Usporen rad računara

Usporen rad računara

offline
  • Pridružio: 11 Jul 2012
  • Poruke: 46

Pozdrav,

računar mi je super radio sve do neki dan otkako je naglo usporio i sve jedva otvara.

Poslednje u zadnjih par dana što se sjećam da sam instalirao je Dropbox ali ne vjerujem da je zbog toga.

Browser takođe usporen.

_____________________________________________________________

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-10-2014
Ran by Aleksandar (administrator) on DELTABH on 26-10-2014 16:22:24
Running from C:\Users\Aleksandar\Desktop
Loaded Profile: Aleksandar (Available profiles: Aleksandar)
Platform: Windows 8.1 Pro with Media Center (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: geekstogo.com/forum/topic/335081-frst-t.....scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(arvato digital services llc) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Yahoo! Inc.) C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Skillbrains) C:\Users\Aleksandar\AppData\Local\Skillbrains\lightshot\5.1.4.17\Lightshot.exe
(MyCity) C:\Program Files (x86)\MCShield\MCShieldRTM.exe
() D:\deltabh\FSCapture48\FSCapture.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Nitro PDF Software) C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe
(Microsoft Corporation) C:\Windows\System32\prevhost.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Reader_6.3.9654.17044_x64__8wekyb3d8bbwe\glcnd.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [641704 2012-11-16] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AMD AVT] => C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [20992 2012-03-19] ()
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKU\S-1-5-21-468891226-946991927-1053560233-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-468891226-946991927-1053560233-1001\...\Run: [LightShot] => C:\Users\Aleksandar\AppData\Local\Skillbrains\lightshot\Lightshot.exe [226560 2014-07-01] ()
HKU\S-1-5-21-468891226-946991927-1053560233-1001\...\Run: [MCShield Monitor] => C:\Program Files (x86)\MCShield\mcshieldrtm.exe [650816 2014-04-11] (MyCity)
HKU\S-1-5-21-468891226-946991927-1053560233-1001\...\Run: [Facebook Update] => C:\Users\Aleksandar\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2014-08-13] (Facebook Inc.)
HKU\S-1-5-21-468891226-946991927-1053560233-1001\...\Run: [Messenger (Yahoo!)] => C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe [6595928 2012-05-25] (Yahoo! Inc.)
HKU\S-1-5-21-468891226-946991927-1053560233-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [22065760 2014-10-01] (Skype Technologies S.A.)
HKU\S-1-5-21-468891226-946991927-1053560233-1001\...\MountPoints2: {83c38255-20a7-11e4-824c-806e6f6e6963} - "E:\DriverPackSolution.exe"
Startup: C:\Users\Aleksandar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Aleksandar\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FastStone Capture.lnk
ShortcutTarget: FastStone Capture.lnk -> D:\deltabh\FSCapture48\FSCapture.exe ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = t.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x3F2BEFC4B7B4CF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = sr-Latn-BA
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: &Yahoo! Toolbar Helper -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM-x32 - Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll No File
FF Plugin: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/AuthorwarePlayer -> C:\Windows\system32\Macromed\AUTHORWA\np32asw.dll No File
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1213153.dll (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 8\npnitromozilla.dll (Nitro PDF)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Aleksandar\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)

