Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Постоянно изскачащи реклами, странници и т.н. Използвам Google Chrome и Internet Exploler.

Featured Replies

Здравейте, имам проблем от доста време, изскачат ми много реклами , странници без съм ги отварял и това е постоянно. Не мога свободно да стоя в интернет без да ми се отвари някаква страница. 
Имам компакт диск за моята операционна система. 
Поздрави. :)

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 21-08-2016 01
Ran by Genovi (administrator) on LENOVO (25-08-2016 14:43:36)
Running from C:\Users\Genovi\Desktop
Loaded Profiles: Genovi & UpdatusUser (Available Profiles: Genovi & UpdatusUser)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Lenovo.) C:\Windows\System32\ibmpmsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(BitTorrent Inc.) C:\Users\Genovi\AppData\Roaming\uTorrent\uTorrent.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(BitTorrent Inc.) C:\Users\Genovi\AppData\Roaming\uTorrent\updates\3.4.8_42449\utorrentie.exe
(BitTorrent Inc.) C:\Users\Genovi\AppData\Roaming\uTorrent\updates\3.4.8_42449\utorrentie.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Reimage®) C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe
(Reimage®) C:\Program Files\Reimage\Reimage Protector\ReiSystem.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2985712 2013-06-04] (Synaptics Incorporated)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [499608 2011-03-15] (Adobe Systems Incorporated)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [112512 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [IME14 CHT Setup] => C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE [109424 2010-01-21] (Microsoft Corporation)
HKLM\...\Run: [IME14 JPN Setup] => C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE [109424 2010-01-21] (Microsoft Corporation)
HKLM\...\Run: [IME14 KOR Setup] => C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE [109424 2010-01-21] (Microsoft Corporation)
HKLM\...\Run: [IME14 CHS Setup] => C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE [109424 2010-01-21] (Microsoft Corporation)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-26] (Intel Corporation)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5.5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [1523360 2011-01-12] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [IME14 CHT Setup] => C:\Program Files (x86)\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE [80240 2010-01-21] (Microsoft Corporation)
HKLM-x32\...\Run: [IME14 JPN Setup] => C:\Program Files (x86)\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE [80240 2010-01-21] (Microsoft Corporation)
HKLM-x32\...\Run: [IME14 KOR Setup] => C:\Program Files (x86)\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE [80240 2010-01-21] (Microsoft Corporation)
HKLM-x32\...\Run: [IME14 CHS Setup] => C:\Program Files (x86)\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE [80240 2010-01-21] (Microsoft Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9103976 2016-08-22] (AVAST Software)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3986698905-1256602312-1290690157-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-3986698905-1256602312-1290690157-1000\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1400232 2016-07-31] (Garmin Ltd. or its subsidiaries)
HKU\S-1-5-21-3986698905-1256602312-1290690157-1000\...\Run: [uTorrent] => C:\Users\Genovi\AppData\Roaming\uTorrent\uTorrent.exe [1972224 2016-08-10] (BitTorrent Inc.)
HKU\S-1-5-21-3986698905-1256602312-1290690157-1000\...\MountPoints2: H - H:\Lenovo_Suite.exe
HKU\S-1-5-21-3986698905-1256602312-1290690157-1000\...\MountPoints2: {1184f165-3463-11e5-9658-142d27ba3d24} - H:\Autorun.exe
HKU\S-1-5-21-3986698905-1256602312-1290690157-1000\...\MountPoints2: {735c4486-cadc-11e4-8641-142d27ba3d24} - F:\Lenovo_Suite.exe
HKU\S-1-5-21-3986698905-1256602312-1290690157-1000\...\MountPoints2: {894ba1fe-e57f-11e4-bd64-142d27ba3d24} - F:\Lenovo_Suite.exe
HKU\S-1-5-21-3986698905-1256602312-1290690157-1001\...\Run: [uTorrent] => C:\Users\Genovi\AppData\Roaming\uTorrent\uTorrent.exe [1972224 2016-08-10] (BitTorrent Inc.)
HKU\S-1-5-21-3986698905-1256602312-1290690157-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-3986698905-1256602312-1290690157-1001\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1400232 2016-07-31] (Garmin Ltd. or its subsidiaries)
HKU\S-1-5-21-3986698905-1256602312-1290690157-1001\...\MountPoints2: H - H:\Lenovo_Suite.exe
HKU\S-1-5-21-3986698905-1256602312-1290690157-1001\...\MountPoints2: {1184f165-3463-11e5-9658-142d27ba3d24} - H:\Autorun.exe
HKU\S-1-5-21-3986698905-1256602312-1290690157-1001\...\MountPoints2: {735c4486-cadc-11e4-8641-142d27ba3d24} - G:\Lenovo_Suite.exe
HKU\S-1-5-21-3986698905-1256602312-1290690157-1001\...\MountPoints2: {894ba1fe-e57f-11e4-bd64-142d27ba3d24} - H:\Lenovo_Suite.exe
HKU\S-1-5-18\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1400232 2016-07-31] (Garmin Ltd. or its subsidiaries)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [184048 2013-10-31] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [156256 2013-10-31] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-08-22] (AVAST Software)
Startup: C:\Users\Genovi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Deskjet 1510 series.lnk [2016-08-25]
ShortcutTarget: Monitor Ink Alerts - HP Deskjet 1510 series.lnk -> C:\Program Files\HP\HP Deskjet 1510 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 46.55.222.38 46.55.222.6
Tcpip\..\Interfaces\{2861413B-B2D6-4AEB-B16E-0C1CC6721565}: [DhcpNameServer] 46.55.222.38 46.55.222.6

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
SearchScopes: HKLM -> OldSearch URL = 
SearchScopes: HKU\S-1-5-21-3986698905-1256602312-1290690157-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-3986698905-1256602312-1290690157-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2011-02-12] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-08-22] (AVAST Software)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-08-22] (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2011-02-12] (Microsoft Corporation)
BHO-x32: ViewerHelper Class -> {78104A01-8E71-4F30-9A36-3793799615B4} -> C:\Program Files (x86)\Microsoft\Rights Management Add-on\RMAFilt.dll [2005-01-27] (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-08-22] (AVAST Software)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-08-22] (Google Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-08-22] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-08-22] (Google Inc.)
Toolbar: HKU\S-1-5-21-3986698905-1256602312-1290690157-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-08-22] (Google Inc.)
Handler-x32: rmh - {23C585BB-48FF-4865-8934-185F0A7EB84C} - C:\Program Files (x86)\Microsoft\Rights Management Add-on\RMAFilt.dll [2005-01-27] (Microsoft Corporation)
Filter-x32: application/msword - {DFF82902-0B96-3B98-6F62-D655E146A23A} - C:\Program Files (x86)\Microsoft\Rights Management Add-on\RMAFilt.dll [2005-01-27] (Microsoft Corporation)
Filter-x32: application/octet-stream - {F969FE8E-1937-45AD-AF42-8A4D11CBDC2A} - C:\Program Files (x86)\Microsoft\Rights Management Add-on\RMAFilt.dll [2005-01-27] (Microsoft Corporation)
Filter: application/vnd-backup-octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\system32\mscoree.dll [2010-11-21] (Microsoft Corporation)
Filter-x32: application/vnd-backup-octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\system32\mscoree.dll [2010-11-21] (Microsoft Corporation)
Filter: application/vnd-viewer - {CD4527E8-4FC7-48DB-9806-10537B501237} -  No File
Filter-x32: application/vnd.ms-excel - {DFF82902-0B96-3B98-6F62-D655E146A23A} - C:\Program Files (x86)\Microsoft\Rights Management Add-on\RMAFilt.dll [2005-01-27] (Microsoft Corporation)
Filter-x32: application/vnd.ms-powerpoint - {DFF82902-0B96-3B98-6F62-D655E146A23A} - C:\Program Files (x86)\Microsoft\Rights Management Add-on\RMAFilt.dll [2005-01-27] (Microsoft Corporation)
Filter-x32: application/x-microsoft-rpmsg-message - {DFF82902-0B96-3B98-6F62-D655E146A23A} - C:\Program Files (x86)\Microsoft\Rights Management Add-on\RMAFilt.dll [2005-01-27] (Microsoft Corporation)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1420982659&from=kmp&uid=ST1000LM024XHN-M101MBB_S30YJ9EF657940

FireFox:
========
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.5.29 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-07-03] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-07-03] (Intel Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-08-22] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-08-22] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-06-23] (Adobe Systems Inc.)
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-08-22]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-08-22]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\WebRep\FF

