Gasenje racunara

1

Gasenje racunara

offline
  • Pridružio: 29 Mar 2014
  • Poruke: 6
  • Gde živiš: Beograd

Pozdrav,

Problem sa mojim racunarom je taj sto se on samo odjednom ugasi, najcesce se to desava kad je otvorena neka full screen igrica. Desavalo mi se to i ranije al poslednjih par dana cesce. Mozda je to i hardverski problem ali sam resila da se i vama obratim za savet. Ako su potrebne jos neke informacije napisacu.

Hvala unapred
Marija

DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 11.0.9600.16521 BrowserJavaVersion: 10.51.2
Run by Marija at 9:30:01 on 2014-03-29
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.2047.1152 [GMT 1:00]
.
AV: avast! Antivirus *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: avast! Antivirus *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Skype\Phone\Skype.exe
C:\Users\Marija\AppData\Local\Skillbrains\lightshot\5.1.0.15\Lightshot.exe
C:\Program Files\DefaultTab\DefaultTabSearch.exe
C:\Users\Marija\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Opera\20.0.1387.82\opera.exe
C:\Program Files\Opera\20.0.1387.82\opera_crashreporter.exe
C:\Program Files\Opera\20.0.1387.82\opera.exe
C:\Program Files\Opera\20.0.1387.82\opera.exe
C:\Program Files\Opera\20.0.1387.82\opera.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Opera\20.0.1387.82\opera.exe
C:\Windows\system32\AUDIODG.EXE
C:\Program Files\Opera\20.0.1387.82\opera.exe
C:\Program Files\Opera\20.0.1387.82\opera.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\System32\svchost.exe -k secsvcs
.
============== Pseudo HJT Report ===============
.
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: DefaultTab Browser Helper: {7F6AFBF1-E065-4627-A2FD-810366367D01} - c:\users\marija\appdata\roaming\defaulttab\defaulttab\DefaultTabBHO.dll
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
TB: avast! Online Security: {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - c:\program files\avast software\avast\aswWebRepIE.dll
uRun: [LightShot] c:\users\marija\appdata\local\skillbrains\lightshot\Lightshot.exe Flags: uninsdeletevalue
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /minimized /regrun
mRun: [AvastUI.exe] "c:\program files\avast software\avast\AvastUI.exe" /nogui
mRun: [HDAudDeck] c:\program files\via\viaudioi\vdeck\VDeck.exe -r
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [mobilegeni daemon] c:\program files\mobogenie\DaemonProcess.exe
mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{442FAB12-DD94-422D-9531-A7AF0C60E207} : DHCPNameServer = 192.168.1.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\33.0.1750.154\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;avast! Revert;c:\windows\system32\drivers\aswRvrt.sys [2013-12-22 49944]
R0 aswVmm;avast! VM Monitor;c:\windows\system32\drivers\aswVmm.sys [2013-12-22 180248]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2013-12-22 775952]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2013-12-22 410784]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-12-22 67824]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2014-1-25 50344]
R2 DefaultTabSearch;DefaultTabSearch;c:\program files\defaulttab\DefaultTabSearch.exe [2013-12-20 574464]
R2 DefaultTabUpdate;DefaultTabUpdate;c:\users\marija\appdata\roaming\defaulttab\defaulttab\DTUpdate.exe [2014-1-23 107520]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2013-10-23 414496]
R3 aswStm;aswStm;c:\windows\system32\drivers\aswstm.sys [2013-12-22 64168]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2013-12-22 1086976]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2013-10-23 172192]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 62464]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\ieetwcollector.exe [2014-3-12 108032]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
S3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\Synth3dVsc.sys [2010-11-21 77184]
S3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2010-11-21 25600]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2010-11-20 52224]
S3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-21 112640]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2013-12-23 1343400]
.
=============== File Associations ===============
.
ShellExec: Opera.exe: open="c:\program files\opera\Launcher.exe" "%1"
.
=============== Created Last 30 ================
.
2014-03-28 10:42:26 -------- d-----w- c:\program files\Microsoft WSE
2014-03-28 10:42:13 2414360 ----a-w- c:\windows\system32\d3dx9_31.dll
2014-03-28 08:17:31 7969936 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{a12ec411-23eb-4d71-bc94-eb8a29cee2f2}\mpengine.dll
2014-03-26 08:18:07 -------- d-----w- c:\users\marija\appdata\local\Skype
2014-03-26 08:17:55 -------- d-----r- c:\program files\Skype
2014-03-21 14:38:05 -------- d-----w- c:\users\marija\appdata\local\TunaMediaLtd
2014-03-21 14:37:38 -------- d-----w- c:\program files\TunaMediaLtd
2014-03-21 14:36:34 -------- d-----w- c:\users\marija\appdata\local\Downloaded Installations
2014-03-12 08:34:00 999936 ----a-w- c:\program files\internet explorer\networkinspection.dll
2014-03-12 08:34:00 646144 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2014-03-12 08:34:00 553472 ----a-w- c:\windows\system32\jscript9diag.dll
2014-03-12 08:34:00 51200 ----a-w- c:\windows\system32\ieetwproxystub.dll
2014-03-12 08:34:00 509440 ----a-w- c:\windows\system32\qedit.dll
2014-03-12 08:34:00 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2014-03-12 08:34:00 184320 ----a-w- c:\program files\internet explorer\F12Tools.dll
2014-03-12 08:34:00 1389568 ----a-w- c:\program files\internet explorer\MemoryAnalyzer.dll
2014-03-12 08:34:00 108032 ----a-w- c:\windows\system32\ieetwcollector.exe
2014-03-09 11:08:32 -------- d-----w- c:\program files\Skillbrains
2014-03-09 11:08:12 -------- d-----w- c:\users\marija\appdata\local\Skillbrains
2014-02-28 20:25:10 -------- d-----w- c:\users\marija\appdata\roaming\Awesomium
2014-02-28 20:10:23 -------- d-----w- c:\programdata\Elder Scrolls Online
2014-02-28 09:02:26 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2014-02-28 09:02:26 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
2014-02-28 09:02:26 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
2014-02-28 09:02:25 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2014-02-28 09:02:25 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
2014-02-28 09:02:23 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
2014-02-28 09:02:23 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
2014-02-28 09:02:22 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
.
==================== Find3M ====================
.
2014-03-11 17:53:37 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-03-11 17:53:37 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-03-01 04:11:20 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2014-03-01 03:52:43 61952 ----a-w- c:\windows\system32\iesetup.dll
2014-03-01 03:38:26 112128 ----a-w- c:\windows\system32\ieUnatt.exe
2014-03-01 03:14:15 4244480 ----a-w- c:\windows\system32\jscript9.dll
2014-03-01 03:00:08 1964032 ----a-w- c:\windows\system32\inetcpl.cpl
2014-03-01 02:32:16 1820160 ----a-w- c:\windows\system32\wininet.dll
2014-02-07 01:07:56 2349056 ----a-w- c:\windows\system32\win32k.sys
2014-02-04 02:04:22 1230336 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-01-31 09:24:19 715038 ----a-w- c:\windows\unins000.exe
2014-01-29 02:06:47 381440 ----a-w- c:\windows\system32\wer.dll
2014-01-28 02:07:07 185344 ----a-w- c:\windows\system32\wwansvc.dll
2014-01-25 09:27:16 775952 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2014-01-25 09:27:16 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-01-25 09:27:16 64168 ----a-w- c:\windows\system32\drivers\aswstm.sys
2014-01-25 09:27:15 43152 ----a-w- c:\windows\avastSS.scr
.
============= FINISH: 9:30:41.16 ===============

mycity.rs/must-login.png

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Pozdrav.

