Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Проверка за зарази

Featured Replies

Добър ден

Днес забелязах, че имам някакви странни start up програми като Microsoft Operating System или като Domino, което се намира в Windows папката? Компютърът ми не се бави, но може и да е инфектиран. Поствам лог файловете

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:31-08-2015
Ran by PC (administrator) on PC-PC (02-09-2015 13:17:47)
Running from C:\Users\PC\Desktop
Loaded Profiles: PC (Available Profiles: PC)
Platform: Windows 7 Enterprise Service Pack 1 (X64) Language: Bulgarian (Bulgaria)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(COMODO) E:\COMODO\COMODO Internet Security\cmdagent.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD13\Kernel\DMS\CLMSMonitorServicePDVD13.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD13\Kernel\DMS\CLMSServerPDVD13.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(COMODO) E:\COMODO\COMODO Internet Security\cistray.exe
(Vimicro) C:\Windows\vmsnap3.exe
(Skype Technologies S.A.) D:\Skype\Phone\Skype.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Skillbrains) C:\Program Files (x86)\Skillbrains\lightshot\5.2.1.1\Lightshot.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(COMODO) E:\COMODO\COMODO Internet Security\cavwp.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(COMODO) E:\COMODO\COMODO Internet Security\cis.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13662936 2013-10-24] (Realtek Semiconductor)
HKLM\...\Run: [COMODO Internet Security] => E:\COMODO\COMODO Internet Security\cistray.exe [1426136 2015-04-20] (COMODO)
HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [226560 2014-12-12] ()
HKLM-x32\...\Run: [sunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-09-02] (Oracle Corporation)
HKU\S-1-5-21-1372586815-2290778262-161615380-1000\...\Run: [LightShot] => C:\Users\PC\AppData\Local\Skillbrains\lightshot\Lightshot.exe
HKU\S-1-5-21-1372586815-2290778262-161615380-1000\...\Run: [skype] => D:\Skype\Phone\Skype.exe [53736048 2015-08-07] (Skype Technologies S.A.)
Startup: C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.exe - Shortcut.lnk [2015-06-21]
ShortcutTarget: ctfmon.exe - Shortcut.lnk -> C:\Windows\System32\ctfmon.exe (Microsoft Corporation)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
ProxyServer: [s-1-5-21-1372586815-2290778262-161615380-1000] => 107.6.143.81:8080
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{3AB5CAD0-65B5-4640-85EA-D28F04097744}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{3AB5CAD0-65B5-4640-85EA-D28F04097744}: [DhcpNameServer] 192.168.0.1
 
Internet Explorer:
==================
HKU\S-1-5-21-1372586815-2290778262-161615380-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.bg/
HKU\S-1-5-21-1372586815-2290778262-161615380-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
SearchScopes: HKU\S-1-5-21-1372586815-2290778262-161615380-1000 -> {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL = 
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-07-18] (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll [2015-09-02] (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-07-18] (Google Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-09-02] (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-07-18] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-07-18] (Google Inc.)
Toolbar: HKU\S-1-5-21-1372586815-2290778262-161615380-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-07-18] (Google Inc.)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
 
FireFox:
========
FF ProfilePath: C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\sjqg2c0o.default-1435491856987
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll [2015-08-21] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [No File]
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-08-21] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-09-02] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-09-02] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2013-08-20] (Nero AG)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2013-12-19] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2013-12-19] (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [No File]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-28] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1372586815-2290778262-161615380-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\PC\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-09-02] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-1372586815-2290778262-161615380-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2014-12-27] ()
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\911bg.xml [2014-11-14]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\diribg.xml [2014-11-14]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\pe-bg.xml [2014-11-14]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\portalbgdict.xml [2014-11-14]
FF Extension: RivalGaming  - C:\Users\PC\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[email protected] [2014-01-23]
 
Chrome: 
=======
CHR StartupUrls: Default -> "hxxp://www.google.bg/"
CHR Profile: C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Duolingo on the Web) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aiahmijlpehemcpleichkcokhegllfjl [2015-05-08]
CHR Extension: (Lamborghini Newport) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aoophnighhnlkbbfhbmjgkogegjhijfg [2014-01-23]
CHR Extension: (Search by Image (by Google)) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\dajedkncpodkggklbegccjpmnglmnflm [2014-08-16]
CHR Extension: (Digital Clock) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\gdkjifoifglkpcdffkenpinlbjgephlo [2014-01-23]
CHR Extension: (AdBlock) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-06-04]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-13]
CHR Extension: (Clock) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjocghlclkpgheifflemilcnblodjohg [2015-02-06]
CHR Extension: (Chrome Web Store Payments) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-23]
CHR Extension: (My Chrome Theme) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\oehpjpccmlcalbenfhnacjeocbjdonic [2014-01-23]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 cmdAgent; E:\COMODO\COMODO Internet Security\cmdagent.exe [5540424 2015-04-20] (COMODO)
S3 cmdvirth; E:\COMODO\COMODO Internet Security\cmdvirth.exe [2265816 2015-04-20] (COMODO)
R2 CyberLink PowerDVD 13 Media Server Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD13\Kernel\DMS\CLMSMonitorServicePDVD13.exe [77576 2013-03-20] (CyberLink)
R2 CyberLink PowerDVD 13 Media Server Service; C:\Program Files (x86)\CyberLink\PowerDVD13\Kernel\DMS\CLMSServerPDVD13.exe [323336 2013-03-20] (CyberLink)
R2 MSSQL$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [57617752 2009-03-30] (Microsoft Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1494304 2013-12-10] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15129376 2013-12-10] (NVIDIA Corporation)
S3 Origin Client Service; D:\Origin\OriginClientService.exe [1900400 2014-11-05] (Electronic Arts)
S2 SkypeUpdate; D:\Skype\Updater\Updater.exe [327296 2015-07-09] (Skype Technologies)
S4 SQLAgent$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [427880 2009-03-30] (Microsoft Corporation)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5448976 2015-04-25] (TeamViewer GmbH)
S3 VsEtwService120; D:\Visual Studio\Common7\Packages\Debugger\Services\VsEtwService.exe [87728 2013-10-05] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [303616 2014-03-18] () [File not signed]
R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [20696 2015-04-01] (COMODO)
R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [797280 2015-04-01] (COMODO)
R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [45880 2015-04-01] (COMODO)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-01-26] (Disc Soft Ltd)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [104608 2015-04-01] (COMODO)
S2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [35328 2014-03-18] () [File not signed]
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-05] (NVIDIA Corporation)
S3 RTL8023x64; C:\Windows\System32\DRIVERS\Rtnic64.sys [51712 2009-06-10] (Realtek Semiconductor Corporation                           )
R3 vvftav303; C:\Windows\System32\drivers\vvftav303.sys [308096 2015-09-02] (Vimicro Corporation)
R3 ZSMC0303; C:\Windows\System32\Drivers\usbVM303.sys [1494656 2015-09-02] (Vimicro Corporation)
R2 {09F57980-3432-4AFC-957D-27AC45FAE1F5}; C:\Program Files (x86)\CyberLink\PowerDVD13\Common\NavFilter\000.fcl [130320 2013-03-19] (CyberLink Corp.)
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-09-02 13:17 - 2015-09-02 13:18 - 00016101 _____ C:\Users\PC\Desktop\FRST.txt
2015-09-02 13:17 - 2015-09-02 13:17 - 02188800 _____ (Farbar) C:\Users\PC\Desktop\FRST64.exe
2015-09-02 13:17 - 2015-09-02 13:17 - 00000000 ____D C:\FRST
2015-09-02 02:37 - 2015-09-02 02:37 - 00000000 ____D C:\Users\PC\AppData\Roaming\Unity
2015-09-02 02:20 - 2015-09-02 02:20 - 01494656 _____ (Vimicro Corporation) C:\Windows\system32\Drivers\usbVM303.sys
2015-09-02 02:20 - 2015-09-02 02:20 - 00360448 _____ (Vimicro) C:\Windows\SysWOW64\VM303Prp.Ax
2015-09-02 02:20 - 2015-09-02 02:20 - 00308096 _____ (Vimicro Corporation) C:\Windows\system32\Drivers\vvftav303.sys
2015-09-02 02:20 - 2015-09-02 02:20 - 00172032 _____ (Microsoft Corporation) C:\Windows\amcap.exe
2015-09-02 02:20 - 2015-09-02 02:20 - 00122880 _____ C:\Windows\rm303b.exe
2015-09-02 02:20 - 2015-09-02 02:20 - 00122880 _____ (www.zsmc.com.cn) C:\Windows\VM303Cap.exe
2015-09-02 02:20 - 2015-09-02 02:20 - 00102400 _____ (Vimicro) C:\Windows\SysWOW64\vvftprpav303.ax
2015-09-02 02:20 - 2015-09-02 02:20 - 00081920 _____ (VM) C:\Windows\system32\VM303STI.dll
2015-09-02 02:20 - 2015-09-02 02:20 - 00049152 _____ (Vimicro) C:\Windows\vmsnap3.exe
2015-09-02 02:20 - 2015-09-02 02:20 - 00049152 _____ () C:\Windows\Domino.exe
2015-09-02 02:20 - 2015-09-02 02:20 - 00046592 _____ (Vimicro Cooperation) C:\Windows\SysWOW64\VvFtCtrl.dll
2015-09-02 02:20 - 2015-09-02 02:20 - 00000000 ____D C:\Windows\EffectResources
2015-09-02 02:20 - 2015-09-02 02:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\A4 TECH PC Camera H
2015-09-02 02:20 - 2015-09-02 02:20 - 00000000 ____D C:\Program Files (x86)\A4 tech
2015-09-02 00:59 - 2015-09-02 00:59 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-09-02 00:59 - 2015-09-02 00:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-08-31 18:47 - 2015-08-31 18:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-08-31 18:47 - 2015-08-31 18:47 - 00000000 ____D C:\Program Files (x86)\Skype
2015-08-28 10:25 - 2015-08-28 10:25 - 00000994 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0e162bad01cd4.job
2015-08-21 23:46 - 2015-08-21 23:46 - 00000000 ____D C:\Users\PC\AppData\Roaming\Sun
2015-08-21 23:46 - 2015-08-21 23:46 - 00000000 ____D C:\Users\PC\.oracle_jre_usage
2015-08-19 22:48 - 2015-08-27 20:22 - 00000203 _____ C:\Users\PC\Desktop\To-Do List.txt
2015-08-06 00:15 - 2015-08-06 00:15 - 00000000 ____D C:\Users\PC\AppData\Roaming\java
2015-08-06 00:14 - 2015-08-06 00:14 - 00002106 _____ C:\Users\PC\Desktop\Minecraft.lnk
2015-08-06 00:14 - 2015-08-06 00:14 - 00000000 ____D C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-09-02 13:16 - 2014-01-23 18:14 - 00000000 ____D C:\Users\PC\AppData\Roaming\Skype
2015-09-02 13:10 - 2009-07-14 07:45 - 00021984 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-09-02 13:10 - 2009-07-14 07:45 - 00021984 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-09-02 11:29 - 2014-01-23 17:42 - 02063147 _____ C:\Windows\WindowsUpdate.log
2015-09-02 11:26 - 2014-01-23 18:00 - 00000000 ____D C:\ProgramData\NVIDIA
2015-09-02 11:26 - 2009-07-14 07:51 - 00235351 _____ C:\Windows\setupact.log
2015-09-02 02:20 - 2014-01-23 18:07 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-09-02 02:20 - 2009-07-14 05:34 - 00000776 _____ C:\Windows\win.ini
2015-09-02 00:59 - 2014-08-07 22:14 - 00000000 ____D C:\Program Files (x86)\Java
2015-09-01 20:43 - 2014-01-23 18:20 - 00000000 ____D C:\Users\PC\AppData\Local\Google
2015-08-31 18:47 - 2014-01-23 18:13 - 00000000 ____D C:\ProgramData\Skype
2015-08-29 16:25 - 2014-01-23 18:08 - 00000000 ____D C:\Users\PC\AppData\Roaming\uTorrent
2015-08-28 21:14 - 2009-07-14 06:20 - 00000000 ____D C:\Windows\system32\NDF
2015-08-28 10:25 - 2015-07-15 22:07 - 00000994 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0bf3180585b63.job
2015-08-21 23:46 - 2014-01-23 17:46 - 00000000 ____D C:\Users\PC
2015-08-21 10:02 - 2014-01-23 18:17 - 00778440 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-08-21 10:02 - 2014-01-23 18:17 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-08-21 10:02 - 2014-01-23 18:17 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-08-07 00:05 - 2014-02-09 18:13 - 00000000 ____D C:\Users\PC\AppData\Roaming\.minecraft
 
