Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Windows Defender - проблем с иконата

Featured Replies

Здравейте.Имам антивирусна програма 360 Total Security.Спрял съм дефендъра,но през 10-15мин. ми излиза съобщение да я включа от прозореца за известия ма не става трите точки за промяна на това съобщение не светят за промяна.Как да премахна досадното съобщение за програмата, която си е с Windows 10 Pro?

  • Отговори 54
  • Прегледи 10,9k
  • Създадено
  • Последен отговор

Потребители с най-много отговори

Най-популярни публикации

  • Естествено , друг китаец в системата ти има ли? Махаш го и си оставаш на WD и вече си го конфигурираш.

  • modedit:  Обединих темите ви в една ...не е нужно за всеки ваш проблем с Windows Defender  да създавате нова тема...! Благодаря за разбирането..!  

  • Как деинсталирахте програмата ..? Вероятни са остатъци от програмата и точно това да е проблема..!  How To Uninstall 360 Total Security on Windows | 360 Total Security

Публикувани изображения

  • Автор

Не може да се инсталира.Слагам паролата разхивирам и като се покаже ексе файла с програмата изчезва за секунди и при спряна ант.програма моята не дефендъра и като съм я дал в исключение за нея в антив.програма,и включена пак така.

Цитат

Компонент: Защита за файловете
Описание на резултат: Изтрито
Тип: Троянец
Име: Trojan-Downloader.Win32.Trone.oo
Точност: Точно
Ниво на заплаха: Високо
Тип на обекта: Файл
Име на обекта: dfControl.exe
Път на обекта: C:\Users\ХХХХХХi\Downloads\dControl\dControl\dControl
MD5: 10D8E4CA3FA2902859C77F41BAEE4DDA

 

преди 50 минути, nikssi написа:

 

Цитат

This file is Encrypted because “Defender Control” Software may cause false alerts in VirusTotal

 

Password : sordum

Стартирай gpedit.msc и разгърни:

Computer Configuration
> Administrative Templates
> Windows Components
> Windows Defender Antivirus
 > Real-time Protection
В десния панел кликни двукратно на Turn on behavior monitoring policy, избери Disabled >[Apply] > [OK]
turn-off-win-defender-policy.jpg?itok=n5OUYgxI

В Real-time Protection кликни двукатно на Monitor file and program activity on your computer policy
defender-reat-time-protection-policies__.jpg?itok=d-aA6vcq

избери Disabled >[Apply] > [OK]

преди 2 часа, pancho1960 написа:

Не може да се инсталира.Слагам паролата разхивирам и като се покаже ексе файла с програмата изчезва за секунди и при спряна ант.програма моята не дефендъра и като съм я дал в исключение за нея в антив.програма,и включена пак така.

Инструментът не се инсталира! Ползва се като портативен. Вариант за заобикаляне на Дефендъра е с помощта на Defender Exclusion Tool да се добави папка  изклчения и в тази папка да се разархивира и стартира Defender Control.
 

А има вариант да се добавят изклчения в дефендъра с помощта на скрипт, който се записва в папката, където ще се разархивира DControl.exe:
 

call :Admin

START Powershell -nologo -noninteractive -windowStyle hidden -noprofile -command ^
$First = "Add-MpPreference -ThreatIDDefaultAction_Ids "; ^
$Third = " -ThreatIDDefaultAction_Actions Allow -Force"; ^
$ListPath = "%~dp0","%~dp0dfControl.exe" ; ^
$First = "Add-MpPreference -ExclusionPath "; ^
$Third = "-Force"; ^
ForEach ($Path in $ListPath) { Invoke-Expression ($First + $Path + $Third) }; ^

:Admin
reg query "HKU\S-1-5-19\Environment" >nul 2>&1
if not %errorlevel% EQU 0 (
    cls
    powershell.exe -windowstyle hidden -noprofile "Start-Process '%~dpnx0' -Verb RunAs"
    exit
)

Запазва се от notepad примерно като Def_excl.bat.

  • Автор

Не може да се инсталира.Слагам паролата разхивирам и като се покаже ексе файла с програмата изчезва за секунди и при спряна ант.програма моята не дефендъра и като съм я дал в исключение за нея в антив.програма,и включена пак така.

Не ми излиза твойта опция ,както си показал на снимката.1033122799_Screenshot2022-02-26233259.png.09c1eb984de59d07f542a9a7fcb0080b.png

Според теб дали да оставя и двете антивирусни да работят или да махна тая 360 Total Security или дефендъра?

преди 45 минути, pancho1960 написа:

Според теб дали да оставя и двете антивирусни да работят или да махна тая 360 Total Security или дефендъра?

Махай го този китаец, само проблеми ти прави. Не знам какво толкова му харесват на този шпионин.

  • Автор

Имаш предвид 360 Total Security ли?

преди 1 час, pancho1960 написа:

Имаш предвид 360 Total Security ли?

Естествено , друг китаец в системата ти има ли? Махаш го и си оставаш на WD и вече си го конфигурираш.

  • Автор

Здравейте.Искам да попитам как да си върна иконата на Windows Defender  в трея до часовника в лентата на задачите.Когато го бях преинсталирал около два месеца заради калпав ъпдейт си беше там,но спрях дефендера и тя си стоеше ,но след време изчезна сама защото имах друга антив.програма 360 Total security.Сега реших да махна 360Тотала и я деинсталирах и да си остана с вградената Windows Defender.Пуснах я да сканира настроена е,но иконата не се появява долу в трея до часовника.Гледах от тук ама не или бъркам някъде.https://bg.macspots.com/how-show-hide-windows-defender-tray-icon-windows-10

modedit:  Обединих темите ви в една ...не е нужно за всеки ваш проблем с Windows Defender  да създавате нова тема...! Благодаря за разбирането..! :) 

преди 9 минути, pancho1960 написа:

Сега реших да махна 360Тотала и я деинсталирах

Как деинсталирахте програмата ..? Вероятни са остатъци от програмата и точно това да е проблема..! 

How To Uninstall 360 Total Security on Windows | 360 Total Security

  • Автор

В старт менюто има икона и мога да я закача в лентата на задачата , но тя отваря само приложението , не примерно настройки за програмата ,като карантина и др.Програмата 360Total Security съм я деинсталирал от показаното тук:https://soringpcrepair.com/how-remove-360-total-security-from-computer/

Enable_Windows_Security_notification_icon_for_all_users.reg

  • Запазете .reg файла на вашия работен плот
  • Щракнете двукратно изтегления .reg файл, за да го обедините.
  • Когато бъдете подканени, щракнете Run, OK (UAC), Yes и OK, за да одобрите сливането.
  • Рестартирайте компютъра
  • Проверете и пишете за резултата
  • Можете да изтриете изтегления .reg файл

Hide or Show Windows Security Notification Area Icon in Windows 10 | Tutorials (tenforums.com)

  • Автор

В старт менюто има икона и мога да я закача в лентата на задачата , но тя отваря само приложението , не примерно настройки за програмата ,като карантина и др.Програмата 360Total Security съм я деинсталирал от показаното тук:https://soringpcrepair.com/how-remove-360-total-security-from-computer/

Как да я намеря тази карантина на файловете където ги слага дефендъра.Гледах клипове от тубата ама са за по стара версия на дефендера.Аз съм с

Издание    Windows 10 Pro
Версия    21H2
Инсталирана на    ‎12.‎1.‎2022 ‎г.
Компилация на ОС    19044.1566
Персонализиране    Windows Feature Experience Pack 120.2212.4170.0

 

  • Автор

Много Ви благодаря Г-н icotonev.Излезе иконата и работи.А имам ли възможност как да я видя тази карантина ,където влизат заразените файлове?Гледах един клип в тубата там един път месечно предлагат да се използва и програмата:https://www.malwarebytes.com/

  • Автор

С коя програма да почистя компютъра си идеално ,ако имам вируси за да съм сигурен ,че е чист?Имам само Windows Defender ,но той хваща по някой път вирус при пълно сканиране за да си направя бекъп на дял :C: с програмата:Macrium Reflect понеже Windows  е на два месеца след преинсталиране.

