Problem sa firefox-om

1

Problem sa firefox-om

offline
  • Pridružio: 28 Nov 2009
  • Poruke: 145

Napisano: 12 Feb 2015 14:15

Ne znam da li da ponovo otvaram istu temu ili samo da prekopiram link sa teme sa koje su me uputili ovde?
Uglavnom evo te teme:
mycity.rs/Web-browseri/Problem-sa-firefox-om-2.html
Pa ako moze neka pomoc?
Hvala unapred.

Dopuna: 12 Feb 2015 14:22

Evo i fajlova:
mycity.rs/must-login.png
mycity.rs/must-login.png


temScan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-02-2015 02
Ran by Aleksandar (administrator) on ALEKSANDAR-PC on 12-02-2015 14:16:52
Running from C:\Users\Aleksandar\Desktop
Loaded Profiles: Aleksandar (Available profiles: Aleksandar)
Platform: Windows 8.1 Pro (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: geekstogo.com/forum/topic/335081-frst-t.....scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Stardock Software, Inc) C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe
(Stardock Software, Inc) C:\Program Files (x86)\Stardock\Start8\Start8_64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
(Microsoft©) C:\Program Files (x86)\Windows Installer\msiupd.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
() C:\Program Files (x86)\Rainlendar2\Rainlendar2.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\egui.exe [6330568 2013-03-21] (ESET)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
HKU\S-1-5-21-3188151745-266478930-1470971803-1001\...\Run: [Rainlendar2] => C:\Program Files (x86)\Rainlendar2\Rainlendar2.exe [2587136 2012-12-29] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Aggiorna ESET license.lnk
ShortcutTarget: Aggiorna ESET license.lnk -> C:\Program Files (x86)\ESET\MiNODLogin\launcher.exe (GuillerSoft)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

ProxyEnable: [HKLM] => ProxyEnable is set.
ProxyEnable: [HKLM-x32] => ProxyEnable is set.
ProxyServer: [HKLM] => http=127.0.0.1:8080;https=127.0.0.1:8080
ProxyServer: [HKLM-x32] => http=127.0.0.1:8080;https=127.0.0.1:8080
HKU\S-1-5-21-3188151745-266478930-1470971803-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = msn.com/?ocid=iehp
BHO: SavePass 1.1 -> {11111111-1111-1111-1111-110611341129} -> No File
BHO: Sense -> {11111111-1111-1111-1111-110611901159} -> No File
BHO: Ge-Force -> {11111111-1111-1111-1111-110611911129} -> No File
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: BHOImpl Class -> {E1499FE7-129D-4B6E-B681-DDF21E14172C} -> No File
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll (Oracle Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: BHOImpl Class -> {E1499FE7-129D-4B6E-B681-DDF21E14172C} -> No File
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF ProfilePath: C:\Users\Aleksandar\AppData\Roaming\Mozilla\Firefox\Profiles\qgilhvod.default
FF NewTab: chrome://fvd.speeddial/content/fvd_about_blank.html
FF Homepage: chrome://fvd.speeddial/content/fvd_about_blank.html
FF Plugin: @itools.hk/npiTools, version=1.0.0 -> C:\Users\Aleksandar\Documents\iTools\Plugin\npiTools.dll No File
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @itools.hk/npiTools, version=1.0.0 -> C:\Users\Aleksandar\Documents\iTools\Plugin\npiTools.dll No File
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)
FF Extension: Ant Video Downloader - C:\Users\Aleksandar\AppData\Roaming\Mozilla\Firefox\Profiles\qgilhvod.default\Extensions\anttoolbar@ant.com [2015-02-07]
FF Extension: Speed Dial [FVD] - New Tab Page, Sync... - C:\Users\Aleksandar\AppData\Roaming\Mozilla\Firefox\Profiles\qgilhvod.default\Extensions\pavel.sherbakov@gmail.com [2015-02-07]
FF Extension: Element Hiding Helper for Adblock Plus - C:\Users\Aleksandar\AppData\Roaming\Mozilla\Firefox\Profiles\qgilhvod.default\Extensions\elemhidehelper@adblockplus.org.xpi [2015-02-07]
FF Extension: OmniSidebar - C:\Users\Aleksandar\AppData\Roaming\Mozilla\Firefox\Profiles\qgilhvod.default\Extensions\osb@quicksaver.xpi [2015-02-07]
FF Extension: Secure Login - C:\Users\Aleksandar\AppData\Roaming\Mozilla\Firefox\Profiles\qgilhvod.default\Extensions\secureLogin@blueimp.net.xpi [2015-02-07]
FF Extension: Download Tab - C:\Users\Aleksandar\AppData\Roaming\Mozilla\Firefox\Profiles\qgilhvod.default\Extensions\{a949831f-d9c0-45ae-8c60-91c2a86fbfb6}.xpi [2015-02-08]
FF Extension: Adblock Plus - C:\Users\Aleksandar\AppData\Roaming\Mozilla\Firefox\Profiles\qgilhvod.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-02-07]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2014-07-09]

Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [jbolfgndggfhhpbnkgnpjkfhinclbigj] - No Path

