Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Проблеми с браузъра

Featured Replies

Здравейте имам проблеми с браузъра и компютъра ми доста често засича.... Отварят се постоянно някакви реклами и страници от само себе си (имам адблокър, но и преди съм имал и не са ставали такива проблеми). Ще се радвам, ако ми помогнете да разрешим проблема.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14.03.2018
Ran by Stefan (administrator) on STEFAN-PC (15-03-2018 19:54:33)
Running from C:\Users\Stefan\Downloads
Loaded Profiles: Stefan (Available Profiles: Stefan)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Български (България)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
() C:\Users\Stefan\AppData\Roaming\Q72b3mECjZq12zf0\0LuPuDDUlwHJ.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Blizzard Entertainment) C:\Program Files (x86)\Battle.net\Battle.net.9854\Battle.net Helper.exe
(Blizzard Entertainment) C:\ProgramData\Battle.net\Agent\Agent.6082\Agent.exe
(Blizzard Entertainment) C:\Program Files (x86)\Battle.net\Battle.net.9887\Battle.net Helper.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Blizzard Entertainment) C:\ProgramData\Battle.net\Agent\Agent.6082\Agent.exe
(Blizzard Entertainment) C:\Program Files (x86)\Battle.net\Battle.net.exe
(Blizzard Entertainment) C:\Program Files (x86)\Battle.net\Battle.net.9887\Battle.net Helper.exe
(Blizzard Entertainment) C:\Program Files (x86)\Battle.net\Battle.net.9887\Battle.net Helper.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [112512 2010-03-13] (Microsoft Corporation)
HKU\S-1-5-21-1138422693-3855770178-890708622-1000\...\Run: [Overwolf] => C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe [1207112 2018-03-05] ()
HKU\S-1-5-21-1138422693-3855770178-890708622-1000\...\Run: [Skype for Desktop] => C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe [58899912 2018-02-02] (Skype Technologies S.A.)
HKU\S-1-5-21-1138422693-3855770178-890708622-1000\...\Run: [Discord] => C:\Users\Stefan\AppData\Local\Discord\app-0.0.300\Discord.exe [57821176 2018-01-08] (Discord Inc.)
HKU\S-1-5-21-1138422693-3855770178-890708622-1000\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4471536 2015-05-21] (Disc Soft Ltd)
HKU\S-1-5-21-1138422693-3855770178-890708622-1000\...\MountPoints2: {f58cc662-09e3-11e8-8edf-606c665b70ec} - F:\SETUP.EXE
HKU\S-1-5-21-1138422693-3855770178-890708622-1000\...\Winlogon: [Shell] "C:\Users\Stefan\AppData\Roaming\Q72b3mECjZq12zf0\0LuPuDDUlwHJ.exe",explorer.exe <==== ATTENTION
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [181280 2017-01-25] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [158392 2017-01-25] (NVIDIA Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\Parameters: [NameServer] 82.163.143.176 82.163.142.178
Tcpip\..\Interfaces\{083BFCEF-CB63-4EA3-A4FF-CEE046393EDD}: [NameServer] 82.163.143.176 82.163.142.178
Tcpip\..\Interfaces\{083BFCEF-CB63-4EA3-A4FF-CEE046393EDD}: [DhcpNameServer] 82.163.143.176
Tcpip\..\Interfaces\{2E27C145-51D0-4556-9C2C-0E2441CFD2DE}: [NameServer] 82.163.143.176 82.163.142.178
Tcpip\..\Interfaces\{2E27C145-51D0-4556-9C2C-0E2441CFD2DE}: [DhcpNameServer] 82.163.143.176
Tcpip\..\Interfaces\{82F15432-F21B-4575-809F-754B40549B71}: [NameServer] 82.163.143.176 82.163.142.178
Tcpip\..\Interfaces\{82F15432-F21B-4575-809F-754B40549B71}: [DhcpNameServer] 82.163.143.176
Tcpip\..\Interfaces\{8FEEE6C2-2C34-4DE5-9AD1-F9A1B13F1A84}: [NameServer] 82.163.143.176 82.163.142.178
Tcpip\..\Interfaces\{8FEEE6C2-2C34-4DE5-9AD1-F9A1B13F1A84}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{CE8462F4-4F8C-4B6A-A02E-5901E757BD66}: [NameServer] 82.163.143.176 82.163.142.178
Tcpip\..\Interfaces\{CE8462F4-4F8C-4B6A-A02E-5901E757BD66}: [DhcpNameServer] 82.163.143.176

Internet Explorer:
==================
HKU\S-1-5-21-1138422693-3855770178-890708622-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2011-02-12] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2011-02-12] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation)

FireFox:
========
FF DefaultProfile: 5mi4sz4p.default
FF ProfilePath: C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\5mi4sz4p.default [2018-03-15]
FF Extension: (Adblock Plus) - C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\5mi4sz4p.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2018-01-26]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_29_0_0_113.dll [2018-03-14] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_29_0_0_113.dll [2018-03-14] ()
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2018-01-23] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2018-01-23] (Google Inc.)

Chrome:
=======
CHR Profile: C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default [2018-03-15]
CHR Extension: (Slides) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-01-23]
CHR Extension: (Docs) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-01-23]
CHR Extension: (Google Drive) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-01-23]
CHR Extension: (YouTube) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-01-23]
CHR Extension: (Foxtrick) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpfbbngccefbbndginomofgpagkjckik [2018-01-26]
CHR Extension: (Sheets) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-01-23]
CHR Extension: (Google Docs Offline) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-01-23]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-01-23]
CHR Extension: (Gmail) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-01-23]
CHR Extension: (Chrome Media Router) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-03-09]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1272560 2015-05-21] (Disc Soft Ltd)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [330136 2015-08-27] (Intel Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2011-12-08] ()
S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [1452360 2018-03-05] (Overwolf LTD)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10945776 2017-12-15] (TeamViewer GmbH)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [594704 2011-12-08] (Intel® Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem"

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2018-02-28] (Disc Soft Ltd)
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-03-15 19:54 - 2018-03-15 19:55 - 000011699 _____ C:\Users\Stefan\Downloads\FRST.txt
2018-03-15 19:54 - 2018-03-15 19:54 - 002403328 _____ (Farbar) C:\Users\Stefan\Downloads\FRST64.exe
2018-03-15 19:54 - 2018-03-15 19:54 - 000000000 ____D C:\FRST
2018-03-14 19:40 - 2018-03-14 19:40 - 000004466 _____ C:\Windows\System32\Tasks\Adobe Flash Player NPAPI Notifier
2018-03-07 08:17 - 2018-03-07 08:17 - 000000000 ____D C:\ProgramData\91c0a3a2-65d7-1
2018-03-07 08:17 - 2018-03-07 08:17 - 000000000 ____D C:\ProgramData\91c0a3a2-07c5-0
2018-03-06 22:03 - 2018-03-06 22:03 - 000000000 ____D C:\ProgramData\91c0a3a2-4027-0
2018-03-06 22:03 - 2018-03-06 22:03 - 000000000 ____D C:\ProgramData\91c0a3a2-2463-1
2018-03-06 12:01 - 2018-03-06 14:00 - 000000000 ____D C:\ProgramData\91c0a3a2-1683-0
2018-03-06 12:01 - 2018-03-06 14:00 - 000000000 ____D C:\ProgramData\91c0a3a2-0153-1
2018-03-06 04:03 - 2018-03-06 04:03 - 000000000 ____D C:\ProgramData\91c0a3a2-6337-0
2018-03-06 04:03 - 2018-03-06 04:03 - 000000000 ____D C:\ProgramData\91c0a3a2-2bb1-1
2018-03-06 03:16 - 2018-03-06 03:16 - 001743789 _____ ( ) C:\Users\Stefan\Downloads\JavaSetup_0062159658.exe
2018-03-05 22:15 - 2018-03-05 22:15 - 000003730 _____ C:\Windows\System32\Tasks\{CAADFADF-EC91-42D5-AEAA-CDCB1A45B15A}
2018-03-05 22:15 - 2018-03-05 22:15 - 000000000 ____D C:\ProgramData\cbcdaaae-71a3-0
2018-03-05 22:15 - 2018-03-05 22:15 - 000000000 ____D C:\ProgramData\cbcdaaae-0765-1
2018-03-05 22:15 - 2018-03-05 22:15 - 000000000 ____D C:\ProgramData\9db6a9f8
2018-03-05 22:14 - 2018-03-05 22:15 - 000004396 _____ C:\Windows\System32\Tasks\5A431ED8-BAC5-ECA5-E830-978D5C3B4E31
2018-03-05 22:14 - 2018-03-05 22:15 - 000000000 ____D C:\Users\Stefan\AppData\Local\85A0D816-3ABA-0B19-770D-C62137D36FB8
2018-03-05 22:10 - 2018-03-05 22:10 - 000000000 ____D C:\ProgramData\{543674dd-212c-0}
2018-03-05 22:10 - 2018-03-05 22:10 - 000000000 ____D C:\ProgramData\{1d3e7d30-212c-1}
2018-02-28 22:04 - 2018-02-28 22:04 - 000000000 ____D C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2018-02-28 22:03 - 2018-03-15 14:39 - 000000278 _____ C:\Windows\Tasks\One System CarePeriod.job
2018-02-28 22:03 - 2018-02-28 22:03 - 000002856 _____ C:\Windows\System32\Tasks\One System CarePeriod
2018-02-28 22:03 - 2018-02-28 22:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
2018-02-28 22:03 - 2018-02-28 22:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2018-02-28 22:03 - 2018-02-28 22:03 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2018-02-28 22:02 - 2018-02-28 22:02 - 000000000 ____D C:\Windows\PCHEALTH
2018-02-28 22:02 - 2018-02-28 22:02 - 000000000 ____D C:\Program Files\Microsoft Synchronization Services
2018-02-28 22:02 - 2018-02-28 22:02 - 000000000 ____D C:\Program Files\Microsoft Sync Framework
2018-02-28 22:02 - 2018-02-28 22:02 - 000000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition
2018-02-28 22:00 - 2018-02-28 22:00 - 000000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 8
2018-02-28 21:59 - 2018-02-28 22:03 - 000000000 ____D C:\Windows\SHELLNEW
2018-02-28 21:59 - 2018-02-28 22:02 - 000000000 ____D C:\Program Files\Microsoft Office
2018-02-28 21:59 - 2018-02-28 21:59 - 000000000 __RHD C:\MSOCache
2018-02-28 21:59 - 2018-02-28 21:59 - 000000000 ____D C:\Users\Stefan\AppData\Local\Microsoft Help
2018-02-28 21:59 - 2018-02-28 21:59 - 000000000 ____D C:\Program Files\Microsoft Analysis Services
2018-02-28 21:59 - 2018-02-28 21:59 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2018-02-28 21:59 - 2018-02-28 21:59 - 000000000 ____D C:\Program Files (x86)\Microsoft Analysis Services
2018-02-28 21:58 - 2018-03-05 22:15 - 000000000 ____D C:\ProgramData\91c0a3a2-4095-0
2018-02-28 21:58 - 2018-03-05 22:15 - 000000000 ____D C:\ProgramData\91c0a3a2-2991-1
2018-02-28 21:58 - 2018-02-28 22:04 - 000000000 ____D C:\Users\Stefan\AppData\Roaming\One System Care
2018-02-28 21:58 - 2018-02-28 22:03 - 000000000 ____D C:\Program Files (x86)\OneSystemCare
2018-02-28 21:58 - 2018-02-28 21:58 - 000024210 _____ C:\Windows\System32\Tasks\{090B0547-7804-0879-0F11-7F0D7F08110B}
2018-02-28 21:58 - 2018-02-28 21:58 - 000003570 _____ C:\Windows\System32\Tasks\OneSystemCare Task
2018-02-28 21:58 - 2018-02-28 21:58 - 000003326 _____ C:\Windows\System32\Tasks\One System Care Monitor
2018-02-28 21:58 - 2018-02-28 21:58 - 000003318 _____ C:\Windows\System32\Tasks\One System Care Delayed
2018-02-28 21:58 - 2018-02-28 21:58 - 000000000 ____D C:\Users\Stefan\AppData\Local\Disc_Soft_Ltd
2018-02-28 21:58 - 2018-02-28 21:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\One System Care
2018-02-28 21:58 - 2018-02-28 21:58 - 000000000 ____D C:\ProgramData\9aa09a6d-1dc7-485c-83f5-e9da458d08eb
2018-02-28 21:57 - 2018-02-28 21:58 - 000000000 ____D C:\Users\Stefan\AppData\Roaming\DAEMON Tools Lite
2018-02-28 21:57 - 2018-02-28 21:57 - 000030264 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtlitescsibus.sys
2018-02-28 21:57 - 2018-02-28 21:57 - 000000000 ____D C:\Users\Stefan\AppData\Roaming\OneSystemCare
2018-02-28 21:57 - 2018-02-28 21:57 - 000000000 ____D C:\Program Files\DAEMON Tools Lite
2018-02-28 21:56 - 2018-02-28 21:57 - 000000000 ____D C:\ProgramData\DAEMON Tools Lite
2018-02-28 21:56 - 2018-02-28 21:56 - 019312736 ____R (Disc Soft Ltd) C:\Users\Stefan\Downloads\DAEMON Tools Lite 10.0.0.54.exe
2018-02-28 21:47 - 2018-02-28 21:47 - 000000000 ____D C:\Users\Stefan\Downloads\Microsoft Office Professional Plus 2010 with Service Pack 1 VL EN x64
2018-02-24 19:24 - 2018-02-24 19:24 - 000071680 _____ C:\Users\Stefan\Downloads\Klasirane Ataka 2016.xls
2018-02-14 03:25 - 2018-02-14 03:25 - 000000000 ____D C:\Users\Stefan\AppData\Local\TeamViewer
2018-02-14 03:19 - 2018-02-15 02:52 - 000000000 ____D C:\Users\Stefan\Documents\888poker
2018-02-14 03:18 - 2018-02-14 20:26 - 000001953 _____ C:\Users\Stefan\Desktop\888poker.lnk
2018-02-14 03:18 - 2018-02-14 20:26 - 000000000 ____D C:\Users\Stefan\AppData\Roaming\pacificpoker
2018-02-14 03:18 - 2018-02-14 20:26 - 000000000 ____D C:\Users\Stefan\AppData\Roaming\InstallShield Installation Information
2018-02-14 03:18 - 2018-02-14 20:26 - 000000000 ____D C:\Users\Stefan\AppData\Local\Downloaded Installations
2018-02-14 03:18 - 2018-02-14 03:18 - 000000000 ____D C:\Program Files (x86)\PacificPoker
2018-02-14 03:17 - 2018-02-14 03:18 - 000000000 ____D C:\Users\Stefan\Documents\PokerInstallerLogs
2018-02-14 03:17 - 2018-02-14 03:17 - 000641328 _____ (Random-Logic) C:\Users\Stefan\Downloads\888poker_installer.exe