==================== Files in the root of some directories =======
 
2014-01-23 17:15 - 2013-12-15 20:05 - 0010240 _____ () C:\Users\PC\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-01-23 17:15 - 2012-08-14 15:08 - 0000090 _____ () C:\Users\PC\AppData\Local\fusioncache.dat
2014-01-23 17:15 - 2013-02-09 18:23 - 0000036 _____ () C:\Users\PC\AppData\Local\housecall.guid.cache
2014-01-23 17:15 - 2014-09-15 15:07 - 0007601 _____ () C:\Users\PC\AppData\Local\Resmon.ResmonCfg
2014-01-23 17:15 - 2013-12-09 21:21 - 0000003 _____ () C:\Users\PC\AppData\Local\updater.log
2014-01-23 17:15 - 2015-04-23 18:20 - 0000424 _____ () C:\Users\PC\AppData\Local\UserProducts.xml
2014-01-23 17:51 - 2014-01-23 17:51 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-05-25 10:07
 
==================== End of FRST.txt ============================
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version:31-08-2015
Ran by PC (2015-09-02 13:18:23)
Running from C:\Users\PC\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1372586815-2290778262-161615380-500 - Administrator - Disabled)
Guest (S-1-5-21-1372586815-2290778262-161615380-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1372586815-2290778262-161615380-1002 - Limited - Enabled)
PC (S-1-5-21-1372586815-2290778262-161615380-1000 - Administrator - Enabled) => C:\Users\PC
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Comodo Defense+ (Enabled - Up to date) {4BDD6856-AF0D-06BD-38AB-8A0FE39860CC}
FW: COMODO Firewall (Enabled) {C8870897-C358-086B-2944-184866CC6D0A}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
µTorrent (HKU\S-1-5-21-1372586815-2290778262-161615380-1000\...\uTorrent) (Version: 3.4.2.32239 - BitTorrent Inc.)
A4 TECH PC Camera H (HKLM\...\{ADE16A9D-FBDC-4ecc-B6BD-9C31E51D303B}) (Version:  - )
A4 TECH PC Camera H (HKLM-x32\...\{CE3B8E96-B0AF-4871-9178-1519B58E3A93}) (Version: 2007.11.12 - A4 TECH)
Adobe Flash Player 17 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.232 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.11) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.11 - Adobe Systems Incorporated)
Age of Mythology: Extended Edition (HKLM-x32\...\QWdlb2ZNeXRob2xvZ3lFeHRlbmRlZEVkaXRpb24=_is1) (Version: 1 - )
Auto Clicker v1.9 (HKLM-x32\...\{C0A7E4F3-82CC-416B-82C6-BA06AACFD635}_is1) (Version: 1.9 - MurGee.com)
BS.Player FREE (HKLM-x32\...\BSPlayerf) (Version: 2.67.1076 - AB Team, d.o.o.)
Build Tools - amd64 (Version: 12.0.21005 - Microsoft Corporation) Hidden
Build Tools - x86 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden
Build Tools Language Resources - amd64 (Version: 12.0.21005 - Microsoft Corporation) Hidden
Build Tools Language Resources - x86 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden
BulgarianPhonetic XP by G. Atanasov (HKLM\...\Bulgarian(Phonetic)) (Version:  - )
Canon MP550 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP550_series) (Version:  - )
Cheat Engine 6.4 (HKLM-x32\...\Cheat Engine 6.4_is1) (Version:  - Cheat Engine)
Clicker Heroes (HKLM-x32\...\Steam App 363970) (Version:  - )
COMODO Firewall (HKLM\...\{901D1D88-408D-48E5-80DD-CC3145BD8456}) (Version: 6.3.39949.2976 - COMODO Security Solutions Inc.)
Copa Petrobras de Marcas (HKLM-x32\...\Steam App 359800) (Version:  - Reiza Studios)
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version:  - Valve)
CyberLink PowerDVD 13 (HKLM-x32\...\InstallShield_{3CFDF154-7E60-4E98-A8DF-C693A4F8E6B6}) (Version: 13.0.2720.57 - CyberLink Corp.)
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.48.1.0347 - Disc Soft Ltd)
Entity Framework Tools for Visual Studio 2013 (HKLM-x32\...\{08AEF86A-1956-4846-B906-B01350E96E30}) (Version: 12.0.20912.0 - Microsoft Corporation)
Euro Truck Simulator 2 (HKLM-x32\...\Steam App 227300) (Version:  - SCS Software)
Euro Truck Simulator 2 Multiplayer 0.1.1 r3 Alpha (HKLM-x32\...\{A227B892-C548-4490-9C5D-DB341F8194A6}_is1) (Version: 0.1.1 r3 Alpha - ETS2MP Team)
Europa Universalis III (HKLM-x32\...\Steam App 25800) (Version:  - Paradox Development Studio)
Europa Universalis IV (HKLM-x32\...\Steam App 236850) (Version:  - Paradox Development Studio)
Favorite-Games 5.22 (HKLM-x32\...\Favorite-Games_is1) (Version:  - Favorite-Games 2001-2013 ©)
Gaberoff Koral German Dictionary 1.01 (HKLM-x32\...\Gaberoff Koral German Dictionary 1.01) (Version: 1.01 - Gaberoff KoralSoft )
Garry's Mod (HKLM-x32\...\Steam App 4000) (Version:  - Facepunch Studios)
GeForce Experience NvStream Client Components (Version: 1.6.28 - NVIDIA Corporation) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 44.0.2403.157 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.6710.2136 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.13 - Google Inc.) Hidden
Grand Theft Auto V (HKLM-x32\...\{E01FA564-2094-4833-8F2F-1FFEC6AFCC46}) (Version: "1.00.0000" - Rockstar Games)
Grand Theft Auto: Episodes From Liberty City (HKLM-x32\...\{61B8B2F9-D8DA-4B24-89A9-DB09F38A4899}) (Version: 1.1.0.0 - Rockstar Games)
Grand Theft Auto: Episodes from Liberty City (x32 Version: 1.0.0002.135 - Rockstar Games Inc.) Hidden
GRID 2 (HKLM-x32\...\Steam App 44350) (Version:  - Codemasters Racing)
Java 8 Update 60 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218060F0}) (Version: 8.0.600.27 - Oracle Corporation)
K-Lite Codec Pack 7.9.0 (Full) (HKLM-x32\...\KLiteCodecPack_is1) (Version: 7.9.0 - )
KoralSoft - EuroDictXP (HKLM-x32\...\EuroDictXP) (Version: 3.1 - KoralSoft)
Left 4 Dead 2 (HKLM-x32\...\Steam App 550) (Version:  - Valve)
Lightshot-5.2.1.1 (HKLM-x32\...\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1) (Version: 5.2.1.1 - Skillbrains)
Malwarebytes Anti-Malware version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5 SDK (HKLM-x32\...\{4AE57014-05C4-4864-A13D-86517A7E1BA4}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU) (HKLM-x32\...\{D3517C62-68A5-37CF-92F7-93C029A89681}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft Chart Controls for Microsoft .NET Framework 3.5 (HKLM-x32\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.0.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{F2508213-9989-4E85-A078-72BE483917EF}) (Version: 3.5.88.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation)
Microsoft Help Viewer 1.0 (HKLM\...\Microsoft Help Viewer 1.0) (Version: 1.0.30319 - Microsoft Corporation)
Microsoft Help Viewer 2.1 (HKLM-x32\...\Microsoft Help Viewer 2.1) (Version: 2.1.21005 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2008 (64-bit) (HKLM\...\Microsoft SQL Server 10 Release) (Version:  - Microsoft Corporation)
Microsoft SQL Server 2008 Browser (HKLM-x32\...\{C688457E-03FD-4941-923B-A27F4D42A7DD}) (Version: 10.1.2531.0 - Microsoft Corporation)
Microsoft SQL Server 2008 Native Client (HKLM\...\{BBDE8A3D-64A2-43A6-95F3-C27B87DF7AC1}) (Version: 10.1.2531.0 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Management Objects (HKLM-x32\...\{4E968D9C-21A7-4915-B698-F7AEB913541D}) (Version: 10.50.1447.4 - Microsoft Corporation)
Microsoft SQL Server 2008 Setup Support Files  (HKLM\...\{B40EE88B-400A-4266-A17B-E3DE64E94431}) (Version: 10.1.2731.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Command Line Utilities  (HKLM\...\{58FED865-4F13-408D-A5BF-996019C4B936}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Data-Tier App Framework  (HKLM-x32\...\{1B876496-B3A2-4D22-9B12-B608A3FD4B8B}) (Version: 11.1.2902.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Data-Tier App Framework  (x64) (HKLM\...\{A6BA243E-85A3-4635-A269-32949C98AC7F}) (Version: 11.1.2902.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Express LocalDB  (HKLM\...\{6C026A91-640F-4A23-8B68-05D589CC6F18}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Management Objects  (HKLM-x32\...\{2F7DBBE6-8EBC-495C-9041-46A772F4E311}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Management Objects  (x64) (HKLM\...\{43A5C316-9521-49C3-B9B6-FCE5E1005DF0}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Native Client  (HKLM\...\{D411E9C9-CE62-4DBF-9D92-4CB22B750ED5}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Transact-SQL ScriptDom  (HKLM\...\{54C5041B-0E91-4E92-8417-AAA12493C790}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft SQL Server 2012 T-SQL Language Service  (HKLM-x32\...\{04DD7AF4-A6D3-4E30-9BB9-3B3670719234}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\...\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 x64 ENU (HKLM\...\{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 SP1 x64 ENU (HKLM\...\{78909610-D229-459C-A936-25D92283D3FD}) (Version: 4.0.8876.1 - Microsoft Corporation)
Microsoft SQL Server Data Tools - enu (12.0.30919.1) (HKLM-x32\...\{0D7FCBFB-F478-4D32-901C-83F0BF5A3501}) (Version: 12.0.30919.1 - Microsoft Corporation)
Microsoft SQL Server Data Tools Build Utilities - enu (12.0.30919.1) (HKLM-x32\...\{6781FF9B-E87D-4A03-9373-A55A288B83FA}) (Version: 12.0.30919.1 - Microsoft Corporation)
Microsoft SQL Server System CLR Types (HKLM-x32\...\{2A2F3AE8-246A-4252-BB26-1BEB45627074}) (Version: 10.50.1447.4 - Microsoft Corporation)
Microsoft SQL Server VSS Writer (HKLM\...\{0826F9E4-787E-481D-83E0-BC6A57B056D5}) (Version: 10.1.2531.0 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2012 (HKLM-x32\...\{070C38AC-05CE-43DF-9A20-141332F6AB2B}) (Version: 11.1.3366.16 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2012 (x64) (HKLM\...\{05FF8209-C4F1-4C77-BC28-791653156D20}) (Version: 11.1.3366.16 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974 (HKLM-x32\...\{B7E38540-E355-3503-AFD7-635B2F2F76E1}) (Version: 9.0.30729.4974 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Runtime - 10.0.30319 (HKLM\...\{94D70749-4281-39AC-AD90-B56A0E0A402E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools (HKLM-x32\...\{14DD7530-CCD2-3798-B37D-3839ED6A441C}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual Studio 2010 Express Prerequisites x64 - ENU (HKLM\...\{BCA26999-EC22-3007-BB79-638913079C9A}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual Studio Express 2013 for Windows Desktop - ENU (HKLM-x32\...\{bec3d87e-1d6d-4b15-8383-29068c86b888}) (Version: 12.0.21005.13 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
Minecraft1.7.2 (HKLM-x32\...\Minecraft1.7.2) (Version:  - )
Minecraft1.8 (HKLM-x32\...\Minecraft1.8) (Version:  - )
Mozilla Firefox 33.1.1 (x86 bg) (HKLM-x32\...\Mozilla Firefox 33.1.1 (x86 bg)) (Version: 33.1.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 33.1.1 - Mozilla)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML4 Parser (HKLM-x32\...\{01501EBA-EC35-4F9F-8889-3BE346E5DA13}) (Version: 1.0.0 - Microsoft Game Studios)
MyDefrag v4.3.1 (HKLM\...\MyDefrag v4.3.1_is1) (Version: 4.0.0.0 - J.C. Kessels)
Need for Speed: Hot Pursuit (HKLM-x32\...\Steam App 47870) (Version:  - Criterion Games)
Nero 2014 (HKLM-x32\...\{F384C1E1-3A16-4073-95C3-7271FE0ED4C2}) (Version: 15.0.02200 - Nero AG)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.7.4 - Notepad++ Team)
NVIDIA 3D Vision Controller Driver 332.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 332.21 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 332.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 332.21 - NVIDIA Corporation)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version:  - )
NVIDIA GeForce Experience 1.8.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 1.8.1 - NVIDIA Corporation)
NVIDIA Graphics Driver 332.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 332.21 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.30.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\...\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation)
NVIDIA Virtual Audio 1.2.19 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver) (Version: 1.2.19 - NVIDIA Corporation)
Origin (HKLM-x32\...\Origin) (Version: 9.4.22.2815 - Electronic Arts, Inc.)
PokerStars.bg (HKLM-x32\...\PokerStars.bg) (Version:  - PokerStars.bg)
Prerequisite installer (x32 Version: 15.0.0005 - Nero AG) Hidden
Prerequisites for SSDT  (HKLM-x32\...\{35C1D9D6-87C0-46A3-B1B4-EDBCC063221C}) (Version: 11.1.3000.0 - Microsoft Corporation)
Python 2.7 (64-bit) (HKLM\...\{20C31435-2A0A-4580-BE8B-AC06FC243CA5}) (Version: 2.7.150 - Python Software Foundation)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.49.927.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7083 - Realtek Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.1.5.8 - Rockstar Games)
S.T.A.L.K.E.R. - Shadow of Chernobyl (HKLM-x32\...\S.T.A.L.K.E.R. - Shadow of Chernobyl_is1) (Version: 1.0000 - THQ)
SA Dictionary 2008 Beta 4 (HKLM-x32\...\{055A5AF0-9FEB-440D-B00A-18935C7C171C}) (Version: 6.6.12 - Stefan Angelov)
Service Pack 1 for SQL Server 2008 (KB968369) (64-bit) (HKLM\...\KB968369) (Version: 10.1.2531.0 - Microsoft Corporation)
SHIELD Streaming (Version: 1.6.85 - NVIDIA Corporation) Hidden
Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version:  - 2K Games, Inc.)
Skype™ 7.8 (HKLM-x32\...\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.8.102 - Skype Technologies S.A.)
Speccy (HKLM\...\Speccy) (Version: 1.28 - Piriform)
Sql Server Customer Experience Improvement Program (Version: 10.1.2531.0 - Microsoft Corporation) Hidden
Steam (HKLM-x32\...\Steam) (Version:  - Valve Corporation)
System Requirements Lab CYRI (HKLM-x32\...\{1110A014-1471-4B66-BFDC-E8EED120CC59}) (Version: 6.0.20.0 - Husdawg, LLC)
Team Explorer for Microsoft Visual Studio 2013 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden
TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.41459 - TeamViewer)
The Sims 4 (HKLM-x32\...\VGhlU2ltczQ=_is1) (Version: 1 - )
The Sims™ 4 (HKLM-x32\...\{48EBEBBF-B9F8-4520-A3CF-89A730721917}) (Version: 1.0.732.20 - Electronic Arts Inc.)
TrackMania Nations Forever (HKLM-x32\...\Steam App 11020) (Version:  - Nadeo)
TreeSize Free V3.1 (HKLM-x32\...\TreeSize Free_is1) (Version: 3.1 - JAM Software)
Tropico 4 (HKLM-x32\...\Steam App 57690) (Version:  - Haemimont Games)
Tunatic (HKLM-x32\...\Tunatic) (Version:  - )
Unity Web Player (HKU\S-1-5-21-1372586815-2290778262-161615380-1000\...\UnityWebPlayer) (Version: 4.6.1f1 - Unity Technologies ApS)
Uplay (HKLM-x32\...\Uplay) (Version: 2.0 - Ubisoft)
Victoria II (HKLM-x32\...\Steam App 42960) (Version:  - Paradox Development Studio)
Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU (HKLM-x32\...\{112C23F2-C036-4D40-BED4-0CB47BF5555C}) (Version: 4.0.8080.0 - Microsoft Corporation)
VLC media player 1.1.4 (HKLM-x32\...\VLC media player) (Version: 1.1.4 - VideoLAN)
Winamp (HKLM-x32\...\Winamp) (Version: 5.621  - Nullsoft, Inc)
Winamp Detector Plug-in (HKU\S-1-5-21-1372586815-2290778262-161615380-1000\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc)
Windows Live ID Sign-in Assistant (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation)
WinRAR archiver (HKLM-x32\...\WinRAR archiver) (Version:  - )
Zune (HKLM\...\Zune) (Version: 04.08.2345.00 - Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== Restore Points =========================
 
