Kako izbrisati Wondershare?

Kako izbrisati Wondershare?

offline
  • Istrazivanje Windowsa
  • Pridružio: 12 Jul 2012
  • Poruke: 1023

Pozdrav ljudi! Imam problem sa nekim programom Wondershare. Dok su mi ukucani bili na racunaru, nekako su uspeli skinuti i instalirati program ''Wondershare''. Izbrisao sam ga, medjutim njegove stavke su ostale i mozete da ih vidite i u ovim FRST logovima. Koristio sam i adware cleaner medjutim on nikada nije uspeo da ga potpuno obrise.

Ne znam kako su uspeli da ga skinu a navodno su samo gledali film.

Evo izvestaja FRST:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 04.03.2018
Ran by Stefan (administrator) on STEFAN (08-03-2018 11:40:53)
Running from C:\Users\Stefan\Downloads
Loaded Profiles: Stefan (Available Profiles: Stefan)
Platform: Windows 10 Home Version 1703 (X64) Language: English (United Kingdom)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-t.....scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9217024 2017-04-13] (Realtek Semiconductor)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-03-15] (Oracle Corporation)
HKLM-x32\...\Run: [Aimersoft Helper Compact.exe] => C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe [2138272 2016-10-08] (AimerSoft)
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-3845861192-373603742-3298966185-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [10024624 2017-11-08] (Piriform Ltd)
HKU\S-1-5-21-3845861192-373603742-3298966185-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3102496 2017-10-31] (Valve Corporation)
HKU\S-1-5-21-3845861192-373603742-3298966185-1001\...\MountPoints2: D - "D:\ResidentEvil3_menu.exe"
HKU\S-1-5-21-3845861192-373603742-3298966185-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\SysWOW64\launcher.scr
HKU\S-1-5-18\...\Run: [Samsung.PCSync] => "C:\Program Files (x86)\Samsung\Samsung PC Studio 7\PcSync2.exe" /NoDialog

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{0ce1500c-317b-467d-86f3-e4409f86db53}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\ssv.dll [2017-04-29] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-04-29] (Oracle Corporation)

FireFox:
========
FF DefaultProfile: 4lveho68.default
FF ProfilePath: C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\4lveho68.default [2018-03-08]
FF Homepage: Mozilla\Firefox\Profiles\4lveho68.default -> hxxps://www.google.rs/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_27_0_0_183.dll [2017-11-01] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_183.dll [2017-11-01] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-04-29] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-04-29] (Oracle Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-11-14] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-11-14] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-12-05] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-12-05] (Google Inc.)

