Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Премахване на omiga-plus, delta-homes

Featured Replies

Здравейте,

Не мога да премахне omiga-plus и delta-homes от Mozilla Firefox. От Интернет експлорър май успях, но не разчитам, че няма да се появи пак. Ползвах само ръчно премахване - от началната страница, от Add ons, от предложените търсачки, от Пропъртис на иконката на браузъра, и в Трабълшутинг информейшън рестартирах Мозила-настройките, после и лаптопа - пак се появява омига-та.

 

Нямам инсталанционен диск.

 

Ето съдържанието на единия файл от скана:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 28-12-2014
Ran by rtest (administrator) on TEST-EC4625775C on 29-12-2014 21:08:28
Running from C:\Documents and Settings\rtest\My Documents\Downloads
Loaded Profile: rtest (Available profiles: rtest)
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English (United States)
Internet Explorer Version 7 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe
(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(SigmaTel, Inc.) C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
(BitTorrent, Inc.) C:\Program Files\uTorrent\uTorrent.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.bin
(Cherished Technololgy LIMITED) C:\Documents and Settings\All Users\Application Data\IePluginServices\PluginService.exe
(Fuyu LIMITED) C:\Documents and Settings\All Users\Application Data\WindowsMangerProtect\ProtectWindowsManager.exe
() C:\Program Files\SupTab\HpUI.exe
(Taiwan Shui Mu Chih Ching Technology Limited.) C:\Program Files\WinZipper\winzipersvc.exe
() C:\Program Files\SupTab\Loader32.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.25.11\GoogleCrashHandler.exe
(Skype Technologies S.A.) C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(SigmaTel, Inc.) C:\WINDOWS\system32\stacsv.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\WLKEEPER.exe
(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
(Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [bluetoothAuthenticationAgent] => rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [nwiz] => nwiz.exe /installquiet
HKLM\...\Run: [NVHotkey] => rundll32.exe nvHotkey.dll,Start
HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
HKLM\...\Run: [intelZeroConfig] => C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe [1372160 2009-11-03] (Intel® Corporation)
HKLM\...\Run: [intelWireless] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1202448 2009-11-03] (Intel® Corporation)
HKLM\...\Run: [avast] => C:\Program Files\AVAST Software\Avast\avastUI.exe [3451496 2011-02-23] (AVAST Software)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [sigmatelSysTrayApp] => C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe [405504 2007-05-10] (SigmaTel, Inc.)
HKU\S-1-5-19\...\RunOnce: [nltide_2] => regsvr32 /s /n /i:U shell32
HKU\S-1-5-20\...\RunOnce: [nltide_2] => regsvr32 /s /n /i:U shell32
HKU\S-1-5-21-515967899-602609370-1417001333-1003\...\Run: [uTorrent] => C:\Program Files\uTorrent\uTorrent.exe [399736 2011-04-16] (BitTorrent, Inc.)
HKU\S-1-5-21-515967899-602609370-1417001333-1003\...\Run: [skype] => C:\Program Files\Skype\Phone\Skype.exe [30872168 2014-12-11] (Skype Technologies S.A.)
HKU\S-1-5-21-515967899-602609370-1417001333-1003\...\MountPoints2: {000474e4-3f4d-11e4-8169-001cbfada684} - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Toshiba Places.html
HKU\S-1-5-21-515967899-602609370-1417001333-1003\...\MountPoints2: {26f49b48-1995-11e4-813e-001cbfada684} - H:\USBNB.exe
HKU\S-1-5-21-515967899-602609370-1417001333-1003\...\MountPoints2: {39b47589-640e-11e0-ad56-001a6b19875d} - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE      .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
HKU\S-1-5-21-515967899-602609370-1417001333-1003\...\MountPoints2: {5d8eda92-642e-11e0-ad57-001a6b19875d} - RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe
HKU\S-1-5-18\...\RunOnce: [nltide_2] => regsvr32 /s /n /i:U shell32
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ColorVisionStartup.lnk
ShortcutTarget: ColorVisionStartup.lnk -> C:\Program Files\ColorVision\ColorVisionStartup\ColorVisionStartup.exe (Datacolor)
Startup: C:\Documents and Settings\rtest\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKU\S-1-5-21-515967899-602609370-1417001333-1003\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.bg/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://isearch.omiga-plus.com/?type=sc&ts=1405769732&from=ild&uid=ST9160823ASG_5NK13FFVXXXX5NK13FFV
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1405769732&from=ild&uid=ST9160823ASG_5NK13FFVXXXX5NK13FFV&q={searchTerms}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1405769732&from=ild&uid=ST9160823ASG_5NK13FFVXXXX5NK13FFV&q={searchTerms}
SearchScopes: HKU\S-1-5-21-515967899-602609370-1417001333-1003 -> DefaultScope {7AC159B1-5EB3-453C-A90F-C753AC7F8F99} URL = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
SearchScopes: HKU\S-1-5-21-515967899-602609370-1417001333-1003 -> {7AC159B1-5EB3-453C-A90F-C753AC7F8F99} URL = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: IETabPage Class -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> C:\Program Files\SupTab\SupTab.dll (Thinknice Co. Limited)
BHO: avast! WebRep -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO: uTorrentBar Toolbar -> {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} -> C:\Program Files\uTorrentBar\prxtbuTo2.dll (Conduit Ltd.)
BHO: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll No File
Toolbar: HKLM - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
Toolbar: HKLM - uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\prxtbuTo2.dll (Conduit Ltd.)
Toolbar: HKU\S-1-5-21-515967899-602609370-1417001333-1003 -> uTorrentBar Toolbar - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - C:\Program Files\uTorrentBar\prxtbuTo2.dll (Conduit Ltd.)
Toolbar: HKU\S-1-5-21-515967899-602609370-1417001333-1003 -> No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} -  No File
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Documents and Settings\rtest\Application Data\Mozilla\Firefox\Profiles\05r7it1e.default-1419879444015
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_15_0_0_246.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @photodex.com/PhotodexPresenter -> C:\Program Files\Photodex Presenter\npPxPlay.dll ( )
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\delta-homes.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\omiga-plus.xml
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-11-10]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-11-10]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! WebRep - C:\Program Files\AVAST Software\Avast\WebRep\FF [2011-04-16]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Documents and Settings\rtest\Application Data\Mozilla\Firefox\Profiles\u4egywgh.default\extensions\[email protected]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Documents and Settings\rtest\Application Data\Mozilla\Firefox\Profiles\u4egywgh.default\extensions\[email protected]
FF StartMenuInternet: FIREFOX.EXE - C:\Program Files\Mozilla Firefox\firefox.exe http://www.delta-homes.com/?type=sc&ts=1419407860&from=wpm12233&uid=ST9160823ASG_5NK13FFVXXXX5NK13FFV

