Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Слаба интернет връзка(вирус?)

Featured Replies

Напоследък интернетът ми е доста зле на този лаптоп(wi-fi).Това,което забелязах е че при свърването към мрежи са по-малко доста често отколкото реално са.

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 23-04-2017 01
Ran by vilian (administrator) on VILI (23-04-2017 20:45:59)
Running from C:\Users\vilian\Desktop
Loaded Profiles: vilian (Available Profiles: vilian)
Platform: Windows 8.1 Pro (Update) (X64) Language: Английски (Съединени щати)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe
() C:\Program Files (x86)\Garena Plus\ggdllhost.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Hi-Rez Studios) C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
() C:\Program Files (x86)\Garena Plus\ggdllhost.exe
(Copyright (c) 2017 Plays.tv, LLC) C:\Program Files (x86)\Raptr Inc\PlaysTV\plays_service.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Lenovo) C:\Users\vilian\AppData\Local\Apps\2.0\7PYEQKEN.YXO\MZM4YECQ.Q71\lsb...tion_2d7b41b05b24775e_0001.0006_3b0a905c8de4f74a\LSB.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Qualcomm®Atheros®) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
() C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(© 2015 Microsoft Corporation) C:\Users\vilian\AppData\Local\Microsoft\BingSvc\BingSvc.exe
(Corsair Components, Inc.) C:\Program Files (x86)\Corsair\Corsair Gaming Headset Software\HeadsetControlPanel.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Raptr, Inc) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe
(Raptr, Inc) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe
(Raptr Inc.) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_ep64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Hammer & Chisel, Inc.) C:\Users\vilian\AppData\Local\Discord\app-0.0.297\Discord.exe
(Hammer & Chisel, Inc.) C:\Users\vilian\AppData\Local\Discord\app-0.0.297\Discord.exe
(Hammer & Chisel, Inc.) C:\Users\vilian\AppData\Local\Discord\app-0.0.297\Discord.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Clementine) C:\Program Files (x86)\Clementine\clementine.exe
() C:\Program Files (x86)\Clementine\clementine-tagreader.exe
() C:\Program Files (x86)\Clementine\clementine-tagreader.exe
() C:\Program Files (x86)\Clementine\clementine-tagreader.exe
() C:\Program Files (x86)\Clementine\clementine-tagreader.exe
() C:\Program Files (x86)\Clementine\clementine-tagreader.exe
() C:\Program Files (x86)\Clementine\clementine-tagreader.exe
() C:\Program Files (x86)\Clementine\clementine-tagreader.exe
() C:\Program Files (x86)\Clementine\clementine-tagreader.exe
(HI-REZ STUDIOS, INC.) C:\Program Files (x86)\Hi-Rez Studios\SteamLauncherUI.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [161728 2015-11-12] (IvoSoft)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [193008 2016-03-26] (Lenovo(beijing) Limited)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [903384 2013-07-24] (Conexant Systems, Inc.)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17111056 2016-03-26] (Lenovo (Beijing) Limited)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-01-07] (Adobe Systems Incorporated)
HKLM\...\Run: [RtsFT] => C:\Windows\RTFTrack.exe [5459456 2016-11-29] (Realtek semiconductor)
HKLM-x32\...\Run: [PlaysTV] => C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv_launcher.exe [51928 2017-02-16] (Copyright (c) 2017 Plays.tv, LLC)
HKLM-x32\...\Run: [Corsair Gaming Headset Software] => C:\Program Files (x86)\Corsair\Corsair Gaming Headset Software\HeadsetControlPanel.exe [2916160 2015-09-21] (Corsair Components, Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-12-12] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [132736 2013-09-07] (Qualcomm®Atheros®)
HKU\S-1-5-21-796519841-2226784028-2922330728-1001\...\Run: [Google Update] => C:\Users\vilian\AppData\Local\Google\Update\1.3.33.3\GoogleUpdateCore.exe [599632 2017-04-11] (Google Inc.)
HKU\S-1-5-21-796519841-2226784028-2922330728-1001\...\Run: [BingSvc] => C:\Users\vilian\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-05] (© 2015 Microsoft Corporation)
HKU\S-1-5-21-796519841-2226784028-2922330728-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9292504 2016-12-21] (Piriform Ltd)
HKU\S-1-5-21-796519841-2226784028-2922330728-1001\...\Run: [Discord] => C:\Users\vilian\AppData\Local\Discord\app-0.0.297\Discord.exe [64290304 2017-01-04] (Hammer & Chisel, Inc.)
HKU\S-1-5-21-796519841-2226784028-2922330728-1001\...\Run: [GalaxyClient] => C:\Program Files (x86)\GOG Galaxy\GalaxyClient.exe [4006464 2017-01-31] (GOG.com)
HKU\S-1-5-21-796519841-2226784028-2922330728-1001\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
HKU\S-1-5-21-796519841-2226784028-2922330728-1001\...\MountPoints2: {09234235-3601-11e6-826a-18cf5e626a7b} - "F:\Lenovo_Suite.exe"
ShellIconOverlayIdentifiers: [.QMDeskTopGCIcon] -> {B7667919-3765-4815-A66D-98A09BE662D6} =>  -> No File
ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2015-11-12] (IvoSoft)
ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll [2015-11-12] (IvoSoft)
Startup: C:\Users\vilian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AMD Gaming Evolved.lnk [2017-01-31]
ShortcutTarget: AMD Gaming Evolved.lnk -> C:\Program Files (x86)\Raptr Inc\Raptr\raptrstub.exe (Raptr, Inc)
GroupPolicy: Restriction - Windows Defender <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 62.221.132.211 85.130.60.11
Tcpip\..\Interfaces\{42F6DBFA-84CD-4346-AEE6-37083B624FBE}: [DhcpNameServer] 62.221.132.211 85.130.60.11
Tcpip\..\Interfaces\{51D76FB0-809C-4578-B99A-844385208107}: [DhcpNameServer] 172.16.245.1

