Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Заразена съм от някакъв крипто вирус

Featured Replies

Здравейте, заразена съм от някакъв крипто вирус/криптирани са всички doc, xls и др. файлове/ окончанието е .crypt

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 30-10-2016
Ran by admin (administrator) on ADMIN-TOSH (02-11-2016 20:26:20)
Running from C:\Users\admin\Desktop
Loaded Profiles: admin (Available Profiles: admin)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

() D:\Program Files\Bluesoleil\BlueSoleilCS.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(TOSHIBA CORPORATION.) C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\TosBtMng.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Hewlett-Packard Company) C:\Program Files (x86)\HP\StatusAlerts\bin\HPStatusAlerts.exe
(C-Dilla Ltd) C:\Windows\SysWOW64\drivers\CDAC11BA.EXE
(HP) C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
() D:\Program Files\Bluesoleil\BsHelpCS.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe
(TOSHIBA CORPORATION.) C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\TosA2dp.exe
(TOSHIBA CORPORATION.) C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\TosBtHid.exe
(TOSHIBA CORPORATION.) C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\TosBtHSP.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(QIHU 360 SOFTWARE CO. LIMITED) C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe
(QIHU 360 SOFTWARE CO. LIMITED) C:\Program Files (x86)\360\Total Security\safemon\QHWatchdog.exe
(QIHU 360 SOFTWARE CO. LIMITED) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
(www.BitComet.com) D:\Program Files\BitComet\BitComet.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Desktop.exe
() D:\Program Files\Bluesoleil\BtTray.exe


==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [TPwrMain] => C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [505696 2009-11-05] (TOSHIBA Corporation)
HKLM\...\Run: [HSON] => C:\Program Files\TOSHIBA\TBS\HSON.exe [52600 2009-03-09] (TOSHIBA Corporation)
HKLM\...\Run: [SmoothView] => C:\Program Files\Toshiba\SmoothView\SmoothView.exe [570680 2009-08-13] (TOSHIBA Corporation)
HKLM\...\Run: [00TCrdMain] => C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [910136 2009-11-10] (TOSHIBA Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1870120 2009-10-15] (Synaptics Incorporated)
HKLM\...\Run: [Windows Mobile Device Center] => C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM-x32\...\Run: [QHSafeTray] => C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe [1894824 2016-10-24] (QIHU 360 SOFTWARE CO. LIMITED)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [StatusAlerts] => C:\Program Files (x86)\HP\StatusAlerts\bin\HPStatusAlerts.exe [330176 2014-08-19] (Hewlett-Packard Company)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-4281457091-153058287-3019275391-1000\...\Policies\Explorer: [] 
HKU\S-1-5-21-4281457091-153058287-3019275391-1000\...\MountPoints2: F - F:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-4281457091-153058287-3019275391-1000\...\MountPoints2: {19a59e67-f95c-11df-beeb-705ab6ba6057} - F:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-4281457091-153058287-3019275391-1000\...\MountPoints2: {19a59e73-f95c-11df-beeb-705ab6ba6057} - F:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-4281457091-153058287-3019275391-1000\...\MountPoints2: {743a9f53-be54-11e3-a04a-705ab6ba6057} - F:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-4281457091-153058287-3019275391-1000\...\MountPoints2: {76f0a63e-16d0-11e2-b87a-bfbab139c4b5} - F:\autorun.exe
HKU\S-1-5-21-4281457091-153058287-3019275391-1000\...\MountPoints2: {fc0e2634-c550-11e3-b1df-705ab6ba6057} - F:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-4281457091-153058287-3019275391-1000\...\MountPoints2: {fc0e2642-c550-11e3-b1df-705ab6ba6057} - F:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-4281457091-153058287-3019275391-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\WLXPGSS.scr [301936 2010-09-23] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll [2013-02-08] (Autodesk, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth Manager.lnk [2010-11-29]
ShortcutTarget: Bluetooth Manager.lnk -> C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)
GroupPolicyScripts-x32: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{089D1799-5564-4EA4-A037-13CC0D961FA2}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{1A25A7A3-DCE3-4F94-9C1D-539DC66EB7F1}: [DhcpNameServer] 10.250.238.3 10.250.238.4
Tcpip\..\Interfaces\{826507D6-DCEC-4AD0-AB95-1B80A594389B}: [DhcpNameServer] 100.100.0.102
Tcpip\..\Interfaces\{A4DB0CC2-38AE-4A65-9D15-CADFD509263D}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-4281457091-153058287-3019275391-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.bg/
HKU\S-1-5-21-4281457091-153058287-3019275391-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSEH&bmod=TSEH
HKU\S-1-5-21-4281457091-153058287-3019275391-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
SearchScopes: HKLM -> DefaultScope value is missing
SearchScopes: HKLM-x32 -> DefaultScope value is missing
SearchScopes: HKLM-x32 -> {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=HJxdm007YYbg&ptnrS=HJxdm007YYbg&si=CIGDo93RqLECFUZd3wodDTYAsg&ptb=E72BEF5D-ACD8-4338-B5C9-3C7311452B44&ind=2012072012&n=77edc84c&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKU\S-1-5-21-4281457091-153058287-3019275391-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = 
SearchScopes: HKU\S-1-5-21-4281457091-153058287-3019275391-1000 -> {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = 
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: SafeMon Class -> {B69F34DD-F0F9-42DC-9EDD-957187DA688D} -> C:\Program Files (x86)\360\Total Security\safemon\safemon64.dll [2016-10-24] (Qihu 360 Software Co., Ltd.)
BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2013-10-08] (Adblock Plus)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27] (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-03-24] (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-09-23] (Microsoft Corporation)
BHO-x32: SafeMon Class -> {B69F34DD-F0F9-42DC-9EDD-957187DA688D} -> C:\Program Files (x86)\360\Total Security\safemon\safemon.dll [2016-10-24] (Qihu 360 Software Co., Ltd.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-03-24] (Oracle Corporation)
BHO-x32: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2013-10-08] (Adblock Plus)
Toolbar: HKU\S-1-5-21-4281457091-153058287-3019275391-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
DPF: HKLM-x32 {02BCC737-B171-4746-94C9-0D8A0B2C0089} hxxp://office.microsoft.com/_layouts/ClientBin/ieawsdc32.cab
DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: HKLM-x32 {A996E48C-D3DC-4244-89F7-AFA33EC60679} hxxps://ebb.ubb.bg/CAPICOM/capicom.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)

FireFox:
========
FF ProfilePath: C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\jkq1rx38.default [2016-11-02]
FF Homepage: Mozilla\Firefox\Profiles\jkq1rx38.default -> hxxp://google.atcomet.com/m/
FF Extension: (Firefox Hotfix) - C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\jkq1rx38.default\Extensions\[email protected] [2016-09-16]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\360\Total Security\safemon\webprotection_firefox
FF Extension: (360 Internet Protection) - C:\Program Files (x86)\360\Total Security\safemon\webprotection_firefox [2016-06-27]
FF HKLM-x32\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird => not found
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll [2014-03-24] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll [2014-03-24] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1219159.dll [2015-06-26] (Adobe Systems, Inc.)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> D:\Program Files\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-03-24] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-03-24] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-09-23] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2012-03-17] (VideoLAN)

