Valjda internet

3

Valjda internet

offline
  • Pridružio: 01 Jun 2014
  • Poruke: 23

nisi mi poslao FRST



offline
  • Pridružio: 09 Avg 2011
  • Poruke: 15879
  • Gde živiš: Beograd

Poslao sam ti link Smile

[Link mogu videti samo ulogovani korisnici]



offline
  • Pridružio: 01 Jun 2014
  • Poruke: 23

Napisano: 04 Jun 2014 0:54

Uspelo je druže Very Happy nisam ja shvatio na šta misliš pod FRST odmah xD

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-06-2014
Ran by win7 (administrator) on WIN7-PC on 04-06-2014 00:43:44
Running from C:\Users\win7\Downloads
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: [Link mogu videti samo ulogovani korisnici]
Download link for 64-Bit Version: [Link mogu videti samo ulogovani korisnici]
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: [Link mogu videti samo ulogovani korisnici]

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(BitTorrent Inc.) C:\Users\win7\AppData\Roaming\uTorrent\uTorrent.exe
(Akamai Technologies, Inc.) C:\Users\win7\AppData\Local\Akamai\netsession_win.exe
(Akamai Technologies, Inc.) C:\Users\win7\AppData\Local\Akamai\netsession_win.exe
() C:\Program Files (x86)\AVG Secure Search\vprot.exe
(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.0\ToolbarUpdater.exe
() C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.0\loggingserver.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\audiodg.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

HKLM-x32\...\Run: [vProt] => C:\Program Files (x86)\AVG Secure Search\vprot.exe [2557976 2014-04-27] ()
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [3888648 2014-06-01] (AVAST Software)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKU\S-1-5-21-169506411-3708393231-39178482-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [17706088 2013-02-07] (Skype Technologies S.A.)
HKU\S-1-5-21-169506411-3708393231-39178482-1000\...\Run: [uTorrent] => C:\Users\win7\AppData\Roaming\uTorrent\uTorrent.exe [1270352 2014-04-29] (BitTorrent Inc.)
HKU\S-1-5-21-169506411-3708393231-39178482-1000\...\Run: [Akamai NetSession Interface] => C:\Users\win7\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.)
HKU\S-1-5-21-169506411-3708393231-39178482-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [Link mogu videti samo ulogovani korisnici]
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - DefaultScope {1A60F180-496E-4E03-98B3-110464D79941} URL =
SearchScopes: HKCU - DefaultScope {1A60F180-496E-4E03-98B3-110464D79941} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}&SearchSource=4&ctid=CT3282698&CUI=UN21704424982530139&UM=2
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}&babsrc=SP_ss_Btisdt4&mntrId=321174DE2B10034A&affID=119776&tsp=5004
SearchScopes: HKCU - {185B5932-4EC3-4492-B9F2-C0A8ACC60760} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}
SearchScopes: HKCU - {1A60F180-496E-4E03-98B3-110464D79941} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}&SearchSource=4&ctid=CT3282698&CUI=UN21704424982530139&UM=2
SearchScopes: HKCU - {CDA45BC0-98B6-4367-8E38-5AA3B6AAE1A5} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}&SearchSource=4&cc=&mi=321197d700000000000074de2b10034a&r=754
SearchScopes: HKCU - {DE9F5114-D6D7-4DB1-8B46-29D8D5E656E9} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO-x32: SecretSauce - {0ffd0ef2-dbe9-483a-80c4-d2c331da1ce4} - C:\Program Files (x86)\SecretSauce\SecretSauceBHO.dll No File
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: No Name - {95B7759C-8C7F-4BF1-B163-73684A933233} - No File
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM-x32 - No Name - {95B7759C-8C7F-4BF1-B163-73684A933233} - No File
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.0\ViProtocol.dll (AVG Secure Search)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\win7\AppData\Roaming\Mozilla\Firefox\Profiles\4hcbmhpf.default
FF DefaultSearchEngine: BS Player ControlBar Customized Web Search
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\18.1.0\\npsitesafety.dll No File
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @gentek.com/thinclient - C:\IGG\twclient_us\npthinclient.dll No File
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\win7\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF user.js: detected! => C:\Users\win7\AppData\Roaming\Mozilla\Firefox\Profiles\4hcbmhpf.default\user.js
FF SearchPlugin: C:\Users\win7\AppData\Roaming\Mozilla\Firefox\Profiles\4hcbmhpf.default\searchplugins\bs-player-controlbar-customized-web-search.xml
FF SearchPlugin: C:\Users\win7\AppData\Roaming\Mozilla\Firefox\Profiles\4hcbmhpf.default\searchplugins\softonic.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\sweettunes_search.xml
FF Extension: SweetTunes1 - C:\Users\win7\AppData\Roaming\Mozilla\Firefox\Profiles\4hcbmhpf.default\Extensions\{f9d1c08c-2031-4e6c-ab51-50330ac2d988} [2014-06-03]
FF Extension: BS Player ControlBar - C:\Users\win7\AppData\Roaming\Mozilla\Firefox\Profiles\4hcbmhpf.default\Extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} [2014-06-02]
FF Extension: FT Downloader - C:\Users\win7\AppData\Roaming\Mozilla\Firefox\Profiles\4hcbmhpf.default\Extensions\ftd@ftd.com.xpi [2013-06-26]
FF Extension: SecretSauce - C:\Users\win7\AppData\Roaming\Mozilla\Firefox\Profiles\4hcbmhpf.default\Extensions\{345422e3-72fa-447a-9550-97803edfacf3}.xpi [2014-02-04]
FF HKLM-x32\...\Firefox\Extensions: [xz123@ya456.com] - C:\Program Files (x86)\BetterSurf\ff
FF Extension: No Name - C:\Program Files (x86)\BetterSurf\ff [2013-11-14]
FF HKLM-x32\...\Firefox\Extensions: [12x3q@3244516.com] - C:\Program Files (x86)\Better-Surf\ff
FF Extension: No Name - C:\Program Files (x86)\Better-Surf\ff [2013-11-26]
FF HKLM-x32\...\Firefox\Extensions: [ext@bettersurfplus.com] - C:\Program Files (x86)\BetterSurf\BetterSurfPlus\ff
FF Extension: No Name - C:\Program Files (x86)\BetterSurf\BetterSurfPlus\ff [2013-12-10]
FF HKLM-x32\...\Firefox\Extensions: [ext@WebexpEnhancedV1alpha800.net] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha800\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@VideoPlayerV3beta220.net] - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta220\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaPlayerV1alpha293.net] - C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha293\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaViewerV1alpha1806.net] - C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha1806\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaViewV1alpha1507.net] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1507\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaWatchV1home218.net] - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home218\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaBuzzV1mode4065.net] - C:\Program Files (x86)\MediaBuzzV1\MediaBuzzV1mode4065\ff
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-05-22]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird

