Restartuje mi se racunar

2

Restartuje mi se racunar

offline
  • Pridružio: 09 Jun 2015
  • Poruke: 56

Zavrsilo je evo fajlova adwcleaner ( mycity.rs/must-login.png ) i evo od ovog drugog ( mycity.rs/must-login.png )

offline
  • Research Engineer @MalwareBytes
  • Pridružio: 09 Avg 2011
  • Poruke: 15877
  • Gde živiš: Beograd

Sada otvori oba izvestaja i pogledaj sta je sve tu obrisano, pa mi kazi da li je to normalno.


Ponovo pokreni FRST, cekiraj Addition.txt, klikni na Scan i prikaci oba sveza izvestaja.

offline
  • Pridružio: 09 Jun 2015
  • Poruke: 56

Evo izvezstaja ( mycity.rs/must-login.png ) i ( mycity.rs/must-login.png ) ali u medjuvrenu racunar se restartovao 2x.




Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:23-09-2015
Ran by N1kola (administrator) on N1KOLA-PC (26-09-2015 07:19:59)
Running from C:\Users\N1kola\Downloads
Loaded Profiles: N1kola (Available Profiles: N1kola)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: geekstogo.com/forum/topic/335081-frst-t.....scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BBSvc.EXE
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Lavasoft Limited) C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.3.0\LavasoftTcpService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.163\SSScheduler.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\avastui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
() C:\Windows\SysWOW64\PnkBstrB.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_19_0_0_185.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_19_0_0_185.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13636824 2013-07-26] (Realtek Semiconductor)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [676608 2013-08-30] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [226560 2014-11-18] ()
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496 2015-05-12] (Avast Software s.r.o.)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-06-09] (Oracle Corporation)
HKU\S-1-5-21-2202714847-2926606003-1158938094-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [5583120 2015-02-28] (Disc Soft Ltd)
HKU\S-1-5-21-2202714847-2926606003-1158938094-1000\...\Run: [uTorrent] => C:\Users\N1kola\AppData\Roaming\uTorrent\uTorrent.exe [1774432 2015-09-18] (BitTorrent Inc.)
HKU\S-1-5-21-2202714847-2926606003-1158938094-1000\...\Run: [LightShot] => C:\Users\N1kola\AppData\Local\Skillbrains\lightshot\Lightshot.exe
HKU\S-1-5-21-2202714847-2926606003-1158938094-1000\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [785416 2015-02-18] (Sandboxie Holdings, LLC)
HKU\S-1-5-21-2202714847-2926606003-1158938094-1000\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3632472 2015-04-10] (Electronic Arts)
HKU\S-1-5-21-2202714847-2926606003-1158938094-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53655680 2015-07-29] (Skype Technologies S.A.)
HKU\S-1-5-21-2202714847-2926606003-1158938094-1000\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe [1303872 2015-03-12] (Lavasoft)
HKU\S-1-5-21-2202714847-2926606003-1158938094-1000\...\MountPoints2: F - F:\Autorun.exe
HKU\S-1-5-21-2202714847-2926606003-1158938094-1000\...\MountPoints2: {029cffd4-d21f-11e4-8977-b8975a6ec3eb} - G:\setup.exe
HKU\S-1-5-21-2202714847-2926606003-1158938094-1000\...\MountPoints2: {1d28a83a-f2a9-11e4-8ebf-b8975a6ec3eb} - H:\setup.exe
HKU\S-1-5-21-2202714847-2926606003-1158938094-1000\...\MountPoints2: {b0c1268b-c6fc-11e4-930a-b8975a6ec3eb} - F:\Autorun.exe
ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\ProgramData\MEGAsync\ShellExtX64.dll [2014-05-01] ()
ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\ProgramData\MEGAsync\ShellExtX64.dll [2014-05-01] ()
ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\ProgramData\MEGAsync\ShellExtX64.dll [2014-05-01] ()
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-05-11] (Avast Software s.r.o.)
ShellIconOverlayIdentifiers-x32: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\ProgramData\MEGAsync\ShellExtX32.dll [2014-05-01] ()
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\ProgramData\MEGAsync\ShellExtX32.dll [2014-05-01] ()
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\ProgramData\MEGAsync\ShellExtX32.dll [2014-05-01] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2015-04-16]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.163\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Users\N1kola\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GameRanger.lnk [2015-06-09]
ShortcutTarget: GameRanger.lnk -> C:\Users\N1kola\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe (GameRanger Technologies)
Startup: C:\Users\N1kola\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk [2015-08-18]
ShortcutTarget: MEGAsync.lnk -> C:\ProgramData\MEGAsync\MEGAsync.exe (Mega Limited)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{BA0454EC-5BF5-41B6-935D-0325022A04C8}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKU\S-1-5-21-2202714847-2926606003-1158938094-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.yahoo.com/?fr=vmn&type=vmn__webcompa__1_0__ya__hp_WCYID10099_swoc_campaign_150421__yaie
HKU\S-1-5-21-2202714847-2926606003-1158938094-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
SearchScopes: HKU\S-1-5-21-2202714847-2926606003-1158938094-1000 -> DefaultScope {C0C3A6C6-03BC-4195-8FCB-AEA091301353} URL =
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-03-24] (Avast Software s.r.o.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\ssv.dll [2015-07-26] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-03-24] (Avast Software s.r.o.)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO-x32: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll [2012-02-14] (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-07-26] (Oracle Corporation)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll [2012-02-14] (Microsoft Corporation.)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2015-07-17] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2015-07-17] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2015-07-17] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2015-07-17] (Microsoft Corporation)

