Sporo radi, muči se!

1

Sporo radi, muči se!

offline
  • Pridružio: 01 Nov 2008
  • Poruke: 87
  • Gde živiš: Kragujevac

Zdravo ljudi,
Imam problem, mnogo mi se usporio komp, ram memoriju nešto mnogo jede, računar se muči i ako ništa nisam pokrenuo. Želim da vidite o čemu se radi, da očistimo to. Zagrljaj
To mi se dešava možda zadnjih mesec dana. GUZ - Glavom U Zid
Brzina interneta je 3mbps. (IPTV) Wink

DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 10.45.2
Run by DJ Sone at 18:15:28 on 2014-01-11
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.381.1033.18.2047.503 [GMT 1:00]
.
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe
C:\Windows\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Windows\vsnp2uvc.exe
C:\Program Files\Common Files\SNP2UVC\tsnp2uvc.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Google\Update\1.3.22.3\GoogleCrashHandler.exe
C:\Program Files\PANDORA.TV\PanService\KMPService.exe
C:\Program Files\PANDORA.TV\PanService\KMPProcess.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe
C:\Program Files\Aurora\firefox.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Aurora\plugin-container.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_9_900_152.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_9_900_152.exe
C:\Users\DJSONE~1\AppData\Local\Temp\nssC840.tmp\nsCFEE.tmp
C:\Windows\system32\conhost.exe
C:\Users\DJSONE~1\AppData\Local\Temp\nssC840.tmp\MBR.DAT
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Start Menu X\StartMenuX.exe
C:\Windows\system32\mmc.exe
C:\Windows\System32\vdsldr.exe
C:\Windows\System32\vds.exe
C:\Windows\system32\taskmgr.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.myhoome.com/
uDefault_Page_URL = hxxp://www.myhoome.com/
mStart Page = hxxp://www.myhoome.com/
mDefault_Page_URL = hxxp://www.myhoome.com/
BHO: Avira SearchFree Toolbar: {41564952-412D-5637-00A7-7A786E7484D7} -
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - c:\program files\windows live\companion\companioncore.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
TB: Avira SearchFree Toolbar: {41564952-412D-5637-00A7-7A786E7484D7} -
TB: Avira SearchFree Toolbar: {41564952-412D-5637-00A7-7A786E7484D7} -
uRun: [iLivid] "c:\users\dj sone\appdata\local\ilivid\iLivid.exe" -autorun
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /minimized /regrun
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [StartMenuX] c:\program files\start menu x\StartMenuX.exe
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [ApnTBMon] "c:\program files\askpartnernetwork\toolbar\updater\TBNotifier.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE -startup
mRun: [RTHDVCPL] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [snp2uvc] c:\windows\vsnp2uvc.exe
mRun: [tsnp2uvc] c:\program files\common files\snp2uvc\tsnp2uvc.exe
StartupFolder: c:\users\djsone~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\bitcoin.lnk - c:\users\dj sone\desktop\bitcoin-0.8.5-win32\bitcoin-qt.exe
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{F37E809D-9287-4DDB-89F1-19A7C727FB16} : DHCPNameServer = 192.168.1.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\31.0.1650.63\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\dj sone\appdata\roaming\mozilla\firefox\profiles\ijimues6.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.myhoome.com/
FF - plugin: c:\program files\google\update\1.3.22.3\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre7\bin\dtplugin\npdeployJava1.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.50401.0\npctrlui.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_9_900_152.dll
.
============= SERVICES / DRIVERS ===============
.
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [2013-10-25 37352]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-3-9 176128]
R2 AMD FUEL Service;AMD FUEL Service;c:\program files\ati technologies\ati.ace\fuel\Fuel.Service.exe [2011-3-9 294400]
R2 AMD Reservation Manager;AMD Reservation Manager;c:\program files\ati technologies\ati.ace\reservation manager\AMD Reservation Manager.exe [2010-6-17 140224]
R2 AntiVirSchedulerService;Avira Scheduler;c:\program files\avira\antivir desktop\sched.exe [2013-10-25 440376]
R2 AntiVirService;Avira Real-Time Protection;c:\program files\avira\antivir desktop\avguard.exe [2013-10-25 440376]
R2 AntiVirWebService;Avira Web Protection;c:\program files\avira\antivir desktop\avwebg7.exe [2013-10-25 1011768]
R2 APNMCP;Ask Update Service;c:\program files\askpartnernetwork\toolbar\apnmcp.exe [2013-12-20 166352]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2013-10-25 90400]
R2 avnetflt;avnetflt;c:\windows\system32\drivers\avnetflt.sys [2013-10-25 69240]
R2 PanService;PandoraService;c:\program files\pandora.tv\panservice\KMPService.exe [2013-10-25 1922600]
R3 amdiox86;AMD IO Driver;c:\windows\system32\drivers\amdiox86.sys [2013-10-25 37944]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [2013-10-25 101392]
R3 SrvHsfPCI;SrvHsfPCI;c:\windows\system32\drivers\VSTBS23.SYS [2009-7-13 266752]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\drivers\VSTDPV3.SYS [2009-7-13 980992]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\drivers\VSTCNXT3.SYS [2009-7-13 661504]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2012-4-30 104872]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2013-10-23 172192]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\microsoft sql server\100\shared\sqladhlp.exe [2009-7-23 47128]
S4 RsFx0103;RsFx0103 Driver;c:\windows\system32\drivers\RsFx0103.sys [2009-3-30 239336]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\microsoft sql server\mssql10.sqlexpress\mssql\binn\SQLAGENT.EXE [2009-3-30 366936]
.
=============== Created Last 30 ================
.
2014-01-11 16:59:26 -------- d-----w- c:\users\dj sone\appdata\roaming\StartMenuX
2014-01-11 16:59:26 -------- d-----w- c:\programdata\StartMenuX
2014-01-11 16:59:26 -------- d-----w- c:\program files\Start Menu X
2014-01-11 03:30:39 -------- d-----w- c:\users\dj sone\appdata\local\{FFAD36CF-C450-4878-8ABC-E5E50633528B}
2014-01-08 18:14:01 -------- d-----w- c:\program files\Aurora
2014-01-07 08:16:42 -------- d-----w- c:\users\dj sone\appdata\local\{7ABA22A7-6EE9-4905-A3C3-56917F0137D1}
2014-01-07 08:16:38 -------- d-----w- c:\users\dj sone\appdata\local\{77AB4EC4-1A3B-48E8-91BE-0AF7D097A3E1}
2014-01-07 08:15:46 -------- d-----w- c:\users\dj sone\Tracing
2014-01-05 21:48:07 -------- d-----r- c:\program files\Skype
2013-12-30 17:44:26 -------- d-----w- c:\users\dj sone\appdata\local\Temporary Projects
2013-12-30 16:37:42 50200 ----a-w- c:\windows\system32\perf-SQLAgent$SQLEXPRESS-sqlagtctr10.1.2531.0.dll
2013-12-30 16:37:12 79896 ----a-w- c:\windows\system32\perf-MSSQL$SQLEXPRESS-sqlctr10.1.2531.0.dll
2013-12-30 16:35:19 -------- d-----w- c:\windows\system32\RsFx
2013-12-30 16:33:13 -------- d-----w- c:\windows\system32\1033
2013-12-30 16:23:27 -------- d-----w- c:\program files\Microsoft SQL Server
2013-12-30 16:22:56 -------- d-----w- c:\program files\Microsoft Synchronization Services
2013-12-30 16:22:55 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2013-12-30 16:22:22 188128 ----a-w- c:\programdata\microsoft\vcsexpress\10.0\1033\ResourceCache.dll
2013-12-30 16:19:46 -------- d-----w- c:\program files\Microsoft Visual Studio 10.0
2013-12-30 16:19:46 -------- d-----w- c:\program files\Microsoft Help Viewer
2013-12-29 21:17:16 -------- d-----w- c:\program files\Dev-C++
2013-12-27 15:19:45 -------- d-----w- c:\users\dj sone\.jmc
2013-12-27 15:19:33 -------- d-----w- c:\users\dj sone\.eclipse
2013-12-27 14:44:34 -------- d-----w- c:\program files\WiFi Password Revealer
2013-12-25 16:53:16 -------- d-----w- c:\users\dj sone\appdata\local\WMTools Downloaded Files
2013-12-25 16:47:24 -------- d-----w- c:\program files\Movie Maker 2.6
2013-12-17 20:27:09 18944 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\mdippr.dll
2013-12-17 20:27:08 17920 ----a-w- c:\windows\system32\mdimon.dll
2013-12-17 20:26:03 -------- d-----w- c:\program files\Microsoft ActiveSync
.
==================== Find3M ====================
.
2013-12-18 18:12:20 90400 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-12-18 18:12:20 69240 ----a-w- c:\windows\system32\drivers\avnetflt.sys
2013-11-19 17:45:26 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-11-19 17:45:26 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-11-05 13:14:09 138184 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2013-11-05 13:13:57 183112 ----a-w- c:\windows\system32\PnkBstrB.exe
2013-10-30 19:12:41 66872 ----a-w- c:\windows\system32\PnkBstrA.exe
2013-10-25 15:41:22 0 ----a-w- c:\windows\ativpsrm.bin
.
============= FINISH: 18:16:03,66 ===============


