molim za proveru

molim za proveru

offline
  • Pridružio: 15 Feb 2011
  • Poruke: 112

Napisano: 12 Okt 2022 18:26

U pitanju je drugarov laptop.
Upravo sam mu podigao windows 7 na starom laptop-u.
Zalio mi se da ne moze da otvori neke serije i filmove koje je skidao,kad pusti sa playerom(bs ili pot) slika bas secka.

Sad posle dizanja sistema,istalirao sam mu opet BS i Pot i opet isto.
Bidim ekstenzija filmova je .towz.
Kad sam to ukucao u google vidim da je to nesto povezano sa nekim malverom.
Uhvatila ga manija za neki spanskim serijama i filmovima i vidim da mu svi imaju tu .tow eksteziju.
Svi filmovi i seriju su na D particiji.

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11.10.2022
Ran by Port 792 (administrator) on PORT792-PC (Hewlett-Packard HP 250 G1 Notebook PC) (12-10-2022 19:17:56)
Running from C:\Users\Port 792\Desktop
Loaded Profiles: Port 792
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(C:\Program Files\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\Hewlett-Packard\HP Support Solutions\Modules\UpdaterTemp\HPSALight\Setup.exe
(C:\Program Files\Hewlett-Packard\HP Support Solutions\Modules\UpdaterTemp\HPSALight\Setup.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\Hewlett-Packard\HP Support Solutions\Modules\UpdaterTemp\HPSALight\InstallHPSA.exe
(C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE.EXE ->) (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe
(explorer.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <39>
(Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\igfxTray.exe
(services.exe ->) (Andrea Electronics -> Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(services.exe ->) (HP Inc. -> HP) C:\Program Files\HP\Shared\hpqwmiex.exe
(services.exe ->) (Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Dynamic Code Publisher -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\msiexec.exe
(services.exe ->) (Ralink Technology, Corp.) [File not signed] C:\Program Files\Ralink\Common\RaCountryRegion.exe
(services.exe ->) (Ralink Technology, Corp.) [File not signed] C:\Program Files\Ralink\Common\RaRegistry.exe
(services.exe ->) (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE.EXE
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(taskeng.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe
(taskeng.exe ->) (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe
(wininit.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\LogonUI.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2428656 2013-05-16] (Synaptics Incorporated -> Synaptics Incorporated)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\106.0.5249.119\Installer\chrmstp.exe [2022-10-12] (Google LLC -> Google LLC)

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {15547FB6-2FD6-4984-A052-271DDC681891} - System32\Tasks\GoogleUpdateTaskMachineCore{DFA6E436-53B4-4C6B-B427-A90E54292EBB} => C:\Program Files\Google\Update\GoogleUpdate.exe [171480 2022-10-12] (Google LLC -> Google LLC)
Task: {39D82B64-879F-4C6B-B379-E2233A424652} - System32\Tasks\GoogleUpdateTaskMachineUA{3B23487E-72C4-4D70-BCC5-AEC7D0470B3B} => C:\Program Files\Google\Update\GoogleUpdate.exe [171480 2022-10-12] (Google LLC -> Google LLC)
Task: {4A9648FC-6E5C-44B4-A7DB-93070C214E07} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [4206096 2022-09-12] (Piriform Software Ltd -> Piriform Software) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --configpath "C:\Program Files\CCleaner\Setup" --guid "2917a574-4caa-4a6d-b634-b61c65add77f" --version "6.04.10044" --silent
Task: {4ADE4CD4-1484-4650-854B-148309B2A2F8} - System32\Tasks\Hewlett-Packard\HPDeviceCheck => C:\Program Files\Hewlett-Packard\HP Support Solutions\Modules\HPDeviceCheck.exe [304248 2021-04-01] (HP Inc. -> )
Task: {6261ABEE-8B42-4AF3-85E4-5E45B5BAB755} - System32\Tasks\Hewlett-Packard\HP Web Products Detection => C:\Program Files\Hewlett-Packard\HP Support Solutions\Modules\HPWPD.exe [291160 2021-04-01] (HP Inc. -> HP Inc.)
Task: {6C5C0238-8181-470B-86BC-E4E2DD61AFDC} - System32\Tasks\wufuc.{72EEE38B-9997-42BD-85D3-2DD96DA17307} => "%WinDir%\System32\rundll32.exe" "%ProgramFiles%\wufuc\wufuc.dll",RUNDLL32_Start
Task: {868B8A38-8525-4CFE-BB5B-F65CCD14B4AE} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [324952 2020-08-20] (HP Inc. -> HP Inc.)
Task: {932CBCC7-75A4-4EC5-861E-250D5FEB628A} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2022-09-12] (Piriform Software Ltd -> Piriform)
Task: {985B25D3-73D5-4681-982B-FB92B375148F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater – Install HPSA => C:\Program Files\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [665944 2021-04-01] (HP Inc. -> HP Inc.)
Task: {B49CDDF5-DA29-4B9F-8FE2-C9764BEE0C35} - System32\Tasks\CCleanerSkipUAC - Port 792 => C:\Program Files\CCleaner\CCleaner.exe [32204304 2022-09-12] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {B5118A3B-7AD1-489B-9BBD-917982E0D082} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [134768 2021-04-01] (HP Inc. -> HP Inc.)
Task: {BF50B2B9-9749-4DCD-8E09-D10300F46F58} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe [6319176 2013-06-06] (Realtek Semiconductor Corp -> Realtek Semiconductor)
Task: {CC898BCD-D852-4967-B364-4A453A7C871B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [665944 2021-04-01] (HP Inc. -> HP Inc.)
Task: {DF3EEA78-EC18-4935-9D7B-1C1541343E66} - System32\Tasks\klcp_update => C:\Program Files\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2113024 2022-08-26] () [File not signed]

