Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Помощ! Антивирусната не ми засича вируса! (спешно)

Featured Replies

Първо да уточня, че не съм много веща и нямам познати специалисти, затова моля за помощ тук.

Сърфирам си нормално в нета, когато изведнъж десктопа ми се сменя с това: "Attention! Your computer was attacked by virus-encoder, All your files are encrypted cryptographycally strong, without the original key recovery is impossible! To get the decoder and the original key, you need to write to us at the e-mail [email protected] with the subject "encryption" stating your id. Write on the case, do not waste your and our time on empty threats. Responses to letters only appropriate people are not adequate ignore."

Общо взето всичките ми файлове, били те avi, doc или каквото там, ми излизат като програмки, когато ги отворя ми се включва DOS система. С Windows XP съм, преди известно време сама смених на SP3 без проблеми. Защитих си компютъра през System Information както сте показали във форума. Но антивирусната не ми засича вируса. Ползвам Malwarebytes Anty-Malware, пробвах и McAfee Security Scan Plus и пак нищо. В интернет влизах успешно, докато не направих тази защита през System Information, сега някъде ми прави проблеми, предполагам, че така трябва, не съм много наясно с тези неща, както виждате. Пуснах си CCleanser и ми махна бисквитки, история и прочие. Махала съм преди успешно Троянци, но сега не мога да се справя, а трябва до края на седмицата да предам задачи за следването ми и сроковете ме притискат. Казвайте да го давам ли за поправка или има някакъв начин да го оправя сама. Благодаря предварително, очаквам отговор!

1.Прочети малко правилата: 2.3 Заглавието на темата трябва да е ясно и точно, да не е съставено единствено от главни букви и да описва максимално съдържанието на самата тема. Теми със заглавия от една дума или от рода на "Помощ!", "Имам проблем", "Спешно" и т.н. се изтриват без предупреждение.

2.Прочети тази тема и изпълни стъпките там, за да могат колегите от HJT Team да ти помогнат

Здравейте,

 

Можем да изчистим компютъра напълно, но за криптираните файлове зависи от варианта на бацила. Има такива при които файловете не могат да се декриптират (дори не си и помисляйте да плащате на злосторниците, които ви уверяват, че ще ви предоставят декриптиращ ключ) и ако нямате System Resore points (Volume Shadow Copies на файловете за да извлечем стари версии на документите) и ако нямате бекъп на тези документи на външен хардиск можете почти сигурно да се простите с данните си. Често се случва крипто вируса да изключи System Restore-a на системата и положението става още по-зле. Все пак за да видим с какво си имаме работа изпълнете стъпките посочени от колегата над мен и пуснете логовете от FRST.

 

Също така ще ви помоля да архивирате няколко файла от криптираните и да ми изпратите архива на адрес за да видя дали има шанс за спасяване на данните въобще. Ако не, само ще почистим зловредния софтуер в системата...Кофти са крипторите и стават все по-голяма напаст, но явно в България все още не са достигнали до такава степен на заразяване.

 

Има си и начини на превенция, но затова малко по-късно. Засега очаквам да изпълните препоръките от моя пост и поста на колегата.

 

Поздрави!

  • Автор

Първо благодаря за бързата реакция и се извинявам за заглавието, но в момент на паника не мога да мисля И за правилата, колкото и важни да са те, признавам. Знаете, човек изключва точно в такива стресови ситуации.

 

Мислех да пиша подтема в другия раздел, както е посочено, но за да не затрупвам с еднаква информация форума, продължавам тук, ако трябва да се преместя, кажете.

 

В отговор на по-горния пост, не съм си и помисляла да плащам на тях, просто питам да нося ли на сервиз машината, ако е неспасяемо положението или няма смисъл?

Така, сканирах с FRST, ще ви изпратя резултатите на посочения адрес, както и няколко криптирани файла в архив, както сте поръчали. Искрени благодарности за проявеното разбиране и бързия отговор! :)

Да допълня, че това "нещо" изяде днес около 12:40 доста информация при мен. Все още незнам как и от къде е влезнало. Имам едно ПЦ и няколко мрежови фолдера криптирани. Предполагам, че е влезнало от ПЦто, и през него е конвертирало и мрежовите у-ва. Изпратих логовете от тази програма която сте описали стартирана на въпросното ПЦ, и 2 от криптираните файлове. На някой от файловете имам архив и съм изпратил и архивираното копие за сравнение.

Пратих файловете на специалистите по декриптиране, но ще се наложи да изчакате докато получа отговор от тях...Да...те умеят да заразяват споделени файлове и папки и външни носители. Засега избягвайте да използвате флашки и външни дискове.

 

Логовете от FRST копирайте в следващия си комантар. Да видим дали ще можем поне да изчистим машината за да не заразява други.

  • Автор

Благодарности!  Не знам какъв е проблемът при Александър, но при мен са засегнати като че ли по-голяма част от файловете. Естествено, в диск С всичко е заразено, плаче ми се като вляза в My Documents, в другите дискове имам avi и mp3 файлове, които се отварят нормално, поне засега. Доколкото виждам, нямам засегнати музикални файлове и слава Богу! Аз също нямам идея откъде може да се е промъкнало. Не искам да съм нагла, но пак да попитам, ще се наложи ли да дам компютъра на сервиз, искам да съм наясно отсега, за да не ви губя излишно времето тук, и без това ви занимават стотици хора като мен, неудобно ми е така. И имате ли представа колко време би отнело поправянето на този проблем? Ще се наложи преинсталация, нали? Благодаря отново!

Пращам Ви резултатите от скана на FRST. Наясно съм с използването на флашки и външни устройства в такива ситуации, не съм си и помисляла да ползвам, но имате ли други полезни съвети в конкретния случай или къде да открия такива? Рових се за това днес, но не намерих нищо конкретно. Мерси!

  • Автор

 

Също така можете ли да кажата дали имате представа как сте се заразили? Ако е от прикачен файл в електронната поща, можете ли да изпратите и него на посочения адрес тук?

 

Благодаря предварително!

 

Въобще нямам представа как съм се заразила, всичко се случи буквално за миг, докато си четях статии в интернет, писах го още в първия си коментар. Така че предполагам, че не е от електронната ми поща. И Ви го пратих така, защото ми дава, че коментарът е твърде дълъг за да бъде публикуван. Но ако искате, ще пробвам на части, ако не е проблем за Вас.

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 10-11-2014

Ran by PC (administrator) on PC-698796166478 on 12-11-2014 15:47:32

Running from C:\Documents and Settings\PC\Local Settings\Temporary Internet Files\Content.IE5\RHBVJXCV

Loaded Profile: PC (Available profiles: PC)

Platform: Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English (United States)

Internet Explorer Version 8

Boot Mode: Normal

Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe

(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe

(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

(Skype Technologies S.A.) C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe

(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE

(Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

(BitTorrent Inc.) C:\Documents and Settings\PC\Application Data\BitTorrent\BitTorrent.exe

(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe

(ArcSoft, Inc.) C:\Program Files\Hama\Hama Webcam Suite\Magic-i Visual Effects\Magic-i Visual Effects.exe

(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe

(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe

(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe

(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe

(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe

(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe

(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe

(Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe

(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe

(Farbar) C:\Documents and Settings\PC\Local Settings\Temporary Internet Files\Content.IE5\RHBVJXCV\FRST[1].exe

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\qttask.exe [421888 2014-01-17] (Apple Inc.)

HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2014-05-08] (Adobe Systems Incorporated)

HKLM\...\Policies\Explorer: [TaskbarNoNotification] 1

HKLM\...\Policies\Explorer: [HideSCAHealth] 1

HKU\S-1-5-21-484763869-179605362-1417001333-1003\...\Run: [ALLUpdate] => C:\Program Files\OpenSubtitlesPlayer\ALLUpdate.exe [1022464 2011-02-26] ()

HKU\S-1-5-21-484763869-179605362-1417001333-1003\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-07-30] (Google Inc.)

HKU\S-1-5-21-484763869-179605362-1417001333-1003\...\Run: [bitTorrent] => C:\Documents and Settings\PC\Application Data\BitTorrent\BitTorrent.exe [1388376 2014-10-28] (BitTorrent Inc.)

HKU\S-1-5-21-484763869-179605362-1417001333-1003\...\Run: [skype] => C:\Program Files\Skype\Phone\Skype.exe [21652064 2014-07-24] (Skype Technologies S.A.)

HKU\S-1-5-21-484763869-179605362-1417001333-1003\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [4826904 2014-10-30] (Piriform Ltd)

HKU\S-1-5-21-484763869-179605362-1417001333-1003\...\Policies\Explorer: [TaskbarNoNotification] 1

HKU\S-1-5-21-484763869-179605362-1417001333-1003\...\Policies\Explorer: [HideSCAHealth] 1

IFEO\bitguard.exe: [Debugger] tasklist.exe

IFEO\bprotect.exe: [Debugger] tasklist.exe

IFEO\bpsvc.exe: [Debugger] tasklist.exe

IFEO\browserdefender.exe: [Debugger] tasklist.exe

IFEO\browserprotect.exe: [Debugger] tasklist.exe

IFEO\browsersafeguard.exe: [Debugger] tasklist.exe

IFEO\dprotectsvc.exe: [Debugger] tasklist.exe

IFEO\jumpflip: [Debugger] tasklist.exe

IFEO\protectedsearch.exe: [Debugger] tasklist.exe

IFEO\searchinstaller.exe: [Debugger] tasklist.exe

IFEO\searchprotection.exe: [Debugger] tasklist.exe

IFEO\searchprotector.exe: [Debugger] tasklist.exe

IFEO\searchsettings.exe: [Debugger] tasklist.exe

IFEO\searchsettings64.exe: [Debugger] tasklist.exe

IFEO\snapdo.exe: [Debugger] tasklist.exe

IFEO\stinst32.exe: [Debugger] tasklist.exe

IFEO\stinst64.exe: [Debugger] tasklist.exe

IFEO\umbrella.exe: [Debugger] tasklist.exe

IFEO\utiljumpflip.exe: [Debugger] tasklist.exe

IFEO\volaro: [Debugger] tasklist.exe

IFEO\vonteera: [Debugger] tasklist.exe

IFEO\websteroids.exe: [Debugger] tasklist.exe

IFEO\websteroidsservice.exe: [Debugger] tasklist.exe

Lsa: [Authentication Packages] msv1_0 nwprovau

Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Magic-i Visual Effects.lnk

ShortcutTarget: Magic-i Visual Effects.lnk -> C:\Program Files\Hama\Hama Webcam Suite\Magic-i Visual Effects\Magic-i Visual Effects.exe (ArcSoft, Inc.)

Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk

ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)

Startup: C:\Documents and Settings\PC\Start Menu\Programs\Startup\bytor.bmp ()

Startup: C:\Documents and Settings\PC\Start Menu\Programs\Startup\wlort.dll ( )

HKLM\...\AppCertDlls: [x64] -> c:\program files\browser tab search by ask\safetynut\x64\safetycrt.dll

GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dir.bg/

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

HKCU\Software\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = http://www.dir.bg/

HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds&ts=1406827062&from=sfpsnew1&uid=WDCXWD5000AAKS-22V1A0_WD-WCAWF709257892578&q={searchTerms}

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com

URLSearchHook: HKCU - BS Player ControlBar Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\prxtbBS_0.dll (Conduit Ltd.)

StartMenuInternet: IEXPLORE.EXE - iexplore.exe

SearchScopes: HKLM - Backup.Old.DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990}

SearchScopes: HKLM - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=nv1&chnl=nv1&cd=2XzuyEtN2Y1L1QzuyC0C0FtDyEzy0AzytCyEtA0B0AtDtCyCtN0D0Tzu0CtBtAyCtN1L2XzutBtFtCtFtCtFtAtCtB&cr=190592590

SearchScopes: HKLM - {783F2C96-19EB-5DD9-793C-53FCA22CC9F4} URL =

SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} URL = http://dts.search.ask.com/sr?src=ieb&gct=ds&appid=210&systemid=488&v=a12834-348&apn_uid=8606670471324815&apn_dtid=TCH001&o=APN11459&apn_ptnrs=AG1&q={searchTerms}

SearchScopes: HKLM - {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL = http://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=AgnUpd&cd=2XzuyEtN2Y1L1QzuyC0C0FtDyEzy0AzytCyEtA0B0AtDtCyCtN0D0Tzu0CyEtAzztN1L2XzutN1L1Czu&cr=576868586&ir=

SearchScopes: HKLM - {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^HJ^xdm007^YY^bg&si=CO7Oreaxi7UCFUW_zAodfU8AIg&ptb=6CC997F7-A728-4A7F-8E15-1A41887E329B&ind=2013012810&n=77fc234a&psa=&st=sb&searchfor={searchTerms}

SearchScopes: HKCU - Backup.Old.DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990}

SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

SearchScopes: HKCU - {1F096B29-E9DA-4D64-8D63-936BE7762CC5} URL = http://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=3cb8a0160000000000006cf049a9143b&tlver=1.4.19.19&affID=19579

SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} URL = http://dts.search.ask.com/sr?src=ieb&gct=ds&appid=210&systemid=488&v=a12834-348&apn_uid=8606670471324815&apn_dtid=TCH001&o=APN11459&apn_ptnrs=AG1&q={searchTerms}

SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1750559&CUI=UN33889770456943066&UM=1

SearchScopes: HKCU - {C2367743-5BC1-4816-8307-4172465CAC6C} URL = http://websearch.ask.com/redirect?client=ie&tb=OSUB&o=100000079&src=crm&q={searchTerms}&locale=en_EU&apn_ptnrs=V6&apn_dtid=YYYYYYYYBG&apn_uid=9c84e4a2-05d3-4cbd-bbbc-e2e938d7738f&apn_sauid=B7C812BC-C2B1-4310-815C-774336BAC174&

SearchScopes: HKCU - {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^HJ^xdm007^YY^bg&si=CO7Oreaxi7UCFUW_zAodfU8AIg&ptb=6CC997F7-A728-4A7F-8E15-1A41887E329B&ind=2013012810&n=77fc234a&psa=&st=sb&searchfor={searchTerms}

BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)

BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)

BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

BHO: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.)

BHO: IplexToALLPlayer -> {DF925EF3-7A87-44E4-9CAF-8D7B280BF616} -> C:\Program Files\OpenSubtitlesPlayer\Iplex\IplexToALLPlayer.dll (ALLCinema Ltd.)

BHO: BS Player ControlBar Toolbar -> {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} -> C:\Program Files\BS_Player\prxtbBS_0.dll (Conduit Ltd.)

Toolbar: HKLM - No Name - {98889811-442D-49dd-99D7-DC866BE87DBC} - No File

Toolbar: HKLM - BS Player ControlBar Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\prxtbBS_0.dll (Conduit Ltd.)

Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

DPF: {B479199A-1242-4E3C-AD81-7F0DF801B4AE} http://download.microsoft.com/download/C/9/C/C9C3D86D-84AC-4AF0-8584-842756A66467/MicrosoftDownloadManager.cab

DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)

Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

FireFox:

========

FF ProfilePath: C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default

FF DefaultSearchEngine: WebSearch

FF DefaultSearchEngine,S: WebSearch

FF DefaultSearchUrl: hxxp://websearch.allsearches.info/?pid=3400&r=2014/10/09&hid=10091285608446518072&lg=EN&cc=BG&unqvl=64&l=1&q=

FF SearchEngineOrder.1: WebSearch

FF SearchEngineOrder.1,S: WebSearch

FF SearchEngineOrder.3: Bing

FF SelectedSearchEngine: WebSearch

FF SelectedSearchEngine,S: WebSearch

FF Homepage: hxxp://websearch.allsearches.info/?pid=3400&r=2014/10/09&hid=10091285608446518072&lg=EN&cc=BG&unqvl=64

FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll ()

FF Plugin: @Microsoft.com/DownloadManager,version=1.1 -> C:\WINDOWS\ ()

FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)

FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File

FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File

FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF user.js: detected! => C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\user.js

FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)

FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)

FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)

FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)

FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)

FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)

FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)

FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)

FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)

FF SearchPlugin: C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\searchplugins\Ask.xml

FF SearchPlugin: C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\searchplugins\askcom.xml

FF SearchPlugin: C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\searchplugins\bingp.xml

FF SearchPlugin: C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\searchplugins\Search.xml

FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\911bg.xml

FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\Ask.xml

FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\diribg.xml

FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\pe-bg.xml

FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\portalbgdict.xml

FF Extension: ADDICT-THING - C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\Extensions\[email protected] [2012-08-21]

FF Extension: GGouSaave - C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\Extensions\[email protected] [2014-10-09]

FF Extension: DealEXporeess - C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\Extensions\[email protected] [2014-10-16]

FF Extension: GoSSave - C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\Extensions\[email protected] [2014-10-24]

FF Extension: YoutubeAdeBliocke - C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\Extensions\[email protected] [2014-10-09]

FF Extension: FUn2Save - C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\Extensions\[email protected] [2014-10-24]

FF Extension: Purple Fox - C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\Extensions\{3ffb7be0-8bde-11de-8a39-0800200c9a66} [2014-08-03]

FF Extension: OneClickDownloader - C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\Extensions\[email protected] [2013-01-31]

FF Extension: Babylon OCR - C:\Program Files\Mozilla Firefox\extensions\[email protected] [2014-10-27]

FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension

FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2012-02-01]

FF Extension: No Name - C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\extensions\[email protected] [Not Found]

FF Extension: No Name - C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\extensions\[email protected] [Not Found]

FF Extension: No Name - C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\extensions\{32b29df0-2237-4370-9a29-37cebb730e9b} [Not Found]

FF Extension: No Name - [email protected] [Not Found]

FF Extension: No Name - [email protected] [Not Found]

FF Extension: No Name - {32b29df0-2237-4370-9a29-37cebb730e9b} [Not Found]

Chrome:

=======

CHR dev: Chrome dev build detected! <======= ATTENTION

CHR Plugin: (Remoting Viewer) - internal-remoting-viewer

CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\38.0.2125.101\ppGoogleNaClPluginChrome.dll No File

CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\38.0.2125.101\pdf.dll ()

CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\38.0.2125.101\gcswf32.dll No File

CHR Plugin: (Shockwave Flash) - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll No File

CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File

CHR Plugin: (Microsoft® Windows Media Player Firefox Plugin) - C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll (Microsoft Corporation)

CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)

CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)

CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)

CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)

CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)

CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.)

CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.)

CHR Plugin: (Microsoft® DRM) - C:\Program Files\Windows Media Player\npdrmv2.dll (Microsoft Corporation)

CHR Plugin: (Microsoft® DRM) - C:\Program Files\Windows Media Player\npwmsdrm.dll (Microsoft Corporation)

CHR Plugin: (DNA Plug-in) - C:\Program Files\DNA\plugins\npbtdna.dll No File

CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File

CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll No File

CHR Plugin: (RayV Plugin) - C:\Program Files\RayV\RayV\plugins\nprayvplugin.dll No File

CHR Plugin: (Windows Presentation Foundation) - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

CHR Profile: C:\Documents and Settings\PC\Local Settings\Application Data\Google\Chrome\User Data\Default

CHR Extension: (Menu button) - C:\Documents and Settings\PC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\goblmaagcgfbjlaahdohiomenekdpnci [2014-10-23]

CHR Extension: (Tweet Button for Chrome by Shareaholic) - C:\Documents and Settings\PC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\homldgnlpldcmdflhnabedgkgpmeanhd [2014-10-19]

CHR Extension: (Facebook Login Video Background) - C:\Documents and Settings\PC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kofmneijajkgajeffbphblliaeidahcn [2014-10-16]

CHR Extension: (Linkclump) - C:\Documents and Settings\PC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lfpjkncokllnfokkgpkobnkbkmelfefj [2014-10-09]

CHR Extension: (Skype Click to Call) - C:\Documents and Settings\PC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2013-10-16]

CHR Extension: (GGouSaave) - C:\Documents and Settings\PC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pefdgighdfaaojjebinjleeinndfdfij [2014-10-09]

CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2013-10-09]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

Locked "apkcfzpt" service was unlocked successfully. <===== ATTENTION

Locked "gfmiban" service was unlocked successfully. <===== ATTENTION

Locked "hhbso" service was unlocked successfully. <===== ATTENTION

Locked "hwvlyh" service was unlocked successfully. <===== ATTENTION

Locked "sdogua" service was unlocked successfully. <===== ATTENTION

Locked "snmibdk" service was unlocked successfully. <===== ATTENTION

R2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [109056 2008-07-03] (ArcSoft Inc.)

