Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Проблем с премахването на разширението GoSave в Chrome

Featured Replies

Здравейте. Не мога да се отърва от тази добавка. След като премахна от настройките, при следващото стартиране на браузъра тя пак се връща. Иначе от контролен панел е махната.

Ето логовете от сканирането:

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-09-2014
Ran by Radi (administrator) on R777 on 20-09-2014 20:21:32
Running from C:\Users\Radi\Desktop
Platform: Windows 8.1 Enterprise (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Ellora Assets Corp.) C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\wscript.exe
(Microsoft Corporation) C:\Windows\System32\schtasks.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AIMP DevTeam) C:\Program Files (x86)\AIMP3\AIMP3.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13423688 2013-02-26] (Realtek Semiconductor)
HKLM\...\Run: [iAStorIcon] => C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [286704 2013-04-30] (Intel Corporation)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
HKLM-x32\...\Run: [TkBellExe] => C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe [198160 2014-03-04] (RealNetworks, Inc.)
HKLM-x32\...\Run: [startCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-04-15] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [sunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3454556834-3080989196-3808751203-1001\...\MountPoints2: {f55974fb-9afd-11e3-824f-806e6f6e6963} - "F:\Run.exe" 
Startup: C:\Users\Radi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Configure Bulgarian Speech.lnk
ShortcutTarget: Configure Bulgarian Speech.lnk -> C:\Users\Radi\AppData\Roaming\Microsoft\Installer\{319A3CA9-DA63-4D65-8B25-403CF9CBF087}\_5af141bb.exe ()
Startup: C:\Users\Radi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Radi\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Radi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Radi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Radi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Radi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: StorageProviderError -> {0CA2640D-5B9C-4c59-A5FB-2DA61A7437CF} => C:\Windows\System32\shell32.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: StorageProviderSyncing -> {0A30F902-8398-4ee8-86F7-4CFB589F04D1} => C:\Windows\System32\shell32.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Radi\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Radi\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Radi\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Radi\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: StorageProviderError -> {0CA2640D-5B9C-4c59-A5FB-2DA61A7437CF} => C:\Windows\SysWOW64\shell32.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: StorageProviderSyncing -> {0A30F902-8398-4ee8-86F7-4CFB589F04D1} => C:\Windows\SysWOW64\shell32.dll (Microsoft Corporation)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://t.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US,en;q=0.7,bg;q=0.3
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: RealPlayer Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Winsock: Catalog5 07 C:\Program Files (x86)\Bonjour\mdnsNSP.dll File Not found ()
Tcpip\..\Interfaces\{2C410F47-D090-47B3-A238-55C4BC9119D1}: [NameServer] 84.22.2.62 212.116.131.21
 
FireFox:
========
FF ProfilePath: C:\Users\Radi\AppData\Roaming\Mozilla\Firefox\Profiles\g00zvjn0.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=6.0.12.448 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprjplug;version=1.0.3.448 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpjplug;version=6.0.12.448 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File
FF Extension: GoSauve - C:\Users\Radi\AppData\Roaming\Mozilla\Firefox\Profiles\g00zvjn0.default\Extensions\[email protected] [2014-09-17]
FF Extension: No Name - C:\Users\Radi\AppData\Roaming\Mozilla\Firefox\Profiles\g00zvjn0.default\Extensions\staged [2014-09-18]
FF Extension: DownloadHelper - C:\Users\Radi\AppData\Roaming\Mozilla\Firefox\Profiles\g00zvjn0.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-09-09]
FF Extension: Flash and Video Download - C:\Users\Radi\AppData\Roaming\Mozilla\Firefox\Profiles\g00zvjn0.default\Extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a} [2014-09-09]
FF Extension: Default Full Zoom Level - C:\Users\Radi\AppData\Roaming\Mozilla\Firefox\Profiles\g00zvjn0.default\Extensions\{D9A7CBEC-DE1A-444f-A092-844461596C4D} [2014-09-09]
FF Extension: NoSquint - C:\Users\Radi\AppData\Roaming\Mozilla\Firefox\Profiles\g00zvjn0.default\Extensions\[email protected] [2014-08-14]
FF Extension: Adblock Plus - C:\Users\Radi\AppData\Roaming\Mozilla\Firefox\Profiles\g00zvjn0.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-09-17]
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\Program Files (x86)\Real\RealPlayer\browserrecord\firefox\ext
FF Extension: RealPlayer Browser Record Plugin - C:\Program Files (x86)\Real\RealPlayer\browserrecord\firefox\ext [2014-03-04]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[email protected]
FF Extension: Freemake Video Downloader Plugin - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[email protected] [2014-03-13]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[email protected]
FF Extension: Freemake Youtube Download Button - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[email protected] [2014-03-13]
FF Extension: No Name - C:\Users\Radi\AppData\Roaming\Mozilla\Firefox\Profiles\g00zvjn0.default\extensions\{2b55ea1c-5d12-4fb5-bb9b-2067f8eda4ca}.xpi [Not Found]
FF StartMenuInternet: FIREFOX.EXE - D:\Other programs\Mozzila\firefox.exe
 
