Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Viber.exe вирус от фейсбук

Featured Replies

здравейте,и аз като доста хора пипнах новия вирус от фейсбук чрез отваряне на непознат файл,изпратен от приятел.Антивирусната нищо не засече и по време на заразяването и след  сканиране.Сега във фейсбук профила си не мога да ползвам опцията "споделения" след всяка  публикация .Отварянето на която и да е страница с браузъра става много по-бавно и  при отваряне на нов прозорец в полето за писане се появяват различни адреси. Инсталира се приложението Viber.ехе ,което не ползвам.Операционна система Windows 7 Ultimate,Service Pack 1 ,64-бита .Ето и логовете след сканиране :

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:27-01-2016
Ran by GERGANA (administrator) on GERGANA-PC (31-01-2016 20:56:25)
Running from C:\Users\GERGANA\Desktop
Loaded Profiles: GERGANA (Available Profiles: GERGANA)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Български (България)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Zemana Ltd.) C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco Systems\VPN Client\vpngui.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\splwow64.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM-x32\...\Run: [ZALFree] => C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe [8205944 2014-12-30] (Zemana Ltd.)
HKLM-x32\...\Run: [PSUAMain] => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe [54520 2015-10-22] (Panda Security, S.L.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [NoAutorun] 1
HKU\S-1-5-21-2308581884-3569660230-120424562-1000\...\Run: [Viber] => "C:\Users\GERGANA\AppData\Local\Viber\Viber.exe"
AppInit_DLLs: C:\PROGRA~2\KEYCRY~1\KEYCRY~4.DLL => C:\Program Files (x86)\KeyCryptSDK\KeyCrypt64(3).dll [94664 2014-12-30] (Zemana Ltd.)
AppInit_DLLs-x32: C:\PROGRA~2\KEYCRY~1\KEYCRY~3.DLL => C:\Program Files (x86)\KeyCryptSDK\KeyCrypt32(3).dll [86400 2014-12-30] (Zemana Ltd.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\vpngui.exe.lnk [2015-01-08]
ShortcutTarget: vpngui.exe.lnk -> C:\Windows\Installer\{5FDC06BF-3D3D-4367-8FFB-4FAFCB61972D}\Icon09DB8A851.exe ()
BootExecute: autocheck autochk * PCloudBroom64.exe \systemroot\system32\BroomData.bit
GroupPolicyScripts-x32: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 84.54.128.100 84.54.128.100
Tcpip\..\Interfaces\{94C064C5-8139-44AB-810C-1E9D0A2F024F}: [DhcpNameServer] 84.54.128.100 84.54.128.100
Tcpip\..\Interfaces\{C9DE01DF-38AF-422C-8292-00BF45A44DE5}: [DhcpNameServer] 217.18.252.131 87.246.20.11

Internet Explorer:
==================
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-04-04] (Adobe Systems Incorporated)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12] (Microsoft Corporation)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)

FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @real.com/nppl3260;version=6.0.12.69 -> C:\Program Files (x86)\Win7codecs\rm\browser\plugins\nppl3260.dll [2008-09-10] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpjplug;version=6.0.12.69 -> C:\Program Files (x86)\Win7codecs\rm\browser\plugins\nprpjplug.dll [2008-09-10] (RealNetworks, Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-04] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-04] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2012-04-04] (Adobe Systems Inc.)

Chrome: 
=======
CHR NewTab: Default -> "chrome-extension://jdpnghbmfklnmnpkpimicoclacbglfdg/nt/nt-h.html"
CHR Profile: C:\Users\GERGANA\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Документи) - C:\Users\GERGANA\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-04]
CHR Extension: (Google Диск) - C:\Users\GERGANA\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-23]
CHR Extension: (YouTube) - C:\Users\GERGANA\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (Google Търсене) - C:\Users\GERGANA\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Google Документи офлайн) - C:\Users\GERGANA\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-18]
CHR Extension: (Watch Later) - C:\Users\GERGANA\AppData\Local\Google\Chrome\User Data\Default\Extensions\hneblhapdjagodpfkenaiiaajkkbcfph [2016-01-31]
CHR Extension: (Start Home) - C:\Users\GERGANA\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdpnghbmfklnmnpkpimicoclacbglfdg [2016-01-20]
CHR Extension: (Плащания в уеб магазина на Chrome) - C:\Users\GERGANA\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-24]
CHR Extension: (Gmail) - C:\Users\GERGANA\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-01-08]

Opera: 
=======
OPR StartupUrls: "hxxp://google.bg/"

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-01-08] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-01-08] (Microsoft Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-07-05] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [178312 2015-09-25] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-08-21] (Intel Corporation)
R2 NanoServiceMain; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe [142072 2015-10-18] (Panda Security, S.L.)
R2 PandaAgent; C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe [73464 2015-10-28] (Panda Security, S.L.)
R2 PSUAService; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe [38136 2015-10-22] (Panda Security, S.L.)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [332800 2013-04-25] (IDT, Inc.) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [306536 2011-03-04] ()
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S3 gfiark; C:\Windows\System32\drivers\gfiark.sys [41032 2013-05-23] (ThreatTrack Security)
S3 gfiutil; C:\Windows\System32\drivers\gfiutil.sys [31264 2013-09-04] (ThreatTrack Security)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28656 2013-03-11] (Intel Corporation)
S3 jrdusbser; C:\Windows\System32\DRIVERS\jrdusbser.sys [119680 2009-11-17] (TCT International Mobile Ltd)
R3 keycrypt; C:\Windows\System32\DRIVERS\KeyCrypt64.sys [76520 2014-12-30] (Zemana Ltd.)
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [118504 2012-12-19] (Qualcomm Atheros Co., Ltd.)
R1 NNSALPC; C:\Windows\System32\DRIVERS\NNSAlpc.sys [94456 2015-07-09] (Panda Security, S.L.)
R1 NNSHTTP; C:\Windows\System32\DRIVERS\NNSHttp.sys [201976 2015-07-09] (Panda Security, S.L.)
R1 NNSHTTPS; C:\Windows\System32\DRIVERS\NNSHttps.sys [110840 2015-07-09] (Panda Security, S.L.)
R1 NNSIDS; C:\Windows\System32\DRIVERS\NNSIds.sys [110840 2015-07-09] (Panda Security, S.L.)
R1 NNSNAHSL; C:\Windows\System32\DRIVERS\NNSNAHSL.sys [57648 2015-05-20] (Panda Security, S.L.)
R1 NNSPICC; C:\Windows\System32\DRIVERS\NNSPicc.sys [103160 2015-07-09] (Panda Security, S.L.)
R1 NNSPIHSW; C:\Windows\System32\DRIVERS\NNSPihsw.sys [73464 2015-08-31] (Panda Security, S.L.)
R1 NNSPOP3; C:\Windows\System32\DRIVERS\NNSPop3.sys [124152 2015-07-09] (Panda Security, S.L.)
R1 NNSPROT; C:\Windows\System32\DRIVERS\NNSProt.sys [300280 2015-07-09] (Panda Security, S.L.)
R1 NNSPRV; C:\Windows\System32\DRIVERS\NNSPrv.sys [170232 2015-07-09] (Panda Security, S.L.)
R1 NNSSMTP; C:\Windows\System32\DRIVERS\NNSSmtp.sys [113400 2015-07-09] (Panda Security, S.L.)
R1 NNSSTRM; C:\Windows\System32\DRIVERS\NNSStrm.sys [257784 2015-07-09] (Panda Security, S.L.)
R1 NNSTLSC; C:\Windows\System32\DRIVERS\NNSTlsc.sys [106232 2015-07-09] (Panda Security, S.L.)
R2 PSINAflt; C:\Windows\System32\DRIVERS\PSINAflt.sys [164088 2015-07-19] (Panda Security, S.L.)
R2 PSINFile; C:\Windows\System32\DRIVERS\PSINFile.sys [121592 2015-07-19] (Panda Security, S.L.)
R1 PSINKNC; C:\Windows\System32\DRIVERS\psinknc.sys [197880 2015-07-19] (Panda Security, S.L.)
R2 PSINProc; C:\Windows\System32\DRIVERS\PSINProc.sys [124152 2015-07-19] (Panda Security, S.L.)
R2 PSINProt; C:\Windows\System32\DRIVERS\PSINProt.sys [134392 2015-07-19] (Panda Security, S.L.)
R2 PSINReg; C:\Windows\System32\DRIVERS\PSINReg.sys [107768 2015-07-19] (Panda Security, S.L.)
U3 PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [61712 2015-05-22] (Panda Security, S.L.)
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-01-31 20:56 - 2016-01-31 20:56 - 00013655 _____ C:\Users\GERGANA\Desktop\FRST.txt
2016-01-31 20:56 - 2016-01-31 20:56 - 00000000 ____D C:\FRST
2016-01-31 20:50 - 2016-01-31 20:50 - 02370560 _____ (Farbar) C:\Users\GERGANA\Desktop\FRST64.exe
2016-01-31 15:30 - 2015-05-22 10:45 - 00061712 _____ (Panda Security, S.L.) C:\Windows\system32\Drivers\PSKMAD.sys
2016-01-20 23:25 - 2016-01-20 23:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Free Antivirus
2016-01-17 22:36 - 2016-01-17 22:36 - 00407276 _____ C:\Users\GERGANA\Desktop\photo.htm
2016-01-08 19:23 - 2016-01-08 19:23 - 00012890 _____ C:\Users\GERGANA\Desktop\The.Hateful.Eight.2015.DVDScr.XVID.AC3.HQ.Hive-CM8.torrent
2016-01-04 19:59 - 2016-01-04 19:59 - 00000000 ____D C:\Users\GERGANA\Documents\2

