Provera posle pojavljivanja čudnog procesa

Provera posle pojavljivanja čudnog procesa

offline
  • Pridružio: 31 Dec 2015
  • Poruke: 1419

Napisano: 28 Sep 2026 18:48

Zdravo, ne znam da li je ambulanta aktivna, ali hajde da postavim temu. Možda ću u međuvremenu probati sa Malwarebytes programom da skeniram laptop.

Pre nekoliko minuta dok sam gledao YT Shorts mi se u sekundu isključio zvuk i u taskbar-u pojavilo ono za proširenje da se vide pokrenuti programi (kao kad je uključen Viber, Outlook i sl.). Kada sam otvorio pojavila se default ikonica aplikacije nekog procesa. Kada sam hover-ovao preko ikonice pisalo je "silent install" i ikonica se pretvorila u neku ikonicu sa belom pozadinom i crvenim čekićem ili su bile obrnute boje, nisam siguran. Onda sam ja ugasio desnim klikom pa exit. Ništa se ne dešava čudno trenutno.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 26-09-2026
Ran by mikic (administrator) on MILOSLAPTOP (LENOVO 21MW) (28-09-2026 19:44:43)
Running from C:\Users\mikic\OneDrive\Desktop\FRST64.exe
Loaded Profiles: mikic
Platform: Microsoft Windows 11 Pro Version 25H2 26200.9457 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(C:\Program Files (x86)\Lenovo\VantageService\5.1.2609.9\LenovoVantageService.exe ->) (Lenovo -> Lenovo) C:\Program Files (x86)\Lenovo\VantageService\5.1.2609.9\LenovoVantage-(GenericMessagingAddin).exe
(C:\Program Files (x86)\Lenovo\VantageService\5.1.2609.9\LenovoVantageService.exe ->) (Lenovo -> Lenovo) C:\Program Files (x86)\Lenovo\VantageService\5.1.2609.9\LenovoVantage-(LenovoServiceBridgeAddin).exe
(C:\Program Files (x86)\Lenovo\VantageService\5.1.2609.9\LenovoVantageService.exe ->) (Lenovo -> Lenovo) C:\Program Files (x86)\Lenovo\VantageService\5.1.2609.9\LenovoVantage-(VantageCoreAddin).exe
(D:\Programi\PostgreSQL\bin\pg_ctl.exe ->) (PostgreSQL Global Development Group) [File not signed] D:\Programi\PostgreSQL\bin\postgres.exe
(drivers\lenovo\UDC\Service\UDClientService.exe ->) (Lenovo -> ) C:\ProgramData\Lenovo\Udc\Hosts\x64\AppProvisioningPlugin.exe
(drivers\lenovo\UDC\Service\UDClientService.exe ->) (Lenovo -> ) C:\ProgramData\Lenovo\Udc\Hosts\x64\MessagingPlugin.exe
(DriverStore\FileRepository\dax3_swc_aposvc.inf_amd64_2d43ea2009b9f4a0\DAX3API.exe ->) (Dolby Laboratories, Inc. -> Dolby Laboratories) C:\Windows\System32\DriverStore\FileRepository\DAX3_S~4.INF\DAX3API.exe
(DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_5e21bf389d23855a\LenovoUtilityService.exe ->) (Lenovo -> Lenovo) C:\Windows\System32\DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_5e21bf389d23855a\FnHotkeyCapsLKNumLK.exe
(DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_5e21bf389d23855a\LenovoUtilityService.exe ->) (Lenovo -> Lenovo) C:\Windows\System32\DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_5e21bf389d23855a\FnHotkeyUtility.exe
(DriverStore\FileRepository\u0196534.inf_amd64_2d01ca9c95f4f068\B025475\atiesrxx.exe ->) (Advanced Micro Devices -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0196534.inf_amd64_2d01ca9c95f4f068\B025475\atieclxx.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <12>
(LNBITSSvc.exe ->) (Lenovo -> Lenovo) C:\Windows\System32\AutoModeDetect.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\153.0.4234.48\msedgewebview2.exe <6>
(PostgreSQL Global Development Group) [File not signed] D:\Programi\PostgreSQL\bin\postgres.exe <6>
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_a112e46fc636d880\RtkAudUService64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_e747b8bdadfd6fe3\RtkAudUService64.exe
(services.exe ->) (Advanced Micro Devices -> Advanced Micro Devices, Inc) C:\Windows\System32\DriverStore\FileRepository\amdppkg.inf_amd64_8938b7cd0816afff\AmdPpkgSvc.exe
(services.exe ->) (Advanced Micro Devices -> Advanced Micro Devices, Inc.) C:\Windows\System32\DriverStore\FileRepository\amdfendr.inf_amd64_a45773f484fe1fd0\amdfendrsr.exe
(services.exe ->) (Advanced Micro Devices -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0196534.inf_amd64_2d01ca9c95f4f068\B025475\atiesrxx.exe
(services.exe ->) (Dolby Laboratories, Inc. -> Dolby Laboratories) C:\Windows\System32\DriverStore\FileRepository\dax3_swc_aposvc.inf_amd64_2d43ea2009b9f4a0\DAX3API.exe
(services.exe ->) (ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronics Corp.) C:\Windows\System32\ELAN_Detection_Service.exe
(services.exe ->) (Elevoc Technology Co.,Ltd. -> Elevoc Technology Co.,Ltd.) C:\Windows\System32\ElevocInstallDriver\ElevocControlService.exe
(services.exe ->) (Lenovo -> Lenovo Group Ltd.) C:\Windows\System32\drivers\lenovo\UDC\Service\UDClientService.exe
(services.exe ->) (Lenovo -> Lenovo) C:\Program Files (x86)\Lenovo\VantageService\5.1.2609.9\LenovoVantageService.exe
(services.exe ->) (Lenovo -> Lenovo) C:\Windows\System32\DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_5e21bf389d23855a\LenovoUtilityService.exe
(services.exe ->) (Lenovo -> Lenovo) C:\Windows\System32\LNBITSSvc.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WSL\wslservice.exe