mycity.rs/must-login.png

offline
  • Pridružio: 09 Avg 2011
  • Poruke: 15879
  • Gde živiš: Beograd

Pozdrav,



Preuzmi sUBs-ov ComboFix sa sledeće adrese na Desktop:


Bleeping Computer
Klikni desnim tasterom na link i odaberi opciju Save Target As... (Save Link As..., Save Linked Content As... ili sličnu);
Kada se otvori dijalog za izbor lokacije na kojoj treba sačuvati file, odaberi Desktop i klikni Save.




Kada preuzimanje programa bude završeno:
deaktiviraj zaštitni softver (uputstvo);
zatvori pokrenute programe;
dvoklikom pokreni program ComboFix;
u prozoru koji se otvori klikni "I Agree".

U toku rada, ComboFix će:proveriti postoji li novija verzija programa:
klikni Yes ako bude ponuđeno preuzimanje iste.
ako Recovery Console nije instalirana, ponuditi instalaciju:
obavezno prihvati klikom na Yes i isprati postupak.
postaviti/dati određeni broj upita/obaveštenja:
prihvati klikom na Yes ili OK.
po potrebi, restartovati Windows (više puta);
na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.


Iskopiraj izveštaj koji je ComboFix napravio u temu na forumu:
klikni desnim tasterom miša u prozor Notepad-a i izaberi Select All;
klikni desnim tasterom miša na obeleženi tekst i izaberi Copy;
klikni desnim tasterom miša u polje za pisanje poruke i izaberi Paste.



Napomena:Izveštaj će biti sačuvan pod nazivom ComboFix.txt na sistemskoj particiji (tipična lokacija: C:\ComboFix.txt);
Ukoliko nakon slanja poruke primetiš da izveštaj nije kompletan, iskoristi opciju Prikači fajl za prilaganje file-a C:\ComboFix.txt uz poruku;
Nemoj kliktati u okviru ComboFix prozora dok radi jer to može usporiti rad alata;
Nemoj ponovo pokretati ComboFix na svoju ruku - javi se u temi bilo kakav problem da imaš tokom prvog pokretanja alata;
Ako nakon restarta dobijaš grešku prilikom startovanja pojedinih programa da su označeni za brisanje (Illegal operation attempted on a registry key that has been marked for deletion), onda ponovo restartuj sistem i to ce rešiti problem.

offline
  • Pridružio: 01 Nov 2008
  • Poruke: 87
  • Gde živiš: Kragujevac

Probao sam večeras par puta, otvorim ComboFix, radi.. Ali kada restartuje računar, ponovo startuje ne pojavljuje se više ništa. Kao da ne pamti šta je započeo. Da li se to dešavalo bilo kome, možda znate iz iskustva..? Ne znam.

offline
  • Pridružio: 09 Avg 2011
  • Poruke: 15879
  • Gde živiš: Beograd

Kazi mi detaljno sta se desi kada pokrenes ComboFix, da li si ugasio antivirus?

offline
  • Pridružio: 01 Nov 2008
  • Poruke: 87
  • Gde živiš: Kragujevac

Jesam ako misliš na donju desnu stranu, sve sam pogasio. Radi ComboFix, startuje radi ali u procesu restarta, ne otvara log na kraju, nista.

