Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Съмнение за криптиращ вирус

Featured Replies

Здравейте,ако можете да проверите и евентуално да се отстрани проблема.Има променени имена "KUKI"

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-12-2019
Ran by bojid (administrator) on XI6TNIKA (ASUSTeK COMPUTER INC. G752VY) (16-12-2019 21:16:47)
Running from C:\Users\bojid\Desktop
Loaded Profiles: bojid (Available Profiles: bojid & Administrator)
Platform: Windows 10 Pro Version 1803 17134.885 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(@ByELDI -> @ByELDI) [File not signed] C:\Program Files\KMSpico\Service_KMS.exe
(Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
(BitTorrent Inc -> BitTorrent Inc.) C:\Users\bojid\AppData\Roaming\uTorrent\helper\helper.exe
(BitTorrent Inc -> BitTorrent Inc.) C:\Users\bojid\AppData\Roaming\uTorrent\updates\3.5.5_45395\utorrentie.exe
(BitTorrent Inc -> BitTorrent Inc.) C:\Users\bojid\AppData\Roaming\uTorrent\updates\3.5.5_45395\utorrentie.exe
(BitTorrent Inc -> BitTorrent Inc.) C:\Users\bojid\AppData\Roaming\uTorrent\uTorrent.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.422\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.422\GoogleCrashHandler64.exe
(Intel(R) Software -> Intel Corporation) C:\Windows\SysWOW64\esif_uf.exe
(Intel(R) Software -> Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
(Intel(R) Software Development Products -> ) C:\Program Files\Intel\SUR\QUEENCREEK\SurSvc.exe
(Intel(R) Software Development Products -> ) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv.exe
(Intel(R) Software Development Products -> ) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe
(Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotifyIcon.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1911.3-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1911.3-0\NisSrv.exe
(NETGATE Technologies s.r.o. -> NETGATE Technologies s.r.o.) C:\Program Files\NETGATE\Registry Cleaner\RegistryCleanerSrv.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-12] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12162019191539424\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-2491579097-1836322396-851961227-1001\...\Run: [uTorrent] => C:\Users\bojid\AppData\Roaming\uTorrent\uTorrent.exe [2005224 2019-11-06] (BitTorrent Inc -> BitTorrent Inc.)
HKU\S-1-5-21-2491579097-1836322396-851961227-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [731240 2018-12-17] (AVB Disc Soft, SIA -> Disc Soft Ltd)
HKU\S-1-5-21-2491579097-1836322396-851961227-1001\...\Run: [gtarcade] => "C:\Users\bojid\AppData\Local\Gtarcade\app\gtarcade.exe"   /auto_start=1 
HKU\S-1-5-21-2491579097-1836322396-851961227-1001\Sortware\Policies\...\system: [DisableCMD] 0
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\79.0.3945.79\Installer\chrmstp.exe [2019-12-11] (Google LLC -> Google LLC)
Startup: C:\Users\bojid\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Изпращане в OneNote.lnk [2018-05-21]
ShortcutTarget: Изпращане в OneNote.lnk -> C:\Program Files\Microsoft Office\Office16\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation)
GroupPolicy: Restriction ? <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0FE0CC32-E039-4313-A1CF-4497369AA59A} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1133368 2019-10-24] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {170EBE05-C609-4920-8A90-6212CFC99DF9} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1133368 2019-10-24] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {1C6C9761-5DD0-460E-AE63-92E5CC6218F9} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [654456 2019-10-24] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {215942B9-EBBB-4791-A219-1CA58B23691D} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1133368 2019-10-24] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {2170B0B8-B84D-46C5-9A2F-15482F16EA81} - System32\Tasks\AutoPico Daily Restart => C:\Program Files\KMSpico\AutoPico.exe [745664 2016-01-12] (@ByELDI -> @ByELDI) [File not signed]
Task: {23215B9F-112C-4D44-915C-EA0F2E57329C} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [858480 2019-09-28] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {24A73EFF-2698-40A6-A477-021220C7A64E} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MpCmdRun.exe [469648 2019-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {418829EC-673B-4C96-9276-849C0F017030} - System32\Tasks\RunAsStdUser Task => C:\Program Files (x86)\Moo0\FileShredder 1.23\FileShredder.exe
Task: {42FF2710-9CC5-4011-B5AA-5BCAFEBE9772} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1133368 2019-10-24] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {463731D2-2D23-4D3F-8D29-4E41A5B43406} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MpCmdRun.exe [469648 2019-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {4F679045-5AE6-4340-B0DF-6153536C7A3A} - System32\Tasks\USER_ESRV_SVC_QUEENCREEK => "C:\windows\System32\Wscript.exe" //B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.vbs"
Task: {5270C65D-FC58-4A79-B851-36B9F7DA1076} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [18744 2019-04-15] (Intel(R) Software Development Products -> Intel Corporation)
Task: {57A47B3C-2F4D-4395-A8FD-E173A2A6AE86} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-03-09] (Google Inc -> Google Inc.)
Task: {5F624D1D-824E-43C9-B0D6-6F1D19EE7EF1} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [858480 2019-09-28] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {60A7811B-AE86-44D0-AA24-88CE729EF79E} - \K-9-3-11-1121762101-1106494043-1063864577-4313\{Z1EGG9M-WVK2-W9TC-VFY1-QEIQ9G3BRPWI} -> No File <==== ATTENTION
Task: {62D4F134-666C-4543-ACA5-64D217051E69} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2491579097-1836322396-851961227-1002 => C:\Users\bojid\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
Task: {755B068A-9FD4-4BB8-B1A7-F6E822B095E7} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\Office16\msoia.exe [416432 2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {848B701D-FAB9-4A6F-8C53-5C8044502477} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe
Task: {84FE198D-C1FB-4F22-8A71-88F04EA1188F} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2491579097-1836322396-851961227-1001 => C:\Users\bojid\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
Task: {A38A3D08-4140-43C2-8691-F3D3910B5785} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\Office16\msoia.exe [416432 2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {B252F78E-1062-467E-8C7F-CD53153DD80E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-03-09] (Google Inc -> Google Inc.)
Task: {B7B13C35-5922-4F50-9B44-D5CCDE028E41} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MpCmdRun.exe [469648 2019-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {BCA5D2EE-6C06-4FA5-B764-8F0CD1EF1AF6} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2491579097-1836322396-851961227-500 => C:\Users\bojid\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
Task: {BFC0BC86-1AD8-4A5C-8F1B-A2BF7F96AC06} - System32\Tasks\KMSAutoNet => C:\ProgramData\KMSAutoS\KMSAuto Net.exe
Task: {C72F04B6-371D-498D-897F-51C68A084045} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [913720 2019-10-24] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D4E9AC0D-C25B-493E-8700-AB1E678978AD} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8822528 2016-05-26] (Realtek Semiconductor Corp -> Realtek Semiconductor)
Task: {D7A5170B-8D96-451E-BAEC-68A51A804BA7} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3301928 2019-10-25] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {E22ABAFD-F4CA-4DFF-8885-B6B95EEC9AEE} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [18744 2019-04-15] (Intel(R) Software Development Products -> Intel Corporation)
Task: {EA6ABC09-3C9E-4FD0-8FC8-94CC0A98E70E} - System32\Tasks\RtHDVBg_ListenToDevice => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1454336 2016-05-26] (Realtek Semiconductor Corp -> Realtek Semiconductor)
Task: {EF1D51E0-99C0-4303-A17B-1B7EAA90306D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MpCmdRun.exe [469648 2019-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {F0CA1189-CF3E-4C29-A033-350B8036AA8C} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1240656 2019-09-10] (Adobe Inc. -> Adobe Systems)
Task: {FB0650A7-35BA-47A2-A94D-47D9318BAEF3} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office16\OLicenseHeartbeat.exe [316632 2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {FD7EBA69-13DB-421D-B509-BF1D67ADD38F} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [913720 2019-10-24] (NVIDIA Corporation -> NVIDIA Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\windows\explorer.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 0.0.0.0
Tcpip\..\Interfaces\{3a5a5a17-ad48-4c95-a6a8-02601fd05d43}: [DhcpNameServer] 192.168.0.1 0.0.0.0
Tcpip\..\Interfaces\{a77e0f52-0b6c-485d-bec5-8e6aa84c40a3}: [DhcpNameServer] 192.168.0.1 0.0.0.0

Internet Explorer:
==================
SearchScopes: HKU\S-1-5-21-2491579097-1836322396-851961227-1001 -> {C0C3A6C6-03BC-4195-8FCB-AEA091301353} URL = hxxps://search.yahoo.com/yhs/search?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__ch_WCYID10438__180309__yaie&p={searchTerms}
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL [2018-07-20] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office16\GROOVEEX.DLL [2018-07-22] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2019-06-12] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2019-06-12] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2019-06-12] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2019-06-12] (Microsoft Corporation -> Microsoft Corporation)

Edge: 
======
DownloadDir: F:\Downloads

FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.35.422\npGoogleUpdate3.dll [2019-12-14] (Google LLC -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.35.422\npGoogleUpdate3.dll [2019-12-14] (Google LLC -> Google LLC)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-12-03] (Adobe Inc. -> Adobe Systems Inc.)