(services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Locator.exe
(services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\WUDFCompanionHost.exe <3>
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\NisSrv.exe
(services.exe ->) (PostgreSQL Global Development Group) [File not signed] D:\Programi\PostgreSQL\bin\pg_ctl.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_a112e46fc636d880\RtkAudUService64.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.380.2.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\NgcIso.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_a112e46fc636d880\RtkAudUService64.exe [3499560 2026-09-04] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [Riot Vanguard] => C:\Program Files\Riot Vanguard\vgtray.exe [7336968 2026-09-04] (Riot Games, Inc. -> Riot Games, Inc.)
HKU\S-1-5-21-3251834896-1342706484-4142744029-1001\...\Run: [Discord] => C:\Users\mikic\AppData\Local\Discord\Update.exe [1516408 2025-05-19] (Discord Inc. -> Discord Inc.)
HKU\S-1-5-21-3251834896-1342706484-4142744029-1001\...\Run: [Docker Desktop] => C:\Program Files\Docker\Docker\Docker Desktop.exe [6702000 2025-10-31] (Docker Inc -> Docker Inc.)
HKU\S-1-5-21-3251834896-1342706484-4142744029-1001\...\Run: [MicrosoftEdgeAutoLaunch_C033CC1D3CC12986C8DA1A1BAD62DA2F] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [5403976 2026-09-24] (Microsoft Corporation -> Microsoft Corporation)
HKLM\Software\...\AppCompatFlags\InstalledSDB\{08274920-8908-45c2-9258-8ad67ff77b09}: [DatabasePath] -> C:\WINDOWS\AppPatch\CustomSDB\{08274920-8908-45c2-9258-8ad67ff77b09}.sdb [2025-02-06]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{49210152-871f-4ffa-961d-a172abcbc09d}] -> C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [4924568 2026-08-11] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\153.0.8010.53\Installer\chrmstp.exe [8030872 2026-09-17] (Google LLC -> Google LLC)
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {923123E2-18BD-4144-BF05-7042B875D314} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem156.0.8067.0{7DF10F7E-0AD8-4807-A7B8-11C68F221817} => C:\Program Files (x86)\Google\GoogleUpdater\156.0.8067.0\updater.exe [9992344 2026-09-21] (Google LLC -> Google LLC)
Task: {A6F3EFE4-80CF-46C3-95D6-9E86A96D7228} - System32\Tasks\GoogleUserPEH\RunPlatformExperienceHelper_Daily => C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [4924568 2026-08-11] (Google LLC -> Google LLC)
Task: {CE8A4388-3874-46ED-B1F5-CC5AAC0EBF40} - System32\Tasks\GoogleUserPEH\RunPlatformExperienceHelper_Metrics => C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [4924568 2026-08-11] (Google LLC -> Google LLC)
Task: {848B021C-667D-44A3-A7C2-646E6A4A8A18} - System32\Tasks\GoogleUserPEH\RunPlatformExperienceHelperOnUnlock => C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [4924568 2026-08-11] (Google LLC -> Google LLC)
Task: {64C81A7A-4871-4134-B095-3B2364E14B64} - System32\Tasks\Lenovo\LenovoMachineFixUser_OOBE_AUTO_Notification => C:\ProgramData\Lenovo\Vantage\Addins\LenovoMachineFixUserAddin\1.0.10.390\ScheduleEventAction.exe [17888 2026-09-17] (Lenovo -> Lenovo) -> C:\ProgramData\Lenovo\Vantage\Addins\LenovoMachineFixUserAddin\1.0.10.390\"LenovoMachineFixUser_OOBE_AUTO_Notification"
Task: {32ACECBA-9F0B-4844-A68D-FEEC4F5E6CD1} - System32\Tasks\Lenovo\UDC\Lenovo UDC Diagnostic Scan => C:\WINDOWS\system32\sc.exe [102400 2025-07-08] (Microsoft Windows -> Microsoft Corporation) -> control udcservice 210
Task: {41510C1D-A2D8-4382-BCBE-000A6FEA8771} - System32\Tasks\Lenovo\UDC\Lenovo UDC Lazy Deployment => C:\WINDOWS\system32\sc.exe [102400 2025-07-08] (Microsoft Windows -> Microsoft Corporation) -> control udcservice 221
Task: {6AF586CB-210E-4CFB-8223-EA7DD056140A} - System32\Tasks\Lenovo\UDC\Lenovo UDC Maintainance Task => C:\WINDOWS\system32\sc.exe [102400 2025-07-08] (Microsoft Windows -> Microsoft Corporation) -> control udcservice 220
Task: {899B611F-70EE-4144-ABB5-C55D825BB460} - System32\Tasks\Lenovo\UDC\Lenovo UDC Monitor => C:\WINDOWS\system32\drivers\lenovo\udc\data\InfBackup\UdcInfInstaller.exe [257936 2026-07-22] (Lenovo -> Lenovo Group Ltd.)
Task: {04BF876D-8EC1-4A7E-8A37-1081AD12B778} - System32\Tasks\Lenovo\Vantage\Lenovo.Vantage.ServiceMaintainance => C:\WINDOWS\system32\sc.exe [102400 2025-07-08] (Microsoft Windows -> Microsoft Corporation) -> start LenovoVantageService
Task: {358B4DF7-2555-4BA5-8288-4FB9BCE728CA} - System32\Tasks\Lenovo\Vantage\Schedule\ConsumerAddinDailyScheduleTask => C:\Program Files (x86)\Lenovo\VantageService\5.1.2609.9\ScheduleEventAction.exe [275520 2026-09-21] (Lenovo -> Lenovo)
Task: {B7127903-BE65-4DC4-A76F-2CA48029A3A6} - System32\Tasks\Lenovo\Vantage\Schedule\DailyTelemetryTransmission => C:\Program Files (x86)\Lenovo\VantageService\5.1.2609.9\ScheduleEventAction.exe [275520 2026-09-21] (Lenovo -> Lenovo)
Task: {2913AE39-0037-4216-83E4-46FB24A409FF} - System32\Tasks\Lenovo\Vantage\Schedule\GenericMessagingAddin => C:\Program Files (x86)\Lenovo\VantageService\5.1.2609.9\ScheduleEventAction.exe [275520 2026-09-21] (Lenovo -> Lenovo)
