Provera

Provera

offline
  • Pridružio: 22 Nov 2012
  • Poruke: 70
  • Gde živiš: Daleko iza planina

U poslednje vreme je poceo da baguje bez razloga, ne znam tacno od kada zato sto ga koriste moji roditelji Smile
Evo log-ova

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 23-11-2016
Ran by Petrovici (administrator) on PETROVIC-2DC4B6 (26-11-2016 08:50:07)
Running from C:\Documents and Settings\Petrovici\My Documents\preuzimanja
Loaded Profiles: Petrovici & UpdatusUser (Available Profiles: Petrovici & UpdatusUser)
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) Language: English (United States)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

() C:\Program Files\BitX\bitxsvc.exe
(Apple Computer, Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\soundman.exe
(Microsoft Corporation) C:\WINDOWS\system32\MDM.EXE


==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [NvMediaCenter] => RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
HKLM\...\Run: [nwiz] => C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [1632360 2011-10-08] ()
HKLM\...\Run: [SoundMan] => C:\WINDOWS\SOUNDMAN.EXE [577536 2006-08-02] (Realtek Semiconductor Corp.)
HKLM\...\Run: [PAC7302_Monitor] => C:\WINDOWS\PixArt\PAC7302\Monitor.exe [319488 2006-11-03] (PixArt Imaging Incorporation)
HKU\S-1-5-21-796845957-1614895754-1606980848-1003\...\Run: [BitTorrent] => C:\Documents and Settings\Petrovici\Application Data\BitTorrent\BitTorrent.exe [2149064 2016-11-23] (BitTorrent Inc.)
HKU\S-1-5-21-796845957-1614895754-1606980848-1003\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [4910912 2011-08-02] (DT Soft Ltd)
HKU\S-1-5-21-796845957-1614895754-1606980848-1003\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-796845957-1614895754-1606980848-1003\...\Run: [OscarEditor] => C:\Program Files\Anti-Vibrate Oscar Editor\OscarEditor.exe [2636800 2010-07-22] ()
HKU\S-1-5-21-796845957-1614895754-1606980848-1003\...\Run: [MSMSGS] => C:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation)
HKU\S-1-5-21-796845957-1614895754-1606980848-1003\...\MountPoints2: {51b04daf-0c60-11e6-8a62-000feafb0ce1} - E:\Setup.exe autorun
SecurityProviders: msapsspc.dll, schannel.dll, credssp.dll, digest.dll, msnsspc.dll
Startup: C:\Documents and Settings\Petrovici\Start Menu\Programs\Startup\GameRanger.lnk [2016-07-06]
ShortcutTarget: GameRanger.lnk -> C:\Documents and Settings\Petrovici\Application Data\GameRanger\GameRanger\GameRanger.exe (GameRanger Technologies)
GroupPolicy: Restriction ? <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [94208 2006-02-28] (Apple Computer, Inc.)
Tcpip\Parameters: [DhcpNameServer] 212.200.191.166 212.200.190.166
Tcpip\..\Interfaces\{68123747-265C-4180-905E-32857678780F}: [DhcpNameServer] 212.200.191.166 212.200.190.166

Internet Explorer:
==================
HKU\S-1-5-21-796845957-1614895754-1606980848-1004\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-796845957-1614895754-1606980848-1003\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
URLSearchHook: [S-1-5-21-796845957-1614895754-1606980848-1004] ATTENTION => Default URLSearchHook is missing
SearchScopes: HKU\S-1-5-21-796845957-1614895754-1606980848-1003 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

