Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Проблем с delta-homes.com

Featured Replies

Здравейте, имам проблем с delta-homes.com на браузера (Firefox) пробвах да го махна с Spyhunter 4 но не стана. Някой ако може да помогне ще съм много благодарен.

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 06-06-2015
Ran by Антон (administrator) on ACHITO on 06-06-2015 14:29:27
Running from F:\Documents and Settings\Антон\My Documents\Изтегляния
Loaded Profiles: Антон (Available Profiles: Антон)
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English (United States)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Enigma Software Group USA, LLC.) F:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE
(ATI Technologies Inc.) F:\WINDOWS\system32\ati2evxx.exe
(AVAST Software) F:\Program Files\AVAST Software\Avast\AvastSvc.exe
(ATI Technologies Inc.) F:\WINDOWS\system32\ati2evxx.exe
(Realtek Semiconductor Corp.) F:\WINDOWS\RTHDCPL.exe
(AVAST Software) F:\Program Files\AVAST Software\Avast\avastui.exe
(Enigma Software Group USA, LLC.) F:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe
(BitTorrent Inc.) F:\Documents and Settings\Антон\Application Data\uTorrent\uTorrent.exe
(Piriform Ltd) F:\Program Files\CCleaner\CCleaner.exe
() F:\WINDOWS\Datecs\Flex2K.exe
(Microsoft Corporation) F:\WINDOWS\system32\wuauclt.exe
(Microsoft Corporation) F:\WINDOWS\system32\wbem\unsecapp.exe
(Microsoft Corporation) F:\WINDOWS\system32\wuauclt.exe
(Mozilla Corporation) F:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) F:\WINDOWS\system32\rundll32.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDCPL] => F:\WINDOWS\RTHDCPL.EXE [16377344 2015-03-02] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Alcmtr] => F:\WINDOWS\ALCMTR.EXE [69632 2015-03-02] (Realtek Semiconductor Corp.)
HKLM\...\Run: [AvastUI.exe] => F:\Program Files\AVAST Software\Avast\AvastUI.exe [5227648 2015-03-31] (AVAST Software)
HKLM\...\Run: [startCCC] => F:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [90112 2006-11-10] ()
HKLM\...\Run: [Adobe ARM] => F:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2014-05-08] (Adobe Systems Incorporated)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => F:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [499608 2015-04-10] (Adobe Systems Incorporated)
HKLM\...\Run: [AdobeCS5.5ServiceManager] => F:\Program Files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [1523360 2011-01-12] (Adobe Systems Incorporated)
HKLM\...\Run: [switchBoard] => F:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM\...\Run: [spyHunter Security Suite] => F:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe [5076416 2015-06-06] (Enigma Software Group USA, LLC.)
Winlogon\Notify\AtiExtEvent: F:\WINDOWS\system32\Ati2evxx.dll [2015-03-02] (ATI Technologies Inc.)
HKU\S-1-5-21-725345543-2025429265-1801674531-1003\...\Run: [DAEMON Tools Lite] => F:\Program Files\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-725345543-2025429265-1801674531-1003\...\Run: [MSMSGS] => F:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation)
HKU\S-1-5-21-725345543-2025429265-1801674531-1003\...\Run: [skype] => F:\Program Files\Skype\Phone\Skype.exe [28917376 2015-05-14] (Skype Technologies S.A.)
HKU\S-1-5-21-725345543-2025429265-1801674531-1003\...\Run: [uTorrent] => F:\Documents and Settings\Антон\Application Data\uTorrent\uTorrent.exe [1994592 2015-06-06] (BitTorrent Inc.)
HKU\S-1-5-21-725345543-2025429265-1801674531-1003\...\Run: [CCleaner Monitoring] => F:\Program Files\CCleaner\CCleaner.exe [6369048 2015-05-08] (Piriform Ltd)
HKU\S-1-5-21-725345543-2025429265-1801674531-1003\...\MountPoints2: {6ad2645b-c0dc-11e4-8440-647002027b11} - I:\Autoplay.exe -auto
Startup: F:\Documents and Settings\All Users\Start Menu\Programs\Startup\FlexType 2K.lnk [2015-03-02]
ShortcutTarget: FlexType 2K.lnk -> F:\WINDOWS\Datecs\Flex2K.exe ()
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => F:\Program Files\AVAST Software\Avast\ashShell.dll [2015-03-02] (AVAST Software)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
SearchScopes: HKU\S-1-5-21-725345543-2025429265-1801674531-1003 -> DefaultScope {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL =
SearchScopes: HKU\S-1-5-21-725345543-2025429265-1801674531-1003 -> {67C334C0-408D-4E6D-B5A7-0ADD6AFFA252} URL =
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> F:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-03-02] (AVAST Software)
Hosts: There are more than one entry in Hosts. See Hosts section of  Addition.txt
Tcpip\Parameters: [DhcpNameServer] 62.221.132.211 85.130.60.11

FireFox:
========
FF ProfilePath: F:\Documents and Settings\Антон\Application Data\Mozilla\Firefox\Profiles\vi2lattu.default
FF NewTab: hxxp://www.delta-homes.com/newtab/?type=nt&ts=1432896147&z=0e1da790e171dc38c62bdafgbz9c4ocbetfq1g4g8q&from=wpm052932&uid=HitachiXHDP725025GLA380_GEL231RB06A3SB06A3SBX
FF SelectedSearchEngine: delta-homes
FF Homepage: https://www.google.bg/
FF Plugin: @adobe.com/FlashPlayer -> F:\WINDOWS\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] ()
FF Plugin: Adobe Reader -> F:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-725345543-2025429265-1801674531-1003: @unity3d.com/UnityPlayer,version=1.0 -> F:\Documents and Settings\Антон\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll [2015-03-27] (Unity Technologies ApS)
FF SearchPlugin: F:\Program Files\mozilla firefox\browser\searchplugins\diribg.xml [2015-02-23]
FF SearchPlugin: F:\Program Files\mozilla firefox\browser\searchplugins\portalbgdict.xml [2015-02-23]
FF Extension: Adblock Plus - F:\Documents and Settings\Антон\Application Data\Mozilla\Firefox\Profiles\vi2lattu.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-04-13]
FF HKLM\...\Firefox\Extensions: [[email protected]] - F:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - F:\Program Files\AVAST Software\Avast\WebRep\FF [2015-03-02]