Chrome:
=======
CHR Extension: (Google Drive) - C:\Users\win7\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-08-07]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\win7\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-05-23]
CHR Extension: (YouTube) - C:\Users\win7\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-08-07]
CHR Extension: (Google Search) - C:\Users\win7\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-08-07]
CHR Extension: (Google Wallet) - C:\Users\win7\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-21]
CHR Extension: (Gmail) - C:\Users\win7\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-08-07]
CHR HKCU\...\Chrome\Extension: [cflheckfmhopnialghigdlggahiomebp] - C:\Users\win7\AppData\Local\CRE\cflheckfmhopnialghigdlggahiomebp.crx [2013-08-07]
CHR HKCU\...\Chrome\Extension: [giolhomkcooifelkdfpejhidfidaahlc] - C:\Users\win7\AppData\Local\CRE\giolhomkcooifelkdfpejhidfidaahlc.crx [2013-10-03]
CHR HKLM-x32\...\Chrome\Extension: [cflheckfmhopnialghigdlggahiomebp] - C:\Users\win7\AppData\Local\CRE\cflheckfmhopnialghigdlggahiomebp.crx [2013-10-03]
CHR HKLM-x32\...\Chrome\Extension: [dbpebffoameokfhnaaedmefjncfboino] - C:\Program Files (x86)\SecretSauce\dbpebffoameokfhnaaedmefjncfboino.crx [2013-10-03]
CHR HKLM-x32\...\Chrome\Extension: [dedmngkbaffkenlfdcbganndoghblmap] - C:\Program Files (x86)\BetterSurf\ch\Chrome.crx [2013-10-03]
CHR HKLM-x32\...\Chrome\Extension: [deihhdcgleffbeklojkembpgmenfjgbi] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1507\ch\MediaViewV1alpha1507.crx [2013-10-03]
CHR HKLM-x32\...\Chrome\Extension: [fokohpfmgfedjpcfmflailjgoekaldka] - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta220\ch\VideoPlayerV3beta220.crx [2013-10-03]
CHR HKLM-x32\...\Chrome\Extension: [giolhomkcooifelkdfpejhidfidaahlc] - C:\Users\win7\AppData\Local\CRE\giolhomkcooifelkdfpejhidfidaahlc.crx [2013-10-03]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-05-22]
CHR HKLM-x32\...\Chrome\Extension: [inldfkehmpgiankjeocgjbieccdcjncp] - C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha1806\ch\MediaViewerV1alpha1806.crx [2014-05-22]
CHR HKLM-x32\...\Chrome\Extension: [mjljkmhdlcmkkkjkefeeoaphpikpdodd] - C:\Program Files (x86)\MediaBuzzV1\MediaBuzzV1mode4065\ch\MediaBuzzV1mode4065.crx [2014-05-22]
CHR HKLM-x32\...\Chrome\Extension: [mmifolfpllfdhilecpdpmemhelmanajl] - C:\Program Files (x86)\BetterSurf\BetterSurfPlus\ch\BetterSurfPlus.crx [2014-05-22]
CHR HKLM-x32\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\ProgramData\AVG Secure Search\ChromeExt\18.1.0.443\avg.crx [2014-04-27]
CHR HKLM-x32\...\Chrome\Extension: [ofddoohgffcmgnajhoblocignnnjnbma] - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home218\ch\MediaWatchV1home218.crx [2014-04-27]
CHR HKLM-x32\...\Chrome\Extension: [ogfaegbpanaecpfjidcbhhnlpgoaookh] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha800\ch\WebexpEnhancedV1alpha800.crx [2014-04-27]
CHR HKLM-x32\...\Chrome\Extension: [poheodfamflhhhdcmjfeggbgigeefaco] - C:\Program Files (x86)\Better-Surf\ch\Chrome.crx [2014-04-27]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-05-22] (AVAST Software)
R2 vToolbarUpdater18.1.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.0\ToolbarUpdater.exe [1801240 2014-04-27] (AVG Secure Search)
S3 MozillaMaintenance; "C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe" [X]

==================== Drivers (Whitelisted) ====================

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-05-22] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-05-22] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-05-22] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-05-22] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-05-22] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-05-22] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [85328 2014-05-22] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208416 2014-05-22] ()
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [50464 2014-04-27] (AVG Technologies)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-09-13] (DT Soft Ltd)
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-06-04 00:43 - 2014-06-04 00:44 - 00017004 _____ () C:\Users\win7\Downloads\FRST.txt
2014-06-04 00:43 - 2014-06-04 00:43 - 00000000 ____D () C:\FRST
2014-06-04 00:42 - 2014-06-04 00:42 - 02068992 _____ (Farbar) C:\Users\win7\Downloads\FRST64.exe
2014-06-04 00:35 - 2014-06-04 00:35 - 01059840 _____ (Farbar) C:\Users\win7\Downloads\FRST.exe
2014-06-03 20:50 - 2014-06-03 20:50 - 00025069 _____ () C:\ComboFix.txt
2014-06-03 20:50 - 2014-06-03 20:50 - 00000000 ____D () C:\Users\Public\AppData\Local\temp
2014-06-03 20:50 - 2014-06-03 20:50 - 00000000 ____D () C:\Users\Default\AppData\Local\temp
2014-06-03 20:50 - 2014-06-03 20:50 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp
2014-06-02 23:24 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-06-02 23:24 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-06-02 23:24 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-06-02 23:24 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-06-02 23:24 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-06-02 23:24 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-06-02 23:24 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-06-02 23:24 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-06-02 23:23 - 2014-06-03 20:50 - 00000000 ____D () C:\Qoobox
2014-06-02 23:23 - 2014-06-03 20:45 - 00000000 ____D () C:\Windows\erdnt
2014-06-02 23:20 - 2014-06-03 20:33 - 05206532 ____R (Swearware) C:\Users\win7\Desktop\ComboFix.exe
2014-06-02 20:45 - 2014-06-02 20:45 - 00000000 ____D () C:\zoek_backup
2014-06-01 23:14 - 2014-06-01 23:14 - 00000000 ____D () C:\Users\win7\Desktop\Kristina
2014-05-26 16:47 - 2014-05-26 16:50 - 00000000 ____D () C:\Program Files (x86)\Yu-Gi-Oh! Power Chaos common
2014-05-22 12:03 - 2014-05-22 12:02 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-05-22 12:02 - 2014-06-01 20:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-05-22 12:02 - 2014-05-22 12:02 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-05-22 12:02 - 2014-05-22 12:02 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-05-22 12:02 - 2014-05-22 12:02 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-05-22 00:49 - 2014-05-22 00:49 - 00000000 ____D () C:\Users\win7\AppData\Roaming\AVAST Software
2014-05-22 00:48 - 2014-06-01 20:34 - 00001966 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-05-22 00:48 - 2014-06-01 20:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-05-22 00:47 - 2014-06-02 21:51 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-05-22 00:47 - 2014-05-22 00:47 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys.1400712477417
2014-05-22 00:47 - 2014-05-22 00:47 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2014-05-22 00:47 - 2014-05-22 00:47 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys.1400712477417
2014-05-22 00:47 - 2014-05-22 00:47 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-05-22 00:47 - 2014-05-22 00:47 - 00208416 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-05-22 00:47 - 2014-05-22 00:47 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-05-22 00:47 - 2014-05-22 00:47 - 00085328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2014-05-22 00:47 - 2014-05-22 00:47 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-05-22 00:47 - 2014-05-22 00:47 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-05-22 00:47 - 2014-05-22 00:47 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-05-22 00:47 - 2014-05-22 00:47 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-05-22 00:46 - 2014-05-22 00:46 - 00000000 ____D () C:\Program Files\AVAST Software
2014-05-19 13:00 - 2014-05-19 13:12 - 580310760 _____ () C:\Users\win7\Desktop\kiki.mxf
2014-05-18 19:02 - 2014-05-19 12:59 - 00028904 _____ () C:\Users\win7\Desktop\kiki.veg
2014-05-15 12:23 - 2014-05-15 12:23 - 00000000 ____D () C:\Windows\CheckSur
2014-05-14 18:47 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-14 18:47 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-14 18:47 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-05-14 18:47 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-05-14 18:47 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-05-14 18:47 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-05-14 18:47 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-05-14 18:47 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-05-14 18:47 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-05-14 18:47 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-05-14 18:47 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-05-14 18:47 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-14 18:47 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-14 18:47 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-05-14 18:47 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-05-14 18:47 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-05-14 18:47 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-05-14 18:47 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-05-14 18:47 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-05-14 18:47 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-05-14 18:47 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-05-14 18:47 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-05-14 18:47 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-05-14 18:47 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-05-14 18:47 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-05-14 18:47 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-05-14 18:47 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-05-14 18:47 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-05-14 18:47 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-05-14 18:47 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-05-14 18:47 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-05-14 18:47 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-05-14 18:47 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-05-14 18:47 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-05-14 18:47 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-05-14 18:47 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-05-14 18:47 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-05-14 18:47 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2014-05-14 18:47 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2014-05-14 18:47 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2014-05-14 18:47 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2014-05-14 18:47 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-05-14 18:47 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2014-05-14 18:47 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-05-14 18:47 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-05-12 17:02 - 2014-05-12 17:02 - 397025428 _____ () C:\Windows\MEMORY.DMP
2014-05-12 17:02 - 2014-05-12 17:02 - 00344088 _____ () C:\Windows\Minidump\051214-16255-01.dmp
2014-05-12 17:02 - 2014-05-12 17:02 - 00000000 ____D () C:\Windows\Minidump
2014-05-11 21:30 - 2014-06-01 20:29 - 00000000 ____D () C:\Users\win7\Desktop\Luna (pjevacica_mala) on Twitter_files
2014-05-11 21:25 - 2014-05-11 21:25 - 13003141 _____ () C:\Users\win7\Documents\4U (California King Bed - Rihanna) - X Factor Adria - LIVE 5 - Pesma spasa.mp4
2014-05-09 23:28 - 2014-05-09 23:28 - 00000080 _____ () C:\Users\win7\Documents\Sookie lovers.mxf.sfl
2014-05-09 21:29 - 2014-05-09 21:29 - 06723629 _____ () C:\Users\win7\Documents\True Blood_ Sookie meets Bill for the first time 1x01.mp4
2014-05-08 23:57 - 2014-05-08 23:57 - 00000981 _____ () C:\Users\win7\Desktop\vegas110 - Shortcut.lnk
2014-05-08 23:57 - 2014-05-08 23:57 - 00000000 ____D () C:\Users\win7\AppData\Roaming\Publish Providers
2014-05-08 23:49 - 2014-05-08 23:49 - 00000728 _____ () C:\Users\win7\Documents\Default.sfvidcap
2014-05-08 23:47 - 2014-05-08 23:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2014-05-08 23:46 - 2014-05-08 23:49 - 00000000 ____D () C:\Users\win7\AppData\Local\Sony
2014-05-08 23:46 - 2014-05-08 23:46 - 00000000 ____D () C:\ProgramData\Sony
2014-05-08 23:46 - 2014-05-08 23:46 - 00000000 ____D () C:\Program Files (x86)\Sony
2014-05-08 23:41 - 2014-05-09 23:06 - 00000000 ____D () C:\Users\win7\AppData\Roaming\Sony
2014-05-06 10:06 - 2014-05-15 14:06 - 00000000 ___SD () C:\Windows\system32\CompatTel