S2 apkcfzpt; C:\WINDOWS\system32\svchost.exe [14336 2008-04-14] (Microsoft Corporation)

S2 gfmiban; C:\WINDOWS\system32\svchost.exe [14336 2008-04-14] (Microsoft Corporation)

S2 hhbso; C:\WINDOWS\system32\svchost.exe [14336 2008-04-14] (Microsoft Corporation)

S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.)

R2 MDM; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [323584 2008-12-09] (Microsoft Corporation) [File not signed]

R2 NWCWorkstation; C:\WINDOWS\System32\nwwks.dll [65536 2008-04-14] (Microsoft Corporation)

S3 ose; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [89600 2008-12-09] (Microsoft Corporation) [File not signed]

S2 sdogua; C:\WINDOWS\system32\svchost.exe [14336 2008-04-14] (Microsoft Corporation)

R2 Skype C2C Service; C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3275136 2013-10-09] (Skype Technologies S.A.)

S2 snmibdk; C:\WINDOWS\system32\svchost.exe [14336 2008-04-14] (Microsoft Corporation)

S2 hwvlyh; C:\Program Files\Movie Maker\zwokur.dll [X]

  • Автор

==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 Afc; C:\WINDOWS\System32\drivers\Afc.sys [18688 2006-11-10] (Arcsoft, Inc.) S3 Ambfilt; C:\WINDOWS\System32\drivers\Ambfilt.sys [1684736 2008-08-05] (Creative) R3 ArcSoftKsUFilter; C:\WINDOWS\System32\DRIVERS\ArcSoftKsUFilter.sys [13184 2007-05-30] (ArcSoft, Inc.) S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation) R2 DgiVecp; C:\WINDOWS\System32\Drivers\DgiVecp.sys [40448 2003-07-29] (DeviceGuys, Inc.) [File not signed] R3 L1c; C:\WINDOWS\System32\DRIVERS\l1c51x86.sys [44032 2009-07-27] (Atheros Communications, Inc.) S3 Monfilt; C:\WINDOWS\System32\drivers\Monfilt.sys [1389056 2006-01-04] (Creative Technology Ltd.) S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation) R2 NwlnkIpx; C:\WINDOWS\System32\DRIVERS\nwlnkipx.sys [88320 2008-04-14] (Microsoft Corporation) R2 NwlnkNb; C:\WINDOWS\System32\DRIVERS\nwlnknb.sys [63232 2008-04-14] (Microsoft Corporation) R2 NwlnkSpx; C:\WINDOWS\System32\DRIVERS\nwlnkspx.sys [55936 2008-04-14] (Microsoft Corporation) R3 NWRDR; C:\WINDOWS\System32\DRIVERS\nwrdr.sys [163584 2008-04-14] (Microsoft Corporation) S3 SNPSTD3; C:\WINDOWS\System32\DRIVERS\snpstd3.sys [10376576 2007-10-16] (Sonix Co. Ltd.) [File not signed] R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}; C:\Program Files\CyberLink\PowerDVD10\NavFilter\000.fcl [87536 2010-03-13] (CyberLink Corp.) S3 AEXPAM; System32\Drivers\aexpamdrv.sys [X] S4 IntelIde; No ImagePath U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation) U1 WS2IFSL; No ImagePath ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) NETSVC: apkcfzpt -> No Registry Path. NETSVC: gfmiban -> No Registry Path. NETSVC: snmibdk -> No Registry Path. NETSVC: hhbso -> No Registry Path. NETSVC: sdogua -> No Registry Path. NETSVC: hwvlyh -> C:\Program Files\Movie Maker\zwokur.dll ==> No File. ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-12 15:47 - 2014-11-12 15:48 - 00000000 ___DC () C:\FRST 2014-11-12 15:14 - 2014-11-12 15:14 - 00004066 _____ () C:\Documents and Settings\PC\My Documents\cc_20141112_151400.reg 2014-11-12 15:08 - 2014-11-12 15:09 - 00977810 _____ () C:\Documents and Settings\PC\My Documents\cc_20141112_150820.reg 2014-11-12 14:17 - 2014-11-12 14:17 - 00000682 _____ () C:\Documents and Settings\All Users\Desktop\CCleaner.lnk 2014-11-12 14:17 - 2014-11-12 14:17 - 00000000 ____D () C:\Program Files\CCleaner 2014-11-12 14:17 - 2014-11-12 14:17 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner 2014-11-12 14:10 - 2014-09-11 08:57 - 02480312 _____ (Sysinternals - www.sysinternals.com) C:\Documents and Settings\PC\Desktop\procexp.exe 2014-11-12 13:40 - 2014-11-12 13:40 - 00401942 _____ () C:\Documents and Settings\PC\Application Data\bytor.bmp 2014-10-31 23:21 - 2014-11-12 13:37 - 04816205 _____ () C:\Documents and Settings\PC\My Documents\PI otg [email protected] 2014-10-31 23:20 - 2014-11-12 13:37 - 02949219 _____ () C:\Documents and Settings\PC\My Documents\PI [email protected] 2014-10-31 21:32 - 2014-11-12 13:32 - 157269444 _____ () C:\Documents and Settings\PC\My Documents\Materiali [email protected] 2014-10-31 18:33 - 2014-11-12 13:32 - 00053764 _____ () C:\Documents and Settings\PC\My Documents\mrrb_kniga [email protected] 2014-10-31 02:03 - 2014-11-12 13:39 - 00000180 ____H () C:\Documents and Settings\PC\My Documents\[email protected] 2014-10-30 17:03 - 2014-10-30 17:03 - 00001607 _____ () C:\Documents and Settings\PC\Desktop\Моят персонален компютър по правна информатика в ЮФ.lnk 2014-10-30 17:03 - 2014-10-30 17:03 - 00000813 _____ () C:\Documents and Settings\PC\My Documents\Моят персонален компютър по правна информатика в ЮФ.vbs 2014-10-27 14:45 - 2014-11-12 13:39 - 00180228 _____ () C:\Documents and Settings\PC\My Documents\Жулиета[email protected] 2014-10-27 13:27 - 2014-11-12 14:42 - 00114904 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2014-10-27 13:26 - 2014-10-27 13:26 - 00000777 _____ () C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk 2014-10-27 13:26 - 2014-10-27 13:26 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware 2014-10-27 13:26 - 2014-10-27 13:26 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware 2014-10-27 13:26 - 2014-10-27 13:26 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Malwarebytes 2014-10-27 13:26 - 2014-10-01 11:20 - 00054360 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2014-10-27 13:26 - 2014-10-01 11:20 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys 2014-10-27 12:48 - 2014-10-27 12:48 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-10-26 15:15 - 2014-11-12 13:39 - 00180228 _____ () C:\Documents and Settings\PC\My Documents\Ивелина[email protected] 2014-10-23 11:28 - 2014-10-23 11:28 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Fun2Saavei 2014-10-22 19:54 - 2014-11-12 13:39 - 00033284 _____ () C:\Documents and Settings\PC\My Documents\Августина се огледа отново[email protected] 2014-10-22 00:15 - 2014-11-12 13:37 - 00028164 _____ () C:\Documents and Settings\PC\My Documents\Out of the [email protected] 2014-10-21 18:04 - 2014-11-12 13:38 - 03841718 _____ () C:\Documents and Settings\PC\My Documents\III РљСѓСЂСЃ[email protected] 2014-10-16 12:31 - 2014-10-27 13:55 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\DEalExpResis 2014-10-15 12:04 - 2014-10-15 12:05 - 00002347 _____ () C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader XI.lnk 2014-10-15 12:04 - 2014-10-15 12:04 - 00001734 _____ () C:\Documents and Settings\All Users\Desktop\Adobe Reader XI.lnk 2014-10-14 14:36 - 2014-11-12 13:39 - 00039428 _____ () C:\Documents and Settings\PC\My Documents\Жулиета Добрева Автобиография[email protected] 2014-10-13 18:52 - 2014-11-12 13:37 - 00000000 ____D () C:\Documents and Settings\PC\My Documents\New Folder ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-12 15:48 - 2010-09-22 19:03 - 00000000 ____D () C:\Documents and Settings\PC\Application Data\BitTorrent 2014-11-12 15:48 - 2010-09-21 09:25 - 00000000 ____D () C:\Documents and Settings\PC\Local Settings\Temp 2014-11-12 15:47 - 2011-07-30 23:09 - 00000978 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2014-11-12 15:44 - 2012-04-01 22:39 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2014-11-12 15:43 - 2010-09-21 10:00 - 00000000 ____D () C:\Documents and Settings\PC\Application Data\Skype 2014-11-12 15:42 - 2010-09-21 10:00 - 00002497 _____ () C:\Documents and Settings\PC\Desktop\Microsoft Office Word 2003.lnk 2014-11-12 15:18 - 2010-09-21 12:16 - 00000343 _____ () C:\WINDOWS\wiadebug.log 2014-11-12 14:29 - 2010-10-05 11:21 - 00000116 ____C () C:\WINDOWS\NeroDigital.ini 2014-11-12 14:25 - 2010-09-22 19:02 - 00000000 ____D () C:\Documents and Settings\PC\Application Data\Media Player Classic 2014-11-12 14:25 - 2010-09-21 09:25 - 00000000 ____D () C:\Documents and Settings\PC 2014-11-12 14:24 - 2011-03-15 15:48 - 00000000 ____D () C:\WINDOWS\Minidump 2014-11-12 14:10 - 2010-09-21 09:21 - 01772583 ____N () C:\WINDOWS\WindowsUpdate.log 2014-11-12 14:02 - 2010-09-21 12:14 - 00512960 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2014-11-12 14:00 - 2011-07-30 23:09 - 00000974 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2014-11-12 13:49 - 2010-09-21 12:16 - 00000053 ____N () C:\WINDOWS\wiaservc.log 2014-11-12 13:49 - 2010-09-21 09:25 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2014-11-12 13:40 - 2014-09-10 01:22 - 00000000 ___DC () C:\ZET 9 2014-11-12 13:40 - 2014-08-06 22:13 - 00025092 ____C () C:\Documents and Settings\PC\My Documents\Честит рожден ден[email protected] 2014-11-12 13:40 - 2014-03-08 20:13 - 00000000 ____D () C:\Frozen.2013.BRRip.XviD.AC3-SANTi 2014-11-12 13:40 - 2014-01-01 15:04 - 00024068 ____C () C:\Documents and Settings\PC\My Documents\Честита Нова Година[email protected] 2014-11-12 13:40 - 2013-12-25 19:48 - 00024580 ____C () C:\Documents and Settings\PC\My Documents\Честито Рождество Христово[email protected] 2014-11-12 13:40 - 2013-06-18 16:40 - 00044036 ____C () C:\Documents and Settings\PC\My Documents\Хороскопи на The [email protected] 2014-11-12 13:40 - 2013-06-08 02:11 - 00026628 ____C () C:\Documents and Settings\PC\My Documents\Хороскоп One [email protected] 2014-11-12 13:40 - 2013-02-09 21:50 - 00253444 ____C () C:\Documents and Settings\PC\My Documents\уч.програма_специализации[email protected] 2014-11-12 13:40 - 2013-01-25 17:14 - 363745372 _____ () C:\[email protected] 2014-11-12 13:40 - 2013-01-05 00:03 - 00000000 ____D () C:\[ www.TorrentDay.com ] - Punkd.S09E06.HDTV.XviD-AFG 2014-11-12 13:40 - 2012-12-07 21:31 - 00000000 ____D () C:\[ www.TorrentDay.com ] - Glee.S04E09.480p.HDTV.x264-mSD 2014-11-12 13:40 - 2012-12-05 02:07 - 00000000 ____D () C:\How To Read a Person Like a Book 2014-11-12 13:40 - 2012-12-02 20:23 - 00000000 ____D () C:\Glee.S04E01.HDTV.XviD-AFG 2014-11-12 13:40 - 2012-11-02 03:57 - 00036356 ____C () C:\Documents and Settings\PC\My Documents\Утопичност в ученията за държавата[email protected] 2014-11-12 13:40 - 2012-11-02 03:55 - 00034308 ____C () C:\Documents and Settings\PC\My Documents\Учение за оправдаването или легитимирането на държавата[email protected] 2014-11-12 13:40 - 2012-11-02 03:53 - 00033284 ____C () C:\Documents and Settings\PC\My Documents\Ученията за държавата и правото като предмет на научно познание[email protected] 2014-11-12 13:40 - 2012-05-02 18:05 - 00000000 ____D () C:\This.Means.War.2012.DVDRip.XviD-SPARKS 2014-11-12 13:40 - 2012-04-25 13:06 - 367407424 _____ () C:\[email protected] 2014-11-12 13:40 - 2012-04-18 14:16 - 00000000 ____D () C:\One.For.The.Money.2012.480p.BRRip.XviD.AC3-NYDIC 2014-11-12 13:40 - 2012-04-18 14:14 - 00000000 ____D () C:\Glee.S03E16.HDTV.XviD-2HD 2014-11-12 13:40 - 2012-04-11 11:30 - 366112512 ____C () C:\glee.s03e15.big.brother.hdtv.xvid-2hd.avi.id-1665414413_decode@india.com 2014-11-12 13:40 - 2012-04-01 22:33 - 00028164 ____C () C:\Documents and Settings\PC\My Documents\Шаран на скара[email protected] 2014-11-12 13:40 - 2012-03-23 19:00 - 00000000 ____D () C:\The Vow 2012 R5 LiNE XViD - INSPiRAL 2014-11-12 13:40 - 2012-03-21 17:00 - 00000000 ____D () C:\Switched.at.Birth.S01E22.HDTV.XviD-2HD 2014-11-12 13:40 - 2012-02-28 18:05 - 00024068 ____C () C:\Documents and Settings\PC\My Documents\часово разписание[email protected] 2014-11-12 13:40 - 2012-02-15 19:03 - 00000000 ____D () C:\Sound Forge Audio Studio 10.0 Build 177 2014-11-12 13:40 - 2012-01-18 12:13 - 00000000 ____D () C:\Yours.Mine.and.Ours.1968.DVBRip.XviD.BULSUB-MGM 2014-11-12 13:40 - 2011-03-12 20:55 - 00000000 ____D () C:\julie doc 2014-11-12 13:40 - 2011-03-09 21:47 - 323160095 _____ () C:\[email protected] 2014-11-12 13:39 - 2014-10-10 23:09 - 00071364 _____ () C:\Documents and Settings\PC\My Documents\Конспект за изпит по териториално и селищно устройство[email protected] 2014-11-12 13:39 - 2014-10-10 23:02 - 00117581 _____ () C:\Documents and Settings\PC\My Documents\Конспект за изпит по облигационно право[email protected] 2014-11-12 13:39 - 2014-10-10 22:57 - 00113053 _____ () C:\Documents and Settings\PC\My Documents\Конспект за изпит по финансово право[email protected] 2014-11-12 13:39 - 2014-10-10 22:53 - 00082468 _____ () C:\Documents and Settings\PC\My Documents\Конспект за изпит по вешно право[email protected] 2014-11-12 13:39 - 2014-10-10 21:50 - 00202182 _____ () C:\Documents and Settings\PC\My Documents\Въпросник по правна информатика[email protected] 2014-11-12 13:39 - 2014-10-10 17:56 - 00796676 _____ () C:\Documents and Settings\PC\My Documents\Veshtno [email protected] 2014-11-12 13:39 - 2014-10-07 15:58 - 00091652 _____ () C:\Documents and Settings\PC\My Documents\Здрасти Криси[email protected] 2014-11-12 13:39 - 2014-10-05 23:18 - 00434692 _____ () C:\Documents and Settings\PC\My Documents\Телепатия[email protected] 2014-11-12 13:39 - 2014-10-05 23:10 - 01859076 _____ () C:\Documents and Settings\PC\My Documents\Тайните подземия на България Част [email protected] 2014-11-12 13:39 - 2014-10-04 13:11 - 00040964 _____ () C:\Documents and Settings\PC\My Documents\Подписка[email protected] 2014-11-12 13:39 - 2014-08-11 15:17 - 00031748 _____ () C:\Documents and Settings\PC\My Documents\Мотивационно_писмо_Жулиета_Добрева[email protected] 2014-11-12 13:39 - 2014-08-07 17:57 - 00000180 ___HC () C:\Documents and Settings\PC\My Documents\~$дравей[email protected] 2014-11-12 13:39 - 2014-08-03 00:19 - 00028164 _____ () C:\Documents and Settings\PC\My Documents\славейче[email protected] 2014-11-12 13:39 - 2014-07-31 16:30 - 00030724 ____C () C:\Documents and Settings\PC\My Documents\Мотивационно писмо_Жулиета Добрева[email protected] 2014-11-12 13:39 - 2014-07-23 00:11 - 00028164 ____C () C:\Documents and Settings\PC\My Documents\П О К А Н А[email protected] 2014-11-12 13:39 - 2014-07-22 23:46 - 00039940 ____C () C:\Documents and Settings\PC\My Documents\ПРОТОКО[email protected] 2014-11-12 13:39 - 2014-07-22 18:54 - 00038916 _____ () C:\Documents and Settings\PC\My Documents\констативен протокол[email protected] 2014-11-12 13:39 - 2014-07-11 14:40 - 02500100 _____ () C:\Documents and Settings\PC\My Documents\_ОП Траян Конов[email protected] 2014-11-12 13:39 - 2014-07-11 14:40 - 00000180 ___HC () C:\Documents and Settings\PC\My Documents\~$П Траян Конов[email protected] 2014-11-12 13:39 - 2014-07-06 20:45 - 00000180 ____H () C:\Documents and Settings\PC\My Documents\~$одължение на изборът[email protected] 2014-11-12 13:39 - 2014-07-03 22:43 - 00029700 _____ () C:\Documents and Settings\PC\My Documents\оренда статия[email protected] 2014-11-12 13:39 - 2014-06-23 20:51 - 00118276 _____ () C:\Documents and Settings\PC\My Documents\РЕЙКИ [email protected] 2014-11-12 13:39 - 2014-06-13 11:32 - 00026116 ____C () C:\Documents and Settings\PC\My Documents\vuprosi gp - [email protected] 2014-11-12 13:39 - 2014-06-11 18:03 - 00025092 ____C () C:\Documents and Settings\PC\My Documents\Сравнение на гражданскоправни понятия[email protected] 2014-11-12 13:39 - 2014-06-05 15:42 - 00000180 ___HC () C:\Documents and Settings\PC\My Documents\~$СЉРїСЂРѕСЃРё РѕС‚ изпитите РїРѕ ГО - обща част[email protected] 2014-11-12 13:39 - 2014-06-05 14:23 - 00000180 ___HC () C:\Documents and Settings\PC\My Documents\~$p [email protected] 2014-11-12 13:39 - 2014-06-04 14:08 - 00044036 ____C () C:\Documents and Settings\PC\My Documents\Р’СЉРїСЂРѕСЃРё РѕС‚ изпитите РїРѕ ГО - обща част[email protected] 2014-11-12 13:39 - 2014-05-10 22:56 - 40004778 _____ () C:\Documents and Settings\PC\My Documents\Източници Русчев[email protected] 2014-11-12 13:39 - 2014-04-28 16:38 - 04664324 ____C () C:\Documents and Settings\PC\My Documents\РЕЙКИ [email protected] 2014-11-12 13:39 - 2014-04-28 16:38 - 00266244 _____ () C:\Documents and Settings\PC\My Documents\рейки - 2 допълнение[email protected] 2014-11-12 13:39 - 2014-04-19 22:00 - 00135684 ____C () C:\Documents and Settings\PC\My Documents\ИЗИС СЕЙКИМ[email protected] 2014-11-12 13:39 - 2014-04-16 18:56 - 00359741 _____ () C:\Documents and Settings\PC\My Documents\Автореферат РЅР° Рњ.