Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Контролно сканиране за вируси

Featured Replies

Здравейте! Реших да направя едно контролно сканиране за вируси понеже отдавна PC-то не е проверявано.

Ето лога от FRST.txt

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-02-2015
Ran by USER (administrator) on USER-PC on 02-02-2015 12:14:28
Running from C:\Users\USER\Desktop
Loaded Profiles: USER (Available profiles: USER)
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 10 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(IVT Corporation) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
() D:\Install\Testing Tools\quietHDD\quietHDD.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Fork, Ltd.) C:\Windows\Prey\wpxsvc.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe
(IVT Corporation) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BtTray.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
(Joyent, Inc) C:\Windows\Prey\versions\1.3.6\bin\node.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe
(Fork, Ltd.) C:\Windows\Prey\versions\1.3.6\node_modules\triggers\bin\lightevt.exe
(HP) C:\Windows\System32\HPSIsvc.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(IVT Corporation) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BsHelpCS.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\egui.exe [5595336 2014-10-01] (ESET)
HKLM-x32\...\Run: [uSB3MON] => C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-03-27] (Intel Corporation)
HKLM-x32\...\Run: [QLBController] => C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe [322432 2012-04-04] (Hewlett-Packard Company)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [btTray] => C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BtTray.exe [387832 2013-05-14] (IVT Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2316775370-2964681540-2297035872-1000\...\Run: [skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [30872672 2014-12-11] (Skype Technologies S.A.)
HKU\S-1-5-21-2316775370-2964681540-2297035872-1000\...\MountPoints2: F - F:\SISetup.exe
HKU\S-1-5-21-2316775370-2964681540-2297035872-1000\...\MountPoints2: {947222fa-a1c7-11e2-80e6-b4b52f788ef4} - F:\setup.exe
AppInit_DLLs: C:\Windows\Jaksta\AC\x64\jaudcap.dll => C:\Windows\Jaksta\AC\x64\jaudcap.dll [311584 2014-05-16] (Jaksta Technologies Pty Ltd)
Startup: C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\quietHDD.lnk
ShortcutTarget: quietHDD.lnk -> D:\Install\Testing Tools\quietHDD\quietHDD.exe ()
ShellIconOverlayIdentifiers: [shareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
ShellIconOverlayIdentifiers-x32: [  MailRuCloudIconOverlay0] -> {64A9418A-B6B1-4112-B75C-E61633C9A31F} =>  No File
ShellIconOverlayIdentifiers-x32: [  MailRuCloudIconOverlay1] -> {6A2E142B-EA63-433A-AC05-5223CBD26E65} =>  No File
ShellIconOverlayIdentifiers-x32: [  MailRuCloudIconOverlay2] -> {6AFCC535-2F12-4F50-9F0A-1CF856CFC95D} =>  No File
ShellIconOverlayIdentifiers-x32: [shareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

ProxyServer: [s-1-5-21-2316775370-2964681540-2297035872-1000] => https=127.0.0.1:54745
HKU\S-1-5-21-2316775370-2964681540-2297035872-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.bg/
HKU\S-1-5-21-2316775370-2964681540-2297035872-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
SearchScopes: HKU\S-1-5-21-2316775370-2964681540-2297035872-1000 -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{3D41CC7B-1CA0-4A34-B378-EF83D183B83F}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{42A1B73C-2FD5-4744-A1AC-DD4C68DBB756}: [NameServer] 8.8.8.8,8.8.4.4

