Umesto brauzera Edge u Win 10 otvara se Find it

1

Umesto brauzera Edge u Win 10 otvara se Find it

offline
  • Pridružio: 15 Dec 2008
  • Poruke: 177
  • Gde živiš: Beograd

Kako piše u naslovu, u Win 10 koristio sam brauzer Edge do večeras. Postojao je Avast Free, ali sam ga jutros bio deinstalirao, a sada neće da primi novu instalaciju jer veli da su ostali delovi programa i da se najpre moraju oni očistiti da bi se postavio novi Avast. A ne vidim ga među programima da bi ih deinstalirao.

Otvaranje Edge se odjednom pretvorilo u otvaranje nekog programa FIND IT, a kažu mi da je virus-trojan ili u svakom slučaju, rekao bih, štetan. Pomagajte!

Kada Windows defender skenira on tvrdi da je našao pretnju, ali ne pokazuje kakvu i ne daje opcije da se ona očisti.
ADW Cleaner nađe neke "potencijalno neželjene programe" ali i kad se oni uklone FIND IT ostaje.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 08-01-2023
Ran by Radovan (administrator) on DESKTOP-QHE25B4 (Gigabyte Technology Co., Ltd. H81M-DS2) (08-01-2023 21:51:11)
Running from C:\Users\Radovan\OneDrive\Desktop
Loaded Profiles: Radovan
Platform: Microsoft Windows 10 IoT Enterprise LTSC Version 21H2 19044.2364 (X64) Language: English (United States)
Default browser: Edge
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(C:\Program Files (x86)\FormatFactory\net_updater64.exe ->) (Bright Data Ltd -> BrightData Ltd. (certified)) C:\ProgramData\BrightData\d71ae678248c6f808fef312e7563ca8a3655c744\brightdata.exe
(C:\Program Files\Google\Chrome\Application\chrome.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(C:\Program Files\McAfee\WebAdvisor\servicehost.exe ->) (McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\uihost.exe
(cmd.exe ->) (McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\browserhost.exe
(explorer.exe ->) () [File not signed] C:\Program Files\Atomic Alarm Clock\AtomicAlarmClock.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <39>
(explorer.exe ->) (Microsoft Corporation) [File not signed] [File is in use] C:\Program Files\Windows Sidebar\sidebar.exe
(explorer.exe ->) (VS Revo Group Ltd. -> VS Revo Group) C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RevoUninPro.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <9>
(services.exe ->) (Bright Data Ltd -> BrightData Ltd. (certified)) C:\Program Files (x86)\FormatFactory\net_updater64.exe
(services.exe ->) (McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\servicehost.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\NisSrv.exe
(svchost.exe ->) (Adobe Systems Incorporated) C:\Program Files\WindowsApps\ReaderNotificationClient_1.0.4.0_x86__e1rzdqpraam7r\AcrobatNotificationClient.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-19\...\RunOnce: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [2626440 2023-01-07] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [2626440 2023-01-07] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2226373433-464874539-114592448-1001\...\Run: [AtomicAlarmClock6] => C:\Program Files\Atomic Alarm Clock\AtomicAlarmClock.exe [5321728 2016-08-16] () [File not signed]
HKU\S-1-5-21-2226373433-464874539-114592448-1001\...\Run: [Viber] => C:\Users\Radovan\AppData\Local\Viber\Viber.exe [60743376 2022-12-13] (Viber Media S.à r.l. -> Viber Media S.à r.l.)
HKU\S-1-5-21-2226373433-464874539-114592448-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [2626440 2023-01-07] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2226373433-464874539-114592448-1001\...\Run: [Software Informer] => C:\Program Files\Software Informer\softinfo.exe [1689600 2022-07-30] (Informer Technologies, Inc.) [File not signed]
HKU\S-1-5-21-2226373433-464874539-114592448-1001\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [7223248 2022-11-14] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-2226373433-464874539-114592448-1001\...\Run: [MicrosoftEdgeAutoLaunch_257AA465338D314A2D2F3ADBEBB84D5B] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [3879368 2023-01-05] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2226373433-464874539-114592448-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\ssText3d.scr [224768 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\108.0.5359.125\Installer\chrmstp.exe [2022-12-16] (Google LLC -> Google LLC)
Startup: C:\Users\Radovan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sidebar519.lnk [2022-11-26]
ShortcutTarget: Sidebar519.lnk -> C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) [File not signed] [File is in use]
BootExecute: autocheck autochk * aswBoot.exe /M:16289edb /dir:"C:\Program Files\Avast Software\Avast"
GroupPolicy: Restriction - Chrome <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {01C0C9EF-D7BC-445D-A1BE-AD7A1E7BEA90} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26308584 2022-12-18] (Microsoft Corporation -> Microsoft Corporation)
Task: {056FE5D8-389B-4E75-958A-BB25F6C3F1A3} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe /from_scheduler:1 (No File)
Task: {10D0820D-DBDE-4584-88A6-62DEE956762D} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1552376 2022-09-26] (Adobe Inc. -> Adobe Inc.)
Task: {1D2C8226-4E5C-42E9-A439-D1A00A778015} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe /NoUACCheck
Task: {270485DB-1F32-435B-A2FC-75D4A2DBEABA} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MpCmdRun.exe [1592184 2022-12-11] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {2BA730EF-5865-4DF0-8E4B-39C055E7173C} - System32\Tasks\Online_KMS_Activation_Script-Renewal => %ProgramData%\Online_KMS_Activation\Activate.cmd Task
Task: {452981B1-4D48-4659-9FBB-7BC5A5B923C9} - System32\Tasks\CCleanerSkipUAC - Radovan => C:\Program Files\CCleaner\CCleaner.exe [32472400 2022-10-20] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {49692194-5D7D-41EE-B980-81664F4BE4AB} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2113024 2022-11-28] () [File not signed]
Task: {52178561-EB5B-44AE-8F3E-35200428BD8C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MpCmdRun.exe [1592184 2022-12-11] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {56DB71AE-1AC5-4EAA-8275-E761DAF5F74D} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144344 2022-12-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {571B61D1-B283-4BCF-8666-9DFF87A21D13} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26308584 2022-12-18] (Microsoft Corporation -> Microsoft Corporation)
Task: {5811F2AF-6BDC-4375-BFCE-592C325F2D5D} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8509392 2022-12-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {60815AA5-CFB8-4A61-AAE7-57D8C978E21A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MpCmdRun.exe [1592184 2022-12-11] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {626EFF37-19FD-45B1-9A1A-75F348ADAC03} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe do-task "308046B0AF4A39CB"
Task: {65888DCB-39DC-4869-9E55-5AF24499F66E} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [146816 2022-12-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {92062F27-2007-4316-A7A9-340BE06DB36E} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144344 2022-12-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {9DA43D03-793A-4328-AC1D-C0BEA972C41E} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2022-10-20] (Piriform Software Ltd -> Piriform)
Task: {A291E604-1C41-4795-9B75-3155415BFD78} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [4669264 2022-10-20] (PIRIFORM SOFTWARE LIMITED -> Piriform Software) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --configpath "C:\Program Files\CCleaner\Setup" --guid "ca5d4853-2b28-455f-ad31-9342d5211014" --version "6.05.10110" --silent
Task: {C8C85472-9D99-4B12-998B-7EAD4F4A9D18} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4189064 2023-01-07] (Microsoft Corporation -> Microsoft Corporation)
Task: {CE99322B-A625-447C-8C61-B97C9523CEC0} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate
Task: {D1A4DA0F-0479-466E-AC30-1CBA40AAB4B2} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2226373433-464874539-114592448-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4189064 2023-01-07] (Microsoft Corporation -> Microsoft Corporation)
Task: {EB135B37-EDAB-4975-BE59-CAAA0844ECE3} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8509392 2022-12-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {F5BF5DFE-090D-41C4-ABEB-60D6D8295DB4} - System32\Tasks\SoftwareInformerService => C:\Program Files\Software Informer\softinfo.exe [1689600 2022-07-30] (Informer Technologies, Inc.) [File not signed]
Task: {FC404022-1397-4F25-ADDB-A4E4E7D9F6D1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MpCmdRun.exe [1592184 2022-12-11] (Microsoft Windows Publisher -> Microsoft Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 89.216.1.30 89.216.1.40 89.216.1.50
Tcpip\..\Interfaces\{63c3661e-c4e1-47fd-bcb5-c30199942196}: [DhcpNameServer] 89.216.1.30 89.216.1.40 89.216.1.50

Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Radovan\AppData\Local\Microsoft\Edge\User Data\Default [2023-01-08]
Edge DownloadDir: Default -> D:\01 D DOWNLOAD
Edge Notifications: Default -> hxxps://best-loan-info.com; hxxps://ccleaner-download.xyz; hxxps://mail-notification.info; hxxps://mail.google.com; hxxps://mnthor.xyz; hxxps://pinghauz.xyz; hxxps://s-tracking.xyz; hxxps://supertopfreegames.com; hxxps://www.facebook.com; hxxps://zarabotok-online.xyz
Edge HomePage: Default -> about:tabs
Edge StartupUrls: Default -> "hxxps://find-it.pro/?utm_source=distr_m"
Edge DefaultSearchURL: Default -> hxxp://search-cdn.net/fip/?q={searchTerms}
Edge DefaultSearchKeyword: Default -> cdn
Edge DefaultSuggestURL: Default -> hxxps://www.google.ru/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&q={searchTerms}
Edge Extension: (Mailtrack - Email Tracker for Gmail) - C:\Users\Radovan\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\cemhcpmgfkheedjjbgflkldmkoiappji [2022-11-25]
Edge Extension: (Adblocker for Youtube™) - C:\Users\Radovan\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ggnchfknjkebijkdlbddehcpgfebapdc [2023-01-07] [UpdateUrl:hxxps://clients35.google.com/service/update2/crx] <==== ATTENTION
Edge Extension: (OneNote Web Clipper) - C:\Users\Radovan\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\oogbnpmeihfgnccdnmmlgicknopghhma [2022-11-16]

