Prilikom starta računara se pojavljuje "insyde H2O"

Prilikom starta računara se pojavljuje "insyde H2O"

offline
  • Pridružio: 14 Avg 2015
  • Poruke: 25

Dobro veče. Juče sam primetio da mi se prilikom starta računara pojavljuje neko plavo čudo u donjem levom uglu ekrana. Mislim da sam greškom kliknuo na tinypic file. Pošto brzo nestaje, morao sam telefonom da usnimim i skontam šta piše. Za sada nema nikakvih manifestacija. CCleaner i Eset ne pomažu, a ni iz control panela ne mogu da skontam šta je i gde se nalazi. Ipak, moram da vam se obratim. Hvala.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:25-12-2015
Ran by Mesh (administrator) on DIOGEN (10-02-2016 01:21:01)
Running from C:\Users\Mesh\Desktop
Loaded Profiles: Mesh (Available Profiles: Mesh)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: geekstogo.com/forum/topic/335081-frst-t.....scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
(Ellora Assets Corp.) C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe
(Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Nitro PDF Software) C:\Program Files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Windows\SysWOW64\PnkBstrB.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation) C:\Windows\SoftwareDistribution\Download\Install\mpas-fe.exe
(Microsoft Corporation) D:\3a6f70e87ebb2c7955d133\MPSigStub.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472992 2013-03-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCEPServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe [1039248 2013-03-13] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)
HKU\S-1-5-21-4209369173-3384524162-1790046760-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-4209369173-3384524162-1790046760-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-4209369173-3384524162-1790046760-1000\...\MountPoints2: {bd2f6ac5-d73b-11e4-bbf6-047d7b5c334d} - G:\AutoRun.exe
ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => No File
ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => No File
ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => No File
ShellIconOverlayIdentifiers-x32: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => No File
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => No File
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => No File
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 89.216.1.40 89.216.1.50
Tcpip\..\Interfaces\{1C56B0E3-AB8F-4DAB-AF2D-1A64BB81223B}: [DhcpNameServer] 89.216.1.40 89.216.1.50
Tcpip\..\Interfaces\{802476BF-2C34-448B-85E6-8A295CD6DA12}: [DhcpNameServer] 192.168.42.129

Internet Explorer:
==================
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-02-10] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2013-09-13] (Microsoft Corporation)
BHO-x32: Adobe PDF Reader Link Helper -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2011-09-05] (Adobe Systems Incorporated)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-09-05] (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll [2015-09-27] (Oracle Corporation)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-05] (Adobe Systems Incorporated)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2013-09-13] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2015-01-21] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-09-27] (Oracle Corporation)
BHO-x32: Freemake.YoutubeButton -> {e9e8eb35-ff77-455d-b677-91e5e4fc06c2} -> C:\Windows\SysWOW64\mscoree.dll [2010-11-21] (Microsoft Corporation)
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-05] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-05] (Adobe Systems Incorporated)
IE Session Restore: HKU\S-1-5-21-4209369173-3384524162-1790046760-1000 -> is enabled.
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2014-04-01] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

