Премини към съдържанието
15 години Kaldata.com – време е да почерпим! Прочети още... ×

viktor123

Потребител
  • Публикации

    19
  • Регистрация

  • Последно онлайн

Харесвания

7 Неутрална репутация

Всичко за viktor123

  • Титла
    Потребител
  1. viktor123

    Проверка за вируси...

    Да! Благодаря за отделеното време и оказаното съдействие
  2. viktor123

    Проверка за вируси...

    Сега се прибирам и видях поста Ви. Рестартирах и всичко е ок
  3. viktor123

    Проверка за вируси...

    Готово... Ъъъъ , малко прибързано.... След ползване на Делфикс елементите които останаха тръгнах да ги трия ръчно и се получи това на шота Изглежда релийзът на моята ОС не е много читав. Отивам пак в Сейв Мод да чистя с Хънтъра. Иначе май поприключихме
  4. viktor123

    Проверка за вируси...

    Ееееее най-после стана. Жалко, че не се сетих по-рано да пробвам в Safe Modе . Сигурно Аваста е блокирал и другите инструменти които пробвах.
  5. viktor123

    Проверка за вируси...

    Спрях Крипто Превент и щитовете на АВАСТ, но не става и не става.Макар и със спрени щитове антивируса явно не се дава, като гледам това което показва долу вдясно при опит за старт на Хънтъра.
  6. viktor123

    Проверка за вируси...

    АВАСТ това го блокира... заради "самозащита" както ми пише. Спрях всички щитове на АВАСТ но пак го реже, а не виждам от къде да спра временно цялата антивирусна. Не видях такава опция. Програмката не може да си зареди драйвера и не става нищо. П.П. Не знам защо ПС Хънтър ми показва два реда с този проблемен запис, като единият ред дори го е дал в червено? Да не би нещо и Крипто превент да прецаква някои от ползваните инструменти?
  7. viktor123

    Проверка за вируси...

    " Елементът не може да бъде намерен " Не става... Ще го преживея
  8. viktor123

    Проверка за вируси...

    - EventData Checking file system on C: The type of the file system is NTFS. A disk check has been scheduled. Windows will now check the disk. CHKDSK is verifying files (stage 1 of 5)... 177408 file records processed. File verification completed. 918 large file records processed. 0 bad file records processed. 2 EA records processed. 30 reparse records processed. CHKDSK is verifying indexes (stage 2 of 5)... 239584 index entries processed. Index verification completed. 0 unindexed files scanned. 0 unindexed files recovered. CHKDSK is verifying security descriptors (stage 3 of 5)... 177408 file SDs/SIDs processed. Cleaning up 1291 unused index entries from index $SII of file 0x9. Cleaning up 1291 unused index entries from index $SDH of file 0x9. Cleaning up 1291 unused security descriptors. Security descriptor verification completed. 31089 data files processed. CHKDSK is verifying Usn Journal... 33985176 USN bytes processed. Usn Journal verification completed. CHKDSK is verifying file data (stage 4 of 5)... 177392 files processed. File data verification completed. CHKDSK is verifying free space (stage 5 of 5)... 5460010 free clusters processed. Free space verification is complete. CHKDSK discovered free space marked as allocated in the master file table (MFT) bitmap. CHKDSK discovered free space marked as allocated in the volume bitmap. Windows has made corrections to the file system. 102296575 KB total disk space. 80091052 KB in 124436 files. 83576 KB in 31090 indexes. 0 KB in bad sectors. 281903 KB in use by the system. 65536 KB occupied by the log file. 21840044 KB available on disk. 4096 bytes in each allocation unit. 25574143 total allocation units on disk. 5460011 allocation units available on disk. Internal Info: 00 b5 02 00 91 5f 02 00 06 98 04 00 00 00 00 00 ....._.......... 65 05 00 00 1e 00 00 00 00 00 00 00 00 00 00 00 e............... 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ Windows has finished checking your disk. Please wait while your computer restarts.
  9. viktor123

    Проверка за вируси...

    Това нещо е безсмъртно...
  10. viktor123

    Проверка за вируси...

    Дава същата грешка която съм показал горе на скриншота...
  11. viktor123

    Проверка за вируси...

    Аз ли нещо обърках, но не се получава...
  12. viktor123

    Проверка за вируси...

    Не само си стои, но и при опит да го махна пак ми дава същото като това което съм показал горе В краен случай ще си остане така и това е...
  13. viktor123

    Проверка за вируси...