Chrome: 
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Profile: C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default [2016-11-02]
CHR Extension: (Google Docs) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-10-05]
CHR Extension: (Google Drive) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-02]
CHR Extension: (YouTube) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-05]
CHR Extension: (uBlock Origin) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2016-11-02]
CHR Extension: (Google Search) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-11]
CHR Extension: (Google Docs Offline) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-07-24]
CHR Extension: (Ghostery) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2016-11-02]
CHR Extension: (Chrome Web Store Payments) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-07-24]
CHR Extension: (Gmail) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-10-05]
CHR Extension: (Chrome Media Router) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-11-02]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [12288 2012-12-13] (Autodesk, Inc.) [File not signed]
R2 BlueSoleilCS; D:\Program Files\Bluesoleil\BlueSoleilCS.exe [850432 2009-02-27] () [File not signed]
R3 BsHelpCS; D:\Program Files\Bluesoleil\BsHelpCS.exe [191488 2009-02-27] () [File not signed]
S2 BsMobileCS; D:\Program Files\Bluesoleil\BsMobileCS.exe [143467 2009-02-27] () [File not signed]
R2 C-DillaCdaC11BA; C:\Windows\SysWOW64\drivers\CDAC11BA.EXE [39936 2010-11-30] (C-Dilla Ltd) [File not signed]
R2 HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [176128 2014-06-24] (HP) [File not signed]
S3 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [29728 2016-08-15] (HP Inc.)
R3 LMS; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [262144 2009-09-30] (Intel Corporation) [File not signed]
R2 QHActiveDefense; C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe [926632 2016-10-24] (QIHU 360 SOFTWARE CO. LIMITED)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH)
R2 UNS; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2314240 2009-09-30] (Intel Corporation) [File not signed]
S4 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 360AntiHacker; C:\Windows\System32\Drivers\360AntiHacker64.sys [151784 2016-06-21] (360.cn)
R3 360AvFlt; C:\Windows\System32\DRIVERS\360AvFlt.sys [86248 2016-10-24] (360.cn)
R3 360AvFlt; C:\Windows\SysWOW64\DRIVERS\360AvFlt.sys [86248 2016-10-24] (360.cn)
R3 360Box64; C:\Windows\System32\DRIVERS\360Box64.sys [330472 2016-10-24] (360.cn)
R3 360Camera; C:\Windows\System32\Drivers\360Camera64.sys [40520 2015-04-10] (360.cn)
R1 360FsFlt; C:\Windows\System32\DRIVERS\360FsFlt.sys [391392 2016-09-15] (360.cn)
R1 BAPIDRV; C:\Windows\System32\DRIVERS\BAPIDRV64.sys [188864 2016-09-15] (360.cn)
U5 BlueletAudio; C:\Windows\System32\Drivers\BlueletAudio.sys [36360 2008-11-25] (IVT Corporation.)
R3 Btcsrusb; C:\Windows\System32\Drivers\btcusb.sys [47880 2009-01-03] (IVT Corporation.)
R0 BtHidBus; C:\Windows\System32\Drivers\BtHidBus.sys [24840 2009-01-07] (IVT Corporation.)
R3 btnetBUs; C:\Windows\System32\Drivers\btnetBus.sys [35848 2008-12-07] ()
S2 CdaC15BA; C:\Windows\SysWOW64\drivers\CDAC15BA.SYS [8864 2014-05-15] () [File not signed]
R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2015-03-23] (DT Soft Ltd)
S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R3 IvtBtBUs; C:\Windows\System32\Drivers\IvtBtBus.sys [31624 2008-07-02] (IVT Corporation.)
S3 jrdusbser; C:\Windows\System32\DRIVERS\jrdusbser.sys [119680 2009-11-17] (TCT International Mobile Ltd)
S3 RSUSBSTOR; C:\Windows\SysWOW64\Drivers\RtsUStor.sys [225280 2009-09-22] (Realtek Semiconductor Corp.)
R3 VComm; C:\Windows\System32\DRIVERS\VComm.sys [17032 2008-01-21] (IVT Corporation.)
R3 VcommMgr; C:\Windows\System32\Drivers\VcommMgr.sys [42888 2009-01-08] (IVT Corporation.)
U5 BlueletAudio; C:\Windows\SysWOW64\Drivers\BlueletAudio.sys [36360 2008-11-25] (IVT Corporation.)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-11-02 20:26 - 2016-11-02 20:26 - 00019289 _____ C:\Users\admin\Desktop\FRST.txt
2016-11-02 20:25 - 2016-11-02 20:26 - 00000000 ____D C:\FRST
2016-11-02 20:23 - 2016-11-02 20:23 - 02408960 _____ (Farbar) C:\Users\admin\Desktop\FRST64.exe
2016-11-02 20:08 - 2016-05-05 14:13 - 01551174 ____T C:\Users\admin\Desktop\de_crypt_readme.bmp
2016-11-02 18:47 - 2016-11-02 18:47 - 05122856 _____ C:\Windows\system32\FNTCACHE.DAT
2016-11-02 11:01 - 2016-11-02 11:01 - 00143600 _____ C:\Users\admin\AppData\Local\GDIPFONTCACHEV1.DAT
2016-11-01 20:15 - 2016-11-01 20:15 - 00069208 _____ C:\Users\admin\Desktop\800231016739040_20161028.pdf
2016-11-01 19:56 - 2016-11-01 19:57 - 00603533 _____ C:\Users\admin\Downloads\62_Botanica1.pdf
2016-11-01 17:58 - 2016-11-01 17:58 - 00000000 ____D C:\Users\admin\Desktop\бети м
2016-10-28 09:54 - 2016-10-28 09:54 - 00603072 _____ C:\Users\admin\Desktop\PROFORMA_METAL SISITEM EOOD_28.10.2016_.pdf
2016-10-04 05:56 - 2016-10-04 05:56 - 01317111 _____ C:\Users\admin\Downloads\att_11882.zip

