Премини към съдържанието

Филтри за търсене

Показани резултати за тагове 'приключен'.

  • Търсене по таг

    Въведете тагове разделени със запетая
  • Търсене по автор

Търсене в


Форуми

  • Софтуер
    • Нови Програми
    • Търсене на Програми
    • Програми - Проблеми и Дискусии
    • Драйвери - Търсене, Проблеми, Линкове
    • Операционни системи
    • Сигурност и антивирусна защита
    • Игри
  • Хардуер
    • Общи хардуерни въпроси
    • Преносими компютри
    • Дънни платки
    • Запаметяващи устройства и памети
    • Монитори, Аудио и Видеокарти
    • Периферия
    • Овърклок и PC модинг
    • Нови конфигурации и части, въпроси, препоръки и мнения
  • Мобилни телефони, GSM, Мобилни приложения, Комуникации
    • Мобилни телефони - Въпроси, Проблеми, Софтуер
    • Съвети при избор на телефон
    • Мобилни Приложения (Apps)
    • Мобилни оператори, Мрежи, Промоции, Абонаменти, Услуги
    • Други теми относно мобилни телефони
  • Уеб дизайн, Графичен дизайн, Програмиране
    • Програмиране
    • Графичен Дизайн и Визуални изкуства
    • CMS, Форумни и Торент системи
    • Хостинг, Домейни, Уеб сървъри
    • SEO, Уеб оптимизация и стандарти
  • Битова Техника
    • Аудиотехника
    • Телевизори, Видео и Фото техника, Видео наблюдение
    • Климатици - проблеми, съвети, въпроси
    • Бойлери, Печки, Отопление
    • Друга битова техника
  • Интернет, Локални Мрежи и GPS Навигации
    • Интернет, WiFi, xDSL и Локална Мрежа
    • Биткойн и Криптовалути
    • Онлайн бизнес, AdSense, Affilate програми
    • Рутери, Модеми, Суичове
    • Facebook - проблеми, въпроси, вируси
    • Skype, VoIP - Интернет телефония
    • GPS, Навигационни системи - Въпроси, Карти, Проблеми
  • Изкуство
    • Музика
    • Кино и Телевизия
    • Поезия и Лично творчество
    • Изкуство - Изящно, Приложно и Сценично
    • Фотография и Фотографска техника
    • Литература, Книги (e-books, video trainings, tutorials & etc.)
  • Други
    • Статии и ревюта
    • Образование и обща култура
    • Религия, Мистика, Езотерика
    • История
    • Философия
    • Психология и Психотерапия
    • Новини от България и Света
    • Българите по света
    • Политика
    • Право и Юридически консултации
    • Здраве и Mедицина
    • Банки, Застраховане, Финанси, Кредити
    • Тийн Зона (Teen Zone)
    • Купувам / Продавам
    • Всичко останало
  • Хоби, Развлечение и Свободно време
  • За kaldata.com
  • Теми
  • Photoshop майнаци Теми
  • python3 data types
  • какви са ви любимите игри?? Темиигри за вас
  • супрески игри и рекорди Темиигри за вас

Блогове

Няма резултати

Няма резултати

Категории

  • Компютри
    • Компютърни конфигурации
    • Компютърни компоненти
    • Периферни устройства
    • Дънни платки
    • Мултимедия
    • Компютърни игри и софтуер
    • Администриране и интернет услуги
    • Компютърни аксесоари
    • Лаптопи и таблети
    • Видеокарти
    • Монитори
    • Процесори
    • Хард дискове и Памети
    • Други
  • Електроника
    • Телефони, GSM апарати
    • Аудио
    • Битова електроника
    • GPS и навигационни системи
    • Фотоапарати и обективи
    • TV и Видео
    • Други
  • Имоти
    • Гарсониери
    • Къщи и вили
    • Търговски площи
    • Гаражи
    • Апартаменти
    • Терени
    • Офиси
    • Други имоти в продажба
  • Авто-мото
    • Автомобили
    • Велосипеди
    • Лодки
    • Резервни части
    • Авто аксесоари
    • Мотоциклети
    • Скутери и ATV
    • Камиони и Автобуси
    • Авто сервизи и Rent-a-Car
    • Други
  • Работа
    • Работа в страната
    • Работа в чужбина
    • Стажове
    • Работа от вкъщи
    • Непълно работно време
  • Услуги
  • Строителство
  • Туризъм
  • Курсове и обучение
  • Домашни любимци
  • Други
  • супрески игри и рекорди Обяви
  • супрески игри и рекорди Обяви

Категории

  • Домашни любимци и Животни
  • Игри
  • Инциденти и Екстремни
  • Коли и превозни средства
  • Музика
    • Българска музика
    • Джаз
    • Електронна
    • Метъл и Рок
    • Народна и Фолклор
    • Поп и Диско
    • Поп-фолк
    • Рап и хип-хоп
    • Ритъм енд блус и соул
    • Друга
  • Новини и политика
  • Реклами
  • Смях и Развлечение
  • Спорт
  • Технологии, Компютри, Хардуер
  • ТВ Предавания и Шоу Програми
  • Хора и блогове
  • Филми и анимация
  • Други
  • Old School Hip-Hop and Electroo 80" Видео клипчета

Календари

  • Събития
  • Изложения
  • Семинари
  • Парти
  • Празници в България

Групи продукти

  • Банер Реклами

Търсене в...

Търси резултати които съдържат...


Дата

  • Начало

    Край


Последно обновяване

  • Начало

    Край


Филтриране по брой...