Chrome: 
=======
CHR HomePage: Default -> 
CHR StartupUrls: Default -> "hxxp://search.conduit.com/?ctid=CT3325576&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SP1BE40AE2-8405-4329-A077-BEC86AF4BA38&SSPV=", "", "hxxp://search.gboxapp.com/"
CHR DefaultSearchKeyword: Default -> 6C106A0F4B20235008A76BDCE2B709751CF8D3CC3A668457E5661F341411FBEC
CHR DefaultSearchURL: Default -> DFEDC50D025C1FB9BA0F4FE403CAC670A2DB7D32C09BE1A8D7DC6A1C6B172987
CHR Profile: C:\Users\Radi\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Диск) - C:\Users\Radi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-02-22]
CHR Extension: (YouTube) - C:\Users\Radi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-02-22]
CHR Extension: (Chrome YouTube Downloader) - C:\Users\Radi\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbdjiinahkdjdcdlgfimlcolkjpbooja [2014-03-09]
CHR Extension: (Google Търсене) - C:\Users\Radi\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-02-22]
CHR Extension: (Tampermonkey) - C:\Users\Radi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2014-03-12]
CHR Extension: (GoSauve) - C:\Users\Radi\AppData\Local\Google\Chrome\User Data\Default\Extensions\diejjagoaklphhjkpbgfijcgcommapal [2014-09-15]
CHR Extension: (Easy Youtube Video Downloader) - C:\Users\Radi\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmknocfkgffdgekmfonabppnhdgmghem [2014-03-12]
CHR Extension: (AdBlock) - C:\Users\Radi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-02-22]
CHR Extension: (Imgur Uploader) - C:\Users\Radi\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgmpmjpekinnebjgnakcahjikbomnmlb [2014-02-22]
CHR Extension: (Windows Media Player Extension for HTML5) - C:\Users\Radi\AppData\Local\Google\Chrome\User Data\Default\Extensions\hokdglbhghcebcopdbanieangmcamaak [2014-09-15]
CHR Extension: (Google Wallet) - C:\Users\Radi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-22]
CHR Extension: (Gmail) - C:\Users\Radi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-02-22]
CHR Extension: (GoSauve) - C:\Users\Radi\AppData\Local\Google\Chrome\User Data\Default\Extensions\diejjagoaklphhjkpbgfijcgcommapal\2.0 [2014-09-15]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 amdacpusrsvc; C:\AMD\amdacpusrsvc.exe [82432 2014-04-15] () [File not signed]
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-07] ()
R2 FreemakeVideoCapture; C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [9216 2014-03-12] (Ellora Assets Corp.) [File not signed]
S3 GSService; C:\Windows\SysWOW64\GSService.exe [464384 2011-11-12] () [File not signed]
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-04-30] (Intel Corporation)
R2 Intel® Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-13] (Intel® Corporation) [File not signed]
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel® Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [169432 2013-04-12] (Intel Corporation)
S3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [44032 2013-08-22] (Microsoft Corporation)
S3 lfsvc; C:\Windows\SysWOW64\GeofenceMonitorService.dll [357376 2013-09-30] (Microsoft Corporation)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
S3 Netlogon; C:\Windows\SysWOW64\netlogon.dll [688640 2013-08-22] (Microsoft Corporation)
S2 Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [1050904 2013-12-11] () [File not signed]
S3 smphost; C:\Windows\SysWOW64\smphost.dll [11776 2013-08-22] (Microsoft Corporation)
S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18944 2013-08-22] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation)
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 amdacpksd; C:\Windows\system32\drivers\amdacpksd.sys [274656 2014-04-16] (Advanced Micro Devices)
