Izgleda da sam pokupio neki virus

Izgleda da sam pokupio neki virus

offline
  • coa93  Male
  • Zaslužni građanin
  • Pridružio: 31 Okt 2014
  • Poruke: 614

Napisano: 02 Maj 2017 14:31

Da budem iskren,ni sam ne znam kako sam pokupio neki virus.Google chrome mi sada ima neki drugi pocetni sajt(ozipcompression).Kad god otvorim neki sajt iskace mi dodatni spawn tab,opsti haos.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 01-05-2017
Ran by coa (administrator) on DESKTOP-MBT2QQ8 (02-05-2017 14:28:08)
Running from C:\Users\coa\Desktop
Loaded Profiles: coa (Available Profiles: defaultuser0 & coa)
Platform: Windows 10 Enterprise Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-t.....scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe
() C:\Program Files\ATI Technologies\ATI.ACE\a4\AdaptiveSleepService.exe
(Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.12.112.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(BitTorrent Inc.) C:\Users\coa\AppData\Roaming\BitTorrent\BitTorrent.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTAgent.exe
(Skillbrains) C:\Program Files (x86)\Skillbrains\lightshot\5.4.0.5\Lightshot.exe
(GIGABYTE Technology Co.,Ltd.) C:\Program Files (x86)\GIGABYTE\XTREME GAMING ENGINE\Xtreme.exe
(BitTorrent Inc.) C:\Users\coa\AppData\Roaming\BitTorrent\updates\7.9.9_43389\bittorrentie.exe
(BitTorrent Inc.) C:\Users\coa\AppData\Roaming\BitTorrent\updates\7.9.9_43389\bittorrentie.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.214.10010.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8899592 2016-08-19] (Realtek Semiconductor)
HKLM\...\Run: [StartCN] => C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe [8027016 2016-11-21] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [225944 2016-07-11] ()
HKU\S-1-5-21-3300525602-279851040-2939320548-1001\...\Run: [BitTorrent] => C:\Users\coa\AppData\Roaming\BitTorrent\BitTorrent.exe [2239176 2017-03-19] (BitTorrent Inc.)
HKU\S-1-5-21-3300525602-279851040-2939320548-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4959424 2016-11-21] (Disc Soft Ltd)
HKU\S-1-5-21-3300525602-279851040-2939320548-1001\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3046264 2017-04-10] (Electronic Arts)
HKU\S-1-5-21-3300525602-279851040-2939320548-1001\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [225816 2017-03-03] (BlueStack Systems, Inc.)
HKU\S-1-5-21-3300525602-279851040-2939320548-1001\...\MountPoints2: {f606d3dd-0e6e-11e7-a049-38d54715fb77} - "F:\setup.exe"
Startup: C:\Users\coa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GIGABYTE AORUS GRAPHICS ENGINE.lnk [2017-03-19]
ShortcutTarget: GIGABYTE AORUS GRAPHICS ENGINE.lnk -> C:\Program Files (x86)\GIGABYTE\AORUS GRAPHICS ENGINE\autorun.exe (No File)
Startup: C:\Users\coa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GIGABYTE XTREME GAMING ENGINE.lnk [2017-03-20]
ShortcutTarget: GIGABYTE XTREME GAMING ENGINE.lnk -> C:\Program Files (x86)\GIGABYTE\XTREME GAMING ENGINE\autorun.exe ()
GroupPolicy: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

AutoConfigURL: [S-1-5-21-3300525602-279851040-2939320548-1001] => hxxp://webaccesses.net/wpad.dat?8a04d5e42257160139d97586fee4bfc229342771
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 0.0.0.0
Tcpip\..\Interfaces\{34792887-c6c0-4d64-8c0c-4d74c1db830e}: [DhcpNameServer] 192.168.1.1 0.0.0.0
ManualProxies: 0hxxp://webaccesses.net/wpad.dat?8a04d5e42257160139d97586fee4bfc229342771

Internet Explorer:
==================
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-04-29] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-04-29] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2017-04-29] (Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2017-04-29] (Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-04-29] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-04-29] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-04-29] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-04-29] (Microsoft Corporation)

FireFox:
========
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2017-03-19] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-03-19] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)