FireFox:
========
FF ProfilePath: C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\mluugfdi.default
FF NewTab: google.bg
FF Homepage: hxxp://www.google.bg/
FF Keyword.URL: https://www.google.com/search?q=
FF NetworkProxy: "backup.ftp", "127.0.0.1"
FF NetworkProxy: "backup.ftp_port", 9050
FF NetworkProxy: "backup.socks", "127.0.0.1"
FF NetworkProxy: "backup.socks_port", 9050
FF NetworkProxy: "backup.ssl", "127.0.0.1"
FF NetworkProxy: "backup.ssl_port", 9050
FF NetworkProxy: "ftp", "127.0.0.1"
FF NetworkProxy: "ftp_port", 9050
FF NetworkProxy: "no_proxies_on", ""
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks", "127.0.0.1"
FF NetworkProxy: "socks_port", 9050
FF NetworkProxy: "ssl", "127.0.0.1"
FF NetworkProxy: "ssl_port", 9050
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_296.dll ()
FF Plugin: @java.com/DTPlugin,version=10.15.2 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 -> C:\Windows\SysWOW64\npDeployJava1.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
FF user.js: detected! => C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\mluugfdi.default\user.js
FF Extension: WOT - C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\mluugfdi.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-11-26]
FF Extension: DownloadHelper - C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\mluugfdi.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-12-31]
FF Extension: Classic Theme Restorer - C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\mluugfdi.default\Extensions\[email protected] [2014-06-06]
FF Extension: Awesome screenshot: Capture and Annotate - C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\mluugfdi.default\Extensions\[email protected] [2014-09-19]
FF Extension: Status-4-Evar - C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\mluugfdi.default\Extensions\[email protected] [2013-02-03]
FF Extension: Downloads Window - C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\mluugfdi.default\Extensions\{a7213cf2-fa1e-4373-88ff-255d0abd3020}.xpi [2013-12-22]
FF Extension: Download YouTube Videos as MP4 - C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\mluugfdi.default\Extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi [2014-11-06]
FF Extension: Adblock Plus - C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\mluugfdi.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-01-07]
FF HKLM\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF HKLM-x32\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 BlueSoleilCS; C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe [1630456 2013-06-07] (IVT Corporation)
R3 BsHelpCS; C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BsHelpCS.exe [145656 2013-05-14] (IVT Corporation)
R2 CronService; C:\Windows\Prey\wpxsvc.exe [611854 2015-01-25] (Fork, Ltd.) [File not signed]
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1349576 2014-10-01] (ESET)
R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe [368512 2012-04-04] (Hewlett-Packard Company)
S2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [165144 2012-03-28] (Intel Corporation)
S4 NetMsmqActivator; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [139680 2012-07-08] (Microsoft Corporation) [File not signed]
S4 NetPipeActivator; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [139680 2012-07-08] (Microsoft Corporation) [File not signed]
S4 NetTcpActivator; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [139680 2012-07-08] (Microsoft Corporation) [File not signed]
S4 NetTcpPortSharing; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [139680 2012-07-08] (Microsoft Corporation) [File not signed]
S4 STacSV; C:\Program Files\IDT\WDM\stacsv64.exe [323072 2012-09-20] (IDT, Inc.) [File not signed]
S4 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