S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [21160 2012-09-23] (Advanced Micro Devices, Inc.)
R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21584 2013-02-19] ()
S3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2014-03-11] (Advanced Micro Devices)
R2 hmip; C:\Windows\system32\Drivers\hmip64.sys [38760 2013-06-19] (Hide My IP)
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO64A.SYS [31648 2014-02-21] (REALiX)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation)
S1 UsbCharger; C:\Windows\System32\DRIVERS\UsbCharger.sys [21584 2013-05-06] ()
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation)
S3 gdrv; \??\C:\Windows\gdrv.sys [X]
S3 NPF; system32\drivers\NPF.sys [X]
S4 NVHDA; \SystemRoot\system32\drivers\nvhda64v.sys [X]
S4 nvvad_WaveExtensible; \SystemRoot\system32\drivers\nvvad64v.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-09-20 20:21 - 2014-09-20 20:21 - 00021706 _____ () C:\Users\Radi\Desktop\FRST.txt
2014-09-20 20:21 - 2014-09-20 20:21 - 00000000 ____D () C:\FRST
2014-09-20 20:20 - 2014-09-20 20:20 - 02105856 _____ (Farbar) C:\Users\Radi\Desktop\FRST64.exe
2014-09-18 20:30 - 2014-09-20 19:54 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-18 20:30 - 2014-09-18 20:30 - 00001118 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-09-18 20:30 - 2014-09-18 20:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-09-18 20:30 - 2014-09-18 20:30 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-18 20:30 - 2014-09-18 20:30 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-09-18 20:30 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-09-18 20:30 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-09-18 20:30 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-09-18 20:27 - 2014-09-18 20:27 - 00000640 _____ () C:\Users\Radi\Desktop\JRT.txt
2014-09-18 20:17 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-09-18 20:09 - 2014-09-18 20:09 - 00003934 _____ () C:\Windows\system32\.crusader
2014-09-18 20:02 - 2014-09-19 21:39 - 00000000 ____D () C:\Program Files\HitmanPro
2014-09-18 20:01 - 2014-09-18 20:09 - 00000000 ____D () C:\ProgramData\HitmanPro
2014-09-18 19:55 - 2014-09-18 19:55 - 00000000 ____D () C:\Windows\ERUNT
2014-09-18 19:54 - 2014-09-18 20:23 - 00000000 ____D () C:\AdwCleaner
2014-09-17 21:00 - 2014-09-19 23:45 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-17 21:00 - 2014-09-17 21:00 - 00003718 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-09-15 19:47 - 2014-09-15 19:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-09-15 19:47 - 2014-09-15 19:47 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-09-15 19:47 - 2014-09-15 19:47 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-09-15 19:26 - 2014-09-18 11:43 - 00000000 ____D () C:\ProgramData\GoSauve
2014-09-15 19:26 - 2014-09-18 11:42 - 00000394 __RSH () C:\ProgramData\ntuser.pol
2014-09-15 19:26 - 2014-09-18 11:42 - 00000000 ____D () C:\Program Files (x86)\GoSauve
2014-08-27 21:19 - 2014-08-30 11:16 - 00000000 ___RD () C:\Users\Radi\Desktop\  
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-09-20 20:21 - 2014-09-20 20:21 - 00021706 _____ () C:\Users\Radi\Desktop\FRST.txt
2014-09-20 20:21 - 2014-09-20 20:21 - 00000000 ____D () C:\FRST
2014-09-20 20:20 - 2014-09-20 20:20 - 02105856 _____ (Farbar) C:\Users\Radi\Desktop\FRST64.exe
2014-09-20 20:16 - 2014-02-22 06:52 - 00003906 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{6E24E77B-E356-48FE-91EE-5EC842509B73}