FireFox:
========
FF DefaultProfile: p9ju1wtj.default
FF ProfilePath: C:\Users\Radovan\AppData\Roaming\Mozilla\Firefox\Profiles\p9ju1wtj.default [2023-01-07]
FF SearchPlugin: C:\Users\Radovan\AppData\Roaming\Mozilla\Firefox\Profiles\p9ju1wtj.default\searchplugins\cdnsearch.xml [2023-01-07]
FF ProfilePath: C:\Users\Radovan\AppData\Roaming\Mozilla\Firefox\Profiles\g73xp1r0.default-release [2023-01-08]
FF Homepage: Mozilla\Firefox\Profiles\g73xp1r0.default-release -> hxxps://www.google.com/
FF Notifications: Mozilla\Firefox\Profiles\g73xp1r0.default-release -> hxxps://mail-notification.info; hxxps://zarabotok-online.xyz; hxxps://supertopfreegames.com; hxxps://best-loan-info.com; hxxps://ccleaner-download.xyz; hxxps://pinghauz.xyz; hxxps://s-tracking.xyz; hxxps://mnthor.xyz
FF SearchPlugin: C:\Users\Radovan\AppData\Roaming\Mozilla\Firefox\Profiles\g73xp1r0.default-release\searchplugins\cdnsearch.xml [2023-01-07]
FF Extension: (No Name) - C:\Program Files\Mozilla Firefox\browser\features\{A5735E22-7BD8-4CED-A24E-FBBD2D9CABB9}.xpi [2023-01-07] [not signed]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-12-30] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.17.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.18 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2022-11-14] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2022-12-30] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2022-12-30] (Microsoft Corporation -> Microsoft Corporation)

