Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Самоинсталиращи се програми, които не се премахват

Featured Replies

  • Автор

Да, предишния не съм изтрила и той се е модифицирал.

 

~ ZHPCleaner v2015.8.23.330 by Nicolas Coolman (2015/08/23)
~ Run by user (Administrator)  (24/08/2015 11:15:33)
~ State version : Version OK
~ Type : Repair
~ Report : C:\Users\user\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\user\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt
~ UAC : Deactivate
~ Boot Mode : Normal (Normal boot)
Windows 7 Ultimate, 32-bit Service Pack 1 (Build 7601)
 
 
---\\  Services (0)
~ No malicious or unnecessary items found.
 
 
---\\  Browser internet (0)
~ No malicious or unnecessary items found.
 
 
---\\  Hosts file (1)
~ The hosts file is legitimate (21)
 
 
---\\  Scheduled automatic tasks. (1)
DELETED task: [AutoKMS] [C:\Windows\Tasks\AutoKMS.job (Not File) ]  =>HackTool.AutoKMS
 
 
---\\  Explorer ( File, Folder) (4)
MOVED file: C:\Windows\Tasks\AutoKMS.job    =>HackTool.AutoKMS
MOVED file: C:\Windows\AutoKMS\AutoKMS.exe [CODYQX4 & Bosh - AutoKMS]  =>HackTool.AutoKMS
MOVED file: C:\Windows\AutoKMS\AutoKMS.log    =>HackTool.AutoKMS
MOVED folder: C:\Windows\AutoKMS  =>HackTool.AutoKMS
 
 
---\\  Registry ( Key, Value, Data) (9)
DELETED key*: HKLM\SOFTWARE\MozillaPlugins\@qq.com/npAndroidAssistant [Tencent, Inc.]  =>PUP.Optional.TencentAddressBar
DELETED key*: HKEY_USERS\S-1-5-21-2224806993-1213079895-3238273190-1000\Software\Tencent []  =>PUP.Optional.TencentAddressBar
DELETED key: HKCU\Software\Tencent []  =>PUP.Optional.TencentAddressBar
DELETED key*: HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1B5D5DBD-C857-4377-A755-06E50B4AC2B0} [C:\Program Files\Common Files\Tencent\QQPhoneManager\2.0.201.3198 (Not File)]  =>PUP.Optional.TencentAddressBar
DELETED key*: HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1E6A8DA1-1731-465B-B036-B9E16EF26CAC} [C:\IQIYI Video\LStyle\ (Not File)]  =>PUP.Optional.IQIYIVideo
DELETED key*: HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2E6A8DA1-2731-465B-B036-B9E16EF26CAC} [C:\IQIYI Video\LStyle\ (Not File)]  =>PUP.Optional.IQIYIVideo
DELETED key*: HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{639B74F1-0594-432C-97C8-68C8C17A1E1D} [C:\Program Files\Tencent\QQPCMgr\10.11.16588.235\Plugins\QQPCB1AndroidJmp (Not File)]  =>PUP.Optional.TencentAddressBar
DELETED key*: HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} [iTool]  =>Toolbar.Ask
DELETED key*: HKLM\SOFTWARE\Tencent []  =>PUP.Optional.TencentAddressBar
 
 
---\\ Result of repair
~ Repair carried out successfully
~ Browser not found (Mozilla Firefox)
 
 
---\\ Statistics
~ Items scanned : 624
~ Items found : 0
~ Items cancelled : 0
~ Items repaired : 14
 
