Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

проблем с компютъра

Featured Replies

Здравейте вижте ще обясня проблема най-кратко и най-ясно!Аз пиша курсови работи и съм любител астролог. Така видях проблема при астрологичната ми програма знаците на планетите започнаха да се показват йероглифи. Реших да я деинсталирам и наново да я инсталирам. Явно видях че моя компютър има проблем. Антивирусната ми програма която беше Nod32 нищо не намери но компютъра беше бавен. Опитах се да инсталирам една друга  с чужд език астрологична програма видях че мозалията отдолу на всеки сайт излизат реклами. Един приятел ми каза че ще го направи инсталира ми Malawarebaytes. И дотам. Видя че паметта на компютъра не е висока и ми каза че трябва офис пакета д абъде или 2005 или 2003. И оттогава ни вест от него ни кост. Онзи ден Malawarebaytes искаше нова версия на тази програма да се инсталира, направих го но на всеки час се показва че прави някакви актуализации. Рекламите в мозалията на всеки сайт който отворя си стоят а когато искам да ги затворя искачат някакви прозорци. Ужас! Може ли този проблем да се оправи. И да ви кажа преди имах аваст но тя хептен ми бавеше компютъра друг приятел ми каза сложи си Nod 32 ще видиш че няма да имаш пробелми но бавеше компютъра. Кажете ми какъв ми е проблема. Благодаря за отговора!

  • Автор

ами страх ме е да инсталирам тези файлове но ще се опитам!

преди 9 часа, mimisimova написа:

ами страх ме е да инсталирам тези файлове но ще се опитам!

Тези файлове не се инсталират и са напълно безвредни. Няма от какво да ви е страх. Без анализа на логовете от FRST просто няма как да се даде решение на вашия проблем... :)

  • Автор

Здравейте сканирах го и вижте какво излезе:

can result of Farbar Recovery Scan Tool (FRST) (x86) Version:18-11-2015
Ran by User (administrator) on SL (18-11-2015 16:29:48)
Running from D:\My Documents\Downloads
Loaded Profiles: User (Available Profiles: User & Administrator)
Platform: Microsoft Windows XP Home Edition Service Pack 3 (X86) Language: English (United States)
Internet Explorer Version 7 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Panda Security) C:\Program Files\Panda USB Vaccine\USBVaccine.exe
() C:\Documents and Settings\All Users\Application Data\DatacardService\HWDeviceService.exe
(Sun Microsystems, Inc.) C:\Program Files\Java\jre6\bin\jqs.exe
(Malwarebytes) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Skype Technologies S.A.) C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
() C:\Documents and Settings\All Users\Application Data\VIVACOM 3G USB Modem\OnlineUpdate\ouc.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [NvMediaCenter] => RunDLL32.exe NvMCTray.dll,NvTaskbarInit
HKLM\...\Run: [nwiz] => nwiz.exe /install
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKU\S-1-5-21-725345543-1390067357-839522115-1004\...\Run: [Adobe Reader Synchronizer] => C:\Program Files\Adobe\Reader 11.0\Reader\AdobeCollabSync.exe [746376 2014-05-08] (Adobe Systems Incorporated)
HKU\S-1-5-21-725345543-1390067357-839522115-1004\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-725345543-1390067357-839522115-1004\...\MountPoints2: {b8192b08-cc11-11e4-95ef-0018f38a4a54} - F:\AutoRun.exe
HKU\S-1-5-21-725345543-1390067357-839522115-1004\...\MountPoints2: {b8192b0d-cc11-11e4-95ef-0018f38a4a54} - F:\AutoRun.exe
HKU\S-1-5-21-725345543-1390067357-839522115-1004\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\ssflwbox.scr [393216 2008-04-14] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-10-12] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-10-12] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-10-12] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} =>  No File
Startup: C:\Documents and Settings\User\Start Menu\Programs\Startup\PandaUSBVaccine.lnk [2015-07-18]
ShortcutTarget: PandaUSBVaccine.lnk -> C:\Program Files\Panda USB Vaccine\USBVaccine.exe (Panda Security)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

ProxyServer: [S-1-5-21-725345543-1390067357-839522115-1004] => :80
AutoConfigURL: [S-1-5-21-725345543-1390067357-839522115-1004] => :80
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{0802F261-32C7-4393-8270-330BB30ED319}: [DhcpNameServer] 192.168.1.1 192.168.1.1

