Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Лаптопа ми работи постоянно на 100 % Disk Processes - Task Manager

Featured Replies

Здравейте, лаптопа ми работи постоянно на 100 % Disk в Task Manager и стана много бавен. Дали има начин да се оправи ?

image.png.776f7d12456be7ee82630e4a042571b9.png

Аз лично не виждам нищо притеснително. 

System товари често харда, и при мен - но в началото при стартиране на машината, и за няколко минути.

Също и SysMain -системни файлове.

Ако желаете пуснете тема за проверка на компютъра за вируси в раздел https://www.kaldata.com/forums/forum/137-премахване-на-зловреден-софтуер/, като изпълните правилата и следвайте инструкциите...

  • Автор

Благодаря, ще го пусна в другият форум.

 

  • Автор

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 11-10-2022
Ran by vlupo (administrator) on ASUS (ASUSTeK COMPUTER INC. X540LA) (12-10-2022 23:02:29)
Running from C:\Users\vlupo\OneDrive\Desktop
Loaded Profiles: vlupo
Platform: Microsoft Windows 10 Home Version 21H2 19044.2130 (X64) Language: English (United States)
Default browser: Edge
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe ->) (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MsMpEng.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MpCopyAccelerator.exe
(C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe ->) (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(C:\Windows\SysWOW64\esif_uf.exe ->) (Intel(R) Software -> Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <15>
(Intel Corporation -> ) C:\Windows\System32\igfxTray.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(services.exe ->) (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(services.exe ->) (Intel(R) Software -> Intel Corporation) C:\Windows\SysWOW64\esif_uf.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\NisSrv.exe
(services.exe ->) (Qualcomm Atheros -> Windows (R) Win 7 DDK provider) C:\Windows\System32\drivers\AdminService.exe
(services.exe ->) (SafeNet, Inc. -> SafeNet, Inc.) C:\Windows\System32\hasplms.exe
(svchost.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.152\GoogleCrashHandler.exe
(svchost.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.152\GoogleCrashHandler64.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.1940_none_7dd80d767cb5c7b0\TiWorker.exe
(svchost.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKU\S-1-5-21-1399149081-3949388591-1868938846-1001\...\Run: [uTorrent] => C:\Users\vlupo\AppData\Roaming\uTorrent\uTorrent.exe [2146776 2021-03-06] (BitTorrent Inc -> BitTorrent Inc.)
HKU\S-1-5-21-1399149081-3949388591-1868938846-1001\...\Run: [Viber] => C:\Users\vlupo\AppData\Local\Viber\Viber.exe [47907032 2021-02-25] (Viber Media S.à r.l. -> Viber Media S.à r.l.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\106.0.5249.103\Installer\chrmstp.exe [2022-10-07] (Google LLC -> Google LLC)
HKLM\Software\...\Authentication\Credential Providers: [{f64945df-4fa9-4068-a2fb-61af319edd33}] -> C:\WINDOWS\system32\rdpcredentialprovider.dll [2022-10-12] (Microsoft Windows -> Microsoft Corporation)

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {04B3B6F2-EEF0-4280-8196-0904D4A720A5} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MpCmdRun.exe [1335960 2022-09-07] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {0B3B22B9-2C42-466C-84A8-C1B63AE7E2EE} - System32\Tasks\Opera scheduled assistant Autoupdate 1615028966 => C:\Users\vlupo\AppData\Local\Programs\Opera\launcher.exe -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\vlupo\AppData\Local\Programs\Opera\assistant" $(Arg0)
Task: {0F3B90C1-E1D3-4FA0-92B7-4C4AD632E7B1} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1492960 2017-11-16] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {3EB5C4E0-F35D-449D-90F0-F28EF2630590} - System32\Tasks\Opera scheduled Autoupdate 1615028954 => C:\Users\vlupo\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate $(Arg0) (No File)
Task: {5275FDD3-EF2E-4E10-B57C-45290B8D167F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155592 2020-12-13] (Google LLC -> Google LLC)
Task: {533305E1-9C21-4311-BAE9-4BBD0204853A} - System32\Tasks\ATK Package 36D18D69AFC3 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [122008 2015-09-22] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
Task: {7860D3DA-7D77-47FA-AA1A-98355758E141} - System32\Tasks\ATK Package A22126881260 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [122008 2015-09-22] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
Task: {A70DEA14-129B-41AC-9503-B32E5E9137FE} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1552376 2022-09-26] (Adobe Inc. -> Adobe Inc.)
Task: {AA46A57F-CDDA-4E89-A3B7-3B94DC42D8C7} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155592 2020-12-13] (Google LLC -> Google LLC)
Task: {CBDD1404-46AD-4EA6-B65B-2E3CAA79BB71} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MpCmdRun.exe [1335960 2022-09-07] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {DBEEC12E-0B0B-4BDE-A7B1-C84562FBB409} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MpCmdRun.exe [1335960 2022-09-07] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {DDCE6EB7-1D2E-4AF3-97BA-51FDA6773F86} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MpCmdRun.exe [1335960 2022-09-07] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {F8999838-3D53-4FF8-B803-56FFB3A227AF} - System32\Tasks\RtHDVBg_ListenToDevice => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1492960 2017-11-16] (Realtek Semiconductor Corp. -> Realtek Semiconductor)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\..\Interfaces\{035bbb0c-43fe-4d95-9db7-b516a78b0d8b}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{d2464b2f-fac7-461d-944b-0c33360c2f02}: [DhcpNameServer] 192.168.0.1

