Fix result of Farbar Recovery Scan Tool (x64) Version: 29-08-2020 Ran by Степа (31-08-2020 17:10:50) Run:1 Running from C:\Users\Степа\Desktop Loaded Profiles: Степа Boot Mode: Normal ============================================== fixlist content: ***************** CreateRestorePoint: (Microsoft Corporation) [File not signed] C:\ProgramData\RealtekHD\taskhost.exe (Microsoft Corporation) [File not signed] C:\ProgramData\RunDLL\rundll.exe (Microsoft Corporation) [File not signed] C:\ProgramData\RunDLL\system.exe (Realtek Semiconductor) [File not signed] C:\ProgramData\RealtekHD\taskhostw.exe HKLM\...\Run: [Realtek HD Audio] => C:\ProgramData\RealtekHD\taskhostw.exe [3027968 2020-05-05] (Realtek Semiconductor) [File not signed] <==== ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\Run: [MailRuUpdater] => C:\Users\Степа\AppData\Local\Mail.Ru\MailRuUpdater.exe [3255480 2019-08-07] (LLC Mail.Ru -> Mail.Ru) <==== ATTENTION HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\Policies\Explorer: [DisallowRun] 1 HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\Policies\Explorer\DisallowRun: [1] eav_trial_rus.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\Policies\Explorer\DisallowRun: [2] avast_free_antivirus_setup_online.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\Policies\Explorer\DisallowRun: [3] eis_trial_rus.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\Policies\Explorer\DisallowRun: [4] essf_trial_rus.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\Policies\Explorer\DisallowRun: [5] hitmanpro_x64.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\Policies\Explorer\DisallowRun: [6] ESETOnlineScanner_UKR.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\Policies\Explorer\DisallowRun: [7] ESETOnlineScanner_RUS.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\Policies\Explorer\DisallowRun: [8] HitmanPro.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\Policies\Explorer\DisallowRun: [9] 360TS_Setup_Mini.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\Policies\Explorer\DisallowRun: [10] Cezurity_Scanner_Pro_Free.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\Policies\Explorer\DisallowRun: [11] Cube.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\MountPoints2: J - J:\HiSuiteDownLoader.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\MountPoints2: {0be89d98-137b-11e7-890f-8c89a5c892db} - J:\Setup.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\MountPoints2: {77fdf047-5121-11e9-b5b0-8c89a5c892db} - J:\HiSuiteDownLoader.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\MountPoints2: {866b30a1-c3a1-11e7-8c03-8c89a5c892db} - J:\HiSuiteDownLoader.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\MountPoints2: {90a1244e-b2bf-11e6-8972-c7c3005845a5} - K:\LGAutoRun.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\MountPoints2: {be0b0aab-a7e3-11e9-89f4-8c89a5c892db} - L:\HiSuiteDownLoader.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\MountPoints2: {d38c54b1-e8c3-11e8-b0e2-8c89a5c892db} - J:\HiSuiteDownLoader.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\MountPoints2: {fb251bd2-9af8-11e8-8d59-8c89a5c892db} - J:\HiSuiteDownLoader.exe GroupPolicy: Restriction ? <==== ATTENTION GroupPolicy\User: Restriction ? <==== ATTENTION FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Default\Extensions\odijcgafkhpobjlnfdgiacpdenpmbgme C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\akkhkcocfnopiccplnimkefmaejepdlj CHR HKLM-x32\...\Chrome\Extension: [ajflepegnononcfmoikdnephfleldnbh] CHR HKLM-x32\...\Chrome\Extension: [bobeehhgpnppdghmfffdjadmbjbaeeod] CHR HKLM-x32\...\Chrome\Extension: [ccfifbojenkenpkmnbnndeadpfdiffof] CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] CHR HKLM-x32\...\Chrome\Extension: [fhoibnponjcgjgcnfacekaijdbbplhib] - hxxps://chrome.google.com/webstore/detail/fhoibnponjcgjgcnfacekaijdbbplhib CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] CHR HKLM-x32\...\Chrome\Extension: [indjgiebmakhmnaplnlnanodkfiejfjd] CHR HKLM-x32\...