Chrome:
=======
CHR Profile: C:\Users\Radovan\AppData\Local\Google\Chrome\User Data\Default [2023-01-08]
CHR DownloadDir: D:\01 D DOWNLOAD
CHR Notifications: Default -> hxxps://best-loan-info.com; hxxps://ccleaner-download.xyz; hxxps://mail-notification.info; hxxps://mnthor.xyz; hxxps://pinghauz.xyz; hxxps://s-tracking.xyz; hxxps://supertopfreegames.com; hxxps://zarabotok-online.xyz
CHR HomePage: Default -> hxxps://www.google.com/
CHR StartupUrls: Default -> "hxxps://find-it.pro/?utm_source=distr_m"
CHR Extension: (Torrent Search) - C:\Users\Radovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\afbpdhiclgghnffhkinjikglgmolhpee [2023-01-08]
CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\Radovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2022-12-08]
CHR Extension: (Google News) - C:\Users\Radovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dllkocilcinkggkchnjgegijklcililc [2022-11-15]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\Radovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2022-12-28]
CHR Extension: (Google Docs Offline) - C:\Users\Radovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-12-08]
CHR Extension: (AdBlock — best ad blocker) - C:\Users\Radovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2022-12-27]
CHR Extension: (Adblocker for Youtube™) - C:\Users\Radovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\iddmabhekhhonkmomaklnflhhgbfnioe [2023-01-07] [UpdateUrl:hxxps://clients24.google.com/service/update2/crx] <==== ATTENTION
CHR Extension: (Google Mail Checker) - C:\Users\Radovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2022-11-15]
CHR Extension: (SmoothScroll) - C:\Users\Radovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbokbjkabcmbfdlbddjidfmibcpneigj [2022-11-15]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Radovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2022-11-15]
CHR Extension: (AIO Search) - C:\Users\Radovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\obhijjefkkokfaiffkcemldacdabpeei [2022-11-15]
CHR Extension: (Send from Gmail (by Google)) - C:\Users\Radovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgphcomnlaojlmmcjmiddhdapjpbgeoc [2022-11-15]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
CHR HKLM-x32\...\Chrome\Extension: [dhancbnhabhandieicagelcddkdfgoif] - C:\Program Files (x86)\Allavsoft\Video Downloader Converter\extensions\3.25.0.8302\BVDChromeExt.crx [2022-12-17]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [173040 2022-09-26] (Adobe Inc. -> Adobe Inc.)
S2 AtomicAlarmClock; C:\Program Files\Atomic Alarm Clock\timeserv.exe [2007040 2013-04-24] () [File not signed]
S3 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1185616 2022-10-20] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12540928 2022-12-18] (Microsoft Corporation -> Microsoft Corporation)
S2 Everything; C:\Program Files (x86)\Everything\Everything.exe [1778184 2022-10-10] (voidtools -> voidtools)
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\22.248.1127.0001\FileSyncHelper.exe [3478912 2023-01-07] (Microsoft Corporation -> Microsoft Corporation)
R2 luminati_net_updater_win_formatfactory_pcfreetime_com; C:\Program Files (x86)\FormatFactory\net_updater64.exe [9872976 2023-01-03] (Bright Data Ltd -> BrightData Ltd. (certified))
R2 McAfee WebAdvisor; C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe [849744 2022-12-09] (McAfee, LLC -> McAfee, LLC)
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\22.248.1127.0001\OneDriveUpdaterService.exe [3845000 2023-01-07] (Microsoft Corporation -> Microsoft Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [224184 2022-12-14] (Microsoft Windows Publisher -> Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\NisSrv.exe [3191264 2022-12-11] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MsMpEng.exe [133592 2022-12-11] (Microsoft Windows Publisher -> Microsoft Corporation)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R0 aswArDisk; C:\WINDOWS\System32\drivers\aswArDisk.sys [31424 2023-01-07] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [229208 2023-01-07] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [391272 2023-01-07] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [297832 2023-01-07] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [95960 2023-01-07] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [25576 2023-01-07] (Microsoft Windows Early Launch Anti-malware Publisher -> AVAST Software)