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-11-02 20:24 - 2011-01-16 20:41 - 00006496 _____ C:\Windows\SysWOW64\LOCALSERVICE.INI
2016-11-02 20:24 - 2011-01-16 20:41 - 00000091 _____ C:\Windows\SysWOW64\LOCALDEVICE.INI
2016-11-02 20:24 - 2009-02-27 17:04 - 00001084 _____ C:\Windows\SysWOW64\bscs.ini
2016-11-02 20:23 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\tracing
2016-11-02 20:23 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf
2016-11-02 20:21 - 2015-04-21 19:14 - 00001010 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk
2016-11-02 20:21 - 2011-01-11 21:27 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2016-11-02 20:11 - 2015-07-26 21:34 - 00002162 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-11-02 20:11 - 2015-07-26 21:34 - 00002150 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-11-02 20:09 - 2013-01-09 15:21 - 12895232 ___SH C:\Users\admin\Desktop\Thumbs.db
2016-11-02 20:09 - 2010-11-28 20:47 - 00003934 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{21777A99-6D87-4CC9-AAC8-AA8CE7AEB611}
2016-11-02 19:52 - 2015-04-21 21:40 - 00000000 ____D C:\Users\admin\AppData\LocalLow\360WD
2016-11-02 19:40 - 2015-04-21 21:39 - 00001044 _____ C:\Users\Public\Desktop\360 Total Security.lnk
2016-11-02 19:40 - 2015-04-21 21:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\360 Security Center
2016-11-02 19:34 - 2009-07-14 07:13 - 00782066 _____ C:\Windows\system32\PerfStringBackup.INI
2016-11-02 19:34 - 2009-07-14 06:45 - 00016304 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-11-02 19:34 - 2009-07-14 06:45 - 00016304 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-11-02 19:29 - 2011-01-13 14:06 - 00000000 ____D C:\Users\admin\AppData\Roaming\TeamViewer
2016-11-02 19:27 - 2010-11-29 11:14 - 00065536 _____ C:\Windows\system32\Ikeext.etl
2016-11-02 18:47 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-11-02 10:53 - 2010-11-27 12:19 - 00000000 ____D C:\Users\admin\AppData\Roaming\Skype
2016-11-02 10:48 - 2015-04-21 21:47 - 00000000 __SHD C:\ProgramData\360Quarant
2016-11-02 10:48 - 2015-04-21 21:47 - 00000000 __SHD C:\$360Section
2016-11-01 20:09 - 2016-03-08 21:13 - 00003186 _____ C:\Windows\System32\Tasks\HPCeeScheduleForadmin
2016-11-01 20:09 - 2016-03-08 21:13 - 00000332 _____ C:\Windows\Tasks\HPCeeScheduleForadmin.job
2016-11-01 17:44 - 2014-01-06 16:19 - 00000000 ____D C:\Users\admin\AppData\LocalLow\Adblock Plus for IE
2016-10-31 18:36 - 2012-08-10 16:59 - 00000000 ____D C:\Users\admin\AppData\Roaming\vlc
2016-10-26 15:28 - 2015-04-21 21:41 - 00000000 ____D C:\Users\admin\AppData\Roaming\360safe
2016-10-24 15:12 - 2014-09-23 14:49 - 00000000 ____D C:\Users\admin\Documents\ViberDownloads
2016-10-24 15:11 - 2014-09-19 06:42 - 00000000 ____D C:\Users\admin\AppData\Roaming\ViberPC
2016-10-24 05:09 - 2015-11-25 17:23 - 00086248 _____ (360.cn) C:\Windows\SysWOW64\Drivers\360AvFlt.sys
2016-10-24 05:09 - 2015-04-21 21:39 - 00330472 _____ (360.cn) C:\Windows\system32\Drivers\360Box64.sys
2016-10-24 05:09 - 2015-04-21 21:39 - 00086248 _____ (360.cn) C:\Windows\system32\Drivers\360AvFlt.sys
2016-10-12 17:48 - 2011-05-30 20:26 - 00375296 ___SH C:\Users\admin\Documents\Thumbs.db
2016-10-12 10:33 - 2011-01-17 17:43 - 00009424 _____ C:\Windows\SysWOW64\SHORTCUT.INI
2016-10-12 10:33 - 2011-01-17 17:43 - 00002002 _____ C:\Windows\SysWOW64\REMOTEDEVICE.INI
2016-10-10 12:44 - 2016-01-26 20:29 - 00000000 ____D C:\Users\admin\Desktop\документи

==================== Files in the root of some directories =======

2014-10-08 19:56 - 2014-10-08 19:56 - 0699016 _____ (CNET Download.com) C:\Program Files\cbsidlm-cbsi213-KMPlayer-SEO-10659939.exe
2016-01-21 22:06 - 2016-01-22 01:10 - 0000132 _____ () C:\Users\admin\AppData\Roaming\Adobe PNG Format CS5 Prefs
2011-08-01 22:25 - 2014-08-19 18:19 - 0006656 _____ () C:\Users\admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2011-07-17 07:09 - 2011-07-17 07:10 - 0000000 _____ () C:\Users\admin\AppData\Local\{63650ECE-BD60-4802-B0F8-8571139EED20}
2011-05-21 15:15 - 2011-05-21 15:16 - 0000000 _____ () C:\Users\admin\AppData\Local\{68B3D3BE-44E9-40D9-8BEC-4C843D676F04}
2011-07-20 13:52 - 2011-07-20 13:54 - 0000000 _____ () C:\Users\admin\AppData\Local\{DD54AE83-3352-4B06-B846-C6A322989FF7}
2013-02-14 16:11 - 2013-02-14 16:11 - 0137041 _____ () C:\ProgramData\1360851078.bdinstall.bin
2013-04-10 19:39 - 2013-04-10 19:39 - 0022693 _____ () C:\ProgramData\1365615553.bdinstall.bin
2013-04-10 19:53 - 2013-04-10 19:53 - 0163289 _____ () C:\ProgramData\1365615555.bdinstall.bin
2013-09-07 11:09 - 2013-09-07 11:09 - 0022832 _____ () C:\ProgramData\1378544943.bdinstall.bin
2013-09-07 11:09 - 2013-09-07 11:09 - 0043127 _____ () C:\ProgramData\1378544949.bdinstall.bin
2013-09-07 11:11 - 2013-09-07 11:11 - 0028666 _____ () C:\ProgramData\1378545076.1496.bin
2013-09-07 11:11 - 2013-09-07 11:11 - 0004387 _____ () C:\ProgramData\1378545076.2504.bin
2013-09-07 11:11 - 2013-09-07 11:11 - 0004355 _____ () C:\ProgramData\1378545076.2508.bin
2013-09-07 11:11 - 2013-09-07 11:12 - 0039104 _____ () C:\ProgramData\1378545076.3020.bin
2016-05-05 14:11 - 2016-05-05 14:11 - 0000003 _____ () C:\ProgramData\76E96546D015.dat
2011-01-17 12:18 - 2011-03-02 17:09 - 0000000 _____ () C:\ProgramData\LauncherAccess.dt
2015-03-23 19:44 - 2015-03-23 19:44 - 0000153 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc

Files to move or delete:
====================
C:\ProgramData\76E96546D015.dat


==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-10-26 16:20

==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 30-10-2016
Ran by admin (02-11-2016 20:27:20)
Running from C:\Users\admin\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2010-11-26 12:06:42)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

admin (S-1-5-21-4281457091-153058287-3019275391-1000 - Administrator - Enabled) => C:\Users\admin
Administrator (S-1-5-21-4281457091-153058287-3019275391-500 - Administrator - Disabled)
Guest (S-1-5-21-4281457091-153058287-3019275391-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-4281457091-153058287-3019275391-1002 - Limited - Enabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Bitdefender Antivirus Free Edition (Enabled - Up to date) {9B5F5313-CAF9-DD97-C460-E778420237B4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Bitdefender Antivirus Free Edition (Enabled - Up to date) {203EB2F7-ECC3-D219-FED0-DC0A39857D09}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