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-03-15 19:50 - 2018-01-26 17:47 - 000000000 ____D C:\Users\Stefan\AppData\Local\Battle.net
2018-03-15 19:48 - 2018-01-26 17:46 - 000000000 ____D C:\Program Files (x86)\Battle.net
2018-03-15 19:44 - 2009-07-14 06:45 - 000026112 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-03-15 19:44 - 2009-07-14 06:45 - 000026112 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-03-15 13:45 - 2018-01-23 12:48 - 000003974 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{5D3F7C17-CFD3-45C5-AD70-212AB69F4E91}
2018-03-14 19:40 - 2018-01-26 18:30 - 000804352 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2018-03-14 19:40 - 2018-01-26 18:30 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2018-03-14 19:40 - 2018-01-26 18:30 - 000004324 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2018-03-14 19:40 - 2018-01-26 18:30 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2018-03-14 19:40 - 2018-01-26 18:30 - 000000000 ____D C:\Windows\system32\Macromed
2018-03-14 01:09 - 2018-01-23 13:03 - 000002222 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-03-14 01:09 - 2018-01-23 13:03 - 000002181 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-03-12 19:34 - 2018-01-26 17:50 - 000000000 ____D C:\Program Files (x86)\Hearthstone
2018-03-08 20:59 - 2018-02-03 00:59 - 000000000 ____D C:\Program Files (x86)\Overwolf
2018-03-06 01:54 - 2018-02-10 01:25 - 000000000 ____D C:\Users\Stefan\AppData\Roaming\discord
2018-03-02 23:19 - 2018-02-03 00:59 - 000000000 ____D C:\ProgramData\Overwolf
2018-03-02 21:22 - 2009-07-14 07:13 - 000781298 _____ C:\Windows\system32\PerfStringBackup.INI
2018-03-02 21:22 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\inf
2018-03-02 18:04 - 2018-02-03 00:58 - 000000000 ____D C:\Users\Stefan\AppData\Local\Overwolf
2018-03-02 18:04 - 2018-01-23 12:38 - 000000000 __SHD C:\Users\Stefan\IntelGraphicsProfiles
2018-03-02 18:03 - 2018-01-23 12:34 - 000000000 ____D C:\ProgramData\NVIDIA
2018-03-02 18:03 - 2009-07-14 07:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-03-02 18:02 - 2009-07-14 06:45 - 000409192 _____ C:\Windows\system32\FNTCACHE.DAT
2018-02-28 23:04 - 2018-01-23 12:54 - 000000000 ____D C:\Users\Stefan\AppData\Roaming\uTorrent
2018-02-28 22:09 - 2009-07-14 05:20 - 000000000 ____D C:\Program Files\Common Files\System
2018-02-28 22:09 - 2009-07-14 04:34 - 000000478 _____ C:\Windows\win.ini
2018-02-28 22:04 - 2018-01-23 12:53 - 000109280 _____ C:\Users\Stefan\AppData\Local\GDIPFONTCACHEV1.DAT
2018-02-28 22:03 - 2009-07-14 05:20 - 000000000 ____D C:\Program Files\Common Files\Microsoft Shared
2018-02-28 22:02 - 2009-07-14 07:32 - 000000000 ____D C:\Program Files (x86)\MSBuild
2018-02-17 03:01 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\LiveKernelReports
2018-02-15 00:25 - 2018-01-28 14:06 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2018-02-13 07:15 - 2018-02-07 00:06 - 000000000 ____D C:\Users\Stefan\Desktop\finansi

==================== Files in the root of some directories =======

2014-11-18 11:22 - 2014-11-18 11:22 - 033160370 ____R () C:\Users\Stefan\AppData\Roaming\K.J_121026.exe

Some files in TEMP:
====================
2018-02-14 03:17 - 2018-02-14 03:18 - 124311352 _____ (888) C:\Users\Stefan\AppData\Local\Temp\888pokersetup.exe
2017-12-07 11:15 - 2017-12-07 11:15 - 000656069 _____ (Random-Logic) C:\Users\Stefan\AppData\Local\Temp\installer.exe
2017-11-29 11:49 - 2017-11-29 11:49 - 124499168 _____ (888) C:\Users\Stefan\AppData\Local\Temp\setup.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe
[2018-01-23 12:54] - [2011-01-16 02:01] - 000389632 _____ (Microsoft Corporation) 81257415084B84F3C0D95C381A8D4C8F

C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll
[2010-11-21 05:24] - [2011-01-16 02:01] - 001008640 _____ (Microsoft Corporation) 0B864E15A0BADFF0E7BB8B59009FDDCF

C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-01-23 11:50

==================== End of FRST.txt ============================

Addition.txt

  • Автор

Преди около месец, месец и нещо изгоря хард диска и го смениха с нов, инсталираха ми някакъв windows, но за антивирусна не съм сигурен... Най-вероятно нямам антивирусна и оттам се лепят заразите...

Здравейте,

 

СТЪПКА 1

 

Изтеглете програмата GeekUninstaller и я запазете на десктопа.

Разархивирайте я и стартирайте файла geek.exe IxXO5oO.jpg
От списъка намерете One System Care  (примера е за Mozilla Firefox, но това е просто за показно).

Кликнете с десен бутон върху програмата и изберете Force Removal
 
XhV2QLa.png
 
След края на инсталацията ще се отвори прозорец подканващ ви да премахнете всички остатъци от програмата (ако има такива, ако няма този прозорец няма да се появи):
 
Пример за Mozilla браузъра:

geekuninstaller-3.png

Натиснете бутона Finish за да изтриете останките от програмата.

 

 

СТЪПКА 2

 

След това изтеглете edit-text.giffixlist.txt и го запазете на в папката, където сте свалили FRST64.exe (в папката C:\Users\Stefan\Downloads).
Стартирайте FRST64.exe и натиснете бутона Fix веднъж!
След като приключи, ако ви поиска рестарт - съгласете се. След рестарта публикувайте лог файла - fixlog.txt, който ще се създаде след работата на програмата.
 
Внимание: Скрипта е създаден за текущата система. Да не се ползва за други системи с подобни проблеми!

 

 

СТЪПКА 3

 

  • Изтеглете и стартирайте 6sv1DN9.jpgAdwCleaner.exe
  • Натиснете бутона Scan.
  • AdwCleaner ще започне да проверява компютъра.
  • След като проверката приключи натиснете бутона Clean.
  • Програмата ще затвори всички излишни процеси и след почистването ще иска да рестартира машината. Съгласете се.
  • Ще се появи автоматично лог файл с името (AdwCleaner[S0].txt и AdwCleaner[С0].txt) в C:\Adwcleaner
  • Публикувайте съдържанието на  AdwCleaner[С0].txt в следващия си коментар.

 

След това пишете как е положението.

Поздрави!

  • Автор

# AdwCleaner 7.0.8.0 - Logfile created on Thu Mar 15 22:40:10 2018
# Updated on 2018/08/02 by Malwarebytes
# Running on Windows 7 Ultimate (X64)
# Mode: clean
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services deleted.

***** [ Folders ] *****

Deleted: C:\Users\Stefan\AppData\Roaming\imminent
Deleted: C:\Users\Stefan\AppData\Roaming\OneSystemCare


***** [ Files ] *****

No malicious files deleted.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks deleted.

***** [ Registry ] *****

Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\11598763487076930564
Deleted: [Key] - HKLM\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\ROOT\CERTIFICATES\26D9E607FFF0C58C7844B47FF8B6E079E5A2220E


***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries deleted.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries deleted.

*************************

::Tracing keys deleted
::Winsock settings cleared
::Additional Actions: 0

 

*************************

C:/AdwCleaner/AdwCleaner[S0].txt - [1267 B] - [2018/3/15 22:39:15]


########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt ##########

 

Ами мисля, че е доста по-добре... Браузъра вече не се отваря самичък и не излизат изскачащи прозорци. :)

  • Автор

Fix result of Farbar Recovery Scan Tool (x64) Version: 14.03.2018
Ran by Stefan (16-03-2018 00:31:22) Run:1
Running from C:\Users\Stefan\Downloads
Loaded Profiles: Stefan (Available Profiles: Stefan)
Boot Mode: Normal
==============================================

