offline
- milos97

- Počasni građanin
- Pridružio: 05 Dec 2010
- Poruke: 717
- Gde živiš: Beograd
|
Pozdrav, izgleda da sam pokupio nekog trojanca po imenu Trojan.RenpyLoader kad sam pokušao da instaliram neku igricu.
Na trenutak mi Windows Defender prijavio da je blokirao nekog trojanca, nakon čega sam obrisao igru misleći da se tu priča završila.
Sutradan, dok sam bio na poslu, a dok je kompjuter na kom sam imao trojanca isključen, sa mog Discord naloga kreno da spamuje svima neku MrBeast poruku u vezi nekih kriptovaluta. Odmah sam promenio lozinku na Discord-u, Gmail-u i još par nekih naloga kojih sam se setio u tom trenutku.
Posle sam uključio taj računar, sa isključenim lan kablom, i pokrenuo Malwarebytes scan gde je on pronašao trojanca po imenu Trojan.RenpyLoader.BAT.
Koliko sam video po internetu, to je trojanac koji krade lozinke/sesije iz browsera. Nakon toga sam preko telefona prošao kros ostale naloge i svima promenio lozinku i gde sam mogao izabrao opciju da me izloguje sa svih uređaja. Osim onih poruka na Discord-u, nisam primetio nijednu drugu neobičnu aktivnost.
Malwarebytes je navodno stavio trojanca u karantin i više ne prijavljuje ništa kada ponovo skeniram ali nisam siguran da li je sve čisto i zato sam hteo da proverim ovde. Do tada se nigde neću logovati preko tog računara.
U prilogu ću dodati i log iz Malwerebytes-a.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 26-09-2026
Ran by milos (administrator) on MILOS (29-09-2026 19:29:33)
Running from C:\Users\zola9\Desktop\FRST64.exe
Loaded Profiles: milos
Platform: Microsoft Windows 10 Pro Version 22H2 19045.6466 (X64) Language: srpski (latinica, Srbija)
Default browser: "C:\Program Files\Ablaze Floorp\floorp.exe" -osint -url "%1"
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe
(Autodesk, Inc. -> Autodesk, Inc.) C:\Program Files\Autodesk\Autodesk AdSSO\AdSSO.exe
(C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\MSI_ActiveX_Service.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\EyeRest.exe
(C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\MSI_ActiveX_Service.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\TriggerModeMonitor.exe
(C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\MSI_ActiveX_Service.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\VideoCardMonitorII.exe
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe
(C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MsMpEng.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\DefenderSessionHelper.exe
(C:\ProgramData\Safing\Portmaster\portmaster-start.exe ->) () [File not signed] [File is in use] C:\ProgramData\Safing\Portmaster\updates\windows_amd64\core\portmaster-core_v1-6-10.exe
(C:\ProgramData\Safing\Portmaster\portmaster-start.exe ->) () [File not signed] [File is in use] C:\ProgramData\Safing\Portmaster\updates\windows_amd64\notifier\portmaster-notifier_v0-3-6.exe
(explorer.exe ->) () [File not signed] C:\Users\zola9\Desktop\nesto\auto hotkey\AutoHotkeyU64.exe <2>
(explorer.exe ->) (Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe
(explorer.exe ->) (AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
(explorer.exe ->) (F.lux Software LLC -> f.lux Software LLC) C:\Users\zola9\AppData\Local\FluxSoftware\Flux\flux.exe
(explorer.exe ->) (Open Source Developer, Phillip Gibbons -> Highresolution Enterprises) C:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonControl.exe
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(explorer.exe ->) (Safing ICS Technologies GmbH -> ) C:\ProgramData\Safing\Portmaster\portmaster-start.exe
(Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Kastelo AB -> The Syncthing Authors) C:\Users\zola9\AppData\Local\Programs\Syncthing\syncthing.exe <2>
(Microsoft Corporation) [File not signed] [File is in use] C:\Program Files\Windows Sidebar\sidebar.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\Display.NvContainer\NVDisplay.Container.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Autodesk, Inc. -> Autodesk, Inc.) C:\Program Files\Autodesk\AdODIS\V1\Setup\AdskAccessServiceHost.exe
(services.exe ->) (AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(services.exe ->) (Flexera Software LLC -> Flexera Software LLC) C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
(services.exe ->) (Hewlett-Packard Company -> HP) C:\Windows\System32\HPSIsvc.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
(services.exe ->) (HP) [File not signed] C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_af50fdb80983f7bc\jhi_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_c2ac023763d5d3ad\OneApp.IGCC.WinService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_d51901c26227fb29\WMIRegistrationService.exe
(services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(services.exe ->) (Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(services.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\NisSrv.exe
(services.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe
(services.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe
(services.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\MSI_ActiveX_Service.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\Display.NvContainer\NVDisplay.Container.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.) C:\Windows\RtkBtManServ.exe
(services.exe ->) (Safing ICS Technologies GmbH -> ) C:\ProgramData\Safing\Portmaster\portmaster-start.exe
(SignPath Foundation -> Mozilla Corporation) C:\Program Files\Ablaze Floorp\floorp.exe <11>
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\zola9\AppData\Local\Microsoft\OneDrive\26.168.0830.0006\FileCoAuth.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(svchost.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey.exe
(svchost.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI) C:\Windows\SysWOW64\muachost.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [18388936 2018-05-02] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [320584 2018-01-29] (Intel(R) Rapid Storage Technology -> Intel Corporation)
HKLM\...\Run: [XMouseButtonControl] => C:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonControl.exe [1738088 2023-06-24] (Open Source Developer, Phillip Gibbons -> Highresolution Enterprises)
HKLM\...\Run: [Autodesk Access] => C:\Program Files\Autodesk\AdODIS\V1\Access\AdskAccessCore.exe [21229344 2024-04-16] (Autodesk, Inc. -> Autodesk, Inc.)
