Poslao: 20 Jan 2018 12:46
|
offline
- tacija
- Počasni građanin
- Miroslav Tanaskovic
- Gradjevinski tehnicar
- Pridružio: 02 Jan 2009
- Poruke: 787
- Gde živiš: Cacak
|
Koristim win7 32 bitni i u browserima mi se instalirao pretrazivac handy tab koji nemogu da uklonim. Probao sam sa chromeovim alatom sa adwcleanerom i sa MBAM i nikako nije uspelo . Internet mi je telekom adsl
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 17.01.2018 01
Ran by miroslav (administrator) on MIROSLAV-PC (20-01-2018 12:22:43)
Running from C:\Users\miroslav\Desktop
Loaded Profiles: miroslav (Available Profiles: miroslav)
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) Language: English (United States)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-t.....scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Nitro PDF Software) C:\Program Files\Nitro\Pro 9\NitroPDFDriverService9.exe
(Nalpeiron Ltd.) C:\Windows\System32\NLSSRV32.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe
(Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
(RaMMicHaeL) C:\Program Files\Unchecky\bin\unchecky_svc.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(RaMMicHaeL) C:\Program Files\Unchecky\bin\unchecky_bg.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
(Logitech Inc.) C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe
(MyCity) C:\Program Files\MCShield\MCShieldRTM.exe
() C:\Program Files\RocketDock\RocketDock.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(BitTorrent Inc.) C:\Users\miroslav\AppData\Roaming\uTorrent\uTorrent.exe
(Viber Media S.Ã r.l.) C:\Users\miroslav\AppData\Local\Viber\Viber.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Skype Technologies S.A.) C:\Program Files\Microsoft\Skype for Desktop\Skype.exe
() C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Skype Technologies S.A.) C:\Program Files\Microsoft\Skype for Desktop\Skype.exe
(BitTorrent Inc.) C:\Users\miroslav\AppData\Roaming\uTorrent\updates\3.5.1_44332\utorrentie.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(BitTorrent Inc.) C:\Users\miroslav\AppData\Roaming\uTorrent\updates\3.5.1_44332\utorrentie.exe
(Skype Technologies S.A.) C:\Program Files\Microsoft\Skype for Desktop\Skype.exe
(Skype Technologies S.A.) C:\Program Files\Microsoft\Skype for Desktop\Skype.exe
(Mobo, Inc.) C:\Program Files\Mobo\Service\MoboDeviceService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Free Time Co., Ltd.) C:\Program Files\FormatFactory\FormatFactory.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
() C:\Program Files\FormatFactory\FFModules\Encoder\ffmpeg.exe
(Mobo) C:\Program Files\Mobo\Service\MoboDeviceProxy.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Farbar) C:\Users\miroslav\Desktop\FRST (1).exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NvBackend] => C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2279712 2013-12-10] (NVIDIA Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [10996368 2012-06-11] (Realtek Semiconductor)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1002984 2016-11-15] (Microsoft Corporation)
HKLM\...\Run: [Windows Mobile Device Center] => C:\Windows\WindowsMobile\wmdc.exe [648072 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [LWS] => C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe [204136 2012-09-12] (Logitech Inc.)
HKU\S-1-5-21-961669800-890686474-1414387024-1001\...\Run: [MCShield Monitor] => C:\Program Files\MCShield\mcshieldrtm.exe [650816 2014-04-11] (MyCity)
HKU\S-1-5-21-961669800-890686474-1414387024-1001\...\Run: [RocketDock] => C:\Program Files\RocketDock\RocketDock.exe [495616 2007-09-02] ()
HKU\S-1-5-21-961669800-890686474-1414387024-1001\...\Run: [uTorrent] => C:\Users\miroslav\AppData\Roaming\uTorrent\uTorrent.exe [1981624 2017-12-27] (BitTorrent Inc.)
HKU\S-1-5-21-961669800-890686474-1414387024-1001\...\Run: [AceStream] => C:\Users\miroslav\AppData\Roaming\ACEStream\engine\ace_engine.exe
HKU\S-1-5-21-961669800-890686474-1414387024-1001\...\Run: [Viber] => C:\Users\miroslav\AppData\Local\Viber\Viber.exe [34720840 2018-01-12] (Viber Media S.Ã r.l.)
HKU\S-1-5-21-961669800-890686474-1414387024-1001\...\Run: [Skype for Desktop] => C:\Program Files\Microsoft\Skype for Desktop\Skype.exe [57446856 2018-01-09] (Skype Technologies S.A.)