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKU\S-1-5-21-725345543-1390067357-839522115-1004\Software\Microsoft\Internet Explorer\Main,Prev Search Page = hxxp://google.icq.com
HKU\S-1-5-21-725345543-1390067357-839522115-1004\Software\Microsoft\Internet Explorer\Main,Prev Search Bar = hxxp://google.icq.com/search/search_frame.php
HKU\S-1-5-21-725345543-1390067357-839522115-1004\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
HKU\S-1-5-21-725345543-1390067357-839522115-1004\Software\Microsoft\Internet Explorer\Main,ICQ Search = hxxp://www.icq.com/search/results.php?q={searchTerms}&ch_id=osd
HKU\S-1-5-21-725345543-1390067357-839522115-1004\Software\Microsoft\Internet Explorer\Main,Start Page Restore = hxxp://www.google.bg/
URLSearchHook: HKU\S-1-5-21-725345543-1390067357-839522115-1004 - (No Name) - {e8de9422-3b2c-4243-bf6f-235da84d8ef8} -  No File
SearchScopes: HKLM -> Yandex URL = hxxp://yandex.ru/yandsearch?clid=165534&text={searchTerms}
SearchScopes: HKU\S-1-5-21-725345543-1390067357-839522115-1004 -> URL hxxp://www.moovida.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-725345543-1390067357-839522115-1004 -> Yandex URL = hxxp://yandex.ru/yandsearch?clid=165534&text={searchTerms}
BHO: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-13] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre6\bin\ssv.dll [2012-10-26] (Sun Microsystems, Inc.)
BHO: Windows Live Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-23] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll [2012-10-26] (Sun Microsystems, Inc.)
BHO: JQSIEStartDetectorImpl Class -> {E7E6F031-17CE-4C07-BC86-EABFE594F69C} -> C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2012-10-26] (Sun Microsystems, Inc.)
BHO: No Name -> {e8de9422-3b2c-4243-bf6f-235da84d8ef8} -> No File
Toolbar: HKLM - No Name - {e8de9422-3b2c-4243-bf6f-235da84d8ef8} -  No File
Toolbar: HKU\S-1-5-21-725345543-1390067357-839522115-1004 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} -  No File
Toolbar: HKU\S-1-5-21-725345543-1390067357-839522115-1004 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} -  No File
Toolbar: HKU\S-1-5-21-725345543-1390067357-839522115-1004 -> No Name - {E8DE9422-3B2C-4243-BF6F-235DA84D8EF8} -  No File
Toolbar: HKU\S-1-5-21-725345543-1390067357-839522115-1004 -> No Name - {0E1230F8-EA50-42A9-983C-D22ABC2EED3C} -  No File
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2009-02-13] (Microsoft Corporation)
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-17] (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-17] (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} -  No File
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

FireFox:
========
FF ProfilePath: C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\z2o0wjni.default-1400879248015
FF DefaultSearchEngine: Default
FF Homepage: user_pref("browser.startup.homepage", "hxxps://www.malwarebytes.org/restorebrowser/
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-11-10] ()
FF Plugin: @java.com/DTPlugin,version=1.6.0_37 -> C:\WINDOWS\system32\npdeployJava1.dll [2012-09-25] (Sun Microsystems, Inc.)
FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll [2012-09-25] (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll [2014-02-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=14.0.8117.0416 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-04-17] (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-30] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Extension: Record Page - C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\z2o0wjni.default-1400879248015\Extensions\{a37f329e-23c2-45ef-bf9b-54b45cd32b31}.xpi [2015-06-26] [not signed]
FF Extension: Adblock Plus - C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\z2o0wjni.default-1400879248015\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-11-16]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-10-31] [not signed]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Java\jre6\lib\deploy\jqs\ff
FF Extension: Java Quick Starter - C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2012-07-01] [not signed]

Chrome: 
=======
CHR HomePage: Default -> hxxp://www.oursurfing.com/?type=hp&ts=1434117720&z=f81a17fe7be67cd4923ba80g2zec5zcgcg0m7mce1b&from=amt&uid=WDCXWD800JD-00LSA0_WD-WMAM9EN9954999549
CHR DefaultSearchURL: Default -> hxxp://www.oursurfing.com/web/?type=ds&ts=1434117720&z=f81a17fe7be67cd4923ba80g2zec5zcgcg0m7mce1b&from=amt&uid=WDCXWD800JD-00LSA0_WD-WMAM9EN9954999549&q={searchTerms}
CHR DefaultSearchKeyword: Default -> oursurfing
CHR Profile: C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default
CHR Extension: (Плащания в уеб магазина на Chrome) - C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-29]
CHR HKLM\...\Chrome\Extension: [bejbohlohkkgompgecdcbbglkpjfjgdj] - <no Path\update_url>
CHR HKLM\...\Chrome\Extension: [hdjacnejoohiamgmaciljlpniffgkojd] - <no Path\update_url>
CHR HKLM\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - <no Path\update_url>
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - <no Path\update_url>
StartMenuInternet: chrome.exe - Chrome.exe

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 HWDeviceService.exe; C:\Documents and Settings\All Users\Application Data\DatacardService\HWDeviceService.exe [271712 2011-03-14] ()
R2 JavaQuickStarterService; C:\Program Files\Java\jre6\bin\jqs.exe [153584 2012-09-25] (Sun Microsystems, Inc.)
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 Skype C2C Service; C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3275136 2013-10-10] (Skype Technologies S.A.)
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [5495056 2015-06-18] (TeamViewer GmbH)
S2 VIVACOM 3G USB Modem. RunOuc; C:\Program Files\VIVACOM 3G USB Modem\UpdateDog\ouc.exe [655712 2015-03-16] ()