Task: {5D04F722-EC0C-47D6-8744-6AD66BCB6C02} - System32\Tasks\Lenovo\Vantage\Schedule\GenericMessagingAddin_Pulsation => C:\Program Files (x86)\Lenovo\VantageService\5.1.2609.9\ScheduleEventAction.exe [275520 2026-09-21] (Lenovo -> Lenovo)
Task: {A64F1429-41EE-44CF-A30C-B0F7B0EDA6F2} - System32\Tasks\Lenovo\Vantage\Schedule\HeartbeatAddinDailyScheduleTask => C:\Program Files (x86)\Lenovo\VantageService\5.1.2609.9\ScheduleEventAction.exe [275520 2026-09-21] (Lenovo -> Lenovo)
Task: {126D3AC0-C9CC-4E75-8071-B887E6F2B093} - System32\Tasks\Lenovo\Vantage\Schedule\IdeaNotebookAddinDailyEvent => C:\Program Files (x86)\Lenovo\VantageService\5.1.2609.9\ScheduleEventAction.exe [275520 2026-09-21] (Lenovo -> Lenovo)
Task: {9E122697-CE93-443D-8287-A9175F49827D} - System32\Tasks\Lenovo\Vantage\Schedule\Lenovo.Vantage.SmartPerformance.MonthlyReport => C:\Program Files (x86)\Lenovo\VantageService\5.1.2609.9\ScheduleEventAction.exe [275520 2026-09-21] (Lenovo -> Lenovo)
Task: {92809231-522A-42F9-A8DD-BD0103E11CE9} - System32\Tasks\Lenovo\Vantage\Schedule\LenovoCompanionAppAddinDailyScheduleTask => C:\Program Files (x86)\Lenovo\VantageService\5.1.2609.9\ScheduleEventAction.exe [275520 2026-09-21] (Lenovo -> Lenovo)
Task: {85B27CDD-4D48-4000-9BB3-C51B26BCC754} - System32\Tasks\Lenovo\Vantage\Schedule\LenovoSupportHealthReportSchedule => C:\Program Files (x86)\Lenovo\VantageService\5.1.2609.9\ScheduleEventAction.exe [275520 2026-09-21] (Lenovo -> Lenovo)
Task: {C0DFE55C-E5A0-4D36-B525-6D81B07965D8} - System32\Tasks\Lenovo\Vantage\Schedule\LenovoSystemUpdateAddin_WeeklyTask => C:\Program Files (x86)\Lenovo\VantageService\5.1.2609.9\ScheduleEventAction.exe [275520 2026-09-21] (Lenovo -> Lenovo)
Task: {E508E41E-E793-4428-89AD-08481876E0D0} - System32\Tasks\Lenovo\Vantage\Schedule\NightChargeToastEvent => C:\Program Files (x86)\Lenovo\VantageService\5.1.2609.9\ScheduleEventAction.exe [275520 2026-09-21] (Lenovo -> Lenovo)
Task: {E1D9D3F5-E176-4D5D-A06D-6F20343A38BB} - System32\Tasks\Lenovo\Vantage\Schedule\SettingsWidgetAddinDailyScheduleTask => C:\Program Files (x86)\Lenovo\VantageService\5.1.2609.9\ScheduleEventAction.exe [275520 2026-09-21] (Lenovo -> Lenovo)
Task: {4F89860E-ED5C-44D4-8993-2258AA2C57DA} - System32\Tasks\Lenovo\Vantage\Schedule\SmartPerformance.ExpireReminder => C:\Program Files (x86)\Lenovo\VantageService\5.1.2609.9\ScheduleEventAction.exe [275520 2026-09-21] (Lenovo -> Lenovo)
Task: {B9ECB196-F9EB-4AD3-97C9-56567634E46C} - System32\Tasks\Lenovo\Vantage\Schedule\VantageCoreAddinDailyScheduleTask => C:\Program Files (x86)\Lenovo\VantageService\5.1.2609.9\ScheduleEventAction.exe [275520 2026-09-21] (Lenovo -> Lenovo)
Task: {61FEA65F-0935-4549-BB55-CB9CCFAA4676} - System32\Tasks\Lenovo\Vantage\Schedule\VantageCoreAddinIdleScheduleTask => C:\ProgramData\Lenovo\Vantage\Addins\VantageCoreAddin\1.1.0.51\x86\IdleScheduleEventAction.exe [173536 2026-07-31] (Lenovo -> )
Task: {29995147-39EA-43F1-A521-577235A824F7} - System32\Tasks\Lenovo\Vantage\Schedule\VantageCoreAddinWeekScheduleTask => C:\Program Files (x86)\Lenovo\VantageService\5.1.2609.9\ScheduleEventAction.exe [275520 2026-09-21] (Lenovo -> Lenovo)
Task: {7CB1908B-95EE-4906-B27A-27EAC8CAEC4E} - System32\Tasks\Microsoft\VisualStudio\Updates\BackgroundDownload => C:\Program Files (x86)\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\BackgroundDownload.exe [185232 2026-06-15] (Microsoft Corporation -> Microsoft)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {3E42FDA7-2A2C-49D9-9DB9-F5FBCF326C64} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MpCmdRun.exe [1902880 2026-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {48407187-3053-4C8D-8FD1-BA550FC54AAD} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MpCmdRun.exe [1902880 2026-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {F4E8187B-0144-41E7-A4D1-B267D217388C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MpCmdRun.exe [1902880 2026-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {95C3CB3A-C08B-4608-AC4A-A871144EA229} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MpCmdRun.exe [1902880 2026-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 89.216.1.30 89.216.1.40 89.216.1.50
Tcpip\..\Interfaces\{6f220fbb-e87c-4d14-bc31-69a878944bb3}: [DhcpNameServer] 89.216.1.30 89.216.1.40 89.216.1.50
Tcpip\..\Interfaces\{6f220fbb-e87c-4d14-bc31-69a878944bb3}\255646D69602E4F64756021333: [DhcpNameServer] 10.215.77.4
Tcpip\..\Interfaces\{6f220fbb-e87c-4d14-bc31-69a878944bb3}\8416A6E616C61363: [DhcpNameServer] 89.216.1.30 89.216.1.40 89.216.1.50
Tcpip\..\Interfaces\{6f220fbb-e87c-4d14-bc31-69a878944bb3}\D4D44454: [DhcpNameServer] 93.184.80.109 8.8.8.8
Tcpip\..\Interfaces\{6f220fbb-e87c-4d14-bc31-69a878944bb3}\D4D4445423: [DhcpNameServer] 212.200.191.166 212.200.190.166
Tcpip\..\Interfaces\{6f220fbb-e87c-4d14-bc31-69a878944bb3}\D4F6260277966696: [DhcpNameServer] 192.168.43.1
Tcpip\..\Interfaces\{c243c00a-e50c-4442-8154-7ab7c6df4c18}: [DhcpNameServer] 93.184.80.109 8.8.8.8

