eset prijavljuije blokadu ip adrese posle skidanja sa torrenta

eset prijavljuije blokadu ip adrese posle skidanja sa torrenta

offline
  • Pridružio: 16 Avg 2007
  • Poruke: 315
  • Gde živiš: Srbija

Napisano: 06 Feb 2016 10:28

Posle skidanja nekog filma sa torrenta a preko kuckassa eset smart stalno prijavljuje blokadu nekog sajta mega-track.org. Da li je neki virus il kako da ocistim to. Koristim mozzilu firfox
evo i fajlova:

https://www.mycity.rs/must-login.png

Dopuna: 06 Feb 2016 10:34

Greskom sam iskopirao aditional
evo frst



Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:27-01-2016
Ran by Boban (administrator) on THE_RAIN (07-02-2016 10:21:58)
Running from C:\Users\Boban\Desktop
Loaded Profiles: Boban (Available Profiles: Boban & postgres & Administrator)
Platform: Microsoft Windows 8.1 Pro (X86) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-t.....scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Intel Corporation) C:\WINDOWS\System32\igfxCUIService.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe
(Nero AG) C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files\Intel\Bluetooth\ibtrksrv.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(MDL Forum, mod by Ratiborus) C:\ProgramData\KMSAuto\bin\KMSSS.exe
(Nitro PDF Software) C:\Program Files\Nitro\Pro 9\NitroPDFDriverService9.exe
(Nalpeiron Ltd.) C:\WINDOWS\System32\NLSSRV32.EXE
() C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Motorola Solutions, Inc.) C:\Program Files\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files\Intel\Bluetooth\obexsrv.exe
(Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Intel Corporation) C:\WINDOWS\System32\igfxEM.exe
(Intel Corporation) C:\WINDOWS\System32\igfxHK.exe
(Intel Corporation) C:\WINDOWS\System32\igfxTray.exe
(DT Soft Ltd) C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Realtek semiconductor) C:\WINDOWS\RTFTrack.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Lenovo (Beijing) Limited) C:\Program Files\Lenovo\Energy Management\Energy Management.exe
(Lenovo(beijing) Limited) C:\Program Files\Lenovo\Energy Management\utility.exe
(iSkySoft) C:\Program Files\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe
(Microsoft Corporation) C:\WINDOWS\System32\rundll32.exe
() C:\Users\Boban\AppData\Local\Viber\Viber.exe
(BitTorrent Inc.) C:\Users\Boban\AppData\Roaming\uTorrent\uTorrent.exe
(Microsoft Corporation) C:\WINDOWS\System32\GWX\GWX.exe
(BitTorrent Inc.) C:\Users\Boban\AppData\Roaming\uTorrent\updates\3.4.5_41372\utorrentie.exe
(BitTorrent Inc.) C:\Users\Boban\AppData\Roaming\uTorrent\updates\3.4.5_41372\utorrentie.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\WINDOWS\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17709_none_9e5a9771e29ebd0a\TiWorker.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2248080 2013-03-06] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RtsFT] => C:\WINDOWS\RTFTrack.exe [4899552 2013-01-05] (Realtek semiconductor)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\egui.exe [5088456 2014-09-22] (ESET)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [558496 2014-02-27] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe Creative Cloud] => C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2303152 2015-06-13] (Adobe Systems Incorporated)
HKLM\...\Run: [Energy Management] => C:\Program Files\Lenovo\Energy Management\Energy Management.exe [15464464 2013-08-09] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files\Lenovo\Energy Management\Utility.exe [183280 2013-05-10] (Lenovo(beijing) Limited)
HKLM\...\Run: [NeroFilterCheck] => C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [153136 2007-03-01] (Nero AG)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [597040 2015-10-06] (Oracle Corporation)
HKLM\...\Run: [iSkysoft Helper Compact.exe] => C:\Program Files\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe [2066432 2014-10-31] (iSkySoft)
HKLM\...\Run: [DelaypluginInstall] => C:\ProgramData\iSkysoft\Video Converter Ultimate\DelayPluginI.exe [1960248 2015-09-01] ()
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files\Intel\Bluetooth\btmshellex.dll",TrayApp
HKU\S-1-5-21-1993937917-1451754262-3973385152-1000\...\Run: [Viber] => C:\Users\Boban\AppData\Local\Viber\Viber.exe [51657424 2015-11-09] ()
HKU\S-1-5-21-1993937917-1451754262-3973385152-1000\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [152872 2007-06-27] (Nero AG)
HKU\S-1-5-21-1993937917-1451754262-3973385152-1000\...\Run: [uTorrent] => C:\Users\Boban\AppData\Roaming\uTorrent\uTorrent.exe [2026520 2015-12-03] (BitTorrent Inc.)
HKU\S-1-5-21-1993937917-1451754262-3973385152-1000\...\Run: [DAEMON Tools Pro Agent] => C:\Program Files\DAEMON Tools Pro\DTAgent.exe [3108480 2012-10-23] (DT Soft Ltd)
HKU\S-1-5-21-1993937917-1451754262-3973385152-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6564776 2015-10-19] (Piriform Ltd)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x86.dll [2015-06-13] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x86.dll [2015-06-13] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x86.dll [2015-06-13] ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: 127.0.0.1 cap.cyberlink.com
Tcpip\Parameters: [DhcpNameServer] 8.8.8.8 192.168.1.1
Tcpip\..\Interfaces\{D5E9BD5E-CCB1-4A6B-9FA7-F25D74923A37}: [DhcpNameServer] 8.8.8.8 192.168.1.1