FireFox:
========
FF ProfilePath: C:\Users\Mesh\AppData\Roaming\Mozilla\Firefox\Profiles\y5ffwpys.default-1443258431762
FF Session Restore: -> is enabled.
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_20_0_0_286.dll [2016-02-09] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2013-03-21] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_286.dll [2016-02-09] ()
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2014-04-15] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2014-04-15] (Foxit Corporation)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-09-27] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-09-27] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2013-11-15] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro PDF\Reader 2\npnitromozilla.dll [2012-09-13] ( )
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2011-01-16] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2011-01-16] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll [2011-09-05] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2013-03-21] (Adobe Systems)
FF Plugin HKU\S-1-5-21-4209369173-3384524162-1790046760-1000: @rising.com.cn/nprising -> C:\Program Files (x86)\Rising\RAV\nprising.dll [No File]
FF Plugin HKU\S-1-5-21-4209369173-3384524162-1790046760-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Mesh\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-07-21] (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2013-11-15] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2003-05-15] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppluginrichmediaplayer.dll [2013-03-12] ()
FF Extension: Adblock Plus Pop-up Addon - C:\Users\Mesh\AppData\Roaming\Mozilla\Firefox\Profiles\x2udtauw.Keri\Extensions\adblockpopups@jessehakanen.net.xpi [2012-11-29] [not signed]
FF Extension: Australis - C:\Users\Mesh\AppData\Roaming\Mozilla\Firefox\Profiles\x2udtauw.Keri\Extensions\Australis@SoapyHamHocks.xpi [2012-12-30] [not signed]
FF Extension: Fasterfox Lite - C:\Users\Mesh\AppData\Roaming\Mozilla\Firefox\Profiles\x2udtauw.Keri\Extensions\FasterFox_Lite@BigRedBrent [2012-11-29] [not signed]
FF Extension: Shareaholic - C:\Users\Mesh\AppData\Roaming\Mozilla\Firefox\Profiles\x2udtauw.Keri\Extensions\firefox-extension@shareaholic.com.xpi [2012-11-29] [not signed]
FF Extension: NASA Night Launch - C:\Users\Mesh\AppData\Roaming\Mozilla\Firefox\Profiles\x2udtauw.Keri\Extensions\nasanightlaunch@example.com.xpi [2012-12-30] [not signed]
FF Extension: Feedback - C:\Users\Mesh\AppData\Roaming\Mozilla\Firefox\Profiles\x2udtauw.Keri\Extensions\testpilot@labs.mozilla.com.xpi [2012-10-31] [not signed]
FF Extension: Thumbnail Zoom Plus - C:\Users\Mesh\AppData\Roaming\Mozilla\Firefox\Profiles\x2udtauw.Keri\Extensions\thumbnailZoom@dadler.github.com.xpi [2012-12-08] [not signed]
FF Extension: 8 Ultimo - C:\Users\Mesh\AppData\Roaming\Mozilla\Firefox\Profiles\x2udtauw.Keri\Extensions\{2b6788a0-0ccd-11e1-be50-0800200c9a66} [2012-11-29] [not signed]
FF Extension: MeasureIt - C:\Users\Mesh\AppData\Roaming\Mozilla\Firefox\Profiles\x2udtauw.Keri\Extensions\{75CEEE46-9B64-46f8-94BF-54012DE155F0}.xpi [2012-11-29] [not signed]
FF Extension: FT DeepDark - C:\Users\Mesh\AppData\Roaming\Mozilla\Firefox\Profiles\x2udtauw.Keri\Extensions\{77d2ed30-4cd2-11e0-b8af-0800200c9a66} [2012-11-29] [not signed]
FF Extension: Adblock Plus - C:\Users\Mesh\AppData\Roaming\Mozilla\Firefox\Profiles\x2udtauw.Keri\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-11-29] [not signed]
FF Extension: No Name - C:\Users\Mesh\AppData\Roaming\Mozilla\Firefox\Profiles\ackepv40.default\Extensions\cryptocat@crypto.cat.xpi [2014-06-14] [not signed]
FF Extension: No Name - C:\Users\Mesh\AppData\Roaming\Mozilla\Firefox\Profiles\ackepv40.default\Extensions\firebug@software.joehewitt.com.xpi [2014-06-21] [not signed]
FF Extension: Shareaholic - C:\Users\Mesh\AppData\Roaming\Mozilla\Firefox\Profiles\ackepv40.default\Extensions\firefox-extension@shareaholic.com.xpi [2012-10-23] [not signed]
FF Extension: No Name - C:\Users\Mesh\AppData\Roaming\Mozilla\Firefox\Profiles\ackepv40.default\Extensions\maskingagent@basa.nl.xpi [2013-02-23] [not signed]
FF Extension: NASA Night Launch - C:\Users\Mesh\AppData\Roaming\Mozilla\Firefox\Profiles\ackepv40.default\Extensions\nasanightlaunch@example.com.xpi [2014-02-25] [not signed]
FF Extension: No Name - C:\Users\Mesh\AppData\Roaming\Mozilla\Firefox\Profiles\ackepv40.default\Extensions\nightlaunchcompanion@example.com.xpi [2014-05-28] [not signed]
FF Extension: Thumbnail Zoom Plus - C:\Users\Mesh\AppData\Roaming\Mozilla\Firefox\Profiles\ackepv40.default\Extensions\thumbnailZoom@dadler.github.com.xpi [2014-01-01] [not signed]
FF Extension: Session Manager - C:\Users\Mesh\AppData\Roaming\Mozilla\Firefox\Profiles\ackepv40.default\Extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}.xpi [2014-06-07] [not signed]
FF Extension: No Name - C:\Users\Mesh\AppData\Roaming\Mozilla\Firefox\Profiles\ackepv40.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-06-05] [not signed]
FF Extension: Thumbnail Zoom - C:\Users\Mesh\AppData\Roaming\Mozilla\Firefox\Profiles\ackepv40.default\Extensions\{E10A6337-382E-4FE6-96DE-936ADC34DD04}.xpi [2013-01-13] [not signed]
FF Extension: No Name - C:\Users\Mesh\AppData\Roaming\Mozilla\Firefox\Profiles\y5ffwpys.default-1443258431762\Extensions\jid1-MnnxcxisBPnSXQ@jetpack.xpi [2015-12-23] [not signed]
FF Extension: No Name - C:\Users\Mesh\AppData\Roaming\Mozilla\Firefox\Profiles\y5ffwpys.default-1443258431762\Extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}.xpi [2016-02-09] [not signed]
FF Extension: No Name - C:\Users\Mesh\AppData\Roaming\Mozilla\Firefox\Profiles\y5ffwpys.default-1443258431762\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-01-21] [not signed]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2012-07-24] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [fmdownloader@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com
FF Extension: Freemake Video Downloader Plugin - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com [2014-06-05] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [ytfmdownloader@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com
FF Extension: Freemake Youtube Download Button - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com [2014-06-05] [not signed]

