Otvara se oursurfing upretrazivacu i puno reklama

1

Otvara se oursurfing upretrazivacu i puno reklama

offline
  • Pridružio: 06 Feb 2013
  • Poruke: 104
  • Gde živiš: Zajecar

Napisano: 13 Okt 2015 20:35

Pri svakom otvaranju pretrazivaca otvaraju se novi tabovi gde pise oursurfing.U regeditu ga nigde nema da bi ga obrisao.Na svaki klik otvaraju se novi tabovi sa reklamama.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:12-10-2015
Ran by Mica Petkovic (administrator) on MICAPETKOVIC-PC (13-10-2015 20:23:35)
Running from C:\Users\Mica Petkovic\Desktop
Loaded Profiles: Mica Petkovic (Available Profiles: Mica Petkovic)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: engleski (SAD)
Internet Explorer Version 10 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: geekstogo.com/forum/topic/335081-frst-t.....scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
() C:\Users\Mica Petkovic\AppData\Local\Viber\Viber.exe
(BitTorrent Inc.) C:\Users\Mica Petkovic\AppData\Roaming\uTorrent\uTorrent.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(BitTorrent Inc.) C:\Users\Mica Petkovic\AppData\Roaming\uTorrent\updates\3.4.5_41162\utorrentie.exe
(BitTorrent Inc.) C:\Users\Mica Petkovic\AppData\Roaming\uTorrent\updates\3.4.5_41162\utorrentie.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6111824 2015-08-26] (AVAST Software)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1715614436-2009014575-3900974691-1001\...\Run: [MCShield Monitor] => D:\Programi\Internet\MCShield\mcshieldrtm.exe
HKU\S-1-5-21-1715614436-2009014575-3900974691-1001\...\Run: [Viber] => C:\Users\Mica Petkovic\AppData\Local\Viber\Viber.exe [72389840 2015-07-15] ()
HKU\S-1-5-21-1715614436-2009014575-3900974691-1001\...\Run: [uTorrent] => C:\Users\Mica Petkovic\AppData\Roaming\uTorrent\uTorrent.exe [1821536 2015-09-26] (BitTorrent Inc.)
HKU\S-1-5-21-1715614436-2009014575-3900974691-1001\...\RunOnce: [Uninstall C:\Users\Mica Petkovic\AppData\Local\Microsoft\OneDrive\17.3.5907.0716] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Mica Petkovic\AppData\Local\Microsoft\OneDrive\17.3.5907.0716"
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-08-09] (AVAST Software)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{64EC62AA-4EE8-490C-AC62-B42FEB41D835}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-1715614436-2009014575-3900974691-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKU\S-1-5-21-1715614436-2009014575-3900974691-1001 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKU\S-1-5-21-1715614436-2009014575-3900974691-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-08-09] (AVAST Software)
BHO: Skype add-on for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll [2015-08-28] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-08-09] (AVAST Software)
BHO-x32: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-08-28] (Oracle Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)

FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> D:\Programi\Muzika\VLC\npvlc.dll [2015-04-16] (VideoLAN)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2014-04-15] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2014-04-15] (Foxit Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-08-28] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-08-28] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [2015-10-10] (globalUpdate)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [2015-10-10] (globalUpdate)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin-x32: @verimatrix.com/ViewRightWeb -> C:\Program Files (x86)\Verimatrix\ViewRight Web\\npViewRight.dll [2014-06-10] (Verimatrix, Inc.)
FF Plugin HKU\S-1-5-21-1715614436-2009014575-3900974691-1001: @verimatrix.com/ViewRightWeb -> C:\Program Files (x86)\Verimatrix\ViewRight Web\\npViewRight.dll [2014-06-10] (Verimatrix, Inc.)
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-08-09]

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com/ig?rls=ig&hl=sr&source=iglk
CHR StartupUrls: Default -> "hxxp://www.google.com/","hxxp://www.oursurfing.com/?type=hp&ts=1444475701&z=7513ebe44ecd2b09e7b64ecgez4z0z3zcm1wem0e2g&from=amt&uid=hgstxhts545050a7e380_te85134ngdlt9rgdlt9rx"
CHR Profile: C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google преводилац) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2015-08-01]
CHR Extension: (Google презентације) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-08-01]
CHR Extension: (Google документи) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-01]
CHR Extension: (Google диск) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-08-01]
CHR Extension: (YouTube) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-08-01]
CHR Extension: (OneTab) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\chphlpgkkbolifaimnlloiipkdnihall [2015-08-01]
CHR Extension: (Google Search) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-08-01]
CHR Extension: (Google табеле) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-08-01]
CHR Extension: (Mini Radio Player) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffeaebedjghkdbccfenjbiilalegknlj [2015-08-01]
CHR Extension: (Google документи офлајн) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-03]
CHR Extension: (Porsche) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkclphmapdcppbmekmbkcjfanpmoidpg [2015-08-01]
CHR Extension: (Avast Online Security) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-08-10]
CHR Extension: (SearchPreview) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcjdanpjacpeeppdjkppebobilhaglfo [2015-08-01]
CHR Extension: (CloudConvert) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfpmbfgodkfcebpgheiedaddoikmljkk [2015-09-02]
CHR Extension: (Skype Click to Call) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2015-08-02]
CHR Extension: (CinemaP-1.9cV10.10) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi [2015-10-10]
CHR Extension: (Google Dictionary (by Google)) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja [2015-08-01]
CHR Extension: (Google провера поште) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2015-08-01]
CHR Extension: (LocalChromecast Player) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmladpigjlinmngadjgfogblnmddndcp [2015-10-01]
CHR Extension: (Плаћања у Chrome веб-продавници) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-01]
CHR Extension: (Auto-Translate) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\obgoiaeapddkeekbocomnjlckbbfapmk [2015-09-04]
CHR Extension: (Audio Converter) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojfphighcpfimfhblaigjckljcoeipga [2015-09-02]
CHR Extension: (Gmail) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-01]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1715614436-2009014575-3900974691-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bknbnapaddjdnbilpmlacdkjdkjmbjhd] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [bknbnapaddjdnbilpmlacdkjdkjmbjhd] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-08-09]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-08-09]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2013-10-09]