Chrome:
=======
CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - F:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-03-02]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - F:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-03-02]
StartMenuInternet: Google Chrome - F:\Program Files (x86)\Google\Chrome\Application\chrome.exe

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; F:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2015-03-02] (AVAST Software)
R2 SpyHunter 4 Service; F:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [763840 2012-07-11] (Enigma Software Group USA, LLC.)
S3 SwitchBoard; F:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; F:\WINDOWS\system32\drivers\aswHwid.sys [24184 2015-03-02] ()
R2 aswMonFlt; F:\WINDOWS\system32\drivers\aswMonFlt.sys [73480 2015-03-02] (AVAST Software)
R1 aswRdr; F:\WINDOWS\system32\drivers\aswRdr.sys [55240 2015-03-02] (AVAST Software)
R0 aswRvrt; F:\WINDOWS\system32\Drivers\aswRvrt.sys [49944 2015-03-02] ()
R1 aswSnx; F:\WINDOWS\system32\drivers\aswSnx.sys [787800 2015-03-02] (AVAST Software)
R1 aswSP; F:\WINDOWS\system32\drivers\aswSP.sys [423784 2015-03-02] (AVAST Software)
R1 aswTdi; F:\WINDOWS\system32\drivers\aswTdi.sys [57928 2015-03-02] (AVAST Software)
R0 aswVmm; F:\WINDOWS\system32\Drivers\aswVmm.sys [206248 2015-03-02] ()
R1 dtsoftbus01; F:\WINDOWS\System32\DRIVERS\dtsoftbus01.sys [243128 2015-03-02] (Disc Soft Ltd)
R3 esgiguard; F:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [13904 2011-05-06] ()
R3 rtl8139; F:\WINDOWS\System32\DRIVERS\RTL8139.SYS [20992 2008-04-13] (Realtek Semiconductor Corporation)
S4 IntelIde; No ImagePath
S3 MBAMSwissArmy; \??\F:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [X]
U1 WS2IFSL; No ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-06 14:29 - 2015-06-06 14:29 - 00000000 ____D F:\FRST
2015-06-06 14:02 - 2015-06-06 14:02 - 00001980 _____ F:\Documents and Settings\Антон\Desktop\SpyHunter.lnk
2015-06-06 14:02 - 2015-06-06 14:02 - 00000000 ____D F:\sh4ldr
2015-06-06 14:02 - 2015-06-06 14:02 - 00000000 ____D F:\Documents and Settings\Антон\Start Menu\Programs\SpyHunter
2015-06-06 14:00 - 2015-06-06 14:02 - 00000000 ____D F:\WINDOWS\CC1F6DA021D2425AB1B65B164A598450.TMP
2015-06-06 13:56 - 2015-06-06 14:00 - 00000000 ____D F:\Program Files\Common Files\Wise Installation Wizard
2015-06-06 11:56 - 2015-06-06 11:56 - 00000000 _____ F:\autoexec.bat
2015-06-06 11:54 - 2015-06-06 14:00 - 00003408 _____ F:\WINDOWS\setupapi.log
2015-06-06 11:54 - 2015-06-06 11:54 - 00000000 ____D F:\Program Files\Enigma Software Group
2015-06-06 10:59 - 2015-06-06 10:59 - 00000082 _____ F:\Documents and Settings\Антон\My Documents\cc_20150606_105919.reg
2015-06-06 10:58 - 2015-06-06 10:58 - 00000000 ____D F:\Documents and Settings\All Users\Application Data\Malwarebytes
2015-06-06 10:49 - 2015-06-06 10:54 - 00000000 ____D F:\Program Files\CCleaner
2015-06-06 10:49 - 2015-06-06 10:49 - 00000689 _____ F:\Documents and Settings\All Users\Desktop\CCleaner.lnk
2015-06-06 10:49 - 2015-06-06 10:49 - 00000000 ____D F:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
2015-06-06 10:46 - 2015-06-06 10:46 - 00000837 _____ F:\Documents and Settings\Антон\Start Menu\µTorrent.lnk
2015-06-06 10:46 - 2015-06-06 10:46 - 00000837 _____ F:\Documents and Settings\Антон\Desktop\µTorrent.lnk
2015-06-06 10:45 - 2015-06-06 14:28 - 00000000 ____D F:\Documents and Settings\Антон\Application Data\uTorrent
2015-06-05 23:57 - 2015-06-05 23:57 - 00000288 _____ F:\WINDOWS\Tasks\Advanced System~Protector.job
2015-06-05 23:56 - 2015-06-06 11:22 - 00000000 ____D F:\Documents and Settings\Антон\Application Data\Systweak
2015-06-05 23:56 - 2015-06-06 11:22 - 00000000 ____D F:\Documents and Settings\All Users\Application Data\Systweak
2015-06-05 23:56 - 2015-05-25 11:48 - 00018216 _____ F:\WINDOWS\system32\sasnative32.exe
2015-06-05 21:31 - 2015-06-06 14:29 - 00000000 ____D F:\Documents and Settings\Антон\My Documents\Изтегляния
2015-06-03 05:59 - 2015-06-03 07:33 - 00000000 ____D F:\Program Files\Mozilla Firefox