Chrome: 
=======
CHR HomePage: Default -> hxxp://google.bg/
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Profile: C:\Users\Genovi\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Презентации) - C:\Users\Genovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-02-08]
CHR Extension: (Google Документи) - C:\Users\Genovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-02-08]
CHR Extension: (Google Диск) - C:\Users\Genovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-02-08]
CHR Extension: (YouTube) - C:\Users\Genovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-02-08]
CHR Extension: (Adblock Plus) - C:\Users\Genovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-08-24]
CHR Extension: (Google Търсене) - C:\Users\Genovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-02-08]
CHR Extension: (Електронни таблици от Google) - C:\Users\Genovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-02-08]
CHR Extension: (Google Документи офлайн) - C:\Users\Genovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15]
CHR Extension: (AdBlock) - C:\Users\Genovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-08-24]
CHR Extension: (Online Anti-Virus Scan) - C:\Users\Genovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\klbfhfklbfkhmmmaijegeejbnbeknbph [2016-02-11]
CHR Extension: (Плащания в уеб магазина на Chrome) - C:\Users\Genovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR Extension: (Layout Saver) - C:\Users\Genovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojpdacbapfghmhnklegllclfcohofmdc [2016-08-16]
CHR Extension: (Gmail) - C:\Users\Genovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-02-08]
CHR Extension: (Chrome Media Router) - C:\Users\Genovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-08-21]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-09-02] (Apple Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-08-22] (AVAST Software)
S2 Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [809488 2016-07-31] (Garmin Ltd. or its subsidiaries)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 ImeDictUpdateService; C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE [83312 2010-01-21] (Microsoft Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-07-03] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-07-03] (Intel Corporation)
S2 KMService; C:\Windows\SysWOW64\srvany.exe [8192 2016-01-10] () [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
S2 MSSQLSERVER; C:\Program Files\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [62218696 2012-06-29] (Microsoft Corporation)
R2 ReimageRealTimeProtector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [7951728 2016-08-18] (Reimage®)
S4 SQLSERVERAGENT; C:\Program Files\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE [441288 2012-06-29] (Microsoft Corporation)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-08-22] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-08-22] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [108816 2016-08-22] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-08-22] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-08-22] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [969560 2016-08-22] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [513496 2016-08-22] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [163416 2016-08-22] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [292704 2016-08-22] (AVAST Software)
R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2015-01-11] (Disc Soft Ltd)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-08-25] (Malwarebytes)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64896 2016-03-10] (Malwarebytes Corporation)
S4 RsFx0153; C:\Windows\System32\DRIVERS\RsFx0153.sys [321992 2012-06-29] (Microsoft Corporation)
R3 RTWlanE; C:\Windows\System32\DRIVERS\rtwlane.sys [2974424 2013-08-02] (Realtek Semiconductor Corporation                           )
R3 SmbDrvI; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [33008 2013-06-04] (Synaptics Incorporated)
S3 tpflhlp; \??\C:\SWTOOLS\FLASH\j7uj57ww\tpflhlp.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 vm331avs; System32\Drivers\vm331avs.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-08-25 14:43 - 2016-08-25 14:43 - 00024893 _____ C:\Users\Genovi\Desktop\FRST.txt
2016-08-25 14:43 - 2016-08-25 14:43 - 00000000 ____D C:\FRST
2016-08-25 14:42 - 2016-08-25 14:42 - 02396672 _____ (Farbar) C:\Users\Genovi\Desktop\FRST64.exe
2016-08-25 14:19 - 2016-08-25 14:19 - 00004272 _____ C:\Windows\System32\Tasks\ReimageUpdater
2016-08-25 14:19 - 2016-08-25 14:19 - 00000000 ____D C:\ProgramData\Reimage Protector
2016-08-25 14:19 - 2016-08-25 14:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair
2016-08-25 14:19 - 2016-08-25 14:19 - 00000000 ____D C:\Program Files\Reimage
2016-08-25 14:18 - 2016-08-25 14:37 - 00000150 _____ C:\Windows\Reimage.ini
2016-08-25 14:18 - 2016-08-25 14:37 - 00000000 ____D C:\rei
2016-08-24 17:31 - 2016-08-22 18:17 - 00003118 _____ C:\Users\Genovi\Desktop\AdwCleaner[C0].txt
2016-08-24 17:31 - 2016-08-22 18:16 - 00003545 _____ C:\Users\Genovi\Desktop\AdwCleaner[S1].txt
2016-08-24 17:29 - 2016-08-24 17:29 - 00012654 _____ C:\Users\Genovi\Desktop\protection log.txt
2016-08-24 17:29 - 2016-08-24 17:29 - 00001061 _____ C:\Users\Genovi\Desktop\scan log.txt
2016-08-24 17:15 - 2016-08-24 17:15 - 00000080 _____ C:\Users\Genovi\AppData\Roaming\Microsoft\Windows\Start Menu\чTorrent.lnk
2016-08-24 17:01 - 2016-08-25 13:59 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-08-24 17:01 - 2016-08-24 17:15 - 00001100 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-08-24 17:01 - 2016-08-24 17:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-08-24 17:01 - 2016-08-24 17:01 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-08-24 17:01 - 2016-08-24 17:01 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-08-24 17:01 - 2016-03-10 14:09 - 00064896 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2016-08-24 17:01 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-08-24 17:01 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2016-08-24 16:58 - 2016-08-24 16:59 - 22851472 _____ (Malwarebytes ) C:\Users\Genovi\Desktop\mbam-setup-2.2.1.1043.exe
2016-08-22 18:53 - 2016-08-24 17:15 - 00002259 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-08-22 18:53 - 2016-08-24 17:15 - 00002253 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-08-22 18:51 - 2016-08-22 18:51 - 00000000 ____D C:\Users\Genovi\AppData\Roaming\Google
2016-08-22 18:51 - 2016-07-22 14:48 - 06500888 _____ (Geek Uninstaller) C:\Users\Genovi\Desktop\geek.exe
2016-08-22 18:36 - 2016-08-22 18:36 - 00000000 ____D C:\Users\Genovi\Tracing
2016-08-22 18:35 - 2016-08-22 18:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2016-08-22 18:35 - 2016-08-22 18:35 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-08-22 18:30 - 2016-08-24 17:15 - 00001165 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2016-08-22 18:30 - 2016-08-22 18:30 - 00003886 _____ C:\Windows\System32\Tasks\SafeZone scheduled Autoupdate 1471879801
2016-08-22 18:29 - 2016-08-22 18:29 - 00000000 ____D C:\ProgramData\Google
2016-08-22 18:29 - 2016-08-22 18:29 - 00000000 ____D C:\Program Files\Google
2016-08-22 18:28 - 2016-08-25 14:41 - 00000998 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-08-22 18:28 - 2016-08-25 13:57 - 00000994 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-08-22 18:28 - 2016-08-22 18:36 - 00003994 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-08-22 18:28 - 2016-08-22 18:36 - 00003742 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2016-08-22 18:28 - 2016-08-22 18:28 - 00037144 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2016-08-22 18:27 - 2016-08-24 17:15 - 00001960 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2016-08-22 18:27 - 2016-08-22 18:27 - 00003922 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2016-08-22 18:27 - 2016-08-22 18:27 - 00000000 ____D C:\Windows\System32\Tasks\AVAST Software
2016-08-22 18:27 - 2016-08-22 18:27 - 00000000 ____D C:\Users\Genovi\AppData\Roaming\AVAST Software
2016-08-22 18:27 - 2016-08-22 18:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2016-08-22 18:27 - 2016-08-22 18:27 - 00000000 ____D C:\Program Files\Common Files\AV
2016-08-22 18:27 - 2016-08-22 18:26 - 00163416 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2016-08-22 18:26 - 2016-08-22 18:26 - 00992960 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2016-08-22 18:26 - 2016-08-22 18:26 - 00969560 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2016-08-22 18:26 - 2016-08-22 18:26 - 00921280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2016-08-22 18:26 - 2016-08-22 18:26 - 00513496 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2016-08-22 18:26 - 2016-08-22 18:26 - 00391496 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2016-08-22 18:26 - 2016-08-22 18:26 - 00292704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2016-08-22 18:26 - 2016-08-22 18:26 - 00108816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2016-08-22 18:26 - 2016-08-22 18:26 - 00103064 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2016-08-22 18:26 - 2016-08-22 18:26 - 00074544 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2016-08-22 18:26 - 2016-08-22 18:26 - 00053208 _____ (AVAST Software) C:\Windows\avastSS.scr
2016-08-22 18:26 - 2016-08-22 18:26 - 00037656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2016-08-22 18:25 - 2016-08-22 18:28 - 00000000 ____D C:\ProgramData\AVAST Software
2016-08-22 18:25 - 2016-08-22 18:28 - 00000000 ____D C:\Program Files\AVAST Software
2016-08-22 18:13 - 2016-08-22 18:17 - 00000000 ____D C:\AdwCleaner
2016-08-22 18:09 - 2016-08-22 18:13 - 00000000 ____D C:\Users\Genovi\AppData\Roaming\Geek Uninstaller
2016-08-13 15:06 - 2016-08-25 13:57 - 00000000 ____D C:\Users\Genovi\AppData\LocalLow\uTorrent
2016-08-06 17:16 - 2016-08-06 17:32 - 00000000 ____D C:\Users\Genovi\Desktop\Писта - пловдив
2016-08-05 14:39 - 2016-08-05 14:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-08-25 14:43 - 2015-01-11 16:20 - 00000000 ____D C:\Users\Genovi\AppData\Roaming\uTorrent
2016-08-25 14:27 - 2015-01-11 16:16 - 00000000 ____D C:\Users\Genovi\AppData\Local\Google
2016-08-25 14:13 - 2009-07-14 07:45 - 00026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-08-25 14:13 - 2009-07-14 07:45 - 00026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-08-25 13:57 - 2016-03-20 18:58 - 00000202 _____ C:\Windows\Tasks\AutoKMS.job
2016-08-25 13:57 - 2009-07-14 08:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-08-24 17:18 - 2016-03-20 18:58 - 00000202 _____ C:\Windows\Tasks\AutoKMSDaily.job
2016-08-24 17:15 - 2016-03-16 17:27 - 00000000 ____D C:\Program Files (x86)\EViews 8
2016-08-24 17:15 - 2015-12-13 17:47 - 00001202 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS5.1.lnk
2016-08-24 17:15 - 2015-12-13 17:47 - 00001150 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS5.1 (64 Bit).lnk
2016-08-24 17:15 - 2015-12-13 17:46 - 00001295 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Device Central CS5.5.lnk
2016-08-24 17:15 - 2015-12-13 17:45 - 00001543 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS5.5.lnk
2016-08-24 17:15 - 2015-12-13 17:45 - 00001396 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS5.5.lnk
2016-08-24 17:15 - 2015-12-13 17:44 - 00000985 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
2016-08-24 17:15 - 2015-06-23 15:01 - 00000000 ___RD C:\Users\Genovi\Desktop\Програми
2016-08-24 17:15 - 2015-06-23 15:00 - 00000000 ___RD C:\Users\Genovi\Desktop\Игри
2016-08-24 17:15 - 2015-03-07 10:35 - 00000000 ____D C:\Users\Genovi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2016-08-24 17:15 - 2015-01-21 22:30 - 00000631 _____ C:\Users\Genovi\Desktop\Роси.lnk
2016-08-24 17:15 - 2015-01-11 16:30 - 00002429 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2016-08-24 17:15 - 2015-01-11 15:28 - 00001447 _____ C:\Users\Genovi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-08-24 17:15 - 2015-01-11 15:28 - 00001413 _____ C:\Users\Genovi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2016-08-24 17:15 - 2015-01-11 15:15 - 00001333 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2016-08-24 17:15 - 2015-01-11 15:14 - 00001314 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2016-08-24 17:15 - 2009-07-14 08:01 - 00001282 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk
2016-08-24 17:15 - 2009-07-14 07:57 - 00001535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-08-24 17:15 - 2009-07-14 07:57 - 00001318 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
2016-08-24 17:15 - 2009-07-14 07:57 - 00001234 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
2016-08-24 17:15 - 2009-07-14 07:54 - 00001198 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
2016-08-24 17:15 - 2009-07-14 07:49 - 00001266 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk
2016-08-24 16:49 - 2016-03-20 18:58 - 00002740 _____ C:\Windows\System32\Tasks\AutoKMSDaily
2016-08-22 18:53 - 2015-01-11 16:16 - 00000000 ____D C:\Program Files (x86)\Google
2016-08-22 18:36 - 2015-01-11 16:22 - 00000000 ____D C:\Users\Genovi\AppData\Roaming\Skype
2016-08-22 18:36 - 2015-01-11 15:27 - 00000000 ____D C:\Users\Genovi
2016-08-22 18:35 - 2015-01-11 16:22 - 00000000 ____D C:\Users\Genovi\AppData\Local\Skype
2016-08-22 18:35 - 2015-01-11 16:22 - 00000000 ____D C:\ProgramData\Skype
2016-08-22 18:18 - 2015-06-11 11:18 - 00000670 __RSH C:\ProgramData\ntuser.pol
2016-08-13 16:21 - 2016-02-08 22:58 - 00000000 ___SD C:\Users\Genovi\AppData\LocalLow\Temp
2016-08-13 15:06 - 2015-01-11 15:42 - 00000000 ____D C:\Windows\SysWOW64\NV
2016-08-13 15:06 - 2015-01-11 15:42 - 00000000 ____D C:\Windows\system32\NV
2016-08-13 15:06 - 2015-01-11 15:41 - 00000000 ____D C:\ProgramData\NVIDIA
2016-08-12 23:07 - 2015-01-21 22:29 - 381391479 _____ C:\Windows\MEMORY.DMP
2016-08-12 23:07 - 2015-01-21 22:29 - 00000000 ____D C:\Windows\Minidump
2016-08-06 17:21 - 2009-07-14 08:13 - 00873744 _____ C:\Windows\system32\PerfStringBackup.INI
2016-08-06 17:21 - 2009-07-14 06:20 - 00000000 ____D C:\Windows\inf
2016-08-05 14:40 - 2015-10-20 22:32 - 00000000 ____D C:\ProgramData\Package Cache
2016-08-05 14:39 - 2015-10-20 22:32 - 00003554 _____ C:\Windows\System32\Tasks\GarminUpdaterTask
2016-08-05 14:39 - 2015-10-20 22:32 - 00000000 ____D C:\Program Files (x86)\Garmin

==================== Files in the root of some directories =======

2015-03-12 15:12 - 2015-03-12 15:12 - 0000057 _____ () C:\ProgramData\Ament.ini
2015-01-11 15:32 - 2015-01-11 15:32 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2015-09-01 15:49 - 2015-09-01 15:49 - 0000000 _____ () C:\ProgramData\temp

Some files in TEMP:
====================
C:\Users\Genovi\AppData\Local\Temp\AutoRun.exe
C:\Users\Genovi\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\Genovi\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpevgvfp.dll
C:\Users\Genovi\AppData\Local\Temp\EASOUNInstaller.exe
C:\Users\Genovi\AppData\Local\Temp\eauninstall.exe
C:\Users\Genovi\AppData\Local\Temp\FIFA 07_uninst.exe
C:\Users\Genovi\AppData\Local\Temp\GarminExpressInstaller.exe
C:\Users\Genovi\AppData\Local\Temp\libeay32.dll
C:\Users\Genovi\AppData\Local\Temp\msvcr120.dll
C:\Users\Genovi\AppData\Local\Temp\ose00000.exe
C:\Users\Genovi\AppData\Local\Temp\ose00001.exe
C:\Users\Genovi\AppData\Local\Temp\ose00002.exe
C:\Users\Genovi\AppData\Local\Temp\ose00005.exe
C:\Users\Genovi\AppData\Local\Temp\ReimagePackage.exe
C:\Users\Genovi\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Genovi\AppData\Local\Temp\SpotifyUninstall.exe
C:\Users\Genovi\AppData\Local\Temp\sqlite3.dll
C:\Users\Genovi\AppData\Local\Temp\sqlite3.exe
C:\Users\Genovi\AppData\Local\Temp\UmmyVideoDownloader.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-08-06 16:47

==================== End of FRST.txt ============================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 21-08-2016 01
Ran by Genovi (25-08-2016 14:45:36)
Running from C:\Users\Genovi\Desktop
Windows 7 Ultimate Service Pack 1 (X64) (2015-01-11 12:27:48)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3986698905-1256602312-1290690157-500 - Administrator - Disabled)
Genovi (S-1-5-21-3986698905-1256602312-1290690157-1000 - Administrator - Enabled) => C:\Users\Genovi
Guest (S-1-5-21-3986698905-1256602312-1290690157-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3986698905-1256602312-1290690157-1007 - Limited - Enabled)
UpdatusUser (S-1-5-21-3986698905-1256602312-1290690157-1001 - Limited - Enabled) => C:\Users\UpdatusUser

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avast Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-3986698905-1256602312-1290690157-1000\...\uTorrent) (Version: 3.4.8.42449 - BitTorrent Inc.)
µTorrent (HKU\S-1-5-21-3986698905-1256602312-1290690157-1001\...\uTorrent) (Version: 3.4.5.41712 - BitTorrent Inc.)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 2.6.0.19140 - Adobe Systems Incorporated)
Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.5.23 - Adobe Systems Incorporated.)
Adobe Photoshop CS5.1 (HKLM-x32\...\{9158FF30-78D7-40EF-B83E-451AC5334640}) (Version: 12.1 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.17) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.17 - Adobe Systems Incorporated)
ANT Drivers Installer x64 (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
Apple Application Support (64-bit) (HKLM\...\{1F72FDD5-A069-45B4-928F-D0F16492DC69}) (Version: 4.0.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{FD244E19-6EFE-4A2D-948A-0D45D4C168BE}) (Version: 9.0.0.26 - Apple Inc.)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 12.3.2280 - AVAST Software)
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.)
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
Elevated Installer (x32 Version: 4.1.25.0 - Garmin Ltd or its subsidiaries) Hidden
EViews 8 (HKLM-x32\...\InstallShield_{1D78E62C-B585-446A-8FC7-2754332C0521}) (Version: 8.00.0000 - IHS Global Inc.)
EViews 8 (x32 Version: 8.00.0000 - IHS Global Inc.) Hidden
Garmin Express (HKLM-x32\...\{686d881a-083e-4030-80db-52c493bf89d3}) (Version: 4.1.25.0 - Garmin Ltd or its subsidiaries)
Garmin Express (x32 Version: 4.1.25.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express Tray (x32 Version: 4.1.25.0 - Garmin Ltd or its subsidiaries) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 52.0.2743.116 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.7619.1252 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.21.169 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
HP Deskjet 1510 series Basic Device Software (HKLM\...\{D17E60E8-478A-4D4A-8147-21D481B5CA55}) (Version: 32.2.188.47710 - Hewlett-Packard Co.)
HP Deskjet 1510 series Help (HKLM-x32\...\{2E25FCEB-EFCB-4696-AA01-D3CBAC721831}) (Version: 30.0.0 - Hewlett Packard)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
IBM SPSS Statistics 23 (HKLM\...\{C3BA73A4-2A45-4036-8541-4F5F8146078B}) (Version: 23.0.0.0 - IBM Corp)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1011 - Intel Corporation)
Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: 1.0.0.36943 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.0.13.1402 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.18.10.3234 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 3.0.0.66956 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 2.5.0.19 - Intel Corporation)
KMPlayer (remove only) (HKLM-x32\...\The KMPlayer) (Version: 3.9.1.131 - PandoraTV)
Lenovo Patch Utility (x32 Version: 1.3.2.6 - Lenovo Group Limited) Hidden
Lenovo Patch Utility 64 bit (Version: 1.3.2.6 - Lenovo Group Limited) Hidden
Lenovo Power Management Driver (HKLM\...\Power Management Driver) (Version: 1.67.07.06 - )
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2010 Service Pack 1 (SP1) (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{7BC9B5EB-125A-4E9B-97E1-8D85B5E960B8}) (Version:  - Microsoft)
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.6029.1000 - Microsoft Corporation)
Microsoft Office Proofing Tools Kit Compilation 2010 (HKLM\...\Office14.PROOFKIT) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 (64-bit) (HKLM\...\Microsoft SQL Server 2008 R2) (Version:  - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Native Client (HKLM\...\{79A2C6E8-C727-4D12-B4B3-19790C181DEA}) (Version: 10.52.4000.0 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Setup (English) (HKLM\...\{C3525BF7-3698-4CD3-A8C3-69BD6F57BA3B}) (Version: 10.52.4000.0 - Microsoft Corporation)
Microsoft SQL Server 2008 Setup Support Files  (HKLM\...\{B40EE88B-400A-4266-A17B-E3DE64E94431}) (Version: 10.1.2731.0 - Microsoft Corporation)
Microsoft SQL Server Browser (HKLM-x32\...\{BF9BF038-FE03-429D-9B26-2FA0FD756052}) (Version: 10.52.4000.0 - Microsoft Corporation)
Microsoft SQL Server Native Client (HKLM\...\{751EE164-9F12-4E57-ADB0-02D8F34A10AD}) (Version: 9.00.1399.06 - Microsoft Corporation)
Microsoft SQL Server VSS Writer (HKLM\...\{288D79EE-A2D1-42AF-9597-B0ADCC23A8ED}) (Version: 10.52.4000.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.40303 - Microsoft Corporation)
Need for Speed™ Most Wanted (HKLM-x32\...\{ADE91A13-434D-4229-00BC-182BAD607303}) (Version:  - )
NVIDIA Graphics Driver 327.62 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 327.62 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.13.0725 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0725 - NVIDIA Corporation)
NVIDIA Update 1.14.17 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.14.17 - NVIDIA Corporation)
OpenOffice.org 2.3 (HKLM-x32\...\{83C03FBE-4492-4133-BBAB-421CD88ADA32}) (Version: 2.3.9221 - OpenOffice.org)
PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden
PhotoScape (HKLM-x32\...\PhotoScape) (Version:  - )
Picture Collage Maker 4.1.2 (HKLM-x32\...\{D53599B0-AA76-4CC6-B9EF-CC2F27B56F24}_is1) (Version: 4.1.2 - PearlMountain Technology Co., Ltd)
Product Improvement Study for HP Deskjet 1510 series (HKLM\...\{35DB2630-846E-47C5-AF84-9D6AC3629F55}) (Version: 32.2.188.47710 - Hewlett-Packard Co.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.30161 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.50.1123.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7005 - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver (HKLM-x32\...\{9DAABC60-A5EF-41FF-B2B9-17329590CD5}) (Version: 1.00.0225 - REALTEK Semiconductor Corp.)
Reimage Repair (HKLM\...\Reimage Repair) (Version: 1.8.4.2 - Reimage) <==== ATTENTION
Rights Management Add-on for Internet Explorer (HKLM-x32\...\{3505E1E2-8127-4681-A3EC-F9B5CAAA07C9}) (Version: 1.0.1.0000 - Microsoft)
SafeZone Stable 1.51.2220.53 (x32 Version: 1.51.2220.53 - Avast Software) Hidden
Service Pack 2 for SQL Server 2008 R2 (KB2630458) (64-bit) (HKLM\...\KB2630458) (Version: 10.52.4000.0 - Microsoft Corporation)
Skype™ 7.26 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.26.101 - Skype Technologies S.A.)
SQL Server 2008 R2 SP2 Common Files (Version: 10.52.4000.0 - Microsoft Corporation) Hidden
SQL Server 2008 R2 SP2 Database Engine Services (Version: 10.52.4000.0 - Microsoft Corporation) Hidden
SQL Server 2008 R2 SP2 Database Engine Shared (Version: 10.52.4000.0 - Microsoft Corporation) Hidden
Sql Server Customer Experience Improvement Program (Version: 10.50.1600.1 - Microsoft Corporation) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.6.4.13 - Synaptics Incorporated)
Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
WinRAR 5.20 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.20.0 - win.rar GmbH)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3986698905-1256602312-1290690157-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Genovi\AppData\Roaming\Dropbox\bin\Dropbox.exe /autoplay => No File