Chrome:
=======
CHR Profile: C:\Users\Mesh\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Mesh\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-12-29]
CHR Extension: (Google Docs) - C:\Users\Mesh\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-12-29]
CHR Extension: (Google Drive) - C:\Users\Mesh\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-12-29]
CHR Extension: (YouTube) - C:\Users\Mesh\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-12-29]
CHR Extension: (Freemake Video Downloader) - C:\Users\Mesh\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpegkgagfojjbcpkihigfmkojdmmimdf [2015-12-29]
CHR Extension: (Google Search) - C:\Users\Mesh\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-12-29]
CHR Extension: (Freemake Youtube Download Button) - C:\Users\Mesh\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehgldbbpchgpcfagfpfjgoomddhccfgh [2015-12-29]
CHR Extension: (Google Sheets) - C:\Users\Mesh\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-12-29]
CHR Extension: (Google Docs Offline) - C:\Users\Mesh\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-01-06]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Mesh\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-12-29]
CHR Extension: (Gmail) - C:\Users\Mesh\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-12-29]
CHR HKLM-x32\...\Chrome\Extension: [bpegkgagfojjbcpkihigfmkojdmmimdf] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx [2012-07-25]
CHR HKLM-x32\...\Chrome\Extension: [ehgldbbpchgpcfagfpfjgoomddhccfgh] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\ChromeYoutubePlugin.crx [2012-09-29]