Chrome:
=======
CHR Profile: C:\Users\coa\AppData\Local\Google\Chrome\User Data\Default [2017-05-02]
CHR Extension: (Google Slides) - C:\Users\coa\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-03-19]
CHR Extension: (Google Docs) - C:\Users\coa\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-03-19]
CHR Extension: (Google Drive) - C:\Users\coa\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-03-19]
CHR Extension: (YouTube) - C:\Users\coa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-03-19]
CHR Extension: (Adblock Plus) - C:\Users\coa\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2017-03-22]
CHR Extension: (Google Sheets) - C:\Users\coa\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-03-19]
CHR Extension: (Google Docs Offline) - C:\Users\coa\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-03-19]
CHR Extension: (Chrome Web Store Payments) - C:\Users\coa\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-19]
CHR Extension: (Gmail) - C:\Users\coa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-03-19]
CHR Extension: (Chrome Media Router) - C:\Users\coa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-03-19]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdaptiveSleepService; C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe [155016 2016-11-21] ()
S3 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [428056 2017-03-03] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [406040 2017-03-03] (BlueStack Systems, Inc.)
S3 BstHdPlusAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Plus-Service.exe [452632 2017-03-03] (BlueStack Systems, Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3801280 2017-04-19] (Microsoft Corporation)
S3 cplspcon; C:\Windows\system32\IntelCpHDCPSvc.exe [439800 2016-06-03] (Intel Corporation)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [1472704 2016-11-21] (Disc Soft Ltd)
R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [365048 2016-06-03] (Intel Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2147216 2017-04-10] (Electronic Arts)
R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3116440 2017-04-10] (Electronic Arts)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2016-07-16] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [49448 2016-08-18] (Advanced Micro Devices, Inc.)
R3 amdkmdag; C:\Windows\System32\DriverStore\FileRepository\c0313248.inf_amd64_aad49543f8f714a1\atikmdag.sys [36556696 2017-04-14] (Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\Windows\System32\DriverStore\FileRepository\c0313248.inf_amd64_aad49543f8f714a1\atikmpag.sys [528792 2017-04-14] (Advanced Micro Devices, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWT6.sys [101376 2016-12-08] (Advanced Micro Devices)
R3 atillk64; C:\Program Files (x86)\GIGABYTE\XTREME GAMING ENGINE\AtiTool\atillk64.sys [14608 2006-07-19] (ATI Technologies Inc.)
S3 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [152672 2017-03-03] (BlueStack Systems)
S3 BstkDrv; C:\Program Files (x86)\BlueStacks\BstkDrv.sys [270904 2017-03-03] (Bluestack System Inc. )
S3 cpuz140; C:\Users\coa\AppData\Local\Temp\cpuz140\cpuz140_x64.sys [45888 2017-04-08] (CPUID) <==== ATTENTION
S3 cpuz143; C:\Users\coa\AppData\Local\Temp\cpuz143\cpuz143_x64.sys [48952 2017-04-24] (CPUID) <==== ATTENTION
R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2017-03-19] (Disc Soft Ltd)
R3 dtliteusbbus; C:\Windows\System32\drivers\dtliteusbbus.sys [47672 2017-03-19] (Disc Soft Ltd)
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO64A.SYS [27552 2017-03-19] (REALiX(tm))
S3 NetAdapterCx; C:\Windows\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [589824 2016-07-16] (Realtek )
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-05-02 14:28 - 2017-05-02 14:28 - 00013484 _____ C:\Users\coa\Desktop\FRST.txt
2017-05-02 14:27 - 2017-05-02 14:28 - 00000000 ____D C:\FRST
2017-05-02 14:27 - 2017-05-02 14:27 - 02428416 _____ (Farbar) C:\Users\coa\Desktop\FRST64.exe
2017-05-02 09:00 - 2017-05-02 11:26 - 00000000 ____D C:\Users\coa\AppData\LocalLow\BitTorrent
2017-05-01 19:35 - 2017-05-01 19:36 - 00414140 _____ C:\Windows\Minidump\050117-23640-01.dmp
