Usporen rad računara

Usporen rad računara

offline
  • Pridružio: 11 Jul 2012
  • Poruke: 46

Pozdrav,

računar mi je super radio sve do neki dan otkako je naglo usporio i sve jedva otvara.

Poslednje u zadnjih par dana što se sjećam da sam instalirao je Dropbox ali ne vjerujem da je zbog toga.

Browser takođe usporen.

_____________________________________________________________

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-10-2014
Ran by Aleksandar (administrator) on DELTABH on 26-10-2014 16:22:24
Running from C:\Users\Aleksandar\Desktop
Loaded Profile: Aleksandar (Available profiles: Aleksandar)
Platform: Windows 8.1 Pro with Media Center (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: geekstogo.com/forum/topic/335081-frst-t.....scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(arvato digital services llc) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Yahoo! Inc.) C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Skillbrains) C:\Users\Aleksandar\AppData\Local\Skillbrains\lightshot\5.1.4.17\Lightshot.exe
(MyCity) C:\Program Files (x86)\MCShield\MCShieldRTM.exe
() D:\deltabh\FSCapture48\FSCapture.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Nitro PDF Software) C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe
(Microsoft Corporation) C:\Windows\System32\prevhost.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Reader_6.3.9654.17044_x64__8wekyb3d8bbwe\glcnd.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [641704 2012-11-16] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AMD AVT] => C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [20992 2012-03-19] ()
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKU\S-1-5-21-468891226-946991927-1053560233-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-468891226-946991927-1053560233-1001\...\Run: [LightShot] => C:\Users\Aleksandar\AppData\Local\Skillbrains\lightshot\Lightshot.exe [226560 2014-07-01] ()
HKU\S-1-5-21-468891226-946991927-1053560233-1001\...\Run: [MCShield Monitor] => C:\Program Files (x86)\MCShield\mcshieldrtm.exe [650816 2014-04-11] (MyCity)
HKU\S-1-5-21-468891226-946991927-1053560233-1001\...\Run: [Facebook Update] => C:\Users\Aleksandar\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2014-08-13] (Facebook Inc.)
HKU\S-1-5-21-468891226-946991927-1053560233-1001\...\Run: [Messenger (Yahoo!)] => C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe [6595928 2012-05-25] (Yahoo! Inc.)
HKU\S-1-5-21-468891226-946991927-1053560233-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [22065760 2014-10-01] (Skype Technologies S.A.)
HKU\S-1-5-21-468891226-946991927-1053560233-1001\...\MountPoints2: {83c38255-20a7-11e4-824c-806e6f6e6963} - "E:\DriverPackSolution.exe"
Startup: C:\Users\Aleksandar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Aleksandar\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FastStone Capture.lnk
ShortcutTarget: FastStone Capture.lnk -> D:\deltabh\FSCapture48\FSCapture.exe ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = t.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x3F2BEFC4B7B4CF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = sr-Latn-BA
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: &Yahoo! Toolbar Helper -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM-x32 - Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll No File
FF Plugin: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/AuthorwarePlayer -> C:\Windows\system32\Macromed\AUTHORWA\np32asw.dll No File
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1213153.dll (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 8\npnitromozilla.dll (Nitro PDF)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Aleksandar\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)

