Poslao: 11 Jul 2016 20:20
|
offline
- LoXo
- Super građanin
- Pridružio: 14 Okt 2011
- Poruke: 1212
|
Napisano: 11 Jul 2016 21:16
Mali brat je sa torenta skidao neke (film-za-odrasle)-ice i navukao mi adware na chrome...
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 10-07-2016 01
Ran by LoxoSRB (administrator) on LOXOSRB-PC (11-07-2016 21:14:19)
Running from C:\Users\LoxoSRB\Downloads
Loaded Profiles: LoxoSRB (Available Profiles: LoxoSRB & UpdatusUser)
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-t.....scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
() D:\Acunetix\Web Vulnerability Scanner 8\WVSScheduler.exe
() C:\Program Files\Gramblr\gramblr.exe
(Skillbrains) C:\Program Files\Skillbrains\lightshot\5.3.0.0\Lightshot.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [91520 2010-01-21] (Microsoft Corporation)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2011-10-24] (Apple Inc.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM\...\Run: [Lightshot] => C:\Program Files\Skillbrains\lightshot\Lightshot.exe [226560 2014-11-18] ()
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [596528 2015-11-09] (Oracle Corporation)
HKU\S-1-5-21-937694239-2368957015-2011986524-1000\...\Run: [LightShot] => C:\Users\LoxoSRB\AppData\Local\Skillbrains\lightshot\Lightshot.exe
HKU\S-1-5-21-937694239-2368957015-2011986524-1000\...\Run: [BitTorrent] => C:\Users\LoxoSRB\AppData\Roaming\BitTorrent\BitTorrent.exe [1972232 2016-05-20] (BitTorrent Inc.)
HKU\S-1-5-21-937694239-2368957015-2011986524-1000\...\Run: [DAEMON Tools Lite] => E:\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd)
HKU\S-1-5-21-937694239-2368957015-2011986524-1000\...\Run: [CyberGhost] => "C:\Program Files\CyberGhost 5\CyberGhost.exe" /autostart /min
HKU\S-1-5-21-937694239-2368957015-2011986524-1000\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-937694239-2368957015-2011986524-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-937694239-2368957015-2011986524-1000\...\MountPoints2: {1de478ab-1c03-11e4-a6ac-0019dbf2f5ee} - L:\AutoRun.exe {D2D77DC2-8299-11D1-8949-444553540000} 5.2066.1.A11B02 PID_0083
HKU\S-1-5-21-937694239-2368957015-2011986524-1000\...\MountPoints2: {84eae620-fa9a-11e5-9390-0019dbf2f5ee} - G:\Lenovo_Suite.exe
HKU\S-1-5-21-937694239-2368957015-2011986524-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [878592 2010-11-20] (Microsoft Corporation)
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2013-06-16] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
Startup: C:\Users\LoxoSRB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\specvrme.vbs [2016-05-30] ()
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog9 01 C:\Windows\system32\sslsp104.dll [74352 2013-06-21] (SumRando)
Winsock: Catalog9 02 C:\Windows\system32\sslsp104.dll [74352 2013-06-21] (SumRando)
Winsock: Catalog9 13 C:\Windows\system32\sslsp104.dll [74352 2013-06-21] (SumRando)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 89.216.1.40 89.216.1.50
Tcpip\..\Interfaces\{898D954E-5D5E-49F9-A299-89C0925EAA79}: [DhcpNameServer] 89.216.1.40 89.216.1.50
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
SearchScopes: HKLM -> DefaultScope value is missing
BHO: Adobe PDF Reader Link Helper -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2012-09-23] (Adobe Systems Incorporated)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2010-01-21] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_66\bin\ssv.dll [2015-12-09] (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-01-16] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-12-09] (Oracle Corporation)
FireFox:
========
FF ProfilePath: C:\Users\LoxoSRB\AppData\Roaming\Mozilla\Firefox\Profiles\822m2evv.default
FF NetworkProxy: "backup.ftp", "36.72.66.68"
FF NetworkProxy: "backup.ftp_port", 8080
FF NetworkProxy: "backup.socks", "36.72.66.68"
FF NetworkProxy: "backup.socks_port", 8080
FF NetworkProxy: "backup.ssl", "36.72.66.68"
FF NetworkProxy: "backup.ssl_port", 8080
FF NetworkProxy: "ftp", "202.182.55.10"
FF NetworkProxy: "ftp_port", 8081
FF NetworkProxy: "http", "202.182.55.10"
FF NetworkProxy: "http_port", 8081
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks", "202.182.55.10"
FF NetworkProxy: "socks_port", 8081
FF NetworkProxy: "ssl", "202.182.55.10"
FF NetworkProxy: "ssl_port", 8081
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-25] ()
FF Plugin: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-12-09] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-12-09] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL [2010-01-10] (Microsoft Corporation)
FF Plugin: @pandonetworks.com/PandoWebPlugin -> C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll [No File]
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-11] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-11] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> D:\VLC\npvlc.dll [2014-02-05] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-09-12] (Adobe Systems Inc.)