HKLM\...\Run: [KeePass 2 PreLoad] => C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe [3308928 2024-06-01] (Open Source Developer, Dominik Reichl -> Dominik Reichl)
HKLM\...\Run: [Autodesk Access Service] => C:\Program Files\Autodesk\AdODIS\V1\Setup\AdskAccessService.exe [18170648 2025-06-07] (Autodesk, Inc. -> Autodesk, Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [HPUsageTrackingLEDM] => "C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe" "C:\Program Files (x86)\HP\HP UT LEDM\" [Folder 2021-02-07]
HKLM-x32\...\Run: [Autodesk Genuine Service ] => C:\ProgramData\Autodesk\Genuine Service\x64\GenuineService.exe [3738160 2022-06-29] (Autodesk, Inc. -> Autodesk)
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2133728 2024-09-29] (Wondershare Technology Co.,Ltd -> Wondershare)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [742536 2026-07-23] (Oracle America, Inc. -> Oracle Corporation)
HKLM\Software\Policies\...\system: [EnableActivityFeed] 0
HKLM\Software\Policies\...\system: [PublishUserActivities] 0
HKLM\Software\Policies\...\system: [UploadUserActivities] 0
HKLM\Software\Policies\...\system: [AllowCrossDeviceClipboard] 0
HKU\S-1-5-21-3578565935-3243947977-760430267-1001\...\Run: [Steam] => D:\Program Files (x86)\Steam\steam.exe [5774488 2026-07-23] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-3578565935-3243947977-760430267-1001\...\Run: [Discord] => C:\Users\zola9\AppData\Local\Discord\Update.exe [1512760 2020-12-03] (Discord Inc. -> GitHub)
HKU\S-1-5-21-3578565935-3243947977-760430267-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [371304 2019-09-26] (AVB Disc Soft, SIA -> Disc Soft Ltd)
HKU\S-1-5-21-3578565935-3243947977-760430267-1001\...\Run: [com.squirrel.Teams.Teams] => C:\Users\zola9\AppData\Local\Microsoft\Teams\Update.exe [2454200 2021-07-10] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-3578565935-3243947977-760430267-1001\...\Run: [IrisMini] => "C:\Users\zola9\AppData\Local\Iris mini\iris-mini-dynamic.exe" (No File)
HKU\S-1-5-21-3578565935-3243947977-760430267-1001\...\Run: [f.lux] => C:\Users\zola9\AppData\Local\FluxSoftware\Flux\flux.exe [1536232 2026-04-08] (F.lux Software LLC -> f.lux Software LLC)
HKU\S-1-5-21-3578565935-3243947977-760430267-1001\...\Run: [GalaxyClient] => [X]
HKU\S-1-5-21-3578565935-3243947977-760430267-1001\...\Run: [GogGalaxy] => C:\Program Files (x86)\GOG Galaxy\GalaxyClient.exe [14511952 2025-06-08] (GOG sp. z o.o -> GOG.com)
HKU\S-1-5-21-3578565935-3243947977-760430267-1001\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [45610456 2026-09-16] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-3578565935-3243947977-760430267-1001\...\Run: [MicrosoftEdgeAutoLaunch_EAAE2ABEFE2E2FE40E6C78B332CB8F37] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [5403976 2026-09-24] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3578565935-3243947977-760430267-1001\...\MountPoints2: {2d4d33a3-4e39-11e8-8c79-7085c27b44f2} - "E:\SISetup.exe"
HKLM\...\Windows x64\Print Processors\HP1100PrintProc: C:\Windows\System32\spool\prtprocs\x64\HP1100PP.DLL [74240 2012-08-31] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\...\Print\Monitors\HP1100LM: C:\Windows\system32\HP1100LM.DLL [288768 2012-08-31] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\Software\Microsoft\Active Setup\Installed Components: [{AFE6A462-C574-4B8A-AF43-4CC60DF4563B}] -> C:\Program Files\BraveSoftware\Brave-Browser\Application\154.1.96.59\Installer\chrmstp.exe [6547536 2026-09-24] (Brave Software, Inc. -> Brave Software, Inc.)
Startup: C:\Users\zola9\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\auto volume – scroll.lnk [2024-11-25]
ShortcutTarget: auto volume – scroll.lnk -> C:\Users\zola9\Desktop\nesto\auto hotkey\auto volume – scroll.ahk () [File not signed]
Startup: C:\Users\zola9\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CHAT.lnk [2018-12-16]
ShortcutTarget: CHAT.lnk -> D:\Chat\CHAT.jar (No File)
Startup: C:\Users\zola9\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dark.lnk [2022-12-29]
ShortcutTarget: Dark.lnk -> C:\Users\zola9\AppData\Local\FluxSoftware\Flux\flux.exe (F.lux Software LLC -> f.lux Software LLC)
Startup: C:\Users\zola9\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GenuineService.lnk [2022-12-18] <==== ATTENTION
ShortcutTarget: GenuineService.lnk -> C:\Users\zola9\Autodesk\Genuine Service\GenuineService.exe (Autodesk Inc -> Autodesk) <==== ATTENTION
Startup: C:\Users\zola9\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ollama.lnk [2025-11-14]
ShortcutTarget: Ollama.lnk -> C:\Users\zola9\AppData\Local\Programs\Ollama\ollama app.exe (Ollama Inc. -> )
Startup: C:\Users\zola9\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\openf - prečica.lnk [2023-04-03]
ShortcutTarget: openf - prečica.lnk -> C:\Users\zola9\Desktop\nesto\auto hotkey\openf.ahk () [File not signed]
Startup: C:\Users\zola9\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\todo - prečica.lnk [2022-01-03]
ShortcutTarget: todo - prečica.lnk -> C:\Users\zola9\Desktop\todo.txt () [File not signed]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\LocalCooling.lnk [2022-08-05]
ShortcutTarget: LocalCooling.lnk -> D:\Program Files (x86)\Uniblue\LocalCooling\localcooling2.exe (Uniblue Ltd) [File not signed]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Portmaster Notifier.lnk [2022-01-10]
ShortcutTarget: Portmaster Notifier.lnk -> C:\ProgramData\Safing\Portmaster\portmaster-start.exe (Safing ICS Technologies GmbH -> )
HKU\S-1-5-21-3578565935-3243947977-760430267-1001\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {F3904AB8-BCFA-4C5D-A7B7-8A77C155833B} - System32\Tasks\Ablaze\Floorp Default Browser Agent 22EB8429C9C8096C => C:\Program Files\Ablaze Floorp\default-browser-agent.exe [44368 2026-09-28] (SignPath Foundation -> Mozilla Foundation)
Task: {96A92592-BDC8-4603-9861-94671DEBE056} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1617408 2026-08-03] (Adobe Inc. -> Adobe Inc.)
Task: {7D82877C-547F-4D3C-8ECA-580FE22F23FF} - System32\Tasks\BraveSoftwareUpdateTaskMachineCore => C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [162384 2021-01-12] (Brave Software, Inc. -> BraveSoftware Inc.)
Task: {E117F825-B81D-4C32-86F3-BBC183BFE919} - System32\Tasks\BraveSoftwareUpdateTaskMachineUA => C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [162384 2021-01-12] (Brave Software, Inc. -> BraveSoftware Inc.)
Task: {11F0BBAB-AE10-4B8F-B179-32A26B3FF112} - System32\Tasks\DuplicatePhotoCleaner => C:\Program Files\Duplicate Photo Cleaner 7\DuplicatePhotoCleaner.exe [7191312 2023-09-25] (Webminds, Inc. -> Webminds, Inc.)
Task: {92165D97-8BA8-4313-AEDA-4EEDCB7801FC} - System32\Tasks\GadgetPack => C:\Program Files\Windows Sidebar\sidebar.exe [1448448 2024-11-01] (Microsoft Corporation) [File not signed] [File is in use] <==== ATTENTION
Task: {004CEF83-4DBB-4F09-B0BF-81CA64AE16E6} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [95752 2026-09-16] (HP Inc. -> HP Inc.)
Task: {D27F51F4-625C-4A79-86CF-2F7A9737A184} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor Logon => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [95752 2026-09-16] (HP Inc. -> HP Inc.)
