Премини към съдържанието

Препоръчан отговор


Добро утро колеги :rolleyes:

От няколко дни ме мъчи една гадина, която и с 300 зора не успявам да махна. Всеки ден ми задава началната страница да е http://www.globasearch.com/?serie=211&b=2&installkey=DKsV3XsUJhMJGW8ZYJnT  и въпреки че сменям настройките и че съм чистил с MBAM и Adwcleaner, след всяко изключване на компютъра началната страница се връща, а понякога и при отваряне на нов таб ми зарежда тази страница. Прилагам FRST.txt в спойлер.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:04-10-2015
Ran by Dennis (administrator) on DENNIS-PC (07-10-2015 07:18:17)
Running from C:\Users\Dennis\Downloads
Loaded Profiles: Dennis &  (Available Profiles: Dennis)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Български (България)
Internet Explorer Version 9 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(MY.COM B.V.) C:\Users\Dennis\AppData\Local\MyComGames\MyComGames.exe
(Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_19_0_0_185.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_19_0_0_185.exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG)
HKU\S-1-5-21-3207238838-1028525852-2977458650-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [57872912 2015-09-17] (Skype Technologies S.A.)
HKU\S-1-5-21-3207238838-1028525852-2977458650-1000\...\Run: [MyComGames] => C:\Users\Dennis\AppData\Local\MyComGames\MyComGames.exe [4216776 2015-10-05] (MY.COM B.V.)
HKU\S-1-5-21-3207238838-1028525852-2977458650-1000\...\MountPoints2: {4391c6ef-6672-11e5-bdba-e0cb4ec26c86} - G:\setup.exe
HKU\S-1-5-21-3207238838-1028525852-2977458650-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [333824 2010-11-21] (Microsoft Corporation)
HKU\S-1-5-21-3207238838-1028525852-2977458650-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [57872912 2015-09-17] (Skype Technologies S.A.)
HKU\S-1-5-21-3207238838-1028525852-2977458650-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [MyComGames] => C:\Users\Dennis\AppData\Local\MyComGames\MyComGames.exe [4216776 2015-10-05] (MY.COM B.V.)
HKU\S-1-5-21-3207238838-1028525852-2977458650-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {4391c6ef-6672-11e5-bdba-e0cb4ec26c86} - G:\setup.exe
HKU\S-1-5-21-3207238838-1028525852-2977458650-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [333824 2010-11-21] (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{63B51B86-DB83-4254-9278-CF35DE3431C1}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.globasearch.com/?serie=211&b=3&installkey=DKsV3XsUJhMJGW8ZYJnT
HKU\S-1-5-21-3207238838-1028525852-2977458650-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
HKU\S-1-5-21-3207238838-1028525852-2977458650-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.globasearch.com/?serie=211&b=3&installkey=DKsV3XsUJhMJGW8ZYJnT
HKU\S-1-5-21-3207238838-1028525852-2977458650-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
HKU\S-1-5-21-3207238838-1028525852-2977458650-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.globasearch.com/?serie=211&b=3&installkey=DKsV3XsUJhMJGW8ZYJnT
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.globasearch.com/?serie=211&installkey=DKsV3XsUJhMJGW8ZYJnT&b=3&q={searchTerms}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.globasearch.com/?serie=211&installkey=DKsV3XsUJhMJGW8ZYJnT&b=3&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3207238838-1028525852-2977458650-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.globasearch.com/?serie=211&installkey=DKsV3XsUJhMJGW8ZYJnT&b=3&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3207238838-1028525852-2977458650-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.globasearch.com/?serie=211&installkey=DKsV3XsUJhMJGW8ZYJnT&b=3&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3207238838-1028525852-2977458650-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.globasearch.com/?serie=211&installkey=DKsV3XsUJhMJGW8ZYJnT&b=3&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3207238838-1028525852-2977458650-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.globasearch.com/?serie=211&installkey=DKsV3XsUJhMJGW8ZYJnT&b=3&q={searchTerms}
Toolbar: HKU\S-1-5-21-3207238838-1028525852-2977458650-1000 -> No Name - {2007D797-C67F-48C0-BDCE-ADEF2697D17E} -  No File
Toolbar: HKU\S-1-5-21-3207238838-1028525852-2977458650-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> No Name - {2007D797-C67F-48C0-BDCE-ADEF2697D17E} -  No File