Opera:
=======
OPR Extension: (Discover Treasure) - C:\Users\Mesh\AppData\Roaming\Opera Software\Opera Stable\Extensions\dlbmnfpclfbclhdohgppgaaknggkmggb [2015-12-28]
OPR Extension: (Fastest Facebook™) - C:\Users\Mesh\AppData\Roaming\Opera Software\Opera Stable\Extensions\fneegbjfomckiofaikblpahnnhhaacel [2015-08-06]
OPR Extension: (Opera Bookmarks Share Portal) - C:\Users\Mesh\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi [2015-08-13]
OPR Extension: (Pixezoom: Pixel-Perfect Zoom) - C:\Users\Mesh\AppData\Roaming\Opera Software\Opera Stable\Extensions\nhkfophdaplidchjldgoallpdeaondlb [2014-06-29]
OPR Extension: (Adblock Plus) - C:\Users\Mesh\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2015-09-30]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [974944 2011-08-09] (ESET)
R2 FreemakeVideoCapture; C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [9216 2014-12-03] (Ellora Assets Corp.) [File not signed]
R2 NitroReaderDriverReadSpool2; C:\Program Files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe [229392 2012-09-13] (Nitro PDF Software)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [66872 2012-08-04] ()
R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [107832 2012-08-04] ()
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 Themes; C:\Windows\system32\themeservice.dll [44544 2014-12-07] (Microsoft Corporation) [File not signed]
S2 UnsignedThemes; C:\Windows\UnsignedThemesSvc.exe [24168 2009-07-13] (The Within Network, LLC)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [202576 2011-08-09] (ESET)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [146432 2011-08-04] (ESET)
S4 epfw; C:\Windows\System32\DRIVERS\epfw.sys [187632 2011-08-04] (ESET)
R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [38288 2011-08-04] (ESET)
S4 epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [62496 2011-08-04] (ESET)
S3 massfilter_hs; C:\Windows\system32\drivers\massfilter_hs.sys [20232 2012-06-20] (HandSet Incorporated)
R2 npf; C:\Windows\System32\drivers\npf.sys [35344 2011-02-11] (CACE Technologies, Inc.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [386680 2014-04-23] (Duplex Secure Ltd.)
U3 akd14xyn; C:\Windows\System32\Drivers\akd14xyn.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero byte File/Folder)
S1 HyperVM; \??\C:\Windows\system32\drivers\hvm.sys [X]
S0 sysmon; system32\DRIVERS\sysmon.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-02-10 01:04 - 2016-02-10 01:04 - 11451510 _____ C:\Users\Mesh\Desktop\drm1.bmp
2016-02-10 01:03 - 2016-02-10 01:03 - 11451510 _____ C:\Users\Mesh\Desktop\drm.bmp
2016-02-10 01:02 - 2016-02-10 01:02 - 00087600 _____ C:\Users\Mesh\AppData\Local\GDIPFONTCACHEV1.DAT
2016-02-10 00:58 - 2016-02-10 00:58 - 05065128 _____ C:\Windows\system32\FNTCACHE.DAT
2016-02-09 02:09 - 2016-02-09 06:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-02-04 06:00 - 2016-02-10 01:04 - 00000844 _____ C:\Users\Mesh\Desktop\CDisplayEx.lnk
2016-02-04 06:00 - 2016-02-09 02:25 - 00000000 ____D C:\Users\Mesh\AppData\Roaming\CDisplayEx
2016-02-04 06:00 - 2016-02-04 06:00 - 07151352 _____ (Progdigy Software S.A.R.L. ) C:\CDisplayExWin64v1.10.29.exe
2016-02-04 06:00 - 2016-02-04 06:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDisplayEx
2016-02-04 06:00 - 2016-02-04 06:00 - 00000000 ____D C:\Program Files\CDisplayEx
2016-02-02 06:02 - 2016-02-02 06:02 - 00001242 _____ C:\Windows\system32\prokofiev-montagues-and-capulets-or-dance-of-the-knights-is-a-1930s-piece-of-classical-music-written-by-russian-composer-sergei-prokofiev-for-his-ballet-romeo-and-juliet-also-adapted-by-him-for-bot.mp3.lnk
2016-01-12 04:49 - 2016-01-12 04:49 - 00555539 _____ C:\Users\Mesh\Desktop\Index Lista za Forum_ Domaće knjige - Mali Pirat.pdf
2016-01-11 06:46 - 2016-01-11 06:46 - 04547878 _____ C:\Users\Mesh\Desktop\NAJNOVIJI SPISAK KNJIGA 301015.pdf
2016-01-11 04:45 - 2016-01-11 05:11 - 00000246 _____ C:\Users\Mesh\Desktop\platforme.txt