    Fix result of Farbar Recovery Scan Tool (x64) Version: 20-08-2017 Ran by Милен (25-08-2017 22:06:04) Run:2 Running from C:\Users\Милен\Desktop Loaded Profiles: Милен (Available Profiles: Милен) Boot Mode: Normal ============================================== fixlist content: ***************** start cmd: ipconfig /flushdns C:\Users\�����\Desktop\Paul McCartney-(I Want To) Come Home - iz filma 2017-08-19 21:29 - 2017-08-19 21:38 - 011584088 _____ (SurfRight B.V.) C:\Users\�����\AppData\Local\Temp\HitmanPro_x64.exe C:\AdwCleaner 2017-08-19 21:46 - 2017-08-19 21:46 - 000000000 ____D C:\ProgramData\Emsisoft 2017-08-19 21:43 - 2017-08-19 23:20 - 000000000 ____D C:\EEK 2017-08-19 21:37 - 2017-08-19 21:37 - 011599120 _____ (SurfRight B.V.) C:\Users\�����\Desktop\HitmanPro_x64.exe 2017-08-19 21:36 - 2017-08-19 21:36 - 352185744 _____ C:\Users\�����\Desktop\EmsisoftEmergencyKit.exe 2017-08-19 21:28 - 2017-08-19 21:28 - 000000000 ____D C:\ProgramData\HitmanPro 2017-08-19 23:27 - 2017-08-19 23:27 - 000000687 _____ C:\Users\�����\Desktop\JRT.txt 2017-08-19 23:26 - 2017-08-19 23:26 - 001790024 _____ (Malwarebytes) C:\Users\�����\Desktop\JRT.exe emptytemp: end ***************** ========= ipconfig /flushdns ========= Windows IP Configuration Successfully flushed the DNS Resolver Cache. ========= End of CMD: ========= "C:\Users\Милен\Desktop\Paul McCartney-(I Want To) Come Home - iz filma" => not found. C:\Users\Милен\AppData\Local\Temp\HitmanPro_x64.exe => moved successfully C:\AdwCleaner => moved successfully C:\ProgramData\Emsisoft => moved successfully C:\EEK => moved successfully C:\Users\Милен\Desktop\HitmanPro_x64.exe => moved successfully C:\Users\Милен\Desktop\EmsisoftEmergencyKit.exe => moved successfully C:\ProgramData\HitmanPro => moved successfully C:\Users\Милен\Desktop\JRT.txt => moved successfully C:\Users\Милен\Desktop\JRT.exe => moved successfully =========== EmptyTemp: ========== BITS transfer queue => 0 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 14048978 B Java, Flash, Steam htmlcache => 4118 B Windows/system/drivers => 0 B Edge => 0 B Chrome => 0 B Firefox => 377576963 B Opera => 0 B Temp, IE cache, history, cookies, recent: Users => 0 B Default => 0 B Public => 0 B ProgramData => 0 B systemprofile => 0 B systemprofile32 => 0 B LocalService => 0 B NetworkService => 0 B Милен => 15033208 B RecycleBin => 23175482 B EmptyTemp: => 409.9 MB temporary data Removed. ================================ The system needed a reboot. ==== End of Fixlog 22:06:09 ====
  14. viktor123

    Проверка за вируси...