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1341664 2013-03-21] (ESET)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed]
R2 msiupd.exe; C:\Program Files (x86)\Windows Installer\msiupd.exe [28160 2015-01-17] (Microsoft©) [File not signed]
R2 Start8; C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe [142960 2013-03-19] (Stardock Software, Inc)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2145080 2014-06-16] (TuneUp Software)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 anvsnddrv; C:\Windows\system32\drivers\anvsnddrv.sys [33872 2011-11-28] (AnvSoft Inc.)
U3 dtscsidrv; C:\Windows\System32\Drivers\dtscsidrv.sys [309248 2014-11-23] (Disc Soft Ltd)
R3 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-07-08] (Disc Soft Ltd)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [213416 2013-02-20] (ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [150616 2013-01-10] (ESET)
R2 epfw; C:\Windows\system32\DRIVERS\epfw.sys [190232 2013-01-10] (ESET)
R1 EpfwLWF; C:\Windows\system32\DRIVERS\EpfwLWF.sys [59440 2013-01-10] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [58416 2013-02-20] (ESET)
R3 PAC207; C:\Windows\system32\DRIVERS\PFC027.SYS [686592 2009-06-25] (PixArt Imaging Inc.)
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19152 2013-09-30] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] ()
R3 RTL8023x64; C:\Windows\system32\DRIVERS\Rtnic64.sys [51712 2013-06-18] (Realtek Semiconductor Corporation )
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [386680 2014-11-23] (Duplex Secure Ltd.)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [14112 2014-03-26] (TuneUp Software)
U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] ()
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2014-08-15] (Apple, Inc.) [File not signed]
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)
R2 {C5F942FD-1110-4664-86CE-0C6BDA305235}; C:\Program Files (x86)\CyberLink\PowerDVD14\Common\NavFilter\000.fcl [32456 2014-11-04] (CyberLink Corp.)
S2 sbmntr; \??\C:\PROGRA~2\YTDOWN~1\sbmntr.sys [X]
S2 SPDRIVER_1459.0.0.0; \??\C:\Program Files (x86)\ShopperPro\JSDriver\1459.0.0.0\jsdrv.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-12 14:16 - 2015-02-12 14:17 - 00011516 _____ () C:\Users\Aleksandar\Desktop\FRST.txt
2015-02-12 14:16 - 2015-02-12 14:16 - 02134016 _____ (Farbar) C:\Users\Aleksandar\Desktop\FRST64.exe
2015-02-12 14:16 - 2015-02-12 14:16 - 00000000 ____D () C:\FRST
2015-02-12 13:57 - 2015-02-12 13:57 - 00000000 ___HD () C:\Users\Aleksandar\Desktop\[Originals]
2015-02-12 13:56 - 2015-02-12 13:56 - 00961200 _____ (Adobe Systems Incorporated) C:\Users\Aleksandar\Desktop\uninstall_flash_player.exe
2015-02-12 13:56 - 2015-02-12 13:56 - 00000000 ____D () C:\Users\Aleksandar\Desktop\New folder
2015-02-12 13:43 - 2015-02-12 13:43 - 00000000 ____D () C:\9981f042654b424c72dc
2015-02-12 12:29 - 2015-02-12 12:29 - 00803721 _____ () C:\Users\Aleksandar\Desktop\STRIPOVI.rar
2015-02-12 12:28 - 2015-02-12 12:29 - 00000000 ____D () C:\Users\Aleksandar\Desktop\STRIPOVI
2015-02-12 11:36 - 2015-02-12 11:48 - 00000350 _____ () C:\Users\Aleksandar\Desktop\New Text Document.txt
2015-02-12 10:34 - 2015-02-12 10:35 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-02-12 10:34 - 2015-02-12 10:34 - 00001114 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-02-12 10:34 - 2015-02-12 10:34 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-02-12 10:34 - 2015-02-12 10:34 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-02-12 10:34 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-02-12 10:34 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-02-12 10:34 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-02-12 10:33 - 2015-02-12 10:34 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Aleksandar\Desktop\mbam-setup-2.0.4.1028.exe
2015-02-11 21:52 - 2015-02-11 21:52 - 00000000 ____D () C:\Users\Public\Documents\RootGenius
2015-02-11 21:52 - 2015-02-11 21:52 - 00000000 ____D () C:\Users\Aleksandar\.android
2015-02-11 20:46 - 2015-02-11 20:47 - 04954744 _____ () C:\Users\Aleksandar\Desktop\RootGenius_en.exe
2015-02-11 20:25 - 2015-02-11 20:25 - 00001210 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\One Click Root.lnk
2015-02-11 20:25 - 2015-02-11 20:25 - 00001198 _____ () C:\Users\Public\Desktop\One Click Root.lnk
2015-02-11 20:25 - 2015-02-11 20:25 - 00000000 ____D () C:\Users\Aleksandar\AppData\Roaming\One Click Root
2015-02-11 20:25 - 2015-02-11 20:25 - 00000000 ____D () C:\Users\Aleksandar\AppData\Local\AWSToolkit
2015-02-11 20:25 - 2015-02-11 20:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\One Click Root
2015-02-11 20:25 - 2015-02-11 20:25 - 00000000 ____D () C:\Program Files (x86)\One Click Root
2015-02-11 20:21 - 2015-02-11 20:22 - 03720040 _____ (One Click Root) C:\Users\Aleksandar\Desktop\OneClickRoot.exe
2015-02-11 18:37 - 2015-02-11 23:53 - 00000000 ____D () C:\Users\Aleksandar\Desktop\UBACI !!!!!!!!!!!!!!!!!!!!!!!!
2015-02-11 17:58 - 2015-02-11 17:57 - 00568641 _____ () C:\Users\Aleksandar\Desktop\Screenshot_2015-02-11-17-57-17.jpeg
2015-02-11 15:46 - 2015-02-11 15:56 - 00005072 _____ () C:\Users\Aleksandar\Desktop\ZA SPEED - a.txt
2015-02-10 08:48 - 2015-02-10 08:48 - 00000061 _____ () C:\Users\Aleksandar\Desktop\ZA BLICER !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!.txt
2015-02-09 20:08 - 2015-02-11 13:53 - 00000000 ____D () C:\Users\Aleksandar\Desktop\FILMOVI
2015-02-08 23:07 - 2015-02-08 23:07 - 00000000 ____D () C:\ProgramData\SystemRequirementsLab
