Премини към съдържанието
  • Добре дошли!

    Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

    Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

     

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

doktorkartar

Мисля че имам рекламен вирус

Препоръчан отговор


От известно време ми излизат всякакви реклами и не мога да ги премахна с adBlock.

Като отворя някои торент и на снимката му ми излиза прозорец с реклама които закрива обложката на филма, играта...

Това не е само с торентите , в които и сайт да отворя някоя снимка върху нея излиза реклама.

 

http://prikachi.com/images/293/6834293s.jpg

http://prikachi.com/images/292/6834292m.jpg

 

 

Също така от скоро започна да се пуска процес с има GPU Monitor които почва да товари видеото на 100%

 

 

 

Имам диск с ОС

DDS (Ver_2011-09-30.01) - NTFS_AMD64 Internet Explorer: 9.10.9200.16721Run by eclips at 13:41:12 on 2013-12-09Microsoft Windows 7 Ultimate   6.1.7601.1.1251.359.1033.18.4079.2768 [GMT 2:00].AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}FW: FireWall *Enabled* {CE40CCC0-8ADB-6D67-25A0-C5B6438E4B57}.============== Running Processes ===============.C:Windowssystem32wininit.exeC:Windowssystem32lsm.exeC:Windowssystem32svchost.exe -k DcomLaunchC:Windowssystem32svchost.exe -k RPCSSC:Windowssystem32atiesrxx.exeC:WindowsSystem32svchost.exe -k LocalServiceNetworkRestrictedC:WindowsSystem32svchost.exe -k LocalSystemNetworkRestrictedC:Windowssystem32svchost.exe -k LocalServiceC:Windowssystem32svchost.exe -k netsvcsC:Windowssystem32svchost.exe -k NetworkServiceC:Windowssystem32atieclxx.exeC:Windowssystem32Dwm.exeC:Program Files (x86)AviraAntiVir Desktopsched.exeC:WindowsExplorer.EXEC:Windowssystem32taskhost.exeC:Windowssystem32svchost.exe -k LocalServiceNoNetworkC:Program Files (x86)AviraAntiVir Desktopavfwsvc.exeC:Program Files (x86)AviraAntiVir Desktopavguard.exeC:Program Files (x86)AskPartnerNetworkToolbarapnmcp.exeC:Program Files (x86)Malwarebytes' Anti-Malwarembamscheduler.exeC:Program Files (x86)Malwarebytes' Anti-Malwarembamservice.exeC:Program Files (x86)Malwarebytes' Anti-Malwarembamgui.exeC:Program Files (x86)TuneUp Utilities 2014TuneUpUtilitiesService64.exeC:Windowssystem32viakaraokesrv.exeC:Program Files (x86)SkypePhoneSkype.exeC:Program Files (x86)AviraAntiVir Desktopavgnt.exeC:Program Files (x86)AskPartnerNetworkToolbarUpdaterTBNotifier.exeC:Program Files (x86)AviraAntiVir Desktopavshadow.exeC:Program Files (x86)TuneUp Utilities 2014TuneUpUtilitiesApp64.exeC:Program Files (x86)AviraAntiVir Desktopavmailc7.exeC:Program Files (x86)AviraAntiVir Desktopavwebg7.exeC:Windowssystem32svchost.exe -k NetworkServiceNetworkRestrictedC:Program Files (x86)Mozilla Firefoxfirefox.exeC:Program Files (x86)Mozilla Firefoxplugin-container.exeC:WindowsSysWOW64MacromedFlashFlashPlayerPlugin_11_9_900_152.exeC:WindowsSysWOW64MacromedFlashFlashPlayerPlugin_11_9_900_152.exeC:Windowssystem32conhost.exeC:Windowssystem32wbemwmiprvse.exeC:Windowssystem32DllHost.exeC:WindowsSystem32cscript.exe.============== Pseudo HJT Report ===============.mWinlogon: Userinit = userinit.exe,BHO: BitComet Helper: {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:Program Files (x86)BitComettoolsBitCometBHO_1.4.11.9.dllBHO: Avira SearchFree Toolbar: {41564952-412D-5637-00A7-7A786E7484D7} - BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:Program Files (x86)Microsoft OfficeOffice12GrooveShellExtensions.dllTB: Avira SearchFree Toolbar: {41564952-412D-5637-00A7-7A786E7484D7} - uRun: [DAEMON Tools Lite] "D:PROGRAMKIDAEMON Tools LiteDTLite.exe" -autorun                                                                                                                                                                                                                     uRun: [Skype] "C:Program Files (x86)SkypePhoneSkype.exe" /nosplash /minimizedmRun: [StartCCC] "C:Program Files (x86)ATI TechnologiesATI.ACECore-Staticamd64CLIStart.exe" MSRun                                                                                                                                                                                   mRun: [20131121] C:Program FilesAVAST SoftwareAvastsetupemupdatefc5b3b7b-5a18-48b5-ae49-c8648f5b721e.exe /checkmRun: [AvastUI.exe] "C:Program FilesAVAST SoftwareAvastAvastUI.exe" /noguimRun: [GrooveMonitor] "C:Program Files (x86)Microsoft OfficeOffice12GrooveMonitor.exe"mRun: [IME JPN 2007 Migration] C:PROGRA~2COMMON~1MICROS~1IME12IMEJPIMJPKLMG.EXE /PreloadmRun: [Korean IME Migration] C:PROGRA~2COMMON~1MICROS~1IME12IMEKRIMKRMIG.EXEmRun: [Microsoft Pinyin IME Migration] C:PROGRA~2COMMON~1MICROS~1IME12IMESCIMSCMIG.EXE /INSTALLmRun: [GPULoader] "C:Program Files (x86)VLC Player GPU+GPULog.exe"                                                                                                                                                                                                                      mRun: [avgnt] "C:Program Files (x86)AviraAntiVir Desktopavgnt.exe" /minmRun: [ApnTBMon] "C:Program Files (x86)AskPartnerNetworkToolbarUpdaterTBNotifier.exe"mPolicies-Explorer: NoActiveDesktopChanges = dword:1mPolicies-System: ConsentPromptBehaviorAdmin = dword:0mPolicies-System: ConsentPromptBehaviorUser = dword:3mPolicies-System: EnableLUA = dword:0mPolicies-System: EnableUIADesktopToggle = dword:0mPolicies-System: PromptOnSecureDesktop = dword:0IE: &D&ownload &with BitComet - C:Program FilesBitCometBitComet.exe/AddLink.htmIE: &D&ownload all with BitComet - C:Program FilesBitCometBitComet.exe/AddAllLink.htmIE: E&xport to Microsoft Excel - C:PROGRA~2MICROS~1Office12EXCEL.EXE/3000IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:Program Files (x86)BitComettoolsBitCometBHO_1.4.11.9.dll/206TCP: Interfaces{A3236531-A5CD-4450-8F87-65A07C468862} : DHCPNameServer = 178.254.208.2 178.254.192.3TCP: Interfaces{BEC556CF-51D7-4695-803A-32D19749B62C} : NameServer = 85.130.60.11 62.222.132.211Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:Program Files (x86)Microsoft OfficeOffice12GrooveSystemServices.dllHandler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:Program Files (x86)Common FilesSkypeSkype4COM.dllSSODL: WebCheck - <orphaned>SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:Program Files (x86)Microsoft OfficeOffice12GrooveShellExtensions.dllIFEO: dtlite.exe - "C:Program Files (x86)TuneUp Utilities 2014TUAutoReactivator64.exe"IFEO: sptdinst-x64.exe - "C:Program Files (x86)TuneUp Utilities 2014TUAutoReactivator64.exe"x64-BHO: Avira SearchFree Toolbar: {41564952-412D-5637-00A7-7A786E7484D7} - x64-BHO: SmileysWeLoveToolbar: {E4EF8A64-0A30-48F5-B3FE-5FDA978DA775} - x64-TB: SmileysWeLove: {CF0F43AB-9C23-4D7B-8040-201B82844854} - x64-TB: Avira SearchFree Toolbar: {41564952-412D-5637-00A7-7A786E7484D7} - x64-Run: [IME JPN 2007 Migration] C:PROGRA~1COMMON~1MICROS~1IME12IMEJPIMJPKLMG.EXE /Preloadx64-Run: [Korean IME Migration] C:PROGRA~1COMMON~1MICROS~1IME12IMEKRIMKRMIG.EXEx64-Run: [Microsoft Pinyin IME Migration] C:PROGRA~1COMMON~1MICROS~1IME12IMESCIMSCMIG.EXE /INSTALLx64-Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - <orphaned>x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>x64-SSODL: WebCheck - <orphaned>x64-IFEO: dtlite.exe - "C:Program Files (x86)TuneUp Utilities 2014TUAutoReactivator64.exe"x64-IFEO: sptdinst-x64.exe - "C:Program Files (x86)TuneUp Utilities 2014TUAutoReactivator64.exe".================= FIREFOX ===================.FF - ProfilePath - C:UserseclipsAppDataRoamingMozillaFirefoxProfiles9qq5rp0a.defaultFF - prefs.js: browser.startup.homepage - hxxp://www.google.bg/FF - plugin: C:Program Files (x86)GoogleGoogle Earthpluginnpgeplugin.dllFF - plugin: C:Program Files (x86)GoogleUpdate1.3.22.3npGoogleUpdate3.dllFF - plugin: C:WindowsSysWOW64MacromedFlashNPSWF32_11_9_900_152.dll.============= SERVICES / DRIVERS ===============.R1 avfwot;avfwot;C:WindowsSystem32driversavfwot.sys [2013-12-8 141376]R1 avkmgr;avkmgr;C:WindowsSystem32driversavkmgr.sys [2013-12-8 28600]R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:WindowsSystem32driversdtsoftbus01.sys [2013-8-20 283200]R2 AMD External Events Utility;AMD External Events Utility;C:WindowsSystem32atiesrxx.exe [2013-10-8 239616]R2 AntiVirFirewallService;Avira FireWall;C:Program Files (x86)AviraAntiVir Desktopavfwsvc.exe [2013-12-8 1012280]R2 AntiVirMailService;Avira Mail Protection;C:Program Files (x86)AviraAntiVir Desktopavmailc7.exe [2013-12-8 972872]R2 AntiVirSchedulerService;Avira Scheduler;C:Program Files (x86)AviraAntiVir Desktopsched.exe [2013-12-8 440376]R2 AntiVirService;Avira Real-Time Protection;C:Program Files (x86)AviraAntiVir Desktopavguard.exe [2013-12-8 440376]R2 AntiVirWebService;Avira Web Protection;C:Program Files (x86)AviraAntiVir Desktopavwebg7.exe [2013-12-8 1164360]R2 AODDriver4.2;AODDriver4.2;C:Program FilesATI TechnologiesATI.ACEFuelamd64aoddriver2.sys [2012-11-20 57512]R2 APNMCP;Ask Update Service;C:Program Files (x86)AskPartnerNetworkToolbarapnmcp.exe [2013-10-23 166352]R2 avgntflt;avgntflt;C:WindowsSystem32driversavgntflt.sys [2013-12-8 107416]R2 avnetflt;avnetflt;C:WindowsSystem32driversavnetflt.sys [2013-12-8 83160]R2 MBAMScheduler;MBAMScheduler;C:Program Files (x86)Malwarebytes' Anti-Malwarembamscheduler.exe [2013-12-7 418376]R2 MBAMService;MBAMService;C:Program Files (x86)Malwarebytes' Anti-Malwarembamservice.exe [2013-12-7 701512]R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;C:Program Files (x86)TuneUp Utilities 2014TuneUpUtilitiesService64.exe [2013-8-29 2100024]R2 VIAKaraokeService;VIA Karaoke digital mixer Service;C:WindowsSystem32ViakaraokeSrv.exe [2013-11-19 27760]R3 amdkmdag;amdkmdag;C:WindowsSystem32driversatikmdag.sys [2013-10-8 12534784]R3 amdkmdap;amdkmdap;C:WindowsSystem32driversatikmpag.sys [2013-10-8 619008]R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:WindowsSystem32driversAtihdW76.sys [2013-7-5 96256]R3 avfwim;AvFw Packet Filter Miniport;C:WindowsSystem32driversavfwim.sys [2013-12-8 114608]R3 MBAMProtector;MBAMProtector;C:WindowsSystem32driversmbam.sys [2013-12-7 25928]R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;C:Program Files (x86)TuneUp Utilities 2014TuneUpUtilitiesDriver64.sys [2013-8-21 14112]R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;C:WindowsSystem32driversviahduaa.sys [2013-11-19 2159728]S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:WindowsMicrosoft.NETFrameworkv4.0.30319mscorsvw.exe [2012-7-9 104912]S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:WindowsMicrosoft.NETFramework64v4.0.30319mscorsvw.exe [2012-7-8 123856]S2 gupdate;Услуга на Google Актуализация (gupdate);C:Program Files (x86)GoogleUpdateGoogleUpdate.exe [2013-11-30 116648]S3 BITCOMET_HELPER_SERVICE;BitComet Disk Boost Service;C:Program FilesBitComettoolsBitCometService.exe -service --> C:Program FilesBitComettoolsBitCometService.exe -service [?]S3 dmvsc;dmvsc;C:WindowsSystem32driversdmvsc.sys [2011-4-12 71168]S3 gupdatem;Услуга на Google Актуализация (gupdatem);C:Program Files (x86)GoogleUpdateGoogleUpdate.exe [2013-11-30 116648]S3 McComponentHostService;McAfee Security Scan Component Host Service;C:Program Files (x86)McAfee Security Scan3.0.285McCHSvc.exe [2012-9-5 234776]S3 MozillaMaintenance;Mozilla Maintenance Service;C:Program Files (x86)Mozilla Maintenance Servicemaintenanceservice.exe [2013-11-19 119408]S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:WindowsSystem32driversrdpvideominiport.sys [2010-11-21 20992]S3 rt61x64;Ralink RT61 Wireless Driver for Windows Vista;C:WindowsSystem32driversnetr6164.sys [2013-11-20 386560]S3 Synth3dVsc;Synth3dVsc;C:WindowsSystem32driversSynth3dVsc.sys [2011-4-12 88960]S3 terminpt;Microsoft Remote Desktop Input Driver;C:WindowsSystem32driversterminpt.sys [2011-4-12 34816]S3 TsUsbFlt;TsUsbFlt;C:WindowsSystem32driversTsUsbFlt.sys [2010-11-21 59392]S3 TsUsbGD;Remote Desktop Generic USB Device;C:WindowsSystem32driversTsUsbGD.sys [2010-11-21 31232]S3 tsusbhub;tsusbhub;C:WindowsSystem32driverstsusbhub.sys [2011-4-12 117248]S3 WatAdminSvc;Windows Activation Technologies Service;C:WindowsSystem32WatWatAdminSvc.exe [2013-10-16 1255736]S4 AMD FUEL Service;AMD FUEL Service;C:Program FilesATI TechnologiesATI.ACEFuelFuel.Service.exe [2013-10-8 344064].=============== File Associations ===============.FileExt: .txt: txtfile=C:WindowsSysWow64notepad.exe %1FileExt: .ini: inifile=C:WindowsSysWow64notepad.exe %1FileExt: .inf: inffile=C:WindowsSysWow64notepad.exe %1FileExt: .vbe: vbefile=C:WindowsSysWow64WScript.exe "%1" %*FileExt: .vbs: vbsfile=C:WindowsSysWow64WScript.exe "%1" %*FileExt: .js: jsfile=C:WindowsSysWow64WScript.exe "%1" %*FileExt: .jse: jsefile=C:WindowsSysWow64WScript.exe "%1" %*FileExt: .wsf: wsffile=C:WindowsSysWow64WScript.exe "%1" %*.=============== Created Last 30 ================.2013-12-08 17:59:29	--------	d-----w-	C:UserseclipsAppDataRoamingAvira2013-12-08 17:58:58	--------	d-----w-	C:ProgramDataAskPartnerNetwork2013-12-08 17:58:58	--------	d-----w-	C:Program Files (x86)AskPartnerNetwork2013-12-08 17:58:43	--------	d-----w-	C:ProgramDataAPN2013-12-08 17:56:59	83160	----a-w-	C:WindowsSystem32driversavnetflt.sys2013-12-08 17:56:59	28600	----a-w-	C:WindowsSystem32driversavkmgr.sys2013-12-08 17:56:59	107416	----a-w-	C:WindowsSystem32driversavgntflt.sys2013-12-08 17:56:58	141376	----a-w-	C:WindowsSystem32driversavfwot.sys2013-12-08 17:56:58	114608	----a-w-	C:WindowsSystem32driversavfwim.sys2013-12-08 17:56:58	--------	d-----w-	C:ProgramDataAvira2013-12-08 17:56:58	--------	d-----w-	C:Program Files (x86)Avira2013-12-08 17:35:45	--------	d-----w-	C:ProgramDataKaspersky Lab Setup Files2013-12-08 17:34:41	--------	d-s---w-	C:WindowsSysWow64Microsoft2013-12-08 16:42:41	--------	d-----w-	C:AdwCleaner2013-12-07 18:44:14	--------	d-----w-	C:UserseclipsAppDataRoamingMalwarebytes2013-12-07 18:43:54	--------	d-----w-	C:ProgramDataMalwarebytes2013-12-07 18:43:52	25928	----a-w-	C:WindowsSystem32driversmbam.sys2013-12-07 18:43:52	--------	d-----w-	C:Program Files (x86)Malwarebytes' Anti-Malware2013-12-07 17:59:17	--------	d-----w-	C:UserseclipsAppDataRoamingHD Tune Pro2013-12-07 17:59:07	--------	d-----w-	C:Program Files (x86)HD Tune Pro2013-12-06 21:48:19	--------	d-----w-	C:UserseclipsAppDataRoamingMAXON2013-12-04 09:52:44	--------	d-----w-	C:Program Files (x86)VideoLAN2013-12-04 09:43:31	--------	d-----w-	C:Program Files (x86)Winamp Detect2013-12-04 09:43:25	--------	d-----w-	C:Program Files (x86)Shopping Suggestion2013-12-04 09:43:20	--------	d-----w-	C:Program Files (x86)VLC Player GPU+2013-12-04 09:43:13	--------	d-----w-	C:Program Files (x86)Common FilesPX Storage Engine2013-12-04 07:13:06	--------	d-----w-	C:WindowsSystem32appmgmt2013-11-30 17:46:13	--------	d-----w-	C:UserseclipsAppDataLocalGoogle2013-11-29 04:55:48	--------	d-----w-	C:Program Files (x86)Common FilesSteam2013-11-28 20:27:12	--------	d-----w-	C:WindowsPCHEALTH2013-11-28 20:25:43	--------	d-----w-	C:Program Files (x86)Microsoft Visual Studio 82013-11-28 20:25:13	--------	d-----w-	C:UserseclipsAppDataLocalMicrosoft Help2013-11-23 18:41:24	--------	d-----w-	C:UserseclipsAppDataRoamingAVAST Software2013-11-21 18:23:02	--------	d-----w-	C:ProgramDataEA Core2013-11-20 15:55:58	--------	d-----w-	C:Program Files (x86)Skype2013-11-20 15:04:02	77656	----a-w-	C:WindowsSystem32XAPOFX1_5.dll2013-11-20 15:04:02	74072	----a-w-	C:WindowsSysWow64XAPOFX1_5.dll2013-11-20 15:04:01	527192	----a-w-	C:WindowsSysWow64XAudio2_7.dll2013-11-20 15:04:01	518488	----a-w-	C:WindowsSystem32XAudio2_7.dll2013-11-20 15:04:01	2526056	----a-w-	C:WindowsSystem32D3DCompiler_43.dll2013-11-20 15:04:01	239960	----a-w-	C:WindowsSysWow64xactengine3_7.dll2013-11-20 15:04:01	176984	----a-w-	C:WindowsSystem32xactengine3_7.dll2013-11-20 15:04:00	1907552	----a-w-	C:WindowsSystem32d3dcsx_43.dll2013-11-20 15:04:00	1868128	----a-w-	C:WindowsSysWow64d3dcsx_43.dll2013-11-20 15:02:14	--------	d-----w-	C:WindowsSysWow64directx2013-11-20 14:22:54	--------	d-----w-	C:Windowspss2013-11-20 12:59:27	386560	----a-w-	C:WindowsSystem32driversnetr6164.sys2013-11-20 12:59:25	--------	d-----w-	C:Program Files (x86)EDIMAX2013-11-20 12:18:45	--------	d-----w-	C:Program Files (x86)BitComet2013-11-20 12:07:42	--------	d-----w-	C:UserseclipsAppDataRoaminguTorrent2013-11-20 11:59:13	--------	d-----w-	C:Program FilesBitComet2013-11-20 10:47:59	--------	d-----w-	C:ProgramDataCodemasters2013-11-20 10:47:57	--------	d-----w-	C:ProgramDataSteam2013-11-20 10:08:30	--------	d-----w-	C:UserseclipsAppDataLocalPrograms2013-11-20 08:45:46	--------	d-----w-	C:UserseclipsAppDataLocalMacromedia2013-11-20 08:44:37	--------	d-----w-	C:ProgramDataMcAfee Security Scan2013-11-20 08:44:36	--------	d-----w-	C:Program Files (x86)McAfee Security Scan2013-11-20 08:44:34	71048	----a-w-	C:WindowsSysWow64FlashPlayerCPLApp.cpl2013-11-20 08:44:34	692616	----a-w-	C:WindowsSysWow64FlashPlayerApp.exe2013-11-20 03:31:37	--------	d-----w-	C:Program Files (x86)AMD AVT2013-11-20 03:22:40	--------	d-----w-	C:ProgramDataPackage Cache2013-11-20 02:27:35	--------	d-----w-	C:UserseclipsAppDataRoamingOrigin2013-11-20 02:27:34	--------	d-----w-	C:UserseclipsAppDataLocalOrigin2013-11-20 02:25:24	--------	d-----w-	C:ProgramDataOrigin2013-11-20 02:25:23	--------	d-----w-	C:ProgramDataElectronic Arts2013-11-20 02:18:41	--------	d-----w-	C:UserseclipsAppDataLocalElevatedDiagnostics2013-11-20 01:52:42	--------	d-----w-	C:UserseclipsAppDataRoamingDAEMON Tools Lite2013-11-20 01:51:39	--------	d-----w-	C:ProgramDataDAEMON Tools Lite2013-11-19 20:49:08	--------	d-----w-	C:UserseclipsAppDataRoamingBSplayer Pro2013-11-19 20:49:08	--------	d-----w-	C:UserseclipsAppDataRoamingBSplayer2013-11-19 20:49:08	--------	d-----w-	C:Program Files (x86)Webteh2013-11-19 20:46:57	--------	d-----w-	C:UserseclipsAppDataLocalAMD2013-11-19 20:46:46	--------	d-----w-	C:UserseclipsAppDataLocalATI2013-11-19 20:45:57	0	----a-w-	C:Windowsativpsrm.bin2013-11-19 20:42:00	--------	d-----w-	C:Program Files (x86)AMD APP2013-11-19 20:41:50	--------	d-----w-	C:Program FilesCommon FilesATI Technologies2013-11-19 20:41:50	--------	d-----w-	C:Program Files (x86)Common FilesATI Technologies2013-11-19 20:41:02	--------	d-----w-	C:ProgramDataAMD2013-11-19 20:39:32	--------	d-----w-	C:Program Files (x86)ATI Technologies2013-11-19 20:35:36	--------	d-----w-	C:Program FilesATI2013-11-19 20:34:32	--------	d-----w-	C:Program FilesATI Technologies2013-11-19 20:20:51	--------	d-----w-	C:Program FilesAVAST Software2013-11-19 20:20:05	--------	d-----w-	C:ProgramDataAVAST Software2013-11-19 19:42:58	--------	d-----w-	C:UserseclipsAppDataLocalMozilla2013-11-19 19:42:52	--------	d-----w-	C:Program Files (x86)Mozilla Maintenance Service2013-11-19 18:25:22	40760	----a-w-	C:WindowsSystem32TURegOpt.exe2013-11-19 18:25:21	29496	----a-w-	C:WindowsSystem32authuitu.dll2013-11-19 18:25:21	25400	----a-w-	C:WindowsSysWow64authuitu.dll2013-11-19 18:25:12	--------	d-----w-	C:UserseclipsAppDataRoamingTuneUp Software2013-11-19 18:24:52	--------	d-----w-	C:Program Files (x86)TuneUp Utilities 20142013-11-19 18:24:05	--------	d-----w-	C:ProgramDataTuneUp Software2013-11-19 18:23:42	--------	d-sh--w-	C:ProgramData{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}2013-11-19 18:23:42	--------	d--h--w-	C:ProgramDataCommon Files2013-11-19 16:49:39	--------	d-----w-	C:UserseclipsAppDataLocalAdobe2013-11-19 16:37:59	--------	d-----w-	C:Downloads2013-11-19 16:37:49	--------	d-----w-	C:UserseclipsAppDataRoamingBitComet2013-11-19 09:42:11	--------	d-----w-	C:WindowsPanther2013-11-19 09:41:57	--------	d-sh--w-	C:Boot2013-11-19 00:12:01	--------	d-----w-	C:UserseclipsAppDataLocalDiagnostics2013-11-18 23:58:04	994928	----a-w-	C:WindowsSystem32VIAPropPageExt.dll2013-11-18 23:57:45	414632	------w-	C:Windowsdifxapi.dll2013-11-18 23:57:45	--------	d-----w-	C:Program Files (x86)VIA2013-11-18 23:56:12	--------	d-sh--w-	C:WindowsInstaller2013-11-18 23:55:37	702976	----a-r-	C:WindowsSystem32cohelper.dll2013-11-18 23:55:37	5940	----a-r-	C:WindowsSystem32driversnvphy.bin2013-11-18 23:55:36	339360	----a-w-	C:WindowsSystem32driversnvmf6264.sys.