FireFox:
========
FF DefaultProfile: 71w0fy2r.default-release -> 308046B0AF4A39CB
FF ProfilePath: C:\Users\mikic\AppData\Roaming\Mozilla\Firefox\Profiles\9d8zcwz0.default [2025-06-05]
FF ProfilePath: C:\Users\mikic\AppData\Roaming\Mozilla\Firefox\Profiles\71w0fy2r.default-release [2025-06-05]

Edge:
=======
Edge Profile: C:\Users\mikic\AppData\Local\Microsoft\Edge\User Data\Default [2026-09-20]
Edge StartupUrls: Default -> "hxxps://www.google.com/"
Edge Extension: (Google Docs Offline) - C:\Users\mikic\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-08-31]
Edge Extension: (Edge relevant text changes) - C:\Users\mikic\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2025-05-28]
Edge Extension: (Lyrics Finder) - D:\Lyrics extension\LyricsFinder [2025-12-03] [UpdateUrl:0] <==== ATTENTION

Chrome:
=======
CHR Profile: C:\Users\mikic\AppData\Local\Google\Chrome\User Data\Default [2026-09-28]
CHR HomePage: Default -> [Link mogu videti samo ulogovani korisnici]
CHR Extension: (Google Translate) - C:\Users\mikic\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2026-07-02]
CHR Extension: (Adblock for Youtube™) - C:\Users\mikic\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2026-09-14]
CHR Extension: (uBlock Origin Lite) - C:\Users\mikic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ddkjiahejlhfcafbddmgiahcphecmpfh [2026-09-27]
CHR Extension: (Google Docs Offline) - C:\Users\mikic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-09-11]
CHR Extension: (Chrome Web Store Payments) - C:\Users\mikic\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2025-05-28]
CHR Extension: (PDF Viewer) - C:\Users\mikic\AppData\Local\Google\Chrome\User Data\Default\Extensions\oemmndcbldboiebfnladdacbdfmadadm [2025-05-28]
CHR Extension: (Lyrics Finder) - D:\Lyrics extension\LyricsFinder [2025-12-03] [UpdateUrl:0] <==== ATTENTION