Opera:
=======
OPR Extension: (CinemaP-1.9cV10.10) - C:\Users\Mica Petkovic\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi [2015-10-10]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-08-09] (AVAST Software)
S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [68608 2015-10-10] (globalUpdate) [File not signed] <==== ATTENTION
S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [68608 2015-10-10] (globalUpdate) [File not signed] <==== ATTENTION
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [24888 2015-07-26] (Hewlett-Packard Company)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [245832 2013-05-17] (Realtek Semiconductor)
S2 Service KMSELDI; D:\Programi\Sistem\KMSpico\Service_KMS.exe [1069248 2014-02-06] () [File not signed]
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-08-16] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 andnetadb; C:\Windows\System32\Drivers\lgandnetadb.sys [31744 2013-04-18] (Google Inc)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-08-09] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-08-09] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-08-09] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-08-09] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1048344 2015-08-15] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [447944 2015-08-09] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [150672 2015-08-09] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-08-09] (AVAST Software)
S3 b06diag; C:\Windows\system32\drivers\bxdiaga.sys [88104 2012-03-08] (Broadcom Corporation)
S3 BFN7x64; C:\Windows\system32\drivers\Xeno7x64.sys [157288 2012-02-22] (Bigfoot Networks, Inc.)
S3 bxfcoe; C:\Windows\system32\drivers\bxfcoe.sys [178216 2012-02-22] (Broadcom Corporation)
S3 bxois; C:\Windows\system32\drivers\bxois.sys [539176 2012-02-22] (Broadcom Corporation)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3341904 2012-03-26] (Broadcom Corporation)
S3 EtronSTOR; C:\Windows\System32\Drivers\EtronSTOR.sys [32512 2012-07-24] (Etron Technology Inc)
S3 RSP2STOR; C:\Windows\System32\DRIVERS\RtsP2Stor.sys [273040 2013-02-01] (Realtek Semiconductor Corp.)
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-10-13 20:23 - 2015-10-13 20:23 - 00019940 _____ C:\Users\Mica Petkovic\Desktop\FRST.txt
2015-10-13 20:23 - 2015-10-13 20:23 - 00000000 ____D C:\FRST
2015-10-13 20:21 - 2015-10-13 20:21 - 02196480 _____ (Farbar) C:\Users\Mica Petkovic\Desktop\FRST64.exe
2015-10-11 15:34 - 2015-10-11 15:34 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_lgandnetadb_01005.Wdf
2015-10-11 12:54 - 2015-10-11 12:54 - 00000000 ____D C:\Users\Mica Petkovic\Documents\LG OSP
2015-10-11 12:54 - 2015-10-11 12:54 - 00000000 ____D C:\Users\Mica Petkovic\AppData\Local\LG Electronics
2015-10-11 12:51 - 2015-10-11 15:58 - 00000000 ____D C:\Program Files (x86)\LG Electronics
2015-10-11 12:49 - 2015-10-11 12:50 - 24749088 _____ (LG Electronics) C:\Users\Mica Petkovic\Downloads\LGOSP_Setup.exe
2015-10-11 12:39 - 2015-10-13 20:09 - 00000000 ____D C:\Users\Mica Petkovic\AppData\LocalLow\uTorrent
2015-10-10 21:10 - 2015-10-10 21:10 - 227204979 _____ C:\Users\Mica Petkovic\Desktop\Sygic 15.5.3.zip
2015-10-10 20:22 - 2015-10-10 20:23 - 00063738 _____ C:\Users\Mica Petkovic\Downloads\Ispitivanje sirovog mleka oktobar.xlsx
2015-10-10 17:34 - 2015-10-10 17:58 - 00000000 ____D C:\Users\Mica Petkovic\Desktop\iGO_NextGen
2015-10-10 16:55 - 2015-10-10 16:55 - 02040701 _____ C:\Users\Mica Petkovic\Downloads\4e4f2d2d0070385dce86c400771c3b1bd3582f5766616bea0c05ec8166a16d85.mp4
2015-10-10 16:16 - 2015-10-10 16:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Daum
2015-10-10 15:36 - 2015-10-10 15:36 - 02040701 _____ C:\Users\Mica Petkovic\Desktop\4e4f2d2d0070385dce86c400771c3b1bd3582f5766616bea0c05ec8166a16d85.mp4
2015-10-10 15:35 - 2015-10-10 15:35 - 01379684 _____ C:\Users\Mica Petkovic\Desktop\43eedab6b98bb637ab9617484eafb022cffdaf4b39413fd7012fffe4e5c317f1.mp4
2015-10-10 13:18 - 2015-10-13 20:07 - 00001072 _____ C:\Windows\Tasks\Crossbrowse.job
2015-10-10 13:18 - 2015-10-10 13:26 - 00000000 ____D C:\Users\Mica Petkovic\AppData\Local\Crossbrowse
2015-10-10 13:18 - 2015-10-10 13:18 - 00004128 _____ C:\Windows\System32\Tasks\Crossbrowse
2015-10-10 13:17 - 2015-10-13 20:08 - 00001036 _____ C:\Windows\Tasks\279FnhtXLywJFfGN.job
2015-10-10 13:17 - 2015-10-13 20:07 - 00002456 _____ C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-5_user.job
2015-10-10 13:17 - 2015-10-10 13:17 - 00004092 _____ C:\Windows\System32\Tasks\279FnhtXLywJFfGN
2015-10-10 13:16 - 2015-10-13 20:16 - 00005528 _____ C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-6.job
2015-10-10 13:16 - 2015-10-13 20:16 - 00003148 _____ C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-1-6.job
2015-10-10 13:16 - 2015-10-13 20:07 - 00005528 _____ C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-7.job
2015-10-10 13:16 - 2015-10-13 20:07 - 00003148 _____ C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-1-7.job
2015-10-10 13:16 - 2015-10-13 20:07 - 00002456 _____ C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-5.job
2015-10-10 13:16 - 2015-10-12 19:21 - 00000990 _____ C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
2015-10-10 13:16 - 2015-10-10 13:16 - 00008558 _____ C:\Windows\System32\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-7
2015-10-10 13:16 - 2015-10-10 13:16 - 00008556 _____ C:\Windows\System32\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-6
2015-10-10 13:16 - 2015-10-10 13:16 - 00008224 _____ C:\Windows\System32\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-11
2015-10-10 13:16 - 2015-10-10 13:16 - 00006178 _____ C:\Windows\System32\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-1-7
2015-10-10 13:16 - 2015-10-10 13:16 - 00006176 _____ C:\Windows\System32\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-1-6
2015-10-10 13:16 - 2015-10-10 13:16 - 00005486 _____ C:\Windows\System32\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-5
2015-10-10 13:16 - 2015-10-10 13:16 - 00003988 _____ C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA
2015-10-10 13:15 - 2015-10-13 20:14 - 00002122 _____ C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-10_user.job
2015-10-10 13:15 - 2015-10-13 20:08 - 00000986 _____ C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2015-10-10 13:15 - 2015-10-13 20:07 - 00005194 _____ C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-11.job
2015-10-10 13:15 - 2015-10-13 20:07 - 00004168 _____ C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-3.job
2015-10-10 13:15 - 2015-10-10 18:15 - 00000004 _____ C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-10-10 13:15 - 2015-10-10 13:15 - 00007198 _____ C:\Windows\System32\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-3
2015-10-10 13:15 - 2015-10-10 13:15 - 00003734 _____ C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore
2015-10-10 13:15 - 2015-10-10 13:15 - 00000000 ____D C:\Users\Mica Petkovic\AppData\Local\globalUpdate
2015-10-10 13:15 - 2015-10-10 13:15 - 00000000 ____D C:\Program Files (x86)\globalUpdate
2015-10-08 20:24 - 2015-10-08 20:24 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2015-10-07 21:09 - 2015-07-11 15:15 - 00429568 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2015-10-07 21:08 - 2015-07-16 21:12 - 06131200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2015-10-07 21:08 - 2015-07-16 21:12 - 00856064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2015-10-07 21:08 - 2015-07-16 21:12 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2015-10-07 21:08 - 2015-07-16 21:11 - 07077376 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-10-07 21:08 - 2015-07-16 21:11 - 01057792 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2015-10-07 21:08 - 2015-07-16 21:11 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2015-10-07 21:08 - 2014-12-11 19:47 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-10-06 22:28 - 2015-10-08 20:24 - 00000000 ___SD C:\Windows\system32\GWX
2015-10-06 19:30 - 2013-10-02 04:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2015-10-06 19:30 - 2013-10-02 04:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2015-10-06 19:30 - 2013-10-02 04:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2015-10-06 19:30 - 2013-10-02 03:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2015-10-06 19:30 - 2013-10-02 03:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2015-10-06 19:30 - 2013-10-02 03:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2015-10-06 19:30 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2015-10-06 19:30 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2015-10-06 19:30 - 2013-10-02 01:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2015-10-06 19:30 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2015-10-06 19:26 - 2015-08-05 20:02 - 00157016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-10-06 19:26 - 2015-08-05 20:02 - 00097112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-10-06 19:26 - 2015-08-05 19:56 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-10-06 19:26 - 2015-08-05 19:56 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-10-06 19:26 - 2015-08-05 19:56 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-10-06 19:26 - 2015-08-05 19:56 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-10-06 19:26 - 2015-08-05 19:56 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-10-06 19:26 - 2015-08-05 19:56 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-10-06 19:26 - 2015-08-05 19:56 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-10-06 19:26 - 2015-08-05 19:56 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-10-06 19:26 - 2015-08-05 19:56 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-10-06 19:26 - 2015-08-05 19:56 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2015-10-06 19:26 - 2015-08-05 19:56 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-10-06 19:26 - 2015-08-05 19:56 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-10-06 19:26 - 2015-08-05 19:56 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll
2015-10-06 19:26 - 2015-08-05 19:56 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-10-06 19:26 - 2015-08-05 19:55 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-10-06 19:26 - 2015-08-05 19:55 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-10-06 19:26 - 2015-08-05 19:50 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-10-06 19:26 - 2015-08-05 19:50 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-10-06 19:26 - 2015-08-05 19:46 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-10-06 19:26 - 2015-08-05 19:41 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-10-06 19:26 - 2015-08-05 19:41 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-10-06 19:26 - 2015-08-05 19:41 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-10-06 19:26 - 2015-08-05 19:41 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-10-06 19:26 - 2015-08-05 19:40 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-10-06 19:26 - 2015-08-05 19:40 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-10-06 19:26 - 2015-08-05 19:40 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-10-06 19:26 - 2015-08-05 19:40 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2015-10-06 19:26 - 2015-08-05 19:40 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-10-06 19:26 - 2015-08-05 19:39 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2015-10-06 19:26 - 2015-08-05 19:39 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-10-06 19:26 - 2015-08-05 19:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-10-06 19:26 - 2015-08-05 19:34 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-10-06 19:26 - 2015-08-05 19:34 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-10-06 19:26 - 2015-08-05 19:30 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-10-06 19:26 - 2015-08-05 19:06 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2015-10-06 19:26 - 2015-08-05 18:38 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-10-06 19:26 - 2015-08-05 18:37 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-10-06 19:26 - 2015-08-05 18:37 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-10-06 19:23 - 2015-10-06 19:23 - 00000000 ____D C:\Users\Mica Petkovic\AppData\Local\GWX
2015-10-06 19:23 - 2015-07-18 15:08 - 00984448 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00901264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00063840 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-eventing-provider-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-eventing-provider-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2015-10-03 18:13 - 2015-10-03 18:13 - 00000000 ____D C:\Users\Mica Petkovic\.oracle_jre_usage
2015-10-02 20:45 - 2015-10-02 20:45 - 00000000 ____D C:\Users\Mica Petkovic\AppData\Roaming\Publish Providers
2015-10-02 20:37 - 2015-10-06 19:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2015-10-02 20:36 - 2015-10-06 19:18 - 00000000 ____D C:\Program Files (x86)\Sony
2015-10-02 20:36 - 2015-10-02 20:37 - 00000000 ____D C:\Users\Mica Petkovic\AppData\Local\Sony
2015-10-02 20:36 - 2015-10-02 20:37 - 00000000 ____D C:\ProgramData\Sony
2015-10-02 20:08 - 2015-10-02 20:09 - 01660697 _____ C:\Users\Mica Petkovic\Downloads\Sony.Sound.Forge.7.0.keygen.by.cat.exe.zip
2015-10-02 19:47 - 2015-10-02 19:47 - 02224352 _____ C:\Users\Mica Petkovic\Desktop\8292f3d702b4242dfe2c8415b98451369fcd6ab4657040f30e7bfe3a7ca16eb6.mp4
2015-10-02 15:55 - 2015-10-02 15:55 - 00016384 _____ C:\Users\Mica Petkovic\Downloads\rom-0
2015-10-01 21:23 - 2015-10-10 19:35 - 00000000 ____D C:\Users\Mica Petkovic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-09-27 18:33 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
2015-09-27 18:33 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll
2015-09-27 18:28 - 2015-09-27 18:29 - 66595421 _____ C:\Users\Mica Petkovic\Downloads\kodi-15.2-Isengard_rc2.exe
2015-09-24 18:47 - 2015-09-24 18:53 - 00000000 ____D C:\Users\Mica Petkovic\Desktop\fleska
2015-09-22 19:48 - 2015-09-26 18:49 - 00001860 _____ C:\Users\Mica Petkovic\Desktop\Telefonski imenik 1.10.2014. - prečica.lnk
2015-09-22 19:48 - 2015-09-26 18:49 - 00001748 _____ C:\Users\Mica Petkovic\Desktop\Tel.Otkupljivaca - prečica.lnk
2015-09-22 19:48 - 2015-09-22 19:48 - 00019915 _____ C:\Users\Mica Petkovic\Downloads\Telefonski imenik 1.10.2014..xlsx
2015-09-22 19:48 - 2015-09-22 19:48 - 00012764 _____ C:\Users\Mica Petkovic\Downloads\Tel.Otkupljivaca.xlsx
2015-09-21 20:32 - 2015-07-10 13:22 - 00922704 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxDrv.sys
2015-09-21 20:31 - 2015-07-10 13:21 - 00128592 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxUSBMon.sys
2015-09-21 20:04 - 2015-09-21 20:04 - 00000971 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk
2015-09-21 18:53 - 2015-09-21 18:53 - 00000000 ____D C:\ProgramData\Apple
2015-09-21 18:52 - 2015-09-21 18:52 - 00000000 ____D C:\Program Files\Oracle
2015-09-21 18:12 - 2015-09-21 18:14 - 00000000 ____D C:\Users\Mica Petkovic\Desktop\Sergej septembar 2015
2015-09-16 20:47 - 2015-09-16 20:47 - 00022882 _____ C:\Users\Mica Petkovic\Desktop\Ispitivanja sirovog mleka-Sept.xlsx
2015-09-15 19:51 - 2015-09-15 19:51 - 00000000 ____D C:\Users\Public\Foxit Software
2015-09-15 19:50 - 2015-09-15 19:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader
2015-09-15 19:50 - 2015-09-15 19:50 - 00000000 ____D C:\Program Files (x86)\Foxit Software
2015-09-15 19:28 - 2015-09-15 20:36 - 00000000 ____D C:\Users\Mica Petkovic\Downloads\2014.06_8.3TT_EU
2015-09-15 18:44 - 2015-10-02 20:34 - 00000000 ____D C:\Users\Mica Petkovic\AppData\Roaming\Foxit Software