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-01-31 20:54 - 2009-07-14 06:45 - 00021472 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-01-31 20:54 - 2009-07-14 06:45 - 00021472 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-01-31 20:40 - 2013-12-11 15:41 - 00000998 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-01-31 20:40 - 2013-12-11 15:41 - 00000994 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-01-31 16:37 - 2015-09-06 21:37 - 00000334 _____ C:\Windows\Tasks\CountCalories.job
2016-01-31 15:35 - 2009-07-14 07:13 - 00713888 _____ C:\Windows\system32\PerfStringBackup.INI
2016-01-31 15:35 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf
2016-01-31 15:30 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-01-30 16:23 - 2013-12-11 14:31 - 00000000 ____D C:\Users\GERGANA\AppData\Roaming\Skype
2016-01-28 23:42 - 2013-12-11 15:42 - 00002210 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-01-24 13:24 - 2009-07-14 07:08 - 00032526 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2016-01-24 01:18 - 2013-12-11 14:23 - 00000000 ____D C:\Users\GERGANA\AppData\Roaming\uTorrent
2016-01-21 09:45 - 2014-11-10 19:54 - 00003866 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1415642044
2016-01-21 09:45 - 2014-11-10 19:54 - 00000000 ____D C:\Program Files (x86)\Opera
2016-01-21 09:30 - 2014-04-22 18:15 - 00465272 _____ C:\Windows\system32\FNTCACHE.DAT
2016-01-21 09:30 - 2014-04-22 18:15 - 00110336 _____ C:\Users\GERGANA\AppData\Local\GDIPFONTCACHEV1.DAT
2016-01-20 23:23 - 2013-12-11 14:16 - 00000000 ____D C:\Program Files (x86)\Panda Security
2016-01-17 11:05 - 2013-12-11 11:35 - 00000000 ____D C:\Users\GERGANA
2016-01-14 19:25 - 2014-11-27 18:22 - 00000000 ___RD C:\Program Files (x86)\Skype

==================== Files in the root of some directories =======

2014-03-20 22:13 - 2015-11-29 00:34 - 0007680 _____ () C:\Users\GERGANA\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-12-17 19:46 - 2014-09-03 22:44 - 0007668 _____ () C:\Users\GERGANA\AppData\Local\resmon.resmoncfg
2014-02-01 23:20 - 2014-02-01 23:20 - 0000000 _____ () C:\ProgramData\0x0304A000.sfl

Some files in TEMP:
====================
C:\Users\GERGANA\AppData\Local\Temp\SkypeSetup.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-01-31 00:12

==================== End of FRST.txt ============================

Addition.txt

Здравейте..! :)

Сканиране с AdwCleaner

 
Моля, изтеглете и стартирайте програмата AdwCleaner (by Xplode):

  • Затворете всички стартирани програми и браузъри
  • Кликнете два пъти върху adwcleaner.exe за да стартирате инструмента.
  • Натиснете OK, за да потвърдите, че всички стартирани програми ще бъдат затворени.
  • Маркирайте Clean
  • Вашият компютър ще се рестартира автоматично. Текстовия файл ще се отвори след рестарта.
  • Моля, да публикувате съдържанието на този лог в отговора си
  • Можете да намерите лога,който автоматично се запомня тук C:AdwCleaner[s0].txt

 

Сканиране с Junkware Removal Tool
 
Моля, изтеглете Junkware Removal Tool (by Thisisu ) и запазете на вашия десктоп.

  • Спрете временно работата на защитните програми.
  • Стартирайте инструмента JRT.exe
  • Ще се отвори ДОС прозорец. Натиснете което и да е копче от клавиатурата.
  • Затворете излишните приложения и всички браузъри и изчакайте проверката да завърши.
  • Ще се появи лог файл (който можете да намерите и ръчно на десктопа с името JRT.txt).
  • Моля копирайте съдържанието на лог файла в следващия си пост.

 

122.jpg?1414578932  Моля, изтеглете  Check Browsers' LNK by Dragokas & regist

  • Запомнете архива на вашия декстоп,разархивирате.
  • Временно спрете вашия  антивирусен софтуер.
  • Стартирайте файла Check Browsers LNK.exe от името на администратор.
  • Изчакайте програмата да завърши работата си.Това може да отнеме до 5 минути. Моля бъдете търпеливи. След сканирането, отворете генерираната папка LOG и публикувайте отчета Check_Browsers_LNK.log, в следвашия си пост.

 

Изтрийте FRST.exe и логовете към нея. След това изтеглете отново свежа версия и повторете сканирането по тази инструкция:

 

Сканиране с Farbar Recovery Scan Tool

 

  • Моля изтеглете icon1337953436.pngFarbar Recovery Scan Tool (според версията на Windows изберете 32 битовата или 64 битовата версия) и го запазете на десктопа.
  • Стартирайте файла FRST.exe (или FRST64.exe)
  • Програмата ще се стартира. Натиснете YES за да се съгласите с лицензионното споразумение.
  • Натиснете бутона YClYkft.jpg.
  • Изчакайте търпеливо проверката да приключи.
  • Ще се създадат два лог файла с името - FRST.txt и Addition.txt на десктопа.
  • Копирайте съдържанието на файла FRST.txt в следващия си пост. Прикачете Addition.txt в коментар си (погледнете опцията Прикачване на файлове, когато публикувате мнение).

 

Дневници
 
В следващия си отговор, моля да включите следните дневници:

  • AdwCleaner[s0].txt
  • JRT.txt
  • Check_Browsers_LNK.log
  • FRST.txt (копирате цялото съдържание)
  • Addition.txt (прикачате..)

 

 

  • Автор

Здравейте,извърших посочените сканирания.Ето ги и логовете,като не знам защо AdwCleaner  генерира лог AdwCleaner[S1].txt

# AdwCleaner v5.032 - Лог файлът е създаден 02/02/2016 при 19:37:46
# Обновен 31/01/2016 от Xplode
# База данни : 2016-01-31.1 [Сървър]
# Операционна система : Windows 7 Ultimate Service Pack 1 (x64)
# Потребителско име : GERGANA - GERGANA-PC
# Изпълнява се от : C:\Users\GERGANA\Desktop\adwcleaner_5.032.exe
# Опция : Сканирай
# Поддръжка : http://toolslib.net/forum

***** [ Сервизи ] *****


***** [ Папки ] *****


***** [ Файлове ] *****


***** [ DLL ] *****


***** [ Преки пътища ] *****


***** [ Планирани задачи ] *****


***** [ Регистър ] *****

Ключ Намерен : HKLM\SOFTWARE\Classes\CLSID\{3CCC052E-BDEE-408A-BEA7-90914EF2964B}
Ключ Намерен : HKLM\SOFTWARE\Classes\CLSID\{61F47056-E400-43D3-AF1E-AB7DFFD4C4AD}
Ключ Намерен : HKLM\SOFTWARE\Classes\CLSID\{E2B98EEA-EE55-4E9B-A8C1-6E5288DF785A}

***** [ Уеб браузъри ] *****

[C:\Users\GERGANA\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Намерен : ask.com

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1200 байта] ########## 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.2 (01.06.2016)
Operating System: Windows 7 Ultimate x64
Ran by GERGANA (Limited) on ўв 02.02.2016 Ј. at 19:46:39,95
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 


File System: 6

Successfully deleted: C:\ProgramData\productdata (Folder)
Successfully deleted: C:\Users\GERGANA\AppData\Roaming\productdata (Folder)
Successfully deleted: C:\Users\GERGANA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2XQ59SYT (Folder)
Successfully deleted: C:\Users\GERGANA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CWW9ODUI (Folder)
Successfully deleted: C:\Users\GERGANA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HKPEROKJ (Folder)
Successfully deleted: C:\Users\GERGANA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZNC5QX22 (Folder)