FireFox:
========
FF ProfilePath: C:\Users\N1kola\AppData\Roaming\Mozilla\Firefox\Profiles\fy9eeq4j.default
FF DefaultSearchEngine: oursurfing
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_185.dll [2015-09-22] ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-10] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_185.dll [2015-09-22] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-07-26] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-07-26] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-25] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-04-01] (Microsoft Corporation)
FF Plugin-x32: @qq.com/npAndroidAssistant -> C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3198\npQQPhoneManagerExt.dll [No File]
FF Plugin-x32: @t.garena.com/garenatalk -> C:\Program Files (x86)\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll [2015-05-27] ( Garena)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin-x32: @verimatrix.com/ViewRightWeb -> C:\Program Files (x86)\Verimatrix\ViewRight Web\\npViewRight.dll [2014-06-10] (Verimatrix, Inc.)
FF Plugin HKU\S-1-5-21-2202714847-2926606003-1158938094-1000: @verimatrix.com/ViewRightWeb -> C:\Program Files (x86)\Verimatrix\ViewRight Web\\npViewRight.dll [2014-06-10] (Verimatrix, Inc.)
FF Plugin HKU\S-1-5-21-2202714847-2926606003-1158938094-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll No File
FF SearchPlugin: C:\Users\N1kola\AppData\Roaming\Mozilla\Firefox\Profiles\fy9eeq4j.default\searchplugins\oursurfing-1.xml [2015-09-23]
FF SearchPlugin: C:\Users\N1kola\AppData\Roaming\Mozilla\Firefox\Profiles\fy9eeq4j.default\searchplugins\oursurfing-2.xml [2015-09-23]
FF SearchPlugin: C:\Users\N1kola\AppData\Roaming\Mozilla\Firefox\Profiles\fy9eeq4j.default\searchplugins\oursurfing-3.xml [2015-09-23]
FF SearchPlugin: C:\Users\N1kola\AppData\Roaming\Mozilla\Firefox\Profiles\fy9eeq4j.default\searchplugins\oursurfing-4.xml [2015-09-25]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-03-24]
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\!BBE3F2ADA671A2F3CE8917BDEA4A3466BBE3.js [2015-09-08]