2015-02-08 23:07 - 2015-02-08 23:07 - 00000000 ____D () C:\Program Files (x86)\SystemRequirementsLab
2015-02-08 23:03 - 2015-02-08 23:10 - 00000032 _____ () C:\Users\Aleksandar\Desktop\Call of Duty Advanced Warfare.txt
2015-02-07 22:08 - 2015-02-07 22:11 - 00000000 ____D () C:\Users\Aleksandar\AppData\Roaming\Apple Computer
2015-02-07 22:08 - 2015-02-07 22:08 - 00002535 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2015-02-07 22:08 - 2015-02-07 22:08 - 00000000 ____D () C:\Users\Aleksandar\AppData\Local\Apple Computer
2015-02-07 22:08 - 2015-02-07 22:08 - 00000000 ____D () C:\Users\Aleksandar\AppData\Local\Apple
2015-02-07 22:08 - 2015-02-07 22:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-02-07 22:08 - 2015-02-07 22:08 - 00000000 ____D () C:\Program Files\iTunes
2015-02-07 22:08 - 2015-02-07 22:08 - 00000000 ____D () C:\Program Files\iPod
2015-02-07 22:08 - 2015-02-07 22:08 - 00000000 ____D () C:\Program Files\Bonjour
2015-02-07 22:08 - 2015-02-07 22:08 - 00000000 ____D () C:\Program Files (x86)\iTunes
2015-02-07 22:08 - 2015-02-07 22:08 - 00000000 ____D () C:\Program Files (x86)\Bonjour
2015-02-07 22:08 - 2015-02-07 22:08 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update
2015-02-07 22:08 - 2012-08-21 13:01 - 00033240 _____ (GEAR Software Inc.) C:\Windows\system32\Drivers\GEARAspiWDM.sys
2015-02-07 21:50 - 2015-02-07 21:50 - 00000000 ____D () C:\Users\Aleksandar\AppData\Local\Macromedia
2015-02-07 18:48 - 2015-02-07 18:48 - 00000000 ____D () C:\Users\Aleksandar\AppData\Roaming\Macromedia
2015-02-07 18:44 - 2015-02-12 10:55 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-02-07 18:44 - 2015-02-07 18:44 - 00001171 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-02-07 18:44 - 2015-02-07 18:44 - 00000000 ____D () C:\Users\Aleksandar\AppData\Roaming\Mozilla
2015-02-07 18:44 - 2015-02-07 18:44 - 00000000 ____D () C:\Users\Aleksandar\AppData\Local\Mozilla
2015-02-07 18:43 - 2015-02-12 13:42 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-02-07 15:52 - 2015-02-07 15:52 - 00003670 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore1d042e5bf8df5bb
2015-02-07 15:52 - 2015-02-07 15:52 - 00003670 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-02-06 10:43 - 2015-02-06 14:08 - 00002630 _____ () C:\Users\Aleksandar\Desktop\Pad Firmware upgrade.lnk
2015-02-06 10:38 - 2015-02-06 10:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Actions Tools
2015-02-06 10:38 - 2015-02-06 10:38 - 00000000 ____D () C:\Program Files (x86)\Actions
2015-02-06 09:07 - 2015-02-06 09:07 - 00001043 _____ () C:\Users\Public\Desktop\Kingo ROOT.lnk
2015-02-06 09:07 - 2015-02-06 09:07 - 00000000 ____D () C:\Users\Aleksandar\AppData\Roaming\Kingosoft
2015-02-06 09:07 - 2015-02-06 09:07 - 00000000 ____D () C:\Users\Aleksandar\AppData\Local\Kingosoft
2015-02-06 09:07 - 2015-02-06 09:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kingo ROOT
2015-02-06 09:06 - 2015-02-06 09:07 - 00000000 ____D () C:\Program Files (x86)\Kingo ROOT
2015-02-04 21:32 - 2015-02-04 22:08 - 00000000 ____D () C:\Users\Aleksandar\Desktop\PLIN !!!!!!!!!!!
2015-02-04 10:44 - 2015-02-04 10:44 - 00000000 ___HD () C:\Users\Aleksandar\InstallAnywhere
2015-02-03 13:04 - 2015-02-03 13:06 - 00000000 ____D () C:\Users\Aleksandar\Desktop\ZA POSAO !!!!!!!!!!!!!!!!!!!!!!!!!!
2015-02-01 21:45 - 2015-02-11 17:33 - 00000000 ____D () C:\Users\Aleksandar\Desktop\Goclever Quantum 785
2015-02-01 21:24 - 2015-02-01 21:25 - 00000028 _____ () C:\Users\Aleksandar\Desktop\RADNO VREME.txt
2015-01-27 22:09 - 2015-01-27 22:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-01-27 22:09 - 2015-01-09 23:27 - 00621200 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2015-01-27 22:06 - 2015-01-13 05:15 - 01540240 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
2015-01-27 22:06 - 2015-01-10 09:07 - 32102544 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2015-01-27 22:06 - 2015-01-10 09:07 - 25459856 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2015-01-27 22:06 - 2015-01-10 09:07 - 24765584 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2015-01-27 22:06 - 2015-01-10 09:07 - 20465296 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2015-01-27 22:06 - 2015-01-10 09:07 - 17250776 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2015-01-27 22:06 - 2015-01-10 09:07 - 16009120 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2015-01-27 22:06 - 2015-01-10 09:07 - 14115944 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2015-01-27 22:06 - 2015-01-10 09:07 - 13295552 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2015-01-27 22:06 - 2015-01-10 09:07 - 13210248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2015-01-27 22:06 - 2015-01-10 09:07 - 10774544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2015-01-27 22:06 - 2015-01-10 09:07 - 10714488 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2015-01-27 22:06 - 2015-01-10 09:07 - 10274448 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2015-01-27 22:06 - 2015-01-10 09:07 - 03607184 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2015-01-27 22:06 - 2015-01-10 09:07 - 03298816 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2015-01-27 22:06 - 2015-01-10 09:07 - 03245712 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2015-01-27 22:06 - 2015-01-10 09:07 - 02902456 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2015-01-27 22:06 - 2015-01-10 09:07 - 01895240 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6434725.dll
2015-01-27 22:06 - 2015-01-10 09:07 - 01556808 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6434725.dll