offline
  • Pridružio: 09 Avg 2011
  • Poruke: 15879
  • Gde živiš: Beograd

Pogledaj da li mozda na C particiji ima ComboFix izvestaj ili unutar Qoobox foldera...

offline
  • Pridružio: 01 Nov 2008
  • Poruke: 87
  • Gde živiš: Kragujevac

U Qoobox-u, nema, tražio sam svuda Log, nema ga, stvarno ga nema!
Startovao sam ComboFix još par puta isto, podigne system i na tome se završi.
Mada kada mi se rastartuje kompjuter, traži F1 da stisnem da bi ga startovao. CPU ERROR, tako piše i da stisnem F1. Ali ok radi ovako podigne se system radi sve ok malo usporeno ali radi. Ne razumem zašto ComboFix neće.

offline
  • Pridružio: 09 Avg 2011
  • Poruke: 15879
  • Gde živiš: Beograd

OK, idemo sa drugim alatom

Preuzmi Farbar-ov Farbar Recovery Scan Tool () sa ove adrese na Desktop:
Postoji 32bit. i 64bit.-na verzija. Potrebno je preuzeti verziju koja je kompatibilna sa tvojim sistemom.
Ako nisi siguran koja verzija se odnosi na tvoj sistem, preuzmi ih obe i pokreni. Samo jedan od njih će raditi na tvom sistemu, to će biti prava verzija.


dvoklikom pokreni program, kada se alat pokrene klikni Yes na disclaimer prozor;
pričekati koji trenutak dok alat proverava postoji li novija verzija;
klikni na dugme Scan;
po završetku skeniranja, alat će formirati izveštaj (FRST.txt) u isti direktorijum gde je FRST alat sačuvan;
iskopiraj sadržaj FRST.txt izveštaja u poruku;
po prvom pokretanju, alat bi trebao formirati i dodatni izveštaj (Addition.txt);
okači Addition.txt izveštaj uz poruku koristeći opciju Prikači fajl

offline
  • Pridružio: 01 Nov 2008
  • Poruke: 87
  • Gde živiš: Kragujevac

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-01-2014 01
Ran by DJ Sone (administrator) on DJSONE-PC on 12-01-2014 20:56:03
Running from C:\Users\DJ Sone\Desktop
Microsoft Windows 7 Ultimate (X86) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Advanced Micro Devices) C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
(Pandora.TV) C:\Program Files\PANDORA.TV\PanService\KMPService.exe
(PandoraTV) C:\Program Files\PANDORA.TV\PanService\KMPProcess.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Google Inc.) C:\Program Files\Google\Update\1.3.22.3\GoogleCrashHandler.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Sonix Technology Co., Ltd.) C:\Program Files\Common Files\SNP2UVC\tsnp2uvc.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(OrdinarySoft) C:\Program Files\Start Menu X\StartMenuX.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Mozilla Corporation) C:\Program Files\Aurora\firefox.exe
(Mozilla Corporation) C:\Program Files\Aurora\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_9_900_152.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_9_900_152.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-03-08] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-18] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [11930696 2013-03-29] (Realtek Semiconductor)
HKLM\...\Run: [tsnp2uvc] - C:\Program Files\Common Files\SNP2UVC\tsnp2uvc.exe [322560 2012-02-23] (Sonix Technology Co., Ltd.)
HKCU\...\Run: [StartMenuX] - C:\Program Files\Start Menu X\StartMenuX.exe [5379392 2013-11-20] (OrdinarySoft)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = myhoome.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x40F3819319EBCE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = sr-rs
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = myhoome.com/
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = myhoome.com/
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = myhoome.com/
BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
Toolbar: HKCU - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\DJ Sone\AppData\Roaming\Mozilla\Firefox\Profiles\ijimues6.default
FF Homepage: hxxp://www.myhoome.com/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_152.dll ()
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF StartMenuInternet: FIREFOX.EXE - C:\Program Files\Aurora\firefox.exe

Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR RestoreOnStartup: "hxxp://www.myhoome.com/"
CHR Extension: (Google Docs) - C:\Users\DJ Sone\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 [2013-10-25]
CHR Extension: (Google Drive) - C:\Users\DJ Sone\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 [2013-10-25]
CHR Extension: (YouTube) - C:\Users\DJ Sone\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 [2013-10-25]
CHR Extension: (Google Search) - C:\Users\DJ Sone\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 [2013-10-25]
CHR Extension: (Google Wallet) - C:\Users\DJ Sone\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0 [2013-12-23]
CHR Extension: (Winter Night in Moonlight) - C:\Users\DJ Sone\AppData\Local\Google\Chrome\User Data\Default\Extensions\offcedjaceddaegkpebcocccakpdjkin\1_0 [2013-10-25]
CHR Extension: (WebSite Recommendation) - C:\Users\DJ Sone\AppData\Local\Google\Chrome\User Data\Default\Extensions\olakgnkoldmagdblaalodobkmeokmgjj\2.4_0 [2013-12-27]
CHR Extension: (Gmail) - C:\Users\DJ Sone\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1 [2013-10-25]

========================== Services (Whitelisted) =================

R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [294400 2011-03-09] (Advanced Micro Devices, Inc.)
R2 AMD Reservation Manager; C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe [140224 2010-06-17] (Advanced Micro Devices)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-12-18] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe [1011768 2013-12-18] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-12-20] (APN LLC.)
R2 PanService; C:\Program Files\PANDORA.TV\PanService\KMPService.exe [1922600 2013-07-08] (Pandora.TV)