Chrome:
=======
CHR HomePage: Default -> google.ba/
CHR StartupUrls: Default -> "hxxp://www.google.rs/", "hxxp://start.mysearchdial.com/?f=1&a=md_14_11_ch&cd=2XzuyEtN2Y1L1QzutDtD0EtDyB0DzyyByCzz0D0FtB0ByCtBtN0D0Tzu0SzztDyDtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyDtA0CyEyCtCyDtAtGtC0FyE0AtG0A0FtCyDtGyEzytB0DtGyByE0CzztD0AyCtC0AtD0AyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyC0D0DyCzyyDzyyEtGtA0D0FtAtGyD0AyEtCtGyE0BtDyBtGtB0B0E0FyC0DtCtB0AtCtDyD2Q&cr=569384714&ir="
CHR Profile: C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Entanglement Web App) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd [2014-09-04]
CHR Extension: (Note Board Web) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\apgackkfllmckgkbdfmbfodpinmnnpab [2014-09-04]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-08-10]
CHR Extension: (WOT) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2014-09-04]
CHR Extension: (Honey) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2014-09-04]
CHR Extension: (X-notifier (for Gmail™,Hotmail,Yahoo,AOL...)) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdfjbkbddpfnoplfhceolpopfoepleco [2014-09-05]
CHR Extension: (Full Page Screen Capture) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdpohaocaechififmbbbbbknoalclacl [2014-10-05]
CHR Extension: (Shield For Chrome ) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\gceighgadbamgchioaofojlblndjcggh [2014-09-04]
CHR Extension: (Click&Clean) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghgabhipcejejjmhhchfonmamedcbeod [2014-09-04]
CHR Extension: (AdBlock) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-09-04]
CHR Extension: (PDF Mergy) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgecghmkcdefnknohcimkoemhaofpoha [2014-09-04]
CHR Extension: (Bitly | Unleash the power of the link) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\iabeihobmhlgpkcgjiloemdbofjbdcic [2014-09-04]
CHR Extension: (Typing Test - KeyHero) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkcieoaeooeidmpaopkpjpjfakidlabm [2014-09-04]
CHR Extension: (Todoist: To-Do list and Task Manager) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\jldhpllghnbhlbpcmnajkpdmadaolakh [2014-09-04]
CHR Extension: (Auto Replay for YouTube™) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\kanbnempkjnhadplbfgdaagijdbdbjeb [2014-09-04]
CHR Extension: (Google Mail Checker) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2014-09-04]
CHR Extension: (Quick Note) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\mijlebbfndhelmdpmllgcfadlkankhok [2014-09-04]
CHR Extension: (Google Wallet) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-08-10]
CHR Extension: (Buffer) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\noojglkidnpfjbincgijbaiedldjfbhh [2014-09-04]
CHR Extension: (My Chrome Theme) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\oehpjpccmlcalbenfhnacjeocbjdonic [2014-09-04]
CHR Extension: (Click&Clean App) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp [2014-09-04]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [44032 2013-08-22] (Microsoft Corporation)
S3 lfsvc; C:\Windows\SysWOW64\GeofenceMonitorService.dll [357376 2014-03-08] (Microsoft Corporation)
S3 Netlogon; C:\Windows\SysWOW64\netlogon.dll [688640 2013-08-22] (Microsoft Corporation)
R2 NitroDriverReadSpool8; C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe [230408 2012-12-13] (Nitro PDF Software)
R2 PSI_SVC_2_x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [337776 2013-09-13] (arvato digital services llc)
S3 smphost; C:\Windows\SysWOW64\smphost.dll [11776 2013-08-22] (Microsoft Corporation)
S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18944 2013-08-22] (Microsoft Corporation)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S3 wampapache64; c:\wamp\bin\apache\apache2.4.9\bin\httpd.exe [24576 2014-05-01] (Apache Software Foundation) [File not signed]
S3 wampmysqld64; c:\wamp\bin\mysql\mysql5.6.17\bin\mysqld.exe [12942848 2014-05-01] () [File not signed]
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [348392 2014-03-12] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-12] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 Atc002; C:\Windows\system32\DRIVERS\l260x64.sys [34304 2013-06-18] (Atheros Communications, Inc.)
R3 cmuda3; C:\Windows\system32\drivers\cmudax3.sys [1155072 2009-12-01] (C-Media Inc)
R3 MTsensor; C:\Windows\system32\DRIVERS\ASACPI.sys [17280 2013-05-17] ()
R3 RTL8023x64; C:\Windows\system32\DRIVERS\Rtnic64.sys [51712 2013-06-18] (Realtek Semiconductor Corporation )
S3 ssudserd; C:\Windows\system32\DRIVERS\ssudserd.sys [206080 2014-01-22] (DEVGURU Co., LTD.(www.devguru.co.kr))
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124760 2014-03-12] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-26 16:22 - 2014-10-26 16:24 - 00015653 _____ () C:\Users\Aleksandar\Desktop\FRST.txt
2014-10-26 16:22 - 2014-10-26 16:22 - 00000000 ____D () C:\FRST
2014-10-26 16:21 - 2014-10-26 16:21 - 02113024 _____ (Farbar) C:\Users\Aleksandar\Desktop\FRST64.exe
2014-10-26 16:17 - 2014-10-26 16:17 - 00000000 ____D () C:\Users\Aleksandar\AppData\Roaming\Nitro
2014-10-26 16:09 - 2012-12-13 11:47 - 00029704 _____ (Nitro PDF Software) C:\Windows\system32\nitrolocalmon2.dll
2014-10-26 16:09 - 2012-12-13 11:47 - 00017928 _____ (Nitro PDF Software) C:\Windows\system32\nitrolocalui2.dll
2014-10-26 16:08 - 2014-10-26 16:08 - 00002547 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nitro Pro 8.lnk
2014-10-26 16:08 - 2014-10-26 16:08 - 00001978 _____ () C:\Users\Public\Desktop\Nitro Pro 8.lnk
2014-10-26 16:01 - 2014-10-26 16:02 - 00000000 ____D () C:\Users\Aleksandar\Desktop\zip
2014-10-26 15:59 - 2014-10-26 15:59 - 00000000 ____D () C:\Program Files\Common Files\Nitro
2014-10-26 15:58 - 2014-10-26 15:58 - 00000000 ____D () C:\ProgramData\Nitro
2014-10-26 15:58 - 2014-10-26 15:58 - 00000000 ____D () C:\Program Files (x86)\Nitro
2014-10-26 15:51 - 2014-10-26 15:51 - 00000000 ____D () C:\Users\Aleksandar\AppData\Roaming\Downloaded Installations
2014-10-26 01:07 - 2014-10-26 01:07 - 00006832 _____ () C:\Users\Aleksandar\Desktop\nbkp.txt
2014-10-25 21:25 - 2014-10-25 21:25 - 00006454 _____ () C:\Users\Aleksandar\Desktop\Kontaktirajtenas---10-25-2014-.nff
2014-10-25 20:34 - 2014-10-25 20:38 - 00000000 ____D () C:\Users\Aleksandar\Desktop\salmont bekap 25.10.2014
2014-10-25 19:16 - 2014-10-25 19:16 - 06126536 _____ (Tim Kosse) C:\Users\Aleksandar\Downloads\FileZilla_3.9.0.6_win32-setup.exe
2014-10-23 22:16 - 2011-12-11 20:51 - 01683481 _____ () C:\Users\Aleksandar\Desktop\Photoshop Letterpress Effect.psd
2014-10-23 20:28 - 2013-09-04 22:57 - 44930490 _____ () C:\Users\Aleksandar\Desktop\Cutout Logo Mock-Up.psd
2014-10-23 20:09 - 2013-11-18 20:42 - 17900998 _____ () C:\Users\Aleksandar\Desktop\Wood Engraved Logo Mock-Up.psd
2014-10-23 17:34 - 2014-10-23 17:34 - 00000000 ____D () C:\Users\Aleksandar\AppData\Local\Michele_Locati
2014-10-23 17:34 - 2014-10-23 17:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BetterPoEditor
2014-10-23 17:34 - 2014-10-23 17:34 - 00000000 ____D () C:\Program Files (x86)\BetterPoEditor
2014-10-23 17:31 - 2014-10-23 17:31 - 00000000 ____D () C:\Program Files (x86)\Reference Assemblies
2014-10-23 17:30 - 2014-10-23 17:30 - 00000000 ____D () C:\Program Files\Reference Assemblies
2014-10-23 17:30 - 2014-10-23 17:30 - 00000000 ____D () C:\Program Files\MSBuild
2014-10-23 17:24 - 2013-08-03 05:48 - 01166520 _____ (Microsoft Corporation) C:\Windows\system32\PresentationNative_v0300.dll
2014-10-23 17:24 - 2013-08-03 05:48 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2014-10-23 17:24 - 2013-08-03 05:48 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-10-23 17:24 - 2013-08-03 05:41 - 00778936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationNative_v0300.dll
2014-10-23 17:24 - 2013-08-03 05:41 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2014-10-23 17:24 - 2013-08-03 05:41 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-10-23 00:28 - 2014-10-25 19:13 - 00000000 ___RD () C:\Users\Aleksandar\Dropbox
2014-10-23 00:28 - 2014-10-23 00:28 - 00001093 _____ () C:\Users\Aleksandar\Desktop\Dropbox.lnk
2014-10-23 00:25 - 2014-10-23 00:25 - 00000000 ____D () C:\Users\Aleksandar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-10-23 00:19 - 2014-10-25 17:58 - 00000000 ____D () C:\Users\Aleksandar\AppData\Roaming\Dropbox
2014-10-23 00:18 - 2014-10-23 00:19 - 00323672 _____ (Dropbox, Inc.) C:\Users\Aleksandar\Desktop\DropboxInstaller.exe
2014-10-22 23:52 - 2014-10-22 23:52 - 03507639 _____ () C:\Users\Aleksandar\Desktop\logo%20iso%202010[1].psd
2014-10-22 17:08 - 2014-10-22 17:16 - 81763259 _____ () C:\Users\Aleksandar\Desktop\Mivex Malina 250g.ai
2014-10-22 00:17 - 2014-10-22 00:17 - 00000897 _____ () C:\Users\Aleksandar\Desktop\k.txt
2014-10-21 21:18 - 2014-10-21 21:18 - 00308851 _____ () C:\Users\Aleksandar\Desktop\logo4.psd
2014-10-20 19:11 - 2014-10-20 19:11 - 00938594 _____ () C:\Users\Aleksandar\Desktop\logo3 vektor.ai
2014-10-20 18:58 - 2014-10-20 18:58 - 00296354 _____ () C:\Users\Aleksandar\Desktop\logo3.psd
2014-10-20 00:41 - 2014-10-20 00:41 - 00001244 _____ () C:\Users\Aleksandar\Desktop\ll.txt
2014-10-19 19:34 - 2014-10-19 19:35 - 00288979 _____ () C:\Users\Aleksandar\Desktop\logo2.psd
2014-10-19 13:36 - 2014-10-19 13:36 - 00003955 _____ () C:\Users\Aleksandar\Desktop\wp-config.php
2014-10-17 22:18 - 2014-06-10 10:01 - 00009217 _____ () C:\Users\Aleksandar\Desktop\layout2-revslider.txt
2014-10-17 20:04 - 2014-10-26 16:05 - 00000000 ____D () C:\Users\Aleksandar\Desktop\salmont
2014-10-17 18:19 - 2014-10-17 18:19 - 00000000 ____D () C:\Users\Aleksandar\Desktop\bekap
2014-10-13 23:50 - 2014-10-14 00:10 - 01424791 _____ () C:\Users\Aleksandar\Desktop\Untitled-2.psd
2014-10-13 22:23 - 2014-10-13 22:23 - 00061440 _____ () C:\Users\Aleksandar\Desktop\Book 1.indb
2014-10-13 22:19 - 2014-10-13 22:19 - 00061440 _____ () C:\Users\Aleksandar\Desktop\knjiga.indb
2014-10-13 22:01 - 2014-10-13 22:01 - 00001211 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe InDesign CS6.lnk
2014-10-13 21:57 - 2014-10-13 21:59 - 00001301 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Media Encoder CS6.lnk
2014-10-13 21:14 - 2012-04-29 22:06 - 00000000 ____D () C:\Users\Aleksandar\Desktop\Adobe Indesign CS6
2014-10-12 16:18 - 2014-10-12 16:18 - 00000000 ____D () C:\Users\Aleksandar\Desktop\lijekzadusu
2014-10-11 17:25 - 2014-10-11 17:25 - 00789502 _____ () C:\Users\Aleksandar\Desktop\alienware-2.zip
2014-10-10 19:52 - 2014-10-26 16:05 - 00000000 ____D () C:\Users\Aleksandar\Desktop\slike
2014-10-02 17:56 - 2014-10-02 17:56 - 00000196 _____ () C:\Users\Aleksandar\Desktop\ponuda.txt

