Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Съмнения за заразен лаптоп

Featured Replies

Здравейте. Измина доста време от както чистихме за последно машината. Явно гадинките са се навъдили отново. Лаптопа е на моя позната.

Проблема е следния. От известно време се забелязва много бавна и тромава работа на лаптопа. Без никакви включени приложения , процесора се товари на 90 100% ,и се чува силно бучене на перката, а когато се опитаме да включим някое приложение , Лиско на пример, се чака повече от минута. Лаптопа е чистен за прах, от сервиз преди 2 месеца мисля. Друг много странен проблем е че звука напълно му е спрял. Но не знам дали двете неща са  свързани помежду си. Това е за сега , ако имате въпроси , питайте. Благодаря! Ето и логовете

 

FRST

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 21-08-2016 01
Ran by Dzhemal (administrator) on DZHEMAL-HP (26-08-2016 19:16:16)
Running from C:\Users\Dzhemal\Desktop
Loaded Profiles: Dzhemal (Available Profiles: Dzhemal & Guest)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
() C:\Program Files (x86)\Common Files\DeviceHelper\DeviceManager.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccsvchst.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccsvchst.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
() C:\Program Files (x86)\VIVACOM 3G USB MODEM\ModemListener.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
(Easybits) C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe
() C:\Program Files (x86)\OLBPre\OLBPre.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
() C:\Program Files (x86)\VIVACOM 3G USB MODEM\HSPA USB MODEM.exe
(Nullsoft) C:\Program Files (x86)\Winamp\winamp.exe
(Nullsoft) C:\Program Files (x86)\Winamp\winamp.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2480936 2010-12-17] (Synaptics Incorporated)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [525312 2011-01-25] (IDT, Inc.)
HKLM-x32\...\Run: [ModemListener] => C:\Program Files (x86)\VIVACOM 3G USB MODEM\ModemListener.exe [98304 2010-01-27] ()
HKLM-x32\...\Run: [HPOSD] => C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [379960 2011-08-19] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [578944 2012-03-05] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [Magic Desktop for HP notification] => C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe [1444880 2015-11-30] (Easybits)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd)
HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\Run: [Google Update] => C:\Users\Dzhemal\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-28] (Google Inc.)
HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\MountPoints2: F - F:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\MountPoints2: {5fa5e8a3-725e-11e4-a2d8-2c27d7dba7d9} - F:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\MountPoints2: {76c9ea40-887a-11e5-9196-806e6f6e6963} - F:\setup.exe
HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\MountPoints2: {93820bb2-fb5c-11e5-885e-2c27d7dba7d9} - J:\HTC_Sync_Manager_PC.exe
ShellExecuteHooks-x32: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll [52920 2011-04-20] (EasyBits Software Corp.)
Startup: C:\Users\Dzhemal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk [2016-01-14]
ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\OLBPre\OLBPre.exe ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: 127.0.0.1    localhost
Tcpip\Parameters: [DhcpNameServer] 192.168.137.1
Tcpip\..\Interfaces\{076D2BED-0D24-460C-918E-196FE4EEA97E}: [DhcpNameServer] 192.168.137.1
Tcpip\..\Interfaces\{081680D8-998A-4C20-B247-3A6FC448AA3D}: [DhcpNameServer] 194.141.86.3 194.141.0.3 194.141.0.4

Internet Explorer:
==================
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKU\S-1-5-21-966336249-240343522-4042860801-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM -> DefaultScope value is missing
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
SearchScopes: HKLM -> {903E9084-8050-4C90-870A-226613C1C2F5} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/710-111095-2958-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C} URL = 
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/710-111095-2958-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
SearchScopes: HKU\S-1-5-21-966336249-240343522-4042860801-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-966336249-240343522-4042860801-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-966336249-240343522-4042860801-1000 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/710-111095-2958-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
SearchScopes: HKU\S-1-5-21-966336249-240343522-4042860801-1000 -> {EF87F31E-38AE-4881-B513-151ED9619405} URL = hxxp://search.yahoo.com/search?fr=mcafee&p={SearchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2013-07-23] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-22] (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-24] (Google Inc.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-07-23] (Oracle Corporation)
BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2014-12-16] (Adblock Plus)
BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll [2013-02-02] (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\IPS\IPSBHO.DLL [2012-06-21] (Symantec Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-22] (Microsoft Corp.)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-24] (Google Inc.)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-04-20] (Sun Microsystems, Inc.)
BHO-x32: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2014-12-16] (Adblock Plus)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-24] (Google Inc.)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll [2013-02-02] (Symantec Corporation)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-24] (Google Inc.)
DPF: HKLM-x32 {A996E48C-D3DC-4244-89F7-AFA33EC60679} hxxps://ebb.ubb.bg/CAPICOM/capicom.cab
DPF: HKLM-x32 {B015B944-7316-49AE-AC84-ACCA9379EA32} hxxp://77.85.205.2:90/IPCamPluginMJPEG.cab
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation)

FireFox:
========
FF Plugin: @java.com/DTPlugin,version=10.25.2 -> C:\Windows\system32\npDeployJava1.dll [2013-07-23] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2013-07-23] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-966336249-240343522-4042860801-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Dzhemal\AppData\Local\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin HKU\S-1-5-21-966336249-240343522-4042860801-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Dzhemal\AppData\Local\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\IPSFF
FF Extension: (Norton Vulnerability Protection) - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\IPSFF [2013-10-12] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\coFFPlgn
FF Extension: (Norton Toolbar) - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\coFFPlgn [2016-06-06] [not signed]

Chrome: 
=======
CHR DefaultSearchURL: Profile 1 -> hxxp://www.bing.com/search?FORM=__PARAM__DF&PC=__PARAM__&q={searchTerms}
CHR DefaultSearchKeyword: Profile 1 -> bing.com
CHR Plugin: (Shockwave Flash) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\Application\21.0.1180.89\PepperFlash\pepflashplayer.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\Application\52.0.2743.116\gcswf32.dll => No File
CHR Plugin: (Native Client) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\Application\52.0.2743.116\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\Application\52.0.2743.116\pdf.dll => No File
CHR Plugin: (McAfee SiteAdvisor) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.50.146.2_0\McChPlg.dll => No File
CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll => No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll => No File
CHR Plugin: (Java Deployment Toolkit 6.0.240.7) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.)
CHR Plugin: (Java(TM) Platform SE 6 U24) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll => No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll => No File
CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll => No File
CHR Plugin: (McAfee SecurityCenter) - c:\progra~2\mcafee\msc\npmcsn~1.dll => No File
CHR Profile: C:\Users\Dzhemal\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (YouTube) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (uBlock Origin) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2016-08-26]
CHR Extension: (Google Търсене) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Google Документи офлайн) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-18]
CHR Extension: (Плащания в уеб магазина на Chrome) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-07]
CHR Extension: (Gmail) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-30]
CHR Extension: (Chrome Media Router) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-08-20]
CHR HKU\S-1-5-21-966336249-240343522-4042860801-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\Dzhemal\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx <not found>
CHR HKU\S-1-5-21-966336249-240343522-4042860801-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bmkckgpgekmanipelfidlhmkfcjicion] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [jndgbbkddogdjbjdckoheoaakboeccio] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-05-25]
CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\Exts\Chrome.crx [2013-09-16]
StartMenuInternet: Google Chrome.PECBBCEAM7EKEESMXUJI2TS4CM - C:\Users\Dzhemal\AppData\Local\Google\Chrome\Application\chrome.exe

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1364096 2016-05-25] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1687680 2016-05-25] (Microsoft Corporation)
R2 DeviceManager; C:\Program Files (x86)\Common Files\DeviceHelper\DeviceManager.exe [40960 2009-11-17] () [File not signed]
R2 ezSharedSvc; C:\Windows\SysWOW64\ezSharedSvcHost.exe [514232 2010-04-23] (EasyBits Software AS) [File not signed]
R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [86528 2012-09-27] (Hewlett-Packard Company) [File not signed]
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2372096 2011-02-19] (Realsil Microelectronics Inc.) [File not signed]
R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe [138272 2012-06-16] (Symantec Corporation)
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S4 NMIndexingService; "C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe" [X]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\Definitions\BASHDefs\20150418.001\BHDrvx64.sys [1639128 2015-04-08] (Symantec Corporation)
R1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1309010.00E\ccSetx64.sys [167072 2012-06-07] (Symantec Corporation)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [487216 2014-12-12] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [142640 2014-12-12] (Symantec Corporation)
S3 HtcVCom32; C:\Windows\System32\DRIVERS\HtcVComV64.sys [121800 2010-03-08] (QUALCOMM Incorporated)
R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\Definitions\IPSDefs\20150420.001\IDSvia64.sys [671448 2015-03-24] (Symantec Corporation)
S3 jrdusbser; C:\Windows\System32\DRIVERS\jrdusbser.sys [119680 2009-11-17] (TCT International Mobile Ltd)
S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\Definitions\VirusDefs\20150420.041\ENG64.SYS [129752 2015-04-19] (Symantec Corporation)
S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\Definitions\VirusDefs\20150420.041\EX64.SYS [2137304 2015-04-19] (Symantec Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2015-11-11] (Duplex Secure Ltd.)
S3 SRTSP; C:\Windows\System32\Drivers\NISx64\1309010.00E\SRTSP64.SYS [737952 2012-07-06] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1309010.00E\SRTSPX64.SYS [37536 2012-07-06] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\NISx64\1309010.00E\SYMDS64.SYS [451192 2012-04-17] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\NISx64\1309010.00E\SYMEFA64.SYS [1129120 2012-05-22] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [175736 2012-12-25] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NISx64\1309010.00E\Ironx64.SYS [190072 2012-04-18] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\NISx64\1309010.00E\SYMNETS.SYS [405624 2012-04-18] (Symantec Corporation)
U3 a0op1pbi; C:\Windows\System32\Drivers\a0op1pbi.sys [0 ] (Intel Corporation) <==== ATTENTION (zero byte File/Folder)
S3 clwvd; system32\DRIVERS\clwvd.sys [X]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
U2 wuaserv; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-08-26 19:16 - 2016-08-26 19:18 - 00022609 _____ C:\Users\Dzhemal\Desktop\FRST.txt
2016-08-26 19:15 - 2016-08-26 19:16 - 00000000 ____D C:\FRST
2016-08-26 19:15 - 2016-08-26 19:15 - 02396160 _____ (Farbar) C:\Users\Dzhemal\Desktop\FRST64.exe

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-08-26 19:12 - 2015-12-11 23:40 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-08-26 19:12 - 2013-07-22 22:45 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-08-26 19:03 - 2015-07-20 13:55 - 00000000 ____D C:\Users\Dzhemal\AppData\Roaming\Skype
2016-08-26 19:00 - 2015-12-11 23:40 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-08-26 18:59 - 2012-06-26 17:50 - 00001016 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-966336249-240343522-4042860801-1000UA.job
2016-08-26 18:59 - 2012-06-26 17:50 - 00000964 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-966336249-240343522-4042860801-1000Core.job
2016-08-25 22:14 - 2015-10-18 09:11 - 00000000 ____D C:\Users\Dzhemal\Desktop\E-snimki
2016-08-25 18:41 - 2011-05-30 11:01 - 00000000 ____D C:\ProgramData\Norton
2016-08-25 17:38 - 2009-07-14 08:13 - 00006298 _____ C:\Windows\system32\PerfStringBackup.INI
2016-08-24 21:45 - 2014-04-10 07:30 - 00003198 _____ C:\Windows\System32\Tasks\HPCeeScheduleForDzhemal
2016-08-24 21:45 - 2014-04-10 07:30 - 00000340 _____ C:\Windows\Tasks\HPCeeScheduleForDzhemal.job
2016-08-09 22:33 - 2012-06-26 18:24 - 00002382 _____ C:\Users\Dzhemal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-07-29 18:43 - 2015-12-11 23:40 - 00003894 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-07-29 18:43 - 2015-12-11 23:40 - 00003642 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2016-07-29 18:26 - 2012-06-26 17:50 - 00003990 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-966336249-240343522-4042860801-1000UA
2016-07-29 18:26 - 2012-06-26 17:50 - 00003594 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-966336249-240343522-4042860801-1000Core