Chrome:
=======
CHR Plugin: (Shockwave Flash) - C:\Users\LoxoSRB\AppData\Local\Google\Chrome\User Data\PepperFlash\11.7.700.225\pepflashplayer.dll => No File
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\51.0.2704.103\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\51.0.2704.103\pdf.dll => No File
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll => No File
CHR Plugin: (npAPI Plugin) - C:\Users\LoxoSRB\AppData\Local\TNT2\2.0.0.1534\npTNT2.dll => No File
CHR Plugin: (npAPI Ghost Plugin) - C:\Users\LoxoSRB\AppData\Local\TNT2\2.0.0.1534\npTNT2ghost.dll => No File
CHR Plugin: (Java Deployment Toolkit 7.0.210.11) - C:\Windows\system32\npDeployJava1.dll => No File
CHR Plugin: (Java(TM) Platform SE 7 U21) - E:\Java\bin\plugin2\npjp2.dll => No File
CHR Profile: C:\Users\LoxoSRB\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (HTML5 Banner Maker) - C:\Users\LoxoSRB\AppData\Local\Google\Chrome\User Data\Default\Extensions\abmkmgbpbcmoomenlldbdnjmfhcmonag [2013-07-06]
CHR Extension: (Textcraft) - C:\Users\LoxoSRB\AppData\Local\Google\Chrome\User Data\Default\Extensions\alkilhboimleigdblhagakfnfdalebbm [2013-07-06]
CHR Extension: (Google диск) - C:\Users\LoxoSRB\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-22]
CHR Extension: (Adblock Plus) - C:\Users\LoxoSRB\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-06-30]
CHR Extension: (Toolkit For Facebook) - C:\Users\LoxoSRB\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcachklhcihfinmagjnlomehfdhndhep [2016-07-08]
CHR Extension: (Creately - Online Diagramming) - C:\Users\LoxoSRB\AppData\Local\Google\Chrome\User Data\Default\Extensions\figjjaggcjcojopflaabmebmocabdglm [2013-07-06]
CHR Extension: (HTML5 Banner Maker by TweenUI) - C:\Users\LoxoSRB\AppData\Local\Google\Chrome\User Data\Default\Extensions\hioegghdmpcchhfdcbkldeiobkahllhg [2016-04-14]
CHR Extension: (SnapPages) - C:\Users\LoxoSRB\AppData\Local\Google\Chrome\User Data\Default\Extensions\iedpncdncgcneohjpggphlkhjofphgkf [2013-11-15]
CHR Extension: (Sumo.Fm) - C:\Users\LoxoSRB\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpbphlbiljhndljcmaaajibocclcdmbb [2013-07-06]
CHR Extension: (Download Fonts) - C:\Users\LoxoSRB\AppData\Local\Google\Chrome\User Data\Default\Extensions\lgmjfmdomlhhodhmmfaomfbbdadpeefk [2013-07-06]
CHR Extension: (Google провера поште) - C:\Users\LoxoSRB\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2013-06-29]
CHR Extension: (Text Logo Maker) - C:\Users\LoxoSRB\AppData\Local\Google\Chrome\User Data\Default\Extensions\mocbgbekdcklalbipkekjlhphchgnddm [2015-12-31]
CHR Extension: (Плаћања у Chrome веб-продавници) - C:\Users\LoxoSRB\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-14]
CHR Extension: (Autodesk 123D Make) - C:\Users\LoxoSRB\AppData\Local\Google\Chrome\User Data\Default\Extensions\pcbnagfoedaclggcfcoodicggmnlhajl [2013-07-06]
CHR Extension: (Cacoo - Crtanje dijagrama & kolaboracija u realnom vremenu) - C:\Users\LoxoSRB\AppData\Local\Google\Chrome\User Data\Default\Extensions\pcflmbddgcmomcfngehfhlajjapabojh [2015-09-24]
CHR Extension: (Facebook friend inviter!) - D:\facebook invite [2016-01-01]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AcuWVSSchedulerv8; D:\Acunetix\Web Vulnerability Scanner 8\WVSScheduler.exe [1009840 2012-07-04] ()
R2 gramblrclient; C:\Program Files\Gramblr\gramblr.exe [7324752 2016-07-01] () [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [X]
S2 Update service; C:\Program Files\Popcorn Time\Updater.exe [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 Apowersoft_AudioDevice; C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [26032 2014-04-09] (Wondershare)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2013-06-17] (DT Soft Ltd)
S3 mirrorv3; C:\Windows\System32\DRIVERS\rminiv3.sys [3328 2009-10-09] (Famatech International Corp.)
S3 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
S1 prodrv06; C:\Windows\System32\drivers\prodrv06.sys [53920 2004-08-09] (Protection Technology) [File not signed]
S0 prohlp02; C:\Windows\System32\drivers\prohlp02.sys [114016 2004-08-09] (Protection Technology) [File not signed]
S0 prosync1; C:\Windows\System32\drivers\prosync1.sys [7040 2004-07-19] (Protection Technology) [File not signed]
S0 sfhlp01; C:\Windows\System32\drivers\sfhlp01.sys [4832 2003-12-01] (Protection Technology) [File not signed]
R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [18624 2014-06-04] (IObit)
S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [35288 2013-08-22] (The OpenVPN Project)
S3 tun3326; C:\Windows\System32\DRIVERS\tun3326.sys [30392 2013-03-22] (The OpenVPN Project)
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 vmci; \SystemRoot\system32\DRIVERS\vmci.sys [X]
S3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-07-11 21:14 - 2016-07-11 21:15 - 00013737 _____ C:\Users\LoxoSRB\Downloads\FRST.txt
2016-07-11 21:14 - 2016-07-11 21:14 - 00000000 ____D C:\FRST
2016-07-11 21:13 - 2016-07-11 21:14 - 01741312 _____ (Farbar) C:\Users\LoxoSRB\Downloads\FRST.exe
2016-07-11 20:44 - 2016-07-11 20:44 - 00000000 ____D C:\Users\LoxoSRB\AppData\LocalLow\BitTorrent
2016-07-11 20:22 - 2016-07-11 20:22 - 00000000 ____D C:\ProgramData\boost_interprocess
2016-07-11 20:21 - 2016-07-11 20:22 - 00000000 ____D C:\Users\LoxoSRB\AppData\Roaming\SpringFiles
2016-07-11 13:59 - 2016-07-11 14:02 - 00000000 ____D C:\Users\LoxoSRB\Desktop\sns novo
2016-07-10 23:42 - 2016-03-16 09:59 - 01299356 _____ C:\Users\LoxoSRB\Desktop\Amazon Video Cash PDF.pdf
2016-07-10 15:57 - 2016-07-10 16:16 - 00000000 ____D C:\Users\LoxoSRB\Desktop\New folder (2)
2016-07-09 23:34 - 2016-07-09 23:34 - 02692748 _____ C:\Users\LoxoSRB\Downloads\IZF.rar
2016-07-07 22:55 - 2016-07-07 22:55 - 00186210 _____ C:\Users\LoxoSRB\Downloads\list.txt
