Здравейте от няколко дни браузърът зарежда по-бавно от преди и получих съобщение "Вие излязохте от вашият профил , моля влезте отново"
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 22-04-2022
Ran by ВЕСКО (administrator) on ZEUS (Hewlett-Packard HP EliteBook 6930p) (02-05-2022 12:48:22)
Running from C:\Users\ВЕСКО\Downloads
Loaded Profiles: ВЕСКО
Platform: Microsoft Windows 8.1 Pro (Update) (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Users\ВЕСКО\AppData\Local\Plarium\PlariumPlay\7.0.0-0.0.0\PlariumPlay.exe ->) (Plarium Global Ltd -> ) C:\Users\ВЕСКО\AppData\Local\Plarium\PlariumPlay\7.0.0-0.0.0\PlariumPlayInfo.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <11>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.132\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.132\GoogleCrashHandler64.exe
(Plarium Global Ltd -> Plarium) C:\Users\ВЕСКО\AppData\Local\Plarium\PlariumPlay\7.0.0-0.0.0\PlariumPlay.exe <7>
(services.exe ->) (Avago Technologies U.S. Inc. -> LSI Corporation) C:\Program Files\LSI SoftModem\agr64svc.exe
(services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\msiexec.exe
(services.exe ->) (Plarium Global Ltd -> ) C:\Users\ВЕСКО\AppData\Local\Plarium\PlariumPlay\7.0.0-0.0.0\PlariumPlayClientService\PlariumPlayClientService.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.20332_none_fadb6b40b4386518\TiWorker.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [hola] => C:\Program Files\Hola\app\hola.exe --silent (No File) <==== ATTENTION
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2096424 2010-05-27] (Synaptics Incorporated -> Synaptics Incorporated)
HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [226728 2019-07-21] (Kilonova LLC -> )
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\101.0.4951.41\Installer\chrmstp.exe [2022-04-27] (Google LLC -> Google LLC)
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {44580A62-4F66-4298-B732-D6EE9216611C} - System32\Tasks\update-S-1-5-21-4248551122-1917605105-3787785301-1001 => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [414872 2017-04-12] (OOO Lightshot -> TODO: <Company name>)
Task: {8EA63310-2CD9-42BC-9E55-D63EE9E04128} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154456 2021-06-08] (Google LLC -> Google LLC)
Task: {9F00D945-6165-4943-BB4B-03311AF092A5} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154456 2021-06-08] (Google LLC -> Google LLC)
Task: {9FFB107F-0674-47AD-ACBD-C0B8ED348B1E} - System32\Tasks\update-sys => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [414872 2017-04-12] (OOO Lightshot -> TODO: <Company name>)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\update-S-1-5-21-4248551122-1917605105-3787785301-1001.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
Task: C:\Windows\Tasks\update-sys.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 46.35.180.1 46.35.180.2
Tcpip\..\Interfaces\{40881A9F-94AA-4A4C-B977-590CBB590806}: [DhcpNameServer] 46.35.180.1 46.35.180.2
Chrome:
=======
CHR Profile: C:\Users\ВЕСКО\AppData\Local\Google\Chrome\User Data\Default [2022-05-02]
CHR HomePage: Default -> hxxp://google.bg/
CHR StartupUrls: Default -> "hxxps://www.google.bg/"
CHR Extension: (uBlock Origin) - C:\Users\ВЕСКО\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2022-04-09]
CHR Extension: (GDPlay) - C:\Users\ВЕСКО\AppData\Local\Google\Chrome\User Data\Default\Extensions\idjmioilgmedmbfabcfnpeaclcndeekb [2021-08-30]
CHR Extension: (Lightshot (скрииншот инструмент)) - C:\Users\ВЕСКО\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbniclmhobmnbdlbpiphghaielnnpgdp [2021-06-08]