Task: {04EA3BE9-9273-4EF9-B6CF-A15C12AE217E} - System32\Tasks\MATLAB R2017a Startup Accelerator => D:\Program Files\MATLAB\R2017a\bin\win64\MATLABStartupAccelerator.exe [47104 2017-01-19] () [File not signed]
Task: {71E78128-3161-4FB2-8D2A-51A6FDED47BF} - System32\Tasks\Microsoft\Office\Office Actions Server => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\ActionsServer\ActionsServer.exe [11735856 2026-09-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {B68DB1FC-F431-4C6B-870F-8518DFED9E0B} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28440976 2026-09-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {536D1B2D-8636-47BF-AC80-F52CA0C846F6} - System32\Tasks\Microsoft\Office\Office Background Push Maintenance => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonx86\Microsoft Shared\OFFICE16\opushutil.exe [62376 2026-09-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {434C44A6-ED10-42A5-8FC2-492512602332} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28440976 2026-09-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {4847AB5C-0A8F-4660-8C41-3C058F09253D} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [314736 2026-09-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {6D7ECC80-EEBF-4025-83F2-ABE0E90A1148} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [314736 2026-09-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {C23242B3-0F91-4FBA-BE04-A57ABAA43F87} - System32\Tasks\Microsoft\Office\Office Startup Maintenance => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\ActionsServer\ActionsServer.exe [11735856 2026-09-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {8E6756C5-7BDE-4546-81D1-6320549C623D} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Orchestrator => C:\Program Files (x86)\InstallShield Installation Information\{BB281145-A521-2EF3-B593-C5D534DC9911}\orchestrator.exe [1662662 2018-02-24] (MS) [File not signed]
Task: {805E3143-89EA-4DE1-87E3-695CB3F207DA} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Shutdown => C:\Program Files (x86)\InstallShield Installation Information\{BB281145-A521-2EF3-B593-C5D534DC9911}\orchestrator.exe [1662662 2018-02-24] (MS) [File not signed]
Task: {6FC94737-2C5E-4B83-B236-9CCF85FE446E} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MpCmdRun.exe [1902880 2026-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {61841ACC-D929-4321-9B9E-B6FF6E9C462A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MpCmdRun.exe [1902880 2026-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {D1CD6936-515E-430B-A78D-2B89D232E617} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MpCmdRun.exe [1902880 2026-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {F63C8F5A-1087-4284-A15D-CE09D1ADF0E4} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MpCmdRun.exe [1902880 2026-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {345711E0-897B-4A3C-82CB-B55B98386AC9} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [695424 2026-03-27] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {E8B861B0-4F21-44D5-BB0C-9A3B38DC4966} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-3578565935-3243947977-760430267-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [695424 2026-03-27] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {850E2EFA-DF80-4BDF-A81A-CF12DEED3378} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [34944 2026-03-27] (Mozilla Corporation -> Mozilla Foundation)
Task: {3943C375-214D-4DBF-BFEB-7CD70CDF261A} - System32\Tasks\Mozilla\Floorp Default Browser Agent 22EB8429C9C8096C => C:\Program Files\Ablaze Floorp\default-browser-agent.exe [44368 2026-09-28] (SignPath Foundation -> Mozilla Foundation)
Task: {EA5C6861-0AEA-46CD-A5F1-B4A6E663EC43} - System32\Tasks\MSIGH_Host => C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey.exe [3353784 2018-03-22] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.)
Task: {042DD5C2-C736-4C49-AFF4-6B75C2469655} - System32\Tasks\MSIOSDx64_Host => C:\Program Files (x86)\MSI\Gaming APP\OSD\x64\MsiGamingOSD_x64.exe (No File)
Task: {8EC7754E-7E13-4211-82E5-D3CB2678B114} - System32\Tasks\MSIOSDx86_Host => C:\Program Files (x86)\MSI\Gaming APP\OSD\x86\MsiGamingOSD_x86.exe (No File)
Task: {CEB73E5A-B541-4691-9E47-E08E294A32B0} - System32\Tasks\MSISW_Host => C:\Windows\SysWOW64\muachost.exe [1692840 2015-08-18] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
Task: {919249D9-461C-4176-B24F-C3DD46694E20} - System32\Tasks\Start Syncthing at logon (milos@MILOS) => C:\Users\zola9\AppData\Local\Programs\Syncthing\stctl.exe [169984 2025-08-18] (Bill Stewart (bstewart at iname.com)) [File not signed]
Task: {24889E5C-3032-44DE-8FD6-67F6771E6269} - System32\Tasks\TA Unofficial Patch Updater => D:\Games\Total Annihilation\updater.exe [321024 2013-10-03] (Total Annihilation Universe) [File not signed] -> D:\Games\Total Annihilation\\/silent
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\MATLAB R2017a Startup Accelerator.job => D:\Program Files\MATLAB\R2017a\bin\win64\MATLABStartupAccelerator.exe
Task: C:\WINDOWS\Tasks\MSISW_Host.job => C:\WINDOWS\SysWOW64\muachost.exe
Task: C:\WINDOWS\Tasks\TA Unofficial Patch Updater.job => D:\Games\Total Annihilation\updater.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 89.216.1.30 89.216.1.40 89.216.1.50
Tcpip\..\Interfaces\{dbc45994-4b14-4c4c-830f-c42a0fb20501}: [DhcpNameServer] 89.216.1.30 89.216.1.40 89.216.1.50
Tcpip\..\Interfaces\{dcbbf509-d9cd-47c0-88f5-3262324585c1}: [DhcpNameServer] 89.216.1.30 89.216.1.50
FireFox:
========
FF TaskBarID: 308046B0AF4A39CB -> C:\Program Files\Mozilla Firefox
FF TaskBarID: 22EB8429C9C8096C -> C:\Program Files\Ablaze Floorp
FF DefaultProfile: qcrxq59e.default-1525289934905 -> 308046B0AF4A39CB
FF DefaultProfile: wfhg3ecj.default-release -> 22EB8429C9C8096C
FF ProfilePath: C:\Users\zola9\AppData\Roaming\Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905 [2026-09-28]
FF Homepage: Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905 -> [Link mogu videti samo ulogovani korisnici]
FF Extension: (Firefox DevTools ADB Extension) - C:\Users\zola9\AppData\Roaming\Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905\Extensions\adb@mozilla.org.xpi [2024-04-22] [UpdateUrl:hxxps://ftp.mozilla.org/pub/labs/devtools/adb-extension/win32/update.json]
FF Extension: (Arc Dark Theme) - C:\Users\zola9\AppData\Roaming\Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905\Extensions\arc-dark-theme@afnankhan.xpi [2021-06-02]
FF Extension: (Arc Darker Theme) - C:\Users\zola9\AppData\Roaming\Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905\Extensions\arc-darker-theme@afnankhan.xpi [2020-08-28]
FF Extension: (Enhancer for YouTube™) - C:\Users\zola9\AppData\Roaming\Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905\Extensions\enhancerforyoutube@maximerf.addons.mozilla.org.xpi [2024-12-02]
FF Extension: (АудД® музичко препознавање) - C:\Users\zola9\AppData\Roaming\Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905\Extensions\firefox@audd.tech.xpi [2025-11-08]
FF Extension: (Tampermonkey) - C:\Users\zola9\AppData\Roaming\Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905\Extensions\firefox@tampermonkey.net.xpi [2025-11-13]
FF Extension: (Terms of Service; Didn’t Read) - C:\Users\zola9\AppData\Roaming\Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905\Extensions\jid0-3GUEt1r69sQNSrca5p8kx9Ezc3U@jetpack.xpi [2025-07-01]