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {128FF04C-B222-464E-B693-75C266D9170B} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2013-07-26] (Realtek Semiconductor)
Task: {19704BED-D84C-4864-97BA-C2E13C95F84B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-08-22] (Google Inc.)
Task: {2674FF8E-3311-4470-BA1E-D3131E8CDE39} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [2016-07-31] ()
Task: {3577B8E1-250C-4135-9903-6A1C8873A391} - System32\Tasks\SafeZone scheduled Autoupdate 1471879801 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-08-09] (Avast Software)
Task: {539EFEF1-B87D-4D91-8FEF-87CACEFBB06B} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS.exe
Task: {7CB94EBD-1CF1-45DC-B94F-92066C51F089} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-08-22] (Google Inc.)
Task: {7F38D0B1-DA4E-4AFE-9C5B-D8917A4E57C3} - System32\Tasks\{850DDB30-EF7A-4AE4-9D86-611F3ED065EE} => Chrome.exe hxxp://ui.skype.com/ui/0/7.3.0.101/bg/abandoninstall?page=tsProgressBar
Task: {83322B78-226E-4D11-87BF-B72F9C6C0458} - System32\Tasks\AutoKMSDaily => C:\Windows\AutoKMS.exe
Task: {870B4C36-4F91-427A-8CC2-B4B99BBE20CF} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2013-03-07] (Intel Corporation)
Task: {87AE16C4-8EF4-4ADC-9009-F6CDAAB8EFA6} - System32\Tasks\ReimageUpdater => C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [2016-08-18] (Reimage®) <==== ATTENTION
Task: {98BA7BD3-72F6-43BC-9BC8-EFED4C17B51F} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2013-03-07] (Intel Corporation)
Task: {B3B1FBD1-D8BB-4D0D-9999-86088465A945} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-06-25] (Adobe Systems Incorporated)
Task: {CED0E0F7-8B3A-4AA1-B35A-7EE4A5529E5F} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-08-22] (AVAST Software)
Task: {CFE7D0AE-D58E-4B6A-BEAF-C90182A12C98} - System32\Tasks\AdobeAAMUpdater-1.0-Lenovo-Genovi => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2011-03-15] (Adobe Systems Incorporated)
Task: {E52ABFEE-E013-40EB-9F4F-5AD2990CA4BD} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2016-08-22] (AVAST Software)
Task: {F067214B-F2C5-4C51-B33E-98EA23F32248} - System32\Tasks\HPCustParticipation HP Deskjet 1510 series => C:\Program Files\HP\HP Deskjet 1510 series\Bin\HPCustPartic.exe [2014-03-06] (Hewlett-Packard Co.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\AutoKMS.job => C:\Windows\AutoKMS.exe
Task: C:\Windows\Tasks\AutoKMSDaily.job => C:\Windows\AutoKMS.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

Shortcut: C:\Users\Genovi\AppData\Local\Microsoft\Windows\GameExplorer\{50C3471D-5DF4-4E58-BE33-5E28723D5091}\SupportTasks\1\Support.lnk -> hxxp://support.ea.com/
Shortcut: C:\Users\Genovi\AppData\Local\Microsoft\Windows\GameExplorer\{50C3471D-5DF4-4E58-BE33-5E28723D5091}\SupportTasks\0\More Games from Microsoft.lnk -> hxxp://www.fifa07.ea.com/

ShortcutWithArgument: C:\Users\Genovi\Desktop\Програми\Стартов панел с приложения за Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --show-app-list
ShortcutWithArgument: C:\Users\Genovi\AppData\Local\Google\Chrome\User Data\Стартов панел с приложения за Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --show-app-list

==================== Loaded Modules (Whitelisted) ==============

2015-01-11 15:41 - 2013-10-29 02:38 - 00097568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2015-09-23 16:47 - 2015-09-23 16:47 - 00085800 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-09-23 16:47 - 2015-09-23 16:47 - 01328912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2015-01-11 15:41 - 2013-10-31 16:13 - 00013088 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll
2011-03-17 01:07 - 2011-03-17 01:07 - 04297568 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 16:23 - 2010-10-20 16:23 - 08801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2016-08-22 18:26 - 2016-08-22 18:26 - 00169064 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2016-08-24 16:48 - 2016-08-24 16:48 - 03016192 _____ () C:\Program Files\AVAST Software\Avast\defs\16082400\algo.dll
2016-08-22 18:26 - 2016-08-22 18:26 - 00482928 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2016-08-22 18:26 - 2016-08-22 18:26 - 48936448 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2011-03-17 01:11 - 2011-03-17 01:11 - 04297568 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 16:45 - 2010-10-20 16:45 - 08801120 _____ () C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2015-01-11 15:35 - 2013-07-03 11:40 - 01199576 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2016-08-22 18:53 - 2016-08-03 03:24 - 01771336 _____ () C:\Program Files (x86)\Google\Chrome\Application\52.0.2743.116\libglesv2.dll
2016-08-22 18:53 - 2016-08-03 03:23 - 00094024 _____ () C:\Program Files (x86)\Google\Chrome\Application\52.0.2743.116\libegl.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 05:34 - 2009-06-11 00:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3986698905-1256602312-1290690157-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Genovi\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 46.55.222.38 - 46.55.222.6
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{57EF499B-6697-44E4-88B6-F37B4256793A}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{90564E8F-49B7-4C6A-8E6F-52E391F1896A}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{D9DEF69F-CB83-4D8D-8551-C6A4955DA180}] => (Allow) C:\Users\Genovi\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{A4EF9EA6-1C3F-44BD-A1B6-81608EA00BA5}] => (Allow) C:\Users\Genovi\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{A29938D3-6644-4889-9CD5-A426FACC7CD2}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [TCP Query User{D64A55D6-5186-4ABF-827B-63BA942C1416}C:\program files (x86)\ea games\need for speed most wanted\speed.exe] => (Block) C:\program files (x86)\ea games\need for speed most wanted\speed.exe
FirewallRules: [UDP Query User{C5E7F432-B1AA-4BD5-9771-3FE882CB37B5}C:\program files (x86)\ea games\need for speed most wanted\speed.exe] => (Block) C:\program files (x86)\ea games\need for speed most wanted\speed.exe
FirewallRules: [TCP Query User{132EB091-8E0E-4C41-A202-C851FF3A1B31}C:\program files (x86)\fifa 14\game\fifa14.exe] => (Allow) C:\program files (x86)\fifa 14\game\fifa14.exe
FirewallRules: [UDP Query User{AE2B9CD1-38F7-4064-88DB-48D7DEEE2F56}C:\program files (x86)\fifa 14\game\fifa14.exe] => (Allow) C:\program files (x86)\fifa 14\game\fifa14.exe
FirewallRules: [{DCE6B7F9-B33E-4A05-82EF-748693272639}] => (Allow) C:\Program Files\HP\HP Deskjet 1510 series\Bin\USBSetup.exe
FirewallRules: [{EB792C4F-6206-4994-8FB9-D8FA27D07F56}] => (Allow) C:\Program Files\HP\HP Deskjet 1510 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{E69600EC-2F37-4A38-9E65-EDAF4CBC0E05}] => (Allow) LPort=1433
FirewallRules: [TCP Query User{76B89CD8-95A7-4DCE-A775-CB59C382F3E8}C:\program files (x86)\connectify\connectify.exe] => (Allow) C:\program files (x86)\connectify\connectify.exe
FirewallRules: [UDP Query User{B94E21FA-6321-4EC8-8C3F-62334E43856D}C:\program files (x86)\connectify\connectify.exe] => (Allow) C:\program files (x86)\connectify\connectify.exe
FirewallRules: [TCP Query User{7AB2541D-F9E4-4DEB-9580-6A5707E3DDA1}C:\program files (x86)\fifa 14\game\fifa14.exe] => (Block) C:\program files (x86)\fifa 14\game\fifa14.exe
FirewallRules: [UDP Query User{73CF5938-17E3-42CC-BF62-A5816ACA6D83}C:\program files (x86)\fifa 14\game\fifa14.exe] => (Block) C:\program files (x86)\fifa 14\game\fifa14.exe
FirewallRules: [{611D7EAD-6717-4811-967C-0B59B3A82E7B}] => (Allow) C:\Program Files (x86)\SpringFiles\SpringFiles.exe
FirewallRules: [{09D76DAB-22C6-4E71-8E02-06294F69D432}] => (Allow) C:\Program Files (x86)\SpringFiles\SpringFiles.exe
FirewallRules: [{6CF1B9B1-471B-434E-A616-1479E22B9329}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\23\stats.com
FirewallRules: [{8FF4AB06-AEB5-4C05-AD99-35F0672DB517}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\23\WinWrapIDE.exe
FirewallRules: [{6121FB7C-2FCD-4D0F-9E3C-BBF856AEAC4D}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\23\stats.exe
FirewallRules: [{54EE832F-A1B7-4D47-9F41-932405C35530}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\23\stats.com
FirewallRules: [{E8D69806-245F-4912-B1C5-CD8A9391C8F5}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\23\WinWrapIDE.exe
FirewallRules: [{D0E29158-9130-49CB-9C4C-11CECAA481B7}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\23\stats.exe
FirewallRules: [TCP Query User{D9E2415D-0EFB-49DD-BD9D-2C858F13DB44}C:\program files\ibm\spss\statistics\23\stats.exe] => (Allow) C:\program files\ibm\spss\statistics\23\stats.exe
FirewallRules: [UDP Query User{D60F6001-689C-46DD-BA48-89FCBCBEAB7E}C:\program files\ibm\spss\statistics\23\stats.exe] => (Allow) C:\program files\ibm\spss\statistics\23\stats.exe
FirewallRules: [TCP Query User{F47B1F5D-5F3D-4F3C-A475-AD856A5315F3}C:\users\genovi\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\genovi\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{EEC88CD5-2132-4380-9150-89CFC9F79071}C:\users\genovi\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\genovi\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{F8687B8F-A28F-4749-B403-C9915D27D7B2}C:\users\genovi\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\genovi\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{E5C3CEB9-8136-4158-B8A3-C779C8BFB75F}C:\users\genovi\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\genovi\appdata\roaming\spotify\spotify.exe
FirewallRules: [{2343B0DE-A313-45E7-8B72-C401495487E5}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Restore Points =========================

06-07-2016 17:09:27 Scheduled Checkpoint
15-07-2016 16:32:30 Scheduled Checkpoint
22-07-2016 22:24:32 Scheduled Checkpoint
05-08-2016 14:38:43 Garmin Express
22-08-2016 18:32:20 ASU_MSI_TRAN

==================== Faulty Device Manager Devices =============

Name: 
Description: 
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (08/25/2016 01:58:26 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (08/25/2016 01:58:06 PM) (Source: MSSQLSERVER) (EventID: 9003) (User: )
Description: The log scan number (321:80:1) passed to log scan in database 'master' is not valid. This error may indicate data corruption or that the log file (.ldf) does not match the data file (.mdf). If this error occurred during replication, re-create the publication. Otherwise, restore from backup if the problem results in a failure during startup.

Error: (08/24/2016 05:19:28 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (08/24/2016 05:19:13 PM) (Source: MSSQLSERVER) (EventID: 9003) (User: )
Description: The log scan number (321:80:1) passed to log scan in database 'master' is not valid. This error may indicate data corruption or that the log file (.ldf) does not match the data file (.mdf). If this error occurred during replication, re-create the publication. Otherwise, restore from backup if the problem results in a failure during startup.

Error: (08/24/2016 04:48:39 PM) (Source: MSSQLSERVER) (EventID: 9003) (User: )
Description: The log scan number (321:80:1) passed to log scan in database 'master' is not valid. This error may indicate data corruption or that the log file (.ldf) does not match the data file (.mdf). If this error occurred during replication, re-create the publication. Otherwise, restore from backup if the problem results in a failure during startup.

Error: (08/24/2016 04:48:37 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (08/23/2016 06:02:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (08/23/2016 06:02:38 PM) (Source: MSSQLSERVER) (EventID: 9003) (User: )
Description: The log scan number (321:80:1) passed to log scan in database 'master' is not valid. This error may indicate data corruption or that the log file (.ldf) does not match the data file (.mdf). If this error occurred during replication, re-create the publication. Otherwise, restore from backup if the problem results in a failure during startup.

Error: (08/22/2016 06:40:34 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (08/22/2016 06:40:03 PM) (Source: MSSQLSERVER) (EventID: 9003) (User: )
Description: The log scan number (321:80:1) passed to log scan in database 'master' is not valid. This error may indicate data corruption or that the log file (.ldf) does not match the data file (.mdf). If this error occurred during replication, re-create the publication. Otherwise, restore from backup if the problem results in a failure during startup.


System errors:
=============
Error: (08/25/2016 01:58:06 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: The SQL Server (MSSQLSERVER) service terminated with service-specific error %%3417.

Error: (08/25/2016 01:57:59 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Garmin Device Interaction Service service failed to start due to the following error: 
%%1053 = The service did not respond to the start or control request in a timely fashion.

Error: (08/25/2016 01:57:59 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Garmin Device Interaction Service service to connect.

Error: (08/24/2016 05:19:14 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: The SQL Server (MSSQLSERVER) service terminated with service-specific error %%3417.

Error: (08/24/2016 05:18:49 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Garmin Device Interaction Service service failed to start due to the following error: 
%%1053 = The service did not respond to the start or control request in a timely fashion.

Error: (08/24/2016 05:18:49 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Garmin Device Interaction Service service to connect.

Error: (08/24/2016 04:48:40 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: The SQL Server (MSSQLSERVER) service terminated with service-specific error %%3417.

Error: (08/23/2016 06:02:38 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: The SQL Server (MSSQLSERVER) service terminated with service-specific error %%3417.

Error: (08/22/2016 06:40:03 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: The SQL Server (MSSQLSERVER) service terminated with service-specific error %%3417.

Error: (08/22/2016 06:18:12 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: The SQL Server (MSSQLSERVER) service terminated with service-specific error %%3417.