==================== Find3M  ====================.2013-11-20 10:47:41	248672	----a-w-	C:WindowsSysWow64d3dx11_43.dll2013-11-20 10:46:42	2106216	----a-w-	C:WindowsSysWow64D3DCompiler_43.dll2013-11-20 10:44:57	81768	----a-w-	C:WindowsSysWow64xinput1_3.dll2013-11-20 03:14:10	875472	----a-w-	C:WindowsSysWow64msvcr110.dll2013-11-20 03:09:10	535008	----a-w-	C:WindowsSysWow64msvcp110.dll2013-11-20 02:58:30	348160	----a-w-	C:WindowsSysWow64msvcr71.dll2013-11-20 02:58:29	499712	----a-w-	C:WindowsSysWow64MSVCP71.DLL2013-11-20 02:48:32	499712	----a-w-	C:WindowsSystem32MSVCP71.DLL2013-11-20 02:48:32	348160	----a-w-	C:WindowsSystem32msvcr71.dll2013-11-20 01:52:45	283200	----a-w-	C:WindowsSystem32driversdtsoftbus01.sys2013-10-16 17:41:09	134656	----a-w-	C:WindowsSystem32WinToolkitRunOnce.exe2013-10-16 17:39:09	39936	----a-w-	C:WindowsSystem32driverstssecsrv.sys2013-10-16 17:39:09	1111552	----a-w-	C:WindowsSystem32rdpcorets.dll2013-10-15 22:57:28	496128	----a-w-	C:WindowsSystem32driversafd.sys2013-10-15 22:57:28	376768	----a-w-	C:WindowsSystem32driversnetio.sys2013-10-15 22:57:28	327168	----a-w-	C:WindowsSystem32mswsock.dll2013-10-15 22:57:28	288192	----a-w-	C:WindowsSystem32driversFWPKCLNT.SYS2013-10-15 22:57:28	231424	----a-w-	C:WindowsSysWow64mswsock.dll2013-10-15 22:57:28	1896896	----a-w-	C:WindowsSystem32driverstcpip.sys2013-10-15 22:55:24	3159040	----a-w-	C:WindowsSystem32win32k.sys2013-10-15 22:53:21	983488	----a-w-	C:WindowsSystem32driversdxgkrnl.sys2013-10-15 22:53:21	265064	----a-w-	C:WindowsSystem32driversdxgmms1.sys2013-10-15 22:53:21	144384	----a-w-	C:WindowsSystem32cdd.dll2013-10-15 22:48:45	100864	----a-w-	C:WindowsSystem32driversusbcir.sys2013-10-15 22:47:43	785624	----a-w-	C:WindowsSystem32driversWdf01000.sys2013-10-15 22:46:43	633856	----a-w-	C:WindowsSystem32comctl32.dll2013-10-15 22:46:43	530432	----a-w-	C:WindowsSysWow64comctl32.dll2013-10-15 22:44:41	2048	----a-w-	C:WindowsSysWow64tzres.dll2013-10-15 22:44:41	2048	----a-w-	C:WindowsSystem32tzres.dll2013-10-15 22:42:40	224256	----a-w-	C:WindowsSystem32wintrust.dll2013-10-15 22:42:40	184320	----a-w-	C:WindowsSystem32cryptsvc.dll2013-10-15 22:42:40	175104	----a-w-	C:WindowsSysWow64wintrust.dll2013-10-15 22:42:40	1472512	----a-w-	C:WindowsSystem32crypt32.dll2013-10-15 22:42:40	140288	----a-w-	C:WindowsSysWow64cryptsvc.dll2013-10-15 22:42:40	139776	----a-w-	C:WindowsSystem32cryptnet.dll2013-10-15 22:42:40	1166848	----a-w-	C:WindowsSysWow64crypt32.dll2013-10-15 22:42:40	103936	----a-w-	C:WindowsSysWow64cryptnet.dll2013-10-15 22:40:19	76800	----a-w-	C:WindowsSystem32drivershidclass.sys2013-10-15 22:40:19	32896	----a-w-	C:WindowsSystem32drivershidparse.sys2013-10-15 22:37:55	99840	----a-w-	C:WindowsSystem32driversusbccgp.sys2013-10-15 22:37:55	7808	----a-w-	C:WindowsSystem32driversusbd.sys2013-10-15 22:37:55	52736	----a-w-	C:WindowsSystem32driversusbehci.sys2013-10-15 22:37:55	343040	----a-w-	C:WindowsSystem32driversusbhub.sys2013-10-15 22:37:55	325120	----a-w-	C:WindowsSystem32driversusbport.sys2013-10-15 22:37:55	30720	----a-w-	C:WindowsSystem32driversusbuhci.sys2013-10-15 22:37:55	25600	----a-w-	C:WindowsSystem32driversusbohci.sys2013-10-15 22:35:52	124112	----a-w-	C:WindowsSystem32PresentationCFFRasterizerNative_v0300.dll2013-10-15 22:35:52	102608	----a-w-	C:WindowsSysWow64PresentationCFFRasterizerNative_v0300.dll2013-10-15 22:33:19	155584	----a-w-	C:WindowsSystem32driversataport.sys2013-10-15 22:32:17	461312	----a-w-	C:WindowsSystem32scavengeui.dll2013-10-15 22:31:15	663552	----a-w-	C:WindowsSysWow64rpcrt4.dll2013-10-15 22:31:15	1217024	----a-w-	C:WindowsSystem32rpcrt4.dll2013-10-15 22:29:11	70656	----a-w-	C:WindowsSysWow64fontsub.dll2013-10-15 22:29:11	46080	----a-w-	C:WindowsSystem32atmlib.dll2013-10-15 22:29:11	41472	----a-w-	C:WindowsSystem32lpk.dll2013-10-15 22:29:11	368128	----a-w-	C:WindowsSystem32atmfd.dll2013-10-15 22:29:11	34304	----a-w-	C:WindowsSysWow64atmlib.dll2013-10-15 22:29:11	295424	----a-w-	C:WindowsSysWow64atmfd.dll2013-10-15 22:29:11	25600	----a-w-	C:WindowsSysWow64lpk.dll2013-10-15 22:29:11	14336	----a-w-	C:WindowsSystem32dciman32.dll2013-10-15 22:29:11	10240	----a-w-	C:WindowsSysWow64dciman32.dll2013-10-15 22:29:11	100864	----a-w-	C:WindowsSystem32fontsub.dll2013-10-15 22:28:10	89088	----a-w-	C:WindowsSysWow64davclnt.dll2013-10-15 22:28:10	264704	----a-w-	C:WindowsSystem32WebClnt.dll2013-10-15 22:28:10	209408	----a-w-	C:WindowsSysWow64WebClnt.dll2013-10-15 22:28:10	141824	----a-w-	C:WindowsSystem32driversmrxdav.sys2013-10-15 22:28:10	110592	----a-w-	C:WindowsSystem32davclnt.dll2013-10-15 22:27:08	624128	----a-w-	C:WindowsSystem32qedit.dll2013-10-15 22:27:08	509440	----a-w-	C:WindowsSysWow64qedit.dll2013-10-15 22:24:02	1686888	----a-w-	C:WindowsSystem32driversntfs.sys2013-10-15 22:23:01	751104	----a-w-	C:WindowsSystem32win32spl.dll2013-10-15 22:23:01	492544	----a-w-	C:WindowsSysWow64win32spl.dll2013-10-15 22:19:56	1424384	----a-w-	C:WindowsSystem32WindowsCodecs.dll2013-10-15 22:19:56	1230336	----a-w-	C:WindowsSysWow64WindowsCodecs.dll2013-10-15 22:17:53	1643520	----a-w-	C:WindowsSystem32DWrite.dll2013-10-15 22:17:53	1247744	----a-w-	C:WindowsSysWow64DWrite.dll2013-10-15 22:15:50	1887232	----a-w-	C:WindowsSystem32d3d11.dll2013-10-15 22:15:50	1505280	----a-w-	C:WindowsSysWow64d3d11.dll2013-10-15 22:12:45	800768	----a-w-	C:WindowsSystem32usp10.dll2013-10-15 22:12:45	626688	----a-w-	C:WindowsSysWow64usp10.dll2013-10-15 22:11:44	561664	----a-w-	C:WindowsapppatchAcLayers.dll2013-10-15 22:11:44	474624	----a-w-	C:WindowsapppatchAcSpecfc.dll2013-10-15 22:11:44	350208	----a-w-	C:WindowsapppatchAppPatch64AcLayers.dll2013-10-15 22:11:44	308736	----a-w-	C:WindowsapppatchAppPatch64AcGenral.dll2013-10-15 22:11:44	2176512	----a-w-	C:WindowsapppatchAcGenral.dll2013-10-15 22:11:44	135168	----a-w-	C:WindowsapppatchAppPatch64AcXtrnal.dll2013-10-15 22:11:44	111104	----a-w-	C:WindowsapppatchAppPatch64acspecfc.dll2013-10-15 22:09:39	48640	----a-w-	C:WindowsSystem32wwanprotdim.dll2013-10-15 22:09:39	230400	----a-w-	C:WindowsSystem32wwansvc.dll2013-10-15 22:08:50	903168	----a-w-	C:WindowsSysWow64certutil.exe2013-10-15 22:08:50	52224	----a-w-	C:WindowsSystem32certenc.dll2013-10-15 22:08:50	43008	----a-w-	C:WindowsSysWow64certenc.dll2013-10-15 22:08:50	1192448	----a-w-	C:WindowsSystem32certutil.exe2013-10-15 22:07:45	44032	----a-w-	C:WindowsSystem32tsgqec.dll2013-10-15 22:07:45	3717632	----a-w-	C:WindowsSystem32mstscax.dll2013-10-15 22:07:45	36864	----a-w-	C:WindowsSysWow64tsgqec.dll2013-10-15 22:07:45	3217408	----a-w-	C:WindowsSysWow64mstscax.dll2013-10-15 22:07:45	158720	----a-w-	C:WindowsSystem32aaclient.dll2013-10-15 22:07:45	131584	----a-w-	C:WindowsSysWow64aaclient.dll2013-10-15 22:06:39	30720	----a-w-	C:WindowsSystem32cryptdlg.dll.============= FINISH: 13:41:29,94 ===============
.UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.IF REQUESTED, ZIP IT UP & ATTACH IT.DDS (Ver_2011-09-30.01).Microsoft Windows 7 Ultimate Boot Device: DeviceHarddiskVolume2Install Date: 19.11.2013 г. 01:52:36System Uptime: 9.12.2013 г. 13:08:59 (0 hours ago).Motherboard: ASRock |  | N68C-GS FXProcessor: AMD FX(tm)-4300 Quad-Core Processor             | CPUSocket | 3800/200mhz.==== Disk Partitions =========================.C: is FIXED (NTFS) - 39 GiB total, 6,82 GiB free.D: is FIXED (NTFS) - 114 GiB total, 1,44 GiB free.E: is CDROM ()F: is FIXED (NTFS) - 38 GiB total, 0,299 GiB free.G: is CDROM ().==== Disabled Device Manager Items =============.Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}Description: Ralink RT61 Turbo Wireless LAN CardDevice ID: PCIVEN_1814&DEV_0301&SUBSYS_25611814&REV_004&2F735D55&0&4020Manufacturer: Ralink Technology Corp.Name: Ralink RT61 Turbo Wireless LAN CardPNP Device ID: PCIVEN_1814&DEV_0301&SUBSYS_25611814&REV_004&2F735D55&0&4020Service: rt61x64.Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}Description: avast! Firewall NDIS Filter MiniportDevice ID: ROOTSW_ASWNDISMP0000Manufacturer: ALWIL SoftwareName: avast! Firewall NDIS Filter MiniportPNP Device ID: ROOTSW_ASWNDISMP0000Service: aswNdis.==== System Restore Points ===================.No restore point in system..==== Installed Programs ======================.µTorrentAdobe Flash Player 11 PluginAMD Accelerated Video TranscodingAMD APP SDK RuntimeAMD Catalyst Control CenterAMD Catalyst Install ManagerAMD Drag and Drop TranscodingAMD FuelAMD Media Foundation DecodersAvira Internet SecurityAvira SearchFree ToolbarBitComet 1.24BitComet 1.36 64-bitBS.Player FREECatalyst Control Center - BrandingCatalyst Control Center Graphics Previews CommonCatalyst Control Center InstallProxyCatalyst Control Center Localization Allccc-utility64CCC Help Chinese StandardCCC Help Chinese TraditionalCCC Help CzechCCC Help DanishCCC Help DutchCCC Help EnglishCCC Help FinnishCCC Help FrenchCCC Help GermanCCC Help GreekCCC Help HungarianCCC Help ItalianCCC Help JapaneseCCC Help KoreanCCC Help NorwegianCCC Help PolishCCC Help PortugueseCCC Help RussianCCC Help SpanishCCC Help SwedishCCC Help ThaiCCC Help TurkishDAEMON Tools LiteEdimax Wireless LANGoogle Earth Plug-inGoogle Update HelperGPU MonitorHD Tune Pro 5.00Malwarebytes Anti-Malware, версия 1.75.0.1300McAfee Security Scan PlusMicrosoft .NET Framework 4.5Microsoft Office Access MUI (English) 2007Microsoft Office Access Setup Metadata MUI (English) 2007Microsoft Office Enterprise 2007Microsoft Office Excel MUI (English) 2007Microsoft Office Groove MUI (English) 2007Microsoft Office Groove Setup Metadata MUI (English) 2007Microsoft Office IME (Chinese (Simplified)) 2007Microsoft Office IME (Chinese (Traditional)) 2007Microsoft Office IME (Japanese) 2007Microsoft Office IME (Korean) 2007Microsoft Office InfoPath MUI (English) 2007Microsoft Office Office 64-bit Components 2007Microsoft Office OneNote MUI (English) 2007Microsoft Office Outlook MUI (English) 2007Microsoft Office PowerPoint MUI (English) 2007Microsoft Office Proof (Arabic) 2007Microsoft Office Proof (Basque) 2007Microsoft Office Proof (Bulgarian) 2007Microsoft Office Proof (Catalan) 2007Microsoft Office Proof (Chinese (Simplified)) 2007Microsoft Office Proof (Chinese (Traditional)) 2007Microsoft Office Proof (Croatian) 2007Microsoft Office Proof (Czech) 2007Microsoft Office Proof (Danish) 2007Microsoft Office Proof (Dutch) 2007Microsoft Office Proof (English) 2007Microsoft Office Proof (Estonian) 2007Microsoft Office Proof (Finnish) 2007Microsoft Office Proof (French) 2007Microsoft Office Proof (Galician) 2007Microsoft Office Proof (German) 2007Microsoft Office Proof (Greek) 2007Microsoft Office Proof (Gujarati) 2007Microsoft Office Proof (Hebrew) 2007Microsoft Office Proof (Hindi) 2007Microsoft Office Proof (Hungarian) 2007Microsoft Office Proof (Italian) 2007Microsoft Office Proof (Japanese) 2007Microsoft Office Proof (Kannada) 2007Microsoft Office Proof (Korean) 2007Microsoft Office Proof (Latvian) 2007Microsoft Office Proof (Lithuanian) 2007Microsoft Office Proof (Marathi) 2007Microsoft Office Proof (Norwegian (Bokmal)) 2007Microsoft Office Proof (Norwegian (Nynorsk)) 2007Microsoft Office Proof (Polish) 2007Microsoft Office Proof (Portuguese (Brazil)) 2007Microsoft Office Proof (Portuguese (Portugal)) 2007Microsoft Office Proof (Punjabi) 2007Microsoft Office Proof (Romanian) 2007Microsoft Office Proof (Russian) 2007Microsoft Office Proof (Serbian (Latin)) 2007Microsoft Office Proof (Slovak) 2007Microsoft Office Proof (Slovenian) 2007Microsoft Office Proof (Spanish) 2007Microsoft Office Proof (Swedish) 2007Microsoft Office Proof (Tamil) 2007Microsoft Office Proof (Telugu) 2007Microsoft Office Proof (Thai) 2007Microsoft Office Proof (Turkish) 2007Microsoft Office Proof (Ukrainian) 2007Microsoft Office Proof (Urdu) 2007Microsoft Office Proofing (English) 2007Microsoft Office Proofing Kit 2007Microsoft Office Proofing Tools Kit 2007Microsoft Office ProofMUI (English) 2007Microsoft Office Publisher MUI (English) 2007Microsoft Office Shared 64-bit MUI (English) 2007Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007Microsoft Office Shared MUI (English) 2007Microsoft Office Shared Setup Metadata MUI (English) 2007Microsoft Office Word MUI (English) 2007Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727Mozilla Firefox 25.0.1 (x86 bg)Mozilla Maintenance ServiceNeed for Speed(TM) RivalsOriginPlatformSkype™ 3.5Smileys We Love Toolbar for IESteamTuneUp Utilities 2014TuneUp Utilities 2014 (en-US)VIA п»їVLC media player 2.0.6WinampWinamp Detector Plug-inWinRAR archiver.==== Event Viewer Messages From Past Week ========.9.12.2013 г. 13:10:01, Error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  KLIM69.12.2013 г. 07:09:56, Error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  KLIM68.12.2013 г. 22:00:43, Error: Disk [11]  - The driver detected a controller error on DeviceHarddisk2DR2.8.12.2013 г. 22:00:43, Error: Disk [11]  - The driver detected a controller error on DeviceHarddisk2DR2.8.12.2013 г. 22:00:42, Error: Disk [11]  - The driver detected a controller error on DeviceHarddisk2DR2.8.12.2013 г. 22:00:42, Error: Disk [11]  - The driver detected a controller error on DeviceHarddisk2DR2.8.12.2013 г. 20:01:37, Error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  KLIM68.12.2013 г. 19:58:48, Error: Service Control Manager [7006]  - The ScRegSetValueExW call failed for DeleteFlag with the following error:  Access is denied.8.12.2013 г. 19:37:17, Error: volsnap [36]  - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.8.12.2013 г. 19:30:13, Error: Service Control Manager [7034]  - The avast! Antivirus service terminated unexpectedly.  It has done this 3 time(s).8.12.2013 г. 19:29:37, Error: Service Control Manager [7034]  - The avast! Firewall service terminated unexpectedly.  It has done this 3 time(s).8.12.2013 г. 19:29:33, Error: Service Control Manager [7031]  - The avast! Antivirus service terminated unexpectedly.  It has done this 2 time(s).  The following corrective action will be taken in 5000 milliseconds: Restart the service.8.12.2013 г. 19:29:27, Error: Service Control Manager [7031]  - The avast! Firewall service terminated unexpectedly.  It has done this 2 time(s).  The following corrective action will be taken in 5000 milliseconds: Restart the service.8.12.2013 г. 19:29:24, Error: Service Control Manager [7031]  - The avast! Antivirus service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 5000 milliseconds: Restart the service.8.12.2013 г. 19:29:20, Error: Service Control Manager [7031]  - The avast! Firewall service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 5000 milliseconds: Restart the service.8.12.2013 г. 19:18:55, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}8.12.2013 г. 19:16:40, Error: Service Control Manager [7001]  - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:  The dependency service or group failed to start.8.12.2013 г. 19:16:40, Error: Service Control Manager [7001]  - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:  The dependency service or group failed to start.8.12.2013 г. 19:16:40, Error: Service Control Manager [7001]  - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:  The dependency service or group failed to start.8.12.2013 г. 19:16:40, Error: Service Control Manager [7001]  - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:  The dependency service or group failed to start.8.12.2013 г. 19:16:40, Error: Service Control Manager [7001]  - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:  The dependency service or group failed to start.8.12.2013 г. 19:16:40, Error: Service Control Manager [7001]  - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:  The dependency service or group failed to start.8.12.2013 г. 19:16:30, Error: Service Control Manager [7001]  - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:  The dependency service or group failed to start.8.12.2013 г. 19:16:30, Error: Service Control Manager [7001]  - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:  The dependency service or group failed to start.8.12.2013 г. 19:16:30, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}8.12.2013 г. 19:16:30, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}8.12.2013 г. 19:16:28, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}8.12.2013 г. 19:16:22, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}8.12.2013 г. 19:16:13, Error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  AFD aswFW aswNdisFlt aswRdr aswSnx aswSP aswTdi CSC DfsC discache NetBIOS NetBT nsiproxy Psched rdbss spldr tdx Wanarpv6 WfpLwf8.12.2013 г. 19:16:13, Error: Service Control Manager [7001]  - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error:  The dependency service or group failed to start.8.12.2013 г. 19:16:13, Error: Service Control Manager [7001]  - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error:  A device attached to the system is not functioning.8.12.2013 г. 19:16:13, Error: Service Control Manager [7001]  - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error:  A device attached to the system is not functioning.8.12.2013 г. 19:16:13, Error: Service Control Manager [7001]  - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error:  The dependency service or group failed to start.8.12.2013 г. 19:16:13, Error: Service Control Manager [7001]  - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error:  The dependency service or group failed to start.8.12.2013 г. 19:16:13, Error: Service Control Manager [7001]  - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error:  A device attached to the system is not functioning.8.12.2013 г. 19:16:13, Error: Service Control Manager [7001]  - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error:  The dependency service or group failed to start.8.12.2013 г. 19:16:13, Error: Service Control Manager [7001]  - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error:  The dependency service or group failed to start.8.12.2013 г. 19:16:13, Error: Service Control Manager [7001]  - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error:  A device attached to the system is not functioning.8.12.2013 г. 19:16:13, Error: Service Control Manager [7001]  - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error:  A device attached to the system is not functioning.8.12.2013 г. 19:13:34, Error: Service Control Manager [7034]  - The avast! Firewall service terminated unexpectedly.  It has done this 3 time(s).8.12.2013 г. 19:13:30, Error: Service Control Manager [7034]  - The AMD External Events Utility service terminated unexpectedly.  It has done this 1 time(s).8.12.2013 г. 19:13:28, Error: Service Control Manager [7034]  - The avast! Antivirus service terminated unexpectedly.  It has done this 3 time(s).8.12.2013 г. 19:13:26, Error: Service Control Manager [7031]  - The avast! Firewall service terminated unexpectedly.  It has done this 2 time(s).  The following corrective action will be taken in 5000 milliseconds: Restart the service.8.12.2013 г. 19:13:20, Error: Service Control Manager [7031]  - The avast! Antivirus service terminated unexpectedly.  It has done this 2 time(s).  The following corrective action will be taken in 5000 milliseconds: Restart the service.8.12.2013 г. 19:13:12, Error: Service Control Manager [7031]  - The avast! Antivirus service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 5000 milliseconds: Restart the service.8.12.2013 г. 19:13:06, Error: Service Control Manager [7031]  - The avast! Firewall service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 5000 milliseconds: Restart the service.7.12.2013 г. 19:33:38, Error: volsnap [36]  - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.7.12.2013 г. 18:06:31, Error: Microsoft-Windows-WHEA-Logger [20]  - A fatal hardware error has occurred. Component: AMD Northbridge Error Source: Machine Check Exception Error Type: 11 Processor ID: 0 The details view of this entry contains further information.7.12.2013 г. 18:06:19, Error: Microsoft-Windows-WER-SystemErrorReporting [1001]  - The computer has rebooted from a bugcheck.  The bugcheck was: 0x00000124 (0x0000000000000000, 0xfffffa8004cfe038, 0x0000000000000000, 0x0000000000000000). A dump was saved in: C:WindowsMinidump120713-18735-01.dmp. Report Id: 120713-18735-01.5.12.2013 г. 22:26:33, Error: Disk [11]  - The driver detected a controller error on DeviceHarddisk2DR2.5.12.2013 г. 22:26:33, Error: Disk [11]  - The driver detected a controller error on DeviceHarddisk2DR2.5.12.2013 г. 22:26:32, Error: Disk [11]  - The driver detected a controller error on DeviceHarddisk2DR2.5.12.2013 г. 22:26:32, Error: Disk [11]  - The driver detected a controller error on DeviceHarddisk2DR2.5.12.2013 г. 21:20:51, Error: volsnap [36]  - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.4.12.2013 г. 22:28:43, Error: volsnap [36]  - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.4.12.2013 г. 15:06:57, Error: Disk [11]  - The driver detected a controller error on DeviceHarddisk2DR2.4.12.2013 г. 15:06:57, Error: Disk [11]  - The driver detected a controller error on DeviceHarddisk2DR2.4.12.2013 г. 15:06:56, Error: Disk [11]  - The driver detected a controller error on DeviceHarddisk2DR2.4.12.2013 г. 15:06:56, Error: Disk [11]  - The driver detected a controller error on DeviceHarddisk2DR2..==== End Of File ===========================