U5 BlueletAudio; C:\Windows\System32\Drivers\BlueletAudio.sys [33968 2012-12-19] (IVT Corporation)
R3 BtAudioBusSrv; C:\Windows\System32\Drivers\BtAudioBus.sys [23136 2012-06-15] (IVT Corporation)
R0 BtHidBus; C:\Windows\System32\Drivers\BtHidBus.sys [24840 2009-01-07] (IVT Corporation.)
S3 BthL2caScoIfSrv; C:\Windows\System32\Drivers\BtL2caScoIf.sys [54064 2013-04-26] (Ralink Corporation)
S3 btnetBUs; C:\Windows\System32\Drivers\btnetBus.sys [35848 2008-12-07] ()
S3 btUrbFilterDrv; C:\Windows\System32\Drivers\IvtUrbBtFlt.sys [49584 2013-03-25] (Ralink Corporation)
R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-09-19] (Disc Soft Ltd)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [243440 2014-10-10] (ESET)
U5 edevmon; C:\Windows\System32\Drivers\edevmon.sys [241368 2014-10-10] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [169280 2014-10-10] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [222280 2014-10-10] (ESET)
R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [44632 2014-10-10] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [63160 2014-10-10] (ESET)
S1 ISODrive; C:\Windows\SysWOW64\Drivers\ISODrv64.sys [115600 2010-01-29] (EZB Systems, Inc.)
S3 IvtBtBUs; C:\Windows\System32\Drivers\IvtBtBus.sys [31624 2008-07-02] (IVT Corporation.)
S3 mvusbews; C:\Windows\System32\Drivers\mvusbews.sys [19968 2012-11-08] (Marvell Semiconductor, Inc.)
R3 rtbth; C:\Windows\System32\DRIVERS\rtbth.sys [1162952 2013-07-13] (Ralink Technology, Corp.)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1864328 2012-10-03] ()
U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] ()
U5 BlueletAudio; C:\Windows\SysWOW64\Drivers\BlueletAudio.sys [33968 2012-12-19] (IVT Corporation)
S3 BT; system32\DRIVERS\btnetdrv.sys [X]
S3 BTCOM; system32\DRIVERS\btcomport.sys [X]
S3 BTCOMBUS; System32\Drivers\btcombus.sys [X]
S3 NSNDIS5; \??\C:\Windows\system32\NSNDIS5.SYS [X]
S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [X]
S3 VComm; system32\DRIVERS\VComm.sys [X]
S3 VcommMgr; System32\Drivers\VcommMgr.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-02 12:14 - 2015-02-02 12:14 - 00013848 _____ () C:\Users\USER\Desktop\FRST.txt
2015-02-02 12:14 - 2015-02-02 12:14 - 00000000 ____D () C:\FRST
2015-02-02 12:13 - 2015-02-02 12:13 - 02131456 _____ (Farbar) C:\Users\USER\Desktop\FRST64.exe
2015-02-02 11:37 - 2015-02-02 11:50 - 00000112 _____ () C:\Windows\setupact.log
2015-02-02 11:37 - 2015-02-02 11:37 - 00000000 _____ () C:\Windows\setuperr.log
2015-02-02 11:36 - 2015-02-02 11:37 - 00288904 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-02-01 15:48 - 2015-02-01 15:48 - 00001300 _____ () C:\Users\USER\Desktop\CamStudio.lnk
2015-02-01 15:22 - 2015-02-01 15:46 - 00000000 ____D () C:\Users\USER\Documents\My CamStudio Temp Files
2015-02-01 15:20 - 2015-02-01 15:49 - 00000096 _____ () C:\Users\USER\AppData\Roaming\version2.xml
2015-01-28 20:10 - 2015-01-28 20:10 - 00000000 _____ () C:\Users\USER\Desktop\vtornik 3.02.15 - 9.30.txt
2015-01-26 23:06 - 2015-01-26 23:57 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-25 17:47 - 2015-01-25 17:47 - 00000000 ____D () C:\Users\USER\AppData\Roaming\Macromedia
2015-01-25 17:47 - 2015-01-25 17:47 - 00000000 ____D () C:\Users\USER\AppData\Local\Macromedia
2015-01-25 17:42 - 2015-01-25 17:42 - 00001058 _____ () C:\Users\Public\Desktop\BurnAware.lnk
2015-01-25 17:42 - 2015-01-25 17:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BurnAware Free
2015-01-25 17:42 - 2015-01-25 17:42 - 00000000 ____D () C:\Program Files (x86)\BurnAware Free
2015-01-25 17:37 - 2015-02-02 11:55 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-01-25 17:37 - 2015-01-26 10:07 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-01-25 17:37 - 2015-01-25 17:38 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-01-25 17:37 - 2015-01-25 17:38 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-23 21:36 - 2015-01-23 22:06 - 00000000 ___RD () C:\Program Files (x86)\Winamp
2015-01-23 21:36 - 2015-01-23 21:37 - 00001061 _____ () C:\Users\Public\Desktop\Winamp.lnk
2015-01-23 21:36 - 2015-01-23 21:36 - 00001013 _____ () C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Winamp.lnk
2015-01-05 21:15 - 2015-01-05 21:15 - 00000000 ____D () C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WMV9 VCM
2015-01-05 21:15 - 2015-01-05 21:15 - 00000000 ____D () C:\Program Files\WMV9_VCM