FF Extension: (Substital: Add subtitles to videos and movies) - C:\Users\zola9\AppData\Roaming\Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905\Extensions\jid1-Cn7LiNrWh4k6RA@jetpack.xpi [2025-11-08]
FF Extension: (Privacy Badger) - C:\Users\zola9\AppData\Roaming\Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905\Extensions\jid1-MnnxcxisBPnSXQ@jetpack.xpi [2025-11-08]
FF Extension: (AdBlock — block ads across the web) - C:\Users\zola9\AppData\Roaming\Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905\Extensions\jid1-NIfFY2CA8fy1tg@jetpack.xpi [2025-11-13]
FF Extension: (Dark Background and Light Text) - C:\Users\zola9\AppData\Roaming\Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905\Extensions\jid1-QoFqdK4qzUfGWQ@jetpack.xpi [2021-02-09]
FF Extension: (JSONView) - C:\Users\zola9\AppData\Roaming\Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905\Extensions\jsonview@brh.numbera.com.xpi [2025-07-01]
FF Extension: (Context Search) - C:\Users\zola9\AppData\Roaming\Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905\Extensions\olivier.debroqueville@gmail.com.xpi [2024-08-20]
FF Extension: (Open Multiple URLs) - C:\Users\zola9\AppData\Roaming\Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905\Extensions\openmultipleurls@ustat.de.xpi [2025-07-01]
FF Extension: (Playback speed) - C:\Users\zola9\AppData\Roaming\Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905\Extensions\playbackSpeed@waldemar.b.xpi [2021-11-07]
FF Extension: (Side View) - C:\Users\zola9\AppData\Roaming\Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905\Extensions\side-view@mozilla.org.xpi [2024-11-18]
FF Extension: (Skip Redirect) - C:\Users\zola9\AppData\Roaming\Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905\Extensions\skipredirect@sblask.xpi [2022-10-15]
FF Extension: (uBlock Origin) - C:\Users\zola9\AppData\Roaming\Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905\Extensions\uBlock0@raymondhill.net.xpi [2025-11-13]
FF Extension: (TWP - Translate Web Pages) - C:\Users\zola9\AppData\Roaming\Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905\Extensions\{036a55b4-5e72-4d05-a06c-cba2dfcc134a}.xpi [2025-07-01]
FF Extension: (Video Speed Control) - C:\Users\zola9\AppData\Roaming\Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905\Extensions\{24e032ab-bf0b-41ad-b404-79abc127bcbf}.xpi [2025-11-08]
FF Extension: (REST Client APIsHub) - C:\Users\zola9\AppData\Roaming\Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905\Extensions\{2a0af89a-02d2-4b63-aecd-58fe408f0541}.xpi [2024-10-18]
FF Extension: (Search by Image) - C:\Users\zola9\AppData\Roaming\Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905\Extensions\{2e5ff8c8-32fe-46d0-9fc8-6b8986621f3c}.xpi [2025-11-08]
FF Extension: (OCR_extension) - C:\Users\zola9\AppData\Roaming\Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905\Extensions\{4478e81c-ef1c-43d1-9197-fdcaf7f3d135}.xpi [2025-11-08]
FF Extension: (Add 9 to page number) - C:\Users\zola9\AppData\Roaming\Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905\Extensions\{57B65ABB-F4E3-4358-8472-15AEE0833E11}.xpi [2024-06-12]
FF Extension: (Return YouTube Dislike) - C:\Users\zola9\AppData\Roaming\Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905\Extensions\{762f9885-5a13-4abd-9c77-433dcd38b8fd}.xpi [2024-10-28]
FF Extension: (Flash Player ) - C:\Users\zola9\AppData\Roaming\Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905\Extensions\{87e997f4-ae0e-42e6-a780-ff73977188c5}.xpi [2022-11-30]
FF Extension: (Понављање Иоутубеа, убрзавање ХТМЛ5 видео записа) - C:\Users\zola9\AppData\Roaming\Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905\Extensions\{8c621a61-a261-4651-9818-a0b75b82ebb0}.xpi [2022-02-20]
FF Extension: (Feedbro) - C:\Users\zola9\AppData\Roaming\Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905\Extensions\{a9c2ad37-e940-4892-8dce-cd73c6cbbc0c}.xpi [2024-03-27]
FF Extension: (a debugger for RESTful web services.) - C:\Users\zola9\AppData\Roaming\Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905\Extensions\{ad0d925d-88f8-47f1-85ea-8463569e756e}.xpi [2024-04-25]
FF Extension: (Right Click Search) - C:\Users\zola9\AppData\Roaming\Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905\Extensions\{bbbb88d7-7da7-47e6-8836-d7d329e92dd9}.xpi [2021-07-13]
FF Extension: (Matte Black (White)) - C:\Users\zola9\AppData\Roaming\Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905\Extensions\{bcf9bb24-1417-4c9e-b901-1ffa328ba873}.xpi [2022-02-24]
FF Extension: (Greasemonkey) - C:\Users\zola9\AppData\Roaming\Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2025-03-11]
FF Extension: (OCR - Image Reader) - C:\Users\zola9\AppData\Roaming\Mozilla\Firefox\Profiles\qcrxq59e.default-1525289934905\Extensions\{e4c6eef1-8b3b-4daa-8757-707702e7528d}.xpi [2025-11-08]
FF ProfilePath: C:\Users\zola9\AppData\Roaming\Floorp\Profiles\51hzullf.default [2025-03-09]
FF ProfilePath: C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release [2026-09-29]
FF Homepage: Floorp\Profiles\wfhg3ecj.default-release -> [Link mogu videti samo ulogovani korisnici]
FF Extension: (Firefox DevTools ADB Extension) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\adb@mozilla.org.xpi [2024-04-22] [UpdateUrl:hxxps://ftp.mozilla.org/pub/labs/devtools/adb-extension/win32/update.json]
FF Extension: (Arc Dark Theme) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\arc-dark-theme@afnankhan.xpi [2021-06-02]
FF Extension: (Arc Darker Theme) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\arc-darker-theme@afnankhan.xpi [2020-08-28]
FF Extension: (CORS Everywhere) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\cors-everywhere@spenibus.xpi [2025-10-13]
FF Extension: (Enhancer for YouTube™) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\enhancerforyoutube@maximerf.addons.mozilla.org.xpi [2026-08-04]
FF Extension: (АудД® музичко препознавање) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\firefox@audd.tech.xpi [2025-08-06]
FF Extension: (Tampermonkey) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\firefox@tampermonkey.net.xpi [2026-05-22]
FF Extension: (Terms of Service; Didn’t Read) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\jid0-3GUEt1r69sQNSrca5p8kx9Ezc3U@jetpack.xpi [2025-04-03]
FF Extension: (Substital: Add subtitles to videos and movies) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\jid1-Cn7LiNrWh4k6RA@jetpack.xpi [2026-04-24]
FF Extension: (Privacy Badger) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\jid1-MnnxcxisBPnSXQ@jetpack.xpi [2026-09-16]
FF Extension: (AdBlock — block ads across the web) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\jid1-NIfFY2CA8fy1tg@jetpack.xpi [2026-09-16]
FF Extension: (Dark Background and Light Text) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\jid1-QoFqdK4qzUfGWQ@jetpack.xpi [2026-09-09]
FF Extension: (JSONView) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\jsonview@brh.numbera.com.xpi [2025-05-26]
FF Extension: (Context Search) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\olivier.debroqueville@gmail.com.xpi [2024-08-20]
FF Extension: (Open Multiple URLs) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\openmultipleurls@ustat.de.xpi [2025-04-28]
FF Extension: (Playback speed) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\playbackSpeed@waldemar.b.xpi [2021-11-07]
FF Extension: (Side View) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\side-view@mozilla.org.xpi [2024-11-18]
FF Extension: (Skip Redirect) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\skipredirect@sblask.xpi [2026-08-20]