Chrome:
=======
CHR DefaultSearchURL: Default -> hxxp://musixlib.searchalgo.com/search/?category=web&s=amds&q={searchTerms}
CHR DefaultSearchKeyword: Default -> MusixLib Search
CHR DefaultSuggestURL: Default -> hxxp://sug.searchalgo.com/search/index_sg.php?q={searchTerms}
CHR Profile: C:\Users\N1kola\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\N1kola\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-03-10]
CHR Extension: (Google Docs) - C:\Users\N1kola\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-03-10]
CHR Extension: (Google Drive) - C:\Users\N1kola\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-03-10]
CHR Extension: (YouTube) - C:\Users\N1kola\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-03-10]
CHR Extension: (Google Search) - C:\Users\N1kola\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-03-10]
CHR Extension: (Avast SafePrice) - C:\Users\N1kola\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2015-03-29]
CHR Extension: (Google Docs Offline) - C:\Users\N1kola\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-08]
CHR Extension: (Avast Online Security) - C:\Users\N1kola\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-03-24]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\N1kola\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-10]
CHR Extension: (Chrome Web Store Payments) - C:\Users\N1kola\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-28]
CHR Extension: (Gmail) - C:\Users\N1kola\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-10]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-03-24]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-03-24]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-05-01]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 ACTION_SVC; C:\Program Files (x86)\Mirillis\Action!\action_svc.exe [16064 2014-10-25] ()
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2013-08-30] (Advanced Micro Devices, Inc.) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-05-11] (Avast Software s.r.o.)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4034896 2015-05-11] (Avast Software)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1272592 2015-02-28] (Disc Soft Ltd)
R2 LavasoftTcpService; C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.3.0\LavasoftTcpService.exe [836984 2015-03-12] (Lavasoft Limited)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.163\McCHSvc.exe [289256 2015-07-31] (McAfee, Inc.)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1931632 2015-04-10] (Electronic Arts)
R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [214520 2015-07-31] ()
R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [175112 2015-02-18] (Sandboxie Holdings, LLC)
S2 SearchProtectionService; C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WinService.exe [17768 2015-03-12] ()
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5495056 2015-06-01] (TeamViewer GmbH)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [X]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-05-11] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [89944 2015-05-11] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-05-11] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-05-11] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-05-11] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-06-27] (Avast Software s.r.o.)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [137288 2015-05-11] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [272248 2015-05-11] ()
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [88480 2015-08-06] ()
R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30352 2015-03-10] (Disc Soft Ltd)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-11] (Broadcom Corporation)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [46400 2015-08-06] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [237064 2015-02-18] (Sandboxie Holdings, LLC)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [381608 2015-03-31] (Duplex Secure Ltd.)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [273824 2015-05-11] (Avast Software)
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S3 EsgScanner; system32\DRIVERS\EsgScanner.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-09-26 07:18 - 2015-09-26 07:18 - 00040890 _____ C:\Users\N1kola\Desktop\FRST1.txt
2015-09-25 21:29 - 2015-09-25 21:29 - 00038701 _____ C:\Users\N1kola\Desktop\malware.txt
2015-09-25 20:52 - 2015-09-25 21:28 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-09-25 20:51 - 2015-09-25 21:21 - 00001100 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-09-25 20:51 - 2015-09-25 20:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-09-25 20:51 - 2015-09-25 20:51 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-09-25 20:51 - 2015-09-25 20:51 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-09-25 20:51 - 2015-06-18 14:41 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-09-25 20:51 - 2015-06-18 14:41 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-09-25 20:51 - 2015-06-18 14:41 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-09-25 20:50 - 2015-09-25 20:50 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\N1kola\Downloads\mbam-setup-2.1.8.1057.exe
2015-09-25 20:47 - 2015-09-25 20:47 - 00024440 _____ C:\Users\N1kola\Desktop\AdwCleaner[C1].txt
2015-09-25 20:42 - 2015-09-25 20:45 - 00000000 ____D C:\AdwCleaner
2015-09-25 20:42 - 2015-09-25 20:42 - 01662976 _____ C:\Users\N1kola\Downloads\AdwCleaner.exe
2015-09-25 20:20 - 2015-09-25 21:21 - 00001181 _____ C:\Users\N1kola\Desktop\Mad Max.lnk
2015-09-25 20:20 - 2015-09-25 20:20 - 00000000 ____D C:\Users\N1kola\AppData\Roaming\Mad Max
2015-09-25 18:15 - 2015-09-25 18:15 - 00048037 _____ C:\Users\N1kola\Desktop\Addition.txt
2015-09-25 18:14 - 2015-09-25 18:14 - 00045233 _____ C:\Users\N1kola\Desktop\FRST.txt
2015-09-25 18:09 - 2015-09-25 18:13 - 00048037 _____ C:\Users\N1kola\Downloads\Addition.txt
2015-09-25 18:00 - 2015-09-26 07:19 - 00021633 _____ C:\Users\N1kola\Downloads\FRST.txt
2015-09-25 17:59 - 2015-09-26 07:20 - 00000000 ____D C:\FRST
2015-09-25 17:58 - 2015-09-25 17:59 - 02192384 _____ (Farbar) C:\Users\N1kola\Downloads\FRST64.exe
2015-09-25 17:04 - 2015-09-25 17:04 - 00068477 _____ C:\Users\N1kola\Desktop\file.txt
2015-09-25 17:03 - 2015-09-25 17:04 - 00068477 _____ C:\Users\N1kola\Downloads\MTB.txt
2015-09-25 17:02 - 2015-09-25 17:03 - 00891392 _____ (Farbar) C:\Users\N1kola\Downloads\MiniToolBox.exe
2015-09-24 19:07 - 2015-09-24 21:50 - 00000000 ____D C:\Users\N1kola\Downloads\[R.G. Mechanics] Mad Max
2015-09-24 08:30 - 2015-09-24 08:30 - 00000000 ____D C:\ProgramData\SystemRequirementsLab
2015-09-19 16:45 - 2015-09-19 16:45 - 00103889 _____ C:\Users\N1kola\Downloads\Mad Max FULL UNLOCKED.torrent
2015-09-19 16:12 - 2015-09-25 21:21 - 00000906 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pro Evolution Soccer 2016.lnk
2015-09-19 16:12 - 2015-09-25 21:21 - 00000900 _____ C:\Users\Public\Desktop\Pro Evolution Soccer 2016.lnk
2015-09-19 16:12 - 2015-09-19 16:31 - 00000000 ____D C:\Program Files (x86)\Pro Evolution Soccer 2016
2015-09-19 01:03 - 2015-09-19 01:03 - 00000000 ____D C:\Users\N1kola\Downloads\3DMGAME-Mad.Max.Update.0.Incl.DLC.and.(zabranjeno).v3-3DM
2015-09-18 23:51 - 2015-09-25 20:22 - 00000000 ____D C:\Users\N1kola\Documents\WB Games
2015-09-18 23:43 - 2015-09-18 23:46 - 00000000 ____D C:\Users\N1kola\Downloads\3DMGAME-Mad.Max.Update.0.Incl.DLC.and.(zabranjeno)-3DM
2015-09-18 23:34 - 2015-09-18 23:34 - 00000029 _____ C:\Users\N1kola\Desktop\mad max aa.txt
2015-09-18 20:41 - 2015-09-19 15:59 - 905117696 _____ C:\Users\N1kola\Downloads\rld-prevso2016.iso
2015-09-18 20:40 - 2015-09-18 20:40 - 00013001 _____ C:\Users\N1kola\Downloads\Pro Evolution Soccer 2016-RELOADED-[rarbg.com].torrent
2015-09-17 00:15 - 2015-09-17 00:15 - 00000000 ____D C:\Users\N1kola\Documents\Amnesia
2015-09-17 00:15 - 2015-09-17 00:15 - 00000000 ____D C:\Users\N1kola\AppData\Roaming\fltk.org
2015-09-17 00:15 - 2015-09-17 00:15 - 00000000 ____D C:\ProgramData\fltk.org
2015-09-16 22:43 - 2015-09-16 22:43 - 00000221 _____ C:\Users\N1kola\Desktop\Amnesia The Dark Descent.url
2015-09-14 21:12 - 2015-09-14 21:41 - 00000000 ____D C:\ProgramData\Test Drive Unlimited
2015-09-14 21:12 - 2015-09-14 21:12 - 00000000 ____D C:\Users\N1kola\Documents\Test Drive Unlimited
2015-09-14 21:02 - 2015-09-14 21:02 - 00000000 ____D C:\Users\N1kola\Desktop\TDU