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20-08-2017 Ran by Милен (administrator) on МИЛЕН-PC (24-08-2017 22:16:32) Running from C:\Users\Милен\Desktop Loaded Profiles: Милен (Available Profiles: Милен) Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Български (България) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe () C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (Copyright 2017.) C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe (StarWind Software) C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Copyright 2017.) C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe (AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Farbar) C:\Users\Милен\Desktop\FRST64(1).exe (Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ==================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13671792 2014-03-14] (Realtek Semiconductor) HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [213832 2017-07-18] (AVAST Software) HKLM\...\Run: [ZAM] => C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [15775888 2017-08-09] (Copyright 2017.) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2014-02-21] (Intel Corporation) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-07-12] (Oracle Corporation) HKLM-x32\...\Run: [Malwarebytes Anti-Exploit] => C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe [2480584 2017-07-18] (Malwarebytes Corporation) HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.pif <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\*.js <==== ATTENTION HKLM Group Policy restriction on software: *.docx*.pif <==== ATTENTION HKLM Group Policy restriction on software: %allusersprofile%\*.jse <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\7z*\*.bat <==== ATTENTION HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.scr <==== ATTENTION HKLM Group Policy restriction on software: *.divx*.js <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.js <==== ATTENTION HKLM Group Policy restriction on software: *.xlsx*.bat <==== ATTENTION HKLM Group Policy restriction on software: %allusersprofile%\*.pif <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.js <==== ATTENTION HKLM Group Policy restriction on software: *.wav*.js <==== ATTENTION HKLM Group Policy restriction on software: scsvserv.exe <==== ATTENTION HKLM Group Policy restriction on software: %appdata%\*.cmd <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\*.jse <==== ATTENTION HKLM Group Policy restriction on software: %programdata%\*.cmd <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*\*.js <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.pif <==== ATTENTION HKLM Group Policy restriction on software: *.jpg*.jse <==== ATTENTION HKLM Group Policy restriction on software: C:\Users\*.jse <==== ATTENTION HKLM Group Policy restriction on software: *.ppt*.exe <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.bat <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\rar*\*.exe <==== ATTENTION HKLM Group Policy restriction on software: *.txt*.exe <==== ATTENTION HKLM Group Policy restriction on software: *.jpeg*.pif <==== ATTENTION HKLM Group Policy restriction on software: *.mp4*.exe <==== ATTENTION HKLM Group Policy restriction on software: *.divx*.cmd <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.jse <==== ATTENTION HKLM Group Policy restriction on software: *.pub*.com <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\7z*\*.jse <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\7z*\*.exe <==== ATTENTION HKLM Group Policy restriction on software: *.gif*.com <==== ATTENTION HKLM Group Policy restriction on software: *.mp3*.jse <==== ATTENTION HKLM Group Policy restriction on software: *.rtf*.bat <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.bat <==== ATTENTION HKLM Group Policy restriction on software: %allusersprofile%\*.cmd <==== ATTENTION HKLM Group Policy restriction on software: *.doc*.cmd <==== ATTENTION HKLM Group Policy restriction on software: *.doc*.jse <==== ATTENTION HKLM Group Policy restriction on software: *.png*.jse <==== ATTENTION HKLM Group Policy restriction on software: *.divx*.pif <==== ATTENTION HKLM Group Policy restriction on software: *.pdf*.com <==== ATTENTION HKLM Group Policy restriction on software: *.avi*.bat <==== ATTENTION HKLM Group Policy restriction on software: %appdata%\*\*.bat <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\wz*\*.bat <==== ATTENTION HKLM Group Policy restriction on software: *.gif*.js <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\*.exe <==== ATTENTION HKLM Group Policy restriction on software: *.jpeg*.jse <==== ATTENTION HKLM Group Policy restriction on software: *.xls*.cmd <==== ATTENTION HKLM Group Policy restriction on software: *.txt*.scr <==== ATTENTION HKLM Group Policy restriction on software: *.png*.scr <==== ATTENTION HKLM Group Policy restriction on software: *.wav*.com <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.jse <==== ATTENTION HKLM Group Policy restriction on software: *.divx*.bat <==== ATTENTION HKLM Group Policy restriction on software: lsassw86s.exe <==== ATTENTION HKLM Group Policy restriction on software: *.wav*.exe <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\*.bat <==== ATTENTION HKLM Group Policy restriction on software: *.bmp*.pif <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.com <==== ATTENTION HKLM Group Policy restriction on software: %programdata%\*.bat <==== ATTENTION HKLM Group Policy restriction on software: *.jpg*.pif <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*\*.scr <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.jse <==== ATTENTION HKLM Group Policy restriction on software: *.rtf*.com <==== ATTENTION HKLM Group Policy restriction on software: *.png*.com <==== ATTENTION HKLM Group Policy restriction on software: *.wav*.bat <==== ATTENTION HKLM Group Policy restriction on software: *.pdf*.cmd <==== ATTENTION HKLM Group Policy restriction on software: *.png*.pif <==== ATTENTION HKLM Group Policy restriction on software: *.zip*.pif <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*\*.com <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\*.zip\*.js <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\*.pif <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.exe <==== ATTENTION HKLM Group Policy restriction on software: *.doc*.js <==== ATTENTION HKLM Group Policy restriction on software: *.zip*.cmd <==== ATTENTION HKLM Group Policy restriction on software: *.pptx*.scr <==== ATTENTION HKLM Group Policy restriction on software: *.jpg*.js <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\*.zip\*.cmd <==== ATTENTION HKLM Group Policy restriction on software: *.pub*.jse <==== ATTENTION HKLM Group Policy restriction on software: *.divx*.exe <==== ATTENTION HKLM Group Policy restriction on software: *.zip*.js <==== ATTENTION HKLM Group Policy restriction on software: *.rar*.scr <==== ATTENTION HKLM Group Policy restriction on software: *.xlsx*.scr <==== ATTENTION HKLM Group Policy restriction on software: *.wmv*.scr <==== ATTENTION HKLM Group Policy restriction on software: *.xls*.bat <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.exe <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\*.zip\*.bat <==== ATTENTION HKLM Group Policy restriction on software: *.wmv*.pif <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.exe <==== ATTENTION HKLM Group Policy restriction on software: *.wav*.pif <==== ATTENTION HKLM Group Policy restriction on software: *.xls*.scr <==== ATTENTION HKLM Group Policy restriction on software: *.pdf*.js <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\*.exe <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\*.zip\*.pif <==== ATTENTION HKLM Group Policy restriction on software: *.wav*.cmd <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*\*.jse <==== ATTENTION HKLM Group Policy restriction on software: *.jpeg*.bat <==== ATTENTION HKLM Group Policy restriction on software: *.xlsx*.com <==== ATTENTION HKLM Group Policy restriction on software: *.wmv*.cmd <==== ATTENTION HKLM Group Policy restriction on software: *.rtf*.cmd <==== ATTENTION HKLM Group Policy restriction on software: *.xls*.exe <==== ATTENTION HKLM Group Policy restriction on software: *.rar*.js <==== ATTENTION HKLM Group Policy restriction on software: *.gif*.cmd <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\*.com <==== ATTENTION HKLM Group Policy restriction on software: *.docx*.com <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*\*.pif <==== ATTENTION HKLM Group Policy restriction on software: %appdata%\*.scr <==== ATTENTION HKLM Group Policy restriction on software: *.doc*.bat <==== ATTENTION HKLM Group Policy restriction on software: *.pdf*.jse <==== ATTENTION HKLM Group Policy restriction on software: *.mp3*.js <==== ATTENTION HKLM Group Policy restriction on software: *.mp4*.cmd <==== ATTENTION HKLM Group Policy restriction on software: *.xlsx*.js <==== ATTENTION HKLM Group Policy restriction on software: %allusersprofile%\*.com <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.cmd <==== ATTENTION HKLM Group Policy restriction on software: *.ppt*.com <==== ATTENTION HKLM Group Policy restriction on software: cipher.exe <==== ATTENTION HKLM Group Policy restriction on software: C:\Users\*.cmd <==== ATTENTION HKLM Group Policy restriction on software: *.rtf*.pif <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\rar*\*.jse <==== ATTENTION HKLM Group Policy restriction on software: %appdata%\*.com <==== ATTENTION HKLM Group Policy restriction on software: *.mp3*.exe <==== ATTENTION HKLM Group Policy restriction on software: *.avi*.com <==== ATTENTION HKLM Group Policy restriction on software: *.rar*.cmd <==== ATTENTION HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.cmd <==== ATTENTION HKLM Group Policy restriction on software: *.gif*.bat <==== ATTENTION HKLM Group Policy restriction on software: *.mp3*.bat <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\7z*\*.com <==== ATTENTION HKLM Group Policy restriction on software: *.mp4*.js <==== ATTENTION HKLM Group Policy restriction on software: *.mp4*.pif <==== ATTENTION HKLM Group Policy restriction on software: *.avi*.exe <==== ATTENTION HKLM Group Policy restriction on software: *.wmv*.com <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\rar*\*.js <==== ATTENTION HKLM Group Policy restriction on software: C:\Users\*.pif <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.bat <==== ATTENTION HKLM Group Policy restriction on software: %programfiles%\*\svchost.exe <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.jse <==== ATTENTION HKLM Group Policy restriction on software: *.png*.js <==== ATTENTION HKLM Group Policy restriction on software: *.jpg*.com <==== ATTENTION HKLM Group Policy restriction on software: *.docx*.bat <==== ATTENTION HKLM Group Policy restriction on software: *.pub*.cmd <==== ATTENTION HKLM Group Policy restriction on software: *.docx*.cmd <==== ATTENTION HKLM Group Policy restriction on software: *.avi*.js <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.js <==== ATTENTION HKLM Group Policy restriction on software: *.rar*.bat <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*\*.exe <==== ATTENTION HKLM Group Policy restriction on software: *.avi*.scr <==== ATTENTION HKLM Group Policy restriction on software: %appdata%\*\*.js <==== ATTENTION HKLM Group Policy restriction on software: %appdata%\*\*.cmd <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\wz*\*.jse <==== ATTENTION HKLM Group Policy restriction on software: *.txt*.pif <==== ATTENTION HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.bat <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\*.pif <==== ATTENTION HKLM Group Policy restriction on software: %allusersprofile%\*.scr <==== ATTENTION HKLM Group Policy restriction on software: *.bmp*.exe <==== ATTENTION HKLM Group Policy restriction on software: *.docx*.scr <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\7z*\*.cmd <==== ATTENTION HKLM Group Policy restriction on software: *.wma*.jse <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.scr <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.com <==== ATTENTION HKLM Group Policy restriction on software: *.doc*.scr <==== ATTENTION HKLM Group Policy restriction on software: *.pptx*.pif <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\rar*\*.com <==== ATTENTION HKLM Group Policy restriction on software: bcdedit.exe <==== ATTENTION HKLM Group Policy restriction on software: ** <==== ATTENTION HKLM Group Policy restriction on software: *.7z*.pif <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.jse <==== ATTENTION HKLM Group Policy restriction on software: *:\$Recycle.Bin <==== ATTENTION HKLM Group Policy restriction on software: *.xlsx*.exe <==== ATTENTION HKLM Group Policy restriction on software: *.png*.cmd <==== ATTENTION HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.exe <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\*.zip\*.jse <==== ATTENTION HKLM Group Policy restriction on software: *.gif*.pif <==== ATTENTION HKLM Group Policy restriction on software: *.txt*.bat <==== ATTENTION HKLM Group Policy restriction on software: *.gif*.scr <==== ATTENTION HKLM Group Policy restriction on software: *.rtf*.jse <==== ATTENTION HKLM Group Policy restriction on software: *.wav*.jse <==== ATTENTION HKLM Group Policy restriction on software: *.pub*.exe <==== ATTENTION HKLM Group Policy restriction on software: syskey.exe <==== ATTENTION HKLM Group Policy restriction on software: C:\Users\*.bat <==== ATTENTION HKLM Group Policy restriction on software: *.pub*.scr <==== ATTENTION HKLM Group Policy restriction on software: *.doc*.com <==== ATTENTION HKLM Group Policy restriction on software: *.jpeg*.exe <==== ATTENTION HKLM Group Policy restriction on software: C:\Users\*.exe <==== ATTENTION HKLM Group Policy restriction on software: *.wmv*.js <==== ATTENTION HKLM Group Policy restriction on software: *.wma*.bat <==== ATTENTION HKLM Group Policy restriction on software: %systemdrive%\*\svchost.exe <==== ATTENTION HKLM Group Policy restriction on software: %appdata%\*\*.exe <==== ATTENTION HKLM Group Policy restriction on software: *.gif*.exe <==== ATTENTION HKLM Group Policy restriction on software: *.xls*.jse <==== ATTENTION HKLM Group Policy restriction on software: *.xlsx*.jse <==== ATTENTION HKLM Group Policy restriction on software: *.pdf*.scr <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\7z*\*.js <==== ATTENTION HKLM Group Policy restriction on software: *.png*.exe <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\7z*\*.pif <==== ATTENTION HKLM Group Policy restriction on software: *.bmp*.scr <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.com <==== ATTENTION HKLM Group Policy restriction on software: *.rar*.jse <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\*.com <==== ATTENTION HKLM Group Policy restriction on software: *.ppt*.bat <==== ATTENTION HKLM Group Policy restriction on software: *.txt*.com <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\*.cmd <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\rar*\*.cmd <==== ATTENTION HKLM Group Policy restriction on software: *.mp4*.jse <==== ATTENTION HKLM Group Policy restriction on software: *.gif*.jse <==== ATTENTION HKLM Group Policy restriction on software: %appdata%\*.pif <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.cmd <==== ATTENTION HKLM Group Policy restriction on software: *.bmp*.js <==== ATTENTION HKLM Group Policy restriction on software: *.png*.bat <==== ATTENTION HKLM Group Policy restriction on software: *.pptx*.cmd <==== ATTENTION HKLM Group Policy restriction on software: *.avi*.jse <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\Appdata\Roaming\Microsoft\Windows\IEUpdate\*.exe <==== ATTENTION HKLM Group Policy restriction on software: *.7z*.cmd <==== ATTENTION HKLM Group Policy restriction on software: *.rar*.pif <==== ATTENTION HKLM Group Policy restriction on software: vssadmin.exe <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.cmd <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\*.scr <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\*.bat <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.pif <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.cmd <==== ATTENTION HKLM Group Policy restriction on software: *.pptx*.js <==== ATTENTION HKLM Group Policy restriction on software: %allusersprofile%\*.exe <==== ATTENTION HKLM Group Policy restriction on software: *.jpeg*.js <==== ATTENTION HKLM Group Policy restriction on software: *.bmp*.bat <==== ATTENTION HKLM Group Policy restriction on software: *.bmp*.com <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.js <==== ATTENTION HKLM Group Policy restriction on software: %programdata%\*.com <==== ATTENTION HKLM Group Policy restriction on software: %programfiles(x86)%\*\svchost.exe <==== ATTENTION HKLM Group Policy restriction on software: *.jpeg*.com <==== ATTENTION HKLM Group Policy restriction on software: *.divx*.scr <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\*.zip\*.scr <==== ATTENTION HKLM Group Policy restriction on software: *.pdf*.exe <==== ATTENTION HKLM Group Policy restriction on software: *.wma*.exe <==== ATTENTION HKLM Group Policy restriction on software: *.7z*.js <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.scr <==== ATTENTION HKLM Group Policy restriction on software: *.jpg*.bat <==== ATTENTION HKLM Group Policy restriction on software: *.docx*.js <==== ATTENTION HKLM Group Policy restriction on software: *.pdf*.bat <==== ATTENTION HKLM Group Policy restriction on software: %programdata%\*\svchost.exe <==== ATTENTION HKLM Group Policy restriction on software: %appdata%\*.js <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*\*.cmd <==== ATTENTION HKLM Group Policy restriction on software: %programdata%\*.pif <==== ATTENTION HKLM Group Policy restriction on software: *.mp3*.scr <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.bat <==== ATTENTION HKLM Group Policy restriction on software: *.rtf*.exe <==== ATTENTION HKLM Group Policy restriction on software: *.docx*.jse <==== ATTENTION HKLM Group Policy restriction on software: *.xls*.pif <==== ATTENTION HKLM Group Policy restriction on software: C:\Users\*.js <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\*.cmd <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\7z*\*.scr <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.scr <==== ATTENTION HKLM Group Policy restriction on software: *.rar*.com <==== ATTENTION HKLM Group Policy restriction on software: *.pdf*.pif <==== ATTENTION HKLM Group Policy restriction on software: *.avi*.cmd <==== ATTENTION HKLM Group Policy restriction on software: *.pub*.js <==== ATTENTION HKLM Group Policy restriction on software: *.mp3*.com <==== ATTENTION HKLM Group Policy restriction on software: *.ppt*.jse <==== ATTENTION HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.jse <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.bat <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.cmd <==== ATTENTION HKLM Group Policy restriction on software: *.txt*.jse <==== ATTENTION HKLM Group Policy restriction on software: *.wmv*.jse <==== ATTENTION HKLM Group Policy restriction on software: *.pptx*.jse <==== ATTENTION HKLM Group Policy restriction on software: *.7z*.exe <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\*.js <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.exe <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*\*.bat <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\rar*\*.bat <==== ATTENTION HKLM Group Policy restriction on software: %allusersprofile%\*.bat <==== ATTENTION HKLM Group Policy restriction on software: *.ppt*.js <==== ATTENTION HKLM Group Policy restriction on software: %allusersprofile%\*.js <==== ATTENTION HKLM Group Policy restriction on software: *.divx*.com <==== ATTENTION HKLM Group Policy restriction on software: *.zip*.scr <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.exe <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\rar*\*.scr <==== ATTENTION HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.com <==== ATTENTION HKLM Group Policy restriction on software: *.pptx*.bat <==== ATTENTION HKLM Group Policy restriction on software: *.pub*.bat <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.scr <==== ATTENTION HKLM Group Policy restriction on software: *.ppt*.pif <==== ATTENTION HKLM Group Policy restriction on software: *.divx*.jse <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.scr <==== ATTENTION HKLM Group Policy restriction on software: *.doc*.exe <==== ATTENTION HKLM Group Policy restriction on software: C:\Users\*.scr <==== ATTENTION HKLM Group Policy restriction on software: *.7z*.com <==== ATTENTION HKLM Group Policy restriction on software: *.wma*.pif <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.pif <==== ATTENTION HKLM Group Policy restriction on software: *.wmv*.bat <==== ATTENTION HKLM Group Policy restriction on software: *.7z*.bat <==== ATTENTION HKLM Group Policy restriction on software: *.mp4*.com <==== ATTENTION HKLM Group Policy restriction on software: *.xls*.com <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.bat <==== ATTENTION HKLM Group Policy restriction on software: *.pptx*.exe <==== ATTENTION HKLM Group Policy restriction on software: *.mp4*.scr <==== ATTENTION HKLM Group Policy restriction on software: %appdata%\*\*.pif <==== ATTENTION HKLM Group Policy restriction on software: *.wma*.scr <==== ATTENTION HKLM Group Policy restriction on software: *.jpg*.exe <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.com <==== ATTENTION HKLM Group Policy restriction on software: %appdata%\*.jse <==== ATTENTION HKLM Group Policy restriction on software: *.xls*.js <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\*.com <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.pif <==== ATTENTION HKLM Group Policy restriction on software: *.bmp*.jse <==== ATTENTION HKLM Group Policy restriction on software: %appdata%\*.exe <==== ATTENTION HKLM Group Policy restriction on software: *.zip*.jse <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\rar*\*.pif <==== ATTENTION HKLM Group Policy restriction on software: *.jpeg*.scr <==== ATTENTION HKLM Group Policy restriction on software: %appdata%\*\*.jse <==== ATTENTION HKLM Group Policy restriction on software: *.pub*.pif <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.pif <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\*.jse <==== ATTENTION HKLM Group Policy restriction on software: *.rtf*.scr <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.jse <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\wz*\*.exe <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.js <==== ATTENTION HKLM Group Policy restriction on software: *.ppt*.scr <==== ATTENTION HKLM Group Policy restriction on software: *.ppt*.cmd <==== ATTENTION HKLM Group Policy restriction on software: *.pptx*.com <==== ATTENTION HKLM Group Policy restriction on software: *.zip*.bat <==== ATTENTION HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.js <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\*.bat <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\wz*\*.cmd <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.com <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\*.zip\*.com <==== ATTENTION HKLM Group Policy restriction on software: *.wma*.com <==== ATTENTION HKLM Group Policy restriction on software: *.7z*.jse <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.js <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\*.exe <==== ATTENTION HKLM Group Policy restriction on software: *.xlsx*.pif <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\wz*\*.scr <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.scr <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.exe <==== ATTENTION HKLM Group Policy restriction on software: %programdata%\*.js <==== ATTENTION HKLM Group Policy restriction on software: *.jpg*.cmd <==== ATTENTION HKLM Group Policy restriction on software: *.zip*.com <==== ATTENTION HKLM Group Policy restriction on software: %appdata%\*\*.com <==== ATTENTION HKLM Group Policy restriction on software: *.bmp*.cmd <==== ATTENTION HKLM Group Policy restriction on software: %programdata%\*.scr <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\*.cmd <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\wz*\*.js <==== ATTENTION HKLM Group Policy restriction on software: *.wmv*.exe <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\*.js <==== ATTENTION HKLM Group Policy restriction on software: *.wma*.cmd <==== ATTENTION HKLM Group Policy restriction on software: *.rar*.exe <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\wz*\*.com <==== ATTENTION HKLM Group Policy restriction on software: %programdata%\*.exe <==== ATTENTION HKLM Group Policy restriction on software: *.docx*.exe <==== ATTENTION HKLM Group Policy restriction on software: %appdata%\*\*.scr <==== ATTENTION HKLM Group Policy restriction on software: *.jpeg*.cmd <==== ATTENTION HKLM Group Policy restriction on software: *.wma*.js <==== ATTENTION HKLM Group Policy restriction on software: *.doc*.pif <==== ATTENTION HKLM Group Policy restriction on software: *.avi*.pif <==== ATTENTION HKLM Group Policy restriction on software: %appdata%\*.bat <==== ATTENTION HKLM Group Policy restriction on software: *.mp3*.cmd <==== ATTENTION HKLM Group Policy restriction on software: *.mp3*.pif <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.com <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.cmd <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\*.pif <==== ATTENTION HKLM Group Policy restriction on software: *.xlsx*.cmd <==== ATTENTION HKLM Group Policy restriction on software: lsassvrtdbks.exe <==== ATTENTION HKLM Group Policy restriction on software: *.txt*.js <==== ATTENTION HKLM Group Policy restriction on software: *.txt*.cmd <==== ATTENTION HKLM Group Policy restriction on software: *.zip*.exe <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\*.scr <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.pif <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\*.zip\*.exe <==== ATTENTION HKLM Group Policy restriction on software: *.7z*.scr <==== ATTENTION HKLM Group Policy restriction on software: *.wav*.scr <==== ATTENTION HKLM Group Policy restriction on software: %programdata%\*.jse <==== ATTENTION HKLM Group Policy restriction on software: *.jpg*.scr <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\*.scr <==== ATTENTION HKLM Group Policy restriction on software: *.mp4*.bat <==== ATTENTION HKLM Group Policy restriction on software: *.rtf*.js <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\wz*\*.pif <==== ATTENTION HKLM Group Policy restriction on software: %userprofile%\AppData\Local\Temp\*.jse <==== ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION HKU\S-1-5-21-4240577764-2134474633-1759713092-1000\...