mihnev_sz Публикувано Май 8, 2009 Report Share Публикувано Май 8, 2009 Най накря успях да го изтегля Dr.WEB CureIt! 5.00.0 ,но не от линка кото си ми дал ,а от Dimisoft.Изпълних инструкциите и ето шот след сканиране (нищо не откри):Ако има още нещо да се прави казвайте!!! Ти май си направил "бързо" сканиране,сложи отметка на "пълно"сканиране с DR.WebПри "бързото" сканиране,сканира само стартиращите се файлове и процеси . П.с. М/у другото току що видях новия лог,въпросното Fake.Alert което е rogue приложение и от OIB.EXE,няма остатъци,фикса от HijackThis,определено до-разчистил и е свършил работа!С това мисля,че проблема вече е решен.Но за всеки случай направи и пълно сканиране с антивирусната и с доктора. Цитирай Link to comment Сподели другаде More sharing options...
plamen74.72 Публикувано Май 8, 2009 Author Report Share Публикувано Май 8, 2009 Dr.WEB CureIt! 5.00.0 още сканира и не е стигнал даже и до половината ,но показа че тези два файла съдържат инфектирани обекти:http://i39.tinypic.com/qq23hz.png Трябва ли въобще да ги има в тази папка -> C:\Documents and Settings\Пламен\Application Data\Downloaded Installations\{9B5DAF0D-F5A3-4739-AA18-DCBF4CBC873F} ??? Цитирай Link to comment Сподели другаде More sharing options...
mihnev_sz Публикувано Май 8, 2009 Report Share Публикувано Май 8, 2009 Dr.WEB CureIt! 5.00.0 още сканира и не е стигнал даже и до половината ,но показа че тези два файла съдържат инфектирани обекти:Трябва ли въобще да ги има в тази папка -> C:\Documents and Settings\Пламен\Application Data\Downloaded Installations\{9B5DAF0D-F5A3-4739-AA18-DCBF4CBC873F} ??? Аз нямам такава папка там Downloaded Installations ,щом е открил, че съдържат инфекция,ще ги излекува.Да,пълното сканиране на доктора отнема повечко време,но пък е задълбочено и задължително изчакай до край. Цитирай Link to comment Сподели другаде More sharing options...
plamen74.72 Публикувано Май 8, 2009 Author Report Share Публикувано Май 8, 2009 Аз нямам такава папка там Downloaded Installations ,щом е открил, че съдържат инфекция,ще ги излекува.Да,пълното сканиране на доктора отнема повечко време,но пък е задълбочено и задължително изчакай до край. Dr.WEB CureIt! 5.00.0 приключи сканирането и освен тези нямаше други и направо му дадох да ги изтрие (понеже каза че ти нямаш такава папка -като ръчно премахнах и папката).Антивирусната нищо не откри ,освен това сканирах отново и със MBAB и SAS - и те не откриха нищо!!!Ако е нужно да пусна още един лог от HijackThis или GMER??? п.с.Ако сменя ESS със Avira Free и добавя Ashampoo FireWall FREE за която още имам валиден лиценз - ще бъде ли по добре или да ги оставя както са сега??? Цитирай Link to comment Сподели другаде More sharing options...
Night_Raven Публикувано Май 8, 2009 Report Share Публикувано Май 8, 2009 Последният път когато пробвах ESS, MBAM ми намери Trojan.Vundo. Поставих въпроса с намек за промяна - от лога бе видна каква е реално-времевата охрана.А от ESET от колко години никакви вируси не били пропускали - вече не си спомням... ПоздравиVundo не е реален тест. Не само NOD32 не лови Vundo базираните гадинки. Всички антивирусни се дънят при тях. Ако е нужно да пусна още един лог от HijackThis или GMER??? Изтегли DDS и:1) стартирай я;2) изчакай да събере информацията си;3) ще се появят 2 текстови файла, копирай съдържанието и на двата тук или ги архивирай и прикачи архива към коментара си. п.с.Ако сменя ESS със Avira Free и добавя Ashampoo FireWall FREE за която още имам валиден лиценз - ще бъде ли по добре или да ги оставя както са сега???Както ESS/ЕAV, така и Avira AntiVir са добри програми. Ползвай която комбинация ти допада повече. Цитирай Link to comment Сподели другаде More sharing options...