==================== Files in the root of some directories =======

2014-06-19 20:32 - 2014-06-19 20:32 - 0000024 _____ () C:\Users\Dzhemal\AppData\Roaming\temp.ini
2013-01-18 22:22 - 2013-01-18 22:22 - 0003584 _____ () C:\Users\Dzhemal\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-11-21 01:11 - 2014-11-21 01:11 - 0007601 _____ () C:\Users\Dzhemal\AppData\Local\Resmon.ResmonCfg

Some files in TEMP:
====================
C:\Users\Dzhemal\AppData\Local\Temp\GoogleUpdateSetup_1.3.21.169.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-08-15 21:18

==================== End of FRST.txt ============================

 

Addition

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 21-08-2016 01
Ran by Dzhemal (26-08-2016 19:21:22)
Running from C:\Users\Dzhemal\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2011-08-19 15:03:06)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-966336249-240343522-4042860801-500 - Administrator - Disabled)
Dzhemal (S-1-5-21-966336249-240343522-4042860801-1000 - Administrator - Enabled) => C:\Users\Dzhemal
Guest (S-1-5-21-966336249-240343522-4042860801-501 - Limited - Disabled) => C:\Users\Guest
HomeGroupUser$ (S-1-5-21-966336249-240343522-4042860801-1002 - Limited - Enabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Norton Internet Security (Disabled - Out of date) {53C7D717-52E2-B95E-FA61-6F32ECC805DB}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Norton Internet Security (Disabled - Out of date) {E8A636F3-74D8-B6D0-C0D1-5440974F4F66}
FW: Norton Internet Security (Disabled) {6BFC5632-188D-B806-D13E-C607121B42A0}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\uTorrent) (Version: 3.4.5.41712 - BitTorrent Inc.)
Adblock Plus за IE (32-битов и 64-битов) (HKLM\...\{BF90EE7E-18AC-497B-99E0-6827E98D63FA}) (Version: 1.3 - Eyeo GmbH)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.7.0.2090 - Adobe Systems Incorporated)
Adobe Flash Player 11 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 11.8.800.94 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Advego Plagiatus 1.3.1.3 (HKLM-x32\...\{86819F43-51E6-4776-ABAF-A5EACBFE1805}}_is1) (Version:  - Advego, Ltd.)
BS.Player FREE (HKLM-x32\...\BSPlayerf) (Version: 2.63.1071 - AB Team, d.o.o.)
Cabela's Big Game Hunter Pro Hunts (HKLM-x32\...\Q2FiZWxhc0JpZ0dhbWVIdW50ZXJQcm9IdW50cw==_is1) (Version: 1 - )
CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.4.5143 - CDBurnerXP)
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.6.5931 - CDBurnerXP)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.47.1.0333 - Disc Soft Ltd)
ESU for Microsoft Windows 7 (HKLM-x32\...\{3877C901-7B90-4727-A639-B6ED2DD59D43}) (Version: 1.0.0 - Hewlett-Packard)
Google Chrome (HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\Google Chrome) (Version: 52.0.2743.116 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.7619.1252 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.21.169 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
HP On Screen Display (HKLM-x32\...\{ED1BD69A-07E3-418C-91F1-D856582581BF}) (Version: 1.3.5 - Hewlett-Packard Company)
HP Power Manager (HKLM-x32\...\{7E799992-5DA0-4A1A-9443-B1836B063FEC}) (Version: 1.4.8 - Hewlett-Packard Company)
HP Quick Launch (HKLM-x32\...\{53B17A98-5BF0-40BC-AAFF-850A357975AC}) (Version: 2.7.2 - Hewlett-Packard Company)
HP Setup (HKLM-x32\...\{210A03F5-B2ED-4947-B27E-516F50CBB292}) (Version: 8.6.4530.3651 - Hewlett-Packard Company)
HP Setup Manager (HKLM-x32\...\{AE856388-AFAD-4753-81DF-D96B19D0A17C}) (Version: 1.1.13253.3682 - Hewlett-Packard Company)
HP Software Framework (HKLM-x32\...\{675D093B-815D-47FD-AB2C-192EC751E8E2}) (Version: 4.6.10.1 - Hewlett-Packard Company)
HP Support Assistant (HKLM-x32\...\{EE202411-2C26-49E8-9784-1BC1DBF7DE96}) (Version: 7.0.39.15 - Hewlett-Packard Company)
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6324.0 - IDT)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2279 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.2.1004 - Intel Corporation)
IPTInstaller (HKLM-x32\...\{08208143-777D-4A06-BB54-71BF0AD1BB70}) (Version: 4.0.9 - HTC)
Java 7 Update 25 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417025FF}) (Version: 7.0.250 - Oracle)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
K-Lite Codec Pack 6.0.0 (Full) (HKLM-x32\...\KLiteCodecPack_is1) (Version: 6.0.0 - )
Magic Desktop (HKLM-x32\...\EasyBits Magic Desktop) (Version: 3.0 - EasyBits Software AS)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
MyPC Backup  (HKLM\...\OLBPre) (Version:  - MyPC Backup) <==== ATTENTION
Norton Internet Security (HKLM-x32\...\NIS) (Version: 19.9.1.14 - Symantec Corporation)
Ralink RT5390 802.11b/g/n WiFi Adapter (HKLM-x32\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 3.2.13.0 - Ralink)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.48.823.2011 - Realtek)
Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7600.77 - Realtek Semiconductor Corp.)
Recovery Manager (x32 Version: 2.0.0 - Hewlett-Packard) Hidden
SA Dictionary 2008 Beta 4 (HKLM-x32\...\{055A5AF0-9FEB-440D-B00A-18935C7C171C}) (Version: 6.6.12 - Stefan Angelov)
Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 8.3.0.9150 - Microsoft Corporation)
Skype™ 7.13 (HKLM-x32\...\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.13.101 - Skype Technologies S.A.)
Speccy (HKLM\...\Speccy) (Version: 1.29 - Piriform)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.2.4.4 - Synaptics Incorporated)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
VIVACOM 3G USB MODEM (HKLM-x32\...\VIVACOM 3G USB MODEM ALCATEL_is1) (Version:  - Alcatel)
Winamp (HKLM-x32\...\Winamp) (Version: 5.57  - Nullsoft, Inc)
Winamp Application Detect (HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
WinRAR archiver (HKLM-x32\...\WinRAR archiver) (Version:  - )

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-966336249-240343522-4042860801-1000_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Dzhemal\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-966336249-240343522-4042860801-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Dzhemal\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => No File

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {17E948B4-5840-4479-A927-EED1C7B2F0EE} - System32\Tasks\{AAAFC7AF-3B57-456B-A4E0-C532DA109A98} => Iexplore.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&amp;ver=7.6.0.105&amp;LastError=12002
Task: {3219DB7E-175F-4B87-8107-981363264FD7} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\WSCStub.exe [2015-08-06] (Symantec Corporation)
Task: {37F50600-8F0C-44DD-BBFE-72DE669080CB} - System32\Tasks\{3ED9213C-364E-424B-9794-9BF14F4FF84A} => Iexplore.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&amp;ver=7.0.0.102&amp;LastError=12002
Task: {4244458F-6275-43A1-96A7-9E6D1A73D267} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\SymErr.exe [2012-02-04] (Symantec Corporation)
Task: {49CCCFA1-85BA-4C6D-A1BF-B44F5DC7B91B} - System32\Tasks\Remediation\AntimalwareMigrationTask => C:\Program Files\Common Files\AV\Norton Internet Security\Upgrade.exe [2015-08-06] (Symantec Corporation)
Task: {57CA1EE8-5FB9-4E8E-A104-E0405DC70F0D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2014-02-10] (Hewlett-Packard)
Task: {606811AB-DF36-4D62-A538-DE81CBE2FCA7} - System32\Tasks\{E7D340C6-2943-4B99-A714-41A208A2D07A} => Iexplore.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&amp;ver=7.0.0.102&amp;LastError=12007
Task: {6C6D50D2-78B4-427E-A427-A5987581177A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-12-13] (Google Inc.)
Task: {878BED2C-6AA2-4C05-97CE-B4AD9D1508E0} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-966336249-240343522-4042860801-1000UA => C:\Users\Dzhemal\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {9D31538F-8BE4-42A1-9CA2-FDC7A3456732} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-966336249-240343522-4042860801-1000Core => C:\Users\Dzhemal\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {A647C214-D348-472E-9317-A078132B8D9E} - System32\Tasks\LaunchPreSignup => C:\Program Files (x86)\OLBPre\OLBPre.exe [2016-01-14] () <==== ATTENTION
Task: {B58F9550-E595-4BE4-8D78-59DBD1B80F7A} - System32\Tasks\HPCeeScheduleForDzhemal => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14] (Hewlett-Packard)
Task: {B7F35B8F-DFB7-4B6F-AEB0-03C8342E329B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-22] (Adobe Systems Incorporated)
Task: {BB7344DA-96B9-4934-B74A-40E023454747} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\SymErr.exe [2012-02-04] (Symantec Corporation)
Task: {F1FD9C52-8AF0-41F7-9C92-7571A9ABB1D7} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-12-13] (Google Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-966336249-240343522-4042860801-1000Core.job => C:\Users\Dzhemal\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-966336249-240343522-4042860801-1000UA.job => C:\Users\Dzhemal\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\HPCeeScheduleForDzhemal.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

Shortcut: C:\Users\Dzhemal\AppData\Local\Microsoft\Windows\GameExplorer\{8D07B7B1-CD24-47AA-8CF6-01D397FCA80A}\SupportTasks\0\More Games from Microsoft.lnk -> hxxp://www.rockstargames.com/sanandreas/
Shortcut: C:\Users\Dzhemal\AppData\Local\Microsoft\Windows\GameExplorer\{200E24CA-3AEB-4553-8E6A-6BD3FA4A0AAA}\SupportTasks\1\Support.lnk -> hxxp://support.ea.com/
Shortcut: C:\Users\Dzhemal\AppData\Local\Microsoft\Windows\GameExplorer\{200E24CA-3AEB-4553-8E6A-6BD3FA4A0AAA}\SupportTasks\0\More Games from Microsoft.lnk -> hxxp://www.ea.com/nfs/carbon/us/home.jsp/