Ето и от MB

Malwarebytes Anti-Malware (PRO) 1.75.0.1300www.malwarebytes.orgВерсия на базата от данни: v2013.12.07.06Windows 7 Service Pack 1 x64 NTFSInternet Explorer 10.0.9200.16721eclips :: ECLIPS-PC [администратор]Защита: включена8.12.2013 г. 21:22:43 ч.mbam-log-2013-12-08 (21-22-43).txtТип сканиране: Пълно сканиране (C:|D:|F:|)Включени опции за сканиране: Памет | Автоматично зареждане | Системен регистър | Файлова система | Евристики/Допълнителни | Евристики/Shuriken | PUP | PUMИзключени опции за сканиране: P2PСканирани обекти: 428931Изминало време: 1 час(а), 5 минута(и), 50 секунда(и)Открити процеси в паметта: 0(Не бяха открити зловредни обекти)Открити модули в паметта: 0(Не бяха открити зловредни обекти)Открити ключове в системния регистър: 0(Не бяха открити зловредни обекти)Открити стойности в системния регистър: 0(Не бяха открити зловредни обекти)Открити информационни обекти в системния регистър: 0(Не бяха открити зловредни обекти)Открити папки: 0(Не бяха открити зловредни обекти)Открити файлове: 14D:Desktopnpp.6.4.5.Installer-jd(1).exe (PUP.Optional.OpenCandy) -> Не беше предприето действие.D:Desktopnpp.6.4.5.Installer-jd.exe (PUP.Optional.OpenCandy) -> Не беше предприето действие.D:DownloadDaemon Tools Lite 4.47.1.0333DTLite4471-0333.exe (PUP.Optional.OpenCandy) -> Не беше предприето действие.D:DownloadWinamp.Pro.v5.7.3363.Incl.Keygen-FFFwinamp57_3363_beta_full_all.exe (PUP.Optional.OpenCandy) -> Не беше предприето действие.F:Desktopnpp.6.4.5.Installer-jd(1).exe (PUP.Optional.OpenCandy) -> Не беше предприето действие.F:Desktopnpp.6.4.5.Installer-jd.exe (PUP.Optional.OpenCandy) -> Не беше предприето действие.D:DesktopBg phonetic for Win Xp(1).EXE (Trojan.Dropper.Delf) -> Поставен под карантина и изтрит успешно.D:DesktopBg phonetic for Win Xp.EXE (Trojan.Dropper.Delf) -> Поставен под карантина и изтрит успешно.F:DesktopBg phonetic for Win Xp(1).EXE (Trojan.Dropper.Delf) -> Поставен под карантина и изтрит успешно.F:DesktopBg phonetic for Win Xp.EXE (Trojan.Dropper.Delf) -> Поставен под карантина и изтрит успешно.F:New Folder 3memTest.exe (Backdoor.Agent.Gen) -> Поставен под карантина и изтрит успешно.F:PROGRAMKIKoralSoftEuroDictXPUnInstall.exe (Trojan.Downloader.bh) -> Поставен под карантина и изтрит успешно.F:PROGRAMKIpariFiestaBarCFFilter.dll (Adware.######) -> Поставен под карантина и изтрит успешно.F:Нова папкаdesktop 2DesktopCall Of Duty Modern Warfare 2 Co Op Patch [TeknoGods].rar (Backdoor.Agent.Gen) -> Поставен под карантина и изтрит успешно.(край)

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

Здравейте ..! :) В системата ви се виждат остатъци от Аваст и McAfee Security Scan Plus..Деинсталирайте ги по следния начин:
 
Аваст

  • [*]Изтеглете инструмента 
avastclear.exe  и го запазете на вашия работен плот [*]Стартирайте Windows в Safe Mode. [*]Стартирайте инструмента. [*]Кликнете върху Премахване (REMOVE). [*]Рестартирайте компютъра си.

 

McAfee Security Scan Plus
 
Моля, деинсталирате програмата McAfee Security Scan Plus по стандартния начин..!
  За да се уверете, че няма остатъци..:
  Моля, изтеглите MCPR.exe и го запишете на вашия Desktop.

  • [*]   Затворете всички програми и щракнете двукратно върху
MCPR.exe след това кликнете на Run [*]   Следвайте инструкциите на екрана. [*]   Когато процедурата приключи, ще се появи съобщение 'CLEANUP SUCCESSFUL'. [*]   Кликнете върху ''Yes', за да рестартирате компютъра си. [*]   След това изтрийте MCPR.exe от вашия работен плот.

Освен това деинсталирайте следния софтуер:
 
Smileys We Love Toolbar for IE
 
 
След всичко това:
 
 
Публикувано изображениеМоля, изтеглете и стартирайте програмата AdwCleaner(by Xplode):

  • [*]Затворете всички стартирани програми и браузъри [*]Кликнете два пъти върху
adwcleaner.exe за да стартирате инструмента. [*]Натиснете OK, за да потвърдите, че всички стартирани програми ще бъдат затворени. [*]Маркирайте Clean [*]Вашият компютър ще се рестартира автоматично. Текстовия файл ще се отвори след рестарта. [*]Моля, да публикувате съдържанието на този лог в отговора си [*]Можете да намерите лога,който автоматично се запомня тук C:AdwCleaner[s0].txt

Публикувано изображение

 

Публикувано изображение Моля, изтеглете Junkware Removal Tool (by Thisisu ) и запазете на вашия десктоп.

  • [*]Спрете временно работата на защитните програми. [*]Стартирайте инструмента
JRT.exe [*]Ще се отвори ДОС прозорец. Натиснете което и да е копче от клавиатурата. [*]Затворете излишните приложения и всички браузъри и изчакайте проверката да завърши. [*]Ще се появи лог файл (който можете да намерите и ръчно на десктопа с името JRT.txt). [*]Моля копирайте съдържанието на лог файла в следващия си пост.

Публикувано изображение

 
 
Публикувано изображение Стартирайте програмата Malwarebytes' Anti-Malware отново и изберете "Perform quick scan", след това кликнете на Scan.
* Когато сканирането завърши, кликнете на OK, след това Show Results, за да видите резултата
* Уверете се, че на всички редове има отметки, и кликнете на Remove Selected.
* Когато всичко бъде премахнато, в Notepad ще бъде отворен лог.
Копирайте този лог и го публикувайте в следващия си коментар по темата.

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

Мисля че премахнах проблема но това вие ще го решите.

Изглежда че само мозилата беше заразена.

Днес сутринта я премахнах напълно с всички добавки и тем подобни след което си я качих на ново и рекламите вече ги нямаше.

 

Пуснах Авира после касперски и накрая МБ като всеки намери по нещо и го премахна.

 

 

Сега изпълних и горните стъпки но това Smileys We Love Toolbar for IE не иска да се премахне пробвал съм го и от преди.

http://prikachi.com/images.php?images/871/6838871q.jpg

 

 

AdwCleaner

# AdwCleaner v3.014 - Report created 10/12/2013 at 19:24:05# Updated 01/12/2013 by Xplode# Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)# Username : eclips - ECLIPS-PC# Running from : C:UserseclipsDesktopadwcleaner.exe# Option : Clean***** [ Services ] ********** [ Files / Folders ] *****Folder Deleted : C:ProgramDataapnFolder Deleted : C:UserseclipsAppDataLocalTempapnFile Deleted : C:UserseclipsAppDataRoamingMozillaFirefoxProfilesb7dozaqg.defaultsearchpluginsdaemon-search.xmlFile Deleted : C:UserseclipsAppDataRoamingMozillaFirefoxProfilesnmd593mr.defaultsearchpluginsdaemon-search.xmlFile Deleted : C:UserseclipsAppDataRoamingMozillaFirefoxProfilesxt6jsszk.defaultsearchpluginsdaemon-search.xmlFile Deleted : C:UserseclipsAppDataRoamingMozillaFirefoxProfiles31gcqwly.defaultsearchpluginsicqplugin.xmlFile Deleted : C:UserseclipsAppDataRoamingMozillaFirefoxProfiles89u6ln5o.defaultsearchpluginsicqplugin.xmlFile Deleted : C:UserseclipsAppDataRoamingMozillaFirefoxProfilesb7dozaqg.defaultsearchpluginsicqplugin.xmlFile Deleted : C:UserseclipsAppDataRoamingMozillaFirefoxProfilesh47mvk1q.defaultsearchpluginsicqplugin.xmlFile Deleted : C:UserseclipsAppDataRoamingMozillaFirefoxProfilesnmd593mr.defaultsearchpluginsicqplugin.xmlFile Deleted : C:UserseclipsAppDataRoamingMozillaFirefoxProfilessi8rqqsc.defaultsearchpluginsicqplugin.xmlFile Deleted : C:UserseclipsAppDataRoamingMozillaFirefoxProfilesvwuwipox.defaultsearchpluginsicqplugin.xmlFile Deleted : C:UserseclipsAppDataRoamingMozillaFirefoxProfilesxt6jsszk.defaultsearchpluginsicqplugin.xmlFile Deleted : C:UserseclipsAppDataRoamingMozillaFirefoxProfilesnmd593mr.defaultuser.jsFile Deleted : C:UserseclipsAppDataRoamingMozillaFirefoxProfilesxt6jsszk.defaultuser.js***** [ Shortcuts ] ********** [ Registry ] *****Key Deleted : HKLMSOFTWAREMicrosoftTracingApnSetup_RASAPI32Key Deleted : HKLMSOFTWAREMicrosoftTracingApnSetup_RASMANCSKey Deleted : HKCUSoftwareConduit***** [ Browsers ] *****- Internet Explorer v10.0.9200.16720- Mozilla Firefox v25.0.1 (bg)[ File : C:UserseclipsAppDataRoamingMozillaFirefoxProfiles31gcqwly.defaultprefs.js ]Line Deleted : user_pref("browser.startup.homepage", "hxxp://start.icq.com/");Line Deleted : user_pref("icqtoolbar.installsource", "1");[ File : C:UserseclipsAppDataRoamingMozillaFirefoxProfiles89u6ln5o.defaultprefs.js ]Line Deleted : user_pref("browser.startup.homepage", "hxxp://start.icq.com/");Line Deleted : user_pref("icqtoolbar.installsource", "1");[ File : C:UserseclipsAppDataRoamingMozillaFirefoxProfilesb7dozaqg.defaultprefs.js ][ File : C:UserseclipsAppDataRoamingMozillaFirefoxProfilesh47mvk1q.defaultprefs.js ]Line Deleted : user_pref("browser.startup.homepage", "hxxp://start.icq.com/");Line Deleted : user_pref("icqtoolbar.installsource", "1");[ File : C:UserseclipsAppDataRoamingMozillaFirefoxProfilesnmd593mr.defaultprefs.js ][ File : C:UserseclipsAppDataRoamingMozillaFirefoxProfilessi8rqqsc.defaultprefs.js ]Line Deleted : user_pref("browser.startup.homepage", "hxxp://start.icq.com/");Line Deleted : user_pref("icqtoolbar.installsource", "1");[ File : C:UserseclipsAppDataRoamingMozillaFirefoxProfilesvwuwipox.defaultprefs.js ]Line Deleted : user_pref("browser.startup.homepage", "hxxp://start.icq.com/");Line Deleted : user_pref("icqtoolbar.installsource", "1");[ File : C:UserseclipsAppDataRoamingMozillaFirefoxProfilesxt6jsszk.defaultprefs.js ]Line Deleted : user_pref("extensions.wrc.SearchRules.ask.com.style", ".WRCN {display:none} #yui-main .tsrc_vnru .title + .WRCN, #yui-main #teoma-results .title + .WRCN {display:inline !important; background: url("I[...]Line Deleted : user_pref("extensions.wrc.SearchRules.ask.com.url", "^hxxp(s)?://(.+.)?ask.com/.*");Line Deleted : user_pref("extensions.wrc.SearchRules.rambler.ru.style", ".WRCN {display:none} .search-results .title + .WRCN {display:inline !important; background: url("IMAGE") right no-repeat}");Line Deleted : user_pref("icqtoolbar.installsource", "1");*************************AdwCleaner[R0].txt - [1684 octets] - [08/12/2013 18:42:45]AdwCleaner[R1].txt - [890 octets] - [08/12/2013 18:46:35]AdwCleaner[R2].txt - [4739 octets] - [10/12/2013 19:23:08]AdwCleaner[S0].txt - [1642 octets] - [08/12/2013 18:43:48]AdwCleaner[S1].txt - [950 octets] - [08/12/2013 18:47:41]AdwCleaner[S2].txt - [4687 octets] - [10/12/2013 19:24:05]########## EOF - C:AdwCleanerAdwCleaner[S2].txt - [4747 octets] ##########

 

 

 

 

 

 

 

 

 

 

JRT

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~Junkware Removal Tool (JRT) by ThisisuVersion: 6.0.8 (11.05.2013:1)OS: Windows 7 Ultimate x64Ran by eclips on ўв 10.12.2013 Ј. at 19:30:56,34~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Services~~~ Registry Values~~~ Registry Keys~~~ Files~~~ Folders~~~ FireFoxEmptied folder: C:UserseclipsAppDataRoamingmozillafirefoxprofilesnmd593mr.defaultminidumps [9 files]~~~ Event Viewer Logs were cleared~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~Scan was completed on ўв 10.12.2013 Ј. at 19:36:23,12End of JRT log~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

МБ не откри нищо.

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

Изтеглете SystemLook (32-bit) или SystemLook (64-bit) и запазете програмата на десктопа.

  • [*]Кликнете два пъти върху
SystemLook.exe, за да стартирате програмата. [*]Копирайте съдържанието от цитата по-долу в текстовото поле на програмата:

:filefind*Smileys We Love Toolbar*:regfind*Smileys We Love Toolbar*
  • [*]Кликнете на бутона
Look, за да започне сканирането. [*]Когато сканирането завърши ще се отвори Notepad с резултата от
сканирането. После публикувайте лог файла в следващия си коментар.