02-09-2015 02:19:57 Инсталиран A4 TECH PC Camera H
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-14 05:34 - 2014-09-15 19:53 - 00000822 ____A C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {07042B20-FD32-4CFC-ABC2-50F01231217D} - System32\Tasks\Nero\Nero Info => C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe [2013-08-20] (Nero AG)
Task: {4C141D5F-4EF0-4617-9077-C111740B4B3B} - System32\Tasks\{FFFCEC4A-2068-4A3F-A47E-310E8E61CA36} => pcalua.exe -a C:\Users\PC\AppData\Roaming\.minecraft\minecraft.exe -c launcher\Uninstall.exe
Task: {70CD43E2-1F98-4D85-AC6B-63C4A1682910} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => E:\COMODO\COMODO Internet Security\cfpconfg.exe [2015-04-20] (COMODO)
Task: {7914994B-ADF3-4320-A8B2-5411BF95D980} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => E:\COMODO\COMODO Internet Security\cfpconfg.exe [2015-04-20] (COMODO)
Task: {83540555-A2EF-40E8-A47C-78B3445446EC} - System32\Tasks\MyDefrag v4.3.1 Monthly => C:\Program Files\MyDefrag v4.3.1\Scripts\AutomaticMonthly.MyD [2010-05-21] ()
Task: {8649C545-9D2E-411E-B0C9-286B5214796B} - System32\Tasks\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} => E:\COMODO\COMODO Internet Security\cistray.exe [2015-04-20] (COMODO)
Task: {91432982-12DF-4E0C-82DA-41BF8C929003} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {969D6791-439A-4BD8-B97C-FB2F1F3F02E8} - System32\Tasks\MyDefrag v4.3.1 Daily => C:\Program Files\MyDefrag v4.3.1\Scripts\AutomaticDaily.MyD [2010-05-21] ()
Task: {BF3B8E63-5C08-48D9-A766-18AAD8644DCB} - System32\Tasks\update-sys => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [2014-03-25] ()
Task: {D39B3D95-8FB4-4B7A-9A11-C1601FCDC39F} - System32\Tasks\update-S-1-5-21-1372586815-2290778262-161615380-1000 => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [2014-03-25] ()
Task: {E6CE4C90-D98C-4322-B122-78940ADC9203} - System32\Tasks\{DA10CDE3-0A81-4727-84CC-3B6FBDE2A267} => pcalua.exe -a "E:\Revo Uninstaller\Revouninstaller.exe" -d "E:\Revo Uninstaller"
Task: {E8CDCB0F-6F65-4C2C-936F-AC0255D656B2} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-21] (Adobe Systems Incorporated)
Task: {EF791479-0421-4307-A25A-34873E7D3BD7} - System32\Tasks\{CA82246C-FECB-4D0F-B66B-ED1AB6E7E820} => pcalua.exe -a G:\OriginInstaller.exe -d G:\
Task: {F75C29B2-02E9-4D8F-B3E3-EE9721CA145C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {FFAA08E1-B894-45A7-8207-80F0D990B9DE} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-26] (Adobe Systems Incorporated)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0bf3180585b63.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0e162bad01cd4.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\update-S-1-5-21-1372586815-2290778262-161615380-1000.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
Task: C:\Windows\Tasks\update-sys.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
Task: C:\Windows\Tasks\User_Feed_Synchronization-{922373A3-ACF6-4016-AEF9-45FCFD5F8897}.job => C:\Windows\system32\msfeedssync.exe
 