Internet Explorer:
==================
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1993937917-1451754262-3973385152-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1993937917-1451754262-3973385152-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_65\bin\ssv.dll [2015-11-15] (Oracle Corporation)
BHO: iSkysoft iMedia Converter Deluxe 5.1.0 -> {AEAF002F-E6D8-4A21-ABD3-2B309B79A6CE} -> C:\ProgramData\iSkysoft\Video Converter Ultimate\WSBrowserAppMgr.dll [2015-09-01] (Wondershare)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-11-15] (Oracle Corporation)
Handler: WSISVCUchrome - {78A543EB-3A61-4ED3 - No File

FireFox:
========
FF ProfilePath: C:\Users\Boban\AppData\Roaming\Mozilla\Firefox\Profiles\v49fqbsg.Default User
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_20_0_0_286.dll [2016-01-21] ()
FF Plugin: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> C:\Program Files\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2015-01-12] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2015-01-12] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> C:\Program Files\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2015-01-12] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2015-01-12] (Foxit Corporation)
FF Plugin: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)
FF Plugin: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)
FF Plugin: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-11-15] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-11-15] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-10] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-25] (Microsoft Corporation)
FF Plugin: @nitropdf.com/NitroPDF -> C:\Program Files\Nitro\Pro 9\npnitromozilla.dll [2013-11-12] (Nitro PDF)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2014-04-28] (Adobe Systems)
FF Extension: 1-Click YouTube Video Downloader - C:\Users\Boban\AppData\Roaming\Mozilla\Firefox\Profiles\v49fqbsg.Default User\extensions\YoutubeDownloader@PeterOlayev.com.xpi [2016-01-23]
FF Extension: Translate This! - C:\Users\Boban\AppData\Roaming\Mozilla\Firefox\Profiles\v49fqbsg.Default User\Extensions\jid0-k75TfRGfOXPHfEZmJ9cKu5eCgLc@jetpack.xpi [2016-01-06]
FF HKLM\...\Firefox\Extensions: [ISVCU@iSkysoft.com] - C:\ProgramData\iSkysoft\Video Converter Ultimate\ISVCU@iSkysoft.com
FF Extension: iSkysoft iMedia Converter Deluxe - C:\ProgramData\iSkysoft\Video Converter Ultimate\ISVCU@iSkysoft.com [2015-12-26] [not signed]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdobeUpdateService; C:\Program Files\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [680112 2015-06-09] (Adobe Systems Incorporated)
R2 Bluetooth Device Monitor; C:\Program Files\Intel\Bluetooth\devmonsrv.exe [1132920 2013-06-25] (Motorola Solutions, Inc.)
R2 Bluetooth OBEX Service; C:\Program Files\Intel\Bluetooth\obexsrv.exe [1161592 2013-07-04] (Motorola Solutions, Inc.)
S3 cphs; C:\WINDOWS\system32\IntelCpHeciSvc.exe [281488 2014-10-02] (Intel Corporation)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [1350112 2014-09-16] (ESET)
R2 HTCMonitorService; C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2014-06-27] (Nero AG)
R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [281488 2014-10-02] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [462088 2012-06-19] (Intel(R) Corporation)
R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files\Intel\Bluetooth\ibtrksrv.exe [133576 2013-08-02] (Intel Corporation)
R2 jhi_service; C:\Program Files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-08-21] (Intel Corporation)
R2 KMSEmulator; C:\ProgramData\KMSAuto\bin\KMSSS.exe [297472 2014-05-20] (MDL Forum, mod by Ratiborus) [File not signed]
R2 NitroDriverReadSpool9; C:\Program Files\Nitro\Pro 9\NitroPDFDriverService9.exe [197128 2013-11-12] (Nitro PDF Software)
R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () [File not signed]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [284520 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [22224 2015-07-07] (Microsoft Corporation)
S2 TeamViewer9; "C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe" [X]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 ACPIVPC; C:\WINDOWS\System32\drivers\AcpiVpc.sys [28432 2015-07-23] (Lenovo Corporation)
R3 athr; C:\WINDOWS\system32\DRIVERS\athw8.sys [2795520 2013-06-18] (Qualcomm Atheros Communications, Inc.)
R3 BtFilter; C:\WINDOWS\system32\DRIVERS\btfilter.sys [511504 2015-04-29] (Qualcomm Atheros)
R3 btmaux; C:\WINDOWS\system32\DRIVERS\btmaux.sys [109880 2013-04-23] (Motorola Solutions, Inc.)
R1 dtsoftbus01; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [242240 2015-10-30] (DT Soft Ltd)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [191928 2014-08-18] (ESET)
