Skeniranje racunara.

1

Skeniranje racunara.

offline
  • Student by day. Hacker by night
  • Pridružio: 11 Maj 2014
  • Poruke: 189
  • Gde živiš: 192.168.0.1

Skidao sam svastsa nesto ovih dana, i ostalo sto mi je bilo potrebno prebacio na eksterni hard. Bilo je tu verujem i svakakvih virusa i ostalih gluposti. Naime skinuo sam veceras jos nesto, ali ovo ne mogu da obrisem nikako. Pa se zato vama obracam, da obrisem sa racunara.

mycity.rs/must-login.png

mycity.rs/must-login.png

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 31-08-2016
Ran by Aleksandar (administrator) on ALEKSANDAR-PC (10-09-2016 23:29:52)
Running from C:\Users\Aleksandar\Downloads
Loaded Profiles: Aleksandar (Available Profiles: Aleksandar)
Platform: Windows 7 Professional (X64) Language: English (United States)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: geekstogo.com/forum/topic/335081-frst-t.....scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Popcorn Time) C:\Program Files (x86)\Popcorn Time\Updater.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
() C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(VMware, Inc.) C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
() C:\Users\Aleksandar\AppData\Local\Drpbx\drpbx.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9107104 2016-09-07] (AVAST Software)
HKLM-x32\...\Run: [SunJavaUpdateSched] => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [vmware-tray.exe] => C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe [104128 2016-04-14] (VMware, Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2643023827-58587059-3105705347-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8894680 2016-08-05] (Piriform Ltd)
HKU\S-1-5-21-2643023827-58587059-3105705347-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [29538432 2016-08-17] (Skype Technologies S.A.)
HKU\S-1-5-21-2643023827-58587059-3105705347-1000\...\Run: [Steam] => D:\Program Files (x86)\Steam\steam.exe [2857248 2016-08-23] (Valve Corporation)
HKU\S-1-5-21-2643023827-58587059-3105705347-1000\...\Run: [firefox.exe] => C:\Users\Aleksandar\AppData\Roaming\Frfx\firefox.exe [290816 2016-08-03] ()
HKU\S-1-5-21-2643023827-58587059-3105705347-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [11264 2009-07-14] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-09-07] (AVAST Software)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 0.0.0.0
Tcpip\..\Interfaces\{4CC4C214-BCC2-4403-912D-2A2687F72A44}: [DhcpNameServer] 192.168.1.1 0.0.0.0

Internet Explorer:
==================
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_102\bin\ssv.dll [2016-09-07] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-09-07] (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_102\bin\jp2ssv.dll [2016-09-07] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-09-07] (AVAST Software)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-14] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-14] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-14] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-14] (Microsoft Corporation)