Кънева[email protected] 2014-11-12 13:39 - 2014-04-16 18:54 - 00322034 _____ () C:\Documents and Settings\PC\My Documents\Автореферат РЅР° Орлин Колев[email protected] 2014-11-12 13:39 - 2014-04-16 18:53 - 00362125 _____ () C:\Documents and Settings\PC\My Documents\Автореферат РЅР° Петър Радославов Рлиев[email protected] 2014-11-12 13:39 - 2014-04-14 18:05 - 00000180 ___HC () C:\Documents and Settings\PC\My Documents\~$ЕЙКИ [email protected] 2014-11-12 13:39 - 2014-04-14 16:34 - 01637892 ____C () C:\Documents and Settings\PC\My Documents\РЕЙКИ [email protected] 2014-11-12 13:39 - 2014-03-25 22:57 - 00708612 ____C () C:\Documents and Settings\PC\My Documents\РљРџ [email protected] 2014-11-12 13:39 - 2014-03-08 04:07 - 00027140 ____C () C:\Documents and Settings\PC\My Documents\Обръщам се към теб[email protected] 2014-11-12 13:39 - 2014-02-27 11:45 - 00061444 ____C () C:\Documents and Settings\PC\My Documents\Здравей[email protected] 2014-11-12 13:39 - 2014-02-25 23:09 - 00080068 _____ () C:\Documents and Settings\PC\My Documents\Конспект по всеобща история на държавата и правото[email protected] 2014-11-12 13:39 - 2014-02-25 23:08 - 00074580 _____ () C:\Documents and Settings\PC\My Documents\Конспект за изпит по правна психология[email protected] 2014-11-12 13:39 - 2014-02-25 23:07 - 00072516 _____ () C:\Documents and Settings\PC\My Documents\Въпросник по право на Европейския съюз[email protected] 2014-11-12 13:39 - 2014-02-25 23:06 - 00093076 _____ () C:\Documents and Settings\PC\My Documents\конспект -конституционно право на РБ[email protected] 2014-11-12 13:39 - 2014-02-25 23:05 - 00074996 _____ () C:\Documents and Settings\PC\My Documents\Въпросник по гражданско право-обща част[email protected] 2014-11-12 13:39 - 2014-02-24 00:50 - 00074244 ____C () C:\Documents and Settings\PC\My Documents\Здравей, Мирче[email protected] 2014-11-12 13:39 - 2014-02-24 00:49 - 00051204 ____C () C:\Documents and Settings\PC\My Documents\Здравей мирче[email protected] 2014-11-12 13:39 - 2014-02-23 17:22 - 00034820 ____C () C:\Documents and Settings\PC\My Documents\Неделя[email protected] 2014-11-12 13:39 - 2014-02-21 19:11 - 00051716 ____C () C:\Documents and Settings\PC\My Documents\Корбън Блу[email protected] 2014-11-12 13:39 - 2014-02-03 18:24 - 20283381 _____ () C:\Documents and Settings\PC\My Documents\jan.van.helsing-vlasta.na.tainite.obshtestva.prez.xx.vek.pdf.id-1665414413_decode@india.com 2014-11-12 13:39 - 2014-01-24 00:16 - 00043604 _____ () C:\Documents and Settings\PC\My Documents\Летен семестър (print)[email protected] 2014-11-12 13:39 - 2014-01-20 01:32 - 11556320 ____C () C:\Documents and Settings\PC\My Documents\Гражданско право[email protected] 2014-11-12 13:39 - 2014-01-20 01:32 - 00379908 ____C () C:\Documents and Settings\PC\My Documents\РРџ - съкратени теми[email protected] 2014-11-12 13:39 - 2014-01-20 01:30 - 04692283 ____C () C:\Documents and Settings\PC\My Documents\IP - [email protected] 2014-11-12 13:39 - 2014-01-17 17:08 - 00299524 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:39 - 2014-01-17 17:07 - 00124071 ____C () C:\Documents and Settings\PC\My Documents\juli [email protected] 2014-11-12 13:39 - 2014-01-16 19:55 - 00024580 ____C () C:\Documents and Settings\PC\My Documents\криси[email protected] 2014-11-12 13:39 - 2014-01-16 11:59 - 00000000 ____D () C:\Documents and Settings\PC\My Documents\ip 2014-11-12 13:39 - 2014-01-11 20:52 - 69578489 ____C () C:\Documents and Settings\PC\My Documents\vzet [email protected] 2014-11-12 13:39 - 2013-12-29 23:16 - 01588529 ____C () C:\Documents and Settings\PC\My Documents\РёРї 24,25,26,[email protected] 2014-11-12 13:39 - 2013-12-29 23:15 - 03335371 ____C () C:\Documents and Settings\PC\My Documents\РёРї 10,11,12,13,14,15,[email protected] 2014-11-12 13:39 - 2013-12-29 23:15 - 01236304 ____C () C:\Documents and Settings\PC\My Documents\ip 16,17,19,20,21,[email protected] 2014-11-12 13:39 - 2013-12-26 22:40 - 00024580 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:39 - 2013-12-17 16:05 - 00000180 ___HC () C:\Documents and Settings\PC\My Documents\~$серите на Пиперков[email protected] 2014-11-12 13:39 - 2013-12-10 22:29 - 00025604 ____C () C:\Documents and Settings\PC\My Documents\Пълномощн[email protected] 2014-11-12 13:39 - 2013-12-04 20:37 - 00033796 ____C () C:\Documents and Settings\PC\My Documents\Р’_РЄ_Рџ_Р _Рћ_РЎ_Рќ_Р_РљРїРѕ_РђРґРј._право[email protected] 2014-11-12 13:39 - 2013-12-04 20:11 - 00429197 ____C () C:\Documents and Settings\PC\My Documents\Административно право[email protected] 2014-11-12 13:39 - 2013-11-12 21:59 - 00076292 ____C () C:\Documents and Settings\PC\My Documents\новият септември[email protected] 2014-11-12 13:39 - 2013-11-04 14:46 - 00132300 _____ () C:\Documents and Settings\PC\My Documents\конспект-избирателни системи Рё избирателни процедури[email protected] 2014-11-12 13:39 - 2013-11-01 00:19 - 00025604 ____C () C:\Documents and Settings\PC\My Documents\въпроси[email protected] 2014-11-12 13:39 - 2013-10-25 23:05 - 00126980 ____C () C:\Documents and Settings\PC\My Documents\Здравей[email protected] 2014-11-12 13:39 - 2013-10-20 18:09 - 00208900 ____C () C:\Documents and Settings\PC\My Documents\Защита РЅР° правата РЅР° човека[email protected] 2014-11-12 13:39 - 2013-10-17 23:21 - 00183300 ____C () C:\Documents and Settings\PC\My Documents\Привет[email protected] 2014-11-12 13:39 - 2013-10-12 18:48 - 02592458 _____ () C:\Documents and Settings\PC\My Documents\МПП - конспект[email protected] 2014-11-12 13:39 - 2013-10-12 18:47 - 00034228 _____ () C:\Documents and Settings\PC\My Documents\Въпросник по административно право[email protected] 2014-11-12 13:39 - 2013-10-09 19:15 - 00027140 ____C () C:\Documents and Settings\PC\My Documents\за С.Г[email protected] 2014-11-12 13:39 - 2013-09-07 21:38 - 00026116 ____C () C:\Documents and Settings\PC\My Documents\Съединението прави силата ! [email protected] 2014-11-12 13:39 - 2013-09-07 21:37 - 00012404 ____C () C:\Documents and Settings\PC\My Documents\Съединението прави силата ! [email protected] 2014-11-12 13:39 - 2013-07-23 20:14 - 00089604 ____C () C:\Documents and Settings\PC\My Documents\писмо д[email protected] 2014-11-12 13:39 - 2013-07-17 22:53 - 00024580 ____C () C:\Documents and Settings\PC\My Documents\Бисерите на Пиперков[email protected] 2014-11-12 13:39 - 2013-07-04 13:26 - 00264708 ____C () C:\Documents and Settings\PC\My Documents\кака[email protected] 2014-11-12 13:39 - 2013-06-30 23:51 - 00194052 ____C () C:\Documents and Settings\PC\My Documents\продължение на изборът[email protected] 2014-11-12 13:39 - 2013-06-20 21:22 - 00025604 ____C () C:\Documents and Settings\PC\My Documents\ода за образУванието[email protected] 2014-11-12 13:39 - 2013-06-17 16:37 - 00031748 ____C () C:\Documents and Settings\PC\My Documents\Професия ром[email protected] 2014-11-12 13:39 - 2013-06-17 16:09 - 00026628 ____C () C:\Documents and Settings\PC\My Documents\Докато си превключвах каналите се спрях на Канал [email protected] 2014-11-12 13:39 - 2013-05-30 18:39 - 00033284 ____C () C:\Documents and Settings\PC\My Documents\за слави1 [email protected] 2014-11-12 13:39 - 2013-05-15 18:15 - 00025604 ____C () C:\Documents and Settings\PC\My Documents\за абитуриенти[email protected] 2014-11-12 13:39 - 2013-05-08 10:54 - 00034820 ____C () C:\Documents and Settings\PC\My Documents\Не ме е страх[email protected] 2014-11-12 13:39 - 2013-04-07 10:42 - 00035844 ____C () C:\Documents and Settings\PC\My Documents\ГРАДИНАТА Е ЕНЕРГИЕН РАЙ[email protected] 2014-11-12 13:39 - 2013-04-06 12:43 - 00037380 ____C () C:\Documents and Settings\PC\My Documents\Ето КАК да РАЗВАЛИМ черна МАГИЯ[email protected] 2014-11-12 13:39 - 2013-04-06 12:39 - 00030724 ____C () C:\Documents and Settings\PC\My Documents\Лесни начини[email protected] 2014-11-12 13:39 - 2013-04-05 01:46 - 00318980 ____C () C:\Documents and Settings\PC\My Documents\ОПИ [email protected] 2014-11-12 13:39 - 2013-04-05 01:00 - 00025604 ____C () C:\Documents and Settings\PC\My Documents\Пълномощно [email protected] 2014-11-12 13:39 - 2013-03-28 18:59 - 00049332 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:39 - 2013-03-23 19:05 - 00000000 ____D () C:\Documents and Settings\PC\My Documents\Университет 2014-11-12 13:39 - 2013-03-15 22:52 - 00028164 ____C () C:\Documents and Settings\PC\My Documents\продължение на статия[email protected] 2014-11-12 13:39 - 2013-03-15 20:06 - 00026116 ____C () C:\Documents and Settings\PC\My Documents\Не си го мислел[email protected] 2014-11-12 13:39 - 2013-03-13 19:30 - 01583620 ____C () C:\Documents and Settings\PC\My Documents\Обща икономическа теория[email protected] 2014-11-12 13:39 - 2013-03-13 11:55 - 00029444 ____C () C:\Documents and Settings\PC\My Documents\РќРѕРІ Microsoft Office Word [email protected] 2014-11-12 13:39 - 2013-03-12 00:08 - 00027652 ____C () C:\Documents and Settings\PC\My Documents\Молитви за успешен изпит[email protected] 2014-11-12 13:39 - 2013-03-11 15:29 - 00026708 ____C () C:\Documents and Settings\PC\My Documents\РќРѕРІ Microsoft Office Word Document (13)[email protected] 2014-11-12 13:39 - 2013-03-05 21:13 - 00148484 ____C () C:\Documents and Settings\PC\My Documents\РћРџР-20.02.2013Р“[email protected] 2014-11-12 13:39 - 2013-03-05 16:56 - 00024068 ____C () C:\Documents and Settings\PC\My Documents\Отключване[email protected] 2014-11-12 13:39 - 2013-02-21 21:14 - 00034308 ____C () C:\Documents and Settings\PC\My Documents\Тази утрин Витоша бе тъй загадъчна и нежна[email protected] 2014-11-12 13:39 - 2013-02-09 17:37 - 00024068 ____C () C:\Documents and Settings\PC\My Documents\izborni_1 [email protected] 2014-11-12 13:39 - 2013-01-23 22:07 - 00000000 ____D () C:\Documents and Settings\PC\My Documents\verji 2014-11-12 13:39 - 2013-01-14 21:37 - 01272836 ____C () C:\Documents and Settings\PC\My Documents\ОБЩА ТЕОРИЯ НА ПРАВОТО (1)[email protected] 2014-11-12 13:39 - 2013-01-07 19:04 - 00184693 ____C () C:\Documents and Settings\PC\My Documents\МО[email protected] 2014-11-12 13:39 - 2012-12-31 19:34 - 00046084 ____C () C:\Documents and Settings\PC\My Documents\Нова година[email protected] 2014-11-12 13:39 - 2012-12-08 23:30 - 00885252 ____C () C:\Documents and Settings\PC\My Documents\Въпросник по История на българската държава и право[email protected] 2014-11-12 13:39 - 2012-12-01 21:11 - 00125444 ____C () C:\Documents and Settings\PC\My Documents\Отчет.Право-з.2012-2013 -за студентите[email protected] 2014-11-12 13:39 - 2012-11-20 19:23 - 00045060 ____C () C:\Documents and Settings\PC\My Documents\Жулиета.Домашно[email protected] 2014-11-12 13:39 - 2012-11-20 19:20 - 00026116 ____C () C:\Documents and Settings\PC\My Documents\Здравейте отново[email protected] 2014-11-12 13:39 - 2012-11-16 01:51 - 00094212 ____C () C:\Documents and Settings\PC\My Documents\Здравейте[email protected] 2014-11-12 13:39 - 2012-11-15 13:45 - 00150532 ____C () C:\Documents and Settings\PC\My Documents\РћРўР” (1)[email protected] 2014-11-12 13:39 - 2012-11-02 03:47 - 00054788 ____C () C:\Documents and Settings\PC\My Documents\Носиологични отношения в държавата[email protected] 2014-11-12 13:39 - 2012-11-02 03:44 - 00026084 ____C () C:\Documents and Settings\PC\My Documents\Носиологични отношения в държавата[email protected] 2014-11-12 13:39 - 2012-10-28 19:25 - 00043012 ____C () C:\Documents and Settings\PC\My Documents\zhulieta_dobreva - [email protected] 2014-11-12 13:39 - 2012-10-25 17:50 - 00265732 ____C () C:\Documents and Settings\PC\My Documents\Презентация за Паисий Хилендарски[email protected] 2014-11-12 13:39 - 2012-09-17 18:45 - 00064004 ____C () C:\Documents and Settings\PC\My Documents\Държавата на управленско ниво[email protected] 2014-11-12 13:39 - 2012-09-17 18:39 - 00021332 ____C () C:\Documents and Settings\PC\My Documents\Въпрос_daniel [email protected] 2014-11-12 13:39 - 2012-09-17 18:38 - 00017988 ____C () C:\Documents and Settings\PC\My Documents\Държавата на управленско ниво[email protected] 2014-11-12 13:39 - 2012-09-08 20:14 - 00189444 ____C () C:\Documents and Settings\PC\My Documents\І курс[email protected] 2014-11-12 13:39 - 2012-08-17 16:21 - 00000180 ___HC () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:39 - 2012-07-25 20:47 - 00028676 ____C () C:\Documents and Settings\PC\My Documents\Начало и край на ваканциите с изключение на лятната през учебната [email protected] 2014-11-12 13:39 - 2012-07-24 18:27 - 00078852 ____C () C:\Documents and Settings\PC\My Documents\Входящ номер[email protected] 2014-11-12 13:39 - 2012-07-24 18:06 - 00025092 ____C () C:\Documents and Settings\PC\My Documents\Небходими документи за записване[email protected] 2014-11-12 13:39 - 2012-07-18 15:24 - 00042500 ____C () C:\Documents and Settings\PC\My Documents\ПРОТОКОЛ[email protected] 2014-11-12 13:39 - 2012-07-12 00:54 - 00028164 ____C () C:\Documents and Settings\PC\My Documents\Азбучна молитва[email protected] 2014-11-12 13:39 - 2012-06-11 20:50 - 00025604 ____C () C:\Documents and Settings\PC\My Documents\Vorurteile nach dem Aussehen 4 - [email protected] 2014-11-12 13:39 - 2012-06-11 17:29 - 00060420 ____C () C:\Documents and Settings\PC\My Documents\Прабългари и славяни през епохата на[email protected] 2014-11-12 13:39 - 2012-06-10 23:14 - 00011588 ____C () C:\Documents and Settings\PC\My Documents\Vorurteile nach dem Aussehen 4 - [email protected] 2014-11-12 13:39 - 2012-05-19 14:02 - 185333333 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:39 - 2012-05-19 13:47 - 38394571 ____C () C:\Documents and Settings\PC\My Documents\Izprashtane i [email protected] 2014-11-12 13:39 - 2012-05-18 11:04 - 00024580 ____C () C:\Documents and Settings\PC\My Documents\Скъпи мой клас[email protected] 2014-11-12 13:39 - 2012-05-15 17:18 - 178515276 ____C () C:\Documents and Settings\PC\My Documents\СЕРЕНАДИ[email protected] 2014-11-12 13:39 - 2012-05-02 22:58 - 00041476 ____C () C:\Documents and Settings\PC\My Documents\Възможности за реализация на младите българи в България[email protected] 2014-11-12 13:39 - 2012-05-01 15:05 - 00024068 ____C () C:\Documents and Settings\PC\My Documents\Няма светец без минало и грешник без бъдеще[email protected] 2014-11-12 13:39 - 2012-04-21 01:50 - 00035844 ____C () C:\Documents and Settings\PC\My Documents\Извори[email protected] 2014-11-12 13:39 - 2012-04-20 15:40 - 00068612 ____C () C:\Documents and Settings\PC\My Documents\Политическо и културно развитие при цар Симеон[email protected] 2014-11-12 13:39 - 2012-04-17 20:03 - 00057348 ____C () C:\Documents and Settings\PC\My Documents\ИСТОРИЯ [email protected] 2014-11-12 13:39 - 2012-04-14 22:04 - 00071684 ____C () C:\Documents and Settings\PC\My Documents\Семки и бомбонки[email protected] 2014-11-12 13:39 - 2012-04-06 00:12 - 00036356 ____C () C:\Documents and Settings\PC\My Documents\реч[email protected] 2014-11-12 13:39 - 2012-03-30 18:52 - 00024580 ____C () C:\Documents and Settings\PC\My Documents\Пълномощно[email protected] 2014-11-12 13:39 - 2012-03-14 20:18 - 00118276 ____C () C:\Documents and Settings\PC\My Documents\Подай ръка[email protected] 2014-11-12 13:39 - 2012-03-13 20:24 - 00092164 ____C () C:\Documents and Settings\PC\My Documents\Проект[email protected] 2014-11-12 13:39 - 2012-03-11 23:42 - 00064004 ____C () C:\Documents and Settings\PC\My Documents\Видин[email protected] 2014-11-12 13:39 - 2012-03-11 21:11 - 60244848 ____C () C:\Documents and Settings\PC\My Documents\Североизточен регион[email protected] 2014-11-12 13:39 - 2012-03-11 20:49 - 15497220 ____C () C:\Documents and Settings\PC\My Documents\Северозападен район презентация[email protected] 2014-11-12 13:39 - 2012-03-11 20:46 - 58198998 ____C () C:\Documents and Settings\PC\My Documents\география[email protected] 2014-11-12 13:39 - 2012-03-11 15:54 - 01261060 ____C () C:\Documents and Settings\PC\My Documents\Северозападен район[email protected] 2014-11-12 13:39 - 2012-03-10 22:47 - 00037892 ____C () C:\Documents and Settings\PC\My Documents\врачански говор[email protected] 2014-11-12 13:39 - 2012-03-10 00:44 - 00027652 ____C () C:\Documents and Settings\PC\My Documents\Жулиета Meine [email protected] 2014-11-12 13:39 - 2012-03-09 21:35 - 20283381 _____ () C:\Documents and Settings\PC\My Documents\jan.van.helsing-vlasta.na.tainite.obshtestva.prez.xx.vek[1][email protected] 2014-11-12 13:39 - 2012-03-06 23:12 - 00030212 ____C () C:\Documents and Settings\PC\My Documents\Един български физик е доказал научно[email protected] 2014-11-12 13:39 - 2012-03-06 22:59 - 00037380 ____C () C:\Documents and Settings\PC\My Documents\Президент с топки[email protected] 2014-11-12 13:39 - 2012-03-04 20:10 - 02388484 ____C () C:\Documents and Settings\PC\My Documents\Видин[email protected] 2014-11-12 13:39 - 2012-02-23 22:03 - 00783063 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:39 - 2012-02-19 14:28 - 00024068 ____C () C:\Documents and Settings\PC\My Documents\Националноосвободително движение през Възраждането-понятия[email protected] 2014-11-12 13:39 - 2012-02-19 00:29 - 00028164 ____C () C:\Documents and Settings\PC\My Documents\Априлско въстание[email protected] 2014-11-12 13:39 - 2012-02-11 19:44 - 05386756 ____C () C:\Documents and Settings\PC\My Documents\Млечният път[email protected] 2014-11-12 13:39 - 2012-02-10 16:47 - 00048644 ____C () C:\Documents and Settings\PC\My Documents\Иван Александър[email protected] 2014-11-12 13:39 - 2012-02-06 01:36 - 00039428 ____C () C:\Documents and Settings\PC\My Documents\Из старите ми тетрадки[email protected] 2014-11-12 13:39 - 2012-02-03 19:52 - 00046596 ____C () C:\Documents and Settings\PC\My Documents\метеора[email protected] 2014-11-12 13:39 - 2012-02-02 00:01 - 00026116 ____C () C:\Documents and Settings\PC\My Documents\статия[email protected] 2014-11-12 13:39 - 2012-01-25 23:09 - 00037892 ____C () C:\Documents and Settings\PC\My Documents\дати[email protected] 2014-11-12 13:39 - 2012-01-18 20:47 - 00024068 ____C () C:\Documents and Settings\PC\My Documents\стих[email protected] 2014-11-12 13:39 - 2012-01-05 23:15 - 00671748 ____C () C:\Documents and Settings\PC\My Documents\празници[email protected] 2014-11-12 13:39 - 2011-12-18 19:45 - 01786974 _____ () C:\Documents and Settings\PC\My Documents\zapoved09-1738_24-11-2011_olimpiadi.pdf.id-1665414413_decode@india.com 2014-11-12 13:39 - 2011-11-18 22:03 - 00304132 ____C () C:\Documents and Settings\PC\My Documents\Обичате ли да четете[email protected] 2014-11-12 13:39 - 2011-11-01 20:12 - 00000180 ___HC () C:\Documents and Settings\PC\My Documents\~$ло дневниче[email protected] 2014-11-12 13:39 - 2011-07-01 00:00 - 00083460 ____C () C:\Documents and Settings\PC\My Documents\Къде е батко[email protected] 2014-11-12 13:39 - 2011-06-23 21:30 - 00051716 ____C () C:\Documents and Settings\PC\My Documents\Скръбна вест[email protected] 2014-11-12 13:39 - 2011-05-20 00:50 - 00026628 ____C () C:\Documents and Settings\PC\My Documents\Скъпи вълци[email protected] 2014-11-12 13:39 - 2011-05-08 00:26 - 00033284 ____C () C:\Documents and Settings\PC\My Documents\Списък[email protected] 2014-11-12 13:39 - 2011-04-23 17:19 - 00450052 ____C () C:\Documents and Settings\PC\My Documents\оръжията и човекът[email protected] 2014-11-12 13:39 - 2011-04-20 16:21 - 01540100 ____C () C:\Documents and Settings\PC\My Documents\Видео[email protected] 2014-11-12 13:39 - 2011-04-19 23:47 - 00024068 ____C () C:\Documents and Settings\PC\My Documents\Безплодните висини на интелигентността[email protected] 2014-11-12 13:39 - 2011-02-04 20:48 - 00024068 ____C () C:\Documents and Settings\PC\My Documents\Вие се преброихте успешно[email protected] 2014-11-12 13:39 - 2011-01-28 17:36 - 00003668 ____C () C:\Documents and Settings\PC\My Documents\Любовта е всичко[email protected] 2014-11-12 13:39 - 2010-12-31 19:48 - 00043012 ____C () C:\Documents and Settings\PC\My Documents\късмети [email protected] 2014-11-12 13:39 - 2010-09-22 18:38 - 00000000 ____D () C:\Documents and Settings\PC\My Documents\julie 2014-11-12 13:38 - 2014-09-09 03:30 - 00035332 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2014-07-31 20:47 - 00000000 ____D () C:\Documents and Settings\PC\My Documents\Stellar Theology and Masonic Astronomy 2014-11-12 13:38 - 2014-07-31 13:55 - 06061060 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2014-07-26 23:46 - 01700881 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2014-07-26 23:45 - 01732086 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2014-07-26 23:44 - 01924801 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2014-07-26 23:32 - 01850846 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2014-07-26 23:25 - 01533136 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2014-07-26 23:25 - 01456960 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2014-07-26 23:25 - 01412436 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2014-07-26 23:25 - 01379695 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2014-07-26 23:23 - 01686447 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2014-07-26 23:23 - 00130194 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2014-07-26 23:23 - 00114649 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2014-06-11 11:48 - 00303725 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2014-06-05 