360 Total Security (HKLM-x32\...\360TotalSecurity) (Version: 8.8.0.1083 - 360 Security Center)
ABBYY FineReader 5.0 Sprint (HKLM-x32\...\{D1696920-9794-4BBC-8A30-7A88763DE5A2}) (Version: 5.0.0.33417 - ABBYY Software House)
ABBYY FineReader 6.0 (HKLM-x32\...\{AF600F7B-67A7-48D9-BA3B-0FF97F35F970}) (Version: 6.0.759.29421 - ABBYY Software House)
Adblock Plus for IE (32-bit and 64-bit) (HKLM\...\{C23EE7CE-C1A3-4F94-A8F0-9E0AC9C6DE6E}) (Version: 1.1 - Eyeo GmbH)
Adblock Plus for IE (HKLM-x32\...\{fd97d1e2-368a-4cd9-af63-8eeff938044a}) (Version: 1.1 - )
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.7.0.1530 - Adobe Systems Incorporated)
Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated)
Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated)
Adobe Photoshop CS5 (HKLM-x32\...\{15FEDA5F-141C-4127-8D7E-B962D1742728}) (Version: 12.0 - Adobe Systems Incorporated)
Adobe Reader 9.2 (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-A92000000001}) (Version: 9.2.0 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.9.159 - Adobe Systems, Inc.)
AIDA64 Extreme Edition v1.50 (HKLM-x32\...\AIDA64 Extreme Edition_is1) (Version: 1.50 - FinalWire Ltd.)
AutoCAD 2014 - English (Version: 19.1.18.0 - Autodesk) Hidden
AutoCAD 2014 Language Pack - English (Version: 19.1.18.0 - Autodesk) Hidden
Autodesk AutoCAD 2014 - English (HKLM\...\AutoCAD 2014 - English) (Version: 19.1.18.0 - Autodesk)
Autodesk Content Service (HKLM-x32\...\Autodesk Content Service) (Version: 3.1.3.0 - Autodesk)
Autodesk Content Service (x32 Version: 3.1.3.0 - Autodesk) Hidden
Autodesk Content Service Language Pack (x32 Version: 3.1.3.0 - Autodesk) Hidden
Autodesk Featured Apps (HKLM-x32\...\{F732FEDA-7713-4428-934B-EF83B8DD65D0}) (Version: 1.1.0 - Autodesk)
Autodesk Material Library 2014 (HKLM-x32\...\{644F9B19-A462-499C-BF4D-300ABC2A28B1}) (Version: 4.0.19.0 - Autodesk)
Autodesk Material Library Base Resolution Image Library 2014 (HKLM-x32\...\{51BF3210-B825-4092-8E0D-66D689916E02}) (Version: 4.0.19.0 - Autodesk)
BitComet 1.24 (HKLM-x32\...\BitComet) (Version: 1.24 - CometNetwork)
Bluesoleil 6.4.249.0 (HKLM\...\{23A2D29F-4E89-42F8-A30B-6BB8A192926B}) (Version: 6.4.249.0 - IVT Corporation)
Bluetooth Stack for Windows by Toshiba (HKLM\...\{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}) (Version: v7.00.15(T) - TOSHIBA CORPORATION)
BookReader 4.6 (HKLM-x32\...\BookReader_is1) (Version:  - Rudenko Software)
CCleaner (HKLM\...\CCleaner) (Version: 5.20 - Piriform)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.46.1.0327 - DT Soft Ltd)
EPSON Copy Utility 3 (HKLM-x32\...\{67EDD823-135A-4D59-87BD-950616D6E857}) (Version: 3.0.1.0 - )
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version:  - )
EPSON Smart Panel (HKLM-x32\...\{6C11D561-620B-47DA-A693-4C597F3CDF40}) (Version:  - )
FARO LS 1.1.501.0 (64bit) (HKLM-x32\...\{8A470330-70B2-49AD-86AF-79885EF9898A}) (Version: 5.1.0.30630 - FARO Scanner Production)
GOM Player (HKLM-x32\...\GOM Player) (Version: 2.2.56.5183 - Gretech Corporation)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 54.0.2840.87 - Google Inc.)
Google Update Helper (x32 Version: 1.3.24.7 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
Google+ Auto Backup (HKLM-x32\...\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google)
HP LaserJet Pro MFP M125-M126 (HKLM-x32\...\{c65448bc-e467-4ec7-b4a5-246697f52957}) (Version: 15.0.15188.1312 - Hewlett-Packard)
HP Support Assistant (HKLM-x32\...\{79C54A05-F146-4EA0-8A70-D4EFE6181E52}) (Version: 8.3.34.7 - Hewlett-Packard Company)
HP Support Solutions Framework (HKLM-x32\...\{4DD2A506-31F4-45E5-80E5-C365C71C108F}) (Version: 12.5.32.37 - Hewlett-Packard Company)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDXP (x32 Version: 3.0.26.59 - HP) Hidden
HPLJDXPHelper (x32 Version: 140.069.007 - HP) Hidden
HPLJProMFPM125M126 (HKLM-x32\...\{B2894225-82C7-4006-B243-6272589993B2}) (Version: 1.00.0000 - Име на компания)
HPLJUTCore (x32 Version: 014.000.0001 - HP) Hidden
HPLJUTM125_126 (x32 Version: 008.000.0001 - HP) Hidden
hppLaserJetService (x32 Version: 009.033.00926 - Hewlett-Packard) Hidden
hppM125LaserJetService (x32 Version: 001.032.00682 - Hewlett-Packard) Hidden
hpStatusAlerts (x32 Version: 140.040.00231 - Hewlett Packard) Hidden
hpStatusAlertsM125-M126 (x32 Version: 080.046.00113 - Hewlett-Packard) Hidden
ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden
Intel(R) Graphics Media Accelerator Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.1986 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 9.5.7.1002 - Intel Corporation)
Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.510 - Oracle)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
LJDXPHelperUI (x32 Version: 140.069.007 - HP) Hidden
Malwarebytes Anti-Malware, версия 2.00.0.1000 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.00.0.1000 - Malwarebytes Corporation)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office Suite Activation Assistant (HKLM-x32\...\{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}) (Version: 2.9 - Microsoft Corporation)
Microsoft Office XP Professional with FrontPage (HKLM-x32\...\{90280409-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.6626.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\...\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual Studio Community 2013 with Update 4 (HKLM-x32\...\{96a8b90c-0a91-4e76-ab34-730c23923d11}) (Version: 12.0.31101 - Microsoft Corporation)
Microsoft Works (HKLM-x32\...\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}) (Version: 9.7.0621 - Microsoft Corporation)
Mozilla Firefox 47.0.1 (x86 bg) (HKLM-x32\...\Mozilla Firefox 47.0.1 (x86 bg)) (Version: 47.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 47.0.1.6018 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MyDefrag v4.3.1 (HKLM\...\MyDefrag v4.3.1_is1) (Version: 4.0.0.0 - J.C. Kessels)
OCCT 4.4.2 (HKLM-x32\...\OCCT) (Version: 4.4.2 - Ocbase.com)
PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden
Perf2480P_2580P Reference Guide (HKLM-x32\...\Perf2480P_2580P Reference Guide) (Version:  - )
Photo Service - powered by myphotobook (HKLM-x32\...\eu.myphotobook.001F9DF2D0BAABEB11F42CCEE43224607B61109C.1) (Version: 1.0.5-124 - myphotobook GmbH)
PhotoImpression 5 (HKLM-x32\...\{66C8BE35-8BBB-472B-96C7-C7C9A499F988}) (Version:  - )
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