==================== One Month Modified Files and Folders =======

2014-06-04 00:44 - 2014-06-04 00:43 - 00017004 _____ () C:\Users\win7\Downloads\FRST.txt
2014-06-04 00:44 - 2013-08-07 16:15 - 00000000 ____D () C:\Users\win7\AppData\Local\Temp
2014-06-04 00:43 - 2014-06-04 00:43 - 00000000 ____D () C:\FRST
2014-06-04 00:43 - 2013-08-07 17:36 - 00000000 ____D () C:\Users\win7\AppData\Roaming\uTorrent
2014-06-04 00:42 - 2014-06-04 00:42 - 02068992 _____ (Farbar) C:\Users\win7\Downloads\FRST64.exe
2014-06-04 00:42 - 2013-08-07 16:45 - 00000000 ____D () C:\Users\win7\AppData\Roaming\Skype
2014-06-04 00:35 - 2014-06-04 00:35 - 01059840 _____ (Farbar) C:\Users\win7\Downloads\FRST.exe
2014-06-04 00:23 - 2013-08-07 16:14 - 01765917 _____ () C:\Windows\WindowsUpdate.log
2014-06-04 00:09 - 2013-08-07 16:30 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-04 00:01 - 2013-11-29 01:16 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-03 22:54 - 2013-08-13 13:49 - 00000924 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-169506411-3708393231-39178482-1000UA.job
2014-06-03 22:52 - 2013-08-07 16:29 - 00000890 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-03 22:52 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-03 22:52 - 2009-07-14 06:51 - 00060719 _____ () C:\Windows\setupact.log
2014-06-03 22:48 - 2009-07-14 06:45 - 00020832 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-03 22:48 - 2009-07-14 06:45 - 00020832 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-03 20:50 - 2014-06-03 20:50 - 00025069 _____ () C:\ComboFix.txt
2014-06-03 20:50 - 2014-06-03 20:50 - 00000000 ____D () C:\Users\Public\AppData\Local\temp
2014-06-03 20:50 - 2014-06-03 20:50 - 00000000 ____D () C:\Users\Default\AppData\Local\temp
2014-06-03 20:50 - 2014-06-03 20:50 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp
2014-06-03 20:50 - 2014-06-02 23:23 - 00000000 ____D () C:\Qoobox
2014-06-03 20:46 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-06-03 20:45 - 2014-06-02 23:23 - 00000000 ____D () C:\Windows\erdnt
2014-06-03 20:45 - 2010-11-21 05:47 - 00285112 _____ () C:\Windows\PFRO.log
2014-06-03 20:45 - 2009-07-14 04:34 - 58204160 _____ () C:\Windows\system32\config\SOFTWARE.bak
2014-06-03 20:45 - 2009-07-14 04:34 - 14680064 _____ () C:\Windows\system32\config\SYSTEM.bak
2014-06-03 20:45 - 2009-07-14 04:34 - 00159744 _____ () C:\Windows\system32\config\DEFAULT.bak
2014-06-03 20:45 - 2009-07-14 04:34 - 00061440 _____ () C:\Windows\system32\config\SAM.bak
2014-06-03 20:45 - 2009-07-14 04:34 - 00024576 _____ () C:\Windows\system32\config\SECURITY.bak
2014-06-03 20:33 - 2014-06-02 23:20 - 05206532 ____R (Swearware) C:\Users\win7\Desktop\ComboFix.exe
2014-06-03 19:48 - 2009-07-14 04:34 - 00000699 _____ () C:\Windows\win.ini
2014-06-03 00:34 - 2013-09-23 21:59 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-02 23:43 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-06-02 23:32 - 2013-09-10 00:23 - 00000000 ____D () C:\ProgramData\TEMP
2014-06-02 21:51 - 2014-05-22 00:47 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-06-02 20:45 - 2014-06-02 20:45 - 00000000 ____D () C:\zoek_backup
2014-06-01 23:14 - 2014-06-01 23:14 - 00000000 ____D () C:\Users\win7\Desktop\Kristina
2014-06-01 20:37 - 2009-07-14 07:13 - 00005152 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-01 20:34 - 2014-05-22 00:48 - 00001966 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-06-01 20:30 - 2013-08-19 23:15 - 00001108 __RSH () C:\Users\win7\ntuser.pol
2014-06-01 20:30 - 2013-08-07 16:15 - 00000000 ____D () C:\Users\win7
2014-06-01 20:29 - 2014-05-22 12:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-06-01 20:29 - 2014-05-22 00:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-06-01 20:29 - 2014-05-11 21:30 - 00000000 ____D () C:\Users\win7\Desktop\Luna (pjevacica_mala) on Twitter_files
2014-06-01 20:29 - 2013-11-26 00:03 - 00000000 ____D () C:\Program Files (x86)\Better-Surf
2014-06-01 20:29 - 2013-11-14 00:03 - 00000000 ____D () C:\Program Files (x86)\BetterSurf
2014-06-01 20:29 - 2013-08-13 11:54 - 00000000 ____D () C:\Users\win7\AppData\Local\Akamai
2014-06-01 20:29 - 2013-08-07 16:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-06-01 20:29 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration
2014-06-01 20:29 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\AppCompat
2014-05-27 23:21 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-05-27 23:14 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-05-27 23:11 - 2013-08-07 16:30 - 00002183 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-05-27 23:06 - 2010-11-21 09:16 - 00000000 ___RD () C:\Users\Public\Recorded TV
2014-05-26 16:50 - 2014-05-26 16:47 - 00000000 ____D () C:\Program Files (x86)\Yu-Gi-Oh! Power Chaos common
2014-05-22 12:04 - 2014-04-24 16:07 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-05-22 12:03 - 2013-09-13 18:27 - 00000000 ____D () C:\Users\win7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-05-22 12:03 - 2013-09-13 18:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-05-22 12:03 - 2013-09-13 18:27 - 00000000 ____D () C:\Program Files (x86)\WinRAR