CHR Extension: (Плащания в уеб магазина на Chrome) - C:\Users\ВЕСКО\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-06-08]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AgereModemAudio; C:\Program Files\LSI SoftModem\agr64svc.exe [42096 2015-08-04] (Avago Technologies U.S. Inc. -> LSI Corporation)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [8022200 2022-03-21] (Malwarebytes Inc -> Malwarebytes)
R2 Plarium Play Client Service; C:\Users\ВЕСКО\AppData\Local\Plarium\PlariumPlay\7.0.0-0.0.0\PlariumPlayClientService\PlariumPlayClientService.exe [99960 2022-03-31] (Plarium Global Ltd -> )
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-01-12] (Microsoft Corporation -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [112144 2021-05-18] (Microsoft Corporation -> Microsoft Corporation)
S2 hola_svc; "C:\Program Files\Hola\app\hola_svc.exe" --service [X] <==== ATTENTION
S2 hola_updater; "C:\Program Files\Hola\app\hola_updater.exe" --service --run-as hola_updater [X] <==== ATTENTION
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 cpuz148; C:\Windows\temp\cpuz148\cpuz148_x64.sys [44832 2021-08-18] (CPUID S.A.R.L.U. -> CPUID)
S3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [248992 2021-07-15] (Malwarebytes Inc -> Malwarebytes)
S3 phantomtap; C:\Windows\system32\DRIVERS\phantomtap.sys [39448 2022-01-25] (Avira Operations GmbH & Co. KG -> The OpenVPN Project)
R3 RICOH SmartCard Reader; C:\Windows\system32\DRIVERS\rismcx64.sys [79488 2006-10-03] (Microsoft Windows Hardware Compatibility Publisher -> RICOH Company, Ltd.)
S3 SNP2UVC; C:\Windows\system32\DRIVERS\snp2uvc.sys [1848496 2009-07-01] (Chicony Electronics Co., Ltd. -> )
S3 tap0901; C:\Windows\system32\DRIVERS\tap0901.sys [30720 2019-10-31] (OpenVPN Inc. -> The OpenVPN Project)
S3 tapnordvpn; C:\Windows\system32\DRIVERS\tapnordvpn.sys [41792 2021-06-13] (nordvpn s.a. -> The OpenVPN Project)
S3 vjoy; C:\Windows\System32\drivers\vjoy.sys [57976 2017-04-06] (Shaul Eizikovich -> Shaul Eizikovich)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [46600 2017-02-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [274776 2017-01-12] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [117592 2017-01-12] (Microsoft Windows -> Microsoft Corporation)
S3 bntap; \SystemRoot\system32\DRIVERS\bntap.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-05-02 12:48 - 2022-05-02 12:49 - 000008218 _____ C:\Users\ВЕСКО\Downloads\FRST.txt
2022-05-02 12:47 - 2022-05-02 12:48 - 000000000 ____D C:\FRST
2022-05-02 12:47 - 2022-05-02 12:47 - 002366976 _____ (Farbar) C:\Users\ВЕСКО\Downloads\FRST64.exe
2022-04-25 10:34 - 2022-04-25 10:34 - 001503928 _____ (Adobe) C:\Users\ВЕСКО\Downloads\uninstall_flash_player.exe
2022-04-15 19:45 - 2022-04-15 19:45 - 000000000 ____D C:\Program Files\Reference Assemblies
2022-04-15 19:45 - 2022-04-15 19:45 - 000000000 ____D C:\Program Files\MSBuild
2022-04-15 19:45 - 2022-04-15 19:45 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2022-04-15 19:45 - 2022-04-15 19:45 - 000000000 ____D C:\Program Files (x86)\MSBuild
2022-04-15 19:39 - 2022-04-15 19:39 - 052403599 _____ (Free Games Downloads, Inc. ) C:\Users\ВЕСКО\Downloads\AvtoKSetup.exe
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-05-02 12:46 - 2021-08-13 16:29 - 000000000 ____D C:\ProgramData\Package Cache
2022-05-02 12:45 - 2013-08-22 16:36 - 000000000 ____D C:\Windows\Inf
2022-05-02 12:36 - 2021-06-08 17:29 - 000000000 ____D C:\Program Files (x86)\Google
2022-05-02 12:32 - 2021-06-18 19:24 - 000000398 _____ C:\Windows\Tasks\update-sys.job