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Winsock: Catalog5 01 %SystemRoot%\system32\NLAapi.dll => No File ATTENTION: LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 02 %SystemRoot%\system32\napinsp.dll => No File ATTENTION: LibraryPath should be "%SystemRoot%\system32\napinsp.dll"
Winsock: Catalog5 03 %SystemRoot%\system32\pnrpnsp.dll => No File ATTENTION: LibraryPath should be "%SystemRoot%\system32\pnrpnsp.dll"
Winsock: Catalog5 04 %SystemRoot%\system32\pnrpnsp.dll => No File ATTENTION: LibraryPath should be "%SystemRoot%\system32\pnrpnsp.dll"
Winsock: Catalog5 05 %SystemRoot%\System32\mswsock.dll => No File ATTENTION: LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog5 06 %SystemRoot%\System32\winrnr.dll => No File ATTENTION: LibraryPath should be "%SystemRoot%\System32\winrnr.dll"
Tcpip\Parameters: [DhcpNameServer] 109.122.99.130 109.122.99.129
Tcpip\..\Interfaces\{7097B411-BBBC-4AA1-8486-6FA1E615D487}: [DhcpNameServer] 109.122.99.130 109.122.99.129

Chrome:
=======
CHR Profile: C:\Users\Port 792\AppData\Local\Google\Chrome\User Data\Default [2022-10-12]
CHR DownloadDir: C:\Users\Port 792\Desktop
CHR Extension: (Magic Actions for YouTube™) - C:\Users\Port 792\AppData\Local\Google\Chrome\User Data\Default\Extensions\abjcfabbhafbcdfjoecdgepllmpfceif [2022-10-12]
CHR Extension: (Safe Torrent Scanner) - C:\Users\Port 792\AppData\Local\Google\Chrome\User Data\Default\Extensions\aegnopegbbhjeeiganiajffnalhlkkjb [2022-10-12]
CHR Extension: (Google Docs Offline) - C:\Users\Port 792\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-10-12]
CHR Extension: (AdBlock — best ad blocker) - C:\Users\Port 792\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2022-10-12]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Port 792\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2022-10-12]
CHR HKLM\...\Chrome\Extension: [aegnopegbbhjeeiganiajffnalhlkkjb]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 cphs; C:\Windows\system32\IntelCpHeciSvc.exe [290224 2015-08-27] (Intel Corporation - pGFX -> Intel Corporation)
R3 hpqcaslwmiex; C:\Program Files\HP\Shared\hpqwmiex.exe [1149480 2018-06-07] (HP Inc. -> HP)
R2 HPSupportSolutionsFrameworkService; C:\Program Files\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [403576 2021-04-01] (HP Inc. -> HP Inc.)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [283568 2015-08-27] (Intel Corporation - pGFX -> Intel Corporation)
R2 RalinkCountryRegion; C:\Program Files\Ralink\Common\RaCountryRegion.exe [33280 2012-07-27] (Ralink Technology, Corp.) [File not signed]
R2 RalinkRegistryWriter; C:\Program Files\Ralink\Common\RaRegistry.exe [372736 2012-07-04] (Ralink Technology, Corp.) [File not signed]
S2 RaMediaServer; C:\Program Files\Ralink\Common\RaMediaServer.exe [1863680 2012-07-06] (Ralink) [File not signed]
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService.exe [166984 2013-06-06] (Realtek Semiconductor Corp -> Realtek Semiconductor)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Windows -> Microsoft Corporation)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 amdhub30; C:\Windows\system32\drivers\amdhub30.sys [95216 2018-12-19] (Advanced Micro Devices Inc. -> Advanced Micro Devices, INC.)
S3 amdhub31; C:\Windows\system32\drivers\amdhub31.sys [124256 2018-01-27] (ASMedia Technology Inc. -> Advanced Micro Devices, Inc.)
S3 amdxhc; C:\Windows\system32\drivers\amdxhc.sys [188400 2018-12-19] (Advanced Micro Devices Inc. -> Advanced Micro Devices, INC.)
S3 amdxhc31; C:\Windows\system32\drivers\amdxhc31.sys [374112 2018-01-27] (ASMedia Technology Inc. -> Advanced Micro Devices, Inc.)