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AmdPpkgSvc; C:\WINDOWS\System32\DriverStore\FileRepository\amdppkg.inf_amd64_8938b7cd0816afff\AmdPpkgSvc.exe [515480 2025-09-29] (Advanced Micro Devices -> Advanced Micro Devices, Inc)
S3 com.docker.service; C:\Program Files\Docker\Docker\com.docker.service [39344 2025-10-31] (Docker Inc -> Docker Inc.)
R2 DolbyDAXAPI; C:\WINDOWS\System32\DriverStore\FileRepository\dax3_swc_aposvc.inf_amd64_2d43ea2009b9f4a0\DAX3API.exe [2761360 2025-10-16] (Dolby Laboratories, Inc. -> Dolby Laboratories)
R2 ELAN_Detection_Service; C:\WINDOWS\System32\ELAN_Detection_Service.exe [257008 2025-09-09] (ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronics Corp.)
R2 ElevocService; C:\WINDOWS\System32\ElevocInstallDriver\ElevocControlService.exe [1071208 2025-09-21] (Elevoc Technology Co.,Ltd. -> Elevoc Technology Co.,Ltd.)
R2 LenovoFnAndFunctionKeys; C:\WINDOWS\System32\DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_5e21bf389d23855a\LenovoUtilityService.exe [199744 2026-03-09] (Lenovo -> Lenovo)
R2 LenovoVantageService; C:\Program Files (x86)\Lenovo\VantageService\5.1.2609.9\LenovoVantageService.exe [44096 2026-09-21] (Lenovo -> Lenovo)
R2 LITSSVC; C:\WINDOWS\System32\LNBITSSvc.exe [1872000 2025-10-23] (Lenovo -> Lenovo)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MpDefenderCoreService.exe [2307776 2026-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 postgresql-x64-17; D:\Programi\PostgreSQL\bin\pg_ctl.exe [129536 2025-05-07] (PostgreSQL Global Development Group) [File not signed]
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [914752 2026-08-31] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 UDCService; C:\WINDOWS\System32\drivers\Lenovo\udc\Service\UDClientService.exe [72592 2026-07-22] (Lenovo -> Lenovo Group Ltd.)
S3 VBoxSDS; C:\Program Files\Oracle\VirtualBox\VBoxSDS.exe [763024 2025-04-11] (Oracle America, Inc. -> Oracle and/or its affiliates)
S3 vgc; C:\Program Files\Riot Vanguard\vgc.exe [94532048 2026-09-04] (Riot Games, Inc. -> Riot Games, Inc.)
S3 VSInstallerElevationService; C:\Program Files (x86)\Microsoft Visual Studio\Installer\VSInstallerElevationService.exe [52096 2026-06-15] (Microsoft Corporation -> Microsoft)
S3 VSStandardCollectorService150; D:\Programi\VS2022\Shared\Common\DiagnosticsHub.Collection.Service\StandardCollector.Service.exe [163456 2025-08-12] (Microsoft Corporation -> Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\NisSrv.exe [5311776 2026-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MsMpEng.exe [291360 2026-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 ACPIVPC; C:\WINDOWS\System32\DriverStore\FileRepository\acpivpc.inf_amd64_07db38bc9e02b27d\AcpiVpc.sys [52800 2026-06-16] (Lenovo -> Lenovo)
R3 amdfendrmgr; C:\WINDOWS\System32\DriverStore\FileRepository\amdfendr.inf_amd64_a45773f484fe1fd0\amdfendrmgr.sys [37272 2025-10-15] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
R3 AmdPpkg; C:\WINDOWS\System32\DriverStore\FileRepository\amdppkg.inf_amd64_8938b7cd0816afff\AmdPpkg.sys [35192 2025-09-29] (Advanced Micro Devices -> Advanced Micro Devices)
S3 amduw23g; C:\WINDOWS\System32\DriverStore\FileRepository\u0415927.inf_amd64_451cd5ac8b1e359d\B415716\amdkmdag.sys [111962520 2025-08-05] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
R3 amduw23g-196534-223643d3; C:\WINDOWS\System32\DriverStore\FileRepository\u0196534.inf_amd64_2d01ca9c95f4f068\B025475\amdkmdag.sys [102038544 2025-12-04] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
S3 amduw23g-419082-2c8b87ff; C:\WINDOWS\System32\DriverStore\FileRepository\u0419082.inf_amd64_602c074a57bfa294\B418901\amdkmdag.sys [101862360 2025-09-10] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
R0 bhtsddr; C:\WINDOWS\System32\DRIVERS\bhtsddr.sys [178376 2025-08-27] (BayHub Technology Inc. -> BayHubTech)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [573440 2024-10-05] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [200704 2024-10-05] (Microsoft Corporation) [File not signed]
S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [110592 2025-05-28] (Microsoft Corporation) [File not signed]
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [175824 2024-10-17] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R0 fse; C:\WINDOWS\System32\drivers\fse.sys [230888 2026-08-31] (Microsoft Windows -> Microsoft Corporation)
R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [83008 2026-09-03] (Microsoft Windows -> Microsoft Corporation)
S2 l1vhlwf; C:\WINDOWS\System32\drivers\l1vhlwf.sys [144864 2026-08-31] (Microsoft Windows -> Microsoft Corporation)
R3 MTKBTFilterx64; C:\WINDOWS\System32\DriverStore\FileRepository\mtkbtfilter.inf_amd64_0dbc7108794e9d54\mtkbtfilterx.sys [404088 2026-01-30] (MEDIATEK INC. -> MediaTek Inc.)
R3 mtkwlex; C:\WINDOWS\System32\DriverStore\FileRepository\mtkwl6ex.inf_amd64_e5c4110782778a57\mtkwl6ex.sys [1755680 2026-01-30] (MEDIATEK INC. -> MediaTek Inc.)
S3 rt68cx21; C:\WINDOWS\System32\DriverStore\FileRepository\rt68cx21x64.inf_amd64_8075652acf50fbcd\rt68cx21x64.sys [831472 2024-08-26] (Realtek Semiconductor Corp. -> Realtek)
S3 rtcx21; C:\WINDOWS\System32\DriverStore\FileRepository\rtcx21x64.inf_amd64_feec7a9662e785f0\rtcx21x64.sys [539648 2024-03-28] (Microsoft Windows -> Realtek)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174264 2024-10-17] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R3 VBoxNetAdp; C:\WINDOWS\system32\DRIVERS\VBoxNetAdp6.sys [246232 2025-04-11] (Oracle America, Inc. -> Oracle and/or its affiliates)
R1 VBoxNetLwf; C:\WINDOWS\system32\DRIVERS\VBoxNetLwf.sys [256512 2025-04-11] (Oracle America, Inc. -> Oracle and/or its affiliates)
R1 VBoxSup; C:\WINDOWS\System32\drivers\VBoxSup.sys [1052968 2025-04-11] (Oracle America, Inc. -> Oracle and/or its affiliates)
R1 VBoxUSBMon; C:\WINDOWS\System32\drivers\VBoxUSBMon.sys [195560 2025-04-11] (Oracle America, Inc. -> Oracle and/or its affiliates)
S1 vgk; \??\C:\Program Files\Riot Vanguard\vgk.sys [72094952 2026-09-04] (Riot Games, Inc. -> )
S3 vmbusproxy; C:\WINDOWS\system32\drivers\vmbusproxy.sys [98304 2025-05-29] (Microsoft Windows -> Microsoft Corporation)
S4 WdAiNisDrv; C:\WINDOWS\System32\drivers\wd\WdAiNisDrv.sys [51264 2026-09-18] (Microsoft Windows -> Microsoft Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [21632 2026-09-18] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [664592 2026-09-18] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [137240 2026-09-18] (Microsoft Windows -> Microsoft Corporation)
S3 LenovoDiagnosticsDriver; \??\C:\ProgramData\Lenovo\Vantage\Addins\LenovoHardwareScanAddin\4.3.0.11\LenovoDiagnosticsDriver.sys (No File)