FF Extension: (uBlock Origin) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\uBlock0@raymondhill.net.xpi [2026-09-18]
FF Extension: (TWP - Translate Web Pages) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\{036a55b4-5e72-4d05-a06c-cba2dfcc134a}.xpi [2026-08-18]
FF Extension: (Local Image File Viewer) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\{13c9fd7a-58f4-4a28-9ff9-75e54ad1d540}.xpi [2026-03-20]
FF Extension: (Video Speed Control) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\{24e032ab-bf0b-41ad-b404-79abc127bcbf}.xpi [2026-06-28]
FF Extension: (Trancy - AI Translator & Dual Subtitles) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\{29f42579-9618-4dc7-8647-eaad7cd3343e}.xpi [2026-09-18]
FF Extension: (REST Client APIsHub) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\{2a0af89a-02d2-4b63-aecd-58fe408f0541}.xpi [2024-10-18]
FF Extension: (Search by Image) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\{2e5ff8c8-32fe-46d0-9fc8-6b8986621f3c}.xpi [2026-06-12]
FF Extension: (OCR_extension) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\{4478e81c-ef1c-43d1-9197-fdcaf7f3d135}.xpi [2025-09-21]
FF Extension: (Gesturefy) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\{506e023c-7f2b-40a3-8066-bc5deb40aebe}.xpi [2026-09-26]
FF Extension: (Add 9 to page number) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\{57B65ABB-F4E3-4358-8472-15AEE0833E11}.xpi [2024-06-12]
FF Extension: (Return YouTube Dislike) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\{762f9885-5a13-4abd-9c77-433dcd38b8fd}.xpi [2026-09-13]
FF Extension: (Flash Player ) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\{87e997f4-ae0e-42e6-a780-ff73977188c5}.xpi [2022-11-30]
FF Extension: (Понављање Иоутубеа, убрзавање ХТМЛ5 видео записа) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\{8c621a61-a261-4651-9818-a0b75b82ebb0}.xpi [2022-02-20]
FF Extension: (Show QRcode) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\{9aeca40d-0ccc-400e-9054-464403277ce1}.xpi [2026-09-07]
FF Extension: (Feedbro) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\{a9c2ad37-e940-4892-8dce-cd73c6cbbc0c}.xpi [2024-03-27]
FF Extension: (Custom Site JS) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\{acffb7c6-3759-4e93-9676-f916e4c0accb}.xpi [2025-03-10]
FF Extension: (a debugger for RESTful web services.) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\{ad0d925d-88f8-47f1-85ea-8463569e756e}.xpi [2024-04-25]
FF Extension: (Video Download Helper) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2026-09-24]
FF Extension: (Right Click Search) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\{bbbb88d7-7da7-47e6-8836-d7d329e92dd9}.xpi [2021-07-13]
FF Extension: (Matte Black (White)) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\{bcf9bb24-1417-4c9e-b901-1ffa328ba873}.xpi [2022-02-24]
FF Extension: (600% Jačina zvuka) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\{c4b582ec-4343-438c-bda2-2f691c16c262}.xpi [2025-07-15]
FF Extension: (javascript) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\{d4bc778f-3a98-44f4-9b2e-45fab92a21db}.xpi [2025-03-10]
FF Extension: (Greasemonkey) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2026-06-08]
FF Extension: (OCR - Image Reader) - C:\Users\zola9\AppData\Roaming\Floorp\Profiles\wfhg3ecj.default-release\Extensions\{e4c6eef1-8b3b-4daa-8757-707702e7528d}.xpi [2026-08-26]
FF HKLM-x32\...\Firefox\Extensions: [quickprint@hp.com] - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension
FF Extension: (SmartPrintButton) - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension [2011-01-26] [Legacy] [not signed]
FF Plugin: @java.com/DTPlugin,version=11.503.2 -> C:\Program Files\Java\jre1.8.0_503\bin\dtplugin\npDeployJava1.dll [2026-07-23] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.503.2 -> C:\Program Files\Java\jre1.8.0_503\bin\plugin2\npjp2.dll [2026-07-23] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2026-09-16] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.503.2 -> C:\Program Files (x86)\Java\jre1.8.0_503\bin\dtplugin\npDeployJava1.dll [2026-07-23] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.503.2 -> C:\Program Files (x86)\Java\jre1.8.0_503\bin\plugin2\npjp2.dll [2026-07-23] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2026-08-21] (Microsoft Corporation -> Microsoft Corporation)
StartMenuInternet: Firefox-22EB8429C9C8096C - C:\Program Files\Ablaze Floorp\floorp.exe
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\zola9\AppData\Local\Microsoft\Edge\User Data\Default [2026-09-28]
Edge DownloadDir: C:\Users\zola9\Downloads
Edge Notifications: Default -> [Link mogu videti samo ulogovani korisnici] [Link mogu videti samo ulogovani korisnici]
Edge HomePage: Default -> [Link mogu videti samo ulogovani korisnici]
Edge Extension: (External Application Launcher) - C:\Users\zola9\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bifmfjgpgndemajpeeoiopbeilbaifdo [2026-07-29]
Edge Extension: (Custom JavaScript for Websites 2) - C:\Users\zola9\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ddbjnfjiigjmcpcpkmhogomapikjbjdk [2025-01-04]
Edge Extension: (Custom Style Script) - C:\Users\zola9\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\eocdolakkgkbmnfojgicnicdnmimfhoo [2026-06-28]
Edge Extension: (Google документи офлајн) - C:\Users\zola9\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-08-21]
Edge Extension: (Edge relevant text changes) - C:\Users\zola9\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-02-15]
Edge Extension: (Speech Translator) - C:\Users\zola9\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jodfjmaiakpnmeddgpeflpafebmlhppn [2026-07-28]
Edge Extension: (Open in Firefox™ Browser) - C:\Users\zola9\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\lmeddoobegbaiopohmpmmobpnpjifpii [2026-03-13]
Edge Extension: (uBlock Origin) - C:\Users\zola9\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\odfafepnkmbhccpbejgmiehpchacaeak [2026-09-01]
Edge Extension: (Next Page) - C:\Users\zola9\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\onajnlcpcfhahbmnppgkajefblapkhln [2025-02-08]
Edge DownloadDir: Default -> C:\Users\zola9\Downloads
Brave:
=======
BRA DefaultProfile: Default
BRA Profile: C:\Users\zola9\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default [2026-09-28]
BRA HomePage: Default -> [Link mogu videti samo ulogovani korisnici]
BRA NewTab: Default -> Active:"chrome-extension://jbfeongihppeenfnaofmdeikahaefljd/newtab.html"
BRA Extension: (Prevodilac Slika - Photo Translate) - C:\Users\zola9\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\docbjjoadpgkaokfihfbhaipmpacpfbc [2026-03-17]
BRA Extension: (Enhanced Image Viewer) - C:\Users\zola9\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\gefiaaeadjbmhjndnhedfccdjjlgjhho [2026-06-11]
BRA Extension: (Manganum: Sidebar with Gmail and Google Calendar) - C:\Users\zola9\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\jbfeongihppeenfnaofmdeikahaefljd [2025-10-19]
BRA Extension: (Brave Ad Block Updater (Brave First Party Adblock Filters (plaintext))) - C:\Users\zola9\AppData\Local\BraveSoftware\Brave-Browser\User Data\adcocjohghhfpidemphmcmlmhnfgikei [2026-09-25]
BRA Extension: (Brave Local Data Files Updater) - C:\Users\zola9\AppData\Local\BraveSoftware\Brave-Browser\User Data\afalakplffnnnlkncjhbmahjfjhmlkal [2026-09-27]
