Iskacu mi reklame kao lude!

2

Iskacu mi reklame kao lude!

offline
  • Pridružio: 15 Feb 2011
  • Poruke: 94

Reinstalirao chrome ali ekstenzije nece da rade...

online
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8039
  • Gde živiš: Novi Beograd

Ne znam zasto nece. Probaj nesto od ovog: https://productforums.google.com/forum/#!topic/chrome/C6mHMe8-kBY

offline
  • Pridružio: 15 Feb 2011
  • Poruke: 94

Uspeo sam uz pomoc .crx fajlova od ove dve ekstenzije.
Puno puno puno hvala za pomoc.

Kako da pobrisem ove alate sa kojima su skidani virusi?

online
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8039
  • Gde živiš: Novi Beograd

Ako taj DVBViewer ne vrsi posao, deinstaliraj ga preko Control Panela. Ja nisam uspeo da saznam koliku opasnost predstavlja, ili je taj adware dosao uz njega samo.

Takodje, u istom trenutku su stigli i ovi dole navedeni folderi. Folderi su legitimni, al ocito nisi ih zeleo, tako da to mozes isto da obrises, ako ti ne treba:

C:\WINDOWS\IObit
C:\Users\aca\AppData\LocalLow\IObit
C:\ProgramData\IObit
C:\Users\aca\AppData\Roaming\IObit

---------------

Sledeća procedura će implementirati završno čišćenje.



Arrow Preuzmi "Xplode"-ov DelFix alat i snimi ga na Desktop.

Dvoklikom pokreni alat i štikliraj kućice ispred sledećih opcija;
Remove disinfection tools
Create registry backup
Purge System Restore


Klikni na dugme Run i pričekaj trenutak dok alat ne završi svoj rad.

Od ovog trenutka, svi korišćeni alati u ovoj temi bi trebali biti obrisani.
Ukoliko neki alat ili izveštaj nije uklonjen, slobodno ih obriši ručno.


Alat će takođe formirati izveštaj za tebe. (C:\DelFix.txt)
- Alat će snimiti i zdravo stanje registy-ja i napraviti backup koristeci integrisan program "ERUNT" u %windir%\ERUNT\DelFix
- DelFix briše stare system restore tačke i pravi novu, svežu tačku nakon čišćenja.

offline
  • Pridružio: 15 Feb 2011
  • Poruke: 94

Napisano: 11 Jan 2017 20:02

Moram ponovo da aktiviram ovo.
Razlog je ovaj;





Danas sam dosao sa posla,upalio net i vidim ovo se pojavilo.

Primecujem da je net u bas losem stanju danas.mislio sam da je zbog ovog vremena ali me sad i ovo buni sa ovim prozorom sto iskace.

Posatavicu opet logove.

Dopuna: 11 Jan 2017 20:06

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 11-01-2017
Ran by aca (administrator) on DESKTOP-TKJJRE0 (11-01-2017 20:02:39)
Running from C:\Users\aca\Desktop
Loaded Profiles: aca (Available Profiles: aca)
Platform: Windows 10 Pro Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: geekstogo.com/forum/topic/335081-frst-t.....scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Garmin Ltd. or its subsidiaries) C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe
(@ByELDI) C:\Program Files\KMSpico\Service_KMS.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.145.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Corporation) C:\Windows\System32\osk.exe
(Microsoft Corporation) C:\Windows\System32\AtBroker.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\SppExtComObj.Exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13877464 2015-05-15] (Realtek Semiconductor)
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-09-07] (Microsoft Corporation)
HKLM-x32\...\Run: [Raptr] => C:\Program Files (x86)\Raptr Inc\Raptr\raptrstub.exe [58640 2016-08-23] (Raptr, Inc)
HKLM-x32\...\Run: [PowerDVD16Agent] => C:\Program Files (x86)\CyberLink\PowerDVD16\PowerDVD16Agent.exe [525352 2016-07-07] (CyberLink Corp.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-09-22] (Oracle Corporation)
HKU\S-1-5-21-3854506088-2188221789-2845878084-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [23818360 2016-11-30] (Google)
HKU\S-1-5-21-3854506088-2188221789-2845878084-1001\...\Run: [Viber] => C:\Users\aca\AppData\Local\Viber\Viber.exe [41351248 2016-12-07] (Viber Media S.à r.l.)
HKU\S-1-5-21-3854506088-2188221789-2845878084-1001\...\Run: [Sony PC Companion] => C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [457088 2015-09-23] (Sony)
HKU\S-1-5-21-3854506088-2188221789-2845878084-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4289728 2016-04-04] (Disc Soft Ltd)
HKU\S-1-5-21-3854506088-2188221789-2845878084-1001\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1407912 2016-11-29] (Garmin Ltd. or its subsidiaries)
HKU\S-1-5-21-3854506088-2188221789-2845878084-1001\...\MountPoints2: {1cd55e35-0e47-11e6-a16e-fcaa1455c31f} - "G:\Setup.exe"
HKU\S-1-5-21-3854506088-2188221789-2845878084-1001\...\MountPoints2: {1cd56658-0e47-11e6-a16e-fcaa1455c31f} - "D:\Setup.exe"
HKU\S-1-5-18\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1407912 2016-11-29] (Garmin Ltd. or its subsidiaries)
IFEO\OSppSvc.exe: [Debugger] KMS-R@1nHook.exe
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
Startup: C:\Users\aca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sidebar739.lnk [2017-01-11]
ShortcutTarget: Sidebar739.lnk -> C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
GroupPolicy: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{859ccec6-8666-450c-af15-d9210332362b}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{86031528-50c3-480a-802d-0d79c04a8b15}: [DhcpNameServer] 192.168.1.1 192.168.1.1