fixlist content:
*****************
start
CreateRestorePoint:
CloseProcesses:
() C:\Users\Stefan\AppData\Roaming\Q72b3mECjZq12zf0\0LuPuDDUlwHJ.exe
HKU\S-1-5-21-1138422693-3855770178-890708622-1000\...\Winlogon: [Shell] "C:\Users\Stefan\AppData\Roaming\Q72b3mECjZq12zf0\0LuPuDDUlwHJ.exe",explorer.exe <==== ATTENTION
C:\Users\Stefan\AppData\Roaming\Q72b3mECjZq12zf0
C:\ProgramData\91c0a3a2-65d7-1
C:\ProgramData\91c0a3a2-07c5-0
C:\ProgramData\91c0a3a2-4027-0
C:\ProgramData\91c0a3a2-2463-1
C:\ProgramData\91c0a3a2-1683-0
C:\ProgramData\91c0a3a2-0153-1
C:\ProgramData\91c0a3a2-6337-0
C:\ProgramData\91c0a3a2-2bb1-1
C:\ProgramData\cbcdaaae-71a3-0
C:\ProgramData\cbcdaaae-0765-1
C:\ProgramData\9db6a9f8
C:\Users\Stefan\AppData\Local\85A0D816-3ABA-0B19-770D-C62137D36FB8
C:\ProgramData\{543674dd-212c-0}
C:\ProgramData\{1d3e7d30-212c-1}
C:\ProgramData\91c0a3a2-4095-0
C:\ProgramData\91c0a3a2-2991-1
C:\ProgramData\9aa09a6d-1dc7-485c-83f5-e9da458d08eb
File: C:\Users\Stefan\Downloads\JavaSetup_0062159658.exe
File: C:\Windows\system32\winlogon.exe
File: C:\Windows\system32\User32.dll
File: C:\Windows\System32\fsquirt.exe
Task: {5D1C589F-15A4-4C58-BE41-207238A3B1B8} - System32\Tasks\One System CarePeriod => C:\Program Files (x86)\OneSystemCare\OneSystemCare.exe [2018-02-26] () <==== ATTENTION
Task: {6DB54783-F182-4B03-9E04-B101842355EC} - System32\Tasks\One System Care Monitor => C:\Program Files (x86)\OneSystemCare\CleanupConsole.exe [2018-02-26] () <==== ATTENTION
Task: {7B1535FD-4542-462B-B24F-0C9B6A2F45E6} - System32\Tasks\OneSystemCare Task => C:\Program Files (x86)\OneSystemCare\SystemConsole.exe [2018-02-26] () <==== ATTENTION
Task: {89B5ED8A-A2C3-4DE5-9DDA-11DDB42ADD9A} - System32\Tasks\5A431ED8-BAC5-ECA5-E830-978D5C3B4E31 => C:\Windows\SysWOW64\regsvr32.exe /n /s /i:"/02c2319629550762 /q" "C:\Users\Stefan\AppData\Local\85A0D816-3ABA-0B19-770D-C62137D36FB8\{EE71FB67-529F-73C7-7123-D16B2568DE78}.."
Task: {A9FC4A58-3C57-4EEB-BC14-CAC9EABB210B} - System32\Tasks\{CAADFADF-EC91-42D5-AEAA-CDCB1A45B15A} => C:\Windows\system32\regsvr32.exe /s /n /i:"/rt" "C:\PROGRA~3\9db6a9f8\ee71fb67.dll" <==== ATTENTION
Task: {C2B3DCFA-9FEE-4D30-A28C-60E3D0BCABAB} - System32\Tasks\{090B0547-7804-0879-0F11-7F0D7F08110B} => C:\Windows\system32\WindowsPowershell\v1.0\powershell.exe -nologo -executionpolicy bypass -noninteractive -windowstyle hidden -EncodedCommand IAA7ADsAOwAgADsAIAAgACAAIAAkAEUAcgByAG8AcgBBAGMAdABpAG8AbgBQAHIAZQBmAGUAcgBlAG4AYwBlAD0AIgBzAHQAbwBwACIAOwAkAHMAYwA9ACIAUwBpAGwAZQBuAHQAbAB5AEMAbwBuAHQAaQBuAHUAZQAiADsAJABXAGEAcgBuAGkAbgBnAFAAcgBlAGYAZQByAGUAbgBjAGUA (the data entry has 9944 more characters). <==== ATTENTION
Task: {E2E19E8B-9B87-4E7C-83CB-6887DD992CBE} - System32\Tasks\One System Care Delayed => C:\Program Files (x86)\OneSystemCare\OneSystemCare.exe [2018-02-26] () <==== ATTENTION
Task: C:\Windows\Tasks\One System CarePeriod.job => C:\Program Files (x86)\OneSystemCare\OneSystemCare.exe <==== ATTENTION
CMD: winmgmt /resyncperf
CMD: lodctr /R
CMD: bitsadmin /reset /allusers
CMD: netsh winsock reset catalog
CMD: ipconfig /flushdns
RemoveProxy:
EmptyTemp:
End
*****************

Restore point was successfully created.
Processes closed successfully.
[1420] C:\Users\Stefan\AppData\Roaming\Q72b3mECjZq12zf0\0LuPuDDUlwHJ.exe => process closed successfully.
"HKU\S-1-5-21-1138422693-3855770178-890708622-1000\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell" => removed successfully
C:\Users\Stefan\AppData\Roaming\Q72b3mECjZq12zf0 => moved successfully
C:\ProgramData\91c0a3a2-65d7-1 => moved successfully
C:\ProgramData\91c0a3a2-07c5-0 => moved successfully
C:\ProgramData\91c0a3a2-4027-0 => moved successfully
C:\ProgramData\91c0a3a2-2463-1 => moved successfully
C:\ProgramData\91c0a3a2-1683-0 => moved successfully
C:\ProgramData\91c0a3a2-0153-1 => moved successfully
C:\ProgramData\91c0a3a2-6337-0 => moved successfully
C:\ProgramData\91c0a3a2-2bb1-1 => moved successfully
C:\ProgramData\cbcdaaae-71a3-0 => moved successfully
C:\ProgramData\cbcdaaae-0765-1 => moved successfully
C:\ProgramData\9db6a9f8 => moved successfully
C:\Users\Stefan\AppData\Local\85A0D816-3ABA-0B19-770D-C62137D36FB8 => moved successfully
C:\ProgramData\{543674dd-212c-0} => moved successfully
C:\ProgramData\{1d3e7d30-212c-1} => moved successfully
C:\ProgramData\91c0a3a2-4095-0 => moved successfully
C:\ProgramData\91c0a3a2-2991-1 => moved successfully
"C:\ProgramData\9aa09a6d-1dc7-485c-83f5-e9da458d08eb" => not found

========================= File: C:\Users\Stefan\Downloads\JavaSetup_0062159658.exe ========================

C:\Users\Stefan\Downloads\JavaSetup_0062159658.exe
File not signed
MD5: F3205A5B0C3D29918693B281B4D573BA
Creation and modification date: 2018-03-06 03:16 - 2018-03-06 03:16
Size: 001743789
Attributes: ----A
Company Name:                                                             
Internal Name:
Original Name:
Product: Simurom                                                     
Description: Simurom Setup                                               
File Version: 2.2.3.6             
Product Version: 2.1                                               
Copyright: File Fast                                                                                           
VirusTotal: https://www.virustotal.com/file/9c9ef432137dd33cc02a366ce02aa9df8b7d09c501bcc65242868137a49a59eb/analysis/1521055332/

====== End of File: ======


========================= File: C:\Windows\system32\winlogon.exe ========================

C:\Windows\system32\winlogon.exe
File not signed
MD5: 81257415084B84F3C0D95C381A8D4C8F
Creation and modification date: 2018-01-23 12:54 - 2011-01-16 02:01
Size: 000389632
Attributes: ----A
Company Name: Microsoft Corporation
Internal Name: winlogon
Original Name: WINLOGON.EXE
Product: Microsoft® Windows® Operating System
Description: Windows Logon Application
File Version: 6.1.7600.16447 (win7_gdr.091027-1503)
Product Version: 6.1.7600.16447
Copyright: © Microsoft Corporation. All rights reserved.
VirusTotal: https://www.virustotal.com/file/2c361196d0b06d8e361f1d68f708eeb02cb72ba204a1a2865041bd8c0c5d2a00/analysis/1518022863/

====== End of File: ======


========================= File: C:\Windows\system32\User32.dll ========================

C:\Windows\system32\User32.dll
File not signed
MD5: 0B864E15A0BADFF0E7BB8B59009FDDCF
Creation and modification date: 2010-11-21 05:24 - 2011-01-16 02:01
Size: 001008640
Attributes: ----A
Company Name: Microsoft Corporation
Internal Name: user32
Original Name: user32
Product: Microsoft® Windows® Operating System
Description: Multi-User Windows USER API Client DLL
File Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850)
Product Version: 6.1.7601.17514
Copyright: © Microsoft Corporation. All rights reserved.
VirusTotal: https://www.virustotal.com/file/4fd9a85de35bfe8e74ffd3b96e779ea1c5d8660784041b2ec475da2baa1ee3a0/analysis/1499332287/

====== End of File: ======


========================= File: C:\Windows\System32\fsquirt.exe ========================

C:\Windows\System32\fsquirt.exe
File is digitally signed
MD5: 49B3F2AA15C59729F86489C3ABAA1315
Creation and modification date: 2010-11-21 05:23 - 2010-11-21 05:23
Size: 000229376
Attributes: ----A
Company Name: Microsoft Corporation
Internal Name: fsquirt.exe
Original Name: fsquirt.exe
Product: Microsoft® Windows® Operating System
Description:
File Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850)
Product Version: 6.1.7601.17514
Copyright: © Microsoft Corporation. All rights reserved.
VirusTotal: https://www.virustotal.com/file/aa5abb71f0d5f2e9230d12668aee326f9ee0d3d5e5d29fa7f7f1375a307c3d2f/analysis/1520877173/

====== End of File: ======

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5D1C589F-15A4-4C58-BE41-207238A3B1B8} => could not remove. Access Denied.
"C:\Windows\System32\Tasks\One System CarePeriod" => not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\One System CarePeriod => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6DB54783-F182-4B03-9E04-B101842355EC} => could not remove. Access Denied.
"C:\Windows\System32\Tasks\One System Care Monitor" => not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\One System Care Monitor => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7B1535FD-4542-462B-B24F-0C9B6A2F45E6} => could not remove. Access Denied.
"C:\Windows\System32\Tasks\OneSystemCare Task" => not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OneSystemCare Task => could not remove. Access Denied.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{89B5ED8A-A2C3-4DE5-9DDA-11DDB42ADD9A}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{89B5ED8A-A2C3-4DE5-9DDA-11DDB42ADD9A}" => removed successfully
C:\Windows\System32\Tasks\5A431ED8-BAC5-ECA5-E830-978D5C3B4E31 => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\5A431ED8-BAC5-ECA5-E830-978D5C3B4E31" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A9FC4A58-3C57-4EEB-BC14-CAC9EABB210B}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A9FC4A58-3C57-4EEB-BC14-CAC9EABB210B}" => removed successfully
C:\Windows\System32\Tasks\{CAADFADF-EC91-42D5-AEAA-CDCB1A45B15A} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{CAADFADF-EC91-42D5-AEAA-CDCB1A45B15A}" => removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C2B3DCFA-9FEE-4D30-A28C-60E3D0BCABAB} => could not remove. Access Denied.
"C:\Windows\System32\Tasks\{090B0547-7804-0879-0F11-7F0D7F08110B}" => not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{090B0547-7804-0879-0F11-7F0D7F08110B} => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E2E19E8B-9B87-4E7C-83CB-6887DD992CBE} => could not remove. Access Denied.
"C:\Windows\System32\Tasks\One System Care Delayed" => not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\One System Care Delayed => could not remove. Access Denied.
"C:\Windows\Tasks\One System CarePeriod.job" => not found

========= winmgmt /resyncperf =========


========= End of CMD: =========


========= lodctr /R =========


Info: Successfully rebuilt performance counter setting from system backup store
========= End of CMD: =========


========= bitsadmin /reset /allusers =========


BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

Unable to cancel {F1EE59FD-C524-44DD-8FA2-A82DC78212D5}.
Unable to cancel {8894212E-A64D-4209-B0EA-26D70DDE0BDE}.
Unable to cancel {52534C1D-6DFB-4BFB-9B00-C31D9FF8EA1E}.
Unable to cancel {737481A7-4176-4D3C-84CA-AE610F4CBBFC}.
{E7402C74-DF29-4645-8B67-A8324C1EC64E} canceled.
{DD756038-16E8-400F-AD9C-2441152FA798} canceled.
{5F6C5280-FEC8-483B-8D6E-05DF64A0AEDC} canceled.
{51390BC5-C500-4C36-86BB-0865B6230239} canceled.
{F7B6D494-B1C7-424E-95CB-0B832110CD29} canceled.
{69B1FC1A-8703-4F43-A8DE-C3583D1B785B} canceled.
6 out of 10 jobs canceled.

========= End of CMD: =========


========= netsh winsock reset catalog =========


Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.


========= End of CMD: =========


========= ipconfig /flushdns =========


Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========


========= RemoveProxy: =========

"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
"HKU\S-1-5-21-1138422693-3855770178-890708622-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\S-1-5-21-1138422693-3855770178-890708622-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully


========= End of RemoveProxy: =========


=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 18103814 B
Java, Flash, Steam htmlcache => 2766 B
Windows/system/drivers => 1960188 B
Edge => 0 B
Chrome => 733141404 B
Firefox => 397415208 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 58558406 B
systemprofile32 => 66356 B
LocalService => 66228 B
NetworkService => 66228 B
Stefan => 614812813 B

RecycleBin => 0 B
EmptyTemp: => 1.7 GB temporary data Removed.

================================

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 16-03-2018 00:35:20)


Result of scheduled keys to remove after reboot:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5D1C589F-15A4-4C58-BE41-207238A3B1B8} => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\One System CarePeriod => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6DB54783-F182-4B03-9E04-B101842355EC} => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\One System Care Monitor => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7B1535FD-4542-462B-B24F-0C9B6A2F45E6} => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OneSystemCare Task => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C2B3DCFA-9FEE-4D30-A28C-60E3D0BCABAB} => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{090B0547-7804-0879-0F11-7F0D7F08110B} => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E2E19E8B-9B87-4E7C-83CB-6887DD992CBE} => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\One System Care Delayed => could not remove. Access Denied.

