Provjera ako moze ?

Provjera ako moze ?

offline
  • Nemanja Djukanovic
  • Pridružio: 18 Dec 2012
  • Poruke: 1761
  • Gde živiš: Niksic - Crna Gora

Napisano: 14 Nov 2015 3:38

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:07-11-2015
Ran by NeMaNjiNo (administrator) on DESKTOP-U6IFMIB (14-11-2015 03:37:22)
Running from C:\Users\NeMaNjiNo\Desktop
Loaded Profiles: NeMaNjiNo (Available Profiles: NeMaNjiNo)
Platform: Windows 10 Pro (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: [Link mogu videti samo ulogovani korisnici]

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(Popcorn Time) C:\Program Files (x86)\Popcorn Time\Updater.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1026.13580.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16174328 2015-10-01] (Realtek Semiconductor)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2655520 2015-10-12] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)
HKU\S-1-5-21-2327723578-2138191117-1412739755-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4468056 2015-06-18] (Disc Soft Ltd)
HKU\S-1-5-21-2327723578-2138191117-1412739755-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [50264704 2015-11-05] (Skype Technologies S.A.)
HKU\S-1-5-21-2327723578-2138191117-1412739755-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8551848 2015-10-19] (Piriform Ltd)
HKU\S-1-5-21-2327723578-2138191117-1412739755-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [232960 2015-07-10] (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.2
Tcpip\..\Interfaces\{5b5c8ac8-7116-4eba-96bd-4e520dafa5b4}: [NameServer] 8.8.8.8,7.8.8.8
Tcpip\..\Interfaces\{5b5c8ac8-7116-4eba-96bd-4e520dafa5b4}: [DhcpNameServer] 192.168.0.2

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [Link mogu videti samo ulogovani korisnici]
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = [Link mogu videti samo ulogovani korisnici]
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [Link mogu videti samo ulogovani korisnici]
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = [Link mogu videti samo ulogovani korisnici]
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [Link mogu videti samo ulogovani korisnici]
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = [Link mogu videti samo ulogovani korisnici]
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [Link mogu videti samo ulogovani korisnici]
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = [Link mogu videti samo ulogovani korisnici]
HKU\S-1-5-21-2327723578-2138191117-1412739755-1001\Software\Microsoft\Internet Explorer\Main,Start Page = [Link mogu videti samo ulogovani korisnici]
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll [2015-10-10] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-10-10] (Oracle Corporation)

Edge:
======
Edge HomeButtonPage: HKU\S-1-5-21-2327723578-2138191117-1412739755-1001 -> [Link mogu videti samo ulogovani korisnici]

FireFox:
========
FF ProfilePath: C:\Users\NeMaNjiNo\AppData\Roaming\Mozilla\Firefox\Profiles\0trrw8ev.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_245.dll [2015-11-11] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-11-11] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-10-10] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-10-10] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-11-05] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-11-05] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-10-30] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-10-30] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2327723578-2138191117-1412739755-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\NeMaNjiNo\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-08-28] (Unity Technologies ApS)
FF Extension: Adblock Plus - C:\Users\NeMaNjiNo\AppData\Roaming\Mozilla\Firefox\Profiles\0trrw8ev.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-11-12]