2015-01-27 22:06 - 2015-01-10 09:07 - 00994712 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2015-01-27 22:06 - 2015-01-10 09:07 - 00969360 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2015-01-27 22:06 - 2015-01-10 09:07 - 00942736 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2015-01-27 22:06 - 2015-01-10 09:07 - 00929424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2015-01-27 22:06 - 2015-01-10 09:07 - 00906384 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2015-01-27 22:06 - 2015-01-10 09:07 - 00877488 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2015-01-27 22:06 - 2015-01-10 09:07 - 00833864 _____ () C:\Windows\system32\nvmcumd.dll
2015-01-27 22:06 - 2015-01-10 09:07 - 00496456 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2015-01-27 22:06 - 2015-01-10 09:07 - 00399688 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2015-01-27 22:06 - 2015-01-10 09:07 - 00390472 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2015-01-27 22:06 - 2015-01-10 09:07 - 00353040 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2015-01-27 22:06 - 2015-01-10 09:07 - 00345744 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2015-01-27 22:06 - 2015-01-10 09:07 - 00305320 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2015-01-27 22:06 - 2015-01-10 09:07 - 00177624 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2015-01-27 22:06 - 2015-01-10 09:07 - 00164568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2015-01-27 20:58 - 2015-01-30 19:55 - 00000000 ____D () C:\ProgramData\YTD Video Downloader
2015-01-27 20:55 - 2015-01-27 20:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YTD Video Downloader
2015-01-27 20:55 - 2015-01-27 20:55 - 00000000 ____D () C:\Program Files (x86)\GreenTree Applications
2015-01-27 20:25 - 2015-02-10 12:00 - 00000508 _____ () C:\Windows\Tasks\Windows Installer Update Task.job
2015-01-27 20:25 - 2015-01-27 20:25 - 00003258 _____ () C:\Windows\System32\Tasks\Windows Installer Update Task
2015-01-26 01:37 - 2015-01-26 01:37 - 00002770 _____ () C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013
2015-01-24 22:08 - 2015-01-24 22:08 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 14
2015-01-24 22:08 - 2015-01-24 22:08 - 00000000 ____D () C:\ProgramData\PDVD
2015-01-24 22:07 - 2015-01-24 22:07 - 00000000 ____D () C:\ProgramData\SUPPORTDIR
2015-01-24 22:07 - 2015-01-24 22:07 - 00000000 ____D () C:\Program Files (x86)\CyberLink
2015-01-24 21:59 - 2015-01-24 22:07 - 00000000 ____D () C:\ProgramData\install_clap
2015-01-21 11:13 - 2015-01-21 11:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-01-14 12:35 - 2014-04-16 00:35 - 00028352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aspnet_counters.dll
2015-01-14 12:35 - 2014-04-16 00:34 - 00029888 _____ (Microsoft Corporation) C:\Windows\system32\aspnet_counters.dll
2015-01-14 12:17 - 2015-02-12 10:56 - 00008184 _____ () C:\Windows\setupact.log
2015-01-14 12:17 - 2015-01-14 12:17 - 00000000 _____ () C:\Windows\setuperr.log
2015-01-14 07:54 - 2014-12-19 07:26 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-14 07:54 - 2014-12-12 03:04 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-14 07:54 - 2014-12-12 01:51 - 00075776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ahcache.sys
2015-01-14 07:54 - 2014-12-09 02:50 - 00225280 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-14 07:54 - 2014-12-08 20:42 - 00535640 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2015-01-14 07:54 - 2014-12-08 20:42 - 00531616 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2015-01-14 07:54 - 2014-12-08 20:42 - 00448792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2015-01-14 07:54 - 2014-12-08 20:42 - 00413248 _____ (Microsoft Corporation) C:\Windows\system32\Faultrep.dll
2015-01-14 07:54 - 2014-12-08 20:42 - 00372408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Faultrep.dll
2015-01-14 07:54 - 2014-12-08 20:42 - 00108944 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2015-01-14 07:54 - 2014-12-08 20:42 - 00038264 _____ (Microsoft Corporation) C:\Windows\system32\WerFaultSecure.exe
2015-01-14 07:54 - 2014-12-08 20:42 - 00033584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFaultSecure.exe
2015-01-14 07:54 - 2014-12-06 04:17 - 00360448 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2015-01-14 07:54 - 2014-12-06 02:41 - 00391680 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-14 07:54 - 2014-12-06 02:35 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll
2015-01-14 07:54 - 2014-10-29 05:00 - 00465320 _____ (Microsoft Corporation) C:\Windows\system32\WerFault.exe
2015-01-14 07:54 - 2014-10-29 05:00 - 00139984 _____ (Microsoft Corporation) C:\Windows\system32\wermgr.exe
2015-01-14 07:54 - 2014-10-29 04:52 - 00500016 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2015-01-14 07:54 - 2014-10-29 04:52 - 00482872 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2015-01-14 07:54 - 2014-10-29 04:52 - 00394120 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2015-01-14 07:54 - 2014-10-29 04:52 - 00272248 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2015-01-14 07:54 - 2014-10-29 04:12 - 00413136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe
2015-01-14 07:54 - 2014-10-29 04:12 - 00136296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wermgr.exe