2022-05-02 11:41 - 2021-06-18 19:25 - 000000398 _____ C:\Windows\Tasks\update-S-1-5-21-4248551122-1917605105-3787785301-1001.job
2022-05-02 07:10 - 2021-06-08 17:17 - 000003910 _____ C:\Windows\system32\Tasks\User_Feed_Synchronization-{59FA8249-2279-4382-BD15-0E59F9718588}
2022-05-02 02:23 - 2021-06-08 16:51 - 000000000 __RHD C:\Users\Public\AccountPictures
2022-04-29 16:31 - 2021-06-08 20:00 - 000000000 ___DO C:\Users\ВЕСКО\SkyDrive
2022-04-29 16:28 - 2013-09-30 07:14 - 000865068 _____ C:\Windows\system32\PerfStringBackup.INI
2022-04-28 20:30 - 2013-08-22 18:36 - 000000000 ____D C:\Windows\system32\NDF
2022-04-28 01:26 - 2013-08-22 18:36 - 000000000 ____D C:\Windows\AppReadiness
2022-04-27 03:58 - 2021-06-08 17:02 - 000003600 _____ C:\Windows\system32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-4248551122-1917605105-3787785301-1001
2022-04-27 02:44 - 2021-06-08 17:36 - 000002188 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2022-04-27 02:44 - 2021-06-08 17:36 - 000002147 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2022-04-25 10:38 - 2013-08-22 17:45 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2022-04-25 10:37 - 2013-08-22 16:25 - 000262144 ___SH C:\Windows\system32\config\BBI
2022-04-25 10:34 - 2021-06-08 16:50 - 000000000 ____D C:\Users\ВЕСКО\AppData\Roaming\Adobe
2022-04-25 10:32 - 2021-06-08 21:13 - 000000000 ____D C:\Program Files\Easeware
2022-04-25 10:31 - 2021-06-08 21:14 - 000000000 ____D C:\Users\ВЕСКО\AppData\Roaming\Easeware
2022-04-22 04:25 - 2021-06-08 17:51 - 000000000 ____D C:\Users\ВЕСКО\AppData\LocalLow\Unity
2022-04-21 18:59 - 2019-01-06 07:43 - 000000000 ____D C:\LFS
2022-04-21 18:47 - 2021-12-19 10:20 - 000000542 _____ C:\Users\ВЕСКО\Desktop\LFS.lnk
2022-04-20 16:28 - 2021-06-08 17:30 - 000003434 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA
2022-04-20 16:28 - 2021-06-08 17:30 - 000003306 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore
2022-04-17 05:48 - 2013-08-22 18:36 - 000000000 ____D C:\Windows\rescache
2022-04-17 01:40 - 2013-08-22 18:20 - 000000000 ____D C:\Windows\CbsTemp
2022-04-14 17:35 - 2021-12-04 13:42 - 000000000 ____D C:\Users\ВЕСКО\AppData\Roaming\WhatsApp
2022-04-14 17:32 - 2021-06-18 19:30 - 000000000 ____D C:\Users\ВЕСКО\Documents\Lightshot
2022-04-14 16:36 - 2021-06-08 19:26 - 000000000 ____D C:\Windows\system32\MRT
2022-04-14 16:32 - 2021-06-08 19:26 - 143823848 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2022-04-13 16:19 - 2013-08-22 17:44 - 000337808 _____ C:\Windows\system32\FNTCACHE.DAT
2022-04-13 06:06 - 2013-08-22 18:36 - 000000000 ___RD C:\Windows\ToastData
==================== Files in the root of some directories ========
2021-06-08 20:01 - 2021-06-08 20:01 - 000000000 _____ () C:\Users\ВЕСКО\AppData\Local\AtStart.txt
2022-01-19 20:19 - 2022-01-20 13:00 - 000000107 _____ () C:\Users\ВЕСКО\AppData\Local\dc4f79923a5baeb14164.bin
2021-06-08 20:01 - 2021-06-08 20:01 - 000000000 _____ () C:\Users\ВЕСКО\AppData\Local\DSwitch.txt
2021-06-08 17:38 - 2021-12-03 17:21 - 000857429 _____ () C:\Users\ВЕСКО\AppData\Local\PlariumPlay.log
2021-06-08 20:01 - 2021-06-08 20:01 - 000000000 _____ () C:\Users\ВЕСКО\AppData\Local\QSwitch.txt
2021-06-18 19:24 - 2021-06-18 19:24 - 000000003 _____ () C:\Users\ВЕСКО\AppData\Local\updater.log
2021-06-18 19:25 - 2021-06-18 19:25 - 000000424 _____ () C:\Users\ВЕСКО\AppData\Local\UserProducts.xml
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
LastRegBack: 2022-04-26 02:04
==================== End of FRST.txt ========================