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-06 14:29 - 2015-03-02 15:07 - 00000000 ____D F:\Documents and Settings\Антон\Local Settings\Temp
2015-06-06 14:26 - 2015-03-02 16:39 - 00464096 _____ F:\WINDOWS\system32\PerfStringBackup.INI
2015-06-06 14:23 - 2015-03-02 15:00 - 01770294 _____ F:\WINDOWS\WindowsUpdate.log
2015-06-06 14:22 - 2015-03-02 15:32 - 00000362 ____H F:\WINDOWS\Tasks\avast! Emergency Update.job
2015-06-06 14:21 - 2015-03-03 09:51 - 00000222 _____ F:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job
2015-06-06 14:21 - 2015-03-03 09:33 - 00000260 _____ F:\WINDOWS\Tasks\WGASetup.job
2015-06-06 14:21 - 2015-03-02 15:06 - 00000006 ____H F:\WINDOWS\Tasks\SA.DAT
2015-06-06 14:20 - 2015-03-02 15:07 - 00000178 ___SH F:\Documents and Settings\Антон\ntuser.ini
2015-06-06 14:20 - 2015-03-02 15:06 - 00032634 _____ F:\WINDOWS\SchedLgU.Txt
2015-06-06 13:59 - 2015-03-02 16:05 - 00000830 _____ F:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-06-06 12:09 - 2015-03-02 15:07 - 00001606 _____ F:\Documents and Settings\Антон\Start Menu\Programs\Remote Assistance.lnk
2015-06-06 12:06 - 2015-03-02 15:01 - 00001614 _____ F:\Documents and Settings\All Users\Start Menu\Set Program Access and Defaults.lnk
2015-06-06 12:06 - 2015-03-02 15:01 - 00001606 _____ F:\Documents and Settings\Default User\Start Menu\Programs\Remote Assistance.lnk
2015-06-06 12:06 - 2015-03-02 15:01 - 00001514 _____ F:\Documents and Settings\All Users\Start Menu\Windows Update.lnk
2015-06-06 11:23 - 2015-03-03 09:26 - 00000000 __HDC F:\WINDOWS\$NtUninstallKB2914368$
2015-06-06 11:00 - 2015-03-02 15:07 - 00000000 ____D F:\Documents and Settings\Антон
2015-06-06 10:57 - 2015-03-02 16:40 - 00000000 ____D F:\Documents and Settings\Антон\Application Data\DAEMON Tools Lite
2015-06-06 10:52 - 2015-03-02 16:02 - 00000000 ____D F:\Program Files\WinRAR
2015-06-06 10:52 - 2015-03-02 16:02 - 00000000 ____D F:\Documents and Settings\Антон\Start Menu\Programs\WinRAR
2015-06-06 10:52 - 2015-03-02 16:02 - 00000000 ____D F:\Documents and Settings\All Users\Start Menu\Programs\WinRAR
2015-06-06 06:59 - 2015-03-02 15:47 - 00000000 ____D F:\WINDOWS\Microsoft.NET
2015-06-05 23:55 - 2015-03-02 16:33 - 00000000 ____D F:\WINDOWS\system32\mui
2015-06-05 21:32 - 2015-03-02 15:30 - 00013888 _____ F:\Documents and Settings\Антон\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2015-06-05 11:14 - 2015-03-02 15:38 - 00000000 ____D F:\Program Files\Mozilla Maintenance Service
2015-06-05 11:14 - 2008-04-14 14:00 - 00002206 _____ F:\WINDOWS\system32\wpa.dbl
2015-06-03 11:26 - 2015-04-02 19:11 - 00002265 _____ F:\Documents and Settings\All Users\Desktop\Skype.lnk
2015-05-29 20:51 - 2015-03-02 16:05 - 00000000 ____D F:\Documents and Settings\Антон\Application Data\Skype
2015-05-29 20:51 - 2015-03-02 16:04 - 00000000 ____D F:\Documents and Settings\All Users\Application Data\Skype
2015-05-29 14:08 - 2015-03-02 16:38 - 03409736 _____ F:\WINDOWS\system32\FNTCACHE.DAT
2015-05-29 14:08 - 2015-03-02 15:03 - 00000000 ____D F:\WINDOWS\system32\bg-Bg
2015-05-29 13:42 - 2015-03-02 15:38 - 00001050 _____ F:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
2015-05-29 13:42 - 2015-03-02 15:38 - 00001044 _____ F:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
2015-05-29 13:42 - 2015-03-02 15:08 - 00001123 _____ F:\Documents and Settings\Антон\Start Menu\Programs\Internet Explorer.lnk
2015-05-08 15:00 - 2015-03-03 09:51 - 00000216 _____ F:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job

==================== Files in the root of some directories =======

2015-04-10 15:41 - 2015-04-10 16:10 - 0001456 _____ () F:\Documents and Settings\Антон\Local Settings\Application Data\Adobe Save for Web 12.0 Prefs
2015-03-02 15:36 - 2015-04-14 15:12 - 0005120 _____ () F:\Documents and Settings\Антон\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

Some files in TEMP:
====================
F:\Documents and Settings\Антон\Local Settings\Temp\dt_220.tmp.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

F:\WINDOWS\explorer.exe => File is digitally signed
F:\WINDOWS\system32\winlogon.exe => File is digitally signed
F:\WINDOWS\system32\svchost.exe => File is digitally signed
F:\WINDOWS\system32\services.exe => File is digitally signed
F:\WINDOWS\system32\User32.dll => File is digitally signed
F:\WINDOWS\system32\userinit.exe => File is digitally signed
F:\WINDOWS\system32\rpcss.dll => File is digitally signed
F:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

==================== End of log ============================

Addition.txt

Здравейте..!