HKU\S-1-5-21-961669800-890686474-1414387024-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\PROGRA~1\Crawler\SSaver\bin\3DAQUA~1\3DAQUA~1.SCR
GroupPolicy: Restriction - Chrome <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 0.0.0.0
Tcpip\..\Interfaces\{A1DE0E0E-1595-4216-B22A-8F4F035F1AB3}: [DhcpNameServer] 192.168.1.1 0.0.0.0
Internet Explorer:
==================
HKU\S-1-5-21-961669800-890686474-1414387024-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_111\bin\ssv.dll [2016-12-28] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-12-28] (Oracle Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL [2000-04-19] (Microsoft Corporation)
FireFox:
========
FF DefaultProfile: 7ostk6yx.default
FF ProfilePath: C:\Users\miroslav\AppData\Roaming\Mozilla\Firefox\Profiles\7ostk6yx.default [2018-01-20]
FF Homepage: Mozilla\Firefox\Profiles\7ostk6yx.default -> hxxps://google.com
FF Session Restore: Mozilla\Firefox\Profiles\7ostk6yx.default -> is enabled.
FF Extension: (S3.Translator) - C:\Users\miroslav\AppData\Roaming\Mozilla\Firefox\Profiles\7ostk6yx.default\Extensions\s3google@translator.xpi [2018-01-01]
FF Extension: (FlashGot) - C:\Users\miroslav\AppData\Roaming\Mozilla\Firefox\Profiles\7ostk6yx.default\Extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi [2016-12-28] [Legacy]
FF Extension: (X-notifier (for Gmail™,Hotmail,Yahoo,AOL...)) - C:\Users\miroslav\AppData\Roaming\Mozilla\Firefox\Profiles\7ostk6yx.default\Extensions\{37fa1426-b82d-11db-8314-0800200c9a66}.xpi [2017-09-14]
FF Extension: (Web Secure) - C:\Users\miroslav\AppData\Roaming\Mozilla\Firefox\Profiles\7ostk6yx.default\Extensions\{b6d09408-a35e-11e7-bc48-f3e9438e081e}.xpi [2017-12-12]
FF Extension: (Video DownloadHelper) - C:\Users\miroslav\AppData\Roaming\Mozilla\Firefox\Profiles\7ostk6yx.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2018-01-20]
FF Extension: (Adblock Plus) - C:\Users\miroslav\AppData\Roaming\Mozilla\Firefox\Profiles\7ostk6yx.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-12-19]
FF Extension: (User Agent Switcher) - C:\Users\miroslav\AppData\Roaming\Mozilla\Firefox\Profiles\7ostk6yx.default\Extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi [2017-05-13] [Legacy]
FF Extension: (Disable JavaScript Shared Memory) - C:\Users\miroslav\AppData\Roaming\Mozilla\Firefox\Profiles\7ostk6yx.default\features\{c03d9240-99f5-41ab-9bb4-c4515aa7b8b0}\disable-js-shared-memory@mozilla.org.xpi [2018-01-20] [Legacy]
FF HKU\S-1-5-21-961669800-890686474-1414387024-1001\...\Firefox\Extensions: [acewebextension_unlisted@acestream.org] - C:\Users\miroslav\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi => not found
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_28_0_0_137.dll [2018-01-10] ()
FF Plugin: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-12-28] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-12-28] (Oracle Corporation)
FF Plugin: @nitropdf.com/NitroPDF -> C:\Program Files\Nitro\Pro 9\npnitromozilla.dll [2013-10-07] (Nitro PDF)
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2013-12-19] (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2013-12-19] (NVIDIA Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin HKU\S-1-5-21-961669800-890686474-1414387024-1001: @acestream.net/acestreamplugin,version=3.1.16.1 -> C:\Users\miroslav\AppData\Roaming\ACEStream\player\npace_plugin.dll [No File]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxps://www.google.com/","hxxps://www.google.com/","hxxp://mail.ru/cnt/10445?gp=811040","hxxps://www.google.com/"
CHR NewTab: Default -> Not-active:"chrome-extension://fdckocnfhibclnnkifmjbbogcfkbijki/main.html"
CHR DefaultSearchURL: Default -> hxxps://feed.browserhunt.com/?fext=true&publisherid=51624&publisher=huntext&st=et&q={searchTerms}
CHR DefaultSearchKeyword: Default -> BrowserHunt
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\miroslav\AppData\Local\Google\Chrome\User Data\Default [2018-01-20]
CHR Extension: (Презентације) - C:\Users\miroslav\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-13]
CHR Extension: (Документи) - C:\Users\miroslav\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-13]
CHR Extension: (Google диск) - C:\Users\miroslav\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-07-23]
CHR Extension: (WOT: Web of Trust, Website Reputation Ratings) - C:\Users\miroslav\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2017-12-29]
CHR Extension: (Turtle) - C:\Users\miroslav\AppData\Local\Google\Chrome\User Data\Default\Extensions\bjjoabbgdgocpncdlhlfhbaocdddffjf [2017-09-30]
CHR Extension: (YouTube) - C:\Users\miroslav\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-07-23]
CHR Extension: (Adblock Plus) - C:\Users\miroslav\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2018-01-18]
CHR Extension: (Gmail ван мреже) - C:\Users\miroslav\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejidjjhkpiempkbhmpbfngldlkglhimk [2017-08-21]
CHR Extension: (Табеле) - C:\Users\miroslav\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-13]
CHR Extension: (Google документи офлајн) - C:\Users\miroslav\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-07-23]
CHR Extension: (New Tab - Winter Animation) - C:\Users\miroslav\AppData\Local\Google\Chrome\User Data\Default\Extensions\leenkjhmbcgekojlkimcbodmniopgfnp [2018-01-05]
CHR Extension: (Nemoze da se izbrise) - C:\Users\miroslav\AppData\Local\Google\Chrome\User Data\Default\Extensions\mflobcdhgnlibbiegemmoenkeaplpoid [2017-08-21]