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-10-13 20:24 - 2015-08-02 12:26 - 01185846 _____ C:\Windows\WindowsUpdate.log
2015-10-13 20:24 - 2015-08-01 20:00 - 00000000 ____D C:\Users\Mica Petkovic\AppData\Roaming\uTorrent
2015-10-13 20:19 - 2009-07-14 06:45 - 00026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-10-13 20:19 - 2009-07-14 06:45 - 00026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-10-13 20:12 - 2015-08-01 19:15 - 00000000 ____D C:\Users\Mica Petkovic\AppData\Roaming\ViberPC
2015-10-13 20:12 - 2015-08-01 18:45 - 00000000 ____D C:\Users\Mica Petkovic\AppData\Local\Viber
2015-10-13 20:08 - 2015-08-01 16:32 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-10-13 20:07 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-10-13 20:07 - 2009-07-14 06:51 - 00034755 _____ C:\Windows\setupact.log
2015-10-12 21:23 - 2015-08-02 11:04 - 00000000 ____D C:\Users\Mica Petkovic\Documents\Outlook Files
2015-10-12 20:48 - 2015-08-01 16:32 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-10-11 13:34 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2015-10-11 13:31 - 2015-08-01 23:05 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2015-10-11 12:40 - 2015-08-09 22:22 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2015-10-11 12:38 - 2010-11-21 05:47 - 00428336 _____ C:\Windows\PFRO.log
2015-10-10 21:13 - 2015-08-01 16:38 - 00000000 ____D C:\Temp
2015-10-10 19:21 - 2015-08-01 15:41 - 00000000 ____D C:\Users\Mica Petkovic
2015-10-10 19:19 - 2015-08-04 20:13 - 00000000 ____D C:\Program Files (x86)\Opera
2015-10-10 15:53 - 2015-09-03 21:47 - 00000000 ____D C:\Users\Mica Petkovic\.umplayer
2015-10-10 13:18 - 2015-08-01 16:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-10-10 13:15 - 2015-08-04 20:16 - 00001427 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2015-10-08 18:32 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2015-10-07 22:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\sr-Latn-CS
2015-10-07 22:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\sr-Latn-CS
2015-10-06 19:52 - 2009-07-14 05:20 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-06 18:28 - 2015-08-02 21:51 - 00000000 ____D C:\Users\Mica Petkovic\AppData\Roaming\vlc
2015-10-03 20:21 - 2009-07-14 07:13 - 00785878 _____ C:\Windows\system32\PerfStringBackup.INI
2015-10-02 20:45 - 2015-08-31 20:28 - 00000000 ____D C:\Users\Mica Petkovic\AppData\Roaming\Sony
2015-10-01 19:26 - 2015-08-04 20:16 - 00003862 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1438712178
2015-09-29 22:38 - 2015-08-01 17:18 - 00778492 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2015-09-27 18:33 - 2015-08-01 17:21 - 00000000 ____D C:\ProgramData\Package Cache
2015-09-21 20:04 - 2015-08-01 23:12 - 00000959 _____ C:\Users\Public\Desktop\TeamViewer 10.lnk
2015-09-21 19:46 - 2015-08-01 16:32 - 00000000 ____D C:\Program Files (x86)\Google
2015-09-17 19:43 - 2015-08-01 16:32 - 00003894 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-09-17 19:43 - 2015-08-01 16:32 - 00003642 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-09-15 20:35 - 2015-08-01 18:36 - 00106496 ___SH C:\Users\Mica Petkovic\Thumbs.db
2015-09-15 19:28 - 2015-08-01 16:32 - 00000000 ____D C:\Users\Mica Petkovic\AppData\Local\Google

==================== Files in the root of some directories =======

2015-04-19 14:20 - 2015-04-19 14:20 - 0005872 _____ () C:\Users\Mica Petkovic\AppData\Roaming\279FnhtXLywJFfGN
2015-04-20 16:05 - 2015-04-20 16:05 - 1579520 _____ () C:\Users\Mica Petkovic\AppData\Roaming\279FnhtXLywJFfGN.exe

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-10-12 19:54

==================== End of FRST.txt ============================
mycity.rs/must-login.png

Dopuna: 15 Okt 2015 19:46

Ima li nekog da pomogne.Koristim win7 i skoro da nista ne mogu da otvorim,stalno mi se otvaraju novi i novi tabovi sa raznim sajtovima i reklamama.

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

1. Otvori Notepad (Text Document) i iskopiraj sledeći tekst unutar kod polja ispod:

CreateRestorePoint:
Task: {015BED4F-F142-449E-B337-1C08AC1E9C5E} - System32\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-1-7 => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-1-7.exe <==== ATTENTION
Task: {03A721A3-3B23-43F0-ADB6-5FEDA31CF26E} - System32\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-6 => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-6.exe <==== ATTENTION
Task: {05A27E6C-DC1A-453F-83F9-31302ADCE5FE} - System32\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-5 => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-5.exe <==== ATTENTION
Task: {0869AD2D-343B-44F7-8AA0-D1A34A969300} - System32\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-7 => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-7.exe <==== ATTENTION
Task: {09B06870-D43B-4E85-8413-53621808CF1B} - System32\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-3 => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-3.exe <==== ATTENTION
Task: {11FC0104-12D7-410E-9983-F280D9424491} - System32\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-5_user => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-5.exe <==== ATTENTION
Task: {15CCFB78-6D16-420F-B6C8-D770D6E50F3C} - System32\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-10_user => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-10.exe <==== ATTENTION
Task: {2547CC0D-380C-44EC-915A-51B0B9ABE4DF} - System32\Tasks\Crossbrowse => C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\utility.exe <==== ATTENTION
Task: {6C3F1E12-AB2E-4D52-9A23-CF81A0CFA770} - System32\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-11 => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-11.exe <==== ATTENTION
Task: {86D4543A-6FF6-4866-B3BD-AFE65DB18088} - System32\Tasks\globalUpdateUpdateTaskMachineUA => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [2015-10-10] (globalUpdate) <==== ATTENTION
Task: {AE04567C-87EE-48D1-B30F-4366CB2F53CE} - System32\Tasks\279FnhtXLywJFfGN => C:\Users\Mica Petkovic\AppData\Roaming\279FnhtXLywJFfGN.exe [2015-04-20] () <==== ATTENTION
Task: {CC73D48F-A07D-4101-BE71-9D40733F3135} - System32\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-1-6 => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-1-6.exe <==== ATTENTION
Task: {E939C4D1-2F39-4118-AB43-D830A08244CE} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [2015-10-10] (globalUpdate) <==== ATTENTION
Task: C:\Windows\Tasks\279FnhtXLywJFfGN.job => C:\Users\Mica Petkovic\AppData\Roaming\279FnhtXLywJFfGN.exe <==== ATTENTION
Task: C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-1-6.job => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-1-6.exe <==== ATTENTION
Task: C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-1-7.job => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-1-7.exe <==== ATTENTION
Task: C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-10_user.job => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-10.exe <==== ATTENTION
Task: C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-11.job => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-11.exe <==== ATTENTION
Task: C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-3.job => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-3.exe <==== ATTENTION
Task: C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-5.job => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-5_user.job => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-6.job => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-6.exe <==== ATTENTION
Task: C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-7.job => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-7.exe <==== ATTENTION
Task: C:\Windows\Tasks\Crossbrowse.job => C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\utility.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe <==== ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKU\S-1-5-21-1715614436-2009014575-3900974691-1001 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKU\S-1-5-21-1715614436-2009014575-3900974691-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
CHR StartupUrls: Default -> "hxxp://www.google.com/","hxxp://www.oursurfing.com/?type=hp&ts=1444475701&z=7513ebe44ecd2b09e7b64ecgez4z0z3zcm1wem0e2g&from=amt&uid=hgstxhts545050a7e380_te85134ngdlt9rgdlt9rx"
CHR Extension: (CinemaP-1.9cV10.10) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi [2015-10-10]
OPR Extension: (CinemaP-1.9cV10.10) - C:\Users\Mica Petkovic\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi [2015-10-10]
S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [68608 2015-10-10] (globalUpdate) [File not signed] <==== ATTENTION
S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [68608 2015-10-10] (globalUpdate) [File not signed] <==== ATTENTION
C:\Program Files (x86)\globalUpdate
C:\Program Files (x86)\CinemaP-1.9cV10.10
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [2015-10-10] (globalUpdate)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [2015-10-10] (globalUpdate)
EmptyTemp:


2. Sačuvaj notepad na Desktop pod nazivom fixlist.txt
To možes uraditi i iz notepad-a => klik na File potom na Save As i u novom prozoru, dole pod File Name: staviš za naziv fixlist.txt
Napomena: Važno je da se oba fajla, FRST i fixlist nalaze na istoj lokaciji jer u suprotnom fix nece raditi.

