Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Намерих странна папка в С: май е криптовирус

Featured Replies

Случайно забелязах папка със непознато ми име RarVault в дял С. В нея има три файла - един текстови, един линк към страница и един svhost.exe Веднага изгасих компютъра и пуснах kaspersry reskue cd да сканира. папката я архивирах и качих тук http://tranzit.dir.b...41QGPuu22731467 ако някой иска да види за какво става дума, естествено на негова отговорност. Та какво да правя сега и как да махна нещото, дали само като изтрия папката ще си махне?
Касперски сканира и каза че съм чист, но щом пуснах уиндоуса и влязох в С папката сама се появи пак.

Май по-рано днес цъкнах на линк от един приятел по скайп

 

ето логовете

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 31-08-2016
Ran by Valio (06-09-2016 22:36:23)
Running from C:\Documents and Settings\Valio\Desktop
Microsoft Windows XP Professional Service Pack 3 (X86) (2010-11-07 17:20:38)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2052111302-630328440-1801674531-500 - Administrator - Enabled)
Guest (S-1-5-21-2052111302-630328440-1801674531-501 - Limited - Disabled)
HelpAssistant (S-1-5-21-2052111302-630328440-1801674531-1000 - Limited - Disabled)
SUPPORT_388945a0 (S-1-5-21-2052111302-630328440-1801674531-1002 - Limited - Disabled)
Valio (S-1-5-21-2052111302-630328440-1801674531-1003 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Valio

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Panda Free Antivirus (Enabled - Up to date) {5AD27692-540A-464E-B625-78275FA38393}
FW: Panda Firewall (Disabled) {1337562C-110A-4AF8-B12B-750C0B30E802}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKLM\...\uTorrent) (Version: 2.0.3 - )
Acronis MigrateEasy (HKLM\...\MigrateEasy) (Version:  - Acronis)
Adobe Flash Player 22 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 22.0.0.209 - Adobe Systems Incorporated)
Ashampoo Burning Studio 6 FREE (HKLM\...\Ashampoo Burning Studio 6 FREE_is1) (Version: 6.7.7 - ashampoo GmbH & Co. KG)
Atheros Communications Inc.(R) AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver (HKLM\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.40 - Atheros Communications Inc.)
ATI Catalyst Install Manager (HKLM\...\{B000FB7B-A489-25FC-EA84-1AA54AAD55BB}) (Version: 3.0.790.0 - ATI Technologies, Inc.)
ATI Catalyst Registration (Version: 3.00.0000 - ATI Technologies Inc.) Hidden
Bluetooth Stack for Windows by Toshiba (HKLM\...\{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}) (Version: v7.00.16(T) - TOSHIBA CORPORATION)
ccc-core-static (Version: 2010.0910.2122.36517 - ATI) Hidden
CryptoPrevent (HKLM\...\{5C5B24E7-4694-4049-A222-CCE7D3FAC63F}_is1) (Version:  - Foolish IT LLC)
FormatFactory 2.80 (HKLM\...\FormatFactory) (Version: 2.80 - Free Time)
Foxit Reader (HKLM\...\Foxit Reader) (Version: 4.0.0.619 - Foxit Software Company)
Free Video Editor version 1.4.13.805 (HKLM\...\Free Video Editor_is1) (Version: 1.4.13.805 - DVDVideoSoft Ltd.)
Hard Disk Sentinel (HKLM\...\Hard Disk Sentinel_is1) (Version:  - HDS)
HDDlife (HKLM\...\{8A142E1E-0B3A-459D-9908-BF77F284297F}) (Version: 2.9.105 - BinarySense)
K-Lite Codec Pack 12.0.5 Standard (HKLM\...\KLiteCodecPack_is1) (Version: 12.0.5 - KLCP)
Malwarebytes Anti-Malware, версия 2.2.1.1043 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\...\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
MiniTool Partition Wizard Free 9.1 (HKLM\...\{05D996FA-ADCB-4D23-BA3C-A7C184A8FAC6}_is1) (Version:  - MiniTool Solution Ltd.)
MozBackup 1.4.10 (HKLM\...\MozBackup) (Version:  - Pavel Cvrcek)
Mozilla Firefox 43.0.1 (x86 bg) (HKLM\...\Mozilla Firefox 43.0.1 (x86 bg)) (Version: 43.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 43.0.1 - Mozilla)
NitroFamily (HKLM\...\{008E8741-8888-4BEE-89B6-5AECB5FB9611}) (Version:  - )
Opera 11.10 (HKLM\...\Opera 11.10.2092) (Version: 11.10.2092 - Opera Software ASA)
Panda Devices Agent (Version: 1.03.08 - Panda Security) Hidden
Panda Devices Agent (Version: 1.08.00 - Panda Security) Hidden
Panda Free Antivirus (HKLM\...\Panda Universal Agent Endpoint) (Version: 17.00.01.0000 - Panda Security)
Panda Free Antivirus (Version: 8.31.00 - Panda Security) Hidden
PIXresizer 2.0.1 (HKLM\...\PIXresizer_is1) (Version:  - Bluefive software)
Platform (Version: 1.34 - VIA Technologies, Inc.) Hidden
Ralink RT7x Wireless LAN Card (HKLM\...\{E91E8912-769D-42F0-8408-0E329443BABC}) (Version: 1.5.4.0 - Ralink)
Revo Uninstaller 2.0.0 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.0.0 - VS Revo Group, Ltd.)
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.55.0 - Samsung Electronics Co., Ltd.)
Skype 7.0.0.102 (HKLM\...\Skype 7.0.0.102) (Version:  - )
Skype™ 7.0 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
The Lord of the Rings FREE Trial  (Version: 1.00.0000 - ATI Technologies Inc.) Hidden
VIA Platform Device Manager (HKLM\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.34 - VIA Technologies, Inc.)
Viber (HKU\S-1-5-21-2052111302-630328440-1801674531-1003\...\{acc83058-83b0-41e2-b372-266672a1af16}) (Version: 6.0.1.5 - Viber Media Inc.)
Viber (Version: 6.0.1.5 - Viber Media Inc.) Hidden
WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden
WhoCrashed 3.05 (HKLM\...\WhoCrashed_is1) (Version:  - Resplendence Software Projects Sp.)
Windows Bulgarian Interface Pack (HKLM\...\{C408D81A-CB17-4CDF-98AF-2E64036B3F32}) (Version: 1.0.0.2600 - Microsoft Corporation)
Windows Internet Explorer 8 (HKLM\...\ie8) (Version: 20090308.140743 - Microsoft Corporation)
Windows Media Format Runtime (HKLM\...\Windows Media Format Runtime) (Version:  - )
Windows Media Player 10 (HKLM\...\Windows Media Player) (Version:  - )
XviD MPEG-4 Video Codec (HKLM\...\xvid) (Version:  - XviD Development Team)
Архиватор WinRAR (HKLM\...\WinRAR archiver) (Version:  - )

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-2052111302-630328440-1801674531-1003_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll => No File
CustomCLSID: HKU\S-1-5-21-2052111302-630328440-1801674531-1003_Classes\CLSID\{42481700-CF3C-4D05-8EC6-F9A1C57E8DC0}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll => No File
CustomCLSID: HKU\S-1-5-21-2052111302-630328440-1801674531-1003_Classes\CLSID\{D0D38C6E-BF64-4C42-840D-3E0019D9F7A6}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll => No File

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\klcp_update.job => CMD /C sc create KLCPU binPath CMD /V /C SET \FILE \ ProgramFiles \ Lite Codec Pack Tools CodecTweakTool exe\\ IF EXIST FILE START \CTT\ FILE /verysilent /update /freq 30 type own type interact net start KLCPU sc delete KLCPU CMD Valio

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\VMware\ThinApp Help.lnk -> hxxp://www.vmware.com/info?id=766

==================== Loaded Modules (Whitelisted) ==============

2010-11-07 21:00 - 2006-12-03 15:53 - 00126464 _____ () C:\Program Files\WinRAR\rarext.dll
2005-08-13 21:03 - 2005-08-13 21:03 - 00124928 _____ () C:\Program Files\BinarySense\HDDlife\crashrpt.dll
2015-12-15 20:17 - 2015-12-15 20:17 - 00618544 _____ () C:\Program Files\Panda Security\Panda Security Protection\SQLite3.dll
2010-03-16 13:22 - 2010-03-16 13:22 - 00014848 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\AxInterop.WBOCXLib.dll
2010-08-04 16:58 - 2010-08-04 16:58 - 00016384 ____R () C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll
2010-09-10 22:21 - 2010-09-10 22:21 - 00270336 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Documents and Settings\Valio\My Documents\Shareaza Downloads:Shareaza.GUID [16]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NanoServiceMain => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSUAService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NanoServiceMain => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PSUAService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

HKLM\...\.scr: CryptoPreventSCR => "C:\Program Files\Foolish IT\CryptoPrevent\CryptoPreventFilterMod.CryptoPreventEXEC" "%1" /S %*

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2008-04-14 15:00 - 2008-04-14 15:00 - 00000734 ____A C:\WINDOWS\system32\Drivers\etc\hosts

127.0.0.1       localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2052111302-630328440-1801674531-1003\Control Panel\Desktop\\Wallpaper -> C:\Documents and Settings\Valio\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
DNS Servers: 192.168.137.1
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

StandardProfile\AuthorizedApplications: [C:\Program Files\uTorrent\uTorrent.exe] => Enabled:µTorrent
StandardProfile\AuthorizedApplications: [C:\Program Files\NitroFamily\NitroFamily.exe] => Enabled:NitroFamily
StandardProfile\AuthorizedApplications: [C:\Program Files\ASUS\GamerOSD\GamerOSD.exe] => Enabled:ASUS GamerOSD APP
StandardProfile\AuthorizedApplications: [G:\instal\INTERNET\DC++\sdc222\StrongDC.exe] => G:\instal\INTERNET\DC++\sdc222\StrongDC.exe:*:Enabled:StrongDC++
StandardProfile\AuthorizedApplications: [C:\Program Files\BitComet\BitComet.exe] => Enabled:BitComet - a BitTorrent Client
StandardProfile\AuthorizedApplications: [C:\Program Files\Opera\opera.exe] => Enabled:Opera Internet Browser
StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Valio\Desktop\Sky38i.exe] => Enabled:Skype
StandardProfile\AuthorizedApplications: [C:\Program Files\Mozilla Firefox\firefox.exe] => Enabled:Firefox (C:\Program Files\Mozilla Firefox)
StandardProfile\AuthorizedApplications: [C:\Program Files\Skype\Phone\Skype.exe] => Enabled:Skype
StandardProfile\GloballyOpenPorts: [16752:TCP] => Enabled:BitComet 16752 TCP
StandardProfile\GloballyOpenPorts: [16752:UDP] => Enabled:BitComet 16752 UDP

==================== Restore Points =========================

16-03-2016 22:26:03 Installed ASUS Smart Doctor
20-03-2016 22:11:27 Installed ASUS Gamer OSD
21-03-2016 01:35:46 Removed ASUS Gamer OSD
21-03-2016 01:39:25 Configured ASUS Smart Doctor
26-03-2016 11:17:33 Configured ASUS Smart Doctor
26-03-2016 11:18:34 Configured ASUS Smart Doctor
26-03-2016 11:19:04 Configured ASUS Smart Doctor
02-04-2016 22:05:47 Installed VMware ThinApp
10-08-2016 20:05:30 Операция за възстановяване
06-09-2016 14:51:26 Installed HDDlife
06-09-2016 16:22:09 Installed Windows Internet Explorer 8.
06-09-2016 18:36:30 Installed WIDCOMM Bluetooth Software
06-09-2016 19:02:53 Removed WIDCOMM Bluetooth Software
06-09-2016 19:36:40 Премахнат Skype™ 7.26
06-09-2016 19:37:17 Installed Skype™ 6.14
06-09-2016 20:27:32 Installed Bluetooth Stack for Windows by Toshiba.

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (09/06/2016 10:33:24 PM) (Source: .NET Runtime 2.0 Error Reporting) (EventID: 5000) (User: )
Description: EventType clr20r3, P1 006C0073043000730073, P2 5.1.1600.5512, P3 566ff9da, P4 microsoft.visualbasic, P5 8.0.0.0, P6 4889f422, P7 349, P8 4f, P9 system.invalidcastexception, P10 NIL.

Error: (09/06/2016 10:17:47 PM) (Source: .NET Runtime 2.0 Error Reporting) (EventID: 5000) (User: )
Description: EventType clr20r3, P1 006C0073043000730073, P2 5.1.1600.5512, P3 566ff9da, P4 microsoft.visualbasic, P5 8.0.0.0, P6 4889f422, P7 349, P8 4f, P9 system.invalidcastexception, P10 NIL.

Error: (09/06/2016 08:53:35 PM) (Source: .NET Runtime 2.0 Error Reporting) (EventID: 5000) (User: )
Description: EventType clr20r3, P1 006C0073043000730073, P2 5.1.1600.5512, P3 566ff9da, P4 microsoft.visualbasic, P5 8.0.0.0, P6 4889f422, P7 349, P8 4f, P9 system.invalidcastexception, P10 NIL.

Error: (09/06/2016 08:47:30 PM) (Source: .NET Runtime 2.0 Error Reporting) (EventID: 5000) (User: )
Description: EventType clr20r3, P1 006C0073043000730073, P2 5.1.1600.5512, P3 566ff9da, P4 microsoft.visualbasic, P5 8.0.0.0, P6 4889f422, P7 349, P8 4f, P9 system.invalidcastexception, P10 NIL.

Error: (09/06/2016 08:23:07 PM) (Source: .NET Runtime 2.0 Error Reporting) (EventID: 5000) (User: )
Description: EventType clr20r3, P1 006C0073043000730073, P2 5.1.1600.5512, P3 566ff9da, P4 microsoft.visualbasic, P5 8.0.0.0, P6 4889f422, P7 349, P8 4f, P9 system.invalidcastexception, P10 NIL.

Error: (09/06/2016 08:14:16 PM) (Source: .NET Runtime 2.0 Error Reporting) (EventID: 5000) (User: )
Description: EventType clr20r3, P1 006C0073043000730073, P2 5.1.1600.5512, P3 566ff9da, P4 microsoft.visualbasic, P5 8.0.0.0, P6 4889f422, P7 349, P8 4f, P9 system.invalidcastexception, P10 NIL.

Error: (09/06/2016 07:35:56 PM) (Source: MsiInstaller) (EventID: 1013) (User: VALIO-PC)
Description: Product: Skype™ 6.14 -- A later version of Skype™ 6.14 is already installed.


System errors:
=============
Error: (09/06/2016 08:20:08 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Windows Installer service terminated unexpectedly.  It has done this 1 time(s).

Error: (09/06/2016 08:20:08 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Print Spooler service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.

Error: (09/06/2016 08:20:07 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Application Layer Gateway Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (09/06/2016 08:20:06 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Windows User Mode Driver Framework service terminated unexpectedly.  It has done this 1 time(s).

Error: (09/06/2016 08:20:06 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The SAMSUNG Mobile Connectivity Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (09/06/2016 08:20:06 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Panda Devices Agent service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 300000 milliseconds: Restart the service.