CHR Extension: (Ace Script) - C:\Users\miroslav\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjbepbhonbojpoaenhckjocchgfiaofo [2017-12-14]
CHR Extension: (Onlive Clock) - C:\Users\miroslav\AppData\Local\Google\Chrome\User Data\Default\Extensions\moddbcckaikhdnigidfcmaeelcobchpm [2017-08-21]
CHR Extension: (Плаћања у Chrome веб-продавници) - C:\Users\miroslav\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-22]
CHR Extension: (Gmail) - C:\Users\miroslav\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-07-23]
CHR Extension: (Chrome Media Router) - C:\Users\miroslav\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-11-17]
CHR Profile: C:\Users\miroslav\AppData\Local\Google\Chrome\User Data\Default.old [2017-08-27] <==== ATTENTION
CHR Extension: (Google диск) - C:\Users\miroslav\AppData\Local\Google\Chrome\User Data\Default.old\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-12-28]
CHR Extension: (WOT: Web of Trust, Website Reputation Ratings) - C:\Users\miroslav\AppData\Local\Google\Chrome\User Data\Default.old\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2017-07-17]
CHR Extension: (YouTube) - C:\Users\miroslav\AppData\Local\Google\Chrome\User Data\Default.old\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-12-28]
CHR Extension: (Gmail ван мреже) - C:\Users\miroslav\AppData\Local\Google\Chrome\User Data\Default.old\Extensions\ejidjjhkpiempkbhmpbfngldlkglhimk [2016-12-28]
CHR Extension: (New Tab - Winter Animation) - C:\Users\miroslav\AppData\Local\Google\Chrome\User Data\Default.old\Extensions\leenkjhmbcgekojlkimcbodmniopgfnp [2017-06-02]
CHR Extension: (Onlive Clock) - C:\Users\miroslav\AppData\Local\Google\Chrome\User Data\Default.old\Extensions\moddbcckaikhdnigidfcmaeelcobchpm [2016-12-28]
CHR Extension: (Плаћања у Chrome веб-продавници) - C:\Users\miroslav\AppData\Local\Google\Chrome\User Data\Default.old\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-09]
CHR Extension: (Gmail) - C:\Users\miroslav\AppData\Local\Google\Chrome\User Data\Default.old\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-12-28]
CHR Extension: (Chrome Media Router) - C:\Users\miroslav\AppData\Local\Google\Chrome\User Data\Default.old\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-07-14]
CHR Profile: C:\Users\miroslav\AppData\Local\Google\Chrome\User Data\System Profile [2017-09-06]
==================== Services (Whitelisted) ====================
===================== Drivers (Whitelisted) ======================
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-01-20 12:22 - 2018-01-20 12:22 - 001753600 _____ (Farbar) C:\Users\miroslav\Desktop\FRST (1).exe
2018-01-20 12:07 - 2018-01-20 12:23 - 000016515 _____ C:\Users\miroslav\Desktop\FRST.txt
2018-01-20 12:07 - 2018-01-20 12:22 - 000000000 ____D C:\FRST
2018-01-17 09:56 - 2018-01-17 09:57 - 000000000 ____D C:\Users\miroslav\AppData\Local\Viber
2018-01-16 10:29 - 2013-11-26 09:16 - 003419136 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2018-01-15 10:57 - 2016-04-14 14:49 - 000603648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2018-01-15 10:57 - 2016-04-09 05:20 - 001230848 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2018-01-15 10:57 - 2015-12-08 22:54 - 002285056 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2018-01-15 10:57 - 2015-07-30 18:57 - 001987584 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2018-01-15 10:57 - 2015-02-04 03:54 - 000417792 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2018-01-15 10:56 - 2017-05-12 17:25 - 001251328 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2018-01-15 10:56 - 2017-05-12 17:25 - 000909824 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2018-01-15 10:56 - 2016-10-11 14:33 - 000187392 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2018-01-15 10:44 - 2018-01-15 15:03 - 000000000 ____D C:\Program Files\Kodi
2018-01-15 10:29 - 2013-01-13 22:17 - 000009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2018-01-15 10:29 - 2013-01-13 22:17 - 000002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2018-01-15 10:29 - 2013-01-13 22:16 - 000010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2018-01-15 10:29 - 2013-01-13 22:12 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2018-01-15 10:29 - 2013-01-13 22:11 - 000005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2018-01-15 10:29 - 2013-01-13 22:11 - 000005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2018-01-15 10:29 - 2013-01-13 22:11 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2018-01-15 10:29 - 2013-01-13 22:11 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2018-01-15 10:29 - 2013-01-13 22:11 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2018-01-15 10:29 - 2013-01-13 21:20 - 000293376 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2018-01-15 10:29 - 2013-01-13 21:09 - 000249856 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2018-01-15 10:29 - 2013-01-13 21:08 - 000220160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2018-01-15 10:29 - 2013-01-13 20:53 - 000207872 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2018-01-15 10:29 - 2013-01-13 20:48 - 000161792 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2018-01-15 10:29 - 2013-01-13 20:46 - 001080832 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2018-01-15 10:29 - 2013-01-13 19:34 - 000364544 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2018-01-15 10:29 - 2013-01-13 18:26 - 001158144 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2018-01-14 12:17 - 2018-01-14 12:16 - 009680416 _____ C:\Users\miroslav\Desktop\0-02-05-272c67dcb91779bf3ca32454ee656a7e3e9056c8669438e03c57e2811ba932b0_full.mp4