2014-05-22 12:02 - 2014-05-22 12:03 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-05-22 12:02 - 2014-05-22 12:02 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-05-22 12:02 - 2014-05-22 12:02 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-05-22 12:02 - 2014-05-22 12:02 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-05-22 11:59 - 2014-04-24 14:47 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-05-22 00:49 - 2014-05-22 00:49 - 00000000 ____D () C:\Users\win7\AppData\Roaming\AVAST Software
2014-05-22 00:47 - 2014-05-22 00:47 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys.1400712477417
2014-05-22 00:47 - 2014-05-22 00:47 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2014-05-22 00:47 - 2014-05-22 00:47 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys.1400712477417
2014-05-22 00:47 - 2014-05-22 00:47 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-05-22 00:47 - 2014-05-22 00:47 - 00208416 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-05-22 00:47 - 2014-05-22 00:47 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-05-22 00:47 - 2014-05-22 00:47 - 00085328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2014-05-22 00:47 - 2014-05-22 00:47 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-05-22 00:47 - 2014-05-22 00:47 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-05-22 00:47 - 2014-05-22 00:47 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-05-22 00:47 - 2014-05-22 00:47 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-05-22 00:47 - 2013-08-07 20:12 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-05-22 00:46 - 2014-05-22 00:46 - 00000000 ____D () C:\Program Files\AVAST Software
2014-05-22 00:46 - 2013-08-07 20:11 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-05-22 00:44 - 2013-08-07 16:29 - 00000000 ____D () C:\ProgramData\Package Cache
2014-05-21 13:54 - 2013-08-13 13:49 - 00000902 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-169506411-3708393231-39178482-1000Core.job
2014-05-19 13:12 - 2014-05-19 13:00 - 580310760 _____ () C:\Users\win7\Desktop\kiki.mxf
2014-05-19 12:59 - 2014-05-18 19:02 - 00028904 _____ () C:\Users\win7\Desktop\kiki.veg
2014-05-18 19:33 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-05-15 14:09 - 2013-08-07 16:15 - 00000000 ___RD () C:\Users\win7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-15 14:09 - 2013-08-07 16:15 - 00000000 ___RD () C:\Users\win7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-15 14:06 - 2014-05-06 10:06 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-15 14:05 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-05-15 12:23 - 2014-05-15 12:23 - 00000000 ____D () C:\Windows\CheckSur
2014-05-14 23:20 - 2013-08-26 18:04 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-05-14 15:01 - 2013-11-29 01:16 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-14 15:01 - 2013-11-29 01:16 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-14 15:01 - 2013-11-29 01:16 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-12 17:02 - 2014-05-12 17:02 - 397025428 _____ () C:\Windows\MEMORY.DMP
2014-05-12 17:02 - 2014-05-12 17:02 - 00344088 _____ () C:\Windows\Minidump\051214-16255-01.dmp
2014-05-12 17:02 - 2014-05-12 17:02 - 00000000 ____D () C:\Windows\Minidump
2014-05-11 21:25 - 2014-05-11 21:25 - 13003141 _____ () C:\Users\win7\Documents\4U (California King Bed - Rihanna) - X Factor Adria - LIVE 5 - Pesma spasa.mp4
2014-05-09 23:28 - 2014-05-09 23:28 - 00000080 _____ () C:\Users\win7\Documents\Sookie lovers.mxf.sfl
2014-05-09 23:06 - 2014-05-08 23:41 - 00000000 ____D () C:\Users\win7\AppData\Roaming\Sony
2014-05-09 21:29 - 2014-05-09 21:29 - 06723629 _____ () C:\Users\win7\Documents\True Blood_ Sookie meets Bill for the first time 1x01.mp4
2014-05-09 08:14 - 2014-05-14 18:47 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-09 08:11 - 2014-05-14 18:47 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-08 23:57 - 2014-05-08 23:57 - 00000981 _____ () C:\Users\win7\Desktop\vegas110 - Shortcut.lnk
2014-05-08 23:57 - 2014-05-08 23:57 - 00000000 ____D () C:\Users\win7\AppData\Roaming\Publish Providers
2014-05-08 23:49 - 2014-05-08 23:49 - 00000728 _____ () C:\Users\win7\Documents\Default.sfvidcap
2014-05-08 23:49 - 2014-05-08 23:46 - 00000000 ____D () C:\Users\win7\AppData\Local\Sony
2014-05-08 23:47 - 2014-05-08 23:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2014-05-08 23:46 - 2014-05-08 23:46 - 00000000 ____D () C:\ProgramData\Sony
2014-05-08 23:46 - 2014-05-08 23:46 - 00000000 ____D () C:\Program Files (x86)\Sony
2014-05-07 11:11 - 2013-10-15 15:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2014-05-07 01:04 - 2013-08-07 16:30 - 00003890 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-05-07 01:04 - 2013-08-07 16:29 - 00003638 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore

Some content of TEMP:
====================
C:\Users\win7\AppData\Local\Temp\7za.exe
C:\Users\win7\AppData\Local\Temp\hijackthis.exe
C:\Users\win7\AppData\Local\Temp\NirCmd.exe
C:\Users\win7\AppData\Local\Temp\PEVZ.EXE
C:\Users\win7\AppData\Local\Temp\remove.exe
C:\Users\win7\AppData\Local\Temp\sed.exe
C:\Users\win7\AppData\Local\Temp\shortcut.exe
C:\Users\win7\AppData\Local\Temp\swreg.exe
C:\Users\win7\AppData\Local\Temp\swxcacls.exe
C:\Users\win7\AppData\Local\Temp\wget.exe
C:\Users\win7\AppData\Local\Temp\zoek-delete.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-05-30 18:46

==================== End Of Log ============================
[Link mogu videti samo ulogovani korisnici]

