Kako izbrisati Wondershare?

Kako izbrisati Wondershare?

offline
  • Istrazivanje Windowsa
  • Pridružio: 12 Jul 2012
  • Poruke: 1023

Pozdrav ljudi! Imam problem sa nekim programom Wondershare. Dok su mi ukucani bili na racunaru, nekako su uspeli skinuti i instalirati program ''Wondershare''. Izbrisao sam ga, medjutim njegove stavke su ostale i mozete da ih vidite i u ovim FRST logovima. Koristio sam i adware cleaner medjutim on nikada nije uspeo da ga potpuno obrise.

Ne znam kako su uspeli da ga skinu a navodno su samo gledali film.

Evo izvestaja FRST:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 04.03.2018
Ran by Stefan (administrator) on STEFAN (08-03-2018 11:40:53)
Running from C:\Users\Stefan\Downloads
Loaded Profiles: Stefan (Available Profiles: Stefan)
Platform: Windows 10 Home Version 1703 (X64) Language: English (United Kingdom)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: [Link mogu videti samo ulogovani korisnici]

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9217024 2017-04-13] (Realtek Semiconductor)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-03-15] (Oracle Corporation)
HKLM-x32\...\Run: [Aimersoft Helper Compact.exe] => C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe [2138272 2016-10-08] (AimerSoft)
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-3845861192-373603742-3298966185-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [10024624 2017-11-08] (Piriform Ltd)
HKU\S-1-5-21-3845861192-373603742-3298966185-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3102496 2017-10-31] (Valve Corporation)
HKU\S-1-5-21-3845861192-373603742-3298966185-1001\...\MountPoints2: D - "D:\ResidentEvil3_menu.exe"
HKU\S-1-5-21-3845861192-373603742-3298966185-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\SysWOW64\launcher.scr
HKU\S-1-5-18\...\Run: [Samsung.PCSync] => "C:\Program Files (x86)\Samsung\Samsung PC Studio 7\PcSync2.exe" /NoDialog

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{0ce1500c-317b-467d-86f3-e4409f86db53}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\ssv.dll [2017-04-29] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-04-29] (Oracle Corporation)

FireFox:
========
FF DefaultProfile: 4lveho68.default
FF ProfilePath: C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\4lveho68.default [2018-03-08]
FF Homepage: Mozilla\Firefox\Profiles\4lveho68.default -> [Link mogu videti samo ulogovani korisnici]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_27_0_0_183.dll [2017-11-01] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_183.dll [2017-11-01] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-04-29] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-04-29] (Oracle Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-11-14] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-11-14] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-12-05] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-12-05] (Google Inc.)