Chrome: 
=======
CHR Notifications: Default -> hxxps://audibg.com; hxxps://www.youtube.com; hxxps://www80.hattrick.org; hxxps://www82.hattrick.org; hxxps://www83.hattrick.org; hxxps://www91.hattrick.org; hxxps://www92.hattrick.org; hxxps://www93.hattrick.org; hxxps://www95.hattrick.org; hxxps://www96.hattrick.org; hxxps://www97.hattrick.org
CHR Profile: C:\Users\bojid\AppData\Local\Google\Chrome\User Data\Default [2019-12-16]
CHR DownloadDir: F:\Downloads
CHR Extension: (Slides) - C:\Users\bojid\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-03-09]
CHR Extension: (Docs) - C:\Users\bojid\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-03-09]
CHR Extension: (Google Drive) - C:\Users\bojid\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-03-09]
CHR Extension: (YouTube) - C:\Users\bojid\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-03-09]
CHR Extension: (Adaware Ad Block) - C:\Users\bojid\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmllgdnjnkbapbchnebiedipojhmnjej [2018-07-05]
CHR Extension: (Sheets) - C:\Users\bojid\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-03-09]
CHR Extension: (Google Docs Offline) - C:\Users\bojid\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-09-11]
CHR Extension: (Chrome Web Store Payments) - C:\Users\bojid\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-03]
CHR Extension: (Gmail) - C:\Users\bojid\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-15]
CHR Extension: (Chrome Media Router) - C:\Users\bojid\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-12-13]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [6212880 2018-06-26] (BattlEye Innovations e.K. -> )
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [3644008 2018-12-17] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R2 esifsvc; C:\windows\SysWOW64\esif_uf.exe [1394360 2015-08-12] (Intel(R) Software -> Intel Corporation)
R2 ESRV_SVC_QUEENCREEK; C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe [877368 2019-08-16] (Intel(R) Software Development Products -> )
R2 ibtsiva; C:\windows\system32\ibtsiva.exe [530424 2019-07-10] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation)
S3 Intel(R) SUR QC SAM; C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [18744 2019-04-15] (Intel(R) Software Development Products -> Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6960640 2019-11-15] (Malwarebytes Inc -> Malwarebytes)
R2 NGRegClnSrv; C:\Program Files\NETGATE\Registry Cleaner\RegistryCleanerSrv.exe [618832 2013-02-21] (NETGATE Technologies s.r.o. -> NETGATE Technologies s.r.o.)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [858480 2019-09-28] (NVIDIA Corporation -> NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [858480 2019-09-28] (NVIDIA Corporation -> NVIDIA Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5073792 2019-07-04] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [745664 2016-01-12] (@ByELDI -> @ByELDI) [File not signed]
R2 SystemUsageReportSvc_QUEENCREEK; C:\Program Files\Intel\SUR\QUEENCREEK\SurSvc.exe [204088 2019-08-16] (Intel(R) Software Development Products -> )
S3 USER_ESRV_SVC_QUEENCREEK; C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe [877368 2019-08-16] (Intel(R) Software Development Products -> )
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\NisSrv.exe [3206472 2019-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MsMpEng.exe [103376 2019-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000 

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 ampa; C:\WINDOWS\system32\ampa.sys [38320 2016-12-25] (CHENGDU AOMEI Tech Co., Ltd. -> )
R3 dptf_cpu; C:\windows\System32\drivers\dptf_cpu.sys [53752 2015-08-12] (Intel(R) Software -> Intel Corporation)
R3 dtlitescsibus; C:\windows\System32\drivers\dtlitescsibus.sys [30264 2018-03-10] (Disc Soft Ltd -> Disc Soft Ltd)
R3 dtliteusbbus; C:\windows\System32\drivers\dtliteusbbus.sys [47672 2018-03-10] (Disc Soft Ltd -> Disc Soft Ltd)
R3 esif_lf; C:\windows\system32\DRIVERS\esif_lf.sys [261624 2015-08-12] (Intel(R) Software -> Intel Corporation)
R3 HIDSwitch; C:\windows\System32\drivers\AsRadioControl.sys [32680 2019-08-07] (ASUSTek Computer Inc. -> ASUS)
R3 ibtusb; C:\windows\system32\DRIVERS\ibtusb.sys [734496 2019-07-10] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation)
R2 MBAMChameleon; C:\windows\System32\Drivers\MbamChameleon.sys [248480 2019-11-15] (Malwarebytes Inc -> Malwarebytes)
S0 MbamElam; C:\windows\System32\DRIVERS\MbamElam.sys [20936 2019-11-15] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\windows\System32\Drivers\mbamswissarmy.sys [278344 2019-12-16] (Malwarebytes Inc -> Malwarebytes)
S3 Netwtw04; C:\windows\System32\drivers\Netwtw04.sys [7689728 2018-04-12] (Microsoft Windows -> Intel Corporation)
R3 Netwtw06; C:\windows\System32\drivers\Netwtw06.sys [8835360 2019-07-02] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation)
R3 nvlddmkm; C:\windows\System32\DriverStore\FileRepository\nvami.inf_amd64_fb9ec72187c47cbc\nvlddmkm.sys [23231744 2019-12-08] (NVIDIA Corporation -> NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30336 2019-07-23] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\windows\system32\drivers\nvvad64v.sys [69840 2019-03-19] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvhci; C:\windows\System32\drivers\nvvhci.sys [75600 2019-04-17] (NVIDIA Corporation -> NVIDIA Corporation)
R3 rt640x64; C:\windows\System32\drivers\rt640x64.sys [896272 2016-01-19] (Realtek Semiconductor Corp -> Realtek )
R3 semav6msr64; C:\windows\system32\drivers\semav6msr64.sys [41816 2019-08-16] (Intel Corporation -> )
S0 WdBoot; C:\windows\System32\drivers\wd\WdBoot.sys [45664 2019-12-08] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\windows\System32\drivers\wd\WdFilter.sys [355760 2019-12-08] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\windows\System32\drivers\wd\WdNisDrv.sys [54192 2019-12-08] (Microsoft Windows -> Microsoft Corporation)
U4 WinDivert1.1; C:\Program Files\KMSpico\WinDivert.sys [35376 2019-01-10] (Nemea Mjukvaruutveckling AB -> Basil Projects)
S3 WinFsp; C:\windows\system32\disko\winfsp-x64.sys [149208 2019-02-15] (Navimatics Corporation -> Navimatics Corporation)
R3 XtuAcpiDriver; C:\windows\System32\drivers\XtuAcpiDriver.sys [63840 2015-06-06] (Intel(R) Software -> Intel Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ===================

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-12-16 21:16 - 2019-12-16 21:17 - 000027725 ____C C:\Users\bojid\Desktop\FRST.txt
2019-12-16 21:16 - 2019-12-16 21:15 - 002264064 ____C (Farbar) C:\Users\bojid\Desktop\FRST64.exe
2019-12-16 19:31 - 2019-12-16 21:17 - 000000000 ____D C:\FRST
2019-12-15 19:50 - 2019-12-16 19:15 - 000278344 ____C (Malwarebytes) C:\windows\system32\Drivers\mbamswissarmy.sys
2019-12-15 19:40 - 2019-12-15 19:40 - 000000000 ___DC C:\ProgramData\LHService
2019-12-15 19:39 - 2019-12-15 19:39 - 000000000 ___DC C:\ProgramData\LockHunter
2019-12-15 19:36 - 2019-12-15 19:36 - 000000000 ___DC C:\Users\bojid\AppData\Roaming\LockHunter
2019-12-10 22:18 - 2019-12-08 23:28 - 011843696 ____C (NVIDIA Corporation) C:\windows\system32\nvptxJitCompiler.dll
2019-12-10 22:18 - 2019-12-08 23:28 - 010167952 ____C (NVIDIA Corporation) C:\windows\SysWOW64\nvptxJitCompiler.dll
2019-12-10 22:18 - 2019-12-08 23:28 - 001729440 ____C C:\windows\system32\vulkaninfo-1-999-0-0-0.exe
2019-12-10 22:18 - 2019-12-08 23:28 - 001729440 ____C C:\windows\system32\vulkaninfo.exe
2019-12-10 22:18 - 2019-12-08 23:28 - 001329568 ____C C:\windows\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2019-12-10 22:18 - 2019-12-08 23:28 - 001329568 ____C C:\windows\SysWOW64\vulkaninfo.exe
2019-12-10 22:18 - 2019-12-08 23:28 - 001079200 ____C C:\windows\system32\vulkan-1-999-0-0-0.dll
2019-12-10 22:18 - 2019-12-08 23:28 - 001079200 ____C C:\windows\system32\vulkan-1.dll
2019-12-10 22:18 - 2019-12-08 23:28 - 000937888 ____C C:\windows\SysWOW64\vulkan-1-999-0-0-0.dll
2019-12-10 22:18 - 2019-12-08 23:28 - 000937888 ____C C:\windows\SysWOW64\vulkan-1.dll
2019-12-10 22:18 - 2019-12-08 23:28 - 000451656 ____C (Khronos Group) C:\windows\system32\OpenCL.dll
2019-12-10 22:18 - 2019-12-08 23:28 - 000352712 ____C (Khronos Group) C:\windows\SysWOW64\OpenCL.dll
2019-12-10 22:18 - 2019-12-08 23:27 - 001483712 ____C (NVIDIA Corporation) C:\windows\system32\NvIFR64.dll
2019-12-10 22:18 - 2019-12-08 23:27 - 001146880 ____C (NVIDIA Corporation) C:\windows\SysWOW64\NvIFR.dll
2019-12-10 22:18 - 2019-12-08 23:27 - 000824256 ____C (NVIDIA Corporation) C:\windows\system32\nvmcumd.dll
2019-12-10 22:18 - 2019-12-08 23:27 - 000684992 ____C (NVIDIA Corporation) C:\windows\system32\NvIFROpenGL.dll
2019-12-10 22:18 - 2019-12-08 23:27 - 000676608 ____C C:\windows\system32\nvofapi64.dll
2019-12-10 22:18 - 2019-12-08 23:27 - 000557072 ____C (NVIDIA Corporation) C:\windows\SysWOW64\NvIFROpenGL.dll
2019-12-10 22:18 - 2019-12-08 23:27 - 000545296 ____C C:\windows\SysWOW64\nvofapi.dll
2019-12-10 22:18 - 2019-12-08 23:26 - 040510424 ____C (NVIDIA Corporation) C:\windows\system32\nvcompiler.dll
2019-12-10 22:18 - 2019-12-08 23:26 - 035380264 ____C (NVIDIA Corporation) C:\windows\SysWOW64\nvcompiler.dll
2019-12-10 22:18 - 2019-12-08 23:26 - 017462424 ____C (NVIDIA Corporation) C:\windows\system32\nvcuda.dll
2019-12-10 22:18 - 2019-12-08 23:26 - 015030896 ____C (NVIDIA Corporation) C:\windows\SysWOW64\nvcuda.dll
2019-12-10 22:18 - 2019-12-08 23:26 - 005382024 ____C (NVIDIA Corporation) C:\windows\system32\nvcuvid.dll
2019-12-10 22:18 - 2019-12-08 23:26 - 004717656 ____C (NVIDIA Corporation) C:\windows\SysWOW64\nvcuvid.dll
2019-12-10 22:18 - 2019-12-08 23:26 - 002076064 ____C (NVIDIA Corporation) C:\windows\system32\NvFBC64.dll
2019-12-10 22:18 - 2019-12-08 23:26 - 001727920 ____C (NVIDIA Corporation) C:\windows\system32\nvdispco6444166.dll
2019-12-10 22:18 - 2019-12-08 23:26 - 001568504 ____C (NVIDIA Corporation) C:\windows\SysWOW64\NvFBC.dll
2019-12-10 22:18 - 2019-12-08 23:26 - 001491472 ____C (NVIDIA Corporation) C:\windows\system32\nvdispgenco6444166.dll
2019-12-10 22:18 - 2019-12-08 23:26 - 001371648 ____C (NVIDIA Corporation) C:\windows\system32\nvfatbinaryLoader.dll
2019-12-10 22:18 - 2019-12-08 23:26 - 001064840 ____C (NVIDIA Corporation) C:\windows\SysWOW64\nvfatbinaryLoader.dll
2019-12-10 22:18 - 2019-12-08 23:26 - 000812800 ____C (NVIDIA Corporation) C:\windows\system32\nvEncodeAPI64.dll
2019-12-10 22:18 - 2019-12-08 23:26 - 000659152 ____C (NVIDIA Corporation) C:\windows\SysWOW64\nvEncodeAPI.dll
2019-12-10 22:18 - 2019-12-08 19:20 - 004224176 ____C (NVIDIA Corporation) C:\windows\SysWOW64\nvapi.dll
2019-12-10 17:56 - 2019-12-10 18:09 - 000000000 ___HD C:\$WINDOWS.~BT
2019-12-10 17:56 - 2019-12-10 18:09 - 000000000 ____D C:\windows\Panther
2019-12-10 17:51 - 2019-12-10 18:09 - 000000000 ___HD C:\$GetCurrent
2019-11-28 22:04 - 2019-11-28 22:04 - 000000000 ____D C:\windows\LastGood
2019-11-28 22:02 - 2019-11-21 17:43 - 001733264 ____C (NVIDIA Corporation) C:\windows\system32\nvdispco6444141.dll
2019-11-28 22:02 - 2019-11-21 17:43 - 001491568 ____C (NVIDIA Corporation) C:\windows\system32\nvdispgenco6444141.dll
2019-11-21 22:06 - 2019-11-21 22:06 - 000000737 ____C C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 10 Update Assistant.lnk
2019-11-19 21:47 - 2019-11-20 00:17 - 000000000 ___DC C:\Users\bojid\AppData\Roaming\JAM Software
2019-11-17 00:02 - 2019-11-17 00:03 - 000000000 ____D C:\windows\LastGood.Tmp
2019-11-17 00:01 - 2019-11-08 12:06 - 001734256 ____C (NVIDIA Corporation) C:\windows\system32\nvdispco6444120.dll
2019-11-17 00:01 - 2019-11-08 12:06 - 001492696 ____C (NVIDIA Corporation) C:\windows\system32\nvdispgenco6444120.dll
2019-11-16 23:55 - 2019-12-10 17:51 - 000000000 ____D C:\Windows10Upgrade

