Problem sa ADWARE/CrossRider.pg

1

Problem sa ADWARE/CrossRider.pg

offline
  • Pridružio: 18 Okt 2012
  • Poruke: 57

Evo sta mi Avira non stop prijavljuje, molim za pomoc.





offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Da bismo mogli da ti pomognemo potrebno je da ispratiš uputstvo za otvaranje teme i postaviš tražene izvještaje. Smile

http://www.mycity.rs/Ambulanta/Kako-otvoriti-temu-u-Ambulanti.html

offline
  • Pridružio: 18 Okt 2012
  • Poruke: 57

Dugo nisam koristio net i tek danas sam apdejtovao Aviru, problem se javio posle instalacije ovog programa download.cnet.com/Free-MKV-to-AVI-Converter/3000-2194_4-75984422.html mada sam pre toga instalirao u mozili converter koj mi je preporucio downloadhelper.net/ skidao sam neki klip koj nije uspeo da konvertuje pa sam zato potrazio program na download.cnet.com.

Skinuo sam free Malwarebytes Anti-Malware pustio scan i naso mi je dosta toga za izbaciti sto sami ucinio ali ove tri stavke i dalje su tu.
Nemamam nekih problema vec mi povremeno avira prijavi ta tri virusa i iskoce mi 3 prozorcica kao sa slike.

Evo reporta od FRST64
mycity.rs/must-login.png

mycity.rs/must-login.png

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-09-2014
Ran by Gile (administrator) on GILE-PC on 18-09-2014 01:52:17
Running from C:\Users\Gile\Desktop
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 9
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: geekstogo.com/forum/topic/335081-frst-t.....scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(SANDBOXIE L.T.D) C:\Program Files\Sandboxie\SbieSvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ACD Systems International Inc.) C:\Program Files (x86)\Common Files\ACD Systems\EN\DevDetect.exe
(MediaGet LLC) C:\Users\Gile\AppData\Local\MediaGet2\mediaget.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(MPC-HC Team) C:\Program Files (x86)\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11775592 2011-02-23] (Realtek Semiconductor)
HKLM-x32\...\Run: [NPSStartup] => [X]
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [751184 2014-09-17] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [164656 2014-08-27] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-1181290801-2996569609-2719667674-1000\...\Run: [Device Detector] => DevDetect.exe -autorun
HKU\S-1-5-21-1181290801-2996569609-2719667674-1000\...\Run: [MediaGet2] => C:\Users\Gile\AppData\Local\MediaGet2\mediaget.exe [13091304 2014-09-17] (MediaGet LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AML Device Install.lnk
ShortcutTarget: AML Device Install.lnk -> C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x2896551EACD2CF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = msn.com/?ocid=iehp
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - {AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} URL = daemon-search.com/search/web?q={searchTerms}
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
DPF: HKLM-x32 {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} appldnld.apple.com.edgesuite.net/content.in.....plugin.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 01 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [326144] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Tcpip\Parameters: [DhcpNameServer] 89.216.1.40 89.216.1.50

FireFox:
========
FF ProfilePath: C:\Users\Gile\AppData\Roaming\Mozilla\Firefox\Profiles\hffbw6h2.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