S3 asmthub3; C:\Windows\system32\drivers\asmthub3.sys [124688 2019-08-21] (ASMedia Technology Inc. -> ASMedia Technology Inc)
S3 asmtxhci; C:\Windows\system32\drivers\asmtxhci.sys [377616 2019-08-21] (ASMedia Technology Inc. -> ASMedia Technology Inc)
S3 CYUSB; C:\Windows\System32\Drivers\CYUSB.sys [49176 2016-08-04] (Microsoft Windows Hardware Compatibility Publisher -> Cypress Semiconductor)
S3 CYUSB3; C:\Windows\System32\Drivers\CYUSB3.sys [62688 2017-07-05] (Cypress Semiconductor Technology India Pvt Ltd. -> Cypress Semiconductor)
S3 EtronHub3; C:\Windows\System32\Drivers\EtronHub3.sys [51456 2014-02-12] (Microsoft Windows Hardware Compatibility Publisher -> Etron Technology Inc)
S3 EtronSTOR; C:\Windows\System32\Drivers\EtronSTOR.sys [31360 2014-02-12] (Microsoft Windows Hardware Compatibility Publisher -> Etron Technology Inc)
S3 EtronXHCI; C:\Windows\System32\Drivers\EtronXHCI.sys [75392 2014-02-12] (Microsoft Windows Hardware Compatibility Publisher -> Etron Technology Inc)
S3 FLxHCIc; C:\Windows\system32\drivers\FLxHCIc.sys [379080 2019-03-26] (Fresco Logic, Inc -> Fresco Logic)
R0 iusb3hcs; C:\Windows\System32\drivers\iusb3hcs.sys [19968 2017-05-12] (Intel(R) USB eXtensible Host Controller Drivers -> Intel Corporation)
R3 MEI; C:\Windows\System32\DRIVERS\HECI.sys [55104 2012-07-17] (Intel Corporation -> Intel Corporation)
R3 netr28; C:\Windows\System32\DRIVERS\netr28.sys [2075792 2014-12-10] (MEDIATEK INC. -> MediaTek Inc.)
S3 nusb3hub; C:\Windows\system32\drivers\nusb3hub.sys [86408 2012-08-27] (Renesas Electronics Corporation -> Renesas Electronics Corporation)
S3 nusb3xhc; C:\Windows\system32\drivers\nusb3xhc.sys [178568 2012-08-27] (Renesas Electronics Corporation -> Renesas Electronics Corporation)
R0 oem-drv86; C:\Windows\System32\DRIVERS\oem-drv86.sys [28160 2022-10-11] (secr9tos) [File not signed]
S3 RSP2STOR; C:\Windows\System32\DRIVERS\RtsP2Stor.sys [205968 2013-02-01] (Realtek Semiconductor Corp -> Realtek Semiconductor Corp.)
S3 rusb3hub; C:\Windows\system32\drivers\rusb3hub.sys [91016 2012-08-27] (Renesas Electronics Corporation -> Renesas Electronics Corporation)
S3 rusb3xhc; C:\Windows\system32\drivers\rusb3xhc.sys [181128 2012-08-27] (Renesas Electronics Corporation -> Renesas Electronics Corporation)
S3 tihub3; C:\Windows\system32\drivers\tihub3.sys [118264 2016-05-12] (Texas Instruments, Inc. -> Texas Instruments Incorporated)
S3 tixhci; C:\Windows\system32\drivers\tixhci.sys [337400 2016-05-12] (Texas Instruments, Inc. -> Texas Instruments Incorporated)
S3 tusb3hub; C:\Windows\system32\drivers\tusb3hub.sys [410664 2017-12-19] (Intel(R) Client Connectivity Division SW -> Intel Corporation)
S3 tusb3xhc; C:\Windows\system32\drivers\tusb3xhc.sys [820736 2020-01-03] (上海域联软件技术有限公司 -> Intel Corporation)
S3 VUSB3HUB; C:\Windows\system32\drivers\ViaHub3.sys [198136 2017-07-18] (VIA Technologies, Inc -> VIA Technologies, Inc.)
S3 xhcdrv; C:\Windows\system32\drivers\xhcdrv.sys [255480 2017-07-18] (VIA Technologies, Inc -> VIA Technologies, Inc.)
S3 Zh3Hub; C:\Windows\system32\drivers\ZhHub3.sys [198168 2019-11-16] (上海兆芯集成电路有限公司 -> Shanghai Zhaoxin Semiconductor Co., Ltd.)
S3 zhxhc; C:\Windows\system32\drivers\zhxhc.sys [255512 2019-11-16] (上海兆芯集成电路有限公司 -> Shanghai Zhaoxin Semiconductor Co., Ltd.)
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2022-10-12 19:17 - 2022-10-12 19:18 - 000015592 _____ C:\Users\Port 792\Desktop\FRST.txt
2022-10-12 19:17 - 2022-10-12 19:18 - 000000000 ____D C:\FRST
2022-10-12 19:16 - 2022-10-12 19:17 - 002075648 _____ (Farbar) C:\Users\Port 792\Desktop\FRST.exe
2022-10-12 19:14 - 2022-10-12 19:14 - 000000000 ____D C:\Users\Port 792\AppData\Roaming\hpqLog
2022-10-12 19:14 - 2022-10-12 19:14 - 000000000 ____D C:\Program Files\HP
