Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Попъпи във Файърфокс

Featured Replies

Нещо почна да ми хвърля попъпи на сайтове за залагания. Ето лог от Хайджак. Идеи?

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 20:25:38 ч., on 23.1.2017 г.
Platform: Windows 7  (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)

FIREFOX: 50.1.0 (x86 en-US)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\F-Secure\SAFE\fshoster32.exe
C:\Windows\SysWOW64\HsMgr.exe
C:\Users\freako\AppData\Local\MiPhoneManager\main\MiPhoneHelper.exe
C:\Program Files\UNi Xonar Audio\Customapp\ASUSAUDIOCENTER.EXE
C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe
E:\Download\HijackThis.exe
C:\Windows\SysWOW64\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Browsing Protection by F-Secure - {45BBE08D-81C5-4A67-AF20-B2A077C67747} - C:\Program Files (x86)\F-Secure\SAFE\apps\CCF_Scanning\bin\browser\install\fs_ie_https\fs_ie_https.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll
O2 - BHO: iSkysoft iMedia Converter Deluxe 5.1.0 - {AEAF002F-E6D8-4A21-ABD3-2B309B79A6CE} - C:\PROGRA~3\iSkysoft\VIDEOC~1\WSBROW~1.DLL
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll
O4 - HKLM\..\Run: [iSkysoft Helper Compact.exe] C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe
O4 - HKLM\..\Run: [DelaypluginInstall] C:\ProgramData\iSkysoft\Video Converter Ultimate\DelayPluginI.exe
O4 - HKCU\..\Run: [MiPhoneManager] "C:\Users\freako\AppData\Local\MiPhoneManager\main\MiPhoneHelper.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office15\EXCEL.EXE/3000
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Autodata Limited License Service - Autodata Limited - C:\Program Files (x86)\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: F-Secure Hoster (fshoster) - F-Secure Corporation - C:\Program Files (x86)\F-Secure\SAFE\fshoster32.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files (x86)\F-Secure\SAFE\apps\ComputerSecurity\Common\FSMA32.EXE
O23 - Service: F-Secure Hoster (Restricted) (fsnethoster) - F-Secure Corporation - C:\Program Files (x86)\F-Secure\SAFE\fshoster32.exe
O23 - Service: F-Secure ORSP Client (FSORSPClient) - F-Secure Corporation - C:\Program Files (x86)\F-Secure\SAFE\apps\CCF_Reputation\fsorsp.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\AMT\LMS.exe
O23 - Service: MiRalinkRegistryWriter - Mediatek Inc. - C:\Program Files (x86)\Xiaomi\MiWiFi\RaRegistry.exe
O23 - Service: MiRalinkRegistryWriter64 - Mediatek Inc. - C:\Program Files (x86)\Xiaomi\MiWiFi\RaRegistry64.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: This service enables products that use the Nalpeiron Licensing System. (nlsX86cc) - Nalpeiron Ltd. - C:\Windows\SysWOW64\nlssrv32.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: StarWind AE Service (StarWindServiceAE) - StarWind Software - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

--
End of file - 8286 bytes

 

  • Автор
преди 37 минути, Stoyannnov написа:

HiJackThis е доста стар софтуер и пропуска по-новите зарази!

Изпълнете стъпките от темата по-долу:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 22-01-2017
Ran by freako (administrator) on FREAKO-PC (23-01-2017 21:09:28)
Running from E:\Download
Loaded Profiles: freako (Available Profiles: freako)
Platform: Windows 7 Ultimate (X64) Language: English (United States)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Autodata Limited) C:\Program Files (x86)\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\SAFE\fshoster32.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\SAFE\fshoster32.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\SAFE\apps\CCF_Reputation\fsorsp.exe
(Intel Corporation) C:\Program Files (x86)\Intel\AMT\LMS.exe
(Mediatek Inc.) C:\Program Files (x86)\Xiaomi\MiWiFi\RaRegistry.exe
(Mediatek Inc.) C:\Program Files (x86)\Xiaomi\MiWiFi\RaRegistry64.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\SAFE\fshoster32.exe
() C:\Windows\SysWOW64\HsMgr.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\SAFE\apps\ComputerSecurity\Anti-Virus\fsgk32.exe
() C:\Windows\system\HsMgr64.exe
(Intel Corporation) C:\Program Files (x86)\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe
() C:\Users\freako\AppData\Local\MiPhoneManager\main\MiPhoneHelper.exe
(CMedia) C:\Program Files\UNi Xonar Audio\Customapp\AsusAudioCenter.exe
(iSkySoft) C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\nlssrv32.exe
(StarWind Software) C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Intel Corporation) C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\SAFE\apps\ComputerSecurity\Common\FSMA32.EXE
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\SAFE\apps\ComputerSecurity\Common\FSHDLL64.EXE
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\SAFE\apps\ComputerSecurity\Anti-Virus\fssm32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(McAfee, Inc.) C:\Program Files\McAfee\Real Protect\RealProtect.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Cmaudio8788] => C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cmicnfgp.dll,CMICtrlWnd
HKLM\...\Run: [Cmaudio8788GX] => C:\Windows\syswow64\HsMgr.exe [200704 2008-07-11] ()
HKLM\...\Run: [Cmaudio8788GX64] => C:\Windows\system\HsMgr64.exe [282112 2008-07-11] ()
HKLM\...\Run: [picon] => C:\Program Files (x86)\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe [796696 2009-07-21] (Intel Corporation)
HKLM-x32\...\Run: [iSkysoft Helper Compact.exe] => C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe [2138272 2016-10-08] (iSkySoft)
HKLM-x32\...\Run: [DelaypluginInstall] => C:\ProgramData\iSkysoft\Video Converter Ultimate\DelayPluginI.exe [1971872 2016-10-25] ()
HKLM\...\RunOnce: [RealProtect] => C:\Program Files\McAfee\Real Protect\RealProtect.exe [6808224 2017-01-23] (McAfee, Inc.)
HKU\S-1-5-21-3292285495-1262821695-1980909435-1000\...\Run: [MiPhoneManager] => C:\Users\freako\AppData\Local\MiPhoneManager\main\MiPhoneHelper.exe [157624 2016-11-01] ()
HKU\S-1-5-21-3292285495-1262821695-1980909435-1000\...\MountPoints2: {5da897ce-09e1-11e6-b65d-00241dcfff0e} - H:\Startme.exe
GroupPolicy: Restriction <======= ATTENTION
GroupPolicy\User: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{CE61CCA5-434E-4FD9-8BD5-BC25C7144071}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-3292285495-1262821695-1980909435-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKU\S-1-5-21-3292285495-1262821695-1980909435-1000 -> DefaultScope {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = hxxp://go.mail.ru/distib/ep/?q={SearchTerms}&product_id=%7B9BA40AB0-CC1F-46C5-ABDB-E5EAB68A971C%7D&gp=811041
SearchScopes: HKU\S-1-5-21-3292285495-1262821695-1980909435-1000 -> {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = hxxp://go.mail.ru/distib/ep/?q={SearchTerms}&product_id=%7B9BA40AB0-CC1F-46C5-ABDB-E5EAB68A971C%7D&gp=811041
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2013-11-15] (Microsoft Corporation)
BHO: Browsing Protection by F-Secure -> {45BBE08D-81C5-4A67-AF20-B2A077C67747} -> C:\Program Files (x86)\F-Secure\SAFE\apps\CCF_Scanning\bin\browser\install\fs_ie_https\fs_ie_https64.dll [2017-01-02] (F-Secure Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2013-09-13] (Microsoft Corporation)
BHO-x32: Browsing Protection by F-Secure -> {45BBE08D-81C5-4A67-AF20-B2A077C67747} -> C:\Program Files (x86)\F-Secure\SAFE\apps\CCF_Scanning\bin\browser\install\fs_ie_https\fs_ie_https.dll [2017-01-02] (F-Secure Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2015-11-18] (Oracle Corporation)
BHO-x32: iSkysoft iMedia Converter Deluxe 5.1.0 -> {AEAF002F-E6D8-4A21-ABD3-2B309B79A6CE} -> C:\ProgramData\iSkysoft\Video Converter Ultimate\WSBrowserAppMgr.dll [2016-10-25] (Wondershare)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2013-09-13] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2013-11-02] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-11-18] (Oracle Corporation)
Toolbar: HKLM - No Name - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -  No File
Toolbar: HKU\S-1-5-21-3292285495-1262821695-1980909435-1000 -> No Name - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -  No File
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2012-10-01] (Microsoft Corporation)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-14] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-14] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-14] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-14] (Microsoft Corporation)