Chrome:
=======

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-09-17] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-09-17] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [160048 2014-08-27] (Avira Operations GmbH & Co. KG)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [123664 2012-12-16] (SANDBOXIE L.T.D)
S3 vsmon; C:\Windows\SysWOW64\ZoneLabs\vsmon.exe [2435592 2010-11-16] (Check Point Software Technologies LTD)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2013-11-03] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-09-17] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-09-17] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-09-17] (Avira Operations GmbH & Co. KG)
R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-03-29] (DT Soft Ltd)
S3 FsUsbExDisk; C:\Windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-02-05] () [File not signed]
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2013-11-03] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-09-18] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [202632 2012-12-16] (SANDBOXIE L.T.D)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S1 StarOpen; C:\Windows\SysWow64\Drivers\StarOpen.sys [5632 2006-07-24] () [File not signed]
R1 Vsdatant; C:\Windows\System32\DRIVERS\vsdatant.sys [458840 2010-05-15] (Check Point Software Technologies LTD)
S3 dgderdrv; System32\drivers\dgderdrv.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-18 01:52 - 2014-09-18 01:52 - 00009749 _____ () C:\Users\Gile\Desktop\FRST.txt
2014-09-18 01:51 - 2014-09-18 01:52 - 00000000 ____D () C:\FRST
2014-09-18 01:51 - 2014-09-18 01:50 - 02105856 _____ (Farbar) C:\Users\Gile\Desktop\FRST64.exe
2014-09-18 01:50 - 2014-09-18 01:50 - 02105856 _____ (Farbar) C:\Users\Gile\Downloads\FRST64.exe
2014-09-18 00:27 - 2014-09-18 00:27 - 00000056 _____ () C:\Windows\setupact.log
2014-09-18 00:27 - 2014-09-18 00:27 - 00000000 _____ () C:\Windows\setuperr.log
2014-09-18 00:22 - 2014-09-18 00:22 - 00000740 _____ () C:\Windows\PFRO.log
2014-09-17 23:00 - 2014-09-17 23:01 - 00000000 ____D () C:\Users\Gile\AppData\Roaming\Mozilla
2014-09-17 23:00 - 2014-09-17 23:00 - 00001163 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-09-17 23:00 - 2014-09-17 23:00 - 00001151 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-09-17 23:00 - 2014-09-17 23:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-09-17 23:00 - 2014-09-17 23:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-09-17 22:53 - 2014-09-17 22:59 - 00244056 _____ () C:\Users\Gile\Downloads\Firefox Setup Stub 32.0.1.exe
2014-09-17 22:11 - 2014-09-18 00:59 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-17 22:11 - 2014-09-17 22:11 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-09-17 22:11 - 2014-09-17 22:11 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-17 22:11 - 2014-09-17 22:11 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-09-17 22:11 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-09-17 22:11 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-09-17 22:11 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-09-17 22:09 - 2014-09-17 22:11 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Gile\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-17 20:14 - 2014-09-17 20:13 - 00042040 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-09-17 20:13 - 2014-09-17 22:35 - 00000000 ____D () C:\ProgramData\Package Cache
2014-09-17 20:13 - 2014-09-17 22:34 - 00001133 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-09-17 20:13 - 2014-09-17 20:13 - 00000000 ____D () C:\Users\Gile\AppData\Roaming\Avira
2014-09-17 20:12 - 2014-09-17 22:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-09-17 20:12 - 2014-09-17 22:34 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-09-17 20:12 - 2014-09-17 20:13 - 00000000 ____D () C:\ProgramData\Avira
2014-09-17 20:12 - 2014-09-17 20:12 - 00001994 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk
2014-09-17 20:12 - 2014-09-17 19:57 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-09-17 20:12 - 2014-09-17 19:57 - 00117712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-09-17 20:12 - 2014-09-17 19:57 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2014-09-17 19:56 - 2014-09-17 19:56 - 00000000 ____D () C:\Users\Gile\Desktop\Old Firefox Data
2014-09-17 19:46 - 2014-09-17 20:08 - 00000000 ____D () C:\Users\Gile\AppData\Roaming\Convert Audio Free
2014-09-17 19:45 - 2014-09-17 19:45 - 00004324 _____ () C:\Windows\System32\Tasks\Installer_shopperpro
2014-09-17 19:45 - 2014-09-17 19:45 - 00004314 _____ () C:\Windows\System32\Tasks\Installer_geforce
2014-09-17 19:45 - 2014-09-17 19:45 - 00004306 _____ () C:\Windows\System32\Tasks\Installer_sense
2014-09-17 19:43 - 2014-09-17 19:43 - 00000000 ____D () C:\Users\Gile\AppData\Local\CrashRpt
2014-09-17 19:40 - 2014-09-17 22:26 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2014-09-17 19:40 - 2014-09-17 19:40 - 00000000 ____D () C:\Users\Gile\AppData\Local\globalUpdate
2014-09-16 21:31 - 2014-09-16 21:31 - 00000000 ____D () C:\Users\Public\Documents\Sports Interactive
2014-09-16 21:31 - 2014-09-16 21:31 - 00000000 ____D () C:\Users\Gile\Documents\Sports Interactive
2014-09-16 21:31 - 2014-09-16 21:31 - 00000000 ____D () C:\Users\Gile\AppData\Local\Sports Interactive
2014-09-16 21:28 - 2014-09-16 21:28 - 00001677 _____ () C:\Users\Gile\Desktop\fm - Shortcut.lnk
2014-09-16 21:14 - 2014-09-16 21:17 - 00000000 ____D () C:\Program Files (x86)\FM 2014
2014-09-16 12:00 - 2014-09-16 12:00 - 00009912 ____N () C:\bootsqm.dat
2014-09-09 14:44 - 2014-09-17 17:10 - 00000000 ____D () C:\Users\Gile\Desktop\New folder
2014-08-26 18:20 - 2014-09-18 00:29 - 00000434 _____ () C:\Windows\system32\Drivers\etc\hosts.ics