==================== Memory info =========================== 

Processor: Intel(R) Core(TM) i5-4200M CPU @ 2.50GHz
Percentage of memory in use: 74%
Total physical RAM: 3867.37 MB
Available physical RAM: 1004.19 MB
Total Virtual: 7732.93 MB
Available Virtual: 4682.19 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:147.31 GB) (Free:81.85 GB) NTFS
Drive d: (Local Dick) (Fixed) (Total:783.2 GB) (Free:622.65 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 6D4AA18E)
Partition 1: (Active) - (Size=1 GB) - (Type=0B)
Partition 2: (Not Active) - (Size=147.3 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=783.2 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

Здравейте ..! :)

Преди да започнем, моля, прочетете и искрено се надявам да следвате тези важни насоки, така че нещата да преминат  плавно и безпроблемно.

  • Инструкциите които ще Ви  давам, ще са само за вашия компютър и само за вашата система! Използването на тези инструкции на друг компютър могат да доведат до увреждане на този компютър и евентуално да го направи неизползваем !
  • Моля да следвате инструкциите ми в реда в който ги давам.
  • Трябва да имате права на администратор за този компютър,инструментите които ще използваме се стартират единствено от името на администратор.
  • Не стартирайте никакви други инструменти за премахване на зловреден софтуер, освен ако не сте инструктирани!
  • Не инсталирайте  софтуер (или хардуер) по време на процеса на почистване,както и не сваляйте или сканирай те с нищо  вашата система, защото към нея се  добавят повече елементи.Това прави анализа по-труден.
  • Вашите програми за сигурност могат да дават предупреждения за някои от инструментите които използваме.  Бъдете сигурни, всички връзки които давам за изтегляне на инструментите както и самите те, са безопасни.
  •  Моля,по възможност да отговаряте в темата  докато не ви потвърдя че тя е  " Чиста !"
  • Липсата на симптоми не означава, че всичко е чисто.

Моля, имайте предвид, че премахването на зловреден софтуер е непредвидим процес.. Аз ще се погрижа да ви  предложа начини на действие, които не могатда повредят вашия компютър. Въпреки това, за мен е невъзможно да  предвидя всички взаимодействия, които могат да се случат между софтуера на компютъра ви и инструментите които ще използваме , за да ви изчистим от инфекции, и в някои случаи аз не мога да  гарантирам целостта на вашата система. Възможно е, да възникнат ситуации, в които единственото решение е системата ви да се  форматира и да се преинсталира операционната система.Поради тази причина аз ви съветвам  да направите резервно копие на всички ваши лични файлове и папки, преди да започнем с почистването.

 

Изтеглете програмата GeekUninstaller и я запазете на десктопа.
Разархивирайте я и стартирайте файла geek.exe IxXO5oO.jpg  От списъка намерете и деинсталирайте всички програми които съм ви написал в карето:  Reimage-Repair

Цитат

Reimage Repair

Кликнете с десен бутон върху програмата и изберете Uninstall
 
XhV2QLa.png
 
 
След края на всяка деинсталацията ще се отвори прозорец подканващ ви да премахнете всички остатъци от програмата (ако има такива, ако няма този прозорец няма да се появи).Натиснете бутона Finish за да изтриете останките от програмата.

 

GfiJrQ9.png Malwarebytes Anti-Malware (MBAM)

Моля, изтеглете Malwarebytes Anti-Malware 2.2.0.1024 Final и я запазете на вашия десктоп.

  • Стартирайте файла mbam-setup-bc.1878-2.2.0.1024.exe и следвайте указанията за да инсталирате програмата.
  • След като инсталацията приключи се уверете че сте сложили отметка пред:
  • Launch Malwarebytes Anti-Malware
  • Отметката активираща пробния 14 дневен период също е маркиран по-подразбиране. Ако не желаете да тествате защитата в реално време на програмата през следващите 14 дни тогава премахнете отметката. Т.е. премахнете първата отметка:

DkgJ7Zr.png

  • Натиснете бутона Finish.
  • Отидете до табът Settings > Detection and Protection > и под категориятаDetection Options включете опцията "Scan for rootkits".
  • Отидете до табът Scan, сложете радио-бутона пред Threat Scan и след това натиснете бутона Scan Now >> . Ако е намерена актуализация тогава натиснете бутона Update Now.
  • Ще започне проверка за зловреден софтуер.
  • При някои инфекции можете да видите съобщението:
  • "Could not load DDA driver"
  • Натиснете "Yes" на това съобщение за да позволите драйвера да се зареди след рестарт.
  • Разрешете на компютъра да се рестартира и след това продължете с останалите инструкции.
  • След като проверката приключи натиснете бутона Apply Actions.
  • Изчакайте да се появи прозореца подканващ ви да рестартирате и след това натиснете бутона Yes.
  • След рестарта, когато се появи десктопа MBAM ще се зареди още веднъж.
  • Отидете то табът History > Application Logs.

65ZBqkR.jpg

  • Отворете рапорта с последната дата и час и натиснете бутона "Copy to Clipboard"
  • Сега вече поставете съдържанието на лог файла с клавишната комбинацияCtrl + V и го публикувайте в следващия си коментар.

 

BY4dvz9.png Сканиране с AdwCleaner

 
Моля, изтеглете и стартирайте програмата AdwCleaner (by Xplode):

  • Затворете всички стартирани програми и браузъри
  • Кликнете два пъти върху adwcleaner.exe за да стартирате инструмента.
  • Натиснете OK, за да потвърдите, че всички стартирани програми ще бъдат затворени.
  • Маркирайте Clean
  • Вашият компютър ще се рестартира автоматично. Текстовия файл ще се отвори след рестарта.
  • Моля, да публикувате съдържанието на този лог в отговора си

 

E3feWj5.png  Сканиране с Junkware Removal Tool
 
Моля, изтеглете Junkware Removal Tool (by Thisisu ) и запазете на вашия десктоп.

  • Спрете временно работата на защитните програми.
  • Стартирайте инструмента JRT.exe
  • Ще се отвори ДОС прозорец. Натиснете което и да е копче от клавиатурата.
  • Затворете излишните приложения и всички браузъри и изчакайте проверката да завърши.
  • Ще се появи лог файл (който можете да намерите и ръчно на десктопа с името JRT.txt).
  • Моля копирайте съдържанието на лог файла в следващия си пост.

 

122.jpg?1414578932  Моля, изтеглете  Check Browsers' LNK by Dragokas & regist

  • Запомнете архива на вашия декстоп,разархивирате.
  • Временно спрете вашия  антивирусен софтуер.
  • Стартирайте файла Check Browsers LNK.exe от името на администратор.
  • Изчакайте програмата да завърши работата си.Това може да отнеме до 5 минути. Моля бъдете търпеливи. След сканирането, отворете генерираната папка LOG и публикувайте отчета Check_Browsers_LNK.log, в следвашия си пост.

 

25.jpg?1426074241   Сканиране с SecurityCheck by glax24

  • Изтеглете SecurityCheck by glax24 от тук и запомнете инструмента на десктопа .
  • Стартирате програмата (ако използвате Windows XP) или стартирате с десен бутон на мишката от името на администратор (ако използватеWindows Vista/7/8/10)
  • Изчакайте да приключи сканирането.Ще се отвори в текстов файл с имеSecurityCheck.txt. Копирайте съдържанието на  този файл  следващия си пост
  • Можете да намерите този файл в основната директория на системния диск в папка с име SecurityCheck, напр. C:\SecurityCheck\SecurityCheck.txt

 

pfNZP4A.png  Дневници
 
В следващия си отговор, моля да включите следните дневници:

  • Дневник от Malwarebytes Anti -Malware
  • AdwCleaner.txt
  • JRT.txt
  • Check_Browsers_LNK.log
  • SecurityCheck.txt
  • Автор

Прилагам лог от Malwarebytes Anti-Malware 

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 25.8.2016 г.
Scan Time: 17:53 ч.
Logfile: log1.txt
Administrator: Yes

Version: 2.2.1.1043
Malware Database: v2016.08.25.06
Rootkit Database: v2016.08.15.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Genovi

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 344266
Time Elapsed: 21 min, 52 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)


Прилагам лог от adwcleaner_6.010 :


# AdwCleaner v6.010 - Logfile created 25/08/2016 at 18:21:24
# Updated on 12/08/2016 by ToolsLib
# Database : 2016-08-24.2 [Server]
# Operating System : Windows 7 Ultimate Service Pack 1 (X64)
# Username : Genovi - LENOVO
# Running from : C:\Users\Genovi\Desktop\adwcleaner_6.010.exe
# Mode: Clean
# Support : https://toolslib.net/forum

***** [ Services ] *****

[-] Service deleted: ReimageRealTimeProtector


***** [ Folders ] *****

[-] Folder deleted: C:\Program Files\Reimage
[-] Folder deleted: C:\ProgramData\Reimage Protector
[#] Folder deleted on reboot: C:\ProgramData\Application Data\Reimage Protector


***** [ Files ] *****

[-] File deleted: C:\Windows\Reimage.ini


***** [ DLL ] *****

***** [ WMI ] *****

***** [ Shortcuts ] *****

***** [ Scheduled Tasks ] *****

***** [ Registry ] *****

[-] Key deleted: HKLM\SOFTWARE\Classes\protector_dll.Protector
[-] Key deleted: HKLM\SOFTWARE\Classes\protector_dll.Protector.1
[-] Key deleted: HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib
[-] Key deleted: HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib.1
[-] Key deleted: HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine
[-] Key deleted: HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine.1
[-] Key deleted: [x64] HKLM\SOFTWARE\Classes\CLSID\{10ECCE17-29B5-4880-A8F5-EAD298611484}
[-] Key deleted: [x64] HKLM\SOFTWARE\Classes\CLSID\{801B440B-1EE3-49B0-B05D-2AB076D4E8CB}
[-] Key deleted: [x64] HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
[-] Key deleted: [x64] HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
[-] Key deleted: HKLM\SOFTWARE\Classes\AppID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
[-] Key deleted: HKLM\SOFTWARE\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}
[-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10ECCE17-29B5-4880-A8F5-EAD298611484}
[-] Key deleted: [x64] HKLM\SOFTWARE\Reimage
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Reimage Protector
[-] Key deleted: HKU\S-1-5-21-3986698905-1256602312-1290690157-1000\Software\Reimage
[-] Key deleted: HKU\S-1-5-21-3986698905-1256602312-1290690157-1000\Software\Local AppWizard-Generated Applications\Reimage - Windows Problem Relief.
[#] Key deleted on reboot: HKCU\Software\Reimage
[#] Key deleted on reboot: HKCU\Software\Local AppWizard-Generated Applications\Reimage - Windows Problem Relief.
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\bettersearch.tk
[-] Key deleted: HKLM\SOFTWARE\Classes\AppID\REI_AxControl.DLL


***** [ Web browsers ] *****

[-] [r] [Search Provider] Deleted: r
[-] [ask.com] [Search Provider] Deleted: ask.com
[-] [websearch.ask.com] [Search Provider] Deleted: websearch.ask.com
[-] [mystartsearch.com] [Search Provider] Deleted: mystartsearch.com
[-] [mystartsearch] [Search Provider] Deleted: mystartsearch
[-] [delta-search.com] [Search Provider] Deleted: delta-search.com
[-] [daemon-search.com] [Search Provider] Deleted: daemon-search.com
[-] [yahoo.com search] [Search Provider] Deleted: yahoo.com search
[-] [delta-homes] [Search Provider] Deleted: delta-homes
[-] [searchinterneat-a.akamaihd.net] [Search Provider] Deleted: searchinterneat-a.akamaihd.net
[-] [feed.sonic-search.com] [Search Provider] Deleted: feed.sonic-search.com


*************************

:: "Tracing" keys deleted
:: Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [3118 Bytes] - [22/08/2016 18:17:03]
C:\AdwCleaner\AdwCleaner[C2].txt - [3745 Bytes] - [25/08/2016 18:21:24]
C:\AdwCleaner\AdwCleaner[S0].txt - [6769 Bytes] - [22/08/2016 18:14:38]
C:\AdwCleaner\AdwCleaner[S1].txt - [3545 Bytes] - [22/08/2016 18:16:35]
C:\AdwCleaner\AdwCleaner[S2].txt - [4500 Bytes] - [25/08/2016 18:19:03]

########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt - [4037 Bytes] ##########


Прилагам лог от Junkware Removal Tool :

 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.7 (07.03.2016)
Operating System: Windows 7 Ultimate x64 
Ran by Genovi (Administrator) on зҐвў 25.08.2016 Ј. at 18:28:28,64
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


File System: 34 

Successfully deleted: C:\Users\Genovi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0892PWDX (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Genovi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Genovi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5I0GGROX (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Genovi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5YSI0ALY (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Genovi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8MDQCSJU (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Genovi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ADKWS6G3 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Genovi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DGFTRS3K (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Genovi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F3ZQJT55 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Genovi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I1XZRKEJ (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Genovi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IBSJ0XAY (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Genovi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JH6GITFR (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Genovi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KU1E4KPL (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Genovi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MGEMLAZ2 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Genovi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\REDU8Z31 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Genovi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCKSH3RR (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Genovi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VSSLW740 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Genovi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XE4TGK2H (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0892PWDX (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5I0GGROX (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5YSI0ALY (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8MDQCSJU (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ADKWS6G3 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DGFTRS3K (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F3ZQJT55 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I1XZRKEJ (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IBSJ0XAY (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JH6GITFR (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KU1E4KPL (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MGEMLAZ2 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\REDU8Z31 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCKSH3RR (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VSSLW740 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XE4TGK2H (Temporary Internet Files Folder) 

Registry: 0 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on зҐвў 25.08.2016 Ј. at 18:30:18,76
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Прилагам лог от Check Browse ' LNK By Dragokas and regist 

Check Browsers' LNK  by Alex Dragokas & regist                                 ver. 2.1.0.7 ( Beta )

OS:       x64 Windows 7 (Ultimate), 6.1.7601, Service Pack: 1        (SM=SingleUserTS, PT=Workstation)
Time:     25.08.2016 - 18:34
Language: OS: English (0x409). Display: English (0x409). Non-Unicode: Bulgarian (0x402). Codepage: OEM - c_866.nls (ok), ANSI - c_1251.nls (ok)
Elevated: Yes
User:     Genovi    (group: Administrator) on LENOVO


* Suspicious objects will be marked with prefix >>>

===========================================================================
              ((((((        BROWSER shortcuts        ))))))
===========================================================================

[__________________________  With arguments  _____________________________]

>>>  "C:\Users\Genovi\AppData\Local\Google\Chrome\User Data\Стартов панел с приложения за Chrome.lnk"          -> ["C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"  =>> --show-app-list]
>>>  "C:\Users\Genovi\Desktop\Програми\Стартов панел с приложения за Chrome.lnk"           -> ["C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"  =>> --show-app-list]

[=========================================================================]
                ((((((       Other shortcuts       ))))))
===========================================================================

[______________________  Suspicious ( low risk )  ________________________]

-[HTTP] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA GAMES\Need for Speed™ Most Wanted\Web.lnk"    -> ["(Internet Explorer)"  =>> hxxp://vvv.eagames.com/official/nfs/mostwanted/us/home.jsp]

[_______________________  Target does not exist  _________________________]

>>>  "C:\Users\Genovi\AppData\Local\Microsoft\Windows\GameExplorer\{50C3471D-5DF4-4E58-BE33-5E28723D5091}\PlayTasks\0\Play.lnk"    -> ["C:\Program Files (x86)\EA SPORTS\FIFA 07\fifa07.exe"]
>>>  "C:\Users\Genovi\Desktop\Игри\FIFA 07.lnk"    -> ["C:\Program Files (x86)\EA SPORTS\FIFA 07\fifa07.exe"]

[=========================================================================]
          ((((((        Other files and attributes       ))))))
===========================================================================

[__________________________   "Start menu"   ______________________________]

- "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EViews 8\EViews.8-patch (32-bit).exe"     (729088 bytes) (MD5: 94D3AD6BDDA749C7F46BECE0D4A8E398) -> (PE EXE)

[=========================================================================]
                 ((((((      Internet shortcuts       ))))))
===========================================================================

- "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA GAMES\Need for Speed™ Most Wanted\Check For Update.url"  ->  hxxp://patches.ea.com/nfs_mostwanted/home.html
- "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picture Collage Maker\Picture Collage Maker on the Web.url"  -> hxxp://vvv.picturecollagesoftware.com/

[_____________________________  Favorites  _______________________________]

- "C:\Users\Genovi\Favorites\Links\www.abv.bg.url"  ->                hxxp://vvv.abv.bg/

[_________________________   Microsoft Games   ___________________________]

- "C:\Users\Genovi\AppData\Local\Microsoft\Windows\GameExplorer\{50C3471D-5DF4-4E58-BE33-5E28723D5091}\SupportTasks\0\More Games from Microsoft.lnk"  ->             hxxp://vvv.fifa07.ea.com/
- "C:\Users\Genovi\AppData\Local\Microsoft\Windows\GameExplorer\{50C3471D-5DF4-4E58-BE33-5E28723D5091}\SupportTasks\1\Support.lnk"  -> hxxp://support.ea.com/

[____________________ Statistics ___________________]

Threats found:      4
Files listed:       9144 (folders: 1842, shortcuts: 273)
Time spent:         3 sec. (search: 2 sec.)