dditional scan result of Farbar Recovery Scan Tool (x64) Version: 22-04-2022
Ran by ВЕСКО (02-05-2022 12:50:22)
Running from C:\Users\ВЕСКО\Downloads
Microsoft Windows 8.1 Pro (Update) (X64) (2021-06-08 13:50:20)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-4248551122-1917605105-3787785301-500 - Administrator - Disabled)
Guest (S-1-5-21-4248551122-1917605105-3787785301-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-4248551122-1917605105-3787785301-1003 - Limited - Enabled)
ВЕСКО (S-1-5-21-4248551122-1917605105-3787785301-1001 - Administrator - Enabled) => C:\Users\ВЕСКО
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Disabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Malwarebytes (Disabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 101.0.4951.41 - Google LLC)
HP Webcam (HKLM-x32\...\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}) (Version: 5.8.39017.0 - Sonix)
KMSpico (HKLM\...\{8B29D47F-92E2-4C20-9EE0-F710991F5D7C}_is1) (Version: - )
Lightshot-5.5.0.7 (HKLM-x32\...\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1) (Version: 5.5.0.7 - Skillbrains)
LINE (HKU\S-1-5-21-4248551122-1917605105-3787785301-1001\...\LINE) (Version: 6.7.4.2508 - LINE Corporation)
LSI HDA Modem (HKLM\...\LSI Soft Modem) (Version: 2.2.100 - LSI Corporation)
Malwarebytes version 4.5.6.180 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.5.6.180 - Malwarebytes)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.29.30133 (HKLM-x32\...\{295d1583-fdb9-414b-a4c8-da539362a26b}) (Version: 14.29.30133.0 - Microsoft Corporation)
Plarium Play (HKLM-x32\...\{1165C29E-6794-419B-AFAF-8C615C2D590F}) (Version: 7.0.0 - Plarium) Hidden
Plarium Play (HKLM-x32\...\{a0117c0b-1a87-4e45-b41f-6ca56d7cf688}) (Version: 7.0.0 - Plarium)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.0.17.4 - Synaptics Incorporated)
WhatsApp (HKU\S-1-5-21-4248551122-1917605105-3787785301-1001\...\WhatsApp) (Version: 2.2210.9 - WhatsApp)
WinRAR 6.01 (64-bit) (HKLM\...\WinRAR archiver) (Version: 6.01.0 - win.rar GmbH)
Packages:
=========
Frameworkuapbase -> C:\Program Files\WindowsApps\48682KiddoTest.Frameworkuapbase_1.0.0.2_neutral__81ffpr532s7pc [2021-06-08] (KiddoTest)
Kinect for Windows Framework -> C:\Program Files\WindowsApps\Microsoft.WindowsPreview.Kinect.8.0_2.0.1410.19000_x64__8wekyb3d8bbwe [2021-06-08] (Microsoft Corporation)
Kinect for Windows Framework -> C:\Program Files\WindowsApps\Microsoft.WindowsPreview.Kinect.8.0_2.0.1410.19000_x86__8wekyb3d8bbwe [2021-06-08] (Microsoft Corporation)
Kinect for Windows Framework -> C:\Program Files\WindowsApps\Microsoft.WindowsPreview.Kinect.8.1_2.0.1410.19000_x64__8wekyb3d8bbwe [2021-06-08] (Microsoft Corporation)
Kinect for Windows Framework -> C:\Program Files\WindowsApps\Microsoft.WindowsPreview.Kinect.8.1_2.0.1410.19000_x86__8wekyb3d8bbwe [2021-06-08] (Microsoft Corporation)
Microsoft PlayReady -> C:\Program Files\WindowsApps\Microsoft.Internal.Media.PlayReadyClient_2.3.1678.1_x64__8wekyb3d8bbwe [2021-06-08] (Microsoft Corporation)
Microsoft PlayReady -> C:\Program Files\WindowsApps\Microsoft.Internal.Media.PlayReadyClient_2.3.1678.1_x86__8wekyb3d8bbwe [2021-06-08] (Microsoft Corporation)
Microsoft Visual C++ Runtime Package -> C:\Program Files\WindowsApps\Microsoft.VCLibs.120.00.Preview.Internal_12.0.20222.2_x64__8wekyb3d8bbwe [2021-06-08] (Microsoft Platform Extensions Internal)
Microsoft Visual C++ Runtime Package -> C:\Program Files\WindowsApps\Microsoft.VCLibs.120.00.Preview.Internal_12.0.20222.2_x86__8wekyb3d8bbwe [2021-06-08] (Microsoft Platform Extensions Internal)