Chrome:
=======
CHR StartupUrls: Default -> "hxxp://www.google.rs/"
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\NeMaNjiNo\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.8.824\_platform_specific\win_x86\widevinecdmadapter.dll (Google Inc.)
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.86\PepperFlash\pepflashplayer.dll ()
CHR Profile: C:\Users\NeMaNjiNo\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google презентације) - C:\Users\NeMaNjiNo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-10-30]
CHR Extension: (Google документи) - C:\Users\NeMaNjiNo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-10-30]
CHR Extension: (Google диск) - C:\Users\NeMaNjiNo\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-30]
CHR Extension: (YouTube) - C:\Users\NeMaNjiNo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-30]
CHR Extension: (Adblock Plus) - C:\Users\NeMaNjiNo\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-10-30]
CHR Extension: (Google Search) - C:\Users\NeMaNjiNo\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-30]
CHR Extension: (Google табеле) - C:\Users\NeMaNjiNo\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-10-30]
CHR Extension: (Google документи офлајн) - C:\Users\NeMaNjiNo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-10-30]
CHR Extension: (Плаћања у Chrome веб-продавници) - C:\Users\NeMaNjiNo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-10-30]
CHR Extension: (Gmail) - C:\Users\NeMaNjiNo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-10-30]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1268568 2015-06-18] (Disc Soft Ltd)
R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2505472 2015-10-09] (ESET)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1156384 2015-10-12] (NVIDIA Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1873696 2015-10-12] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5568288 2015-10-12] (NVIDIA Corporation)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH)
R2 Update service; C:\Program Files (x86)\Popcorn Time\Updater.exe [339968 2015-10-19] (Popcorn Time) [File not signed]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 adgnetworktdidrv; C:\Windows\System32\drivers\adgnetworktdidrv.sys [61432 2015-06-02] ()
R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2015-10-25] (Disc Soft Ltd)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [264040 2015-07-30] (ESET)
S0 eelam; C:\Windows\System32\DRIVERS\eelam.sys [14976 2015-07-30] (ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [186784 2015-07-30] (ESET)
R2 epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [170792 2015-07-30] (ESET)
R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [193336 2015-10-01] (Intel Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20768 2015-10-12] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [50472 2015-08-11] (NVIDIA Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [587264 2015-06-18] (Realtek )
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-11-14 03:37 - 2015-11-14 03:37 - 00012989 _____ C:\Users\NeMaNjiNo\Desktop\FRST.txt
2015-11-14 03:37 - 2015-11-14 03:37 - 00000000 ____D C:\FRST
2015-11-14 03:36 - 2015-11-14 03:36 - 02198528 _____ (Farbar) C:\Users\NeMaNjiNo\Desktop\FRST64.exe
2015-11-14 03:25 - 2015-11-14 03:25 - 00016148 _____ C:\Windows\system32\DESKTOP-U6IFMIB_NeMaNjiNo_HistoryPrediction.bin
2015-11-13 20:57 - 2015-11-13 20:57 - 00014116 _____ C:\Users\NeMaNjiNo\Desktop\tempdecal.wad
2015-11-13 19:11 - 2015-11-13 19:13 - 00000055 _____ C:\Users\NeMaNjiNo\Desktop\BIND.txt
2015-11-13 19:10 - 2015-11-13 19:10 - 00000882 _____ C:\Users\NeMaNjiNo\Desktop\CS 1.6 FULL v42.lnk
2015-11-13 19:09 - 2015-11-13 19:09 - 00000000 ____D C:\Users\NeMaNjiNo\Desktop\maps
2015-11-12 22:51 - 2015-11-12 22:51 - 00000000 ____D C:\Users\NeMaNjiNo\Downloads\XFakePlayers
2015-11-12 20:43 - 2015-11-12 20:43 - 00002878 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2015-11-12 20:43 - 2015-11-12 20:43 - 00000000 ____D C:\Program Files\CCleaner
2015-11-12 20:39 - 2015-11-12 20:39 - 00000000 ____D C:\Users\NeMaNjiNo\AppData\Local\TechSmith
2015-11-12 20:37 - 2015-11-12 20:37 - 00000000 ____D C:\Users\NeMaNjiNo\Documents\Camtasia Studio
2015-11-12 20:37 - 2010-03-04 17:27 - 00411480 _____ (TechSmith Corporation) C:\Windows\SysWOW64\tsccvid.dll
2015-11-12 20:36 - 2015-11-12 20:36 - 00000788 _____ C:\Users\Public\Desktop\Camtasia Studio 7.lnk
2015-11-12 20:36 - 2015-11-12 20:36 - 00000000 ____D C:\Windows\SysWOW64\QuickTime
2015-11-12 20:36 - 2015-11-12 20:36 - 00000000 ____D C:\ProgramData\TechSmith
2015-11-12 20:36 - 2015-11-12 20:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Camtasia Studio 7
2015-11-12 20:36 - 2015-11-12 20:36 - 00000000 ____D C:\Program Files (x86)\QuickTime
2015-11-12 17:32 - 2015-11-12 17:32 - 00002640 _____ C:\Users\Public\Desktop\Skype.lnk