 
~ End of clean in 0 minutes
===================
ZHPCleaner-[R]-24082015-11_15_53.txt
ZHPCleaner--24082015-00_33_16.txt
ZHPCleaner--24082015-11_01_03.txt
  • Автор
C:\FRST\Quarantine.rar multiple threats
C:\FRST\Quarantine\C\Program Files\4C4C4544-1440146753-5710-804D-B5C04F4B344A\4C4C4544-1440146753-5710-804D-B5C04F4B344A\vnsa8CA2.tmp a variant of Win32/Adware.ConvertAd.WZ.gen application
C:\FRST\Quarantine\C\Program Files\globalUpdate\Update\1.3.25.0\globalupdate.exe Win32/AlteredSoftware.F potentially unwanted application
C:\FRST\Quarantine\C\Program Files\globalUpdate\Update\1.3.25.0\globalupdateBroker.exe Win32/AlteredSoftware.H potentially unwanted application
C:\FRST\Quarantine\C\Program Files\globalUpdate\Update\1.3.25.0\globalupdateOnDemand.exe Win32/AlteredSoftware.H potentially unwanted application
C:\FRST\Quarantine\C\Program Files\globalUpdate\Update\1.3.25.0\psuser.dll a variant of Win32/AlteredSoftware.G potentially unwanted application
C:\FRST\Quarantine\C\Program Files\igfx32\igfx32.exe a variant of MSIL/Amonetize.AA potentially unwanted application
C:\FRST\Quarantine\C\Program Files\igfx32\packages\73a7afbd-e3e0-4448-bf52-09e1ab982ebd\Jackson.exe a variant of MSIL/Toolbar.Linkury.S potentially unwanted application
C:\FRST\Quarantine\C\ProgramData\CismaUva\yveg3ufu.dll a variant of Win32/Adware.PennyBee.L application
C:\FRST\Quarantine\C\Users\user\AppData\Local\nszB6C5.tmp.xBAD Win32/AnyProtect.G potentially unwanted application
C:\FRST\Quarantine\C\Users\user\AppData\Local\Temp\3280.exe.xBAD a variant of Win32/Toolbar.CrossRider.CZ potentially unwanted application
C:\FRST\Quarantine\C\Users\user\AppData\Local\Temp\9569.exe.xBAD a variant of Win32/Packed.ScrambleWrapper.O potentially unwanted application
C:\FRST\Quarantine\C\Users\user\AppData\Local\Temp\amisetup7124__13312.exe.xBAD a variant of Win32/Amonetize.HG potentially unwanted application
C:\FRST\Quarantine\C\Users\user\AppData\Local\Temp\bitool.dll.xBAD Win32/Somoto.B potentially unwanted application
C:\FRST\Quarantine\C\Users\user\AppData\Local\Temp\KMP_3.9.1.135.exe.xBAD a variant of Win32/CNETInstaller.B potentially unwanted application
C:\FRST\Quarantine\C\Users\user\AppData\Local\Temp\setup3.exe.xBAD a variant of Win32/HideBaid.L potentially unwanted application
C:\FRST\Quarantine\C\Users\user\AppData\Roaming\3QfIPPiT.xBAD JS/Toolbar.Crossrider.I potentially unwanted application
C:\FRST\Quarantine\C\Users\user\AppData\Roaming\5UQtIkbPTkE.xBAD JS/Toolbar.Crossrider.I potentially unwanted application
C:\Program Files\baidu\Bind.exe a variant of Win32/HideBaid.L potentially unwanted application
C:\Users\user\AppData\Roaming\uTorrent\updates\3.4.2_38758.exe a variant of Win32/OpenCandy.C potentially unsafe application
C:\Users\user\AppData\Roaming\ZHP\Quarantine\AutoKMS.exe MSIL/HackKMS.A potentially unsafe application
C:\Users\user\Downloads\dfdownloader_6LVB1B_.exe Win32/DepoDownloader.A potentially unwanted application
C:\Users\user\Downloads\uTorrent.exe a variant of Win32/OpenCandy.C potentially unsafe application
C:\Users\user\Downloads\Английско-немско-български картинен речник-8651764-6.zip a variant of Win32/Adware.FileTour.ACZ application

Пуснете ново сканиране като този път, освен отметките, които сложихте предния път, сега сложете отметка и на Remove found threats.