 

Registry: 0

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on ўв 02.02.2016 Ј. at 19:50:03,50
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Check Browsers' LNK  by Alex Dragokas & regist                                 ver. 2.0.0.12 ( Beta )

OS:       x64 Windows 7 Ultimate, 6.1.7601, Service Pack: 1
Time:     02.02.2016 - 19:53
Language: OS: Bulgarian (0x402). Display: Bulgarian (0x402). Non-Unicode: Bulgarian (0x402)
Elevated: Yes
User:     GERGANA (group: Administrator)


* Suspicious objects will be marked with prefix >>>

=========================================================================
               ((((((       Other shortcuts       ))))))                
=========================================================================

_______________________  Target does not exist  _________________________

- "C:\Users\GERGANA\AppData\Roaming\Microsoft\Office\Последни\15.LNK"  -> ["C:\Users\GERGANA\Desktop\15.ppt"]
- "C:\Users\GERGANA\AppData\Roaming\Microsoft\Office\Последни\brinka.LNK"        -> ["C:\Users\GERGANA\Desktop\Нова папка\brinka"]
- "C:\Users\GERGANA\AppData\Roaming\Microsoft\Office\Последни\Cu.LNK"  -> ["C:\Users\GERGANA\Desktop\Cu.ppt"]
- "C:\Users\GERGANA\AppData\Roaming\Microsoft\Office\Последни\deklaratsiya-za-polzvane-na-otpusk-po-chl163-al1-ili-al6-ot-kodeksa-na-truda-ot-maykata (1).doc.LNK"         -> ["C:\Users\GERGANA\Desktop\deklaratsiya-za-polzvane-na-otpusk-po-chl163-al1-ili-al6-ot-kodeksa-na-truda-ot-maykata (1).doc"]
- "C:\Users\GERGANA\AppData\Roaming\Microsoft\Office\Последни\deklaratsiya-za-polzvane-na-otpusk-po-chl163-al1-ili-al6-ot-kodeksa-na-truda-ot-maykata.doc.LNK"   -> ["C:\Users\GERGANA\Desktop\deklaratsiya-za-polzvane-na-otpusk-po-chl163-al1-ili-al6-ot-kodeksa-na-truda-ot-maykata.doc"]
- "C:\Users\GERGANA\AppData\Roaming\Microsoft\Office\Последни\dinko.xls.LNK"     -> ["C:\Users\GERGANA\Desktop\dinko.xls"]
- "C:\Users\GERGANA\AppData\Roaming\Microsoft\Office\Последни\don4o.LNK"         -> ["C:\Users\GERGANA\Desktop\don4o.xls"]
- "C:\Users\GERGANA\AppData\Roaming\Microsoft\Office\Последни\exportFile (1).xls.LNK"      -> ["C:\Users\GERGANA\Desktop\exportFile (1).xls"]
- "C:\Users\GERGANA\AppData\Roaming\Microsoft\Office\Последни\exportFile.LNK"    -> ["C:\Users\GERGANA\Desktop\exportFile.xls"]
- "C:\Users\GERGANA\AppData\Roaming\Microsoft\Office\Последни\exportFile.xls.LNK"          -> ["C:\Users\GERGANA\Desktop\exportFile.xls"]
- "C:\Users\GERGANA\AppData\Roaming\Microsoft\Office\Последни\Ghost Rider.LNK"   -> ["D:\филми\Ghost Rider"]
- "C:\Users\GERGANA\AppData\Roaming\Microsoft\Office\Последни\mtm-ii-22.LNK"     -> ["C:\Users\GERGANA\Desktop\mtm-ii-22.ppt"]
- "C:\Users\GERGANA\AppData\Roaming\Microsoft\Office\Последни\NOV Otchet 12vd-okonchatelen11.xls.LNK"          -> ["C:\Users\GERGANA\Desktop\NOV Otchet 12vd-okonchatelen11.xls"]
- "C:\Users\GERGANA\AppData\Roaming\Microsoft\Office\Последни\pril2_2016.doc.LNK"          -> ["C:\Users\GERGANA\Desktop\pril2_2016.doc"]
- "C:\Users\GERGANA\AppData\Roaming\Microsoft\Office\Последни\reportIdent32 (1).doc.LNK"   -> ["C:\Users\GERGANA\Desktop\reportIdent32 (1).doc"]
- "C:\Users\GERGANA\AppData\Roaming\Microsoft\Office\Последни\reportIdent32.doc.LNK"       -> ["C:\Users\GERGANA\Desktop\reportIdent32.doc"]
- "C:\Users\GERGANA\AppData\Roaming\Microsoft\Office\Последни\Zaharen_kombinat_Plovdiv_AD_bg.ppt.LNK"          -> ["C:\Users\GERGANA\Desktop\Zaharen_kombinat_Plovdiv_AD_bg.ppt"]
- "C:\Users\GERGANA\AppData\Roaming\Microsoft\Office\Последни\Валта  13.09.2014.doc.LNK"   -> ["C:\Users\GERGANA\Desktop\Валта  13.09.2014.doc"]
- "C:\Users\GERGANA\AppData\Roaming\Microsoft\Office\Последни\Валта  21.01.2016.doc.LNK"   -> ["C:\Users\GERGANA\Desktop\Валта  21.01.2016.doc"]
- "C:\Users\GERGANA\AppData\Roaming\Microsoft\Office\Последни\защита по делото в адмниситративен съд-пловдив.docx.LNK"   -> ["C:\Users\GERGANA\Desktop\защита по делото в адмниситративен съд-пловдив.docx"]
- "C:\Users\GERGANA\AppData\Roaming\Microsoft\Office\Последни\Заявление-и-заповед-майчинство.docx.LNK"         -> ["C:\Users\GERGANA\Desktop\Заявление-и-заповед-майчинство.docx"]
- "C:\Users\GERGANA\AppData\Roaming\Microsoft\Office\Последни\николай.LNK"       -> ["C:\Users\GERGANA\Desktop\николай.xls"]
- "C:\Users\GERGANA\AppData\Roaming\Microsoft\Office\Последни\оферта зоовет февруари 2015.xls.LNK"   -> ["C:\Users\GERGANA\Desktop\оферта зоовет февруари 2015.xls"]
- "C:\Users\GERGANA\AppData\Roaming\Microsoft\Office\Последни\Приложение 5 Ръководство на потребителя вариант 2.doc.LNK"           -> ["C:\Users\GERGANA\Desktop\Приложение 5 Ръководство на потребителя вариант 2.doc"]
- "C:\Users\GERGANA\AppData\Roaming\Microsoft\Office\Последни\Тодор Пенков 13.,01.2016.doc.LNK"      -> ["C:\Users\GERGANA\Desktop\Тодор Пенков 13.,01.2016.doc"]
- "C:\Users\GERGANA\AppData\Roaming\Microsoft\Office\Последни\Указанияпроби РВЛ вариант 2.docx.LNK"  -> ["C:\Users\GERGANA\Desktop\Указанияпроби РВЛ вариант 2.docx"]
- "C:\Users\GERGANA\AppData\Roaming\Microsoft\Office\Последни\Черните.doc.LNK"   -> ["C:\Users\GERGANA\Desktop\Черните.doc"]
- "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Jewel of Atlantis\Buy Now.lnk"     -> ["C:\Program Files (x86)\Jewel of Atlantis\data\drm\Buy Now.url"]
- "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Jewel of Atlantis\Enkord website.lnk"        -> ["C:\Program Files (x86)\Jewel of Atlantis\data\drm\Enkord.url"]
- "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Jewel of Atlantis\Jewel of Atlantis.lnk"     -> ["C:\Program Files (x86)\Jewel of Atlantis\Jewel of Atlantis.exe"]
- "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Jewel of Atlantis\More games.lnk"  -> ["C:\Program Files (x86)\Jewel of Atlantis\data\drm\More games.url"]
- "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Jewel of Atlantis\Newsletter.lnk"  -> ["C:\Program Files (x86)\Jewel of Atlantis\data\drm\Newsletter.url"]
- "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Jewel of Atlantis\Uninstall.lnk"   -> ["C:\Program Files (x86)\Jewel of Atlantis\Uninstall.exe"]
- "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Cloud Antivirus\Help.lnk"    -> ["C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSUAMain.exe"  =>> /URL:WebHelp]
- "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Cloud Antivirus\Online tech support.lnk"         -> ["C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSUAMain.exe"  =>> /URL:TechSupport]
- "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Cloud Antivirus\Share ideas and solutions.lnk"   -> ["C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSUAMain.exe"  =>> /URL:YourOpinion]
- "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shark007 Codecs\Settings Application.lnk"    -> ["C:\Program Files (x86)\Win7codecs\Tools\Settings32.exe"]