Сподели този отговор


Линк към този отговор
Сподели в други сайтове
SystemLook 30.07.11 by jpshortstuffLog created at 20:36 on 10/12/2013 by eclipsAdministrator - Elevation successful========== filefind ==========Searching for "*Smileys We Love Toolbar*"No files found.========== regfind ==========Searching for "*Smileys We Love Toolbar*"No data found.-= EOF =-

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

Опссс..малка грешка..!
 
Изтеглете SystemLook (32-bit) или SystemLook (64-bit) и запазете програмата на десктопа.

  • [*]Кликнете два пъти върху
SystemLook.exe, за да стартирате програмата. [*]Копирайте съдържанието от цитата по-долу в текстовото поле на програмата:

:filefind*Smileys We Love*:regfind*Smileys We Love*
  • [*]Кликнете на бутона
Look, за да започне сканирането. [*]Когато сканирането завърши ще се отвори Notepad с резултата от
сканирането. После публикувайте лог файла в следващия си коментар.

+
 
Публикувано изображение Изтеглете ComboFix Публикувано изображение от тук и го запазете на десктопа си
Изключете вашата антивирусна и антишпионска програма, обикновено това става чрез натискане на десния бутон на мишката върху иконата на програма в системния трей.
Бележка: Ако не можете я спрете или не сте сигурни коя програма да изключите, моля прегледайте информацията от този линк: How to disable your security applications by amateur
Стартирайте Combo-Fix.com Публикувано изображение и следвайте инструкциите.
Бележка: ComboFix ще се стартира без инсталирана Recovery Console.
Като част от неговата работа, ComboFix ще провери дали Microsoft Windows Recovery Console е инсталирана. Предвид бързо развиващия се зловреден софтуер е силно препоръчително да бъде инсталирана преди премахването на зловредния софтуер. Това ще Ви позволи да влезете в специален recovery/repai режим, който ще ни позволи по-лесно да решите проблем, който би могъл да възникне при премахване на зловредния софтуер.

  • [*]Следвайте инструкциите, за да позволите на
ComboFix да изтегли и инсталира Microsoft Windows Recovery Console.В един момент ще бъдете попитани дали сте съгласни с лицензното споразумение. Необходимо е да потвърдите, че сте съгласни, за да инсталирате Microsoft Windows Recovery Console.

** Забележете: Ако Microsoft Windows Recovery Console е вече инсталирана, ComboFix ще продължи към процеса по премахване на зловредния софтуер.

Публикувано изображение

След като Microsoft Windows Recovery Console е инсталирана, използвайки ComboFix, Вие ще видите следното съобщение:

Публикувано изображение

Изберете Yes, за да продължи сканирането за зловреден софтуер.
Когато процесът приключи успешно, инструментът ще създаде лог файл. Моля, включете съдържанието на C:ComboFix.txt в следващия Ви коментар в тази тема.
Публикувано изображение Моля, не прикачвайте лог файла/овете от програмата, а го/ги копирайте и поставете в следващия Ви коментар в тази тема.

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

Много добре изглеждат нещата..! :) Вие наблюдавате ли нещо притеснително..?
 
Контролни проверки..:
 
Публикувано изображение Изтеглете Security Check (автор: screen317) от тук

  • [*]Кликнете два пъти върху
SecurityCheck.exe и следвайте инструкциите. [*]Когато програмата завърши работата си, ще се отвори един текстов документ: checkup.txt. [*]Копирайте съдържанието на checkup.txt с Копирай (Copy) и с Постави (Paste) го поставете в следващия си коментар.


Публикувано изображение Изтеглете програмата: ESET Online Scanner

  • [*]Стартирайте esetsmartinstaller_enu.exe Публикувано изображение [*]Сложете отметка на
YES, I accept the Terms of Use и изберете Start:

  • [*]Публикувано изображение

  • [*]Скенерът ще започне да изтегля компонентите, които са му необходими:

  • [*]Публикувано изображение

Уверете се, че е премахната отметката от:

  • [*]
Remove found threats

Уверете се че са маркирани следните позиции:

  • [*]
Scan Archives

Кликнете върху Advanced Settings и маркирайте следните опции:

  • [*]
Scan for potentially unwanted applications [*]Scan for potentially unsafe applications [*]Enable Anti-Stealth Technology

Накрая изберете Start
Скенерът ще започне да изтегля последните дефиниции и ще започне сканиране на вашия компютър.
Моля, бъдете търпеливи, тъй като това може да отнеме известно време.

  • [*]След, като сканирането завърши кликнете на
List of found threats. [*]Щракнете върху Export, и запишете файла на вашия работен плот с  име  ESETScan. Копирайте съдържанието на този доклад, в следващия си отговор. [*]Изберете бутона Back. [*]Изберете бутона Finish.

Сподели този отговор


Линк към този отговор
Сподели в други сайтове
 Results of screen317's Security Check version 0.99.77   Windows 7 Service Pack 1 x64 [color=red][b](UAC is disabled!)[/b][/color]   Internet Explorer 10 [color=red][b]Out of date![/b][/color][b][u]``````````````Antivirus/Firewall Check:``````````````[/b][/u] Windows Firewall Enabled!  Kaspersky Internet Security    Antivirus up to date!  (On Access scanning [b]disabled[/b]!)[b][u]`````````Anti-malware/Other Utilities Check:`````````[/b][/u] TuneUp Utilities 2014    TuneUp Utilities 2014 (en-US)   TuneUp Utilities 2014    Adobe Flash Player 11.9.900.152   Adobe Reader 10.1.1 [color=red][b]Adobe Reader out of Date![/b][/color]   Mozilla Firefox (25.0.1)[b][u]````````Process Check: objlist.exe by Laurent````````[/b][/u]   Malwarebytes Anti-Malware mbamservice.exe   Malwarebytes Anti-Malware mbamgui.exe   Malwarebytes' Anti-Malware mbamscheduler.exe   [b][u]`````````````````System Health check`````````````````[/b][/u] Total Fragmentation on Drive C: 5%[b][u]````````````````````End of Log``````````````````````[/b][/u]

А ЕСЕТ ми изписва: Can not get update. is proxy configured ?

 

 

Иначе за сега системата работи добре мисля че няма нужда да пускаме ESET.

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

Радвам се...! :)
 
Преди да маркирам случая за "Решен", моля, направете следното..:
 
Деинсталирайте ComboFix така:

  • [*]Натиснете Start ==> Run ==> въведете командата
Combofix /Uninstall ==> OK

  • [*]Публикувано изображение

  • [*]Моля, следвайте инструкциите, за да деинсталирате ComboFix. Ще получите съобщение, в което се казва ComboFix е деинсталиран успешно.

Публикувано изображение Изтеглете Delfix.exe и го стартирайте. Сложете отметка пред Remove disinfection tools => натиснете бутона Run Инструмента ще се самоизтрие след като приключи своята задача!
 

Публикувано изображение Деинсталирайте adwcleaner.exe

  • [*]Моля, затворете всички отворени програми и интернет браузъри. [*]Кликнете два пъти върху
adwcleaner.exe за да стартирате инструмента. [*]Кликнете върху Uninstall . [*]Щракнете върху Yes за да деинсталирате Adwcleaner

 

Публикувано изображение Деинсталирайте ESET Online Scaner.

  • [*]
Start => Run, въведете control appwiz.cpl в полето.След това натиснете ENTER. [*]Изберете ESET Online Scanner от списъка с приложения, а след това маркирайте Remove. Aко бъдете подканени рестартирайте компютъра си.

 

Публикувано изображение  Препоръчвам програмата Malwarebytes' Anti-Malware  да остане на вашия компютър и периодично да сканирате системата си с нея (поне един -два пъти в седмицата),като не забравяйте да обновите дефинициите и преди всяко сканиране..!
 
 
Стартирайте PatchMyPC и инсталирайте всички ъпдейти, които инструмента ви предложи.
 
Малко превенции:

Едно от важните неща са MICROSOFT UPDATES. Чрез тях можете да получите всички критични актуализации за вашата операционна система и Internet Explorer. Поддържането на вашата операционна система и браузър с актуални ъпдейти, ще помогне да  направи системата по-малко податлива на атаки от троянски коне и вируси. Моля, отидете на Microsoft и изтеглите всички критични актуализации за да се предотврати възможно повторно заразяване.
 
WOT  Web от Trust, ви предупреждава за рискови сайтове, които се опитват да закачат зловреден софтуер  или  спам. Цветово кодираните икони на WOT  показват рейтингите на 21 милиона уеб сайтове, като ви помага да се избегнат опасните обекти:

  • [*]
Зелена - чисто,можете да влезете [*]Жълто - с повишено внимание [*]Червено - stop

WOT има добавка на разположение за IE, Firefox и Chrome.
 
MVPS HOSTS FILE замества настоящия HOSTS файла с такъв, който ще ограничи известни рекламни сайтове както и нежелани реклами. По същество това не позволява на компютъра да се свързва към тези сайтове, като ги пренасочва към 127.0.0.1, което е IP на локалния ви компютър.

 

 

Поддържайте антивирусната си програма и ако използвате друг antispyware софтуер с актуални ъпдейти и  сканирайте с тях редовно.

 

Пожелавам ви безопасен интернет и лек ден..! :)

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

При стартирането на  PatchMyPC ми излиза това:

 

http://prikachi.com/images.php?images/453/6844453C.jpg 

 

Горните стъпки ги изпълних.

А след като махнах combo fix остана ли Recovery Console ?

Спомням си че преди го имах на хп-то

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

  • Разглеждащи това в момента   0 потребители

    Няма регистрирани потребители разглеждащи тази страница.

  • Горещи теми в момента

  • Подобни теми

    • от ivchodx
      Здравейте,
      снощи пуснах тема в "Сигурност и антивирусна защита", където ми препоръчаха да пиша тук.
      Копирам всичко написано от предходната тема + някои допълнения.
      Машина:
      Лаптоп ASUS F550V с Windows 10 Education (Платен).
      Симптоми:
           Не мога да ъпдейта Windows-a.

          Windows Defender не работи.

          Troubleshooter-a не върши никаква работа.
        
          Kaspersky не се стартира.
           
          Host Service 64 е постоянно включен и понякога използва доста ресурси.
       *Подробности относно проблемите в предишната ми тема.

      Допълнения:
      Снощи вечер пуснах проверка с RogueKiller. Прикачвам снимка с резултата, както и с резултат от премахването, но Host services 64 вече не се вижда в task manager-a, но все още не мога да ъпдейтна windows.
      sfc /scannow DISM /Online /Cleanup-Image /RestoreHealth Написах следните команди като администратор. Всичко беше поправено или наред.

      Прикачвам резултатите от Farbar Recovery Scan Tool. Направих сканиратено след проверката с RogueKiller.

      Addition.txt FRST.txt
    • от achodemo
      Здравейте .
      Не успявам да премахна (предполагам е) вирус . Проблема е следния : записват се едни файлове на всяка флашка , която се постави в PC-то .
      Файловете ги трия ръчно , форматирам флашката и на момента се записват пак .
      Петте файла плюс папка "RECYCLER", в която се създават други папки с произволни имена и във всяка от тях два файла , които се размножават до безкрайно с произволни имена , през цялото време до като флашката стои включена .
      Имам "Malwarebytes " , при сканиране ми премахна доста вредители , но проблема остава .
      Пробвах и с Avast , при включване флашката веднага пуска аларма за autorun-а , че записва 4-те шорткъта и до там , при сканиране не открива нищо на PC-то .

      Моля за съвет и насока , какво може да бъде това и как, с какво , да го премахна ?!

      Търсих в Google , има информация за такъв проблем , но решение не намерих работещо .
      И като цяло виждам че в таск менажера има прекалено много работещи процеси , които нямам идея какви са , но заемат почти цялата ми RAM . 

      Давам снимки  и логовете най-отдолу :

       


      FRST.txt    Addition.txt     
    • от ivan.ivanov.543
      Здрасти! Предварително се извинявам за опростеното и неграмотно обяснение, не разбирам много от компютри, надявам се да е достатъчно разбираемо.   
       
      Преди няколко дена си изтеглих един учебник в pdf формат от замунда, но беше заключен от към търсене на думи в него, копиране и принтиране, също така беше много голям (270мб) за да го кача в онлайн програмите за откючване на pdf файлове който намерих, затова реших да потърся офлайн такава, която да изтегля и без да се замисля  изтеглих  и инсталирах първата програма която намерих в гугъл (понежене в замунда не можах да намеря такава) и тя се оказа вирус. След като я инсталирах, започна автоматично да изтегля и инсталира някакви програми. 
       
      Спрях интернета, деинсталирах програмите който бяха се инсталирали (вкючително и първата програма - вируса) и пробвах да пусна windows defender, но пишеше нещо от сорта на "програмата е блокирана от групата" . Пуснах пак интернета за да потъся как в този случай да пусна дефендъра и в момента в който отворих хрома, автоматично се отвори и затвори нов раздел в браузъра и пак започнаха да се теглят и да се инсталират програми. Спрях отново интернета, деинсталирах пак програмите и от допълнителните системни настройки пуснах възстановяване на системата.
       
      След като възстановяването мина, забелязах, че повечето ми файлове завършват на .qewe. и не може да се отворят и като им сменям формата в такъв какъвто си бяха(pdf, jped или mp4) ми изписва "невалиден файл"Потърсих в ютюб "How to remove .qewe virus " цъкнах на един от туториалите с повече гледания и следвах стъпките - натиснах windows key+r, написах msconfig, влязох в boot, после цъкнах на сейфти мод с нетуърк, натиснах ок и после рестартиране, лаптопа се рестартира и влезе в безопасен режим, после влязох в C:/ не помня къде точно, последната директории бяха drivesr и ect или нещо такова и отворих един фаил с notepad, май се казваше host, изтрих последните 2 ред, май бяха някакъв Ip адрес - нз, след това влязох в хром и изтеглих malwarebytes, пуснах я, намери 118 файла, натиснах да ги сложи под карантина и след като програмата си свърши работата, натиснах пак win.key+r, msconfig и махнах тикчето от сейфти буут-а, рестартирах лаптопа и си помислих, че всичко вече ще си е нормално. Когато влизах в хром вече автоматично не се теглеха и инсталираха различни програми, но повечето файлове си останаха .qewe и win.def. не се отваряше.
       
      Потърсих пак в тубата как да оправя дефендъра, намерих туториал, следвах стъпките (win.key+r, regedit, влязох някъде и изтрих един файл) и дефендъра тръгна, пуснах го да сканира - не намери нищо. Потърсих из ютюб малко информация за .qewe - каквъ формат е и т.н, и се оказа, че е някакъв вид криптиране и че вирусът който съм инсталирал се казва ransomware и такива вируси се ползват за искане на подкуп. Подкуп никой не ми е искал, но забелязах нещо странно в фейсбук - някой ми е влязъл в фейсбука с ip адрес от щатите, въпреки, че съм с google authenticator, т.е дори да ми зане паролата, му трябва да въведе код от приложението google authenticator което е инсталирано на телефона ми. Някакви страници е правено от фбка ми, реклами са пускани за някви хранителни добавки и най-странното беше, че когато си смених паролата на фейсбука и се опитах пак да се логна в него от компа, (понеже като си я сменях цъкнах да се лог офне от всички устойства) ми влезе в някакъв съвсем различен фейсбук, без профилна снимка и с някфо странно име. Този фб е бил регнат в деня в който инсталирах вируса и беше регистриран с телефонният ми номер и беше админ на тези страници, от които са се пускали рекламите, т.е в този момен имаше 2 фейсбука с регистриран еднакъв основен телефонен номер. Изтрих страниците от този фейсбук, направих имейл в абв от сорта на [email protected] и сложих този имейл за основен, след това си изтрих телефонният номер от този фб акаунт и после изтрих и самият акаунт. След това като се опитах да се логна в фб с тел.си номер вече си влезе в моят си фб. 
       
      За сега всичко изглежда наред, но не съм сигурен дали съм махнал вируса напълно. Лаптопа си бачка както преди с изключение на това, че се включва по бавно и повечето ми файлове са .qewe. Може ли да ми помогнете да разбера дали наистина съм махнал вируса напълно и как да си възстановя файловете? 
       
    • от porata
      Добър ден след като стартирам пц-то може би 10-на минути след това ми излзиа един прозорец като "цмд" 
      Който се казва Таскенг.ехе интересно ми е дали това  не е вирус тъй като ми казаха че може да е троянец 



       
      Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-04-2020
      Ran by GAMEPC (13-04-2020 13:05:30)
      Running from C:\Users\GAMEPC\Downloads
      Windows 7 Home Premium Service Pack 1 (X64) (2017-09-08 09:32:01)
      Boot Mode: Normal
      ==========================================================