FireFox:
========
FF ProfilePath: C:\Users\freako\AppData\Roaming\Mozilla\Firefox\Profiles\ulidtilh.freako [2017-01-23]
FF user.js: detected! => C:\Users\freako\AppData\Roaming\Mozilla\Firefox\Profiles\ulidtilh.freako\user.js [2015-08-02]
FF Homepage: Mozilla\Firefox\Profiles\ulidtilh.freako -> chrome://speeddial/content/speeddial.xul
FF Keyword.URL: Mozilla\Firefox\Profiles\ulidtilh.freako ->
FF Extension: (ABV Notifier) - C:\Users\freako\AppData\Roaming\Mozilla\Firefox\Profiles\ulidtilh.freako\Extensions\[email protected] [2016-12-05]
FF Extension: (Roomy Bookmarks Toolbar) - C:\Users\freako\AppData\Roaming\Mozilla\Firefox\Profiles\ulidtilh.freako\Extensions\[email protected] [2017-01-09]
FF Extension: (Bulgarian Dictionary) - C:\Users\freako\AppData\Roaming\Mozilla\Firefox\Profiles\ulidtilh.freako\Extensions\[email protected] [2015-12-21] [not signed]
FF Extension: (Enhancer for YouTube™) - C:\Users\freako\AppData\Roaming\Mozilla\Firefox\Profiles\ulidtilh.freako\Extensions\[email protected] [2016-12-04]
FF Extension: (Xmarks) - C:\Users\freako\AppData\Roaming\Mozilla\Firefox\Profiles\ulidtilh.freako\Extensions\[email protected] [2017-01-21]
FF Extension: (Gmail™ Notifier +) - C:\Users\freako\AppData\Roaming\Mozilla\Firefox\Profiles\ulidtilh.freako\Extensions\[email protected] [2016-12-05]
FF Extension: (The Addon Bar (restored)) - C:\Users\freako\AppData\Roaming\Mozilla\Firefox\Profiles\ulidtilh.freako\Extensions\[email protected] [2016-05-04]
FF Extension: (All-in-One Sidebar) - C:\Users\freako\AppData\Roaming\Mozilla\Firefox\Profiles\ulidtilh.freako\Extensions\{097d3191-e6fa-4728-9826-b533d755359d}.xpi [2016-11-07]
FF Extension: (Autocopy) - C:\Users\freako\AppData\Roaming\Mozilla\Firefox\Profiles\ulidtilh.freako\Extensions\{0FED7D55-65D4-47b6-A6DE-9A4ADB55355F} [2016-04-28]
FF Extension: (FEBE) - C:\Users\freako\AppData\Roaming\Mozilla\Firefox\Profiles\ulidtilh.freako\Extensions\{4BBDD651-70CF-4821-84F8-2B918CF89CA3} [2016-11-13]
FF Extension: (Speed Dial) - C:\Users\freako\AppData\Roaming\Mozilla\Firefox\Profiles\ulidtilh.freako\Extensions\{64161300-e22b-11db-8314-0800200c9a66}.xpi [2015-10-15]
FF Extension: (Video DownloadHelper) - C:\Users\freako\AppData\Roaming\Mozilla\Firefox\Profiles\ulidtilh.freako\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2016-12-30]
FF Extension: (Adblock Plus) - C:\Users\freako\AppData\Roaming\Mozilla\Firefox\Profiles\ulidtilh.freako\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-11-23]
FF Extension: (Tab Mix Plus) - C:\Users\freako\AppData\Roaming\Mozilla\Firefox\Profiles\ulidtilh.freako\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2017-01-12]
FF Extension: (DownThemAll!) - C:\Users\freako\AppData\Roaming\Mozilla\Firefox\Profiles\ulidtilh.freako\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2016-09-29]
FF Extension: (Search by F-Secure) - C:\Program Files (x86)\F-Secure\SAFE\apps\SafeSearch\\Firefox\main.xpi [2016-10-24]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\F-Secure\SAFE\apps\CCF_Scanning\bin\browser\install\fs_firefox_https\fs_firefox_https.xpi
FF Extension: (Browsing Protection by F-Secure) - C:\Program Files (x86)\F-Secure\SAFE\apps\CCF_Scanning\bin\browser\install\fs_firefox_https\fs_firefox_https.xpi [2017-01-02]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\ProgramData\iSkysoft\Video Converter Ultimate\[email protected]_xpi
FF Extension: (iSkysoft iMedia Converter Deluxe) - C:\ProgramData\iSkysoft\Video Converter Ultimate\[email protected]_xpi [2016-11-01]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\F-Secure\SAFE\apps\CCF_Scanning\bin\browser\install\fs_firefox_https\fs_firefox_https.xpi
FF HKU\S-1-5-21-3292285495-1262821695-1980909435-1000\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\F-Secure\SAFE\apps\SafeSearch\\Firefox\main.xpi
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_24_0_0_194.dll [2017-01-10] ()
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_194.dll [2017-01-10] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-11-18] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-11-18] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2013-11-15] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2010-04-03] (NVIDIA Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2013-11-15] (Microsoft Corporation)