В такъв случай ще прехвърля темата ви в раздел:  Премахване на зловреден софтуер - kaldata.com - Форуми

Очаквам резултати от сканирането със следната програма:

Сканиране с Farbar Recovery Scan Tool 

  • Моля изтеглете  Farbar Recovery Scan Tool (според версията на Windows изберете 32 битовата или 64 битовата версия) и го запазете на десктопа.
  • Стартирайте файла FRST.exe (или FRST64.exe)
  • Програмата ще се стартира. Натиснете YES за да се съгласите с лицензионното споразумение.
  • Натиснете бутона Scan
  • Изчакайте търпеливо проверката да приключи.
  • Ще се създадат два лог файла с името - FRST.txt и Addition.txt на десктопа.
  • Копирайте съдържанието на файла FRST.txt в следващия си пост.Прикачете Addition.txt в коментар си (погледнете опцията Прикачване на файлове, когато публикувате мнение).

 

  Дневници 

В следващия си отговор, моля да включите (като копирате целите съдържания ) следните дневници:

  • FRST.txt (копирате цялото съдържание)
  • Addition.txt (копирате цялото съдържание
  • Автор

:)

 

Addition.txt FRST.txt

Spoiler

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27-02-2022
Ran by Pancho (administrator) on PANCHO (Micro-Star International Co., Ltd. MS-7B89) (02-03-2022 19:48:55)
Running from C:\Users\Pancho\OneDrive\Работен плот
Loaded Profiles: Pancho
Platform: Microsoft Windows 10 Pro Version 21H2 19044.1566 (X64) Language: Английски (Съединени щати) -> Български (България)
Default browser: FF
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(C:\Program Files (x86)\Digital Communications\SAntivirus\SAntivirusService.exe ->) (Digital Communications Inc -> DlGlTAL COMMUNICATIONS INC) C:\Program Files (x86)\Digital Communications\SAntivirus\SAntivirusClient.exe
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe <2>
(Eclipse.org Foundation, Inc. -> Temurin) C:\Program Files (x86)\Universal Media Server\jre8\bin\javaw.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SystemSettingsAdminFlows.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <20>
(Nvidia Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(services.exe ->) (Digital Communications Inc -> DlGlTAL COMMUNICATIONS INC) C:\Program Files (x86)\Digital Communications\SAntivirus\SAntivirusIC.exe
(services.exe ->) (Digital Communications Inc -> DlGlTAL COMMUNICATIONS INC) C:\Program Files (x86)\Digital Communications\SAntivirus\SAntivirusService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.10-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.10-0\NisSrv.exe
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3>
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_3b12ac0f95b18b9d\Display.NvContainer\NVDisplay.Container.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SecurityHealthHost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.1525_none_7e00daaa7c97a563\TiWorker.exe
(SystemSettingsAdminFlows.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Users\Pancho\AppData\Local\Temp\46638535-AF23-4CD7-A3CC-A6CDFFCF2C20\DismHost.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Policies\Explorer: [NoAutorun] 1
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-176537593-2728283085-4065151155-1001\...\Run: [Windows Defender] => '% ProgramFiles%  Windows Defender  MSASCui.exe'-runkey (No File)
HKU\S-1-5-21-176537593-2728283085-4065151155-1001\...\Run: [uTorrent] => C:\Program Files (x86)\uTorrent\uTorrent.exe [399224 2022-01-14] (BitTorrent Inc -> BitTorrent, Inc.)
HKU\S-1-5-21-176537593-2728283085-4065151155-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-176537593-2728283085-4065151155-1001\...\Policies\Explorer: [NoAutorun] 1
HKU\S-1-5-21-176537593-2728283085-4065151155-1001\...\MountPoints2: {976dc93c-74a2-11ec-832b-2cf05d810562} - "F:\setup.exe"
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Universal Media Server.lnk [2022-01-13]
ShortcutTarget: Universal Media Server.lnk -> C:\Program Files (x86)\Universal Media Server\UMS.exe (Universal Media Server) [File not signed]
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {042BED6D-2A5A-4D59-92C6-2BDC651E7B16} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1656320 2022-01-28] (Nvidia Corporation -> NVIDIA Corporation)
Task: {0BAB7644-FFA1-4E37-8ED8-407F4602162B} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe do-task "308046B0AF4A39CB"
Task: {14392B30-5500-4F1C-9410-ADB797A07440} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1656320 2022-01-28] (Nvidia Corporation -> NVIDIA Corporation)
Task: {2B27EA45-7EFA-4ECF-AE98-0573AC3059E0} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [906752 2022-01-28] (Nvidia Corporation -> NVIDIA Corporation)
Task: {48E5C71B-F87B-43BA-AE6C-387D1BE5C1E0} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [906752 2022-01-28] (Nvidia Corporation -> NVIDIA Corporation)
Task: {4CBE5AA0-4F05-42E4-97F2-986CA403AF55} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.10-0\MpCmdRun.exe [925848 2022-02-26] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {51BB9AC7-9B1B-40AF-AA7A-613779803F0C} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate
Task: {7449CA2A-BF9F-41F3-A9FA-4ED12E7E24F2} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.10-0\MpCmdRun.exe [925848 2022-02-26] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {77886110-142F-400E-B64D-38EE969F94B5} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.10-0\MpCmdRun.exe [925848 2022-02-26] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {7DD731D8-513D-495F-B2F9-464AB82FB8F1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.10-0\MpCmdRun.exe [925848 2022-02-26] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {890B7231-4947-4FC4-AF0A-552D858109C7} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3339472 2022-02-03] (Nvidia Corporation -> NVIDIA Corporation)
Task: {A96D59CC-0E8D-4E02-BE48-610EE138FB1D} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1656320 2022-01-28] (Nvidia Corporation -> NVIDIA Corporation)
Task: {AC9A99FC-4672-4C97-8F38-5A1C30269770} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1656320 2022-01-28] (Nvidia Corporation -> NVIDIA Corporation)
Task: {E0D9E82A-DEE2-4177-A80F-C12CA454E8E0} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [647376 2022-01-28] (Nvidia Corporation -> NVIDIA Corporation)
Task: {E6254BE0-B6D8-4F6B-B56A-FA14E8779B7C} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [1009872 2021-11-02] (Nvidia Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.100.1
Tcpip\..\Interfaces\{ca2ec9f2-e047-4daf-b11d-6bac02f97cf9}: [DhcpNameServer] 192.168.100.1

Edge:
=======
Edge Profile: C:\Users\Pancho\AppData\Local\Microsoft\Edge\User Data\Default [2022-03-01]