Dopuna: 04 Jun 2014 0:56

E da zaboravio sam da ti napomenem od kad sam počeo da radim ovo što mi pričaš počelo je s vremena na vreme da se ponaša normalno ali opet se vrati posle nekog vremena

offline
  • Pridružio: 09 Avg 2011
  • Poruke: 15879
  • Gde živiš: Beograd

1. Otvori Notepad (Text Document) i iskopiraj sledeći tekst unutar kod polja ispod:

GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
SearchScopes: HKCU - DefaultScope {1A60F180-496E-4E03-98B3-110464D79941} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3282698&CUI=UN21704424982530139&UM=2
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://isearch.babylon.com/?q={searchTerms}&babsrc=SP_ss_Btisdt4&mntrId=321174DE2B10034A&affID=119776&tsp=5004
SearchScopes: HKCU - {185B5932-4EC3-4492-B9F2-C0A8ACC60760} URL = http://www.mysearchresults.com/search?c=2408&t=14&q={searchTerms}
SearchScopes: HKCU - {1A60F180-496E-4E03-98B3-110464D79941} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3282698&CUI=UN21704424982530139&UM=2
SearchScopes: HKCU - {CDA45BC0-98B6-4367-8E38-5AA3B6AAE1A5} URL = http://search.softonic.com/INF00176/tb_v1?q={searchTerms}&SearchSource=4&cc=&mi=321197d700000000000074de2b10034a&r=754
SearchScopes: HKCU - {DE9F5114-D6D7-4DB1-8B46-29D8D5E656E9} URL = http://search.yahoo.com/search?fr=chr-greentree_ie.....=407453&p={searchTerms}
FF SearchPlugin: C:\Users\win7\AppData\Roaming\Mozilla\Firefox\Profiles\4hcbmhpf.default\searchplugins\bs-player-controlbar-customized-web-search.xml
FF SearchPlugin: C:\Users\win7\AppData\Roaming\Mozilla\Firefox\Profiles\4hcbmhpf.default\searchplugins\softonic.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\sweettunes_search.xml
FF Extension: SweetTunes1 - C:\Users\win7\AppData\Roaming\Mozilla\Firefox\Profiles\4hcbmhpf.default\Extensions\{f9d1c08c-2031-4e6c-ab51-50330ac2d988} [2014-06-03]
FF Extension: BS Player ControlBar - C:\Users\win7\AppData\Roaming\Mozilla\Firefox\Profiles\4hcbmhpf.default\Extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} [2014-06-02]
FF Extension: FT Downloader - C:\Users\win7\AppData\Roaming\Mozilla\Firefox\Profiles\4hcbmhpf.default\Extensions\ftd@ftd.com.xpi [2013-06-26]
FF Extension: SecretSauce - C:\Users\win7\AppData\Roaming\Mozilla\Firefox\Profiles\4hcbmhpf.default\Extensions\{345422e3-72fa-447a-9550-97803edfacf3}.xpi [2014-02-04]
FF HKLM-x32\...\Firefox\Extensions: [xz123@ya456.com] - C:\Program Files (x86)\BetterSurf\ff
FF Extension: No Name - C:\Program Files (x86)\BetterSurf\ff [2013-11-14]
FF HKLM-x32\...\Firefox\Extensions: [12x3q@3244516.com] - C:\Program Files (x86)\Better-Surf\ff
FF Extension: No Name - C:\Program Files (x86)\Better-Surf\ff [2013-11-26]
FF HKLM-x32\...\Firefox\Extensions: [ext@bettersurfplus.com] - C:\Program Files (x86)\BetterSurf\BetterSurfPlus\ff
FF Extension: No Name - C:\Program Files (x86)\BetterSurf\BetterSurfPlus\ff [2013-12-10]
FF HKLM-x32\...\Firefox\Extensions: [ext@WebexpEnhancedV1alpha800.net] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha800\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@VideoPlayerV3beta220.net] - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta220\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaPlayerV1alpha293.net] - C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha293\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaViewerV1alpha1806.net] - C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha1806\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaViewV1alpha1507.net] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1507\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaWatchV1home218.net] - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home218\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaBuzzV1mode4065.net] - C:\Program Files (x86)\MediaBuzzV1\MediaBuzzV1mode4065\ff
C:\Program Files (x86)\BetterSurf
C:\Program Files (x86)\MediaBuzzV1
C:\Program Files (x86)\WebexpEnhancedV1
CHR HKCU\...\Chrome\Extension: [cflheckfmhopnialghigdlggahiomebp] - C:\Users\win7\AppData\Local\CRE\cflheckfmhopnialghigdlggahiomebp.crx [2013-08-07]
CHR HKCU\...\Chrome\Extension: [giolhomkcooifelkdfpejhidfidaahlc] - C:\Users\win7\AppData\Local\CRE\giolhomkcooifelkdfpejhidfidaahlc.crx [2013-10-03]
CHR HKLM-x32\...\Chrome\Extension: [cflheckfmhopnialghigdlggahiomebp] - C:\Users\win7\AppData\Local\CRE\cflheckfmhopnialghigdlggahiomebp.crx [2013-10-03]
CHR HKLM-x32\...\Chrome\Extension: [dbpebffoameokfhnaaedmefjncfboino] - C:\Program Files (x86)\SecretSauce\dbpebffoameokfhnaaedmefjncfboino.crx [2013-10-03]
CHR HKLM-x32\...\Chrome\Extension: [dedmngkbaffkenlfdcbganndoghblmap] - C:\Program Files (x86)\BetterSurf\ch\Chrome.crx [2013-10-03]
CHR HKLM-x32\...\Chrome\Extension: [deihhdcgleffbeklojkembpgmenfjgbi] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1507\ch\MediaViewV1alpha1507.crx [2013-10-03]
CHR HKLM-x32\...\Chrome\Extension: [fokohpfmgfedjpcfmflailjgoekaldka] - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta220\ch\VideoPlayerV3beta220.crx [2013-10-03]
CHR HKLM-x32\...\Chrome\Extension: [giolhomkcooifelkdfpejhidfidaahlc] - C:\Users\win7\AppData\Local\CRE\giolhomkcooifelkdfpejhidfidaahlc.crx [2013-10-03]
CHR HKLM-x32\...\Chrome\Extension: [inldfkehmpgiankjeocgjbieccdcjncp] - C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha1806\ch\MediaViewerV1alpha1806.crx [2014-05-22]
CHR HKLM-x32\...\Chrome\Extension: [mjljkmhdlcmkkkjkefeeoaphpikpdodd] - C:\Program Files (x86)\MediaBuzzV1\MediaBuzzV1mode4065\ch\MediaBuzzV1mode4065.crx [2014-05-22]
CHR HKLM-x32\...\Chrome\Extension: [mmifolfpllfdhilecpdpmemhelmanajl] - C:\Program Files (x86)\BetterSurf\BetterSurfPlus\ch\BetterSurfPlus.crx [2014-05-22]
CHR HKLM-x32\...\Chrome\Extension: [ofddoohgffcmgnajhoblocignnnjnbma] - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home218\ch\MediaWatchV1home218.crx [2014-04-27]
CHR HKLM-x32\...\Chrome\Extension: [ogfaegbpanaecpfjidcbhhnlpgoaookh] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha800\ch\WebexpEnhancedV1alpha800.crx [2014-04-27]
CHR HKLM-x32\...\Chrome\Extension: [poheodfamflhhhdcmjfeggbgigeefaco] - C:\Program Files (x86)\Better-Surf\ch\Chrome.crx [2014-04-27]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
C:\Users\win7\AppData\Local\Temp\7za.exe
C:\Users\win7\AppData\Local\Temp\hijackthis.exe
C:\Users\win7\AppData\Local\Temp\NirCmd.exe
C:\Users\win7\AppData\Local\Temp\PEVZ.EXE
C:\Users\win7\AppData\Local\Temp\remove.exe
C:\Users\win7\AppData\Local\Temp\sed.exe
C:\Users\win7\AppData\Local\Temp\shortcut.exe
C:\Users\win7\AppData\Local\Temp\swreg.exe
C:\Users\win7\AppData\Local\Temp\swxcacls.exe
C:\Users\win7\AppData\Local\Temp\wget.exe
C:\Users\win7\AppData\Local\Temp\zoek-delete.exe
Task: {9CFD84C4-D727-4DDB-BB85-27DA3B844F95} - System32\Tasks\DTReg => C:\Users\win7\AppData\Roaming\DefaultTab\DefaultTab\DTReg.exe <==== ATTENTION
C:\Users\win7\AppData\Roaming\DefaultTab
cmd: ipconfig /flushdns
Reboot:


2. Sačuvaj notepad na Desktop pod nazivom fixlist.txt
To možes uraditi i iz notepad-a => klik na File potom na Save As i u novom prozoru, dole pod File Name: staviš za naziv fixlist.txt
Napomena: Važno je da se oba fajla, FRST i fixlist nalaze na istoj lokaciji jer u suprotnom fix nece raditi.