14:34 - 00000000 ____D () C:\Documents and Settings\PC\My Documents\gp 2014-11-12 13:38 - 2014-06-05 14:23 - 04513796 ____C () C:\Documents and Settings\PC\My Documents\gp [email protected] 2014-11-12 13:38 - 2014-04-28 16:12 - 01357316 ____C () C:\Documents and Settings\PC\My Documents\Reiki 1 Krasimira Sasheva Hristova (2)[email protected] 2014-11-12 13:38 - 2014-04-14 16:34 - 00151726 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2014-04-14 16:33 - 00158086 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2014-04-02 19:24 - 00030724 ____C () C:\Documents and Settings\PC\My Documents\pr psihologiq [email protected] 2014-11-12 13:38 - 2014-03-30 16:27 - 00068612 ____C () C:\Documents and Settings\PC\My Documents\pr [email protected] 2014-11-12 13:38 - 2014-03-22 21:21 - 00000000 ____D () C:\Documents and Settings\PC\My Documents\Preselenie v Rusia 2014-11-12 13:38 - 2014-02-28 00:32 - 00024068 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2014-02-21 22:05 - 00033796 ____C () C:\Documents and Settings\PC\My Documents\Hey [email protected] 2014-11-12 13:38 - 2014-01-27 19:07 - 00071028 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:59 - 01782938 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:59 - 01537334 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:59 - 01434260 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:59 - 01425816 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:59 - 01417294 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:59 - 01382813 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:59 - 01317940 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:59 - 00372588 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:59 - 00372583 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:59 - 00371554 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:56 - 01532431 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:56 - 01456521 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:56 - 01436782 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:56 - 01411442 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:56 - 01394680 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:55 - 01549989 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:55 - 01542527 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:55 - 01477860 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:55 - 01472933 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:55 - 01387209 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:55 - 01350630 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:52 - 01622368 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:52 - 01434238 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:52 - 01319023 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:51 - 01724159 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:51 - 01676522 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:49 - 01402420 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:48 - 01635852 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:47 - 01509046 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:46 - 01493893 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:46 - 01233949 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:45 - 01410938 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:45 - 01380485 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:44 - 01664858 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:44 - 01421545 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:43 - 01494511 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:43 - 01407102 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:43 - 01336774 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:42 - 01802048 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:41 - 01391049 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-23 22:41 - 01323979 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-10-22 18:46 - 00057380 _____ () C:\Documents and Settings\PC\My Documents\snimka [email protected] 2014-11-12 13:38 - 2013-09-20 19:24 - 00000000 ____D () C:\Documents and Settings\PC\My Documents\pic 2014-11-12 13:38 - 2013-07-27 21:38 - 175923808 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-05-15 18:41 - 00030212 ____C () C:\Documents and Settings\PC\My Documents\statiqta na [email protected] 2014-11-12 13:38 - 2013-04-30 20:50 - 01975593 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-04-10 18:55 - 00470942 _____ () C:\Documents and Settings\PC\My Documents\Picture [email protected] 2014-11-12 13:38 - 2013-04-05 01:21 - 02680333 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-04-05 01:19 - 01184717 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-04-01 19:05 - 00077652 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-03-19 02:13 - 00043012 ____C () C:\Documents and Settings\PC\My Documents\pismo [email protected] 2014-11-12 13:38 - 2013-03-05 19:40 - 00072628 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-03-02 15:12 - 00000000 ____D () C:\Documents and Settings\PC\My Documents\telefon 2014-11-12 13:38 - 2013-02-26 20:01 - 00039428 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-02-15 20:03 - 00026116 ____C () C:\Documents and Settings\PC\My Documents\recepta za [email protected] 2014-11-12 13:38 - 2013-02-07 18:47 - 54731018 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-01-29 11:48 - 00031748 ____C () C:\Documents and Settings\PC\My Documents\polezni hrani za kryvna grupa [email protected] 2014-11-12 13:38 - 2013-01-29 11:40 - 00341508 ____C () C:\Documents and Settings\PC\My Documents\polezni hrani za kryvna grupa [email protected] 2014-11-12 13:38 - 2013-01-29 11:31 - 00038916 ____C () C:\Documents and Settings\PC\My Documents\polezni hrani za kryvna grupa [email protected] 2014-11-12 13:38 - 2013-01-10 20:58 - 05039853 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-01-09 22:26 - 02659848 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-01-04 18:56 - 41212222 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-01-04 18:56 - 10395302 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-01-01 23:03 - 00796370 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-01-01 23:02 - 00750312 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2013-01-01 23:02 - 00685833 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2012-11-02 03:50 - 00053252 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2012-10-30 16:56 - 02657284 ____C () C:\Documents and Settings\PC\My Documents\TEORIA NA MEJDUNARODNITE OTNOSHENIA [email protected] 2014-11-12 13:38 - 2012-10-24 00:26 - 00029700 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2012-09-03 23:09 - 02165445 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2012-09-03 23:09 - 02124677 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2012-09-03 23:09 - 01918065 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2012-09-03 23:09 - 01915464 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2012-09-03 23:08 - 02057760 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2012-09-03 23:08 - 02057278 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2012-09-03 23:07 - 02141730 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2012-08-18 23:34 - 00033796 ____C () C:\Documents and Settings\PC\My Documents\upgrade [email protected] 2014-11-12 13:38 - 2012-07-25 11:46 - 00034308 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2012-07-03 01:06 - 00036868 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2012-06-27 00:47 - 00025092 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2012-06-17 00:21 - 00050180 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2012-05-02 19:11 - 04286837 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2012-04-15 18:10 - 08666333 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2012-03-14 18:34 - 00104452 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2012-03-04 17:14 - 03373572 ____C () C:\Documents and Settings\PC\My Documents\severozapadna [email protected] 2014-11-12 13:38 - 2012-02-28 17:42 - 00212071 _____ () C:\Documents and Settings\PC\My Documents\Picture [email protected] 2014-11-12 13:38 - 2012-02-28 17:40 - 00631758 _____ () C:\Documents and Settings\PC\My Documents\Picture [email protected] 2014-11-12 13:38 - 2012-02-09 02:06 - 00025604 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2012-02-01 23:34 - 00013412 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2012-01-14 21:44 - 00663681 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2012-01-05 15:12 - 00000000 ____D () C:\Documents and Settings\PC\My Documents\recepti 2014-11-12 13:38 - 2011-07-11 00:49 - 00014852 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2011-05-17 15:09 - 00119300 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2011-04-29 15:35 - 00043636 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2011-02-04 16:57 - 00024068 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:38 - 2010-12-27 18:24 - 00999371 ____C () C:\Documents and Settings\PC\My Documents\indesit_win [email protected] 2014-11-12 13:38 - 2010-12-13 10:09 - 00022020 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:37 - 2014-07-03 15:58 - 00031236 ____C () C:\Documents and Settings\PC\My Documents\dobrich - grada na [email protected] 2014-11-12 13:37 - 2014-04-29 02:56 - 00033796 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:37 - 2014-04-12 02:54 - 108085743 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:37 - 2014-01-27 19:07 - 00058052 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:37 - 2014-01-20 01:31 - 23230174 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:37 - 2014-01-20 01:31 - 00028756 ____C () C:\Documents and Settings\PC\My Documents\PES like a [email protected] 2014-11-12 13:37 - 2013-10-30 18:26 - 00077780 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:37 - 2013-07-24 18:49 - 00099140 _____ () C:\Documents and Settings\PC\My Documents\gabcho [email protected] 2014-11-12 13:37 - 2013-07-23 19:28 - 00093108 _____ () C:\Documents and Settings\PC\My Documents\gabcho [email protected] 2014-11-12 13:37 - 2013-05-27 18:40 - 03532991 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:37 - 2013-04-05 01:39 - 00272900 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:37 - 2013-03-17 21:21 - 00088612 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:37 - 2013-03-17 21:20 - 00106656 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:37 - 2013-02-18 21:59 - 00000036 _____ () C:\Documents and Settings\PC\My Documents\New WinRAR ZIP [email protected] 2014-11-12 13:37 - 2013-02-13 20:58 - 00064772 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:37 - 2013-02-09 20:52 - 00097236 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:37 - 2013-02-01 20:45 - 00059972 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:37 - 2012-12-15 17:28 - 00853665 _____ () C:\Documents and Settings\PC\My Documents\F313FB1A-3CDA-40CE-8604-E4080C6F1118.jpg.id-1665414413_decode@india.com 2014-11-12 13:37 - 2012-12-15 17:27 - 01101303 _____ () C:\Documents and Settings\PC\My Documents\E575B831-3A8C-47F5-B29D-1AE30A3350B1.jpg.id-1665414413_decode@india.com 2014-11-12 13:37 - 2012-12-15 17:27 - 00701165 _____ () C:\Documents and Settings\PC\My Documents\EF5760D8-94AB-46C4-B23B-A45C2374AC24.jpg.id-1665414413_decode@india.com 2014-11-12 13:37 - 2012-11-26 23:09 - 00077828 ____C () C:\Documents and Settings\PC\My Documents\pesni za [email protected] 2014-11-12 13:37 - 2012-11-22 16:37 - 00580100 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:37 - 2012-11-19 20:56 - 02157233 _____ () C:\Documents and Settings\PC\My Documents\D6201D46-7D75-44CE-9DE5-42AA67026B45.jpg.id-1665414413_decode@india.com 2014-11-12 13:37 - 2012-10-10 00:27 - 43021225 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:37 - 2012-09-03 23:43 - 00025092 ____C () C:\Documents and Settings\PC\My Documents\disney pri4inata za [email protected] 2014-11-12 13:37 - 2012-07-06 19:43 - 00217621 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:37 - 2012-06-17 01:02 - 00061444 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:37 - 2012-04-06 20:20 - 14292877 ____C () C:\Documents and Settings\PC\My Documents\Dimitar [email protected] 2014-11-12 13:37 - 2012-03-27 00:43 - 00026628 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:37 - 2012-03-10 19:22 - 00025092 ____C () C:\Documents and Settings\PC\My Documents\Das letzte [email protected] 2014-11-12 13:37 - 2012-02-14 22:57 - 05504916 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:37 - 2012-02-14 22:57 - 05447750 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:37 - 2012-02-14 22:57 - 05365121 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:37 - 2012-02-14 22:57 - 05069817 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:37 - 2012-02-03 22:20 - 03007449 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:37 - 2012-02-02 21:45 - 00721266 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:37 - 2012-02-02 21:41 - 00731644 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:37 - 2011-06-10 18:42 - 01115225 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:37 - 2011-06-10 18:42 - 00910340 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:37 - 2010-09-28 21:21 - 00000000 ____D () C:\Documents and Settings\PC\My Documents\daskalo 2014-11-12 13:36 - 2014-07-27 01:42 - 00060452 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:36 - 2014-04-06 17:55 - 00574938 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:36 - 2014-02-03 00:02 - 00049140 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:36 - 2014-02-02 20:42 - 00051092 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:36 - 2013-12-04 20:36 - 00589828 ____C () C:\Documents and Settings\PC\My Documents\administrativno [email protected] 2014-11-12 13:36 - 2013-12-04 02:25 - 00035844 ____C () C:\Documents and Settings\PC\My Documents\adm. [email protected] 2014-11-12 13:36 - 2013-09-24 19:32 - 00042356 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:36 - 2013-06-18 13:08 - 00246667 _____ () C:\Documents and Settings\PC\My Documents\cef75aa2-3b29-4581-bb4a-5954a9df6b56wallpaper.jpg.id-1665414413_decode@india.com 2014-11-12 13:36 - 2013-05-21 21:38 - 00027412 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:36 - 2013-03-28 19:01 - 00054500 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:36 - 2013-03-16 18:50 - 00015172 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:36 - 2013-03-15 23:20 - 00053380 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:36 - 2013-03-13 16:42 - 00024068 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:36 - 2013-01-29 12:06 - 00049668 ____C () C:\Documents and Settings\PC\My Documents\NASLEDSTVENOST PRI KRYVNITE [email protected] 2014-11-12 13:36 - 2012-12-15 17:27 - 00793114 _____ () C:\Documents and Settings\PC\My Documents\AD3ED0E1-7D0D-416D-840D-F4F9001B6A3A.jpg.id-1665414413_decode@india.com 2014-11-12 13:36 - 2012-12-03 01:07 - 00027652 ____C () C:\Documents and Settings\PC\My Documents\Billboard Top Artists Of The [email protected] 2014-11-12 13:36 - 2012-11-19 20:59 - 02506887 _____ () C:\Documents and Settings\PC\My Documents\B16C04DF-C3D0-4C32-9CFD-6A57B10FC7C3.jpg.id-1665414413_decode@india.com 2014-11-12 13:36 - 2012-08-12 14:33 - 00026116 ____C () C:\Documents and Settings\PC\My Documents\both of [email protected] 2014-11-12 13:36 - 2012-07-04 15:56 - 00039940 ____C () C:\Documents and Settings\PC\My Documents\contract [email protected] 2014-11-12 13:36 - 2012-07-04 15:54 - 00166916 ____C () C:\Documents and Settings\PC\My Documents\contract [email protected] 2014-11-12 13:36 - 2012-07-04 15:52 - 00196100 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:36 - 2012-05-16 22:12 - 06669897 _____ () C:\Documents and Settings\PC\My Documents\NEMSKI (2)[email protected] 2014-11-12 13:36 - 2012-03-08 17:59 - 00000000 ____D () C:\Documents and Settings\PC\My Documents\bg 2014-11-12 13:36 - 2012-02-19 00:29 - 00028164 ____C () C:\Documents and Settings\PC\My Documents\Copy of Априлско въстание[email protected] 2014-11-12 13:36 - 2012-02-10 23:59 - 00026116 ____C () C:\Documents and Settings\PC\My Documents\conversations with mz 13 year old [email protected] 2014-11-12 13:36 - 2012-02-08 12:38 - 00000000 ____D () C:\Documents and Settings\PC\My Documents\mydrosti 2014-11-12 13:36 - 2012-01-10 22:00 - 00000000 ____D () C:\Documents and Settings\PC\My Documents\9v 2014-11-12 13:36 - 2011-03-14 19:34 - 00154628 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:36 - 2011-03-07 22:40 - 00985604 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:33 - 2014-09-22 00:54 - 00033284 _____ () C:\Documents and Settings\PC\Desktop\Августина се огледа отново[email protected] 2014-11-12 13:33 - 2014-09-12 21:41 - 00028164 _____ () C:\Documents and Settings\PC\Desktop\razpisi_3 [email protected] 2014-11-12 13:33 - 2014-09-12 21:39 - 00028676 _____ () C:\Documents and Settings\PC\Desktop\razpisi_2 [email protected] 2014-11-12 13:33 - 2014-07-31 18:15 - 00050180 _____ () C:\Documents and Settings\PC\Desktop\Автобиография_Жулиета Добрева[email protected] 2014-11-12 13:33 - 2014-06-15 19:53 - 00027652 ____C () C:\Documents and Settings\PC\Desktop\Молитви за успешен изпит[email protected] 2014-11-12 13:33 - 2014-04-06 14:47 - 00782340 ____C () C:\Documents and Settings\PC\Desktop\Светците лечители[email protected] 2014-11-12 13:33 - 2014-04-03 19:29 - 00026116 _____ () C:\Documents and Settings\PC\Desktop\Молитва към Светител Серафим[email protected] 2014-11-12 13:33 - 2014-02-13 21:27 - 00028164 ____C () C:\Documents and Settings\PC\Desktop\СЪБРАНИ СЪЧИНЕНИЯ_desa [email protected] 2014-11-12 13:33 - 2014-02-13 21:27 - 00028164 ____C () C:\Documents and Settings\PC\Desktop\СЪБРАНИ СЪЧИНЕНИЯ[email protected] 2014-11-12 13:33 - 2013-09-27 23:05 - 00000000 ____D () C:\Documents and Settings\PC\Desktop\juli_270913 2014-11-12 13:33 - 2013-09-20 20:11 - 00000000 ____D () C:\Documents and Settings\PC\Desktop\july_09_13 2014-11-12 13:33 - 2013-08-20 18:36 - 00024580 _____ () C:\Documents and Settings\PC\Desktop\Светът около нас е такъв[email protected] 2014-11-12 13:33 - 2013-08-18 09:52 - 00022020 ____C () C:\Documents and Settings\PC\Desktop\[email protected] 2014-11-12 13:33 - 2013-08-12 19:29 - 00000180 ____H () C:\Documents and Settings\PC\Desktop\[email protected] 2014-11-12 13:33 - 2012-05-19 19:24 - 00293380 _____ () C:\Documents and Settings\PC\Desktop\[email protected] 2014-11-12 13:32 - 2014-07-18 20:19 - 03000236 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:32 - 2014-06-23 23:30 - 02639151 _____ () C:\Documents and Settings\PC\My Documents\milan.milanov-tainite.podzemia.na.bulgaria.1 [email protected] 2014-11-12 13:32 - 2014-06-02 02:20 - 00000000 ____D () C:\Documents and Settings\PC\Desktop\GRAJDANSKO PRAVO 2014-11-12 13:32 - 2014-05-28 18:22 - 01541264 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:32 - 2014-03-13 02:35 - 00024580 ____C () C:\Documents and Settings\PC\My Documents\Like [email protected] 2014-11-12 13:32 - 2014-03-02 17:24 - 05285028 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:32 - 2014-02-03 20:11 - 00065908 _____ () C:\Documents and Settings\PC\My Documents\kevin-danielle-jonas-welcome-baby-girl-alena-rose-first-photo.jpg.id-1665414413_decode@india.com 2014-11-12 13:32 - 2014-01-20 01:31 - 02530820 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:32 - 2014-01-20 01:30 - 00190468 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:32 - 2013-11-03 21:12 - 02326588 ____C () C:\Documents and Settings\PC\Desktop\2СЂРё РєСѓСЂСЃ[email protected] 2014-11-12 13:32 - 2013-10-22 18:43 - 00077188 _____ () C:\Documents and Settings\PC\My Documents\999992_657251634306979_454413920_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:32 - 2013-10-19 21:41 - 00097796 _____ () C:\Documents and Settings\PC\My Documents\995518_388430274593615_362765035_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:32 - 2013-06-20 14:55 - 00056020 _____ () C:\Documents and Settings\PC\My Documents\971092_254475201360250_1229856415_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:32 - 2013-06-09 20:37 - 00089204 _____ () C:\Documents and Settings\PC\My Documents\984188_550228055023778_253411387_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:32 - 2013-03-16 19:02 - 00070004 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:32 - 2013-03-16 18:59 - 00096708 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:32 - 2013-02-11 19:00 - 41534066 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:32 - 2013-01-07 19:25 - 00325636 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:32 - 2012-12-18 01:50 - 00028676 ____C () C:\Documents and Settings\PC\My Documents\kraqt na one [email protected] 2014-11-12 13:32 - 2012-11-12 19:24 - 00247300 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:32 - 2012-10-28 19:26 - 00511756 ____C () C:\Documents and Settings\PC\My Documents\Mandelbaum_The Frugal [email protected] 2014-11-12 13:32 - 2012-05-30 19:05 - 00023396 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:32 - 2012-05-19 13:55 - 93712719 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:32 - 2012-03-14 23:36 - 00048132 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:32 - 2012-03-10 19:57 - 00026628 ____C () C:\Documents and Settings\PC\My Documents\Meine Strasse [email protected] 2014-11-12 13:32 - 2012-01-10 21:58 - 00000000 ____D () C:\Documents and Settings\PC\My Documents\8v 2014-11-12 13:32 - 2012-01-07 19:40 - 00036356 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:32 - 2011-05-06 20:23 - 00000000 ____D () C:\Documents and Settings\PC\My Documents\My Downloaded Video 2014-11-12 13:32 - 2010-09-21 09:59 - 00000000 ____D () C:\Documents and Settings\PC\Application Data\uTorrent 2014-11-12 13:30 - 2014-10-10 21:58 - 00227844 _____ () C:\Documents and Settings\PC\My Documents\2014-2015 - Анализ на нормативно [email protected] 2014-11-12 13:30 - 2014-09-05 16:10 - 00018180 _____ () C:\Documents and Settings\PC\My Documents\1_2_180x135[1][email protected] 2014-11-12 13:30 - 2014-09-05 16:10 - 00017860 _____ () C:\Documents and Settings\PC\My Documents\402-1297-large[1][email protected] 2014-11-12 13:30 - 2014-01-20 01:39 - 00035332 ____C () C:\Documents and Settings\PC\My Documents\8 РІСЉРїСЂРѕСЃ[email protected] 2014-11-12 13:30 - 2014-01-16 11:36 - 00052228 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:30 - 2014-01-16 11:36 - 00039428 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:30 - 2014-01-16 11:35 - 00048132 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:30 - 2014-01-16 11:34 - 00126468 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:30 - 2013-10-31 17:55 - 00027300 ____C () C:\Documents and Settings\PC\My Documents\392526_2128961159220_846825244_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:30 - 2013-10-25 18:24 - 00172537 _____ () C:\Documents and Settings\PC\My Documents\2013-2014 - Въпросник по информационно право[email protected] 2014-11-12 13:30 - 2013-10-24 17:53 - 00059700 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:30 - 2013-10-20 18:10 - 00172537 _____ () C:\Documents and Settings\PC\My Documents\2013-2014 - Р’СЉРїСЂРѕСЃРЅРёРє РїРѕ информационно право[email protected] 2014-11-12 13:30 - 2013-10-01 17:44 - 00045348 _____ () C:\Documents and Settings\PC\My Documents\603935_644973742201435_1285109110_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:30 - 2013-06-24 18:52 - 01267583 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:30 - 2013-06-24 18:24 - 00082916 _____ () C:\Documents and Settings\PC\My Documents\308312_342694605833790_1308668382_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:30 - 2013-06-09 21:19 - 00057604 _____ () C:\Documents and Settings\PC\My Documents\579302_436585216365306_1241150123_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:30 - 2013-06-09 20:41 - 00085460 _____ () C:\Documents and Settings\PC\My Documents\603157_550227991690451_1947031427_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:30 - 2013-05-29 17:25 - 00032596 _____ () C:\Documents and Settings\PC\My Documents\484754_514256855305003_1237456322_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:30 - 2013-05-27 18:39 - 00295089 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:30 - 2013-05-21 21:51 - 00083236 _____ () C:\Documents and Settings\PC\My Documents\8982_583384778340633_245556279_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:30 - 2013-05-14 21:13 - 01013446 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:30 - 2013-05-14 21:06 - 00570940 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:30 - 2013-04-28 20:40 - 00058036 _____ () C:\Documents and Settings\PC\My Documents\374635_532422706804313_1864288841_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:30 - 2013-03-30 22:17 - 00064820 _____ () C:\Documents and Settings\PC\My Documents\733800_297179347079472_1135079241_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:30 - 2013-03-30 21:48 - 00057764 _____ () C:\Documents and Settings\PC\My Documents\8538_10151527790954844_1126958557_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:30 - 2013-03-23 21:49 - 00029764 _____ () C:\Documents and Settings\PC\My Documents\578670_494591953910910_872930192_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:30 - 2013-03-21 22:43 - 00046340 _____ () C:\Documents and Settings\PC\My Documents\487871_171227736360704_498453675_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:30 - 2013-03-20 19:37 - 00066580 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:30 - 2013-03-16 19:43 - 00016516 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:30 - 2013-01-29 23:06 - 00021460 _____ () C:\Documents and Settings\PC\My Documents\533036_3435124843291_1650269738_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:30 - 2013-01-25 21:16 - 00068804 _____ () C:\Documents and Settings\PC\My Documents\296913_245443248836964_1580239347_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:30 - 2013-01-17 20:03 - 00036196 _____ () C:\Documents and Settings\PC\My Documents\486080_551457788197882_1911575100_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:30 - 2013-01-10 21:15 - 00085860 _____ () C:\Documents and Settings\PC\My Documents\562702_372744156095964_100000811478859_936583_1148558974_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:30 - 2013-01-10 21:14 - 00061284 _____ () C:\Documents and Settings\PC\My Documents\382022_500360799996695_892112939_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:30 - 2013-01-10 21:01 - 00238500 _____ () C:\Documents and Settings\PC\My Documents\538884_3915483493609_1475125881_3320037_1544041587_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:30 - 2013-01-10 20:59 - 00059604 _____ () C:\Documents and Settings\PC\My Documents\282802_3255881807157_1589066558_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:30 - 2013-01-07 19:47 - 00049156 ____C () C:\Documents and Settings\PC\My Documents\6 въпрос[email protected] 2014-11-12 13:30 - 2012-12-15 17:29 - 01513615 _____ () C:\Documents and Settings\PC\My Documents\52FF8367-7615-4454-85FE-A980FB481F4B.jpg.id-1665414413_decode@india.com 2014-11-12 13:30 - 2012-12-15 17:28 - 01232893 _____ () C:\Documents and Settings\PC\My Documents\2769F5F5-E79B-4539-A3BB-3FF439DD163B.jpg.id-1665414413_decode@india.com 2014-11-12 13:30 - 2012-12-15 17:28 - 01090703 _____ () C:\Documents and Settings\PC\My Documents\1884DAF3-597A-4E42-830C-6CEA85569D8D.jpg.id-1665414413_decode@india.com 2014-11-12 13:30 - 2012-12-15 17:28 - 00820806 _____ () C:\Documents and Settings\PC\My Documents\3A063131-E63A-40EF-A3F9-C4216EDBB2D1.jpg.id-1665414413_decode@india.com 2014-11-12 13:30 - 2012-12-15 17:28 - 00758766 _____ () C:\Documents and Settings\PC\My Documents\8206A401-3C6B-4C9A-9BBD-5CE73856B051.jpg.id-1665414413_decode@india.com 2014-11-12 13:30 - 2012-12-15 17:27 - 01051526 _____ () C:\Documents and Settings\PC\My Documents\8E9FDAFB-C0BF-4CB9-A20D-C1D587795CD9.jpg.id-1665414413_decode@india.com 2014-11-12 13:30 - 2012-12-15 17:27 - 00768324 _____ () C:\Documents and Settings\PC\My Documents\4425218B-0ADE-45F2-8B4E-EBC58EE527DB.jpg.id-1665414413_decode@india.com 2014-11-12 13:30 - 2012-12-15 17:26 - 00929879 _____ () C:\Documents and Settings\PC\My Documents\5338159F-4F41-4C0F-A193-13538D895829.jpg.id-1665414413_decode@india.com 2014-11-12 13:30 - 2012-12-15 17:26 - 00838446 _____ () C:\Documents and Settings\PC\My Documents\796DB06A-477D-4FA7-A23A-FC48BA41AD38.jpg.id-1665414413_decode@india.com 2014-11-12 13:30 - 2012-12-15 17:26 - 00770815 _____ () C:\Documents and Settings\PC\My Documents\58B3664F-6D44-4766-BE3F-5835BD2ACBCA.jpg.id-1665414413_decode@india.com 2014-11-12 13:30 - 2012-12-11 10:32 - 00105331 _____ () C:\Documents and Settings\PC\My Documents\318476_3477884805822_1792401860_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:30 - 2012-12-11 10:32 - 00102836 _____ () C:\Documents and Settings\PC\My Documents\532392_3477884165806_719254217_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:30 - 2012-11-19 21:02 - 01460227 _____ () C:\Documents and Settings\PC\My Documents\35F822E7-0213-4420-A4D3-FA905005D5C3.jpg.id-1665414413_decode@india.com 2014-11-12 13:30 - 2012-11-19 21:00 - 02021983 _____ () C:\Documents and Settings\PC\My Documents\577F9616-9972-466F-8E03-87F92E3A7C5A.jpg.id-1665414413_decode@india.com 2014-11-12 13:30 - 2012-05-31 00:18 - 01873500 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:30 - 2012-05-19 14:58 - 00000000 ____D () C:\Documents and Settings\PC\My Documents\18.05.2012 2014-11-12 13:30 - 2012-05-15 16:06 - 53976729 ____C () C:\Documents and Settings\PC\My Documents\2010-01-05 [email protected] 2014-11-12 13:30 - 2012-01-27 17:40 - 00065764 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:30 - 2010-09-21 09:21 - 00000000 __SHD () C:\Documents and Settings\All Users\DRM 2014-11-12 13:29 - 2014-07-27 01:39 - 00044356 _____ () C:\Documents and Settings\PC\My Documents\1499730_714768948536213_2031137680_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:29 - 2014-07-22 18:53 - 00026116 _____ () C:\Documents and Settings\PC\My Documents\15_Zayavlenie_izdavane_akt_narushenie.doc.id-1665414413_decode@india.com 2014-11-12 13:29 - 2014-04-07 18:58 - 00096548 _____ () C:\Documents and Settings\PC\My Documents\1378130_743750618985015_903546552_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:29 - 2014-02-13 23:04 - 00023492 _____ () C:\Documents and Settings\PC\My Documents\1506035_10152193179015606_1367699512_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:29 - 2014-02-03 00:13 - 00016836 _____ () C:\Documents and Settings\PC\My Documents\1619087_720105974674555_302935868_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:29 - 2014-01-27 19:09 - 00019300 _____ () C:\Documents and Settings\PC\My Documents\1618502_715899238440996_175134797_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:29 - 2014-01-27 19:09 - 00017284 _____ () C:\Documents and Settings\PC\My Documents\1533854_715901285107458_760432967_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:29 - 2014-01-15 22:19 - 01521051 ____C () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:29 - 2013-10-19 19:20 - 00066292 _____ () C:\Documents and Settings\PC\My Documents\1380851_655392721159537_1111546180_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:29 - 2013-10-17 18:35 - 00071172 _____ () C:\Documents and Settings\PC\My Documents\1379221_630358576984643_79333104_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:29 - 2013-10-17 18:32 - 00073252 _____ () C:\Documents and Settings\PC\My Documents\1385097_654142591284550_1386510717_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:29 - 2013-10-15 19:03 - 00046468 _____ () C:\Documents and Settings\PC\My Documents\1395348_754767477882184_579039661_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:29 - 2013-10-13 21:26 - 00079732 _____ () C:\Documents and Settings\PC\My Documents\1381860_608513175861932_1535859183_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:29 - 2013-10-10 18:58 - 00060820 _____ () C:\Documents and Settings\PC\My Documents\1381269_650093231689486_1146606596_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:29 - 2013-10-01 17:52 - 00063156 _____ () C:\Documents and Settings\PC\My Documents\1238013_631855013513308_514543655_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:29 - 2013-07-10 17:42 - 00085044 _____ () C:\Documents and Settings\PC\My Documents\1002128_599956593360805_1171709958_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:29 - 2013-07-09 20:47 - 00077012 _____ () C:\Documents and Settings\PC\My Documents\1013042_562283990484851_697733529_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:29 - 2013-06-17 15:29 - 00075908 _____ () C:\Documents and Settings\PC\My Documents\1012374_10151735385214560_1390590469_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:29 - 2013-05-21 19:14 - 00498768 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:29 - 2012-12-11 13:02 - 00086116 _____ () C:\Documents and Settings\PC\My Documents\14524_10151277655328104_1633174922_n.jpg.id-1665414413_decode@india.com 2014-11-12 13:29 - 2012-11-19 21:06 - 01623670 _____ () C:\Documents and Settings\PC\My Documents\11E7DEC5-1F1A-4B84-B363-65250A50CDFB.jpg.id-1665414413_decode@india.com 2014-11-12 13:29 - 2012-05-17 13:41 - 09398861 _____ () C:\Documents and Settings\PC\My Documents\[email protected] 2014-11-12 13:29 - 2012-05-05 20:39 - 00000000 ____D () C:\Documents and Settings\PC\My Documents\12v 2014-11-12 01:46 - 2010-09-21 09:25 - 00032428 ____N () C:\WINDOWS\SchedLgU.Txt 2014-11-12 01:46 - 2010-09-21 09:25 - 00000278 ___SH () C:\Documents and Settings\PC\ntuser.ini 2014-11-11 23:10 - 2013-03-05 23:10 - 00000408 _____ () C:\WINDOWS\Tasks\At1.job 2014-11-11 17:44 - 2008-04-14 14:00 - 00002206 _____ () C:\WINDOWS\system32\wpa.dbl 2014-11-03 18:06 - 2011-07-25 00:52 - 00036188 ____C () C:\Documents and Settings\PC\Desktop\New Text Document (2).txt 2014-11-03 16:50 - 2014-09-01 20:49 - 00000000 ____D () C:\Documents and Settings\PC\Local Settings\Application Data\Adobe 2014-11-03 16:50 - 2012-04-01 22:39 - 00701104 ____C (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe 2014-11-03 16:50 - 2011-05-14 07:34 - 00071344 ____C (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl 2014-10-30 17:36 - 2010-10-08 20:29 - 00000000 __SHD () C:\WINDOWS\ftpcache 2014-10-30 01:11 - 2010-09-25 13:41 - 00000000 ____D () C:\Program Files\Virtual Piano 2014-10-27 14:01 - 2012-04-30 21:57 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-10-27 14:00 - 2014-10-09 19:31 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Trusted Publisher 2014-10-27 14:00 - 2014-02-15 21:01 - 00000000 ____D () C:\Documents and Settings\PC\Application Data\Java 2014-10-27 14:00 - 2010-09-21 12:07 - 00000000 ____D () C:\WINDOWS\addins 2014-10-27 13:56 - 2011-11-13 16:01 - 00000000 ____D () C:\Program Files\SweetIM 2014-10-27 13:55 - 2014-10-09 19:30 - 00000000 ____D () C:\Program Files\YoutubeAdeBliocke 2014-10-27 13:55 - 2014-10-09 19:30 - 00000000 ____D () C:\Program Files\GoSaavue 2014-10-27 13:55 - 2014-10-09 19:30 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\YoutubeAdeBliocke 2014-10-27 13:55 - 2014-10-09 19:30 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\GoSaavue 2014-10-27 13:55 - 2014-07-24 19:47 - 00000000 ____D () C:\Documents and Settings\PC\Application Data\Faim 2014-10-27 13:55 - 2014-07-24 17:20 - 00000000 ____D () C:\Documents and Settings\PC\Application Data\Acmi 2014-10-27 13:55 - 2014-07-11 19:12 - 00000000 ____D () C:\Documents and Settings\PC\Application Data\Zeky 2014-10-27 13:55 - 2014-07-01 14:15 - 00000000 ____D () C:\Documents and Settings\PC\Application Data\Yvqa 2014-10-27 13:55 - 2014-06-19 15:02 - 00000000 ____D () C:\Documents and Settings\PC\Application Data\Epuqxe 2014-10-27 13:55 - 2014-02-04 19:01 - 00000000 ____D () C:\Documents and Settings\PC\Application Data\Inbumu 2014-10-27 13:55 - 2013-03-07 13:57 - 00000000 ____D () C:\Program Files\BS_Player 2014-10-27 13:55 - 2012-03-27 16:07 - 00000000 ____D () C:\Program Files\FreeSoundRecorder 2014-10-27 13:55 - 2010-09-21 09:20 - 00000000 ____D () C:\Program Files\Movie Maker 2014-10-27 00:37 - 2011-07-30 23:08 - 00000000 ____D () C:\Program Files\Google 2014-10-27 00:36 - 2011-07-30 23:09 - 00000000 ____D () C:\Documents and Settings\LocalService\Local Settings\Application Data\Google 2014-10-23 11:29 - 2014-10-09 19:29 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\c5e40736dbd8493d 2014-10-21 01:49 - 2010-09-21 10:01 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Temp 2014-10-19 01:33 - 2014-04-29 02:56 - 00034304 ___HC () C:\Documents and Settings\PC\My Documents\~WRL0006.tmp 2014-10-15 12:04 - 2010-12-19 00:23 - 00000000 ____D () C:\Program Files\Adobe 2014-10-15 12:04 - 2010-09-21 09:55 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-10-15 12:04 - 2010-09-21 09:55 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Adobe