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-26 16:20 - 2014-08-10 17:23 - 00003594 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-468891226-946991927-1053560233-1001
2014-10-26 16:04 - 2014-08-10 18:39 - 00000000 ____D () C:\Users\Aleksandar\AppData\Roaming\Skype
2014-10-26 16:02 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sru
2014-10-26 15:42 - 2014-08-12 18:48 - 00000000 ____D () C:\ProgramData\MCShield
2014-10-26 15:37 - 2014-08-10 17:27 - 00000956 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-10-26 15:18 - 2014-08-12 13:19 - 00000414 _____ () C:\Windows\Tasks\update-sys.job
2014-10-26 15:02 - 2014-08-13 19:57 - 00000964 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-468891226-946991927-1053560233-1001UA.job
2014-10-26 14:43 - 2014-08-12 13:19 - 00000414 _____ () C:\Windows\Tasks\update-S-1-5-21-468891226-946991927-1053560233-1001.job
2014-10-26 14:28 - 2014-09-06 13:11 - 01181974 _____ () C:\Windows\WindowsUpdate.log
2014-10-26 13:39 - 2014-08-11 18:24 - 03481088 ___SH () C:\Users\Aleksandar\Desktop\Thumbs.db
2014-10-26 12:02 - 2014-09-21 11:34 - 00003758 _____ () C:\Windows\System32\Tasks\AutoKMS
2014-10-26 12:02 - 2014-08-10 17:27 - 00000952 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-10-26 01:00 - 2014-08-11 22:55 - 00000000 ____D () C:\Users\Aleksandar\AppData\Local\Adobe
2014-10-26 00:42 - 2014-08-13 22:48 - 00000000 ____D () C:\Users\Aleksandar\AppData\Roaming\FileZilla
2014-10-25 20:02 - 2014-08-13 19:57 - 00000942 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-468891226-946991927-1053560233-1001Core.job
2014-10-25 19:18 - 2014-08-13 22:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2014-10-25 19:18 - 2014-08-13 22:47 - 00000000 ____D () C:\Program Files (x86)\FileZilla FTP Client
2014-10-25 19:14 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\rescache
2014-10-24 23:54 - 2014-08-10 17:17 - 00000000 ____D () C:\Users\Aleksandar
2014-10-24 14:58 - 2013-08-22 15:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-23 17:33 - 2013-08-22 16:20 - 00000000 ____D () C:\Windows\CbsTemp
2014-10-23 17:31 - 2014-09-18 23:44 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2014-10-22 18:45 - 2014-08-10 17:31 - 00002203 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-10-21 21:18 - 2014-08-29 22:38 - 00000132 _____ () C:\Users\Aleksandar\AppData\Roaming\Adobe PNG Format CS6 Prefs
2014-10-21 14:27 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\AppReadiness
2014-10-21 14:16 - 2013-08-22 15:44 - 05186616 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-10-15 18:24 - 2014-08-10 18:19 - 00000000 ____D () C:\ProgramData\Skype
2014-10-14 17:32 - 2014-08-10 17:27 - 00003928 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-10-14 17:32 - 2014-08-10 17:27 - 00003692 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-10-13 22:02 - 2014-08-12 06:41 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2014-10-13 22:01 - 2014-08-11 22:56 - 00000000 ____D () C:\ProgramData\Adobe
2014-10-13 21:59 - 2014-08-12 06:39 - 00001185 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS6.lnk
2014-10-13 21:59 - 2014-08-12 06:37 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-10-13 21:58 - 2014-08-12 06:37 - 00001539 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS6.lnk
2014-10-13 21:58 - 2014-08-12 06:37 - 00001369 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS6.lnk
2014-10-13 21:57 - 2014-08-12 06:39 - 00000000 ____D () C:\Program Files\Adobe
2014-10-13 21:57 - 2014-08-10 17:17 - 00000000 ____D () C:\Users\Aleksandar\AppData\Roaming\Adobe
2014-10-13 21:56 - 2014-08-12 06:34 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-10-08 17:33 - 2014-08-12 13:19 - 00003272 _____ () C:\Windows\System32\Tasks\update-S-1-5-21-468891226-946991927-1053560233-1001
2014-10-08 17:33 - 2014-08-12 13:19 - 00000447 _____ () C:\Users\Aleksandar\AppData\Local\UserProducts.xml
2014-10-08 17:33 - 2014-08-12 13:19 - 00000000 ____D () C:\Users\Aleksandar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lightshot
2014-10-05 15:18 - 2014-08-28 19:55 - 00000000 ____D () C:\Users\Aleksandar\AppData\Roaming\vlc
2014-10-01 19:58 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2014-10-01 06:37 - 2014-09-25 19:23 - 00000000 ____D () C:\Users\Aleksandar\Desktop\5 Blurred Backgrounds Vol.2
2014-09-26 13:44 - 2013-08-22 14:25 - 00262144 ___SH () C:\Windows\system32\config\BBI