R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [190368 2014-08-18] (ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [135296 2014-08-18] (ESET)
R2 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [176448 2014-08-18] (ESET)
R1 EpfwLWF; C:\WINDOWS\system32\DRIVERS\EpfwLWF.sys [37928 2014-08-18] (ESET)
R0 epfwwfp; C:\WINDOWS\System32\DRIVERS\epfwwfp.sys [51288 2014-09-18] (ESET)
R3 ETD; C:\WINDOWS\system32\DRIVERS\ETD.sys [311696 2013-03-06] (ELAN Microelectronics Corp.)
S3 intaud_WaveExtensible; C:\WINDOWS\system32\drivers\intelaud.sys [32152 2014-08-01] (Intel Corporation)
R3 iwdbus; C:\WINDOWS\System32\drivers\iwdbus.sys [23448 2014-08-01] (Intel Corporation)
S3 LGBusEnum; C:\WINDOWS\system32\drivers\LGBusEnum.sys [33824 2015-06-11] (Logitech Inc.)
S3 LGJoyXlCore; C:\WINDOWS\system32\drivers\LGJoyXlCore.sys [64168 2015-06-11] (Logitech Inc.)
S3 LGVirHid; C:\WINDOWS\system32\drivers\LGVirHid.sys [25768 2015-06-11] (Logitech Inc.)
R0 LHDmgr; C:\WINDOWS\System32\DRIVERS\LhdX86.sys [32352 2010-01-15] (Lenovo.)
R3 MEI; C:\WINDOWS\System32\drivers\HECI.sys [55104 2012-07-18] (Intel Corporation)
S3 RSUSBVSTOR; C:\WINDOWS\System32\Drivers\RtsUVStor.sys [242760 2013-01-16] (Realtek Semiconductor Corp.)
R3 rtsuvc; C:\WINDOWS\system32\DRIVERS\rtsuvc.sys [6367072 2013-01-05] (Realtek Semiconductor Corp.)
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [28656 2013-03-09] (Synaptics Incorporated)
S3 tap0901; C:\WINDOWS\system32\DRIVERS\tap0901.sys [35288 2013-08-22] (The OpenVPN Project)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [38928 2015-07-07] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [233304 2015-07-07] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [84824 2015-07-07] (Microsoft Corporation)
R3 WUDFSensorLP; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [190976 2014-11-21] (Microsoft Corporation)
R3 WUDFWpdMtp; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [190976 2014-11-21] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-02-07 10:21 - 2016-02-07 10:22 - 00017303 _____ C:\Users\Boban\Desktop\FRST.txt
2016-02-07 10:21 - 2016-02-07 10:21 - 00000000 ____D C:\FRST
2016-02-07 10:20 - 2016-02-07 10:21 - 01721856 _____ (Farbar) C:\Users\Boban\Desktop\FRST.exe
2016-02-06 16:18 - 2016-02-06 16:18 - 00032402 _____ C:\Users\Boban\Desktop\default(1).ashx
2016-02-06 16:16 - 2016-02-06 16:16 - 00027501 _____ C:\Users\Boban\Desktop\sr-latn-spectre-2015-SubRip-windows-1250.zip
2016-02-06 16:13 - 2016-02-06 16:13 - 00032402 _____ C:\Users\Boban\Desktop\default.ashx
2016-02-06 15:33 - 2016-02-06 16:20 - 00000000 ____D C:\Users\Boban\Downloads\Spectre 2015 1080p BluRay x264 DTS-JYK
2016-02-06 15:33 - 2016-02-06 16:07 - 00000000 ____D C:\Users\Boban\Downloads\MICROSOFT Office PRO Plus 2016 v16.0.4266.1003 RTM + Activator [TechTools.NET]
2016-02-06 15:32 - 2016-02-06 15:32 - 00020070 _____ C:\Users\Boban\Desktop\[kat.cr]spectre.2015.1080p.bluray.x264.dts.jyk.torrent
2016-02-06 15:28 - 2016-02-06 15:28 - 01916928 _____ C:\Users\Boban\Desktop\Celik 1230 32-bit.msi
2016-02-06 15:24 - 2016-02-06 15:24 - 00013462 _____ C:\Users\Boban\Desktop\[kat.cr]microsoft.office.pro.plus.2016.v16.0.4266.1003.rtm.activator.techtools.torrent
2016-02-05 14:25 - 2016-02-07 10:14 - 00000000 ____D C:\Users\Boban\AppData\LocalLow\uTorrent
2016-02-05 14:09 - 2016-02-05 14:17 - 00000000 ____D C:\Users\Boban\Downloads\Adobe Ilustrator CC 21015.2 v19.2.0
2016-02-05 14:08 - 2016-02-05 14:14 - 00000000 ____D C:\Users\Boban\Downloads\CORELDRAW GRAPHICS SUITE X7 2 WIN32-XFORCE
2016-02-05 13:54 - 2016-02-05 13:03 - 00001135 _____ C:\Users\Boban\Desktop\Logo Maker.lnk
2016-02-05 13:54 - 2016-02-05 12:01 - 00001100 _____ C:\Users\Boban\Desktop\Aurora 3D Text & Logo Maker.lnk
2016-02-05 13:18 - 2016-02-05 13:26 - 00000000 ____D C:\Users\Boban\Documents\LogoMaker
2016-02-05 13:18 - 2016-02-05 13:18 - 00000000 ____D C:\Users\Boban\AppData\Roaming\LogoMaker
2016-02-05 13:03 - 2016-02-05 13:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Studio V5
2016-02-05 12:56 - 2016-02-05 12:56 - 00000000 ____D C:\Program Files\Studio V5
2016-02-05 12:44 - 2016-02-05 12:44 - 00000000 ____D C:\Users\Boban\Downloads\Studio V5 Logo Maker v4.0
2016-02-05 12:11 - 2016-02-05 12:11 - 00000000 ____D C:\Users\Boban\Documents\Aurora3D
2016-02-05 12:01 - 2016-02-05 12:01 - 00000000 ____D C:\Users\Boban\AppData\Local\Maker3D
2016-02-05 12:01 - 2016-02-05 12:01 - 00000000 ____D C:\Users\Boban\AppData\Local\Configure
2016-02-05 12:01 - 2016-02-05 12:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aurora 3D Text & Logo Maker
2016-02-05 12:00 - 2016-02-05 12:00 - 00000000 ____D C:\Program Files\Aurora3D
2016-02-05 12:00 - 2011-09-13 17:58 - 00581632 _____ (Optima SC Inc.) C:\WINDOWS\system32\vp8vfw.dll
2016-02-05 11:57 - 2016-02-05 11:58 - 45487389 ____R C:\Users\Boban\Downloads\Aurora 3D Text & Logo Maker 16.01.07 [ENG] [(zabranjeno)ed Kaizer Soze_CORE] [AT-TEAM].rar