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-12-16 21:16 - 2018-03-09 23:16 - 000000000 ___DC C:\Users\bojid\AppData\Roaming\uTorrent
2019-12-16 21:15 - 2018-04-12 01:38 - 000000000 ___DC C:\ProgramData\regid.1991-06.com.microsoft
2019-12-16 21:11 - 2018-03-18 20:07 - 000000000 ___DC C:\Users\bojid\AppData\Local\CrashDumps
2019-12-16 20:20 - 2019-05-21 16:46 - 000000000 ___DC C:\Users\bojid\AppData\Local\BitTorrentHelper
2019-12-16 19:30 - 2018-03-09 20:45 - 000000000 ___DC C:\ProgramData\TEMP
2019-12-16 19:24 - 2018-04-12 01:36 - 000000000 ___DC C:\windows\INF
2019-12-16 19:21 - 2019-11-01 01:44 - 000004152 ____C C:\windows\system32\Tasks\User_Feed_Synchronization-{C2927199-3A2A-4566-ADD4-7BE3DC46ECF6}
2019-12-16 19:21 - 2018-04-12 01:38 - 000000000 ____D C:\windows\AppReadiness
2019-12-16 19:19 - 2018-05-20 14:29 - 000842652 ____C C:\windows\system32\PerfStringBackup.INI
2019-12-16 19:16 - 2019-10-14 18:59 - 000000000 ___DC C:\Users\bojid\AppData\LocalLow\uTorrent
2019-12-16 19:16 - 2018-03-07 23:15 - 000000000 ___DC C:\ProgramData\NVIDIA
2019-12-16 19:15 - 2018-05-20 14:33 - 000000006 ___HC C:\windows\Tasks\SA.DAT
2019-12-16 19:15 - 2018-05-20 14:11 - 000000000 ___DC C:\windows\system32\SleepStudy
2019-12-15 19:49 - 2018-04-11 23:04 - 001310720 _____ C:\windows\system32\config\BBI
2019-12-15 19:39 - 2018-05-20 14:17 - 000000000 ___DC C:\Users\bojid
2019-12-14 12:02 - 2019-07-07 18:35 - 000153312 ____C (Malwarebytes) C:\windows\system32\Drivers\mbae64.sys
2019-12-14 10:30 - 2018-05-20 14:33 - 000003420 ____C C:\windows\system32\Tasks\GoogleUpdateTaskMachineUA
2019-12-14 10:30 - 2018-05-20 14:33 - 000003296 ____C C:\windows\system32\Tasks\GoogleUpdateTaskMachineCore
2019-12-13 18:48 - 2018-04-12 01:38 - 000000000 ___HD C:\Program Files\WindowsApps
2019-12-11 23:31 - 2018-03-09 18:42 - 000002307 ____C C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-12-10 23:36 - 2018-04-22 19:56 - 000002457 ____C C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2019-12-10 18:09 - 2018-05-20 14:32 - 000001908 _____ C:\windows\diagwrn.xml
2019-12-10 18:09 - 2018-05-20 14:32 - 000001908 _____ C:\windows\diagerr.xml
2019-12-10 18:06 - 2018-04-11 23:04 - 000032768 _____ C:\windows\system32\config\ELAM
2019-12-10 18:03 - 2018-04-12 01:38 - 000000000 ___DC C:\windows\Registration
2019-12-10 17:56 - 2018-03-07 23:44 - 000000036 _____ C:\windows\progress.ini
2019-12-09 20:49 - 2018-05-21 22:30 - 000000000 ___DC C:\Users\bojid\AppData\Local\D3DSCache
2019-12-08 19:20 - 2018-05-09 23:42 - 004957288 ____C (NVIDIA Corporation) C:\windows\system32\nvapi64.dll
2019-12-08 10:34 - 2018-03-09 19:02 - 000000000 ____D C:\windows\system32\Drivers\wd
2019-12-07 05:09 - 2018-05-09 23:42 - 000055685 ____C C:\windows\system32\nvinfo.pb
2019-12-07 03:21 - 2018-03-07 23:14 - 005562208 ____C (NVIDIA Corporation) C:\windows\system32\nvcpl.dll
2019-12-07 03:21 - 2018-03-07 23:14 - 002652712 _____ (NVIDIA Corporation) C:\windows\system32\nvsvc64.dll
2019-12-07 03:21 - 2018-03-07 23:14 - 001768456 _____ (NVIDIA Corporation) C:\windows\system32\nvsvcr.dll
2019-12-07 03:21 - 2018-03-07 23:14 - 000670744 ____C (NVIDIA Corporation) C:\windows\system32\nv3dappshext.dll
2019-12-07 03:21 - 2018-03-07 23:14 - 000455152 ____C (NVIDIA Corporation) C:\windows\system32\nvmctray.dll
2019-12-07 03:21 - 2018-03-07 23:14 - 000129392 ____C (NVIDIA Corporation) C:\windows\system32\nvshext.dll
2019-12-07 03:21 - 2018-03-07 23:14 - 000083392 ____C (NVIDIA Corporation) C:\windows\system32\nv3dappshextr.dll
2019-12-04 12:50 - 2018-03-07 23:14 - 008800072 ____C C:\windows\system32\nvcoproc.bin
2019-11-30 20:58 - 2018-03-09 20:39 - 000000000 ____D C:\KMPlayer
2019-11-24 23:12 - 2019-02-19 18:55 - 000000817 ____C C:\Users\bojid\Desktop\Counter-Strike Global Offensive.lnk
2019-11-21 17:40 - 2019-11-15 00:53 - 000000000 ___DC C:\Users\bojid\AppData\Roaming\PC App Store
2019-11-19 20:58 - 2019-01-13 14:24 - 000000115 _____ C:\Users\bojid\Desktop\Add Server.txt
2019-11-18 21:06 - 2018-04-12 01:38 - 000000000 ___DC C:\windows\system32\Catroot2.old
2019-11-16 23:52 - 2019-05-27 18:50 - 000003858 ____C C:\windows\system32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-11-16 23:52 - 2019-05-27 18:50 - 000003858 ____C C:\windows\system32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-11-16 23:52 - 2019-05-27 18:50 - 000003858 ____C C:\windows\system32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-11-16 23:52 - 2019-05-27 18:50 - 000003858 ____C C:\windows\system32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-11-16 23:52 - 2018-10-09 18:45 - 000003976 ____C C:\windows\system32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-11-16 23:52 - 2018-10-09 18:45 - 000003940 ____C C:\windows\system32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-11-16 23:52 - 2018-10-09 18:44 - 000004308 ____C C:\windows\system32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-11-16 23:52 - 2018-10-09 18:44 - 000004106 ____C C:\windows\system32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-11-16 23:52 - 2018-10-09 18:44 - 000003894 ____C C:\windows\system32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-11-16 23:52 - 2018-10-09 18:44 - 000003654 ____C C:\windows\system32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-11-16 23:52 - 2018-03-07 23:15 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2019-11-16 23:52 - 2018-03-07 23:14 - 000000000 ___DC C:\ProgramData\NVIDIA Corporation
2019-11-16 23:52 - 2018-03-07 23:14 - 000000000 ___DC C:\Program Files\NVIDIA Corporation
2019-11-16 23:02 - 2018-04-12 01:30 - 000000000 ___DC C:\windows\CbsTemp
2019-11-16 23:00 - 2018-03-08 01:05 - 000000000 ___DC C:\Users\bojid\AppData\Local\Packages

==================== Files in the root of some directories ========

2018-03-09 21:29 - 2018-03-09 21:35 - 000000298 ____C () C:\ProgramData\fontcacheev1.dat
2019-10-14 23:47 - 2019-10-14 23:47 - 000000043 ____C () C:\Users\bojid\AppData\Roaming\WB.CFG
2018-05-04 23:01 - 2019-01-17 18:05 - 000007604 ____C () C:\Users\bojid\AppData\Local\resmon.resmoncfg