Error: (09/06/2016 08:20:06 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Ati HotKey Poller service terminated unexpectedly.  It has done this 1 time(s).

Error: (09/06/2016 07:47:33 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: Generate Activation Context failed for C:\Program Files\DVDVideoSoft\Free Video Editor\FreeVideoEditor.exe.
Reference error message: The operation completed successfully.
.

Error: (09/06/2016 07:47:33 PM) (Source: SideBySide) (EventID: 58) (User: )
Description: Syntax error in manifest or policy file "C:\Program Files\DVDVideoSoft\Free Video Editor\FreeVideoEditor.exe" on line 0.

Error: (09/06/2016 06:55:37 PM) (Source: System Error) (EventID: 1003) (User: )
Description: Error code 000000ea, parameter1 88f00a58, parameter2 89b947a0, parameter3 8a4883f0, parameter4 00000001.


==================== Memory info ===========================

Processor: Pentium(R) Dual-Core CPU E5300 @ 2.60GHz
Percentage of memory in use: 16%
Total physical RAM: 3071.11 MB
Available physical RAM: 2549.96 MB
Total Virtual: 4956.19 MB
Available Virtual: 4432.85 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:149.05 GB) (Free:46.37 GB) NTFS ==>[drive with boot components (Windows XP)]
Drive d: (ADATA UFD) (Removable) (Total:28.89 GB) (Free:4.55 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 149.1 GB) (Disk ID: A21C08DC)
Partition 1: (Active) - (Size=149 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 28.9 GB) (Disk ID: C3072E18)
Partition 1: (Not Active) - (Size=28.9 GB) - (Type=0C)

==================== End of Addition.txt ============================

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 31-08-2016
Ran by Valio (administrator) on VALIO-PC (06-09-2016 22:34:59)
Running from C:\Documents and Settings\Valio\Desktop
Loaded Profiles: Valio (Available Profiles: Valio)
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) Language: English (United States)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(VIA Technologies, Inc.) C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Panda Security, S.L.) C:\Program Files\Panda Security\Panda Security Protection\PSUAMain.exe
(BinarySense, Ltd.) C:\Program Files\BinarySense\HDDlife\HDDlifePro.exe
(TOSHIBA CORPORATION.) C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
(Panda Security, S.L.) C:\Program Files\Panda Security\Panda Devices Agent\AgentSvc.exe
(Panda Security, S.L.) C:\Program Files\Panda Security\Panda Security Protection\PSUAService.exe
(DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe
(TOSHIBA CORPORATION.) C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
(TOSHIBA CORPORATION) C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
(Panda Security, S.L.) C:\Program Files\Panda Security\Panda Security Protection\PSANHost.exe
(TOSHIBA CORPORATION.) C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
(TOSHIBA CORPORATION.) C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [BluetoothAuthenticationAgent] => rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
HKLM\...\Run: [HDAudDeck] => C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe [33673216 2009-08-28] (VIA Technologies, Inc.)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-09-10] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [ATICustomerCare] => C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe [311296 2010-05-04] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [PSUAMain] => C:\Program Files\Panda Security\Panda Security Protection\PSUAMain.exe [109824 2016-08-05] (Panda Security, S.L.)
HKLM\...\Run: [ITSecMng] => C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe [83336 2009-07-22] (TOSHIBA CORPORATION)
HKLM Group Policy restriction on software: *.pub*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.js <====== ATTENTION
HKLM Group Policy restriction on software: cipher.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\*\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Start Menu\Programs\Startup\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\*\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Start Menu\Programs\Startup\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.js <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.com <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\*\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\*\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.exe <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\*\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\*\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*\svchost.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\*\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Start Menu\Programs\Startup\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\*\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.com <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\*\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.com <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Start Menu\Programs\Startup\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Start Menu\Programs\Startup\*.js <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\*.com <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.js <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\*\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\*\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.com <====== ATTENTION
HKLM Group Policy restriction on software: vssadmin.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\*\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Start Menu\Programs\Startup\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\*\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\*\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\*\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Start Menu\Programs\Startup\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\*\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.com <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Start Menu\Programs\Startup\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\Microsoft\Windows\IEUpdate\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\*\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\*\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: ** <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.exe <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Start Menu\Programs\Startup\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.scr <====== ATTENTION
HKLM Group Policy restriction on software: syskey.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: lsassvrtdbks.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Start Menu\Programs\Startup\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *:\RECYCLER <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\*\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Start Menu\Programs\Startup\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\*\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.com <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\*\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.js <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\*\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\*\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %programfiles%\*\svchost.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.com <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\*\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.js <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: scsvserv.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\*\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\*\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.js <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\*\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Start Menu\Programs\Startup\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\*\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.js <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.bat <====== ATTENTION
HKLM Group Policy restriction on software: lsassw86s.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Start Menu\Programs\Startup\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\*\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\*\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\*\*.com <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Start Menu\Programs\Startup\*.js <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\*.js <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %systemdrive%\*\svchost.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Start Menu\Programs\Startup\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.js <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.js <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Start Menu\Programs\Startup\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\*\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\viber\updater.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\viber\viber.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\viber\qtwebengineprocess.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\viber\linkparser.exe <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\viber\qtwebengineprocess.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\viber\updater.exe <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\viber\viber.exe <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\viber\updater.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\viber\updater.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\viber\qtwebengineprocess.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\viber\updater.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\viber\linkparser.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\viber\viber.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\viber\linkparser.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\viber\qtwebengineprocess.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\viber\linkparser.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\viber\viber.exe <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\viber\linkparser.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\viber\qtwebengineprocess.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\viber\viber.exe <====== ATTENTION
Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll [2010-09-11] (ATI Technologies Inc.)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk [2016-09-06]
ShortcutTarget: Bluetooth Manager.lnk -> C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe (TOSHIBA CORPORATION.)
Startup: C:\Documents and Settings\Valio\Start Menu\Programs\Startup\HDDlife.lnk [2016-09-06]
ShortcutTarget: HDDlife.lnk -> C:\Program Files\BinarySense\HDDlife\HDDlifePro.exe (BinarySense, Ltd.)
Startup: C:\Documents and Settings\Valio\Start Menu\Programs\Startup\LocalSystem.lnk [2016-09-06]
ShortcutTarget: LocalSystem.lnk -> C:\WINDOWS\system32\lsаss.exe (Microsoft Corporation)
GroupPolicyScripts: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.137.1
Tcpip\..\Interfaces\{06CABE20-480A-4AA0-9CC1-AA36453BEC30}: [DhcpNameServer] 192.168.137.1
Tcpip\..\Interfaces\{799F7017-7406-4F39-919E-BB864845E776}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{A252AF90-EA63-4EC7-B1E1-457811249394}: [DhcpNameServer] 192.168.43.1
Tcpip\..\Interfaces\{C5DBAAF7-1739-484D-AE2D-C517657F1640}: [DhcpNameServer] 192.168.137.1
Tcpip\..\Interfaces\{CA100D9E-F1C7-4A77-A69D-963437D8BDCA}: [DhcpNameServer] 192.168.137.1
Tcpip\..\Interfaces\{F19BF960-CE76-4F20-BD48-BE12EAA8AC0E}: [DhcpNameServer] 192.168.137.1
Tcpip\..\Interfaces\{FAE64C97-ECD7-4296-8BD4-603BEEC607B1}: [DhcpNameServer] 192.168.137.1

Internet Explorer:
==================
HKU\S-1-5-21-2052111302-630328440-1801674531-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.bg/
HKU\S-1-5-21-2052111302-630328440-1801674531-1003\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

FireFox:
========
FF ProfilePath: C:\Documents and Settings\Valio\Application Data\Mozilla\Firefox\Profiles\tbt07bz3.default
FF DefaultSearchEngine: Google Custom Search
FF Homepage: hxxps://google.bg
FF Keyword.URL: hxxp://search.musicfrost.com/results.php?q=
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_22_0_0_209.dll [2016-09-06] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npFoxitReaderPlugin.dll [2016-09-06] (Foxit Software Company)
FF SearchPlugin: C:\Documents and Settings\Valio\Application Data\Mozilla\Firefox\Profiles\tbt07bz3.default\searchplugins\daemon-search.xml [2010-09-13]
FF SearchPlugin: C:\Documents and Settings\Valio\Application Data\Mozilla\Firefox\Profiles\tbt07bz3.default\searchplugins\MFGSearch.xml [2011-01-29]
FF Extension: (Forecastfox) - C:\Documents and Settings\Valio\Application Data\Mozilla\Firefox\Profiles\tbt07bz3.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3} [2016-09-06]
FF Extension: (oldbar) - C:\Documents and Settings\Valio\Application Data\Mozilla\Firefox\Profiles\tbt07bz3.default\extensions\{46868735-c3fa-47ce-8ce7-cce51a66aceb}.xpi [2016-09-06]
FF Extension: (Forecastfox (fix version)) - C:\Documents and Settings\Valio\Application Data\Mozilla\Firefox\Profiles\tbt07bz3.default\extensions\forecastfox@s3_fix_version.xpi [2016-09-06]
FF Extension: (Bulgarian Dictionary) - C:\Documents and Settings\Valio\Application Data\Mozilla\Firefox\Profiles\tbt07bz3.default\Extensions\[email protected] [2016-03-06] [not signed]
FF Extension: (YouTube™ Flash® Player) - C:\Documents and Settings\Valio\Application Data\Mozilla\Firefox\Profiles\tbt07bz3.default\Extensions\[email protected] [2016-09-06]
FF Extension: (Firefox Hello Beta) - C:\Documents and Settings\Valio\Application Data\Mozilla\Firefox\Profiles\tbt07bz3.default\Extensions\[email protected] [2016-09-06]
FF Extension: (Модул за сканиране на уеб адреси) - C:\Program Files\Mozilla Firefox\extensions\[email protected]_bak [2011-02-13] [not signed]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\[email protected] => not found
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\[email protected] => not found