Some content of TEMP:
====================
C:\Users\Aleksandar\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpcqlrad.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-10-19 16:56

==================== End Of Log ============================

mycity.rs/must-login.png

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Arrow Korak 1

Otvori Notepad i iskopiraj sljedeći tekst koji se nalazi unutar Kod polja.

Start
CHR Extension: (X-notifier (for Gmail™,Hotmail,Yahoo,AOL...)) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdfjbkbddpfnoplfhceolpopfoepleco [2014-09-05]
CHR Extension: (Full Page Screen Capture) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdpohaocaechififmbbbbbknoalclacl [2014-10-05]
CHR Extension: (Shield For Chrome ) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\gceighgadbamgchioaofojlblndjcggh [2014-09-04]
EmptyTemp:
End


U okviru Notepad-a klikni na File --> Save As
Fajl nazovi Fixlist i sačuvaj na Desktop
Dvoklikom ponovo pokreni FRST.exe
Klikni na Fix i sačekaj dok program ne završi.
Ukoliko program zatraži restart računara, omogući mu da to nesmetano obavi.
Nakon završetka rada, otvoriće se Notepad, sa sadržajem koji treba da kopiraš u temu.
Takođe, na Desktop-u će se nalaziti (fixlog.txt). Potrebno je da sadržaj fixlog.txt kopiraš na forum




Arrow Korak 2

Preuzmi zoek.exe sa ovog ili ovog linka i sačuvaj ga na Desktop.