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-12-2019
Ran by bojid (16-12-2019 21:17:56)
Running from C:\Users\bojid\Desktop
Windows 10 Pro Version 1803 17134.885 (X64) (2018-05-20 12:34:51)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2491579097-1836322396-851961227-500 - Administrator - Enabled) => C:\Users\Administrator
bojid (S-1-5-21-2491579097-1836322396-851961227-1001 - Administrator - Enabled) => C:\Users\bojid
DefaultAccount (S-1-5-21-2491579097-1836322396-851961227-503 - Limited - Disabled)
Guest (S-1-5-21-2491579097-1836322396-851961227-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-2491579097-1836322396-851961227-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-2491579097-1836322396-851961227-1001\...\uTorrent) (Version: 3.5.5.45395 - BitTorrent Inc.)
7Launcher CSGO 1.3.4 (HKLM\...\7l_csgo_is1) (Version: 1.3.4 - SE7EN Solutions)
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 19.021.20058 - Adobe Systems Incorporated)
AIDA64 5.75.3900 Final (HKLM-x32\...\AIDA64 5.75.3900 Final) (Version:  - )
AIMP (HKLM-x32\...\AIMP) (Version: v4.60.2156, 21.10.2019 - AIMP DevTeam)
AOMEI Partition Assistant Pro Edition 7.1 (DEMO) (HKLM-x32\...\{02F850ED-FD0E-4ED1-BE0B-5498165BF3D1}_is1) (Version:  - AOMEI Technology Co., Ltd.)
Cutting Optimization pro (HKLM-x32\...\cutting) (Version:  - )
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.9.0.0677 - Disc Soft Ltd)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 79.0.3945.79 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.421 - Google LLC) Hidden
Intel(R) Computing Improvement Program (HKLM\...\{A9133872-C9FE-45CC-8F01-D1947B0F09EA}) (Version: 2.4.04755 - Intel Corporation)
Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{00000030-0210-1033-84C8-B8D95FA3C8C3}) (Version: 21.30.0.5 - Intel Corporation)
KMPlayer (remove only) (HKLM-x32\...\The KMPlayer) (Version: 4.2.2.13 - PandoraTV)
KMSpico (HKLM\...\{8B29D47F-92E2-4C20-9EE0-F710991F5D7C}_is1) (Version:  - )
Malwarebytes version 4.0.4.49 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.0.4.49 - Malwarebytes)
Microsoft Office Standard 2016 (HKLM\...\Office16.STANDARD) (Version: 16.0.4266.1001 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50918.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61187 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61186 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.7523 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.7523 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.7523 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.7523 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61135 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61135 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61135 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61135 - Microsoft Corporation)
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61135 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61135 - Microsoft Corporation)
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61135 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61135 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40660 (HKLM\...\{5740BD44-B58D-321A-AFC0-6D3D4556DD6C}) (Version: 12.0.40660 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40660 (HKLM\...\{CB0836EC-B072-368D-82B2-D3470BF95707}) (Version: 12.0.40660 - Microsoft Corporation)
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40660 (HKLM-x32\...\{7DAD0258-515C-3DD4-8964-BD714199E0F7}) (Version: 12.0.40660 - Microsoft Corporation)
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40660 (HKLM-x32\...\{E30D8B21-D82D-3211-82CC-0F0A5D1495E8}) (Version: 12.0.40660 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 x64 Additional Runtime - 14.0.24516 (HKLM\...\{6B66663C-055F-3A2E-A09D-168840A82362}) (Version: 14.0.24516 - Microsoft Corporation)
Microsoft Visual C++ 2015 x64 Minimum Runtime - 14.0.24516 (HKLM\...\{EE6E34BF-D825-384C-AFF5-305DF5CFAF5A}) (Version: 14.0.24516 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.22.27821 (HKLM-x32\...\{5bfc1380-fd35-4b85-9715-7351535d077e}) (Version: 14.22.27821.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\{FD9D64F4-CAF5-3D23-845A-B843C78CC1A5}) (Version: 10.0.60830 - Microsoft Corporation)
Need for Speed™ Payback (HKLM-x32\...\{F4CF3D08-565C-40B7-B351-D3033DE2172B}) (Version: 1.0.51.15364 - Electronic Arts)
NETGATE Registry Cleaner (HKLM\...\NETGATE Registry Cleaner_is1) (Version:  - NETGATE Technologies s.r.o.)
NVAPI Monitor plugin for NvContainer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NvapiMonitor) (Version: 1.19 - NVIDIA Corporation) Hidden
NVIDIA GeForce Experience 3.20.1.57 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.20.1.57 - NVIDIA Corporation)
NVIDIA Graphics Driver 441.66 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 441.66 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.38.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.38.21 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation)
Pro Evolution Soccer 2019 (HKLM-x32\...\{879B9B7F-6AAF-4686-A7FC-E937EE6BE37B}_is1) (Version:  - KONAMI)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7831 - Realtek Semiconductor Corp.)
Update for Skype for Business 2016 (KB4484102) 64-Bit Edition (HKLM\...\{90160000-0012-0000-1000-0000000FF1CE}_Office16.STANDARD_{BE84972D-5F00-49E3-8F22-316ACAB0E6FF}) (Version:  - Microsoft)
Update for Skype for Business 2016 (KB4484102) 64-Bit Edition (HKLM\...\{90160000-00C1-0000-1000-0000000FF1CE}_Office16.STANDARD_{BE84972D-5F00-49E3-8F22-316ACAB0E6FF}) (Version:  - Microsoft)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{32DC821E-4A7D-4878-BEE8-337FA153D7F2}) (Version: 2.63.0.0 - Microsoft Corporation) Hidden
UpdateAssistant (HKLM\...\{F339C545-24DC-4870-AA32-6EB6B0500B95}) (Version: 1.24.0.0 - Microsoft Corporation) Hidden
Windows 10 Update Assistant (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.22899 - Microsoft Corporation)
WinRAR 5.71 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.71.0 - win.rar GmbH)
Your Uninstaller! 7 (HKLM-x32\...\YU2010_is1) (Version: 7.5.2014.3 - URSoft, Inc.)
Средства проверки правописания Microsoft Office 2016 — русский (HKLM\...\{90160000-001F-0419-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden

Packages:
=========
Autodesk SketchBook -> C:\Program Files\WindowsApps\89006A2E.AutodeskSketchBook_5.1.0.0_x64__tf1gferkr813w [2019-11-05] (Autodesk Inc.)
Football Management Ultra-FMU -> C:\Program Files\WindowsApps\TROPHYGAMES.FOOTBALLMANAGEMENTULTRA-FMU_2.1.25.0_x64__g129gj36h42s2 [2018-12-20] (Trophy Games ApS)
March of Empires: War of Lords -> C:\Program Files\WindowsApps\A278AB0D.MarchofEmpires_4.5.0.9_x86__h6adky7gbf63m [2019-12-03] (Gameloft.)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-26] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-26] (Microsoft Corporation) [MS Ad]
Microsoft News -> C:\Program Files\WindowsApps\Microsoft.BingNews_4.33.13094.0_x64__8wekyb3d8bbwe [2019-11-14] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.5.12061.0_x64__8wekyb3d8bbwe [2019-12-11] (Microsoft Studios) [MS Ad]
MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.33.13253.0_x64__8wekyb3d8bbwe [2019-11-23] (Microsoft Corporation) [MS Ad]
Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2019-10-30] (Microsoft Corporation)
Plex -> C:\Program Files\WindowsApps\CAF9E577.Plex_3.2.20.0_x64__aam28m9va5cke [2018-03-07] (Plex)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-2491579097-1836322396-851961227-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12162019191539440_Classes\CLSID\{4299B2BA-5F79-4F6E-ACF8-11DAB8B7E79D}\InprocServer32 -> C:\Users\bojid\AppData\Local\Mail.Ru\Disk-O\CloudShell64.dll (LLC Mail.Ru -> Mail.Ru)
CustomCLSID: HKU\S-1-5-21-2491579097-1836322396-851961227-1001_Classes\CLSID\{4299B2BA-5F79-4F6E-ACF8-11DAB8B7E79D}\InprocServer32 -> C:\Users\bojid\AppData\Local\Mail.Ru\Disk-O\CloudShell64.dll (LLC Mail.Ru -> Mail.Ru)
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} =>  -> No File
ContextMenuHandlers1: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files (x86)\AIMP\System\aimp_menu64.dll [2019-11-15] (Artem Izmaylov -> AIMP DevTeam)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers2: [DaemonShellExtDriveLite] -> {C06369D6-E77D-4626-9656-1256312BD576} => C:\Program Files\DAEMON Tools Lite\DTShl64.dll [2018-12-17] (AVB Disc Soft, SIA -> Disc Soft Ltd)
ContextMenuHandlers3: [DaemonShellExtImageLite] -> {1D1B5D7B-0FC9-452E-902C-12BACD4FBC20} => C:\Program Files\DAEMON Tools Lite\DTShl64.dll [2018-12-17] (AVB Disc Soft, SIA -> Disc Soft Ltd)
ContextMenuHandlers4: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files (x86)\AIMP\System\aimp_menu64.dll [2019-11-15] (Artem Izmaylov -> AIMP DevTeam)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\windows\system32\nvshext.dll [2019-12-07] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers3_S-1-5-21-2491579097-1836322396-851961227-1001: [MailRuCloudContextMenu] -> {4299B2BA-5F79-4F6E-ACF8-11DAB8B7E79D} => C:\Users\bojid\AppData\Local\Mail.Ru\Disk-O\CloudShell64.dll [2019-04-19] (LLC Mail.Ru -> Mail.Ru)

==================== Codecs (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Drivers32-x32: [vidc.XVID] => xvidvfw.dll
HKLM\...\Drivers32-x32: [VIDC.VP80] => vp8vfw.dll

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive за бизнеса.lnk -> C:\Windows\Installer\{90160000-0012-0000-1000-0000000FF1CE}\grv_icons.exe () <==== Cyrillic
ShortcutWithArgument: C:\Users\bojid\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Изпращане в OneNote.lnk -> C:\Program Files\Microsoft Office\Office16\ONENOTEM.EXE (Microsoft Corporation) -> /tsr <==== Cyrillic

==================== Loaded Modules (Whitelisted) =============

2019-01-10 01:17 - 2019-01-10 01:17 - 000016896 _____ () [File not signed] C:\Program Files\KMSpico\WinDivert.dll
2019-08-16 13:29 - 2019-08-16 13:29 - 001635840 _____ (Robert Simpson, et al.) [File not signed] C:\Program Files\Intel\SUR\QUEENCREEK\x64\SQLite.Interop.dll
2019-08-16 13:29 - 2019-08-16 13:29 - 001902080 _____ (SQLite Development Team) [File not signed] C:\Program Files\Intel\SUR\QUEENCREEK\sqlite3.DLL
2019-08-16 13:29 - 2019-08-16 13:29 - 001902080 _____ (SQLite Development Team) [File not signed] C:\Program Files\Intel\SUR\QUEENCREEK\x64\sqlite3.dll

==================== Alternate Data Streams (Whitelisted) ========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData:Easy$Duplicate$Finder [140]
AlternateDataStreams: C:\Users\All Users:Easy$Duplicate$Finder [140]
AlternateDataStreams: C:\ProgramData\Application Data:Easy$Duplicate$Finder [140]
AlternateDataStreams: C:\ProgramData\TEMP:1CE11B51 [152]

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"