Internet Explorer:
==================
HKU\S-1-5-21-3854506088-2188221789-2845878084-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office16\OCHelper.dll [2015-07-31] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL [2015-07-31] (Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office16\OCHelper.dll [2015-07-31] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll [2016-10-22] (Oracle Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office16\GROOVEEX.DLL [2015-07-31] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-10-22] (Oracle Corporation)
Handler: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation)

FireFox:
========
FF DefaultProfile: t5i6mpri.default
FF ProfilePath: C:\Users\aca\AppData\Roaming\Mozilla\Firefox\Profiles\t5i6mpri.default [2017-01-11]
FF Extension: (X-notifier (for Gmail™,Hotmail,Yahoo,AOL...)) - C:\Users\aca\AppData\Roaming\Mozilla\Firefox\Profiles\t5i6mpri.default\Extensions\{37fa1426-b82d-11db-8314-0800200c9a66}.xpi [2016-11-30]
FF SearchPlugin: C:\Users\aca\AppData\Roaming\Mozilla\Firefox\Profiles\t5i6mpri.default\searchplugins\g8skjwn1.xml [2017-01-09]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_24_0_0_186.dll [2016-12-18] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWoW64\Macromed\Flash\NPSWF32_24_0_0_186.dll [2016-12-18] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll [2015-11-18] (Adobe Systems, Inc.)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2015-12-29] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2015-12-29] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2015-12-29] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2015-12-29] (Foxit Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-10-22] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-10-22] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-07-31] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin-x32: @verimatrix.com/ViewRightWeb -> C:\Program Files (x86)\Verimatrix\ViewRight Web\\npViewRight.dll [2015-04-06] (Verimatrix, Inc.)
FF Plugin HKU\S-1-5-21-3854506088-2188221789-2845878084-1001: @verimatrix.com/ViewRightWeb -> C:\Program Files (x86)\Verimatrix\ViewRight Web\\npViewRight.dll [2015-04-06] (Verimatrix, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-07-31] (Microsoft Corporation)