Chrome:
=======
CHR Profile: C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default [2018-03-08]
CHR Extension: (Google Drive) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-04-29]
CHR Extension: (YouTube) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-04-29]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-24]
CHR Extension: (Gmail) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-04-29]
CHR Extension: (Chrome Media Router) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-02-27]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S4 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [518264 2017-11-14] (NVIDIA Corporation)
S4 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [518264 2017-11-14] (NVIDIA Corporation)
R2 osrss; C:\Windows\system32\osrss.dll [108584 2018-01-18] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-03-18] (Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
S4 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r
S4 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.4.3.231\WsAppService.exe [X]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_c791f781cd94491f\nvlddmkm.sys [16989296 2017-11-15] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30328 2017-11-14] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [50808 2017-11-14] (NVIDIA Corporation)
R3 nvvhci; C:\Windows\System32\drivers\nvvhci.sys [57976 2017-11-14] (NVIDIA Corporation)
U5 PROCMON23; C:\Windows\System32\Drivers\PROCMON23.sys [92992 2017-09-20] (Sysinternals - www.sysinternals.com)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [604160 2017-03-18] (Realtek )
S3 SDFRd; C:\Windows\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-03-08 11:40 - 2018-03-08 11:41 - 000008731 _____ C:\Users\Stefan\Downloads\FRST.txt
2018-03-08 11:40 - 2018-03-08 11:40 - 000000000 ____D C:\FRST
2018-03-08 11:39 - 2018-03-08 11:39 - 002403328 _____ (Farbar) C:\Users\Stefan\Downloads\FRST64.exe
2018-03-06 16:25 - 2018-03-06 16:26 - 000000000 ____D C:\Users\Stefan\Desktop\New folder (7)
2018-03-03 22:45 - 2018-03-03 22:45 - 000000000 ____D C:\Program Files (x86)\Age of empires
2018-02-28 00:52 - 2018-02-28 01:29 - 000000000 ____D C:\Users\Stefan\Desktop\New folder (6)
2018-02-27 18:29 - 2018-02-27 18:33 - 000000000 ____D C:\Program Files (x86)\iSkysoft
2018-02-27 18:29 - 2018-02-27 18:29 - 000000000 ____D C:\Users\Stefan\AppData\Local\Wondershare
2018-02-27 18:28 - 2018-02-27 18:29 - 000000000 ____D C:\Users\Public\Documents\iSkysoft
2018-02-22 04:51 - 2018-02-22 04:51 - 000000000 ____D C:\Users\Stefan\AppData\Local\ASHelper
2018-02-21 20:46 - 2018-02-21 20:47 - 000000000 ____D C:\Users\Stefan\AppData\Roaming\HandBrake
2018-02-21 20:46 - 2018-02-21 20:46 - 000000000 ____D C:\Users\Stefan\AppData\Roaming\HandBrake Team
2018-02-21 20:39 - 2018-02-21 20:42 - 000000000 ____D C:\Users\Stefan\AppData\Roaming\KeepVid
2018-02-21 20:39 - 2018-02-21 20:42 - 000000000 ____D C:\Program Files (x86)\Keepvid
2018-02-21 20:39 - 2018-02-21 20:39 - 000000000 ____D C:\Users\Stefan\AppData\Local\KeepVid
2018-02-21 20:39 - 2018-02-21 20:39 - 000000000 ____D C:\Users\Stefan\AppData\Local\Aimersoft
2018-02-21 20:39 - 2018-02-21 20:39 - 000000000 ____D C:\ProgramData\KeepVid
2018-02-21 20:39 - 2018-02-21 20:39 - 000000000 ____D C:\ProgramData\GraphicsType
2018-02-21 20:39 - 2018-02-21 20:39 - 000000000 ____D C:\ProgramData\Aimersoft
2018-02-21 20:38 - 2018-02-21 20:39 - 000000000 ____D C:\Users\Public\Documents\Keepvid
2018-02-21 20:11 - 2018-02-21 20:13 - 000000000 ____D C:\Users\Stefan\Desktop\New folder (5)
2018-02-21 17:32 - 2018-02-21 17:41 - 000000000 ____D C:\Program Files (x86)\Gta San Andreas
2018-02-21 17:27 - 2018-02-21 17:27 - 000000000 ____D C:\Users\Stefan\Desktop\New folder (4)