FireFox:
========
FF ProfilePath: C:\Users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\rc0bshlr.default-1444149669000
FF NewTab: hxxp://www.globasearch.com/?serie=211&b=2&installkey=DKsV3XsUJhMJGW8ZYJnT&newtab
FF Homepage: google.bg
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_185.dll [2015-09-29] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_185.dll [2015-09-29] ()
FF Plugin HKU\S-1-5-21-3207238838-1028525852-2977458650-1000: @my.com/Games -> C:\Users\Dennis\AppData\Local\MyComGames\NPMyComDetector.dll [2015-10-04] (My.com, Inc)
FF Plugin HKU\S-1-5-21-3207238838-1028525852-2977458650-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @my.com/Games -> C:\Users\Dennis\AppData\Local\MyComGames\NPMyComDetector.dll [2015-10-04] (My.com, Inc)

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 BRSptStub; C:\ProgramData\BitRaider\BRSptStub.exe [363208 2015-09-30] (BitRaider, LLC)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [113880 2015-10-07] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
R3 RTL8023x64; C:\Windows\System32\DRIVERS\Rtnic64.sys [51712 2009-06-10] (Realtek Semiconductor Corporation                           )
S3 BRDriver64_1_3_3_E02B25FC; \??\C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-10-07 07:18 - 2015-10-07 07:18 - 00008830 _____ C:\Users\Dennis\Downloads\FRST.txt
2015-10-07 07:18 - 2015-10-07 07:18 - 00000000 ____D C:\FRST
2015-10-07 07:17 - 2015-10-07 07:17 - 02193920 _____ (Farbar) C:\Users\Dennis\Downloads\FRST64.exe
2015-10-07 07:13 - 2015-10-07 07:13 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\40484B52.sys
2015-10-05 22:49 - 2015-10-05 22:49 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\My.com
2015-10-04 15:18 - 2015-10-04 15:18 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\My.com Games
2015-10-04 15:17 - 2015-10-07 07:14 - 00000000 ____D C:\Users\Dennis\AppData\Local\MyComGames
2015-10-04 13:02 - 2015-10-04 13:02 - 00032765 _____ C:\Users\Dennis\Downloads\Star_Wars_Episode_IV___A_New_Hope_1977_1080p_Blu_ray_ITA_AVC_DTS_HD.MA_6.1_EbP.(subs.sab.bz).rar
2015-10-04 12:33 - 2015-10-04 12:33 - 01670656 _____ C:\Users\Dennis\Downloads\adwcleaner_5.009.exe
2015-10-03 21:16 - 2015-10-03 21:16 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-10-03 15:01 - 2015-10-03 15:01 - 00000199 _____ C:\Windows\DirectX.log
2015-10-03 15:01 - 2015-10-03 15:01 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2015-10-03 15:01 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
2015-10-03 15:01 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll
2015-10-03 15:01 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll
2015-10-03 15:01 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll
2015-10-03 15:01 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
2015-10-03 15:01 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll
2015-10-03 15:00 - 2015-10-03 15:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Catalyst
2015-10-03 00:42 - 2015-10-05 07:55 - 00001081 _____ C:\Users\Dennis\Desktop\Format Factory.lnk
2015-10-03 00:42 - 2015-10-03 00:42 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
2015-10-03 00:42 - 2015-10-03 00:42 - 00000000 ____D C:\Program Files (x86)\FormatFactory
2015-10-03 00:42 - 2015-10-03 00:42 - 00000000 _____ C:\Windows\SysWOW64\track
2015-10-03 00:28 - 2015-10-03 00:28 - 00003336 _____ C:\Windows\System32\Tasks\Format Factory
2015-10-02 23:53 - 2015-10-03 00:40 - 00000000 ____D C:\Program Files (x86)\Burrrn
2015-10-01 20:07 - 2015-10-01 20:07 - 04596720 _____ (MY.COM B.V.) C:\Users\Dennis\Downloads\SkyforgeLoader_en.exe
2015-10-01 09:01 - 2015-10-01 09:01 - 00000000 ____D C:\Users\Dennis\AppData\Local\SWTOR
2015-10-01 07:26 - 2015-10-05 07:55 - 00001110 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-09-30 11:36 - 2015-09-30 11:36 - 00000000 ____D C:\Users\Dennis\AppData\Local\Blizzard
2015-09-30 09:31 - 2015-09-30 09:31 - 00000000 ____D C:\Users\Public\Documents\BitRaider
2015-09-30 09:31 - 2015-09-30 09:31 - 00000000 ____D C:\Users\Dennis\AppData\Local\SWTORPerf
2015-09-30 09:31 - 2015-09-30 09:31 - 00000000 ____D C:\ProgramData\BitRaider
2015-09-30 09:29 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll
2015-09-30 09:29 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll
2015-09-30 09:28 - 2015-09-30 09:30 - 00014553 _____ C:\Users\Dennis\Documents\Install STAR WARS The Old Republic.log
2015-09-30 09:13 - 2015-09-30 09:13 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2015-09-30 00:51 - 2015-10-07 07:14 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-09-30 00:50 - 2015-10-01 07:26 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-09-30 00:50 - 2015-06-18 09:48 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-09-30 00:50 - 2015-06-18 09:47 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-09-30 00:50 - 2015-06-18 09:47 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-09-30 00:44 - 2015-09-30 00:44 - 00749404 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2015-09-30 00:09 - 2015-09-30 00:09 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-09-30 00:00 - 2015-09-30 00:00 - 00000000 ____D C:\Users\Dennis\AppData\LocalLow\KMPlayer
2015-09-29 23:59 - 2015-09-29 23:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone
2015-09-29 23:58 - 2015-10-06 21:32 - 00000000 ____D C:\Users\Dennis\AppData\Local\Battle.net