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 NanoServiceMain; C:\Program Files\Panda Security\Panda Security Protection\PSANHost.exe [153096 2016-08-05] (Panda Security, S.L.)
R2 PandaAgent; C:\Program Files\Panda Security\Panda Devices Agent\AgentSvc.exe [86104 2016-07-19] (Panda Security, S.L.)
R2 PSUAService; C:\Program Files\Panda Security\Panda Security Protection\PSUAService.exe [48584 2016-08-05] (Panda Security, S.L.)
R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2015-05-21] (DEVGURU Co., LTD.)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AR9271; C:\WINDOWS\System32\DRIVERS\athuw.sys [1763584 2013-06-29] (Atheros Communications, Inc.)
S3 asusgsb; C:\WINDOWS\System32\drivers\asusgsb.sys [12416 2009-02-17] (ASUSTeK Computer Inc.) [File not signed]
R3 AtiHDAudioService; C:\WINDOWS\System32\drivers\AtihdXP3.sys [101904 2010-07-21] (ATI Technologies, Inc.)
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
R2 EIO_XP; C:\WINDOWS\system32\drivers\EIO_XP.sys [14336 2009-07-30] (ASUSTeK Computer Inc.) [File not signed]
S3 es1371; C:\WINDOWS\System32\drivers\es1371mp.sys [40704 2001-08-17] (Creative Technology Ltd.)
R1 HWiNFO32; C:\WINDOWS\system32\drivers\HWiNFO32.SYS [23840 2016-09-06] (REALiX(tm))
R3 L1e; C:\WINDOWS\System32\DRIVERS\l1e51x86.sys [39424 2009-08-05] (Atheros Communications, Inc.)
R3 MTsensor; C:\WINDOWS\System32\DRIVERS\ASACPI.sys [5810 2004-08-13] ()
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
R1 NNSALPC; C:\WINDOWS\System32\DRIVERS\NNSAlpc.sys [87032 2015-12-04] (Panda Security, S.L.)
R1 NNSHTTP; C:\WINDOWS\System32\DRIVERS\NNSHttp.sys [202104 2015-12-04] (Panda Security, S.L.)
R1 NNSHTTPS; C:\WINDOWS\System32\DRIVERS\NNSHttps.sys [109688 2015-12-04] (Panda Security, S.L.)
R1 NNSIDS; C:\WINDOWS\System32\DRIVERS\NNSIds.sys [121720 2015-12-04] (Panda Security, S.L.)
R3 NNSNAHS; C:\WINDOWS\System32\DRIVERS\NNSNAHS.sys [46480 2015-04-27] (Panda Security, S.L.)
R1 NNSPICC; C:\WINDOWS\System32\DRIVERS\NNSPicc.sys [102392 2015-12-04] (Panda Security, S.L.)
R1 NNSPIHS; C:\WINDOWS\System32\DRIVERS\NNSPihs.sys [52088 2015-12-04] (Panda Security, S.L.)
R1 NNSPOP3; C:\WINDOWS\System32\DRIVERS\NNSPop3.sys [120568 2015-12-04] (Panda Security, S.L.)
R1 NNSPROT; C:\WINDOWS\System32\DRIVERS\NNSProt.sys [281720 2015-12-04] (Panda Security, S.L.)
R1 NNSPRV; C:\WINDOWS\System32\DRIVERS\NNSPrv.sys [216208 2016-02-17] (Panda Security, S.L.)
R1 NNSSMTP; C:\WINDOWS\System32\DRIVERS\NNSSmtp.sys [108408 2015-12-04] (Panda Security, S.L.)
R1 NNSSTRM; C:\WINDOWS\System32\DRIVERS\NNSStrm.sys [247568 2016-02-17] (Panda Security, S.L.)
R1 NNSTLSC; C:\WINDOWS\System32\DRIVERS\NNSTlsc.sys [94968 2015-12-04] (Panda Security, S.L.)
R2 PSINAflt; C:\WINDOWS\System32\DRIVERS\PSINAflt.sys [148496 2016-08-05] (Panda Security, S.L.)
R2 PSINFile; C:\WINDOWS\System32\DRIVERS\PSINFile.sys [109456 2016-08-05] (Panda Security, S.L.)
R1 PSINKNC; C:\WINDOWS\System32\DRIVERS\psinknc.sys [180112 2016-08-05] (Panda Security, S.L.)
R2 PSINProc; C:\WINDOWS\System32\DRIVERS\PSINProc.sys [121872 2016-08-05] (Panda Security, S.L.)
R2 PSINProt; C:\WINDOWS\System32\DRIVERS\PSINProt.sys [133520 2016-08-05] (Panda Security, S.L.)
R2 PSINReg; C:\WINDOWS\System32\DRIVERS\PSINReg.sys [107920 2016-08-05] (Panda Security, S.L.)
U3 PSKMAD; C:\WINDOWS\System32\DRIVERS\PSKMAD.sys [58288 2016-08-08] (Panda Security, S.L.)
R0 pwdrvio; C:\WINDOWS\System32\pwdrvio.sys [17160 2015-03-05] ()
S3 pwdspio; C:\WINDOWS\system32\pwdspio.sys [13064 2015-03-05] ()
R3 RT73; C:\WINDOWS\System32\DRIVERS\rt73.sys [451968 2007-10-01] (Ralink Technology, Corp.)
R0 snapman; C:\WINDOWS\System32\DRIVERS\snapman.sys [65856 2016-09-06] (Acronis) [File not signed]
R0 sptd; C:\WINDOWS\System32\Drivers\sptd.sys [691696 2016-03-06] () [File not signed]
R1 Tcpip; C:\WINDOWS\System32\DRIVERS\tcpip.sys [361344 2010-11-07] (Microsoft Corporation) [File not signed]
S3 VBoxNetAdp; C:\WINDOWS\System32\DRIVERS\VBoxNetAdp.sys [95376 2009-10-29] (Sun Microsystems, Inc.)
S3 VBoxUSB; C:\WINDOWS\System32\Drivers\VBoxUSB.sys [32016 2009-10-29] (Sun Microsystems, Inc.)
R3 VIAHdAudAddService; C:\WINDOWS\System32\drivers\viahduaa.sys [1390976 2009-08-17] (VIA Technologies, Inc.)
S4 IntelIde; no ImagePath
S3 SNP325; system32\DRIVERS\snp325.sys [X]
S3 StarOpen; no ImagePath
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]
S3 Video3D; System32\Drivers\Video3D32.sys [X]
U1 WS2IFSL; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-09-07 00:07 - 2016-09-07 01:14 - 00000000 ____D C:\Kaspersky Rescue Disk 10.0
2016-09-06 22:34 - 2016-09-06 22:35 - 00042908 _____ C:\Documents and Settings\Valio\Desktop\FRST.txt
2016-09-06 22:34 - 2016-09-06 22:34 - 00000000 ____D C:\FRST
2016-09-06 22:34 - 2016-09-06 22:29 - 01747968 _____ (Farbar) C:\Documents and Settings\Valio\Desktop\FRST.exe
2016-09-06 22:33 - 2016-08-08 12:00 - 00058288 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\PSKMAD.sys
2016-09-06 22:17 - 2016-09-06 22:33 - 00000000 ____D C:\RarVault
2016-09-06 21:02 - 2016-09-06 21:02 - 02307616 _____ (Kaspersky Lab) C:\Documents and Settings\Valio\Desktop\kts17.0.0.611en_10781.exe
2016-09-06 20:58 - 2016-09-06 20:58 - 00000400 __RSH C:\Documents and Settings\All Users\ntuser.pol
2016-09-06 20:58 - 2016-09-06 20:58 - 00000067 _____ C:\Documents and Settings\Valio\Desktop\rufus.ini
2016-09-06 20:54 - 2016-09-06 20:58 - 291952640 _____ C:\Documents and Settings\Valio\Desktop\kav_rescue_10.iso
2016-09-06 20:49 - 2016-09-06 20:49 - 02619784 _____ (Foolish IT LLC ) C:\Documents and Settings\Valio\Desktop\CryptoPreventSetup.exe
2016-09-06 20:49 - 2016-09-06 20:49 - 00000865 _____ C:\Documents and Settings\All Users\Desktop\CryptoPrevent.lnk
2016-09-06 20:49 - 2016-09-06 20:49 - 00000000 ____D C:\Program Files\Foolish IT
2016-09-06 20:49 - 2016-09-06 20:49 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Foolish IT
2016-09-06 20:47 - 2016-09-06 20:47 - 00458652 _____ C:\RarVault.rar
2016-09-06 20:46 - 2016-09-06 20:46 - 00000000 ____D C:\Documents and Settings\Valio\Local Settings\Application Data\Toshiba
2016-09-06 20:46 - 2016-09-06 20:46 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\TOSHIBA
2016-09-06 20:38 - 2016-09-06 20:38 - 00002419 _____ C:\Documents and Settings\Valio\Local Settings\Temp2.html
2016-09-06 20:29 - 2016-09-06 20:29 - 00000882 _____ C:\Documents and Settings\All Users\Desktop\Revo Uninstaller.lnk
2016-09-06 20:29 - 2016-09-06 20:29 - 00000000 ____D C:\Program Files\VS Revo Group
2016-09-06 20:29 - 2016-09-06 20:29 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Revo Uninstaller
2016-09-06 20:27 - 2016-09-06 20:27 - 00000000 ____D C:\Program Files\Toshiba
2016-09-06 20:27 - 2016-09-06 20:27 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\TOSHIBA
2016-09-06 20:27 - 2009-07-28 20:01 - 00069480 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\Drivers\tosrfcom.sys
2016-09-06 20:27 - 2009-06-17 11:59 - 00046984 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\Drivers\tosporte.sys
2016-09-06 20:17 - 2016-09-06 20:20 - 00000000 ____D C:\AdwCleaner
2016-09-06 20:15 - 2016-09-06 20:15 - 00000000 ____D C:\Program Files\Common Files\Skype
2016-09-06 20:15 - 2016-09-06 20:15 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Skype
2016-09-06 19:48 - 2016-09-06 19:48 - 00000917 _____ C:\Documents and Settings\All Users\Desktop\Free Video Editor.lnk
2016-09-06 19:47 - 2016-09-06 19:47 - 00000000 ____D C:\Program Files\DVDVideoSoft
2016-09-06 19:47 - 2016-09-06 19:47 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft
2016-09-06 19:47 - 2016-09-06 19:47 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\DVDVideoSoft
2016-09-06 19:37 - 2016-09-06 20:29 - 00002265 _____ C:\Documents and Settings\All Users\Desktop\Skype.lnk
2016-09-06 19:37 - 2016-09-06 20:15 - 00000000 ___RD C:\Program Files\Skype
2016-09-06 19:37 - 2016-09-06 19:37 - 00000000 ____D C:\Documents and Settings\Valio\Local Settings\Application Data\Skype
2016-09-06 19:28 - 2016-09-06 19:36 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\ProductData
2016-09-06 19:28 - 2016-09-06 19:28 - 00000000 ____D C:\WINDOWS\IObit
2016-09-06 19:27 - 2016-09-06 19:27 - 00023840 _____ (REALiX(tm)) C:\WINDOWS\system32\Drivers\HWiNFO32.SYS
2016-09-06 19:27 - 2016-09-06 19:27 - 00000000 ____D C:\Documents and Settings\Valio\Application Data\IObit
2016-09-06 19:27 - 2016-09-06 19:27 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\IObit
2016-09-06 19:23 - 2016-09-06 19:24 - 15206472 _____ (IObit ) C:\Documents and Settings\Valio\Desktop\driver_booster_setup.exe
2016-09-06 19:08 - 2016-09-06 19:08 - 00007385 _____ C:\Documents and Settings\Valio\Local Settings\Temp6.html
2016-09-06 19:08 - 2016-09-06 19:08 - 00000000 __SHD C:\Documents and Settings\Valio\PrivacIE
2016-09-06 18:54 - 2016-09-06 18:52 - 00068000 ____H C:\WINDOWS\Minidump\Mini090616-01.dmp
2016-09-06 18:53 - 2016-09-06 18:53 - 00000664 _____ C:\WINDOWS\system32\d3d9caps.dat
2016-09-06 18:51 - 2016-09-06 18:51 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\TOSHIBA Bluetooth Stack 7.00.16 (x86)
2016-09-06 18:51 - 2016-09-06 18:51 - 00000000 ____D C:\Documents and Settings\Val\Desktop\Femanic
2016-09-06 18:35 - 2016-09-06 18:35 - 00000000 ____D C:\Program Files\WhoCrashed
2016-09-06 18:35 - 2016-09-06 18:35 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\WhoCrashed
2016-09-06 18:31 - 2001-08-17 12:12 - 00117760 ____C (Intel Corporation) C:\WINDOWS\system32\dllcache\e100b325.sys
2016-09-06 18:31 - 2001-08-17 12:12 - 00117760 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\e100b325.sys
2016-09-06 16:47 - 2016-09-06 16:47 - 00000000 __SHD C:\Documents and Settings\Valio\IETldCache
2016-09-06 16:47 - 2016-09-06 16:47 - 00000000 __SHD C:\Documents and Settings\LocalService\IETldCache
2016-09-06 16:22 - 2016-09-06 16:45 - 00065536 _____ C:\WINDOWS\system32\config\Internet.evt
2016-09-06 16:22 - 2009-01-07 18:21 - 00026144 _____ (Microsoft Corporation) C:\WINDOWS\system32\spupdsvc.exe
2016-09-06 16:22 - 2009-01-07 18:20 - 00016928 ____N (Microsoft Corporation) C:\WINDOWS\system32\spmsg.dll
2016-09-06 16:21 - 2016-09-06 16:22 - 00000000 __HDC C:\WINDOWS\ie8
2016-09-06 14:51 - 2016-09-06 14:51 - 00000000 ____D C:\Program Files\BinarySense
2016-09-06 14:51 - 2016-09-06 14:51 - 00000000 ____D C:\Documents and Settings\Valio\Application Data\BinarySense
2016-09-06 14:51 - 2016-09-06 14:51 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\HDDlife
2016-09-06 14:43 - 2016-09-06 14:43 - 00000000 ____D C:\Documents and Settings\Val\Local Settings\Application Data\Opera
2016-09-06 14:43 - 2016-09-06 14:43 - 00000000 ____D C:\Documents and Settings\Val
2016-09-06 14:42 - 2016-09-06 14:42 - 00001498 _____ C:\Documents and Settings\All Users\Start Menu\Programs\Opera.lnk
2016-09-06 14:42 - 2016-09-06 14:42 - 00000000 ____D C:\Program Files\Opera
2016-09-06 14:41 - 2016-09-06 14:43 - 00000000 ____D C:\Documents and Settings\Valio\Application Data\Opera
2016-09-06 14:41 - 2016-09-06 14:41 - 00000000 ____D C:\Documents and Settings\Valio\Local Settings\Application Data\Opera
2016-09-06 13:53 - 2016-09-06 13:53 - 00000000 ____D C:\Program Files\Foxit Software
2016-09-06 13:53 - 2016-09-06 13:53 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Foxit Reader
2016-09-06 13:47 - 2016-09-06 16:49 - 00000000 ____D C:\Documents and Settings\Valio\Application Data\ViberPC
2016-09-06 13:46 - 2016-09-06 13:46 - 00000875 _____ C:\Documents and Settings\Valio\Start Menu\Viber.lnk
2016-09-06 13:46 - 2016-09-06 13:46 - 00000000 ____D C:\Documents and Settings\Valio\Start Menu\Programs\Viber
2016-09-06 13:45 - 2016-09-06 13:46 - 00000000 ____D C:\Documents and Settings\Valio\Local Settings\Application Data\Viber
2016-09-06 13:45 - 2016-09-06 13:45 - 00000000 ____D C:\Documents and Settings\Valio\Local Settings\Application Data\Package Cache
2016-09-06 13:32 - 2016-09-06 13:33 - 00000000 ____D C:\Program Files\RevConnect
2016-09-06 13:25 - 2016-09-06 18:51 - 00000000 ____D C:\Documents and Settings\Valio\Application Data\uTorrent
2016-09-06 13:19 - 2016-09-06 20:38 - 00001667 _____ C:\Documents and Settings\Valio\Local Settings\Temp1.html
2016-09-06 13:18 - 2016-09-06 13:18 - 00000000 ____D C:\Program Files\PIXresizer
2016-09-06 13:18 - 2016-09-06 13:18 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\PIXresizer
2016-09-06 13:18 - 2007-04-15 01:05 - 00991232 _____ (Viscom Software ) C:\WINDOWS\system32\imageviewer2.ocx
2016-09-06 13:18 - 2004-03-09 00:00 - 00224016 _____ (Microsoft Corporation) C:\WINDOWS\system32\tabctl32.ocx
2016-09-06 13:18 - 2002-08-29 20:00 - 01703936 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdiplus.dll
2016-09-06 13:18 - 2000-07-09 19:15 - 00106496 _____ (Marco Bellinaso) C:\WINDOWS\system32\mbprgbar.ocx
2016-09-06 13:18 - 2000-05-22 01:00 - 00608448 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.ocx
2016-09-06 13:18 - 2000-05-02 00:02 - 00110592 _____ (Common Controls Replacement Project (CCRP)) C:\WINDOWS\system32\ccrpbds6.dll
2016-09-06 13:18 - 1999-09-16 10:04 - 00151552 _____ (Domenico Statuto - CCRP) C:\WINDOWS\system32\ccrpfd6.ocx
2016-09-06 13:18 - 1998-06-24 01:00 - 00164144 _____ (Microsoft Corporation) C:\WINDOWS\system32\comct232.ocx
2016-09-06 13:18 - 1996-01-12 01:00 - 00200704 _____ (Sheridan Software Systems, Inc.) C:\WINDOWS\system32\threed32.ocx
2016-09-06 13:15 - 2016-09-06 22:18 - 00196608 _____ C:\WINDOWS\system32\config\Nano.evt
2016-09-06 13:15 - 2016-09-06 13:15 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Panda Free Antivirus
2016-09-06 11:46 - 2016-09-06 12:30 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\wetandpissy
2016-09-06 11:46 - 2016-09-06 11:49 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\old
2016-09-06 11:46 - 2016-09-06 11:46 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\Нова папка
2016-09-06 11:42 - 2016-09-06 20:58 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\WinSetupFromUSB-1-7
2016-09-06 11:40 - 2016-09-06 11:41 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\turk
2016-09-06 11:40 - 2016-09-06 11:40 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\TeamViewerPortable
2016-09-06 11:39 - 2016-09-06 11:40 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\simbian
2016-09-06 11:29 - 2016-09-06 18:46 - 00000000 ____D C:\Program Files\Hard Disk Sentinel
2016-09-06 11:29 - 2016-09-06 11:29 - 00000690 _____ C:\Documents and Settings\Valio\Desktop\Hard Disk Sentinel.lnk
2016-09-06 11:29 - 2016-09-06 11:29 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Hard Disk Sentinel
2016-09-06 11:25 - 2016-09-06 11:28 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\Sophia E
2016-09-06 11:22 - 2016-09-06 11:22 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\sharewareonsale_giveaway_hdsentinel_setup
2016-09-06 11:20 - 2016-09-06 11:20 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\NOVI
2016-09-06 11:20 - 2016-09-06 11:20 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\muziki
2016-09-06 11:15 - 2016-09-06 11:17 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\MPLMay
2016-09-06 11:12 - 2016-09-06 11:14 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\MPLFevral
2016-09-06 11:09 - 2016-09-06 11:12 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\MPLAvgust
2016-09-06 11:07 - 2016-09-06 11:07 - 00000000 ____D C:\Program Files\BitComet
2016-09-06 11:07 - 2016-02-06 23:29 - 00069824 _____ C:\Documents and Settings\Valio\My Documents\Антивирусни програми   Софтуер.htm
2016-09-06 11:07 - 2016-01-13 19:29 - 00220776 _____ C:\Documents and Settings\Valio\My Documents\arhiv abonati v skaip valio_andonov.vcf
2016-09-06 11:07 - 2016-01-04 19:00 - 00001022 _____ C:\Documents and Settings\Valio\My Documents\indexfile.txt
2016-09-06 11:07 - 2015-12-16 20:51 - 00144594 _____ C:\Documents and Settings\Valio\My Documents\otmetki ot opera .adr
2016-09-06 11:07 - 2011-01-01 15:29 - 03022787 _____ C:\Documents and Settings\Valio\My Documents\ASYA12LGC%20-%20AOYR12LGC%20-%20Technical.pdf
2016-09-06 11:07 - 2010-09-06 16:31 - 01034741 _____ C:\Documents and Settings\Valio\My Documents\whirlpool.pdf
2016-09-06 11:07 - 2010-05-15 19:52 - 00069167 _____ C:\Documents and Settings\Valio\My Documents\bookmarks.html
2016-09-06 11:07 - 2010-03-06 16:52 - 44193796 _____ C:\Documents and Settings\Valio\My Documents\Todor Jivkov.mpeg
2016-09-06 11:07 - 2009-12-27 20:13 - 00444098 _____ C:\Documents and Settings\Valio\My Documents\staq.sh3d
2016-09-06 11:07 - 2009-03-29 20:25 - 01036150 _____ C:\Documents and Settings\Valio\My Documents\AquariumV11.rar
2016-09-06 11:05 - 2016-09-06 11:05 - 00000000 ____D C:\Documents and Settings\Valio\My Documents\Изтегляния
2016-09-06 11:05 - 2016-09-06 11:05 - 00000000 ____D C:\Documents and Settings\Valio\My Documents\ViberDownloads
2016-09-06 11:04 - 2016-09-06 11:04 - 00000000 ___RD C:\Documents and Settings\Valio\My Documents\Shareaza Downloads
2016-09-06 11:04 - 2016-09-06 11:04 - 00000000 ____D C:\Documents and Settings\Valio\My Documents\sdc222
2016-09-06 11:04 - 2016-09-06 11:04 - 00000000 ____D C:\Documents and Settings\Valio\My Documents\MusicFrost
2016-09-06 11:04 - 2016-09-06 11:04 - 00000000 ____D C:\Documents and Settings\Valio\My Documents\ICQ Lite
2016-09-06 11:04 - 2016-09-06 11:04 - 00000000 ____D C:\Documents and Settings\Valio\My Documents\gegl-0.0
2016-09-06 11:04 - 2016-09-06 11:04 - 00000000 ____D C:\Documents and Settings\Valio\My Documents\FFOutput
2016-09-06 11:03 - 2016-09-06 13:26 - 00000000 ___RD C:\Documents and Settings\Valio\Desktop\Program Files
2016-09-06 11:03 - 2016-09-06 11:04 - 00000000 ___RD C:\Documents and Settings\Valio\My Documents\Dropbox
2016-09-06 11:03 - 2016-09-06 11:03 - 00000000 ____D C:\Documents and Settings\Valio\My Documents\Bluetooth Exchange Folder
2016-09-06 11:03 - 2016-09-06 11:03 - 00000000 ____D C:\Documents and Settings\Valio\My Documents\AquariumV11
2016-09-06 11:03 - 2016-09-06 11:03 - 00000000 ____D C:\Documents and Settings\Valio\My Documents\alia
2016-09-06 11:01 - 2016-09-06 11:01 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\MPL - 2011-07 Video
2016-09-06 10:55 - 2016-09-06 11:00 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\MET-ART  11 - 20 June  2015
2016-09-06 10:55 - 2016-09-06 10:55 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\lv6tboxhda2 notonly на vali преминават на стендбай - Страница 16 - Digital TV Forums - БЪЛГАРСКИЯТ ФОРУМ ЗА ЦИФРОВА ТЕЛЕВИЗИЯ_files
2016-09-06 10:53 - 2016-09-06 10:55 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\Lena pics
2016-09-06 10:53 - 2016-09-06 10:53 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\king
2016-09-06 10:53 - 2016-09-06 10:53 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\ireland
2016-09-06 10:52 - 2016-09-06 10:52 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\delux mouse
2016-09-06 10:52 - 2016-09-06 10:52 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\DCIM
2016-09-06 10:52 - 2016-09-06 10:52 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\Barbara_Pease_-_Zashto_myzhete_ne_ch1.txt
2016-09-06 10:50 - 2016-09-06 10:51 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\antivirus
2016-09-06 10:50 - 2016-09-06 10:50 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\2015
2016-09-06 10:50 - 2016-09-06 10:50 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\2014
2016-09-06 10:50 - 2016-09-06 10:50 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\2013
2016-09-06 10:50 - 2016-09-06 10:50 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\2012
2016-09-06 10:50 - 2016-09-06 10:50 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\2011
2016-09-06 10:47 - 2015-08-11 12:22 - 02895360 _____ C:\WINDOWS\system32\pwNative.exe
2016-09-06 10:47 - 2015-03-05 10:15 - 00017160 ____N C:\WINDOWS\system32\pwdrvio.sys
2016-09-06 10:47 - 2015-03-05 10:15 - 00013064 ____N C:\WINDOWS\system32\pwdspio.sys
2016-09-06 10:46 - 2016-09-06 10:47 - 00000000 ____D C:\Program Files\MiniTool Partition Wizard Free 9.1
2016-09-06 10:46 - 2016-09-06 10:46 - 00000854 _____ C:\Documents and Settings\All Users\Desktop\MiniTool Partition Wizard Free.lnk
2016-09-06 10:46 - 2016-09-06 10:46 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\MiniTool Partition Wizard Free 9.1
2016-09-06 09:55 - 2016-09-06 09:55 - 00373248 _____ (Acronis) C:\WINDOWS\system32\autoprnt.exe
2016-09-06 09:55 - 2016-09-06 09:55 - 00102400 _____ (Acronis) C:\WINDOWS\system32\snapapi.dll
2016-09-06 09:55 - 2016-09-06 09:55 - 00065856 _____ (Acronis) C:\WINDOWS\system32\Drivers\snapman.sys
2016-09-06 09:55 - 2016-09-06 09:55 - 00037888 _____ C:\WINDOWS\system32\setupnt.dll
2016-09-06 09:55 - 2016-09-06 09:55 - 00000936 _____ C:\Documents and Settings\Valio\Desktop\Acronis MigrateEasy.lnk
2016-09-06 09:55 - 2016-09-06 09:55 - 00000000 ____D C:\Program Files\Common Files\Acronis
2016-09-06 09:55 - 2016-09-06 09:55 - 00000000 ____D C:\Program Files\Acronis
2016-09-06 09:55 - 2016-09-06 09:55 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Acronis
2016-09-05 23:52 - 2016-09-05 23:53 - 41700480 _____ (Skype Technologies S.A.) C:\Documents and Settings\Valio\Desktop\SkypeSetupFullXp.exe
2016-09-05 20:50 - 2016-09-06 13:46 - 00000875 _____ C:\Documents and Settings\Valio\Desktop\Viber.lnk
2016-09-05 19:51 - 2016-09-05 19:51 - 00937080 _____ (Akeo Consulting (hxxp://akeo.ie)) C:\Documents and Settings\Valio\Desktop\rufus-2.10p.exe
2016-09-04 22:28 - 2012-03-17 19:07 - 259157272 _____ C:\Documents and Settings\Valio\Desktop\3123v_hi.avi
2016-09-04 20:19 - 2016-02-10 20:51 - 19057568 _____ (Microsoft) C:\Documents and Settings\Valio\Desktop\NokiaSoftwareRecoveryToolInstaller.exe
2016-09-02 22:39 - 2016-09-02 22:39 - 01038335 _____ C:\Documents and Settings\Valio\Desktop\[Guru3D.com]-DDU.zip
2016-09-02 21:42 - 2016-09-06 13:17 - 00000656 _____ C:\Documents and Settings\Valio\Desktop\Пряк път до Ultra Video Joiner.exe.lnk
2016-09-02 21:41 - 2016-09-02 21:41 - 00000706 _____ C:\Documents and Settings\Valio\Desktop\Пряк път до DCPlusPlus.exe.lnk
2016-09-02 21:36 - 2016-09-06 13:18 - 00000706 _____ C:\Documents and Settings\Valio\Desktop\PIXresizer.lnk
2016-09-02 21:30 - 2016-09-06 13:33 - 00000682 _____ C:\Documents and Settings\Valio\Desktop\Пряк път до BitComet.exe.lnk
2016-09-02 21:25 - 2016-09-02 21:25 - 03826240 _____ C:\Documents and Settings\Valio\Desktop\adwcleaner_6.010.exe
2016-09-02 21:01 - 2016-09-02 21:02 - 36580047 _____ (KLCP ) C:\Documents and Settings\Valio\Desktop\K-Lite_Codec_Pack_1235_Full.exe
2016-09-01 18:13 - 2016-08-27 21:44 - 06543984 _____ (IObit ) C:\Documents and Settings\Valio\Desktop\AWCSetup_Major.exe
2016-09-01 18:13 - 2016-03-05 18:57 - 31095938 _____ C:\Documents and Settings\Valio\Desktop\bg-science86.pdf
2016-09-01 18:13 - 2016-01-14 21:26 - 30984401 _____ C:\Documents and Settings\Valio\Desktop\bg-science84.pdf
2016-09-01 18:13 - 2015-12-18 21:59 - 19819451 ____R C:\Documents and Settings\Valio\Desktop\2015-12-18 Valio 2690.nbu
2016-09-01 18:13 - 2015-01-23 10:38 - 156129250 _____ C:\Documents and Settings\Valio\Desktop\95a14b0fd6153328c12fe1072b3f3be0.flv
2016-09-01 18:13 - 2010-04-17 14:28 - 56804132 _____ C:\Documents and Settings\Valio\Desktop\2DB06C3-48942980.avi
2016-09-01 18:13 - 2010-03-03 19:08 - 00921011 _____ C:\Documents and Settings\Valio\Desktop\ConnectifyInstaller.exe
2016-09-01 18:12 - 2016-09-06 13:17 - 00000620 _____ C:\Documents and Settings\Valio\Desktop\Sweet Home 3D.lnk
2016-09-01 18:12 - 2016-09-04 19:47 - 00000734 _____ C:\Documents and Settings\Valio\Desktop\Start Tor Browser.lnk
2016-09-01 18:12 - 2016-09-04 18:27 - 00000697 _____ C:\Documents and Settings\Valio\Desktop\StrongDC.lnk
2016-09-01 18:12 - 2016-08-26 21:21 - 02342176 _____ (Panda Security, S.L.) C:\Documents and Settings\Valio\Desktop\PANDAFREEAV.exe
2016-09-01 18:12 - 2016-03-25 22:22 - 00088238 _____ C:\Documents and Settings\Valio\Desktop\lv6tboxhda2 notonly на vali преминават на стендбай - Страница 16 - Digital TV Forums - БЪЛГАРСКИЯТ ФОРУМ ЗА ЦИФРОВА ТЕЛЕВИЗИЯ.htm
2016-09-01 18:12 - 2016-03-25 21:35 - 02603732 _____ C:\Documents and Settings\Valio\Desktop\J1300660_MC6379_LV6TBOXHDA2_V1.0.9_20131120-.rar
2016-09-01 18:12 - 2016-03-07 18:49 - 09553766 _____ C:\Documents and Settings\Valio\Desktop\rsload.net.HL.P.4.1.203.zip
2016-09-01 18:12 - 2016-03-04 22:55 - 01094289 _____ C:\Documents and Settings\Valio\Desktop\Psiloc_ir_remote_update_database_1.04-worked.rar
2016-09-01 18:12 - 2016-02-26 22:22 - 00000062 _____ C:\Documents and Settings\Valio\Desktop\listen.pls
2016-09-01 18:12 - 2016-01-09 15:19 - 02500096 _____ (rejetto) C:\Documents and Settings\Valio\Desktop\hfs.exe
2016-09-01 18:12 - 2015-11-05 19:46 - 00101811 _____ C:\Documents and Settings\Valio\Desktop\results-2015-11-04.pdf
2016-09-01 18:12 - 2015-09-25 22:33 - 13935966 _____ (Favorite-Games 2001-2013 © ) C:\Documents and Settings\Valio\Desktop\favorite-games_bg.exe
2016-09-01 18:12 - 2015-09-21 15:58 - 06930432 _____ C:\Documents and Settings\Valio\Desktop\SkypeWebPlugin.msi
2016-09-01 18:12 - 2015-09-04 23:46 - 24178176 _____ (SAMSUNG Electronics Co., Ltd.) C:\Documents and Settings\Valio\Desktop\samsung_android_usb_driver.exe
2016-09-01 18:12 - 2015-06-26 21:25 - 07332272 _____ C:\Documents and Settings\Valio\Desktop\MyPhoneExplorer_Setup_v1.8.6.exe
2016-09-01 18:12 - 2014-08-20 22:07 - 19531504 _____ (SAMSUNG Electronics Co., Ltd.) C:\Documents and Settings\Valio\Desktop\SAMSUNG_USB_Driver_for_Mobile_Phones.exe
2016-09-01 18:12 - 2014-08-20 08:51 - 21633320 _____ (Skype Technologies S.A.) C:\Documents and Settings\Valio\Desktop\Sky38i.exe
2016-09-01 18:12 - 2014-04-30 09:31 - 01954304 _____ (Topala Software Solutions) C:\Documents and Settings\Valio\Desktop\siw.exe
2016-09-01 18:12 - 2012-03-19 15:46 - 67735119 ____H (PortableAppZ.blogspot.com) C:\Documents and Settings\Valio\Desktop\Photoshop_Portable_12.0_en-fr-de-es-it-ru-zh-tw.paf.exe
2016-09-01 18:12 - 2010-08-15 14:16 - 02769333 _____ C:\Documents and Settings\Valio\Desktop\thebible.pdf
2016-09-01 18:12 - 2010-06-06 18:03 - 00320849 _____ C:\Documents and Settings\Valio\Desktop\standart_psihiatriq.pdf
2016-09-01 18:12 - 2010-03-05 12:07 - 00904704 _____ (KaKasoft) C:\Documents and Settings\Valio\Desktop\lockdir.exe
2016-09-01 18:12 - 2007-07-22 16:39 - 00032768 _____ (KenamicK Entertainment) C:\Documents and Settings\Valio\Desktop\opencd.exe
2016-09-01 18:12 - 2005-09-11 22:57 - 00331776 _____ () C:\Documents and Settings\Valio\Desktop\ShutdownTimer.exe
2016-09-01 18:11 - 2016-09-04 19:10 - 00000936 _____ C:\Documents and Settings\Valio\Desktop\Пряк път до GIMPPortable.exe.lnk
2016-09-01 18:11 - 2016-09-04 18:28 - 00000914 _____ C:\Documents and Settings\Valio\Desktop\Пряк път до FSViewer.exe.lnk
2016-09-01 18:11 - 2016-09-04 18:28 - 00000675 _____ C:\Documents and Settings\Valio\Desktop\Пряк път до Diction.exe.lnk
2016-09-01 18:11 - 2016-09-04 18:27 - 00000664 _____ C:\Documents and Settings\Valio\Desktop\Пряк път до WNetWatcher.exe.lnk
2016-09-01 18:11 - 2016-03-04 12:03 - 32047935 _____ C:\Documents and Settings\Valio\Desktop\Мега окончание.mp4
2016-09-01 18:11 - 2015-11-29 15:18 - 00000036 _____ C:\Documents and Settings\Valio\Desktop\Нов Текстов документ (3).txt
2016-09-01 18:11 - 2011-03-27 13:27 - 00000146 _____ C:\Documents and Settings\Valio\Desktop\Нов Текстов документ (2).txt
2016-09-01 18:11 - 2010-01-31 18:30 - 00000019 _____ C:\Documents and Settings\Valio\Desktop\Нов Текстов документ (4).bat
2016-09-01 18:11 - 2008-12-21 18:09 - 00146378 _____ C:\Documents and Settings\Valio\Desktop\Нов Текстов документ.txt
2016-08-31 21:15 - 2016-09-06 18:35 - 00000706 _____ C:\Documents and Settings\Valio\Desktop\WhoCrashed.lnk
2016-08-10 20:14 - 2016-08-10 20:14 - 00000000 ____D C:\Program Files\Samsung
2016-08-10 20:14 - 2016-08-10 20:14 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Samsung
2016-08-10 20:12 - 2016-08-10 20:12 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\TL-WN721N_V1_140915
2016-08-10 20:12 - 2013-06-29 06:49 - 01763584 _____ (Atheros Communications, Inc.) C:\WINDOWS\system32\Drivers\athuw.sys