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKU\S-1-5-21-796519841-2226784028-2922330728-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://pandasecurity.mystart.com/?pr=vmn&id=pandasecuritytb&v=4_3&utm_campaign=675&idate=2017-04-23&ent=hp_675&u=57CFD93241DAED43EF6B6858FCB5169A
HKU\S-1-5-21-796519841-2226784028-2922330728-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
SearchScopes: HKU\S-1-5-21-796519841-2226784028-2922330728-1001 -> DefaultScope {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = hxxp://pandasecurity.mystart.com/results.php?pr=vmn&gen=ms&id=pandasecuritytb&v=4_3&idate=2017-04-23&ent=ch_675&q={searchTerms}
SearchScopes: HKU\S-1-5-21-796519841-2226784028-2922330728-1001 -> {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = hxxp://pandasecurity.mystart.com/results.php?pr=vmn&gen=ms&id=pandasecuritytb&v=4_3&idate=2017-04-23&ent=ch_675&q={searchTerms}
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll => No File
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2015-11-12] (IvoSoft)
BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-05-27] (Adobe Systems Incorporated)
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2015-11-12] (IvoSoft)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-05-27] (Adobe Systems Incorporated)
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2015-11-12] (IvoSoft)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-02-01] (Oracle Corporation)
BHO-x32: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-05-27] (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-02-01] (Oracle Corporation)
BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2015-11-12] (IvoSoft)
BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-05-27] (Adobe Systems Incorporated)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-05-27] (Adobe Systems Incorporated)
Toolbar: HKU\S-1-5-21-796519841-2226784028-2922330728-1001 -> Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-05-27] (Adobe Systems Incorporated)
Handler: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation)

FireFox:
========
FF DefaultProfile: q65lkn3u.default
FF ProfilePath: C:\Users\vilian\AppData\Roaming\Mozilla\Firefox\Profiles\q65lkn3u.default [2017-04-23]
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\q65lkn3u.default -> Search The Web
FF Homepage: Mozilla\Firefox\Profiles\q65lkn3u.default -> hxxp://pandasecurity.mystart.com/?pr=vmn&id=pandasecuritytb&v=4_3&utm_campaign=675&idate=2017-04-23&ent=hp_675&u=57CFD93241DAED43EF6B6858FCB5169A
FF Extension: (AdBlocker Ultimate) - C:\Users\vilian\AppData\Roaming\Mozilla\Firefox\Profiles\q65lkn3u.default\Extensions\[email protected] [2017-02-01]
FF Extension: (Panda Security Toolbar) - C:\Users\vilian\AppData\Roaming\Mozilla\Firefox\Profiles\q65lkn3u.default\Extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}.xpi [2017-04-23]
FF Extension: (Disable TLS Certificate Transparency) - C:\Users\vilian\AppData\Roaming\Mozilla\Firefox\Profiles\q65lkn3u.default\features\{3553b7be-0691-4508-84ab-6b7f4ff27452}\[email protected] [2017-04-18]
FF Extension: (Disable Prefetch) - C:\Users\vilian\AppData\Roaming\Mozilla\Firefox\Profiles\q65lkn3u.default\features\{3553b7be-0691-4508-84ab-6b7f4ff27452}\[email protected] [2017-04-18]
FF Extension: (Site Deployment Checker) - C:\Program Files (x86)\Mozilla Firefox\browser\features\[email protected] [2017-03-29] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn
FF Extension: (Adobe Acrobat DC - Create PDF) - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn [2017-01-04]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_25_0_0_148.dll [2017-04-11] ()
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-07-29] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_148.dll [2017-04-11] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-08-08] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-08-08] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-02-01] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-02-01] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-07-31] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation)
FF Plugin-x32: @t.garena.com/garenatalk -> C:\Program Files (x86)\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll [2016-09-23] ( Garena)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll [2017-04-11] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll [2017-04-11] (Google Inc.)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2016-05-27] (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-05] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-07-29] (Adobe Systems)
FF Plugin HKU\S-1-5-21-796519841-2226784028-2922330728-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\vilian\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-796519841-2226784028-2922330728-1001: @talk.google.com/O1DPlugin -> C:\Users\vilian\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-796519841-2226784028-2922330728-1001: @tools.google.com/Google Update;version=3 -> C:\Users\vilian\AppData\Local\Google\Update\1.3.33.3\npGoogleUpdate3.dll [2017-04-11] (Google Inc.)
FF Plugin HKU\S-1-5-21-796519841-2226784028-2922330728-1001: @tools.google.com/Google Update;version=9 -> C:\Users\vilian\AppData\Local\Google\Update\1.3.33.3\npGoogleUpdate3.dll [2017-04-11] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-07-31] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2017-04-05] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\vilian\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\vilian\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-12-08] (Google)

