Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Проблем с уеб браузър."Имате инсталиран в системата зловреден софтуер!"

Featured Replies

Здравейте,всеки път когато стартирам своя браузър, а и други програми ми излиза следната грешка.
"There was a problem starting C:\Program Files\Settings Manager\systemk\sysapcrt.dll
Access is denied."
След като потвърдя с ОК,браузърът си стартира нормално,но е досадно всеки път да има ерор.
ОС е уиндоус 7.Не съм инсталирал нов софтуер наскоро.

 

Не разполагам с нов диск за операционната си система.

 

Това са логовете, които имам от препоръчаната от Вас програма.

 

Съдържанието на FRST.txt

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-01-2015 01
Ran by myPC (administrator) on myPC on 27-01-2015 12:18:26
Running from C:\Users\myPC\Desktop
Loaded Profiles: myPC (Available profiles: myPC)
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Motorola) C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(StarWind Software) C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Aztec Media Inc) C:\Program Files (x86)\Settings Manager\systemk\SystemkService.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(Aztec Media Inc) C:\Program Files (x86)\Settings Manager\systemk\SystemkService.exe
() D:\garena\Garena Plus\ggdllhost.exe
(Aztec Media Inc) C:\Program Files (x86)\Settings Manager\systemk\systemku.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\audiodg.exe
() D:\garena\Garena Plus\GarenaMessenger.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_296.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_296.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [5581888 2014-02-24] (ESET)
HKLM-x32\...\Run: [bCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2583040 2009-09-21] (VIA)
HKLM-x32\...\Run: [sunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKU\S-1-5-21-3522770205-4233124857-3227214610-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [6501656 2014-10-30] (Piriform Ltd)
IFEO\bitguard.exe: [Debugger] tasklist.exe
IFEO\bprotect.exe: [Debugger] tasklist.exe
IFEO\bpsvc.exe: [Debugger] tasklist.exe
IFEO\browserdefender.exe: [Debugger] tasklist.exe
IFEO\browserprotect.exe: [Debugger] tasklist.exe
IFEO\browsersafeguard.exe: [Debugger] tasklist.exe
IFEO\dprotectsvc.exe: [Debugger] tasklist.exe
IFEO\jumpflip: [Debugger] tasklist.exe
IFEO\protectedsearch.exe: [Debugger] tasklist.exe
IFEO\searchinstaller.exe: [Debugger] tasklist.exe
IFEO\searchprotection.exe: [Debugger] tasklist.exe
IFEO\searchprotector.exe: [Debugger] tasklist.exe
IFEO\searchsettings.exe: [Debugger] tasklist.exe
IFEO\searchsettings64.exe: [Debugger] tasklist.exe
IFEO\snapdo.exe: [Debugger] tasklist.exe
IFEO\stinst32.exe: [Debugger] tasklist.exe
IFEO\stinst64.exe: [Debugger] tasklist.exe
IFEO\umbrella.exe: [Debugger] tasklist.exe
IFEO\utiljumpflip.exe: [Debugger] tasklist.exe
IFEO\volaro: [Debugger] tasklist.exe
IFEO\vonteera: [Debugger] tasklist.exe
IFEO\websteroids.exe: [Debugger] tasklist.exe
IFEO\websteroidsservice.exe: [Debugger] tasklist.exe
HKLM\...\AppCertDlls: [x64] -> C:\Program Files (x86)\Settings Manager\systemk\x64\sysapcrt.dll [664592 2014-05-18] ()
HKLM\...\AppCertDlls: [x86] -> C:\Program Files (x86)\Settings Manager\systemk\sysapcrt.dll [490000 2014-05-18] ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-21-3522770205-4233124857-3227214610-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.softonic.com/INF00176/tb_v1?SearchSource=10&cc=&mi=8073f234000000000000001966fa4207
HKU\S-1-5-21-3522770205-4233124857-3227214610-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
SearchScopes: HKU\S-1-5-21-3522770205-4233124857-3227214610-1000 -> DefaultScope {0FB51F6C-83D2-4836-88DF-8CF4E4DF0CBC} URL = http://search.softonic.com/INF00176/tb_v1?q={searchTerms}&SearchSource=4&cc=&mi=8073f234000000000000001966fa4207&r=218
SearchScopes: HKU\S-1-5-21-3522770205-4233124857-3227214610-1000 -> {0FB51F6C-83D2-4836-88DF-8CF4E4DF0CBC} URL = http://search.softonic.com/INF00176/tb_v1?q={searchTerms}&SearchSource=4&cc=&mi=8073f234000000000000001966fa4207&r=218
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 78.159.128.2 78.159.128.3

FireFox:
========
FF ProfilePath: C:\Users\myPC\AppData\Roaming\Mozilla\Firefox\Profiles\38gkhptu.default-1418649727470
FF Homepage: hxxp://www.google.bg/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_296.dll ()
FF Plugin: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1207148.dll (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @t.garena.com/garenatalk -> D:\garena\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll ( Garena)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> D:\vlc\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> D:\vlc\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> D:\vlc\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> D:\vlc\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\default-search.xml
FF Extension: ABV Notifier - C:\Users\myPC\AppData\Roaming\Mozilla\Firefox\Profiles\38gkhptu.default-1418649727470\Extensions\[email protected] [2014-12-15]
FF Extension: FlashGot - C:\Users\myPC\AppData\Roaming\Mozilla\Firefox\Profiles\38gkhptu.default-1418649727470\Extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi [2015-01-10]
FF Extension: Adblock Plus - C:\Users\myPC\AppData\Roaming\Mozilla\Firefox\Profiles\38gkhptu.default-1418649727470\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-12-15]
FF HKLM\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2014-08-27]
FF HKLM-x32\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird

Chrome:
=======
CHR Profile: C:\Users\myPC\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Документи) - C:\Users\myPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-16]
CHR Extension: (Google Диск) - C:\Users\myPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-16]
CHR Extension: (YouTube) - C:\Users\myPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-16]
CHR Extension: (Google Търсене) - C:\Users\myPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-16]
CHR Extension: (Google Wallet) - C:\Users\myPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-16]
CHR Extension: (Gmail) - C:\Users\myPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-16]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [1343408 2014-02-24] (ESET)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1721800 2014-08-09] (NVIDIA Corporation)
R2 PST Service; C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe [65657 2011-09-02] (Motorola) [File not signed]
R2 StarWindServiceAE; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [File not signed]
R2 SystemkService; C:\Program Files (x86)\Settings Manager\systemk\SystemkService.exe [3543056 2014-05-18] (Aztec Media Inc)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [239320 2013-09-17] (ESET)
U5 edevmon; C:\Windows\System32\Drivers\edevmon.sys [239296 2013-09-17] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [168256 2013-09-17] (ESET)
R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [59440 2012-10-08] (ESET)
R2 epfwwfpr; C:\Windows\System32\DRIVERS\epfwwfpr.sys [157432 2013-09-17] (ESET)
R1 F06DEFF2-5B9C-490D-910F-35D3A9119622; C:\Program Files (x86)\Settings Manager\systemk\x64\systemkmgrc1.cfg [36240 2014-05-18] (Aztec Media Inc)
R0 FSProFilter; C:\Windows\System32\Drivers\FSPFltd.sys [54848 2010-07-22] (FSPro Labs)
S4 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
S3 RTL8187B; C:\Windows\System32\DRIVERS\RTL8187B.sys [416768 2009-06-10] (Realtek Semiconductor Corporation                           )
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2014-06-21] (Duplex Secure Ltd.)
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation)
U3 ahsxfwvb; No ImagePath
S3 APackDrv; \??\C:\Windows\SysWOW64\Drivers\APackDrv.sys [X]
S3 GGSAFERDriver; \??\D:\garena\Garena Plus\Room\safedrv.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-27 12:18 - 2015-01-27 12:18 - 00014040 _____ () C:\Users\myPC\Desktop\FRST.txt
2015-01-27 12:16 - 2015-01-27 12:18 - 00000000 ____D () C:\FRST
2015-01-27 12:13 - 2015-01-27 12:14 - 02129920 _____ (Farbar) C:\Users\myPC\Desktop\FRST64.exe
2015-01-27 00:08 - 2015-01-27 00:08 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-26 16:15 - 2015-01-27 12:05 - 00005264 _____ () C:\Windows\setupact.log
2015-01-26 16:15 - 2015-01-26 16:15 - 00000000 _____ () C:\Windows\setuperr.log
2015-01-22 22:50 - 2015-01-25 23:22 - 00000000 ____D () C:\Users\myPC\Desktop\5 i 6
2015-01-22 22:48 - 2015-01-22 22:48 - 00000000 ____D () C:\Users\myPC\Desktop\posledna lekciq MO
2015-01-22 00:22 - 2015-01-22 00:22 - 00000000 ____D () C:\Users\myPC\Desktop\OTD MARIQ S IMENA
2015-01-20 01:46 - 2015-01-25 03:00 - 00000000 ____D () C:\Users\myPC\Desktop\shit
2015-01-16 00:53 - 2015-01-16 00:54 - 00000000 ____D () C:\Users\myPC\Documents\Fax
2015-01-15 20:57 - 2015-01-22 00:22 - 00000000 ____D () C:\Users\myPC\Desktop\Отд Мария
2015-01-15 20:07 - 2015-01-15 20:09 - 00000187 _____ () C:\Users\myPC\Desktop\МО най-чести теми.txt
2015-01-14 14:42 - 2015-01-14 14:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BitComet
2015-01-13 00:38 - 2015-01-13 00:38 - 00000028 _____ () C:\Users\myPC\Desktop\mo.txt