Chrome:
=======
CHR HKLM\...\Chrome\Extension: [jmjjnhpacphpjmnnlnccpfmhkcloaade] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [dhhejlifdlcgcmogbggeomfodgklfaem] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [jmjjnhpacphpjmnnlnccpfmhkcloaade] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 Autodata Limited License Service; C:\Program Files (x86)\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe [72704 2015-10-20] (Autodata Limited) [File not signed]
R2 fshoster; C:\Program Files (x86)\F-Secure\SAFE\fshoster32.exe [181216 2016-10-25] (F-Secure Corporation)
R3 FSMA; C:\Program Files (x86)\F-Secure\SAFE\apps\ComputerSecurity\Common\FSMA32.EXE [218080 2016-10-26] (F-Secure Corporation)
R2 fsnethoster; C:\Program Files (x86)\F-Secure\SAFE\fshoster32.exe [181216 2016-10-25] (F-Secure Corporation)
R2 FSORSPClient; C:\Program Files (x86)\F-Secure\SAFE\apps\CCF_Reputation\fsorsp.exe [62432 2016-05-20] (F-Secure Corporation)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed]
R2 LMS; C:\Program Files (x86)\Intel\AMT\LMS.exe [174616 2009-07-21] (Intel Corporation)
R2 MiRalinkRegistryWriter; C:\Program Files (x86)\Xiaomi\MiWiFi\RaRegistry.exe [399600 2016-10-16] (Mediatek Inc.)
R2 MiRalinkRegistryWriter64; C:\Program Files (x86)\Xiaomi\MiWiFi\RaRegistry64.exe [450192 2016-10-16] (Mediatek Inc.)
R2 nlsX86cc; C:\Windows\SysWOW64\nlssrv32.exe [66560 2011-09-22] (Nalpeiron Ltd.) [File not signed]
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2104840 2016-02-09] (Electronic Arts)
R2 StarWindServiceAE; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [File not signed]
R2 UNS; C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe [2066968 2009-07-21] (Intel Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 cmudaxp; C:\Windows\System32\drivers\cmudaxp.sys [2735616 2013-12-11] (C-Media Inc)
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [17480 2013-03-07] () [File not signed]
S3 epmntdrv; C:\Windows\SysWOW64\epmntdrv.sys [14920 2013-03-07] () [File not signed]
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9800 2013-03-07] () [File not signed]
S3 EuGdiDrv; C:\Windows\SysWOW64\EuGdiDrv.sys [9160 2013-03-07] () [File not signed]
R3 F-Secure Gatekeeper; C:\Program Files (x86)\F-Secure\SAFE\apps\ComputerSecurity\Anti-Virus\minifilter\FSgk.sys [229080 2016-12-14] (F-Secure Corporation)
R1 F-Secure HIPS; C:\Program Files (x86)\F-Secure\SAFE\apps\ComputerSecurity\HIPS\drivers\fshs.sys [106712 2016-12-14] (F-Secure Corporation)
R0 fsbts; C:\Windows\System32\Drivers\fsbts.sys [73928 2016-12-10] ()
R3 fsni; C:\Program Files (x86)\F-Secure\SAFE\apps\CCF_Scanning\bin\fsni64.sys [110800 2017-01-02] (F-Secure Corporation)
R1 ntflt; C:\Windows\System32\DRIVERS\ntflt.sys [124144 2016-10-16] (     )
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [503352 2015-10-15] () [File not signed]
U3 a4t2qec3; C:\Windows\System32\Drivers\a4t2qec3.sys [0 ] (Advanced Micro Devices) <==== ATTENTION (zero byte File/Folder)
S3 b06bdrv; \SystemRoot\system32\DRIVERS\bxvbda.sys [X]
S0 ignis; system32\DRIVERS\ignis.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-01-23 21:09 - 2017-01-23 21:09 - 00000000 ____D C:\FRST
2017-01-23 19:36 - 2017-01-23 19:36 - 00000000 ____D C:\Quarantine
2017-01-23 19:27 - 2017-01-23 19:27 - 00000000 ____D C:\Program Files\McAfee
2017-01-23 19:26 - 2017-01-23 21:08 - 00000000 ____D C:\Program Files\stinger
2017-01-23 15:20 - 2017-01-23 15:32 - 00000000 ____D C:\Users\freako\AppData\LocalLow\Unity
2017-01-23 15:20 - 2017-01-23 15:32 - 00000000 ____D C:\Users\freako\AppData\Local\Unity
2017-01-23 15:17 - 2017-01-23 15:32 - 00000000 ____D C:\Users\freako\AppData\Local\Mail.Ru
2017-01-23 15:17 - 2017-01-23 15:17 - 00000000 ____D C:\ProgramData\Mail.Ru
2017-01-23 15:16 - 2017-01-23 15:18 - 00003614 _____ C:\Windows\System32\Tasks\pineapples
2017-01-09 13:52 - 2017-01-23 15:23 - 00000000 ____D C:\Users\freako\AppData\Local\Viber