2015-11-12 17:32 - 2015-11-12 17:32 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-11-12 17:32 - 2015-11-12 17:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-11-10 15:21 - 2015-11-05 15:41 - 00102520 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2015-11-10 15:19 - 2015-11-05 18:00 - 42914096 _____ C:\Windows\system32\nvcompiler.dll
2015-11-10 15:19 - 2015-11-05 18:00 - 37882160 _____ C:\Windows\SysWOW64\nvcompiler.dll
2015-11-10 15:19 - 2015-11-05 18:00 - 22343800 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2015-11-10 15:19 - 2015-11-05 18:00 - 18389112 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2015-11-10 15:19 - 2015-11-05 18:00 - 16561320 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2015-11-10 15:19 - 2015-11-05 18:00 - 15839200 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2015-11-10 15:19 - 2015-11-05 18:00 - 14844304 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2015-11-10 15:19 - 2015-11-05 18:00 - 13533608 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2015-11-10 15:19 - 2015-11-05 18:00 - 12040952 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2015-11-10 15:19 - 2015-11-05 18:00 - 02876720 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2015-11-10 15:19 - 2015-11-05 18:00 - 02496632 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2015-11-10 15:19 - 2015-11-05 18:00 - 01905456 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6435891.dll
2015-11-10 15:19 - 2015-11-05 18:00 - 01564792 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6435891.dll
2015-11-10 15:19 - 2015-11-05 18:00 - 00877688 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2015-11-10 15:19 - 2015-11-05 18:00 - 00861816 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2015-11-10 15:19 - 2015-11-05 18:00 - 00689784 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2015-11-10 15:19 - 2015-11-05 18:00 - 00674096 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2015-11-10 15:19 - 2015-11-05 18:00 - 00539648 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2015-11-10 15:19 - 2015-11-05 18:00 - 00445216 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2015-11-10 15:19 - 2015-11-05 18:00 - 00177416 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2015-11-10 15:19 - 2015-11-05 18:00 - 00155792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2015-11-10 15:19 - 2015-11-05 18:00 - 00151368 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2015-11-10 15:19 - 2015-11-05 18:00 - 00128512 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2015-11-08 14:47 - 2015-11-08 14:47 - 00000000 ____D C:\Users\NeMaNjiNo\AppData\Roaming\PowerISO
2015-11-07 23:37 - 2015-11-07 23:37 - 00001270 _____ C:\Users\Public\Desktop\Popcorn Time.lnk
2015-11-07 23:36 - 2015-11-07 23:37 - 00000000 ____D C:\Program Files (x86)\Popcorn Time
2015-11-05 20:11 - 2015-11-02 23:49 - 00039240 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2015-11-05 20:11 - 2015-11-02 18:03 - 01905272 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6435887.dll
2015-11-05 20:11 - 2015-11-02 18:03 - 01564976 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6435887.dll
2015-11-05 03:51 - 2015-11-05 04:00 - 00000400 __RSH C:\ProgramData\ntuser.pol
2015-10-30 12:48 - 2015-11-11 08:54 - 00002262 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-10-30 12:48 - 2015-10-30 12:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-10-30 12:47 - 2015-11-14 02:52 - 00000970 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-10-30 12:47 - 2015-11-13 12:52 - 00000966 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-10-30 12:47 - 2015-10-30 12:48 - 00000000 ____D C:\Program Files (x86)\Google
2015-10-30 12:47 - 2015-10-30 12:47 - 00004028 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-10-30 12:47 - 2015-10-30 12:47 - 00003796 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-10-30 12:25 - 2015-10-30 12:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-10-30 00:50 - 2015-10-30 00:50 - 00000262 _____ C:\Windows\SysWOW64\Drivers\vwifikerneldrv.sys
2015-10-30 00:50 - 2015-10-30 00:50 - 00000262 _____ C:\ProgramData\fontcacheev1.dat
2015-10-30 00:50 - 2015-10-30 00:50 - 00000000 ____D C:\Users\NeMaNjiNo\AppData\Roaming\Performix LLC
2015-10-30 00:50 - 2015-06-02 16:38 - 00061432 _____ () C:\Windows\system32\Drivers\adgnetworktdidrv.sys
2015-10-30 00:30 - 2015-10-21 13:45 - 00541024 _____ (Microsoft Corporation) C:\Windows\system32\mcupdate_GenuineIntel.dll
2015-10-30 00:30 - 2015-10-21 12:59 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\browserbroker.dll
2015-10-30 00:30 - 2015-10-21 12:52 - 02987520 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll
2015-10-30 00:30 - 2015-10-21 12:50 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\MusUpdateHandlers.dll
2015-10-30 00:30 - 2015-10-21 12:47 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Usb.dll
2015-10-30 00:30 - 2015-10-21 12:46 - 01602560 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-10-30 00:30 - 2015-10-21 12:40 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\dssvc.dll