==================== Loaded Modules (Whitelisted) ==============
 
2014-01-23 17:59 - 2013-12-19 21:53 - 00117536 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2010-01-30 03:40 - 2010-01-30 03:40 - 04254560 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2010-03-24 22:38 - 2010-03-24 22:38 - 08794976 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2014-01-23 18:06 - 2005-06-07 13:26 - 00043008 _____ () C:\Program Files (x86)\WinRAR\rarext64.dll
2014-05-12 12:49 - 2014-05-12 12:49 - 00222720 _____ () E:\Notepad++\NppShell_06.dll
2010-01-30 03:41 - 2010-01-30 03:41 - 04254560 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2010-03-24 22:17 - 2010-03-24 22:17 - 08794464 _____ () C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\Windows\amcap.exe:$CmdTcID
AlternateDataStreams: C:\Windows\Domino.exe:$CmdTcID
AlternateDataStreams: C:\Windows\rm303b.exe:$CmdTcID
AlternateDataStreams: C:\Windows\VM303Cap.exe:$CmdTcID
AlternateDataStreams: C:\Windows\vmsnap3.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\CNC550C.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\CNC550I.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\CNC550L.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\CNC550O.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\CNHMCA6.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\CNMIU9Z.DLL:$CmdTcID
AlternateDataStreams: C:\Windows\system32\CNMLM9Z.DLL:$CmdTcID
AlternateDataStreams: C:\Windows\system32\fsquirt.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\MyDefragScreenSaver_v4.3.1.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\MyDefragScreenSaver_v4.3.1.scr:$CmdTcID
AlternateDataStreams: C:\Windows\system32\VM303STI.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\CNC550L.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\CNC550U.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\CNHMCA.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\FlashPlayerApp.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\FlashPlayerInstaller.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\javaws.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\PnkBstrB.ex0:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\PnkBstrB.xtr:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\VM303Prp.Ax:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\vp6vfw.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\VvFtCtrl.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\vvftprpav303.ax:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\bthenum.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\bthpan.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\bthport.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\BTHUSB.SYS:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\mbam.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\mbamchameleon.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\mwac.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\rfcomm.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\USBAUDIO.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\usbscan.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\usbVM303.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\vvftav303.sys:$CmdTcID
AlternateDataStreams: C:\Users\PC\Desktop\FRST64.exe:$CmdTcID
AlternateDataStreams: C:\Users\PC\Desktop\FRST64.exe:$CmdZnID
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1372586815-2290778262-161615380-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\PC\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 8.8.8.8 - 8.8.4.4
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is disabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\Services: eventlog => 2
MSCONFIG\Services: Wecsvc => 3
MSCONFIG\startupfolder: C:^Users^PC^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2010 Screen Clipper and Launcher.lnk => C:\Windows\pss\OneNote 2010 Screen Clipper and Launcher.lnk.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: BCSSync => "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
MSCONFIG\startupreg: Domino => C:\Windows\Domino.exe
MSCONFIG\startupreg: LogMeIn Hamachi Ui => "E:\Hamachi\hamachi-2-ui.exe" --auto-start
MSCONFIG\startupreg: MurGee.com Auto Clicker => D:\Auto Clicker\AutoClicker.exe :silent
MSCONFIG\startupreg: NvBackend => "C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
MSCONFIG\startupreg: PowerDVD13Agent => "C:\Program Files (x86)\CyberLink\PowerDVD13\PowerDVD13Agent.exe"
MSCONFIG\startupreg: ShadowPlay => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
MSCONFIG\startupreg: Skype => "D:\Skype\Phone\Skype.exe" /nosplash /minimized
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: uTorrent => "C:\Users\PC\AppData\Roaming\uTorrent\uTorrent.exe"  /MINIMIZED
MSCONFIG\startupreg: VMSnap3 => C:\Windows\VMSnap3.exe
MSCONFIG\startupreg: Zune Launcher => "C:\Program Files\Zune\ZuneLauncher.exe"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [sPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [sPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [{C8B7E276-0EE3-4C56-B333-7BE4BBFB1E55}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{B37E21E6-5FAA-48FE-8FA4-822794D51E5C}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{7BFD07CD-8E99-491C-B541-E5113F64B417}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{406C4B17-2019-46EE-AA2C-82DDCDC54392}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{FE9695F0-57E4-485A-99CF-CC9BCB519331}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{8140B637-F277-4AB8-A55E-860088FF4687}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{2CB92587-8C39-4C8D-9E02-0C9AD815C2C7}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD13\PowerDVD13.exe
FirewallRules: [{D0B3BC3D-860B-422A-8E15-2F7EFE5D2B9B}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD13\Kernel\DMR\PowerDVD13DMREngine.exe
FirewallRules: [{880B3D97-C17B-435A-9D34-1EDABD61E6FB}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD13\Kernel\DMS\CLMSServerPDVD13.exe
FirewallRules: [{97DD0BD5-9FFA-4160-B481-0A3F09C17F3D}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD13\PowerDVD13Agent.exe
FirewallRules: [{D1B9945F-3AAF-4F40-BEA0-AE6479FACFFF}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD13\PowerDVD13ML.exe
FirewallRules: [{0960DC2F-C566-4B65-8E81-09E51DBF27A3}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD13\Movie\PowerDVD.exe
FirewallRules: [{1C336AEB-717B-4B0C-BEE9-DC8A0C66323B}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD13\Movie\PowerDVD Cinema\PowerDVDCinema13.exe
FirewallRules: [{40B36178-F75B-435B-93C3-A2AB9EB1B2EE}] => (Allow) C:\Program Files (x86)\Nero\Nero Blu-ray Player\Blu-rayPlayer.exe
FirewallRules: [{AB839946-E022-4317-8362-79315DCD77D1}] => (Allow) C:\Program Files (x86)\Nero\Nero Blu-ray Player\Blu-rayPlayer.exe
FirewallRules: [{041BE717-0CA2-4D8A-BF80-98BC00F3F1C7}] => (Allow) C:\Program Files (x86)\Nero\KM\NMDllHost.exe
FirewallRules: [{6D32B088-02DE-4109-97E8-F0029F558B04}] => (Allow) C:\Program Files (x86)\Nero\KM\NMDllHost.exe
FirewallRules: [{05BD0760-294C-4CE0-A3E8-4C415B0112E5}] => (Allow) E:\Steam\Steam.exe
FirewallRules: [{8A05BAE4-E566-4485-A7F0-E08C482D3582}] => (Allow) E:\Steam\Steam.exe
FirewallRules: [{4836D28D-AD3B-4A3C-8C95-7192103AE45C}] => (Allow) C:\Users\PC\uTorrent\uTorrent.exe
FirewallRules: [{D2111862-CA5F-406D-8B09-607AD66EBD7E}] => (Allow) C:\Users\PC\uTorrent\uTorrent.exe
FirewallRules: [{C3E995D5-E7B4-4C14-BA9D-FA8C4E72E6AC}] => (Allow) D:\TBoGT\EFLC\LaunchEFLC.exe
FirewallRules: [{314425D3-5866-4189-AE95-ECC049FD7FCC}] => (Allow) D:\TBoGT\EFLC\LaunchEFLC.exe
FirewallRules: [{59549E8A-33A0-454B-B3A8-9617921BF152}] => (Allow) D:\Visual Studio\Common7\IDE\WDExpress.exe
FirewallRules: [{3E6560E6-C28E-4AB6-B12F-8FDCE0500AF1}] => (Allow) E:\Steam\SteamApps\common\rust\rustlauncher.exe
FirewallRules: [{3E8F7480-7A91-495E-815E-F6C5339D4EB8}] => (Allow) E:\Steam\SteamApps\common\rust\rustlauncher.exe
FirewallRules: [{73892C9F-AA1F-4B6F-8B35-C4F3E7DAC3EF}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{547AC21C-5277-4AB3-8743-0C77032B3DB7}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{5CFDE8CB-D04E-4C4B-813C-7F4C05474E5F}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{E3EE8D42-16D9-4E4F-9B7F-865E015721B2}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{B8636AFD-A375-4025-9DEC-5252D2C8F6E1}] => (Allow) D:\SteamLibrary\SteamApps\common\Europa Universalis IV\eu4.exe
FirewallRules: [{F8B4F00C-5126-49AE-AE90-839AE93FC6E3}] => (Allow) D:\SteamLibrary\SteamApps\common\Europa Universalis IV\eu4.exe
FirewallRules: [{7598C56F-76B0-43C5-9F06-BAF0E2C1D936}] => (Allow) C:\Users\PC\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{91488942-86AE-4573-B690-5A83C295C7F9}] => (Allow) C:\Users\PC\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{4504A1C8-337F-4B1F-ADA8-FA1CE05966E2}] => (Allow) D:\Skype\Phone\Skype.exe
FirewallRules: [{33FAD8D8-6211-4C75-8555-E485CABF6EBF}] => (Allow) C:\Program Files (x86)\Fiddler2\Fiddler.exe
FirewallRules: [{753344BD-0663-496A-ABD8-C1667255D7CC}] => (Allow) E:\Steam\bin\steamwebhelper.exe