2017-05-01 19:19 - 2017-05-01 19:20 - 00414140 _____ C:\Windows\Minidump\050117-25984-01.dmp
2017-04-27 22:12 - 2017-04-27 22:12 - 00414012 _____ C:\Windows\Minidump\042717-20640-01.dmp
2017-04-27 12:19 - 2017-04-27 12:19 - 00000000 ____D C:\Users\coa\AppData\LocalLow\Temp
2017-04-26 20:35 - 2017-04-26 20:35 - 00000000 ____D C:\Users\Public\Documents\Steam
2017-04-26 20:35 - 2017-04-26 20:35 - 00000000 ____D C:\Users\coa\Documents\My Games
2017-04-24 13:29 - 2017-04-24 13:29 - 00405380 _____ C:\Windows\Minidump\042417-20656-01.dmp
2017-04-24 13:11 - 2017-04-24 13:11 - 00000000 ____D C:\Windows\LastGood
2017-04-23 21:35 - 2017-04-23 21:35 - 00000000 ____D C:\Users\coa\AppData\Local\drmingw
2017-04-23 21:35 - 2017-04-23 21:35 - 00000000 ____D C:\ProgramData\dbg
2017-04-23 21:09 - 2017-04-23 21:09 - 00000000 ____D C:\Users\coa\AppData\Local\4kdownload.com
2017-04-23 21:08 - 2017-04-23 21:08 - 00001333 _____ C:\Users\coa\Desktop\4K Video Downloader.lnk
2017-04-23 21:08 - 2017-04-23 21:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4K Download
2017-04-23 21:08 - 2017-04-23 21:08 - 00000000 ____D C:\Program Files (x86)\4KDownload
2017-04-17 18:08 - 2017-04-17 18:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightshot
2017-04-14 21:53 - 2017-04-14 21:53 - 00001644 _____ C:\Users\Public\Desktop\BlueStacks.lnk
2017-04-14 21:53 - 2017-04-14 21:53 - 00001644 _____ C:\ProgramData\Microsoft\Windows\Start Menu\BlueStacks.lnk
2017-04-14 21:52 - 2017-04-14 21:53 - 00000000 ____D C:\Program Files (x86)\BlueStacks
2017-04-14 21:52 - 2017-03-03 19:40 - 00000000 ____D C:\ProgramData\BlueStacks
2017-04-14 21:32 - 2017-04-14 21:32 - 01040792 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxx.dll
2017-04-14 21:31 - 2017-04-14 21:31 - 00121240 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2017-04-14 21:31 - 2017-04-14 21:31 - 00112024 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2017-04-14 12:12 - 2017-04-14 12:12 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2017-04-14 01:44 - 2017-04-14 01:44 - 00120368 _____ C:\Windows\system32\kapp_ci.sbin
2017-04-09 20:36 - 2017-04-24 19:55 - 00000000 ____D C:\Users\coa\AppData\LocalLow\AMD
2017-04-09 20:27 - 2017-04-09 20:27 - 00000000 ____D C:\Windows\LastGood.Tmp
2017-04-08 14:19 - 2017-04-08 14:19 - 00000000 ____D C:\Users\coa\Documents\BioWare
2017-04-05 20:32 - 2017-04-25 18:13 - 00000000 ____D C:\Users\coa\Desktop\while
2017-04-03 19:52 - 2017-04-14 21:33 - 00924568 _____ (AMD) C:\Windows\system32\coinst_17.10.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-05-02 14:27 - 2017-03-26 21:46 - 00000000 ____D C:\Users\coa\Downloads\pes 2017 patch
2017-05-02 14:26 - 2017-03-19 10:44 - 00000000 ____D C:\Users\coa\AppData\Roaming\BitTorrent
2017-05-02 14:23 - 2017-03-19 17:00 - 00000000 ____D C:\Windows\system32\SleepStudy
2017-05-02 11:26 - 2017-03-19 10:56 - 00003472 _____ C:\Windows\System32\Tasks\Launcher GIGABYTE XTREME GAMING ENGINE
2017-05-02 11:26 - 2017-03-19 10:51 - 00000000 ____D C:\Users\coa\Documents\temp
2017-05-02 11:25 - 2017-03-19 13:38 - 00000000 __SHD C:\Users\coa\IntelGraphicsProfiles
2017-05-02 11:25 - 2017-03-19 10:36 - 00000180 _____ C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-05-02 09:02 - 2017-03-21 00:06 - 00000000 ____D C:\Program Files (x86)\Origin
2017-05-01 22:00 - 2017-03-19 10:08 - 00000000 ____D C:\Users\coa
2017-05-01 19:35 - 2017-03-21 05:13 - 713066735 _____ C:\Windows\MEMORY.DMP
2017-05-01 19:35 - 2017-03-21 05:13 - 00000000 ____D C:\Windows\Minidump
2017-05-01 19:35 - 2017-03-19 17:00 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-05-01 19:17 - 2017-04-01 09:29 - 00000000 ____D C:\ProgramData\BlueStacksSetup
2017-04-29 20:42 - 2016-07-16 13:47 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-04-29 20:41 - 2017-03-19 19:29 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2017-04-28 18:58 - 2017-03-19 10:18 - 00003416 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2017-04-28 18:58 - 2017-03-19 10:18 - 00003292 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2017-04-27 20:07 - 2017-03-19 10:08 - 00000000 ____D C:\Users\coa\AppData\Local\Packages
2017-04-24 19:52 - 2017-03-19 10:28 - 00065536 _____ C:\Windows\system32\spu_storage.bin