2016-02-05 11:47 - 2015-07-06 13:21 - 01369035 _____ C:\CC.ZIP
2016-02-04 08:42 - 2016-02-04 08:42 - 02718366 _____ C:\Users\Boban\Desktop\tehnicko uputstvo.pdf
2016-02-03 19:50 - 2016-02-03 19:54 - 00000000 ____D C:\Users\Boban\Downloads\Incomedia WebSite X5 Professional v12.0.1.15 MultiLang-d33p57a7u5
2016-02-03 16:17 - 2016-02-03 16:18 - 00000000 ____D C:\Users\Boban\Downloads\The Vow (2012)
2016-01-29 18:30 - 2016-01-29 19:25 - 3104495616 _____ C:\Users\Boban\Downloads\160109-1156.RS1_RELEASE_CLIENTPRO_OEMRET_X64FRE_EN-US-Freeware-Sys.iso
2016-01-29 15:50 - 2016-01-29 15:50 - 00000000 ____D C:\sajt1
2016-01-29 14:33 - 2016-01-29 18:07 - 00000000 ____D C:\Users\Boban\Desktop\sava
2016-01-29 14:20 - 2016-01-29 14:20 - 00000000 ____D C:\Program Files\GTWorks
2016-01-26 16:31 - 2016-01-26 16:31 - 00000000 ____D C:\Users\Boban\Documents\My Received Files
2016-01-26 16:29 - 2016-01-26 16:29 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_btmaux_01009.Wdf
2016-01-26 16:27 - 2016-01-26 16:27 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2016-01-26 16:27 - 2016-01-26 16:26 - 00000000 ____D C:\WINDOWS\system32\Drivers\Win32
2016-01-26 16:27 - 2013-08-02 14:18 - 00020606 _____ C:\WINDOWS\system32\Drivers\ibtfltcoex_wp8.cat
2016-01-26 16:21 - 2016-01-26 16:23 - 175672152 _____ (Lenovo Group Limited ) C:\Users\Boban\Desktop\0dgb019f.exe
2016-01-26 15:23 - 2016-01-26 15:23 - 01615368 _____ C:\Users\Boban\Desktop\iGO8_Uputstvo_srpski.pdf
2016-01-25 22:19 - 2016-01-25 22:22 - 137498241 _____ C:\Users\Boban\Documents\Nemanja Radulović & _Double Sens_ - Zajdi, zajdi ... - YouTube [720p].mp4
2016-01-25 22:18 - 2016-01-25 22:21 - 134102552 _____ C:\Users\Boban\Documents\Nemanja Radulovic & Ksenija Milosevic - Zajdi Zajdi in SALLE PLEYEL -Paris France - YouTube [720p].mp4
2016-01-25 22:17 - 2016-01-25 22:17 - 14397736 _____ C:\Users\Boban\Documents\_za moju mamu_ - Nemanja Radulović - YouTube [360p].webm
2016-01-25 22:15 - 2016-01-25 22:16 - 34339801 _____ C:\Users\Boban\Documents\Nemanja Radulovic - Pašona kolo - YouTube [720p].mp4
2016-01-25 22:13 - 2016-01-25 22:14 - 44960550 _____ C:\Users\Boban\Documents\Una Saga Serbica - Kalaj Kolo (2014) - YouTube [720p].mp4
2016-01-25 22:12 - 2016-01-25 22:14 - 86685389 _____ C:\Users\Boban\Documents\Una Saga Sebica, Centar Sava 26.10.2013. - YouTube [720p].mp4
2016-01-25 22:12 - 2016-01-25 22:12 - 17355648 _____ C:\Users\Boban\Documents\USS - Igre i zvuci Balkana - Performans TopNight - YouTube [720p].mp4
2016-01-25 22:10 - 2016-01-25 22:10 - 24061207 _____ C:\Users\Boban\Documents\Makedonsko devojče - Una Saga Serbica - YouTube [720p].mp4
2016-01-25 22:09 - 2016-01-25 22:10 - 81161365 _____ C:\Users\Boban\Documents\Manasija 2015 Una Saga Serbica 1 - YouTube [720p].mp4
2016-01-25 13:16 - 2016-01-25 13:16 - 03986810 _____ C:\Users\Boban\Desktop\com.scannerradio_pro_5.2.1_paid-www.apkhere.com.apk
2016-01-25 13:00 - 2016-01-25 13:01 - 38254850 _____ C:\Users\Boban\Desktop\com.viber.voip-5.6.0.2415-APK4Fun.com.apk
2016-01-25 11:20 - 2016-01-25 11:20 - 00000000 ____D C:\Users\Boban\Downloads\Truck2014
2016-01-15 17:18 - 2015-12-30 20:38 - 05764440 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-01-15 17:18 - 2015-12-30 20:38 - 01469968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2016-01-15 17:18 - 2015-12-11 01:11 - 00951808 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2016-01-15 17:18 - 2015-12-11 01:11 - 00425472 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2016-01-15 17:18 - 2015-12-11 01:11 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2016-01-15 17:18 - 2015-12-08 20:07 - 00507176 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll
2016-01-15 17:18 - 2015-12-07 12:01 - 01132640 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2016-01-15 17:18 - 2015-12-05 07:03 - 01581024 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMALFXGFXDSP.dll
2016-01-15 17:18 - 2015-12-05 06:58 - 02528784 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVDECOD.DLL
2016-01-15 17:18 - 2015-12-05 06:58 - 02447136 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVENCOD.DLL
2016-01-15 17:18 - 2015-12-05 06:58 - 02324744 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2016-01-15 17:18 - 2015-12-05 06:58 - 01484888 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2adec.dll
2016-01-15 17:18 - 2015-12-05 06:58 - 01115640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
2016-01-15 17:18 - 2015-12-05 06:58 - 01037680 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMADMOD.DLL
2016-01-15 17:18 - 2015-12-05 06:58 - 00914672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMADMOE.DLL
2016-01-15 17:18 - 2015-12-05 06:58 - 00700360 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2016-01-15 17:18 - 2015-12-05 06:58 - 00584656 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll
2016-01-15 17:18 - 2015-12-05 06:58 - 00492736 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVSDECD.DLL
2016-01-15 17:18 - 2015-12-05 06:58 - 00463776 _____ (Microsoft Corporation) C:\WINDOWS\system32\MP4SDECD.DLL
2016-01-15 17:18 - 2015-12-05 06:58 - 00399776 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2016-01-15 17:18 - 2015-12-05 06:58 - 00275312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPG4DECD.DLL
2016-01-15 17:18 - 2015-12-05 06:58 - 00274280 _____ (Microsoft Corporation) C:\WINDOWS\system32\MP43DECD.DLL
2016-01-15 17:18 - 2015-12-05 06:58 - 00229272 _____ (Microsoft Corporation) C:\WINDOWS\system32\RESAMPLEDMO.DLL
2016-01-15 17:18 - 2015-12-05 06:58 - 00184912 _____ (Microsoft Corporation) C:\WINDOWS\system32\COLORCNV.DLL
2016-01-15 17:18 - 2015-12-05 06:58 - 00183856 _____ (Microsoft Corporation) C:\WINDOWS\system32\VIDRESZR.DLL
2016-01-15 17:18 - 2015-12-05 06:58 - 00110544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2016-01-15 17:18 - 2015-12-05 06:58 - 00099136 _____ (Microsoft Corporation) C:\WINDOWS\system32\MP3DMOD.DLL
2016-01-15 17:18 - 2015-12-05 06:58 - 00081032 _____ (Microsoft Corporation) C:\WINDOWS\system32\devenum.dll
2016-01-15 17:18 - 2015-12-05 06:58 - 00076936 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfvdsp.dll
2016-01-15 17:18 - 2015-12-03 19:52 - 00478800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-01-15 17:18 - 2015-12-03 19:52 - 00340872 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcryptprimitives.dll
2016-01-15 17:18 - 2015-12-03 19:52 - 00120376 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncrypt.dll
2016-01-15 17:18 - 2015-12-03 19:52 - 00091416 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptsslp.dll
2016-01-15 17:18 - 2015-12-03 19:51 - 00148312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2016-01-15 17:18 - 2015-12-03 18:46 - 00153088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2016-01-15 17:18 - 2015-12-03 18:45 - 00328192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2016-01-15 17:18 - 2015-12-03 18:28 - 00519680 _____ (Microsoft Corporation) C:\WINDOWS\system32\qdvd.dll
2016-01-15 17:18 - 2015-12-03 18:28 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\system32\ksproxy.ax
2016-01-15 17:18 - 2015-12-03 18:27 - 00736256 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVXENCD.DLL
2016-01-15 17:18 - 2015-12-03 18:24 - 01411584 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMSPDMOE.DLL
2016-01-15 17:18 - 2015-12-03 18:23 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVSENCD.DLL
2016-01-15 17:18 - 2015-12-03 18:21 - 00346624 ____C (Microsoft Corporation) C:\WINDOWS\system32\SysFxUI.dll
2016-01-15 17:18 - 2015-12-03 18:06 - 01501184 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll
2016-01-15 17:18 - 2015-12-03 18:01 - 00743936 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFWMAAEC.DLL
2016-01-15 17:18 - 2015-12-03 17:46 - 01117696 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-01-15 17:18 - 2015-12-03 17:45 - 00357888 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2016-01-15 17:18 - 2015-12-03 17:29 - 00887296 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMSPDMOD.DLL
2016-01-15 17:17 - 2015-12-11 04:50 - 20367360 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-01-15 17:17 - 2015-12-11 04:21 - 00496640 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2016-01-15 17:17 - 2015-12-11 04:09 - 00663552 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2016-01-15 17:17 - 2015-12-11 03:43 - 04610560 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-01-15 17:17 - 2015-12-11 03:43 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2016-01-15 17:17 - 2015-12-11 03:37 - 00687104 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2016-01-15 17:17 - 2015-12-11 03:35 - 12856320 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-01-15 17:17 - 2015-12-11 03:12 - 02011136 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-01-15 17:17 - 2015-12-11 03:08 - 01311744 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-01-15 17:17 - 2015-12-11 03:07 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2016-01-15 17:17 - 2015-12-10 01:44 - 00030896 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2016-01-15 17:17 - 2015-12-02 16:01 - 00561664 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll
2016-01-15 17:17 - 2015-11-17 21:26 - 01230336 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2016-01-15 17:17 - 2015-11-17 21:26 - 00633856 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2016-01-15 17:17 - 2015-11-17 21:26 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2016-01-09 23:13 - 2016-01-24 16:12 - 00000000 ____D C:\Users\Boban\Downloads\q3Truck2015