2014-09-20 20:15 - 2014-02-22 06:53 - 00000904 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-20 20:14 - 2014-02-21 16:54 - 01489004 _____ () C:\Windows\WindowsUpdate.log
2014-09-20 20:05 - 2014-02-21 19:31 - 00000000 ____D () C:\Users\Radi\AppData\Roaming\AIMP3
2014-09-20 20:00 - 2013-08-22 18:36 - 00000000 ____D () C:\Windows\system32\sru
2014-09-20 19:54 - 2014-09-18 20:30 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-20 19:54 - 2014-02-22 06:53 - 00000900 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-20 19:53 - 2013-08-22 17:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-19 23:45 - 2014-09-17 21:00 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-19 22:20 - 2014-02-21 16:54 - 00003600 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3454556834-3080989196-3808751203-1001
2014-09-19 21:39 - 2014-09-18 20:02 - 00000000 ____D () C:\Program Files\HitmanPro
2014-09-19 21:39 - 2014-07-07 20:06 - 00000000 ____D () C:\ProgramData\Ashampoo
2014-09-19 12:00 - 2013-09-30 07:02 - 00029930 _____ () C:\Windows\PFRO.log
2014-09-18 20:30 - 2014-09-18 20:30 - 00001118 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-09-18 20:30 - 2014-09-18 20:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-09-18 20:30 - 2014-09-18 20:30 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-18 20:30 - 2014-09-18 20:30 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-09-18 20:27 - 2014-09-18 20:27 - 00000640 _____ () C:\Users\Radi\Desktop\JRT.txt
2014-09-18 20:23 - 2014-09-18 19:54 - 00000000 ____D () C:\AdwCleaner
2014-09-18 20:09 - 2014-09-18 20:09 - 00003934 _____ () C:\Windows\system32\.crusader
2014-09-18 20:09 - 2014-09-18 20:01 - 00000000 ____D () C:\ProgramData\HitmanPro
2014-09-18 19:55 - 2014-09-18 19:55 - 00000000 ____D () C:\Windows\ERUNT
2014-09-18 11:44 - 2014-03-13 01:04 - 00000000 ____D () C:\ProgramData\f62ad08a1a637f8a
2014-09-18 11:43 - 2014-09-15 19:26 - 00000000 ____D () C:\ProgramData\GoSauve
2014-09-18 11:42 - 2014-09-15 19:26 - 00000394 __RSH () C:\ProgramData\ntuser.pol
2014-09-18 11:42 - 2014-09-15 19:26 - 00000000 ____D () C:\Program Files (x86)\GoSauve
2014-09-17 21:00 - 2014-09-17 21:00 - 00003718 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-09-16 18:21 - 2014-02-22 06:53 - 00000000 ____D () C:\Program Files (x86)\Google
2014-09-16 00:16 - 2013-08-22 16:25 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-09-16 00:15 - 2014-03-02 15:57 - 00000000 ____D () C:\Users\Radi\AppData\Roaming\uTorrent
2014-09-15 19:47 - 2014-09-15 19:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-09-15 19:47 - 2014-09-15 19:47 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-09-15 19:47 - 2014-09-15 19:47 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-09-15 19:26 - 2013-08-22 18:36 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-09-15 19:26 - 2013-08-22 18:36 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-09-14 20:41 - 2013-08-22 18:36 - 00000000 ____D () C:\Windows\AppReadiness
2014-09-14 15:23 - 2013-09-30 07:14 - 00865408 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-12 21:02 - 2014-03-02 18:46 - 00000000 ____D () C:\Users\Radi\AppData\Roaming\Skype
2014-09-08 20:06 - 2014-06-22 22:47 - 00000000 ____D () C:\Users\Radi\AppData\Local\Adobe
2014-08-30 22:41 - 2014-03-02 23:44 - 00000000 ____D () C:\Users\Radi\Documents\FIFA 14
2014-08-30 21:10 - 2014-02-25 22:07 - 00004938 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for R777-Radi R777
2014-08-30 11:16 - 2014-08-27 21:19 - 00000000 ___RD () C:\Users\Radi\Desktop\  
2014-08-30 10:20 - 2013-08-22 17:46 - 00028380 _____ () C:\Windows\setupact.log
2014-08-25 13:45 - 2014-02-21 16:49 - 00000000 ____D () C:\Users\Radi\AppData\Local\Packages
 