Deinstaliraj sledece programe:

Pando Media Booster
DefaultTab





Preuzmi smeenk-ov zoek.zip ili zoek.rar () sa ovog ili ovog linka i sačuvaj ga na Desktop.

Raspakuj arhivu u neki folder (uputstvo), a zatim:

zatvori browser i ostale pokrenute programe;
privremeno deaktiviraj zaštitni softver ( ukoliko je to potrebno ) Uputstvo ;
dvoklikom pokreni zoek na ikonicu programa ;
pričekaj da se alat startuje ...


U beli okvir prozora iskopiraj sledeći tekst:


autoclean;
C:\Program Files\DefaultTab;fs
C:\Users\Marija\AppData\Roaming\DefaultTab;fs
{7F6AFBF1-E065-4627-A2FD-810366367D01};c
c:\program files\mobogenie;fs
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run];r
"mobilegeni daemon"=-;r
DefaultTabSearch;s
DefaultTabUpdate;s
filesrcm;
startupall;
skipfix-iedefaults;
firefoxlook;
chromelook;
emptyalltemp;
emptyclsid;



Klikni na dugme i pričekaj da se skeniranje završi.


zoek ce po potrebi, restartovati Windows a na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.

Napomena:Izveštaj će biti sačuvan pod nazivom zoek-results.log na sistemskoj particiji (tipična lokacija: C:\zoek-results.log)


Arrow Kopiraj sadrzaj tog loga u poruku.

offline
  • Pridružio: 29 Mar 2014
  • Poruke: 6
  • Gde živiš: Beograd

Zoek.exe v5.0.0.0 Updated 07-March-2014
Tool run by Marija on Sat 03/29/2014 at 11:35:41.37.
Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Marija\Downloads\zoek.com [Scan all users] [Script inserted]

==== System Restore Info ======================

3/29/2014 11:37:18 AM Zoek.exe System Restore Point Created Succesfully.

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-3644864302-3415500735-3647736944-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7F6AFBF1-E065-4627-A2FD-810366367D01} deleted successfully
HKEY_USERS\S-1-5-21-3644864302-3415500735-3647736944-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7F6AFBF1-E065-4627-A2FD-810366367D01} deleted successfully
HKEY_USERS\S-1-5-21-3644864302-3415500735-3647736944-1000\Software\Microsoft\Internet Explorer\SearchScopes\{59460B71-25CA-4EAA-8D5C-A30784C6FCCC} deleted successfully

==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\DefaultTabSearch deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\DefaultTabUpdate deleted successfully

==== Registry Fix Code ======================

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mobilegeni daemon"=-

==== Deleting Files \ Folders ======================

C:\Program Files\DefaultTab not found
c:\program files\mobogenie not found
C:\Users\Marija\AppData\Roaming\DefaultTab deleted
C:\Users\Marija\AppData\Local\genienext deleted
C:\Users\Marija\daemonprocess.txt deleted
C:\Users\Marija\.android deleted
C:\Program Files\MyPC Backup deleted
C:\Users\Marija\AppData\Roaming\newnext.me deleted
C:\Users\Marija\AppData\Local\Mobogenie deleted
C:\Users\Marija\AppData\Local\cache deleted
C:\Windows\system32\tasks\DTReg deleted
C:\Windows\System32\AI_RecycleBin deleted
C:\Users\Marija\Documents\Mobogenie deleted