Chrome:
=======
CHR HomePage: Default -> google.ba/
CHR StartupUrls: Default -> "hxxp://www.google.rs/", "hxxp://start.mysearchdial.com/?f=1&a=md_14_11_ch&cd=2XzuyEtN2Y1L1QzutDtD0EtDyB0DzyyByCzz0D0FtB0ByCtBtN0D0Tzu0SzztDyDtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyDtA0CyEyCtCyDtAtGtC0FyE0AtG0A0FtCyDtGyEzytB0DtGyByE0CzztD0AyCtC0AtD0AyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyC0D0DyCzyyDzyyEtGtA0D0FtAtGyD0AyEtCtGyE0BtDyBtGtB0B0E0FyC0DtCtB0AtCtDyD2Q&cr=569384714&ir="
CHR Profile: C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Entanglement Web App) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd [2014-09-04]
CHR Extension: (Note Board Web) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\apgackkfllmckgkbdfmbfodpinmnnpab [2014-09-04]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-08-10]
CHR Extension: (WOT) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2014-09-04]
CHR Extension: (Honey) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2014-09-04]
CHR Extension: (X-notifier (for Gmail™,Hotmail,Yahoo,AOL...)) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdfjbkbddpfnoplfhceolpopfoepleco [2014-09-05]
CHR Extension: (Full Page Screen Capture) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdpohaocaechififmbbbbbknoalclacl [2014-10-05]
CHR Extension: (Shield For Chrome ) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\gceighgadbamgchioaofojlblndjcggh [2014-09-04]
CHR Extension: (Click&Clean) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghgabhipcejejjmhhchfonmamedcbeod [2014-09-04]
CHR Extension: (AdBlock) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-09-04]
CHR Extension: (PDF Mergy) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgecghmkcdefnknohcimkoemhaofpoha [2014-09-04]
CHR Extension: (Bitly | Unleash the power of the link) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\iabeihobmhlgpkcgjiloemdbofjbdcic [2014-09-04]
CHR Extension: (Typing Test - KeyHero) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkcieoaeooeidmpaopkpjpjfakidlabm [2014-09-04]
CHR Extension: (Todoist: To-Do list and Task Manager) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\jldhpllghnbhlbpcmnajkpdmadaolakh [2014-09-04]
CHR Extension: (Auto Replay for YouTube™) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\kanbnempkjnhadplbfgdaagijdbdbjeb [2014-09-04]
CHR Extension: (Google Mail Checker) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2014-09-04]
CHR Extension: (Quick Note) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\mijlebbfndhelmdpmllgcfadlkankhok [2014-09-04]
CHR Extension: (Google Wallet) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-08-10]
CHR Extension: (Buffer) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\noojglkidnpfjbincgijbaiedldjfbhh [2014-09-04]
CHR Extension: (My Chrome Theme) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\oehpjpccmlcalbenfhnacjeocbjdonic [2014-09-04]
CHR Extension: (Click&Clean App) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp [2014-09-04]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [44032 2013-08-22] (Microsoft Corporation)
S3 lfsvc; C:\Windows\SysWOW64\GeofenceMonitorService.dll [357376 2014-03-08] (Microsoft Corporation)
S3 Netlogon; C:\Windows\SysWOW64\netlogon.dll [688640 2013-08-22] (Microsoft Corporation)
R2 NitroDriverReadSpool8; C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe [230408 2012-12-13] (Nitro PDF Software)
R2 PSI_SVC_2_x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [337776 2013-09-13] (arvato digital services llc)
S3 smphost; C:\Windows\SysWOW64\smphost.dll [11776 2013-08-22] (Microsoft Corporation)
S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18944 2013-08-22] (Microsoft Corporation)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S3 wampapache64; c:\wamp\bin\apache\apache2.4.9\bin\httpd.exe [24576 2014-05-01] (Apache Software Foundation) [File not signed]
S3 wampmysqld64; c:\wamp\bin\mysql\mysql5.6.17\bin\mysqld.exe [12942848 2014-05-01] () [File not signed]
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [348392 2014-03-12] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-12] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 Atc002; C:\Windows\system32\DRIVERS\l260x64.sys [34304 2013-06-18] (Atheros Communications, Inc.)
R3 cmuda3; C:\Windows\system32\drivers\cmudax3.sys [1155072 2009-12-01] (C-Media Inc)
R3 MTsensor; C:\Windows\system32\DRIVERS\ASACPI.sys [17280 2013-05-17] ()
R3 RTL8023x64; C:\Windows\system32\DRIVERS\Rtnic64.sys [51712 2013-06-18] (Realtek Semiconductor Corporation )
S3 ssudserd; C:\Windows\system32\DRIVERS\ssudserd.sys [206080 2014-01-22] (DEVGURU Co., LTD.(www.devguru.co.kr))
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124760 2014-03-12] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-26 16:22 - 2014-10-26 16:24 - 00015653 _____ () C:\Users\Aleksandar\Desktop\FRST.txt
2014-10-26 16:22 - 2014-10-26 16:22 - 00000000 ____D () C:\FRST
2014-10-26 16:21 - 2014-10-26 16:21 - 02113024 _____ (Farbar) C:\Users\Aleksandar\Desktop\FRST64.exe
2014-10-26 16:17 - 2014-10-26 16:17 - 00000000 ____D () C:\Users\Aleksandar\AppData\Roaming\Nitro
2014-10-26 16:09 - 2012-12-13 11:47 - 00029704 _____ (Nitro PDF Software) C:\Windows\system32\nitrolocalmon2.dll
2014-10-26 16:09 - 2012-12-13 11:47 - 00017928 _____ (Nitro PDF Software) C:\Windows\system32\nitrolocalui2.dll
2014-10-26 16:08 - 2014-10-26 16:08 - 00002547 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nitro Pro 8.lnk
2014-10-26 16:08 - 2014-10-26 16:08 - 00001978 _____ () C:\Users\Public\Desktop\Nitro Pro 8.lnk
2014-10-26 16:01 - 2014-10-26 16:02 - 00000000 ____D () C:\Users\Aleksandar\Desktop\zip
2014-10-26 15:59 - 2014-10-26 15:59 - 00000000 ____D () C:\Program Files\Common Files\Nitro
2014-10-26 15:58 - 2014-10-26 15:58 - 00000000 ____D () C:\ProgramData\Nitro
2014-10-26 15:58 - 2014-10-26 15:58 - 00000000 ____D () C:\Program Files (x86)\Nitro
2014-10-26 15:51 - 2014-10-26 15:51 - 00000000 ____D () C:\Users\Aleksandar\AppData\Roaming\Downloaded Installations
2014-10-26 01:07 - 2014-10-26 01:07 - 00006832 _____ () C:\Users\Aleksandar\Desktop\nbkp.txt
2014-10-25 21:25 - 2014-10-25 21:25 - 00006454 _____ () C:\Users\Aleksandar\Desktop\Kontaktirajtenas---10-25-2014-.nff
2014-10-25 20:34 - 2014-10-25 20:38 - 00000000 ____D () C:\Users\Aleksandar\Desktop\salmont bekap 25.10.2014
2014-10-25 19:16 - 2014-10-25 19:16 - 06126536 _____ (Tim Kosse) C:\Users\Aleksandar\Downloads\FileZilla_3.9.0.6_win32-setup.exe
2014-10-23 22:16 - 2011-12-11 20:51 - 01683481 _____ () C:\Users\Aleksandar\Desktop\Photoshop Letterpress Effect.psd
2014-10-23 20:28 - 2013-09-04 22:57 - 44930490 _____ () C:\Users\Aleksandar\Desktop\Cutout Logo Mock-Up.psd
2014-10-23 20:09 - 2013-11-18 20:42 - 17900998 _____ () C:\Users\Aleksandar\Desktop\Wood Engraved Logo Mock-Up.psd
2014-10-23 17:34 - 2014-10-23 17:34 - 00000000 ____D () C:\Users\Aleksandar\AppData\Local\Michele_Locati
2014-10-23 17:34 - 2014-10-23 17:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BetterPoEditor
2014-10-23 17:34 - 2014-10-23 17:34 - 00000000 ____D () C:\Program Files (x86)\BetterPoEditor
2014-10-23 17:31 - 2014-10-23 17:31 - 00000000 ____D () C:\Program Files (x86)\Reference Assemblies
2014-10-23 17:30 - 2014-10-23 17:30 - 00000000 ____D () C:\Program Files\Reference Assemblies
2014-10-23 17:30 - 2014-10-23 17:30 - 00000000 ____D () C:\Program Files\MSBuild
2014-10-23 17:24 - 2013-08-03 05:48 - 01166520 _____ (Microsoft Corporation) C:\Windows\system32\PresentationNative_v0300.dll
2014-10-23 17:24 - 2013-08-03 05:48 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2014-10-23 17:24 - 2013-08-03 05:48 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-10-23 17:24 - 2013-08-03 05:41 - 00778936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationNative_v0300.dll
2014-10-23 17:24 - 2013-08-03 05:41 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2014-10-23 17:24 - 2013-08-03 05:41 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-10-23 00:28 - 2014-10-25 19:13 - 00000000 ___RD () C:\Users\Aleksandar\Dropbox
2014-10-23 00:28 - 2014-10-23 00:28 - 00001093 _____ () C:\Users\Aleksandar\Desktop\Dropbox.lnk
2014-10-23 00:25 - 2014-10-23 00:25 - 00000000 ____D () C:\Users\Aleksandar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-10-23 00:19 - 2014-10-25 17:58 - 00000000 ____D () C:\Users\Aleksandar\AppData\Roaming\Dropbox
2014-10-23 00:18 - 2014-10-23 00:19 - 00323672 _____ (Dropbox, Inc.) C:\Users\Aleksandar\Desktop\DropboxInstaller.exe
2014-10-22 23:52 - 2014-10-22 23:52 - 03507639 _____ () C:\Users\Aleksandar\Desktop\logo%20iso%202010[1].psd
2014-10-22 17:08 - 2014-10-22 17:16 - 81763259 _____ () C:\Users\Aleksandar\Desktop\Mivex Malina 250g.ai
2014-10-22 00:17 - 2014-10-22 00:17 - 00000897 _____ () C:\Users\Aleksandar\Desktop\k.txt
2014-10-21 21:18 - 2014-10-21 21:18 - 00308851 _____ () C:\Users\Aleksandar\Desktop\logo4.psd
2014-10-20 19:11 - 2014-10-20 19:11 - 00938594 _____ () C:\Users\Aleksandar\Desktop\logo3 vektor.ai
2014-10-20 18:58 - 2014-10-20 18:58 - 00296354 _____ () C:\Users\Aleksandar\Desktop\logo3.psd
2014-10-20 00:41 - 2014-10-20 00:41 - 00001244 _____ () C:\Users\Aleksandar\Desktop\ll.txt
2014-10-19 19:34 - 2014-10-19 19:35 - 00288979 _____ () C:\Users\Aleksandar\Desktop\logo2.psd
2014-10-19 13:36 - 2014-10-19 13:36 - 00003955 _____ () C:\Users\Aleksandar\Desktop\wp-config.php
2014-10-17 22:18 - 2014-06-10 10:01 - 00009217 _____ () C:\Users\Aleksandar\Desktop\layout2-revslider.txt
2014-10-17 20:04 - 2014-10-26 16:05 - 00000000 ____D () C:\Users\Aleksandar\Desktop\salmont
2014-10-17 18:19 - 2014-10-17 18:19 - 00000000 ____D () C:\Users\Aleksandar\Desktop\bekap
2014-10-13 23:50 - 2014-10-14 00:10 - 01424791 _____ () C:\Users\Aleksandar\Desktop\Untitled-2.psd
2014-10-13 22:23 - 2014-10-13 22:23 - 00061440 _____ () C:\Users\Aleksandar\Desktop\Book 1.indb
2014-10-13 22:19 - 2014-10-13 22:19 - 00061440 _____ () C:\Users\Aleksandar\Desktop\knjiga.indb
2014-10-13 22:01 - 2014-10-13 22:01 - 00001211 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe InDesign CS6.lnk
2014-10-13 21:57 - 2014-10-13 21:59 - 00001301 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Media Encoder CS6.lnk
2014-10-13 21:14 - 2012-04-29 22:06 - 00000000 ____D () C:\Users\Aleksandar\Desktop\Adobe Indesign CS6
2014-10-12 16:18 - 2014-10-12 16:18 - 00000000 ____D () C:\Users\Aleksandar\Desktop\lijekzadusu
2014-10-11 17:25 - 2014-10-11 17:25 - 00789502 _____ () C:\Users\Aleksandar\Desktop\alienware-2.zip
2014-10-10 19:52 - 2014-10-26 16:05 - 00000000 ____D () C:\Users\Aleksandar\Desktop\slike
2014-10-02 17:56 - 2014-10-02 17:56 - 00000196 _____ () C:\Users\Aleksandar\Desktop\ponuda.txt