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 aswKbd; C:\WINDOWS\system32\Drivers\aswKbd.sys [18544 2012-08-21] (AVAST Software)
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
R2 fssfltr; C:\WINDOWS\System32\DRIVERS\fssfltr_tdi.sys [54760 2010-04-28] (Microsoft Corporation)
R3 HdAudAddService; C:\WINDOWS\System32\drivers\HdAudio.sys [145920 2004-10-27] (Windows (R) Server 2003 DDK provider)
S3 huawei_cdcacm; C:\WINDOWS\System32\DRIVERS\ew_jucdcacm.sys [95616 2015-03-16] (Huawei Technologies Co., Ltd.)
S3 huawei_cdcecm; C:\WINDOWS\System32\DRIVERS\ew_jucdcecm.sys [70016 2015-03-16] (Huawei Technologies Co., Ltd.)
S3 huawei_ext_ctrl; C:\WINDOWS\System32\DRIVERS\ew_juextctrl.sys [27520 2015-03-16] (Huawei Technologies Co., Ltd.)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2015-10-05] (Malwarebytes)
R3 MTsensor; C:\WINDOWS\System32\DRIVERS\ASACPI.sys [5810 2004-08-13] ()
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
R3 NVENETFD; C:\WINDOWS\System32\DRIVERS\NVENETFD.sys [57856 2006-06-29] (NVIDIA Corporation) [File not signed]
R3 nvnetbus; C:\WINDOWS\System32\DRIVERS\nvnetbus.sys [20480 2006-06-29] (NVIDIA Corporation) [File not signed]
S3 swmidi; C:\WINDOWS\System32\drivers\swmidi.sys [54272 2001-08-17] (Microsoft Corporation) [File not signed]
S3 tap0901; C:\WINDOWS\System32\DRIVERS\tap0901.sys [35088 2013-04-30] (The OpenVPN Project)
S3 WiseHDInfo; C:\WINDOWS\WiseHDInfo32.dll [13264 2015-07-18] (wisecleaner.com)
S2 adfs; no ImagePath
S3 ADIHdAudAddService; system32\drivers\ADIHdAud.sys [X]
S3 AEAudioService; system32\drivers\AEAudio.sys [X]
U5 ewusbnet; C:\Windows\System32\Drivers\ewusbnet.sys [249472 2015-03-16] (Huawei Technologies Co., Ltd.)
U5 ew_hwusbdev; C:\Windows\System32\Drivers\ew_hwusbdev.sys [102784 2015-03-16] (Huawei Technologies Co., Ltd.)
S4 IntelIde; no ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
S3 SenFiltService; system32\drivers\Senfilt.sys [X]
U1 WS2IFSL; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-11-18 16:29 - 2015-11-18 16:29 - 00000000 ____D C:\FRST
2015-11-10 21:19 - 2015-11-10 21:19 - 05286088 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe
2015-11-05 00:03 - 2015-11-05 19:43 - 00000000 ____D C:\Program Files\Mozilla Firefox

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-11-18 16:30 - 2006-12-22 10:02 - 00000000 ____D C:\Documents and Settings\User\Local Settings\Temp
2015-11-18 16:23 - 2013-05-01 13:15 - 00000886 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-11-18 16:20 - 2015-07-18 09:39 - 00588593 _____ C:\WINDOWS\WindowsUpdate.log
2015-11-18 16:19 - 2015-07-18 09:38 - 00000159 _____ C:\WINDOWS\wiadebug.log
2015-11-18 16:19 - 2015-07-18 09:38 - 00000053 _____ C:\WINDOWS\wiaservc.log
2015-11-18 16:19 - 2015-07-16 17:28 - 00000882 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-11-18 16:19 - 2015-07-03 16:53 - 00000448 _____ C:\WINDOWS\Tasks\Wise Memory Optimizer Task.job
2015-11-18 16:19 - 2006-12-22 10:01 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-11-18 15:12 - 2006-12-22 10:02 - 00000178 ___SH C:\Documents and Settings\User\ntuser.ini
2015-11-18 15:12 - 2006-12-22 10:01 - 00032590 _____ C:\WINDOWS\SchedLgU.Txt
2015-11-18 15:02 - 2015-06-12 21:50 - 00170200 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-11-18 01:31 - 2007-03-16 17:50 - 00000000 ____D C:\Documents and Settings\User\Application Data\Skype
2015-11-18 01:19 - 2012-04-17 06:07 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-11-17 19:11 - 2006-12-28 15:48 - 00113152 ____C C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-11-16 17:58 - 2006-02-28 14:00 - 00013646 _____ C:\WINDOWS\system32\wpa.dbl
2015-11-14 19:03 - 2015-06-12 21:50 - 00000777 _____ C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2015-11-14 19:03 - 2015-06-12 21:50 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
2015-11-14 19:03 - 2015-06-12 21:49 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-11-12 18:27 - 2013-05-01 13:19 - 00001813 _____ C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
2015-11-10 21:19 - 2012-04-17 06:07 - 00780488 ____C (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-11-10 21:19 - 2011-05-16 06:48 - 00142536 ____C (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-11-09 20:32 - 2015-08-04 17:50 - 00014353 _____ C:\WINDOWS\setupapi.log
2015-11-02 19:10 - 2007-01-29 18:29 - 00000151 ____C C:\WINDOWS\PhotoSnapViewer.INI

==================== Files in the root of some directories =======

2006-12-28 15:48 - 2015-11-17 19:11 - 0113152 ____C () C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

Some files in TEMP:
====================
C:\Documents and Settings\User\Local Settings\Temp\SkypeSetup.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

==================== End of FRST.txt =====================

А на addition  вижте какво излезе:

Additional scan result of Farbar Recovery Scan Tool (x86) Version:18-11-2015
Ran by User (2015-11-18 16:30:55)
Running from D:\My Documents\Downloads
Microsoft Windows XP Home Edition Service Pack 3 (X86) (2006-12-22 08:00:47)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-725345543-1390067357-839522115-500 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Administrator
Guest (S-1-5-21-725345543-1390067357-839522115-501 - Limited - Disabled)
HelpAssistant (S-1-5-21-725345543-1390067357-839522115-1000 - Limited - Disabled)
SUPPORT_388945a0 (S-1-5-21-725345543-1390067357-839522115-1002 - Limited - Disabled)
User (S-1-5-21-725345543-1390067357-839522115-1004 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\User