==================== SvcHost (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2026-09-28 19:44 - 2026-09-28 19:45 - 000028218 _____ C:\Users\mikic\OneDrive\Desktop\FRST.txt
2026-09-28 19:44 - 2026-09-28 19:44 - 000000000 ____D C:\FRST
2026-09-28 19:42 - 2026-09-28 19:43 - 002455552 _____ (Farbar) C:\Users\mikic\OneDrive\Desktop\FRST64.exe
2026-09-28 19:35 - 2026-09-04 18:56 - 000022512 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtEventLog.dll
2026-09-27 12:53 - 2026-09-27 17:07 - 000000000 ____D C:\WINDOWS\CbsTemp
2026-09-22 21:57 - 2026-09-22 21:57 - 000010311 _____ C:\Users\mikic\.bash_history
2026-09-22 21:10 - 2026-09-22 21:10 - 000000020 _____ C:\Users\mikic\.lesshst
2026-09-16 01:31 - 2026-09-16 01:31 - 000000578 __RSH C:\ProgramData\ntuser.pol
2026-08-31 22:15 - 2026-08-31 22:15 - 000004646 _____ C:\WINDOWS\system32\ResPriUHMImageList
2026-08-31 22:15 - 2026-08-31 22:15 - 000004646 _____ C:\WINDOWS\system32\ResPriLMImageList
2026-08-31 22:15 - 2026-08-31 22:15 - 000004646 _____ C:\WINDOWS\system32\ResPriImageList
2026-08-31 22:15 - 2026-08-31 22:15 - 000004646 _____ C:\WINDOWS\system32\ResPriHMImageList
2026-08-31 22:15 - 2026-08-31 22:15 - 000004555 _____ C:\WINDOWS\system32\ResPriImageListLowCost
2026-08-31 22:15 - 2026-08-31 22:15 - 000004555 _____ C:\WINDOWS\system32\ResPriHMImageListLowCost
2026-08-31 22:14 - 2026-08-31 22:14 - 000039215 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2026-08-31 22:14 - 2026-08-31 22:14 - 000039215 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2026-08-31 22:14 - 2026-08-31 22:14 - 000014689 _____ C:\WINDOWS\system32\ecoscore_config.json
2026-08-30 21:21 - 2026-08-30 21:21 - 000001454 _____ C:\Users\mikic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord.lnk
2026-08-30 11:17 - 2026-08-30 11:17 - 000005155 _____ C:\WINDOWS\system32\InstallMonitorLog.csv