Chrome:
=======
CHR Profile: C:\Users\vilian\AppData\Local\Google\Chrome\User Data\Default [2017-04-13]
CHR Extension: (Google Slides) - C:\Users\vilian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-02-10]
CHR Extension: (Google Docs) - C:\Users\vilian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-02-10]
CHR Extension: (Google Drive) - C:\Users\vilian\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-02-10]
CHR Extension: (YouTube) - C:\Users\vilian\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-02-10]
CHR Extension: (Adobe Acrobat) - C:\Users\vilian\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-09]
CHR Extension: (Google Sheets) - C:\Users\vilian\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-02-10]
CHR Extension: (Google Docs Offline) - C:\Users\vilian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-03-09]
CHR Extension: (Skype) - C:\Users\vilian\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2017-03-09]
CHR Extension: (Chrome Web Store Payments) - C:\Users\vilian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-09]
CHR Extension: (Gmail) - C:\Users\vilian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-02-10]
CHR Extension: (Chrome Media Router) - C:\Users\vilian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-04-13]
CHR HKLM\...\Chrome\Extension: [fagakgcelolinfnkfgekcnedpaklfcok] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [fagakgcelolinfnkfgekcnedpaklfcok] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2227312 2017-02-27] (Adobe Systems, Incorporated)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-08-05] (Apple Inc.)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [312448 2013-09-07] (Windows (R) Win 7 DDK provider) [File not signed]
S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [395536 2017-01-12] (EasyAntiCheat Ltd)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2836296 2016-12-14] (ESET)
S3 ESRV_SVC_WILLAMETTE; C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe [416408 2016-03-09] ()
S3 GalaxyClientService; C:\Program Files (x86)\GOG Galaxy\GalaxyClientService.exe [284736 2017-01-31] (GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6625856 2017-01-31] (GOG.com)
R2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9728 2017-03-28] (Hi-Rez Studios) [File not signed]
S4 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [630048 2016-10-13] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [196200 2016-12-19] (Intel Corporation)
S2 panda_url_filtering; C:\Program Files\Panda Security URL Filtering\Panda_URL_Filteringb.exe [287752 2015-11-06] (Visicom Media Inc.)
R2 PlaysService; C:\Program Files (x86)\Raptr Inc\PlaysTV\plays_service.exe [55000 2017-02-16] (Copyright (c) 2017 Plays.tv, LLC)
S3 SystemUsageReportSvc_WILLAMETTE; C:\Program Files (x86)\Intel Driver Update Utility\SUR\SurSvc.exe [118424 2016-03-09] ()
S3 USER_ESRV_SVC_WILLAMETTE; C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe [416408 2016-03-09] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-04-21] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-04-21] (Microsoft Corporation)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2013-09-07] (Atheros) [File not signed]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [79120 2016-03-03] (Advanced Micro Devices, Inc.)
R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [4297216 2016-04-09] (Qualcomm Atheros Communications, Inc.)
R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-09-07] (Qualcomm Atheros)
R3 CorsairAudioFilter; C:\Windows\system32\DRIVERS\corsveng2kamd64.sys [112808 2015-09-21] (Corsair Components, Inc.)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [132272 2017-01-17] (ESET)
R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [106768 2017-01-17] (ESET)
S0 eelam; C:\Windows\System32\DRIVERS\eelam.sys [15488 2017-01-17] (ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [180544 2017-01-17] (ESET)
R2 ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [49672 2017-01-17] (ESET)
R1 epfw; C:\Windows\system32\DRIVERS\epfw.sys [77616 2017-01-17] (ESET)
R1 epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [96856 2017-01-17] (ESET)