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-27 12:11 - 2014-07-08 22:50 - 00000000 ____D () C:\ProgramData\systemk
2015-01-27 12:11 - 2014-06-21 21:33 - 00000000 ____D () C:\Users\myPC\AppData\Roaming\GarenaPlus
2015-01-27 12:11 - 2014-06-21 21:33 - 00000000 ____D () C:\ProgramData\GarenaMessenger
2015-01-27 12:08 - 2013-02-03 10:06 - 01588818 _____ () C:\Windows\WindowsUpdate.log
2015-01-27 12:05 - 2014-12-20 12:55 - 00003418 _____ () C:\Windows\System32\Tasks\gg_uac_daemon_myPC
2015-01-27 12:05 - 2014-12-16 20:40 - 00000994 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-27 12:05 - 2014-08-27 12:55 - 00000360 _____ () C:\Windows\Tasks\DriverToolkit Autorun.job
2015-01-27 12:05 - 2013-02-03 10:35 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-01-27 12:05 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-27 12:04 - 2013-02-03 10:19 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-01-27 03:51 - 2013-02-03 10:49 - 00000000 ____D () C:\Users\myPC\AppData\Roaming\uTorrent
2015-01-27 03:51 - 2009-07-14 06:45 - 00026144 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-27 03:51 - 2009-07-14 06:45 - 00026144 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-27 03:46 - 2014-12-16 20:41 - 00002181 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-01-27 03:46 - 2014-12-16 20:40 - 00000998 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-27 03:41 - 2009-07-14 07:32 - 00000000 ____D () C:\Windows\system32\FxsTmp
2015-01-27 02:56 - 2013-02-03 11:16 - 00000000 ____D () C:\Users\myPC\AppData\Roaming\vlc
2015-01-27 02:53 - 2013-02-18 15:08 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-01-27 01:27 - 2014-01-12 12:38 - 00045270 _____ () C:\Users\myPC\AppData\Roaming\room_v3.dat
2015-01-26 23:03 - 2009-07-14 07:13 - 00786598 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-26 22:37 - 2013-11-22 13:39 - 00000000 ____D () C:\Program Files (x86)\The KMPlayer
2015-01-25 22:53 - 2013-02-18 15:08 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-01-25 22:53 - 2013-02-03 10:43 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-01-25 22:53 - 2013-02-03 10:43 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-24 18:45 - 2013-02-03 14:31 - 00000000 ____D () C:\Users\myPC\AppData\Roaming\Skype
2015-01-24 18:01 - 2014-09-19 14:35 - 00000000 ___RD () C:\Program Files (x86)\Skype
2015-01-24 18:01 - 2013-02-03 14:31 - 00000000 ____D () C:\ProgramData\Skype
2015-01-23 22:27 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2015-01-09 19:01 - 2014-04-14 11:28 - 00000000 ____D () C:\Program Files (x86)\Settings Manager

==================== Files in the root of some directories =======

2014-01-12 12:38 - 2015-01-27 01:27 - 0045270 _____ () C:\Users\myPC\AppData\Roaming\room_v3.dat
2014-08-27 12:24 - 2014-08-27 12:27 - 0000003 _____ () C:\Users\myPC\AppData\Local\user_data.ini

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe
[2014-05-14 19:26] - [2011-01-16 02:01] - 0389632 ____A (Microsoft Corporation) 81257415084B84F3C0D95C381A8D4C8F

C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll
[2010-11-21 05:24] - [2011-01-16 02:01] - 1008640 ____A (Microsoft Corporation) 0B864E15A0BADFF0E7BB8B59009FDDCF

C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-01-24 19:24

==================== End Of Log ============================

 

 

 

Прикачвам Addition.txt.

Addition.txt

Редактирано от icotonev (преглед на промените)

Добър вечер..! :)

 

remove%20outdated.jpg Деинсталиране нa програми
 
Изтеглете програмата GeekUninstaller и я запазете на десктопа.
Разархивирайте я и стартирайте файла geek.exe IxXO5oO.jpg  От списъка намерете и деинсталирайте всички програми които съм ви написал в карето:

 

Settings Manager

YTD Video Downloader 4.7.4

 

Кликнете с десен бутон върху програмата и изберете Uninstall
 
XhV2QLa.png
 
 
След края на всяка деинсталацията ще се отвори прозорец подканващ ви да премахнете всички остатъци от програмата (ако има такива, ако няма този прозорец няма да се появи):
 
Пример:
 
geek-uninstaller-remove-leftovers.png
 
Натиснете бутона Finish за да изтриете останките от програмата.

 

 

 

adwcleaner_new.png Сканиране с AdwCleaner
 
Моля, изтеглете и стартирайте програмата AdwCleaner (by Xplode):

  • Затворете всички стартирани програми и браузъри
  • Кликнете два пъти върху adwcleaner.exe за да стартирате инструмента.
  • Натиснете OK, за да потвърдите, че всички стартирани програми ще бъдат затворени.
  • Маркирайте Clean
  • Вашият компютър ще се рестартира автоматично. Текстовия файл ще се отвори след рестарта.
  • Моля, да публикувате съдържанието на този лог в отговора си
  • Можете да намерите лога,който автоматично се запомня тук C:AdwCleaner[s0].txt

 

JRTbythisisu.png Сканиране с Junkware Removal Tool
 
Моля, изтеглете Junkware Removal Tool (by Thisisu ) и запазете на вашия десктоп.

  • Спрете временно работата на защитните програми.
  • Стартирайте инструмента JRT.exe
  • Ще се отвори ДОС прозорец. Натиснете което и да е копче от клавиатурата.
  • Затворете излишните приложения и всички браузъри и изчакайте проверката да завърши.
  • Ще се появи лог файл (който можете да намерите и ръчно на десктопа с името JRT.txt).
  • Моля копирайте съдържанието на лог файла в следващия си пост.

 

FRST.gif Сканиране с Farbar Recovery Scan Tool

Повторете сканирането с Farbar Recovery Scan Tool

 

 

xpfNZP4A.png.pagespeed.ic.bp5cRl1pJg.jpg  Дневници
 
В следващия си отговор, моля да включите следните дневници:

  • FRST.txt
  • Addition.txt
  • JRT.txt
  • AdwCleaner[s0].txt
  • Автор

Ето лога от AdwCleaner.

# AdwCleaner v4.109 - Report created 28/01/2015 at 16:31:02
# Updated 24/01/2015 by Xplode
# Database : 2015-01-26.1 [Live]
# Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)
# Username : my pc
# Running from : C:\Users\CryptR\Desktop\adwcleaner_4.109.exe
# Option : Clean

***** [ Services ] *****

Service Deleted : F06DEFF2-5B9C-490D-910F-35D3A9119622
[#] Service Deleted : SystemkService

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\systemk
Folder Deleted : C:\Program Files (x86)\GreenTree Applications
Folder Deleted : C:\Program Files (x86)\Settings Manager
Folder Deleted : C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\FirefoxToolbar
Folder Deleted : C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Settings Manager
Folder Deleted : C:\Users\CryptR\AppData\Local\eSupport.com
Folder Deleted : C:\Users\CryptR\AppData\Roaming\RHEng
File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\default-search.xml

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Value Deleted : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64]
Value Deleted : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x86]
Value Deleted : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x64]
Value Deleted : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x86]
Key Deleted : HKLM\SOFTWARE\Classes\SettingsManagerIEHelper.DNSGuard.1
Key Deleted : HKLM\SOFTWARE\Classes\SettingsManagerIEHelper.DNSGuard
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{54739D49-AC03-4C57-9264-C5195596B3A1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E1842850-FB16-4471-B327-7343FBAED55C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AA760BA8-5862-4BC5-9263-4452CBC0B264}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{93D511B5-143B-4A99-ABFC-B5B78AD0AE1B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{54739D49-AC03-4C57-9264-C5195596B3A1}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{54739D49-AC03-4C57-9264-C5195596B3A1}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{E1842850-FB16-4471-B327-7343FBAED55C}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{AA760BA8-5862-4BC5-9263-4452CBC0B264}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4613B1C1-FBC0-43C3-A4B9-B1D6CD360BB3}
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\eSupport.com
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Deleted : HKLM\SOFTWARE\dt soft\daemon tools toolbar
Key Deleted : HKLM\SOFTWARE\PIP
Key Deleted : HKLM\SOFTWARE\SystemK
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IM
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe

***** [ Browsers ] *****

-\\ Internet Explorer v0.0.0.0


-\\ Mozilla Firefox v35.0.1 (x86 en-US)


-\\ Google Chrome v40.0.2214.93

[C:\Users\CryptR\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [search Provider] : hxxp://www.ask.com/web?q={searchTerms}

*************************

AdwCleaner[R0].txt - [4754 octets] - [28/01/2015 16:28:13]
AdwCleaner[s0].txt - [4454 octets] - [28/01/2015 16:31:02]

########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [4514 octets] ##########




Ето лога и от JRT

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.1 (12.28.2014:1)
OS: Windows 7 Ultimate x64
Ran by my pc on 28-Jan-15 at 16:18:55.85
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services