2015-09-29 23:58 - 2015-09-29 23:59 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Battle.net
2015-09-29 23:58 - 2015-09-29 23:58 - 00000000 ____D C:\Users\Dennis\AppData\Local\Blizzard Entertainment
2015-09-29 23:58 - 2015-09-29 23:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
2015-09-29 23:58 - 2015-09-29 23:58 - 00000000 ____D C:\ProgramData\Blizzard Entertainment
2015-09-29 23:57 - 2015-10-06 20:51 - 00000000 ____D C:\Program Files (x86)\Battle.net
2015-09-29 23:57 - 2015-09-29 23:57 - 00000000 ____D C:\ProgramData\Battle.net
2015-09-29 23:26 - 2015-09-29 23:26 - 00000000 ____D C:\Users\Dennis\AppData\Local\Macromedia
2015-09-29 23:25 - 2015-09-29 23:25 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-09-29 23:25 - 2015-09-29 23:25 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-09-29 23:25 - 2015-09-29 23:25 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2015-09-29 23:25 - 2015-09-29 23:25 - 00000000 ____D C:\Windows\system32\Macromed
2015-09-29 23:24 - 2015-09-29 23:25 - 00000000 ____D C:\Users\Dennis\AppData\Local\Adobe
2015-09-29 20:07 - 2015-10-04 12:35 - 00000000 ____D C:\AdwCleaner
2015-09-29 20:06 - 2015-09-08 19:55 - 00000000 ____D C:\Users\Dennis\Documents\Telltale Games
2015-09-29 20:06 - 2015-09-08 19:54 - 00000000 ____D C:\Users\Dennis\Documents\BioWare
2015-09-29 12:34 - 2015-09-29 12:34 - 00002990 _____ C:\Windows\System32\Tasks\elbyExecuteWithUAC
2015-09-29 12:33 - 2015-09-29 12:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elaborate Bytes
2015-09-29 12:33 - 2015-09-29 12:33 - 00000000 ____D C:\Program Files (x86)\Elaborate Bytes
2015-09-29 12:32 - 2015-09-30 17:45 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\AIMP3
2015-09-29 12:32 - 2015-09-29 12:32 - 00000000 ____D C:\Program Files (x86)\AIMP3
2015-09-29 12:29 - 2015-09-29 12:30 - 00000000 ____D C:\Program Files (x86)\Opera
2015-09-29 12:29 - 2015-09-29 12:29 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Opera Software
2015-09-29 12:29 - 2015-09-29 12:29 - 00000000 ____D C:\Users\Dennis\AppData\Local\Opera Software
2015-09-29 12:28 - 2015-09-29 12:28 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The KMPlayer
2015-09-29 12:28 - 2015-09-29 12:28 - 00000000 ____D C:\Program Files (x86)\The KMPlayer
2015-09-29 12:25 - 2015-10-06 10:42 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Skype
2015-09-29 12:25 - 2015-09-29 12:25 - 00000000 ____D C:\Users\Dennis\Tracing
2015-09-29 12:25 - 2015-09-29 12:25 - 00000000 ____D C:\Users\Dennis\AppData\Local\Skype
2015-09-29 12:24 - 2015-09-29 12:24 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-09-29 12:24 - 2015-09-29 12:24 - 00000000 ____D C:\ProgramData\Skype
2015-09-29 12:24 - 2015-09-29 12:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-09-29 12:13 - 2015-09-29 12:14 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-09-29 12:13 - 2015-09-29 12:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-09-29 12:13 - 2015-09-29 12:13 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\WinRAR
2015-09-29 12:13 - 2015-09-29 12:13 - 00000000 ____D C:\Program Files\WinRAR
2015-09-29 12:12 - 2015-10-05 07:55 - 00000822 _____ C:\Users\Dennis\Desktop\All in 1.lnk
2015-09-29 10:12 - 2015-09-29 09:20 - 00000000 ____D C:\Windows\Panther
2015-09-29 09:45 - 2015-10-03 21:16 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-09-29 09:45 - 2015-09-29 09:45 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Mozilla
2015-09-29 09:45 - 2015-09-29 09:45 - 00000000 ____D C:\Users\Dennis\AppData\Local\Mozilla
2015-09-29 09:43 - 2015-09-29 09:43 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Macromedia
2015-09-29 09:43 - 2015-09-29 09:43 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Adobe
2015-09-29 09:40 - 2015-09-29 09:40 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Maxthon3
2015-09-29 09:33 - 2015-09-29 09:33 - 00000000 ____D C:\Program Files (x86)\uTorrent
2015-09-29 09:31 - 2015-10-07 00:18 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\uTorrent
2015-09-29 09:27 - 2015-09-29 09:27 - 00057560 _____ C:\Users\Dennis\AppData\Local\GDIPFONTCACHEV1.DAT
2015-09-29 09:23 - 2015-10-07 07:16 - 00105659 _____ C:\Windows\WindowsUpdate.log
2015-09-29 09:21 - 2015-10-05 07:55 - 00001449 _____ C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-09-29 09:21 - 2015-10-05 07:55 - 00001409 _____ C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2015-09-29 09:20 - 2015-10-01 23:58 - 00000000 ____D C:\Users\Dennis
2015-09-29 09:20 - 2015-09-29 09:20 - 00000020 ___SH C:\Users\Dennis\ntuser.ini
2015-09-29 09:20 - 2015-09-29 09:20 - 00000000 ____D C:\Users\Dennis\AppData\Local\VirtualStore
2015-09-29 09:20 - 2009-07-14 07:54 - 00000000 ___RD C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-09-29 09:20 - 2009-07-14 07:49 - 00000000 ___RD C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-09-29 09:19 - 2015-09-29 09:19 - 00000000 __SHD C:\Recovery
2015-09-29 09:16 - 2015-10-05 07:55 - 00001333 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2015-09-29 09:16 - 2015-10-05 07:55 - 00001314 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2015-09-29 09:15 - 2015-09-29 09:15 - 00001355 _____ C:\Windows\TSSysprep.log
2015-09-29 09:15 - 2015-09-29 09:15 - 00000000 _____ C:\Windows\system32\atiicdxx.dat
2015-09-29 09:15 - 2015-09-29 09:15 - 00000000 _____ C:\Windows\ativpsrm.bin
2015-09-29 00:27 - 2015-09-29 00:27 - 63718957 _____ C:\Users\Dennis\Documents\saves.rar