      ==================== Accounts: =============================
      Administrator (S-1-5-21-2297230751-1021565052-1431566534-500 - Administrator - Disabled)
      GAMEPC (S-1-5-21-2297230751-1021565052-1431566534-1000 - Administrator - Enabled) => C:\Users\GAMEPC
      Guest (S-1-5-21-2297230751-1021565052-1431566534-501 - Limited - Disabled)
      ==================== Security Center ========================
      (If an entry is included in the fixlist, it will be removed.)
      AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
      ==================== Installed Programs ======================
      (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
      Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 26.0.0.127 - Adobe Systems Incorporated)
      Adobe Flash Player 32 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 32.0.0.344 - Adobe)
      Adobe Flash Player 32 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 32.0.0.344 - Adobe)
      Adobe Shockwave Player 12.2 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.2.9.199 - Adobe Systems, Inc.)
      AIDA64 Extreme v6.10 (HKLM-x32\...\AIDA64 Extreme_is1) (Version: 6.10 - FinalWire Ltd.)
      Apex Legends (HKLM-x32\...\{D7FBF176-382D-484E-863A-DFD1124A2A1C}) (Version: 1.0.3.3 - Electronic Arts, Inc.)
      ATI Catalyst Install Manager (HKLM\...\{DC9C8BC1-72CE-B5FE-EA4F-6D9127E51746}) (Version: 3.0.736.0 - ATI Technologies, Inc.)
      Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
      CpuCoreParking (HKLM-x32\...\{0984C56D-2985-4786-AB62-39AB985E269C}) (Version: 2.1.2.0 - CpuCoreParking)
      DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.6.0.0283 - Disc Soft Ltd)
      Discord (HKU\S-1-5-21-2297230751-1021565052-1431566534-1000\...\Discord) (Version: 0.0.306 - Discord Inc.)
      Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
      Euro Truck Simulator 2 Road to the Black Sea (HKLM-x32\...\Euro Truck Simulator 2 Road to the Black Sea_is1) (Version:  - )
      FiveM (HKU\S-1-5-21-2297230751-1021565052-1431566534-1000\...\CitizenFX_FiveM) (Version:  - The CitizenFX Collective)
      GOM Player (HKLM-x32\...\GOM Player) (Version: 2.3.14.5270 - Gretech Corporation)
      Google Chrome (HKLM\...\{DA081EB6-F64C-358C-9BB0-AF1EA8001F34}) (Version: 80.0.3987.163 - Google, Inc.)
      Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
      Heroes of Might and Magic III HD Edition (HKLM-x32\...\SGVyb2Vzb2ZNaWdodGFuZE1hZ2ljSUlJSERFZGl0aW9u_is1) (Version: 1 - )
      Heroes of Might and Magic V - Tribes of the East (HKLM-x32\...\{66FF4C48-0083-4E60-8556-B883AB200092}) (Version:  - )
      House Flipper Garden (HKLM-x32\...\House Flipper Garden_is1) (Version:  - )
      Java 8 Update 171 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180171F0}) (Version: 8.0.1710.11 - Oracle Corporation)
      Java 8 Update 171 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180171F0}) (Version: 8.0.1710.11 - Oracle Corporation)
      Kinect for Windows Speech Recognition Language Pack (en-AU) (HKLM-x32\...\{48CEC0A3-AE10-4EE3-AC62-76D3D58792E5}) (Version: 11.0.7400.336 - Microsoft Corporation)
      Kinect for Windows Speech Recognition Language Pack (en-CA) (HKLM-x32\...\{9C5505DA-F9C1-46CB-9F8F-AC38F8EA518A}) (Version: 11.0.7400.336 - Microsoft Corporation)
      Kinect for Windows Speech Recognition Language Pack (en-GB) (HKLM-x32\...\{A0186231-0A8B-455A-8A25-B64AABCC11A6}) (Version: 11.0.7400.336 - Microsoft Corporation)
      Kinect for Windows Speech Recognition Language Pack (en-US) (HKLM-x32\...\{8AAA44BB-487E-4D01-AF76-484ACB90DBFE}) (Version: 11.0.7400.336 - Microsoft Corporation)
      Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
      Lightshot-5.5.0.4 (HKLM-x32\...\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1) (Version: 5.5.0.4 - Skillbrains)
      Microsoft .NET Framework 4.7.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.03062 - Microsoft Corporation)
      Microsoft Office Language Pack 2010 - Bulgarian/български (HKLM-x32\...\Office14.OMUI.bg-bg) (Version: 14.0.4763.1021 - Microsoft Corporation)
      Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.4734.1000 - Microsoft Corporation)
      Microsoft Server Speech Platform Runtime (x64) (HKLM\...\{3B433087-E62E-4BF5-97F9-4AF6E1C2409C}) (Version: 11.0.7400.345 - Microsoft Corporation)
      Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
      Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{2DFD8316-9EF1-3210-908C-4CB61961C1AC}) (Version: 9.0.30729 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{527BBE2F-1FED-3D8B-91CB-4DB0F838E69E}) (Version: 9.0.30729 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{887868A2-D6DE-3255-AA92-AA0B5A59B874}) (Version: 9.0.30729 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
      Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
      Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
      Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
      Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
      Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
      Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
      Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation)
      Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.22.27821 (HKLM-x32\...\{6361b579-2795-4886-b2a8-53d5239b6452}) (Version: 14.22.27821.0 - Microsoft Corporation)
      Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.22.27821 (HKLM-x32\...\{5bfc1380-fd35-4b85-9715-7351535d077e}) (Version: 14.22.27821.0 - Microsoft Corporation)
      Mozilla Firefox 67.0 (x64 bg) (HKLM\...\Mozilla Firefox 67.0 (x64 bg)) (Version: 67.0 - Mozilla)
      Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 55.0.3 - Mozilla)
      NVIDIA Graphics Driver 442.74 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 442.74 - NVIDIA Corporation)
      NVIDIA HD Audio Driver 1.3.38.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.38.21 - NVIDIA Corporation)
      NVIDIA PhysX System Software 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation)
      OBS Studio (HKLM-x32\...\OBS Studio) (Version: 23.2.1 - OBS Project)
      OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
      Origin (HKLM-x32\...\Origin) (Version: 10.5.67.39484 - Electronic Arts, Inc.)
      PotPlayer-64 bit (HKLM\...\PotPlayer64) (Version: 200317 - Kakao Corp.)
      PotPlayer-64 bit (HKLM-x32\...\PotPlayer64) (Version: 1.7.8556 - Kakao Corp.)
      qBittorrent 4.2.1 (HKLM-x32\...\qBittorrent) (Version: 4.2.1 - The qBittorrent project)
      Rockstar Games Launcher (HKLM-x32\...\Rockstar Games Launcher) (Version: 1.0.18.217 - Rockstar Games)
      Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 2.0.4.8 - Rockstar Games)
      Shutdown8 (HKU\S-1-5-21-2297230751-1021565052-1431566534-1000\...\Shutdown8) (Version: 1.08 - Bandisoft.com)
      Spotify (HKU\S-1-5-21-2297230751-1021565052-1431566534-1000\...\Spotify) (Version: 1.1.30.658.gf13cde74 - Spotify AB)
      StarCraft II (HKLM-x32\...\StarCraft II) (Version:  - Blizzard Entertainment)
      Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
      StreamLabels 0.3.1 (only current user) (HKU\S-1-5-21-2297230751-1021565052-1431566534-1000\...\8000d50a-fcb7-5b38-8a3b-a02a0ec79daa) (Version: 0.3.1 - Streamlabs)
      StreamLabels 0.3.8 (HKU\S-1-5-21-2297230751-1021565052-1431566534-1000\...\{8000d50a-fcb7-5b38-8a3b-a02a0ec79daa}) (Version: 0.3.8 - Streamlabs)
      Streamlabs OBS 0.16.3 (HKLM\...\029c4619-0385-5543-9426-46f9987161d9) (Version: 0.16.3 - General Workings, Inc.)
      swMSM (HKLM-x32\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
      TeamSpeak 3 Client (HKU\S-1-5-21-2297230751-1021565052-1431566534-1000\...\TeamSpeak 3 Client) (Version: 3.1.8 - TeamSpeak Systems GmbH)
      TruckersMP Launcher 1.0.0.4 (HKLM\...\{A227B892-C548-4490-9C5D-DB341F8194A6}_is1) (Version: 1.0.0.4 - TruckersMP Team)
      Uplay (HKLM-x32\...\Uplay) (Version: 73.0 - Ubisoft)
      VALORANT (HKU\S-1-5-21-2297230751-1021565052-1431566534-1000\...\Riot Game valorant.live) (Version:  - Riot Games, Inc)
      Viber (HKLM-x32\...\{0B3F5AEE-47B2-4A5F-8D02-289B7E0828E6}) (Version: 11.9.1.3 - Viber Media S.a.r.l) Hidden
      Viber (HKU\S-1-5-21-2297230751-1021565052-1431566534-1000\...\{8b6836ad-bf1d-4591-9f20-735338e295ea}) (Version: 11.9.1.3 - Viber Media S.a.r.l)
      Winamp (HKLM-x32\...\Winamp) (Version: 5.666  - Nullsoft, Inc)
      WinRAR 5.40 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH)
      WinRAR 5.50 (64-битова версия) (HKLM\...\WinRAR archiver) (Version: 5.50.0 - win.rar GmbH)
      ==================== Custom CLSID (Whitelisted): ==============
      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
      HKU\S-1-5-21-2297230751-1021565052-1431566534-1000\...\ChromeHTML: ->  <==== ATTENTION
      ShellExecuteHooks: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [6723984 2010-01-21] (Microsoft Corporation -> Microsoft Corporation)
      ShellExecuteHooks-x32: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [4222864 2010-01-21] (Microsoft Corporation -> Microsoft Corporation)
      ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2016-08-15] (win.rar GmbH -> Alexander Roshal)
      ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2016-08-15] (win.rar GmbH -> Alexander Roshal)
      ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2020-03-14] (NVIDIA Corporation -> NVIDIA Corporation)
      ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2016-08-15] (win.rar GmbH -> Alexander Roshal)
      ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2016-08-15] (win.rar GmbH -> Alexander Roshal)
      ==================== Codecs (Whitelisted) ====================
      (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
      HKLM\...\Drivers32: [vidc.pDAD] => C:\Windows\system32\prodad-codec.dll [607256 2019-10-15] (proDAD GmbH -> proDAD GmbH)
      HKLM\...\Drivers32: [msacm.voxacm160] => C:\Windows\SysWOW64\vct3216.acm [82944 2003-05-21] (Voxware, Inc.) [File not signed]
      HKLM\...\Drivers32: [msacm.scg726] => C:\Windows\SysWOW64\scg726.acm [13239 2000-03-14] (SHARP Corporation) [File not signed]
      HKLM\...\Drivers32: [msacm.alf2cd] => C:\Windows\SysWOW64\alf2cd.acm [38912 2003-05-21] (NCT Company) [File not signed]
      HKLM\...\Drivers32: [msacm.ac3acm] => C:\Windows\SysWOW64\AC3ACM.acm [81920 2004-02-04] (fccHandler) [File not signed]
      HKLM\...\Drivers32: [msacm.lame] => C:\Windows\SysWOW64\lame.ax [245760 2005-08-01] () [File not signed]
      HKLM\...\Drivers32: [vidc.dvsd] => C:\Windows\SysWOW64\mcdvd_32.dll [261632 2003-05-21] (MainConcept) [File not signed]
      HKLM\...\Drivers32: [vidc.mpg4] => C:\Windows\SysWOW64\mpg4c32.dll [413760 2002-08-20] (Microsoft Corporation) [File not signed]
      HKLM\...\Drivers32: [vidc.mp42] => C:\Windows\SysWOW64\mpg4c32.dll [413760 2002-08-20] (Microsoft Corporation) [File not signed]
      HKLM\...\Drivers32: [vidc.mp43] => C:\Windows\SysWOW64\mpg4c32.dll [413760 2002-08-20] (Microsoft Corporation) [File not signed]
      HKLM\...\Drivers32: [vidc.xvid] => C:\Windows\SysWOW64\xvidvfw.dll [139264 2004-07-03] () [File not signed]
      HKLM\...\Drivers32: [vidc.DIVX] => C:\Windows\SysWOW64\DivX.dll [638976 2003-05-22] (DivXNetworks, Inc.) [File not signed]
      HKLM\...\Drivers32: [vidc.VP60] => C:\Windows\SysWOW64\vp6vfw.dll [438272 2004-12-10] (On2.com) [File not signed]
      HKLM\...\Drivers32: [vidc.VP61] => C:\Windows\SysWOW64\vp6vfw.dll [438272 2004-12-10] (On2.com) [File not signed]
      HKLM\...\Drivers32: [vidc.VP62] => C:\Windows\SysWOW64\vp6vfw.dll [438272 2004-12-10] (On2.com) [File not signed]
      HKLM\...\Drivers32: [vidc.LAGS] => C:\Windows\SysWOW64\lagarith.dll [216064 2011-12-07] ( ) [File not signed]
      ==================== Shortcuts & WMI ========================
      (The entries could be listed to be restored or removed.)
      Shortcut: C:\Users\GAMEPC\Desktop\OSC - Пряк път.lnk -> C:\Users\GAMEPC\Desktop\moi neshta\OSC 1.9\OSC.exe (Frawzy) <==== Cyrillic
      ShortcutWithArgument: C:\Users\GAMEPC\Desktop\moi neshta\Tinder.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  --profile-directory=Default --app-id=hejiihbkifllpgdfndalmghiodgkefan
      ShortcutWithArgument: C:\Users\GAMEPC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Приложения в Chrome\Tinder.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  --profile-directory=Default --app-id=hejiihbkifllpgdfndalmghiodgkefan
      ShortcutWithArgument: C:\Users\GAMEPC\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\d249d9ddd424b688\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory=Default
      ==================== Loaded Modules (Whitelisted) =============
      2017-09-08 12:27 - 2017-09-08 12:27 - 002651136 _____ (Microsoft Corporation) [File not signed] c:\windows\system32\wuaueng2.dll
      ==================== Alternate Data Streams (Whitelisted) ========
      (If an entry is included in the fixlist, only the ADS will be removed.)
      AlternateDataStreams: C:\Users\GAMEPC\AppData\Roaming:00e481b5e22dbe1f649fcddd505d3eb7 [394]
      AlternateDataStreams: C:\Users\GAMEPC\AppData\Roaming:6699d3ee8dd9cf775caae782c8f44f03 [394]
      AlternateDataStreams: C:\Users\GAMEPC\AppData\Roaming:fbd50e2f7662a5c33287ddc6e65ab5a1 [394]
      AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [474]
      ==================== Safe Mode (Whitelisted) ==================
      (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
      ==================== Association (Whitelisted) =================
      ==================== Internet Explorer trusted/restricted ==========
      ==================== Hosts content: =========================
      (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
      2009-07-14 05:34 - 2009-06-11 00:00 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts
      ==================== Other Areas ===========================
      (Currently there is no automatic fix for this section.)
      HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common
      HKU\S-1-5-21-2297230751-1021565052-1431566534-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\GAMEPC\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
      DNS Servers: 192.168.0.1
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
      Windows Firewall is enabled.
      ==================== MSCONFIG/TASK MANAGER disabled items ==
      (If an entry is included in the fixlist, it will be removed.)
      MSCONFIG\startupreg: BCSSync => "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
      MSCONFIG\startupreg: DAEMON Tools Lite Automount => "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
      MSCONFIG\startupreg: EpicGamesLauncher => "C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe" -silent
      MSCONFIG\startupreg: FACEIT => "C:\Users\GAMEPC\AppData\Local\FACEITApp\update.exe" --processStart "FACEIT.exe"
      MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
      MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
      MSCONFIG\startupreg: Spotify => C:\Users\GAMEPC\AppData\Roaming\Spotify\Spotify.exe --autostart --minimized
      MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
      MSCONFIG\startupreg: Viber => "C:\Users\GAMEPC\AppData\Local\Viber\Viber.exe" StartMinimized
      ==================== FirewallRules (Whitelisted) ================
      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
      FirewallRules: [{11074DEE-7B8C-4DC2-AE4C-93DF0A309913}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
      FirewallRules: [{D19357FE-92D5-4C15-865D-6BA1144E3141}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
      FirewallRules: [{21EB0059-8DA7-4F26-8EBC-947F0C4E2AAA}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe () [File not signed]
      FirewallRules: [{F8BB1871-4D02-4C5E-A222-4D557710B3E1}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe () [File not signed]
      FirewallRules: [{1EE7FB5D-9E25-4DA9-ACB5-D608ECDBB452}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe No File
      FirewallRules: [{84ACAD4A-CAC3-405E-BED8-CCE7B6F558B9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe No File
      FirewallRules: [{5C9FEA0E-0037-4228-8A5E-308AD75AC1DF}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe No File
      FirewallRules: [{FD05E114-41E1-4EC3-B5A2-BBA593EE39E2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe No File
      FirewallRules: [{831352BE-7396-43E6-9657-9ED9D8BAB30D}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
      FirewallRules: [{AB5ACC3F-22CB-469F-9EB3-8D69417E7CD5}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
      FirewallRules: [{43ADA9C0-2E56-45D1-B73D-9C89040C463D}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe (Valve -> )
      FirewallRules: [{06129773-C563-4DFF-8D34-BEA82843A4F0}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe (Valve -> )
      FirewallRules: [TCP Query User{0D1FADB8-FCE1-4E0E-B19A-D5490965A994}C:\program files (x86)\winamp\winamp.exe] => (Allow) C:\program files (x86)\winamp\winamp.exe (Nullsoft Inc. -> Nullsoft, Inc.)
      FirewallRules: [UDP Query User{F6FECCC1-1C2E-45A5-B7AC-EAF4B88229DF}C:\program files (x86)\winamp\winamp.exe] => (Allow) C:\program files (x86)\winamp\winamp.exe (Nullsoft Inc. -> Nullsoft, Inc.)
      FirewallRules: [TCP Query User{DEFA441A-0140-4630-9B49-0F0DB88705EC}D:\steamlibrary\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) D:\steamlibrary\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe (PUBG CORPORATION -> Bluehole GinnoGames, Inc.)
      FirewallRules: [UDP Query User{2F3AD7BE-C36D-4E24-BFFA-EED5BE5D11F4}D:\steamlibrary\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) D:\steamlibrary\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe (PUBG CORPORATION -> Bluehole GinnoGames, Inc.)
      FirewallRules: [{B5E37EE1-9BE1-4B57-9AD5-EEF981D7F031}] => (Allow) D:\SteamLibrary\steamapps\common\TheLongDark\tld.exe () [File not signed]
      FirewallRules: [{DC6EA5CC-0B14-4DA5-BA55-E772E5860678}] => (Allow) D:\SteamLibrary\steamapps\common\TheLongDark\tld.exe () [File not signed]
      FirewallRules: [{FF76D716-DBA6-437A-A34F-847AF6AB88AD}] => (Allow) D:\SteamLibrary\steamapps\common\PUBG\TslGame\Binaries\Win64\TslGame_BE.exe (BattlEye Innovations e.K. -> BattlEye Innovations)
      FirewallRules: [{13A0D233-1007-4376-A4B4-1DA27C101ECB}] => (Allow) D:\SteamLibrary\steamapps\common\PUBG\TslGame\Binaries\Win64\TslGame_BE.exe (BattlEye Innovations e.K. -> BattlEye Innovations)
      FirewallRules: [TCP Query User{86D55748-40A6-4288-AEF7-2C0B25BDF778}C:\program files\java\jre1.8.0_171\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_171\bin\javaw.exe
      FirewallRules: [UDP Query User{D8AE6DDF-C0F2-475C-AB9C-B84C11DDC8AB}C:\program files\java\jre1.8.0_171\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_171\bin\javaw.exe
      FirewallRules: [TCP Query User{695C8135-FF2C-4E94-9566-E526643684CA}C:\program files (x86)\common files\oracle\java\javapath_target_116381722\java.exe] => (Allow) C:\program files (x86)\common files\oracle\java\javapath_target_116381722\java.exe
      FirewallRules: [UDP Query User{3091889E-265D-4648-88DF-CEE54431325D}C:\program files (x86)\common files\oracle\java\javapath_target_116381722\java.exe] => (Allow) C:\program files (x86)\common files\oracle\java\javapath_target_116381722\java.exe
      FirewallRules: [{DB2F74E8-C7EB-44B3-81D7-12B84175E2EA}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
      FirewallRules: [{E44676E1-030C-4238-B65F-434792B61DE5}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
      FirewallRules: [TCP Query User{0E86F5BD-F2B3-4EF9-8B0C-48823DA809CB}D:\steamlibrary\steamapps\common\warface\gamecenter\gamecenter.exe] => (Allow) D:\steamlibrary\steamapps\common\warface\gamecenter\gamecenter.exe No File
      FirewallRules: [UDP Query User{0C5E839A-52EC-40D4-969E-24F12ED8D2D0}D:\steamlibrary\steamapps\common\warface\gamecenter\gamecenter.exe] => (Allow) D:\steamlibrary\steamapps\common\warface\gamecenter\gamecenter.exe No File
      FirewallRules: [TCP Query User{8796E73D-79C0-4D0B-AF34-FB3AF9BCC9BA}D:\steamlibrary\steamapps\common\warface\warface\bin32release\game.exe] => (Allow) D:\steamlibrary\steamapps\common\warface\warface\bin32release\game.exe No File
      FirewallRules: [UDP Query User{EFB29360-AB3A-4A44-9CB4-EF91CEBDB39C}D:\steamlibrary\steamapps\common\warface\warface\bin32release\game.exe] => (Allow) D:\steamlibrary\steamapps\common\warface\warface\bin32release\game.exe No File
      FirewallRules: [TCP Query User{91266298-136D-4BB3-8C13-A850A76C9BF1}D:\steamlibrary\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\steamlibrary\steamapps\common\grand theft auto v\gta5.exe (Rockstar Games, Inc. -> Rockstar Games)
      FirewallRules: [UDP Query User{E3EAEE44-6095-4A5E-BE2F-F3E3F8349E0A}D:\steamlibrary\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\steamlibrary\steamapps\common\grand theft auto v\gta5.exe (Rockstar Games, Inc. -> Rockstar Games)
      FirewallRules: [{2D541380-97BF-4291-BDBE-2F2228CAEA60}] => (Allow) D:\SteamLibrary\steamapps\common\EasyAntiCheat\EasyAntiCheat.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
      FirewallRules: [{127D37C8-619F-462E-BE1A-E32131065FF4}] => (Allow) D:\SteamLibrary\steamapps\common\EasyAntiCheat\EasyAntiCheat.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
      FirewallRules: [TCP Query User{3DE0592A-8D12-447D-939D-BCA439AFF137}C:\users\gamepc\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\gamepc\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
      FirewallRules: [UDP Query User{33216198-C2C2-482B-9DC9-2D0D13DBB4FA}C:\users\gamepc\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\gamepc\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
      FirewallRules: [TCP Query User{270B0322-3799-457B-960A-455318931953}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe No File
      FirewallRules: [UDP Query User{A13AA196-1978-4C67-902B-2460B54A5BBF}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe No File
      FirewallRules: [{59D96386-6E3E-4356-8348-CF3CFA65A81B}] => (Allow) D:\SteamLibrary\steamapps\common\Counter-Strike Global Offensive\csgo.exe (Valve -> )
      FirewallRules: [{FFA55DD9-7016-4EC4-A808-1A467A45E95C}] => (Allow) D:\SteamLibrary\steamapps\common\Counter-Strike Global Offensive\csgo.exe (Valve -> )
      FirewallRules: [TCP Query User{DC649560-4400-4885-84A1-B96EE04BD03C}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
      FirewallRules: [UDP Query User{962C91EA-9380-4D1D-8A2F-E951089E3F37}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
      FirewallRules: [TCP Query User{DA0687C4-1D0D-4E01-B34C-68E8FF09FF9F}C:\program files (x86)\origin games\apex\r5apex.exe] => (Allow) C:\program files (x86)\origin games\apex\r5apex.exe No File
      FirewallRules: [UDP Query User{0C271F5D-81B6-4DA7-A0B8-50362178C932}C:\program files (x86)\origin games\apex\r5apex.exe] => (Allow) C:\program files (x86)\origin games\apex\r5apex.exe No File
      FirewallRules: [TCP Query User{5EFBA878-9A61-49AC-9416-CAFD7167CF8E}D:\steamlibrary\steamapps\common\smite\binaries\win64\smite.exe] => (Allow) D:\steamlibrary\steamapps\common\smite\binaries\win64\smite.exe No File
      FirewallRules: [UDP Query User{C837A044-1793-46A0-A9B2-FFC280606631}D:\steamlibrary\steamapps\common\smite\binaries\win64\smite.exe] => (Allow) D:\steamlibrary\steamapps\common\smite\binaries\win64\smite.exe No File
      FirewallRules: [TCP Query User{6C87ADBA-41D8-49FB-A494-F0A177B7F2E5}D:\12323\icarus\appdata\bin64\launcher.exe] => (Allow) D:\12323\icarus\appdata\bin64\launcher.exe No File
      FirewallRules: [UDP Query User{D3766998-33A3-4AAC-836F-4BC92BA34D50}D:\12323\icarus\appdata\bin64\launcher.exe] => (Allow) D:\12323\icarus\appdata\bin64\launcher.exe No File
      FirewallRules: [TCP Query User{5540B6FC-35DB-4545-AF53-B4FE05B85DD6}D:\steamlibrary\steamapps\common\bless online\binaries\win64\bless.exe] => (Allow) D:\steamlibrary\steamapps\common\bless online\binaries\win64\bless.exe No File
      FirewallRules: [UDP Query User{ED42665E-2CA2-4092-A15B-69F686B8F831}D:\steamlibrary\steamapps\common\bless online\binaries\win64\bless.exe] => (Allow) D:\steamlibrary\steamapps\common\bless online\binaries\win64\bless.exe No File
      FirewallRules: [{A6CE7A48-587B-440C-A6B7-9B3AB8F758E0}] => (Allow) D:\SteamLibrary\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe (Rockstar Games, Inc. -> Rockstar Games)
      FirewallRules: [{CD3B56C1-242C-4706-81ED-FF29362608F3}] => (Allow) D:\SteamLibrary\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe (Rockstar Games, Inc. -> Rockstar Games)
      FirewallRules: [TCP Query User{9A6D9654-27A6-4122-9C9C-4D7727258BAA}C:\users\gamepc\appdata\local\fivem\fivem.app\cache\subprocess\fivem_gtaprocess.exe] => (Allow) C:\users\gamepc\appdata\local\fivem\fivem.app\cache\subprocess\fivem_gtaprocess.exe (cfx-collective) [File not signed]
      FirewallRules: [UDP Query User{E49D6701-B325-4215-8711-030A5EC46C9B}C:\users\gamepc\appdata\local\fivem\fivem.app\cache\subprocess\fivem_gtaprocess.exe] => (Allow) C:\users\gamepc\appdata\local\fivem\fivem.app\cache\subprocess\fivem_gtaprocess.exe (cfx-collective) [File not signed]
      FirewallRules: [{279065A7-F5E9-4060-BA27-39476EE213D2}] => (Allow) C:\Users\GAMEPC\Downloads\bin\BlackDesert32.exe No File
      FirewallRules: [{B218AD4A-5B74-40DE-AB02-A3681FCE9C1C}] => (Allow) C:\Users\GAMEPC\Downloads\bin64\BlackDesert64.exe No File
      FirewallRules: [{10F99049-3DA4-4E89-A086-C023E8CD82B2}] => (Allow) C:\Users\GAMEPC\Downloads\BlackDesert_Launcher.exe No File
      FirewallRules: [{3FD78764-41FE-4680-9342-001EA21ECF27}] => (Allow) C:\Users\GAMEPC\Downloads\BlackDesert_Downloader.exe No File
      FirewallRules: [{CD2DAD40-C60E-41F0-ABBF-63FED12CD684}] => (Allow) D:\SteamLibrary\steamapps\common\Albion Online\launcher\AlbionLauncher.exe No File
      FirewallRules: [{9BAD4B07-A517-4574-ABA6-922FE4DA36F4}] => (Allow) D:\SteamLibrary\steamapps\common\Albion Online\launcher\AlbionLauncher.exe No File
      FirewallRules: [TCP Query User{757DFE1C-9664-41C4-B600-E39F75F3E007}D:\fortnait\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) D:\fortnait\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe No File
      FirewallRules: [UDP Query User{00AC97A7-683C-4F74-9AF6-EBFD84CB000D}D:\fortnait\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) D:\fortnait\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe No File
      FirewallRules: [TCP Query User{391AE70C-4E68-4DE8-A05A-D56058FAEBFA}D:\fortnait\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) D:\fortnait\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe No File
      FirewallRules: [UDP Query User{61C858A3-948F-407A-A7BF-2712693C1649}D:\fortnait\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) D:\fortnait\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe No File
      FirewallRules: [TCP Query User{CBB94106-0926-4293-AA94-864143E7ACDC}D:\city\city car driving\bin\win32\starter.exe] => (Allow) D:\city\city car driving\bin\win32\starter.exe No File
      FirewallRules: [UDP Query User{1602653C-F8D6-481F-B4DE-483B83E4A081}D:\city\city car driving\bin\win32\starter.exe] => (Allow) D:\city\city car driving\bin\win32\starter.exe No File
      FirewallRules: [{D70481FE-EDB4-4F66-A879-015B84C54F1C}] => (Allow) D:\SteamLibrary\steamapps\common\PUBG\TslGame\Binaries\Win64\ExecPubg.exe (Bluehole, Inc. -> PUBG Corporation )
      FirewallRules: [{0255AAE2-A93D-49F6-84EA-91CF71112821}] => (Allow) D:\SteamLibrary\steamapps\common\PUBG\TslGame\Binaries\Win64\ExecPubg.exe (Bluehole, Inc. -> PUBG Corporation )
      FirewallRules: [{3EEC0786-9E2E-4EAC-9CB1-97F68AE8DBDA}] => (Allow) D:\SteamLibrary\steamapps\common\TrackMania Nations Forever\TmForever.exe () [File not signed]
      FirewallRules: [{F07A3467-6DA2-4A61-BFA9-75DFE2760BAA}] => (Allow) D:\SteamLibrary\steamapps\common\TrackMania Nations Forever\TmForever.exe () [File not signed]
      FirewallRules: [{7BCD6AF7-E264-49EC-B3DF-0B903C656894}] => (Allow) D:\SteamLibrary\steamapps\common\TrackMania Nations Forever\TmForeverLauncher.exe () [File not signed]
      FirewallRules: [{9796C8A1-0246-4D08-94F7-97B3A81204AF}] => (Allow) D:\SteamLibrary\steamapps\common\TrackMania Nations Forever\TmForeverLauncher.exe () [File not signed]
      FirewallRules: [TCP Query User{4194E6A1-B90A-4C01-AAC1-A150648BD511}D:\1.6\hl.exe] => (Allow) D:\1.6\hl.exe No File
      FirewallRules: [UDP Query User{39B944DB-8264-4416-BBBA-052EEC50F7FC}D:\1.6\hl.exe] => (Allow) D:\1.6\hl.exe No File
      FirewallRules: [TCP Query User{857D0C4A-0661-4E7D-B23A-735FF8ADABA1}D:\steamlibrary\steamapps\common\warface\warface\bin64release\game.exe] => (Allow) D:\steamlibrary\steamapps\common\warface\warface\bin64release\game.exe No File
      FirewallRules: [UDP Query User{29AE9F40-6F4A-4698-8241-A75FE2382548}D:\steamlibrary\steamapps\common\warface\warface\bin64release\game.exe] => (Allow) D:\steamlibrary\steamapps\common\warface\warface\bin64release\game.exe No File
      FirewallRules: [TCP Query User{92B59CE8-E0C7-43A9-9D55-2AEDA2AA9FA5}D:\steamlibrary\steamapps\common\deep rock galactic\fsd\binaries\win64\fsd-win64-shipping.exe] => (Allow) D:\steamlibrary\steamapps\common\deep rock galactic\fsd\binaries\win64\fsd-win64-shipping.exe No File
      FirewallRules: [UDP Query User{8AEEF23D-67B8-4B6C-9DA0-D61F44EFC129}D:\steamlibrary\steamapps\common\deep rock galactic\fsd\binaries\win64\fsd-win64-shipping.exe] => (Allow) D:\steamlibrary\steamapps\common\deep rock galactic\fsd\binaries\win64\fsd-win64-shipping.exe No File
      FirewallRules: [{A383D054-F8C2-45B5-A517-E63819807BB6}] => (Allow) D:\SteamLibrary\steamapps\common\Grand Theft Auto V\PlayGTAV.exe (Rockstar Games, Inc. -> Rockstar Games)
      FirewallRules: [{FD87341A-3B7F-44E8-B09F-ADFBDF1B247D}] => (Allow) D:\SteamLibrary\steamapps\common\Grand Theft Auto V\PlayGTAV.exe (Rockstar Games, Inc. -> Rockstar Games)
      FirewallRules: [{2C2C2027-2BB8-4A51-9A9C-ED9A4BBCB358}] => (Allow) D:\SteamLibrary\steamapps\common\raceroom racing experience\Game\x64\RRRE64.exe No File
      FirewallRules: [{9B1767CE-81DE-4826-8906-9DEFCC351FAB}] => (Allow) D:\SteamLibrary\steamapps\common\raceroom racing experience\Game\x64\RRRE64.exe No File
      FirewallRules: [{E2FEE995-77A6-4556-A200-30CB17D4ABA6}] => (Allow) D:\SteamLibrary\steamapps\common\raceroom racing experience\Game\RRRE.exe No File
      FirewallRules: [{DFB2A3C2-EA05-4944-B38A-7A85B48E8A1F}] => (Allow) D:\SteamLibrary\steamapps\common\raceroom racing experience\Game\RRRE.exe No File
      FirewallRules: [TCP Query User{5A72CD9B-BF9D-4B23-A72B-26D40F24F859}D:\pubg\pubglite\client\shadowtrackerextra\binaries\win64\pubglite-win64-shipping.exe] => (Allow) D:\pubg\pubglite\client\shadowtrackerextra\binaries\win64\pubglite-win64-shipping.exe No File
      FirewallRules: [UDP Query User{8312C3A6-76BE-4C56-A5A6-DE950D9F08F1}D:\pubg\pubglite\client\shadowtrackerextra\binaries\win64\pubglite-win64-shipping.exe] => (Allow) D:\pubg\pubglite\client\shadowtrackerextra\binaries\win64\pubglite-win64-shipping.exe No File
      FirewallRules: [TCP Query User{F64B2B06-1EDF-4393-8640-332BC5898996}D:\apex\apex\r5apex.exe] => (Allow) D:\apex\apex\r5apex.exe (Electronic Arts, Inc. -> Respawn Entertainment)
      FirewallRules: [UDP Query User{E2BBA317-E554-46F4-9705-DB7E4991BF19}D:\apex\apex\r5apex.exe] => (Allow) D:\apex\apex\r5apex.exe (Electronic Arts, Inc. -> Respawn Entertainment)
      FirewallRules: [TCP Query User{06645CA2-731E-4100-8BFC-CF2887EC9BD4}C:\users\gamepc\appdata\local\fivem\fivem.exe] => (Allow) C:\users\gamepc\appdata\local\fivem\fivem.exe (cfx-collective) [File not signed]
      FirewallRules: [UDP Query User{68EFF667-1BA0-46F4-B7E4-B8AC10475E9D}C:\users\gamepc\appdata\local\fivem\fivem.exe] => (Allow) C:\users\gamepc\appdata\local\fivem\fivem.exe (cfx-collective) [File not signed]
      FirewallRules: [{B94666B2-3213-45DC-9A55-A01D147CA93D}] => (Allow) D:\SteamLibrary\steamapps\common\Half-Life\hl.exe (Valve -> Valve)
      FirewallRules: [{35AD171F-75C6-469B-A634-4E9ABEFB99C0}] => (Allow) D:\SteamLibrary\steamapps\common\Half-Life\hl.exe (Valve -> Valve)
      FirewallRules: [TCP Query User{8333A1F9-D09D-4985-B9CD-10A78C408300}C:\users\gamepc\appdata\roaming\acestream\engine\ace_engine.exe] => (Allow) C:\users\gamepc\appdata\roaming\acestream\engine\ace_engine.exe (Innovative Digital Technologies -> )
      FirewallRules: [UDP Query User{D9E8A289-BA55-45AE-A241-45085DACBF2D}C:\users\gamepc\appdata\roaming\acestream\engine\ace_engine.exe] => (Allow) C:\users\gamepc\appdata\roaming\acestream\engine\ace_engine.exe (Innovative Digital Technologies -> )
      FirewallRules: [{F60269A0-9AA8-46D8-98B9-0A888500723C}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe () [File not signed]
      FirewallRules: [{C584D871-7182-4224-96CC-26C664539C6B}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe () [File not signed]
      FirewallRules: [TCP Query User{0E05C3B9-C433-4C3A-8C01-FF69520BF241}C:\users\gamepc\appdata\local\layerth-ethereal-dota2\app-2.5.9\ethereal - dota 2.exe] => (Allow) C:\users\gamepc\appdata\local\layerth-ethereal-dota2\app-2.5.9\ethereal - dota 2.exe No File
      FirewallRules: [UDP Query User{76E5872D-7EB0-40F2-9AD9-61CD16A593A8}C:\users\gamepc\appdata\local\layerth-ethereal-dota2\app-2.5.9\ethereal - dota 2.exe] => (Allow) C:\users\gamepc\appdata\local\layerth-ethereal-dota2\app-2.5.9\ethereal - dota 2.exe No File
      FirewallRules: [TCP Query User{20420812-2158-4116-BD8E-FE273007CA43}C:\users\gamepc\downloads\fivem.exe] => (Allow) C:\users\gamepc\downloads\fivem.exe (cfx-collective) [File not signed]
      FirewallRules: [UDP Query User{1C53FDAE-2CE7-44AD-8F95-828A28E4D6B1}C:\users\gamepc\downloads\fivem.exe] => (Allow) C:\users\gamepc\downloads\fivem.exe (cfx-collective) [File not signed]
      FirewallRules: [TCP Query User{0DE874C5-C399-4C71-A2FB-7D012892D73B}C:\users\gamepc\downloads\cache\subprocess\fivem_gtaprocess.exe] => (Allow) C:\users\gamepc\downloads\cache\subprocess\fivem_gtaprocess.exe No File
      FirewallRules: [UDP Query User{201BA7D9-6E59-4592-89FE-45240B104987}C:\users\gamepc\downloads\cache\subprocess\fivem_gtaprocess.exe] => (Allow) C:\users\gamepc\downloads\cache\subprocess\fivem_gtaprocess.exe No File
      FirewallRules: [TCP Query User{42114D4D-52E5-4B29-A4B1-5EA3A87CE648}D:\warzone\wasda\call of duty modern warfare\modernwarfare.exe] => (Allow) D:\warzone\wasda\call of duty modern warfare\modernwarfare.exe No File
      FirewallRules: [UDP Query User{ADC3D6A5-74A9-43BE-9C8E-0EA092058F7B}D:\warzone\wasda\call of duty modern warfare\modernwarfare.exe] => (Allow) D:\warzone\wasda\call of duty modern warfare\modernwarfare.exe No File
      FirewallRules: [{5C7D63B1-F70B-4ED6-A325-B196C2FEBB19}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
      FirewallRules: [{0ECBF459-D321-4FFE-A103-D92F19E70819}] => (Allow) D:\apex\Apex\EasyAntiCheat_launcher.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
      FirewallRules: [{41EE669E-05F2-472E-BD87-338219AB5C30}] => (Allow) D:\apex\Apex\EasyAntiCheat_launcher.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
      ==================== Restore Points =========================
      07-04-2020 04:20:29 Планирана контролна точка
      08-04-2020 21:01:42 Installed DirectX
      08-04-2020 21:03:15 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030
      12-04-2020 03:12:38 Installed DirectX
      12-04-2020 03:14:16 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030
      ==================== Faulty Device Manager Devices ============
      Name: Realtek RTL8139/810x Family Fast Ethernet NIC
      Description: Realtek RTL8139/810x Family Fast Ethernet NIC
      Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
      Manufacturer: Realtek Semiconductor Corp.
      Service: RTL8023x64
      Problem: : This device is disabled. (Code 22)
      Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