3. Ponovo pokreni FRST/FRST64, klikni jednom na dugme Fix i sačekaj.
Ukoliko alat zatraži restart sistema, dozvoli mu i postaraj se da alat kompletira fix nakon restarta sistema.



Alat će formirati log (Fixlog.txt) na Desktop-u. Potrebno je sadržaj tog loga iskopirati u poruku.
Napomena: Ukoliko te alat upozori da postoji novija verzija, postaraj se da preuzmes i koristiš ažuriranu kopiju FRST-a.

offline
  • Pridružio: 06 Feb 2013
  • Poruke: 104
  • Gde živiš: Zajecar

Napisano: 15 Okt 2015 20:38

Fix result of Farbar Recovery Scan Tool (x64) Version:15-10-2015
Ran by Mica Petkovic (2015-10-15 20:27:40) Run:1
Running from C:\Users\Mica Petkovic\Desktop
Loaded Profiles: Mica Petkovic (Available Profiles: Mica Petkovic)
Boot Mode: Normal
==============================================

fixlist content:
*****************
CreateRestorePoint:
Task: {015BED4F-F142-449E-B337-1C08AC1E9C5E} - System32\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-1-7 => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-1-7.exe <==== ATTENTION
Task: {03A721A3-3B23-43F0-ADB6-5FEDA31CF26E} - System32\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-6 => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-6.exe <==== ATTENTION
Task: {05A27E6C-DC1A-453F-83F9-31302ADCE5FE} - System32\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-5 => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-5.exe <==== ATTENTION
Task: {0869AD2D-343B-44F7-8AA0-D1A34A969300} - System32\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-7 => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-7.exe <==== ATTENTION
Task: {09B06870-D43B-4E85-8413-53621808CF1B} - System32\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-3 => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-3.exe <==== ATTENTION
Task: {11FC0104-12D7-410E-9983-F280D9424491} - System32\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-5_user => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-5.exe <==== ATTENTION
Task: {15CCFB78-6D16-420F-B6C8-D770D6E50F3C} - System32\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-10_user => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-10.exe <==== ATTENTION
Task: {2547CC0D-380C-44EC-915A-51B0B9ABE4DF} - System32\Tasks\Crossbrowse => C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\utility.exe <==== ATTENTION
Task: {6C3F1E12-AB2E-4D52-9A23-CF81A0CFA770} - System32\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-11 => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-11.exe <==== ATTENTION
Task: {86D4543A-6FF6-4866-B3BD-AFE65DB18088} - System32\Tasks\globalUpdateUpdateTaskMachineUA => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [2015-10-10] (globalUpdate) <==== ATTENTION
Task: {AE04567C-87EE-48D1-B30F-4366CB2F53CE} - System32\Tasks\279FnhtXLywJFfGN => C:\Users\Mica Petkovic\AppData\Roaming\279FnhtXLywJFfGN.exe [2015-04-20] () <==== ATTENTION
Task: {CC73D48F-A07D-4101-BE71-9D40733F3135} - System32\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-1-6 => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-1-6.exe <==== ATTENTION
Task: {E939C4D1-2F39-4118-AB43-D830A08244CE} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [2015-10-10] (globalUpdate) <==== ATTENTION
Task: C:\Windows\Tasks\279FnhtXLywJFfGN.job => C:\Users\Mica Petkovic\AppData\Roaming\279FnhtXLywJFfGN.exe <==== ATTENTION
Task: C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-1-6.job => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-1-6.exe <==== ATTENTION
Task: C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-1-7.job => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-1-7.exe <==== ATTENTION
Task: C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-10_user.job => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-10.exe <==== ATTENTION
Task: C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-11.job => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-11.exe <==== ATTENTION
Task: C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-3.job => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-3.exe <==== ATTENTION
Task: C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-5.job => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-5_user.job => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-6.job => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-6.exe <==== ATTENTION
Task: C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-7.job => C:\Program Files (x86)\CinemaP-1.9cV10.10\b293f196-7f04-4f95-9b88-e865ef27a0d4-7.exe <==== ATTENTION
Task: C:\Windows\Tasks\Crossbrowse.job => C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\utility.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe <==== ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKU\S-1-5-21-1715614436-2009014575-3900974691-1001 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKU\S-1-5-21-1715614436-2009014575-3900974691-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
CHR StartupUrls: Default -> "hxxp://www.google.com/","hxxp://www.oursurfing.com/?type=hp&ts=1444475701&z=7513ebe44ecd2b09e7b64ecgez4z0z3zcm1wem0e2g&from=amt&uid=hgstxhts545050a7e380_te85134ngdlt9rgdlt9rx"
CHR Extension: (CinemaP-1.9cV10.10) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi [2015-10-10]
OPR Extension: (CinemaP-1.9cV10.10) - C:\Users\Mica Petkovic\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi [2015-10-10]
S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [68608 2015-10-10] (globalUpdate) [File not signed] <==== ATTENTION
S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [68608 2015-10-10] (globalUpdate) [File not signed] <==== ATTENTION
C:\Program Files (x86)\globalUpdate
C:\Program Files (x86)\CinemaP-1.9cV10.10
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [2015-10-10] (globalUpdate)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [2015-10-10] (globalUpdate)
EmptyTemp:
*****************

Restore point was successfully created.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{015BED4F-F142-449E-B337-1C08AC1E9C5E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{015BED4F-F142-449E-B337-1C08AC1E9C5E}" => key removed successfully
C:\Windows\System32\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-1-7 => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\b293f196-7f04-4f95-9b88-e865ef27a0d4-1-7" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{03A721A3-3B23-43F0-ADB6-5FEDA31CF26E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{03A721A3-3B23-43F0-ADB6-5FEDA31CF26E}" => key removed successfully
C:\Windows\System32\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-6 => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\b293f196-7f04-4f95-9b88-e865ef27a0d4-6" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{05A27E6C-DC1A-453F-83F9-31302ADCE5FE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{05A27E6C-DC1A-453F-83F9-31302ADCE5FE}" => key removed successfully
C:\Windows\System32\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-5 => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\b293f196-7f04-4f95-9b88-e865ef27a0d4-5" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0869AD2D-343B-44F7-8AA0-D1A34A969300}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0869AD2D-343B-44F7-8AA0-D1A34A969300}" => key removed successfully
C:\Windows\System32\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-7 => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\b293f196-7f04-4f95-9b88-e865ef27a0d4-7" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{09B06870-D43B-4E85-8413-53621808CF1B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{09B06870-D43B-4E85-8413-53621808CF1B}" => key removed successfully
C:\Windows\System32\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-3 => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\b293f196-7f04-4f95-9b88-e865ef27a0d4-3" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{11FC0104-12D7-410E-9983-F280D9424491}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{11FC0104-12D7-410E-9983-F280D9424491}" => key removed successfully
C:\Windows\System32\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-5_user => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\b293f196-7f04-4f95-9b88-e865ef27a0d4-5_user" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{15CCFB78-6D16-420F-B6C8-D770D6E50F3C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{15CCFB78-6D16-420F-B6C8-D770D6E50F3C}" => key removed successfully
C:\Windows\System32\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-10_user => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\b293f196-7f04-4f95-9b88-e865ef27a0d4-10_user" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{2547CC0D-380C-44EC-915A-51B0B9ABE4DF}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2547CC0D-380C-44EC-915A-51B0B9ABE4DF}" => key removed successfully
C:\Windows\System32\Tasks\Crossbrowse => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Crossbrowse" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6C3F1E12-AB2E-4D52-9A23-CF81A0CFA770}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6C3F1E12-AB2E-4D52-9A23-CF81A0CFA770}" => key removed successfully
C:\Windows\System32\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-11 => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\b293f196-7f04-4f95-9b88-e865ef27a0d4-11" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{86D4543A-6FF6-4866-B3BD-AFE65DB18088}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{86D4543A-6FF6-4866-B3BD-AFE65DB18088}" => key removed successfully
C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineUA" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{AE04567C-87EE-48D1-B30F-4366CB2F53CE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AE04567C-87EE-48D1-B30F-4366CB2F53CE}" => key removed successfully
C:\Windows\System32\Tasks\279FnhtXLywJFfGN => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\279FnhtXLywJFfGN" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{CC73D48F-A07D-4101-BE71-9D40733F3135}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CC73D48F-A07D-4101-BE71-9D40733F3135}" => key removed successfully
C:\Windows\System32\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-1-6 => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\b293f196-7f04-4f95-9b88-e865ef27a0d4-1-6" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E939C4D1-2F39-4118-AB43-D830A08244CE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E939C4D1-2F39-4118-AB43-D830A08244CE}" => key removed successfully
C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineCore" => key removed successfully
C:\Windows\Tasks\279FnhtXLywJFfGN.job => moved successfully
C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-1-6.job => moved successfully
C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-1-7.job => moved successfully
C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-10_user.job => moved successfully
C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-11.job => moved successfully
C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-3.job => moved successfully
C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-5.job => moved successfully
C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-5_user.job => moved successfully
C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-6.job => moved successfully
C:\Windows\Tasks\b293f196-7f04-4f95-9b88-e865ef27a0d4-7.job => moved successfully
C:\Windows\Tasks\Crossbrowse.job => moved successfully
C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => moved successfully
C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => moved successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => key removed successfully
HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => key removed successfully
HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key not found.
HKU\S-1-5-21-1715614436-2009014575-3900974691-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
"HKU\S-1-5-21-1715614436-2009014575-3900974691-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => key removed successfully
HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key not found.
Chrome StartupUrls => removed successfully
C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi => moved successfully
C:\Users\Mica Petkovic\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi => moved successfully
globalUpdate => service removed successfully
globalUpdatem => service removed successfully
C:\Program Files (x86)\globalUpdate => moved successfully
"C:\Program Files (x86)\CinemaP-1.9cV10.10" => File/Folder not found.
"HKLM\Software\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10" => key removed successfully
C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll => not found.
"HKLM\Software\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4" => key removed successfully
C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll => not found.
EmptyTemp: => 1.1 GB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 20:30:10 ====

Dopuna: 15 Okt 2015 20:40

vec je bolje ne otvara se oursurfing.