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-02-10 01:21 - 2015-12-27 01:39 - 00022253 _____ C:\Users\Mesh\Desktop\FRST.txt
2016-02-10 01:21 - 2015-08-14 12:44 - 00000000 ____D C:\FRST
2016-02-10 01:06 - 2009-07-14 05:45 - 00029168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-02-10 01:06 - 2009-07-14 05:45 - 00029168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-02-10 01:04 - 2014-12-07 22:09 - 00000802 _____ C:\Users\Public\Desktop\Registry First Aid.lnk
2016-02-10 01:03 - 2009-07-14 06:13 - 00782510 _____ C:\Windows\system32\PerfStringBackup.INI
2016-02-10 01:03 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf
2016-02-10 00:58 - 2014-01-21 12:48 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-02-10 00:58 - 2012-07-25 00:24 - 00000000 ____D C:\ProgramData\NVIDIA
2016-02-10 00:58 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-02-10 00:58 - 2009-07-14 04:20 - 00000000 ____D C:\Windows
2016-02-10 00:55 - 2015-05-12 15:30 - 00000000 ____D C:\Users\Mesh\AppData\Roaming\AIMP3
2016-02-10 00:55 - 2012-07-24 22:20 - 00000000 ____D C:\Users\Mesh\AppData\Roaming\uTorrent
2016-02-10 00:52 - 2013-01-24 03:15 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-02-10 00:19 - 2014-01-21 12:48 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-02-09 07:10 - 2012-10-23 15:35 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-02-09 06:48 - 2016-01-06 06:22 - 00000000 ____D C:\Users\Mesh\Desktop\k
2016-02-09 01:53 - 2013-01-24 03:15 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-02-09 01:53 - 2012-11-21 04:17 - 00801984 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-02-09 01:53 - 2012-11-21 04:17 - 00143040 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-02-09 00:52 - 2012-10-01 03:13 - 00003914 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{84005110-EA47-4FCC-A8B1-0CFC2347E861}
2016-02-08 21:44 - 2012-07-24 21:38 - 00000000 ____D C:\Program Files (x86)\The KMPlayer
2016-02-07 01:57 - 2015-09-29 22:26 - 00003554 _____ C:\Users\Mesh\Desktop\linx.txt
2016-02-06 01:41 - 2015-01-07 16:43 - 00002216 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-02-06 01:41 - 2015-01-07 16:43 - 00002187 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-02-04 00:43 - 2014-06-05 20:01 - 00003834 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1378421089
2016-02-04 00:43 - 2013-09-05 23:44 - 00000000 ____D C:\Program Files (x86)\Opera
2016-02-02 01:35 - 2014-01-21 12:48 - 00003894 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-02-02 01:35 - 2014-01-21 12:48 - 00003642 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2016-01-21 22:00 - 2009-07-14 06:08 - 00032544 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2016-01-11 11:25 - 2015-12-27 04:31 - 00000000 ____D C:\Windows\rescache
2016-01-11 04:22 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\AppCompat

==================== Files in the root of some directories =======

2012-08-18 00:58 - 2012-08-18 00:58 - 0893936 _____ (Oracle Corporation) C:\Program Files\chromeinstall-7u5.exe
2013-03-11 19:30 - 2013-03-11 19:30 - 0000132 _____ () C:\Users\Mesh\AppData\Roaming\Adobe GIF Format CS6 Prefs
2012-07-24 23:47 - 2015-12-29 05:24 - 0007597 _____ () C:\Users\Mesh\AppData\Local\Resmon.ResmonCfg

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-01-29 15:54

==================== End of FRST.txt ============================
mycity.rs/must-login.png

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Arrow Korak 1

Otvori Notepad i iskopiraj sljedeći tekst koji se nalazi unutar Kod polja.

CreateRestorePoint:
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
FF Extension: Australis - C:\Users\Mesh\AppData\Roaming\Mozilla\Firefox\Profiles\x2udtauw.Keri\Extensions\Australis@SoapyHamHocks.xpi [2012-12-30] [not signed]
FF Extension: Fasterfox Lite - C:\Users\Mesh\AppData\Roaming\Mozilla\Firefox\Profiles\x2udtauw.Keri\Extensions\FasterFox_Lite@BigRedBrent [2012-11-29] [not signed]
CHR Extension: (Freemake Video Downloader) - C:\Users\Mesh\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpegkgagfojjbcpkihigfmkojdmmimdf [2015-12-29]
CHR Extension: (Freemake Youtube Download Button) - C:\Users\Mesh\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehgldbbpchgpcfagfpfjgoomddhccfgh [2015-12-29]
CHR HKLM-x32\...\Chrome\Extension: [ehgldbbpchgpcfagfpfjgoomddhccfgh] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\ChromeYoutubePlugin.crx [2012-09-29]
OPR Extension: (Discover Treasure) - C:\Users\Mesh\AppData\Roaming\Opera Software\Opera Stable\Extensions\dlbmnfpclfbclhdohgppgaaknggkmggb [2015-12-28]
OPR Extension: (Fastest Facebook™) - C:\Users\Mesh\AppData\Roaming\Opera Software\Opera Stable\Extensions\fneegbjfomckiofaikblpahnnhhaacel [2015-08-06]
OPR Extension: (Opera Bookmarks Share Portal) - C:\Users\Mesh\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi [2015-08-13]
OPR Extension: (Pixezoom: Pixel-Perfect Zoom) - C:\Users\Mesh\AppData\Roaming\Opera Software\Opera Stable\Extensions\nhkfophdaplidchjldgoallpdeaondlb [2014-06-29]
HKU\S-1-5-21-4209369173-3384524162-1790046760-1000\...\MountPoints2: {bd2f6ac5-d73b-11e4-bbf6-047d7b5c334d} - G:\AutoRun.exe
ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => No File
ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => No File
ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => No File
ShellIconOverlayIdentifiers-x32: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => No File
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => No File
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => No File
EmptyTemp:


