![]() |
| |||||||
| Inregistrare | Site-ul Spy | Lista de stat | Doneaza | Căuta | Posturi de azi | Marchează forumurile citite | Forum Regulamentul |
|
![]() |
| | Thread Tools |
|
#1
| ||||||||||||
| ||||||||||||
| În primul rând am presupunând că acesta este locul potrivit pentru a pune acest lucru. M-am dus în panoul de control şi de performanţă şi a găsit o pereche de probleme de performanţă a spune:
Incepand încet: http://i7.photobucket.com/albums/y27...tartslowly.jpg Închiderea: http://i7.photobucket.com/albums/y27...downslowly.jpg De asemenea, am alergat HijackThis şi a luat acest mesaj: http://i7.photobucket.com/albums/y27...rormessage.jpg Aceasta este, probabil, o întrebare foarte prost, dar cum pot să remedieze aceste? Dacă voi putea punctul de mine în direcţia cea bună, care ar fi grozav.
__________________
__________________
Euro Championships tip = Spania & Torres <- Fir-ar ar fi trebuit sa pus un pariu pe ele Make Poverty History Justiţie pentru 96 <- Vă rugăm să aruncaţi o privire Sistemul meu: HistoryGirls Self Build!
|
|
#2
| |||
| |||
| Cu Vista va trebui să faceţi clic dreapta pe pictograma HJT şi a alege "a alerga as Administrator". Ai făcut orice întreţinere în ultima vreme? Curăţire disc, Defrag? |
|
#3
| |||
| |||
| Da, am am alerga Curăţire disc si defrag recent ar fi că ceea ce a fost cauzează probleme? Noua HijackThis Log: Citat:
__________________ Euro Championships tip = Spania & Torres <- Fir-ar ar fi trebuit sa pus un pariu pe ele Make Poverty History Justiţie pentru 96 <- Vă rugăm să aruncaţi o privire |
|
#4
| |||
| |||
| Deschide HijackThis şi selectaţi Fă-un sistem de scanare numai. Se pune un semn de selectare lângă următoarele menţiuni: (dacă există)
Important: Închideţi toate ferestrele cu excepţia HijackThis apoi faceţi clic pe Fix verificate. Exit HijackThis. ---------- Descarca ComboFix © de sUBs de la unul din link-urile de mai jos. Asiguraţi-vă că aţi început să-l salvaţi în Spaţiul de lucru. Link # 1 Link # 2 ** Notă: Este important că este salvat direct pe Desktop Închideţi orice deschide browsere. (Firefox, Internet Explorer, etc), înainte de a începe ComboFix. Temporar dezactiva al tău antivirus, Precum şi orice antispyware de protecţie în timp real înainte care efectuează o scanare. Faceţi clic pe acest link pentru a vedea o listă de programe de securitate care ar trebui să fie cu handicap şi modul de dezactivare a lor. Faceţi dublu clic combofix.exe & urmăriţi solicitările. Când aţi terminat ComboFix va produce un jurnal pentru tine. Post de ComboFix jurnal în următoarea replică. Important: Nu mouseclick ComboFix de fereastră în timp ce se execută. Care pot determina să-l băga în grajd. Amintiţi-vă să vă reactiva de protecţie antivirus şi antispyware, atunci când ComboFix este completă. Dacă aveţi probleme cu ComboFix de utilizare, a se vedea Cum să utilizaţi ComboFix |
|
#5
| |||
| |||
| În primul rând mulţumesc pentru ajutor şi sfaturi. I-am făcut ceea ce aţi spus HJT şi că a fost bine. Cu toate acestea l-am facut ca pe link-ul spune că în ceea ce priveşte dezactivarea scutului rezident AVG, dar în ciuda acestui cînd I try şi a alerga ComboFix ea, încă, spune AVG Anti-Virus se execută astfel încât nu sunt destul de sigur de ce. Vrei sa sugereze poate reporni sistemul meu?
__________________ Euro Championships tip = Spania & Torres <- Fir-ar ar fi trebuit sa pus un pariu pe ele Make Poverty History Justiţie pentru 96 <- Vă rugăm să aruncaţi o privire |
|
#6
| |||
| |||
| AVG si Combofix au această problemă. Chiar a alerga ComboFix oricum. În cazul în care AVG încearcă să blocheze it apoi atunci doar să îi permită să ruleze. |
|
#7
| |||
| |||
| Dreapta ok făcut tot. Log solicitat ca. Citat:
__________________ Euro Championships tip = Spania & Torres <- Fir-ar ar fi trebuit sa pus un pariu pe ele Make Poverty History Justiţie pentru 96 <- Vă rugăm să aruncaţi o privire |
|
#8
| |||
| |||
| Ştergeţi aceste fişiere / foldere, după cum urmează: 1. Du-te la Porni > Fugi > Tip Notepad.exe şi faceţi clic pe OK pentru a deschide Notepad. El / ea trebui fi Notepad, nu Wordpad. 2. Copia textul în caseta de mai jos codul de evidenţă tot textul şi apăsând Ctrl + C Cod: Killall:: Inregistrare:: [-HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Security Center \ de monitorizare a \ SymantecAntiVirus] [-HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Security Center \ de monitorizare a \ SymantecFirewall] [-HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ mountpoints2 \ E] [-HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ mountpoints2 \ (c1865685-0291-11dc-b943-806e6f6e6963)] Firefox:: FF - prefs.js: browser.search.defaulturl - hxxp: / / search.conduit.com / ResultsExt.aspx? ctid = CT1178131 & SearchSource = 3 & q = CF - prefs.js: browser.search.selectedEngine - Web Search 4. Apoi, faceţi clic pe Dosar > Economisi 5. Nume de fişier CFScript.txt - Salvaţi fişierul pe spaţiul de lucru 6. Apoi, glisaţi CFScript (ţineţi butonul stânga al mouse-ului în timp ce fişierul de lungă durată) şi fixaţi-l (de eliberare din stânga mouse-ul) în ComboFix.exe după cum puteţi vedea în imaginea de mai jos. Important: Efectua această instrucţiune cu atenţie! ![]() ComboFix vor începe să execute, urmaţi solicitările. După repornirea sistemului (în cazul în care le cere să reporniţi), aceasta va produce un jurnal pentru tine. Post că jurnal (Combofix.txt) în următoarea replică. Notă: Nu mouseclick ComboFix de fereastră în timp ce se execută. Care pot determina sistemul dvs. pentru a se congela ---------- Descărcaţi Norton Eliminarea Tool (SymNRT) pe Desktop. Odată descărcat şi vă rugăm să închideţi toate browserele deschis, de asemenea, cu excepţia orice lucru, deoarece acest lucru poate necesita un restart.