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Preuzmi "Xplode"-ov AdwCleaner () i sacuvaj ga na Desktop

Dvoklikom pokreni program.
Klikni na dugme [Scan] i pricekaj da program zavrsi.
Klikni na dugme [Clean]
Program ce zatvoriti sve aktivne programe i izbaciti prozor sa tim upozorenjem. Klikni Ok kao potvrdu.
Na sledeca dva prozora koja se otvore (Informations i Restart required ) klikni Ok


Racunar ce se restartovati a potom otvoriti notepad (C:\AdwCleaner[S1].txt) sa izvestajem.
Sacuvaj taj notepad na Desktop i okaci ga uz poruku koristeci opciju "Prikaci fajl"

Napomena: Izvestaj ce takodje biti sacuvan na C:\AdwCleaner[S0].txt
-----

Preuzmi Junkware Removal Tool ( JRT ) i sacuvaj ga na desktop.

zatvori browser i ostale pokrenute programe;
Jel potrebno navesti napomenu za duzinu scana? Da postavim ovaj PG ili nema potrebe za tim?

Privremeno deaktiviraj zastitni softver (Uputstvo);

dvoklikom na ikonicu ( )pokreni program JRT;

Kod obavestenja "press any key" pritisnuti bilo koji taster i alat ce zapoceti skeniranje.
Napomena: u ovisnosti od sistemske specifikacije vreme skeniranja u nekim slucajevima moze da potraje.

Kada zavrsi otvorice se log sa izvestajem koji ce biti sacuvan na desktopu pod nazivom JRT.txt


Arrow Kopiraj sadrzaj tog loga u temu.

offline
  • Pridružio: 06 Feb 2013
  • Poruke: 104
  • Gde živiš: Zajecar

mycity.rs/must-login.png
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.4 (09.28.2015:1)
OS: Windows 7 Ultimate x64
Ran by Mica Petkovic on 15-Oct-15 at 21:21:02.79
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Tasks



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] (Default) REG_SZ Crossbrowse



~~~ Files