 

remove%20outdated.jpg Деинсталиране нa програми

  • Натиснете WindowsKey.png + R на клавиатурата си по едно и също време. Въведете appwiz.cpl и щракнете върху OK.

 

SpyHunter

 

 

adwcleaner_new.png Сканиране с AdwCleaner
 
Моля, изтеглете и стартирайте програмата AdwCleaner(by Xplode):

  • Затворете всички стартирани програми и браузъри
  • Кликнете два пъти върху adwcleaner.exe за да стартирате инструмента.
  • Натиснете OK, за да потвърдите, че всички стартирани програми ще бъдат затворени.
  • Маркирайте Clean
  • Вашият компютър ще се рестартира автоматично. Текстовия файл ще се отвори след рестарта.
  • Моля, да публикувате съдържанието на този лог в отговора си
  • Можете да намерите лога,който автоматично се запомня тук C:AdwCleaner[s0].txt

 

 
 
JRTbythisisu.png Сканиране с Junkware Removal Tool
 
Моля, изтеглете Junkware Removal Tool (by Thisisu ) и запазете на вашия десктоп.

  • Спрете временно работата на защитните програми.
  • Стартирайте инструмента JRT.exe
  • Ще се отвори ДОС прозорец. Натиснете което и да е копче от клавиатурата.
  • Затворете излишните приложения и всички браузъри и изчакайте проверката да завърши.
  • Ще се появи лог файл (който можете да намерите и ръчно на десктопа с името JRT.txt).
  • Моля копирайте съдържанието на лог файла в следващия си пост.

 

Направете ново  сканиране с:

 

 

FRST.gif Сканиране с Farbar Recovery Scan Tool

 

  • Моля изтеглете icon1337953436.pngFarbar Recovery Scan Tool (според версията на Windows изберете 32 битовата или 64 битовата версия) и го запазете на десктопа.
  • Стартирайте файла FRST.exe (или FRST64.exe)
  • Програмата ще се стартира. Натиснете YES за да се съгласите с лицензионното споразумение.
  • Натиснете бутона YClYkft.jpg.
  • Изчакайте търпеливо проверката да приключи.
  • Ще се създадат два лог файла с името - FRST.txt и Addition.txt на десктопа.
  • Копирайте съдържанието на файла FRST.txt в следващия си пост. Прикачете Addition.txt в коментар си (погледнете опцията Прикачване на файлове, когато публикувате мнение).

 

xpfNZP4A.png.pagespeed.ic.bp5cRl1pJg.jpg  Дневници
 
В следващия си отговор, моля да включите следните дневници:

 

  • FRST.txt
  • Addition.txt
  • Автор

Благодаря за бързият отговор. Мисля, че всичко е ок вече.

JRT:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.8.8 (06.03.2015:1)
OS: Microsoft Windows XP x86
Ran by Ђ­І®­ on ±єЎ®І  06/06/2015 at 16:44:50,89
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Tasks

Successfully deleted: [Task] F:\WINDOWS\tasks\Advanced System~Protector.job



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\Util SourceApp



~~~ Files