3. Ponovo pokreni FRST/FRST64, klikni jednom na dugme Fix i sačekaj.
Ukoliko alat zatraži restart sistema, dozvoli mu i postaraj se da alat kompletira fix nakon restarta sistema.



Alat će formirati log (Fixlog.txt) na Desktop-u. Potrebno je sadržaj tog loga iskopirati u poruku.
Napomena: Ukoliko te alat upozori da postoji novija verzija, postaraj se da preuzmes i koristiš ažuriranu kopiju FRST-a.




Nakon ovoga bi voleo da pokrenes Zoek, ali pre toga iskljuci Avast, jer je poznato da ga blokira.

offline
  • Pridružio: 01 Jun 2014
  • Poruke: 23

Napisano: 04 Jun 2014 21:32

Druže evo ti ovo a sad ću da probam zoek

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 02-06-2014
Ran by win7 at 2014-06-04 21:26:51 Run:1
Running from C:\Users\win7\Downloads
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
SearchScopes: HKCU - DefaultScope {1A60F180-496E-4E03-98B3-110464D79941} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}&SearchSource=4&ctid=CT3282698&CUI=UN21704424982530139&UM=2
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}&babsrc=SP_ss_Btisdt4&mntrId=321174DE2B10034A&affID=119776&tsp=5004
SearchScopes: HKCU - {185B5932-4EC3-4492-B9F2-C0A8ACC60760} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}
SearchScopes: HKCU - {1A60F180-496E-4E03-98B3-110464D79941} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}&SearchSource=4&ctid=CT3282698&CUI=UN21704424982530139&UM=2
SearchScopes: HKCU - {CDA45BC0-98B6-4367-8E38-5AA3B6AAE1A5} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}&SearchSource=4&cc=&mi=321197d700000000000074de2b10034a&r=754
SearchScopes: HKCU - {DE9F5114-D6D7-4DB1-8B46-29D8D5E656E9} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}
FF SearchPlugin: C:\Users\win7\AppData\Roaming\Mozilla\Firefox\Profiles\4hcbmhpf.default\searchplugins\bs-player-controlbar-customized-web-search.xml
FF SearchPlugin: C:\Users\win7\AppData\Roaming\Mozilla\Firefox\Profiles\4hcbmhpf.default\searchplugins\softonic.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\sweettunes_search.xml
FF Extension: SweetTunes1 - C:\Users\win7\AppData\Roaming\Mozilla\Firefox\Profiles\4hcbmhpf.default\Extensions\{f9d1c08c-2031-4e6c-ab51-50330ac2d988} [2014-06-03]
FF Extension: BS Player ControlBar - C:\Users\win7\AppData\Roaming\Mozilla\Firefox\Profiles\4hcbmhpf.default\Extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} [2014-06-02]
FF Extension: FT Downloader - C:\Users\win7\AppData\Roaming\Mozilla\Firefox\Profiles\4hcbmhpf.default\Extensions\ftd@ftd.com.xpi [2013-06-26]
FF Extension: SecretSauce - C:\Users\win7\AppData\Roaming\Mozilla\Firefox\Profiles\4hcbmhpf.default\Extensions\{345422e3-72fa-447a-9550-97803edfacf3}.xpi [2014-02-04]
FF HKLM-x32\...\Firefox\Extensions: [xz123@ya456.com] - C:\Program Files (x86)\BetterSurf\ff
FF Extension: No Name - C:\Program Files (x86)\BetterSurf\ff [2013-11-14]
FF HKLM-x32\...\Firefox\Extensions: [12x3q@3244516.com] - C:\Program Files (x86)\Better-Surf\ff
FF Extension: No Name - C:\Program Files (x86)\Better-Surf\ff [2013-11-26]
FF HKLM-x32\...\Firefox\Extensions: [ext@bettersurfplus.com] - C:\Program Files (x86)\BetterSurf\BetterSurfPlus\ff
FF Extension: No Name - C:\Program Files (x86)\BetterSurf\BetterSurfPlus\ff [2013-12-10]
FF HKLM-x32\...\Firefox\Extensions: [ext@WebexpEnhancedV1alpha800.net] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha800\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@VideoPlayerV3beta220.net] - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta220\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaPlayerV1alpha293.net] - C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha293\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaViewerV1alpha1806.net] - C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha1806\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaViewV1alpha1507.net] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1507\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaWatchV1home218.net] - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home218\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaBuzzV1mode4065.net] - C:\Program Files (x86)\MediaBuzzV1\MediaBuzzV1mode4065\ff
C:\Program Files (x86)\BetterSurf
C:\Program Files (x86)\MediaBuzzV1
C:\Program Files (x86)\WebexpEnhancedV1
CHR HKCU\...\Chrome\Extension: [cflheckfmhopnialghigdlggahiomebp] - C:\Users\win7\AppData\Local\CRE\cflheckfmhopnialghigdlggahiomebp.crx [2013-08-07]
CHR HKCU\...\Chrome\Extension: [giolhomkcooifelkdfpejhidfidaahlc] - C:\Users\win7\AppData\Local\CRE\giolhomkcooifelkdfpejhidfidaahlc.crx [2013-10-03]
CHR HKLM-x32\...\Chrome\Extension: [cflheckfmhopnialghigdlggahiomebp] - C:\Users\win7\AppData\Local\CRE\cflheckfmhopnialghigdlggahiomebp.crx [2013-10-03]
CHR HKLM-x32\...\Chrome\Extension: [dbpebffoameokfhnaaedmefjncfboino] - C:\Program Files (x86)\SecretSauce\dbpebffoameokfhnaaedmefjncfboino.crx [2013-10-03]
CHR HKLM-x32\...\Chrome\Extension: [dedmngkbaffkenlfdcbganndoghblmap] - C:\Program Files (x86)\BetterSurf\ch\Chrome.crx [2013-10-03]
CHR HKLM-x32\...\Chrome\Extension: [deihhdcgleffbeklojkembpgmenfjgbi] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1507\ch\MediaViewV1alpha1507.crx [2013-10-03]
CHR HKLM-x32\...\Chrome\Extension: [fokohpfmgfedjpcfmflailjgoekaldka] - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta220\ch\VideoPlayerV3beta220.crx [2013-10-03]
CHR HKLM-x32\...\Chrome\Extension: [giolhomkcooifelkdfpejhidfidaahlc] - C:\Users\win7\AppData\Local\CRE\giolhomkcooifelkdfpejhidfidaahlc.crx [2013-10-03]
CHR HKLM-x32\...\Chrome\Extension: [inldfkehmpgiankjeocgjbieccdcjncp] - C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha1806\ch\MediaViewerV1alpha1806.crx [2014-05-22]
CHR HKLM-x32\...\Chrome\Extension: [mjljkmhdlcmkkkjkefeeoaphpikpdodd] - C:\Program Files (x86)\MediaBuzzV1\MediaBuzzV1mode4065\ch\MediaBuzzV1mode4065.crx [2014-05-22]
CHR HKLM-x32\...\Chrome\Extension: [mmifolfpllfdhilecpdpmemhelmanajl] - C:\Program Files (x86)\BetterSurf\BetterSurfPlus\ch\BetterSurfPlus.crx [2014-05-22]
CHR HKLM-x32\...\Chrome\Extension: [ofddoohgffcmgnajhoblocignnnjnbma] - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home218\ch\MediaWatchV1home218.crx [2014-04-27]
CHR HKLM-x32\...\Chrome\Extension: [ogfaegbpanaecpfjidcbhhnlpgoaookh] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha800\ch\WebexpEnhancedV1alpha800.crx [2014-04-27]
CHR HKLM-x32\...\Chrome\Extension: [poheodfamflhhhdcmjfeggbgigeefaco] - C:\Program Files (x86)\Better-Surf\ch\Chrome.crx [2014-04-27]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
C:\Users\win7\AppData\Local\Temp\7za.exe
C:\Users\win7\AppData\Local\Temp\hijackthis.exe
C:\Users\win7\AppData\Local\Temp\NirCmd.exe
C:\Users\win7\AppData\Local\Temp\PEVZ.EXE
C:\Users\win7\AppData\Local\Temp\remove.exe
C:\Users\win7\AppData\Local\Temp\sed.exe
C:\Users\win7\AppData\Local\Temp\shortcut.exe
C:\Users\win7\AppData\Local\Temp\swreg.exe
C:\Users\win7\AppData\Local\Temp\swxcacls.exe
C:\Users\win7\AppData\Local\Temp\wget.exe
C:\Users\win7\AppData\Local\Temp\zoek-delete.exe
Task: {9CFD84C4-D727-4DDB-BB85-27DA3B844F95} - System32\Tasks\DTReg => C:\Users\win7\AppData\Roaming\DefaultTab\DefaultTab\DTReg.exe <==== ATTENTION
C:\Users\win7\AppData\Roaming\DefaultTab
cmd: ipconfig /flushdns
Reboot:
*****************