2017-04-24 19:52 - 2016-07-16 08:04 - 00262144 _____ C:\Windows\system32\config\BBI
2017-04-24 13:33 - 2017-03-19 10:11 - 01204714 _____ C:\Windows\system32\PerfStringBackup.INI
2017-04-24 13:11 - 2016-07-16 13:45 - 00000000 ____D C:\Windows\INF
2017-04-24 13:02 - 2017-03-19 10:28 - 00000000 ____D C:\AMD
2017-04-24 00:42 - 2017-03-21 00:07 - 00000000 ____D C:\Users\coa\AppData\Roaming\Origin
2017-04-24 00:42 - 2017-03-20 23:39 - 00000000 ____D C:\ProgramData\Origin
2017-04-22 09:20 - 2017-03-20 23:27 - 00000416 _____ C:\Windows\Tasks\update-sys.job
2017-04-22 09:20 - 2017-03-20 23:27 - 00000416 _____ C:\Windows\Tasks\update-S-1-5-21-3300525602-279851040-2939320548-1001.job
2017-04-19 19:25 - 2016-07-16 13:47 - 00000000 ____D C:\Windows\LiveKernelReports
2017-04-18 17:08 - 2017-03-20 23:27 - 00003342 _____ C:\Windows\System32\Tasks\update-sys
2017-04-17 18:08 - 2017-03-20 23:27 - 00003400 _____ C:\Windows\System32\Tasks\update-S-1-5-21-3300525602-279851040-2939320548-1001
2017-04-17 18:08 - 2017-03-20 23:27 - 00000424 _____ C:\Users\coa\AppData\Local\UserProducts.xml
2017-04-14 21:55 - 2017-04-01 09:43 - 00000552 _____ C:\Users\coa\AppData\Local\TroubleshooterConfig.json
2017-04-14 21:53 - 2017-04-01 09:29 - 00000000 ____D C:\Users\coa\AppData\Local\Bluestacks
2017-04-14 21:53 - 2016-07-16 13:47 - 00000000 __RHD C:\Users\Public\Libraries
2017-04-14 21:33 - 2017-03-16 07:34 - 00551832 _____ C:\Windows\system32\dgtrayicon.exe
2017-04-14 21:33 - 2017-03-16 07:34 - 00531352 _____ C:\Windows\system32\GameManager64.dll
2017-04-14 21:33 - 2017-03-16 07:34 - 00365464 _____ C:\Windows\SysWOW64\GameManager32.dll
2017-04-14 21:33 - 2017-03-16 07:34 - 00278424 _____ C:\Windows\system32\clinfo.exe
2017-04-14 21:33 - 2017-03-16 07:34 - 00276376 _____ C:\Windows\system32\hsa-thunk64.dll
2017-04-14 21:33 - 2017-03-16 07:34 - 00242072 _____ C:\Windows\SysWOW64\hsa-thunk.dll
2017-04-14 21:33 - 2017-03-16 07:34 - 00191384 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\mantle64.dll
2017-04-14 21:33 - 2017-03-16 07:34 - 00169880 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\mantleaxl64.dll
2017-04-14 21:33 - 2017-03-16 07:34 - 00167832 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atisamu64.dll
2017-04-14 21:33 - 2017-03-16 07:34 - 00150936 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\mantle32.dll
2017-04-14 21:33 - 2017-03-16 07:34 - 00135064 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\mantleaxl32.dll
2017-04-14 21:33 - 2017-03-16 07:34 - 00133528 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atisamu32.dll
2017-04-14 21:33 - 2017-03-15 20:37 - 00546712 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Rapidfire64.dll
2017-04-14 21:33 - 2017-03-15 20:37 - 00478104 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\Rapidfire.dll
2017-04-14 21:33 - 2017-03-15 20:37 - 00044952 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\RapidFireServer64.dll
2017-04-14 21:33 - 2017-03-15 20:37 - 00042392 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\RapidFireServer.dll
2017-04-14 21:33 - 2017-03-15 20:37 - 00029080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\detoured.dll
2017-04-14 21:33 - 2017-03-15 20:37 - 00029080 _____ (Microsoft Corporation) C:\Windows\system32\detoured.dll
2017-04-14 21:32 - 2017-03-16 07:34 - 01516440 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiadlxx.dll
2017-04-14 21:32 - 2017-03-16 07:34 - 01040792 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll
2017-04-14 21:32 - 2017-03-16 07:34 - 00777112 _____ (AMD) C:\Windows\system32\atieclxx.exe
2017-04-14 21:32 - 2017-03-16 07:34 - 00551832 _____ (AMD) C:\Windows\system32\atiesrxx.exe
2017-04-14 21:32 - 2017-03-16 07:34 - 00483736 _____ C:\Windows\system32\atieah64.exe
2017-04-14 21:32 - 2017-03-16 07:34 - 00467352 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atidemgy.dll
2017-04-14 21:32 - 2017-03-16 07:34 - 00411032 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiapfxx.exe
2017-04-14 21:32 - 2017-03-16 07:34 - 00334232 _____ C:\Windows\SysWOW64\atieah32.exe
2017-04-14 21:32 - 2017-03-16 07:34 - 00245144 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6txx.dll