Регистрация

  • Начало

    Край


Група


Skype


Facebook


Google+


Twitter


ICQ


Yahoo


Интернет сайт


Град


Интереси

Открити 321 резултата

  1. здравейте моля и в тази тема специалистите за помощ,проблемът е следният последно си спомням че имах няколко имейла от които единият отворих и на следващият ден при включване на компютъра таск менаджера показва 100% и непрекъснат сигнал след което се изключва сам, с много мъки успях да инсталирам Kaspersky и в момента е по добре,но все още ми товари много без да има основание предимно при гледане на клип в ютуб,качвам ви резултата от сканирането
  2. Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 29-03-2020 Ran by NightRider (administrator) on OUTPOST (01-04-2020 15:19:27) Running from C:\Users\NightRider\Desktop Loaded Profiles: NightRider (Available Profiles: NightRider) Platform: Windows 10 Pro Version 1909 18363.753 (X64) Language: Български (България) Default browser: FF Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 20.0\avp.exe (Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 20.0\avpui.exe (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Windows Firewall Control\wfc.exe (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Windows Firewall Control\wfcs.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12003.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\CredentialEnrollmentManager.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (MICRO-STAR INTERNATIONAL CO., LTD. -> ) C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d223212c0a2275b5\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d223212c0a2275b5\Display.NvContainer\NVDisplay.Container.exe (Valve -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve -> Valve Corporation) E:\Games\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) E:\Games\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) E:\Games\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) E:\Games\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) E:\Games\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) E:\Games\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) E:\Games\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) E:\Games\Steam\steam.exe (VoodooSoft, LLC -> VoodooSoft, LLC ) C:\Program Files\VoodooShield\VoodooShield.exe (VoodooSoft, LLC -> VoodooSoft, LLC ) C:\Program Files\VoodooShield\VoodooShieldService.exe ==================== Registry (Whitelisted) =================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Malwarebytes Windows Firewall Control] => C:\Program Files\Malwarebytes\Windows Firewall Control\wfc.exe [647856 2020-01-05] (Malwarebytes Inc -> Malwarebytes) HKU\S-1-5-21-1903147458-2263829336-249963103-1001\...\Run: [Steam] => E:\Games\Steam\steam.exe [3370272 2020-03-27] (Valve -> Valve Corporation) ==================== Scheduled Tasks (Whitelisted) ============ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {221E7CE6-5148-42C5-A220-9EF6F74E9A63} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe [739624 2018-04-23] (MICRO-STAR INTERNATIONAL CO., LTD. -> ) Task: {B4A41E61-B4EE-4894-B34F-69ED2CD1A78C} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [18233016 2020-02-28] (Piriform Software Ltd -> Piriform Software Ltd) Task: {B9473F12-BF68-46A8-ABB2-FCE28B5FCEC6} - System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} => C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe [791232 2020-01-03] (Kaspersky Lab -> AO Kaspersky Lab) Task: {DAE116B0-629E-4A4B-B509-24E39DF374CC} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [686384 2020-02-28] (Piriform Software Ltd -> Piriform Software Ltd) Task: {E2964865-E1B7-4E2C-B492-BC9EB0C98BEE} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [1724928 2020-01-21] () [File not signed] (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 217.10.251.114 Tcpip\..\Interfaces\{9706d7e1-ab22-4a95-8faa-594f0f5e1d81}: [NameServer] 1.1.1.1,1.0.0.1 Tcpip\..\Interfaces\{9706d7e1-ab22-4a95-8faa-594f0f5e1d81}: [DhcpNameServer] 217.10.251.114 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = Edge: ====== DownloadDir: C:\Users\NightRider\Downloads FireFox: ======== FF DefaultProfile: 84toqkl3.default FF ProfilePath: C:\Users\NightRider\AppData\Roaming\Mozilla\Firefox\Profiles\84toqkl3.default [2020-01-17] FF ProfilePath: C:\Users\NightRider\AppData\Roaming\Mozilla\Firefox\Profiles\ujtk5yth.default-release [2020-04-01] FF Homepage: Mozilla\Firefox\Profiles\ujtk5yth.default-release -> about:blank FF Extension: (HTTPS Навсякъде) - C:\Users\NightRider\AppData\Roaming\Mozilla\Firefox\Profiles\ujtk5yth.default-release\Extensions\[email protected] [2020-03-28] FF Extension: (Privacy Badger) - C:\Users\NightRider\AppData\Roaming\Mozilla\Firefox\Profiles\ujtk5yth.default-release\Extensions\[email protected] [2020-02-20] FF Extension: (Kaspersky Protection) - C:\Users\NightRider\AppData\Roaming\Mozilla\Firefox\Profiles\ujtk5yth.default-release\Extensions\[email protected] [2020-02-15] FF Extension: (uBlock Origin) - C:\Users\NightRider\AppData\Roaming\Mozilla\Firefox\Profiles\ujtk5yth.default-release\Extensions\[email protected] [2020-03-10] FF Extension: (Black Pixel Firefox) - C:\Users\NightRider\AppData\Roaming\Mozilla\Firefox\Profiles\ujtk5yth.default-release\Extensions\{46f60d87-d458-4083-b2a6-d8165d1c296c}.xpi [2020-01-03] FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\kl_prefs_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.js [2020-01-03] <==== ATTENTION (Points to *.cfg file) FF ExtraCheck: C:\Program Files\mozilla firefox\kl_config_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.cfg [2020-01-03] <==== ATTENTION Chrome: ======= CHR HKLM\...\Chrome\Extension: [elhpdacimkjpccooodognopfhbdgnpbk] - hxxps://chrome.google.com/webstore/detail/elhpdacimkjpccooodognopfhbdgnpbk CHR HKLM-x32\...\Chrome\Extension: [elhpdacimkjpccooodognopfhbdgnpbk] - hxxps://chrome.google.com/webstore/detail/elhpdacimkjpccooodognopfhbdgnpbk ==================== Services (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AVP20.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 20.0\avp.exe [357416 2019-03-21] (Kaspersky Lab -> AO Kaspersky Lab) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8402648 2020-01-04] (BattlEye Innovations e.K. -> ) S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [805488 2020-01-04] (EasyAntiCheat Oy -> EasyAntiCheat Ltd) S3 klvssbridge64_20.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 20.0\x64\vssbridge64.exe [438928 2019-03-21] (Kaspersky Lab -> AO Kaspersky Lab) S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [6933272 2020-02-28] (Malwarebytes Inc -> Malwarebytes) S3 mracsvc; C:\Windows\System32\mracsvc.exe [18997912 2020-01-05] (Mail.Ru LLC -> LLC Mail.Ru) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5930136 2020-03-27] (Microsoft Windows Publisher -> Microsoft Corporation) R2 VoodooShieldService; C:\Program Files\VoodooShield\VoodooShieldService.exe [147968 2020-01-10] (VoodooSoft, LLC -> VoodooSoft, LLC ) S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\NisSrv.exe [3294680 2020-03-27] (Microsoft Windows Publisher -> Microsoft Corporation) R2 wfcs; C:\Program Files\Malwarebytes\Windows Firewall Control\wfcs.exe [124592 2020-01-05] (Malwarebytes Inc -> Malwarebytes) S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MsMpEng.exe [103168 2020-03-27] (Microsoft Windows Publisher -> Microsoft Corporation) R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d223212c0a2275b5\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d223212c0a2275b5\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem ===================== Drivers (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 BEDaisy; C:\Program Files (x86)\Common Files\BattlEye\BEDaisy.sys [2836840 2020-01-05] (BattlEye Innovations e.K. -> ) R0 cm_km; C:\Windows\System32\DRIVERS\cm_km.sys [246912 2019-02-16] (Kaspersky Lab -> AO Kaspersky Lab) R0 klbackupdisk; C:\Windows\System32\DRIVERS\klbackupdisk.sys [79768 2020-02-12] (Kaspersky Lab -> AO Kaspersky Lab) R1 klbackupflt; C:\Windows\System32\DRIVERS\klbackupflt.sys [145504 2020-02-12] (Kaspersky Lab -> AO Kaspersky Lab) R1 kldisk; C:\Windows\system32\DRIVERS\kldisk.sys [93312 2019-03-13] (Kaspersky Lab -> AO Kaspersky Lab) S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [37816 2019-01-24] (Microsoft Windows Early Launch Anti-malware Publisher -> AO Kaspersky Lab) R3 klflt; C:\Windows\system32\DRIVERS\klflt.sys [251512 2019-11-01] (Kaspersky Lab -> AO Kaspersky Lab) R1 klgse; C:\Windows\System32\DRIVERS\klgse.sys [586496 2020-01-27] (Kaspersky Lab -> AO Kaspersky Lab) R1 klhk; C:\Windows\system32\DRIVERS\klhk.sys [1163216 2020-01-24] (Kaspersky Lab -> AO Kaspersky Lab) R3 klids; C:\ProgramData\Kaspersky Lab\AVP20.0\Bases\klids.sys [203328 2020-03-19] (Kaspersky Lab -> AO Kaspersky Lab) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [998296 2020-02-12] (Kaspersky Lab -> AO Kaspersky Lab) R1 klim6; C:\Windows\system32\DRIVERS\klim6.sys [58192 2019-03-19] (Kaspersky Lab -> AO Kaspersky Lab) R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [79184 2019-03-18] (Kaspersky Lab -> AO Kaspersky Lab) R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [59512 2019-03-18] (Kaspersky Lab -> AO Kaspersky Lab) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [51328 2019-03-13] (Kaspersky Lab -> AO Kaspersky Lab) S3 klpnpflt; C:\Windows\system32\DRIVERS\klpnpflt.sys [45904 2019-03-10] (Kaspersky Lab -> AO Kaspersky Lab) R0 klupd_klif_arkmon; C:\Windows\System32\Drivers\klupd_klif_arkmon.sys [251256 2020-01-03] (Kaspersky Lab -> AO Kaspersky Lab) R3 klupd_klif_kimul; C:\Windows\System32\Drivers\klupd_klif_kimul.sys [99152 2020-01-03] (Kaspersky Lab -> AO Kaspersky Lab) R3 klupd_klif_klark; C:\Windows\System32\Drivers\klupd_klif_klark.sys [306248 2020-01-03] (Kaspersky Lab -> AO Kaspersky Lab) R0 klupd_klif_klbg; C:\Windows\System32\Drivers\klupd_klif_klbg.sys [119744 2020-01-03] (Kaspersky Lab -> AO Kaspersky Lab) R3 klupd_klif_mark; C:\Windows\System32\Drivers\klupd_klif_mark.sys [204520 2020-01-03] (Kaspersky Lab -> AO Kaspersky Lab) S4 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [105600 2019-03-05] (Kaspersky Lab -> AO Kaspersky Lab) R1 klwtp; C:\Windows\system32\DRIVERS\klwtp.sys [211048 2020-01-03] (Kaspersky Lab -> AO Kaspersky Lab) R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [232272 2019-03-19] (Kaspersky Lab -> AO Kaspersky Lab) S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [20936 2020-02-28] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes) S3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [248968 2020-03-31] (Malwarebytes Inc -> Malwarebytes) S3 mracdrv; C:\Windows\System32\drivers\mracdrv.sys [18234792 2020-01-05] (Mail.Ru LLC -> LLC Mail.Ru) R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d223212c0a2275b5\nvlddmkm.sys [23251968 2019-12-28] (NVIDIA Corporation -> NVIDIA Corporation) R3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [14024 2017-08-27] (MICRO-STAR INTERNATIONAL CO., LTD. -> ) R3 RTL8023x64; C:\Windows\System32\drivers\Rtnic64.sys [51712 2019-03-19] (Microsoft Windows -> Realtek Semiconductor Corporation ) R3 VSScanner; C:\Windows\System32\DRIVERS\vsscanner.sys [29752 2018-06-25] (Microsoft Windows Hardware Compatibility Publisher -> VoodooSoft, LLC) S3 WdBoot; C:\Windows\system32\drivers\wd\WdBoot.sys [45960 2020-03-27] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\wd\WdFilter.sys [391392 2020-03-27] (Microsoft Windows -> Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [59104 2020-03-27] (Microsoft Windows -> Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) =================== (If an entry is included in the fixlist, the file/folder will be moved.) 2020-04-01 15:19 - 2020-04-01 15:20 - 000015114 _____ C:\Users\NightRider\Desktop\FRST.txt 2020-04-01 15:18 - 2020-04-01 15:19 - 000000000 ____D C:\FRST 2020-04-01 15:18 - 2020-04-01 15:18 - 002280448 _____ (Farbar) C:\Users\NightRider\Desktop\FRST64.exe 2020-04-01 02:55 - 2020-04-01 02:55 - 000000641 _____ C:\Users\NightRider\Desktop\JRT.txt 2020-04-01 02:50 - 2020-04-01 02:50 - 000000000 ____D C:\AdwCleaner 2020-04-01 02:49 - 2020-04-01 02:49 - 008199856 _____ (Malwarebytes) C:\Users\NightRider\Desktop\AdwCleaner.exe 2020-04-01 02:48 - 2020-04-01 02:48 - 001790024 _____ (Malwarebytes) C:\Users\NightRider\Desktop\JRT.exe 2020-03-31 04:09 - 2020-03-31 04:09 - 000248968 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys 2020-03-31 04:09 - 2020-03-31 04:09 - 000214496 ____N (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys 2020-03-31 04:04 - 2020-03-31 04:04 - 000000000 ___HD C:\Windows\system32\GroupPolicy 2020-03-31 02:42 - 2020-03-31 02:42 - 025444352 _____ (Microsoft Corporation) C:\Windows\system32\Hydrogen.dll 2020-03-31 02:42 - 2020-03-31 02:42 - 009930760 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2020-03-31 02:42 - 2020-03-31 02:42 - 007604584 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll 2020-03-31 02:42 - 2020-03-31 02:42 - 006522320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll 2020-03-31 02:42 - 2020-03-31 02:42 - 005040640 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2020-03-31 02:42 - 2020-03-31 02:42 - 004563416 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe 2020-03-31 02:42 - 2020-03-31 02:42 - 004538880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2020-03-31 02:42 - 2020-03-31 02:42 - 004129416 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll 2020-03-31 02:42 - 2020-03-31 02:42 - 002494744 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2020-03-31 02:42 - 2020-03-31 02:42 - 001610240 _____ (Microsoft Corporation) C:\Windows\system32\HologramCompositor.dll 2020-03-31 02:42 - 2020-03-31 02:42 - 001397560 _____ (Microsoft Corporation) C:\Windows\system32\hvix64.exe 2020-03-31 02:42 - 2020-03-31 02:42 - 001077048 _____ (Microsoft Corporation) C:\Windows\system32\hvax64.exe 2020-03-31 02:42 - 2020-03-31 02:42 - 000982840 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll 2020-03-31 02:42 - 2020-03-31 02:42 - 000783480 _____ (Microsoft Corporation) C:\Windows\system32\tcblaunch.exe 2020-03-31 02:42 - 2020-03-31 02:42 - 000772096 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2020-03-31 02:42 - 2020-03-31 02:42 - 000768736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll 2020-03-31 02:42 - 2020-03-31 02:42 - 000701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Mirage.Internal.dll 2020-03-31 02:42 - 2020-03-31 02:42 - 000561464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2020-03-31 02:42 - 2020-03-31 02:42 - 000530432 _____ (Microsoft Corporation) C:\Windows\system32\sppcext.dll 2020-03-31 02:42 - 2020-03-31 02:42 - 000420360 _____ (Microsoft Corporation) C:\Windows\system32\MSAudDecMFT.dll 2020-03-31 02:42 - 2020-03-31 02:42 - 000211256 _____ (Microsoft Corporation) C:\Windows\system32\tcbloader.dll 2020-03-31 02:42 - 2020-03-31 02:42 - 000012288 _____ (Microsoft Corporation) C:\Windows\system32\pacjsworker.exe 2020-03-31 02:42 - 2020-03-31 02:42 - 000000315 _____ C:\Windows\system32\DrtmAuth9.bin 2020-03-31 02:42 - 2020-03-31 02:42 - 000000315 _____ C:\Windows\system32\DrtmAuth8.bin 2020-03-31 02:42 - 2020-03-31 02:42 - 000000315 _____ C:\Windows\system32\DrtmAuth7.bin 2020-03-31 02:42 - 2020-03-31 02:42 - 000000315 _____ C:\Windows\system32\DrtmAuth6.bin 2020-03-31 02:42 - 2020-03-31 02:42 - 000000315 _____ C:\Windows\system32\DrtmAuth5.bin 2020-03-31 02:42 - 2020-03-31 02:42 - 000000315 _____ C:\Windows\system32\DrtmAuth4.bin 2020-03-31 02:42 - 2020-03-31 02:42 - 000000315 _____ C:\Windows\system32\DrtmAuth3.bin 2020-03-31 02:42 - 2020-03-31 02:42 - 000000315 _____ C:\Windows\system32\DrtmAuth2.bin 2020-03-31 02:42 - 2020-03-31 02:42 - 000000315 _____ C:\Windows\system32\DrtmAuth12.bin 2020-03-31 02:42 - 2020-03-31 02:42 - 000000315 _____ C:\Windows\system32\DrtmAuth11.bin 2020-03-31 02:42 - 2020-03-31 02:42 - 000000315 _____ C:\Windows\system32\DrtmAuth10.bin 2020-03-31 02:42 - 2020-03-31 02:42 - 000000315 _____ C:\Windows\system32\DrtmAuth1.bin 2020-03-27 02:57 - 2020-03-27 02:57 - 022636544 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 019813376 _____ (Microsoft Corporation) C:\Windows\system32\HologramWorld.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 018027008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 014818816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 008013824 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 007017472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 003799552 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 003753472 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_nt.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 003742544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OneCoreUAPCommonProxyStub.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 002986808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2020-03-27 02:57 - 2020-03-27 02:57 - 002800128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32kfull.sys 2020-03-27 02:57 - 2020-03-27 02:57 - 002768440 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 002369576 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Uev.AppAgent.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 002188600 _____ (Microsoft Corporation) C:\Windows\system32\AppVEntSubsystems64.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 002087168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 001835008 _____ (Microsoft Corporation) C:\Windows\system32\enterprisecsps.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 001659408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Microsoft.Uev.AppAgent.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 001587712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aadtb.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 001545216 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2020-03-27 02:57 - 2020-03-27 02:57 - 001495864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppVEntSubsystems32.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 001477112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dcomp.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 001386296 _____ (Microsoft Corporation) C:\Windows\system32\AppVEntSubsystemController.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 001368576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 001368576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Input.Inking.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 001264640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2020-03-27 02:57 - 2020-03-27 02:57 - 001245184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TokenBroker.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 001081856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.Vpn.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 001055376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000993280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000980832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webservices.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000923136 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Management.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000912896 _____ (Microsoft Corporation) C:\Windows\system32\rasmans.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000892416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MbaeApiPublic.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000865280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authentication.Web.Core.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000865280 _____ (Microsoft Corporation) C:\Windows\system32\netlogon.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000785920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000744960 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Uev.Office2013CustomActions.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000729600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FlightSettings.