FireFox:
========
FF DefaultProfile: 7rcucp3q.default
FF ProfilePath: C:\Documents and Settings\Petrovici\Application Data\Mozilla\Firefox\Profiles\7rcucp3q.default [2016-11-26]
FF Extension: (Firebug) - C:\Documents and Settings\Petrovici\Application Data\Mozilla\Firefox\Profiles\7rcucp3q.default\Extensions\firebug@software.joehewitt.com.xpi [2016-10-11]
FF Extension: (Firefox Hotfix) - C:\Documents and Settings\Petrovici\Application Data\Mozilla\Firefox\Profiles\7rcucp3q.default\Extensions\firefox-hotfix@mozilla.org.xpi [2016-09-09]
FF Extension: (Adblock Plus) - C:\Documents and Settings\Petrovici\Application Data\Mozilla\Firefox\Profiles\7rcucp3q.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-11-23]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_17_0_0_134.dll [2016-04-28] ()
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2007-11-07] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.1 -> D:\Program Files\VideoLAN\VLC\npvlc.dll [2012-03-17] (VideoLAN)

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 BitXService; C:\Program Files\BitX\bitxsvc.exe [1886208 2016-08-14] () [File not signed]
R2 Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [229376 2006-02-28] (Apple Computer, Inc.) [File not signed]
S3 FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [654848 2016-07-09] (Macrovision Europe Ltd.) [File not signed]
S3 idsvc; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [864256 2007-10-11] (Microsoft Corporation) [File not signed]
S4 NetTcpPortSharing; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [122880 2007-10-11] (Microsoft Corporation) [File not signed]
R2 NIHardwareService; C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [4590968 2012-09-05] (Native Instruments GmbH)
R2 nvUpdatusService; C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2253120 2011-10-08] (NVIDIA Corporation)
S3 Visual Studio Analyzer RPC bridge; D:\Program Files\Microsoft Visual Studio\Common\Tools\VS-Ent98\Vanalyzr\varpc.exe [34036 1998-06-05] (Microsoft Corporation) [File not signed]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 ALCXWDM; C:\WINDOWS\System32\drivers\ALCXWDM.SYS [4017536 2006-08-18] (Realtek Semiconductor Corp.)
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
S3 cmuda; C:\WINDOWS\System32\drivers\cmuda.sys [1368000 2005-12-15] (C-Media Inc)
R1 dtsoftbus01; C:\WINDOWS\System32\DRIVERS\dtsoftbus01.sys [232512 2016-04-27] (DT Soft Ltd)
R3 FETND5BV; C:\WINDOWS\System32\DRIVERS\fetnd5bv.sys [42496 2004-12-16] (VIA Technologies, Inc.              )
S3 FETNDIS; C:\WINDOWS\System32\DRIVERS\fetnd5.sys [27165 2001-08-17] (VIA Technologies, Inc.              )
R3 gameenum; C:\WINDOWS\System32\DRIVERS\gameenum.sys [10624 2008-04-14] (Microsoft Corporation)
S3 hamachi; C:\WINDOWS\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
R3 Moufiltr; C:\WINDOWS\System32\DRIVERS\Moufiltr.sys [9661 2005-08-06] (Windows (R) 2000 DDK provider) [File not signed]
R3 MouseCap; C:\WINDOWS\System32\Drivers\MouseCap.sys [6640 2005-08-08] () [File not signed]
R0 mv61xxmm; C:\WINDOWS\system32\Drivers\mv61xxmm.sys [14184 2016-04-23] (Marvell Semiconductor Inc.)
R0 mv64xxmm; C:\WINDOWS\system32\Drivers\mv64xxmm.sys [5632 2016-04-23] (Marvell Semiconductor Inc.) [File not signed]
R0 mvxxmm; C:\WINDOWS\system32\Drivers\mvxxmm.sys [14184 2016-04-23] (Marvell Semiconductor Inc.)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
S3 rtl8139; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [20992 2008-04-13] (Realtek Semiconductor Corporation)
R0 viamraid; C:\WINDOWS\System32\DRIVERS\viamraid.sys [116608 2010-11-18] (VIA Technologies inc,.ltd)
R0 videX32; C:\WINDOWS\System32\DRIVERS\videX32.sys [13976 2010-02-11] (VIA Technologies, Inc.)
S3 WinRing0_1_2_0; C:\Program Files\IObit\Game Booster 3\Driver\WinRing0.sys [14416 2010-11-01] (OpenLibSys.org)
S4 IntelIde; no ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2016-04-23] (Microsoft Corporation)
U1 WS2IFSL; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-11-26 08:43 - 2008-04-13 22:05 - 00020992 ____C (Realtek Semiconductor Corporation) C:\WINDOWS\system32\dllcache\rtl8139.sys
2016-11-26 08:43 - 2008-04-13 22:05 - 00020992 _____ (Realtek Semiconductor Corporation) C:\WINDOWS\system32\Drivers\RTL8139.sys
2016-11-20 01:09 - 2016-11-20 01:09 - 00000000 ____D C:\Documents and Settings\Petrovici\.jssc
2016-11-20 00:55 - 2016-11-20 01:24 - 00000000 ____D C:\Documents and Settings\Petrovici\Local Settings\Application Data\Arduino15
2016-11-20 00:55 - 2016-11-20 00:55 - 00000000 ____D C:\Documents and Settings\Petrovici\My Documents\Arduino
2016-11-20 00:55 - 2016-11-20 00:55 - 00000000 ____D C:\Documents and Settings\Petrovici\.oracle_jre_usage
2016-11-20 00:52 - 2016-11-20 00:52 - 00000564 _____ C:\Documents and Settings\All Users\Start Menu\Programs\Arduino.lnk
2016-11-20 00:52 - 2016-11-20 00:52 - 00000564 _____ C:\Documents and Settings\All Users\Desktop\Arduino.lnk
2016-11-20 00:42 - 2016-11-20 01:17 - 00000400 __RSH C:\Documents and Settings\All Users\ntuser.pol
2016-11-20 00:42 - 2016-11-20 00:42 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy
2016-11-19 16:20 - 2016-11-19 16:21 - 05954677 _____ C:\Documents and Settings\Petrovici\Desktop\Poster42.psd
2016-11-19 16:00 - 2016-09-21 12:14 - 00000000 ____D C:\Documents and Settings\Petrovici\Desktop\arduino-1.6.12
2016-10-30 13:47 - 2016-10-30 13:47 - 00000000 ____D C:\Documents and Settings\Petrovici\Application Data\GeoGebra 5.0
2016-10-30 13:46 - 2016-10-30 13:46 - 00001526 _____ C:\Documents and Settings\All Users\Desktop\GeoGebra.lnk
2016-10-30 13:46 - 2016-10-30 13:46 - 00000000 ____D C:\Program Files\GeoGebra 5.0
2016-10-30 13:46 - 2016-10-30 13:46 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\GeoGebra 5