C:\Windows\system32\GroupPolicy\Machine => Moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully.
HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{185B5932-4EC3-4492-B9F2-C0A8ACC60760} => Key deleted successfully.
HKCR\CLSID\{185B5932-4EC3-4492-B9F2-C0A8ACC60760} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1A60F180-496E-4E03-98B3-110464D79941} => Key deleted successfully.
HKCR\CLSID\{1A60F180-496E-4E03-98B3-110464D79941} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CDA45BC0-98B6-4367-8E38-5AA3B6AAE1A5} => Key deleted successfully.
HKCR\CLSID\{CDA45BC0-98B6-4367-8E38-5AA3B6AAE1A5} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{DE9F5114-D6D7-4DB1-8B46-29D8D5E656E9} => Key deleted successfully.
HKCR\CLSID\{DE9F5114-D6D7-4DB1-8B46-29D8D5E656E9} => Key not found.
C:\Users\win7\AppData\Roaming\Mozilla\Firefox\Profiles\4hcbmhpf.default\searchplugins\bs-player-controlbar-customized-web-search.xml => Moved successfully.
C:\Users\win7\AppData\Roaming\Mozilla\Firefox\Profiles\4hcbmhpf.default\searchplugins\softonic.xml => Moved successfully.
C:\Program Files (x86)\mozilla firefox\browser\searchplugins\sweettunes_search.xml => Moved successfully.
C:\Users\win7\AppData\Roaming\Mozilla\Firefox\Profiles\4hcbmhpf.default\Extensions\{f9d1c08c-2031-4e6c-ab51-50330ac2d988} => Moved successfully.
C:\Users\win7\AppData\Roaming\Mozilla\Firefox\Profiles\4hcbmhpf.default\Extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} => Moved successfully.
C:\Users\win7\AppData\Roaming\Mozilla\Firefox\Profiles\4hcbmhpf.default\Extensions\ftd@ftd.com.xpi => Moved successfully.
C:\Users\win7\AppData\Roaming\Mozilla\Firefox\Profiles\4hcbmhpf.default\Extensions\{345422e3-72fa-447a-9550-97803edfacf3}.xpi => Moved successfully.
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\xz123@ya456.com => Value deleted successfully.
C:\Program Files (x86)\BetterSurf\ff => Moved successfully.
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\12x3q@3244516.com => Value deleted successfully.
C:\Program Files (x86)\Better-Surf\ff => Moved successfully.
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\ext@bettersurfplus.com => Value deleted successfully.
C:\Program Files (x86)\BetterSurf\BetterSurfPlus\ff => Moved successfully.
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\ext@WebexpEnhancedV1alpha800.net => Value deleted successfully.
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\ext@VideoPlayerV3beta220.net => Value deleted successfully.
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\ext@MediaPlayerV1alpha293.net => Value deleted successfully.
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\ext@MediaViewerV1alpha1806.net => Value deleted successfully.
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\ext@MediaViewV1alpha1507.net => Value deleted successfully.
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\ext@MediaWatchV1home218.net => Value deleted successfully.
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\ext@MediaBuzzV1mode4065.net => Value deleted successfully.
C:\Program Files (x86)\BetterSurf => Moved successfully.
"C:\Program Files (x86)\MediaBuzzV1" => File/Directory not found.
"C:\Program Files (x86)\WebexpEnhancedV1" => File/Directory not found.
HKCU\SOFTWARE\Google\Chrome\Extensions\cflheckfmhopnialghigdlggahiomebp => Key deleted successfully.
"C:\Users\win7\AppData\Local\CRE\cflheckfmhopnialghigdlggahiomebp.crx" => File/Directory not found.
HKCU\SOFTWARE\Google\Chrome\Extensions\giolhomkcooifelkdfpejhidfidaahlc => Key deleted successfully.
C:\Users\win7\AppData\Local\CRE\giolhomkcooifelkdfpejhidfidaahlc.crx => Moved successfully.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\cflheckfmhopnialghigdlggahiomebp => Key deleted successfully.
"C:\Users\win7\AppData\Local\CRE\cflheckfmhopnialghigdlggahiomebp.crx" => File/Directory not found.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\dbpebffoameokfhnaaedmefjncfboino => Key deleted successfully.
"C:\Program Files (x86)\SecretSauce\dbpebffoameokfhnaaedmefjncfboino.crx" => File/Directory not found.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\dedmngkbaffkenlfdcbganndoghblmap => Key deleted successfully.
"C:\Program Files (x86)\BetterSurf\ch\Chrome.crx" => File/Directory not found.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\deihhdcgleffbeklojkembpgmenfjgbi => Key deleted successfully.
"C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1507\ch\MediaViewV1alpha1507.crx" => File/Directory not found.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fokohpfmgfedjpcfmflailjgoekaldka => Key deleted successfully.
"C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta220\ch\VideoPlayerV3beta220.crx" => File/Directory not found.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\giolhomkcooifelkdfpejhidfidaahlc => Key deleted successfully.
"C:\Users\win7\AppData\Local\CRE\giolhomkcooifelkdfpejhidfidaahlc.crx" => File/Directory not found.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\inldfkehmpgiankjeocgjbieccdcjncp => Key deleted successfully.
"C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha1806\ch\MediaViewerV1alpha1806.crx" => File/Directory not found.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\mjljkmhdlcmkkkjkefeeoaphpikpdodd => Key deleted successfully.
"C:\Program Files (x86)\MediaBuzzV1\MediaBuzzV1mode4065\ch\MediaBuzzV1mode4065.crx" => File/Directory not found.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\mmifolfpllfdhilecpdpmemhelmanajl => Key deleted successfully.
"C:\Program Files (x86)\BetterSurf\BetterSurfPlus\ch\BetterSurfPlus.crx" => File/Directory not found.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ofddoohgffcmgnajhoblocignnnjnbma => Key deleted successfully.
"C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home218\ch\MediaWatchV1home218.crx" => File/Directory not found.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ogfaegbpanaecpfjidcbhhnlpgoaookh => Key deleted successfully.
"C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha800\ch\WebexpEnhancedV1alpha800.crx" => File/Directory not found.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\poheodfamflhhhdcmjfeggbgigeefaco => Key deleted successfully.
"C:\Program Files (x86)\Better-Surf\ch\Chrome.crx" => File/Directory not found.
HKLM\SOFTWARE\Policies\Google => Key deleted successfully.
C:\Users\win7\AppData\Local\Temp\7za.exe => Moved successfully.
C:\Users\win7\AppData\Local\Temp\hijackthis.exe => Moved successfully.
C:\Users\win7\AppData\Local\Temp\NirCmd.exe => Moved successfully.
C:\Users\win7\AppData\Local\Temp\PEVZ.EXE => Moved successfully.
C:\Users\win7\AppData\Local\Temp\remove.exe => Moved successfully.
C:\Users\win7\AppData\Local\Temp\sed.exe => Moved successfully.
C:\Users\win7\AppData\Local\Temp\shortcut.exe => Moved successfully.
C:\Users\win7\AppData\Local\Temp\swreg.exe => Moved successfully.
C:\Users\win7\AppData\Local\Temp\swxcacls.exe => Moved successfully.
C:\Users\win7\AppData\Local\Temp\wget.exe => Moved successfully.
C:\Users\win7\AppData\Local\Temp\zoek-delete.exe => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9CFD84C4-D727-4DDB-BB85-27DA3B844F95} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9CFD84C4-D727-4DDB-BB85-27DA3B844F95} => Key deleted successfully.
C:\Windows\System32\Tasks\DTReg => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DTReg => Key deleted successfully.
"C:\Users\win7\AppData\Roaming\DefaultTab" => File/Directory not found.