2018-01-10 11:11 - 2018-01-10 11:11 - 005845504 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe
2018-01-09 01:56 - 2018-01-01 03:02 - 001310528 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 012880384 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 011035648 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 006041088 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 002088960 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 001499648 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 001417728 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 001390080 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 001270272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 001155584 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 001062912 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 001004032 _____ (Microsoft Corporation) C:\Windows\system32\PeerDistSvc.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000983552 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000872448 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000741888 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000717312 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000627712 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000564736 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000554496 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000463360 _____ (Microsoft Corporation) C:\Windows\system32\FirewallAPI.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000436736 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000389632 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000377344 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000328192 _____ (Microsoft Corporation) C:\Windows\system32\p2psvc.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000294400 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000269824 _____ (Microsoft Corporation) C:\Windows\system32\pnrpsvc.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000261120 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000254464 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000223232 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000217600 _____ (Microsoft Corporation) C:\Windows\system32\P2P.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000216064 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000195072 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000186368 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000171008 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000153088 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000141312 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000139776 _____ (Microsoft Corporation) C:\Windows\system32\PeerDist.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000096256 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000095744 _____ (Microsoft Corporation) C:\Windows\system32\PeerDistWSDDiscoProv.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000089088 _____ (Microsoft Corporation) C:\Windows\system32\icfupgd.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000072192 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000056320 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000053760 _____ (Microsoft Corporation) C:\Windows\system32\vmicres.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000048128 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000033280 _____ (Microsoft Corporation) C:\Windows\system32\traffic.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000010752 _____ (Microsoft Corporation) C:\Windows\system32\wshnetbs.dll
2018-01-09 01:56 - 2018-01-01 03:00 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2018-01-09 01:56 - 2018-01-01 02:59 - 001806848 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2018-01-09 01:56 - 2018-01-01 02:59 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2018-01-09 01:56 - 2018-01-01 02:59 - 000644096 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2018-01-09 01:56 - 2018-01-01 02:59 - 000082432 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2018-01-09 01:56 - 2018-01-01 02:59 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2018-01-09 01:56 - 2018-01-01 02:59 - 000047104 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2018-01-09 01:56 - 2018-01-01 02:59 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2018-01-09 01:56 - 2018-01-01 02:59 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2018-01-09 01:56 - 2018-01-01 02:59 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2018-01-09 01:56 - 2018-01-01 02:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2018-01-09 01:56 - 2018-01-01 02:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2018-01-09 01:56 - 2018-01-01 02:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2018-01-09 01:56 - 2018-01-01 02:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2018-01-09 01:56 - 2018-01-01 02:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2018-01-09 01:56 - 2018-01-01 02:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2018-01-09 01:56 - 2018-01-01 02:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2018-01-09 01:56 - 2018-01-01 02:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2018-01-09 01:56 - 2018-01-01 02:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2018-01-09 01:56 - 2018-01-01 02:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2018-01-09 01:56 - 2018-01-01 02:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2018-01-09 01:56 - 2018-01-01 02:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2018-01-09 01:56 - 2018-01-01 02:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-01-09 01:56 - 2018-01-01 02:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2018-01-09 01:56 - 2018-01-01 02:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2018-01-09 01:56 - 2018-01-01 02:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2018-01-09 01:56 - 2018-01-01 02:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2018-01-09 01:56 - 2018-01-01 02:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2018-01-09 01:56 - 2018-01-01 02:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2018-01-09 01:56 - 2018-01-01 02:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2018-01-09 01:56 - 2018-01-01 02:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2018-01-09 01:56 - 2018-01-01 02:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2018-01-09 01:56 - 2018-01-01 02:54 - 004013800 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2018-01-09 01:56 - 2018-01-01 02:54 - 003959016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2018-01-09 01:56 - 2018-01-01 02:54 - 001214184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2018-01-09 01:56 - 2018-01-01 02:54 - 000712936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2018-01-09 01:56 - 2018-01-01 02:54 - 000201960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fltMgr.sys
2018-01-09 01:56 - 2018-01-01 02:54 - 000198888 _____ (Microsoft Corporation) C:\Windows\system32\halmacpi.dll
2018-01-09 01:56 - 2018-01-01 02:54 - 000198888 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2018-01-09 01:56 - 2018-01-01 02:54 - 000173288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdyboost.sys
2018-01-09 01:56 - 2018-01-01 02:54 - 000139496 _____ (Microsoft Corporation) C:\Windows\system32\halacpi.dll
2018-01-09 01:56 - 2018-01-01 02:54 - 000137960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2018-01-09 01:56 - 2018-01-01 02:54 - 000105192 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2018-01-09 01:56 - 2018-01-01 02:54 - 000067304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2018-01-09 01:56 - 2018-01-01 02:50 - 000317952 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
2018-01-09 01:56 - 2018-01-01 02:44 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\PeerDistHttpTrans.dll
2018-01-09 01:56 - 2018-01-01 02:43 - 000104448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pacer.sys
2018-01-09 01:56 - 2018-01-01 02:43 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mpsdrv.sys
2018-01-09 01:56 - 2018-01-01 02:43 - 000036352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbios.sys
2018-01-09 01:56 - 2018-01-01 02:43 - 000018944 _____ (Microsoft Corporation) C:\Windows\system32\wfapigp.dll
2018-01-09 01:56 - 2018-01-01 02:43 - 000013824 _____ (Microsoft Corporation) C:\Windows\system32\wshqos.dll
2018-01-09 01:56 - 2018-01-01 02:41 - 001638912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2018-01-09 01:56 - 2018-01-01 02:41 - 000227328 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2018-01-09 01:56 - 2018-01-01 02:41 - 000181248 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2018-01-09 01:56 - 2018-01-01 02:41 - 000151552 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2018-01-09 01:56 - 2018-01-01 02:41 - 000044544 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2018-01-09 01:56 - 2018-01-01 02:41 - 000015872 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2018-01-09 01:56 - 2018-01-01 02:41 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll
2018-01-09 01:56 - 2018-01-01 02:40 - 000097792 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2018-01-09 01:56 - 2018-01-01 02:40 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2018-01-09 01:56 - 2018-01-01 02:40 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2018-01-09 01:56 - 2018-01-01 02:40 - 000016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2018-01-09 01:56 - 2018-01-01 02:39 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2018-01-09 01:56 - 2018-01-01 02:38 - 000271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2018-01-09 01:56 - 2018-01-01 02:38 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\vmicsvc.exe
2018-01-09 01:56 - 2018-01-01 02:38 - 000113664 _____ (Microsoft Corporation) C:\Windows\system32\IcCoinstall.dll
2018-01-09 01:56 - 2018-01-01 02:38 - 000047616 _____ (Microsoft Corporation) C:\Windows\system32\vmictimeprovider.dll