==== Files Recently Created / Modified ======================

====== C:\Windows ====
====== C:\Users\Marija\AppData\Local\Temp ====
====== Java Cache =====
2014-03-17 19:14:58 F87D912D86550770E0978A22E7B94DE0 17249 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0\38be0680-50c1abd7
2014-03-17 21:39:54 0DF0735CB38A63B121BE472C8647D31D 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10\cf2478a-6.0.lap
2014-03-20 22:24:14 72439AF14BEBCCB3AC480734F9968CF7 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\15d964cb-6.0.lap
2014-03-23 14:54:19 EAD068670169D07B5CC08C0BFBBD0EF1 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\7b690cc-6.0.lap
2014-03-17 19:21:12 C1BBA7F1278F193AB584FFF460DB5E2A 17878 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\eef218c-6375d9e0
2014-03-17 19:21:04 415FC9732A3F4D89A0E01251CD66E136 646 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\49a00451-43381efa
2014-03-25 20:19:21 1F69EA8C3CD5EEA708C78DF3EE54B018 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\4d94df52-6.0.lap
2014-03-17 19:21:03 415FC9732A3F4D89A0E01251CD66E136 646 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\3d7894d3-475b12c9
2014-03-19 14:50:33 3650E4198A1A37BDF09ADBB699514BC7 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\7a21e53-6.0.lap
2014-03-17 19:23:40 4CF2CBFA99CD797C4C73C62CBF539CBE 17298 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\273acec2-431d6a40
2014-03-17 19:18:05 FA06DA647BDEEE8ABB3D25FF15C81838 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\2e86afc2-6.0.lap
2014-03-21 12:28:14 8711CCCACA00E13E86504138FEBAB112 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\d0dc482-6.0.lap
2014-03-24 21:19:35 E7CA0BFF4F02C05512DD89F086826CE3 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26\58ebbdda-6.0.lap
2014-03-23 18:42:24 5E71EBA134E5F888D830080F613FB13A 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\1f6909c-6.0.lap
2014-03-19 17:05:58 F87D912D86550770E0978A22E7B94DE0 17249 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\f6ed69d-1deeb059
2014-03-25 10:53:06 8A1A1A26C54CBACC086387192FF50FED 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3\67cdc083-6.0.lap
2014-03-24 21:24:15 9B042223B8B81B9763E71F6856C10941 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\40cadc21-6.0.lap
2014-03-23 13:39:21 646899554E85CC27AFDCE15C688AD0A9 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34\6098f0a2-6.0.lap
2014-03-24 10:30:51 EF0882AC12EF542DF9B8B29918893FB1 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35\439ab5e3-6.0.lap
2014-03-09 20:56:04 0EA539E25970B0B662AF7ECEC802F46B 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4\6bcc8b04-6.0.lap
2014-03-25 15:17:12 4CF2CBFA99CD797C4C73C62CBF539CBE 17298 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\2d583168-1496d80f
2014-03-17 20:28:52 E0EE32510A86B6AB1F131B1F7580A282 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41\65b2aaa9-6.0.lap
2014-03-25 10:54:22 550D98C3FED4E15451FD8D5C43E0FD65 17193 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42\3a835eea-59431048
2014-03-17 19:21:05 34FA8033B50A3F99D3AB8209C72C0ABA 6860 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\1ca2666b-47868ac9
2014-03-04 19:44:47 F87D912D86550770E0978A22E7B94DE0 17249 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45\5aae61ed-2b75cc46
2014-03-25 10:54:21 FD8CDC9F0866547CFC9E0CC10E860DE1 79 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\16cb04f0-6.0.lap
2014-03-04 19:44:46 A005EFE387D53ABA025E449030BE69EC 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\36c1bc71-6.0.lap
2014-03-24 21:17:59 E438540B7D71350EA89A652410D657BE 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5\2183de45-6.0.lap
2014-03-23 17:20:35 F91151647D0353D7DBFA854CA7A8A0F9 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\2e5daef4-6.0.lap
2014-03-23 16:08:44 958CFCCD3476860CB4EAB29AAB6CC865 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\5ac79574-6.0.lap
2014-03-25 10:50:58 443E4FD4E738D595BA30116E191E5CC1 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\7fd71574-6.0.lap
2014-03-25 12:13:13 4CF2CBFA99CD797C4C73C62CBF539CBE 17298 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53\579cd375-2a1d45f5
2014-03-23 13:39:56 96DC1D8B36FF946400C44B34C59AF35F 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54\3416bc36-6.0.lap
2014-03-25 21:24:49 162F101DF21E66CE55650865C14741DE 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55\211f9bb7-6.0.lap
2014-03-19 11:19:15 4451EE7456DF297EEB282915D84BA97C 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55\60ba62b7-6.0.lap
2014-03-20 18:34:59 9726AD9EA99E693AFB714E1B2D074ACE 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55\9899077-6.0.lap
2014-03-21 13:12:17 62DA176FD696B22C7BBCFA8FC7E99507 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\6dd015b8-6.0.lap
2014-03-25 12:13:12 911A09BBA1061C16AD78D9DD1516588A 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\26f91039-6.0.lap
2014-03-25 16:27:29 CBE4A1069C5BF92F7CE7E56233BECB01 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\6dafe7b9-6.0.lap
2014-03-20 13:10:00 A37D45B724B8F7D6F03022E0FDC76D80 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59\362ad8bb-6.0.lap
2014-03-23 19:34:27 3161C840781F629ED8E30FE665D54101 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59\55afdb7b-6.0.lap
2014-03-20 23:42:34 3E73B5BA8F6471D0630DDD2FBA68EE67 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60\262923c-6.0.lap
2014-03-17 19:14:55 C3138678C7B2EA948C493EDF210755B8 37 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60\7b59673c-6.0.lap
2014-03-25 09:21:54 C53B53EF948AED398B3EEBC4CD7A2C4D 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61\2c41167d-6.0.lap
2014-03-21 17:40:53 E082EB95D4C585D04F196C49D66985FF 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62\40e876fe-6.0.lap
2014-03-19 17:06:06 F198A6548C1BC93BD89D934EBEBC70C3 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\62d04f3f-6.0.lap
2014-03-25 22:18:59 7E91C46E93D87A2336B7C6C8B1C9CA82 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\71423a3f-6.0.lap
2014-03-25 15:17:10 8B2F6BC5F6429470BE0DBFDFB8913132 84 ----a-w- C:\Users\Marija\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9\a3858c9-6.0.lap
====== C:\Windows\system32 =====
2014-03-28 10:42:13 797E24743937D67D69F28F2CF5052EE8 2414360 ----a-w- C:\Windows\System32\d3dx9_31.dll
====== C:\Windows\system32\drivers =====
====== C:\Windows\Tasks ======
2014-03-09 11:08:40 F51ED061FDB3A983B388855A44C5A06B 3254 ----a-w- C:\Windows\system32\Tasks\update-S-1-5-21-3644864302-3415500735-3647736944-1000
2014-03-09 11:08:40 F0DD8E1964FF29344C0430C7BC632865 378 ----a-w- C:\Windows\Tasks\update-S-1-5-21-3644864302-3415500735-3647736944-1000.job
2014-03-09 11:08:36 DA115427693EBDD1F9D77F329F201C77 378 ----a-w- C:\Windows\Tasks\update-sys.job
2014-03-09 11:08:36 85A6CD866369D1AF066E39F885277E52 3274 ----a-w- C:\Windows\system32\Tasks\update-sys
====== C:\Windows\Temp ======
======= C:\Program Files =====
2014-03-28 10:42:26 -------- d-----w- C:\Program Files\Microsoft WSE
2014-03-26 08:17:55 -------- d-----w- C:\Program Files\Common Files\Skype
2014-03-26 08:17:55 -------- d-----r- C:\Program Files\Skype
2014-03-21 14:37:38 -------- d-----w- C:\Program Files\TunaMediaLtd
2014-03-09 11:08:32 -------- d-----w- C:\Program Files\Skillbrains
======= C: =====
====== C:\Users\Marija\AppData\Roaming ======
2014-03-26 08:18:07 -------- d-----w- C:\Users\Marija\AppData\Local\Skype
2014-03-21 14:38:05 -------- d-----w- C:\Users\Marija\AppData\Local\TunaMediaLtd
2014-03-21 14:36:34 -------- d-----w- C:\Users\Marija\AppData\Local\Downloaded Installations
2014-03-11 10:17:31 -------- d-----w- C:\Users\Marija\AppData\Locallow\Temp
2014-03-09 11:08:40 AE346A02E922B6C327981BD6603E2C16 443 ----a-w- C:\Users\Marija\AppData\Local\UserProducts.xml
2014-03-09 11:08:15 -------- d-----w- C:\Users\Marija\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lightshot
2014-03-09 11:08:12 -------- d-----w- C:\Users\Marija\AppData\Local\Skillbrains
2014-03-08 15:14:02 -------- d-----w- C:\Windows\serviceprofiles\Localservice\AppData\Local\PnrpSqm
2014-03-08 15:11:28 -------- d-----w- C:\Windows\serviceprofiles\Localservice\AppData\Roaming\PeerNetworking
2014-02-28 20:25:10 -------- d-----w- C:\Users\Marija\AppData\Roaming\Awesomium
====== C:\Users\Marija ======
2014-03-26 08:17:55 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-03-21 14:37:41 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Radio Tuna
2014-03-21 14:35:34 B8F66254796B35F2C26B327B925582BE 4200896 ----a-w- C:\Users\Marija\Downloads\RadioTunaSetup.exe
2014-02-28 20:10:23 -------- d-----w- C:\ProgramData\Elder Scrolls Online
2014-02-28 08:54:08 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Elder Scrolls Online Beta