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-10-07 07:13 - 2009-07-14 08:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-10-07 07:13 - 2009-07-14 07:51 - 00024532 _____ C:\Windows\setupact.log
2015-10-06 19:45 - 2009-07-14 07:45 - 00023680 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-10-06 19:45 - 2009-07-14 07:45 - 00023680 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-10-06 19:43 - 2009-07-14 08:13 - 00781298 _____ C:\Windows\system32\PerfStringBackup.INI
2015-10-05 14:21 - 2010-11-21 06:47 - 00008972 _____ C:\Windows\PFRO.log
2015-10-05 08:11 - 2009-07-14 06:20 - 00000000 ____D C:\Windows\schemas
2015-10-05 07:55 - 2009-07-14 08:01 - 00001218 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk
2015-10-05 07:55 - 2009-07-14 07:57 - 00001511 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-10-05 07:55 - 2009-07-14 07:57 - 00001292 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
2015-10-05 07:55 - 2009-07-14 07:57 - 00001234 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
2015-10-05 07:55 - 2009-07-14 07:54 - 00001198 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
2015-10-05 07:55 - 2009-07-14 07:49 - 00001246 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk
2015-10-03 11:06 - 2009-07-14 08:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-09-30 00:41 - 2009-07-14 06:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2015-09-30 00:29 - 2011-04-12 11:34 - 00000000 ____D C:\Windows\RemotePackages
2015-09-29 12:33 - 2009-07-14 08:32 - 00000000 ____D C:\Windows\system32\restore
2015-09-29 10:12 - 2009-07-14 08:38 - 00025600 ___SH C:\Windows\system32\config\BCD-Template.LOG
2015-09-29 10:12 - 2009-07-14 08:32 - 00028672 _____ C:\Windows\system32\config\BCD-Template
2015-09-29 10:11 - 2009-07-14 07:45 - 00000000 ____D C:\Windows\Setup
2015-09-29 09:19 - 2009-07-14 06:20 - 00000000 __RHD C:\Users\Public\Libraries
2015-09-29 09:19 - 2009-07-14 06:20 - 00000000 ____D C:\Windows\rescache
2015-09-29 09:17 - 2009-07-14 06:20 - 00000000 ____D C:\Windows\system32\oobe
2015-09-29 09:16 - 2009-07-14 07:46 - 00002790 _____ C:\Windows\DtcInstall.log
2015-09-29 09:16 - 2009-07-14 06:20 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-09-29 09:16 - 2009-07-14 06:20 - 00000000 ____D C:\Windows\system32\sysprep
2015-09-29 09:13 - 2011-04-12 11:34 - 00000000 ____D C:\Windows\CSC
2015-09-29 09:13 - 2009-07-14 07:45 - 00274320 _____ C:\Windows\system32\FNTCACHE.DAT