~~~ Folders



~~~ Chrome


[C:\Users\Mica Petkovic\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset

[C:\Users\Mica Petkovic\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:

[C:\Users\Mica Petkovic\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset

[C:\Users\Mica Petkovic\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 15-Oct-15 at 21:25:48.35
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Ponovo se vratio our surfing

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Postavi mi novi FRST log i Addition.

offline
  • Pridružio: 06 Feb 2013
  • Poruke: 104
  • Gde živiš: Zajecar

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:15-10-2015
Ran by Mica Petkovic (administrator) on MICAPETKOVIC-PC (15-10-2015 21:44:27)
Running from C:\Users\Mica Petkovic\Desktop
Loaded Profiles: Mica Petkovic (Available Profiles: Mica Petkovic)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: engleski (SAD)
Internet Explorer Version 10 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: geekstogo.com/forum/topic/335081-frst-t.....scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
() D:\Programi\Sistem\KMSpico\Service_KMS.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6111824 2015-08-26] (AVAST Software)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1715614436-2009014575-3900974691-1001\...\Run: [MCShield Monitor] => D:\Programi\Internet\MCShield\mcshieldrtm.exe
HKU\S-1-5-21-1715614436-2009014575-3900974691-1001\...\Run: [Viber] => C:\Users\Mica Petkovic\AppData\Local\Viber\Viber.exe [72389840 2015-07-15] ()
HKU\S-1-5-21-1715614436-2009014575-3900974691-1001\...\Run: [uTorrent] => C:\Users\Mica Petkovic\AppData\Roaming\uTorrent\uTorrent.exe [1821536 2015-09-26] (BitTorrent Inc.)
HKU\S-1-5-21-1715614436-2009014575-3900974691-1001\...\RunOnce: [Uninstall C:\Users\Mica Petkovic\AppData\Local\Microsoft\OneDrive\17.3.5907.0716] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Mica Petkovic\AppData\Local\Microsoft\OneDrive\17.3.5907.0716"
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-08-09] (AVAST Software)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{64EC62AA-4EE8-490C-AC62-B42FEB41D835}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKU\S-1-5-21-1715614436-2009014575-3900974691-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-08-09] (AVAST Software)
BHO: Skype add-on for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll [2015-08-28] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-08-09] (AVAST Software)
BHO-x32: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-08-28] (Oracle Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)

FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> D:\Programi\Muzika\VLC\npvlc.dll [2015-04-16] (VideoLAN)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2014-04-15] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2014-04-15] (Foxit Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-08-28] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-08-28] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin-x32: @verimatrix.com/ViewRightWeb -> C:\Program Files (x86)\Verimatrix\ViewRight Web\\npViewRight.dll [2014-06-10] (Verimatrix, Inc.)
FF Plugin HKU\S-1-5-21-1715614436-2009014575-3900974691-1001: @verimatrix.com/ViewRightWeb -> C:\Program Files (x86)\Verimatrix\ViewRight Web\\npViewRight.dll [2014-06-10] (Verimatrix, Inc.)
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-08-09]

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com/ig?rls=ig&hl=sr&source=iglk
CHR StartupUrls: Default -> "hxxp://www.google.com/","hxxp://www.oursurfing.com/?type=hp&ts=1444475701&z=7513ebe44ecd2b09e7b64ecgez4z0z3zcm1wem0e2g&from=amt&uid=hgstxhts545050a7e380_te85134ngdlt9rgdlt9rx"
CHR Profile: C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google преводилац) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2015-08-01]
CHR Extension: (Google презентације) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-08-01]
CHR Extension: (Google документи) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-01]
CHR Extension: (Google диск) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-08-01]
CHR Extension: (YouTube) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-08-01]
CHR Extension: (OneTab) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\chphlpgkkbolifaimnlloiipkdnihall [2015-10-15]
CHR Extension: (Google Search) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-08-01]
CHR Extension: (Google табеле) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-08-01]
CHR Extension: (Mini Radio Player) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffeaebedjghkdbccfenjbiilalegknlj [2015-08-01]
CHR Extension: (Google документи офлајн) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-03]
CHR Extension: (Porsche) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkclphmapdcppbmekmbkcjfanpmoidpg [2015-08-01]
CHR Extension: (Avast Online Security) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-08-10]
CHR Extension: (SearchPreview) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcjdanpjacpeeppdjkppebobilhaglfo [2015-08-01]
CHR Extension: (CloudConvert) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfpmbfgodkfcebpgheiedaddoikmljkk [2015-09-02]
CHR Extension: (Skype Click to Call) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2015-08-02]
CHR Extension: (Bleaner) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi [2015-10-15]
CHR Extension: (Google Dictionary (by Google)) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja [2015-08-01]
CHR Extension: (Google провера поште) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2015-08-01]
CHR Extension: (LocalChromecast Player) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmladpigjlinmngadjgfogblnmddndcp [2015-10-01]
CHR Extension: (Плаћања у Chrome веб-продавници) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-01]
CHR Extension: (Auto-Translate) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\obgoiaeapddkeekbocomnjlckbbfapmk [2015-09-04]
CHR Extension: (Audio Converter) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojfphighcpfimfhblaigjckljcoeipga [2015-09-02]
CHR Extension: (Gmail) - C:\Users\Mica Petkovic\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-01]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1715614436-2009014575-3900974691-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bknbnapaddjdnbilpmlacdkjdkjmbjhd] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [bknbnapaddjdnbilpmlacdkjdkjmbjhd] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-08-09]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-08-09]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2013-10-09]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-08-09] (AVAST Software)
S2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [24888 2015-07-26] (Hewlett-Packard Company)
S2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [245832 2013-05-17] (Realtek Semiconductor)
S2 Service KMSELDI; D:\Programi\Sistem\KMSpico\Service_KMS.exe [1069248 2014-02-06] () [File not signed]
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-08-16] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-08-09] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-08-09] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-08-09] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-08-09] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1048344 2015-08-15] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [447944 2015-08-09] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [150672 2015-08-09] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-08-09] (AVAST Software)
S3 b06diag; C:\Windows\system32\drivers\bxdiaga.sys [88104 2012-03-08] (Broadcom Corporation)
S3 BFN7x64; C:\Windows\system32\drivers\Xeno7x64.sys [157288 2012-02-22] (Bigfoot Networks, Inc.)
S3 bxfcoe; C:\Windows\system32\drivers\bxfcoe.sys [178216 2012-02-22] (Broadcom Corporation)
S3 bxois; C:\Windows\system32\drivers\bxois.sys [539176 2012-02-22] (Broadcom Corporation)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3341904 2012-03-26] (Broadcom Corporation)
S3 EtronSTOR; C:\Windows\System32\Drivers\EtronSTOR.sys [32512 2012-07-24] (Etron Technology Inc)
S3 RSP2STOR; C:\Windows\System32\DRIVERS\RtsP2Stor.sys [273040 2013-02-01] (Realtek Semiconductor Corp.)
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-10-15 21:44 - 2015-10-15 21:44 - 00016607 _____ C:\Users\Mica Petkovic\Desktop\FRST.txt
2015-10-15 21:25 - 2015-10-15 21:26 - 00001172 _____ C:\Users\Mica Petkovic\Desktop\JRT.txt
2015-10-15 21:18 - 2015-10-15 21:18 - 00013034 _____ C:\Users\Mica Petkovic\Desktop\AdwCleaner[C1].txt
2015-10-15 21:11 - 2015-10-15 21:15 - 00000000 ____D C:\AdwCleaner
2015-10-15 21:10 - 2015-10-15 21:10 - 01801288 _____ (Malwarebytes) C:\Users\Mica Petkovic\Desktop\JRT.exe
2015-10-15 21:07 - 2015-10-15 21:07 - 01682432 _____ C:\Users\Mica Petkovic\Desktop\AdwCleaner.exe
2015-10-15 20:28 - 2015-10-15 20:29 - 02196992 _____ (Farbar) C:\Users\Mica Petkovic\Downloads\FRST64.exe
2015-10-15 20:25 - 2015-10-15 20:26 - 02196992 _____ (Farbar) C:\Users\Mica Petkovic\Desktop\FRST64.exe
2015-10-14 22:05 - 2015-09-18 21:22 - 00025432 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2015-10-14 22:05 - 2015-09-18 21:19 - 01291264 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-10-14 22:05 - 2015-09-18 21:19 - 00766464 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-10-14 22:05 - 2015-09-18 21:19 - 00700416 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-10-14 22:05 - 2015-09-18 21:19 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-10-14 22:05 - 2015-09-18 21:19 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-10-14 22:05 - 2015-09-18 21:09 - 01163776 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-10-14 22:05 - 2015-08-06 20:04 - 14176768 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-10-14 22:05 - 2015-08-06 20:03 - 01866752 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2015-10-14 22:05 - 2015-08-06 19:44 - 12875776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2015-10-14 22:05 - 2015-08-06 19:44 - 01498624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2015-10-14 22:04 - 2015-10-01 20:06 - 00692672 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2015-10-14 22:04 - 2015-10-01 20:04 - 00616360 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2015-10-14 22:04 - 2015-10-01 20:00 - 00147456 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2015-10-14 22:04 - 2015-10-01 20:00 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2015-10-14 22:04 - 2015-10-01 20:00 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2015-10-14 22:04 - 2015-10-01 20:00 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2015-10-14 22:04 - 2015-10-01 20:00 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2015-10-14 22:04 - 2015-10-01 19:50 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2015-10-14 22:04 - 2015-09-29 05:16 - 05569472 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-10-14 22:04 - 2015-09-29 05:13 - 01730496 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-10-14 22:04 - 2015-09-29 05:11 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-10-14 22:04 - 2015-09-29 05:11 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2015-10-14 22:04 - 2015-09-29 05:11 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2015-10-14 22:04 - 2015-09-29 05:11 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-10-14 22:04 - 2015-09-29 05:11 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-10-14 22:04 - 2015-09-29 05:11 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-10-14 22:04 - 2015-09-29 05:11 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-10-14 22:04 - 2015-09-29 05:11 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2015-10-14 22:04 - 2015-09-29 05:10 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-10-14 22:04 - 2015-09-29 05:10 - 01164800 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-10-14 22:04 - 2015-09-29 05:10 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-10-14 22:04 - 2015-09-29 05:10 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-10-14 22:04 - 2015-09-29 05:10 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-10-14 22:04 - 2015-09-29 05:10 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-10-14 22:04 - 2015-09-29 05:10 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-10-14 22:04 - 2015-09-29 05:10 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2015-10-14 22:04 - 2015-09-29 05:10 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-10-14 22:04 - 2015-09-29 05:10 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-10-14 22:04 - 2015-09-29 05:10 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2015-10-14 22:04 - 2015-09-29 05:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-10-14 22:04 - 2015-09-29 05:09 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-10-14 22:04 - 2015-09-29 05:05 - 03990976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-10-14 22:04 - 2015-09-29 05:05 - 03936192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-10-14 22:04 - 2015-09-29 05:05 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-10-14 22:04 - 2015-09-29 05:05 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-10-14 22:04 - 2015-09-29 05:02 - 01311768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-10-14 22:04 - 2015-09-29 05:01 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-10-14 22:04 - 2015-09-29 05:01 