![]() |
| |||||||
| Inregistrare | Site-ul Spy | Lista de stat | Doneaza | Căuta | Posturi de azi | Marchează forumurile citite | Forum Regulamentul |
|
![]() |
| | Thread Tools |
|
#1
| |||
| |||
| Bine, asa ca le-am citit în jurul un pic şi se pare că există diverse soluţii. I'm running regula Windows Vista. CTRL ALT DEL nu funcţionează ... click dreapta nu funcţionează. atunci când am de căutare pentru taskmgr.exe se spune că a fost dezactivat de către administrator. Ce pot face? |
|
#2
| ||||||||||||
| ||||||||||||
| Vista este diferit la XP.
__________________
Click dreapta pe bara de activităţi, apoi faceţi clic pe Manager de activităţi. Sistemul meu: Hybr! D
|
|
#3
| |||
| |||
| Am făcut clic dreapta task bar şi este gri afară. Cu toate acestea am cautat in jurul un pic si am gasit un site cu o legătură directă cu reged meu şi ea mi-a dat avertismente şi apoi am ieşit afară pentru că am avut nici o idee despre ceea ce făceam. Ulterior din curiousity am cheked task bar şi nu a fost gri afară. I restarted meu calculator (pentru a vă asigura că nu a fost un lucru temporar) şi dintr-un motiv ciudat atunci când pe ecran pentru a autentifica-ar veni ... ea a spus apăsaţi CTRL ALT DEL pentru a va autentifica eu nu înţeleg ceea ce sa întâmplat . |
|
#4
| |||
| |||
| Iată Hijackthis meu jurnal C: \ Windows \ system32 \ taskeng.exe C: \ Windows \ system32 \ Dwm.exe C: \ Windows \ Explorer.exe C: \ Program Files \ Synaptics \ SynTP \ SynTPEnh.exe C: \ Program Files \ HP \ QuickPlay \ QPService.exe C: \ Program Files \ HP \ HP Software Update \ hpwuSchd2.exe C: \ Program Files \ Hewlett-Packard \ HP Quick Launch Buttons \ QLBCTRL.exe C: \ Program Files \ Hewlett-Packard \ HP Wireless Assistant \ WiFiMsg.exe C: \ Program Files \ Hewlett-Packard \ HP Wireless Assistant \ HPWAMain.exe C: \ Program Files \ Java \ jre1.6.0 \ bin \ jusched.exe C: \ Program Files \ Common Files \ Real \ Update_OB \ realsched.exe C: \ Program Files \ Common Files \ Symantec Shared \ ccApp.exe C: \ Program Files \ Comcast \ Desktop doctor \ bin \ sprtcmd.exe C: \ Program Files \ Windows Sidebar \ sidebar.exe C: \ Program Files \ Hewlett-Packard \ HP Advisor \ HPAdvisor.exe C: \ Windows \ system32 \ rundll32.exe C: \ WINDOWS \ ehome \ ehtray.exe C: \ Windows \ ehome \ ehmsas.exe C: \ Users \ Yasmany \ Desktop \ Veoh \ VeohClient.exe C: \ Program Files \ Google \ GoogleToolbarNotifier \ 1.2.1128.5462 \ G oogleToolbarNotifier.exe C: \ Program Files \ Common Files \ Adobe \ Updater5 \ AdobeUpdater.exe C: \ Program Files \ HP Connections \ 6811507 \ Program \ HP Connections.exe C: \ Windows \ system32 \ wbem \ unsecapp.exe C: \ PROGRA ~ 1 \ HEWLET ~ 1 \ Shared \ HPQTOA ~ 1.EXE C: \ Program Files \ Hewlett-Packard \ HP Advisor \ SSDK04.exe C: \ Program Files \ Internet Explorer \ ieuser.exe C: \ Program Files \ Internet Explorer \ iexplore.exe C: \ Program Files \ Common Files \ Microsoft Shared \ Windows Live \ WLLoginProxy.exe C: \ Windows \ system32 \ SearchFilterHost.exe C: \ Program Files \ Trend Micro \ HijackThis \ HijackThis.exe C: \ Windows \ system32 \ Macromed \ Flash \ FlashUtil9b.exe R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://www.comcast.net/ R1 - HKLM \ SOFTWARE \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...lion&pf=laptop R1 - HKLM \ SOFTWARE \ Microsoft \ Internet Explorer \ Main, Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM \ SOFTWARE \ Microsoft \ Internet Explorer \ Main, Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM \ SOFTWARE \ Microsoft \ Internet Explorer \ Main, Start Page = http://www.comcast.net/ R0 - HKLM \ SOFTWARE \ Microsoft \ Internet Explorer \ Search, SearchAssistant = R0 - HKLM \ SOFTWARE \ Microsoft \ Internet Explorer \ Search, CustomizeSearch = R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Window title = Windows Internet Explorer furnizate de către Comcast R1 - HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Int ernet Setări, ProxyServer =: 0 R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Toolbar, LinksFolderName = R3 - URLSearchHook: AOLTBSearch Class - (EA756889-43DB-2338-8F07-D1CA6FB9C90D) - C: \ Program Files \ AOL \ AIM Toolbar 5.0 \ aoltb.dll O1 - Hosts::: 1 localhost O2 - BHO: BHO mele Căutare - (014DA6C1-189F-421a-88CD-07CFE51CFF10) - C: \ Program Files \ MySearch \ bar \ 1.bin \ S4BAR.DLL O2 - BHO: Adobe PDF Reader Link Helper - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Program Files \ Adobe \ Acrobat 7.0 \ ActiveX \ AcroIEHelper.dll O2 - BHO: RealPlayer Descărcaţi Plug-in-ului şi a înregistra pentru Internet Explorer - (3049C3E9-B461-4BC5-8870-4C09146192CA) - C: \ Program Files \ Real \ RealPlayer \ rpbrowserrecordplugin.dll O2 - BHO: SSVHelper Class - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C: \ Program Files \ Java \ jre1.6.0 \ bin \ ssv.dll O2 - BHO: AOL Toolbar Launcher - (7C554162-8CB7-45A4-B8F4-8EA1C75885F9) - C: \ Program Files \ AOL \ AIM Toolbar 5.0 \ aoltb.dll O2 - BHO: (no name) - (7E853D72-626A-48EC-A868-BA8D5E23E045) - (no file) O2 - BHO: Windows Live Sign-in-Helper - (9030D464-4C02-4ABF-8ECC-5164760863C6) - C: \ Program Files \ Common Files \ Microsoft Shared \ Windows Live \ WindowsLiveLogin.dll O2 - BHO: BDEX System - (A8565FBC-8D53-4D4F-9BB0-CBC68A22B126) - C: \ Windows \ blopenvxdt.dll O2 - BHO: Google Toolbar Helper - (AA58ED58-01DD-4d91-8333-CF10577473F7) - C: \ Program Files \ Google \ googletoolbar1.dll O2 - BHO: FastRX - (E09962E7-A39E-4F60-8003-66D57BED27B7) - C: \ Windows \ system32 \ fastRX.dll (fişier lipsă) O3 - Toolbar: Bar mele Căutare - (014DA6C9-189F-421a-88CD-07CFE51CFF10) - C: \ Program Files \ MySearch \ bar \ 1.bin \ S4BAR.DLL O3 - Toolbar: Veoh