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-02 12:15 - 2014-12-31 14:19 - 00000000 ____D () C:\Users\USER\AppData\Roaming\Skype
2015-02-02 11:58 - 2009-07-14 06:45 - 00026352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-02 11:58 - 2009-07-14 06:45 - 00026352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-02 11:56 - 2009-07-14 07:13 - 00785302 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-02-02 11:52 - 2014-06-06 23:25 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-02-02 11:50 - 2013-09-13 16:20 - 00001017 _____ () C:\Windows\SysWOW64\bscs.ini
2015-02-02 11:50 - 2013-03-07 11:42 - 00000990 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-02 11:50 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-02 11:47 - 2013-03-07 11:42 - 00000994 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-02 11:46 - 2014-06-06 16:38 - 00003620 _____ () C:\Windows\SysWOW64\LOCALSERVICE.INI
2015-02-02 11:46 - 2014-06-06 16:38 - 00000043 _____ () C:\Windows\SysWOW64\LOCALDEVICE.INI
2015-02-02 11:30 - 2014-06-06 15:53 - 00000000 ____D () C:\Users\USER\AppData\Roaming\uTorrent
2015-02-02 00:24 - 2013-11-26 22:18 - 00000000 ____D () C:\Users\USER\AppData\Roaming\vlc
2015-01-26 16:20 - 2014-11-30 15:30 - 00001349 _____ () C:\Users\USER\Desktop\CCleaner.lnk
2015-01-26 09:17 - 2009-07-14 07:08 - 00032646 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-01-25 17:49 - 2014-12-31 14:12 - 00000000 ____D () C:\Windows\Prey
2015-01-25 17:45 - 2014-10-29 16:20 - 00000236 _____ () C:\Users\USER\AppData\Roaming\burnaware.ini
2015-01-25 17:42 - 2014-12-31 13:17 - 00000000 ____D () C:\ProgramData\Martau
2015-01-25 17:37 - 2013-03-28 20:01 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2015-01-25 17:30 - 2014-06-06 20:47 - 00000812 _____ () C:\Users\USER\Desktop\µTorrent.lnk
2015-01-25 17:30 - 2014-06-06 20:47 - 00000792 _____ () C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2015-01-24 15:40 - 2012-12-29 22:34 - 00000000 ____D () C:\Users\USER\AppData\Roaming\Thinstall
2015-01-23 23:11 - 2012-12-30 00:56 - 00000000 ____D () C:\ProgramData\TEMP
2015-01-10 11:07 - 2014-11-03 20:17 - 00004096 _____ () C:\Users\USER\AppData\Local\keyfile3.drm
2015-01-08 18:04 - 2014-09-19 16:02 - 00000000 ____D () C:\Users\USER\AppData\Roaming\DAEMON Tools Lite

==================== Files in the root of some directories =======

2014-10-29 16:20 - 2015-01-25 17:45 - 0000236 _____ () C:\Users\USER\AppData\Roaming\burnaware.ini
2015-02-01 15:20 - 2015-02-01 15:49 - 0000096 _____ () C:\Users\USER\AppData\Roaming\version2.xml
2013-04-18 15:40 - 2013-04-26 13:00 - 0007168 _____ () C:\Users\USER\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-11-03 20:17 - 2015-01-10 11:07 - 0004096 _____ () C:\Users\USER\AppData\Local\keyfile3.drm
2013-02-05 23:18 - 2013-02-05 23:18 - 0000001 _____ () C:\Users\USER\AppData\Local\llftool.4.25.agreement
2013-02-18 20:48 - 2013-02-18 20:48 - 0007650 _____ () C:\Users\USER\AppData\Local\Resmon.ResmonCfg
2014-12-31 10:34 - 2014-12-31 10:34 - 0000016 _____ () C:\ProgramData\mntemp

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-01-24 19:24

==================== End Of Log ============================

 