Chrome:
=======
CHR Profile: C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default [2018-03-08]
CHR Extension: (Google Drive) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-04-29]
CHR Extension: (YouTube) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-04-29]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-24]
CHR Extension: (Gmail) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-04-29]
CHR Extension: (Chrome Media Router) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-02-27]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S4 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [518264 2017-11-14] (NVIDIA Corporation)
S4 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [518264 2017-11-14] (NVIDIA Corporation)
R2 osrss; C:\Windows\system32\osrss.dll [108584 2018-01-18] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-03-18] (Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
S4 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r
S4 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.4.3.231\WsAppService.exe [X]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_c791f781cd94491f\nvlddmkm.sys [16989296 2017-11-15] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30328 2017-11-14] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [50808 2017-11-14] (NVIDIA Corporation)
R3 nvvhci; C:\Windows\System32\drivers\nvvhci.sys [57976 2017-11-14] (NVIDIA Corporation)
U5 PROCMON23; C:\Windows\System32\Drivers\PROCMON23.sys [92992 2017-09-20] (Sysinternals - [Link mogu videti samo ulogovani korisnici])
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [604160 2017-03-18] (Realtek )
S3 SDFRd; C:\Windows\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-03-08 11:40 - 2018-03-08 11:41 - 000008731 _____ C:\Users\Stefan\Downloads\FRST.txt
2018-03-08 11:40 - 2018-03-08 11:40 - 000000000 ____D C:\FRST
2018-03-08 11:39 - 2018-03-08 11:39 - 002403328 _____ (Farbar) C:\Users\Stefan\Downloads\FRST64.exe
2018-03-06 16:25 - 2018-03-06 16:26 - 000000000 ____D C:\Users\Stefan\Desktop\New folder (7)
2018-03-03 22:45 - 2018-03-03 22:45 - 000000000 ____D C:\Program Files (x86)\Age of empires
2018-02-28 00:52 - 2018-02-28 01:29 - 000000000 ____D C:\Users\Stefan\Desktop\New folder (6)
2018-02-27 18:29 - 2018-02-27 18:33 - 000000000 ____D C:\Program Files (x86)\iSkysoft
2018-02-27 18:29 - 2018-02-27 18:29 - 000000000 ____D C:\Users\Stefan\AppData\Local\Wondershare
2018-02-27 18:28 - 2018-02-27 18:29 - 000000000 ____D C:\Users\Public\Documents\iSkysoft
2018-02-22 04:51 - 2018-02-22 04:51 - 000000000 ____D C:\Users\Stefan\AppData\Local\ASHelper
2018-02-21 20:46 - 2018-02-21 20:47 - 000000000 ____D C:\Users\Stefan\AppData\Roaming\HandBrake
2018-02-21 20:46 - 2018-02-21 20:46 - 000000000 ____D C:\Users\Stefan\AppData\Roaming\HandBrake Team
2018-02-21 20:39 - 2018-02-21 20:42 - 000000000 ____D C:\Users\Stefan\AppData\Roaming\KeepVid
2018-02-21 20:39 - 2018-02-21 20:42 - 000000000 ____D C:\Program Files (x86)\Keepvid
2018-02-21 20:39 - 2018-02-21 20:39 - 000000000 ____D C:\Users\Stefan\AppData\Local\KeepVid
2018-02-21 20:39 - 2018-02-21 20:39 - 000000000 ____D C:\Users\Stefan\AppData\Local\Aimersoft
2018-02-21 20:39 - 2018-02-21 20:39 - 000000000 ____D C:\ProgramData\KeepVid
2018-02-21 20:39 - 2018-02-21 20:39 - 000000000 ____D C:\ProgramData\GraphicsType
2018-02-21 20:39 - 2018-02-21 20:39 - 000000000 ____D C:\ProgramData\Aimersoft
2018-02-21 20:38 - 2018-02-21 20:39 - 000000000 ____D C:\Users\Public\Documents\Keepvid
2018-02-21 20:11 - 2018-02-21 20:13 - 000000000 ____D C:\Users\Stefan\Desktop\New folder (5)
2018-02-21 17:32 - 2018-02-21 17:41 - 000000000 ____D C:\Program Files (x86)\Gta San Andreas
2018-02-21 17:27 - 2018-02-21 17:27 - 000000000 ____D C:\Users\Stefan\Desktop\New folder (4)