Browser Plug-in - (D0943516-5076-4020-A3B5-AEFAF26AB263) - C: \ Users \ Yasmany \ Desktop \ Veoh \ Plugins \ reg \ VeohTool bar.dll O3 - Toolbar: & Google - (2318C2B1-4965-11d4-9B18-009027A5CD4F) - C: \ Program Files \ Google \ googletoolbar1.dll O3 - Toolbar: AIM Toolbar - (DE9C389F-3316-41A7-809B-AA305ED9D922) - C: \ Program Files \ AOL \ AIM Toolbar 5.0 \ aoltb.dll O3 - Toolbar: retnsrp - (CC304A4D-FC79-4CD3-9A67-46E3AF59319D) - C: \ Windows \ retnsrp.dll O4 - HKLM \ .. \ Run: [Windows Defender]% ProgramFiles% \ Windows Defender \ MSASCui.exe-a ascunde O4 - HKLM \ .. \ Run: [SynTPEnh] C: \ Program Files \ Synaptics \ SynTP \ SynTPEnh.exe O4 - HKLM \ .. \ Run: [QPService] "C: \ Program Files \ HP \ QuickPlay \ QPService.exe" O4 - HKLM \ .. \ Run: [HP Software Update] C: \ Program Files \ Hp \ HP Software Update \ HPWuSchd2.exe O4 - HKLM \ .. \ Run: [QlbCtrl]% ProgramFiles% \ Hewlett-Packard \ HP Quick Launch Buttons \ QlbCtrl.exe / Start O4 - HKLM \ .. \ Run: [HP stării de sănătate Scheduler] C: \ Program Files \ Hewlett-Packard \ HP stării de sănătate \ HPHC_Scheduler.exe O4 - HKLM \ .. \ Run: [WAWifiMessage]% ProgramFiles% \ Hewlett-Packard \ HP Wireless Assistant \ WiFiMsg.exe O4 - HKLM \ .. \ Run: [hpWirelessAssistant]% ProgramFiles% \ Hewlett-Packard \ HP Wireless Assistant \ HPWAMain.exe O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] "C: \ Program Files \ Java \ jre1.6.0 \ bin \ jusched.exe" O4 - HKLM \ .. \ Run: [kpx] C: \ Windows \ system32 \ C rundll32.exe: \ Windows \ system32 \ DllInitApp fastRX.dll O4 - HKLM \ .. \ Run: [NvSvc] RUNDLL32.EXE C: \ Windows \ system32 \ nvsvc.dll, nvsvcStart O4 - HKLM \ .. \ Run: [NvCplDaemon] RUNDLL32.EXE C: \ Windows \ system32 \ NvCpl.dll, NvStartup O4 - HKLM \ .. \ Run: [NvMediaCenter] RUNDLL32.EXE C: \ Windows \ system32 \ NvMcTray.dll, NvTaskbarInit O4 - HKLM \ .. \ Run: [TkBellExe] "C: \ Program Files \ Common Files \ Real \ Update_OB \ realsched.exe"-osboot O4 - HKLM \ .. \ Run: [SeekmoOE] C: \ Program Files \ Seekmo \ bin \ 10.0.341.0 \ OEAddOn.exe O4 - HKLM \ .. \ Run: [SeekmoSA] "C: \ Program Files \ Seekmo \ bin \ 10.0.341.0 \ SeekmoSA.exe" O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ QuickTime \ QTTask.exe"-atboottime O4 - HKLM \ .. \ Run: [ccApp] "C: \ Program Files \ Common Files \ Symantec Shared \ ccApp.exe" O4 - HKLM \ .. \ Run: [Symantec PIF AlertEng] "C: \ Program Files \ Common Files \ Symantec Shared \ PIF \ (B8E1DD85-8582-4c61-B58F-2F227FCA9A08) \ PIFSvc.exe" / a / m " C: \ Program Files \ Common Files \ Symantec Shared \ PIF \ (B8E1DD85-8582-4c61-B58F-2F227FCA9A08) \ AlertEng.dll " O4 - HKLM \ .. \ Run: [ddoctorv2] "C: \ Program Files \ Comcast \ Desktop doctor \ bin \ sprtcmd.exe" / P ddoctorv2 O4 - HKLM \ .. \ RunOnce: [Launcher]% WINDIR% \ SMINST \ launcher.exe O4 - HKCU \ .. \ Run: [Sidebar] C: \ Program Files \ Windows Sidebar \ sidebar.exe / autorun O4 - HKCU \ .. \ Run: [HPAdvisor] C: \ Program Files \ Hewlett-Packard \ HP Advisor \ HPAdvisor.exe O4 - HKCU \ .. \ Run: [Aim6] "C: \ Program Files \ AIM6 \ aim6.exe" / localizare d = en-US ee: / / AOL / imApp O4 - HKCU \ .. \ Run: [ehTray.exe] C: \ Windows \ ehome \ ehTray.exe O4 - HKCU \ .. \ Run: [Veoh] "C: \ Users \ Yasmany \ Desktop \ Veoh \ VeohClient.exe" / VeohHide O4 - HKCU \ .. \ Run: [MsnMsgr] "C: \ Program Files \ MSN Messenger \ MsnMsgr.Exe" / fundal O4 - HKCU \ .. \ Run: [swg] C: \ Program Files \ Google \ GoogleToolbarNotifier \ 1.2.1128.5462 \ G oogleToolbarNotifier.exe O4 - HKCU \ .. \ Run: [AdobeUpdater] C: \ Program Files \ Common Files \ Adobe \ Updater5 \ AdobeUpdater.exe O4 - HKCU \ .. \ Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll, ShowWelcomeCenter O4 - HKUS \ S-1-5-19 \ .. \ Run: [Sidebar]% ProgramFiles% \ Windows Sidebar \ Sidebar.exe / detectMem (User 'LOCAL SERVICE') O4 - HKUS \ S-1-5-19 \ .. \ Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll, ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS \ S-1-5-20 \ .. \ Run: [Sidebar]% ProgramFiles% \ Windows Sidebar \ Sidebar.exe / detectMem (User 'NETWORK SERVICE') O4 - Startup: LimeWire Pe Startup.lnk = C: \ Program Files \ LimeWire \ LimeWire.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C: \ Program Files \ Adobe \ Acrobat 7.0 \ Reader \ reader_sl.exe O4 - Global Startup: Adobe Reader Synchronizer.lnk = C: \ Program Files \ Adobe \ Reader 8.0 \ Reader \ AdobeCollabSync.exe O4 - Global Startup: HP Connections.lnk = C: \ Program Files \ HP Connections \ 6811507 \ Program \ HP Connections.exe O8 - Extra context menu item: & AOL Toolbar Search - C: \ Program Files \ AOL \ scopul bara de instrumente 5.0 \ resurse \ en-US \ local \ search.html O8 - Extra context menu item: E & xportaţi la Microsoft Excel - res: / / C: \ PROGRA ~ 1 \ milionimi ~ 3 \ Office12 \ EXCEL.EXE/3000 O9 - Extra button: (no name) - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0 \ bin \ ssv.dll O9 - Extra 'Tools' MENUITEM: Sun Java Console - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0 \ bin \ ssv.dll O9 - Extra button: Send to OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C: \ PROGRA ~ 1 \ milionimi ~ 3 \ Office12 \ ONBttnIE.dll O9 - Extra 'Tools' MENUITEM: S & la sfârşitul OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C: \ PROGRA ~ 1 \ milionimi ~ 3 \ Office12 \ ONBttnIE.dll O9 - Extra button: AIM Toolbar - (3369AF0D-62E9-4bda-8103-B4C75499B578) - C: \ Program Files \ AOL \ AIM Toolbar 5.0 \ aoltb.dll O9 - Extra button: Cercetare - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C: \ PROGRA ~ 1 \ milionimi ~ 3 \ Office12 \ REFIEBAR.DLL O13 - Gopher Prefix: O16 - DPF: (48DD0448-9209-4F81-9F6D-D83562940134) (MySpace Uploader