Been verified:
C:\Users\Genovi
C:\Users\UpdatusUser
C:\Users\Default
C:\Users\Public
C:\ProgramData
_____________________________ End of Log ________________________________8168 bytes, CRC32: FFFFFFFF. Sign: ??


Прилагам лог от SecurityCheck :

SecurityCheck by glax24 & Severnyj v.1.4.0.44 [17.08.16]
WebSite: www.safezone.cc
DateLog: 25.08.2016 18:38:52
Path starting: C:\Users\Genovi\AppData\Local\Temp\SecurityCheck\SecurityCheck.exe
Log directory: C:\SecurityCheck\
IsAdmin: True
User: Genovi
VersionXML: 3.36is-19.08.2016
___________________________________________________________________________

Windows 7(6.1.7601) Service Pack 1 (x64) Ultimate Lang: English(0409)
Installation date OS: 11.01.2015 12:27:48
LicenseStatus: Windows(R) 7, Ultimate edition The machine is permanently activated.
Boot Mode: Normal
Default Browser: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
SystemDrive: C: FS: [NTFS] Capacity: [147.3 Gb] Used: [63.9 Gb] Free: [83.4 Gb]
------------------------------- [ Windows ] -------------------------------
Internet Explorer 8.0.7601.17514 Warning! Download Update
Online installation. Last version available when Windows update is enabled throught the Internet.
User Account Control enabled
Automatic Updates disabled (-1)
Windows Update (wuauserv) - The service is running
Security Center (wscsvc) - The service is running
Remote Registry (RemoteRegistry) - The service has stopped
SSDP Discovery (SSDPSRV) - The service is running
Remote Desktop Services (TermService) - The service has stopped
Windows Remote Management (WS-Management) (WinRM) - The service has stopped
------------------------------ [ MS Office ] ------------------------------
Microsoft Office 2010 x64 v.14.0.6029.1000
---------------------------- [ Antivirus_WMI ] ----------------------------
Avast Antivirus (disabled and out of date)
--------------------------- [ FirewallWindows ] ---------------------------
Windows Firewall (MpsSvc) - The service is running
--------------------------- [ AntiSpyware_WMI ] ---------------------------
Windows Defender (disabled and out of date)
Avast Antivirus (disabled and out of date)
---------------------- [ AntiVirusFirewallInstall ] -----------------------
Avast Free Antivirus v.12.3.2280
-------------------------- [ SecurityUtilities ] --------------------------
Malwarebytes Anti-Malware version 2.2.1.1043 v.2.2.1.1043
--------------------------- [ OtherUtilities ] ----------------------------
WinRAR 5.20 (32-bit) v.5.20.0 Warning! Download Update
OpenOffice.org 2.3 v.2.3.9221 Warning! Download Update
--------------------------------- [ IM ] ----------------------------------
Skype™ 7.26 v.7.26.101
--------------------------------- [ P2P ] ---------------------------------
µTorrent v.3.4.8.42449 Warning! P2P-client.
--------------------------- [ AdobeProduction ] ---------------------------
Adobe AIR v.2.6.0.19140 Warning! Download Update
Adobe Reader XI (11.0.17) v.11.0.17
------------------------------- [ Browser ] -------------------------------
Google Chrome v.52.0.2743.116
--------------------------- [ RunningProcess ] ----------------------------
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe v.52.0.2743.116
------------------ [ AntivirusFirewallProcessServices ] -------------------
Avast Antivirus (avast! Antivirus) - The service is running
C:\Program Files\AVAST Software\Avast\AvastSvc.exe v.12.3.3154.0
C:\Program Files\AVAST Software\Avast\AvastUI.exe v.12.3.3154.0
MBAMScheduler (MBAMScheduler) - The service has stopped
MBAMService (MBAMService) - The service has stopped
Windows Defender (WinDefend) - The service has stopped
---------------------------- [ UnwantedApps ] -----------------------------
Google Toolbar for Internet Explorer v.1.0.0 << Hidden Warning! Browser's toolbar. It can slow down the working of your browser and have violation privacy problems.
----------------------------- [ End of Log ] ------------------------------
 

Поздрави :) 

След процедурите до тук...какво е моментното състояние на системата ви...Наблюдавате ли първоначалните проблеми..?

 

Деинсталирайте следния софтуер:

Цитат

Google Toolbar for Internet Explorer

Обновете следния софтуер:

Цитат

WinRAR 5.20 (32-bit) v.5.20.0 Warning! Download Update

Internet Explorer 8.0.7601.17514 Warning! Download Update
OpenOffice.org 2.3 v.2.3.9221 Warning! Download Update

Adobe AIR v.2.6.0.19140 Warning! Download Update

 

Направете ново  сканиране с Farbar Recovery Scan Tool като предварително изтриете вашето копие и карантинната папка на инструмента разположена вC:FRS\Quarantine. Изтеглете последна свежа версия и сканирайте..!

 

Сканиране с Farbar Recovery Scan Tool

  • Моля изтеглете icon1337953436.pngFarbar Recovery Scan Tool (според версията на Windows изберете 32 битовата или 64 битовата версия) и го запазете надесктопа.
  • Стартирайте файла FRST.exe (или FRST64.exe)
  • Програмата ще се стартира. Натиснете YES за да се съгласите с лицензионното споразумение.
  • Натиснете бутона YClYkft.jpg.
  • Изчакайте търпеливо проверката да приключи.
  • Ще се създадат два лог файла с името - FRST.txt и Addition.txt надесктопа.
  • Копирайте съдържанието на файла FRST.txt в следващия си пост.Прикачете Addition.txt в коментар си (погледнете опцията Прикачване на файлове, когато публикувате мнение). 

Дневници
 
В следващия си отговор, моля да включите следните дневници:

  • FRST.txt (копирате цялото съдържание)
  • Addition.txt (прикачате..)
  • Автор

Добър вечер. Не се забелязва промяна в проблем, все така изскачащи страници има. 

 

Прикачвам лог от  Farbar Recovery Scan Tool 
 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 21-08-2016 01
Ran by Genovi (administrator) on LENOVO (25-08-2016 23:11:16)
Running from C:\Users\Genovi\Desktop
Loaded Profiles: Genovi & UpdatusUser (Available Profiles: Genovi & UpdatusUser)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Lenovo.) C:\Windows\System32\ibmpmsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(BitTorrent Inc.) C:\Users\Genovi\AppData\Roaming\uTorrent\uTorrent.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(BitTorrent Inc.) C:\Users\Genovi\AppData\Roaming\uTorrent\updates\3.4.8_42449\utorrentie.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(BitTorrent Inc.) C:\Users\Genovi\AppData\Roaming\uTorrent\updates\3.4.8_42449\utorrentie.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2985712 2013-06-04] (Synaptics Incorporated)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [499608 2011-03-15] (Adobe Systems Incorporated)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [112512 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [IME14 CHT Setup] => C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE [109424 2010-01-21] (Microsoft Corporation)
HKLM\...\Run: [IME14 JPN Setup] => C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE [109424 2010-01-21] (Microsoft Corporation)
HKLM\...\Run: [IME14 KOR Setup] => C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE [109424 2010-01-21] (Microsoft Corporation)
HKLM\...\Run: [IME14 CHS Setup] => C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE [109424 2010-01-21] (Microsoft Corporation)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-26] (Intel Corporation)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5.5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [1523360 2011-01-12] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [IME14 CHT Setup] => C:\Program Files (x86)\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE [80240 2010-01-21] (Microsoft Corporation)
HKLM-x32\...\Run: [IME14 JPN Setup] => C:\Program Files (x86)\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE [80240 2010-01-21] (Microsoft Corporation)
HKLM-x32\...\Run: [IME14 KOR Setup] => C:\Program Files (x86)\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE [80240 2010-01-21] (Microsoft Corporation)
HKLM-x32\...\Run: [IME14 CHS Setup] => C:\Program Files (x86)\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE [80240 2010-01-21] (Microsoft Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9103976 2016-08-22] (AVAST Software)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3986698905-1256602312-1290690157-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-3986698905-1256602312-1290690157-1000\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1400232 2016-07-31] (Garmin Ltd. or its subsidiaries)
HKU\S-1-5-21-3986698905-1256602312-1290690157-1000\...\Run: [uTorrent] => C:\Users\Genovi\AppData\Roaming\uTorrent\uTorrent.exe [1972224 2016-08-10] (BitTorrent Inc.)
HKU\S-1-5-21-3986698905-1256602312-1290690157-1000\...\MountPoints2: H - H:\Lenovo_Suite.exe
HKU\S-1-5-21-3986698905-1256602312-1290690157-1000\...\MountPoints2: {1184f165-3463-11e5-9658-142d27ba3d24} - H:\Autorun.exe
HKU\S-1-5-21-3986698905-1256602312-1290690157-1000\...\MountPoints2: {735c4486-cadc-11e4-8641-142d27ba3d24} - F:\Lenovo_Suite.exe
HKU\S-1-5-21-3986698905-1256602312-1290690157-1000\...\MountPoints2: {894ba1fe-e57f-11e4-bd64-142d27ba3d24} - F:\Lenovo_Suite.exe
HKU\S-1-5-21-3986698905-1256602312-1290690157-1001\...\Run: [uTorrent] => C:\Users\Genovi\AppData\Roaming\uTorrent\uTorrent.exe [1972224 2016-08-10] (BitTorrent Inc.)
HKU\S-1-5-21-3986698905-1256602312-1290690157-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-3986698905-1256602312-1290690157-1001\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1400232 2016-07-31] (Garmin Ltd. or its subsidiaries)
HKU\S-1-5-21-3986698905-1256602312-1290690157-1001\...\MountPoints2: H - H:\Lenovo_Suite.exe
HKU\S-1-5-21-3986698905-1256602312-1290690157-1001\...\MountPoints2: {1184f165-3463-11e5-9658-142d27ba3d24} - H:\Autorun.exe
HKU\S-1-5-21-3986698905-1256602312-1290690157-1001\...\MountPoints2: {735c4486-cadc-11e4-8641-142d27ba3d24} - G:\Lenovo_Suite.exe
HKU\S-1-5-21-3986698905-1256602312-1290690157-1001\...\MountPoints2: {894ba1fe-e57f-11e4-bd64-142d27ba3d24} - H:\Lenovo_Suite.exe
HKU\S-1-5-18\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1400232 2016-07-31] (Garmin Ltd. or its subsidiaries)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [184048 2013-10-31] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [156256 2013-10-31] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-08-22] (AVAST Software)
Startup: C:\Users\Genovi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Deskjet 1510 series.lnk [2016-08-25]
ShortcutTarget: Monitor Ink Alerts - HP Deskjet 1510 series.lnk -> C:\Program Files\HP\HP Deskjet 1510 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 46.55.222.38 46.55.222.6
Tcpip\..\Interfaces\{2861413B-B2D6-4AEB-B16E-0C1CC6721565}: [DhcpNameServer] 46.55.222.38 46.55.222.6

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
SearchScopes: HKLM -> OldSearch URL = 
SearchScopes: HKU\S-1-5-21-3986698905-1256602312-1290690157-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-3986698905-1256602312-1290690157-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2011-02-12] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-08-22] (AVAST Software)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2011-02-12] (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-08-22] (AVAST Software)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation)
Toolbar: HKU\S-1-5-21-3986698905-1256602312-1290690157-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Filter: application/x-microsoft-rpmsg-message - {DFF82902-0B96-3B98-6F62-D655E146A23A} -  No File
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1420982659&from=kmp&uid=ST1000LM024XHN-M101MBB_S30YJ9EF657940

FireFox:
========
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.5.29 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-07-03] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-07-03] (Intel Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-08-22] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-08-22] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-06-23] (Adobe Systems Inc.)
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-08-22]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-08-22]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\WebRep\FF