2018-02-20 22:17 - 2018-02-20 22:17 - 000000000 ____D C:\Users\Stefan\Desktop\New folder (2)
2018-02-20 22:03 - 2018-02-21 18:03 - 000000000 ____D C:\Users\Stefan\Documents\GTA San Andreas User Files
2018-02-20 21:43 - 2011-04-25 09:05 - 000000000 ____D C:\Users\Stefan\Desktop\Hot_Coffee_21
2018-02-16 15:07 - 2018-02-16 15:07 - 000000279 _____ C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recycle Bin.lnk
2018-02-16 14:57 - 2018-02-16 14:57 - 000000883 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Counter-Strike WaRzOnE.lnk
2018-02-15 16:57 - 2018-02-15 16:57 - 000000000 ____D C:\Windows\system32\MRT
2018-02-15 16:56 - 2018-02-15 16:57 - 130067560 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2018-02-15 16:56 - 2018-02-15 16:56 - 130067560 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-02-15 16:56 - 2018-01-18 01:05 - 000108584 _____ (Microsoft Corporation) C:\Windows\system32\osrss.dll
2018-02-15 16:56 - 2017-10-17 06:11 - 001578904 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2018-02-15 16:56 - 2017-10-17 06:10 - 002032536 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2018-02-15 16:56 - 2017-10-17 06:10 - 000678808 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2018-02-15 16:56 - 2017-10-17 06:10 - 000613784 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2018-02-15 16:56 - 2017-10-17 06:10 - 000484248 _____ (Microsoft Corporation) C:\Windows\system32\dcntel.dll
2018-02-15 16:56 - 2017-10-17 06:10 - 000379288 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2018-02-15 16:56 - 2017-10-17 06:10 - 000190360 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2018-02-15 16:56 - 2017-10-17 06:10 - 000136088 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2018-02-15 16:56 - 2017-10-17 06:10 - 000067992 _____ (Microsoft Corporation) C:\Windows\system32\win32appinventorycsp.dll
2018-02-15 16:56 - 2017-10-17 06:10 - 000034712 _____ (Microsoft Corporation) C:\Windows\system32\DeviceCensus.exe
2018-02-15 16:56 - 2017-10-17 06:05 - 000503704 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2018-02-15 16:56 - 2017-10-17 06:04 - 000612248 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2018-02-15 16:55 - 2018-02-15 16:55 - 000000000 ____H C:\ProgramData\DP45977C.lfl
2018-02-15 16:55 - 2018-02-15 16:55 - 000000000 ____D C:\Windows\SysWOW64\RTCOM
2018-02-15 16:55 - 2018-02-15 16:55 - 000000000 ____D C:\Windows\system32\DAX3
2018-02-15 16:55 - 2018-02-15 16:55 - 000000000 ____D C:\Windows\system32\DAX2
2018-02-15 16:55 - 2018-02-15 16:55 - 000000000 ____D C:\Program Files\Realtek
2018-02-15 01:35 - 2018-02-15 01:35 - 000000000 ____D C:\Users\Stefan\AppData\Roaming\Need for Speed World
2018-02-15 01:27 - 2018-02-15 01:27 - 000000000 ____D C:\ProgramData\Caphyon
2018-02-15 01:26 - 2018-02-15 01:26 - 000000000 ____D C:\Users\Stefan\AppData\Roaming\Appveyor
2018-02-14 20:16 - 2018-02-14 20:16 - 000000000 ____D C:\Program Files (x86)\Sigma Production Inc
2018-02-14 04:44 - 2018-02-15 16:56 - 000000000 ____D C:\Program Files\rempl
2018-02-14 04:44 - 2018-01-01 02:41 - 000087040 _____ (Microsoft Corporation) C:\Windows\system32\usoapi.dll
2018-02-14 04:44 - 2018-01-01 02:40 - 000378880 _____ (Microsoft Corporation) C:\Windows\system32\MusNotification.exe
2018-02-14 04:44 - 2018-01-01 02:40 - 000052736 _____ (Microsoft Corporation) C:\Windows\system32\musdialoghandlers.dll
2018-02-14 04:44 - 2018-01-01 02:39 - 000204800 _____ (Microsoft Corporation) C:\Windows\system32\MusNotificationUx.exe
2018-02-14 04:44 - 2018-01-01 02:38 - 000739840 _____ (Microsoft Corporation) C:\Windows\system32\MusUpdateHandlers.dll
2018-02-14 04:44 - 2018-01-01 02:35 - 000060928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usoapi.dll
2018-02-14 04:44 - 2018-01-01 02:30 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\usocore.dll