      ==================== Event log errors: ========================
      Application errors:
      ==================
      Error: (04/13/2020 12:43:23 PM) (Source: SetupARService) (EventID: 0) (User: )
      Description: Service cannot be started. System.NullReferenceException: Object reference not set to an instance of an object.
         at SetupAfterRebootService.SetupARService.OnStart(String[] args)
         at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
      Error: (04/13/2020 12:42:03 PM) (Source: Application Error) (EventID: 1000) (User: )
      Description: Име на приложение с грешки: FreemakeUtilsService.exe, версия: 1.0.0.0, времево клеймо: 0x5e454538
      Име на модул с грешки: KERNELBASE.dll, версия: 6.1.7601.24408, времево клеймо: 0x5c92f101
      Код на изключение: 0xe0434352
      Отместване на грешка: 0x0000c5af
      ИД на процес на грешка: 0x5a4
      Начален час на приложението с грешки: 0x01d61177bc69c281
      Път на приложението с грешки: C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
      Път на модула с грешки: C:\Windows\syswow64\KERNELBASE.dll
      ИД на доклад: 078618cf-7d6b-11ea-a16d-94de809321cd
      Error: (04/13/2020 12:41:47 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
      Description: Application: FreemakeUtilsService.exe
      Framework Version: v4.0.30319
      Description: The process was terminated due to an unhandled exception.
      Exception Info: System.IO.FileNotFoundException
         at FreemakeUtilsService.Program.Main(System.String[])
      Error: (04/12/2020 01:52:27 PM) (Source: SetupARService) (EventID: 0) (User: )
      Description: Service cannot be started. System.NullReferenceException: Object reference not set to an instance of an object.
         at SetupAfterRebootService.SetupARService.OnStart(String[] args)
         at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
      Error: (04/12/2020 01:51:13 PM) (Source: Application Error) (EventID: 1000) (User: )
      Description: Име на приложение с грешки: FreemakeUtilsService.exe, версия: 1.0.0.0, времево клеймо: 0x5e454538
      Име на модул с грешки: KERNELBASE.dll, версия: 6.1.7601.24408, времево клеймо: 0x5c92f101
      Код на изключение: 0xe0434352
      Отместване на грешка: 0x0000c5af
      ИД на процес на грешка: 0x5a0
      Начален час на приложението с грешки: 0x01d610b83a55eadf
      Път на приложението с грешки: C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
      Път на модула с грешки: C:\Windows\syswow64\KERNELBASE.dll
      ИД на доклад: 8671c75e-7cab-11ea-97de-94de809321cd
      Error: (04/12/2020 01:50:55 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
      Description: Application: FreemakeUtilsService.exe
      Framework Version: v4.0.30319
      Description: The process was terminated due to an unhandled exception.
      Exception Info: System.IO.FileNotFoundException
         at FreemakeUtilsService.Program.Main(System.String[])
      Error: (04/09/2020 09:03:40 AM) (Source: SetupARService) (EventID: 0) (User: )
      Description: Service cannot be started. System.NullReferenceException: Object reference not set to an instance of an object.
         at SetupAfterRebootService.SetupARService.OnStart(String[] args)
         at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
      Error: (04/09/2020 09:02:22 AM) (Source: Application Error) (EventID: 1000) (User: )
      Description: Име на приложение с грешки: FreemakeUtilsService.exe, версия: 1.0.0.0, времево клеймо: 0x5e454538
      Име на модул с грешки: KERNELBASE.dll, версия: 6.1.7601.24408, времево клеймо: 0x5c92f101
      Код на изключение: 0xe0434352
      Отместване на грешка: 0x0000c5af
      ИД на процес на грешка: 0x5ac
      Начален час на приложението с грешки: 0x01d60e346165c638
      Път на приложението с грешки: C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
      Път на модула с грешки: C:\Windows\syswow64\KERNELBASE.dll
      ИД на доклад: ad3e8ed0-7a27-11ea-99ea-94de809321cd

      System errors:
      =============
      Error: (04/13/2020 12:43:38 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
      Description: Неуспешно зареждане на следния драйвер, който се активира с включване на компютъра или стартиране на системата: 
      cdrom
      Error: (04/13/2020 12:42:43 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
      Description: Услуга Origin Web Helper Service не може да бъде стартирана поради следната грешка: 
      Услугата не отговори навреме на искане за стартиране или управление.
      Error: (04/13/2020 12:42:43 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
      Description: Изтекъл период на изчакване (30000 милисекунди) при изчакване на услуга Origin Web Helper Service да се свърже.
      Error: (04/13/2020 12:42:11 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
      Description: Услуга Freemake Improver не може да бъде стартирана поради следната грешка: 
      Услугата не отговори навреме на искане за стартиране или управление.
      Error: (04/13/2020 12:42:11 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
      Description: Изтекъл период на изчакване (30000 милисекунди) при изчакване на услуга Freemake Improver да се свърже.
      Error: (04/12/2020 01:52:28 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
      Description: Неуспешно зареждане на следния драйвер, който се активира с включване на компютъра или стартиране на системата: 
      cdrom
      Error: (04/12/2020 01:51:51 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
      Description: Услуга Origin Web Helper Service не може да бъде стартирана поради следната грешка: 
      Услугата не отговори навреме на искане за стартиране или управление.
      Error: (04/12/2020 01:51:51 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
      Description: Изтекъл период на изчакване (30000 милисекунди) при изчакване на услуга Origin Web Helper Service да се свърже.