Control) -- http://lads.myspace.com/upload/MySpaceUploader1005.cab O16 - DPF: (5D6F45B3-9043-443D-A792-115447494D24) (UnoCtrl Class) -- http://messenger.zone.msn.com/EN-US/.../GAME_UNO1.cab O16 - DPF: (67DABFBF-D0AB-41FA-9C46-CC0F21721616) (DivXBrowserPlugin Object) -- http://download.divx.com/player/DivXBrowserPlugin.cab O16 - DPF: (B8BE5E93-A60C-4D26-A2DC-220313175592) (MSN Games - Installer) -- http://messenger.zone.msn.com/binary...o.cab56649.cab O16 - DPF: (BD393C14-72AD-4790-A095-76522973D6B8) (CBreakshotControl Class) -- http://messenger.zone.msn.com/binary...t.cab57213.cab O16 - DPF: (C3F79A2B-B9B4-4A66-B012-3EE46475B072) (MessengerStatsClient Class) -- http://messenger.zone.msn.com/binary...t.cab56907.cab O16 - DPF: (DA758BB1-5F89-4465-975F-8D7179A4BCF3) (WheelofFortune Object) -- http://messenger.zone.msn.com/binary/WoF.cab57176.cab O21 - SSODL: leorop - (38CA8AE4-A78E-4111-8D0E-BDDF145A5040) - C: \ Windows \ leorop.dll O21 - SSODL: nopzet - (9543D4D7-3E5B-4B70-BB93-83AC9865627C) - C: \ Windows \ nopzet.dll O23 - Service: AddFiltr - Hewlett-Packard Development Company, LP - C: \ Program Files \ Hewlett-Packard \ HP Quick Launch Buttons \ AddFiltr.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C: \ Program Files \ Symantec \ LiveUpdate \ ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccSvcHst.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccSvcHst.exe O23 - Service: CyberLink Background Captură Service (CBCS) (CLCapSvc) - Unknown owner - C: \ Program Files \ HP \ QuickPlay \ Kernel \ TV \ CLCapSvc.exe O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C: \ Program Files \ HP \ QuickPlay \ Kernel \ TV \ CLSched.exe O23 - Service: Symantec LIC NetConnect serviciu (CLTNetCnService) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccSvcHst.exe O23 - Service: Google Updater Service (gusvc) - Google - C: \ Program Files \ Google \ Common \ Google Updater \ GoogleUpdaterService.exe O23 - Service: HP stării de sănătate Service - Hewlett-Packard - C: \ Program Files \ Hewlett-Packard \ HP stării de sănătate \ hphc_service.exe O23 - Service: hpqwmiex - Hewlett-Packard Development Company, LP - C: \ Program Files \ Hewlett-Packard \ Shared \ hpqwmiex.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C: \ Program Files \ Roxio \ Roxio MyDVD Basic v9 \ InstallShield \ Driver \ 1050 \ Intel 32 \ IDriverT.exe O23 - Service: Symantec Password Validation ESTE (ISPwdSvc) - Symantec Corporation - C: \ Program Files \ Norton AntiVirus \ isPwdSvc.exe O23 - Service: LightScribeService Direct Disc Etichetarea Service (LightScribeService) - Hewlett-Packard Company - C: \ Program Files \ Common Files \ LightScribe \ LSSrvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C: \ PROGRA ~ 1 \ Symantec \ LIVEUP ~ 1 \ LUCOMS ~ 1.EXE O23 - Service: LiveUpdate Notice Service ex (LiveUpdate Notice Ex) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccSvcHst.exe O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ PIF \ (B8E1DD85-8582-4c61-B58F-2F227FCA9A08) \ PIFSvc.exe O23 - Service: RoxMediaDB9 - Sonic Solutions - C: \ Program Files \ Common Files \ Roxio Shared \ 9.0 \ SharedCOM \ RoxMediaDB9.exe O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc - C: \ Program Files \ Comcast \ Desktop doctor \ bin \ sprtsvc.exe O23 - Service: stllssvr - MicroVision Dezvoltare, Inc - C: \ Program Files \ Common Files \ SureThing Shared \ stllssvr.exe O23 - Service: Symantec Core LC - Unknown owner - C: \ Program Files \ Common Files \ Symantec Shared \ CCPD-LC \ symlcsvc.exe O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ AppCore \ AppSvc32.exe O23 - Service: punct de vedere Manager Service - punct de vedere Corporation - C: \ Program Files \ punct de vedere \ Common \ ViewpointService.exe O23 - Service: XAudioService - Conexant Systems, Inc - C: \ Windows \ system32 \ drivers \ xaudio.exe |
|
#5
| |||
| |||
| Sistem de dvs. este ciuruite cu malware. Merge AICI şi urmaţi instrucţiunile exact. Post solicitat fişierele log. I `ll a lua un mod de a muta acest thread înapoi la forum de securitate. Nu stiu de ce-am mutat de acolo, în primul rând. Regards Howard. |
|
#6
| |||
| |||
| Înainte de a pune sus ceva Vreau să reţineţi că, atunci când m-am dus la spre a alerga Online scanare, nu ar lasa-ma sa ... ea a spus ceva despre care nu au permisiunea. Când m-am uitat în mea Add / Remove turnare Acestea sunt unele dintre lucrurile pe care le-am găsit un suspect puţin sau care le-am ştiut nimic despre. MSXML 4.0 SP2 My Search Bar muvee autoProducer 5.0 Smart Video Codec v1.6 SUPERAntiSpyware jurnal SUPERAntiSpyware Scan Log http://www.superantispyware.com AM Generated 01.05.2008 la 07:32 Application Version: 3-9-1008 Core Reguli Baza de date Versiune: 3374 Trace Reguli Baza de date Versiune: 1369 Scan type: Complete Scan Total Scan Ora: 01:23:02 Elemente de memorie scanate: 712 Memorie ameninţările detectate: 1 Elementele de registry scanate: 8254 Ameninţările Registrul detectate: 122 Elemente Fişier scanate: 60434 File ameninţările detectate: 12 Trojan.Net-MSV/VPS-Variant C: \ WINDOWS \ BLOPENVXDT.DLL C: \ WINDOWS \ BLOPENVXDT.DLL HKLM \ Software \ Classes \ CLSID \ (A8565FBC-8D53-4D4F-9BB0-CBC68A22B126) HKCR \ CLSID \ (A8565FBC-8D53-4D4F-9BB0-CBC68A22B126) HKCR \ CLSID \ (A8565FBC-8D53-4D4F-9BB0-CBC68A22B126) HKCR \ CLSID \ (A8565FBC-8D53-4D4F-9BB0-CBC68A22B126) \ InprocServer32 HKCR \ CLSID \ (A8565FBC-8D53-4D4F-9BB0-CBC68A22B126) \ InprocServer32 # ThreadingModel HKCR \ CLSID \ (A8565FBC-8D53-4D4F-9BB0-CBC68A22B126) \ ProgID HKCR \ CLSID \ (A8565FBC-8D53-4D4F-9BB0-CBC68A22B126) \ programabile HKCR \ CLSID \ (A8565FBC-8D53-4D4F-9BB0-CBC68A22B126) \ typelib HKCR \ CLSID \ (A8565FBC-8D53-4D4F-9BB0-CBC68A22B126) \ VersionIndependentProgID HKLM \ Software \ Microsoft \ Windows \ CurrentVersion \ lorer Exp \ Browser Helper Objects \ (A8565FBC-8D53-4D4F-9BB0-CBC68A22B126) Adware.MyWay HKLM \ Software \ Classes \ CLSID \ (014DA6C1-189F-421a-88CD-07CFE51CFF10) HKCR \ CLSID \ (014DA6C1-189F-421A-88CD-07CFE51CFF10) HKCR \ CLSID \ (014DA6C1-189F-421A-88CD-07CFE51CFF10) HKCR \ CLSID \ (014DA6C1-189F-421A-88CD-07CFE51CFF10) \ InprocServer32 HKCR \ CLSID \ (014DA6C1-189F-421A-88CD-07CFE51CFF10) \ InprocServer32 # ThreadingModel HKCR \ CLSID \ (014DA6C1-189F-421A-88CD-07CFE51CFF10) \ programabile HKCR \ CLSID \ (014DA6C1-189F-421A-88CD-07CFE51CFF10) \ typelib C: \ Program Files \ MYSEARCH \ bar \ 1.BIN \ S4BAR.DLL HKLM \ Software \ Classes \ CLSID \ (014DA6C9-189F-421a-88CD-07CFE51CFF10) HKCR \ CLSID \ (014DA6C9-189F-421A-88CD-07CFE51CFF10) HKCR \ CLSID \ (014DA6C9-189F-421A-88CD-07CFE51CFF10) HKCR \ CLSID \ (014DA6C9-189F-421A-88CD-07CFE51CFF10) \ InprocServer32 HKCR \ CLSID \ (014DA6C9-189F-421A-88CD-07CFE51CFF10) \ InprocServer32 # ThreadingModel HKCR \ CLSID \ (014DA6C9-189F-421A-88CD-07CFE51CFF10) \ programabile HKCR \ CLSID \ (014DA6C9-189F-421A-88CD-07CFE51CFF10) \ typelib HKLM \ Software \ Microsoft \ Windows \ CurrentVersion \ lorer Exp \ Browser Helper Objects \ (014DA6C1-189F-421a-88CD-07CFE51CFF10) HKLM \ Software \ Microsoft \ Internet Explorer \ Toolbar # (014DA6C9-189F-421a-88CD-07CFE51CFF10) HKCR \ typelib \ (014DA6C0-189F-421a-88CD-07CFE51CFF10) HKCR \ typelib \ (014DA6C0-189F-421a-88CD-07CFE51CFF10) \ 1.0 HKCR \ typelib \ (014DA6C0-189F-421a-88CD-07CFE51CFF10) \ 1.0 \ 0 HKCR \ typelib \ (014DA6C0-189F-421a-88CD-07CFE51CFF10) \ 1.0 \ 0 \ win32 HKCR \ typelib \ (014DA6C0-189F-421a-88CD-07CFE51CFF10) \ 1.0 \ FLAGS HKCR \ typelib \ (014DA6C0-189F-421a-88CD-07CFE51CFF10) \ 1.0 \ HELPDIR HKU \ S-1-5-21-3682377349-2593316749-328379415-1000 \ Software \ Microsoft \ Internet Explorer \ Toolbar \ WebBrowser # (014DA6C9-189F-421A-88CD-07CFE51CFF10) Unclassified.Unknown Origine HKLM \ Software \ Classes \ CLSID \ (E09962E7-A39E-4F60-8003-66D57BED27B7) HKCR \ CLSID \ (E09962E7-A39E-4F60-8003-66D57BED27B7) HKCR \ CLSID \ (E09962E7-A39E-4F60-8003-66D57BED27B7) HKCR \ CLSID \ (E09962E7-A39E-4F60-8003-66D57BED27B7) \ InprocServer32 HKCR \ CLSID \ (E09962E7-A39E-4F60-8003-66D57BED27B7) \ InprocServer32 # ThreadingModel HKCR \ CLSID \ (E09962E7-A39E-4F60-8003-66D57BED27B7) \ ProgID HKCR \ CLSID \ (E09962E7-A39E-4F60-8003-66D57BED27B7) \ programabile HKCR \ CLSID \ (E09962E7-A39E-4F60-8003-66D57BED27B7) \ typelib HKCR \ CLSID \ (E09962E7-A39E-4F60-8003-66D57BED27B7) \ VersionIndependentProgID C: \ WINDOWS \ System32 \ FASTRX.DLL HKLM \ Software \ Microsoft \ Windows \ CurrentVersion \ lorer Exp \ Browser Helper Objects \ (E09962E7-A39E-4F60-8003-66D57BED27B7) Adware.Tracking Cookie C: \ Users \ Yasmany \ AppData \ Roaming \ Microsoft \ Windows \ Cookies \ yasmany@ar.atwola [2]. Txt C: \ Users \ Yasmany \ AppData \ Roaming \ Microsoft \ Windows \ Cookies \ yasmany @ atwola [1]. Txt C: \ Users \ Yasmany \ AppData \ Roaming \ Microsoft \ Windows \ Cookies \ yasmany @ DoubleClick [1]. Txt C: \ Users \ Yasmany \ AppData \ Roaming \ Microsoft \ Windows \ Cookies \ yasmany @ adlegend [1]. Txt C: \ Users \ Yasmany \ AppData \ Roaming \ Microsoft \ Windows \ Cookies \ yasmany @ de publicitate [2]. Txt C: \ Users \ Yasmany \ AppData \ Roaming \ Microsoft \ Windows \ Cookies \ yasmany @ 2o7 [1]. Txt C: \ Users \ Yasmany \ AppData \ Roaming \ Microsoft \ Windows \ Cookies \ yasmany @ atdmt [2]. Txt C: \ Users \ Yasmany \ AppData \ Roaming \ Microsoft \ Windows \ Cookies \ yasmany @ mediaplex [1]. Txt Adware.180solutions/Seekmo HKCR \ Seekmo.DesktopFlash HKCR \ Seekmo.DesktopFlash \ CLSID HKCR \ Seekmo.DesktopFlash \ CurVer HKCR \ Seekmo.DesktopFlash.1 HKCR \ Seekmo.DesktopFlash.1 \ CLSID HKCR \ SeekmoAX.ClientDetector HKCR \ SeekmoAX.ClientDetector \ CLSID HKCR \ SeekmoAX.ClientDetector \ CurVer HKCR \ SeekmoAX.ClientDetector.1 HKCR \ SeekmoAX.ClientDetector.1 \ CLSID HKCR \ SeekmoAX.UserProfiles HKCR \ SeekmoAX.UserProfiles \ CLSID HKCR \ SeekmoAX.UserProfiles \ CurVer HKCR \ SeekmoAX.UserProfiles.1 HKCR \ SeekmoAX.UserProfiles.1 \ CLSID HKCR \ CLSID \ (1F158A1E-A687-4a11-9679-B3AC64B86A1C) HKCR \ CLSID \ (1F158A1E-A687-4a11-9679-B3AC64B86A1C) \ Control HKCR \ CLSID \ (1F158A1E-A687-4a11-9679-B3AC64B86A1C) \ InprocServer32 HKCR \ CLSID \ (1F158A1E-A687-4a11-9679-B3AC64B86A1C) \ InprocServer32 # ThreadingModel HKCR \ CLSID \ (1F158A1E-A687-4a11-9679-B3AC64B86A1C) \ MiscStatus HKCR \ CLSID \ (1F158A1E-A687-4a11-9679-B3AC64B86A1C) \ MiscStatus \ 1 HKCR \ CLSID \ (1F158A1E-A687-4a11-9679-B3AC64B86A1C) \ ProgID HKCR \ CLSID \ (1F158A1E-A687-4a11-9679-B3AC64B86A1C) \ programabile HKCR \ CLSID \ (1F158A1E-A687-4a11-9679-B3AC64B86A1C) \ ToolboxBitmap32 HKCR \ CLSID \ (1F158A1E-A687-4a11-9679-B3AC64B86A1C) \ typelib HKCR \ CLSID \ (1F158A1E-A687-4a11-9679-B3AC64B86A1C) \ versiunilor HKCR \ CLSID \ (1F158A1E-A687-4a11-9679-B3AC64B86A1C) \ VersionIndependentProgID HKCR \ CLSID \ (914A8F99-38E4-47ec-B875-2B0653516030) HKCR \ CLSID \ (914A8F99-38E4-47ec-B875-2B0653516030) # AppID HKCR \ CLSID \ (914A8F99-38E4-47ec-B875-2B0653516030) \ LocalServer32 HKCR \ CLSID \ (914A8F99-38E4-47ec-B875-2B0653516030) \ ProgID HKCR \ CLSID \ (914A8F99-38E4-47ec-B875-2B0653516030) \ programabile HKCR \ CLSID \ (914A8F99-38E4-47ec-B875-2B0653516030) \ typelib HKCR \ CLSID \ (914A8F99-38E4-47ec-B875-2B0653516030) \ VersionIndependentProgID HKCR \ CLSID \ (E313F5DC-CFE7-4568-84A4-C76653547571) HKCR \ CLSID \ (E313F5DC-CFE7-4568-84A4-C76653547571) \ InprocServer32 HKCR \ CLSID \ (E313F5DC-CFE7-4568-84A4-C76653547571) \ InprocServer32 # ThreadingModel HKCR \ CLSID \ (E313F5DC-CFE7-4568-84A4-C76653547571) \ ProgID HKCR \ CLSID \ (E313F5DC-CFE7-4568-84A4-C76653547571) \ programabile HKCR \ CLSID \ (E313F5DC-CFE7-4568-84A4-C76653547571) \ typelib HKCR \ CLSID \ (E313F5DC-CFE7-4568-84A4-C76653547571) \ VersionIndependentProgID HKCR \ typelib \ (995E885E-3FF5-4F66-A107-8BFB3A0F8F12) HKCR \ typelib \ (995E885E-3FF5-4F66-A107-8BFB3A0F8F12) \ 1.0 HKCR \ typelib \ (995E885E-3FF5-4F66-A107-8BFB3A0F8F12) \ 1.0 \ 0 HKCR \ typelib \ (995E885E-3FF5-4F66-A107-8BFB3A0F8F12) \ 1.0 \ 0 \ win32 HKCR \ typelib \ (995E885E-3FF5-4F66-A107-8BFB3A0F8F12) \ 1.0 \ FLAGS HKCR \ typelib \ (995E885E-3FF5-4F66-A107-8BFB3A0F8F12) \ 1.0 \ HELPDIR HKCR \ typelib \ (FBB40FDF-B715-4342-AB82-244ECC66E979) HKCR \ typelib \ (FBB40FDF-B715-4342-AB82-244ECC66E979) \ 1.0 HKCR \ typelib \ (FBB40FDF-B715-4342-AB82-244ECC66E979) \ 1.0 \ 0 HKCR \ typelib \ (FBB40FDF-B715-4342-AB82-244ECC66E979) \ 1.0 \ 0 \ win32 HKCR \ typelib \ (FBB40FDF-B715-4342-AB82-244ECC66E979) \ 1.0 \ FLAGS HKCR \ typelib \ (FBB40FDF-B715-4342-AB82-244ECC66E979) \ 1.0 \ HELPDIR HKCR \ Interface \ (BD5258AF-20AE-4BD3-B748-B2851ACA7335) HKCR \ Interface \ (BD5258AF-20AE-4BD3-B748-B2851ACA7335) \ ProxyStubClsid HKCR \ Interface \ (BD5258AF-20AE-4BD3-B748-B2851ACA7335) \ ProxyStubClsid32 HKCR \ Interface \ (BD5258AF-20AE-4BD3-B748-B2851ACA7335) \ typelib HKCR \ Interface \ (BD5258AF-20AE-4BD3-B748-B2851ACA7335) \ typelib # versiunilor HKCR \ AppId \ SeekmoSA_df.exe HKCR \ AppId \ SeekmoSA_df.exe # AppID HKCR \ AppId \ (4A40E8FC-C7E4-4F57-9FA4-85DD77402897) HKU \ S-1-5-21-3682377349-2593316749-328379415-1000 \ Software \ seekmosa HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ nstall Uni \ SeekmoSA HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ nstall Uni \ SeekmoSA # DisplayName HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ nstall Uni \ SeekmoSA # DisplayIcon HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ nstall Uni \ SeekmoSA # UninstallString HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ nstall Uni \ SeekmoSA # DisplayVersion HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ nstall Uni \ SeekmoSA HelpLink # HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ nstall Uni \ SeekmoSA Distribuitor # HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ nstall Uni \ SeekmoSA # URLInfoAbout HKLM \ Software \ Microsoft \ Windows \ CurrentVersion \ Run # SeekmoOE [C: \ Program Files \ Seekmo \ bin \ 10.0.341.0 \ OEAddOn.exe] C: \ Users \ Yasmany \ AppData \ Roaming \ Seekmo Trojan.DNSChanger-Codec HKCR \ VAC.Video HKCR \ VAC.Video \ CLSID Trojan.Net-MSV/VPS HKCR \ MSVPS.MSVPSApp HKCR \ MSVPS.MSVPSApp \ CLSID HKCR \ MSVPS.MSVPSApp \ CurVer Trojan.Net-MU/Gen HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ nstall Uni \ WebVideo HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ nstall Uni \ WebVideo # DisplayName HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ nstall Uni \ WebVideo # UninstallString HijackThis Log Logfile de Trend Micro HijackThis v2.0.2 Scan saved at 8:13:58, pe 12.23.2007 Platforma: Windows Vista (WINNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16575) Boot mode: Normal Rularea procese: C: \ Windows \ system32 \ taskeng.exe C: \ Windows \ system32 \ Dwm.exe C: \ Windows \ Explorer.exe C: \ Program Files \ Synaptics \ SynTP \ SynTPEnh.exe C: \ Program Files \ HP \ QuickPlay \ QPService.exe C: \ Program Files \ HP \ HP Software Update \ hpwuSchd2.exe C: \ Program Files \ Hewlett-Packard \ HP Quick Launch Buttons \ QLBCTRL.exe C: \ Program Files \ Hewlett-Packard \ HP Wireless Assistant \ WiFiMsg.exe C: \ Program Files \ Hewlett-Packard \ HP Wireless Assistant \ HPWAMain.exe C: \ Program Files \ Java \ jre1.6.0 \ bin \ jusched.exe C: \ Program Files \ Common Files \ Real \ Update_OB \ realsched.exe C: \ Program Files \ Common Files \ Symantec Shared \ ccApp.exe C: \ Program Files \ Comcast \ Desktop doctor \ bin \ sprtcmd.exe C: \ Program Files \ Windows Sidebar \ sidebar.exe C: \ Program Files \ Hewlett-Packard \ HP Advisor \ HPAdvisor.exe C: \ Windows \ system32 \ rundll32.exe C: \ WINDOWS \ ehome \ ehtray.exe C: \ Windows \ ehome \ ehmsas.exe C: \ Users \ Yasmany \ Desktop \ Veoh \ VeohClient.exe C: \ Program Files \ Google \ GoogleToolbarNotifier \ 1.2.1128.5462 \ G oogleToolbarNotifier.exe C: \ Program Files \ Common Files \ Adobe \ Updater5 \ AdobeUpdater.exe C: \ Program Files \ HP Connections \ 6811507 \ Program \ HP Connections.exe C: \ Windows \ system32 \ wbem \ unsecapp.exe C: \ PROGRA ~ 1 \ HEWLET ~ 1 \ Shared \ HPQTOA ~ 1.EXE C: \ Program Files \ Hewlett-Packard \ HP Advisor \ SSDK04.exe C: \ Program Files \ Internet Explorer \ ieuser.exe C: \ Program Files \ Internet Explorer \ iexplore.exe C: \ Program Files \ Common Files \ Microsoft Shared \ Windows Live \ WLLoginProxy.exe C: \ Windows \ system32 \ SearchFilterHost.exe C: \ Program Files \ Trend Micro \ HijackThis \ HijackThis.exe C: \ Windows \ system32 \ Macromed \ Flash \ FlashUtil9b.exe R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://www.comcast.net/ R1 - HKLM \ SOFTWARE \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...lion&pf=laptop R1 - HKLM \ SOFTWARE \ Microsoft \ Internet Explorer \ Main, Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM \ SOFTWARE \ Microsoft \ Internet Explorer \ Main, Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM \ SOFTWARE \ Microsoft \ Internet Explorer \ Main, Start Page = http://www.comcast.net/ R0 - HKLM \ SOFTWARE \ Microsoft \ Internet Explorer \ Search, SearchAssistant = R0 - HKLM \ SOFTWARE \ Microsoft \ Internet Explorer \ Search, CustomizeSearch = R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Window title = Windows Internet Explorer furnizate de către Comcast R1 - HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Int ernet Setări, ProxyServer =: 0 R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Toolbar, LinksFolderName = R3 - URLSearchHook: AOLTBSearch Class - (EA756889-43DB-2338-8F07-D1CA6FB9C90D) - C: \ Program Files \ AOL \ AIM Toolbar 5.0 \ aoltb.dll O1 - Hosts::: 1 localhost O2 - BHO: BHO mele Căutare - (014DA6C1-189F-421a-88CD-07CFE51CFF10) - C: \ Program Files \ MySearch \ bar \ 1.bin \ S4BAR.DLL O2 - BHO: Adobe PDF Reader Link Helper - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Program Files \ Adobe \ Acrobat 7.0 \ ActiveX \ AcroIEHelper.dll O2 - BHO: RealPlayer Descărcaţi Plug-in-ului şi a înregistra pentru Internet Explorer - (3049C3E9-B461-4BC5-8870-4C09146192CA) - C: \ Program Files \ Real \ RealPlayer \ rpbrowserrecordplugin.dll O2 - BHO: SSVHelper Class - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C: \ Program Files \ Java \ jre1.6.0 \ bin \ ssv.dll O2 - BHO: AOL Toolbar Launcher - (7C554162-8CB7-45A4-B8F4-8EA1C75885F9) - C: \ Program Files \ AOL \ AIM Toolbar 5.0 \ aoltb.dll O2 - BHO: (no name) - (7E853D72-626A-48EC-A868-BA8D5E23E045) - (no file) O2 - BHO: Windows Live Sign-in-Helper - (9030D464-4C02-4ABF-8ECC-5164760863C6) - C: \ Program Files \ Common Files \ Microsoft Shared \ Windows Live \ WindowsLiveLogin.dll O2 - BHO: BDEX System - (A8565FBC-8D53-4D4F-9BB0-CBC68A22B126) - C: \ Windows \ blopenvxdt.dll O2 - BHO: Google Toolbar Helper - (AA58ED58-01DD-4d91-8333-CF10577473F7) - C: \ Program Files \ Google \ googletoolbar1.dll O2 - BHO: FastRX - (E09962E7-A39E-4F60-8003-66D57BED27B7) - C: \ Windows \ system32 \ fastRX.dll (fişier lipsă) O3 - Toolbar: Bar mele Căutare - (014DA6C9-189F-421a-88CD-07CFE51CFF10) - C: \ Program Files \ MySearch \ bar \ 1.bin \ S4BAR.DLL O3 - Toolbar: Veoh Browser Plug-in - (D0943516-5076-4020-A3B5-AEFAF26AB263) - C: \ Users \ Yasmany \ Desktop \ Veoh \ Plugins \ reg \ VeohTool bar.dll O3 - Toolbar: & Google - (2318C2B1-4965-11d4-9B18-009027A5CD4F) - C: \ Program Files \ Google \ googletoolbar1.dll O3 - Toolbar: AIM Toolbar - (DE9C389F-3316-41A7-809B-AA305ED9D922) - C: \ Program Files \ AOL \ AIM Toolbar 5.0 \ aoltb.dll O3 - Toolbar: retnsrp - (CC304A4D-FC79-4CD3-9A67-46E3AF59319D) - C: \ Windows \ retnsrp.dll O4 - HKLM \ .. \ Run: [Windows Defender]% ProgramFiles% \ Windows Defender \ MSASCui.exe-a ascunde O4 - HKLM \ .. \ Run: [SynTPEnh] C: \ Program Files \ Synaptics \ SynTP \ SynTPEnh.exe O4 - HKLM \ .. \ Run: [QPService] "C: \ Program Files \ HP \ QuickPlay \ QPService.exe" O4 - HKLM \ .. \ Run: [HP Software Update] C: \ Program Files \ Hp \ HP Software Update \ HPWuSchd2.exe O4 - HKLM \ .. \ Run: [QlbCtrl]% ProgramFiles% \ Hewlett-Packard \ HP Quick Launch Buttons \ QlbCtrl.exe / Start O4 - HKLM \ .. \ Run: [HP stării de sănătate Scheduler] C: \ Program Files \ Hewlett-Packard \ HP stării de sănătate \ HPHC_Scheduler.exe O4 - HKLM \ .. \ Run: [WAWifiMessage]% ProgramFiles% \ Hewlett-Packard \ HP Wireless Assistant \ WiFiMsg.exe O4 - HKLM \ .. \ Run: [hpWirelessAssistant]% ProgramFiles% \ Hewlett-Packard \ HP Wireless Assistant \ HPWAMain.exe O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] "C: \ Program Files \ Java \ jre1.6.0 \ bin \ jusched.exe" O4 - HKLM \ .. \ Run: [kpx] C: \ Windows \ system32 \ C rundll32.exe: \ Windows \ system32 \ DllInitApp fastRX.dll O4 - HKLM \ .. \ Run: [NvSvc] RUNDLL32.EXE C: \ Windows \ system32 \ nvsvc.dll, nvsvcStart O4 - HKLM \ .. \ Run: [NvCplDaemon] RUNDLL32.EXE C: \ Windows \ system32 \ NvCpl.dll, NvStartup O4 - HKLM \ .. \ Run: [NvMediaCenter] RUNDLL32.EXE C: \ Windows \ system32 \ NvMcTray.dll, NvTaskbarInit O4 - HKLM \ .. \ Run: [TkBellExe] "C: \ Program Files \ Common Files \ Real \ Update_OB \ realsched.exe"-osboot O4 - HKLM \ .. \ Run: [SeekmoOE] C: \ Program Files \ Seekmo \ bin \ 10.0.341.0 \ OEAddOn.exe O4 - HKLM \ .. \ Run: [SeekmoSA] "C: \ Program Files \ Seekmo \ bin \ 10.0.341.0 \ SeekmoSA.exe" O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ QuickTime \ QTTask.exe"-atboottime O4 - HKLM \ .. \ Run: [ccApp] "C: \ Program Files \ Common Files \ Symantec Shared \ ccApp.exe" O4 - HKLM \ .. \ Run: [Symantec PIF AlertEng] "C: \ Program Files \ Common Files \ Symantec Shared \ PIF \ (B8E1DD85-8582-4c61-B58F-2F227FCA9A08) \ PIFSvc.exe" / a / m " C: \ Program Files \ Common Files \ Symantec Shared \ PIF \ (B8E1DD85-8582-4c61-B58F-2F227FCA9A08) \ AlertEng.dll " O4 - HKLM \ .. \ Run: [ddoctorv2] "C: \ Program Files \ Comcast \ Desktop doctor \ bin \ sprtcmd.exe" / P ddoctorv2 O4 - HKLM \ .. \ RunOnce: [Launcher]% WINDIR% \ SMINST \ launcher.exe O4 - HKCU \ .. \ Run: [Sidebar] C: \ Program Files \ Windows Sidebar \ sidebar.exe / autorun O4 - HKCU \ .. \ Run: [HPAdvisor] C: \ Program Files \ Hewlett-Packard \ HP Advisor \ HPAdvisor.exe O4 - HKCU \ .. \ Run: [Aim6] "C: \ Program Files \ AIM6 \ aim6.exe" / localizare d = en-US ee: / / AOL / imApp O4 - HKCU \ .. \ Run: [ehTray.exe] C: \ Windows \ ehome \ ehTray.exe O4 - HKCU \ .. \ Run: [Veoh] "C: \ Users \ Yasmany \ Desktop \ Veoh \ VeohClient.exe" / VeohHide O4 - HKCU \ .. \ Run: [MsnMsgr] "C: \ Program Files \ MSN Messenger \ MsnMsgr.Exe" / fundal O4 - HKCU \ .. \ Run: [swg] C: \ Program Files \ Google \ GoogleToolbarNotifier \ 1.2.1128.5462 \ G oogleToolbarNotifier.exe O4 - HKCU \ .. \ Run: [AdobeUpdater] C: \ Program Files \ Common Files \ Adobe \ Updater5 \ AdobeUpdater.exe O4 - HKCU \ .. \ Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll, ShowWelcomeCenter O4 - HKUS \ S-1-5-19 \ .. \ Run: [Sidebar]% ProgramFiles% \ Windows Sidebar \ Sidebar.exe / detectMem (User 'LOCAL SERVICE') O4 - HKUS \ S-1-5-19 \ .. \ Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll, ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS \ S-1-5-20 \ .. \ Run: [Sidebar]% ProgramFiles% \ Windows Sidebar \ Sidebar.exe / detectMem (User 'NETWORK SERVICE') O4 - Startup: LimeWire Pe Startup.lnk = C: \ Program Files \ LimeWire \ LimeWire.