2016-07-01 18:12 - 2016-07-11 20:49 - 00000000 ____D C:\Users\LoxoSRB\AppData\Local\2K Games
2016-07-01 18:12 - 2016-07-01 18:12 - 00000000 ____D C:\Program Files\AGEIA Technologies
2016-07-01 18:10 - 2016-07-01 18:10 - 00000000 ____D C:\Windows\3F5C371F8EA24F259D3DD0B4526E3AEA.TMP
2016-07-01 16:59 - 2016-07-01 17:00 - 00000000 ____D C:\Program Files\Gramblr
2016-06-29 21:11 - 2016-06-29 21:11 - 00000201 _____ C:\Users\LoxoSRB\Desktop\PAYDAY The Heist.url
2016-06-26 01:11 - 2016-06-26 01:11 - 00000202 _____ C:\Users\LoxoSRB\Desktop\Brawlhalla.url
2016-06-25 20:22 - 2016-06-25 20:37 - 00000000 ____D C:\Users\LoxoSRB\Desktop\New folder
2016-06-24 18:23 - 2016-06-24 18:23 - 00000000 ____D C:\Users\LoxoSRB\Downloads\i
2016-06-21 22:29 - 2016-06-21 22:29 - 00000000 ____D C:\Users\LoxoSRB\Desktop\ssk
2016-06-21 19:22 - 2016-06-21 19:22 - 00000000 _____ C:\Windows\system32\atiicdxx.dat
2016-06-21 19:22 - 2016-06-21 19:22 - 00000000 _____ C:\Windows\ativpsrm.bin
2016-06-21 11:26 - 2016-06-21 11:26 - 00000662 _____ C:\Users\Public\Desktop\Speccy.lnk
2016-06-21 11:26 - 2016-06-21 11:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
2016-06-17 23:28 - 2016-06-17 23:28 - 00000000 ____D C:\Users\LoxoSRB\Documents\League of Legends
2016-06-17 21:15 - 2016-06-17 21:15 - 00000000 ____D C:\Program Files\Speccy
2016-06-17 21:07 - 2016-06-17 21:07 - 00001503 _____ C:\Users\Public\Desktop\League of Legends.lnk
2016-06-17 21:07 - 2016-06-17 21:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends
2016-06-15 17:06 - 2016-06-15 17:06 - 00000170 _____ C:\Users\LoxoSRB\Desktop\auto add friends fb.txt
2016-06-15 14:35 - 2016-06-06 17:26 - 00037096 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2016-06-15 14:35 - 2016-06-06 17:23 - 01001472 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2016-06-15 14:35 - 2016-06-03 15:04 - 01225216 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2016-06-15 14:35 - 2016-05-27 15:05 - 00466944 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2016-06-15 14:35 - 2016-05-27 15:05 - 00461824 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2016-06-15 14:35 - 2016-05-27 15:05 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2016-06-15 14:35 - 2016-05-27 15:05 - 00205824 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
2016-06-15 14:35 - 2016-05-22 15:05 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2016-06-15 14:35 - 2016-05-13 23:54 - 00308456 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2016-06-15 14:35 - 2016-05-13 23:49 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2016-06-15 14:35 - 2016-05-13 23:49 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2016-06-15 14:35 - 2016-05-13 23:49 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2016-06-15 14:35 - 2016-05-13 23:27 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2016-06-15 14:35 - 2016-05-12 17:18 - 00606720 _____ (Microsoft Corporation) C:\Windows\system32\gpsvc.dll
2016-06-15 14:35 - 2016-05-12 17:18 - 00591872 _____ (Microsoft Corporation) C:\Windows\system32\gpprefcl.dll
2016-06-15 14:35 - 2016-05-12 17:18 - 00351744 _____ (Microsoft Corporation) C:\Windows\system32\IPSECSVC.DLL
2016-06-15 14:35 - 2016-05-12 17:18 - 00274944 _____ (Microsoft Corporation) C:\Windows\system32\polstore.dll
2016-06-15 14:35 - 2016-05-12 17:18 - 00079360 _____ (Microsoft Corporation) C:\Windows\system32\gpapi.dll
2016-06-15 14:35 - 2016-05-12 17:18 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\winipsec.dll
2016-06-15 14:35 - 2016-05-12 17:18 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\FwRemoteSvr.dll
2016-06-15 14:35 - 2016-05-12 16:57 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\gpscript.dll
2016-06-15 14:35 - 2016-05-12 16:57 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\gpscript.exe
2016-06-15 14:35 - 2016-05-11 17:19 - 00363520 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll
2016-06-15 14:35 - 2016-04-09 08:54 - 12881408 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2016-06-15 14:35 - 2016-04-09 08:54 - 01499648 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2016-06-15 14:35 - 2016-04-09 07:44 - 02973184 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2016-06-15 14:35 - 2016-03-09 20:40 - 00316416 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
2016-06-15 14:34 - 2016-05-24 00:54 - 00346312 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2016-06-15 14:34 - 2016-05-21 18:57 - 20341248 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-06-15 14:34 - 2016-05-21 00:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2016-06-15 14:34 - 2016-05-21 00:14 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2016-06-15 14:34 - 2016-05-20 23:57 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2016-06-15 14:34 - 2016-05-20 23:57 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2016-06-15 14:34 - 2016-05-20 23:57 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2016-06-15 14:34 - 2016-05-20 23:56 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2016-06-15 14:34 - 2016-05-20 23:55 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2016-06-15 14:34 - 2016-05-20 23:50 - 02287104 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2016-06-15 14:34 - 2016-05-20 23:49 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2016-06-15 14:34 - 2016-05-20 23:48 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2016-06-15 14:34 - 2016-05-20 23:45 - 00476160 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2016-06-15 14:34 - 2016-05-20 23:44 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2016-06-15 14:34 - 2016-05-20 23:44 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2016-06-15 14:34 - 2016-05-20 23:44 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2016-06-15 14:34 - 2016-05-20 23:43 