plamen74.72 Публикувано Май 8, 2009 Author Report Share Публикувано Май 8, 2009 Vundo не е реален тест. Не само NOD32 не лови Vundo базираните гадинки. Всички антивирусни се дънят при тях. Изтегли DDS и:1) стартирай я;2) изчакай да събере информацията си;3) ще се появят 2 текстови файла, копирай съдържанието и на двата тук или ги архивирай и прикачи архива към коментара си. Както ESS/ЕAV, така и Avira AntiVir са добри програми. Ползвай която комбинация ти допада повече. Ето ги:DDS (Ver_09-03-16.01) - NTFSx86 Run by Џ« ¬Ґ at 22:05:01,74 on 08.05.2009 Ј.Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_13Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.1279.409 [GMT 3:00] AV: ESET Smart Security 3.0 *On-access scanning enabled* (Updated)FW: Лична защитна стена на ESET *enabled* ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunchsvchost.exeC:\WINDOWS\System32\svchost.exe -k netsvcssvchost.exesvchost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\Program Files\ESET\ESET Smart Security\egui.exeC:\Program Files\Multimedia Keyboard Driver\M-KbdDrv.exeC:\Program Files\PicPick\picpick.exeC:\Program Files\Vista Drive Icon\DrvIcon.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\VisualTaskTips\VisualTaskTips.exeC:\Program Files\Spybot - Search & Destroy\TeaTimer.exeC:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exeC:\Program Files\Weather Clock\WeatherClock.exeC:\Program Files\RocketDock\RocketDock.exeC:\Program Files\8start Launcher\8start.exeC:\Documents and Settings\Пламен\Local Settings\Application Data\Google\Update\GoogleUpdate.exeC:\Program Files\BACL\SpeechLab\TTSProfileDlg.exeC:\Program Files\Google\Update\GoogleUpdate.exeC:\Program Files\Stardock\ObjectDock\ObjectDock.exesvchost.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exeC:\Program Files\ESET\ESET Smart Security\ekrn.exeC:\Program Files\Java\jre6\bin\jqs.exeC:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXEC:\WINDOWS\system32\nvsvc32.exeC:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exeC:\WINDOWS\system32\svchost.exe -k imgsvcC:\Program Files\Skype\Phone\Skype.exeC:\Program Files\Opera\opera.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\Documents and Settings\Пламен\My Documents\DDS.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://teteven.net/uInternet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunchBHO: Flashget Catch Url Class: {2f364306-aa45-47b5-9f9d-39a8b94e7ef7} - c:\program files\flashget\jccatch.dllBHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dllBHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - c:\program files\bitcomet\tools\BitCometBHO.dllBHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dllBHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dllBHO: FlashFXP Helper for Internet Explorer: {e5a1691b-d188-4419-ad02-90002030b8ee} - c:\progra~1\flashfxp\IEFlash.dllBHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dllBHO: FlashGet GetFlash Class: {f156768e-81ef-470c-9057-481ba8380dba} - c:\program files\flashget\getflash.dllTB: {E52BE12D-A44A-4F51-9DC1-34F37A488CC7} - No FileuRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exeuRun: [VisualTaskTips] c:\program files\visualtasktips\VisualTaskTips.exeuRun: [spybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exeuRun: [sUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exeuRun: [WeatherClock] c:\program files\weather clock\WeatherClock.exeuRun: [RocketDock] "c:\program files\rocketdock\RocketDock.exe"uRun: [8start] c:\program files\8start launcher\8start.exeuRun: [Google Update] "c:\documents and settings\пламен\local settings\application data\google\update\GoogleUpdate.exe" /cmRun: [egui] "c:\program files\eset\eset smart security\egui.exe" /hide /waitservicemRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartupmRun: [MutlimediaKbdDriver] c:\program files\multimedia keyboard driver\M-KbdDrv.exemRun: [PicPick Start] c:\program files\picpick\picpick.exemRun: [DrvIcon] c:\program files\vista drive icon\DrvIcon.exemRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottimedRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXEStartupFolder: c:\docume~1\92c1~1\startm~1\programs\startup\config~1.lnk - c:\docume~1\92c1~1\applic~1\microsoft\installer\{319a3ca9-da63-4d65-8b25-403cf9cbf087}\_5af141bb.exeStartupFolder: c:\docume~1\92c1~1\startm~1\programs\startup\stardo~1.lnk - c:\program files\stardock\objectdock\ObjectDock.exeIE: &Сваляне на всички с FlashGet - c:\program files\flashget\jc_all.htmIE: &Сваляне с FlashGet - c:\program files\flashget\jc_link.htmIE: Download all links using BitComet - c:\program files\bitcomet\BitComet.exe/AddAllLink.htmIE: Download all videos using BitComet - c:\program files\bitcomet\BitComet.exe/AddVideo.htmIE: Download link using &BitComet - c:\program files\bitcomet\BitComet.exe/AddLink.htmIE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000IE: {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - c:\progra~1\flashget\flashget.exeIE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exeIE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLLIE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dllDPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cabDPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cabDPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cabDPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cabDPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabTCP: {BC778969-3DF9-4CF2-98C1-D32E6F39A4EC} = 84.22.28.50 212.116.131.138Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dllSSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dllSEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\92c1~1\applic~1\mozilla\firefox\profiles\kvqmjoxt.default\FF - prefs.js: browser.startup.homepage - hxxp://teteven.net/|http://www.google.bg/firefox?client=firefox-a&rls=org.mozilla:bg:official|http://www.google.bg/|http://forums.softvisia.com/index.php?|http://torrents.teteven.net/index.php?page=forumFF - component: c:\program files\real\realplayer\browserrecord\components\nprpbrowserrecordplugin.dllFF - plugin: c:\documents and settings\рџр»р°рјрµрѕ\local settings\application data\google\update\1.2.145.5\npGoogleOneClick8.dllFF - plugin: c:\program files\google\google earth plugin\npgeplugin.dllFF - plugin: c:\program files\google\update\1.2.141.5\npGoogleOneClick7.dllFF - plugin: c:\program files\google\update\1.2.145.5\npGoogleOneClick8.dllFF - plugin: c:\program files\opera\program\plugins\np_gp.dll ============= SERVICES / DRIVERS =============== R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-3-23 9968]R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-3-23 72944]R2 ekrn;Eset Service;c:\program files\eset\eset smart security\ekrn.exe [2008-10-24 468224]R2 PD91Agent;PD91Agent;c:\program files\raxco\perfectdisk2008\PD91Agent.exe [2008-12-31 693512]R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-3-23 7408]R3 vmfilter303;vmfilter303;c:\windows\system32\drivers\vmfilter303.sys [2009-4-9 428160]S2 gupdate1c9badc96537230;Услуга Google Update (gupdate1c9badc96537230);c:\program files\google\update\GoogleUpdate.exe [2009-4-11 133104]S3 getPlus® Helper;getPlus® Helper;c:\program files\nos\bin\getplus_helpersvc.exe --> c:\program files\nos\bin\getPlus_HelperSvc.exe [?]S3 PD91Engine;PD91Engine;c:\program files\raxco\perfectdisk2008\PD91Engine.exe [2008-12-31 910600] =============== Created Last 30 ================ 2009-05-08 21:55 <DIR> --d-hr-- c:\documents and settings\пламен\Recent2009-05-08 17:23 <DIR> --d----- c:\documents and settings\пламен\DoctorWeb2009-05-07 20:41 <DIR> --d----- c:\program files\common files\ODBC2009-05-06 08:56 0 a------- c:\windows\ams70.INI2009-05-06 01:09 <DIR> --d----- c:\docume~1\92c1~1\applic~1\Free Sound Recorder2009-05-05 14:05 231 a------- c:\windows\info2009-05-05 00:34 <DIR> --d----- c:\docume~1\92c1~1\applic~1\IndigoRose2009-05-05 00:34 <DIR> --d----- c:\docume~1\92c1~1\applic~1\Thinstall2009-05-05 00:34 400 a------- c:\windows\system32VSKD.0012009-05-04 15:03 <DIR> --d----- c:\docume~1\alluse~1\applic~1\VirtualFarm2009-05-04 02:12 <DIR> --d----- c:\program files\sisagp2009-05-04 02:12 36,992 a------- c:\windows\system32\drivers\SISAGPX.SYS2009-05-03 18:13 <DIR> --d----- c:\program files\Vista Icons For XP2009-05-03 18:02 71,184 a----r-- c:\windows\system32\drivers\DefragFS.sys2009-05-03 17:59 <DIR> --d----- c:\program files\Vista Drive Icon2009-05-01 19:03 <DIR> --d----- c:\docume~1\92c1~1\applic~1\Audio Recorder for Free2009-05-01 19:02 1,986,560 a------- c:\windows\system32\NCTAudioFile2.dll2009-05-01 19:02 966,144 a------- c:\windows\system32\NCTAudioInformation2.dll2009-05-01 19:02 634,880 a------- c:\windows\system32\NCTAudioEditor2.dll2009-05-01 19:02 522,752 a------- c:\windows\system32\NCTAudioTransform2.dll2009-05-01 19:02 478,208 a------- c:\windows\system32\NCTAudioVisualization2.dll2009-05-01 19:02 467,968 a------- c:\windows\system32\NCTAudioRecord2.dll2009-05-01 19:02 467,456 a------- c:\windows\system32\NCTAudioPlayer2.dll2009-05-01 19:02 417,792 a------- c:\windows\system32\NCTTextToAudio2.dll2009-05-01 19:02 348,160 a------- c:\windows\system32\NCTWMAFile2.dll2009-05-01 19:02 113,486 a------- c:\windows\system32\NCTWMAProfiles.prx2009-05-01 19:02 479,744 a------- c:\windows\system32\NCTAudioCDGrabber2.dll2009-04-30 21:10 <DIR> --d-h--- c:\windows\system32\CyberInstallerUninstallerSystem2009-04-30 20:07 <DIR> --d----- c:\program files\gfx2009-04-30 19:37 <DIR> --d----- c:\program files\CreateInstall Free2009-04-30 15:01 276 