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BTAGService.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000673704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netlogon.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000647680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Management.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000632832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WpcWebFilter.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000628408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000618296 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000555008 _____ (Microsoft Corporation) C:\Windows\system32\appwiz.cpl 2020-03-27 02:57 - 2020-03-27 02:57 - 000538160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000529408 _____ (Microsoft Corporation) C:\Windows\system32\nltest.exe 2020-03-27 02:57 - 2020-03-27 02:57 - 000514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Microsoft.Uev.Office2013CustomActions.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000507152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskschd.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000497152 _____ (Microsoft Corporation) C:\Windows\system32\wuuhext.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000491008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sppcext.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000487784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000477496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS 2020-03-27 02:57 - 2020-03-27 02:57 - 000456504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys 2020-03-27 02:57 - 2020-03-27 02:57 - 000456192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appwiz.cpl 2020-03-27 02:57 - 2020-03-27 02:57 - 000452096 _____ (Microsoft Corporation) C:\Windows\system32\rdpclip.exe 2020-03-27 02:57 - 2020-03-27 02:57 - 000415760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aepic.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000410112 _____ (Microsoft Corporation) C:\Windows\system32\rascustom.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000406480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Enumeration.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntshrui.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000336384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\es.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000330240 _____ (Microsoft Corporation) C:\Windows\system32\omadmclient.exe 2020-03-27 02:57 - 2020-03-27 02:57 - 000324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32k.sys 2020-03-27 02:57 - 2020-03-27 02:57 - 000321536 _____ (Microsoft Corporation) C:\Windows\system32\wbadmin.exe 2020-03-27 02:57 - 2020-03-27 02:57 - 000277864 _____ (Microsoft Corporation) C:\Windows\system32\LsaIso.exe 2020-03-27 02:57 - 2020-03-27 02:57 - 000234496 _____ (Microsoft Corporation) C:\Windows\system32\iasrad.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000227840 _____ (Microsoft Corporation) C:\Windows\system32\IndexedDbLegacy.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000203264 _____ (Microsoft Corporation) C:\Windows\system32\LanguageComponentsInstaller.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000190048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\logoncli.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iasrad.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000185952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\deviceaccess.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000179200 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.XamlHost.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000178192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys 2020-03-27 02:57 - 2020-03-27 02:57 - 000175616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IndexedDbLegacy.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\updatepolicy.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000147696 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2020-03-27 02:57 - 2020-03-27 02:57 - 000135168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.XamlHost.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000123952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KerbClientShared.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000118272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\slc.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000105984 _____ (Microsoft Corporation) C:\Windows\system32\utcutil.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000101888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sppc.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000093712 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000090624 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000089536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32u.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000087040 _____ (Microsoft Corporation) C:\Windows\system32\iasacct.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000084280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hvservice.sys 2020-03-27 02:57 - 2020-03-27 02:57 - 000071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Custom.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000066624 _____ (Microsoft Corporation) C:\Windows\system32\iumcrypt.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000066048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iasacct.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000050544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CloudNotifications.exe 2020-03-27 02:57 - 2020-03-27 02:57 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\iaspolcy.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tbauth.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000045568 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Uev.Office2010CustomActions.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000040448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iaspolcy.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Microsoft.Uev.Office2010CustomActions.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000033080 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hwpolicy.sys 2020-03-27 02:57 - 2020-03-27 02:57 - 000031744 _____ (Microsoft Corporation) C:\Windows\system32\ias.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cmintegrator.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000029184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TokenBrokerCookies.exe 2020-03-27 02:57 - 2020-03-27 02:57 - 000023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ias.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000021520 _____ (Microsoft Corporation) C:\Windows\system32\kdhvcom.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000019968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\slcext.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000015872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Custom.ps.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000010752 _____ (Microsoft Corporation) C:\Windows\system32\DMAlertListener.ProxyStub.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DMAlertListener.ProxyStub.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 017790464 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 007849216 _____ (Microsoft Corporation) C:\Windows\system32\OneCoreUAPCommonProxyStub.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 006168064 _____ (Microsoft Corporation) C:\Windows\system32\twinui.pcshell.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 003977216 _____ (Microsoft Corporation) C:\Windows\system32\tellib.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 003728384 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys 2020-03-27 02:56 - 2020-03-27 02:56 - 003708928 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 003586872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2020-03-27 02:56 - 2020-03-27 02:56 - 003547648 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 003109376 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 002871608 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 002143232 _____ (Microsoft Corporation) C:\Windows\system32\WpcDesktopMonSvc.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 002126144 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 002114560 _____ (Microsoft Corporation) C:\Windows\system32\Windows.CloudStore.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001960448 _____ (Microsoft Corporation) C:\Windows\system32\aadtb.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001945600 _____ (Microsoft Corporation) C:\Windows\system32\dcomp.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001942528 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001918976 _____ (Microsoft Corporation) C:\Windows\system32\wevtsvc.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001783296 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Input.Inking.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001762816 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001757096 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2020-03-27 02:56 - 2020-03-27 02:56 - 001726264 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001719808 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001512832 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 001497600 _____ (Microsoft Corporation) C:\Windows\system32\TokenBroker.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001480192 _____ (Microsoft Corporation) C:\Windows\system32\usocoreworker.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 001427456 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.Vpn.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001413704 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001378528 _____ (Microsoft Corporation) C:\Windows\system32\webservices.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001300280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys 2020-03-27 02:56 - 2020-03-27 02:56 - 001263856 _____ (Microsoft Corporation) C:\Windows\system32\WpcMon.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 001261808 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001257472 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001243648 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001180672 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.Web.Core.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001136128 _____ (Microsoft Corporation) C:\Windows\system32\MbaeApiPublic.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001127424 _____ (Microsoft Corporation) C:\Windows\system32\WpcRefreshTask.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001083904 _____ (Microsoft Corporation) C:\Windows\system32\MusUpdateHandlers.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001071616 _____ (Microsoft Corporation) C:\Windows\system32\BTAGService.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001011200 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000974336 _____ (Microsoft Corporation) C:\Windows\system32\uDWM.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000924672 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000915192 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000893952 _____ (Microsoft Corporation) C:\Windows\system32\FlightSettings.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000879616 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Management.Service.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000874512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms2.sys 2020-03-27 02:56 - 2020-03-27 02:56 - 000840704 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_Language.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000811320 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000759272 _____ (Microsoft Corporation) C:\Windows\system32\taskschd.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000747320 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000735744 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000722072 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000684560 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000654912 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000638480 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000637240 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2020-03-27 02:56 - 2020-03-27 02:56 - 000605184 _____ (Microsoft Corporation) C:\Windows\system32\MusNotification.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 000604984 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000589384 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 000550400 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2020-03-27 02:56 - 2020-03-27 02:56 - 000524264 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Enumeration.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000516096 _____ (Microsoft Corporation) C:\Windows\system32\MusNotificationUx.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 000515600 _____ (Microsoft Corporation) C:\Windows\system32\dcntel.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000513576 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000498688 _____ (Microsoft Corporation) C:\Windows\system32\ntshrui.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000469504 _____ (Microsoft Corporation) C:\Windows\system32\cloudAP.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000465208 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000459688 _____ (Microsoft Corporation) C:\Windows\system32\MusNotifyIcon.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 000441144 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys 2020-03-27 02:56 - 2020-03-27 02:56 - 000437560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys 2020-03-27 02:56 - 2020-03-27 02:56 - 000416016 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000401408 _____ (Microsoft Corporation) C:\Windows\system32\es.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000374784 _____ (Microsoft Corporation) C:\Windows\system32\ncbservice.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000355328 _____ (Microsoft Corporation) C:\Windows\system32\WpcApi.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000324408 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000323584 _____ (Microsoft Corporation) C:\Windows\system32\sppcommdlg.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000297272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys 2020-03-27 02:56 - 2020-03-27 02:56 - 000278016 _____ (Microsoft Corporation) C:\Windows\system32\WpcTok.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 000265216 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000259776 _____ (Microsoft Corporation) C:\Windows\system32\logoncli.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000259072 _____ (Microsoft Corporation) C:\Windows\system32\VPNv2CSP.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000256000 _____ (Microsoft Corporation) C:\Windows\system32\UpdateDeploymentProvider.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000251704 _____ (Microsoft Corporation) C:\Windows\system32\offlinesam.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000251392 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\winnat.sys 2020-03-27 02:56 - 2020-03-27 02:56 - 000241152 _____ (Microsoft Corporation) C:\Windows\system32\policymanagerprecheck.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000231912 _____ (Microsoft Corporation) C:\Windows\system32\deviceaccess.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000200192 _____ (Microsoft Corporation) C:\Windows\system32\updatepolicy.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000197632 _____ (Microsoft Corporation) C:\Windows\system32\Win32CompatibilityAppraiserCSP.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000193848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys 2020-03-27 02:56 - 2020-03-27 02:56 - 000169472 _____ (Microsoft Corporation) C:\Windows\system32\SpatialAudioLicenseSrv.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 000164368 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 000152408 _____ (Microsoft Corporation) C:\Windows\system32\KerbClientShared.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000151352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\scmbus.sys 2020-03-27 02:56 - 2020-03-27 02:56 - 000142544 _____ (Microsoft Corporation) C:\Windows\system32\LicensingUI.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 000140800 _____ (Microsoft Corporation) C:\Windows\system32\slc.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000136192 _____ (Microsoft Corporation) C:\Windows\system32\sppc.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000127064 _____ (Microsoft Corporation) C:\Windows\system32\win32u.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000122368 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000115120 _____ (Microsoft Corporation) C:\Windows\system32\phoneactivate.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 000108032 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000102216 _____ (Microsoft Corporation) C:\Windows\system32\changepk.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 000096768 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Custom.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000089912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgr.sys 2020-03-27 02:56 - 2020-03-27 02:56 - 000088352 _____ (Microsoft Corporation) C:\Windows\system32\remoteaudioendpoint.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\autopilot.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000071480 _____ (Microsoft Corporation) C:\Windows\system32\win32appinventorycsp.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000070656 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Management.EnrollmentStatusTracking.ConfigProvider.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000070656 _____ (Microsoft Corporation) C:\Windows\system32\keepaliveprovider.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\tbauth.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\CloudNotifications.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 000059192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storufs.sys 2020-03-27 02:56 - 2020-03-27 02:56 - 000057856 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000057344 _____ (Microsoft Corporation) C:\Windows\system32\audioresourceregistrar.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000051200 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 000047208 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 000045568 _____ (Microsoft Corporation) C:\Windows\system32\cmintegrator.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Resources.Common.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000043008 _____ (Microsoft Corporation) C:\Windows\system32\UpgradeResultsUI.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 000039424 _____ (Microsoft Corporation) C:\Windows\system32\WpcProxyStubs.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000036864 _____ (Microsoft Corporation) C:\Windows\system32\TokenBrokerCookies.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 000036152 _____ (Microsoft Corporation) C:\Windows\system32\DeviceCensus.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 000031744 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\KNetPwrDepBroker.sys 2020-03-27 02:56 - 2020-03-27 02:56 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\flpydisk.sys 2020-03-27 02:56 - 2020-03-27 02:56 - 000023552 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Custom.ps.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\slcext.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\sbservicetrigger.