2018-02-20 22:17 - 2018-02-20 22:17 - 000000000 ____D C:\Users\Stefan\Desktop\New folder (2)
2018-02-20 22:03 - 2018-02-21 18:03 - 000000000 ____D C:\Users\Stefan\Documents\GTA San Andreas User Files
2018-02-20 21:43 - 2011-04-25 09:05 - 000000000 ____D C:\Users\Stefan\Desktop\Hot_Coffee_21
2018-02-16 15:07 - 2018-02-16 15:07 - 000000279 _____ C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recycle Bin.lnk
2018-02-16 14:57 - 2018-02-16 14:57 - 000000883 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Counter-Strike WaRzOnE.lnk
2018-02-15 16:57 - 2018-02-15 16:57 - 000000000 ____D C:\Windows\system32\MRT
2018-02-15 16:56 - 2018-02-15 16:57 - 130067560 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2018-02-15 16:56 - 2018-02-15 16:56 - 130067560 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-02-15 16:56 - 2018-01-18 01:05 - 000108584 _____ (Microsoft Corporation) C:\Windows\system32\osrss.dll
2018-02-15 16:56 - 2017-10-17 06:11 - 001578904 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2018-02-15 16:56 - 2017-10-17 06:10 - 002032536 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2018-02-15 16:56 - 2017-10-17 06:10 - 000678808 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2018-02-15 16:56 - 2017-10-17 06:10 - 000613784 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2018-02-15 16:56 - 2017-10-17 06:10 - 000484248 _____ (Microsoft Corporation) C:\Windows\system32\dcntel.dll
2018-02-15 16:56 - 2017-10-17 06:10 - 000379288 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2018-02-15 16:56 - 2017-10-17 06:10 - 000190360 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2018-02-15 16:56 - 2017-10-17 06:10 - 000136088 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2018-02-15 16:56 - 2017-10-17 06:10 - 000067992 _____ (Microsoft Corporation) C:\Windows\system32\win32appinventorycsp.dll
2018-02-15 16:56 - 2017-10-17 06:10 - 000034712 _____ (Microsoft Corporation) C:\Windows\system32\DeviceCensus.exe
2018-02-15 16:56 - 2017-10-17 06:05 - 000503704 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2018-02-15 16:56 - 2017-10-17 06:04 - 000612248 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2018-02-15 16:55 - 2018-02-15 16:55 - 000000000 ____H C:\ProgramData\DP45977C.lfl
2018-02-15 16:55 - 2018-02-15 16:55 - 000000000 ____D C:\Windows\SysWOW64\RTCOM
2018-02-15 16:55 - 2018-02-15 16:55 - 000000000 ____D C:\Windows\system32\DAX3
2018-02-15 16:55 - 2018-02-15 16:55 - 000000000 ____D C:\Windows\system32\DAX2
2018-02-15 16:55 - 2018-02-15 16:55 - 000000000 ____D C:\Program Files\Realtek
2018-02-15 01:35 - 2018-02-15 01:35 - 000000000 ____D C:\Users\Stefan\AppData\Roaming\Need for Speed World
2018-02-15 01:27 - 2018-02-15 01:27 - 000000000 ____D C:\ProgramData\Caphyon
2018-02-15 01:26 - 2018-02-15 01:26 - 000000000 ____D C:\Users\Stefan\AppData\Roaming\Appveyor
2018-02-14 20:16 - 2018-02-14 20:16 - 000000000 ____D C:\Program Files (x86)\Sigma Production Inc
2018-02-14 04:44 - 2018-02-15 16:56 - 000000000 ____D C:\Program Files\rempl
2018-02-14 04:44 - 2018-01-01 02:41 - 000087040 _____ (Microsoft Corporation) C:\Windows\system32\usoapi.dll
2018-02-14 04:44 - 2018-01-01 02:40 - 000378880 _____ (Microsoft Corporation) C:\Windows\system32\MusNotification.exe
2018-02-14 04:44 - 2018-01-01 02:40 - 000052736 _____ (Microsoft Corporation) C:\Windows\system32\musdialoghandlers.dll
2018-02-14 04:44 - 2018-01-01 02:39 - 000204800 _____ (Microsoft Corporation) C:\Windows\system32\MusNotificationUx.exe
2018-02-14 04:44 - 2018-01-01 02:38 - 000739840 _____ (Microsoft Corporation) C:\Windows\system32\MusUpdateHandlers.dll
2018-02-14 04:44 - 2018-01-01 02:35 - 000060928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usoapi.dll
2018-02-14 04:44 - 2018-01-01 02:30 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\usocore.dll