====== C: exe-files ==
2014-03-28 10:42:27 6E42CF0D47AF25DEA4CECDBE093D521C 10134 ----a-r- C:\Users\Marija\AppData\Roaming\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
2014-03-28 10:36:22 199576171AD8DDB10E2AADE61BBF87CB 398608 ----a-w- C:\Program Files\InstallShield Installation Information\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}\Sims3Setup.exe
2014-03-28 09:01:58 869C51A87817563644547C58308A7B66 10720392 ----a-w- C:\Users\Marija\Downloads\The Sims 3 - Razor1911 Final MAXSPEED\Final Version Patch\Sims3_1.0.632.00002_from_1.0.631.00002.exe
2014-03-28 08:54:43 861FAC71B1751E14F8BCEF651021047B 11285776 ----a-w- C:\Users\Marija\Downloads\The Sims 3 - Razor1911 Final MAXSPEED\(zabranjeno)\TS3.exe
2014-03-22 20:10:03 8718A02FBD2AC65C2D9A1C7BBD98DCA1 16383840 ----a-w- C:\Riot Games\League of Legends\RADS\projects\lol_game_client\releases\0.0.0.204\deploy\League of Legends.exe
=== C: other files ==

==== Startup Registry Enabled ======================

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"

[HKEY_USERS\S-1-5-21-3644864302-3415500735-3647736944-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"LightShot"="C:\Users\Marija\AppData\Local\Skillbrains\lightshot\Lightshot.exe Flags: uninsdeletevalue"
"Skype"="C:\Program Files\Skype\Phone\Skype.exe /minimized /regrun"

[HKEY_USERS\S-1-5-21-3644864302-3415500735-3647736944-1001\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"

[HKEY_USERS\S-1-5-21-3644864302-3415500735-3647736944-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvastUI.exe /nogui"
"HDAudDeck"="C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe -r"
"SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe"
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"LightShot"="C:\Users\Marija\AppData\Local\Skillbrains\lightshot\Lightshot.exe Flags: uninsdeletevalue"
"Skype"="C:\Program Files\Skype\Phone\Skype.exe /minimized /regrun"

==== Task Scheduler Jobs ======================

C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [03/11/2014 06:53 PM]
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [12/23/2013 01:10 AM]
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ [Undetermined Task]
C:\Windows\tasks\update-S-1-5-21-3644864302-3415500735-3647736944-1000.job --a------ C:\Program Files\Skillbrains\Updater\Updater.exe [09/27/2013 01:37 PM]
C:\Windows\tasks\update-sys.job --a------ C:\Program Files\Skillbrains\Updater\Updater.exe [09/27/2013 01:37 PM]

==== Other Scheduled Tasks ======================

"C:\Windows\system32\tasks\Adobe Flash Player Updater" [C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe]
"C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files\Google\Update\GoogleUpdate.exe]
"C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files\Google\Update\GoogleUpdate.exe]
"C:\Windows\system32\tasks\update-S-1-5-21-3644864302-3415500735-3647736944-1000" [C:\Program Files\Skillbrains\Updater\Updater.exe]
"C:\Windows\system32\tasks\update-sys" [C:\Program Files\Skillbrains\Updater\Updater.exe]
"C:\Windows\system32\tasks\{BF3BD3AC-2ACA-44C0-ADE2-97CD3D683835}" ["c:\program files\google\chrome\application\chrome.exe"]

==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[01/25/2014 10:27 AM]

Forge of Empires - Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\anaphblkfplenhkephgneolhnmjminjg
Google Docs - Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake
Google Drive - Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf
YouTube - Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
Entanglement - Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmnpffgfpcohhpoddjankjanolcekbni
Google Search - Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
Hotmail Checker - Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkkhlmcnbdhoddgjhlgikcpmigdmlcmd
Yulia Brodskaya - Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlgdloilieclkegafohackmhffbmdpko
DefaultTab - Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc
Webcam Toy - Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfbgimoladefibpklnfmkpknadbklade
Google Maps - Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh
Google Mail Checker - Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff
Google Wallet - Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Talking Ginger - Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\nopmlcbgegmbnpmlfedeaoflpbgohlim
Background Tab - Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\oehpjpccmlcalbenfhnacjeocbjdonic
Gmail - Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
DefaultTab - C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc

==== Chrome Fix ======================

C:\Users\Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc deleted successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"

==== Empty IE Cache ======================

C:\Users\Marija\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Marija\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\032ZXHES will be deleted at reboot
C:\Users\Marija\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HTHR500V will be deleted at reboot
C:\Users\Marija\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X0H995IA will be deleted at reboot

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Chrome Cache ======================

C:\Users\Marija\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache is not empty, a reboot is needed

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=502 folders=104 28131135 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Marija\AppData\Local\Temp will be emptied at reboot
C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\Marija\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\MpCmdRun.log" not found
"C:\Users\Marija\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\032ZXHES" not found
"C:\Users\Marija\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HTHR500V" not found
"C:\Users\Marija\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X0H995IA" not found
"C:\Users\Marija\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\2BUVJU2B\dd9vanvlu7np7.cloudfront.net" not found
"C:\Users\Marija\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\2BUVJU2B\tag.atvnetworks.tv" not found
"C:\Users\Marija\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\2BUVJU2B\vidzur.com" not found

==== EOF on Sat 03/29/2014 at 11:48:20.23 ======================

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

U redu, da proverimo jos nesto.


Preuzmi Farbar-ov Farbar Recovery Scan Tool () sa ove adrese na Desktop:
Postoji 32bit. i 64bit.-na verzija. Potrebno je preuzeti verziju koja je kompatibilna sa tvojim sistemom.
Ako nisi siguran koja verzija se odnosi na tvoj sistem, preuzmi ih obe i pokreni. Samo jedan od njih će raditi na tvom sistemu, to će biti prava verzija.


dvoklikom pokreni program, kada se alat pokrene klikni Yes na disclaimer prozor;
pričekati koji trenutak dok alat proverava postoji li novija verzija;
klikni na dugme Scan;
po završetku skeniranja, alat će formirati izveštaj (FRST.txt) u isti direktorijum gde je FRST alat sačuvan;
iskopiraj sadržaj FRST.txt izveštaja u poruku;
po prvom pokretanju, alat bi trebao formirati i dodatni izveštaj (Addition.txt);
okači Addition.txt izveštaj uz poruku koristeći opciju Prikači fajl

offline
  • Pridružio: 29 Mar 2014
  • Poruke: 6
  • Gde živiš: Beograd

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014 01
Ran by Marija (administrator) on MARIJA-PC on 29-03-2014 12:11:19
Running from C:\Users\Marija\Desktop\New folder (3)
Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: English(US)
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: geekstogo.com/forum/topic/335081-frst-t.....scan-tool/