==================== Loaded Modules (Whitelisted) ==============

2011-08-19 20:21 - 2005-06-07 14:26 - 00043008 _____ () C:\Program Files (x86)\WinRAR\rarext64.dll
2011-12-14 16:50 - 2009-11-17 11:44 - 00040960 _____ () C:\Program Files (x86)\Common Files\DeviceHelper\DeviceManager.exe
2013-10-17 16:27 - 2013-10-17 16:27 - 00166912 _____ () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
2011-12-14 16:50 - 2010-01-27 12:08 - 00098304 _____ () C:\Program Files (x86)\VIVACOM 3G USB MODEM\ModemListener.exe
2016-01-14 21:56 - 2016-01-14 21:56 - 02472960 _____ () C:\Program Files (x86)\OLBPre\OLBPre.exe
2016-01-14 21:55 - 2016-01-14 21:55 - 00060928 _____ () C:\Program Files (x86)\OLBPre\LinqBridge.dll
2011-12-14 16:50 - 2010-01-27 12:08 - 01609728 _____ () C:\Program Files (x86)\VIVACOM 3G USB MODEM\Hspa USB Modem.exe
2014-10-25 08:15 - 2014-10-25 08:15 - 00169472 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\9b1cac8d98bd69d3e56a26ff2f96f266\IsdiInterop.ni.dll
2011-05-30 10:50 - 2011-01-13 03:56 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2009-07-14 00:03 - 2009-07-14 04:15 - 00364544 _____ () C:\Windows\SysWOW64\msjetoledb40.dll
2011-12-14 16:50 - 2010-01-27 12:08 - 00040960 _____ () C:\Program Files (x86)\VIVACOM 3G USB MODEM\Driver\InstallWindowHook.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00052224 _____ () C:\Program Files (x86)\Winamp\nsutil.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00076288 _____ () C:\Program Files (x86)\Winamp\nde.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00174080 _____ () C:\Program Files (x86)\Winamp\System\auth.w5s
2009-12-18 03:31 - 2013-12-22 21:57 - 00018432 _____ () C:\Program Files (x86)\Winamp\System\bmp.w5s
2009-12-18 03:31 - 2013-12-22 21:57 - 00047616 _____ () C:\Program Files (x86)\Winamp\zlib.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00014336 _____ () C:\Program Files (x86)\Winamp\System\dlmgr.w5s
2009-12-18 03:31 - 2013-12-22 21:57 - 00014336 _____ () C:\Program Files (x86)\Winamp\System\filereader.w5s
2009-12-18 03:31 - 2013-12-22 21:57 - 00019456 _____ () C:\Program Files (x86)\Winamp\System\gif.w5s
2009-12-18 03:31 - 2013-12-22 21:57 - 00016384 _____ () C:\Program Files (x86)\Winamp\System\gracenote.w5s
2009-12-18 03:31 - 2013-12-22 21:57 - 00623104 _____ () C:\Program Files (x86)\Winamp\System\jnetlib.w5s
2009-12-18 03:31 - 2013-12-22 21:57 - 00154624 _____ () C:\Program Files (x86)\Winamp\System\jpeg.w5s
2009-12-18 03:31 - 2013-12-22 21:57 - 00083968 _____ () C:\Program Files (x86)\Winamp\System\playlist.w5s
2009-12-18 03:31 - 2013-12-22 21:57 - 00084992 _____ () C:\Program Files (x86)\Winamp\System\png.w5s
2009-12-18 03:31 - 2013-12-22 21:57 - 00013824 _____ () C:\Program Files (x86)\Winamp\System\primo.w5s
2009-12-18 03:31 - 2013-12-22 21:57 - 00021504 _____ () C:\Program Files (x86)\Winamp\System\tagz.w5s
2009-12-18 03:31 - 2013-12-22 21:57 - 00035840 _____ () C:\Program Files (x86)\Winamp\System\timer.w5s
2009-12-18 03:31 - 2013-12-22 21:57 - 00090112 _____ () C:\Program Files (x86)\Winamp\System\xml.w5s
2009-12-18 03:31 - 2013-12-22 21:57 - 00066560 _____ () C:\Program Files (x86)\Winamp\Plugins\in_avi.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00102400 _____ () C:\Program Files (x86)\Winamp\Plugins\in_cdda.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00074240 _____ () C:\Program Files (x86)\Winamp\Plugins\in_dshow.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00057344 _____ () C:\Program Files (x86)\Winamp\Plugins\in_flac.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00041984 _____ () C:\Program Files (x86)\Winamp\Plugins\in_flv.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00007168 _____ () C:\Program Files (x86)\Winamp\Plugins\in_linein.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00107008 _____ () C:\Program Files (x86)\Winamp\Plugins\in_midi.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00048640 _____ () C:\Program Files (x86)\Winamp\Plugins\in_mkv.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00162304 _____ () C:\Program Files (x86)\Winamp\Plugins\in_mod.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00284160 _____ () C:\Program Files (x86)\Winamp\Plugins\in_mp3.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00044032 _____ () C:\Program Files (x86)\Winamp\Plugins\in_mp4.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00074240 _____ () C:\Program Files (x86)\Winamp\Plugins\in_nsv.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00023040 _____ () C:\Program Files (x86)\Winamp\Plugins\in_swf.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00217088 _____ () C:\Program Files (x86)\Winamp\Plugins\in_vorbis.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00016384 _____ () C:\Program Files (x86)\Winamp\Plugins\in_wave.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00245760 _____ () C:\Program Files (x86)\Winamp\libsndfile.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00311808 _____ () C:\Program Files (x86)\Winamp\Plugins\in_wm.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00022016 _____ () C:\Program Files (x86)\Winamp\Plugins\out_disk.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00050688 _____ () C:\Program Files (x86)\Winamp\Plugins\out_ds.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00018432 _____ () C:\Program Files (x86)\Winamp\Plugins\out_wave.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 01735680 _____ () C:\Program Files (x86)\Winamp\Plugins\gen_ff.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00083968 _____ () C:\Program Files (x86)\Winamp\tataki.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00340992 _____ () C:\Program Files (x86)\Winamp\Plugins\freeform\wacs\freetype\freetype.wac
2009-12-18 03:31 - 2013-12-22 21:57 - 00026624 _____ () C:\Program Files (x86)\Winamp\Plugins\gen_hotkeys.dll
2009-12-16 02:21 - 2013-12-22 21:57 - 00212480 _____ () C:\Program Files (x86)\Winamp\Plugins\gen_jumpex.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00304640 _____ () C:\Program Files (x86)\Winamp\Plugins\gen_ml.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00288768 _____ () C:\Program Files (x86)\Winamp\Plugins\ml_local.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00081920 _____ () C:\Program Files (x86)\Winamp\Plugins\ml_playlists.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00121344 _____ () C:\Program Files (x86)\Winamp\Plugins\ml_online.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00198144 _____ () C:\Program Files (x86)\Winamp\Plugins\ml_disc.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00212480 _____ () C:\Program Files (x86)\Winamp\Plugins\ml_pmp.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00113152 _____ () C:\Program Files (x86)\Winamp\Plugins\pmp_ipod.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00020992 _____ () C:\Program Files (x86)\Winamp\Plugins\pmp_njb.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00115200 _____ () C:\Program Files (x86)\Winamp\Plugins\pmp_p4s.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00050176 _____ () C:\Program Files (x86)\Winamp\Plugins\pmp_usb.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00023040 _____ () C:\Program Files (x86)\Winamp\Plugins\ml_bookmarks.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00048128 _____ () C:\Program Files (x86)\Winamp\Plugins\ml_history.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00028672 _____ () C:\Program Files (x86)\Winamp\Plugins\ml_autotag.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00053248 _____ () C:\Program Files (x86)\Winamp\Plugins\ml_impex.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00061952 _____ () C:\Program Files (x86)\Winamp\Plugins\ml_plg.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00033280 _____ () C:\Program Files (x86)\Winamp\Plugins\ml_rg.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00031232 _____ () C:\Program Files (x86)\Winamp\Plugins\ml_transcode.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00057344 _____ () C:\Program Files (x86)\Winamp\Plugins\gen_orgler.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00024064 _____ () C:\Program Files (x86)\Winamp\Plugins\gen_tray.dll
2009-12-18 03:31 - 2013-12-22 21:57 - 00237056 _____ () C:\Program Files (x86)\Winamp\System\aacPlusDecoder.w5s

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\1001movie.com -> 1001movie.com
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\1001night.biz -> 1001night.biz
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\100gal.net -> 100gal.net
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\100sexlinks.com -> 100sexlinks.com

There are 4789 more sites.


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 05:34 - 2014-11-24 00:09 - 00000739 ____N C:\Windows\system32\Drivers\etc\hosts

127.0.0.1    localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-966336249-240343522-4042860801-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Dzhemal\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.137.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Adobe Reader Speed Launcher => 
MSCONFIG\startupreg: BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} => "C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe"
MSCONFIG\startupreg: BingSvc => C:\Users\Dzhemal\AppData\Local\Microsoft\BingSvc\BingSvc.exe
MSCONFIG\startupreg: DAEMON Tools Lite => 
MSCONFIG\startupreg: Easybits Recovery => C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
MSCONFIG\startupreg: Google Update => "C:\Users\Dzhemal\AppData\Local\Google\Update\GoogleUpdate.exe" /c
MSCONFIG\startupreg: GoogleDriveSync => "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
MSCONFIG\startupreg: IAStorIcon => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: SunJavaUpdateSched => 

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{9BF25C51-4C12-48EC-9F08-9CD5F0D3FFFB}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{42479DBE-68BF-4F7E-AF37-66711D560892}] => (Allow) LPort=2869
FirewallRules: [{F7D19BD8-7A94-448F-9EC6-F3BD278972A2}] => (Allow) LPort=1900
FirewallRules: [{63A2BFE8-DA65-4285-90E9-0EBA277E154F}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{208B53D3-6B30-4D99-A53A-F0F7E7AAE949}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{EC95A8C2-2D2F-4135-8A42-FBBC7CCF8569}] => (Allow) C:\Windows\system32\ezSharedSvcHost.exe
FirewallRules: [{B99C1DE5-D04F-402A-B70E-A46F45781AA1}] => (Allow) C:\Program Files (x86)\EasyBits For Kids\ezDesktop.exe
FirewallRules: [{28B8A17F-2D8B-4587-A368-0EE3F32DDEAA}] => (Allow) C:\Users\Dzhemal\AppData\Local\Temp\7zS898B.tmp\SymNRT.exe
FirewallRules: [{790B5446-616B-4D59-8130-7FF846427F59}] => (Allow) C:\Users\Dzhemal\AppData\Local\Temp\7zS898B.tmp\SymNRT.exe
FirewallRules: [{E7A6784D-34FA-4A79-A770-A14CC6226B3E}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPDeviceDetection3.exe
FirewallRules: [{65758C9E-F964-4112-ADAF-0BEDAB0C6E30}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [TCP Query User{92FF9F0D-7301-4728-A42A-E22CD6E7F46F}C:\users\dzhemal\appdata\roaming\utorrent\utorrent.exe] => (Block) C:\users\dzhemal\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [UDP Query User{70747BAC-9EA1-4D8B-BF01-C64CDB95D20C}C:\users\dzhemal\appdata\roaming\utorrent\utorrent.exe] => (Block) C:\users\dzhemal\appdata\roaming\utorrent\utorrent.exe

==================== Restore Points =========================

05-06-2016 20:01:36 Windows Backup
12-06-2016 19:08:26 Windows Backup
19-06-2016 22:08:45 Windows Backup
27-06-2016 12:09:09 Windows Backup
03-07-2016 21:52:15 Windows Backup
10-07-2016 21:37:46 Windows Backup
17-07-2016 21:19:34 Windows Backup
24-07-2016 19:18:04 Windows Backup
31-07-2016 19:00:15 Windows Backup
07-08-2016 22:05:17 Windows Backup
14-08-2016 19:38:59 Windows Backup
21-08-2016 20:03:35 Windows Backup

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (08/25/2016 05:38:26 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

Error: (08/25/2016 05:38:26 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

Error: (08/24/2016 05:47:51 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

Error: (08/24/2016 05:47:51 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

Error: (08/24/2016 05:44:39 PM) (Source: RasClient) (EventID: 20227) (User: )
Description: CoId={37148371-D87D-42AA-8AB1-0B357503DF8E}: The user Dzhemal-HP\Dzhemal dialed a connection named VIVACOM which has failed. The error code returned on failure is 797.

Error: (08/24/2016 05:44:38 PM) (Source: RasClient) (EventID: 20227) (User: )
Description: CoId={F1060CE0-F28A-4659-86E0-0AA578D335AB}: The user Dzhemal-HP\Dzhemal dialed a connection named VIVACOM which has failed. The error code returned on failure is 797.

Error: (08/24/2016 05:44:37 PM) (Source: RasClient) (EventID: 20227) (User: )
Description: CoId={B0455E81-9CD5-4E76-A729-6574C152A4B3}: The user Dzhemal-HP\Dzhemal dialed a connection named VIVACOM which has failed. The error code returned on failure is 797.

Error: (08/24/2016 05:44:27 PM) (Source: RasClient) (EventID: 20227) (User: )
Description: CoId={28C0CE0C-33FD-4A30-808A-4A7B91165700}: The user Dzhemal-HP\Dzhemal dialed a connection named VIVACOM which has failed. The error code returned on failure is 797.

Error: (08/23/2016 09:58:18 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

Error: (08/23/2016 09:58:18 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.


System errors:
=============
Error: (08/26/2016 01:57:57 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Netman service.

Error: (08/24/2016 04:49:58 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Netman service.

Error: (08/23/2016 05:22:16 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.

Error: (08/22/2016 10:48:27 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Netman service.

Error: (08/21/2016 08:11:30 PM) (Source: VDS Basic Provider) (EventID: 1) (User: )
Description: Unexpected failure. Error code: 490@01010004

Error: (08/19/2016 09:45:37 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the LanmanServer service.

Error: (08/18/2016 09:47:49 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the LanmanServer service.

Error: (08/18/2016 03:30:56 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.

Error: (08/15/2016 06:25:20 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the NIS service.

Error: (08/15/2016 04:56:45 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.