Files to move or delete: ==================== C:\Windows\Tasks\At1.job Some content of TEMP: ==================== C:\Documents and Settings\PC\Local Settings\Temp\OEMCFG.dll C:\Documents and Settings\PC\Local Settings\Temp\OEMDM.dll C:\Documents and Settings\PC\Local Settings\Temp\OEMIMG.dll C:\Documents and Settings\PC\Local Settings\Temp\OEMTW.dll C:\Documents and Settings\PC\Local Settings\Temp\OEMUI.dll C:\Documents and Settings\PC\Local Settings\Temp\SkypeSetup.exe C:\Documents and Settings\PC\Local Settings\Temp\Ssdevm.dll C:\Documents and Settings\PC\Local Settings\Temp\Ssuiext.dll C:\Documents and Settings\PC\Local Settings\Temp\Ssusbpn.dll C:\Documents and Settings\PC\Local Settings\Temp\Sswiadrv.dll C:\Documents and Settings\PC\Local Settings\Temp\Tsu-134C.dll C:\Documents and Settings\PC\Local Settings\Temp\WIAEH.dll C:\Documents and Settings\PC\Local Settings\Temp\WIAIPH.dll C:\Documents and Settings\PC\Local Settings\Temp\WIASTIIO.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed ==================== End Of Log ============================ Additional scan result of Farbar Recovery Scan Tool (x86) Version: 10-11-2014 Ran by PC at 2014-11-12 15:49:33 Running from C:\Documents and Settings\PC\Local Settings\Temporary Internet Files\Content.IE5\RHBVJXCV Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 15 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 15.0.0.189 - Adobe Systems Incorporated) Adobe Flash Player 15 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated) Adobe Reader XI (11.0.08) (HKLM\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated) AKVIS Sketch (HKLM\...\{AC0BAA05-28E6-4911-B3F3-0AE2EB0F54A1}) (Version: 11.0.2148.7184 - AKVIS) ALLConverter PRO 1.1 (HKLM\...\{9370105C-71BB-4FF9-A85B-36D79B95457A}_is1) (Version: - ALLCinema, Inc.) AP Tuner 3.08 (HKLM\...\AP Tuner 3.08) (Version: - ) Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver (HKLM\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.23 - Atheros Communications Inc.) Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.) BS Player Toolbar (HKLM\...\BS_Player Toolbar) (Version: 6.11.0.36 - BS Player) <==== ATTENTION BS.Player FREE (HKLM\...\BSPlayerf) (Version: 2.64.1073 - AB Team, d.o.o.) BulgarianPhonetic XP by G. Atanasov (HKLM\...\Bulgarian(Phonetic)) (Version: - ) CCleaner (HKLM\...\CCleaner) (Version: 4.19 - Piriform) CyberLink PowerDVD 10 (HKLM\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.1516 - CyberLink Corp.) Disneynature - Oceans Screen Saver (HKLM\...\Disneynature - Oceans) (Version: - ) Fhotoroom HDR 3.0.4 (HKLM\...\{95174FE5-D61C-48F1-B427-9F9F8DC416C7}) (Version: 3.0.4 - SCI Fhotoroom) Foxit PDF Editor (HKLM\...\Foxit PDF Editor) (Version: 2.2.1.1119 - Foxit Corporation) Free Sound Recorder v9.3.1 (HKLM\...\Free Sound Recorder_is1) (Version: - Copyright© 2005-2012 FreeSoundRecorder Technologies, Inc.) FreeSoundRecorder Toolbar (HKLM\...\FreeSoundRecorder Toolbar) (Version: 6.13.3.505 - FreeSoundRecorder) <==== ATTENTION Fun2Saavei (HKLM\...\{9D9BEFAE-9499-F52B-6CC4-94818CCC2AB5}) (Version: - "") Gaberoff Koral German Dictionary 1.01 (HKLM\...\Gaberoff Koral German Dictionary 1.01) (Version: 1.01 - Gaberoff KoralSoft ) Google Chrome (HKLM\...\Google Chrome) (Version: 38.0.2125.101 - Google Inc.) Google Toolbar for Internet Explorer (HKLM\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.) Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden Google Update Helper (Version: 1.3.24.15 - Google Inc.) Hidden Guitar Explorer 1.0 (HKLM\...\Guitar Explorer 1.0) (Version: - ) Hama Webcam AC-155 (HKLM\...\{ECD03DA7-5952-406A-8156-5F0C93618D1F}) (Version: Hama Webcam AC-155 - Sonix) Intel® Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: - Intel Corporation) K-Lite Codec Pack 6.3.0 (Full) (HKLM\...\KLiteCodecPack_is1) (Version: 6.3.0 - ) Malwarebytes Anti-Malware version 2.0.3.1025 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.3.1025 - Malwarebytes Corporation) Mario Forever (HKLM\...\Mario Forever) (Version: - ) McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.) Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\...\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation) Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\...\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation) Microsoft Download Manager (HKLM\...\{654977DB-0001-0002-0001-EABD228DDE8B}) (Version: 1.2.1 - Microsoft Corporation) Microsoft Office Professional Edition 2003 (HKLM\...\{90110409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.7969.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft User-Mode Driver Framework Feature Pack 1.0 (HKLM\...\Wudf01000) (Version: - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio Tools for Applications 2.0 - ENU (HKLM\...\{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual Studio Tools for Applications 2.0 Runtime (HKLM\...\{299C0434-4F4E-341F-A916-4E07AEB35E79}) (Version: 9.0.30729 - Microsoft Corporation) Mozilla Firefox 33.0.1 (x86 bg) (HKLM\...\Mozilla Firefox 33.0.1 (x86 bg)) (Version: 33.0.1 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 30.0 - Mozilla) MSVCRT Redists (Version: 1.0 - Sony Creative Software Inc.) Hidden Nero 6 Ultra Edition (HKLM\...\Nero - Burning Rom!UninstallKey) (Version: - ) Nuclear Coffee - VideoGet (HKLM\...\VideoGet_is1) (Version: - Nuclear Coffee) OpenSubtitlesPlayer V4.X (HKLM\...\OpenSubtitlesPlayer_is1) (Version: - ALLCinema Ltd.) Philips Flat Panel Adjust (HKLM\...\{23430AE3-6FFF-47CF-B7E7-1552FC61DF39}) (Version: - ) Photo Effect Studio 5.56 (HKLM\...\Photo Effect Studio_is1) (Version: - LiangZhu Software, Inc.) Picture Collage Maker Pro 3.2.6 (HKLM\...\{6D308A90-6C14-4A02-9B04-CB0EF17894A9}_is1) (Version: - PearlMountain Technology Co., Ltd) QuickTime 7 (HKLM\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 5.10.0.5845 - Realtek Semiconductor Corp.) Revo Uninstaller 1.95 (HKLM\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) SA Dictionary 2005 T2 (HKLM\...\SA Dictionary 2005 T2) (Version: - ) Skype Click to Call (HKLM\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.13.13771 - Skype Technologies S.A.) Skype™ 6.18 (HKLM\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.18.106 - Skype Technologies S.A.) Subtitle Workshop 2.51 (HKLM\...\SubtitleWorkshop) (Version: - ) SweetIM for Messenger 3.6 (HKLM\...\{A81A974F-8A22-43E6-9243-5198FF758DA1}) (Version: 3.6.0002 - SweetIM Technologies Ltd.) <==== ATTENTION SweetIM Toolbar for Internet Explorer 4.2 (HKLM\...\{A7BC02AF-1128-4A31-BCF8-1A3EE803D3B3}) (Version: 4.2.0004 - SweetIM Technologies Ltd.) <==== ATTENTION Swift 3D v6.00 (HKLM\...\{65EEA363-8D47-4268-BBCE-85CD54ACDC15}) (Version: 6.00.0000 - Electric Rain, Inc.) UpdateMyDrivers (HKLM\...\UpdateMyDrivers) (Version: 9.0.0.5 - SmartTweak Software) UpdateMyDrivers (Version: 9.0.0.5 - SmartTweak Software) Hidden USB Video Camera Driver v1.10 (HKLM\...\{926B578B-505F-4820-A62D-088E1124FED4}) (Version: 1.1.00 - Generic) Video Download Converter version 1.0.0.0 (HKLM\...\VDC_is1) (Version: 1.0.0.0 - ) <==== ATTENTION Virtual DJ - Atomix Productions (HKLM\...\Virtual DJ - Atomix Productions) (Version: - ) Virtual Piano 2.5 (HKLM\...\Virtual Piano_is1) (Version: - The CyberBrothers) VLC media player 0.9.9 (HKLM\...\VLC media player) (Version: 0.9.9 - VideoLAN Team) WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden Windows Internet Explorer 8 (HKLM\...\ie8) (Version: 20090308.140743 - Microsoft Corporation) Windows Live ID Sign-in Assistant (HKLM\...\{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}) (Version: 6.500.3165.0 - Microsoft Corporation) Windows Media Format 11 runtime (HKLM\...\Windows Media Format Runtime) (Version: - ) Windows Media Player Firefox Plugin (HKLM\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp) WinRAR archiver (HKLM\...\WinRAR archiver) (Version: - ) Xerox WorkCentre 3119 Series Driver Uninstall (HKLM\...\Xerox WorkCentre 3119 Series) (Version: - ) XML Paper Specification Shared Components Pack 1.0 (Version: - Microsoft Corporation) Hidden ZET 9 Lite 2.20 (HKLM\...\ZET 9 Lite 2.20) (Version: 2.20 - ZET Astrology Software) История на България - електронно издание (HKLM\...\HEncyclopedia) (Version: - ) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2008-04-14 14:00 - 2010-11-03 09:37 - 00001814 ___RA C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 localhost 127.0.0.1 nero.com 127.0.0.1 www.nero.com 127.0.0.1 my.nero.com 127.0.0.1 support.nero.com 127.0.0.1 registernero.com 127.0.0.1 www.registernero.com 127.0.0.1 www.nero.com/rus/index.html 127.0.0.1 www.nero.com/enu/support-nero8.html 127.0.0.1 secure.nero.com/us/secure.asp 127.0.0.1 www.nero.com/rus/support.html 127.0.0.1 www.nero.com/rus/support-customer-service-product-registration.html 127.0.0.1 www.nero.com/rus/store-upgrade-center.html 127.0.0.1 www.nero.com/rus/store-volume-licensing.html 127.0.0.1 www.nero.com/eng/privacy.html 127.0.0.1 www.nero.com/eng/support.html?NeroSID=392cba06859c3dcd87b47525e97a3b80 127.0.0.1 www.nero.com/eng/support-customer-service-product-registration.html?NeroSID=392cba06859c3dcd87b47525e97a3b80 127.0.0.1 www.nero.com/eng/index.html 127.0.0.1 www.nero.com/eng/store-upgrade-center.html?NeroSID=392cba06859c3dcd87b47525e97a3b80 127.0.0.1 www.nero.com/eng/store-upgrade-center.html?sa=X?oi=smap?resnum=1?ct=result?cd=6?usg=AFQjCNFRzc_q0umeKlIj7pPYNNBYCFbXkg 127.0.0.1 [email protected] 127.0.0.1 [email protected] ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\At1.job => C:\DOCUME~1\PC\APPLIC~1\Funmoods\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2010-09-22 18:05 - 2006-02-06 05:24 - 00049152 _____ () C:\WINDOWS\system32\sswiadrv.dll 2010-09-22 18:05 - 2006-02-06 03:05 - 00049152 _____ () C:\WINDOWS\system32\WIASTIIO.dll 2010-09-22 18:05 - 2006-02-01 02:11 - 00086016 _____ () C:\WINDOWS\system32\WIAEH.dll 2010-09-22 18:05 - 2006-02-01 02:12 - 00094208 _____ () C:\WINDOWS\system32\WIAIPH.dll 2010-09-21 09:56 - 2009-01-11 00:15 - 00159744 _____ () C:\Program Files\K-Lite Codec Pack\Filters\Haali\mmfinfo.dll 2010-09-21 09:56 - 2010-05-19 22:55 - 00024576 _____ () C:\Program Files\K-Lite Codec Pack\Filters\Haali\mkunicode.dll 2010-09-21 09:55 - 2006-09-13 23:20 - 00126464 _____ () C:\Program Files\WinRAR\rarext.dll 2010-09-21 09:59 - 2010-09-21 09:59 - 00094636 _____ () C:\WINDOWS\dropcpyr.dll 2008-04-14 14:00 - 2008-04-14 14:00 - 00014336 _____ () C:\WINDOWS\system32\msdmo.dll 2008-04-14 14:00 - 2008-04-14 14:00 - 00059904 _____ () C:\WINDOWS\system32\devenum.dll 2013-09-05 22:23 - 2006-11-13 13:01 - 00436992 _____ () C:\Program Files\Hama\Hama Webcam Suite\Magic-i Visual Effects\fpxlib.dll 2013-09-05 22:23 - 2007-05-18 13:06 - 00805632 _____ () C:\Program Files\Hama\Hama Webcam Suite\Magic-i Visual Effects\ColorTrack.dll 2013-09-05 22:23 - 2007-01-25 15:22 - 00056064 _____ () C:\Program Files\Hama\Hama Webcam Suite\Magic-i Visual Effects\uMSGHook.dll 2013-09-05 22:23 - 2006-11-13 13:01 - 00146176 _____ () C:\Program Files\Hama\Hama Webcam Suite\Magic-i Visual Effects\AglSwf.dll 2013-09-05 22:23 - 2006-11-13 13:01 - 00252672 _____ () C:\Program Files\Hama\Hama Webcam Suite\Magic-i Visual Effects\kgl.dll 2013-09-05 22:23 - 2007-03-16 11:44 - 00256768 _____ () C:\Program Files\Hama\Hama Webcam Suite\Magic-i Visual Effects\distort.dll 2014-10-23 21:19 - 2014-10-23 21:19 - 00046592 _____ () C:\Program Files\CCleaner\lang\lang-1026.dll 2014-04-14 21:41 - 2014-04-14 21:41 - 00039192 _____ () C:\Program Files\CCleaner\branding.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\Temp:054B9966 AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\Temp:F8B88761 ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) ========================= Accounts: ========================== Administrator (S-1-5-21-484763869-179605362-1417001333-500 - Administrator - Enabled) Guest (S-1-5-21-484763869-179605362-1417001333-501 - Limited - Disabled) HelpAssistant (S-1-5-21-484763869-179605362-1417001333-1000 - Limited - Disabled) PC (S-1-5-21-484763869-179605362-1417001333-1003 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\PC SUPPORT_388945a0 (S-1-5-21-484763869-179605362-1417001333-1002 - Limited - Disabled) ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (11/12/2014 03:44:36 PM) (Source: MsiInstaller) (EventID: 11308) (User: PC-698796166478) Description: Product: Microsoft Office Professional Edition 2003 -- Error 1308. Setup cannot find the required file D:\Install\Microsoft Office 2003\FILES\APPDATA\MS\OFFICE\DATA\OPA11.BAK. Check your connection to the network, or CD-ROM drive. For other potential solutions to this problem, see C:\Program Files\Microsoft Office\OFFICE11\1033\SETUP.CHM. Error: (11/12/2014 03:44:36 PM) (Source: MsiInstaller) (EventID: 11308) (User: PC-698796166478) Description: Product: Microsoft Office Professional Edition 2003 -- Error 1308. Setup cannot find the required file D:\Install\Microsoft Office 2003\FILES\APPDATA\MS\OFFICE\DATA\OPA11.BAK. Check your connection to the network, or CD-ROM drive. For other potential solutions to this problem, see C:\Program Files\Microsoft Office\OFFICE11\1033\SETUP.CHM. Error: (11/12/2014 03:33:31 PM) (Source: Application Hang) (EventID: 1001) (User: ) Description: Fault bucket 1180947459. Error: (11/12/2014 03:33:29 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Hanging application iexplore.exe, version 8.0.6001.18702, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error: (11/12/2014 02:32:15 PM) (Source: Application Error) (EventID: 1001) (User: ) Description: Fault bucket 527563823. The Wep key exchange did not result in a secure connection setup after 802.1x authentication. The current setting has been marked as failed and the Wireless connection will be disconnected. Error: (11/12/2014 02:31:35 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application iexplore.exe, version 8.0.6001.18702, faulting module unknown, version 0.0.0.0, fault address 0xf9c96339. Processing media-specific event for [iexplore.exe!ws!] Error: (11/12/2014 01:44:30 PM) (Source: Application Error) (EventID: 1001) (User: ) Description: Fault bucket 637745343. The Wep key exchange did not result in a secure connection setup after 802.1x authentication. The current setting has been marked as failed and the Wireless connection will be disconnected. Error: (11/12/2014 01:44:05 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application disney~1.scr, version 3.5.4.0, faulting module flash32_15_0_0_189.ocx, version 15.0.0.189, fault address 0x001ff74b. Processing media-specific event for [disney~1.scr!ws!] Error: (11/12/2014 00:12:32 AM) (Source: Application Hang) (EventID: 1001) (User: ) Description: Fault bucket 1180947459. Error: (11/12/2014 00:12:14 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Hanging application iexplore.exe, version 8.0.6001.18702, hang module hungapp, version 0.0.0.0, hang address 0x00000000. System errors: ============= Error: (11/12/2014 01:50:41 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Installer Config service terminated with the following error: %%2 Error: (11/12/2014 01:50:41 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Task Image service terminated with the following error: %%2 Error: (11/12/2014 01:50:41 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Support Config service terminated with the following error: %%126 Error: (11/12/2014 01:50:41 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Monitor Support service terminated with the following error: %%2 Error: (11/12/2014 01:50:41 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The fboyovdmq service terminated with the following error: %%2 Error: (11/12/2014 01:50:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Услуга Google Update (gupdate) service failed to start due to the following error: %%2 Error: (11/12/2014 01:50:41 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Config Support service terminated with the following error: %%2 Error: (11/12/2014 01:23:58 PM) (Source: DCOM) (EventID: 10000) (User: PC-698796166478) Description: Unable to start a DCOM Server: {ABC01078-F197-4B0B-ADBC-CFE684B39C82}. The error: "%{ABC01078-F197-4B0B-ADBC-CFE684B39C82}" Happened while starting this command: "C:\Program Files\Google\Update\1.3.24.15\GoogleUpdateOnDemand.exe" -Embedding Error: (11/12/2014 01:23:14 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Installer Config service terminated with the following error: %%2 Error: (11/12/2014 01:23:14 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Task Image service terminated with the following error: %%2 Microsoft Office Sessions: ========================= Error: (11/12/2014 03:44:36 PM) (Source: MsiInstaller) (EventID: 11308) (User: PC-698796166478) Description: Product: Microsoft Office Professional Edition 2003 -- Error 1308. Setup cannot find the required file D:\Install\Microsoft Office 2003\FILES\APPDATA\MS\OFFICE\DATA\OPA11.BAK. Check your connection to the network, or CD-ROM drive. For other potential solutions to this problem, see C:\Program Files\Microsoft Office\OFFICE11\1033\SETUP.CHM.(NULL)(NULL)(NULL)(NULL) Error: (11/12/2014 03:44:36 PM) (Source: MsiInstaller) (EventID: 11308) (User: PC-698796166478) Description: Product: Microsoft Office Professional Edition 2003 -- Error 1308. Setup cannot find the required file D:\Install\Microsoft Office 2003\FILES\APPDATA\MS\OFFICE\DATA\OPA11.BAK. Check your connection to the network, or CD-ROM drive. For other potential solutions to this problem, see C:\Program Files\Microsoft Office\OFFICE11\1033\SETUP.CHM.(NULL)(NULL)(NULL)(NULL) Error: (11/12/2014 03:33:31 PM) (Source: Application Hang) (EventID: 1001) (User: ) Description: 1180947459 Error: (11/12/2014 03:33:29 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: iexplore.exe8.0.6001.18702hungapp0.0.0.000000000 Error: (11/12/2014 02:32:15 PM) (Source: Application Error) (EventID: 1001) (User: ) Description: 527563823 Error: (11/12/2014 02:31:35 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: iexplore.exe8.0.6001.18702unknown0.0.0.0f9c96339 Error: (11/12/2014 01:44:30 PM) (Source: Application Error) (EventID: 1001) (User: ) Description: 637745343 Error: (11/12/2014 01:44:05 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: disney~1.scr3.5.4.0flash32_15_0_0_189.ocx15.0.0.189001ff74b Error: (11/12/2014 00:12:32 AM) (Source: Application Hang) (EventID: 1001) (User: ) Description: 1180947459 Error: (11/12/2014 00:12:14 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: iexplore.exe8.0.6001.18702hungapp0.0.0.000000000 ==================== Memory info =========================== Processor: Intel® Celeron® CPU E3300 @ 2.50GHz Percentage of memory in use: 60% Total physical RAM: 2037.42 MB Available physical RAM: 799.99 MB Total Pagefile: 3930.39 MB Available Pagefile: 2895.19 MB Total Virtual: 2047.88 MB Available Virtual: 1919.97 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:48.83 GB) (Free:3.69 GB) NTFS ==>[Drive with boot components (Windows XP)] Drive d: () (Fixed) (Total:208.46 GB) (Free:0.15 GB) NTFS Drive e: () (Fixed) (Total:208.46 GB) (Free:1.76 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows XP) (Size: 465.8 GB) (Disk ID: AC71AC71) Partition 1: (Active) - (Size=48.8 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=416.9 GB) - (Type=OF Extended) ==================== End Of Log ============================