2018-01-09 01:56 - 2018-01-01 02:37 - 000262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2018-01-09 01:56 - 2018-01-01 02:36 - 000314368 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2018-01-09 01:56 - 2018-01-01 02:36 - 000313344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2018-01-09 01:56 - 2018-01-01 02:36 - 000226304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2018-01-09 01:56 - 2018-01-01 02:35 - 000514048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2018-01-09 01:56 - 2018-01-01 02:35 - 000124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2018-01-09 01:56 - 2018-01-01 02:35 - 000115712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2018-01-09 01:56 - 2018-01-01 02:35 - 000098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2018-01-09 01:56 - 2018-01-01 02:35 - 000081408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2018-01-09 01:56 - 2018-01-01 02:35 - 000069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2018-01-09 01:56 - 2018-01-01 02:35 - 000036352 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2018-01-09 01:56 - 2018-01-01 02:35 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2018-01-09 01:56 - 2018-01-01 02:35 - 000015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2018-01-09 01:56 - 2018-01-01 02:35 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2018-01-09 01:56 - 2018-01-01 02:35 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2018-01-09 01:56 - 2018-01-01 02:35 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2018-01-09 01:56 - 2018-01-01 02:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2018-01-09 01:56 - 2017-12-21 07:27 - 000535656 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2018-01-09 01:56 - 2017-12-13 17:15 - 000309480 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2018-01-09 01:56 - 2017-12-13 17:11 - 000071168 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2018-01-09 01:56 - 2017-12-13 17:11 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2018-01-09 01:56 - 2017-12-13 17:11 - 000010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2018-01-09 01:56 - 2017-12-13 16:50 - 000034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2018-01-09 01:56 - 2017-12-05 18:08 - 000481792 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll
2018-01-09 01:56 - 2017-12-05 18:08 - 000215040 _____ (Microsoft Corporation) C:\Windows\system32\icm32.dll
2018-01-09 01:56 - 2017-12-05 16:50 - 002402816 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2018-01-09 01:56 - 2017-12-05 16:49 - 000032768 _____ (Microsoft Corporation) C:\Windows\system32\WcsPlugInService.dll
2017-12-27 11:34 - 2018-01-20 09:36 - 000000000 ____D C:\Users\miroslav\AppData\LocalLow\uTorrent
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-01-20 12:21 - 2017-01-02 10:19 - 000000000 ____D C:\Users\miroslav\AppData\Roaming\uTorrent
2018-01-20 11:56 - 2016-12-28 15:51 - 000000000 ____D C:\Users\miroslav\AppData\LocalLow\Mozilla
2018-01-20 10:29 - 2016-10-09 13:31 - 000000000 ___RD C:\Users\miroslav\Desktop\video
2018-01-20 10:03 - 2009-07-14 05:34 - 000016944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-01-20 10:03 - 2009-07-14 05:34 - 000016944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-01-20 09:52 - 2017-01-07 18:06 - 000000000 ____D C:\Users\miroslav\Documents\ViberDownloads
2018-01-20 09:48 - 2016-12-28 10:55 - 000782470 _____ C:\Windows\system32\PerfStringBackup.INI
2018-01-20 09:48 - 2009-07-14 03:37 - 000000000 ____D C:\Windows\inf
2018-01-20 09:45 - 2016-12-28 13:46 - 000000000 ____D C:\ProgramData\MCShield
2018-01-20 09:35 - 2016-12-28 11:24 - 000000000 ____D C:\ProgramData\NVIDIA
2018-01-20 09:35 - 2009-07-14 05:53 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-01-17 09:55 - 2017-01-07 18:06 - 000000000 ____D C:\Users\miroslav\AppData\Roaming\ViberPC
2018-01-15 15:05 - 2017-04-21 13:27 - 000000000 ____D C:\ProgramData\TEMP
2018-01-15 11:42 - 2009-07-14 03:37 - 000000000 ____D C:\Windows\rescache
2018-01-15 10:59 - 2016-12-28 11:18 - 000000000 ____D C:\Users\miroslav\Desktop\Precice
2018-01-15 10:45 - 2017-09-25 17:54 - 000000998 _____ C:\Users\miroslav\Desktop\il.txt
2018-01-14 14:18 - 2017-03-19 13:41 - 000000000 ____D C:\Users\miroslav\AppData\Roaming\AVI ReComp
2018-01-13 11:22 - 2017-12-08 11:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2018-01-11 00:17 - 2016-12-30 08:13 - 000000000 ____D C:\Windows\system32\MRT
2018-01-11 00:12 - 2017-10-11 22:25 - 126487616 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2018-01-11 00:11 - 2016-12-30 08:13 - 126487616 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-01-10 11:11 - 2017-02-24 14:34 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2018-01-10 11:11 - 2017-02-24 14:34 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2018-01-10 11:11 - 2017-02-24 14:34 - 000000000 ____D C:\Windows\system32\Macromed
2018-01-09 10:51 - 2009-07-14 05:33 - 000281520 _____ C:\Windows\system32\FNTCACHE.DAT
2018-01-07 15:14 - 2016-12-28 12:43 - 000000000 ____D C:\Users\miroslav\AppData\Roaming\AIMP
2018-01-05 14:51 - 2017-09-05 17:18 - 000000000 ____D C:\AdwCleaner
2018-01-02 07:48 - 2017-06-11 17:59 - 000000000 ____D C:\Program Files\Mozilla Firefox
2018-01-02 07:48 - 2016-12-28 16:26 - 000000000 ____D C:\Program Files\Mozilla Maintenance Service
2017-12-24 00:11 - 2017-05-06 13:59 - 000000000 ____D C:\Users\miroslav\AppData\Roaming\vlc
2017-12-21 09:33 - 2017-12-20 10:31 - 000221112 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
==================== Files in the root of some directories =======
2017-12-13 18:27 - 2017-12-13 18:34 - 000003584 _____ () C:\Users\miroslav\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2018-01-18 15:53
==================== End of FRST.txt ============================
https://www.mycity.rs/must-login.png
|
|
|
|
Poslao: 20 Jan 2018 22:54
|
offline
- Sass Drake
- Anti Malware Fighter
Rank 2
- Pridružio: 26 Avg 2010
- Poruke: 10622
- Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building
|
Otvori Notepad i iskopiraj sljedeći tekst koji se nalazi unutar Kod polja.