Ето и от Addition.txt

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-02-2015
Ran by USER at 2015-02-02 12:15:10
Running from C:\Users\USER\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: ESET Smart Security 8.0 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET Smart Security 8.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
FW: Лична защитна стена на ESET (Enabled) {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-2316775370-2964681540-2297035872-1000\...\uTorrent) (Version: 3.4.2.38397 - BitTorrent Inc.)
Adobe Flash Player 16.0.0.296 for Internet Explorer (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 16.0.0.296 - Adobe Systems Incorporated)
Adobe Flash Player 16.0.0.296 for Mozilla Firefox (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.296 - Adobe Systems Incorporated)
BurnAware Free 7.8 (HKLM-x32\...\BurnAware Free_is1) (Version:  - Burnaware)
Classic Shell (HKLM\...\{840C85B7-D3D6-4143-9AF9-DAE80FD54CFC}) (Version: 4.1.0 - IvoSoft)
Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6514.5001 - Microsoft Corporation)
DAEMON Tools Lite 4.49.1.0356 (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
doPDF 7.3 Build 393 (HKLM\...\doPDF 7 printer_is1) (Version: 7.3.393 - Softland)
ESET Smart Security (HKLM\...\{4E84B341-680E-43B9-A016-CBF11DDC1049}) (Version: 8.0.304.1 - ESET, spol s r. o.)
Foxit PhantomPDF (HKLM\...\{8FBFCE1E-C0AD-4FB6-A1B9-674613748597}) (Version: 5.2.1.615 - Foxit Corporation)
Google Update Helper (x32 Version: 1.3.21.135 - Google Inc.) Hidden
High Quality Photo Resizer 3.0 (HKLM-x32\...\High Quality Photo Resizer_is1) (Version:  - Naturpic Software)
HP 3D DriveGuard (HKLM\...\{C35A147C-5037-443A-9BF8-A5E7C2154CE4}) (Version: 5.1.7.1 - Hewlett-Packard Company)
HP HD Webcam Driver (HKLM-x32\...\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}) (Version: 6.0.1112.2_WHQL - Sonix)
HP Hotkey Support (HKLM-x32\...\{C97CC14E-4789-4FC5-BC75-79191F7CE009}) (Version: 4.5.12.1 - Hewlett-Packard Company)
HP LaserJet Professional M1130-M1210 MFP Series (HKLM\...\HP LaserJet Professional M1130-M1210 MFP Series) (Version:  - )
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6428.0 - IDT)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.10.1464 - Intel Corporation)
Intel® OpenCL CPU Runtime (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version:  - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2712 - Intel Corporation)
Intel® Turbo Boost Technology Monitor 2.6 (HKLM\...\{6C9365EB-1F9E-4893-9196-3EC77C88D0C5}) (Version: 2.6.2.0 - Intel)
Intel® USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.4.225 - Intel Corporation)
JMicron Flash Media Controller Driver (HKLM-x32\...\{26604C7E-A313-4D12-867F-7C6E7820BE4C}) (Version: 1.0.72.4 - JMicron Technology Corp.)
KeyControl v1.02 (HKLM-x32\...\KeyControl) (Version:  - )
Malwarebytes Anti-Malware 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Mediatek Bluetooth (HKLM\...\{A9409290-2A97-8735-93A3-DF710B1F44B0}) (Version: 11.0.742.0 - Mediatek)
Microsoft .NET Framework 4.5 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50709 - Microsoft Corporation)
Microsoft Office 2003 Proofing Tools (HKLM-x32\...\{901F0409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.5614.0 - Microsoft Corporation)
Microsoft Office Professional Edition 2003 (HKLM-x32\...\{90110409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.5614.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Windows Media Video 9 VCM (HKLM-x32\...\WMV9_VCM) (Version:  - )
Mozilla Firefox 35.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 35.0.1 (x86 en-US)) (Version: 35.0.1 - Mozilla)
Prey Anti-Theft (x32 Version: 1.3.6 - Prey, Inc.) Hidden
Ralink RT3290 802.11bgn Wi-Fi Adapter (HKLM-x32\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 5.0.2.0 - Ralink)
Realtek Ethernet Controller All-In-One Windows Driver (HKLM-x32\...\{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}) (Version: 7.58.411.2012 - Realtek)
Scan To (HKLM\...\{E8A34AC8-0137-4515-A94B-0A0946DDC251}) (Version: 2.0.1 - HP)
Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
Streamripper Plugin 1.62.2 (HKLM-x32\...\Streamripper.Plugin) (Version:  - )
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.0.3.0 - Synaptics Incorporated)
Teamviewer 7.0.14563.0 (HKLM-x32\...\TeamViewer 7) (Version: 7.0.14563 - TeamViewer)
Unlocker 1.9.2 (HKLM\...\Unlocker) (Version: 1.9.2 - Cedrick Collomb)
Winamp Pro 5.666 Build 3516 (HKLM-x32\...\Winamp_is1) (Version: 5.66 Build 3516 - l-rePack®)
Windows Movie Maker 2.6 (HKLM-x32\...\{B3DAF54F-DB25-4586-9EF1-96D24BB14088}) (Version: 2.6.4037.0 - Microsoft Corporation)
WinRAR 5.11 (64-битова версия) (HKLM\...\WinRAR archiver) (Version: 5.11.0 - win.rar GmbH)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points  =========================

ATTENTION: System Restore is disabled.

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2014-12-31 11:43 - 00000923 ____R C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       ursoftware.com
127.0.0.1       www.ursoftware.com
127.0.0.1   www.martau.com