Microsoft Windows Library for JavaScript -> C:\Program Files\WindowsApps\Microsoft.WinJS.2.0.Preview.Internal_1.0.9385.3_neutral__8wekyb3d8bbwe [2021-06-08] (Microsoft Platform Extensions)
Microsoft Windows Library for JavaScript -> C:\Program Files\WindowsApps\Microsoft.WinJS.2.0.Preview_1.0.9431.0_neutral__8wekyb3d8bbwe [2021-06-08] (Microsoft Platform Extensions)
Microsoft Windows Library for JavaScript -> C:\Program Files\WindowsApps\Microsoft.WinJS.Preview.1_1.0.9345.0_neutral__8wekyb3d8bbwe [2021-06-08] (Microsoft Platform Extensions)
MSN Време -> C:\Program Files\WindowsApps\Microsoft.BingWeather_3.0.4.350_x64__8wekyb3d8bbwe [2021-06-10] (Microsoft Corporation) [MS Ad]
MSN Новини -> C:\Program Files\WindowsApps\Microsoft.BingNews_3.0.4.344_x64__8wekyb3d8bbwe [2021-06-10] (Microsoft Corporation) [MS Ad]
MSN Пътуване -> C:\Program Files\WindowsApps\Microsoft.BingTravel_3.0.4.336_x64__8wekyb3d8bbwe [2021-06-10] (Microsoft Corporation) [MS Ad]
MSN Спорт -> C:\Program Files\WindowsApps\Microsoft.BingSports_3.0.4.345_x64__8wekyb3d8bbwe [2022-03-29] (Microsoft Corporation) [MS Ad]
mxtest2 -> C:\Program Files\WindowsApps\24712m1dfmmengesha.mxtest2_2.0.0.0_neutral__x35ns48czryn0 [2021-06-08] (m1df_mmengesha)
Test_Framework_BP_052015 -> C:\Program Files\WindowsApps\24712m1dfmmengesha.TestFrameworkBP052015_1.0.0.9_neutral__x35ns48czryn0 [2021-06-08] (m1df_mmengesha)
Test_FrameworkBackpublish_050515 -> C:\Program Files\WindowsApps\24712m1dfmmengesha.TestFrameworkBackpublish050515_1.0.0.0_neutral__x35ns48czryn0 [2021-06-08] (m1df_mmengesha)
Test_FrameworkProd_062215_01 -> C:\Program Files\WindowsApps\50856m1dfLL.TestFrameworkProd06221501_1.0.0.10_neutral__nwcxtg9ehxpvt [2021-06-08] (m1df_lucyll)
TESTFRAMEWORKABO2 -> C:\Program Files\WindowsApps\40538vasetest101.TESTFRAMEWORKABO2_12.0.21005.1_x64__ssm1v0s3df7zc [2021-06-08] (vasetest101)
Видео -> C:\Program Files\WindowsApps\Microsoft.ZuneVideo_2.6.446.0_x64__8wekyb3d8bbwe [2021-06-10] (Microsoft Corporation) [MS Ad]
Игри -> C:\Program Files\WindowsApps\Microsoft.XboxLIVEGames_2.0.139.0_x64__8wekyb3d8bbwe [2021-06-10] (Microsoft Corporation) [MS Ad]
Музика -> C:\Program Files\WindowsApps\Microsoft.ZuneMusic_2.6.672.0_x64__8wekyb3d8bbwe [2021-06-10] (Microsoft Corporation) [MS Ad]
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2021-04-07] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2021-04-07] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2021-06-09] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2021-06-09] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2021-04-07] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2021-04-07] (win.rar GmbH -> Alexander Roshal)
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
Shortcut: C:\Users\ВЕСКО\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LINE\Удаление LINE.lnk -> C:\Users\ВЕСКО\AppData\Local\LINE\bin\LineUnInst.exe () <==== Cyrillic
==================== Loaded Modules (Whitelisted) =============
==================== Alternate Data Streams (Whitelisted) ========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\ProgramData:MHD [274]
AlternateDataStreams: C:\Users\All Users:MHD [274]
AlternateDataStreams: C:\ProgramData\Application Data:MHD [274]
AlternateDataStreams: C:\Users\ВЕСКО\Local Settings:MHD [270]
AlternateDataStreams: C:\Users\ВЕСКО\AppData\Local:MHD [270]
AlternateDataStreams: C:\Users\ВЕСКО\AppData\Local\Application Data:MHD [270]
AlternateDataStreams: C:\Users\ВЕСКО\AppData\Local\Temp:MHD [274]
AlternateDataStreams: C:\Users\ВЕСКО\Documents\Malinovka:MHD [274]