Chrome:
=======
CHR HomePage: Default -> hxxp://www.elitesecurity.org/f101
CHR Profile: C:\Users\aca\AppData\Local\Google\Chrome\User Data\Default [2017-01-11]
CHR Extension: (Magic Actions for YouTube™) - C:\Users\aca\AppData\Local\Google\Chrome\User Data\Default\Extensions\abjcfabbhafbcdfjoecdgepllmpfceif [2017-01-10]
CHR Extension: (Docs) - C:\Users\aca\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-01-09]
CHR Extension: (Google Drive) - C:\Users\aca\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-01-09]
CHR Extension: (YouTube) - C:\Users\aca\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-01-09]
CHR Extension: (X-notifier (for Gmail™,Hotmail,Yahoo,AOL...)) - C:\Users\aca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdfjbkbddpfnoplfhceolpopfoepleco [2017-01-09]
CHR Extension: (AdBlock) - C:\Users\aca\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-01-09]
CHR Extension: (Gmail) - C:\Users\aca\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-01-09]
CHR HKU\S-1-5-21-3854506088-2188221789-2845878084-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1443520 2016-04-04] (Disc Soft Ltd)
R2 Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [1029648 2016-11-29] (Garmin Ltd. or its subsidiaries)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [373744 2016-11-01] (Intel Corporation)
S2 KMS-R@1n; C:\Windows\KMS-R@1n.exe [26112 2015-12-08] () [File not signed]
S3 PAExec; C:\Windows\PAExec.exe [189112 2016-07-16] (Power Admin LLC)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2016-09-15] (Microsoft Corporation)
R2 Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [739520 2015-09-27] (@ByELDI) [File not signed]
S3 ShareItSvc; C:\Program Files (x86)\SHAREit\SHAREit\Shareit.Service.exe [31176 2016-01-14] (SHAREit Technologies Co.Ltd)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
S2 Shbuscmety; C:\Program Files (x86)\Fulwarddronerle\hoperghtuhewardProvider.dll [X]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S0 amdkmafd; C:\WINDOWS\System32\drivers\amdkmafd.sys [49448 2016-08-18] (Advanced Micro Devices, Inc.)
R3 amdkmdag; C:\WINDOWS\System32\DriverStore\FileRepository\c0309270.inf_amd64_47c09dd18e1ee4c5\atikmdag.sys [28729240 2016-12-07] (Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\WINDOWS\System32\DriverStore\FileRepository\c0309270.inf_amd64_47c09dd18e1ee4c5\atikmpag.sys [530328 2016-12-07] (Advanced Micro Devices, Inc.)
R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [101376 2016-07-24] (Advanced Micro Devices)
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2015-12-08] (Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2016-04-30] (Disc Soft Ltd)
R1 HWiNFO32; C:\WINDOWS\SysWoW64\drivers\HWiNFO64A.SYS [27552 2017-01-09] (REALiX(tm))
R1 MpKsla0b4a154; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{85CD3B90-C3B5-4009-867B-ABA32EBB618B}\MpKsla0b4a154.sys [44928 2017-01-11] (Microsoft Corporation)
R1 MpKslb4ccc78f; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CDFCF55-AE21-4A22-AFAF-557537CEAC86}\MpKslb4ccc78f.sys [44928 2017-01-09] (Microsoft Corporation)
R3 MTSBDA; C:\WINDOWS\System32\Drivers\MtsBda.sys [344592 2009-07-13] (TechniSat Provide)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
S3 ptun0901; C:\WINDOWS\System32\drivers\ptun0901.sys [27136 2014-08-08] (The OpenVPN Project)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [589824 2016-07-16] (Realtek )
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
R2 {41E8078B-96D9-42DC-8789-A1CF102CD880}; C:\Program Files (x86)\CyberLink\PowerDVD16\Common\NavFilter\000.fcl [38168 2016-07-05] (CyberLink Corp.)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-01-11 20:03 - 2017-01-11 20:03 - 00000020 _____ C:\Users\aca\Desktop\slike.rar
2017-01-11 20:02 - 2017-01-11 20:03 - 00017238 _____ C:\Users\aca\Desktop\FRST.txt
2017-01-11 20:01 - 2017-01-11 20:02 - 00000000 ____D C:\FRST
2017-01-11 20:00 - 2017-01-11 20:00 - 02419200 _____ (Farbar) C:\Users\aca\Desktop\FRST64.exe
2017-01-11 19:53 - 2017-01-11 19:54 - 00000894 _____ C:\DelFix.txt
2017-01-10 22:11 - 2017-01-10 22:11 - 00000000 ____D C:\Users\aca\Desktop\TransEdit 4.0.1
2017-01-10 22:06 - 2017-01-10 22:06 - 02273713 _____ C:\Users\aca\Desktop\TransEdit 4.0.1.rar
2017-01-10 22:02 - 2017-01-10 22:02 - 00157877 _____ C:\Users\aca\Desktop\Hadu_CCCam_DVB_plugin_beta0.127.zip
2017-01-10 22:01 - 2017-01-10 22:02 - 00506816 _____ C:\Users\aca\Desktop\ACamd_v0.6.2.0.rar
2017-01-10 18:30 - 2017-01-10 18:30 - 00003968 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier
2017-01-10 18:30 - 2017-01-10 18:30 - 00000892 _____ C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job