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-09-06 22:35 - 2010-11-07 20:23 - 00000000 ____D C:\Documents and Settings\Valio\Local Settings\Temp
2016-09-06 22:32 - 2010-11-07 22:01 - 00000000 ___HD C:\WINDOWS\inf
2016-09-06 22:32 - 2010-11-07 20:22 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-09-06 22:18 - 2010-11-07 21:02 - 00524288 _____ C:\WINDOWS\system32\config\ACEEvent.evt
2016-09-06 22:18 - 2010-11-07 20:23 - 00000178 ___SH C:\Documents and Settings\Valio\ntuser.ini
2016-09-06 22:18 - 2010-11-07 20:22 - 00029312 _____ C:\WINDOWS\SchedLgU.Txt
2016-09-06 22:17 - 2015-12-02 20:37 - 01037824 _____ (Microsoft Corporation) C:\WINDOWS\system32\svсhоst.exe
2016-09-06 20:58 - 2014-08-13 17:05 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy
2016-09-06 20:58 - 2010-11-07 22:08 - 00000000 ____D C:\Documents and Settings\All Users
2016-09-06 20:56 - 2010-11-07 22:09 - 00464096 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-09-06 20:36 - 2013-06-29 21:20 - 00796352 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2016-09-06 20:36 - 2013-06-29 21:20 - 00142528 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2016-09-06 20:30 - 2011-01-30 20:58 - 00000000 ____D C:\Documents and Settings\Valio\Application Data\Skype
2016-09-06 20:21 - 2013-07-14 13:08 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2016-09-06 20:15 - 2011-01-30 20:57 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Skype
2016-09-06 19:27 - 2010-11-07 20:23 - 00000000 ____D C:\Documents and Settings\Valio
2016-09-06 19:21 - 2011-01-30 21:00 - 00000000 ____D C:\Program Files\Mozilla Firefox
2016-09-06 18:54 - 2002-01-01 01:12 - 00000000 ____D C:\WINDOWS\Minidump
2016-09-06 18:31 - 2010-11-07 22:01 - 00000000 RSHDC C:\WINDOWS\system32\dllcache
2016-09-06 16:47 - 2010-11-07 20:23 - 00000803 _____ C:\Documents and Settings\Valio\Start Menu\Programs\Internet Explorer.lnk
2016-09-06 16:47 - 2010-11-07 20:23 - 00000000 ___RD C:\Documents and Settings\Valio\My Documents\My Pictures
2016-09-06 16:47 - 2010-11-07 20:23 - 00000000 ___RD C:\Documents and Settings\Valio\My Documents\My Music
2016-09-06 16:47 - 2010-11-07 20:23 - 00000000 ___RD C:\Documents and Settings\Valio\My Documents
2016-09-06 16:47 - 2010-11-07 20:22 - 00000000 __SHD C:\Documents and Settings\LocalService
2016-09-06 16:46 - 2010-11-07 22:08 - 00100640 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-09-06 16:46 - 2010-11-07 22:01 - 00000000 ____D C:\WINDOWS\Help
2016-09-06 16:22 - 2010-11-07 22:01 - 00000000 ____D C:\WINDOWS\Media
2016-09-06 14:47 - 2016-03-20 22:30 - 00170200 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-09-06 14:43 - 2010-11-07 22:08 - 00000000 ____D C:\Documents and Settings
2016-09-06 14:38 - 2016-03-20 22:29 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2016-09-06 14:38 - 2016-03-20 22:29 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
2016-09-06 14:38 - 2016-03-20 22:24 - 00000777 _____ C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2016-09-06 13:15 - 2014-04-14 22:56 - 00000000 ____D C:\Documents and Settings\Valio\Application Data\Panda Security
2016-09-06 13:15 - 2014-04-14 22:54 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Panda Security
2016-09-06 13:15 - 2010-11-07 20:54 - 00012800 _____ C:\Documents and Settings\Valio\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2016-09-06 13:14 - 2016-03-08 20:49 - 00000000 ____D C:\Program Files\Panda Security
2016-09-06 10:47 - 2010-11-07 22:07 - 00000211 ___SH C:\boot.ini
2016-09-06 09:46 - 2008-04-14 15:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2016-08-28 18:36 - 2010-11-07 20:16 - 00000000 ____D C:\WINDOWS\system32\Macromed
2016-08-10 20:06 - 2010-11-07 20:21 - 00000000 __SHD C:\Documents and Settings\NetworkService
2016-08-10 20:06 - 2010-11-07 20:15 - 00000000 ____D C:\WINDOWS\Registration
2016-08-10 20:04 - 2014-04-14 23:06 - 00227960 _____ C:\WINDOWS\ntbtlog.txt