GroupPolicy: Restriction - Chrome <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
CHR NewTab: Default -> Not-active:"chrome-extension://fdckocnfhibclnnkifmjbbogcfkbijki/main.html"
CHR DefaultSearchURL: Default -> hxxps://feed.browserhunt.com/?fext=true&publisherid=51624&publisher=huntext&st=et&q={searchTerms}
CHR DefaultSearchKeyword: Default -> BrowserHunt
CHR Extension: (Nemoze da se izbrise) - C:\Users\miroslav\AppData\Local\Google\Chrome\User Data\Default\Extensions\mflobcdhgnlibbiegemmoenkeaplpoid [2017-08-21]
AlternateDataStreams: C:\Windows:nlsPreferences [386]
AlternateDataStreams: C:\ProgramData\TEMP:1CE11B51 [152]
AlternateDataStreams: C:\ProgramData\TEMP:BD34FFC5 [286]
U okviru Notepad-a klikni na File --> Save As
Pod Encoding izaberi UTF-8.
Fajl nazovi Fixlist i sačuvaj na Desktop
Dvoklikom ponovo pokreni FRST.exe
Klikni na Fix i sačekaj dok program ne završi.
Ukoliko program zatraži restart računara, omogući mu da to nesmetano obavi.
Nakon završetka rada, otvoriće se fixlog.txt, sa sadržajem koji treba da kopiraš u temu.
Takođe, na Desktop-u će se nalaziti (fixlog.txt).
|
|
|
|
Poslao: 20 Jan 2018 23:30
|
offline
- tacija
- Počasni građanin
- Miroslav Tanaskovic
- Gradjevinski tehnicar
- Pridružio: 02 Jan 2009
- Poruke: 787
- Gde živiš: Cacak
|
Fix result of Farbar Recovery Scan Tool (x86) Version: 17.01.2018 01
Ran by miroslav (20-01-2018 23:14:51) Run:1
Running from C:\Users\miroslav\Desktop
Loaded Profiles: miroslav (Available Profiles: miroslav)
Boot Mode: Normal
==============================================
fixlist content:
*****************
GroupPolicy: Restriction - Chrome <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
CHR NewTab: Default -> Not-active:"chrome-extension://fdckocnfhibclnnkifmjbbogcfkbijki/main.html"
CHR DefaultSearchURL: Default -> hxxps://feed.browserhunt.com/?fext=true&publisherid=51624&publisher=huntext&st=et&q={searchTerms}
CHR DefaultSearchKeyword: Default -> BrowserHunt
CHR Extension: (Nemoze da se izbrise) - C:\Users\miroslav\AppData\Local\Google\Chrome\User Data\Default\Extensions\mflobcdhgnlibbiegemmoenkeaplpoid [2017-08-21]
AlternateDataStreams: C:\Windows:nlsPreferences [386]
AlternateDataStreams: C:\ProgramData\TEMP:1CE11B51 [152]
AlternateDataStreams: C:\ProgramData\TEMP:BD34FFC5 [286]
*****************
C:\Windows\system32\GroupPolicy\Machine => moved successfully
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
"HKLM\SOFTWARE\Policies\Google" => removed successfully.
"Chrome NewTab" => removed successfully.
"Chrome DefaultSearchURL" => removed successfully.
"Chrome DefaultSearchKeyword" => removed successfully.
CHR Extension: (Nemoze da se izbrise) - C:\Users\miroslav\AppData\Local\Google\Chrome\User Data\Default\Extensions\mflobcdhgnlibbiegemmoenkeaplpoid [2017-08-21] => Error: No automatic fix found for this entry.
C:\Windows => ":nlsPreferences" ADS removed successfully.
C:\ProgramData\TEMP => ":1CE11B51" ADS removed successfully.
C:\ProgramData\TEMP => ":BD34FFC5" ADS removed successfully.
The system needed a reboot.
==== End of Fixlog 23:14:56 ====
|
|
|
|
Poslao: 20 Jan 2018 23:42
|
offline
- Sass Drake
- Anti Malware Fighter
Rank 2
- Pridružio: 26 Avg 2010
- Poruke: 10622
- Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building
|
Preuzmi Malwarebytes Anti-Malware sa ovog ili ovog ili ovog linka i instaliraj aplikaciju.
Pokreni mb3-setup-consumer-{verzija}.exe i isprati uputstva za instalaciju programa. Nakon instalacije, klikni na Finish
Prilikom prvog pokretanja, program će prikazati prozor "dobrodošlice". Slobodno zatvori taj prozor.
Napomena: Premium funkcije programa su već aktivirane i važe 13 dana od trenutka instalacije. Premium funkcije možeš isključiti preko Settings > My Account tab podešavanja.
• Podešavanja skenera - u Settings, klikni na Protection tab. Ispod Scan Options sekcije, uključi "Scan for rootkits" opciju.
• Pripremi podešavanja za Threat Scan - u Dashboard , klikni na Scan Now dugme. MBAM će ažurirati bazu i započeti skeniranje.