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-10-14 22:04 - 2015-09-29 05:01 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 05:01 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 05:01 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 05:01 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 05:01 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 05:01 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 05:01 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 05:01 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 05:01 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 05:01 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 05:01 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 05:01 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 05:01 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 05:01 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 05:01 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 05:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 05:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 05:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 05:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 05:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 05:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 05:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 05:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 05:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 05:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 05:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 05:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 05:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 04:59 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-10-14 22:04 - 2015-09-29 04:59 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-10-14 22:04 - 2015-09-29 04:59 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-10-14 22:04 - 2015-09-29 04:59 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-10-14 22:04 - 2015-09-29 04:59 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-10-14 22:04 - 2015-09-29 04:59 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-10-14 22:04 - 2015-09-29 04:58 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-10-14 22:04 - 2015-09-29 04:58 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2015-10-14 22:04 - 2015-09-29 04:58 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-10-14 22:04 - 2015-09-29 04:58 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-10-14 22:04 - 2015-09-29 04:57 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2015-10-14 22:04 - 2015-09-29 04:57 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2015-10-14 22:04 - 2015-09-29 04:57 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2015-10-14 22:04 - 2015-09-29 04:57 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-10-14 22:04 - 2015-09-29 04:53 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-10-14 22:04 - 2015-09-29 04:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-10-14 22:04 - 2015-09-29 04:49 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-10-14 22:04 - 2015-09-29 04:49 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-10-14 22:04 - 2015-09-29 04:49 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 04:49 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 04:49 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 04:49 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 04:49 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 04:49 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 04:49 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 04:49 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 04:49 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 04:49 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 04:49 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 04:49 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 04:49 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 04:49 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 04:49 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 04:49 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 04:49 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 04:49 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 04:49 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 04:49 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 04:49 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 04:49 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 04:49 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 04:49 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 03:50 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-10-14 22:04 - 2015-09-29 03:49 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-10-14 22:04 - 2015-09-29 03:49 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-10-14 22:04 - 2015-09-29 03:43 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-10-14 22:04 - 2015-09-29 03:43 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-10-14 22:04 - 2015-09-29 03:40 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 03:40 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 03:40 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-10-14 22:04 - 2015-09-29 03:40 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-10-14 22:04 - 2015-09-25 20:07 - 03168768 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-10-14 22:04 - 2015-09-25 20:07 - 02607104 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-10-14 22:04 - 2015-09-25 20:07 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-10-14 22:04 - 2015-09-25 20:07 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-10-14 22:04 - 2015-09-25 20:07 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-10-14 22:04 - 2015-09-25 20:07 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-10-14 22:04 - 2015-09-25 20:07 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-10-14 22:04 - 2015-09-25 20:06 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-10-14 22:04 - 2015-09-25 20:06 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-10-14 22:04 - 2015-09-25 20:06 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-10-14 22:04 - 2015-09-25 20:06 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-10-14 22:04 - 2015-09-25 19:59 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-10-14 22:04 - 2015-09-25 19:59 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-10-14 22:04 - 2015-09-25 19:59 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-10-14 22:04 - 2015-09-25 19:59 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-10-14 22:04 - 2015-09-25 19:58 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-10-14 22:04 - 2015-09-15 20:17 - 00157016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-10-14 22:04 - 2015-09-15 20:17 - 00097112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-10-14 22:04 - 2015-09-15 20:11 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-10-14 22:04 - 2015-09-15 20:11 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-10-14 22:04 - 2015-09-15 20:11 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-10-14 22:04 - 2015-09-15 20:11 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-10-14 22:04 - 2015-09-15 20:11 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-10-14 22:04 - 2015-09-15 20:11 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-10-14 22:04 - 2015-09-15 20:10 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-10-14 22:04 - 2015-09-15 19:36 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-10-14 22:04 - 2015-09-15 19:36 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-10-14 22:04 - 2015-09-15 19:36 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-10-14 22:04 - 2015-09-15 19:35 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-10-14 22:03 - 2015-10-01 19:00 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2015-10-14 17:47 - 2015-10-14 17:47 - 00032143 _____ C:\Users\Mica Petkovic\Downloads\307552_1535666419_Addition (1).txt
2015-10-13 22:04 - 2015-10-15 21:18 - 00000000 ____D C:\Users\Mica Petkovic\AppData\LocalLow\uTorrent
2015-10-13 20:23 - 2015-10-15 21:44 - 00000000 ____D C:\FRST
2015-10-11 12:54 - 2015-10-11 12:54 - 00000000 ____D C:\Users\Mica Petkovic\Documents\LG OSP
2015-10-11 12:54 - 2015-10-11 12:54 - 00000000 ____D C:\Users\Mica Petkovic\AppData\Local\LG Electronics
2015-10-11 12:51 - 2015-10-11 12:51 - 00000000 ____D C:\Program Files (x86)\LG Electronics
2015-10-11 12:49 - 2015-10-11 12:50 - 24749088 _____ (LG Electronics) C:\Users\Mica Petkovic\Downloads\LGOSP_Setup.exe
2015-10-10 21:10 - 2015-10-10 21:10 - 227204979 _____ C:\Users\Mica Petkovic\Desktop\Sygic 15.5.3.zip
2015-10-10 20:22 - 2015-10-10 20:23 - 00063738 _____ C:\Users\Mica Petkovic\Downloads\Ispitivanje sirovog mleka oktobar.xlsx
2015-10-10 17:34 - 2015-10-10 17:58 - 00000000 ____D C:\Users\Mica Petkovic\Desktop\iGO_NextGen
2015-10-10 16:55 - 2015-10-10 16:55 - 02040701 _____ C:\Users\Mica Petkovic\Downloads\4e4f2d2d0070385dce86c400771c3b1bd3582f5766616bea0c05ec8166a16d85.mp4
2015-10-10 16:16 - 2015-10-14 21:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Daum
2015-10-10 15:36 - 2015-10-10 15:36 - 02040701 _____ C:\Users\Mica Petkovic\Desktop\4e4f2d2d0070385dce86c400771c3b1bd3582f5766616bea0c05ec8166a16d85.mp4
2015-10-10 15:35 - 2015-10-10 15:35 - 01379684 _____ C:\Users\Mica Petkovic\Desktop\43eedab6b98bb637ab9617484eafb022cffdaf4b39413fd7012fffe4e5c317f1.mp4
2015-10-10 13:15 - 2015-10-10 18:15 - 00000004 _____ C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-10-08 20:24 - 2015-10-14 21:44 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2015-10-07 21:09 - 2015-07-11 15:15 - 00429568 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2015-10-07 21:08 - 2015-07-16 21:12 - 06131200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2015-10-07 21:08 - 2015-07-16 21:12 - 00856064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2015-10-07 21:08 - 2015-07-16 21:12 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2015-10-07 21:08 - 2015-07-16 21:11 - 07077376 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-10-07 21:08 - 2015-07-16 21:11 - 01057792 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2015-10-07 21:08 - 2015-07-16 21:11 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2015-10-07 21:08 - 2014-12-11 19:47 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-10-06 22:28 - 2015-10-14 21:44 - 00000000 ___SD C:\Windows\system32\GWX
2015-10-06 19:30 - 2013-10-02 04:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2015-10-06 19:30 - 2013-10-02 04:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2015-10-06 19:30 - 2013-10-02 04:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2015-10-06 19:30 - 2013-10-02 03:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2015-10-06 19:30 - 2013-10-02 03:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2015-10-06 19:30 - 2013-10-02 03:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2015-10-06 19:30 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2015-10-06 19:30 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2015-10-06 19:30 - 2013-10-02 01:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2015-10-06 19:30 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2015-10-06 19:26 - 2015-08-05 19:56 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv(91).dll
2015-10-06 19:26 - 2015-08-05 19:56 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4(96).dll
2015-10-06 19:26 - 2015-08-05 19:56 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\kerberos(88).dll
2015-10-06 19:26 - 2015-08-05 19:56 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel(97).dll
2015-10-06 19:26 - 2015-08-05 19:56 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0(93).dll
2015-10-06 19:26 - 2015-08-05 19:56 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt(94).dll
2015-10-06 19:26 - 2015-08-05 19:56 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest(105).dll
2015-10-06 19:26 - 2015-08-05 19:56 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli(102).dll
2015-10-06 19:26 - 2015-08-05 19:56 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg(104).dll
2015-10-06 19:26 - 2015-08-05 19:56 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase(86).dll
2015-10-06 19:26 - 2015-08-05 19:56 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv(103).dll
2015-10-06 19:26 - 2015-08-05 19:56 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32(98).dll
2015-10-06 19:26 - 2015-08-05 19:56 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll
2015-10-06 19:26 - 2015-08-05 19:56 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp(85).dll
2015-10-06 19:26 - 2015-08-05 19:55 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass(92).exe
2015-10-06 19:26 - 2015-08-05 19:40 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase(112).dll
2015-10-06 19:26 - 2015-08-05 19:39 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4(116).dll
2015-10-06 19:26 - 2015-08-05 19:39 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli(118).dll
2015-10-06 19:26 - 2015-08-05 19:06 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2015-10-06 19:23 - 2015-10-06 19:23 - 00000000 ____D C:\Users\Mica Petkovic\AppData\Local\GWX