2015-10-30 00:30 - 2015-10-21 06:05 - 02639872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll
2015-10-30 00:30 - 2015-10-21 06:03 - 01380864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-10-30 00:30 - 2015-10-21 06:03 - 00311296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Usb.dll
2015-10-30 00:29 - 2015-10-28 00:38 - 21871616 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll
2015-10-30 00:29 - 2015-10-21 13:44 - 00459104 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2015-10-30 00:29 - 2015-10-21 13:43 - 01392480 _____ (Microsoft Corporation) C:\Windows\system32\LicenseManager.dll
2015-10-30 00:29 - 2015-10-21 13:39 - 03621248 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-10-30 00:29 - 2015-10-21 13:00 - 24595968 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-10-30 00:29 - 2015-10-21 12:57 - 02418688 _____ (Microsoft Corporation) C:\Windows\system32\MFMediaEngine.dll
2015-10-30 00:29 - 2015-10-21 12:48 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2015-10-30 00:29 - 2015-10-21 12:46 - 02179584 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2015-10-30 00:29 - 2015-10-21 12:44 - 00713216 _____ (Microsoft Corporation) C:\Windows\system32\usermgr.dll
2015-10-30 00:29 - 2015-10-21 12:44 - 00579072 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2015-10-30 00:29 - 2015-10-21 12:42 - 00627712 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.dll
2015-10-30 00:29 - 2015-10-21 12:41 - 01795072 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.dll
2015-10-30 00:29 - 2015-10-21 12:38 - 00502272 _____ (Microsoft Corporation) C:\Windows\system32\dlnashext.dll
2015-10-30 00:29 - 2015-10-21 06:53 - 00961376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LicenseManager.dll
2015-10-30 00:29 - 2015-10-21 06:49 - 02878512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-10-30 00:29 - 2015-10-21 06:08 - 01918976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2015-10-30 00:29 - 2015-10-21 05:58 - 00464896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.dll
2015-10-30 00:29 - 2015-10-21 05:55 - 00441344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dlnashext.dll
2015-10-30 00:28 - 2015-10-28 00:16 - 18801664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
2015-10-30 00:28 - 2015-10-21 13:00 - 03248128 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.dll
2015-10-30 00:28 - 2015-10-21 12:43 - 02675200 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepository.dll
2015-10-30 00:28 - 2015-10-21 06:13 - 19326464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-10-30 00:28 - 2015-10-21 06:11 - 02647040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll
2015-10-30 00:28 - 2015-10-21 05:58 - 02049536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepository.dll
2015-10-28 21:10 - 2015-10-28 21:10 - 00000000 ____D C:\Users\NeMaNjiNo\AppData\LocalLow\Temp
2015-10-28 20:20 - 2015-10-28 20:20 - 00000000 ___RD C:\Users\NeMaNjiNo\3D Objects
2015-10-28 00:41 - 2015-10-29 16:53 - 00000000 ____D C:\Users\NeMaNjiNo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2015-10-28 00:41 - 2015-10-29 16:53 - 00000000 ____D C:\Users\NeMaNjiNo\AppData\Local\Deployment
2015-10-28 00:41 - 2015-10-28 00:41 - 00000332 _____ C:\Users\NeMaNjiNo\Desktop\Ghost Recon Phantoms - EU.appref-ms
2015-10-28 00:41 - 2015-10-28 00:41 - 00000000 ____D C:\Users\NeMaNjiNo\AppData\Local\Apps\2.0
2015-10-28 00:41 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll
2015-10-28 00:41 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll
2015-10-27 15:21 - 2015-10-27 15:21 - 00000000 ____D C:\Program Files (x86)\Microsoft ASP.NET
2015-10-26 23:18 - 2015-10-26 23:18 - 00001769 _____ C:\Users\NeMaNjiNo\Desktop\Movie Maker.lnk
2015-10-26 23:07 - 2015-10-26 23:07 - 00001238 _____ C:\Users\NeMaNjiNo\Desktop\Wave Editor.lnk
2015-10-26 23:07 - 2015-10-26 23:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Abyssmedia
2015-10-26 23:07 - 2015-10-26 23:07 - 00000000 ____D C:\Program Files (x86)\Abyssmedia
2015-10-26 23:01 - 2015-10-26 23:01 - 00001447 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
2015-10-26 23:01 - 2015-10-26 23:01 - 00001378 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk
2015-10-26 23:01 - 2015-10-26 23:01 - 00000000 ____D C:\Windows\PCHEALTH
2015-10-26 23:01 - 2015-10-26 23:01 - 00000000 ____D C:\Windows\en
2015-10-26 23:01 - 2015-10-26 23:01 - 00000000 ____D C:\Program Files (x86)\Windows Live
2015-10-26 23:01 - 2015-10-26 23:01 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2015-10-26 23:00 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll
2015-10-26 23:00 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
2015-10-26 23:00 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
2015-10-26 23:00 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll
2015-10-26 23:00 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
2015-10-26 23:00 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
2015-10-26 23:00 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
2015-10-26 23:00 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll
2015-10-26 23:00 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll
2015-10-26 23:00 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll
2015-10-26 23:00 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
2015-10-26 23:00 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll
2015-10-26 22:59 - 2015-10-31 15:01 - 00000000 ____D C:\Users\NeMaNjiNo\AppData\Local\Windows Live
2015-10-26 22:58 - 2015-10-26 23:00 - 00000000 ____D C:\Users\NeMaNjiNo\AppData\Roaming\Solveig Multimedia
2015-10-26 22:47 - 2015-10-26 22:47 - 00000609 _____ C:\Users\Public\Desktop\Fraps.lnk
2015-10-26 22:46 - 2015-10-26 22:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fraps
2015-10-26 22:40 - 2015-10-26 22:47 - 00000000 ____D C:\Fraps
2015-10-25 02:56 - 2015-10-25 03:16 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-10-25 02:56 - 2015-10-25 02:56 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-10-25 02:05 - 2015-10-25 02:05 - 00000000 ____D C:\Users\NeMaNjiNo\AppData\Local\ESET
2015-10-25 01:59 - 2015-10-25 01:59 - 00000000 ____D C:\Users\NeMaNjiNo\AppData\Local\Disc_Soft_Ltd
2015-10-25 01:56 - 2015-10-25 01:56 - 00000000 ____D C:\Program Files (x86)\Disc Soft
2015-10-25 01:55 - 2015-10-25 02:06 - 00000000 ____D C:\Users\NeMaNjiNo\AppData\Roaming\DAEMON Tools Lite
2015-10-25 01:55 - 2015-10-25 01:56 - 00030264 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtlitescsibus.sys
2015-10-25 01:55 - 2015-10-25 01:56 - 00000000 ____D C:\Program Files\DAEMON Tools Lite
2015-10-25 01:55 - 2015-10-25 01:55 - 00001814 _____ C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
2015-10-25 01:55 - 2015-10-25 01:55 - 00000000 ____D C:\ProgramData\DAEMON Tools Lite
2015-10-24 20:29 - 2015-10-24 20:29 - 00000000 ____D C:\Users\NeMaNjiNo\AppData\Roaming\IGG
2015-10-23 20:02 - 2015-10-23 20:02 - 00000000 ____D C:\Users\NeMaNjiNo\AppData\Local\AutorunX2
2015-10-23 13:06 - 2015-10-23 13:06 - 00000000 ____D C:\Users\NeMaNjiNo\AppData\LocalLow\Adobe
2015-10-23 13:05 - 2015-10-30 10:20 - 00003972 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2015-10-23 13:05 - 2015-10-29 14:42 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-10-23 13:05 - 2015-10-23 13:05 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-10-23 13:04 - 2015-10-23 13:06 - 00000000 ____D C:\ProgramData\Adobe
2015-10-22 20:47 - 2015-11-12 20:43 - 00000000 ____D C:\Users\NeMaNjiNo\AppData\Local\CrashDumps
2015-10-22 19:58 - 2015-10-22 19:58 - 00000000 ____D C:\Users\NeMaNjiNo\AppData\Roaming\FileZilla Server
2015-10-21 22:52 - 2015-10-21 22:52 - 00275501 _____ C:\Windows\diagerr.xml
2015-10-21 22:52 - 2015-10-21 22:52 - 00002596 _____ C:\Windows\diagwrn.xml
2015-10-21 22:52 - 2015-10-21 22:52 - 00000000 ____D C:\$WINDOWS.~BT
2015-10-21 22:44 - 2015-10-21 22:44 - 00000000 ___HD C:\$Windows.~WS
2015-10-20 18:16 - 2015-10-20 18:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2015-10-20 18:16 - 2015-10-20 18:16 - 00000000 ____D C:\ProgramData\ESET
2015-10-20 18:16 - 2015-10-20 18:16 - 00000000 ____D C:\Program Files\ESET
2015-10-18 02:45 - 2015-10-25 00:20 - 00000000 ____D C:\Users\NeMaNjiNo\AppData\Local\Filmovita-App
2015-10-18 02:45 - 2015-10-18 02:49 - 00000000 ____D C:\Users\NeMaNjiNo\AppData\Local\Filmovita
2015-10-18 02:45 - 2015-10-18 02:45 - 00000000 ____D C:\ProgramData\Caphyon
2015-10-18 02:44 - 2015-10-18 02:44 - 00000000 ____D C:\Users\NeMaNjiNo\AppData\Roaming\CG
2015-10-17 23:17 - 2015-10-17 23:17 - 00000000 ____D C:\Windows\ERUNT
2015-10-17 03:11 - 2015-10-28 03:32 - 00007613 _____ C:\Users\NeMaNjiNo\AppData\Local\Resmon.ResmonCfg
2015-10-15 13:39 - 2015-10-15 13:44 - 00000000 ____D C:\Users\NeMaNjiNo\AppData\Local\Comodo
2015-10-15 13:39 - 2015-10-15 13:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
2015-10-15 13:38 - 2015-10-15 13:38 - 01060864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71.dll
2015-10-15 13:38 - 2015-10-15 13:38 - 00348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-11-14 03:37 - 2015-07-30 23:42 - 00000000 ____D C:\Windows\system32\sru
2015-11-14 03:32 - 2015-10-01 09:29 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-11-14 03:03 - 2015-10-01 17:41 - 00000000 ____D C:\Users\NeMaNjiNo\AppData\Roaming\Skype
2015-11-14 02:29 - 2015-10-07 20:29 - 00004176 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{3B49DB2E-2EA5-4C75-8AE0-B4EE8534A7FE}
2015-11-13 18:02 - 2015-07-30 23:42 - 00000000 ____D C:\Windows\AppReadiness
2015-11-12 20:41 - 2015-10-04 20:25 - 00000000 ____D C:\Users\NeMaNjiNo\AppData\Roaming\uTorrent
2015-11-12 20:38 - 2015-10-01 08:56 - 00000000 ____D C:\Users\NeMaNjiNo
2015-11-12 20:20 - 2015-10-01 08:57 - 00875126 _____ C:\Windows\system32\PerfStringBackup.INI