S3 ExterminateIt; C:\Windows\SysWOW64\drivers\extit.sys [39936 2016-03-26] (CurioLab S.M.B.A.) [File not signed]
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-04-02] (REALiX(tm))
R2 memudrv; D:\Program Files\Microvirt\MEmuHyperv\MEmuDrv.sys [260328 2016-01-16] (Microvirt Corporation)
R2 npf; C:\Windows\System32\drivers\npf.sys [36600 2014-08-19] (Riverbed Technology, Inc.)
S3 panda_url_filteringd; C:\Program Files\Panda Security URL Filtering\panda_url_filteringd.sys [51288 2014-03-19] (Visicom Media Inc.)
S3 RTSUER; C:\Windows\system32\Drivers\RtsUer.sys [413912 2016-04-09] (Realsil Semiconductor Corporation)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [3222016 2016-11-29] (Realtek Semiconductor Corp.)
S3 semav6msr64; C:\Windows\system32\drivers\semav6msr64.sys [21984 2016-03-09] ()
S3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33960 2016-04-02] (Synaptics Incorporated)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44024 2015-04-21] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [264000 2015-04-21] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-04-21] (Microsoft Corporation)
S3 WinRing0_1_2_0; C:\Users\vilian\Desktop\RealTemp_370\WinRing0x64.sys [14544 2008-07-26] (OpenLibSys.org)
R3 XSplit_Dummy; C:\Windows\system32\drivers\xspltspk.sys [26200 2015-05-25] (SplitmediaLabs Limited)
S3 cpuz138; \??\C:\Users\vilian\AppData\Local\Temp\cpuz138\cpuz138_x64.sys [X] <==== ATTENTION
S3 DrvAgent64; \??\C:\Windows\SysWOW64\Drivers\DrvAgent64.SYS [X]
S3 GGSAFERDriver; \??\C:\Program Files (x86)\Garena Plus\Room\safedrv.sys [X]
S3 gkernel; \??\C:\Users\vilian\AppData\Local\Temp\gkernel.sys [X] <==== ATTENTION
S3 iobit_monitor_server; \??\C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\drivers\Monitor_x64.sys [X]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-04-23 20:45 - 2017-04-23 20:46 - 00026541 _____ C:\Users\vilian\Desktop\FRST.txt
2017-04-23 20:45 - 2017-04-23 20:45 - 02426368 _____ (Farbar) C:\Users\vilian\Desktop\FRST64.exe
2017-04-23 20:45 - 2017-04-23 20:45 - 00000000 ____D C:\FRST
2017-04-23 20:10 - 2017-04-23 20:10 - 00000070 _____ C:\Windows\RAVTC.TMP
2017-04-23 17:08 - 2017-04-23 17:08 - 00000000 ____D C:\ProgramData\panda_url_filtering
2017-04-23 17:08 - 2017-04-23 17:08 - 00000000 ____D C:\Program Files\Panda Security URL Filtering
2017-04-23 17:07 - 2017-04-23 20:10 - 00000000 ____D C:\Users\vilian\AppData\Roaming\Panda Security
2017-04-23 17:07 - 2017-04-23 20:06 - 00000000 ____D C:\Program Files (x86)\pandasecuritytb
2017-04-23 17:07 - 2017-04-23 17:07 - 00000000 ____D C:\Users\vilian\AppData\Roaming\Search The Web
2017-04-23 17:07 - 2017-04-23 17:07 - 00000000 ____D C:\Users\vilian\AppData\LocalLow\pandasecuritytb
2017-04-23 17:06 - 2017-04-23 20:10 - 00000000 ____D C:\Program Files (x86)\Panda Security
2017-04-23 17:04 - 2017-04-23 20:10 - 00000000 ____D C:\ProgramData\Panda Security
2017-04-23 16:05 - 2017-04-23 20:08 - 00000000 ____D C:\ProgramData\Norton
2017-04-23 16:04 - 2017-04-23 16:04 - 00000000 ____D C:\ProgramData\NortonInstaller
2017-04-21 13:39 - 2017-04-21 13:45 - 00000000 ____D C:\Users\vilian\Desktop\Протоколи Цеко
2017-04-19 19:24 - 2017-04-19 19:25 - 00000000 ____D C:\ProgramData\Atheros
2017-04-19 19:24 - 2017-04-19 19:24 - 00000000 ____D C:\Users\vilian\AppData\Roaming\Atheros
2017-04-19 19:15 - 2017-04-19 19:15 - 00003646 _____ C:\Windows\System32\Tasks\Intel PTT EK Recertification
2017-04-19 19:13 - 2017-04-19 19:13 - 00000000 ____D C:\ProgramData\Dell
2017-04-19 19:13 - 2017-04-19 19:13 - 00000000 ____D C:\ProgramData\2e8c1871-4c4c-483d-a166-75c815962f12
2017-04-19 19:12 - 2017-04-19 19:13 - 111353264 _____ (Dell Inc.) C:\Users\vilian\Downloads\Chipset_Driver_RNXGY_WN32_11.6.0.1047_A01.EXE
2017-04-19 19:11 - 2017-04-19 19:11 - 01526176 _____ (Lenovo Group Limited ) C:\Users\vilian\Downloads\wwet030e.exe
2017-04-19 19:09 - 2017-04-19 19:09 - 02719982 _____ C:\Users\vilian\Downloads\mb_driver_chipset_intel_thin-itx_tn.zip
2017-04-19 19:08 - 2017-04-19 19:09 - 02701590 _____ C:\Users\vilian\Downloads\FPC48-2167-01_Chipset__28.7z
2017-04-19 19:06 - 2017-04-19 19:06 - 02740289 _____ C:\Users\vilian\Downloads\chipset_v1.0_Intel.zip