Zatvori browser i ostale pokrenute programe;
deaktiviraj zaštitni softver ( po potrebi ) Uputstvo ;
dvoklikom pokreni zoek.exe;
pričekaj da se alat startuje ...


U beli okvir prozora iskopiraj sljedeći tekst:

process;
startupall;
skipfix-iedefaults;
firefoxlook;
chromelook;
filesrcm;


Klikni na dugme i pričekaj da se skeniranje završi.


Zoek će po potrebi restartovati Windows, a na kraju rada otvoriti Notepad sa izvještajem o skeniranju.

Napomena: Izvještaj će biti sačuvan pod nazivom zoek-results.log na sistemskoj particiji (tipična lokacija: C:\zoek-results.log)


Arrow Kopiraj sadržaj tog loga u poruku.

offline
  • Pridružio: 11 Jul 2012
  • Poruke: 46

Arrow Korak 1

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 26-10-2014
Ran by Aleksandar at 2014-10-26 18:00:44 Run:1
Running from C:\Users\Aleksandar\Desktop
Loaded Profile: Aleksandar (Available profiles: Aleksandar)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
CHR Extension: (X-notifier (for Gmail™,Hotmail,Yahoo,AOL...)) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdfjbkbddpfnoplfhceolpopfoepleco [2014-09-05]
CHR Extension: (Full Page Screen Capture) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdpohaocaechififmbbbbbknoalclacl [2014-10-05]
CHR Extension: (Shield For Chrome ) - C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\gceighgadbamgchioaofojlblndjcggh [2014-09-04]
EmptyTemp:
End
*****************

C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdfjbkbddpfnoplfhceolpopfoepleco => Moved successfully.
C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdpohaocaechififmbbbbbknoalclacl => Moved successfully.
C:\Users\Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\gceighgadbamgchioaofojlblndjcggh => Moved successfully.
EmptyTemp: => Removed 326.1 MB temporary data.


The system needed a reboot.

==== End of Fixlog ====


Arrow Korak 2


Zoek.exe v5.0.0.0 Updated 26-10-2014
Tool run by Aleksandar on ned. 26.10.2014. at 18:12:00,86.
Microsoft Windows 8.1 Pro with Media Center 6.3.9600 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Aleksandar\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

26.10.2014. 18:13:03 Zoek.exe System Restore Point Created Succesfully.

==== Running Processes ======================

C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
C:\Program Files (x86)\Yahoo\SoftwareUpdate\YahooAUService.exe
C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe
C:\Users\Aleksandar\AppData\Local\Skillbrains\lightshot\5.1.4.17\Lightshot.exe
C:\Program Files (x86)\MCShield\MCShieldRTM.exe
C:\Users\Aleksandar\AppData\Local\Facebook\Update\FacebookUpdate.exe
D:\deltabh\FSCapture48\FSCapture.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
C:\Users\Aleksandar\Desktop\zoek.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\cmd.exe

==== Files Recently Created / Modified ======================

====== C:\Windows ====
====== C:\Users\ALEKSA~1\AppData\Local\Temp ====
====== Java Cache =====
====== C:\Windows\SysWOW64 =====
2014-10-23 16:24:18 262AD0EF90F757FB715B3EDD6A8E469C 778936 ----a-w- C:\Windows\SysWOW64\PresentationNative_v0300.dll
2014-10-23 16:24:18 2083BD93AE43F9494318B422FF8943D1 102608 ----a-w- C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2014-10-23 16:24:18 134F0E458D2DBDC297CD785F53F7129F 35480 ----a-w- C:\Windows\SysWOW64\TsWpfWrp.exe
====== C:\Windows\SysWOW64\drivers =====
====== C:\Windows\Sysnative =====
2014-10-26 15:09:03 C1CAC3EBBDB3FE0131A9672E43EDB764 29704 ----a-w- C:\Windows\Sysnative\nitrolocalmon2.dll
2014-10-26 15:09:03 530B66672AE8BD426157DE42732E25B1 17928 ----a-w- C:\Windows\Sysnative\nitrolocalui2.dll
2014-10-23 16:24:15 E35AD6DAECED1213658E0976A16D6266 1166520 ----a-w- C:\Windows\Sysnative\PresentationNative_v0300.dll
2014-10-23 16:24:15 DF290FC4E1116D92F34D8B6410AE544E 124112 ----a-w- C:\Windows\Sysnative\PresentationCFFRasterizerNative_v0300.dll
2014-10-23 16:24:15 A0E7332DC41BB85FBE8E266B8CDF5AC4 35480 ----a-w- C:\Windows\Sysnative\TsWpfWrp.exe
====== C:\Windows\Sysnative\drivers =====
====== C:\Windows\Tasks ======
====== C:\Windows\Temp ======
======= C:\Program Files =====
2014-10-26 14:59:29 -------- d-----w- C:\Program Files\Common Files\Nitro
2014-10-23 16:30:45 -------- d-----w- C:\Program Files\Reference Assemblies
2014-10-23 16:30:45 -------- d-----w- C:\Program Files\MSBuild
======= C:\PROGRA~2 =====
2014-10-26 14:59:15 -------- d-----w- C:\PROGRA~2\COMMON~1\Nitro
2014-10-26 14:58:58 -------- d-----w- C:\PROGRA~2\Nitro
2014-10-23 16:34:20 -------- d-----w- C:\PROGRA~2\BetterPoEditor
2014-10-23 16:31:06 -------- d-----w- C:\PROGRA~2\Reference Assemblies
======= C: =====
====== C:\Users\Aleksandar\AppData\Roaming ======
2014-10-26 15:17:06 -------- d-----w- C:\Users\Aleksandar\AppData\Roaming\Nitro
2014-10-26 14:51:06 -------- d-----w- C:\Users\Aleksandar\AppData\Roaming\Downloaded Installations
2014-10-23 16:34:52 -------- d-----w- C:\Users\Aleksandar\AppData\Local\Michele_Locati
2014-10-22 23:25:42 -------- d-----w- C:\Users\Aleksandar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-10-22 23:19:45 -------- d-----w- C:\Users\Aleksandar\AppData\Roaming\Dropbox
2014-10-14 16:32:54 -------- d-----w- C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google
====== C:\Users\Aleksandar ======
2014-10-26 15:21:04 0FF660E032AEE5C0B44A2D9E3BAE65A5 2113024 ----a-w- C:\Users\Aleksandar\Desktop\FRST64.exe
2014-10-26 14:58:58 -------- d-----w- C:\ProgramData\Nitro
2014-10-25 18:16:02 C01900034966F722ED450F1CC6CDD2AC 6126536 ----a-w- C:\Users\Aleksandar\Downloads\FileZilla_3.9.0.6_win32-setup.exe
2014-10-23 16:34:21 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BetterPoEditor
2014-10-22 23:28:07 -------- d-----r- C:\Users\Aleksandar\Dropbox
2014-10-22 23:18:01 3757254F501BAE3264C86513999F1BCD 323672 ----a-w- C:\Users\Aleksandar\Desktop\DropboxInstaller.exe