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-18 01:52 - 2014-09-18 01:52 - 00009749 _____ () C:\Users\Gile\Desktop\FRST.txt
2014-09-18 01:52 - 2014-09-18 01:51 - 00000000 ____D () C:\FRST
2014-09-18 01:50 - 2014-09-18 01:51 - 02105856 _____ (Farbar) C:\Users\Gile\Desktop\FRST64.exe
2014-09-18 01:50 - 2014-09-18 01:50 - 02105856 _____ (Farbar) C:\Users\Gile\Downloads\FRST64.exe
2014-09-18 01:45 - 2012-04-06 18:50 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-18 01:11 - 2011-02-24 02:02 - 00000000 ____D () C:\Users\Gile\AppData\Roaming\Media Player Classic
2014-09-18 00:59 - 2014-09-17 22:11 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-18 00:38 - 2009-07-14 06:45 - 00017136 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-18 00:38 - 2009-07-14 06:45 - 00017136 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-18 00:33 - 2012-10-17 22:38 - 01420414 _____ () C:\Windows\WindowsUpdate.log
2014-09-18 00:33 - 2009-07-14 07:13 - 00726316 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-18 00:29 - 2014-08-26 18:20 - 00000434 _____ () C:\Windows\system32\Drivers\etc\hosts.ics
2014-09-18 00:27 - 2014-09-18 00:27 - 00000056 _____ () C:\Windows\setupact.log
2014-09-18 00:27 - 2014-09-18 00:27 - 00000000 _____ () C:\Windows\setuperr.log
2014-09-18 00:27 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-18 00:22 - 2014-09-18 00:22 - 00000740 _____ () C:\Windows\PFRO.log
2014-09-17 23:01 - 2014-09-17 23:00 - 00000000 ____D () C:\Users\Gile\AppData\Roaming\Mozilla
2014-09-17 23:01 - 2011-02-23 22:52 - 00000000 ____D () C:\Users\Gile\AppData\Local\Mozilla
2014-09-17 23:00 - 2014-09-17 23:00 - 00001163 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-09-17 23:00 - 2014-09-17 23:00 - 00001151 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-09-17 23:00 - 2014-09-17 23:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-09-17 23:00 - 2014-09-17 23:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-09-17 22:59 - 2014-09-17 22:53 - 00244056 _____ () C:\Users\Gile\Downloads\Firefox Setup Stub 32.0.1.exe
2014-09-17 22:43 - 2011-03-17 23:26 - 00000000 ____D () C:\Users\Gile\AppData\Roaming\DAEMON Tools Lite
2014-09-17 22:43 - 2011-02-24 18:29 - 00000000 ____D () C:\Users\Gile\AppData\Roaming\Winamp
2014-09-17 22:43 - 2011-02-24 01:12 - 00000000 ____D () C:\Users\Gile\AppData\Roaming\uTorrent
2014-09-17 22:35 - 2014-09-17 20:13 - 00000000 ____D () C:\ProgramData\Package Cache
2014-09-17 22:34 - 2014-09-17 20:13 - 00001133 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-09-17 22:34 - 2014-09-17 20:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-09-17 22:34 - 2014-09-17 20:12 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-09-17 22:27 - 2009-07-14 07:37 - 00000000 ____D () C:\Windows\DigitalLocker
2014-09-17 22:26 - 2014-09-17 19:40 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2014-09-17 22:11 - 2014-09-17 22:11 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-09-17 22:11 - 2014-09-17 22:11 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-17 22:11 - 2014-09-17 22:11 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-09-17 22:11 - 2014-09-17 22:09 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Gile\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-17 20:13 - 2014-09-17 20:14 - 00042040 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-09-17 20:13 - 2014-09-17 20:13 - 00000000 ____D () C:\Users\Gile\AppData\Roaming\Avira