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)


==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

2007 Microsoft Office Suite Service Pack 2 (SP2) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}) (Version:  - Microsoft)
2007 Microsoft Office Suite Service Pack 2 (SP2) (Version:  - Microsoft) Hidden
7-Zip 9.20 (HKLM\...\7-Zip) (Version:  - )
Adobe AIR (HKLM\...\Adobe AIR) (Version: 3.7.0.1530 - Adobe Systems Incorporated)
Adobe Flash Player 19 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 19.0.0.245 - Adobe Systems Incorporated)
Adobe Flash Player 19 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 19.0.0.245 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.08) (HKLM\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated)
Apple Application Support (HKLM\...\{6A3F9D74-BB80-4451-8CA1-4B3A857F1359}) (Version: 2.0.1 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Attribute Extractor (HKLM\...\{C4FB4C85-6E46-4033-8DC6-62ED8BFB7FC5}) (Version:  - )
CCleaner (HKLM\...\CCleaner) (Version: 3.05 - Piriform)
Corel Graphics - Windows Shell Extension (HKLM\...\_{51DD370C-6690-424E-9674-5F14468B323F}) (Version: 15.0.0.487 - Corel Corporation)
Corel Graphics - Windows Shell Extension (Version: 15.0.487 - Corel Corporation) Hidden
Google Chrome (HKLM\...\Google Chrome) (Version: 46.0.2490.86 - Google Inc.)
Google Drive (HKLM\...\{9C350701-AC04-48BA-A435-BD5E0D82897E}) (Version: 1.25.0523.2491 - Google, Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.28.15 - Google Inc.) Hidden
Java(TM) 6 Update 37 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83216033FF}) (Version: 6.0.370 - Oracle)
Junk Mail filter update (Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Keyboards Palankov Standard 2.6 (HKLM\...\Keyboards Palankov Standard) (Version:  - )
K-Lite Codec Pack 7.2.0 (Basic) (HKLM\...\KLiteCodecPack_is1) (Version: 7.2.0 - )
Macromedia Shockwave Player (HKLM\...\Macromedia Shockwave Player) (Version:  - )
Malwarebytes Anti-Malware, версия 2.2.0.1024 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\...\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\...\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Compression Client Pack 1.0 for Windows XP (HKLM\...\MSCompPackV1) (Version: 1 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.6425.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft PowerPoint Viewer (HKLM\...\{95140000-00AF-0409-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Sync Framework Runtime Native v1.0 (x86) (HKLM\...\{8A74E887-8F0F-4017-AF53-CBA42211AAA5}) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft Sync Framework Services Native v1.0 (x86) (HKLM\...\{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft User-Mode Driver Framework Feature Pack 1.0 (HKLM\...\Wudf01000) (Version:  - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 - ENU (HKLM\...\{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 Runtime (HKLM\...\{299C0434-4F4E-341F-A916-4E07AEB35E79}) (Version: 9.0.30729 - Microsoft Corporation)
Mozilla Firefox 42.0 (x86 bg) (HKLM\...\Mozilla Firefox 42.0 (x86 bg)) (Version: 42.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 38.0.5 - Mozilla)
MSN (HKLM\...\MSNINST) (Version:  - )
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 6 Service Pack 2 (KB973686) (HKLM\...\{56EA8BC0-3751-4B93-BC9D-6651CC36E5AA}) (Version: 6.20.2003.0 - Microsoft Corporation)
Nero OEM (HKLM\...\Nero - Burning Rom!UninstallKey) (Version:  - )
Nero Suite (HKLM\...\NeroMultiInstaller!UninstallKey) (Version:  - )
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version:  - )
Panda USB Vaccine 1.0.1.16 (HKLM\...\{55A41219-9B22-4098-BAE7-AE289B3C569A}_is1) (Version:  - Panda Security)
Recuva (HKLM\...\Recuva) (Version: 1.50 - Piriform)
Segoe UI (Version: 14.0.4327.805 - Microsoft Corp) Hidden
Skype Click to Call (HKLM\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.13.13771 - Skype Technologies S.A.)
Skype™ 7.6 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.6.105 - Skype Technologies S.A.)
SoundMAX (HKLM\...\{F0A37341-D692-11D4-A984-009027EC0A9C}) (Version: 5.10.01.4151 - Analog Devices)
TeamViewer 10 (HKLM\...\TeamViewer) (Version: 10.0.43879 - TeamViewer)
The KMPlayer (HKLM\...\The KMPlayer) (Version: 3.4.0.55 - KMP Media co., Ltd)
TreeSize Free V2.4 (HKLM\...\TreeSize Free_is1) (Version: 2.4 - JAM Software)
Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
UseNeXT (HKLM\...\UseNeXT_is1) (Version:  - Tangysoft Ltd.)
Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VIVACOM 3G USB Modem (HKLM\...\VIVACOM 3G USB Modem) (Version: 21.005.22.07.738 - Huawei Technologies Co.,Ltd)
WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden
WinAVI All-in-One Converter (HKLM\...\WinAVI All-in-One Converter) (Version: 1.7.0.4653 - ZJMedia Digital Technology Ltd.)
Windows Imaging Component (HKLM\...\WIC) (Version: 3.0.0.0 - Microsoft Corporation)
Windows Internet Explorer 7 (HKLM\...\ie7) (Version: 20070813.185237 - Microsoft Corporation)
Windows Live Essentials (HKLM\...\WinLiveSuite_Wave3) (Version: 14.0.8117.0416 - Microsoft Corporation)
Windows Live Sign-in Assistant (HKLM\...\{45338B07-A236-4270-9A77-EBB4115517B5}) (Version: 5.000.818.5 - Microsoft Corporation)
Windows Live Sync (HKLM\...\{B10914FD-8812-47A4-85A1-50FCDE7F1F33}) (Version: 14.0.8117.416 - Microsoft Corporation)
Windows Media Format 11 runtime (HKLM\...\Windows Media Format Runtime) (Version:  - )
Windows Media Player 11 (HKLM\...\Windows Media Player) (Version:  - )
Windows Media Player Firefox Plugin (HKLM\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)
Windows XP Service Pack 3 (HKLM\...\Windows XP Service Pack) (Version: 20080414.031525 - Microsoft Corporation)
Инструмент за качване на Windows Live (HKLM\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-725345543-1390067357-839522115-1004_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB}\InprocServer32 -> C:\Documents and Settings\All Users\Application Data\Easybits GO\ezGameXN.dll (EasyBits Media)
CustomCLSID: HKU\S-1-5-21-725345543-1390067357-839522115-1004_Classes\CLSID\{42481700-CF3C-4D05-8EC6-F9A1C57E8DC0}\InprocServer32 -> C:\Documents and Settings\All Users\Application Data\Easybits GO\ezGameXN.dll (EasyBits Media)
CustomCLSID: HKU\S-1-5-21-725345543-1390067357-839522115-1004_Classes\CLSID\{BB6410D8-F879-4184-9C5C-6A02D16AE0B3}\InprocServer32 -> C:\Documents and Settings\All Users\Application Data\Easybits GO\ezGameXN.dll (EasyBits Media)
CustomCLSID: HKU\S-1-5-21-725345543-1390067357-839522115-1004_Classes\CLSID\{CA1073A2-5F3F-4445-8E5E-7109BDCEDDBE}\InprocServer32 -> C:\Documents and Settings\All Users\Application Data\Easybits GO\ezGameXN.dll (EasyBits Media)
CustomCLSID: HKU\S-1-5-21-725345543-1390067357-839522115-1004_Classes\CLSID\{D5A55D2D-C59D-42C3-A5BF-4C08EEE74339}\InprocServer32 -> C:\Documents and Settings\All Users\Application Data\Easybits GO\ezGameXN.dll (EasyBits Media)