====== C: exe-files ==
2014-10-26 15:21:04 0FF660E032AEE5C0B44A2D9E3BAE65A5 2113024 ----a-w- C:\Users\Aleksandar\Desktop\FRST64.exe
2014-10-25 18:16:02 C01900034966F722ED450F1CC6CDD2AC 6126536 ----a-w- C:\Users\Aleksandar\Downloads\FileZilla_3.9.0.6_win32-setup.exe
2014-10-23 16:34:20 EC5CB5AA03AE99EB3AF77D1BDA2568DF 249856 ----a-w- C:\Program Files (x86)\BetterPoEditor\BetterPoEditor.exe
2014-10-23 16:34:20 8CFCF204C146B131CF458F4419B4662A 715253 ----a-w- C:\Program Files (x86)\BetterPoEditor\unins000.exe
2014-10-23 16:34:20 75736764DE6376A82080B18E1C0DD49F 110592 ----a-w- C:\Program Files (x86)\BetterPoEditor\NetSpell.DictionaryBuild.exe
2014-10-23 16:34:20 7255663AADAEB4A37C9DC0D758AC588D 2754417 ----a-w- C:\Program Files (x86)\BetterPoEditor\tools\msgfmt.exe
2014-10-23 16:24:15 A0E7332DC41BB85FBE8E266B8CDF5AC4 35480 ----a-w- C:\Windows\System32\TsWpfWrp.exe
2014-10-22 23:25:25 5FD0245516E2A06C527FDB04F0555071 225296 ----a-w- C:\Users\Aleksandar\AppData\Roaming\Dropbox\bin\DropboxUpdateHelper.exe
2014-10-22 23:25:24 93680B96D6C7998998057BA457F2FFBF 35487064 ----a-w- C:\Users\Aleksandar\AppData\Roaming\Dropbox\bin\Dropbox.exe
2014-10-22 23:18:01 3757254F501BAE3264C86513999F1BCD 323672 ----a-w- C:\Users\Aleksandar\Desktop\DropboxInstaller.exe
2014-10-22 17:39:22 68270679465EC5A66B65489C6E44AD64 11100752 ----a-w- C:\Program Files (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\38.0.2125.104\38.0.2125.104_37.0.2062.124_chrome_updater.exe
=== C: other files ==
2014-10-25 19:39:40 EF9F78AEFDB3CAD71748B187C159A130 266160 ----a-w- C:\Users\Aleksandar\Desktop\salmont bekap 25.10.2014\flatsome\inc\plugins\nextend-facebook-connect.zip
2014-10-25 19:39:39 AABEB088A92B7131986121EC0B6FF5C7 3695 ----a-w- C:\Users\Aleksandar\Desktop\salmont bekap 25.10.2014\flatsome\inc\plugins\taxonomy-metadata.zip
2014-10-25 19:39:39 AA2415A71AE0E54750D8A8EEABA76729 26405 ----a-w- C:\Users\Aleksandar\Desktop\salmont bekap 25.10.2014\flatsome\inc\plugins\woosidebars.zip
2014-10-25 19:39:39 925876720F6CBB4342D486E434576553 182835 ----a-w- C:\Users\Aleksandar\Desktop\salmont bekap 25.10.2014\flatsome\inc\plugins\regenerate-thumbnails.zip
2014-10-25 19:39:39 1C57EC5DEF59C03DAB8F84250427AAB2 57053 ----a-w- C:\Users\Aleksandar\Desktop\salmont bekap 25.10.2014\flatsome\inc\plugins\yith-woocommerce-ajax-search.zip
2014-10-23 21:10:36 2BEB1FD0D6AA8B4F8E4A058A5CBFB9E0 1721592 ----a-w- C:\Users\Aleksandar\Desktop\zip\photoshop_letterpress_effect_psd_by_g_seven-d4j8ids.zip
2014-10-23 17:33:50 CD519825E2A964F1660B81FA300A985A 8950609 ----a-w- C:\Users\Aleksandar\Desktop\zip\Quick letter pressed text effect.zip
2014-10-22 23:34:29 25DF3415AD5C084B101110923C187700 40591372 ----a-w- C:\Users\Aleksandar\Dropbox\Knjige\pesma leda i vatre.zip
2014-10-22 23:25:24 2CECD4EA4A73E70B02159E1DBB1DBCE3 1129310 ----a-w- C:\Users\Aleksandar\AppData\Roaming\Dropbox\bin\xui_resources.zip
2014-10-20 17:55:24 332A6B74A45F3EE6A02B4979551216F5 46323 ----a-w- C:\Users\Aleksandar\Desktop\zip\bodoni_svtytwo_sc_itc_tt_book.zip