Presto! BizCard 4.0 Component for Windows CE (HKLM-x32\...\{41B20968-B2E1-49C0-9508-CC1544D568F5}) (Version:  - )
Presto! BizCard 4.1 Eng (HKLM-x32\...\Uninstall Presto! BizCard 4.1 Eng) (Version:  - )
QuickTime (HKLM-x32\...\{0E64B098-8018-4256-BA23-C316A43AD9B0}) (Version: 7.72.80.56 - Apple Inc.)
Realtek Ethernet Controller Driver For Windows Vista and Later (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5964 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30105 - Realtek Semiconductor Corp.)
Realtek WLAN Driver (HKLM-x32\...\{0FB630AB-7BD8-40AE-B223-60397D57C3C9}) (Version: 2.00.0006 - Realtek)
SAMSUNG CDMA Modem Driver Set (HKLM-x32\...\SAMSUNG CDMA Modem) (Version:  - )
SAMSUNG Mobile USB Modem 1.0 Software (HKLM-x32\...\SAMSUNG Mobile USB Modem 1.0) (Version:  - )
SAMSUNG Mobile USB Modem Software (HKLM-x32\...\SAMSUNG Mobile USB Modem) (Version:  - )
Samsung PC Studio (HKLM-x32\...\{C4A4722E-79F9-417C-BD72-8D359A090C97}) (Version: 3.0.1.60610 - Samsung Electronics Co., Ltd.)
Samsung PC Studio (x32 Version: 3.0.0.60610 - Samsung Electronics Co., Ltd.) Hidden
Samsung PC Studio 3 USB Driver Installer (HKLM-x32\...\{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}) (Version: 1.00.0000 - Samsung Electronics Co., Ltd.)
ScanToWeb (HKLM-x32\...\{EBAE381B-60A6-4863-AA9F-FCAB755BC9E5}) (Version:  - )
SketchUp Import for AutoCAD 2014 (HKLM-x32\...\{644E9589-F73A-49A4-AC61-A953B9DE5669}) (Version: 1.1.0 - Autodesk)
Skype™ 6.14 (HKLM-x32\...\{1845470B-EB14-4ABC-835B-E36C693DC07D}) (Version: 6.14.104 - Skype Technologies S.A.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 14.0.11.0 - Synaptics Incorporated)
TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.47484 - TeamViewer)
TOSHIBA Disc Creator (HKLM\...\{5DA0E02F-970B-424B-BF41-513A5018E4C0}) (Version: 2.1.0.2 for x64 - TOSHIBA Corporation)
TOSHIBA Flash Cards Support Utility (HKLM-x32\...\InstallShield_{620BBA5E-F848-4D56-8BDA-584E44584C5E}) (Version: 1.63.0.4C - TOSHIBA CORPORATION)
TOSHIBA Hardware Setup (HKLM-x32\...\InstallShield_{5279374D-87FE-4879-9385-F17278EBB9D3}) (Version: 1.63.0.18C - TOSHIBA CORPORATION)
TOSHIBA Value Added Package (HKLM-x32\...\InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}) (Version: 1.2.34.64 - TOSHIBA Corporation)
TOSHIBA Web Camera Application (HKLM-x32\...\{5E6F6CF3-BACC-4144-868C-E14622C658F3}) (Version: 1.1.1.9 - TOSHIBA Corporation)
TRORMCLauncher (HKLM-x32\...\InstallShield_{E65C7D8E-186D-484B-BEA8-DEF0331CE600}) (Version:  - )
TRORMCLauncher (Version: 1.0.0.9 - TOSHIBA) Hidden
UnCleaner (HKLM\...\UnCleaner) (Version: 1.7 - Josh Cell Softwares Corporation)
Utility Common Driver (x32 Version: 1.0.50.27C - TOSHIBA) Hidden
Viber (HKU\S-1-5-21-4281457091-153058287-3019275391-1000\...\Viber) (Version: 5.2.0.2546 - Viber Media Inc)
VLC media player 2.0.1 (HKLM-x32\...\VLC media player) (Version: 2.0.1 - VideoLAN)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Sync (HKLM-x32\...\{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}) (Version: 14.0.8089.726 - Microsoft Corporation)
Windows Mobile Device Center (HKLM\...\{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}) (Version: 6.1.6965.0 - Microsoft Corporation)
WinRAR archiver (HKLM\...\WinRAR archiver) (Version:  - )
Пакет за съвместимост за системата Office 2007 (HKLM-x32\...\{90120000-0020-0402-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-4281457091-153058287-3019275391-1000_Classes\CLSID\{6A221957-2D85-42A7-8E19-BE33950D1DEB}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2014\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-4281457091-153058287-3019275391-1000_Classes\CLSID\{7DE1BE5C-CEBA-4F1D-ACBC-9CE11EE9A2A1}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2014\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-4281457091-153058287-3019275391-1000_Classes\CLSID\{BD0DEB94-63DB-4392-9420-6EEE05094B1F}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2014\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-4281457091-153058287-3019275391-1000_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2014\en-US\acadficn.dll (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-4281457091-153058287-3019275391-1000_Classes\CLSID\{F6BF8414-962C-40FE-90F1-B80A7E72DB9A}\InprocServer32 -> C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8}\acledit.dll => No File <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {036CD953-27BB-4F16-920E-D47C69E9C110} - System32\Tasks\HPCeeScheduleForadmin => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2015-06-16] (Hewlett-Packard)
Task: {07386106-3DC9-4B26-96DE-BF42784A3A18} - System32\Tasks\{2745CCDA-0476-4DA0-AAD3-90DEFA166320} => pcalua.exe -a C:\Users\admin\Desktop\KYOCERA_KX_4.2.1027a_2K_XP_EN.exe -d C:\Users\admin\Desktop
Task: {182C5061-0D90-4BDB-8B42-409952E56148} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {47AFA797-11B3-4997-A034-2CB8473C125F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2016-08-23] (HP Inc.)
Task: {63E352A0-C4E2-481D-A818-8E91454DC668} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {6CBD1DDA-D25D-484A-A2F4-F23DB30C8667} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-24] (Adobe Systems Incorporated)
Task: {728FDEDC-0CF6-4ACE-BC0A-FC3234FFCF26} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-08-03] (HP Inc.)
Task: {77CC50E4-7A60-4D6A-A9F3-5AC55C694E63} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Active Health Launcher => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2016-05-18] (HP Inc.)
Task: {89DF908D-8408-46E0-A4B2-A1FD7AA07C83} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2016-05-09] (Hewlett-Packard)
Task: {95CF2A5C-7A5E-4735-BC83-C23C5B9DEF70} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-07-13] (Piriform Ltd)
Task: {AFCE0DD7-2D35-4A08-9ACC-C754E598D5CE} - System32\Tasks\{1E52E74E-E1BF-4A6B-A8F8-81291AFA6820} => C:\Program Files (x86)\Skype\\Phone\Skype.exe [2014-02-10] (Skype Technologies S.A.)
Task: {CF5EF035-9FAC-4838-BC2F-E7F2F4BA85ED} - System32\Tasks\HPLJCustParticipation => C:\Program Files (x86)\HP\HPLJUT\HPLJUTSCH.exe [2014-10-19] (Hewlett Packard)
Task: {DC85E4DA-D483-4B12-B561-42C66FDA9951} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2016-08-23] (HP Inc.)
Task: {E64A7166-8043-4C28-9373-3A540E568261} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2016-05-18] (HP Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\HPCeeScheduleForadmin.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