Chrome: 
=======
CHR HomePage: Default -> hxxp://google.bg/
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Profile: C:\Users\Genovi\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Презентации) - C:\Users\Genovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-02-08]
CHR Extension: (Google Документи) - C:\Users\Genovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-02-08]
CHR Extension: (Google Диск) - C:\Users\Genovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-02-08]
CHR Extension: (YouTube) - C:\Users\Genovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-02-08]
CHR Extension: (Adblock Plus) - C:\Users\Genovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-08-24]
CHR Extension: (Google Търсене) - C:\Users\Genovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-02-08]
CHR Extension: (Електронни таблици от Google) - C:\Users\Genovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-02-08]
CHR Extension: (Google Документи офлайн) - C:\Users\Genovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15]
CHR Extension: (AdBlock) - C:\Users\Genovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-08-24]
CHR Extension: (Online Anti-Virus Scan) - C:\Users\Genovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\klbfhfklbfkhmmmaijegeejbnbeknbph [2016-02-11]
CHR Extension: (Плащания в уеб магазина на Chrome) - C:\Users\Genovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR Extension: (Layout Saver) - C:\Users\Genovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojpdacbapfghmhnklegllclfcohofmdc [2016-08-16]
CHR Extension: (Gmail) - C:\Users\Genovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-02-08]
CHR Extension: (Chrome Media Router) - C:\Users\Genovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-08-21]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-09-02] (Apple Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-08-22] (AVAST Software)
S2 Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [809488 2016-07-31] (Garmin Ltd. or its subsidiaries)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 ImeDictUpdateService; C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE [83312 2010-01-21] (Microsoft Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-07-03] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-07-03] (Intel Corporation)
S2 KMService; C:\Windows\SysWOW64\srvany.exe [8192 2016-01-10] () [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
S2 MSSQLSERVER; C:\Program Files\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [62218696 2012-06-29] (Microsoft Corporation)
S4 SQLSERVERAGENT; C:\Program Files\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE [441288 2012-06-29] (Microsoft Corporation)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-08-22] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-08-22] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [108816 2016-08-22] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-08-22] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-08-22] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [969560 2016-08-22] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [513496 2016-08-22] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [163416 2016-08-22] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [292704 2016-08-22] (AVAST Software)
R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2015-01-11] (Disc Soft Ltd)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-08-25] (Malwarebytes)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64896 2016-03-10] (Malwarebytes Corporation)
S4 RsFx0153; C:\Windows\System32\DRIVERS\RsFx0153.sys [321992 2012-06-29] (Microsoft Corporation)
R3 RTWlanE; C:\Windows\System32\DRIVERS\rtwlane.sys [2974424 2013-08-02] (Realtek Semiconductor Corporation                           )
R3 SmbDrvI; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [33008 2013-06-04] (Synaptics Incorporated)
S3 tpflhlp; \??\C:\SWTOOLS\FLASH\j7uj57ww\tpflhlp.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 vm331avs; System32\Drivers\vm331avs.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-08-25 23:11 - 2016-08-25 23:11 - 00022192 _____ C:\Users\Genovi\Desktop\FRST.txt
2016-08-25 23:06 - 2016-08-25 23:06 - 02396160 _____ (Farbar) C:\Users\Genovi\Desktop\FRST64.exe
2016-08-25 23:04 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE
2016-08-25 22:55 - 2016-08-25 22:54 - 57981648 ____N (Microsoft Corporation) C:\Users\Genovi\Desktop\IE11-Windows6.1-x64-bg-bg.exe
2016-08-25 22:45 - 2016-08-25 22:45 - 10753776 _____ (Adobe Systems Inc.) C:\Users\Genovi\Desktop\AdobeAIRInstaller.exe
2016-08-25 22:44 - 2016-08-25 22:44 - 00001078 _____ C:\Users\Public\Desktop\OpenOffice 4.1.2.lnk
2016-08-25 22:44 - 2016-08-25 22:44 - 00000000 ___SD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.2
2016-08-25 22:43 - 2016-08-25 22:43 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4
2016-08-25 22:39 - 2016-08-25 22:40 - 00000000 ____D C:\Users\Genovi\Desktop\OpenOffice 4.1.2 (bg) Installation Files
2016-08-25 22:36 - 2016-08-25 22:38 - 129447817 _____ C:\Users\Genovi\Desktop\Apache_OpenOffice_4.1.2_Win_x86_install_bg.exe
2016-08-25 22:34 - 2016-08-25 22:34 - 00000000 ____D C:\Program Files\WinRAR
2016-08-25 22:33 - 2016-08-25 22:33 - 02179856 _____ C:\Users\Genovi\Desktop\winrar-x64-540.exe
2016-08-25 18:38 - 2016-08-25 18:38 - 00506285 _____ (glax24 (safezone.cc)) C:\Users\Genovi\Desktop\SecurityCheck.exe
2016-08-25 18:38 - 2016-08-25 18:38 - 00000000 ____D C:\SecurityCheck
2016-08-25 18:34 - 2016-08-25 18:34 - 00000000 ____D C:\Users\Genovi\Desktop\LOG
2016-08-25 18:34 - 2016-05-07 16:10 - 00741488 _____ (Alex Dragokas) C:\Users\Genovi\Desktop\Check Browsers LNK.exe
2016-08-25 18:33 - 2016-08-25 18:33 - 00265036 _____ C:\Users\Genovi\Desktop\CheckBrowsersLNK.zip
2016-08-25 18:30 - 2016-08-25 18:30 - 00006161 _____ C:\Users\Genovi\Desktop\JRT.txt
2016-08-25 18:28 - 2016-08-25 18:28 - 01610560 _____ (Malwarebytes) C:\Users\Genovi\Desktop\JRT.exe
2016-08-25 18:17 - 2016-08-25 18:17 - 03826240 _____ C:\Users\Genovi\Desktop\adwcleaner_6.010.exe
2016-08-25 17:43 - 2016-08-25 17:43 - 22908888 _____ (Malwarebytes ) C:\Users\Genovi\Desktop\mbam-setup-2.2.0.1024.exe
2016-08-25 14:44 - 2016-08-25 14:46 - 00032157 _____ C:\Users\Genovi\Desktop\Addition212.txt
2016-08-25 14:43 - 2016-08-25 23:11 - 00000000 ____D C:\FRST
2016-08-25 14:43 - 2016-08-25 23:07 - 00038425 _____ C:\Users\Genovi\Desktop\FRST2142.txt
2016-08-24 17:31 - 2016-08-22 18:17 - 00003118 _____ C:\Users\Genovi\Desktop\AdwCleaner[C0].txt
2016-08-24 17:31 - 2016-08-22 18:16 - 00003545 _____ C:\Users\Genovi\Desktop\AdwCleaner[S1].txt
2016-08-24 17:29 - 2016-08-24 17:29 - 00012654 _____ C:\Users\Genovi\Desktop\protection log.txt
2016-08-24 17:29 - 2016-08-24 17:29 - 00001061 _____ C:\Users\Genovi\Desktop\scan log.txt
2016-08-24 17:15 - 2016-08-24 17:15 - 00000080 _____ C:\Users\Genovi\AppData\Roaming\Microsoft\Windows\Start Menu\чTorrent.lnk
2016-08-24 17:01 - 2016-08-25 22:26 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-08-24 17:01 - 2016-08-25 17:52 - 00001106 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-08-24 17:01 - 2016-08-25 17:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-08-24 17:01 - 2016-08-25 17:52 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-08-24 17:01 - 2016-08-24 17:01 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-08-24 17:01 - 2016-03-10 14:09 - 00064896 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2016-08-24 17:01 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-08-24 17:01 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2016-08-24 16:58 - 2016-08-24 16:59 - 22851472 _____ (Malwarebytes ) C:\Users\Genovi\Desktop\mbam-setup-2.2.1.1043.exe
2016-08-22 18:53 - 2016-08-24 17:15 - 00002259 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-08-22 18:53 - 2016-08-24 17:15 - 00002253 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-08-22 18:51 - 2016-07-22 14:48 - 06500888 _____ (Geek Uninstaller) C:\Users\Genovi\Desktop\geek.exe
2016-08-22 18:36 - 2016-08-22 18:36 - 00000000 ____D C:\Users\Genovi\Tracing
2016-08-22 18:35 - 2016-08-22 18:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2016-08-22 18:35 - 2016-08-22 18:35 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-08-22 18:30 - 2016-08-24 17:15 - 00001165 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2016-08-22 18:30 - 2016-08-22 18:30 - 00003886 _____ C:\Windows\System32\Tasks\SafeZone scheduled Autoupdate 1471879801
2016-08-22 18:29 - 2016-08-22 18:29 - 00000000 ____D C:\Program Files\Google
2016-08-22 18:28 - 2016-08-25 22:41 - 00000998 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-08-22 18:28 - 2016-08-25 22:24 - 00000994 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-08-22 18:28 - 2016-08-22 18:36 - 00003994 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-08-22 18:28 - 2016-08-22 18:36 - 00003742 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2016-08-22 18:28 - 2016-08-22 18:28 - 00037144 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2016-08-22 18:27 - 2016-08-24 17:15 - 00001960 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2016-08-22 18:27 - 2016-08-22 18:27 - 00003922 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2016-08-22 18:27 - 2016-08-22 18:27 - 00000000 ____D C:\Windows\System32\Tasks\AVAST Software
2016-08-22 18:27 - 2016-08-22 18:27 - 00000000 ____D C:\Users\Genovi\AppData\Roaming\AVAST Software
2016-08-22 18:27 - 2016-08-22 18:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2016-08-22 18:27 - 2016-08-22 18:27 - 00000000 ____D C:\Program Files\Common Files\AV
2016-08-22 18:27 - 2016-08-22 18:26 - 00163416 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2016-08-22 18:26 - 2016-08-22 18:26 - 00992960 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2016-08-22 18:26 - 2016-08-22 18:26 - 00969560 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2016-08-22 18:26 - 2016-08-22 18:26 - 00921280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2016-08-22 18:26 - 2016-08-22 18:26 - 00513496 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2016-08-22 18:26 - 2016-08-22 18:26 - 00391496 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2016-08-22 18:26 - 2016-08-22 18:26 - 00292704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2016-08-22 18:26 - 2016-08-22 18:26 - 00108816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2016-08-22 18:26 - 2016-08-22 18:26 - 00103064 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2016-08-22 18:26 - 2016-08-22 18:26 - 00074544 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2016-08-22 18:26 - 2016-08-22 18:26 - 00053208 _____ (AVAST Software) C:\Windows\avastSS.scr
2016-08-22 18:26 - 2016-08-22 18:26 - 00037656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2016-08-22 18:25 - 2016-08-22 18:28 - 00000000 ____D C:\ProgramData\AVAST Software
2016-08-22 18:25 - 2016-08-22 18:28 - 00000000 ____D C:\Program Files\AVAST Software
2016-08-22 18:13 - 2016-08-25 18:21 - 00000000 ____D C:\AdwCleaner
2016-08-22 18:09 - 2016-08-22 18:13 - 00000000 ____D C:\Users\Genovi\AppData\Roaming\Geek Uninstaller
2016-08-13 15:06 - 2016-08-25 22:25 - 00000000 ____D C:\Users\Genovi\AppData\LocalLow\uTorrent
2016-08-05 14:39 - 2016-08-05 14:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-08-25 23:11 - 2015-01-11 16:20 - 00000000 ____D C:\Users\Genovi\AppData\Roaming\uTorrent
2016-08-25 22:44 - 2015-11-26 00:28 - 00000000 ____D C:\Program Files (x86)\OpenOffice.org 2.3
2016-08-25 22:34 - 2015-01-11 16:19 - 00000000 ____D C:\Users\Genovi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-08-25 22:34 - 2015-01-11 16:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-08-25 22:33 - 2009-07-14 07:45 - 00026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-08-25 22:33 - 2009-07-14 07:45 - 00026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-08-25 22:29 - 2009-07-14 06:20 - 00000000 ____D C:\Windows\Help
2016-08-25 22:27 - 2015-01-11 16:16 - 00000000 ____D C:\Users\Genovi\AppData\Local\Google
2016-08-25 22:27 - 2015-01-11 16:16 - 00000000 ____D C:\Program Files (x86)\Google
2016-08-25 22:25 - 2015-06-11 11:18 - 00000670 __RSH C:\ProgramData\ntuser.pol
2016-08-25 22:24 - 2016-03-20 18:58 - 00000202 _____ C:\Windows\Tasks\AutoKMS.job
2016-08-25 22:24 - 2015-01-11 15:42 - 00000000 ____D C:\Windows\SysWOW64\NV
2016-08-25 22:24 - 2015-01-11 15:42 - 00000000 ____D C:\Windows\system32\NV
2016-08-25 22:24 - 2015-01-11 15:41 - 00000000 ____D C:\ProgramData\NVIDIA
2016-08-25 22:24 - 2009-07-14 08:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-08-25 18:46 - 2015-10-31 08:35 - 00000000 ____D C:\Users\Genovi\Desktop\Музика - lenovo mp3
2016-08-25 18:44 - 2015-06-23 14:55 - 00000000 ___RD C:\Users\Genovi\Desktop\Снимки
2016-08-25 17:51 - 2009-07-14 06:20 - 00000000 ____D C:\Windows\system32\NDF
2016-08-24 17:18 - 2016-03-20 18:58 - 00000202 _____ C:\Windows\Tasks\AutoKMSDaily.job
2016-08-24 17:15 - 2016-03-16 17:27 - 00000000 ____D C:\Program Files (x86)\EViews 8
2016-08-24 17:15 - 2015-12-13 17:47 - 00001202 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS5.1.lnk
2016-08-24 17:15 - 2015-12-13 17:47 - 00001150 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS5.1 (64 Bit).lnk
2016-08-24 17:15 - 2015-12-13 17:46 - 00001295 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Device Central CS5.5.lnk
2016-08-24 17:15 - 2015-12-13 17:45 - 00001543 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS5.5.lnk
2016-08-24 17:15 - 2015-12-13 17:45 - 00001396 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS5.5.lnk
2016-08-24 17:15 - 2015-12-13 17:44 - 00000985 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
2016-08-24 17:15 - 2015-06-23 15:01 - 00000000 ___RD C:\Users\Genovi\Desktop\Програми
2016-08-24 17:15 - 2015-03-07 10:35 - 00000000 ____D C:\Users\Genovi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2016-08-24 17:15 - 2015-01-21 22:30 - 00000631 _____ C:\Users\Genovi\Desktop\Роси.lnk
2016-08-24 17:15 - 2015-01-11 16:30 - 00002429 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2016-08-24 17:15 - 2015-01-11 15:28 - 00001447 _____ C:\Users\Genovi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-08-24 17:15 - 2015-01-11 15:28 - 00001413 _____ C:\Users\Genovi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2016-08-24 17:15 - 2015-01-11 15:15 - 00001333 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2016-08-24 17:15 - 2015-01-11 15:14 - 00001314 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2016-08-24 17:15 - 2009-07-14 08:01 - 00001282 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk
2016-08-24 17:15 - 2009-07-14 07:57 - 00001535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-08-24 17:15 - 2009-07-14 07:57 - 00001318 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
2016-08-24 17:15 - 2009-07-14 07:57 - 00001234 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
2016-08-24 17:15 - 2009-07-14 07:54 - 00001198 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
2016-08-24 17:15 - 2009-07-14 07:49 - 00001266 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk
2016-08-24 16:49 - 2016-03-20 18:58 - 00002740 _____ C:\Windows\System32\Tasks\AutoKMSDaily
2016-08-22 18:36 - 2015-01-11 16:22 - 00000000 ____D C:\Users\Genovi\AppData\Roaming\Skype
2016-08-22 18:36 - 2015-01-11 15:27 - 00000000 ____D C:\Users\Genovi
2016-08-22 18:35 - 2015-01-11 16:22 - 00000000 ____D C:\Users\Genovi\AppData\Local\Skype
2016-08-22 18:35 - 2015-01-11 16:22 - 00000000 ____D C:\ProgramData\Skype
2016-08-13 16:21 - 2016-02-08 22:58 - 00000000 ___SD C:\Users\Genovi\AppData\LocalLow\Temp
2016-08-12 23:07 - 2015-01-21 22:29 - 381391479 _____ C:\Windows\MEMORY.DMP
2016-08-12 23:07 - 2015-01-21 22:29 - 00000000 ____D C:\Windows\Minidump
2016-08-06 17:21 - 2009-07-14 08:13 - 00873744 _____ C:\Windows\system32\PerfStringBackup.INI
2016-08-06 17:21 - 2009-07-14 06:20 - 00000000 ____D C:\Windows\inf
2016-08-05 14:40 - 2015-10-20 22:32 - 00000000 ____D C:\ProgramData\Package Cache
2016-08-05 14:39 - 2015-10-20 22:32 - 00003554 _____ C:\Windows\System32\Tasks\GarminUpdaterTask
2016-08-05 14:39 - 2015-10-20 22:32 - 00000000 ____D C:\Program Files (x86)\Garmin

==================== Files in the root of some directories =======

2015-03-12 15:12 - 2015-03-12 15:12 - 0000057 _____ () C:\ProgramData\Ament.ini
2015-01-11 15:32 - 2015-01-11 15:32 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2015-09-01 15:49 - 2015-09-01 15:49 - 0000000 _____ () C:\ProgramData\temp