~~~ Folders



~~~ FireFox

Successfully deleted the following from F:\Documents and Settings\Ђ­І®­\Application Data\mozilla\firefox\profiles\vi2lattu.default\prefs.js

user_pref(browser.search.selectedEngine, delta-homes);

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on ±єЎ®І  06/06/2015 at 16:48:04,93
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 06-06-2015
Ran by Антон (administrator) on ACHITO on 06-06-2015 16:50:50
Running from F:\Documents and Settings\Антон\Desktop
Loaded Profiles: Антон (Available Profiles: Антон)
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English (United States)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVAST Software) F:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) F:\Program Files\AVAST Software\Avast\avastui.exe
(Microsoft Corporation) F:\WINDOWS\system32\wbem\unsecapp.exe
(Microsoft Corporation) F:\WINDOWS\system32\wscntfy.exe
(Microsoft Corporation) F:\WINDOWS\system32\wuauclt.exe
(Mozilla Corporation) F:\Program Files\Mozilla Firefox\firefox.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDCPL] => F:\WINDOWS\RTHDCPL.EXE [16377344 2015-03-02] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Alcmtr] => F:\WINDOWS\ALCMTR.EXE [69632 2015-03-02] (Realtek Semiconductor Corp.)
HKLM\...\Run: [AvastUI.exe] => F:\Program Files\AVAST Software\Avast\AvastUI.exe [5227648 2015-03-31] (AVAST Software)
HKLM\...\Run: [startCCC] => F:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [90112 2006-11-10] ()
HKLM\...\Run: [Adobe ARM] => F:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2014-05-08] (Adobe Systems Incorporated)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => F:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [499608 2015-04-10] (Adobe Systems Incorporated)
HKLM\...\Run: [AdobeCS5.5ServiceManager] => F:\Program Files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [1523360 2011-01-12] (Adobe Systems Incorporated)
HKLM\...\Run: [switchBoard] => F:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
Winlogon\Notify\AtiExtEvent: F:\WINDOWS\system32\Ati2evxx.dll [2015-03-02] (ATI Technologies Inc.)
HKU\S-1-5-21-725345543-2025429265-1801674531-1003\...\Run: [DAEMON Tools Lite] => F:\Program Files\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-725345543-2025429265-1801674531-1003\...\Run: [MSMSGS] => F:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation)
HKU\S-1-5-21-725345543-2025429265-1801674531-1003\...\Run: [skype] => F:\Program Files\Skype\Phone\Skype.exe [28917376 2015-05-14] (Skype Technologies S.A.)
HKU\S-1-5-21-725345543-2025429265-1801674531-1003\...\Run: [uTorrent] => F:\Documents and Settings\Антон\Application Data\uTorrent\uTorrent.exe [1994592 2015-06-06] (BitTorrent Inc.)
HKU\S-1-5-21-725345543-2025429265-1801674531-1003\...\Run: [CCleaner Monitoring] => F:\Program Files\CCleaner\CCleaner.exe [6369048 2015-05-08] (Piriform Ltd)
HKU\S-1-5-21-725345543-2025429265-1801674531-1003\...\MountPoints2: {6ad2645b-c0dc-11e4-8440-647002027b11} - I:\Autoplay.exe -auto
Startup: F:\Documents and Settings\All Users\Start Menu\Programs\Startup\FlexType 2K.lnk [2015-03-02]
ShortcutTarget: FlexType 2K.lnk -> F:\WINDOWS\Datecs\Flex2K.exe ()
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => F:\Program Files\AVAST Software\Avast\ashShell.dll [2015-03-02] (AVAST Software)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-725345543-2025429265-1801674531-1003 -> {67C334C0-408D-4E6D-B5A7-0ADD6AFFA252} URL =
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> F:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-03-02] (AVAST Software)
Hosts: There are more than one entry in Hosts. See Hosts section of  Addition.txt
Tcpip\Parameters: [DhcpNameServer] 62.221.132.211 85.130.60.11

FireFox:
========
FF ProfilePath: F:\Documents and Settings\Антон\Application Data\Mozilla\Firefox\Profiles\vi2lattu.default
FF Homepage: https://www.google.bg/
FF Plugin: @adobe.com/FlashPlayer -> F:\WINDOWS\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] ()
FF Plugin: Adobe Reader -> F:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-725345543-2025429265-1801674531-1003: @unity3d.com/UnityPlayer,version=1.0 -> F:\Documents and Settings\Антон\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll [2015-03-27] (Unity Technologies ApS)
FF SearchPlugin: F:\Program Files\mozilla firefox\browser\searchplugins\diribg.xml [2015-02-23]
FF SearchPlugin: F:\Program Files\mozilla firefox\browser\searchplugins\portalbgdict.xml [2015-02-23]
FF Extension: Adblock Plus - F:\Documents and Settings\Антон\Application Data\Mozilla\Firefox\Profiles\vi2lattu.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-04-13]
FF HKLM\...\Firefox\Extensions: [[email protected]] - F:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - F:\Program Files\AVAST Software\Avast\WebRep\FF [2015-03-02]

Chrome:
=======
CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - F:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-03-02]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - F:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-03-02]
StartMenuInternet: Google Chrome - F:\Program Files (x86)\Google\Chrome\Application\chrome.exe

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; F:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2015-03-02] (AVAST Software)