==== End of Fixlog 00:35:20 ====

 

Това би трябвало да е, тотално съм изключил за него, съжалявам....

Имаме още работа.

 

СТЪПКА 1

 

След това изтеглете edit-text.giffixlist.txt и го запазете на в папката, където сте свалили FRST64.exe (в папката C:\Users\Stefan\Downloads).
Стартирайте FRST64.exe и натиснете бутона Fix веднъж!
След като приключи, ако ви поиска рестарт - съгласете се. След рестарта публикувайте лог файла - fixlog.txt, който ще се създаде след работата на програмата.
 
Внимание: Скрипта е създаден за текущата система. Да не се ползва за други системи с подобни проблеми!

 

СТЪПКА 2

 

Моля изтеглете  Malwarebytes Anti-Malware 3.4.4.2398.exe и я запазете на вашия десктоп.

  • Стартирайте файла mb3-setup-consumer-3.4.4.2398.exe и следвайте указанията за да инсталирате програмата.
  • След като инсталацията приключи програмата ще стартира автоматично.
  • Отидете до табът Settings => Protection > и под категорията Scan Options включете опцията "Scan for rootkits" като преместите плъзгача надясно.

xTvORSF.png

  • Отидете до табът Scan, и изберете Threat Scan и след това натиснете бутона Start Scan.

RUSrqgW.png

  • Ще започне проверка за зловреден софтуер.

4CJ90KI.png

  • При някои инфекции можете да видите съобщението:
  • "Could not load DDA driver"
  • Натиснете "Yes" на това съобщение за да позволите драйвера да се зареди след рестарт.
  • Разрешете на компютъра да се рестартира и след това продължете с останалите инструкции.
  • След като проверката приключи ще се появи списъка с резултатите (ако има намерени обекти). Ако програмата е минимизирана докато сканира ще се появи следното съобщение ако има открити заплахи. Натиснете бутона View Scan Results.

37b.png

  • . Натиснете бутона Quarantine Selected.

2CfXEk1.png

  • Изчакайте да се появи прозореца подканващ ви да рестартирате и след това натиснете бутона Yes.

8Jc9dl9.png

  • След рестарта, стартирайте отново Malwarebytes Anti-Malware.
  • Отидете то табът Reports и отворете лог файла с името Scan Report.

X0ha4sd.png

  • Натиснете бутона Export и след това =>  "Copy to Clipboard"

fE9qzai.png

  • Сега вече поставете съдържанието на лог файла с клавишната комбинация Ctrl + V и го публикувайте в следващия си коментар.

 

СТЪПКА 3

 

Имате липсващи драйвери за чипсета и за USB контролера според лог файла в Device Manager-a:

Цитат

Name: SM Bus Controller
Description: SM Bus Controller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

 

Цитат

Name: Universal Serial Bus (USB) Controller
Description: Universal Serial Bus (USB) Controller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Желателно е да ги изтеглите и инсталирате от сайта на производителя на дънната платка.

 

Поздрави!

  • Автор

Fix result of Farbar Recovery Scan Tool (x64) Version: 14.03.2018
Ran by Stefan (16-03-2018 03:28:42) Run:2
Running from C:\Users\Stefan\Downloads
Loaded Profiles: Stefan (Available Profiles: Stefan)
Boot Mode: Normal
==============================================

fixlist content:
*****************
start
CloseProcesses:
Tcpip\Parameters: [NameServer] 82.163.143.176 82.163.142.178
Tcpip\..\Interfaces\{083BFCEF-CB63-4EA3-A4FF-CEE046393EDD}: [NameServer] 82.163.143.176 82.163.142.178
Tcpip\..\Interfaces\{083BFCEF-CB63-4EA3-A4FF-CEE046393EDD}: [DhcpNameServer] 82.163.143.176
Tcpip\..\Interfaces\{2E27C145-51D0-4556-9C2C-0E2441CFD2DE}: [NameServer] 82.163.143.176 82.163.142.178
Tcpip\..\Interfaces\{2E27C145-51D0-4556-9C2C-0E2441CFD2DE}: [DhcpNameServer] 82.163.143.176
Tcpip\..\Interfaces\{82F15432-F21B-4575-809F-754B40549B71}: [NameServer] 82.163.143.176 82.163.142.178
Tcpip\..\Interfaces\{82F15432-F21B-4575-809F-754B40549B71}: [DhcpNameServer] 82.163.143.176
Tcpip\..\Interfaces\{8FEEE6C2-2C34-4DE5-9AD1-F9A1B13F1A84}: [NameServer] 82.163.143.176 82.163.142.178
Tcpip\..\Interfaces\{CE8462F4-4F8C-4B6A-A02E-5901E757BD66}: [NameServer] 82.163.143.176 82.163.142.178
Tcpip\..\Interfaces\{CE8462F4-4F8C-4B6A-A02E-5901E757BD66}: [DhcpNameServer] 82.163.143.176
C:\Users\Stefan\Downloads\JavaSetup_0062159658.exe
Startbatch:
@echo off
net stop BITS
ipconfig /flushdns
ren "%programdata%\Microsoft\Network\Downloader\qmgr0.dat" qmgr0.dat.old
ren "%programdata%\Microsoft\Network\Downloader\qmgr1.dat" qmgr1.dat.old
net start BITS
Endbatch:
cmd: bitsadmin /reset /allusers
powershell: Get-BitsTransfer -AllUsers
powershell: Get-BitsTransfer -AllUsers | select -ExpandProperty FileList
Reg: reg add "HKLM\System\CurrentControlSet\Control" /v ServicesPipeTimeout /t REG_DWORD /d 100000 /f
ListPermissions: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5D1C589F-15A4-4C58-BE41-207238A3B1B8}
ListPermissions: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\One System CarePeriod
ListPermissions: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6DB54783-F182-4B03-9E04-B101842355EC}
ListPermissions: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\One System Care Monitor
ListPermissions: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7B1535FD-4542-462B-B24F-0C9B6A2F45E6}
ListPermissions: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OneSystemCare Task
ListPermissions: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C2B3DCFA-9FEE-4D30-A28C-60E3D0BCABAB
ListPermissions: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{090B0547-7804-0879-0F11-7F0D7F08110B}
ListPermissions: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E2E19E8B-9B87-4E7C-83CB-6887DD992CBE}
ListPermissions: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\One System Care Delayed
Unlock: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5D1C589F-15A4-4C58-BE41-207238A3B1B8}
Unlock: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\One System CarePeriod
Unlock: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6DB54783-F182-4B03-9E04-B101842355EC}
Unlock: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\One System Care Monitor
Unlock: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7B1535FD-4542-462B-B24F-0C9B6A2F45E6}
Unlock: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OneSystemCare Task
Unlock: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C2B3DCFA-9FEE-4D30-A28C-60E3D0BCABAB
Unlock: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{090B0547-7804-0879-0F11-7F0D7F08110B}
Unlock: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E2E19E8B-9B87-4E7C-83CB-6887DD992CBE}
Unlock: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\One System Care Delayed
Task: {5D1C589F-15A4-4C58-BE41-207238A3B1B8} - System32\Tasks\One System CarePeriod => C:\Program Files (x86)\OneSystemCare\OneSystemCare.exe [2018-02-26] () <==== ATTENTION
Task: {6DB54783-F182-4B03-9E04-B101842355EC} - System32\Tasks\One System Care Monitor => C:\Program Files (x86)\OneSystemCare\CleanupConsole.exe [2018-02-26] () <==== ATTENTION
Task: {7B1535FD-4542-462B-B24F-0C9B6A2F45E6} - System32\Tasks\OneSystemCare Task => C:\Program Files (x86)\OneSystemCare\SystemConsole.exe [2018-02-26] () <==== ATTENTION
Task: {89B5ED8A-A2C3-4DE5-9DDA-11DDB42ADD9A} - System32\Tasks\5A431ED8-BAC5-ECA5-E830-978D5C3B4E31 => C:\Windows\SysWOW64\regsvr32.exe /n /s /i:"/02c2319629550762 /q" "C:\Users\Stefan\AppData\Local\85A0D816-3ABA-0B19-770D-C62137D36FB8\{EE71FB67-529F-73C7-7123-D16B2568DE78}.."
Task: {A9FC4A58-3C57-4EEB-BC14-CAC9EABB210B} - System32\Tasks\{CAADFADF-EC91-42D5-AEAA-CDCB1A45B15A} => C:\Windows\system32\regsvr32.exe /s /n /i:"/rt" "C:\PROGRA~3\9db6a9f8\ee71fb67.dll" <==== ATTENTION
Task: {C2B3DCFA-9FEE-4D30-A28C-60E3D0BCABAB} - System32\Tasks\{090B0547-7804-0879-0F11-7F0D7F08110B} => C:\Windows\system32\WindowsPowershell\v1.0\powershell.exe -nologo -executionpolicy bypass -noninteractive -windowstyle hidden -EncodedCommand IAA7ADsAOwAgADsAIAAgACAAIAAkAEUAcgByAG8AcgBBAGMAdABpAG8AbgBQAHIAZQBmAGUAcgBlAG4AYwBlAD0AIgBzAHQAbwBwACIAOwAkAHMAYwA9ACIAUwBpAGwAZQBuAHQAbAB5AEMAbwBuAHQAaQBuAHUAZQAiADsAJABXAGEAcgBuAGkAbgBnAFAAcgBlAGYAZQByAGUAbgBjAGUA (the data entry has 9944 more characters). <==== ATTENTION
Task: {E2E19E8B-9B87-4E7C-83CB-6887DD992CBE} - System32\Tasks\One System Care Delayed => C:\Program Files (x86)\OneSystemCare\OneSystemCare.exe [2018-02-26] () <==== ATTENTION
Task: C:\Windows\Tasks\One System CarePeriod.job => C:\Program Files (x86)\OneSystemCare\OneSystemCare.exe <==== ATTENTION
Unlock: HKCR\CLSID\{4EB61BAC-A3B6-4760-9581-655041EF4D69}
Reg: reg query HKCR\CLSID\{4EB61BAC-A3B6-4760-9581-655041EF4D69} /s
CMD: vssadmin list shadowstorage
CMD: vssadmin delete shadows /all
CMD: vssadmin Resize ShadowStorage /For=C: /On=C: /MaxSize=5GB
CreateRestorePoint:
end
*****************

Processes closed successfully.
"HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\\NameServer" => removed successfully
"HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{083BFCEF-CB63-4EA3-A4FF-CEE046393EDD}\\NameServer" => removed successfully
"HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{083BFCEF-CB63-4EA3-A4FF-CEE046393EDD}\\DhcpNameServer" => removed successfully
"HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2E27C145-51D0-4556-9C2C-0E2441CFD2DE}\\NameServer" => removed successfully
"HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2E27C145-51D0-4556-9C2C-0E2441CFD2DE}\\DhcpNameServer" => not found
"HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{82F15432-F21B-4575-809F-754B40549B71}\\NameServer" => removed successfully
"HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{82F15432-F21B-4575-809F-754B40549B71}\\DhcpNameServer" => removed successfully
"HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8FEEE6C2-2C34-4DE5-9AD1-F9A1B13F1A84}\\NameServer" => removed successfully
"HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{CE8462F4-4F8C-4B6A-A02E-5901E757BD66}\\NameServer" => removed successfully
"HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{CE8462F4-4F8C-4B6A-A02E-5901E757BD66}\\DhcpNameServer" => not found
C:\Users\Stefan\Downloads\JavaSetup_0062159658.exe => moved successfully

========= Batch: =========
The Background Intelligent Transfer Service service is stopping..
The Background Intelligent Transfer Service service was stopped successfully.


Windows IP Configuration

Successfully flushed the DNS Resolver Cache.
The Background Intelligent Transfer Service service is starting.
The Background Intelligent Transfer Service service was started successfully.


========= End of Batch: =========


========= bitsadmin /reset /allusers =========


BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

0 out of 0 jobs canceled.

========= End of CMD: =========


========= Get-BitsTransfer -AllUsers =========


========= End of Powershell: =========


========= Get-BitsTransfer -AllUsers | select -ExpandProperty FileList =========


========= End of Powershell: =========


========= reg add "HKLM\System\CurrentControlSet\Control" /v ServicesPipeTimeout /t REG_DWORD /d 100000 /f =========

ЋЇҐа жЁпв  § ўкаиЁ гбЇҐи­®.