2014-09-17 20:13 - 2014-09-17 20:12 - 00000000 ____D () C:\ProgramData\Avira
2014-09-17 20:12 - 2014-09-17 20:12 - 00001994 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk
2014-09-17 20:08 - 2014-09-17 19:46 - 00000000 ____D () C:\Users\Gile\AppData\Roaming\Convert Audio Free
2014-09-17 19:57 - 2014-09-17 20:12 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-09-17 19:57 - 2014-09-17 20:12 - 00117712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-09-17 19:57 - 2014-09-17 20:12 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2014-09-17 19:56 - 2014-09-17 19:56 - 00000000 ____D () C:\Users\Gile\Desktop\Old Firefox Data
2014-09-17 19:45 - 2014-09-17 19:45 - 00004324 _____ () C:\Windows\System32\Tasks\Installer_shopperpro
2014-09-17 19:45 - 2014-09-17 19:45 - 00004314 _____ () C:\Windows\System32\Tasks\Installer_geforce
2014-09-17 19:45 - 2014-09-17 19:45 - 00004306 _____ () C:\Windows\System32\Tasks\Installer_sense
2014-09-17 19:43 - 2014-09-17 19:43 - 00000000 ____D () C:\Users\Gile\AppData\Local\CrashRpt
2014-09-17 19:40 - 2014-09-17 19:40 - 00000000 ____D () C:\Users\Gile\AppData\Local\globalUpdate
2014-09-17 19:40 - 2012-01-15 17:28 - 00000000 ____D () C:\Program Files (x86)\Google
2014-09-17 17:10 - 2014-09-09 14:44 - 00000000 ____D () C:\Users\Gile\Desktop\New folder
2014-09-17 14:54 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-09-17 14:27 - 2011-11-04 16:30 - 00000000 ____D () C:\Users\Gile\AppData\Roaming\Media Get LLC
2014-09-17 14:27 - 2011-11-04 16:30 - 00000000 ____D () C:\ProgramData\Media Get LLC
2014-09-17 04:02 - 2011-02-24 15:57 - 00000000 ____D () C:\Users\Gile\AppData\Roaming\Skype
2014-09-17 00:25 - 2011-11-03 19:09 - 00000000 ____D () C:\Users\Gile\AppData\Local\MediaGet2
2014-09-16 21:31 - 2014-09-16 21:31 - 00000000 ____D () C:\Users\Public\Documents\Sports Interactive
2014-09-16 21:31 - 2014-09-16 21:31 - 00000000 ____D () C:\Users\Gile\Documents\Sports Interactive
2014-09-16 21:31 - 2014-09-16 21:31 - 00000000 ____D () C:\Users\Gile\AppData\Local\Sports Interactive
2014-09-16 21:28 - 2014-09-16 21:28 - 00001677 _____ () C:\Users\Gile\Desktop\fm - Shortcut.lnk
2014-09-16 21:17 - 2014-09-16 21:14 - 00000000 ____D () C:\Program Files (x86)\FM 2014
2014-09-16 12:00 - 2014-09-16 12:00 - 00009912 ____N () C:\bootsqm.dat
2014-09-16 10:45 - 2012-04-06 18:50 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-16 10:45 - 2012-04-06 18:50 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-09-16 10:45 - 2012-02-16 16:27 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-09-15 02:57 - 2011-02-24 18:21 - 00151552 _____ () C:\Users\Gile\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-09-14 23:23 - 2012-10-18 23:10 - 00000000 ___HD () C:\Users\Gile\Desktop\[Originals]
2014-08-26 19:48 - 2011-02-25 16:15 - 00000000 ____D () C:\ProgramData\TEMP
2014-08-26 17:16 - 2012-08-01 20:06 - 00057176 _____ () C:\Users\Gile\AppData\Local\GDIPFONTCACHEV1.DAT
2014-08-26 14:39 - 2009-07-14 06:45 - 00273584 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-25 00:57 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-08-25 00:55 - 2011-02-23 23:55 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information