FirewallRules: [{0D77B0A2-B9EA-4AD2-96A1-24E97A47C2FA}] => (Allow) E:\Steam\bin\steamwebhelper.exe
FirewallRules: [{92E34AB0-EA37-4143-A424-ABB2703412A9}] => (Allow) D:\New folder\TeamViewer.exe
FirewallRules: [{2F3073F9-B393-4415-9A8E-F0EB0C3DFCC7}] => (Allow) D:\New folder\TeamViewer.exe
FirewallRules: [{64DE7991-B0F2-4820-BD51-418727DE22EA}] => (Allow) D:\New folder\TeamViewer_Service.exe
FirewallRules: [{FC6D7414-C3E4-4ABB-A298-48F5B2102711}] => (Allow) D:\New folder\TeamViewer_Service.exe
FirewallRules: [{F49D3652-9F8B-4A42-98F3-8F168CD3A7E1}] => (Allow) E:\Steam\SteamApps\common\rust\legacy\rust.exe
FirewallRules: [{7FDBF735-0B6A-44C9-9A19-F57F8B861A68}] => (Allow) E:\Steam\SteamApps\common\rust\legacy\rust.exe
FirewallRules: [{CAB705D8-D96B-4097-8216-5E0C1E02318C}] => (Allow) E:\Steam\SteamApps\common\rust\experimental\Rust.exe
FirewallRules: [{9084A275-3EBA-41A6-AE8A-248252BAFD8A}] => (Allow) E:\Steam\SteamApps\common\rust\experimental\Rust.exe
FirewallRules: [{9D1C98AA-7AA2-4D06-AB10-93CB0ECAA11D}] => (Allow) %ProgramFiles%\Zune\Zune.exe
FirewallRules: [{102562F1-CA0F-482E-BBE7-4FB37F055046}] => (Allow) %ProgramFiles%\Zune\ZuneNSS.exe
FirewallRules: [{6C819994-0B0C-44E8-9433-157C8BE6E7B2}] => (Allow) %ProgramFiles%\Zune\ZuneNSS.exe
FirewallRules: [{886D2D36-3B0A-424B-B3BC-7CDB9E8565B5}] => (Allow) %ProgramFiles%\Zune\ZuneNSS.exe
FirewallRules: [{A92F6B7E-3CE8-44D2-93CC-844FD6B0E847}] => (Allow) %ProgramFiles%\Zune\ZuneNSS.exe
FirewallRules: [{31D85505-21AF-419F-AB86-E14B4D277342}] => (Allow) %ProgramFiles%\Zune\ZuneNSS.exe
FirewallRules: [{BE0ED44F-C064-4BBA-9FE0-BD267AE21E7F}] => (Allow) %ProgramFiles%\Zune\ZuneNSS.exe
FirewallRules: [{47B72E46-778F-411F-A8C4-DE2B7F86577A}] => (Allow) %ProgramFiles%\Zune\ZuneNSS.exe
FirewallRules: [{02DAA7CF-225F-4415-A2B8-B40AC7174B51}] => (Allow) %ProgramFiles%\Zune\ZuneNSS.exe
FirewallRules: [{7E4BA311-9A17-4A69-9047-DB58D8B4E5CB}] => (Allow) E:\Steam\SteamApps\common\Victoria 2\victoria2.exe
FirewallRules: [{A68FE55C-90C8-4A82-87B7-6743CB0EC702}] => (Allow) E:\Steam\SteamApps\common\Victoria 2\victoria2.exe
FirewallRules: [{0B09B28F-041B-4D4B-ADCB-19DFC4805D3F}] => (Allow) E:\Steam\SteamApps\common\CSNZ\Bin\cstrike-online.exe
FirewallRules: [{C87AD9B8-6498-4A52-9B9C-0A7D69BBA893}] => (Allow) E:\Steam\SteamApps\common\CSNZ\Bin\cstrike-online.exe
FirewallRules: [{82E7F948-85CF-4C54-8D24-358E63489B99}] => (Allow) E:\Steam\SteamApps\common\Europa Universalis III - Complete\eu3game.exe
FirewallRules: [{6340A8C6-4E03-4E95-A610-7F4C54C44044}] => (Allow) E:\Steam\SteamApps\common\Europa Universalis III - Complete\eu3game.exe
FirewallRules: [{6968C2AF-B9A6-4234-AC63-83AF7FCCBD94}] => (Allow) D:\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\XR_3DA.exe
FirewallRules: [{85FC1DAC-05DF-49AD-A024-7FD612F1F57C}] => (Allow) D:\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\XR_3DA.exe
FirewallRules: [{BF0A9B5C-1A62-4ABE-BE02-600A889E0208}] => (Allow) D:\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\dedicated\XR_3DA.exe
FirewallRules: [{3EFD79A8-07C3-40BA-8F8E-5EAF8A0F8B30}] => (Allow) D:\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\dedicated\XR_3DA.exe
FirewallRules: [{439A91E2-D37A-4C53-A5BF-C838C4C5DB0E}] => (Allow) E:\Steam\SteamApps\common\TrackMania Nations Forever\TmForever.exe
FirewallRules: [{35F819D6-17BE-4481-9873-85D74D0E5953}] => (Allow) E:\Steam\SteamApps\common\TrackMania Nations Forever\TmForever.exe
FirewallRules: [{A5959C18-2A38-43B8-B428-1F98FFB8FA8B}] => (Allow) E:\Steam\SteamApps\common\TrackMania Nations Forever\TmForeverLauncher.exe
FirewallRules: [{D3D7C8A0-C6B0-415F-A8AE-CE9B3891C31E}] => (Allow) E:\Steam\SteamApps\common\TrackMania Nations Forever\TmForeverLauncher.exe
FirewallRules: [{BD8E108D-D08C-4F60-A33A-A542B0E25910}] => (Allow) E:\Steam\SteamApps\common\Left 4 Dead 2\left4dead2.exe
FirewallRules: [{6FEC8933-B259-4327-B083-6A881993334F}] => (Allow) E:\Steam\SteamApps\common\Left 4 Dead 2\left4dead2.exe
FirewallRules: [{44EE4019-4CD7-4F30-82A4-4BACC86EB3BD}] => (Allow) E:\Steam\SteamApps\common\Far Cry 3\bin\FC3UpdaterSteam.exe
FirewallRules: [{E01E2C04-4BDA-409E-B35B-10F196E3DCD8}] => (Allow) E:\Steam\SteamApps\common\Far Cry 3\bin\FC3UpdaterSteam.exe
FirewallRules: [{4F851702-A405-4C62-8884-03D23C024CBE}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{AB0AB9A4-0554-45D9-AC7A-F8CB0C9EF67E}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{DB363DFF-BD13-46EB-811E-702AB206D8D0}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{08B2150C-CA0A-4CC1-9C5B-FA720BD36707}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{AB929A15-5681-4CE6-BF86-D34364822E39}] => (Allow) E:\Steam\SteamApps\common\grid 2\grid2.exe
FirewallRules: [{D587E02B-B39D-4213-86C9-E9F0B12445BB}] => (Allow) E:\Steam\SteamApps\common\grid 2\grid2.exe
FirewallRules: [{42C34893-D301-4CB1-8F78-7E0BC3F6280D}] => (Allow) E:\Steam\SteamApps\common\Dishonored\Binaries\Win32\Dishonored.exe
FirewallRules: [{C210CAE8-5C66-43B2-8D0B-4832EB86976E}] => (Allow) E:\Steam\SteamApps\common\Dishonored\Binaries\Win32\Dishonored.exe
FirewallRules: [{2962F3A6-B209-487A-9F2A-B05EB7F9465B}] => (Allow) E:\Steam\SteamApps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe
FirewallRules: [{78773129-1557-406B-A453-936CF235D7C1}] => (Allow) E:\Steam\SteamApps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe
FirewallRules: [{8EF11285-27A0-4A37-AD52-52B2B7D1FF3A}] => (Allow) E:\Steam\SteamApps\common\Sid Meier's Civilization V\Launcher.exe
FirewallRules: [{6F64225B-B33C-441B-984B-1644FE04A12C}] => (Allow) E:\Steam\SteamApps\common\Sid Meier's Civilization V\Launcher.exe
FirewallRules: [{BBAB28CE-4F4C-4AA5-AC59-02ABED98CB1E}] => (Allow) E:\Steam\SteamApps\common\Need for Speed Hot Pursuit\NFS11.exe
FirewallRules: [{CA303219-6FB3-4F99-B42C-08BBD80ED61F}] => (Allow) E:\Steam\SteamApps\common\Need for Speed Hot Pursuit\NFS11.exe
FirewallRules: [{BF0E711B-E933-4E5A-A310-B8413F550B76}] => (Allow) E:\Steam\SteamApps\common\Merchants of Brooklyn\Bin32\Launcher.exe
FirewallRules: [{2FBD6E6E-6D76-44BB-A102-481EEF77F632}] => (Allow) E:\Steam\SteamApps\common\Merchants of Brooklyn\Bin32\Launcher.exe
FirewallRules: [{5FECE63F-341E-4E1D-BA37-D126E288D458}] => (Allow) E:\Steam\SteamApps\common\Tropico 4\Tropico4.exe
FirewallRules: [{2367D4EB-4866-47D9-A3DB-87C15FB6208F}] => (Allow) E:\Steam\SteamApps\common\Tropico 4\Tropico4.exe
FirewallRules: [{5C4508EC-3D76-4C7F-AB4A-761562D42500}] => (Allow) E:\Steam\SteamApps\common\GarrysMod\hl2.exe
FirewallRules: [{A69B35AD-5C93-431A-BC9A-A9D402A6C33E}] => (Allow) E:\Steam\SteamApps\common\GarrysMod\hl2.exe
FirewallRules: [{33300E4A-DA8A-4951-959F-9B86B29CC65A}] => (Allow) E:\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{170035D0-3DF0-4782-A0F4-21781B562DDD}] => (Allow) E:\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{BBA09E23-5AD3-409E-B615-03BB8A7F9479}] => (Allow) E:\Steam\SteamApps\common\Copa Petrobras de Marcas\Marcas.exe
FirewallRules: [{113A8581-E547-43FF-A9A2-7D905A00200A}] => (Allow) E:\Steam\SteamApps\common\Copa Petrobras de Marcas\Marcas.exe
FirewallRules: [{71C6147B-5685-43BF-ABE5-AD85489AD1C0}] => (Allow) E:\Steam\SteamApps\common\Copa Petrobras de Marcas\Config.exe
FirewallRules: [{9395938D-E7F3-4486-87D0-11395A5BEE65}] => (Allow) E:\Steam\SteamApps\common\Copa Petrobras de Marcas\Config.exe
FirewallRules: [{84918C45-F5EB-4EAA-A561-87929655869B}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{07876DF1-BA27-4291-8201-3F8EB8ABF4C0}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{13B2BF1A-9DD8-4A39-95B6-3E47D00F196A}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{A0E4C179-EB1E-4D42-A142-AA950888EDF0}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{C1C65901-FF82-4A99-823B-274CDA84214B}] => (Allow) D:\EFLC\LaunchEFLC.exe
FirewallRules: [{451B16F8-2506-4FFF-BC48-7C94E7B713C3}] => (Allow) D:\EFLC\LaunchEFLC.exe
FirewallRules: [{FBD35FAE-0B5A-434E-85EA-211BF1C672FA}] => (Allow) E:\Steam\SteamApps\common\Clicker Heroes\Clicker Heroes.exe
FirewallRules: [{A1D7BB96-C9C9-44B5-8F47-154ADD3C5F88}] => (Allow) E:\Steam\SteamApps\common\Clicker Heroes\Clicker Heroes.exe
FirewallRules: [{A7E477DC-39BB-479E-9626-1BCFA2CFFE19}] => (Allow) D:\The Sims 4\Game\Bin\TS4.exe
FirewallRules: [{5E9DFCCF-54D3-42F8-AD88-7FC9D7302F17}] => (Allow) D:\The Sims 4\Game\Bin\TS4.exe
FirewallRules: [{76C09925-FC4F-40DD-8338-282FF19C4CD2}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{89251630-716C-42D7-84CA-38650BAC1B1D}] => (Allow) E:\Steam\SteamApps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe
FirewallRules: [{C2F5B448-A40F-41C7-AC12-CE3D240C793B}] => (Allow) E:\Steam\SteamApps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe
FirewallRules: [{F6231063-7434-436D-9C28-54402E1ACEAD}] => (Allow) E:\Steam\SteamApps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe
FirewallRules: [{FD8919BA-9B12-4DE2-B7E2-D1057611785C}] => (Allow) E:\Steam\SteamApps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (05/25/2015 12:56:46 PM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) (EventID: 1) (User: )
Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008]
 