2017-04-14 21:32 - 2017-03-16 07:34 - 00203672 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll
2017-04-14 21:32 - 2017-03-16 07:34 - 00156720 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\aticfx64.dll
2017-04-14 21:32 - 2017-03-16 07:34 - 00148456 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\aticfx32.dll
2017-04-14 21:32 - 2017-03-16 07:34 - 00122776 _____ (AMD) C:\Windows\system32\atimuixx.dll
2017-04-14 21:32 - 2017-03-16 07:34 - 00115096 _____ C:\Windows\system32\atidxx64.dll
2017-04-14 21:32 - 2017-03-16 07:34 - 00101784 _____ C:\Windows\SysWOW64\atidxx32.dll
2017-04-14 21:32 - 2017-03-16 07:34 - 00069016 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\ati2erec.dll
2017-04-14 21:31 - 2017-03-16 07:34 - 10320280 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdvlk64.dll
2017-04-14 21:31 - 2017-03-16 07:34 - 08479128 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdvlk32.dll
2017-04-14 21:31 - 2017-03-16 07:34 - 02536344 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\amfrt64.dll
2017-04-14 21:31 - 2017-03-16 07:34 - 02198424 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\amfrt32.dll
2017-04-14 21:31 - 2017-03-15 20:37 - 00112536 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdxc64.dll
2017-04-14 21:31 - 2017-03-15 20:37 - 00099224 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdxc32.dll
2017-04-14 21:30 - 2017-03-16 07:34 - 00864152 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\amdlvr64.dll
2017-04-14 21:30 - 2017-03-16 07:34 - 00696216 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\amdlvr32.dll
2017-04-14 21:30 - 2017-03-16 07:34 - 00514456 _____ C:\Windows\system32\amdgfxinfo64.dll
2017-04-14 21:30 - 2017-03-16 07:34 - 00360344 _____ C:\Windows\SysWOW64\amdgfxinfo32.dll
2017-04-14 21:30 - 2017-03-16 07:34 - 00091544 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmcl64.dll
2017-04-14 21:30 - 2017-03-16 07:34 - 00075160 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdmcl32.dll
2017-04-14 21:28 - 2017-03-16 07:34 - 00573824 _____ C:\Windows\system32\amdmiracast.dll
2017-04-14 21:28 - 2017-03-16 07:34 - 00196200 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\amdhcp64.dll
2017-04-14 21:28 - 2017-03-16 07:34 - 00164424 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\amdhcp32.dll
2017-04-14 21:28 - 2017-03-16 07:34 - 00139096 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdave64.dll
2017-04-14 21:28 - 2017-03-16 07:34 - 00131296 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atimpc64.dll
2017-04-14 21:28 - 2017-03-16 07:34 - 00131296 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdpcom64.dll
2017-04-14 21:28 - 2017-03-16 07:34 - 00116088 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdave32.dll
2017-04-14 21:28 - 2017-03-16 07:34 - 00102536 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll
2017-04-14 21:28 - 2017-03-16 07:34 - 00102536 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll
2017-04-14 01:44 - 2016-11-22 01:55 - 00791456 _____ C:\Windows\SysWOW64\atiapfxx.blb
2017-04-14 01:44 - 2016-11-22 01:55 - 00791456 _____ C:\Windows\system32\atiapfxx.blb
2017-04-14 01:44 - 2016-11-22 01:50 - 03437632 _____ C:\Windows\system32\atiumd6a.cap
2017-04-14 01:44 - 2016-11-22 01:46 - 03471376 _____ C:\Windows\SysWOW64\atiumdva.cap
2017-04-14 01:43 - 2015-12-17 01:06 - 00000144 _____ C:\Windows\system32\amd-vulkan64.json
2017-04-14 01:43 - 2015-12-15 21:54 - 00000144 _____ C:\Windows\SysWOW64\amd-vulkan32.json
2017-04-09 20:26 - 2017-03-19 13:35 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2017-04-09 20:21 - 2017-03-19 10:28 - 00000000 ____D C:\ProgramData\Package Cache
2017-04-09 20:17 - 2017-03-20 14:59 - 00000975 _____ C:\Users\Public\Desktop\CPUID HWMonitor.lnk
2017-04-06 10:58 - 2017-03-19 10:26 - 00002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-04-06 10:58 - 2017-03-19 10:26 - 00002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-04-05 20:44 - 2017-03-19 10:12 - 00003286 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task v2
2017-04-05 20:44 - 2017-03-19 10:10 - 00002357 _____ C:\Users\coa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-04-05 20:44 - 2017-03-19 10:10 - 00000000 ___RD C:\Users\coa\OneDrive