Some content of TEMP:
====================
C:\Users\Gile\AppData\Local\Temp\avgnt.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-09-09 01:22

==================== End Of Log ============================

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Arrow Korak 1

Otvori Notepad i iskopiraj sljedeći tekst koji se nalazi unutar Kod polja.

CloseProcesses:
(MediaGet LLC) C:\Users\Gile\AppData\Local\MediaGet2\mediaget.exe
HKU\S-1-5-21-1181290801-2996569609-2719667674-1000\...\Run: [MediaGet2] => C:\Users\Gile\AppData\Local\MediaGet2\mediaget.exe [13091304 2014-09-17] (MediaGet LLC)
SearchScopes: HKCU - {AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} URL = http://www.daemon-search.com/search/web?q={searchTerms}
Task: {39336EF7-64D4-4B2C-B8C8-7190678988B1} - System32\Tasks\Installer_shopperpro => C:\Users\Gile\AppData\Local\Installer\Installshopperpro_6345\DC1_Offer_2.exe [2014-09-17] () <==== ATTENTION
Task: {62505A9D-4729-4330-B6E5-15AC85AD68CF} - System32\Tasks\Installer_geforce => C:\Users\Gile\AppData\Local\Installer\Installgeforce_19114\DC1_Offer_2.exe [2014-09-17] () <==== ATTENTION
Task: {D2826AE8-019F-4251-AA2B-DC0B54999B2B} - System32\Tasks\Installer_sense => C:\Users\Gile\AppData\Local\Installer\Installsense_23806\DC1_Offer_2.exe [2014-09-17] () <==== ATTENTION
C:\Windows\System32\Tasks\Installer_sense
C:\Windows\System32\Tasks\Installer_geforce
C:\Windows\System32\Tasks\Installer_shopperpro
C:\Users\Gile\AppData\Local\Installer\Installshopperpro_6345
C:\Users\Gile\AppData\Local\Installer\Installgeforce_19114
C:\Users\Gile\AppData\Local\Installer\Installsense_23806
C:\Program Files (x86)\globalUpdate
C:\Users\Gile\AppData\Local\globalUpdate
C:\Users\Gile\AppData\Local\MediaGet2
EmptyTemp:


U okviru Notepad-a klikni na File --> Save As
Fajl nazovi Fixlist i sačuvaj na Desktop
Dvoklikom ponovo pokreni FRST.exe
Klikni na Fix i sačekaj dok program ne završi.
Ukoliko program zatraži restart računara, omogući mu da to nesmetano obavi.
Nakon završetka rada, otvoriće se Notepad, sa sadržajem koji treba da kopiraš u temu.
Takođe, na Desktop-u će se nalaziti (fixlog.txt). Potrebno je da sadržaj fixlog.txt kopiraš na forum




Arrow Korak 2

Preuzmi "Xplode"-ov AdwCleaner i sačuvaj ga na Desktop
Dvoklikom pokreni program.
u EULA prozoru klikni na I agree.
Klikni na dugme Scan i sačekaj da se završi skeniranje.
Klikni na dugme Clean i pričekaj da program završi.
Program će zatvoriti sve aktivne programe i izbaciti prozor sa tim upozorenjem. Klikni OK kao potvrdu.
Na sljedeća dva prozora koja se otvore (Informations i Restart required ) klikni OK

Računar će se restartovati, a potom otvoriti Notepad (C:\AdwCleaner[S0].txt) sa izvještajem.
Sačuvaj taj izvještaj na Desktop i okači ga uz poruku koristeći opciju "Prikači fajl"

Napomena: Izvještaj ce takođe biti sačuvan na C:\Adwcleaner\AdwCleaner[S0].txt

offline
  • Pridružio: 18 Okt 2012
  • Poruke: 57

Nakon završetka rada, otvoriće se Notepad, sa sadržajem koji treba da kopiraš u temu.
Nakon restartovanja nije se otvorio notepad
Evo ga (fixlog.txt) i prikacen (C:\AdwCleaner[S0].txt)