FireFox:
========
FF ProfilePath: C:\Users\Aleksandar\AppData\Roaming\Mozilla\Firefox\Profiles\yjipztjf.default
FF Homepage: google.com
FF Plugin: @java.com/DTPlugin,version=11.102.2 -> C:\Program Files\Java\jre1.8.0_102\bin\dtplugin\npDeployJava1.dll [2016-09-07] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.102.2 -> C:\Program Files\Java\jre1.8.0_102\bin\plugin2\npjp2.dll [2016-09-07] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Extension: (Greasemonkey) - C:\Users\Aleksandar\AppData\Roaming\Mozilla\Firefox\Profiles\yjipztjf.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2016-09-09]
FF Extension: (anonymoX) - C:\Users\Aleksandar\AppData\Roaming\Mozilla\Firefox\Profiles\yjipztjf.default\Extensions\client@anonymox.net.xpi [2016-09-10]
FF Extension: (Firefox Hotfix) - C:\Users\Aleksandar\AppData\Roaming\Mozilla\Firefox\Profiles\yjipztjf.default\Extensions\firefox-hotfix@mozilla.org.xpi [2016-09-08]
FF Extension: (Adblock Plus) - C:\Users\Aleksandar\AppData\Roaming\Mozilla\Firefox\Profiles\yjipztjf.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-09-07]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-09-07]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-09-07] (AVAST Software)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 Update service; C:\Program Files (x86)\Popcorn Time\Updater.exe [339968 2016-08-03] (Popcorn Time) [File not signed]
R2 VMwareHostd; C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe [12471368 2016-04-14] ()
S3 WatAdminSvc; C:\Windows\system32\Wat\WatAdminSvc.exe [1255736 2016-09-07] () [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-09-07] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [108816 2016-09-07] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-09-07] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-09-07] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [969560 2016-09-07] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [513496 2016-09-07] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [163416 2016-09-07] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [292704 2016-09-07] (AVAST Software)
S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R1 VBoxNetAdp; C:\Windows\System32\DRIVERS\VBoxNetAdp6.sys [121248 2016-08-16] (Oracle Corporation)
R1 VBoxNetLwf; C:\Windows\System32\DRIVERS\VBoxNetLwf.sys [195936 2016-08-16] (Oracle Corporation)
R0 vsock; C:\Windows\System32\drivers\vsock.sys [75512 2015-11-05] (VMware, Inc.)
R2 vstor2-mntapi20-shared; C:\Windows\SysWow64\drivers\vstor2-mntapi20-shared.sys [34520 2015-07-09] (VMware, Inc.)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-09-10 23:30 - 2016-09-10 23:29 - 00018079 _____ C:\Users\Aleksandar\Desktop\Addition.txt
2016-09-10 23:30 - 2016-09-10 23:29 - 00009704 _____ C:\Users\Aleksandar\Desktop\FRST.txt
2016-09-10 23:29 - 2016-09-10 23:29 - 00018079 _____ C:\Users\Aleksandar\Downloads\Addition.txt
2016-09-10 23:28 - 2016-09-10 23:29 - 00009704 _____ C:\Users\Aleksandar\Downloads\FRST.txt
2016-09-10 23:28 - 2016-09-10 23:29 - 00000000 ____D C:\FRST
2016-09-10 23:27 - 2016-09-10 23:28 - 02397696 _____ (Farbar) C:\Users\Aleksandar\Downloads\FRST64.exe
2016-09-10 23:16 - 2016-09-10 23:16 - 00000000 ____D C:\Users\Aleksandar\AppData\Roaming\Frfx
2016-09-10 23:16 - 2016-09-10 23:16 - 00000000 ____D C:\Users\Aleksandar\AppData\Local\Drpbx
2016-09-10 23:11 - 2009-11-25 21:47 - 01942856 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2016-09-10 23:11 - 2009-11-25 21:47 - 01130824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll
2016-09-10 23:11 - 2009-11-25 21:47 - 00444752 _____ (Microsoft Corporation) C:\Windows\system32\mscoree.dll
2016-09-10 23:11 - 2009-11-25 21:47 - 00320352 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHost.exe
2016-09-10 23:11 - 2009-11-25 21:47 - 00297808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscoree.dll
2016-09-10 23:11 - 2009-11-25 21:47 - 00295264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationHost.exe
2016-09-10 23:11 - 2009-11-25 21:47 - 00109912 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHostProxy.dll
2016-09-10 23:11 - 2009-11-25 21:47 - 00099176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationHostProxy.dll
2016-09-10 23:11 - 2009-11-25 21:47 - 00049472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netfxperf.dll
2016-09-10 23:11 - 2009-11-25 21:47 - 00048960 _____ (Microsoft Corporation) C:\Windows\system32\netfxperf.dll
2016-09-10 23:10 - 2016-09-10 23:10 - 00672288 _____ (Disc Soft Ltd.) C:\Users\Aleksandar\Downloads\DTUltraInstaller1.1.exe
2016-09-10 23:02 - 2016-09-10 23:02 - 00000000 ____D C:\Users\Aleksandar\Desktop\1for5 easy method
2016-09-10 22:30 - 2016-09-10 22:30 - 00000000 ____D C:\Users\Aleksandar\Downloads\Adobe Photoshop CS4 Extended [CLEAN] [blaze69]
2016-09-10 22:27 - 2016-09-10 22:27 - 00000000 ____D C:\Users\Aleksandar\Downloads\kali-linux-2016.2-i386
2016-09-09 01:24 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll
2016-09-09 01:24 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
2016-09-09 01:24 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll
2016-09-09 01:24 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll
2016-09-09 01:24 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
2016-09-09 01:24 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll
2016-09-09 01:24 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
2016-09-09 01:24 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll
2016-09-09 01:24 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
2016-09-09 01:24 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll
2016-09-09 01:24 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll
2016-09-09 01:24 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll
2016-09-09 01:24 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll
2016-09-09 01:24 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll
2016-09-09 01:24 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
2016-09-09 01:24 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll
2016-09-09 01:24 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll
2016-09-09 01:24 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll
2016-09-09 01:24 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll
2016-09-09 01:24 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll
2016-09-09 01:24 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll
2016-09-09 01:24 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll
2016-09-09 01:24 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll
2016-09-09 01:24 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll
2016-09-09 01:24 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll
2016-09-09 01:24 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll
2016-09-09 01:24 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll
2016-09-09 01:24 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll
2016-09-09 01:24 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll
2016-09-09 01:24 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll
2016-09-09 01:24 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll
2016-09-09 01:24 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll
2016-09-09 01:24 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
2016-09-09 01:24 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
2016-09-09 01:24 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll
2016-09-09 01:24 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll
2016-09-09 01:24 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll
2016-09-09 01:24 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll
2016-09-09 01:24 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll
2016-09-09 01:24 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll
2016-09-09 01:24 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll
2016-09-09 01:24 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll
2016-09-09 01:24 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll
2016-09-09 01:24 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll
2016-09-09 01:24 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll
2016-09-09 01:24 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll
2016-09-09 01:24 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll
2016-09-09 01:24 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll
2016-09-09 01:24 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll
2016-09-09 01:24 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_41.dll
2016-09-09 01:24 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll
2016-09-09 01:24 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_41.dll
2016-09-09 01:24 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll
2016-09-09 01:24 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll
2016-09-09 01:24 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll
2016-09-09 01:24 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll
2016-09-09 01:24 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll
2016-09-09 01:24 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll
2016-09-09 01:24 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll
2016-09-09 01:24 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll
2016-09-09 01:24 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll
2016-09-09 01:24 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll
2016-09-09 01:24 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll
2016-09-09 01:24 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll
2016-09-09 01:24 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll
2016-09-09 01:24 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll
2016-09-09 01:24 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll
2016-09-09 01:24 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll
2016-09-09 01:24 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll
2016-09-09 01:24 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll
2016-09-09 01:24 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll
2016-09-09 01:24 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll
2016-09-09 01:24 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll
2016-09-09 01:24 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll
2016-09-09 01:24 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll
2016-09-09 01:24 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll
2016-09-09 01:24 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll
2016-09-09 01:24 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll
2016-09-09 01:24 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll
2016-09-09 01:24 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll
2016-09-09 01:24 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll
2016-09-09 01:24 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll
2016-09-09 01:24 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll
2016-09-09 01:24 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll
2016-09-09 01:24 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll
2016-09-09 01:24 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll
2016-09-09 01:24 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll
2016-09-09 01:24 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll
2016-09-09 01:24 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll
2016-09-09 01:24 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll
2016-09-09 01:24 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll
2016-09-09 01:24 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll
2016-09-09 01:24 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll
2016-09-09 01:24 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll
2016-09-09 01:24 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll
2016-09-09 01:24 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll
2016-09-09 01:24 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll
2016-09-09 01:24 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll
2016-09-09 01:24 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll
2016-09-09 01:24 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll
2016-09-09 01:24 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll
2016-09-09 01:24 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll
2016-09-09 01:24 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll
2016-09-09 01:24 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll
2016-09-09 01:24 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll
2016-09-09 01:24 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll
2016-09-09 01:24 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll
2016-09-09 01:24 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll
2016-09-09 01:24 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll
2016-09-09 01:24 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll
2016-09-09 01:24 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll
2016-09-09 01:24 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll
2016-09-09 01:24 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll
2016-09-09 01:24 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll
2016-09-09 01:24 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll
2016-09-09 01:24 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll
2016-09-09 01:24 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll
2016-09-09 01:24 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll
2016-09-09 01:24 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll
2016-09-09 01:24 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll
2016-09-09 01:24 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll
2016-09-09 01:24 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll
2016-09-09 01:24 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll
2016-09-09 01:24 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll
2016-09-09 01:24 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll
2016-09-09 01:24 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll
2016-09-09 01:24 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll
2016-09-09 01:24 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll
2016-09-09 01:24 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll
2016-09-09 01:24 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll
2016-09-09 01:24 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll
2016-09-09 01:24 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll
2016-09-09 01:24 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
2016-09-09 01:24 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll
2016-09-09 01:24 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll
2016-09-09 01:24 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll
2016-09-09 01:24 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll
2016-09-09 01:24 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll
2016-09-09 01:24 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll
2016-09-09 01:24 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll
2016-09-09 01:24 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll
2016-09-09 01:24 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll
2016-09-09 01:24 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll
2016-09-09 01:24 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll
2016-09-09 01:24 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll
2016-09-09 01:24 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll
2016-09-09 01:24 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
2016-09-09 01:24 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll
2016-09-09 01:24 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll
2016-09-09 01:24 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll
2016-09-09 01:24 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll
2016-09-09 01:24 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll
2016-09-09 01:23 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll
2016-09-09 01:23 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll
2016-09-09 01:23 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
2016-09-09 01:23 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll
2016-09-09 01:23 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll
2016-09-09 01:23 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll
2016-09-09 01:23 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll
2016-09-09 01:23 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll
2016-09-09 01:23 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
2016-09-09 01:23 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll
2016-09-09 01:23 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll
2016-09-09 01:23 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll
2016-09-09 01:23 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
2016-09-09 01:23 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll
2016-09-09 01:23 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
2016-09-09 01:23 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll
2016-09-09 01:23 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll
2016-09-09 01:23 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll
2016-09-09 01:23 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll
2016-09-09 01:23 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll
2016-09-09 01:23 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
2016-09-09 01:23 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll
2016-09-09 01:23 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll
2016-09-09 01:23 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll
2016-09-09 01:23 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
2016-09-09 01:23 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll
2016-09-09 01:23 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
2016-09-09 01:23 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll
2016-09-09 01:23 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
2016-09-09 01:23 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll
2016-09-08 20:50 - 2016-09-08 20:50 - 00000000 ____D C:\Users\Aleksandar\Documents\Virtual Machines
2016-09-08 20:49 - 2016-09-08 20:51 - 00000000 ____D C:\Users\Aleksandar\AppData\Roaming\VMware
2016-09-08 20:49 - 2016-09-08 20:51 - 00000000 ____D C:\Users\Aleksandar\AppData\Local\VMware
2016-09-08 20:47 - 2016-04-14 17:17 - 00066752 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vmx86.sys
2016-09-08 20:47 - 2015-11-05 19:25 - 00075512 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vsock.sys
2016-09-08 20:47 - 2015-11-05 19:25 - 00068288 _____ (VMware, Inc.) C:\Windows\system32\vsocklib.dll
2016-09-08 20:47 - 2015-11-05 19:25 - 00064192 _____ (VMware, Inc.) C:\Windows\SysWOW64\vsocklib.dll
2016-09-08 20:46 - 2016-09-08 20:46 - 00001024 _____ C:\Windows\SysWOW64\%TMP%
2016-09-08 20:46 - 2016-04-14 17:17 - 00934080 _____ (VMware, Inc.) C:\Windows\system32\vnetlib64.dll
2016-09-08 20:46 - 2016-04-14 17:17 - 00392896 _____ (VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
2016-09-08 20:46 - 2016-04-14 17:17 - 00358080 _____ (VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
2016-09-08 20:46 - 2016-04-14 16:53 - 00026816 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vmnetuserif.sys
2016-09-08 20:46 - 2016-03-10 08:03 - 00057536 _____ (VMware, Inc.) C:\Windows\system32\Drivers\hcmon.sys
2016-09-08 20:45 - 2016-09-10 23:14 - 00000000 ____D C:\ProgramData\VMware
2016-09-08 20:45 - 2016-09-08 20:45 - 00731106 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2016-09-08 20:45 - 2016-09-08 20:45 - 00001203 _____ C:\Users\Public\Desktop\VMware Workstation Pro.lnk
2016-09-08 20:45 - 2016-09-08 20:45 - 00000000 ____D C:\Users\Public\Documents\Shared Virtual Machines
2016-09-08 20:45 - 2016-09-08 20:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VMware
2016-09-08 20:45 - 2016-09-08 20:45 - 00000000 ____D C:\Program Files\Common Files\VMware
2016-09-08 20:45 - 2016-09-08 20:45 - 00000000 ____D C:\Program Files (x86)\VMware
2016-09-08 20:01 - 2016-09-08 20:17 - 00000000 ____D C:\Users\Aleksandar\VirtualBox VMs
2016-09-08 20:00 - 2016-09-08 20:18 - 00000000 ____D C:\Users\Aleksandar\.VirtualBox
2016-09-08 19:59 - 2016-09-08 19:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
2016-09-08 19:59 - 2016-08-16 20:18 - 00920168 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxDrv.sys
2016-09-08 19:59 - 2016-08-16 20:18 - 00149256 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxUSBMon.sys
2016-09-08 19:22 - 2016-09-08 19:22 - 00000712 _____ C:\Users\Public\Desktop\Mask My IP.lnk
2016-09-08 19:22 - 2016-09-08 19:22 - 00000000 ____D C:\Users\Aleksandar\AppData\Roaming\MaskMyIP
2016-09-08 19:22 - 2016-09-08 19:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mask My IP
2016-09-08 19:22 - 2016-09-08 19:22 - 00000000 ____D C:\ProgramData\MaskMyIP
2016-09-08 16:02 - 2016-09-08 16:02 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2016-09-08 15:59 - 2016-09-08 16:01 - 00000000 ____D C:\Program Files (x86)\Adobe
2016-09-08 15:59 - 2016-09-08 15:59 - 00001519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS6.lnk
2016-09-08 15:59 - 2016-09-08 15:59 - 00001353 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS6.lnk
2016-09-08 15:57 - 2016-09-08 15:57 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2016-09-08 15:56 - 2016-09-08 16:01 - 00000000 ____D C:\Program Files\Common Files\Adobe
2016-09-08 15:56 - 2016-09-08 15:56 - 00000219 _____ C:\Users\Aleksandar\Desktop\Dota 2.url
2016-09-08 15:56 - 2016-09-08 15:56 - 00000000 ____D C:\Users\Aleksandar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2016-09-08 15:52 - 2016-09-09 10:39 - 00000000 ____D C:\Users\Aleksandar\AppData\Local\Adobe
2016-09-08 15:52 - 2016-09-08 16:02 - 00000000 ____D C:\ProgramData\Adobe
2016-09-08 15:52 - 2016-09-08 15:59 - 00000000 ____D C:\Users\Aleksandar\AppData\Roaming\Adobe
2016-09-08 15:52 - 2016-09-08 15:52 - 00000000 ____D C:\Users\Aleksandar\AppData\Roaming\Macromedia
2016-09-08 10:37 - 2016-09-09 15:47 - 00000000 ____D C:\Users\Aleksandar\Downloads\PopcornTime
2016-09-08 10:37 - 2016-09-08 10:37 - 00000000 ____D C:\Users\Aleksandar\AppData\Local\PopcornTimeDesktop
2016-09-08 07:57 - 2016-09-07 22:03 - 00000000 ____D C:\Windows\Panther
2016-09-08 07:00 - 2016-09-08 07:00 - 00001345 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2016-09-08 07:00 - 2016-09-08 07:00 - 00001326 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2016-09-08 06:59 - 2016-09-08 06:59 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2016-09-07 23:14 - 2016-09-07 23:15 - 00000000 ____D C:\Users\Aleksandar\Downloads\Microsoft Office Professional Plus 2010 with Service Pack 1 VL EN x86
2016-09-07 23:07 - 2016-09-10 22:27 - 00000000 ____D C:\Users\Aleksandar\AppData\LocalLow\uTorrent
2016-09-07 23:07 - 2016-09-07 23:19 - 00000000 ___SD C:\Users\Aleksandar\AppData\LocalLow\Temp
2016-09-07 23:02 - 2016-09-07 23:02 - 00000000 ____D C:\Users\Aleksandar\AppData\Local\Steam
2016-09-07 22:58 - 2016-09-07 22:58 - 00001197 _____ C:\Users\Public\Desktop\Popcorn Time.lnk
2016-09-07 22:58 - 2016-09-07 22:58 - 00000720 _____ C:\Users\Public\Desktop\Notepad++.lnk
2016-09-07 22:58 - 2016-09-07 22:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Popcorn Time
2016-09-07 22:58 - 2016-09-07 22:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++
2016-09-07 22:58 - 2016-09-07 22:58 - 00000000 ____D C:\Program Files (x86)\Popcorn Time
2016-09-07 22:57 - 2016-09-08 17:56 - 00000000 ____D C:\Users\Aleksandar\AppData\Roaming\Notepad++
2016-09-07 22:56 - 2016-09-07 22:56 - 00000680 _____ C:\Users\Public\Desktop\Steam.lnk
2016-09-07 22:56 - 2016-09-07 22:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2016-09-07 22:54 - 2016-09-10 23:15 - 00000000 ____D C:\Users\Aleksandar\AppData\Roaming\Skype