BRA Extension: (Brave NTP background images) - C:\Users\zola9\AppData\Local\BraveSoftware\Brave-Browser\User Data\aoojcmojmmcbpfgoecoadbdpnagfchel [2026-09-25]
BRA Extension: (Brave Ad Block Updater (Mobile app promo blocker (plaintext))) - C:\Users\zola9\AppData\Local\BraveSoftware\Brave-Browser\User Data\bfpgedeaaibpoidldhjcknekahbikncb [2026-09-25]
BRA Extension: (Wallet Data Files Updater) - C:\Users\zola9\AppData\Local\BraveSoftware\Brave-Browser\User Data\BraveWallet [2023-08-13]
BRA Extension: (Brave Ad Block Updater (Cookie notice blocker (plaintext))) - C:\Users\zola9\AppData\Local\BraveSoftware\Brave-Browser\User Data\cdbbhgbmjhfnhnmgeddbliobbofkgdhe [2026-09-27]
BRA Extension: (Query Filter) - C:\Users\zola9\AppData\Local\BraveSoftware\Brave-Browser\User Data\cemdlagocoimleflkfkjoihojfainiho [2026-09-28]
BRA Extension: (Brave Ad Block Updater (Default)) - C:\Users\zola9\AppData\Local\BraveSoftware\Brave-Browser\User Data\cffkpbalmllkdoenhmdmpbkajipdjfam [2022-10-11]
BRA Extension: (Brave Tor Client Updater (Windows)) - C:\Users\zola9\AppData\Local\BraveSoftware\Brave-Browser\User Data\cpoalefficncklhjfpglfiplenlpccdb [2024-10-29]
BRA Extension: (Brave Ad Block Updater (Allow X/Twitter Embeds (plaintext))) - C:\Users\zola9\AppData\Local\BraveSoftware\Brave-Browser\User Data\dkpggglmbjhgjhachikgmohmecomjndo [2026-08-01]
BRA Extension: (Brave WebMCP Tool Scripts) - C:\Users\zola9\AppData\Local\BraveSoftware\Brave-Browser\User Data\eingdhelnaolbpcdkgddekhifcjfkalf [2026-09-13]
BRA Extension: (Brave Ad Block Updater (Regional Catalog)) - C:\Users\zola9\AppData\Local\BraveSoftware\Brave-Browser\User Data\gkboaolpopklhgplhaaiboijnklogmbc [2026-09-09]
BRA Extension: (Brave Ad Block Updater (Brave Default Adblock Filters (plaintext))) - C:\Users\zola9\AppData\Local\BraveSoftware\Brave-Browser\User Data\iodkpdagapdfkphljnddpjlldadblomo [2026-09-27]
BRA Extension: (Brave SpeedReader Updater) - C:\Users\zola9\AppData\Local\BraveSoftware\Brave-Browser\User Data\jicbkmdloagakknpihibphagfckhjdih [2022-04-02]
BRA Extension: (Brave Ad Block Updater (Allow Facebook Embeds (plaintext))) - C:\Users\zola9\AppData\Local\BraveSoftware\Brave-Browser\User Data\jmfhneobcdckobmonkfjkbknnjjnegoh [2026-08-01]
BRA Extension: (Brave Ad Block Updater (Brave Default Privacy Filters (plaintext))) - C:\Users\zola9\AppData\Local\BraveSoftware\Brave-Browser\User Data\kihnoaefogbkmblfimmibknnmkllbhlf [2026-09-27]
BRA Extension: (Brave Ad Block Updater (Resources)) - C:\Users\zola9\AppData\Local\BraveSoftware\Brave-Browser\User Data\mfddibmblmbccpadfndgakiopmmhebop [2026-09-18]
BRA Extension: (Brave NTP sponsored images) - C:\Users\zola9\AppData\Local\BraveSoftware\Brave-Browser\User Data\nkegnmcaaingjdpfadapphceooopdkpj [2026-09-28]
BRA Extension: (Brave User Agent) - C:\Users\zola9\AppData\Local\BraveSoftware\Brave-Browser\User Data\nlpaeekllejnmhoonlpcefpfnpbajbpe [2026-09-28]
BRA Extension: (Brave HTTPS Everywhere Updater) - C:\Users\zola9\AppData\Local\BraveSoftware\Brave-Browser\User Data\oofiananboodjbbmdelgdommihjbkfag [2023-08-13]
BRA Extension: (P3A Configuration) - C:\Users\zola9\AppData\Local\BraveSoftware\Brave-Browser\User Data\P3AConfig [2025-10-09]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [182776 2026-08-03] (Adobe Inc. -> Adobe Inc.)
R2 Autodesk Access Service Host; C:\Program Files\Autodesk\AdODIS\V1\Setup\AdskAccessServiceHost.exe [19981080 2025-06-07] (Autodesk, Inc. -> Autodesk, Inc.)
S2 brave; C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [162384 2021-01-12] (Brave Software, Inc. -> BraveSoftware Inc.)
S3 BraveElevationService; C:\Program Files\BraveSoftware\Brave-Browser\Application\154.1.96.59\elevation_service.exe [5166672 2026-09-24] (Brave Software, Inc. -> Brave Software, Inc.)
S3 bravem; C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [162384 2021-01-12] (Brave Software, Inc. -> BraveSoftware Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [13372816 2026-09-15] (Microsoft Corporation -> Microsoft Corporation)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [4452456 2019-09-26] (AVB Disc Soft, SIA -> Disc Soft Ltd)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [774272 2018-08-26] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
S3 GalaxyClientService; C:\Program Files (x86)\GOG Galaxy\GalaxyClientService.exe [2422096 2025-06-08] (GOG sp. z o.o -> GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [7654224 2025-06-08] (GOG sp. z o.o -> GOG.com)
R2 GamingApp_Service; C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe [48824 2018-04-11] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.)
R2 GamingHotkey_Service; C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe [2027192 2018-03-22] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.)
R2 HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [136704 2009-06-24] (HP) [File not signed]
R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [243720 2026-09-16] (HP Inc. -> HP Inc.)
R2 HPSIService; C:\WINDOWS\system32\HPSIsvc.exe [126880 2012-09-27] (Hewlett-Packard Company -> HP)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [11671792 2026-09-07] (Malwarebytes Inc -> Malwarebytes)
S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [4291576 2026-06-13] (Malwarebytes Inc -> Malwarebytes)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MpDefenderCoreService.exe [2307776 2026-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 MSI_ActiveX_Service; C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\MSI_ActiveX_Service.exe [83104 2018-03-19] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\Display.NvContainer\NVDisplay.Container.exe [1275568 2024-12-04] (NVIDIA Corporation -> NVIDIA Corporation)
R2 PortmasterCore; C:\ProgramData\Safing\Portmaster\portmaster-start.exe [14014488 2024-01-18] (Safing ICS Technologies GmbH -> )
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [803064 2025-10-14] (Microsoft Windows Publisher -> Microsoft Corporation)
S4 Update service; C:\Program Files (x86)\Popcorn Time\Updater.exe [339968 2018-04-06] (Popcorn Time) [File not signed]
S3 VBoxSDS; C:\Program Files\Oracle\VirtualBox\VBoxSDS.exe [690424 2019-01-25] (Oracle Corporation -> Oracle Corporation)
S3 VSStandardCollectorService150; D:\Program Files (x86)\Microsoft Visual Studio\Shared\Common\DiagnosticsHub.Collection.Service\StandardCollector.Service.exe [157480 2018-08-02] (Microsoft Corporation -> Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\NisSrv.exe [5311776 2026-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MsMpEng.exe [291360 2026-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 NativePushService; "C:\Users\zola9\AppData\Local\Wondershare\Wondershare NativePush\WsNativePushService.exe" (No File)
S3 YaCy; "C:\Program Files\YaCy\addon\windowsService\amd64\prunsrv.exe" //RS//YaCy (No File)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AsrDrv101; \??\C:\Windows\SysWOW64\Drivers\AsrDrv101.sys [22280 2018-05-02] (ASROCK Incorporation -> )
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [42256 2019-09-26] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [59360 2019-09-26] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R1 ESProtectionDriver; \??\C:\WINDOWS\system32\drivers\mbae.sys [159296 2025-07-29] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 gcdbus; C:\WINDOWS\System32\drivers\gcdbus.sys [168960 2018-10-17] (Power Software Limited -> Power Software Ltd)
R3 I2cHkBurn; C:\WINDOWS\system32\drivers\I2cHkBurn.sys [41760 2015-07-26] (Feature Integration Technology -> FINTEK Corp.)