 

========= End of Reg: =========


"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5D1C589F-15A4-4C58-BE41-207238A3B1B8}" -> Getting permissions failed. key not found.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\One System CarePeriod" -> Getting permissions failed. key not found.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6DB54783-F182-4B03-9E04-B101842355EC}" -> Getting permissions failed. key not found.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\One System Care Monitor" -> Getting permissions failed. key not found.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7B1535FD-4542-462B-B24F-0C9B6A2F45E6}" -> Getting permissions failed. key not found.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OneSystemCare Task" -> Getting permissions failed. key not found.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C2B3DCFA-9FEE-4D30-A28C-60E3D0BCABAB" -> Getting permissions failed. key not found.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{090B0547-7804-0879-0F11-7F0D7F08110B}" -> Getting permissions failed. key not found.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E2E19E8B-9B87-4E7C-83CB-6887DD992CBE}" -> Getting permissions failed. key not found.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\One System Care Delayed" -> Getting permissions failed. key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5D1C589F-15A4-4C58-BE41-207238A3B1B8}" => key could not be unlocked
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\One System CarePeriod" => key could not be unlocked
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6DB54783-F182-4B03-9E04-B101842355EC}" => key could not be unlocked
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\One System Care Monitor" => key could not be unlocked
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7B1535FD-4542-462B-B24F-0C9B6A2F45E6}" => key could not be unlocked
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OneSystemCare Task" => key could not be unlocked
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C2B3DCFA-9FEE-4D30-A28C-60E3D0BCABAB" => key could not be unlocked
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{090B0547-7804-0879-0F11-7F0D7F08110B}" => key could not be unlocked
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E2E19E8B-9B87-4E7C-83CB-6887DD992CBE}" => key could not be unlocked
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\One System Care Delayed" => key could not be unlocked
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5D1C589F-15A4-4C58-BE41-207238A3B1B8} => could not remove. Access Denied.
"C:\Windows\System32\Tasks\One System CarePeriod" => not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\One System CarePeriod => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6DB54783-F182-4B03-9E04-B101842355EC} => could not remove. Access Denied.
"C:\Windows\System32\Tasks\One System Care Monitor" => not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\One System Care Monitor => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7B1535FD-4542-462B-B24F-0C9B6A2F45E6} => could not remove. Access Denied.
"C:\Windows\System32\Tasks\OneSystemCare Task" => not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OneSystemCare Task => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{89B5ED8A-A2C3-4DE5-9DDA-11DDB42ADD9A} => could not remove. Access Denied.
"C:\Windows\System32\Tasks\5A431ED8-BAC5-ECA5-E830-978D5C3B4E31" => not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\5A431ED8-BAC5-ECA5-E830-978D5C3B4E31 => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A9FC4A58-3C57-4EEB-BC14-CAC9EABB210B} => could not remove. Access Denied.
"C:\Windows\System32\Tasks\{CAADFADF-EC91-42D5-AEAA-CDCB1A45B15A}" => not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{CAADFADF-EC91-42D5-AEAA-CDCB1A45B15A} => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C2B3DCFA-9FEE-4D30-A28C-60E3D0BCABAB} => could not remove. Access Denied.
"C:\Windows\System32\Tasks\{090B0547-7804-0879-0F11-7F0D7F08110B}" => not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{090B0547-7804-0879-0F11-7F0D7F08110B} => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E2E19E8B-9B87-4E7C-83CB-6887DD992CBE} => could not remove. Access Denied.
"C:\Windows\System32\Tasks\One System Care Delayed" => not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\One System Care Delayed => could not remove. Access Denied.
"C:\Windows\Tasks\One System CarePeriod.job" => not found
"HKCR\CLSID\{4EB61BAC-A3B6-4760-9581-655041EF4D69}" => key could not be unlocked

========= reg query HKCR\CLSID\{4EB61BAC-A3B6-4760-9581-655041EF4D69} /s =========

ERROR: The system was unable to find the specified registry key or value.


========= End of Reg: =========


========= vssadmin list shadowstorage =========

vssadmin 1.1 - Volume Shadow Copy Service administrative command-line tool
(C) Copyright 2001-2005 Microsoft Corp.

Shadow Copy Storage association
   For volume: (C:)\\?\Volume{e0d9951c-0022-11e8-9019-806e6f6e6963}\
   Shadow Copy Storage volume: (C:)\\?\Volume{e0d9951c-0022-11e8-9019-806e6f6e6963}\
   Used Shadow Copy Storage space: 817.656 MB (0%)
   Allocated Shadow Copy Storage space: 1.281 GB (0%)
   Maximum Shadow Copy Storage space: 10 GB (2%)


========= End of CMD: =========


========= vssadmin delete shadows /all =========

vssadmin 1.1 - Volume Shadow Copy Service administrative command-line tool
(C) Copyright 2001-2005 Microsoft Corp.

Do you really want to delete 1 shadow copies (Y/N): [N]? N


========= End of CMD: =========


========= vssadmin Resize ShadowStorage /For=C: /On=C: /MaxSize=5GB =========

vssadmin 1.1 - Volume Shadow Copy Service administrative command-line tool
(C) Copyright 2001-2005 Microsoft Corp.

Successfully resized the shadow copy storage association

========= End of CMD: =========

Restore point was successfully created.

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 16-03-2018 03:31:03)


Result of scheduled keys to remove after reboot:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5D1C589F-15A4-4C58-BE41-207238A3B1B8} => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\One System CarePeriod => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6DB54783-F182-4B03-9E04-B101842355EC} => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\One System Care Monitor => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7B1535FD-4542-462B-B24F-0C9B6A2F45E6} => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OneSystemCare Task => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{89B5ED8A-A2C3-4DE5-9DDA-11DDB42ADD9A} => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\5A431ED8-BAC5-ECA5-E830-978D5C3B4E31 => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A9FC4A58-3C57-4EEB-BC14-CAC9EABB210B} => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{CAADFADF-EC91-42D5-AEAA-CDCB1A45B15A} => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C2B3DCFA-9FEE-4D30-A28C-60E3D0BCABAB} => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{090B0547-7804-0879-0F11-7F0D7F08110B} => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E2E19E8B-9B87-4E7C-83CB-6887DD992CBE} => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\One System Care Delayed => could not remove. Access Denied.

==== End of Fixlog 03:31:03 ====

 

Това са резултатите от стъпка 1.

  • Автор

Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 3/16/18
Scan Time: 3:35 AM
Log File: 4c4957d2-28ba-11e8-a645-3085a9164318.json
Administrator: Yes

-Software Information-
Version: 3.4.4.2398
Components Version: 1.0.322
Update Package Version: 1.0.4374
License: Trial

-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Stefan-PC\Stefan

-Scan Summary-
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 239624
Threats Detected: 12
Threats Quarantined: 11
Time Elapsed: 3 min, 45 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 3
PUP.Optional.PSScriptLoad.ACMB3, HKU\S-1-5-21-1138422693-3855770178-890708622-1000\CONSOLE\%SYSTEMROOT%_SYSTEM32_SVCHOST.EXE, Quarantined, [5048], [425124],1.0.4374
PUP.Optional.PSScriptLoad.ACMB3, HKU\S-1-5-21-1138422693-3855770178-890708622-1000\CONSOLE\TASKENG.EXE, Quarantined, [5048], [425125],1.0.4374
PUP.Optional.DNSUnlocker.ACMB2, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{9db6a9f8}, Quarantined, [20], [260250],1.0.4374

Registry Value: 4
PUP.Optional.PSScriptLoad.ACMB3, HKU\S-1-5-21-1138422693-3855770178-890708622-1000\CONSOLE\%SYSTEMROOT%_SYSTEM32_WINDOWSPOWERSHELL_V1.0_POWERSHELL.EXE|WINDOWPOSITION, Quarantined, [5048], [425126],1.0.4374
PUP.Optional.PSScriptLoad.ACMB3, HKU\S-1-5-21-1138422693-3855770178-890708622-1000\CONSOLE\%SYSTEMROOT%_SYSTEM32_SVCHOST.EXE|WINDOWPOSITION, Quarantined, [5048], [425124],1.0.4374
PUP.Optional.PSScriptLoad.ACMB3, HKU\S-1-5-21-1138422693-3855770178-890708622-1000\CONSOLE\TASKENG.EXE|WINDOWPOSITION, Quarantined, [5048], [425125],1.0.4374
PUP.Optional.DNSUnlocker.ACMB2, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{9db6a9f8}|1, Quarantined, [20], [260250],1.0.4374

Registry Data: 2
PUP.Optional.DNSUnlocker.ACMB2, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS|DhcpNameServer, Replaced, [20], [-1],0.0.0
PUP.Optional.DNSUnlocker.ACMB2, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{8FEEE6C2-2C34-4DE5-9AD1-F9A1B13F1A84}|DhcpNameServer, Replaced, [20], [-1],0.0.0

Data Stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 3
Generic.Malware/Suspicious, C:\WINDOWS\SYSWOW64\FIWLLC.EXE, Quarantined, [0], [392686],1.0.4374
Backdoor.Agent.RND, C:\WINDOWS\SYSWOW64\FIWLLC.EXE, Quarantined, [1351], [56646],1.0.4374
PUP.Optional.OpenCandy, C:\USERS\STEFAN\DOWNLOADS\DAEMON TOOLS LITE 10.0.0.54.EXE, Removal Failed, [478], [297667],1.0.4374

Physical Sector: 0
(No malicious items detected)


(end)

 

Това са резултатите от стъпка 2.

  • Автор

Ако може да ме опътите малко за стъпка 3, защото въобще не съм наясно кой е производителя и откъде се инсталират тези драйвъри...

СТЪПКА 1

 

Свалете програмата software.gif HWiNFO64

Разархивирайте програмата и стартирайте файла - HWiNFO64.exe. Ще се появи следния прозорец:
e2991178c154ba7b.jpg

Натиснете Run.
Изчакайте търпеливо. След това изберете Save Report и HTML формат и натиснете Browse.

Посочете вашия десктоп и натиснете Next.

0897c918f37fc402.jpg

Ще се появява се Report Filter, изберете Finish.

На десктопа ще се появи HTML файл с име "User Name-PC.HTM", където "User Name" е името на компютъра Ви (например файла от снимката се казва HOLLER-PC.HTM). Качете файла тук и публикувайте линка за download в следващия си пост.

 

СТЪПКА 2

 

Направете и нова проверка с FRST и публикувайте новите два лог файлове. Почти сме готови, но искам да проверя още едно-две неща преди да приключим.

 

А иначе ще пиша след 17.00, защото ще съм зает с лични ангажименти преди това.

 

Поздрави!

Да не би да сте в Safe Mode (безопасен режим)?

https://www.hwinfo.com/forum/Thread-Check-user-rights-and-antivirus-filters

Иначе според снимката сте изтеглили версия 5.79, която е бета, а не тази, която съм дал 5.74.

Да пробваме с CPU-Z. Ако и тя не иска да стартира значи нещо пречи на инсталирането на драйверите на програмите.

Изтеглете CPU-Z:

https://www.cpuid.com/downloads/cpu-z/cpu-z_1.83-en.zip

Разархивирайте файла и стартирайте с десен бутон Run As Administrator файла cpuz_x64.exe

Отидете до Mainboard и направете снимка за да видя модела на дъното.

Поздрави!

По-скоро извлечи всички....Не сте разархивирали файла...първо разархивирате и след това стартирате с десен бутон Run as administrator.

Би трябвало да са това:

http://dlcdnet.asus.com/pub/ASUS/nb/Drivers/Chipset/Chipset_Intel_INFUpdate_Win7_64_Z9301019.zip

http://dlcdnet.asus.com/pub/ASUS/nb/Drivers/USB3.0/USB3_Asmedia_Win7_64_Z11440.zip

Изтеглете архивите един по един, разархивирайте ги и ги инсталирайте един по един и след това рестартирайте.

След това направете нова проверка с FRST и публикувайте новите лог файлове.

Поздрави!