2015-01-14 07:54 - 2014-10-29 04:07 - 00424544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2015-01-14 07:54 - 2014-10-29 04:07 - 00370424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2015-01-14 07:54 - 2014-10-29 04:07 - 00344536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2015-01-14 07:54 - 2014-10-29 03:44 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\werdiagcontroller.dll
2015-01-14 07:54 - 2014-10-29 02:59 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werdiagcontroller.dll
2015-01-14 07:54 - 2014-10-29 02:24 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2015-01-14 07:54 - 2014-10-29 02:02 - 00911360 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2015-01-14 07:54 - 2014-10-29 02:01 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-12 14:12 - 2014-07-09 10:36 - 00000000 ____D () C:\Users\Aleksandar\AppData\Local\Adobe
2015-02-12 14:09 - 2014-11-12 16:26 - 01056096 _____ () C:\Windows\WindowsUpdate.log
2015-02-12 14:09 - 2014-07-08 18:07 - 00000000 ____D () C:\Users\Aleksandar\AppData\Roaming\POP Peeper
2015-02-12 14:00 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sru
2015-02-12 13:55 - 2014-07-14 14:05 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-02-12 13:55 - 2014-07-08 09:29 - 00003596 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3188151745-266478930-1470971803-1001
2015-02-12 13:55 - 2013-08-22 16:20 - 00000000 ____D () C:\Windows\CbsTemp
2015-02-12 13:54 - 2014-07-14 14:00 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-02-12 13:48 - 2014-07-10 07:28 - 00000000 ____D () C:\Windows\system32\MRT
2015-02-12 13:45 - 2014-07-10 07:28 - 116773704 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-02-12 13:44 - 2013-08-22 14:25 - 00000167 _____ () C:\Windows\win.ini
2015-02-12 12:25 - 2014-07-08 18:04 - 00000000 ____D () C:\Program Files (x86)\POP Peeper
2015-02-12 10:57 - 2014-07-08 17:20 - 00000000 ____D () C:\Users\Aleksandar\.rainlendar2
2015-02-12 10:56 - 2014-12-25 23:42 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-02-12 10:56 - 2013-08-22 15:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-12 10:55 - 2014-11-13 22:46 - 00036446 _____ () C:\Windows\PFRO.log
2015-02-12 10:54 - 2013-08-22 14:25 - 00786432 ___SH () C:\Windows\system32\config\BBI
2015-02-12 10:42 - 2014-11-23 19:13 - 00000000 ____D () C:\Users\Aleksandar\Desktop\23 XI 2014 - ZA TELEFON
2015-02-12 10:24 - 2013-09-30 05:14 - 00863592 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-02-12 07:47 - 2014-07-08 17:02 - 00000000 ____D () C:\Users\Aleksandar\AppData\Roaming\uTorrent
2015-02-12 07:25 - 2014-07-09 09:08 - 00000105 _____ () C:\Users\Aleksandar\Desktop\SERIJE.txt
2015-02-12 07:23 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\AppReadiness
2015-02-11 21:52 - 2014-07-08 09:24 - 00000000 ____D () C:\Users\Aleksandar
2015-02-11 20:00 - 2014-07-09 08:47 - 00000000 ____D () C:\Users\Aleksandar\Desktop\Drzavni Posao
2015-02-11 17:10 - 2014-07-08 15:12 - 00000000 ___RD () C:\Users\Aleksandar\Desktop\ZA SLUSANJE
2015-02-08 15:46 - 2014-07-21 17:27 - 00000000 ____D () C:\Users\Aleksandar\AppData\Roaming\AIMP3
2015-02-08 15:06 - 2014-07-08 23:06 - 00000000 ___RD () C:\Users\Aleksandar\Desktop\RAZNO
2015-02-08 14:29 - 2014-07-08 09:24 - 00000000 ____D () C:\Users\Aleksandar\AppData\Local\Packages
2015-02-07 22:08 - 2015-01-08 20:22 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2015-02-07 22:07 - 2014-07-08 17:28 - 00000000 ____D () C:\ProgramData\Apple
2015-02-07 21:30 - 2015-01-03 15:14 - 00000000 ____D () C:\ProgramData\TEMP
2015-02-07 18:42 - 2014-07-08 09:24 - 00000000 ____D () C:\Users\Aleksandar\AppData\Roaming\Adobe
2015-02-07 18:18 - 2015-01-02 14:36 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-02-07 18:17 - 2015-01-08 21:11 - 00000000 ____D () C:\Program Files\Common Files\Apple
2015-02-07 18:02 - 2014-08-20 19:04 - 00000000 ____D () C:\Windows\SysWOW64\Adobe
2015-02-07 17:06 - 2014-07-09 22:12 - 00000000 ____D () C:\ProgramData\Oracle
2015-02-07 17:05 - 2014-07-09 21:29 - 00000000 ____D () C:\Program Files (x86)\Java
2015-02-07 16:59 - 2014-07-09 22:12 - 00272296 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2015-02-07 16:59 - 2014-07-09 22:12 - 00176552 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2015-02-07 16:59 - 2014-07-09 22:12 - 00176552 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2015-02-07 16:59 - 2014-07-09 22:12 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-02-04 12:18 - 2013-08-22 15:44 - 00484360 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-02-03 20:31 - 2013-08-22 16:38 - 00714720 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-02-03 20:31 - 2013-08-22 16:38 - 00106976 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-29 08:28 - 2014-07-08 18:21 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2015-01-26 23:27 - 2015-01-03 20:55 - 00000000 ____D () C:\Users\Aleksandar\Desktop\ZA SATELITSKU !!!!!!!!!!!
2015-01-24 22:14 - 2014-11-11 15:08 - 00000000 ____D () C:\ProgramData\CyberLink
2015-01-24 22:11 - 2014-11-11 15:10 - 00000000 ____D () C:\Users\Aleksandar\Documents\CyberLink
2015-01-24 22:11 - 2014-11-11 15:09 - 00000000 ____D () C:\Users\Public\Documents\CyberLink
2015-01-24 22:08 - 2014-11-11 15:08 - 00000000 ____D () C:\Users\Aleksandar\AppData\Local\CyberLink
2015-01-24 22:08 - 2014-07-09 07:17 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-01-24 22:01 - 2014-11-11 15:08 - 00000000 ____D () C:\Users\Public\CyberLink
2015-01-21 11:57 - 2014-07-09 07:12 - 00000000 ____D () C:\Users\Aleksandar\AppData\Roaming\Skype
2015-01-21 11:13 - 2014-09-22 21:19 - 00000000 ___RD () C:\Program Files (x86)\Skype
2015-01-21 11:13 - 2014-07-09 07:12 - 00000000 ____D () C:\ProgramData\Skype