U okviru Notepad-a klikni na File --> Save As
Fajl nazovi Fixlist i sačuvaj na Desktop
Dvoklikom ponovo pokreni FRST.exe
Klikni na Fix i sačekaj dok program ne završi.
Ukoliko program zatraži restart računara, omogući mu da to nesmetano obavi.
Nakon završetka rada, otvoriće se fixlog.txt, sa sadržajem koji treba da kopiraš u temu.
Takođe, na Desktop-u će se nalaziti (fixlog.txt).




Arrow Korak 2

Preuzmi "Xplode"-ov AdwCleaner i sačuvaj ga na Desktop
Dvoklikom pokreni program.
U EULA prozoru klikni na I agree.
U Options isključi Reset Winsock settings ako je uključen.
Klikni na dugme Scan i sačekaj da se završi skeniranje.
Klikni na dugme Cleaning i pričekaj da program završi.
Program će zatvoriti sve aktivne programe i izbaciti prozor sa tim upozorenjem. Klikni OK kao potvrdu.
Na sljedeća dva prozora koja se otvore (Informations i Restart required ) klikni OK

Računar će se restartovati, a potom otvoriti Notepad (C:\Adwcleaner\AdwCleaner[C1].txt) sa izvještajem.
Sačuvaj taj izvještaj na Desktop i okači ga uz poruku koristeći opciju "Prikači fajl"

offline
  • Pridružio: 14 Avg 2015
  • Poruke: 25

Sad sam uradio oba koraka. I posle prvog i posle drugog restarta to plavo čudo, u donjem desnom uglu, stoji. Vi ćete to već videti iz izveštaja:

Fix result of Farbar Recovery Scan Tool (x64) Version:25-12-2015
Ran by Mesh (2016-02-13 01:46:51) Run:3
Running from C:\Users\Mesh\Desktop
Loaded Profiles: Mesh (Available Profiles: Mesh)
Boot Mode: Normal
==============================================

fixlist content:
*****************
CreateRestorePoint:
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
FF Extension: Australis - C:\Users\Mesh\AppData\Roaming\Mozilla\Firefox\Profiles\x2udtauw.Keri\Extensions\Australis@SoapyHamHocks.xpi [2012-12-30] [not signed]
FF Extension: Fasterfox Lite - C:\Users\Mesh\AppData\Roaming\Mozilla\Firefox\Profiles\x2udtauw.Keri\Extensions\FasterFox_Lite@BigRedBrent [2012-11-29] [not signed]
CHR Extension: (Freemake Video Downloader) - C:\Users\Mesh\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpegkgagfojjbcpkihigfmkojdmmimdf [2015-12-29]
CHR Extension: (Freemake Youtube Download Button) - C:\Users\Mesh\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehgldbbpchgpcfagfpfjgoomddhccfgh [2015-12-29]
CHR HKLM-x32\...\Chrome\Extension: [ehgldbbpchgpcfagfpfjgoomddhccfgh] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\ChromeYoutubePlugin.crx [2012-09-29]
OPR Extension: (Discover Treasure) - C:\Users\Mesh\AppData\Roaming\Opera Software\Opera Stable\Extensions\dlbmnfpclfbclhdohgppgaaknggkmggb [2015-12-28]
OPR Extension: (Fastest Facebook™) - C:\Users\Mesh\AppData\Roaming\Opera Software\Opera Stable\Extensions\fneegbjfomckiofaikblpahnnhhaacel [2015-08-06]
OPR Extension: (Opera Bookmarks Share Portal) - C:\Users\Mesh\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi [2015-08-13]
OPR Extension: (Pixezoom: Pixel-Perfect Zoom) - C:\Users\Mesh\AppData\Roaming\Opera Software\Opera Stable\Extensions\nhkfophdaplidchjldgoallpdeaondlb [2014-06-29]
HKU\S-1-5-21-4209369173-3384524162-1790046760-1000\...\MountPoints2: {bd2f6ac5-d73b-11e4-bbf6-047d7b5c334d} - G:\AutoRun.exe
ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => No File
ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => No File
ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => No File
ShellIconOverlayIdentifiers-x32: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => No File
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => No File
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => No File
EmptyTemp:
*****************