това е всичко. сега, предполагам, разбирате защо първоначално не го публикувах тук, а го прикачих. надявам се да е от някаква помощ и силно се извинявам, ако съм постнала нещо излишно! отново благодарности!

Мисля, че е най-добре да прикачите и двала лога, защото има грешка при копирането им и създаването на скрипт в този им вид би било опасно и безполезно начинание.

Благодаря! :)

Здравейте,

 

Първо моля деинсталирайте следните две програми от Контролния панел:

 

BS Player Toolbar

FreeSoundRecorder Toolbar

SweetIM for Messenger 3.6
SweetIM Toolbar for Internet Explorer 4.2

Video Download Converter version 1.0.0.0

 

Да опитаме да почистим поне видимите неща:

 

Изтеглете edit-text.giffixlist.txt и го запазете в папката от която стартирахте FRST.exe.
Стартирайте FRST.exe и натиснете бутона Fix веднъж!
След като приключи, ако ви поиска рестарт - съгласете се. След рестарта публикувайте лог файла - fixlog.txt, който ще се създаде след работата на програмата.
 
Внимание: Скрипта е създаден за текущата система. Да не се ползва за други системи с подобни проблеми!

 

 

Поздрави!

  • Автор

Не знам към мен ли беше насочен последният пост, но така предположих и изпълних чинно всичко, макар и с големи усилия да деинсталирах програмите, добре, че имам Revo Uninstaller. Но проблемът тук дойде от друго място. След клик върху Fix: "No fixlist.txt found. The fixlist.txt should be in the folder/directory the tool is located." При положение, че е в папката, както сте ме инструктирали. Не знам къде бъркам, много се извинявам, но може ли да ми посочите? Както казах, не съм най-вещият човек в тази област... Извинения и поредни благодарности!


Извинявам се, открих си грешката, всичко мина нормално, пращам fixlog файла. А сега какво? :)

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 10-11-2014
Ran by PC at 2014-11-12 22:42:46 Run:1
Running from C:\Documents and Settings\PC\Desktop
Loaded Profile: PC (Available profiles: PC)
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
start
ClosrProcesses:
IFEO\bitguard.exe: [Debugger] tasklist.exe
IFEO\bprotect.exe: [Debugger] tasklist.exe
IFEO\bpsvc.exe: [Debugger] tasklist.exe
IFEO\browserdefender.exe: [Debugger] tasklist.exe
IFEO\browserprotect.exe: [Debugger] tasklist.exe
IFEO\browsersafeguard.exe: [Debugger] tasklist.exe
IFEO\dprotectsvc.exe: [Debugger] tasklist.exe
IFEO\jumpflip: [Debugger] tasklist.exe
IFEO\protectedsearch.exe: [Debugger] tasklist.exe
IFEO\searchinstaller.exe: [Debugger] tasklist.exe
IFEO\searchprotection.exe: [Debugger] tasklist.exe
IFEO\searchprotector.exe: [Debugger] tasklist.exe
IFEO\searchsettings.exe: [Debugger] tasklist.exe
IFEO\searchsettings64.exe: [Debugger] tasklist.exe
IFEO\snapdo.exe: [Debugger] tasklist.exe
IFEO\stinst32.exe: [Debugger] tasklist.exe
IFEO\stinst64.exe: [Debugger] tasklist.exe
IFEO\umbrella.exe: [Debugger] tasklist.exe
IFEO\utiljumpflip.exe: [Debugger] tasklist.exe
IFEO\volaro: [Debugger] tasklist.exe
IFEO\vonteera: [Debugger] tasklist.exe
IFEO\websteroids.exe: [Debugger] tasklist.exe
IFEO\websteroidsservice.exe: [Debugger] tasklist.exe
C:\Documents and Settings\PC\Start Menu\Programs\Startup\bytor.bmp ()
C:\Documents and Settings\PC\Start Menu\Programs\Startup\wlort.dll
HKLM\...\AppCertDlls: [x64] -> c:\program files\browser tab search by ask\safetynut\x64\safetycrt.dll
c:\program files\browser tab search by ask
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds&ts=1406827062&from=sfpsnew1&uid=WDCXWD5000AAKS-22V1A0_WD-WCAWF709257892578&q={searchTerms}
URLSearchHook: HKCU - BS Player ControlBar Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\prxtbBS_0.dll (Conduit Ltd.)
C:\Program Files\BS_Player\prxtbBS_0.dll
SearchScopes: HKLM - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=nv1&chnl=nv1&cd=2XzuyEtN2Y1L1QzuyC0C0FtDyEzy0AzytCyEtA0B0AtDtCyCtN0D0Tzu0CtBtAyCtN1L2XzutBtFtCtFtCtFtAtCtB&cr=190592590
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} URL = http://dts.search.ask.com/sr?src=ieb&gct=ds&appid=210&systemid=488&v=a12834-348&apn_uid=8606670471324815&apn_dtid=TCH001&o=APN11459&apn_ptnrs=AG1&q={searchTerms}
SearchScopes: HKLM - {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL = http://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=AgnUpd&cd=2XzuyEtN2Y1L1QzuyC0C0FtDyEzy0AzytCyEtA0B0AtDtCyCtN0D0Tzu0CyEtAzztN1L2XzutN1L1Czu&cr=576868586&ir=
SearchScopes: HKLM - {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^HJ^xdm007^YY^bg&si=CO7Oreaxi7UCFUW_zAodfU8AIg&ptb=6CC997F7-A728-4A7F-8E15-1A41887E329B&ind=2013012810&n=77fc234a&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKCU - {1F096B29-E9DA-4D64-8D63-936BE7762CC5} URL = http://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=3cb8a0160000000000006cf049a9143b&tlver=1.4.19.19&affID=19579
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} URL = http://dts.search.ask.com/sr?src=ieb&gct=ds&appid=210&systemid=488&v=a12834-348&apn_uid=8606670471324815&apn_dtid=TCH001&o=APN11459&apn_ptnrs=AG1&q={searchTerms}
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1750559&CUI=UN33889770456943066&UM=1
SearchScopes: HKCU - {C2367743-5BC1-4816-8307-4172465CAC6C} URL = http://websearch.ask.com/redirect?client=ie&tb=OSUB&o=100000079&src=crm&q={searchTerms}&locale=en_EU&apn_ptnrs=V6&apn_dtid=YYYYYYYYBG&apn_uid=9c84e4a2-05d3-4cbd-bbbc-e2e938d7738f&apn_sauid=B7C812BC-C2B1-4310-815C-774336BAC174&
SearchScopes: HKCU - {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^HJ^xdm007^YY^bg&si=CO7Oreaxi7UCFUW_zAodfU8AIg&ptb=6CC997F7-A728-4A7F-8E15-1A41887E329B&ind=2013012810&n=77fc234a&psa=&st=sb&searchfor={searchTerms}
BHO: BS Player ControlBar Toolbar -> {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} -> C:\Program Files\BS_Player\prxtbBS_0.dll (Conduit Ltd.)
Toolbar: HKLM - No Name - {98889811-442D-49dd-99D7-DC866BE87DBC} -  No File
Toolbar: HKLM - BS Player ControlBar Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\prxtbBS_0.dll (Conduit Ltd.)
FF DefaultSearchEngine: WebSearch
FF DefaultSearchEngine,S: WebSearch
FF DefaultSearchUrl: hxxp://websearch.allsearches.info/?pid=3400&r=2014/10/09&hid=10091285608446518072&lg=EN&cc=BG&unqvl=64&l=1&q=
FF SearchEngineOrder.1: WebSearch
FF SearchEngineOrder.1,S: WebSearch
FF SearchEngineOrder.3: Bing
FF SelectedSearchEngine: WebSearch
FF SelectedSearchEngine,S: WebSearch
FF Homepage: hxxp://websearch.allsearches.info/?pid=3400&r=2014/10/09&hid=10091285608446518072&lg=EN&cc=BG&unqvl=64
FF SearchPlugin: C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\searchplugins\Ask.xml
FF SearchPlugin: C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\searchplugins\askcom.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\Ask.xml
FF Extension: ADDICT-THING - C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\Extensions\[email protected] [2012-08-21]
FF Extension: GGouSaave - C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\Extensions\[email protected] [2014-10-09]
FF Extension: DealEXporeess - C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\Extensions\[email protected] [2014-10-16]
FF Extension: GoSSave - C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\Extensions\[email protected] [2014-10-24]
FF Extension: YoutubeAdeBliocke - C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\Extensions\[email protected] [2014-10-09]
FF Extension: FUn2Save - C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\Extensions\[email protected] [2014-10-24]
FF Extension: OneClickDownloader - C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\Extensions\[email protected] [2013-01-31]
FF Extension: Babylon OCR - C:\Program Files\Mozilla Firefox\extensions\[email protected] [2014-10-27]
FF Extension: No Name - C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\extensions\[email protected] [Not Found]
FF Extension: No Name - C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\extensions\[email protected] [Not Found]
FF Extension: No Name - C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\extensions\{32b29df0-2237-4370-9a29-37cebb730e9b} [Not Found]
FF Extension: No Name - [email protected] [Not Found]
FF Extension: No Name - [email protected] [Not Found]
FF Extension: No Name - {32b29df0-2237-4370-9a29-37cebb730e9b} [Not Found]
CHR Extension: (GGouSaave) - C:\Documents and Settings\PC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pefdgighdfaaojjebinjleeinndfdfij [2014-10-09]
S2 apkcfzpt; C:\WINDOWS\system32\svchost.exe [14336 2008-04-14] (Microsoft Corporation)
S2 gfmiban; C:\WINDOWS\system32\svchost.exe [14336 2008-04-14] (Microsoft Corporation)
S2 hhbso; C:\WINDOWS\system32\svchost.exe [14336 2008-04-14] (Microsoft Corporation)
S2 sdogua; C:\WINDOWS\system32\svchost.exe [14336 2008-04-14] (Microsoft Corporation)
S2 snmibdk; C:\WINDOWS\system32\svchost.exe [14336 2008-04-14] (Microsoft Corporation)
S2 hwvlyh; C:\Program Files\Movie Maker\zwokur.dll [X]
C:\Program Files\Movie Maker\zwokur.dll
NETSVC: apkcfzpt -> No Registry Path.
NETSVC: gfmiban -> No Registry Path.
NETSVC: snmibdk -> No Registry Path.
NETSVC: hhbso -> No Registry Path.
NETSVC: sdogua -> No Registry Path.
NETSVC: hwvlyh -> C:\Program Files\Movie Maker\zwokur.dll ==> No File.
2014-11-12 13:40 - 2014-11-12 13:40 - 00401942 _____ () C:\Documents and Settings\PC\Application Data\bytor.bmp
2014-10-23 11:28 - 2014-10-23 11:28 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Fun2Saavei
2014-11-11 23:10 - 2013-03-05 23:10 - 00000408 _____ () C:\WINDOWS\Tasks\At1.job
2014-10-27 13:55 - 2014-10-09 19:30 - 00000000 ____D () C:\Program Files\YoutubeAdeBliocke
2014-10-27 13:55 - 2014-10-09 19:30 - 00000000 ____D () C:\Program Files\GoSaavue
2014-10-27 13:55 - 2014-10-09 19:30 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\YoutubeAdeBliocke
2014-10-27 13:55 - 2014-10-09 19:30 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\GoSaavue
2014-10-27 13:55 - 2014-07-24 19:47 - 00000000 ____D () C:\Documents and Settings\PC\Application Data\Faim
2014-10-27 13:55 - 2014-07-24 17:20 - 00000000 ____D () C:\Documents and Settings\PC\Application Data\Acmi
2014-10-27 13:55 - 2014-07-11 19:12 - 00000000 ____D () C:\Documents and Settings\PC\Application Data\Zeky
2014-10-27 13:55 - 2014-07-01 14:15 - 00000000 ____D () C:\Documents and Settings\PC\Application Data\Yvqa
2014-10-27 13:55 - 2014-06-19 15:02 - 00000000 ____D () C:\Documents and Settings\PC\Application Data\Epuqxe
2014-10-27 13:55 - 2014-02-04 19:01 - 00000000 ____D () C:\Documents and Settings\PC\Application Data\Inbumu
2014-10-23 11:29 - 2014-10-09 19:29 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\c5e40736dbd8493d
2014-10-21 01:49 - 2010-09-21 10:01 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Temp
2014-10-19 01:33 - 2014-04-29 02:56 - 00034304 ___HC () C:\Documents and Settings\PC\My Documents\~WRL0006.tmp
Task: C:\WINDOWS\Tasks\At1.job => C:\DOCUME~1\PC\APPLIC~1\Funmoods\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\Temp:054B9966
AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\Temp:F8B88761
emptytemp:
end
*****************

ClosrProcesses: => Error: No automatic fix found for this entry.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bitguard.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bprotect.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bpsvc.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browserdefender.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browserprotect.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browsersafeguard.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\dprotectsvc.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\jumpflip" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\protectedsearch.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchinstaller.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchprotection.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchprotector.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchsettings.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchsettings64.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\snapdo.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\stinst32.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\stinst64.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\umbrella.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\utiljumpflip.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\volaro" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\vonteera" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\websteroids.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\websteroidsservice.exe" => Key deleted successfully.
"C:\Documents and Settings\PC\Start Menu\Programs\Startup\bytor.bmp ()" => File/Directory not found.
C:\Documents and Settings\PC\Start Menu\Programs\Startup\wlort.dll => Moved successfully.
HKLM\System\CurrentControlSet\Control\Session Manager\AppCertDlls\\x64 => value deleted successfully.
"c:\program files\browser tab search by ask" => File/Directory not found.
C:\WINDOWS\system32\GroupPolicy\Machine => Moved successfully.
C:\WINDOWS\system32\GroupPolicy\GPT.ini => Moved successfully.
"HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully.
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} => Value not found.
C:\Program Files\BS_Player\prxtbBS_0.dll => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" => Key deleted successfully.
"HKCR\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" => Key not found.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488}" => Key deleted successfully.
"HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488}" => Key not found.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}" => Key deleted successfully.
"HKCR\CLSID\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}" => Key not found.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8}" => Key deleted successfully.
"HKCR\CLSID\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8}" => Key not found.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1F096B29-E9DA-4D64-8D63-936BE7762CC5}" => Key deleted successfully.
"HKCR\CLSID\{1F096B29-E9DA-4D64-8D63-936BE7762CC5}" => Key not found.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488}" => Key deleted successfully.
"HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488}" => Key not found.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}" => Key deleted successfully.
"HKCR\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}" => Key not found.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C2367743-5BC1-4816-8307-4172465CAC6C}" => Key deleted successfully.
"HKCR\CLSID\{C2367743-5BC1-4816-8307-4172465CAC6C}" => Key not found.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8}" => Key deleted successfully.
"HKCR\CLSID\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8}" => Key not found.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}" => Key not found.
"HKCR\CLSID\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}" => Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{98889811-442D-49dd-99D7-DC866BE87DBC} => value deleted successfully.
"HKCR\CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC}" => Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} => Value not found.
"HKCR\CLSID\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}" => Key not found.
Firefox DefaultSearchEngine deleted successfully.
Firefox DefaultSearchEngine,S deleted successfully.
Firefox DefaultSearchUrl deleted successfully.
Firefox SearchEngineOrder.1 deleted successfully.
Firefox SearchEngineOrder.1,S deleted successfully.
Firefox SearchEngineOrder.3 deleted successfully.
Firefox SelectedSearchEngine deleted successfully.
Firefox SelectedSearchEngine,S deleted successfully.
Firefox homepage deleted successfully.
C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\searchplugins\Ask.xml => Moved successfully.
C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\searchplugins\askcom.xml => Moved successfully.
C:\Program Files\mozilla firefox\browser\searchplugins\Ask.xml => Moved successfully.
C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\Extensions\[email protected] => Moved successfully.
C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\Extensions\[email protected] => Moved successfully.
C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\Extensions\[email protected] => Moved successfully.
C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\Extensions\[email protected] => Moved successfully.
C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\Extensions\[email protected] => Moved successfully.
C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\Extensions\[email protected] => Moved successfully.
C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\Extensions\[email protected] => Moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected] => Moved successfully.
C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\extensions\[email protected] => not found.
C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\extensions\[email protected] => not found.
C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\pptquoul.default\extensions\{32b29df0-2237-4370-9a29-37cebb730e9b} => not found.
FF Extension: No Name - [email protected] [Not Found] => not found.
FF Extension: No Name - [email protected] [Not Found] => not found.
FF Extension: No Name - {32b29df0-2237-4370-9a29-37cebb730e9b} [Not Found] => not found.
C:\Documents and Settings\PC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pefdgighdfaaojjebinjleeinndfdfij => Moved successfully.
apkcfzpt => Service deleted successfully.
gfmiban => Service deleted successfully.
hhbso => Service deleted successfully.
sdogua => Service deleted successfully.
snmibdk => Service deleted successfully.
hwvlyh => Service deleted successfully.
"C:\Program Files\Movie Maker\zwokur.dll" => File/Directory not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs apkcfzpt => Value deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs gfmiban => Value deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs snmibdk => Value deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs hhbso => Value deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs sdogua => Value deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs hwvlyh => Value deleted successfully.
C:\Documents and Settings\PC\Application Data\bytor.bmp => Moved successfully.
C:\Documents and Settings\All Users\Application Data\Fun2Saavei => Moved successfully.
C:\WINDOWS\Tasks\At1.job => Moved successfully.
C:\Program Files\YoutubeAdeBliocke => Moved successfully.
C:\Program Files\GoSaavue => Moved successfully.
C:\Documents and Settings\All Users\Application Data\YoutubeAdeBliocke => Moved successfully.
C:\Documents and Settings\All Users\Application Data\GoSaavue => Moved successfully.
C:\Documents and Settings\PC\Application Data\Faim => Moved successfully.
C:\Documents and Settings\PC\Application Data\Acmi => Moved successfully.
C:\Documents and Settings\PC\Application Data\Zeky => Moved successfully.
C:\Documents and Settings\PC\Application Data\Yvqa => Moved successfully.
C:\Documents and Settings\PC\Application Data\Epuqxe => Moved successfully.
C:\Documents and Settings\PC\Application Data\Inbumu => Moved successfully.
C:\Documents and Settings\All Users\Application Data\c5e40736dbd8493d => Moved successfully.
C:\Documents and Settings\All Users\Application Data\Temp => Moved successfully.
C:\Documents and Settings\PC\My Documents\~WRL0006.tmp => Moved successfully.
C:\WINDOWS\Tasks\At1.job not found.
"C:\Documents and Settings\All Users\Application Data\Temp" => ":054B9966" ADS not found.
"C:\Documents and Settings\All Users\Application Data\Temp" => ":F8B88761" ADS not found.
EmptyTemp: => Removed 1.1 GB temporary data.