2016-09-07 22:54 - 2016-09-07 22:54 - 00002697 _____ C:\Users\Public\Desktop\Skype.lnk
2016-09-07 22:54 - 2016-09-07 22:54 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-09-07 22:54 - 2016-09-07 22:54 - 00000000 ____D C:\Users\Aleksandar\Tracing
2016-09-07 22:54 - 2016-09-07 22:54 - 00000000 ____D C:\ProgramData\Skype
2016-09-07 22:54 - 2016-09-07 22:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2016-09-07 22:53 - 2016-09-07 22:53 - 00000000 ____D C:\Users\Aleksandar\AppData\Roaming\Sun
2016-09-07 22:53 - 2016-09-07 22:53 - 00000000 ____D C:\Users\Aleksandar\AppData\LocalLow\Sun
2016-09-07 22:52 - 2016-09-07 22:52 - 00110144 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2016-09-07 22:52 - 2016-09-07 22:52 - 00000000 ____D C:\ProgramData\Oracle
2016-09-07 22:52 - 2016-09-07 22:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-09-07 22:52 - 2016-09-07 22:52 - 00000000 ____D C:\Program Files\Java
2016-09-07 22:49 - 2016-09-07 22:49 - 00003922 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2016-09-07 22:49 - 2016-09-07 22:49 - 00002622 _____ C:\Users\Aleksandar\Desktop\µTorrent.lnk
2016-09-07 22:49 - 2016-09-07 22:49 - 00002622 _____ C:\Users\Aleksandar\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2016-09-07 22:49 - 2016-09-07 22:49 - 00001922 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2016-09-07 22:49 - 2016-09-07 22:49 - 00000000 ____D C:\Windows\System32\Tasks\AVAST Software
2016-09-07 22:49 - 2016-09-07 22:49 - 00000000 ____D C:\Users\Aleksandar\AppData\Roaming\AVAST Software
2016-09-07 22:49 - 2016-09-07 22:49 - 00000000 ____D C:\Users\Aleksandar\AppData\Local\CEF
2016-09-07 22:49 - 2016-09-07 22:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2016-09-07 22:49 - 2016-09-07 22:49 - 00000000 ____D C:\Program Files\Common Files\AV
2016-09-07 22:49 - 2016-09-07 22:48 - 00969560 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2016-09-07 22:49 - 2016-09-07 22:48 - 00513496 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2016-09-07 22:49 - 2016-09-07 22:48 - 00292704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2016-09-07 22:49 - 2016-09-07 22:48 - 00163416 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2016-09-07 22:49 - 2016-09-07 22:48 - 00108816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2016-09-07 22:49 - 2016-09-07 22:48 - 00103064 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2016-09-07 22:49 - 2016-09-07 22:48 - 00074544 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2016-09-07 22:49 - 2016-09-07 22:48 - 00037656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2016-09-07 22:48 - 2016-09-10 23:03 - 00000000 ____D C:\Users\Aleksandar\AppData\Roaming\uTorrent
2016-09-07 22:48 - 2016-09-07 22:48 - 00992960 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2016-09-07 22:48 - 2016-09-07 22:48 - 00921280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2016-09-07 22:48 - 2016-09-07 22:48 - 00391496 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2016-09-07 22:48 - 2016-09-07 22:48 - 00053208 _____ (AVAST Software) C:\Windows\avastSS.scr
2016-09-07 22:48 - 2016-09-07 22:48 - 00000000 ____D C:\ProgramData\AVAST Software
2016-09-07 22:48 - 2016-09-07 22:48 - 00000000 ____D C:\Program Files\AVAST Software
2016-09-07 22:44 - 2016-09-07 22:44 - 00000871 _____ C:\Users\Public\Desktop\VLC media player.lnk
2016-09-07 22:44 - 2016-09-07 22:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2016-09-07 22:44 - 2016-09-07 22:44 - 00000000 ____D C:\Program Files\VideoLAN
2016-09-07 22:43 - 2016-09-07 22:43 - 00002810 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2016-09-07 22:43 - 2016-09-07 22:43 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk
2016-09-07 22:43 - 2016-09-07 22:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2016-09-07 22:43 - 2016-09-07 22:43 - 00000000 ____D C:\Program Files\CCleaner
2016-09-07 22:35 - 2016-07-26 14:24 - 00504488 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2016-09-07 22:15 - 2016-09-07 22:15 - 00000000 ____D C:\Users\Aleksandar\AppData\Roaming\WinRAR
2016-09-07 22:15 - 2016-09-07 22:15 - 00000000 ____D C:\Users\Aleksandar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-09-07 22:15 - 2016-09-07 22:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-09-07 22:15 - 2016-09-07 22:15 - 00000000 ____D C:\Program Files\WinRAR
2016-09-07 22:12 - 2016-09-07 22:21 - 00000000 ____D C:\Users\Aleksandar\AppData\Local\Mozilla
2016-09-07 22:12 - 2016-09-07 22:13 - 00000000 ____D C:\Users\Aleksandar\AppData\Roaming\Mozilla
2016-09-07 22:12 - 2016-09-07 22:12 - 00001159 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-09-07 22:12 - 2016-09-07 22:12 - 00001147 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-09-07 22:12 - 2016-09-07 22:12 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-09-07 22:12 - 2016-09-07 22:12 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-09-07 22:10 - 2016-09-08 19:47 - 00057560 _____ C:\Users\Aleksandar\AppData\Local\GDIPFONTCACHEV1.DAT
2016-09-07 22:10 - 2016-09-07 22:10 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-09-07 22:10 - 2016-09-07 22:10 - 00000000 ____D C:\Program Files (x86)\Realtek WLAN Driver
2016-09-07 22:10 - 2011-06-20 17:07 - 01225832 _____ (Realtek Semiconductor Corporation ) C:\Windows\system32\Drivers\rtl8192se.sys
2016-09-07 22:10 - 2011-04-22 13:42 - 01143400 _____ (Realtek Semiconductor Corporation ) C:\Windows\system32\Drivers\rtl8192ce.sys
2016-09-07 22:10 - 2010-12-22 16:24 - 00626792 _____ (Realtek Semiconductor Corporation ) C:\Windows\system32\Drivers\rtl819xp.sys
2016-09-07 22:10 - 2010-12-01 09:31 - 00451072 _____ C:\Windows\SysWOW64\ISSRemoveSP.exe
2016-09-07 22:10 - 2010-04-01 14:01 - 00442368 _____ (Realtek Semiconductor Corporation ) C:\Windows\system32\Drivers\rtl8187Se.sys
2016-09-07 22:10 - 2010-03-31 11:10 - 00450048 _____ (Realtek Semiconductor Corporation ) C:\Windows\system32\Drivers\rtl8187B.sys
2016-09-07 22:09 - 2016-09-07 22:09 - 00003492 _____ C:\Windows\System32\Tasks\ConfigFree Startup Programs
2016-09-07 22:09 - 2016-09-07 22:09 - 00000000 ____D C:\Users\Aleksandar\AppData\Local\Toshiba
2016-09-07 22:09 - 2016-09-07 22:09 - 00000000 ____D C:\ProgramData\Toshiba
2016-09-07 22:09 - 2016-09-07 22:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TOSHIBA
2016-09-07 22:09 - 2016-09-07 22:09 - 00000000 ____D C:\Program Files (x86)\TOSHIBA
2016-09-07 22:08 - 2016-09-07 22:08 - 00000000 ____D C:\Program Files (x86)\Intel
2016-09-07 22:08 - 2009-11-18 16:03 - 00053248 _____ (Windows XP Bundled build C-Centric Single User) C:\Windows\SysWOW64\CSVer.dll
2016-09-07 22:07 - 2016-09-07 22:08 - 00000000 ____D C:\Intel
2016-09-07 22:07 - 2016-09-07 22:07 - 00000000 ____D C:\Users\Aleksandar\AppData\Roaming\WinBatch
2016-09-07 22:04 - 2016-09-08 10:37 - 00000000 ____D C:\Users\Aleksandar\AppData\Local\VirtualStore
2016-09-07 22:04 - 2016-09-07 22:04 - 00001443 _____ C:\Users\Aleksandar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-09-07 22:04 - 2016-09-07 22:04 - 00001409 _____ C:\Users\Aleksandar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2016-09-07 22:03 - 2016-09-08 20:01 - 00000000 ____D C:\Users\Aleksandar
2016-09-07 22:03 - 2016-09-07 22:03 - 00000020 ___SH C:\Users\Aleksandar\ntuser.ini
2016-09-07 22:03 - 2016-09-07 22:03 - 00000000 _SHDL C:\Users\Aleksandar\My Documents
2016-09-07 22:03 - 2016-09-07 22:03 - 00000000 _SHDL C:\Users\Aleksandar\Documents\My Videos
2016-09-07 22:03 - 2016-09-07 22:03 - 00000000 _SHDL C:\Users\Aleksandar\Documents\My Pictures
2016-09-07 22:03 - 2016-09-07 22:03 - 00000000 _SHDL C:\Users\Aleksandar\Documents\My Music
2016-09-07 22:03 - 2009-07-14 09:45 - 00000000 ____D C:\Users\Aleksandar\AppData\Roaming\Media Center Programs
2016-08-16 20:18 - 2016-08-16 20:18 - 00195936 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxNetLwf.sys
2016-08-16 20:18 - 2016-08-16 20:18 - 00121248 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxNetAdp6.sys