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C: \ Program Files \ Adobe \ Acrobat 7.0 \ Reader \ reader_sl.exe O4 - Global Startup: Adobe Reader Synchronizer.lnk = C: \ Program Files \ Adobe \ Reader 8.0 \ Reader \ AdobeCollabSync.exe O4 - Global Startup: HP Connections.lnk = C: \ Program Files \ HP Connections \ 6811507 \ Program \ HP Connections.exe O8 - Extra context menu item: & AOL Toolbar Search - C: \ Program Files \ AOL \ scopul bara de instrumente 5.0 \ resurse \ en-US \ local \ search.html O8 - Extra context menu item: E & xportaţi la Microsoft Excel - res: / / C: \ PROGRA ~ 1 \ milionimi ~ 3 \ Office12 \ EXCEL.EXE/3000 O9 - Extra button: (no name) - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0 \ bin \ ssv.dll O9 - Extra 'Tools' MENUITEM: Sun Java Console - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0 \ bin \ ssv.dll O9 - Extra button: Send to OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C: \ PROGRA ~ 1 \ milionimi ~ 3 \ Office12 \ ONBttnIE.dll O9 - Extra 'Tools' MENUITEM: S & la sfârşitul OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C: \ PROGRA ~ 1 \ milionimi ~ 3 \ Office12 \ ONBttnIE.dll O9 - Extra button: AIM Toolbar - (3369AF0D-62E9-4bda-8103-B4C75499B578) - C: \ Program Files \ AOL \ AIM Toolbar 5.0 \ aoltb.dll O9 - Extra button: Cercetare - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C: \ PROGRA ~ 1 \ milionimi ~ 3 \ Office12 \ REFIEBAR.DLL O13 - Gopher Prefix: O16 - DPF: (48DD0448-9209-4F81-9F6D-D83562940134) (MySpace Uploader Control) -- http://lads.myspace.com/upload/MySpaceUploader1005.cab O16 - DPF: (5D6F45B3-9043-443D-A792-115447494D24) (UnoCtrl Class) -- http://messenger.zone.msn.com/EN-US/.../GAME_UNO1.cab O16 - DPF: (67DABFBF-D0AB-41FA-9C46-CC0F21721616) (DivXBrowserPlugin Object) -- http://download.divx.com/player/DivXBrowserPlugin.cab O16 - DPF: (B8BE5E93-A60C-4D26-A2DC-220313175592) (MSN Games - Installer) -- http://messenger.zone.msn.com/binary...o.cab56649.cab O16 - DPF: (BD393C14-72AD-4790-A095-76522973D6B8) (CBreakshotControl Class) -- http://messenger.zone.msn.com/binary...t.cab57213.cab O16 - DPF: (C3F79A2B-B9B4-4A66-B012-3EE46475B072) (MessengerStatsClient Class) -- http://messenger.zone.msn.com/binary...t.cab56907.cab O16 - DPF: (DA758BB1-5F89-4465-975F-8D7179A4BCF3) (WheelofFortune Object) -- http://messenger.zone.msn.com/binary/WoF.cab57176.cab O21 - SSODL: leorop - (38CA8AE4-A78E-4111-8D0E-BDDF145A5040) - C: \ Windows \ leorop.dll O21 - SSODL: nopzet - (9543D4D7-3E5B-4B70-BB93-83AC9865627C) - C: \ Windows \ nopzet.dll O23 - Service: AddFiltr - Hewlett-Packard Development Company, LP - C: \ Program Files \ Hewlett-Packard \ HP Quick Launch Buttons \ AddFiltr.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C: \ Program Files \ Symantec \ LiveUpdate \ ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccSvcHst.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccSvcHst.exe O23 - Service: CyberLink Background Captură Service (CBCS) (CLCapSvc) - Unknown owner - C: \ Program Files \ HP \ QuickPlay \ Kernel \ TV \ CLCapSvc.exe O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C: \ Program Files \ HP \ QuickPlay \ Kernel \ TV \ CLSched.exe O23 - Service: Symantec LIC NetConnect serviciu (CLTNetCnService) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccSvcHst.exe O23 - Service: Google Updater Service (gusvc) - Google - C: \ Program Files \ Google \ Common \ Google Updater \ GoogleUpdaterService.exe O23 - Service: HP stării de sănătate Service - Hewlett-Packard - C: \ Program Files \ Hewlett-Packard \ HP stării de sănătate \ hphc_service.exe O23 - Service: hpqwmiex - Hewlett-Packard Development Company, LP - C: \ Program Files \ Hewlett-Packard \ Shared \ hpqwmiex.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C: \ Program Files \ Roxio \ Roxio MyDVD Basic v9 \ InstallShield \ Driver \ 1050 \ Intel 32 \ IDriverT.exe O23 - Service: Symantec Password Validation ESTE (ISPwdSvc) - Symantec Corporation - C: \ Program Files \ Norton AntiVirus \ isPwdSvc.exe O23 - Service: LightScribeService Direct Disc Etichetarea Service (LightScribeService) - Hewlett-Packard Company - C: \ Program Files \ Common Files \ LightScribe \ LSSrvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C: \ PROGRA ~ 1 \ Symantec \ LIVEUP ~ 1 \ LUCOMS ~ 1.EXE O23 - Service: LiveUpdate Notice Service ex (LiveUpdate Notice Ex) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccSvcHst.exe O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ PIF \ (B8E1DD85-8582-4c61-B58F-2F227FCA9A08) \ PIFSvc.exe O23 - Service: RoxMediaDB9 - Sonic Solutions - C: \ Program Files \ Common Files \ Roxio Shared \ 9.0 \ SharedCOM \ RoxMediaDB9.exe O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc - C: \ Program Files \ Comcast \ Desktop doctor \ bin \ sprtsvc.exe O23 - Service: stllssvr - MicroVision Dezvoltare, Inc - C: \ Program Files \ Common Files \ SureThing Shared \ stllssvr.exe O23 - Service: Symantec Core LC - Unknown owner - C: \ Program Files \ Common Files \ Symantec Shared \ CCPD-LC \ symlcsvc.exe O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ AppCore \ AppSvc32.exe O23 - Service: punct de vedere Manager Service - punct de vedere Corporation - C: \ Program Files \ punct de vedere \ Common \ ViewpointService.exe O23 - Service: XAudioService - Conexant Systems, Inc - C: \ Windows \ system32 \ drivers \ xaudio.exe -- Sfârşit de fişier - 13628 bytes |