__________________  Target on remote / network device  __________________

- "C:\Users\GERGANA\AppData\Roaming\Microsoft\Office\Последни\Вичка.LNK"         -> ["F:\ДПЖ\Вичка"] ( target is on the removable device: DISCONNECTED )
- "C:\Users\GERGANA\AppData\Roaming\Microsoft\Office\Последни\Деян.LNK"          -> ["F:\ДПЖ\Деян"] ( target is on the removable device: DISCONNECTED )
- "C:\Users\GERGANA\AppData\Roaming\Microsoft\Office\Последни\Димо Йорданов.LNK"           -> ["F:\ДПЖ\Димо Йорданов"] ( target is on the removable device: DISCONNECTED )
- "C:\Users\GERGANA\AppData\Roaming\Microsoft\Office\Последни\Руси.LNK"          -> ["F:\ДПЖ\Руси"] ( target is on the removable device: DISCONNECTED )
- "C:\Users\GERGANA\AppData\Roaming\Microsoft\Office\Последни\Сарито.LNK"        -> ["F:\ДПЖ\Сарито"] ( target is on the removable device: DISCONNECTED )
- "C:\Users\GERGANA\AppData\Roaming\Microsoft\Office\Последни\Сменяем диск (F).LNK"        -> ["F:\"] ( target is on the removable device: DISCONNECTED )
- "C:\Users\GERGANA\AppData\Roaming\Microsoft\Office\Последни\Циганин георги.LNK"          -> ["F:\ДПЖ\Циганин георги"] ( target is on the removable device: DISCONNECTED )

=========================================================================
                 ((((((      Internet shortcuts       ))))))            
=========================================================================

- "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Icecream Media Converter\Icecream Media Converter on the Web.url"  ->          hxxp://icecreamapps.com/Media-Converter/
- "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiLogger Free\AntiLogger Free on the Web.url"  ->      hxxp://vvv.zemana.com/

_________________ Browser by default ________________

- [OK] http  = "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Chrome)
- [OK] https = "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Chrome)
- [OK] ftp   = "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Chrome)
- [OK] .htm  = "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Chrome)
- [OK] .html = "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Chrome)
- [OK] .url  = "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Internet Explorer)

_____________________ Statistics ____________________

Threats found:      0
Removed attrib. RO: 0 from 0
Start mode:         Normal
Time spent:         4 sec. (search: 2 sec.)
Folders processed:  1457
Files processed:    6001 (shortcuts: 231)

Been verified:
C:\Users\GERGANA
C:\Users\Default
C:\Users\Public
C:\ProgramData
_____________________________ End of Log ________________________________

______________________ Maximum of file objects __________________________
391   ( 391 )   - C:\Users\GERGANA\AppData\Local\Google\Chrome\User Data\Default\Media Cache
55    ( 646 )   - C:\Users\GERGANA\AppData\Local\Google\Chrome\User Data\Default
204   ( 216 )   - C:\Users\GERGANA\AppData\Roaming\uTorrent
396   ( 1952 )  - C:\ProgramData\Adobe\ARM\Reader_10.1.3

_________________________________________________________________________20146 bytes, CRC32: FFFFFFFF. Sign: 遻ຬ

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:27-01-2016
Ran by GERGANA (administrator) on GERGANA-PC (02-02-2016 19:57:20)
Running from C:\Users\GERGANA\Desktop
Loaded Profiles: GERGANA (Available Profiles: GERGANA)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Български (България)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM-x32\...\Run: [ZALFree] => C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe [8205944 2014-12-30] (Zemana Ltd.)
HKLM-x32\...\Run: [PSUAMain] => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe [54520 2015-10-22] (Panda Security, S.L.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [NoAutorun] 1
HKU\S-1-5-21-2308581884-3569660230-120424562-1000\...\Run: [Viber] => "C:\Users\GERGANA\AppData\Local\Viber\Viber.exe"
AppInit_DLLs: C:\PROGRA~2\KEYCRY~1\KEYCRY~4.DLL => C:\Program Files (x86)\KeyCryptSDK\KeyCrypt64(3).dll [94664 2014-12-30] (Zemana Ltd.)
AppInit_DLLs-x32: C:\PROGRA~2\KEYCRY~1\KEYCRY~3.DLL => C:\Program Files (x86)\KeyCryptSDK\KeyCrypt32(3).dll [86400 2014-12-30] (Zemana Ltd.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\vpngui.exe.lnk [2015-01-08]
ShortcutTarget: vpngui.exe.lnk -> C:\Windows\Installer\{5FDC06BF-3D3D-4367-8FFB-4FAFCB61972D}\Icon09DB8A851.exe ()
BootExecute: autocheck autochk * PCloudBroom64.exe \systemroot\system32\BroomData.bit
GroupPolicyScripts-x32: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 84.54.128.100 84.54.128.100
Tcpip\..\Interfaces\{94C064C5-8139-44AB-810C-1E9D0A2F024F}: [DhcpNameServer] 84.54.128.100 84.54.128.100
Tcpip\..\Interfaces\{C9DE01DF-38AF-422C-8292-00BF45A44DE5}: [DhcpNameServer] 217.18.252.131 87.246.20.11

Internet Explorer:
==================
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-04-04] (Adobe Systems Incorporated)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12] (Microsoft Corporation)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)

FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @real.com/nppl3260;version=6.0.12.69 -> C:\Program Files (x86)\Win7codecs\rm\browser\plugins\nppl3260.dll [2008-09-10] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpjplug;version=6.0.12.69 -> C:\Program Files (x86)\Win7codecs\rm\browser\plugins\nprpjplug.dll [2008-09-10] (RealNetworks, Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2012-04-04] (Adobe Systems Inc.)

Chrome:
=======
CHR NewTab: Default -> "chrome-extension://jdpnghbmfklnmnpkpimicoclacbglfdg/nt/nt-h.html"
CHR Profile: C:\Users\GERGANA\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Документи) - C:\Users\GERGANA\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-04]
CHR Extension: (Google Диск) - C:\Users\GERGANA\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-23]
CHR Extension: (YouTube) - C:\Users\GERGANA\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (Google Търсене) - C:\Users\GERGANA\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Google Документи офлайн) - C:\Users\GERGANA\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-18]
CHR Extension: (Watch Later) - C:\Users\GERGANA\AppData\Local\Google\Chrome\User Data\Default\Extensions\hneblhapdjagodpfkenaiiaajkkbcfph [2016-01-31]
CHR Extension: (Start Home) - C:\Users\GERGANA\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdpnghbmfklnmnpkpimicoclacbglfdg [2016-01-20]
CHR Extension: (Плащания в уеб магазина на Chrome) - C:\Users\GERGANA\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-24]
CHR Extension: (Gmail) - C:\Users\GERGANA\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-01-08]

Opera:
=======
OPR StartupUrls: "hxxp://google.bg/"