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-09-10 23:20 - 2009-07-14 07:13 - 00730464 _____ C:\Windows\system32\PerfStringBackup.INI
2016-09-10 23:20 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf
2016-09-10 23:14 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-09-09 10:38 - 2009-07-14 06:45 - 04891888 _____ C:\Windows\system32\FNTCACHE.DAT
2016-09-08 15:57 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2016-09-08 15:46 - 2009-07-14 06:45 - 00009600 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-09-08 15:46 - 2009-07-14 06:45 - 00009600 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-09-08 07:56 - 2009-07-14 07:32 - 00028672 _____ C:\Windows\system32\config\BCD-Template
2016-09-08 07:00 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\sysprep
2016-09-08 06:58 - 2009-07-14 09:46 - 00000000 ____D C:\Windows\CSC
2016-09-07 22:15 - 2009-07-14 01:56 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\systemcpl.dll
2016-09-07 22:15 - 2009-07-14 01:52 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\slwga.dll
2016-09-07 22:15 - 2009-07-14 01:38 - 01008640 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2016-09-07 22:15 - 2009-07-14 01:36 - 00013824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\slwga.dll
2016-09-07 22:15 - 2009-07-14 01:24 - 00833024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2016-09-07 22:04 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache

Some files in TEMP:
====================
C:\Users\Aleksandar\AppData\Local\Temp\xmlUpdater.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll
[2009-07-14 01:38] - [2016-09-07 22:15] - 1008640 ____A (Microsoft Corporation) 2C353B6CE0C8D03225CAA2AF33B68D79