FireFox:
========
FF DefaultProfile: tx3x9c32.default
FF ProfilePath: C:\Users\Pancho\AppData\Roaming\Mozilla\Firefox\Profiles\tx3x9c32.default [2022-01-13]
FF ProfilePath: C:\Users\Pancho\AppData\Roaming\Mozilla\Firefox\Profiles\2ql37ue6.default-release [2022-03-02]
FF Homepage: Mozilla\Firefox\Profiles\2ql37ue6.default-release -> hxxps://homepage.bg/|hxxps://***/bananas
FF Session Restore: Mozilla\Firefox\Profiles\2ql37ue6.default-release -> is enabled.
FF Notifications: Mozilla\Firefox\Profiles\2ql37ue6.default-release -> hxxps://www.kaldata.com
FF Extension: (АБВ Уведомител) - C:\Users\Pancho\AppData\Roaming\Mozilla\Firefox\Profiles\2ql37ue6.default-release\Extensions\[email protected] [2022-01-12]
FF Extension: (AdBlocker Ultimate) - C:\Users\Pancho\AppData\Roaming\Mozilla\Firefox\Profiles\2ql37ue6.default-release\Extensions\[email protected] [2022-01-12]
FF Extension: (Fire Fox, The Anime Girl: Nebula Space [Red]) - C:\Users\Pancho\AppData\Roaming\Mozilla\Firefox\Profiles\2ql37ue6.default-release\Extensions\[email protected] [2022-01-12]
FF Extension: (Fire Fox, The Anime Girl: Nebula Space [Blue]) - C:\Users\Pancho\AppData\Roaming\Mozilla\Firefox\Profiles\2ql37ue6.default-release\Extensions\[email protected] [2022-01-12]
FF Extension: (Google Translator for Firefox) - C:\Users\Pancho\AppData\Roaming\Mozilla\Firefox\Profiles\2ql37ue6.default-release\Extensions\[email protected] [2022-01-12]
FF Extension: (theme2) - C:\Users\Pancho\AppData\Roaming\Mozilla\Firefox\Profiles\2ql37ue6.default-release\Extensions\{02326643-97e1-4c77-9c06-d8662ab54ba9}.xpi [2022-01-12]
FF Extension: (FireFox Quantum - Blue) - C:\Users\Pancho\AppData\Roaming\Mozilla\Firefox\Profiles\2ql37ue6.default-release\Extensions\{04d24a4c-761a-4dac-bcf4-d7c6c2bed9ce}.xpi [2022-01-12]
FF Extension: (FIRE2) - C:\Users\Pancho\AppData\Roaming\Mozilla\Firefox\Profiles\2ql37ue6.default-release\Extensions\{38eace05-4183-4109-a66e-63d3998a8c1f}.xpi [2022-01-12]
FF Extension: (Blue Glow Theme) - C:\Users\Pancho\AppData\Roaming\Mozilla\Firefox\Profiles\2ql37ue6.default-release\Extensions\{4dd9d8d5-b091-48e9-a092-74e30d6864f4}.xpi [2022-01-12]
FF Extension: (pink polkadots theme <3) - C:\Users\Pancho\AppData\Roaming\Mozilla\Firefox\Profiles\2ql37ue6.default-release\Extensions\{52cdd758-87e2-43e1-85e9-6361d58a3f9b}.xpi [2022-01-12]
FF Extension: (RED) - C:\Users\Pancho\AppData\Roaming\Mozilla\Firefox\Profiles\2ql37ue6.default-release\Extensions\{5d8f3509-5bf8-4e9a-b374-38b1c3abf1f1}.xpi [2022-01-12]
FF Extension: (Vintage plain ) - C:\Users\Pancho\AppData\Roaming\Mozilla\Firefox\Profiles\2ql37ue6.default-release\Extensions\{62cfd93d-1046-406b-8823-85717ef40b0c}.xpi [2022-01-12]
FF Extension: (ANIMATED  FIREFOX) - C:\Users\Pancho\AppData\Roaming\Mozilla\Firefox\Profiles\2ql37ue6.default-release\Extensions\{68637f4d-f924-4aae-b062-b929b20e5ead}.xpi [2022-01-12]
FF Extension: (YouTube High Definition) - C:\Users\Pancho\AppData\Roaming\Mozilla\Firefox\Profiles\2ql37ue6.default-release\Extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi [2022-01-12]
FF Extension: (Purple and Gold) - C:\Users\Pancho\AppData\Roaming\Mozilla\Firefox\Profiles\2ql37ue6.default-release\Extensions\{84de84a5-1a8c-40fe-b138-1aa8a529ca46}.xpi [2022-01-12]
FF Extension: (YouTube Converter Button) - C:\Users\Pancho\AppData\Roaming\Mozilla\Firefox\Profiles\2ql37ue6.default-release\Extensions\{8f4bbf79-5514-4d04-a901-d5fabfe91d73}.xpi [2022-01-12]
FF Extension: (theme) - C:\Users\Pancho\AppData\Roaming\Mozilla\Firefox\Profiles\2ql37ue6.default-release\Extensions\{95f95f17-aa65-4d42-9fce-d73aae667674}.xpi [2022-01-12]
FF Extension: (DarkTheme) - C:\Users\Pancho\AppData\Roaming\Mozilla\Firefox\Profiles\2ql37ue6.default-release\Extensions\{99c277af-d778-4a0b-9faa-b1d8165f0a55}.xpi [2022-01-12]
FF Extension: (Firefox Quantum by M♥Donna) - C:\Users\Pancho\AppData\Roaming\Mozilla\Firefox\Profiles\2ql37ue6.default-release\Extensions\{9e05d9a4-a9ac-48a6-8e0d-e599cbc4498b}.xpi [2022-01-12]
FF Extension: (A Color Within Another Color) - C:\Users\Pancho\AppData\Roaming\Mozilla\Firefox\Profiles\2ql37ue6.default-release\Extensions\{9e420261-1c2f-4eb7-a9f0-dc7292f17459}.xpi [2022-01-12]
FF Extension: (solar system by candelora) - C:\Users\Pancho\AppData\Roaming\Mozilla\Firefox\Profiles\2ql37ue6.default-release\Extensions\{a6237f6d-0674-4dc8-a59f-a010c2758d4c}.xpi [2022-01-12]
FF Extension: (Red Tiles) - C:\Users\Pancho\AppData\Roaming\Mozilla\Firefox\Profiles\2ql37ue6.default-release\Extensions\{a91f90b0-9320-4464-a2d4-3f229c575915}.xpi [2022-01-12]
FF Extension: (Casino Time) - C:\Users\Pancho\AppData\Roaming\Mozilla\Firefox\Profiles\2ql37ue6.default-release\Extensions\{aac9360d-e5f1-4e02-b90f-3cea960f76dc}.xpi [2022-01-12]
FF Extension: (Speed Tweaks) - C:\Users\Pancho\AppData\Roaming\Mozilla\Firefox\Profiles\2ql37ue6.default-release\Extensions\{c541dcb6-72ed-450d-8186-680e9d12b305}.xpi [2022-01-12]
FF Extension: (Adblock Plus — безплатен блокер на реклами) - C:\Users\Pancho\AppData\Roaming\Mozilla\Firefox\Profiles\2ql37ue6.default-release\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2022-01-12]
FF Extension: (Web Apps by 123apps) - C:\Users\Pancho\AppData\Roaming\Mozilla\Firefox\Profiles\2ql37ue6.default-release\Extensions\{e662576a-2f73-4069-bcca-ddf440fea62b}.xpi [2022-01-12]
FF Extension: (Red Firefox Theme) - C:\Users\Pancho\AppData\Roaming\Mozilla\Firefox\Profiles\2ql37ue6.default-release\Extensions\{fa85c84a-45ce-4fe9-96b5-0d0b10cb039c}.xpi [2022-01-12]
FF Extension: (Animated Stars at Night [Blue]) - C:\Users\Pancho\AppData\Roaming\Mozilla\Firefox\Profiles\2ql37ue6.default-release\Extensions\{fde51127-2a91-4ea0-99d3-ea07e8d18726}.xpi [2022-01-12]
FF Plugin: @videolan.org/vlc,version=3.0.10 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.16 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\plugins\npFoxitReaderPlugin.dll [2021-07-21] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.cpdf -> C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\plugins\npFoxitReaderPlugin.dll [2021-07-21] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\plugins\npFoxitReaderPlugin.dll [2021-07-21] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\plugins\npFoxitReaderPlugin.dll [2021-07-21] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\plugins\npFoxitReaderPlugin.dll [2021-07-21] (FOXIT SOFTWARE INC. -> Foxit Corporation)