Error: (05/25/2015 09:43:57 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (05/25/2015 09:42:46 AM) (Source: NvStreamSvc) (EventID: 1) (User: )
Description: NvStreamSvcNvVAD initialization failed [6]
 
Error: (05/25/2015 09:42:46 AM) (Source: NvStreamSvc) (EventID: 1) (User: )
Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0]
 
Error: (05/24/2015 11:14:43 PM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) (EventID: 1) (User: )
Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008]
 
Error: (05/24/2015 06:28:59 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (05/24/2015 06:27:53 PM) (Source: NvStreamSvc) (EventID: 1) (User: )
Description: NvStreamSvcNvVAD initialization failed [6]
 
Error: (05/24/2015 06:27:53 PM) (Source: NvStreamSvc) (EventID: 1) (User: )
Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0]
 
Error: (05/24/2015 11:37:49 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (05/24/2015 11:36:36 AM) (Source: NvStreamSvc) (EventID: 1) (User: )
Description: NvStreamSvcNvVAD initialization failed [6]
 
 
System errors:
=============
Error: (05/26/2015 02:10:07 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The lirsgt service failed to start due to the following error: 
%%577
 
Error: (05/26/2015 02:10:05 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The atksgt service failed to start due to the following error: 
%%577
 
Error: (05/26/2015 02:09:59 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Планировчик на задачите service depends on the Windows Event Log service which failed to start because of the following error: 
%%1058
 
Error: (05/25/2015 07:36:05 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The lirsgt service failed to start due to the following error: 
%%577
 
Error: (05/25/2015 07:36:04 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The atksgt service failed to start due to the following error: 
%%577
 
Error: (05/25/2015 07:35:58 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Планировчик на задачите service depends on the Windows Event Log service which failed to start because of the following error: 
%%1058
 
Error: (05/25/2015 01:41:50 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The lirsgt service failed to start due to the following error: 
%%577
 
Error: (05/25/2015 01:41:49 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The atksgt service failed to start due to the following error: 
%%577
 
Error: (05/25/2015 01:41:44 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Планировчик на задачите service depends on the Windows Event Log service which failed to start because of the following error: 
%%1058
 
Error: (05/25/2015 09:42:25 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The lirsgt service failed to start due to the following error: 
%%577
 
 
Microsoft Office:
=========================
Error: (05/25/2015 12:56:46 PM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) (EventID: 1) (User: )
Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008]
 
Error: (05/25/2015 09:43:57 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (05/25/2015 09:42:46 AM) (Source: NvStreamSvc) (EventID: 1) (User: )
Description: NvStreamSvcNvVAD initialization failed [6]
 
Error: (05/25/2015 09:42:46 AM) (Source: NvStreamSvc) (EventID: 1) (User: )
Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0]
 
Error: (05/24/2015 11:14:43 PM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) (EventID: 1) (User: )
Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008]
 
Error: (05/24/2015 06:28:59 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (05/24/2015 06:27:53 PM) (Source: NvStreamSvc) (EventID: 1) (User: )
Description: NvStreamSvcNvVAD initialization failed [6]
 
Error: (05/24/2015 06:27:53 PM) (Source: NvStreamSvc) (EventID: 1) (User: )
Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0]
 
Error: (05/24/2015 11:37:49 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (05/24/2015 11:36:36 AM) (Source: NvStreamSvc) (EventID: 1) (User: )
Description: NvStreamSvcNvVAD initialization failed [6]
 
 
CodeIntegrity:
===================================
  Date: 2015-05-26 14:10:07.650
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\lirsgt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2015-05-26 14:10:07.616
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\lirsgt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2015-05-26 14:10:05.889
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\atksgt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2015-05-26 14:10:05.873
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\atksgt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2015-05-25 19:36:05.544
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\lirsgt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2015-05-25 19:36:05.512
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\lirsgt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2015-05-25 19:36:04.624
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\atksgt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2015-05-25 19:36:04.592
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\atksgt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2015-05-25 13:41:50.218
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\lirsgt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2015-05-25 13:41:50.187
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\lirsgt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
 
==================== Memory info =========================== 
 
Processor: Pentium® Dual-Core CPU E5700 @ 3.00GHz
Percentage of memory in use: 35%
Total physical RAM: 6142.49 MB
Available physical RAM: 3977.3 MB
Total Virtual: 6140.67 MB
Available Virtual: 3796.26 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:58.5 GB) (Free:22.99 GB) NTFS
Drive d: () (Fixed) (Total:203.57 GB) (Free:44.74 GB) NTFS
Drive e: () (Fixed) (Total:203.58 GB) (Free:131.62 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 5E10308D)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=58.5 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=407.2 GB) - (Type=OF Extended)
 
==================== End of Addition.txt ============================
 

Здравейте ..активни зарази не се виждат в системата ви..! За контрол:

 

icon_zps423a0d9f.jpgМоля изтеглете ZHPcleaner и я запазете на вашия десктоп.

  • Стартирайте ZHPCleaner с десен клик върху файла и изберете от контекстното меню "Run as administrator"
  • Кликнете върху Ashampoo_Snap_20140819_13h09m50s_001__zp за да се съгласите с лицензионното споразумение.
  • Изберете бутона y3pI4LR.png.
  • Браузърите ще бъдат затворени автоматично.
  • Ще се отвори лог файл след приключването на проверката.
  • Публикувайте лог файла в следващия си коментар.