========= ipconfig /flushdns =========


Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========



The system needed a reboot.

==== End of Fixlog ====

Dopuna: 04 Jun 2014 21:43

Neće zoek opet restartuje, nego sad mi palo na pamet ja uglavnom izbrišem zoek kad neće pa ga posle opet skidam možda zato neće prvo sam uradio fix pa sam tek onda skinuo zoek opet, a mislim da se ovo moje sredilo više ne pravi probleme barem nije danas tako da hvala puno Very Happy možda ipak i ne treba zoek Very Happy mada ja čekam da ti kažeš da je gotovo Very Happy

offline
  • Pridružio: 09 Avg 2011
  • Poruke: 15879
  • Gde živiš: Beograd

OK, zaboravicemo Zoek, probacemo alternativu

Preuzmi "Xplode"-ov AdwCleaner () i sacuvaj ga na Desktop

Dvoklikom pokreni program.
Klikni na dugme [Scan] i pricekaj da program zavrsi.
Klikni na dugme [Clean]
Program ce zatvoriti sve aktivne programe i izbaciti prozor sa tim upozorenjem. Klikni Ok kao potvrdu.
Na sledeca dva prozora koja se otvore (Informations i Restart required ) klikni Ok


Racunar ce se restartovati a potom otvoriti notepad (C:\AdwCleaner[S1].txt) sa izvestajem.
Sacuvaj taj notepad na Desktop i okaci ga uz poruku koristeci opciju "Prikaci fajl"

Napomena: Izvestaj ce takodje biti sacuvan na C:\AdwCleaner[S1].txt

offline
  • Pridružio: 01 Jun 2014
  • Poruke: 23

Izvoli druže Very Happy
[Link mogu videti samo ulogovani korisnici]

offline
  • Pridružio: 09 Avg 2011
  • Poruke: 15879
  • Gde živiš: Beograd

Odlicno, kazi mi kakva je sada sveobuhvatna situacija?

offline
  • Pridružio: 01 Jun 2014
  • Poruke: 23

Radi sve super, druže ti si car Very Happy

offline
  • Pridružio: 09 Avg 2011
  • Poruke: 15879
  • Gde živiš: Beograd

Odlicno, onda da privedemo kraju Smile

Druze, sistem ti je bio u katastrofalnom stanju, znaci toliku kolicinu Adware-a nisam do sada video iako ovo radim par godina. Nikad mi se nije desilo da ovoliko alata nece da radi. Da li deca koriste taj racunar ili ko vec, ali je zalosno cega tu sve nije bilo. Ne znam ni kako je uopste radio. Preporucicu ti par aplikacija i tema da procitas da se ovo vise ne bi desavalo, jer zaista treba da pazis odakle skidas aplikacije i kako ih instaliras.

Znaci ove dve aplikacije pod obavezno da se instaliraju:

Adblock za Google Chrome (ako koristis mozillu, pronadji isto se zove ekstenzija) --> [Link mogu videti samo ulogovani korisnici]

Unchecky --> [Link mogu videti samo ulogovani korisnici]



Arrow Obavezno poseti temu "Testirajte da li vam je pretraživač ranjiv", pročitaj i isprati link koji stoji u njoj.
Link do teme je: [Link mogu videti samo ulogovani korisnici]



Arrow Takode, isprati i temu "Kako izbeci i ukloniti toolbar-ove" , procitaj i isprati korake u njoj. Link do teme je: [Link mogu videti samo ulogovani korisnici]



Preuzmi "Xplode"-ov DelFix i sačuvaj ga na Desktop

Dvoklikom pokreni program.

Štikliraj sledeće opcije:
Remove disinfection tools
Purge System Restore
Reset system settings


Klikni na dugme "Run" i pričekaj da program završi rad.
Alat ce ukloniti sve koriscene alate u ovoj temi...
Kada alat završi, otvoriće izvestaj u notepadu.
Napomena: Izvestaj ce takodje biti sacuvan na C:\DelFix.txt

Nije potrebno dostavljati izvestaj.




TwinHeadedEagle (AMF Tim)

Ko je trenutno na forumu
 

Ukupno su 985 korisnika na forumu :: 160 registrovanih, 16 sakrivenih i 809 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 15694 - dana 01 Feb 2026 12:23

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 4. Ozrenska, 9k38, _Sale, _stipa_, airliners, akrep, alex71, ambra, AMX72, asdfjklc, Asteker, babaroga, baltazar01, Bbbggg1979, bobpp, bojank, BORUTUS, Bosnjo, braca57, ceman, Cicumile, cifra, cinoeye, comi, Crazzer, crnitrn, cyprus, DejanCG, dekan.m, Deki Duga Devetka, deki1001, Despot Đurađ, Dimitrije Paunovic, Dioniss, djordjemiklusev, Doc, dragan_mig31, draganca, Draganeli, dskrlec33, dukikan, dule10savic, dulleo, dusan2022, dushan, Electron, eulereix, foksmolder, gale48, GeoM, Giskard, Gitzherai, GUARIN, herrDule, HrcAk47, hyla, Ivanmateja, Jan, jodzula, Kazablankasrb, Kenanjoz, KimiMR, king111, KizJ, Kobrim, kolle.the.kid, Konda, kovacicbozo, krasta, Krusarac, Le Banner, ljubsz, lucko1, majstro, Manjane, markolopin, mercedesamg, Mihajlo, mikelija, miki kv, MIKI63, mikrimaus, milenko crazy north, Mili026, milivoje_vatrogasac, Milos ZA, MilosM, MiroslavD, Mićko, moldway, mrgud2025, Ndsk, nebidrag, nekdo, nelezele, Nemanja94, nenad81, nerislav2025, nevjerna beba, Niki2024, nikola11, nikolapetkovic, nizam, nobutado, Ognjen D., operniki, Paklenica, Papadubi, pein, Pekman, peraklio, Plavi Jadran, Povratak1912, Prečanin30, procesor, proljece, Prometeus, Pv123, q9q8q7q6, royst33, Samo gledam, SamoGledam, saputnik plavetnila, Sarmat, Sass Drake, Sawages, semity, Semprini, Shinobi, SlaKoj, Smiljkovich, sosko, stalja, stegonosa, superwhy, tachinni, The_new_Statesman, TheDictator, Trimi68, Tumansky, uruk, US_Rank_0, Username1000, v0idmp3, Vanderx, vathra, Velibor Radoja, veljko82, vensla, vladao75, Vojkan Petrovic, xAlex2, YFSS33, yrraf, Zdenko, zemljanin, ZlatniRez, Zoca, Žoržo, 79693