S3 SwitchBoard; F:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; F:\WINDOWS\system32\drivers\aswHwid.sys [24184 2015-03-02] ()
R2 aswMonFlt; F:\WINDOWS\system32\drivers\aswMonFlt.sys [73480 2015-03-02] (AVAST Software)
R1 aswRdr; F:\WINDOWS\system32\drivers\aswRdr.sys [55240 2015-03-02] (AVAST Software)
R0 aswRvrt; F:\WINDOWS\system32\Drivers\aswRvrt.sys [49944 2015-03-02] ()
R1 aswSnx; F:\WINDOWS\system32\drivers\aswSnx.sys [787800 2015-03-02] (AVAST Software)
R1 aswSP; F:\WINDOWS\system32\drivers\aswSP.sys [423784 2015-03-02] (AVAST Software)
R1 aswTdi; F:\WINDOWS\system32\drivers\aswTdi.sys [57928 2015-03-02] (AVAST Software)
R0 aswVmm; F:\WINDOWS\system32\Drivers\aswVmm.sys [206248 2015-03-02] ()
R1 dtsoftbus01; F:\WINDOWS\System32\DRIVERS\dtsoftbus01.sys [243128 2015-03-02] (Disc Soft Ltd)
R3 rtl8139; F:\WINDOWS\System32\DRIVERS\RTL8139.SYS [20992 2008-04-13] (Realtek Semiconductor Corporation)
S3 esgiguard; \??\F:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S4 IntelIde; No ImagePath
S3 MBAMSwissArmy; \??\F:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [X]
U1 WS2IFSL; No ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-06 16:50 - 2015-06-06 16:51 - 00008758 _____ F:\Documents and Settings\Антон\Desktop\FRST.txt
2015-06-06 16:49 - 2015-06-06 16:49 - 01147392 _____ (Farbar) F:\Documents and Settings\Антон\Desktop\FRST.exe
2015-06-06 16:48 - 2015-06-06 16:48 - 00001040 _____ F:\Documents and Settings\Антон\Desktop\JRT.txt
2015-06-06 16:44 - 2015-06-06 16:44 - 00000000 ____D F:\RegBackup
2015-06-06 16:36 - 2015-06-06 16:37 - 00000000 ____D F:\AdwCleaner
2015-06-06 14:40 - 2015-06-06 14:40 - 00000109 _____ F:\Documents and Settings\Антон\Desktop\Нов Текстов документ.txt
2015-06-06 14:29 - 2015-06-06 16:50 - 00000000 ____D F:\FRST
2015-06-06 14:02 - 2015-06-06 16:34 - 00000000 ____D F:\sh4ldr
2015-06-06 14:00 - 2015-06-06 16:34 - 00000000 ____D F:\WINDOWS\CC1F6DA021D2425AB1B65B164A598450.TMP
2015-06-06 13:56 - 2015-06-06 14:00 - 00000000 ____D F:\Program Files\Common Files\Wise Installation Wizard
2015-06-06 11:56 - 2015-06-06 11:56 - 00000000 _____ F:\autoexec.bat
2015-06-06 11:54 - 2015-06-06 14:00 - 00003408 _____ F:\WINDOWS\setupapi.log
2015-06-06 11:54 - 2015-06-06 11:54 - 00000000 ____D F:\Program Files\Enigma Software Group
2015-06-06 10:59 - 2015-06-06 10:59 - 00000082 _____ F:\Documents and Settings\Антон\My Documents\cc_20150606_105919.reg
2015-06-06 10:58 - 2015-06-06 10:58 - 00000000 ____D F:\Documents and Settings\All Users\Application Data\Malwarebytes
2015-06-06 10:49 - 2015-06-06 10:54 - 00000000 ____D F:\Program Files\CCleaner
2015-06-06 10:49 - 2015-06-06 10:49 - 00000689 _____ F:\Documents and Settings\All Users\Desktop\CCleaner.lnk
2015-06-06 10:49 - 2015-06-06 10:49 - 00000000 ____D F:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
2015-06-06 10:46 - 2015-06-06 10:46 - 00000837 _____ F:\Documents and Settings\Антон\Start Menu\µTorrent.lnk
2015-06-06 10:46 - 2015-06-06 10:46 - 00000837 _____ F:\Documents and Settings\Антон\Desktop\µTorrent.lnk
2015-06-06 10:45 - 2015-06-06 16:44 - 00000000 ____D F:\Documents and Settings\Антон\Application Data\uTorrent
2015-06-05 21:31 - 2015-06-06 16:49 - 00000000 ____D F:\Documents and Settings\Антон\My Documents\Изтегляния
2015-06-03 05:59 - 2015-06-03 07:33 - 00000000 ____D F:\Program Files\Mozilla Firefox

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-06 16:51 - 2015-03-02 15:07 - 00000000 ____D F:\Documents and Settings\Антон\Local Settings\Temp
2015-06-06 16:45 - 2015-03-02 15:00 - 01778691 _____ F:\WINDOWS\WindowsUpdate.log
2015-06-06 16:44 - 2015-03-02 15:32 - 00000362 ____H F:\WINDOWS\Tasks\avast! Emergency Update.job
2015-06-06 16:43 - 2015-03-02 16:39 - 00464096 _____ F:\WINDOWS\system32\PerfStringBackup.INI
2015-06-06 16:39 - 2015-03-03 09:51 - 00000222 _____ F:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job
2015-06-06 16:39 - 2015-03-03 09:33 - 00000260 _____ F:\WINDOWS\Tasks\WGASetup.job
2015-06-06 16:38 - 2015-03-02 15:07 - 00000178 ___SH F:\Documents and Settings\Антон\ntuser.ini
2015-06-06 16:38 - 2015-03-02 15:06 - 00032634 _____ F:\WINDOWS\SchedLgU.Txt
2015-06-06 16:38 - 2015-03-02 15:06 - 00000006 ____H F:\WINDOWS\Tasks\SA.DAT
2015-06-06 16:37 - 2015-03-02 15:38 - 00000737 _____ F:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
2015-06-06 16:37 - 2015-03-02 15:38 - 00000731 _____ F:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
2015-06-06 16:37 - 2015-03-02 15:08 - 00000752 _____ F:\Documents and Settings\Антон\Start Menu\Programs\Internet Explorer.lnk
2015-06-06 15:59 - 2015-03-02 16:05 - 00000830 _____ F:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-06-06 12:09 - 2015-03-02 15:07 - 00001606 _____ F:\Documents and Settings\Антон\Start Menu\Programs\Remote Assistance.lnk
2015-06-06 12:06 - 2015-03-02 15:01 - 00001614 _____ F:\Documents and Settings\All Users\Start Menu\Set Program Access and Defaults.lnk
2015-06-06 12:06 - 2015-03-02 15:01 - 00001606 _____ F:\Documents and Settings\Default User\Start Menu\Programs\Remote Assistance.lnk
2015-06-06 12:06 - 2015-03-02 15:01 - 00001514 _____ F:\Documents and Settings\All Users\Start Menu\Windows Update.lnk
2015-06-06 11:23 - 2015-03-03 09:26 - 00000000 __HDC F:\WINDOWS\$NtUninstallKB2914368$
2015-06-06 11:00 - 2015-03-02 15:07 - 00000000 ____D F:\Documents and Settings\Антон