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-01-23 20:25 - 2016-11-16 18:59 - 00000000 ____D C:\Users\freako\AppData\LocalLow\Mozilla
2017-01-23 20:25 - 2016-04-09 06:12 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2017-01-23 19:26 - 2016-04-01 21:54 - 00000000 ____D C:\AdwCleaner
2017-01-23 18:04 - 2016-11-20 23:23 - 00004966 _____ C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for freako-PC-freako freako-PC
2017-01-23 17:57 - 2009-07-14 06:45 - 00016944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-01-23 17:57 - 2009-07-14 06:45 - 00016944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-01-23 17:56 - 2009-07-14 07:13 - 00861560 _____ C:\Windows\system32\PerfStringBackup.INI
2017-01-23 17:56 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf
2017-01-23 17:51 - 2016-03-29 22:17 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-01-23 17:50 - 2015-10-15 14:59 - 00000000 ____D C:\ProgramData\NVIDIA
2017-01-23 17:49 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-01-23 16:03 - 2015-10-31 14:31 - 00000000 ____D C:\ProgramData\Ashampoo
2017-01-23 16:03 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\Resources
2017-01-23 15:33 - 2015-10-16 07:05 - 00000000 ____D C:\Users\freako\AppData\Roaming\AIMP3
2017-01-23 15:23 - 2016-05-24 19:26 - 00000000 ____D C:\Users\freako\AppData\Roaming\ViberPC
2017-01-23 15:20 - 2016-07-23 14:57 - 00000400 __RSH C:\ProgramData\ntuser.pol
2017-01-23 13:06 - 2016-04-02 22:10 - 00000000 ____D C:\Users\freako\AppData\Roaming\qBittorrent
2017-01-10 15:25 - 2016-04-09 06:12 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-01-10 15:25 - 2015-10-15 20:00 - 00802904 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-01-10 15:25 - 2015-10-15 20:00 - 00144472 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-01-10 15:25 - 2015-10-15 20:00 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-01-10 15:25 - 2015-10-15 20:00 - 00000000 ____D C:\Windows\system32\Macromed
2017-01-09 16:37 - 2016-05-24 19:31 - 00000000 ____D C:\Users\freako\Documents\ViberDownloads
2016-12-24 21:30 - 2016-12-23 19:51 - 00001909 _____ C:\Users\freako\Desktop\Photomatix Essentials 4.0.2 (64-bit).lnk

==================== Files in the root of some directories =======

2015-03-26 13:48 - 2015-03-26 13:48 - 2174976 _____ (Advanced Micro Devices Inc.) C:\Program Files (x86)\Common Files\atimpenc.dll
2015-12-26 17:39 - 2016-03-27 11:23 - 0000132 _____ () C:\Users\freako\AppData\Roaming\Adobe PNG Format CS6 Prefs
2016-10-16 14:34 - 2016-10-16 14:35 - 0000931 _____ () C:\Users\freako\AppData\Roaming\lua_setup_log.txt
2015-12-16 07:33 - 2015-12-16 07:33 - 0407448 _____ () C:\ProgramData\1450243697.bdinstall.bin
2016-02-16 06:58 - 2016-02-16 06:58 - 0025189 _____ () C:\ProgramData\1455598695.bdinstall.bin
2016-03-21 23:19 - 2016-03-21 23:19 - 0025925 _____ () C:\ProgramData\1458595138.bdinstall.bin
2016-03-22 18:05 - 2016-03-22 18:05 - 0025973 _____ () C:\ProgramData\1458662717.bdinstall.bin
2016-03-22 19:05 - 2016-03-22 19:05 - 0025973 _____ () C:\ProgramData\1458666331.bdinstall.bin
2016-04-01 06:09 - 2016-04-01 06:09 - 0025973 _____ () C:\ProgramData\1459483737.bdinstall.bin
2016-06-14 18:12 - 2016-06-14 18:12 - 0026778 _____ () C:\ProgramData\1465920752.bdinstall.bin

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-01-23 07:39

==================== End of FRST.txt ============================

 

Addition.txt

Стъпка 1

Изтеглете файла fixlist и го запазете на вашия десктоп.

  • Стартирайте FRST.exe и натиснете бутона FIX веднъж!
  • Почистването ще започне, не използвайте системата!
  • След като приключи, ако ви поиска рестартиране, съгласете се.
  • След като зареди системата публикувайте лог файла с име fixlog.txt, който се намира на десктопа Ви.

Забележка: Текущия фикс да не се използва на други системи!

 

Стъпка 2

Изтеглете: 8864097u.png ADWCleaner.

  • Затворете всички браузъри и стартирайте AdwCleaner.exe.
  • Натиснете бутона SCAN.
  • След като приключи проверката натиснете бутона CLEAN.
  • Програмата ще затвори излишния софтуер и ще започне почистването.
  • След като приключи почистването ADWCleaner ще поиска рестарт. Съгласете се.
  • След зареждането на системата отидете до: C:\AdwCleaner и потърсете лог файл с името AdwCleaner[C0].txt.
  • Публикувайте съдържанието на "AdwCleaner[C0]" в следващия Ви коментар.

 

Стъпка 3

Изтеглете: 8864098w.png JRT.

  • Запазете файла на вашия десктоп.
  • Затворете всички браузъри.
  • Стартирайте JRT.exe.
  • След като се появи съобщението "Press any key to continue . . .". Натиснете което и да е копче от клавиатурата.
  • Програмата ще започне почистването. Не прекъсвайте работата и, и не използвайте системата докато протича почистването.
  • След като приключи почистването ще се отвори лог файл, който се намира на десктопа с име JRT.txt.
  • Копирайте съдържанието му и го поставете към следващия Ви коментар.

 

Стъпка 4

Изтеглете: 9008931T.png Malwarebytes Anti-Malware.

  • Стартирайте инсталационния файл и следвайте съветника за инсталация.
  • Преди края на инсталацията премахнете отметката от: "Enable free trial of Malwarebytes Anti-Malware Premium" и се уверете че има отметка пред "Launch Malwarebytes Anti-Malware".
  • Отидете до табът Settings => Detection and Protection => сложете отметка на "Scan for rootkits".
  • Отидете до табът Dashboard => натиснете бутона "SCAN NOW".
  • Програмата автоматично ще провери за актуализации и ще започне сканирането.

Забележка: Ако видите съобщението "Could not load DDA driver" натиснете бутона "YES". След което разрешете на системата да се рестартира.

  • След като проверката приключи натиснете бутона "Remove Selected".
  • Системата ще поиска рестарт, съгласете се.
  • След като системата зареди MBAB ще зареди.
  • Отидете до табът History => Applications Logs.
  • Потърсете лог с име "SCAN LOG" с последната дата и час и натиснете върху него.
  • Натиснете бутона EXPORT => Copy to Clipboard.
  • Поставете съдържанието на лога с клавишната комбинация CTRL+V към следващия Ви коментар.