==================== Files in the root of some directories =======

2012-06-06 05:06 - 2012-06-06 05:06 - 2174976 _____ (Advanced Micro Devices Inc.) C:\Program Files (x86)\Common Files\atimpenc.dll
2014-11-26 10:59 - 2014-11-26 10:59 - 0003584 _____ () C:\Users\Aleksandar\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-07-09 12:58 - 2014-07-09 12:58 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2014-08-20 18:39 - 2014-08-25 08:20 - 14389052 _____ () C:\ProgramData\OfflineCatalogue_1_2014_TECDOC_CD.log

Some content of TEMP:
====================
C:\Users\Aleksandar\AppData\Local\Temp\SRLDetectionLibrary6733754770607934835.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-02-12 07:30

==================== End Of Log ============================

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Pošalji mi ovaj fajl:
C:\Program Files (x86)\Windows Installer\msiupd.exe

preko sljedećeg linka:
http://www.mycity.rs/ambulanta-upload.php

offline
  • Pridružio: 28 Nov 2009
  • Poruke: 145

Poslao sam vam fajl.

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Arrow Korak 1

Idi u Start -> Control Panel -> Programs and Features:

YTD Video Downloader 4.8.9



Arrow Korak 2

Otvori Notepad i iskopiraj sljedeći tekst koji se nalazi unutar Kod polja.