\Run: [AlcoholAutomount] => C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team) HKU\S-1-5-21-4240577764-2134474633-1759713092-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9288408 2016-12-06] (Piriform Ltd) HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2014-12-22] (Microsoft Corporation) HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE -> ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 172.16.1.1 Tcpip\..\Interfaces\{494BD764-1142-476E-A28D-76261643AE57}: [DhcpNameServer] 172.16.1.1 Internet Explorer: ================== BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-06-30] (AVAST Software) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_141\bin\ssv.dll [2017-07-24] (Oracle Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-06-30] (AVAST Software) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_141\bin\jp2ssv.dll [2017-07-24] (Oracle Corporation) FireFox: ======== FF DefaultProfile: tpkce43a.default FF ProfilePath: C:\Users\Милен\AppData\Roaming\Mozilla\Firefox\Profiles\tpkce43a.default [2017-08-24] FF Extension: (Avast SafePrice) - C:\Users\Милен\AppData\Roaming\Mozilla\Firefox\Profiles\tpkce43a.default\Extensions\sp@avast.com.xpi [2017-05-31] FF Extension: (Avast Online Security) - C:\Users\Милен\AppData\Roaming\Mozilla\Firefox\Profiles\tpkce43a.default\Extensions\wrc@avast.com.xpi [2017-08-18] FF Extension: (Adblock Plus) - C:\Users\Милен\AppData\Roaming\Mozilla\Firefox\Profiles\tpkce43a.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-06-07] FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_26_0_0_151.dll [2017-08-16] () FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_151.dll [2017-08-16] () FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-10-13] (Google, Inc.) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-16] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-16] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.141.2 -> C:\Program Files (x86)\Java\jre1.8.0_141\bin\dtplugin\npDeployJava1.dll [2017-07-24] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.141.2 -> C:\Program Files (x86)\Java\jre1.8.0_141\bin\plugin2\npjp2.dll [2017-07-24] (Oracle Corporation) FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-08-01] (Adobe Systems Inc.) Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx <not found> CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7430992 2017-07-18] (AVAST Software s.r.o.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [263312 2017-07-18] (AVAST Software) R2 HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [192200 2016-11-25] () [File not signed] R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [345864 2015-03-19] (Intel Corporation) R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation) R2 MbaeSvc; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe [155080 2017-07-18] (Malwarebytes Corporation) S3 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1570520 2016-02-02] (Secunia) R2 StarWindServiceAE; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-24] (StarWind Software) [File not signed] S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) R2 ZAMSvc; C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [15775888 2017-08-09] (Copyright 2017.) U4 AvastVBoxSvc; "C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe" [X] ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R1 aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [320008 2017-07-18] (AVAST Software s.r.o.) R0 aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [198976 2017-07-18] (AVAST Software s.r.o.) R0 aswblog; C:\Windows\system32\drivers\aswbloga.sys [343288 2017-07-18] (AVAST Software s.r.o.) R0 aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [57728 2017-07-18] (AVAST Software s.r.o.) S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [46984 2017-06-30] (AVAST Software) R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [41800 2017-06-30] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [146704 2017-08-09] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [110352 2017-06-30] (AVAST Software) R0 aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [84392 2017-06-30] (AVAST Software) R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1015880 2017-08-09] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [585608 2017-06-30] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [198768 2017-06-30] (AVAST Software) R0 aswVmm; C:\Windows\system32\drivers\aswVmm.sys [361336 2017-06-30] (AVAST Software) R1 ESProtectionDriver; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys [77432 2017-07-18] () U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2016-11-25] (Huawei Technologies Co., Ltd.) R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation) S3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2016-02-02] (Secunia) S4 secdrv; C:\Windows\SysWow64\Drivers\secdrv.sys [11376 2003-09-09] () [File not signed] R0 sptd; C:\Windows\System32\Drivers\sptd.sys [386680 2015-01-13] (Duplex Secure Ltd.) R3 XtuAcpiDriver; C:\Windows\System32\DRIVERS\XtuAcpiDriver.sys [54344 2016-11-22] (Intel Corporation) R1 ZAM; C:\Windows\System32\drivers\zam64.sys [203680 2017-08-16] (Zemana Ltd.) R1 ZAM_Guard; C:\Windows\System32\drivers\zamguard64.sys [203680 2017-08-16] (Zemana Ltd.) U3 ahjxyl47; C:\Windows\System32\Drivers\ahjxyl47.