2018-02-14 04:44 - 2017-11-02 06:12 - 000026472 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2018-02-14 04:44 - 2017-11-02 05:35 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2018-02-14 04:44 - 2017-11-02 05:34 - 000113152 _____ (Microsoft Corporation) C:\Windows\system32\wuuhosdeployment.dll
2018-02-14 04:44 - 2017-11-02 05:34 - 000095232 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2018-02-14 04:44 - 2017-11-02 05:34 - 000033792 _____ (Microsoft Corporation) C:\Windows\system32\wuautoappupdate.dll
2018-02-14 04:44 - 2017-11-02 05:30 - 000165888 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2018-02-14 04:44 - 2017-11-02 05:29 - 000415232 _____ (Microsoft Corporation) C:\Windows\system32\updatehandlers.dll
2018-02-14 04:44 - 2017-11-02 05:27 - 000079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2018-02-14 04:44 - 2017-11-02 05:26 - 000986624 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2018-02-14 04:44 - 2017-11-02 05:23 - 002449408 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2018-02-14 04:44 - 2017-11-02 05:23 - 000407040 _____ (Microsoft Corporation) C:\Windows\system32\wuuhext.dll
2018-02-14 04:44 - 2017-11-02 05:21 - 000787456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2018-02-14 04:44 - 2017-09-29 08:40 - 000086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\updatepolicy.dll
2018-02-14 04:44 - 2017-09-29 08:29 - 000102912 _____ (Microsoft Corporation) C:\Windows\system32\updatepolicy.dll
2018-02-14 04:44 - 2017-09-29 08:28 - 000256000 _____ (Microsoft Corporation) C:\Windows\system32\domgmt.dll
2018-02-14 04:44 - 2017-09-29 08:24 - 001307648 _____ (Microsoft Corporation) C:\Windows\system32\dosvc.dll
2018-02-14 04:44 - 2017-07-28 05:19 - 000417792 _____ (Microsoft Corporation) C:\Windows\system32\InstallAgentUserBroker.exe
2018-02-14 04:44 - 2017-07-28 05:16 - 000383488 _____ (Microsoft Corporation) C:\Windows\system32\InstallAgent.exe
2018-02-14 04:44 - 2017-07-28 05:14 - 000368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallAgentUserBroker.exe
2018-02-14 04:44 - 2017-07-28 05:12 - 000337920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallAgent.exe
2018-02-14 04:44 - 2017-05-20 09:20 - 000807424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StoreAgent.dll
2018-02-14 04:44 - 2017-05-20 07:00 - 001078272 _____ (Microsoft Corporation) C:\Windows\system32\StoreAgent.dll
2018-02-07 16:49 - 2018-02-07 17:24 - 000000000 ____D C:\Users\Stefan\AppData\Roaming\audacity
2018-02-07 16:49 - 2018-02-07 16:49 - 000000000 ____D C:\Users\Stefan\AppData\Local\Audacity
2018-02-06 16:41 - 2018-02-06 16:41 - 000000000 ____D C:\ProgramData\Codemasters
2018-02-06 16:39 - 2018-02-06 16:39 - 000466456 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll
2018-02-06 16:39 - 2018-02-06 16:39 - 000444952 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
2018-02-06 16:39 - 2018-02-06 16:39 - 000122904 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll
2018-02-06 16:39 - 2018-02-06 16:39 - 000109080 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
2018-02-06 16:39 - 2018-02-06 16:39 - 000000000 ____D C:\Program Files (x86)\OpenAL
2018-02-06 14:07 - 2018-02-06 14:07 - 000000000 ____D C:\Users\Stefan\AppData\Roaming\Hard Disk Sentinel
2018-02-06 12:48 - 2018-02-06 12:48 - 000000000 ____D C:\Program Files\Common Files\AVG
2018-02-06 12:44 - 2018-02-06 15:18 - 000000000 ____D C:\Users\Stefan\AppData\Local\Avg
2018-02-06 12:44 - 2018-02-06 15:18 - 000000000 ____D C:\ProgramData\Avg
2018-02-06 12:44 - 2018-02-06 15:12 - 000000000 ____D C:\Users\Stefan\AppData\Local\AvgSetupLog
2018-02-06 12:44 - 2018-02-06 12:44 - 003449304 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Stefan\Downloads\AVG_Protection_Free_1606.exe