2015-09-08 21:19 - 2015-09-08 21:19 - 00003056 _____ C:\Windows\System32\Tasks\Fruit
2015-09-06 23:57 - 2015-09-25 21:21 - 00001932 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2015-09-06 23:57 - 2015-09-06 23:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2015-09-06 23:57 - 2015-09-06 23:57 - 00000000 ____D C:\Program Files\McAfee Security Scan
2015-09-01 02:39 - 2015-09-01 02:39 - 222643542 _____ C:\Windows\MEMORY.DMP
2015-09-01 02:39 - 2015-09-01 02:39 - 00341336 _____ C:\Windows\Minidump\083115-26192-01.dmp
2015-08-28 20:39 - 2015-09-08 21:19 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-09-26 07:19 - 2009-07-14 13:13 - 00778834 _____ C:\Windows\system32\PerfStringBackup.INI
2015-09-26 07:17 - 2015-07-17 04:56 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-09-26 07:17 - 2015-03-10 15:27 - 02057426 _____ C:\Windows\WindowsUpdate.log
2015-09-26 07:14 - 2015-07-17 04:56 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-09-26 07:13 - 2015-03-11 10:08 - 00000000 ____D C:\Users\N1kola\AppData\Roaming\uTorrent
2015-09-26 07:13 - 2009-07-14 13:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-09-26 07:13 - 2009-07-14 12:51 - 00058354 _____ C:\Windows\setupact.log
2015-09-26 06:11 - 2015-04-16 18:48 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-09-26 04:24 - 2015-03-10 20:53 - 00000000 ____D C:\Program Files (x86)\Steam
2015-09-26 00:27 - 2009-07-14 12:45 - 00021248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-09-26 00:27 - 2009-07-14 12:45 - 00021248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-09-25 23:22 - 2015-03-27 22:29 - 00000000 ____D C:\Users\N1kola\AppData\Roaming\Skype
2015-09-25 23:04 - 2015-03-10 15:26 - 00000000 ____D C:\Users\N1kola
2015-09-25 23:04 - 2010-11-21 11:47 - 00263772 _____ C:\Windows\PFRO.log
2015-09-25 21:23 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\tracing
2015-09-25 21:22 - 2015-07-31 02:20 - 00000785 _____ C:\Users\N1kola\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Call of Duty 2 SinglePlayer.lnk
2015-09-25 21:22 - 2015-07-31 02:20 - 00000785 _____ C:\Users\N1kola\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Call of Duty 2 MultiPlayer.lnk
2015-09-25 21:22 - 2015-06-09 19:36 - 00001078 _____ C:\Users\N1kola\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameRanger.lnk
2015-09-25 21:22 - 2015-03-11 10:08 - 00000946 _____ C:\Users\N1kola\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\µTorrent.lnk
2015-09-25 21:22 - 2015-03-10 15:27 - 00001423 _____ C:\Users\N1kola\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-09-25 21:22 - 2015-03-10 15:27 - 00001389 _____ C:\Users\N1kola\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2015-09-25 21:21 - 2015-08-18 18:55 - 00000722 _____ C:\Users\Public\Desktop\MEGAsync.lnk
2015-09-25 21:21 - 2015-08-16 01:29 - 00001814 _____ C:\Users\Public\Desktop\Action!.lnk
2015-09-25 21:21 - 2015-08-16 01:14 - 00000992 _____ C:\Users\N1kola\Desktop\Bandicam.lnk
2015-09-25 21:21 - 2015-08-03 04:39 - 00001085 _____ C:\Users\N1kola\Desktop\Documents - Shortcut.lnk
2015-09-25 21:21 - 2015-07-24 03:25 - 00001151 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-09-25 21:21 - 2015-07-19 19:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mortal Kombat Complete Edition
2015-09-25 21:21 - 2015-06-15 06:42 - 00001362 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
2015-09-25 21:21 - 2015-06-15 06:42 - 00001293 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk
2015-09-25 21:21 - 2015-05-10 05:33 - 00000828 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WWE 2K15.lnk
2015-09-25 21:21 - 2015-04-13 04:20 - 00001132 _____ C:\ProgramData\Microsoft\Windows\Start Menu\BS.Player FREE.lnk
2015-09-25 21:21 - 2015-04-03 20:24 - 00000000 ____D C:\Users\N1kola\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2015-09-25 21:21 - 2015-03-31 01:53 - 00000992 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sniper Elite 3.lnk
2015-09-25 21:21 - 2015-03-27 01:12 - 00000959 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk
2015-09-25 21:21 - 2015-03-19 03:40 - 00001014 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pro Evolution Soccer 2015.lnk
2015-09-25 21:21 - 2015-03-11 01:25 - 00001333 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2015-09-25 21:21 - 2015-03-11 01:24 - 00001314 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2015-09-25 21:21 - 2009-07-14 13:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-09-25 21:21 - 2009-07-14 13:01 - 00001218 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk
2015-09-25 21:21 - 2009-07-14 12:57 - 00001511 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-09-25 21:21 - 2009-07-14 12:57 - 00001292 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
2015-09-25 21:21 - 2009-07-14 12:57 - 00001234 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
2015-09-25 21:21 - 2009-07-14 12:54 - 00001198 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
2015-09-25 21:21 - 2009-07-14 12:49 - 00001246 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk
2015-09-25 21:20 - 2015-08-03 04:29 - 00000000 ___RD C:\Users\N1kola\Desktop\Programi
2015-09-25 21:20 - 2015-04-10 03:10 - 00000000 ____D C:\Program Files (x86)\a3ab2504-f860-4500-a151-da698740bd25
2015-09-25 21:20 - 2015-03-25 01:06 - 00000000 ____D C:\Program Files (x86)\2K Sports
2015-09-25 20:45 - 2015-06-09 23:12 - 00000000 ____D C:\Users\N1kola\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ICCup Launcher
2015-09-25 20:45 - 2009-07-14 11:20 - 00000000 ____D C:\Program Files\Common Files\System
2015-09-25 20:20 - 2015-04-22 23:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Mechanics
2015-09-25 20:20 - 2009-07-14 11:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2015-09-25 17:21 - 2015-05-17 23:31 - 00000000 ____D C:\Program Files (x86)\R.G. Mechanics
2015-09-24 19:32 - 2015-07-15 05:36 - 00000000 ____D C:\Program Files (x86)\F1.2015.FULL.UNLOCKED-RLDGAMES
2015-09-24 19:32 - 2015-03-12 08:40 - 00000000 ____D C:\Users\N1kola\Documents\ConvertXtoDVD
2015-09-24 19:25 - 2015-04-26 19:56 - 00000000 ____D C:\Program Files (x86)\SystemRequirementsLab
2015-09-24 19:23 - 2015-03-10 15:55 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-09-24 17:59 - 2015-03-24 01:18 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2015-09-24 08:29 - 2015-03-10 16:53 - 00000000 ____D C:\Users\N1kola\AppData\Roaming\TS3Client
2015-09-23 22:00 - 2010-11-21 15:16 - 00000000 ___RD C:\Users\Public\Recorded TV
2015-09-23 19:26 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\system32\NDF
2015-09-22 03:11 - 2015-04-16 18:48 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-09-22 03:11 - 2015-04-16 18:48 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-09-22 03:11 - 2015-04-16 18:48 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-09-21 17:45 - 2015-03-22 22:36 - 00001678 _____ C:\Windows\Sandboxie.ini
2015-09-19 16:36 - 2015-03-19 04:00 - 00000000 ____D C:\ProgramData\KONAMI
2015-09-19 16:35 - 2015-03-19 03:55 - 00000000 ____D C:\Users\N1kola\Documents\KONAMI
2015-09-19 16:25 - 2015-03-10 16:12 - 00245346 _____ C:\Windows\DirectX.log
2015-09-19 16:23 - 2015-03-22 20:59 - 00000000 ____D C:\Program Files (x86)\Konami
2015-09-18 23:41 - 2015-03-10 15:31 - 00000000 ____D C:\ProgramData\Package Cache
2015-09-18 23:38 - 2015-04-03 00:58 - 00000000 ___HD C:\Windows\msdownld.tmp
2015-09-18 23:38 - 2015-04-03 00:58 - 00000000 ____D C:\Windows\SysWOW64\directx
2015-09-18 07:30 - 2015-04-13 03:49 - 00000000 ____D C:\Users\N1kola\AppData\Local\Windows Live
2015-09-17 17:12 - 2015-07-17 04:56 - 00003894 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-09-17 17:12 - 2015-07-17 04:56 - 00003642 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-09-17 08:30 - 2015-08-25 20:25 - 00000000 ____D C:\ProgramData\update
2015-09-16 22:43 - 2015-03-10 21:01 - 00000000 ____D C:\Users\N1kola\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2015-09-15 21:20 - 2015-03-10 16:00 - 00000000 ____D C:\Users\N1kola\AppData\Local\Google
2015-09-03 17:41 - 2015-07-24 06:39 - 00000000 ____D C:\Users\N1kola\AppData\Roaming\Enigma Software Group
2015-09-03 03:35 - 2015-04-21 22:14 - 00000000 ____D C:\KMPlayer
2015-09-01 02:39 - 2015-03-11 16:15 - 00000000 ____D C:\Windows\Minidump
2015-08-30 18:11 - 2015-07-24 03:25 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-29 19:25 - 2009-07-14 13:08 - 00032596 _____ C:\Windows\Tasks\SCHEDLGU.TXT