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-01-08] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-01-08] (Microsoft Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-07-05] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [178312 2015-09-25] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-08-21] (Intel Corporation)
R2 NanoServiceMain; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe [142072 2015-10-18] (Panda Security, S.L.)
R2 PandaAgent; C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe [73464 2015-10-28] (Panda Security, S.L.)
R2 PSUAService; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe [38136 2015-10-22] (Panda Security, S.L.)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [332800 2013-04-25] (IDT, Inc.) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [306536 2011-03-04] ()
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S3 gfiark; C:\Windows\System32\drivers\gfiark.sys [41032 2013-05-23] (ThreatTrack Security)
S3 gfiutil; C:\Windows\System32\drivers\gfiutil.sys [31264 2013-09-04] (ThreatTrack Security)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28656 2013-03-11] (Intel Corporation)
S3 jrdusbser; C:\Windows\System32\DRIVERS\jrdusbser.sys [119680 2009-11-17] (TCT International Mobile Ltd)
R3 keycrypt; C:\Windows\System32\DRIVERS\KeyCrypt64.sys [76520 2014-12-30] (Zemana Ltd.)
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [118504 2012-12-19] (Qualcomm Atheros Co., Ltd.)
R1 NNSALPC; C:\Windows\System32\DRIVERS\NNSAlpc.sys [94456 2015-07-09] (Panda Security, S.L.)
R1 NNSHTTP; C:\Windows\System32\DRIVERS\NNSHttp.sys [201976 2015-07-09] (Panda Security, S.L.)
R1 NNSHTTPS; C:\Windows\System32\DRIVERS\NNSHttps.sys [110840 2015-07-09] (Panda Security, S.L.)
R1 NNSIDS; C:\Windows\System32\DRIVERS\NNSIds.sys [110840 2015-07-09] (Panda Security, S.L.)
R1 NNSNAHSL; C:\Windows\System32\DRIVERS\NNSNAHSL.sys [57648 2015-05-20] (Panda Security, S.L.)
R1 NNSPICC; C:\Windows\System32\DRIVERS\NNSPicc.sys [103160 2015-07-09] (Panda Security, S.L.)
R1 NNSPIHSW; C:\Windows\System32\DRIVERS\NNSPihsw.sys [73464 2015-08-31] (Panda Security, S.L.)
R1 NNSPOP3; C:\Windows\System32\DRIVERS\NNSPop3.sys [124152 2015-07-09] (Panda Security, S.L.)
R1 NNSPROT; C:\Windows\System32\DRIVERS\NNSProt.sys [300280 2015-07-09] (Panda Security, S.L.)
R1 NNSPRV; C:\Windows\System32\DRIVERS\NNSPrv.sys [170232 2015-07-09] (Panda Security, S.L.)
R1 NNSSMTP; C:\Windows\System32\DRIVERS\NNSSmtp.sys [113400 2015-07-09] (Panda Security, S.L.)
R1 NNSSTRM; C:\Windows\System32\DRIVERS\NNSStrm.sys [257784 2015-07-09] (Panda Security, S.L.)
R1 NNSTLSC; C:\Windows\System32\DRIVERS\NNSTlsc.sys [106232 2015-07-09] (Panda Security, S.L.)
R2 PSINAflt; C:\Windows\System32\DRIVERS\PSINAflt.sys [164088 2015-07-19] (Panda Security, S.L.)
R2 PSINFile; C:\Windows\System32\DRIVERS\PSINFile.sys [121592 2015-07-19] (Panda Security, S.L.)
R1 PSINKNC; C:\Windows\System32\DRIVERS\psinknc.sys [197880 2015-07-19] (Panda Security, S.L.)
R2 PSINProc; C:\Windows\System32\DRIVERS\PSINProc.sys [124152 2015-07-19] (Panda Security, S.L.)
R2 PSINProt; C:\Windows\System32\DRIVERS\PSINProt.sys [134392 2015-07-19] (Panda Security, S.L.)
R2 PSINReg; C:\Windows\System32\DRIVERS\PSINReg.sys [107768 2015-07-19] (Panda Security, S.L.)
U3 PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [61712 2015-05-22] (Panda Security, S.L.)
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-02-02 19:57 - 2016-02-02 19:57 - 00013053 _____ C:\Users\GERGANA\Desktop\FRST.txt
2016-02-02 19:56 - 2016-02-02 19:56 - 02370560 _____ (Farbar) C:\Users\GERGANA\Desktop\FRST64.exe
2016-02-02 19:53 - 2016-02-02 19:53 - 00000000 ____D C:\Users\GERGANA\Desktop\LOG
2016-02-02 19:52 - 2016-02-02 19:52 - 00227504 _____ C:\Users\GERGANA\Desktop\CheckBrowsersLNK.zip
2016-02-02 19:52 - 2016-01-22 18:13 - 00610448 _____ (Alex Dragokas) C:\Users\GERGANA\Desktop\Check Browsers LNK.exe
2016-02-02 19:50 - 2016-02-02 19:50 - 00001208 _____ C:\Users\GERGANA\Desktop\JRT.txt
2016-02-02 19:44 - 2016-02-02 19:44 - 01609032 _____ (Malwarebytes) C:\Users\GERGANA\Desktop\JRT.exe
2016-02-02 19:41 - 2015-05-22 10:45 - 00061712 _____ (Panda Security, S.L.) C:\Windows\system32\Drivers\PSKMAD.sys
2016-02-02 19:37 - 2016-02-02 19:38 - 00001284 _____ C:\Users\GERGANA\Desktop\AdwCleaner[S1].txt
2016-02-02 19:35 - 2016-02-02 19:43 - 00000000 ____D C:\AdwCleaner
2016-02-02 19:33 - 2016-02-02 19:33 - 01508352 _____ C:\Users\GERGANA\Desktop\adwcleaner_5.032.exe
2016-01-31 20:56 - 2016-02-02 19:57 - 00000000 ____D C:\FRST
2016-01-20 23:25 - 2016-01-20 23:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Free Antivirus
2016-01-17 22:36 - 2016-01-17 22:36 - 00407276 _____ C:\Users\GERGANA\Desktop\photo.htm
2016-01-08 19:23 - 2016-01-08 19:23 - 00012890 _____ C:\Users\GERGANA\Desktop\The.Hateful.Eight.2015.DVDScr.XVID.AC3.HQ.Hive-CM8.torrent
2016-01-04 19:59 - 2016-01-04 19:59 - 00000000 ____D C:\Users\GERGANA\Documents\2

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-02-02 19:48 - 2009-07-14 06:45 - 00021472 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-02-02 19:48 - 2009-07-14 06:45 - 00021472 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-02-02 19:47 - 2013-12-11 15:41 - 00000998 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-02-02 19:47 - 2013-12-11 15:41 - 00000994 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-02-02 19:45 - 2009-07-14 07:13 - 00713888 _____ C:\Windows\system32\PerfStringBackup.INI
2016-02-02 19:45 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf
2016-02-02 19:42 - 2013-12-11 15:41 - 00003994 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-02-02 19:42 - 2013-12-11 15:41 - 00003742 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2016-02-02 19:41 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-02-01 16:37 - 2015-09-06 21:37 - 00000334 _____ C:\Windows\Tasks\CountCalories.job
2016-01-30 16:23 - 2013-12-11 14:31 - 00000000 ____D C:\Users\GERGANA\AppData\Roaming\Skype
2016-01-28 23:42 - 2013-12-11 15:42 - 00002210 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-01-24 13:24 - 2009-07-14 07:08 - 00032526 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2016-01-24 01:18 - 2013-12-11 14:23 - 00000000 ____D C:\Users\GERGANA\AppData\Roaming\uTorrent
2016-01-21 09:45 - 2014-11-10 19:54 - 00003866 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1415642044
2016-01-21 09:45 - 2014-11-10 19:54 - 00000000 ____D C:\Program Files (x86)\Opera
2016-01-21 09:30 - 2014-04-22 18:15 - 00465272 _____ C:\Windows\system32\FNTCACHE.DAT
2016-01-21 09:30 - 2014-04-22 18:15 - 00110336 _____ C:\Users\GERGANA\AppData\Local\GDIPFONTCACHEV1.DAT
2016-01-20 23:23 - 2013-12-11 14:16 - 00000000 ____D C:\Program Files (x86)\Panda Security
2016-01-17 11:05 - 2013-12-11 11:35 - 00000000 ____D C:\Users\GERGANA
2016-01-14 19:25 - 2014-11-27 18:22 - 00000000 ___RD C:\Program Files (x86)\Skype

==================== Files in the root of some directories =======

2014-03-20 22:13 - 2015-11-29 00:34 - 0007680 _____ () C:\Users\GERGANA\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-12-17 19:46 - 2014-09-03 22:44 - 0007668 _____ () C:\Users\GERGANA\AppData\Local\resmon.resmoncfg
2014-02-01 23:20 - 2014-02-01 23:20 - 0000000 _____ () C:\ProgramData\0x0304A000.sfl

Some files in TEMP:
====================
C:\Users\GERGANA\AppData\Local\Temp\SkypeSetup.exe
C:\Users\GERGANA\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-01-31 00:12

==================== End of FRST.txt ============================

Addition.txt

Оххх..не не сме приключили..аз те забравих теб...Извинявам се...сега ще прегледам дневниците..!

Фикс с Farbar Recovery Scan Tool

 
icon13.gif Изтеглете прикачения файл - fixlist.txt и го запазете там, където сте свалили FRST.exe
Стартирайте отново FRST.exe и натиснете бутона Fix веднъж и изчакайте.
Ще се създаде нов лог файла FixLog.txt. Прикачете съдържанието му в следващия си коментар.

 
ЗАБЕЛЕЖКА: Този скрипт е написан специално за този потребител,и за тази конкретна машина. Изпълнението на фикса, на друг компютър може да доведе до увреждане на  операционната ви система

 

Какво е състоянието на системата ви след процедурите до тук..! Наблюдавате ли още някакви проблеми..?