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000018944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sfloppy.sys 2020-03-27 02:56 - 2020-03-27 02:56 - 000012800 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll 2020-03-27 02:07 - 2020-04-01 15:06 - 000000384 _____ C:\Users\NightRider\Desktop\А1 - Пряк път.lnk 2020-03-26 19:57 - 2020-03-26 19:57 - 000000000 ____D C:\Users\NightRider\AppData\Local\OneDrive 2020-03-13 02:24 - 2020-03-13 02:24 - 000021718 _____ C:\Users\NightRider\Desktop\stp_01x07_2020_e-tle(subsunacs.net).rar 2020-03-13 01:26 - 2020-02-28 03:44 - 000231936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BthA2dp.sys 2020-03-10 22:06 - 2020-03-10 22:06 - 019850240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 011607552 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 009711616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 007755776 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 005911040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 005764664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 004855808 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 004580352 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 003860832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rtmpltfm.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 003819520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 003488768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 002956688 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 002224952 _____ (Microsoft Corporation) C:\Windows\system32\ResetEngine.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 002072664 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 002031104 _____ C:\Windows\system32\rdpnano.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 001867816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 001835128 _____ (Microsoft Corporation) C:\Windows\system32\mfsrcsnk.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 001770552 _____ (Microsoft Corporation) C:\Windows\system32\winmde.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 001555904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 001490640 _____ (Microsoft Corporation) C:\Windows\system32\mfsvr.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 001417976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsrcsnk.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 001284096 _____ (Microsoft Corporation) C:\Windows\system32\werconcpl.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 001282944 _____ (Microsoft Corporation) C:\Windows\system32\mfreadwrite.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 001214976 _____ (Microsoft Corporation) C:\Windows\system32\reseteng.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 001108040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsvr.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 001098720 _____ (Microsoft Corporation) C:\Windows\system32\DolbyDecMFT.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 001088000 _____ (Microsoft Corporation) C:\Windows\system32\MCRecvSrc.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000980320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rtmpal.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000952416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DolbyDecMFT.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000915296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rtmcodecs.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000883712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MCRecvSrc.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000757632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfreadwrite.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000739328 _____ (Microsoft Corporation) C:\Windows\system32\cscsvc.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000732000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ortcengine.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000705536 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000669496 _____ (Microsoft Corporation) C:\Windows\system32\computecore.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000668672 _____ (Microsoft Corporation) C:\Windows\system32\wsecedit.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000562176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000532480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000525312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsecedit.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000510768 _____ (Microsoft Corporation) C:\Windows\system32\systemreset.exe 2020-03-10 22:06 - 2020-03-10 22:06 - 000455168 _____ (Microsoft Corporation) C:\Windows\system32\upnphost.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000444416 _____ (Microsoft Corporation) C:\Windows\system32\MSFlacDecoder.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000380416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSFlacDecoder.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000328192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\upnphost.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000287744 _____ (Microsoft Corporation) C:\Windows\system32\MSFlacEncoder.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSFlacEncoder.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scecli.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000183808 _____ (Microsoft Corporation) C:\Windows\system32\ResetEngOnline.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000155136 _____ (Microsoft Corporation) C:\Windows\system32\Chakradiag.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000148992 _____ (Microsoft Corporation) C:\Windows\system32\MDMAppInstaller.exe 2020-03-10 22:06 - 2020-03-10 22:06 - 000139776 _____ (Microsoft Corporation) C:\Windows\system32\Chakrathunk.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\wercplsupport.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakradiag.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000105472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakrathunk.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000078848 _____ (Microsoft Corporation) C:\Windows\system32\ProvSysprep.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000068096 _____ (Microsoft Corporation) C:\Windows\system32\udhisapi.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000058368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\udhisapi.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000055376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rtmmvrortc.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000042296 _____ (Microsoft Corporation) C:\Windows\system32\SysResetErr.exe 2020-03-10 22:06 - 2020-03-10 22:06 - 000040960 _____ (Microsoft Corporation) C:\Windows\system32\upnpcont.exe 2020-03-10 22:06 - 2020-03-10 22:06 - 000035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\upnpcont.exe 2020-03-10 22:06 - 2020-03-10 22:06 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000019768 _____ (Microsoft Corporation) C:\Windows\system32\ResetEngine.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 007905784 _____ (Microsoft Corporation) C:\Windows\system32\windows.storage.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 007263992 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 006084344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 004898144 _____ (Microsoft Corporation) C:\Windows\system32\rtmpltfm.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 003263488 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 002870272 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 002715648 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys 2020-03-10 22:05 - 2020-03-10 22:05 - 002698040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2020-03-10 22:05 - 2020-03-10 22:05 - 002561536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 002305536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 002289152 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.onecore.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 001999952 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 001764336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 001751040 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.desktop.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 001697792 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 001665416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 001664896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 001657120 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 001647072 _____ (Microsoft Corporation) C:\Windows\system32\gdi32full.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 001581056 _____ (Microsoft Corporation) C:\Windows\system32\qmgr.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 001484600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 001458688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 001413632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32full.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 001354080 _____ (Microsoft Corporation) C:\Windows\system32\rtmpal.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 001153024 _____ (Microsoft Corporation) C:\Windows\system32\windowsperformancerecordercontrol.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 001149712 _____ (Microsoft Corporation) C:\Windows\system32\ApplyTrustOffline.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 001097728 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Immersive.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 001091936 _____ (Microsoft Corporation) C:\Windows\system32\rtmcodecs.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 001032544 _____ (Microsoft Corporation) C:\Windows\system32\ortcengine.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000898048 _____ (Microsoft Corporation) C:\Windows\system32\MdmDiagnostics.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000895488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Immersive.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000877232 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000868864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windowsperformancerecordercontrol.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000851968 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 000734720 _____ (Microsoft Corporation) C:\Windows\system32\lpksetup.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 000680448 _____ (Microsoft Corporation) C:\Windows\system32\vpnike.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000680184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000670720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 000636848 _____ (Microsoft Corporation) C:\Windows\system32\sxs.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000613888 _____ (Microsoft Corporation) C:\Windows\system32\netprofmsvc.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000595968 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000578560 _____ (Microsoft Corporation) C:\Windows\system32\SppExtComObj.Exe 2020-03-10 22:05 - 2020-03-10 22:05 - 000551824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sxs.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000535552 _____ (Microsoft Corporation) C:\Windows\system32\usosvc.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000401408 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 000392192 _____ (Microsoft Corporation) C:\Windows\system32\Search.ProtocolHandler.MAPI2.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000379904 _____ (Microsoft Corporation) C:\Windows\system32\provengine.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000368128 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\AppxAllUserStore.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000336384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 000329216 _____ (Microsoft Corporation) C:\Windows\system32\DiagnosticLogCSP.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000299520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000294400 _____ (Microsoft Corporation) C:\Windows\system32\provops.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000283136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Search.ProtocolHandler.MAPI2.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppxAllUserStore.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000277504 _____ (Microsoft Corporation) C:\Windows\system32\scecli.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000271872 _____ (Microsoft Corporation) C:\Windows\system32\provhandlers.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000262656 _____ (Microsoft Corporation) C:\Windows\system32\netman.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000248064 _____ (Microsoft Corporation) C:\Windows\system32\weretw.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000240640 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 000233472 _____ (Microsoft Corporation) C:\Windows\system32\KnobsCore.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000232960 _____ (Microsoft Corporation) C:\Windows\system32\provisioningcsp.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000226816 _____ (Microsoft Corporation) C:\Windows\system32\netprofm.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000221200 _____ (Microsoft Corporation) C:\Windows\system32\wermgr.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 000211968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 000206336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndiswan.sys 2020-03-10 22:05 - 2020-03-10 22:05 - 000204800 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000201728 _____ (Microsoft Corporation) C:\Windows\system32\AppXApplicabilityBlob.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000199480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wermgr.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 000193592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\weretw.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000165504 _____ (Microsoft Corporation) C:\Windows\system32\dmcmnutils.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000160768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000147456 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000146712 _____ (Microsoft Corporation) C:\Windows\system32\profext.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000141824 _____ (Microsoft Corporation) C:\Windows\system32\provpackageapidll.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000138752 _____ (Microsoft Corporation) C:\Windows\system32\DeviceMetadataRetrievalClient.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000131896 _____ (Microsoft Corporation) C:\Windows\system32\DTUHandler.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 000130112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dmcmnutils.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000128512 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000120560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\profext.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000120320 _____ (Microsoft Corporation) C:\Windows\system32\KnobsCsp.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000114176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\agilevpn.sys 2020-03-10 22:05 - 2020-03-10 22:05 - 000113152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000112128 _____ (Microsoft Corporation) C:\Windows\system32\AxInstSv.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000102912 _____ (Microsoft Corporation) C:\Windows\system32\NFCProvisioningPlugin.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000097792 _____ (Microsoft Corporation) C:\Windows\system32\provdatastore.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000091136 _____ (Microsoft Corporation) C:\Windows\system32\ProvPluginEng.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000089088 _____ (Microsoft Corporation) C:\Windows\system32\BarcodeProvisioningPlugin.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000084480 _____ (Microsoft Corporation) C:\Windows\system32\provtool.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 000084480 _____ (Microsoft Corporation) C:\Windows\system32\enterpriseresourcemanager.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\CustomInstallExec.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 000071680 _____ (Microsoft Corporation) C:\Windows\system32\lpremove.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\RemovableMediaProvisioningPlugin.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000066048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\enterpriseresourcemanager.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\mf3216.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\AxInstUI.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 000056672 _____ (Microsoft Corporation) C:\Windows\system32\rtmmvrortc.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000046080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000045568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf3216.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000045056 _____ (Microsoft Corporation) C:\Windows\system32\npmproxy.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000044544 _____ (Microsoft Corporation) C:\Windows\system32\werdiagcontroller.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000038912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werdiagcontroller.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000036352 _____ (Microsoft Corporation) C:\Windows\system32\sxstrace.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 000033792 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Management.Provisioning.ProxyStub.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sxstrace.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\nlmproxy.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000017408 _____ (Microsoft Corporation) C:\Windows\system32\nlmsprep.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\MUILanguageCleanup.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\LangCleanupSysprepAction.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000010240 _____ (Microsoft Corporation) C:\Windows\system32\lpksetupproxyserv.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000008192 _____ (Microsoft Corporation) C:\Windows\system32\msimg32.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimg32.dll 2020-03-10 21:56 - 2020-02-11 07:48 - 000390656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe 2020-03-10 21:56 - 2020-02-11 07:37 - 000492544 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe ==================== One month (modified) ================== (If an entry is included in the fixlist, the file/folder will be moved.) 