==================== Memory info =========================== 

Processor: Intel(R) Pentium(R) CPU B940 @ 2.00GHz
Percentage of memory in use: 60%
Total physical RAM: 4043.86 MB
Available physical RAM: 1610.5 MB
Total Virtual: 8085.91 MB
Available Virtual: 4074.05 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:342.96 GB) (Free:227.9 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (RECOVERY) (Fixed) (Total:13.51 GB) (Free:1.48 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive f: (Cabela's Big Gam) (CDROM) (Total:3.57 GB) (Free:0 GB) CDFS
Drive g: (Local Disk) (Fixed) (Total:341.86 GB) (Free:85.43 GB) NTFS
Drive h: (HP_TOOLS) (Fixed) (Total:0.1 GB) (Free:0.07 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 698.6 GB) (Disk ID: D91F86F8)
Partition 1: (Not Active) - (Size=993 KB) - (Type=42)
Partition 2: (Active) - (Size=199 MB) - (Type=42)
Partition 3: (Not Active) - (Size=343 GB) - (Type=42)
Partition 4: (Not Active) - (Size=355.5 GB) - (Type=42)

==================== End of Addition.txt ============================

 

Здравейте.

Стъпка 1

  • Деинсталирайте следния софтуер от контролния панел
Цитат

MyPC Backup

 

Стъпка 2

Изтеглете: 8864097u.png ADWCleaner.

  • Затворете всички браузъри и стартирайте AdwCleaner.exe.
  • Натиснете бутона SCAN.
  • След като приключи проверката натиснете бутона CLEAN.
  • Програмата ще затвори излишния софтуер и ще започне почистването.
  • След като приключи почистването ADWCleaner ще поиска рестарт. Съгласете се.
  • След зареждането на системата отидете до: C:\AdwCleaner и потърсете лог файл с името AdwCleaner[C1].txt.
  • Публикувайте съдържанието на "AdwCleaner[C1]" в следващия Ви коментар.

 

Стъпка 3

Изтеглете: 8864098w.png JRT.

  • Запазете файла на вашия десктоп.
  • Затворете всички браузъри.
  • Стартирайте JRT.exe.
  • След като се появи съобщението "Press any key to continue . . .". Натиснете което и да е копче от клавиатурата.
  • Програмата ще започне почистването. Не прекъсвайте работата и, и не използвайте системата докато протича почистването.
  • След като приключи почистването ще се отвори лог файл, който се намира на десктопа с име JRT.txt.
  • Копирайте съдържанието му и го поставете към следващия Ви коментар.

 

Стъпка 4

  • Направете нови логове с FRST и ги прикачете към следващия ви коментар.
  • Автор

# AdwCleaner v6.010 - Logfile created 27/08/2016 at 00:22:55
# Updated on 12/08/2016 by ToolsLib
# Database : 2016-08-25.1 [Server]
# Operating System : Windows 7 Home Premium Service Pack 1 (X64)
# Username : Dzhemal - DZHEMAL-HP
# Running from : C:\Users\Dzhemal\Desktop\adwcleaner_6.010.exe
# Mode: Clean
# Support : https://toolslib.net/forum

***** [ Services ] *****

***** [ Folders ] *****

[-] Folder deleted: C:\Users\Dzhemal\AppData\Roaming\OpenCandy
[-] Folder deleted: C:\Program Files (x86)\OLBPre
[-] Folder deleted: C:\extensions


***** [ Files ] *****

***** [ DLL ] *****

***** [ WMI ] *****

***** [ Shortcuts ] *****

***** [ Scheduled Tasks ] *****

***** [ Registry ] *****

[-] Key deleted: HKLM\SOFTWARE\14919ea49a8f3b4aa3cf1058d9a64cec
[-] Key deleted: HKLM\SOFTWARE\Classes\OCComSDK.ComSDK
[-] Key deleted: HKLM\SOFTWARE\Classes\OCComSDK.ComSDK.1
[-] Key deleted: [x64] HKLM\SOFTWARE\Classes\Interface\{FA7B2795-C0C8-4A58-8672-3F8D80CC0270}
[-] Key deleted: [x64] HKLM\SOFTWARE\Classes\Interface\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{3CCC052E-BDEE-408A-BEA7-90914EF2964B}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{61F47056-E400-43D3-AF1E-AB7DFFD4C4AD}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{E2B98EEA-EE55-4E9B-A8C1-6E5288DF785A}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{B9D64D3B-BE75-4FA2-B94A-C4AE772A0146}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{FA7B2795-C0C8-4A58-8672-3F8D80CC0270}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A}
[-] Key deleted: HKLM\SOFTWARE\Classes\TypeLib\{1112F282-7099-4624-A439-DB29D6551552}
[-] Key deleted: HKU\.DEFAULT\Software\IBUpdaterService
[-] Key deleted: HKU\S-1-5-21-966336249-240343522-4042860801-1000\Software\Conduit
[-] Key deleted: HKU\S-1-5-21-966336249-240343522-4042860801-1000\Software\PRODUCTSETUP
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-966336249-240343522-4042860801-1000\Software\Smiley Bar for Facebook
[#] Key deleted on reboot: HKU\S-1-5-18\Software\IBUpdaterService
[#] Key deleted on reboot: HKCU\Software\Conduit
[#] Key deleted on reboot: HKCU\Software\PRODUCTSETUP
[-] Value deleted: HKU\S-1-5-21-966336249-240343522-4042860801-1000\Software\Microsoft\Internet Explorer\SearchScopes [DoNotAskAgain]
[#] Value deleted on reboot: HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DoNotAskAgain]
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cdn.castplatform.com


***** [ Web browsers ] *****

*************************

:: "Tracing" keys deleted
:: Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [2951 Bytes] - [27/08/2016 00:22:55]
C:\AdwCleaner\AdwCleaner[S0].txt - [3113 Bytes] - [27/08/2016 00:22:18]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [3097 Bytes] ##########
 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.7 (07.03.2016)
Operating System: Windows 7 Home Premium x64 
Ran by Dzhemal (Administrator) on бкЎ 27.08.2016 Ј. at  0:28:23,01
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


File System: 11 

Successfully deleted: C:\ProgramData\productdata (Folder) 
Successfully deleted: C:\Users\Dzhemal\AppData\Local\{43478160-C75D-4297-9B89-CC2BB01A0529} (Empty Folder)
Successfully deleted: C:\Users\Dzhemal\AppData\Local\{C8B19AB0-2FB2-4618-AF15-20EF90F49F64} (Empty Folder)
Successfully deleted: C:\Users\Dzhemal\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0ENVC778 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Dzhemal\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B2SX97NH (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Dzhemal\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ILYGT90K (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Dzhemal\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\N85I0A53 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0ENVC778 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B2SX97NH (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ILYGT90K (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\N85I0A53 (Temporary Internet Files Folder) 

Registry: 1 

Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EF87F31E-38AE-4881-B513-151ED9619405} (Registry Key)


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on бкЎ 27.08.2016 Ј. at  0:32:18,68
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 21-08-2016 01
Ran by Dzhemal (administrator) on DZHEMAL-HP (27-08-2016 00:35:00)
Running from C:\Users\Dzhemal\Desktop
Loaded Profiles: Dzhemal (Available Profiles: Dzhemal & Guest)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
() C:\Program Files (x86)\Common Files\DeviceHelper\DeviceManager.exe
(EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccsvchst.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccsvchst.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Users\Dzhemal\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Dzhemal\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Dzhemal\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Dzhemal\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Dzhemal\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Dzhemal\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2480936 2010-12-17] (Synaptics Incorporated)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [525312 2011-01-25] (IDT, Inc.)
HKLM-x32\...\Run: [ModemListener] => C:\Program Files (x86)\VIVACOM 3G USB MODEM\ModemListener.exe [98304 2010-01-27] ()
HKLM-x32\...\Run: [HPOSD] => C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [379960 2011-08-19] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [578944 2012-03-05] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [Magic Desktop for HP notification] => C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe [1444880 2015-11-30] (Easybits)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\Run: [Google Update] => C:\Users\Dzhemal\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-28] (Google Inc.)
HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\MountPoints2: F - F:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\MountPoints2: {5fa5e8a3-725e-11e4-a2d8-2c27d7dba7d9} - F:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\MountPoints2: {76c9ea40-887a-11e5-9196-806e6f6e6963} - F:\setup.exe
HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\MountPoints2: {93820bb2-fb5c-11e5-885e-2c27d7dba7d9} - J:\HTC_Sync_Manager_PC.exe
ShellExecuteHooks-x32: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll [52920 2011-04-20] (EasyBits Software Corp.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: 127.0.0.1    localhost
Tcpip\Parameters: [DhcpNameServer] 192.168.137.1
Tcpip\..\Interfaces\{076D2BED-0D24-460C-918E-196FE4EEA97E}: [DhcpNameServer] 192.168.137.1
Tcpip\..\Interfaces\{081680D8-998A-4C20-B247-3A6FC448AA3D}: [DhcpNameServer] 194.141.86.3 194.141.0.3 194.141.0.4

Internet Explorer:
==================
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKU\S-1-5-21-966336249-240343522-4042860801-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM -> DefaultScope value is missing
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
SearchScopes: HKLM -> {903E9084-8050-4C90-870A-226613C1C2F5} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/710-111095-2958-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C} URL = 
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/710-111095-2958-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
SearchScopes: HKU\S-1-5-21-966336249-240343522-4042860801-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-966336249-240343522-4042860801-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-966336249-240343522-4042860801-1000 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/710-111095-2958-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2013-07-23] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-22] (Microsoft Corp.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-07-23] (Oracle Corporation)
BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2014-12-16] (Adblock Plus)
BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll [2013-02-02] (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\IPS\IPSBHO.DLL [2012-06-21] (Symantec Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-22] (Microsoft Corp.)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-04-20] (Sun Microsystems, Inc.)
BHO-x32: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2014-12-16] (Adblock Plus)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll [2013-02-02] (Symantec Corporation)
DPF: HKLM-x32 {A996E48C-D3DC-4244-89F7-AFA33EC60679} hxxps://ebb.ubb.bg/CAPICOM/capicom.cab
DPF: HKLM-x32 {B015B944-7316-49AE-AC84-ACCA9379EA32} hxxp://77.85.205.2:90/IPCamPluginMJPEG.cab
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation)

FireFox:
========
FF Plugin: @java.com/DTPlugin,version=10.25.2 -> C:\Windows\system32\npDeployJava1.dll [2013-07-23] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2013-07-23] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-966336249-240343522-4042860801-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Dzhemal\AppData\Local\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin HKU\S-1-5-21-966336249-240343522-4042860801-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Dzhemal\AppData\Local\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\IPSFF
FF Extension: (Norton Vulnerability Protection) - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\IPSFF [2013-10-12] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\coFFPlgn
FF Extension: (Norton Toolbar) - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\coFFPlgn [2016-08-27] [not signed]

Chrome: 
=======
CHR DefaultSearchURL: Profile 1 -> hxxp://www.bing.com/search?FORM=__PARAM__DF&PC=__PARAM__&q={searchTerms}
CHR DefaultSearchKeyword: Profile 1 -> bing.com
CHR Plugin: (Shockwave Flash) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\Application\21.0.1180.89\PepperFlash\pepflashplayer.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\Application\52.0.2743.116\gcswf32.dll => No File
CHR Plugin: (Native Client) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\Application\52.0.2743.116\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\Application\52.0.2743.116\pdf.dll => No File
CHR Plugin: (McAfee SiteAdvisor) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.50.146.2_0\McChPlg.dll => No File
CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll => No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll => No File
CHR Plugin: (Java Deployment Toolkit 6.0.240.7) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.)
CHR Plugin: (Java(TM) Platform SE 6 U24) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll => No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll => No File
CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll => No File
CHR Plugin: (McAfee SecurityCenter) - c:\progra~2\mcafee\msc\npmcsn~1.dll => No File
CHR Profile: C:\Users\Dzhemal\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (YouTube) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (uBlock Origin) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2016-08-26]
CHR Extension: (Google Търсене) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Google Документи офлайн) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-18]
CHR Extension: (Плащания в уеб магазина на Chrome) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-07]
CHR Extension: (Gmail) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-30]
CHR Extension: (Chrome Media Router) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-08-20]
CHR HKU\S-1-5-21-966336249-240343522-4042860801-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\Dzhemal\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx <not found>
CHR HKU\S-1-5-21-966336249-240343522-4042860801-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bmkckgpgekmanipelfidlhmkfcjicion] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [jndgbbkddogdjbjdckoheoaakboeccio] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-05-25]
CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\Exts\Chrome.crx [2013-09-16]
StartMenuInternet: Google Chrome.PECBBCEAM7EKEESMXUJI2TS4CM - C:\Users\Dzhemal\AppData\Local\Google\Chrome\Application\chrome.exe