 

Дневници
 
В следващия си отговор, моля да включите следните дневници:

  • FixLog.txt
  • Автор

няма проблем 

изпълних инсструкцията и прилагам лог файла.На всеки нов отворен прозорец с браузъра (хром) се изписват  различни адреси -http://enikensky.com/s.html ,http://merhome.com/s.html ,http://glostas.com/s.html ,http://glsearch1.com/s.html и т.н. ,постоянно генерира нови препратки ,като бързина на работа видимо се подобриха нещата. 

Fix result of Farbar Recovery Scan Tool (x64) Version:27-01-2016
Ran by GERGANA (2016-02-05 19:13:05) Run:1
Running from C:\Users\GERGANA\Desktop
Loaded Profiles: GERGANA (Available Profiles: GERGANA)
Boot Mode: Normal
==============================================

fixlist content:
*****************
start
CreateRestorePoint:
CloseProcesses:
HKU\S-1-5-21-2308581884-3569660230-120424562-1000\...\Run: [Viber] => "C:\Users\GERGANA\AppData\Local\Viber\Viber.exe"
GroupPolicyScripts-x32: Restriction <======= ATTENTION 
C:\Users\GERGANA\AppData\Local\Temp\SkypeSetup.exe
C:\Users\GERGANA\AppData\Local\Temp\sqlite3.dll 
Task: {A8A8B5B9-83E2-4598-B0A4-51348188A5D7} - System32\Tasks\CountCalories => c:\programdata\{1dace886-e5fd-fbba-1dac-ce886e5fa21b}\download.exe [2014-09-06] () <==== ATTENTION
Task: C:\Windows\Tasks\CountCalories.job => c:\programdata\{1dace886-e5fd-fbba-1dac-ce886e5fa21b}\download.exe <==== ATTENTION
AlternateDataStreams: C:\ProgramData\TEMP:3FF8C45D
cmd: bitsadmin /reset /allusers
cmd: netsh winsock reset catalog
cmd: ipconfig /flushdns
emptytemp:
reboot:
end
*****************

Restore point was successfully created.
Processes closed successfully.
HKU\S-1-5-21-2308581884-3569660230-120424562-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Viber => value removed successfully
C:\Windows\SysWOW64\GroupPolicy\Machine => moved successfully
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
C:\Windows\SysWOW64\GroupPolicy\GPT.ini => moved successfully
C:\Users\GERGANA\AppData\Local\Temp\SkypeSetup.exe => moved successfully
C:\Users\GERGANA\AppData\Local\Temp\sqlite3.dll => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A8A8B5B9-83E2-4598-B0A4-51348188A5D7}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A8A8B5B9-83E2-4598-B0A4-51348188A5D7}" => key removed successfully
C:\Windows\System32\Tasks\CountCalories => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CountCalories" => key removed successfully
C:\Windows\Tasks\CountCalories.job => moved successfully
C:\ProgramData\TEMP => ":3FF8C45D" ADS removed successfully.

=========  bitsadmin /reset /allusers =========


BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

0 out of 0 jobs canceled.

========= End of CMD: =========


=========  netsh winsock reset catalog =========


Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.


========= End of CMD: =========


=========  ipconfig /flushdns =========


Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========

EmptyTemp: => 1.6 GB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 19:14:31 ====

  • Автор

пробвах се  много пъти и винаги в браузъра се появява нов адрес.Погледнах в настройките на браузъра и открих че в настройката "при стартиране" в опцията "да се отваря нов раздел в браузъра" пише че разширението " Start Home " контролира тази настройка.

Редактирано от мирослав24 (преглед на промените)

СТЪПКА 1

 

icon_zps423a0d9f.jpgМоля изтеглете ZHPcleaner и я запазете на вашия десктоп.

  • Стартирайте ZHPCleaner с десен клик върху файла и изберете от контекстното меню "Run as administrator"
  • Кликнете върху Ashampoo_Snap_20140819_13h09m50s_001__zp за да се съгласите с лицензионното споразумение.
  • Изберете бутона y3pI4LR.png.
  • Браузърите ще бъдат затворени автоматично.
  • Ще се отвори лог файл след прикючването на проверката.
  • Публикувайте лог файла в следващия си коментар.

 

СТЪПКА 2

 

 

Моля изтеглете Malwarebytes Anti-Malware 2.2.0.1024 Final и я запазете на вашия десктоп.

  • Стартирайте файла mbam-setup-2.1.8.1057.exe и следвайте указанията за да инсталирате програмата.
  • След като инсталацията приключи се уверете че сте сложили отметка пред:
  • Launch Malwarebytes Anti-Malware
  • Отметката активираща пробния 14 дневен период също е маркиран по-подразбиране. Ако не желаете да тествате защитата в реално време на програмата през следващите 14 дни тогава премахнете отметката. Т.е. премахнете първата отметка:

DkgJ7Zr.png

  • Натиснете бутона Finish.
  • Отидете до табът Settings > Detection and Protection > и под категорията Detection Options включете опцията "Scan for rootkits".
  • Отидете до табът Scan, сложете радио-бутона пред Threat Scan и след това натиснете бутона Scan Now >> . Ако е намерена актуализация тогава натиснете бутона Update Now.
  • Ще започне проверка за зловреден софтуер.
  • При някои инфекции можете да видите съобщението:
  • "Could not load DDA driver"
  • Натиснете "Yes" на това съобщение за да позволите драйвера да се зареди след рестарт.
  • Разрешете на компютъра да се рестартира и след това продължете с останалите инструкции.
  • След като проверката приключи натиснете бутона Apply Actions.
  • Изчакайте да се появи прозореца подканващ ви да рестартирате и след това натиснете бутона Yes.
  • След рестарта, когато се появи десктопа MBAM ще се зареди още веднъж.
  • Отидете то табът History > Application Logs.

65ZBqkR.jpg

  • Отворете рапорта с последната дата и час и натиснете бутона "Copy to Clipboard"
  • Сега вече поставете съдържанието на лог файла с клавишната комбинация Ctrl + V и го публикувайте в следващия си коментар.

 

СТЪПКА 3

 

1.Изтеглете Hitman Pro.

За 32-битова система - dEMD6.gif.
За 64-битова система - Download-button3.gif

2.Стартирайте програмата.
3.След като сте стартирали програмата като кликнете върху иконата 5vo5F.jpg и натиснете бутона „Напред“ като се съгласите с лицензионното споразумение (EULA).

4.Сложете отметка пред "Не, искам да завърша еднократно сканиране на компютъра".

5.Натиснете бутона „Напред“.

6.Програмата ще започне да сканира. Времето за сканиране е около 2 минути.

7.След завършване на сканирането от списъка с намерените неща (ако има такива) изберете Apply to all => Ignore.

8.Натиснете "Next" и след това натиснете "Изнеси резултата в XML file" и запазете лог файла на десктопа.

9.Архивирайте файла и го прикачете в следващия си коментар или копирайте съдържанието му в следващия си коментар.
 
Забележка: Ако няма падащо меню, където да изберете ignore както на снимката:
 
6-scanfin-choose.jpg
 
Тогава просто затворете програмата след края на проверката (без да премахвате нищо)...след това отворете C:\Programdata\HitmanPro\Logs, отворете и публикувайте съдържанието на лог файла в следващия си коментар.

Забележка: Папката C:\ProgramData е скрита и затова трябва да направите скритите файлове видими по-следния начин:

От My Computer => Tools => Folder Options => View:

Сложете отметка пред "Show hidden files, folders and drives"

и махнете отметката пред "Hide protected operating system files (recommended)".

Натиснете Apply.

Сега проверете за лог файла в папката C:\Programdata\HitmanPro\Logs и го прикачете в следващия си коментар. :)

 

СТЪПКА 4

 

emsisoft_emergency_kit.pnglogo.png

  • Моля изтеглете EmsisoftEmergencyKit, стартирайте exe файла и посочете къде да се разархивира програмата - например в (C:\EEK), натискайки бутона Extract.
  • Стартирайте иконата на файла Start Emsisoft Emergency Kit от десктопа за да стартирате приложението.
  • Натиснете бутона"Yes", когато бъдете подканени да обновите дефинициите на програмата.

EKK.gif

  • След като процеса по обновяването на дефинициите приключи натиснете бутона "Scan".
  • Натиснете бутона "Yes", когато бъдете попитани дали да програмата да включи засичането на потенциално нежелани приложения (Potentially Unwanted Applications).
  • Сега вече изберете бутона Custom Scan. Премахнете от списъка всички дялове без C:\ (т.е. нека да остане само дял C:\ в списъка).
  • Натиснете Next за да започне проверката.
  • Когато проверката приключи натиснете бутона View Report.
  • Копирайте съдържанието на лог файла в следващия си коментар.