==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {1B029E70-7038-4428-BBDF-0C3C8B51A3F3} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {7DDA1AC3-2D59-4CD5-82D1-E512C8CB0DBD} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {A1E6B2AD-1700-438F-9F24-A8E81B743FFE} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-25] (Adobe Systems Incorporated)
Task: {B151D2D2-45F3-4918-B0CE-52258596D04D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {FF0EB138-88BB-47BD-B1E4-30441289A378} - System32\Tasks\{B2AA4A6B-D6FD-400E-9C85-520FF4CC53C8} => Firefox.exe http://ui.skype.com/ui/0/6.22.64.107/bg/abandoninstall?source=lightinstaller&page=tsMain
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2013-05-14 16:33 - 2013-05-14 16:33 - 00029432 _____ () C:\Windows\system32\BsTrace.dll
2013-04-20 12:02 - 2012-09-29 12:25 - 00409088 _____ () C:\Windows\System32\HPM1210LM.DLL
2013-04-20 12:03 - 2012-09-29 12:25 - 00074240 _____ () C:\Windows\system32\spool\PRTPROCS\x64\HPM1210PP.dll
2013-02-18 11:57 - 2009-01-12 20:01 - 00061440 _____ () D:\Install\Testing Tools\quietHDD\quietHDD.exe
2013-05-14 16:33 - 2013-05-14 16:33 - 00016632 _____ () C:\Windows\system32\BsHelpCSps.dll
2013-05-14 16:33 - 2013-05-14 16:33 - 00080120 _____ () C:\Windows\system32\BsProfilefunc.dll
2013-05-14 16:33 - 2013-05-14 16:33 - 00371448 _____ () C:\Windows\system32\BsExtendFunc.dll
2015-01-26 23:06 - 2015-01-26 23:06 - 03925104 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\Windows:AstInfo
AlternateDataStreams: C:\ProgramData\TEMP:1CE11B51

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)


========================= Accounts: ==========================

Administrator (S-1-5-21-2316775370-2964681540-2297035872-500 - Administrator - Disabled)
Guest (S-1-5-21-2316775370-2964681540-2297035872-501 - Limited - Disabled)
pyxzbclulwzn (S-1-5-21-2316775370-2964681540-2297035872-1009 - Limited - Disabled)
taybzabqb (S-1-5-21-2316775370-2964681540-2297035872-1007 - Limited - Disabled)
USER (S-1-5-21-2316775370-2964681540-2297035872-1000 - Administrator - Enabled) => C:\Users\USER

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (02/02/2015 11:51:08 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/02/2015 11:37:43 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (02/02/2015 11:53:04 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Intel® Management and Security Application User Notification Service service failed to start due to the following error:
%%1053

Error: (02/02/2015 11:53:04 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Intel® Management and Security Application User Notification Service service to connect.

Error: (02/02/2015 11:51:01 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Intel® Dynamic Application Loader Host Interface Service service failed to start due to the following error:
%%1053

Error: (02/02/2015 11:51:01 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Intel® Dynamic Application Loader Host Interface Service service to connect.

Error: (02/02/2015 11:51:00 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The HP Software Framework Service service failed to start due to the following error:
%%1053

Error: (02/02/2015 11:51:00 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the HP Software Framework Service service to connect.

Error: (02/02/2015 11:39:43 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Intel® Management and Security Application User Notification Service service failed to start due to the following error:
%%1053

Error: (02/02/2015 11:39:43 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Intel® Management and Security Application User Notification Service service to connect.

Error: (02/02/2015 11:37:43 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Intel® Dynamic Application Loader Host Interface Service service failed to start due to the following error:
%%1053

Error: (02/02/2015 11:37:43 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Intel® Dynamic Application Loader Host Interface Service service to connect.


Microsoft Office Sessions:
=========================
Error: (02/02/2015 11:51:08 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/02/2015 11:37:43 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


==================== Memory info ===========================

Processor: Intel® Core i5-3210M CPU @ 2.50GHz
Percentage of memory in use: 47%
Total physical RAM: 3976.57 MB
Available physical RAM: 2082.76 MB
Total Pagefile: 7951.32 MB
Available Pagefile: 5860.96 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:39.9 GB) (Free:18.42 GB) NTFS
Drive d: (Local Disk) (Fixed) (Total:658.63 GB) (Free:527.06 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 698.6 GB) (Disk ID: E3DB5E23)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=39.9 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=658.6 GB) - (Type=07 NTFS)

==================== End Of Log ============================

Редактирано от B-boy[StyLe] (преглед на промените)

Здравейте,

 

Пробвахте ли да видите каква е скоростта при изключена антивирусна програма и с DNS настройките на вашия доставчик (вместо Google)?

А прокситата вие ли сте ги слагали?

  • Автор

Проблемът беше в доставчика. Всико вече е наред.

Да, дневника потвърждава че няма зарази. Ами в такъв случай маркирам случая като приключен! :)

 

Поздрави и лек ден! :bye1:

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.