==== Startup Registry Enabled ======================

[HKEY_USERS\S-1-5-21-468891226-946991927-1053560233-1001\Software\Microsoft\Windows\CurrentVersion\Run]
"LightShot"="C:\Users\Aleksandar\AppData\Local\Skillbrains\lightshot\Lightshot.exe"
"MCShield Monitor"="C:\Program Files (x86)\MCShield\mcshieldrtm.exe"
"Facebook Update"="C:\Users\Aleksandar\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver"
"Messenger (Yahoo\PROGRA~2\Yahoo\Messenger\YahooMessenger.exe -quiet"
"Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe MSRun"
"AMD AVT"="Cmd.exe /c start AMD Accelerated Video Transcoding device initialization /min C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe aml"
"SwitchBoard"="C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe"
"AdobeCS6ServiceManager"="C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe -launchedbylogin"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"LightShot"="C:\Users\Aleksandar\AppData\Local\Skillbrains\lightshot\Lightshot.exe"
"MCShield Monitor"="C:\Program Files (x86)\MCShield\mcshieldrtm.exe"
"Facebook Update"="C:\Users\Aleksandar\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver"
"Messenger (Yahoo\PROGRA~2\Yahoo\Messenger\YahooMessenger.exe -quiet"
"Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun"

==== Startup Registry Enabled x64 ======================

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdobeAAMUpdater-1.0"="C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"

==== Startup Folders ======================

2014-10-22 23:27:10 1103 ----a-w- C:\Users\Aleksandar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
2014-10-05 16:13:05 769 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FastStone Capture.lnk

==== Task Scheduler Jobs ======================

C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-468891226-946991927-1053560233-1001Core.job --a-------- C:\Users\Aleksandar\AppData\Local\Facebook\Update\FacebookUpdate.exC: nocrashserverDeltaBH\AleksandarKeeps your Facebook software up to date. If this task is disabled or stopped your Facebook software will not be kept up to date meaning sC:urity vulnerabilities that may arise cannot be fixed and features may not work. This task uninstalls itself when there is no Facebook software using it.0 []
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-468891226-946991927-1053560233-1001UA.job --a-------- [Undetermined Task]
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a-------- [Undetermined Task]
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a-------- [Undetermined Task]
C:\Windows\tasks\update-S-1-5-21-468891226-946991927-1053560233-1001.job --a-------- [Undetermined Task]
C:\Windows\tasks\update-sys.job --a-------- [Undetermined Task]

==== Other Scheduled Tasks ======================

"C:\Windows\SysNative\tasks\AdobeAAMUpdater-1.0-DeltaBH-Aleksandar" [C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe]
"C:\Windows\SysNative\tasks\AutoKMS" [C:\Windows\AutoKMS\AutoKMS.exe]
"C:\Windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"]
"C:\Windows\SysNative\tasks\FacebookUpdateTaskUserS-1-5-21-468891226-946991927-1053560233-1001Core" [C:\Users\Aleksandar\AppData\Local\Facebook\Update\FacebookUpdate.exe]
"C:\Windows\SysNative\tasks\FacebookUpdateTaskUserS-1-5-21-468891226-946991927-1053560233-1001UA" [C:\Users\Aleksandar\AppData\Local\Facebook\Update\FacebookUpdate.exe]
"C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe]
"C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe]
"C:\Windows\SysNative\tasks\update-S-1-5-21-468891226-946991927-1053560233-1001" [C:\Program Files (x86)\Skillbrains\Updater\Updater.exe]
"C:\Windows\SysNative\tasks\update-sys" [C:\Program Files (x86)\Skillbrains\Updater\Updater.exe]
"C:\Windows\SysNative\tasks\{CE6A2F4C-155B-4B00-AB09-AAC15FC4430D}" ["c:\program files (x86)\google\chrome\application\chrome.exe"]
"C:\Windows\SysNative\tasks\{FC6BF67D-4C04-4B88-9208-18F55F0B75BF}" ["c:\program files (x86)\google\chrome\application\chrome.exe"]
"C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc]