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 12-09-2014
Ran by Gile at 2014-09-18 15:18:39 Run:1
Running from C:\Users\Gile\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
CloseProcesses:
(MediaGet LLC) C:\Users\Gile\AppData\Local\MediaGet2\mediaget.exe
HKU\S-1-5-21-1181290801-2996569609-2719667674-1000\...\Run: [MediaGet2] => C:\Users\Gile\AppData\Local\MediaGet2\mediaget.exe [13091304 2014-09-17] (MediaGet LLC)
SearchScopes: HKCU - {AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} URL = daemon-search.com/search/web?q={searchTerms}
Task: {39336EF7-64D4-4B2C-B8C8-7190678988B1} - System32\Tasks\Installer_shopperpro => C:\Users\Gile\AppData\Local\Installer\Installshopperpro_6345\DC1_Offer_2.exe [2014-09-17] () <==== ATTENTION
Task: {62505A9D-4729-4330-B6E5-15AC85AD68CF} - System32\Tasks\Installer_geforce => C:\Users\Gile\AppData\Local\Installer\Installgeforce_19114\DC1_Offer_2.exe [2014-09-17] () <==== ATTENTION
Task: {D2826AE8-019F-4251-AA2B-DC0B54999B2B} - System32\Tasks\Installer_sense => C:\Users\Gile\AppData\Local\Installer\Installsense_23806\DC1_Offer_2.exe [2014-09-17] () <==== ATTENTION
C:\Windows\System32\Tasks\Installer_sense
C:\Windows\System32\Tasks\Installer_geforce
C:\Windows\System32\Tasks\Installer_shopperpro
C:\Users\Gile\AppData\Local\Installer\Installshopperpro_6345
C:\Users\Gile\AppData\Local\Installer\Installgeforce_19114
C:\Users\Gile\AppData\Local\Installer\Installsense_23806
C:\Program Files (x86)\globalUpdate
C:\Users\Gile\AppData\Local\globalUpdate
C:\Users\Gile\AppData\Local\MediaGet2
EmptyTemp:
*****************

Processes closed successfully.
C:\Users\Gile\AppData\Local\MediaGet2\mediaget.exe => No running process found
HKU\S-1-5-21-1181290801-2996569609-2719667674-1000\Software\Microsoft\Windows\CurrentVersion\Run\\MediaGet2 => value deleted successfully.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}" => Key deleted successfully.
"HKCR\CLSID\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}" => Key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{39336EF7-64D4-4B2C-B8C8-7190678988B1}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{39336EF7-64D4-4B2C-B8C8-7190678988B1}" => Key deleted successfully.
C:\Windows\System32\Tasks\Installer_shopperpro => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Installer_shopperpro" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{62505A9D-4729-4330-B6E5-15AC85AD68CF}" => Key not found.
C:\Windows\System32\Tasks\Installer_geforce not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Installer_geforce" => Key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D2826AE8-019F-4251-AA2B-DC0B54999B2B}" => Key not found.
C:\Windows\System32\Tasks\Installer_sense not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Installer_sense" => Key not found.
"C:\Windows\System32\Tasks\Installer_sense" => File/Directory not found.
"C:\Windows\System32\Tasks\Installer_geforce" => File/Directory not found.
"C:\Windows\System32\Tasks\Installer_shopperpro" => File/Directory not found.
C:\Users\Gile\AppData\Local\Installer\Installshopperpro_6345 => Moved successfully.
C:\Users\Gile\AppData\Local\Installer\Installgeforce_19114 => Moved successfully.
C:\Users\Gile\AppData\Local\Installer\Installsense_23806 => Moved successfully.
C:\Program Files (x86)\globalUpdate => Moved successfully.
C:\Users\Gile\AppData\Local\globalUpdate => Moved successfully.
C:\Users\Gile\AppData\Local\MediaGet2 => Moved successfully.
EmptyTemp: => Removed 684.3 MB temporary data.


The system needed a reboot.

==== End of Fixlog ====

mycity.rs/must-login.png

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Kakvo je sada stanje?


Preuzmite program GMER sa donjeg linka na Desktop:


GMER download
Kliknite dati link;
Kada se otvori dijalog za izbor lokacije na kojoj treba sačuvati file, odaberite Desktop i kliknite Save.