==================== Restore Points =========================

06-10-2015 19:36:20 System Checkpoint
09-10-2015 19:52:14 System Checkpoint
11-10-2015 17:34:39 System Checkpoint
13-10-2015 18:35:19 System Checkpoint
15-10-2015 19:32:08 System Checkpoint
16-10-2015 19:34:17 System Checkpoint
20-10-2015 17:07:32 System Checkpoint
24-10-2015 18:42:00 System Checkpoint
26-10-2015 19:41:13 System Checkpoint
28-10-2015 20:06:32 System Checkpoint
29-10-2015 20:38:48 System Checkpoint
31-10-2015 13:56:58 System Checkpoint
02-11-2015 19:38:17 System Checkpoint
04-11-2015 18:27:38 System Checkpoint
05-11-2015 21:16:12 System Checkpoint
06-11-2015 22:00:03 System Checkpoint
10-11-2015 18:57:02 System Checkpoint
11-11-2015 19:15:27 System Checkpoint
12-11-2015 19:58:17 System Checkpoint
16-11-2015 20:03:41 System Checkpoint

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-09-22 15:03 - 2013-09-22 15:03 - 00000822 ____A C:\WINDOWS\system32\Drivers\etc\hosts

127.0.0.1       localhost
::1             localhost

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\AppleSoftwareUpdate.job => C:\Program Files\Apple Software Update\SoftwareUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Wise Memory Optimizer Task.job => C:\Program Files\Wise\Wise Memory Optimizer\WiseMemoryOptimzer.exe