==================== Association (Whitelisted) =================

==================== Internet Explorer trusted/restricted ==========

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-2491579097-1836322396-851961227-1001\...\localhost -> localhost
IE trusted site: HKU\S-1-5-21-2491579097-1836322396-851961227-1001\...\webcompanion.com -> hxxp://webcompanion.com

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2017-03-18 23:03 - 2019-02-08 19:43 - 000000884 ____C C:\windows\system32\drivers\etc\hosts
0.0.0.0 serius.mwbsys.com
0.0.0.0 keystone.mwbsys.com

2018-04-29 11:50 - 2018-04-29 11:53 - 000000437 ____C C:\windows\system32\drivers\etc\hosts.ics

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\ProgramData\Oracle\Java\javapath;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\System32\OpenSSH\;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR
HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-12162019191539424\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-21-2491579097-1836322396-851961227-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\bojid\Desktop\68929.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKU\S-1-5-21-2491579097-1836322396-851961227-1001\...\StartupApproved\StartupFolder: => "Изпращане в OneNote.lnk"
HKU\S-1-5-21-2491579097-1836322396-851961227-1001\...\StartupApproved\Run: => "DAEMON Tools Lite Automount"
HKU\S-1-5-21-2491579097-1836322396-851961227-1001\...\StartupApproved\Run: => "QQMusic"
HKU\S-1-5-21-2491579097-1836322396-851961227-1001\...\StartupApproved\Run: => "gtarcade"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{A5DBBC26-A9E6-4DAC-9FC5-ED0A34835DCB}] => (Allow) %systemroot%\system32\alg.exe No File
FirewallRules: [{17FD372B-7A2D-4273-AB85-7289E25EAE34}] => (Allow) %systemroot%\system32\alg.exe No File
FirewallRules: [{3647504A-D091-4975-ACE6-EA6C790F1DBB}] => (Allow) %systemroot%\system32\alg.exe No File
FirewallRules: [{1722C3AD-A3BB-4E7C-B974-7B84FB85E2DA}] => (Allow) %systemroot%\system32\alg.exe No File
FirewallRules: [{F7BE5201-B1AD-4C98-B83D-0C7FF707B686}] => (Allow) %systemroot%\system32\alg.exe No File
FirewallRules: [{7BF3CC51-E1E9-4489-B9E1-AE3AA8AC9F29}] => (Allow) %systemroot%\system32\alg.exe No File
FirewallRules: [{5D1FE110-7DD7-44BB-8994-BBBA0E993B03}] => (Allow) G:\NeedForSpeedPayback.exe No File
FirewallRules: [{16DC7278-CDF0-4404-833F-6BD20B552652}] => (Allow) G:\NeedForSpeedPayback.exe No File
FirewallRules: [{1A951F05-2407-41EA-A698-6F1F37405DF1}] => (Allow) G:\NeedForSpeedPaybackTrial.exe No File
FirewallRules: [{36FABFF1-CD41-46A2-84C0-568FC836C69C}] => (Allow) G:\NeedForSpeedPaybackTrial.exe No File
FirewallRules: [UDP Query User{8978C564-BF2B-4722-8102-2D1F251B3B0A}G:\cs.go war zone\csgo.exe] => (Allow) G:\cs.go war zone\csgo.exe No File
FirewallRules: [TCP Query User{79384DA9-8666-4E59-B64D-BB5D4F66B749}G:\cs.go war zone\csgo.exe] => (Allow) G:\cs.go war zone\csgo.exe No File
FirewallRules: [{3D0FB576-9992-4C63-AB24-A80C84DD89D0}] => (Allow) C:\Users\bojid\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{39FD2466-5EE1-4BC3-94E5-35B3C35B0B3C}] => (Allow) C:\Users\bojid\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{E7EBCB25-639C-4295-B1A5-46499705AA6A}] => (Allow) C:\Users\bojid\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{6D15AE14-1D5F-447C-9A99-C494F588BCA0}] => (Allow) C:\Users\bojid\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{2A9D6A75-81FD-48BE-B704-063D9D5BE983}] => (Allow) C:\Users\bojid\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{98C0C0A5-273B-4178-A970-0DC37FDCD30B}] => (Allow) C:\Users\bojid\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [UDP Query User{8522AD14-9224-409E-A9EB-5D5BE736DEEE}G:\cs.go war zone\launcher\tools\steamcmd.exe] => (Allow) G:\cs.go war zone\launcher\tools\steamcmd.exe No File
FirewallRules: [TCP Query User{E7D9B396-2CAA-44F5-B927-359ED3DCC986}G:\cs.go war zone\launcher\tools\steamcmd.exe] => (Allow) G:\cs.go war zone\launcher\tools\steamcmd.exe No File
FirewallRules: [UDP Query User{305D92BC-F544-46AC-AF98-CC324638CD45}G:\launcher\tools\steamcmd.exe] => (Allow) G:\launcher\tools\steamcmd.exe No File
FirewallRules: [TCP Query User{E6468268-5A03-45F5-9B91-5C941C824A36}G:\launcher\tools\steamcmd.exe] => (Allow) G:\launcher\tools\steamcmd.exe No File
FirewallRules: [{B230E6F2-9509-42E3-A85C-59E1A5DBC387}] => (Allow) G:\csgo_launcher.exe No File
FirewallRules: [{DB420D44-2082-486F-ACAA-C8DD21D335A0}] => (Allow) G:\Loader.exe No File
FirewallRules: [TCP Query User{98407FEB-21DB-4B1B-82C6-E25DAF9227A1}G:\cs.go war zone\launcher\tools\steamcmd.exe] => (Allow) G:\cs.go war zone\launcher\tools\steamcmd.exe No File
FirewallRules: [UDP Query User{9769B24A-DF8B-4729-B8C0-03DAA58A30A2}G:\cs.go war zone\launcher\tools\steamcmd.exe] => (Allow) G:\cs.go war zone\launcher\tools\steamcmd.exe No File
FirewallRules: [TCP Query User{788B027B-06F9-404B-9E44-544D4506FE34}G:\cs.go war zone\csgo.exe] => (Allow) G:\cs.go war zone\csgo.exe No File
FirewallRules: [UDP Query User{FEB9227B-F206-4584-98A0-5A450078B551}G:\cs.go war zone\csgo.exe] => (Allow) G:\cs.go war zone\csgo.exe No File
FirewallRules: [{052EE169-8598-423A-9025-E41AC9251A6D}] => (Allow) C:\Users\bojid\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{8B89BD70-C0EC-4481-B195-769F69A66AA7}] => (Allow) C:\Users\bojid\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [TCP Query User{C4B8C100-CE99-45BD-ABCD-6512154EEF25}C:\users\bojid\appdata\roaming\utorrent\updates\3.5.3_44494.exe] => (Allow) C:\users\bojid\appdata\roaming\utorrent\updates\3.5.3_44494.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [UDP Query User{4DC33396-E492-4A95-9A76-269453847D2F}C:\users\bojid\appdata\roaming\utorrent\updates\3.5.3_44494.exe] => (Allow) C:\users\bojid\appdata\roaming\utorrent\updates\3.5.3_44494.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{DA523D4C-A9E1-4721-9D16-42D5BE9C3BBA}] => (Block) %SystemDrive%\KMPlayer\KMPlayer.exe (Pandora TV Co., Ltd. -> PandoraTV)
FirewallRules: [TCP Query User{726DE22B-7174-4513-AFDF-B2086FE468E1}C:\users\bojid\appdata\roaming\utorrent\updates\3.5.4_44520.exe] => (Allow) C:\users\bojid\appdata\roaming\utorrent\updates\3.5.4_44520.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [UDP Query User{B3B850BD-177E-4311-A978-22951ADA6151}C:\users\bojid\appdata\roaming\utorrent\updates\3.5.4_44520.exe] => (Allow) C:\users\bojid\appdata\roaming\utorrent\updates\3.5.4_44520.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [TCP Query User{F602F287-1BD4-4483-A666-DFAFA2E2CFF2}G:\cs go\counter-strike global offensive\csgo.exe] => (Allow) G:\cs go\counter-strike global offensive\csgo.exe No File
FirewallRules: [UDP Query User{89E58C4F-0653-4EFF-9E59-02C033ED9B29}G:\cs go\counter-strike global offensive\csgo.exe] => (Allow) G:\cs go\counter-strike global offensive\csgo.exe No File
FirewallRules: [TCP Query User{D33BE738-5BF3-456C-8F53-997A602D36CC}G:\cs go\counter-strike global offensive\7launcher\tools\steamcmd\steamcmd.exe] => (Allow) G:\cs go\counter-strike global offensive\7launcher\tools\steamcmd\steamcmd.exe No File
FirewallRules: [UDP Query User{A47F20B2-F05F-470A-9EC3-DD7D5F2100D6}G:\cs go\counter-strike global offensive\7launcher\tools\steamcmd\steamcmd.exe] => (Allow) G:\cs go\counter-strike global offensive\7launcher\tools\steamcmd\steamcmd.exe No File
FirewallRules: [{8C1E097C-7A62-4BA9-B267-72AAA686B0F7}] => (Allow) G:\Counter Strike Global Offensive - Warzone\Counter Strike Global Offensive - Warzone Setup.exe No File
FirewallRules: [{3143A689-C953-4CFD-B94A-9B6FC73B5DB9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{9C5DFE78-2A2B-4C97-867B-BEBA2F23AD81}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{1B4B8942-4CBB-4214-B4EA-CADAA371D79E}] => (Allow) G:\CS GO\Counter-Strike Global Offensive\7launcher\tools\steamcmd\steamcmd.exe No File
FirewallRules: [{187CB010-0612-47EC-8EC4-EE655011FEE9}] => (Allow) G:\CS GO\Counter-Strike Global Offensive\7launcher\tools\steamcmd\steamcmd.exe No File
FirewallRules: [{95B1EF95-44DC-4B8F-8546-81ECCB9B9A52}] => (Allow) G:\CS GO\Counter-Strike Global Offensive\Run_CSGO.exe No File
FirewallRules: [{1F379D6C-02D1-4DEF-B76C-9370DA2BB42D}] => (Allow) G:\CS GO\Counter-Strike Global Offensive\Run_CSGO.exe No File
FirewallRules: [{3B49A406-9B9D-444E-864B-03161E051D17}] => (Allow) G:\Counter-Strike Global Offensive\7launcher\tools\steamcmd\steamcmd.exe (Valve -> Valve Corporation)
FirewallRules: [{E897C650-2AF0-48AD-B4EA-B03D94768CC8}] => (Allow) G:\Counter-Strike Global Offensive\7launcher\tools\steamcmd\steamcmd.exe (Valve -> Valve Corporation)
FirewallRules: [{363CC1D6-59C1-4EA4-B08A-3841336C44BB}] => (Allow) G:\Counter-Strike Global Offensive\Run_CSGO.exe (IP Rainskiy Dmitriy Valeryevich -> SE7EN Solutions)
FirewallRules: [{5327838C-0ADE-4BFE-B778-6425AE597801}] => (Allow) G:\Counter-Strike Global Offensive\Run_CSGO.exe (IP Rainskiy Dmitriy Valeryevich -> SE7EN Solutions)
FirewallRules: [TCP Query User{A49AFA23-1CCE-4726-ADA9-C73C6D7A1CFA}G:\counter-strike global offensive\csgo.exe] => (Allow) G:\counter-strike global offensive\csgo.exe () [File not signed]
FirewallRules: [UDP Query User{2B3F19E8-D40F-4623-8721-E1FBB5FA55F5}G:\counter-strike global offensive\csgo.exe] => (Allow) G:\counter-strike global offensive\csgo.exe () [File not signed]
FirewallRules: [{F5FA42B6-8506-4480-8A3B-EE5307D01887}] => (Allow) G:\Counter-Strike Global Offensive\7launcher\tools\steamcmd\steamcmd.exe (Valve -> Valve Corporation)