2022-10-12 19:13 - 2022-10-12 19:13 - 000000000 ____D C:\system.sav
2022-10-12 19:10 - 2022-10-12 19:10 - 000000836 _____ C:\Users\Port 792\Desktop\BitTorrent.lnk
2022-10-12 19:09 - 2022-10-12 19:10 - 000000000 ____D C:\Users\Port 792\AppData\Roaming\bittorrent
2022-10-12 19:09 - 2022-10-12 19:09 - 000000000 ____D C:\ProgramData\Package Cache
2022-10-12 19:08 - 2022-10-12 19:08 - 000003362 _____ C:\Windows\system32\Tasks\CCleanerCrashReporting
2022-10-12 19:08 - 2022-10-12 19:08 - 000000760 _____ C:\Windows\Tasks\CCleanerCrashReporting.job
2022-10-12 19:08 - 2022-10-12 19:08 - 000000000 ____D C:\Users\Port 792\AppData\Local\Adaware
2022-10-12 19:07 - 2022-10-12 19:08 - 000000000 ____D C:\Program Files\CCleaner
2022-10-12 19:07 - 2022-10-12 19:07 - 000003870 _____ C:\Windows\system32\Tasks\CCleaner Update
2022-10-12 19:07 - 2022-10-12 19:07 - 000002818 _____ C:\Windows\system32\Tasks\CCleanerSkipUAC - Port 792
2022-10-12 19:07 - 2022-10-12 19:07 - 000000965 _____ C:\Users\Public\Desktop\CCleaner.lnk
2022-10-12 19:04 - 2022-10-12 19:04 - 000003230 _____ C:\Windows\system32\Tasks\klcp_update
2022-10-12 19:04 - 2022-10-12 19:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2022-10-12 19:04 - 2022-10-12 19:04 - 000000000 ____D C:\Program Files\K-Lite Codec Pack
2022-10-12 18:55 - 2022-10-12 18:55 - 000000000 ____D C:\Users\Port 792\AppData\Roaming\Daum
2022-10-12 18:54 - 2022-10-12 18:55 - 000000000 ____D C:\Users\Port 792\AppData\Roaming\PotPlayerMini
2022-10-12 18:54 - 2022-10-12 18:54 - 000001116 _____ C:\Users\Public\Desktop\PotPlayer.lnk
2022-10-12 18:54 - 2022-10-12 18:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PotPlayer
2022-10-12 18:54 - 2022-10-12 18:54 - 000000000 ____D C:\Program Files\DAUM
2022-10-12 18:52 - 2022-10-12 18:52 - 000001086 _____ C:\ProgramData\Microsoft\Windows\Start Menu\BS.Player FREE.lnk
2022-10-12 18:52 - 2022-10-12 18:52 - 000001080 _____ C:\Users\Public\Desktop\BS.Player FREE.lnk
2022-10-12 18:52 - 2022-10-12 18:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BS.Player
2022-10-12 18:51 - 2022-10-12 18:59 - 000000000 ____D C:\Users\Port 792\AppData\Roaming\BSplayer
2022-10-12 18:51 - 2022-10-12 18:51 - 000000000 ____D C:\Users\Port 792\AppData\Roaming\BSplayer Pro
2022-10-12 18:51 - 2022-10-12 18:51 - 000000000 ____D C:\Program Files\Webteh
2022-10-12 18:43 - 2022-10-12 18:43 - 000000000 ____D C:\Windows\system32\Tasks\Hewlett-Packard
2022-10-12 18:43 - 2022-10-12 18:43 - 000000000 ____D C:\Users\Port 792\AppData\Local\HP
2022-10-12 18:43 - 2022-10-12 18:43 - 000000000 ____D C:\ProgramData\Hewlett-Packard
2022-10-12 18:42 - 2022-10-12 18:42 - 000059144 _____ C:\Users\Port 792\AppData\Local\GDIPFONTCACHEV1.DAT
2022-10-12 18:41 - 2022-10-12 19:14 - 000000000 ____D C:\Program Files\Hewlett-Packard
2022-10-12 18:19 - 2022-10-12 18:19 - 000002242 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2022-10-12 18:19 - 2022-10-12 18:19 - 000002201 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2022-10-12 18:19 - 2022-10-12 18:19 - 000000000 ____D C:\Users\Port 792\AppData\Local\Google
2022-10-12 18:17 - 2022-10-12 18:23 - 000000000 ____D C:\Program Files\Google
2022-10-12 18:17 - 2022-10-12 18:17 - 000003322 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA{3B23487E-72C4-4D70-BCC5-AEC7D0470B3B}
2022-10-12 18:17 - 2022-10-12 18:17 - 000003194 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore{DFA6E436-53B4-4C6B-B427-A90E54292EBB}
2022-10-12 18:06 - 2022-10-12 18:06 - 000000000 ____D C:\Users\Port 792\AppData\Roaming\Synaptics
2022-10-12 18:06 - 2022-10-12 18:06 - 000000000 ____D C:\ProgramData\Synaptics
2022-10-12 06:44 - 2022-10-12 06:44 - 000000000 ____D C:\Windows.old.000
