Problem sa startovanjem racunara

1

Problem sa startovanjem racunara

offline
  • Pridružio: 10 Jan 2012
  • Poruke: 27

Imam problem sa startovanjem racunara.
Samo botovanje traje skoro normalno.
Desktop i ikonice se pojave dosta brzo, ali je racunar nemoguce koristiti sledecih 25min kao da nesto radi u pozadini.
Jedino sto se vidi je indikacija pokusaja konektovanja na wireles, i to traje oko 20min a onda jos 5 min nije moguce pokrenutu nista na racunaru.
Posle radi relativno normalno.

Fajl dobijen AdwCleaner-om zakacen je ovde:

mycity.rs/must-login.png

Moze li neka preporuka za resnje problema!

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6103

Pozdrav igorpet i dobrodosao u Ambulantu MyCity foruma.

Videcemo da ti pomognemo, ali na osnovu samo AdwareCleaner izvestaja, malo sta ti mozemo reci osim onoga sto vidimo, a to je samo ono sto je alat video kao maliciozan program i zakazao uklanjanje.
Video je gomilu foldera koje skladiste PUP a.k.a Potentially Unwanted programe, njima vezane registry kljuceve i uklonio njihova podesavanja iz tvog browsera.

Za dijagnostiku samog sistema mi koristimo pravi dijagnosticki alat. Poseti top temu i isprati uputstvo za postavljanje trazenih izvestaja;
http://www.mycity.rs/Ambulanta/Kako-otvoriti-temu-u-Ambulanti.html
Na osnovu postavljenih izvestaja, neko od nas (AMF Tim) moze analizirati izvestaje i proslediti ti dalje instrukcije kako da pomognes svom sistemu.

offline
  • Pridružio: 10 Jan 2012
  • Poruke: 27

FRST izveštaja:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 24-06-2015
Ran by Korisnik (administrator) on KORISNIK-PC on 26-06-2015 23:04:28
Running from C:\Users\Korisnik\Downloads
Loaded Profiles: Korisnik (Available Profiles: Korisnik)
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: English (United States)
Internet Explorer Version 11 (Default browser path: "C:\Program Files\Opera\Opera.exe" "%1")
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: geekstogo.com/forum/topic/335081-frst-t.....scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9b219d80a8843bf8\stacsv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9b219d80a8843bf8\AEstSrv.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(LSI Corporation) C:\Program Files\LSI SoftModem\agrsmsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Launcher\Avira.Systray.exe
(BitTorrent Inc.) C:\Users\Korisnik\AppData\Roaming\uTorrent\uTorrent.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\VS7DEBUG\mdm.exe
(arvato digital services llc) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(Software 2000 Limited) C:\Windows\System32\spool\drivers\w32x86\3\HP1006MC.EXE
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
() C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
(Hewlett-Packard Development Company L.P.) C:\Program Files\Hewlett-Packard\Shared\hpCaslNotification.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\tv_w32.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer_Desktop.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray.exe [495708 2010-01-28] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1791272 2010-06-04] (Synaptics Incorporated)
HKLM\...\Run: [QLBController] => C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe [256056 2010-01-28] (Hewlett-Packard Company)
HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2010-01-08] (Intel Corporation)
HKLM\...\Run: [WirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [499768 2009-09-01] (Hewlett-Packard)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [981688 2015-04-30] (Microsoft Corporation)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [730416 2015-06-10] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [557768 2014-09-19] (Adobe Systems Incorporated)
HKLM\...\Run: [AdobeCS6ServiceManager] => C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\Launcher\Avira.Systray.exe [130864 2015-05-21] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-1146453529-3827096963-1341687669-1000\...\Run: [] => C:\Users\Korisnik\AppData\Local\Temp\wpbt0.dll <===== ATTENTION
HKU\S-1-5-21-1146453529-3827096963-1341687669-1000\...\Run: [uTorrent] => C:\Users\Korisnik\AppData\Roaming\uTorrent\uTorrent.exe [1694560 2015-05-06] (BitTorrent Inc.)
HKU\S-1-5-21-1146453529-3827096963-1341687669-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [31280256 2015-04-17] (Skype Technologies S.A.)
HKU\S-1-5-21-1146453529-3827096963-1341687669-1000\...\Run: [Facebook Update] => C:\Users\Korisnik\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-05-07] (Facebook Inc.)
HKU\S-1-5-21-1146453529-3827096963-1341687669-1000\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-1146453529-3827096963-1341687669-1000\...\Run: [GoogleChromeAutoLaunch_771154D8C18E782B4C9CFC63E3C3969D] => C:\Program Files\Google\Chrome\Application\chrome.exe [813896 2015-06-20] (Google Inc.)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1146453529-3827096963-1341687669-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1146453529-3827096963-1341687669-1000\Software\Microsoft\Internet Explorer\Main,Search Page = microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1146453529-3827096963-1341687669-1000 -> {C2E752DD-3236-4C3D-ACA6-897956DCE3AC} URL = search.yahoo.com/search?p={searchTerms}&fr=chr-ydwnld
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21] (Adobe Systems Incorporated)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2013-05-26] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-05-26] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-1146453529-3827096963-1341687669-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 0.0.0.0

FireFox:
========
FF ProfilePath: C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default
FF SearchEngineOrder.3: Bing
FF SelectedSearchEngine: Yahoo Search
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_190.dll [2015-06-23] ()
FF Plugin: @java.com/DTPlugin,version=10.21.2 -> C:\Windows\system32\npDeployJava1.dll [2013-05-26] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.21.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2013-05-26] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=6.0.12.732 -> C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll [2010-06-02] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.732 -> C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll [2010-06-02] (RealNetworks, Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2013-09-23] (VideoLAN)
FF Plugin HKU\S-1-5-21-1146453529-3827096963-1341687669-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Korisnik\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Extension: leethax.net extension - C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default\Extensions\leethax@leethax.net.xpi [2013-05-27]
FF Extension: Test Pilot - C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default\Extensions\testpilot@labs.mozilla.com.xpi [2011-01-27]
FF Extension: Update My Browser - C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default\Extensions\{cc8f597b-0765-404e-a575-82aefbd81daf}.xpi [2013-03-13]
FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-05-01]
FF Extension: No Name - C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default\extensions\{cde38172-4160-4091-bf76-de675198d659}.xpi [not found]
FF Extension: No Name - C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi [not found]
FF ExtraCheck: C:\Program Files\mozilla firefox\firefox.cfg [2013-07-12] <==== ATTENTION

Chrome:
=======
CHR Profile: C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-23]
CHR Extension: (Google Docs) - C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-05-24]
CHR Extension: (Google Drive) - C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-05-24]
CHR Extension: (YouTube) - C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-07-26]
CHR Extension: (Google Search) - C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-07-26]
CHR Extension: (Google Sheets) - C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-23]
CHR Extension: (Pin It Button) - C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2015-03-09]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-04-19]
CHR Extension: (Skype Click to Call) - C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-02-27]
CHR Extension: (No Name) - C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl [2015-06-26]
CHR Extension: (No Name) - C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\nafaimnnclfjfedmmabolbppcngeolgf [2015-06-26]
CHR Extension: (Google Wallet) - C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-04]
CHR Extension: (Gmail) - C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-07-26]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-05-01]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AgereModemAudio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [26112 2009-12-03] (LSI Corporation)
S2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc7.exe [827184 2015-06-10] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [450808 2015-06-10] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [450808 2015-06-10] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe [1188360 2015-06-10] (Avira Operations GmbH & Co. KG)
S2 Avira.ServiceHost; C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe [208632 2015-05-21] (Avira Operations GmbH & Co. KG)
R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
R2 HP Health Check Service; C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [120832 2009-10-15] (Hewlett-Packard) [File not signed]
R2 hpHotkeyMonitor; C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [265272 2010-01-28] (Hewlett-Packard Company)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 MDM; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed]
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2015-04-30] (Microsoft Corporation)
S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [284504 2015-04-30] (Microsoft Corporation)
R2 PSI_SVC_2; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [277360 2014-04-30] (arvato digital services llc)
R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9b219d80a8843bf8\STacSV.exe [229458 2010-01-28] (IDT, Inc.)
S2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [5448464 2015-03-30] (TeamViewer GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 androidusb; C:\Windows\System32\Drivers\androidusb.sys [26112 2010-04-29] (Google Inc)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108448 2015-06-10] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136728 2015-06-10] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37896 2015-05-05] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [37896 2015-03-04] (Avira Operations GmbH & Co. KG)
S3 HtcVCom32; C:\Windows\System32\DRIVERS\HtcVComV32.sys [105984 2009-10-27] (QUALCOMM Incorporated)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-04-14] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [245096 2015-03-04] (Microsoft Corporation)
R3 pfc; C:\Windows\System32\drivers\pfc.sys [10368 2011-02-21] (Padus, Inc.) [File not signed]
S3 s125bus; C:\Windows\System32\DRIVERS\s125bus.sys [83336 2007-04-24] (MCCI Corporation)
S3 s125mdfl; C:\Windows\System32\DRIVERS\s125mdfl.sys [15112 2007-04-24] (MCCI Corporation)
S3 s125mdm; C:\Windows\System32\DRIVERS\s125mdm.sys [108680 2007-04-24] (MCCI Corporation)
S3 s125obex; C:\Windows\System32\DRIVERS\s125obex.sys [98696 2007-04-24] (MCCI Corporation)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1763968 2010-01-18] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2010-09-13] () [File not signed]
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [31848 2015-06-10] (Avira Operations GmbH & Co. KG)
U3 amaswpt7; C:\Windows\system32\Drivers\amaswpt7.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero byte File/Folder)
S3 catchme; \??\C:\Users\Korisnik\AppData\Local\Temp\catchme.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-26 23:04 - 2015-06-26 23:06 - 00019999 _____ C:\Users\Korisnik\Downloads\FRST.txt
2015-06-26 23:04 - 2015-06-26 23:04 - 00000000 ____D C:\FRST
2015-06-26 23:03 - 2015-06-26 23:03 - 01636352 _____ (Farbar) C:\Users\Korisnik\Downloads\FRST.exe
2015-06-26 23:03 - 2015-06-26 23:03 - 01636352 _____ (Farbar) C:\Users\Korisnik\Downloads\FRST (1).exe
2015-06-26 22:26 - 2015-06-26 22:26 - 00049164 _____ C:\Users\Korisnik\Desktop\AdwCleaner[S0].txt
2015-06-26 21:55 - 2015-06-26 21:58 - 00000000 ____D C:\AdwCleaner
2015-06-26 21:55 - 2015-06-26 21:55 - 02244096 _____ C:\Users\Korisnik\Downloads\AdwCleaner.exe
2015-06-22 22:50 - 2015-06-23 16:20 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-06-22 22:49 - 2015-06-22 22:49 - 00001064 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-06-22 22:49 - 2015-06-22 22:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-06-22 22:49 - 2015-06-22 22:49 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-06-22 22:49 - 2015-04-14 09:37 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-06-22 22:49 - 2015-04-14 09:37 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-06-21 12:43 - 2015-06-21 12:43 - 00035950 _____ C:\Users\Korisnik\Downloads\Sablon handmade bez kruga (2).cdr
2015-06-21 12:42 - 2015-06-21 12:42 - 00268329 _____ C:\Users\Korisnik\Downloads\mira pecar poslednji.dxf
2015-06-21 12:41 - 2015-06-21 12:41 - 00035950 _____ C:\Users\Korisnik\Downloads\Sablon handmade bez kruga (1).cdr
2015-06-21 12:40 - 2015-06-21 12:40 - 00036676 _____ C:\Users\Korisnik\Downloads\Sablon handmade.cdr
2015-06-21 12:40 - 2015-06-21 12:40 - 00036676 _____ C:\Users\Korisnik\Downloads\Sablon handmade (1).cdr
2015-06-20 19:48 - 2015-06-20 19:47 - 00035950 _____ C:\Users\Korisnik\Downloads\Backup_of_Sablon handmade bez kruga.cdr
2015-06-20 19:47 - 2015-06-20 19:48 - 00026006 _____ C:\Users\Korisnik\Downloads\Sablon handmade bez kruga.cdr
2015-06-18 09:55 - 2015-06-18 09:55 - 00038968 _____ C:\Users\Korisnik\Downloads\Sablon mira kutlesic handmade (1).cdr
2015-06-15 19:20 - 2015-06-15 19:20 - 00051110 _____ C:\Users\Korisnik\Downloads\Sablon mira kutlesic handmade.cdr
2015-06-11 18:41 - 2015-06-11 18:41 - 00000000 ____D C:\Users\Korisnik\AppData\Local\GWX
2015-06-10 15:16 - 2015-06-02 21:35 - 00342728 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-06-10 15:16 - 2015-05-23 05:15 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-06-10 15:16 - 2015-05-23 05:08 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-06-10 15:16 - 2015-05-23 05:05 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-06-10 15:16 - 2015-05-23 05:00 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-06-10 15:16 - 2015-05-23 04:52 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-06-10 15:16 - 2015-05-23 04:38 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-06-10 15:16 - 2015-05-23 04:16 - 01309696 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-06-10 15:15 - 2015-05-27 16:08 - 19607040 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-06-10 15:15 - 2015-05-23 05:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-06-10 15:15 - 2015-05-23 05:28 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-06-10 15:15 - 2015-05-23 05:15 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-06-10 15:15 - 2015-05-23 05:15 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-06-10 15:15 - 2015-05-23 05:14 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-06-10 15:15 - 2015-05-23 05:13 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-06-10 15:15 - 2015-05-23 05:10 - 02278912 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-06-10 15:15 - 2015-05-23 05:09 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-06-10 15:15 - 2015-05-23 05:06 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-06-10 15:15 - 2015-05-23 05:05 - 00664064 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-06-10 15:15 - 2015-05-23 05:05 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-06-10 15:15 - 2015-05-23 05:04 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-06-10 15:15 - 2015-05-23 04:57 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-06-10 15:15 - 2015-05-23 04:49 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-06-10 15:15 - 2015-05-23 04:48 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-06-10 15:15 - 2015-05-23 04:47 - 04305920 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-06-10 15:15 - 2015-05-23 04:47 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-06-10 15:15 - 2015-05-23 04:38 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-06-10 15:15 - 2015-05-23 04:37 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-06-10 15:15 - 2015-05-23 04:37 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-06-10 15:15 - 2015-05-23 04:28 - 12829696 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-06-10 15:15 - 2015-05-23 04:20 - 01950720 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-06-10 15:15 - 2015-05-23 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-06-10 15:11 - 2015-05-25 19:00 - 02384384 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-06-10 15:11 - 2015-05-22 20:03 - 00571392 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-06-10 15:11 - 2015-05-22 20:02 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-06-10 15:11 - 2015-05-22 20:02 - 00621568 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-06-10 15:11 - 2015-05-22 20:02 - 00333824 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-06-10 15:11 - 2015-05-22 20:02 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-06-10 15:11 - 2015-05-22 20:02 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-06-10 15:11 - 2015-05-22 19:58 - 00901120 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-06-10 15:11 - 2015-05-21 15:20 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-06-10 15:10 - 2015-04-11 05:07 - 00054656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stream.sys
2015-06-10 15:06 - 2015-05-25 20:07 - 03989440 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-06-10 15:06 - 2015-05-25 20:07 - 03934144 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-06-10 15:06 - 2015-05-25 20:07 - 00137664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-06-10 15:06 - 2015-05-25 20:07 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-06-10 15:06 - 2015-05-25 20:04 - 01307648 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-06-10 15:06 - 2015-05-25 20:01 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-06-10 15:06 - 2015-05-25 20:01 - 00853504 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-06-10 15:06 - 2015-05-25 20:01 - 00641536 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-06-10 15:06 - 2015-05-25 20:01 - 00635392 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-06-10 15:06 - 2015-05-25 20:01 - 00551424 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-06-10 15:06 - 2015-05-25 20:01 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-06-10 15:06 - 2015-05-25 20:01 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-06-10 15:06 - 2015-05-25 20:01 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-06-10 15:06 - 2015-05-25 20:01 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-06-10 15:06 - 2015-05-25 20:01 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-06-10 15:06 - 2015-05-25 20:01 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-06-10 15:06 - 2015-05-25 20:01 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
2015-06-10 15:06 - 2015-05-25 20:01 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-06-10 15:06 - 2015-05-25 20:01 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-06-10 15:06 - 2015-05-25 20:01 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-06-10 15:06 - 2015-05-25 20:01 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-06-10 15:06 - 2015-05-25 20:01 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-06-10 15:06 - 2015-05-25 20:00 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe
2015-06-10 15:06 - 2015-05-25 20:00 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-06-10 15:06 - 2015-05-25 20:00 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe
2015-06-10 15:06 - 2015-05-25 20:00 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-06-10 15:06 - 2015-05-25 20:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-06-10 15:06 - 2015-05-25 20:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe
2015-06-10 15:06 - 2015-05-25 20:00 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe
2015-06-10 15:06 - 2015-05-25 20:00 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-06-10 15:06 - 2015-05-25 20:00 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe
2015-06-10 15:05 - 2015-05-25 20:01 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-06-10 15:05 - 2015-05-25 19:57 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-06-10 15:05 - 2015-05-25 19:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-06-10 15:05 - 2015-05-25 19:55 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-06-10 15:05 - 2015-05-25 19:55 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-06-10 15:05 - 2015-05-25 18:53 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-06-10 15:05 - 2015-05-09 05:14 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-06-10 15:05 - 2015-05-09 05:13 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-06-10 15:05 - 2015-05-09 05:13 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-06-10 15:05 - 2015-05-09 05:12 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-06-10 15:05 - 2015-05-09 05:08 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 03:59 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 03:59 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 03:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 03:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-06-10 15:05 - 2015-04-29 20:07 - 11411456 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-06-10 15:05 - 2015-04-29 20:07 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2015-06-10 15:05 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2015-06-10 15:05 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2015-06-10 15:05 - 2015-04-29 20:05 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2015-06-10 15:05 - 2015-04-24 19:56 - 00530432 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2015-05-29 21:01 - 2015-06-13 20:02 - 00000000 ____D C:\Users\Korisnik\Desktop\repro