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1364096 2016-05-25] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1687680 2016-05-25] (Microsoft Corporation)
R2 DeviceManager; C:\Program Files (x86)\Common Files\DeviceHelper\DeviceManager.exe [40960 2009-11-17] () [File not signed]
R2 ezSharedSvc; C:\Windows\SysWOW64\ezSharedSvcHost.exe [514232 2010-04-23] (EasyBits Software AS) [File not signed]
R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [86528 2012-09-27] (Hewlett-Packard Company) [File not signed]
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2372096 2011-02-19] (Realsil Microelectronics Inc.) [File not signed]
R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe [138272 2012-06-16] (Symantec Corporation)
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S4 NMIndexingService; "C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe" [X]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\Definitions\BASHDefs\20150418.001\BHDrvx64.sys [1639128 2015-04-08] (Symantec Corporation)
R1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1309010.00E\ccSetx64.sys [167072 2012-06-07] (Symantec Corporation)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [487216 2014-12-12] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [142640 2014-12-12] (Symantec Corporation)
S3 HtcVCom32; C:\Windows\System32\DRIVERS\HtcVComV64.sys [121800 2010-03-08] (QUALCOMM Incorporated)
R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\Definitions\IPSDefs\20150420.001\IDSvia64.sys [671448 2015-03-24] (Symantec Corporation)
S3 jrdusbser; C:\Windows\System32\DRIVERS\jrdusbser.sys [119680 2009-11-17] (TCT International Mobile Ltd)
S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\Definitions\VirusDefs\20150420.041\ENG64.SYS [129752 2015-04-19] (Symantec Corporation)
S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\Definitions\VirusDefs\20150420.041\EX64.SYS [2137304 2015-04-19] (Symantec Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2015-11-11] (Duplex Secure Ltd.)
S3 SRTSP; C:\Windows\System32\Drivers\NISx64\1309010.00E\SRTSP64.SYS [737952 2012-07-06] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1309010.00E\SRTSPX64.SYS [37536 2012-07-06] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\NISx64\1309010.00E\SYMDS64.SYS [451192 2012-04-17] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\NISx64\1309010.00E\SYMEFA64.SYS [1129120 2012-05-22] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [175736 2012-12-25] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NISx64\1309010.00E\Ironx64.SYS [190072 2012-04-18] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\NISx64\1309010.00E\SYMNETS.SYS [405624 2012-04-18] (Symantec Corporation)
S3 clwvd; system32\DRIVERS\clwvd.sys [X]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
U2 wuaserv; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-08-27 00:35 - 2016-08-27 00:35 - 00021032 _____ C:\Users\Dzhemal\Desktop\FRST.txt
2016-08-27 00:32 - 2016-08-27 00:34 - 00002299 _____ C:\Users\Dzhemal\Desktop\JRT.txt
2016-08-27 00:27 - 2016-08-27 00:27 - 01610560 _____ (Malwarebytes) C:\Users\Dzhemal\Desktop\JRT.exe
2016-08-27 00:26 - 2016-08-27 00:26 - 00003184 _____ C:\Users\Dzhemal\Desktop\AdwCleaner[C0].txt
2016-08-27 00:20 - 2016-08-27 00:22 - 00000000 ____D C:\AdwCleaner
2016-08-27 00:18 - 2016-08-27 00:20 - 03826240 _____ C:\Users\Dzhemal\Desktop\adwcleaner_6.010.exe
2016-08-27 00:13 - 2016-07-22 13:48 - 06500888 _____ (Geek Uninstaller) C:\Users\Dzhemal\Desktop\geek.exe
2016-08-26 19:15 - 2016-08-27 00:35 - 00000000 ____D C:\FRST
2016-08-26 19:15 - 2016-08-26 19:15 - 02396160 _____ (Farbar) C:\Users\Dzhemal\Desktop\FRST64.exe

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-08-27 00:31 - 2012-06-26 17:50 - 00001016 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-966336249-240343522-4042860801-1000UA.job
2016-08-27 00:31 - 2009-07-14 07:45 - 00032064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-08-27 00:31 - 2009-07-14 07:45 - 00032064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-08-27 00:24 - 2015-12-12 18:27 - 00000000 ____D C:\Program Files\Google
2016-08-27 00:24 - 2015-12-11 23:40 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-08-27 00:24 - 2012-08-18 17:51 - 00000000 ____D C:\Program Files (x86)\Google
2016-08-27 00:24 - 2009-07-14 08:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-08-27 00:15 - 2011-08-19 21:57 - 00000000 ____D C:\Users\Dzhemal\AppData\Local\Google
2016-08-27 00:12 - 2015-08-11 22:28 - 00000000 ____D C:\Windows\System32\Tasks\Remediation
2016-08-27 00:12 - 2013-07-22 22:45 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-08-26 19:48 - 2015-12-11 23:40 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-08-26 19:03 - 2015-07-20 13:55 - 00000000 ____D C:\Users\Dzhemal\AppData\Roaming\Skype
2016-08-26 18:59 - 2012-06-26 17:50 - 00000964 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-966336249-240343522-4042860801-1000Core.job
2016-08-25 22:14 - 2015-10-18 09:11 - 00000000 ____D C:\Users\Dzhemal\Desktop\E-snimki
2016-08-25 18:41 - 2011-05-30 11:01 - 00000000 ____D C:\ProgramData\Norton
2016-08-25 17:38 - 2009-07-14 08:13 - 00006298 _____ C:\Windows\system32\PerfStringBackup.INI
2016-08-24 21:45 - 2014-04-10 07:30 - 00003198 _____ C:\Windows\System32\Tasks\HPCeeScheduleForDzhemal
2016-08-24 21:45 - 2014-04-10 07:30 - 00000340 _____ C:\Windows\Tasks\HPCeeScheduleForDzhemal.job
2016-08-09 22:33 - 2012-06-26 18:24 - 00002382 _____ C:\Users\Dzhemal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-07-29 18:43 - 2015-12-11 23:40 - 00003894 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-07-29 18:43 - 2015-12-11 23:40 - 00003642 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2016-07-29 18:26 - 2012-06-26 17:50 - 00003990 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-966336249-240343522-4042860801-1000UA
2016-07-29 18:26 - 2012-06-26 17:50 - 00003594 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-966336249-240343522-4042860801-1000Core

==================== Files in the root of some directories =======

2014-06-19 20:32 - 2014-06-19 20:32 - 0000024 _____ () C:\Users\Dzhemal\AppData\Roaming\temp.ini
2013-01-18 22:22 - 2013-01-18 22:22 - 0003584 _____ () C:\Users\Dzhemal\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-11-21 01:11 - 2014-11-21 01:11 - 0007601 _____ () C:\Users\Dzhemal\AppData\Local\Resmon.ResmonCfg

Some files in TEMP:
====================
C:\Users\Dzhemal\AppData\Local\Temp\GoogleUpdateSetup_1.3.21.169.exe
C:\Users\Dzhemal\AppData\Local\Temp\libeay32.dll
C:\Users\Dzhemal\AppData\Local\Temp\msvcr120.dll
C:\Users\Dzhemal\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-08-15 21:18

==================== End of FRST.txt ============================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 21-08-2016 01
Ran by Dzhemal (27-08-2016 00:36:25)
Running from C:\Users\Dzhemal\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2011-08-19 15:03:06)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-966336249-240343522-4042860801-500 - Administrator - Disabled)
Dzhemal (S-1-5-21-966336249-240343522-4042860801-1000 - Administrator - Enabled) => C:\Users\Dzhemal
Guest (S-1-5-21-966336249-240343522-4042860801-501 - Limited - Disabled) => C:\Users\Guest
HomeGroupUser$ (S-1-5-21-966336249-240343522-4042860801-1002 - Limited - Enabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Norton Internet Security (Disabled - Out of date) {53C7D717-52E2-B95E-FA61-6F32ECC805DB}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Norton Internet Security (Disabled - Out of date) {E8A636F3-74D8-B6D0-C0D1-5440974F4F66}
FW: Norton Internet Security (Disabled) {6BFC5632-188D-B806-D13E-C607121B42A0}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\uTorrent) (Version: 3.4.5.41712 - BitTorrent Inc.)
Adblock Plus за IE (32-битов и 64-битов) (HKLM\...\{BF90EE7E-18AC-497B-99E0-6827E98D63FA}) (Version: 1.3 - Eyeo GmbH)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.7.0.2090 - Adobe Systems Incorporated)
Adobe Flash Player 11 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 11.8.800.94 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Advego Plagiatus 1.3.1.3 (HKLM-x32\...\{86819F43-51E6-4776-ABAF-A5EACBFE1805}}_is1) (Version:  - Advego, Ltd.)
BS.Player FREE (HKLM-x32\...\BSPlayerf) (Version: 2.63.1071 - AB Team, d.o.o.)
Cabela's Big Game Hunter Pro Hunts (HKLM-x32\...\Q2FiZWxhc0JpZ0dhbWVIdW50ZXJQcm9IdW50cw==_is1) (Version: 1 - )
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
ESU for Microsoft Windows 7 (HKLM-x32\...\{3877C901-7B90-4727-A639-B6ED2DD59D43}) (Version: 1.0.0 - Hewlett-Packard)
Google Chrome (HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\Google Chrome) (Version: 52.0.2743.116 - Google Inc.)
Google Update Helper (x32 Version: 1.3.21.169 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
HP On Screen Display (HKLM-x32\...\{ED1BD69A-07E3-418C-91F1-D856582581BF}) (Version: 1.3.5 - Hewlett-Packard Company)
HP Power Manager (HKLM-x32\...\{7E799992-5DA0-4A1A-9443-B1836B063FEC}) (Version: 1.4.8 - Hewlett-Packard Company)
HP Quick Launch (HKLM-x32\...\{53B17A98-5BF0-40BC-AAFF-850A357975AC}) (Version: 2.7.2 - Hewlett-Packard Company)
HP Setup (HKLM-x32\...\{210A03F5-B2ED-4947-B27E-516F50CBB292}) (Version: 8.6.4530.3651 - Hewlett-Packard Company)
HP Setup Manager (HKLM-x32\...\{AE856388-AFAD-4753-81DF-D96B19D0A17C}) (Version: 1.1.13253.3682 - Hewlett-Packard Company)
HP Software Framework (HKLM-x32\...\{675D093B-815D-47FD-AB2C-192EC751E8E2}) (Version: 4.6.10.1 - Hewlett-Packard Company)
HP Support Assistant (HKLM-x32\...\{EE202411-2C26-49E8-9784-1BC1DBF7DE96}) (Version: 7.0.39.15 - Hewlett-Packard Company)
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6324.0 - IDT)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2279 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.2.1004 - Intel Corporation)
IPTInstaller (HKLM-x32\...\{08208143-777D-4A06-BB54-71BF0AD1BB70}) (Version: 4.0.9 - HTC)
Java 7 Update 25 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417025FF}) (Version: 7.0.250 - Oracle)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
K-Lite Codec Pack 6.0.0 (Full) (HKLM-x32\...\KLiteCodecPack_is1) (Version: 6.0.0 - )
Magic Desktop (HKLM-x32\...\EasyBits Magic Desktop) (Version: 3.0 - EasyBits Software AS)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Norton Internet Security (HKLM-x32\...\NIS) (Version: 19.9.1.14 - Symantec Corporation)
Ralink RT5390 802.11b/g/n WiFi Adapter (HKLM-x32\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 3.2.13.0 - Ralink)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.48.823.2011 - Realtek)
Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7600.77 - Realtek Semiconductor Corp.)
Recovery Manager (x32 Version: 2.0.0 - Hewlett-Packard) Hidden
SA Dictionary 2008 Beta 4 (HKLM-x32\...\{055A5AF0-9FEB-440D-B00A-18935C7C171C}) (Version: 6.6.12 - Stefan Angelov)
Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 8.3.0.9150 - Microsoft Corporation)
Skype™ 7.13 (HKLM-x32\...\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.13.101 - Skype Technologies S.A.)
Speccy (HKLM\...\Speccy) (Version: 1.29 - Piriform)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.2.4.4 - Synaptics Incorporated)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
VIVACOM 3G USB MODEM (HKLM-x32\...\VIVACOM 3G USB MODEM ALCATEL_is1) (Version:  - Alcatel)
Winamp (HKLM-x32\...\Winamp) (Version: 5.57  - Nullsoft, Inc)
Winamp Application Detect (HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
WinRAR archiver (HKLM-x32\...\WinRAR archiver) (Version:  - )