Edge: 
=======
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge DefaultProfile: Default
Edge Profile: C:\Users\vlupo\AppData\Local\Microsoft\Edge\User Data\Default [2022-10-12]
Edge Notifications: Default -> hxxps://mail.yahoo.com; hxxps://www.forexfactory.com
Edge HomePage: Default -> hxxp://www.bronav.com
Edge Session Restore: Default -> is enabled.
Edge Extension: (Malwarebytes Browser Guard) - C:\Users\vlupo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bojobppfploabceghnmlahpoonbcbacn [2022-10-12]
Edge Extension: (Avast Online Security & Privacy) - C:\Users\vlupo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fdgpikaaheckgdijjmepmdjjkbceakif [2022-10-09]

FireFox:
========
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2022-09-08] (Adobe Inc. -> Adobe Systems Inc.)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\autoconfig.js [2018-11-08] <==== ATTENTION (Points to *.cfg file)
FF ExtraCheck: C:\Program Files\mozilla firefox\cck2.cfg [2018-11-08] <==== ATTENTION

Chrome: 
=======
CHR Profile: C:\Users\vlupo\AppData\Local\Google\Chrome\User Data\Default [2022-10-09]
CHR Notifications: Default -> hxxps://angelovdimitar.com; hxxps://calendar.google.com
CHR HomePage: Default -> hxxp://www.bronav.com
CHR DefaultSearchURL: Default -> hxxps://www.qsearch.pw/se/search?sspid=10&mid=23b977abb9fed1a001c84cce48cebd78&source=ctappex&os_version=12.1.0&source_version=1.0.94&channel=&query={searchTerms}
CHR DefaultSearchKeyword: Default -> qsearch
CHR Session Restore: Default -> is enabled.
CHR Extension: (Avast Passwords) - C:\Users\vlupo\AppData\Local\Google\Chrome\User Data\Default\Extensions\emhginjpijfggbofeediiojmdlmlkoik [2020-12-13]
CHR Extension: (iCloud Bookmarks) - C:\Users\vlupo\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkepacicchenbjecpbpbclokcabebhah [2022-06-09]
CHR Extension: (Google Docs Offline) - C:\Users\vlupo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-10-08]
CHR Extension: (Grammarly: Grammar Checker and Writing App) - C:\Users\vlupo\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2022-10-07]
CHR Extension: (Zoom Scheduler) - C:\Users\vlupo\AppData\Local\Google\Chrome\User Data\Default\Extensions\kgjfgplpablkjnlkjmjdecgdpfankdle [2022-06-09]
CHR Extension: (Chrome Web Store Payments) - C:\Users\vlupo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29]
CHR Extension: (Bookmarks clean up) - C:\Users\vlupo\AppData\Local\Google\Chrome\User Data\Default\Extensions\oncbjlgldmiagjophlhobkogeladjijl [2020-12-13]

Opera: 
=======
OPR Profile: C:\Users\vlupo\AppData\Roaming\Opera Software\Opera Stable [2021-03-06]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S4 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [173040 2022-09-26] (Adobe Inc. -> Adobe Inc.)
R2 hasplms; C:\WINDOWS\system32\hasplms.exe [4574520 2017-02-14] (SafeNet, Inc. -> SafeNet, Inc.)
S2 Macs3.BlueTrackerConnector; c:\mxmacs3\macs3.bluetrackerconnector.exe [29184 2016-05-20] (Microsoft) [File not signed]
S2 Macs3.Online32; c:\mxmacs3\macs3.online32.exe [15872 2016-05-23] () [File not signed]
S2 Macs3.Server; c:\mxmacs3\macs3.server.exe [12288 2016-05-23] () [File not signed]
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\NisSrv.exe [3125112 2022-09-07] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MsMpEng.exe [133560 2022-09-07] (Microsoft Windows Publisher -> Microsoft Corporation)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 AsusSGDrv; C:\WINDOWS\System32\drivers\AsusSGDrv.sys [140032 2019-08-19] (ASUSTek Computer Inc. -> ASUS Corporation)
R1 ATKWMIACPIIO_; C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [20096 2015-05-08] (Microsoft Windows Hardware Compatibility Publisher -> ASUSTek Computer Inc.)
R2 hardlock; C:\WINDOWS\system32\drivers\hardlock.sys [1287496 2017-02-14] (SafeNet, Inc. -> SafeNet, Inc.)
R3 HIDSwitch; C:\WINDOWS\System32\drivers\AsRadioControl.sys [32696 2020-11-19] (ASUSTek Computer Inc. -> ASUS)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49576 2022-09-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [453904 2022-09-07] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [94480 2022-09-07] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2022-10-12 23:01 - 2022-10-12 23:04 - 000000000 ____D C:\FRST
2022-10-12 20:00 - 2022-10-12 20:00 - 000039936 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2022-10-12 20:00 - 2022-10-12 20:00 - 000012253 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2022-10-12 19:59 - 2022-10-12 19:59 - 001333760 _____ C:\WINDOWS\SysWOW64\TextInputMethodFormatter.dll
2022-10-12 19:57 - 2022-10-12 19:57 - 000060928 _____ C:\WINDOWS\system32\runexehelper.exe
2022-10-12 19:57 - 2022-10-12 19:57 - 000048640 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2022-10-12 19:55 - 2022-10-12 19:55 - 002260480 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll
2022-10-12 19:54 - 2022-10-12 19:54 - 000288768 _____ C:\WINDOWS\system32\Windows.Management.InprocObjects.dll
2022-10-12 18:41 - 2022-10-12 18:41 - 000000000 ___HD C:\$WinREAgent
2022-10-08 19:23 - 2022-10-08 19:23 - 000000000 ____D C:\Users\vlupo\AppData\Local\mbam
2022-10-08 19:18 - 2022-10-08 19:19 - 000000000 ____D C:\Program Files\Malwarebytes
2022-10-08 19:09 - 2022-10-08 19:15 - 000000000 ____D C:\AdwCleaner
2022-10-08 19:08 - 2022-10-08 19:08 - 008551608 _____ (Malwarebytes) C:\Users\vlupo\Downloads\AdwCleaner.exe
2022-10-08 19:06 - 2022-10-08 19:06 - 002631672 _____ (Malwarebytes) C:\Users\vlupo\Downloads\MBSetup.exe
2022-10-08 13:36 - 2022-10-08 13:47 - 000000000 ____D C:\Users\vlupo\AppData\Roaming\Geek Uninstaller
2022-10-08 13:34 - 2022-10-08 13:34 - 002789978 _____ C:\Users\vlupo\Downloads\geek.zip
2022-10-07 14:24 - 2022-10-07 14:24 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2022-10-07 13:26 - 2022-10-07 13:26 - 000000000 ____D C:\WINDOWS\pss
2022-10-07 12:06 - 2022-10-09 14:39 - 000007601 _____ C:\Users\vlupo\AppData\Local\Resmon.ResmonCfg
2022-09-14 21:19 - 2022-09-14 21:19 - 000413696 _____ C:\WINDOWS\system32\AzureCheck.dll
2022-09-14 21:19 - 2022-09-14 21:19 - 000098816 _____ C:\WINDOWS\system32\Drivers\cimfs.sys
2022-09-13 19:37 - 2022-09-13 19:37 - 000000000 ____D C:\Users\vlupo\AppData\Roaming\com.adobe.dunamis