==================== Loaded Modules (Whitelisted) ==============

2006-08-24 03:03 - 2006-10-22 12:22 - 00466944 _____ () C:\WINDOWS\system32\nvshell.dll
2011-03-14 17:27 - 2011-03-14 17:27 - 00271712 _____ () C:\Documents and Settings\All Users\Application Data\DatacardService\HWDeviceService.exe
2015-03-16 21:38 - 2015-03-16 21:36 - 00655712 _____ () C:\Documents and Settings\All Users\Application Data\VIVACOM 3G USB Modem\OnlineUpdate\ouc.exe
2015-03-16 21:38 - 2015-03-16 21:36 - 00011362 _____ () C:\Documents and Settings\All Users\Application Data\VIVACOM 3G USB Modem\OnlineUpdate\mingwm10.dll
2015-03-16 21:38 - 2015-03-16 21:36 - 00043008 _____ () C:\Documents and Settings\All Users\Application Data\VIVACOM 3G USB Modem\OnlineUpdate\libgcc_s_dw2-1.dll
2015-03-16 21:38 - 2015-03-16 21:36 - 02415104 _____ () C:\Documents and Settings\All Users\Application Data\VIVACOM 3G USB Modem\OnlineUpdate\QtCore4.dll
2015-03-16 21:38 - 2015-03-16 21:36 - 01148416 _____ () C:\Documents and Settings\All Users\Application Data\VIVACOM 3G USB Modem\OnlineUpdate\QtNetwork4.dll
2015-03-16 21:38 - 2015-03-16 21:36 - 00843264 _____ () C:\Documents and Settings\All Users\Application Data\VIVACOM 3G USB Modem\OnlineUpdate\QueryStrategy.dll
2015-03-16 21:38 - 2015-03-16 21:36 - 00398336 _____ () C:\Documents and Settings\All Users\Application Data\VIVACOM 3G USB Modem\OnlineUpdate\QtXml4.dll
2006-02-28 14:00 - 2008-04-14 02:11 - 00059904 _____ () C:\WINDOWS\system32\devenum.dll
2006-02-28 14:00 - 2008-04-14 02:11 - 00014336 _____ () C:\WINDOWS\system32\msdmo.dll
2014-04-14 15:44 - 2014-02-10 12:44 - 04592128 _____ () C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libglesv2.dll
2014-04-14 15:44 - 2014-02-10 12:44 - 00112128 _____ () C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libegl.dll
2006-12-28 12:36 - 2004-11-02 16:57 - 00121344 _____ () C:\Program Files\WinRAR\rarext.dll
2007-01-29 17:58 - 2006-10-15 19:53 - 00057451 _____ () C:\Program Files\ICQLite\ICQLiteShell.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-725345543-1390067357-839522115-1004\Control Panel\Desktop\\Wallpaper -> C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
DNS Servers: 192.168.1.1
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Update.lnk => C:\WINDOWS\pss\Windows Update.lnkCommon Startup
MSCONFIG\startupfolder: C:^Documents and Settings^User^Start Menu^Programs^Startup^BGOPEN.NET.lnk => C:\WINDOWS\pss\BGOPEN.NET.lnkStartup
MSCONFIG\startupfolder: C:^Documents and Settings^User^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk => C:\WINDOWS\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: AdobeBridge => 
MSCONFIG\startupreg: Google Update => "C:\Documents and Settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
MSCONFIG\startupreg: GrooveMonitor => "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
MSCONFIG\startupreg: High Definition Audio Property Page Shortcut => HDAShCut.exe
MSCONFIG\startupreg: NeroFilterCheck => C:\WINDOWS\system32\NeroCheck.exe
MSCONFIG\startupreg: Skype => "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: SoundMAX => "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

DomainProfile\AuthorizedApplications: [C:\Program Files\Windows Live\Messenger\wlcsdk.exe] => Enabled:Windows Live Call
DomainProfile\AuthorizedApplications: [C:\Program Files\Windows Live\Messenger\msnmsgr.exe] => Enabled:Windows Live Messenger
DomainProfile\AuthorizedApplications: [C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe] => Enabled:Windows Live Sync
StandardProfile\AuthorizedApplications: [C:\Program Files\Messenger\msmsgs.exe] => Enabled:Windows Messenger
StandardProfile\AuthorizedApplications: [C:\WINDOWS\pchealth\helpctr\binaries\HelpCtr.exe] => Enabled:Remote Assistance - Windows Messenger and Voice
StandardProfile\AuthorizedApplications: [C:\Program Files\Internet Explorer\iexplore.exe] => Disabled:Internet Explorer
StandardProfile\AuthorizedApplications: [C:\Program Files\Windows Live\Messenger\wlcsdk.exe] => Enabled:Windows Live Call
StandardProfile\AuthorizedApplications: [C:\Program Files\Windows Live\Messenger\msnmsgr.exe] => Enabled:Windows Live Messenger
StandardProfile\AuthorizedApplications: [C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe] => Enabled:Windows Live Sync
StandardProfile\AuthorizedApplications: [C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe] => Enabled:WebKit
StandardProfile\AuthorizedApplications: [C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE] => Enabled:Microsoft Office Outlook
StandardProfile\AuthorizedApplications: [C:\Program Files\Microsoft Office\Office12\GROOVE.EXE] => Enabled:Microsoft Office Groove
StandardProfile\AuthorizedApplications: [C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE] => Enabled:Microsoft Office OneNote
StandardProfile\AuthorizedApplications: [C:\WINDOWS\system32\msiexec.exe] => Enabled:UpdateManagerSetup
StandardProfile\AuthorizedApplications: [C:\Documents and Settings\User\Desktop\Skype.exe] => Enabled:Skype 
StandardProfile\AuthorizedApplications: [C:\Program Files\Google\Chrome\Application\chrome.exe] => Enabled:Google Chrome
StandardProfile\AuthorizedApplications: [C:\Program Files\Skype\Phone\Skype.exe] => Enabled:Skype
StandardProfile\AuthorizedApplications: [C:\Program Files\TeamViewer\TeamViewer.exe] => Enabled:Teamviewer Remote Control Application
StandardProfile\AuthorizedApplications: [C:\Program Files\TeamViewer\TeamViewer_Service.exe] => Enabled:Teamviewer Remote Control Service
StandardProfile\AuthorizedApplications: [C:\Program Files\Mozilla Firefox\firefox.exe] => Enabled:'Firefox' (C:\Program Files\Mozilla Firefox)
StandardProfile\GloballyOpenPorts: [1900:UDP] => :LocalSubNet:Disabled:@xpsp2res.dll,-22007
StandardProfile\GloballyOpenPorts: [2869:TCP] => :LocalSubNet:Disabled:@xpsp2res.dll,-22008
StandardProfile\GloballyOpenPorts: [20912:TCP] => Enabled:BitComet 20912 TCP
StandardProfile\GloballyOpenPorts: [20912:UDP] => Enabled:BitComet 20912 UDP

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (10/26/2015 05:51:02 PM) (Source: LoadPerf) (EventID: 3001) (User: )
Description: The performance counter name string value in the registry is incorrectly
formatted. The bogus string is 21074, the bogus index value is the first
DWORD in Data section while the last valid index values are the second and
third DWORD in Data section.