Files to move or delete:
====================
C:\Users\Radi\AppData\Roaming\Origin\update.vbe
 
 
Some content of TEMP:
====================
C:\Users\Radi\AppData\Local\Temp\AskPIP_FF_.exe
C:\Users\Radi\AppData\Local\Temp\HitmanPro.exe
C:\Users\Radi\AppData\Local\Temp\jre-7u65-windows-i586-iftw.exe
C:\Users\Radi\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
C:\Users\Radi\AppData\Local\Temp\nvStInst.exe
C:\Users\Radi\AppData\Local\Temp\ose00000.exe
C:\Users\Radi\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Radi\AppData\Local\Temp\_is14E8.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2014-09-16 20:00
 
==================== End Of Log ============================

Addition.txt

Редактирано от locke (преглед на промените)

Изтеглете edit-text.giffixlist.txt и го запазете в папката от която стартирахте FRST.exe.
Стартирайте FRST.exe и натиснете бутона Fix веднъж!
След като приключи, ако ви поиска рестарт - съгласете се. След рестарта публикувайте лог файла - fixlog.txt, който ще се създаде след работата на програмата.
 
Внимание: Скрипта е създаден за текущата система. Да не се ползва за други системи с подобни проблеми!

  • Автор

Пуснах скрипта, но ми изтри всички настройки от браузъра - отметки, пароли, история. Как да ги възстановя?

 

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 12-09-2014
Ran by Radi at 2014-09-22 12:36:59 Run:1
Running from C:\Users\Radi\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
start
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
FF Extension: GoSauve - C:\Users\Radi\AppData\Roaming\Mozilla\Firefox\Profiles\g00zvjn0.default\Extensions\[email protected] [2014-09-17]
CHR StartupUrls: Default -> "hxxp://search.conduit.com/?ctid=CT3325576&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SP1BE40AE2-8405-4329-A077-BEC86AF4BA38&SSPV=", "", "hxxp://search.gboxapp.com/"
CHR Extension: (GoSauve) - C:\Users\Radi\AppData\Local\Google\Chrome\User Data\Default\Extensions\diejjagoaklphhjkpbgfijcgcommapal [2014-09-15]
CHR Extension: (GoSauve) - C:\Users\Radi\AppData\Local\Google\Chrome\User Data\Default\Extensions\diejjagoaklphhjkpbgfijcgcommapal\2.0 [2014-09-15]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
2014-09-15 19:26 - 2014-09-18 11:43 - 00000000 ____D () C:\ProgramData\GoSauve
2014-09-15 19:26 - 2014-09-18 11:42 - 00000000 ____D () C:\Program Files (x86)\GoSauve
2014-09-18 11:44 - 2014-03-13 01:04 - 00000000 ____D () C:\ProgramData\f62ad08a1a637f8a
cmd: bitsadmin /reset /allusers
cmd: netsh winsock reset catalog
cmd: ipconfig /flushdns
emptytemp:
end
*****************

C:\Windows\system32\GroupPolicy\Machine => Moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully.
C:\Users\Radi\AppData\Roaming\Mozilla\Firefox\Profiles\g00zvjn0.default\Extensions\[email protected] => Moved successfully.
Chrome StartupUrls deleted successfully.
C:\Users\Radi\AppData\Local\Google\Chrome\User Data\Default\Extensions\diejjagoaklphhjkpbgfijcgcommapal => Moved successfully.
C:\Users\Radi\AppData\Local\Google\Chrome\User Data\Default\Extensions\diejjagoaklphhjkpbgfijcgcommapal\2.0 directory not found.
"HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
C:\ProgramData\GoSauve => Moved successfully.
C:\Program Files (x86)\GoSauve => Moved successfully.
C:\ProgramData\f62ad08a1a637f8a => Moved successfully.

=========  bitsadmin /reset /allusers =========


BITSADMIN version 3.0 [ 7.7.9600 ]
BITS administration utility.
© Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

{61EA08A7-6F89-41F5-9F72-1D9114A06250} canceled.
1 out of 1 jobs canceled.

========= End of CMD: =========


=========  netsh winsock reset catalog =========


Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.


========= End of CMD: =========


=========  ipconfig /flushdns =========


Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========

EmptyTemp: => Removed 978.4 MB temporary data.


The system needed a reboot.

==== End of Fixlog ====

Редактирано от locke (преглед на промените)

Не виждам в скрипта да сме изтрили неща свързани със загубата на данните запаметени в браузъра ви.

Ако нямате бекъп не виждам и как можем да ги възстановим. Ако имате инсталационен диск можем да влезнем в Recovery Environment и да се опитаме да върнем промените по регистрите преди използване на скрипта, както и да възстановим съдържанието на карантинната папка в C:\FRST\Quarantine. Но така ще върнем и адуера, а няма гаранция, че настройките на браузъра ви ще се оправят...Друг вариант е да се опита System Restore.

 

Поздрави!

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.