R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [39648 2023-01-07] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [267888 2023-01-07] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswNetHub; C:\WINDOWS\System32\drivers\aswNetHub.sys [555560 2023-01-07] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [105248 2023-01-07] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [80376 2023-01-07] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [852000 2023-01-07] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [695496 2023-01-07] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [212632 2023-01-07] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [318456 2023-01-07] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
R3 MpKsld312544d; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{197F1380-2033-4248-AA4C-8F95F2DA77A6}\MpKslDrv.sys [214280 2023-01-08] (Microsoft Windows -> Microsoft Corporation)
S3 Revoflt; C:\WINDOWS\System32\DRIVERS\revoflt.sys [38400 2020-10-14] (Microsoft Windows Hardware Compatibility Publisher -> VS Revo Group)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49568 2022-12-11] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [473376 2022-12-11] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [99616 2022-12-11] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2023-01-08 21:50 - 2023-01-08 21:51 - 000000000 ____D C:\FRST
2023-01-07 15:56 - 2023-01-08 18:56 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software
2023-01-07 15:55 - 2023-01-07 15:55 - 000273816 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2023-01-07 15:55 - 2023-01-07 15:55 - 000000000 ____D C:\Program Files\Avast Software
2023-01-07 14:56 - 2023-01-07 14:56 - 006008628 _____ C:\Users\Radovan\OneDrive\Documents\KMSAuto-Net-Portable_EBlJNpwe.exe
2023-01-07 12:53 - 2023-01-07 12:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2023-01-07 12:53 - 2023-01-07 12:53 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2023-01-07 12:53 - 2023-01-07 12:53 - 000000000 ____D C:\Program Files\WinRAR
2023-01-07 12:51 - 2023-01-07 15:57 - 000000004 _____ C:\ProgramData\rc.dat
2023-01-07 12:50 - 2023-01-07 15:57 - 000000004 _____ C:\ProgramData\lock.dat
2023-01-07 12:50 - 2023-01-07 13:14 - 000000016 _____ C:\ProgramData\lir.bats
2023-01-07 12:50 - 2023-01-07 12:50 - 000000008 _____ C:\ProgramData\ts.dat
2023-01-07 12:46 - 2023-01-07 16:00 - 000000000 ____D C:\Program Files (x86)\xzQPDMqrQnZyvJJzPrR
2023-01-07 12:46 - 2023-01-07 16:00 - 000000000 ____D C:\Program Files (x86)\UeOGQDGbBgTU2
2023-01-07 12:46 - 2023-01-07 16:00 - 000000000 ____D C:\Program Files (x86)\KfBVaxxIqNosC
2023-01-07 12:46 - 2023-01-07 16:00 - 000000000 ____D C:\Program Files (x86)\cnWDCNXmU
2023-01-07 12:46 - 2023-01-07 15:59 - 000000000 ____D C:\ProgramData\mvBWwLwMpQYvllVB
2023-01-07 12:46 - 2023-01-07 12:46 - 000000000 ____D C:\Program Files (x86)\qZmJDUQbSwUn
2023-01-07 12:45 - 2023-01-07 15:59 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\Win32Sync
2023-01-07 12:45 - 2023-01-07 15:57 - 000000000 ____D C:\ProgramData\PrintManager
2023-01-07 12:45 - 2023-01-07 12:58 - 032726866 _____ C:\Users\Radovan\OneDrive\Documents\kmsauto-net-portable-zip
2023-01-07 12:45 - 2023-01-07 12:46 - 000004740 __RSH C:\ProgramData\ntuser.pol
2023-01-07 12:45 - 2023-01-07 12:45 - 006867456 _____ C:\Users\Radovan\AppData\Roaming\Z4Ros270.exe
2023-01-07 12:45 - 2023-01-07 12:45 - 000684984 _____ (Mozilla Foundation) C:\Users\Radovan\AppData\LocalLow\freebl3.dll
2023-01-07 12:45 - 2023-01-07 12:45 - 000627128 _____ (Mozilla Foundation) C:\Users\Radovan\AppData\LocalLow\mozglue.dll
2023-01-07 12:45 - 2023-01-07 12:45 - 000254392 _____ (Mozilla Foundation) C:\Users\Radovan\AppData\LocalLow\softokn3.dll
2023-01-07 12:45 - 2023-01-07 12:45 - 000000014 _____ C:\ProgramData\wefwegge.txt
2023-01-07 12:45 - 2023-01-07 12:45 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\ZCqer9KRKR6
2023-01-07 12:45 - 2023-01-07 12:45 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\hRxnsq3mr
2023-01-07 12:45 - 2023-01-07 12:45 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\dwtjgei1
2023-01-07 12:45 - 2023-01-07 12:45 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\8ZeDrl
2023-01-07 12:45 - 2023-01-07 12:45 - 000000000 ____D C:\Users\Radovan\AppData\Local\Yandex
2023-01-07 12:45 - 2023-01-07 12:45 - 000000000 ____D C:\Program Files (x86)\Nitter
2023-01-07 12:33 - 2023-01-07 12:35 - 000000000 ____D C:\Program Files\Office 2019 KMS Activator Ultimate 1.7
2023-01-07 12:18 - 2023-01-07 13:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KMSpico
2023-01-07 12:18 - 2023-01-07 13:17 - 000000000 ____D C:\Program Files\KMSpico
2023-01-07 12:18 - 2023-01-07 12:18 - 000004608 _____ C:\WINDOWS\SECOH-QAD.exe
2023-01-07 12:18 - 2010-12-06 03:16 - 000090112 _____ (Vestris Inc.) C:\WINDOWS\system32\Vestris.ResourceLib.dll