2022-10-12 06:19 - 2022-10-12 06:19 - 000000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf
2022-10-12 06:19 - 2022-10-12 06:19 - 000000000 ____D C:\Program Files\Synaptics
2022-10-12 06:18 - 2022-10-12 06:18 - 000003130 _____ C:\Windows\system32\Tasks\RTKCPL
2022-10-12 06:18 - 2022-10-12 06:18 - 000000000 ____D C:\Windows\system32\SRSLabs
2022-10-12 06:18 - 2022-10-12 06:18 - 000000000 ____D C:\Windows\system32\RTCOM
2022-10-12 06:18 - 2022-10-12 06:18 - 000000000 ____D C:\Program Files\Realtek
2022-10-12 05:53 - 2022-10-12 05:53 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2022-10-12 05:53 - 2022-10-12 05:53 - 000000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_iusb3hcs_01009.Wdf
2022-10-12 03:41 - 2017-11-07 22:46 - 000341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2022-10-12 03:41 - 2017-10-12 02:40 - 000308456 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2022-10-12 03:41 - 2017-10-12 02:16 - 000034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2022-10-12 03:41 - 2017-08-11 08:10 - 000066048 _____ C:\Windows\system32\PrintBrmUi.exe
2022-10-12 03:41 - 2017-07-21 16:26 - 000518144 _____ C:\Windows\system32\msjetoledb40.dll
2022-10-12 03:41 - 2016-10-11 17:18 - 001027584 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10.IME
2022-10-12 03:41 - 2016-10-11 17:18 - 000430080 _____ (Microsoft Corporation) C:\Windows\system32\imkr80.ime
2022-10-12 03:41 - 2016-10-11 17:18 - 000126976 _____ (Microsoft Corporation) C:\Windows\system32\tintlgnt.ime
2022-10-12 03:41 - 2016-10-11 17:18 - 000125952 _____ (Microsoft Corporation) C:\Windows\system32\quick.ime
2022-10-12 03:41 - 2016-10-11 17:18 - 000125952 _____ (Microsoft Corporation) C:\Windows\system32\qintlgnt.ime
2022-10-12 03:41 - 2016-10-11 17:18 - 000125952 _____ (Microsoft Corporation) C:\Windows\system32\phon.ime
2022-10-12 03:41 - 2016-10-11 17:18 - 000125952 _____ (Microsoft Corporation) C:\Windows\system32\cintlgnt.ime
2022-10-12 03:41 - 2016-10-11 17:18 - 000125952 _____ (Microsoft Corporation) C:\Windows\system32\chajei.ime
2022-10-12 03:41 - 2016-10-11 17:18 - 000090112 _____ (Microsoft Corporation) C:\Windows\system32\pintlgnt.ime
2022-10-12 03:41 - 2016-10-11 15:18 - 000419648 _____ C:\Windows\system32\locale.nls
2022-10-12 03:30 - 2022-10-12 18:06 - 000000000 __SHD C:\Users\Port 792\IntelGraphicsProfiles
2022-10-12 03:29 - 2022-10-12 03:29 - 000000000 ____D C:\Users\Port 792\AppData\Roaming\Adobe
2022-10-11 22:34 - 2015-08-27 18:20 - 000070632 _____ (Khronos Group) C:\Windows\system32\OpenCL.DLL
2022-10-11 22:33 - 2022-10-11 22:33 - 000000000 ____D C:\Program Files\Common Files\Intel
2022-10-11 22:28 - 2012-06-02 16:57 - 000000003 _____ C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
2022-10-11 22:09 - 2022-10-11 22:09 - 000616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2022-10-11 22:01 - 2022-10-12 03:06 - 000000000 ____D C:\Windows\system32\MRT
2022-10-11 21:50 - 2012-12-07 12:46 - 000055296 _____ (Microsoft) C:\Windows\system32\cero.rs
2022-10-11 21:50 - 2012-12-07 12:46 - 000051712 _____ (Microsoft) C:\Windows\system32\esrb.rs
2022-10-11 21:50 - 2012-12-07 12:46 - 000046592 _____ (Microsoft) C:\Windows\system32\fpb.rs
2022-10-11 21:50 - 2012-12-07 12:46 - 000045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs
2022-10-11 21:50 - 2012-12-07 12:46 - 000044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs
2022-10-11 21:50 - 2012-12-07 12:46 - 000043520 _____ (Microsoft) C:\Windows\system32\csrr.rs
2022-10-11 21:50 - 2012-12-07 12:46 - 000040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs
2022-10-11 21:50 - 2012-12-07 12:46 - 000030720 _____ (Microsoft) C:\Windows\system32\usk.rs