Some files in TEMP:
====================
C:\Users\Dennis\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-10-01 21:44

==================== End of FRST.txt ============================

Addition.txt

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

Изтеглете KKdS6sj.pngfixlist.txt и го запазете в папката от която стартирахте FRST.exe.
Стартирайте FRST.exe и натиснете бутона Fix веднъж!
След като приключи, ако ви поиска рестарт - съгласете се. След рестарта публикувайте лог файла - fixlog.txt, който ще се създаде след работата на програмата.
 
Внимание: Скрипта е създаден за текущата система. Да не се ползва за други системи с подобни проблеми!

  • Харесва ми 1

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

Съжалявам за късния отговор - доставчика спря интернет достъпа -.- fixlog.txt:

Fix result of Farbar Recovery Scan Tool (x64) Version:04-10-2015
Ran by Dennis (2015-10-07 18:54:09) Run:1
Running from C:\Users\Dennis\Downloads
Loaded Profiles: Dennis (Available Profiles: Dennis)
Boot Mode: Normal
==============================================

fixlist content:
*****************
start
CreateRestorePoint:
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.globasearch.com/?serie=211&b=3&installkey=DKsV3XsUJhMJGW8ZYJnT
HKU\S-1-5-21-3207238838-1028525852-2977458650-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.globasearch.com/?serie=211&b=3&installkey=DKsV3XsUJhMJGW8ZYJnT
HKU\S-1-5-21-3207238838-1028525852-2977458650-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.globasearch.com/?serie=211&b=3&installkey=DKsV3XsUJhMJGW8ZYJnT
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.globasearch.com/?serie=211&installkey=DKsV3XsUJhMJGW8ZYJnT&b=3&q={searchTerms}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.globasearch.com/?serie=211&installkey=DKsV3XsUJhMJGW8ZYJnT&b=3&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3207238838-1028525852-2977458650-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.globasearch.com/?serie=211&installkey=DKsV3XsUJhMJGW8ZYJnT&b=3&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3207238838-1028525852-2977458650-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.globasearch.com/?serie=211&installkey=DKsV3XsUJhMJGW8ZYJnT&b=3&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3207238838-1028525852-2977458650-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.globasearch.com/?serie=211&installkey=DKsV3XsUJhMJGW8ZYJnT&b=3&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3207238838-1028525852-2977458650-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.globasearch.com/?serie=211&installkey=DKsV3XsUJhMJGW8ZYJnT&b=3&q={searchTerms}
Toolbar: HKU\S-1-5-21-3207238838-1028525852-2977458650-1000 -> No Name - {2007D797-C67F-48C0-BDCE-ADEF2697D17E} -  No File
Toolbar: HKU\S-1-5-21-3207238838-1028525852-2977458650-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> No Name - {2007D797-C67F-48C0-BDCE-ADEF2697D17E} -  No File
FF NewTab: hxxp://www.globasearch.com/?serie=211&b=2&installkey=DKsV3XsUJhMJGW8ZYJnT&newtab
Task: {E2D8A756-7E6A-44DA-A793-51A07BDCEBAA} - System32\Tasks\Format Factory => C:\Users\Dennis\AppData\Local\Temp\is-OQDVQ.tmp\prsetup.exe [2015-09-19] (Free Time                                                   ) <==== ATTENTION
FirewallRules: [{8C750C11-59B6-4A22-A707-C900E4CCBE39}] => (Allow) C:\Users\Dennis\AppData\Local\TNT2\2.0.0.2010\TNT2User.exe
C:\Users\Dennis\AppData\Local\TNT2
cmd: bitsadmin /reset /allusers
cmd: netsh winsock reset catalog
cmd: ipconfig /flushdns
RemoveProxy:
Hosts:
EmptyTemp:
End
*****************