R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [83008 2026-09-07] (Microsoft Windows -> Microsoft Corporation)
R2 mbamchameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [235624 2026-09-28] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [22120 2025-03-08] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\Drivers\farflt.sys [215656 2026-09-28] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\System32\Drivers\mbam.sys [132712 2026-09-29] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [246376 2026-07-10] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMWebProtection; \??\C:\WINDOWS\system32\DRIVERS\mwac.sys [190096 2026-09-29] (Malwarebytes Inc -> )
S3 mvusbews; C:\WINDOWS\System32\Drivers\mvusbews.sys [20480 2012-09-26] (Microsoft Windows Hardware Compatibility Publisher -> Marvell Semiconductor, Inc.)
R2 NPF; C:\WINDOWS\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.)
S3 NTIOLib_MBAPI; \??\C:\Program Files (x86)\MSI\Gaming APP\Lib\NTIOLib_X64.sys [14288 2017-07-10] (MICRO-STAR INTERNATIONAL CO., LTD. -> )
R3 PortmasterKext; \??\C:\ProgramData\Safing\Portmaster\updates\windows_amd64\kext\portmaster-kext_v1-1-2.sys [70024 2023-08-21] (Microsoft Windows Hardware Compatibility Publisher -> )
R2 speedfan; \??\C:\WINDOWS\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> )
S3 usbrndis6; C:\WINDOWS\System32\drivers\usb80236.sys [24064 2020-09-10] (Microsoft Corporation) [File not signed]
S3 VBoxNetAdp; C:\WINDOWS\System32\drivers\VBoxNetAdp6.sys [235832 2019-01-28] (Oracle Corporation -> Oracle Corporation)
R1 VBoxNetLwf; C:\WINDOWS\system32\DRIVERS\VBoxNetLwf.sys [247216 2019-01-28] (Oracle Corporation -> Oracle Corporation)
S4 WdAiNisDrv; C:\WINDOWS\System32\drivers\wd\WdAiNisDrv.sys [51264 2026-09-18] (Microsoft Windows -> Microsoft Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [21632 2026-09-18] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [664592 2026-09-18] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [137240 2026-09-18] (Microsoft Windows -> Microsoft Corporation)
R3 wovad_micarray; C:\WINDOWS\system32\drivers\womic.sys [34496 2020-02-16] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
S3 dg_ssudbus; \SystemRoot\system32\DRIVERS\ssudbus2.sys (No File)
S4 nvvhci; \SystemRoot\System32\drivers\nvvhci.sys (No File)
S3 ssudmdm; \SystemRoot\system32\DRIVERS\ssudmdm.sys (No File)
==================== SvcHost (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-09-29 19:29 - 2026-09-29 19:30 - 000055490 _____ C:\Users\zola9\Desktop\FRST.txt
2026-09-29 19:23 - 2026-09-29 19:23 - 000000000 ____D C:\Users\zola9\Desktop\v1
2026-09-29 18:32 - 2026-09-29 19:30 - 000000000 ____D C:\FRST
2026-09-29 18:21 - 2026-09-29 18:25 - 000000000 ____D C:\Users\zola9\AppData\LocalLow\IGDump
2026-09-29 18:20 - 2026-09-29 18:20 - 000190096 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2026-09-28 22:17 - 2026-09-28 22:06 - 002455552 _____ (Farbar) C:\Users\zola9\Desktop\FRST64.exe
2026-09-28 21:14 - 2026-09-28 21:14 - 000000000 ____D C:\WINDOWS\Panther
2026-09-28 20:15 - 2026-09-28 21:28 - 136314880 _____ C:\WINDOWS\system32\config\SOFTWARE
2026-09-28 20:15 - 2026-09-28 20:15 - 000000000 ____D C:\WINDOWS\Microsoft Antimalware
2026-09-28 18:32 - 2026-09-28 20:40 - 000000022 _____ C:\Users\zola9\Desktop\virus.txt
2026-09-28 18:16 - 2026-09-28 18:16 - 000000000 ____D C:\WINDOWS\system32\Tasks\Ablaze
2026-09-28 01:19 - 2026-09-28 01:20 - 000000000 ____D C:\Users\Public\.ff_tmp
2026-09-28 01:19 - 2026-09-28 01:19 - 000000000 ____D C:\Users\zola9\AppData\Local\Intel
2026-09-25 01:13 - 2026-09-25 01:13 - 012889269 _____ C:\Users\zola9\Downloads\Видео запис Facebook.mp4
2026-09-17 22:35 - 2026-09-17 22:35 - 000001340 _____ C:\Users\zola9\Desktop\gzdoom - prečica.lnk
2026-09-17 20:06 - 2026-09-17 20:06 - 000001485 _____ C:\Users\zola9\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord.lnk
2026-09-14 01:16 - 2026-09-14 01:16 - 000000389 _____ C:\Users\zola9\.claude.json
2026-09-14 01:16 - 2026-09-14 01:16 - 000000000 ____D C:\Users\zola9\.claude
2026-09-13 15:01 - 2026-09-13 15:01 - 000000000 ____D C:\Program Files (x86)\Java
2026-09-13 15:01 - 2026-07-23 12:49 - 000182456 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2026-09-13 15:01 - 2026-07-23 12:40 - 000214712 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll
2026-09-01 20:31 - 2026-09-01 20:31 - 001385718 _____ C:\Users\zola9\Downloads\Dunav potvrda o osiguranju 1641357.pdf
2026-09-01 20:25 - 2026-09-01 20:25 - 001385723 _____ C:\Users\zola9\Downloads\Dunav potvrda o osiguranju 1641348.pdf
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-09-29 19:27 - 2021-12-19 06:12 - 000000000 ____D C:\WINDOWS\SystemTemp
2026-09-29 19:25 - 2023-05-01 11:38 - 000000000 ____D C:\Users\zola9\AppData\Local\Malwarebytes
2026-09-29 19:21 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-09-29 18:28 - 2020-08-25 12:08 - 000921844 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2026-09-29 18:28 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2026-09-29 18:28 - 2018-05-02 17:29 - 000075748 _____ C:\WINDOWS\system32\perfh01A.dat
2026-09-29 18:28 - 2018-05-02 17:29 - 000020206 _____ C:\WINDOWS\system32\perfc01A.dat
2026-09-29 18:22 - 2019-12-17 19:46 - 000000000 ____D C:\ProgramData\boost_interprocess
2026-09-29 18:21 - 2026-03-20 20:51 - 000000000 ____D C:\Users\zola9\AppData\Local\Syncthing
2026-09-29 18:20 - 2024-06-28 18:39 - 000000000 ____D C:\Intel
2026-09-29 18:20 - 2020-08-25 12:05 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2026-09-29 18:20 - 2020-08-25 11:58 - 000008192 ___SH C:\DumpStack.log.tmp
2026-09-29 18:20 - 2018-05-02 14:30 - 000000000 ____D C:\ProgramData\NVIDIA
2026-09-28 21:28 - 2019-12-07 11:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2026-09-28 20:44 - 2022-02-11 19:36 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2026-09-28 20:43 - 2021-10-10 11:59 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2026-09-28 19:32 - 2025-10-27 19:23 - 000000000 ____D C:\ProgramData\Noraneko-1de4eec8-1241-4177-a864-e594e8d1fb38