==================== Files in the root of some directories =======

2017-04-01 09:43 - 2017-04-14 21:55 - 0000552 _____ () C:\Users\coa\AppData\Local\TroubleshooterConfig.json
2017-03-20 23:27 - 2017-03-20 23:27 - 0000003 _____ () C:\Users\coa\AppData\Local\updater.log
2017-03-20 23:27 - 2017-04-17 18:08 - 0000424 _____ () C:\Users\coa\AppData\Local\UserProducts.xml
2017-03-19 10:18 - 2017-03-19 10:18 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Some files in TEMP:
====================
2017-04-25 08:22 - 2017-04-25 08:22 - 0061440 _____ () C:\Users\coa\AppData\Local\Temp\e1dx-1th.dll
2017-04-14 21:51 - 2017-03-03 19:38 - 0897560 _____ (BlueStack Systems, Inc.) C:\Users\coa\AppData\Local\Temp\HD-Common.dll
2017-04-14 21:51 - 2017-03-03 19:39 - 0516120 _____ (BlueStack Systems, Inc.) C:\Users\coa\AppData\Local\Temp\HD-InstallerUtils.dll
2017-04-14 21:51 - 2017-03-03 19:29 - 0187416 _____ (BlueStack Systems) C:\Users\coa\AppData\Local\Temp\HD-LibraryHandler.dll
2017-04-14 21:51 - 2017-03-03 19:27 - 0246808 _____ (BlueStack Systems) C:\Users\coa\AppData\Local\Temp\HD-Logger-Native.dll
2017-04-14 21:51 - 2017-03-03 19:38 - 0426008 _____ (BlueStack Systems, Inc.) C:\Users\coa\AppData\Local\Temp\HD-Uninstaller.exe
2017-04-25 12:31 - 2017-04-25 12:31 - 0061440 _____ () C:\Users\coa\AppData\Local\Temp\kzffnlt8.dll
2017-04-01 18:16 - 2017-04-01 18:16 - 0061440 _____ () C:\Users\coa\AppData\Local\Temp\vgmao2fq.dll

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-04-27 12:24

==================== End of FRST.txt ============================
https://www.mycity.rs/must-login.png

Dopuna: 02 Maj 2017 14:33

S vremena na vreme racunar izbaci neku gresku da windows ne radi dobro i da racunar treba da se restartuje

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Otvori Notepad i iskopiraj sljedeći tekst koji se nalazi unutar Kod polja.