2015-06-06 10:57 - 2015-03-02 16:40 - 00000000 ____D F:\Documents and Settings\Антон\Application Data\DAEMON Tools Lite
2015-06-06 10:52 - 2015-03-02 16:02 - 00000000 ____D F:\Program Files\WinRAR
2015-06-06 10:52 - 2015-03-02 16:02 - 00000000 ____D F:\Documents and Settings\Антон\Start Menu\Programs\WinRAR
2015-06-06 10:52 - 2015-03-02 16:02 - 00000000 ____D F:\Documents and Settings\All Users\Start Menu\Programs\WinRAR
2015-06-06 06:59 - 2015-03-02 15:47 - 00000000 ____D F:\WINDOWS\Microsoft.NET
2015-06-05 23:55 - 2015-03-02 16:33 - 00000000 ____D F:\WINDOWS\system32\mui
2015-06-05 21:32 - 2015-03-02 15:30 - 00013888 _____ F:\Documents and Settings\Антон\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2015-06-05 11:14 - 2015-03-02 15:38 - 00000000 ____D F:\Program Files\Mozilla Maintenance Service
2015-06-05 11:14 - 2008-04-14 14:00 - 00002206 _____ F:\WINDOWS\system32\wpa.dbl
2015-06-03 11:26 - 2015-04-02 19:11 - 00002265 _____ F:\Documents and Settings\All Users\Desktop\Skype.lnk
2015-05-29 20:51 - 2015-03-02 16:05 - 00000000 ____D F:\Documents and Settings\Антон\Application Data\Skype
2015-05-29 20:51 - 2015-03-02 16:04 - 00000000 ____D F:\Documents and Settings\All Users\Application Data\Skype
2015-05-29 14:08 - 2015-03-02 16:38 - 03409736 _____ F:\WINDOWS\system32\FNTCACHE.DAT
2015-05-29 14:08 - 2015-03-02 15:03 - 00000000 ____D F:\WINDOWS\system32\bg-Bg
2015-05-08 15:00 - 2015-03-03 09:51 - 00000216 _____ F:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job

==================== Files in the root of some directories =======

2015-04-10 15:41 - 2015-04-10 16:10 - 0001456 _____ () F:\Documents and Settings\Антон\Local Settings\Application Data\Adobe Save for Web 12.0 Prefs
2015-03-02 15:36 - 2015-04-14 15:12 - 0005120 _____ () F:\Documents and Settings\Антон\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

Some files in TEMP:
====================
F:\Documents and Settings\Антон\Local Settings\Temp\dt_220.tmp.exe
F:\Documents and Settings\Антон\Local Settings\Temp\Quarantine.exe
F:\Documents and Settings\Антон\Local Settings\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

F:\WINDOWS\explorer.exe => File is digitally signed
F:\WINDOWS\system32\winlogon.exe => File is digitally signed
F:\WINDOWS\system32\svchost.exe => File is digitally signed
F:\WINDOWS\system32\services.exe => File is digitally signed
F:\WINDOWS\system32\User32.dll => File is digitally signed
F:\WINDOWS\system32\userinit.exe => File is digitally signed
F:\WINDOWS\system32\rpcss.dll => File is digitally signed
F:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

==================== End of log ============================
 

Addition.txt

  • Автор

# AdwCleaner v4.206 - Logfile created 06/06/2015 at 16:37:46
# Updated 01/06/2015 by Xplode
# Database : 2015-06-05.1 [server]
# Operating system : Microsoft Windows XP Service Pack 3 (x86)
# Username : Антон - ACHITO
# Running from : F:\Documents and Settings\Антон\My Documents\Изтегляния\adwcleaner_4.206.exe
# Option : Cleaning

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : F:\Documents and Settings\All Users\Application Data\Systweak
Folder Deleted : F:\Documents and Settings\Антон\Application Data\Systweak
File Deleted : F:\WINDOWS\system32\sasnative32.exe

***** [ Scheduled tasks ] *****


***** [ Shortcuts ] *****

Shortcut Disinfected : F:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
Shortcut Disinfected : F:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
Shortcut Disinfected : F:\Documents and Settings\Антон\Start Menu\Programs\Internet Explorer.lnk
Shortcut Disinfected : F:\Documents and Settings\Антон\Start Menu\Programs\Accessories\System Tools\Internet Explorer (без добавки).lnk

***** [ Registry ] *****

Key Deleted : HKCU\Software\systweak
Key Deleted : HKCU\Software\V9
Key Deleted : HKLM\SOFTWARE\hdcode
Key Deleted : HKLM\SOFTWARE\systweak

***** [ Web browsers ] *****

-\\ Internet Explorer v8.0.6001.18702


-\\ Mozilla Firefox v38.0.5 (x86 bg)

[vi2lattu.default\prefs.js] - Line Deleted : user_pref("browser.newtab.url", "hxxp://www.delta-homes.com/newtab/?type=nt&ts=1432896147&z=0e1da790e171dc38c62bdafgbz9c4ocbetfq1g4g8q&from=wpm052932&uid=HitachiXHDP725025GLA380_GEL231RB06A3SB06A3SBX"[...]

*************************

AdwCleaner[R0].txt - [1776 bytes] - [06/06/2015 16:36:27]
AdwCleaner[s0].txt - [1738 bytes] - [06/06/2015 16:37:46]

########## EOF - F:\AdwCleaner\AdwCleaner[s0].txt - [1797  bytes] ##########
 

FRST.gif Фикс с Farbar Recovery Scan Tool

 
icon13.gif Изтеглете прикачения файл и го запазете там, където сте свалили FRST.exe => fixlist.txt
Стартирайте отново FRST.exe и натиснете бутона Fix веднъж и изчакайте.
Ще се създаде нов лог файла FixLog.txt. Прикачете съдържанието му в следващия си коментар.

 
ЗАБЕЛЕЖКА: Този скрипт е написан специално за този потребител,и за тази конкретна машина. Изпълнението на фикса, на друг компютър може да доведе до увреждане на  операционната ви система

 

 

xpfNZP4A.png.pagespeed.ic.bp5cRl1pJg.jpg  Дневници
 
В следващия си отговор, моля да включите следните дневници:

 

  • FixLog.txt
  • Автор

Fix result of Farbar Recovery Scan Tool (x86) Version: 06-06-2015
Ran by Антон at 2015-06-06 17:21:06 Run:1
Running from F:\Documents and Settings\Антон\Desktop
Loaded Profiles: Антон (Available Profiles: Антон)
Boot Mode: Normal

==============================================

fixlist content:
*****************
start