FirewallRules: [{77A8E9A1-199A-479F-BB32-A29645618EBF}] => (Allow) G:\Counter-Strike Global Offensive\7launcher\tools\steamcmd\steamcmd.exe (Valve -> Valve Corporation)
FirewallRules: [{E55046A6-2D1C-4A82-9061-9ADF68EF11F6}] => (Allow) G:\Counter-Strike Global Offensive\Run_CSGO.exe (IP Rainskiy Dmitriy Valeryevich -> SE7EN Solutions)
FirewallRules: [{A64BB7F0-F418-4558-B137-34AD597D1D46}] => (Allow) G:\Counter-Strike Global Offensive\Run_CSGO.exe (IP Rainskiy Dmitriy Valeryevich -> SE7EN Solutions)
FirewallRules: [TCP Query User{7DEF3900-1A50-4016-8E22-4E24377528BF}C:\games\counter-strike global offensive\7launcher\tools\steamcmd\steamcmd.exe] => (Allow) C:\games\counter-strike global offensive\7launcher\tools\steamcmd\steamcmd.exe No File
FirewallRules: [UDP Query User{06AFF661-327F-49B4-A05C-2750557805EB}C:\games\counter-strike global offensive\7launcher\tools\steamcmd\steamcmd.exe] => (Allow) C:\games\counter-strike global offensive\7launcher\tools\steamcmd\steamcmd.exe No File
FirewallRules: [TCP Query User{D860EAC2-4030-40E1-BCFF-709E514EB028}C:\games\counter-strike global offensive\csgo.exe] => (Allow) C:\games\counter-strike global offensive\csgo.exe No File
FirewallRules: [UDP Query User{6A5221F9-C45F-45D6-B8C1-C40C256C0959}C:\games\counter-strike global offensive\csgo.exe] => (Allow) C:\games\counter-strike global offensive\csgo.exe No File
FirewallRules: [{C8EBE22E-B60F-4915-9C6D-19A41DEA30F2}] => (Allow) G:\Counter-Strike Global Offensive\7launcher\tools\steamcmd\steamcmd.exe (Valve -> Valve Corporation)
FirewallRules: [{CF2BAF9C-8150-4305-A99C-04C4FF0D8FC0}] => (Allow) G:\Counter-Strike Global Offensive\7launcher\tools\steamcmd\steamcmd.exe (Valve -> Valve Corporation)
FirewallRules: [{C41979C8-5980-4B9C-82D5-648C4575D6E7}] => (Allow) G:\Counter-Strike Global Offensive\Run_CSGO.exe (IP Rainskiy Dmitriy Valeryevich -> SE7EN Solutions)
FirewallRules: [{D2E81CDD-0E92-47FB-98D0-EAD7F36B55FD}] => (Allow) G:\Counter-Strike Global Offensive\Run_CSGO.exe (IP Rainskiy Dmitriy Valeryevich -> SE7EN Solutions)
FirewallRules: [{4F1F4469-FBC0-4349-B8EB-085EFB108A89}] => (Allow) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe (AVB Disc Soft, SIA -> Disc Soft Ltd)
FirewallRules: [TCP Query User{D454E320-3518-487A-9A2C-3DFD950475B6}G:\16nosteam\hl.exe] => (Allow) G:\16nosteam\hl.exe (Valve) [File not signed]
FirewallRules: [UDP Query User{BF181F3B-5FF4-4F83-9252-BBB501E40725}G:\16nosteam\hl.exe] => (Allow) G:\16nosteam\hl.exe (Valve) [File not signed]
FirewallRules: [TCP Query User{F7CF6ABC-AF82-4D79-8C09-B75BDB99E2ED}W:\users\bojid\appdata\roaming\utorrent\utorrent.exe] => (Allow) W:\users\bojid\appdata\roaming\utorrent\utorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [UDP Query User{E8C4987F-7EAA-4486-ACC2-04B96B9086F3}W:\users\bojid\appdata\roaming\utorrent\utorrent.exe] => (Allow) W:\users\bojid\appdata\roaming\utorrent\utorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [TCP Query User{10FC7323-BAFD-451D-9295-DD38836790B9}W:\users\bojid\appdata\roaming\utorrent\updates\3.5.5_44994.exe] => (Allow) W:\users\bojid\appdata\roaming\utorrent\updates\3.5.5_44994.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [UDP Query User{90B6B6A6-887C-44B3-B176-89E4505ED001}W:\users\bojid\appdata\roaming\utorrent\updates\3.5.5_44994.exe] => (Allow) W:\users\bojid\appdata\roaming\utorrent\updates\3.5.5_44994.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{EECCD177-67C6-473B-AF5F-F0A1C2DBC02E}] => (Allow) G:\Counter-Strike Global Offensive\7launcher\tools\steamcmd\steamcmd.exe (Valve -> Valve Corporation)
FirewallRules: [{AA9E26F7-A1C9-48AD-8F43-F25F6B9BED56}] => (Allow) G:\Counter-Strike Global Offensive\7launcher\tools\steamcmd\steamcmd.exe (Valve -> Valve Corporation)
FirewallRules: [{2DEA5CCB-A1B1-4F1F-AB0A-E394CAA51DF8}] => (Allow) G:\Counter-Strike Global Offensive\Run_CSGO.exe (IP Rainskiy Dmitriy Valeryevich -> SE7EN Solutions)
FirewallRules: [{409FEBB9-8B75-4D61-A8A2-D1E7F1DCBF2B}] => (Allow) G:\Counter-Strike Global Offensive\Run_CSGO.exe (IP Rainskiy Dmitriy Valeryevich -> SE7EN Solutions)
FirewallRules: [{92D80591-23A3-4D97-9D60-7ED97897DBBD}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe (@ByELDI -> @ByELDI) [File not signed]
FirewallRules: [{3D0B5926-8C22-4A00-9099-4E549F5B9225}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe (@ByELDI -> @ByELDI) [File not signed]
FirewallRules: [{85E188C8-E89D-406C-868D-5437C864D5FB}] => (Allow) G:\Counter-Strike Global Offensive\7launcher\tools\steamcmd\steamcmd.exe (Valve -> Valve Corporation)
FirewallRules: [{32DDB727-F242-4C00-98FF-CAA2E4E97197}] => (Allow) G:\Counter-Strike Global Offensive\7launcher\tools\steamcmd\steamcmd.exe (Valve -> Valve Corporation)
FirewallRules: [{F1EC71DC-5D17-4C79-9A9D-4C4F5C97565F}] => (Allow) G:\Counter-Strike Global Offensive\Run_CSGO.exe (IP Rainskiy Dmitriy Valeryevich -> SE7EN Solutions)
FirewallRules: [{EB1D5A63-7D9B-4397-97FE-0DD48A786302}] => (Allow) G:\Counter-Strike Global Offensive\Run_CSGO.exe (IP Rainskiy Dmitriy Valeryevich -> SE7EN Solutions)
FirewallRules: [TCP Query User{2ED09B33-BF2F-4161-9A7F-7594B824453E}C:\users\bojid\appdata\roaming\utorrent\updates\3.5.5_45291.exe] => (Allow) C:\users\bojid\appdata\roaming\utorrent\updates\3.5.5_45291.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [UDP Query User{5018EE46-2954-49E5-83EC-0F42859C20C6}C:\users\bojid\appdata\roaming\utorrent\updates\3.5.5_45291.exe] => (Allow) C:\users\bojid\appdata\roaming\utorrent\updates\3.5.5_45291.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{D054ED99-ADEF-4DC1-944F-97227D9F73AD}] => (Allow) C:\Program Files (x86)\Tencent\QQMusic\QQMusicExternal.exe No File
FirewallRules: [{8634BF33-325A-4D83-A01B-86164DA44D2F}] => (Allow) C:\Program Files (x86)\Tencent\QQMusic\moleplugin\tadb.exe No File
FirewallRules: [{4BEBD914-57D0-4119-AEA1-8AE399CF9330}] => (Allow) C:\Program Files (x86)\Tencent\QQMusic\QQMusic.exe No File
FirewallRules: [{A694BA93-A264-4CA5-BBB8-D7ECA68915FA}] => (Allow) C:\Program Files (x86)\Common Files\Tencent\QQMusic\QQMusicService.exe No File
FirewallRules: [{CC9EBB4D-4ED7-4B0C-96C8-694F2D8110C5}] => (Allow) C:\Program Files (x86)\Tencent\QQMusic\QQMusicUp.exe No File
FirewallRules: [TCP Query User{8AC6AB96-54BC-4EDD-B7CD-1E49FD0B6ED3}C:\users\bojid\appdata\roaming\utorrent\updates\3.5.5_45311.exe] => (Allow) C:\users\bojid\appdata\roaming\utorrent\updates\3.5.5_45311.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [UDP Query User{92CCCB67-C72D-4268-AC49-B716EF664708}C:\users\bojid\appdata\roaming\utorrent\updates\3.5.5_45311.exe] => (Allow) C:\users\bojid\appdata\roaming\utorrent\updates\3.5.5_45311.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{D6A43F9F-A89C-4DF0-AEE3-BA42F7E65FDE}] => (Block) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> )
FirewallRules: [{C554F619-64B9-4F25-A85D-BA3F945A76FE}] => (Block) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> )
FirewallRules: [{3D876E57-62E4-445B-BF82-2971019E5382}] => (Allow) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> )
FirewallRules: [{A23B4D04-ADD2-491A-8921-55DB696160D5}] => (Allow) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> )
FirewallRules: [TCP Query User{5F358706-40C9-49EB-A89D-51E498705010}C:\windows\system32\mmc.exe] => (Allow) C:\windows\system32\mmc.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [UDP Query User{4C388BA8-F1AE-4C75-8194-7CE6496743D1}C:\windows\system32\mmc.exe] => (Allow) C:\windows\system32\mmc.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{C2045A0C-6770-4824-9F13-B78F15338DD5}] => (Allow) G:\Counter-Strike Global Offensive\7launcher\tools\steamcmd\steamcmd.exe (Valve -> Valve Corporation)
FirewallRules: [{8A4095BC-C10D-4066-A7D7-E550E6197EF5}] => (Allow) G:\Counter-Strike Global Offensive\7launcher\tools\steamcmd\steamcmd.exe (Valve -> Valve Corporation)
FirewallRules: [{59086788-F231-4A05-90BC-D07F7161E7B7}] => (Allow) G:\Counter-Strike Global Offensive\Run_CSGO.exe (IP Rainskiy Dmitriy Valeryevich -> SE7EN Solutions)
FirewallRules: [{C99412F9-F456-4CA4-90BE-FCFD6E31B4F7}] => (Allow) G:\Counter-Strike Global Offensive\Run_CSGO.exe (IP Rainskiy Dmitriy Valeryevich -> SE7EN Solutions)
FirewallRules: [{BBDEC045-AEA7-4FA7-9CA8-915534A7E267}] => (Allow) LPort=1688
FirewallRules: [{38ADD02F-8DD2-4EE9-85C4-492BF8335635}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{E37531A3-5FDA-44C2-A7B0-D9C7B745A1C9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{E1F1FFF6-0890-4D2B-996C-03C580FC3FB6}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{18551ED9-A5F9-4A60-8E62-7F058C591CF3}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{0689B574-8510-4B2D-9F5A-16F64A414CF2}] => (Allow) G:\Counter-Strike Global Offensive\7launcher\tools\steamcmd\steamcmd.exe (Valve -> Valve Corporation)
FirewallRules: [{6ADDE4B7-1CE4-45F3-9379-9971C051CD99}] => (Allow) G:\Counter-Strike Global Offensive\7launcher\tools\steamcmd\steamcmd.exe (Valve -> Valve Corporation)
FirewallRules: [{F1036F64-8EDF-401C-99B3-375772EDFE64}] => (Allow) G:\Counter-Strike Global Offensive\Run_CSGO.exe (IP Rainskiy Dmitriy Valeryevich -> SE7EN Solutions)
FirewallRules: [{3B35AF26-5829-4E0E-9E8A-8F69E11DB643}] => (Allow) G:\Counter-Strike Global Offensive\Run_CSGO.exe (IP Rainskiy Dmitriy Valeryevich -> SE7EN Solutions)
FirewallRules: [{10369631-55F2-485D-9717-8C6DD7A93ECD}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)