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Windows\system32\AUDIODG.EXE
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(VIA) C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(PowerISO Computing, Inc.) C:\Program Files\PowerISO\PWRISOVM.EXE
(Skillbrains) C:\Users\Marija\AppData\Local\Skillbrains\lightshot\5.1.0.15\Lightshot.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(TunaMediaLtd) C:\Program Files\TunaMediaLtd\RadioTuna\RadioTuna.exe
(Opera Software) C:\Program Files\Opera\20.0.1387.82\opera.exe
() C:\Program Files\Opera\20.0.1387.82\opera_crashreporter.exe
(Opera Software) C:\Program Files\Opera\20.0.1387.82\opera.exe
(Opera Software) C:\Program Files\Opera\20.0.1387.82\opera.exe
(Opera Software) C:\Program Files\Opera\20.0.1387.82\opera.exe
(Opera Software) C:\Program Files\Opera\20.0.1387.82\opera.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3767096 2014-01-25] (AVAST Software)
HKLM\...\Run: [HDAudDeck] - C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe [1681408 2009-09-22] (VIA)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [PWRISOVM.EXE] - C:\Program Files\PowerISO\PWRISOVM.EXE [180224 2010-04-12] (PowerISO Computing, Inc.)
HKU\S-1-5-21-3644864302-3415500735-3647736944-1000\...\Run: [LightShot] - C:\Users\Marija\AppData\Local\Skillbrains\lightshot\Lightshot.exe [226592 2014-03-06] ()
HKU\S-1-5-21-3644864302-3415500735-3647736944-1000\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.)
HKU\S-1-5-21-3644864302-3415500735-3647736944-1000\...\MountPoints2: F - F:\Autorun.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x608D015073FFCE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR Extension: (Forge of Empires) - C:\Users\Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\anaphblkfplenhkephgneolhnmjminjg [2014-02-12]
CHR Extension: (Google Docs) - C:\Users\Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-22]
CHR Extension: (Google Drive) - C:\Users\Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-22]
CHR Extension: (YouTube) - C:\Users\Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-22]
CHR Extension: (Entanglement) - C:\Users\Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmnpffgfpcohhpoddjankjanolcekbni [2014-01-02]
CHR Extension: (Google Search) - C:\Users\Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-22]
CHR Extension: (Hotmail Checker) - C:\Users\Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkkhlmcnbdhoddgjhlgikcpmigdmlcmd [2013-12-22]
CHR Extension: (Yulia Brodskaya) - C:\Users\Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlgdloilieclkegafohackmhffbmdpko [2013-12-22]
CHR Extension: (Webcam Toy) - C:\Users\Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfbgimoladefibpklnfmkpknadbklade [2014-02-11]
CHR Extension: (Google Maps) - C:\Users\Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2014-01-02]
CHR Extension: (Google Mail Checker) - C:\Users\Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2013-12-22]
CHR Extension: (Google Wallet) - C:\Users\Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-22]
CHR Extension: (Talking Ginger) - C:\Users\Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\nopmlcbgegmbnpmlfedeaoflpbgohlim [2014-02-11]
CHR Extension: (My Chrome Theme) - C:\Users\Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\oehpjpccmlcalbenfhnacjeocbjdonic [2013-12-22]
CHR Extension: (Gmail) - C:\Users\Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-22]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2013-12-22]

========================== Services (Whitelisted) =================

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-01-25] (AVAST Software)

