HikachThis - yonutz31
Last Updated: Aug 13 2013 19:51, Started by
yonutz31
, Aug 10 2013 18:23
·
0
![](https://forum.softpedia.com//public/style_images/classic/icon_users.png)
#37
Posted 13 August 2013 - 17:21
![](https://forum.softpedia.com//public/style_images/classic/post_offline.png)
RogueKiller V8.6.5 _x64_ [Aug 5 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com Feedback : http://www.adlice.com/forum/ Website : http://www.adlice.co...es/roguekiller/ Blog : http://tigzyrk.blogspot.com/ Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version Started in : Normal mode User : Ionut [Admin rights] Mode : Remove -- Date : 08/13/2013 18:21:27 | ARK || FAK || MBR | ¤¤¤ Bad processes : 0 ¤¤¤ ¤¤¤ Registry Entries : 6 ¤¤¤ [HJ POL] HKCU\[...]\System : DisableTaskMgr (0) -> DELETED [HJ POL] HKCU\[...]\System : DisableRegistryTools (0) -> DELETED [HJ POL] HKLM\[...]\System : EnableLUA (0) -> REPLACED (1) [HJ POL] HKLM\[...]\Wow6432Node\[...]\System : EnableLUA (0) -> REPLACED (1) [HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NOT SELECTED [HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NOT SELECTED ¤¤¤ Scheduled tasks : 0 ¤¤¤ ¤¤¤ Startup Entries : 0 ¤¤¤ ¤¤¤ Web browsers : 0 ¤¤¤ ¤¤¤ Particular Files / Folders: ¤¤¤ ¤¤¤ Driver : [NOT LOADED 0x0] ¤¤¤ ¤¤¤ External Hives: ¤¤¤ ¤¤¤ Infection : ¤¤¤ ¤¤¤ HOSTS File: ¤¤¤ --> %SystemRoot%\System32\drivers\etc\hosts ÿþ1 ¤¤¤ MBR Check: ¤¤¤ +++++ PhysicalDrive0: Hitachi HTS547550A9E384 +++++ --- User --- [MBR] c72424b0495a34313ef942cabef5f82b [BSP] 2ee18edf56eb573bfe8fc4993312b762 : Windows 7/8 MBR Code Partition table: 0 - [XXXXXX] FAT32-LBA (0x1c) [HIDDEN!] Offset (sectors): 2048 | Size: 25600 Mo 1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 52430848 | Size: 200042 Mo 2 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 462116864 | Size: 251296 Mo User = LL1 ... OK! User = LL2 ... OK! Finished : << RKreport[0]_D_08132013_182127.txt >> RKreport[0]_S_08132013_181055.txt;RKreport[0]_S_08132013_182025.txt |
#38
Posted 13 August 2013 - 17:23
![](https://forum.softpedia.com//public/style_images/classic/post_offline.png)
Descarca: ComboFix si salveaza-l pe Desktop.
Apoi asigura-te ca ai inchis toate programele care ruleaza (Yahoo Messenger, Mozila Firefox, etc) si ruleaza ComboFix. Te va intreba daca sa inceapa sa curete sistemul. Confirma cu Yes de fiecare data. Nu-l opri in timp ce scaneaza si dezinfecteaza sistemul. E posibil ca in timpul rularii lui desktop-ul sa dispara, dar nu te ingrijora. La sfarsit va afisa rezultatele scanarii. Salveaza acel fisier si posteaza continutul AICI. |
#39
Posted 13 August 2013 - 17:43
![](https://forum.softpedia.com//public/style_images/classic/post_offline.png)
Quote ComboFix 13-08-12.01 - Ionut 13.08.2013 18:28:20.1.8 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1250.40.1048.18.4007.2366 [GMT 3:00] Running from: c:\users\Ionut\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . C:\hosts c:\programdata\Roaming c:\windows\msvcr71.dll c:\windows\SysWow64\Uninstall-TvPlugin-5.8 c:\windows\Uninstall-TvPlugin-5.9 . . ((((((((((((((((((((((((( Files Created from 2013-07-13 to 2013-08-13 ))))))))))))))))))))))))))))))) . . 2013-08-13 15:00 . 2013-08-13 15:00 -------- d-----w- C:\_OTL 2013-08-13 07:53 . 2013-07-02 08:34 9460976 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{86F46DB7-92D3-4F75-88BB-368D7B273B4E}\mpengine.dll 2013-08-11 11:13 . 2013-08-11 11:18 378944 ----a-w- c:\windows\system32\drivers\aswSP.sys 2013-08-11 11:13 . 2013-05-09 08:59 33400 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2013-08-11 11:13 . 2013-05-09 08:59 72016 ----a-w- c:\windows\system32\drivers\aswRdr2.sys 2013-08-11 11:13 . 2013-08-11 11:18 189936 ----a-w- c:\windows\system32\drivers\aswVmm.sys 2013-08-11 11:13 . 2013-08-11 11:18 1030952 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2013-08-11 11:13 . 