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2022-10-12 22:47 - 2020-12-13 19:21 - 000000000 ____D C:\Program Files (x86)\Google
2022-10-12 22:47 - 2020-12-13 16:24 - 000000000 __SHD C:\Users\vlupo\IntelGraphicsProfiles
2022-10-12 22:47 - 2020-12-13 16:07 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2022-10-12 22:46 - 2021-01-08 11:55 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2022-10-12 21:27 - 2019-12-07 12:13 - 000000000 ____D C:\WINDOWS\INF
2022-10-12 21:24 - 2021-01-08 12:30 - 000795738 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2022-10-12 21:23 - 2019-12-07 12:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2022-10-12 21:21 - 2021-01-08 11:55 - 000442144 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2022-10-12 21:19 - 2021-01-08 12:57 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2022-10-12 21:18 - 2019-12-07 12:14 - 000000000 ____D C:\WINDOWS\ServiceState
2022-10-12 21:17 - 2021-01-08 11:54 - 000008192 ___SH C:\DumpStack.log.tmp
2022-10-12 21:16 - 2019-12-07 12:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2022-10-12 21:11 - 2019-12-07 12:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2022-10-12 21:10 - 2019-12-07 12:14 - 000000000 ____D C:\WINDOWS\SystemResources
2022-10-12 21:10 - 2019-12-07 12:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2022-10-12 21:09 - 2019-12-07 12:14 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2022-10-12 21:09 - 2019-12-07 12:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2022-10-12 21:09 - 2019-12-07 12:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2022-10-12 21:07 - 2019-12-07 12:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2022-10-12 21:07 - 2019-12-07 12:14 - 000000000 ____D C:\WINDOWS\Provisioning
2022-10-12 21:07 - 2019-12-07 12:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2022-10-12 21:07 - 2019-12-07 12:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2022-10-12 20:57 - 2019-12-07 12:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2022-10-12 20:26 - 2019-12-07 12:15 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2022-10-12 20:26 - 2019-12-07 12:14 - 000232448 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2022-10-12 19:54 - 2021-01-08 12:04 - 003015168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2022-10-12 18:28 - 2020-12-13 18:50 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2022-10-12 18:28 - 2019-12-07 12:14 - 000000000 ___HD C:\Program Files\WindowsApps
2022-10-12 18:28 - 2019-12-07 12:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2022-10-12 18:24 - 2020-12-13 20:17 - 000000000 ____D C:\WINDOWS\system32\MRT
2022-10-12 18:09 - 2020-12-13 20:17 - 147398024 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2022-10-11 22:29 - 2021-01-08 12:13 - 000000000 ____D C:\Users\vlupo
2022-10-11 22:25 - 2019-12-07 12:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2022-10-11 20:45 - 2021-01-08 12:57 - 000004168 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{1BA4487B-BC25-49B0-9B2B-27D82AB57D16}
2022-10-10 17:35 - 2021-03-06 19:39 - 000000000 ____D C:\Users\vlupo\AppData\Local\CrashDumps
2022-10-10 10:32 - 2022-07-06 18:33 - 000000000 ____D C:\Users\vlupo\AppData\Roaming\Telegram Desktop
2022-10-08 20:07 - 2020-12-13 15:54 - 000000000 ____D C:\Users\vlupo\AppData\Local\Packages
2022-10-08 20:04 - 2020-12-22 20:58 - 000000000 ____D C:\Users\vlupo\AppData\Local\D3DSCache
2022-10-08 19:31 - 2021-04-01 13:17 - 000000000 ____D C:\mxmacs3
2022-10-08 19:15 - 2020-12-13 20:22 - 000000000 ____D C:\Program Files (x86)\ASUS
2022-10-08 18:47 - 2020-12-13 20:33 - 000000000 ____D C:\ProgramData\ASUS Smart Gesture
2022-10-08 13:56 - 2021-04-01 17:10 - 000000000 ____D C:\Users\vlupo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Macs3 Loading - Stability
2022-10-07 22:34 - 2020-12-13 19:22 - 000002247 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2022-10-07 18:01 - 2021-01-09 12:42 - 000000000 ____D C:\Users\vlupo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Trader Workstation
2022-10-07 18:01 - 2021-01-09 12:41 - 000000000 ____D C:\Jts
2022-10-07 17:22 - 2019-12-07 12:14 - 000000000 ____D C:\WINDOWS\system32\spool
2022-10-07 12:09 - 2021-01-12 11:57 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2022-10-07 11:49 - 2022-01-02 15:09 - 000000000 ___RD C:\Users\vlupo\iCloudDrive
2022-09-14 23:40 - 2019-12-07 12:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2022-09-14 23:40 - 2019-12-07 12:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2022-09-14 23:40 - 2019-12-07 12:14 - 000000000 ____D C:\WINDOWS\system32\setup
2022-09-14 23:40 - 2019-12-07 12:14 - 000000000 ____D C:\WINDOWS\system32\DDFs
2022-09-12 16:34 - 2021-01-12 11:55 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk

==================== Files in the root of some directories ========

2022-10-07 12:06 - 2022-10-09 14:39 - 000007601 _____ () C:\Users\vlupo\AppData\Local\Resmon.ResmonCfg

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================

  • Автор

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-10-2022
Ran by vlupo (12-10-2022 23:14:06)
Running from C:\Users\vlupo\OneDrive\Desktop
Microsoft Windows 10 Home Version 21H2 19044.2130 (X64) (2021-01-08 10:02:45)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================


(If an entry is included in the fixlist, it will be removed.)

Administrator (S-1-5-21-1399149081-3949388591-1868938846-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1399149081-3949388591-1868938846-503 - Limited - Disabled)
Guest (S-1-5-21-1399149081-3949388591-1868938846-501 - Limited - Disabled)
vlupo (S-1-5-21-1399149081-3949388591-1868938846-1001 - Administrator - Enabled) => C:\Users\vlupo
WDAGUtilityAccount (S-1-5-21-1399149081-3949388591-1868938846-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-1399149081-3949388591-1868938846-1001\...\uTorrent) (Version: 3.5.5.45852 - BitTorrent Inc.)
Admiral Markets MT4 (HKLM-x32\...\Admiral Markets MT4) (Version: 4.00 - MetaQuotes Software Corp.)
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 22.002.20212 - Adobe Systems Incorporated)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601032}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0050 - ASUS)
BS.Player FREE (HKLM-x32\...\BSPlayerf) (Version: 2.75.1089 - AB Team, d.o.o.)
FX Delta (HKLM-x32\...\FX Delta) (Version:  - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 106.0.5249.103 - Google LLC)
iCloud Outlook (HKLM\...\{F054257C-600A-4918-B730-F6829E491781}) (Version: 13.0.0.201 - Apple Inc.)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.5107 - Intel Corporation)
MetaTrader 4 IC Markets (HKLM-x32\...\MetaTrader 4 IC Markets) (Version: 4.00 - MetaQuotes Software Corp.)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 106.0.1370.42 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 106.0.1370.37 - Microsoft Corporation)
Microsoft Office Access MUI (English) 2010 (HKLM-x32\...\{90140000-0015-0409-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Access Setup Metadata MUI (English) 2010 (HKLM-x32\...\{90140000-0117-0409-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (English) 2010 (HKLM-x32\...\{90140000-0016-0409-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (English) 2010 (HKLM-x32\...\{90140000-00BA-0409-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (English) 2010 (HKLM-x32\...\{90140000-0044-0409-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2010 (HKLM\...\{90140000-002A-0000-1000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (English) 2010 (HKLM-x32\...\{90140000-00A1-0409-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (English) 2010 (HKLM-x32\...\{90140000-001A-0409-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (English) 2010 (HKLM-x32\...\{90140000-0018-0409-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2010 (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Proof (English) 2010 (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Spanish) 2010 (HKLM-x32\...\{90140000-001F-0C0A-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (English) 2010 (HKLM-x32\...\{90140000-002C-0409-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (English) 2010 (HKLM-x32\...\{90140000-0019-0409-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (English) 2010 (HKLM\...\{90140000-002A-0409-1000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010 (HKLM\...\{90140000-0116-0409-1000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (English) 2010 (HKLM-x32\...\{90140000-006E-0409-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared Setup Metadata MUI (English) 2010 (HKLM-x32\...\{90140000-0115-0409-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (English) 2010 (HKLM-x32\...\{90140000-001B-0409-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Update Health Tools (HKLM\...\{7B1FCD52-8F6B-4F12-A143-361EA39F5E7C}) (Version: 3.67.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (HKLM-x32\...\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (HKLM-x32\...\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\{9495AEB4-AB97-39DE-8C42-806EEF75ECA7}) (Version: 10.0.50908 - Microsoft Corporation) Hidden
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8302 - Realtek Semiconductor Corp.)