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2016-06-15 14:34 - 2016-05-20 23:36 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2016-06-15 14:34 - 2016-05-20 23:33 - 00416256 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2016-06-15 14:34 - 2016-05-20 23:29 - 13815808 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2016-06-15 14:34 - 2016-05-20 23:27 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2016-06-15 14:34 - 2016-05-20 23:26 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2016-06-15 14:34 - 2016-05-20 23:23 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2016-06-15 14:34 - 2016-05-20 23:23 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2016-06-15 14:34 - 2016-05-20 23:21 - 00279040 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2016-06-15 14:34 - 2016-05-20 23:19 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2016-06-15 14:34 - 2016-05-20 23:14 - 04610048 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2016-06-15 14:34 - 2016-05-20 23:12 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2016-06-15 14:34 - 2016-05-20 23:09 - 00693248 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2016-06-15 14:34 - 2016-05-20 23:09 - 00689664 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2016-06-15 14:34 - 2016-05-20 23:08 - 02055680 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2016-06-15 14:34 - 2016-05-20 23:07 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2016-06-15 14:34 - 2016-05-20 22:42 - 02121216 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-06-15 14:34 - 2016-05-20 22:38 - 01310208 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-06-15 14:34 - 2016-05-20 22:38 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2016-06-15 14:34 - 2016-05-18 18:10 - 00306688 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2016-06-15 14:34 - 2016-05-12 17:22 - 00137960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-06-15 14:34 - 2016-05-12 17:22 - 00067304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2016-06-15 14:34 - 2016-05-12 17:18 - 01062400 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-06-15 14:34 - 2016-05-12 17:18 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2016-06-15 14:34 - 2016-05-12 17:18 - 00655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2016-06-15 14:34 - 2016-05-12 17:18 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-06-15 14:34 - 2016-05-12 17:18 - 00260608 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-06-15 14:34 - 2016-05-12 17:18 - 00251392 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-06-15 14:34 - 2016-05-12 17:18 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2016-06-15 14:34 - 2016-05-12 17:18 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2016-06-15 14:34 - 2016-05-12 17:18 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2016-06-15 14:34 - 2016-05-12 17:18 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2016-06-15 14:34 - 2016-05-12 17:18 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2016-06-15 14:34 - 2016-05-12 17:18 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2016-06-15 14:34 - 2016-05-12 17:18 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2016-06-15 14:34 - 2016-05-12 17:18 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2016-06-15 14:34 - 2016-05-12 17:18 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2016-06-15 14:34 - 2016-05-12 17:18 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2016-06-15 14:34 - 2016-05-12 16:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2016-06-15 14:34 - 2016-05-12 16:54 - 02397696 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-06-15 14:34 - 2016-05-12 16:52 - 00313856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2016-06-15 14:34 - 2016-05-12 16:52 - 00310784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2016-06-15 14:34 - 2016-05-12 16:52 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2016-06-15 14:34 - 2016-05-12 16:52 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2016-06-15 14:34 - 2016-05-12 16:52 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2016-06-15 14:34 - 2016-05-12 16:52 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2016-06-15 14:34 - 2016-05-12 16:51 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2016-06-15 14:34 - 2016-05-12 16:51 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2016-06-15 14:34 - 2016-05-12 16:51 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2016-06-15 14:34 - 2016-05-12 15:04 - 00370784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2016-06-15 14:34 - 2016-05-12 15:04 - 00249352 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll
2016-06-15 14:34 - 2016-05-11 17:19 - 00351744 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
2016-06-15 14:34 - 2016-05-11 17:19 - 00231424 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2016-06-15 14:34 - 2016-05-11 17:19 - 00206336 _____ (Microsoft Corporation) C:\Windows\system32\ws2_32.dll
2016-06-15 14:34 - 2016-05-11 17:01 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\netbtugc.exe
2016-06-15 14:34 - 2016-05-11 16:52 - 00188928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbt.sys
2016-06-15 14:34 - 2016-04-14 17:38 - 00105192 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2016-06-15 14:34 - 2016-04-14 17:33 - 02365440 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2016-06-15 14:34 - 2016-04-14 17:33 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2016-06-15 14:34 - 2016-04-14 17:33 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2016-06-15 14:34 - 2016-04-14 17:33 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2016-06-15 14:34 - 2016-04-14 17:33 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll
2016-06-15 14:34 - 2016-04-14 17:11 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-07-11 21:15 - 2015-12-23 02:48 - 00000000 ____D C:\ProgramData\Gramblr
2016-07-11 20:49 - 2013-06-13 22:12 - 00000000 ____D C:\Users\LoxoSRB\AppData\Roaming\BitTorrent
2016-07-11 20:48 - 2013-06-13 11:54 - 00000886 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-07-11 20:45 - 2013-06-13 13:23 - 00000380 _____ C:\Windows\Tasks\update-sys.job
2016-07-11 20:30 - 2013-06-17 18:52 - 00000000 ____D C:\Users\LoxoSRB\AppData\Local\CrashDumps
2016-07-11 20:29 - 2014-01-28 23:04 - 49033728 ___SH C:\Users\LoxoSRB\Desktop\Thumbs.db
2016-07-11 20:21 - 2016-04-17 19:00 - 00000864 _____ C:\Users\LoxoSRB\Desktop\Start Tor Browser.lnk
2016-07-11 20:21 - 2016-04-17 19:00 - 00000864 _____ C:\Users\LoxoSRB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk
2016-07-11 20:21 - 2013-06-13 11:55 - 00002347 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-07-11 20:21 - 2013-06-13 00:11 - 00001617 _____ C:\Users\LoxoSRB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-07-11 19:11 - 2013-06-13 13:23 - 00000380 _____ C:\Windows\Tasks\update-S-1-5-21-937694239-2368957015-2011986524-1000.job
2016-07-11 13:42 - 2009-07-14 06:34 - 00033072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-07-11 13:42 - 2009-07-14 06:34 - 00033072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-07-11 12:22 - 2013-06-13 11:54 - 00000882 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-07-11 12:22 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-07-10 16:00 - 2013-06-13 00:12 - 00785794 _____ C:\Windows\system32\PerfStringBackup.INI
2016-07-10 16:00 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\inf
2016-07-10 15:36 - 2014-07-14 01:06 - 00000000 ____D C:\Users\LoxoSRB\AppData\Roaming\vlc
2016-07-10 13:46 - 2013-06-13 12:39 - 00000000 ____D C:\Program Files\Common Files\Steam
2016-07-08 23:05 - 2013-06-25 17:54 - 00000000 ____D C:\Users\LoxoSRB\AppData\Roaming\Skype
2016-07-01 18:12 - 2013-06-13 15:29 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2016-07-01 16:59 - 2015-12-23 02:49 - 00000951 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gramblr.lnk
2016-06-30 01:17 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\NDF
2016-06-29 21:30 - 2013-08-18 14:31 - 00000000 ____D C:\Users\LoxoSRB\AppData\Local\PAYDAY
2016-06-29 20:48 - 2015-10-22 20:15 - 00000000 ____D C:\Users\LoxoSRB\BrawlhallaReplays
2016-06-24 13:41 - 2013-06-16 22:25 - 00000000 ____D C:\Users\LoxoSRB\.VirtualBox
2016-06-24 13:41 - 2013-06-13 00:10 - 00000000 ____D C:\Users\LoxoSRB
2016-06-21 19:14 - 2013-06-13 15:31 - 00000000 ____D C:\ProgramData\NVIDIA
2016-06-21 12:13 - 2013-06-13 12:03 - 00400552 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2016-06-18 12:17 - 2016-05-03 19:51 - 00000710 _____ C:\Users\LoxoSRB\Desktop\New Text Document.txt
2016-06-17 21:07 - 2013-07-01 17:23 - 00000000 ____D C:\Program Files\Common Files\Adobe
2016-06-17 21:06 - 2014-08-09 13:04 - 00000000 ____D C:\Users\LoxoSRB\AppData\Roaming\Riot Games
2016-06-17 21:06 - 2013-07-04 01:31 - 00000000 ____D C:\ProgramData\Adobe
2016-06-17 21:06 - 2013-06-14 04:22 - 00000000 ____D C:\Users\LoxoSRB\AppData\Roaming\Adobe
2016-06-17 21:05 - 2013-07-04 01:45 - 00000000 ____D C:\Program Files\Adobe
2016-06-17 21:04 - 2013-06-13 22:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Net Tools
2016-06-17 21:03 - 2013-06-13 11:54 - 00000000 ____D C:\Program Files\Google
2016-06-17 21:00 - 2014-01-11 17:30 - 00000000 ____D C:\Users\LoxoSRB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2016-06-16 14:51 - 2009-07-14 06:33 - 04045624 _____ C:\Windows\system32\FNTCACHE.DAT
2016-06-16 14:48 - 2014-12-11 20:51 - 00000000 ____D C:\Windows\system32\appraiser
2016-06-15 23:00 - 2013-08-14 17:16 - 00000000 ____D C:\Windows\system32\MRT
2016-06-15 23:00 - 2013-08-04 18:01 - 139785240 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
==================== Files in the root of some directories =======
2013-11-14 00:43 - 2013-11-14 00:43 - 0000132 _____ () C:\Users\LoxoSRB\AppData\Roaming\Adobe BMP Format CS5 Prefs
2014-10-25 23:59 - 2015-11-03 11:37 - 0000132 _____ () C:\Users\LoxoSRB\AppData\Roaming\Adobe PNG Format CS6 Prefs
2003-04-09 05:28 - 2003-04-09 05:28 - 0233472 ____R () C:\Users\LoxoSRB\AppData\Roaming\MafiaSetup.exe
2015-09-21 18:00 - 2015-09-21 18:00 - 0000000 ____H () C:\Users\LoxoSRB\AppData\Local\BITAE3D.tmp
2016-04-15 18:12 - 2016-04-15 18:12 - 0000869 _____ () C:\Users\LoxoSRB\AppData\Local\recently-used.xbel
2013-06-13 13:23 - 2013-06-13 13:23 - 0000003 _____ () C:\Users\LoxoSRB\AppData\Local\updater.log
2013-06-13 13:23 - 2015-10-01 23:36 - 0000412 _____ () C:\Users\LoxoSRB\AppData\Local\UserProducts.xml
2015-09-21 17:59 - 2015-09-21 18:00 - 0000000 _____ () C:\Users\LoxoSRB\AppData\Local\{5657809B-BF10-4E9B-B02B-111A9CAF2C15}
Some files in TEMP:
====================
C:\Users\LoxoSRB\AppData\Local\Temp\SkypeSetup.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-07-07 22:13
==================== End of FRST.txt ============================
https://www.mycity.rs/must-login.png
Dopuna: 11 Jul 2016 21:20
Obrisao sam ono sto je instalirao to je ovaj:
Citat:2016-07-11 20:21 - 2016-07-11 20:22 - 00000000 ____D C:\Users\LoxoSRB\AppData\Roaming\SpringFiles
I bio je neki proces tog slicnog naziva i to sam obrisao i nista nisam resio...
Gde god da kliknem otvaraju se reklame, default page je promenjen, na guglu ne mogu da kucam odma me prebacuje na neki njihov pretrazivac...
A podesavanja u chrome su normalna...
|
|
|
|
Poslao: 12 Jul 2016 00:53
|
offline
- Sass Drake
- Anti Malware Fighter
Rank 2
- Pridružio: 26 Avg 2010
- Poruke: 10622
- Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building
|
Otvori Notepad i iskopiraj sljedeći tekst koji se nalazi unutar Kod polja.