Restore point was successfully created.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKU\S-1-5-21-3207238838-1028525852-2977458650-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKU\S-1-5-21-3207238838-1028525852-2977458650-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main\\Start Page => Error setting value.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
HKU\S-1-5-21-3207238838-1028525852-2977458650-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
"HKU\S-1-5-21-3207238838-1028525852-2977458650-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
HKU\S-1-5-21-3207238838-1028525852-2977458650-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value not found.
HKU\S-1-5-21-3207238838-1028525852-2977458650-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
HKU\S-1-5-21-3207238838-1028525852-2977458650-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2007D797-C67F-48C0-BDCE-ADEF2697D17E} => value removed successfully
HKCR\CLSID\{2007D797-C67F-48C0-BDCE-ADEF2697D17E} => key not found.
HKU\S-1-5-21-3207238838-1028525852-2977458650-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\Toolbar: HKU\S-1-5-21-3207238838-1028525852-2977458650-1000-{{2007D797-C67F-48C0-BDCE-ADEF2697D17E} => value not found.
HKCR\CLSID\Toolbar: HKU\S-1-5-21-3207238838-1028525852-2977458650-1000-{{2007D797-C67F-48C0-BDCE-ADEF2697D17E} => key not found.
Firefox "newtab" removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E2D8A756-7E6A-44DA-A793-51A07BDCEBAA}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E2D8A756-7E6A-44DA-A793-51A07BDCEBAA}" => key removed successfully
C:\Windows\System32\Tasks\Format Factory => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Format Factory" => key removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{8C750C11-59B6-4A22-A707-C900E4CCBE39} => value removed successfully
"C:\Users\Dennis\AppData\Local\TNT2" => File/Folder not found.

=========  bitsadmin /reset /allusers =========


BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

0 out of 0 jobs canceled.

========= End of CMD: =========


=========  netsh winsock reset catalog =========


Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.


========= End of CMD: =========


=========  ipconfig /flushdns =========


Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========


========= RemoveProxy: =========

HKU\S-1-5-21-3207238838-1028525852-2977458650-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\S-1-5-21-3207238838-1028525852-2977458650-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully


========= End of RemoveProxy: =========

C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
EmptyTemp: => 535.8 MB temporary data Removed.


The system needed a reboot..

==== End of Fixlog 18:55:19 ====

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

Има ли промяна?

 

СТЪПКА 1

 

icon_zps423a0d9f.jpgМоля изтеглете ZHPcleaner и я запазете на вашия десктоп.

  • Стартирайте ZHPCleaner с десен клик върху файла и изберете от контекстното меню "Run as administrator"
  • Кликнете върху Ashampoo_Snap_20140819_13h09m50s_001__zp за да се съгласите с лицензионното споразумение.
  • Изберете бутона y3pI4LR.png.
  • Браузърите ще бъдат затворени автоматично.
  • Ще се отвори лог файл след приключването на проверката.
  • Публикувайте лог файла в следващия си коментар.

 

 

СТЪПКА 2

 

Моля изтеглете Malwarebytes Anti-Malware 2.1.8.1057 Final и я запазете на вашия десктоп.

