публикувано Януари 14, 2010 Report Share Публикувано Януари 14, 2010 Благодаря. Това ме интересуваше. Мисля, че системата е вече чиста.Ако искаш да сме сигурни за финал пусни нов лог от OTL.exe.При нови проблеми пиши отново. Лека вечер. Цитирай Link to comment Сподели другаде More sharing options...
krasimirson Публикувано Януари 14, 2010 Report Share Публикувано Януари 14, 2010 Би трябвало всичко да е наред ,ето все пак ... TL logfile created on: 15.01.2010 00:37:45 - Run 1OTL by OldTimer - Version 3.1.24.0 Folder = C:\Documents and Settings\user\DesktopWindows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstationInternet Explorer (Version = 8.0.6001.18702)Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.MM.yyyy 3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 74.00% Memory free5.00 Gb Paging File | 4.00 Gb Available in Paging File | 86.00% Paging File freePaging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program FilesDrive C: | 55.60 Gb Total Space | 39.20 Gb Free Space | 70.51% Space Free | Partition Type: NTFSDrive D: | 205.08 Gb Total Space | 146.13 Gb Free Space | 71.26% Space Free | Partition Type: NTFSDrive E: | 205.08 Gb Total Space | 205.01 Gb Free Space | 99.96% Space Free | Partition Type: NTFSDrive F: | 186.61 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFSG: Drive not present or media not loadedH: Drive not present or media not loadedI: Drive not present or media not loaded Computer Name: ACER5738Current User Name: userLogged in as Administrator. Current Boot Mode: NormalScan Mode: All usersCompany Name Whitelist: OnSkip Microsoft Files: OnFile Age = 30 DaysOutput = Minimal ========== Processes (SafeList) ========== PRC - C:\Documents and Settings\user\Desktop\OTL.exe (OldTimer Tools)PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)PRC - C:\WINDOWS\system32\TUProgSt.exe (TuneUp Software)PRC - C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)PRC - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (ESET)PRC - C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)PRC - C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)PRC - C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)PRC - C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)PRC - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)PRC - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Advanced Micro Devices Inc.)PRC - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (ATI Technologies Inc.)PRC - C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)PRC - C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe (Intel® Corporation)PRC - C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)PRC - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)PRC - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)PRC - C:\Program Files\Skype\Plugin Manager\skypePM.exe (Skype Technologies)PRC - C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)PRC - C:\WINDOWS\system32\wbem\unsecapp.exe (Microsoft Corporation)PRC - C:\Program Files\Winamp\winamp.exe (Nullsoft)PRC - C:\WINDOWS\system32\agrsmsvc.exe (Agere Systems)PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)PRC - C:\Program Files\Datecs\FlexType 2K\FType2K.exe () ========== Modules (SafeList) ========== MOD - C:\Documents and Settings\user\Desktop\OTL.exe (OldTimer Tools)MOD - C:\WINDOWS\system32\BtMmHook.dll (Broadcom Corporation.)MOD - C:\WINDOWS\system32\newdll.dll () ========== Win32 Services (SafeList) ========== SRV - (gusvc) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)SRV - (TuneUp.ProgramStatisticsSvc) -- C:\WINDOWS\system32\TUProgSt.exe (TuneUp Software)SRV - (TuneUp.Defrag) -- C:\WINDOWS\system32\TuneUpDefragService.exe (TuneUp Software)SRV - (EHttpSrv) -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe (ESET)SRV - (ekrn) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (ESET)SRV - (Ati HotKey Poller) -- C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)SRV - (btwdins) -- C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)SRV - (UxTuneUp) -- C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)SRV - (EvtEng) -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)SRV - (S24EventMonitor) -- C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)SRV - (RegSrvc) -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)SRV - (Irmon) -- C:\WINDOWS\system32\irmon.dll (Microsoft Corporation)SRV - (AgereModemAudio) -- C:\WINDOWS\system32\agrsmsvc.exe (Agere Systems)SRV - (ose) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV - (atksgt) -- C:\WINDOWS\system32\drivers\atksgt.sys ()DRV - (lirsgt) -- C:\WINDOWS\system32\drivers\lirsgt.sys ()DRV - (hamachi) -- C:\WINDOWS\system32\drivers\hamachi.sys (Applied Networking Inc.)DRV - (sptd) -- C:\WINDOWS\System32\Drivers\sptd.sys ()DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)DRV - (epfwtdir) -- C:\WINDOWS\system32\drivers\epfwtdir.sys (ESET)DRV - (ehdrv) -- C:\WINDOWS\system32\drivers\ehdrv.sys (ESET)DRV - (eamon) -- C:\WINDOWS\system32\drivers\eamon.sys (ESET)DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)DRV - (BTKRNL) -- C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)DRV - (RTHDMIAzAudService) -- C:\WINDOWS\system32\drivers\RtHDMI.sys (Realtek Semiconductor Corp.)DRV - (AtiHdmiService) -- C:\WINDOWS\system32\drivers\AtiHdmi.sys (ATI Research Inc.)DRV - (BTWUSB) -- C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)DRV - (NETw5x32) Intel® -- C:\WINDOWS\system32\drivers\NETw5x32.sys (Intel Corporation)DRV - (k57w2k) Broadcom NetLink -- C:\WINDOWS\system32\drivers\k57xp32.sys (Broadcom Corporation)DRV - (Ambfilt) -- C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)DRV - (s24trans) -- C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)DRV - (BTWDNDIS) -- C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)DRV - (btaudio) -- C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)DRV - (HDAudBus) -- C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)DRV - (Secdrv) -- C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)DRV - (Ptilink) -- C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)DRV - (btwhid) -- C:\WINDOWS\system32\drivers\btwhid.sys (Broadcom Corporation.)DRV - (BTDriver) -- C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)DRV - (btwmodem) -- C:\WINDOWS\system32\drivers\btwmodem.sys (Broadcom Corporation.)DRV - (AgereSoftModem) -- C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)DRV - (PxHelp20) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)DRV - (DKbFltr) -- C:\WINDOWS\system32\drivers\DKbFltr.SYS (Dritek System Inc.)DRV - (Monfilt) -- C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)DRV - (STIrUsb) -- C:\WINDOWS\system32\drivers\irstusb.sys (SigmaTel, Inc.) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1547161642-362288127-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.comIE - HKU\S-1-5-21-1547161642-362288127-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.start.bg/IE - HKU\S-1-5-21-1547161642-362288127-1801674531-1003\S-1-5-21-1547161642-362288127-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2010.01.15 00:15:21 | 00,000,000 | ---D | M] [2009.09.30 15:33:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Mozilla\Extensions[2009.09.30 15:33:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\ehe3y68v.default\extensions[2009.12.30 17:46:18 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions O1 HOSTS File: (734 bytes) - C:\WINDOWS\system32\drivers\etc\hostsO1 - Hosts: 127.0.0.1 localhostO2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)O3 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe (Realtek Semiconductor Corp.)O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)O4 - HKLM..\Run: [Google Quick Search Box] C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)O4 - HKLM..\Run: [intelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)O4 - HKLM..\Run: [intelZeroConfig] C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe (Intel® Corporation)O4 - HKLM..\Run: [iSUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)O4 - HKLM..\Run: [iSUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)O4 - HKLM..\Run: [oynxncnfjzrzq] File not foundO4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)O4 - HKLM..\Run: [startCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)O4 - HKLM..\Run: [yojzvqhfpljxulhnevc] C:\DOCUME~1\user\LOCALS~1\Temp\xkcpiaojqjepjxqt.exe File not foundO4 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)O4 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003..