==================== Files in the root of some directories =======

2016-03-06 19:04 - 2016-03-06 19:04 - 0000000 _____ () C:\Documents and Settings\All Users\Application Data\0x0304A000.sfl

Some files in TEMP:
====================
C:\Documents and Settings\Valio\Local Settings\Temp\libeay32.dll
C:\Documents and Settings\Valio\Local Settings\Temp\lsаss.exe
C:\Documents and Settings\Valio\Local Settings\Temp\msvcr120.dll
C:\Documents and Settings\Valio\Local Settings\Temp\SkypeSetup.exe
C:\Documents and Settings\Valio\Local Settings\Temp\Skype_7.0.0.102.exe
C:\Documents and Settings\Valio\Local Settings\Temp\sqlite3.dll


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

==================== End of FRST.txt ============================

 

Здравейте,

Мисля, че вируса стартира оттук...използвал е легитимно име, не съвсем. Ако се изпише ръчно lsass.exe търсачката на Windows ще го намери, но като копирах името от лог файла ви и търсачката не го намира...явно са хитрували нещо или са използвали някакви специални символи...

Startup: C:\Documents and Settings\Valio\Start Menu\Programs\Startup\LocalSystem.lnk [2016-09-06]
ShortcutTarget: LocalSystem.lnk -> C:\WINDOWS\system32\lsаss.exe (Microsoft Corporation)

Та бих искал да отворите Virustotal.com

Изберете "Избиране" копирайте C:\WINDOWS\system32\lsаss.exe директно оттук (не го въвеждайте ръчно) и проверете файла и публикувайте линка с резултатите в следващия си коментар.

  • Автор

Да, точно там е била заразата. Сканирах под сейв мод с MBAM и хитман про и го намериха като gen:heur.msil.krypt.2 във lsass.exe изтрих го с мбам и вече папката не се появява при рестартиране. Преди това като я изтриех и след рестарт се появяваше. Между другото под сейв мод също не се беше създала, явно е действала при всяко нормално стартиране. За щастие я видях навреме.

Сега файлът е чист https://www.virustotal.com/bg/file/f7794b5d12dc5d820a162850f4388e2aa80426ad07cb221799cf941c682ab501/analysis/1473198136/

Дали може вече да съм спокоен че всичко е наред?

Оффф...всичко объркахте! Трябваше ми Hash стойността на заразата. Няма какво да ми сканирате оригиналния файл, който е ясно, че ще е чист след като не е пачнат. Това са два различни файла като заразения е създаден да прилича на оригиналния, както вече писах, но буквата a не е на английски език, а е написана с кирилица.

Ще е добре, ако можете да видите дали изтрития файл се намира в карантинната папка на MBAM или HitmanPro и ако да, да го възстановите оттам и да ми ги пратите за анализ. След това ако искате пак го изтрийте.

  • Автор

Ето анализа на заразения файл https://www.virustotal.com/bg/file/f9d087a488ecd5055323b07ee4bae2577b637c61431eb3fcbd45ea866b61cff0/analysis/1473199477/ 

Ако ви трябва и самия файл, кажете къде да ви го пратя.

 

Може да ви е от полза и това че изкарваше тази грешка при всяко стартиранебез име.JPG

Редактирано от baitexpo (преглед на промените)

Ок, благодаря за файла. Колегите на които им бе нужен файла могат да си го свалят от VirusTotal услугата та можете да го изтриете.

Ако искате да проверим системата ще е добре да следвате инструкциите и да не правите нищи на своя глава, защото това ще повлияе на крайните резултати!

Покажете ми логовете от инструментите с които сте почиствали без мое знание и освен това направете нова проверка с FRST след като вече логовете са променени (като не забравите да сложите отметка пред Addition.txt преди да натиснете бутона SCAN) и прикачете новите резултати.

Утре ще ги погледна обаче, защото мисля да лягам.

Поздрави!

Поради липса на обратна връзка случая се маркира като приключен макар за мен проблема да е решен! Видях, че автора има и такава тема в data.bg и оттам са го посъветвали да сканира с MBAM и HitmanPro, които почистиха системата му, но пък и аз успях да идентифицирам заразата и без тези инструменти та считам за честно заслугите да са и на двата форума.

  • Автор

Нямах възможност да пиша по-рано и ще се радвам ако докараме нещата до щастлив край. Заслугата за решаването на проблема е на всички отделили от времето си и дали адекватни отговори  без значение в този или друг форум. Ще съм благодарен ако прегледате логовете, за да съм спокоен и да приема проблема за решен :-)

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 31-08-2016
Ran by Valio (administrator) on VALIO-PC (08-09-2016 20:58:39)
Running from C:\Documents and Settings\Valio\Desktop
Loaded Profiles: Valio (Available Profiles: Valio)
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) Language: English (United States)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(VIA Technologies, Inc.) C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(BinarySense, Ltd.) C:\Program Files\BinarySense\HDDlife\HDDlifePro.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\WINDOWS\system32\dumprep.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [BluetoothAuthenticationAgent] => rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
HKLM\...\Run: [HDAudDeck] => C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe [33673216 2009-08-28] (VIA Technologies, Inc.)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-09-10] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [ATICustomerCare] => C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe [311296 2010-05-04] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9107104 2016-09-07] (AVAST Software)
HKLM Group Policy restriction on software: *.pub*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.js <====== ATTENTION
HKLM Group Policy restriction on software: cipher.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\*\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Start Menu\Programs\Startup\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\*\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Start Menu\Programs\Startup\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.js <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.com <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\*\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\*\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.exe <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\*\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\*\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*\svchost.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\*\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Start Menu\Programs\Startup\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\*\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.com <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\*\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.com <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Start Menu\Programs\Startup\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Start Menu\Programs\Startup\*.js <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\*.com <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.js <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\*\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\*\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.com <====== ATTENTION
HKLM Group Policy restriction on software: vssadmin.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\*\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Start Menu\Programs\Startup\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\*\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\*\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\*\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Start Menu\Programs\Startup\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\*\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.com <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Start Menu\Programs\Startup\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\Microsoft\Windows\IEUpdate\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\*\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\*\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: ** <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.exe <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Start Menu\Programs\Startup\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.scr <====== ATTENTION
HKLM Group Policy restriction on software: syskey.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: lsassvrtdbks.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Start Menu\Programs\Startup\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *:\RECYCLER <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\*\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Start Menu\Programs\Startup\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\*\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.com <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\*\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.js <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\*\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\*\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %programfiles%\*\svchost.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.com <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\*\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.js <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: scsvserv.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\*\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\*\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.js <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\*\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Start Menu\Programs\Startup\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\*\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.js <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.bat <====== ATTENTION
HKLM Group Policy restriction on software: lsassw86s.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Start Menu\Programs\Startup\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\*\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\*\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\*\*.com <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Start Menu\Programs\Startup\*.js <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\*.js <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %systemdrive%\*\svchost.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Start Menu\Programs\Startup\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.js <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.js <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Start Menu\Programs\Startup\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\*\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\viber\updater.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\viber\viber.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\viber\qtwebengineprocess.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\viber\linkparser.exe <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\viber\qtwebengineprocess.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\viber\updater.exe <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\viber\viber.exe <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\viber\updater.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\viber\updater.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\viber\qtwebengineprocess.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\viber\updater.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\viber\linkparser.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\viber\viber.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Local Settings\Application Data\viber\linkparser.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\viber\qtwebengineprocess.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Application Data\viber\linkparser.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\viber\viber.exe <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\viber\linkparser.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Application Data\viber\qtwebengineprocess.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\Local Settings\Application Data\viber\viber.exe <====== ATTENTION
Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll [2010-09-11] (ATI Technologies Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2016-09-07] (AVAST Software)
Startup: C:\Documents and Settings\Valio\Start Menu\Programs\Startup\HDDlife.lnk [2016-09-08]
ShortcutTarget: HDDlife.lnk -> C:\Program Files\BinarySense\HDDlife\HDDlifePro.exe (BinarySense, Ltd.)
GroupPolicyScripts: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.137.1
Tcpip\..\Interfaces\{06CABE20-480A-4AA0-9CC1-AA36453BEC30}: [DhcpNameServer] 192.168.137.1
Tcpip\..\Interfaces\{799F7017-7406-4F39-919E-BB864845E776}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{A252AF90-EA63-4EC7-B1E1-457811249394}: [DhcpNameServer] 192.168.43.1
Tcpip\..\Interfaces\{C5DBAAF7-1739-484D-AE2D-C517657F1640}: [DhcpNameServer] 192.168.137.1
Tcpip\..\Interfaces\{CA100D9E-F1C7-4A77-A69D-963437D8BDCA}: [DhcpNameServer] 192.168.137.1
Tcpip\..\Interfaces\{F19BF960-CE76-4F20-BD48-BE12EAA8AC0E}: [DhcpNameServer] 192.168.137.1
Tcpip\..\Interfaces\{FAE64C97-ECD7-4296-8BD4-603BEEC607B1}: [DhcpNameServer] 192.168.137.1

Internet Explorer:
==================
HKU\S-1-5-21-2052111302-630328440-1801674531-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.bg/
HKU\S-1-5-21-2052111302-630328440-1801674531-1003\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-09-07] (AVAST Software)