 

СТЪПКА 5

Сканиране с SecurityCheck by glax24

  • Изтеглете SecurityCheck by glax24 от тук и запомнете инструмента на десктопа .
  • Стартирате програмата (ако използвате Windows XP) или стартирате с десен бутон на мишката от името на администратор (ако използвате Windows Vista/7/8/10)
  • Изчакайте да приключи сканирането.Ще се отвори в текстов файл с име SecurityCheck.txt. Копирайте съдържанието на  този файл  следващия си пост
  • Можете да намерите този файл в основната директория на системния диск в папка с име SecurityCheck, напр. C:\SecurityCheck\SecurityCheck.txt

 

  • Автор

здравейте,успях да приключа със сканирането ,макар и късно днес.Прилагам логовете,които по някаква причина част от тях са зачеркнати.При копиране и прилагане изглеждат по тоя начин,иначе са си нормални при мен.Ако трябва ще ги архивирам или ще ги прикача .

~ ZHPCleaner v2016.2.4.22 by Nicolas Coolman (2016/02/04)
~ Run by GERGANA (Administrator)  (07/02/2016 20:29:48)
~ Site : http://www.nicolascoolman.fr
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : Version OK
~ Type : Scan
~ Report : C:\Users\GERGANA\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\GERGANA\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
Windows 7 Ultimate, 64-bit Service Pack 1 (Build 7601)


---\\  Services (0)
~ No malicious or unnecessary items found.


---\\  Browser internet (0)
~ No malicious or unnecessary items found.


---\\  Hosts file (1)
~ The hosts file is legitimate (21)


---\\  Scheduled automatic tasks. (0)
~ No malicious or unnecessary items found.


---\\  Explorer ( File, Folder) (0)
~ No malicious or unnecessary items found.


---\\  Registry ( Key, Value, Data) (0)
~ No malicious or unnecessary items found.


---\\ Result of repair
~ Any repair made
~ Browser not found (Mozilla Firefox)


---\\ Statistics
~ Items scanned : 69233
~ Items found : 0
~ Items cancelled : 0
~ Items repaired : 0


~ End of search in 00h06mn22s
===================
ZHPCleaner-[R]-01032015-09_53_25.txt
ZHPCleaner--07022016-20_36_10.txt
 

 

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 7.2.2016 г.
Scan Time: 20:51 ч.
Logfile: mbam.txt
Administrator: Yes

Version: 2.2.0.1024
Malware Database: v2016.02.07.04
Rootkit Database: v2016.01.20.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: GERGANA

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 326898
Time Elapsed: 19 min, 45 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 1
PUP.Optional.MultiPlug.Gen, C:\ProgramData\{1dace886-e5fd-fbba-1dac-ce886e5fa21b}, Quarantined, [0dd393ca1a7fc86e3974b30fb152ed13], 

Files: 4
PUP.Optional.MultiPlug, C:\ProgramData\{1dace886-e5fd-fbba-1dac-ce886e5fa21b}\download.exe, Quarantined, [954bf8655b3ea5918e9838faa25f9967], 
PUP.Optional.MultiPlug.Gen, C:\ProgramData\{1dace886-e5fd-fbba-1dac-ce886e5fa21b}\download.dat, Quarantined, [0dd393ca1a7fc86e3974b30fb152ed13], 
PUP.Optional.MultiPlug.Gen, C:\ProgramData\{1dace886-e5fd-fbba-1dac-ce886e5fa21b}\1242fe3c9df0ddf, Quarantined, [0dd393ca1a7fc86e3974b30fb152ed13], 
PUP.Optional.MultiPlug.Gen, C:\ProgramData\{1dace886-e5fd-fbba-1dac-ce886e5fa21b}\ccd989b6ee0bea0b, Quarantined, [0dd393ca1a7fc86e3974b30fb152ed13], 

Physical Sectors: 0
(No malicious items detected)


(end)

 

 


	HitmanPro 3.7.12.253

	www.hitmanpro.com


   Computer name . . . . : GERGANA-PC
   Windows . . . . . . . : 6.1.1.7601.X64/2
   User name . . . . . . : GERGANA-PC\GERGANA
   UAC . . . . . . . . . : Enabled
   License . . . . . . . : Free

   Scan date . . . . . . : 2016-02-07 21:24:31
   Scan mode . . . . . . : Normal
   Scan duration . . . . : 3m 55s
   Disk access mode  . . : Direct disk access (SRB)
   Cloud . . . . . . . . : Internet
   Reboot  . . . . . . . : No

   Threats . . . . . . . : 0
   Traces  . . . . . . . : 3

   Objects scanned . . . : 1 147 032
   Files scanned . . . . : 17 024
   Remnants scanned  . . : 143 013 files / 986 995 keys

Suspicious files ____________________________________________________________

   C:\Users\GERGANA\Desktop\FRST64.exe
      Size . . . . . . . : 2 370 560 bytes
      Age  . . . . . . . : 5.1 days (2016-02-02 19:56:51)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 329DE119D3FD38387AA31C04A3C649587B579C89467D26DA5BA601346994BB87
      Needs elevation  . : Yes
      Fuzzy  . . . . . . : 24.0
         Program has no publisher information but prompts the user for permission elevation.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Time indicates that the file appeared recently on this computer.
      References
         HKU\S-1-5-21-2308581884-3569660230-120424562-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\C:\Users\GERGANA\Desktop\FRST64.exe
      Forensic Cluster
          0.0s C:\Users\GERGANA\Desktop\FRST64.exe
         28.6s C:\Users\GERGANA\Desktop\FRST.txt


Cookies _____________________________________________________________________

   C:\Users\GERGANA\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.kaldata.com



 

 

Emsisoft Emergency Kit - Version 11.0
Last update: 7.2.2016 г. 22:14:42
User account: GERGANA-PC\GERGANA

Scan settings:

Scan type: Custom Scan
Objects: Rootkits, Memory, Traces, C:\

Detect PUPs: On
Scan archives: On
ADS Scan: On
File extension filter: Off
Advanced caching: On
Direct disk access: Off

Scan start:    7.2.2016 г. 22:15:46
Value: HKEY_USERS\S-1-5-21-2308581884-3569660230-120424562-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLETASKMGR     detected: Setting.DisableTaskMgr (A)
Value: HKEY_USERS\S-1-5-21-2308581884-3569660230-120424562-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLEREGISTRYTOOLS     detected: Setting.DisableRegistryTools (A)

Scanned    170801
Found    2

Scan end:    7.2.2016 г. 22:37:18
Scan time:    0:21:32
 

SecurityCheck by glax24 & Severnyj v.1.4.0.35 [23.01.16]
WebSite: www.safezone.cc
DateLog: 07.02.2016 22:40:49
Path starting: C:\Users\GERGANA\AppData\Local\Temp\SecurityCheck\SecurityCheck.exe
Log directory: C:\SecurityCheck\
IsAdmin: True
User: GERGANA
VersionXML: 2.40is-05.02.2016
___________________________________________________________________________

Windows 7(6.1.7601) Service Pack 1 (x64) Ultimate Lang: 0402
Installation date OS: 11.12.2013 09:35:16
LicenseStatus: Windows(R) 7, Ultimate edition The machine is permanently activated.
Boot Mode: Normal
Default Browser: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
SystemDrive: C: FS: [NTFS] Capacity: [244 Gb] Used: [33.3 Gb] Free: [210.7 Gb]
------------------------------- [ Windows ] -------------------------------
Internet Explorer 11.0.9600.17239 Warning! Download Update
Online installation. Last version available when Windows update is enabled throught the Internet.
User Account Control enabled
Automatic Updates disabled
Date install updates: 2014-08-21 13:03:14
Windows Update (wuauserv) - The service is running
Security Center (wscsvc) - The service is running
Remote Registry (RemoteRegistry) - The service has stopped
SSDP Discovery (SSDPSRV) - The service is running
Remote Desktop Services (TermService) - The service has stopped
Windows Remote Management (WS-Management) (WinRM) - The service has stopped
---------------------------- [ Antivirus_WMI ] ----------------------------
Panda Free Antivirus (enabled)
---------------------------- [ Firewall_WMI ] -----------------------------
Panda Firewall
--------------------------- [ AntiSpyware_WMI ] ---------------------------
Panda Free Antivirus (enabled)
Windows Defender (enabled and out of date)
---------------------- [ AntiVirusFirewallInstall ] -----------------------
Panda Free Antivirus v.8.04.00.0000
-------------------------- [ SecurityUtilities ] --------------------------
Malwarebytes Anti-Malware version 2.2.0.1024 v.2.2.0.1024
--------------------------- [ OtherUtilities ] ----------------------------
WinRAR archiver
--------------------------------- [ IM ] ----------------------------------
Skype™ 7.10 v.7.10.101 Warning! Download Update
^Optional update.^
--------------------------------- [ P2P ] ---------------------------------
µTorrent v.3.4.2.33394 Warning! P2P-client.
--------------------------- [ AdobeProduction ] ---------------------------
Adobe Flash Player 11 ActiveX v.11.9.900.170 Warning! Download Update
Adobe Reader X (10.1.3) v.10.1.3 Warning! Download Update
Uninstall old version and install new one.
------------------------------- [ Browser ] -------------------------------
Google Chrome v.48.0.2564.103
Opera Stable 35.0.2066.37 v.35.0.2066.37
--------------------------- [ RunningProcess ] ----------------------------
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe v.48.0.2564.103
C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe v.4.0.0.646
C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe v.4.0.0.785
C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe v.4.0.0.637
C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe v.1.3.5.0
---------------------------- [ UnwantedApps ] -----------------------------
Skype Click to Call v.8.0.0.9103 Warning! Browser's toolbar. It can slow down the working of your browser and have violation privacy problems.
----------------------------- [ End of Log ] ------------------------------
 