2018-02-14 04:44 - 2017-11-02 06:12 - 000026472 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2018-02-14 04:44 - 2017-11-02 05:35 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2018-02-14 04:44 - 2017-11-02 05:34 - 000113152 _____ (Microsoft Corporation) C:\Windows\system32\wuuhosdeployment.dll
2018-02-14 04:44 - 2017-11-02 05:34 - 000095232 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2018-02-14 04:44 - 2017-11-02 05:34 - 000033792 _____ (Microsoft Corporation) C:\Windows\system32\wuautoappupdate.dll
2018-02-14 04:44 - 2017-11-02 05:30 - 000165888 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2018-02-14 04:44 - 2017-11-02 05:29 - 000415232 _____ (Microsoft Corporation) C:\Windows\system32\updatehandlers.dll
2018-02-14 04:44 - 2017-11-02 05:27 - 000079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2018-02-14 04:44 - 2017-11-02 05:26 - 000986624 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2018-02-14 04:44 - 2017-11-02 05:23 - 002449408 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2018-02-14 04:44 - 2017-11-02 05:23 - 000407040 _____ (Microsoft Corporation) C:\Windows\system32\wuuhext.dll
2018-02-14 04:44 - 2017-11-02 05:21 - 000787456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2018-02-14 04:44 - 2017-09-29 08:40 - 000086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\updatepolicy.dll
2018-02-14 04:44 - 2017-09-29 08:29 - 000102912 _____ (Microsoft Corporation) C:\Windows\system32\updatepolicy.dll
2018-02-14 04:44 - 2017-09-29 08:28 - 000256000 _____ (Microsoft Corporation) C:\Windows\system32\domgmt.dll
2018-02-14 04:44 - 2017-09-29 08:24 - 001307648 _____ (Microsoft Corporation) C:\Windows\system32\dosvc.dll
2018-02-14 04:44 - 2017-07-28 05:19 - 000417792 _____ (Microsoft Corporation) C:\Windows\system32\InstallAgentUserBroker.exe
2018-02-14 04:44 - 2017-07-28 05:16 - 000383488 _____ (Microsoft Corporation) C:\Windows\system32\InstallAgent.exe
2018-02-14 04:44 - 2017-07-28 05:14 - 000368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallAgentUserBroker.exe
2018-02-14 04:44 - 2017-07-28 05:12 - 000337920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallAgent.exe
2018-02-14 04:44 - 2017-05-20 09:20 - 000807424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StoreAgent.dll
2018-02-14 04:44 - 2017-05-20 07:00 - 001078272 _____ (Microsoft Corporation) C:\Windows\system32\StoreAgent.dll
2018-02-07 16:49 - 2018-02-07 17:24 - 000000000 ____D C:\Users\Stefan\AppData\Roaming\audacity
2018-02-07 16:49 - 2018-02-07 16:49 - 000000000 ____D C:\Users\Stefan\AppData\Local\Audacity
2018-02-06 16:41 - 2018-02-06 16:41 - 000000000 ____D C:\ProgramData\Codemasters
2018-02-06 16:39 - 2018-02-06 16:39 - 000466456 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll
2018-02-06 16:39 - 2018-02-06 16:39 - 000444952 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
2018-02-06 16:39 - 2018-02-06 16:39 - 000122904 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll
2018-02-06 16:39 - 2018-02-06 16:39 - 000109080 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
2018-02-06 16:39 - 2018-02-06 16:39 - 000000000 ____D C:\Program Files (x86)\OpenAL
2018-02-06 14:07 - 2018-02-06 14:07 - 000000000 ____D C:\Users\Stefan\AppData\Roaming\Hard Disk Sentinel
2018-02-06 12:48 - 2018-02-06 12:48 - 000000000 ____D C:\Program Files\Common Files\AVG
2018-02-06 12:44 - 2018-02-06 15:18 - 000000000 ____D C:\Users\Stefan\AppData\Local\Avg
2018-02-06 12:44 - 2018-02-06 15:18 - 000000000 ____D C:\ProgramData\Avg
2018-02-06 12:44 - 2018-02-06 15:12 - 000000000 ____D C:\Users\Stefan\AppData\Local\AvgSetupLog
2018-02-06 12:44 - 2018-02-06 12:44 - 003449304 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Stefan\Downloads\AVG_Protection_Free_1606.exe