      CodeIntegrity:
      ===================================
      Date: 2019-06-09 17:12:15.330
      Description: 
      Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\GAMEPC\AppData\Local\Temp\ASC-53D9481D\setup32\vfdriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
      Date: 2019-06-09 17:12:15.275
      Description: 
      Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\GAMEPC\AppData\Local\Temp\ASC-53D9481D\setup32\vfdriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
      Date: 2019-06-09 16:10:34.363
      Description: 
      Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\GAMEPC\AppData\Local\Temp\ASC-53D9481D\setup32\vfdriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
      Date: 2019-06-09 16:10:34.318
      Description: 
      Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\GAMEPC\AppData\Local\Temp\ASC-53D9481D\setup32\vfdriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
      Date: 2019-06-09 05:58:19.154
      Description: 
      Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\GAMEPC\AppData\Local\Temp\ASC-6F3B2470\setup32\vfdriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
      Date: 2019-06-09 05:58:19.101
      Description: 
      Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\GAMEPC\AppData\Local\Temp\ASC-6F3B2470\setup32\vfdriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
      Date: 2019-06-09 05:31:45.759
      Description: 
      Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\GAMEPC\AppData\Local\Temp\ASC-6F3B2470\setup32\vfdriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
      Date: 2019-06-09 05:31:45.707
      Description: 
      Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\GAMEPC\AppData\Local\Temp\ASC-6F3B2470\setup32\vfdriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
      ==================== Memory info =========================== 
      BIOS: Award Software International, Inc. F4b 04/26/2013
      Motherboard: Gigabyte Technology Co., Ltd. GA-78LMT-S2P
      Processor: AMD FX-8320E Eight-Core Processor 
      Percentage of memory in use: 30%
      Total physical RAM: 16381.54 MB
      Available physical RAM: 11368.57 MB
      Total Virtual: 32761.22 MB
      Available Virtual: 26564.91 MB
      ==================== Drives ================================
      Drive 😄 () (Fixed) (Total:150 GB) (Free:33.1 GB) NTFS
      Drive d: () (Fixed) (Total:781.41 GB) (Free:352.36 GB) NTFS
      \\?\Volume{2f050b3f-9477-11e7-8c98-806e6f6e6963}\ (Резервирана за системата) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS
      ==================== MBR & Partition Table ====================
      ==========================================================
      Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 0C59AE75)
      Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
      Partition 2: (Not Active) - (Size=150 GB) - (Type=07 NTFS)
      Partition 3: (Not Active) - (Size=781.4 GB) - (Type=05)
      ==================== End of Addition.txt =======================





       
      Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 13-04-2020
      Ran by GAMEPC (administrator) on GAMEPC-PC (Gigabyte Technology Co., Ltd. GA-78LMT-S2P) (13-04-2020 13:04:14)
      Running from C:\Users\GAMEPC\Downloads
      Loaded Profiles: GAMEPC (Available Profiles: GAMEPC)
      Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Български (България)
      Internet Explorer Version 11 (Default browser: Chrome)
      Boot Mode: Normal
      Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
      ==================== Processes (Whitelisted) =================
      (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
      (Discord Inc. -> Discord Inc.) C:\Users\GAMEPC\AppData\Local\Discord\app-0.0.306\Discord.exe <6>
      (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <28>
      (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
      (Valve -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
      (Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <7>
      (Valve -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
      ==================== Registry (Whitelisted) ===================
      (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
      HKLM\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
      HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
      HKU\S-1-5-21-2297230751-1021565052-1431566534-1000\...\Run: [Spotify] => C:\Users\GAMEPC\AppData\Roaming\Spotify\Spotify.exe [22932200 2020-04-09] (Spotify AB -> Spotify Ltd)
      HKU\S-1-5-21-2297230751-1021565052-1431566534-1000\...\Run: [GAMEPC] => explorer.exe hxxp://dinoraptzor.org <==== ATTENTION
      HKU\S-1-5-21-2297230751-1021565052-1431566534-1000\...\Run: [FACEIT] => "C:\Users\GAMEPC\AppData\Local\FACEITApp\update.exe" --processStart "FACEIT.exe"
      HKU\S-1-5-21-2297230751-1021565052-1431566534-1000\...\Run: [gtarcade] => "C:\Users\GAMEPC\AppData\Local\Gtarcade\app\gtarcade.exe"   /auto_start=1 
      HKU\S-1-5-21-2297230751-1021565052-1431566534-1000\...\Run: [Discord] => C:\Users\GAMEPC\AppData\Local\Discord\app-0.0.306\Discord.exe [90950968 2020-02-24] (Discord Inc. -> Discord Inc.)
      HKU\S-1-5-21-2297230751-1021565052-1431566534-1000\...\MountPoints2: {2d2c5be0-94b8-11e7-8704-048d38748987} - E:\setup.exe
      HKU\S-1-5-21-2297230751-1021565052-1431566534-1000\...\MountPoints2: {609d2171-c4d2-11e7-a1c0-048d38748987} - E:\Lenovo_Suite.exe
      HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\80.0.3987.163\Installer\chrmstp.exe [2020-04-08] (Google LLC -> Google LLC)
      Startup: C:\Users\GAMEPC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registration Heroes of Might & Magic 5 - Tribes of the East.LNK [2019-05-20]
      ShortcutTarget: Registration Heroes of Might & Magic 5 - Tribes of the East.LNK -> D:\heroes 3\Heroes of Might and Magic V - Tribes of the East\registration\RegistrationReminder.exe (No File)
      CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
      ==================== Scheduled Tasks (Whitelisted) ============
      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
      Task: {29CD2B59-F360-4EA0-8046-E993FB989355} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_344_pepper.exe [1453624 2020-03-11] (Adobe Inc. -> Adobe)
      Task: {31987656-F768-4D69-96DF-7AD4AB429034} - System32\Tasks\update-S-1-5-21-2297230751-1021565052-1431566534-1000 => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [414872 2017-04-12] (OOO Lightshot -> TODO: <Company name>)
      Task: {3DAD135E-7AD5-4D57-B3E2-9E7F6AD9E01C} - System32\Tasks\{76A40252-E785-4407-9A98-34E12F6F05C9} => C:\Windows\system32\pcalua.exe -a "c:\program files (x86)\hi-rez studios\HiRezGamesDiagAndSupport.exe" -c uninstall=0
      Task: {5A3FE129-72EA-42EB-BA09-CBF91559E528} - System32\Tasks\update-sys => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [414872 2017-04-12] (OOO Lightshot -> TODO: <Company name>)
      Task: {64503CA0-D96B-485A-A2ED-32E1ADEC5130} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2017-09-08] (Google Inc -> Google Inc.)
      Task: {A19D33FF-7FBC-4D6F-B122-FFBC2947D956} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-03-11] (Adobe Inc. -> Adobe)
      Task: {A1D60D55-A6B8-401B-BC05-2938E02DF2F2} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => d:\program files\windows defender\MpCmdRun.exe
      Task: {C4E8B14A-4159-4C58-BDAD-281DBBFC97E8} - System32\Tasks\Microsoft\Windows Defender\MpIdleTask => d:\program files\windows defender\MpCmdRun.exe
      Task: {C84BADD3-E09D-4A90-9F80-FC6F9C4BF9D6} - System32\Tasks\GAMEPC => cmd.exe /c REG ADD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /f /v GAMEPC /t REG_SZ /d "explorer.exe hxxp://dinoraptzor.org" <==== ATTENTION
      Task: {F67C982E-B27B-4B4D-B6F1-B5474BEA2341} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_344_Plugin.exe [1458232 2020-03-11] (Adobe Inc. -> Adobe)
      Task: {FB761E82-2ABF-4B7D-A0A8-3F00F3533DD3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2017-09-08] (Google Inc -> Google Inc.)
      (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
      Task: C:\Windows\Tasks\update-S-1-5-21-2297230751-1021565052-1431566534-1000.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
      Task: C:\Windows\Tasks\update-sys.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
      ==================== Internet (Whitelisted) ====================
      (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
      Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
      Tcpip\..\Interfaces\{BFE47783-CFC6-4DEE-8858-A9889FC23A55}: [DhcpNameServer] 192.168.0.1
      Tcpip\..\Interfaces\{F8E6BFBF-08DD-4CEC-8468-25670AF9DFE4}: [DhcpNameServer] 94.72.140.1
      Internet Explorer:
      ==================
      HKU\S-1-5-21-2297230751-1021565052-1431566534-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/en-xl/?ocid=iehp
      BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2010-01-21] (Microsoft Corporation -> Microsoft Corporation)
      BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_171\bin\ssv.dll [2018-04-20] (Oracle America, Inc. -> Oracle Corporation)
      BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-01-16] (Microsoft Corporation -> Microsoft Corporation)
      BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_171\bin\jp2ssv.dll [2018-04-20] (Oracle America, Inc. -> Oracle Corporation)
      BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2010-01-21] (Microsoft Corporation -> Microsoft Corporation)
      BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\ssv.dll [2018-04-20] (Oracle America, Inc. -> Oracle Corporation)
      BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-01-16] (Microsoft Corporation -> Microsoft Corporation)
      BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\jp2ssv.dll [2018-04-20] (Oracle America, Inc. -> Oracle Corporation)
      FireFox:
      ========
      FF DefaultProfile: mrpwyf7s.default
      FF ProfilePath: C:\Users\GAMEPC\AppData\Roaming\Mozilla\Firefox\Profiles\mrpwyf7s.default [2020-03-02]
      FF user.js: detected! => C:\Users\GAMEPC\AppData\Roaming\Mozilla\Firefox\Profiles\mrpwyf7s.default\user.js [2019-01-02]
      FF Homepage: Mozilla\Firefox\Profiles\mrpwyf7s.default -> google.bg
      FF Notifications: Mozilla\Firefox\Profiles\mrpwyf7s.default -> hxxps://www.instagram.com
      FF Extension: (hotfix-update-xpi-intermediate) - C:\Users\GAMEPC\AppData\Roaming\Mozilla\Firefox\Profiles\mrpwyf7s.default\Extensions\[email protected] [2020-01-04]
      FF Extension: (uBlock Origin) - C:\Users\GAMEPC\AppData\Roaming\Mozilla\Firefox\Profiles\mrpwyf7s.default\Extensions\[email protected] [2019-01-31]
      FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_32_0_0_344.dll [2020-03-11] (Adobe Inc. -> )
      FF Plugin: @java.com/DTPlugin,version=11.171.2 -> C:\Program Files\Java\jre1.8.0_171\bin\dtplugin\npDeployJava1.dll [2018-04-20] (Oracle America, Inc. -> Oracle Corporation)
      FF Plugin: @java.com/JavaPlugin,version=11.171.2 -> C:\Program Files\Java\jre1.8.0_171\bin\plugin2\npjp2.dll [2018-04-20] (Oracle America, Inc. -> Oracle Corporation)
      FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
      FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] (Microsoft Corporation ->  Microsoft Corporation)
      FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
      FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_344.dll [2020-03-11] (Adobe Inc. -> )
      FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1229199.dll [2017-03-31] (Adobe Systems, Inc.) [File not signed]
      FF Plugin-x32: @java.com/DTPlugin,version=11.171.2 -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\dtplugin\npDeployJava1.dll [2018-04-20] (Oracle America, Inc. -> Oracle Corporation)
      FF Plugin-x32: @java.com/JavaPlugin,version=11.171.2 -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\plugin2\npjp2.dll [2018-04-20] (Oracle America, Inc. -> Oracle Corporation)
      FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
      FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] (Microsoft Corporation ->  Microsoft Corporation)
      FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
      FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-01-10] (Microsoft Corporation -> Microsoft Corporation)
      Chrome: 
      =======
      CHR DefaultProfile: Default
      CHR Profile: C:\Users\GAMEPC\AppData\Local\Google\Chrome\User Data\Default [2020-04-13]
      CHR Notifications: Default -> hxxps://csgofast.com; hxxps://forum.dmg-inc.com; hxxps://ghost-recon.ubisoft.com; hxxps://tinder.com; hxxps://www.emag.bg
      CHR StartupUrls: Default -> "hxxp://google.bg/"
      CHR DefaultSearchURL: Default -> hxxps://tinder.com/static/android-chrome-192x192.png
      CHR Extension: (Презентации) - C:\Users\GAMEPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-13]
      CHR Extension: (Документи) - C:\Users\GAMEPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-13]
      CHR Extension: (Google Диск) - C:\Users\GAMEPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-10-17]
      CHR Extension: (YouTube) - C:\Users\GAMEPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-09-08]
      CHR Extension: (Таблици) - C:\Users\GAMEPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-13]
      CHR Extension: (Google Документи офлайн) - C:\Users\GAMEPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-03-10]
      CHR Extension: (Tinder) - C:\Users\GAMEPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\hejiihbkifllpgdfndalmghiodgkefan [2019-04-05]
      CHR Extension: (Hoxx VPN Proxy) - C:\Users\GAMEPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbcojefnccbanplpoffopkoepjmhgdgh [2020-03-17]
      CHR Extension: (Плащания в уеб магазина на Chrome) - C:\Users\GAMEPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-03]
      CHR Extension: (Gmail) - C:\Users\GAMEPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-24]
      CHR Extension: (Chrome Media Router) - C:\Users\GAMEPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-04-03]
      CHR Profile: C:\Users\GAMEPC\AppData\Local\Google\Chrome\User Data\System Profile [2020-02-17]
      Opera: 
      =======
      OPR Extension: (uBlock Origin) - C:\Users\GAMEPC\AppData\Roaming\Opera Software\Opera Stable\Extensions\kccohkcpppjjkkjppopfnflnebibpida [2020-01-04]
      ==================== Services (Whitelisted) ===================
      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
      S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8402648 2019-11-20] (BattlEye Innovations e.K. -> )
      S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [2291392 2017-08-17] (Disc Soft Ltd -> Disc Soft Ltd)
      S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [803440 2019-11-12] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
      S2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [81280 2020-02-13] (Mixbyte Inc -> Freemake)
      S3 mracsvc; C:\Windows\System32\mracsvc.exe [18534552 2019-08-24] (Mail.Ru LLC -> LLC Mail.Ru)
      S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [8019808 2018-03-29] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.)
      S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2495792 2020-04-12] (Electronic Arts, Inc. -> Electronic Arts)
      S2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3447608 2020-04-12] (Electronic Arts, Inc. -> Electronic Arts)
      S3 Rockstar Service; C:\Program Files\Rockstar Games\Launcher\RockstarService.exe [1688720 2020-03-05] (Rockstar Games, Inc. -> Rockstar Games)
      S2 SetupARService; C:\Program Files (x86)\Realtek\Audio\SetupAfterRebootService.exe [24576 2017-09-08] (Realtek Semiconductor.) [File not signed]
      S3 uncheater_bgl; C:\Program Files\Common Files\Uncheater\uncheater_bgl.exe [2097008 2019-11-08] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.)
      S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2017-06-20] (Microsoft Windows -> Microsoft Corporation)
      R2 wuauserv; C:\Windows\system32\wuaueng2.dll [2651136 2017-09-08] (Microsoft Corporation) [File not signed]
      S3 FACEITService; C:/Program Files/FACEIT AC/FACEITService.exe [X]
      R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000 
      S3 WsDrvInst; "C:\Program Files (x86)\Wondershare\Video Converter Ultimate(CPC)\Transfer\DriverInstall.exe" [X]
      ===================== Drivers (Whitelisted) ===================
      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
      R0 amdide64; C:\Windows\System32\DRIVERS\amdide64.sys [11944 2017-09-08] (Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.)
      R0 amdsata; C:\Windows\System32\DRIVERS\amdsata.sys [67128 2009-04-28] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
      R0 amdxata; C:\Windows\System32\drivers\amdxata.sys [28216 2009-04-28] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
      R0 AtiPcie; C:\Windows\System32\DRIVERS\AtiPcie.sys [16440 2009-05-04] (Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.)
      R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2017-09-11] (Disc Soft Ltd -> Disc Soft Ltd)
      R3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [47672 2017-09-11] (Disc Soft Ltd -> Disc Soft Ltd)
      R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [27552 2017-09-08] (Martin Malik - REALiX -> REALiX(tm))
      R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [129224 2017-09-08] (Qualcomm Atheros -> Qualcomm Atheros Co., Ltd.)
      S3 mracdrv; C:\Windows\System32\drivers\mracdrv.sys [17770920 2019-08-24] (Mail.Ru LLC -> LLC Mail.Ru)
      S3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [69840 2019-07-18] (NVIDIA Corporation -> NVIDIA Corporation)
      S3 RTL8023x64; C:\Windows\System32\DRIVERS\Rtnic64.sys [61656 2017-09-08] (Realtek Semiconductor Corp -> Realtek Semiconductor Corporation )
      R3 usbfilter; C:\Windows\System32\DRIVERS\usbfilter.sys [34872 2009-04-03] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
      S3 VOICEMOD_Driver; C:\Windows\System32\drivers\vmdrv.sys [27648 2019-07-02] (Windows (R) Win 7 DDK provider) [File not signed]
      S3 CLMirrorDriver; system32\DRIVERS\CLMirrorDriver.sys [X]
      S3 IntcAzAudAddService; system32\drivers\RTKVHD64.sys [X]
      S4 nvvhci; system32\DRIVERS\nvvhci.sys [X]
      S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
      ==================== NetSvcs (Whitelisted) ===================
      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