2023-01-01 19:33 - 2023-01-01 19:53 - 000000000 ____D C:\Users\Radovan\.Icecream Ebook Reader
2023-01-01 19:33 - 2023-01-01 19:33 - 000001224 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Icecream Ebook Reader 6.lnk
2023-01-01 19:33 - 2023-01-01 19:33 - 000000000 ____D C:\Users\Radovan\AppData\Local\Icecream
2023-01-01 19:33 - 2023-01-01 19:33 - 000000000 ____D C:\Users\Radovan\AppData\Local\CrashRpt
2023-01-01 19:33 - 2023-01-01 19:33 - 000000000 ____D C:\Program Files (x86)\Icecream Ebook Reader 6
2022-12-29 21:24 - 2022-12-29 21:24 - 000002079 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2022-12-29 21:24 - 2022-12-29 21:24 - 000000000 ____D C:\Program Files\Common Files\Adobe
2022-12-29 21:24 - 2022-12-29 21:24 - 000000000 ____D C:\Program Files\Adobe
2022-12-29 18:28 - 2022-12-29 18:28 - 000000000 ____D C:\Program Files (x86)\Korektor
2022-12-28 23:15 - 2022-12-28 23:15 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2022-12-28 21:42 - 2022-12-28 21:42 - 000000000 ____D C:\ProgramData\VS Revo Group
2022-12-28 21:32 - 2022-12-28 21:47 - 000000000 ____D C:\WINDOWS\system32\Tasks\MEGA
2022-12-28 18:44 - 2022-12-28 18:44 - 000002498 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive for Business.lnk
2022-12-28 18:44 - 2022-12-28 18:44 - 000002467 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Project.lnk
2022-12-28 18:44 - 2022-12-28 18:44 - 000002449 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visio.lnk
2022-12-28 18:44 - 2022-12-28 18:44 - 000002399 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote.lnk
2022-12-28 18:27 - 2022-12-29 21:25 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\com.adobe.dunamis
2022-12-28 18:27 - 2022-12-28 18:27 - 000000000 ____D C:\Users\Radovan\AppData\Local\SolidDocuments
2022-12-28 18:27 - 2022-12-28 18:27 - 000000000 ____D C:\Users\Radovan\.ms-ad
2022-12-28 17:53 - 2022-12-28 17:54 - 000000000 ____D C:\ProgramData\WinZip
2022-12-28 17:53 - 2022-12-28 17:53 - 000002163 _____ C:\ProgramData\Microsoft\Windows\Start Menu\WinZip.lnk
2022-12-28 17:53 - 2022-12-28 17:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
2022-12-28 17:53 - 2022-12-28 17:53 - 000000000 ____D C:\Program Files (x86)\WinZip
2022-12-27 02:57 - 2022-12-27 02:57 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\Macromedia
2022-12-23 19:55 - 2022-12-23 19:55 - 000000000 ____D C:\Users\Radovan\AppData\Local\ElevatedDiagnostics
2022-12-19 01:30 - 2022-12-30 21:20 - 000000000 ____D C:\Users\Radovan\OneDrive\Documents\FormatFactory
2022-12-17 15:08 - 2022-12-17 15:12 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\Allavsoft
2022-12-17 15:08 - 2022-12-17 15:08 - 000000000 ____D C:\Users\Radovan\OneDrive\Documents\Allavsoft
2022-12-17 15:08 - 2022-12-17 15:08 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Allavsoft
2022-12-17 15:08 - 2022-12-17 15:08 - 000000000 ____D C:\Program Files (x86)\Allavsoft
2022-12-15 18:03 - 2022-12-15 18:03 - 000000000 ____D C:\ProgramData\Informer Technologies, Inc
2022-12-15 18:02 - 2023-01-08 21:15 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\Software Informer
2022-12-15 18:02 - 2023-01-08 18:56 - 000002556 _____ C:\WINDOWS\system32\Tasks\SoftwareInformerService
2022-12-15 18:02 - 2022-12-15 18:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Software Informer
2022-12-15 18:02 - 2022-12-15 18:02 - 000000000 ____D C:\Program Files\Software Informer
2022-12-14 13:28 - 2022-12-14 13:28 - 000000000 ____D C:\ProgramData\Piriform
2022-12-14 11:34 - 2022-12-14 11:34 - 000000000 ___HD C:\$WinREAgent
2022-12-12 17:20 - 2022-12-18 20:01 - 000000000 ____D C:\ProgramData\Online_KMS_Activation
2022-12-10 20:51 - 2022-12-10 20:52 - 000000000 ____D C:\AdwCleaner
2022-12-10 12:54 - 2022-12-10 12:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Magoshare Data Recovery 2.1
2022-12-10 12:54 - 2022-12-10 12:54 - 000000000 ____D C:\Program Files (x86)\Magoshare
2022-12-09 22:33 - 2022-12-09 22:33 - 000000016 _____ C:\ProgramData\mntemp
2022-12-09 22:33 - 2022-12-09 22:33 - 000000000 ____D C:\Program Files\Wondershare
2022-12-09 16:21 - 2022-12-09 16:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Office Tab
2022-12-09 16:21 - 2022-12-09 16:21 - 000000000 ____D C:\Program Files (x86)\ExtendOffice
2022-12-09 16:03 - 2022-12-09 16:03 - 000000000 ___HD C:\$AV_ASW
2022-12-09 15:57 - 2022-12-09 15:57 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\NCH Software
2022-12-09 15:57 - 2022-12-09 15:57 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\D4E0ADC434598A5D
2022-12-09 11:49 - 2022-12-09 18:12 - 000000000 ____D C:\WINDOWS\Panther