Restore point was successfully created.
C:\Windows\system32\GroupPolicy\Machine => moved successfully
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
"HKLM\SOFTWARE\Policies\Google" => key removed successfully
C:\Users\Mesh\AppData\Roaming\Mozilla\Firefox\Profiles\x2udtauw.Keri\Extensions\Australis@SoapyHamHocks.xpi => moved successfully
C:\Users\Mesh\AppData\Roaming\Mozilla\Firefox\Profiles\x2udtauw.Keri\Extensions\FasterFox_Lite@BigRedBrent => moved successfully
C:\Users\Mesh\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpegkgagfojjbcpkihigfmkojdmmimdf => moved successfully
C:\Users\Mesh\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehgldbbpchgpcfagfpfjgoomddhccfgh => moved successfully
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ehgldbbpchgpcfagfpfjgoomddhccfgh" => key removed successfully
C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\ChromeYoutubePlugin.crx => moved successfully
C:\Users\Mesh\AppData\Roaming\Opera Software\Opera Stable\Extensions\dlbmnfpclfbclhdohgppgaaknggkmggb => moved successfully
C:\Users\Mesh\AppData\Roaming\Opera Software\Opera Stable\Extensions\fneegbjfomckiofaikblpahnnhhaacel => moved successfully
C:\Users\Mesh\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi => moved successfully
C:\Users\Mesh\AppData\Roaming\Opera Software\Opera Stable\Extensions\nhkfophdaplidchjldgoallpdeaondlb => moved successfully
"HKU\S-1-5-21-4209369173-3384524162-1790046760-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bd2f6ac5-d73b-11e4-bbf6-047d7b5c334d}" => key removed successfully
HKCR\CLSID\{bd2f6ac5-d73b-11e4-bbf6-047d7b5c334d} => key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtPending" => key removed successfully
HKCR\CLSID\{056D528D-CE28-4194-9BA3-BA2E9197FF8C} => key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtSynced" => key removed successfully
HKCR\CLSID\{05B38830-F4E9-4329-978B-1DD28605D202} => key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtSyncing" => key removed successfully
HKCR\CLSID\{0596C850-7BDD-4C9D-AFDF-873BE6890637} => key not found.
"HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtPending" => key removed successfully
HKCR\Wow6432Node\CLSID\{056D528D-CE28-4194-9BA3-BA2E9197FF8C} => key not found.
"HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtSynced" => key removed successfully
HKCR\Wow6432Node\CLSID\{05B38830-F4E9-4329-978B-1DD28605D202} => key not found.
"HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtSyncing" => key removed successfully
HKCR\Wow6432Node\CLSID\{0596C850-7BDD-4C9D-AFDF-873BE6890637} => key not found.
EmptyTemp: => 442.8 MB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 01:48:34 ====

mycity.rs/must-login.png

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Kakvo je sada stanje?

offline
  • Pridružio: 14 Avg 2015
  • Poruke: 25

Nemam internet, pa ne mogu na vreme da reagujem. Sada je sve ok. Velika hvala.

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Obavićemo još jednu provjeru.

Preuzmi Malwarebytes Anti-Rootkit (MBAR) sa sledeceg linka i sacuvaj ga na Desktop.

Dvoklikom pokreni MBAR () na ikonicu programa:
- Klikni OK na sledecem prozoru da bi dozvolio raspakivanje u zaseban mbar folder na desktop-u;
- mbar.exe ce biti startovan. Na nekim sistemima to moze da potraje nekoliko dodatnih sekundi, te pricekati pokretanje.;
- U uvodnom prozoru klikni dugme Next ukoliko si saglasan;



• Na 'Update Database' prozoru klik na dugme Update da bi preuzeo sveze definicije. Kada se ispise poruka 'Success: Database was successfully updated' klik na dugme Next;
• Pod sekcijom 'Scan Targets' proveri da su sve opcije stiklirane, te klikni na dugme Scan;

Obavestenje: sa nekim infekcijama moze se desiti da se prikaze neka od sledecih poruka:
- 'Could not load protection driver' => u tom slucaju klikni OK.
- 'Could not load DDA driver' => klikni Yes na to obavestenje da bi dozvolio ucitavanje nakon restarta. Dozvoli restart i nastavi sa ostatkom instrukcija posle restarta.