Error: (10/26/2015 05:50:59 PM) (Source: LoadPerf) (EventID: 3011) (User: )
Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The
Error code is the first DWORD in Data section.

Error: (10/26/2015 05:50:59 PM) (Source: LoadPerf) (EventID: 3001) (User: )
Description: The performance counter name string value in the registry is incorrectly
formatted. The bogus string is 21074, the bogus index value is the first
DWORD in Data section while the last valid index values are the second and
third DWORD in Data section.

Error: (07/18/2015 08:15:49 AM) (Source: LoadPerf) (EventID: 3011) (User: )
Description: Unloading the performance counter strings for service ISAPISearch (ISAPISearch) failed. The
Error code is the first DWORD in Data section.

Error: (07/18/2015 08:15:49 AM) (Source: LoadPerf) (EventID: 3001) (User: )
Description: The performance counter name string value in the registry is incorrectly
formatted. The bogus string is 21074, the bogus index value is the first
DWORD in Data section while the last valid index values are the second and
third DWORD in Data section.

Error: (07/18/2015 08:15:49 AM) (Source: LoadPerf) (EventID: 3011) (User: )
Description: Unloading the performance counter strings for service ContentFilter (ContentFilter) failed. The
Error code is the first DWORD in Data section.

Error: (07/18/2015 08:15:49 AM) (Source: LoadPerf) (EventID: 3001) (User: )
Description: The performance counter name string value in the registry is incorrectly
formatted. The bogus string is 21074, the bogus index value is the first
DWORD in Data section while the last valid index values are the second and
third DWORD in Data section.

Error: (07/18/2015 08:15:49 AM) (Source: LoadPerf) (EventID: 3011) (User: )
Description: Unloading the performance counter strings for service ContentIndex (ContentIndex) failed. The
Error code is the first DWORD in Data section.

Error: (07/18/2015 08:15:49 AM) (Source: LoadPerf) (EventID: 3001) (User: )

 

Кажете ми много ли ми е зле компютъра. Благодаря за отговора!
Description: The performance counter name string value in the registry is incorrectly
formatted. The bogus string is 21074, the bogus index value is the first
DWORD in Data section while the last valid index values are the second and
third DWORD in Data section.

Error: (06/30/2015 06:24:31 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Hanging application Skype.exe, version 7.5.0.102, hang module hungapp, version 0.0.0.0, hang address 0x00000000.


System errors:
=============
Error: (11/18/2015 04:20:00 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The VIVACOM 3G USB Modem. OUC service failed to start due to the following error: 
%%1053

Error: (11/18/2015 04:20:00 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Timeout (30000 milliseconds) waiting for the VIVACOM 3G USB Modem. OUC service to connect.

Error: (11/18/2015 04:20:00 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The adfs service failed to start due to the following error: 
%%2

Error: (11/18/2015 02:25:27 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The VIVACOM 3G USB Modem. OUC service failed to start due to the following error: 
%%1053

Error: (11/18/2015 02:25:27 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Timeout (30000 milliseconds) waiting for the VIVACOM 3G USB Modem. OUC service to connect.

Error: (11/18/2015 02:25:27 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The adfs service failed to start due to the following error: 
%%2

Error: (11/17/2015 05:58:47 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The VIVACOM 3G USB Modem. OUC service failed to start due to the following error: 
%%1053

Error: (11/17/2015 05:58:47 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Timeout (30000 milliseconds) waiting for the VIVACOM 3G USB Modem. OUC service to connect.

Error: (11/17/2015 05:58:47 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The adfs service failed to start due to the following error: 
%%2

Error: (11/16/2015 11:13:44 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The VIVACOM 3G USB Modem. OUC service failed to start due to the following error: 
%%1053


==================== Memory info =========================== 

Processor: AMD Sempron(tm) Processor 3200+
Percentage of memory in use: 80%
Total physical RAM: 511.3 MB
Available physical RAM: 98.63 MB
Total Virtual: 1248.58 MB
Available Virtual: 825.33 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:20 GB) (Free:4.32 GB) NTFS ==>[drive with boot components (Windows XP)]
Drive d: (User disk) (Fixed) (Total:54.53 GB) (Free:51.65 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 74.5 GB) (Disk ID: 832B832B)
Partition 1: (Active) - (Size=20 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=54.5 GB) - (Type=OF Extended)

==================== End of Addition.txt ===================

Addition.txt

Когато се появи член на HJT. Моля, имайте търпение! Все пак те не живеят в Kaldata.com

Здравейте,

 

Изтеглете 1wPOhWu.giffixlist.txt и го запазете на десктопа.
Стартирайте FRST.exe и натиснете бутона Fix веднъж!
След като приключи, ако ви поиска рестарт - съгласете се. След рестарта публикувайте лог файла - fixlog.txt, който ще се създаде след работата на програмата.
 
Внимание: Скрипта е създаден за текущата система. Да не се ползва за други системи с подобни проблеми!
 
След това пишете дали има подобрение.


Поздрави! HMq9Vuw.png

  • Автор

Здравейте направих всичко както ми казахте ето го файла прикачвам ви го сега ще видя браузера мозалия дали ги има рекламките и дали когато гледам онлайн телевизия има забавяне!