2017-01-09 21:43 - 2017-01-09 21:43 - 00002348 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-01-09 21:43 - 2017-01-09 21:43 - 00002336 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-01-09 17:52 - 2017-01-09 17:52 - 00027552 _____ (REALiX(tm)) C:\WINDOWS\SysWOW64\Drivers\HWiNFO64A.SYS
2017-01-09 17:52 - 2017-01-09 17:52 - 00000000 ____D C:\WINDOWS\IObit
2017-01-09 17:52 - 2017-01-09 17:52 - 00000000 ____D C:\Users\aca\AppData\LocalLow\IObit
2017-01-09 17:52 - 2017-01-09 17:52 - 00000000 ____D C:\ProgramData\IObit
2017-01-09 17:51 - 2017-01-09 17:51 - 00000000 ____D C:\Users\aca\AppData\Roaming\IObit
2017-01-09 17:25 - 2017-01-09 17:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVBViewer Suite
2017-01-08 17:22 - 2017-01-08 17:25 - 00008528 _____ C:\Users\aca\Desktop\todo.xlsx
2017-01-07 21:57 - 2017-01-07 21:57 - 00000000 ____D C:\Users\aca\AppData\Roaming\PotPlayerMini
2017-01-07 21:55 - 2017-01-07 21:55 - 00000000 ____D C:\Program Files (x86)\DAUM
2017-01-07 21:18 - 2017-01-07 21:18 - 00000000 ____D C:\Program Files (x86)\madVR
2017-01-06 22:33 - 2017-01-07 21:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Daum
2017-01-06 22:33 - 2017-01-07 21:48 - 00000000 ____D C:\Program Files\DAUM
2017-01-06 20:44 - 2017-01-06 20:44 - 00000000 ____D C:\Users\aca\AppData\Local\Foxit Reader
2016-12-31 01:52 - 2016-12-31 01:52 - 00000000 ____D C:\Users\aca\Documents\Rise of the Tomb Raider
2016-12-31 01:52 - 2016-12-31 01:52 - 00000000 ____D C:\Users\aca\AppData\Roaming\Crystal Dynamics
2016-12-31 01:44 - 2016-12-31 01:46 - 00000000 ____D C:\WINDOWS\SysWOW64\directx
2016-12-31 01:44 - 2016-12-31 01:44 - 00001022 _____ C:\Users\Public\Desktop\Rise of the Tomb Raider.lnk
2016-12-31 01:44 - 2016-12-31 01:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rise of the Tomb Raider
2016-12-31 01:17 - 2016-12-31 01:18 - 01519575 _____ C:\Users\aca\Desktop\x360ce_x64.zip
2016-12-31 01:15 - 2016-12-31 01:15 - 00000000 ____D C:\Program Files (x86)\CorePack
2016-12-24 19:59 - 2017-01-10 18:01 - 00000000 ____D C:\Users\aca\AppData\Local\Viber
2016-12-21 07:59 - 2016-12-21 07:59 - 00002729 _____ C:\Users\aca\Desktop\Chicken Invaders 5 - Cluck of the Dark Side Christmas Edition.lnk
2016-12-21 07:59 - 2016-12-21 07:59 - 00000000 ____D C:\Users\aca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chicken Invaders 5 - Cluck of the Dark Side Christmas Edition
2016-12-21 07:59 - 2016-12-21 07:59 - 00000000 ____D C:\Program Files (x86)\LeeGT-Games
2016-12-19 00:28 - 2016-12-19 00:28 - 00000367 _____ C:\Users\aca\AppData\Roaming\Weather Meter_Settings.ini
2016-12-18 19:02 - 2016-12-18 19:02 - 00000000 ____D C:\Users\aca\AppData\LocalLow\AMD
2016-12-18 18:12 - 2016-12-18 18:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Problem Report Wizard
2016-12-18 18:11 - 2016-12-18 18:11 - 00003288 _____ C:\WINDOWS\System32\Tasks\StartCN
2016-12-18 18:11 - 2016-12-18 18:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Settings
2016-12-13 20:38 - 2016-12-09 11:42 - 01637728 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2016-12-13 20:38 - 2016-12-09 11:42 - 00137568 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2016-12-13 20:38 - 2016-12-09 11:34 - 01051112 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2016-12-13 20:38 - 2016-12-09 11:34 - 00894096 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-12-13 20:38 - 2016-12-09 11:33 - 01354320 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-12-13 20:38 - 2016-12-09 11:33 - 01173496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-12-13 20:38 - 2016-12-09 11:32 - 07816032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-12-13 20:38 - 2016-12-09 11:30 - 00377184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2016-12-13 20:38 - 2016-12-09 11:29 - 02681200 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2016-12-13 20:38 - 2016-12-09 11:28 - 00764392 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2016-12-13 20:38 - 2016-12-09 11:27 - 00172528 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspicli.dll
2016-12-13 20:38 - 2016-12-09 11:20 - 02677544 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2016-12-13 20:38 - 2016-12-09 11:20 - 02189664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2016-12-13 20:38 - 2016-12-09 11:20 - 01738560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2016-12-13 20:38 - 2016-12-09 11:20 - 00658784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2016-12-13 20:38 - 2016-12-09 11:20 - 00402272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2016-12-13 20:38 - 2016-12-09 11:19 - 01293152 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2016-12-13 20:38 - 2016-12-09 11:19 - 00168424 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcrypt.dll