>> Ukoliko malware nije detektovan, klik na Exit dugme da zatvoris program. U sledecu poruku postavi mbar-log-year-month-day (sat-minuti-sekundi).txt i system-log.txt izveštaje.

>> Ukoliko su infekcija/e pronadjene, proveriti da li je obelezena opcija 'Create Restore Point' i klikni na dugme Cleanup! da bi uklonili pretnje.
- Procedura uklanjanje malware-a (scheduled) ce biti zakazana po restartu, bice prikazano obavestenje u pop-up prozoru. Klikni dugme Yes i sistem bi trebao da se restartuje i da zavrsi proceduru ciscenja.



Obavestenje! samo ukoliko je RootKit detektovan: - postaraj se da pokrenes fixdamage.exe alat koji se nalazi u mbar folderu, \Plugins\fixdamage.exe:
- Dvoklikom pokreni fixdamage, u crnom prozoru koji se otvori (command prompt) ukucaj Y (Y stoji za Yes) da bi nastavio izvrsenje, pricekati da alat odradi sve popravke ...
- Kada vidis poruku 'press any key to exit' popravka je kompletirana. Pritisnuti bilo koju tipku na tastaturi da bi se prozor zatvorio. Restartovati sistem.





Sledeci izvestaji ce biti formirani u mbar folderu.
1. mbar-log-year-month-day (hour-minute-second).txt
2. system-log.txt

Iskopiraj sadrzaj mbar log-a u poruku a system log okaci uz poruku koristeci opciju Prikači fajl.

offline
  • Pridružio: 14 Avg 2015
  • Poruke: 25

Izvinjavam se; sinoć, verovatno zbog brze tranzicije, nisam video "to plavo." Posle nekoliko restarta računara, svaki put pokazuje "insyde H2O." Sada sam uradio scan i javlja da nema ništa. Šta dalje?

mycity.rs/must-login.png

mycity.rs/must-login.png

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Sistem ti je čist, a to što ti pokazuje prije pokretanja je naziv BIOSa za tvoj laptop.


Arrow

Sledeća procedura će implementirati završno čišćenje.

Arrow Preuzmi "Xplode"-ov DelFix alat i snimi ga na Desktop.
Dvoklikom pokreni alat i štikliraj kućice ispred sledećih opcija;

Remove disinfection tools
Create registry backup
Purge System Restore


Klikni na dugme Run i pričekaj trenutak dok alat ne završi svoj rad.
Od ovog trenutka, svi korišćeni alati u ovoj temi bi trebali biti obrisani.
Alat će takođe formirati izveštaj za tebe. (C:\DelFix.txt)

Alat će snimiti i zdravo stanje registy-ja i napraviti backup koristeci integrisan program "ERUNT" u %windir%\ERUNT\DelFix
Alat briše stare system restore tačke i pravi novu, svežu tačku nakon čišćenja.

offline
  • Pridružio: 14 Avg 2015
  • Poruke: 25

U redu. Sada znam je sve ok. Hvala još jedared.

Ko je trenutno na forumu
 

Ukupno su 1094 korisnika na forumu :: 52 registrovanih, 7 sakrivenih i 1035 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 357magnum, _Rade, A.R.Chafee.Jr., Apok, bankulen, bojank, ccoogg123, cincarin, Denaya, Dimitrije Paunovic, dragoljub11987, drimer, Georgius, ginjica, hyla, ILGromovnik, Karla, Komentator, Krvava Devetka, ksyyaj, Kubovac, kybonacci, ladro, ljuba, Lošmi, Luka Blažević, Marko Marković, mercedesamg, Mi lao shu, mikrimaus, milutin134, Mixelotti, nebidrag, nemkea71, nenad81, NoOneEver Dreams, nuke92, ostoja, panzerwaffe, rasok, Ripanjac, RJ, royst33, sasa87, slonic_tonic, stalja, Sumadija34, vathra, voja64, wolf431, wolverined4, ZetaMan