Start
cmd: type "C:\Users\LoxoSRB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\specvrme.vbs"
Startup: C:\Users\LoxoSRB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\specvrme.vbs [2016-05-30] ()
FF NetworkProxy: "backup.ftp", "36.72.66.68"
FF NetworkProxy: "backup.ftp_port", 8080
FF NetworkProxy: "backup.socks", "36.72.66.68"
FF NetworkProxy: "backup.socks_port", 8080
FF NetworkProxy: "backup.ssl", "36.72.66.68"
FF NetworkProxy: "backup.ssl_port", 8080
FF NetworkProxy: "ftp", "202.182.55.10"
FF NetworkProxy: "ftp_port", 8081
FF NetworkProxy: "http", "202.182.55.10"
FF NetworkProxy: "http_port", 8081
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks", "202.182.55.10"
FF NetworkProxy: "socks_port", 8081
FF NetworkProxy: "ssl", "202.182.55.10"
FF NetworkProxy: "ssl_port", 8081
FF NetworkProxy: "type", 0
Shortcut: C:\Users\LoxoSRB\Desktop\Start Tor Browser.lnk -> hxxp://safebrowsing.biz/?ssid=1468261233&a=1024132&src=sh&uuid=8089a967-1f05-48c0-a6be-7493376d664c"( (No File)
Shortcut: C:\Users\LoxoSRB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> hxxp://safebrowsing.biz/?ssid=1468261233&a=1024132&src=sh&uuid=8089a967-1f05-48c0-a6be-7493376d664c" (No File)
Shortcut: C:\Users\LoxoSRB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk -> hxxp://safebrowsing.biz/?ssid=1468261233&a=1024132&src=sh&uuid=8089a967-1f05-48c0-a6be-7493376d664c"( (No File)
Shortcut: C:\Users\LoxoSRB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> hxxp://safebrowsing.biz/?ssid=1468261233&a=1024132&src=sh&uuid=8089a967-1f05-48c0-a6be-7493376d664c" (No File)
Shortcut: C:\Users\LoxoSRB\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> hxxp://safebrowsing.biz/?ssid=1468261233&a=1024132&src=sh&uuid=8089a967-1f05-48c0-a6be-7493376d664c" (No File)
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> "hxxp://safebrowsing.biz/?ssid=1468261233&a=1024132&src=sh&uuid=8089a967-1f05-48c0-a6be-7493376d664c"
FirewallRules: [{AA7B0061-E524-49BA-907F-F012FE6BAECC}] => (Allow) C:\Program Files\SrpnFiles\SrpnFiles.exe
FirewallRules: [{05677663-39A3-4C4C-B78A-FEC8BCF39E07}] => (Allow) C:\Program Files\SrpnFiles\SrpnFiles.exe
FirewallRules: [{CC0F148B-6C70-41BA-80A7-87A98FC0ED20}] => (Allow) C:\Program Files\SrpnFiles\downloader.exe
FirewallRules: [{29076A96-8803-4D67-A9AD-0D8CA4E66292}] => (Allow) C:\Program Files\SrpnFiles\downloader.exe
C:\Program Files\SrpnFiles
C:\Users\LoxoSRB\AppData\Roaming\SpringFiles
HKU\S-1-5-21-937694239-2368957015-2011986524-1000\...\MountPoints2: {1de478ab-1c03-11e4-a6ac-0019dbf2f5ee} - L:\AutoRun.exe {D2D77DC2-8299-11D1-8949-444553540000} 5.2066.1.A11B02 PID_0083
HKU\S-1-5-21-937694239-2368957015-2011986524-1000\...\MountPoints2: {84eae620-fa9a-11e5-9390-0019dbf2f5ee} - G:\Lenovo_Suite.exe
EmptyTemp:
End
U okviru Notepad-a klikni na File --> Save As
Fajl nazovi Fixlist i sačuvaj na Desktop
Dvoklikom ponovo pokreni FRST.exe
Klikni na Fix i sačekaj dok program ne završi.
Ukoliko program zatraži restart računara, omogući mu da to nesmetano obavi.
Nakon završetka rada, otvoriće se fixlog.txt, sa sadržajem koji treba da kopiraš u temu.
Takođe, na Desktop-u će se nalaziti (fixlog.txt).
|
|
|
|
Poslao: 12 Jul 2016 01:06
|
offline
- LoXo
- Super građanin
- Pridružio: 14 Okt 2011
- Poruke: 1212
|
Fix result of Farbar Recovery Scan Tool (x86) Version: 10-07-2016 01
Ran by LoxoSRB (2016-07-12 02:00:44) Run:1
Running from C:\Users\LoxoSRB\Downloads
Loaded Profiles: LoxoSRB (Available Profiles: LoxoSRB & UpdatusUser)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
cmd: type "C:\Users\LoxoSRB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\specvrme.vbs"
Startup: C:\Users\LoxoSRB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\specvrme.vbs [2016-05-30] ()
FF NetworkProxy: "backup.ftp", "36.72.66.68"
FF NetworkProxy: "backup.ftp_port", 8080
FF NetworkProxy: "backup.socks", "36.72.66.68"
FF NetworkProxy: "backup.socks_port", 8080
FF NetworkProxy: "backup.ssl", "36.72.66.68"
FF NetworkProxy: "backup.ssl_port", 8080
FF NetworkProxy: "ftp", "202.182.55.10"
FF NetworkProxy: "ftp_port", 8081
FF NetworkProxy: "http", "202.182.55.10"
FF NetworkProxy: "http_port", 8081
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks", "202.182.55.10"
FF NetworkProxy: "socks_port", 8081
FF NetworkProxy: "ssl", "202.182.55.10"
FF NetworkProxy: "ssl_port", 8081
FF NetworkProxy: "type", 0
Shortcut: C:\Users\LoxoSRB\Desktop\Start Tor Browser.lnk -> hxxp://safebrowsing.biz/?ssid=1468261233&a=1024132&src=sh&uuid=8089a967-1f05-48c0-a6be-7493376d664c"( (No File)
Shortcut: C:\Users\LoxoSRB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> hxxp://safebrowsing.biz/?ssid=1468261233&a=1024132&src=sh&uuid=8089a967-1f05-48c0-a6be-7493376d664c" (No File)
Shortcut: C:\Users\LoxoSRB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk -> hxxp://safebrowsing.biz/?ssid=1468261233&a=1024132&src=sh&uuid=8089a967-1f05-48c0-a6be-7493376d664c"( (No File)
Shortcut: C:\Users\LoxoSRB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> hxxp://safebrowsing.biz/?ssid=1468261233&a=1024132&src=sh&uuid=8089a967-1f05-48c0-a6be-7493376d664c" (No File)
Shortcut: C:\Users\LoxoSRB\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> hxxp://safebrowsing.biz/?ssid=1468261233&a=1024132&src=sh&uuid=8089a967-1f05-48c0-a6be-7493376d664c" (No File)
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> "hxxp://safebrowsing.biz/?ssid=1468261233&a=1024132&src=sh&uuid=8089a967-1f05-48c0-a6be-7493376d664c"
FirewallRules: [{AA7B0061-E524-49BA-907F-F012FE6BAECC}] => (Allow) C:\Program Files\SrpnFiles\SrpnFiles.exe
FirewallRules: [{05677663-39A3-4C4C-B78A-FEC8BCF39E07}] => (Allow) C:\Program Files\SrpnFiles\SrpnFiles.exe
FirewallRules: [{CC0F148B-6C70-41BA-80A7-87A98FC0ED20}] => (Allow) C:\Program Files\SrpnFiles\downloader.exe
FirewallRules: [{29076A96-8803-4D67-A9AD-0D8CA4E66292}] => (Allow) C:\Program Files\SrpnFiles\downloader.exe
C:\Program Files\SrpnFiles
C:\Users\LoxoSRB\AppData\Roaming\SpringFiles
HKU\S-1-5-21-937694239-2368957015-2011986524-1000\...\MountPoints2: {1de478ab-1c03-11e4-a6ac-0019dbf2f5ee} - L:\AutoRun.exe {D2D77DC2-8299-11D1-8949-444553540000} 5.2066.1.A11B02 PID_0083
HKU\S-1-5-21-937694239-2368957015-2011986524-1000\...\MountPoints2: {84eae620-fa9a-11e5-9390-0019dbf2f5ee} - G:\Lenovo_Suite.exe
EmptyTemp:
End
*****************
========= type "C:\Users\LoxoSRB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\specvrme.vbs" =========
Set objShell = CreateObject("Shell.Application")
objShell.ShellExecute "C:\Users\LoxoSRB\AppData\Local\Temp\Spectorn\specvrme.exe", "", "", "", 1
========= End ofCMD: =========
C:\Users\LoxoSRB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\specvrme.vbs => moved successfully
Firefox Proxy settings were reset.