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-02-07 10:22 - 2015-10-08 15:44 - 00000000 ____D C:\Users\Boban\AppData\Roaming\uTorrent
2016-02-07 10:16 - 2015-02-20 22:16 - 00000000 ____D C:\Users\Boban\Documents\ViberDownloads
2016-02-07 10:15 - 2015-06-24 10:16 - 00000000 ____D C:\Users\Boban\AppData\Roaming\ViberPC
2016-02-06 17:26 - 2015-06-24 10:26 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-02-06 16:16 - 2014-11-21 04:14 - 00863592 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-02-06 16:16 - 2013-08-22 07:21 - 00000000 ____D C:\WINDOWS\inf
2016-02-06 15:40 - 2015-11-07 19:12 - 00000000 ____D C:\ProgramData\SmartSound Software Inc
2016-02-06 15:40 - 2015-06-27 18:42 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2016-02-06 15:32 - 2015-06-20 21:16 - 00000000 ____D C:\ProgramData\TEMP
2016-02-06 15:18 - 2015-06-22 14:02 - 00000000 ____D C:\ProgramData\pdf995
2016-02-06 09:52 - 2014-07-02 09:23 - 00000000 ____D C:\usb
2016-02-06 09:31 - 2015-06-21 09:40 - 00000000 ____D C:\Users\Boban\AppData\Local\Adobe
2016-02-05 17:13 - 2015-08-05 20:24 - 03360768 ___SH C:\Users\Boban\Desktop\Thumbs.db
2016-02-05 14:25 - 2015-07-09 13:23 - 00000000 ____D C:\Users\Boban\AppData\Local\HTC MediaHub
2016-02-05 14:24 - 2015-12-30 15:38 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2016-02-05 14:24 - 2013-08-22 08:23 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-02-05 14:24 - 2013-08-22 08:22 - 03999192 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-02-05 11:43 - 2015-08-03 16:07 - 00000000 ____D C:\Users\Boban\AppData\Roaming\vlc
2016-01-29 14:52 - 2015-12-02 15:20 - 00000000 ____D C:\Users\Boban\Desktop\sajt1
2016-01-29 14:45 - 2015-10-23 09:43 - 00000000 ____D C:\Web
2016-01-29 13:13 - 2015-10-02 14:57 - 00000000 ____D C:\Program Files\Mozilla Firefox
2016-01-26 16:35 - 2013-08-22 07:13 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2016-01-26 16:27 - 2015-06-20 18:24 - 00000000 ____D C:\Program Files\Intel
2016-01-25 17:19 - 2015-06-21 09:16 - 00000000 ____D C:\Users\Boban\AppData\Roaming\Skype
2016-01-25 11:15 - 2015-10-08 09:48 - 00000000 ____D C:\Users\Boban\AppData\Roaming\TeamViewer
2016-01-23 11:37 - 2013-08-22 09:17 - 00000000 ____D C:\WINDOWS\rescache
2016-01-21 21:38 - 2015-06-21 09:37 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-01-21 21:34 - 2013-08-22 09:05 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-01-21 21:31 - 2015-06-12 03:08 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-01-21 21:31 - 2014-11-21 06:45 - 00000000 ___SD C:\WINDOWS\system32\CompatTel
2016-01-21 20:33 - 2015-06-12 02:52 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2016-01-21 13:32 - 2015-06-12 02:56 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-01-21 13:27 - 2015-06-12 02:56 - 141317472 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-01-21 13:27 - 2013-08-22 07:13 - 00000167 _____ C:\WINDOWS\win.ini
2016-01-21 13:12 - 2015-06-12 02:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2016-01-11 15:12 - 2015-06-21 03:04 - 00000000 ____D C:\Users\Boban
2016-01-11 09:52 - 2013-08-22 09:17 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-01-08 14:28 - 2015-12-26 17:31 - 00000000 ____D C:\ProgramData\iSkysoft iMedia Converter Deluxe