  • Автор

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14.03.2018
Ran by Stefan (administrator) on STEFAN-PC (16-03-2018 20:09:36)
Running from C:\Users\Stefan\Downloads
Loaded Profiles: Stefan (Available Profiles: Stefan)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Български (България)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
(Discord Inc.) C:\Users\Stefan\AppData\Local\Discord\app-0.0.300\Discord.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
(Nota Inc.) C:\Program Files (x86)\Gyazo\GyStation.exe
(Overwolf LTD) C:\Program Files (x86)\Overwolf\Overwolf.exe
(Overwolf LTD) C:\Program Files (x86)\Overwolf\0.111.1.28\OverwolfBrowser.exe
(Overwolf LTD) C:\Program Files (x86)\Overwolf\0.111.1.28\OverwolfBrowser.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Overwolf LTD) C:\Program Files (x86)\Common Files\Overwolf\0.111.1.28\OverwolfHelper.exe
(Overwolf LTD) C:\Program Files (x86)\Common Files\Overwolf\0.111.1.28\OverwolfHelper64.exe
(Discord Inc.) C:\Users\Stefan\AppData\Local\Discord\app-0.0.300\Discord.exe
(Discord Inc.) C:\Users\Stefan\AppData\Local\Discord\app-0.0.300\Discord.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [112512 2010-03-13] (Microsoft Corporation)
HKU\S-1-5-21-1138422693-3855770178-890708622-1000\...\Run: [Overwolf] => C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe [1207112 2018-03-05] ()
HKU\S-1-5-21-1138422693-3855770178-890708622-1000\...\Run: [Skype for Desktop] => C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe [50100160 2018-03-02] (Skype Technologies S.A.)
HKU\S-1-5-21-1138422693-3855770178-890708622-1000\...\Run: [Discord] => C:\Users\Stefan\AppData\Local\Discord\app-0.0.300\Discord.exe [57821176 2018-01-08] (Discord Inc.)
HKU\S-1-5-21-1138422693-3855770178-890708622-1000\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4471536 2015-05-21] (Disc Soft Ltd)
HKU\S-1-5-21-1138422693-3855770178-890708622-1000\...\Run: [Gyazo] => C:\Program Files (x86)\Gyazo\GyStation.exe [5345672 2017-12-21] (Nota Inc.)
HKU\S-1-5-21-1138422693-3855770178-890708622-1000\...\MountPoints2: {f58cc662-09e3-11e8-8edf-606c665b70ec} - F:\SETUP.EXE
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [181280 2017-01-25] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [158392 2017-01-25] (NVIDIA Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{083BFCEF-CB63-4EA3-A4FF-CEE046393EDD}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{2E27C145-51D0-4556-9C2C-0E2441CFD2DE}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{82F15432-F21B-4575-809F-754B40549B71}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{8FEEE6C2-2C34-4DE5-9AD1-F9A1B13F1A84}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{8FEEE6C2-2C34-4DE5-9AD1-F9A1B13F1A84}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{CE8462F4-4F8C-4B6A-A02E-5901E757BD66}: [NameServer] 8.8.8.8

Internet Explorer:
==================
HKU\S-1-5-21-1138422693-3855770178-890708622-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2011-02-12] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2011-02-12] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation)

FireFox:
========
FF DefaultProfile: 5mi4sz4p.default
FF ProfilePath: C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\5mi4sz4p.default [2018-03-16]
FF Extension: (Adblock Plus) - C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\5mi4sz4p.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2018-01-26]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_29_0_0_113.dll [2018-03-14] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_29_0_0_113.dll [2018-03-14] ()
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2018-01-23] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2018-01-23] (Google Inc.)

Chrome:
=======
CHR Profile: C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default [2018-03-16]
CHR Extension: (Slides) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-01-23]
CHR Extension: (Docs) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-01-23]
CHR Extension: (Google Drive) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-01-23]
CHR Extension: (YouTube) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-01-23]
CHR Extension: (Foxtrick) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpfbbngccefbbndginomofgpagkjckik [2018-01-26]
CHR Extension: (Sheets) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-01-23]
CHR Extension: (Google Docs Offline) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-01-23]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-01-23]
CHR Extension: (Gmail) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-01-23]
CHR Extension: (Chrome Media Router) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-03-09]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1272560 2015-05-21] (Disc Soft Ltd)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [330136 2015-08-27] (Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6440736 2018-03-03] (Malwarebytes)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2011-12-08] ()
S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [1452360 2018-03-05] (Overwolf LTD)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10945776 2017-12-15] (TeamViewer GmbH)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [594704 2011-12-08] (Intel® Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem"

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2018-02-28] (Disc Soft Ltd)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [76200 2018-01-18] ()
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [193248 2018-03-16] (Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [109800 2018-03-16] (Malwarebytes)
R0 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [253664 2018-03-16] (Malwarebytes)
R3 MBAMWebProtection; C:\Windows\System32\DRIVERS\mwac.sys [92280 2018-03-16] (Malwarebytes)
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-03-16 20:04 - 2018-03-16 20:03 - 000053248 _____ (Windows XP Bundled build C-Centric Single User) C:\Windows\SysWOW64\CSVer.dll
2018-03-16 20:03 - 2018-03-16 20:03 - 000000000 ____D C:\Users\Stefan\Desktop\Chipset_Intel_INFUpdate_Win7_64_Z9301019
2018-03-16 20:01 - 2018-03-16 20:01 - 003594036 _____ C:\Users\Stefan\Desktop\USB3_Asmedia_Win7_64_Z11440(1).zip
2018-03-16 20:01 - 2018-03-16 20:01 - 003013588 _____ C:\Users\Stefan\Desktop\Chipset_Intel_INFUpdate_Win7_64_Z9301019.zip
2018-03-16 20:01 - 2018-03-16 20:01 - 000000000 ____D C:\Users\Stefan\Desktop\USB3_Asmedia_Win7_64_Z11440(1)
2018-03-16 18:46 - 2018-03-16 18:46 - 000000000 ____D C:\Users\Stefan\Desktop\cpu-z_1.83-en
2018-03-16 18:26 - 2018-03-16 18:26 - 002675398 _____ C:\Users\Stefan\Desktop\cpu-z_1.83-en.zip
2018-03-16 13:42 - 2018-03-16 13:42 - 000003414 _____ C:\Windows\System32\Tasks\GyazoUpdateTaskMachineDaily
2018-03-16 13:42 - 2018-03-16 13:42 - 000003288 _____ C:\Windows\System32\Tasks\GyazoUpdateTaskMachine
2018-03-16 13:42 - 2018-03-16 13:42 - 000000982 _____ C:\Users\Public\Desktop\Gyazo.lnk
2018-03-16 13:42 - 2018-03-16 13:42 - 000000982 _____ C:\Users\Public\Desktop\Gyazo GIF.lnk
2018-03-16 13:42 - 2018-03-16 13:42 - 000000000 ____D C:\Users\Stefan\AppData\Roaming\Gyazo
2018-03-16 13:42 - 2018-03-16 13:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gyazo
2018-03-16 13:42 - 2018-03-16 13:42 - 000000000 ____D C:\Program Files (x86)\Gyazo
2018-03-16 13:41 - 2018-03-16 13:41 - 011007976 _____ (Nota Inc. ) C:\Users\Stefan\Downloads\Gyazo-3.3.5.exe
2018-03-16 13:40 - 2018-03-16 13:40 - 000000000 ____D C:\Users\Stefan\Desktop\hwi_579_3383
2018-03-16 13:38 - 2018-03-16 13:38 - 008263316 _____ C:\Users\Stefan\Desktop\hwi_579_3383.zip
2018-03-16 03:34 - 2018-03-16 20:07 - 000109800 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2018-03-16 03:34 - 2018-03-16 20:07 - 000092280 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2018-03-16 03:34 - 2018-03-16 03:34 - 000253664 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2018-03-16 03:34 - 2018-03-16 03:34 - 000193248 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2018-03-16 03:34 - 2018-03-16 03:34 - 000001867 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2018-03-16 03:34 - 2018-03-16 03:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-03-16 03:34 - 2018-01-18 08:03 - 000076200 _____ C:\Windows\system32\Drivers\mbae64.sys
2018-03-16 03:33 - 2018-03-16 03:33 - 068724528 _____ (Malwarebytes ) C:\Users\Stefan\Desktop\mb3-setup-consumer-3.4.4.2398-1.0.322-1.0.4190.exe
2018-03-16 03:33 - 2018-03-16 03:33 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-03-16 03:33 - 2018-03-16 03:33 - 000000000 ____D C:\Program Files\Malwarebytes
2018-03-16 03:28 - 2018-03-16 03:27 - 000006035 ____R C:\Users\Stefan\Downloads\fixlist.txt
2018-03-16 00:43 - 2018-03-16 00:43 - 000001306 _____ C:\Users\Public\Desktop\Skype.lnk
2018-03-16 00:37 - 2018-03-16 00:40 - 000000000 ____D C:\AdwCleaner
2018-03-16 00:37 - 2018-03-16 00:37 - 008222496 _____ (Malwarebytes) C:\Users\Stefan\Downloads\adwcleaner_7.0.8.0.exe
2018-03-16 00:31 - 2018-03-16 03:45 - 000639002 _____ C:\Windows\system32\perfh002.dat
2018-03-16 00:31 - 2018-03-16 03:45 - 000113690 _____ C:\Windows\system32\perfc002.dat
2018-03-16 00:31 - 2018-03-16 03:31 - 000018386 _____ C:\Users\Stefan\Downloads\Fixlog.txt
2018-03-16 00:27 - 2018-03-16 00:27 - 000000000 ____D C:\Users\Stefan\AppData\Roaming\Geek Uninstaller
2018-03-16 00:26 - 2018-03-16 00:27 - 002555831 _____ C:\Users\Stefan\Desktop\geek.zip
2018-03-15 20:51 - 2018-03-15 20:51 - 000026103 _____ C:\Users\Stefan\Desktop\Addition.txt
2018-03-15 19:55 - 2018-03-15 20:51 - 000026103 _____ C:\Users\Stefan\Downloads\Addition.txt
2018-03-15 19:54 - 2018-03-16 20:10 - 000012038 _____ C:\Users\Stefan\Downloads\FRST.txt
2018-03-15 19:54 - 2018-03-16 20:09 - 000000000 ____D C:\FRST
2018-03-15 19:54 - 2018-03-15 19:54 - 002403328 _____ (Farbar) C:\Users\Stefan\Downloads\FRST64.exe
2018-03-14 19:40 - 2018-03-14 19:40 - 000004466 _____ C:\Windows\System32\Tasks\Adobe Flash Player NPAPI Notifier
2018-02-28 22:04 - 2018-02-28 22:04 - 000000000 ____D C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2018-02-28 22:03 - 2018-02-28 22:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
2018-02-28 22:03 - 2018-02-28 22:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2018-02-28 22:03 - 2018-02-28 22:03 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2018-02-28 22:02 - 2018-02-28 22:02 - 000000000 ____D C:\Windows\PCHEALTH
2018-02-28 22:02 - 2018-02-28 22:02 - 000000000 ____D C:\Program Files\Microsoft Synchronization Services
2018-02-28 22:02 - 2018-02-28 22:02 - 000000000 ____D C:\Program Files\Microsoft Sync Framework
2018-02-28 22:02 - 2018-02-28 22:02 - 000000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition
2018-02-28 22:00 - 2018-02-28 22:00 - 000000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 8
2018-02-28 21:59 - 2018-02-28 22:03 - 000000000 ____D C:\Windows\SHELLNEW
2018-02-28 21:59 - 2018-02-28 22:02 - 000000000 ____D C:\Program Files\Microsoft Office
2018-02-28 21:59 - 2018-02-28 21:59 - 000000000 __RHD C:\MSOCache
2018-02-28 21:59 - 2018-02-28 21:59 - 000000000 ____D C:\Users\Stefan\AppData\Local\Microsoft Help
2018-02-28 21:59 - 2018-02-28 21:59 - 000000000 ____D C:\Program Files\Microsoft Analysis Services
2018-02-28 21:59 - 2018-02-28 21:59 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2018-02-28 21:59 - 2018-02-28 21:59 - 000000000 ____D C:\Program Files (x86)\Microsoft Analysis Services
2018-02-28 21:58 - 2018-02-28 21:58 - 000000000 ____D C:\Users\Stefan\AppData\Local\Disc_Soft_Ltd
2018-02-28 21:57 - 2018-02-28 21:58 - 000000000 ____D C:\Users\Stefan\AppData\Roaming\DAEMON Tools Lite
2018-02-28 21:57 - 2018-02-28 21:57 - 000030264 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtlitescsibus.sys
2018-02-28 21:57 - 2018-02-28 21:57 - 000000000 ____D C:\Program Files\DAEMON Tools Lite
2018-02-28 21:56 - 2018-02-28 21:57 - 000000000 ____D C:\ProgramData\DAEMON Tools Lite
2018-02-28 21:56 - 2018-02-28 21:56 - 019312736 ____R (Disc Soft Ltd) C:\Users\Stefan\Downloads\DAEMON Tools Lite 10.0.0.54.exe
2018-02-28 21:47 - 2018-02-28 21:47 - 000000000 ____D C:\Users\Stefan\Downloads\Microsoft Office Professional Plus 2010 with Service Pack 1 VL EN x64
2018-02-24 19:24 - 2018-02-24 19:24 - 000071680 _____ C:\Users\Stefan\Downloads\Klasirane Ataka 2016.xls
2018-02-14 03:25 - 2018-02-14 03:25 - 000000000 ____D C:\Users\Stefan\AppData\Local\TeamViewer
2018-02-14 03:19 - 2018-02-15 02:52 - 000000000 ____D C:\Users\Stefan\Documents\888poker
2018-02-14 03:18 - 2018-02-14 20:26 - 000001953 _____ C:\Users\Stefan\Desktop\888poker.lnk
2018-02-14 03:18 - 2018-02-14 20:26 - 000000000 ____D C:\Users\Stefan\AppData\Roaming\pacificpoker
2018-02-14 03:18 - 2018-02-14 20:26 - 000000000 ____D C:\Users\Stefan\AppData\Roaming\InstallShield Installation Information
2018-02-14 03:18 - 2018-02-14 20:26 - 000000000 ____D C:\Users\Stefan\AppData\Local\Downloaded Installations
2018-02-14 03:18 - 2018-02-14 03:18 - 000000000 ____D C:\Program Files (x86)\PacificPoker
2018-02-14 03:17 - 2018-02-14 03:18 - 000000000 ____D C:\Users\Stefan\Documents\PokerInstallerLogs
2018-02-14 03:17 - 2018-02-14 03:17 - 000641328 _____ (Random-Logic) C:\Users\Stefan\Downloads\888poker_installer.exe