Shortcut: C:\Users\admin\Desktop\Бетани- Shortcut.lnk -> D:\betani () <===== Cyrillic
Shortcut: C:\Users\admin\Desktop\Тони-Shortcut.lnk -> D:\Toni () <===== Cyrillic
Shortcut: C:\Users\admin\Desktop\Цветина-Shortcut.lnk -> D:\Cvetina () <===== Cyrillic
Shortcut: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Network Shortcuts\My Web Sites on MSN\target.lnk -> hxxp://www.msnusers.com
Shortcut: C:\Users\Public\Desktop\HP LaserJet Pro MFP M125-M126  - Център за помощ и обучение.lnk -> C:\Program Files (x86)\HP\HP LaserJet Pro MFP M125-M126\Help_Learn\Help.exe (Hewlett-Packard Company) <===== Cyrillic

ShortcutWithArgument: C:\Users\admin\AppData\Roaming\Microsoft\Windows\SendTo\Bluetooth\Бетани Радкова (SM-G35.lnk -> D:\Program Files\Bluesoleil\BsSend2bt.exe () -> -DEV_ADDR=14:A3:64:74:12:27 <===== Cyrillic
ShortcutWithArgument: C:\Users\admin\AppData\Roaming\Microsoft\Windows\SendTo\Bluetooth\Габи (GT-I9060I).lnk -> D:\Program Files\Bluesoleil\BsSend2bt.exe () -> -DEV_ADDR=0C:B3:19:31:99:DC <===== Cyrillic

==================== Loaded Modules (Whitelisted) ==============

2009-02-27 16:46 - 2009-02-27 16:46 - 00022016 _____ () C:\Windows\System32\BsTrace.dll
2009-02-27 16:48 - 2009-02-27 16:48 - 00382976 _____ () C:\Windows\System32\BsMobileSDK.dll
2009-02-27 16:46 - 2009-02-27 16:46 - 00083456 _____ () C:\Windows\System32\Bs2Res.dll
2009-02-27 16:49 - 2009-02-27 16:49 - 00753664 _____ () C:\Windows\System32\BsShell.dll
2008-03-07 13:54 - 2008-03-07 13:54 - 17892352 _____ () C:\Windows\System32\BsLangInDepRes.dll
2009-02-27 16:46 - 2009-02-27 16:46 - 00083456 _____ () C:\Windows\system32\Bs2Res.dll
2010-12-18 18:19 - 2010-03-15 13:28 - 00166400 _____ () C:\Program Files\WinRAR\rarext.dll
2015-04-21 19:33 - 2016-10-24 05:09 - 00782248 _____ () C:\Program Files (x86)\360\Total Security\MenuEx64.dll
2009-02-27 16:46 - 2009-02-27 16:46 - 00009728 _____ () C:\Windows\System32\BsHelpCSps.dll
2009-02-27 16:46 - 2009-02-27 16:46 - 00041984 _____ () C:\Windows\System32\BlueSoleilCSps.dll
2009-02-27 16:47 - 2009-02-27 16:47 - 00011264 _____ () C:\Windows\System32\BsMobileCSps.dll
2009-02-27 17:04 - 2009-02-27 17:04 - 00850432 _____ () D:\Program Files\Bluesoleil\BlueSoleilCS.exe
2009-10-18 16:20 - 2009-10-18 16:20 - 07959864 _____ () C:\Program Files\TOSHIBA\FlashCards\BlackPng.dll
2009-11-03 14:26 - 2009-11-03 14:26 - 00053560 _____ () C:\Program Files\TOSHIBA\FlashCards\Hotkey\FnZ.dll
2009-03-12 20:08 - 2009-03-12 20:08 - 00048640 _____ () C:\Program Files (x86)\Toshiba\PCDiag\NotifyPCD.dll
2009-02-27 16:46 - 2009-02-27 16:46 - 00191488 _____ () D:\Program Files\Bluesoleil\BsHelpCS.exe
2009-02-27 17:04 - 2009-02-27 17:04 - 00278016 _____ () D:\Program Files\Bluesoleil\BtTray.exe
2009-02-27 16:46 - 2009-02-27 16:46 - 00022016 _____ () C:\Windows\system32\bstrace.dll
2009-02-27 16:43 - 2009-02-27 16:43 - 00110712 _____ () D:\Program Files\Bluesoleil\setup.dll
2015-04-21 19:33 - 2016-10-24 05:09 - 00099240 _____ () C:\Program Files (x86)\360\Total Security\deepscan\qutmload.dll
2015-04-21 21:39 - 2016-10-24 05:09 - 00584616 _____ () C:\Program Files (x86)\360\Total Security\safemon\wdui2.dll
2009-02-27 16:46 - 2009-02-27 16:46 - 00022016 _____ () C:\Windows\system32\BsTrace.dll
2009-02-27 16:48 - 2009-02-27 16:48 - 00382976 _____ () C:\Windows\system32\BsMobileSDK.dll
2008-03-07 13:54 - 2008-03-07 13:54 - 17892352 _____ () C:\Windows\system32\BsLangInDepRes.dll
2009-02-27 16:48 - 2009-02-27 16:48 - 00141312 _____ () C:\Windows\system32\BsProfilefunc.dll
2009-02-27 16:40 - 2009-02-27 16:40 - 00028672 _____ () C:\Windows\SysWOW64\BsMobileCSps.dll
2009-02-27 16:44 - 2009-02-27 16:44 - 00622693 _____ () C:\Windows\SysWOW64\BsShell.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

HKU\S-1-5-21-4281457091-153058287-3019275391-1000\Software\Classes\.scr: AutoCADScriptFile => C:\Windows\system32\notepad.exe "%1"

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-4281457091-153058287-3019275391-1000\...\ubb.bg -> hxxps://ebb.ubb.bg

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-4281457091-153058287-3019275391-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\admin\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk => C:\Windows\pss\Microsoft Office.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^admin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^TRDCReminder.lnk => C:\Windows\pss\TRDCReminder.lnk.Startup
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: swg => "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
MSCONFIG\startupreg: Toshiba Registration => C:\Program Files\Toshiba\Registration\ToshibaReminder.exe