2015-10-06 19:23 - 2015-07-18 15:08 - 00984448 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00901264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00063840 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-eventing-provider-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-eventing-provider-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2015-10-06 19:23 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2015-10-03 18:13 - 2015-10-03 18:13 - 00000000 ____D C:\Users\Mica Petkovic\.oracle_jre_usage
2015-10-02 20:45 - 2015-10-02 20:45 - 00000000 ____D C:\Users\Mica Petkovic\AppData\Roaming\Publish Providers
2015-10-02 20:37 - 2015-10-06 19:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2015-10-02 20:36 - 2015-10-06 19:18 - 00000000 ____D C:\Program Files (x86)\Sony
2015-10-02 20:36 - 2015-10-02 20:37 - 00000000 ____D C:\Users\Mica Petkovic\AppData\Local\Sony
2015-10-02 20:36 - 2015-10-02 20:37 - 00000000 ____D C:\ProgramData\Sony
2015-10-02 20:08 - 2015-10-02 20:09 - 01660697 _____ C:\Users\Mica Petkovic\Downloads\Sony.Sound.Forge.7.0.keygen.by.cat.exe.zip
2015-10-02 19:47 - 2015-10-02 19:47 - 02224352 _____ C:\Users\Mica Petkovic\Desktop\8292f3d702b4242dfe2c8415b98451369fcd6ab4657040f30e7bfe3a7ca16eb6.mp4
2015-10-01 21:23 - 2015-10-10 19:35 - 00000000 ____D C:\Users\Mica Petkovic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-09-27 18:33 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
2015-09-27 18:33 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll
2015-09-27 18:28 - 2015-09-27 18:29 - 66595421 _____ C:\Users\Mica Petkovic\Downloads\kodi-15.2-Isengard_rc2.exe
2015-09-24 18:47 - 2015-09-24 18:53 - 00000000 ____D C:\Users\Mica Petkovic\Desktop\fleska
2015-09-22 19:48 - 2015-09-26 18:49 - 00001860 _____ C:\Users\Mica Petkovic\Desktop\Telefonski imenik 1.10.2014. - prečica.lnk
2015-09-22 19:48 - 2015-09-26 18:49 - 00001748 _____ C:\Users\Mica Petkovic\Desktop\Tel.Otkupljivaca - prečica.lnk
2015-09-22 19:48 - 2015-09-22 19:48 - 00019915 _____ C:\Users\Mica Petkovic\Downloads\Telefonski imenik 1.10.2014..xlsx
2015-09-22 19:48 - 2015-09-22 19:48 - 00012764 _____ C:\Users\Mica Petkovic\Downloads\Tel.Otkupljivaca.xlsx
2015-09-21 20:32 - 2015-07-10 13:22 - 00922704 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxDrv.sys
2015-09-21 20:31 - 2015-07-10 13:21 - 00128592 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxUSBMon.sys
2015-09-21 20:04 - 2015-09-21 20:04 - 00000971 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk
2015-09-21 18:53 - 2015-09-21 18:53 - 00000000 ____D C:\ProgramData\Apple
2015-09-21 18:52 - 2015-09-21 18:52 - 00000000 ____D C:\Program Files\Oracle
2015-09-21 18:12 - 2015-09-21 18:14 - 00000000 ____D C:\Users\Mica Petkovic\Desktop\Sergej septembar 2015
2015-09-16 20:47 - 2015-09-16 20:47 - 00022882 _____ C:\Users\Mica Petkovic\Desktop\Ispitivanja sirovog mleka-Sept.xlsx
2015-09-15 19:51 - 2015-09-15 19:51 - 00000000 ____D C:\Users\Public\Foxit Software
2015-09-15 19:50 - 2015-09-15 19:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader
2015-09-15 19:50 - 2015-09-15 19:50 - 00000000 ____D C:\Program Files (x86)\Foxit Software
2015-09-15 19:28 - 2015-09-15 20:36 - 00000000 ____D C:\Users\Mica Petkovic\Downloads\2014.06_8.3TT_EU
2015-09-15 18:44 - 2015-10-02 20:34 - 00000000 ____D C:\Users\Mica Petkovic\AppData\Roaming\Foxit Software

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-10-15 21:27 - 2009-07-14 06:45 - 00026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-10-15 21:27 - 2009-07-14 06:45 - 00026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-10-15 21:22 - 2015-08-02 12:26 - 01231491 _____ C:\Windows\WindowsUpdate.log
2015-10-15 21:18 - 2015-08-01 20:00 - 00000000 ____D C:\Users\Mica Petkovic\AppData\Roaming\uTorrent
2015-10-15 21:18 - 2015-08-01 19:15 - 00000000 ____D C:\Users\Mica Petkovic\AppData\Roaming\ViberPC
2015-10-15 21:17 - 2015-08-01 16:32 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-10-15 21:17 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-10-15 21:17 - 2009-07-14 06:51 - 00033700 _____ C:\Windows\setupact.log
2015-10-15 21:15 - 2015-08-04 20:16 - 00000998 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2015-10-15 20:48 - 2015-08-01 16:32 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-10-15 20:32 - 2010-11-21 05:47 - 00430344 _____ C:\Windows\PFRO.log
2015-10-15 20:30 - 2015-08-01 20:58 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-10-15 20:30 - 2015-08-01 20:58 - 00000000 ____D C:\Windows\system32\appraiser
2015-10-15 20:30 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\sr-Latn-CS
2015-10-15 20:30 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\sr-Latn-CS
2015-10-14 22:13 - 2015-08-01 17:42 - 00000000 ____D C:\Windows\system32\MRT
2015-10-14 22:01 - 2015-08-01 17:42 - 143481208 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-10-14 21:48 - 2015-08-09 22:22 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2015-10-14 21:45 - 2015-08-01 15:41 - 00000000 ____D C:\Users\Mica Petkovic
2015-10-14 21:44 - 2015-08-09 22:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-10-14 21:44 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2015-10-14 21:44 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-10-14 21:43 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration
2015-10-14 21:26 - 2011-04-12 10:28 - 00000000 ___RD C:\Users\Public\Recorded TV
2015-10-14 19:36 - 2015-08-01 16:38 - 00000000 ____D C:\Temp
2015-10-12 21:23 - 2015-08-02 11:04 - 00000000 ____D C:\Users\Mica Petkovic\Documents\Outlook Files
2015-10-10 19:19 - 2015-08-04 20:13 - 00000000 ____D C:\Program Files (x86)\Opera
2015-10-10 15:59 - 2015-08-01 18:45 - 00000000 ____D C:\Users\Mica Petkovic\AppData\Local\Viber
2015-10-10 15:53 - 2015-09-03 21:47 - 00000000 ____D C:\Users\Mica Petkovic\.umplayer
2015-10-10 13:18 - 2015-08-01 16:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-10-08 18:32 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2015-10-06 19:52 - 2009-07-14 05:20 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-06 18:28 - 2015-08-02 21:51 - 00000000 ____D C:\Users\Mica Petkovic\AppData\Roaming\vlc
2015-10-03 20:21 - 2009-07-14 07:13 - 00785878 _____ C:\Windows\system32\PerfStringBackup.INI
2015-10-02 20:45 - 2015-08-31 20:28 - 00000000 ____D C:\Users\Mica Petkovic\AppData\Roaming\Sony
2015-10-01 19:26 - 2015-08-04 20:16 - 00003862 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1438712178
2015-09-29 22:38 - 2015-08-01 17:18 - 00778492 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2015-09-27 18:33 - 2015-08-01 17:21 - 00000000 ____D C:\ProgramData\Package Cache
2015-09-21 20:05 - 2015-08-01 23:05 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2015-09-21 20:04 - 2015-08-01 23:12 - 00000959 _____ C:\Users\Public\Desktop\TeamViewer 10.lnk
2015-09-21 19:46 - 2015-08-01 16:32 - 00000000 ____D C:\Program Files (x86)\Google
2015-09-17 19:43 - 2015-08-01 16:32 - 00003894 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-09-17 19:43 - 2015-08-01 16:32 - 00003642 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-09-15 20:35 - 2015-08-01 18:36 - 00106496 ___SH C:\Users\Mica Petkovic\Thumbs.db
2015-09-15 19:28 - 2015-08-01 16:32 - 00000000 ____D C:\Users\Mica Petkovic\AppData\Local\Google

==================== Files in the root of some directories =======

2015-04-20 16:05 - 2015-04-20 16:05 - 1579520 _____ () C:\Users\Mica Petkovic\AppData\Roaming\279FnhtXLywJFfGN.exe

Some files in TEMP:
====================
C:\Users\Mica Petkovic\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-10-12 19:54

==================== End of FRST.txt ============================
mycity.rs/must-login.png

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

1. Otvori Notepad (Text Document) i iskopiraj sledeći tekst unutar kod polja ispod:


CreateRestorePoint:
HKU\S-1-5-21-1715614436-2009014575-3900974691-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
CHR HomePage: Default -> hxxp://www.google.com/ig?rls=ig&hl=sr&source=iglk
CHR StartupUrls: Default -> "hxxp://www.google.com/","hxxp://www.oursurfing.com/?type=hp&ts=1444475701&z=7513ebe44ecd2b09e7b64ecgez4z0z3zcm1wem0e2g&from=amt&uid=hgstxhts545050a7e380_te85134ngdlt9rgdlt9rx"
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1715614436-2009014575-3900974691-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bknbnapaddjdnbilpmlacdkjdkjmbjhd] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [bknbnapaddjdnbilpmlacdkjdkjmbjhd] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
globalupdate Helper (x32 Version: 1.3.25.0 - globalupdate Inc.) Hidden <==== ATTENTION


2. Sačuvaj notepad na Desktop pod nazivom fixlist.txt
To možes uraditi i iz notepad-a => klik na File potom na Save As i u novom prozoru, dole pod File Name: staviš za naziv fixlist.txt
Napomena: Važno je da se oba fajla, FRST i fixlist nalaze na istoj lokaciji jer u suprotnom fix nece raditi.

3. Ponovo pokreni FRST/FRST64, klikni jednom na dugme Fix i sačekaj.
Ukoliko alat zatraži restart sistema, dozvoli mu i postaraj se da alat kompletira fix nakon restarta sistema.



Alat će formirati log (Fixlog.txt) na Desktop-u. Potrebno je sadržaj tog loga iskopirati u poruku.
Napomena: Ukoliko te alat upozori da postoji novija verzija, postaraj se da preuzmes i koristiš ažuriranu kopiju FRST-a.
---------

Arrow Arrow Zatim idi u Control Panel i probaj da nadjes i deinstaliras globalupdate Helper.

-------

Preuzmi smeenk-ov zoek.zip ili zoek.rar () sa ovog ili ovog linka i sačuvaj ga na Desktop.

Raspakuj arhivu u neki folder (uputstvo), a zatim:

zatvori browser i ostale pokrenute programe;
privremeno deaktiviraj zaštitni softver ( ukoliko je to potrebno ) Uputstvo ;
dvoklikom pokreni zoek na ikonicu programa ;
pričekaj da se alat startuje ...


U beli okvir prozora iskopiraj sledeći tekst:

 
emptyclsid;
emptyfolderscheck;delete
emptyalltemp;
autoclean;
FFdefaults;
chrdefaults;
iedefaults;


Klikni na dugme i pričekaj da se skeniranje završi.


zoek ce po potrebi, restartovati Windows a na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.

Napomena:Izveštaj će biti sačuvan pod nazivom zoek-results.log na sistemskoj particiji (tipična lokacija: C:\zoek-results.log)


Arrow Kopiraj sadrzaj tog loga u poruku.

offline
  • Pridružio: 06 Feb 2013
  • Poruke: 104
  • Gde živiš: Zajecar

Napisano: 15 Okt 2015 22:59

Fix result of Farbar Recovery Scan Tool (x64) Version:15-10-2015
Ran by Mica Petkovic (2015-10-15 22:29:15) Run:2
Running from C:\Users\Mica Petkovic\Desktop
Loaded Profiles: Mica Petkovic (Available Profiles: Mica Petkovic)
Boot Mode: Normal
==============================================

fixlist content:
*****************
CreateRestorePoint:
HKU\S-1-5-21-1715614436-2009014575-3900974691-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
CHR HomePage: Default -> hxxp://www.google.com/ig?rls=ig&hl=sr&source=iglk
CHR StartupUrls: Default -> "hxxp://www.google.com/","hxxp://www.oursurfing.com/?type=hp&ts=1444475701&z=7513ebe44ecd2b09e7b64ecgez4z0z3zcm1wem0e2g&from=amt&uid=hgstxhts545050a7e380_te85134ngdlt9rgdlt9rx"
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1715614436-2009014575-3900974691-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bknbnapaddjdnbilpmlacdkjdkjmbjhd] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [bknbnapaddjdnbilpmlacdkjdkjmbjhd] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
globalupdate Helper (x32 Version: 1.3.25.0 - globalupdate Inc.) Hidden <==== ATTENTION
*****************

Restore point was successfully created.
HKU\S-1-5-21-1715614436-2009014575-3900974691-1001\Software\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache => value removed successfully
Chrome HomePage => removed successfully
Chrome StartupUrls => removed successfully
"HKLM\SOFTWARE\Google\Chrome\Extensions\flliilndjeohchalpbbcdekjklbdgfkk" => key removed successfully
"HKU\S-1-5-21-1715614436-2009014575-3900974691-1001\SOFTWARE\Google\Chrome\Extensions\bknbnapaddjdnbilpmlacdkjdkjmbjhd" => key removed successfully
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\bknbnapaddjdnbilpmlacdkjdkjmbjhd" => key removed successfully
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\flliilndjeohchalpbbcdekjklbdgfkk" => key removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}\\SystemComponent => value removed successfully

==== End of Fixlog 22:29:27 ====

Zoek.exe v5.0.0.1 Updated 15-October-2015
Tool run by Mica Petkovic on 15-Oct-15 at 22:32:35.52.
Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Mica Petkovic\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

15-Oct-15 10:33:59 PM Zoek.exe System Restore Point Created Successfully.

==== Empty Folders Check ======================

C:\PROGRA~2\Avira deleted successfully
C:\PROGRA~3\MCShield deleted successfully
C:\Users\Mica Petkovic\AppData\Roaming\Publish Providers deleted successfully

Dopuna: 15 Okt 2015 23:06

Restartovao racunar,rucno i ponovo je tu oursurfing.

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Nisi mi kopirao ceo zoek log.

Ko je trenutno na forumu
 

Ukupno su 1091 korisnika na forumu :: 55 registrovanih, 5 sakrivenih i 1031 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: _Rade, A.R.Chafee.Jr., atmel, Atomski čoban, babaroga, Bobrock1, bojank, BORUTUS, darkojbn, Dimitrise93, doklevise, DonRumataEstorski, flash12, FOX, goxin, havoc995, HrcAk47, Ilija Cvorovic, ivica976, JimmyNapoli, Karla, krkalon, Kubovac, kunktator, Leonov, Magistar78, MaksicZoran, Mi lao shu, mikrimaus, Milometer, Milos ZA, mkukoleca, Ne doznajem se u oružje, nuke92, Oscar, panzerwaffe, Parker, procesor, RJ, robert1979, Rogan33, ruger357, sasa76, sasakrajina, slonic_tonic, Smiljke, Stefan M, Sumadija34, Vlada1389, wolverined4, YugoSlav, zdrebac, zziko, Živković, 79693