FireFox:
========
FF ProfilePath: C:\Documents and Settings\Valio\Application Data\Mozilla\Firefox\Profiles\tbt07bz3.default
FF DefaultSearchEngine: Google Custom Search
FF Homepage: hxxps://google.bg
FF Keyword.URL: hxxp://search.musicfrost.com/results.php?q=
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_22_0_0_209.dll [2016-09-06] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npFoxitReaderPlugin.dll [2016-09-06] (Foxit Software Company)
FF SearchPlugin: C:\Documents and Settings\Valio\Application Data\Mozilla\Firefox\Profiles\tbt07bz3.default\searchplugins\daemon-search.xml [2010-09-13]
FF SearchPlugin: C:\Documents and Settings\Valio\Application Data\Mozilla\Firefox\Profiles\tbt07bz3.default\searchplugins\MFGSearch.xml [2011-01-29]
FF Extension: (Forecastfox) - C:\Documents and Settings\Valio\Application Data\Mozilla\Firefox\Profiles\tbt07bz3.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3} [2016-09-06]
FF Extension: (oldbar) - C:\Documents and Settings\Valio\Application Data\Mozilla\Firefox\Profiles\tbt07bz3.default\extensions\{46868735-c3fa-47ce-8ce7-cce51a66aceb}.xpi [2016-09-06]
FF Extension: (Forecastfox (fix version)) - C:\Documents and Settings\Valio\Application Data\Mozilla\Firefox\Profiles\tbt07bz3.default\extensions\forecastfox@s3_fix_version.xpi [2016-09-06]
FF Extension: (Bulgarian Dictionary) - C:\Documents and Settings\Valio\Application Data\Mozilla\Firefox\Profiles\tbt07bz3.default\Extensions\[email protected] [2016-03-06] [not signed]
FF Extension: (YouTube™ Flash® Player) - C:\Documents and Settings\Valio\Application Data\Mozilla\Firefox\Profiles\tbt07bz3.default\Extensions\[email protected] [2016-09-06]
FF Extension: (Firefox Hello Beta) - C:\Documents and Settings\Valio\Application Data\Mozilla\Firefox\Profiles\tbt07bz3.default\Extensions\[email protected] [2016-09-06]
FF Extension: (Модул за сканиране на уеб адреси) - C:\Program Files\Mozilla Firefox\extensions\[email protected]_bak [2011-02-13] [not signed]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\[email protected] => not found
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\[email protected] => not found
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-09-07]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-09-07]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-09-07] (AVAST Software)
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2015-05-21] (DEVGURU Co., LTD.)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AR9271; C:\WINDOWS\System32\DRIVERS\athuw.sys [1763584 2013-06-29] (Atheros Communications, Inc.)
S3 asusgsb; C:\WINDOWS\System32\drivers\asusgsb.sys [12416 2009-02-17] (ASUSTeK Computer Inc.) [File not signed]
S3 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [34008 2016-09-07] (AVAST Software)
R1 aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [35096 2016-09-07] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [92256 2016-09-07] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [64272 2016-09-07] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [60424 2016-09-07] (AVAST Software)
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [735352 2016-09-07] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [434144 2016-09-07] (AVAST Software)
R3 aswStmXP; C:\WINDOWS\system32\drivers\aswStmXP.sys [184592 2016-09-07] (AVAST Software)
S3 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [66688 2016-09-07] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [224616 2016-09-07] (AVAST Software)
R3 AtiHDAudioService; C:\WINDOWS\System32\drivers\AtihdXP3.sys [101904 2010-07-21] (ATI Technologies, Inc.)
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
R2 EIO_XP; C:\WINDOWS\system32\drivers\EIO_XP.sys [14336 2009-07-30] (ASUSTeK Computer Inc.) [File not signed]
S3 es1371; C:\WINDOWS\System32\drivers\es1371mp.sys [40704 2001-08-17] (Creative Technology Ltd.)
S3 hitmanpro37; C:\WINDOWS\system32\drivers\hitmanpro37.sys [39280 2016-09-07] ()
R1 HWiNFO32; C:\WINDOWS\system32\drivers\HWiNFO32.SYS [23840 2016-09-06] (REALiX(tm))
R3 L1e; C:\WINDOWS\System32\DRIVERS\l1e51x86.sys [39424 2009-08-05] (Atheros Communications, Inc.)
R3 MTsensor; C:\WINDOWS\System32\DRIVERS\ASACPI.sys [5810 2004-08-13] ()
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
R0 pwdrvio; C:\WINDOWS\System32\pwdrvio.sys [17160 2015-03-05] ()
S3 pwdspio; C:\WINDOWS\system32\pwdspio.sys [13064 2015-03-05] ()
R3 RT73; C:\WINDOWS\System32\DRIVERS\rt73.sys [451968 2007-10-01] (Ralink Technology, Corp.)
R0 snapman; C:\WINDOWS\System32\DRIVERS\snapman.sys [65856 2016-09-06] (Acronis) [File not signed]
R0 sptd; C:\WINDOWS\System32\Drivers\sptd.sys [691696 2016-03-06] () [File not signed]
R1 Tcpip; C:\WINDOWS\System32\DRIVERS\tcpip.sys [361344 2010-11-07] (Microsoft Corporation) [File not signed]
S3 VBoxNetAdp; C:\WINDOWS\System32\DRIVERS\VBoxNetAdp.sys [95376 2009-10-29] (Sun Microsystems, Inc.)
S3 VBoxUSB; C:\WINDOWS\System32\Drivers\VBoxUSB.sys [32016 2009-10-29] (Sun Microsystems, Inc.)
R3 VIAHdAudAddService; C:\WINDOWS\System32\drivers\viahduaa.sys [1390976 2009-08-17] (VIA Technologies, Inc.)
S4 IntelIde; no ImagePath
S3 SNP325; system32\DRIVERS\snp325.sys [X]
S3 StarOpen; no ImagePath
S3 tosporte; system32\DRIVERS\tosporte.sys [X]
S3 Tosrfcom; System32\Drivers\tosrfcom.sys [X]
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]
S3 Video3D; System32\Drivers\Video3D32.sys [X]
U1 WS2IFSL; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-09-07 20:12 - 2016-09-08 19:56 - 00002265 _____ C:\Documents and Settings\All Users\Desktop\Skype.lnk
2016-09-07 20:12 - 2016-09-07 20:12 - 00000000 ____D C:\Program Files\Common Files\Skype
2016-09-07 20:12 - 2016-09-07 20:12 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Skype
2016-09-07 20:11 - 2016-09-07 20:11 - 00000000 ____D C:\Documents and Settings\Valio\Local Settings\Application Data\Temp
2016-09-07 20:07 - 2016-09-08 20:07 - 00000482 _____ C:\WINDOWS\Tasks\SafeZone scheduled Autoupdate 1473268038.job
2016-09-07 20:07 - 2016-09-07 20:07 - 00000756 _____ C:\Documents and Settings\All Users\Start Menu\Programs\Avast SafeZone Browser.lnk
2016-09-07 20:07 - 2016-09-07 20:07 - 00000756 _____ C:\Documents and Settings\All Users\Desktop\Avast SafeZone Browser.lnk
2016-09-07 20:07 - 2016-09-07 20:07 - 00000000 ____D C:\Documents and Settings\Valio\Local Settings\Application Data\CEF
2016-09-07 20:06 - 2016-09-07 20:06 - 00035096 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys
2016-09-07 20:04 - 2016-09-07 20:04 - 00001689 _____ C:\Documents and Settings\All Users\Desktop\Avast Free Antivirus.lnk
2016-09-07 20:04 - 2016-09-07 20:04 - 00000000 ____D C:\Documents and Settings\Valio\Application Data\AVAST Software
2016-09-07 20:04 - 2016-09-07 20:04 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\AVAST Software
2016-09-07 20:03 - 2016-09-08 20:03 - 00000314 ____H C:\WINDOWS\Tasks\avast! Emergency Update.job
2016-09-07 20:03 - 2016-09-07 20:03 - 00000000 __HDC C:\WINDOWS\$NtUninstallWdf01009$
2016-09-07 20:03 - 2016-09-07 20:02 - 00921280 _____ (Microsoft Corporation) C:\WINDOWS\ucrtbase.dll
2016-09-07 20:03 - 2016-09-07 20:02 - 00735352 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2016-09-07 20:03 - 2016-09-07 20:02 - 00434144 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2016-09-07 20:03 - 2016-09-07 20:02 - 00319760 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2016-09-07 20:03 - 2016-09-07 20:02 - 00224616 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2016-09-07 20:03 - 2016-09-07 20:02 - 00184592 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStmXP.sys
2016-09-07 20:03 - 2016-09-07 20:02 - 00092256 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2016-09-07 20:03 - 2016-09-07 20:02 - 00066688 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswTdi.sys
2016-09-07 20:03 - 2016-09-07 20:02 - 00064272 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr.sys
2016-09-07 20:03 - 2016-09-07 20:02 - 00060424 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2016-09-07 20:03 - 2016-09-07 20:02 - 00034008 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2016-09-07 20:03 - 2008-11-07 18:55 - 00016928 ____N (Microsoft Corporation) C:\WINDOWS\system32\spmsgXP_2k3.dll
2016-09-07 20:02 - 2016-09-07 20:02 - 00053208 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2016-09-07 20:00 - 2016-09-07 20:06 - 00000000 ____D C:\Program Files\AVAST Software
2016-09-07 19:59 - 2016-09-07 20:06 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\AVAST Software
2016-09-07 19:49 - 2016-09-07 19:49 - 06253640 _____ (AVAST Software) C:\Documents and Settings\Valio\Desktop\avast_free_antivirus_setup_online_cnet_2.exe
2016-09-07 19:12 - 2016-09-07 19:12 - 00000278 _____ C:\WINDOWS\system32\.crusader
2016-09-07 01:02 - 2016-09-07 01:02 - 00170200 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\2B8B3BA1.sys
2016-09-07 00:07 - 2016-09-07 01:14 - 00000000 ____D C:\Kaspersky Rescue Disk 10.0
2016-09-07 00:04 - 2016-09-07 19:57 - 00065536 _____ C:\WINDOWS\system32\config\Kaspersk.evt
2016-09-06 23:46 - 2016-09-07 19:14 - 00039280 _____ C:\WINDOWS\system32\Drivers\hitmanpro37.sys
2016-09-06 23:43 - 2016-09-06 23:43 - 00000000 ____D C:\WINDOWS\CSC
2016-09-06 23:41 - 2016-09-07 19:57 - 00080138 _____ C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
2016-09-06 23:41 - 2016-09-07 19:54 - 00080138 _____ C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-2052111302-630328440-1801674531-1003-0.dat
2016-09-06 23:08 - 2016-09-06 23:08 - 00002003 _____ C:\RarVault0.rar
2016-09-06 22:50 - 2016-09-06 23:09 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\HitmanPro
2016-09-06 22:45 - 2016-09-06 22:47 - 10451640 _____ (SurfRight B.V.) C:\Documents and Settings\Valio\Desktop\hitmanpro.exe
2016-09-06 22:37 - 2016-09-06 22:37 - 00000000 ____D C:\WINDOWS\pss
2016-09-06 22:36 - 2016-09-08 20:57 - 00007423 _____ C:\Documents and Settings\Valio\Desktop\Addition.txt
2016-09-06 22:34 - 2016-09-08 20:58 - 00041377 _____ C:\Documents and Settings\Valio\Desktop\FRST.txt
2016-09-06 22:34 - 2016-09-08 20:58 - 00000000 ____D C:\FRST
2016-09-06 22:34 - 2016-09-06 22:29 - 01747968 _____ (Farbar) C:\Documents and Settings\Valio\Desktop\FRST.exe
2016-09-06 21:02 - 2016-09-06 21:02 - 02307616 _____ (Kaspersky Lab) C:\Documents and Settings\Valio\Desktop\kts17.0.0.611en_10781.exe
2016-09-06 20:58 - 2016-09-06 20:58 - 00000400 __RSH C:\Documents and Settings\All Users\ntuser.pol
2016-09-06 20:58 - 2016-09-06 20:58 - 00000067 _____ C:\Documents and Settings\Valio\Desktop\rufus.ini
2016-09-06 20:54 - 2016-09-06 20:58 - 291952640 _____ C:\Documents and Settings\Valio\Desktop\kav_rescue_10.iso
2016-09-06 20:49 - 2016-09-06 20:49 - 02619784 _____ (Foolish IT LLC ) C:\Documents and Settings\Valio\Desktop\CryptoPreventSetup.exe
2016-09-06 20:49 - 2016-09-06 20:49 - 00000865 _____ C:\Documents and Settings\All Users\Desktop\CryptoPrevent.lnk
2016-09-06 20:49 - 2016-09-06 20:49 - 00000000 ____D C:\Program Files\Foolish IT
2016-09-06 20:49 - 2016-09-06 20:49 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Foolish IT
2016-09-06 20:47 - 2016-09-06 23:08 - 00458638 _____ C:\RarVault.rar
2016-09-06 20:46 - 2016-09-06 22:39 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\TOSHIBA
2016-09-06 20:46 - 2016-09-06 20:46 - 00000000 ____D C:\Documents and Settings\Valio\Local Settings\Application Data\Toshiba
2016-09-06 20:38 - 2016-09-06 20:38 - 00002419 _____ C:\Documents and Settings\Valio\Local Settings\Temp2.html
2016-09-06 20:29 - 2016-09-06 20:29 - 00000882 _____ C:\Documents and Settings\All Users\Desktop\Revo Uninstaller.lnk
2016-09-06 20:29 - 2016-09-06 20:29 - 00000000 ____D C:\Program Files\VS Revo Group
2016-09-06 20:29 - 2016-09-06 20:29 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Revo Uninstaller
2016-09-06 20:27 - 2016-09-06 20:27 - 00000000 ____D C:\Program Files\Toshiba
2016-09-06 20:17 - 2016-09-06 23:21 - 00000000 ____D C:\AdwCleaner
2016-09-06 19:48 - 2016-09-06 19:48 - 00000917 _____ C:\Documents and Settings\All Users\Desktop\Free Video Editor.lnk
2016-09-06 19:47 - 2016-09-06 19:47 - 00000000 ____D C:\Program Files\DVDVideoSoft
2016-09-06 19:47 - 2016-09-06 19:47 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft
2016-09-06 19:47 - 2016-09-06 19:47 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\DVDVideoSoft
2016-09-06 19:37 - 2016-09-07 20:12 - 00000000 ___RD C:\Program Files\Skype
2016-09-06 19:37 - 2016-09-07 20:12 - 00000000 ____D C:\Documents and Settings\Valio\Local Settings\Application Data\Skype
2016-09-06 19:28 - 2016-09-06 19:36 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\ProductData
2016-09-06 19:28 - 2016-09-06 19:28 - 00000000 ____D C:\WINDOWS\IObit
2016-09-06 19:27 - 2016-09-06 19:27 - 00023840 _____ (REALiX(tm)) C:\WINDOWS\system32\Drivers\HWiNFO32.SYS
2016-09-06 19:27 - 2016-09-06 19:27 - 00000000 ____D C:\Documents and Settings\Valio\Application Data\IObit
2016-09-06 19:27 - 2016-09-06 19:27 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\IObit
2016-09-06 19:08 - 2016-09-06 19:08 - 00007385 _____ C:\Documents and Settings\Valio\Local Settings\Temp6.html
2016-09-06 19:08 - 2016-09-06 19:08 - 00000000 __SHD C:\Documents and Settings\Valio\PrivacIE
2016-09-06 18:54 - 2016-09-06 18:52 - 00068000 ____H C:\WINDOWS\Minidump\Mini090616-01.dmp
2016-09-06 18:53 - 2016-09-07 00:32 - 00001324 _____ C:\WINDOWS\system32\d3d9caps.dat
2016-09-06 18:51 - 2016-09-06 18:51 - 00000000 ____D C:\Documents and Settings\Val\Desktop\Femanic
2016-09-06 18:35 - 2016-09-06 18:35 - 00000000 ____D C:\Program Files\WhoCrashed
2016-09-06 18:35 - 2016-09-06 18:35 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\WhoCrashed
2016-09-06 18:31 - 2001-08-17 12:12 - 00117760 ____C (Intel Corporation) C:\WINDOWS\system32\dllcache\e100b325.sys
2016-09-06 18:31 - 2001-08-17 12:12 - 00117760 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\e100b325.sys
2016-09-06 16:47 - 2016-09-06 16:47 - 00000000 __SHD C:\Documents and Settings\Valio\IETldCache
2016-09-06 16:47 - 2016-09-06 16:47 - 00000000 __SHD C:\Documents and Settings\LocalService\IETldCache
2016-09-06 16:22 - 2016-09-06 16:45 - 00065536 _____ C:\WINDOWS\system32\config\Internet.evt
2016-09-06 16:22 - 2009-01-07 18:20 - 00016928 ____N (Microsoft Corporation) C:\WINDOWS\system32\spmsg.dll
2016-09-06 16:22 - 2008-11-07 18:55 - 00026144 _____ (Microsoft Corporation) C:\WINDOWS\system32\spupdsvc.exe
2016-09-06 16:21 - 2016-09-07 00:25 - 00000000 __HDC C:\WINDOWS\ie8
2016-09-06 14:51 - 2016-09-06 14:51 - 00000000 ____D C:\Program Files\BinarySense
2016-09-06 14:51 - 2016-09-06 14:51 - 00000000 ____D C:\Documents and Settings\Valio\Application Data\BinarySense
2016-09-06 14:51 - 2016-09-06 14:51 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\HDDlife
2016-09-06 14:43 - 2016-09-06 23:36 - 00000000 ____D C:\Documents and Settings\Val
2016-09-06 14:43 - 2016-09-06 14:43 - 00000000 ____D C:\Documents and Settings\Val\Local Settings\Application Data\Opera
2016-09-06 14:42 - 2016-09-06 14:42 - 00001498 _____ C:\Documents and Settings\All Users\Start Menu\Programs\Opera.lnk
2016-09-06 14:42 - 2016-09-06 14:42 - 00000000 ____D C:\Program Files\Opera
2016-09-06 14:41 - 2016-09-06 14:43 - 00000000 ____D C:\Documents and Settings\Valio\Application Data\Opera
2016-09-06 14:41 - 2016-09-06 14:41 - 00000000 ____D C:\Documents and Settings\Valio\Local Settings\Application Data\Opera
2016-09-06 13:53 - 2016-09-06 13:53 - 00000000 ____D C:\Program Files\Foxit Software
2016-09-06 13:53 - 2016-09-06 13:53 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Foxit Reader
2016-09-06 13:47 - 2016-09-06 16:49 - 00000000 ____D C:\Documents and Settings\Valio\Application Data\ViberPC
2016-09-06 13:46 - 2016-09-06 13:46 - 00000875 _____ C:\Documents and Settings\Valio\Start Menu\Viber.lnk
2016-09-06 13:46 - 2016-09-06 13:46 - 00000000 ____D C:\Documents and Settings\Valio\Start Menu\Programs\Viber
2016-09-06 13:45 - 2016-09-06 13:46 - 00000000 ____D C:\Documents and Settings\Valio\Local Settings\Application Data\Viber
2016-09-06 13:45 - 2016-09-06 13:45 - 00000000 ____D C:\Documents and Settings\Valio\Local Settings\Application Data\Package Cache