---------- Java este de actualitate. Versiunile mai vechi au vulnerabilities rău că site-uri pot utiliza pentru a infecta sistemul dumneavoastră. Mai întâi instalaţi noul Sun Java Runtime Environment Aveţi grijă să închideţi toate ferestrele browser-ului înainte de a începe instalarea. Eliminaţi versiunea veche (e) Descărca JavaRa
Nota: De Java rapida pentru începători (JQS.exe) adaugă un serviciu de a îmbunătăţi iniţială de pornire timp de apleturile Java şi aplicaţii. Pentru a dezactiva JQS serviciu, dacă nu doriţi să o folosiţi, du-te la Start> Control Panel> Java> Avansat> Diverse şi unbifaţi caseta pentru Java rapida pentru începători. Faceţi clic pe OK şi reporniţi computerul. ---------- Descărca ATF Cleaner Atribune de pe Desktop. Alternative download link Notă: Vista utilizatorii trebuie să utilizeze Executare ca administrator
Reţineţi că sistemul dvs. va rula mai lent pentru un reboot sau două după ce au folosit acest instrument asa ca nu intra în panică. Important: Reporniţi computerul înainte de a continua. ---------- Cum este de calculator care rulează acum? |
|
#9
| |||
| |||
| Nou ComboFix Jurnal: ComboFix 09-03-29.04 - Chloe 2009-03-31 16:37:20.2 - NTFSx86 Microsoft ® Windows Vista ™ Ultimate 6.0.6001.1.1252.1.1033.18.2046.1173 [GMT 1:00] Running de la: C: \ Users \ Chloe \ Desktop \ ComboFix.exe Comandamentul switch-uri folosite:: C: \ Users \ Chloe \ Desktop \ CFScript.txt AV: AVG Anti-Virus Free * Pe-a permis accesul scanare * (Actualizat) FW: ZoneAlarm Firewall activat * * * Creat un nou punct de restabilire . ((((((((((((((((((((((((( Fişierele create de 2009-02-28 la 2009-03-31 ))))))))))) )))))))))))))))))))) . 2009-03-31 17:15. 2009-03-31 17:15 45.056 - a ------ C: \ windows \ system32 \ acovcnt.exe 2009-03-30 22:26. 2009-03-30 22:26 <DIR> d -------- C: \ Program Files \ MediaMonkey 2009-03-29 16:23. 2008-06-20 02:14 781.344 - un ------ C: \ windows \ system32 \ PresentationNative_v0300.dll 2009-03-29 16:23. 2008-06-20 02:14 622.080 - un ------ C: \ windows \ system32 \ icardagt.exe 2009-03-29 16:23. 2008-06-20 02:14 326.160 - un ------ C: \ windows \ system32 \ PresentationHost.exe 2009-03-29 16:23. 2008-06-20 02:14 105.016 - un ------ C: \ windows \ system32 \ e_v0300.dll PresentationCFFRasterizerNativ 2009-03-29 16:23. 2008-06-20 02:14 97.800 - a ------ C: \ windows \ system32 \ infocardapi.dll 2009-03-29 16:23. 2008-06-20 02:14 43.544 - a ------ C: \ windows \ system32 \ PresentationHostProxy.dll 2009-03-29 16:23. 2008-06-20 02:14 37.384 - a ------ C: \ windows \ system32 \ infocardcpl.cpl 2009-03-29 16:23. 2008-06-20 02:14 11.264 - a ------ C: \ windows \ system32 \ icardres.dll 2009-03-29 16:15. 2008-07-27 19:03 282.112 - un ------ C: \ windows \ system32 \ mscoree.dll 2009-03-29 16:15. 2008-07-27 19:03 96.760 - a ------ C: \ windows \ system32 \ dfshim.dll 2009-03-29 16:15. 2008-07-27 19:03 41.984 - a ------ C: \ windows \ system32 \ netfxperf.dll 2009-03-29 16:14. 2008-07-27 19:03 158.720 - un ------ C: \ windows \ system32 \ mscorier.dll 2009-03-29 16:14. 2008-07-27 19:03 83.968 - a ------ C: \ windows \ system32 \ mscories.dll 2009-03-29 13:52. 2009-03-29 13:53 <DIR> d -------- C: \ Program Files \ Defraggler 2009-03-29 13:26. 2008-02-23 05:38 170.496 - un ------ C: \ windows \ system32 \ tcpipcfg.dll 2009-03-29 13:26. 2008-02-23 03:41 22.528 - a ------ C: \ windows \ system32 \ netiougc.exe 2009-03-29 13:25. 2009-02-16 00:10 1.221.512 - o ------ C: \ windows \ system32 \ zpeng25.dll 2009-03-17 21:57. 2009-03-17 21:57 <DIR> d -------- C: \ Program Files \ Microsoft 2009-03-17 21:56. 2009-03-17 21:56 <DIR> d -------- C: \ windows \ PCHealth 2009-03-16 22:43. 2009-03-28 22:36 <DIR> d - h ----- C: \ $ $ AVG8.VAULT 2009-03-16 20:59. 2009-03-16 20:59 25 - a ------ C: \ windows \ cdplayer.ini 2009-03-14 00:34. 2008-12-05 05:32 428.544 - un ------ C: \ windows \ system32 \ EncDec.dll 2009-03-14 00:34. 2008-12-05 05:32 293.376 - un ------ C: \ windows \ system32 \ psisdecd.dll 2009-03-14 00:34. 2008-12-05 05:31 217.088 - un ------ C: \ windows \ system32 \ psisrndr.ax 2009-03-14 00:34. 2008-12-05 05:31 177.664 - un ------ C: \ windows \ system32 \ mpg2splt.ax 2009-03-14 00:34. 2008-12-05 05:31 80.896 - a ------ C: \ windows \ system32 \ MSNP.ax 2009-03-14 00:29. 2009-03-14 00:29 <DIR> d -------- C: \ programdata \ (00D89592-F643-4D8D-8F0F-AFAE0F14D4C3) 2009-03-14 00:29. 2009-03-14 00:29 <DIR> d -------- C: \ Program Files \ iTunes 2009-03-14 00:29. 2009-03-14 00:29 <DIR> d -------- C: \ Program Files \ iPod 2009-03-14 00:29. 2008-04-17 13:12 107.368 - un ------ C: \ windows \ system32 \ GEARAspi.dll 2009-03-14 00:29. 2009-01-15 13:19 23.848 - a ------ C: \ windows \ system32 \ drivers \ GEARAspiWDM.sys 2009-03-14 00:26. 2009-03-14 00:27 <DIR> d -------- C: \ Program Files \ QuickTime 2009-03-12 23:39. 2009-03-12 23:39 <DIR> d -------- C: \ programdata \ Kontiki 2009-03-12 23:39. 2009-03-12 23:39 <DIR> d -------- C: \ Program Files \ Kontiki 2009-03-12 23:39. 2009-03-12 23:39 <DIR> d -------- C: \ Program Files \ Channel4 2009-03-12 23:38. 2009-03-12 23:38 <DIR> d -------- C: \ programdata \ Channel4 2009-03-11 22:33. 2009-03-31 17:16 <DIR> d -------- C: \ Users \ Chloe \ de calc 2009-03-11 22:22. 2009-03-11 22:22 <DIR> d -------- C: \ Program Files \ Windows Live SkyDrive 2009-03-11 22:22. 2009-03-17 21:57 <DIR> d -------- C: \ Program Files \ Windows Live 2009-03-11 21:57. 