==================== Drivers (Whitelisted) ====================

R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2014-01-25] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [79720 2013-12-22] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2013-12-22] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [775952 2014-01-25] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [410784 2014-01-25] (AVAST Software)
R3 aswStm; C:\Windows\system32\drivers\aswStm.sys [64168 2014-01-25] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [180248 2013-12-22] ()
R3 VIAHdAudAddService; C:\Windows\System32\drivers\viahduaa.sys [1086976 2009-09-18] (VIA Technologies, Inc.)
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-03-29 12:11 - 2014-03-29 12:11 - 00000000 ____D () C:\FRST
2014-03-29 12:10 - 2014-03-29 12:11 - 00000000 ____D () C:\Users\Marija\Desktop\New folder (3)
2014-03-29 12:06 - 2014-03-29 12:06 - 01145856 _____ (Farbar) C:\Users\Marija\Downloads\FRST.exe
2014-03-29 11:46 - 2014-02-13 23:59 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-03-29 11:37 - 2014-03-29 11:48 - 00022528 _____ () C:\zoek-results.log
2014-03-29 11:36 - 2014-03-29 11:36 - 00000847 _____ () C:\Users\Marija\Desktop\New Text Document.txt
2014-03-29 11:35 - 2014-03-29 11:45 - 00000000 ____D () C:\zoek_backup
2014-03-29 11:34 - 2014-03-29 11:34 - 04235514 _____ () C:\Users\Marija\Downloads\zoek.rar
2014-03-29 11:34 - 2014-03-08 11:05 - 01414742 _____ () C:\Users\Marija\Downloads\zoek.scr
2014-03-29 11:34 - 2014-03-08 11:05 - 01414742 _____ () C:\Users\Marija\Downloads\zoek.pif
2014-03-29 11:34 - 2014-03-08 11:05 - 01414742 _____ () C:\Users\Marija\Downloads\zoek.com
2014-03-29 09:30 - 2014-03-29 09:30 - 00010853 _____ () C:\Users\Marija\Desktop\dds.txt
2014-03-29 09:30 - 2014-03-29 09:30 - 00004259 _____ () C:\Users\Marija\Desktop\attach.txt
2014-03-29 09:29 - 2014-03-29 09:29 - 00688992 ____R (Swearware) C:\Users\Marija\Downloads\dds.scr
2014-03-28 11:48 - 2014-03-28 11:48 - 00000000 ____D () C:\Users\Marija\Documents\Electronic Arts
2014-03-28 11:47 - 2014-03-28 11:47 - 00001189 _____ () C:\Users\Marija\Desktop\TS3 - Shortcut.lnk
2014-03-28 11:42 - 2014-03-28 11:42 - 00000000 ____D () C:\Program Files\Microsoft WSE
2014-03-28 11:42 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll
2014-03-28 09:51 - 2014-03-28 11:02 - 00000000 ____D () C:\Users\Marija\Downloads\The Sims 3 - Razor1911 Final MAXSPEED
2014-03-26 09:18 - 2014-03-26 09:18 - 00000000 ____D () C:\Users\Marija\AppData\Local\Skype
2014-03-26 09:17 - 2014-03-26 09:17 - 00000000 ___RD () C:\Program Files\Skype
2014-03-26 09:17 - 2014-03-26 09:17 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-03-25 20:52 - 2014-03-25 20:54 - 00000000 ____D () C:\Users\Marija\Desktop\bebe
2014-03-23 10:38 - 2014-03-25 20:54 - 00000000 ____D () C:\Users\Marija\Desktop\foto
2014-03-23 10:38 - 2014-03-23 10:45 - 00000000 ____D () C:\Users\Marija\Desktop\New folder (2)
2014-03-21 15:38 - 2014-03-21 15:38 - 00000000 ____D () C:\Users\Marija\AppData\Local\TunaMediaLtd
2014-03-21 15:37 - 2014-03-21 15:37 - 00000000 ____D () C:\Program Files\TunaMediaLtd
2014-03-21 15:36 - 2014-03-21 15:36 - 00000000 ____D () C:\Users\Marija\AppData\Local\Downloaded Installations
2014-03-21 15:35 - 2014-03-21 15:36 - 04200896 _____ (TunaMediaLtd) C:\Users\Marija\Downloads\RadioTunaSetup.exe
2014-03-19 22:01 - 2014-03-19 22:02 - 00000000 ____D () C:\Users\Marija\Desktop\New folder
2014-03-19 21:59 - 2014-03-19 22:00 - 00033417 _____ () C:\Users\Marija\Downloads\18707-talisman-online-bot-lillyz-v-beta-talismanonlinebotbylilyz.rar
2014-03-13 19:02 - 2014-03-13 19:33 - 1066078198 _____ () C:\Users\Marija\Downloads\Skymight Talisman Client.rar
2014-03-12 09:34 - 2014-03-01 05:10 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-12 09:34 - 2014-03-01 04:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-12 09:34 - 2014-03-01 04:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-12 09:34 - 2014-03-01 04:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-12 09:34 - 2014-03-01 04:38 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-12 09:34 - 2014-03-01 04:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-12 09:34 - 2014-03-01 04:31 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-12 09:34 - 2014-02-04 03:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-12 09:33 - 2014-03-01 05:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-12 09:33 - 2014-03-01 05:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-12 09:33 - 2014-03-01 04:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-12 09:33 - 2014-03-01 04:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-12 09:33 - 2014-03-01 04:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-12 09:33 - 2014-03-01 04:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-12 09:33 - 2014-03-01 04:25 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-12 09:33 - 2014-03-01 04:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-12 09:33 - 2014-03-01 04:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-12 09:33 - 2014-03-01 04:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-12 09:33 - 2014-03-01 04:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-12 09:33 - 2014-03-01 03:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-12 09:33 - 2014-03-01 03:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-12 09:33 - 2014-03-01 03:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-12 09:33 - 2014-03-01 03:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-12 09:33 - 2014-02-07 02:07 - 02349056 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-12 09:33 - 2014-02-04 03:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-12 09:33 - 2014-01-29 03:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-12 09:33 - 2014-01-28 03:07 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-09 12:08 - 2014-03-29 09:29 - 00000378 _____ () C:\Windows\Tasks\update-sys.job
2014-03-09 12:08 - 2014-03-29 08:42 - 00000378 _____ () C:\Windows\Tasks\update-S-1-5-21-3644864302-3415500735-3647736944-1000.job
2014-03-09 12:08 - 2014-03-09 12:08 - 00000443 _____ () C:\Users\Marija\AppData\Local\UserProducts.xml
2014-03-09 12:08 - 2014-03-09 12:08 - 00000003 _____ () C:\Users\Marija\AppData\Local\updater.log
2014-03-09 12:08 - 2014-03-09 12:08 - 00000000 ____D () C:\Users\Marija\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lightshot
2014-03-09 12:08 - 2014-03-09 12:08 - 00000000 ____D () C:\Users\Marija\AppData\Local\Skillbrains
2014-03-09 12:08 - 2014-03-09 12:08 - 00000000 ____D () C:\Program Files\Skillbrains
2014-03-09 12:06 - 2014-03-09 12:07 - 02182024 _____ (Skillbrains ) C:\Users\Marija\Downloads\setup-lightshot.exe
2014-03-05 21:38 - 2014-03-05 21:39 - 01455528 _____ () C:\Users\Marija\Downloads\SystemCheck_enUS.exe
2014-03-05 21:33 - 2014-03-05 21:34 - 05748928 _____ (Blizzard Entertainment) C:\Users\Marija\Downloads\Battle.net-Beta-Setup-enUS.exe
2014-03-04 20:34 - 2014-03-04 20:35 - 00108064 _____ () C:\Users\Marija\Downloads\setup.exe
2014-02-28 21:25 - 2014-03-16 11:02 - 00000000 ____D () C:\Users\Marija\AppData\Roaming\Awesomium
2014-02-28 21:10 - 2014-02-28 21:10 - 00000000 ____D () C:\Users\Marija\Documents\Elder Scrolls Online
2014-02-28 21:10 - 2014-02-28 21:10 - 00000000 ____D () C:\ProgramData\Elder Scrolls Online
2014-02-28 10:02 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
2014-02-28 10:02 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll
2014-02-28 10:02 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
2014-02-28 10:02 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
2014-02-28 10:02 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll
2014-02-28 10:02 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll
2014-02-28 10:02 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll
2014-02-28 10:02 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
2014-02-28 09:54 - 2014-02-28 09:54 - 00000818 _____ () C:\Users\Marija\Desktop\The Elder Scrolls Online Beta.lnk
2014-02-28 09:41 - 2014-02-28 09:42 - 55903624 _____ ( ) C:\Users\Marija\Downloads\Install_ESO_Beta.exe