2017-04-19 18:59 - 2017-04-19 19:01 - 69983011 _____ C:\Users\vilian\Downloads\Wireless LAN_Atheros_10.0.0.345_W10x64_A.zip
2017-04-19 18:58 - 2017-04-19 19:01 - 62070765 _____ C:\Users\vilian\Downloads\lan_k_2.1.0.26.zip
2017-04-19 18:57 - 2017-04-19 19:03 - 242483187 _____ (Lenovo Group Limited ) C:\Users\vilian\Downloads\j3a205ww.exe.part
2017-04-19 18:57 - 2017-04-19 19:00 - 95496832 _____ (Lenovo Group Limited ) C:\Users\vilian\Downloads\83r502af.exe
2017-04-19 18:56 - 2017-04-19 19:03 - 292415684 _____ (Lenovo Group Limited ) C:\Users\vilian\Downloads\jeac11ww.exe.part
2017-04-19 18:54 - 2016-11-29 02:25 - 05459456 _____ (Realtek semiconductor) C:\Windows\RTFTrack.exe
2017-04-19 18:54 - 2016-11-29 02:25 - 03222016 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\rtsuvc.sys
2017-04-19 18:54 - 2016-11-29 02:25 - 01981952 _____ (Realtek Semiconductor Corp.) C:\Windows\SysWOW64\RsDecode.dll
2017-04-19 18:54 - 2016-11-29 02:25 - 00646656 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtCamP64.dll
2017-04-19 18:54 - 2016-11-29 02:25 - 00561664 _____ (Realtek Semiconductor Corp.) C:\Windows\SysWOW64\RtCamP.dll
2017-04-19 18:54 - 2016-11-29 02:25 - 00104448 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtCamO64.dll
2017-04-19 18:53 - 2017-04-19 18:53 - 14388176 _____ (Hewlett-Packard Company ) C:\Users\vilian\Downloads\sp77413.exe
2017-04-19 18:53 - 2017-04-19 18:53 - 05437272 _____ ( ) C:\Users\vilian\Downloads\atc001af.exe
2017-04-19 18:53 - 2017-04-19 18:53 - 00000000 ____D C:\swsetup
2017-04-19 18:43 - 2017-04-19 18:44 - 00000000 ____D C:\Program Files (x86)\Driver Identifier
2017-04-19 18:43 - 2017-04-19 18:43 - 00000000 ____D C:\Users\vilian\AppData\Roaming\driveridentifier
2017-04-19 18:43 - 2017-04-19 18:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Identifier
2017-04-19 18:42 - 2017-04-19 18:42 - 04275578 _____ (DriverIdentifier ) C:\Users\vilian\Downloads\driveridentifier_setup.exe
2017-04-19 14:23 - 2017-04-19 14:24 - 00000000 ____D C:\Program Files\Common Files\QCA_Bluetooth
2017-04-19 14:23 - 2017-04-19 14:23 - 00000000 ____D C:\Program Files (x86)\Bluetooth Suite
2017-04-19 14:18 - 2017-04-19 14:18 - 41305000 _____ (AMD Inc.) C:\Users\vilian\Downloads\radeon-crimson-relive-17.4.3-minimalsetup-170417_64bit.exe
2017-04-19 14:15 - 2017-04-19 14:15 - 00611400 _____ () C:\Users\vilian\Downloads\LSBsetup.exe
2017-04-19 14:15 - 2017-04-19 14:15 - 00000000 ____D C:\Windows\System32\Tasks\Lenovo
2017-04-19 14:15 - 2017-04-19 14:15 - 00000000 ____D C:\Users\vilian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
2017-04-19 14:12 - 2017-04-19 14:15 - 345473456 _____ (Lenovo Group Limited ) C:\Users\vilian\Downloads\bt143w81.exe
2017-04-17 18:28 - 2017-04-17 18:29 - 88754544 _____ (Audio ) C:\Users\vilian\Downloads\wlan222w81.exe
2017-04-17 18:27 - 2017-04-17 18:27 - 22302856 _____ (Lenovo Group ) C:\Users\vilian\Downloads\cagt26ww.exe
2017-04-14 11:47 - 2017-04-21 15:44 - 00000791 _____ C:\Users\vilian\Desktop\PCCL.txt
2017-04-09 19:19 - 2017-04-19 14:15 - 00000000 ____D C:\Users\vilian\Desktop\Paladins Callouts
2017-04-06 12:57 - 2017-04-06 13:54 - 00009207 _____ C:\Users\vilian\Desktop\Нов Работен лист на Microsoft Excel.xlsx
2017-04-06 11:12 - 2017-04-23 18:00 - 00003476 _____ C:\Windows\System32\Tasks\Garena+ Plugin Host Service
2017-04-04 20:00 - 2017-04-04 20:00 - 00002043 _____ C:\Users\Public\Desktop\ESET Banking & Payment protection.lnk
2017-04-04 20:00 - 2017-04-04 20:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2017-04-04 20:00 - 2017-04-04 20:00 - 00000000 ____D C:\ProgramData\ESET
2017-04-04 20:00 - 2017-04-04 20:00 - 00000000 ____D C:\Program Files\ESET
2017-03-25 01:03 - 2017-03-25 01:03 - 00000000 __SHD C:\Users\vilian\AppData\Local\icsxml
2017-03-25 01:03 - 2017-03-25 01:03 - 00000000 ____D C:\Users\vilian\AppData\Local\MetaGeek,_LLC
2017-03-25 01:02 - 2017-03-25 01:02 - 00000000 __SHD C:\Users\vilian\AppData\Local\ms-drivers
2017-03-25 01:02 - 2017-03-25 01:02 - 00000000 __SHD C:\ProgramData\DIBsection
2017-03-25 00:50 - 2017-04-19 18:54 - 00000000 ____D C:\Windows\LastGood
2017-03-25 00:50 - 2012-08-03 16:30 - 03618304 _____ (Qualcomm Atheros Communications, Inc.) C:\Windows\system32\Drivers\athw8x.sys