2020-04-01 15:19 - 2020-01-04 22:52 - 000000000 ____D C:\ProgramData\VoodooShield 2020-04-01 15:19 - 2020-01-03 23:18 - 000000000 ____D C:\ProgramData\Kaspersky Lab 2020-04-01 15:18 - 2019-03-19 07:50 - 000000000 ____D C:\Windows\INF 2020-04-01 15:11 - 2020-01-03 23:07 - 000000000 ____D C:\Users\NightRider\AppData\LocalLow\Mozilla 2020-04-01 15:02 - 2019-03-19 07:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2020-04-01 14:58 - 2020-01-03 22:32 - 000049064 _____ C:\Windows\system32\perfh002.dat 2020-04-01 14:58 - 2020-01-03 22:32 - 000012206 _____ C:\Windows\system32\perfc002.dat 2020-04-01 14:58 - 2020-01-03 20:16 - 000885446 _____ C:\Windows\system32\PerfStringBackup.INI 2020-04-01 14:52 - 2020-01-03 20:04 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2020-04-01 14:51 - 2020-01-03 23:07 - 000003136 _____ C:\Windows\system32\Tasks\MSIAfterburner 2020-04-01 14:51 - 2020-01-03 21:37 - 000017322 _____ C:\ProgramData\NVDisplay.ContainerLocalSystem.log_backup1 2020-04-01 14:51 - 2020-01-03 21:37 - 000017260 _____ C:\ProgramData\NVDisplayContainerWatchdog.log_backup1 2020-04-01 14:51 - 2020-01-03 21:37 - 000012206 _____ C:\ProgramData\DisplaySessionContainer1.log_backup1 2020-04-01 14:51 - 2019-03-19 07:37 - 000524288 _____ C:\Windows\system32\config\BBI 2020-04-01 14:50 - 2020-01-03 20:03 - 000000000 ____D C:\Windows\system32\SleepStudy 2020-04-01 11:34 - 2020-01-03 21:37 - 000001209 _____ C:\ProgramData\NvcDispCorePlugin.log_backup1 2020-04-01 08:18 - 2020-01-03 23:23 - 000004210 _____ C:\Windows\system32\Tasks\CCleaner Update 2020-04-01 03:44 - 2019-03-19 07:52 - 000000000 ___HD C:\Program Files\WindowsApps 2020-04-01 03:44 - 2019-03-19 07:52 - 000000000 ____D C:\Windows\AppReadiness 2020-04-01 03:26 - 2020-01-03 21:21 - 000000000 ____D C:\Users\NightRider\AppData\Local\D3DSCache 2020-03-31 03:18 - 2020-01-03 21:17 - 000000000 ____D C:\Users\NightRider\AppData\Local\Packages 2020-03-31 03:12 - 2020-01-03 23:05 - 000000000 ____D C:\Program Files (x86)\MSI Afterburner 2020-03-31 03:09 - 2019-03-19 07:37 - 000000000 ____D C:\Windows\CbsTemp 2020-03-31 02:45 - 2019-03-19 07:52 - 000000000 ____D C:\Windows\ShellExperiences 2020-03-31 02:45 - 2019-03-19 07:52 - 000000000 ____D C:\Windows\bcastdvr 2020-03-31 02:44 - 2020-01-03 21:15 - 000000000 ____D C:\Users\NightRider 2020-03-31 02:20 - 2020-01-04 03:56 - 000011069 _____ C:\ProgramData\DisplaySessionContainer2.log_backup1 2020-03-27 03:10 - 2020-01-03 20:03 - 000257824 _____ C:\Windows\system32\FNTCACHE.DAT 2020-03-27 03:08 - 2019-03-19 14:49 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection 2020-03-27 03:08 - 2019-03-19 07:52 - 000000000 ____D C:\Windows\SystemResources 2020-03-27 03:08 - 2019-03-19 07:52 - 000000000 ____D C:\Windows\system32\PerceptionSimulation 2020-03-27 03:08 - 2019-03-19 07:52 - 000000000 ____D C:\Windows\Provisioning 2020-03-27 03:08 - 2019-03-19 07:52 - 000000000 ____D C:\Windows\PolicyDefinitions 2020-03-27 02:42 - 2020-01-03 20:04 - 000000000 ____D C:\Windows\system32\Drivers\wd 2020-03-27 01:57 - 2019-03-19 07:52 - 000000000 ____D C:\Windows\system32\NDF 2020-03-27 01:41 - 2019-03-19 07:37 - 000032768 _____ C:\Windows\system32\config\ELAM 2020-03-27 01:12 - 2020-01-04 00:34 - 000000000 ____D C:\Users\NightRider\AppData\Roaming\uTorrent 2020-03-22 04:51 - 2020-01-03 21:20 - 000003372 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1903147458-2263829336-249963103-1001 2020-03-22 04:51 - 2020-01-03 21:20 - 000000000 ___RD C:\Users\NightRider\OneDrive 2020-03-22 04:51 - 2020-01-03 21:15 - 000002406 _____ C:\Users\NightRider\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2020-03-15 00:17 - 2020-02-12 00:56 - 000000000 ____D C:\Users\NightRider\AppData\Local\ElevatedDiagnostics 2020-03-13 02:38 - 2020-01-04 00:38 - 000000000 ____D C:\Users\NightRider\AppData\LocalLow\uTorrent 2020-03-13 02:24 - 2020-01-04 00:38 - 000000000 ____D C:\Users\NightRider\AppData\Local\BitTorrentHelper 2020-03-12 02:54 - 2020-01-05 23:15 - 000012201 _____ C:\ProgramData\DisplaySessionContainer3.log_backup1 2020-03-10 22:15 - 2020-01-03 21:17 - 000000000 __RHD C:\Users\Public\AccountPictures 2020-03-10 22:15 - 2020-01-03 21:17 - 000000000 ___RD C:\Users\NightRider\AppData\3D Objects 2020-03-10 22:14 - 2020-02-19 23:08 - 000000000 ____D C:\Program Files\Mozilla Firefox 2020-03-10 22:14 - 2020-01-03 23:05 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2020-03-10 22:13 - 2019-03-19 07:52 - 000000000 ___SD C:\Windows\system32\DiagSvcs 2020-03-10 22:13 - 2019-03-19 07:52 - 000000000 ____D C:\Windows\SysWOW64\Dism 2020-03-10 22:13 - 2019-03-19 07:52 - 000000000 ____D C:\Windows\system32\SystemResetPlatform 2020-03-10 22:13 - 2019-03-19 07:52 - 000000000 ____D C:\Windows\system32\Dism 2020-03-10 22:13 - 2019-03-19 07:37 - 000000000 ____D C:\Windows\servicing 2020-03-10 22:12 - 2020-01-03 22:19 - 000000000 ____D C:\Windows\system32\MRT 2020-03-10 22:09 - 2020-01-03 22:19 - 121542864 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2020-03-09 17:47 - 2020-01-03 23:23 - 000000000 ____D C:\Program Files\CCleaner 2020-03-09 16:32 - 2020-02-23 19:48 - 000000000 ____D C:\ProgramData\boost_interprocess ==================== SigCheck ============================ (There is no automatic fix for files that do not pass verification.) ==================== End of FRST.txt ======================== Addition.txt
  3. Здравейте, Получих спам имейл в АБВ пощата ми, който ме изнудваше за 1100 лв в биткойн валута срещу изтриване на потенциален мой клип с нецензурно съдържание. Порчетох, че е измама, но все пак има риск за троянки кон в системата. Изпълних инструкциите от темата, но не мога да ги разчета, затова ги прикачвам тук Благодаря предварително! FRST.txt Addition.txt
  4. Здравейте, Когато стартирам Google.com ми изписва, че връзката е поверителна и. NET::ERR_CERT_AUTHORITY_INVALID. Като това е във всички браузъри които имам - Chrome, Firefox, Explorer. Освен това се случва същото и когато влизам през телефона с Wi-Fi. Като съм с мобилен няма проблем. Дали цялата мрежа не е заразена? Наистина не знам, не разбирам от такива неща много. Освен това отваряйки различни сайтове ми дава, че са заразени с Other:Malware-gen[TrJ] и реално не ми отваря сайтовете. Имам аваст, който само го фиксва вируса. Сканирането ми дава, че имам заразени файлове на лаптопа в размер на 3 Gb. За да ги премахне ми иска да платя. Какво да направя в случая и как да отстраня вируса? Ще се радвам да ми помогнете, благодаря Ви предварително.
  5. Това е темата която ме насочи тук, с подробна информация, какво да правя сега?
  6. Здравейте изпратиха ме тук в този раздел да потърся помощ от вас с вирусите в компютъра ми .... Става въпрос че виждам по монитора си и на всякаде нещо като матрица Немога да прикачя файловете от scan-a на програмата FRST защото има лимит и те го надвишават
  7. Здравейте на всички, Въпросът ми е по - скоро опознаваъелен отколкото от тип проблем. Run-нах един exe файл който не ми даде никакъв output, като не забелязвам промяна и в работата на системата дори. Прекарах файлът през вирустотал като почти всички (с изключение на Cylane и JiangMin които аз не намирам за достоверни) изкараха че файлът е чист. Бихте ли могли да ми кажете дали този софтуер би могъл да причини някакви вреди на системата (или на потребителя като keylogging и други) Качвам линк към файла в докс: Линк П. С. Файлът е свален от репо от гитхъб. Нека който желае да пише, ще му пратя линк към репото. Благодаря предварително!
  8. Здравейте,открих наличието на софтуер за дистанционен достъп до компютъра си ,след като видях курсора на мишката да се движи по екрана.Не знам дали има промяна в работата на компютъра,поне не съм забелязал.Прилагам файловете при сканиране с FRST FRST.txt Addition.txt
  9. Здравейте , нямам оплаквания просто искам да направя профилактична проверка Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 26-02-2020 Ran by ВЕСКО (administrator) on PAPA (Hewlett-Packard HP EliteBook 6930p) (02-03-2020 14:47:25) Running from C:\Users\ВЕСКО\Downloads Loaded Profiles: ВЕСКО (Available Profiles: ВЕСКО) Platform: Windows 8.1 Pro (Update) (X64) Language: English (United States) Default browser: Chrome Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Avago Technologies U.S. Inc. -> LSI Corporation) C:\Program Files\LSI SoftModem\agr64svc.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.442\GoogleCrashHandler.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.442\GoogleCrashHandler64.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (PLARIUM GLOBAL LTD. -> ) C:\Users\ВЕСКО\AppData\Local\Plarium\PlariumPlay\TrayPP.exe (PLARIUM GLOBAL LTD. -> Plarium) C:\Users\ВЕСКО\AppData\Local\Plarium\PlariumPlay\PlariumPlay.exe (PLARIUM GLOBAL LTD. -> Plarium) C:\Users\ВЕСКО\AppData\Local\Plarium\PlariumPlay\PlariumPlay.exe (PLARIUM GLOBAL LTD. -> Plarium) C:\Users\ВЕСКО\AppData\Local\Plarium\PlariumPlay\PlariumPlay.exe (PLARIUM GLOBAL LTD. -> Plarium) C:\Users\ВЕСКО\AppData\Local\Plarium\PlariumPlay\PlariumPlay.exe (SafeIP) [File not signed] C:\Program Files (x86)\SafeIP\SafeIPS.exe ==================== Registry (Whitelisted) =================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2096424 2010-05-27] (Synaptics Incorporated -> Synaptics Incorporated) HKLM\...\Run: [WindowsDefender] => "%ProgramFiles%\Windows Defender\MSASCuiL.exe" HKLM-x32\...\Run: [QlbCtrl.exe] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [287800 2009-11-11] (Hewlett-Packard Company -> Hewlett-Packard Development Company, L.P.) HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [226728 2019-07-21] (Kilonova LLC -> ) HKU\S-1-5-21-2076816696-1300689269-2899885506-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [24552064 2019-10-14] (Piriform Software Ltd -> Piriform Ltd) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\80.0.3987.122\Installer\chrmstp.exe [2020-02-24] (Google LLC -> Google LLC) ==================== Scheduled Tasks (Whitelisted) ============ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {265168EC-659E-486F-A588-95AEB76ABA97} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-02-12] (Adobe Inc. -> Adobe) Task: {55DBABF8-7CBC-45AD-AA41-0CDE6FC314AF} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [608384 2019-10-14] (Piriform Software Ltd -> Piriform Software Ltd) Task: {5CB506C8-E8D6-4C56-AF40-B3D478C337CE} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [18458752 2019-10-14] (Piriform Software Ltd -> Piriform Ltd) Task: {6B9E0AD0-AB0C-4380-A4C4-DCAD81DBD548} - System32\Tasks\update-S-1-5-21-2076816696-1300689269-2899885506-1001 => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [414872 2017-04-12] (OOO Lightshot -> TODO: <Company name>) Task: {87935F6A-A2F4-4866-A907-C7CD2C7A0A21} - System32\Tasks\update-sys => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [414872 2017-04-12] (OOO Lightshot -> TODO: <Company name>) Task: {A843C120-2505-4293-BDFD-A29A24C02977} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-08-10] (Google Inc -> Google LLC) Task: {ACA797F2-DFAE-40E9-A1A1-F0FF47044B6A} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_330_pepper.exe [1453624 2020-02-12] (Adobe Inc. -> Adobe) Task: {BC7D6B7B-03DE-4E5D-A1B5-62B9B694C8C6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-08-10] (Google Inc -> Google LLC) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\update-S-1-5-21-2076816696-1300689269-2899885506-1001.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe Task: C:\Windows\Tasks\update-sys.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Winsock: Catalog9 01 C:\Windows\SysWOW64\SafeIPs.dll [384000 2015-08-03] (SafeIP) [File not signed] Winsock: Catalog9 02 C:\Windows\SysWOW64\SafeIPs.dll [384000 2015-08-03] (SafeIP) [File not signed] Winsock: Catalog9 03 C:\Windows\SysWOW64\SafeIPs.dll [384000 2015-08-03] (SafeIP) [File not signed] Winsock: Catalog9 04 C:\Windows\SysWOW64\SafeIPs.dll [384000 2015-08-03] (SafeIP) [File not signed] Winsock: Catalog9 16 C:\Windows\SysWOW64\SafeIPs.dll [384000 2015-08-03] (SafeIP) [File not signed] Winsock: Catalog9-x64 01 C:\Windows\system32\SafeIPs64.dll [547328 2015-08-03] (SafeIP) [File not signed] Winsock: Catalog9-x64 02 C:\Windows\system32\SafeIPs64.dll [547328 2015-08-03] (SafeIP) [File not signed] Winsock: Catalog9-x64 03 C:\Windows\system32\SafeIPs64.dll [547328 2015-08-03] (SafeIP) [File not signed] Winsock: Catalog9-x64 04 C:\Windows\system32\SafeIPs64.dll [547328 2015-08-03] (SafeIP) [File not signed] Winsock: Catalog9-x64 16 C:\Windows\system32\SafeIPs64.dll [547328 2015-08-03] (SafeIP) [File not signed] Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{A7FF16DF-7DC1-437C-8A22-C8C6BDC82A48}: [DhcpNameServer] 192.168.0.1 Internet Explorer: ================== HKU\S-1-5-21-2076816696-1300689269-2899885506-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://securesearch.org/homepage?hp=2&pId=BT171101&iDate=2020-02-16 08:34:09&bName= SearchScopes: HKU\S-1-5-21-2076816696-1300689269-2899885506-1001 -> {993F5746-4C15-42BC-99C1-064A1764271B} URL = hxxps://securesearch.org?q={searchTerms} Chrome: ======= CHR Profile: C:\Users\ВЕСКО\AppData\Local\Google\Chrome\User Data\Default [2020-03-02] CHR Notifications: Default -> hxxps://realniistorii.com CHR HomePage: Default -> hxxp://google.bg/ CHR StartupUrls: Default -> "hxxps://www.google.bg/" CHR Extension: (Презентации) - C:\Users\ВЕСКО\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-08-10] CHR Extension: (Документи) - C:\Users\ВЕСКО\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-08-10] CHR Extension: (Google Диск) - C:\Users\ВЕСКО\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2019-08-10] CHR Extension: (YouTube) - C:\Users\ВЕСКО\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-08-10] CHR Extension: (Adblock Plus — безплатен блокер на реклами) - C:\Users\ВЕСКО\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2020-02-19] CHR Extension: (Таблици) - C:\Users\ВЕСКО\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-08-10] CHR Extension: (Google Документи офлайн) - C:\Users\ВЕСКО\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-01-09] CHR Extension: (Lightshot (скрииншот инструмент)) - C:\Users\ВЕСКО\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbniclmhobmnbdlbpiphghaielnnpgdp [2020-01-27] CHR Extension: (Плащания в уеб магазина на Chrome) - C:\Users\ВЕСКО\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-04] CHR Extension: (Gmail) - C:\Users\ВЕСКО\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-08-10] CHR Extension: (Chrome Media Router) - C:\Users\ВЕСКО\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-02-20] ==================== Services (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AgereModemAudio; C:\Program Files\LSI SoftModem\agr64svc.exe [42096 2015-08-04] (Avago Technologies U.S. Inc. -> LSI Corporation) S3 GameforgeClientService; C:\Program Files (x86)\GameforgeClient\gfservice.exe [529568 2020-02-12] (Gameforge 4D GmbH -> ) S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [6960640 2020-01-11] (Malwarebytes Inc -> Malwarebytes) R3 SafeIPS; C:\Program Files (x86)\SafeIP\SafeIPs.exe [4606976 2015-08-03] (SafeIP) [File not signed] R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2019-08-11] (Microsoft Corporation -> Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2019-08-11] (Microsoft Corporation -> Microsoft Corporation) ===================== Drivers (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 AgereSoftModem; C:\Windows\system32\DRIVERS\agrsm64.sys [1230104 2015-08-04] (Microsoft Windows Hardware Compatibility Publisher -> LSI Corporation) S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Broadcom Corporation -> Windows (R) Win 7 DDK provider) R3 HBtnKey; C:\Windows\system32\DRIVERS\cpqbttn.sys [19000 2010-02-24] (Hewlett-Packard Company -> Hewlett-Packard Company) R3 HpqKbFiltr; C:\Windows\System32\drivers\HpqKbFiltr.sys [18432 2009-04-29] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Development Company, L.P.) R3 RICOH SmartCard Reader; C:\Windows\system32\DRIVERS\rismcx64.sys [79488 2006-10-03] (Microsoft Windows Hardware Compatibility Publisher -> RICOH Company, Ltd.) S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [46600 2019-08-11] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [274776 2019-08-11] (Microsoft Windows -> Microsoft Corporation) R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [117592 2019-08-11] (Microsoft Windows -> Microsoft Corporation) R0 WofAdk; C:\Windows\System32\drivers\wofadk.sys [221376 2019-08-11] (Microsoft Corporation -> Microsoft Corporation) S1 amsdk; \??\C:\Windows\system32\drivers\amsdk.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) =================== (If an entry is included in the fixlist, the file/folder will be moved.) 2020-03-02 14:47 - 2020-03-02 14:48 - 000011911 _____ C:\Users\ВЕСКО\Downloads\FRST.txt 2020-03-02 14:47 - 2020-03-02 14:48 - 000000000 ____D C:\FRST 2020-03-02 14:37 - 2020-03-02 14:38 - 002279424 _____ (Farbar) C:\Users\ВЕСКО\Downloads\FRST64.exe 2020-02-22 06:34 - 2020-02-22 06:35 - 000000000 ____D C:\Program Files\CCleaner 2020-02-22 06:34 - 2020-02-22 06:34 - 000003870 _____ C:\Windows\system32\Tasks\CCleaner Update 2020-02-22 06:34 - 2020-02-22 06:34 - 000002800 _____ C:\Windows\system32\Tasks\CCleanerSkipUAC 2020-02-22 06:34 - 2020-02-22 06:34 - 000000834 _____ C:\Users\Public\Desktop\CCleaner.lnk 2020-02-22 06:34 - 2020-02-22 06:34 - 000000834 _____ C:\ProgramData\Desktop\CCleaner.lnk 2020-02-22 06:34 - 2020-02-22 06:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2020-02-22 06:33 - 2020-02-22 06:34 - 024581800 _____ (Piriform Software Ltd) C:\Users\ВЕСКО\Downloads\cctrialsetup.exe 2020-02-21 04:37 - 2020-02-21 04:56 - 000002456 _____ C:\Windows\SysWOW64\SafeIPSOff.ini 2020-02-21 04:37 - 2020-02-21 04:56 - 000002456 _____ C:\Windows\system32\SafeIPSOff.ini 2020-02-21 04:28 - 2020-02-21 04:28 - 000000995 _____ C:\Users\ВЕСКО\Desktop\SafeIP.lnk 2020-02-21 04:28 - 2020-02-21 04:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SafeIP 2020-02-21 04:28 - 2020-02-21 04:28 - 000000000 ____D C:\Program Files (x86)\SafeIP 2020-02-21 04:28 - 2015-08-03 08:53 - 000384000 _____ (SafeIP) C:\Windows\SysWOW64\SafeIPs.dll 2020-02-16 12:58 - 2020-02-16 12:58 - 000000000 ____D C:\Users\ВЕСКО\Downloads\Collection 2020-02-16 12:47 - 2020-02-16 12:47 - 000000000 ____D C:\Users\ВЕСКО\AppData\Roaming\WinRAR 2020-02-16 12:47 - 2020-02-16 12:47 - 000000000 ____D C:\Users\ВЕСКО\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2020-02-16 12:47 - 2020-02-16 12:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2020-02-16 12:47 - 2020-02-16 12:47 - 000000000 ____D C:\Program Files\WinRAR 2020-02-16 12:46 - 2020-02-16 12:46 - 003205888 _____ (Alexander Roshal) C:\Users\ВЕСКО\Downloads\winrar-x64-580.exe 2020-02-16 12:37 - 2020-02-16 12:37 - 000000000 ____D C:\Users\Public\Documents\Steam 2020-02-16 12:37 - 2020-02-16 12:37 - 000000000 ____D C:\ProgramData\Documents\Steam 2020-02-16 12:33 - 2020-02-16 12:33 - 000016499 _____ C:\Users\ВЕСКО\Downloads\Collection.torrent 2020-02-16 12:21 - 2020-02-16 12:33 - 000000000 ____D C:\Windows\SysWOW64\directx 2020-02-16 12:21 - 2020-02-16 12:21 - 000000000 ___HD C:\Windows\msdownld.tmp 2020-02-16 11:45 - 2020-02-16 11:45 - 000000000 ____D C:\Users\ВЕСКО\Documents\Lightshot 2020-02-16 11:43 - 2020-03-02 12:45 - 000000398 _____ C:\Windows\Tasks\update-sys.job 2020-02-16 11:43 - 2020-03-02 11:07 - 000000398 _____ C:\Windows\Tasks\update-S-1-5-21-2076816696-1300689269-2899885506-1001.job 2020-02-16 11:43 - 2020-02-16 11:43 - 000003268 _____ C:\Windows\system32\Tasks\update-sys 2020-02-16 11:43 - 2020-02-16 11:43 - 000003246 _____ C:\Windows\system32\Tasks\update-S-1-5-21-2076816696-1300689269-2899885506-1001 2020-02-16 11:43 - 2020-02-16 11:43 - 000000424 _____ C:\Users\ВЕСКО\AppData\Local\UserProducts.xml 2020-02-16 11:43 - 2020-02-16 11:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightshot 2020-02-16 11:43 - 2020-02-16 11:43 - 000000000 ____D C:\Program Files (x86)\Skillbrains 2020-02-16 11:41 - 2020-02-16 11:41 - 002784344 _____ (Skillbrains ) C:\Users\ВЕСКО\Downloads\setup-lightshot.exe 2020-02-16 11:00 - 2020-02-16 14:38 - 000000000 ____D C:\Games 2020-02-16 10:32 - 2020-02-22 06:37 - 000000000 ____D C:\Users\ВЕСКО\AppData\Roaming\BitTorrent 2020-02-16 10:32 - 2020-02-16 10:32 - 000000913 _____ C:\Users\ВЕСКО\Desktop\BitTorrent.lnk 2020-02-16 10:32 - 2020-02-16 10:32 - 000000893 _____ C:\Users\ВЕСКО\AppData\Roaming\Microsoft\Windows\Start Menu\BitTorrent.lnk 2020-02-16 10:30 - 2020-02-16 10:31 - 005077120 _____ (BitTorrent Inc.) C:\Users\ВЕСКО\Downloads\BitTorrent.exe 2020-02-16 10:29 - 2020-02-16 10:30 - 000018355 _____ C:\Users\ВЕСКО\Downloads\Euro Truck Simulator 2 v1.36.2.2s.torrent 2020-02-16 09:56 - 2020-02-16 10:13 - 2092624032 _____ C:\Users\ВЕСКО\Downloads\EuroTruckSimulator2_1_28_1_3_patch.exe 2020-02-14 17:23 - 2020-02-14 17:24 - 001018988 _____ C:\Users\ВЕСКО\Downloads\QTranslate.6.7.4.exe 2020-02-09 11:43 - 2020-02-09 11:43 - 001031213 _____ C:\Users\ВЕСКО\Downloads\05.02.2020_Списък_на_подлежащите_на_запечатване_търговски_обекти_и_тяхното_местонахождение.pdf 2020-02-09 07:55 - 2020-02-09 07:55 - 003045838 _____ C:\Users\ВЕСКО\Downloads\1dad5ad69c6d5c9593aff6de7ce2ae91.mp4 2020-02-09 07:55 - 2020-02-09 07:55 - 002747301 _____ C:\Users\ВЕСКО\Downloads\b073f119aaf0f65be906afc679159766.mp4 2020-02-09 07:54 - 2020-02-09 07:55 - 003781947 _____ C:\Users\ВЕСКО\Downloads\a4e3ac7ac21e72da14d0550abe14d173.mp4 2020-02-07 19:31 - 2020-02-07 19:31 - 000000000 ____D C:\Users\ВЕСКО\AppData\Local\ElevatedDiagnostics ==================== One month (modified) ================== (If an entry is included in the fixlist, the file/folder will be moved.) 