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-26 16:20 - 2014-08-10 17:23 - 00003594 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-468891226-946991927-1053560233-1001
2014-10-26 16:04 - 2014-08-10 18:39 - 00000000 ____D () C:\Users\Aleksandar\AppData\Roaming\Skype
2014-10-26 16:02 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sru
2014-10-26 15:42 - 2014-08-12 18:48 - 00000000 ____D () C:\ProgramData\MCShield
2014-10-26 15:37 - 2014-08-10 17:27 - 00000956 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-10-26 15:18 - 2014-08-12 13:19 - 00000414 _____ () C:\Windows\Tasks\update-sys.job
2014-10-26 15:02 - 2014-08-13 19:57 - 00000964 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-468891226-946991927-1053560233-1001UA.job
2014-10-26 14:43 - 2014-08-12 13:19 - 00000414 _____ () C:\Windows\Tasks\update-S-1-5-21-468891226-946991927-1053560233-1001.job
2014-10-26 14:28 - 2014-09-06 13:11 - 01181974 _____ () C:\Windows\WindowsUpdate.log
2014-10-26 13:39 - 2014-08-11 18:24 - 03481088 ___SH () C:\Users\Aleksandar\Desktop\Thumbs.db
2014-10-26 12:02 - 2014-09-21 11:34 - 00003758 _____ () C:\Windows\System32\Tasks\AutoKMS
2014-10-26 12:02 - 2014-08-10 17:27 - 00000952 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-10-26 01:00 - 2014-08-11 22:55 - 00000000 ____D () C:\Users\Aleksandar\AppData\Local\Adobe
2014-10-26 00:42 - 2014-08-13 22:48 - 00000000 ____D () C:\Users\Aleksandar\AppData\Roaming\FileZilla
2014-10-25 20:02 - 2014-08-13 19:57 - 00000942 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-468891226-946991927-1053560233-1001Core.job
2014-10-25 19:18 - 2014-08-13 22:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2014-10-25 19:18 - 2014-08-13 22:47 - 00000000 ____D () C:\Program Files (x86)\FileZilla FTP Client
2014-10-25 19:14 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\rescache
2014-10-24 23:54 - 2014-08-10 17:17 - 00000000 ____D () C:\Users\Aleksandar
2014-10-24 14:58 - 2013-08-22 15:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-23 17:33 - 2013-08-22 16:20 - 00000000 ____D () C:\Windows\CbsTemp
2014-10-23 17:31 - 2014-09-18 23:44 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2014-10-22 18:45 - 2014-08-10 17:31 - 00002203 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-10-21 21:18 - 2014-08-29 22:38 - 00000132 _____ () C:\Users\Aleksandar\AppData\Roaming\Adobe PNG Format CS6 Prefs
2014-10-21 14:27 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\AppReadiness
2014-10-21 14:16 - 2013-08-22 15:44 - 05186616 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-10-15 18:24 - 2014-08-10 18:19 - 00000000 ____D () C:\ProgramData\Skype
2014-10-14 17:32 - 2014-08-10 17:27 - 00003928 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-10-14 17:32 - 2014-08-10 17:27 - 00003692 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-10-13 22:02 - 2014-08-12 06:41 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2014-10-13 22:01 - 2014-08-11 22:56 - 00000000 ____D () C:\ProgramData\Adobe
2014-10-13 21:59 - 2014-08-12 06:39 - 00001185 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS6.lnk
2014-10-13 21:59 - 2014-08-12 06:37 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-10-13 21:58 - 2014-08-12 06:37 - 00001539 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS6.lnk
2014-10-13 21:58 - 2014-08-12 06:37 - 00001369 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS6.lnk
2014-10-13 21:57 - 2014-08-12 06:39 - 00000000 ____D () C:\Program Files\Adobe
2014-10-13 21:57 - 2014-08-10 17:17 - 00000000 ____D () C:\Users\Aleksandar\AppData\Roaming\Adobe
2014-10-13 21:56 - 2014-08-12 06:34 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-10-08 17:33 - 2014-08-12 13:19 - 00003272 _____ () C:\Windows\System32\Tasks\update-S-1-5-21-468891226-946991927-1053560233-1001
2014-10-08 17:33 - 2014-08-12 13:19 - 00000447 _____ () C:\Users\Aleksandar\AppData\Local\UserProducts.xml
2014-10-08 17:33 - 2014-08-12 13:19 - 00000000 ____D () C:\Users\Aleksandar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lightshot
2014-10-05 15:18 - 2014-08-28 19:55 - 00000000 ____D () C:\Users\Aleksandar\AppData\Roaming\vlc
2014-10-01 19:58 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2014-10-01 06:37 - 2014-09-25 19:23 - 00000000 ____D () C:\Users\Aleksandar\Desktop\5 Blurred Backgrounds Vol.2
2014-09-26 13:44 - 2013-08-22 14:25 - 00262144 ___SH () C:\Windows\system32\config\BBI