2013-05-09 08:59 64288 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2013-08-11 11:13 . 2013-05-09 08:59 65336 ----a-w- c:\windows\system32\drivers\aswRvrt.sys 2013-08-11 11:13 . 2013-05-09 08:59 80816 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2013-08-11 11:13 . 2013-05-09 08:58 287840 ----a-w- c:\windows\system32\aswBoot.exe 2013-08-11 11:13 . 2013-05-09 08:58 41664 ----a-w- c:\windows\avastSS.scr 2013-08-11 11:12 . 2013-08-11 11:12 -------- d-----w- c:\program files\AVAST Software 2013-08-11 11:12 . 2013-08-11 11:12 -------- d-----w- c:\programdata\AVAST Software 2013-08-11 10:18 . 2013-08-11 10:18 -------- d-----w- c:\users\Default\AppData\Local\Power2Go 2013-08-10 22:07 . 2013-08-10 22:07 -------- d-----w- c:\program files\CCleaner 2013-08-10 21:16 . 2013-08-10 21:16 -------- d-----w- c:\windows\ERUNT 2013-08-10 16:44 . 2013-08-10 16:44 -------- d-----w- c:\users\Ionut\AppData\Roaming\Malwarebytes 2013-08-10 16:44 . 2013-08-10 16:44 -------- d-----w- c:\programdata\Malwarebytes 2013-08-10 16:44 . 2013-08-10 16:44 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware 2013-08-10 16:44 . 2013-04-04 11:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys 2013-08-08 17:03 . 2013-08-08 17:03 42297 ----a-w- c:\windows\system32\uninstall.exe 2013-08-08 17:03 . 2013-08-08 17:03 -------- d-----w- c:\windows\SysWow64\custom matrices 2013-08-08 17:03 . 2011-12-17 11:59 1695 ----a-w- c:\windows\SysWow64\openIE.js 2013-08-08 17:03 . 2012-04-08 21:44 250880 ----a-w- c:\windows\SysWow64\ff_kernelDeint.dll 2013-08-08 17:03 . 2013-08-08 17:03 1175371 ----a-w- c:\windows\SysWow64\unins000.exe 2013-08-08 17:03 . 2013-06-19 11:58 19456 ----a-w- c:\windows\system32\roboot64.exe 2013-08-08 17:03 . 2013-08-08 17:03 -------- d-----w- c:\users\Ionut\AppData\Local\Programs 2013-08-08 08:16 . 2007-01-30 03:58 145920 ----a-w- c:\windows\system32\Spool\prtprocs\x64\lxcepp6c.dll 2013-08-08 08:16 . 2013-08-08 08:17 -------- d-----w- c:\program files\Lexmark 4300 Series 2013-08-08 08:02 . 2013-08-08 08:02 -------- d-----w- c:\program files (x86)\Lexmark Fax Solutions 2013-08-08 08:02 . 2013-08-08 08:02 -------- d-----w- C:\Lexmark 2013-07-29 15:55 . 2013-07-29 15:58 -------- d-----w- c:\windows\system32\MRT 2013-07-17 14:34 . 2013-07-17 14:34 -------- d-----w- c:\program files (x86)\BatchPhoto 2013-07-17 10:47 . 2013-07-17 10:47 -------- d-----w- c:\users\Ionut\AppData\Local\bdch 2013-07-15 17:33 . 2013-07-15 17:33 -------- d-----w- c:\programdata\bdch 2013-07-15 10:23 . 2013-07-15 10:23 -------- d-----w- c:\programdata\BDLogging 2013-07-15 10:23 . 2009-07-14 22:21 1721576 ----a-w- c:\windows\system32\WdfCoInstaller01009.dll 2013-07-15 10:23 . 2007-04-11 08:11 511328 ----a-w- c:\windows\capicom.dll 2013-07-15 10:14 . 2013-08-11 20:32 -------- d-----w- c:\program files\Bitdefender 2013-07-15 10:14 . 2013-08-11 11:08 -------- d-----w- c:\program files\Common Files\Bitdefender 2013-07-15 10:14 . 2013-07-15 10:14 -------- d-----w- c:\program files (x86)\Common Files\Bitdefender . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-08-13 13:23 . 2011-09-07 21:25 45056 ----a-w- c:\windows\system32\acovcnt.exe 2013-06-23 21:57 . 2013-07-12 06:42 78277128 ----a-w- c:\windows\system32\MRT.exe 2013-06-18 11:23 . 2013-06-18 11:23 97280 ----a-w- c:\windows\system32\mshtmled.dll 2013-06-18 11:23 . 2013-06-18 11:23 905728 ----a-w- c:\windows\system32\mshtmlmedia.dll 2013-06-18 11:23 . 2013-06-18 11:23 81408 ----a-w- c:\windows\system32\icardie.dll 2013-06-18 11:23 . 2013-06-18 11:23 762368 ----a-w- c:\windows\system32\ieapfltr.dll 2013-06-18 11:23 . 2013-06-18 11:23 73728 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2013-06-18 11:23 . 2013-06-18 11:23 719360 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll 2013-06-18 11:23 . 