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-04-23 20:13 - 2016-03-25 19:46 - 00003596 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-796519841-2226784028-2922330728-1001
2017-04-23 20:11 - 2016-03-26 02:53 - 00000000 ____D C:\Program Files (x86)\Steam
2017-04-23 20:10 - 2016-03-26 22:46 - 00000000 ____D C:\Users\vilian\AppData\Local\CrashDumps
2017-04-23 20:09 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\Inf
2017-04-23 20:07 - 2016-03-25 22:53 - 00000000 ____D C:\Users\vilian\AppData\Local\ClassicShell
2017-04-23 20:06 - 2016-11-18 14:30 - 00000000 ____D C:\Users\vilian\AppData\LocalLow\Mozilla
2017-04-23 18:03 - 2016-04-02 01:57 - 00000000 ____D C:\Users\vilian\AppData\Roaming\Raptr
2017-04-23 18:03 - 2016-03-26 16:46 - 00003758 _____ C:\Windows\System32\Tasks\AutoKMS
2017-04-23 18:01 - 2016-03-25 19:42 - 00000000 ___RD C:\Users\vilian\OneDrive
2017-04-23 18:00 - 2017-01-12 22:24 - 00000000 ____D C:\Program Files (x86)\Hi-Rez Studios
2017-04-23 17:58 - 2013-08-22 17:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-04-23 17:58 - 2013-08-22 17:44 - 00528936 _____ C:\Windows\system32\FNTCACHE.DAT
2017-04-23 17:57 - 2013-08-22 16:25 - 00262144 ___SH C:\Windows\system32\config\BBI
2017-04-23 17:12 - 2016-07-18 00:07 - 00000000 ____D C:\Program Files (x86)\Garena Plus
2017-04-23 17:04 - 2017-03-03 22:57 - 00000000 ____D C:\Users\vilian\AppData\LocalLow\uTorrent
2017-04-23 17:04 - 2016-03-25 23:46 - 00000000 ____D C:\Users\vilian\AppData\Roaming\uTorrent
2017-04-23 14:52 - 2013-08-22 18:36 - 00000000 ____D C:\Windows\system32\NDF
2017-04-23 13:59 - 2016-07-18 00:09 - 00000000 ____D C:\Users\vilian\AppData\Roaming\GarenaPlus
2017-04-23 13:59 - 2016-07-18 00:07 - 00000000 ____D C:\ProgramData\GarenaMessenger
2017-04-21 13:34 - 2016-03-26 02:54 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-04-20 20:13 - 2016-06-04 15:22 - 00000000 ____D C:\Users\vilian\.MemuHyperv
2017-04-20 19:04 - 2016-03-26 21:45 - 00000000 ____D C:\Users\vilian\AppData\Roaming\Skype
2017-04-20 00:07 - 2017-02-10 13:47 - 00002215 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-04-20 00:07 - 2017-02-10 13:47 - 00002203 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-04-19 19:29 - 2014-11-21 10:38 - 00865408 _____ C:\Windows\system32\PerfStringBackup.INI
2017-04-19 19:14 - 2016-03-26 17:15 - 00000000 ____D C:\Program Files\Intel
2017-04-19 19:14 - 2016-03-26 17:12 - 00000000 ____D C:\Program Files (x86)\Intel
2017-04-19 19:07 - 2016-03-26 17:22 - 00000000 ____D C:\ProgramData\Package Cache
2017-04-19 19:03 - 2016-03-26 17:21 - 00000000 ____D C:\Program Files (x86)\Qualcomm Atheros
2017-04-19 18:50 - 2016-03-26 17:20 - 00000000 ____D C:\ProgramData\Qualcomm Atheros
2017-04-19 14:19 - 2017-03-21 14:49 - 00000060 _____ C:\ProgramData\SoftwareUpdateTemp.xml
2017-04-19 14:18 - 2016-03-26 17:23 - 00000000 ____D C:\AMD
2017-04-19 14:16 - 2016-11-06 20:21 - 00000000 ____D C:\Users\vilian\AppData\Local\Deployment
2017-04-17 22:33 - 2016-03-26 22:23 - 00000000 ____D C:\Users\vilian\AppData\Roaming\TS3Client
2017-04-17 14:07 - 2016-04-05 18:01 - 00000000 ____D C:\Users\vilian\AppData\Roaming\OBS
2017-04-13 20:42 - 2016-11-06 20:21 - 00000000 ____D C:\Users\vilian\Documents\Файлове на Outlook
2017-04-12 01:56 - 2016-03-26 13:51 - 00000000 ____D C:\Users\vilian\AppData\Local\Battle.net
2017-04-12 01:03 - 2013-08-22 18:36 - 00000000 ____D C:\Windows\AppReadiness
2017-04-12 00:59 - 2016-03-25 19:41 - 00000000 ____D C:\Users\vilian\AppData\Local\Packages
2017-04-12 00:57 - 2013-08-22 18:36 - 00000000 ___HD C:\Program Files\WindowsApps
2017-04-12 00:45 - 2016-03-26 13:50 - 00000000 ____D C:\Program Files (x86)\Battle.net
2017-04-11 19:58 - 2016-03-29 21:00 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2017-04-11 19:58 - 2016-03-29 21:00 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-04-11 19:55 - 2017-01-23 12:52 - 00004288 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-04-11 19:55 - 2013-08-22 18:36 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-04-11 19:55 - 2013-08-22 18:36 - 00000000 ____D C:\Windows\system32\Macromed
2017-04-11 13:00 - 2017-02-10 13:35 - 00003430 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2017-04-11 13:00 - 2017-02-10 13:35 - 00003302 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2017-04-11 12:59 - 2016-07-13 16:03 - 00003508 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-796519841-2226784028-2922330728-1001UA
2017-04-11 12:59 - 2016-07-13 16:03 - 00003236 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-796519841-2226784028-2922330728-1001Core
2017-04-10 15:57 - 2016-03-25 19:40 - 00000000 ____D C:\Users\vilian
2017-04-10 12:12 - 2016-06-11 00:01 - 00000000 ____D C:\Users\vilian\AppData\Roaming\discord
2017-04-08 21:02 - 2016-03-31 22:08 - 00000000 ____D C:\Users\vilian\AppData\Roaming\Apple Computer
2017-04-08 17:35 - 2016-04-09 17:18 - 00000000 ____D C:\Users\vilian\AppData\Local\ElevatedDiagnostics
2017-04-08 15:27 - 2016-11-22 19:03 - 00000165 _____ C:\Users\vilian\Desktop\a.txt
2017-04-07 17:56 - 2016-06-22 01:27 - 00000000 ____D C:\Users\vilian\Desktop\Hearthstone Deck Tracker
2017-04-04 20:00 - 2013-08-22 18:36 - 00000000 ___HD C:\Windows\ELAMBKUP
2017-03-25 00:50 - 2016-03-26 22:56 - 00000000 ____D C:\Program Files (x86)\Lenovo
2017-03-25 00:50 - 2016-03-26 17:13 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information