2016-12-13 20:38 - 2016-12-09 11:18 - 02913144 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2016-12-13 20:38 - 2016-12-09 11:18 - 01267512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2016-12-13 20:38 - 2016-12-09 11:18 - 01100128 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2016-12-13 20:38 - 2016-12-09 11:18 - 00989024 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2016-12-13 20:38 - 2016-12-09 11:18 - 00947552 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.efi
2016-12-13 20:38 - 2016-12-09 11:18 - 00811872 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.exe
2016-12-13 20:38 - 2016-12-09 11:18 - 00624048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-12-13 20:38 - 2016-12-09 11:15 - 08168000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2016-12-13 20:38 - 2016-12-09 11:15 - 01988560 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2016-12-13 20:38 - 2016-12-09 11:14 - 01274712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2016-12-13 20:38 - 2016-12-09 11:14 - 00241504 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2016-12-13 20:38 - 2016-12-09 11:11 - 02048496 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2016-12-13 20:38 - 2016-12-09 11:10 - 01572768 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2016-12-13 20:38 - 2016-12-09 11:10 - 01461200 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2016-12-13 20:38 - 2016-12-09 11:09 - 00455520 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2016-12-13 20:38 - 2016-12-09 11:01 - 02323728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2016-12-13 20:38 - 2016-12-09 11:01 - 01503544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2016-12-13 20:38 - 2016-12-09 11:01 - 00861024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2016-12-13 20:38 - 2016-12-09 11:00 - 00106896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcrypt.dll
2016-12-13 20:38 - 2016-12-09 10:59 - 02166752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2016-12-13 20:38 - 2016-12-09 10:59 - 00846560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2016-12-13 20:38 - 2016-12-09 10:57 - 06668040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2016-12-13 20:38 - 2016-12-09 10:57 - 01852720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2016-12-13 20:38 - 2016-12-09 10:56 - 00959112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2016-12-13 20:38 - 2016-12-09 10:52 - 01435896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2016-12-13 20:38 - 2016-12-09 10:52 - 01415752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2016-12-13 20:38 - 2016-12-09 10:51 - 00117240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sspicli.dll
2016-12-13 20:38 - 2016-12-09 10:47 - 22563328 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-12-13 20:38 - 2016-12-09 10:45 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2016-12-13 20:38 - 2016-12-09 10:45 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\WordBreakers.dll
2016-12-13 20:38 - 2016-12-09 10:42 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2016-12-13 20:38 - 2016-12-09 10:41 - 00380928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll
2016-12-13 20:38 - 2016-12-09 10:41 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WordBreakers.dll
2016-12-13 20:38 - 2016-12-09 10:40 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2016-12-13 20:38 - 2016-12-09 10:38 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2016-12-13 20:38 - 2016-12-09 10:37 - 00411136 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll
2016-12-13 20:38 - 2016-12-09 10:37 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll
2016-12-13 20:38 - 2016-12-09 10:37 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-12-13 20:38 - 2016-12-09 10:36 - 06285312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2016-12-13 20:38 - 2016-12-09 10:36 - 03059200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2016-12-13 20:38 - 2016-12-09 10:36 - 00425984 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2016-12-13 20:38 - 2016-12-09 10:36 - 00410112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2016-12-13 20:38 - 2016-12-09 10:36 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2016-12-13 20:38 - 2016-12-09 10:34 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2016-12-13 20:38 - 2016-12-09 10:34 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
2016-12-13 20:38 - 2016-12-09 10:33 - 03777536 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2016-12-13 20:38 - 2016-12-09 10:33 - 01589760 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll
2016-12-13 20:38 - 2016-12-09 10:32 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2016-12-13 20:38 - 2016-12-09 10:31 - 03689984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2016-12-13 20:38 - 2016-12-09 10:31 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2016-12-13 20:38 - 2016-12-09 10:31 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\indexeddbserver.dll