2022-10-11 21:50 - 2012-12-07 12:46 - 000023552 _____ (Microsoft) C:\Windows\system32\oflc.rs
2022-10-11 21:50 - 2012-12-07 12:46 - 000021504 _____ (Microsoft) C:\Windows\system32\grb.rs
2022-10-11 21:50 - 2012-12-07 12:46 - 000020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs
2022-10-11 21:50 - 2012-12-07 12:46 - 000020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs
2022-10-11 21:50 - 2012-12-07 12:46 - 000020480 _____ (Microsoft) C:\Windows\system32\pegi.rs
2022-10-11 21:50 - 2012-12-07 12:46 - 000015360 _____ (Microsoft) C:\Windows\system32\djctq.rs
2022-10-11 21:48 - 2012-11-29 00:57 - 000000003 _____ C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2022-10-11 21:15 - 2022-10-11 21:15 - 000000000 ____D C:\Users\Port 792\AppData\Local\ElevatedDiagnostics
2022-10-11 21:12 - 2022-10-12 19:15 - 000000000 ___HD C:\Program Files\InstallShield Installation Information
2022-10-11 21:12 - 2022-10-11 21:12 - 000000000 ____D C:\Windows\system32\RaLanguages
2022-10-11 21:12 - 2022-10-11 21:12 - 000000000 ____D C:\ProgramData\Ralink Driver
2022-10-11 21:12 - 2022-10-11 21:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Communication and Chat
2022-10-11 21:12 - 2022-10-11 21:12 - 000000000 ____D C:\Program Files\Ralink
2022-10-11 21:12 - 2013-07-03 09:46 - 000008192 _____ C:\Windows\system32\Drivers\rt2860.bin
2022-10-11 21:12 - 2013-07-03 09:46 - 000004096 _____ C:\Windows\system32\Drivers\rt3290.bin
2022-10-11 21:12 - 2013-07-03 09:46 - 000004096 _____ C:\Windows\system32\Drivers\3290PCI4KB.bin
2022-10-11 21:12 - 2012-08-01 16:47 - 000795648 _____ (Ralink Technology, Corp.) C:\Windows\system32\RAIHV.dll
2022-10-11 21:12 - 2012-01-10 11:29 - 000117760 _____ (Ralink Technology, Corp.) C:\Windows\system32\RAEXTUI.dll
2022-10-11 21:12 - 2011-05-04 13:56 - 001608768 _____ (Ralink Technology, Corp.) C:\Windows\system32\RaCertMgr.dll
2022-10-11 21:12 - 2010-06-29 10:34 - 000480608 _____ C:\Windows\system32\DiagFunc.dll
2022-10-11 21:12 - 2010-01-27 11:54 - 000000451 _____ C:\Windows\system32\DiagFunc.ini
2022-10-11 21:09 - 2022-10-11 21:09 - 000000355 _____ C:\Users\Port 792\Desktop\Computer - Shortcut.lnk
2022-10-11 21:06 - 2022-10-11 22:34 - 000000000 ____D C:\Program Files\Intel
2022-10-11 21:06 - 2022-10-11 21:06 - 000000000 ____D C:\Intel
2022-10-11 21:06 - 2012-02-02 16:47 - 000053248 _____ (Windows XP Bundled build C-Centric Single User) C:\Windows\system32\CSVer.dll
2022-10-11 21:03 - 2022-10-12 03:30 - 000000000 ____D C:\Users\Port 792
2022-10-11 21:03 - 2022-10-11 21:03 - 000001413 _____ C:\Users\Port 792\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2022-10-11 21:03 - 2022-10-11 21:03 - 000000020 ___SH C:\Users\Port 792\ntuser.ini
2022-10-11 21:03 - 2022-10-11 21:03 - 000000000 ____D C:\Users\Port 792\AppData\Local\VirtualStore
2022-10-11 21:03 - 2022-10-11 20:15 - 000028160 _____ (secr9tos) C:\Windows\system32\Drivers\oem-drv86.sys
2022-10-11 21:03 - 2020-03-06 08:38 - 000000000 ____D C:\Users\Port 792\AppData\Roaming\Media Center Programs
2022-10-11 21:02 - 2022-10-11 21:02 - 000003744 _____ C:\Windows\system32\Tasks\wufuc.{72EEE38B-9997-42BD-85D3-2DD96DA17307}
2022-10-11 21:02 - 2022-10-11 21:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WUFUC
2022-10-11 21:02 - 2022-10-11 21:02 - 000000000 ____D C:\Program Files\wufuc
2022-10-11 18:27 - 2022-10-11 18:27 - 000000000 ____D C:\SDI_Drivers_mini
2022-10-11 18:27 - 2022-10-11 18:27 - 000000000 ____D C:\Activators
2022-10-11 18:17 - 2022-10-11 18:17 - 000000000 ____D C:\Windows.old
2022-10-10 23:20 - 2022-10-10 23:20 - 000000000 ___HD C:\$AV_ASW
2022-10-09 16:44 - 2022-10-09 16:44 - 000000000 ____D C:\SystemID