==================== Restore Points =========================

ATTENTION: System Restore is disabled (Total:232.28 GB) (Free:141.65 GB) (61%)

==================== Faulty Device Manager Devices ============


==================== Event log errors: ========================

Application errors:
==================
Error: (12/16/2019 09:11:23 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: Explorer.EXE, version: 10.0.17134.858, time stamp: 0x407a5e89
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x00000000052c0fae
Faulting process id: 0x1150
Faulting application start time: 0x01d5b4346e0abb4c
Faulting application path: C:\windows\Explorer.EXE
Faulting module path: unknown
Report Id: 7d7b17e9-b3ce-42d9-bb8d-567d263b7730
Faulting package full name: 
Faulting package-relative application ID:

Error: (12/16/2019 07:19:44 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: The Open Procedure for service "WmiApRpl" in DLL "C:\windows\system32\wbem\wmiaprpl.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.

Error: (12/16/2019 07:19:44 PM) (Source: PerfNet) (EventID: 2004) (User: )
Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code.

Error: (12/16/2019 07:19:44 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: The Open Procedure for service "MSDTC" in DLL "C:\windows\system32\msdtcuiu.DLL" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.

Error: (12/16/2019 07:19:44 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: The Open Procedure for service "Lsa" in DLL "C:\Windows\System32\Secur32.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.

Error: (12/16/2019 07:19:44 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: The Open Procedure for service "ESENT" in DLL "C:\windows\system32\esentprf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.

Error: (12/16/2019 07:19:44 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.

Error: (12/15/2019 07:54:23 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: The Open Procedure for service "WmiApRpl" in DLL "C:\windows\system32\wbem\wmiaprpl.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.


System errors:
=============
Error: (12/16/2019 07:55:32 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (12/16/2019 07:25:42 PM) (Source: DCOM) (EventID: 10000) (User: NT AUTHORITY)
Description: Unable to start a DCOM Server: {3C296D07-90AE-4FAC-86F9-65EAA8B82D22}. The error:
"5"
Happened while starting this command:
C:\windows\system32\SppExtComObj.exe -Embedding

Error: (12/16/2019 07:25:42 PM) (Source: DCOM) (EventID: 10000) (User: NT AUTHORITY)
Description: Unable to start a DCOM Server: {3C296D07-90AE-4FAC-86F9-65EAA8B82D22}. The error:
"5"
Happened while starting this command:
C:\windows\system32\SppExtComObj.exe -Embedding

Error: (12/16/2019 07:22:33 PM) (Source: DCOM) (EventID: 10016) (User: XI6TNIKA)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user XI6TNIKA\bojid SID (S-1-5-21-2491579097-1836322396-851961227-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (12/16/2019 07:16:00 PM) (Source: DCOM) (EventID: 10016) (User: XI6TNIKA)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8BC3F05E-D86B-11D0-A075-00C04FB68820}
 and APPID 
{8BC3F05E-D86B-11D0-A075-00C04FB68820}
 to the user XI6TNIKA\bojid SID (S-1-5-21-2491579097-1836322396-851961227-1001) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.ContentDeliveryManager_10.0.17134.1_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-350187224-1905355452-1037786396-3028148496-2624191407-3283318427-1255436723). This security permission can be modified using the Component Services administrative tool.

Error: (12/16/2019 07:15:46 PM) (Source: DCOM) (EventID: 10000) (User: NT AUTHORITY)
Description: Unable to start a DCOM Server: {3C296D07-90AE-4FAC-86F9-65EAA8B82D22}. The error:
"5"
Happened while starting this command:
C:\windows\system32\SppExtComObj.exe -Embedding

Error: (12/16/2019 07:15:45 PM) (Source: DCOM) (EventID: 10000) (User: NT AUTHORITY)
Description: Unable to start a DCOM Server: {3C296D07-90AE-4FAC-86F9-65EAA8B82D22}. The error:
"5"
Happened while starting this command:
C:\windows\system32\SppExtComObj.exe -Embedding

Error: (12/16/2019 07:15:33 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 10:21:25 PM on ‎12/‎15/‎2019 was unexpected.


Windows Defender:
===================================
Date: 2019-12-16 19:25:38.335
Description: 
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win64/AutoKMS&threatid=2147723334&enterprise=0
Name: HackTool:Win64/AutoKMS
ID: 2147723334
Severity: High
Category: Tool
Path: file:_C:\Windows\SECOH-QAD.dll; file:_C:\Windows\SECOH-QAD.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Program Files\KMSpico\Service_KMS.exe
Signature Version: AV: 1.307.527.0, AS: 1.307.527.0, NIS: 1.307.527.0
Engine Version: AM: 1.1.16600.7, NIS: 1.1.16600.7

Date: 2019-12-16 19:25:38.278
Description: 
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win64/AutoKMS&threatid=2147723334&enterprise=0
Name: HackTool:Win64/AutoKMS
ID: 2147723334
Severity: High
Category: Tool
Path: file:_C:\Windows\SECOH-QAD.dll
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Program Files\KMSpico\Service_KMS.exe
Signature Version: AV: 1.307.527.0, AS: 1.307.527.0, NIS: 1.307.527.0
Engine Version: AM: 1.1.16600.7, NIS: 1.1.16600.7

Date: 2019-12-16 19:16:07.485
Description: 
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win64/AutoKMS&threatid=2147723334&enterprise=0
Name: HackTool:Win64/AutoKMS
ID: 2147723334
Severity: High
Category: Tool
Path: file:_C:\Windows\SECOH-QAD.dll
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: System
Process Name: Unknown
Signature Version: AV: 1.307.527.0, AS: 1.307.527.0, NIS: 1.307.527.0
Engine Version: AM: 1.1.16600.7, NIS: 1.1.16600.7

Date: 2019-12-16 19:16:00.564
Description: 
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win64/AutoKMS&threatid=2147723334&enterprise=0
Name: HackTool:Win64/AutoKMS
ID: 2147723334
Severity: High
Category: Tool
Path: file:_C:\Windows\SECOH-QAD.dll
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: System
Process Name: Unknown
Signature Version: AV: 1.307.527.0, AS: 1.307.527.0, NIS: 1.307.527.0
Engine Version: AM: 1.1.16600.7, NIS: 1.1.16600.7

Date: 2019-12-16 19:15:45.907
Description: 
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win64/AutoKMS&threatid=2147723334&enterprise=0
Name: HackTool:Win64/AutoKMS
ID: 2147723334
Severity: High
Category: Tool
Path: file:_C:\Windows\SECOH-QAD.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Windows\System32\svchost.exe
Signature Version: AV: 1.307.527.0, AS: 1.307.527.0, NIS: 1.307.527.0
Engine Version: AM: 1.1.16600.7, NIS: 1.1.16600.7

Date: 2019-11-28 19:08:37.718
Description: 
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version: 
Previous Signature Version: 1.305.2893.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.16500.1
Error code: 0x80240438
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support. 