Kada se skeniranje završi, ako je infekcija detektovana, obrati pažnju da je sve označeno, pa klikni na Remove Selected. Restartuj računar ako program upita za restart.
• Dostavi log: Pod Reports izaberi trenutni datum izveštaja Scan Report i potom klikni na View Report.
Izvezi log na Desktop;
- Klikni na Export dugme na dnu, pa onda izaberi 'Text file (*.txt)'
# U Save File dijalogu koji se pojavi, klikni na Desktop. U File name: polje, upiši "mbam" (bez navodnika) i klikni na Save.
- Pojaviće se poruka "Your file has been successfully exported", klikni Ok i zatvori prozor.
• U odgovoru prikači mbam.txt log koristeći "Prikači fajl" opciju.
|
|
|
|
Poslao: 21 Jan 2018 11:18
|
offline
- tacija
- Počasni građanin
- Miroslav Tanaskovic
- Gradjevinski tehnicar
- Pridružio: 02 Jan 2009
- Poruke: 787
- Gde živiš: Cacak
|
Sad je sa Chrome u redu ali posto koristim i Mozilu zaboravio sam u pocetnom postu da navedem da prilikom otvaranja Mozile CPU celo vreme bude 100% opterecen
https://www.mycity.rs/must-login.png
|
|
|
|
Poslao: 21 Jan 2018 15:36
|
offline
- Sass Drake
- Anti Malware Fighter
Rank 2
- Pridružio: 26 Avg 2010
- Poruke: 10622
- Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building
|
Otvori Notepad i iskopiraj sljedeći tekst koji se nalazi unutar Kod polja.
FF Extension: (Web Secure) - C:\Users\miroslav\AppData\Roaming\Mozilla\Firefox\Profiles\7ostk6yx.default\Extensions\{b6d09408-a35e-11e7-bc48-f3e9438e081e}.xpi [2017-12-12]
FF HKU\S-1-5-21-961669800-890686474-1414387024-1001\...\Firefox\Extensions: [acewebextension_unlisted@acestream.org] - C:\Users\miroslav\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi => not found
U okviru Notepad-a klikni na File --> Save As
Pod Encoding izaberi UTF-8.
Fajl nazovi Fixlist i sačuvaj na Desktop
Dvoklikom ponovo pokreni FRST.exe
Klikni na Fix i sačekaj dok program ne završi.
Ukoliko program zatraži restart računara, omogući mu da to nesmetano obavi.
Nakon završetka rada, otvoriće se fixlog.txt, sa sadržajem koji treba da kopiraš u temu.
Takođe, na Desktop-u će se nalaziti (fixlog.txt).
|
|
|
|
Poslao: 21 Jan 2018 15:47
|
offline
- tacija
- Počasni građanin
- Miroslav Tanaskovic
- Gradjevinski tehnicar
- Pridružio: 02 Jan 2009
- Poruke: 787
- Gde živiš: Cacak
|
Fix result of Farbar Recovery Scan Tool (x86) Version: 21.01.2018
Ran by miroslav (21-01-2018 15:46:04) Run:2
Running from C:\Users\miroslav\Desktop
Loaded Profiles: miroslav (Available Profiles: miroslav)
Boot Mode: Normal
==============================================
fixlist content:
*****************
FF Extension: (Web Secure) - C:\Users\miroslav\AppData\Roaming\Mozilla\Firefox\Profiles\7ostk6yx.default\Extensions\{b6d09408-a35e-11e7-bc48-f3e9438e081e}.xpi [2017-12-12]
FF HKU\S-1-5-21-961669800-890686474-1414387024-1001\...\Firefox\Extensions: [acewebextension_unlisted@acestream.org] - C:\Users\miroslav\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi => not found
*****************
"C:\Users\miroslav\AppData\Roaming\Mozilla\Firefox\Profiles\7ostk6yx.default\Extensions\{b6d09408-a35e-11e7-bc48-f3e9438e081e}.xpi" => not found
"HKU\S-1-5-21-961669800-890686474-1414387024-1001\Software\Mozilla\Firefox\Extensions\\acewebextension_unlisted@acestream.org" => removed successfully.
==== End of Fixlog 15:47:22 ====
|
|
|
|
Poslao: 21 Jan 2018 15:54
|
offline
- Sass Drake
- Anti Malware Fighter
Rank 2
- Pridružio: 26 Avg 2010
- Poruke: 10622
- Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building
|
Stanje?
|
|
|
|
Poslao: 21 Jan 2018 16:05
|
offline
- tacija
- Počasni građanin
- Miroslav Tanaskovic
- Gradjevinski tehnicar
- Pridružio: 02 Jan 2009
- Poruke: 787
- Gde živiš: Cacak
|
Sa Mozilom nepromenjeno ,opet CPU preopterecen
|
|
|
|
|