\Run: [oynxncnfjzrzq] C:\DOCUME~1\user\LOCALS~1\Temp\lcypmiazkhgvtliphzhy.exe File not foundO4 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003..\Run: [skype] C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)O4 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)O4 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003..\Run: [xkcpiaojqjepjxqt] File not foundO4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\FlexType 2K.lnk = C:\Program Files\Datecs\FlexType 2K\FType2K.exe ()O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 1O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: sevhzqdxdvpzsfx = ncwlgaqnwrobxnindt.exeO6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: pymvkyizcrip = C:\DOCUME~1\user\LOCALS~1\Temp\xkcpiaojqjepjxqt.exe File not foundO6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 0O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 0O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 0O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 0O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145O7 - HKU\S-1-5-21-1547161642-362288127-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 1O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll (Google Inc.)O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)O24 - Desktop WallPaper: C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Wallpaper1.bmpO24 - Desktop BackupWallPaper: C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Wallpaper1.bmpO32 - HKLM CDRom: AutoRun - 1O32 - AutoRun File - [2009.08.29 22:59:46 | 00,000,199 | R--- | M] () - F:\autorun.inf -- [ CDFS ]O34 - HKLM BootExecute: (autocheck autochk *) - File not foundO35 - comfile [open] -- "%1" %*O35 - exefile [open] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2010.01.15 00:37:23 | 00,544,256 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\user\Desktop\OTL.exe[2010.01.15 00:15:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\LastGood[2010.01.14 21:21:23 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Malwarebytes[2010.01.14 21:21:20 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys[2010.01.14 21:21:18 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys[2010.01.14 21:21:18 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware[2010.01.14 21:21:18 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes[2009.12.30 17:46:18 | 00,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox[2009.12.30 17:46:17 | 00,000,000 | ---D | C] -- C:\Program Files\Skype[2009.12.28 18:44:11 | 00,000,000 | ---D | C] -- C:\Program Files\WinUHA[2009.12.28 00:40:29 | 00,000,000 | ---D | C] -- C:\Temp[2009.12.28 00:40:22 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Syntrillium[2009.12.28 00:38:54 | 00,000,000 | ---D | C] -- C:\Program Files\coolpro2[2009.12.25 20:32:17 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\My Documents\NBA LIVE 07[2009.11.22 20:36:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\ESET[2009.09.30 14:23:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\Intel[2009.09.30 14:23:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Intel[2009.09.30 10:26:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft[2009.09.30 10:25:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft[2009.09.30 10:23:06 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft[2009.09.30 10:23:06 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft ========== Files - Modified Within 30 Days ========== [2010.01.15 00:37:37 | 00,544,256 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\user\Desktop\OTL.exe[2010.01.15 00:00:00 | 00,000,484 | ---- | M] () -- C:\WINDOWS\tasks\1-Click Maintenance.job[2010.01.14 23:58:42 | 03,932,160 | -H-- | M] () -- C:\Documents and Settings\user\NTUSER.DAT[2010.01.14 21:37:02 | 00,462,344 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI[2010.01.14 21:37:02 | 00,395,534 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat[2010.01.14 21:37:02 | 00,059,774 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat[2010.01.14 21:33:09 | 00,121,808 | ---- | M] () -- C:\WINDOWS\System32\ativvaxx.cap[2010.01.14 21:32:56 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT[2010.01.14 21:32:55 