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{C424856F-FA56-4BEE-8B53-A8BF2D7FB15E}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{18318ED1-8227-42D1-B02F-2CFD25A369A5}] => (Allow) svchost.exe
FirewallRules: [{2BF9FB4F-D138-4557-A48A-F27FB868162A}] => (Allow) C:\Program Files (x86)\Windows Live\Sync\WindowsLiveSync.exe
FirewallRules: [{8D25FD7F-6E2B-473E-838E-A8F21448F9C9}] => (Allow) D:\Program Files\BitComet\BitComet.exe
FirewallRules: [{C221227F-F45A-4B0A-9764-B640892FEF49}] => (Allow) D:\Program Files\BitComet\BitComet.exe
FirewallRules: [TCP Query User{6AE58579-499F-497B-9CE7-6FABAF4F3E1B}D:\program files\bitcomet\bitcomet.exe] => (Allow) D:\program files\bitcomet\bitcomet.exe
FirewallRules: [UDP Query User{D613231E-61A7-4587-A11E-66E2655B3F1C}D:\program files\bitcomet\bitcomet.exe] => (Allow) D:\program files\bitcomet\bitcomet.exe
FirewallRules: [{3008175C-1B6E-4D55-A483-AF940D0FC7B1}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{B1991A3B-2B40-4BCC-86E2-B0E6D2D1ABDB}] => (Allow) LPort=2869
FirewallRules: [{D51847BF-FA3D-4234-B9BB-2334C9820296}] => (Allow) LPort=1900
FirewallRules: [{F912C1DC-F620-48FD-AC9B-907B0862BDEE}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{8AF505E3-7C8A-41AC-9219-1F7A28402830}] => (Allow) LPort=26072
FirewallRules: [{741A32AD-6788-47A0-88EB-B1081CB565B9}] => (Allow) LPort=26072
FirewallRules: [{B8B541A8-1350-4993-8E07-345A63BE2BA9}] => (Allow) D:\Program Files\Bluesoleil\BlueSoleilCS.exe
FirewallRules: [{44207025-1986-4658-9A30-E619F8112469}] => (Allow) D:\Program Files\Bluesoleil\BlueSoleilCS.exe
FirewallRules: [{2BD71612-B039-4D17-8B3E-BCEED89BFCF5}] => (Allow) D:\Program Files\Bluesoleil\BlueSoleilCS.exe
FirewallRules: [{9E4F5CFC-762C-451E-BA08-C1FAB8EA7D1C}] => (Allow) D:\Program Files\Bluesoleil\BlueSoleilCS.exe
FirewallRules: [{59F6747E-3922-42B3-96B3-02851A979FE0}] => (Allow) LPort=26072
FirewallRules: [{E138D421-F9EE-43D2-A2E4-6CBAA56783FC}] => (Allow) LPort=26072
FirewallRules: [TCP Query User{BAB669CD-F3C8-4C36-9023-BC1C1DA04689}C:\program files (x86)\internet explorer\iexplore.exe] => (Block) C:\program files (x86)\internet explorer\iexplore.exe
FirewallRules: [UDP Query User{CBCCD185-2A2B-4717-9973-F12DA540DB9B}C:\program files (x86)\internet explorer\iexplore.exe] => (Block) C:\program files (x86)\internet explorer\iexplore.exe
FirewallRules: [{86AF9AEB-4AC8-4B78-A2F4-F18B6807FBA5}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{C6D73CA2-C5E9-44BC-A841-E60BE1F1B6CE}] => (Allow) LPort=50248
FirewallRules: [{E6FDD5F9-8873-4307-876F-716160820EEF}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{744B8491-9817-449B-B5C2-81E5052B0812}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{7F81E33A-0106-4CAF-ADE2-7D214B306B53}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{714C2141-5006-41D1-8289-E5BD53801FBD}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{A9F4D7B9-9C9D-4C7C-9BF0-7D5565378781}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{ABCD0FB5-7AA2-4917-A341-FA95CADFD327}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{3AAD8131-5BC8-4BBB-8416-80D29F5A4CAE}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{7FB0C8A6-D470-4BB5-896F-CA70688D3DC1}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{6CEE22AE-4E8D-4D07-9833-DB3DD2C7372C}] => (Allow) C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe
FirewallRules: [{80AA0C3C-CC94-45A2-A6F9-1D46F732F5A7}] => (Allow) C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe
FirewallRules: [{31AFECA8-271C-4F62-8094-05F8132DA47F}] => (Allow) C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe
FirewallRules: [{2B4AD7FF-FB7A-45D4-A923-425BD0CABEDA}] => (Allow) C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe
FirewallRules: [{3A037F0A-CD2E-4955-9A02-EA5B19D14D58}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{E4898E7D-CFD7-4F6A-9363-D26C06542933}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{966AAABB-2709-42BD-9EEE-F2C9A76DAAFD}] => (Allow) C:\Program Files (x86)\HP\HP LaserJet Pro MFP M125-M126\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{4E541EAA-40BE-47ED-88D1-19113FB264AE}] => (Allow) C:\Program Files (x86)\HP\HP LaserJet Pro MFP M125-M126\bin\EWSProxy.exe
FirewallRules: [{55F2F708-6CFF-42B1-95D0-312913396EAF}] => (Allow) C:\Program Files (x86)\360\Total Security\softmgr\360InstantSetup.exe
FirewallRules: [{3CCCE70F-647C-46DC-896A-B6D78F10A55E}] => (Allow) C:\Program Files (x86)\360\Total Security\softmgr\360InstantSetup.exe
FirewallRules: [{C62013CE-1059-49E9-973D-80B6D32B62BD}] => (Allow) C:\Program Files (x86)\360\Total Security\softmgr\360InstantSetup.exe
FirewallRules: [{17A94483-084F-408C-B974-FDED8B6A7DFD}] => (Allow) C:\Program Files (x86)\360\Total Security\softmgr\360InstantSetup.exe
FirewallRules: [{0BFD7072-5B07-4BAD-BEC0-669A505DCE4A}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{63FE5792-0FC3-4EDC-8A77-F2D06E7B5111}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{34E13B33-7769-499C-B838-8EF4E0B0FCA9}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{CA6DDC7F-7B56-44BD-9EE3-B66ACD85CE5B}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{76A185C2-E673-454F-A143-5DB3E5285E96}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{0F37AAF4-3EA8-40F9-9BCC-04D997CB151F}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{B1F44BDF-9A29-438D-A470-B23B837E8D32}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{1251D309-838E-43BB-8DB5-DA01018239AC}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{3A7041D2-AEDA-494D-A9EC-38B31206114B}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe

==================== Restore Points =========================

03-11-2015 10:43:14 Windows Update
10-01-2016 19:25:26 Installed HP Support Solutions Framework
10-01-2016 19:58:07 Installed HP Support Assistant
14-01-2016 22:12:09 Registry Reviver Restore Point (01/14/16)
02-02-2016 20:07:49 Windows Update

==================== Faulty Device Manager Devices =============

Name: IVT_Virtual_0000
Description: IVT_Virtual_0000
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: HL-DT-ST DVDRAM GT20N
Description: CD-ROM Drive
Class Guid: {4d36e965-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard CD-ROM drives)
Service: cdrom
Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
Resolution: A registry problem was detected.
 This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver.

Name: 
Description: 
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (11/02/2016 08:24:13 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: BsMobileCS.exe, version: 1.0.0.1, time stamp: 0x49a7a70e
Faulting module name: ExtraLib.dll, version: 0.0.0.0, time stamp: 0x4954998e
Exception code: 0xc0000005
Fault offset: 0x00001ec5
Faulting process id: 0x1218
Faulting application start time: 0x01d235364e985600
Faulting application path: D:\Program Files\Bluesoleil\BsMobileCS.exe
Faulting module path: D:\Program Files\Bluesoleil\Mobile\ExtraLib.dll
Report Id: 8dd58176-a129-11e6-b709-705ab6ba6057

Error: (11/02/2016 07:27:17 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: BsMobileCS.exe, version: 1.0.0.1, time stamp: 0x49a7a70e
Faulting module name: ExtraLib.dll, version: 0.0.0.0, time stamp: 0x4954998e
Exception code: 0xc0000005
Fault offset: 0x00001ec5
Faulting process id: 0x900
Faulting application start time: 0x01d2352e4e6503a3
Faulting application path: D:\Program Files\Bluesoleil\BsMobileCS.exe
Faulting module path: D:\Program Files\Bluesoleil\Mobile\ExtraLib.dll
Report Id: 99eeb23c-a121-11e6-b709-705ab6ba6057

Error: (11/02/2016 10:34:32 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: WLXPhotoGallery.exe, version: 15.4.3502.922, time stamp: 0x4c9b007c
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x0b7cb5ed
Faulting process id: 0x1590
Faulting application start time: 0x01d234e3de873713
Faulting application path: C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe
Faulting module path: unknown
Report Id: 2cd4d858-a0d7-11e6-be87-705ab6ba6057

Error: (11/02/2016 10:17:26 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: BsMobileCS.exe, version: 1.0.0.1, time stamp: 0x49a7a70e
Faulting module name: ExtraLib.dll, version: 0.0.0.0, time stamp: 0x4954998e
Exception code: 0xc0000005
Fault offset: 0x00001ec5
Faulting process id: 0x7ec
Faulting application start time: 0x01d234e18287f852
Faulting application path: D:\Program Files\Bluesoleil\BsMobileCS.exe
Faulting module path: D:\Program Files\Bluesoleil\Mobile\ExtraLib.dll
Report Id: c98680b9-a0d4-11e6-be87-705ab6ba6057