ProxyEnable: [HKLM] => ProxyEnable is set.
ProxyEnable: [HKLM-x32] => ProxyEnable is set.
ProxyServer: [HKLM] => http=127.0.0.1:8080;https=127.0.0.1:8080
ProxyServer: [HKLM-x32] => http=127.0.0.1:8080;https=127.0.0.1:8080
BHO: SavePass 1.1 -> {11111111-1111-1111-1111-110611341129} -> No File
BHO: Sense -> {11111111-1111-1111-1111-110611901159} -> No File
BHO: Ge-Force -> {11111111-1111-1111-1111-110611911129} -> No File
R2 msiupd.exe; C:\Program Files (x86)\Windows Installer\msiupd.exe [28160 2015-01-17] (Microsoft©) [File not signed]
S2 sbmntr; \??\C:\PROGRA~2\YTDOWN~1\sbmntr.sys [X]
S2 SPDRIVER_1459.0.0.0; \??\C:\Program Files (x86)\ShopperPro\JSDriver\1459.0.0.0\jsdrv.sys [X]
Task: {138C2E79-1410-47CF-8DCD-847B605667D6} - System32\Tasks\Windows Installer Update Task => Wscript.exe //nologo //E:jscript //B "C:\Program Files (x86)\Windows Installer\msiupd.ini"
AlternateDataStreams: C:\ProgramData\TEMP:1CE11B51
AlternateDataStreams: C:\ProgramData\TEMP:3A249E66
C:\Program Files (x86)\Windows Installer
C:\Program Files (x86)\ShopperPro\JSDriver
BHO: BHOImpl Class -> {E1499FE7-129D-4B6E-B681-DDF21E14172C} -> No File
BHO-x32: BHOImpl Class -> {E1499FE7-129D-4B6E-B681-DDF21E14172C} -> No File
EmptyTemp:


U okviru Notepad-a klikni na File --> Save As
Fajl nazovi Fixlist i sačuvaj na Desktop
Dvoklikom ponovo pokreni FRST.exe
Klikni na Fix i sačekaj dok program ne završi.
Ukoliko program zatraži restart računara, omogući mu da to nesmetano obavi.
Nakon završetka rada, otvoriće se fixlog.txt, sa sadržajem koji treba da kopiraš u temu.
Takođe, na Desktop-u će se nalaziti (fixlog.txt).

offline
  • Pridružio: 28 Nov 2009
  • Poruke: 145

Izvini ali nije mi jasno sta da radim sa prvim korakom?Da li trebam da dezinstaliram YTD Video Downloader 4.8.9 ?

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

alex1974 ::Izvini ali nije mi jasno sta da radim sa prvim korakom?Da li trebam da dezinstaliram YTD Video Downloader 4.8.9 ?

Moja greška. Izvini. Treba da ga deinstaliraš.

offline
  • Pridružio: 28 Nov 2009
  • Poruke: 145

Ok ovo drugo sam uradio ali cu sada da ga dezinstaliram pa cu sve ponovo da uradim.

offline
  • Pridružio: 28 Nov 2009
  • Poruke: 145

Evo:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-02-2015 02
Ran by Aleksandar at 2015-02-12 16:51:35 Run:2
Running from C:\Users\Aleksandar\Desktop
Loaded Profiles: Aleksandar (Available profiles: Aleksandar)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
ProxyEnable: [HKLM] => ProxyEnable is set.
ProxyEnable: [HKLM-x32] => ProxyEnable is set.
ProxyServer: [HKLM] => http=127.0.0.1:8080;https=127.0.0.1:8080
ProxyServer: [HKLM-x32] => http=127.0.0.1:8080;https=127.0.0.1:8080
BHO: SavePass 1.1 -> {11111111-1111-1111-1111-110611341129} -> No File
BHO: Sense -> {11111111-1111-1111-1111-110611901159} -> No File
BHO: Ge-Force -> {11111111-1111-1111-1111-110611911129} -> No File
R2 msiupd.exe; C:\Program Files (x86)\Windows Installer\msiupd.exe [28160 2015-01-17] (Microsoft©) [File not signed]
S2 sbmntr; \??\C:\PROGRA~2\YTDOWN~1\sbmntr.sys [X]
S2 SPDRIVER_1459.0.0.0; \??\C:\Program Files (x86)\ShopperPro\JSDriver\1459.0.0.0\jsdrv.sys [X]
Task: {138C2E79-1410-47CF-8DCD-847B605667D6} - System32\Tasks\Windows Installer Update Task => Wscript.exe //nologo //E:jscript //B "C:\Program Files (x86)\Windows Installer\msiupd.ini"
AlternateDataStreams: C:\ProgramData\TEMP:1CE11B51
AlternateDataStreams: C:\ProgramData\TEMP:3A249E66
C:\Program Files (x86)\Windows Installer
C:\Program Files (x86)\ShopperPro\JSDriver
BHO: BHOImpl Class -> {E1499FE7-129D-4B6E-B681-DDF21E14172C} -> No File
BHO-x32: BHOImpl Class -> {E1499FE7-129D-4B6E-B681-DDF21E14172C} -> No File
EmptyTemp:
*****************

HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value deleted successfully.
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => Value not found.
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => Value not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611341129} => Key not found.
HKCR\CLSID\{11111111-1111-1111-1111-110611341129} => Key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611901159} => Key not found.
HKCR\CLSID\{11111111-1111-1111-1111-110611901159} => Key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611911129} => Key not found.
HKCR\CLSID\{11111111-1111-1111-1111-110611911129} => Key not found.
msiupd.exe => Service not found.
sbmntr => Service not found.
SPDRIVER_1459.0.0.0 => Service not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{138C2E79-1410-47CF-8DCD-847B605667D6} => Key not found.
C:\Windows\System32\Tasks\Windows Installer Update Task not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Windows Installer Update Task => Key not found.
C:\ProgramData\TEMP => ":1CE11B51" ADS removed successfully.
"C:\ProgramData\TEMP" => ":3A249E66" ADS not found.
"C:\Program Files (x86)\Windows Installer" => File/Directory not found.
"C:\Program Files (x86)\ShopperPro\JSDriver" => File/Directory not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E1499FE7-129D-4B6E-B681-DDF21E14172C} => Key not found.
HKCR\CLSID\{E1499FE7-129D-4B6E-B681-DDF21E14172C} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E1499FE7-129D-4B6E-B681-DDF21E14172C} => Key not found.
HKCR\Wow6432Node\CLSID\{E1499FE7-129D-4B6E-B681-DDF21E14172C} => Key not found.
EmptyTemp: => Removed 22 MB temporary data.