2015-11-12 19:41 - 2015-10-01 09:10 - 00000000 ____D C:\ProgramData\NVIDIA
2015-11-12 19:41 - 2015-07-30 22:52 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-11-12 17:32 - 2015-10-01 17:40 - 00000000 ____D C:\ProgramData\Skype
2015-11-12 17:21 - 2015-07-10 10:05 - 00262144 ___SH C:\Windows\system32\config\BBI
2015-11-11 12:20 - 2015-10-02 09:45 - 00000000 ____D C:\Windows\system32\MRT
2015-11-11 12:20 - 2015-07-30 23:25 - 00000000 ____D C:\Windows\CbsTemp
2015-11-11 12:17 - 2015-10-02 09:45 - 145617392 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-11-11 03:32 - 2015-10-01 09:29 - 00003816 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-11-10 15:21 - 2015-10-07 20:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-11-10 15:21 - 2015-10-01 09:09 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2015-11-07 23:39 - 2015-10-01 08:56 - 00000000 ____D C:\Users\NeMaNjiNo\AppData\Local\VirtualStore
2015-11-07 04:19 - 2015-10-01 09:09 - 11227280 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2015-11-05 21:50 - 2015-10-01 22:06 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-11-05 21:50 - 2015-07-30 22:49 - 00197800 _____ C:\Windows\system32\FNTCACHE.DAT
2015-11-05 18:00 - 2015-10-01 09:09 - 18487552 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2015-11-05 18:00 - 2015-10-01 09:09 - 15933912 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2015-11-05 18:00 - 2015-10-01 09:09 - 12870192 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2015-11-05 18:00 - 2015-10-01 09:09 - 03540360 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2015-11-05 18:00 - 2015-10-01 09:09 - 03126800 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2015-11-05 18:00 - 2015-10-01 09:09 - 00112944 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2015-11-05 18:00 - 2015-10-01 09:09 - 00105080 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2015-11-05 18:00 - 2015-10-01 09:09 - 00034493 _____ C:\Windows\system32\nvinfo.pb
2015-11-05 16:08 - 2015-10-01 09:09 - 06358648 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2015-11-05 16:08 - 2015-10-01 09:09 - 02983216 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2015-11-05 16:08 - 2015-10-01 09:09 - 02554672 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2015-11-05 16:08 - 2015-10-01 09:09 - 00938616 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2015-11-05 16:08 - 2015-10-01 09:09 - 00385328 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2015-11-05 16:08 - 2015-10-01 09:09 - 00062584 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2015-11-05 03:52 - 2015-10-12 23:56 - 00001286 _____ C:\Users\NeMaNjiNo\AppData\Roaming\Microsoft\Windows\Start Menu\GOM Player.lnk
2015-11-05 03:52 - 2015-10-12 23:56 - 00001262 _____ C:\Users\Public\Desktop\GOM Player.lnk
2015-11-03 19:20 - 2015-07-30 23:43 - 00810488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-11-03 19:20 - 2015-07-30 23:43 - 00176632 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-11-02 23:49 - 2015-10-01 09:09 - 01572496 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
2015-11-02 23:49 - 2015-10-01 09:09 - 00205456 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2015-11-01 21:33 - 2015-10-01 17:30 - 00001949 _____ C:\Users\NeMaNjiNo\Desktop\This PC.lnk
2015-10-30 13:24 - 2015-07-30 23:42 - 00000000 ____D C:\Windows\rescache
2015-10-30 12:48 - 2015-10-01 09:07 - 00000000 ____D C:\Users\NeMaNjiNo\AppData\Local\Google
2015-10-30 12:45 - 2015-10-10 22:03 - 00000000 ____D C:\Windows\system32\appmgmt
2015-10-30 00:33 - 2015-07-30 23:42 - 00000000 ____D C:\Windows\system32\appraiser
2015-10-28 14:49 - 2015-10-01 09:09 - 06027430 _____ C:\Windows\system32\nvcoproc.bin
2015-10-26 23:01 - 2015-07-30 23:42 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-10-25 02:56 - 2015-10-08 18:18 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-10-25 02:56 - 2015-10-08 18:17 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-10-25 02:37 - 2015-10-01 22:06 - 00001134 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-10-25 02:37 - 2015-10-01 22:06 - 00001122 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-10-25 02:05 - 2015-10-01 17:33 - 00001916 _____ C:\Users\NeMaNjiNo\Desktop\Control Panel.lnk
2015-10-23 20:04 - 2015-07-30 23:42 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2015-10-23 20:04 - 2015-07-30 23:42 - 00000000 ____D C:\Windows\SysWOW64\GroupPolicy
2015-10-23 13:06 - 2015-10-01 09:28 - 00000000 ____D C:\Users\NeMaNjiNo\AppData\Local\Adobe
2015-10-23 13:06 - 2015-10-01 08:56 - 00000000 ____D C:\Users\NeMaNjiNo\AppData\Roaming\Adobe
2015-10-21 22:52 - 2015-10-01 18:48 - 00000000 ____D C:\Windows\Panther
2015-10-20 20:58 - 2015-10-13 19:13 - 00000000 ____D C:\Users\NeMaNjiNo\AppData\Roaming\TeamViewer
2015-10-20 18:16 - 2015-07-30 23:42 - 00000000 ___HD C:\Windows\ELAMBKUP
2015-10-17 22:32 - 2015-10-07 20:19 - 00000000 ____D C:\Users\NeMaNjiNo\AppData\Local\NVIDIA Corporation