The system needed a reboot.

==== End of Fixlog ====

Да, всичко е насочено към вас. Това си е вашата тема и тук всички инструкции ще са само за вас. Останалите потребители с този проблем бяха разделени в нови теми за да не стане объркване.

 

Трябва да изтеглите fixlist.txt и да го поставите в папката, където се намира и инаструмента FRST.exe и след това да стартирате FRST.exe и да натиснете бутона Fix. :)

След рестарта после публикувайте лога, който ще се създаде в същата папка - Fixlog.txt

 

 

Поздрави!

  • Автор

Да, вече се извиних, намерих къде съм объркала, в горния ми пост е резултатът от fixloga. Простете невежеството и мерси! Оттук нататък какво трябва да направя?

Моля архивирайте папката C:\FRST\Quarantine и качете архива на файлов хостинг по-избор (например dox.bg).

След това ми пратете линка за изтегляне на Лично съобщение и след това изтрийте архива, който създадохте (но не и самата папка, нея ще я изтрием накрая).

 

Повторете проверката с FRST (сложете отметка пред Addition,txt) и натиснете бутона Scan. Публикувайте новите два лог файла за да видим как се справяме с почистването на системата.

Изтеглете edit-text.giffixlist.txt и го запазете в папката от която стартирахте FRST.exe.
Стартирайте FRST.exe и натиснете бутона Fix веднъж!
След като приключи, ако ви поиска рестарт - съгласете се. След рестарта публикувайте лог файла - fixlog.txt, който ще се създаде след работата на програмата.
 
Внимание: Скрипта е създаден за текущата система. Да не се ползва за други системи с подобни проблеми!

 

След това ако имате запаметени пароли и любими страници (favorites/bookmarks) и някакви лични настройки в Google Chrome ги експортнете.

 

Деинсталирайте след това Google Chrome и Google Update Helper от Контролния панел. След това инсталирайте последната стабилна версия на браузъра => Google Chrome 38.0.2125.122 Stable

 

Причините за тези стъпки е, че има нов адуер, който обновява браузъра до последната версия за разработчици (developer build), защото в нея всички защитни механизми са изключени и гадината може да си добавя добавки с нисък рейтинг без те да бъдат блокирани от браузъра. Стабилната версия няма да позволи на такива добавки да се инсталират. Просто това се изисква след почистването на системата при тази нова гад, колкото и да е неприятно иначе лошите добавки ще се генерират отново.

 

Засега е това...поне поизчисихме системата от вредителите...за декриптирането ще видим дали колегите ще намерят решение за да обърнат процеса. :)

 

 

Поздрави!

  • Автор

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 13-11-2014 01
Ran by PC at 2014-11-14 14:30:25 Run:2
Running from C:\Documents and Settings\PC\Desktop
Loaded Profile: PC (Available profiles: PC)
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
start
CloseProcesses:
C:\Documents and Settings\PC\Start Menu\Programs\Startup\bytor.bmp
C:\Documents and Settings\PC\Local Settings\Application Data\Conduit
Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.24.15 - Google Inc.) Hidden
emptytemp:
end

*****************

Processes closed successfully.
C:\Documents and Settings\PC\Start Menu\Programs\Startup\bytor.bmp => Moved successfully.
C:\Documents and Settings\PC\Local Settings\Application Data\Conduit => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{18455581-E099-4BA8-BC6B-F34B2F06600C}\\SystemComponent => value deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}\\SystemComponent => value deleted successfully.
EmptyTemp: => Removed 525.9 MB temporary data.

The system needed a reboot.

==== End of Fixlog ====

 

Не съм инсталирала новата версия, защото ползвам и Mozzila Firefox, и Internet Explorer, предполагам, че на този етап не е нужно да го правя, освен ако нямате нещо предвид. По отношение на другите 2 браузъра трябва ли да предприема същите стъпки и да експортна отметките? За сведение, в Google Chrome нямах никакви запазени страници, ползвах го рядко и в краен случай, затова нямаше нищо за експортване. Другият ми въпрос, няма да се реши проблема, ако изтрия криптираните файлове, нали? Защото ако това ще помогне, ще трия, важните някак ще ги прежаля, просто искам да махна този бацил, понеже съм притисната откъм време. По всичко, което ми казахте, да разбирам ли, че ако отида на сервиз, ще преинсталират всичко, защото няма да могат да спасят файловете, т.е. безсмислено е да го нося и шансът да го оправите Вие, и то по-безболезно е по-голям, така ли? Отново искрени благодарности! Разбирам, че работите усилено, всички сме ви много признателни за това! Чакам информация, когато излезе нещо. Мерси, стискаме палци скоро да намерите решение! :)

 

Здравейте,

 

Супер, щом нямате отметки в Google Chrome тогава просто деинсталирайте Google Chrome и Google Update Helper и инсталирайте отново последната стабилна версия на Google Chrome за да си я имате. Няма нужда да преинсталирате останалите браузъри...всички ги почистихме така или иначе, но само Google Chrome се нуждае от преинсталация, защото гадината го е обновила до developer версията.

 

Като цяло мисля, че почистихме цялата система. Няма нужда да триете криптираните файлове засега. Т.е. те не са заразени и с тях или без тях системата ще си остане чиста, но ако ги изтриете после няма да можете да ги декриптирате ако въобще това стане възможно. Моя съвет е да ги оставите за още няколко дни и ако не се открие решение тогава ще ги изтрием всичките поне да не заемат място, защото в този си вид са неизползваеми.

 

За сервиза имах предвид, че не вярвам да успеят да се справят с декриптирането на файловете (все пак има колеги, които се занимават с възстановяването на изрити файлове, но няма да е бързо и евтино), не че няма да почистят системата, но то с почистването се справихме и ние. Все пак ще направим още малко проверки за да видим дали сме изкоренили всичко вече:

 

 

СТЪПКА 1

 
Моля изтеглете Malwarebytes Anti-Malware 2.0.3.1025 Final и я запазете на вашия десктоп.

  • Стартирайте файла mbam-setup-2.0.3.1025.exe и следвайте указанията за да инсталирате програмата.
  • След като инсталацията приключи се уверете че сте сложили отметка пред:
  • Launch Malwarebytes Anti-Malware
  • Отметката активираща пробния 14 дневен период също е маркиран по-подразбиране. Ако не желаете да тествате защитата в реално време на програмата през следващите 14 дни тогава премахнете отметката.
  • Натиснете бутона Finish.
  • Отидете до табът Settings > Detection and Protection > и под категорията Detection Options включете опцията "Scan for rootkits".
  • Отидете до табът Scan, сложете радио-бутона пред Threat Scan и след това натиснете бутона Scan Now >> . Ако е намерена актуализация тогава натиснете бутона Update Now.
  • Ще започне проверка за зловреден софтуер.
  • При някои инфекции можете да видите съобщението:
  • "Could not load DDA driver"
  • Натиснете "Yes" на това съобщение за да позволите драйвера да се зареди след рестарт.
  • Разрешете на компютъра да се рестартира и след това продължете с останалите инструкции.
  • След като проверката приключи натиснете бутона Apply Actions.
  • Изчакайте да се появи прозореца подканващ ви да рестартирате и след това натиснете бутона Yes.
  • След рестарта, когато се появи десктопа MBAM ще се зареди още веднъж.
  • Отидете то табът History > Application Logs.
  • Отворете рапорта с последната дата и час и натиснете бутона "Copy to Clipboard"
  • Сега вече поставете съдържанието на лог файла с клавишната комбинация Ctrl + V и го публикувайте в следващия си коментар.


     
    СТЪПКА 2
     

     
    1.Изтеглете Hitman Pro.
    За 32-битова система - dEMD6.gif.
    За 64-битова система - Download-button3.gif


    2.Стартирайте програмата.

    3.След като сте стартирали програмата като кликнете върху иконата 5vo5F.jpg и натиснете бутона „Напред“ като се съгласите с лицензионното споразумение (EULA).

    4.Сложете отметка пред "Не, искам да завърша еднократно сканиране на компютъра".

    5.Натиснете бутона „Напред“.

    6.Програмата ще започне да сканира. Времето за сканиране е около 2 минути.

    7.След завършване на сканирането от списъка с намерените неща (ако има такива) изберете Apply to all => Ignore.

    8.Натиснете "Next" и след това натиснете "Изнеси резултата в XML file" и запазете лог файла на десктопа.

    9.Архивирайте файла и го прикачете в следващия си коментар или копирайте съдържанието му в следващия си коментар.
     
    Забележка: Ако няма падащо меню, където да изберете ignore както на снимката:
     
    6-scanfin-choose.jpg
     
    Тогава просто затворете програмата след края на проверката (без да премахвате нищо)...след това отворете C:ProgramdataHitmanProLogs, отворете и публикувайте съдържанието на лог файла в следващия си коментар.

 

Поздрави!

  • Автор

Огромни благодарности на целия екип за усилията! Ще изчакам докато излезете с резултат, няма проблем, оправих си долу-горе спешните неща. Malware ми е инсталирана и с нейна помощ съм чистила доста троянци, но тук не ми засече нищо, както ви казах, един скан, който ми отнемаше поне 10-15 минути, след вируса ставаше за 2-3 със светкавична бързина. Сега отново ми отне 15-тина минути, но не засече абсолютно нищо.

Malwarebytes Anti-Malware

www.malwarebytes.org

Дата на сканиране: 14.11.2014 г.

Час на сканиране: 22:24:19

Дневник:

Администратор: Да

Версия: 2.00.3.1025

База от данни за злонамерен софтуер: v2014.11.14.08

База от данни за рууткити: v2014.11.12.01

Лиценз: Безплатен

Защита от злонамерен софтуер: Забранено

Защита от злонамерени страници: Забранено

Самозащита: Забранено

ОС: Windows XP Service Pack 3

Процесор: x86

Файлова система: NTFS

Потребител: PC

Тип сканиране: Сканиране за заплахи

Резултат: Завършено

Сканиране обекти: 343281

Изминало време: 14 мин. 17 сек.

Памет: Разрешено

Начално стартиране: Разрешено

Файлова система: Разрешено

Архиви: Разрешено

Рууткити: Разрешено

Евристика: Разрешено

ПНП: Разрешено

ПНИ: Разрешено

Процеси: 0

(№ злобен открити статии)

Модули: 0

(№ злобен открити статии)

Ключове в системния регистър: 0

(№ злобен открити статии)

Стойности в системния регистър: 0

(№ злобен открити статии)

Данни в системния регистър: 0

(№ злобен открити статии)

Папки: 0

(№ злобен открити статии)

Файлове: 0

(№ злобен открити статии)

Физически сектори: 0

(№ злобен открити статии)

(end)

HitmanPro от друга страна вече почти 3 часа не може да се справи със сканирането, засече 5 заплахи и изключително бавно минава през файловете с decode@india, предимно изображенията, те са ми доста и де факто не е сканирана голяма част от файловете. Дори ми засече FRST като подозрителни, не знам защо. Прекъсвам поради времето и ще продължа утре, засега ще премахна само засеченото до момента. за съжаление не мога да кача скрийншот, за да ви покажа, и това не знам защо. Нататък чакам вие да ми кажете как да процедирам. Мерси отново!

Редактирано от [email protected] (преглед на промените)

Това е добър знак, щом поведението на MBAM се е върнало в началното си състояние. Колкото до hitmanpro, намирането на FRST като заплаха е фалшиво засичане и може да се игнорира (но то така или иначе вие не трябва да триете нищо с инструмента според инструкциите ми). :)

 

Когато можете тогава публикувайте и последния лог файл. Поне системата започва вече да прилича на чиста система. :)

  • Автор

Не намерих папката C:\ProgramdataHitmanProLogs, нито въобще каквато и да е папка с програмата. Много интересно, днес ми сканира всичко за 2 часа (отново забавяше на криптираните файлове) и не откри никакви заплахи, доста странно, не знам защо действа така. Притесних се и сканирах и с Malware отново, пак за 10-тина минути, и тя не отчете нищо. Ето резултатите от сканирането с HitmanPro, чакам указания :)

HitmanPro 3.7.9.232
www.hitmanpro.com

   Computer name . . . . : PC-698796166478
   Windows . . . . . . . : 5.1.3.2600.X86/2
   User name . . . . . . : PC-698796166478\PC
   License . . . . . . . : Trial (30 days left)

   Scan date . . . . . . : 2014-11-15 16:29:30
   Scan mode . . . . . . : Normal
   Scan duration . . . . : 2h 28m 9s
   Disk access mode  . . : Direct disk access (SRB)
   Cloud . . . . . . . . : Internet
   Reboot  . . . . . . . : No

   Threats . . . . . . . : 0
   Traces  . . . . . . . : 13

   Objects scanned . . . : 606 070
   Files scanned . . . . : 26 648
   Remnants scanned  . . : 127 958 files / 451 464 keys

Suspicious files ____________________________________________________________

   C:\Documents and Settings\PC\Desktop\FRST-OlderVersion\FRST.exe
      Size . . . . . . . : 1 107 968 bytes
      Age  . . . . . . . : 2.8 days (2014-11-12 22:25:32)
      Entropy  . . . . . : 8.0
      SHA-256  . . . . . : BF04F57C4244A7A2291220E058DDBD2051C0CF0E75D57F6CC2FFCA44459C02CE
      Needs elevation  . : Yes
      Fuzzy  . . . . . . : 24.0
         Program has no publisher information but prompts the user for permission elevation.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Time indicates that the file appeared recently on this computer.

   C:\Documents and Settings\PC\Desktop\FRST.exe
      Size . . . . . . . : 1 108 480 bytes
      Age  . . . . . . . : 1.1 days (2014-11-14 14:28:14)
      Entropy  . . . . . : 8.0
      SHA-256  . . . . . : 3F3E742530C6D33C1BDC57946A70346F23D298A0445000B3BABE6ECAC7D1F1EC
      Needs elevation  . : Yes
      Fuzzy  . . . . . . : 24.0
         Program has no publisher information but prompts the user for permission elevation.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Time indicates that the file appeared recently on this computer.
      References
         HKU\S-1-5-21-484763869-179605362-1417001333-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\Documents and Settings\PC\Desktop\FRST.exe
      Forensic Cluster
          0.0s C:\Documents and Settings\PC\Desktop\FRST.exe
          0.0s C:\Documents and Settings\PC\Desktop\FRST.exe
          0.0s C:\Documents and Settings\PC\Desktop\FRST.exe
          2.6s C:\Documents and Settings\PC\Desktop\FRST-OlderVersion\


Potential Unwanted Programs _________________________________________________

   HKU\S-1-5-21-484763869-179605362-1417001333-1003\Software\Microsoft\Internet Explorer\Approved Extensions\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115} (iLivid)

Cookies _____________________________________________________________________

   C:\Documents and Settings\PC\Cookies\[email protected][1].txt
   C:\Documents and Settings\PC\Cookies\[email protected][1].txt
   C:\Documents and Settings\PC\Cookies\[email protected][1].txt
   C:\Documents and Settings\PC\Cookies\pc@advertising[2].txt
   C:\Documents and Settings\PC\Cookies\[email protected][1].txt
   C:\Documents and Settings\PC\Cookies\pc@casalemedia[1].txt
   C:\Documents and Settings\PC\Cookies\[email protected][2].txt
   C:\Documents and Settings\PC\Cookies\pc@doubleclick[2].txt
   C:\Documents and Settings\PC\Cookies\pc@smartadserver[1].txt

Няма нищо странно. Системата е чиста и затова MBAM ни HitmanPro не намериха нищо. Ние я изчистихме с FRST скриптове. Нормално е и да бави на крипираните файлове и да не ги определя като заплаха, защото те не са заплаха (те са просто безобидни и неизползваеми в момента файлове). Засега няма да ги трием, защото все още се надяваме да намерят декриптиращ механизъм.

 

Остана са изтрием само един ключ в регистрите и да чакаме колегите от чужбина да намерят декриптор (ако изобщо е такъв е възможен).

 

Изтеглете edit-text.giffixlist.txt и го запазете в папката от която стартирахте FRST.exe.
Стартирайте FRST.exe и натиснете бутона Fix веднъж!
След като приключи, ако ви поиска рестарт - съгласете се. След рестарта публикувайте лог файла - fixlog.txt, който ще се създаде след работата на програмата.
 
Внимание: Скрипта е създаден за текущата система. Да не се ползва за други системи с подобни проблеми!

 

 

Повторете проверката с Hitmanpro и публикувайте новите резултати. Очаквам напълно чист лог. :)

  • Автор

Да, и аз се надявам вече да е чиста. Сканира ми го за стотни от секундата, пращам лога:

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 13-11-2014 01
Ran by PC at 2014-11-16 00:34:37 Run:3
Running from C:\Documents and Settings\PC\Desktop
Loaded Profile: PC (Available profiles: PC)
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
start
Unlock: HKU\S-1-5-21-484763869-179605362-1417001333-1003\Software\Microsoft\Internet Explorer\Approved Extensions
Reg: reg delete "HKU\S-1-5-21-484763869-179605362-1417001333-1003\Software\Microsoft\Internet Explorer\Approved Extensions" /v {A40DC6C5-79D0-4CA8-A185-8FF989AF1115} /f
end
*****************

"HKU\S-1-5-21-484763869-179605362-1417001333-1003\Software\Microsoft\Internet Explorer\Approved Extensions" => Key unlocked successfully.

========= reg delete "HKU\S-1-5-21-484763869-179605362-1417001333-1003\Software\Microsoft\Internet Explorer\Approved Extensions" /v {A40DC6C5-79D0-4CA8-A185-8FF989AF1115} /f =========

The operation completed successfully

========= End of Reg: =========

==== End of Fixlog ====

 

Да, предполагам, че е нормално да бави скана на криптираните файлове, осъзнавам, че не са опасни, а просто заключени, колкото и да съм неука в тази област, поне това схващам. Мен ме притеснява друго - не мога да си отворя нито Word, нито Excel, нито PowerPoint, нито която и да е програма от Microsoft Office пакета. Не съм гледала другите програми как са, понеже тези са ми належащи, но може и с тях да е така, видях и в техните папки, че има криптове. Така ли ще бъде докато се декриптират файловете, ако се декриптират въобще? Защото де факто и програмите ми от офис-пакета стават неизползваеми, а това не ме устройва в момента, тъй като имам да пиша курсова работа, книга и куп други неща. Изскочи ми съобщение автоматично за конфигурация на Майкрософт Офис пакета, но ми даде (цитирам, понеже не ми се качва скрийншота):

Error 1308: Setup cannot find required file D:\Install\Microsoft Office 2003\FILES\APPDATA\MS\OFFICE\DATA\OPA11 BAK. Check your connection to the network or CD-Rom drive. For other potential solutions to this problem, see C:\Program Files\Microsoft Office\OFFICE11\1033\SETUP.CHM.  

Никакъв резултат нито при Retry, нито при Ignore. Може да се окаже, че и другите ми програми са така, като гледам, във всяка папка програми има крипт. Както и да е, очевидно няма начин да ги ползвам... А доколкото виждам и по думите ви, декриптирането може да отнеме месеци и пак да е неуспешно...

Сърдечни благодарности за почистването, спестихте ми доста време, разкарване и пари, ако наистина всичко е чисто вече, мога ли да си включа System Restore опцията или да изчакам докато/ако се декриптират файловете? И също мога ли да влизам спокойно в профилите си в сайтовете през Firefox и Explorer, понеже засега не го правих никъде, освен тук. Предполагам, че няма да има проблем, след като сте ги изчистили, но съм длъжна да питам с оглед на моята некомпетентност.

 

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.