 

Стъпка 5

  • Направете нови логове с FRST и ги прикачете към следващия ви коментар.
  • Автор
Цитат

# AdwCleaner v6.042 - Logfile created 24/01/2017 at 07:16:11
# Updated on 06/01/2017 by Malwarebytes
# Database : 2017-01-23.1 [Local]
# Operating System : Windows 7 Ultimate  (X64)
# Username : freako - FREAKO-PC
# Running from : C:\Users\freako\Desktop\adwcleaner_6.042.exe
# Mode: Clean
# Support : https://www.malwarebytes.com/support

 

***** [ Services ] *****

 

***** [ Folders ] *****

[#] Folder deleted on reboot: C:\Users\freako\AppData\Local\Mail.Ru


***** [ Files ] *****

[-] File deleted: C:\Users\freako\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk
[-] File deleted: C:\Users\freako\Favorites\Mail.Ru.url
[-] File deleted: C:\Users\freako\Favorites\Mail.Ru Агент - используй для общения!.url


***** [ DLL ] *****

 

***** [ WMI ] *****

 

***** [ Shortcuts ] *****

[!] Shortcut not deleted: C:\Users\freako\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk


***** [ Scheduled Tasks ] *****

 

***** [ Registry ] *****

[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{FA7B2795-C0C8-4A58-8672-3F8D80CC0270}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A}
[-] Key deleted: HKLM\SOFTWARE\Classes\TypeLib\{1112F282-7099-4624-A439-DB29D6551552}
[-] Key deleted: HKU\S-1-5-21-3292285495-1262821695-1980909435-1000\Software\Mail.Ru
[-] Key deleted: HKU\S-1-5-21-3292285495-1262821695-1980909435-1000\Software\AppDataLow\Software\Mail.Ru
[#] Key deleted on reboot: HKCU\Software\Mail.Ru
[#] Key deleted on reboot: HKCU\Software\AppDataLow\Software\Mail.Ru
[-] Key deleted: HKLM\SOFTWARE\Mail.Ru
[#] Key deleted on reboot: [x64] HKCU\Software\Mail.Ru
[#] Key deleted on reboot: [x64] HKCU\Software\AppDataLow\Software\Mail.Ru


***** [ Web browsers ] *****

 

*************************

:: "Tracing" keys deleted
:: Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [1950 Bytes] - [24/01/2017 07:16:11]
C:\AdwCleaner\AdwCleaner[S0].txt - [2173 Bytes] - [24/01/2017 07:14:58]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [2096 Bytes] ##########

 

 

Цитат

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.0 (12.05.2016)
Operating System: Windows 7 Ultimate x64
Ran by freako (Administrator) on ўв 24.01.2017 Ј. at  7:19:19,47
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 


File System: 15

Failed to delete: C:\Program Files (x86)\xiaomi (Folder)
Successfully deleted: C:\ProgramData\thunder network (Folder)
Successfully deleted: C:\Users\freako\AppData\Local\crashrpt (Folder)
Successfully deleted: C:\Users\freako\AppData\Roaming\1318 (Folder)
Successfully deleted: C:\Users\freako\AppData\Roaming\xiaomi (Folder)
Successfully deleted: C:\Users\Public\thunder network (Folder)
Successfully deleted: C:\xiaomi (Folder)
Successfully deleted: C:\Users\freako\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\13VMHHGR (Temporary Internet Files Folder)
Successfully deleted: C:\Users\freako\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1NZKPAPO (Temporary Internet Files Folder)
Successfully deleted: C:\Users\freako\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9F2FY0NB (Temporary Internet Files Folder)
Successfully deleted: C:\Users\freako\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VAI34MMR (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\13VMHHGR (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1NZKPAPO (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9F2FY0NB (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VAI34MMR (Temporary Internet Files Folder)

 

Registry: 0

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on ўв 24.01.2017 Ј. at  7:21:17,32
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

 

Цитат

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 24.1.2017 г.
Scan Time: 07:25 ч.
Logfile: mbam log.txt
Administrator: Yes

Version: 2.2.1.1043
Malware Database: v2017.01.24.01
Rootkit Database: v2016.11.20.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7
CPU: x64
File System: NTFS
User: freako

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 295029
Time Elapsed: 15 min, 22 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Deep Rootkit Scan: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)

Цитат

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 22-01-2017
Ran by freako (administrator) on FREAKO-PC (24-01-2017 07:44:41)
Running from C:\Users\freako\Desktop
Loaded Profiles: freako (Available Profiles: freako)
Platform: Windows 7 Ultimate (X64) Language: English (United States)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Autodata Limited) C:\Program Files (x86)\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\SAFE\apps\CCF_Reputation\fsorsp.exe
(Intel Corporation) C:\Program Files (x86)\Intel\AMT\LMS.exe
(Mediatek Inc.) C:\Program Files (x86)\Xiaomi\MiWiFi\RaRegistry.exe
(Mediatek Inc.) C:\Program Files (x86)\Xiaomi\MiWiFi\RaRegistry64.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\nlssrv32.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Intel Corporation) C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\SAFE\apps\ComputerSecurity\Common\FSMA32.EXE
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\SAFE\apps\ComputerSecurity\Common\FSHDLL64.EXE
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\SAFE\fshoster32.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\SAFE\fshoster32.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\SAFE\apps\ComputerSecurity\Anti-Virus\fsgk32.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\SAFE\fshoster32.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\SAFE\apps\ComputerSecurity\Anti-Virus\fssm32.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Cmaudio8788] => C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cmicnfgp.dll,CMICtrlWnd
HKLM\...\Run: [Cmaudio8788GX] => C:\Windows\syswow64\HsMgr.exe [200704 2008-07-11] ()
HKLM\...\Run: [Cmaudio8788GX64] => C:\Windows\system\HsMgr64.exe [282112 2008-07-11] ()
HKLM\...\Run: [picon] => C:\Program Files (x86)\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe [796696 2009-07-21] (Intel Corporation)
HKLM-x32\...\Run: [iSkysoft Helper Compact.exe] => C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe [2138272 2016-10-08] (iSkySoft)
HKLM-x32\...\Run: [DelaypluginInstall] => C:\ProgramData\iSkysoft\Video Converter Ultimate\DelayPluginI.exe [1971872 2016-10-25] ()
HKU\S-1-5-21-3292285495-1262821695-1980909435-1000\...\Run: [MiPhoneManager] => C:\Users\freako\AppData\Local\MiPhoneManager\main\MiPhoneHelper.exe [157624 2016-11-01] ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{CE61CCA5-434E-4FD9-8BD5-BC25C7144071}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-3292285495-1262821695-1980909435-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2013-11-15] (Microsoft Corporation)
BHO: Browsing Protection by F-Secure -> {45BBE08D-81C5-4A67-AF20-B2A077C67747} -> C:\Program Files (x86)\F-Secure\SAFE\apps\CCF_Scanning\bin\browser\install\fs_ie_https\fs_ie_https64.dll [2017-01-02] (F-Secure Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2013-09-13] (Microsoft Corporation)
BHO-x32: Browsing Protection by F-Secure -> {45BBE08D-81C5-4A67-AF20-B2A077C67747} -> C:\Program Files (x86)\F-Secure\SAFE\apps\CCF_Scanning\bin\browser\install\fs_ie_https\fs_ie_https.dll [2017-01-02] (F-Secure Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2015-11-18] (Oracle Corporation)
BHO-x32: iSkysoft iMedia Converter Deluxe 5.1.0 -> {AEAF002F-E6D8-4A21-ABD3-2B309B79A6CE} -> C:\ProgramData\iSkysoft\Video Converter Ultimate\WSBrowserAppMgr.dll [2016-10-25] (Wondershare)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2013-09-13] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2013-11-02] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-11-18] (Oracle Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2012-10-01] (Microsoft Corporation)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-14] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-14] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-14] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-14] (Microsoft Corporation)