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero byte File/Folder) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) Error(1) reading file: "C:\Users\Милен\Desktop\Paul McCartney-(I Want To) Come Home - iz filma " 2017-08-24 22:16 - 2017-08-24 22:17 - 000042949 _____ C:\Users\Милен\Desktop\FRST.txt 2017-08-24 22:15 - 2017-08-24 22:15 - 002395648 _____ (Farbar) C:\Users\Милен\Desktop\FRST64(1).exe 2017-08-24 22:12 - 2017-08-24 22:13 - 000000000 ____D C:\Users\Милен\Desktop\FRST 2017-08-22 23:03 - 2017-08-22 23:04 - 000000000 ____D C:\Users\Милен\Desktop\D.Nar.Pr. MP3 2017-08-22 12:19 - 2017-08-22 12:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware 2017-08-20 13:50 - 2017-08-20 14:01 - 000000000 ____D C:\Users\Милен\Desktop\Нова папка 2017-08-20 13:49 - 2017-08-20 13:50 - 000288148 _____ C:\Users\Милен\Desktop\Logs_Милен_20.08_13.50.zip 2017-08-20 13:42 - 2017-08-20 13:42 - 004912350 _____ (Rapture Technology ) C:\Users\Милен\Desktop\Glyph.exe 2017-08-19 23:27 - 2017-08-19 23:27 - 000000687 _____ C:\Users\Милен\Desktop\JRT.txt 2017-08-19 23:26 - 2017-08-19 23:26 - 001790024 _____ (Malwarebytes) C:\Users\Милен\Desktop\JRT.exe 2017-08-19 23:21 - 2017-08-19 23:21 - 008185288 _____ (Malwarebytes) C:\Users\Милен\Desktop\adwcleaner_7.0.1.0.exe 2017-08-19 21:46 - 2017-08-19 21:46 - 000000000 ____D C:\ProgramData\Emsisoft 2017-08-19 21:43 - 2017-08-19 23:20 - 000000000 ____D C:\EEK 2017-08-19 21:37 - 2017-08-19 21:37 - 011599120 _____ (SurfRight B.V.) C:\Users\Милен\Desktop\HitmanPro_x64.exe 2017-08-19 21:36 - 2017-08-19 21:36 - 352185744 _____ C:\Users\Милен\Desktop\EmsisoftEmergencyKit.exe 2017-08-19 21:28 - 2017-08-19 21:28 - 000000000 ____D C:\ProgramData\HitmanPro 2017-08-19 21:21 - 2017-08-19 21:21 - 000000000 ____D C:\Users\Милен\Desktop\FRST-OlderVersion 2017-08-17 14:22 - 2017-08-19 21:21 - 002395648 _____ (Farbar) C:\Users\Милен\Desktop\FRST64.exe 2017-08-17 00:19 - 2017-08-17 00:19 - 000001079 _____ C:\Users\Милен\Desktop\AdwCleaner[S0].txt 2017-08-17 00:18 - 2017-08-17 00:18 - 000004082 _____ C:\Users\Милен\Desktop\2017.08.16-23.40.29-i0-t92-d7.txt 2017-08-17 00:09 - 2017-08-17 00:10 - 000000000 ____D C:\Users\Милен\Desktop\Mir 2017-08-17 00:03 - 2017-08-17 00:11 - 000000000 ____D C:\Users\Милен\Desktop\Sonq 2017-08-17 00:01 - 2017-08-17 00:09 - 000000000 ____D C:\Users\Милен\Desktop\Maq 2017-08-16 23:40 - 2017-08-24 22:16 - 000036921 _____ C:\Windows\ZAM.krnl.trace 2017-08-16 23:40 - 2017-08-24 22:16 - 000013020 _____ C:\Windows\ZAM_Guard.krnl.trace 2017-08-16 23:40 - 2017-08-22 12:19 - 000001076 _____ C:\Users\Public\Desktop\Zemana AntiMalware.lnk 2017-08-16 23:40 - 2017-08-22 12:19 - 000000000 ____D C:\Program Files (x86)\Zemana AntiMalware 2017-08-16 23:40 - 2017-08-16 23:40 - 000203680 _____ (Zemana Ltd.) C:\Windows\system32\Drivers\zamguard64.sys 2017-08-16 23:40 - 2017-08-16 23:40 - 000203680 _____ (Zemana Ltd.) C:\Windows\system32\Drivers\zam64.sys 2017-08-16 23:39 - 2017-08-16 23:39 - 006589840 _____ (Zemana Ltd. ) C:\Users\Милен\Desktop\Zemana.AntiMalware.Setup.exe 2017-08-16 23:39 - 2017-08-16 23:39 - 000000000 ____D C:\Users\Милен\AppData\Local\Zemana 2017-08-16 23:26 - 2017-08-19 23:23 - 000000000 ____D C:\AdwCleaner 2017-08-16 23:16 - 2017-08-16 23:18 - 000000000 ____D C:\PatchMyPCUpdates 2017-08-16 22:52 - 2017-08-16 22:52 - 000004324 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-08-24 22:16 - 2017-01-13 18:44 - 000000000 ____D C:\FRST 2017-08-24 22:14 - 2016-11-18 19:14 - 000000000 ____D C:\Users\Милен\AppData\LocalLow\Mozilla 2017-08-24 22:12 - 2014-12-21 13:24 - 000000000 __SHD C:\Users\Милен\IntelGraphicsProfiles 2017-08-24 22:12 - 2009-07-14 08:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2017-08-23 19:09 - 2009-07-14 07:45 - 000017136 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-08-23 19:09 - 2009-07-14 07:45 - 000017136 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-08-23 19:07 - 2009-07-14 08:13 - 000781790 _____ C:\Windows\system32\PerfStringBackup.INI 2017-08-23 19:07 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\inf 2017-08-20 13:49 - 2015-02-07 21:41 - 000000000 ____D C:\Windows\Minidump 2017-08-19 21:22 - 2015-01-03 00:34 - 000000000 ____D C:\Users\Милен\AppData\LocalLow\Temp 2017-08-18 11:28 - 2014-12-21 23:56 - 000192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2017-08-17 00:58 - 2015-08-22 18:07 - 000000000 ____D C:\ProgramData\Malwarebytes Anti-Exploit 2017-08-17 00:08 - 2016-12-15 17:07 - 000000000 ____D C:\Users\Милен\Desktop\Dokuments Milen i drugi 2017-08-16 23:41 - 2014-12-21 12:56 - 000000000 ____D C:\Users\Милен 2017-08-16 23:16 - 2015-08-13 16:12 - 000793376 _____ (Patch My PC, LLC) C:\Users\Милен\Desktop\PatchMyPC.exe 2017-08-16 22:52 - 2014-12-21 16:50 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2017-08-16 22:52 - 2014-12-21 16:50 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2017-08-16 22:52 - 2014-12-21 16:50 - 000000000 ____D C:\Windows\system32\Macromed 2017-08-16 22:51 - 2014-12-21 16:49 - 000000000 ____D C:\Windows\SysWOW64\Macromed 2017-08-15 18:49 - 2014-12-22 00:29 - 000000000 ____D C:\Users\Милен\AppData\Roaming\Skype 2017-08-12 06:57 - 2016-03-24 01:12 - 000003908 _____ C:\Windows\System32\Tasks\SafeZone scheduled Autoupdate 1458771178 2017-08-11 22:18 - 2015-07-15 22:54 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2017-08-10 17:03 - 2017-05-30 20:30 - 000000000 ____D C:\Users\Милен\AppData\Roaming\vlc 2017-08-09 20:18 - 2014-12-21 15:26 - 001015880 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys 2017-08-09 20:18 - 2014-12-21 15:26 - 000146704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswmonflt.sys 2017-08-08 21:02 - 2014-12-25 19:28 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2017-08-05 18:43 - 2014-12-22 00:29 - 000000000 ____D C:\ProgramData\Skype 2017-07-26 22:09 - 2015-08-22 18:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Exploit 2017-07-26 22:09 - 2015-08-22 18:07 - 000000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Exploit ==================== Files in the root of some directories ======= 2014-12-21 22:37 - 2014-12-21 22:37 - 000000017 _____ () C:\Users\Милен\AppData\Local\resmon.resmoncfg Some files in TEMP: ==================== 2017-08-19 21:29 - 2017-08-19 21:38 - 011584088 _____ (SurfRight B.V.) C:\Users\Милен\AppData\Local\Temp\HitmanPro_x64.exe ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed ATTENTION: ==> Could not access BCD. LastRegBack: 2017-08-21 09:49 ==================== End of FRST.txt ============================ --------------------- Addition.txt
  15. viktor123

    Проверка за вируси...

    Обикновен текстов документ с размер 0 . Преди ми даваше, че се ползва от друга програма и не мога да го трия. Сега вече това..
  • Разглеждащи в момента   0 потребители

    Няма регистрирани потребители разглеждащи тази страница.

×

Информация

Поставихме бисквитки на устройството ви за най-добро потребителско изживяване. Можете да промените настройките си за бисквитки, или в противен случай приемаме, че сте съгласни с нашите условия за ползване.