C:\Windows\SysWOW64\User32.dll
[2009-07-14 01:24] - [2016-09-07 22:15] - 0833024 ____A (Microsoft Corporation) 861C4346F9281DC0380DE72C8D55D6BE

C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-09-07 23:32

==================== End of FRST.txt ============================

offline
  • Pridružio: 02 Jan 2008
  • Poruke: 2167

Pozdrav!

Reci mi, da li su ti kojim slucajem fajlovi na racunaru sifrovani i da li imas backup (rezervnu kopiju) fajlova?

offline
  • Student by day. Hacker by night
  • Pridružio: 11 Maj 2014
  • Poruke: 189
  • Gde živiš: 192.168.0.1

Mislis na neki odredjeni fajl dal je sifrovan ili?
Mislim da imam samo jedan. A rezervnu kopiju kojih fajlova ( ovih sto sam ih ja ubacio ili)?
Izvini ali nisam te bas najbolje razumeo.

offline
  • Pridružio: 02 Jan 2008
  • Poruke: 2167

Ransomware je u pitanju, zato pitam da li imas sifrovane fajlove ili ne.

Zamolio bih te da taj sifrovani fajl zipujes i uploadujes preko ovog linka: http://www.mycity.rs/ambulanta-upload.php

Sto se tice rezervne kopije, mislio sam da li imas rezervne kopije tebi bitnih fajlova i najbitnije, da li imas rezervnu kopiju tog sifrovanog fajla?

offline
  • Student by day. Hacker by night
  • Pridružio: 11 Maj 2014
  • Poruke: 189
  • Gde živiš: 192.168.0.1

To je nesto da nazovem " poverljivo " da li mogu u PM da ti posaljem?

offline
  • Pridružio: 02 Jan 2008
  • Poruke: 2167

Mozes slobodno uploadovati fajl preko linka odozgo, posto se na link koji sam ti dao postavljaju samo inficirani ili fajlovi bitni za AMF tim tj. bitni za resavanje problema korisnika u Ambulanti.