Failed to stop: [service] f06deff2-5b9c-490d-910f-35d3a9119622



~~~ Registry Values

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-3522770205-4233124857-3227214610-1000\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\AskPIP_FF__RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\AskPIP_FF__RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\outobox1120_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\outobox1120_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\outobox_Setup_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\outobox_Setup_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\updateoutobox_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\updateoutobox_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\utiloutobox_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\utiloutobox_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_for_kmplayer_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_for_kmplayer_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\Softonic_chr_1-8-19-3_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\Softonic_chr_1-8-19-3_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\AskPIP_FF__RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\AskPIP_FF__RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\outobox1120_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\outobox1120_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\outobox_Setup_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\outobox_Setup_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\updateoutobox_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\updateoutobox_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\utiloutobox_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\utiloutobox_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_for_kmplayer_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_for_kmplayer_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\Softonic_chr_1-8-19-3_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\Softonic_chr_1-8-19-3_RASMANCS
Successfully deleted: [Registry Key] "hkey_current_user\software\apn pip"
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0FB51F6C-83D2-4836-88DF-8CF4E4DF0CBC}



~~~ Files

Successfully deleted: [File] C:\Windows\Tasks\DriverToolkit Autorun.job



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\apn"
Successfully deleted: [Folder] "C:\Users\CryptR\AppData\Roaming\opencandy"
Successfully deleted: [Folder] "C:\Users\CryptR\AppData\Roaming\thinstall"
Successfully deleted: [Folder] "C:\Users\CryptR\appdata\local\thinstall"



~~~ FireFox

Emptied folder: C:\Users\CryptR\AppData\Roaming\mozilla\firefox\profiles\38gkhptu.default-1418649727470\minidumps [1 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 28-Jan-15 at 16:26:06.69
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 


Ето повторният лог от FRST.
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-01-2015 01
Ran by CryptR (administrator) on my pc on 28-01-2015 16:37:18
Running from C:\Users\CryptR\Desktop
Loaded Profiles: CryptR (Available profiles: CryptR)
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\audiodg.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Motorola) C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(StarWind Software) C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
() D:\garena\Garena Plus\ggdllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [5581888 2014-02-24] (ESET)
HKLM-x32\...\Run: [bCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2583040 2009-09-21] (VIA)
HKLM-x32\...\Run: [sunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKU\S-1-5-21-3522770205-4233124857-3227214610-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [6501656 2014-10-30] (Piriform Ltd)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-21-3522770205-4233124857-3227214610-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 78.159.128.2 78.159.128.3

FireFox:
========
FF ProfilePath: C:\Users\CryptR\AppData\Roaming\Mozilla\Firefox\Profiles\38gkhptu.default-1418649727470
FF Homepage: hxxp://www.google.bg/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_296.dll ()
FF Plugin: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1207148.dll (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @t.garena.com/garenatalk -> D:\garena\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll ( Garena)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> D:\vlc\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> D:\vlc\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> D:\vlc\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> D:\vlc\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: ABV Notifier - C:\Users\CryptR\AppData\Roaming\Mozilla\Firefox\Profiles\38gkhptu.default-1418649727470\Extensions\[email protected] [2014-12-15]
FF Extension: FlashGot - C:\Users\CryptR\AppData\Roaming\Mozilla\Firefox\Profiles\38gkhptu.default-1418649727470\Extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi [2015-01-10]
FF Extension: Adblock Plus - C:\Users\CryptR\AppData\Roaming\Mozilla\Firefox\Profiles\38gkhptu.default-1418649727470\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-12-15]
FF HKLM\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2014-08-27]
FF HKLM-x32\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird

Chrome:
=======
CHR Profile: C:\Users\CryptR\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Документи) - C:\Users\CryptR\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-16]
CHR Extension: (Google Диск) - C:\Users\CryptR\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-16]
CHR Extension: (YouTube) - C:\Users\CryptR\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-16]
CHR Extension: (Google Търсене) - C:\Users\CryptR\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-16]
CHR Extension: (Google Wallet) - C:\Users\CryptR\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-16]
CHR Extension: (Gmail) - C:\Users\CryptR\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-16]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [1343408 2014-02-24] (ESET)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1721800 2014-08-09] (NVIDIA Corporation)
R2 PST Service; C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe [65657 2011-09-02] (Motorola) [File not signed]
R2 StarWindServiceAE; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [239320 2013-09-17] (ESET)
U5 edevmon; C:\Windows\System32\Drivers\edevmon.sys [239296 2013-09-17] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [168256 2013-09-17] (ESET)
R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [59440 2012-10-08] (ESET)
R2 epfwwfpr; C:\Windows\System32\DRIVERS\epfwwfpr.sys [157432 2013-09-17] (ESET)
R0 FSProFilter; C:\Windows\System32\Drivers\FSPFltd.sys [54848 2010-07-22] (FSPro Labs)
S4 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
S3 RTL8187B; C:\Windows\System32\DRIVERS\RTL8187B.sys [416768 2009-06-10] (Realtek Semiconductor Corporation                           )
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2014-06-21] (Duplex Secure Ltd.)
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation)
U3 aaehs22x; No ImagePath
S3 APackDrv; \??\C:\Windows\SysWOW64\Drivers\APackDrv.sys [X]
S3 GGSAFERDriver; \??\D:\garena\Garena Plus\Room\safedrv.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-28 16:33 - 2015-01-28 16:33 - 00000056 _____ () C:\Windows\setupact.log
2015-01-28 16:33 - 2015-01-28 16:33 - 00000000 _____ () C:\Windows\setuperr.log
2015-01-28 16:32 - 2015-01-28 16:32 - 00000314 _____ () C:\Windows\PFRO.log
2015-01-28 16:28 - 2015-01-28 16:31 - 00000000 ____D () C:\AdwCleaner
2015-01-28 16:27 - 2015-01-28 16:27 - 02194432 _____ () C:\Users\CryptR\Desktop\adwcleaner_4.109.exe
2015-01-28 16:26 - 2015-01-28 16:26 - 00007733 _____ () C:\Users\CryptR\Desktop\JRT.txt
2015-01-28 16:18 - 2015-01-28 16:18 - 00000000 ____D () C:\Windows\ERUNT
2015-01-28 16:16 - 2015-01-28 16:16 - 01707939 _____ (Thisisu) C:\Users\CryptR\Desktop\JRT.exe
2015-01-27 21:22 - 2015-01-27 21:22 - 02563502 _____ () C:\Users\CryptR\Desktop\geek.zip
2015-01-27 12:19 - 2015-01-27 12:33 - 00032063 _____ () C:\Users\CryptR\Desktop\Addition.txt
2015-01-27 12:18 - 2015-01-28 16:37 - 00011317 _____ () C:\Users\CryptR\Desktop\FRST.txt
2015-01-27 12:16 - 2015-01-28 16:37 - 00000000 ____D () C:\FRST
2015-01-27 12:13 - 2015-01-27 12:14 - 02129920 _____ (Farbar) C:\Users\CryptR\Desktop\FRST64.exe
2015-01-27 00:08 - 2015-01-27 00:08 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-22 22:50 - 2015-01-25 23:22 - 00000000 ____D () C:\Users\CryptR\Desktop\5 i 6
2015-01-22 22:48 - 2015-01-22 22:48 - 00000000 ____D () C:\Users\CryptR\Desktop\posledna lekciq MO
2015-01-22 00:22 - 2015-01-22 00:22 - 00000000 ____D () C:\Users\CryptR\Desktop\OTD MARIQ S IMENA
2015-01-20 01:46 - 2015-01-25 03:00 - 00000000 ____D () C:\Users\CryptR\Desktop\shit
2015-01-16 00:53 - 2015-01-16 00:54 - 00000000 ____D () C:\Users\CryptR\Documents\Fax