Some files in TEMP:
====================
C:\Users\Genovi\AppData\Local\Temp\AutoRun.exe
C:\Users\Genovi\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\Genovi\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpevgvfp.dll
C:\Users\Genovi\AppData\Local\Temp\EASOUNInstaller.exe
C:\Users\Genovi\AppData\Local\Temp\eauninstall.exe
C:\Users\Genovi\AppData\Local\Temp\FIFA 07_uninst.exe
C:\Users\Genovi\AppData\Local\Temp\GarminExpressInstaller.exe
C:\Users\Genovi\AppData\Local\Temp\libeay32.dll
C:\Users\Genovi\AppData\Local\Temp\msvcr120.dll
C:\Users\Genovi\AppData\Local\Temp\ose00000.exe
C:\Users\Genovi\AppData\Local\Temp\ose00001.exe
C:\Users\Genovi\AppData\Local\Temp\ose00002.exe
C:\Users\Genovi\AppData\Local\Temp\ose00005.exe
C:\Users\Genovi\AppData\Local\Temp\ReimagePackage.exe
C:\Users\Genovi\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Genovi\AppData\Local\Temp\SpotifyUninstall.exe
C:\Users\Genovi\AppData\Local\Temp\sqlite3.dll
C:\Users\Genovi\AppData\Local\Temp\sqlite3.exe
C:\Users\Genovi\AppData\Local\Temp\UmmyVideoDownloader.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-08-06 16:47

==================== End of FRST.txt ============================


 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 21-08-2016 01
Ran by Genovi (25-08-2016 23:11:53)
Running from C:\Users\Genovi\Desktop
Windows 7 Ultimate Service Pack 1 (X64) (2015-01-11 12:27:48)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3986698905-1256602312-1290690157-500 - Administrator - Disabled)
Genovi (S-1-5-21-3986698905-1256602312-1290690157-1000 - Administrator - Enabled) => C:\Users\Genovi
Guest (S-1-5-21-3986698905-1256602312-1290690157-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3986698905-1256602312-1290690157-1007 - Limited - Enabled)
UpdatusUser (S-1-5-21-3986698905-1256602312-1290690157-1001 - Limited - Enabled) => C:\Users\UpdatusUser

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avast Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-3986698905-1256602312-1290690157-1000\...\uTorrent) (Version: 3.4.8.42449 - BitTorrent Inc.)
µTorrent (HKU\S-1-5-21-3986698905-1256602312-1290690157-1001\...\uTorrent) (Version: 3.4.5.41712 - BitTorrent Inc.)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 22.0.0.153 - Adobe Systems Incorporated)
Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.5.23 - Adobe Systems Incorporated.)
Adobe Photoshop CS5.1 (HKLM-x32\...\{9158FF30-78D7-40EF-B83E-451AC5334640}) (Version: 12.1 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.17) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.17 - Adobe Systems Incorporated)
ANT Drivers Installer x64 (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
Apple Application Support (64-bit) (HKLM\...\{1F72FDD5-A069-45B4-928F-D0F16492DC69}) (Version: 4.0.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{FD244E19-6EFE-4A2D-948A-0D45D4C168BE}) (Version: 9.0.0.26 - Apple Inc.)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 12.3.2280 - AVAST Software)
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.)
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
Elevated Installer (x32 Version: 4.1.25.0 - Garmin Ltd or its subsidiaries) Hidden
EViews 8 (HKLM-x32\...\InstallShield_{1D78E62C-B585-446A-8FC7-2754332C0521}) (Version: 8.00.0000 - IHS Global Inc.)
EViews 8 (x32 Version: 8.00.0000 - IHS Global Inc.) Hidden
Garmin Express (HKLM-x32\...\{686d881a-083e-4030-80db-52c493bf89d3}) (Version: 4.1.25.0 - Garmin Ltd or its subsidiaries)
Garmin Express (x32 Version: 4.1.25.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express Tray (x32 Version: 4.1.25.0 - Garmin Ltd or its subsidiaries) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 52.0.2743.116 - Google Inc.)
Google Update Helper (x32 Version: 1.3.21.169 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
HP Deskjet 1510 series Basic Device Software (HKLM\...\{D17E60E8-478A-4D4A-8147-21D481B5CA55}) (Version: 32.2.188.47710 - Hewlett-Packard Co.)
HP Deskjet 1510 series Help (HKLM-x32\...\{2E25FCEB-EFCB-4696-AA01-D3CBAC721831}) (Version: 30.0.0 - Hewlett Packard)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
IBM SPSS Statistics 23 (HKLM\...\{C3BA73A4-2A45-4036-8541-4F5F8146078B}) (Version: 23.0.0.0 - IBM Corp)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1011 - Intel Corporation)
Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: 1.0.0.36943 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.0.13.1402 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.18.10.3234 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 3.0.0.66956 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 2.5.0.19 - Intel Corporation)
KMPlayer (remove only) (HKLM-x32\...\The KMPlayer) (Version: 3.9.1.131 - PandoraTV)
Lenovo Patch Utility (x32 Version: 1.3.2.6 - Lenovo Group Limited) Hidden
Lenovo Patch Utility 64 bit (Version: 1.3.2.6 - Lenovo Group Limited) Hidden
Lenovo Power Management Driver (HKLM\...\Power Management Driver) (Version: 1.67.07.06 - )
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2010 Service Pack 1 (SP1) (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{7BC9B5EB-125A-4E9B-97E1-8D85B5E960B8}) (Version:  - Microsoft)
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.6029.1000 - Microsoft Corporation)
Microsoft Office Proofing Tools Kit Compilation 2010 (HKLM\...\Office14.PROOFKIT) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 (64-bit) (HKLM\...\Microsoft SQL Server 2008 R2) (Version:  - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Native Client (HKLM\...\{79A2C6E8-C727-4D12-B4B3-19790C181DEA}) (Version: 10.52.4000.0 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Setup (English) (HKLM\...\{C3525BF7-3698-4CD3-A8C3-69BD6F57BA3B}) (Version: 10.52.4000.0 - Microsoft Corporation)
Microsoft SQL Server 2008 Setup Support Files  (HKLM\...\{B40EE88B-400A-4266-A17B-E3DE64E94431}) (Version: 10.1.2731.0 - Microsoft Corporation)
Microsoft SQL Server Browser (HKLM-x32\...\{BF9BF038-FE03-429D-9B26-2FA0FD756052}) (Version: 10.52.4000.0 - Microsoft Corporation)
Microsoft SQL Server Native Client (HKLM\...\{751EE164-9F12-4E57-ADB0-02D8F34A10AD}) (Version: 9.00.1399.06 - Microsoft Corporation)
Microsoft SQL Server VSS Writer (HKLM\...\{288D79EE-A2D1-42AF-9597-B0ADCC23A8ED}) (Version: 10.52.4000.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.40303 - Microsoft Corporation)
Need for Speed™ Most Wanted (HKLM-x32\...\{ADE91A13-434D-4229-00BC-182BAD607303}) (Version:  - )
NVIDIA Graphics Driver 327.62 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 327.62 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.13.0725 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0725 - NVIDIA Corporation)
NVIDIA Update 1.14.17 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.14.17 - NVIDIA Corporation)
OpenOffice 4.1.2 (HKLM-x32\...\{62DC054F-C57F-4F44-846C-1B29F2C92252}) (Version: 4.12.9782 - Apache Software Foundation)
PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden
PhotoScape (HKLM-x32\...\PhotoScape) (Version:  - )
Picture Collage Maker 4.1.2 (HKLM-x32\...\{D53599B0-AA76-4CC6-B9EF-CC2F27B56F24}_is1) (Version: 4.1.2 - PearlMountain Technology Co., Ltd)
Product Improvement Study for HP Deskjet 1510 series (HKLM\...\{35DB2630-846E-47C5-AF84-9D6AC3629F55}) (Version: 32.2.188.47710 - Hewlett-Packard Co.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.30161 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.50.1123.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7005 - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver (HKLM-x32\...\{9DAABC60-A5EF-41FF-B2B9-17329590CD5}) (Version: 1.00.0225 - REALTEK Semiconductor Corp.)
SafeZone Stable 1.51.2220.53 (x32 Version: 1.51.2220.53 - Avast Software) Hidden
Service Pack 2 for SQL Server 2008 R2 (KB2630458) (64-bit) (HKLM\...\KB2630458) (Version: 10.52.4000.0 - Microsoft Corporation)
Skype™ 7.26 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.26.101 - Skype Technologies S.A.)
SQL Server 2008 R2 SP2 Common Files (Version: 10.52.4000.0 - Microsoft Corporation) Hidden
SQL Server 2008 R2 SP2 Database Engine Services (Version: 10.52.4000.0 - Microsoft Corporation) Hidden
SQL Server 2008 R2 SP2 Database Engine Shared (Version: 10.52.4000.0 - Microsoft Corporation) Hidden
Sql Server Customer Experience Improvement Program (Version: 10.50.1600.1 - Microsoft Corporation) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.6.4.13 - Synaptics Incorporated)
Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
WinRAR 5.20 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.20.0 - win.rar GmbH)
WinRAR 5.40 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3986698905-1256602312-1290690157-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Genovi\AppData\Roaming\Dropbox\bin\Dropbox.exe /autoplay => No File

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {128FF04C-B222-464E-B693-75C266D9170B} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2013-07-26] (Realtek Semiconductor)
Task: {19704BED-D84C-4864-97BA-C2E13C95F84B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-08-22] (Google Inc.)
Task: {2674FF8E-3311-4470-BA1E-D3131E8CDE39} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [2016-07-31] ()
Task: {3577B8E1-250C-4135-9903-6A1C8873A391} - System32\Tasks\SafeZone scheduled Autoupdate 1471879801 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-08-09] (Avast Software)
Task: {539EFEF1-B87D-4D91-8FEF-87CACEFBB06B} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS.exe
Task: {7CB94EBD-1CF1-45DC-B94F-92066C51F089} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-08-22] (Google Inc.)
Task: {7F38D0B1-DA4E-4AFE-9C5B-D8917A4E57C3} - System32\Tasks\{850DDB30-EF7A-4AE4-9D86-611F3ED065EE} => Chrome.exe hxxp://ui.skype.com/ui/0/7.3.0.101/bg/abandoninstall?page=tsProgressBar
Task: {83322B78-226E-4D11-87BF-B72F9C6C0458} - System32\Tasks\AutoKMSDaily => C:\Windows\AutoKMS.exe
Task: {870B4C36-4F91-427A-8CC2-B4B99BBE20CF} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2013-03-07] (Intel Corporation)
Task: {98BA7BD3-72F6-43BC-9BC8-EFED4C17B51F} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2013-03-07] (Intel Corporation)
Task: {B3B1FBD1-D8BB-4D0D-9999-86088465A945} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-06-25] (Adobe Systems Incorporated)
Task: {CED0E0F7-8B3A-4AA1-B35A-7EE4A5529E5F} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-08-22] (AVAST Software)
Task: {CFE7D0AE-D58E-4B6A-BEAF-C90182A12C98} - System32\Tasks\AdobeAAMUpdater-1.0-Lenovo-Genovi => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2011-03-15] (Adobe Systems Incorporated)
Task: {E52ABFEE-E013-40EB-9F4F-5AD2990CA4BD} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2016-08-22] (AVAST Software)
Task: {F067214B-F2C5-4C51-B33E-98EA23F32248} - System32\Tasks\HPCustParticipation HP Deskjet 1510 series => C:\Program Files\HP\HP Deskjet 1510 series\Bin\HPCustPartic.exe [2014-03-06] (Hewlett-Packard Co.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\AutoKMS.job => C:\Windows\AutoKMS.exe
Task: C:\Windows\Tasks\AutoKMSDaily.job => C:\Windows\AutoKMS.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

Shortcut: C:\Users\Genovi\AppData\Local\Microsoft\Windows\GameExplorer\{50C3471D-5DF4-4E58-BE33-5E28723D5091}\SupportTasks\1\Support.lnk -> hxxp://support.ea.com/
Shortcut: C:\Users\Genovi\AppData\Local\Microsoft\Windows\GameExplorer\{50C3471D-5DF4-4E58-BE33-5E28723D5091}\SupportTasks\0\More Games from Microsoft.lnk -> hxxp://www.fifa07.ea.com/

ShortcutWithArgument: C:\Users\Genovi\Desktop\Програми\Стартов панел с приложения за Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --show-app-list
ShortcutWithArgument: C:\Users\Genovi\AppData\Local\Google\Chrome\User Data\Стартов панел с приложения за Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --show-app-list

==================== Loaded Modules (Whitelisted) ==============

2015-01-11 15:41 - 2013-10-29 02:38 - 00097568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2015-01-11 15:41 - 2013-10-31 16:13 - 00013088 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll
2011-03-17 01:07 - 2011-03-17 01:07 - 04297568 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 16:23 - 2010-10-20 16:23 - 08801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2015-09-23 16:47 - 2015-09-23 16:47 - 00085800 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-09-23 16:47 - 2015-09-23 16:47 - 01328912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2016-08-22 18:26 - 2016-08-22 18:26 - 00169064 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2016-08-24 16:48 - 2016-08-24 16:48 - 03016192 _____ () C:\Program Files\AVAST Software\Avast\defs\16082400\algo.dll
2016-08-22 18:26 - 2016-08-22 18:26 - 00482928 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2016-08-22 18:26 - 2016-08-22 18:26 - 48936448 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2011-03-17 01:11 - 2011-03-17 01:11 - 04297568 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 16:45 - 2010-10-20 16:45 - 08801120 _____ () C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2015-01-11 15:35 - 2013-07-03 11:40 - 01199576 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2016-08-22 18:53 - 2016-08-03 03:24 - 01771336 _____ () C:\Program Files (x86)\Google\Chrome\Application\52.0.2743.116\libglesv2.dll
2016-08-22 18:53 - 2016-08-03 03:23 - 00094024 _____ () C:\Program Files (x86)\Google\Chrome\Application\52.0.2743.116\libegl.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 05:34 - 2009-06-11 00:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3986698905-1256602312-1290690157-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Genovi\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 46.55.222.38 - 46.55.222.6
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{57EF499B-6697-44E4-88B6-F37B4256793A}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{90564E8F-49B7-4C6A-8E6F-52E391F1896A}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{D9DEF69F-CB83-4D8D-8551-C6A4955DA180}] => (Allow) C:\Users\Genovi\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{A4EF9EA6-1C3F-44BD-A1B6-81608EA00BA5}] => (Allow) C:\Users\Genovi\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{A29938D3-6644-4889-9CD5-A426FACC7CD2}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [TCP Query User{D64A55D6-5186-4ABF-827B-63BA942C1416}C:\program files (x86)\ea games\need for speed most wanted\speed.exe] => (Block) C:\program files (x86)\ea games\need for speed most wanted\speed.exe
FirewallRules: [UDP Query User{C5E7F432-B1AA-4BD5-9771-3FE882CB37B5}C:\program files (x86)\ea games\need for speed most wanted\speed.exe] => (Block) C:\program files (x86)\ea games\need for speed most wanted\speed.exe
FirewallRules: [TCP Query User{132EB091-8E0E-4C41-A202-C851FF3A1B31}C:\program files (x86)\fifa 14\game\fifa14.exe] => (Allow) C:\program files (x86)\fifa 14\game\fifa14.exe
FirewallRules: [UDP Query User{AE2B9CD1-38F7-4064-88DB-48D7DEEE2F56}C:\program files (x86)\fifa 14\game\fifa14.exe] => (Allow) C:\program files (x86)\fifa 14\game\fifa14.exe
FirewallRules: [{DCE6B7F9-B33E-4A05-82EF-748693272639}] => (Allow) C:\Program Files\HP\HP Deskjet 1510 series\Bin\USBSetup.exe
FirewallRules: [{EB792C4F-6206-4994-8FB9-D8FA27D07F56}] => (Allow) C:\Program Files\HP\HP Deskjet 1510 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{E69600EC-2F37-4A38-9E65-EDAF4CBC0E05}] => (Allow) LPort=1433
FirewallRules: [TCP Query User{76B89CD8-95A7-4DCE-A775-CB59C382F3E8}C:\program files (x86)\connectify\connectify.exe] => (Allow) C:\program files (x86)\connectify\connectify.exe
FirewallRules: [UDP Query User{B94E21FA-6321-4EC8-8C3F-62334E43856D}C:\program files (x86)\connectify\connectify.exe] => (Allow) C:\program files (x86)\connectify\connectify.exe
FirewallRules: [TCP Query User{7AB2541D-F9E4-4DEB-9580-6A5707E3DDA1}C:\program files (x86)\fifa 14\game\fifa14.exe] => (Block) C:\program files (x86)\fifa 14\game\fifa14.exe
FirewallRules: [UDP Query User{73CF5938-17E3-42CC-BF62-A5816ACA6D83}C:\program files (x86)\fifa 14\game\fifa14.exe] => (Block) C:\program files (x86)\fifa 14\game\fifa14.exe
FirewallRules: [{611D7EAD-6717-4811-967C-0B59B3A82E7B}] => (Allow) C:\Program Files (x86)\SpringFiles\SpringFiles.exe
FirewallRules: [{09D76DAB-22C6-4E71-8E02-06294F69D432}] => (Allow) C:\Program Files (x86)\SpringFiles\SpringFiles.exe
FirewallRules: [{6CF1B9B1-471B-434E-A616-1479E22B9329}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\23\stats.com
FirewallRules: [{8FF4AB06-AEB5-4C05-AD99-35F0672DB517}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\23\WinWrapIDE.exe
FirewallRules: [{6121FB7C-2FCD-4D0F-9E3C-BBF856AEAC4D}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\23\stats.exe
FirewallRules: [{54EE832F-A1B7-4D47-9F41-932405C35530}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\23\stats.com
FirewallRules: [{E8D69806-245F-4912-B1C5-CD8A9391C8F5}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\23\WinWrapIDE.exe
FirewallRules: [{D0E29158-9130-49CB-9C4C-11CECAA481B7}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\23\stats.exe
FirewallRules: [TCP Query User{D9E2415D-0EFB-49DD-BD9D-2C858F13DB44}C:\program files\ibm\spss\statistics\23\stats.exe] => (Allow) C:\program files\ibm\spss\statistics\23\stats.exe
FirewallRules: [UDP Query User{D60F6001-689C-46DD-BA48-89FCBCBEAB7E}C:\program files\ibm\spss\statistics\23\stats.exe] => (Allow) C:\program files\ibm\spss\statistics\23\stats.exe
FirewallRules: [TCP Query User{F47B1F5D-5F3D-4F3C-A475-AD856A5315F3}C:\users\genovi\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\genovi\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{EEC88CD5-2132-4380-9150-89CFC9F79071}C:\users\genovi\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\genovi\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{F8687B8F-A28F-4749-B403-C9915D27D7B2}C:\users\genovi\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\genovi\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{E5C3CEB9-8136-4158-B8A3-C779C8BFB75F}C:\users\genovi\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\genovi\appdata\roaming\spotify\spotify.exe
FirewallRules: [{2343B0DE-A313-45E7-8B72-C401495487E5}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Restore Points =========================