Sentinel Runtime (HKLM-x32\...\{2C536B88-EA6B-4C24-A241-FD21981A99B0}) (Version: 7.54.1.67019 - Gemalto)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0015-0409-0000-0000000FF1CE}_Office14.PROPLUS_{D6A2CD7F-C90C-4B90-BBA7-2BADE2E08610}) (Version:  - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0016-0409-0000-0000000FF1CE}_Office14.PROPLUS_{D6A2CD7F-C90C-4B90-BBA7-2BADE2E08610}) (Version:  - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0409-0000-0000000FF1CE}_Office14.PROPLUS_{D6A2CD7F-C90C-4B90-BBA7-2BADE2E08610}) (Version:  - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0019-0409-0000-0000000FF1CE}_Office14.PROPLUS_{D6A2CD7F-C90C-4B90-BBA7-2BADE2E08610}) (Version:  - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUS_{D6A2CD7F-C90C-4B90-BBA7-2BADE2E08610}) (Version:  - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-001B-0409-0000-0000000FF1CE}_Office14.PROPLUS_{D6A2CD7F-C90C-4B90-BBA7-2BADE2E08610}) (Version:  - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUS_{09A9DF49-DA06-4093-A2FD-F339211E39EA}) (Version:  - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUS_{ECC1D579-DC17-4B90-929C-B4A0BB35F7B3}) (Version:  - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUS_{8C5A05B6-FF56-480F-A0E6-9F4BCA4B4CAC}) (Version:  - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{E4D76E88-C65F-4003-9C71-EC4306679D17}) (Version:  - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0409-1000-0000000FF1CE}_Office14.PROPLUS_{03AE1408-7BF1-4AC6-A327-E32E7799BCE4}) (Version:  - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-002C-0409-0000-0000000FF1CE}_Office14.PROPLUS_{945F1D43-451D-4383-9BBE-241F37950B15}) (Version:  - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0044-0409-0000-0000000FF1CE}_Office14.PROPLUS_{D6A2CD7F-C90C-4B90-BBA7-2BADE2E08610}) (Version:  - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-006E-0409-0000-0000000FF1CE}_Office14.PROPLUS_{8DD50F3B-E0BD-4E39-AF1F-2F316B4FC528}) (Version:  - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-00A1-0409-0000-0000000FF1CE}_Office14.PROPLUS_{D6A2CD7F-C90C-4B90-BBA7-2BADE2E08610}) (Version:  - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-00BA-0409-0000-0000000FF1CE}_Office14.PROPLUS_{D6A2CD7F-C90C-4B90-BBA7-2BADE2E08610}) (Version:  - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0115-0409-0000-0000000FF1CE}_Office14.PROPLUS_{8DD50F3B-E0BD-4E39-AF1F-2F316B4FC528}) (Version:  - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0116-0409-1000-0000000FF1CE}_Office14.PROPLUS_{03AE1408-7BF1-4AC6-A327-E32E7799BCE4}) (Version:  - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0117-0409-0000-0000000FF1CE}_Office14.PROPLUS_{D6A2CD7F-C90C-4B90-BBA7-2BADE2E08610}) (Version:  - Microsoft) Hidden
tastyworks (HKLM\...\{0BE7561E-EE36-3713-B8C8-DDF655DCE93F}) (Version: 1.12.2 - tastyworks, inc.)
Telegram Desktop (HKU\S-1-5-21-1399149081-3949388591-1868938846-1001\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 4.0.2 - Telegram FZ-LLC)
Trader Workstation (HKU\S-1-5-21-1399149081-3949388591-1868938846-1001\...\5889-6375-8446-2021) (Version: latest (10.19.1c) 20221003 15:39:58 - Interactive Brokers LLC)
Update for Windows 10 for x64-based Systems (KB5001716) (HKLM\...\{82BD0A1C-815F-487F-9AE7-CE73DA413CFF}) (Version: 4.91.0.0 - Microsoft Corporation)
Varchev Absolute Trader (HKU\S-1-5-21-1399149081-3949388591-1868938846-1001\...\Varchev_Absolute_Trader) (Version: 2.38.1-Build6 - X Open Hub)
Varchev MT4 (HKLM-x32\...\Varchev MT4) (Version: 4.00 - MetaQuotes Software Corp.)
Viber (HKLM-x32\...\{C3909B59-A21E-4BA2-8E6B-E0985804E405}) (Version: 14.8.0.3 - Viber Media S.a.r.l) Hidden
Viber (HKU\S-1-5-21-1399149081-3949388591-1868938846-1001\...\{ec8a1876-e90b-4cb2-b2e8-f31d30357d17}) (Version: 14.8.0.3 - 2010-2021 Viber Media S.a.r.l)
WhatsApp (HKU\S-1-5-21-1399149081-3949388591-1868938846-1001\...\WhatsApp) (Version: 2.2222.12 - WhatsApp)
Windows PC Health Check (HKLM\...\{6798C408-2636-448C-8AC6-F4E341102D27}) (Version: 3.6.2204.08001 - Microsoft Corporation)
WinRAR 5.01 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)

Packages:
=========
iCloud -> C:\Program Files\WindowsApps\AppleInc.iCloud_13.4.101.0_x86__nzyj5cx40ttqa [2022-08-07] (Apple Inc.) [Startup Task]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2021-01-08] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2021-01-08] (Microsoft Corporation) [MS Ad]

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1399149081-3949388591-1868938846-1001_Classes\CLSID\{913AA462-7BA0-4D83-B3CC-3CEEEC397AF5} -> [iCloud Drive] => C:\Users\vlupo\iCloudDrive [2022-01-02 15:09]
ShellExecuteHooks: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [6671064 2013-12-19] (Microsoft Corporation -> Microsoft Corporation)
ShellExecuteHooks-x32: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [4171480 2013-12-19] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} =>  -> No File
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2013-12-01] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2013-12-01] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2020-01-16] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2013-12-01] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2013-12-01] (win.rar GmbH -> Alexander Roshal)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) ==========

SearchScopes: HKU\S-1-5-21-1399149081-3949388591-1868938846-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation -> Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation -> Microsoft Corporation)