  • Автор
C:\FRST\Quarantine.rar multiple threats deleted - quarantined
C:\FRST\Quarantine\C\Program Files\4C4C4544-1440146753-5710-804D-B5C04F4B344A\4C4C4544-1440146753-5710-804D-B5C04F4B344A\vnsa8CA2.tmp a variant of Win32/Adware.ConvertAd.WZ.gen application cleaned by deleting - quarantined
C:\FRST\Quarantine\C\Program Files\globalUpdate\Update\1.3.25.0\globalupdate.exe Win32/AlteredSoftware.F potentially unwanted application cleaned by deleting - quarantined
C:\FRST\Quarantine\C\Program Files\globalUpdate\Update\1.3.25.0\globalupdateBroker.exe Win32/AlteredSoftware.H potentially unwanted application cleaned by deleting - quarantined
C:\FRST\Quarantine\C\Program Files\globalUpdate\Update\1.3.25.0\globalupdateOnDemand.exe Win32/AlteredSoftware.H potentially unwanted application cleaned by deleting - quarantined
C:\FRST\Quarantine\C\Program Files\globalUpdate\Update\1.3.25.0\psuser.dll a variant of Win32/AlteredSoftware.G potentially unwanted application cleaned by deleting - quarantined
C:\FRST\Quarantine\C\Program Files\igfx32\igfx32.exe a variant of MSIL/Amonetize.AA potentially unwanted application cleaned by deleting - quarantined
C:\FRST\Quarantine\C\Program Files\igfx32\packages\73a7afbd-e3e0-4448-bf52-09e1ab982ebd\Jackson.exe a variant of MSIL/Toolbar.Linkury.S potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\ProgramData\CismaUva\yveg3ufu.dll a variant of Win32/Adware.PennyBee.L application cleaned by deleting - quarantined
C:\FRST\Quarantine\C\ProgramData\ExtTag\ExtTag.dll a variant of MSIL/Toolbar.Linkury.AD potentially unwanted application cleaned by deleting - quarantined
C:\FRST\Quarantine\C\Users\user\AppData\Local\nszB6C5.tmp.xBAD Win32/AnyProtect.G potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Users\user\AppData\Local\Temp\3280.exe.xBAD a variant of Win32/Toolbar.CrossRider.CZ potentially unwanted application cleaned by deleting - quarantined
C:\FRST\Quarantine\C\Users\user\AppData\Local\Temp\9569.exe.xBAD a variant of Win32/Packed.ScrambleWrapper.O potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Users\user\AppData\Local\Temp\amisetup7124__13312.exe.xBAD a variant of Win32/Amonetize.HG potentially unwanted application cleaned by deleting - quarantined
C:\FRST\Quarantine\C\Users\user\AppData\Local\Temp\bitool.dll.xBAD Win32/Somoto.B potentially unwanted application cleaned by deleting - quarantined
C:\FRST\Quarantine\C\Users\user\AppData\Local\Temp\KMP_3.9.1.135.exe.xBAD a variant of Win32/CNETInstaller.B potentially unwanted application cleaned by deleting - quarantined
C:\FRST\Quarantine\C\Users\user\AppData\Local\Temp\setup3.exe.xBAD a variant of Win32/HideBaid.L potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Users\user\AppData\Roaming\3QfIPPiT.xBAD JS/Toolbar.Crossrider.I potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Users\user\AppData\Roaming\5UQtIkbPTkE.xBAD JS/Toolbar.Crossrider.I potentially unwanted application deleted - quarantined
C:\Program Files\baidu\Bind.exe a variant of Win32/HideBaid.L potentially unwanted application cleaned by deleting - quarantined
C:\Users\user\AppData\Roaming\uTorrent\updates\3.4.2_38758.exe a variant of Win32/OpenCandy.C potentially unsafe application cleaned by deleting - quarantined
C:\Users\user\AppData\Roaming\ZHP\Quarantine\AutoKMS.exe MSIL/HackKMS.A potentially unsafe application cleaned by deleting - quarantined
C:\Users\user\Downloads\dfdownloader_6LVB1B_.exe Win32/DepoDownloader.A potentially unwanted application cleaned by deleting - quarantined
C:\Users\user\Downloads\uTorrent.exe a variant of Win32/OpenCandy.C potentially unsafe application cleaned by deleting - quarantined
C:\Users\user\Downloads\Английско-немско-български картинен речник-8651764-6.zip a variant of Win32/Adware.FileTour.ACZ application deleted - quarantined

След сканирането Уиндоус иска да се ъпдейтва и рестартира. Спрях го за сега,ще чакам отговорът Ви. Това ли трябваше да се случи?