a------- c:\windows\system\cmicnfg.ini2009-04-30 14:56 736 -------- c:\windows\setup.ini2009-04-30 14:56 266,240 a------- c:\windows\CMIUninstall.exe2009-04-30 14:56 225,280 a------- c:\windows\CmiRmRedundDir.exe2009-04-30 14:56 28,672 a------- c:\windows\CMIRmDriver.dll2009-04-30 14:56 <DIR> --d----- c:\program files\C-Media 3D Audio2009-04-30 14:55 <DIR> --d----- c:\program files\C-Media AC97 driver 51.3 for Win2K-XP2009-04-30 14:48 0 a------- c:\windows\wininit.ini2009-04-30 13:52 <DIR> --d----- c:\program files\HMSoft2009-04-29 23:49 167,936 a------- c:\windows\system32\ccrpftv6.ocx2009-04-29 22:07 <DIR> --d----- c:\program files\NSIS2009-04-29 21:35 2 a------- c:\windows\EzInstA1.LRU2009-04-29 19:14 <DIR> --d----- c:\program files\ISTool2009-04-29 19:14 <DIR> --d----- c:\docume~1\92c1~1\applic~1\ISTool2009-04-29 19:13 <DIR> --d----- c:\program files\Inno Setup 52009-04-29 00:43 <DIR> --d----- c:\windows\Icons2009-04-28 14:05 107,864 a------- c:\windows\system32\tsccvid.dll2009-04-27 19:20 <DIR> --d----- c:\program files\IZArc2009-04-26 18:08 <DIR> --d----- c:\docume~1\alluse~1\applic~1\phenomedia2009-04-25 22:11 <DIR> --d----- c:\program files\Magic Video Converter2009-04-25 14:45 639 a------- c:\windows\7THLEVEL.INI2009-04-25 00:25 221,184 a------- c:\windows\system32\wmpns.dll2009-04-24 22:46 2,145,280 -c------ c:\windows\system32\dllcache\ntkrnlmp.exe2009-04-24 22:46 2,189,056 -c------ c:\windows\system32\dllcache\ntoskrnl.exe2009-04-24 22:46 2,023,936 -c------ c:\windows\system32\dllcache\ntkrpamp.exe2009-04-24 22:46 2,560 -------- c:\windows\system32\xpsp4res.dll2009-04-24 22:27 73 a------- c:\windows\EurekaLog.ini2009-04-24 17:43 5,120 a--sh--- c:\windows\system32\Thumbs.db2009-04-21 19:37 <DIR> --d----- c:\program files\PicPick2009-04-20 01:25 125 a------- c:\windows\system32\temp_0000_65-20.aok2009-04-20 01:25 126 a------- c:\windows\system32\test.aok2009-04-20 01:24 258,048 a------- c:\windows\system32\GplMpgDec.ax2009-04-20 01:24 242,176 a------- c:\windows\system32\fixflash.exe2009-04-20 01:24 129,024 a------- c:\windows\system32\AVERM.dll2009-04-20 01:24 28,672 a------- c:\windows\system32\AVEQT.dll2009-04-18 18:33 86,016 a------- c:\windows\unvise32.exe2009-04-18 02:08 168,448 a------- c:\windows\system32\unrar.dll2009-04-18 02:08 414 a------- c:\windows\system32\lame_acm.xml2009-04-18 02:08 839,680 a------- c:\windows\system32\lameACM.acm2009-04-18 02:08 217,088 a------- c:\windows\system32\yv12vfw.dll2009-04-18 02:08 118,784 a------- c:\windows\system32\ac3acm.acm2009-04-18 02:08 3,596,288 a------- c:\windows\system32\qt-dx331.dll2009-04-18 02:08 795,648 a------- c:\windows\system32\xvidcore.dll2009-04-18 02:08 130,048 a------- c:\windows\system32\xvidvfw.dll2009-04-18 02:08 86,016 a------- c:\windows\system32\dpl100.dll2009-04-18 02:08 684,032 a------- c:\windows\system32\divx.dll2009-04-18 02:08 67,584 a------- c:\windows\system32\ff_vfw.dll2009-04-18 02:08 547 a------- c:\windows\system32\ff_vfw.dll.manifest2009-04-18 02:08 <DIR> --d----- c:\program files\K-Lite Codec Pack2009-04-18 00:45 <DIR> --d----- c:\program files\GRETECH2009-04-17 23:56 <DIR> --d----- c:\program files\Flock2009-04-16 22:15 <DIR> --d----- c:\program files\mp3DirectCut2009-04-16 19:43 <DIR> --d----- c:\program files\AEDiction2009-04-16 17:12 <DIR> --d----- c:\docume~1\92c1~1\applic~1\XnView2009-04-16 16:54 <DIR> --d----- c:\program files\Stardock2009-04-16 16:54 <DIR> --d----- c:\program files\common files\Stardock2009-04-15 00:43 27,648 a------- c:\windows\system32\AVSredirect.dll2009-04-15 00:42 70,656 a------- c:\windows\system32\i420vfw.dll2009-04-15 00:38 92,672 ---shr-- c:\windows\system32\RLVorbisDec.ax2009-04-15 00:38 67,584 ---shr-- c:\windows\system32\RLTheoraDec.ax2009-04-15 00:38 51,712 ---shr-- c:\windows\system32\RLSpeexDec.ax2009-04-15 00:38 186,880 ---shr-- c:\windows\system32\RLOgg.ax2009-04-15 00:38 179,200 ---shr-- c:\windows\system32\DiracSplitter.ax2009-04-15 00:38 175,104 ---shr-- c:\windows\system32\CoreAAC.ax2009-04-15 00:38 81,920 ---shr-- c:\windows\system32\aac_parser.ax2009-04-15 00:13 487,424 a------- c:\windows\system32\msvcp70.dll2009-04-15 00:13 344,064 a------- c:\windows\system32\msvcr70.dll2009-04-14 20:50 <DIR> --d----- c:\docume~1\alluse~1\applic~1\FreshGames2009-04-14 16:19 50 a------- c:\windows\cdplayer.ini2009-04-12 23:55 272,128 -c------ c:\windows\system32\dllcache\bthport.sys2009-04-12 23:55 272,128 -------- c:\windows\system32\drivers\bthport.sys2009-04-12 23:51 455,296 -c------ c:\windows\system32\dllcache\mrxsmb.sys2009-04-12 23:39 <DIR> --d----- c:\windows\system32\PreInstall2009-04-12 23:39 <DIR> --d-h--- c:\windows\$hf_mig$2009-04-12 23:33 <DIR> --d----- c:\windows\system32\SoftwareDistribution2009-04-12 19:08 <DIR> --d----- c:\program files\uTorrent2009-04-12 18:38 <DIR> --d----- c:\docume~1\92c1~1\applic~1\URSoft2009-04-12 18:38 <DIR> --d----- c:\program files\Your Uninstaller 20082009-04-12 17:36 <DIR> --d----- c:\windows\system32\appmgmt2009-04-12 16:36 <DIR> --d----- c:\documents and settings\пламен\LocalLow2009-04-12 16:15 <DIR> --d----- C:\Downloads2009-04-12 16:14 <DIR> --d----- c:\program files\BitComet2009-04-12 16:11 <DIR> --d----- c:\program files\FlashGet2009-04-12 16:09 <DIR> --d----- c:\docume~1\92c1~1\applic~1\uTorrent2009-04-12 14:55 <DIR> --d----- c:\program files\common files\xing shared2009-04-12 14:55 <DIR> --d----- c:\program files\common files\Real2009-04-12 14:53 <DIR> --d----- c:\program files\vloader2009-04-12 14:20 107,368 a------- c:\windows\system32\GEARAspi.dll2009-04-12 14:20 23,400 a------- c:\windows\system32\drivers\GEARAspiWDM.sys2009-04-12 14:20 <DIR> --d----- c:\docume~1\alluse~1\applic~1\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}2009-04-12 14:16 <DIR> --d----- c:\program files\Spider Video Downloader2009-04-12 14:09 410,984 a------- c:\windows\system32\deploytk.dll2009-04-12 14:09 73,728 a------- c:\windows\system32\javacpl.cpl2009-04-11 22:47 <DIR> --d----- C:\Estir20032009-04-11 22:45 <DIR> --d----- c:\program files\Estir20032009-04-11 13:23 <DIR> --ds---- c:\documents and settings\пламен\UserData2009-04-11 00:20 <DIR> --d----- c:\documents and settings\пламен\dwhelper2009-04-10 19:29 348,160 a------- c:\windows\system32\msvcr71.dll2009-04-10 01:16 <DIR> --d----- c:\program files\Mp3_Siem2009-04-10 00:52 <DIR> --d----- c:\windows\pss2009-04-10 00:45 <DIR> --d-h--- c:\windows\system32\GroupPolicy2009-04-10 00:20 <DIR> --d----- c:\program files\XnView2009-04-10 00:02 <DIR> --d----- c:\program files\The KMPlayer2009-04-09 23:47 <DIR> --d----- c:\program files\VanyoG2009-04-09 23:47 299,520 a------- c:\windows\uninst.exe2009-04-09 23:47 <DIR> --d----- c:\documents and settings\пламен\WINDOWS2009-04-09 23:40 <DIR> --d----- c:\program files\Skype2009-04-09 23:28 <DIR> --d----- c:\program files\RocketDock2009-04-09 23:26 <DIR> --d----- c:\program files\BACL2009-04-09 23:18 <DIR> --d----- c:\docume~1\92c1~1\applic~1\FlashFXP2009-04-09 23:18 <DIR> --d----- c:\program files\FlashFXP2009-04-09 23:14 <DIR> --d----- c:\program files\Everest2009-04-09 23:05 116 a------- c:\windows\NeroDigital.ini2009-04-09 23:04 <DIR> --d----- c:\docume~1\92c1~1\applic~1\JLC's Software2009-04-09 23:04 <DIR> --d----- c:\program files\JLC's Software2009-04-09 23:03 <DIR> --d----- c:\docume~1\92c1~1\applic~1\FastStone2009-04-09 23:03 <DIR> --d----- c:\program files\FastStone Image Viewer2009-04-09 23:02 47,360 a------- c:\windows\system32\drivers\pcouffin.sys2009-04-09 23:00 <DIR> --d----- c:\program files\Screamer Radio2009-04-09 22:58 <DIR> --d----- c:\program files\CCleaner2009-04-09 22:51 <DIR> --d----- c:\docume~1\92c1~1\applic~1\Weather Clock2009-04-09 22:51 <DIR> --d----- c:\program files\Weather Clock2009-04-09 22:48 <DIR> --d----- c:\program files\Raxco2009-04-09 22:43 376 a------- c:\windows\ODBC.INI2009-04-09 22:43 17,920 a------- c:\windows\system32\mdimon.dll2009-04-09 22:41 <DIR> --d----- c:\program files\common files\L&H2009-04-09 22:41 <DIR> --d----- c:\program files\Microsoft ActiveSync2009-04-09 22:40 <DIR> --d----- c:\windows\SHELLNEW2009-04-09 22:33 160,640 a------- c:\windows\system32\drivers\a347bus.sys2009-04-09 22:33 5,248 a------- c:\windows\system32\drivers\a347scsi.sys2009-04-09 22:33 <DIR> --d----- c:\program files\Alcohol Soft2009-04-09 22:25 <DIR> --d----- c:\program files\IObit2009-04-09 22:24 <DIR> --d----- c:\program files\8start Launcher2009-04-09 22:18 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com2009-04-09 22:17 <DIR> --d----- c:\program files\SUPERAntiSpyware2009-04-09 22:17 <DIR> --d----- c:\docume~1\92c1~1\applic~1\SUPERAntiSpyware.com2009-04-09 22:17 <DIR> --d----- c:\program files\common files\Wise Installation Wizard2009-04-09 22:09 <DIR> --d----- c:\program files\Spybot - Search & Destroy2009-04-09 22:09 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy2009-04-09 22:05 <DIR> --d----- c:\docume~1\92c1~1\applic~1\Malwarebytes2009-04-09 22:05 15,504 a------- c:\windows\system32\drivers\mbam.sys2009-04-09 22:05 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys2009-04-09 22:05 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes2009-04-09 22:05 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware2009-04-09 21:13 <DIR> --d----- c:\docume~1\92c1~1\applic~1\BSplayer Pro2009-04-09 21:12 <DIR> --d----- c:\program files\Webteh2009-04-09 21:00 4,444 a------- c:\windows\system32\pid.PNF2009-04-09 20:57 57,600 a------- c:\windows\system32\drivers\redbook.sys2009-04-09 20:56 32,768 a------- c:\windows\system32\drivers\sisnic.sys2009-04-09 20:56 74,240 a------- c:\windows\system32\usbui.dll2009-04-09 20:56 