2015-01-15 20:57 - 2015-01-22 00:22 - 00000000 ____D () C:\Users\CryptR\Desktop\Отд Мария
2015-01-15 20:07 - 2015-01-15 20:09 - 00000187 _____ () C:\Users\CryptR\Desktop\МО най-чести теми.txt
2015-01-14 14:42 - 2015-01-14 14:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BitComet
2015-01-13 00:38 - 2015-01-13 00:38 - 00000028 _____ () C:\Users\CryptR\Desktop\mo.txt
2015-01-11 23:43 - 2015-01-24 19:31 - 00000000 ____D () C:\Users\CryptR\Desktop\МО МИЛЕН
2015-01-11 18:42 - 2015-01-28 12:00 - 00000000 ____D () C:\Users\CryptR\Desktop\PRAVO
2015-01-11 16:23 - 2015-01-28 00:34 - 00000000 ____D () C:\Users\CryptR\Desktop\МО
2015-01-09 22:08 - 2015-01-24 22:12 - 00000000 ____D () C:\Program Files (x86)\BitComet
2015-01-07 13:06 - 2015-01-11 11:43 - 00000148 _____ () C:\Users\CryptR\Desktop\Opel Astra G VIN  security code key No. Radio Code.txt

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-28 16:33 - 2014-12-20 12:55 - 00003418 _____ () C:\Windows\System32\Tasks\gg_uac_daemon_CryptR
2015-01-28 16:33 - 2014-12-16 20:40 - 00000994 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-28 16:33 - 2013-02-03 10:35 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-01-28 16:33 - 2013-02-03 10:06 - 01632408 _____ () C:\Windows\WindowsUpdate.log
2015-01-28 16:33 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-28 16:31 - 2009-07-14 06:45 - 00026144 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-28 16:31 - 2009-07-14 06:45 - 00026144 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-28 16:17 - 2014-01-12 12:38 - 00045270 _____ () C:\Users\CryptR\AppData\Roaming\room_v3.dat
2015-01-28 15:53 - 2013-02-18 15:08 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-01-28 15:45 - 2014-12-16 20:40 - 00000998 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-28 14:15 - 2014-06-21 21:33 - 00000000 ____D () C:\Users\CryptR\AppData\Roaming\GarenaPlus
2015-01-28 14:15 - 2014-06-21 21:33 - 00000000 ____D () C:\ProgramData\GarenaMessenger
2015-01-28 12:02 - 2009-07-14 07:32 - 00000000 ____D () C:\Windows\system32\FxsTmp
2015-01-27 20:29 - 2013-02-03 11:16 - 00000000 ____D () C:\Users\CryptR\AppData\Roaming\vlc
2015-01-27 19:09 - 2013-02-03 10:49 - 00000000 ____D () C:\Users\CryptR\AppData\Roaming\uTorrent
2015-01-27 17:14 - 2013-11-22 13:39 - 00000000 ____D () C:\Program Files (x86)\The KMPlayer
2015-01-27 12:04 - 2013-02-03 10:19 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-01-27 03:46 - 2014-12-16 20:41 - 00002181 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-01-26 23:03 - 2009-07-14 07:13 - 00786598 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-25 22:53 - 2013-02-18 15:08 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-01-25 22:53 - 2013-02-03 10:43 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-01-25 22:53 - 2013-02-03 10:43 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-24 18:45 - 2013-02-03 14:31 - 00000000 ____D () C:\Users\CryptR\AppData\Roaming\Skype
2015-01-24 18:01 - 2014-09-19 14:35 - 00000000 ___RD () C:\Program Files (x86)\Skype
2015-01-24 18:01 - 2013-02-03 14:31 - 00000000 ____D () C:\ProgramData\Skype
2015-01-23 22:27 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF

==================== Files in the root of some directories =======

2014-01-12 12:38 - 2015-01-28 16:17 - 0045270 _____ () C:\Users\CryptR\AppData\Roaming\room_v3.dat
2014-08-27 12:24 - 2014-08-27 12:27 - 0000003 _____ () C:\Users\CryptR\AppData\Local\user_data.ini

Some content of TEMP:
====================
C:\Users\CryptR\AppData\Local\Temp\Quarantine.exe
C:\Users\CryptR\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe
[2014-05-14 19:26] - [2011-01-16 02:01] - 0389632 ____A (Microsoft Corporation) 81257415084B84F3C0D95C381A8D4C8F

C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll
[2010-11-21 05:24] - [2011-01-16 02:01] - 1008640 ____A (Microsoft Corporation) 0B864E15A0BADFF0E7BB8B59009FDDCF

C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-01-24 19:24

==================== End Of Log ============================

Добре изглежда този път дневника..!Само че сте пропуснали да публикувате и Addition.txt..! Излиза ли ви проблемния ерор..?
 
Контролни проверки:

 

GUZVCQN.jpg  Моля, изтеглете Malwarebytes Anti -Malware и го запомнете на вашия работен плот .
  Кликнете два пъти върху mbam-setup-consumer-2.0.0.1хххх.exe и следвайте инструкциите, за да инсталирате програмата .

  • В секцията Settings = > Detection and Protection => Detection Options, се поставя отметка в квадратчето 'Scan for rootkits'.

MBAMsettings.JPG

  • В главния прозорец на програмата , щракнете върху 'Update Now'
  • След актуализацията завърши, кликнете на бутона " 'Scan Now  " .
  • Ако има налична актуализация , щракнете върху бутона Update Now button .
  • Ще стартира Threat Scan.
  • Когато сканирането приключи, ако има някакви открити зарази , щракнете върху Apply Actions за да се позволи на Mbam да почисти засеченото. .

MBAMReboot.JPG

  •   След рестарта ,стартирайте Mbam още веднъж.
  •   Кликнете на History tab > Application Logs .
  •   Кликнете два пъти върху реда , който показва датата и часа на сканирането или View Detailed Log .
  •   Кликнете върху " Copy да Clipboard "

MBAMLog.JPG

 

  Поставете  съдържанието на клипборда в следващия си  отговор

 

Hitman-Pro-Logo.png Сканиране с HitmanPro

 

1.Изтеглете Hitman Pro.
 

  • За 32-битова система - dEMD6.gif.
  • За 64-битова система - Download-button3.gif
    2.Стартирайте програмата.

3.След като сте стартирали програмата като кликнете върху иконата 5vo5F.jpg и натиснете бутона „Напред“ като се съгласите с лицензионното споразумение (EULA).
4.Сложете отметка пред "Не, искам да завърша еднократно сканиране на компютъра".

5.Натиснете бутона „Напред“.

6.Програмата ще започне да сканира. Времето за сканиране е около 2 минути.

7.След завършване на сканирането от списъка с намерените неща (ако има такива) изберете Apply to all => Ignore.

8.Натиснете "Next" и след това натиснете "Изнеси резултата в XML file" и запазете лог файла на десктопа.

9.Архивирайте файла и го прикачете в следващия си коментар или копирайте съдържанието му в следващия си коментар.
 
Забележка: Ако няма падащо меню, където да изберете ignore както на снимката:
 
6-scanfin-choose.jpg
 
Тогава просто затворете програмата след края на проверката (без да премахвате нищо)...след това отворете C:Programdata/HitmanPro/Logs, отворете и публикувайте съдържанието на лог файла в следващия си коментар.

 

 

xpfNZP4A.png.pagespeed.ic.bp5cRl1pJg.jpg  Дневници
 
В следващия си отговор, моля да включите следните дневници:

  • Дневник от Malwarebytes Anti -Malware
  • Дневник от Hitman Pro
  • Автор

Благодаря ви много.Наистина сте специалисти в тази област.Еррора се махна.Сега ще сканирам и с тези две програми.Логовете от тях трябват ли Ви?
Не постнах addition.txt,защото беше доста обемен,а еррора се махна.Ако трябва кажете да го постна.

Сърдечни благодарности отново,без вашата помощ нямаше да се оправя!

Редактирано от trqbvatiaccount (преглед на промените)

Благодаря ви много.Наистина сте специалисти в тази област.Еррора се махна.Сега ще сканирам и с тези две програми.Логовете от тях трябват ли Ви?

Не постнах addition.txt,защото беше доста обемен,а еррора се махна.Ако трябва кажете да го постна.

Сърдечни благодарности отново,без вашата помощ нямаше да се оправя!

 

Благодаря ви...! Да, всички дневници ми са необходими за да проверим за остатъци..!

  • Автор

Благодаря ви...! Да, всички дневници ми са необходими за да проверим за остатъци..!

Добре.Ето addition.txt.След като приключат сканирането и другите 2 програми ще дам лог и от тях.

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24-01-2015 01

Ran by myPC at 2015-01-27 12:19:52

Running from C:\Users\myPC\Desktop

Boot Mode: Normal

==========================================================

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: ESET NOD32 Antivirus 7.0 (Enabled - Out of date) {19259FAE-8396-A113-46DB-15B0E7DFA289}

AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

AS: ESET NOD32 Antivirus 7.0 (Enabled - Out of date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-3522770205-4233124857-3227214610-1000\...\uTorrent) (Version: 3.4.2.37754 - BitTorrent Inc.)

Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.296 - Adobe Systems Incorporated)

Adobe Reader XI (11.0.09) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated)

Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.7.148 - Adobe Systems, Inc.)

CCleaner (HKLM\...\CCleaner) (Version: 4.19 - Piriform)

DEVIL MAY CRY 4 (HKLM\...\{D4E5A687-797D-44B1-8F96-4FD7A24166A9}) (Version: 1.00.000 - CAPCOM CO., LTD.)

DEVIL MAY CRY 4 (HKLM-x32\...\{D4E5A687-797D-44B1-8F96-4FD7A24166A9}) (Version: 1.00.000 - CAPCOM CO., LTD.)

ESET NOD32 Antivirus (HKLM\...\{38740AB8-5577-43E5-A086-EAD4BD457A95}) (Version: 7.0.317.4 - ESET, spol s r. o.)

Fraps (HKLM-x32\...\Fraps) (Version:  - )

Garena+ (HKLM-x32\...\im) (Version: 2011 - Garena Online Pte Ltd.)

Google Chrome (HKLM-x32\...\Google Chrome) (Version: 40.0.2214.93 - Google Inc.)

Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden

Java 7 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)

Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation)

Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)

Microsoft Help Viewer 1.0 (HKLM\...\Microsoft Help Viewer 1.0) (Version: 1.0.30319 - Microsoft Corporation)

Microsoft Office Language Pack 2010 - Bulgarian/български (HKLM-x32\...\Office14.OMUI.bg-bg) (Version: 14.0.7015.1000 - Microsoft Corporation)

Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)

Microsoft SQL Server 2008 R2 Management Objects (HKLM-x32\...\{4E968D9C-21A7-4915-B698-F7AEB913541D}) (Version: 10.50.1447.4 - Microsoft Corporation)

Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\...\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation)

Microsoft SQL Server Compact 3.5 SP2 x64 ENU (HKLM\...\{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}) (Version: 3.5.8080.0 - Microsoft Corporation)

Microsoft SQL Server System CLR Types (HKLM-x32\...\{2A2F3AE8-246A-4252-BB26-1BEB45627074}) (Version: 10.50.1447.4 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974 (HKLM-x32\...\{B7E38540-E355-3503-AFD7-635B2F2F76E1}) (Version: 9.0.30729.4974 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)

Microsoft Visual C++ 2010  x64 Runtime - 10.0.30319 (HKLM\...\{94D70749-4281-39AC-AD90-B56A0E0A402E}) (Version: 10.0.30319 - Microsoft Corporation)

Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)

Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)

Mozilla Firefox 35.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 35.0.1 (x86 en-US)) (Version: 35.0.1 - Mozilla)

Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)

MSVC90_x64 (Version: 1.0.1.2 - Nokia) Hidden

MSVC90_x86 (x32 Version: 1.0.1.2 - Nokia) Hidden

MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)

MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)

MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)

Nokia Connectivity Cable Driver (HKLM-x32\...\{D4BF151C-70A8-4CE2-906F-4173A575BAD9}) (Version: 7.1.182.0 - Nokia)

NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.3 - NVIDIA Corporation)

NVIDIA PhysX (HKLM-x32\...\{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}) (Version: 9.09.0814 - NVIDIA Corporation)

NVIDIA Stereoscopic 3D Driver (HKLM-x32\...\NVIDIAStereo) (Version: 7.16.11.9107 - NVIDIA Corporation)

PC Connectivity Solution (HKLM-x32\...\{644F4910-E812-49AD-93EC-86828CB81A0D}) (Version: 12.0.27.0 - Nokia)

PC Remote (HKLM-x32\...\{C934DF74-D0D9-445C-90AA-34012A04E11D}) (Version: 3.51 - PC Remote)

Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5919 - Realtek Semiconductor Corp.)

Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)

Service Pack 2 for Microsoft Office 2010 Language Pack (KB2687449) 32-Bit Edition (HKLM-x32\...\{90140000-0100-0402-0000-0000000FF1CE}_Office14.OMUI.bg-bg_{19EC17F0-B5A9-45D6-9BDD-E198B4E15CF9}) (Version:  - Microsoft)

Settings Manager (HKLM-x32\...\Settings Manager) (Version: 5.0.0.12302 - Aztec Media Inc) <==== ATTENTION

Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)

swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden

The KMPlayer (HKLM-x32\...\The KMPlayer) (Version: 3.8.0.122 - PandoraTV)

VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN)

Windows Driver Package - Nokia pccsmcfd LegacyDriver  (05/31/2012 7.1.2.0) (HKLM\...\62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F) (Version: 05/31/2012 7.1.2.0 - Nokia)

WinRAR 4.20 (64-битова версия) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)

XFast LAN v6.61 (HKLM\...\XFast LAN) (Version: 6.61 - cFos Software GmbH, Bonn)

YTD Video Downloader 4.7.4 (HKLM-x32\...\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}) (Version: 4.7.4 - GreenTree Applications SRL) <==== ATTENTION

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

==================== Restore Points  =========================

22-01-2015 15:47:35 Scheduled Checkpoint

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {0970AD06-26C4-4D06-A24C-05DAAA98DF10} - System32\Tasks\{82F2A357-686E-494A-B43B-4F3F9AA2C7E7} => D:\Blitzkrieg.2\blitzkrieg\EXE\bin\GAME.EXE

Task: {2F6F5A12-F457-41B8-BCF9-339465B305EC} - System32\Tasks\DriverToolkit Autorun => C:\Program Files (x86)\DriverToolkit\DriverToolkit.exe

Task: {2FE61740-BB70-4011-B897-78A0E63B49AA} - System32\Tasks\{E056DDAD-0986-47F4-91FE-2C99BEF6A0ED} => pcalua.exe -a C:\Users\myPC\Desktop\AllIn1_Win7-64(15.37)\setup.exe -d C:\Users\myPC\Desktop\AllIn1_Win7-64(15.37)

Task: {33FEAFA0-9E22-42C5-A5DC-B1435EDE992B} - System32\Tasks\{F040485C-F08B-47FB-87A4-DEDBD46BD1BF} => pcalua.exe -a C:\Users\myPC\Desktop\cf_driver---da042d41-62bb-4d53-8b5d-508153a852b2\driver_v5.8.48204.100.exe -d C:\Users\myPC\Desktop\cf_driver---da042d41-62bb-4d53-8b5d-508153a852b2

Task: {35725492-F0A0-41D1-854B-8F1B7A55811A} - System32\Tasks\{61C9B171-8786-4A54-A6D5-78FA64E70CCD} => D:\Blitzkrieg.2\blitzkrieg\EXE\bin\GAME.EXE

Task: {3B4EDE03-FC4A-4410-8E47-B32CDF79C8BC} - System32\Tasks\Microsoft\Windows\Windows Activation Technologies\WatTask => C:\Windows Activation Technologies\wat.exe [2006-04-21] ()

Task: {5110D119-569E-440C-A723-23BE878A236D} - System32\Tasks\gg_uac_daemon_myPC => D:\garena\Garena Plus\ggdllhost.exe [2015-01-20] ()

Task: {6323B90D-E0DF-4145-96E8-A6291D5F0D4D} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc

Task: {7B65D70E-F2D6-4144-9EB3-8F960E029A9A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-16] (Google Inc.)

Task: {9337004F-FE24-4B51-8AB2-C299128FF2DD} - System32\Tasks\{70476680-5549-41A5-AB77-476215496518} => pcalua.exe -a C:\Users\myPC\Desktop\hda_v40a\SETUP.EXE -d C:\Users\myPC\Desktop\hda_v40a

Task: {9BB5D7C0-4615-4F61-B9FB-DC2BDAB7B64C} - System32\Tasks\{AA4C3558-9B65-4A1A-B247-CCCB982197CA} => pcalua.exe -a D:\Hercules.exe -d D:\

Task: {B13B355D-6D6D-4BA8-A3CB-AAAFF79BACA1} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-10-30] (Piriform Ltd)

Task: {BB73D29D-F2ED-494C-958F-DD3E3BBFD408} - System32\Tasks\asrRd => C:\Program Files\ASRock Utility\XFast RAM\asrRd.exe

Task: {CD779AD2-7FB8-4B5F-8810-0F959B1835BF} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-25] (Adobe Systems Incorporated)

Task: {F5BED33F-C4CC-434C-978D-35488DAF81C4} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-16] (Google Inc.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

Task: C:\Windows\Tasks\DriverToolkit Autorun.job => C:\Program Files (x86)\DriverToolkit\DriverToolkit.exe

Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2014-04-14 11:28 - 2014-05-18 11:50 - 00664592 ____N () C:\Program Files (x86)\Settings Manager\systemk\x64\sysapcrt.dll

2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF

2010-10-20 15:23 - 2010-10-20 15:23 - 08801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll

2014-08-27 13:28 - 2009-05-07 15:51 - 00071680 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\QsApoApi64.dll

2014-08-27 13:28 - 2009-05-07 15:53 - 00379392 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Dts2ApoApi64.dll

2014-08-27 13:28 - 2008-01-18 13:50 - 00098816 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\VMicApi.dll

2014-08-27 13:28 - 2009-09-02 08:26 - 47601664 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Skin.dll

2014-06-25 11:04 - 2015-01-20 14:20 - 00055896 _____ () D:\garena\Garena Plus\ggdllhost.exe

2014-06-25 11:04 - 2015-01-20 14:20 - 09981528 _____ () D:\garena\Garena Plus\GarenaMessenger.exe

2014-04-14 11:28 - 2014-05-18 11:50 - 00490000 ____N () C:\Program Files (x86)\Settings Manager\systemk\sysapcrt.dll

2014-06-25 11:04 - 2015-01-20 14:20 - 00560216 _____ () D:\garena\Garena Plus\ggspawn.dll

2015-01-27 00:08 - 2015-01-27 00:08 - 03925104 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll

2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF

2010-10-20 15:45 - 2010-10-20 15:45 - 08801120 _____ () C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll

2014-06-25 11:04 - 2015-01-20 14:20 - 00111192 _____ () D:\garena\Garena Plus\CommonLib.dll

2014-06-25 11:04 - 2015-01-20 14:20 - 00040024 _____ () D:\garena\Garena Plus\DibModule.dll

2014-06-25 11:04 - 2015-01-20 14:20 - 00034392 _____ () D:\garena\Garena Plus\VersionModule.dll

2014-06-25 11:04 - 2015-01-20 14:20 - 00057944 _____ () D:\garena\Garena Plus\FileLoader.dll

2014-06-25 11:04 - 2015-01-20 14:20 - 00093784 _____ () D:\garena\Garena Plus\PluginKernel.dll

2014-06-25 11:04 - 2015-01-20 14:20 - 00493656 _____ () D:\garena\Garena Plus\CxImage.dll

2014-06-25 11:04 - 2015-01-20 14:20 - 00031832 _____ () D:\garena\Garena Plus\PluginModule.dll

2014-06-25 11:05 - 2015-01-20 14:20 - 00177240 _____ () D:\garena\Garena Plus\lib\fs\YYFileSystem.dll

2014-06-25 11:05 - 2015-01-20 14:20 - 00380504 _____ () D:\garena\Garena Plus\lib\Http.dll

2014-06-25 11:05 - 2015-01-20 14:20 - 00191064 _____ () D:\garena\Garena Plus\lib\MP3Module.dll

2012-02-22 10:52 - 2012-02-22 10:52 - 00162304 _____ () D:\garena\Garena Plus\lame_enc.DLL

2014-06-25 11:05 - 2015-01-20 14:20 - 00226392 _____ () D:\garena\Garena Plus\lib\TaskManagerLib.dll