FireFox:
========
FF ProfilePath: C:\Users\freako\AppData\Roaming\Mozilla\Firefox\Profiles\ulidtilh.freako [2017-01-24]
FF Homepage: Mozilla\Firefox\Profiles\ulidtilh.freako -> chrome://speeddial/content/speeddial.xul
FF Keyword.URL: Mozilla\Firefox\Profiles\ulidtilh.freako ->
FF Extension: (ABV Notifier) - C:\Users\freako\AppData\Roaming\Mozilla\Firefox\Profiles\ulidtilh.freako\Extensions\[email protected] [2016-12-05]
FF Extension: (Bulgarian Dictionary) - C:\Users\freako\AppData\Roaming\Mozilla\Firefox\Profiles\ulidtilh.freako\Extensions\[email protected] [2015-12-21] [not signed]
FF Extension: (Enhancer for YouTube™) - C:\Users\freako\AppData\Roaming\Mozilla\Firefox\Profiles\ulidtilh.freako\Extensions\[email protected] [2016-12-04]
FF Extension: (Xmarks) - C:\Users\freako\AppData\Roaming\Mozilla\Firefox\Profiles\ulidtilh.freako\Extensions\[email protected] [2017-01-23]
FF Extension: (Gmail™ Notifier +) - C:\Users\freako\AppData\Roaming\Mozilla\Firefox\Profiles\ulidtilh.freako\Extensions\[email protected] [2016-12-05]
FF Extension: (The Addon Bar (restored)) - C:\Users\freako\AppData\Roaming\Mozilla\Firefox\Profiles\ulidtilh.freako\Extensions\[email protected] [2016-05-04]
FF Extension: (All-in-One Sidebar) - C:\Users\freako\AppData\Roaming\Mozilla\Firefox\Profiles\ulidtilh.freako\Extensions\{097d3191-e6fa-4728-9826-b533d755359d}.xpi [2016-11-07]
FF Extension: (Autocopy) - C:\Users\freako\AppData\Roaming\Mozilla\Firefox\Profiles\ulidtilh.freako\Extensions\{0FED7D55-65D4-47b6-A6DE-9A4ADB55355F} [2016-04-28]
FF Extension: (FEBE) - C:\Users\freako\AppData\Roaming\Mozilla\Firefox\Profiles\ulidtilh.freako\Extensions\{4BBDD651-70CF-4821-84F8-2B918CF89CA3} [2016-11-13]
FF Extension: (Speed Dial) - C:\Users\freako\AppData\Roaming\Mozilla\Firefox\Profiles\ulidtilh.freako\Extensions\{64161300-e22b-11db-8314-0800200c9a66}.xpi [2015-10-15]
FF Extension: (Video DownloadHelper) - C:\Users\freako\AppData\Roaming\Mozilla\Firefox\Profiles\ulidtilh.freako\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2016-12-30]
FF Extension: (Adblock Plus) - C:\Users\freako\AppData\Roaming\Mozilla\Firefox\Profiles\ulidtilh.freako\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-11-23]
FF Extension: (Tab Mix Plus) - C:\Users\freako\AppData\Roaming\Mozilla\Firefox\Profiles\ulidtilh.freako\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2017-01-12]
FF Extension: (DownThemAll!) - C:\Users\freako\AppData\Roaming\Mozilla\Firefox\Profiles\ulidtilh.freako\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2016-09-29]
FF Extension: (Search by F-Secure) - C:\Program Files (x86)\F-Secure\SAFE\apps\SafeSearch\\Firefox\main.xpi [2016-10-24]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\F-Secure\SAFE\apps\CCF_Scanning\bin\browser\install\fs_firefox_https\fs_firefox_https.xpi
FF Extension: (Browsing Protection by F-Secure) - C:\Program Files (x86)\F-Secure\SAFE\apps\CCF_Scanning\bin\browser\install\fs_firefox_https\fs_firefox_https.xpi [2017-01-02]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\ProgramData\iSkysoft\Video Converter Ultimate\[email protected]_xpi
FF Extension: (iSkysoft iMedia Converter Deluxe) - C:\ProgramData\iSkysoft\Video Converter Ultimate\[email protected]_xpi [2016-11-01]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\F-Secure\SAFE\apps\CCF_Scanning\bin\browser\install\fs_firefox_https\fs_firefox_https.xpi
FF HKU\S-1-5-21-3292285495-1262821695-1980909435-1000\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\F-Secure\SAFE\apps\SafeSearch\\Firefox\main.xpi
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_24_0_0_194.dll [2017-01-10] ()
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_194.dll [2017-01-10] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-11-18] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-11-18] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2013-11-15] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2010-04-03] (NVIDIA Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2013-11-15] (Microsoft Corporation)