Some content of TEMP:
====================
C:\Users\Aleksandar\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpcqlrad.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-10-19 16:56

==================== End Of Log ============================

mycity.rs/must-login.png

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Arrow Korak 1

Otvori Notepad i iskopiraj sljedeći tekst koji se nalazi unutar Kod polja.

Start
CHR Extension: (X-notifier (for Gmail™,Hotmail,Yahoo,AOL...)) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdfjbkbddpfnoplfhceolpopfoepleco [2014-09-05]
CHR Extension: (Full Page Screen Capture) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdpohaocaechififmbbbbbknoalclacl [2014-10-05]
CHR Extension: (Shield For Chrome ) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\gceighgadbamgchioaofojlblndjcggh [2014-09-04]
EmptyTemp:
End


U okviru Notepad-a klikni na File --> Save As
Fajl nazovi Fixlist i sačuvaj na Desktop
Dvoklikom ponovo pokreni FRST.exe
Klikni na Fix i sačekaj dok program ne završi.
Ukoliko program zatraži restart računara, omogući mu da to nesmetano obavi.
Nakon završetka rada, otvoriće se Notepad, sa sadržajem koji treba da kopiraš u temu.
Takođe, na Desktop-u će se nalaziti (fixlog.txt). Potrebno je da sadržaj fixlog.txt kopiraš na forum




Arrow Korak 2

Preuzmi zoek.exe sa ovog ili ovog linka i sačuvaj ga na Desktop.