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-03-16 20:07 - 2018-02-03 00:58 - 000000000 ____D C:\Users\Stefan\AppData\Local\Overwolf
2018-03-16 20:07 - 2018-01-23 12:38 - 000000000 __SHD C:\Users\Stefan\IntelGraphicsProfiles
2018-03-16 20:06 - 2018-01-23 12:34 - 000000000 ____D C:\ProgramData\NVIDIA
2018-03-16 20:06 - 2009-07-14 07:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-03-16 20:04 - 2018-01-23 12:33 - 000000000 ____D C:\Program Files (x86)\Intel
2018-03-16 20:04 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\inf
2018-03-16 19:56 - 2009-07-14 06:45 - 000026112 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-03-16 19:56 - 2009-07-14 06:45 - 000026112 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-03-16 15:58 - 2018-01-23 12:48 - 000003974 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{5D3F7C17-CFD3-45C5-AD70-212AB69F4E91}
2018-03-16 15:21 - 2018-01-26 17:47 - 000000000 ____D C:\Users\Stefan\AppData\Local\Battle.net
2018-03-16 14:40 - 2018-01-26 17:46 - 000000000 ____D C:\Program Files (x86)\Battle.net
2018-03-16 03:45 - 2009-07-14 07:13 - 001492576 _____ C:\Windows\system32\PerfStringBackup.INI
2018-03-16 00:43 - 2018-02-08 23:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2018-03-16 00:32 - 2018-02-06 22:50 - 000000000 ____D C:\Users\Stefan\AppData\LocalLow\Temp
2018-03-14 19:40 - 2018-01-26 18:30 - 000804352 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2018-03-14 19:40 - 2018-01-26 18:30 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2018-03-14 19:40 - 2018-01-26 18:30 - 000004324 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2018-03-14 19:40 - 2018-01-26 18:30 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2018-03-14 19:40 - 2018-01-26 18:30 - 000000000 ____D C:\Windows\system32\Macromed
2018-03-14 01:09 - 2018-01-23 13:03 - 000002222 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-03-14 01:09 - 2018-01-23 13:03 - 000002181 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-03-12 19:34 - 2018-01-26 17:50 - 000000000 ____D C:\Program Files (x86)\Hearthstone
2018-03-08 20:59 - 2018-02-03 00:59 - 000000000 ____D C:\Program Files (x86)\Overwolf
2018-03-06 01:54 - 2018-02-10 01:25 - 000000000 ____D C:\Users\Stefan\AppData\Roaming\discord
2018-03-02 23:19 - 2018-02-03 00:59 - 000000000 ____D C:\ProgramData\Overwolf
2018-03-02 18:02 - 2009-07-14 06:45 - 000409192 _____ C:\Windows\system32\FNTCACHE.DAT
2018-02-28 23:04 - 2018-01-23 12:54 - 000000000 ____D C:\Users\Stefan\AppData\Roaming\uTorrent
2018-02-28 22:09 - 2009-07-14 05:20 - 000000000 ____D C:\Program Files\Common Files\System
2018-02-28 22:09 - 2009-07-14 04:34 - 000000478 _____ C:\Windows\win.ini
2018-02-28 22:04 - 2018-01-23 12:53 - 000109280 _____ C:\Users\Stefan\AppData\Local\GDIPFONTCACHEV1.DAT
2018-02-28 22:03 - 2009-07-14 05:20 - 000000000 ____D C:\Program Files\Common Files\Microsoft Shared
2018-02-28 22:02 - 2009-07-14 07:32 - 000000000 ____D C:\Program Files (x86)\MSBuild
2018-02-17 03:01 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\LiveKernelReports
2018-02-15 00:25 - 2018-01-28 14:06 - 000000000 ____D C:\Program Files (x86)\TeamViewer

==================== Files in the root of some directories =======

2014-11-18 11:22 - 2014-11-18 11:22 - 033160370 ____R () C:\Users\Stefan\AppData\Roaming\K.J_121026.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe
[2018-01-23 12:54] - [2011-01-16 02:01] - 000389632 _____ (Microsoft Corporation) 81257415084B84F3C0D95C381A8D4C8F

C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll
[2010-11-21 05:24] - [2011-01-16 02:01] - 001008640 _____ (Microsoft Corporation) 0B864E15A0BADFF0E7BB8B59009FDDCF

C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-01-23 11:50

==================== End of FRST.txt ============================

  • Автор


µTorrent (HKU\S-1-5-21-1138422693-3855770178-890708622-1000\...\uTorrent) (Version: 3.5.3.44358 - BitTorrent Inc.)
888poker (HKLM-x32\...\{0039E386-43BF-4D4A-B6F2-642ADF4E86BF}) (Version: 7.4.11005 - 888) Hidden
888poker (HKU\S-1-5-21-1138422693-3855770178-890708622-1000\...\InstallShield_{0039E386-43BF-4D4A-B6F2-642ADF4E86BF}) (Version: 7.4.11005 - 888)
Adobe Flash Player 29 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 29.0.0.113 - Adobe Systems Incorporated)
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.14.4.0 - Asmedia Technology)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.0.0.0054 - Disc Soft Ltd)
Discord (HKU\S-1-5-21-1138422693-3855770178-890708622-1000\...\Discord) (Version: 0.0.300 - Discord Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 65.0.3325.162 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Gyazo 3.3.5 (HKLM-x32\...\{6DB8C365-E719-4BA5-9594-10DFC244D3FD}_is1) (Version:  - Nota Inc.)
Hearthstone (HKLM-x32\...\Hearthstone) (Version:  - Blizzard Entertainment)
Hearthstone Deck Tracker (HKU\S-1-5-21-1138422693-3855770178-890708622-1000\...\HearthstoneDeckTracker) (Version: 1.5.11 - HearthSim)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4276 - Intel Corporation)
Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed (HKLM\...\{2C0E6BD4-65B1-4E82-B2AC-43EFFC8F100C}) (Version: 15.0.0.0083 - Intel Corporation)
Intel® PROSet/Wireless WiFi Software (HKLM\...\{DF7756DD-656A-45C3-BA71-74673E8259A9}) (Version: 15.00.0000.0708 - Intel Corporation)
League of Legends (HKLM-x32\...\League of Legends 1.0) (Version: 1.0 - Riot Games, Inc)
Malwarebytes version 3.4.4.2398 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.4.4.2398 - Malwarebytes)
Microsoft .NET Framework 4.5 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50709 - Microsoft Corporation)
Microsoft Office 2010 Service Pack 1 (SP1) (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{7BC9B5EB-125A-4E9B-97E1-8D85B5E960B8}) (Version:  - Microsoft)
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.6029.1000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Mozilla Firefox 58.0.2 (x64 bg) (HKLM\...\Mozilla Firefox 58.0.2 (x64 bg)) (Version: 58.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 58.0 - Mozilla)
NVIDIA Graphics Driver 376.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 376.54 - NVIDIA Corporation)
Overwolf (HKLM-x32\...\Overwolf) (Version: 0.111.1.28 - Overwolf Ltd.)
Overwolf.Setup.VC100CRTx86.Dist (HKLM-x32\...\{8989DBC1-E87B-448F-9147-57EEEC5A24A5}) (Version: 1.0.0 - Overwolf) Hidden
Poker at bet365.BG (HKU\S-1-5-21-1138422693-3855770178-890708622-1000\...\bet365pokerbg) (Version:  - )
PokerStars.bg (HKLM-x32\...\PokerStars.bg) (Version:  - PokerStars.bg)
Qualcomm Atheros WiFi Driver Installation (HKLM-x32\...\{7D916FA5-DAE9-4A25-B089-655C70EAF607}) (Version: 9.2 - Qualcomm Atheros)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.10586.27055 - Realtek Semiconduct Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.48.823.2011 - Realtek)
Skype, версия 8.17 (HKLM-x32\...\Skype_is1) (Version: 8.17 - Skype Technologies S.A.)
TeamViewer 13 (HKLM-x32\...\TeamViewer) (Version: 13.0.6447 - TeamViewer)
Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1138422693-3855770178-890708622-1000_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-03-03] (Malwarebytes)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\Windows\system32\igfxDTCM.dll [2015-08-27] (Intel Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2016-12-29] (NVIDIA Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-03-03] (Malwarebytes)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {4E66CEB0-4D65-40B9-87CD-E9E83B5B4BEB} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-03-14] (Adobe Systems Incorporated)
Task: {526B5FCD-53CF-4F57-A683-6E8F67F10A8A} - System32\Tasks\Microsoft\Windows\Windows Activation Technologies\WatTask => C:\Windows Activation Technologies\wat.exe [2006-04-21] ()
Task: {5601B1F1-936C-4DE3-AA16-DAF3CBB013B7} - System32\Tasks\GyazoUpdateTaskMachineDaily => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [2017-12-21] (Nota Inc.)
Task: {57C620DE-9F56-4238-8CE1-B4A354B69907} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-01-23] (Google Inc.)
Task: {93619E2B-69E9-429A-8CFD-644579ADB151} - System32\Tasks\GyazoUpdateTaskMachine => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [2017-12-21] (Nota Inc.)
Task: {B60F5066-8E85-4866-AB41-934BF4751B5A} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_29_0_0_113_Plugin.exe [2018-03-14] (Adobe Systems Incorporated)
Task: {C50EF9F2-26B6-418A-B7D2-58D05373EDC4} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2018-03-05] (Overwolf LTD)
Task: {CEC8FB41-A628-4821-A9A1-D8DA1E1D79CC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-01-23] (Google Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


Shortcut: C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\SendTo\Прехвърляне на файлове с Bluetooth.LNK -> C:\Windows\System32\fsquirt.exe (Microsoft Corporation) <==== Cyrillic