==================== Files in the root of some directories =======

2015-10-17 03:11 - 2015-10-28 03:32 - 0007613 _____ () C:\Users\NeMaNjiNo\AppData\Local\Resmon.ResmonCfg
2015-10-30 00:50 - 2015-10-30 00:50 - 0000262 _____ () C:\ProgramData\fontcacheev1.dat

Files to move or delete:
====================
C:\ProgramData\fontcacheev1.dat


Some files in TEMP:
====================
C:\Users\NeMaNjiNo\AppData\Local\Temp\Uninstall.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-11-06 13:17

==================== End of FRST.txt ============================

Dopuna: 14 Nov 2015 3:39

[Link mogu videti samo ulogovani korisnici]



offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8657
  • Gde živiš: Novi Beograd

Zdravo,

1. Otvori Notepad (Text Document) i iskopiraj sledeći tekst unutar kod polja ispod:

CreateRestorePoint:
Edge HomeButtonPage: HKU\S-1-5-21-2327723578-2138191117-1412739755-1001 -> hxxp://www.oursurfing.com/?type=hp&ts=1445735110&z=08e877bce1fcb7969c97db5g0z7zbwcm3caw7g0gbe&from=amt&uid=st1500dm003-9yn16g_s1e0mnw0xxxxs1e0mnw0
C:\ProgramData\fontcacheev1.dat
EmptyTemp:


2. Sačuvaj notepad na Desktop pod nazivom fixlist.txt
To možes uraditi i iz notepad-a => klik na File potom na Save As i u novom prozoru, dole pod File Name: staviš za naziv fixlist.txt
Napomena: Važno je da se oba fajla, FRST i fixlist nalaze na istoj lokaciji jer u suprotnom fix nece raditi.

3. Ponovo pokreni FRST/FRST64, klikni jednom na dugme Fix i sačekaj.
Ukoliko alat zatraži restart sistema, dozvoli mu i postaraj se da alat kompletira fix nakon restarta sistema.



Alat će formirati log (Fixlog.txt) na Desktop-u. Potrebno je sadržaj tog loga iskopirati u poruku.
Napomena: Ukoliko te alat upozori da postoji novija verzija, postaraj se da preuzmes i koristiš ažuriranu kopiju FRST-a.

-----

Preuzmi "Xplode"-ov AdwCleaner () i sacuvaj ga na Desktop

Dvoklikom pokreni program.
Klikni na dugme [Scan] i pricekaj da program zavrsi.
Klikni na dugme [Clean]
Program ce zatvoriti sve aktivne programe i izbaciti prozor sa tim upozorenjem. Klikni Ok kao potvrdu.
Na sledeca dva prozora koja se otvore (Informations i Restart required ) klikni Ok


Racunar ce se restartovati a potom otvoriti notepad (C:\AdwCleaner[S1].txt) sa izvestajem.
Sacuvaj taj notepad na Desktop i okaci ga uz poruku koristeci opciju "Prikaci fajl"

Napomena: Izvestaj ce takodje biti sacuvan na C:\AdwCleaner[S0].txt

------

Preuzmi Junkware Removal Tool ( JRT ) i sacuvaj ga na desktop.

zatvori browser i ostale pokrenute programe;

Privremeno deaktiviraj zastitni softver (Uputstvo);

dvoklikom na ikonicu ( )pokreni program JRT;

Kod obavestenja "press any key" pritisnuti bilo koji taster i alat ce zapoceti skeniranje.
Napomena: u zavisnosti od sistemske specifikacije vreme skeniranja u nekim slucajevima moze da potraje.