2016-12-13 20:38 - 2016-12-09 10:30 - 23677952 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-12-13 20:38 - 2016-12-09 10:30 - 19413504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-12-13 20:38 - 2016-12-09 10:30 - 04612608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2016-12-13 20:38 - 2016-12-09 10:29 - 04749312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-12-13 20:38 - 2016-12-09 10:28 - 03306496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2016-12-13 20:38 - 2016-12-09 10:28 - 01004544 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2016-12-13 20:38 - 2016-12-09 10:27 - 19417088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-12-13 20:38 - 2016-12-09 10:27 - 13084160 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-12-13 20:38 - 2016-12-09 10:27 - 05114368 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2016-12-13 20:38 - 2016-12-09 10:27 - 00981504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll
2016-12-13 20:38 - 2016-12-09 10:26 - 08129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-12-13 20:38 - 2016-12-09 10:26 - 01692672 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2016-12-13 20:38 - 2016-12-09 10:25 - 00376832 _____ (Microsoft Corporation) C:\WINDOWS\system32\CryptoWinRT.dll
2016-12-13 20:38 - 2016-12-09 10:24 - 02275840 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-12-13 20:38 - 2016-12-09 10:23 - 12177920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-12-13 20:38 - 2016-12-09 10:22 - 02820096 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2016-12-13 20:38 - 2016-12-09 10:22 - 02688512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-12-13 20:38 - 2016-12-09 10:22 - 01490944 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-12-13 20:38 - 2016-12-09 10:21 - 04746752 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-12-13 20:38 - 2016-12-09 10:21 - 03616768 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-12-13 20:38 - 2016-12-09 10:21 - 01512960 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-12-13 20:38 - 2016-12-09 10:21 - 00716800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll
2016-12-13 20:38 - 2016-12-09 10:20 - 06044160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-12-13 20:38 - 2016-12-09 10:20 - 03198464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2016-12-13 20:38 - 2016-12-09 10:20 - 00730624 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2016-12-13 20:38 - 2016-12-09 10:20 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2016-12-13 20:38 - 2016-12-09 10:20 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2016-12-13 20:38 - 2016-12-09 10:19 - 01121280 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2016-12-13 20:38 - 2016-12-09 10:19 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2016-12-13 20:38 - 2016-12-09 10:19 - 00261120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2016-12-13 20:38 - 2016-12-09 10:19 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2016-12-13 20:38 - 2016-12-09 10:19 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditBufferTestHook.dll
2016-12-13 20:38 - 2016-12-09 10:18 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2016-12-13 20:38 - 2016-12-09 10:18 - 02138112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2016-12-13 20:38 - 2016-12-09 10:18 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2016-12-13 20:38 - 2016-12-09 10:17 - 00886272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2016-12-13 20:38 - 2016-12-09 10:17 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll
2016-12-13 20:38 - 2016-12-09 10:16 - 02998272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2016-12-13 20:38 - 2016-12-09 10:16 - 01880576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2016-12-13 20:38 - 2016-12-09 10:16 - 00353280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2016-12-13 20:38 - 2016-12-09 10:15 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2016-12-13 20:38 - 2016-12-09 10:15 - 00092672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll
2016-12-13 20:38 - 2016-12-09 10:15 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditBufferTestHook.dll
2016-12-13 20:38 - 2016-12-09 09:54 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2016-12-13 20:38 - 2016-11-02 11:28 - 00807424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.OnlineId.dll
2016-12-13 20:38 - 2016-11-02 11:25 - 00956416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2016-12-13 20:38 - 2016-09-15 17:36 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2016-12-13 16:32 - 2016-12-13 16:32 - 00045099 _____ C:\Users\aca\Desktop\primer_2.zip
2016-12-13 16:31 - 2016-12-13 16:31 - 00053930 _____ C:\Users\aca\Desktop\primer.zip