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-11-26 08:50 - 2016-07-19 10:08 - 00000000 ____D C:\FRST
2016-11-26 08:50 - 2016-04-23 22:07 - 00000000 ____D C:\Documents and Settings\Petrovici\Local Settings\Temp
2016-11-26 08:49 - 2016-04-24 19:27 - 00000000 ____D C:\Documents and Settings\Petrovici\My Documents\preuzimanja
2016-11-26 08:48 - 2016-06-23 15:03 - 00000286 _____ C:\WINDOWS\Tasks\Game_Booster_AutoUpdate.job
2016-11-26 08:48 - 2016-04-27 11:10 - 00000000 ____D C:\Documents and Settings\Petrovici\Application Data\BitTorrent
2016-11-26 08:48 - 2016-04-23 22:06 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-11-26 08:43 - 2016-04-23 14:28 - 00000000 RSHDC C:\WINDOWS\system32\dllcache
2016-11-26 08:40 - 2016-04-23 22:07 - 00000178 ___SH C:\Documents and Settings\Petrovici\ntuser.ini
2016-11-26 08:40 - 2016-04-23 22:06 - 00032554 _____ C:\WINDOWS\SchedLgU.Txt
2016-11-26 08:36 - 2016-04-24 10:09 - 00000178 ___SH C:\Documents and Settings\UpdatusUser\ntuser.ini
2016-11-26 01:04 - 2016-06-05 17:58 - 00000000 ____D C:\Documents and Settings\Petrovici\Application Data\AIMP
2016-11-25 20:26 - 2016-05-17 18:33 - 00000000 ____D C:\Documents and Settings\Petrovici\Application Data\vlc
2016-11-25 20:13 - 2016-04-23 14:33 - 00588124 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-11-25 13:45 - 2016-04-23 11:52 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2016-11-20 01:30 - 2016-04-23 14:28 - 00000000 ___HD C:\WINDOWS\inf
2016-11-20 01:17 - 2016-04-23 14:30 - 00000000 ____D C:\Documents and Settings\All Users
2016-11-20 01:09 - 2016-04-23 22:07 - 00000000 ____D C:\Documents and Settings\Petrovici
2016-11-20 00:55 - 2016-04-23 22:07 - 00000000 ___RD C:\Documents and Settings\Petrovici\My Documents
2016-11-19 16:21 - 2016-04-24 10:08 - 00286052 _____ C:\WINDOWS\system32\nvdrsdb1.bin
2016-11-19 16:21 - 2016-04-24 10:08 - 00286052 _____ C:\WINDOWS\system32\nvdrsdb0.bin
2016-11-19 16:21 - 2016-04-24 10:08 - 00000001 _____ C:\WINDOWS\system32\nvdrssel.bin
2016-11-12 16:47 - 2016-09-30 16:23 - 00002169 _____ C:\Documents and Settings\All Users\Desktop\LFSCarImp.lnk
2016-11-11 19:22 - 2016-06-20 13:06 - 00000000 ____D C:\Documents and Settings\Petrovici\Application Data\Audacity
2016-11-11 19:07 - 2016-09-06 15:45 - 00000000 ___RD C:\Documents and Settings\Petrovici\Desktop\Petrovo sve
2016-11-10 21:28 - 2001-09-19 18:18 - 00009052 _____ C:\WINDOWS\Zmodeler.ini
2016-11-06 18:21 - 2016-04-23 22:08 - 00000000 ____D C:\Documents and Settings\Petrovici\Application Data\Adobe