 

adwcleaner_new.png Сканиране с AdwCleaner
 
Моля, изтеглете и стартирайте програмата AdwCleaner (by Xplode):

  • Затворете всички стартирани програми и браузъри
  • Кликнете два пъти върху adwcleaner.exe за да стартирате инструмента.
  • Натиснете OK, за да потвърдите, че всички стартирани програми ще бъдат затворени.
  • Маркирайте Clean
  • Вашият компютър ще се рестартира автоматично. Текстовия файл ще се отвори след рестарта.
  • Моля, да публикувате съдържанието на този лог в отговора си
  • Можете да намерите лога,който автоматично се запомня тук C:AdwCleaner[s0].txt

 

 

JRTbythisisu.png Сканиране с Junkware Removal Tool
 
Моля, изтеглете Junkware Removal Tool (by Thisisu ) и запазете на вашия десктоп.

  • Спрете временно работата на защитните програми.
  • Стартирайте инструмента JRT.exe
  • Ще се отвори ДОС прозорец. Натиснете което и да е копче от клавиатурата.
  • Затворете излишните приложения и всички браузъри и изчакайте проверката да завърши.
  • Ще се появи лог файл (който можете да намерите и ръчно на десктопа с името JRT.txt).
  • Моля копирайте съдържанието на лог файла в следващия си пост.

 

GUZVCQN.jpg Моля, изтеглете Malwarebytes Anti -Malware и го запомнете на вашия работен плот .

Кликнете два пъти върху mbam-setup - 2.1.4.1018.exe и следвайте инструкциите, за да инсталирате програмата . Убедете се че преди края на инсталацията има отметка тук:

  • Launch Malwarebytes Anti-Malware
  • 14-дневен пробен период е предварително избран. Можете да премахнете отметката ако желаете, при което няма да се ограничат възможностите за сканиране и премахване на зловреден софтуер с програмата.
  • Натиснете Finish
  • В края на инсталацията, ще се извърши актуализация на база данни.
  • Отидете до табът Settings > Detection and Protection > и под категорията Detection Options включете опцията "Scan for rootkits".
  • Отидете до табът Scan, сложете радио-бутона пред Threat Scan и кликнете върху Scan Now и ще започне сканиране за зловреден софтуер.
  • При някои инфекции можете да видите съобщението:

                                      "Could not load DDA driver"

  • Натиснете "Yes" на това съобщение за да позволите драйвера да се зареди след рестарт.
  • Когато сканирането приключи, ако има някакви открити зарази , щракнете върху Remove Selected за да се позволи на Mbam да почисти засеченото. .
  • В повечето случаи, ще се поиска рестартиране
  • Изчакайте подканата за рестартиране на компютъра, за да се появи, след това кликнете върху Yes
  • След рестарта ,стартирайте Mbam още веднъж.
  • Кликнете на History tab > Application Logs .
  • Кликнете два пъти върху реда , който показва датата и часа на сканирането и натиснете бутона "Copy to Clipboard"
  • Поставете съдържанието на лог файла с клавишната комбинация Ctrl + V и го публикувайте в следващия си коментар.

 

 

xpfNZP4A.png.pagespeed.ic.bp5cRl1pJg.jpg  Дневници
 
В следващия си отговор, моля да включите следните дневници:

 

  • Лог файл от ZHPCleaner
  • AdwCleaner[s0].txt
  • JRT.txt
  • Дневник от Malwarebytes Anti -Malware
  • Автор

~ ZHPCleaner v2015.9.4.342 by Nicolas Coolman (2015/09/04)
~ Run by PC (Administrator)  (04/09/2015 22:03:04)
~ Site : http://www.nicolascoolman.fr
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : Version OK
~ Type : Scan
~ Report : C:\Users\PC\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\PC\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
Windows 7 Enterprise, 64-bit Service Pack 1 (Build 7601)


---\\  Services (0)
~ No malicious or unnecessary items found.


---\\  Browser internet (0)
~ No malicious or unnecessary items found.


---\\  Hosts file (1)
~ The hosts file is legitimate (21)


---\\  Scheduled automatic tasks. (0)
~ No malicious or unnecessary items found.


---\\  Explorer ( File, Folder) (23)
FOUND file: C:\END    =>PUP.Optional.Conduit
FOUND file: C:\ProgramData\Tbccint\Multi\CT3329621\UninstallerUI.exe [ClientConnect Ltd. - 1.6.1.11]  =>PUP.Optional.ClientConnect
FOUND file: C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.azlyrics.com_0.localstorage    =>PUP.Optional.AddLyrics
FOUND file: C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.azlyrics.com_0.localstorage-journal    =>PUP.Optional.AddLyrics
FOUND folder: C:\Program Files (x86)\Tbccint  =>PUP.Optional.Conduit
FOUND folder: C:\ProgramData\Tbccint\IE  =>PUP.Optional.Conduit
FOUND folder: C:\ProgramData\Tbccint\Multi  =>PUP.Optional.Conduit
FOUND folder: C:\ProgramData\Tbccint  =>PUP.Optional.Conduit
FOUND file: C:\Users\PC\Documents\Browser\Cookies    =>PUP.Optional.SpeedBrowser
FOUND file: C:\Users\PC\Documents\Browser\iepass.txt    =>PUP.Optional.SpeedBrowser
FOUND file: C:\Users\PC\Documents\Browser\log.txt    =>PUP.Optional.SpeedBrowser
FOUND file: C:\Users\PC\Documents\Browser\login.txt    =>PUP.Optional.SpeedBrowser
FOUND folder: C:\Users\PC\Documents\MediaGet\User  =>PUP.Optional.MediaGet
FOUND folder: C:\Users\PC\Documents\Browser  =>PUP.Optional.SpeedBrowser
FOUND folder: C:\Users\PC\Documents\MediaGet  =>PUP.Optional.MediaGet
FOUND folder: C:\Users\PC\AppData\LocalLow\Tbccint\Community Alerts  =>PUP.Optional.Conduit
FOUND folder: C:\Users\PC\AppData\LocalLow\Tbccint  =>PUP.Optional.Conduit
FOUND folder: C:\Users\PC\AppData\Local\AllSearch\AllSearch.vshost.exe_Url_n5obkntniarz5fm0lgrxbscbqmxv2o0y  =>PUP.Optional.SocialSkinz
FOUND folder: C:\Users\PC\AppData\Local\CrashRpt\UnsentCrashReports  =>.Superfluous.CrashReports
FOUND folder: C:\Users\PC\AppData\Local\Tbccint\Community Alerts  =>PUP.Optional.Conduit
FOUND folder: C:\Users\PC\AppData\Local\AllSearch  =>PUP.Optional.SocialSkinz
FOUND folder: C:\Users\PC\AppData\Local\CrashRpt  =>.Superfluous.CrashReports
FOUND folder: C:\Users\PC\AppData\Local\Tbccint  =>PUP.Optional.Conduit


---\\  Registry ( Key, Value, Data) (5)
FOUND key: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Favorite-Games_is1 [Favorite-Games 5.22]  =>Adware.Favorit
FOUND key: [X64] HKLM\SOFTWARE\Classes\protector_dll.protectorbho [Google Toolbar Notifier BHO]  =>PUP.Optional.BProtector
FOUND key: [X64] HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1 [Google Toolbar Notifier BHO]  =>PUP.Optional.BProtector
FOUND key: [X64] HKLM\SOFTWARE\Classes\Toolbar.CT3329621 []  =>PUP.Optional.Conduit
FOUND key: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} [iTool]  =>Toolbar.Ask


---\\ Result of repair
~ Any repair made


---\\ Statistics
~ Items scanned : 77138
~ Items found : 32
~ Items cancelled : 0
~ Items repaired : 0


~ End of search in 4 minutes
===================
ZHPCleaner--04092015-22_07_30.txt
 

# AdwCleaner v5.005 - Logfile created 04/09/2015 at 22:10:09
# Updated 31/08/2015 by Xplode
# Database : 2015-08-31.2 [server]
# Operating system : Windows 7 Enterprise Service Pack 1 (x64)
# Username : PC - PC-PC
# Running from : C:\Users\PC\Desktop\adwcleaner_5.005.exe
# Option : Scan
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****

Folder Found : C:\Program Files (x86)\Tbccint
Folder Found : C:\ProgramData\Tbccint
Folder Found : C:\Users\PC\AppData\Local\allsearch
Folder Found : C:\Users\PC\AppData\Local\Tbccint
Folder Found : C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\dajedkncpodkggklbegccjpmnglmnflm
Folder Found : C:\Users\PC\AppData\LocalLow\Tbccint
Folder Found : C:\Users\PC\Documents\Browser

***** [ Files ] *****

File Found : C:\END

***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****

Task Found : update-sys
Task Found : update-S-1-5-21-1372586815-2290778262-161615380-1000
Task Found : update-sys
Task Found : update-S-1-5-21-1372586815-2290778262-161615380-1000
Task Found : update-sys

***** [ Registry ] *****

Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3329621
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3A1209A4-8568-40F0-9B5E-4A06A2A06417}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\OCS
Key Found : HKCU\Software\Tbccint
Key Found : HKCU\Software\Tbccint_HKLM
Key Found : HKCU\Software\AppDataLow\Software\Tbccint
Key Found : HKLM\SOFTWARE\Conduit
Key Found : [x64] HKCU\Software\Conduit
Key Found : [x64] HKCU\Software\OCS
Key Found : [x64] HKCU\Software\Tbccint
Key Found : [x64] HKCU\Software\Tbccint_HKLM
Key Found : HKU\S-1-5-21-1372586815-2290778262-161615380-1000\Software\AppDataLow\Software\Tbccint

***** [ Web browsers ] *****

[C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Web data] [search Provider] Found : ask.com
[C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Web data] [search Provider] Found : babylon.com
[C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : bkomkajifikmkfnjgphkjcfeepbnojok
[C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : dajedkncpodkggklbegccjpmnglmnflm
[C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : eooncjejnppfjjklapaamhcdmjbilmde
[C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : nfengeggddojhakldhlpjdlddgkkjkdd