Zatvori browser i ostale pokrenute programe;
deaktiviraj zaštitni softver ( po potrebi ) Uputstvo ;
dvoklikom pokreni zoek.exe;
pričekaj da se alat startuje ...


U beli okvir prozora iskopiraj sljedeći tekst:

process;
startupall;
skipfix-iedefaults;
firefoxlook;
chromelook;
filesrcm;


Klikni na dugme i pričekaj da se skeniranje završi.


Zoek će po potrebi restartovati Windows, a na kraju rada otvoriti Notepad sa izvještajem o skeniranju.

Napomena: Izvještaj će biti sačuvan pod nazivom zoek-results.log na sistemskoj particiji (tipična lokacija: C:\zoek-results.log)


Arrow Kopiraj sadržaj tog loga u poruku.

offline
  • Pridružio: 11 Jul 2012
  • Poruke: 46

Arrow Korak 1

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 26-10-2014
Ran by Aleksandar at 2014-10-26 18:00:44 Run:1
Running from C:\Users\Aleksandar\Desktop
Loaded Profile: Aleksandar (Available profiles: Aleksandar)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
CHR Extension: (X-notifier (for Gmail™,Hotmail,Yahoo,AOL...)) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdfjbkbddpfnoplfhceolpopfoepleco [2014-09-05]
CHR Extension: (Full Page Screen Capture) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdpohaocaechififmbbbbbknoalclacl [2014-10-05]
CHR Extension: (Shield For Chrome ) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\gceighgadbamgchioaofojlblndjcggh [2014-09-04]
EmptyTemp:
End
*****************

C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdfjbkbddpfnoplfhceolpopfoepleco => Moved successfully.
C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdpohaocaechififmbbbbbknoalclacl => Moved successfully.
C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\gceighgadbamgchioaofojlblndjcggh => Moved successfully.
EmptyTemp: => Removed 326.1 MB temporary data.


The system needed a reboot.

==== End of Fixlog ====


Arrow Korak 2


Zoek.exe v5.0.0.0 Updated 26-10-2014
Tool run by Aleksandar on ned. 26.10.2014. at 18:12:00,86.
Microsoft Windows 8.1 Pro with Media Center 6.3.9600 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Aleksandar\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

26.10.2014. 18:13:03 Zoek.exe System Restore Point Created Succesfully.

==== Running Processes ======================

C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
C:\Program Files (x86)\Yahoo\SoftwareUpdate\YahooAUService.exe
C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe
C:\Users\Aleksandar\AppData\Local\Skillbrains\lightshot\5.1.4.17\Lightshot.exe
C:\Program Files (x86)\MCShield\MCShieldRTM.exe
C:\Users\Aleksandar\AppData\Local\Facebook\Update\FacebookUpdate.exe
D:\deltabh\FSCapture48\FSCapture.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
C:\Users\Aleksandar\Desktop\zoek.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\cmd.exe

==== Files Recently Created / Modified ======================

====== C:\Windows ====
====== C:\Users\ALEKSA~1\AppData\Local\Temp ====
====== Java Cache =====
====== C:\Windows\SysWOW64 =====
2014-10-23 16:24:18 262AD0EF90F757FB715B3EDD6A8E469C 778936 ----a-w- C:\Windows\SysWOW64\PresentationNative_v0300.dll
2014-10-23 16:24:18 2083BD93AE43F9494318B422FF8943D1 102608 ----a-w- C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2014-10-23 16:24:18 134F0E458D2DBDC297CD785F53F7129F 35480 ----a-w- C:\Windows\SysWOW64\TsWpfWrp.exe
====== C:\Windows\SysWOW64\drivers =====
====== C:\Windows\Sysnative =====
2014-10-26 15:09:03 C1CAC3EBBDB3FE0131A9672E43EDB764 29704 ----a-w- C:\Windows\Sysnative\nitrolocalmon2.dll
2014-10-26 15:09:03 530B66672AE8BD426157DE42732E25B1 17928 ----a-w- C:\Windows\Sysnative\nitrolocalui2.dll
2014-10-23 16:24:15 E35AD6DAECED1213658E0976A16D6266 1166520 ----a-w- C:\Windows\Sysnative\PresentationNative_v0300.dll
2014-10-23 16:24:15 DF290FC4E1116D92F34D8B6410AE544E 124112 ----a-w- C:\Windows\Sysnative\PresentationCFFRasterizerNative_v0300.dll
2014-10-23 16:24:15 A0E7332DC41BB85FBE8E266B8CDF5AC4 35480 ----a-w- C:\Windows\Sysnative\TsWpfWrp.exe
====== C:\Windows\Sysnative\drivers =====
====== C:\Windows\Tasks ======
====== C:\Windows\Temp ======
======= C:\Program Files =====
2014-10-26 14:59:29 -------- d-----w- C:\Program Files\Common Files\Nitro
2014-10-23 16:30:45 -------- d-----w- C:\Program Files\Reference Assemblies
2014-10-23 16:30:45 -------- d-----w- C:\Program Files\MSBuild
======= C:\PROGRA~2 =====
2014-10-26 14:59:15 -------- d-----w- C:\PROGRA~2\COMMON~1\Nitro
2014-10-26 14:58:58 -------- d-----w- C:\PROGRA~2\Nitro
2014-10-23 16:34:20 -------- d-----w- C:\PROGRA~2\BetterPoEditor
2014-10-23 16:31:06 -------- d-----w- C:\PROGRA~2\Reference Assemblies
======= C: =====
====== C:\Users\Aleksandar\AppData\Roaming ======
2014-10-26 15:17:06 -------- d-----w- C:\Users\Aleksandar\AppData\Roaming\Nitro
2014-10-26 14:51:06 -------- d-----w- C:\Users\Aleksandar\AppData\Roaming\Downloaded Installations
2014-10-23 16:34:52 -------- d-----w- C:\Users\Aleksandar\AppData\Local\Michele_Locati
2014-10-22 23:25:42 -------- d-----w- C:\Users\Aleksandar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-10-22 23:19:45 -------- d-----w- C:\Users\Aleksandar\AppData\Roaming\Dropbox
2014-10-14 16:32:54 -------- d-----w- C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google
====== C:\Users\Aleksandar ======
2014-10-26 15:21:04 0FF660E032AEE5C0B44A2D9E3BAE65A5 2113024 ----a-w- C:\Users\Aleksandar\Desktop\FRST64.exe
2014-10-26 14:58:58 -------- d-----w- C:\ProgramData\Nitro
2014-10-25 18:16:02 C01900034966F722ED450F1CC6CDD2AC 6126536 ----a-w- C:\Users\Aleksandar\Downloads\FileZilla_3.9.0.6_win32-setup.exe
2014-10-23 16:34:21 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BetterPoEditor
2014-10-22 23:28:07 -------- d-----r- C:\Users\Aleksandar\Dropbox
2014-10-22 23:18:01 3757254F501BAE3264C86513999F1BCD 323672 ----a-w- C:\Users\Aleksandar\Desktop\DropboxInstaller.exe