20,992 a------- c:\windows\system32\drivers\RTL8139.sys2009-04-09 20:56 40,960 a------- c:\windows\system32\drivers\SISAGP.SYS2009-04-09 20:55 <DIR> --d----- c:\program files\common files\SpeechEngines2009-04-09 20:54 <DIR> --d--r-- c:\documents and settings\all users\Documents2009-04-09 20:54 144,484 ac------ c:\windows\system32\dllcache\netfx.cat2009-04-09 20:54 <DIR> --d----- c:\program files\Nero2009-04-09 20:53 261 a------- c:\windows\system32\$winnt$.inf2009-04-09 20:48 <DIR> --d----- c:\docume~1\92c1~1\applic~1\AIMP2009-04-09 20:47 <DIR> --d----- c:\program files\AIMP22009-04-09 20:45 <DIR> --d----- c:\program files\VisualTaskTips2009-04-09 20:44 <DIR> --d----- c:\program files\Unlocker2009-04-09 20:26 <DIR> --d----- c:\program files\T610-T616-T630 Handset Manager2009-04-09 20:26 <DIR> --d----- c:\docume~1\92c1~1\applic~1\MobileAction2009-04-09 20:10 <DIR> --d----- c:\program files\IVT Corporation2009-04-09 20:08 <DIR> --d----- c:\program files\Multimedia Keyboard Driver2009-04-09 19:31 <DIR> --d----- c:\docume~1\92c1~1\applic~1\ESET2009-04-09 19:30 <DIR> --d----- c:\program files\ESET2009-04-09 19:13 <DIR> --d----- c:\program files\Windows Media Connect 22009-04-09 18:16 <DIR> --ds---- c:\documents and settings\пламен\Cookies2009-04-09 18:16 <DIR> --d-hr-- c:\documents and settings\пламен\Application Data2009-04-09 18:16 <DIR> --d--r-- c:\documents and settings\пламен\Favorites2009-04-09 18:16 <DIR> --d----- c:\documents and settings\пламен\Desktop2009-04-09 18:16 8,650,752 a---h--- c:\documents and settings\пламен\NTUSER.DAT2009-04-09 18:16 <DIR> --d-hr-- c:\documents and settings\пламен\SendTo2009-04-09 18:16 <DIR> --d-h--- c:\documents and settings\пламен\Templates2009-04-09 18:16 <DIR> --d-h--- c:\documents and settings\пламен\PrintHood2009-04-09 18:16 <DIR> --d-h--- c:\documents and settings\пламен\NetHood2009-04-09 18:16 <DIR> --d-h--- c:\documents and settings\пламен\Local Settings2009-04-09 18:16 <DIR> --d--r-- c:\documents and settings\пламен\Start Menu2009-04-09 18:16 <DIR> --d--r-- c:\documents and settings\пламен\My Documents2009-04-09 18:07 <DIR> --dsh--- c:\documents and settings\all users\DRM2009-04-09 18:06 <DIR> --d-h--- c:\program files\WindowsUpdate2009-04-09 18:06 <DIR> --d----- c:\program files\common files\MSSoap2009-04-09 18:04 <DIR> --d----- c:\program files\Online Services2009-04-09 18:03 <DIR> --d----- c:\program files\Messenger2009-04-09 18:03 <DIR> --d----- c:\program files\MSN Gaming Zone2009-04-09 18:03 <DIR> --d----- c:\program files\Windows NT ==================== Find3M ==================== 2009-04-15 22:10 86,627 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat2009-04-12 16:15 2,560 a------- c:\windows\system32\BitCometRes.dll2009-04-12 14:55 499,712 a------- c:\windows\system32\msvcp71.dll2009-04-09 20:41 60,357 a------- c:\windows\system32\uninstWMPbg.exe2009-04-09 18:04 21,640 a------- c:\windows\system32\emptyregdb.dat2009-03-06 17:22 284,160 a------- c:\windows\system32\pdh.dll2009-02-20 11:10 666,112 a------- c:\windows\system32\wininet.dll2009-02-20 11:10 81,920 a------- c:\windows\system32\ieencode.dll2009-02-09 15:10 729,088 a------- c:\windows\system32\lsasrv.dll2009-02-09 15:10 714,752 a------- c:\windows\system32\ntdll.dll2009-02-09 15:10 617,472 a------- c:\windows\system32\advapi32.dll2009-02-09 15:10 401,408 a------- c:\windows\system32\rpcss.dll2009-02-09 14:13 1,846,784 a------- c:\windows\system32\win32k.sys2001-11-23 12:08 712,704 a----r-- c:\windows\inf\other\AUDIO3D.DLL ============= FINISH: 22:05:36,98 ===============DDS (Ver_09-03-16.01) Microsoft Windows XP ProfessionalBoot Device: \Device\HarddiskVolume1Install Date: 09.4.2009 г. 18:11:36System Uptime: 05.8.2009 г. 15:37:41 (-2129 hours ago) Motherboard: ECS | | K7S5A Processor: AMD Athlon XP 2000+ | Socket-A | 1659/66mhz ==== Disk Partitions ========================= A: is RemovableC: is FIXED (NTFS) - 12 GiB total, 2,116 GiB free.D: is FIXED (NTFS) - 26 GiB total, 4,891 GiB free.E: is CDROM ()G: is CDROM ()H: is CDROM ()I: is CDROM ()J: is CDROM ()K: is CDROM ()L: is CDROM ()M: is CDROM ()N: is CDROM () ==== Disabled Device Manager Items ============= Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}Description: SiS 900-Based PCI Fast Ethernet AdapterDevice ID: PCI\VEN_1039&DEV_0900&SUBSYS_0A141019&REV_90\3&61AAA01&0&18Manufacturer: SiSName: SiS 900-Based PCI Fast Ethernet AdapterPNP Device ID: PCI\VEN_1039&DEV_0900&SUBSYS_0A141019&REV_90\3&61AAA01&0&18Service: SISNIC ==== System Restore Points =================== RP73: 03.5.2009 г. 19:32:42 - Before uninstall SSE Setup 5.2RP74: 03.5.2009 г. 19:32:44 - Before uninstall Adobe Shockwave Player 11.5RP75: 03.5.2009 г. 19:32:46 - Removed iTunesRP76: 03.5.2009 г. 19:32:48 - Before uninstall Apple Mobile Device SupportRP77: 03.5.2009 