      ==================== One month (created) ===================
      (If an entry is included in the fixlist, the file/folder will be moved.)
      2020-04-13 13:04 - 2020-04-13 13:05 - 000018493 _____ C:\Users\GAMEPC\Downloads\FRST.txt
      2020-04-13 13:03 - 2020-04-13 13:04 - 000000000 ____D C:\FRST
      2020-04-13 13:02 - 2020-04-13 13:03 - 002281984 _____ (Farbar) C:\Users\GAMEPC\Downloads\FRST64.exe
      2020-04-13 13:02 - 2020-04-13 13:02 - 002281984 _____ (Farbar) C:\Users\GAMEPC\Downloads\Непотвърдено 720436.crdownload
      2020-04-12 15:52 - 2020-04-12 15:54 - 021108919 _____ C:\Users\GAMEPC\Downloads\IMG_0571.mov
      2020-04-11 14:13 - 2020-04-11 14:13 - 000013913 _____ C:\Users\GAMEPC\Downloads\Richard.Hammond's.Big.Longest.Railway.Tunnel.2020.1080i.HDTV.x264.torrent
      2020-04-11 14:13 - 2020-04-11 14:13 - 000013724 _____ C:\Users\GAMEPC\Downloads\Richard.Hammond's.Big.Super.Stadium.2020.1080i.HDTV.x264.torrent
      2020-04-11 14:07 - 2020-04-11 14:07 - 000020396 _____ C:\Users\GAMEPC\Downloads\Richard.Hammond's.Big.Tallest.Building.On.Earth.2020.720p.HDTV.x264.torrent
      2020-04-11 14:07 - 2020-04-11 14:07 - 000013420 _____ C:\Users\GAMEPC\Downloads\Richard.Hammond's.Big.Mega.Ship.2020.1080i.HDTV.x264.torrent
      2020-04-10 13:56 - 2020-04-10 13:56 - 000011541 _____ C:\Users\GAMEPC\Downloads\Busty.Coeds.vs.Lusty.Cheerleaders.2011.HDRip.720p.x264.mp4.torrent
      2020-04-09 13:58 - 2020-04-09 14:13 - 169566096 _____ C:\Users\GAMEPC\Downloads\twerk.AVI
      2020-04-09 13:58 - 2020-04-09 14:06 - 058040907 _____ C:\Users\GAMEPC\Downloads\MOV01556.mpeg
      2020-04-07 15:07 - 2020-04-07 15:07 - 000001655 _____ C:\Users\Public\Desktop\VALORANT.lnk
      2020-04-07 15:07 - 2020-04-07 15:07 - 000001655 _____ C:\ProgramData\Desktop\VALORANT.lnk
      2020-04-07 15:07 - 2020-04-07 15:07 - 000000000 ____D C:\Users\GAMEPC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Riot Games
      2020-04-07 15:07 - 2020-04-07 15:07 - 000000000 ____D C:\Riot Games
      2020-04-07 15:07 - 2020-04-07 15:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games
      2020-04-07 15:06 - 2020-04-07 15:07 - 000000000 ____D C:\Users\GAMEPC\AppData\Local\Riot Games
      2020-04-07 15:06 - 2020-04-07 15:07 - 000000000 ____D C:\ProgramData\Riot Games
      2020-04-07 15:05 - 2020-04-07 15:06 - 068288168 _____ (Riot Games, Inc.) C:\Users\GAMEPC\Downloads\Install VALORANT.exe
      2020-04-06 20:12 - 2020-04-06 20:12 - 000016557 _____ C:\Users\GAMEPC\Downloads\Now.You.See.Me.2013.EXTENDED.480p.BDRip.x265.AC3.BGaudio-REFLUX.torrent
      2020-04-06 20:08 - 2020-04-06 20:08 - 000011672 _____ C:\Users\GAMEPC\Downloads\The.Lone.Ranger.2013.BDRip.x264.BGAUDiO-SLSS.torrent
      2020-04-06 20:05 - 2020-04-06 20:05 - 000014150 _____ C:\Users\GAMEPC\Downloads\Jack.the.Giant.Slayer.2013.576p.BDRip.x265.DUAL-REFLUX.torrent
      2020-04-05 02:03 - 2020-04-05 02:03 - 000151200 _____ C:\Users\GAMEPC\Downloads\The.Penguins.of.Madagascar.2008.DVDRip.XviD.BGAUDIO-nikio96.torrent
      2020-04-04 15:32 - 2020-04-04 15:32 - 000173894 _____ C:\Users\GAMEPC\Downloads\Hawaii.Five-0.S01.720p.WEB-DL.BG.ENG.H.264-smsliverpool.torrent
      2020-04-04 14:41 - 2020-04-04 14:41 - 000053564 _____ C:\Users\GAMEPC\Downloads\Arrival__2016.(subs.sab.bz).rar
      2020-04-04 14:41 - 2020-04-04 14:41 - 000011894 _____ C:\Users\GAMEPC\Downloads\Arrival.2016.576p.BDRIP.x264.AAC-GOD.torrent
      2020-04-02 01:56 - 2020-04-02 01:56 - 000014519 _____ C:\Users\GAMEPC\Downloads\National.Treasure.2004.BRRip.XviD.BGAUDiO-ZmN.torrent
      2020-04-01 02:07 - 2020-04-01 02:07 - 000055713 _____ C:\Users\GAMEPC\Downloads\Meet The Fockers [DVDRip][2004][BGAudio][BugzBunny].avi.torrent
      2020-03-31 23:21 - 2020-03-31 23:21 - 000089245 _____ C:\Users\GAMEPC\Downloads\Addams.Family.Values.1993.1080p.BluRay.x264-SlzD.torrent
      2020-03-31 23:21 - 2020-03-31 23:21 - 000026602 _____ C:\Users\GAMEPC\Downloads\addams.family.values.1993.bluray.bg(subsunacs.net).rar
      2020-03-31 23:19 - 2020-03-31 23:19 - 000026083 _____ C:\Users\GAMEPC\Downloads\the_addams_family(subsunacs.net).zip
      2020-03-31 23:19 - 2020-03-31 23:19 - 000015432 _____ C:\Users\GAMEPC\Downloads\The.Addams.Family.1991.HDTVRip.XviD.AC3-KiNGS.torrent
      2020-03-30 23:36 - 2020-03-31 00:08 - 000000000 ____D C:\Users\GAMEPC\Documents\Assassin's Creed Syndicate
      2020-03-30 23:36 - 2020-03-30 23:36 - 000000000 ____D C:\Users\GAMEPC\AppData\Roaming\uplay
      2020-03-30 21:17 - 2020-03-30 21:17 - 000058328 _____ C:\Users\GAMEPC\Downloads\Assassin's Creed Syndicate - Gold Edition + v1.5 + All DLCs [FitGirl Repack].torrent
      2020-03-30 20:08 - 2020-03-30 20:08 - 001024240 _____ C:\Users\GAMEPC\Downloads\filmora-idco_setup_full1901.exe
      2020-03-30 20:07 - 2020-03-30 20:07 - 001153264 _____ C:\Users\GAMEPC\Downloads\filmorapro_setup_full4895.exe
      2020-03-30 20:03 - 2020-03-30 20:03 - 000000000 ____D C:\Users\GAMEPC\Documents\New Folder(2)
      2020-03-30 20:03 - 2020-03-30 20:03 - 000000000 ____D C:\Users\GAMEPC\Documents\New Folder(1)
      2020-03-30 20:02 - 2020-03-30 20:02 - 000000000 ____D C:\Users\GAMEPC\Documents\New Folder
      2020-03-30 19:35 - 2020-03-30 19:37 - 135856128 _____ C:\Users\GAMEPC\Downloads\blender-2.82a-windows64.msi
      2020-03-28 04:34 - 2020-03-28 04:35 - 018548431 _____ C:\Users\GAMEPC\Downloads\voicemod crack .rar
      2020-03-28 04:22 - 2020-03-28 04:22 - 023272680 _____ (Voicemod S.L. ) C:\Users\GAMEPC\Downloads\VoicemodSetup.exe
      2020-03-28 04:22 - 2019-07-02 17:50 - 000027648 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\vmdrv.sys
      2020-03-26 16:39 - 2020-03-26 16:39 - 000021708 _____ C:\Users\GAMEPC\Downloads\the_hunt(subsunacs.net).7z
      2020-03-26 16:38 - 2020-03-26 16:38 - 000038078 _____ C:\Users\GAMEPC\Downloads\The.Hunt.2020.1080p.AMZN.WEBRip.DDP5.1.x264-NTG.torrent
      2020-03-25 22:47 - 2019-01-01 00:02 - 006045924 _____ C:\Users\GAMEPC\Desktop\meepoof_legacy_nonQcast.exe
      2020-03-25 22:45 - 2020-03-25 22:45 - 005896438 _____ C:\Users\GAMEPC\Downloads\meepoofv1_legacy_nonQcast.zip
      2020-03-25 02:45 - 2020-03-25 02:45 - 000002971 _____ C:\Users\GAMEPC\Downloads\Unacknowledged.2017.1080p.WEB.x265.AAC-Dr3adLoX.torrent
      2020-03-25 02:42 - 2020-03-25 02:42 - 000013592 _____ C:\Users\GAMEPC\Downloads\Most.Evil.Egocentric.Killers.1080i.HDTV.x264.torrent
      2020-03-24 19:05 - 2020-03-24 19:05 - 000002374 _____ C:\Users\GAMEPC\Desktop\StreamLabels.lnk
      2020-03-24 19:04 - 2020-03-24 19:05 - 000000000 ____D C:\Users\GAMEPC\AppData\Local\streamlabels-updater
      2020-03-23 15:18 - 2020-03-23 15:18 - 000045449 _____ C:\Users\GAMEPC\Downloads\The_Invisible_Man.(subs.sab.bz).zip
      2020-03-23 15:18 - 2020-03-23 15:18 - 000039071 _____ C:\Users\GAMEPC\Downloads\The.Invisible.Man.2020.1080p.WEB-DL.H264.AC3-EVO.torrent
      2020-03-23 15:14 - 2020-03-23 15:14 - 000012215 _____ C:\Users\GAMEPC\Downloads\Toy.Story.4.2019.BRRip.x265.AC3.BGAUDiO-SiSO.torrent
      2020-03-22 14:43 - 2020-03-22 14:43 - 000315856 _____ C:\Users\GAMEPC\Downloads\SHUTDOWN8-SETUP.EXE
      2020-03-22 14:43 - 2020-03-22 14:43 - 000001043 _____ C:\Users\GAMEPC\Desktop\Shutdown8.lnk
      2020-03-22 14:43 - 2020-03-22 14:43 - 000000000 ____D C:\Users\GAMEPC\AppData\Local\Shutdown8
      2020-03-22 14:42 - 2020-03-22 14:42 - 000566784 _____ C:\Users\GAMEPC\Downloads\ShutDown.exe
      2020-03-22 14:32 - 2020-03-16 16:07 - 039835432 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
      2020-03-22 14:32 - 2020-03-16 16:07 - 022106560 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
      2020-03-22 14:32 - 2020-03-16 16:07 - 018416616 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
      2020-03-22 14:32 - 2020-03-16 16:06 - 004257984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
      2020-03-22 14:32 - 2020-03-16 13:10 - 001729440 _____ C:\Windows\system32\vulkaninfo-1-999-0-0-0.exe
      2020-03-22 14:32 - 2020-03-16 13:10 - 001729440 _____ C:\Windows\system32\vulkaninfo.exe
      2020-03-22 14:32 - 2020-03-16 13:10 - 001329576 _____ C:\Windows\SysWOW64\vulkaninfo-1-999-0-0-0.exe
      2020-03-22 14:32 - 2020-03-16 13:10 - 001329576 _____ C:\Windows\SysWOW64\vulkaninfo.exe
      2020-03-22 14:32 - 2020-03-16 13:10 - 001079208 _____ C:\Windows\system32\vulkan-1-999-0-0-0.dll
      2020-03-22 14:32 - 2020-03-16 13:10 - 001079208 _____ C:\Windows\system32\vulkan-1.dll
      2020-03-22 14:32 - 2020-03-16 13:10 - 000937920 _____ C:\Windows\SysWOW64\vulkan-1-999-0-0-0.dll
      2020-03-22 14:32 - 2020-03-16 13:10 - 000937920 _____ C:\Windows\SysWOW64\vulkan-1.dll
      2020-03-22 14:32 - 2020-03-16 13:10 - 000440040 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
      2020-03-22 14:32 - 2020-03-16 13:10 - 000343784 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
      2020-03-22 14:32 - 2020-03-16 13:09 - 127357328 _____ (NVIDIA Corp.) C:\Windows\system32\nvoptix.dll
      2020-03-22 14:32 - 2020-03-16 13:09 - 040314976 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
      2020-03-22 14:32 - 2020-03-16 13:09 - 029930728 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl64.dll
      2020-03-22 14:32 - 2020-03-16 13:09 - 027555560 _____ (NVIDIA Corporation) C:\Windows\system32\nvrtum64.dll
      2020-03-22 14:32 - 2020-03-16 13:09 - 025239952 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl32.dll
      2020-03-22 14:32 - 2020-03-16 13:09 - 011834784 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll
      2020-03-22 14:32 - 2020-03-16 13:09 - 010161040 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll
      2020-03-22 14:32 - 2020-03-16 13:09 - 000420240 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
      2020-03-22 14:32 - 2020-03-16 13:08 - 029545584 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
      2020-03-22 14:32 - 2020-03-16 13:08 - 022880352 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
      2020-03-22 14:32 - 2020-03-16 13:08 - 017464208 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
      2020-03-22 14:32 - 2020-03-16 13:08 - 015029992 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
      2020-03-22 14:32 - 2020-03-16 13:08 - 004988136 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
      2020-03-22 14:32 - 2020-03-16 13:08 - 004447648 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
      2020-03-22 14:32 - 2020-03-16 13:08 - 002068368 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
      2020-03-22 14:32 - 2020-03-16 13:08 - 001720208 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6444274.dll
      2020-03-22 14:32 - 2020-03-16 13:08 - 001560808 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
      2020-03-22 14:32 - 2020-03-16 13:08 - 001482984 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6444274.dll
      2020-03-22 14:32 - 2020-03-16 13:08 - 001476536 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
      2020-03-22 14:32 - 2020-03-16 13:08 - 001363176 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll
      2020-03-22 14:32 - 2020-03-16 13:08 - 001139832 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
      2020-03-22 14:32 - 2020-03-16 13:08 - 001057696 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll
      2020-03-22 14:32 - 2020-03-16 13:08 - 000625776 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
      2020-03-22 14:32 - 2020-03-16 13:08 - 000539880 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
      2020-03-22 14:32 - 2020-03-16 13:08 - 000517232 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
      2020-03-22 14:32 - 2020-03-16 13:08 - 000422328 _____ C:\Windows\system32\nvofapi64.dll
      2020-03-22 14:32 - 2020-03-16 13:08 - 000373360 _____ C:\Windows\SysWOW64\nvofapi.dll
      2020-03-22 14:32 - 2020-03-16 13:08 - 000182368 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
      2020-03-22 14:32 - 2020-03-16 13:08 - 000164464 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
      2020-03-22 14:32 - 2020-03-16 13:08 - 000158304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
      2020-03-22 14:32 - 2020-03-16 13:08 - 000143288 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
      2020-03-22 14:32 - 2020-03-16 13:07 - 040502176 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
      2020-03-22 14:32 - 2020-03-16 13:07 - 035371424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
      2020-03-22 14:32 - 2020-03-16 13:07 - 000518560 _____ (NVIDIA Corporation) C:\Windows\system32\nvcbl64.dll
      2020-03-22 14:28 - 2020-03-22 14:29 - 554302392 _____ (NVIDIA Corporation) C:\Users\GAMEPC\Downloads\442.74-desktop-win8-win7-64bit-international-whql.exe
      2020-03-21 05:08 - 2020-03-21 05:08 - 000021014 _____ C:\Users\GAMEPC\Downloads\Scooby Doo Mystery Incorporated Season 2 DVDRip BG Audio - SPYRO.torrent
      2020-03-20 16:09 - 2020-03-20 16:09 - 000077329 _____ C:\Users\GAMEPC\Downloads\_Yavka.net_The.Outsider.S01E01.WEBRip.x264-ION10.zip
      2020-03-20 16:09 - 2020-03-20 16:09 - 000041769 _____ C:\Users\GAMEPC\Downloads\The.Outsider.2020.S01E01.WEB.H264-XLF.torrent
      2020-03-20 15:11 - 2020-03-20 15:11 - 000056630 _____ C:\Users\GAMEPC\Downloads\Secret.Window.2004.DVDrip.XviD.Brutus-WORKZ.torrent
      2020-03-20 15:08 - 2020-03-20 15:08 - 000025691 _____ C:\Users\GAMEPC\Downloads\1408.2007.Director_s.Cut.720p.HDDVD.x264_CtrlHD.(subs.sab.bz).rar
      2020-03-20 15:07 - 2020-03-20 15:07 - 000014658 _____ C:\Users\GAMEPC\Downloads\1408.2007.BRRip.XViD.AC3 -playXD.torrent
      2020-03-20 15:03 - 2020-03-20 15:03 - 000014435 _____ C:\Users\GAMEPC\Downloads\Daybreakers.2009.BDRip.x264.AAC.BGAUDiO-SiSO.torrent
      2020-03-20 14:59 - 2020-03-20 14:59 - 000056731 _____ C:\Users\GAMEPC\Downloads\Dreamcatcher.DVDrip.AC3.torrent
      2020-03-19 14:12 - 2020-03-19 14:22 - 000000000 ____D C:\Users\GAMEPC\AppData\Roaming\ShootersPool
      2020-03-19 14:12 - 2020-03-19 14:12 - 000000000 ____D C:\Users\GAMEPC\Documents\ShootersPool
      2020-03-19 14:12 - 2020-03-19 14:12 - 000000000 ____D C:\Users\GAMEPC\AppData\Local\ShootersPool
      2020-03-19 13:39 - 2020-03-19 13:57 - 1545182216 _____ C:\Users\GAMEPC\Downloads\ShootersPool-1.8.2c_Setup.exe
      2020-03-17 16:31 - 2020-03-17 16:31 - 000033204 _____ C:\Users\GAMEPC\Downloads\swtros_2019_web_unacs_team(subsunacs.net).rar
      2020-03-17 16:30 - 2020-03-17 16:30 - 000027541 _____ C:\Users\GAMEPC\Downloads\Star.Wars.Episode.IX.The.Rise.of.Skywalker.2020.HDRip.AC3.x264-CMRG.torrent
      2020-03-15 14:48 - 2020-03-15 14:48 - 000013669 _____ C:\Users\GAMEPC\Downloads\Richard.Hammond's.Big.Austria's.Mega.Dam.2020.1080i.HDTV.x264.torrent
      2020-03-15 00:26 - 2020-03-15 00:30 - 068914501 _____ C:\Users\GAMEPC\Downloads\FullSizeRender.mov
      2020-03-14 19:01 - 2020-03-14 19:08 - 000000000 ____D C:\Users\GAMEPC\AppData\Roaming\CitizenFX
      2020-03-14 18:50 - 2020-04-09 18:17 - 000000000 ____D C:\Users\GAMEPC\AppData\Local\FiveM
      2020-03-14 18:50 - 2020-03-14 18:50 - 008885192 _____ (cfx-collective) C:\Users\GAMEPC\Downloads\FiveM.exe
      2020-03-14 18:50 - 2020-03-14 18:50 - 000002024 _____ C:\Users\GAMEPC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FiveM Singleplayer.lnk
      2020-03-14 18:50 - 2020-03-14 18:50 - 000002016 _____ C:\Users\GAMEPC\Desktop\FiveM Singleplayer.lnk
      2020-03-14 18:50 - 2020-03-14 18:50 - 000002016 _____ C:\Users\GAMEPC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FiveM.lnk
      2020-03-14 18:50 - 2020-03-14 18:50 - 000002008 _____ C:\Users\GAMEPC\Desktop\FiveM.lnk
      ==================== One month (modified) ==================
      (If an entry is included in the fixlist, the file/folder will be moved.)
      2020-04-13 12:56 - 2017-09-23 18:42 - 000000000 ____D C:\Program Files (x86)\Steam
      2020-04-13 12:51 - 2009-07-14 07:45 - 000028352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
      2020-04-13 12:51 - 2009-07-14 07:45 - 000028352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
      2020-04-13 12:49 - 2019-03-14 23:38 - 000000000 ____D C:\Users\GAMEPC\AppData\Local\Spotify
      2020-04-13 12:44 - 2017-09-09 22:09 - 000000000 ____D C:\Users\GAMEPC\AppData\Roaming\discord
      2020-04-13 12:42 - 2019-03-14 23:37 - 000000000 ____D C:\Users\GAMEPC\AppData\Roaming\Spotify
      2020-04-13 12:42 - 2017-09-08 14:03 - 000000000 ____D C:\ProgramData\NVIDIA
      2020-04-13 12:41 - 2009-07-14 08:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
      2020-04-13 03:59 - 2019-07-31 00:33 - 000000000 ____D C:\Users\GAMEPC\AppData\Roaming\obs-studio
      2020-04-13 03:38 - 2019-08-14 02:36 - 000000390 _____ C:\Windows\Tasks\update-sys.job
      2020-04-13 02:45 - 2019-08-14 02:36 - 000000390 _____ C:\Windows\Tasks\update-S-1-5-21-2297230751-1021565052-1431566534-1000.job
      2020-04-12 03:45 - 2019-12-26 03:14 - 000000000 ____D C:\Users\GAMEPC\AppData\Roaming\Origin
      2020-04-12 03:12 - 2019-02-11 22:09 - 000000000 ____D C:\ProgramData\Origin
      2020-04-12 03:11 - 2019-12-26 03:16 - 000000000 ____D C:\Program Files (x86)\Origin
      2020-04-12 03:11 - 2019-12-26 03:14 - 000000000 ____D C:\Users\GAMEPC\AppData\Local\Origin
      2020-04-11 17:11 - 2017-09-10 01:33 - 000000000 ____D C:\Users\GAMEPC\AppData\Roaming\qBittorrent
      2020-04-08 00:03 - 2018-11-16 15:10 - 000002181 _____ C:\Users\Public\Desktop\Google Chrome.lnk
      2020-04-08 00:03 - 2018-11-16 15:10 - 000002181 _____ C:\ProgramData\Desktop\Google Chrome.lnk
      2020-04-08 00:03 - 2017-09-08 13:35 - 000002222 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
      2020-04-06 03:47 - 2017-09-19 23:12 - 000000000 ____D C:\Users\GAMEPC\AppData\Roaming\TS3Client
      2020-04-03 11:39 - 2018-01-11 17:53 - 000640612 _____ C:\Windows\system32\perfh002.dat
      2020-04-03 11:39 - 2018-01-11 17:53 - 000114470 _____ C:\Windows\system32\perfc002.dat
      2020-04-03 11:39 - 2009-07-14 08:13 - 001498588 _____ C:\Windows\system32\PerfStringBackup.INI
      2020-04-03 11:39 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\inf
      2020-03-31 00:08 - 2009-07-14 08:32 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
      2020-03-30 20:00 - 2019-08-08 04:08 - 000000000 ____D C:\Users\GAMEPC\AppData\Local\NVIDIA
      2020-03-28 04:27 - 2017-09-08 15:54 - 000000000 ____D C:\Users\GAMEPC\AppData\Local\CrashDumps
      2020-03-24 19:05 - 2019-10-04 14:40 - 000002382 _____ C:\Users\GAMEPC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StreamLabels.lnk
      2020-03-24 19:02 - 2019-07-31 03:15 - 000000000 ____D C:\Users\GAMEPC\AppData\Roaming\slobs-client
      2020-03-24 19:01 - 2019-07-31 03:14 - 000000000 ____D C:\Program Files\Streamlabs OBS
      2020-03-21 16:32 - 2018-11-03 19:10 - 000000000 ____D C:\Users\GAMEPC\AppData\Local\DigitalEntitlements
      2020-03-21 02:54 - 2017-09-08 13:35 - 000003434 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA
      2020-03-21 02:54 - 2017-09-08 13:35 - 000003306 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore
      2020-03-20 21:19 - 2017-09-18 19:14 - 000000000 ____D C:\ProgramData\McAfee
      2020-03-20 17:01 - 2017-12-06 19:25 - 000000000 ____D C:\Users\GAMEPC\AppData\Roaming\ViberPC
      2020-03-19 14:12 - 2018-07-27 18:56 - 000466456 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll
      2020-03-19 14:12 - 2018-07-27 18:56 - 000444952 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
      2020-03-19 14:12 - 2018-07-27 18:56 - 000122904 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll
      2020-03-19 14:12 - 2018-07-27 18:56 - 000109080 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
      2020-03-19 03:22 - 2018-10-18 17:36 - 000000979 _____ C:\Users\Public\Desktop\PotPlayer 64 bit.lnk
      2020-03-19 03:22 - 2018-10-18 17:36 - 000000979 _____ C:\ProgramData\Desktop\PotPlayer 64 bit.lnk
      2020-03-16 16:07 - 2020-03-11 03:56 - 034369720 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
      2020-03-16 16:07 - 2017-09-08 14:02 - 004813752 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
      2020-03-16 13:09 - 2017-09-08 14:02 - 000502672 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
      2020-03-16 13:08 - 2020-03-11 03:56 - 000469904 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
      2020-03-14 01:34 - 2017-09-08 13:21 - 000052925 _____ C:\Windows\system32\nvinfo.pb
      2020-03-14 00:04 - 2017-09-08 14:03 - 005580272 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
      2020-03-14 00:04 - 2017-09-08 14:03 - 002631480 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
      2020-03-14 00:04 - 2017-09-08 14:03 - 001759032 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
      2020-03-14 00:04 - 2017-09-08 14:03 - 000660792 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
      2020-03-14 00:04 - 2017-09-08 14:03 - 000447464 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
      2020-03-14 00:04 - 2017-09-08 14:03 - 000121328 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
      2020-03-14 00:04 - 2017-09-08 14:03 - 000074552 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
      ==================== Files in the root of some directories ========
      2020-02-19 00:22 - 2020-02-19 00:22 - 000000733 _____ () C:\Users\GAMEPC\AppData\Local\recently-used.xbel
      2018-12-17 21:42 - 2018-12-23 19:48 - 000007597 _____ () C:\Users\GAMEPC\AppData\Local\Resmon.ResmonCfg
      2019-08-14 02:36 - 2019-08-14 02:36 - 000000003 _____ () C:\Users\GAMEPC\AppData\Local\updater.log
      2019-08-14 02:36 - 2019-08-14 02:36 - 000000424 _____ () C:\Users\GAMEPC\AppData\Local\UserProducts.xml
      ==================== SigCheck ============================
      (There is no automatic fix for files that do not pass verification.)

      LastRegBack: 2020-04-07 04:13
      ==================== End of FRST.txt ========================
    • от stefanbkanev
      Здравейте, лаптопа ми е нов и със сравнително прилични характеристики, но от няколко дена като го включа и прегрява... Натоварва се изключително много, а нямам включено почти нищо (единствено браузър, скайп и още 1-2 неща дето не би трябвало да натоварват много)...  Най-вероятно съм пипнал някой вирус, ще съм благодарен, ако ми помогнете

      Addition.txt FRST.txt
  • Дарение

×
×
  • Добави ново...