==================== Safe Mode (Whitelisted) ==================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) ==========
HKU\S-1-5-21-4248551122-1917605105-3787785301-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.bg/
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-4248551122-1917605105-3787785301-1001\...\hola.org -> hxxp://hola.org
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 16:25 - 2022-01-01 17:04 - 000000822 _____ C:\Windows\system32\drivers\etc\hosts
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-4248551122-1917605105-3787785301-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\ВЕСКО\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\img0.jpg
DNS Servers: 46.35.180.1 - 46.35.180.2
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
HKLM\...\StartupApproved\Run: => "SynTPEnh"
HKLM\...\StartupApproved\Run: => "hola"
HKLM\...\StartupApproved\Run: => "UrbanVPN"
HKLM\...\StartupApproved\Run32: => "Lightshot"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{438FEB20-5E02-4677-A24D-FCE04A95B5DA}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe => No File
FirewallRules: [{BBE954D3-DB2D-410A-9234-505CBF643383}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe => No File
FirewallRules: [TCP Query User{9A3849A3-9C4A-47DA-8658-143441770B16}C:\program files\qbittorrent\qbittorrent.exe] => (Allow) C:\program files\qbittorrent\qbittorrent.exe => No File
FirewallRules: [UDP Query User{5836B2ED-D662-4218-85CA-5D0123A9B453}C:\program files\qbittorrent\qbittorrent.exe] => (Allow) C:\program files\qbittorrent\qbittorrent.exe => No File
FirewallRules: [TCP Query User{69AAE2E3-7B16-4C7A-B8E3-586F78E99B73}C:\game\stalkeronline\stalkeronline launcher.exe] => (Allow) C:\game\stalkeronline\stalkeronline launcher.exe => No File
FirewallRules: [UDP Query User{7B206F09-BFDF-4AA3-8CBC-D07C264E44D7}C:\game\stalkeronline\stalkeronline launcher.exe] => (Allow) C:\game\stalkeronline\stalkeronline launcher.exe => No File
FirewallRules: [{CCE90183-AB61-4F26-B8DE-2A042F9EC112}] => (Allow) C:\Users\ВЕСКО\Downloads\SO_installer.exe => No File
FirewallRules: [{912E0F12-5441-4C48-8C42-C9FE392F84DF}] => (Allow) C:\Users\ВЕСКО\Downloads\SO_installer.exe => No File
FirewallRules: [{02042581-ED33-4074-A69E-CC725FF9AA53}] => (Allow) C:\Users\ВЕСКО\Downloads\SO_installer.exe => No File
FirewallRules: [{F823040A-CE11-4E56-8BEA-507DF8D08094}] => (Allow) C:\Users\ВЕСКО\Downloads\SO_installer.exe => No File
FirewallRules: [{42A2F294-4710-4E39-AE45-63EE7B67762D}] => (Allow) C:\program files\qbittorrent\qbittorrent.exe => No File
FirewallRules: [{1D08DC4C-7F31-4FA7-B894-AAB233E3CE25}] => (Allow) C:\program files\qbittorrent\qbittorrent.exe => No File
FirewallRules: [TCP Query User{3AF60D81-643B-4FCF-A056-E20DF13D9CAC}C:\game\stalkeronline\stalkeronline launcher.exe] => (Allow) C:\game\stalkeronline\stalkeronline launcher.exe => No File
FirewallRules: [UDP Query User{4B75E347-0542-4F7A-8154-D5966FC7795A}C:\game\stalkeronline\stalkeronline launcher.exe] => (Allow) C:\game\stalkeronline\stalkeronline launcher.exe => No File
FirewallRules: [TCP Query User{E9746411-2329-464A-A5DE-C3498ABE8DD6}C:\lfs\lfs.exe] => (Allow) C:\lfs\lfs.exe () [File not signed]
FirewallRules: [UDP Query User{0A4E6EB7-D0AF-4111-89F4-111CACDFD7AD}C:\lfs\lfs.exe] => (Allow) C:\lfs\lfs.exe () [File not signed]
FirewallRules: [TCP Query User{CAC1137E-2735-4BFE-86A2-CF6611095F03}C:\users\веско\appdata\local\gamecenter\gamecenter.exe] => (Allow) C:\users\веско\appdata\local\gamecenter\gamecenter.exe => No File