г. 19:32:51 - Removed QuickTimeRP78: 03.5.2009 г. 19:32:55 - Installed QuickTimeRP79: 03.5.2009 г. 19:32:57 - Removed Apple Software UpdateRP80: 06.5.2009 г. 23:23:40 - Installed SiSAGP driverRP81: 06.5.2009 г. 23:23:42 - Before uninstall UltraISO Premium V9.32RP82: 06.5.2009 г. 23:23:44 - Installed AutoPlay Media Studio 7.5 TrialRP83: 06.5.2009 г. 23:23:47 - Software Distribution Service 3.0RP84: 08.5.2009 г. 21:29:45 - Installed Windows XP WgaNotify.RP85: 08.5.2009 г. 21:29:48 - Контролна точка на систематаRP86: 08.5.2009 г. 21:29:53 - Software Distribution Service 3.0 ==== Installed Programs ====================== Архиватор WinRARµTorrentБългарски интерфейс за WinAmp 5.5Български интерфейс за Your Uninstaller! Pro 2008 6.1.1232Български интерфейсен пакет за FlashFXP v3.4.0.1145Пакет за езиков интерфейс на WindowsA4 TECH PC Camera HAdobe Flash Player 10 ActiveXAdobe Flash Player PluginAEnglish Dictionary XP 1.72AIMP2Allok Video to FLV Converter 5.2.0202AutoPlay Media Studio 7.0BitComet 0.81BlueSoleilBSPlayerC-Media 3D AudioC-Media AC97 driver 51.3 for Win2K-XPCCleaner (remove only)CreateInstall freeESET Smart SecurityFastStone Image Viewer 3.7FlashFXP v3FlashGet(Jetcar) 1.81Free Sound RecorderGOM PlayerGoogle ЗемяGoogle ChromeGoogle Earth PluginGoogle Update HelperHM NIS Edit 2.0.3ImgBurnInno Setup, версия 5.2.3ISTool 5.2.1.0IZArc 4.0 beta 1Java 6 Update 13JLC's Internet TVK-Lite Codec Pack 4.6.2 (Full)Longhorn Theme 4Malwarebytes' Anti-MalwareMicrosoft .NET Framework 2.0Microsoft Compression Client Pack 1.0 for Windows XPMicrosoft Office 2003 Bulgarian User Interface PackMicrosoft Office Professional Edition 2003Microsoft User-Mode Driver Framework Feature Pack 1.0Mozilla Firefox (3.0.10)Multimedia Keyboard DriverNero 7 Ultra EditionNullsoft Install SystemNVIDIA DriversObjectDockOpera 9.64PerfectDisk 2008 ProfessionalQuickTimeRealPlayerRocketDock 1.3.5Royale Remixed ThemeScreamer RadioSiSAGP driverSkype™ 3.8Smart Defrag 1.03Smart Install Maker 5.02SpeechLabSpybot - Search & DestroySUPERAntiSpyware Free EditionSVD 1.4.6T610-T616-T630 Handset ManagerThe KMPlayer 2.9.3.1429Unlocker 1.8.7Vista Drive Icon 1.4Visual Task Tips 2.3vloader 2.4VP-EYEWeather Clock 3.5WebFldrs XPWinampWindows Genuine Advantage Notifications (KB905474)Windows Media Format 11 runtimeWindows Media Player 11Windows Media Player Firefox PluginXnView 1.96Your Uninstaller! 2008 Version 6.2 ==== Event Viewer Messages From Past Week ======== 04.5.2009 г. 00:11:40, error: Dhcp [1002] - The IP address lease 192.168.0.65 for the Network Card with network address 001D0FC2E819 has been denied by the DHCP server 192.168.10.171 (The DHCP Server sent a DHCPNACK message).03.5.2009 г. 19:23:35, error: Dhcp [1002] - The IP address lease 192.168.0.95 for the Network Card with network address 001D0FC2E819 has been denied by the DHCP server 192.168.10.171 (The DHCP Server sent a DHCPNACK message).03.5.2009 г. 19:21:47, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.02.5.2009 г. 17:17:48, error: Dhcp [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 001D0FC2E819. The following error occurred: The semaphore timeout period has expired. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.01.5.2009 г. 23:37:26, error: Dhcp [1002] - The IP address lease 192.168.0.21 for the Network Card with network address 001D0FC2E819 has been denied by the DHCP server 192.168.10.171 (The DHCP Server sent a DHCPNACK message).01.5.2009 г. 22:06:59, error: Dhcp [1002] - The IP address lease 192.168.0.104 for the Network Card with network address 001D0FC2E819 has been denied by the DHCP server 192.168.10.171 (The DHCP Server sent a DHCPNACK message).07.5.2009 г. 10:44:44, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the Dnscache service.07.5.2009 г. 19:30:14, error: Tcpip [4199] - The system detected an address conflict for IP address 192.168.0.30 with the system having network hardware address 00:1F:E2:66:3B:D1. Network operations on this system may be disrupted as a result.07.5.2009 г. 21:14:40, error: Dhcp [1002] - The IP address lease 192.168.0.30 for the Network Card with network address 001D0FC2E819 has been denied by the DHCP server 192.168.10.171 (The DHCP Server sent a DHCPNACK message).07.5.2009 г. 21:50:29, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.08.5.2009 г. 13:00:06, error: Dhcp [1002] - The IP address lease 192.168.0.134 for the Network Card with network address 001D0FC2E819 has been denied by the DHCP server 192.168.10.171 (The DHCP Server sent a DHCPNACK message). ==== End Of File =========================== За сега ми допада ESS (понеже е на Български),но искам да ви попитам - защитната и стена да я оставя ли в автоматичен режим или да я включа в интерактивен??? Цитирай Link to comment Сподели другаде More sharing options...