Fixlog.txt

B-boy/Style Бог да те поживи!Жив и здрав бъди!Всичко е наред! Няма на браузера реклами няма забавяния!Всичко е наред! Може ли да попитам да инсталирам ли на флашката си астрологичната ми програма за да не товари компютъра ми! Правих опити но компютъра ми даде прозорец, че системата не може да я инсталира! Благодаря за отговора! И извинявайте за безпокойствието което ви причиних!

Редактирано от mimisimova (преглед на промените)

Радвам се, че всичко е наред вече. :)

Няма проблеми за безпокойството.

Коя е тази програма и къде не ви дава да я инсталирате? На флашката ли или на компютъра? А вие сигурна ли сте, че тя може да работи от флашката? Обикновено има преносими версии на програмите, които са пригодени за работа от флашка.

Поздрави! 

  • Автор

Здравейте ами програмата се казва Astrology millenium не ми дава нито на компютъра нито на флашката. А първия път преди 4г ми я даде да я инсталирам. Първо отидох в библиотеката там имаше жена компютърен специалист и тя ми каза че трябвало на моя компютър да я инсталирам, защото ако съм я инсталирала на друг компютър на флашка нямало да работи програмата. После отидох в една от залите на дом там момчето ми каза че моя диск имал вирус и не можел да ми я инсталира. Сложих диска да видя дали има вирус програмата Malwarebaytes не откри такъв вирус. Какво да правя как да разбера дали диска който съм си го закупила преди 4г има вирус!Благодаря за отговора!:emoji_smiley-06:

Здравейте,

Цитат

А първия път преди 4г ми я даде да я инсталирам.

Къде? На компютъра или на флашката? Като цяло за 4г. доста вода е изтекла. Имало ли е промени по конфигурацията, хардуера, настройките на системата? Като гледам изискванията на програмата би трябвало да ги покривате...Имате инсталиран и .Net Framework 2 и Windows XP. Попаднах на телефон и адрес на автора на програмата. Остава да се опитате да се свържете с него за съвет?

E-mail: [email protected]
GSM: 0888 776 753

Цитат

После отидох в една от залите на дом там момчето ми каза че моя диск имал вирус и не можел да ми я инсталира.

Интересно какъв вирус е видял след като аз такъв поне в логовете не виждам. А и малко вируси предотвратяват инсталирането на програми (главно ако са пипали по правата на файловата система като ZeroAccess, ако са заразили всички exe файлове като Sality/Virut или някой друг, който бърника по Image File Execution Options в регистрите или има поставен Junction Point капан). Аз лично такива поразии не видях. Като цяло е малко вероятно да има вирус на диска щом сте я инсталирали преди 4г. ако е ползван същия диск. Значи тогава е бил чист, а диск не може да се зарази със вирус, ако вече е със затворена сесия...няма как да се качи вирус на затворен вече диск. А ако има такъв на диска няма да можете да го премахнете, защото той вече ще е запечатан на диска...Най-лесно е просто да пробвате да инсталирате програмата на друга система за да видите дали проблема е от диска изобщо или да се свържете с автора за съдействие. Ако се окаже, че е от вашата система тогава просто може да се наложи да направите една чиста инсталация на Операционната Система за да сте сигурни, че всичко ще работи след това.

Все пак можете да направите и следните 2 проверки за всеки случай:

 

СТЪПКА 1

 

 

  • Моля изтеглет EmsisoftEmergencyKit, стартирайте exe файла и посочете къде да се разархивира програмата - например в (C:\EEK), натискайки бутона Extract.
  • Стартирайте иконата на файла Start Emsisoft Emergency Kit от десктопа за да стартирате приложението.
  • Натиснете бутона"Yes", когато бъдете подканени да обновите дефинициите на програмата.
  • След като процеса по обновяването на дефинициите приключи натиснете бутона "Scan".
  • Натиснете бутона "Yes", когато бъдете попитани дали да програмата да включи засичането на потенциално нежелани приложения (Potentially Unwanted Applications).
  • Сега вече изберете бутона Custom Scan. Премахнете от списъка всички дялове без C:\ (т.е. нека да остане само дял C:\ в списъка).
  • Натиснете Next за да започне проверката.
  • Когато проверката приключи натиснете бутона View Report.
  • Копирайте съдържанието на лог файла в следващия си коментар.

 

СТЪПКА 2

 

  • Моля изтеглете и стартирайте изпълнимия файл от линка отдолу:
    ESET OnlineScan
  • Сложете отметката предesetAcceptTerms.png
  • Натиснете бутона esetStart.png.
  • Сложете отметката пред Enable detection of potentially unwanted applications.
  • Сега кликнете на Advanced Settings и се уверете, че опцията Remove found threats не е маркирана, а следните са маркирани:
    • Scan archives
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
    • Изберете сега бутона Change и изберете само Operating memory и дял C:\

fhSji42.png

  • Натиснете бутона Start.
  • ESET ще започне да сваля и инсталира актуализации за вирусните дефиниции и след това ще започне да сканира компютъра. Бъдете търпеливи, защото процеса е бавен и може да отнеме доста време.
  • След като проверката приключи натиснете бутонаesetListThreats.png
  • Сега натиснете бутона esetExport.png, и запазете файла на десктопа с име по избор като например (ESETScan.txt). Копирайте резултата в следващия си коментар.
  • Натиснете бутона esetBack.png и след това натиснете бутона esetFinish.png за да затворите приложението.

 

Поздрави!

   

Тъй като основния проблем в темата беше решен (а той беше за изскачащи реклами в браузърите) ще маркирам случая като решен!

Поздрави и хубав ден!

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.