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2022-10-12 18:22 - 2009-07-14 06:34 - 000026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2022-10-12 18:22 - 2009-07-14 06:34 - 000026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2022-10-12 18:10 - 2020-03-05 14:36 - 000724158 _____ C:\Windows\system32\perfh019.dat
2022-10-12 18:10 - 2020-03-05 14:36 - 000150428 _____ C:\Windows\system32\perfc019.dat
2022-10-12 18:10 - 2010-11-20 23:01 - 001647438 _____ C:\Windows\system32\PerfStringBackup.INI
2022-10-12 18:10 - 2009-07-14 04:37 - 000000000 ____D C:\Windows\inf
2022-10-12 18:04 - 2009-07-14 06:53 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2022-10-12 18:04 - 2009-07-14 06:33 - 000267016 _____ C:\Windows\system32\FNTCACHE.DAT
2022-10-12 18:02 - 2009-07-14 06:52 - 000000000 ____D C:\Program Files\DVD Maker
2022-10-12 18:02 - 2009-07-14 04:37 - 000000000 ____D C:\Windows\tracing
2022-10-12 18:02 - 2009-07-14 04:37 - 000000000 ____D C:\Windows\system32\Setup
2022-10-12 18:02 - 2009-07-14 04:37 - 000000000 ____D C:\Windows\system32\migwiz
2022-10-12 18:02 - 2009-07-14 04:37 - 000000000 ____D C:\Windows\PolicyDefinitions
2022-10-12 18:02 - 2009-07-14 04:37 - 000000000 ____D C:\Program Files\Common Files\System
2022-10-12 06:50 - 2009-07-14 06:52 - 000028672 _____ C:\Windows\system32\config\BCD-Template
2022-10-12 06:50 - 2009-07-14 06:34 - 000000000 ____D C:\Windows\Setup
2022-10-12 04:17 - 2009-07-14 04:37 - 000000000 ____D C:\Windows\rescache
2022-10-12 03:30 - 2009-07-14 06:46 - 000001515 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2022-10-12 03:24 - 2009-07-14 06:52 - 000000000 ____D C:\Program Files\Windows Defender
2022-10-12 03:24 - 2009-07-14 04:37 - 000000000 ____D C:\Windows\system32\Dism
2022-10-12 03:24 - 2009-07-14 04:37 - 000000000 ____D C:\Windows\system32\AdvancedInstallers
2022-10-11 21:15 - 2009-07-14 04:37 - 000000000 ____D C:\Windows\system32\NDF
2022-10-11 21:11 - 2019-08-17 20:38 - 000000000 ____D C:\SWSetup
2022-10-11 21:03 - 2020-03-06 19:21 - 000000000 ____D C:\Windows\Panther
2022-10-09 17:08 - 2022-07-19 18:33 - 000000000 ____D C:\DF_Files