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-26 23:06 - 2012-06-17 23:39 - 00000000 ____D C:\Users\Korisnik\AppData\Roaming\uTorrent
2015-06-26 23:04 - 2013-01-14 03:28 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-06-26 22:30 - 2009-07-14 06:34 - 00016880 _____ C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-06-26 22:30 - 2009-07-14 06:34 - 00016880 _____ C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-06-26 22:27 - 2010-09-13 15:37 - 00000000 ____D C:\Users\Korisnik\AppData\Roaming\Skype
2015-06-26 22:25 - 2010-09-13 16:07 - 01449907 _____ C:\Windows\WindowsUpdate.log
2015-06-26 22:17 - 2011-08-19 08:03 - 00000886 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-26 21:59 - 2013-10-23 22:39 - 00046103 _____ C:\Windows\setupact.log
2015-06-26 21:59 - 2011-08-19 08:03 - 00000882 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-26 21:59 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-06-26 21:39 - 2013-05-07 09:34 - 00000940 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1146453529-3827096963-1341687669-1000UA.job
2015-06-26 20:42 - 2015-02-06 20:56 - 00000000 ____D C:\Users\Korisnik\Desktop\sabloncici
2015-06-26 09:39 - 2013-05-07 09:34 - 00000918 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1146453529-3827096963-1341687669-1000Core.job
2015-06-26 06:48 - 2010-09-13 15:14 - 00000000 ____D C:\Users\Korisnik\AppData\Local\Adobe
2015-06-25 18:50 - 2013-06-10 23:16 - 00000000 ____D C:\Program Files\Opera
2015-06-25 18:36 - 2015-02-06 23:03 - 00000000 ____D C:\ProgramData\boost_interprocess
2015-06-23 22:04 - 2013-01-14 03:28 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-06-23 22:04 - 2012-01-12 09:20 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-06-23 18:18 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache
2015-06-23 17:23 - 2013-11-18 01:29 - 01895432 _____ C:\Windows\PFRO.log
2015-06-23 16:18 - 2011-02-21 22:31 - 00000000 ____D C:\Windows\system32\appmgmt
2015-06-23 16:16 - 2010-09-13 15:13 - 00000000 ____D C:\Program Files\Adobe
2015-06-23 16:15 - 2010-09-13 15:14 - 00000000 ____D C:\Users\Korisnik\AppData\Roaming\Adobe
2015-06-23 15:42 - 2015-04-07 15:53 - 00000332 _____ C:\Windows\Tasks\HPCeeScheduleForKorisnik.job
2015-06-23 14:33 - 2010-09-13 14:30 - 00000052 _____ C:\Windows\system32\DOErrors.log
2015-06-22 23:48 - 2014-08-26 15:48 - 00000000 ____D C:\Users\Korisnik\AppData\Local\TB
2015-06-22 23:48 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\L2Schemas
2015-06-22 22:49 - 2011-10-31 16:08 - 00000000 ____D C:\Users\Korisnik\AppData\Roaming\Malwarebytes
2015-06-22 22:49 - 2011-10-31 16:08 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-06-22 22:49 - 2011-10-31 16:08 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2015-06-17 20:31 - 2013-03-13 12:15 - 00000000 ____D C:\ProgramData\Avira
2015-06-16 19:20 - 2014-08-07 15:58 - 00000000 ____D C:\ProgramData\Package Cache
2015-06-16 19:20 - 2013-03-13 12:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-06-16 19:20 - 2013-03-13 12:15 - 00000000 ____D C:\Program Files\Avira
2015-06-14 08:15 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET
2015-06-14 07:42 - 2010-09-13 09:32 - 00809448 _____ C:\Windows\system32\PerfStringBackup.INI
2015-06-14 07:38 - 2013-08-16 23:20 - 00000000 ____D C:\Windows\system32\MRT
2015-06-14 07:23 - 2011-05-27 13:03 - 136900096 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-06-13 22:46 - 2011-03-07 14:28 - 00000000 ____D C:\Users\Korisnik\kreacije
2015-06-13 22:46 - 2010-09-13 09:28 - 00000000 ____D C:\Users\Korisnik
2015-06-11 18:40 - 2011-10-31 15:14 - 00001515 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-06-11 18:38 - 2009-07-14 06:33 - 03882464 _____ C:\Windows\system32\FNTCACHE.DAT
2015-06-11 18:36 - 2015-04-16 08:12 - 00000000 ____D C:\Windows\system32\appraiser
2015-06-11 18:36 - 2014-05-06 12:51 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-06-11 00:01 - 2010-09-13 15:05 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-06-10 14:47 - 2013-03-13 12:15 - 00136728 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2015-06-10 14:47 - 2013-03-13 12:15 - 00108448 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2015-06-10 14:47 - 2013-03-13 12:15 - 00031848 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\ssmdrv.sys
2015-06-07 11:47 - 2011-01-07 14:13 - 00000069 _____ C:\Windows\NeroDigital.ini
2015-06-04 10:49 - 2015-03-26 10:16 - 00000000 ____D C:\Users\Korisnik\Desktop\nada sabloni
2015-05-31 13:39 - 2015-03-27 14:33 - 00037770 _____ C:\Users\Korisnik\Desktop\sabloni dim. i cene.xlsx
2015-05-28 08:05 - 2010-09-13 15:37 - 00000000 ___RD C:\Program Files\Skype

==================== Files in the root of some directories =======

2011-08-31 11:20 - 2011-09-05 07:52 - 0000000 _____ () C:\Users\Korisnik\AppData\Roaming\windrvconfig.txt
2011-01-22 12:37 - 2011-07-29 15:54 - 0013312 _____ () C:\Users\Korisnik\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2011-10-29 13:03 - 2011-10-29 13:24 - 0000440 _____ () C:\ProgramData\1kAlMiG2Kb7FzP
2010-09-13 14:46 - 2015-06-26 22:05 - 0000184 _____ () C:\ProgramData\HPWALog.txt
2011-10-29 13:03 - 2011-10-29 13:23 - 0000192 _____ () C:\ProgramData\~1kAlMiG2Kb7FzP
2011-10-29 13:03 - 2011-10-29 13:23 - 0000088 _____ () C:\ProgramData\~1kAlMiG2Kb7FzPr

Some files in TEMP:
====================
C:\Users\Korisnik\AppData\Local\temp\avgnt.exe
C:\Users\Korisnik\AppData\Local\temp\Quarantine.exe
C:\Users\Korisnik\AppData\Local\temp\setup.exe
C:\Users\Korisnik\AppData\Local\temp\sqlite3.dll
C:\Users\Korisnik\AppData\Local\temp\utt3BE8.tmp.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-06-23 18:10

==================== End of log ============================
mycity.rs/must-login.png

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6103

Zdravo opet igorpet, ja cu raditi na tvom slucaju.