22-07-2016 22:24:32 Scheduled Checkpoint
05-08-2016 14:38:43 Garmin Express
22-08-2016 18:32:20 ASU_MSI_TRAN
25-08-2016 18:28:32 JRT Pre-Junkware Removal
25-08-2016 22:28:57 Removed Rights Management Add-on for Internet Explorer
25-08-2016 22:40:11 Installed Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
25-08-2016 22:41:12 Installed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
25-08-2016 22:42:19 OpenOffice 4.1.2 е инсталиран
25-08-2016 22:56:47 Windows Modules Installer

==================== Faulty Device Manager Devices =============

Name: 
Description: 
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (08/25/2016 10:26:25 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (08/25/2016 10:25:43 PM) (Source: MSSQLSERVER) (EventID: 9003) (User: )
Description: The log scan number (321:80:1) passed to log scan in database 'master' is not valid. This error may indicate data corruption or that the log file (.ldf) does not match the data file (.mdf). If this error occurred during replication, re-create the publication. Otherwise, restore from backup if the problem results in a failure during startup.

Error: (08/25/2016 06:24:00 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (08/25/2016 06:23:47 PM) (Source: MSSQLSERVER) (EventID: 9003) (User: )
Description: The log scan number (321:80:1) passed to log scan in database 'master' is not valid. This error may indicate data corruption or that the log file (.ldf) does not match the data file (.mdf). If this error occurred during replication, re-create the publication. Otherwise, restore from backup if the problem results in a failure during startup.

Error: (08/25/2016 05:50:08 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (08/25/2016 05:49:40 PM) (Source: MSSQLSERVER) (EventID: 9003) (User: )
Description: The log scan number (321:80:1) passed to log scan in database 'master' is not valid. This error may indicate data corruption or that the log file (.ldf) does not match the data file (.mdf). If this error occurred during replication, re-create the publication. Otherwise, restore from backup if the problem results in a failure during startup.

Error: (08/25/2016 05:16:07 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (08/25/2016 05:15:43 PM) (Source: MSSQLSERVER) (EventID: 9003) (User: )
Description: The log scan number (321:80:1) passed to log scan in database 'master' is not valid. This error may indicate data corruption or that the log file (.ldf) does not match the data file (.mdf). If this error occurred during replication, re-create the publication. Otherwise, restore from backup if the problem results in a failure during startup.

Error: (08/25/2016 01:58:26 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (08/25/2016 01:58:06 PM) (Source: MSSQLSERVER) (EventID: 9003) (User: )
Description: The log scan number (321:80:1) passed to log scan in database 'master' is not valid. This error may indicate data corruption or that the log file (.ldf) does not match the data file (.mdf). If this error occurred during replication, re-create the publication. Otherwise, restore from backup if the problem results in a failure during startup.


System errors:
=============
Error: (08/25/2016 10:26:41 PM) (Source: WMPNetworkSvc) (EventID: 14332) (User: )
Description: WMPNetworkSvc0x80004005

Error: (08/25/2016 10:25:45 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: The SQL Server (MSSQLSERVER) service terminated with service-specific error %%3417.

Error: (08/25/2016 10:25:16 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Garmin Device Interaction Service service failed to start due to the following error: 
%%1053 = The service did not respond to the start or control request in a timely fashion.

Error: (08/25/2016 10:25:16 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Garmin Device Interaction Service service to connect.

Error: (08/25/2016 06:23:48 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: The SQL Server (MSSQLSERVER) service terminated with service-specific error %%3417.

Error: (08/25/2016 06:23:23 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Garmin Device Interaction Service service failed to start due to the following error: 
%%1053 = The service did not respond to the start or control request in a timely fashion.

Error: (08/25/2016 06:23:23 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Garmin Device Interaction Service service to connect.

Error: (08/25/2016 06:21:38 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.

Module Path: C:\Windows\system32\Rtlihvs.dll

Error: (08/25/2016 06:21:38 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.

Module Path: C:\Windows\system32\Rtlihvs.dll

Error: (08/25/2016 06:21:37 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Search service, but this action failed with the following error: 
%%1056 = An instance of the service is already running.


==================== Memory info =========================== 

Processor: Intel(R) Core(TM) i5-4200M CPU @ 2.50GHz
Percentage of memory in use: 64%
Total physical RAM: 3867.37 MB
Available physical RAM: 1390.43 MB
Total Virtual: 7732.93 MB
Available Virtual: 4907.96 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:147.31 GB) (Free:85.6 GB) NTFS
Drive d: (Local Dick) (Fixed) (Total:783.2 GB) (Free:621.08 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 6D4AA18E)
Partition 1: (Active) - (Size=1 GB) - (Type=0B)
Partition 2: (Not Active) - (Size=147.3 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=783.2 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

Направете резервно копие на вашите Favourites/Bookmarks  и други данни, следвайки инструкциите по-долу за наличните ви браузери.

 

 

102.jpg?1414583023 Моля, изтеглете ClearLNK by Dragokas & regist.

  • Запомнете архива на вашия декстоп,разархивирате програмата ClearLNK
  • Влачите и пускате файла Check_Browsers_LNK.log (логът генериран от програмата Check Browsers LNK в предния ми инструкция) на иконката на програмата ClearLNK.


[IMG]

  • Ще се генерира отчет ClearLNK-<Дата>.log, който ще бъде създаден в папката LOG. Публикувайте дневника в следващия си пост.

 

Фикс с Farbar Recovery Scan Tool

 
icon13.gif Изтеглете прикачения файл - fixlist.txt  и го запазете там, където сте свалили FRST.exe
Стартирайте отново FRST.exe и натиснете бутона Fix веднъж и изчакайте.
Ще се създаде нов лог файла FixLog.txt. Прикачете съдържанието му в следващия си коментар.

 
ЗАБЕЛЕЖКА: Този скрипт е написан специално за този потребител,и за тази конкретна машина. Изпълнението на фикса, на друг компютър може да доведе до увреждане на  операционната ви система

 

  Дневници
 
В следващия си отговор, моля да включите следните дневници:

  • FixLog.txt
  • ClearLNK-<Дата>.log
  • Автор

Добър вечер, проблема е само при Google Chrome. Рутера ми е пред компютъра. 

 

ClearLNK by Alex Dragokas                                 ver. 2.9.0.7

OS:       x64 Windows 7 Ultimate, 6.1.7601, Service Pack: 1
Time:     26.08.2016 - 22:39
Language: OS: EN (0x409). Display: EN (0x409). Non-Unicode: BG (0x402)
Elevated: Yes
User:     Genovi    (group: Administrator). SM=SingleUserTS, PT=Workstation.

_____________________________ Begin of Log ______________________________
.
[SKIP] 3  "C:\Users\Genovi\AppData\Local\Microsoft\Windows\GameExplorer\{50C3471D-5DF4-4E58-BE33-5E28723D5091}\PlayTasks\0\Play.lnk"    (shortcut was not found)
[SKIP] 4  "C:\Users\Genovi\Desktop\Игри\FIFA 07.lnk"    (shortcut was not found)
.
[WARN] 1  "C:\Users\Genovi\AppData\Local\Google\Chrome\User Data\Стартов панел с приложения за Chrome.lnk"    -> [ "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" ]   (already cured)
[WARN] 2  "C:\Users\Genovi\Desktop\Програми\Стартов панел с приложения за Chrome.lnk"    -> [ "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" ]   (already cured)
.

______________________________ Statistics _______________________________
Cure ran per today: 2 times.

  Total processed:  4

         Omitted:   2
         Warnings:  2
______________________________ End of Log _______________________________CRC32: 9C105F6F


 

New Text Document.txt

Здравейте..! Ако след процедурите до тук не се е решил проблема с  Google Chrome  направете  бекъп на паролите и любимите страници ( ако не сте го направили вече):

Експортиране на отметки от Chrome .Backup Chrome Bookmarks

  1. В горния десен ъгъл на прозореца на браузъра кликнете върху менюто на Chrome.
  2. Изберете Отметки > Диспечер на отметките.
  3. Кликнете върху менюто „Организиране“ в диспечера.
  4. Сега изберете Export bookmarks to HTML file.

 

Тук са даден инструкции след това как да ги импортнете обратно след ресет  на браузъра:

https://support.goog...wer/96816?hl=bg

http://www.wikihow.c...rks-from-Chrome

 

За паролите използвайте следния инструмент:

http://www.intowindo...chrome-browser/

 

След това ресетнете браузера на настройки по поразбиране:

 

Моля, изтеглете ZOEK (by Smeenk) и да го запишете на вашия работен плот
Временно деактивирайте вашата антивирусна и антишпионска защита - инструкции тук

  • Щракнете с десния бутон върху тази икона  и изберете Run as Administrator, за да стартирате инструмента.
  • Изчакайте търпеливо, докато  се появи  главната конзола (може да отнеме минута или две).

52b6de58f1952-Zoek_Startpagina_5.0.0.0.P

 

  • В главния прозорец, моля поставете в следния скрипт:
createsrpoint;
autoclean;
chrdefaults;
emptyclsid;
emptyalltemp;
  • Уверете се, че  опцията Scan All Users е маркирана.
  • Натиснете Run Script и изчакайте. Сканирането може да отнеме няколко минути.
  • Когато сканирането приключи, ще се отвори лог файл с име zoek-results.
  • Ако е необходимо рестартиране, той ще се отвори след това.
  • Копирайте съдържанието му в следващия си отговор.

 

  Дневници
 
В следващия си отговор, моля да включите следните дневници:

  • Лог файл с име zoek-results

Иначе, като изключим проблема с рекламите в  Google Chrome  .... как се държи системата като цяло..? Наблюдавате ли някакво подобрение в работата на компютъра..? 

Поради липса на обратна връзка с автора на темата ..същата маркирам като приключена ...Ако има нужда да продължим нека автора да ме уведоми със лично съобщение. Приятен ден..!

  • 3 седмици по-късно...

Темата е активна по искане на автора и..! :)  Моля той да продължи с инструкциите от:

на 27.08.2016 г. в 10:08, icotonev написа:

Здравейте..! Ако след процедурите до тук не се е решил проблема с  Google Chrome  направете  бекъп на паролите и любимите страници ( ако не сте го направили вече):

Експортиране на отметки от Chrome .Backup Chrome Bookmarks

  1. В горния десен ъгъл на прозореца на браузъра кликнете върху менюто на Chrome.
  2. Изберете Отметки > Диспечер на отметките.
  3. Кликнете върху менюто „Организиране“ в диспечера.
  4. Сега изберете Export bookmarks to HTML file.

 

Тук са даден инструкции след това как да ги импортнете обратно след ресет  на браузъра:

https://support.goog...wer/96816?hl=bg

http://www.wikihow.c...rks-from-Chrome

 

За паролите използвайте следния инструмент:

http://www.intowindo...chrome-browser/

 

След това ресетнете браузера на настройки по поразбиране:

 

Моля, изтеглете ZOEK (by Smeenk) и да го запишете на вашия работен плот
Временно деактивирайте вашата антивирусна и антишпионска защита - инструкции тук

  • Щракнете с десния бутон върху тази икона  и изберете Run as Administrator, за да стартирате инструмента.
  • Изчакайте търпеливо, докато  се появи  главната конзола (може да отнеме минута или две).

52b6de58f1952-Zoek_Startpagina_5.0.0.0.P

 

  • В главния прозорец, моля поставете в следния скрипт:

createsrpoint;
autoclean;
chrdefaults;
emptyclsid;
emptyalltemp;
  • Уверете се, че  опцията Scan All Users е маркирана.
  • Натиснете Run Script и изчакайте. Сканирането може да отнеме няколко минути.
  • Когато сканирането приключи, ще се отвори лог файл с име zoek-results.
  • Ако е необходимо рестартиране, той ще се отвори след това.
  • Копирайте съдържанието му в следващия си отговор.

 

  Дневници
 
В следващия си отговор, моля да включите следните дневници:

  • Лог файл с име zoek-results

Иначе, като изключим проблема с рекламите в  Google Chrome  .... как се държи системата като цяло..? Наблюдавате ли някакво подобрение в работата на компютъра..? 

 

  • 2 седмици по-късно...

По искане на автора темата беше активирана миналата седмица за финализиране почистването на системата...Отново няма реакция от автора и..! Темата е "Приключена" ...завинаги..!

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.