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)


LastRegBack: 2022-10-12 00:21
==================== End of FRST.txt ========================

Dopuna: 12 Okt 2022 18:28

mycity.rs/must-login.png

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

To je ekstenzija nekog ransomwera. Program zakljuca sve ili vecinu fajlova. Da li ima neki program koji uspesno dekriptuje ovu vrstu ransomwera, ne znam. Verovatno zakljucani fajlovi ne mogu vise da se koriste.

offline
  • Pridružio: 15 Feb 2011
  • Poruke: 112

helen1 ::To je ekstenzija nekog ransomwera. Program zakljuca sve ili vecinu fajlova. Da li ima neki program koji uspesno dekriptuje ovu vrstu ransomwera, ne znam. Verovatno zakljucani fajlovi ne mogu vise da se koriste.

Uzeo sam opet da ispeglam sistem,prilikom instalacije mi uopste nije dao da formatiram D particiju.
Cekam da se podigne sistem pa da probam kroz cmd.

Ko je trenutno na forumu
 

Ukupno su 961 korisnika na forumu :: 63 registrovanih, 11 sakrivenih i 887 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., Apok, babaroga, Batinas, cifra, comi_pfc, darkangel, deLacy, Denaya, Dimitrise93, Djokkinen, doklevise, DonRumataEstorski, Dorcolac, dule10savic, Gargantua, Georgius, goxin, havoc995, HogarStrashni, hooraay, ikan, Karla, kobaja77, kolle.the.kid, krkalon, Krusarac, Kubovac, kunktator, Lord Nem, LUDI, MB120mm, mercedesamg, mikrimaus, Misirac, nenad81, nikoladim, NoOneEver Dreams, ozzy, procesor, RecA, Ripanjac, S2M, Sančo, sasa87, ser.hill, shaja1, Shinobi, slonic_tonic, srbijaiznadsvega, Srle993, Vatreni Zmaj, Vlad000, Vlada1389, vladaa012, vlajkox, vobo, yrraf, ZetaMan, |_MeD_|, Žrnov, 125, 79693