2020-03-02 14:45 - 2019-08-10 22:00 - 000003598 _____ C:\Windows\system32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2076816696-1300689269-2899885506-1001 2020-03-02 14:39 - 2019-12-01 14:43 - 000000037 _____ C:\Users\Public\Desktop\Gameforge Client.url 2020-03-02 14:39 - 2019-12-01 14:43 - 000000037 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Gameforge Client.url 2020-03-02 14:39 - 2019-12-01 14:43 - 000000037 _____ C:\ProgramData\Desktop\Gameforge Client.url 2020-03-02 14:39 - 2019-12-01 14:43 - 000000000 ____D C:\Program Files (x86)\GameforgeClient 2020-03-02 08:40 - 2019-08-10 22:08 - 000003910 _____ C:\Windows\system32\Tasks\User_Feed_Synchronization-{54DC4300-FD57-426E-B02E-B8CE96343A01} 2020-02-28 12:39 - 2019-08-10 22:03 - 000000000 ___DO C:\Users\ВЕСКО\SkyDrive 2020-02-28 12:38 - 2013-08-22 16:45 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2020-02-28 12:37 - 2013-08-22 15:25 - 000262144 ___SH C:\Windows\system32\config\BBI 2020-02-28 01:00 - 2013-08-22 15:36 - 000000000 ____D C:\Windows\Inf 2020-02-25 18:01 - 2020-01-04 20:07 - 000000065 _____ C:\Users\ВЕСКО\Downloads\uopilot.ini 2020-02-24 21:44 - 2019-08-10 22:13 - 000002244 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2020-02-24 21:44 - 2019-08-10 22:13 - 000002203 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2020-02-24 21:44 - 2019-08-10 22:13 - 000002203 _____ C:\ProgramData\Desktop\Google Chrome.lnk 2020-02-22 06:37 - 2019-10-10 03:14 - 000000000 ____D C:\Windows\Minidump 2020-02-22 06:37 - 2019-08-11 08:47 - 000000000 ____D C:\Windows\Panther 2020-02-16 12:33 - 2013-08-22 17:36 - 000000000 ____D C:\Program Files\Common Files\microsoft shared 2020-02-14 17:24 - 2020-01-15 20:02 - 000001047 _____ C:\Users\ВЕСКО\Desktop\QTranslate.lnk 2020-02-12 04:05 - 2019-10-13 11:30 - 000004424 _____ C:\Windows\system32\Tasks\Adobe Flash Player PPAPI Notifier 2020-02-12 04:05 - 2019-10-13 11:30 - 000004282 _____ C:\Windows\system32\Tasks\Adobe Flash Player Updater 2020-02-12 04:04 - 2013-08-22 17:36 - 000000000 ____D C:\Windows\SysWOW64\Macromed 2020-02-12 04:04 - 2013-08-22 17:36 - 000000000 ____D C:\Windows\system32\Macromed 2020-02-05 02:36 - 2019-08-10 22:11 - 000003434 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA 2020-02-05 02:36 - 2019-08-10 22:11 - 000003306 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore 2020-02-01 06:12 - 2013-08-22 17:36 - 000000000 ____D C:\Windows\system32\NDF 2020-02-01 03:03 - 2019-08-12 01:06 - 000000000 ____D C:\Users\ВЕСКО\AppData\LocalLow\Unity ==================== Files in the root of some directories ======== 2019-10-27 11:08 - 2019-10-27 11:08 - 000137168 _____ (Mozilla Foundation) C:\ProgramData\mozglue.dll 2019-10-27 11:08 - 2019-10-27 11:08 - 000440120 _____ (Microsoft Corporation) C:\ProgramData\msvcp140.dll 2019-10-27 11:08 - 2019-10-27 11:08 - 001246160 _____ (Mozilla Foundation) C:\ProgramData\nss3.dll 2019-10-27 11:08 - 2019-10-27 11:08 - 000083784 _____ (Microsoft Corporation) C:\ProgramData\vcruntime140.dll 2019-10-13 11:25 - 2019-10-13 11:24 - 051823104 _____ () C:\Program Files\Macromedia Captivate.msi 2019-08-11 00:00 - 2019-08-11 00:00 - 000000000 _____ () C:\Users\ВЕСКО\AppData\Local\AtStart.txt 2019-10-27 11:08 - 2019-10-27 11:08 - 000000556 _____ () C:\Users\ВЕСКО\AppData\Local\bowsakkdestx.txt 2019-08-11 00:00 - 2019-08-11 00:00 - 000000000 _____ () C:\Users\ВЕСКО\AppData\Local\DSwitch.txt 2019-08-10 22:45 - 2019-12-12 16:42 - 000039733 _____ () C:\Users\ВЕСКО\AppData\Local\PlariumPlay.log 2019-08-11 00:00 - 2019-08-11 00:00 - 000000000 _____ () C:\Users\ВЕСКО\AppData\Local\QSwitch.txt 2020-02-16 11:43 - 2020-02-16 11:43 - 000000003 _____ () C:\Users\ВЕСКО\AppData\Local\updater.log 2020-02-16 11:43 - 2020-02-16 11:43 - 000000424 _____ () C:\Users\ВЕСКО\AppData\Local\UserProducts.xml ==================== SigCheck ============================ (There is no automatic fix for files that do not pass verification.) LastRegBack: 2020-02-28 01:00 ==================== End of FRST.txt ======================== Additional scan result of Farbar Recovery Scan Tool (x64) Version: 26-02-2020 Ran by ВЕСКО (02-03-2020 14:49:23) Running from C:\Users\ВЕСКО\Downloads Windows 8.1 Pro (Update) (X64) (2019-08-10 19:55:10) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-2076816696-1300689269-2899885506-500 - Administrator - Disabled) Guest (S-1-5-21-2076816696-1300689269-2899885506-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-2076816696-1300689269-2899885506-1003 - Limited - Enabled) ВЕСКО (S-1-5-21-2076816696-1300689269-2899885506-1001 - Administrator - Enabled) => C:\Users\ВЕСКО ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 32 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 32.0.0.330 - Adobe) BitTorrent (HKU\S-1-5-21-2076816696-1300689269-2899885506-1001\...\BitTorrent) (Version: 7.10.5.45496 - BitTorrent Inc.) CCleaner (HKLM\...\CCleaner) (Version: 5.63 - Piriform) Gameforge Client (HKLM-x32\...\{d3b2a0c1-f0d0-4888-ae0b-1c5e1febdafb}_is1) (Version: 2.0.51.124 - Gameforge) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 80.0.3987.122 - Google LLC) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.441 - Google LLC) Hidden HP Quick Launch Buttons (HKLM-x32\...\{34D2AB40-150D-475D-AE32-BD23FB5EE355}) (Version: 6.50.14.1 - Hewlett-Packard Company) Lightshot-5.5.0.4 (HKLM-x32\...\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1) (Version: 5.5.0.4 - Skillbrains) LINE (HKU\S-1-5-21-2076816696-1300689269-2899885506-1001\...\LINE) (Version: 5.22.0.2111 - LINE Corporation) LSI HDA Modem (HKLM\...\LSI Soft Modem) (Version: 2.2.100 - LSI Corporation) Malwarebytes version 4.0.4.49 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.0.4.49 - Malwarebytes) Metin2 ru-RU (HKLM-x32\...\{fab180a3-cd65-4b7e-bd0e-2ef77fd0c258.ru-RU}) (Version: - Gameforge) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.24.28127 (HKLM-x32\...\{282975d8-55fe-4991-bbbb-06a72581ce58}) (Version: 14.24.28127.4 - Microsoft Corporation) Plarium Play (HKLM-x32\...\{4EE55C89-1180-4702-86C0-0E999BF691FD}) (Version: 5.1.0 - Plarium) Hidden Plarium Play (HKU\S-1-5-21-2076816696-1300689269-2899885506-1001\...\{1077884f-6e6c-4848-8a7c-9dec58d99637}) (Version: 5.1.0 - Plarium) QLBCASL (HKLM-x32\...\{F1D7AC58-554A-4A58-B784-B61558B1449A}) (Version: 6.40.17.2 - Hewlett-Packard) Hidden QTranslate 6.7.4 (HKLM-x32\...\QTranslate) (Version: 6.7.4 - QuestSoft) SafeIP (HKLM-x32\...\SAFEIP_is1) (Version: - SafeIP) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.0.17.4 - Synaptics Incorporated) WinRAR 5.80 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.80.0 - win.rar GmbH) Packages: ========= Frameworkuapbase -> C:\Program Files\WindowsApps\48682KiddoTest.Frameworkuapbase_1.0.0.2_neutral__81ffpr532s7pc [2019-08-11] (KiddoTest) Kinect for Windows Framework -> C:\Program Files\WindowsApps\Microsoft.WindowsPreview.Kinect.8.0_2.0.1410.19000_x64__8wekyb3d8bbwe [2019-08-11] (Microsoft Corporation) Kinect for Windows Framework -> C:\Program Files\WindowsApps\Microsoft.WindowsPreview.Kinect.8.0_2.0.1410.19000_x86__8wekyb3d8bbwe [2019-08-11] (Microsoft Corporation) Kinect for Windows Framework -> C:\Program Files\WindowsApps\Microsoft.WindowsPreview.Kinect.8.1_2.0.1410.19000_x64__8wekyb3d8bbwe [2019-08-11] (Microsoft Corporation) Kinect for Windows Framework -> C:\Program Files\WindowsApps\Microsoft.WindowsPreview.Kinect.8.1_2.0.1410.19000_x86__8wekyb3d8bbwe [2019-08-11] (Microsoft Corporation) Microsoft PlayReady -> C:\Program Files\WindowsApps\Microsoft.Internal.Media.PlayReadyClient_2.3.1678.1_x64__8wekyb3d8bbwe [2019-08-11] (Microsoft Corporation) Microsoft PlayReady -> C:\Program Files\WindowsApps\Microsoft.Internal.Media.PlayReadyClient_2.3.1678.1_x86__8wekyb3d8bbwe [2019-08-11] (Microsoft Corporation) Microsoft Visual C++ Runtime Package -> C:\Program Files\WindowsApps\Microsoft.VCLibs.120.00.Preview.Internal_12.0.20222.2_x64__8wekyb3d8bbwe [2019-08-11] (Microsoft Platform Extensions Internal) Microsoft Visual C++ Runtime Package -> C:\Program Files\WindowsApps\Microsoft.VCLibs.120.00.Preview.Internal_12.0.20222.2_x86__8wekyb3d8bbwe [2019-08-11] (Microsoft Platform Extensions Internal) Microsoft Windows Library for JavaScript -> C:\Program Files\WindowsApps\Microsoft.WinJS.2.0.Preview.Internal_1.0.9385.3_neutral__8wekyb3d8bbwe [2019-08-11] (Microsoft Platform Extensions) Microsoft Windows Library for JavaScript -> C:\Program Files\WindowsApps\Microsoft.WinJS.2.0.Preview_1.0.9431.0_neutral__8wekyb3d8bbwe [2019-08-11] (Microsoft Platform Extensions) Microsoft Windows Library for JavaScript -> C:\Program Files\WindowsApps\Microsoft.WinJS.Preview.1_1.0.9345.0_neutral__8wekyb3d8bbwe [2019-08-11] (Microsoft Platform Extensions) MSN Време -> C:\Program Files\WindowsApps\Microsoft.BingWeather_3.0.4.322_x64__8wekyb3d8bbwe [2019-08-11] (Microsoft Corporation) [MS Ad] MSN Кулинария -> C:\Program Files\WindowsApps\Microsoft.BingFoodAndDrink_3.0.4.336_x64__8wekyb3d8bbwe [2019-08-11] (Microsoft Corporation) [MS Ad] MSN Пътуване -> C:\Program Files\WindowsApps\Microsoft.BingTravel_3.0.4.336_x64__8wekyb3d8bbwe [2019-08-11] (Microsoft Corporation) [MS Ad] mxtest2 -> C:\Program Files\WindowsApps\24712m1dfmmengesha.mxtest2_2.0.0.0_neutral__x35ns48czryn0 [2019-08-11] (m1df_mmengesha) Test_Framework_BP_052015 -> C:\Program Files\WindowsApps\24712m1dfmmengesha.TestFrameworkBP052015_1.0.0.9_neutral__x35ns48czryn0 [2019-08-11] (m1df_mmengesha) Test_Framework_win81appxneutral_061115 -> C:\Program Files\WindowsApps\24712m1dfmmengesha.TestFrameworkwin81appxneutral06_4.0.0.7_neutral__x35ns48czryn0 [2019-08-11] (M1DF_Mmengesha) Test_FrameworkBackpublish_050515 -> C:\Program Files\WindowsApps\24712m1dfmmengesha.TestFrameworkBackpublish050515_1.0.0.0_neutral__x35ns48czryn0 [2019-08-11] (m1df_mmengesha) Test_FrameworkProd_062215_01 -> C:\Program Files\WindowsApps\50856m1dfLL.TestFrameworkProd06221501_1.0.0.10_neutral__nwcxtg9ehxpvt [2019-08-11] (m1df_lucyll) TESTFRAMEWORKABO2 -> C:\Program Files\WindowsApps\40538vasetest101.TESTFRAMEWORKABO2_12.0.21005.1_x64__ssm1v0s3df7zc [2019-08-11] (vasetest101) Видео -> C:\Program Files\WindowsApps\Microsoft.ZuneVideo_2.2.802.0_x64__8wekyb3d8bbwe [2019-08-11] (Microsoft Corporation) [MS Ad] Игри -> C:\Program Files\WindowsApps\Microsoft.XboxLIVEGames_2.0.139.0_x64__8wekyb3d8bbwe [2019-08-11] (Microsoft Corporation) [MS Ad] Музика -> C:\Program Files\WindowsApps\Microsoft.ZuneMusic_2.2.800.0_x64__8wekyb3d8bbwe [2019-08-11] (Microsoft Corporation) [MS Ad] ==================== Custom CLSID (Whitelisted): ============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-12-05] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-12-05] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-01-11] (Malwarebytes Corporation -> Malwarebytes) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-01-11] (Malwarebytes Corporation -> Malwarebytes) ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-12-05] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-12-05] (win.rar GmbH -> Alexander Roshal) ==================== Codecs (Whitelisted) ==================== ==================== Shortcuts & WMI ======================== ==================== Loaded Modules (Whitelisted) ============= 2019-08-15 04:28 - 2015-08-03 08:54 - 000547328 _____ (SafeIP) [File not signed] C:\Windows\system32\SafeIPs64.dll ==================== Alternate Data Streams (Whitelisted) ======== ==================== Safe Mode (Whitelisted) ================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\amsdk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\amsdk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SafeIPS => ""="service" ==================== Association (Whitelisted) ================= ==================== Internet Explorer trusted/restricted ========== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-2076816696-1300689269-2899885506-1001\...\localhost -> localhost IE trusted site: HKU\S-1-5-21-2076816696-1300689269-2899885506-1001\...\webcompanion.com -> hxxp://webcompanion.com ==================== Hosts content: ========================= (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 15:25 - 2019-12-06 18:21 - 000000822 _____ C:\Windows\system32\drivers\etc\hosts ==================== Other Areas =========================== (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2076816696-1300689269-2899885506-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\ВЕСКО\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\img0.jpg DNS Servers: 192.168.0.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (If an entry is included in the fixlist, it will be removed.) HKLM\...\StartupApproved\Run: => "WindowsDefender" HKLM\...\StartupApproved\Run: => "SynTPEnh" HKLM\...\StartupApproved\Run32: => "QlbCtrl.exe" ==================== FirewallRules (Whitelisted) ================ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{90A6F7DD-E504-4409-ABEC-C48BCE0F48C2}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) FirewallRules: [TCP Query User{75128495-E63B-4C18-86A2-FA3306C63C36}E:\lfs\lfs.exe] => (Allow) E:\lfs\lfs.exe () [File not signed] FirewallRules: [UDP Query User{C5906F14-8730-4E59-AB30-06C67E9BC2EB}E:\lfs\lfs.exe] => (Allow) E:\lfs\lfs.exe () [File not signed] FirewallRules: [{1BED8524-52DB-4260-8BBE-A881BD9D3E34}] => (Allow) C:\Users\ВЕСКО\AppData\Roaming\BitTorrent\BitTorrent.exe (BitTorrent Inc -> BitTorrent Inc.) FirewallRules: [{AA496B3E-2F6F-4807-965E-F158476BB027}] => (Allow) C:\Users\ВЕСКО\AppData\Roaming\BitTorrent\BitTorrent.exe (BitTorrent Inc -> BitTorrent Inc.) FirewallRules: [{A809C2BA-1C3A-4ECC-A381-6678FB2DAD54}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) ==================== Restore Points ========================= 21-12-2019 21:54:55 Scheduled Checkpoint 20-01-2020 02:26:46 Scheduled Checkpoint 27-01-2020 03:35:29 Scheduled Checkpoint ==================== Faulty Device Manager Devices ============ Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Fingerprint Sensor Description: Fingerprint Sensor Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Base System Device Description: Base System Device Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ======================== Application errors: ================== Error: (03/02/2020 06:15:56 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PAPA) Description: Activation of app winstore_cw5n1h2txyewy!Windows.Store failed with error: -2144927142 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (03/02/2020 06:15:56 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program WWAHost.exe version 6.3.9600.17031 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: d24 Start Time: 01d5f0493947cd5c Termination Time: 4294967295 Application Path: C:\Windows\System32\WWAHost.exe Report Id: 810a4bbc-5c3c-11ea-828f-002713343a56 Faulting package full name: winstore_1.0.0.0_neutral_neutral_cw5n1h2txyewy Faulting package-relative application ID: Windows.Store Error: (03/02/2020 06:15:51 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2486) (User: PAPA) Description: App winstore_1.0.0.0_neutral_neutral_cw5n1h2txyewy+Windows.Store did not launch within its allotted time. Error: (02/28/2020 12:39:52 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code. Error: (02/27/2020 04:18:13 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: skydrive.exe, version: 6.3.9600.17484, time stamp: 0x545d76bd Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0x00000000 Fault offset: 0x0000000000000000 Faulting process id: 0x1114 Faulting application start time: 0x01d5ed78bd3cd471 Faulting application path: C:\Windows\System32\skydrive.exe Faulting module path: unknown Report Id: fccfc0d4-596b-11ea-828e-002713343a56 Faulting package full name: Faulting package-relative application ID: Error: (02/26/2020 04:20:02 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: skydrive.exe, version: 6.3.9600.17484, time stamp: 0x545d76bd Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0x00000000 Fault offset: 0x0000000000000000 Faulting process id: 0x1614 Faulting application start time: 0x01d5ecafd3283424 Faulting application path: C:\Windows\System32\skydrive.exe Faulting module path: unknown Report Id: 134ef253-58a3-11ea-828e-002713343a56 Faulting package full name: Faulting package-relative application ID: Error: (02/26/2020 04:58:58 AM) (Source: Perflib) (EventID: 1008) (User: ) Description: The Open Procedure for service "WmiApRpl" in DLL "C:\Windows\system32\wbem\wmiaprpl.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code. Error: (02/26/2020 04:58:51 AM) (Source: Perflib) (EventID: 1023) (User: ) Description: Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. System errors: ============= Error: (02/27/2020 04:27:58 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY) Description: DCOM got error "1053" attempting to start the service gupdate with arguments "/comsvc" in order to run the server: {4EB61BAC-A3B6-4760-9581-655041EF4D69} Error: (02/27/2020 04:27:57 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Услуга на Google Актуализация (gupdate) service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. Error: (02/27/2020 04:27:57 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (30000 milliseconds) while waiting for the Услуга на Google Актуализация (gupdate) service to connect. Error: (02/27/2020 04:18:47 PM) (Source: DCOM) (EventID: 10010) (User: PAPA) Description: The server {1B1F472E-3221-4826-97DB-2C2324D389AE} did not register with DCOM within the required timeout. Error: (02/26/2020 04:21:21 PM) (Source: DCOM) (EventID: 10010) (User: PAPA) Description: The server {1B1F472E-3221-4826-97DB-2C2324D389AE} did not register with DCOM within the required timeout. Error: (02/25/2020 04:19:39 PM) (Source: DCOM) (EventID: 10010) (User: PAPA) Description: The server {1B1F472E-3221-4826-97DB-2C2324D389AE} did not register with DCOM within the required timeout. Error: (02/21/2020 04:23:25 PM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Peer Name Resolution Protocol service, but this action failed with the following error: An instance of the service is already running. Error: (02/21/2020 04:21:26 PM) (Source: DCOM) (EventID: 10010) (User: PAPA) Description: The server {1B1F472E-3221-4826-97DB-2C2324D389AE} did not register with DCOM within the required timeout. Windows Defender: =================================== Date: 2020-03-02 14:49:21.815 Description: Windows Defender has detected malware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:BAT/AutoKms.S!MTB&threatid=2147743496&enterprise=0 Name: HackTool:BAT/AutoKms.S!MTB ID: 2147743496 Severity: High Category: Tool Path: file:_C:\Users\ВЕСКО\Documents\windows8.cmd Detection Origin: Local machine Detection Type: Concrete Detection Source: Real-Time Protection Process Name: C:\Users\ВЕСКО\Downloads\FRST64.exe Signature Version: AV: 1.311.394.0, AS: 1.311.394.0, NIS: 119.0.0.0 Engine Version: AM: 1.1.16800.2, NIS: 2.1.14600.4 Date: 2020-02-24 16:49:50.613 Description: Windows Defender has detected malware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=Program:Win32/Vigram.A&threatid=232718&enterprise=0 Name: Program:Win32/Vigram.A ID: 232718 Severity: Severe Category: Potentially Unwanted Software Path: file:_C:\Users\ВЕСКО\Downloads\SafeIP.exe Detection Origin: Local machine Detection Type: FastPath Detection Source: System Process Name: Unknown Signature Version: AV: 1.309.1602.0, AS: 1.309.1602.0, NIS: 119.0.0.0 Engine Version: AM: 1.1.16700.3, NIS: 2.1.14600.4 Date: 2020-02-21 04:27:22.929 Description: Windows Defender has detected