Chrome:
=======
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2013-05-14]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [42184 2011-02-23] (AVAST Software)
R2 IePluginServices; C:\Documents and Settings\All Users\Application Data\IePluginServices\PluginService.exe [3427208 2014-07-19] (Cherished Technololgy LIMITED)
R2 S24EventMonitor; C:\Program Files\Intel\WiFi\bin\S24EvMon.exe [909312 2009-11-03] (Intel® Corporation) [File not signed]
R2 Skype C2C Service; C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3048136 2012-05-30] (Skype Technologies S.A.)
R2 STacSV; C:\WINDOWS\system32\StacSV.exe [94208 2007-05-10] (SigmaTel, Inc.)
R2 WindowsMangerProtect; C:\Documents and Settings\All Users\Application Data\WindowsMangerProtect\ProtectWindowsManager.exe [472064 2014-12-24] (Fuyu LIMITED) [File not signed]
R2 winzipersvc; C:\Program Files\WinZipper\winzipersvc.exe [470704 2014-12-17] (Taiwan Shui Mu Chih Ching Technology Limited.) <==== ATTENTION
R2 WLANKEEPER; C:\Program Files\Intel\WiFi\bin\WLKeeper.exe [348160 2009-11-03] (Intel® Corporation) [File not signed]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R1 Aavmker4; C:\WINDOWS\system32\Drivers\Aavmker4.sys [30680 2011-02-23] (AVAST Software)
R2 aswFsBlk; C:\WINDOWS\system32\Drivers\aswFsBlk.sys [19544 2011-02-23] (AVAST Software)
R2 aswMon2; C:\WINDOWS\system32\Drivers\aswMon2.sys [102232 2011-02-23] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\Drivers\aswRdr.sys [25432 2011-02-23] (AVAST Software)
R1 aswSnx; C:\WINDOWS\system32\Drivers\aswSnx.sys [371544 2011-02-23] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\Drivers\aswSP.sys [301528 2011-02-23] (AVAST Software)
R1 aswTdi; C:\WINDOWS\system32\Drivers\aswTdi.sys [49240 2011-02-23] (AVAST Software)
S3 ENTECH; C:\WINDOWS\system32\DRIVERS\ENTECH.SYS [21664 2004-10-25] (EnTech Taiwan) [File not signed]
R3 NETw5x32; C:\WINDOWS\System32\DRIVERS\NETw5x32.sys [4221952 2009-10-26] (Intel Corporation)
R2 s24trans; C:\WINDOWS\System32\DRIVERS\s24trans.sys [11904 2008-08-13] (Intel Corporation)
S3 Spyder2; C:\WINDOWS\System32\DRIVERS\Spyder2.sys [12288 2007-01-17] ()
R3 STHDA; C:\WINDOWS\System32\drivers\sthda.sys [1222840 2007-05-10] (SigmaTel, Inc.)
S4 IntelIde; No ImagePath
U1 WS2IFSL; No ImagePath

==================== NetSvcs (Whitelisted) ===================


(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-12-29 21:08 - 2014-12-29 21:08 - 00000000 ____D () C:\FRST
2014-12-24 13:13 - 2014-12-29 20:57 - 00000000 ____D () C:\Documents and Settings\rtest\Desktop\Old Firefox Data
2014-12-24 09:58 - 2014-12-29 21:06 - 00000000 ____D () C:\Program Files\WinZipper
2014-12-24 09:58 - 2014-12-24 09:58 - 00000000 ____D () C:\Documents and Settings\rtest\Application Data\WinZipper
2014-12-24 09:58 - 2014-12-24 09:58 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\WinZipper
2014-12-20 09:32 - 2014-12-20 09:32 - 00002669 _____ () C:\Documents and Settings\rtest\Desktop\201411-84976-5088682.txt
2014-12-12 17:45 - 2014-12-12 17:45 - 00106415 _____ () C:\Documents and Settings\rtest\My Documents\abonament 2015.odt

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-12-29 21:08 - 2011-04-11 09:35 - 00000000 ____D () C:\Documents and Settings\rtest\Local Settings\Temp
2014-12-29 21:07 - 2011-04-11 11:57 - 00458340 ____C () C:\WINDOWS\system32\PerfStringBackup.INI
2014-12-29 21:05 - 2011-05-06 10:03 - 00000000 ____D () C:\Documents and Settings\rtest\Application Data\Skype
2014-12-29 21:04 - 2011-05-06 10:02 - 00000000 ___RD () C:\Program Files\Skype
2014-12-29 21:04 - 2011-05-06 10:02 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Skype
2014-12-29 21:03 - 2011-04-11 13:20 - 00066962 _____ () C:\WINDOWS\system32\nvModes.001
2014-12-29 21:03 - 2011-04-11 11:59 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2014-12-29 21:03 - 2011-04-11 11:59 - 00000050 _____ () C:\WINDOWS\wiaservc.log
2014-12-29 21:03 - 2011-04-11 09:34 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-12-29 21:03 - 2011-04-11 09:25 - 00366356 _____ () C:\WINDOWS\WindowsUpdate.log
2014-12-29 21:00 - 2011-04-16 20:19 - 00000000 ____D () C:\Documents and Settings\rtest\Application Data\uTorrent
2014-12-29 20:58 - 2011-04-11 09:34 - 00032564 _____ () C:\WINDOWS\SchedLgU.Txt
2014-12-29 20:57 - 2011-04-11 09:35 - 00000178 ___SH () C:\Documents and Settings\rtest\ntuser.ini
2014-12-29 20:24 - 2012-04-02 18:13 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-12-29 20:23 - 2014-04-21 10:45 - 00000886 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-12-29 15:28 - 2008-04-14 10:00 - 00002206 _____ () C:\WINDOWS\system32\wpa.dbl
2014-12-28 19:23 - 2014-04-21 10:45 - 00000882 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-12-28 14:11 - 2011-05-29 09:59 - 00093184 ____C () C:\Documents and Settings\rtest\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-12-24 12:39 - 2011-04-11 11:55 - 00124520 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-12-24 10:41 - 2011-04-11 09:35 - 00020648 ____C () C:\Documents and Settings\rtest\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2014-12-24 09:57 - 2014-07-24 20:45 - 00000928 _____ () C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
2014-12-24 09:57 - 2014-07-19 13:35 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\WindowsMangerProtect
2014-12-24 09:57 - 2011-04-20 17:28 - 00000934 ____C () C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
2014-12-24 09:57 - 2011-04-11 09:35 - 00001007 ____C () C:\Documents and Settings\rtest\Start Menu\Programs\Internet Explorer.lnk
2014-12-17 04:43 - 2010-03-18 06:45 - 00773808 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr100.dll
2014-12-17 04:43 - 2010-03-18 06:45 - 00421040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp100.dll
2014-12-14 16:06 - 2014-11-15 17:54 - 00000132 _____ () C:\Documents and Settings\rtest\Application Data\Adobe PNG Format CS5 Prefs
2014-12-14 14:06 - 2011-04-11 11:56 - 00192893 _____ () C:\WINDOWS\setupact.log
2014-12-12 18:10 - 2013-01-26 18:08 - 00146944 __SHC () C:\Documents and Settings\rtest\My Documents\Thumbs.db
2014-12-12 16:30 - 2014-11-10 22:44 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-12-12 14:53 - 2013-12-10 20:31 - 00000000 ____D () C:\Documents and Settings\rtest\Desktop\kids
2014-12-12 12:12 - 2012-04-28 07:39 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-12-12 10:24 - 2012-04-02 18:13 - 00701104 ____C (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2014-12-12 10:24 - 2011-06-19 08:54 - 00071344 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2014-11-29 18:45 - 2011-05-08 09:51 - 00001456 ____C () C:\Documents and Settings\rtest\Local Settings\Application Data\Adobe Save for Web 12.0 Prefs