2014-06-25 11:05 - 2015-01-20 14:20 - 00112728 _____ () D:\garena\Garena Plus\lib\UILayout.dll

2014-06-25 11:05 - 2015-01-20 14:20 - 00964696 _____ () D:\garena\Garena Plus\lib\XLL.dll

2014-06-25 11:05 - 2015-01-20 14:20 - 00061528 _____ () D:\garena\Garena Plus\lib\XmlUIModule.dll

2012-02-22 10:52 - 2012-02-22 10:52 - 00573100 _____ () D:\garena\Garena Plus\sqlite3.dll

2014-06-25 11:05 - 2015-01-20 14:20 - 00231000 _____ () D:\garena\Garena Plus\Plugins\StatsPlugin.dll

2014-06-25 11:04 - 2015-01-20 14:20 - 00961112 _____ () D:\garena\Garena Plus\Plugins\ggplugin.dll

2014-06-25 11:04 - 2015-01-20 14:20 - 00199256 _____ () D:\garena\Garena Plus\ImageModule.dll

2014-06-25 11:04 - 2015-01-20 14:20 - 00161880 _____ () D:\garena\Garena Plus\libmpg123.dll

2014-06-25 11:04 - 2015-01-20 14:20 - 02947672 _____ () D:\garena\Garena Plus\ggdownloader.dll

2014-06-25 11:05 - 2015-01-20 14:20 - 00072280 _____ () D:\garena\Garena Plus\lib\delay_load\AudioMixerLib.dll

2014-06-25 11:05 - 2015-01-20 14:20 - 00023128 _____ () D:\garena\Garena Plus\lib\delay_load\ClientTcp.dll

2014-06-25 11:05 - 2015-01-20 14:20 - 01551960 _____ () D:\garena\Garena Plus\lib\delay_load\FileSender.dll

2013-02-01 07:42 - 2013-02-01 07:42 - 00153088 _____ () D:\garena\Garena Plus\libzmq.dll

2014-06-25 11:05 - 2015-01-20 14:20 - 00962648 _____ () D:\garena\Garena Plus\lib\delay_load\GaFileTransfer.dll

2014-06-25 11:05 - 2015-01-20 14:20 - 00251480 _____ () D:\garena\Garena Plus\lib\delay_load\MediaEngine.dll

2014-06-25 11:04 - 2015-01-20 14:20 - 00032856 _____ () D:\garena\Garena Plus\ServerMemAlloc.dll

2014-06-25 11:05 - 2015-01-20 14:20 - 00523352 _____ () D:\garena\Garena Plus\lib\delay_load\RSALib.dll

2014-06-25 11:05 - 2015-01-20 14:20 - 00074840 _____ () D:\garena\Garena Plus\lib\delay_load\UdtLib.dll

2014-06-25 11:04 - 2015-01-20 14:20 - 00153688 _____ () D:\garena\Garena Plus\xIM.dll

2014-06-25 11:05 - 2015-01-20 14:20 - 00596568 _____ () D:\garena\Garena Plus\xim\plugin_msn.dll

2014-06-25 11:05 - 2015-01-20 14:20 - 00467032 _____ () D:\garena\Garena Plus\xim\plugin_xmpp.dll

2014-06-25 11:05 - 2015-01-20 14:20 - 00201304 _____ () D:\garena\Garena Plus\xim\plugin_yahoo.dll

2014-06-25 11:04 - 2015-01-20 14:20 - 00107608 _____ () D:\garena\Garena Plus\Plugins\PlatformPlugin.dll

2014-06-25 11:04 - 2015-01-20 14:20 - 00243288 _____ () D:\garena\Garena Plus\Plugins\PluginNews.dll

2014-06-25 11:04 - 2015-01-20 14:20 - 00404056 _____ () D:\garena\Garena Plus\Plugins\GarenaTalkPlugin.dll

2014-06-25 11:04 - 2015-01-20 14:20 - 00293464 _____ () D:\garena\Garena Plus\Plugins\DailyTaskPlugin.dll

2014-06-25 11:05 - 2015-01-20 14:20 - 00222808 _____ () D:\garena\Garena Plus\Plugins\GameSalePlugin.dll

2015-01-25 22:53 - 2015-01-25 22:53 - 16844976 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:1CE11B51

AlternateDataStreams: C:\ProgramData\TEMP:BF3D62E7

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MSIServer => ""="Service"

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)

==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^Users^myPC^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Warcraft Config.lnk => C:\Windows\pss\Warcraft Config.lnk.Startup

MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

MSCONFIG\startupreg: BlueStacks Agent => C:\Program Files (x86)\BlueStacks\HD-Agent.exe

MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR

MSCONFIG\startupreg: GarenaPlus => "D:\garena\Garena Plus\GarenaMessenger.exe" -autolaunch

MSCONFIG\startupreg: mylbx => C:\Program Files\My Lockbox\mylbx.exe /a

MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

MSCONFIG\startupreg: Viber => "C:\Users\myPC\AppData\Local\Viber\Viber.exe" StartMinimized

========================= Accounts: ==========================

Administrator (S-1-5-21-3522770205-4233124857-3227214610-500 - Administrator - Disabled)

myPC (S-1-5-21-3522770205-4233124857-3227214610-1000 - Administrator - Enabled) => C:\Users\myPC

Guest (S-1-5-21-3522770205-4233124857-3227214610-501 - Limited - Disabled)

HomeGroupUser$ (S-1-5-21-3522770205-4233124857-3227214610-1002 - Limited - Enabled)

==================== Faulty Device Manager Devices =============

Name:

Description:

Class Guid:

Manufacturer:

Service:

Problem: : The drivers for this device are not installed. (Code 28)

Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name:

Description:

Class Guid:

Manufacturer:

Service:

Problem: : The drivers for this device are not installed. (Code 28)

Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name:

Description:

Class Guid:

Manufacturer:

Service:

Problem: : The drivers for this device are not installed. (Code 28)

Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name:

Description:

Class Guid:

Manufacturer:

Service:

Problem: : The drivers for this device are not installed. (Code 28)

Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name:

Description:

Class Guid:

Manufacturer:

Service:

Problem: : The drivers for this device are not installed. (Code 28)

Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name:

Description:

Class Guid:

Manufacturer:

Service:

Problem: : The drivers for this device are not installed. (Code 28)

Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: AP0O8LQU IDE Controller

Description: AP0O8LQU IDE Controller

Class Guid: {4D36E97B-E325-11CE-BFC1-08002BE10318}

Manufacturer: (Standard mass storage controllers)

Service: ahsxfwvb

Problem: : Windows cannot load the device driver for this hardware. The driver may be corrupted or missing. (Code 39)

Resolution: Reasons for this error include a driver that is not present; a binary file that is corrupt; a file I/O problem, or a driver that references an entry point in another binary file that could not be loaded.

Uninstall the driver, and then click "Scan for hardware changes" to reinstall or upgrade the driver.

Name: Microsoft PS/2 Mouse

Description: Microsoft PS/2 Mouse

Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}

Manufacturer: Microsoft

Service: i8042prt

Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)

Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.

Devices stay in this state if they have been prepared for removal.

After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: Copystar Fantom SCSI Controller

Description: Copystar Fantom SCSI Controller

Class Guid:

Manufacturer:

Service:

Problem: : The drivers for this device are not installed. (Code 28)

Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name:

Description:

Class Guid:

Manufacturer:

Service:

Problem: : The drivers for this device are not installed. (Code 28)

Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name:

Description:

Class Guid:

Manufacturer:

Service:

Problem: : The drivers for this device are not installed. (Code 28)

Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name:

Description:

Class Guid:

Manufacturer:

Service:

Problem: : The drivers for this device are not installed. (Code 28)

Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name:

Description:

Class Guid:

Manufacturer:

Service:

Problem: : The drivers for this device are not installed. (Code 28)

Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name:

Description:

Class Guid:

Manufacturer:

Service:

Problem: : The drivers for this device are not installed. (Code 28)

Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

==================== Event log errors: =========================

Application errors:

==================

Error: (01/27/2015 00:06:48 PM) (Source: WinMgmt) (EventID: 10) (User: )

Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/26/2015 07:54:41 PM) (Source: WinMgmt) (EventID: 10) (User: )

Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/26/2015 03:46:33 PM) (Source: Windows Search Service) (EventID: 1019) (User: )

Description: Windows Search Service failed to process the list of included and excluded locations with the error <30, 0x80040d07, "iehistory://{S-1-5-21-3522770205-4233124857-3227214610-1000}/">.

Error: (01/26/2015 03:46:13 PM) (Source: Windows Search Service) (EventID: 1019) (User: )

Description: Windows Search Service failed to process the list of included and excluded locations with the error <30, 0x80040d07, "iehistory://{S-1-5-21-3522770205-4233124857-3227214610-1000}/">.

Error: (01/26/2015 11:53:55 AM) (Source: WinMgmt) (EventID: 10) (User: )

Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/25/2015 10:14:39 PM) (Source: WinMgmt) (EventID: 10) (User: )

Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/25/2015 03:55:50 PM) (Source: Windows Search Service) (EventID: 1019) (User: )

Description: Windows Search Service failed to process the list of included and excluded locations with the error <30, 0x80040d07, "iehistory://{S-1-5-21-3522770205-4233124857-3227214610-1000}/">.

Error: (01/25/2015 11:18:49 AM) (Source: WinMgmt) (EventID: 10) (User: )

Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/24/2015 10:12:34 PM) (Source: Windows Search Service) (EventID: 1019) (User: )

Description: Windows Search Service failed to process the list of included and excluded locations with the error <30, 0x80040d07, "iehistory://{S-1-5-21-3522770205-4233124857-3227214610-1000}/">.

Error: (01/24/2015 10:12:26 PM) (Source: Windows Search Service) (EventID: 1019) (User: )

Description: Windows Search Service failed to process the list of included and excluded locations with the error <30, 0x80040d07, "iehistory://{S-1-5-21-3522770205-4233124857-3227214610-1000}/">.

System errors:

=============

Error: (01/27/2015 00:05:28 PM) (Source: Service Control Manager) (EventID: 7026) (User: )

Description: The following boot-start or system-start driver(s) failed to load:

cdrom

Error: (01/27/2015 00:04:57 PM) (Source: Microsoft-Windows-Kernel-Processor-Power) (EventID: 6) (User: NT AUTHORITY)

Description: Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware.

Error: (01/27/2015 03:51:41 AM) (Source: Service Control Manager) (EventID: 7016) (User: )

Description: The NVIDIA Display Driver Service service has reported an invalid current state 32.

Error: (01/26/2015 07:53:17 PM) (Source: Service Control Manager) (EventID: 7026) (User: )

Description: The following boot-start or system-start driver(s) failed to load:

cdrom

Error: (01/26/2015 07:52:48 PM) (Source: Microsoft-Windows-Kernel-Processor-Power) (EventID: 6) (User: NT AUTHORITY)

Description: Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware.

Error: (01/26/2015 07:38:23 PM) (Source: Service Control Manager) (EventID: 7016) (User: )

Description: The NVIDIA Display Driver Service service has reported an invalid current state 32.

Error: (01/26/2015 11:52:33 AM) (Source: Service Control Manager) (EventID: 7026) (User: )

Description: The following boot-start or system-start driver(s) failed to load:

cdrom

Error: (01/26/2015 11:52:02 AM) (Source: Microsoft-Windows-Kernel-Processor-Power) (EventID: 6) (User: NT AUTHORITY)

Description: Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware.

Error: (01/26/2015 02:24:10 AM) (Source: Service Control Manager) (EventID: 7016) (User: )

Description: The NVIDIA Display Driver Service service has reported an invalid current state 32.

Error: (01/25/2015 10:13:12 PM) (Source: Service Control Manager) (EventID: 7026) (User: )

Description: The following boot-start or system-start driver(s) failed to load:

cdrom

Microsoft Office Sessions:

=========================

Error: (01/27/2015 00:06:48 PM) (Source: WinMgmt) (EventID: 10) (User: )

Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/26/2015 07:54:41 PM) (Source: WinMgmt) (EventID: 10) (User: )

Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/26/2015 03:46:33 PM) (Source: Windows Search Service) (EventID: 1019) (User: )

Description: 300x80040d07iehistory://{S-1-5-21-3522770205-4233124857-3227214610-1000}/

Error: (01/26/2015 03:46:13 PM) (Source: Windows Search Service) (EventID: 1019) (User: )

Description: 300x80040d07iehistory://{S-1-5-21-3522770205-4233124857-3227214610-1000}/

Error: (01/26/2015 11:53:55 AM) (Source: WinMgmt) (EventID: 10) (User: )

Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/25/2015 10:14:39 PM) (Source: WinMgmt) (EventID: 10) (User: )

Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/25/2015 03:55:50 PM) (Source: Windows Search Service) (EventID: 1019) (User: )

Description: 300x80040d07iehistory://{S-1-5-21-3522770205-4233124857-3227214610-1000}/

Error: (01/25/2015 11:18:49 AM) (Source: WinMgmt) (EventID: 10) (User: )

Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/24/2015 10:12:34 PM) (Source: Windows Search Service) (EventID: 1019) (User: )

Description: 300x80040d07iehistory://{S-1-5-21-3522770205-4233124857-3227214610-1000}/

Error: (01/24/2015 10:12:26 PM) (Source: Windows Search Service) (EventID: 1019) (User: )

Description: 300x80040d07iehistory://{S-1-5-21-3522770205-4233124857-3227214610-1000}/

CodeIntegrity Errors:

===================================

  Date: 2013-02-03 10:30:22.796

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\user32.dll because the set of per-page image hashes could not be found on the system.

==================== Memory info ===========================

Processor: AMD Athlon II X2 240 Processor

Percentage of memory in use: 47%

Total physical RAM: 3071.3 MB

Available physical RAM: 1606.68 MB

Total Pagefile: 6140.79 MB

Available Pagefile: 4330.67 MB

Total Virtual: 8192 MB

Available Virtual: 8191.82 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:39.07 GB) (Free:3.31 GB) NTFS ==>[Drive with boot components (obtained from BCD)]

Drive d: (Local Disk) (Fixed) (Total:193.82 GB) (Free:83.44 GB) NTFS

==================== MBR & Partition Table ==================

========================================================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: 2BD2C32A)

Partition 1: (Active) - (Size=39.1 GB) - (Type=07 NTFS)

Partition 2: (Not Active) - (Size=193.8 GB) - (Type=07 NTFS)

==================== End Of Log ============================

Логът от malwarebytes показва,"Scan completed successfully.No malicious items were detected".

Сега ще пусна сканиране и с другата програма.

Редактирано от trqbvatiaccount (преглед на промените)

  • Автор

Ето и логът от втората програма.

HitmanPro 3.7.9.234
www.hitmanpro.com

   Computer name . . . . : my pc
   Windows . . . . . . . : 6.1.1.7601.X64/2
   User name . . . . . . : my pc
   UAC . . . . . . . . . : Disabled
   License . . . . . . . : Free

   Scan date . . . . . . : 2015-01-29 02:46:52
   Scan mode . . . . . . : Normal
   Scan duration . . . . : 3m 29s
   Disk access mode  . . : Direct disk access (SRB)
   Cloud . . . . . . . . : Internet
   Reboot  . . . . . . . : No

   Threats . . . . . . . : 2
   Traces  . . . . . . . : 14

   Objects scanned . . . : 1,504,546
   Files scanned . . . . : 23,968
   Remnants scanned  . . : 313,340 files / 1,167,238 keys

Miniport ____________________________________________________________________

   Primary
      DriverObject . . . : FFFFFA8002E944E0
      DriverName . . . . : \Driver\nvstor64
      DriverPath . . . . : \SystemRoot\system32\DRIVERS\nvstor64.sys
      StartIo  . . . . . : 0000000000000000 +0
      IRP_MJ_SCSI  . . . : FFFFFA8002DB92C0 +0
   Solution
      DriverObject . . . : FFFFFA8002E944E0
      DriverName . . . . : \Driver\nvstor64
      DriverPath . . . . : \SystemRoot\system32\DRIVERS\nvstor64.sys
      StartIo  . . . . . : 0000000000000000 +0
      IRP_MJ_SCSI  . . . : FFFFF88000C016C0 \SystemRoot\system32\drivers\storport.sys+5824

Malware _____________________________________________________________________

   C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Temp\nsgCEEC.tmp\Starter.exe
      Size . . . . . . . : 128,528 bytes
      Age  . . . . . . . : 1.6 days (2015-01-27 12:05:41)
      Entropy  . . . . . : 5.3
      SHA-256  . . . . . : 8D037DCDDBC86ACAB56B91278166173E09362A81708EB2404BA44105C8F3315B
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
    > Bitdefender  . . . : Adware.Linkey.B
    > Kaspersky  . . . . : not-a-virus:WebToolbar.Win64.SearchSuite.e
      Fuzzy  . . . . . . : 101.0
      Forensic Cluster
         -10.0s C:\Users\CryptR\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_b7389babec638f2b864b546c0653b4239197fb1_0174a96f\
         -10.0s C:\Users\CryptR\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_b7389babec638f2b864b546c0653b4239197fb1_0174a96f\Report.wer
         -9.6s C:\Users\CryptR\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_b7389babec638f2b864b546c0653b4239197fb1_0174ab24\
         -9.6s C:\Users\CryptR\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_b7389babec638f2b864b546c0653b4239197fb1_0174ab24\Report.wer
         -9.4s C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.675.gthr
         -9.3s C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.675.Crwl
         -8.5s C:\Users\CryptR\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_b7389babec638f2b864b546c0653b4239197fb1_0174af3b\
         -8.5s C:\Users\CryptR\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_b7389babec638f2b864b546c0653b4239197fb1_0174af3b\Report.wer
         -6.3s C:\Users\CryptR\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_b7389babec638f2b864b546c0653b4239197fb1_0174b805\
         -6.3s C:\Users\CryptR\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_b7389babec638f2b864b546c0653b4239197fb1_0174b805\Report.wer
         -2.4s C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\379e9b817139723ae834324910e3e029_b087ca71-d6d4-41a0-9dc2-f70d439b4b67
         -0.4s C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Temp\nsgCEEC.tmp\
          0.0s C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Temp\nsgCEEC.tmp\Starter.exe
         15.1s C:\Users\CryptR\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_b7389babec638f2b864b546c0653b4239197fb1_01750b84\
         15.1s C:\Users\CryptR\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_b7389babec638f2b864b546c0653b4239197fb1_01750b84\Report.wer