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

"SAntivirusIC" => service was unlocked. <==== ATTENTION

S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [383016 2017-07-18] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
S4 FoxitReaderUpdateService; C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\FoxitPDFReaderUpdateService.exe [2357880 2021-07-21] (FOXIT SOFTWARE INC. -> Foxit Software Inc.)
S4 NymphwellDadapy; C:\Program Files (x86)\NymphwellDadapy\NymphwellDadapy.exe [31255368 2021-08-08] (MM Apps, Inc. -> Problem Bumota) [File not signed]
R2 SAntivirusIC; C:\Program Files (x86)\Digital Communications\SAntivirus\SAntivirusIC.exe [6941200 2022-01-13] (Digital Communications Inc -> DlGlTAL COMMUNICATIONS INC) <==== ATTENTION
R2 SAntivirusSvc; C:\Program Files (x86)\Digital Communications\SAntivirus\SAntivirusService.exe [690704 2022-01-13] (Digital Communications Inc -> DlGlTAL COMMUNICATIONS INC) <==== ATTENTION
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [6133448 2022-02-15] (Microsoft Windows Publisher -> Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.10-0\NisSrv.exe [2909208 2022-02-26] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.10-0\MsMpEng.exe [128376 2022-02-26] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_3b12ac0f95b18b9d\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_3b12ac0f95b18b9d\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [279040 2021-10-06] (Microsoft Corporation) [File not signed]
S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus2.sys [160376 2021-10-08] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S4 IObitUnlocker; C:\Program Files (x86)\IObit\IObit Unlocker\IObitUnlocker.sys [39000 2020-10-10] (IObit CO., LTD -> IObit Information Technology)
R3 MpKsl8a24c004; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B493D8D4-D4BD-486C-A4DF-40ABE938B567}\MpKslDrv.sys [135440 2022-03-02] (Microsoft Windows -> Microsoft Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [48552 2022-01-11] (Microsoft Windows Hardware Compatibility Publisher -> NVIDIA Corporation)
S3 Revoflt; C:\Windows\System32\DRIVERS\revoflt.sys [38400 2020-10-14] (Microsoft Windows Hardware Compatibility Publisher -> VS Revo Group)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [167544 2021-10-08] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R1 TASANTIVIRUSKD; C:\Program Files (x86)\Digital Communications\SAntivirus\TASAntivirusKD.sys [86024 2022-01-13] (Digital Communications Inc -> DlGlTAL COMMUNICATIONS INC) <==== ATTENTION
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [48536 2022-02-26] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [438520 2022-02-26] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [90360 2022-02-26] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2022-03-02 19:48 - 2022-03-02 19:49 - 000000000 ____D C:\FRST
2022-03-01 00:52 - 2022-03-01 00:52 - 000481408 _____ C:\Windows\system32\FNTCACHE.DAT
2022-02-28 19:34 - 2022-02-28 19:45 - 000000008 __RSH C:\ProgramData\ntuser.pol
2022-02-28 10:45 - 2022-03-01 22:01 - 076808192 _____ C:\Windows\system32\config\SOFTWARE
2022-02-28 04:26 - 2022-02-28 04:26 - 000000000 ____D C:\Users\Pancho\AppData\Local\ElevatedDiagnostics
2022-02-27 08:36 - 2022-02-28 10:45 - 000000000 ____D C:\Windows\Microsoft Antimalware
2022-02-26 11:28 - 2022-02-26 11:28 - 000000000 ____D C:\Users\Pancho\AppData\Local\Viber
2022-02-25 17:25 - 2022-02-25 17:25 - 000000000 ____D C:\Users\Pancho\AppData\Roaming\dvdcss
2022-02-22 22:06 - 2022-02-22 22:06 - 000000000 ____D C:\Windows\pss
2022-02-21 22:30 - 2020-11-23 08:22 - 000372224 _____ (EasternGraphics GmbH) C:\Windows\system32\emp.dll
2022-02-21 04:14 - 2022-02-21 21:08 - 000000000 ____D C:\Windows\SysWOW64\directx
2022-02-21 02:13 - 2022-02-20 16:39 - 002653184 _____ (EA PopCap) C:\Windows\SysWOW64\dbdataEA.dll
2022-02-21 02:08 - 2022-02-21 02:08 - 000000000 ____D C:\Windows\SysWOW64\dbdataEA
2022-02-21 01:56 - 2022-02-21 01:56 - 000000000 ____D C:\Users\Pancho\AppData\Local\DBG
2022-02-21 01:48 - 2022-02-20 16:39 - 002653184 _____ (EA PopCap) C:\Windows\system32\dbdataEA.dll
2022-02-21 01:46 - 2022-02-21 01:46 - 000000000 ____D C:\Windows\system32\dbdataEA
2022-02-20 20:57 - 2022-02-21 20:32 - 000000000 ____D C:\Windows\Minidump
2022-02-20 20:55 - 2022-02-26 18:34 - 003517448 _____ (EasyAntiCheat Oy) C:\Windows\system32\Drivers\EasyAntiCheat.sys
2022-02-20 20:55 - 2017-07-18 11:14 - 000383016 _____ (EasyAntiCheat Ltd) C:\Windows\SysWOW64\EasyAntiCheat.exe
2022-02-20 05:50 - 2022-02-20 05:50 - 000000000 ____D C:\Users\Pancho\AppData\Roaming\EasyAntiCheat
2022-02-20 05:49 - 2022-02-20 05:50 - 000000000 ____D C:\Program Files (x86)\EasyAntiCheat
2022-02-17 21:42 - 2022-02-17 21:42 - 000000000 ____D C:\Users\Pancho\AppData\Local\Yandex
2022-02-17 20:19 - 2022-02-18 20:22 - 000000000 ____D C:\Program Files\Mozilla Firefox
2022-02-15 20:11 - 2022-02-15 20:11 - 000195584 _____ C:\Windows\system32\uwfcfgmgmt.dll
2022-02-15 20:10 - 2022-02-15 20:10 - 002260992 _____ C:\Windows\system32\TextInputMethodFormatter.dll
2022-02-15 20:10 - 2022-02-15 20:10 - 002254336 _____ C:\Windows\system32\dwmscene.dll
2022-02-15 20:10 - 2022-02-15 20:10 - 000272896 _____ C:\Windows\system32\TpmTool.exe
2022-02-15 20:10 - 2022-02-15 20:10 - 000223744 _____ C:\Windows\SysWOW64\TpmTool.exe
2022-02-15 20:10 - 2022-02-15 20:10 - 000011821 _____ C:\Windows\system32\DrtmAuthTxt.wim
2022-02-14 22:00 - 2022-02-10 20:42 - 001905936 _____ C:\Windows\system32\vulkaninfo-1-999-0-0-0.exe
2022-02-14 22:00 - 2022-02-10 20:42 - 001905936 _____ C:\Windows\system32\vulkaninfo.exe
2022-02-14 22:00 - 2022-02-10 20:42 - 001478416 _____ C:\Windows\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2022-02-14 22:00 - 2022-02-10 20:42 - 001478416 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2022-02-14 22:00 - 2022-02-10 20:42 - 001467840 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2022-02-14 22:00 - 2022-02-10 20:42 - 001432336 _____ C:\Windows\system32\vulkan-1-999-0-0-0.dll
2022-02-14 22:00 - 2022-02-10 20:42 - 001432336 _____ C:\Windows\system32\vulkan-1.dll
2022-02-14 22:00 - 2022-02-10 20:42 - 001209280 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2022-02-14 22:00 - 2022-02-10 20:42 - 001145616 _____ C:\Windows\SysWOW64\vulkan-1-999-0-0-0.dll
2022-02-14 22:00 - 2022-02-10 20:42 - 001145616 _____ C:\Windows\SysWOW64\vulkan-1.dll
2022-02-14 22:00 - 2022-02-10 20:39 - 001531872 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2022-02-14 22:00 - 2022-02-10 20:39 - 001176704 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2022-02-14 22:00 - 2022-02-10 20:39 - 000797112 _____ C:\Windows\system32\nvofapi64.dll
2022-02-14 22:00 - 2022-02-10 20:39 - 000717760 _____ (NVIDIA Corporation) C:\Windows\system32\nvml.dll
2022-02-14 22:00 - 2022-02-10 20:39 - 000636032 _____ C:\Windows\SysWOW64\nvofapi.dll
2022-02-14 22:00 - 2022-02-10 20:38 - 002120320 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2022-02-14 22:00 - 2022-02-10 20:38 - 001602728 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2022-02-14 22:00 - 2022-02-10 20:38 - 000983992 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2022-02-14 22:00 - 2022-02-10 20:38 - 000795584 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2022-02-14 22:00 - 2022-02-10 20:38 - 000711608 _____ (NVIDIA Corporation) C:\Windows\system32\nvidia-smi.exe
2022-02-14 22:00 - 2022-02-10 20:37 - 008612496 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2022-02-14 22:00 - 2022-02-10 20:37 - 007714960 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2022-02-14 22:00 - 2022-02-10 20:37 - 005727376 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2022-02-14 22:00 - 2022-02-10 20:37 - 005099152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2022-02-14 22:00 - 2022-02-10 20:37 - 002935744 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2022-02-14 22:00 - 2022-02-10 20:37 - 000456848 _____ (NVIDIA Corporation) C:\Windows\system32\nvdebugdump.exe
2022-02-14 22:00 - 2022-02-10 20:35 - 000849024 _____ (NVIDIA Corporation) C:\Windows\system32\MCU.exe
2022-02-14 22:00 - 2022-02-10 20:34 - 006461040 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2022-02-14 22:00 - 2022-02-10 08:18 - 000089251 _____ C:\Windows\system32\nvinfo.pb
2022-02-12 21:41 - 2022-02-12 21:41 - 000000000 ____D C:\Users\Pancho\OneDrive\Документи\DyingLight
2022-02-12 19:20 - 2022-02-12 19:20 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2022-02-12 19:20 - 2021-10-08 11:00 - 000167544 _____ (Samsung Electronics Co., Ltd.) C:\Windows\system32\Drivers\ssudmdm.sys
2022-02-12 19:20 - 2021-10-08 11:00 - 000160376 _____ (Samsung Electronics Co., Ltd.) C:\Windows\system32\Drivers\ssudbus2.sys
2022-02-10 09:42 - 2022-03-01 22:05 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2022-02-08 20:27 - 2022-02-21 22:15 - 000000000 __SHD C:\$360Section
2022-02-01 23:07 - 2022-02-01 23:07 - 000000000 ____D C:\Users\Pancho\OneDrive\Документи\Stranglehold
2022-02-01 23:07 - 2022-02-01 23:07 - 000000000 ____D C:\Users\Pancho\AppData\Local\Midway
2022-02-01 23:02 - 2022-02-01 23:02 - 000000000 ____D C:\Users\Pancho\OneDrive\Документи\Manhunt User Files
2022-02-01 21:54 - 2022-01-28 13:28 - 000040920 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhdap64.dll
2022-01-31 10:59 - 2022-01-31 10:59 - 000000000 ____D C:\Users\Pancho\AppData\Local\Viber Media S.à r.l