==================== Loaded Modules (Whitelisted) ==============

2017-01-25 19:12 - 2017-01-25 19:12 - 000027576 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll
2011-03-17 00:07 - 2011-03-17 00:07 - 004297568 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 15:23 - 2010-10-20 15:23 - 008801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2018-01-23 12:35 - 2016-12-29 15:16 - 000134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2018-03-16 03:34 - 2018-03-01 10:31 - 002488608 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2018-03-16 03:34 - 2018-02-05 14:44 - 002299168 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2018-02-08 23:45 - 2018-03-02 21:44 - 001782904 _____ () C:\Program Files (x86)\Microsoft\Skype for Desktop\ffmpeg.dll
2017-01-25 19:12 - 2017-01-25 19:12 - 000027576 _____ () C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll
2018-03-16 00:43 - 2018-03-02 21:44 - 000097224 _____ () \\?\C:\Program Files (x86)\Microsoft\Skype for Desktop\resources\app.asar.unpacked\node_modules\keytar\build\Release\keytar.node
2018-02-10 01:25 - 2018-01-08 17:52 - 001891832 _____ () C:\Users\Stefan\AppData\Local\Discord\app-0.0.300\ffmpeg.dll
2018-02-10 01:25 - 2018-02-11 21:11 - 001780216 _____ () \\?\C:\Users\Stefan\AppData\Roaming\discord\0.0.300\modules\discord_overlay2\discord_overlay2.node
2018-02-08 23:45 - 2018-03-02 21:44 - 002559608 _____ () C:\Program Files (x86)\Microsoft\Skype for Desktop\libglesv2.dll
2018-02-08 23:45 - 2018-03-02 21:44 - 000031864 _____ () C:\Program Files (x86)\Microsoft\Skype for Desktop\libegl.dll
2018-03-16 00:43 - 2018-03-02 21:44 - 000216520 _____ () \\?\C:\Program Files (x86)\Microsoft\Skype for Desktop\resources\app.asar.unpacked\node_modules\electron-ssid\build\Release\electron-ssid.node
2018-03-16 00:43 - 2018-03-02 21:44 - 000409544 _____ () \\?\C:\Program Files (x86)\Microsoft\Skype for Desktop\resources\app.asar.unpacked\node_modules\@paulcbetts\spellchecker\build\Release\spellchecker.node
2018-03-16 00:43 - 2018-03-02 21:44 - 000138688 _____ () \\?\C:\Program Files (x86)\Microsoft\Skype for Desktop\resources\app.asar.unpacked\node_modules\keyboard-layout\build\Release\keyboard-layout-manager.node
2018-03-16 00:43 - 2018-03-02 21:44 - 002188800 _____ () \\?\C:\Program Files (x86)\Microsoft\Skype for Desktop\resources\app.asar.unpacked\node_modules\slimcore\bin\skypert.dll
2018-03-05 10:20 - 2018-03-05 10:20 - 069441864 _____ () C:\Program Files (x86)\Overwolf\0.111.1.28\libcef.DLL
2018-03-05 10:20 - 2018-03-05 10:20 - 003110216 _____ () C:\Program Files (x86)\Overwolf\0.111.1.28\libglesv2.dll
2018-03-05 10:20 - 2018-03-05 10:20 - 000086856 _____ () C:\Program Files (x86)\Overwolf\0.111.1.28\libegl.dll
2018-02-10 01:25 - 2018-01-08 17:52 - 001937912 _____ () C:\Users\Stefan\AppData\Local\Discord\app-0.0.300\libglesv2.dll
2018-02-10 01:25 - 2018-01-08 17:52 - 000095736 _____ () C:\Users\Stefan\AppData\Local\Discord\app-0.0.300\libegl.dll
2018-02-10 01:25 - 2018-03-14 02:43 - 009634296 _____ () \\?\C:\Users\Stefan\AppData\Roaming\discord\0.0.300\modules\discord_voice\discord_voice.node
2018-02-10 01:25 - 2018-02-10 01:25 - 001508344 _____ () \\?\C:\Users\Stefan\AppData\Roaming\discord\0.0.300\modules\discord_utils\discord_utils.node
2018-02-10 01:25 - 2018-02-10 01:25 - 000513016 _____ () \\?\C:\Users\Stefan\AppData\Roaming\discord\0.0.300\modules\discord_erlpack\discord_erlpack.node
2018-02-10 01:25 - 2018-02-10 01:25 - 002662904 _____ () \\?\C:\Users\Stefan\AppData\Roaming\discord\0.0.300\modules\discord_rpc\discord_rpc.node
2018-02-10 01:25 - 2018-03-14 02:43 - 001517560 _____ () \\?\C:\Users\Stefan\AppData\Roaming\discord\0.0.300\modules\discord_game_utils\discord_game_utils.node
2018-02-10 01:27 - 2018-03-08 21:48 - 002749944 _____ () \\?\C:\Users\Stefan\AppData\Roaming\discord\0.0.300\modules\discord_contact_import\discord_contact_import.node
2017-07-17 19:30 - 2017-07-17 19:30 - 000863744 _____ () C:\Windows\mod_frst.exe

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2009-06-10 23:00 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1138422693-3855770178-890708622-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 8.8.8.8
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{089E43CA-278C-456A-A2F4-D4A8D4F9F6E9}] => (Allow) C:\Users\Stefan\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{6A0D2E4D-FBAF-4E42-8A19-246640E3FCAE}] => (Allow) C:\Users\Stefan\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{64292B4B-FB82-42B5-8A2D-D6C80F4039D6}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{9BF2C919-49D5-4841-9D9C-A0FDB5E0F10A}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{6D9C3328-2448-4B8E-9A55-D3B9A3B8061B}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{4AFB54FA-6510-4748-BB62-9049573A0166}C:\program files (x86)\hearthstone\hearthstone.exe] => (Allow) C:\program files (x86)\hearthstone\hearthstone.exe
FirewallRules: [UDP Query User{B4C4BDCA-9898-4579-9D35-912230FE3CC9}C:\program files (x86)\hearthstone\hearthstone.exe] => (Allow) C:\program files (x86)\hearthstone\hearthstone.exe
FirewallRules: [{5350A10F-0C08-4C20-BEE4-56631D0FDA8C}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{A8981F2A-B7A5-418F-907D-7AFC0D1A1C65}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{2472C402-B219-4DE1-AD46-0A1656607DF2}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{8B10B2EB-35D9-4E80-9A29-B7DD6C7136E1}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [TCP Query User{973D3956-499B-4125-80B2-07A333AF98D0}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{5DAFD007-C4A4-4BD1-A62D-AF9E0A613D4F}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{C47629B3-0487-4324-BDC6-2A6E16CA8683}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.129\deploy\leagueclient.exe] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.129\deploy\leagueclient.exe
FirewallRules: [UDP Query User{57B3C86D-E98E-4285-96DD-A27C1241C844}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.129\deploy\leagueclient.exe] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.129\deploy\leagueclient.exe
FirewallRules: [{1B510222-4DBF-43C3-8FF3-25293AE1C930}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{87E127F4-2165-48EC-A9A8-067812D29462}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
FirewallRules: [{F930D6BD-3A16-44C1-ADFB-3CA64C76887A}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe

==================== Restore Points =========================

16-03-2018 00:31:23 Restore Point Created by FRST
16-03-2018 03:28:56 Restore Point Created by FRST

==================== Faulty Device Manager Devices =============

Name: Universal Serial Bus (USB) Controller
Description: Universal Serial Bus (USB) Controller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (03/16/2018 08:07:50 PM) (Source: Windows Search Service) (EventID: 10021) (User: )
Description: Could not get performance counter registry info for WSearchIdxPi for instance   due to the following error: Операцията завърши успешно.   0x0.

Error: (03/16/2018 08:07:44 PM) (Source: Windows Search Service) (EventID: 3007) (User: )
Description: Performance monitoring cannot be initialized for the gatherer object, because the counters are not loaded or the shared memory object cannot be opened. This only affects availability of the perfmon counters. Restart the computer.

Context:  Application, SystemIndex Catalog

Error: (03/16/2018 08:07:43 PM) (Source: Windows Search Service) (EventID: 3006) (User: )
Description: Performance monitoring cannot be initialized for the gatherer service, because the counters are not loaded or the shared memory object cannot be opened. This only affects availability of the perfmon counters. Restart the computer.

Error: (03/16/2018 08:07:00 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (03/16/2018 03:41:57 AM) (Source: Windows Search Service) (EventID: 10021) (User: )
Description: Could not get performance counter registry info for WSearchIdxPi for instance   due to the following error: Операцията завърши успешно.   0x0.

Error: (03/16/2018 03:41:52 AM) (Source: Windows Search Service) (EventID: 3007) (User: )
Description: Performance monitoring cannot be initialized for the gatherer object, because the counters are not loaded or the shared memory object cannot be opened. This only affects availability of the perfmon counters. Restart the computer.

Context:  Application, SystemIndex Catalog

Error: (03/16/2018 03:41:51 AM) (Source: Windows Search Service) (EventID: 3006) (User: )
Description: Performance monitoring cannot be initialized for the gatherer service, because the counters are not loaded or the shared memory object cannot be opened. This only affects availability of the perfmon counters. Restart the computer.

Error: (03/16/2018 03:41:34 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.


System errors:
=============
Error: (03/16/2018 03:32:13 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Услуга HWiNFO32/64 Kernel Driver не може да бъде стартирана поради следната грешка:
Windows не може да провери цифровия подпис за този файл. Извършена наскоро промяна в хардуера или софтуера може да е инсталирала файл, който е подписан неправилно или е повреден, а това може и да е злонамерен софтуер от неизвестен източник.

Error: (03/16/2018 03:32:12 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Услуга HWiNFO32/64 Kernel Driver не може да бъде стартирана поради следната грешка:
Windows не може да провери цифровия подпис за този файл. Извършена наскоро промяна в хардуера или софтуера може да е инсталирала файл, който е подписан неправилно или е повреден, а това може и да е злонамерен софтуер от неизвестен източник.

Error: (03/16/2018 03:32:12 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Услуга HWiNFO32/64 Kernel Driver не може да бъде стартирана поради следната грешка:
Windows не може да провери цифровия подпис за този файл. Извършена наскоро промяна в хардуера или софтуера може да е инсталирала файл, който е подписан неправилно или е повреден, а това може и да е злонамерен софтуер от неизвестен източник.

Error: (03/16/2018 03:32:11 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Услуга HWiNFO32/64 Kernel Driver не може да бъде стартирана поради следната грешка:
Windows не може да провери цифровия подпис за този файл. Извършена наскоро промяна в хардуера или софтуера може да е инсталирала файл, който е подписан неправилно или е повреден, а това може и да е злонамерен софтуер от неизвестен източник.

Error: (03/16/2018 03:32:10 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Услуга HWiNFO32/64 Kernel Driver не може да бъде стартирана поради следната грешка:
Windows не може да провери цифровия подпис за този файл. Извършена наскоро промяна в хардуера или софтуера може да е инсталирала файл, който е подписан неправилно или е повреден, а това може и да е злонамерен софтуер от неизвестен източник.

Error: (03/16/2018 03:32:10 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Услуга HWiNFO32/64 Kernel Driver не може да бъде стартирана поради следната грешка:
Windows не може да провери цифровия подпис за този файл. Извършена наскоро промяна в хардуера или софтуера може да е инсталирала файл, който е подписан неправилно или е повреден, а това може и да е злонамерен софтуер от неизвестен източник.

Error: (03/16/2018 03:31:18 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Услуга HWiNFO32/64 Kernel Driver не може да бъде стартирана поради следната грешка:
Windows не може да провери цифровия подпис за този файл. Извършена наскоро промяна в хардуера или софтуера може да е инсталирала файл, който е подписан неправилно или е повреден, а това може и да е злонамерен софтуер от неизвестен източник.

Error: (03/16/2018 03:31:18 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Услуга HWiNFO32/64 Kernel Driver не може да бъде стартирана поради следната грешка:
Windows не може да провери цифровия подпис за този файл. Извършена наскоро промяна в хардуера или софтуера може да е инсталирала файл, който е подписан неправилно или е повреден, а това може и да е злонамерен софтуер от неизвестен източник.


CodeIntegrity:
===================================

Date: 2018-03-16 20:06:31.868
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\user32.dll because the set of per-page image hashes could not be found on the system.

Date: 2018-03-16 18:09:43.762
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\user32.dll because the set of per-page image hashes could not be found on the system.

Date: 2018-03-16 15:32:13.307
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\Stefan\AppData\Local\Temp\HWiNFO64A.SYS because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-03-16 15:32:13.189
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\Stefan\AppData\Local\Temp\HWiNFO64A.SYS because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-03-16 15:32:12.725
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\Stefan\AppData\Local\Temp\HWiNFO64A.SYS because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-03-16 15:32:12.605
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\Stefan\AppData\Local\Temp\HWiNFO64A.SYS because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-03-16 15:32:12.140
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\Stefan\AppData\Local\Temp\HWiNFO64A.SYS because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-03-16 15:32:12.022
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\Stefan\AppData\Local\Temp\HWiNFO64A.SYS because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

==================== Memory info ===========================

Processor: Intel(R) Core(TM) i7-3630QM CPU @ 2.40GHz
Percentage of memory in use: 38%
Total physical RAM: 8077.48 MB
Available physical RAM: 4985.36 MB
Total Virtual: 16153.18 MB
Available Virtual: 12948.68 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:443.13 GB) (Free:381.98 GB) NTFS

\\?\Volume{e0d9951b-0022-11e8-9019-806e6f6e6963}\ (Резервирана за системата) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 00DE11BB)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=443.1 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=488.3 GB) - (Type=06)

==================== End of Addition.txt ============================

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.