1. Otvori Notepad (Text Document) i iskopiraj sledeći tekst unutar kod polja ispod:

Start
CreateRestorePoint:
Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f
CMD: bitsadmin /reset /allusers

CloseProcesses:
HKLM\...\Run: [] => [X]
HKU\S-1-5-21-1146453529-3827096963-1341687669-1000\...\Run: [] => C:\Users\Korisnik\AppData\Local\Temp\wpbt0.dll <===== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1146453529-3827096963-1341687669-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Toolbar: HKU\S-1-5-21-1146453529-3827096963-1341687669-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
FF Extension: Update My Browser - C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default\Extensions\{cc8f597b-0765-404e-a575-82aefbd81daf}.xpi [2013-03-13]
FF Extension: No Name - C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default\extensions\{cde38172-4160-4091-bf76-de675198d659}.xpi [not found]
FF Extension: No Name - C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi [not found]
FF ExtraCheck: C:\Program Files\mozilla firefox\firefox.cfg [2013-07-12] <==== ATTENTION
CHR Extension: (No Name) - C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl [2015-06-26]
CHR Extension: (No Name) - C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\nafaimnnclfjfedmmabolbppcngeolgf [2015-06-26]
U3 amaswpt7; C:\Windows\system32\Drivers\amaswpt7.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero byte File/Folder)
S3 catchme; \??\C:\Users\Korisnik\AppData\Local\Temp\catchme.sys [X]

Hosts:
C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default\Extensions\{cc8f597b-0765-404e-a575-82aefbd81daf}.xpi
C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl
C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\nafaimnnclfjfedmmabolbppcngeolgf
C:\Windows\system32\Drivers\amaswpt7.sys
C:\ProgramData\1kAlMiG2Kb7FzP
C:\ProgramData\HPWALog.txt
C:\ProgramData\~1kAlMiG2Kb7FzP
C:\ProgramData\~1kAlMiG2Kb7FzPr

RemoveProxy:
AlternateDataStreams: C:\ProgramData\TEMP:BC359956
RemoveDirectory: C:\AdwCleaner

EmptyTemp:
End


2. Sačuvaj notepad na Desktop pod nazivom fixlist.txt
To možes uraditi i iz notepad-a => klik na File potom na Save As i u novom prozoru, dole pod File Name: staviš za naziv fixlist.txt
Napomena: Važno je da se oba fajla, FRST i fixlist nalaze na istoj lokaciji jer u suprotnom fix nece raditi.

3. Ponovo pokreni FRST/FRST64, klikni jednom na dugme Fix i sačekaj.
Ukoliko alat zatraži restart sistema, dozvoli mu i postaraj se da alat kompletira fix nakon restarta sistema.



Alat će formirati log (Fixlog.txt) na Desktop-u. Potrebno je sadržaj tog loga iskopirati u poruku.
Napomena: Ukoliko te alat upozori da postoji novija verzija, postaraj se da preuzmes i koristiš ažuriranu kopiju FRST-a.

offline
  • Pridružio: 10 Jan 2012
  • Poruke: 27

Napisano: 27 Jun 2015 19:26

Hvala za trud Smile

Fix result of Farbar Recovery Scan Tool (x86) Version: 24-06-2015
Ran by Korisnik at 2015-06-27 15:18:31 Run:1
Running from C:\Users\Korisnik\Desktop
Loaded Profiles: Korisnik (Available Profiles: Korisnik)
Boot Mode: Normal

==============================================

fixlist content:
*****************
Start
CreateRestorePoint:
Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f
CMD: bitsadmin /reset /allusers

CloseProcesses:
HKLM\...\Run: [] => [X]
HKU\S-1-5-21-1146453529-3827096963-1341687669-1000\...\Run: [] => C:\Users\Korisnik\AppData\Local\Temp\wpbt0.dll <===== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1146453529-3827096963-1341687669-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Toolbar: HKU\S-1-5-21-1146453529-3827096963-1341687669-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
FF Extension: Update My Browser - C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default\Extensions\{cc8f597b-0765-404e-a575-82aefbd81daf}.xpi [2013-03-13]
FF Extension: No Name - C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default\extensions\{cde38172-4160-4091-bf76-de675198d659}.xpi [not found]
FF Extension: No Name - C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi [not found]
FF ExtraCheck: C:\Program Files\mozilla firefox\firefox.cfg [2013-07-12] <==== ATTENTION
CHR Extension: (No Name) - C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl [2015-06-26]
CHR Extension: (No Name) - C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\nafaimnnclfjfedmmabolbppcngeolgf [2015-06-26]
U3 amaswpt7; C:\Windows\system32\Drivers\amaswpt7.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero byte File/Folder)
S3 catchme; \??\C:\Users\Korisnik\AppData\Local\Temp\catchme.sys [X]

Hosts:
C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default\Extensions\{cc8f597b-0765-404e-a575-82aefbd81daf}.xpi
C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl
C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\nafaimnnclfjfedmmabolbppcngeolgf
C:\Windows\system32\Drivers\amaswpt7.sys
C:\ProgramData\1kAlMiG2Kb7FzP
C:\ProgramData\HPWALog.txt
C:\ProgramData\~1kAlMiG2Kb7FzP
C:\ProgramData\~1kAlMiG2Kb7FzPr

RemoveProxy:
AlternateDataStreams: C:\ProgramData\TEMP:BC359956
RemoveDirectory: C:\AdwCleaner

EmptyTemp:
End
*****************

Restore point was successfully created.

========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f =========

The operation completed successfully.



========= End of Reg: =========


========= bitsadmin /reset /allusers =========


BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

Unable to cancel {C3203D0C-4948-4DAC-A8C0-87D5865781BF}.
Unable to cancel {5307308F-D093-4A24-9B2B-24176EC6A287}.
0 out of 2 jobs canceled.

========= End of CMD: =========

Processes closed successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully.
HKU\S-1-5-21-1146453529-3827096963-1341687669-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully.
"HKLM\SOFTWARE\Policies\Google" => key removed successfully.
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully.
"HKU\S-1-5-21-1146453529-3827096963-1341687669-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully.
HKU\S-1-5-21-1146453529-3827096963-1341687669-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value removed successfully.
HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => key not found.
C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default\Extensions\{cc8f597b-0765-404e-a575-82aefbd81daf}.xpi => moved successfully.
C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default\extensions\{cde38172-4160-4091-bf76-de675198d659}.xpi => not found.
C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi => not found.
C:\Program Files\mozilla firefox\firefox.cfg => moved successfully.
C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl => moved successfully.
C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\nafaimnnclfjfedmmabolbppcngeolgf => moved successfully.
amaswpt7 => Service not found.
catchme => Service removed successfully.
"C:\Windows\System32\Drivers\etc\hosts" => Could not move.
Could not restore Hosts.
"C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default\Extensions\{cc8f597b-0765-404e-a575-82aefbd81daf}.xpi" => File/Folder not found.
"C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl" => File/Folder not found.
"C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\nafaimnnclfjfedmmabolbppcngeolgf" => File/Folder not found.
"C:\Windows\system32\Drivers\amaswpt7.sys" => File/Folder not found.
C:\ProgramData\1kAlMiG2Kb7FzP => moved successfully.
C:\ProgramData\HPWALog.txt => moved successfully.
C:\ProgramData\~1kAlMiG2Kb7FzP => moved successfully.
C:\ProgramData\~1kAlMiG2Kb7FzPr => moved successfully.

========= RemoveProxy: =========

HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully.
HKU\S-1-5-21-1146453529-3827096963-1341687669-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully.
HKU\S-1-5-21-1146453529-3827096963-1341687669-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully.


========= End of RemoveProxy: =========

C:\ProgramData\TEMP => ":BC359956" ADS removed successfully..
"C:\AdwCleaner" => removed successfully..
EmptyTemp: => 2.5 GB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 15:22:00 ====

Dopuna: 27 Jun 2015 19:41

Racunar je sada startovan znatno brze nego pre ove intervencije, oko 3-4 min, mada bio je malo brzi pre, u svakom slucaju ostvaren je vidan napredak

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6103

Odlicno, idemo sada na dodatnu laku proveru. Preuzmi smeenk-ov zoek () sa ovog linka i sačuvaj ga na Desktop.
Raspakuj arhivu u neki folder (uputstvo), a zatim:

zatvori browser i ostale pokrenute programe;
privremeno deaktiviraj zaštitni softver ( ukoliko je to potrebno ) Uputstvo ;
dvoklikom pokreni zoek na ikonicu programa ;
pričekaj da se alat startuje ...


Klikni na More Options dugme i stikliraj polje ispred sledece opcije:
Auto Clean
Napomena: Stikliraj samo navedenu opciju, ostale opcije ne dirati ! !


Klikni na dugme i pričekaj da se skeniranje završi.
zoek ce po potrebi, restartovati Windows a na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.

Napomena:Izveštaj će biti sačuvan pod nazivom zoek-results.log na sistemskoj particiji (tipična lokacija: C:\zoek-results.log)

Arrow Kopiraj sadrzaj tog loga u poruku.

offline
  • Pridružio: 10 Jan 2012
  • Poruke: 27

Napisano: 27 Jun 2015 22:47

Opet je restart trajao dosta dugo, preko 20min.
Izbacio upozorenje, sliku prilazem, a ubrzo nakon zaustavljanja scripta pokrenuo se i komp.
Izvestaj:

Zoek.exe v5.0.0.0 Updated 04-May-2015
Tool run by Korisnik on Sat 06/27/2015 at 21:54:27.17.
Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Korisnik\Desktop\zoek.exe [Scan all users] [Checkboxes used]

==== System Restore Info ======================

6/27/2015 21:56:14 Zoek.exe System Restore Point Created Successfully.

==== Empty Folders Check ======================

C:\Program Files\Malwarebytes' Anti-Malware deleted successfully
C:\Program Files\MSXML 4.0 deleted successfully
C:\PROGRA~2\ALM deleted successfully
C:\PROGRA~2\CorelDRAW Graphics Suite X7 deleted successfully
C:\Users\Korisnik\AppData\Roaming\Malwarebytes deleted successfully
C:\Users\Korisnik\AppData\Roaming\Media Player Classic deleted successfully
C:\Users\Korisnik\AppData\Local\TB deleted successfully
C:\Users\Korisnik\AppData\Local\VirtualStore deleted successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-1146453529-3827096963-1341687669-1000\Software\Microsoft\Internet Explorer\SearchScopes\{C2E752DD-3236-4C3D-ACA6-897956DCE3AC} deleted successfully
HKEY_USERS\S-1-5-21-1146453529-3827096963-1341687669-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} deleted successfully

==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== FireFox Fix ======================