Редактирано от Sneji_B (преглед на промените)

Това, което виждате в лог файла: application deleted - quarantined трябваше да се случи. Уверете се, че антивирусната ви е напълно обновена и направете пълно сканиране на системата ви. След това ми пишете за резултатите.

  • Автор

Пуснах сканирането , но стигна до 99% и ми излезе съобщение че е намерило нещи си, и за да продължи сканирането трябва да избера действие Въпроса е какво действие да предприема за този файл ?

post-361097-0-85932500-1440492697_thumb.

Изберете Delete, това е копие на зловредния софтуер, който премахнахме и ще изчистим веднага след като приключим работата ни тук.

  • Автор
25.08.2015 12.28.19 Full Scan Task completed Completion time: Today, 8/25/2015 12:28 PM
25.08.2015 12.28.19 Detected object (file) was deleted. C:\FRST\Quarantine\C\Program Files\4C4C4544-1440146753-5710-804D-B5C04F4B344A\4C4C4544-1440146753-5710-804D-B5C04F4B344A\Uninstall.exe File: C:\FRST\Quarantine\C\Program Files\4C4C4544-1440146753-5710-804D-B5C04F4B344A\4C4C4544-1440146753-5710-804D-B5C04F4B344A\Uninstall.exe Object name: not-a-virus:AdWare.NSIS.ConvertAd.jko
25.08.2015 12.28.19 Detected object (file) was moved to Quarantine. C:\FRST\Quarantine\C\Program Files\4C4C4544-1440146753-5710-804D-B5C04F4B344A\4C4C4544-1440146753-5710-804D-B5C04F4B344A\Uninstall.exe File: C:\FRST\Quarantine\C\Program Files\4C4C4544-1440146753-5710-804D-B5C04F4B344A\4C4C4544-1440146753-5710-804D-B5C04F4B344A\Uninstall.exe Object name: not-a-virus:AdWare.NSIS.ConvertAd.jko
25.08.2015 10.52.34 Object (file) not processed. C:\FRST\Quarantine\C\Program Files\4C4C4544-1440146753-5710-804D-B5C04F4B344A\4C4C4544-1440146753-5710-804D-B5C04F4B344A\Uninstall.exe File: C:\FRST\Quarantine\C\Program Files\4C4C4544-1440146753-5710-804D-B5C04F4B344A\4C4C4544-1440146753-5710-804D-B5C04F4B344A\Uninstall.exe Object name: not-a-virus:AdWare.NSIS.ConvertAd.jko Reason: Postponed
25.08.2015 10.52.34 Object (file) detected. C:\FRST\Quarantine\C\Program Files\4C4C4544-1440146753-5710-804D-B5C04F4B344A\4C4C4544-1440146753-5710-804D-B5C04F4B344A\Uninstall.exe File: C:\FRST\Quarantine\C\Program Files\4C4C4544-1440146753-5710-804D-B5C04F4B344A\4C4C4544-1440146753-5710-804D-B5C04F4B344A\Uninstall.exe Object name: not-a-virus:AdWare.NSIS.ConvertAd.jko
25.08.2015 10.38.23 Full Scan Task started Time: Today, 8/25/2015 10:38 AM

25.08.2015 12.37.51 Rootkit Scan Task completed Completion time: Today, 8/25/2015 12:37 PM
25.08.2015 12.28.19 Rootkit Scan Task started Time: Today, 8/25/2015 12:28 PM
 
 
Май това трябва да са логовете.

Редактирано от Sneji_B (преглед на промените)

Точно така! Благодаря!

  • Моля, изтеглете ESET Service Repair и го запазете на вашия работен плот.
  • Кликнете с десен бутон върху ServiceRepair.exe и изберете Run as administrator и потвърдете с Yes.
  • Ще получите въпроса дали искате да продължите с изпълнението на този инструмент, изберете отново Yes.
  • След като инструментът приключи своята работа ще бъде поискано да се рестартира компютъра. Изберете Yes.
След рестарта, моля генерирайте нов лог файл от Farbar Service Scanner и публикувайте лог файла си тук.
  • Автор

Аз Ви благодаря! 