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-966336249-240343522-4042860801-1000_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Dzhemal\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-966336249-240343522-4042860801-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Dzhemal\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => No File

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {17E948B4-5840-4479-A927-EED1C7B2F0EE} - System32\Tasks\{AAAFC7AF-3B57-456B-A4E0-C532DA109A98} => Iexplore.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&amp;ver=7.6.0.105&amp;LastError=12002
Task: {3219DB7E-175F-4B87-8107-981363264FD7} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\WSCStub.exe [2015-08-06] (Symantec Corporation)
Task: {37F50600-8F0C-44DD-BBFE-72DE669080CB} - System32\Tasks\{3ED9213C-364E-424B-9794-9BF14F4FF84A} => Iexplore.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&amp;ver=7.0.0.102&amp;LastError=12002
Task: {4244458F-6275-43A1-96A7-9E6D1A73D267} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\SymErr.exe [2012-02-04] (Symantec Corporation)
Task: {57CA1EE8-5FB9-4E8E-A104-E0405DC70F0D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2014-02-10] (Hewlett-Packard)
Task: {606811AB-DF36-4D62-A538-DE81CBE2FCA7} - System32\Tasks\{E7D340C6-2943-4B99-A714-41A208A2D07A} => Iexplore.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&amp;ver=7.0.0.102&amp;LastError=12007
Task: {6C6D50D2-78B4-427E-A427-A5987581177A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-12-13] (Google Inc.)
Task: {878BED2C-6AA2-4C05-97CE-B4AD9D1508E0} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-966336249-240343522-4042860801-1000UA => C:\Users\Dzhemal\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {9D31538F-8BE4-42A1-9CA2-FDC7A3456732} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-966336249-240343522-4042860801-1000Core => C:\Users\Dzhemal\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {A60E1600-E2DD-4987-9D0C-C634C319A129} - System32\Tasks\Remediation\AntimalwareMigrationTask => C:\Program Files\Common Files\AV\Norton Internet Security\Upgrade.exe [2015-08-06] (Symantec Corporation)
Task: {B58F9550-E595-4BE4-8D78-59DBD1B80F7A} - System32\Tasks\HPCeeScheduleForDzhemal => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14] (Hewlett-Packard)
Task: {B7F35B8F-DFB7-4B6F-AEB0-03C8342E329B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-22] (Adobe Systems Incorporated)
Task: {BB7344DA-96B9-4934-B74A-40E023454747} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\SymErr.exe [2012-02-04] (Symantec Corporation)
Task: {F1FD9C52-8AF0-41F7-9C92-7571A9ABB1D7} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-12-13] (Google Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-966336249-240343522-4042860801-1000Core.job => C:\Users\Dzhemal\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-966336249-240343522-4042860801-1000UA.job => C:\Users\Dzhemal\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\HPCeeScheduleForDzhemal.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

Shortcut: C:\Users\Dzhemal\AppData\Local\Microsoft\Windows\GameExplorer\{8D07B7B1-CD24-47AA-8CF6-01D397FCA80A}\SupportTasks\0\More Games from Microsoft.lnk -> hxxp://www.rockstargames.com/sanandreas/
Shortcut: C:\Users\Dzhemal\AppData\Local\Microsoft\Windows\GameExplorer\{200E24CA-3AEB-4553-8E6A-6BD3FA4A0AAA}\SupportTasks\1\Support.lnk -> hxxp://support.ea.com/
Shortcut: C:\Users\Dzhemal\AppData\Local\Microsoft\Windows\GameExplorer\{200E24CA-3AEB-4553-8E6A-6BD3FA4A0AAA}\SupportTasks\0\More Games from Microsoft.lnk -> hxxp://www.ea.com/nfs/carbon/us/home.jsp/

==================== Loaded Modules (Whitelisted) ==============

2011-12-14 16:50 - 2009-11-17 11:44 - 00040960 _____ () C:\Program Files (x86)\Common Files\DeviceHelper\DeviceManager.exe
2013-10-17 16:27 - 2013-10-17 16:27 - 00166912 _____ () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
2014-10-25 08:15 - 2014-10-25 08:15 - 00169472 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\9b1cac8d98bd69d3e56a26ff2f96f266\IsdiInterop.ni.dll
2011-05-30 10:50 - 2011-01-13 03:56 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2016-08-09 22:33 - 2016-08-03 03:24 - 01771336 _____ () C:\Users\Dzhemal\AppData\Local\Google\Chrome\Application\52.0.2743.116\libglesv2.dll
2016-08-09 22:33 - 2016-08-03 03:23 - 00094024 _____ () C:\Users\Dzhemal\AppData\Local\Google\Chrome\Application\52.0.2743.116\libegl.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\1001movie.com -> 1001movie.com
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\1001night.biz -> 1001night.biz
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\100gal.net -> 100gal.net
IE restricted site: HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\100sexlinks.com -> 100sexlinks.com

There are 4789 more sites.


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 05:34 - 2014-11-24 00:09 - 00000739 ____N C:\Windows\system32\Drivers\etc\hosts

127.0.0.1    localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-966336249-240343522-4042860801-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Dzhemal\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.137.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Adobe Reader Speed Launcher => 
MSCONFIG\startupreg: BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} => "C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe"
MSCONFIG\startupreg: BingSvc => C:\Users\Dzhemal\AppData\Local\Microsoft\BingSvc\BingSvc.exe
MSCONFIG\startupreg: DAEMON Tools Lite => 
MSCONFIG\startupreg: Easybits Recovery => C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
MSCONFIG\startupreg: Google Update => "C:\Users\Dzhemal\AppData\Local\Google\Update\GoogleUpdate.exe" /c
MSCONFIG\startupreg: GoogleDriveSync => "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
MSCONFIG\startupreg: IAStorIcon => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: SunJavaUpdateSched => 

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{9BF25C51-4C12-48EC-9F08-9CD5F0D3FFFB}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{42479DBE-68BF-4F7E-AF37-66711D560892}] => (Allow) LPort=2869
FirewallRules: [{F7D19BD8-7A94-448F-9EC6-F3BD278972A2}] => (Allow) LPort=1900
FirewallRules: [{63A2BFE8-DA65-4285-90E9-0EBA277E154F}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{208B53D3-6B30-4D99-A53A-F0F7E7AAE949}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{EC95A8C2-2D2F-4135-8A42-FBBC7CCF8569}] => (Allow) C:\Windows\system32\ezSharedSvcHost.exe
FirewallRules: [{B99C1DE5-D04F-402A-B70E-A46F45781AA1}] => (Allow) C:\Program Files (x86)\EasyBits For Kids\ezDesktop.exe
FirewallRules: [{28B8A17F-2D8B-4587-A368-0EE3F32DDEAA}] => (Allow) C:\Users\Dzhemal\AppData\Local\Temp\7zS898B.tmp\SymNRT.exe
FirewallRules: [{790B5446-616B-4D59-8130-7FF846427F59}] => (Allow) C:\Users\Dzhemal\AppData\Local\Temp\7zS898B.tmp\SymNRT.exe
FirewallRules: [{E7A6784D-34FA-4A79-A770-A14CC6226B3E}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPDeviceDetection3.exe
FirewallRules: [{65758C9E-F964-4112-ADAF-0BEDAB0C6E30}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [TCP Query User{92FF9F0D-7301-4728-A42A-E22CD6E7F46F}C:\users\dzhemal\appdata\roaming\utorrent\utorrent.exe] => (Block) C:\users\dzhemal\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [UDP Query User{70747BAC-9EA1-4D8B-BF01-C64CDB95D20C}C:\users\dzhemal\appdata\roaming\utorrent\utorrent.exe] => (Block) C:\users\dzhemal\appdata\roaming\utorrent\utorrent.exe

==================== Restore Points =========================

05-06-2016 20:01:36 Windows Backup
12-06-2016 19:08:26 Windows Backup
19-06-2016 22:08:45 Windows Backup
27-06-2016 12:09:09 Windows Backup
03-07-2016 21:52:15 Windows Backup
10-07-2016 21:37:46 Windows Backup
17-07-2016 21:19:34 Windows Backup
24-07-2016 19:18:04 Windows Backup
31-07-2016 19:00:15 Windows Backup
07-08-2016 22:05:17 Windows Backup
14-08-2016 19:38:59 Windows Backup
21-08-2016 20:03:35 Windows Backup
27-08-2016 00:28:37 JRT Pre-Junkware Removal

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (08/25/2016 05:38:26 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

Error: (08/25/2016 05:38:26 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

Error: (08/24/2016 05:47:51 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

Error: (08/24/2016 05:47:51 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

Error: (08/24/2016 05:44:39 PM) (Source: RasClient) (EventID: 20227) (User: )
Description: CoId={37148371-D87D-42AA-8AB1-0B357503DF8E}: The user Dzhemal-HP\Dzhemal dialed a connection named VIVACOM which has failed. The error code returned on failure is 797.

Error: (08/24/2016 05:44:38 PM) (Source: RasClient) (EventID: 20227) (User: )
Description: CoId={F1060CE0-F28A-4659-86E0-0AA578D335AB}: The user Dzhemal-HP\Dzhemal dialed a connection named VIVACOM which has failed. The error code returned on failure is 797.

Error: (08/24/2016 05:44:37 PM) (Source: RasClient) (EventID: 20227) (User: )
Description: CoId={B0455E81-9CD5-4E76-A729-6574C152A4B3}: The user Dzhemal-HP\Dzhemal dialed a connection named VIVACOM which has failed. The error code returned on failure is 797.

Error: (08/24/2016 05:44:27 PM) (Source: RasClient) (EventID: 20227) (User: )
Description: CoId={28C0CE0C-33FD-4A30-808A-4A7B91165700}: The user Dzhemal-HP\Dzhemal dialed a connection named VIVACOM which has failed. The error code returned on failure is 797.

Error: (08/23/2016 09:58:18 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

Error: (08/23/2016 09:58:18 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.


System errors:
=============
Error: (08/27/2016 12:24:26 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
cdrom

Error: (08/27/2016 12:23:13 AM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Search service, but this action failed with the following error: 
%%1056 = An instance of the service is already running.

Error: (08/27/2016 12:22:44 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Modules Installer service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.

Error: (08/27/2016 12:22:44 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Installer service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.

Error: (08/27/2016 12:22:44 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Media Player Network Sharing Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.

Error: (08/27/2016 12:22:43 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel(R) Management and Security Application User Notification Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (08/27/2016 12:22:43 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel(R) Rapid Storage Technology service terminated unexpectedly.  It has done this 1 time(s).

Error: (08/27/2016 12:22:43 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The HP Support Assistant Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.

Error: (08/27/2016 12:22:43 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Search service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.

Error: (08/27/2016 12:22:42 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Live ID Sign-in Assistant service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.


==================== Memory info =========================== 

Processor: Intel(R) Pentium(R) CPU B940 @ 2.00GHz
Percentage of memory in use: 71%
Total physical RAM: 4043.86 MB
Available physical RAM: 1163.62 MB
Total Virtual: 8085.91 MB
Available Virtual: 4790.81 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:342.96 GB) (Free:227.88 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (RECOVERY) (Fixed) (Total:13.51 GB) (Free:1.48 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive g: (Local Disk) (Fixed) (Total:341.86 GB) (Free:85.43 GB) NTFS
Drive h: (HP_TOOLS) (Fixed) (Total:0.1 GB) (Free:0.07 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 698.6 GB) (Disk ID: D91F86F8)
Partition 1: (Not Active) - (Size=993 KB) - (Type=42)
Partition 2: (Active) - (Size=199 MB) - (Type=42)
Partition 3: (Not Active) - (Size=343 GB) - (Type=42)
Partition 4: (Not Active) - (Size=355.5 GB) - (Type=42)

==================== End of Addition.txt ============================

Стъпка 1

Качете следния файл във https://www.virustotal.com/ за проверка и ми дайте линка от сканирането.

Цитат

C:\Users\Dzhemal\AppData\Local\Microsoft\BingSvc\BingSvc.exe

 

Стъпка 2

Изтеглете файла fixlist и го запазете на вашия десктоп.