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 Autodata Limited License Service; C:\Program Files (x86)\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe [72704 2015-10-20] (Autodata Limited) [File not signed]
R2 fshoster; C:\Program Files (x86)\F-Secure\SAFE\fshoster32.exe [181216 2016-10-25] (F-Secure Corporation)
R3 FSMA; C:\Program Files (x86)\F-Secure\SAFE\apps\ComputerSecurity\Common\FSMA32.EXE [218080 2016-10-26] (F-Secure Corporation)
R2 fsnethoster; C:\Program Files (x86)\F-Secure\SAFE\fshoster32.exe [181216 2016-10-25] (F-Secure Corporation)
R2 FSORSPClient; C:\Program Files (x86)\F-Secure\SAFE\apps\CCF_Reputation\fsorsp.exe [62432 2016-05-20] (F-Secure Corporation)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed]
R2 LMS; C:\Program Files (x86)\Intel\AMT\LMS.exe [174616 2009-07-21] (Intel Corporation)
R2 MiRalinkRegistryWriter; C:\Program Files (x86)\Xiaomi\MiWiFi\RaRegistry.exe [399600 2016-10-16] (Mediatek Inc.)
R2 MiRalinkRegistryWriter64; C:\Program Files (x86)\Xiaomi\MiWiFi\RaRegistry64.exe [450192 2016-10-16] (Mediatek Inc.)
R2 nlsX86cc; C:\Windows\SysWOW64\nlssrv32.exe [66560 2011-09-22] (Nalpeiron Ltd.) [File not signed]
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2104840 2016-02-09] (Electronic Arts)
R2 UNS; C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe [2066968 2009-07-21] (Intel Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 cmudaxp; C:\Windows\System32\drivers\cmudaxp.sys [2735616 2013-12-11] (C-Media Inc)
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [17480 2013-03-07] () [File not signed]
S3 epmntdrv; C:\Windows\SysWOW64\epmntdrv.sys [14920 2013-03-07] () [File not signed]
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9800 2013-03-07] () [File not signed]
S3 EuGdiDrv; C:\Windows\SysWOW64\EuGdiDrv.sys [9160 2013-03-07] () [File not signed]
R3 F-Secure Gatekeeper; C:\Program Files (x86)\F-Secure\SAFE\apps\ComputerSecurity\Anti-Virus\minifilter\FSgk.sys [229080 2016-12-14] (F-Secure Corporation)
R1 F-Secure HIPS; C:\Program Files (x86)\F-Secure\SAFE\apps\ComputerSecurity\HIPS\drivers\fshs.sys [106712 2016-12-14] (F-Secure Corporation)
R0 fsbts; C:\Windows\System32\Drivers\fsbts.sys [73928 2016-12-10] ()
R3 fsni; C:\Program Files (x86)\F-Secure\SAFE\apps\CCF_Scanning\bin\fsni64.sys [110800 2017-01-02] (F-Secure Corporation)
R1 ntflt; C:\Windows\System32\DRIVERS\ntflt.sys [124144 2016-10-16] (     )
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [503352 2015-10-15] () [File not signed]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-01-24 07:44 - 2017-01-24 07:45 - 00014949 _____ C:\Users\freako\Desktop\FRST.txt
2017-01-24 07:41 - 2017-01-24 07:43 - 00001074 _____ C:\Users\freako\Desktop\mbam log.txt
2017-01-24 07:21 - 2017-01-24 07:21 - 00002325 _____ C:\Users\freako\Desktop\JRT.txt
2017-01-24 07:18 - 2017-01-24 07:18 - 00004320 _____ C:\Users\freako\Desktop\AdwCleaner[C0].txt
2017-01-24 07:13 - 2017-01-24 07:16 - 00000000 ____D C:\AdwCleaner
2017-01-24 07:12 - 2017-01-24 07:12 - 01663040 _____ (Malwarebytes) C:\Users\freako\Desktop\JRT.exe
2017-01-24 07:11 - 2017-01-24 07:11 - 03988944 _____ C:\Users\freako\Desktop\adwcleaner_6.042.exe
2017-01-23 22:08 - 2017-01-23 22:08 - 00000000 ____D C:\Windows\pss
2017-01-23 21:24 - 2017-01-23 22:25 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2017-01-23 21:24 - 2017-01-23 22:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
2017-01-23 21:24 - 2017-01-23 22:04 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy
2017-01-23 21:24 - 2017-01-23 21:24 - 00001262 _____ C:\Users\freako\Desktop\Spybot - Search & Destroy.lnk
2017-01-23 21:09 - 2017-01-24 07:44 - 00000000 ____D C:\FRST
2017-01-23 21:08 - 2017-01-23 21:08 - 02420736 _____ (Farbar) C:\Users\freako\Desktop\FRST64.exe
2017-01-23 15:20 - 2017-01-23 15:32 - 00000000 ____D C:\Users\freako\AppData\LocalLow\Unity
2017-01-23 15:20 - 2017-01-23 15:32 - 00000000 ____D C:\Users\freako\AppData\Local\Unity
2017-01-23 15:17 - 2017-01-23 22:04 - 00000000 ____D C:\Users\freako\AppData\Local\Mail.Ru
2017-01-23 15:16 - 2017-01-23 15:18 - 00003614 _____ C:\Windows\System32\Tasks\pineapples
2017-01-09 13:52 - 2017-01-23 15:23 - 00000000 ____D C:\Users\freako\AppData\Local\Viber

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-01-24 07:42 - 2016-03-29 22:17 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-01-24 07:41 - 2016-11-16 18:59 - 00000000 ____D C:\Users\freako\AppData\LocalLow\Mozilla
2017-01-24 07:25 - 2016-04-09 06:12 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2017-01-24 07:24 - 2009-07-14 06:45 - 00016944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-01-24 07:24 - 2009-07-14 06:45 - 00016944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-01-24 07:21 - 2009-07-14 07:13 - 00861560 _____ C:\Windows\system32\PerfStringBackup.INI
2017-01-24 07:21 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf
2017-01-24 07:20 - 2015-10-16 06:30 - 00000000 ____D C:\Program Files (x86)\Xiaomi
2017-01-24 07:18 - 2016-11-20 23:23 - 00004966 _____ C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for freako-PC-freako freako-PC
2017-01-24 07:17 - 2015-10-15 14:59 - 00000000 ____D C:\ProgramData\NVIDIA
2017-01-24 07:17 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-01-24 07:08 - 2016-07-23 14:57 - 00000008 __RSH C:\ProgramData\ntuser.pol
2017-01-24 07:06 - 2009-07-14 05:20 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2017-01-24 07:06 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\GroupPolicy
2017-01-23 22:04 - 2016-05-24 19:26 - 00000000 ____D C:\Users\freako\AppData\Roaming\ViberPC
2017-01-23 22:04 - 2016-04-02 22:10 - 00000000 ____D C:\Users\freako\AppData\Roaming\qBittorrent
2017-01-23 22:04 - 2015-10-16 21:24 - 00000000 ____D C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2017-01-23 22:04 - 2015-10-15 14:05 - 00000000 ____D C:\Users\freako
2017-01-23 22:04 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration
2017-01-23 17:49 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\Resources
2017-01-23 16:03 - 2015-10-31 14:31 - 00000000 ____D C:\ProgramData\Ashampoo
2017-01-23 15:33 - 2015-10-16 07:05 - 00000000 ____D C:\Users\freako\AppData\Roaming\AIMP3
2017-01-10 15:25 - 2016-04-09 06:12 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-01-10 15:25 - 2015-10-15 20:00 - 00802904 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-01-10 15:25 - 2015-10-15 20:00 - 00144472 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-01-10 15:25 - 2015-10-15 20:00 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-01-10 15:25 - 2015-10-15 20:00 - 00000000 ____D C:\Windows\system32\Macromed
2017-01-09 16:37 - 2016-05-24 19:31 - 00000000 ____D C:\Users\freako\Documents\ViberDownloads