На работният плот се появи папка CC Support с две подпaпки в нея Logs i Tools:

Това е лога от подпапка Logs. Това ли Ви трябва?

 

Log Opened: 2015-08-25 @ 14:46:59
14:46:59 - -----------------
14:46:59 - | Begin Logging |
14:46:59 - -----------------
14:46:59 - Fix started on a WIN_7 X86 computer
14:46:59 - Prep in progress.  Please Wait.
14:47:00 - Prep complete
14:47:00 - Repairing Services Now.  Please wait...
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\BFE.sddl'
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE\Parameters\Policy\Persistent\SubLayer>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE\Parameters\Policy\Persistent\Provider>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE\Parameters\Policy\Persistent\Filter>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE\Parameters\Policy\Persistent>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE\Parameters\Policy\BootTime\Filter>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE\Parameters\Policy\BootTime>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE\Parameters\Policy>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE\Parameters>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE>
 
SetACL finished successfully.
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\BITS.sddl'
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BITS\Security>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BITS\Performance>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BITS\Parameters>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BITS>
 
SetACL finished successfully.
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\iphlpsvc.sddl'
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\Teredo>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\Parameters\Teredo\{FA88062C-9A61-4C1E-AC45-7143F8F01AAD}>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\Parameters\Teredo>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\Parameters\Isatap\{8AD2FB26-F91E-44F1-9B24-3C0AE56C9CE0}>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\Parameters\Isatap>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\Parameters\IPHTTPS>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\Parameters>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\Interfaces>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\config>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc>
 
SetACL finished successfully.
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\MpsSvc.sddl'
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc\Security>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc\Parameters\PortKeywords\Teredo>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc\Parameters\PortKeywords\RPC-EPMap>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc\Parameters\PortKeywords\IPTLSOut>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc\Parameters\PortKeywords\IPTLSIn>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc\Parameters\PortKeywords\DHCP>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc\Parameters\PortKeywords>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc\Parameters>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc>
 
SetACL finished successfully.
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\SharedAccess.sddl'
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\Logging>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\RestrictedServices\Static\System>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\RestrictedServices\Static>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\RestrictedServices\Configurable\System>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\RestrictedServices\Configurable>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\RestrictedServices>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\Logging>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\GloballyOpenPorts>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\AuthorizedApplications>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\Logging>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Epoch2>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Epoch>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Defaults\FirewallPolicy\StandardProfile\Logging>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Defaults\FirewallPolicy\StandardProfile>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Defaults\FirewallPolicy\PublicProfile\Logging>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Defaults\FirewallPolicy\PublicProfile>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Defaults\FirewallPolicy\FirewallRules>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Defaults\FirewallPolicy\DomainProfile\Logging>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Defaults\FirewallPolicy\DomainProfile>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Defaults\FirewallPolicy>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Defaults>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess>
 
SetACL finished successfully.
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\WinDefend.sddl'
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\WinDefend\TriggerInfo\0>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\WinDefend\TriggerInfo>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\WinDefend\Security>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\WinDefend\Parameters>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\WinDefend>
 
SetACL finished successfully.
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\wscsvc.sddl'
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\wscsvc\Security>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\wscsvc\Parameters>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\wscsvc>
 
SetACL finished successfully.
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\wuauserv.sddl'
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\wuauserv\Security>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\wuauserv\Parameters>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\wuauserv>
 
SetACL finished successfully.
14:47:03 - Services Repair Complete.
14:47:25 - Reboot Initiated

И това също е полезно. Друго, което ми трябва е лог файла от Farbar Service Scanner, който използвахте при стъпка 4 тук:

https://www.kaldata.com/forums/topic/244966-самоинсталиращи-се-програми-които-не-се-премах/?p=3186680

  • Автор
Farbar Service Scanner Version: 26-07-2015
Ran by user (administrator) on 25-08-2015 at 15:09:47
Running from "C:\Users\user\Downloads"
Microsoft Windows 7 Ultimate  Service Pack 1 (X86)
Boot Mode: Normal
****************************************************************
 
Internet Services:
============
 
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.
 