|
#7
| |||
| |||
| S-ar putea să doriţi să copiaţi şi să inseraţi aceste instrucţiuni într-un fişier notepad. Apoi, puteţi să aibă fişier deschis în modul de siguranţă, astfel încât să puteţi să urmaţi instrucţiunile de mai uşor. Porni în modul de siguranţă, sub numele dvs. de utilizator normal (nu cont de administrator). Vezi cum AICI. În Windows Explorer, la rândul său, "Arata toate fişierele şi folderele, inclusiv ascunse şi de sistem". Vezi cum AICI. Du-te pentru a adăuga şi elimina programele de pe panoul de control şi a dezinstala nimic de a face cu (dacă există). MySearch bar Seekmo Punct de vedere Închideţi Control Panel. Faceţi clic pe Start / a alerga şi tip services.msc în caseta de a alerga şi apăsaţi tasta Enter. Atunci când fereastra apare, a maximiza-o. Faceţi dublu clic pe următoarele servicii (dacă există) Şi selectaţi oprire, dacă acestea sunt difuzate. Setaţi tipul de pornire la cu handicap. Faceţi clic pe Apply / OK pentru fiecare serviciu va fi de acord. Punct de vedere Manager Service Închideţi fereastra de servicii. Deschide-ţi Task Manager, prin deţinerea pe Ctrl şi Alt cheile şi apăsând tasta Delete. Faceţi clic pe tab-ul şi a proceselor de sfârşitul procesului de (dacă există). ViewpointService.exe LAUNCHER.EXE SeekmoSA.exe OEAddOn.exe Close Task Manager. Run HJT fără alte programe deschise (cu excepţia notepad). Faceţi clic pe butonul de scanare. Au HJT stabili următoarele, prin plasarea unui tic în caseta de lângă mic (dacă există). O2 - BHO: BHO mele Căutare - (014DA6C1-189F-421a-88CD-07CFE51CFF10) - C: \ Program Files \ MySearch \ bar \ 1.bin \ S4BAR.DLL O2 - BHO: (no name) - (7E853D72-626A-48EC-A868-BA8D5E23E045) - (no file) O2 - BHO: BDEX System - (A8565FBC-8D53-4D4F-9BB0-CBC68A22B126) - C: \ Windows \ blopenvxdt.dll O2 - BHO: FastRX - (E09962E7-A39E-4F60-8003-66D57BED27B7) - C: \ Windows \ system32 \ fastRX.dll (fişier lipsă) O3 - Toolbar: Bar mele Căutare - (014DA6C9-189F-421a-88CD-07CFE51CFF10) - C: \ Program Files \ MySearch \ bar \ 1.bin \ S4BAR.DLL O3 - Toolbar: retnsrp - (CC304A4D-FC79-4CD3-9A67-46E3AF59319D) - C: \ Windows \ retnsrp.dll O4 - HKLM \ .. \ Run: [kpx] C: \ Windows \ system32 \ C rundll32.exe: \ Windows \ system32 \ DllInitApp fastRX.dll O4 - HKLM \ .. \ Run: [SeekmoOE] C: \ Program Files \ Seekmo \ bin \ 10.0.341.0 \ OEAddOn.exe O4 - HKLM \ .. \ Run: [SeekmoSA] "C: \ Program Files \ Seekmo \ bin \ 10.0.341.0 \ SeekmoSA.exe" O4 - HKLM \ .. \ RunOnce: [Launcher]% WINDIR% \ SMINST \ launcher.exe O21 - SSODL: leorop - (38CA8AE4-A78E-4111-8D0E-BDDF145A5040) - C: \ Windows \ leorop.dll O21 - SSODL: nopzet - (9543D4D7-3E5B-4B70-BB93-83AC9865627C) - C: \ Windows \ nopzet.dll O23 - Service: punct de vedere Manager Service - punct de vedere Corporation - C: \ Program Files \ punct de vedere \ Common \ ViewpointService.exe Faceţi clic pe butonul stabili verificate. Inchide HJT. Găsiţi şi ştergeţi următoarele bold fişierelor şi / sau dosarelor (dacă există). C: \ Program Files \Punct de vedere<Ştergere întregul dosar. C: \ Windows \nopzet.dll C: \ Windows \leorop.dll % WINDIR% \ SMINST \LAUNCHER.EXE C: \ Program Files \Seekmo<Ştergere întregul dosar. C: \ Windows \ system32 \fastRX.dll C: \ Windows \retnsrp.dll C: \ Program Files \MySearch<Ştergere întregul dosar. C: \ Windows \blopenvxdt.dll Reporniţi în modul normal şi rehide dvs. protejat OS fişiere. Descărca combofix.exe pe desktop. Combofix.exe dublu click & Urmaţi solicitările. Va deschide o fereastră cu un avertisment. De tip "1" (şi Enter) pentru a începe fix. Când scanarea sa incheiat se va deschide o fereastra de text. Vă rugăm să ataşaţi că vă conectaţi din nou aici, împreună cu un jurnal de HJT proaspăt. Atenţie - nu atingeţi-vă mouse / tastatura de scanare până când sa terminat. De scanare va dezactiva temporar pe spaţiul de lucru, şi, dacă este întreruptă poate părăsi spaţiul de lucru cu handicap. Dacă se întâmplă acest lucru, vă rugăm să reporniţi sistemul pentru a restaura spaţiul de lucru. Combofix va salva automat fişierul jurnal la C: \ combofix.txt Post de Combofix jurnal, precum şi de un nou HJT log. Regards Howard. |
|
#8
| |||
| |||
| Omul Am calendarul rău. I chiar a întemeia cum la spre a alerga on-line a scanda. I'm running chiar acum în timp ce vorbim. Mai vrei să fac eu aşa cum aţi spus. |
|
#9
| |||
| |||
| Uita de on-line a scanda pentru acum, doar să urmaţi instrucţiunile v-am dat. Regards Howard. |
|
#10
| |||
| |||
| Cînd I try la spre A alerga ComboFix I a lua fereastra albastru, dar apoi se spune: pregătirea pentru a rula, apoi din memorie sau de încălcare de acces şi apoi atunci I a lua un alt pop sus a spune "Freeware punerea în aplicare a REG.EXE a încetat să funcţioneze şi mă obligă să închidă de stabilire a programului. Vrei să posta log HJT? Îmi cer scuze pentru toate necazurile. Stai un pic, nu stiu cum, dar acum e de lucru am de gând să-l rulaţi. |
![]() |
|
| Marcaje |
Similar Threads | ||||
| Fir | Thread Starter | Forum | Răspunsurile | Ultimul mesaj |
| Ajutor, nu se poate accesa meu Task Manager | Raph78 | Sisteme de operare Windows | 5 | 23 iulie 2009 02:45 |
| Task Manager nu închide programe | tbarber | Sisteme de operare Windows | 0 | 17 iunie 2009 17:52 |
| Task Manager Procese .. | IsoldeAislinn | Sisteme de operare Windows | 9 | 25 Sep 2008 19:26 |
| Verificaţi-mi Task Manager pentru mine plz:) | pete21 | General Chat Software | 5 | 9 iulie 2008 06:05 |
| AnVir Task Manager | evilfantasy | General Chat Software | 0 | 28 martie 2008 14:40 |
| Thread Tools | |
| |