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-1399149081-3949388591-1868938846-1001\...\localhost -> localhost

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2019-03-19 07:49 - 2019-03-19 07:49 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

2022-03-03 19:58 - 2022-03-03 19:58 - 000000374 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1399149081-3949388591-1868938846-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\vlupo\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\img0.jpg
DNS Servers: 8.8.8.8
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKLM\...\StartupApproved\Run: => "SecurityHealth"
HKU\S-1-5-21-1399149081-3949388591-1868938846-1001\...\StartupApproved\Run: => "uTorrent"
HKU\S-1-5-21-1399149081-3949388591-1868938846-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_3B94AEE614AD99E018DDD3CE7C5A0315"
HKU\S-1-5-21-1399149081-3949388591-1868938846-1001\...\StartupApproved\Run: => "Viber"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{83FFBACA-4762-468B-9B4C-F55BD8886513}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe => No File
FirewallRules: [{A7B2DC85-2084-4751-8951-31474672EA15}] => (Block) C:\users\vlupo\appdata\local\temp\driverpack-20201214102056\tools\aria2c.exe => No File
FirewallRules: [{FBABA434-0973-40C0-A288-AFC09F427A9F}] => (Block) C:\users\vlupo\appdata\local\temp\driverpack-20201214102056\tools\aria2c.exe => No File
FirewallRules: [UDP Query User{E29BEA18-706C-47F9-81C3-76D832A08F6F}C:\users\vlupo\appdata\local\temp\driverpack-20201214102056\tools\aria2c.exe] => (Allow) C:\users\vlupo\appdata\local\temp\driverpack-20201214102056\tools\aria2c.exe => No File
FirewallRules: [TCP Query User{2684BD2B-AAF9-4A8B-9371-71FE39528FA0}C:\users\vlupo\appdata\local\temp\driverpack-20201214102056\tools\aria2c.exe] => (Allow) C:\users\vlupo\appdata\local\temp\driverpack-20201214102056\tools\aria2c.exe => No File
FirewallRules: [{8941309D-5ADA-43BA-8805-A1044DC85BF9}] => (Allow) C:\Users\vlupo\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{57EBFE1D-ADC9-46C7-A4B6-0E842E7D69CB}] => (Allow) C:\Users\vlupo\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{270FF534-0EDF-45F4-91D8-1EC7AD37F333}] => (Allow) C:\Users\vlupo\AppData\Local\Programs\Opera\74.0.3911.203\opera.exe => No File
FirewallRules: [TCP Query User{9C838F05-55A5-426D-AFFF-11832899499F}C:\users\vlupo\appdata\local\viber\viber.exe] => (Allow) C:\users\vlupo\appdata\local\viber\viber.exe (Viber Media S.à r.l. -> Viber Media S.à r.l.)
FirewallRules: [UDP Query User{C2CAB0DC-008F-45E7-95E1-1ECA8FB6DFE8}C:\users\vlupo\appdata\local\viber\viber.exe] => (Allow) C:\users\vlupo\appdata\local\viber\viber.exe (Viber Media S.à r.l. -> Viber Media S.à r.l.)
FirewallRules: [{CCACE71B-8E92-4481-A5EC-A7F58D138EA4}] => (Allow) C:\WINDOWS\system32\hasplms.exe (SafeNet, Inc. -> SafeNet, Inc.)
FirewallRules: [TCP Query User{47166DAD-D566-4D49-825E-B53797550D8A}C:\mxmacs3\macs3.exe] => (Allow) C:\mxmacs3\macs3.exe (Interschalt maritime systems AG) [File not signed]
FirewallRules: [UDP Query User{C123888B-B262-47A9-B07A-E96201E2E7CC}C:\mxmacs3\macs3.exe] => (Allow) C:\mxmacs3\macs3.exe (Interschalt maritime systems AG) [File not signed]
FirewallRules: [{3FE7F281-6975-45B2-A024-F17047599EB2}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.88.3401.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{0D7E4EC4-8210-489C-B4C0-64413E7F50C1}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.88.3401.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{1FA7361A-25ED-48F1-BE9A-2839E7C3C17A}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.88.3401.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{817351D2-A08C-4B9F-8231-06F037A302EB}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.88.3401.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{5CCAAF6A-A29A-431E-8EE5-0A10C6E20D02}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{38372330-F07D-4ED3-9A6A-A7F20C54A646}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\106.0.1370.37\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)

==================== Restore Points =========================

07-10-2022 17:18:51 Windows Modules Installer
08-10-2022 19:13:46 AdwCleaner_BeforeCleaning_08/10/2022_19:13:44
12-10-2022 18:30:45 Windows Modules Installer
12-10-2022 18:41:53 Windows Modules Installer

==================== Faulty Device Manager Devices ============


==================== Event log errors: ========================

Application errors:
==================
Error: (10/11/2022 10:22:08 PM) (Source: SecurityCenter) (EventID: 17) (User: )
Description: Security Center failed to validate caller with error %1.

Error: (10/10/2022 05:35:32 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: MbamBgNativeMsg.exe, version: 4.0.0.100, time stamp: 0x63225bbc
Faulting module name: ntdll.dll, version: 10.0.19041.1949, time stamp: 0xfe96c48e
Exception code: 0xc0000005
Fault offset: 0x000000000002faad
Faulting process id: 0x4ac
Faulting application start time: 0x01d8dcb587b957f6
Faulting application path: C:\Program Files\Malwarebytes\Anti-Malware\MbamBgNativeMsg.exe
Faulting module path: C:\WINDOWS\SYSTEM32\ntdll.dll
Report Id: 74086214-1c4d-4be7-8a6e-120af96a0dfc
Faulting package full name: 
Faulting package-relative application ID:

Error: (10/08/2022 08:49:20 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x8007045b, A system shutdown is in progress.
.