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

==================== End Of Log ============================

 

Addition.txt

Здравейте,

 

 

СТЪПКА 1

 

 

Деинсталирайте следните програми от Control Panel-a:

 

uTorrentBar Toolbar

WinZipper

 

 

 

СТЪПКА 2

 

 

Добре е да спрем Autorun, защото имате и червей Conficker.

 

Изтеглете и стартирайте следния файл Button_FixIt_Silver.jpg
Стартирайте го и се съгласете с лицензионното споразумение.
Натиснете Next и изчакайте да си свърпи работата.
Рестартирайте системата ако се наложи.

 

 

 

СТЪПКА 3

 

След това изтеглете edit-text.giffixlist.txt и го запазете в папката от която стартирахте FRST.exe.
Стартирайте FRST.exe и натиснете бутона Fix веднъж!
След като приключи, ако ви поиска рестарт - съгласете се. След рестарта публикувайте лог файла - fixlog.txt, който ще се създаде след работата на програмата.
 
Внимание: Скрипта е създаден за текущата система. Да не се ползва за други системи с подобни проблеми!

 

Пишете дали проблема остава!

 

Това е засега. :)

 

Поздрави!

  • Автор

Здравейте,

 

 

СТЪПКА 1

 

 

Деинсталирайте следните програми от Control Panel-a:

 

uTorrentBar Toolbar

WinZipper

 

 

 

СТЪПКА 2

 

 

Добре е да спрем Autorun, защото имате и червей Conficker.

 

Изтеглете и стартирайте следния файл http://isearch.omiga...FFVXXXX5NK13FFV

SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga...q={searchTerms}

SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga...q={searchTerms}

BHO: IETabPage Class -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> C:\Program Files\SupTab\SupTab.dll (Thinknice Co. Limited)

BHO: uTorrentBar Toolbar -> {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} -> C:\Program Files\uTorrentBar\prxtbuTo2.dll (Conduit Ltd.)

Toolbar: HKLM - uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\prxtbuTo2.dll (Conduit Ltd.)

Toolbar: HKU\S-1-5-21-515967899-602609370-1417001333-1003 -> uTorrentBar Toolbar - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - C:\Program Files\uTorrentBar\prxtbuTo2.dll (Conduit Ltd.)

Toolbar: HKU\S-1-5-21-515967899-602609370-1417001333-1003 -> No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} -  No File

FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\delta-homes.xml

FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\omiga-plus.xml

FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Documents and Settings\rtest\Application Data\Mozilla\Firefox\Profiles\u4egywgh.default\extensions\[email protected]

FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Documents and Settings\rtest\Application Data\Mozilla\Firefox\Profiles\u4egywgh.default\extensions\[email protected]

FF StartMenuInternet: FIREFOX.EXE - C:\Program Files\Mozilla Firefox\firefox.exe http://www.delta-hom...FFVXXXX5NK13FFV

R2 IePluginServices; C:\Documents and Settings\All Users\Application Data\IePluginServices\PluginService.exe [3427208 2014-07-19] (Cherished Technololgy LIMITED)

R2 WindowsMangerProtect; C:\Documents and Settings\All Users\Application Data\WindowsMangerProtect\ProtectWindowsManager.exe [472064 2014-12-24] (Fuyu LIMITED) [File not signed]

R2 winzipersvc; C:\Program Files\WinZipper\winzipersvc.exe [470704 2014-12-17] (Taiwan Shui Mu Chih Ching Technology Limited.) <==== ATTENTION

cmd: bitsadmin /reset /allusers

cmd: netsh winsock reset catalog

cmd: ipconfig /flushdns

emptytemp:

end

*****************

Processes closed successfully.

C:\Documents and Settings\All Users\Application Data\IePluginServices => Moved successfully.

C:\Documents and Settings\All Users\Application Data\WindowsMangerProtect => Moved successfully.

C:\Program Files\SupTab => Moved successfully.

C:\Program Files\WinZipper => Moved successfully.

C:\Program Files\uTorrentBar => Moved successfully.

C:\Documents and Settings\rtest\Application Data\WinZipper => Moved successfully.

"C:\Documents and Settings\All Users\Start Menu\Programs\WinZipper" => File/Directory not found.

"HKU\S-1-5-21-515967899-602609370-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{39b47589-640e-11e0-ad56-001a6b19875d}" => Key deleted successfully.

HKCR\CLSID\{39b47589-640e-11e0-ad56-001a6b19875d} => Key not found.

"HKU\S-1-5-21-515967899-602609370-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5d8eda92-642e-11e0-ad57-001a6b19875d}" => Key deleted successfully.

HKCR\CLSID\{5d8eda92-642e-11e0-ad57-001a6b19875d} => Key not found.

=========  vssadmin delete shadows /all =========

vssadmin 1.0 - Volume Shadow Copy Service administrative command-line tool

© Copyright 2001 Microsoft Corp.

Usage:

vssadmin list shadows [/set={shadow copy set guid}]

    Lists all shadow copies in the system, grouped by shadow copy set Id.

vssadmin list writers

    Lists all writers in the system

vssadmin list providers

    Lists all currently installed shadow copy providers

========= End of CMD: =========

Restore point was successfully created.

HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully.

HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.

"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully.

HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found.

"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}" => Key deleted successfully.

"HKCR\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}" => Key deleted successfully.

"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}" => Key deleted successfully.

"HKCR\CLSID\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}" => Key deleted successfully.

HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} => value deleted successfully.

HKCR\CLSID\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} => Key not found.

HKU\S-1-5-21-515967899-602609370-1417001333-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} => value deleted successfully.

HKCR\CLSID\{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} => Key not found.

HKU\S-1-5-21-515967899-602609370-1417001333-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320C79847} => value deleted successfully.

HKCR\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847} => Key not found.

C:\Program Files\mozilla firefox\browser\searchplugins\delta-homes.xml => Moved successfully.

C:\Program Files\mozilla firefox\browser\searchplugins\omiga-plus.xml => Moved successfully.

HKLM\Software\Mozilla\Firefox\Extensions\\[email protected] => value deleted successfully.