   C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Temp\nsqC140.tmp\Starter.exe
      Size . . . . . . . : 128,528 bytes
      Age  . . . . . . . : 2.6 days (2015-01-26 11:52:45)
      Entropy  . . . . . : 5.3
      SHA-256  . . . . . : 8D037DCDDBC86ACAB56B91278166173E09362A81708EB2404BA44105C8F3315B
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
    > Bitdefender  . . . : Adware.Linkey.B
    > Kaspersky  . . . . : not-a-virus:WebToolbar.Win64.SearchSuite.e
      Fuzzy  . . . . . . : 101.0
      Forensic Cluster
         -7.9s C:\Users\CryptR\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_b7389babec638f2b864b546c0653b4239197fb1_0bdca577\
         -7.9s C:\Users\CryptR\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_b7389babec638f2b864b546c0653b4239197fb1_0bdca577\Report.wer
         -7.5s C:\Users\CryptR\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_b7389babec638f2b864b546c0653b4239197fb1_0bdca72c\
         -7.5s C:\Users\CryptR\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_b7389babec638f2b864b546c0653b4239197fb1_0bdca72c\Report.wer
         -6.3s C:\Users\CryptR\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_b7389babec638f2b864b546c0653b4239197fb1_0bdcabff\
         -6.3s C:\Users\CryptR\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_b7389babec638f2b864b546c0653b4239197fb1_0bdcabff\Report.wer
         -2.4s C:\Users\CryptR\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_b7389babec638f2b864b546c0653b4239197fb1_0bdcbb51\
         -2.4s C:\Users\CryptR\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_b7389babec638f2b864b546c0653b4239197fb1_0bdcbb51\Report.wer
         -0.8s C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Temp\nsqC140.tmp\
          0.0s C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Temp\nsqC140.tmp\Starter.exe
          3.6s C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010017.wid
          3.7s C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010017.ci
          4.0s C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\95ef569ff47719e2376a4ccf2f0ab5d6_b087ca71-d6d4-41a0-9dc2-f70d439b4b67
         22.9s C:\Users\CryptR\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_b7389babec638f2b864b546c0653b4239197fb1_0bdd1e22\
         22.9s C:\Users\CryptR\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_b7389babec638f2b864b546c0653b4239197fb1_0bdd1e22\Report.wer


Suspicious files ____________________________________________________________

   C:\Users\CryptR\Desktop\FRST64.exe
      Size . . . . . . . : 2,129,920 bytes
      Age  . . . . . . . : 1.6 days (2015-01-27 12:13:59)
      Entropy  . . . . . : 7.5
      SHA-256  . . . . . : 8520252BCBD09C72401072B5E83DE245ECE0119E30A52DF462C64D6F94651C65
      Needs elevation  . : Yes
      Fuzzy  . . . . . . : 24.0
         Program has no publisher information but prompts the user for permission elevation.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Time indicates that the file appeared recently on this computer.


Potential Unwanted Programs _________________________________________________

   HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_F06DEFF2-5B9C-490D-910F-35D3A9119622\ (Linkey)
   HKLM\SYSTEM\ControlSet001\services\F06DEFF2-5B9C-490D-910F-35D3A9119622\ (Linkey)
   HKLM\SYSTEM\ControlSet001\services\SystemkService\ (Linkey)
   HKLM\SYSTEM\ControlSet002\Enum\Root\LEGACY_F06DEFF2-5B9C-490D-910F-35D3A9119622\ (Linkey)
   HKLM\SYSTEM\ControlSet003\Enum\Root\LEGACY_F06DEFF2-5B9C-490D-910F-35D3A9119622\ (Linkey)
   HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_F06DEFF2-5B9C-490D-910F-35D3A9119622\ (Linkey)
   HKU\.DEFAULT\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}\ (FLV Player)
   HKU\S-1-5-18\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}\ (FLV Player)
   HKU\S-1-5-21-3522770205-4233124857-3227214610-1000\Software\Linkey\ (Linkey)
   HKU\S-1-5-21-3522770205-4233124857-3227214610-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{54739D49-AC03-4C57-9264-C5195596B3A1} (Linkey)

Cookies _____________________________________________________________________

   C:\Users\CryptR\AppData\Roaming\Mozilla\Firefox\Profiles\38gkhptu.default-1418649727470\cookies.sqlite:doubleclick.net
 

Наистина ви благодаря отново,темата вече  за кошчето!

 

 

Да, обаче когато приключим..! :)

 

FRST.gif Фикс с Farbar Recovery Scan Tool

 

 

icon13.gif Изтеглете прикачения файл и го запазете там, където сте свалили FRST.exe => fixlist.txt

Стартирайте отново FRST.exe и натиснете бутона Fix веднъж и изчакайте.

Ще се създаде нов лог файла FixLog.txt. Прикачете съдържанието му в следващия си коментар.

 

ЗАБЕЛЕЖКА: Този скрипт е написан специално за този потребител,и за тази конкретна машина. Изпълнението на фикса, на друг компютър може да доведе до увреждане на  операционната ви система

 

xpfNZP4A.png.pagespeed.ic.bp5cRl1pJg.jpg  Дневници

 

В следващия си отговор, моля да включите следните дневници:

  • FixLog.txt
  • Автор

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 28-01-2015
Ran by CryptR at 2015-01-31 10:23:19 Run:1
Running from C:\Users\CryptR\Desktop
Loaded Profiles: CryptR (Available profiles: CryptR)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
start
CreateRestorePoint:
CloseProcesses:
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Temp\nsqC140.tmp\Starter.exe
DeleteKey: HKU\.DEFAULT\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}  
DeleteKey: HKU\S-1-5-18\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
DeleteKey: HKU\S-1-5-21-3522770205-4233124857-3227214610-1000\Software\Linkey
DeleteKey: HKU\S-1-5-21-3522770205-4233124857-3227214610-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{54739D49-AC03-4C57-9264-C5195596B3A1}
emptytemp:
reboot:
end
*****************

Restore point was successfully created.
Processes closed successfully.
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Temp\nsqC140.tmp\Starter.exe => Moved successfully.
HKU\.DEFAULT\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} => Failed to delete key at first attempt (Error: C0000121), see next line.
HKU\.DEFAULT\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} => Key Deleted Successfully.
HKU\S-1-5-18\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} => Key not found.
HKU\S-1-5-21-3522770205-4233124857-3227214610-1000\Software\Linkey => Key Deleted successfully.
HKU\S-1-5-21-3522770205-4233124857-3227214610-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{54739D49-AC03-4C57-9264-C5195596B3A1} => Key not found.
EmptyTemp: => Removed 392.3 MB temporary data.


The system needed a reboot.

==== End of Fixlog 10:24:15 ====

Прекрасно..! :)

 

icon_arrow.gif Изтеглете следния файл и го запазете в папката от която стартирахте FRST.exe.
Стартирайте FRST.exe и натиснете бутона Fix веднъж!
След като приключи публикувайте лог файла - fixlog.txt, който ще се създаде след работата. Той трябва да изтрие карантинната папка на инструмента разположена в C:FRSTQuarantine.
 
 
icon_arrow.gif Изтеглете DelFix и го стартирайте. Сложете отметка пред Remove disinfection tools и след това натиснете бутона Run
Инструмента ще се самоизтрие след като приключи своята задача!
 
1_tmb_68929169_delfix.gif.jpg

 

icon_arrow.gif Препоръчвам програмата Malwarebytes' Anti-Malware да остане на вашия компютър и периодично да сканирате системата си с нея (поне един -два пъти в седмицата),като не забравяйте да обновите дефинициите и преди всяко сканиране..!Напомням че това не е антивирусна програма а едно изключително добро допълнение към нея..!

 

 

vxyzw0.gifИзползвайте програмите PatchMyPC или Secunia Personal Software Inspector за да инсталирайте всички ъпдейти и последни версии на софтуер, които инструментите ви предложат.

 

Предлагам ви да използвате тази много добра малка програма, която автоматично ще премахва всички нежелани допълнения  по време на инсталирането на софтуера. Това помага за предотвратяване на инсталиране на зловреден код.
 
Кликнете тук за да изтеглите програмата и я инсталирайте..!

 

xunchecky1_zps667e512d.jpg.pagespeed.ic.

xunchecky2_zpsca4e7d0d.jpg.pagespeed.ic.

 

 

Ако има инструменти, папки или логове от използваните от нас неща и те не са се изтрили при горе-споменатите процедури, ги изтрийте ръчно.

 

Ако нямате други въпроси маркирам случая за "Решен"...! Пожелавам лек ден и безопасен интернет..! :)

  • Автор

Ето логът от изчистването на карантината.
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 28-01-2015
Ran by CryptR at 2015-01-31 11:12:15 Run:2
Running from C:\Users\CryptR\Desktop
Loaded Profiles: CryptR (Available profiles: CryptR)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
start
DeleteQuarantine:
end
*****************

"C:\FRST\Quarantine" => Removed successfully.

==== End of Fixlog 11:12:15 ====

Ще инсталирам останалите програми и ще сканирам компютъра своевременно.Благодаря ви пак за помоща.Изключително ми бяхте полезен с вашите съвети.

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.