2009-03-11 21:57 <DIR> d -------- C: \ Program Files \ Common Files \ Windows Live 2009-03-11 13:13. 2009-03-11 21:47 <DIR> d -------- C: \ Program Files \ Amazon 2009-03-11 13:13. 2009-03-11 13:13 107.272 - un ------ C: \ windows \ system32 \ drivers \ avgtdix.sys 2009-03-11 02:09. 2009-01-15 04:36 1.383.424 - o ------ C: \ windows \ system32 \ mshtml.tlb 2009-03-11 02:09. 2009-01-15 07:11 827.392 - un ------ C: \ windows \ system32 \ Wininet.dll 2009-03-11 02:05. 2008-12-16 04:29 8.147.456 - o ------ C: \ windows \ system32 \ wmploc.DLL 2009-03-11 02:05. 2008-12-16 06:31 7.680 - o ------ C: \ windows \ system32 \ spwmp.dll 2009-03-11 02:05. 2008-12-16 06:31 4.096 - o ------ C: \ windows \ system32 \ msdxm.ocx 2009-03-11 02:05. 2008-12-16 06:31 4.096 - o ------ C: \ windows \ system32 \ dxmasf.dll 2009-03-11 02:03. 2008-12-16 03:42 288.768 - un ------ C: \ windows \ system32 \ drivers \ srv.sys 2009-03-11 02:03. 2008-11-27 05:43 268.288 - un ------ C: \ windows \ system32 \ schannel.dll 2009-03-11 02:02. 2009-02-09 04:10 2.033.152 - o ------ C: \ windows \ system32 \ Win32k.sys 2009-02-06 19:52. 2009-02-06 19:52 49.504 - a ------ C: \ windows \ system32 \ sirenacm.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Raport )))))))) )))))))))))))))))))))))))))))))))))))))))))) . 2009-03-31 16:15 --------- d --- aw C: \ programdata \ Temp 2009-03-31 16:14 350.195 --- ha-w C: \ windows \ system32 \ drivers \ vsconfig.xml 2009-03-29 14:42 --------- d ----- WC: \ programdata \ Spybot - Search & Destroy 2009-03-29 14:42 --------- d ----- WC: \ Program Files \ Spybot - Search & Destroy 2009-03-29 14:42 --------- d ----- WC: \ Program Files \ CCleaner 2009-03-19 16:48 --------- d ----- WC: \ Users \ Chloe \ AppData \ Roaming \ uTorrent 2009-03-16 19:58 --------- d ----- WC: \ Program Files \ \ Common Files \ Real 2009-03-13 23:29 --------- d ----- WC: \ programdata \ Apple Computer 2009-03-13 23:29 --------- d ----- WC: \ Program Files \ \ Common Files \ Apple 2009-03-13 23:27 --------- d ----- WC: \ Program Files \ Bonjour 2009-03-12 22:24 --------- d ----- WC: \ Program Files \ Google 2009-03-11 23:07 --------- d ----- WC: \ Program Files \ Microsoft Silverlight 2009-03-11 23:05 --------- d ----- WC: \ Program Files \ Windows Mail 2009-03-11 12:13 325,128 ---- aw C: \ windows \ system32 \ drivers \ avgldx86.sys 2009-03-11 11:52 --------- d ----- WC: \ programdata \ avg8 2009-02-15 23:11 293,528 ---- aw C: \ windows \ system32 \ drivers \ vsdatant.sys 2009-01-14 20:20 55.232 ---- aw C: \ Users \ Chloe \ AppData \ Roaming \ GDIPFONTCACHEV1.DAT 2008-12-31 21:51 13.025 ---- aw C: \ Users \ Chloe \ AppData \ Roaming \ nvModes.dat 2008-12-31 14:32 174 - Sha-w C: \ Program Files \ desktop.ini 2008-11-19 15:31 81.920 ---- aw C: \ Users \ Chloe \ AppData \ Roaming \ ezpinst.exe 2008-11-19 15:31 47.360 ---- aw C: \ Users \ Chloe \ AppData \ Roaming \ pcouffin.sys 2007-05-31 18:23 77.160 ---- aw C: \ Users \ Chloe \ DSETUP.dll 2007-05-31 18:23 503,144 ---- aw C: \ Users \ Chloe \ DXSETUP.exe 2007-05-31 18:23 1.673.576 ---- aw C: \ Users \ Chloe \ dsetup32.dll . ((((((((((((((((((((((((((((( SnapShot@2009-03-30_22.13.33.29 )))))))))) ))))))))))))))))))))))))))))))) . + 2009-03-31 16:14:31 2.048 - Sha-w C: \ windows \ ServiceProfiles \ LocalService \ AppData \ Lo cal \ lastalive0.dat + 2009-03-31 16:14:31 2.048 - Sha-w C: \ windows \ ServiceProfiles \ LocalService \ AppData \ Lo cal \ lastalive1.dat - 2009-03-30 21:07:56 1.048.576 - Sha-w C: \ windows \ ServiceProfiles \ LocalService \ NTUSER.DAT + 2009-03-31 16:15:44 1.048.576 - Sha-w C: \ windows \ ServiceProfiles \ LocalService \ NTUSER.DAT - 2009-03-30 21:07:56 1.048.576 - Sha-w C: \ windows \ ServiceProfiles \ NetworkService \ NTUSER.D AT + 2009-03-31 16:15:44 1.048.576 - Sha-w C: \ windows \ ServiceProfiles \ NetworkService \ NTUSER.D AT - 2009-03-30 21:07:06 16.384 - Sha-w C: \ windows \ system32 \ config \ systemprofile \ AppData \ L Locală \ Microsoft \ Windows \ istoric \ History.IE5 \ index.d la + 2009-03-31 16:14:35 16.384 - Sha-w C: \ windows \ system32 \ config \ systemprofile \ AppData \ L Locală \ Microsoft \ Windows \ istoric \ History.IE5 \ index.d la - 2009-03-30 21:07:06 32.768 - Sha-w C: \ windows \ system32 \ config \ systemprofile \ AppData \ L Locală \ Microsoft \ Windows \ Temporary Internet Files \ Content.IE5 \ index.dat + 2009-03-31 16:14:35 32.768 - Sha-w C: \ windows \ system32 \ config \ systemprofile \ AppData \ L Locală \ Microsoft \ Windows \ Temporary Internet Files \ Content.IE5 \ index.dat - 2009-03-30 21:07:06 16.384 - Sha-w C: \ windows \ system32 \ config \ systemprofile \ AppData \ oaming R \ Microsoft \ Windows \ Cookies \ index.dat + 2009-03-31 16:14:35 16.384 - Sha-w C: \ windows \ system32 \ config \ systemprofile \ AppData \ r oaming \ Microsoft \ Windows \ Cookies \ index.dat - 2009-03-30 19:05:35 126.818 ---- aw C: \ windows \ system32 \ perfc007.dat + 2009-03-31 15:21:23 126.818 ---- aw C: \ windows \ system32 \ perfc007.dat - 2009-03-30 19:05:35 119.076 ---- aw C: \ windows \ system32 \ perfc009.dat + 2009-03-31 15:21:23 119.076 ---- aw C: \ windows \ system32 \ perfc009.dat - 2009-03-30 19:05:35 127.578 ---- aw C: \ windows \ system32 \ perfc00C.dat + 2009-03-31 15:21:23 127.578 ---- aw C: \ windows \ system32 \ perfc00C.dat - 2009-03-30 19:05:35 124.352 ---- aw C: \ windows \ system32 \ perfc010.dat + 2009-03-31 15:21:23 124.352 ---- aw C: \ windows \ system32 \ perfc010.dat - 2009-03-30 