ProfilePath: C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default

user.js not found
---- Lines CT3072253 removed from prefs.js ----
user_pref("CT3072253.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT3072253.FirstTime", "true");
user_pref("CT3072253.FirstTimeFF3", "true");
user_pref("CT3072253.LoginRevertSettingsEnabled", true);
user_pref("CT3072253.RevertSettingsEnabled", true);
user_pref("CT3072253.UserID", "UN34630251176747673");
user_pref("CT3072253.addressBarTakeOverEnabledInHidden", "true");
user_pref("CT3072253.autoDisableScopes", -1);
user_pref("CT3072253.browser.search.defaultthis.engineName", true);
user_pref("CT3072253.cbcountry_001", "GR");
user_pref("CT3072253.cbfirsttime", "Thu Jul 26 2012 10:10:39 GMT+0200 (Central Europe Daylight Time)");
user_pref("CT3072253.enableAlerts", "always");
user_pref("CT3072253.enableFix404ByUser", "FALSE");
user_pref("CT3072253.enableSearchFromAddressBar", "true");
user_pref("CT3072253.firstTimeDialogOpened", "true");
user_pref("CT3072253.fixPageNotFoundError", "true");
user_pref("CT3072253.fixPageNotFoundErrorByUser", "true");
user_pref("CT3072253.fixPageNotFoundErrorInHidden", "true");
user_pref("CT3072253.fixUrls", true);
user_pref("CT3072253.fullUserID", "UN34630251176747673.UP.20130713175956");
user_pref("CT3072253.installId", "fft142C.tmp.exe");
user_pref("CT3072253.installType", "XPE");
user_pref("CT3072253.isCheckedStartAsHidden", true);
user_pref("CT3072253.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT3072253.isFirstTimeToolbarLoading", "false");
user_pref("CT3072253.isNewTabEnabled", true);
user_pref("CT3072253.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
user_pref("CT3072253.isWelcomPage", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
user_pref("CT3072253.keyword", true);
user_pref("CT3072253.lastVersion", "10.16.4.519");
user_pref("CT3072253.mam_gk_installer_preapproved.enc", "ZmFsc2U=");
user_pref("CT3072253.migrateAppsAndComponents", true);
user_pref("CT3072253.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"\",\"EB_MAIN_FRAME_URL\":\"https%3A%2F%2Fwww.facebook.com%2F%3Fstype%3Dlo%26jlou%3
user_pref("CT3072253.openThankYouPage", "true");
user_pref("CT3072253.openUninstallPage", "FALSE");
user_pref("CT3072253.search.searchAppId", "129571859753931591");
user_pref("CT3072253.search.searchCount", "1");
user_pref("CT3072253.searchInNewTabEnabledByUser", "true");
user_pref("CT3072253.searchInNewTabEnabledInHidden", "true");
user_pref("CT3072253.searchProtector.notifyChanges", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT3072253.searchSuggestEnabledByUser", "false");
user_pref("CT3072253.searchUserMode", "2");
user_pref("CT3072253.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT3072253.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
user_pref("CT3072253.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}");
user_pref("CT3072253.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT3072253\"}");
user_pref("CT3072253.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"http://uTorrentControl2.OurToolbar.
user_pref("CT3072253.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"uTorrentControl2\"}");
user_pref("CT3072253.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT3072253.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"2\"}");
user_pref("CT3072253.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1343290236505");
user_pref("CT3072253.serviceLayer_services_appTracking_lastUpdate", "1343290237320");
user_pref("CT3072253.serviceLayer_services_appsMetadata_lastUpdate", "1343290236483");
user_pref("CT3072253.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1343290237048");
user_pref("CT3072253.serviceLayer_services_location_lastUpdate", "1372448618293");
user_pref("CT3072253.serviceLayer_services_login_10.10.20.14_lastUpdate", "1347023114036");
user_pref("CT3072253.serviceLayer_services_login_10.10.27.6_lastUpdate", "1353344661248");
user_pref("CT3072253.serviceLayer_services_login_10.13.40.15_lastUpdate", "1358532213915");
user_pref("CT3072253.serviceLayer_services_login_10.14.370.524_lastUpdate", "1364228964658");
user_pref("CT3072253.serviceLayer_services_login_10.14.40.128_lastUpdate", "1360668009617");
user_pref("CT3072253.serviceLayer_services_login_10.14.65.43_lastUpdate", "1363693618356");
user_pref("CT3072253.serviceLayer_services_login_10.15.0.562_lastUpdate", "1368218069251");
user_pref("CT3072253.serviceLayer_services_login_10.15.2.523_lastUpdate", "1369672407341");
user_pref("CT3072253.serviceLayer_services_login_10.16.2.509_lastUpdate", "1372506228000");
user_pref("CT3072253.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1343290237099");
user_pref("CT3072253.serviceLayer_services_searchAPI_lastUpdate", "1343290235748");
user_pref("CT3072253.serviceLayer_services_serviceMap_lastUpdate", "1372448617775");
user_pref("CT3072253.serviceLayer_services_toolbarContextMenu_lastUpdate", "1343290236959");
user_pref("CT3072253.serviceLayer_services_toolbarSettings_lastUpdate", "1372513425114");
user_pref("CT3072253.serviceLayer_services_translation_lastUpdate", "1372448618127");
user_pref("CT3072253.settingsINI", true);
user_pref("CT3072253.shouldFirstTimeDialog", "false");
user_pref("CT3072253.showToolbarPermission", "false");
user_pref("CT3072253.toolbarBornServerTime", "26-7-2012");
user_pref("CT3072253.toolbarCurrentServerTime", "29-6-2013");
user_pref("CT3072253.toolbarDisabled", "true");
user_pref("CT3072253.toolbarLoginClientTime", "Tue Mar 19 2013 16:05:58 GMT+0100 (Central Europe Standard Time)");
user_pref("CT3072253.upgradeFromClearSBVersion", true);
user_pref("CT3072253.url_history0001", "http://www.facebook.com/?ref=tn_tnmn:::clickhandler:::1343295109138,,,http://www.facebook.com/?ref=tn_tnmn:::c
user_pref("CT3072253_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1407511471477,\"isWithState\":\"\",\"timeFromStar
---- Lines CT3078318 removed from prefs.js ----
user_pref("CT3078318.browser.search.defaultthis.engineName", "true");
user_pref("CT3078318.FF19Solved", "true");
user_pref("CT3078318.fullUserID", "UN32865346572378324.IN.2013060402549");
user_pref("CT3078318.installDate", "04/06/2013 0:25:50");
user_pref("CT3078318.installerVersion", "1.4.3.0");
user_pref("CT3078318.installSessionId", "-1");
user_pref("CT3078318.installSp", "TRUE");
user_pref("CT3078318.installUsage", "04/06/2013 0:26:44");
user_pref("CT3078318.installUsageEarly", "04/06/2013 0:26:44");
user_pref("CT3078318.keyword", "true");
user_pref("CT3078318.searchRevert", "false");
user_pref("CT3078318.searchUserMode", "2");
user_pref("CT3078318.UserID", "UN32865346572378324");
user_pref("CT3078318.versionFromInstaller", "10.16.1.21");
---- Lines CT3115642 removed from prefs.js ----
user_pref("CT3115642..clientLogIsEnabled", false);
user_pref("CT3115642..clientLogServiceUrl", "http://clientlog.users.tbccint.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
user_pref("CT3115642..uninstallLogServiceUrl", "http://uninstall.users.tbccint.com/Uninstall.asmx/RegisterToolbarUninstallation");
user_pref("CT3115642.alertChannelId", "1510401");
user_pref("CT3115642.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
user_pref("CT3115642.AppTrackingLastCheckTime", "Mon Jul 23 2012 02:09:25 GMT+0200 (Central Europe Daylight Time)");
user_pref("CT3115642.autoDisableScopes", -1);
user_pref("CT3115642.backendstorage.cb", "31");
user_pref("CT3115642.backendstorage.cbcountry_001", "5253");
user_pref("CT3115642.backendstorage.cbfirsttime", "53756E204A756E20313720323031322032333A34313A313420474D542B30323030202843656E7472616C204575726F70652
user_pref("CT3115642.backendstorage.url_history0001", "687474703A2F2F7777772E66616365626F6F6B2E636F6D2F233A3A3A636C69636B68616E646C65723A3A3A313334333
user_pref("CT3115642.BrowserCompStateIsOpen_129670699498945147", true);
user_pref("CT3115642.BrowserCompStateIsOpen_130055935814101039", true);
user_pref("CT3115642.CTID", "CT3115642");
user_pref("CT3115642.CurrentServerDate", "8-8-2014");
user_pref("CT3115642.DialogsAlignMode", "LTR");
user_pref("CT3115642.DialogsGetterLastCheckTime", "Fri Aug 08 2014 17:24:45 GMT+0200 (Central Europe Standard Time)");
user_pref("CT3115642.DownloadReferralCookieData", "");
user_pref("CT3115642.DSChangedManually", true);
user_pref("CT3115642.DSInstall", true);
user_pref("CT3115642.FirstServerDate", "18-6-2012");
user_pref("CT3115642.FirstTime", true);
user_pref("CT3115642.FirstTimeFF3", true);
user_pref("CT3115642.FirstTimeHiddenVer", true);
user_pref("CT3115642.FixPageNotFoundErrors", true);
user_pref("CT3115642.globalFirstTimeInfoLastCheckTime", "Fri Jul 20 2012 10:59:50 GMT+0200 (Central Europe Daylight Time)");
user_pref("CT3115642.GroupingServerCheckInterval", 1440);
user_pref("CT3115642.GroupingServiceUrl", "http://grouping.tbccint.com/");
user_pref("CT3115642.HasUserGlobalKeys", true);
user_pref("CT3115642.homepageProtectorEnableByLogin", true);
user_pref("CT3115642.HomePageProtectorEnabled", true);
user_pref("CT3115642.HPInstall", true);
user_pref("CT3115642.initDone", true);
user_pref("CT3115642.Initialize", true);
user_pref("CT3115642.InitializeCommonPrefs", true);
user_pref("CT3115642.InstallationAndCookieDataSentCount", 3);
user_pref("CT3115642.InstallationId", "fft9802.tmp.exe");
user_pref("CT3115642.InstallationType", "XPE");
user_pref("CT3115642.InstalledDate", "Sun Jun 17 2012 23:41:08 GMT+0200 (Central Europe Daylight Time)");
user_pref("CT3115642.IsAlertDBUpdated", true);
user_pref("CT3115642.isAppTrackingManagerOn", true);
user_pref("CT3115642.IsGrouping", false);
user_pref("CT3115642.IsInitSetupIni", true);
user_pref("CT3115642.IsMulticommunity", false);
user_pref("CT3115642.IsOpenThankYouPage", true);
user_pref("CT3115642.IsOpenUninstallPage", false);
user_pref("CT3115642.IsProtectorsInit", true);
user_pref("CT3115642.LanguagePackLastCheckTime", "Fri Aug 08 2014 17:24:42 GMT+0200 (Central Europe Standard Time)");
user_pref("CT3115642.LanguagePackReloadIntervalMM", 1440);
user_pref("CT3115642.LanguagePackServiceUrl", "http://translation.users.tbccint.com/Translation.ashx");
user_pref("CT3115642.LastLogin_3.13.0.6", "Thu Jul 12 2012 12:09:50 GMT+0200 (Central Europe Daylight Time)");
user_pref("CT3115642.LastLogin_3.14.1.0", "Mon Jul 23 2012 09:28:55 GMT+0200 (Central Europe Daylight Time)");
user_pref("CT3115642.LastLogin_3.15.1.0", "Tue Nov 13 2012 08:28:27 GMT+0100 (Central Europe Standard Time)");
user_pref("CT3115642.LastLogin_3.16.0.3", "Tue Feb 12 2013 12:18:07 GMT+0100 (Central Europe Standard Time)");
user_pref("CT3115642.LastLogin_3.18.0.7", "Fri Aug 08 2014 17:24:44 GMT+0200 (Central Europe Standard Time)");
user_pref("CT3115642.LatestVersion", "3.20.0.4"ooltipUrl", "http://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
user_pref("CT3115642.MCDetectTooltipWidth", "295");
user_pref("CT3115642.myStuffEnabled", true);
user_pref("CT3115642.MyStuffEnabledAtInstallation", true);
user_pref("CT3115642.myStuffPublihserMinWidth", 400);
user_pref("CT3115642.myStuffSearchUrl", "http://appstrm.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
user_pref("CT3115642.myStuffServiceIntervalMM", 1440);
user_pref("CT3115642.navigateToUrlOnSearch", false);
user_pref("CT3115642.oldAppsList", "10000001,10000002,111,129749429815607036,129670699498945147,1000034,1000080,1000082,1000234,1000515,1000,1001,1002
user_pref("CT3115642.OriginalFirstVersion", "3.13.0.6");
user_pref("CT3115642.revertSettingsEnabled", true);
user_pref("CT3115642.SavedHomepage", "http://www.google.com/");
user_pref("CT3115642.SearchBoxWidth", 303);
user_pref("CT3115642.SearchEngineBeforeUnload", "chrome://browser-region/locale/region.properties");
user_pref("CT3115642.SearchFromAddressBarIsInit", true);
user_pref("CT3115642.SearchInNewTabEnabled", true);
user_pref("CT3115642.SearchInNewTabIntervalMM", 1440);
user_pref("CT3115642.SearchInNewTabLastCheckTime", "Fri Aug 08 2014 17:24:32 GMT+0200 (Central Europe Standard Time)");
user_pref("CT3115642.SearchInNewTabUserEnabled", false);
user_pref("CT3115642.searchProtectorDialogDelayInSec", 10);
user_pref("CT3115642.searchProtectorEnableByLogin", true);
user_pref("CT3115642.SearchProtectorEnabled", false);
user_pref("CT3115642.SearchProtectorToolbarDisabled", true);
user_pref("CT3115642.SendProtectorDataViaLogin", true);
user_pref("CT3115642.ServiceMapLastCheckTime", "Fri Aug 08 2014 17:24:41 GMT+0200 (Central Europe Standard Time)");
user_pref("CT3115642.SettingsLastCheckTime", "Fri Aug 08 2014 17:24:32 GMT+0200 (Central Europe Standard Time)");
user_pref("CT3115642.SettingsLastUpdate", "1405919504");
user_pref("CT3115642.SHRINK_TOOLBAR", 1);
user_pref("CT3115642.testingCtid", "");
user_pref("CT3115642.ThirdPartyComponentsInterval", 504);
user_pref("CT3115642.ThirdPartyComponentsLastCheck", "Tue Jul 10 2012 10:59:47 GMT+0200 (Central Europe Daylight Time)");
user_pref("CT3115642.ThirdPartyComponentsLastUpdate", "1331805997");
user_pref("CT3115642.toolbarAppMetaDataLastCheckTime", "Fri Aug 08 2014 17:24:42 GMT+0200 (Central Europe Standard Time)");
user_pref("CT3115642.toolbarContextMenuLastCheckTime", "Mon Jul 16 2012 08:26:47 GMT+0200 (Central Europe Daylight Time)");
user_pref("CT3115642.ToolbarDisabled", true);
user_pref("CT3115642.ToolbarShrinkedFromSetup", false);
user_pref("CT3115642.TrusteLinkUrl", "http://trust.cpccint.com");
user_pref("CT3115642.usagesFlag", 2);
user_pref("CT3115642.UserID", "UN44935616540269765");
user_pref("CT3115642.ValidationData_Search", 2);
user_pref("CT3115642.ValidationData_Toolbar", 2);
---- Lines CT3289075 removed from prefs.js ----
user_pref("CT3289075.FF19Solved", "true");
user_pref("CT3289075.fullUserID", "UN36271699063818199.IN.20140826154725");
user_pref("CT3289075.installDate", "26/08/2014 15:47:37");
user_pref("CT3289075.installerVersion", "1.8.1.4");
user_pref("CT3289075.installSessionId", "{3E587DA8-E4A9-4F0B-9153-420F26658ACF}");
user_pref("CT3289075.installSp", "false");
user_pref("CT3289075.searchRevert", "false");
user_pref("CT3289075.searchUninstallUserMode", "7");
user_pref("CT3289075.searchUserMode", "7");
user_pref("CT3289075.toolbarInstallDate", "26-08-2014 15:47:26");
user_pref("CT3289075.UserID", "UN36271699063818199");
user_pref("CT3289075.versionFromInstaller", "10.33.0.17");
user_pref("CT3289075.xpeMode", "1");
---- Lines Search removed from prefs.js ----
user_pref("sweetim.toolbar.search.external", "<?xml version=\"1.0\"?><TOOLBAR><EXTERNAL_SEARCH engine=\"http://*google.*\" param=\"q=\" /><EXTERNAL_SE
---- Lines ask.com modified from prefs.js ----