==================== Files in the root of some directories =======

2016-11-14 21:25 - 2016-11-14 21:25 - 0000146 _____ () C:\Users\vilian\AppData\Roaming\gamma_ramp.reg
2016-03-26 00:05 - 2016-03-26 00:05 - 0005120 _____ () C:\Users\vilian\AppData\Roaming\GiftBag.db
2016-11-25 06:17 - 2016-11-25 06:17 - 0000840 _____ () C:\Users\vilian\AppData\Local\recently-used.xbel
2016-04-03 14:17 - 2016-04-03 14:17 - 0007602 _____ () C:\Users\vilian\AppData\Local\Resmon.ResmonCfg
2016-03-26 17:36 - 2016-03-26 17:36 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2017-03-21 14:49 - 2017-04-19 14:19 - 0000060 _____ () C:\ProgramData\SoftwareUpdateTemp.xml

Some files in TEMP:
====================
2017-03-30 14:01 - 2017-02-24 02:36 - 0037376 _____ (Microsoft) C:\Users\vilian\AppData\Local\Temp\HiPatchSelfUpdateWindow.exe
2017-03-30 14:01 - 2017-02-23 19:05 - 0020480 _____ (Microsoft) C:\Users\vilian\AppData\Local\Temp\HiRezLauncherControls.dll
2017-04-20 20:14 - 2017-04-20 20:14 - 0492544 _____ () C:\Users\vilian\AppData\Local\Temp\s3.exe
2017-03-07 18:56 - 2017-04-08 22:01 - 43902976 _____ () C:\Users\vilian\AppData\Local\Temp\SkypeSetup.exe
2017-04-23 20:08 - 2017-04-23 16:04 - 1516256 _____ (Symantec Corporation) C:\Users\vilian\AppData\Local\Temp\{397E31AA-0D78-4649-A01C-339D73A2ED35}_NSS__{1E335DB5-2B67-4B7C-905E-1D4EED8F0999}.exe
2017-04-23 17:04 - 2017-04-23 17:05 - 68469144 _____ (Panda Security, S.L.) C:\Users\vilian\AppData\Local\Temp\{59EC8056-D88C-4000-9DD5-1156B797CCDB}.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-04-23 14:09

==================== End of FRST.txt ============================

Addition.txt

  • Автор

Както си играя някоя игра и се появява висок пинг и като погледна списъка с възможни wi-fi за свързване е доста по-малък отколкото трябва да е.Получава се само на моя лаптоп.

Щом проблема е само в тази система едва ли е от рутера или от доставчика. Но като гледам лог файловете едва ли се дължи на зловреден софтуер.

Изтеглете edit-text.giffixlist.txt и го запазете на десктопа.
Стартирайте FRST64.exe и натиснете бутона Fix веднъж!
След като приключи, ако ви поиска рестарт - съгласете се. След рестарта публикувайте лог файла - fixlog.txt, който ще се създаде след работата на програмата.
 
Внимание: Скрипта е създаден за текущата система. Да не се ползва за други системи с подобни проблеми!

След това пишете дали има някакво подобрение.

Spoiler

Само да предложа да се инсталира различна от инсталираната версия (по-нова/по-стара) на драйвъра за безжичната мрежова карта.

 

  • Автор

Благодаря ще пиша след 1-2 дни като видя оправи ли се е/

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 27-04-2017
Ran by vilian (28-04-2017 13:03:03) Run:1
Running from C:\Users\vilian\Desktop
Loaded Profiles: vilian (Available Profiles: vilian)
Boot Mode: Normal
==============================================

fixlist content:
*****************
start
HKLM-x32\...\Run: [] => [X]
ShellIconOverlayIdentifiers: [.QMDeskTopGCIcon] -> {B7667919-3765-4815-A66D-98A09BE662D6} =>  -> No File
GroupPolicy: Restriction - Windows Defender <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-796519841-2226784028-2922330728-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://pandasecurity.mystart.com/?pr=vmn&id=pandasecuritytb&v=4_3&utm_campaign=675&idate=2017-04-23&ent=hp_675&u=57CFD93241DAED43EF6B6858FCB5169A
SearchScopes: HKU\S-1-5-21-796519841-2226784028-2922330728-1001 -> DefaultScope {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = hxxp://pandasecurity.mystart.com/results.php?pr=vmn&gen=ms&id=pandasecuritytb&v=4_3&idate=2017-04-23&ent=ch_675&q={searchTerms}
SearchScopes: HKU\S-1-5-21-796519841-2226784028-2922330728-1001 -> {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = hxxp://pandasecurity.mystart.com/results.php?pr=vmn&gen=ms&id=pandasecuritytb&v=4_3&idate=2017-04-23&ent=ch_675&q={searchTerms}
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll => No File
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\q65lkn3u.default -> Search The Web
FF Homepage: Mozilla\Firefox\Profiles\q65lkn3u.default -> hxxp://pandasecurity.mystart.com/?pr=vmn&id=pandasecuritytb&v=4_3&utm_campaign=675&idate=2017-04-23&ent=hp_675&u=57CFD93241DAED43EF6B6858FCB5169A
FF Extension: (Panda Security Toolbar) - C:\Users\vilian\AppData\Roaming\Mozilla\Firefox\Profiles\q65lkn3u.default\Extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}.xpi [2017-04-23]
FF Extension: (Disable TLS Certificate Transparency) - C:\Users\vilian\AppData\Roaming\Mozilla\Firefox\Profiles\q65lkn3u.default\features\{3553b7be-0691-4508-84ab-6b7f4ff27452}\[email protected] [2017-04-18]
FF Extension: (Disable Prefetch) - C:\Users\vilian\AppData\Roaming\Mozilla\Firefox\Profiles\q65lkn3u.default\features\{3553b7be-0691-4508-84ab-6b7f4ff27452}\[email protected] [2017-04-18]
FF Extension: (Site Deployment Checker) - C:\Program Files (x86)\Mozilla Firefox\browser\features\[email protected] [2017-03-29] [not signed]
CHR Extension: (Chrome Media Router) - C:\Users\vilian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-04-13]
S2 panda_url_filtering; C:\Program Files\Panda Security URL Filtering\Panda_URL_Filteringb.exe [287752 2015-11-06] (Visicom Media Inc.)
S3 panda_url_filteringd; C:\Program Files\Panda Security URL Filtering\panda_url_filteringd.sys [51288 2014-03-19] (Visicom Media Inc.)
2017-04-23 20:10 - 2017-04-23 20:10 - 00000070 _____ C:\Windows\RAVTC.TMP
2017-04-23 17:08 - 2017-04-23 17:08 - 00000000 ____D C:\ProgramData\panda_url_filtering
2017-04-23 17:08 - 2017-04-23 17:08 - 00000000 ____D C:\Program Files\Panda Security URL Filtering
2017-04-23 17:07 - 2017-04-23 20:10 - 00000000 ____D C:\Users\vilian\AppData\Roaming\Panda Security
2017-04-23 17:07 - 2017-04-23 20:06 - 00000000 ____D C:\Program Files (x86)\pandasecuritytb
2017-04-23 17:07 - 2017-04-23 17:07 - 00000000 ____D C:\Users\vilian\AppData\Roaming\Search The Web
2017-04-23 17:07 - 2017-04-23 17:07 - 00000000 ____D C:\Users\vilian\AppData\LocalLow\pandasecuritytb
2017-04-23 17:06 - 2017-04-23 20:10 - 00000000 ____D C:\Program Files (x86)\Panda Security
2017-04-23 17:04 - 2017-04-23 20:10 - 00000000 ____D C:\ProgramData\Panda Security
2017-04-23 16:05 - 2017-04-23 20:08 - 00000000 ____D C:\ProgramData\Norton
2017-04-23 16:04 - 2017-04-23 16:04 - 00000000 ____D C:\ProgramData\NortonInstaller
Folder: C:\ProgramData\2e8c1871-4c4c-483d-a166-75c815962f12
FirewallRules: [{37383793-A3EE-4058-BE92-155D75E9274E}] => (Allow) C:\Program Files (x86)\pandasecuritytb\ToolbarCleaner.exe
FirewallRules: [{1727B1C0-CFE5-44F8-8B9F-C0A46AABFF75}] => (Allow) C:\Program Files (x86)\pandasecuritytb\ToolbarCleaner.exe
cmd: bitsadmin /reset /allusers
cmd: netsh winsock reset catalog
cmd: ipconfig /flushdns
RemoveProxy:
EmptyTemp:
End
*****************

HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\.QMDeskTopGCIcon => key removed successfully
HKCR\CLSID\{B7667919-3765-4815-A66D-98A09BE662D6} => key not found.
C:\Windows\system32\GroupPolicy\Machine => moved successfully
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer => key removed successfully
HKU\S-1-5-21-796519841-2226784028-2922330728-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKU\S-1-5-21-796519841-2226784028-2922330728-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-21-796519841-2226784028-2922330728-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} => key removed successfully
HKCR\CLSID\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} => key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814} => key removed successfully
HKCR\CLSID\{10921475-03CE-4E04-90CE-E2E7EF20C814} => key not found.
Firefox SelectedSearchEngine removed successfully
Firefox "homepage" removed successfully
C:\Users\vilian\AppData\Roaming\Mozilla\Firefox\Profiles\q65lkn3u.default\Extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}.xpi => moved successfully
C:\Users\vilian\AppData\Roaming\Mozilla\Firefox\Profiles\q65lkn3u.default\features\{3553b7be-0691-4508-84ab-6b7f4ff27452}\[email protected] => not found.
C:\Users\vilian\AppData\Roaming\Mozilla\Firefox\Profiles\q65lkn3u.default\features\{3553b7be-0691-4508-84ab-6b7f4ff27452}\[email protected] => not found.
C:\Program Files (x86)\Mozilla Firefox\browser\features\[email protected] => not found.
C:\Users\vilian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm => moved successfully
panda_url_filtering => Unable to stop service.
HKLM\System\CurrentControlSet\Services\panda_url_filtering => key removed successfully
panda_url_filtering => service removed successfully
panda_url_filteringd => Unable to stop service.
HKLM\System\CurrentControlSet\Services\panda_url_filteringd => key removed successfully
panda_url_filteringd => service removed successfully
"C:\Windows\RAVTC.TMP" => not found.
C:\ProgramData\panda_url_filtering => moved successfully
C:\Program Files\Panda Security URL Filtering => moved successfully
C:\Users\vilian\AppData\Roaming\Panda Security => moved successfully
C:\Program Files (x86)\pandasecuritytb => moved successfully
C:\Users\vilian\AppData\Roaming\Search The Web => moved successfully
C:\Users\vilian\AppData\LocalLow\pandasecuritytb => moved successfully
C:\Program Files (x86)\Panda Security => moved successfully
C:\ProgramData\Panda Security => moved successfully
C:\ProgramData\Norton => moved successfully
C:\ProgramData\NortonInstaller => moved successfully

========================= Folder: C:\ProgramData\2e8c1871-4c4c-483d-a166-75c815962f12 ========================

2017-04-19 19:13 - 2017-04-19 19:13 - 0000000 ____D () C:\ProgramData\2e8c1871-4c4c-483d-a166-75c815962f12\dell
2017-04-19 19:13 - 2017-04-19 19:15 - 0000000 ____D () C:\ProgramData\2e8c1871-4c4c-483d-a166-75c815962f12\dell\drivers

====== End of Folder: ======

HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{37383793-A3EE-4058-BE92-155D75E9274E} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1727B1C0-CFE5-44F8-8B9F-C0A46AABFF75} => value removed successfully

========= bitsadmin /reset /allusers =========


BITSADMIN version 3.0 [ 7.7.9600 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

0 out of 0 jobs canceled.

========= End of CMD: =========


========= netsh winsock reset catalog =========


Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.


========= End of CMD: =========


========= ipconfig /flushdns =========


Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========


========= RemoveProxy: =========

HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
HKU\S-1-5-21-796519841-2226784028-2922330728-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\S-1-5-21-796519841-2226784028-2922330728-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully


========= End of RemoveProxy: =========


=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 95217265 B
Java, Flash, Steam htmlcache => 490463067 B
Windows/system/drivers => 150484556 B
Edge => 0 B
Chrome => 35027831 B
Firefox => 439218598 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 715757 B
systemprofile32 => 128 B
LocalService => 95424 B
NetworkService => 5288 B
vilian => 819489479 B

RecycleBin => 521113368 B
EmptyTemp: => 2.4 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 13:03:38 ====

Ок, дръжте ме в течение. Има още какво да опитаме, а след това ако нищо не помогне ще преместя темата, където и е мястото за да могат повече хора да вземат участие в нея със съвети. ;)

Поздрави!

  • Автор

Случи се два пъти отново.Единият докато гледах стрийм и играех Paladins,а другият докато си ровех в интернета.

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.