The system needed a reboot.

==== End of Fixlog 16:51:41 ====

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Kakvo je sada stanje?



Arrow

Preuzmi Malwarebytes Anti-Rootkit (MBAR) sa sledeceg linka i sacuvaj ga na Desktop.

Dvoklikom pokreni MBAR () na ikonicu programa:
- Klikni OK na sledecem prozoru da bi dozvolio raspakivanje u zaseban mbar folder na desktop-u;
- mbar.exe ce biti startovan. Na nekim sistemima to moze da potraje nekoliko dodatnih sekundi, te pricekati pokretanje.;
- U uvodnom prozoru klikni dugme Next ukoliko si saglasan;



• Na 'Update Database' prozoru klik na dugme Update da bi preuzeo sveze definicije. Kada se ispise poruka 'Success: Database was successfully updated' klik na dugme Next;
• Pod sekcijom 'Scan Targets' proveri da su sve opcije stiklirane, te klikni na dugme Scan;

Obavestenje: sa nekim infekcijama moze se desiti da se prikaze neka od sledecih poruka:
- 'Could not load protection driver' => u tom slucaju klikni OK.
- 'Could not load DDA driver' => klikni Yes na to obavestenje da bi dozvolio ucitavanje nakon restarta. Dozvoli restart i nastavi sa ostatkom instrukcija posle restarta.





>> Ukoliko malware nije detektovan, klik na Exit dugme da zatvoris program. U sledecu poruku postavi mbar-log-year-month-day (sat-minuti-sekundi).txt i system-log.txt izveštaje.

>> Ukoliko su infekcija/e pronadjene, proveriti da li je obelezena opcija 'Create Restore Point' i klikni na dugme Cleanup! da bi uklonili pretnje.
- Procedura uklanjanje malware-a (scheduled) ce biti zakazana po restartu, bice prikazano obavestenje u pop-up prozoru. Klikni dugme Yes i sistem bi trebao da se restartuje i da zavrsi proceduru ciscenja.



Obavestenje! samo ukoliko je RootKit detektovan: - postaraj se da pokrenes fixdamage.exe alat koji se nalazi u mbar folderu, \Plugins\fixdamage.exe:
- Dvoklikom pokreni fixdamage, u crnom prozoru koji se otvori (command prompt) ukucaj Y (Y stoji za Yes) da bi nastavio izvrsenje, pricekati da alat odradi sve popravke ...
- Kada vidis poruku 'press any key to exit' popravka je kompletirana. Pritisnuti bilo koju tipku na tastaturi da bi se prozor zatvorio. Restartovati sistem.





Sledeci izvestaji ce biti formirani u mbar folderu.
1. mbar-log-year-month-day (hour-minute-second).txt
2. system-log.txt

Iskopiraj sadrzaj mbar log-a u poruku a system log okaci uz poruku koristeci opciju Prikači fajl.

offline
  • Pridružio: 28 Nov 2009
  • Poruke: 145

Napisano: 12 Feb 2015 17:11

Izgleda da je sada bolje uspeo je da instalira flas player,izvini ali sada moram da idem do lekara pa cu se kasnije javiti.

Dopuna: 12 Feb 2015 21:00

Malwarebytes Anti-Rootkit BETA 1.08.3.1004
malwarebytes.org

Database version:
main: v2015.02.12.05
rootkit: v2015.02.03.01

Windows 8.1 x64 NTFS
Internet Explorer 11.0.9600.17631
Aleksandar :: ALEKSANDAR-PC [administrator]

12-Feb-15 8:22:52 PM
mbar-log-2015-02-12 (20-22-52).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Kernel memory modifications detected. Deep Anti-Rootkit Scan engaged.
Objects scanned: 364598
Time elapsed: 21 minute(s), 23 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\Users\Aleksandar\Desktop\Dual Core Fix\Extreme Injector v3.exe (Riskware.Injector.DC) -> Delete on reboot. [cfc609149af03bfbe60cb14d54ad6b95]

Physical Sectors Detected: 0
(No malicious items detected)

(end)


mycity.rs/must-login.png

Ko je trenutno na forumu
 

Ukupno su 905 korisnika na forumu :: 30 registrovanih, 4 sakrivenih i 871 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: darkangel, goxsys, kybonacci, Lieutenant, lord sir giga, maiden6657, MB120mm, mikrimaus, Misha V, mkukoleca, Mr. Majevica, ozzy, raptorsi, repac, Rogan33, royst33, S-lash, S2M, savaskytec, Smiljke, Srki94, Srle993, stalja, Sumadija34, Trpe Grozni, Tvrtko I, Vlada1389, wolf431, ZetaMan, zziko