==================== Files in the root of some directories =======

2015-07-16 06:30 - 2015-07-16 06:30 - 6420480 _____ () C:\Program Files (x86)\GUT8756.tmp
2015-08-07 02:36 - 2015-08-07 02:36 - 0327984 _____ (Microsoft Corporation) C:\Users\N1kola\AppData\Roaming\appraiserxp.dll
2015-08-26 21:02 - 2015-08-26 21:02 - 0008277 _____ () C:\Users\N1kola\AppData\Roaming\BlockSoftareList.json
2015-03-27 03:14 - 2015-03-27 03:14 - 0005542 _____ () C:\Users\N1kola\AppData\Roaming\ERUKVJ
2015-07-16 05:35 - 2015-07-16 05:35 - 0330032 _____ (Microsoft Corporation) C:\Users\N1kola\AppData\Roaming\GetCurrentDeploy.dll
2015-03-11 17:32 - 2015-03-20 04:17 - 0099384 _____ () C:\Users\N1kola\AppData\Roaming\inst.exe
2015-03-27 03:14 - 2015-03-27 03:14 - 0005542 _____ () C:\Users\N1kola\AppData\Roaming\MOFLXU
2015-03-11 17:32 - 2015-03-20 04:17 - 0007859 _____ () C:\Users\N1kola\AppData\Roaming\pcouffin.cat
2015-03-11 17:32 - 2015-03-20 04:17 - 0001167 _____ () C:\Users\N1kola\AppData\Roaming\pcouffin.inf
2015-03-11 17:32 - 2015-03-20 04:17 - 0000055 _____ () C:\Users\N1kola\AppData\Roaming\pcouffin.log
2015-03-11 17:32 - 2015-03-20 04:17 - 0082816 _____ (VSO Software) C:\Users\N1kola\AppData\Roaming\pcouffin.sys
2015-08-26 21:02 - 2015-08-26 21:02 - 0465248 _____ (Tencent) C:\Users\N1kola\AppData\Roaming\QMNetWorkMgr.dll
2015-06-03 01:12 - 2015-06-03 01:12 - 0709424 _____ (Microsoft Corporation) C:\Users\N1kola\AppData\Roaming\wimgapi.dll
2015-08-26 21:02 - 2015-08-26 21:02 - 1259872 _____ (Tencent) C:\Users\N1kola\AppData\Roaming\Win10TipsCfg.dll
2015-06-03 01:12 - 2015-06-03 01:12 - 0125744 _____ (Microsoft Corporation) C:\Users\N1kola\AppData\Roaming\xmllite.dll
2015-04-13 03:58 - 2015-04-13 03:59 - 0004608 _____ () C:\Users\N1kola\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-03-22 21:19 - 2015-03-22 21:19 - 0000003 _____ () C:\Users\N1kola\AppData\Local\updater.log
2015-03-22 21:19 - 2015-05-09 18:11 - 0000424 _____ () C:\Users\N1kola\AppData\Local\UserProducts.xml
2015-08-25 20:25 - 2015-08-25 20:25 - 0000124 _____ () C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat

Files to move or delete:
====================
C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat


Some files in TEMP:
====================
C:\Users\N1kola\AppData\Local\Temp\360Inst_sohuyy.exe
C:\Users\N1kola\AppData\Local\Temp\bdcam64_0.dll
C:\Users\N1kola\AppData\Local\Temp\bdcam64_1.dll
C:\Users\N1kola\AppData\Local\Temp\bdfilters.dll
C:\Users\N1kola\AppData\Local\Temp\BingBarSetup-Partner.exe
C:\Users\N1kola\AppData\Local\Temp\CojLauncher.exe
C:\Users\N1kola\AppData\Local\Temp\downloader.dll
C:\Users\N1kola\AppData\Local\Temp\drm_dialogs.dll
C:\Users\N1kola\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmphm4uwj.dll
C:\Users\N1kola\AppData\Local\Temp\EsgInstallerx64Stub.exe
C:\Users\N1kola\AppData\Local\Temp\genteert.dll
C:\Users\N1kola\AppData\Local\Temp\gjdatareport.dll
C:\Users\N1kola\AppData\Local\Temp\install1213087.exe
C:\Users\N1kola\AppData\Local\Temp\jre-8u45-windows-au.exe
C:\Users\N1kola\AppData\Local\Temp\KMPAddedCode_KMP_adpageopen_Step1.exe
C:\Users\N1kola\AppData\Local\Temp\mfc110u.dll
C:\Users\N1kola\AppData\Local\Temp\msvcp110.dll
C:\Users\N1kola\AppData\Local\Temp\msvcr110.dll
C:\Users\N1kola\AppData\Local\Temp\OnlineWeatherSetup.exe
C:\Users\N1kola\AppData\Local\Temp\ose00000.exe
C:\Users\N1kola\AppData\Local\Temp\qqpcmgr_v10.10.16434.218_45080_Silence.exe
C:\Users\N1kola\AppData\Local\Temp\SandboxieInstall.exe
C:\Users\N1kola\AppData\Local\Temp\Skin.dll
C:\Users\N1kola\AppData\Local\Temp\Social%20Club%20v1.1.6.1%20Setup.exe
C:\Users\N1kola\AppData\Local\Temp\SoHuVA_4.2.0.16-c20762-ng-nti-s-tp-x.exe
C:\Users\N1kola\AppData\Local\Temp\SpOrder.dll
C:\Users\N1kola\AppData\Local\Temp\sqlite3.dll
C:\Users\N1kola\AppData\Local\Temp\SRLDetectionLibrary7139661488652000504.dll
C:\Users\N1kola\AppData\Local\Temp\SRLDetectionLibrary7205297484220954437.dll
C:\Users\N1kola\AppData\Local\Temp\tu17p84.exe
C:\Users\N1kola\AppData\Local\Temp\ubi1892.tmp.exe
C:\Users\N1kola\AppData\Local\Temp\Uninstall.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-09-21 23:49