 
Windows Firewall:
=============
 
Firewall Disabled Policy: 
==================
 
 
System Restore:
============
 
System Restore Policy: 
========================
 
 
Action Center:
============
 
 
Windows Update:
============
 
Windows Autoupdate Disabled Policy: 
============================
 
 
Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.
 
 
Windows Defender Disabled Policy: 
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1
 
 
Other Services:
==============
 
 
File Check:
========
C:\Windows\system32\nsisvc.dll => File is digitally signed
C:\Windows\system32\Drivers\nsiproxy.sys => File is digitally signed
C:\Windows\system32\dhcpcore.dll => File is digitally signed
C:\Windows\system32\Drivers\afd.sys => File is digitally signed
C:\Windows\system32\Drivers\tdx.sys => File is digitally signed
C:\Windows\system32\Drivers\tcpip.sys => File is digitally signed
C:\Windows\system32\dnsrslvr.dll => File is digitally signed
C:\Windows\system32\mpssvc.dll => File is digitally signed
C:\Windows\system32\bfe.dll => File is digitally signed
C:\Windows\system32\Drivers\mpsdrv.sys => File is digitally signed
C:\Windows\system32\SDRSVC.dll => File is digitally signed
C:\Windows\system32\vssvc.exe => File is digitally signed
C:\Windows\system32\wscsvc.dll => File is digitally signed
C:\Windows\system32\wbem\WMIsvc.dll => File is digitally signed
C:\Windows\system32\wuaueng.dll => File is digitally signed
C:\Windows\system32\qmgr.dll => File is digitally signed
C:\Windows\system32\es.dll => File is digitally signed
C:\Windows\system32\cryptsvc.dll => File is digitally signed
C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
C:\Windows\system32\ipnathlp.dll => File is digitally signed
C:\Windows\system32\iphlpsvc.dll => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
 
 
**** End of log ****
  • Автор

Чудесно се държи! Струва ми се,че по-бързо зарежда страниците.

Радвам се! :)

Почисти сме готови!

Стъпка 1

Нека изчистим използваните инструменти:

Изтеглете Delfix.exe и го стартирайте. Сложете отметка пред Remove disinfection tools (трябва да има такава по-подразбиране, но все пак да си кажа) => натиснете бутона Run. Инструмента ще се самоизтрие след като приключи своята задача!

Стъпка 2

Изтеглете Security Check от screen317 от този линк или и го запаметете на вашия десктоп.

Кликнете два пъти върху SecurityCheck.exe и следвайте инструкциите.

Накрая, автоматично ще се отвори текстов документ, наречен checkup.txt, моля прикачете го в следващия ви коментар в тази тема.

  • Автор

А тези съобщения на Касперски, предполагам са стари, как да ги изчистя?

post-361097-0-52734700-1440505027_thumb.

  • Автор
 Results of screen317's Security Check version 1.008  
 Windows 7 Service Pack 1 x86 (UAC is disabled!)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:`````````````` 
 Windows Firewall Enabled!  
Kaspersky Total Security   
 Antivirus up to date!   
`````````Anti-malware/Other Utilities Check:````````` 
 Java 7 Update 75  
 Java 8 Update 45  
 Java version 32-bit out of Date! 
  Adobe Flash Player 11.1.102.55 Flash Player out of Date!  
 Adobe Reader 9 Adobe Reader out of Date! 
 Google Chrome (44.0.2403.157) 
````````Process Check: objlist.exe by Laurent````````  
 Kaspersky Lab Kaspersky Total Security 16.0.0 avp.exe  
 Kaspersky Lab Kaspersky Total Security 16.0.0 avpui.exe  
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C: 2% 
````````````````````End of Log`````````````````````` 

Няколко малки стъпки:

  • Автор

Добре, изпълних препоръките Ви.

За User Account Control (UAC) избрах предпоследното ниво на защита (Програми се опитват да инсталират софтуер или искат да правят промени). Вие, кое ще ми препоръчате?

Security check е само изпълним файл и мога просто да го изтрия, нали?

Редактирано от Sneji_B (преглед на промените)

  • Автор

Признателна съм Ви, за това което направихте! Помоща Ви е безценна! :)

 

 

Благодаря Ви! 

Успех!

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.