plamen74.72 Публикувано Май 8, 2009 Author Report Share Публикувано Май 8, 2009 Има ли нещо нередно в логовете??? Цитирай Link to comment Сподели другаде More sharing options...
B-boy/StyLe/ Публикувано Май 8, 2009 Report Share Публикувано Май 8, 2009 Лога ти от RSIT, който ми прати на Л.С. бе непълен. Доста обемен лог, но не мисля, че е чак толкова зле положението. Провери на този адрес: http://www.virustotal.com/img/VirusTotal-logo.png следните файлове: C:\WINDOWS\system32\pvyvm.exe C:\WINDOWS\system32\fixflash.exe C:\WINDOWS\unvise32.exe C:\Documents and Settings\Пламен\oib.exe Можеш да изтриеш следните папки: C:\Program Files\trend microC:\rsitc:\documents and settings\пламен\DoctorWeb Изтрий услугата - getPlus® Helper (явно останала след деинсталацията на Adobe Reader). Отвори Notepad и въведи: @echo offsc stop getPlus® Helpersc delete getPlus® Helperdel fix.bat Запази файла с име fix.bat и го стартирай Няма да е зле да провериш с още антивирусни (тези не се нуждаят от инсталиране): http://forums.softvisia.com/index.php?show...amp;#entry68242 Като приключиш можеш да ги изтриеш и да почистиш временните файлове и System Restore-a. Цитирай Link to comment Сподели другаде More sharing options...
Night_Raven Публикувано Май 9, 2009 Report Share Публикувано Май 9, 2009 1. plamen74.72 не давай зор. Не е учтиво.2. Какви са тия потайни помощи? Дявол да го вземе, това е форум. Идеята е да се помага публично, а не всеки да си общува на ЛС зад кулисите. Да не би да трябва да се забрани използването на системата за лични съобщения? Цитирай Link to comment Сподели другаде More sharing options...
plamen74.72 Публикувано Май 9, 2009 Author Report Share Публикувано Май 9, 2009 1. plamen74.72 не давай зор. Не е учтиво.2. Какви са тия потайни помощи? Дявол да го вземе, това е форум. Идеята е да се помага публично, а не всеки да си общува на ЛС зад кулисите. Да не би да трябва да се забрани използването на системата за лични съобщения?Много се извинявам ,не исках да ви давам зор! А колкото до ЛС-то ,бях помолен лично от B-boy/StyLe/ да му пратя логовете на ЛС, но ще ги публикувам и тук!Той ме помоли за лог от тази дето и Night_Raven поиска последно - DDS и също и тази RSIT - цитат от ЛС-то:Каква е тази програма, защото излежда съмнителна ? C:\Documents and Settings\Пламен\oib.exeМожеш да ми дадеш и един лог от RSIT или DDS http://images.malwareremoval.com/random/RSIT.exe http://download.bleepingcomputer.com/sUBs/dds.scrА ето ги и логовете от RSIT:log.txtinfo.txt А ето и нови логове от DDS след почистване на системата и новото и стартиране днес:DDS.txtAttach.txt Дано този път да няма нищо опасно!!! п.с.B-boy/StyLe/ не се сърди че публикувах ЛС-то ти ,но Night_Raven е прав - трябва да става публично - нали за това е форума!!! Цитирай Link to comment Сподели другаде More sharing options...
plamen74.72 Публикувано Май 13, 2009 Author Report Share Публикувано Май 13, 2009 Извинете ме ,че отново отварям темата ,но не успях да разбера дали има нещо нередно в логовете които поискахте или още не ми е свършило наказанието за моето прибързване по горе??? Цитирай Link to comment Сподели другаде More sharing options...
Night_Raven Публикувано Май 14, 2009 Report Share Публикувано Май 14, 2009 Продължавам да не виждам нищо опасно. Цитирай Link to comment Сподели другаде More sharing options...
plamen74.72 Публикувано Май 14, 2009 Author Report Share Публикувано Май 14, 2009 Продължавам да не виждам нищо опасно. Благодаря Night_Raven - вече наистина ще дишам спокойно!!! Цитирай Link to comment Сподели другаде More sharing options...
Препоръчан пост
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.