==================== End of FRST.txt ============================

offline
  • Research Engineer @MalwareBytes
  • Pridružio: 09 Avg 2011
  • Poruke: 15877
  • Gde živiš: Beograd

Hajde jos nesto da probamo:


1. Otvori Notepad (Text Document) i iskopiraj sledeći tekst unutar kod polja ispod:

createrestorepoint:
closeprocesses:
emptytemp:
Task: {0F83CDE7-C063-40E5-B38B-6562BB6ACFDF} - System32\Tasks\{68AA565D-B69F-4596-853F-C97F349E517C} => pcalua.exe -a C:\Users\N1kola\AppData\Roaming\oursurfing\UninstallManager.exe -c  -ptid=amt
Task: {FFF1CEAB-F64A-419C-B47C-572D095ABD02} - System32\Tasks\Fruit => Rundll32.exe "C:\Users\N1kola\AppData\Local\Fruit\Bin\Fruit.dll",#3
AlternateDataStreams: C:\Users\N1kola\Downloads\Beogradski Sindikat - Svedok (saradnik) 2010 Tekst Video.mp3.crdownload (mp3cut.net).mp3:TOC.WMV
AlternateDataStreams: C:\Users\N1kola\Downloads\F4 - Rep i Grad (2010) Tekst (mp3cut.net).mp3:TOC.WMV
HKU\S-1-5-21-2202714847-2926606003-1158938094-1000\...\MountPoints2: {029cffd4-d21f-11e4-8977-b8975a6ec3eb} - G:\setup.exe
HKU\S-1-5-21-2202714847-2926606003-1158938094-1000\...\MountPoints2: {1d28a83a-f2a9-11e4-8ebf-b8975a6ec3eb} - H:\setup.exe
HKU\S-1-5-21-2202714847-2926606003-1158938094-1000\...\MountPoints2: {b0c1268b-c6fc-11e4-930a-b8975a6ec3eb} - F:\Autorun.exe
HKU\S-1-5-21-2202714847-2926606003-1158938094-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.yahoo.com/?fr=vmn&type=vmn__webcompa__1_0__ya__hp_WCYID10099_swoc_campaign_150421__yaie
HKU\S-1-5-21-2202714847-2926606003-1158938094-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
SearchScopes: HKU\S-1-5-21-2202714847-2926606003-1158938094-1000 -> DefaultScope {C0C3A6C6-03BC-4195-8FCB-AEA091301353} URL =
FF DefaultSearchEngine: oursurfing
C:\Users\N1kola\AppData\Roaming\oursurfing
CHR DefaultSearchURL: Default -> hxxp://musixlib.searchalgo.com/search/?category=web&s=amds&q={searchTerms}
CHR DefaultSearchKeyword: Default -> MusixLib Search
CHR DefaultSuggestURL: Default -> hxxp://sug.searchalgo.com/search/index_sg.php?q={searchTerms}
S2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S3 EsgScanner; system32\DRIVERS\EsgScanner.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat

2015-07-16 06:30 - 2015-07-16 06:30 - 6420480 _____ () C:\Program Files (x86)\GUT8756.tmp
2015-08-07 02:36 - 2015-08-07 02:36 - 0327984 _____ (Microsoft Corporation) C:\Users\N1kola\AppData\Roaming\appraiserxp.dll
2015-08-26 21:02 - 2015-08-26 21:02 - 0008277 _____ () C:\Users\N1kola\AppData\Roaming\BlockSoftareList.json
2015-03-27 03:14 - 2015-03-27 03:14 - 0005542 _____ () C:\Users\N1kola\AppData\Roaming\ERUKVJ
2015-07-16 05:35 - 2015-07-16 05:35 - 0330032 _____ (Microsoft Corporation) C:\Users\N1kola\AppData\Roaming\GetCurrentDeploy.dll
2015-03-11 17:32 - 2015-03-20 04:17 - 0099384 _____ () C:\Users\N1kola\AppData\Roaming\inst.exe
2015-03-27 03:14 - 2015-03-27 03:14 - 0005542 _____ () C:\Users\N1kola\AppData\Roaming\MOFLXU
2015-03-11 17:32 - 2015-03-20 04:17 - 0007859 _____ () C:\Users\N1kola\AppData\Roaming\pcouffin.cat
2015-03-11 17:32 - 2015-03-20 04:17 - 0001167 _____ () C:\Users\N1kola\AppData\Roaming\pcouffin.inf
2015-03-11 17:32 - 2015-03-20 04:17 - 0000055 _____ () C:\Users\N1kola\AppData\Roaming\pcouffin.log
2015-03-11 17:32 - 2015-03-20 04:17 - 0082816 _____ (VSO Software) C:\Users\N1kola\AppData\Roaming\pcouffin.sys
2015-08-26 21:02 - 2015-08-26 21:02 - 0465248 _____ (Tencent) C:\Users\N1kola\AppData\Roaming\QMNetWorkMgr.dll
2015-06-03 01:12 - 2015-06-03 01:12 - 0709424 _____ (Microsoft Corporation) C:\Users\N1kola\AppData\Roaming\wimgapi.dll
2015-08-26 21:02 - 2015-08-26 21:02 - 1259872 _____ (Tencent) C:\Users\N1kola\AppData\Roaming\Win10TipsCfg.dll
2015-06-03 01:12 - 2015-06-03 01:12 - 0125744 _____ (Microsoft Corporation) C:\Users\N1kola\AppData\Roaming\xmllite.dll
2015-04-13 03:58 - 2015-04-13 03:59 - 0004608 _____ () C:\Users\N1kola\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-03-22 21:19 - 2015-03-22 21:19 - 0000003 _____ () C:\Users\N1kola\AppData\Local\updater.log
2015-03-22 21:19 - 2015-05-09 18:11 - 0000424 _____ () C:\Users\N1kola\AppData\Local\UserProducts.xml
2015-08-25 20:25 - 2015-08-25 20:25 - 0000124 _____ () C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat


2. Sačuvaj notepad na Desktop pod nazivom fixlist.txt
To možes uraditi i iz notepad-a => klik na File potom na Save As i u novom prozoru, dole pod File Name: staviš za naziv fixlist.txt
Napomena: Važno je da se oba fajla, FRST i fixlist nalaze na istoj lokaciji jer u suprotnom fix nece raditi.

3. Ponovo pokreni FRST/FRST64, klikni jednom na dugme Fix i sačekaj.
Ukoliko alat zatraži restart sistema, dozvoli mu i postaraj se da alat kompletira fix nakon restarta sistema.