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat[2010.01.14 21:32:13 | 00,000,278 | -HS- | M] () -- C:\Documents and Settings\user\ntuser.ini[2010.01.14 21:21:22 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk[2010.01.14 21:18:15 | 00,065,720 | ---- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\GDIPFONTCACHEV1.DAT[2010.01.14 21:18:04 | 00,250,288 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT[2010.01.14 20:13:49 | 00,002,257 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk[2010.01.14 20:12:52 | 00,002,443 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SA Dictionary 2008 Beta 4.lnk[2010.01.14 18:41:35 | 00,000,280 | -H-- | M] () -- C:\WINDOWS\System32\cadbfihnfjplqpthgfusvtx.zfx[2010.01.14 18:41:35 | 00,000,280 | -H-- | M] () -- C:\WINDOWS\cadbfihnfjplqpthgfusvtx.zfx[2010.01.14 18:41:35 | 00,000,280 | -H-- | M] () -- C:\Program Files\cadbfihnfjplqpthgfusvtx.zfx[2010.01.14 18:41:35 | 00,000,280 | -H-- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\cadbfihnfjplqpthgfusvtx.zfx[2010.01.14 18:39:34 | 00,004,248 | -H-- | M] () -- C:\WINDOWS\System32\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo[2010.01.14 18:39:34 | 00,004,248 | -H-- | M] () -- C:\WINDOWS\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo[2010.01.14 18:39:34 | 00,004,248 | -H-- | M] () -- C:\Program Files\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo[2010.01.14 18:39:34 | 00,004,248 | -H-- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo[2010.01.13 19:01:03 | 00,308,155 | ---- | M] () -- C:\Trojan Scanner.exe[2010.01.13 18:22:40 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl[2010.01.12 17:23:44 | 00,001,997 | ---- | M] () -- C:\WINDOWS\unins000.dat[2010.01.12 17:23:23 | 00,685,358 | ---- | M] () -- C:\WINDOWS\unins000.exe[2010.01.10 20:55:20 | 02,106,622 | -H-- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\IconCache.db[2010.01.07 16:07:14 | 00,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys[2010.01.07 16:07:04 | 00,019,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys[2009.12.30 18:50:38 | 00,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini[2009.12.29 23:32:49 | 00,009,216 | ---- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini[2009.12.29 18:04:33 | 00,000,310 | ---- | M] () -- C:\Documents and Settings\user\My Documents\Моите документи.lnk[2009.12.28 00:41:42 | 00,000,603 | ---- | M] () -- C:\WINDOWS\win.ini[2009.12.28 00:41:42 | 00,000,259 | ---- | M] () -- C:\WINDOWS\system.ini[2009.12.28 00:40:19 | 00,156,910 | ---- | M] () -- C:\WINDOWS\WMSysPr8.prx[2009.12.28 00:40:16 | 00,000,682 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Cool Edit Pro 2.0.lnk[2009.12.28 00:20:21 | 00,000,845 | ---- | M] () -- C:\Documents and Settings\user\Desktop\Пряк път до NeroStartSmart.lnk ========== Files Created - No Company Name ========== [2010.01.14 21:21:22 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk[2010.01.14 18:39:34 | 00,004,248 | -H-- | C] () -- C:\WINDOWS\System32\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo[2010.01.14 18:39:34 | 00,004,248 | -H-- | C] () -- C:\WINDOWS\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo[2010.01.14 18:39:34 | 00,004,248 | -H-- | C] () -- C:\Program Files\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo[2010.01.14 18:39:34 | 00,004,248 | -H-- | C] () -- C:\Documents and Settings\user\Local Settings\Application Data\pymvkyizcripfpednxxgudsgqhkzqxnxml.ffo[2010.01.14 18:39:33 | 00,000,280 | -H-- | C] () -- C:\WINDOWS\System32\cadbfihnfjplqpthgfusvtx.zfx[2010.01.14 18:39:33 | 00,000,280 | -H-- | C] () -- C:\WINDOWS\cadbfihnfjplqpthgfusvtx.zfx[2010.01.14 18:39:33 | 00,000,280 | -H-- | C] () -- C:\Program Files\cadbfihnfjplqpthgfusvtx.zfx[2010.01.14 18:39:33 | 00,000,280 | -H-- | C] () -- C:\Documents and Settings\user\Local Settings\Application Data\cadbfihnfjplqpthgfusvtx.zfx[2010.01.13 19:01:02 | 00,308,155 | ---- | C] () -- C:\Trojan Scanner.exe[2010.01.12 17:23:44 | 00,685,358 | ---- | C] () -- C:\WINDOWS\unins000.exe[2010.01.12 17:23:44 | 00,001,997 | ---- | C] () -- C:\WINDOWS\unins000.dat[2009.12.29 18:04:33 | 00,000,310 | ---- | C] () -- C:\Documents and Settings\user\My Documents\Моите документи.lnk[2009.12.28 00:40:19 | 00,156,910 | ---- | C] () -- C:\WINDOWS\WMSysPr8.prx[2009.12.28 00:40:16 | 00,000,682 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Cool Edit Pro 2.0.lnk[2009.12.28 00:20:21 | 00,000,845 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Пряк път до NeroStartSmart.lnk[2009.11.21 16:39:45 | 00,000,000 | ---- | C] () -- C:\Program Files\temp01[2009.11.20 13:18:19 | 00,279,712 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys[2009.11.20 13:18:18 | 00,025,888 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys[2009.11.15 19:57:06 | 00,009,216 | ---- | C] () -- C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini[2009.11.07 22:52:28 | 00,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini[2009.10.02 17:28:10 | 00,000,000 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI[2009.10.01 16:50:55 | 00,721,904 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys[2009.10.01 14:58:19 | 00,000,236 | ---- | C] () -- C:\Program Files\Common Files\dx.reg[2009.10.01 14:58:18 | 01,029,126 | ---- | C] () -- C:\WINDOWS\System32\d3d10.dll[2009.10.01 14:58:18 | 00,874,502 | ---- | C] () -- C:\WINDOWS\System32\kernel32new.dll[2009.10.01 14:58:18 | 00,681,478 | ---- | C] () -- C:\WINDOWS\System32\msvcrtnew.dll[2009.10.01 14:58:18 | 00,187,398 | ---- | C] () -- C:\WINDOWS\System32\d3d10core.dll[2009.09.30 15:41:46 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI[2009.09.30 15:40:14 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\newdll.dll[2009.09.30 15:35:30 | 00,168,448 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll[2009.09.30 15:35:30 | 00,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini[2009.09.30 15:35:29 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll[2009.09.30 15:35:29 | 00,881,664 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll[2009.09.30 15:35:29 | 00,205,824 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll[2009.09.30 15:35:27 | 00,085,504 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll[2009.09.30 15:35:27 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest[2009.08.03 00:21:54 | 00,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll[2009.08.03 00:21:52 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll[2009.08.03 00:21:52 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll[2009.01.16 16:55:38 | 02,854,976 | ---- | C] () -- C:\WINDOWS\System32\btwicons.dll[2005.02.17 10:41:32 | 00,000,603 | ---- | C] () -- C:\WINDOWS\System32\BTNeighborhood.dll.manifest[2005.02.17 10:41:30 | 00,000,593 | ---- | C] () -- C:\WINDOWS\System32\btcss.dll.manifest[2003.01.07 14:05:08 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI[2001.11.14 11:56:00 | 01,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll< End of report > OTL Extras logfile created on: 15.01.2010 00:37:45 - Run 1OTL by OldTimer - Version 3.1.24.0 Folder = C:\Documents and Settings\user\DesktopWindows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstationInternet Explorer (Version = 8.0.6001.18702)Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.MM.yyyy 3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 74.00% Memory free5.00 Gb Paging File | 4.00 Gb Available in Paging File | 86.00% Paging File freePaging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program FilesDrive C: | 55.60 Gb Total Space | 39.20 Gb Free Space | 70.51% Space Free | Partition Type: NTFSDrive D: | 205.08 Gb Total Space | 146.13 Gb Free Space | 71.26% Space Free | Partition Type: NTFSDrive E: | 205.08 Gb Total Space | 205.01 Gb Free Space | 99.96% Space Free | Partition Type: NTFSDrive F: | 186.61 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFSG: Drive not present or media not loadedH: Drive not present or media not loadedI: Drive not present or media not loaded Computer Name: ACER5738Current User Name: userLogged in as Administrator. Current Boot Mode: NormalScan Mode: All usersCompany Name Whitelist: OnSkip Microsoft Files: OnFile Age = 30 DaysOutput = Minimal ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>].html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) [HKEY_USERS\S-1-5-21-1547161642-362288127-1801674531-1003\SOFTWARE\Classes\<extension>].html [@ = FirefoxHTML] -- Reg Error: Key error. File not found ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]batfile [open] -- "%1" %*cmdfile [open] -- "%1" %*comfile [open] -- "%1" %*exefile [open] -- "%1" %*htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)piffile [open] -- "%1" %*regfile [merge] -- Reg Error: Key error.scrfile [config] -- "%1"scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)scrfile [open] -- "%1" /Stxtfile [edit] -- Reg Error: Key error.Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]"FirstRunDisabled" = 1"AntiVirusOverride" = 0"FirewallOverride" = 0"AntiVirusDisableNotify" = 0"FirewallDisableNotify" = 0"UpdatesDisableNotify" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]"EnableFirewall" = 0 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)"D:\Games\PES 2010\pes2010.exe" = D:\Games\PES 2010\pes2010.exe:*:Enabled:Pro Evolution Soccer 2010 -- (Konami Digital Entertainment Co., Ltd.)"D:\Games\PES 2010\PESEdit.exe" = D:\Games\PES 2010\PESEdit.exe:*:Enabled:Pro Evolution Soccer 2010 -- (Konami Digital Entertainment Co., Ltd.)"D:\Games\FM 2010\fm.exe" = D:\Games\FM 2010\fm.exe:*:Enabled:Football Manager 2010 -- (Sports Interactive)"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.) ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR"{055A5AF0-9FEB-440D-B00A-18935C7C171C}" = SA Dictionary 2008 Beta 4"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center"{11202615-E557-4ECF-9B86-F59C81E52909}" = FIFA 10"{164086E1-A5DD-3D64-06B1-186005030854}" = CCC Help Korean"{1800A397-53DF-4F2C-6115-FE2FA9EA69DA}" = ccc-core-static"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer"{18625255-5E1D-6BF1-8809-BE4CEE493D52}" = Catalyst Control Center Graphics Full Existing"{18CD3278-B87E-3026-D38F-38E0A67F2BA4}" = ccc-core-preinstall"{18D07AC5-417D-4735-BC99-C8E77A7A4195}" = Windows Live Messenger"{1F126EDC-DA29-4D5B-80DF-735252475FEE}" = Pro Evolution Soccer 2010 DEMO"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Инструмент за качване на Windows Live"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer"{232AAA95-AE60-46C7-9987-4E7139EA3554}" = Асистент за влизане на Windows Live"{283FFB23-8751-4B08-ACB8-5E0F8BCF7727}" = Pro Evolution Soccer 2010"{298F1470-17A2-124A-B615-9A58F90CDA57}" = CCC Help English"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP"{368B73EA-A46E-94B1-1B20-24D47B4760F3}" = CCC Help Portuguese"{3AD20171-A064-C9EC-0C11-5B036FA6F32C}" = CCC Help Dutch"{3F64C088-9A45-41B3-8B99-71AFAB720A56}" = Sherlock Holmes versus Jack the Ripper"{4A3EB326-F730-4A71-AEBF-3C7DF7ED716F}" = Тайната на сребърната обица"{4F0C7CCF-5666-474B-B02E-AC514A95EC93}" = NVIDIA GAME System Software 2.8.1"{51B83F5C-5660-4B73-AB18-C68993FEDEB3}" = Catalyst Control Center - Branding"{55A29068-F2CE-456C-9148-C869879E2357}" = TuneUp Utilities 2009"{5B78DFB0-0FFE-E76F-E51C-FBA53A01085E}" = CCC Help Polish"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.8"{6144C1EC-0F4E-6514-E633-85AC3724F082}" = CCC Help Spanish"{63686BEF-04CA-461C-B364-53BBC322F7BF}" = Sherlock Holmes Nemesis"{6D144E43-239B-657F-15C5-854EF2C4E55F}" = Catalyst Control Center Core Implementation"{70701602-56D7-64DF-150D-5459C547E058}" = CCC Help Chinese Traditional"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0"{731A3C00-8E73-7893-C15E-4FAFC5787EE5}" = CCC Help Swedish"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com"{839011A6-DF28-4E21-00AE-83482775212B}" = NBA LIVE 07"{84814E6B-2581-46EC-926A-823BD1C670F6}" = Lenovo Bluetooth with Enhanced Data Rate Software"{875FC2BF-BF34-4F26-B579-CFC7CE2FFAEA}" = ESET NOD32 Antivirus"{8E371F04-9B92-42A0-A7AF-6678DDB688E1}" = Windows Live Essentials"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003"{91B323B5-A79C-4D23-BD6D-046C565F9BCF}" = MadOnion.com/3DMark2001 SE"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting"{95991299-E762-2AEA-077D-5DB75E7896C0}" = CCC Help Russian"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = USB2.0 Card Reader Software"{9E478F3F-7A7B-42C5-BE9C-40FC0E07665F}" = The Awakened"{A01D832F-1227-EC5B-6A06-88D53753A789}" = CCC Help Hungarian"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI"{A23DD0F0-58E1-7453-9721-760062EF2369}" = CCC Help German"{A45F3795-1527-47FA-BE1A-2DD242B439E5}_is1" = Need for Speed - Shift"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable"{A4F264EA-5851-4684-185F-83C09B678A9C}" = ccc-utility"{A75C72CA-4D28-C419-5FBA-3762F2344D2F}" = Skins"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9"{B0C4DD22-7D91-E56C-F257-37781CC7FFC2}" = Catalyst Control Center Graphics Full New"{B55E3E57-C706-CFFF-8170-635BB081B3AA}" = CCC Help Greek"{B7BFA380-2559-B766-85FA-EA02218FD8E7}" = CCC Help Norwegian"{B9DD8184-8040-1920-D771-3F77AA3131DB}" = CCC Help Chinese Standard"{BF76EB61-33DA-BBE5-151F-0A1DE5D99A2B}" = CCC Help Japanese"{C408D81A-CB17-4CDF-98AF-2E64036B3F32}" = Windows Bulgarian Interface Pack"{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}" = NVIDIA PhysX"{CC0BD204-465D-B512-E19F-866026F59326}" = CCC Help Italian"{D02C0FA6-7512-5411-BC81-E910C8AF4A9F}" = CCC Help Thai"{D1C8DCCF-790D-62AD-ED46-3E5E170B13B2}" = CCC Help Danish"{D2777D85-7E63-402F-A5E7-2AF436C1C9D4}" = Intel® PROSet/Wireless WiFi Software"{D27840CA-5F61-7CD3-CDF4-A6EB828CF5D7}" = Catalyst Control Center Localization All"{D3F07123-C1BE-3BDE-7B29-C6647C3DCE98}" = Catalyst Control Center Graphics Light"{D9237C88-448A-C1DE-6BA0-EF53462BB1FC}" = CCC Help French"{E86766EB-5D72-ADFF-D2F0-DE0AB25174CF}" = CCC Help Turkish"{EA913B24-ED12-1837-C52C-EA58D6ECDB2F}" = CCC Help Czech"{EBB794ED-D282-4334-92FB-254481EFF514}" = Pro Evolution Soccer 6"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver"{F36547BF-7B05-1B15-E383-D42BFFD57796}" = CCC Help Finnish"Adobe AIR" = Adobe AIR"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin"Agere Systems Soft Modem" = Agere Systems HDA Modem"All ATI Software" = ATI - Software Uninstall Utility"ATI Display Driver" = ATI Display Driver"BFGC" = Big Fish Games Client"BFL_FIFA_10" = BFL_FIFA_10"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com"Cool Edit Pro 2.0" = Cool Edit Pro 2.0"DirectX10_is1" = DirectX10 RC2 Pre Fix 3"ESET Online Scanner" = ESET Online Scanner v3"EVEREST Ultimate Edition_is1" = EVEREST Ultimate Edition v5.00"FIFA 10_is1" = FIFA 10 v1.0 R-E"FlexType 2K" = FlexType 2K"Football Manager 2010" = Football Manager 2010"GOM Player" = GOM Player"Hamachi" = Hamachi 0.9.9.9"ie8" = Windows Internet Explorer 8"InstallShield_{EBB794ED-D282-4334-92FB-254481EFF514}" = Pro Evolution Soccer 6"KLiteCodecPack_is1" = K-Lite Codec Pack 5.0.0 (Full)"LManager" = Launch Manager"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition"NOD32 v3.x FiX 1.1 by TemDono_is1" = NOD32 v3.x FiX 1.1 by TemDono (Free Updates - Expire in 2050)"PESEdit.com 2010 Patch 0.3.1 with Chants" = PESEdit.com 2010 Patch 0.3.1 with Chants"ProInst" = Intel PROSet Wireless"SA Dictionary 2005 T2" = SA Dictionary 2005 T2"Screen Shot Maker_is1" = Screen Shot Maker 2.5"TVUPlayer" = TVUPlayer 2.3.4.1"Veetle TV" = Veetle TV 0.9.15"Winamp" = Winamp"Windows Media Format Runtime" = Windows Media Format Runtime"WinLiveSuite_Wave3" = Windows Live Essentials"WinRAR archiver" = WinRAR archiver"WinUHA_is1" = WinUHA 2.0 RC1 (2005.02.27) ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-1547161642-362288127-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]"uTorrent" = µTorrent ========== Last 10 Event Log Errors ========== [ Application Events ]Error - 25.12.2009 11:41:18 | Computer Name = ACER5738 | Source = Application Hang | ID = 1002Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 25.12.2009 15:20:53 | Computer Name = ACER5738 | Source = Application Error | ID = 1000Description = Faulting application ati2evxx.exe, version 6.14.10.4220, faulting module ntdll.dll, version 5.1.2600.5512, fault address 0x000108b3. Error - 26.12.2009 06:35:13 | Computer Name = ACER5738 | Source = Application Hang | ID = 1002Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 30.12.2009 11:31:17 | Computer Name = ACER5738 | Source = Application Hang | ID = 1002Description = Hanging application msiexec.exe, version 3.1.4001.5512, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 08.01.2010 12:57:38 | Computer Name = ACER5738 | Source = Application Error | ID = 1000Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting module flash10b.ocx, version 10.0.22.87, fault address 0x001ea9e1. Error - 10.01.2010 12:36:36 | Computer Name = ACER5738 | Source = Application Error | ID = 1000Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting module mshtml.dll, version 8.0.6001.18702, fault address 0x0020fbd7. Error - 10.01.2010 12:36:41 | Computer Name = ACER5738 | Source = Application Error | ID = 1000Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting module mshtml.dll, version 8.0.6001.18702, fault address 0x0020fbd7. Error - 10.01.2010 12:36:43 | Computer Name = ACER5738 | Source = Application Error | ID = 1001Description = Fault bucket 1192410865. Error - 10.01.2010 12:37:03 | Computer Name = ACER5738 | Source = Application Error | ID = 1000Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting module mshtml.dll, version 8.0.6001.18702, fault address 0x0020fbd7. Error - 10.01.2010 12:37:08 | Computer Name = ACER5738 | Source = Application Error | ID = 1000Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting module mshtml.dll, version 8.0.6001.18702, fault address 0x0020fbd7. [ System Events ]Error - 14.01.2010 12:39:23 | Computer Name = ACER5738 | Source = Service Control Manager | ID = 7034Description = The Intel® PROSet/Wireless Event Log service terminated unexpectedly. It has done this 1 time(s). Error - 14.01.2010 12:39:23 | Computer Name = ACER5738 | Source = Service Control Manager | ID = 7034Description = The Intel® PROSet/Wireless Registry Service service terminated unexpectedly. It has done this 1 time(s). Error - 14.01.2010 12:39:23 | Computer Name = ACER5738 | Source = Service Control Manager | ID = 7034Description = The TuneUp Program Statistics Service service terminated unexpectedly. It has done this 1 time(s). Error - 14.01.2010 12:39:23 | Computer Name = ACER5738 | Source = Service Control Manager | ID = 7034Description = The Intel® PROSet/Wireless WiFi Service service terminated unexpectedly. It has done this 1 time(s). Error - 14.01.2010 12:39:23 | Computer Name = ACER5738 | Source = Service Control Manager | ID = 7031Description = The Bluetooth Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. Error - 14.01.2010 12:43:02 | Computer Name = ACER5738 | Source = sr | ID = 1Description = The System Restore filter encountered the unexpected error '0xC0000034' while processing the file '_filelst.cfg' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. Error - 14.01.2010 12:43:57 | Computer Name = ACER5738 | Source = DCOM | ID = 10016Description = The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206} to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission can be modified using the Component Services administrative tool. Error - 14.01.2010 12:43:57 | Computer Name = ACER5738 | Source = DCOM | ID = 10016Description = The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206} to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission can be modified using the Component Services administrative tool. Error - 14.01.2010 12:43:57 | Computer Name = ACER5738 | Source = DCOM | ID = 10016Description = The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206} to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission can be modified using the Component Services administrative tool. Error - 14.01.2010 15:18:33 | Computer Name = ACER5738 | Source = System Error | ID = 1003Description = Error code 1000007e, parameter1 c0000005, parameter2 ae3c323a, parameter3 f7042ae0, parameter4 f70427dc. [ TuneUp Events ]Error - 14.01.2010 15:21:57 | Computer Name = ACER5738 | Source = TuneUp Program Statistics | ID = 131840Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-01-14 21:21:57', '\device\harddiskvolume1\program files\malwarebytes' anti-malware\mbam.exe','3992',0) Error - 14.01.2010 15:33:03 | Computer Name = ACER5738 | Source = TuneUp Program Statistics | ID = 131840Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-01-14 21:33:03', '\device\harddiskvolume1\program files\malwarebytes' anti-malware\mbam.exe','2216',0) Error - 14.01.2010 18:00:21 | Computer Name = ACER5738 | Source = TuneUp Program Statistics | ID = 131840Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-01-15 00:00:21', '\device\harddiskvolume1\program files\malwarebytes' anti-malware\mbam.exe','2344',0) < End of report > Айде лека вечер ! Цитирай Link to comment Сподели другаде More sharing options...
Препоръчан пост
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.