==================== Files in the root of some directories =======

2015-03-26 13:48 - 2015-03-26 13:48 - 2174976 _____ (Advanced Micro Devices Inc.) C:\Program Files (x86)\Common Files\atimpenc.dll
2015-12-26 17:39 - 2016-03-27 11:23 - 0000132 _____ () C:\Users\freako\AppData\Roaming\Adobe PNG Format CS6 Prefs
2016-10-16 14:34 - 2016-10-16 14:35 - 0000931 _____ () C:\Users\freako\AppData\Roaming\lua_setup_log.txt

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-01-23 07:39

==================== End of FRST.txt ============================

 

Пак рипат попъпи

EDIT: В настройките на ФФ за попъпи имащше добавен adfly като разрешено. Махнах го, пък ще видим

Addition.txt

Редактирано от freako (преглед на промените)

Не виждам Стъпка 1 да е изпълнена? Изпълнена ли е или сте пропуснали да качите файла?!?!?!?! Много е важно да следвате всичко последователно, не както ви падне!

  • Автор

Изпълнена е тя стъпката ама изтрих лога :(

На своя отговорност махнах СитемРестор, рефрешнах ФФ, пуснах ЗеманаАнтималуер с лог:

Zemana AntiMalware 2.70.189.576 (Portable)

-------------------------------------------------------
Scan Result            : Completed
Scan Date              : 2017.1.24
Operating System       : Windows 7 64-bit
Processor              : 2X Intel(R) Core(TM)2 Duo CPU   E7500 @ 2.93GHz
BIOS Mode              : Legacy
CUID                   : 1207C17E7497710487E743
Scan Type              : System Scan
Duration               : 8m 34s
Scanned Objects        : 45779
Detected Objects       : 2
Excluded Objects       : 0
Read Level             : SCSI
Auto Upload            : Enabled
Detect All Extensions  : Disabled
Scan Documents         : Disabled
Domain Info            : WORKGROUP,0,2

Detected Objects
-------------------------------------------------------

mail.ru
Status             : Scanned
Object             : NE->c:\users\freako\appdata\local\mail.ru
MD5                : -
Publisher          : -
Size               : -
Version            : -
Detection          : PUA:Win32/Mail.Ru.C!Neng
Cleaning Action    : Quarantine
Related Objects    :
                (null) - (null)

pineapples
Status             : Scanned
Object             : NE->c:\windows\system32\tasks\pineapples
MD5                : -
Publisher          : -
Size               : -
Version            : -
Detection          : Adware:Win32/FF.TASKSCHD.GEN.A!Neng
Cleaning Action    : Quarantine
Related Objects    :
                (null) - (null)


Cleaning Result
-------------------------------------------------------
Cleaned               : 2
Reported as safe      : 0
Failed                : 0


 

и ХитманПро:


HitmanPro 3.7.15.281
www.hitmanpro.com

	   Computer name . . . . : FREAKO-PC
   Windows . . . . . . . : 6.1.0.7600.X64/2
   User name . . . . . . : freako-PC\freako
   UAC . . . . . . . . . : Disabled
   License . . . . . . . : Trial (30 days left)
	   Scan date . . . . . . : 2017-01-24 10:20:20
   Scan mode . . . . . . : Normal
   Scan duration . . . . : 4m 7s
   Disk access mode  . . : Direct disk access (SRB)
   Cloud . . . . . . . . : Internet
   Reboot  . . . . . . . : Yes
	   Threats . . . . . . . : 0
   Traces  . . . . . . . : 3
	   Objects scanned . . . : 1 357 938
   Files scanned . . . . : 96 370
   Remnants scanned  . . : 381 443 files / 880 125 keys
	Miniport ____________________________________________________________________
	   Primary
      DriverObject . . . : FFFFFA800451F540
      DriverName . . . . : \Driver\atapi
      DriverPath . . . . : \SystemRoot\system32\DRIVERS\atapi.sys
      StartIo  . . . . . : 0000000000000000 +0
      IRP_MJ_SCSI  . . . : FFFFFA8003BEA2C0 +0
   Solution
      DriverObject . . . : FFFFFA800451F540
      DriverName . . . . : \Driver\atapi
      DriverPath . . . . : \SystemRoot\system32\DRIVERS\atapi.sys
      StartIo  . . . . . : 0000000000000000 +0
      IRP_MJ_SCSI  . . . : FFFFF88000DDB4D8 \SystemRoot\system32\DRIVERS\ataport.SYS+29912
	Suspicious files ____________________________________________________________
	   C:\Users\freako\Desktop\FRST64.exe
      Size . . . . . . . : 2 420 736 bytes
      Age  . . . . . . . : 0.1 days (2017-01-24 07:01:39)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 945C56ADCD33C43D4D6954E99B4427C92C0528C797B08783CD9BE3E9D95A5299
      Needs elevation  . : Yes
      Fuzzy  . . . . . . : 24.0
         Program has no publisher information but prompts the user for permission elevation.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Time indicates that the file appeared recently on this computer.
	
Potential Unwanted Programs _________________________________________________
	   HKLM\SOFTWARE\Classes\TypeLib\{DA624F8F-98BF-4B03-AD11-A12D07119E81}\ (Baidu) -> Deleted
   HKLM\SOFTWARE\Classes\Wow6432Node\TypeLib\{DA624F8F-98BF-4B03-AD11-A12D07119E81}\ (Baidu) -> PendingDelete


и да чукна на дърво половин час вече нищо не изкача

Редактирано от freako (преглед на промените)

ЗА КВО СИ ПУСНАЛ ТЕМАТА след като не следваш елементарни стъпки и правиш неща за които не си инструктиран!  ТЕМАТА СЕ ЗАКЛЮЧВА. А моя съвет към автора на темата е да прочете правилата на този раздел!

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.