user_pref("extensions.installCache", "[{\"name\":\"app-global\",\"addons\":{\"{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\":{\"descriptor\":\"C:\\\\Program
---- Lines Customized removed from prefs.js ----
user_pref("extensions.testpilot.alreadyCustomizedToolbar", true);
---- Lines EEE6C361-6118-11DC-9C72-001320C79847 removed from prefs.js ----
user_pref("extensions.{EEE6C361-6118-11DC-9C72-001320C79847}.install-event-fired", true);
---- Lines EEE6C361-6118-11DC-9C72-001320C79847 modified from prefs.js ----

user_pref("extensions.installCache", "[{\"name\":\"app-global\",\"addons\":{\"{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\":{\"descriptor\":\"C:\\\\Program
---- Lines Sweet removed from prefs.js ----
user_pref("sweetim.toolbar.cargo", "3.1010000.10002");
user_pref("sweetim.toolbar.cda.DisableOveride.enable", "true");
user_pref("sweetim.toolbar.cda.HideOveride.enable", "true");
user_pref("sweetim.toolbar.cda.RemoveOveride.enable", "true");
user_pref("sweetim.toolbar.cda.returnValue", "none");
user_pref("sweetim.toolbar.dialogs.0.enable", "true");
user_pref("sweetim.toolbar.dialogs.0.handler", "chrome://sim_toolbar_package/content/optionsdialog-handler.js");
user_pref("sweetim.toolbar.dialogs.0.height", "335");
user_pref("sweetim.toolbar.dialogs.0.id", "id_options_dialog");
user_pref("sweetim.toolbar.dialogs.0.title", "$string.config.label;");
user_pref("sweetim.toolbar.dialogs.0.width", "761");
user_pref("sweetim.toolbar.dialogs.1.enable", "true");
user_pref("sweetim.toolbar.dialogs.1.handler", "chrome://sim_toolbar_package/content/exampledialog-handler.js");
user_pref("sweetim.toolbar.dialogs.1.height", "300");
user_pref("sweetim.toolbar.dialogs.1.id", "id_example_dialog");
user_pref("sweetim.toolbar.dialogs.1.title", "Example (unit-test) dialog");
user_pref("sweetim.toolbar.dialogs.1.url", "chrome://sim_toolbar_package/content/exampledialog.html");
user_pref("sweetim.toolbar.dialogs.1.width", "500");
user_pref("sweetim.toolbar.dialogs.2.enable", "true");
user_pref("sweetim.toolbar.dialogs.2.handler", "chrome://sim_toolbar_package/content/cdadialog-handler.js");
user_pref("sweetim.toolbar.dialogs.2.height", "150");
user_pref("sweetim.toolbar.dialogs.2.id", "id_dialog_hide_disable_remove");
user_pref("sweetim.toolbar.dialogs.2.title", "Option Dialog");
user_pref("sweetim.toolbar.dialogs.2.width", "530");
user_pref("sweetim.toolbar.highlight.colors", "#FFFF00,#00FFE4,#5AFF00,#0087FF,#FFCC00,#FF00F0");
user_pref("sweetim.toolbar.keywordUrlGuard.enable", "false");
user_pref("sweetim.toolbar.logger.ConsoleHandler.MinReportLevel", "7");
user_pref("sweetim.toolbar.logger.FileHandler.FileName", "ff-toolbar.log");
user_pref("sweetim.toolbar.logger.FileHandler.MaxFileSize", "200000");
user_pref("sweetim.toolbar.logger.FileHandler.MinReportLevel", "7");
user_pref("sweetim.toolbar.mode.debug", "false");
user_pref("sweetim.toolbar.newtab.created", "false");
user_pref("sweetim.toolbar.newtab.enable", "false");
user_pref("sweetim.toolbar.prad.initialized_by_rc", "true");
user_pref("sweetim.toolbar.previous.keyword.URL", "");
user_pref("sweetim.toolbar.RevertDialog.enable", "false");
user_pref("sweetim.toolbar.scripts.0.addcontextdiv", "true");
user_pref("sweetim.toolbar.scripts.0.callback", "simVerification");
user_pref("sweetim.toolbar.scripts.0.domain-blacklist", "");
user_pref("sweetim.toolbar.scripts.0.domain-whitelist", "http://(www.|apps.)?facebook\\.com.*");
user_pref("sweetim.toolbar.scripts.0.elementid", "id_script_sim_fb");
user_pref("sweetim.toolbar.scripts.0.enable", "false");
user_pref("sweetim.toolbar.scripts.0.id", "id_script_fb");
user_pref("sweetim.toolbar.scripts.1.addcontextdiv", "false");
user_pref("sweetim.toolbar.scripts.1.callback", "");
user_pref("sweetim.toolbar.scripts.1.domain-whitelist", "");
user_pref("sweetim.toolbar.scripts.1.elementid", "id_predict_include_script");
user_pref("sweetim.toolbar.scripts.1.enable", "false");
user_pref("sweetim.toolbar.scripts.1.id", "id_script_prad");
user_pref("sweetim.toolbar.scripts.1.url", "http://cdn1.certified-apps.com/scripts/shared/enable.js?si=3104&tid=chff1");
user_pref("sweetim.toolbar.scripts.2.addcontextdiv", "true");
user_pref("sweetim.toolbar.scripts.2.callback", "simVerification");
user_pref("sweetim.toolbar.scripts.2.domain-blacklist", "");
user_pref("sweetim.toolbar.scripts.2.domain-whitelist", "https://(www.|apps.)?facebook\\.com.*");
user_pref("sweetim.toolbar.scripts.2.elementid", "id_script_sim_fb");
user_pref("sweetim.toolbar.scripts.2.enable", "false");
user_pref("sweetim.toolbar.scripts.2.id", "id_script_fb_httpS");
user_pref("sweetim.toolbar.search.history.capacity", "10");
user_pref("sweetim.toolbar.searchguard.enable", "false");
user_pref("sweetim.toolbar.searchguard.initialized_by_rc", "true");
user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_HP", "0");
user_pref("sweetim.toolbar.simapp_id", "{200EC657-D6F6-11E1-B18A-70F3952608C2}");
user_pref("sweetim.toolbar.UserSelectedSaveSettings", "true");
user_pref("sweetim.toolbar.version", "1.9.0.0");
user_pref("sweetim.toolbar.Visibility.enable", "true");
user_pref("sweetim.toolbar.Visibility.intervaldays", "7");
user_pref("sweetim.toolbar.Visibility.VisibilityGuardLastUnHide", "0");
---- FireFox user.js and prefs.js backups ----

prefs_20150627_2212_.backup

==== Deleting Files \ Folders ======================

C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi not found
C:\Windows\system32\appdata deleted
C:\Program Files\Yahoo! deleted
C:\user.js deleted
C:\found.000 deleted
C:\Users\Korisnik\AppData\Roaming\windrvconfig.txt deleted
C:\PROGRA~2\Package Cache deleted
C:\Users\Korisnik\AppData\LocalLow\TB deleted
C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default\CT3072253 deleted
C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default\CT3078318 deleted
C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default\CT3115642 deleted
C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default\CT3289075 deleted
C:\Windows\Installer\{C3E85EE9-5892-4142-B537-BCEB3DAC4C3D} deleted
C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default\smartbar deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default
user_pref("browser.search.selectedEngine", "Yahoo Search");

==== Firefox Extensions ======================

ProfilePath: C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default
- leethax.net extension - %ProfilePath%\extensions\leethax@leethax.net.xpi
- Instrument Test - %ProfilePath%\extensions\testpilot@labs.mozilla.com.xpi

AppDir: C:\Program Files\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
- Skype Click to Call - %AppDir%\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi

==== Firefox Plugins ======================

Profilepath: C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default
3CD19649B2C3023D65E67C056457A2BC - C:\Users\Korisnik\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll - Facebook Video Calling Plugin
D1DC265C3FF7F92B4A75A55B3749D48C - C:\Program Files\VideoLAN\VLC\npvlc.dll - VLC Web Plugin
8F24103AB984847AA2939F58F19CCC98 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U21
ADC539F67D3198679F480974EE203678 - C:\Windows\system32\npDeployJava1.dll - Java Deployment Toolkit 7.0.210.11
C0F8E64200332C0A2B6A78D29257968D - C:\Program Files\QuickTime\Plugins\npqtplugin7.dll - QuickTime Plug-in 7.6.9
A517760D4AD38550BC1DFD6B96F1B59C - C:\Program Files\QuickTime\Plugins\npqtplugin6.dll - QuickTime Plug-in 7.6.9
E2B1CAEE5DDA3A60DB4212BB12AFE1E3 - C:\Program Files\QuickTime\Plugins\npqtplugin5.dll - QuickTime Plug-in 7.6.9
6C79088343E7D1A6E9239CDD21A94EEA - C:\Program Files\QuickTime\Plugins\npqtplugin4.dll - QuickTime Plug-in 7.6.9
ED5D191844D295959F82EB8C27546AC8 - C:\Program Files\QuickTime\Plugins\npqtplugin3.dll - QuickTime Plug-in 7.6.9
8E324717EDBF12F7E005D26DF26A0F96 - C:\Program Files\QuickTime\Plugins\npqtplugin2.dll - QuickTime Plug-in 7.6.9
6C859C6FCE6D694EAFD7EA3AE66D54DB - C:\Program Files\QuickTime\Plugins\npqtplugin.dll - QuickTime Plug-in 7.6.9
DBE61E0345E8B249E67C104877992716 - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll - RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit)
8908AC33D36F55A60A87A5290360FA27 - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll - RealPlayer Version Plugin
A055971A27B8B767F5F0858B8F299282 - C:\Program Files\Adobe\Reader 9.0\Reader\browser\nppdf32.dll - Adobe Acrobat
15E298B5EC5B89C5994A59863969D9FF - C:\Windows\system32\npmproxy.dll - Microsoft® Windows® Operating System