==================== One Month Modified Files and Folders =======

2014-03-29 12:11 - 2014-03-29 12:11 - 00000000 ____D () C:\FRST
2014-03-29 12:11 - 2014-03-29 12:10 - 00000000 ____D () C:\Users\Marija\Desktop\New folder (3)
2014-03-29 12:06 - 2014-03-29 12:06 - 01145856 _____ (Farbar) C:\Users\Marija\Downloads\FRST.exe
2014-03-29 11:53 - 2010-11-20 22:01 - 00778834 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-03-29 11:51 - 2013-12-23 01:05 - 01951158 _____ () C:\Windows\WindowsUpdate.log
2014-03-29 11:49 - 2013-12-22 16:08 - 00000000 ____D () C:\Users\Marija\AppData\Roaming\Skype
2014-03-29 11:48 - 2014-03-29 11:37 - 00022528 _____ () C:\zoek-results.log
2014-03-29 11:48 - 2013-12-22 15:19 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-03-29 11:48 - 2013-12-22 15:09 - 00000882 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-29 11:48 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-29 11:48 - 2009-07-14 05:39 - 00460041 _____ () C:\Windows\setupact.log
2014-03-29 11:47 - 2010-11-20 22:48 - 00009236 _____ () C:\Windows\PFRO.log
2014-03-29 11:45 - 2014-03-29 11:35 - 00000000 ____D () C:\zoek_backup
2014-03-29 11:43 - 2013-12-23 01:07 - 00000000 ____D () C:\Users\Marija
2014-03-29 11:36 - 2014-03-29 11:36 - 00000847 _____ () C:\Users\Marija\Desktop\New Text Document.txt
2014-03-29 11:34 - 2014-03-29 11:34 - 04235514 _____ () C:\Users\Marija\Downloads\zoek.rar
2014-03-29 11:24 - 2013-12-22 15:09 - 00000886 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-29 10:48 - 2014-02-17 17:39 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-03-29 09:30 - 2014-03-29 09:30 - 00010853 _____ () C:\Users\Marija\Desktop\dds.txt
2014-03-29 09:30 - 2014-03-29 09:30 - 00004259 _____ () C:\Users\Marija\Desktop\attach.txt
2014-03-29 09:29 - 2014-03-29 09:29 - 00688992 ____R (Swearware) C:\Users\Marija\Downloads\dds.scr
2014-03-29 09:29 - 2014-03-09 12:08 - 00000378 _____ () C:\Windows\Tasks\update-sys.job
2014-03-29 08:42 - 2014-03-09 12:08 - 00000378 _____ () C:\Windows\Tasks\update-S-1-5-21-3644864302-3415500735-3647736944-1000.job
2014-03-29 08:11 - 2014-01-23 21:50 - 00000884 __RSH () C:\Users\Marija\ntuser.pol
2014-03-28 22:35 - 2009-07-14 05:53 - 00032598 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-03-28 13:12 - 2014-01-13 02:00 - 00000000 ____D () C:\Users\Marija\AppData\Roaming\uTorrent
2014-03-28 11:48 - 2014-03-28 11:48 - 00000000 ____D () C:\Users\Marija\Documents\Electronic Arts
2014-03-28 11:47 - 2014-03-28 11:47 - 00001189 _____ () C:\Users\Marija\Desktop\TS3 - Shortcut.lnk
2014-03-28 11:42 - 2014-03-28 11:42 - 00000000 ____D () C:\Program Files\Microsoft WSE
2014-03-28 11:36 - 2013-12-22 15:59 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2014-03-28 11:02 - 2014-03-28 09:51 - 00000000 ____D () C:\Users\Marija\Downloads\The Sims 3 - Razor1911 Final MAXSPEED
2014-03-26 09:18 - 2014-03-26 09:18 - 00000000 ____D () C:\Users\Marija\AppData\Local\Skype
2014-03-26 09:17 - 2014-03-26 09:17 - 00000000 ___RD () C:\Program Files\Skype
2014-03-26 09:17 - 2014-03-26 09:17 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-03-26 09:17 - 2013-12-22 16:08 - 00000000 ____D () C:\ProgramData\Skype
2014-03-26 02:03 - 2009-07-14 05:34 - 00020640 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-26 02:03 - 2009-07-14 05:34 - 00020640 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-25 21:18 - 2013-12-22 16:09 - 00000000 ____D () C:\Users\Marija\AppData\Local\PMB Files
2014-03-25 21:18 - 2013-12-22 16:09 - 00000000 ____D () C:\ProgramData\PMB Files
2014-03-25 20:54 - 2014-03-25 20:52 - 00000000 ____D () C:\Users\Marija\Desktop\bebe
2014-03-25 20:54 - 2014-03-23 10:38 - 00000000 ____D () C:\Users\Marija\Desktop\foto
2014-03-23 10:45 - 2014-03-23 10:38 - 00000000 ____D () C:\Users\Marija\Desktop\New folder (2)
2014-03-21 15:38 - 2014-03-21 15:38 - 00000000 ____D () C:\Users\Marija\AppData\Local\TunaMediaLtd
2014-03-21 15:37 - 2014-03-21 15:37 - 00000000 ____D () C:\Program Files\TunaMediaLtd
2014-03-21 15:36 - 2014-03-21 15:36 - 00000000 ____D () C:\Users\Marija\AppData\Local\Downloaded Installations
2014-03-21 15:36 - 2014-03-21 15:35 - 04200896 _____ (TunaMediaLtd) C:\Users\Marija\Downloads\RadioTunaSetup.exe
2014-03-20 10:39 - 2014-02-17 17:05 - 00000000 ____D () C:\Program Files\Opera
2014-03-19 22:02 - 2014-03-19 22:01 - 00000000 ____D () C:\Users\Marija\Desktop\New folder
2014-03-19 22:00 - 2014-03-19 21:59 - 00033417 _____ () C:\Users\Marija\Downloads\18707-talisman-online-bot-lillyz-v-beta-talismanonlinebotbylilyz.rar
2014-03-16 11:02 - 2014-02-28 21:25 - 00000000 ____D () C:\Users\Marija\AppData\Roaming\Awesomium
2014-03-15 20:50 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\LogFiles
2014-03-13 19:33 - 2014-03-13 19:02 - 1066078198 _____ () C:\Users\Marija\Downloads\Skymight Talisman Client.rar
2014-03-12 20:30 - 2009-07-14 05:33 - 00268128 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-11 18:53 - 2014-02-17 17:38 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-03-11 18:53 - 2014-02-17 17:38 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-03-11 18:53 - 2014-02-17 17:32 - 00000000 ____D () C:\Users\Marija\AppData\Local\Adobe
2014-03-09 12:08 - 2014-03-09 12:08 - 00000443 _____ () C:\Users\Marija\AppData\Local\UserProducts.xml
2014-03-09 12:08 - 2014-03-09 12:08 - 00000003 _____ () C:\Users\Marija\AppData\Local\updater.log
2014-03-09 12:08 - 2014-03-09 12:08 - 00000000 ____D () C:\Users\Marija\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lightshot
2014-03-09 12:08 - 2014-03-09 12:08 - 00000000 ____D () C:\Users\Marija\AppData\Local\Skillbrains
2014-03-09 12:08 - 2014-03-09 12:08 - 00000000 ____D () C:\Program Files\Skillbrains
2014-03-09 12:07 - 2014-03-09 12:06 - 02182024 _____ (Skillbrains ) C:\Users\Marija\Downloads\setup-lightshot.exe
2014-03-08 16:11 - 2009-07-14 03:37 - 00000000 __RHD () C:\Users\Public\Libraries
2014-03-08 11:05 - 2014-03-29 11:34 - 01414742 _____ () C:\Users\Marija\Downloads\zoek.scr
2014-03-08 11:05 - 2014-03-29 11:34 - 01414742 _____ () C:\Users\Marija\Downloads\zoek.com
2014-03-05 21:39 - 2014-03-05 21:38 - 01455528 _____ () C:\Users\Marija\Downloads\SystemCheck_enUS.exe
2014-03-05 21:34 - 2014-03-05 21:33 - 05748928 _____ (Blizzard Entertainment) C:\Users\Marija\Downloads\Battle.net-Beta-Setup-enUS.exe
2014-03-04 20:35 - 2014-03-04 20:34 - 00108064 _____ () C:\Users\Marija\Downloads\setup.exe
2014-03-01 05:30 - 2014-03-12 09:33 - 17074688 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-01 05:11 - 2014-03-12 09:33 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-01 05:10 - 2014-03-12 09:34 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-01 04:52 - 2014-03-12 09:33 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-01 04:51 - 2014-03-12 09:34 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-01 04:47 - 2014-03-12 09:33 - 02168320 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-01 04:43 - 2014-03-12 09:34 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-01 04:43 - 2014-03-12 09:34 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-01 04:40 - 2014-03-12 09:33 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-01 04:38 - 2014-03-12 09:34 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-01 04:38 - 2014-03-12 09:33 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-01 04:37 - 2014-03-12 09:34 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-01 04:31 - 2014-03-12 09:34 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-01 04:25 - 2014-03-12 09:33 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-01 04:16 - 2014-03-12 09:33 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-01 04:14 - 2014-03-12 09:33 - 04244480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-01 04:03 - 2014-03-12 09:33 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-01 04:00 - 2014-03-12 09:33 - 01964032 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-01 03:57 - 2014-03-12 09:33 - 11266048 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-01 03:32 - 2014-03-12 09:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-01 03:27 - 2014-03-12 09:33 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-01 03:25 - 2014-03-12 09:33 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-28 21:10 - 2014-02-28 21:10 - 00000000 ____D () C:\Users\Marija\Documents\Elder Scrolls Online
2014-02-28 21:10 - 2014-02-28 21:10 - 00000000 ____D () C:\ProgramData\Elder Scrolls Online
2014-02-28 11:06 - 2013-12-22 22:14 - 00000000 ____D () C:\Users\Marija\AppData\Local\Microsoft Games
2014-02-28 09:54 - 2014-02-28 09:54 - 00000818 _____ () C:\Users\Marija\Desktop\The Elder Scrolls Online Beta.lnk
2014-02-28 09:42 - 2014-02-28 09:41 - 55903624 _____ ( ) C:\Users\Marija\Downloads\Install_ESO_Beta.exe