FF NetworkProxy: "backup.ftp_port", 8080 => not found
FF NetworkProxy: "backup.socks", "36.72.66.68" => not found
FF NetworkProxy: "backup.socks_port", 8080 => not found
FF NetworkProxy: "backup.ssl", "36.72.66.68" => not found
FF NetworkProxy: "backup.ssl_port", 8080 => not found
FF NetworkProxy: "ftp", "202.182.55.10" => not found
FF NetworkProxy: "ftp_port", 8081 => not found
FF NetworkProxy: "http", "202.182.55.10" => not found
FF NetworkProxy: "http_port", 8081 => not found
FF NetworkProxy: "share_proxy_settings", true => not found
FF NetworkProxy: "socks", "202.182.55.10" => not found
FF NetworkProxy: "socks_port", 8081 => not found
FF NetworkProxy: "ssl", "202.182.55.10" => not found
FF NetworkProxy: "ssl_port", 8081 => not found
FF NetworkProxy: "type", 0 => not found
Shortcut: C:\Users\LoxoSRB\Desktop\Start Tor Browser.lnk -> hxxp://safebrowsing.biz/?ssid=1468261233&a=1024132&src=sh&uuid=8089a967-1f05-48c0-a6be-7493376d664c"( (No File) => Error: No automatic fix found for this entry.
Shortcut: C:\Users\LoxoSRB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> hxxp://safebrowsing.biz/?ssid=1468261233&a=1024132&src=sh&uuid=8089a967-1f05-48c0-a6be-7493376d664c" (No File) => Error: No automatic fix found for this entry.
Shortcut: C:\Users\LoxoSRB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk -> hxxp://safebrowsing.biz/?ssid=1468261233&a=1024132&src=sh&uuid=8089a967-1f05-48c0-a6be-7493376d664c"( (No File) => Error: No automatic fix found for this entry.
Shortcut: C:\Users\LoxoSRB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> hxxp://safebrowsing.biz/?ssid=1468261233&a=1024132&src=sh&uuid=8089a967-1f05-48c0-a6be-7493376d664c" (No File) => Error: No automatic fix found for this entry.
Shortcut: C:\Users\LoxoSRB\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> hxxp://safebrowsing.biz/?ssid=1468261233&a=1024132&src=sh&uuid=8089a967-1f05-48c0-a6be-7493376d664c" (No File) => Error: No automatic fix found for this entry.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk => Shortcut argument removed successfully..
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{AA7B0061-E524-49BA-907F-F012FE6BAECC} => value removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{05677663-39A3-4C4C-B78A-FEC8BCF39E07} => value removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{CC0F148B-6C70-41BA-80A7-87A98FC0ED20} => value removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{29076A96-8803-4D67-A9AD-0D8CA4E66292} => value removed successfully.
"C:\Program Files\SrpnFiles" => not found.
C:\Users\LoxoSRB\AppData\Roaming\SpringFiles => moved successfully
"HKU\S-1-5-21-937694239-2368957015-2011986524-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1de478ab-1c03-11e4-a6ac-0019dbf2f5ee}" => key removed successfully.
HKCR\CLSID\{1de478ab-1c03-11e4-a6ac-0019dbf2f5ee} => key not found.
"HKU\S-1-5-21-937694239-2368957015-2011986524-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{84eae620-fa9a-11e5-9390-0019dbf2f5ee}" => key removed successfully.
HKCR\CLSID\{84eae620-fa9a-11e5-9390-0019dbf2f5ee} => key not found.
=========== EmptyTemp: ==========
BITS transfer queue => 0 B
DOMStoree, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 262170335 B
Java, Flash, Steam htmlcache => 152832826 B
Windows/system/drivers => 34894276 B
Edge => 0 B
Chrome => 341480692 B
Firefox => 0 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 10288 B
LocalService => 0 B
NetworkService => 83016 B
LoxoSRB => 144398543 B
UpdatusUser => 0 B
RecycleBin => 0 B
EmptyTemp: => 892.5 MB temporary data Removed.
================================
The system needed a reboot.
==== End of Fixlog 02:01:03 ====
|
|
|
|
Poslao: 12 Jul 2016 06:55
|
offline
- Sass Drake
- Anti Malware Fighter
Rank 2
- Pridružio: 26 Avg 2010
- Poruke: 10622
- Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building
|
Preuzmi "Xplode"-ov AdwCleaner i sačuvaj ga na Desktop
Dvoklikom pokreni program.
U EULA prozoru klikni na I agree.