Error: (10/08/2022 08:49:20 PM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} and name CEventSystem cannot be started. [0x8007045b, A system shutdown is in progress.
]

Error: (10/08/2022 08:49:20 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x8007045b, A system shutdown is in progress.
.

Error: (10/08/2022 08:49:20 PM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} and name CEventSystem cannot be started. [0x8007045b, A system shutdown is in progress.
]

Error: (10/08/2022 07:51:16 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program svchost.exe version 10.0.19041.1806 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

Process ID: c78

Start Time: 01d8db33745f74a7

Termination Time: 4294967295

Application Path: C:\Windows\System32\svchost.exe

Report Id: 5fc8c09f-d244-4d33-a53d-8b2a86795f56

Faulting package full name: 

Faulting package-relative application ID: 

Hang type: Unknown

Error: (10/08/2022 07:30:05 PM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} and name CEventSystem cannot be started. [0x8007045b, A system shutdown is in progress.
]


System errors:
=============
Error: (10/12/2022 09:23:49 PM) (Source: Microsoft-Windows-Eventlog) (EventID: 30) (User: NT AUTHORITY)
Description: The event logging service encountered an error (5) while enabling publisher {a70ff94f-570b-4979-ba5c-e59c9feab61b} to channel Microsoft-Windows-WinINet/Operational. This does not affect channel operation, but does affect the ability of the publisher to raise events to the channel. One common reason for this error is that the Provider is using ETW Provider Security and has not granted enable permissions to the Event Log service identity.

Error: (10/12/2022 09:20:31 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Macs3.Server service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.

Error: (10/12/2022 09:20:31 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (45000 milliseconds) while waiting for the Macs3.Server service to connect.

Error: (10/12/2022 09:20:31 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Macs3.BlueTrackerConnector service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.

Error: (10/12/2022 09:20:31 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Macs3.Online32 service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.

Error: (10/12/2022 09:20:31 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (45000 milliseconds) while waiting for the Macs3.Online32 service to connect.

Error: (10/12/2022 09:20:31 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (45000 milliseconds) while waiting for the Macs3.BlueTrackerConnector service to connect.

Error: (10/12/2022 09:20:23 PM) (Source: hasplms) (EventID: 3) (User: )
Description: ERROR: Sentinel LDK License Manager failed to start in a promptly manner!


Windows Defender:
================
Date: 2022-10-07 15:31:43
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2022-09-29 18:03:52
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2022-09-28 18:49:07
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2022-09-21 17:50:26
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2022-09-20 19:41:28
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Event[0]:

Date: 2022-10-07 14:17:19
Description: 
Microsoft Defender Antivirus Real-Time Protection feature has encountered an error and failed.
Feature: On Access
Error Code: 0x8007043c
Error description: This service cannot be started in Safe Mode 
Reason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem.

Date: 2022-10-07 14:11:58
Description: 
Microsoft Defender Antivirus Real-Time Protection feature has encountered an error and failed.
Feature: On Access
Error Code: 0x8007043c
Error description: This service cannot be started in Safe Mode 
Reason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem.

Date: 2022-10-07 14:08:50
Description: 
Microsoft Defender Antivirus Real-Time Protection feature has encountered an error and failed.
Feature: On Access
Error Code: 0x8007043c
Error description: This service cannot be started in Safe Mode 
Reason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem.

Date: 2022-10-07 14:01:00
Description: 
Microsoft Defender Antivirus Real-Time Protection feature has encountered an error and failed.
Feature: On Access
Error Code: 0x8007043c
Error description: This service cannot be started in Safe Mode 
Reason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem.

Date: 2022-10-07 13:57:59
Description: 
Microsoft Defender Antivirus Real-Time Protection feature has encountered an error and failed.
Feature: On Access
Error Code: 0x8007043c
Error description: This service cannot be started in Safe Mode 
Reason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem.

CodeIntegrity:
===============
Date: 2022-10-12 17:58:56
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2022-10-09 14:39:01
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Microsoft signing level requirements.


==================== Memory info =========================== 

BIOS: American Megatrends Inc. X540LA.203 10/13/2015
Motherboard: ASUSTeK COMPUTER INC. X540LA
Processor: Intel(R) Core(TM) i3-5020U CPU @ 2.20GHz
Percentage of memory in use: 74%
Total physical RAM: 3994.44 MB
Available physical RAM: 1021.12 MB
Total Virtual: 5389.44 MB
Available Virtual: 2526.71 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:930.12 GB) (Free:817.43 GB) (Model: TOSHIBA MQ01ABD100) NTFS

\\?\Volume{a4277af3-41ae-4d2a-b0de-7d9a7455d14a}\ () (Fixed) (Total:0.56 GB) (Free:0.09 GB) NTFS
\\?\Volume{bf54d490-8dbe-4dca-a831-1ee5fd775a23}\ () (Fixed) (Total:0.25 GB) (Free:0.22 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: BCCE0F90)

Partition: GPT.

==================== End of Addition.txt =======================

Здравейте,

Лично аз не видях зловредна активност, но пак ще прегледам логовете за всеки случай.

Проблема продължава ли? Да не би да се е дължало на Windows Update, защото вторник имаше кръпки по сигурността на Windows.

Поздрави!

току-що, B-boy/StyLe/ написа:

Здравейте,

Лично аз не видях зловредна активност, но пак ще прегледам логовете за всеки случай.