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2022-03-02 18:36 - 2022-01-13 08:45 - 000000000 ____D C:\Windows\system32\SleepStudy
2022-03-02 17:27 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2022-03-02 17:27 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\AppReadiness
2022-03-02 17:27 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2022-03-02 12:42 - 2022-01-12 23:25 - 000000000 ____D C:\Users\Pancho\AppData\LocalLow\Mozilla
2022-03-02 12:25 - 2022-01-14 17:02 - 000000000 ____D C:\ProgramData\NVIDIA
2022-03-01 22:08 - 2022-01-12 22:51 - 000795738 _____ C:\Windows\system32\PerfStringBackup.INI
2022-03-01 22:08 - 2019-12-07 11:13 - 000000000 ____D C:\Windows\INF
2022-03-01 22:01 - 2022-01-13 23:21 - 000000000 ____D C:\ProgramData\UMS
2022-03-01 22:01 - 2022-01-13 08:45 - 000008192 ___SH C:\DumpStack.log.tmp
2022-03-01 22:01 - 2022-01-13 08:45 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2022-03-01 22:01 - 2019-12-07 11:03 - 000524288 _____ C:\Windows\system32\config\BBI
2022-03-01 21:14 - 2022-01-14 01:38 - 000000000 ____D C:\Users\Pancho\AppData\Roaming\uTorrent
2022-03-01 18:50 - 2022-01-13 21:17 - 000000000 ____D C:\Users\Pancho\AppData\Roaming\vlc
2022-03-01 00:52 - 2022-01-30 21:08 - 000000000 ____D C:\Users\Pancho\AppData\Roaming\ViberPC
2022-03-01 00:49 - 2022-01-13 21:39 - 000000000 ____D C:\Users\Pancho\AppData\Roaming\Wise Disk Cleaner
2022-03-01 00:43 - 2022-01-13 21:39 - 000001289 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Disk Cleaner.lnk
2022-03-01 00:34 - 2022-01-13 17:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2022-02-28 18:44 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\Registration
2022-02-28 00:43 - 2022-01-12 22:50 - 000000000 ____D C:\Users\Pancho
2022-02-27 23:10 - 2022-01-12 22:51 - 000000000 ____D C:\Users\Pancho\AppData\Local\D3DSCache
2022-02-27 19:05 - 2019-12-07 11:03 - 000032768 _____ C:\Windows\system32\config\ELAM
2022-02-27 18:59 - 2022-01-13 17:30 - 000000000 ____D C:\Users\Pancho\AppData\Roaming\360DesktopLite
2022-02-27 18:59 - 2019-12-07 11:14 - 000000000 ___HD C:\Windows\ELAMBKUP
2022-02-26 23:51 - 2022-01-13 08:45 - 000002450 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2022-02-26 22:32 - 2019-12-07 11:03 - 000000000 ____D C:\Windows\CbsTemp
2022-02-26 21:48 - 2022-01-13 08:45 - 000000000 ____D C:\Windows\system32\Drivers\wd
2022-02-26 11:28 - 2022-01-30 21:08 - 000000000 ____D C:\Users\Pancho\OneDrive\Документи\ViberDownloads
2022-02-24 11:46 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\NDF
2022-02-21 03:40 - 2022-01-16 20:49 - 000000000 ____D C:\ProgramData\Package Cache
2022-02-20 05:30 - 2022-01-12 22:51 - 000000000 ____D C:\Users\Pancho\AppData\Local\Packages
2022-02-20 00:13 - 2022-01-12 22:53 - 000000000 ____D C:\Users\Pancho\AppData\Local\PlaceholderTileLogoFolder
2022-02-20 00:13 - 2022-01-12 22:51 - 000000000 ____D C:\ProgramData\Packages
2022-02-19 21:29 - 2019-12-07 11:14 - 000000000 ___HD C:\Windows\system32\GroupPolicy
2022-02-18 20:44 - 2022-01-13 00:12 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2022-02-18 20:22 - 2022-01-13 08:45 - 000000000 ____D C:\Windows\Panther
2022-02-18 20:22 - 2022-01-12 23:25 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2022-02-17 20:23 - 2022-01-12 23:25 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2022-02-17 20:23 - 2022-01-12 23:25 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla
2022-02-17 20:22 - 2022-01-19 23:02 - 000000000 ____D C:\Users\Pancho\AppData\Local\CrashDumps
2022-02-15 20:13 - 2019-12-07 11:54 - 000000000 ___SD C:\Windows\system32\AppV
2022-02-15 20:13 - 2019-12-07 11:54 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2022-02-15 20:13 - 2019-12-07 11:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2022-02-15 20:13 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SystemResources
2022-02-15 20:13 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\WinBioPlugIns
2022-02-15 20:13 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\oobe
2022-02-15 20:13 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\migwiz
2022-02-15 20:13 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\PolicyDefinitions
2022-02-15 20:13 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\bcastdvr
2022-02-15 20:13 - 2019-12-07 11:03 - 000000000 ____D C:\Windows\servicing
2022-02-15 08:56 - 2022-01-13 21:29 - 000000000 ____D C:\Users\Pancho\AppData\Local\NVIDIA
2022-02-13 22:39 - 2022-01-13 23:21 - 000001997 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Universal Media Server.lnk
2022-02-13 22:38 - 2022-01-13 23:20 - 000000000 ____D C:\Program Files (x86)\Universal Media Server
2022-02-12 21:39 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2022-02-10 21:56 - 2022-01-16 20:49 - 000004308 _____ C:\Windows\system32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2022-02-10 21:56 - 2022-01-16 20:49 - 000003976 _____ C:\Windows\system32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2022-02-10 21:56 - 2022-01-16 20:49 - 000003940 _____ C:\Windows\system32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2022-02-10 21:56 - 2022-01-16 20:49 - 000003894 _____ C:\Windows\system32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2022-02-10 21:56 - 2022-01-16 20:49 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2022-02-10 21:56 - 2022-01-16 20:49 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2022-02-10 21:56 - 2022-01-16 20:49 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2022-02-10 21:56 - 2022-01-16 20:49 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2022-02-10 21:56 - 2022-01-16 20:49 - 000003654 _____ C:\Windows\system32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2022-02-10 21:56 - 2022-01-16 20:49 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2022-02-10 21:56 - 2022-01-12 22:50 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2022-02-10 21:56 - 2022-01-12 22:50 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2022-02-10 20:34 - 2022-01-12 22:50 - 007613344 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2022-02-09 20:20 - 2022-01-13 00:11 - 000000000 ____D C:\Windows\system32\MRT
2022-02-09 20:18 - 2022-01-13 00:11 - 149611728 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2022-02-01 23:02 - 2019-12-07 11:10 - 000383488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll
2022-02-01 23:02 - 2019-12-07 11:10 - 000215552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dplayx.dll
2022-02-01 23:02 - 2019-12-07 11:10 - 000060928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnathlp.dll
2022-02-01 23:02 - 2019-12-07 11:10 - 000045568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpwsockx.dll
2022-02-01 23:02 - 2019-12-07 11:10 - 000023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpmodemx.dll
2022-02-01 23:02 - 2019-12-07 11:10 - 000022528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnsvr.exe
2022-02-01 23:02 - 2019-12-07 11:10 - 000020480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dplaysvr.exe
2022-02-01 23:02 - 2019-12-07 11:10 - 000008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnhupnp.dll
2022-02-01 23:02 - 2019-12-07 11:10 - 000008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnhpast.dll
2022-02-01 23:02 - 2019-12-07 11:10 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnlobby.dll
2022-02-01 23:02 - 2019-12-07 11:10 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnaddr.dll
2022-02-01 23:02 - 2019-12-07 11:09 - 000494592 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll
2022-02-01 23:02 - 2019-12-07 11:09 - 000070656 _____ (Microsoft Corporation) C:\Windows\system32\dpnathlp.dll
2022-02-01 23:02 - 2019-12-07 11:09 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\dpnsvr.exe
2022-02-01 23:02 - 2019-12-07 11:09 - 000010240 _____ (Microsoft Corporation) C:\Windows\system32\dpnhupnp.dll
2022-02-01 23:02 - 2019-12-07 11:09 - 000010240 _____ (Microsoft Corporation) C:\Windows\system32\dpnhpast.dll
2022-02-01 23:02 - 2019-12-07 11:09 - 000006144 _____ (Microsoft Corporation) C:\Windows\system32\dpnlobby.dll
2022-02-01 23:02 - 2019-12-07 11:09 - 000006144 _____ (Microsoft Corporation) C:\Windows\system32\dpnaddr.dll
2022-02-01 21:51 - 2022-01-16 20:49 - 000000000 ____D C:\Users\Pancho\AppData\Local\NVIDIA Corporation