2016-09-06 13:32 - 2016-09-06 13:33 - 00000000 ____D C:\Program Files\RevConnect
2016-09-06 13:25 - 2016-09-08 20:01 - 00000000 ____D C:\Documents and Settings\Valio\Application Data\uTorrent
2016-09-06 13:19 - 2016-09-06 20:38 - 00001667 _____ C:\Documents and Settings\Valio\Local Settings\Temp1.html
2016-09-06 13:18 - 2016-09-06 13:18 - 00000000 ____D C:\Program Files\PIXresizer
2016-09-06 13:18 - 2016-09-06 13:18 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\PIXresizer
2016-09-06 13:18 - 2007-04-15 01:05 - 00991232 _____ (Viscom Software ) C:\WINDOWS\system32\imageviewer2.ocx
2016-09-06 13:18 - 2004-03-09 00:00 - 00224016 _____ (Microsoft Corporation) C:\WINDOWS\system32\tabctl32.ocx
2016-09-06 13:18 - 2002-08-29 20:00 - 01703936 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdiplus.dll
2016-09-06 13:18 - 2000-07-09 19:15 - 00106496 _____ (Marco Bellinaso) C:\WINDOWS\system32\mbprgbar.ocx
2016-09-06 13:18 - 2000-05-22 01:00 - 00608448 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.ocx
2016-09-06 13:18 - 2000-05-02 00:02 - 00110592 _____ (Common Controls Replacement Project (CCRP)) C:\WINDOWS\system32\ccrpbds6.dll
2016-09-06 13:18 - 1999-09-16 10:04 - 00151552 _____ (Domenico Statuto - CCRP) C:\WINDOWS\system32\ccrpfd6.ocx
2016-09-06 13:18 - 1998-06-24 01:00 - 00164144 _____ (Microsoft Corporation) C:\WINDOWS\system32\comct232.ocx
2016-09-06 13:18 - 1996-01-12 01:00 - 00200704 _____ (Sheridan Software Systems, Inc.) C:\WINDOWS\system32\threed32.ocx
2016-09-06 13:15 - 2016-09-06 23:28 - 00065536 _____ C:\WINDOWS\system32\config\Nano.evt
2016-09-06 11:46 - 2016-09-06 12:30 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\wetandpissy
2016-09-06 11:46 - 2016-09-06 11:49 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\old
2016-09-06 11:46 - 2016-09-06 11:46 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\Нова папка
2016-09-06 11:42 - 2016-09-06 20:58 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\WinSetupFromUSB-1-7
2016-09-06 11:40 - 2016-09-06 11:41 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\turk
2016-09-06 11:40 - 2016-09-06 11:40 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\TeamViewerPortable
2016-09-06 11:39 - 2016-09-06 11:40 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\simbian
2016-09-06 11:29 - 2016-09-06 18:46 - 00000000 ____D C:\Program Files\Hard Disk Sentinel
2016-09-06 11:29 - 2016-09-06 11:29 - 00000690 _____ C:\Documents and Settings\Valio\Desktop\Hard Disk Sentinel.lnk
2016-09-06 11:29 - 2016-09-06 11:29 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Hard Disk Sentinel
2016-09-06 11:25 - 2016-09-06 11:28 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\Sophia E
2016-09-06 11:22 - 2016-09-06 11:22 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\sharewareonsale_giveaway_hdsentinel_setup
2016-09-06 11:20 - 2016-09-06 11:20 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\NOVI
2016-09-06 11:20 - 2016-09-06 11:20 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\muziki
2016-09-06 11:15 - 2016-09-06 11:17 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\MPLMay
2016-09-06 11:12 - 2016-09-06 11:14 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\MPLFevral
2016-09-06 11:09 - 2016-09-06 11:12 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\MPLAvgust
2016-09-06 11:07 - 2016-09-06 11:07 - 00000000 ____D C:\Program Files\BitComet
2016-09-06 11:07 - 2016-02-06 23:29 - 00069824 _____ C:\Documents and Settings\Valio\My Documents\Антивирусни програми   Софтуер.htm
2016-09-06 11:07 - 2016-01-13 19:29 - 00220776 _____ C:\Documents and Settings\Valio\My Documents\arhiv abonati v skaip valio_andonov.vcf
2016-09-06 11:07 - 2016-01-04 19:00 - 00001022 _____ C:\Documents and Settings\Valio\My Documents\indexfile.txt
2016-09-06 11:07 - 2015-12-16 20:51 - 00144594 _____ C:\Documents and Settings\Valio\My Documents\otmetki ot opera .adr
2016-09-06 11:07 - 2011-01-01 15:29 - 03022787 _____ C:\Documents and Settings\Valio\My Documents\ASYA12LGC%20-%20AOYR12LGC%20-%20Technical.pdf
2016-09-06 11:07 - 2010-09-06 16:31 - 01034741 _____ C:\Documents and Settings\Valio\My Documents\whirlpool.pdf
2016-09-06 11:07 - 2010-05-15 19:52 - 00069167 _____ C:\Documents and Settings\Valio\My Documents\bookmarks.html
2016-09-06 11:07 - 2010-03-06 16:52 - 44193796 _____ C:\Documents and Settings\Valio\My Documents\Todor Jivkov.mpeg
2016-09-06 11:07 - 2009-12-27 20:13 - 00444098 _____ C:\Documents and Settings\Valio\My Documents\staq.sh3d
2016-09-06 11:07 - 2009-03-29 20:25 - 01036150 _____ C:\Documents and Settings\Valio\My Documents\AquariumV11.rar
2016-09-06 11:05 - 2016-09-06 11:05 - 00000000 ____D C:\Documents and Settings\Valio\My Documents\Изтегляния
2016-09-06 11:05 - 2016-09-06 11:05 - 00000000 ____D C:\Documents and Settings\Valio\My Documents\ViberDownloads
2016-09-06 11:04 - 2016-09-06 11:04 - 00000000 ___RD C:\Documents and Settings\Valio\My Documents\Shareaza Downloads
2016-09-06 11:04 - 2016-09-06 11:04 - 00000000 ____D C:\Documents and Settings\Valio\My Documents\sdc222
2016-09-06 11:04 - 2016-09-06 11:04 - 00000000 ____D C:\Documents and Settings\Valio\My Documents\MusicFrost
2016-09-06 11:04 - 2016-09-06 11:04 - 00000000 ____D C:\Documents and Settings\Valio\My Documents\ICQ Lite
2016-09-06 11:04 - 2016-09-06 11:04 - 00000000 ____D C:\Documents and Settings\Valio\My Documents\gegl-0.0
2016-09-06 11:04 - 2016-09-06 11:04 - 00000000 ____D C:\Documents and Settings\Valio\My Documents\FFOutput
2016-09-06 11:03 - 2016-09-06 13:26 - 00000000 ___RD C:\Documents and Settings\Valio\Desktop\Program Files
2016-09-06 11:03 - 2016-09-06 11:04 - 00000000 ___RD C:\Documents and Settings\Valio\My Documents\Dropbox
2016-09-06 11:03 - 2016-09-06 11:03 - 00000000 ____D C:\Documents and Settings\Valio\My Documents\Bluetooth Exchange Folder
2016-09-06 11:03 - 2016-09-06 11:03 - 00000000 ____D C:\Documents and Settings\Valio\My Documents\AquariumV11
2016-09-06 11:03 - 2016-09-06 11:03 - 00000000 ____D C:\Documents and Settings\Valio\My Documents\alia
2016-09-06 11:01 - 2016-09-06 11:01 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\MPL - 2011-07 Video
2016-09-06 10:55 - 2016-09-06 11:00 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\MET-ART  11 - 20 June  2015
2016-09-06 10:55 - 2016-09-06 10:55 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\lv6tboxhda2 notonly на vali преминават на стендбай - Страница 16 - Digital TV Forums - БЪЛГАРСКИЯТ ФОРУМ ЗА ЦИФРОВА ТЕЛЕВИЗИЯ_files
2016-09-06 10:53 - 2016-09-06 10:55 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\Lena pics
2016-09-06 10:53 - 2016-09-06 10:53 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\king
2016-09-06 10:53 - 2016-09-06 10:53 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\ireland
2016-09-06 10:52 - 2016-09-06 10:52 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\delux mouse
2016-09-06 10:52 - 2016-09-06 10:52 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\DCIM
2016-09-06 10:52 - 2016-09-06 10:52 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\Barbara_Pease_-_Zashto_myzhete_ne_ch1.txt
2016-09-06 10:50 - 2016-09-06 10:51 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\antivirus
2016-09-06 10:50 - 2016-09-06 10:50 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\2015
2016-09-06 10:50 - 2016-09-06 10:50 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\2014
2016-09-06 10:50 - 2016-09-06 10:50 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\2013
2016-09-06 10:50 - 2016-09-06 10:50 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\2012
2016-09-06 10:50 - 2016-09-06 10:50 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\2011
2016-09-06 10:47 - 2015-08-11 12:22 - 02895360 _____ C:\WINDOWS\system32\pwNative.exe
2016-09-06 10:47 - 2015-03-05 10:15 - 00017160 ____N C:\WINDOWS\system32\pwdrvio.sys
2016-09-06 10:47 - 2015-03-05 10:15 - 00013064 ____N C:\WINDOWS\system32\pwdspio.sys
2016-09-06 10:46 - 2016-09-06 10:47 - 00000000 ____D C:\Program Files\MiniTool Partition Wizard Free 9.1
2016-09-06 10:46 - 2016-09-06 10:46 - 00000854 _____ C:\Documents and Settings\All Users\Desktop\MiniTool Partition Wizard Free.lnk
2016-09-06 10:46 - 2016-09-06 10:46 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\MiniTool Partition Wizard Free 9.1
2016-09-06 09:55 - 2016-09-06 09:55 - 00373248 _____ (Acronis) C:\WINDOWS\system32\autoprnt.exe
2016-09-06 09:55 - 2016-09-06 09:55 - 00102400 _____ (Acronis) C:\WINDOWS\system32\snapapi.dll
2016-09-06 09:55 - 2016-09-06 09:55 - 00065856 _____ (Acronis) C:\WINDOWS\system32\Drivers\snapman.sys
2016-09-06 09:55 - 2016-09-06 09:55 - 00037888 _____ C:\WINDOWS\system32\setupnt.dll
2016-09-06 09:55 - 2016-09-06 09:55 - 00000936 _____ C:\Documents and Settings\Valio\Desktop\Acronis MigrateEasy.lnk
2016-09-06 09:55 - 2016-09-06 09:55 - 00000000 ____D C:\Program Files\Common Files\Acronis
2016-09-06 09:55 - 2016-09-06 09:55 - 00000000 ____D C:\Program Files\Acronis
2016-09-06 09:55 - 2016-09-06 09:55 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Acronis
2016-09-05 23:52 - 2016-09-05 23:53 - 41700480 _____ (Skype Technologies S.A.) C:\Documents and Settings\Valio\Desktop\SkypeSetupFullXp.exe
2016-09-05 20:50 - 2016-09-06 13:46 - 00000875 _____ C:\Documents and Settings\Valio\Desktop\Viber.lnk
2016-09-05 19:51 - 2016-09-05 19:51 - 00937080 _____ (Akeo Consulting (hxxp://akeo.ie)) C:\Documents and Settings\Valio\Desktop\rufus-2.10p.exe
2016-09-04 22:28 - 2012-03-17 19:07 - 259157272 _____ C:\Documents and Settings\Valio\Desktop\3123v_hi.avi
2016-09-04 20:19 - 2016-02-10 20:51 - 19057568 _____ (Microsoft) C:\Documents and Settings\Valio\Desktop\NokiaSoftwareRecoveryToolInstaller.exe
2016-09-02 22:39 - 2016-09-02 22:39 - 01038335 _____ C:\Documents and Settings\Valio\Desktop\[Guru3D.com]-DDU.zip
2016-09-02 21:42 - 2016-09-06 13:17 - 00000656 _____ C:\Documents and Settings\Valio\Desktop\Пряк път до Ultra Video Joiner.exe.lnk
2016-09-02 21:41 - 2016-09-02 21:41 - 00000706 _____ C:\Documents and Settings\Valio\Desktop\Пряк път до DCPlusPlus.exe.lnk
2016-09-02 21:36 - 2016-09-06 13:18 - 00000706 _____ C:\Documents and Settings\Valio\Desktop\PIXresizer.lnk
2016-09-02 21:30 - 2016-09-06 13:33 - 00000682 _____ C:\Documents and Settings\Valio\Desktop\Пряк път до BitComet.exe.lnk
2016-09-02 21:25 - 2016-09-02 21:25 - 03826240 _____ C:\Documents and Settings\Valio\Desktop\adwcleaner_6.010.exe
2016-09-02 21:01 - 2016-09-02 21:02 - 36580047 _____ (KLCP ) C:\Documents and Settings\Valio\Desktop\K-Lite_Codec_Pack_1235_Full.exe
2016-09-01 18:13 - 2016-08-27 21:44 - 06543984 _____ (IObit ) C:\Documents and Settings\Valio\Desktop\AWCSetup_Major.exe
2016-09-01 18:13 - 2016-03-05 18:57 - 31095938 _____ C:\Documents and Settings\Valio\Desktop\bg-science86.pdf
2016-09-01 18:13 - 2016-01-14 21:26 - 30984401 _____ C:\Documents and Settings\Valio\Desktop\bg-science84.pdf
2016-09-01 18:13 - 2015-12-18 21:59 - 19819451 ____R C:\Documents and Settings\Valio\Desktop\2015-12-18 Valio 2690.nbu
2016-09-01 18:13 - 2015-01-23 10:38 - 156129250 _____ C:\Documents and Settings\Valio\Desktop\95a14b0fd6153328c12fe1072b3f3be0.flv
2016-09-01 18:13 - 2010-04-17 14:28 - 56804132 _____ C:\Documents and Settings\Valio\Desktop\2DB06C3-48942980.avi
2016-09-01 18:13 - 2010-03-03 19:08 - 00921011 _____ C:\Documents and Settings\Valio\Desktop\ConnectifyInstaller.exe
2016-09-01 18:12 - 2016-09-06 13:17 - 00000620 _____ C:\Documents and Settings\Valio\Desktop\Sweet Home 3D.lnk
2016-09-01 18:12 - 2016-09-04 19:47 - 00000734 _____ C:\Documents and Settings\Valio\Desktop\Start Tor Browser.lnk
2016-09-01 18:12 - 2016-09-04 18:27 - 00000697 _____ C:\Documents and Settings\Valio\Desktop\StrongDC.lnk
2016-09-01 18:12 - 2016-08-26 21:21 - 02342176 _____ (Panda Security, S.L.) C:\Documents and Settings\Valio\Desktop\PANDAFREEAV.exe
2016-09-01 18:12 - 2016-03-25 22:22 - 00088238 _____ C:\Documents and Settings\Valio\Desktop\lv6tboxhda2 notonly на vali преминават на стендбай - Страница 16 - Digital TV Forums - БЪЛГАРСКИЯТ ФОРУМ ЗА ЦИФРОВА ТЕЛЕВИЗИЯ.htm
2016-09-01 18:12 - 2016-03-25 21:35 - 02603732 _____ C:\Documents and Settings\Valio\Desktop\J1300660_MC6379_LV6TBOXHDA2_V1.0.9_20131120-.rar
2016-09-01 18:12 - 2016-03-07 18:49 - 09553766 _____ C:\Documents and Settings\Valio\Desktop\rsload.net.HL.P.4.1.203.zip
2016-09-01 18:12 - 2016-03-04 22:55 - 01094289 _____ C:\Documents and Settings\Valio\Desktop\Psiloc_ir_remote_update_database_1.04-worked.rar
2016-09-01 18:12 - 2016-02-26 22:22 - 00000062 _____ C:\Documents and Settings\Valio\Desktop\listen.pls
2016-09-01 18:12 - 2016-01-09 15:19 - 02500096 _____ (rejetto) C:\Documents and Settings\Valio\Desktop\hfs.exe
2016-09-01 18:12 - 2015-11-05 19:46 - 00101811 _____ C:\Documents and Settings\Valio\Desktop\results-2015-11-04.pdf
2016-09-01 18:12 - 2015-09-25 22:33 - 13935966 _____ (Favorite-Games 2001-2013 © ) C:\Documents and Settings\Valio\Desktop\favorite-games_bg.exe
2016-09-01 18:12 - 2015-09-21 15:58 - 06930432 _____ C:\Documents and Settings\Valio\Desktop\SkypeWebPlugin.msi
2016-09-01 18:12 - 2015-09-04 23:46 - 24178176 _____ (SAMSUNG Electronics Co., Ltd.) C:\Documents and Settings\Valio\Desktop\samsung_android_usb_driver.exe
2016-09-01 18:12 - 2015-06-26 21:25 - 07332272 _____ C:\Documents and Settings\Valio\Desktop\MyPhoneExplorer_Setup_v1.8.6.exe
2016-09-01 18:12 - 2014-08-20 22:07 - 19531504 _____ (SAMSUNG Electronics Co., Ltd.) C:\Documents and Settings\Valio\Desktop\SAMSUNG_USB_Driver_for_Mobile_Phones.exe
2016-09-01 18:12 - 2014-08-20 08:51 - 21633320 _____ (Skype Technologies S.A.) C:\Documents and Settings\Valio\Desktop\Sky38i.exe
2016-09-01 18:12 - 2014-04-30 09:31 - 01954304 _____ (Topala Software Solutions) C:\Documents and Settings\Valio\Desktop\siw.exe
2016-09-01 18:12 - 2012-03-19 15:46 - 67735119 ____H (PortableAppZ.blogspot.com) C:\Documents and Settings\Valio\Desktop\Photoshop_Portable_12.0_en-fr-de-es-it-ru-zh-tw.paf.exe
2016-09-01 18:12 - 2010-08-15 14:16 - 02769333 _____ C:\Documents and Settings\Valio\Desktop\thebible.pdf
2016-09-01 18:12 - 2010-06-06 18:03 - 00320849 _____ C:\Documents and Settings\Valio\Desktop\standart_psihiatriq.pdf
2016-09-01 18:12 - 2010-03-05 12:07 - 00904704 _____ (KaKasoft) C:\Documents and Settings\Valio\Desktop\lockdir.exe
2016-09-01 18:12 - 2007-07-22 16:39 - 00032768 _____ (KenamicK Entertainment) C:\Documents and Settings\Valio\Desktop\opencd.exe
2016-09-01 18:12 - 2005-09-11 22:57 - 00331776 _____ () C:\Documents and Settings\Valio\Desktop\ShutdownTimer.exe
2016-09-01 18:11 - 2016-09-04 19:10 - 00000936 _____ C:\Documents and Settings\Valio\Desktop\Пряк път до GIMPPortable.exe.lnk
2016-09-01 18:11 - 2016-09-04 18:28 - 00000914 _____ C:\Documents and Settings\Valio\Desktop\Пряк път до FSViewer.exe.lnk
2016-09-01 18:11 - 2016-09-04 18:28 - 00000675 _____ C:\Documents and Settings\Valio\Desktop\Пряк път до Diction.exe.lnk
2016-09-01 18:11 - 2016-09-04 18:27 - 00000664 _____ C:\Documents and Settings\Valio\Desktop\Пряк път до WNetWatcher.exe.lnk
2016-09-01 18:11 - 2016-03-04 12:03 - 32047935 _____ C:\Documents and Settings\Valio\Desktop\Мега окончание.mp4
2016-09-01 18:11 - 2015-11-29 15:18 - 00000036 _____ C:\Documents and Settings\Valio\Desktop\Нов Текстов документ (3).txt
2016-09-01 18:11 - 2011-03-27 13:27 - 00000146 _____ C:\Documents and Settings\Valio\Desktop\Нов Текстов документ (2).txt
2016-09-01 18:11 - 2010-01-31 18:30 - 00000019 _____ C:\Documents and Settings\Valio\Desktop\Нов Текстов документ (4).bat
2016-09-01 18:11 - 2008-12-21 18:09 - 00146378 _____ C:\Documents and Settings\Valio\Desktop\Нов Текстов документ.txt
2016-08-31 21:15 - 2016-09-06 18:35 - 00000706 _____ C:\Documents and Settings\Valio\Desktop\WhoCrashed.lnk
2016-08-10 20:14 - 2016-08-10 20:14 - 00000000 ____D C:\Program Files\Samsung
2016-08-10 20:14 - 2016-08-10 20:14 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Samsung
2016-08-10 20:12 - 2016-08-10 20:12 - 00000000 ____D C:\Documents and Settings\Valio\Desktop\TL-WN721N_V1_140915
2016-08-10 20:12 - 2013-06-29 06:49 - 01763584 _____ (Atheros Communications, Inc.) C:\WINDOWS\system32\Drivers\athuw.sys