Alat će formirati log (Fixlog.txt) na Desktop-u. Potrebno je sadržaj tog loga iskopirati u poruku.
Napomena: Ukoliko te alat upozori da postoji novija verzija, postaraj se da preuzmes i koristiš ažuriranu kopiju FRST-a.




Takodje sam primetio neke probleme sa Avastom, pa bi najbolje bilo da ga za sada uklonimo dok ne utvrdimo sta se desava.

Isprati ovo uputstvo da obrises Avast:

https://www.avast.com/uninstall-utility

offline
  • Pridružio: 09 Jun 2015
  • Poruke: 56

evo fajl od first ( mycity.rs/must-login.png ) i deinstalirao sam avast





Fix result of Farbar Recovery Scan Tool (x64) Version:23-09-2015
Ran by N1kola (2015-09-26 20:03:51) Run:1
Running from C:\Users\N1kola\Desktop
Loaded Profiles: N1kola (Available Profiles: N1kola)
Boot Mode: Normal
==============================================

fixlist content:
*****************
createrestorepoint:
closeprocesses:
emptytemp:
Task: {0F83CDE7-C063-40E5-B38B-6562BB6ACFDF} - System32\Tasks\{68AA565D-B69F-4596-853F-C97F349E517C} => pcalua.exe -a C:\Users\N1kola\AppData\Roaming\oursurfing\UninstallManager.exe -c -ptid=amt
Task: {FFF1CEAB-F64A-419C-B47C-572D095ABD02} - System32\Tasks\Fruit => Rundll32.exe "C:\Users\N1kola\AppData\Local\Fruit\Bin\Fruit.dll",#3
AlternateDataStreams: C:\Users\N1kola\Downloads\Beogradski Sindikat - Svedok (saradnik) 2010 Tekst Video.mp3.crdownload (mp3cut.net).mp3:TOC.WMV
AlternateDataStreams: C:\Users\N1kola\Downloads\F4 - Rep i Grad (2010) Tekst (mp3cut.net).mp3:TOC.WMV
HKU\S-1-5-21-2202714847-2926606003-1158938094-1000\...\MountPoints2: {029cffd4-d21f-11e4-8977-b8975a6ec3eb} - G:\setup.exe
HKU\S-1-5-21-2202714847-2926606003-1158938094-1000\...\MountPoints2: {1d28a83a-f2a9-11e4-8ebf-b8975a6ec3eb} - H:\setup.exe
HKU\S-1-5-21-2202714847-2926606003-1158938094-1000\...\MountPoints2: {b0c1268b-c6fc-11e4-930a-b8975a6ec3eb} - F:\Autorun.exe
HKU\S-1-5-21-2202714847-2926606003-1158938094-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.yahoo.com/?fr=vmn&type=vmn__webcompa__1_0__ya__hp_WCYID10099_swoc_campaign_150421__yaie
HKU\S-1-5-21-2202714847-2926606003-1158938094-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
SearchScopes: HKU\S-1-5-21-2202714847-2926606003-1158938094-1000 -> DefaultScope {C0C3A6C6-03BC-4195-8FCB-AEA091301353} URL =
FF DefaultSearchEngine: oursurfing
C:\Users\N1kola\AppData\Roaming\oursurfing
CHR DefaultSearchURL: Default -> hxxp://musixlib.searchalgo.com/search/?category=web&s=amds&q={searchTerms}
CHR DefaultSearchKeyword: Default -> MusixLib Search
CHR DefaultSuggestURL: Default -> hxxp://sug.searchalgo.com/search/index_sg.php?q={searchTerms}
S2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S3 EsgScanner; system32\DRIVERS\EsgScanner.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat

2015-07-16 06:30 - 2015-07-16 06:30 - 6420480 _____ () C:\Program Files (x86)\GUT8756.tmp
2015-08-07 02:36 - 2015-08-07 02:36 - 0327984 _____ (Microsoft Corporation) C:\Users\N1kola\AppData\Roaming\appraiserxp.dll
2015-08-26 21:02 - 2015-08-26 21:02 - 0008277 _____ () C:\Users\N1kola\AppData\Roaming\BlockSoftareList.json
2015-03-27 03:14 - 2015-03-27 03:14 - 0005542 _____ () C:\Users\N1kola\AppData\Roaming\ERUKVJ
2015-07-16 05:35 - 2015-07-16 05:35 - 0330032 _____ (Microsoft Corporation) C:\Users\N1kola\AppData\Roaming\GetCurrentDeploy.dll
2015-03-11 17:32 - 2015-03-20 04:17 - 0099384 _____ () C:\Users\N1kola\AppData\Roaming\inst.exe
2015-03-27 03:14 - 2015-03-27 03:14 - 0005542 _____ () C:\Users\N1kola\AppData\Roaming\MOFLXU
2015-03-11 17:32 - 2015-03-20 04:17 - 0007859 _____ () C:\Users\N1kola\AppData\Roaming\pcouffin.cat
2015-03-11 17:32 - 2015-03-20 04:17 - 0001167 _____ () C:\Users\N1kola\AppData\Roaming\pcouffin.inf
2015-03-11 17:32 - 2015-03-20 04:17 - 0000055 _____ () C:\Users\N1kola\AppData\Roaming\pcouffin.log
2015-03-11 17:32 - 2015-03-20 04:17 - 0082816 _____ (VSO Software) C:\Users\N1kola\AppData\Roaming\pcouffin.sys
2015-08-26 21:02 - 2015-08-26 21:02 - 0465248 _____ (Tencent) C:\Users\N1kola\AppData\Roaming\QMNetWorkMgr.dll
2015-06-03 01:12 - 2015-06-03 01:12 - 0709424 _____ (Microsoft Corporation) C:\Users\N1kola\AppData\Roaming\wimgapi.dll
2015-08-26 21:02 - 2015-08-26 21:02 - 1259872 _____ (Tencent) C:\Users\N1kola\AppData\Roaming\Win10TipsCfg.dll
2015-06-03 01:12 - 2015-06-03 01:12 - 0125744 _____ (Microsoft Corporation) C:\Users\N1kola\AppData\Roaming\xmllite.dll
2015-04-13 03:58 - 2015-04-13 03:59 - 0004608 _____ () C:\Users\N1kola\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-03-22 21:19 - 2015-03-22 21:19 - 0000003 _____ () C:\Users\N1kola\AppData\Local\updater.log
2015-03-22 21:19 - 2015-05-09 18:11 - 0000424 _____ () C:\Users\N1kola\AppData\Local\UserProducts.xml
2015-08-25 20:25 - 2015-08-25 20:25 - 0000124 _____ () C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
*****************