2013-06-18 11:23 62976 ----a-w- c:\windows\system32\pngfilt.dll 2013-06-18 11:23 . 2013-06-18 11:23 61952 ----a-w- c:\windows\SysWow64\tdc.ocx 2013-06-18 11:23 . 2013-06-18 11:23 599552 ----a-w- c:\windows\system32\vbscript.dll 2013-06-18 11:23 . 2013-06-18 11:23 523264 ----a-w- c:\windows\SysWow64\vbscript.dll 2013-06-18 11:23 . 2013-06-18 11:23 51200 ----a-w- c:\windows\system32\imgutil.dll 2013-06-18 11:23 . 2013-06-18 11:23 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll 2013-06-18 11:23 . 2013-06-18 11:23 452096 ----a-w- c:\windows\system32\dxtmsft.dll 2013-06-18 11:23 . 2013-06-18 11:23 441856 ----a-w- c:\windows\system32\html.iec 2013-06-18 11:23 . 2013-06-18 11:23 38400 ----a-w- c:\windows\SysWow64\imgutil.dll 2013-06-18 11:23 . 2013-06-18 11:23 361984 ----a-w- c:\windows\SysWow64\html.iec 2013-06-18 11:23 . 2013-06-18 11:23 281600 ----a-w- c:\windows\system32\dxtrans.dll 2013-06-18 11:23 . 2013-06-18 11:23 27648 ----a-w- c:\windows\system32\licmgr10.dll 2013-06-18 11:23 . 2013-06-18 11:23 270848 ----a-w- c:\windows\system32\iedkcs32.dll 2013-06-18 11:23 . 2013-06-18 11:23 247296 ----a-w- c:\windows\system32\webcheck.dll 2013-06-18 11:23 . 2013-06-18 11:23 235008 ----a-w- c:\windows\system32\url.dll 2013-06-18 11:23 . 2013-06-18 11:23 23040 ----a-w- c:\windows\SysWow64\licmgr10.dll 2013-06-18 11:23 . 2013-06-18 11:23 226304 ----a-w- c:\windows\system32\elshyph.dll 2013-06-18 11:23 . 2013-06-18 11:23 216064 ----a-w- c:\windows\system32\msls31.dll 2013-06-18 11:23 . 2013-06-18 11:23 197120 ----a-w- c:\windows\system32\msrating.dll 2013-06-18 11:23 . 2013-06-18 11:23 185344 ----a-w- c:\windows\SysWow64\elshyph.dll 2013-06-18 11:23 . 2013-06-18 11:23 173568 ----a-w- c:\windows\system32\ieUnatt.exe 2013-06-18 11:23 . 2013-06-18 11:23 167424 ----a-w- c:\windows\system32\iexpress.exe 2013-06-18 11:23 . 2013-06-18 11:23 158720 ----a-w- c:\windows\SysWow64\msls31.dll 2013-06-18 11:23 . 2013-06-18 11:23 1509376 ----a-w- c:\windows\system32\inetcpl.cpl 2013-06-18 11:23 . 2013-06-18 11:23 150528 ----a-w- c:\windows\SysWow64\iexpress.exe 2013-06-18 11:23 . 2013-06-18 11:23 149504 ----a-w- c:\windows\system32\occache.dll 2013-06-18 11:23 . 2013-06-18 11:23 144896 ----a-w- c:\windows\system32\wextract.exe 2013-06-18 11:23 . 2013-06-18 11:23 1441280 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2013-06-18 11:23 . 2013-06-18 11:23 1400416 ----a-w- c:\windows\system32\ieapfltr.dat 2013-06-18 11:23 . 2013-06-18 11:23 138752 ----a-w- c:\windows\SysWow64\wextract.exe 2013-06-18 11:23 . 2013-06-18 11:23 13824 ----a-w- c:\windows\system32\mshta.exe 2013-06-18 11:23 . 2013-06-18 11:23 137216 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2013-06-18 11:23 . 2013-06-18 11:23 12800 ----a-w- c:\windows\SysWow64\mshta.exe 2013-06-18 11:23 . 2013-06-18 11:23 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll 2013-06-18 11:23 . 2013-06-18 11:23 1054720 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2013-06-18 11:23 . 2013-06-18 11:23 102912 ----a-w- c:\windows\system32\inseng.dll 2013-06-18 11:23 . 2013-06-18 11:23 92160 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2013-06-18 11:23 . 2013-06-18 11:23 77312 ----a-w- c:\windows\system32\tdc.ocx 2013-06-18 11:23 . 2013-06-18 11:23 52224 ----a-w- c:\windows\system32\msfeedsbs.dll 2013-06-18 11:23 . 2013-06-18 11:23 48640 ----a-w- c:\windows\system32\mshtmler.dll 2013-06-18 11:23 . 2013-06-18 11:23 136192 ----a-w- c:\windows\system32\iepeers.dll 2013-06-18 11:23 . 2013-06-18 11:23 135680 ----a-w- c:\windows\system32\IEAdvpack.dll 2013-06-18 11:23 . 2013-06-18 11:23 12800 ----a-w- c:\windows\system32\msfeedssync.exe 2013-06-12 08:48 . 2012-04-07 09:23 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-06-12 08:48 . 2012-04-07 09:23 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-06-11 23:43 . 2013-07-11 21:27 1767936 ----a-w- c:\windows\SysWow64\wininet.dll 2013-06-11 23:43 . 