CodeIntegrity:
===================================

Date: 2019-12-03 19:29:03.717
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume10\Users\bojid\Desktop\del\temp\mount\Windows\WinSxS\amd64_windows-devices-perception_31bf3856ad364e35_10.0.18362.1_none_97d30a21115429c4\Windows.Devices.Perception.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2019-12-03 19:29:03.703
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume10\Users\bojid\Desktop\del\temp\mount\Windows\WinSxS\amd64_windows-devices-perception_31bf3856ad364e35_10.0.18362.1_none_97d30a21115429c4\Windows.Devices.Perception.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2019-12-03 19:29:03.689
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume10\Users\bojid\Desktop\del\temp\mount\Windows\WinSxS\amd64_windows-devices-perception_31bf3856ad364e35_10.0.18362.1_none_97d30a21115429c4\Windows.Devices.Perception.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2019-12-03 19:29:03.664
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume10\Users\bojid\Desktop\del\temp\mount\Windows\WinSxS\amd64_windows-devices-perception_31bf3856ad364e35_10.0.18362.1_none_97d30a21115429c4\Windows.Devices.Perception.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2019-12-03 19:26:59.599
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume10\Users\bojid\Desktop\del\temp\mount\Windows\WinSxS\amd64_multipoint-wmswlfltr_31bf3856ad364e35_10.0.18362.1_none_cecfa3cb9157c823\WmsWlFltr.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2019-12-03 19:26:59.595
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume10\Users\bojid\Desktop\del\temp\mount\Windows\WinSxS\amd64_multipoint-wmswlfltr_31bf3856ad364e35_10.0.18362.1_none_cecfa3cb9157c823\WmsWlFltr.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2019-12-03 19:26:59.591
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume10\Users\bojid\Desktop\del\temp\mount\Windows\WinSxS\amd64_multipoint-wmswlfltr_31bf3856ad364e35_10.0.18362.1_none_cecfa3cb9157c823\WmsWlFltr.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2019-12-03 19:26:59.574
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume10\Users\bojid\Desktop\del\temp\mount\Windows\WinSxS\amd64_multipoint-wmswlfltr_31bf3856ad364e35_10.0.18362.1_none_cecfa3cb9157c823\WmsWlFltr.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

==================== Memory info =========================== 

BIOS: American Megatrends Inc. G752VY.211 01/19/2016
Motherboard: ASUSTeK COMPUTER INC. G752VY
Processor: Intel(R) Core(TM) i7-6700HQ CPU @ 2.60GHz
Percentage of memory in use: 73%
Total physical RAM: 8127.51 MB
Available physical RAM: 2128.37 MB
Total Virtual: 10038.51 MB
Available Virtual: 2734.18 MB

==================== Drives ================================

Drive 😄 (System) (Fixed) (Total:232.28 GB) (Free:141.65 GB) NTFS
Drive d: (MOVIES) (Fixed) (Total:341.8 GB) (Free:120.73 GB) NTFS
Drive f: (PROGRAMS) (Fixed) (Total:150.26 GB) (Free:135.8 GB) NTFS
Drive g: (GAMES) (Fixed) (Total:341.8 GB) (Free:115.97 GB) NTFS
Drive w: (WINDOWS 10) (Fixed) (Total:97.1 GB) (Free:24.48 GB) NTFS

\\?\Volume{957fb2a2-ecc2-44a3-8a33-1499e8a6d508}\ (Recovery) (Fixed) (Total:0.44 GB) (Free:0.06 GB) NTFS
\\?\Volume{1ef3dddb-a972-4bf7-9f7f-b4695483b523}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32
\\?\Volume{68c6f7f2-1303-11e9-a3f8-973492b92990}\ () (Fixed) (Total:0.58 GB) (Free:0.55 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 27106E20)

Partition: GPT.

==========================================================
Disk: 1 (Protective MBR) (Size: 232.9 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt =======================

 

 

Ще оставя случая за IcoTonev, че аз вече едвам гледам. Но не видях файлове с подобно разширение.

Качете един файл на следния адрес да видим с какво си имаме работа:

https://id-ransomware.malwarehunterteam.com/

  • Автор
преди 4 минути, B-boy/StyLe/ написа:

Ще оставя случая за IcoTonev, че аз вече едвам гледам. Но не видях файлове с подобно разширение.

Качете един файл на следния адрес да видим с какво си имаме работа:

https://id-ransomware.malwarehunterteam.com/

Ами не е точно разширение,ще снимам.

 

 

Untitled.png

Но това са препратки. Интересно. А имате ли файлове с такива разширения?

В Command Prompt (CMD.exe) въведете следната команда и натиснете Enter:

Dir /b c:\*.KUKI* /s >> "%userprofile%\desktop\dir.txt"

Публикувайте файла dir.txt, който ще се създаде на десктопа.

  • Автор

Не съм срещал промени в разширенията.Това го забелязах,след като ми помагахте за изтриване на папката.

dir.txt

Файла е празен.В CMD изписа,че не е открит файла

Да, файла е празен, защото явно няма файлове с такива разширения. Моето заключение е, че това е програма, която се е асоциирала с разширенията за BMP и TXT.

Вижте какви са настройките в

HKEY_CLASSES_ROOT\.bmp и в HKEY_CLASSES_ROOT\.txt

Ето при мен например PicosmosShows се е намърдала в bmp и psd графичните формати...реално не е превзела асоциациите на файловете, а само се е добавила като име:

9gXpNmZ.png

N3o5Kxy.png

 

 

  • Автор
преди 3 минути, B-boy/StyLe/ написа:

Да, файла е празен, защото явно няма файлове с такива разширения. Моето заключение е, че това е програма, която се е асоциирала разширенията за BMP и TXT.

Вижте какви са настройките в

HKEY_CLASSES_ROOT\.bmp и в HKEY_CLASSES_ROOT\.txt

 

Благодаря за отделеното време.Да разбирам ли,че съмненията ви са не са се оправдали и системата не е заразена?

След поправката:

feXWlxo.png

nl94S1I.png

 

преди 1 минута, bojoviki написа:

Благодаря за отделеното време.Да разбирам ли,че съмненията ви са не са се оправдали и системата не е заразена?

Така изглежда. Като споменахте, че имате файлове с променени имена си помислих за най-лошото...но се оказа, че не имената на файловете ви са променени, а на препратките...Пфууу ;)

  • Автор

Може би не съм се изразил правилно,моя грешка.Ще се опитам да поправя регистрите,макар,че там не пипам особено много.Благодаря все пак и лека вечер.

По-добре не пипайте много там ако не знаете какво точно правите или поне направете бекъп на регистрите преди манипулация.

Лека вечер и на вас! ;)

 

Между другото прегледах лог файловете и са чисти. Има някои остатъци, които ако искате могат да се почистят.

Видях и защо папката C:\Users\bojid\Desktop\del е била заключена за изтриване. Може би е била използвана от някоя актуализация на Windows, защото временно е била заредена Junction препратка към C:\Windows\WinSxS\amd64_windows-devices-perception_31bf3856ad364e35_10.0.18362.1_none_97d30a21115429c4

Цитат

Windows is unable to verify the image integrity of the file \Device\HarddiskVolume10\Users\bojid\Desktop\del\temp\mount\Windows\WinSxS\amd64_windows-devices-perception_31bf3856ad364e35_10.0.18362.1_none_97d30a21115429c4\Windows.Devices.Perception.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Дано с изтриването на папката не е била изтрита и дестинацията в C:\Windows\WinSxS папката. Със скрипта ще пуснем проверка на системните файлове и затова може да отнеме повече време и да изглежда като забил, но не го закачайте. Дайте му време да завърши. Може да отнеме над половин час.

Със скрипта ще пуснем и проверка на контекстното меню да видим дали ще мога да ви помогна да оправим (премахнем KUKI надписа от него).

Изтеглете fixlist.txt и го запазете в папката, където сте свалили FRST64.exe (на десктопа)

Стартирайте FRST64.exe и натиснете бутона Fix веднъж!

След като приключи, ако ви поиска рестарт - съгласете се. След рестарта публикувайте лог файла - fixlog.txt, който ще се създаде след работата на програмата.

Внимание: Скрипта е създаден за текущата система. Да не се ползва за други системи с подобни проблеми!

  • Автор

Здравейте отново,контекстното меню го оправих,надписа е премахнат.Папката del наистина беше с ъпдейт на 10ката.Dark ми помагаше да ъпдейтна,понеже се чупеше някъде инсталацията,но така и не се получи.След тази информация да продължавам ли по стъпките,които сте описали?

Ами както желаете. В скрипта има премахване на излишни (липсващи вече обекти) и проверка на системните файлове (с команди които могат да се пуснат и ръчно) и някои други благинки - поправка на performance броячите, премахване на липсващи правила в защитната стена, премахване на подозрителни ADS стриймове и прочие. Ако пускате скрипта е добре да активирате обаче System Restore преди това, защото според лог файловете сте го спряли и няма да можем да върнем състоянието на системата при нужда.

А иначе надписите как ги оправихте? С инструкциите, които дадох или по друг начин? (То има и програми за манипулация на контекстните менюта, но те общо взето и те човъркат в регистрите) :)

  • Автор

Надписите ги оправих по вашите инструкции,но само промених наименованието.Ще стартирам скрипта.Благодаря

 

Untitled.png

Untitled.png1.png

  • Автор

Готово,дано да се е получило,понеже лаптопа по едно време изгасна.Стартирах го наново,и FRST64.exe все още работеше.

Fixlog.txt

Явно е заспал щом след това всичко е продължило откъдето е спряло. Въпреки всичко не сте пуснали System Restore преди скрипта.

След малко ще прегледам лог файла, че е дълъъъъъъг. :)

  • Автор
преди 1 минута, B-boy/StyLe/ написа:

Явно е заспал щом след това всичко е продължило откъдето е спряло. Въпреки всичко не сте пуснали System Restore преди скрипта.

След малко ще прегледам лог файла, че е дълъъъъъъг. :)

Оуу,да.Него съм го забравил.Ами от много време не го ползвам.Благодаря за отделеното време.

П.П.Въпрос:Възможно ли е от лог файла да се разбере какво чупи инсталацията на последния ъпдейт?

Изглежда наред. Само поправката на performance брочите не е минала успешно, но обикновено ако се стартира два пъти един след друг и втория път е успешен.

От CMD.exe стартиран с десен бутон Run as administrator изпълнете командата два пъти и натиснете Enter след всеки един път и направете снимка на резултатите:

lodctr /R

lodctr /R

току-що, bojoviki написа:

П.П.Въпрос:Възможно ли е от лог файла да се разбере какво чупи инсталацията на последния ъпдейт?

Не, но и това не е целта на инструмента като цяло. Нищо, че с него могат да се изпълняват повечето от вградените в Windows команди.

А иначе според SFC и DISM системните файлове са наред. За останалото трябва да питате колегата DarkEdge, който е по-запознат с 10. Аз съм още на 8.1 ;)

Цитат

Windows Resource Protection did not find any integrity violations.

Цитат

No component store corruption detected.
The operation completed successfully.

За изтриване на FRST, просто го преименувайте на uninstall.exe и го стартирайте. Системата може да се рестартира.

Поздрави!

Чудесно. Ами това е от мен.

Деинсталирайте FRST и след това сме готови.

Не е лоша идея според мен да поставите до Windows Defender програма за защита от Ransomware като някоя от следните:

https://box.kaspersky.com/f/4c6ea29841f946fea873/?dl=1

https://www.kaldata.com/софтуер/appcheck-anti-ransomware-274541.html

(Но само една от двете). И винаги правете бекъп на важните си документи на външни носители или cloud услуги (за по-малко важните).

Поздрави и лека вечер! ;)

  • Автор

Благодаря ви много,FRST е деинсталирана.Лека вечер ви желая

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.