FirewallRules: [UDP Query User{354CDE63-CAD1-4757-9438-0C970D40166C}C:\users\веско\appdata\local\gamecenter\gamecenter.exe] => (Allow) C:\users\веско\appdata\local\gamecenter\gamecenter.exe => No File
FirewallRules: [TCP Query User{21007C5D-20AC-4E2B-B6CB-F85BDEC6938E}E:\mygames\stay out\game\sogame.exe] => (Allow) E:\mygames\stay out\game\sogame.exe => No File
FirewallRules: [UDP Query User{33303FBE-6B5F-400C-9397-6F257685DB7D}E:\mygames\stay out\game\sogame.exe] => (Allow) E:\mygames\stay out\game\sogame.exe => No File
FirewallRules: [{135B69D7-856E-427F-9E92-9BC670455BF0}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
==================== Restore Points =========================
23-04-2022 02:37:11 Scheduled Checkpoint
30-04-2022 06:05:38 Scheduled Checkpoint
==================== Faulty Device Manager Devices ============
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Fingerprint Sensor
Description: Fingerprint Sensor
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Base System Device
Description: Base System Device
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: ========================
Application errors:
==================
Error: (05/01/2022 04:29:39 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0xC004F074
Command-line arguments:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=c06b6981-d7fd-4a35-b7b4-054742b7af67;NotificationInterval=1440;Trigger=TimerEvent
Error: (04/30/2022 04:30:18 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0xC004F074
Command-line arguments:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=c06b6981-d7fd-4a35-b7b4-054742b7af67;NotificationInterval=1440;Trigger=TimerEvent
Error: (04/29/2022 04:31:14 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0xC004F074
Command-line arguments:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=c06b6981-d7fd-4a35-b7b4-054742b7af67;NotificationInterval=1440;Trigger=UserLogon;SessionId=5
Error: (04/29/2022 04:27:28 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0xC004F074
Command-line arguments:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=c06b6981-d7fd-4a35-b7b4-054742b7af67;NotificationInterval=1440;Trigger=NetworkAvailable
Error: (04/28/2022 08:42:33 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0xC004F074
Command-line arguments:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=c06b6981-d7fd-4a35-b7b4-054742b7af67;NotificationInterval=1440;Trigger=NetworkAvailable
Error: (04/28/2022 04:22:44 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0xC004F074
Command-line arguments:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=c06b6981-d7fd-4a35-b7b4-054742b7af67;NotificationInterval=1440;Trigger=UserLogon;SessionId=4
Error: (04/28/2022 04:17:50 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0xC004F074
Command-line arguments:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=c06b6981-d7fd-4a35-b7b4-054742b7af67;NotificationInterval=1440;Trigger=NetworkAvailable
Error: (04/27/2022 04:31:23 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0xC004F074
Command-line arguments:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=c06b6981-d7fd-4a35-b7b4-054742b7af67;NotificationInterval=1440;Trigger=UserLogon;SessionId=3
System errors:
=============
Error: (05/02/2022 12:56:01 PM) (Source: DCOM) (EventID: 10010) (User: ZEUS)
Description: The server {BB6DF56B-CACE-11DC-9992-0019B93A3A84} did not register with DCOM within the required timeout.
Error: (05/02/2022 12:54:01 PM) (Source: DCOM) (EventID: 10010) (User: ZEUS)
Description: The server {1ECCA34C-E88A-44E3-8D6A-8921BDE9E452} did not register with DCOM within the required timeout.