2013-07-11 21:27 2877440 ----a-w- c:\windows\SysWow64\jscript9.dll 2013-06-11 23:42 . 2013-07-11 21:27 61440 ----a-w- c:\windows\SysWow64\iesetup.dll 2013-06-11 23:42 . 2013-07-11 21:27 109056 ----a-w- c:\windows\SysWow64\iesysprep.dll 2013-06-11 23:26 . 2013-07-11 21:27 51712 ----a-w- c:\windows\system32\ie4uinit.exe 2013-06-11 23:26 . 2013-07-11 21:27 2241024 ----a-w- c:\windows\system32\wininet.dll 2013-06-11 23:26 . 2013-07-11 21:27 1365504 ----a-w- c:\windows\system32\urlmon.dll 2013-06-11 23:25 . 2013-07-11 21:27 19238912 ----a-w- c:\windows\system32\mshtml.dll 2013-06-11 23:25 . 2013-07-11 21:27 603136 ----a-w- c:\windows\system32\msfeeds.dll 2013-06-11 23:25 . 2013-07-11 21:27 855552 ----a-w- c:\windows\system32\jscript.dll 2013-06-11 23:25 . 2013-07-11 21:27 3958784 ----a-w- c:\windows\system32\jscript9.dll 2013-06-11 23:25 . 2013-07-11 21:27 53248 ----a-w- c:\windows\system32\jsproxy.dll 2013-06-11 23:25 . 2013-07-11 21:27 67072 ----a-w- c:\windows\system32\iesetup.dll 2013-06-11 23:25 . 2013-07-11 21:27 526336 ----a-w- c:\windows\system32\ieui.dll 2013-06-11 23:25 . 2013-07-11 21:27 39936 ----a-w- c:\windows\system32\iernonce.dll 2013-06-11 23:25 . 2013-07-11 21:27 2648576 ----a-w- c:\windows\system32\iertutil.dll 2013-06-11 23:25 . 2013-07-11 21:27 136704 ----a-w- c:\windows\system32\iesysprep.dll 2013-06-11 23:25 . 2013-07-11 21:27 15404032 ----a-w- c:\windows\system32\ieframe.dll 2013-06-11 22:51 . 2013-07-11 21:27 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2013-06-11 22:50 . 2013-07-11 21:27 89600 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe 2013-06-07 03:22 . 2013-07-11 21:27 2706432 ----a-w- c:\windows\system32\mshtml.tlb 2013-06-07 02:37 . 2013-07-11 21:27 2706432 ----a-w- c:\windows\SysWow64\mshtml.tlb 2013-06-05 03:34 . 2013-07-11 20:59 3153920 ----a-w- c:\windows\system32\win32k.sys 2013-06-04 06:00 . 2013-07-11 20:59 624128 ----a-w- c:\windows\system32\qedit.dll 2013-06-04 04:53 . 2013-07-11 20:59 509440 ----a-w- c:\windows\SysWow64\qedit.dll 2013-05-16 20:20 . 2010-06-24 18:33 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "WebcamMaxAutoRun"="c:\program files (x86)\WebcamMax\wcmmon.exe" [2011-07-17 1038848] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Nuance PDF Reader-reminder"="c:\program files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" [2008-11-03 328992] "SonicMasterTray"="c:\program files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe" [2010-07-10 984400] "ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-08-17 5732992] "ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-10-07 170624] "HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016] "Wireless Console 3"="c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe" [2010-09-23 1601536] "UIExec"="c:\program files (x86)\ZTE Join Air\UIExec.exe" [2010-11-01 139088] "AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-05-09 4858968] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ AsusVibeLauncher.lnk - c:\program files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe /start [2011-4-1 548528] FancyStart daemon.lnk - c:\windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe -d [2011-9-8 12862] McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe [2013-2-5 272248] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) "AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0??A??????????????1\0qMhg.??A?autocheck autochk *\0??A???A??????????????1\0o??A??° . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe;c:\program files (x86)\Google\Update\GoogleUpdate.exe [x] R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x] R3 gupdatem;Serviciul Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe;c:\program files (x86)\Google\Update\GoogleUpdate.exe [x] R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x] R3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys;c:\windows\SYSNATIVE\drivers\massfilter.sys [x] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe;c:\program files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [x] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x] R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RTSUVSTOR.sys;c:\windows\SYSNATIVE\Drivers\RTSUVSTOR.sys [x] R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys;c:\windows\SYSNATIVE\DRIVERS\SiSG664.sys [x] R3 ST330;ST330;c:\windows\system32\DRIVERS\st330.sys;c:\windows\SYSNATIVE\DRIVERS\st330.sys [x] R3 STBUS;STBUS;c:\windows\system32\DRIVERS\stbus.sys;c:\windows\SYSNATIVE\DRIVERS\stbus.sys [x] R3 STETH;SpeedTouch Ethernet Adapter NT Driver;c:\windows\system32\DRIVERS\steth.sys;c:\windows\SYSNATIVE\DRIVERS\steth.sys [x] R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 WatAdminSvc;Serviciul tehnologii de activare Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S0 aswRvrt;aswRvrt; [x] S0 aswVmm;aswVmm; [x] S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 ATKWMIACPIIO;ATKWMIACPI Driver;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [x] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x] S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys;c:\windows\SYSNATIVE\drivers\acedrv11.sys [x] S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe;c:\windows\SYSNATIVE\FBAgent.exe [x] S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [x] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x] S2 Autodesk Content Service;Autodesk Content Service;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [x] S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x] S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys;c:\windows\SYSNATIVE\DRIVERS\TurboB.sys [x] S2 TurboBoost;Intel® Turbo Boost Technology Monitor;c:\program files\Intel\TurboBoost\TurboBoost.exe;c:\program files\Intel\TurboBoost\TurboBoost.exe [x] S2 UI Assistant Service;UI Assistant Service;c:\program files (x86)\ZTE Join Air\AssistantServices.exe;c:\program files (x86)\ZTE Join Air\AssistantServices.exe [x] S2 WCMVCAM;WebcamMax, WDM Video Capture;c:\windows\system32\DRIVERS\wcmvcam64.sys;c:\windows\SYSNATIVE\DRIVERS\wcmvcam64.sys [x] S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys;c:\windows\SYSNATIVE\DRIVERS\asmthub3.sys [x] S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys;c:\windows\SYSNATIVE\DRIVERS\asmtxhci.sys [x] S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x] S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\SPB_16.5] 2011-04-14 05:47 930 ----a-w- c:\cadence\SPB_16.5\tools\ConfigUtility\CreateShortcut.vbs . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-08-02 07:41 1173456 ----a-w- c:\program files (x86)\Google\Chrome\Application\28.0.1500.95\Installer\chrmstp.exe . Contents of the 'Scheduled Tasks' folder . 2013-08-13 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-07 08:48] . 2013-08-10 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1893879692-3683617307-328983177-1001Core.job - c:\users\Ionut\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-11-14 17:37] . 2013-08-13 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1893879692-3683617307-328983177-1001UA.job - c:\users\Ionut\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-11-14 17:37] . 2013-08-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-01 08:58] . 