  • Стартирайте FRST.exe и натиснете бутона FIX веднъж!
  • Почистването ще започне, не използвайте системата!
  • След като приключи, ако ви поиска рестартиране, съгласете се.
  • След като зареди системата публикувайте лог файла с име fixlog.txt, който се намира на десктопа Ви.

Забележка: Текущия фикс да не се използва на други системи!

 

Стъпка 3

Изтеглете: 8864095R.jpg Malwarebytes Anti-Malware.

  • Стартирайте инсталационния файл и следвайте съветника за инсталация.
  • Преди края на инсталацията премахнете отметката от: "Enable free trial of Malwarebytes Anti-Malware Premium" и се уверете че има отметка пред "Launch Malwarebytes Anti-Malware".
  • Отидете до табът Settings => Detection and Protection => сложете отметка на "Scan for rootkits".
  • Отидете до табът Dashboard => натиснете бутона "SCAN NOW".
  • Програмата автоматично ще провери за актуализации и ще започне сканирането.

Забележка: Ако видите съобщението "Could not load DDA driver" натиснете бутона "YES". След което разрешете на системата да се рестартира.

  • След като проверката приключи натиснете бутона "Apply Actions".
  • Системата ще поиска рестарт, съгласете се.
  • След като системата зареди MBAB ще зареди.
  • Отидете до табът History => Applications Logs.
  • Потърсете лог с име "SCAN LOG" с последната дата и час и натиснете върху него.
  • Натиснете бутона EXPORT => Copy to Clipboard.
  • Поставете съдържанието на лога с клавишната комбинация CTRL+V към следващия Ви коментар.

 

Стъпка 4

Изтеглете: 8864024K.jpgEmsissoft Emergency Kit

  • Стартирайте файла и посочете къде да се разархивира програмата - например в (C:\EEK), натискайки бутона Extract.
  • Стартирайте файла Start Emsisoft Emergency Kit от десктопа за да стартирате програмата.
  • Натиснете бутона "Yes", когато бъдете подканени да обновите дефинициите на програмата.
  • След като обновяването на дефинициите приключи натиснете бутона "Scan".
  • Програмата ще Ви попита дали искате да включите засичането на Potentially Unwanted Applications,  натиснете бутона "Yes".
  • Натиснете бутона "Custom Scan". Премахнете от списъка оставете само дял C:\.
  • Натиснете "Next" за да започне проверката.
  • Когато проверката приключи натиснете бутона "View Report".
  • Копирайте съдържанието на лог файла в следващия Ви коментар.

 

 

Усеща ли се подобрение на системата или не?

  • Автор

Здравейте! Ето линк от virustotal:

https://www.virustotal.com/bg/file/ee1535a11a49bf578fc4d00096508ffd0c4e20ec164b3abb92ed6e2800f831c8/analysis/

Fix result of Farbar Recovery Scan Tool (x64) Version: 27-08-2016
Ran by Dzhemal (27-08-2016 14:04:13) Run:1
Running from C:\Users\Dzhemal\Desktop
Loaded Profiles: Dzhemal (Available Profiles: Dzhemal & Guest)
Boot Mode: Normal
==============================================

fixlist content:
*****************
start
HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\MountPoints2: F - F:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\MountPoints2: {5fa5e8a3-725e-11e4-a2d8-2c27d7dba7d9} - F:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\MountPoints2: {76c9ea40-887a-11e5-9196-806e6f6e6963} - F:\setup.exe
HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\MountPoints2: {93820bb2-fb5c-11e5-885e-2c27d7dba7d9} - J:\HTC_Sync_Manager_PC.exe
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
SearchScopes: HKLM -> DefaultScope value is missing
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
SearchScopes: HKLM -> {903E9084-8050-4C90-870A-226613C1C2F5} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/710-111095-2958-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C} URL = 
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/710-111095-2958-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
DPF: HKLM-x32 {A996E48C-D3DC-4244-89F7-AFA33EC60679} hxxps://ebb.ubb.bg/CAPICOM/capicom.cab
DPF: HKLM-x32 {B015B944-7316-49AE-AC84-ACCA9379EA32} hxxp://77.85.205.2:90/IPCamPluginMJPEG.cab
FF Extension: (Norton Toolbar) - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\coFFPlgn [2016-08-27] [not signed]
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll [2013-02-02] (Symantec Corporation)
CHR DefaultSearchURL: Profile 1 -> hxxp://www.bing.com/search?FORM=__PARAM__DF&PC=__PARAM__&q={searchTerms}
CHR Plugin: (McAfee SiteAdvisor) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.50.146.2_0\McChPlg.dll => No File
CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll => No File
CHR Plugin: (McAfee SecurityCenter) - c:\progra~2\mcafee\msc\npmcsn~1.dll => No File
CHR HKU\S-1-5-21-966336249-240343522-4042860801-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bmkckgpgekmanipelfidlhmkfcjicion] - hxxps://clients2.google.com/service/update2/crx
CustomCLSID: HKU\S-1-5-21-966336249-240343522-4042860801-1000_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Dzhemal\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-966336249-240343522-4042860801-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Dzhemal\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => No File
Task: {17E948B4-5840-4479-A927-EED1C7B2F0EE} - System32\Tasks\{AAAFC7AF-3B57-456B-A4E0-C532DA109A98} => Iexplore.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&amp;ver=7.6.0.105&amp;LastError=12002
Task: {37F50600-8F0C-44DD-BBFE-72DE669080CB} - System32\Tasks\{3ED9213C-364E-424B-9794-9BF14F4FF84A} => Iexplore.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&amp;ver=7.0.0.102&amp;LastError=12002
Task: {606811AB-DF36-4D62-A538-DE81CBE2FCA7} - System32\Tasks\{E7D340C6-2943-4B99-A714-41A208A2D07A} => Iexplore.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&amp;ver=7.0.0.102&amp;LastError=12007
FirewallRules: [{42479DBE-68BF-4F7E-AF37-66711D560892}] => (Allow) LPort=2869
FirewallRules: [{F7D19BD8-7A94-448F-9EC6-F3BD278972A2}] => (Allow) LPort=1900
FirewallRules: [{28B8A17F-2D8B-4587-A368-0EE3F32DDEAA}] => (Allow) C:\Users\Dzhemal\AppData\Local\Temp\7zS898B.tmp\SymNRT.exe
FirewallRules: [{790B5446-616B-4D59-8130-7FF846427F59}] => (Allow) C:\Users\Dzhemal\AppData\Local\Temp\7zS898B.tmp\SymNRT.exe
Hosts:
cmd: netsh winsock reset catalog
cmd: ipconfig /flushdns
EmptyTemp:
end
*****************

"HKU\S-1-5-21-966336249-240343522-4042860801-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F" => key removed successfully
"HKU\S-1-5-21-966336249-240343522-4042860801-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5fa5e8a3-725e-11e4-a2d8-2c27d7dba7d9}" => key removed successfully
HKCR\CLSID\{5fa5e8a3-725e-11e4-a2d8-2c27d7dba7d9} => key not found. 
"HKU\S-1-5-21-966336249-240343522-4042860801-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{76c9ea40-887a-11e5-9196-806e6f6e6963}" => key removed successfully
HKCR\CLSID\{76c9ea40-887a-11e5-9196-806e6f6e6963} => key not found. 
"HKU\S-1-5-21-966336249-240343522-4042860801-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{93820bb2-fb5c-11e5-885e-2c27d7dba7d9}" => key removed successfully
HKCR\CLSID\{93820bb2-fb5c-11e5-885e-2c27d7dba7d9} => key not found. 
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\EnableShellExecuteHooks => value removed successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. 
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{903E9084-8050-4C90-870A-226613C1C2F5}" => key removed successfully
HKCR\CLSID\{903E9084-8050-4C90-870A-226613C1C2F5} => key not found. 
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}" => key removed successfully
HKCR\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC} => key not found. 
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. 
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}" => key removed successfully
HKCR\Wow6432Node\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC} => key not found. 
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Code Store Database\Distribution Units\{A996E48C-D3DC-4244-89F7-AFA33EC60679}" => key removed successfully
"HKCR\Wow6432Node\CLSID\{A996E48C-D3DC-4244-89F7-AFA33EC60679}" => key removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Code Store Database\Distribution Units\{B015B944-7316-49AE-AC84-ACCA9379EA32}" => key removed successfully
"HKCR\Wow6432Node\CLSID\{B015B944-7316-49AE-AC84-ACCA9379EA32}" => key removed successfully

"C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\coFFPlgn" folder move:

Could not move "C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\coFFPlgn" => Scheduled to move on reboot.

FF Extension: (Norton Toolbar) - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\coFFPlgn [2016-08-27] [not signed] => not found
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => value removed successfully
HKCR\Wow6432Node\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => key not found. 
Chrome DefaultSearchURL => removed successfully
C:\Users\Dzhemal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.50.146.2_0\McChPlg.dll => not found.
C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll => not found.
c:\progra~2\mcafee\msc\npmcsn~1.dll => not found.
"HKU\S-1-5-21-966336249-240343522-4042860801-1000\SOFTWARE\Google\Chrome\Extensions\bmkckgpgekmanipelfidlhmkfcjicion" => key removed successfully
"HKU\S-1-5-21-966336249-240343522-4042860801-1000_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}" => key removed successfully
"HKU\S-1-5-21-966336249-240343522-4042860801-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{17E948B4-5840-4479-A927-EED1C7B2F0EE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{17E948B4-5840-4479-A927-EED1C7B2F0EE}" => key removed successfully
C:\Windows\System32\Tasks\{AAAFC7AF-3B57-456B-A4E0-C532DA109A98} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{AAAFC7AF-3B57-456B-A4E0-C532DA109A98}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{37F50600-8F0C-44DD-BBFE-72DE669080CB}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{37F50600-8F0C-44DD-BBFE-72DE669080CB}" => key removed successfully
C:\Windows\System32\Tasks\{3ED9213C-364E-424B-9794-9BF14F4FF84A} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{3ED9213C-364E-424B-9794-9BF14F4FF84A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{606811AB-DF36-4D62-A538-DE81CBE2FCA7}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{606811AB-DF36-4D62-A538-DE81CBE2FCA7}" => key removed successfully
C:\Windows\System32\Tasks\{E7D340C6-2943-4B99-A714-41A208A2D07A} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{E7D340C6-2943-4B99-A714-41A208A2D07A}" => key removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{42479DBE-68BF-4F7E-AF37-66711D560892} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F7D19BD8-7A94-448F-9EC6-F3BD278972A2} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{28B8A17F-2D8B-4587-A368-0EE3F32DDEAA} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{790B5446-616B-4D59-8130-7FF846427F59} => value removed successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

========= netsh winsock reset catalog =========


Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.


========= End of CMD: =========


========= ipconfig /flushdns =========


Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========


=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 46845377 B
Java, Flash, Steam htmlcache => 17417 B
Windows/system/drivers => 46835399 B
Edge => 0 B
Chrome => 753801218 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 128 B
systemprofile32 => 128 B
LocalService => 0 B
NetworkService => 0 B
Dzhemal => 195038198 B
Guest => 0 B

RecycleBin => 26277547 B
EmptyTemp: => 1 GB temporary data Removed.

================================

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 27-08-2016 14:07:59)

"C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\coFFPlgn" => Could not move

==== End of Fixlog 14:08:02 ====

  • Автор

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 27.8.2016 г.
Scan Time: 14:18 ч.
Logfile: 
Administrator: Yes

Version: 2.2.1.1043
Malware Database: v2016.08.27.04
Rootkit Database: v2016.08.15.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Dzhemal

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 343999
Time Elapsed: 29 min, 49 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Deep Rootkit Scan: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 2
PUP.Optional.ConduitTB.Gen, HKU\S-1-5-21-966336249-240343522-4042860801-501\SOFTWARE\APPDATALOW\SOFTWARE\conduitEngine, Quarantined, [c54b4f01aded0f279fab741e1fe4ec14], 
PUP.Optional.ASK, HKU\S-1-5-21-966336249-240343522-4042860801-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2FA28606-DE77-4029-AF96-B231E3B8F827}, Quarantined, [17f986ca8e0c4aeccf017a54ec1631cf], 

Registry Values: 1
PUP.Optional.ASK, HKU\S-1-5-21-966336249-240343522-4042860801-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2fa28606-de77-4029-af96-b231e3b8f827}|URL, http://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF, Quarantined, [17f986ca8e0c4aeccf017a54ec1631cf]

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 1
RiskWare.GameHack, C:\Program Files (x86)\Cabela's Big Game Hunter Pro Hunts\steam_api.dll, Quarantined, [3ed2232deeacdf5717d2d9ce91736a96], 

Physical Sectors: 0
(No malicious items detected)


(end)

  • Автор

стъпка 4 още сканира , вече час някъде, беше забили но на 80% но след половин час пак тръгна , остава още малко .