malware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=Program:Win32/Vigram.A&threatid=232718&enterprise=0 Name: Program:Win32/Vigram.A ID: 232718 Severity: Severe Category: Potentially Unwanted Software Path: file:_C:\Users\ВЕСКО\Downloads\SafeIP (1).exe;file:_C:\Users\ВЕСКО\Downloads\SafeIP.exe;webfile:_C:\Users\ВЕСКО\Downloads\SafeIP (1).exe|https://www.freesafeip.com/SafeIP.exe|chrome.exe;webfile:_C:\Users\ВЕСКО\Downloads\SafeIP.exe|https://www.freesafeip.com/SafeIP.exe|chrome.exe Detection Origin: Internet Detection Type: FastPath Detection Source: Downloads and attachments Process Name: Unknown Signature Version: AV: 1.309.1348.0, AS: 1.309.1348.0, NIS: 119.0.0.0 Engine Version: AM: 1.1.16700.3, NIS: 2.1.14600.4 Date: 2020-02-21 04:27:20.517 Description: Windows Defender has detected malware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=Program:Win32/Vigram.A&threatid=232718&enterprise=0 Name: Program:Win32/Vigram.A ID: 232718 Severity: Severe Category: Potentially Unwanted Software Path: file:_C:\Users\ВЕСКО\Downloads\SafeIP.exe;webfile:_C:\Users\ВЕСКО\Downloads\SafeIP.exe|https://www.freesafeip.com/SafeIP.exe|chrome.exe Detection Origin: Internet Detection Type: FastPath Detection Source: Downloads and attachments Process Name: Unknown Signature Version: AV: 1.309.1348.0, AS: 1.309.1348.0, NIS: 119.0.0.0 Engine Version: AM: 1.1.16700.3, NIS: 2.1.14600.4 Date: 2020-02-21 04:24:18.037 Description: Windows Defender has detected malware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=Program:Win32/Vigram.A&threatid=232718&enterprise=0 Name: Program:Win32/Vigram.A ID: 232718 Severity: Severe Category: Potentially Unwanted Software Path: file:_C:\Users\ВЕСКО\Downloads\SafeIP.exe;webfile:_C:\Users\ВЕСКО\Downloads\SafeIP.exe|https://www.freesafeip.com/SafeIP.exe|chrome.exe Detection Origin: Internet Detection Type: FastPath Detection Source: Downloads and attachments Process Name: Unknown Signature Version: AV: 1.309.1348.0, AS: 1.309.1348.0, NIS: 119.0.0.0 Engine Version: AM: 1.1.16700.3, NIS: 2.1.14600.4 Date: 2020-03-02 12:48:53.550 Description: Windows Defender has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.311.300.0 Update Source: Microsoft Update Server Signature Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.16800.2 Error code: 0x80070422 Error description: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Date: 2020-02-29 12:48:53.098 Description: Windows Defender has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.311.96.0 Update Source: Microsoft Update Server Signature Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.16800.2 Error code: 0x80070422 Error description: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Date: 2020-02-27 16:25:58.491 Description: Windows Defender has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.311.51.0 Update Source: Microsoft Update Server Signature Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.16800.2 Error code: 0x80070422 Error description: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Date: 2020-02-26 02:54:12.140 Description: Windows Defender has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.309.1602.0 Update Source: Microsoft Update Server Signature Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.16700.3 Error code: 0x80070422 Error description: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Date: 2020-02-24 16:32:59.871 Description: Windows Defender has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.309.1475.0 Update Source: Microsoft Update Server Signature Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.16700.3 Error code: 0x80070422 Error description: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. CodeIntegrity: =================================== Date: 2020-03-02 14:42:10.317 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\SafeIPs64.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2020-03-02 14:42:09.709 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\SafeIPs64.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2019-12-01 14:45:58.203 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\SafeIPs64.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2019-12-01 14:45:57.468 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\SafeIPs64.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2019-10-27 11:05:31.653 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\SafeIPs64.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2019-10-27 11:05:30.955 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\SafeIPs64.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2019-10-15 17:13:52.723 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\SafeIPs64.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2019-10-15 17:13:51.566 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\SafeIPs64.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== BIOS: Hewlett-Packard 68PCU Ver. F.20 12/08/2011 Motherboard: Hewlett-Packard 30DB Processor: Intel(R) Core(TM)2 Duo CPU P8600 @ 2.40GHz Percentage of memory in use: 57% Total physical RAM: 3000.26 MB Available physical RAM: 1289.71 MB Total Virtual: 7000.26 MB Available Virtual: 5244.19 MB ==================== Drives ================================ Drive 😄 () (Fixed) (Total:365.12 GB) (Free:324.76 GB) NTFS Drive e: () (Fixed) (Total:100.1 GB) (Free:80.41 GB) NTFS \\?\Volume{bce0ecb4-bba7-11e9-8250-806e6f6e6963}\ (Резервирана за системата) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS \\?\Volume{bce0ecb7-bba7-11e9-8250-806e6f6e6963}\ () (Fixed) (Total:0.44 GB) (Free:0.16 GB) NTFS ==================== MBR & Partition Table ==================== ========================================================== Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 0FD73A73) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=100.1 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=365.1 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=450 MB) - (Type=27) ==================== End of Addition.txt =======================
  10. Здравейте. От няколко дни след като си рестартирам компа ми се появява cmd команда и автоматично и ми пуска хрома и отваря този сайт - dinoraptzor.org. С уин 10 съм, но нямам malwarebytes, а уж май би трябвало да имам? Сканирах с друга програма, но не успя да го намери и да го отстрани. Някакви съвети?
  11. Постоянно работи на 1-2% процесора на процес "system" в task manager. Също през няколко секунди се появява и процеса "registry" и от време на време се появява и "Service Host: Windows Event Log". Това нормално ли е? От какво е? Вирус ли е? Или се е повредила системата и трябва да я преинсталирам? Използвам Windows 10 Pro 64 bit 1909. Благодаря. Прикачам нужните файлове. Addition.txt FRST.txt
  12. Здравейте, понеже нещо товареше системата при броузване - мишката и станицата забива, прескача и т.н. реших да пусна една проверка с Malwarebytes но при инсталиране връща грешка след няколко рестарта и опити - прикаченият файл . Свалена е от оригиналният сайт, включително и през препратката от важната тема тук. Често имам над 15-20 таба отворени постоянно, до сега не е имало такъв проблем със забиване - курсора не движи после го показва направо на новата позиция понеже го мърдам постоянно докато прескочи. От известно време, машината изпиуква неясно защо 2-5 пъти дневно, което май се появи след като махнах батерията - единият елемент е подут значително - може би двоен размер в средата, и един има леко подут. Махнах батерията "от страх" да не стане нещо но тъй като явно не ми се занимава конкретно да вземам батерия сега и отново я монтирах поне да не изключва при спиране на ток или друго. Също така не можах да открия темата за разлини програми които пазят от копачи. В няколко теми бяха писали, че има отделна тема за това но така и не я открих, а исках да пусна поне проверка защото свалих някои игри от зеленчука.org Прикачам логовете от сканирането съгласно правилата на раздела с надежда да са "чисти" Addition.txt FRST.txt
  13. Здравейте! Сложих флашка на компютър с Уиндоус 8, написа ми , че е открит злонамерен вирус и всичко от флашката изчезна. може ли да възстановя файловете?
  14. Здравейте, от месец се опитавм да се оправя с един кмопютър. Излизат долу вдясно едни прозорци. Сканирал съм със следните туулчета Hitman Pro - trial Malwarebytes Premium - trial adwcleaner ZHPCleaner Дотук не успях да ги премахна. Гледам и спирам разширенията в google chrome, но пак не става.
  15. Здравейте, след отварянето на файл във формат .doc получен по вайбър, се оказа, че е вирус, който антивирусната засече, но не съм сигурен дали успя да изчисти. Иначе системата си е напълно стабилна. Addition.txt FRST.txt
  16. Здравейте! Накратко - Бях инфектиран от зловреден софтуер с името DJVU ransomware. Вече е напълно премахнат, след пълно дефрагментиране на двата диска C, D и инсталация на нов Windows 10. Всички лични снимки са криптирани с формат. RIGH. Някакви решения как мога да оправя файловете си? Около 20GB снимки имам, качени в OneDrive с името тип на файла. RIGH ЗА РЕШЕНИЕ НА ПРОБЛЕМА ЩЕ СЕ ЗАПЛАТИ СЪОТВЕТНА СУМА ЛИЧНО ОТ МЕН.
  17. Здравейте. Интересува ме, дали има нещо притиснително според логовете от farbar. Просто профилактично. Farbar logs.7z
  18. Здравейте, преди два дена някъде забелязах яко лагене на моменти, мишката едва се влачеше и процесора забелязах че качва на 100%, поня че първите няколко пъти като го забелязах това антивирусната (вградената на win 10pro) изписва че нещо е хванато под карантира, но да речем след няколко часа пак по същия начин, системата забавя и така, общо траеше около 20-25сек. По време на този проблем имах и проблем с geforce experianc-а на видео драйвера, за това и направих тема в отдел драйвери, както и да е проблема с драйвера е решен ала да видим какво ще правим по въпроса. Пиша ви след като колега ми препоръча да изтегля malwarebytes и да сканирам, така и направих, активирах 14денния период и сканирах и намери няколко съмнителни открития, всички поставени под карантина. Сега знам че не съм сканирал както е по ред със програмите посочени от вас, но искам да ви покажа лог-а на malwarebytes и ако кажете ще следвам стъпките както сте посочили в темата за премахване на зловреден софтуер, надявам се че не е проблем че не съм следвал както трябва стъпка по стъпка, ако е извинете. ето го лог-а: https://dox.abv.bg/download?id=d02deebbb7
  19. Здравейте!От известно време имам забавяне и забиване на системата и затова вчера и днес пуснах няколко сканирвания с две различни версии на Eset-a.С най-новата версия откри 4 инфектирани файла.С другата при първото сканирване включих и дял D и също 4.При второто без дял D,3 такива.Чудя се дали трябва да се трият тези файлове.Това са логовете. Eset Online Scanner-07.09.2019.txt Eset Online Scanner-08.09.2019.txt
  20. Здравейте, повече от година изполвам емuлатора за Android под Windows MEmu Play. Седмица след автоматичното му обновяване до версия 6.2.3 антивируса ми - Avira започна почти постоянно да ми изкарва прозорец за засечен Malwarе. Почти година не съм инсталирал нищо ново и за това мисля че гадините са се промъкнали с ъпдейта. Моля за помощ. Предварително Ви благодаря.
  21. Здравейте. Имам един компютър който е доставен преди години от фирма свързана със софтуер за управление на дадена апаратура. Вчера не искаше да тръгне. При пускането на машината започва да зарежда в началото както трябва докато стигне до момента в който трябва да покаже десктопа. Но вместо десктоп, показваше съобщение,че Windows не е легален и трябва да го активирам. Имаше две възможности YES или NO, но която и да избера нищо не се променяше. Съобщението се показваше отново и не ме да вляза. След няколко многократни опита по някакъв начин влязох в системата, но тя работеше много бавно. Каквото и да отворя водеше до затормозяване на компа. Сега даже през Хром не успях да сваля Farbar, даваше, ми че е вирус. Успях с много зор да го сваля през Мозила. Сканирах и с Касперски вчера. FRST.txt Addition.txt report.txt
  22. Здравейте, преди ден антивирусната ми програма непрекъснато даваше известия за троянец, който се опитва да се свърже - "Website Blocked Due to Trojan". При сканиране обаче, не се откриваше нищо. При днешното пускане на компютъра забелязах, че работи изключи бавно, непрекъснато забива и т.н. Пробвах да сканирам - антивирусната отказа да стартира. Когато цъкна рестарт всeки път излиза съобщение "Preparing to configure your computer", и отново лаптопът работи видимо затруднено. Нямам диск за операционна система, по-долу съм прикачил файловете от сканирането с Farbar. FRST.txt Addition.txt
  23. Здравейте, от известно време се появи следния проблем - малко след зареждането на Windows 8.1, започва самоволно стартиране на браузъра по подразбиране, като се отварят по 4-5 прозореца, а понякога и по повече. Прегледах някои теми за сходни проблеми във форума и трябва да отбележа една съществена разлика - при мен браузера се стартира с началния си екран и НЕ тръгва да зарежда някаква страница в интернет... просто си стои на началната страница и стартира още прозорци. След като успях да направя така, че да нямам браузър по default започна да се отваря диалогов прозорец с надпис: "How do you want to open this type of link (http)?", като отдолу са изредени браузерите и win store. Други неща, които се случват: отваряне на десния панел на десктопа на секцията "Search", превключване м/у различни отворени прозорци, отваряне на нови табове при работещ браузър, обхождане на менютата на отворени прозорци, и всичко това придружено със звуков сигнал (бибкане). До момента сканирано с: - Windows defender; - Kasperski Free; - Dr. Web; - Malwarebytes... и всички казват, че системата е чиста... Това е в общи линии. Прилагам резултатите от FRST, благодаря предварително Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 03.03.2019 01 Ran by Kire (administrator) on KIRE-PC (04-03-2019 11:39:00) Running from C:\Users\Kire\Desktop Loaded Profiles: Kire (Available Profiles: Kire) Platform: Windows 8.1 Enterprise (Update) (X64) Language: English (United States) Default browser: "C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe" "%1" Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\atiesrxx.exe (Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\avp.exe (Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksde.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\atieclxx.exe (Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\avpui.exe (Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksdeui.exe (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Microsoft Corporation) [File not signed] C:\Program Files\Windows Sidebar\sidebar.exe (Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe (Opera Software AS -> Opera Software) C:\Program Files (x86)\Opera\58.0.3135.79\opera.exe (Opera Software AS -> Opera Software) C:\Program Files (x86)\Opera\58.0.3135.79\opera_crashreporter.exe (Opera Software AS -> Opera Software) C:\Program Files (x86)\Opera\58.0.3135.79\opera.exe (Opera Software AS -> Opera Software) C:\Program Files (x86)\Opera\58.0.3135.79\opera.exe (Opera Software AS -> Opera Software) C:\Program Files (x86)\Opera\58.0.3135.79\opera.exe (Opera Software AS -> Opera Software) C:\Program Files (x86)\Opera\58.0.3135.79\opera.exe (Opera Software AS -> Opera Software) C:\Program Files (x86)\Opera\58.0.3135.79\opera.exe (Opera Software AS -> Opera Software) C:\Program Files (x86)\Opera\58.0.3135.79\opera.exe (Opera Software AS -> Opera Software) C:\Program Files (x86)\Opera\58.0.3135.79\opera.exe (Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\reader_sl.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8464600 2015-04-07] (Realtek Semiconductor Corp -> Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1392856 2015-03-20] (Realtek Semiconductor Corp -> Realtek Semiconductor) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-12-16] (Oracle America, Inc. -> Oracle Corporation) HKU\S-1-5-21-1687209997-659643034-1432533341-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd -> Disc Soft Ltd) HKU\S-1-5-21-1687209997-659643034-1432533341-1001\...\Run: [Sidebar] => C:\Program Files\Windows Sidebar\sidebar.exe [1475072 2013-10-02] (Microsoft Corporation) [File not signed] HKU\S-1-5-21-1687209997-659643034-1432533341-1001\...\Run: [Viber] => C:\Users\Kire\AppData\Local\Viber\Viber.exe [35950152 2018-02-22] (Viber Media S.à r.l. -> Viber Media S.Ã r.l.) HKU\S-1-5-21-1687209997-659643034-1432533341-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [19646312 2019-02-12] (Piriform Software Ltd -> Piriform Software Ltd) HKU\S-1-5-21-1687209997-659643034-1432533341-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Mystify.scr [133632 2014-11-21] (Microsoft Windows -> Microsoft Corporation) Startup: C:\Users\Kire\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Изпращане в OneNote.lnk [2018-04-21] ShortcutTarget: Изпращане в OneNote.lnk -> C:\Program Files\Microsoft Office\Office15\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 217.9.239.90 217.9.239.94 Tcpip\..\Interfaces\{0AFEE81C-413D-4C4C-87C4-B73D21E67655}: [DhcpNameServer] 217.9.239.90 217.9.239.94 Tcpip\..\Interfaces\{8D5336D0-E0A6-456B-BDA5-1F85837A1179}: [NameServer] 8.8.8.8,8.8.4.4 Internet Explorer: ================== HKU\S-1-5-21-1687209997-659643034-1432533341-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.bg/ HKU\S-1-5-21-1687209997-659643034-1432533341-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2014-01-23] (Microsoft Corporation -> Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2014-01-23] (Microsoft Corporation -> Microsoft Corporation) BHO: Kaspersky Protection -> {EC1E29BB-F56A-45D8-B023-D3EF710FA0E0} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\x64\IEExt\ie_plugin.dll [2019-02-21] (Kaspersky Lab -> AO Kaspersky Lab) BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2014-01-21] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\ssv.dll [2019-01-24] (Oracle America, Inc. -> Oracle Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2014-01-21] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\jp2ssv.dll [2019-01-24] (Oracle America, Inc. -> Oracle Corporation) BHO-x32: Kaspersky Protection -> {EC1E29BB-F56A-45D8-B023-D3EF710FA0E0} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\IEExt\ie_plugin.dll [2019-02-21] (Kaspersky Lab -> AO Kaspersky Lab) Toolbar: HKLM - Kaspersky Protection Toolbar - {C500C267-63BF-451F-8797-4D720C9A2ED9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\x64\IEExt\ie_plugin.dll [2019-02-21] (Kaspersky Lab -> AO Kaspersky Lab) Toolbar: HKLM-x32 - Kaspersky Protection Toolbar - {C500C267-63BF-451F-8797-4D720C9A2ED9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\IEExt\ie_plugin.dll [2019-02-21] (Kaspersky Lab -> AO Kaspersky Lab) DPF: HKLM-x32 {A996E48C-D3DC-4244-89F7-AFA33EC60679} hxxps://ebb.ubb.bg/CAPICOM/capicom.cab Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2014-01-23] (Microsoft Corporation -> Microsoft Corporation) FireFox: ======== FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\FFExt\light_plugin_firefox\addon.xpi FF Extension: (Kaspersky Protection) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\FFExt\light_plugin_firefox\addon.xpi [2019-02-21] FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\FFExt\light_plugin_firefox\addon.xpi FF HKU\S-1-5-21-1687209997-659643034-1432533341-1001\...\Firefox\Extensions: [[email protected]] - C:\Users\Kire\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi => not found FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.201.2 -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\dtplugin\npDeployJava1.dll [2019-01-24] (Oracle America, Inc. -> Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.201.2 -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\plugin2\npjp2.dll [2019-01-24] (Oracle America, Inc. -> Oracle Corporation) FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2014-01-21] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-21] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-02-01] (Adobe Systems, Incorporated -> Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-1687209997-659643034-1432533341-1001: @acestream.net/acestreamplugin,version=3.1.28 -> C:\Users\Kire\AppData\Roaming\ACEStream\player\npace_plugin.dll [No File] Chrome: ======= CHR HKLM\...