==================== Files in the root of some directories =======

2016-04-27 22:36 - 2016-09-08 20:40 - 0006144 _____ () C:\Documents and Settings\Petrovici\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

Some files in TEMP:
====================
C:\Documents and Settings\Petrovici\Local Settings\Temp\AutoRun.exe
C:\Documents and Settings\Petrovici\Local Settings\Temp\AutoRunGUI.dll
C:\Documents and Settings\Petrovici\Local Settings\Temp\BitXUpdaterService.exe
C:\Documents and Settings\Petrovici\Local Settings\Temp\libeay32.dll
C:\Documents and Settings\Petrovici\Local Settings\Temp\msvcr120.dll
C:\Documents and Settings\Petrovici\Local Settings\Temp\sqlite3.dll


==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

==================== End of FRST.txt ============================


mycity.rs/must-login.png

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Da li si ti instalirao BitX?

offline
  • Pridružio: 22 Nov 2012
  • Poruke: 70
  • Gde živiš: Daleko iza planina

Da, jel treba da ga brisem ?

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Ne treba. Sistem ti je čist.

Sledeća procedura će implementirati završno čišćenje.

Arrow Preuzmi "Xplode"-ov DelFix alat i snimi ga na Desktop.
Dvoklikom pokreni alat i štikliraj kućice ispred sledećih opcija;

Remove disinfection tools
Create registry backup
Purge System Restore


Klikni na dugme Run i pričekaj trenutak dok alat ne završi svoj rad.
Od ovog trenutka, svi korišćeni alati u ovoj temi bi trebali biti obrisani.
Alat će takođe formirati izveštaj za tebe. (C:\DelFix.txt)

Alat će snimiti i zdravo stanje registy-ja i napraviti backup koristeci integrisan program "ERUNT" u %windir%\ERUNT\DelFix
Alat briše stare system restore tačke i pravi novu, svežu tačku nakon čišćenja.

Ko je trenutno na forumu
 

Ukupno su 389 korisnika na forumu :: 2 registrovanih, 1 sakriven i 386 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: darios, ILGromovnik