  • Стартирайте файла mbam-setup-2.1.8.1057.exe и следвайте указанията за да инсталирате програмата.
  • След като инсталацията приключи се уверете че сте сложили отметка пред:
  • Launch Malwarebytes Anti-Malware
  • Отметката активираща пробния 14 дневен период също е маркиран по-подразбиране. Ако не желаете да тествате защитата в реално време на програмата през следващите 14 дни тогава премахнете отметката. Т.е. премахнете първата отметка:

DkgJ7Zr.png

  • Натиснете бутона Finish.
  • Отидете до табът Settings > Detection and Protection > и под категорията Detection Options включете опцията "Scan for rootkits".
  • Отидете до табът Scan, сложете радио-бутона пред Threat Scan и след това натиснете бутона Scan Now >> . Ако е намерена актуализация тогава натиснете бутона Update Now.
  • Ще започне проверка за зловреден софтуер.
  • При някои инфекции можете да видите съобщението:
  • "Could not load DDA driver"
  • Натиснете "Yes" на това съобщение за да позволите драйвера да се зареди след рестарт.
  • Разрешете на компютъра да се рестартира и след това продължете с останалите инструкции.
  • След като проверката приключи натиснете бутона Apply Actions.
  • Изчакайте да се появи прозореца подканващ ви да рестартирате и след това натиснете бутона Yes.
  • След рестарта, когато се появи десктопа MBAM ще се зареди още веднъж.
  • Отидете то табът History > Application Logs.

65ZBqkR.jpg

  • Отворете рапорта с последната дата и час и натиснете бутона "Copy to Clipboard"
  • Сега вече поставете съдържанието на лог файла с клавишната комбинация Ctrl + V и го публикувайте в следващия си коментар.
  • Искам да публикувате и стария лог, който извършихте в началото на темата.

 

 

СТЪПКА 3

 

1.Изтеглете Hitman Pro.

За 32-битова система - dEMD6.gif.
За 64-битова система - Download-button3.gif

2.Стартирайте програмата.

3.След като сте стартирали програмата като кликнете върху иконата 5vo5F.jpg и натиснете бутона „Напред“ като се съгласите с лицензионното споразумение (EULA).

4.Сложете отметка пред "Не, искам да завърша еднократно сканиране на компютъра".

5.Натиснете бутона „Напред“.

6.Програмата ще започне да сканира. Времето за сканиране е около 2 минути.

7.След завършване на сканирането от списъка с намерените неща (ако има такива) изберете Apply to all => Ignore.

8.Натиснете "Next" и след това натиснете "Изнеси резултата в XML file" и запазете лог файла на десктопа.

9.Архивирайте файла и го прикачете в следващия си коментар или копирайте съдържанието му в следващия си коментар.
 
Забележка: Ако няма падащо меню, където да изберете ignore както на снимката:
 
6-scanfin-choose.jpg
 
Тогава просто затворете програмата след края на проверката (без да премахвате нищо)...след това отворете C:\Programdata\HitmanPro\Logs, отворете и публикувайте съдържанието на лог файла в следващия си коментар.

Забележка: Папката C:\ProgramData е скрита и затова трябва да направите скритите файлове видими по-следния начин:

От My Computer => Tools => Folder Options => View:

Сложете отметка пред "Show hidden files, folders and drives" и махнете отметката пред "Hide protected operating system files (recommended)".

Натиснете Apply. Сега проверете за лог файла в папката C:Programdata\HitmanPro\Logs и го прикачете в следващия си коментар.

 

Поздрави!

  • Харесва ми 1

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

Има ли промяна?

Отново съжалявам за късния отговор, но ДА, има огромна промяна. Благодаря за оказаната помощ! :)


Сподели този отговор


Линк към този отговор
Сподели в други сайтове

Ок, а останалите стъпки ще ги изпълните ли или приключихме? :)

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

Aми аз вече имам МВАМ и сканирането с нея не откри никакви заплахи. Мисля че всичко е наред, благодаря отново за помощта. Може да заключвате :)

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

Регистрирайте се или влезете в профила си за да коментирате

Трябва да имате регистрация за да може да коментирате това

Регистрирайте се

Създайте нова регистрация в нашия форум. Лесно е!

Нова регистрация

Вход

Имате регистрация? Влезте от тук.

Вход

×

Информация

Поставихме бисквитки на устройството ви за най-добро потребителско изживяване. Можете да промените настройките си за бисквитки, или в противен случай приемаме, че сте съгласни с нашите условия за ползване.