 

mbam.txt

scan_160207-221546.txt

SecurityCheck.txt

HitmanPro_20160207_2130.log

Редактирано от мирослав24 (преглед на промените)

Обновете следния софтуер:

Цитат

Internet Explorer 11.0.9600.17239 Warning! Download Update
Online installation. Last version available when Windows update is enabled throught the Internet.

Adobe Flash Player 11 ActiveX v.11.9.900.170 Warning! Download Update
Adobe Reader X (10.1.3) v.10.1.3 Warning! Download Update
Uninstall old version and install new one.

Skype™ 7.10 v.7.10.101 Warning! Download Update
^Optional update.^

Деинсталирайте по ваше желание:

Цитат

Skype Click to Call v.8.0.0.9103

Иначе дневниците са чисти ..Как е системата ви след процедурите до тук..? Някакви проблеми..?

  • Автор

проблеми не виждам,спряха да се зареждат нови страници при отваряне на браузъра.Сега ще обновя посочените програми.Тези ключове намерени от Емисофт, имали ли са отношение към натрапения софтуер?

Value: HKEY_USERS\S-1-5-21-2308581884-3569660230-120424562-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLETASKMGR     detected: Setting.DisableTaskMgr (A)
Value: HKEY_USERS\S-1-5-21-2308581884-3569660230-120424562-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLEREGISTRYTOOLS     detected: Setting.DisableRegistryTools (A)

  • Автор

Благодаря за обърнатото внимание,ще прочета темата.Ако сее приключили с моята тема да изтривам ли ползваните инструменти?

icon_arrow.gif Изтеглете DelFix и го стартирайте. Сложете отметка пред:

  • Remove disinfection tools
  • Purge system restore

delfix.JPG
 
..и след това натиснете бутона Run

  • След като операцията е завърши,ще се създаде дневник
  • Копирате го и го поставите в следващия си отговор

Инструмента ще се самоизтрие след като приключи своята задача!

Ако има нещо което използвахме в лечението до тук и не се е премахнало след последните инструкции го премахнете ръчно ,по стандартните методи..!

 

i_arrow-r.gif Препоръчвам програмата Malwarebytes' Anti-Malware да остане на вашия компютър и периодично да сканирате системата си с нея (поне един -два пъти в седмицата),като не забравяйте да обновите дефинициите и преди всяко сканиране..!Напомням че това не е антивирусна програма а едно изключително добро допълнение към нея..!

 

112_forum_new.gif Малко превенции:
 
Винаги  поддържайте антивирусната си програма  с актуални дефиниции и  сканирайте с нея редовно.Само ще добавя никога да не разчитате само на  AV програма (ако си изберете безплатен вариант) ,добавете задължително и качествен HIPS базиран софтуер... COMODO, PrivateFirewall, ...What is Host Intrusion Prevention System (HIPS) and how does it work? .Справка: Сигурност и антивирусна защита
 
Забележка: Трябва да имате само една антивирусна инсталиран в даден момент. Ако имате повече от една антивирусна програма е вероятно да предизвика конфликти и може да намали общата защита, както и нарушаване на работата на вашия компютър.
 

icon_arrow.gif Още няколко програмки по мое мнение задължителни за всеки компютър:
 
- CryptoPrevent - за защита срещу CryptoLocker и подобни заплахи Имайте предвид, че ако изберете високо ниво на защита в CryptoPrevent след това можете да срещнете някои проблеми с инсталираните приложения. Може да се наложи да се намали нивото на защита, ако се натъкнете на подобни проблеми или да добавите вписванията към белия списък:
 
mtBkCIZ.jpg
 
 
- Unchecky - която автоматично ще премахва всички нежелани допълнения  по време на инсталирането на софтуера. Това помага за предотвратяване на инсталиране на зловреден код.
 
 
- Malwarebytes Anti-Exploit - за информация  MBAE (Malwarebytes Anti-Exploit) vs All EKs (Exploit Kits)
 
screenshot_2014-04-29_004.png

 

- McShield - за предотвратяване на инфекции, разпространявани чрез сменяеми носители

1.JPG

 

Съвети за сигурност - силно препоръчително четене:

 

icon_arrow.gif Едно от важните неща са MICROSOFT UPDATES. Чрез тях можете да получите всички критични актуализации за вашата операционна система и Internet Explorer. Поддържането на вашата операционна система и браузър с актуални ъпдейти, ще помогне да  направи системата по-малко податлива на атаки от троянски коне и вируси. Освен това зловредния софтуер се създава почти всеки ден. Много от тези заплахи, са насочени към уязвими места във вашия  софтуер. Софтуерните компании редовно публикуват актуализации, които определят тези уязвимости.За да останете защитени, трябва да актуализирате редовно целия  си софтуер. Основно внимание на следните програми:

  • Adobe Reader;
  • Adobe Flash Player;
  • Sun Java;
  • Apple QuickTime;
  • Базите и модулите на антивирусните програми
  • наличните браузъри  - обновени и с със задължителни следните аддони:

 

- За Firefox, използвайте NoScript , Adblock , Web Of Trust
- За Chrome използвайте  ScriptSafe ,Adblock Plus for Chrome, WOT (Web от Trust)

 

Прверявайте вашата система за актуални обновления и уязвимости с помощта на следните програми:

 

Ако нямате други проблеми да приключваме...Маркирам случая за "Решен"...! Пожелавам лека вечер и безопасен интернет..! :)

  • Автор

Благодарен съм за помощта от ваша страна,радвам се че проблема ми се реши леко и не ви затрудних с него.Успехи в борбата ви със зловредните гадинки :)

# DelFix v1.011 - Logfile created 08/02/2016 at 18:55:57
# Updated 18/08/2015 by Xplode
# Username : GERGANA - GERGANA-PC
# Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)

~ Removing disinfection tools ...

Deleted : C:\FRST
Deleted : C:\AdwCleaner
Deleted : C:\SecurityCheck
Deleted : C:\Users\GERGANA\Desktop\Addition.txt
Deleted : C:\Users\GERGANA\Desktop\AdwCleaner[S1].txt
Deleted : C:\Users\GERGANA\Desktop\adwcleaner_5.032.exe
Deleted : C:\Users\GERGANA\Desktop\Fixlog.txt
Deleted : C:\Users\GERGANA\Desktop\FRST.txt
Deleted : C:\Users\GERGANA\Desktop\FRST64.exe
Deleted : C:\Users\GERGANA\Desktop\JRT.exe
Deleted : C:\Users\GERGANA\Desktop\JRT.txt
Deleted : C:\Users\GERGANA\Desktop\SecurityCheck.exe
Deleted : C:\Users\GERGANA\Desktop\SecurityCheck.txt
Deleted : C:\Users\GERGANA\Desktop\SecurityCheck1.txt
Deleted : C:\Users\GERGANA\Desktop\ZHPCleaner.exe
Deleted : C:\Users\GERGANA\Desktop\ZHPCleaner.lnk
Deleted : C:\Users\GERGANA\Desktop\ZHPCleaner.txt

~ Creating registry backup ... OK

~ Cleaning system restore ...

Deleted : RP #19 [Windows Update | 02/08/2016 00:10:53]
Deleted : RP #20 [Removed Skype Click to Call | 02/08/2016 16:22:36]

New restore point created !

~ Resetting system settings ... OK

########## - EOF - ##########
 

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.