==================== Drivers (Whitelisted) ====================

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-09-30] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [69240 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 SCDEmu; C:\Windows\System32\Drivers\SCDEmu.sys [113608 2013-01-27] (Power Software Ltd)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [3565952 2011-09-09] ()
R3 SrvHsfPCI; C:\Windows\System32\DRIVERS\VSTBS23.SYS [266752 2009-07-13] (Conexant Systems, Inc.)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-09-30] (Avira GmbH)
S3 AODDriver4.0; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [x]
S3 catchme; \??\C:\Users\DJSONE~1\AppData\Local\Temp\catchme.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-01-12 20:56 - 2014-01-12 20:56 - 00009769 _____ C:\Users\DJ Sone\Desktop\FRST.txt
2014-01-12 20:55 - 2014-01-12 20:55 - 00000000 ____D C:\FRST
2014-01-12 20:54 - 2014-01-12 20:54 - 01219584 _____ (Farbar) C:\Users\DJ Sone\Desktop\FRST.exe
2014-01-12 20:51 - 2014-01-12 20:51 - 00368640 _____ C:\Windows\Minidump\011214-17082-01.dmp
2014-01-12 19:19 - 2014-01-12 19:20 - 00000000 ___SD C:\ComboFix
2014-01-12 19:19 - 2014-01-12 19:19 - 00000000 ____D C:\Qoobox
2014-01-12 19:17 - 2014-01-12 19:18 - 05164834 ____R (Swearware) C:\Users\DJ Sone\Desktop\ComboFix.exe
2014-01-12 18:44 - 2014-01-12 18:45 - 00368640 _____ C:\Windows\Minidump\011214-16754-01.dmp
2014-01-12 04:06 - 2014-01-12 04:06 - 00368640 _____ C:\Windows\Minidump\011214-16816-01.dmp
2014-01-11 20:37 - 2014-01-11 20:37 - 00367944 _____ C:\Windows\Minidump\011114-17238-01.dmp
2014-01-11 19:55 - 2014-01-11 19:55 - 00000000 ____D C:\Windows\erdnt
2014-01-11 19:55 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe
2014-01-11 19:55 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe
2014-01-11 19:55 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-01-11 19:55 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-01-11 19:55 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-01-11 19:55 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe
2014-01-11 19:55 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe
2014-01-11 19:55 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe
2014-01-11 19:22 - 2014-01-11 19:23 - 00000000 ____D C:\Program Files\Aurora
2014-01-11 18:47 - 2014-01-11 18:47 - 00000000 ____D C:\Windows\pss
2014-01-11 18:16 - 2014-01-11 18:16 - 00012984 _____ C:\Users\DJ Sone\Desktop\dds.txt
2014-01-11 18:16 - 2014-01-11 18:16 - 00005507 _____ C:\Users\DJ Sone\Desktop\attach.txt
2014-01-11 18:13 - 2014-01-11 18:14 - 00000893 _____ C:\Users\DJ Sone\Downloads\94804_340342406_gasenjerestartovanje sistema, sounds panel, system panel.reg
2014-01-11 17:59 - 2014-01-11 17:59 - 00000000 ____D C:\Users\DJ Sone\AppData\Roaming\StartMenuX
2014-01-11 17:59 - 2014-01-11 17:59 - 00000000 ____D C:\ProgramData\StartMenuX
2014-01-11 17:59 - 2014-01-11 17:59 - 00000000 ____D C:\Program Files\Start Menu X
2014-01-11 17:58 - 2014-01-11 17:58 - 04644960 _____ (OrdinarySoft ) C:\Users\DJ Sone\Downloads\StartMenuX_Setup_5_02_freeware.exe
2014-01-11 17:47 - 2014-01-11 17:12 - 00688992 ____R (Swearware) C:\Users\DJ Sone\Desktop\dds.scr
2014-01-11 17:12 - 2014-01-11 17:12 - 00688992 ____R (Swearware) C:\Users\DJ Sone\Downloads\dds.scr
2014-01-11 04:30 - 2014-01-11 16:49 - 00000000 ____D C:\Users\DJ Sone\AppData\Local\{FFAD36CF-C450-4878-8ABC-E5E50633528B}
2014-01-07 09:16 - 2014-01-07 09:17 - 00000000 ____D C:\Users\DJ Sone\AppData\Local\{7ABA22A7-6EE9-4905-A3C3-56917F0137D1}
2014-01-07 09:16 - 2014-01-07 09:16 - 00000000 ____D C:\Users\DJ Sone\AppData\Local\{77AB4EC4-1A3B-48E8-91BE-0AF7D097A3E1}
2014-01-07 09:15 - 2014-01-11 17:06 - 00000000 ____D C:\Users\DJ Sone\Tracing
2014-01-05 22:48 - 2014-01-05 22:48 - 00002685 _____ C:\Users\Public\Desktop\Skype.lnk
2014-01-05 22:48 - 2014-01-05 22:48 - 00000000 ___RD C:\Program Files\Skype
2014-01-05 22:48 - 2014-01-05 22:48 - 00000000 ____D C:\Program Files\Common Files\Skype
2014-01-05 12:27 - 2014-01-05 12:27 - 00816585 _____ C:\Users\DJ Sone\Downloads\Office2010-32bits.rar
2014-01-05 12:25 - 2014-01-05 18:06 - 00000982 _____ C:\Users\DJ Sone\Desktop\Serial Key office 2010.txt
2013-12-30 18:44 - 2013-12-30 18:44 - 00000000 ____D C:\Users\DJ Sone\AppData\Local\Temporary Projects
2013-12-30 17:37 - 2009-07-23 04:08 - 00079896 _____ (Microsoft Corporation) C:\Windows\system32\perf-MSSQL$SQLEXPRESS-sqlctr10.1.2531.0.dll
2013-12-30 17:37 - 2009-07-23 04:08 - 00050200 _____ (Microsoft Corporation) C:\Windows\system32\perf-SQLAgent$SQLEXPRESS-sqlagtctr10.1.2531.0.dll
2013-12-30 17:35 - 2013-12-30 17:35 - 00000000 ____D C:\Windows\system32\RsFx
2013-12-30 17:33 - 2013-12-30 17:33 - 00000000 ____D C:\Windows\system32\1033
2013-12-30 17:33 - 2013-12-30 17:33 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 9.0
2013-12-30 17:23 - 2013-12-30 17:35 - 00000000 ____D C:\Program Files\Microsoft SQL Server
2013-12-30 17:22 - 2013-12-30 17:22 - 00000000 ____D C:\Program Files\Microsoft Synchronization Services
2013-12-30 17:22 - 2013-12-30 17:22 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition
2013-12-30 17:21 - 2013-12-30 18:44 - 00000000 ____D C:\Users\DJ Sone\Documents\Visual Studio 2010
2013-12-30 17:19 - 2013-12-30 17:40 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 10.0
2013-12-30 17:19 - 2013-12-30 17:19 - 00000000 ____D C:\Program Files\Microsoft SDKs
2013-12-30 17:19 - 2013-12-30 17:19 - 00000000 ____D C:\Program Files\Microsoft Help Viewer
2013-12-29 22:42 - 2014-01-12 20:51 - 00000000 ____D C:\Windows\Minidump
2013-12-29 22:42 - 2014-01-12 20:50 - 356446140 _____ C:\Windows\MEMORY.DMP
2013-12-29 22:42 - 2013-12-29 22:43 - 00143712 _____ C:\Windows\Minidump\122913-20404-01.dmp
2013-12-29 22:35 - 2013-12-29 22:35 - 01649892 _____ C:\Users\DJ Sone\Desktop\Programiranje_C_jezikom.rar
2013-12-29 22:32 - 2013-12-29 22:32 - 00964155 _____ C:\Users\DJ Sone\Desktop\Racunari_i_programiranje_3.rar
2013-12-29 22:20 - 2013-12-29 22:20 - 393072811 _____ C:\Users\DJ Sone\Desktop\VS2010Express1.iso.crdownload
2013-12-29 22:17 - 2013-12-29 22:17 - 00000000 ____D C:\Program Files\Dev-C++
2013-12-29 21:55 - 2013-12-29 21:55 - 04012627 _____ C:\Users\DJ Sone\Desktop\theredbook.tar.gz
2013-12-29 21:47 - 2013-12-29 22:23 - 00000000 ____D C:\Users\DJ Sone\Desktop\Programiranje
2013-12-29 17:31 - 2013-12-29 17:31 - 00033698 _____ C:\Users\DJ Sone\Desktop\x1391997_315915368548452_1536176789_n.jpg.pagespeed.ic.RNler5APDW.webp
2013-12-27 16:19 - 2013-12-27 16:19 - 00000000 ____D C:\Users\DJ Sone\.jmc
2013-12-27 16:19 - 2013-12-27 16:19 - 00000000 ____D C:\Users\DJ Sone\.eclipse
2013-12-27 15:44 - 2013-12-27 15:44 - 00001123 _____ C:\Users\Public\Desktop\WiFi Password Revealer.lnk
2013-12-27 15:44 - 2013-12-27 15:44 - 00000000 ____D C:\Program Files\WiFi Password Revealer
2013-12-27 15:43 - 2013-12-27 15:43 - 00401760 _____ (Softonic ) C:\Users\DJ Sone\Downloads\SoftonicDownloader_for_wifi-password-revealer.exe
2013-12-27 15:39 - 2013-12-27 15:39 - 00401752 _____ (Softonic ) C:\Users\DJ Sone\Downloads\SoftonicDownloader_for_wifi-key-generator.exe
2013-12-27 15:25 - 2013-12-27 15:31 - 129487776 _____ (Oracle Corporation) C:\Users\DJ Sone\Downloads\jdk-7u45-windows-i586.exe
2013-12-25 17:53 - 2013-12-25 18:03 - 00000000 ____D C:\Users\DJ Sone\AppData\Local\WMTools Downloaded Files
2013-12-25 17:48 - 2013-12-25 17:48 - 00003584 _____ C:\Users\DJ Sone\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-12-25 17:47 - 2013-12-25 17:47 - 00000000 ____D C:\Program Files\Movie Maker 2.6
2013-12-25 17:44 - 2013-12-25 17:46 - 07357440 _____ C:\Users\DJ Sone\Downloads\MM26_ENU.msi
2013-12-25 17:27 - 2013-12-25 17:38 - 00000000 ____D C:\Users\DJ Sone\Desktop\Nidza
2013-12-24 17:57 - 2013-12-24 17:57 - 00000000 ____D C:\Users\DJ Sone\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2013-12-24 02:24 - 2013-12-24 02:25 - 07008438 _____ C:\Users\DJ Sone\Downloads\Integrated.zip
2013-12-24 02:24 - 2013-12-24 02:24 - 03670966 _____ C:\Users\DJ Sone\Downloads\64bit.zip
2013-12-17 21:27 - 2013-12-17 21:27 - 00000376 _____ C:\Windows\ODBC.INI
2013-12-17 21:27 - 2003-06-18 17:31 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\mdimon.dll
2013-12-17 21:26 - 2013-12-17 21:26 - 00000000 ____D C:\Program Files\Microsoft ActiveSync
2013-12-17 21:26 - 2013-12-17 21:26 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2013-12-17 21:15 - 2013-12-20 15:08 - 00046840 _____ C:\Users\DJ Sone\Desktop\Muzika!.ashprj
2013-12-16 19:02 - 2013-12-16 19:03 - 00000000 ___RD C:\Users\DJ Sone\Desktop\Picture