==================== Files in the root of some directories =======

2015-07-19 09:48 - 2015-07-19 09:48 - 0000001 _____ () C:\Users\Boban\AppData\Local\llftool.4.40.agreement
2015-07-19 09:59 - 2015-07-19 09:59 - 0000019 _____ () C:\Users\Boban\AppData\Local\llftool.license
2015-08-01 07:56 - 2015-08-01 07:56 - 0000017 _____ () C:\Users\Boban\AppData\Local\resmon.resmoncfg

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-02-05 11:55

==================== End of FRST.txt ============================

offline
  • Pridružio: 02 Jan 2008
  • Poruke: 2167

Mozes li mi reci sta konkretno (koji proces) ESET blokira/prijavljuje?

1. Otvori Notepad (Text Document) i iskopiraj sledeći tekst unutar kod polja ispod:

CreateRestorePoint:
Task: {17233BE9-87E9-40B0-B003-AE9D2B92CBBE} - \Microsoft\Windows\SettingSync\BackupTask -> No File <==== ATTENTION
Task: {28C41F83-C3E5-43EB-AA8B-A00A70F16D51} - \Microsoft\Windows\TaskScheduler\Manual Maintenance -> No File <==== ATTENTION
Task: {39696527-FC73-4677-8346-FDAA34F465AD} - \Microsoft\Windows\TaskScheduler\Maintenance Configurator -> No File <==== ATTENTION
Task: {3BBBBBB5-8AB7-4DDA-8045-1341082C863F} - \Optimize Start Menu Cache Files-S-1-5-21-1993937917-1451754262-3973385152-1001 -> No File <==== ATTENTION
Task: {88927B10-1389-4BFC-9324-198B48E6C1AE} - \Microsoft\Windows\Application Experience\AitAgent -> No File <==== ATTENTION
Task: {AF675C1A-904E-4501-9B4D-024149BFA588} - \WPD\SqmUpload_S-1-5-21-1993937917-1451754262-3973385152-1001 -> No File <==== ATTENTION
Task: {BD7A3050-3669-48C1-A5A0-99677E2C626C} - \Microsoft\Windows\TaskScheduler\Idle Maintenance -> No File <==== ATTENTION
Task: {F78A431B-6C44-4B6D-BD3A-38F96C982E5B} - \Microsoft\Windows\TaskScheduler\Regular Maintenance -> No File <==== ATTENTION
AlternateDataStreams: C:\WINDOWS:nlsPreferences
AlternateDataStreams: C:\ProgramData\TEMP:A5C00DEE
AlternateDataStreams: C:\ProgramData\TEMP:ECF54A0E
AlternateDataStreams: C:\Users\Boban\Documents\Site3.wpp:SummaryInformation
AlternateDataStreams: C:\Users\Boban\Documents\Site3.wpp:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
EmptyTemp:


2. Sačuvaj notepad na Desktop pod nazivom fixlist.txt
To možes uraditi i iz notepad-a => klik na File potom na Save As i u novom prozoru, dole pod File Name: staviš za naziv fixlist.txt
Napomena: Važno je da se oba fajla, FRST i fixlist nalaze na istoj lokaciji jer u suprotnom fix nece raditi.

3. Ponovo pokreni FRST/FRST64, klikni jednom na dugme Fix i sačekaj.
Ukoliko alat zatraži restart sistema, dozvoli mu i postaraj se da alat kompletira fix nakon restarta sistema.



Alat će formirati log (Fixlog.txt) na Desktop-u. Potrebno je sadržaj tog loga iskopirati u poruku.
Napomena: Ukoliko te alat upozori da postoji novija verzija, postaraj se da preuzmes i koristiš ažuriranu kopiju FRST-a.

offline
  • Pridružio: 16 Avg 2007
  • Poruke: 315
  • Gde živiš: Srbija

Eset prijavljuje Adress has been blocked
IP 188.138.72.75
http//mega-trac.org/bt/announce.php i jos puno nekih brojeva

Fix result of Farbar Recovery Scan Tool (x86) Version:27-01-2016
Ran by Boban (2016-02-07 18:29:52) Run:1
Running from C:\Users\Boban\Desktop
Loaded Profiles: Boban (Available Profiles: Boban & postgres & Administrator)
Boot Mode: Normal