==== Chromium Look ======================

Google Chrome Version: 43.0.2357.130

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
flliilndjeohchalpbbcdekjklbdgfkk - No path found[]
lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx[05/01/2015 11:17]

Chrome Hotword Shared Module - Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg
Skype Click to Call - Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl

==== Chromium Startpages ======================

C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Preferences
.google.com/service/update2/crx","version":"8.1"},"page_ordinal":"n","path":"pjkljhegncpnkpknbcohdijeoejaedia\\8.1_0","preferences":{},"regular_only_preferences":{},"state":1,"was_installed_by_default":true,"was_installed_by_oem":false}}},"pinned_tabs":[],"protection":{"macs":{"browser":{"show_home_button":"2E26C8CD804008169297C57DFDA02E7C65D572ADE5768CB11EE3B4B54FBF24DE"},"default_search_provider":{"keyword":"6681CE223F050FD3F517A8F9CB8DD5F6DEBE2380441C4BDA43D441E46451757E","name":"7359B9F46272780EDC82573D0719151751D4A8DFDF7BC2A443B780EF03C74BAA","search_url":"B517F45EC06657D817B14BFA2082D942D2678282A702D1412A293D4D13A83639"},"default_search_provider_data":{"template_url_data":"1FF8E0CE06E667E56E29EC2983B5DD2372636CA6E7578EA81CBF37CC8E6E8917"},"extensions":{"settings":{"aapocclcgogkmnckokdopfmhonfmgoek":"822662C59B99383B90447D9965449C134B9646D74D595C269349929D6204DB84","ahfgeienlihckogmohjhadlkjgocpleb":"0F675C968571BC197CEB3059152090C7146E0ABDB490EDABBD4FA610DDEDEA64","aohghmighlieiainnegkcijnfilokake":"4CCDCC705BFD6D81D3513A8A3AD7A6D42F0A438C1EFF8B09D484635D421FDE66","apdfllckaahabafndbhieahigkjlhalf":"B64F5A09C1D319334443816222DDBC1224DB00D7EC30733B22BC105352AFE1FE","bepbmhgboaologfdajaanbcjmnhjmhfn":"26424DBDE7CB9CE78DD51E529F6A3BB7C85EB86B8EF4D6EE651D4A5CC7124A3A","blpcfgokakmgnkcojhhkbfbldkacnbeo":"61A6C76D860AF830DCBBE7B1835F18420EE0193AF4D8080CB9496FBEA8C5A7E1","bopakagnckmlgajfccecajhnimjiiedh":"82E11B5875061046FA0C832A43428B14D87BA5E88701AFD43769A11350190620","coobgpohoikkiipiblmjeljniedjpjpf":"876116B0E5569E42914B02BE0C109C2DB2135424CA7D4A1A0EC353636DAF45D6","dnhpdliibojhegemfjheidglijccjfmc":"32CBE10E352F9CEDCDBA9BF63F3630BA647B869A6C9B5F6CA392EC0EFDB5FA65","eemcgdkfndhakfknompkggombfjjjeno":"44BDC0741B82A9818AC711DC71067C22C34747C92BFB4207DCBC210724920416","ennkphjdgehloodpbhlhldgbnhmacadg":"D847F3B8DD33EC31779D4C8012918A5965F2F0E834A345AEA530219E3DC3D903","felcaaldnbdncclmgdcncolpebgiejap":"6F02AC6B169BEBF31090E16B6E50750CECBF0F98EFD51C582B724D77827AE106","flliilndjeohchalpbbcdekjklbdgfkk":"05C0E267A44C18A2D3C2F00DF5782A2B709B2DC599AA355C59D5BCA85AF8709D","gfdkimpbcpahaombhbimeihdjnejgicl":"F9F1E2968D1E5D58D2BC5A753B366C92B76E2588E4579921C988F06B11D49D72","gpdjojdkbbmdfjfahjcgigfpmkopogic":"ED35FD4FD60FDD54D351F07B1A3CF6FC9924B439742E355E648357ECEA389595","kmendfapggjehodndflmmgagdbamhnfd":"5780AE569305D36892D0B773AE1DE6FCEF96D87CE4B8D1A4F23B824D5DA209EF","lccekmodgklaepjeofjdjpbminllajkg":"AA434C6CF497B58302C4A1B4122503026A1B5D1AA4B3DE3C824005F6A6F3679C","lifbcibllhkdhoafpjfnlhfpfgnpldfl":"83CF81F8FCBCA3C74B28664627946959D3C3D524DFF61B68B5718B667B46C65B","mfehgcgbbipciphmccgaenjidiccnmng":"5ADD8C1765712948ADB1A8CA503C2C371DB156B70103A3EEA59E147C3FAB75FD","mgndgikekgjfcpckkfioiadnlibdjbkf":"4B5C97BFF19D3E1C6D11ACB1BCF8792F642678FF1DDB9DA8242369CBEE235189","mhjfbmdgcfjbbpaeojofohoefgiehjai":"6908828DB4F5E009E00FB14B43A7E747D5192F57CE76CB43922963B04D4836C3","mppnoffgpafgpgbaigljliadgbnhljfl":"1C8249AB07811EB20DA4A920AD8C85DEF171FA62D1EA16FFD2FEC36CA9058C97","nafaimnnclfjfedmmabolbppcngeolgf":"8E18847D835C06DB796D7829A66703F6CBBA60EF47295003F2DF89AC627B9C71","nbpagnldghgfoolbancepceaanlmhfmd":"200482B82A50C7F192795A8798ADB671FD1C31DEB2CBF0C7ECF0A46259833845","neajdppkdcdipfabeoofebfddakdcjhd":"96DB414483D7316845E09553F69FA993004446B04903914D7400A3EB98DFBE4D","nkeimhogjdpnpccoofpliimaahmaaome":"E45F01522D164CDA98B16E3655A26DBDD5540F68289514A69C6BA584568D2ED8","nmmhkkegccagdldgiimedpiccmgmieda":"D136CE328D606CFC492A14F295B1CCF37162F04EAC701CF08C3D7662F1483E2C","pafkbggdmjlpgkdkcbjmhmfcdpncadgh":"DACDEE09C8DEF2106E86C1535D8F896BEBF1ED1820C7455B539624C8720C4D50","pjkljhegncpnkpknbcohdijeoejaedia":"29D21C37F89A07E4786BF305158D487C9911A94A71621C5DA673BE96211E468E"}},"google":{"services":{"last_username":"BCCE78B79BC8D22B4DC4C12E911D653A8A2891E8D719ABB94E2E5E75BBFB40C0","username":"F36F7BF2B4D4FCF4D00205C1854B1658BB5E8B9F97AE7413F31B9A7B565ED92D"}},"homepage":"6AA6C28A3EFC2F00DB8BDA03A174A5DCA46CD964028B57C4B3AD1A8EF474EB54","homepage_is_newtabpage":"179FC6286DBDC6C13BCD62BFFE3E594AB2B56BD2793DC098EC9F45186B09E1C1","pinned_tabs":"EFD98826B4EFFC7882311FCADB74699CFED0E4D6602CD0043B6AF5E2A8FD89C6","prefs":{"preference_reset_time":"00ABB5AB8727E9617FB0D07BB2794B5E9A6436E9CD8A4FFE6FFEDC89CABC2ED1"},"profile":{"reset_prompt_memento":"3071CD5A57B314A1DB045370932817A7ED77C974FD124E697ECFC57A5799B995"},"safebrowsing":{"incidents_sent":"6AC6B8688CBC7FFB611C7C4E7B0FE0473B9CAAF835F3B843126558EB8320062C"},"search_provider_overrides":"7F8198D24D32C5810D16EA2C85C6C1E59413A967EFFFE33220AA7D683B2F7844","session":{"restore_on_startup":"E88FD10172C60FFD47675DE3287217DE4E9FE91BBEACC0C93B870B206EA6076D","startup_urls":"B9DAEE5E1826B6A28D451F125935FB7948B2385B615CCCC16D11CB707B20453B"},"software_reporter":{"prompt_reason":"2A3BF2B3F701AD564E602B92EE80C6183595521187B22AF96AD498A0E10783E8","prompt_seed":"5E80DDAF478D8939AD0BFF617E7505C96F086DB4B1C2CBBBFFD92CB2C177ACB1","prompt_version":"F3E2C04A462C29D4D0E90C68124744408008936F508238D71557C4697F283AF0"},"sync":{"remaining_rollback_tries":"B09ECD70A4360115F381BA1A74005508265CC8889019F1A9A589741CDCDCF213"}},"super_mac":"68AD04629EC9446268EAB46261A31DCAC48ACB4A4AC60EEEE7180EAF5CAEE812"},"session":{"restore_on_startup":4,"startup_urls":["http://www.facebook.com/","https://www.google.rs/","http://www.limundo.com/Clan/KodSecneRuke/SpisakAukcija"]},"software_reporter":{"prompt_reason":0,"prompt_version":"3.20.1"},"sync":{"remaining_rollback_tries":0}}


==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7SKPT_en"

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1 deleted successfully

==== Empty IE Cache ======================

C:\Users\Korisnik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8I2JBOC6 will be deleted at reboot
C:\Users\Korisnik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BG4X4TGM will be deleted at reboot
C:\Users\Korisnik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ES3400E2 will be deleted at reboot
C:\Users\Korisnik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QM9TZ5UJ will be deleted at reboot

==== Empty FireFox Cache ======================

No FireFox Cache found

==== Empty Chrome Cache ======================

C:\Users\Korisnik\AppData\Local\Opera Software\Opera Stable\Cache emptied successfully
C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=289 folders=95 24239420 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\temp emptied successfully
C:\Users\Default User\AppData\Local\temp emptied successfully
C:\Users\Korisnik\AppData\Local\temp will be emptied at reboot
C:\Users\Public\AppData\Local\temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\Korisnik\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\Korisnik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8I2JBOC6" not found
"C:\Users\Korisnik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BG4X4TGM" not found
"C:\Users\Korisnik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ES3400E2" not found
"C:\Users\Korisnik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QM9TZ5UJ" not found
"C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\Low" not deleted

==== EOF on Sat 06/27/2015 at 22:18:26.14 ======================

Dopuna: 27 Jun 2015 22:48

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6103

Pozdrav,

Hajde da reinstaliramo Google Chrome. Znaci iz Start > Control Panel > Add or Remove programs deinstaliraj Google Chrome web browser. Prilikom deinstalacije postaraj se da opcija 'Also delete your browsing data'.

Kada deinstaliras program, proveri da li i dalje imas ovaj folder;
C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data

Ukoliko je i dalje tamo, obrisi ga. Potom restartuj racunar, preuzmi svezu instalaciju Google Chrome browsera i instaliraj. Prijava na gmail (Google nalog) odradice sync.

Zatim, postavi mi sveze FRST izvestaje na uvid. Trebace mi oba, i primarni FRST.txt i dodatni Addition.txt

offline
  • Pridružio: 10 Jan 2012
  • Poruke: 27

Napisano: 28 Jun 2015 12:12

Google Chrome reinstaliran prema instrukcijama.