Проблема продължава ли? Да не би да се е дължало на Windows Update, защото вторник имаше кръпки по сигурността на Windows.

Поздрави!

Знам, че не е редно да пиша във вашите теми, но наистина няма нищо зловредно. Нормална ситуация при 10 и 11 е това нещо. Можеш да ми изтриеш коментара! 

  • Автор
преди 30 минути, B-boy/StyLe/ написа:

Здравейте,

Лично аз не видях зловредна активност, но пак ще прегледам логовете за всеки случай.

Проблема продължава ли? Да не би да се е дължало на Windows Update, защото вторник имаше кръпки по сигурността на Windows.

Поздрави!

kaто че ли е по добре но като пусна да гледам някакъф филм пак ми засича лекоimage.png.489a2e1fa5fec581e7044780a7b6c5ff.png

Може ли докато сте с Task Manager => да отидете на Performance и да кликнете долу Open Resource Monitor.

След това отидете на Disk => подредете и горната и долната колонка по Write (B/sec) и снимайте екрана.

Изпитвам силни съмнения, че проблемът възниква от управлението на виртуалната памет. Задай й
Automatically manage paging file size for all drives - махни отметката
System managed size - сложи отметка и кликни бутона [Apply]. Ще поиска рестарт - потвърди.
Тествай след рестарта

  • Автор
на 13.10.2022 г. в 23:14, B-boy/StyLe/ написа:

Може ли докато сте с Task Manager => да отидете на Performance и да кликнете долу Open Resource Monitor.

След това отидете на Disk => подредете и горната и долната колонка по Write (B/sec) и снимайте екрана.

image.png.aace3f3f050b47bdaca7de3568433a1c.png

  • Автор
на 13.10.2022 г. в 23:23, цър-вул написа:

Изпитвам силни съмнения, че проблемът възниква от управлението на виртуалната памет. Задай й
Automatically manage paging file size for all drives - махни отметката
System managed size - сложи отметка и кликни бутона [Apply]. Ще поиска рестарт - потвърди.
Тествай след рестарта

Здравей, би ли обяснил как да стигна до управлвнието на виртуалната памет ?

 

на 13.10.2022 г. в 23:23, цър-вул написа:

Изпитвам силни съмнения, че проблемът възниква от управлението на виртуалната памет. Задай й
Automatically manage paging file size for all drives - махни отметката
System managed size - сложи отметка и кликни бутона [Apply]. Ще поиска рестарт - потвърди.
Тествай след рестарта

 

преди 8 минути, ves68 написа:

image.png.aace3f3f050b47bdaca7de3568433a1c.png

Само че разпънете Disk Activity отдолу и снимайте пак.

преди 4 минути, ves68 написа:

Здравей, би ли обяснил как да стигна до управлвнието на виртуалната памет ?

Може и с десен бутон на My Computer => Properties => вдясно посочете линка Advanced System Settings => след това на Performance кликнете на Settings => оттам на Advanced => и оттам на Change.

https://howtomanagedevices.com/windows-10/6411/how-to-manage-virtual-memory-page-file-size-in-windows-10/

  • Автор
преди 23 минути, B-boy/StyLe/ написа:

Само че разпънете Disk Activity отдолу и снимайте пак.

Може и с десен бутон на My Computer => Properties => вдясно посочете линка Advanced System Settings => след това на Performance кликнете на Settings => оттам на Advanced => и оттам на Change.

https://howtomanagedevices.com/windows-10/6411/how-to-manage-virtual-memory-page-file-size-in-windows-10/

image.png.a5f8326acbf1b82a1bb2895dc3363801.png

преди 26 минути, B-boy/StyLe/ написа:

Само че разпънете Disk Activity отдолу и снимайте пак.

Може и с десен бутон на My Computer => Properties => вдясно посочете линка Advanced System Settings => след това на Performance кликнете на Settings => оттам на Advanced => и оттам на Change.

https://howtomanagedevices.com/windows-10/6411/how-to-manage-virtual-memory-page-file-size-in-windows-10/

image.png.2277eefcc1203eb8912f482a37eece50.png

преди 34 минути, B-boy/StyLe/ написа:

Само че разпънете Disk Activity отдолу и снимайте пак.

Може и с десен бутон на My Computer => Properties => вдясно посочете линка Advanced System Settings => след това на Performance кликнете на Settings => оттам на Advanced => и оттам на Change.

https://howtomanagedevices.com/windows-10/6411/how-to-manage-virtual-memory-page-file-size-in-windows-10/

надявам се да е правилно 

image.png.11143baac2698b4d230cfa9b53bca4f4.png

image.png

Ами честно казано аз не виждам в момента да има голяма активност. Иначе сте се справили с промените на pagefile-a. Добре е да рестартирате след тези проблеми между другото.

Поздрави!

току-що, ves68 написа:

Ами аз ползвам Edge това спиране дали няма да ми попречи ?

Ще те питам пак. С хард диск ли си или с SSD?

  • Автор
преди 4 минути, Емил Костов написа:

Ще те питам пак. С хард диск ли си или с SSD?

Да ти кажа честно не разбирам но предполагам че е хард диск.

image.png.c47e4cb883e3f136c1f33e1603450a51.png

преди 4 минути, ves68 написа:

Да ти кажа честно не разбирам но предполагам че е хард диск.

image.png.c47e4cb883e3f136c1f33e1603450a51.png

Докато не си сложиш SSD, а държиш този бавен диск, винаги ще си на 100% 

Регистрирайте се или влезете в профила си за да коментирате

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.