\Chrome\Extension: [amkpcclbbgegoafihnpgomddadjhcadd] - hxxps://chrome.google.com/webstore/detail/amkpcclbbgegoafihnpgomddadjhcadd CHR HKU\S-1-5-21-1687209997-659643034-1432533341-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [mjbepbhonbojpoaenhckjocchgfiaofo] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [amkpcclbbgegoafihnpgomddadjhcadd] - hxxps://chrome.google.com/webstore/detail/amkpcclbbgegoafihnpgomddadjhcadd ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [297888 2016-11-08] (Advanced Micro Devices, Inc. -> AMD) R2 AVP19.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\avp.exe [619640 2018-02-28] (Kaspersky Lab -> AO Kaspersky Lab) S3 klvssbridge64_19.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\x64\vssbridge64.exe [414352 2019-02-21] (Kaspersky Lab -> AO Kaspersky Lab) R2 KSDE3.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksde.exe [617016 2018-02-28] (Kaspersky Lab -> AO Kaspersky Lab) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6562472 2019-02-01] (Malwarebytes Corporation -> Malwarebytes) S2 MxService; C:\Program Files (x86)\Maxthon5\Bin\MxService.exe [144152 2018-11-21] (Maxthon Technology Co, Ltd. -> Maxthon International ltd.) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-01-12] (Microsoft Corporation -> Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2017-01-12] (Microsoft Corporation -> Microsoft Corporation) ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [21160 2012-09-23] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) R3 amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [26567696 2016-11-08] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.) R3 amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [528800 2016-11-08] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) R0 cm_km; C:\Windows\System32\DRIVERS\cm_km.sys [243400 2018-01-27] (Kaspersky Lab -> AO Kaspersky Lab) R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2016-04-12] (Disc Soft Ltd -> Disc Soft Ltd) R3 e1dexpress; C:\Windows\system32\DRIVERS\e1d64x64.sys [529392 2015-08-05] (Intel(R) Intel Network Drivers -> Intel Corporation) R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [153328 2019-01-08] (Malwarebytes Corporation -> Malwarebytes) R3 IntcAzAudAddService; C:\Windows\system32\drivers\RTDVHD64.sys [2740056 2015-04-07] (Realtek Semiconductor Corp -> Realtek Semiconductor Corp.) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [528576 2018-02-20] (Kaspersky Lab -> AO Kaspersky Lab) R0 klbackupdisk; C:\Windows\System32\DRIVERS\klbackupdisk.sys [73416 2018-12-05] (Kaspersky Lab -> AO Kaspersky Lab) R1 klbackupflt; C:\Windows\System32\DRIVERS\klbackupflt.sys [123152 2018-12-05] (Kaspersky Lab -> AO Kaspersky Lab) R1 kldisk; C:\Windows\system32\DRIVERS\kldisk.sys [89168 2018-12-05] (Kaspersky Lab -> AO Kaspersky Lab) S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [29208 2017-03-30] (Microsoft Windows Early Launch Anti-malware Publisher -> AO Kaspersky Lab) R3 klflt; C:\Windows\system32\DRIVERS\klflt.sys [219744 2019-02-21] (Kaspersky Lab -> AO Kaspersky Lab) R1 KLHK; C:\Windows\System32\drivers\klhk.sys [1214752 2019-02-21] (Kaspersky Lab -> AO Kaspersky Lab) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [1113696 2019-02-21] (Kaspersky Lab -> AO Kaspersky Lab) R1 klim6; C:\Windows\system32\DRIVERS\klim6.sys [57032 2018-02-12] (Kaspersky Lab -> AO Kaspersky Lab) R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [58048 2018-01-15] (Kaspersky Lab -> AO Kaspersky Lab) R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [83496 2017-12-11] (Kaspersky Lab -> AO Kaspersky Lab) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [50648 2017-05-30] (Kaspersky Lab -> AO Kaspersky Lab) S3 klpnpflt; C:\Windows\system32\DRIVERS\klpnpflt.sys [45768 2018-12-05] (Kaspersky Lab -> AO Kaspersky Lab) R3 kltap; C:\Windows\system32\DRIVERS\kltap.sys [48080 2018-02-12] (AnchorFree Inc -> The OpenVPN Project) S4 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [100552 2018-02-17] (Kaspersky Lab -> AO Kaspersky Lab) R1 klwtp; C:\Windows\system32\DRIVERS\klwtp.sys [176976 2018-12-05] (Kaspersky Lab -> AO Kaspersky Lab) R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [203968 2018-02-24] (Kaspersky Lab -> AO Kaspersky Lab) R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [198512 2019-02-24] (Malwarebytes Corporation -> Malwarebytes) R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [127136 2019-02-24] (Malwarebytes Corporation -> Malwarebytes) R3 MBAMProtection; C:\Windows\system32\DRIVERS\mbam.sys [72864 2019-02-24] (Malwarebytes Corporation -> Malwarebytes) R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [274416 2019-02-24] (Malwarebytes Corporation -> Malwarebytes) R3 MBAMWebProtection; C:\Windows\system32\DRIVERS\mwac.sys [114040 2019-02-24] (Malwarebytes Corporation -> Malwarebytes) S3 s115bus; C:\Windows\System32\drivers\s115bus.sys [108296 2007-04-23] (MCCI Corporation -> MCCI Corporation) S3 s115mdfl; C:\Windows\system32\DRIVERS\s115mdfl.sys [19720 2007-04-23] (MCCI Corporation -> MCCI Corporation) S3 s115mdm; C:\Windows\system32\DRIVERS\s115mdm.sys [144648 2007-04-23] (MCCI Corporation -> MCCI Corporation) S3 s115mgmt; C:\Windows\system32\DRIVERS\s115mgmt.sys [126216 2007-04-23] (MCCI Corporation -> MCCI Corporation) S3 s115obex; C:\Windows\system32\DRIVERS\s115obex.sys [123656 2007-04-23] (MCCI Corporation -> MCCI Corporation) S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [46600 2017-02-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [274776 2017-01-12] (Microsoft Windows -> Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [117592 2017-01-12] (Microsoft Windows -> Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2019-03-04 11:39 - 2019-03-04 11:39 - 000016906 _____ C:\Users\Kire\Desktop\FRST.txt 2019-03-04 11:38 - 2019-03-04 11:39 - 000000000 ____D C:\FRST 2019-03-04 11:35 - 2019-03-04 11:35 - 002434560 _____ (Farbar) C:\Users\Kire\Desktop\FRST64.exe 2019-02-24 16:56 - 2019-02-24 16:56 - 000072864 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2019-02-24 16:55 - 2019-02-24 16:55 - 000274416 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys 2019-02-24 16:55 - 2019-02-24 16:55 - 000127136 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys 2019-02-24 16:55 - 2019-02-24 16:55 - 000114040 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys 2019-02-24 16:47 - 2019-02-24 16:51 - 000000000 ____D C:\AdwCleaner 2019-02-24 16:44 - 2019-02-24 16:44 - 000002305 _____ C:\Users\Kire\Desktop\mbma.txt 2019-02-24 16:32 - 2019-02-24 16:32 - 000198512 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys 2019-02-24 16:32 - 2019-02-24 16:32 - 000001843 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2019-02-24 16:32 - 2019-02-24 16:32 - 000000000 ____D C:\Users\Kire\AppData\Local\mbamtray 2019-02-24 16:32 - 2019-02-24 16:32 - 000000000 ____D C:\Users\Kire\AppData\Local\mbam 2019-02-24 16:32 - 2019-02-24 16:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2019-02-24 16:32 - 2019-01-08 15:32 - 000153328 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys 2019-02-24 16:31 - 2019-02-24 16:31 - 000000000 ____D C:\ProgramData\Malwarebytes 2019-02-24 16:31 - 2019-02-24 16:31 - 000000000 ____D C:\Program Files\Malwarebytes 2019-02-22 00:47 - 2019-02-22 00:47 - 000020476 _____ C:\Windows\ntbtlog.txt 2019-02-22 00:38 - 2019-02-22 01:49 - 000000000 ____D C:\Windows\pss 2019-02-21 23:52 - 2019-02-21 23:52 - 000071912 _____ C:\Users\Kire\Documents\cc_20190221_235210.reg 2019-02-21 23:44 - 2019-02-22 00:56 - 000004128 _____ C:\Windows\System32\Tasks\CCleaner Update 2019-02-21 23:44 - 2019-02-21 23:44 - 000002804 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2019-02-21 23:44 - 2019-02-21 23:44 - 000000794 _____ C:\Users\Public\Desktop\CCleaner.lnk 2019-02-21 23:44 - 2019-02-21 23:44 - 000000000 ____D C:\Program Files\CCleaner 2019-02-21 23:43 - 2019-02-21 23:43 - 019385224 _____ (Piriform Software Ltd) C:\Users\Kire\Desktop\cctrialsetup.exe 2019-02-21 23:40 - 2019-02-21 23:40 - 000001446 _____ C:\Users\Kire\Desktop\uTorrent.exe - Shortcut.lnk 2019-02-21 23:36 - 2019-02-21 23:36 - 000000272 _____ C:\Users\Kire\Desktop\nod.txt 2019-02-21 21:31 - 2019-02-21 21:31 - 000000000 ____D C:\Users\Kire\AppData\Local\ESET 2019-02-21 21:30 - 2019-02-21 21:30 - 007657592 _____ (ESET spol. s r.o.) C:\Users\Kire\Desktop\esetonlinescanner_enu.exe 2019-02-21 21:28 - 2019-02-21 21:30 - 000000000 ____D C:\ProgramData\F-Secure 2019-02-21 21:27 - 2019-02-22 00:28 - 000000000 ____D C:\Users\Kire\AppData\Local\FSDART 2019-02-21 21:27 - 2019-02-21 21:27 - 009603600 _____ (F-Secure Corporation) C:\Users\Kire\Desktop\F-SecureOnlineScanner.exe 2019-02-21 21:27 - 2019-02-21 21:27 - 000000000 ____D C:\Users\Kire\AppData\Local\F-Secure 2019-02-21 20:27 - 2019-02-21 20:27 - 000003032 _____ C:\Windows\System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} 2019-02-21 20:27 - 2019-02-21 20:27 - 000001196 _____ C:\Users\Public\Desktop\Kaspersky Secure Connection.lnk 2019-02-21 20:27 - 2019-02-21 20:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Secure Connection 2019-02-21 20:27 - 2019-02-21 20:27 - 000000000 ____D C:\Program Files\Common Files\AV 2019-02-21 20:26 - 2019-03-04 11:26 - 000000000 ____D C:\ProgramData\Kaspersky Lab 2019-02-21 20:26 - 2019-02-21 20:27 - 000000000 ____D C:\Program Files (x86)\Kaspersky Lab 2019-02-21 20:26 - 2019-02-21 20:26 - 001214752 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klhk.sys 2019-02-21 20:26 - 2019-02-21 20:26 - 001113696 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klif.sys 2019-02-21 20:26 - 2019-02-21 20:26 - 000219744 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klflt.sys 2019-02-21 20:26 - 2019-02-21 20:26 - 000152960 _____ (AO Kaspersky Lab) C:\Windows\system32\klhkum.dll 2019-02-21 20:26 - 2019-02-21 20:26 - 000002051 _____ C:\Users\Public\Desktop\Kaspersky Free.lnk 2019-02-21 20:26 - 2019-02-21 20:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Free 2019-02-21 20:26 - 2013-05-06 08:13 - 000110176 _____ (Kaspersky Lab ZAO) C:\Windows\system32\klfphc.dll 2019-02-21 20:24 - 2019-02-21 20:25 - 000000000 ____D C:\ProgramData\Kaspersky Lab Setup Files 2019-02-21 20:24 - 2019-02-21 20:24 - 002536320 _____ (Kaspersky Lab) C:\Users\Kire\Desktop\startup_14460.exe 2019-02-19 23:28 - 2019-02-19 23:28 - 000000000 ____D C:\Users\Kire\Doctor Web 2019-02-19 23:28 - 2019-02-19 23:28 - 000000000 ____D C:\ProgramData\Doctor Web 2019-02-19 23:27 - 2019-02-19 23:28 - 184226296 _____ C:\Users\Kire\Desktop\5xdzsvd7.exe 2019-02-19 21:05 - 2019-02-19 21:05 - 000007598 _____ C:\Users\Kire\AppData\Local\Resmon.ResmonCfg 2019-02-14 20:08 - 2019-01-26 03:02 - 025736192 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2019-02-14 20:07 - 2019-02-06 04:07 - 003323392 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2019-02-14 20:07 - 2019-02-06 03:43 - 003616768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2019-02-14 20:07 - 2019-02-06 02:53 - 002780160 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2019-02-14 20:07 - 2019-02-06 02:44 - 002464256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2019-02-14 20:07 - 2019-01-26 02:38 - 002902528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2019-02-14 20:07 - 2019-01-26 02:36 - 000576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2019-02-14 20:07 - 2019-01-26 02:32 - 005778944 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2019-02-14 20:07 - 2019-01-26 02:27 - 020279808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2019-02-14 20:07 - 2019-01-26 02:24 - 000790016 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2019-02-14 20:07 - 2019-01-26 02:06 - 000498176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2019-02-14 20:07 - 2019-01-26 02:03 - 002295808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2019-02-14 20:07 - 2019-01-26 01:57 - 000663040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2019-02-14 20:07 - 2019-01-26 01:56 - 001033216 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2019-02-14 20:07 - 2019-01-26 01:48 - 000809472 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2019-02-14 20:07 - 2019-01-26 01:46 - 015283712 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2019-02-14 20:07 - 2019-01-26 01:36 - 000880640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll 2019-02-14 20:07 - 2019-01-26 01:34 - 004858880 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2019-02-14 20:07 - 2019-01-26 01:34 - 004494336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2019-02-14 20:07 - 2019-01-26 01:31 - 000696320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2019-02-14 20:07 - 2019-01-26 01:29 - 013680640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2019-02-14 20:07 - 2019-01-26 01:22 - 001556480 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2019-02-14 20:07 - 2019-01-26 01:12 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2019-02-14 20:07 - 2019-01-26 01:11 - 004386304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2019-02-14 20:07 - 2019-01-26 01:08 - 001331200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2019-02-14 20:07 - 2019-01-26 01:06 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2019-02-14 20:07 - 2019-01-12 03:36 - 000058880 _____ (Microsoft Corporation) C:\Windows\system32\mf3216.dll 2019-02-14 20:07 - 2019-01-12 03:35 - 000044544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf3216.dll 2019-02-14 20:07 - 2019-01-12 03:18 - 000352768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd3x40.dll 2019-02-14 20:07 - 2019-01-09 08:36 - 001901688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2019-02-14 20:07 - 2019-01-09 08:27 - 002533920 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2019-02-14 20:07 - 2019-01-09 08:24 - 007371512 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2019-02-14 20:07 - 2019-01-09 05:34 - 001755136 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll 2019-02-14 20:07 - 2019-01-09 05:34 - 000134656 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.NetworkOperators.HotspotAuthentication.dll 2019-02-14 20:07 - 2019-01-09 05:21 - 001493504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll 2019-02-14 20:07 - 2019-01-09 05:21 - 000102400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.NetworkOperators.HotspotAuthentication.dll 2019-02-14 20:07 - 2019-01-08 06:54 - 000032896 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2019-02-14 20:07 - 2019-01-08 03:22 - 001311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjet40.dll 2019-02-14 20:07 - 2019-01-08 03:22 - 000313344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd2x40.dll 2019-02-14 20:07 - 2019-01-05 19:48 - 004168704 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2019-02-14 20:07 - 2019-01-05 19:47 - 000684032 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2019-02-14 20:07 - 2019-01-05 19:46 - 000243200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys 2019-02-14 20:07 - 2018-12-27 19:57 - 000805376 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll 2019-02-14 20:07 - 2018-12-27 18:30 - 000626176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll 2019-02-14 20:07 - 2018-12-08 18:01 - 000513376 _____ C:\Windows\SysWOW64\locale.nls 2019-02-14 20:07 - 2018-12-08 18:01 - 000513376 _____ C:\Windows\system32\locale.nls 2019-02-14 20:07 - 2018-12-02 12:08 - 000179712 _____ (Microsoft Corporation) C:\Windows\system32\itss.dll 2019-02-14 20:07 - 2018-12-01 18:44 - 000151040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\itss.dll 2019-02-14 20:07 - 2018-10-12 15:19 - 000998480 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll 2019-02-02 11:26 - 2019-02-02 11:26 - 000010752 _____ C:\Users\Kire\Desktop\report_structure.xls ==================== One month (modified) ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2019-03-04 11:38 - 2019-01-13 19:24 - 000005012 _____ C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for Kire-PC-Kire Kire-PC 2019-03-03 19:04 - 2016-04-14 13:11 - 000003860 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1460632245 2019-03-03 19:04 - 2016-04-14 13:10 - 000000000 ____D C:\Program Files (x86)\Opera 2019-02-26 21:35 - 2016-04-11 17:51 - 000003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1687209997-659643034-1432533341-1001 2019-02-26 20:14 - 2013-08-22 15:36 - 000000000 ____D C:\Windows\Inf 2019-02-24 17:00 - 2014-11-21 09:39 - 000865068 _____ C:\Windows\system32\PerfStringBackup.INI 2019-02-24 16:58 - 2016-04-14 13:17 - 000004422 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier 2019-02-24 16:58 - 2016-04-14 13:12 - 000000000 ____D C:\Users\Kire\AppData\Local\Adobe 2019-02-24 16:58 - 2013-08-22 17:36 - 000000000 ____D C:\Windows\SysWOW64\Macromed 2019-02-24 16:58 - 2013-08-22 17:36 - 000000000 ____D C:\Windows\system32\Macromed 2019-02-24 16:55 - 2013-08-22 16:45 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2019-02-24 16:54 - 2016-08-25 17:16 - 000065536 _____ C:\Windows\system32\spu_storage.bin 2019-02-22 00:39 - 2013-08-22 15:25 - 000262144 ___SH C:\Windows\system32\config\BBI 2019-02-21 23:51 - 2018-07-13 10:05 - 000000000 ____D C:\Users\Kire\AppData\Roaming\MPC-HC 2019-02-21 23:51 - 2018-02-28 15:49 - 000000000 ____D C:\Users\Kire\AppData\Roaming\TeamViewer 2019-02-21 23:51 - 2016-04-12 15:40 - 000000000 ____D C:\Users\Kire\AppData\Roaming\DAEMON Tools Lite 2019-02-21 23:51 - 2016-04-12 15:14 - 000000000 ____D C:\Users\Kire\AppData\Roaming\uTorrent 2019-02-21 23:50 - 2017-05-08 15:37 - 000000000 ____D C:\Windows\Minidump 2019-02-21 23:50 - 2016-04-12 04:38 - 000000000 ____D C:\Windows\Panther 2019-02-21 23:39 - 2016-04-12 15:15 - 000000000 ____D C:\Program Files (x86)\uTorrent 2019-02-21 20:32 - 2016-04-14 13:13 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2019-02-21 20:26 - 2013-08-22 17:36 - 000000000 ___HD C:\Windows\ELAMBKUP 2019-02-21 20:26 - 2013-08-22 15:25 - 000262144 ___SH C:\Windows\system32\config\ELAM 2019-02-20 02:39 - 2016-04-11 17:45 - 000000000 ____D C:\Users\Kire 2019-02-14 21:08 - 2013-08-22 17:36 - 000000000 ____D C:\Windows\rescache 2019-02-14 20:28 - 2013-08-22 16:44 - 000551248 _____ C:\Windows\system32\FNTCACHE.DAT 2019-02-14 20:21 - 2013-08-22 17:20 - 000000000 ____D C:\Windows\CbsTemp 2019-02-14 20:16 - 2016-04-12 14:59 - 000000000 ____D C:\Windows\system32\MRT 2019-02-14 20:12 - 2016-04-12 14:59 - 129330784 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2019-02-14 20:10 - 2016-04-14 13:13 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2019-02-02 22:07 - 2019-01-17 20:24 - 000835480 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2019-02-02 22:07 - 2019-01-17 20:24 - 000179600 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2019-02-02 11:27 - 2016-04-11 17:46 - 000000000 ____D C:\Users\Kire\AppData\Local\Packages ==================== Files in the root of some directories ======= 2019-02-19 21:05 - 2019-02-19 21:05 - 000007598 _____ () C:\Users\Kire\AppData\Local\Resmon.ResmonCfg ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\dllhost.exe => File is digitally signed C:\Windows\SysWOW64\dllhost.exe => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2019-03-03 19:14 ==================== End of FRST.txt ============================ Addition.txt
  24. компютъра ми пише сам 100 процента е вирус , преинсталирах го проблема си остава, ако някой знае решение на проблема благодаря ето това прави ѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝ ѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝ до като не натисна някой клавиш и след малко пак. аз нямам такова "И" в клавиатурата "Ѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝ"Ѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝ'ѝ''ѝ'''''ѝ' сега забелязах че когато сложа кавички започва "ѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝѝ благодаря
×
×
  • Добави ново...