==============================================

fixlist content:
*****************
CreateRestorePoint:
Task: {17233BE9-87E9-40B0-B003-AE9D2B92CBBE} - \Microsoft\Windows\SettingSync\BackupTask -> No File <==== ATTENTION
Task: {28C41F83-C3E5-43EB-AA8B-A00A70F16D51} - \Microsoft\Windows\TaskScheduler\Manual Maintenance -> No File <==== ATTENTION
Task: {39696527-FC73-4677-8346-FDAA34F465AD} - \Microsoft\Windows\TaskScheduler\Maintenance Configurator -> No File <==== ATTENTION
Task: {3BBBBBB5-8AB7-4DDA-8045-1341082C863F} - \Optimize Start Menu Cache Files-S-1-5-21-1993937917-1451754262-3973385152-1001 -> No File <==== ATTENTION
Task: {88927B10-1389-4BFC-9324-198B48E6C1AE} - \Microsoft\Windows\Application Experience\AitAgent -> No File <==== ATTENTION
Task: {AF675C1A-904E-4501-9B4D-024149BFA588} - \WPD\SqmUpload_S-1-5-21-1993937917-1451754262-3973385152-1001 -> No File <==== ATTENTION
Task: {BD7A3050-3669-48C1-A5A0-99677E2C626C} - \Microsoft\Windows\TaskScheduler\Idle Maintenance -> No File <==== ATTENTION
Task: {F78A431B-6C44-4B6D-BD3A-38F96C982E5B} - \Microsoft\Windows\TaskScheduler\Regular Maintenance -> No File <==== ATTENTION
AlternateDataStreams: C:\WINDOWS:nlsPreferences
AlternateDataStreams: C:\ProgramData\TEMP:A5C00DEE
AlternateDataStreams: C:\ProgramData\TEMP:ECF54A0E
AlternateDataStreams: C:\Users\Boban\Documents\Site3.wpp:SummaryInformation
AlternateDataStreams: C:\Users\Boban\Documents\Site3.wpp:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
EmptyTemp:
*****************

Restore point was successfully created.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{17233BE9-87E9-40B0-B003-AE9D2B92CBBE}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{17233BE9-87E9-40B0-B003-AE9D2B92CBBE}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\SettingSync\BackupTask" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{28C41F83-C3E5-43EB-AA8B-A00A70F16D51}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{28C41F83-C3E5-43EB-AA8B-A00A70F16D51}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\TaskScheduler\Manual Maintenance" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{39696527-FC73-4677-8346-FDAA34F465AD}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{39696527-FC73-4677-8346-FDAA34F465AD}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\TaskScheduler\Maintenance Configurator" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3BBBBBB5-8AB7-4DDA-8045-1341082C863F}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3BBBBBB5-8AB7-4DDA-8045-1341082C863F}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Optimize Start Menu Cache Files-S-1-5-21-1993937917-1451754262-3973385152-1001" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{88927B10-1389-4BFC-9324-198B48E6C1AE}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{88927B10-1389-4BFC-9324-198B48E6C1AE}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Application Experience\AitAgent" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AF675C1A-904E-4501-9B4D-024149BFA588}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AF675C1A-904E-4501-9B4D-024149BFA588}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WPD\SqmUpload_S-1-5-21-1993937917-1451754262-3973385152-1001" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BD7A3050-3669-48C1-A5A0-99677E2C626C}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BD7A3050-3669-48C1-A5A0-99677E2C626C}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\TaskScheduler\Idle Maintenance" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F78A431B-6C44-4B6D-BD3A-38F96C982E5B}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F78A431B-6C44-4B6D-BD3A-38F96C982E5B}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\TaskScheduler\Regular Maintenance" => key removed successfully.
C:\WINDOWS => ":nlsPreferences" ADS removed successfully..
C:\ProgramData\TEMP => ":A5C00DEE" ADS removed successfully..
C:\ProgramData\TEMP => ":ECF54A0E" ADS removed successfully..
C:\Users\Boban\Documents\Site3.wpp => ":SummaryInformation" ADS removed successfully..
C:\Users\Boban\Documents\Site3.wpp => ":{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}" ADS removed successfully..
EmptyTemp: => 330.3 MB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 18:33:22 ====

offline
  • Pridružio: 02 Jan 2008
  • Poruke: 2167

Problem je najverovatnije uzrokovan nekim torentom koji trenutno preuzimas. Ovo sto ti ESET prijavljuje je torent "tracker". Iskljuci utorrent i onda vidi kakvo je stanje ili pogledaj koji torent koji trenutno preuzimas ima ovu adresu u jezicku "Trackers" . Sto se malvera tice, tvoj racunar je cist Smile

Sledeća procedura će implementirati završno čišćenje.



Arrow Preuzmi "Xplode"-ov DelFix alat i snimi ga na Desktop.

Dvoklikom pokreni alat i štikliraj kućice ispred sledećih opcija;
Remove disinfection tools
Create registry backup
Purge System Restore


Klikni na dugme Run i pričekaj trenutak dok alat ne završi svoj rad.

Od ovog trenutka, svi korišćeni alati u ovoj temi bi trebali biti obrisani.
Ukoliko neki alat ili izveštaj nije uklonjen, slobodno ih obriši ručno.


Alat će takođe formirati izveštaj za tebe. (C:\DelFix.txt)
- Alat će snimiti i zdravo stanje registy-ja i napraviti backup koristeci integrisan program "ERUNT" u %windir%\ERUNT\DelFix
- DelFix briše stare system restore tačke i pravi novu, svežu tačku nakon čišćenja.

offline
  • Pridružio: 16 Avg 2007
  • Poruke: 315
  • Gde živiš: Srbija

Ok. Hvala. Deinstalirao sam torrent i sada je sve ok.

Ko je trenutno na forumu
 

Ukupno su 813 korisnika na forumu :: 7 registrovanih, 1 sakriven i 805 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: Bobrock1, Darko001, mrav pesadinac, naki011, robytz, Srle993, voja64