Kada zavrsi otvorice se log sa izvestajem koji ce biti sacuvan na desktopu pod nazivom JRT.txt


Arrow Kopiraj sadrzaj tog loga u temu.



offline
  • Nemanja Djukanovic
  • Pridružio: 18 Dec 2012
  • Poruke: 1761
  • Gde živiš: Niksic - Crna Gora

Fix result of Farbar Recovery Scan Tool (x64) Version:07-11-2015
Ran by NeMaNjiNo (2015-11-14 11:20:00) Run:1
Running from C:\Users\NeMaNjiNo\Desktop
Loaded Profiles: NeMaNjiNo (Available Profiles: NeMaNjiNo)
Boot Mode: Normal
==============================================

fixlist content:
*****************
CreateRestorePoint:
Edge HomeButtonPage: HKU\S-1-5-21-2327723578-2138191117-1412739755-1001 -> [Link mogu videti samo ulogovani korisnici]
C:\ProgramData\fontcacheev1.dat
EmptyTemp:
*****************

Restore point was successfully created.
HKU\S-1-5-21-2327723578-2138191117-1412739755-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\Main\\HomeButtonPage => value removed successfully
C:\ProgramData\fontcacheev1.dat => moved successfully
EmptyTemp: => 378.7 MB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 11:20:18 ====

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8657
  • Gde živiš: Novi Beograd

Postavi i ostale logove.

offline
  • Nemanja Djukanovic
  • Pridružio: 18 Dec 2012
  • Poruke: 1761
  • Gde živiš: Niksic - Crna Gora

Napisano: 14 Nov 2015 11:28

[Link mogu videti samo ulogovani korisnici]

Dopuna: 14 Nov 2015 11:29

[Link mogu videti samo ulogovani korisnici]

Dopuna: 14 Nov 2015 11:33

[Link mogu videti samo ulogovani korisnici]

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8657
  • Gde živiš: Novi Beograd

Da li ima nekih problema?

offline
  • Nemanja Djukanovic
  • Pridružio: 18 Dec 2012
  • Poruke: 1761
  • Gde živiš: Niksic - Crna Gora

Nema nikakvih Smile

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8657
  • Gde živiš: Novi Beograd

Odlicno.

Sledeća procedura će implementirati završno čišćenje.



Arrow Preuzmi "Xplode"-ov DelFix alat i snimi ga na Desktop.

Dvoklikom pokreni alat i štikliraj kućice ispred sledećih opcija;
Remove disinfection tools
Create registry backup
Purge System Restore


Klikni na dugme Run i pričekaj trenutak dok alat ne završi svoj rad.

Od ovog trenutka, svi korišćeni alati u ovoj temi bi trebali biti obrisani.
Ukoliko neki alat ili izveštaj nije uklonjen, slobodno ih obriši ručno.


Alat će takođe formirati izveštaj za tebe. (C:\DelFix.txt)
- Alat će snimiti i zdravo stanje registy-ja i napraviti backup koristeci integrisan program "ERUNT" u %windir%\ERUNT\DelFix
- DelFix briše stare system restore tačke i pravi novu, svežu tačku nakon čišćenja.

offline
  • Nemanja Djukanovic
  • Pridružio: 18 Dec 2012
  • Poruke: 1761
  • Gde živiš: Niksic - Crna Gora

Hvala puno Smile

Ko je trenutno na forumu
 

Ukupno su 3947 korisnika na forumu :: 75 registrovanih, 8 sakrivenih i 3864 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 20624 - dana 04 Apr 2026 04:18

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 357magnum, A.R.Chafee.Jr., amaterSRB, annon, Apok, aramis s, Asteker, babaroga, Ben Roj, boj.an, bojanM84, celt, CikaKURE, Colt D, cyprus, djordjemiklusev, Dorcolac, Dusko_Dugousko, Electron, EVIDENTICAR, Georgius, Goran_, Grebostrek, iceburn, ILGromovnik, istina, Istman, K-1A, komenski, Krajišnik97, Le Banner, lukac, Macalone, mercedesamg, Miki 84, Milan A. Nikolic, mist-mist, Nemanja.M, NemanjaKT, Nikola93., nixos, NorthWind, OldKresoje, Petarvu, PitterBg, Prečanin30, procesor, RajkoB, Recce, ruso, sabros, sevenino, Sir Budimir, slucajniprolaznik.ba, spektorsky, StalniPromatrač, t.e.m.p.l.a.r., Tas011, TripleTwo, uruk, vaci, vathra, Velizar Laro, vlad4, Vlado82, Vojo06, Warrior, xAlex2, XBMC, yufighter, YugoSlav, zeka013, zombicar153, |_MeD_|, Žrnov