GroupPolicy: Restriction <======= ATTENTION
AutoConfigURL: [S-1-5-21-3300525602-279851040-2939320548-1001] => hxxp://webaccesses.net/wpad.dat?8a04d5e42257160139d97586fee4bfc229342771
ManualProxies: 0hxxp://webaccesses.net/wpad.dat?8a04d5e42257160139d97586fee4bfc229342771
C:\Users\coa\AppData\Local\Temp\kzffnlt8.dll
C:\Users\coa\AppData\Local\Temp\vgmao2fq.dll
C:\Users\coa\AppData\Local\Temp\e1dx-1th.dll
EmptyTemp:


U okviru Notepad-a klikni na File --> Save As
Pod Encoding izaberi UTF-8.
Fajl nazovi Fixlist i sačuvaj na Desktop
Dvoklikom ponovo pokreni FRST.exe
Klikni na Fix i sačekaj dok program ne završi.
Ukoliko program zatraži restart računara, omogući mu da to nesmetano obavi.
Nakon završetka rada, otvoriće se fixlog.txt, sa sadržajem koji treba da kopiraš u temu.
Takođe, na Desktop-u će se nalaziti (fixlog.txt).

offline
  • coa93  Male
  • Zaslužni građanin
  • Pridružio: 31 Okt 2014
  • Poruke: 614

Fix result of Farbar Recovery Scan Tool (x64) Version: 03-05-2017
Ran by coa (03-05-2017 19:25:17) Run:1
Running from C:\Users\coa\Desktop
Loaded Profiles: coa (Available Profiles: defaultuser0 & coa)
Boot Mode: Normal
==============================================

fixlist content:
*****************
GroupPolicy: Restriction <======= ATTENTION
AutoConfigURL: [S-1-5-21-3300525602-279851040-2939320548-1001] => hxxp://webaccesses.net/wpad.dat?8a04d5e42257160139d97586fee4bfc229342771
ManualProxies: 0hxxp://webaccesses.net/wpad.dat?8a04d5e42257160139d97586fee4bfc229342771
C:\Users\coa\AppData\Local\Temp\kzffnlt8.dll
C:\Users\coa\AppData\Local\Temp\vgmao2fq.dll
C:\Users\coa\AppData\Local\Temp\e1dx-1th.dll
EmptyTemp:
*****************

C:\Windows\system32\GroupPolicy\Machine => moved successfully
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
HKU\S-1-5-21-3300525602-279851040-2939320548-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\AutoConfigURL => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies\\ => value removed successfully
C:\Users\coa\AppData\Local\Temp\kzffnlt8.dll => moved successfully
C:\Users\coa\AppData\Local\Temp\vgmao2fq.dll => moved successfully
C:\Users\coa\AppData\Local\Temp\e1dx-1th.dll => moved successfully

=========== EmptyTemp: ==========

BITS transfer queue => 3379008 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 24534445 B
Java, Flash, Steam htmlcache => 705 B
Windows/system/drivers => 23322209 B
Edge => 1327869 B
Chrome => 403079520 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 894014 B
LocalService => 17222 B
NetworkService => 3426 B
defaultuser0 => 7296 B
coa => 1269077815 B

RecycleBin => 50314431 B
EmptyTemp: => 1.7 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 19:25:37 ====

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Arrow

Kakvo je sad stanje sistema?



Arrow

Spakuj u ZIP, RAR ili 7Z arhivu sljedeći folder:

C:\FRST\Quarantine

i pošalji ga preko sljedećeg linka:

http://www.mycity.rs/ambulanta-upload.php

offline
  • coa93  Male
  • Zaslužni građanin
  • Pridružio: 31 Okt 2014
  • Poruke: 614

Napisano: 04 Maj 2017 12:29

Dopuna: 04 Maj 2017 12:33

Koliko sam uspeo da primetim,sredjen je search i pocetna strana,ali mi i dalje izbacuje reklamu sa sajt viid.me

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Trebalo je da arhivu postaviš preko linka kojeg sam ti dao.

Očisti keš u Chrome-u.
Postavi mi nove FRST izvještaje.

Ko je trenutno na forumu
 

Ukupno su 872 korisnika na forumu :: 44 registrovanih, 5 sakrivenih i 823 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 357magnum, 8u47, airsuba, amaterSRB, Apok, babaroga, bankulen, bojcistv, Brana01, darkangel, dekan.m, delrey, Denaya, Dimitrise93, djboj, doklevise, DonRumataEstorski, Dovla, GORDI, Grah0, Istman, Kubovac, kunktator, laganini123, mercedesamg, Mercury, Metanoja, Milos ZA, Mixelotti, mnn2, novator, opt1, ozzy, pein, Polemarchoi, Rogonos, ruma, Sančo, slonic_tonic, Srle993, Tores, tubular, vlajkox, wolf431