Error: (11/02/2016 08:08:02 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: BsMobileCS.exe, version: 1.0.0.1, time stamp: 0x49a7a70e
Faulting module name: ExtraLib.dll, version: 0.0.0.0, time stamp: 0x4954998e
Exception code: 0xc0000005
Fault offset: 0x00001ec5
Faulting process id: 0x105c
Faulting application start time: 0x01d234cf77a8bed7
Faulting application path: D:\Program Files\Bluesoleil\BsMobileCS.exe
Faulting module path: D:\Program Files\Bluesoleil\Mobile\ExtraLib.dll
Report Id: b5e8df08-a0c2-11e6-b178-705ab6ba6057

Error: (11/02/2016 08:01:25 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: BsMobileCS.exe, version: 1.0.0.1, time stamp: 0x49a7a70e
Faulting module name: ExtraLib.dll, version: 0.0.0.0, time stamp: 0x4954998e
Exception code: 0xc0000005
Fault offset: 0x00001ec5
Faulting process id: 0x6cc
Faulting application start time: 0x01d234ce814b8ac6
Faulting application path: D:\Program Files\Bluesoleil\BsMobileCS.exe
Faulting module path: D:\Program Files\Bluesoleil\Mobile\ExtraLib.dll
Report Id: c94328f6-a0c1-11e6-b178-705ab6ba6057

Error: (11/01/2016 05:40:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: BsMobileCS.exe, version: 1.0.0.1, time stamp: 0x49a7a70e
Faulting module name: ExtraLib.dll, version: 0.0.0.0, time stamp: 0x4954998e
Exception code: 0xc0000005
Fault offset: 0x00001ec5
Faulting process id: 0xf48
Faulting application start time: 0x01d234564e01da01
Faulting application path: D:\Program Files\Bluesoleil\BsMobileCS.exe
Faulting module path: D:\Program Files\Bluesoleil\Mobile\ExtraLib.dll
Report Id: 8c47a74f-a049-11e6-99af-705ab6ba6057

Error: (11/01/2016 05:26:10 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: BsMobileCS.exe, version: 1.0.0.1, time stamp: 0x49a7a70e
Faulting module name: ExtraLib.dll, version: 0.0.0.0, time stamp: 0x4954998e
Exception code: 0xc0000005
Fault offset: 0x00001ec5
Faulting process id: 0x7ac
Faulting application start time: 0x01d234543c0fa281
Faulting application path: D:\Program Files\Bluesoleil\BsMobileCS.exe
Faulting module path: D:\Program Files\Bluesoleil\Mobile\ExtraLib.dll
Report Id: 83aab916-a047-11e6-99af-705ab6ba6057

Error: (10/31/2016 06:31:56 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: BsMobileCS.exe, version: 1.0.0.1, time stamp: 0x49a7a70e
Faulting module name: ExtraLib.dll, version: 0.0.0.0, time stamp: 0x4954998e
Exception code: 0xc0000005
Fault offset: 0x00001ec5
Faulting process id: 0x780
Faulting application start time: 0x01d233943fd72d40
Faulting application path: D:\Program Files\Bluesoleil\BsMobileCS.exe
Faulting module path: D:\Program Files\Bluesoleil\Mobile\ExtraLib.dll
Report Id: 894faedd-9f87-11e6-bc5f-705ab6ba6057

Error: (10/28/2016 08:23:57 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: BsMobileCS.exe, version: 1.0.0.1, time stamp: 0x49a7a70e
Faulting module name: ExtraLib.dll, version: 0.0.0.0, time stamp: 0x4954998e
Exception code: 0xc0000005
Fault offset: 0x00001ec5
Faulting process id: 0x79c
Faulting application start time: 0x01d231486904e567
Faulting application path: D:\Program Files\Bluesoleil\BsMobileCS.exe
Faulting module path: D:\Program Files\Bluesoleil\Mobile\ExtraLib.dll
Report Id: b023e65d-9d3b-11e6-85b5-705ab6ba6057


System errors:
=============
Error: (11/02/2016 08:24:13 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The BsMobileCS service terminated unexpectedly.  It has done this 2 time(s).

Error: (11/02/2016 07:40:39 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The 360 Total Security service terminated unexpectedly.  It has done this 1 time(s).

Error: (11/02/2016 07:27:29 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The BsMobileCS service terminated unexpectedly.  It has done this 1 time(s).

Error: (11/02/2016 07:27:29 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
cdrom

Error: (11/02/2016 07:27:01 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The CdaC15BA service failed to start due to the following error: 
This driver has been blocked from loading

Error: (11/02/2016 07:27:01 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \??\C:\Windows\SysWow64\drivers\CDAC15BA.SYS has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

Error: (11/02/2016 07:26:34 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Autodesk Content Service service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.

Error: (11/02/2016 07:26:34 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Autodesk Content Service service to connect.

Error: (11/02/2016 11:03:26 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Peer Networking Grouping service depends on the Peer Name Resolution Protocol service which failed to start because of the following error: 
%%-2140993535

Error: (11/02/2016 11:03:26 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Peer Name Resolution Protocol service terminated with the following error: 
%%-2140993535


CodeIntegrity:
===================================
  Date: 2013-04-09 10:05:47.047
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Bitdefender\Antivirus Free Edition\avc3\avc3_sig_186\avcuf64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-04-09 10:00:36.365
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Bitdefender\Antivirus Free Edition\avc3\avc3_sig_186\avcuf64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-04-09 09:53:26.129
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Bitdefender\Antivirus Free Edition\avc3\avc3_sig_186\avcuf64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-04-09 09:12:46.664
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Bitdefender\Antivirus Free Edition\avc3\avc3_sig_186\avcuf64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-04-08 18:06:50.612
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Bitdefender\Antivirus Free Edition\avc3\avc3_sig_186\avcuf64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-04-08 16:38:33.720
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Bitdefender\Antivirus Free Edition\avc3\avc3_sig_186\avcuf64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-04-08 16:19:45.423
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Bitdefender\Antivirus Free Edition\avc3\avc3_sig_186\avcuf64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-04-08 10:50:12.555
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Bitdefender\Antivirus Free Edition\avc3\avc3_sig_186\avcuf64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-04-08 08:30:44.693
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Bitdefender\Antivirus Free Edition\avc3\avc3_sig_186\avcuf64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-04-08 08:08:45.719
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Bitdefender\Antivirus Free Edition\avc3\avc3_sig_186\avcuf64.dll because the set of per-page image hashes could not be found on the system.


==================== Memory info =========================== 

Processor: Intel(R) Core(TM) i3 CPU M 330 @ 2.13GHz
Percentage of memory in use: 42%
Total physical RAM: 3893.61 MB
Available physical RAM: 2232.27 MB
Total Virtual: 7785.39 MB
Available Virtual: 6151.46 MB

==================== Drives ================================

Drive c: (WINDOWS) (Fixed) (Total:232.88 GB) (Free:178.62 GB) NTFS
Drive d: (Data) (Fixed) (Total:232.49 GB) (Free:167.34 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: AB8BD068)
Partition 1: (Active) - (Size=400 MB) - (Type=27)
Partition 2: (Not Active) - (Size=232.9 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=232.5 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

Прикачам и снимка на искането за пари.

Благодаря предварително на отзовалите се!

de_crypt_readme.bmp

Здравейте,

Пратете проба от заразените файлове на следния адрес за да разберете с коя версия точно сте заразена, защото има няколко (някои подлежат на декриптиране, някои не).

https://id-ransomware.malwarehunterteam.com/

След това публикувайте какво ви е отговорено на сайта.

Ако файловете не подлежат на декриптиране, тогава ще можем само да почистим системата, но не и да възстановим файловете ви!

Поздрави!

  • 2 седмици по-късно...

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.