==================== One Month Modified Files and Folders =======

2014-01-12 20:56 - 2014-01-12 20:56 - 00009769 _____ C:\Users\DJ Sone\Desktop\FRST.txt
2014-01-12 20:55 - 2014-01-12 20:55 - 00000000 ____D C:\FRST
2014-01-12 20:54 - 2014-01-12 20:54 - 01219584 _____ (Farbar) C:\Users\DJ Sone\Desktop\FRST.exe
2014-01-12 20:54 - 2013-10-25 16:24 - 00244224 _____ C:\Windows\WindowsUpdate.log
2014-01-12 20:51 - 2014-01-12 20:51 - 00368640 _____ C:\Windows\Minidump\011214-17082-01.dmp
2014-01-12 20:51 - 2013-12-29 22:42 - 00000000 ____D C:\Windows\Minidump
2014-01-12 20:51 - 2013-10-25 16:55 - 00000884 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-12 20:51 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-12 20:51 - 2009-07-14 05:39 - 00042699 _____ C:\Windows\setupact.log
2014-01-12 20:50 - 2013-12-29 22:42 - 356446140 _____ C:\Windows\MEMORY.DMP
2014-01-12 20:50 - 2013-10-25 17:03 - 00017412 _____ C:\Windows\PFRO.log
2014-01-12 19:49 - 2013-10-25 16:55 - 00000888 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-12 19:20 - 2014-01-12 19:19 - 00000000 ___SD C:\ComboFix
2014-01-12 19:19 - 2014-01-12 19:19 - 00000000 ____D C:\Qoobox
2014-01-12 19:18 - 2014-01-12 19:17 - 05164834 ____R (Swearware) C:\Users\DJ Sone\Desktop\ComboFix.exe
2014-01-12 18:50 - 2009-07-14 05:34 - 00010016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-12 18:50 - 2009-07-14 05:34 - 00010016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-12 18:45 - 2014-01-12 18:44 - 00368640 _____ C:\Windows\Minidump\011214-16754-01.dmp
2014-01-12 18:44 - 2013-11-19 18:30 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2014-01-12 04:06 - 2014-01-12 04:06 - 00368640 _____ C:\Windows\Minidump\011214-16816-01.dmp
2014-01-11 20:37 - 2014-01-11 20:37 - 00367944 _____ C:\Windows\Minidump\011114-17238-01.dmp
2014-01-11 19:55 - 2014-01-11 19:55 - 00000000 ____D C:\Windows\erdnt
2014-01-11 19:45 - 2013-10-31 02:09 - 00000000 ____D C:\Users\DJ Sone\AppData\Roaming\Skype
2014-01-11 19:23 - 2014-01-11 19:22 - 00000000 ____D C:\Program Files\Aurora
2014-01-11 18:47 - 2014-01-11 18:47 - 00000000 ____D C:\Windows\pss
2014-01-11 18:16 - 2014-01-11 18:16 - 00012984 _____ C:\Users\DJ Sone\Desktop\dds.txt
2014-01-11 18:16 - 2014-01-11 18:16 - 00005507 _____ C:\Users\DJ Sone\Desktop\attach.txt
2014-01-11 18:14 - 2014-01-11 18:13 - 00000893 _____ C:\Users\DJ Sone\Downloads\94804_340342406_gasenjerestartovanje sistema, sounds panel, system panel.reg
2014-01-11 17:59 - 2014-01-11 17:59 - 00000000 ____D C:\Users\DJ Sone\AppData\Roaming\StartMenuX
2014-01-11 17:59 - 2014-01-11 17:59 - 00000000 ____D C:\ProgramData\StartMenuX
2014-01-11 17:59 - 2014-01-11 17:59 - 00000000 ____D C:\Program Files\Start Menu X
2014-01-11 17:58 - 2014-01-11 17:58 - 04644960 _____ (OrdinarySoft ) C:\Users\DJ Sone\Downloads\StartMenuX_Setup_5_02_freeware.exe
2014-01-11 17:28 - 2013-11-22 20:13 - 00000000 ____D C:\Users\DJ Sone\AppData\Roaming\Bitcoin
2014-01-11 17:12 - 2014-01-11 17:47 - 00688992 ____R (Swearware) C:\Users\DJ Sone\Desktop\dds.scr
2014-01-11 17:12 - 2014-01-11 17:12 - 00688992 ____R (Swearware) C:\Users\DJ Sone\Downloads\dds.scr
2014-01-11 17:06 - 2014-01-07 09:15 - 00000000 ____D C:\Users\DJ Sone\Tracing
2014-01-11 16:49 - 2014-01-11 04:30 - 00000000 ____D C:\Users\DJ Sone\AppData\Local\{FFAD36CF-C450-4878-8ABC-E5E50633528B}
2014-01-11 16:49 - 2013-12-09 04:45 - 00000000 ____D C:\Users\DJ Sone\AppData\Local\Windows Live
2014-01-11 04:34 - 2013-10-25 16:31 - 00873134 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-07 09:17 - 2014-01-07 09:16 - 00000000 ____D C:\Users\DJ Sone\AppData\Local\{7ABA22A7-6EE9-4905-A3C3-56917F0137D1}
2014-01-07 09:16 - 2014-01-07 09:16 - 00000000 ____D C:\Users\DJ Sone\AppData\Local\{77AB4EC4-1A3B-48E8-91BE-0AF7D097A3E1}
2014-01-07 09:15 - 2013-10-25 16:27 - 00000000 ____D C:\Users\DJ Sone
2014-01-05 22:48 - 2014-01-05 22:48 - 00002685 _____ C:\Users\Public\Desktop\Skype.lnk
2014-01-05 22:48 - 2014-01-05 22:48 - 00000000 ___RD C:\Program Files\Skype
2014-01-05 22:48 - 2014-01-05 22:48 - 00000000 ____D C:\Program Files\Common Files\Skype
2014-01-05 22:48 - 2013-10-31 02:08 - 00000000 ____D C:\ProgramData\Skype
2014-01-05 18:06 - 2014-01-05 12:25 - 00000982 _____ C:\Users\DJ Sone\Desktop\Serial Key office 2010.txt
2014-01-05 12:27 - 2014-01-05 12:27 - 00816585 _____ C:\Users\DJ Sone\Downloads\Office2010-32bits.rar
2013-12-30 18:44 - 2013-12-30 18:44 - 00000000 ____D C:\Users\DJ Sone\AppData\Local\Temporary Projects
2013-12-30 18:44 - 2013-12-30 17:21 - 00000000 ____D C:\Users\DJ Sone\Documents\Visual Studio 2010
2013-12-30 17:55 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\Microsoft.NET
2013-12-30 17:40 - 2013-12-30 17:19 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 10.0
2013-12-30 17:35 - 2013-12-30 17:35 - 00000000 ____D C:\Windows\system32\RsFx