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-03-08 11:27 - 2017-04-29 19:22 - 000000000 ____D C:\Windows\system32\SleepStudy
2018-03-08 08:48 - 2017-12-30 20:15 - 000000000 ____D C:\Users\Stefan\Desktop\slike 1
2018-03-08 08:48 - 2017-05-20 17:23 - 000000000 ____D C:\Users\Stefan\Desktop\New folder
2018-03-08 01:34 - 2017-04-29 16:14 - 000000000 ____D C:\ProgramData\NVIDIA
2018-03-07 21:47 - 2017-09-25 14:57 - 000001519 _____ C:\Users\Stefan\Desktop\New Text Document (5).txt
2018-03-07 12:45 - 2017-07-02 13:38 - 000002895 _____ C:\Users\Stefan\Desktop\11.txt
2018-03-07 02:16 - 2017-04-29 19:31 - 000000000 ____D C:\Users\Stefan
2018-03-05 01:35 - 2017-04-29 15:55 - 000000000 ____D C:\Users\Stefan\AppData\Roaming\uTorrent
2018-03-04 01:57 - 2017-04-30 13:10 - 000000000 ____D C:\Users\Stefan\Desktop\Igre
2018-03-04 01:56 - 2017-03-18 22:03 - 000000000 ____D C:\Windows\AppReadiness
2018-03-03 23:03 - 2017-04-29 19:33 - 000000000 ____D C:\Users\Stefan\AppData\Local\Packages
2018-03-03 19:12 - 2018-01-21 01:18 - 000001373 _____ C:\Users\Stefan\Desktop\BioShock Remastered.lnk
2018-03-03 02:35 - 2017-06-28 22:28 - 000000000 ____D C:\Users\Stefan\Downloads\Snes9x
2018-03-02 14:46 - 2017-04-29 21:42 - 000000000 ____D C:\Users\Stefan\AppData\Local\CrashDumps
2018-03-01 17:05 - 2017-06-02 21:49 - 000000000 ____D C:\Users\Stefan\AppData\Roaming\vlc
2018-02-28 23:54 - 2018-02-04 21:10 - 000000000 ____D C:\Users\Stefan\Downloads\WoW_Legion_torrent
2018-02-28 21:59 - 2018-01-19 21:35 - 000000000 ____D C:\Users\Stefan\AppData\Local\Battle.net
2018-02-28 20:47 - 2018-01-19 21:38 - 000000000 ____D C:\Program Files (x86)\Heroes of the Storm
2018-02-28 20:46 - 2018-01-19 21:34 - 000000000 ____D C:\Program Files (x86)\Battle.net
2018-02-27 22:13 - 2017-07-18 19:15 - 000000023 _____ C:\Windows\BlendSettings.ini
2018-02-27 19:55 - 2017-07-14 12:07 - 000000000 ____D C:\AdwCleaner
2018-02-27 18:28 - 2018-01-20 01:14 - 000000000 ____D C:\Users\Stefan\AppData\Roaming\obs-studio
2018-02-27 15:37 - 2017-04-29 15:55 - 000002663 _____ C:\Users\Stefan\Desktop\µTorrent.lnk
2018-02-27 06:04 - 2017-04-29 15:24 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-02-27 06:04 - 2017-04-29 15:24 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-02-21 20:46 - 2017-12-01 21:25 - 000000000 ____D C:\Users\Public\Documents\Wondershare
2018-02-21 17:38 - 2017-04-30 21:43 - 000000000 ____D C:\Windows\SysWOW64\directx
2018-02-20 22:22 - 2017-04-30 22:15 - 000000000 ____D C:\Program Files (x86)\Mr DJ
2018-02-16 15:02 - 2017-05-20 14:48 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2018-02-16 15:01 - 2017-09-24 13:43 - 000000000 ____D C:\Games
2018-02-15 20:14 - 2017-03-18 22:03 - 000000000 ____D C:\Windows\rescache
2018-02-15 17:13 - 2017-04-29 19:30 - 001284338 _____ C:\Windows\system32\PerfStringBackup.INI
2018-02-15 17:07 - 2017-04-29 19:23 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-02-15 17:07 - 2017-03-18 12:40 - 000262144 _____ C:\Windows\system32\config\BBI
2018-02-15 16:58 - 2017-03-18 22:03 - 000000000 ____D C:\Windows\system32\en-GB
2018-02-15 16:58 - 2017-03-18 22:03 - 000000000 ____D C:\Windows\system32\appraiser
2018-02-15 16:56 - 2017-03-18 22:01 - 000000000 ____D C:\Windows\INF
2018-02-15 16:49 - 2017-04-29 20:22 - 000000000 ____D C:\Windows\Panther
2018-02-15 15:47 - 2017-03-18 21:51 - 000000000 ____D C:\Windows\CbsTemp
2018-02-14 23:26 - 2017-07-17 21:41 - 000001032 _____ C:\Users\Stefan\Desktop\New Text Document.txt
2018-02-14 21:35 - 2017-06-22 11:15 - 000000000 ____D C:\Users\Stefan\AppData\Local\Aspyr
2018-02-14 20:10 - 2017-09-04 17:45 - 000000000 ____D C:\Program Files (x86)\Aspyr
2018-02-14 12:27 - 2017-03-18 22:03 - 000000000 ___HD C:\Program Files\WindowsApps
2018-02-14 00:01 - 2017-05-01 15:35 - 000000000 ____D C:\Users\Stefan\Documents\My Games
2018-02-13 23:20 - 2017-04-30 21:43 - 000000000 ___HD C:\Windows\msdownld.tmp
2018-02-12 21:25 - 2018-02-02 14:36 - 000000000 ____D C:\Users\Stefan\Downloads\World of Warcraft 1.12
2018-02-10 20:54 - 2017-04-29 16:14 - 000001228 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2018-02-10 20:53 - 2017-04-29 16:14 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox

==================== Files in the root of some directories =======

2017-10-01 00:10 - 2017-10-01 00:10 - 000000000 ___RH () C:\Users\Stefan\AppData\Roaming\9c5339e6392c5dbc48efbb6d9f118f892

Some files in TEMP:
====================
2018-01-22 15:12 - 2018-01-22 15:12 - 000192512 _____ () C:\Users\Stefan\AppData\Local\Temp\sfamcc00001.dll
2015-02-10 18:56 - 2015-02-10 18:56 - 000105984 _____ () C:\Users\Stefan\AppData\Local\Temp\sfextra.dll

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-02-27 20:10

==================== End of FRST.txt ============================

Evo i Addition:
https://www.mycity.rs/must-login.png

Molim vas za pomoc!

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Čist si što se malwarea tiče.

Sledeća procedura će implementirati završno čišćenje.

Arrow Preuzmi "Xplode"-ov DelFix alat i snimi ga na Desktop.
Dvoklikom pokreni alat i štikliraj kućice ispred sledećih opcija;

Remove disinfection tools
Create registry backup
Purge System Restore


Klikni na dugme Run i pričekaj trenutak dok alat ne završi svoj rad.
Od ovog trenutka, svi korišćeni alati u ovoj temi bi trebali biti obrisani.
Alat će takođe formirati izveštaj za tebe. (C:\DelFix.txt)

Alat će snimiti i zdravo stanje registy-ja i napraviti backup koristeci integrisan program "ERUNT" u %windir%\ERUNT\DelFix
Alat briše stare system restore tačke i pravi novu, svežu tačku nakon čišćenja.





Što se tiče ostataka Wondershare softvera, servis možeš obrisati pomoću Autorunsa (kartica Services), a nakon toga foldere na disku možeš ručno obrisati.

offline
  • Istrazivanje Windowsa
  • Pridružio: 12 Jul 2012
  • Poruke: 1023

Hvala mnogo!

Ko je trenutno na forumu
 

Ukupno su 902 korisnika na forumu :: 43 registrovanih, 1 sakriven i 858 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., Acivi, aleksandarbl, anta, bato, bestguarder, bigfoot, BlekMen, Boris90, BraneS, cemix, darios, Dimitrije Paunovic, Djokislav, havoc995, Istman, Ivica1102, Kriglord, Kubovac, kunktator, ljuba, Lubica, mgolub, Misirac, moldway, Ne doznajem se u oružje, nemkea71, NoOneEver Dreams, ObelixSRB, oganj123, Petar35, RJ, shone34, slonic_tonic, srbijaiznadsvega, t.mile, theNedjeljko, trajkoni018, Viceroy, virked, Vlajman1957, wolf431, šumar bk2