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-02-2022
Ran by Pancho (02-03-2022 19:49:41)
Running from C:\Users\Pancho\OneDrive\Работен плот
Microsoft Windows 10 Pro Version 21H2 19044.1566 (X64) (2022-01-12 20:46:56)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================


(If an entry is included in the fixlist, it will be removed.)

Administrator (S-1-5-21-176537593-2728283085-4065151155-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-176537593-2728283085-4065151155-503 - Limited - Disabled)
Guest (S-1-5-21-176537593-2728283085-4065151155-501 - Limited - Enabled)
Pancho (S-1-5-21-176537593-2728283085-4065151155-1001 - Administrator - Enabled) => C:\Users\Pancho
WDAGUtilityAccount (S-1-5-21-176537593-2728283085-4065151155-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKLM-x32\...\uTorrent) (Version: 2.2.1 - )
AviSynth (HKLM-x32\...\AviSynth) (Version: 2.6.0 MT - )
CrystalDiskInfo 8.9.0 (HKLM\...\CrystalDiskInfo_is1) (Version: 8.9.0 - Crystal Dew World)
Foxit PDF Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 11.0.1.49938 - Foxit Software Inc.)
IObit Unlocker (HKLM-x32\...\IObit Unlocker_is1) (Version: 1.2.0.1 - IObit)
LibreOffice 7.2.5.2 (HKLM\...\{4EF63F1E-7ADF-4D6E-8F9F-5E1D5CE231D1}) (Version: 7.2.5.2 - The Document Foundation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 98.0.1108.62 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-176537593-2728283085-4065151155-1001\...\OneDriveSetup.exe) (Version: 21.230.1107.0004 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{16E50919-B07A-4B4E-994A-476D4773F5BF}) (Version: 3.65.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.29.30139 (HKLM-x32\...\{2c673fb6-3e65-4751-965d-33d30b68a8a6}) (Version: 14.29.30139.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.22.27821 (HKLM-x32\...\{5bfc1380-fd35-4b85-9715-7351535d077e}) (Version: 14.22.27821.0 - Microsoft Corporation)
Mozilla Firefox (x64 bg) (HKLM\...\Mozilla Firefox 97.0.1 (x64 bg)) (Version: 97.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 96.0 - Mozilla)
NVIDIA FrameView SDK 1.2.7321.30900954 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.2.7321.30900954 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.25.0.84 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.25.0.84 - NVIDIA Corporation)
NVIDIA Graphics Driver 511.79 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 511.79 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.39.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.39.3 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.21.0713 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.21.0713 - NVIDIA Corporation)
NVIDIA USBC Driver 1.46.831.832 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_USBC) (Version: 1.46.831.832 - NVIDIA Corporation)
Revo Uninstaller Pro 4.5.5 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 4.5.5 - VS Revo Group, Ltd.)
Universal Media Server (HKLM-x32\...\Universal Media Server) (Version: 10.16.0 - Universal Media Server)
Viber (HKLM-x32\...\{D20F4645-C2CF-43AC-A2DD-C9AEA937EF93}) (Version: 16.8.1.0 - Viber Media S.a.r.l) Hidden
Viber (HKU\S-1-5-21-176537593-2728283085-4065151155-1001\...\{9118c1ad-5945-45d1-91c4-b5f8234b9e82}) (Version: 16.8.1.0 - 2010-2022 Viber Media S.a.r.l)
VirtualCloneDrive (HKLM-x32\...\VirtualCloneDrive) (Version:  - Elaborate Bytes)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.16 - VideoLAN)
WinRAR 6.00 (64-bit) (HKLM\...\WinRAR archiver) (Version: 6.00.0 - win.rar GmbH)
Wise Disk Cleaner 10.8.3 (HKLM-x32\...\Wise Disk Cleaner_is1) (Version: 10.8.3 - WiseCleaner.com, Inc.)

Packages:
=========
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.12.2180.0_x64__8wekyb3d8bbwe [2022-02-25] (Microsoft Studios) [MS Ad]
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.962.0_x64__56jybvy8sckqj [2022-02-14] (NVIDIA Corp.)
Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.179.763.0_x86__zpdnekdrzrea0 [2022-02-20] (Spotify AB) [Startup Task]

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ContextMenuHandlers1: [UnLockerMenu] -> {410BF280-86EF-4E0F-8279-EC5848546AD3} => C:\Program Files (x86)\IObit\IObit Unlocker\IObitUnlockerExtension.dll [2020-10-10] (IObit Information Technology -> IObit Information Technology)
ContextMenuHandlers1: [VirtualCloneDrive] -> {B7056B8E-4F99-44f8-8CBD-282390FE5428} => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll [2009-12-14] (Elaborate Bytes AG -> Elaborate Bytes AG)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2020-12-01] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2020-12-01] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers2: [VirtualCloneDrive] -> {B7056B8E-4F99-44f8-8CBD-282390FE5428} => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll [2009-12-14] (Elaborate Bytes AG -> Elaborate Bytes AG)
ContextMenuHandlers4: [UnLockerMenu] -> {410BF280-86EF-4E0F-8279-EC5848546AD3} => C:\Program Files (x86)\IObit\IObit Unlocker\IObitUnlockerExtension.dll [2020-10-10] (IObit Information Technology -> IObit Information Technology)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_3b12ac0f95b18b9d\nvshext.dll [2022-02-10] (Nvidia Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [RUShellExt] -> {2C5515DC-2A7E-4BFD-B813-CACC2B685EB7} => C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RUExt.dll [2020-09-28] (VS Revo Group Ltd. -> VS Revo Group)
ContextMenuHandlers6: [UnLockerMenu] -> {410BF280-86EF-4E0F-8279-EC5848546AD3} => C:\Program Files (x86)\IObit\IObit Unlocker\IObitUnlockerExtension.dll [2020-10-10] (IObit Information Technology -> IObit Information Technology)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2020-12-01] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2020-12-01] (win.rar GmbH -> Alexander Roshal)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

2022-03-01 22:01 - 2022-03-01 22:01 - 000254464 ____N (Java(TM) Native Access (JNA)) [File not signed] C:\Users\Pancho\AppData\Local\Temp\jna--1911678195\jna3693507572158144180.dll