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2023-01-08 21:05 - 2022-11-14 20:21 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\qBittorrent
2023-01-08 21:02 - 2022-11-14 17:59 - 000002516 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2023-01-08 21:00 - 2022-11-15 01:59 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\Everything
2023-01-08 20:52 - 2022-11-15 17:38 - 000000000 ____D C:\Program Files\Mozilla Firefox
2023-01-08 20:52 - 2022-11-14 19:31 - 000000000 ____D C:\Users\Radovan\AppData\LocalLow\Mozilla
2023-01-08 20:52 - 2022-11-14 19:31 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2023-01-08 20:50 - 2022-11-26 17:58 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2023-01-08 19:39 - 2022-11-26 18:01 - 000003416 _____ C:\WINDOWS\system32\Tasks\CCleanerCrashReporting
2023-01-08 19:39 - 2022-11-14 19:39 - 000000760 _____ C:\WINDOWS\Tasks\CCleanerCrashReporting.job
2023-01-08 19:39 - 2022-11-14 19:39 - 000000000 ____D C:\Program Files\CCleaner
2023-01-08 19:17 - 2022-11-26 18:04 - 000795738 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2023-01-08 19:17 - 2019-12-07 10:13 - 000000000 ____D C:\WINDOWS\INF
2023-01-08 19:12 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2023-01-08 19:11 - 2022-11-14 18:58 - 000000000 ___RD C:\Users\Radovan\OneDrive
2023-01-08 19:10 - 2022-11-26 18:01 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2023-01-08 19:10 - 2022-11-14 18:14 - 000000000 __SHD C:\Users\Radovan\IntelGraphicsProfiles
2023-01-08 19:10 - 2022-11-14 18:11 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2023-01-08 19:10 - 2022-11-14 17:59 - 000008192 ___SH C:\DumpStack.log.tmp
2023-01-08 19:10 - 2019-12-07 10:03 - 000065536 _____ C:\WINDOWS\system32\config\BBI
2023-01-08 19:09 - 2022-11-23 17:20 - 000000000 ____D C:\ProgramData\Avast Software
2023-01-08 18:56 - 2022-11-26 18:01 - 000004056 _____ C:\WINDOWS\system32\Tasks\Online_KMS_Activation_Script-Renewal
2023-01-08 18:56 - 2022-11-26 18:01 - 000003488 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2023-01-08 18:56 - 2022-11-26 18:01 - 000003482 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2023-01-08 18:56 - 2022-11-26 18:01 - 000003264 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2023-01-08 18:56 - 2022-11-26 18:01 - 000003194 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2023-01-08 18:56 - 2022-11-26 18:01 - 000003062 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2226373433-464874539-114592448-1001
2023-01-08 18:56 - 2022-11-26 18:01 - 000003024 _____ C:\WINDOWS\system32\Tasks\klcp_update
2023-01-08 18:56 - 2022-11-26 18:01 - 000002716 _____ C:\WINDOWS\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2023-01-08 18:56 - 2022-11-26 18:01 - 000002586 _____ C:\WINDOWS\system32\Tasks\CreateExplorerShellUnelevatedTask
2023-01-08 18:56 - 2022-11-26 18:01 - 000002254 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC - Radovan
2023-01-08 11:04 - 2022-12-08 19:49 - 000000000 ____D C:\Users\Radovan\OneDrive\Documents\ViberDownloads
2023-01-07 21:36 - 2022-11-14 19:38 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\vlc
2023-01-07 20:16 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2023-01-07 20:16 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2023-01-07 15:58 - 2022-11-24 18:22 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2023-01-07 15:55 - 2019-12-07 10:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2023-01-07 13:12 - 2022-11-24 18:22 - 000002138 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2023-01-07 13:10 - 2022-11-15 02:17 - 000000000 ____D C:\Users\Radovan\AppData\Local\Everything
2023-01-07 12:58 - 2022-11-23 18:14 - 000000000 ____D C:\Users\Radovan\AppData\Local\CrashDumps
2023-01-07 12:46 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\GroupPolicy
2023-01-07 11:49 - 2022-11-15 17:44 - 000000000 ____D C:\Program Files (x86)\Google
2023-01-05 19:27 - 2022-11-14 19:49 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\ImageGlass
2023-01-05 19:26 - 2022-11-29 21:16 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\MPC-HC
2023-01-03 09:53 - 2022-11-22 16:24 - 000000000 ____D C:\Program Files (x86)\FormatFactory
2023-01-01 19:33 - 2022-11-26 17:51 - 000000000 ____D C:\Users\Radovan
2022-12-30 18:47 - 2022-11-14 21:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Atomic Alarm Clock
2022-12-30 18:47 - 2022-11-14 21:12 - 000000000 ____D C:\Program Files\Atomic Alarm Clock
2022-12-30 04:34 - 2022-11-14 18:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
2022-12-30 04:34 - 2022-11-14 18:56 - 000000000 ____D C:\Program Files\Microsoft Office
2022-12-29 21:25 - 2022-11-14 20:09 - 000000000 ____D C:\Users\Radovan\AppData\Local\Adobe
2022-12-29 21:25 - 2022-11-14 18:15 - 000000000 ____D C:\ProgramData\Packages
2022-12-29 21:25 - 2022-11-14 18:14 - 000000000 ____D C:\Users\Radovan\AppData\Local\Packages
2022-12-29 21:23 - 2022-11-14 20:08 - 000000000 ____D C:\ProgramData\Adobe
2022-12-29 21:20 - 2022-11-26 17:58 - 000467712 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2022-12-29 21:19 - 2022-11-14 19:31 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2022-12-29 21:18 - 2022-11-14 20:12 - 000000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2022-12-29 21:15 - 2022-11-26 18:01 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2022-12-29 21:15 - 2022-11-14 19:31 - 000001011 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2022-12-29 18:28 - 2022-11-14 20:24 - 000000000 ____D C:\ProgramData\Package Cache
2022-12-28 23:14 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2022-12-28 22:26 - 2022-11-22 16:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2022-12-28 22:07 - 2022-11-22 20:38 - 000000000 ____D C:\Program Files (x86)\7-Zip
2022-12-28 22:07 - 2022-11-14 19:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2022-12-28 18:27 - 2022-11-14 20:09 - 000000000 ____D C:\Users\Radovan\AppData\LocalLow\Adobe
2022-12-28 18:27 - 2022-11-14 18:14 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\Adobe
2022-12-26 11:14 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\NDF
2022-12-19 21:23 - 2022-11-22 16:29 - 000007596 _____ C:\Users\Radovan\AppData\Local\resmon.resmoncfg
2022-12-18 19:57 - 2022-11-17 17:49 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\ViberPC
2022-12-18 19:57 - 2022-11-17 17:49 - 000000000 ____D C:\Users\Radovan\AppData\Local\Viber
2022-12-16 01:22 - 2022-11-15 17:45 - 000002253 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2022-12-16 01:22 - 2022-11-15 17:45 - 000002212 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2022-12-14 12:28 - 2019-12-07 10:51 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\UNP
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SystemResources
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SystemApps
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\et-EE
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\es-MX
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\Provisioning
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\System
2022-12-14 11:42 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\servicing
2022-12-14 11:42 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2022-12-14 11:40 - 2022-11-26 17:59 - 003014656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2022-12-14 11:33 - 2022-11-14 19:07 - 000000000 ____D C:\WINDOWS\system32\MRT
2022-12-14 11:30 - 2022-11-14 19:07 - 148633544 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2022-12-11 20:33 - 2022-11-14 17:59 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2022-12-09 22:34 - 2022-11-22 21:06 - 000000000 ____D C:\ProgramData\Wondershare
2022-12-09 22:33 - 2022-11-23 18:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare
2022-12-09 22:33 - 2022-11-22 21:07 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\Wondershare
2022-12-09 12:28 - 2022-11-15 16:09 - 000000000 ____D C:\Users\Radovan\AppData\Local\D3DSCache