Izvestaji:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 24-06-2015
Ran by Korisnik (administrator) on KORISNIK-PC on 28-06-2015 12:06:16
Running from C:\Users\Korisnik\Desktop
Loaded Profiles: Korisnik (Available Profiles: Korisnik)
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: geekstogo.com/forum/topic/335081-frst-t.....scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9b219d80a8843bf8\stacsv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9b219d80a8843bf8\AEstSrv.exe
(LSI Corporation) C:\Program Files\LSI SoftModem\agrsmsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Launcher\Avira.Systray.exe
(BitTorrent Inc.) C:\Users\Korisnik\AppData\Roaming\uTorrent\uTorrent.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\VS7DEBUG\mdm.exe
(arvato digital services llc) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Software 2000 Limited) C:\Windows\System32\spool\drivers\w32x86\3\HP1006MC.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
() C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
(Hewlett-Packard Development Company L.P.) C:\Program Files\Hewlett-Packard\Shared\hpCaslNotification.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer_Desktop.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray.exe [495708 2010-01-28] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1791272 2010-06-04] (Synaptics Incorporated)
HKLM\...\Run: [QLBController] => C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe [256056 2010-01-28] (Hewlett-Packard Company)
HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2010-01-08] (Intel Corporation)
HKLM\...\Run: [WirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [499768 2009-09-01] (Hewlett-Packard)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [981688 2015-04-30] (Microsoft Corporation)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [730416 2015-06-10] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [557768 2014-09-19] (Adobe Systems Incorporated)
HKLM\...\Run: [AdobeCS6ServiceManager] => C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\Launcher\Avira.Systray.exe [130864 2015-05-21] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-1146453529-3827096963-1341687669-1000\...\Run: [uTorrent] => C:\Users\Korisnik\AppData\Roaming\uTorrent\uTorrent.exe [1694560 2015-05-06] (BitTorrent Inc.)
HKU\S-1-5-21-1146453529-3827096963-1341687669-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [31280256 2015-04-17] (Skype Technologies S.A.)
HKU\S-1-5-21-1146453529-3827096963-1341687669-1000\...\Run: [Facebook Update] => C:\Users\Korisnik\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-05-07] (Facebook Inc.)
HKU\S-1-5-21-1146453529-3827096963-1341687669-1000\...\Run: [AdobeBridge] => [X]

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1146453529-3827096963-1341687669-1000\Software\Microsoft\Internet Explorer\Main,Search Page = microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\S-1-5-21-1146453529-3827096963-1341687669-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = google.com/search?q={searchTerms}
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21] (Adobe Systems Incorporated)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2013-05-26] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-05-26] (Oracle Corporation)
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 0.0.0.0

FireFox:
========
FF ProfilePath: C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default
FF SearchEngineOrder.3: Bing
FF SelectedSearchEngine: Yahoo Search
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_190.dll [2015-06-23] ()
FF Plugin: @java.com/DTPlugin,version=10.21.2 -> C:\Windows\system32\npDeployJava1.dll [2013-05-26] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.21.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2013-05-26] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=6.0.12.732 -> C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll [2010-06-02] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.732 -> C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll [2010-06-02] (RealNetworks, Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-28] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-28] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2013-09-23] (VideoLAN)
FF Plugin HKU\S-1-5-21-1146453529-3827096963-1341687669-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Korisnik\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Extension: leethax.net extension - C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default\Extensions\leethax@leethax.net.xpi [2013-05-27]
FF Extension: Test Pilot - C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default\Extensions\testpilot@labs.mozilla.com.xpi [2011-01-27]
FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-05-01]
FF Extension: No Name - C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default\extensions\{cde38172-4160-4091-bf76-de675198d659}.xpi [not found]
FF Extension: No Name - C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi [not found]

Chrome:
=======
CHR Profile: C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Docs) - C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-06-28]
CHR Extension: (Google Search) - C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-06-28]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-06-28]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-05-01]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AgereModemAudio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [26112 2009-12-03] (LSI Corporation)
S2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc7.exe [827184 2015-06-10] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [450808 2015-06-10] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [450808 2015-06-10] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe [1188360 2015-06-10] (Avira Operations GmbH & Co. KG)
S2 Avira.ServiceHost; C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe [208632 2015-05-21] (Avira Operations GmbH & Co. KG)
R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
R2 HP Health Check Service; C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [120832 2009-10-15] (Hewlett-Packard) [File not signed]
R2 hpHotkeyMonitor; C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [265272 2010-01-28] (Hewlett-Packard Company)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 MDM; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed]
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2015-04-30] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [284504 2015-04-30] (Microsoft Corporation)
R2 PSI_SVC_2; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [277360 2014-04-30] (arvato digital services llc)
R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9b219d80a8843bf8\STacSV.exe [229458 2010-01-28] (IDT, Inc.)
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [5495056 2015-06-18] (TeamViewer GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 androidusb; C:\Windows\System32\Drivers\androidusb.sys [26112 2010-04-29] (Google Inc)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108448 2015-06-10] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136728 2015-06-10] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37896 2015-05-05] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [37896 2015-03-04] (Avira Operations GmbH & Co. KG)
S3 HtcVCom32; C:\Windows\System32\DRIVERS\HtcVComV32.sys [105984 2009-10-27] (QUALCOMM Incorporated)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-04-14] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [245096 2015-03-04] (Microsoft Corporation)
R3 pfc; C:\Windows\System32\drivers\pfc.sys [10368 2011-02-21] (Padus, Inc.) [File not signed]
S3 s125bus; C:\Windows\System32\DRIVERS\s125bus.sys [83336 2007-04-24] (MCCI Corporation)
S3 s125mdfl; C:\Windows\System32\DRIVERS\s125mdfl.sys [15112 2007-04-24] (MCCI Corporation)
S3 s125mdm; C:\Windows\System32\DRIVERS\s125mdm.sys [108680 2007-04-24] (MCCI Corporation)
S3 s125obex; C:\Windows\System32\DRIVERS\s125obex.sys [98696 2007-04-24] (MCCI Corporation)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1763968 2010-01-18] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2010-09-13] () [File not signed]
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [31848 2015-06-10] (Avira Operations GmbH & Co. KG)
U3 ay3ofpzy; C:\Windows\system32\Drivers\ay3ofpzy.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero byte File/Folder)
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-28 12:04 - 2015-06-28 12:04 - 00002205 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-06-28 12:04 - 2015-06-28 12:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-06-28 12:03 - 2015-06-28 12:03 - 00931408 _____ (Google Inc.) C:\Users\Korisnik\Downloads\ChromeSetup (3).exe
2015-06-28 12:03 - 2015-06-28 12:03 - 00000890 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-28 12:03 - 2015-06-28 12:03 - 00000886 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-27 22:43 - 2015-06-27 22:44 - 00035517 _____ C:\Users\Korisnik\Desktop\zoek-results.txt
2015-06-27 22:17 - 2015-06-27 21:54 - 00024064 _____ C:\Windows\zoek-delete.exe
2015-06-27 21:55 - 2015-06-27 22:18 - 00035517 _____ C:\zoek-results.log
2015-06-27 21:54 - 2015-06-27 22:18 - 00000000 ____D C:\zoek_backup
2015-06-27 21:52 - 2003-02-02 05:00 - 01308672 _____ C:\Users\Korisnik\Desktop\zoek.exe
2015-06-27 21:51 - 2015-06-27 21:51 - 04180806 _____ C:\Users\Korisnik\Downloads\zoek.zip
2015-06-27 15:17 - 2015-06-26 23:03 - 01636352 _____ (Farbar) C:\Users\Korisnik\Desktop\FRST.exe
2015-06-26 23:04 - 2015-06-28 12:07 - 00016586 _____ C:\Users\Korisnik\Desktop\FRST.txt
2015-06-26 23:04 - 2015-06-28 12:06 - 00000000 ____D C:\FRST
2015-06-26 23:03 - 2015-06-26 23:03 - 01636352 _____ (Farbar) C:\Users\Korisnik\Downloads\FRST.exe
2015-06-26 23:03 - 2015-06-26 23:03 - 01636352 _____ (Farbar) C:\Users\Korisnik\Downloads\FRST (1).exe
2015-06-26 22:26 - 2015-06-26 22:26 - 00049164 _____ C:\Users\Korisnik\Desktop\AdwCleaner[S0].txt
2015-06-26 21:55 - 2015-06-26 21:55 - 02244096 _____ C:\Users\Korisnik\Downloads\AdwCleaner.exe
2015-06-22 22:50 - 2015-06-23 16:20 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-06-22 22:49 - 2015-06-22 22:49 - 00001064 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-06-22 22:49 - 2015-06-22 22:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-06-22 22:49 - 2015-06-22 22:49 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-06-22 22:49 - 2015-04-14 09:37 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-06-22 22:49 - 2015-04-14 09:37 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-06-21 12:43 - 2015-06-21 12:43 - 00035950 _____ C:\Users\Korisnik\Downloads\Sablon handmade bez kruga (2).cdr
2015-06-21 12:42 - 2015-06-21 12:42 - 00268329 _____ C:\Users\Korisnik\Downloads\mira pecar poslednji.dxf
2015-06-21 12:41 - 2015-06-21 12:41 - 00035950 _____ C:\Users\Korisnik\Downloads\Sablon handmade bez kruga (1).cdr
2015-06-21 12:40 - 2015-06-21 12:40 - 00036676 _____ C:\Users\Korisnik\Downloads\Sablon handmade.cdr
2015-06-21 12:40 - 2015-06-21 12:40 - 00036676 _____ C:\Users\Korisnik\Downloads\Sablon handmade (1).cdr
2015-06-20 19:48 - 2015-06-20 19:47 - 00035950 _____ C:\Users\Korisnik\Downloads\Backup_of_Sablon handmade bez kruga.cdr
2015-06-20 19:47 - 2015-06-20 19:48 - 00026006 _____ C:\Users\Korisnik\Downloads\Sablon handmade bez kruga.cdr
2015-06-18 09:55 - 2015-06-18 09:55 - 00038968 _____ C:\Users\Korisnik\Downloads\Sablon mira kutlesic handmade (1).cdr
2015-06-15 19:20 - 2015-06-15 19:20 - 00051110 _____ C:\Users\Korisnik\Downloads\Sablon mira kutlesic handmade.cdr
2015-06-11 18:41 - 2015-06-11 18:41 - 00000000 ____D C:\Users\Korisnik\AppData\Local\GWX
2015-06-10 15:16 - 2015-06-02 21:35 - 00342728 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-06-10 15:16 - 2015-05-23 05:15 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-06-10 15:16 - 2015-05-23 05:08 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-06-10 15:16 - 2015-05-23 05:05 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-06-10 15:16 - 2015-05-23 05:00 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-06-10 15:16 - 2015-05-23 04:52 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-06-10 15:16 - 2015-05-23 04:38 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-06-10 15:16 - 2015-05-23 04:16 - 01309696 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-06-10 15:15 - 2015-05-27 16:08 - 19607040 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-06-10 15:15 - 2015-05-23 05:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-06-10 15:15 - 2015-05-23 05:28 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-06-10 15:15 - 2015-05-23 05:15 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-06-10 15:15 - 2015-05-23 05:15 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-06-10 15:15 - 2015-05-23 05:14 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-06-10 15:15 - 2015-05-23 05:13 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-06-10 15:15 - 2015-05-23 05:10 - 02278912 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-06-10 15:15 - 2015-05-23 05:09 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-06-10 15:15 - 2015-05-23 05:06 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-06-10 15:15 - 2015-05-23 05:05 - 00664064 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-06-10 15:15 - 2015-05-23 05:05 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-06-10 15:15 - 2015-05-23 05:04 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-06-10 15:15 - 2015-05-23 04:57 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-06-10 15:15 - 2015-05-23 04:49 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-06-10 15:15 - 2015-05-23 04:48 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-06-10 15:15 - 2015-05-23 04:47 - 04305920 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-06-10 15:15 - 2015-05-23 04:47 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-06-10 15:15 - 2015-05-23 04:38 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-06-10 15:15 - 2015-05-23 04:37 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-06-10 15:15 - 2015-05-23 04:37 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-06-10 15:15 - 2015-05-23 04:28 - 12829696 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-06-10 15:15 - 2015-05-23 04:20 - 01950720 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-06-10 15:15 - 2015-05-23 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-06-10 15:11 - 2015-05-25 19:00 - 02384384 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-06-10 15:11 - 2015-05-22 20:03 - 00571392 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-06-10 15:11 - 2015-05-22 20:02 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-06-10 15:11 - 2015-05-22 20:02 - 00621568 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-06-10 15:11 - 2015-05-22 20:02 - 00333824 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-06-10 15:11 - 2015-05-22 20:02 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-06-10 15:11 - 2015-05-22 20:02 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-06-10 15:11 - 2015-05-22 19:58 - 00901120 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-06-10 15:11 - 2015-05-21 15:20 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-06-10 15:10 - 2015-04-11 05:07 - 00054656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stream.sys
2015-06-10 15:06 - 2015-05-25 20:07 - 03989440 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-06-10 15:06 - 2015-05-25 20:07 - 03934144 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-06-10 15:06 - 2015-05-25 20:07 - 00137664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-06-10 15:06 - 2015-05-25 20:07 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-06-10 15:06 - 2015-05-25 20:04 - 01307648 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-06-10 15:06 - 2015-05-25 20:01 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-06-10 15:06 - 2015-05-25 20:01 - 00853504 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-06-10 15:06 - 2015-05-25 20:01 - 00641536 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-06-10 15:06 - 2015-05-25 20:01 - 00635392 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-06-10 15:06 - 2015-05-25 20:01 - 00551424 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-06-10 15:06 - 2015-05-25 20:01 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-06-10 15:06 - 2015-05-25 20:01 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-06-10 15:06 - 2015-05-25 20:01 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-06-10 15:06 - 2015-05-25 20:01 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-06-10 15:06 - 2015-05-25 20:01 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-06-10 15:06 - 2015-05-25 20:01 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-06-10 15:06 - 2015-05-25 20:01 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
2015-06-10 15:06 - 2015-05-25 20:01 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-06-10 15:06 - 2015-05-25 20:01 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-06-10 15:06 - 2015-05-25 20:01 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-06-10 15:06 - 2015-05-25 20:01 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-06-10 15:06 - 2015-05-25 20:01 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-06-10 15:06 - 2015-05-25 20:00 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe
2015-06-10 15:06 - 2015-05-25 20:00 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-06-10 15:06 - 2015-05-25 20:00 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe
2015-06-10 15:06 - 2015-05-25 20:00 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-06-10 15:06 - 2015-05-25 20:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-06-10 15:06 - 2015-05-25 20:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe
2015-06-10 15:06 - 2015-05-25 20:00 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe
2015-06-10 15:06 - 2015-05-25 20:00 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-06-10 15:06 - 2015-05-25 20:00 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe
2015-06-10 15:05 - 2015-05-25 20:01 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-06-10 15:05 - 2015-05-25 19:57 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-06-10 15:05 - 2015-05-25 19:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-06-10 15:05 - 2015-05-25 19:55 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-06-10 15:05 - 2015-05-25 19:55 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-06-10 15:05 - 2015-05-25 18:53 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-06-10 15:05 - 2015-05-09 05:14 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-06-10 15:05 - 2015-05-09 05:13 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-06-10 15:05 - 2015-05-09 05:13 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-06-10 15:05 - 2015-05-09 05:12 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-06-10 15:05 - 2015-05-09 05:08 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 03:59 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 03:59 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 03:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-06-10 15:05 - 2015-05-09 03:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-06-10 15:05 - 2015-04-29 20:07 - 11411456 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-06-10 15:05 - 2015-04-29 20:07 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2015-06-10 15:05 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2015-06-10 15:05 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2015-06-10 15:05 - 2015-04-29 20:05 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2015-06-10 15:05 - 2015-04-24 19:56 - 00530432 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2015-05-29 21:01 - 2015-06-13 20:02 - 00000000 ____D C:\Users\Korisnik\Desktop\repro