Restore point was successfully created.
Processes closed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0F83CDE7-C063-40E5-B38B-6562BB6ACFDF}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0F83CDE7-C063-40E5-B38B-6562BB6ACFDF}" => key removed successfully
C:\Windows\System32\Tasks\{68AA565D-B69F-4596-853F-C97F349E517C} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{68AA565D-B69F-4596-853F-C97F349E517C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FFF1CEAB-F64A-419C-B47C-572D095ABD02}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FFF1CEAB-F64A-419C-B47C-572D095ABD02}" => key removed successfully
C:\Windows\System32\Tasks\Fruit => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Fruit" => key removed successfully
C:\Users\N1kola\Downloads\Beogradski Sindikat - Svedok (saradnik) 2010 Tekst Video.mp3.crdownload (mp3cut.net).mp3 => ":TOC.WMV" ADS removed successfully.
C:\Users\N1kola\Downloads\F4 - Rep i Grad (2010) Tekst (mp3cut.net).mp3 => ":TOC.WMV" ADS removed successfully.
"HKU\S-1-5-21-2202714847-2926606003-1158938094-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{029cffd4-d21f-11e4-8977-b8975a6ec3eb}" => key removed successfully
HKCR\CLSID\{029cffd4-d21f-11e4-8977-b8975a6ec3eb} => key not found.
"HKU\S-1-5-21-2202714847-2926606003-1158938094-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1d28a83a-f2a9-11e4-8ebf-b8975a6ec3eb}" => key removed successfully
HKCR\CLSID\{1d28a83a-f2a9-11e4-8ebf-b8975a6ec3eb} => key not found.
"HKU\S-1-5-21-2202714847-2926606003-1158938094-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b0c1268b-c6fc-11e4-930a-b8975a6ec3eb}" => key removed successfully
HKCR\CLSID\{b0c1268b-c6fc-11e4-930a-b8975a6ec3eb} => key not found.
HKU\S-1-5-21-2202714847-2926606003-1158938094-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKU\S-1-5-21-2202714847-2926606003-1158938094-1000\Software\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache => value removed successfully
HKU\S-1-5-21-2202714847-2926606003-1158938094-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
Firefox DefaultSearchEngine removed successfully
"C:\Users\N1kola\AppData\Roaming\oursurfing" => File/Folder not found.
Chrome DefaultSearchURL removed successfully
Chrome DefaultSearchKeyword removed successfully
Chrome DefaultSuggestURL removed successfully
SpyHunter 4 Service => service removed successfully
EagleX64 => service removed successfully
esgiguard => service removed successfully
EsgScanner => service removed successfully
VGPU => service removed successfully
C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat => moved successfully
C:\Program Files (x86)\GUT8756.tmp => moved successfully
C:\Users\N1kola\AppData\Roaming\appraiserxp.dll => moved successfully
C:\Users\N1kola\AppData\Roaming\BlockSoftareList.json => moved successfully
C:\Users\N1kola\AppData\Roaming\ERUKVJ => moved successfully
C:\Users\N1kola\AppData\Roaming\GetCurrentDeploy.dll => moved successfully
C:\Users\N1kola\AppData\Roaming\inst.exe => moved successfully
C:\Users\N1kola\AppData\Roaming\MOFLXU => moved successfully
C:\Users\N1kola\AppData\Roaming\pcouffin.cat => moved successfully
C:\Users\N1kola\AppData\Roaming\pcouffin.inf => moved successfully
C:\Users\N1kola\AppData\Roaming\pcouffin.log => moved successfully
C:\Users\N1kola\AppData\Roaming\pcouffin.sys => moved successfully
C:\Users\N1kola\AppData\Roaming\QMNetWorkMgr.dll => moved successfully
C:\Users\N1kola\AppData\Roaming\wimgapi.dll => moved successfully
C:\Users\N1kola\AppData\Roaming\Win10TipsCfg.dll => moved successfully
C:\Users\N1kola\AppData\Roaming\xmllite.dll => moved successfully
C:\Users\N1kola\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini => moved successfully
C:\Users\N1kola\AppData\Local\updater.log => moved successfully
C:\Users\N1kola\AppData\Local\UserProducts.xml => moved successfully
"C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat" => File/Folder not found.
EmptyTemp: => 23.1 GB temporary data Removed.


The system needed a reboot..

==== End of Fixlog 20:09:11 ====

offline
  • Research Engineer @MalwareBytes
  • Pridružio: 09 Avg 2011
  • Poruke: 15877
  • Gde živiš: Beograd

Odlicno. Javi mi ako se opet desi restart, racunar bi trebao biti cist sada.

offline
  • Pridružio: 22 Apr 2015
  • Poruke: 4

restartovao se jednom, mozda zvuci glupo ali kao da se restartuje kad se ohladi, ja sam oko 2sata vremenski igrao mad max i nije se restartovao ali kad sam otisao do grada i vratio se proslo je nekih sat i pomerio misa da se upali ekran usao sam u igricu in se tad restartovao i evo sad vec pola sata radi...

offline
  • Research Engineer @MalwareBytes
  • Pridružio: 09 Avg 2011
  • Poruke: 15877
  • Gde živiš: Beograd

Da li si mozda proveravao temperature?

Program za te stvari --> http://www.cpuid.com/softwares/hwmonitor.html

Ko je trenutno na forumu
 

Ukupno su 706 korisnika na forumu :: 42 registrovanih, 8 sakrivenih i 656 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: _Petar, _Sale, A.R.Chafee.Jr., babaroga, bato, crnitrn, DJORDJE-NO-1, Dorcolac, dragon986, FOX, goxin, Haryy, havoc995, ikan, ILGromovnik, madza, Mahovljani, manda87, meelosh64, Mercury, Milan A. Nikolic, Misirac, mrkanidja, neutralal.com, Panonsky, pein, repac, RJ, S-lash, Singidunumac, Sirius, Snorks, Srki94, ssekir75, suton, t.mile, theNedjeljko, tmanda323, Toni, vasa.93, vathra, VJ