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2026-09-28 19:45 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemTemp
2026-09-28 19:36 - 2025-08-01 14:54 - 000000000 ____D C:\WINDOWS\TempInst
2026-09-28 19:36 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-09-28 19:36 - 2024-04-01 09:24 - 000000000 ____D C:\WINDOWS\INF
2026-09-28 19:15 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\AppReadiness
2026-09-28 19:09 - 2025-05-29 05:52 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2026-09-28 17:09 - 2025-08-01 14:46 - 000000720 _____ C:\Users\mikic\AppData\Local\elecgbk
2026-09-28 17:04 - 2024-04-01 09:26 - 000000000 ___HD C:\Program Files\WindowsApps
2026-09-26 21:13 - 2025-05-29 05:52 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2026-09-26 10:48 - 2025-05-28 16:35 - 000000441 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2026-09-23 12:03 - 2026-08-24 16:51 - 000000090 _____ C:\Users\mikic\OneDrive\Desktop\Watch Vivy -Fluorite Eye's Song- · Miruro.url
2026-09-22 23:52 - 2025-05-28 17:10 - 000000000 ____D C:\Users\mikic\AppData\Roaming\discord
2026-09-22 23:52 - 2025-05-28 17:10 - 000000000 ____D C:\Users\mikic\AppData\Local\Discord
2026-09-22 21:57 - 2025-05-28 15:17 - 000000000 ____D C:\Users\mikic
2026-09-22 16:07 - 2026-06-10 13:02 - 000002383 _____ C:\Users\mikic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2026-09-22 16:07 - 2025-05-28 15:25 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3251834896-1342706484-4142744029-1001
2026-09-22 16:07 - 2025-05-28 15:25 - 000003576 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-3251834896-1342706484-4142744029-1001
2026-09-22 16:07 - 2025-05-28 15:25 - 000003372 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3251834896-1342706484-4142744029-1001
2026-09-22 15:52 - 2025-05-28 17:42 - 000000000 ____D C:\Users\mikic\AppData\Roaming\Code
2026-09-21 18:29 - 2025-05-28 15:23 - 000000000 ____D C:\Users\mikic\AppData\Local\D3DSCache
2026-09-21 10:00 - 2025-05-29 05:54 - 000000000 ____D C:\ProgramData\Packages
2026-09-21 10:00 - 2025-05-28 15:22 - 000000000 ____D C:\Users\mikic\AppData\Local\Packages
2026-09-20 16:39 - 2026-07-19 13:01 - 000131096 _____ C:\WINDOWS\vgk0001.dat
2026-09-20 16:39 - 2025-06-01 11:21 - 000000001 _____ C:\WINDOWS\vgkbootstatus.dat
2026-09-20 14:47 - 2025-06-01 11:21 - 134222904 _____ C:\WINDOWS\392667600.dat
2026-09-20 14:00 - 2025-06-01 10:39 - 000000000 ____D C:\ProgramData\Riot Games
2026-09-20 13:55 - 2026-03-04 10:42 - 000000000 ____D C:\Users\mikic\AppData\Roaming\Riot Client
2026-09-20 13:55 - 2025-06-01 10:49 - 000000000 ____D C:\Program Files\Riot Vanguard
2026-09-20 13:54 - 2025-06-01 10:42 - 000000000 ____D C:\Users\mikic\AppData\Roaming\riot-client-ux
2026-09-20 13:54 - 2025-05-29 05:52 - 000003610 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA{DFD37931-3DD9-4754-96A5-CC26872F3A4D}
2026-09-20 13:54 - 2025-05-29 05:52 - 000003538 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore{59E5223D-AA0C-4F78-BFBB-798680E07B4E}
2026-09-18 12:06 - 2025-05-29 05:52 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2026-09-18 00:35 - 2025-05-28 17:03 - 000002247 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2026-09-16 11:32 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\USOPrivate
2026-09-16 11:22 - 2025-05-28 15:06 - 000836650 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2026-09-16 01:30 - 2025-05-29 05:53 - 000022192 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2026-09-16 01:30 - 2025-05-29 05:52 - 000012288 ___SH C:\DumpStack.log.tmp
2026-09-16 01:30 - 2025-05-29 05:52 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2026-09-16 01:30 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ServiceState
2026-09-16 01:29 - 2024-04-01 09:21 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2026-09-16 01:28 - 2025-05-29 05:52 - 000001623 _____ C:\WINDOWS\system32\config\VSMIDK
2026-09-16 01:28 - 2025-05-28 16:35 - 000000000 ____D C:\Program Files\Hyper-V
2026-09-16 01:28 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\bcastdvr
2026-09-15 01:40 - 2025-07-02 08:31 - 000000000 ____D C:\ProgramData\boost_interprocess
2026-09-15 00:00 - 2025-05-28 14:57 - 003381760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2026-09-14 23:07 - 2025-05-29 19:53 - 000000000 ____D C:\Users\mikic\AppData\Roaming\pgadmin4
2026-09-14 23:07 - 2025-05-29 19:53 - 000000000 ____D C:\Users\mikic\AppData\Roaming\pgAdmin
2026-09-14 22:25 - 2025-05-29 12:41 - 000000000 ____D C:\Users\mikic\AppData\Local\JetBrains
2026-09-09 15:09 - 2025-05-28 15:03 - 000008192 _____ C:\WINDOWS\system32\Drivers\mtkRunTimeDataWdi.bin
2026-09-09 15:08 - 2025-05-29 05:52 - 000406656 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2026-09-09 15:07 - 2024-04-01 10:03 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2026-09-09 15:07 - 2024-04-01 10:03 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView
2026-09-09 15:07 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2026-09-09 15:07 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2026-09-09 15:07 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2026-09-09 15:07 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2026-09-09 15:07 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemResources
2026-09-09 15:07 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2026-09-09 15:07 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\setup
2026-09-09 15:07 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2026-09-09 15:07 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\oobe
2026-09-09 15:07 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Dism
2026-09-09 15:07 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\appraiser
2026-09-09 15:07 - 2024-04-01 09:21 - 000000000 ____D C:\WINDOWS\servicing
2026-09-09 14:24 - 2025-05-28 15:39 - 000000000 ____D C:\WINDOWS\system32\MRT
2026-09-09 12:40 - 2025-05-28 15:39 - 230964456 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2026-09-08 13:09 - 2025-05-30 11:08 - 000000000 ____D C:\Users\mikic\AppData\Roaming\Microsoft\Word
2026-09-04 17:05 - 2025-05-30 11:08 - 000000000 ____D C:\Users\mikic\AppData\Roaming\Microsoft\Office
2026-08-31 22:25 - 2025-12-10 14:39 - 000000000 ____D C:\WINDOWS\system32\NarratorMCAT
2026-08-31 22:25 - 2025-07-08 23:59 - 000000000 ____D C:\WINDOWS\system32\ruxim
2026-08-31 22:25 - 2024-04-01 10:03 - 000000000 ____D C:\WINDOWS\InboxApps
2026-08-31 22:25 - 2024-04-01 10:03 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2026-08-31 22:25 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\system32\F12
2026-08-31 22:25 - 2024-04-01 09:26 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2026-08-31 22:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\UUS
2026-08-31 22:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz
2026-08-31 22:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\InstallShield
2026-08-31 22:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2026-08-31 22:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2026-08-31 22:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2026-08-31 22:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2026-08-31 22:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2026-08-31 22:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\migwiz
2026-08-31 22:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\HealthAttestationClient
2026-08-31 22:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2026-08-31 22:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellExperiences
2026-08-31 22:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellComponents
2026-08-31 22:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\Provisioning
2026-08-31 22:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2026-08-31 22:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\L2Schemas
2026-08-31 22:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\BrowserCore
2026-08-31 22:25 - 2024-04-01 09:26 - 000000000 ____D C:\Program Files\Common Files\System

==================== Files in the root of some directories ========

2025-08-01 14:46 - 2026-09-28 17:09 - 000000720 _____ () C:\Users\mikic\AppData\Local\elecgbk

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================


[Link mogu videti samo ulogovani korisnici]

Dopuna: 28 Sep 2026 20:27

Evo da dodam šta je našao Malwarebytes kada sam pustio deep scan. Posle nekog vremena sam ga prekinuo, jer sam video da može da traje više sati. Sada sam pustio custom scan C particije sa uključenim rootkit skeniranjem. Okačiću i te rezultate kada budu gotovi.