2013-12-30 17:35 - 2013-12-30 17:23 - 00000000 ____D C:\Program Files\Microsoft SQL Server
2013-12-30 17:33 - 2013-12-30 17:33 - 00000000 ____D C:\Windows\system32\1033
2013-12-30 17:33 - 2013-12-30 17:33 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 9.0
2013-12-30 17:33 - 2009-07-14 03:37 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2013-12-30 17:32 - 2013-10-25 17:56 - 00000000 ____D C:\Program Files\Microsoft.NET
2013-12-30 17:22 - 2013-12-30 17:22 - 00000000 ____D C:\Program Files\Microsoft Synchronization Services
2013-12-30 17:22 - 2013-12-30 17:22 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition
2013-12-30 17:19 - 2013-12-30 17:19 - 00000000 ____D C:\Program Files\Microsoft SDKs
2013-12-30 17:19 - 2013-12-30 17:19 - 00000000 ____D C:\Program Files\Microsoft Help Viewer
2013-12-29 22:43 - 2013-12-29 22:42 - 00143712 _____ C:\Windows\Minidump\122913-20404-01.dmp
2013-12-29 22:35 - 2013-12-29 22:35 - 01649892 _____ C:\Users\DJ Sone\Desktop\Programiranje_C_jezikom.rar
2013-12-29 22:32 - 2013-12-29 22:32 - 00964155 _____ C:\Users\DJ Sone\Desktop\Racunari_i_programiranje_3.rar
2013-12-29 22:23 - 2013-12-29 21:47 - 00000000 ____D C:\Users\DJ Sone\Desktop\Programiranje
2013-12-29 22:20 - 2013-12-29 22:20 - 393072811 _____ C:\Users\DJ Sone\Desktop\VS2010Express1.iso.crdownload
2013-12-29 22:17 - 2013-12-29 22:17 - 00000000 ____D C:\Program Files\Dev-C++
2013-12-29 21:55 - 2013-12-29 21:55 - 04012627 _____ C:\Users\DJ Sone\Desktop\theredbook.tar.gz
2013-12-29 17:31 - 2013-12-29 17:31 - 00033698 _____ C:\Users\DJ Sone\Desktop\x1391997_315915368548452_1536176789_n.jpg.pagespeed.ic.RNler5APDW.webp
2013-12-27 16:19 - 2013-12-27 16:19 - 00000000 ____D C:\Users\DJ Sone\.jmc
2013-12-27 16:19 - 2013-12-27 16:19 - 00000000 ____D C:\Users\DJ Sone\.eclipse
2013-12-27 15:48 - 2013-10-30 22:39 - 00000000 ____D C:\ProgramData\Oracle
2013-12-27 15:44 - 2013-12-27 15:44 - 00001123 _____ C:\Users\Public\Desktop\WiFi Password Revealer.lnk
2013-12-27 15:44 - 2013-12-27 15:44 - 00000000 ____D C:\Program Files\WiFi Password Revealer
2013-12-27 15:44 - 2013-10-25 16:56 - 00000000 ____D C:\Program Files\Java
2013-12-27 15:43 - 2013-12-27 15:43 - 00401760 _____ (Softonic ) C:\Users\DJ Sone\Downloads\SoftonicDownloader_for_wifi-password-revealer.exe
2013-12-27 15:43 - 2009-07-14 03:37 - 00000000 ___RD C:\Users\Public
2013-12-27 15:39 - 2013-12-27 15:39 - 00401752 _____ (Softonic ) C:\Users\DJ Sone\Downloads\SoftonicDownloader_for_wifi-key-generator.exe
2013-12-27 15:31 - 2013-12-27 15:25 - 129487776 _____ (Oracle Corporation) C:\Users\DJ Sone\Downloads\jdk-7u45-windows-i586.exe
2013-12-25 18:03 - 2013-12-25 17:53 - 00000000 ____D C:\Users\DJ Sone\AppData\Local\WMTools Downloaded Files
2013-12-25 17:48 - 2013-12-25 17:48 - 00003584 _____ C:\Users\DJ Sone\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-12-25 17:47 - 2013-12-25 17:47 - 00000000 ____D C:\Program Files\Movie Maker 2.6
2013-12-25 17:46 - 2013-12-25 17:44 - 07357440 _____ C:\Users\DJ Sone\Downloads\MM26_ENU.msi
2013-12-25 17:42 - 2013-10-27 11:17 - 00000000 ____D C:\Users\DJ Sone\Documents\FFOutput
2013-12-25 17:38 - 2013-12-25 17:27 - 00000000 ____D C:\Users\DJ Sone\Desktop\Nidza
2013-12-24 17:57 - 2013-12-24 17:57 - 00000000 ____D C:\Users\DJ Sone\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2013-12-24 02:25 - 2013-12-24 02:24 - 07008438 _____ C:\Users\DJ Sone\Downloads\Integrated.zip
2013-12-24 02:24 - 2013-12-24 02:24 - 03670966 _____ C:\Users\DJ Sone\Downloads\64bit.zip
2013-12-20 15:08 - 2013-12-17 21:15 - 00046840 _____ C:\Users\DJ Sone\Desktop\Muzika!.ashprj
2013-12-19 02:34 - 2009-07-14 05:33 - 00285152 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-18 19:12 - 2013-10-25 16:53 - 00135648 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-12-18 19:12 - 2013-10-25 16:53 - 00090400 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-12-18 19:12 - 2013-10-25 16:53 - 00069240 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-12-17 21:27 - 2013-12-17 21:27 - 00000376 _____ C:\Windows\ODBC.INI
2013-12-17 21:26 - 2013-12-17 21:26 - 00000000 ____D C:\Program Files\Microsoft ActiveSync
2013-12-17 21:26 - 2013-12-17 21:26 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2013-12-17 21:26 - 2013-11-01 22:47 - 00000000 ____D C:\Program Files\Microsoft Office
2013-12-17 21:26 - 2013-10-25 16:41 - 00062304 _____ C:\Users\DJ Sone\AppData\Local\GDIPFONTCACHEV1.DAT
2013-12-17 21:26 - 2009-07-14 08:49 - 00000000 ____D C:\Windows\ShellNew
2013-12-17 21:23 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system
2013-12-16 19:04 - 2013-11-22 19:24 - 00000000 ___RD C:\Users\DJ Sone\Desktop\BTC
2013-12-16 19:03 - 2013-12-16 19:02 - 00000000 ___RD C:\Users\DJ Sone\Desktop\Picture
2013-12-16 18:38 - 2013-10-28 21:23 - 00000180 _____ C:\Users\DJ Sone\Desktop\Your Password.txt