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-03-08 11:27 - 2017-04-29 19:22 - 000000000 ____D C:\Windows\system32\SleepStudy
2018-03-08 08:48 - 2017-12-30 20:15 - 000000000 ____D C:\Users\Stefan\Desktop\slike 1
2018-03-08 08:48 - 2017-05-20 17:23 - 000000000 ____D C:\Users\Stefan\Desktop\New folder
2018-03-08 01:34 - 2017-04-29 16:14 - 000000000 ____D C:\ProgramData\NVIDIA
2018-03-07 21:47 - 2017-09-25 14:57 - 000001519 _____ C:\Users\Stefan\Desktop\New Text Document (5).txt
2018-03-07 12:45 - 2017-07-02 13:38 - 000002895 _____ C:\Users\Stefan\Desktop\11.txt
2018-03-07 02:16 - 2017-04-29 19:31 - 000000000 ____D C:\Users\Stefan
2018-03-05 01:35 - 2017-04-29 15:55 - 000000000 ____D C:\Users\Stefan\AppData\Roaming\uTorrent
2018-03-04 01:57 - 2017-04-30 13:10 - 000000000 ____D C:\Users\Stefan\Desktop\Igre
2018-03-04 01:56 - 2017-03-18 22:03 - 000000000 ____D C:\Windows\AppReadiness
2018-03-03 23:03 - 2017-04-29 19:33 - 000000000 ____D C:\Users\Stefan\AppData\Local\Packages
2018-03-03 19:12 - 2018-01-21 01:18 - 000001373 _____ C:\Users\Stefan\Desktop\BioShock Remastered.lnk
2018-03-03 02:35 - 2017-06-28 22:28 - 000000000 ____D C:\Users\Stefan\Downloads\Snes9x
2018-03-02 14:46 - 2017-04-29 21:42 - 000000000 ____D C:\Users\Stefan\AppData\Local\CrashDumps
2018-03-01 17:05 - 2017-06-02 21:49 - 000000000 ____D C:\Users\Stefan\AppData\Roaming\vlc
2018-02-28 23:54 - 2018-02-04 21:10 - 000000000 ____D C:\Users\Stefan\Downloads\WoW_Legion_torrent
2018-02-28 21:59 - 2018-01-19 21:35 - 000000000 ____D C:\Users\Stefan\AppData\Local\Battle.net
2018-02-28 20:47 - 2018-01-19 21:38 - 000000000 ____D C:\Program Files (x86)\Heroes of the Storm
2018-02-28 20:46 - 2018-01-19 21:34 - 000000000 ____D C:\Program Files (x86)\Battle.net
2018-02-27 22:13 - 2017-07-18 19:15 - 000000023 _____ C:\Windows\BlendSettings.ini
2018-02-27 19:55 - 2017-07-14 12:07 - 000000000 ____D C:\AdwCleaner
2018-02-27 18:28 - 2018-01-20 01:14 - 000000000 ____D C:\Users\Stefan\AppData\Roaming\obs-studio
2018-02-27 15:37 - 2017-04-29 15:55 - 000002663 _____ C:\Users\Stefan\Desktop\µTorrent.lnk
2018-02-27 06:04 - 2017-04-29 15:24 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-02-27 06:04 - 2017-04-29 15:24 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-02-21 20:46 - 2017-12-01 21:25 - 000000000 ____D C:\Users\Public\Documents\Wondershare
2018-02-21 17:38 - 2017-04-30 21:43 - 000000000 ____D C:\Windows\SysWOW64\directx
2018-02-20 22:22 - 2017-04-30 22:15 - 000000000 ____D C:\Program Files (x86)\Mr DJ
2018-02-16 15:02 - 2017-05-20 14:48 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2018-02-16 15:01 - 2017-09-24 13:43 - 000000000 ____D C:\Games
2018-02-15 20:14 - 2017-03-18 22:03 - 000000000 ____D C:\Windows\rescache
2018-02-15 17:13 - 2017-04-29 19:30 - 001284338 _____ C:\Windows\system32\PerfStringBackup.INI
2018-02-15 17:07 - 2017-04-29 19:23 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-02-15 17:07 - 2017-03-18 12:40 - 000262144 _____ C:\Windows\system32\config\BBI
2018-02-15 16:58 - 2017-03-18 22:03 - 000000000 ____D C:\Windows\system32\en-GB
2018-02-15 16:58 - 2017-03-18 22:03 - 000000000 ____D C:\Windows\system32\appraiser
2018-02-15 16:56 - 2017-03-18 22:01 - 000000000 ____D C:\Windows\INF
2018-02-15 16:49 - 2017-04-29 20:22 - 000000000 ____D C:\Windows\Panther
2018-02-15 15:47 - 2017-03-18 21:51 - 000000000 ____D C:\Windows\CbsTemp
2018-02-14 23:26 - 2017-07-17 21:41 - 000001032 _____ C:\Users\Stefan\Desktop\New Text Document.txt
2018-02-14 21:35 - 2017-06-22 11:15 - 000000000 ____D C:\Users\Stefan\AppData\Local\Aspyr
2018-02-14 20:10 - 2017-09-04 17:45 - 000000000 ____D C:\Program Files (x86)\Aspyr
2018-02-14 12:27 - 2017-03-18 22:03 - 000000000 ___HD C:\Program Files\WindowsApps
2018-02-14 00:01 - 2017-05-01 15:35 - 000000000 ____D C:\Users\Stefan\Documents\My Games
2018-02-13 23:20 - 2017-04-30 21:43 - 000000000 ___HD C:\Windows\msdownld.tmp
2018-02-12 21:25 - 2018-02-02 14:36 - 000000000 ____D C:\Users\Stefan\Downloads\World of Warcraft 1.12
2018-02-10 20:54 - 2017-04-29 16:14 - 000001228 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2018-02-10 20:53 - 2017-04-29 16:14 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox

==================== Files in the root of some directories =======

2017-10-01 00:10 - 2017-10-01 00:10 - 000000000 ___RH () C:\Users\Stefan\AppData\Roaming\9c5339e6392c5dbc48efbb6d9f118f892

Some files in TEMP:
====================
2018-01-22 15:12 - 2018-01-22 15:12 - 000192512 _____ () C:\Users\Stefan\AppData\Local\Temp\sfamcc00001.dll
2015-02-10 18:56 - 2015-02-10 18:56 - 000105984 _____ () C:\Users\Stefan\AppData\Local\Temp\sfextra.dll

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-02-27 20:10

==================== End of FRST.txt ============================

Evo i Addition:
[Link mogu videti samo ulogovani korisnici]

Molim vas za pomoc!



offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Čist si što se malwarea tiče.

Sledeća procedura će implementirati završno čišćenje.

Arrow Preuzmi "Xplode"-ov DelFix alat i snimi ga na Desktop.
Dvoklikom pokreni alat i štikliraj kućice ispred sledećih opcija;

Remove disinfection tools
Create registry backup
Purge System Restore


Klikni na dugme Run i pričekaj trenutak dok alat ne završi svoj rad.
Od ovog trenutka, svi korišćeni alati u ovoj temi bi trebali biti obrisani.
Alat će takođe formirati izveštaj za tebe. (C:\DelFix.txt)

Alat će snimiti i zdravo stanje registy-ja i napraviti backup koristeci integrisan program "ERUNT" u %windir%\ERUNT\DelFix
Alat briše stare system restore tačke i pravi novu, svežu tačku nakon čišćenja.





Što se tiče ostataka Wondershare softvera, servis možeš obrisati pomoću Autorunsa (kartica Services), a nakon toga foldere na disku možeš ručno obrisati.



offline
  • Istrazivanje Windowsa
  • Pridružio: 12 Jul 2012
  • Poruke: 1023

Hvala mnogo!

Ko je trenutno na forumu
 

Ukupno su 1132 korisnika na forumu :: 111 registrovanih, 9 sakrivenih i 1012 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 13297 - dana 20 Jan 2026 17:42

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 4. Ozrenska, A.R.Chafee.Jr., aleph_one, armor, avijacija, Ba4e, bavar357, bbrasnjo3, belov, bigbear, boj.an, Bojan198527, Botovac, brufen, Bubimir, bukefal, Chainsaw, cvrle312, darcaud, debeli, dekan.m, Despot1, Dimitrije Paunovic, Dimitrise93, Djolek, djuradj, doktor097, draganl, DS01, ds69, dskrlec33, DuškoMraz, ElGenius, Filip Nježić, Fliper, Fructo, GeoM, Georgius, gorankuba, gregorxix, HrcAk47, ikan, Istman, Jakonjveliki, Jester, jopicus, kaput21, Karaula, koneks, konstruktor, Koser, KostaN, Kubovac, Laluvr, Lap720, ljuba, Lotus, M74AB3, Marko1238, MarkoDzimi, marre, Metanoja, mexo, Miler88, Mirage 2000N, MrG, N.e.m.a.nj.a., nebidrag, nevjerna beba, nightwish 01, nikoladim, Nikolajevic, ozzy, pacika, Pekman, Perudin_92, Pewac21, PlayerOne, Povratak1912, Prečanin30, RAKITNICA, repac, Resad76, Ripanjac, ruma, ruso, Sale0501, Simonsen23, singa, Solunac na steroidima, Sone1983, sova72, sovanova95, suton, tamno.nebo, Tas011, tomo2, toni061, TRAVUNIJA, Trimi68, trutcina, vaci, vathra, VJ, vladao75, Vojkan Petrovic, volimpivuvolimrakiju, XBMC, ZetaMan, zokizemun, Žrnov