==================== Files in the root of some directories ========

2023-01-07 12:50 - 2023-01-07 15:57 - 000000004 _____ () C:\ProgramData\lock.dat
2023-01-07 12:51 - 2023-01-07 15:57 - 000000004 _____ () C:\ProgramData\rc.dat
2023-01-07 12:50 - 2023-01-07 12:50 - 000000008 _____ () C:\ProgramData\ts.dat
2023-01-07 12:45 - 2023-01-07 12:45 - 006867456 _____ () C:\Users\Radovan\AppData\Roaming\Z4Ros270.exe
2022-11-14 20:08 - 2022-12-29 21:18 - 000000615 _____ () C:\Users\Radovan\AppData\Local\oobelibMkey.log
2022-11-22 16:29 - 2022-12-19 21:23 - 000007596 _____ () C:\Users\Radovan\AppData\Local\resmon.resmoncfg

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================
mycity.rs/must-login.png

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Verovatno si pokupio neku napast pokusavajuci da instaliras aktivator za office.

Skini MBAM, skeniraj, pa mi postavi logove kad zavrsi:
https://www.malwarebytes.com/mwb-download/thankyou

offline
  • Pridružio: 15 Dec 2008
  • Poruke: 177
  • Gde živiš: Beograd

Napisano: 20 Jan 2023 0:11

Kasnim u komunikaciji, nije me bilo, putovao sam. Izvini.

Dopuna: 20 Jan 2023 0:12

mycity.rs/must-login.png

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Kao sto sam rekao. Malware je dosao sa aktivatorom. Preporucio bih ti da skeniras sa MBAMom opet i da ovog puta uklonis sve pretnje koje nadje.

offline
  • Pridružio: 15 Dec 2008
  • Poruke: 177
  • Gde živiš: Beograd

Napisano: 20 Jan 2023 13:19

Urađeno, čisto je zasad, Office radi. Hvala veliko makstore.

Dopuna: 20 Jan 2023 13:20

ustvari majstore!

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Ipak mi postavi novi FRST log da vidim da li ima jos nesto.

offline
  • Pridružio: 15 Dec 2008
  • Poruke: 177
  • Gde živiš: Beograd

Napisano: 22 Jan 2023 12:39

mycity.rs/must-login.png

Dopuna: 22 Jan 2023 12:41

Nešto nije u redu, sad ću ponovo.

Dopuna: 22 Jan 2023 12:42

mycity.rs/must-login.png

Dopuna: 22 Jan 2023 12:47

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Treba da mi postavis FRST log, kao u prvoj poruci.

offline
  • Pridružio: 15 Dec 2008
  • Poruke: 177
  • Gde živiš: Beograd

mycity.rs/must-login.png

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Treba mi log iz ove teme: https://www.mycity.rs/Ambulanta/Kako-otvoriti-temu-u-Ambulanti.html

Ko je trenutno na forumu
 

Ukupno su 1284 korisnika na forumu :: 39 registrovanih, 8 sakrivenih i 1237 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., amaterSRB, bagor10, bigfoot, CikaKURE, debeli, Dimitrise93, Dorcolac, draganl, Georgius, hooraay, ikan, ILGromovnik, kikisp, kuntalo, Leonov, lord sir giga, Marko Marković, Mcdado, mercedesamg, Mi lao shu, milenko crazy north, milimoj, Milometer, milos.cbr, Mixelotti, pein, repac, S2M, Skywhaler, Sumadija34, suton, t84dar, Toper, Trpe Grozni, vasa.93, voja64, zlaya011, Zoca