====== C: exe-files ==
2014-10-26 15:21:04 0FF660E032AEE5C0B44A2D9E3BAE65A5 2113024 ----a-w- C:\Users\Aleksandar\Desktop\FRST64.exe
2014-10-25 18:16:02 C01900034966F722ED450F1CC6CDD2AC 6126536 ----a-w- C:\Users\Aleksandar\Downloads\FileZilla_3.9.0.6_win32-setup.exe
2014-10-23 16:34:20 EC5CB5AA03AE99EB3AF77D1BDA2568DF 249856 ----a-w- C:\Program Files (x86)\BetterPoEditor\BetterPoEditor.exe
2014-10-23 16:34:20 8CFCF204C146B131CF458F4419B4662A 715253 ----a-w- C:\Program Files (x86)\BetterPoEditor\unins000.exe
2014-10-23 16:34:20 75736764DE6376A82080B18E1C0DD49F 110592 ----a-w- C:\Program Files (x86)\BetterPoEditor\NetSpell.DictionaryBuild.exe
2014-10-23 16:34:20 7255663AADAEB4A37C9DC0D758AC588D 2754417 ----a-w- C:\Program Files (x86)\BetterPoEditor\tools\msgfmt.exe
2014-10-23 16:24:15 A0E7332DC41BB85FBE8E266B8CDF5AC4 35480 ----a-w- C:\Windows\System32\TsWpfWrp.exe
2014-10-22 23:25:25 5FD0245516E2A06C527FDB04F0555071 225296 ----a-w- C:\Users\Aleksandar\AppData\Roaming\Dropbox\bin\DropboxUpdateHelper.exe
2014-10-22 23:25:24 93680B96D6C7998998057BA457F2FFBF 35487064 ----a-w- C:\Users\Aleksandar\AppData\Roaming\Dropbox\bin\Dropbox.exe
2014-10-22 23:18:01 3757254F501BAE3264C86513999F1BCD 323672 ----a-w- C:\Users\Aleksandar\Desktop\DropboxInstaller.exe
2014-10-22 17:39:22 68270679465EC5A66B65489C6E44AD64 11100752 ----a-w- C:\Program Files (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\38.0.2125.104\38.0.2125.104_37.0.2062.124_chrome_updater.exe
=== C: other files ==
2014-10-25 19:39:40 EF9F78AEFDB3CAD71748B187C159A130 266160 ----a-w- C:\Users\Aleksandar\Desktop\salmont bekap 25.10.2014\flatsome\inc\plugins\nextend-facebook-connect.zip
2014-10-25 19:39:39 AABEB088A92B7131986121EC0B6FF5C7 3695 ----a-w- C:\Users\Aleksandar\Desktop\salmont bekap 25.10.2014\flatsome\inc\plugins\taxonomy-metadata.zip
2014-10-25 19:39:39 AA2415A71AE0E54750D8A8EEABA76729 26405 ----a-w- C:\Users\Aleksandar\Desktop\salmont bekap 25.10.2014\flatsome\inc\plugins\woosidebars.zip
2014-10-25 19:39:39 925876720F6CBB4342D486E434576553 182835 ----a-w- C:\Users\Aleksandar\Desktop\salmont bekap 25.10.2014\flatsome\inc\plugins\regenerate-thumbnails.zip
2014-10-25 19:39:39 1C57EC5DEF59C03DAB8F84250427AAB2 57053 ----a-w- C:\Users\Aleksandar\Desktop\salmont bekap 25.10.2014\flatsome\inc\plugins\yith-woocommerce-ajax-search.zip
2014-10-23 21:10:36 2BEB1FD0D6AA8B4F8E4A058A5CBFB9E0 1721592 ----a-w- C:\Users\Aleksandar\Desktop\zip\photoshop_letterpress_effect_psd_by_g_seven-d4j8ids.zip
2014-10-23 17:33:50 CD519825E2A964F1660B81FA300A985A 8950609 ----a-w- C:\Users\Aleksandar\Desktop\zip\Quick letter pressed text effect.zip
2014-10-22 23:34:29 25DF3415AD5C084B101110923C187700 40591372 ----a-w- C:\Users\Aleksandar\Dropbox\Knjige\pesma leda i vatre.zip
2014-10-22 23:25:24 2CECD4EA4A73E70B02159E1DBB1DBCE3 1129310 ----a-w- C:\Users\Aleksandar\AppData\Roaming\Dropbox\bin\xui_resources.zip
2014-10-20 17:55:24 332A6B74A45F3EE6A02B4979551216F5 46323 ----a-w- C:\Users\Aleksandar\Desktop\zip\bodoni_svtytwo_sc_itc_tt_book.zip