\Chrome\Extension: [odijcgafkhpobjlnfdgiacpdenpmbgme] CHR HKLM-x32\...\Chrome\Extension: [oelpkepjlgmehajehfeicfbjdiobdkfj] CHR HKLM-x32\...\Chrome\Extension: [ojlcebdkbpjdpiligkdbbkdkfjmchbfd] CHR HKLM-x32\...\Chrome\Extension: [phkdcinmmljblpnkohlipaiodlonpinf] CHR HKLM-x32\...\Chrome\Extension: [pmpoaahleccaibbhfjfimigepmfmmbbk] 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Users\Все пользователи\Norton 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Users\Все пользователи\grizzly 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Users\Все пользователи\ESET 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Users\Все пользователи\360safe 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\ProgramData\Norton 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\ProgramData\grizzly 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\ProgramData\ESET 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\ProgramData\360safe 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Program Files\SpyHunter 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Program Files\Malwarebytes 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Program Files\Kaspersky Lab 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Program Files\ESET 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Program Files\Enigma Software Group 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Program Files\COMODO 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Program Files\Common Files\McAfee 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Program Files\Cezurity 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Program Files\AVG 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Program Files\AVAST Software 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Program Files (x86)\SpyHunter 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Program Files (x86)\Panda Security 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Program Files (x86)\GRIZZLY Antivirus 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Program Files (x86)\Cezurity 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Program Files (x86)\AVG 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Program Files (x86)\AVAST Software 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Program Files (x86)\360 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 ____D C:\ProgramData\Avira 2020-08-26 23:27 - 2020-08-31 16:36 - 000000000 __SHD C:\ProgramData\WindowsTask 2020-08-26 23:27 - 2020-08-31 16:36 - 000000000 __SHD C:\ProgramData\RunDLL 2020-08-26 23:27 - 2020-08-29 19:04 - 000000000 __SHD C:\AdwCleaner 2020-08-26 23:27 - 2020-08-26 23:47 - 000000000 __SHD C:\ProgramData\Setup 2020-08-26 23:27 - 2020-08-26 23:28 - 000000000 __SHD C:\ProgramData\RealtekHD 2020-08-26 23:27 - 2020-08-26 23:27 - 000000000 __SHD C:\Program Files\ByteFence 2020-08-26 23:27 - 2020-08-26 23:27 - 000000000 __SHD C:\Program Files (x86)\Microsoft JDX 2020-08-26 23:27 - 2020-08-26 23:27 - 000000000 __SHD C:\KVRT_Data 2020-08-26 23:27 - 2020-08-26 23:27 - 000000000 ____D C:\Windows\speechstracing 2020-08-26 23:27 - 2020-08-26 23:27 - 000000000 ____D C:\ProgramData\System32 2020-08-26 23:27 - 2020-08-26 23:27 - 000000000 ____D C:\ProgramData\MB3Install 2020-08-26 23:27 - 2020-08-26 23:27 - 000000000 ____D C:\ProgramData\Malwarebytes 2020-08-26 23:27 - 2020-08-26 23:27 - 000000000 ____D C:\ProgramData\install 2020-08-26 23:27 - 2020-08-26 23:27 - 000000000 ____D C:\ProgramData\Indus ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File AlternateDataStreams: C:\ProgramData:MHD [306] AlternateDataStreams: C:\Users\All Users:MHD [306] AlternateDataStreams: C:\Users\Все пользователи:MHD [306] AlternateDataStreams: C:\ProgramData\Application Data:MHD [306] AlternateDataStreams: C:\Users\Public\AppData:CSM [464] AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [227] AlternateDataStreams: C:\Users\Все пользователи\Application Data:MHD [306] AlternateDataStreams: C:\Users\Степа\Application Data:!uuid [32] AlternateDataStreams: C:\Users\Степа\Local Settings:MHD [282] AlternateDataStreams: C:\Users\Степа\AppData\Local:MHD [282] AlternateDataStreams: C:\Users\Степа\AppData\Roaming:!uuid [32] AlternateDataStreams: C:\Users\Степа\AppData\Local\Application Data:MHD [282] AlternateDataStreams: C:\Users\Степа\AppData\Local\Temp:$DATA​ [16] AlternateDataStreams: C:\Users\Степа\AppData\Local\Temp:MHD [242] Hosts: FirewallRules: [{5BC886F3-7ED5-4899-A33A-2226E0CDF4C4}] => (Allow) LPort=80 FirewallRules: [{D2367CFE-4E24-4EB9-9363-51D23062DB2C}] => (Allow) LPort=443 FirewallRules: [{C9BAFD22-DE81-4637-8786-FAD6FC2F06B5}] => (Allow) LPort=20010 FirewallRules: [{DCB921DE-8092-4CB8-A7BD-675D3E0AFE94}] => (Allow) LPort=3478 FirewallRules: [{372DC243-374F-4507-9912-E828FB3FBFC2}] => (Allow) LPort=7850 FirewallRules: [{DC673507-5F13-4FE5-B95C-E8963AEAB8F2}] => (Allow) LPort=7852 FirewallRules: [{52C5020E-047B-4AD5-B0EF-A2FB23ED54BC}] => (Allow) LPort=7853 FirewallRules: [{C357E37B-AF88-4C48-AD10-A1A455A67AAB}] => (Allow) LPort=27022 FirewallRules: [{124E1B34-BE43-42EF-A9B4-75AB498A25D0}] => (Allow) LPort=6881 FirewallRules: [{E149A9A9-1806-4971-8AA5-7B99B1FA2188}] => (Allow) LPort=33333 FirewallRules: [{BE955F62-DEBF-45B1-81F1-BFE25A2DE325}] => (Allow) LPort=20443 FirewallRules: [{58BEA939-9653-4D22-B5B1-9FAA31112BFE}] => (Allow) LPort=8090 FirewallRules: [{CB552A22-BF43-4F7C-A31E-ABF924D17DEB}] => (Block) LPort=445 FirewallRules: [{2BA2F1B9-AA81-436A-9B2D-123CD7907A6E}] => (Block) LPort=445 FirewallRules: [{85232E0C-FE35-483E-856D-A0120546CABE}] => (Block) LPort=139 FirewallRules: [{7EF91AEC-895D-427A-9837-4C3CA63CB9D7}] => (Block) LPort=139 EmptyTemp: Reboot: ***************** Error: (0) Failed to create a restore point. [2444] C:\ProgramData\RealtekHD\taskhost.exe => process closed successfully. [11136] C:\ProgramData\RunDLL\rundll.exe => process closed successfully. [8096] C:\ProgramData\RunDLL\system.exe => process closed successfully. [3740] C:\ProgramData\RealtekHD\taskhostw.exe => process closed successfully. "HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Realtek HD Audio" => removed successfully HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => removed successfully "HKU\S-1-5-21-3129829678-2388851804-851762452-1000\Software\Microsoft\Windows\CurrentVersion\Run\\MailRuUpdater" => removed successfully "HKU\S-1-5-21-3129829678-2388851804-851762452-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisallowRun" => removed successfully "HKU\S-1-5-21-3129829678-2388851804-851762452-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\\1" => could not remove "HKU\S-1-5-21-3129829678-2388851804-851762452-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\\2" => could not remove "HKU\S-1-5-21-3129829678-2388851804-851762452-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\\3" => could not remove "HKU\S-1-5-21-3129829678-2388851804-851762452-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\\4" => could not remove "HKU\S-1-5-21-3129829678-2388851804-851762452-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\\5" => could not remove "HKU\S-1-5-21-3129829678-2388851804-851762452-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\\6" => could not remove "HKU\S-1-5-21-3129829678-2388851804-851762452-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\\7" => could not remove "HKU\S-1-5-21-3129829678-2388851804-851762452-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\\8" => could not remove "HKU\S-1-5-21-3129829678-2388851804-851762452-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\\9" => could not remove "HKU\S-1-5-21-3129829678-2388851804-851762452-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\\10" => could not remove "HKU\S-1-5-21-3129829678-2388851804-851762452-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\\11" => could not remove HKU\S-1-5-21-3129829678-2388851804-851762452-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\J => removed successfully HKU\S-1-5-21-3129829678-2388851804-851762452-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0be89d98-137b-11e7-890f-8c89a5c892db} => removed