==== Chromium Look ======================

Entanglement Web App - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd
Note Board Web - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\apgackkfllmckgkbdfmbfodpinmnnpab
Google Voice Search Hotword (Beta) - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn
WOT - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp
Honey - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj
ClickClean - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghgabhipcejejjmhhchfonmamedcbeod
AdBlock - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom
PDF Mergy - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgecghmkcdefnknohcimkoemhaofpoha
Bitly | Unleash the power of the link - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\iabeihobmhlgpkcgjiloemdbofjbdcic
Free online speed typing tests find whats your WPM words per minute speed improve your typing skills and practice typing. - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkcieoaeooeidmpaopkpjpjfakidlabm
Todoist To-Do list and Task Manager - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\jldhpllghnbhlbpcmnajkpdmadaolakh
Auto Replay for YouTube™ - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\kanbnempkjnhadplbfgdaagijdbdbjeb
Google Mail Checker - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff
Quick Note - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\mijlebbfndhelmdpmllgcfadlkankhok
Google Wallet - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Buffer - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\noojglkidnpfjbincgijbaiedldjfbhh
Background Tab - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\oehpjpccmlcalbenfhnacjeocbjdonic
ClickClean App - Aleksandar\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp

==== IE Start and Search Settings ======================

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR"

==== C:\zoek_backup content ======================

C:\zoek_backup (files=0 folders=0 0 bytes)

==== EOF on ned. 26.10.2014. at 18:18:04,57 ======================

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

U postavljenom izvještaju nisam našao ništa sporno. Obavićemo još jednu provjeru.


Preuzmi Malwarebytes Anti-Rootkit (MBAR) sa sledeceg linka i sacuvaj ga na Desktop.

Dvoklikom pokreni MBAR () na ikonicu programa:
- Klikni OK na sledecem prozoru da bi dozvolio raspakivanje u zaseban mbar folder na desktop-u;
- mbar.exe ce biti startovan. Na nekim sistemima to moze da potraje nekoliko dodatnih sekundi, te pricekati pokretanje.;
- U uvodnom prozoru klikni dugme Next ukoliko si saglasan;



• Na 'Update Database' prozoru klik na dugme Update da bi preuzeo sveze definicije. Kada se ispise poruka 'Success: Database was successfully updated' klik na dugme Next;
• Pod sekcijom 'Scan Targets' proveri da su sve opcije stiklirane, te klikni na dugme Scan;

Obavestenje: sa nekim infekcijama moze se desiti da se prikaze neka od sledecih poruka:
- 'Could not load protection driver' => u tom slucaju klikni OK.
- 'Could not load DDA driver' => klikni Yes na to obavestenje da bi dozvolio ucitavanje nakon restarta. Dozvoli restart i nastavi sa ostatkom instrukcija posle restarta.





>> Ukoliko malware nije detektovan, klik na Exit dugme da zatvoris program. U sledecu poruku postavi mbar-log-year-month-day (sat-minuti-sekundi).txt i system-log.txt izveštaje.

>> Ukoliko su infekcija/e pronadjene, proveriti da li je obelezena opcija 'Create Restore Point' i klikni na dugme Cleanup! da bi uklonili pretnje.
- Procedura uklanjanje malware-a (scheduled) ce biti zakazana po restartu, bice prikazano obavestenje u pop-up prozoru. Klikni dugme Yes i sistem bi trebao da se restartuje i da zavrsi proceduru ciscenja.



Obavestenje! samo ukoliko je RootKit detektovan: - postaraj se da pokrenes fixdamage.exe alat koji se nalazi u mbar folderu, \Plugins\fixdamage.exe:
- Dvoklikom pokreni fixdamage, u crnom prozoru koji se otvori (command prompt) ukucaj Y (Y stoji za Yes) da bi nastavio izvrsenje, pricekati da alat odradi sve popravke ...
- Kada vidis poruku 'press any key to exit' popravka je kompletirana. Pritisnuti bilo koju tipku na tastaturi da bi se prozor zatvorio. Restartovati sistem.





Sledeci izvestaji ce biti formirani u mbar folderu.
1. mbar-log-year-month-day (hour-minute-second).txt
2. system-log.txt

Iskopiraj sadrzaj mbar log-a u poruku a system log okaci uz poruku koristeci opciju Prikači fajl.

offline
  • Pridružio: 11 Jul 2012
  • Poruke: 46

Malwarebytes Anti-Rootkit BETA 1.07.0.1012
malwarebytes.org

Database version: v2014.10.30.11

Windows 8.1 x64 NTFS
Internet Explorer 11.0.9600.17031
Aleksandar :: DELTABH [administrator]

30.10.2014. 18:17:36
mbar-log-2014-10-30 (18-17-36).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 316529
Time elapsed: 33 minute(s),

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)

mycity.rs/must-login.png

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Tvoj računar je čist što se malicioznih programa tiče. Otvori temu u Windows potforumu i tamo iznesi svoj problem.

Sledeća procedura će implementirati završno čišćenje.

Arrow Preuzmi "Xplode"-ov DelFix alat i snimi ga na Desktop.
Dvoklikom pokreni alat i štikliraj kućice ispred sledećih opcija;

Remove disinfection tools
Create registry backup
Purge System Restore


Klikni na dugme Run i pričekaj trenutak dok alat ne završi svoj rad.
Od ovog trenutka, svi korišćeni alati u ovoj temi bi trebali biti obrisani.
Alat će takođe formirati izveštaj za tebe. (C:\DelFix.txt)

Alat će snimiti i zdravo stanje registy-ja i napraviti backup koristeci integrisan program "ERUNT" u %windir%\ERUNT\DelFix
Alat briše stare system restore tačke i pravi novu, svežu tačku nakon čišćenja.

offline
  • Pridružio: 11 Jul 2012
  • Poruke: 46

Hvala.

Srdačan pozdrav i ugodan ostatak dana!

Ko je trenutno na forumu
 

Ukupno su 929 korisnika na forumu :: 9 registrovanih, 2 sakrivenih i 918 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: cikadeda, draggan, Georgius, Kenanjoz, Krvava Devetka, milenko crazy north, pacika, saputnik plavetnila, sasa76