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-09-08 20:59 - 2010-11-07 20:23 - 00000000 ____D C:\Documents and Settings\Valio\Local Settings\Temp
2016-09-08 20:56 - 2011-01-30 20:58 - 00000000 ____D C:\Documents and Settings\Valio\Application Data\Skype
2016-09-08 19:50 - 2010-11-07 22:09 - 00513746 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-09-08 19:48 - 2008-04-14 15:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2016-09-08 19:45 - 2010-11-07 20:22 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-09-07 22:37 - 2010-11-07 21:02 - 00393216 _____ C:\WINDOWS\system32\config\ACEEvent.evt
2016-09-07 22:37 - 2010-11-07 20:23 - 00000178 ___SH C:\Documents and Settings\Valio\ntuser.ini
2016-09-07 22:37 - 2010-11-07 20:22 - 00032556 _____ C:\WINDOWS\SchedLgU.Txt
2016-09-07 21:41 - 2010-11-07 22:07 - 00000211 ___SH C:\boot.ini
2016-09-07 21:41 - 2008-04-14 15:00 - 00000747 _____ C:\WINDOWS\win.ini
2016-09-07 21:41 - 2008-04-14 15:00 - 00000227 _____ C:\WINDOWS\system.ini
2016-09-07 21:08 - 2010-11-07 20:23 - 00000000 ____D C:\Documents and Settings\Valio
2016-09-07 20:13 - 2011-01-30 20:57 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Skype
2016-09-07 20:04 - 2016-03-20 22:30 - 00170200 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-09-07 20:03 - 2010-11-07 22:01 - 00000000 ___HD C:\WINDOWS\inf
2016-09-07 19:34 - 2010-11-07 20:32 - 00000000 ____D C:\WINDOWS\system32\ReinstallBackups
2016-09-07 19:13 - 2014-04-14 23:06 - 00544620 _____ C:\WINDOWS\ntbtlog.txt
2016-09-07 01:03 - 2010-11-07 22:01 - 00000000 RSHDC C:\WINDOWS\system32\dllcache
2016-09-06 23:41 - 2010-11-07 22:08 - 00000000 ____D C:\Documents and Settings\All Users
2016-09-06 23:30 - 2010-11-07 20:54 - 00012328 _____ C:\Documents and Settings\Valio\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2016-09-06 23:29 - 2016-03-08 20:49 - 00000000 ____D C:\Program Files\Panda Security
2016-09-06 23:29 - 2015-12-02 20:37 - 01037824 _____ (Microsoft Corporation) C:\WINDOWS\system32\svсhоst.exe
2016-09-06 23:29 - 2014-04-14 22:54 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Panda Security
2016-09-06 23:29 - 2010-11-07 22:08 - 00090296 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-09-06 23:26 - 2014-04-14 22:56 - 00000000 ____D C:\Documents and Settings\Valio\Application Data\Panda Security
2016-09-06 20:58 - 2014-08-13 17:05 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy
2016-09-06 20:36 - 2013-06-29 21:20 - 00796352 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2016-09-06 20:36 - 2013-06-29 21:20 - 00142528 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2016-09-06 20:21 - 2013-07-14 13:08 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2016-09-06 19:21 - 2011-01-30 21:00 - 00000000 ____D C:\Program Files\Mozilla Firefox
2016-09-06 18:54 - 2002-01-01 01:12 - 00000000 ____D C:\WINDOWS\Minidump
2016-09-06 16:47 - 2010-11-07 20:23 - 00000803 _____ C:\Documents and Settings\Valio\Start Menu\Programs\Internet Explorer.lnk
2016-09-06 16:47 - 2010-11-07 20:23 - 00000000 ___RD C:\Documents and Settings\Valio\My Documents\My Pictures
2016-09-06 16:47 - 2010-11-07 20:23 - 00000000 ___RD C:\Documents and Settings\Valio\My Documents\My Music
2016-09-06 16:47 - 2010-11-07 20:23 - 00000000 ___RD C:\Documents and Settings\Valio\My Documents
2016-09-06 16:47 - 2010-11-07 20:22 - 00000000 __SHD C:\Documents and Settings\LocalService
2016-09-06 16:46 - 2010-11-07 22:01 - 00000000 ____D C:\WINDOWS\Help
2016-09-06 16:22 - 2010-11-07 22:09 - 00001355 _____ C:\WINDOWS\imsins.BAK
2016-09-06 16:22 - 2010-11-07 22:01 - 00000000 ____D C:\WINDOWS\Media
2016-09-06 14:43 - 2010-11-07 22:08 - 00000000 ____D C:\Documents and Settings
2016-09-06 14:38 - 2016-03-20 22:29 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2016-09-06 14:38 - 2016-03-20 22:29 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
2016-09-06 14:38 - 2016-03-20 22:24 - 00000777 _____ C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2016-08-28 18:36 - 2010-11-07 20:16 - 00000000 ____D C:\WINDOWS\system32\Macromed
2016-08-10 20:06 - 2010-11-07 20:21 - 00000000 __SHD C:\Documents and Settings\NetworkService
2016-08-10 20:06 - 2010-11-07 20:15 - 00000000 ____D C:\WINDOWS\Registration

==================== Files in the root of some directories =======

2016-03-06 19:04 - 2016-03-06 19:04 - 0000000 _____ () C:\Documents and Settings\All Users\Application Data\0x0304A000.sfl

Some files in TEMP:
====================
C:\Documents and Settings\Valio\Local Settings\Temp\SkypeSetup.exe
C:\Documents and Settings\Valio\Local Settings\Temp\Skype_7.0.0.102.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

==================== End of FRST.txt ============================

Addition.txt

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.