CreateRestorePoint:
CloseProcesses:
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-725345543-2025429265-1801674531-1003 -> {67C334C0-408D-4E6D-B5A7-0ADD6AFFA252} URL =
S3 esgiguard; \??\F:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys
S3 MBAMSwissArmy; \??\F:\WINDOWS\system32\drivers\MBAMSwissArmy.sys
F:\Documents and Settings\Антон\Local Settings\Temp\dt_220.tmp.exe
F:\Documents and Settings\Антон\Local Settings\Temp\Quarantine.exe
F:\Documents and Settings\Антон\Local Settings\Temp\sqlite3.dll
emptytemp:
reboot:
end
*****************

Restore point was successfully created.
Processes closed successfully.
F:\WINDOWS\system32\GroupPolicy\Machine => moved successfully.
F:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully.
"HKLM\SOFTWARE\Policies\Google" => key removed successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully.
"HKU\S-1-5-21-725345543-2025429265-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{67C334C0-408D-4E6D-B5A7-0ADD6AFFA252}" => key removed successfully.
HKCR\CLSID\{67C334C0-408D-4E6D-B5A7-0ADD6AFFA252} => key not found.
esgiguard => Service removed successfully.
MBAMSwissArmy => Service removed successfully.
F:\Documents and Settings\Антон\Local Settings\Temp\dt_220.tmp.exe => moved successfully.
F:\Documents and Settings\Антон\Local Settings\Temp\Quarantine.exe => moved successfully.
F:\Documents and Settings\Антон\Local Settings\Temp\sqlite3.dll => moved successfully.
EmptyTemp: => 2 GB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 17:21:45 ====

Прекрасно..! :)

 

icon_arrow.gif Изтеглете следния файл и го запазете в папката от която стартирахте FRST.exe.
Стартирайте FRST.exe и натиснете бутона Fix веднъж!
След като приключи публикувайте лог файла - fixlog.txt, който ще се създаде след работата. Той трябва да изтрие карантинната папка на инструмента разположена в C:FRSTQuarantine.

 

 

icon_arrow.gif Изтеглете DelFix и го стартирайте. Сложете отметка пред:

  • Remove disinfection tools
  • Purge system restore
  • Reset system settings
  • Create registry backup

delfix.JPG
 
..и след това натиснете бутона Run

  • След като операцията е завърши,ще се създаде дневник
  • Копирате го и го поставите в следващия си отговор

Инструмента ще се самоизтрие след като приключи своята задача!

 

Маркирам случая за "Решен"...! Пожелавам лек ден и безопасен интернет..! :)

  • Автор

Fix result of Farbar Recovery Scan Tool (x86) Version: 06-06-2015
Ran by Антон at 2015-06-07 15:21:42 Run:2
Running from F:\Documents and Settings\Антон\Desktop\Нова папка
Loaded Profiles: Антон (Available Profiles: Антон)
Boot Mode: Normal

==============================================

fixlist content:
*****************
start
DeleteQuarantine:
end
*****************

"F:\FRST\Quarantine" => removed successfully..

==== End of Fixlog 15:21:43 ====

 

# DelFix v1.010 - Logfile created 07/06/2015 at 15:26:57
# Updated 26/04/2015 by Xplode
# Username : Антон - ACHITO
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)

~ Removing disinfection tools ...

Deleted : F:\FRST
Deleted : F:\AdwCleaner
Deleted : F:\RegBackup
Deleted : F:\Documents and Settings\Антон\Desktop\JRT.txt
Deleted : HKLM\SOFTWARE\AdwCleaner

~ Creating registry backup ... OK

~ Cleaning system restore ...

Deleted : RP #91 [software Distribution Service 3.0 | 05/24/2015 01:51:35]
Deleted : RP #92 [software Distribution Service 3.0 | 05/25/2015 02:23:52]
Deleted : RP #93 [software Distribution Service 3.0 | 05/26/2015 12:47:34]
Deleted : RP #94 [software Distribution Service 3.0 | 05/27/2015 03:11:47]
Deleted : RP #95 [software Distribution Service 3.0 | 05/28/2015 02:59:42]
Deleted : RP #96 [software Distribution Service 3.0 | 05/29/2015 09:43:38]
Deleted : RP #97 [software Distribution Service 3.0 | 05/30/2015 03:33:47]
Deleted : RP #98 [software Distribution Service 3.0 | 05/31/2015 03:37:30]
Deleted : RP #99 [software Distribution Service 3.0 | 06/01/2015 02:10:00]
Deleted : RP #100 [software Distribution Service 3.0 | 06/02/2015 05:00:18]
Deleted : RP #101 [software Distribution Service 3.0 | 06/03/2015 02:23:19]
Deleted : RP #102 [software Distribution Service 3.0 | 06/04/2015 02:28:21]
Deleted : RP #103 [software Distribution Service 3.0 | 06/05/2015 02:45:10]
Deleted : RP #104 [software Distribution Service 3.0 | 06/05/2015 08:12:32]
Deleted : RP #105 [software Distribution Service 3.0 | 06/05/2015 08:18:49]
Deleted : RP #106 [installed Microsoft Fix it 50471 | 06/05/2015 20:46:22]
Deleted : RP #107 [software Distribution Service 3.0 | 06/05/2015 21:09:16]
Deleted : RP #108 [software Distribution Service 3.0 | 06/06/2015 03:11:52]
Deleted : RP #109 [installed SpyHunter | 06/06/2015 10:56:48]
Deleted : RP #110 [Removed SpyHunter | 06/06/2015 11:00:38]
Deleted : RP #111 [installed SpyHunter | 06/06/2015 11:00:44]
Deleted : RP #112 [Removed SpyHunter | 06/06/2015 11:01:32]
Deleted : RP #113 [installed SpyHunter | 06/06/2015 11:02:38]
Deleted : RP #114 [Removed SpyHunter | 06/06/2015 13:34:32]
Deleted : RP #115 [avast! antivirus system restore point | 06/06/2015 13:52:10]
Deleted : RP #116 [Restore Point Created by FRST | 06/06/2015 14:21:18]
Deleted : RP #117 [software Distribution Service 3.0 | 06/07/2015 03:31:43]

New restore point created !

~ Resetting system settings ... OK

########## - EOF - ##########
 

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.