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-01-11 20:03 - 2015-12-08 17:51 - 00000000 ___RD C:\Users\aca\Google Drive
2017-01-11 19:55 - 2016-11-01 20:47 - 00000000 ____D C:\WINDOWS\Minidump
2017-01-11 19:55 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2017-01-11 19:55 - 2016-07-16 12:45 - 00000000 ____D C:\WINDOWS\INF
2017-01-11 19:55 - 2016-01-02 03:54 - 00000000 ____D C:\Users\aca\AppData\Roaming\uTorrent
2017-01-11 19:55 - 2015-12-15 23:45 - 00000000 ____D C:\Users\aca\AppData\Roaming\MPC-HC
2017-01-11 18:48 - 2016-11-23 18:19 - 00000000 ____D C:\Users\aca\AppData\LocalLow\Mozilla
2017-01-11 18:48 - 2016-10-15 03:07 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-01-11 18:37 - 2016-07-16 12:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-01-11 18:32 - 2015-12-08 19:15 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-01-11 18:29 - 2015-12-08 19:15 - 135657872 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-01-11 17:24 - 2016-07-16 12:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-01-11 17:24 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-01-11 17:01 - 2016-10-15 03:09 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-01-11 17:01 - 2015-12-08 17:02 - 00000000 __SHD C:\Users\aca\IntelGraphicsProfiles
2017-01-10 23:22 - 2016-10-15 03:13 - 00000000 ____D C:\Users\aca
2017-01-10 22:25 - 2015-12-12 13:45 - 00000000 ____D C:\Users\aca\Documents\ViberDownloads
2017-01-10 22:12 - 2015-12-08 16:34 - 00000000 ____D C:\Users\aca\AppData\Local\Packages
2017-01-10 18:30 - 2016-10-29 06:24 - 00000000 ____D C:\Users\aca\AppData\Local\Adobe
2017-01-10 18:30 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-01-10 18:30 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-01-10 18:30 - 2015-12-08 23:10 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2017-01-10 18:01 - 2015-12-12 13:44 - 00000000 ____D C:\Users\aca\AppData\Roaming\ViberPC
2017-01-10 13:48 - 2016-10-15 03:30 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-01-09 21:43 - 2015-12-08 17:49 - 00000000 ____D C:\Program Files (x86)\Google
2017-01-09 20:31 - 2015-12-08 17:08 - 00000000 ____D C:\Users\aca\AppData\Local\Google
2017-01-09 19:35 - 2016-10-15 03:09 - 00065536 _____ C:\WINDOWS\system32\spu_storage.bin
2017-01-09 19:35 - 2016-07-16 07:04 - 00524288 _____ C:\WINDOWS\system32\config\BBI
2017-01-09 19:35 - 2016-02-19 01:18 - 00000000 ____D C:\Program Files (x86)\Amazon
2017-01-09 17:51 - 2015-12-08 16:34 - 00000000 ____D C:\Users\aca\AppData\Roaming\Adobe
2017-01-08 16:41 - 2016-01-15 22:51 - 00000000 ____D C:\Users\aca\Documents\The Witcher 3
2017-01-07 16:53 - 2015-12-09 01:46 - 00000000 ____D C:\Users\aca\AppData\Local\JDownloader v2.0
2017-01-07 16:03 - 2015-12-08 21:25 - 00002506 _____ C:\Users\aca\Desktop\Hadu.ini
2017-01-07 11:47 - 2015-12-08 20:25 - 00000000 ____D C:\Users\aca\AppData\Roaming\DAEMON Tools Lite
2017-01-02 11:02 - 2015-12-10 16:28 - 00000000 ____D C:\ProgramData\KMSAutoS
2017-01-01 11:27 - 2016-07-07 19:17 - 00002004 _____ C:\Users\aca\Desktop\The Witcher® 3 - Wild Hunt.lnk
2016-12-31 02:34 - 2016-10-15 03:13 - 00524288 ___SH C:\Users\aca\NTUSER.DAT{507aa8e6-9284-11e6-8303-fffa1972cbda}.TMContainer00000000000000000002.regtrans-ms
2016-12-31 02:34 - 2016-10-15 03:13 - 00065536 ___SH C:\Users\aca\NTUSER.DAT{507aa8e6-9284-11e6-8303-fffa1972cbda}.TM.blf
2016-12-31 01:52 - 2016-10-29 14:58 - 00000000 ____D C:\Users\aca\Documents\CPY_SAVES
2016-12-31 01:47 - 2015-12-08 17:20 - 00000000 ____D C:\ProgramData\Package Cache
2016-12-23 00:13 - 2016-07-16 12:49 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-12-23 00:13 - 2016-07-16 12:49 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-12-18 21:38 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\system32\CatRoot
2016-12-18 21:38 - 2016-01-01 23:50 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-12-18 21:38 - 2015-12-08 17:08 - 00000932 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-3854506088-2188221789-2845878084-1001UA.job
2016-12-18 21:38 - 2015-12-08 17:08 - 00000880 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-3854506088-2188221789-2845878084-1001Core.job
2016-12-18 20:16 - 2015-12-09 02:35 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-12-18 19:48 - 2016-07-17 10:49 - 00000000 ____D C:\Users\aca\Documents\My Games
2016-12-18 18:11 - 2016-10-15 03:09 - 00000000 ____D C:\Program Files\AMD
2016-12-18 18:09 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\system32\DriverStore
2016-12-18 18:04 - 2016-07-01 18:46 - 00000000 ____D C:\AMD
2016-12-18 00:54 - 2015-12-08 17:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2016-12-17 00:47 - 2016-10-15 03:30 - 00003416 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2016-12-17 00:47 - 2016-10-15 03:30 - 00003292 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2016-12-16 20:47 - 2016-11-20 15:55 - 00000000 ____D C:\Program Files (x86)\Pro Evolution Soccer 2017
2016-12-14 20:08 - 2016-07-16 12:47 - 00000000 __RSD C:\WINDOWS\assembly
2016-12-14 18:11 - 2016-10-15 03:13 - 00524288 ___SH C:\WINDOWS\system32\config\COMPONENTS{b794f0c9-4b5d-11e6-80e4-e41d2d719790}.TMContainer00000000000000000002.regtrans-ms
2016-12-14 18:11 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\rescache
2016-12-14 16:49 - 2016-10-15 03:06 - 00340624 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-12-13 22:55 - 2016-10-15 03:06 - 00524288 ___SH C:\WINDOWS\system32\config\DRIVERS{b794f0cf-4b5d-11e6-80e4-e41d2d719790}.TMContainer00000000000000000001.regtrans-ms
2016-12-13 22:55 - 2016-10-15 03:06 - 00065536 ___SH C:\WINDOWS\system32\config\DRIVERS{b794f0cf-4b5d-11e6-80e4-e41d2d719790}.TM.blf
2016-12-13 22:55 - 2016-07-16 12:47 - 00000796 ___SH C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini
2016-12-13 22:55 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\en-US
2016-12-13 22:55 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\en-US
2016-12-13 22:55 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\Boot
2016-12-13 22:55 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\ShellExperiences
2016-12-13 22:55 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\AppPatch