Evo onog što sam dobio delimičnim deep scanom.

Malwarebytes
[Link mogu videti samo ulogovani korisnici]

-Log Details-
Scan Date: 28-Sep-26
Scan Time: 20:01
Log File: 9f79f608-bb66-11f1-8fbb-84ba59978363.json

-Software Information-
Version: 5.7.1.346
Components Version: 165.0.5751
Update Package Version: 1.0.0
License: Trial

-System Information-
OS: Windows 11 (Build 26200.9457)
CPU: x64
File System: NTFS
User: MilosLaptop\mikic

-Scan Summary-
Scan Type: Deep Scan
Scan Initiated By: Manual
Result: Cancelled
Objects Scanned: 1,393,222
Threats Detected: 9
Threats Quarantined: 0
Scan Duration: 39 min, 29 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
File system: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Files Scanned-
C:\
D:\
E:\

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 1
PUP.Optional.Utorrent, HKU\S-1-5-21-3251834896-1342706484-4142744029-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\uTorrent, No Action By User, 5978, 1402654, 1.0.0, , ame, , ,

Registry Value: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 8
PUP.Optional.Bittorrent, C:\USERS\MIKIC\APPDATA\ROAMING\UTORRENT\UPDATES\3.6.0_47224.EXE, No Action By User, 5438, 1365044, 1.0.0, , ame, , CBDE3231207103EB7EEA48406FEA8FD8, 250378064F55063BFFBC36280C807E1CAE867FCDA413076D95E1DB369F25C7A9
PUP.Optional.Utorrent, C:\USERS\MIKIC\APPDATA\ROAMING\UTORRENT\UTORRENT.EXE, No Action By User, 5978, 1402654, 1.0.0, , ame, , 657775F666C15E8AC34687E994DBA93C, 285127F8530FCDB0166CF37C97E60A13ECFF7D57D3F0066E7CEC0E89188E9AE2
PUP.Optional.Utorrent, C:\USERS\MIKIC\APPDATA\ROAMING\Microsoft\Internet Explorer\Quick Launch\\u00c2\u00b5Torrent.lnk, No Action By User, 5978, 1402654, 1.0.0, , ame, , 05B46A7C4EC88E4AA3CD2C0F12BE78F4, 16D11392A4E5659F2CC424E051D5E9DC76665DCDE5B429A8DD7AE749A7157FC3
PUP.Optional.Utorrent, C:\USERS\MIKIC\APPDATA\ROAMING\Microsoft\Windows\Start Menu\\u00c2\u00b5Torrent.lnk, No Action By User, 5978, 1402654, 1.0.0, , ame, , FF245770F9068529334B70584FBA71E3, 62768B975ACF5E90AB5DCEA753C1DE8B6EE8B197CEDD632609F6041423C6708D
PUP.Optional.Utorrent, C:\USERS\MIKIC\APPDATA\ROAMING\UTORRENT\UPDATES\UTORRENT.EXE, No Action By User, 5978, 1402654, 1.0.0, , ame, , 657775F666C15E8AC34687E994DBA93C, 285127F8530FCDB0166CF37C97E60A13ECFF7D57D3F0066E7CEC0E89188E9AE2
PUP.Optional.Utorrent, C:\USERS\MIKIC\APPDATA\ROAMING\UTORRENT\UPDATES\3.6.0_47254.EXE, No Action By User, 5978, 1402654, 1.0.0, , ame, , 7B1BCF79461ED67AA315A4E156DC83F7, E2837E13D80E4602B0C2D711C6D6C17217F4A80C8FF0B33DD90DF219F025F3B7
Malware.AI.1932056105, D:\PROGRAMI\GO\PKG\TOOL\WINDOWS_AMD64\PPROF.EXE, No Action By User, 1000000, 0, 1.0.0, 06483B33066949A87328D629, dds, 04071907, DCE5D92D05D0C4ADA4DB3162806075DC, 6337166883BC1DD4EB5C4D6FD37F370D8CD8B2B8E0807D9BE92997A7377DDDD2
PUP.Optional.BundleInstaller, D:\PROGRAMI\UTORRENT\UPDATES\3.6.0_47178.EXE, No Action By User, 72, 1301130, 1.0.0, , ame, , CBDB9A7AB738A9DB5D7DAC92FDC5F412, A2DDAF2BFFE582232FAF1DB05E8E376D8B65472286109034C25664627E5EBD87

Physical Sector: 0
(No malicious items detected)

WMI: 0
(No malicious items detected)


(end)



Ko je trenutno na forumu
 

Ukupno su 5380 korisnika na forumu :: 22 registrovanih, 2 sakrivenih i 5356 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 20624 - dana 04 Apr 2026 04:18

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 04bokibole, blue, Bo96, bobomicek, Dorcolac, icemilos, Jozo74, klepesina, Macalone, maksi007, Marko Marković, mikrimaus, nazgul75, Nemanja Opalić, novator, picknick, Saša31LPB, Sinisa76, spot4chulle, tomigun, yrraf, zziko