HKLM\Software\Mozilla\Firefox\Extensions\\[email protected] => value deleted successfully.

HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\\Default => Value was restored successfully.

IePluginServices => Service deleted successfully.

WindowsMangerProtect => Service deleted successfully.

winzipersvc => Service not found.

=========  bitsadmin /reset /allusers =========

'bitsadmin' is not recognized as an internal or external command,

operable program or batch file.

========= End of CMD: =========

=========  netsh winsock reset catalog =========

Sucessfully reset the Winsock Catalog.

You must restart the machine in order to complete the reset.

========= End of CMD: =========

=========  ipconfig /flushdns =========

Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========

EmptyTemp: => Removed 156.6 MB temporary data.

The system needed a reboot.

==== End of Fixlog 12:36:06 ====

Много ви  благодаря за страхотната помощ и отзивчивост! :)

Здравейте и за МНОГО ГОДИНИ! xmastree6.gif

 

Нека да проверим за остатъци:

 

 

СТЪПКА 1

  • Изтеглете и стартирайтe 6sv1DN9.jpgAdwCleaner.exe.
  • Натиснете бутона Scan.
  • AdwCleaner ще започне да проверява компютъра.
  • След като проверката приключи натиснете бутона Clean.
  • Програмата ще затвори всички излишни процеси и след почистването ще иска да рестартира машината. Съгласете се.
  • Ще се появи автоматично лог файл с името (AdwCleaner[s0].txt) в C:\Adwcleaner
  • Публикувайте съдържанието му в следващия си коментар.


     
    СТЪПКА 2
     

     
    Моля изтеглете icon1351185104.png Junkware Removal Tool на вашия десктоп.
  • Спрете временно работата на защитните програми.
  • Стартирайте инструмента JRT.exe
  • Ще се отвори ДОС прозорец. Натиснете което и да е копче от клавиатурата.
  • Затворете излишните приложения и всички браузъри и изчакайте проверката да завърши.
  • Ще се появи лог файл (който можете да намерите и ръчно на десктопа с името JRT.txt).
  • Моля копирайте съдържанието на лог файла в следващия си пост.


     
    СТЪПКА 3


     
    Моля изтеглете Malwarebytes Anti-Malware 2.0.3.1025 Final и я запазете на вашия десктоп.
  • Стартирайте файла mbam-setup-2.0.3.1025.exe и следвайте указанията за да инсталирате програмата.
  • След като инсталацията приключи се уверете че сте сложили отметка пред:
  • Launch Malwarebytes Anti-Malware
  • Отметката активираща пробния 14 дневен период също е маркиран по-подразбиране. Ако не желаете да тествате защитата в реално време на програмата през следващите 14 дни тогава премахнете отметката.
  • Натиснете бутона Finish.
  • Отидете до табът Settings > Detection and Protection > и под категорията Detection Options включете опцията "Scan for rootkits".
  • Отидете до табът Scan, сложете радио-бутона пред Threat Scan и след това натиснете бутона Scan Now >> . Ако е намерена актуализация тогава натиснете бутона Update Now.
  • Ще започне проверка за зловреден софтуер.
  • При някои инфекции можете да видите съобщението:
  • "Could not load DDA driver"
  • Натиснете "Yes" на това съобщение за да позволите драйвера да се зареди след рестарт.
  • Разрешете на компютъра да се рестартира и след това продължете с останалите инструкции.
  • След като проверката приключи натиснете бутона Apply Actions.
  • Изчакайте да се появи прозореца подканващ ви да рестартирате и след това натиснете бутона Yes.
  • След рестарта, когато се появи десктопа MBAM ще се зареди още веднъж.
  • Отидете то табът History > Application Logs.
  • Отворете рапорта с последната дата и час и натиснете бутона "Copy to Clipboard"
  • Сега вече поставете съдържанието на лог файла с клавишната комбинация Ctrl + V и го публикувайте в следващия си коментар.


     
    СТЪПКА 4
     

     
    1.Изтеглете Hitman Pro.
    За 32-битова система - dEMD6.gif.
    За 64-битова система - Download-button3.gif


    2.Стартирайте програмата.

    3.След като сте стартирали програмата като кликнете върху иконата 5vo5F.jpg и натиснете бутона „Напред“ като се съгласите с лицензионното споразумение (EULA).

    4.Сложете отметка пред "Не, искам да завърша еднократно сканиране на компютъра".

    5.Натиснете бутона „Напред“.

    6.Програмата ще започне да сканира. Времето за сканиране е около 2 минути.

    7.След завършване на сканирането от списъка с намерените неща (ако има такива) изберете Apply to all => Ignore.

    8.Натиснете "Next" и след това натиснете "Изнеси резултата в XML file" и запазете лог файла на десктопа.

    9.Архивирайте файла и го прикачете в следващия си коментар или копирайте съдържанието му в следващия си коментар.
     
    Забележка: Ако няма падащо меню, където да изберете ignore както на снимката:
     
    6-scanfin-choose.jpg
     
    Тогава просто затворете програмата след края на проверката (без да премахвате нищо)...след това отворете C:Programdata\HitmanPro\Logs, отворете и публикувайте съдържанието на лог файла в следващия си коментар.

 

Поздрави!

  • Автор

А, то имало  още работа.

 

Ето първия файл:

 

# AdwCleaner v4.106 - Report created 03/01/2015 at 18:43:22
# Updated 21/12/2014 by Xplode
# Database : 2015-01-03.1 [Live]
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : rtest - TEST-EC4625775C
# Running from : C:\Documents and Settings\rtest\My Documents\Downloads\adwcleaner_4.106.exe
# Option : Clean

***** [ Services ] *****

Service Deleted : Skype C2C Service

***** [ Files / Folders ] *****

Folder Deleted : C:\Software
Folder Deleted : C:\Documents and Settings\All Users\Application Data\Premium
Folder Deleted : C:\Program Files\Conduit
Folder Deleted : C:\Program Files\globalUpdate
Folder Deleted : C:\Documents and Settings\rtest\Local Settings\Application Data\Conduit
Folder Deleted : C:\Documents and Settings\rtest\Local Settings\Application Data\ConduitEngine
Folder Deleted : C:\Documents and Settings\rtest\Local Settings\Application Data\globalUpdate
Folder Deleted : C:\Documents and Settings\rtest\Application Data\PriceGong

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****

Shortcut Disinfected : C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
Shortcut Disinfected : C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
Shortcut Disinfected : C:\Documents and Settings\rtest\Start Menu\Programs\Internet Explorer.lnk
Shortcut Disinfected : C:\Documents and Settings\rtest\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk

***** [ Registry ] *****

Key Deleted : HKCU\Toolbar
Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Key Deleted : HKCU\Software\Mozilla\Extends
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2786678
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35B-6118-11DC-9C72-001320C79847}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35C-6118-11DC-9C72-001320C79847}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\1ClickDownload
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Crossrider
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\powerpack
Key Deleted : HKCU\Software\PriceGong
Key Deleted : HKCU\Software\SmartBar
Key Deleted : HKCU\Software\SupHpUISoft
Key Deleted : HKCU\Software\SweetIM
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\delta-homesSoftware
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\hdcode
Key Deleted : HKLM\SOFTWARE\Iminent
Key Deleted : HKLM\SOFTWARE\omiga-plusSoftware
Key Deleted : HKLM\SOFTWARE\SupDp
Key Deleted : HKLM\SOFTWARE\SupTab
Key Deleted : HKLM\SOFTWARE\supWindowsMangerProtect
Key Deleted : HKLM\SOFTWARE\supWPM
Key Deleted : HKLM\SOFTWARE\SweetIM
Key Deleted : HKLM\SOFTWARE\V9
Key Deleted : HKLM\SOFTWARE\winzipersvc
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\uTorrentBar Toolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\conduitEngine
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\WindowsMangerProtect
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\uTorrentBar Toolbar

***** [ Browsers ] *****

-\\ Internet Explorer v7.0.6000.16674


-\\ Mozilla Firefox v34.0.5 (x86 en-US)


*************************

AdwCleaner[R0].txt - [5033 octets] - [03/01/2015 18:41:14]
AdwCleaner[s0].txt - [5385 octets] - [03/01/2015 18:43:22]

########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [5445 octets] ##########
 


Вторият файл:

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.1 (12.28.2014:1)
OS: Microsoft Windows XP x86
Ran by rtest on Sat 01/03/2015 at 18:53:11.59
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\Documents and Settings\rtest\Local Settings\Application Data\utorrentbar"





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sat 01/03/2015 at 18:57:11.20
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 


И последното:

 

HitmanPro 3.7.9.232
www.hitmanpro.com

   Computer name . . . . : TEST-EC4625775C
   Windows . . . . . . . : 5.1.3.2600.X86/2
   User name . . . . . . : TEST-EC4625775C\rtest
   License . . . . . . . : Free

   Scan date . . . . . . : 2015-01-03 19:01:04
   Scan mode . . . . . . : Normal
   Scan duration . . . . : 6m 12s
   Disk access mode  . . : Direct disk access (SRB)
   Cloud . . . . . . . . : Internet
   Reboot  . . . . . . . : No

   Threats . . . . . . . : 0
   Traces  . . . . . . . : 28

   Objects scanned . . . : 513,912
   Files scanned . . . . : 37,627
   Remnants scanned  . . : 119,700 files / 356,585 keys

Suspicious files ____________________________________________________________

   C:\Documents and Settings\rtest\Desktop\JRT.exe
      Size . . . . . . . : 1,707,939 bytes
      Age  . . . . . . . : 0.0 days (2015-01-03 18:52:05)
      Entropy  . . . . . : 8.0
      SHA-256  . . . . . : 2DD0F84C137A2239E2194101FB1DB9FA38E70EA82B3C0761A2DF366A6C0B8FF4
      Running processes  : 2956
      Fuzzy  . . . . . . : 22.0
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Program is running but currently exposes no human-computer interface (GUI).
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Time indicates that the file appeared recently on this computer.
         The file is in use by one or more active processes.
      References
         HKU\S-1-5-21-515967899-602609370-1417001333-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\Documents and Settings\rtest\Desktop\JRT.exe
      Forensic Cluster
         -9.3s C:\Documents and Settings\rtest\Application Data\Microsoft\CryptnetUrlCache\MetaData\793C6836427E60E90A57B78CB7350E0D
         -9.3s C:\Documents and Settings\rtest\Application Data\Microsoft\CryptnetUrlCache\Content\793C6836427E60E90A57B78CB7350E0D
         -9.2s C:\Documents and Settings\rtest\Cookies\[email protected][2].txt
         -9.2s C:\Documents and Settings\rtest\Local Settings\Temporary Internet Files\Content.IE5\RYS3D0FM\api[1].htm
         -8.7s C:\Documents and Settings\rtest\Local Settings\Temporary Internet Files\Content.IE5\CBP1G6MW\tick-blue[1].png
         -8.7s C:\Documents and Settings\rtest\Local Settings\Temporary Internet Files\Content.IE5\CBP1G6MW\background-banner-middle-v9[1].jpg
         -8.5s C:\Documents and Settings\rtest\Local Settings\Temporary Internet Files\Content.IE5\SZ5Y1GXQ\background_banner_8_en-2014[1].png
         -8.5s C:\Documents and Settings\rtest\Local Settings\Temporary Internet Files\Content.IE5\SZ5Y1GXQ\background-banner-right-v9[1].jpg
         -8.4s C:\Documents and Settings\rtest\Local Settings\Temporary Internet Files\Content.IE5\RYS3D0FM\button-flex-blue2[1].png
         -8.4s C:\Documents and Settings\rtest\Local Settings\Temporary Internet Files\Content.IE5\RYS3D0FM\button-flex-blue2[1].png
         -1.1s C:\Documents and Settings\rtest\Local Settings\Application Data\Mozilla\Firefox\Profiles\05r7it1e.default-1419879444015\cache2\index
         -1.1s C:\Documents and Settings\rtest\Local Settings\Application Data\Mozilla\Firefox\Profiles\05r7it1e.default-1419879444015\cache2\index
          0.0s C:\Documents and Settings\rtest\Desktop\JRT.exe

   C:\Documents and Settings\rtest\My Documents\Downloads\FRST.exe
      Size . . . . . . . : 1,114,624 bytes
      Age  . . . . . . . : 4.9 days (2014-12-29 21:07:30)
      Entropy  . . . . . : 8.0
      SHA-256  . . . . . : FE2D272E9E7468BAB89F4E6B937833A1B52AD0BF5D914450C3E804F94124A824
      Needs elevation  . : Yes
      Fuzzy  . . . . . . : 24.0
         Program has no publisher information but prompts the user for permission elevation.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Time indicates that the file appeared recently on this computer.
      References
         HKU\S-1-5-21-515967899-602609370-1417001333-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\Documents and Settings\rtest\My Documents\Downloads\FRST.exe


Potential Unwanted Programs _________________________________________________

   HKLM\SYSTEM\ControlSet002\Services\Eventlog\Application\winzipersvc\ (AirZip)
   HKLM\SYSTEM\ControlSet003\Services\Eventlog\Application\winzipersvc\ (AirZip)
   HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\winzipersvc\ (AirZip)