19:05:35 130.866 ---- aw C: \ windows \ system32 \ perfc013.dat + 2009-03-31 15:21:23 130.866 ---- aw C: \ windows \ system32 \ perfc013.dat - 2009-03-30 19:05:35 130.272 ---- aw C: \ windows \ system32 \ perfc019.dat + 2009-03-31 15:21:23 130.272 ---- aw C: \ windows \ system32 \ perfc019.dat - 2009-03-30 19:05:35 620.942 ---- aw C: \ windows \ system32 \ perfh007.dat + 2009-03-31 15:21:23 620.942 ---- aw C: \ windows \ system32 \ perfh007.dat - 2009-03-30 19:05:35 644.794 ---- aw C: \ windows \ system32 \ perfh009.dat + 2009-03-31 15:21:23 644.794 ---- aw C: \ windows \ system32 \ perfh009.dat - 2009-03-30 19:05:35 672.380 ---- aw C: \ windows \ system32 \ perfh00C.dat + 2009-03-31 15:21:23 672.380 ---- aw C: \ windows \ system32 \ perfh00C.dat - 2009-03-30 19:05:35 666.234 ---- aw C: \ windows \ system32 \ perfh010.dat + 2009-03-31 15:21:23 666.234 ---- aw C: \ windows \ system32 \ perfh010.dat - 2009-03-30 19:05:35 669.852 ---- aw C: \ windows \ system32 \ perfh013.dat + 2009-03-31 15:21:23 669.852 ---- aw C: \ windows \ system32 \ perfh013.dat - 2009-03-30 19:05:35 657.990 ---- aw C: \ windows \ system32 \ perfh019.dat + 2009-03-31 15:21:23 657.990 ---- aw C: \ windows \ system32 \ perfh019.dat - 2009-03-30 19:03:55 17.414 ---- aw C: \ windows \ system32 \ WDI \ (86432a0b-3c7d-4ddf-a89c-172faa90485d) \ S-1-5-21-3600620296-2450975610 - 132854369-1000_UserData.bin + 2009-03-31 16:17:14 18.026 ---- aw C: \ windows \ system32 \ WDI \ (86432a0b-3c7d-4ddf-a89c-172faa90485d) \ S-1-5-21-3600620296-2450975610 - 132854369-1000_UserData.bin - 2009-03-30 19:03:55 81.750 ---- aw C: \ windows \ system32 \ WDI \ BootPerformanceDiagnostics _SystemData.bin + 2009-03-31 16:17:14 81.884 ---- aw C: \ windows \ system32 \ WDI \ BootPerformanceDiagnostics _SystemData.bin - 2009-03-30 19:03:54 68.204 ---- aw C: \ windows \ system32 \ WDI \ tics_SystemData.bin ShutdownPerformanceDiagnos + 2009-03-31 15:15:30 68.346 ---- aw C: \ windows \ system32 \ WDI \ tics_SystemData.bin ShutdownPerformanceDiagnos . - Snapshot resetate la data curenta -- . ((((((((((((((((((((((((((((((((((((( Reg Se incarca Puncte )))))))))) )))))))))))))))))))))))))))))))))))))))) . . * Nota * gol intrări & legit default intrări nu sunt afişate REGEDIT4 [HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ Curre ntVersion \ Run] "RocketDock" = "C: \ Program Files \ RocketDock \ RocketDock.exe" [2007-09-02 495616] "msnmsgr" = "C: \ Program Files \ Windows Live \ Messenger \ msnmsgr.exe" [2009-02-06 3885408] "WMPNSCFG" = "C: \ Program Files \ Windows Media Player \ WMPNSCFG.exe" [2008-01-19 202240] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ Curr entVersion \ Run] "ASUS Screen Saver protector" = "C: \ windows \ ASScrPro.exe" [2007-05-15 33136] "IFXSPMGT" = "C: \ windows \ system32 \ ifxspmgt.exe" [2007-02-26 677408] "ZoneAlarm Client" = "C: \ Program Files \ Zone Labs \ ZoneAlarm \ zlclient.exe" [2009-02-16 981384] "SynTPEnh" = "C: \ Program Files \ Synaptics \ SynTP \ SynTPEnh.exe" [2007-03-01 857648] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ windows \ curr entversion \ policies \ system] "EnableUIADesktopToggle" = 0 (0x0) [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Windows] "AppInit_DLLs" = avgrsstx.dll APSHook.dll [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ drivers32] "msacm.ac3filter" = ac3filter.acm [HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ contro l \ Lsa] Notificarea Pachete REG_MULTI_SZ SceCli ASWLNPkg [HKLM \ ~ \ startupfolder \ C: ^ ^ programdata Microsoft ^ ^ OWS Vant Start Menu ^ Programs ^ Startup ^ WinZip Quick Pick.lnk] PATH = C: \ programdata \ Microsoft \ Windows \ Start Menu \ Programs \ Startup \ WinZip Quick Pick.lnk backup = C: \ windows \ PSS \ WinZip Quick Pick.lnk.CommonStartup backupExtension =. CommonStartup [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ shared tools \ msconfig \ startupreg \ 4oD] - o ------ 2007-04-23 12:23 1032640 C: \ Program Files \ Kontiki \ KHost.exe [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ shared tools \ msconfig \ startupreg \ Adobe Reader Speed Launcher] - o ------ 2008-06-12 02:38 34672 D: \ Program Files \ Reader \ reader_sl.exe [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Shared Tools \ msconfig \ startupreg \ ASUS Camera ScreenSaver] - o ------ 2007-05-15 05:12 37232 C: \ windows \ ASScrProlog.exe [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Shared Tools \ msconfig \ startupreg \ ATKMEDIA] - o ------ 2006-11-02 16:27 61440 C: \ Program Files \ ASUS \ ATK Media \ DMedia.exe [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ shared tools \ msconfig \ startupreg \ AVG8_TRAY] - o ------ 2009-03-11 13:13 1601304 C: \ Program ~ 1 \ AVG \ AVG8 \ avgtray.exe [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Shared Tools \ msconfig \ startupreg \ CognizanceTS] -ra ------ 2003-12-21 22:11 17920 C: \ Program ~ 1 \ ASUSSE ~ 1 \ ASUSSE ~ 1 \ Bin \ ASTSVCC.dll [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ shared tools \ msconfig \ startupreg \ ehTray.exe] - o ------ 2008-01-19 08:33 125952 C: \ windows \ ehome \ ehtray.exe [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Shared Tools \ msconfig \ startupreg \ Google Update] - A ---- t-2009-03-17 22:06 133104 C: \ Users \ Chloe \ AppData \ Local \ Google \ update \ pdate.exe GoogleU [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ shared tools \ msconfig \ startupreg \ iTunesHelper] - o ------ 2009-03-11 14:52 342312 C: \ Program Files \ iTunes \ iTunesHelper.exe [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ shared tools \ msconfig \ startupreg \ msnmsgr] - o ------ 2009-02-06 19:51 3885408 C: \ Program Files \ Windows Live \ Messenger \ msnmsgr.exe [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ shared tools \ msconfig \ startupreg \ NvCplDaemon] - o ------ 2007-04-04 12:40 8429568 C: \ windows \ system32 \ NvCpl.dll [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ shared tools \ msconfig \ startupreg \ NvMediaCenter] - o ------ 2007-04-04 12:40 81920 C: \ windows \ system32 \ NvMcTray.dll [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Shared Tools \ msconfig \ startupreg \ NvSvc] - o ------ 2007-04-04 12:40 86016 C: \ windows \ system32 \ nvsvc.dll [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ shared tools \ msconfig \ startupreg \ QuickTime Task] - o ------ 2009-01-05 17:18 413696 C: \ Program Files \ QuickTime \ winampa.exe [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Shared Tools \ msconfig \ startupreg \ RocketDock] - o ------ 2007-09-02 13:58 495616 C: \ Program Files \ RocketDock \ RocketDock.exe [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ shared tools \ msconfig \ startupreg \ SpybotSD TeaTimer] -rahs ---- 2009-03-05 16:07 2260480 C: \ Program Files \ Spybot - Search & Destroy \ TeaTimer.exe [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ shared tools \ msconfig \ startupreg \ SunJavaUpdateSched] - o ------ 2008-06-10 04:27 144784 C: \ Program Files \ Java \ jre1.6.0_07 \ bin \ winampa.exe [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ shared tools \ msconfig \ startupreg \ TkBellExe] - o ------ 2009-03-16 20:58 198160 C: \ Program Files \ Common Files \ Real \ Update_OB \ realsched.exe [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Shared Tools \ msconfig \ startupreg \ Windows Defender] - o ------ 2008-01-19 08:38 1008184 C: \ Program Files \ Windows Defender \ MSASCui.exe [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ shared tools \ msconfig \ startupreg \ WMPNSCFG] - o ------ 2008-01-19 08:33 202240 C: \ Program Files \ Windows Media Player \ wmpnscfg.exe [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Shared Tools \ msconfig \ startupreg \ (0228e555-4f9c-4e35-a3ec-b109a192b4c2)] - o ------ 2005-07-15 22:48 479232 C: \ Program Files \ Google \ Gmail Notifier \ gnotify.exe [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Shared Tools \ msconfig \ startupreg \ RtHDVCpl] - o ------ 2007-02-15 10:07 4390912 C: \ windows \ RtHDVCpl.exe [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Security Center \ Monitorizarea] "DisableMonitoring" = dword: 00000001 [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Security Center \ Monitorizarea \ ZoneLabsFirewall] "DisableMonitoring" = dword: 00000001 [HKLM \ ~ \ Services \ sharedaccess \ Parameters \ firewallpo licy \ DomainProfile] "EnableFirewall" = 0 (0x0) [HKLM \ ~ \ Services \ sharedaccess \ Parameters \ firewallpo licy \ FirewallRules] "(71E74FA5-D1FA-4A82-9121-AE2CACB2ED04)" = = Profil de privare | C: \ Program Files \ Windows Live \ Messenger \ livecall.exe: Windows Live Messenger (Telefon) "(2FE2345B-5C77-485E-9855-FC6024DE75EC)" = = Profil de privare | C: \ Program Files \ Windows Live \ Messenger \ livecall.exe: Windows Live Messenger (Telefon) "(CC9CFD37-6799-47CF-9AEE-1063F21C5548)" = = Profil de privare | C: \ Program Files \ Windows Live \ Messenger \ livecall.exe: Windows Live Messenger (Telefon) "(3D44E6E8-68F3-42F0-B97E-1081F1354874)" = UDP: C: \ Program Files \ LimeWire \ LimeWire.exe: LimeWire 4.12.15 "(B2393435-26B3-4482-A391-C964F3370D66)" = TCP: C: \ Program Files \ LimeWire \ LimeWire.exe: LimeWire 4.12.15 "(1B1039C9-3AEF-4B2E-85CA-DA79FB7CDBD3)" = cu handicap: C: \ Program Files \ Windows Live \ Messenger \ livecall.exe: Windows Live Messenger (Telefon) "(F9EC3544-5A35-4D84-A067-E7167563791A)" = cu handicap: C: \ Program Files \ Windows Live \ Messenger \ livecall.exe: Windows Live Messenger (Telefon) "(A9CE85F3-F9BA-4875-B169-9DEF59911C8A)" = cu handicap: C: \ Program Files \ Windows Live \ Messenger \ livecall.exe: Windows Live Messenger (Telefon) "TCP Solicitare Utilizator (0FAAFA32-F5A3-4C35-9AFD-A648E4B3016E) C: \ \ Program Files \ \ uTorrent \ \ utorrent.exe" = UDP: C: \ Program Files \ uTorrent \ utorrent.exe: uTorrent "UDP Solicitare Utilizator (CDC85196-C503-4F00-82DC-B95F8D021895) C: \ \ Program Files \ \ uTorrent \ \ utorrent.exe" = TCP: C: \ Program Files \ uTorrent \ utorrent.exe: uTorrent "TCP Solicitare Utilizator (5D761702-BEB7-4B94-B693-1A7EF8E441ED) C: \ \ Program Files \ \ WebTV usor si de radio \ \ easywebtv.exe" = UDP: C: \ Program Files \ WebTV usor & Radio \ easywebtv.exe : Web TV \ Radio \ Media "UDP Solicitare Utilizator (A7E2F9B1-976E-49B1-960A-8FE671DECB26) C: \ \ Program Files \ \ WebTV usor si de radio \ \ easywebtv.exe" = TCP: C: \ Program Files \ WebTV usor & Radio \ easywebtv.exe : Web TV \ Radio \ Media "(978D57EE-8CEF-4E88-B3CC-472590D8A602)" = C: \ Program Files \ Windows Live \ Messenger \ livecall.exe: Windows Live Messenger (Telefon) "(038AD6DB-57BA-4294-B6BE-DC5AC329D87A)" = C: \ Program Files \ Windows Live \ Messenger \ livecall.exe: Windows Live Messenger (Telefon) "TCP Solicitare Utilizator (20F3997A-2406-42BC-9A96-17DBA8717938) C: \ \ Program Files \ \ SoulSeek \ \ slsk.exe" = UDP: C: \ Program Files \ SoulSeek \ slsk.exe: SoulSeek "UDP Solicitare Utilizator (EBEDABDC-8DFA-4EA4-83A0-5D79C8A2BE45) C: \ \ Program Files \ \ SoulSeek \ \ slsk.exe" = TCP: C: \ Program Files \ SoulSeek \ slsk.exe: SoulSeek "TCP Solicitare Utilizator (A2D20908-089C-441B-B9C8-C8811AFCAB9E) C: \ \ Program Files \ \ \ LimeWire \ \ limewire.exe" = UDP: C: \ Program Files \ LimeWire \ limewire.exe: LimeWire "UDP Solicitare Utilizator (0B6B64F6-D6E9-4D1D-B83A-E6E85E360C05) C: \ \ Program Files \ \ LimeWire \ \ limewire.exe" = TCP: C: \ Program Files \ LimeWire \ limewire.exe: LimeWire "(2E890455-237D-4ABA-BE37-B5E6E1862834)" = C: \ Program Files \ Windows Live \ Messenger \ livecall.exe: Windows Live Messenger (Telefon) "(DDAAC8F6-7557-495A-82B3-EBFF9330A2CC)" = C: \ Program Files \ Windows Live \ Messenger \ livecall.exe: Windows Live Messenger (Telefon) "(5131D757-BC24-44C9-8EA5-E268DFC6DCAC)" = C: \ Program Files \ Windows Live \ Messenger \ livecall.exe: Windows Live Messenger (Telefon) "TCP Solicitare Utilizator (4C52E1A6-D998-41D5-8E99-27F21E3CA7CB) C: \ \ Program Files \ \ Mozilla Firefox \ \ firefox.exe" = UDP: C: \ Program Files \ Mozilla Firefox \ firefox.exe: Suplimente "UDP Solicitare Utilizator (80235B6B-2462-4AC3-8A59-7534841DE76B) C: \ \ Program Files \ \ Mozilla Firefox \ \ firefox.exe" = TCP: C: \ Program Files \ Mozilla Firefox \ firefox.exe: Suplimente "TCP Solicitare Utilizator (049DD1E6-8191-4983-A59D-240E79B46042) C: \ \ Program Files \ \ uTorrent \ \ utorrent.exe" = UDP: C: \ Program Files \ uTorrent \ utorrent.exe: uTorrent "UDP Solicitare Utilizator (9A00A32D-A675-4425-8F5E-1528AAB521FB) C: \ \ Program Files \ \ uTorrent \ \ utorrent.exe" = TCP: C: \ Program Files \ uTorrent \ utorrent.exe: uTorrent "TCP Solicitare Utilizator (348698D9-5A1D-4E1C-AC00-DBDC43BE0ACF) C: \ \ Program Files \ \ SoulSeek \ \ slsk.exe" = UDP: C: \ Program Files \ SoulSeek \ slsk.exe: SoulSeek "UDP Solicitare Utilizator (60AFF659-3A7C-488C-9CCA-0A8589DD32FA) C: \ \ Program Files \ \ SoulSeek \ \ slsk.exe" = TCP: C: \ Program Files \ SoulSeek \ slsk.exe: SoulSeek "TCP Solicitare Utilizator (3EF98A58-7B3C-42B1-8A5A-CF7DEF59C2A7) C: \ \ Program Files \ \ sopcast \ \ sopcast.exe" = UDP: C: \ Program Files \ sopcast \ sopcast.exe: SopCast principale de aplicare "UDP Solicitare Utilizator (D8A0735D-6D19-4482-A90A-35A9D023DEBE) C: \ \ Program Files \ \ sopcast \ \ sopcast.exe" = TCP: C: \ Program Files \ sopcast \ sopcast.exe: SopCast principale de aplicare "TCP Solicitare Utilizator (7B392C25-D64F-4897-B5CC-5C9B83106BB0) C: \ \ Program Files \ \ Mozilla Firefox \ \ firefox.exe" = UDP: C: \ Program Files \ Mozilla Firefox \ firefox.exe: Suplimente "UDP Solicitare Utilizator (9990806D-9198-4760-93E7-C65D44E1FE8A) C: \ \ Program Files \ \ Mozilla Firefox \ \ firefox.exe" = TCP: C: \ Program Files \ Mozilla Firefox \ firefox.exe: Suplimente "TCP Solicitare Utilizator (9998DAB7-D775-4620-A491-D752230551A3) C: \ \ Program Files \ \ Internet Explorer \ \ iexplore.exe" = UDP: C: \ Program Files \ Internet Explorer \ iexplore.exe: Internet Explorer "UDP Solicitare Utilizator (B9293167-A4DC-43ED-893B-B5B1B89F9988) C: \ \ Program Files \ \ Internet Explorer \ \ iexplore.exe" = TCP: C: \ Program Files \ Internet Explorer \ iexplore.exe: Internet Explorer "TCP Solicitare Utilizator (B04F6C2B-953A-469D-AFD8-4F3AE27A4941) C: \ \ \ Users \ Chloe \ \ AppData \ \ Roaming \ \ s opcast \ \ adv \ \ sopadver.exe" = UDP: C: \ Users \ Chloe \ AppData \ Roaming \ sopcast \ adv \ POS adver.exe: sopadver.exe "UDP Solicitare Utilizator (914B6A2A-9A2A-43A8-B4EA-BB1EEDC476B5) C: \ \ \ Users \ Chloe \ \ AppData \ \ Roaming \ \ s opcast \ \ adv \ \ sopadver.exe" = TCP: C: \ Users \ Chloe \ AppData \ Roaming \ sopcast \ adv \ POS adver.exe: sopadver.exe "TCP Solicitare Utilizator (69F8C35B-6614-4033-B40E-59012B10975A) C: \ \ Program Files \ \ bearflix \ \ bearflix.exe" = UDP: C: \ Program Files \ bearflix \ bearflix.exe: BearFlix "UDP Solicitare Utilizator (89ABF64F-F79E-456D-9136-82A8675A3E17) C: \ \ Program Files \ \ bearflix \ \ bearflix.exe" = TCP: C: \ Program Files \ bearflix \ bearflix.exe: BearFlix "(8D76BC83-ABC9-406B-8945-366EA3B7074B)" = UDP: C: \ Program Files \ SmartFTP Client \ SmartFTP.exe: SmartFTP Client "(9FC79C86-3E66-4A61-AA2A-FAB0C61E0453)" = TCP: C: \ Program Files \ SmartFTP Client \ SmartFTP.exe: SmartFTP Client "TCP Solicitare Utilizator (9FF9F89E-5323-45dB-89F0-BA37B84180EE) C: \ \ Program Files \ \ TVAnts \ \ tvants.exe" = UDP: C: \ Program Files \ TVAnts \ tvants.exe: TVAnts "UDP Solicitare Utilizator (C10505B7-BDD4-49BB-93E6-E73B8E6C4E33) C: \ \ Program Files \ \ TVAnts \ \ tvants.exe" = TCP: C: \ Program Files \ TVAnts \ tvants.exe: TVAnts "TCP Solicitare Utilizator (A9E241F3-D69C-4E67-938B-33C91AB576A1) C: \ \ Program Files \ \ TVUPlayer \ \ tvuplayer.exe" = UDP: C: \ Program Files \ TVUPlayer \ tvuplayer.exe: TVU Player Componenta "UDP Solicitare Utilizator (D3542B64-2CF9-4C20-B6CB-1D9096FF27EB) C: \ \ Program Files \ \ TVUPlayer \ \ tvuplayer.exe" = TCP: C: \ Program Files \ TVUPlayer \ tvuplayer.exe: TVU Player Componenta "(F8B68D6E-3A24-4B31-8261-FB3CA92B5740)" = C: \ Program Files \ Windows Live \ Messenger \ livecall.exe: Windows Live Messenger (Telefon) "TCP Solicitare Utilizator (4E95BA55-EDF5-491D-9059-F11FF353A128) C: \ \ \ Users \ Chloe \ \ AppData \ \ Roaming \ \ s opcast \ \ adv \ \ sopadver.exe" = UDP: C: \ Users \ Chloe \ AppData \ Roaming \ sopcast \ adv \ POS adver.exe: sopadver.exe "UDP Solicitare Utilizator (55C79E39-F1AC-45C7-8F99-995A835F089A) C: \ \ \ Users \ Chloe \ \ AppData \ \ Roaming \ \ s opcast \ \ adv \ \ sopadver.exe" = TCP: C: \ Users \ Chloe \ AppData \ Roaming \ sopcast \ adv \ POS adver.exe: sopadver.exe "TCP Solicitare Utilizator (A3EF2380-6740-4FD5-913E-D67F54A54B11) C: \ \ Program Files \ \ sopcast \ \ sopcast.exe" = UDP: C: \ Program Files \ sopcast \ sopcast.exe: SopCast principale de aplicare "UDP Solicitare Utilizator (E9C164FD-CB41-4D08-9DBA-BDDB929D1C86) C: \ \ Program Files \ \ sopcast \ \ sopcast.exe" = TCP: C: \ Program Files \ sopcast \ sopcast.exe: SopCast principale de aplicare "TCP Solicitare Utilizator (C1148110-2D5B-4810-8651-98FBFD3A6751) C: \ \ Program Files \ \ Internet Explorer \ \ iexplore.exe" = UDP: C: \ Program Files \ Internet Explorer \ iexplore.exe: Internet Explorer "UDP Solicitare Utilizator (F15683E5-A578-47EE-BEB1-4541978254F4) C: \ \ Program Files \ \ Internet Explorer \ \ iexplore.exe" = TCP: C: \ Program Files \ Internet Explorer \ iexplore.exe: Internet Explorer "TCP Solicitare Utilizator (CCA39E89-B85B-41BA-9A33-CA6DB37579E4) d: \ \ Program Files \ \ clue.exe" = UDP: D: \ Program Files \ \ clue.exe: Clue "UDP Solicitare Utilizator (39F3C83F-DCF0-43B4-B149-19F3630B3078) d: \ \ Program Files \ \ clue.exe" = TCP: D: \ Program Files \ \ clue.exe: Clue "(01834D55-82B5-480D-BEFF-52EDB82BB8B5)" = C: \ Program Files \ Windows Live \ Messenger \ livecall.exe: Windows Live Messenger (Telefon) "(90ECB35B-6897-4166-A35A-04BC39978BA9)" = C: \ Program Files \ AVG \ AVG8 \ avgemc.exe: avgemc.exe "(504F647E-1476-4948-AA42-DC1DF85CA9A8)" = C: \ Program Files \ AVG \ AVG8 \ avgupd.exe: avgupd.exe "(CC411EBB-9ACA-4217-9994-ABB961E83B3C)" = UDP: C: \ Program Files \ uTorrent \ uTorrent.exe: Torrent (TCP-In) "(031AA3B5-F93B-4E4B-9ED7-66C6B9FFF3E8)" = TCP: C: \ Program Files \ uTorrent \ uTorrent.exe: Torrent (UDP-In) "(1D54F818-ABAC-418F-8F39-17EA7664FABE)" = UDP: C: \ Program Files \ Bonjour \ mDNSResponder.exe: Bonjour "(3C9FFAF4-40EA-450F-A906-D34D3E2EFA72)" = TCP: C: \ Program Files \ Bonjour \ mDNSResponder.exe: Bonjour "(6AC9F5D1-C3AC-4878-8740-8A3E10F857E2)" = UDP: C: \ Program Files \ iTunes \ iTunes.exe: iTunes "(77045B5E-EC2E-4749-AC23-32130CD39567)" = TCP: C: \ Program Files \ iTunes \ iTunes.exe: iTunes "(00BE12C0-42CB-4B64-AA07-80A45C05B97C)" = cu handicap: UDP: C: \ Program Files \ Sports Interactive \ Football Manager 2008 \ fm.exe: Football Manager 2008 "(0A529C81-B8E4-4809-A54B-B5141A997A78)" = cu handicap: TCP: C: \ Program Files \ Sports Interactive \ Football Manager 2008 \ fm.exe: Football Manager 2008 [HKLM \ ~ \ Services \ sharedaccess \ Parameters \ firewallpo licy \ PublicProfile] "EnableFirewall" = 0 (0x0) [HKLM \ ~ \ Services \ sharedaccess \ Parameters \ firewallpo licy \ StandardProfile] "EnableFirewall" = 0 (0x0) R1 AvgLdx86; AVG Free AVI Loader Driver x86; c: \ windows \ system32 \ drivers \ avgldx86.sys [2008-12-24 325128] R1 AvgTdiX; AVG8 Reteaua Redirector; c: \ windows \ system32 \ drivers \ avgtdix.sys [2009-03-11 107272] R1 ItSDisk; ItSDisk; c: \ windows \ system32 \ drivers \ k.sys itsdis [2006-05-16 23496] R1 PersonalSecureDrive; PersonalSecureDrive; c: \ windows \ system32 \ drivers \ psd.sys [2007-01-23 39080] R2 ASBroker; Logon de şedinţă broker; C: \ windows \ system32 \ svchost.exe-k cunoştinţă [2008-08-07 21504] R2 ASChannel; locală de comunicare Channel; C: \ windows \ system32 \ svchost.exe-k cunoştinţă [2008-08-07 21504] R2 avg8emc; AVG Free8 E-mail Scanner; C: \ Program ~ 1 \ AVG \ AVG8 \ avgemc.exe [2009-03-11 903960] R2 avg8wd; AVG Free8 Watchdog; C: \ Program ~ 1 \ AVG \ AVG8 \ avgwdsvc.exe [2009-03-11 298264] R2 HDDlife HDD de acces de servicii; HDDlife HDD de acces de servicii; C: \ Program Files \ BinarySense \ HDDlife 3 \ hldasvc.exe [2007-08-09 816376] R2 SBSDWSCService; SBSD Centrul de securitate Service; C: \ Program Files \ Spybot - Search & Destroy \ SDWinSec.exe [2007-07-15 1153368] R2 StkSSrv; Syntek AVStream USB2.0 WebCam Service; C: \ windows \ system32 \ StkCSrv.exe [2007-02-07 24576] R3 AtcL001; NDIS miniport Driver pentru Attansic L1 Gigabit Ethernet Controller; c: \ windows \ system32 \ drivers \ atl01v32.sy s [2007-03-15 48128] R3 StkCMini; Syntek AVStream USB2.0 1.3M WebCam; c: \ windows \ system32 \ drivers \ StkCMini.sys [2007-02-13 1245056] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Svchost] bthsvcs REG_MULTI_SZ BthServ Cunoştinţă REG_MULTI_SZ ASBroker ASChannel [HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ curre ntversion \ Explorer \ mountpoints2 \ H] \ shell \ AutoRun \ command - H: \ LaunchU3.exe [HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ ntversion versiunea pentru telefoane mobile \ Explorer \ mountpoints2 \ (1a4a90a1-32d4-11dc-aa3d-001bfc03310e)] \ shell \ AutoRun \ command - H: \ LaunchU3.exe . Cuprins de la "Activităţi programate" dosar 2009-01-11 C: \ windows \ Tasks \ Defrag job-uri # 00.job - C: \ Program Files \ DiskTrix \ UltimateDefrag \ UDefrag.exe [] 2009-03-26 C: \ windows \ Tasks \ GoogleUpdateTaskUserS-1-5-21-3600620296-2450975610-132854369-1000.job - C: \ Users \ Chloe \ AppData \ Local \ Google \ update \ GoogleU pdate.exe [2009-03-17 22:06] 2009-03-30 C: \ windows \ Tasks \ User_Feed_Synchronization-(5963E371-2796-42F4-9A54-042DA9F406BC). De locuri de muncă - C: \ windows \ system32 \ msfeedssync.exe [2008-01-19 08:33] . . ------- Suplimentare Scan ------- . uStart Page = hxxp: / / www.google.co.uk/ uInternet Setări, ProxyOverride = *. local IE: E & xportaţi la Microsoft Excel - c: \ progra ~ 1 \ milionimi ~ 2 \ Office10 \ EXCEL.EXE/3000 FF - ProfilePath - C: \ Users \ Chloe \ AppData \ Roaming \ Mozilla \ Firefox \ Pro files \ ppnzryw9.default \ FF - prefs.js: browser.search.defaulturl - hxxp: / / search.conduit.com / ResultsExt.aspx? Ctid = CT1178131 & SearchSource = 3 & q = FF - prefs.js: browser.search.selectedEngine - Web Search FF - prefs.js: browser.startup.homepage - hxxp: / / www.google.co.uk/ FF - componenta: C: \ Program Files \ AVG \ AVG8 \ Firefox \ componente \ avgssff.dll FF - componenta: C: \ Program Files \ AVG \ AVG8 \ ToolbarFF \ componente \ vmAVGConnector. Dll FF - componenta: C: \ Program Files \ Real \ RealPlayer \ browserrecord \ componente \ NPR pbrowserrecordplugin.dll FF - Componenta: C: \ Users \ Chloe \ AppData \ Roaming \ Mozilla \ Firefox \ Pro files \ ppnzryw9.default \ extensii \ (463F6CA5-EE3C-4be1-B7E6-7FEE11953374) \ platforma \ WINNT \ componente \ FoxyTunes. dll FF - plug-in: C: \ Program Files \ Mozilla Firefox \ plugin-uri \ np-mswmp.dll FF - Plugin: C: \ Users \ Chloe \ AppData \ Local \ Google \ update \ 1.2.141 .5 \ npGoogleOneClick7.dll FF - Plugin: D: \ Program Files \ Reader \ browser-ul \ nppdf32.dll ---- FIREFOX POLITICI ---- FF - user.js: general.useragent.extra.zencast - Creative ZENcast v1.02.08); user_pref (general.useragent.extra.zencast, Creative ZENcast v2.00.07. ************************************************** ************************ catchme 0.3.1375 W2K/XP/Vista - rootkit / stealth malware detector de Gmer, http://www.gmer.net Rootkit scan 2009-03-31 17:16:10 Windows 6.0.6001 Service Pack 1 NTFS scanare ascuns procese ... "10ûÿét0ûÿ3ö9sHu [1166747253] 0x75636F44 "10ûÿét0ûÿ3ö9sHu [1166747253] 0x6F6D6D6F scanare ascuns autostart intrări ... scanare fişiere ascunse ... scanare sa finalizat cu succes fişiere ascunse: 0 ************************************************** ************************ . --------------------- DLLs Loaded Sub Running Processes --------------------- - - - - - - -> 'Lsass.exe "(704) C: \ Program Files \ ASUS Security Center \ ASUS Security Protect Manager \ bin \ ASWLNPkg.dll C: \ Program Files \ ASUS Security Center \ ASUS Security Protect Manager \ bin \ ItMsg.dll - - - - - - -> "Explorer.exe" (3304) C: \ Program Files \ RocketDock \ RocketDock.dll C: \ Program Files \ ASUS Security Center \ ASUS Security Protect Manager \ Bin \ SFSShell.dll C: \ Program Files \ ASUS Security Center \ ASUS Security Protect Manager \ Bin \ ItMsg.dll . ------------------------ Other Running Processes ----------------------- -- . C: \ windows \ system32 \ audiodg.exe c: \ windows \ system32 \ ZoneLabs \ vsmon.exe c: \ windows \ system32 \ wlanext.exe C: \ Program Files \ ATK Hotkey \ ASLDRSrv.exe C: \ Program Files \ ATKGFNEX \ GFNEXSrv.exe C: \ Program Files \ Common Files \ Apple \ Mobile Device Support \ bin \ AppleMobileDeviceService.exe C: \ Program Files \ Symantec \ LiveUpdate \ AluSchedulerSvc.exe C: \ Program Files \ Bonjour \ mDNSResponder.exe C: \ Program Files \ Intel \ Wireless \ bin \ EvtEng.exe c: \ progra ~ 1 \ AVG \ AVG8 \ avgrsx.exe c: \ progra ~ 1 \ AVG \ AVG8 \ avgnsx.exe C: \ Program Files \ Intel \ Intel Matrix Storage Manager \ IAANTmon.exe C: \ windows \ system32 \ IFXTCS.exe C: \ Program Files \ Common Files \ LightScribe \ LSSrvc.exe C: \ windows \ system32 \ IfxPsdSv.exe c: \ windows \ system32 \ PSIService.exe C: \ Program Files \ Intel \ Wireless \ bin \ RegSrvc.exe C: \ Program Files \ ASUS \ NB Probe \ SPM \ spmgr.exe C: \ Program Files \ AVG \ AVG8 \ avgcsrvx.exe C: \ Program Files \ ASUS Security Center \ ASUS Security Protect Manager \ Bin \ asghost.exe C: \ Program Files \ ATK Hotkey \ HControl.exe C: \ Program Files \ ATKOSD2 \ ATKOSD2.exe C: \ Program Files \ Wireless Console 2 \ wcourier.exe C: \ Program Files \ ASUS \ Splendid \ ACMON.exe C: \ Program Files \ P4G \ BatteryLife.exe C: \ windows \ system32 \ ACEngSvr.exe C: \ Program Files \ ATK Hotkey \ ATKOSD.exe c: \ windows \ system32 \ IfxUAGUI.exe C: \ Program Files \ Infineon \ Security platformă software \ PSDrt.exe C: \ Program Files \ Infineon \ Security platformă software \ SpTNA.exe C: \ windows \ system32 \ wbem \ WMIADAP.exe C: \ windows \ system32 \ dllhost.exe . ************************************************** ************************ . Finalizarea time: 2009-03-31 17:23:29 - masina a fost repornită ComboFix-carantină-files.txt 2009-03-31 16:23:16 ComboFix2.txt 2009-03-30 21:16:26 Pre-Run: 39213060096 bytes liber Post-Run: 38632595456 bytes liber Current = 1 Implicit = 1 a esuat = 0 LastKnownGood = 41 Seturi = 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18, 19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35, 36,37,38,39,40,41 396 --- EOF --- 2009-03-29 15:30:34
__________________ Euro Championships tip = Spania & Torres <- Fir-ar ar fi trebuit sa pus un pariu pe ele Make Poverty History Justiţie pentru 96 <- Vă rugăm să aruncaţi o privire |
|
#10
| |||
| |||
| În ceea ce priveşte eliminarea Norton N-am instalat Norton pe aici, aşa încât de ce este symantec enumerate?
__________________ Euro Championships tip = Spania & Torres <- Fir-ar ar fi trebuit sa pus un pariu pe ele Make Poverty History Justiţie pentru 96 <- Vă rugăm să aruncaţi o privire |