Some content of TEMP:
====================
C:\Users\DJ Sone\AppData\Local\Temp\228425-662917-ashampoo-burning-studio-10.exe
C:\Users\DJ Sone\AppData\Local\Temp\AskSLib.dll
C:\Users\DJ Sone\AppData\Local\Temp\avgnt.exe
C:\Users\DJ Sone\AppData\Local\Temp\catchme.dll
C:\Users\DJ Sone\AppData\Local\Temp\fp_pl_pfs_installer-1.exe
C:\Users\DJ Sone\AppData\Local\Temp\fp_pl_pfs_installer-2.exe
C:\Users\DJ Sone\AppData\Local\Temp\fp_pl_pfs_installer.exe
C:\Users\DJ Sone\AppData\Local\Temp\instloffer.exe
C:\Users\DJ Sone\AppData\Local\Temp\nse55DE.tmp.exe
C:\Users\DJ Sone\AppData\Local\Temp\OCL56E4.tmp.dll
C:\Users\DJ Sone\AppData\Local\Temp\OCLA9A.tmp.dll
C:\Users\DJ Sone\AppData\Local\Temp\OCLDE2D.tmp.dll
C:\Users\DJ Sone\AppData\Local\Temp\OCLF101.tmp.dll
C:\Users\DJ Sone\AppData\Local\Temp\OCLFC66.tmp.dll
C:\Users\DJ Sone\AppData\Local\Temp\safeguard.exe