Cookies _____________________________________________________________________

   C:\Documents and Settings\rtest\Application Data\Mozilla\Firefox\Profiles\05r7it1e.default-1419879444015\cookies.sqlite:ad.360yield.com
   C:\Documents and Settings\rtest\Application Data\Mozilla\Firefox\Profiles\05r7it1e.default-1419879444015\cookies.sqlite:ad.mlnadvertising.com
   C:\Documents and Settings\rtest\Application Data\Mozilla\Firefox\Profiles\05r7it1e.default-1419879444015\cookies.sqlite:ads.adplxmd.com
   C:\Documents and Settings\rtest\Application Data\Mozilla\Firefox\Profiles\05r7it1e.default-1419879444015\cookies.sqlite:ads.bg-mamma.com
   C:\Documents and Settings\rtest\Application Data\Mozilla\Firefox\Profiles\05r7it1e.default-1419879444015\cookies.sqlite:ads.creative-serving.com
   C:\Documents and Settings\rtest\Application Data\Mozilla\Firefox\Profiles\05r7it1e.default-1419879444015\cookies.sqlite:ads.kaldata.com
   C:\Documents and Settings\rtest\Application Data\Mozilla\Firefox\Profiles\05r7it1e.default-1419879444015\cookies.sqlite:ads.stickyadstv.com
   C:\Documents and Settings\rtest\Application Data\Mozilla\Firefox\Profiles\05r7it1e.default-1419879444015\cookies.sqlite:advertising.com
   C:\Documents and Settings\rtest\Application Data\Mozilla\Firefox\Profiles\05r7it1e.default-1419879444015\cookies.sqlite:at.atwola.com
   C:\Documents and Settings\rtest\Application Data\Mozilla\Firefox\Profiles\05r7it1e.default-1419879444015\cookies.sqlite:atdmt.com
   C:\Documents and Settings\rtest\Application Data\Mozilla\Firefox\Profiles\05r7it1e.default-1419879444015\cookies.sqlite:casalemedia.com
   C:\Documents and Settings\rtest\Application Data\Mozilla\Firefox\Profiles\05r7it1e.default-1419879444015\cookies.sqlite:diff3.smartadserver.com
   C:\Documents and Settings\rtest\Application Data\Mozilla\Firefox\Profiles\05r7it1e.default-1419879444015\cookies.sqlite:doubleclick.net
   C:\Documents and Settings\rtest\Application Data\Mozilla\Firefox\Profiles\05r7it1e.default-1419879444015\cookies.sqlite:ru4.com
   C:\Documents and Settings\rtest\Application Data\Mozilla\Firefox\Profiles\05r7it1e.default-1419879444015\cookies.sqlite:serving-sys.com
   C:\Documents and Settings\rtest\Application Data\Mozilla\Firefox\Profiles\05r7it1e.default-1419879444015\cookies.sqlite:smartadserver.com
   C:\Documents and Settings\rtest\Application Data\Mozilla\Firefox\Profiles\05r7it1e.default-1419879444015\cookies.sqlite:statcounter.com
   C:\Documents and Settings\rtest\Application Data\Mozilla\Firefox\Profiles\05r7it1e.default-1419879444015\cookies.sqlite:yadro.ru
   C:\Documents and Settings\rtest\Cookies\[email protected][2].txt
   C:\Documents and Settings\rtest\Cookies\rtest@doubleclick[2].txt
 
  • Автор

Липсва лог файла от Malwarebytes Anti-malware. :)

Мда, лекинко съм го пропуснала ... :shy11:

 

Ето го

 

Malwarebytes Anti-Malware

www.malwarebytes.org

Scan Date: 1/3/2015

Scan Time: 7:43:11 PM

Logfile:

Administrator: Yes

Version: 2.00.4.1028

Malware Database: v2015.01.03.07

Rootkit Database: v2014.12.30.01

License: Free

Malware Protection: Disabled

Malicious Website Protection: Disabled

Self-protection: Disabled

OS: Windows XP Service Pack 3

CPU: x86

File System: NTFS

User: rtest

Scan Type: Threat Scan

Result: Completed

Objects Scanned: 293546

Time Elapsed: 11 min, 17 sec

Memory: Enabled

Startup: Enabled

Filesystem: Enabled

Archives: Enabled

Rootkits: Enabled

Heuristics: Enabled

PUP: Enabled

PUM: Enabled

Processes: 0

(No malicious items detected)

Modules: 0

(No malicious items detected)

Registry Keys: 2

PUP.Optional.uTorrentBar.A, HKLM\SOFTWARE\uTorrentBar, Quarantined, [8879f37653292e08a9f60d6401028977],

PUP.Optional.uTorrentBar.A, HKU\S-1-5-21-515967899-602609370-1417001333-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\uTorrentBar, Quarantined, [946d17520775af870997b3bed72c60a0],

Registry Values: 0

(No malicious items detected)

Registry Data: 3

PUM.Disabled.SecurityCenter, HKLM\SOFTWARE\MICROSOFT\SECURITY CENTER|AntiVirusDisableNotify, 1, Good: (0), Bad: (1),Replaced,[e51ce78280fc67cf2286245db253867a]

PUM.Disabled.SecurityCenter, HKLM\SOFTWARE\MICROSOFT\SECURITY CENTER|FirewallDisableNotify, 1, Good: (0), Bad: (1),Replaced,[10f199d07dffc0767237334e8283e917]

PUM.Disabled.SecurityCenter, HKLM\SOFTWARE\MICROSOFT\SECURITY CENTER|UpdatesDisableNotify, 1, Good: (0), Bad: (1),Replaced,[c33eb7b21d5fa393b2f8027f0ff6e020]

Folders: 0

(No malicious items detected)

Files: 1

PUP.Optional.OneClickDownloader.A, C:\Documents and Settings\rtest\My Documents\Downloads\Jessica_Drossin_Photo_Overlay_Textures_Vol_3_rar.exe, Quarantined, [c53cf2771567201658e75ed4cb36f30d],

Physical Sectors: 0

(No malicious items detected)

(end)

Трябва ли да правя стъпка 4 отново?

Здравейте,

 

Не, 4-таа стъпка е наред...имаме още 3 стъпки преди да приключим обаче. :)

 

 

СТЪПКА 1

 

Изтеглете обновения edit-text.giffixlist.txt и го запазете в папката от която стартирахте FRST.exe.
Стартирайте FRST.exe и натиснете бутона Fix веднъж!
След като приключи, ако ви поиска рестарт - съгласете се. След рестарта публикувайте лог файла - fixlog.txt, който ще се създаде след работата на програмата.
 
Внимание: Скрипта е създаден за текущата система. Да не се ползва за други системи с подобни проблеми!

 

 

 

СТЪПКА 2 (това е една бавна и мъчителна стъпка, но няма начин...съветвам ви да я изпълните през нощта за да не чакате...).