==== Startup Registry Enabled ======================

[HKEY_USERS\S-1-5-21-468891226-946991927-1053560233-1001\Software\Microsoft\Windows\CurrentVersion\Run]
"LightShot"="C:\Users\Aleksandar\AppData\Local\Skillbrains\lightshot\Lightshot.exe"
"MCShield Monitor"="C:\Program Files (x86)\MCShield\mcshieldrtm.exe"
"Facebook Update"="C:\Users\Aleksandar\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver"
"Messenger (Yahoo\PROGRA~2\Yahoo\Messenger\YahooMessenger.exe -quiet"
"Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe MSRun"
"AMD AVT"="Cmd.exe /c start AMD Accelerated Video Transcoding device initialization /min C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe aml"
"SwitchBoard"="C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe"
"AdobeCS6ServiceManager"="C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe -launchedbylogin"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"LightShot"="C:\Users\Aleksandar\AppData\Local\Skillbrains\lightshot\Lightshot.exe"
"MCShield Monitor"="C:\Program Files (x86)\MCShield\mcshieldrtm.exe"
"Facebook Update"="C:\Users\Aleksandar\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver"
"Messenger (Yahoo\PROGRA~2\Yahoo\Messenger\YahooMessenger.exe -quiet"
"Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun"

==== Startup Registry Enabled x64 ======================

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdobeAAMUpdater-1.0"="C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"

==== Startup Folders ======================

2014-10-22 23:27:10 1103 ----a-w- C:\Users\Aleksandar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
2014-10-05 16:13:05 769 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FastStone Capture.lnk

==== Task Scheduler Jobs ======================

C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-468891226-946991927-1053560233-1001Core.job --a-------- C:\Users\Aleksandar\AppData\Local\Facebook\Update\FacebookUpdate.exC: nocrashserverDeltaBH\AleksandarKeeps your Facebook software up to date. If this task is disabled or stopped your Facebook software will not be kept up to date meaning sC:urity vulnerabilities that may arise cannot be fixed and features may not work. This task uninstalls itself when there is no Facebook software using it.0 []
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-468891226-946991927-1053560233-1001UA.job --a-------- [Undetermined Task]
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a-------- [Undetermined Task]
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a-------- [Undetermined Task]
C:\Windows\tasks\update-S-1-5-21-468891226-946991927-1053560233-1001.job --a-------- [Undetermined Task]
C:\Windows\tasks\update-sys.job --a-------- [Undetermined Task]

==== Other Scheduled Tasks ======================

"C:\Windows\SysNative\tasks\AdobeAAMUpdater-1.0-DeltaBH-Aleksandar" [C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe]
"C:\Windows\SysNative\tasks\AutoKMS" [C:\Windows\AutoKMS\AutoKMS.exe]
"C:\Windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"]
"C:\Windows\SysNative\tasks\FacebookUpdateTaskUserS-1-5-21-468891226-946991927-1053560233-1001Core" [C:\Users\Aleksandar\AppData\Local\Facebook\Update\FacebookUpdate.exe]
"C:\Windows\SysNative\tasks\FacebookUpdateTaskUserS-1-5-21-468891226-946991927-1053560233-1001UA" [C:\Users\Aleksandar\AppData\Local\Facebook\Update\FacebookUpdate.exe]
"C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe]
"C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe]
"C:\Windows\SysNative\tasks\update-S-1-5-21-468891226-946991927-1053560233-1001" [C:\Program Files (x86)\Skillbrains\Updater\Updater.exe]
"C:\Windows\SysNative\tasks\update-sys" [C:\Program Files (x86)\Skillbrains\Updater\Updater.exe]
"C:\Windows\SysNative\tasks\{CE6A2F4C-155B-4B00-AB09-AAC15FC4430D}" ["c:\program files (x86)\google\chrome\application\chrome.exe"]
"C:\Windows\SysNative\tasks\{FC6BF67D-4C04-4B88-9208-18F55F0B75BF}" ["c:\program files (x86)\google\chrome\application\chrome.exe"]
"C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc]

==== Chromium Look ======================

Entanglement Web App - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd
Note Board Web - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\apgackkfllmckgkbdfmbfodpinmnnpab
Google Voice Search Hotword (Beta) - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn
WOT - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp
Honey - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj
ClickClean - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghgabhipcejejjmhhchfonmamedcbeod
AdBlock - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom
PDF Mergy - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgecghmkcdefnknohcimkoemhaofpoha
Bitly | Unleash the power of the link - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\iabeihobmhlgpkcgjiloemdbofjbdcic
Free online speed typing tests find whats your WPM words per minute speed improve your typing skills and practice typing. - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkcieoaeooeidmpaopkpjpjfakidlabm
Todoist To-Do list and Task Manager - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\jldhpllghnbhlbpcmnajkpdmadaolakh
Auto Replay for YouTube™ - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\kanbnempkjnhadplbfgdaagijdbdbjeb
Google Mail Checker - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff
Quick Note - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\mijlebbfndhelmdpmllgcfadlkankhok
Google Wallet - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Buffer - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\noojglkidnpfjbincgijbaiedldjfbhh
Background Tab - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\oehpjpccmlcalbenfhnacjeocbjdonic
ClickClean App - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp

==== IE Start and Search Settings ======================

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR"

==== C:\zoek_backup content ======================

C:\zoek_backup (files=0 folders=0 0 bytes)

==== EOF on ned. 26.10.2014. at 18:18:04,57 ======================

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

U postavljenom izvještaju nisam našao ništa sporno. Obavićemo još jednu provjeru.