Naravno, fajl nece biti deljen niti koriscen niti mu treca lica (ostali clanovi foruma) mogu pristupiti, vec samo zelimo biti sigurni koja ransomware infekcija je u pitanju.

Jos jednom, govorimo o tome da posaljes sifrovani fajl.

Ako i dalje ne zelis da posaljes fajl, u redu, tvoja odluka Smile

offline
  • Student by day. Hacker by night
  • Pridružio: 11 Maj 2014
  • Poruke: 189
  • Gde živiš: 192.168.0.1

Ovaj fajl ima 23mb. A ovamo pise max je 10mb. Nije kriptovan fajl mislio sam da jeste izvini, ali mislim da je on uzrok svemu ovome. Pa hocu da ocistim lepo sve.
Da uploadujem negde drugde?

offline
  • Pridružio: 02 Jan 2008
  • Poruke: 2167

Nista, nema potrebe da saljes fajl, posto nije sifrovan fajl.

1. Otvori Notepad (Text Document) i iskopiraj sledeći tekst unutar kod polja ispod:

CreateRestorePoint:
() C:\Users\Aleksandar\AppData\Local\Drpbx\drpbx.exe
HKU\S-1-5-21-2643023827-58587059-3105705347-1000\...\Run: [firefox.exe] => C:\Users\Aleksandar\AppData\Roaming\Frfx\firefox.exe [290816 2016-08-03] ()
2016-09-10 23:16 - 2016-09-10 23:16 - 00000000 ____D C:\Users\Aleksandar\AppData\Roaming\Frfx
2016-09-10 23:16 - 2016-09-10 23:16 - 00000000 ____D C:\Users\Aleksandar\AppData\Local\Drpbx
2016-09-10 23:16 - 2016-08-03 17:25 - 00290816 _____ () C:\Users\Aleksandar\AppData\Local\Drpbx\drpbx.exe


2. Sačuvaj notepad na Desktop pod nazivom fixlist.txt
To možes uraditi i iz notepad-a => klik na File potom na Save As i u novom prozoru, dole pod File Name: staviš za naziv fixlist.txt
Napomena: Važno je da se oba fajla, FRST i fixlist nalaze na istoj lokaciji jer u suprotnom fix nece raditi.

3. Ponovo pokreni FRST/FRST64, klikni jednom na dugme Fix i sačekaj.
Ukoliko alat zatraži restart sistema, dozvoli mu i postaraj se da alat kompletira fix nakon restarta sistema.



Alat će formirati log (Fixlog.txt) na Desktop-u. Potrebno je sadržaj tog loga iskopirati u poruku.
Napomena: Ukoliko te alat upozori da postoji novija verzija, postaraj se da preuzmes i koristiš ažuriranu kopiju FRST-a.


Potom, pokreni FRST i klikni na Search Files(s).

Nakon toga, u "Search:" polje kopiraj ovo:
User*.bin;User32.dll
i potom ponovo klikni na Search Files(s).

Nakon zavrsene pretrage, dobices i Search.txt izvestaj koji ces mi dostaviti ovde, zajedno sa Fixlog.txt izvestajem.

offline
  • Student by day. Hacker by night
  • Pridružio: 11 Maj 2014
  • Poruke: 189
  • Gde živiš: 192.168.0.1

Izvoli fixlog i search.
mycity.rs/must-login.png

mycity.rs/must-login.png

offline
  • Pridružio: 02 Jan 2008
  • Poruke: 2167

1. Otvori Notepad (Text Document) i iskopiraj sledeći tekst unutar kod polja ispod:

Replace: C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll C:\Windows\SysWOW64\user32.dll
Replace: C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll C:\Windows\System32\user32.dll


2. Sačuvaj notepad na Desktop pod nazivom fixlist.txt
To možes uraditi i iz notepad-a => klik na File potom na Save As i u novom prozoru, dole pod File Name: staviš za naziv fixlist.txt
Napomena: Važno je da se oba fajla, FRST i fixlist nalaze na istoj lokaciji jer u suprotnom fix nece raditi.

3. Ponovo pokreni FRST/FRST64, klikni jednom na dugme Fix i sačekaj.
Ukoliko alat zatraži restart sistema, dozvoli mu i postaraj se da alat kompletira fix nakon restarta sistema.



Alat će formirati log (Fixlog.txt) na Desktop-u. Potrebno je sadržaj tog loga iskopirati u poruku.
Napomena: Ukoliko te alat upozori da postoji novija verzija, postaraj se da preuzmes i koristiš ažuriranu kopiju FRST-a.

Ko je trenutno na forumu
 

Ukupno su 1047 korisnika na forumu :: 17 registrovanih, 2 sakrivenih i 1028 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 1591 - dana 17 Sep 2019 09:01

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: ALBION101, antonic.igor2050, Atomski čoban, dane007, Dusko Nikolin, duskovuk63, dzenan_y, Gama, hs14021993, ltcolonel, Mixelotti, Raptor12, saputnik plavetnila, Shufle, slonic_tonic, wizzardone, wolverined4