2013-08-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-01 08:58] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2013-05-09 08:58 133840 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B] @="{6D4133E5-0742-4ADC-8A8C-9303440F7190}" [HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}] 2010-09-02 08:41 220160 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSShellExt64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O] @="{64174815-8D98-4CE6-8646-4C039977D808}" [HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}] 2010-09-02 08:41 220160 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSShellExt64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-10 391704] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-10 418328] "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-05-17 2226280] "IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-05-02 1935120] "IntelTBRunOnce"="wscript.exe" [2009-07-14 168960] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208] "LXCECATS"="c:\windows\system32\spool\DRIVERS\x64\3\LXCEtime.dll" [2007-02-22 28672] "lxcemon.exe"="c:\program files (x86)\Lexmark 4300 Series\lxcemon.exe" [2007-05-17 205744] "EzPrint"="c:\program files (x86)\Lexmark 4300 Series\ezprint.exe" [2007-05-17 103344] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=c:\windows\System32\nvinitx.dll . ------- Supplementary Scan ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = about:blank mStart Page = about:blank mLocal Page = c:\windows\SysWOW64\blank.htm uSearchURL,(Default) = hxxp://www.google.ro mSearchAssistant = hxxp://www.google.ro mCustomizeSearch = hxxp://www.google.ro IE: {{07BA1DA9-F501-4796-8728-74D1B91A6CD5} - c:\program files (x86)\PokerStars.EU\PokerStarsUpdate.exe TCP: DhcpNameServer = 192.168.1.1 0.0.0.0 . - - - - ORPHANS REMOVED - - - - . HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start HKLM-Run-ETDCtrl - c:\program files (x86)\Elantech\ETDCtrl.exe HKLM-Run-InstallerLauncher - c:\program files\Common Files\Bitdefender\SetupInformation\{6F57816A-791A-4159-A75F-CFD0C7EA4FBF}\setuplauncher.exe AddRemove-SopCast Tv Plugin 5.9 Setup - c:\windows\Uninstall-TvPlugin-5.9 . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\st330service] "ImagePath"="C:\Program Files (x86)/Thomson SpeedTouch/ST330/service/st330service.exe -service" . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2013-08-13 18:42:37 ComboFix-quarantined-files.txt 2013-08-13 15:42 . Pre-Run: 64.360.673.280 bytes free Post-Run: 63.373.180.928 bytes free . - - End Of File - - 4078733B8212602E8A9D7FB9927A1E84 D41D8CD98F00B204E9800998ECF8427E |
#40
Posted 13 August 2013 - 17:51
![](https://forum.softpedia.com//public/style_images/classic/post_offline.png)
#44
Posted 13 August 2013 - 18:09
![](https://forum.softpedia.com//public/style_images/classic/post_offline.png)
Descarca si salveaza pe Desktop Windows Repair (all in one).
Dezarhiveaza si ruleaza Windows Repair. Mergi la Start Repairs si apasa pe Start. [ http://s16.postimg.org/j6wbeq2qt/wr1.jpg - Pentru incarcare in pagina (embed) Click aici ] Verifica sa fie bifate urmatoarele: Reset Registry Permissions Reset File Permissions Register System Files Repair WMI Remove Policies Set By Infections Repair Missing Start menu Icons Repair Proxy Settings Unhide Non System Files Repair Windows Updates Set Windows Services To Default Repair MSI (windows Installer) Repair File Associations Bifeaza Restart System si apasa pe Start. [ http://i121.photobucket.com/albums/o239/kevinf80/Tweaking-com/Tweak6_zpsd6411a53.jpg - Pentru incarcare in pagina (embed) Click aici ] Dupa restart verifica daca mai ai probleme. |
#45
Posted 13 August 2013 - 19:23
![](https://forum.softpedia.com//public/style_images/classic/post_offline.png)
Imediat dupa restart a inceput eroarea
![]() |
#46
Posted 13 August 2013 - 19:47
![](https://forum.softpedia.com//public/style_images/classic/post_offline.png)
|
#47
Posted 13 August 2013 - 19:51
![](https://forum.softpedia.com//public/style_images/classic/post_offline.png)
O sa urmez acei pasi maine, acum este destul de tarziu si cine stie cat dureaza.Sper sa isi revina si shortcut-urile Fn
![]() |
Anunturi
Bun venit pe Forumul Softpedia!
▶ 0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users