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-03-20 10:28

==================== End Of Log ============================
mycity.rs/must-login.png

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

1. Otvori Notepad (Text Document) i iskopiraj sledeći tekst unutar kod polja ispod:
Start
CHR Extension: (Yulia Brodskaya) - C:\Users\Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlgdloilieclkegafohackmhffbmdpko [2013-12-22]
HKU\S-1-5-21-3644864302-3415500735-3647736944-1000\...\MountPoints2: F - F:\Autorun.exe
Task: {91A2ACE7-31D7-4D76-9345-53940D527CA9} - \DTReg No Task File
End

2. Sačuvaj notepad na Desktop pod nazivom fixlist.txt
To možes uraditi i iz notepad-a => klik na File potom na Save As i u novom prozoru, dole pod File Name: staviš za naziv fixlist.txt
Napomena: Važno je da se oba fajla, FRST i fixlist nalaze na istoj lokaciji jer u suprotnom fix nece raditi.

3. Ponovo pokreni FRST/FRST64, klikni jednom na dugme Fix i sačekaj.
Ukoliko alat zatraži restart sistema, dozvoli mu i postaraj se da alat kompletira fix nakon restarta sistema.



Alat će formirati log (Fixlog.txt) na Desktop-u. Potrebno je sadržaj tog loga iskopirati u poruku.
Napomena: Ukoliko te alat upozori da postoji novija verzija, postaraj se da preuzmes i koristiš ažuriranu kopiju FRST-a.

offline
  • Pridružio: 29 Mar 2014
  • Poruke: 6
  • Gde živiš: Beograd

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 13-03-2014 01
Ran by Marija at 2014-03-29 12:36:05 Run:1
Running from C:\Users\Marija\Desktop\New folder (3)
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
Start
CHR Extension: (Yulia Brodskaya) - C:\Users\Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlgdloilieclkegafohackmhffbmdpko [2013-12-22]
HKU\S-1-5-21-3644864302-3415500735-3647736944-1000\...\MountPoints2: F - F:\Autorun.exe
Task: {91A2ACE7-31D7-4D76-9345-53940D527CA9} - \DTReg No Task File
End
*****************

C:\Users\Marija\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlgdloilieclkegafohackmhffbmdpko => Moved successfully.
HKU\S-1-5-21-3644864302-3415500735-3647736944-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\S-1-5-21-3644864302-3415500735-3647736944-1000 => Key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{91A2ACE7-31D7-4D76-9345-53940D527CA9} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{91A2ACE7-31D7-4D76-9345-53940D527CA9} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DTReg => Key deleted successfully.

==== End of Fixlog ====

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Dobro izgleda.

Zoek obrisi rucno i odradi sledece.

Sledeća procedura će implementirati završno čišćenje.

Arrow Preuzmi "Xplode"-ov DelFix alat i snimi ga na Desktop.
Dvoklikom pokreni alat i štikliraj kućice ispred sledećih opcija;

Remove disinfection tools
Create registry backup
Purge System Restore


Klikni na dugme Run i pričekaj trenutak dok alat ne završi svoj rad.
Od ovog trenutka, svi korišćeni alati u ovoj temi bi trebali biti obrisani.
Alat će takođe formirati izveštaj za tebe. (C:\DelFix.txt)

Alat će snimiti i zdravo stanje registy-ja i napraviti backup koristeci integrisan program "ERUNT" u %windir%\ERUNT\DelFix
Alat briše stare system restore tačke i pravi novu, svežu tačku nakon čišćenja.



Idea Preporucujem ti da koristiš program MCShield za zaštitu USB memorijskih uredaja.

Nakon instalacije programa, prikljuci USB memorijske uredaje, koji ce automatski biti skenirani.
Na kraju skeniranja dobices izveštaj da je uredaj cist ili obaveštenje o uklonjenom malware-u.




Arrow

U vezi gasenja racunara jedno pitanje. Da li je nekad otvaran i ciscen od prasine, po logovima rekao bih da se radi o desktop racunaru?

offline
  • Pridružio: 29 Mar 2014
  • Poruke: 6
  • Gde živiš: Beograd

Da Very Happy on meni stoji otvoren xD ne znam da li moze biti do napajanja jer sam njega kupila polovno Question

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Moze biti i do napajanja i do pregrevanja.
To sto je otvoren ne mora nista da znaci, ne bi bilo lose da ga izduvas negde na kompresor, puno je to prasine veruj mi.

Ko je trenutno na forumu
 

Ukupno su 918 korisnika na forumu :: 15 registrovanih, 2 sakrivenih i 901 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: brundo65, draggan, ILGromovnik, JOntra, Koridor, kovac9mm, Krvava Devetka, kybonacci, opt1, pein, radionica1, saputnik plavetnila, TBF1D, wizzardone, šumar bk2