==================== Files in the root of some directories =======

2016-12-19 00:28 - 2016-12-19 00:28 - 0000367 _____ () C:\Users\aca\AppData\Roaming\Weather Meter_Settings.ini
2016-09-21 22:24 - 2016-09-21 22:24 - 0008704 _____ () C:\Users\aca\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-01-03 14:29

==================== End of FRST.txt ============================
mycity.rs/must-login.png

online
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8039
  • Gde živiš: Novi Beograd

1. Otvori Notepad (Text Document) i iskopiraj sledeći tekst unutar kod polja ispod:

CreateRestorePoint:
GroupPolicy: Restriction <======= ATTENTION
Task: {5F520CDE-DC8D-44C0-9565-EEC33FC4A70A} - System32\Tasks\Microsoft\Windows\Multimedia\Manager => C:\Users\aca\AppData\Roaming\Adobe\Manager.exe [2017-01-09] ()
FF SearchPlugin: C:\Users\aca\AppData\Roaming\Mozilla\Firefox\Profiles\t5i6mpri.default\searchplugins\g8skjwn1.xml [2017-01-09]
EmptyTemp:


2. Sačuvaj notepad na Desktop pod nazivom fixlist.txt
To možes uraditi i iz notepad-a => klik na File potom na Save As i u novom prozoru, dole pod File Name: staviš za naziv fixlist.txt
Napomena: Važno je da se oba fajla, FRST i fixlist nalaze na istoj lokaciji jer u suprotnom fix nece raditi.

3. Ponovo pokreni FRST/FRST64, klikni jednom na dugme Fix i sačekaj.
Ukoliko alat zatraži restart sistema, dozvoli mu i postaraj se da alat kompletira fix nakon restarta sistema.



Alat će formirati log (Fixlog.txt) na Desktop-u. Potrebno je sadržaj tog loga iskopirati u poruku.
Napomena: Ukoliko te alat upozori da postoji novija verzija, postaraj se da preuzmes i koristiš ažuriranu kopiju FRST-a.

-----------

Javi stanje sa tom porukom.

offline
  • Pridružio: 15 Feb 2011
  • Poruke: 94

Fix result of Farbar Recovery Scan Tool (x64) Version: 12-01-2017
Ran by aca (12-01-2017 21:14:01) Run:1
Running from C:\Users\aca\Desktop
Loaded Profiles: aca (Available Profiles: aca)
Boot Mode: Normal
==============================================

fixlist content:
*****************
CreateRestorePoint:
GroupPolicy: Restriction <======= ATTENTION
Task: {5F520CDE-DC8D-44C0-9565-EEC33FC4A70A} - System32\Tasks\Microsoft\Windows\Multimedia\Manager => C:\Users\aca\AppData\Roaming\Adobe\Manager.exe [2017-01-09] ()
FF SearchPlugin: C:\Users\aca\AppData\Roaming\Mozilla\Firefox\Profiles\t5i6mpri.default\searchplugins\g8skjwn1.xml [2017-01-09]
EmptyTemp:
*****************

Restore point was successfully created.
C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully
C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully
C:\WINDOWS\SysWOW64\GroupPolicy\GPT.ini => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5F520CDE-DC8D-44C0-9565-EEC33FC4A70A} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5F520CDE-DC8D-44C0-9565-EEC33FC4A70A} => key removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Multimedia\Manager => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Multimedia\Manager => key removed successfully
C:\Users\aca\AppData\Roaming\Mozilla\Firefox\Profiles\t5i6mpri.default\searchplugins\g8skjwn1.xml => moved successfully

=========== EmptyTemp: ==========

BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 11201450 B
Java, Flash, Steam htmlcache => 506 B
Windows/system/drivers => 53412946 B
Edge => 195 B
Chrome => 735385093 B
Firefox => 43528237 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => -658 B
aca => 77366841 B

RecycleBin => 24675462 B
EmptyTemp: => 901.8 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 21:14:21 ====



Pratim stanje pa javljam.

Ko je trenutno na forumu
 

Ukupno su 825 korisnika na forumu :: 62 registrovanih, 11 sakrivenih i 752 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 1567 - dana 15 Jul 2016 19:18

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: airsuba, Altay, alxmi3r, Areal84, awathorn, babaroga, bato3, black venom, BlekMen, damirZR, Dejan Nejic, dekao, Dorcolac2, Dragulče, drdoca, Drug pukovnik, Dzoni Stek, Faki-Valjevo, goran.vvv, helen1, HSMF, ivo.jozinovic, Joe Husaphet 2, Kosa, kosticmilanko, Ljilja Hnovi, Mercury, Misa63, mrkanidja, nedeljkovici, Oscar2, ozzy, powSrb, RADOVAN.S, ray ban11, renoje2, repac2, RJ, Rogi, rovac, ruma, Sale, Sass Drake, sekretar2, shone34, sloboda_ili_smrt, Springfield, Sr.Stat., srdic.vlada, Srki94, stalker, StefanNBG90, suton, theNedjeljko, TwinHeadedEagle, vasa.93, Vazduhoplovac, voja64, vukdra, WS2, zorpetus, |_MeD_|