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

==================== Association (Whitelisted) =================

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

HKLM\...\.scr:  =>  <==== ATTENTION

==================== Internet Explorer (Whitelisted) ==========


==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2019-12-07 11:14 - 2022-02-21 05:29 - 000001294 _____ C:\Windows\system32\drivers\etc\hosts
127.0.0.1                   mercury-cert.ubi.com
127.0.0.1                   ubiservices.ubi.com
127.0.0.1                   public-ubiservices.ubi.com
127.0.0.1                   useast1-public.aws-ubiservices.ubi.com
127.0.0.1                   lb-web-us.ubisoft.com
127.0.0.1                   ghostreconnetwork.ubi.com
127.0.0.1                   uat-beta.ubi.com
127.0.0.1                   uat-payments.ubi.com
127.0.0.1                   mercury.ubi.com

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-176537593-2728283085-4065151155-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Pancho\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\img0.jpg
DNS Servers: 192.168.100.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKU\S-1-5-21-176537593-2728283085-4065151155-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-176537593-2728283085-4065151155-1001\...\StartupApproved\Run: => "uTorrent"
HKU\S-1-5-21-176537593-2728283085-4065151155-1001\...\StartupApproved\Run: => "Windows Defender"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [TCP Query User{D644AE17-656A-4EED-97ED-69357A7AEB19}C:\program files (x86)\universal media server\jre8\bin\javaw.exe] => (Allow) C:\program files (x86)\universal media server\jre8\bin\javaw.exe
FirewallRules: [UDP Query User{6C0B5FD1-8FE3-477D-B773-C5BAF8A4D443}C:\program files (x86)\universal media server\jre8\bin\javaw.exe] => (Allow) C:\program files (x86)\universal media server\jre8\bin\javaw.exe
FirewallRules: [TCP Query User{39F2218F-761C-498B-828C-BBAF62C19F00}C:\program files (x86)\utorrent\utorrent.exe] => (Allow) C:\program files (x86)\utorrent\utorrent.exe (BitTorrent Inc -> BitTorrent, Inc.)
FirewallRules: [UDP Query User{DFE52D42-8B36-4B17-B547-98824D13821F}C:\program files (x86)\utorrent\utorrent.exe] => (Allow) C:\program files (x86)\utorrent\utorrent.exe (BitTorrent Inc -> BitTorrent, Inc.)
FirewallRules: [{D45A5C54-EB1C-4B28-92D3-C4CC3252953D}] => (Block) C:\Windows\system32\Attrib.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{90245B3C-197D-4252-B432-0E2D5262B239}] => (Block) C:\Windows\SysWOW64\Attrib.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{60BD7094-B855-4EF6-8835-C01F59603263}] => (Block) C:\Windows\system32\AtBroker.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{C42F18C1-7B03-454F-A590-66A6BE6AD181}] => (Block) C:\Windows\SysWOW64\AtBroker.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{3B12725C-5620-4C59-9288-43AF47C58333}] => (Block) C:\Windows\system32\Certutil.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{93B23C1F-F355-4EFA-B11F-B68A84C12D7F}] => (Block) C:\Windows\SysWOW64\Certutil.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{3C1BE7BD-BA65-4606-8F3A-6DB8137650CF}] => (Block) C:\Windows\system32\Cmstp.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{E6385C24-CA41-4A7E-81F8-74BD6E3FC709}] => (Block) C:\Windows\SysWOW64\Cmstp.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{3885170D-641B-4CFC-A957-EF31246FDF15}] => (Block) C:\Windows\system32\Esentutl.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{C16A86DF-4E39-42E2-94E2-41A707665BA1}] => (Block) C:\Windows\SysWOW64\Esentutl.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{85E01359-6C42-4D32-9DDA-A17D343464C3}] => (Block) C:\Windows\system32\Extrac32.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{E46580A9-001A-4D61-9EF5-1898E00161A1}] => (Block) C:\Windows\SysWOW64\Extrac32.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{75FC0014-F40D-46AE-9260-6C38EBA6BBBC}] => (Block) C:\Windows\system32\Makecab.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{83C4D570-C228-4FD4-B197-263F5CC863B0}] => (Block) C:\Windows\SysWOW64\Makecab.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{1C32C096-3BDC-4A1D-A8AF-E826CEAF9DC7}] => (Block) C:\Windows\system32\Pcalua.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{913B5975-B608-4D99-AA78-6BEA367FC21E}] => (Block) C:\Windows\system32\ScriptRunner.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{248B1C06-9F4E-4A4C-AE6B-80161C80A019}] => (Block) C:\Windows\system32\wbem\Scrcons.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{5DB2F58C-41D4-42CF-B08E-4F2491D814A3}] => (Block) C:\Windows\system32\CompatTelRunner.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{F5834ED2-87E8-4896-B863-9681A775F091}] => (Block) C:\Windows\system32\Control.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{D60C6FE8-B624-4984-A758-D4133B3D0E54}] => (Block) C:\Windows\SysWOW64\Control.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{CFDD9CAE-5541-442D-BFD2-66EBBF8A4B1F}] => (Block) C:\Windows\system32\Cscript.exe
FirewallRules: [{C409AF14-DA3F-4EC7-A081-AEAED3BFCCD1}] => (Block) C:\Windows\SysWOW64\Cscript.exe
FirewallRules: [{E3A34137-5163-4671-8FEF-36DC65C1AF10}] => (Block) C:\Windows\system32\Csrss.exe (Microsoft Windows Publisher -> Microsoft Corporation)
FirewallRules: [{B0868CA6-A991-466D-96E5-6F17DF103963}] => (Block) C:\Windows\system32\Ctfmon.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{0B75643C-6739-4ED0-A288-45EA7B2A229A}] => (Block) C:\Windows\SysWOW64\Ctfmon.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{0D028D90-3B5E-4A57-98FB-572EDFFD65FD}] => (Block) C:\Windows\system32\Dwm.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{CF910839-AD84-4279-902C-A18BEDDBD043}] => (Block) C:\Windows\system32\Eventvwr.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{1839247B-9D1A-467B-8CDB-83BAB1348F59}] => (Block) C:\Windows\SysWOW64\Eventvwr.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{0F4E4E1C-2F78-491C-A317-30A2989BDFD5}] => (Block) C:\Windows\Explorer.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{A37C5360-E261-418F-9FF6-0F79DD569289}] => (Block) C:\Windows\HH.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{2A0A39DE-FAB9-482C-A7DF-0B5C2D3ADBAC}] => (Block) C:\Windows\system32\MMC.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{B62F7187-3843-45D3-A0F9-C497E1FE39F8}] => (Block) C:\Windows\SysWOW64\MMC.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{E6E67A08-98FF-4804-8768-3EE790E4580F}] => (Block) C:\Windows\system32\Odbcconf.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{6E2F270B-3893-4539-BCD5-324E5ECA733D}] => (Block) C:\Windows\SysWOW64\Odbcconf.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{A10D29EB-4836-4F32-9AE3-1F3D24645E97}] => (Block) powershell.exe => No File
FirewallRules: [{DF70BC14-8A16-48DD-BD7D-1F437E606307}] => (Block) powershell.exe => No File
FirewallRules: [{BB267AEA-E8BF-4490-A671-EC1A8A30E6AC}] => (Block) C:\Windows\system32\Services.exe (Microsoft Windows Publisher -> Microsoft Corporation)
FirewallRules: [{5A3E5EA5-BDF9-424C-98AD-05427DF939CD}] => (Block) C:\Windows\system32\Winlogon.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{17CD3122-7553-48D5-939E-5B1A0133F1CA}] => (Block) C:\Windows\system32\Wininit.exe (Microsoft Windows Publisher -> Microsoft Corporation)
FirewallRules: [{E1143CA3-0782-4CD4-8A32-F5D99B599067}] => (Block) C:\Windows\system32\wbem\Wmic.exe
FirewallRules: [{D880A230-868D-4752-AD44-648C3384212C}] => (Block) C:\Windows\SysWOW64\wbem\Wmic.exe
FirewallRules: [{FDBDB16E-E21E-4494-8B16-4DF40CACF662}] => (Block) C:\Program Files\Windows NT\Accessories\Wordpad.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{533EA8FC-3CE7-4EA6-9D7C-B73075348D60}] => (Block) C:\Windows\system32\Wscript.exe
FirewallRules: [{BA342E99-B320-41F0-9266-6C78DC12B0DE}] => (Block) C:\Windows\SysWOW64\Wscript.exe

==================== Restore Points =========================

28-02-2022 09:44:15 Scheduled Checkpoint
01-03-2022 00:45:31 Created by Wise Disk Cleaner
01-03-2022 21:52:25 Restore Point
01-03-2022 22:00:52 Restore Point

==================== Faulty Device Manager Devices ============


==================== Event log errors: ========================

Application errors:
==================
Error: (03/02/2022 07:49:05 PM) (Source: VSS) (EventID: 12289) (User: )
Description: Volume Shadow Copy Service error: Unexpected error DeviceIoControl(\\?\Volume{81d01049-9552-414d-ae79-9deeb3d3e7d1} - 0000000000000260,0x0053c008,00000274C4C068C0,0,00000274C4C078F0,4096,[0]).  hr = 0x80070005, Access is denied.
.