 

  • Моля изтеглете и стартирайте exe файла от линка отдолу:
    ESET OnlineScan
  • Сложете отметка пред esetAcceptTerms.png
  • Натиснете бутона esetStart.png и изчакайте компонентите да се инсталират.
  • Сложете отметка пред: Enable detection of potentially unwanted applications
  • Сеха натиснете линка с името Advanced Settings и се уверете, че няма отметка пред Remove found threats.
  • Сложете следните други отметки:
    • Scan archives
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
    • Click on the Change button and select only Operating memory and drive C:\

fhSji42.png

 

  • Натиснете бутона esetStart.png.
  • Програмата ще започне да тегли и инсталира ъпдейти и след това ще започне да проверява вашата система.Бъдете търпеливи, защото проверката е доста бавно и може да отнеме повече време (за предпочтане е да я направите, когато имате време и не сте пред компютъра, например през нощта докато спите).
  • След като сканирането приключи натиснете бутона esetListThreats.png
  • Сега натиснете линка esetExport.pngи запазете файла с име по ваш избор като например ESETScan.txt.
  • Натиснете бутона esetBack.png.
  • След това натиснете бутона esetFinish.png
  • Публикувайте лог файла в следващия си коментар.

 

 

СТЪПКА 3

 

 

Както и да видим за стар и уязвим софтуер:

 

 

Изтеглете Security Check от screen317 от този линк или и го запаметете на вашия десктоп.
Кликнете два пъти върху SecurityCheck.exe и следвайте инструкциите.
Накрая, автоматично ще се отвори текстов документ, наречен checkup.txt, моля прикачете го в следващия ви коментар в тази тема.

 

 

Това е...на финалната права сме! :)

Поздрави!

  • Автор

Привет.

 

От fixlog

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 07-01-2015
Ran by rtest at 2015-01-07 19:55:15 Run:2
Running from C:\Documents and Settings\rtest\My Documents\Downloads
Loaded Profile: rtest (Available profiles: rtest)
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
start
DeleteKey: HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\winzipersvc
end
*****************

HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\winzipersvc => Key Deleted successfully.

==== End of Fixlog 19:55:15 ====

  • Автор

C:\AdwCleaner\Quarantine\C\Documents and Settings\rtest\Local Settings\Application Data\Conduit\CT2786678\uTorrentBarAutoUpdaterHelper.exe.vir    a variant of Win32/Toolbar.Conduit.X potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\Conduit\Community Alerts\Alert.dll.vir    Win32/Toolbar.Conduit.Y potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\Conduit\Community Alerts\Alert0.dll.vir    Win32/Toolbar.Conduit.Y potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\Conduit\Community Alerts\Alert1.dll.vir    Win32/Toolbar.Conduit.Y potentially unwanted application
C:\Documents and Settings\rtest\Desktop\Adobe\utorrent.exe    a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application
C:\Documents and Settings\rtest\Desktop\Old Firefox Data\u4egywgh.default\extensions\[email protected]\chrome\content\js\epurls.js    JS/Trackware.Agent.A potentially unwanted application
C:\Documents and Settings\rtest\Desktop\Old Firefox Data\u4egywgh.default\extensions\[email protected]\chrome\content\js\inject.js    JS/Trackware.Agent.A potentially unwanted application
C:\Documents and Settings\rtest\My Documents\Downloads\Setup.exe    Win32/InstallMate potentially unwanted application
C:\Documents and Settings\rtest\My Documents\Downloads\Adobe Photoshop Lightroom v4.1 Final (x32-x64)\Keygen.rar    a variant of Win32/Keygen.DO potentially unsafe application
C:\Documents and Settings\rtest\My Documents\Downloads\Recuva 1.44.778\rcsetup144.exe    Win32/Bundled.Toolbar.Google.E potentially unsafe application
C:\FRST\Quarantine\C\Documents and Settings\All Users\Application Data\IePluginServices\PluginService.exe    a variant of Win32/ELEX.AV potentially unwanted application
C:\FRST\Quarantine\C\Documents and Settings\All Users\Application Data\WindowsMangerProtect\ProtectWindowsManager.exe    a variant of Win32/ELEX.BH potentially unwanted application
C:\FRST\Quarantine\C\Documents and Settings\All Users\Application Data\WindowsMangerProtect\update\update.exe    a variant of Win32/ELEX.BD potentially unwanted application
C:\FRST\Quarantine\C\Program Files\SupTab\DpInterface32.dll    Win32/Thinknice.E potentially unwanted application
C:\FRST\Quarantine\C\Program Files\SupTab\DpInterface64.dll    Win64/Thinknice.F potentially unwanted application
C:\FRST\Quarantine\C\Program Files\SupTab\HpUI.exe    Win32/Thinknice.E potentially unwanted application
C:\FRST\Quarantine\C\Program Files\SupTab\Loader32.exe    Win32/Thinknice.E potentially unwanted application
C:\FRST\Quarantine\C\Program Files\SupTab\Loader64.exe    Win64/Thinknice.E potentially unwanted application
C:\FRST\Quarantine\C\Program Files\SupTab\msvcp110.dll    a variant of Win32/Thinknice.F potentially unwanted application
C:\FRST\Quarantine\C\Program Files\SupTab\msvcr110.dll    a variant of Win32/Thinknice.F potentially unwanted application
C:\FRST\Quarantine\C\Program Files\SupTab\RSHP.exe    a variant of Win32/ELEX.BF potentially unwanted application
C:\FRST\Quarantine\C\Program Files\SupTab\SearchProtect32.dll    Win32/Thinknice.E potentially unwanted application
C:\FRST\Quarantine\C\Program Files\SupTab\SearchProtect64.dll    Win64/Thinknice.F potentially unwanted application
C:\FRST\Quarantine\C\Program Files\SupTab\SupIePluginServiceUpdate.exe    a variant of Win32/ELEX.AV potentially unwanted application
C:\FRST\Quarantine\C\Program Files\SupTab\SupTab.dll    Win32/Thinknice.B potentially unwanted application
C:\FRST\Quarantine\C\Program Files\SupTab\uninstall.exe    Win32/Thinknice.E potentially unwanted application
C:\FRST\Quarantine\C\Program Files\SupTab\WindowsSupportDll32.dll    Win32/Thinknice.E potentially unwanted application
C:\FRST\Quarantine\C\Program Files\SupTab\WindowsSupportDll64.dll    Win64/Thinknice.D potentially unwanted application
C:\FRST\Quarantine\C\Program Files\uTorrentBar\hk64tbuTo0.dll    a variant of Win64/Toolbar.Conduit.B potentially unwanted application
C:\FRST\Quarantine\C\Program Files\uTorrentBar\hk64tbuTo2.dll    a variant of Win64/Toolbar.Conduit.B potentially unwanted application
C:\FRST\Quarantine\C\Program Files\uTorrentBar\hktbuTo0.dll    a variant of Win32/Toolbar.Conduit.X potentially unwanted application
C:\FRST\Quarantine\C\Program Files\uTorrentBar\hktbuTo2.dll    a variant of Win32/Toolbar.Conduit.X potentially unwanted application
C:\FRST\Quarantine\C\Program Files\uTorrentBar\ldrtbuTo0.dll    a variant of Win32/Toolbar.Conduit.P potentially unwanted application
C:\FRST\Quarantine\C\Program Files\uTorrentBar\ldrtbuTo2.dll    a variant of Win32/Toolbar.Conduit.P potentially unwanted application
C:\FRST\Quarantine\C\Program Files\uTorrentBar\prxtbuTo0.dll    a variant of Win32/Toolbar.Conduit.X potentially unwanted application
C:\FRST\Quarantine\C\Program Files\uTorrentBar\prxtbuTo2.dll    Win32/Toolbar.Conduit.N potentially unwanted application
C:\FRST\Quarantine\C\Program Files\uTorrentBar\tbuTo0.dll    a variant of Win32/Toolbar.Conduit.X potentially unwanted application
C:\FRST\Quarantine\C\Program Files\uTorrentBar\tbuTo1.dll    a variant of Win32/Toolbar.Conduit.Y potentially unwanted application
C:\FRST\Quarantine\C\Program Files\uTorrentBar\tbuTo2.dll    a variant of Win32/Toolbar.Conduit.X potentially unwanted application
C:\FRST\Quarantine\C\Program Files\uTorrentBar\tbuTor.dll    a variant of Win32/Toolbar.Conduit.B potentially unwanted application
C:\FRST\Quarantine\C\Program Files\uTorrentBar\uTorrentBarToolbarHelper.exe    Win32/Toolbar.Conduit.V potentially unwanted application
C:\Program Files\Futuremark\PCMark05\patch.exe    a variant of Win32/Keygen.CS potentially unsafe application
 