2026-09-28 18:33 - 2018-12-31 19:29 - 000000000 ____D C:\Users\zola9\AppData\Roaming\.minecraft
2026-09-28 18:33 - 2018-09-19 19:45 - 000000000 ___RD C:\Users\zola9\Desktop\Igrice
2026-09-28 18:17 - 2025-03-09 20:39 - 000000000 ____D C:\Program Files\Ablaze Floorp
2026-09-28 18:16 - 2026-08-28 19:01 - 000002133 _____ C:\Users\zola9\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Floorp.lnk
2026-09-28 18:16 - 2025-03-09 20:39 - 000001079 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Floorp.lnk
2026-09-28 18:16 - 2020-08-25 11:58 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2026-09-28 13:48 - 2018-05-02 16:50 - 000000000 ____D C:\Users\zola9\AppData\Local\CrashDumps
2026-09-28 02:34 - 2018-07-19 11:02 - 000000000 ____D C:\Users\zola9\AppData\Roaming\Microsoft\Excel
2026-09-28 01:11 - 2024-03-22 23:29 - 000000000 ____D C:\Users\zola9\AppData\Roaming\RenPy
2026-09-27 12:29 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2026-09-27 12:29 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2026-09-27 01:24 - 2018-09-19 19:43 - 000000000 ___RD C:\Users\zola9\Desktop\nesto
2026-09-26 18:30 - 2025-06-11 19:12 - 000000000 ____D C:\ProgramData\GamingGaiden
2026-09-26 03:04 - 2019-10-29 18:42 - 000000000 ____D C:\Users\zola9\AppData\Roaming\Code
2026-09-26 03:04 - 2019-10-29 18:42 - 000000000 ____D C:\Users\zola9\AppData\Local\Programs\Microsoft VS Code
2026-09-26 00:11 - 2018-05-02 14:16 - 000000000 ____D C:\Users\zola9\AppData\Local\Packages
2026-09-25 18:41 - 2018-05-02 14:39 - 000000000 ____D C:\Users\zola9\AppData\Local\D3DSCache
2026-09-25 17:34 - 2020-06-08 01:00 - 000002473 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2026-09-25 00:26 - 2018-12-18 21:00 - 000000000 ____D C:\Users\zola9\AppData\Roaming\discord
2026-09-24 23:47 - 2021-01-12 12:44 - 000002537 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brave.lnk
2026-09-24 23:17 - 2018-12-18 21:00 - 000000000 ____D C:\Users\zola9\AppData\Local\Discord
2026-09-23 20:33 - 2020-06-02 23:25 - 000000000 ____D C:\Users\zola9\AppData\Roaming\.tlauncher
2026-09-23 08:53 - 2026-05-10 21:47 - 000000082 _____ C:\Users\zola9\Desktop\rd.txt
2026-09-22 23:23 - 2025-01-27 22:33 - 000003570 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-3578565935-3243947977-760430267-1001
2026-09-22 23:23 - 2021-12-11 23:15 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3578565935-3243947977-760430267-1001
2026-09-22 23:23 - 2020-08-25 12:05 - 000003358 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3578565935-3243947977-760430267-1001
2026-09-22 23:23 - 2020-08-25 11:59 - 000002422 _____ C:\Users\zola9\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2026-09-22 23:23 - 2018-05-02 14:18 - 000000000 ___RD C:\Users\zola9\OneDrive
2026-09-22 18:05 - 2019-02-28 22:34 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2026-09-20 23:34 - 2025-11-14 21:17 - 000000000 ____D C:\Users\zola9\AppData\Local\Ollama
2026-09-20 23:06 - 2026-03-15 18:32 - 000000000 ____D C:\Users\zola9\Desktop\sto
2026-09-20 00:26 - 2020-08-25 12:05 - 000003534 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2026-09-20 00:26 - 2020-08-25 12:05 - 000003462 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2026-09-19 18:24 - 2022-10-11 21:49 - 000002179 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2026-09-19 18:24 - 2020-08-25 12:05 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2026-09-18 08:14 - 2018-05-02 14:07 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2026-09-17 20:06 - 2018-12-18 21:00 - 000002278 _____ C:\Users\zola9\Desktop\Discord.lnk
2026-09-16 17:44 - 2023-08-05 16:07 - 000000000 ____D C:\WINDOWS\system32\Tasks\HP
2026-09-16 17:44 - 2023-07-14 22:23 - 000000000 ____D C:\Program Files\HPPrintScanDoctor
2026-09-15 22:38 - 2018-05-02 16:55 - 000000000 ____D C:\Users\zola9\AppData\Roaming\qBittorrent
2026-09-14 01:16 - 2020-08-25 11:59 - 000000000 ____D C:\Users\zola9
2026-09-13 15:02 - 2019-01-03 00:51 - 000000000 ____D C:\Program Files\Java
2026-09-13 15:01 - 2023-04-27 18:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2026-09-13 15:01 - 2018-11-24 19:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit
2026-09-09 07:44 - 2018-05-08 20:19 - 000000000 ____D C:\WINDOWS\system32\MRT
2026-09-09 07:38 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2026-09-09 07:38 - 2018-05-08 20:18 - 230964456 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2026-09-09 06:00 - 2026-03-20 20:51 - 000000000 ____D C:\Users\zola9\AppData\Local\Programs\Syncthing
2026-09-01 21:13 - 2022-01-20 22:14 - 000011338 _____ C:\Users\zola9\Desktop\vez.txt
==================== Files in the root of some directories ========
2018-09-19 19:44 - 2022-10-02 11:59 - 000000523 _____ () C:\Users\zola9\hide.bat
2026-02-22 02:26 - 2026-02-22 02:26 - 000000092 _____ () C:\Users\zola9\IP_Log_Data.js
2026-02-15 01:13 - 2026-02-22 02:24 - 000000624 _____ () C:\Users\zola9\AppData\Roaming\All CPU MeterV3_Settings.ini
2020-07-10 23:05 - 2020-07-10 23:05 - 000000012 _____ () C:\Users\zola9\AppData\Roaming\alsoft.ini
2021-07-17 01:48 - 2021-07-17 01:48 - 000000064 _____ () C:\Users\zola9\AppData\Roaming\changzhi_leidian.data
2021-07-17 01:48 - 2022-02-02 01:12 - 000000050 _____ () C:\Users\zola9\AppData\Roaming\changzhi_leidianmac.data
2026-02-22 02:26 - 2026-02-22 02:26 - 000000014 _____ () C:\Users\zola9\AppData\Roaming\Network Meter_Usage.ini
2022-12-17 22:04 - 2022-12-17 22:04 - 000001111 _____ () C:\Users\zola9\AppData\Local\gamma_ramp.reg
2024-06-28 22:11 - 2025-11-14 23:28 - 000007601 _____ () C:\Users\zola9\AppData\Local\Resmon.ResmonCfg
2020-04-15 04:27 - 2020-04-15 04:27 - 000040960 _____ () C:\Users\zola9\AppData\Local\Web Data
2020-04-15 04:27 - 2020-04-15 04:27 - 000000512 _____ () C:\Users\zola9\AppData\Local\Web Data-journal
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
[Link mogu videti samo ulogovani korisnici]
[Link mogu videti samo ulogovani korisnici]
|