единственото подобрение което виждам е че се оправи звука, т,е вече има звук. Другото си е същото, само да приключи , програмата и пак ще пиша

Emsisoft Emergency Kit - Version 11.9
Last update: 27.8.2016 г. 15:18:13
User account: Dzhemal-HP\Dzhemal
Computer name: DZHEMAL-HP
OS version: Windows 7x64 Service Pack 1

Scan settings:

Scan type: Custom Scan
Objects: Rootkits, Memory, Traces, C:\

Detect PUPs: On
Scan archives: On
ADS Scan: On
File extension filter: Off
Advanced caching: On
Direct disk access: Off

Scan start:    27.8.2016 г. 15:18:56
Key: HKEY_USERS\S-1-5-21-966336249-240343522-4042860801-501\SOFTWARE\APPDATALOW\SOFTWARE\CONDUIT     detected: Application.Toolbar (A)
Value: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLETASKMGR     detected: Setting.DisableTaskMgr (A)
Value: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLETASKMGR     detected: Setting.DisableTaskMgr (A)
Value: HKEY_USERS\S-1-5-21-966336249-240343522-4042860801-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLETASKMGR     detected: Setting.DisableTaskMgr (A)
Value: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLEREGISTRYTOOLS     detected: Setting.DisableRegistryTools (A)
Value: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLEREGISTRYTOOLS     detected: Setting.DisableRegistryTools (A)
Value: HKEY_USERS\S-1-5-21-966336249-240343522-4042860801-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLEREGISTRYTOOLS     detected: Setting.DisableRegistryTools (A)
Value: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER -> NORUN     detected: Setting.NoRun (A)
Value: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER -> NORUN     detected: Setting.NoRun (A)
Key: HKEY_USERS\S-1-5-21-966336249-240343522-4042860801-501\SOFTWARE\WINAMP TOOLBAR     detected: Application.InstallAd (A)
C:\AdwCleaner\quarantine\files\fekyaieqgjuodcvxjcnqlbdkhffqnxyy\OLBPre.exe     detected: Adware.GenericKD.3255596 (B)

Scanned    206707
Found    11

Scan end:    27.8.2016 г. 16:06:27
Scan time:    0:47:31
 

Да изтрия ли намерените неща  от програмата?

  • Автор

Здр. 

Проблемите бяха 2. Единия от които се реши, нямаше абсолютно никакъв звук. Сега вече има .

Другия проблем е много бавното действие на самата машина. Примерно сега стартирам МБАМ, и се чака около 2 мин да се зареди. С Файрфокс е дори повече. Също така процесора постоянно се товари на  90-100 % , без дори да има стартирано приложение. Общо взето това е. А машинката е пъргава , не е някакъв от панти века.За повече въпроси питайте. Благодаря!!!

  • Автор

Process    CPU    Private Bytes    Working Set    PID    Description    Company Name
System Idle Process    20.32    0 K    24 K    0        
System    0.79    252 K    1 436 K    4        
 Interrupts    1.71    0 K    0 K    n/a    Hardware Interrupts and DPCs    
 smss.exe        528 K    704 K    316        
csrss.exe    0.01    2 356 K    3 564 K    428        
wininit.exe        1 476 K    2 476 K    496        
 services.exe    0.03    6 012 K    7 152 K    544        
  svchost.exe    0.61    4 284 K    6 012 K    684    Host Process for Windows Services    Microsoft Corporation
   WmiPrvSE.exe        3 068 K    5 188 K    2280        
   FlashUtil64_11_8_800_94_ActiveX.exe    0.96    3 356 K    8 720 K    3656    Adobe® Flash® Player Installer/Uninstaller 11.8 r800    Adobe Systems Incorporated
   dllhost.exe        2 008 K    5 672 K    2820    COM Surrogate    Microsoft Corporation
  svchost.exe    0.02    4 736 K    6 496 K    804    Host Process for Windows Services    Microsoft Corporation
  svchost.exe    0.29    22 640 K    14 152 K    900    Host Process for Windows Services    Microsoft Corporation
   audiodg.exe    0.92    16 716 K    17 260 K    1020        
  svchost.exe    0.47    152 172 K    152 176 K    940    Host Process for Windows Services    Microsoft Corporation
   dwm.exe    1.01    54 420 K    42 824 K    1504    Desktop Window Manager    Microsoft Corporation
  svchost.exe    < 0.01    7 588 K    10 120 K    968    Host Process for Windows Services    Microsoft Corporation
  svchost.exe    46.67    1 479 768 K    1 065 456 K    992    Host Process for Windows Services    Microsoft Corporation
   wuauclt.exe        1 932 K    6 276 K    3540    Windows Update    Microsoft Corporation
  stacsv64.exe    0.40    6 668 K    4 764 K    436    IDT PC Audio    IDT, Inc.
  svchost.exe        2 176 K    3 232 K    1092    Host Process for Windows Services    Microsoft Corporation
  svchost.exe    0.03    16 196 K    14 136 K    1184    Host Process for Windows Services    Microsoft Corporation
  spoolsv.exe        6 376 K    10 116 K    1376    Spooler SubSystem App    Microsoft Corporation
  svchost.exe        10 272 K    9 788 K    1408    Host Process for Windows Services    Microsoft Corporation
  taskhost.exe    0.53    8 512 K    10 160 K    1436    Host Process for Windows Tasks    Microsoft Corporation
  armsvc.exe        1 144 K    2 480 K    1572    Adobe Acrobat Update Service    Adobe Systems Incorporated
  SkypeC2CAutoUpdateSvc.exe        1 480 K    2 484 K    1668    Updates Skype Click to Call    Microsoft Corporation
  SkypeC2CPNRSvc.exe        1 864 K    2 344 K    1704    Phone Number Recognition (PNR) module    Microsoft Corporation
  DeviceManager.exe        1 012 K    1 876 K    1744        
  ezSharedSvcHost.exe    < 0.01    1 468 K    3 176 K    1824        
  svchost.exe        6 184 K    10 364 K    1868    Host Process for Windows Services    Microsoft Corporation
  HPClientServices.exe        3 480 K    3 744 K    1892    HP Client Services    Hewlett-Packard Company
  HPWMISVC.exe        1 580 K    3 260 K    2000    HP Quick Launch WMI Service    Hewlett-Packard Development Company, L.P.
  RIconMan.exe        2 000 K    2 812 K    1028    Realtek Card Reader Icon Tool.    Realsil Microelectronics Inc.
  PassThruSvr.exe        1 264 K    2 368 K    1068    PassThruSvr Application    
  svchost.exe        1 888 K    3 944 K    1932    Host Process for Windows Services    Microsoft Corporation
  WLIDSVC.EXE    0.01    6 684 K    7 324 K    1056        
   WLIDSVCM.EXE        1 208 K    1 748 K    2324        
  SearchIndexer.exe    0.56    26 780 K    16 480 K    1968    Microsoft Windows Search Indexer    Microsoft Corporation
  HPSA_Service.exe    < 0.01    23 752 K    16 128 K    252    HP Support Assistant Service    Hewlett-Packard Company
  IAStorDataMgrSvc.exe    0.02    15 084 K    13 220 K    3544    IAStorDataSvc    Intel Corporation
  LMS.exe    0.03    2 148 K    4 488 K    3628    Local Manageability Service    Intel Corporation
  svchost.exe    0.05    46 708 K    25 400 K    3712    Host Process for Windows Services    Microsoft Corporation
  wmpnetwk.exe    < 0.01    18 044 K    8 068 K    3300    Windows Media Player Network Sharing Service    Microsoft Corporation
  UNS.exe        2 940 K    6 936 K    1316    User Notification Service    Intel Corporation
  svchost.exe        1 504 K    4 020 K    3128    Host Process for Windows Services    Microsoft Corporation
  svchost.exe        972 K    2 648 K    864    Host Process for Windows Services    Microsoft Corporation
 lsass.exe    0.11    4 868 K    7 748 K    560    Local Security Authority Process    Microsoft Corporation
 lsm.exe        2 644 K    2 832 K    568        
csrss.exe    0.59    2 588 K    26 984 K    520        
winlogon.exe        2 864 K    3 804 K    720        
explorer.exe    0.04    35 684 K    49 872 K    1604    Windows Explorer    Microsoft Corporation
 SynTPEnh.exe    0.40    8 872 K    8 928 K    2308    Synaptics TouchPad Enhancements    Synaptics Incorporated
  SynTPHelper.exe        1 184 K    1 692 K    2916        
 sttray64.exe        8 408 K    6 060 K    2344    IDT PC Audio    IDT, Inc.
 sidebar.exe        24 728 K    37 452 K    2432    Windows Desktop Gadgets    Microsoft Corporation
 chrome.exe    0.08    52 484 K    89 768 K    5040    Google Chrome    Google Inc.
  chrome.exe        1 376 K    4 104 K    5056    Google Chrome    Google Inc.
  chrome.exe        62 772 K    62 844 K    340    Google Chrome    Google Inc.
  chrome.exe    0.05    109 312 K    147 504 K    4832    Google Chrome    Google Inc.
  chrome.exe        43 176 K    55 880 K    884    Google Chrome    Google Inc.
  chrome.exe    0.08    68 212 K    121 184 K    4024    Google Chrome    Google Inc.
 iexplore.exe    0.43    12 844 K    31 456 K    2760    Internet Explorer    Microsoft Corporation
  iexplore.exe    0.17    45 712 K    41 828 K    1192    Internet Explorer    Microsoft Corporation
   AdblockPlusEngine.exe    1.40    113 220 K    110 600 K    4916    Adblock Plus Engine    Eyeo GmbH
  iexplore.exe    16.73    85 192 K    82 600 K    3476    Internet Explorer    Microsoft Corporation
 procexp.exe        24 044 K    18 980 K    4880    Sysinternals Process Explorer    Sysinternals - www.sysinternals.com
  procexp64.exe    3.67    41 396 K    48 604 K    2144    Sysinternals Process Explorer    Sysinternals - www.sysinternals.com
HPOSD.exe    < 0.01    3 604 K    5 596 K    2752    HP On Screen Display    Hewlett-Packard Development Company, L.P.
HPMSGSVC.exe    < 0.01    2 164 K    5 460 K    2764    HP Message Service    Hewlett-Packard Development Company, L.P.
mdhpSUN.exe        30 016 K    15 028 K    2772    Software update notification    Easybits
uTorrent.exe    0.79    14 204 K    24 300 K    4452    µTorrent    BitTorrent Inc.
 utorrentie.exe    < 0.01    41 832 K    63 028 K    4828    WebHelper    BitTorrent Inc.
 utorrentie.exe    < 0.01    29 752 K    45 216 K    4640    WebHelper    BitTorrent Inc.

Видях процеса който натоварва системата. Спри Windows Update и виж дали ще има подобрение.

Цитат

svchost.exe    46.67    1 479 768 K    1 065 456 K    992    Host Process for Windows Services    Microsoft Corporation

 

  • Автор

Така ... мога да кажа че има значително подобрение в работата на лаптопа и това товарене изобщо го няма вече , почти не минава 50%

 

Намерените неща от Malwarebytes Anti-malware ги изтрийте от карантината.

Изтеглете: 8864064T.png Delfix.

  • Стартирайте Delfix.exе.
  • По подразбиране трябва да има 2 отметки на "Remove disinfection tools" и "Purge system restore ". Ако липсват, ги сложете.
  • Натиснете бутона "Run". 
  • Инструмента ще се самоизтрие след като приключи своята задача.
  • Изтрийте лог файла от Delfix.
  • Ако има останали програми, които сме използвали и не са се изтрили, ги изтрийте ръчно.

 

Системата е чиста. Ако нямате повече въпроси, ще я маркирам като решена.

  • Автор

Добре ! Благодаря много, страхотна работа. Само да попитам какво да правя Емсисофт ем. Кит  и нещата които тя намери? 

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.