 Results of screen317's Security Check version 0.99.93  
 Windows XP Service Pack 3 x86   
 Internet Explorer 7 Out of date!
``````````````Antivirus/Firewall Check:``````````````
 Windows Firewall Enabled!  
avast! Antivirus   
 Antivirus up to date!  
`````````Anti-malware/Other Utilities Check:`````````
 Spyder2express     
  Adobe Flash Player     15.0.0.246 Flash Player out of Date!  
 Adobe Reader 10.1.4 Adobe Reader out of Date!  
 Mozilla Firefox (34.0.5)
````````Process Check: objlist.exe by Laurent````````  
 AVAST Software Avast avastUI.exe  
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C:: 41% Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````
 


Май направих всичко. :)

Поздрави.

Здравейте,

 

Извинявам се за закъснението, но имах служебни ангажименти:

 

 

СТЪПКА 1

 

Изтеглете обновения edit-text.giffixlist.txt и го запазете в папката от която стартирахте FRST.exe.
Стартирайте FRST.exe и натиснете бутона Fix веднъж!
След като приключи, ако ви поиска рестарт - съгласете се. След рестарта публикувайте лог файла - fixlog.txt, който ще се създаде след работата на програмата.
 
Внимание: Скрипта е създаден за текущата система. Да не се ползва за други системи с подобни проблеми!

 

 

 

СТЪПКА 2

 

 

Изтеглете и инсталирайте следните актуализации:

 

software.gif Изтегли: Internet Explorer 8.0 Final за Windows XP x32

software.gif Изтегли: Adobe Flash Player 16.0.0.235 Final за (Internet Explorer)
software.gif Изтегли: Adobe Flash Player 16.0.0.235 Final за (Firefox, Safari, Opera)

software.gif Изтегли: Adobe Reader 11.0.10

 

Проверете и за други стари приложения с помощта на PatchMyPC.

 

 

И няколко финални препоръки.
 

 

3. За да почистим използваните от нас инструменти направете следното:

 

3.1 Изтеглете OTC.exe и го стартирайте. Натиснете бутона CleanUp!
Рестартирайте компютъра, ако ви попита!
 

3.2 Изтеглете Delfix.exe и го стартирайте. Сложете отметка пред Remove disinfection tools (трябва да има такава по-подразбиране, но все пак да си кажа) => натиснете бутона Run

Инструмента ще се самоизтрие след като приключи своята задача! Ако има папки, които не са се изтрили след гореспоменатите процедури пишете и ще ги премахнем ръчно.

 

 

4. За подобряване на производителността (ако системата ви се вижда мудна) вижте следните няколко теми:

 

Оптимизиране на Windows с цел по-добра производителност

Ръководство за поддръжка на Windows (XP, Vista и 7) [Revision 2.0]

Какво да направя, ако компютърът ми работи бавно

Профилактика на компютъра,как?

 

Направете и една дефрагментация с MyDefrag за повишаване на производителността при дисковите операции: (ще се отрази благоприятно и при често използваните програми):

 

Забележка: (само ако диска не е SSD)!

 

Изтеглете MyDefrag и я инсталирайте.

 

Отворете следната папка C:\Program Files\MyDefrag v4.3.1\Scripts и изтрийте всички файлове в нея.

 

Изтеглете следния архив и го разархивирайте в C:\Program Files\MyDefrag v4.3.1\Scripts, която е празна в момента.

 

Стартирайте MyDefrag.exe и изберете System Disk Level V и посочете системния дял C: и натиснете Run

 

KcdlAEi.jpg

 

Може да отнеме доста време, защото за основа на скрипта са използвани скриптовете на Jaspion и на някои други потребители + мои лични настройки и модификации.

Скрипта ще направи приоритизация на често използваните програми и файлове.

След като приключи ще изпише Finished и можете да затворите програмата от X-са.

 

Рестартирайте системата.

 

5. Проверете системата си актуални драйвери от сайтовете на производителите на компонентите ако ви се занимава (не използвайте програми за автоматично обновяване на драйверите за да си спестите главоболията после).

 

6. Инсталирайте Unchecky за да се предпазите от адуерчета, които се опитват да се инсталират по време на инсталация на безплатен софтуер.

 

Поздрави и приятни почивни дни! Ще маркирам случая като РЕШЕН! :bye1:

  • Автор

Eто ме и мен

 

И файлът:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 07-01-2015
Ran by rtest at 2015-01-10 16:43:56 Run:3
Running from C:\Documents and Settings\rtest\My Documents\Downloads
Loaded Profile: rtest (Available profiles: rtest)
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
start
C:\Documents and Settings\rtest\Desktop\Adobe\utorrent.exe
C:\Documents and Settings\rtest\Desktop\Old Firefox Data\u4egywgh.default\extensions\[email protected]
C:\Documents and Settings\rtest\My Documents\Downloads\Setup.exe
end
*****************

C:\Documents and Settings\rtest\Desktop\Adobe\utorrent.exe => Moved successfully.
C:\Documents and Settings\rtest\Desktop\Old Firefox Data\u4egywgh.default\extensions\[email protected] => Moved successfully.
C:\Documents and Settings\rtest\My Documents\Downloads\Setup.exe => Moved successfully.

==== End of Fixlog 16:44:03 ====

Как е сега положението? Мисля, че сме готови. Само вижте и последните ми препоръки от предишния коментар. :)

 

Поздрави!

  • Автор

Не съм направила точка 4, но предните мисля, приключиха успешно. :))


Отново много благодаря за страхотния форум, чудесната помощ, отзивчивост, компетентност и отношение!

Успехи във всички начинания ви желая! Благодаря. :)

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.