########## EOF - C:\AdwCleaner\AdwCleaner[s1].txt - [2832 bytes] ##########
 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.0 (08.31.2015:1)
OS: Windows 7 Enterprise x64
Ran by PC on ЇҐв 04.09.2015 Ј. at 22:16:53,89
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Tasks



~~~ Registry Values



~~~ Registry Keys



~~~ Files

Successfully deleted: [File] C:\Users\PC\Appdata\Local\google\chrome\user data\default\local storage\chrome-extension_gkojfkhlekighikafcpjkiklfbnlmeio_0.localstorage
Successfully deleted: [File] C:\Users\PC\Appdata\Local\google\chrome\user data\default\local storage\chrome-extension_gkojfkhlekighikafcpjkiklfbnlmeio_0.localstorage-journal
Successfully deleted: [File] C:\Users\PC\Appdata\Local\google\chrome\user data\default\local storage\hxxp_www.azlyrics.com_0.localstorage
Successfully deleted: [File] C:\Users\PC\Appdata\Local\google\chrome\user data\default\local storage\hxxp_www.azlyrics.com_0.localstorage-journal



~~~ Folders

Successfully deleted: [Folder] C:\Users\PC\Appdata\Local\crashrpt
Successfully deleted: [Folder] C:\Users\PC\AppData\Roaming\reviversoft
Successfully deleted: [Folder] C:\Windows\SysWOW64\ai_recyclebin



~~~ FireFox

Emptied folder: C:\Users\PC\AppData\Roaming\mozilla\firefox\profiles\5s621qao.default-1441295505000\minidumps [1 files]



~~~ Chrome


[C:\Users\PC\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset

[C:\Users\PC\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
dajedkncpodkggklbegccjpmnglmnflm

[C:\Users\PC\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset

[C:\Users\PC\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on ЇҐв 04.09.2015 Ј. at 22:36:12,18
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 4.9.2015 г.
Scan Time: 22:59 ч.
Logfile:
Administrator: Yes

Version: 2.1.8.1057
Malware Database: v2015.09.04.07
Rootkit Database: v2015.08.16.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: PC

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 388332
Time Elapsed: 16 min, 46 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)

Здравейте..!

 

  • Стартирайте ZHPCleaner с десен клик върху файла и изберете от контекстното меню "Run as administrator"
  • Кликнете върху Ashampoo_Snap_20140819_13h09m50s_001__zp за да се съгласите с лицензионното споразумение.
  • Направете нова проверка и след като приключи натиснете бутона slm23Pe.png
  • Браузърите ще бъдат затворени автоматично.
  • Ще се отвори лог файл след прикючването на проверката.
  • Публикувайте лог файла в следващия си коментар.

 

Моля,  стартирайте  отново програмата AdwCleaner (by Xplode)...и този път не пропускайте да маркирате Clean

  • Затворете всички стартирани програми и браузъри
  • Кликнете два пъти върху adwcleaner.exe за да стартирате инструмента.
  • Натиснете OK, за да потвърдите, че всички стартирани програми ще бъдат затворени.
  • Маркирайте Clean
  • Вашият компютър ще се рестартира автоматично. Текстовия файл ще се отвори след рестарта.
  • Моля, да публикувате съдържанието на този лог в отговора си
  • Можете да намерите лога,който автоматично се запомня тук C:AdwCleaner[s0].txt
  • Автор

~ ZHPCleaner v2015.9.4.342 by Nicolas Coolman (2015/09/04)
~ Run by PC (Administrator)  (05/09/2015 10:54:35)
~ Site : http://www.nicolascoolman.fr
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : Version OK
~ Type : Repair
~ Report : C:\Users\PC\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\PC\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
Windows 7 Enterprise, 64-bit Service Pack 1 (Build 7601)


---\\  Services (0)
~ No malicious or unnecessary items found.


---\\  Browser internet (0)
~ No malicious or unnecessary items found.


---\\  Hosts file (1)
~ The hosts file is legitimate (21)


---\\  Scheduled automatic tasks. (0)
~ No malicious or unnecessary items found.


---\\  Explorer ( File, Folder) (1)
MOVED folder: C:\Users\PC\Documents\MediaGet  =>PUP.Optional.MediaGet


---\\  Registry ( Key, Value, Data) (2)
DELETED key*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Favorite-Games_is1 [Favorite-Games 5.22]  =>Adware.Favorit
DELETED key*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} [iTool]  =>Toolbar.Ask


---\\ Result of repair
~ Repair carried out successfully


---\\ Statistics
~ Items scanned : 1159
~ Items found : 0
~ Items cancelled : 0
~ Items repaired : 3


~ End of clean in 0 minutes
===================
ZHPCleaner-[R]-05092015-10_54_56.txt
ZHPCleaner--04092015-22_07_30.txt
ZHPCleaner--05092015-10_54_02.txt

 

# AdwCleaner v5.005 - Logfile created 05/09/2015 at 10:55:34
# Updated 31/08/2015 by Xplode
# Database : 2015-08-31.2 [server]
# Operating system : Windows 7 Enterprise Service Pack 1 (x64)
# Username : PC - PC-PC
# Running from : C:\Users\PC\Desktop\adwcleaner_5.005.exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****

[-] Folder Deleted : C:\Program Files (x86)\Tbccint
[-] Folder Deleted : C:\ProgramData\Tbccint
[-] Folder Deleted : C:\Users\PC\AppData\Local\allsearch
[-] Folder Deleted : C:\Users\PC\AppData\Local\Tbccint
[-] Folder Deleted : C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\dajedkncpodkggklbegccjpmnglmnflm
[-] Folder Deleted : C:\Users\PC\AppData\LocalLow\Tbccint
[-] Folder Deleted : C:\Users\PC\Documents\Browser

***** [ Files ] *****

[-] File Deleted : C:\END

***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****

[-] Task Deleted : update-sys
[-] Task Deleted : update-S-1-5-21-1372586815-2290778262-161615380-1000
[-] Task Deleted : update-sys
[-] Task Deleted : update-S-1-5-21-1372586815-2290778262-161615380-1000
[-] Task Deleted : update-sys

***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3329621
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3A1209A4-8568-40F0-9B5E-4A06A2A06417}
[-] Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
[-] Key Deleted : HKCU\Software\Conduit
[-] Key Deleted : HKCU\Software\OCS
[-] Key Deleted : HKCU\Software\Tbccint
[-] Key Deleted : HKCU\Software\Tbccint_HKLM
[-] Key Deleted : HKCU\Software\AppDataLow\Software\Tbccint
[-] Key Deleted : HKLM\SOFTWARE\Conduit
[!] Key Not Deleted : [x64] HKCU\Software\Conduit
[!] Key Not Deleted : [x64] HKCU\Software\OCS
[!] Key Not Deleted : [x64] HKCU\Software\Tbccint
[!] Key Not Deleted : [x64] HKCU\Software\Tbccint_HKLM
[!] Key Not Deleted : HKU\S-1-5-21-1372586815-2290778262-161615380-1000\Software\AppDataLow\Software\Tbccint

***** [ Web browsers ] *****

[-] [C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Web Data] [search Provider] Deleted : ask.com
[-] [C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Web Data] [search Provider] Deleted : babylon.com
[-] [C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : bkomkajifikmkfnjgphkjcfeepbnojok
[-] [C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : dajedkncpodkggklbegccjpmnglmnflm
[-] [C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : eooncjejnppfjjklapaamhcdmjbilmde
[-] [C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : nfengeggddojhakldhlpjdlddgkkjkdd

*************************

:: Winsock settings cleared

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [3132 bytes] ##########
 

  • Автор

Не, в момента всичко е нормално. То и преди беше така, просто бях подозрителен.

Ясно..! Няма причини да се съмнявате в заразена система...Всичко е ок..!

 

icon_arrow.gif Изтеглете DelFix и го стартирайте. Сложете отметка пред:

  • Remove disinfection tools
  • Purge system restore
  • Reset system settings - тук не слагайте отметка ..!!!!
  • Create registry backup

delfix.JPG
 
..и след това натиснете бутона Run

  • След като операцията е завърши,ще се създаде дневник
  • Копирате го и го поставите в следващия си отговор

Инструмента ще се самоизтрие след като приключи своята задача!

 

Ако има нещо което използвахме в лечението и не се е премахнало след последните инструкции го премахнете ръчно ,по стандартните методи..!

 

Ако нямате други проблеми да приключваме...Маркирам случая за "Решен"...! Пожелавам лек ден и безопасен интернет..! :)

  • Автор

# DelFix v1.011 - Logfile created 05/09/2015 at 12:06:49
# Updated 18/08/2015 by Xplode
# Username : PC - PC-PC
# Operating System : Windows 7 Enterprise Service Pack 1 (64 bits)

~ Removing disinfection tools ...

Deleted : C:\FRST
Deleted : C:\AdwCleaner
Deleted : C:\Users\PC\Desktop\Addition.txt
Deleted : C:\Users\PC\Desktop\adwcleaner_5.005.exe
Deleted : C:\Users\PC\Desktop\FRST.txt
Deleted : C:\Users\PC\Desktop\FRST64.exe
Deleted : C:\Users\PC\Desktop\JRT.exe
Deleted : C:\Users\PC\Desktop\JRT.txt
Deleted : C:\Users\PC\Desktop\TFC.exe
Deleted : C:\Users\PC\Desktop\ZHPCleaner.exe
Deleted : C:\Users\PC\Desktop\ZHPCleaner.lnk
Deleted : C:\Users\PC\Desktop\ZHPCleaner.txt
Deleted : HKLM\SOFTWARE\AdwCleaner

~ Creating registry backup ... OK

~ Cleaning system restore ...

Deleted : RP #217 [JRT Pre-Junkware Removal | 09/04/2015 19:16:57]

New restore point created !

########## - EOF - ##########
 

Благодаря ви за помощта! Приятен ден и на вас.

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.