Operation:
   Processing EndPrepareSnapshots

Context:
   Execution Context: System Provider

Error: (03/02/2022 07:48:37 PM) (Source: VSS) (EventID: 12289) (User: )
Description: Volume Shadow Copy Service error: Unexpected error DeviceIoControl(\\?\Volume{81d01049-9552-414d-ae79-9deeb3d3e7d1} - 00000000000001AC,0x0053c008,00000274C4C068C0,0,00000274C4C078F0,4096,[0]).  hr = 0x80070005, Access is denied.
.


Operation:
   Processing EndPrepareSnapshots

Context:
   Execution Context: System Provider

Error: (03/01/2022 10:00:52 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.


Operation:
   Gathering Writer Data

Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {9d583dfc-deb9-4c5e-9331-267538dba506}

Error: (03/01/2022 09:52:25 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.


Operation:
   Gathering Writer Data

Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {203aa842-da10-4d9b-8dd9-6b0f60593370}

Error: (03/01/2022 09:43:34 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program ConfigureDefender_x64.exe version 3.0.1.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

Process ID: 25ac

Start Time: 01d82da476e1c905

Termination Time: 4294967295

Application Path: C:\Windows\Temp\101749311059017213\3271\ConfigureDefender_x64.exe

Report Id: 9eb22fff-3cd7-49f1-aa9d-820b140f5b2b

Faulting package full name:

Faulting package-relative application ID:

Hang type: Cross-process

Error: (03/01/2022 09:35:43 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program ConfigureDefender_x64.exe version 3.0.1.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

Process ID: 1d88

Start Time: 01d82da287cf8fc0

Termination Time: 4294967295

Application Path: C:\Windows\Temp\101749311059017213\758\ConfigureDefender_x64.exe

Report Id: 87d40269-d8c4-44ee-89d0-21ddb70945ed

Faulting package full name:

Faulting package-relative application ID:

Hang type: Cross-process

Error: (03/01/2022 12:51:38 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4176) (User: )
Description: Операцията на PFX е неуспешна, тъй като броят на AuthSafes не се намира в очаквания обхват. Максимална разрешена стойност: 200. Стойност за грешка: 284.

Error: (03/01/2022 12:51:38 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4176) (User: )
Description: Операцията на PFX е неуспешна, тъй като броят на AuthSafes не се намира в очаквания обхват. Максимална разрешена стойност: 200. Стойност за грешка: 284.


System errors:
=============
Error: (03/01/2022 10:01:41 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Услуга NcaSvc зависи от услуга iphlpsvc, която не може да бъде стартирана поради следната грешка:
The dependency service or group failed to start.

Error: (03/01/2022 10:01:41 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Услуга iphlpsvc зависи от услуга WinHttpAutoProxySvc, която не може да бъде стартирана поради следната грешка:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Error: (03/01/2022 10:01:17 PM) (Source: DCOM) (EventID: 10010) (User: PANCHO)
Description: The server {9BA05972-F6A8-11CF-A442-00A0C90A8F39} did not register with DCOM within the required timeout.

Error: (03/01/2022 10:01:15 PM) (Source: DCOM) (EventID: 10010) (User: PANCHO)
Description: The server {389510B7-9E58-40D7-98BF-60B911CB0EA9} did not register with DCOM within the required timeout.

Error: (03/01/2022 09:53:14 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Услуга NcaSvc зависи от услуга iphlpsvc, която не може да бъде стартирана поради следната грешка:
The dependency service or group failed to start.

Error: (03/01/2022 09:53:14 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Услуга iphlpsvc зависи от услуга WinHttpAutoProxySvc, която не може да бъде стартирана поради следната грешка:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Error: (03/01/2022 09:52:47 PM) (Source: DCOM) (EventID: 10010) (User: PANCHO)
Description: The server {389510B7-9E58-40D7-98BF-60B911CB0EA9} did not register with DCOM within the required timeout.

Error: (02/28/2022 08:38:33 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Изтекъл период на изчакване (30000 милисекунди) при изчакване на услуга Windows Error Reporting Service да се свърже.


Windows Defender:
================
Date: 2022-03-02 19:48:42
Description:
Controlled Folder Access blocked C:\Windows\System32\svchost.exe from making changes to memory.
Detection time: 2022-03-02T17:48:42.622Z
Path: \Device\HarddiskVolume1
Process Name: C:\Windows\System32\svchost.exe
Security intelligence Version: 1.359.1169.0
Engine Version: 1.1.18900.3
Product Version: 4.18.2201.10

Date: 2022-03-02 19:44:34
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Full Scan

Date: 2022-03-02 19:44:34
Description:
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name=VirTool:Win32/DefenderTamperingRestore&threatid=2147741622&enterprise=0
Name: VirTool:Win32/DefenderTamperingRestore
Severity: Много високо
Category: Инструмент
Path: regkeyvalue:_hklm\software\policies\microsoft\windows defender\\DisableAntiSpyware
Detection Origin: Unknown
Detection Type: Concrete
Detection Source: User
Process Name: Unknown
Security intelligence Version: AV: 1.359.1169.0, AS: 1.359.1169.0, NIS: 1.359.1169.0
Engine Version: AM: 1.1.18900.3, NIS: 1.1.18900.3

Date: 2022-03-02 19:35:42
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Full Scan

Date: 2022-03-02 00:01:41
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan

CodeIntegrity:
===============
Date: 2022-02-28 04:34:34
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\msra.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\nvspcap64.dll that did not meet the Microsoft signing level requirements.

Date: 2022-02-27 18:59:52
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\360\Total Security\safemon\WscReg.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2022-02-27 00:12:13
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\Microsoft\Edge\Application\msedge.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\360\Total Security\safemon\SafeWrapper.dll that did not meet the Microsoft signing level requirements.


==================== Memory info ===========================

BIOS: American Megatrends Inc. 2.80 06/10/2020
Motherboard: Micro-Star International Co., Ltd. B450M MORTAR MAX (MS-7B89)
Processor: AMD Ryzen 5 3600X 6-Core Processor
Percentage of memory in use: 43%
Total physical RAM: 16333.16 MB
Available physical RAM: 9157.81 MB
Total Virtual: 32717.16 MB
Available Virtual: 22771 MB

==================== Drives ================================

Drive 😄 () (Fixed) (Total:476.33 GB) (Free:416.23 GB) NTFS
Drive d: () (Fixed) (Total:931.5 GB) (Free:407.35 GB) NTFS

\\?\Volume{0fd938b6-4a27-48ad-bcd5-3b63c9a118a6}\ () (Fixed) (Total:0.5 GB) (Free:0.08 GB) NTFS
\\?\Volume{0fda4880-f08c-4d34-8af6-ecac1159f6fe}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000)

Partition: GPT.

==========================================================
Disk: 1 (Size: 476.9 GB) (Disk ID: AB29CA33)

Partition: GPT.

==================== End of Addition.txt =======================

 

На първо четене системата ви е заразена ..! SAntivirus е  potentially unwanted program (PUP). 

Утре ще прегледам отново по обстойно дневниците и ще ви върна отговор..! Приятна вечер ..! :) 

Регистрирайте се или влезете в профила си за да коментирате

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.