successfully HKU\S-1-5-21-3129829678-2388851804-851762452-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{77fdf047-5121-11e9-b5b0-8c89a5c892db} => removed successfully HKU\S-1-5-21-3129829678-2388851804-851762452-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{866b30a1-c3a1-11e7-8c03-8c89a5c892db} => removed successfully HKU\S-1-5-21-3129829678-2388851804-851762452-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{90a1244e-b2bf-11e6-8972-c7c3005845a5} => removed successfully HKU\S-1-5-21-3129829678-2388851804-851762452-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{be0b0aab-a7e3-11e9-89f4-8c89a5c892db} => removed successfully HKU\S-1-5-21-3129829678-2388851804-851762452-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d38c54b1-e8c3-11e8-b0e2-8c89a5c892db} => removed successfully HKU\S-1-5-21-3129829678-2388851804-851762452-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fb251bd2-9af8-11e8-8d59-8c89a5c892db} => removed successfully C:\Windows\system32\GroupPolicy\Machine => moved successfully C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully C:\Windows\SysWOW64\GroupPolicy\GPT.ini => moved successfully C:\Windows\system32\GroupPolicy\User => moved successfully HKLM\SOFTWARE\Policies\Mozilla => removed successfully HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer => removed successfully C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Default\Extensions\odijcgafkhpobjlnfdgiacpdenpmbgme => moved successfully C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\akkhkcocfnopiccplnimkefmaejepdlj => moved successfully HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ajflepegnononcfmoikdnephfleldnbh => removed successfully HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\bobeehhgpnppdghmfffdjadmbjbaeeod => removed successfully HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ccfifbojenkenpkmnbnndeadpfdiffof => removed successfully HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck => removed successfully HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fhoibnponjcgjgcnfacekaijdbbplhib => removed successfully HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki => removed successfully HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\indjgiebmakhmnaplnlnanodkfiejfjd => removed successfully HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\odijcgafkhpobjlnfdgiacpdenpmbgme => removed successfully HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\oelpkepjlgmehajehfeicfbjdiobdkfj => removed successfully HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ojlcebdkbpjdpiligkdbbkdkfjmchbfd => removed successfully HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\phkdcinmmljblpnkohlipaiodlonpinf => removed successfully HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pmpoaahleccaibbhfjfimigepmfmmbbk => removed successfully C:\Users\Все пользователи\Norton => moved successfully C:\Users\Все пользователи\grizzly => moved successfully C:\Users\Все пользователи\ESET => moved successfully C:\Users\Все пользователи\360safe => moved successfully "C:\ProgramData\Norton" => not found "C:\ProgramData\grizzly" => not found "C:\ProgramData\ESET" => not found "C:\ProgramData\360safe" => not found C:\Program Files\SpyHunter => moved successfully C:\Program Files\Malwarebytes => moved successfully C:\Program Files\Kaspersky Lab => moved successfully C:\Program Files\ESET => moved successfully C:\Program Files\Enigma Software Group => moved successfully C:\Program Files\COMODO => moved successfully C:\Program Files\Common Files\McAfee => moved successfully C:\Program Files\Cezurity => moved successfully C:\Program Files\AVG => moved successfully C:\Program Files\AVAST Software => moved successfully C:\Program Files (x86)\SpyHunter => moved successfully C:\Program Files (x86)\Panda Security => moved successfully C:\Program Files (x86)\GRIZZLY Antivirus => moved successfully C:\Program Files (x86)\Cezurity => moved successfully C:\Program