Preuzmi Malwarebytes Anti-Rootkit (MBAR) sa sledeceg linka i sacuvaj ga na Desktop.

Dvoklikom pokreni MBAR () na ikonicu programa:
- Klikni OK na sledecem prozoru da bi dozvolio raspakivanje u zaseban mbar folder na desktop-u;
- mbar.exe ce biti startovan. Na nekim sistemima to moze da potraje nekoliko dodatnih sekundi, te pricekati pokretanje.;
- U uvodnom prozoru klikni dugme Next ukoliko si saglasan;



• Na 'Update Database' prozoru klik na dugme Update da bi preuzeo sveze definicije. Kada se ispise poruka 'Success: Database was successfully updated' klik na dugme Next;
• Pod sekcijom 'Scan Targets' proveri da su sve opcije stiklirane, te klikni na dugme Scan;

Obavestenje: sa nekim infekcijama moze se desiti da se prikaze neka od sledecih poruka:
- 'Could not load protection driver' => u tom slucaju klikni OK.
- 'Could not load DDA driver' => klikni Yes na to obavestenje da bi dozvolio ucitavanje nakon restarta. Dozvoli restart i nastavi sa ostatkom instrukcija posle restarta.





>> Ukoliko malware nije detektovan, klik na Exit dugme da zatvoris program. U sledecu poruku postavi mbar-log-year-month-day (sat-minuti-sekundi).txt i system-log.txt izveštaje.

>> Ukoliko su infekcija/e pronadjene, proveriti da li je obelezena opcija 'Create Restore Point' i klikni na dugme Cleanup! da bi uklonili pretnje.
- Procedura uklanjanje malware-a (scheduled) ce biti zakazana po restartu, bice prikazano obavestenje u pop-up prozoru. Klikni dugme Yes i sistem bi trebao da se restartuje i da zavrsi proceduru ciscenja.



Obavestenje! samo ukoliko je RootKit detektovan: - postaraj se da pokrenes fixdamage.exe alat koji se nalazi u mbar folderu, \Plugins\fixdamage.exe:
- Dvoklikom pokreni fixdamage, u crnom prozoru koji se otvori (command prompt) ukucaj Y (Y stoji za Yes) da bi nastavio izvrsenje, pricekati da alat odradi sve popravke ...
- Kada vidis poruku 'press any key to exit' popravka je kompletirana. Pritisnuti bilo koju tipku na tastaturi da bi se prozor zatvorio. Restartovati sistem.





Sledeci izvestaji ce biti formirani u mbar folderu.
1. mbar-log-year-month-day (hour-minute-second).txt
2. system-log.txt

Iskopiraj sadrzaj mbar log-a u poruku a system log okaci uz poruku koristeci opciju Prikači fajl.

offline
  • Pridružio: 11 Jul 2012
  • Poruke: 46

Malwarebytes Anti-Rootkit BETA 1.07.0.1012
malwarebytes.org

Database version: v2014.10.30.11

Windows 8.1 x64 NTFS
Internet Explorer 11.0.9600.17031
Aleksandar :: DELTABH [administrator]

30.10.2014. 18:17:36
mbar-log-2014-10-30 (18-17-36).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 316529
Time elapsed: 33 minute(s),

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)

mycity.rs/must-login.png

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Tvoj računar je čist što se malicioznih programa tiče. Otvori temu u Windows potforumu i tamo iznesi svoj problem.

Sledeća procedura će implementirati završno čišćenje.

Arrow Preuzmi "Xplode"-ov DelFix alat i snimi ga na Desktop.
Dvoklikom pokreni alat i štikliraj kućice ispred sledećih opcija;

Remove disinfection tools
Create registry backup
Purge System Restore


Klikni na dugme Run i pričekaj trenutak dok alat ne završi svoj rad.
Od ovog trenutka, svi korišćeni alati u ovoj temi bi trebali biti obrisani.
Alat će takođe formirati izveštaj za tebe. (C:\DelFix.txt)

Alat će snimiti i zdravo stanje registy-ja i napraviti backup koristeci integrisan program "ERUNT" u %windir%\ERUNT\DelFix
Alat briše stare system restore tačke i pravi novu, svežu tačku nakon čišćenja.

offline
  • Pridružio: 11 Jul 2012
  • Poruke: 46

Hvala.

Srdačan pozdrav i ugodan ostatak dana!

Ko je trenutno na forumu
 

Ukupno su 834 korisnika na forumu :: 39 registrovanih, 7 sakrivenih i 788 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: Acivi, aleksandarbl, bato, ccoogg123, darionis, darios, Dimitrije Paunovic, gmlale, goxin, havoc995, hyla, ILGromovnik, Ivica1102, ivica976, Joja, kjkszpj, Koridor, Kriglord, ljuba, Lubica, Maschinekalibar, milenko crazy north, miodrag, Misirac, nemkea71, NoOneEver Dreams, ObelixSRB, oganj123, Panter, savaskytec, Sir Budimir, slonic_tonic, Srky Boy, stegonosa, theNedjeljko, Tvrtko I, Viceroy, virked, Wrangler