Dvoklikom pokrenite GMER.
Sačekajte da se završi uvodno skeniranje - ukoliko se pojavi bilo kakav upit, kliknite No;

kliknite Scan i sačekajte da skeniranje bude završeno;

kliknite Save ... - izveštaj sačuvajte na Desktop (pod nazivom Gmer1);

kliknite desnim tasterom u prozor programa Gmer i odaberite Options > 3rd party - kliknite Scan;

po završetku skeniranja kliknite Save ... - izveštaj sačuvajte na Desktop (pod nazivom Gmer2);

kliknite taster >>> i odaberite Autostart karticu;

po završetku kratkotrajnog skeniranja, kliknite Copy;

otvorite Notepad i u njega postavite kopirani tekst - izveštaj sačuvajte na Desktop (pod nazivom Gmer3);


Slikoviti prikaz postupka

Priložite sva tri izveštaja uz poruku korišćenjem opcije Prikači fajl.

offline
  • Pridružio: 18 Okt 2012
  • Poruke: 57

Napisano: 18 Sep 2014 18:44

Od kako sam ovo uradio vise mi ni jedno avira nije izbacila prijave za virus.
Hvala da nije vas i ovog foruma...
Ziveli
Sad cu i ovo ostalo da uradim, mislim da mi nije usao sa nekim od onih konvertora mislim da je tu bio vec neko vreme tj da su tu bili posto je 3 komada prijavila avira i kad sam je apdejtovao ona krece da prijavljuje a mislim da mi je uletelo preko getmedia posto koristim torent pa ako ima neka zastita kako bezbdno da skidam sa torentom bio bi zahvalan.

Dopuna: 18 Sep 2014 19:04

Evo sva 3 izvestaja
mycity.rs/must-login.png

mycity.rs/must-login.png

mycity.rs/must-login.png

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Čist si.


Arrow

Sledeća procedura će implementirati završno čišćenje.

Arrow Preuzmi "Xplode"-ov DelFix alat i snimi ga na Desktop.
Dvoklikom pokreni alat i štikliraj kućice ispred sledećih opcija;

Remove disinfection tools
Create registry backup
Purge System Restore


Klikni na dugme Run i pričekaj trenutak dok alat ne završi svoj rad.
Od ovog trenutka, svi korišćeni alati u ovoj temi bi trebali biti obrisani.
Alat će takođe formirati izveštaj za tebe. (C:\DelFix.txt)

Alat će snimiti i zdravo stanje registy-ja i napraviti backup koristeci integrisan program "ERUNT" u %windir%\ERUNT\DelFix
Alat briše stare system restore tačke i pravi novu, svežu tačku nakon čišćenja.




Arrow

Pročitaj ove teme kako bi ubuduće znao da izbjegneš isntalaciju neželjenog softvera:

http://www.mycity.rs/Zastita/Kako-izbeci-i-ukloniti-toolbar-ove.html
http://www.mycity.rs/Zastita/Sta-je-reklama-a-sta-pravi-download-link.html

Što se torenata tiče, pazi šta skidaš.

offline
  • Pridružio: 18 Okt 2012
  • Poruke: 57

Napisano: 18 Sep 2014 20:21

>Very Happy<
steta sto ga nem onaj sto se klanja jer bi ti njega postavio kao zahvalnicu. Ziveli

Dopuna: 18 Sep 2014 20:33

Kazi mi samo ovaj DelFix jel on sam radi restore ili to moram sam ako bude nekih problema?

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

On samo čisti korišćene alate i postojeće System Restore tačke. Windows automatski pravi System Restore tačke tako da oko toga ne moraš da brineš (pod uslovom da ručno nisi isključio System Restore).

Ko je trenutno na forumu
 

Ukupno su 815 korisnika na forumu :: 44 registrovanih, 6 sakrivenih i 765 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: aleksmajstor, babaroga, Battlehammer, cavatina, ccoogg123, cenejac111, dankisha, Denaya, DPera, esx66, GenZee, goxin, Griffon vulture, hatman, hologram, hyla, Karla, ksyyaj, Kubovac, Leonov, Mcdado, mercedesamg, Mercury, milenko crazy north, Milos ZA, nebkv, NoOneEver Dreams, Rakenica, raketaš, raptorsi, Shinobi, Srle993, stegonosa, tubular, vaso1, Vatreni Zmaj, VJ, Vlad000, vladulns, wizzardone, YugoSlav, zeo, Zerajic, 1107