Files (x86)\AVG => moved successfully C:\Program Files (x86)\AVAST Software => moved successfully C:\Program Files (x86)\360 => moved successfully C:\ProgramData\Avira => moved successfully C:\ProgramData\WindowsTask => moved successfully C:\ProgramData\RunDLL => moved successfully C:\AdwCleaner => moved successfully C:\ProgramData\Setup => moved successfully C:\ProgramData\RealtekHD => moved successfully C:\Program Files\ByteFence => moved successfully C:\Program Files (x86)\Microsoft JDX => moved successfully C:\KVRT_Data => moved successfully C:\Windows\speechstracing => moved successfully C:\ProgramData\System32 => moved successfully C:\ProgramData\MB3Install => moved successfully C:\ProgramData\Malwarebytes => moved successfully C:\ProgramData\install => moved successfully C:\ProgramData\Indus => moved successfully HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw => removed successfully C:\ProgramData => ":MHD" ADS removed successfully "C:\Users\All Users" => ":MHD" ADS not found. "C:\Users\Все пользователи" => ":MHD" ADS not found. "C:\ProgramData\Application Data" => ":MHD" ADS not found. C:\Users\Public\AppData => ":CSM" ADS removed successfully C:\Users\Public\Shared Files => ":VersionCache" ADS removed successfully "C:\Users\Все пользователи\Application Data" => ":MHD" ADS not found. C:\Users\Степа\Application Data => ":!uuid" ADS removed successfully C:\Users\Степа\Local Settings => ":MHD" ADS removed successfully "C:\Users\Степа\AppData\Local" => ":MHD" ADS not found. "C:\Users\Степа\AppData\Roaming" => ":!uuid" ADS not found. "C:\Users\Степа\AppData\Local\Application Data" => ":MHD" ADS not found. C:\Users\Степа\AppData\Local\Temp => ":$DATA​" ADS removed successfully C:\Users\Степа\AppData\Local\Temp => ":MHD" ADS removed successfully C:\Windows\System32\Drivers\etc\hosts => moved successfully Hosts restored successfully. "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{5BC886F3-7ED5-4899-A33A-2226E0CDF4C4}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D2367CFE-4E24-4EB9-9363-51D23062DB2C}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C9BAFD22-DE81-4637-8786-FAD6FC2F06B5}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{DCB921DE-8092-4CB8-A7BD-675D3E0AFE94}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{372DC243-374F-4507-9912-E828FB3FBFC2}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{DC673507-5F13-4FE5-B95C-E8963AEAB8F2}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{52C5020E-047B-4AD5-B0EF-A2FB23ED54BC}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C357E37B-AF88-4C48-AD10-A1A455A67AAB}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{124E1B34-BE43-42EF-A9B4-75AB498A25D0}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E149A9A9-1806-4971-8AA5-7B99B1FA2188}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{BE955F62-DEBF-45B1-81F1-BFE25A2DE325}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{58BEA939-9653-4D22-B5B1-9FAA31112BFE}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{CB552A22-BF43-4F7C-A31E-ABF924D17DEB}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{2BA2F1B9-AA81-436A-9B2D-123CD7907A6E}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{85232E0C-FE35-483E-856D-A0120546CABE}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{7EF91AEC-895D-427A-9837-4C3CA63CB9D7}" => removed successfully =========== EmptyTemp: ========== BITS transfer queue => 8388608 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 9975028 B Java, Flash, Steam htmlcache => 524 B Windows/system/drivers => 0 B Edge => 0 B Chrome => 425629917 B Firefox => 1140105561 B Opera => 3778246 B Temp, IE cache, history, cookies, recent: Users => 0 B Default => 0 B Public => 0 B ProgramData => 0 B systemprofile => 36372785 B systemprofile32 => 48153882 B LocalService => 48286126 B NetworkService => 48363004 B Степа => 329001772 B Stepa-2 => 329251327 B RecycleBin => 0 B EmptyTemp: => 2.3 GB temporary data Removed. ================================ The system needed a reboot. ==== End of Fixlog 17:11:44 ====