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-01-09 01:13

==================== End Of Log ============================
mycity.rs/must-login.png

offline
  • Pridružio: 09 Avg 2011
  • Poruke: 15879
  • Gde živiš: Beograd

1. Otvori Notepad (Text Document) i iskopiraj sledeći tekst unutar kod polja ispod:
APN LLC.) C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myhoome.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x40F3819319EBCE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = sr-rs
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.myhoome.com/
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.myhoome.com/
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myhoome.com/
BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
Toolbar: HKCU - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
C:\Program Files\AskPartnerNetwork\Toolbar
CHR Extension: (WebSite Recommendation) - C:\Users\DJ Sone\AppData\Local\Google\Chrome\User Data\Default\Extensions\olakgnkoldmagdblaalodobkmeokmgjj\2.4_0 [2013-12-27]
R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-12-20] (APN LLC.)
C:\Users\DJ Sone\AppData\Local\Temp\228425-662917-ashampoo-burning-studio-10.exe
C:\Users\DJ Sone\AppData\Local\Temp\AskSLib.dll
C:\Users\DJ Sone\AppData\Local\Temp\avgnt.exe
C:\Users\DJ Sone\AppData\Local\Temp\catchme.dll
C:\Users\DJ Sone\AppData\Local\Temp\fp_pl_pfs_installer-1.exe
C:\Users\DJ Sone\AppData\Local\Temp\fp_pl_pfs_installer-2.exe
C:\Users\DJ Sone\AppData\Local\Temp\fp_pl_pfs_installer.exe
C:\Users\DJ Sone\AppData\Local\Temp\instloffer.exe
C:\Users\DJ Sone\AppData\Local\Temp\nse55DE.tmp.exe
C:\Users\DJ Sone\AppData\Local\Temp\OCL56E4.tmp.dll
C:\Users\DJ Sone\AppData\Local\Temp\OCLA9A.tmp.dll
C:\Users\DJ Sone\AppData\Local\Temp\OCLDE2D.tmp.dll
C:\Users\DJ Sone\AppData\Local\Temp\OCLF101.tmp.dll
C:\Users\DJ Sone\AppData\Local\Temp\OCLFC66.tmp.dll
C:\Users\DJ Sone\AppData\Local\Temp\safeguard.exe
AlternateDataStreams: C:\ProgramData\TEMP:B3D74A13
cmd: ipconfig /flushdns

2. Sačuvaj notepad na Desktop pod nazivom fixlist.txt
To možes uraditi i iz notepad-a => klik na File potom na Save As i u novom prozoru, dole pod File Name: staviš za naziv fixlist.txt
Napomena: Važno je da se oba fajla, FRST i fixlist nalaze na istoj lokaciji jer u suprotnom fix nece raditi.

3. Ponovo pokreni FRST/FRST64, klikni jednom na dugme Fix i sačekaj.
Ukoliko alat zatraži restart sistema, dozvoli mu i postaraj se da alat kompletira fix nakon restarta sistema.



Alat će formirati log (Fixlog.txt) na Desktop-u. Potrebno je sadržaj tog loga iskopirati u poruku.
Napomena: Ukoliko te alat upozori da postoji novija verzija, postaraj se da preuzmes i koristiš ažuriranu kopiju FRST-a.



Zatim



Preuzmi "Xplode"-ov AdwCleaner () i sacuvaj ga na Desktop

Dvoklikom pokreni program.
Klikni na dugme [Scan] i pricekaj da program zavrsi.
Klikni na dugme [Clean]
Program ce zatvoriti sve aktivne programe i izbaciti prozor sa tim upozorenjem. Klikni Ok kao potvrdu.
Na sledeca dva prozora koja se otvore (Informations i Restart required ) klikni Ok


Racunar ce se restartovati a potom otvoriti notepad (C:\AdwCleaner[S1].txt) sa izvestajem.
Sacuvaj taj notepad na Desktop i okaci ga uz poruku koristeci opciju "Prikaci fajl"

Napomena: Izvestaj ce takodje biti sacuvan na C:\AdwCleaner[S1].txt

Ko je trenutno na forumu
 

Ukupno su 960 korisnika na forumu :: 63 registrovanih, 11 sakrivenih i 886 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., Apok, babaroga, Batinas, cifra, comi_pfc, darkangel, deLacy, Denaya, Dimitrise93, Djokkinen, doklevise, DonRumataEstorski, Dorcolac, dule10savic, Gargantua, Georgius, goxin, havoc995, HogarStrashni, hooraay, ikan, Karla, kobaja77, kolle.the.kid, krkalon, Krusarac, Kubovac, kunktator, Lord Nem, LUDI, MB120mm, mercedesamg, mikrimaus, Misirac, nenad81, nikoladim, NoOneEver Dreams, ozzy, procesor, RecA, Ripanjac, S2M, Sančo, sasa87, ser.hill, shaja1, Shinobi, slonic_tonic, srbijaiznadsvega, Srle993, Vatreni Zmaj, Vlad000, Vlada1389, vladaa012, vlajkox, vobo, yrraf, ZetaMan, |_MeD_|, Žrnov, 125, 79693