U Options isključi Reset Winsock settings ako je uključen.
Klikni na dugme Scan i sačekaj da se završi skeniranje.
Klikni na dugme Cleaning i pričekaj da program završi.
Program će zatvoriti sve aktivne programe i izbaciti prozor sa tim upozorenjem. Klikni OK kao potvrdu.
Na sljedeća dva prozora koja se otvore (Informations i Restart required ) klikni OK
Računar će se restartovati, a potom otvoriti Notepad (C:\Adwcleaner\AdwCleaner[C1].txt) sa izvještajem.
Sačuvaj taj izvještaj na Desktop i okači ga uz poruku koristeći opciju "Prikači fajl"
|
|
|
|
Poslao: 12 Jul 2016 12:39
|
offline
- LoXo
- Super građanin
- Pridružio: 14 Okt 2011
- Poruke: 1212
|
Napisano: 12 Jul 2016 13:27
https://www.mycity.rs/must-login.png
Dopuna: 12 Jul 2016 13:38
I dalje imam ovaj problem
Dopuna: 12 Jul 2016 13:39
I kada me prebaci tu gore da kucam i kliknem pretragu, onda me redirektuje preko neka 2-3 njihova sajta i na kraju zavrsim na yahoo...
|
|
|
|
Poslao: 12 Jul 2016 13:17
|
offline
- Sass Drake
- Anti Malware Fighter
Rank 2
- Pridružio: 26 Avg 2010
- Poruke: 10622
- Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building
|
Postavi mi nove FRST izvještaje.
|
|
|
|
|
Poslao: 12 Jul 2016 14:52
|
offline
- Sass Drake
- Anti Malware Fighter
Rank 2
- Pridružio: 26 Avg 2010
- Poruke: 10622
- Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building
|
Otvori Notepad i iskopiraj sljedeći tekst koji se nalazi unutar Kod polja.
ManualProxies: 0hxxp://stop-block.net/wpad.dat?e921cee3952ad0fe69896e2e29d9cc9412665873
U okviru Notepad-a klikni na File --> Save As
Fajl nazovi Fixlist i sačuvaj na Desktop
Dvoklikom ponovo pokreni FRST.exe
Klikni na Fix i sačekaj dok program ne završi.
Ukoliko program zatraži restart računara, omogući mu da to nesmetano obavi.
Nakon završetka rada, otvoriće se fixlog.txt, sa sadržajem koji treba da kopiraš u temu.
Takođe, na Desktop-u će se nalaziti (fixlog.txt).
|
|
|
|
Poslao: 12 Jul 2016 17:34
|
offline
- LoXo
- Super građanin
- Pridružio: 14 Okt 2011
- Poruke: 1212
|
Fix result of Farbar Recovery Scan Tool (x86) Version: 10-07-2016 01
Ran by LoxoSRB (2016-07-12 18:34:10) Run:2
Running from C:\Users\LoxoSRB\Downloads
Loaded Profiles: LoxoSRB (Available Profiles: LoxoSRB & UpdatusUser)
Boot Mode: Normal
==============================================
fixlist content:
*****************
ManualProxies: 0hxxp://stop-block.net/wpad.dat?e921cee3952ad0fe69896e2e29d9cc9412665873
*****************
HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies\\ => value removed successfully.
==== End of Fixlog 18:34:10 ====
|
|
|
|
Poslao: 12 Jul 2016 18:49
|
offline
- Sass Drake
- Anti Malware Fighter
Rank 2
- Pridružio: 26 Avg 2010
- Poruke: 10622
- Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building
|
Da li i dalje imaš problema?
Preuzmi instalaciju za Malwarebytes Anti-Malware (MBAM) ver.2.0 i instaliraj aplikaciju.
Dvoklik na mbam-setup.exe i prati uputstva za instalaciju. Instalacija je klasicna, "Next > I Agree . . > Next > Install" princip. Po zavrsenoj instalaciji, klikni Finish.
Napomena: 14 dana besplatna trail verzija je pre-selektovana. Mozes decekirati ovu opciju ako zelis.
- Po prvom pokretanju, MBAM ce zapoceti "Update" u nameri da preuzme najsvezije definicije.
Ili ... klik na 'Update Now >>' link ili dugme radi preuzimanja svezih definicija.
• Konfigurisati skener; Na 'Settings' tabu, Detection and Protection podesiti sledece opcije:
1. pod-tab Detection Options, cekirati kucicu za 'Scan for rootkits';
2. pod-tab Non-Malware Protection, za 'PUP detections', prostarati se da je selektovana 'Threat detections as malware' opcija.
• Izvrsiti 'Threat Scan';
Klik na Scan tab, zatim na 'Scan Now >>' da bi izvrsio skeniranje.
Ukoliko MBAM prijavi da je 'update' dostupan, klik na 'Update Now' a potom nastaviti do skeniranja.
Obavestenje: kod nekih teskih infekcija, moguce je dobiti sledecu poruku "Could not load DDA driver". U tom slucaju, klik Yes na tu poruku, dopustiti ucitavanje drajvera po restartu racunara, dozvoliti restart.
Potom, nastaviti sa ostatkom instrukcija.
• Po zavrsenom skeniranju, klik na Apply Action dugme ukoliko je pretnja detektovana. Sacekati da program zatrazi restart!
- Klik na Yes na poruku koja govori da ce se sistem restartovati.
• Postaviti izvestaj (export-ovati logfile) na uvid;
Ponovo pokrenuti MBAM, klik na History tab > Application Logs. Dvoklik na 'Scan Log' koji pokazuje vreme i datum upravo izvrsenog skeniranja.
1. U novom prozoru klik na 'Export' dugme, pa izabrati 'Text file (*.txt)';
2. Kada se pojavi Save File dialog, izabrati da se log sacuva na Desktop.
U tom istom prozoru, dole pod File name: upisi 'mbam' kao naziv izvestaja i klikni dugme Save.
- Po dobijenoj poruci ("Your file has been successfully exported") izvestaj koji si nazvao kao 'mbam' bice sacuvan na Desktop.
Okaci mbam.txt uz poruku koristeci opciju Prikači fajl.
|
|
|
|