Error: (05/02/2022 05:30:50 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 70.
Error: (05/02/2022 05:30:50 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 70.
Error: (05/02/2022 05:30:35 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 70.
Error: (05/02/2022 05:30:34 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 70.
Error: (05/02/2022 05:30:29 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 70.
Error: (05/02/2022 05:30:29 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 70.
Windows Defender:
================
Date: 2021-08-26 16:47:49.531
Description:
Windows Defender scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2021-08-24 16:59:19.228
Description:
Windows Defender scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2021-08-20 19:16:56.084
Description:
Windows Defender scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2021-08-20 16:38:23.054
Description:
Windows Defender scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2021-08-20 13:05:07.804
Description:
Windows Defender scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Event[0]:
Date: 2021-08-27 23:14:42.965
Description:
Windows Defender has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.347.319.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.18400.5
Error code: 0x80070422
Error description: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
Date: 2021-08-27 16:29:23.054
Description:
Windows Defender has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.347.319.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.18400.5
Error code: 0x80070422
Error description: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
Date: 2021-08-26 16:27:17.888
Description:
Windows Defender has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.347.319.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.18400.5
Error code: 0x80070422
Error description: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
Date: 2021-08-26 02:42:20.250
Description:
Windows Defender has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.347.319.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.18400.5
Error code: 0x80070422
Error description: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
Date: 2021-08-24 16:29:34.458
Description:
Windows Defender has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.345.741.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.18400.4
Error code: 0x80070422
Error description: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
==================== Memory info ===========================
BIOS: Hewlett-Packard 68PCU Ver. F.20 12/08/2011
Motherboard: Hewlett-Packard 30DB
Processor: Intel(R) Core(TM)2 Duo CPU P8600 @ 2.40GHz
Percentage of memory in use: 64%
Total physical RAM: 3000.26 MB
Available physical RAM: 1051.28 MB
Total Virtual: 7096.26 MB
Available Virtual: 4545.51 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:100.1 GB) (Free:64.9 GB) NTFS
Drive e: () (Fixed) (Total:365.12 GB) (Free:292.12 GB) NTFS
\\?\Volume{e2e85733-c85e-11eb-8250-806e6f6e6963}\ (Резервирана за системата) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS
\\?\Volume{e2e85736-c85e-11eb-8250-806e6f6e6963}\ () (Fixed) (Total:0.44 GB) (Free:0.16 GB) NTFS
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 0FD73A73)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=100.1 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=365.1 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=450 MB) - (Type=27)
==================== End of Addition.txt =======================