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-28 12:06 - 2012-06-17 23:39 - 00000000 ____D C:\Users\Korisnik\AppData\Roaming\uTorrent
2015-06-28 12:05 - 2010-09-13 15:37 - 00000000 ____D C:\Users\Korisnik\AppData\Roaming\Skype
2015-06-28 12:04 - 2013-01-14 03:28 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-06-28 12:04 - 2011-08-19 08:03 - 00000000 ____D C:\Users\Korisnik\AppData\Local\Google
2015-06-28 12:04 - 2011-08-19 07:57 - 00000000 ____D C:\Program Files\Google
2015-06-28 11:58 - 2009-07-14 06:34 - 00016880 _____ C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-06-28 11:58 - 2009-07-14 06:34 - 00016880 _____ C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-06-28 11:54 - 2010-09-13 16:07 - 01703101 _____ C:\Windows\WindowsUpdate.log
2015-06-28 11:36 - 2013-10-23 22:39 - 00046383 _____ C:\Windows\setupact.log
2015-06-28 11:36 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-06-28 11:22 - 2010-09-13 15:14 - 00000000 ____D C:\Users\Korisnik\AppData\Local\Adobe
2015-06-27 22:18 - 2013-11-18 01:29 - 01896132 _____ C:\Windows\PFRO.log
2015-06-27 21:39 - 2013-05-07 09:34 - 00000940 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1146453529-3827096963-1341687669-1000UA.job
2015-06-27 21:08 - 2015-02-06 23:03 - 00000000 ____D C:\ProgramData\boost_interprocess
2015-06-27 15:18 - 2013-07-12 11:03 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-06-27 09:39 - 2013-05-07 09:34 - 00000918 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1146453529-3827096963-1341687669-1000Core.job
2015-06-27 09:10 - 2015-03-12 22:24 - 00000000 ____D C:\Program Files\TeamViewer
2015-06-27 09:09 - 2015-03-31 00:28 - 00000929 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk
2015-06-27 09:09 - 2015-03-31 00:28 - 00000917 _____ C:\Users\Public\Desktop\TeamViewer 10.lnk
2015-06-26 20:42 - 2015-02-06 20:56 - 00000000 ____D C:\Users\Korisnik\Desktop\sabloncici
2015-06-25 18:50 - 2013-06-10 23:16 - 00000000 ____D C:\Program Files\Opera
2015-06-23 22:04 - 2013-01-14 03:28 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-06-23 22:04 - 2012-01-12 09:20 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-06-23 18:18 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache
2015-06-23 16:18 - 2011-02-21 22:31 - 00000000 ____D C:\Windows\system32\appmgmt
2015-06-23 16:16 - 2010-09-13 15:13 - 00000000 ____D C:\Program Files\Adobe
2015-06-23 16:15 - 2010-09-13 15:14 - 00000000 ____D C:\Users\Korisnik\AppData\Roaming\Adobe
2015-06-23 15:42 - 2015-04-07 15:53 - 00000332 _____ C:\Windows\Tasks\HPCeeScheduleForKorisnik.job
2015-06-23 14:33 - 2010-09-13 14:30 - 00000052 _____ C:\Windows\system32\DOErrors.log
2015-06-22 23:48 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\L2Schemas
2015-06-22 22:49 - 2011-10-31 16:08 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-06-17 20:31 - 2013-03-13 12:15 - 00000000 ____D C:\ProgramData\Avira
2015-06-16 19:20 - 2013-03-13 12:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-06-16 19:20 - 2013-03-13 12:15 - 00000000 ____D C:\Program Files\Avira
2015-06-14 08:15 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET
2015-06-14 07:42 - 2010-09-13 09:32 - 00809448 _____ C:\Windows\system32\PerfStringBackup.INI
2015-06-14 07:38 - 2013-08-16 23:20 - 00000000 ____D C:\Windows\system32\MRT
2015-06-14 07:23 - 2011-05-27 13:03 - 136900096 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-06-13 22:46 - 2011-03-07 14:28 - 00000000 ____D C:\Users\Korisnik\kreacije
2015-06-13 22:46 - 2010-09-13 09:28 - 00000000 ____D C:\Users\Korisnik
2015-06-11 18:40 - 2011-10-31 15:14 - 00001515 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-06-11 18:38 - 2009-07-14 06:33 - 03882464 _____ C:\Windows\system32\FNTCACHE.DAT
2015-06-11 18:36 - 2015-04-16 08:12 - 00000000 ____D C:\Windows\system32\appraiser
2015-06-11 18:36 - 2014-05-06 12:51 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-06-11 00:01 - 2010-09-13 15:05 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-06-10 14:47 - 2013-03-13 12:15 - 00136728 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2015-06-10 14:47 - 2013-03-13 12:15 - 00108448 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2015-06-10 14:47 - 2013-03-13 12:15 - 00031848 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\ssmdrv.sys
2015-06-07 11:47 - 2011-01-07 14:13 - 00000069 _____ C:\Windows\NeroDigital.ini
2015-06-04 10:49 - 2015-03-26 10:16 - 00000000 ____D C:\Users\Korisnik\Desktop\nada sabloni
2015-05-31 13:39 - 2015-03-27 14:33 - 00037770 _____ C:\Users\Korisnik\Desktop\sabloni dim. i cene.xlsx

==================== Files in the root of some directories =======

2011-01-22 12:37 - 2011-07-29 15:54 - 0013312 _____ () C:\Users\Korisnik\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-06-27 19:15 - 2015-06-28 11:36 - 0000184 _____ () C:\ProgramData\HPWALog.txt

Some files in TEMP:
====================
C:\Users\Korisnik\AppData\Local\Temp\avgnt.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-06-23 18:10

==================== End of log ============================
mycity.rs/must-login.png

Dopuna: 28 Jun 2015 12:16

Restart racunara posle deinstalacije Croma je trajao oko 17-18min

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6103

Problem koji ti imas najverovatnije nije prouzrokovan malicioznim programima. Ali moramo da zavrsimo posao koji smo zapoceli ovde.



--- --- --- --- ---





Arrow FRST Fix;
1. Otvori Notepad (Text Document) i iskopiraj sledeći tekst unutar kod polja ispod:

FF Extension: No Name - C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default\extensions\{cde38172-4160-4091-bf76-de675198d659}.xpi [not found]
FF Extension: No Name - C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\6tytnbjs.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi [not found]
U3 ay3ofpzy; C:\Windows\system32\Drivers\ay3ofpzy.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero byte File/Folder)
C:\Windows\system32\Drivers\ay3ofpzy.sys


2. Sačuvaj notepad na Desktop pod nazivom fixlist.txt
To možes uraditi i iz notepad-a => klik na File potom na Save As i u novom prozoru, dole pod File Name: staviš za naziv fixlist.txt
Napomena: Važno je da se oba fajla, FRST i fixlist nalaze na istoj lokaciji jer u suprotnom fix nece raditi.

3. Ponovo pokreni FRST/FRST64, klikni jednom na dugme Fix i sačekaj.
Ukoliko alat zatraži restart sistema, dozvoli mu i postaraj se da alat kompletira fix nakon restarta sistema.



Alat će formirati log (Fixlog.txt) na Desktop-u. Potrebno je sadržaj tog loga iskopirati u poruku.
Napomena: Ukoliko te alat upozori da postoji novija verzija, postaraj se da preuzmes i koristiš ažuriranu kopiju FRST-a.




--- --- --- --- ---






Arrow Startuj Mozilla Firefox, poseti ovaj link i prateci instrukcije resetuj taj browser na podrazumevana podesavanja (default);
https://support.mozilla.org/en-US/kb/refresh-firefox-reset-add-ons-and-settings





--- --- --- --- ---





Arrow Preuzmi TDSSKiller, sacuvaj alat na Desktop i dvoklikom pokreni TDSSKiller.exe
U "End user Licence Agreement" dijalogu klikni na Accept.
Takođe, u "KSN Statement" dijalogu klikni na Accept.


klikni na dugme Start Scan

Ukoliko sumnjive stavke Suspicious object budu detektovani, podrazumevana opcija (default action) jeste Skip, klikni na Continue.
Ukoliko maliciozni objekti Malicious objects budu detektovani, izaberi opciju Cure.

Okaci mi sadrzaj log-a sa sledece lokacije:
C:\TDSSKiller_verzija programa_DD.MM.GG_HH.MM.SS.txt
(DD-dan, MM-mesec, GG-godina, HH-sat, MM-minut, SS-sekunda; datum i vreme kada je log napravljen)

Ko je trenutno na forumu
 

Ukupno su 983 korisnika na forumu :: 51 registrovanih, 10 sakrivenih i 922 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 8u47, _Petar, A.R.Chafee.Jr., amaterSRB, Apok, babaroga, ccoogg123, cinoeye, dane007, Dannyboy, darkangel, Dimitrise93, djboj, doklevise, DonRumataEstorski, DragoslavS, GORDI, grenadir, Istman, Ivica1102, Kandrbandrdzilo, Kubovac, kunktator, laganini123, laurusri, MB120mm, mercedesamg, Mercury, Milometer, Mixelotti, mkukoleca, novator, ozzy, pein, radionica1, randja26, Ripanjac, sevenino, Sir Budimir, slonic_tonic, Srky Boy, Srle993, Stija zmija, styg, Tores, Vlajman1957, voja64, VP6919, wolf431, zastavnik, zeo