Već hiljaditi put-jaaaako usporen komp

1

Već hiljaditi put-jaaaako usporen komp

offline
  • Pridružio: 30 Dec 2008
  • Poruke: 193

Otvorila sam ovu tenu u Windows-u ali sam dobila predlog da prvo otvorim ovde pa ako je sve ok da nastavim tamo.

Znači...komp mi toliko koči da je to već neizdrživo.Pre pola meseca je urađena reinstalacija Windowsa ali je problem ostao isti.Probala sam i da obrišem sve što je nepotrebno,jer klinci skidaju sve i svašta ali je i dalje kočio. Na netu treba cela večnost dok otvori stanicu.

Instaliran mi je Windows 7 Ultimate,64- bit
Intel(R) Celeron D CPU 3,20 GHz
Radeon x1650 Series
2,00 GB RAM
Avira Antivirus

Ako su potrebni još neki podaci recite pa ću postaviti.



DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.16518 BrowserJavaVersion: 10.51.2
Run by mirjana at 10:22:11 on 2014-02-22
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.381.1033.18.2047.437 [GMT 1:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\DCE\dce.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\SecretSauce\updateSecretSauce.exe
C:\Program Files (x86)\SecretSauce\bin\utilSecretSauce.exe
C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Logitech\SetPointP\SetPoint.exe
C:\Program Files\Retro PC Calculator\ntvmon32.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\mirjana\AppData\Local\Viber\Viber.exe
C:\Users\mirjana\AppData\Roaming\uTorrent\uTorrent.exe
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Retro PC Calculator\winmon.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\msiexec.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\DllHost.exe
C:\Users\mirjana\AppData\Local\Temp\~nsu.tmp\Au_.exe
C:\Program Files\Logitech\SetPointP\LogiAppBroker.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:Tabs
mWinlogon: Userinit = userinit.exe
BHO: SecretSauce: {0ffd0ef2-dbe9-483a-80c4-d2c331da1ce4} - C:\Program Files (x86)\SecretSauce\SecretSauceBHO.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: {A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} - <orphaned>
BHO: Logitech SetPoint: {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
uRun: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
uRun: [Guard] C:\Users\mirjana\AppData\Local\Guard\Guard.exe
uRun: [NextLive] C:\Windows\SysWOW64\rundll32.exe "C:\Users\mirjana\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
uRun: [Viber] "C:\Users\mirjana\AppData\Local\Viber\Viber.exe" StartMinimized
uRun: [uTorrent] "C:\Users\mirjana\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
uRun: [ChicaPasswordManager] "C:\Program Files (x86)\ChicaLogic\Chica Password Manager\stpass.exe" /autorunned
mRun: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
mRun: [Babakan] cmd.exe /k if %date:~6,4%%date:~3,2%%date:~0,2% LEQ 20131027 (exit) else (start dinoraptzor.org && exit)
mRun: [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [Avira Systray] C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-Windows\System: UseOEMBackground = dword:1
TCP: NameServer = 192.168.0.1
TCP: Interfaces\{A3B44135-6C19-4FA5-A676-AB2973A40685} : DHCPNameServer = 192.168.0.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: Logitech SetPoint: {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll
x64-Run: [RTHDVCPL] "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
x64-Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
x64-Run: [Windows NTV Host Monitor] C:\Program Files\Retro PC Calculator\ntvmon32.exe
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\mirjana\AppData\Roaming\Mozilla\Firefox\Profiles\upixml4e.default\
FF - prefs.js: browser.search.selectedEngine - Web Search
FF - prefs.js: browser.startup.homepage - hxxp://searchinfinitas.com/?affilt=4&id={22EB8586-C3D9-49D1-B940-7FBD249B6E56}
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: C:\Users\mirjana\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1207148.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll
.
============= SERVICES / DRIVERS ===============
.
R1 avkmgr;avkmgr;C:\Windows\System32\drivers\avkmgr.sys [2013-12-18 28600]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\System32\drivers\dtsoftbus01.sys [2013-12-18 283064]
R1 tnetfilter2;tnetfilter2;C:\Windows\System32\drivers\tnetfilter2.sys [2014-1-21 60096]
R2 AntiVirSchedulerService;Avira Scheduler;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2013-12-18 440400]
R2 AntiVirService;Avira Real-Time Protection;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2013-12-18 440400]
R2 avgntflt;avgntflt;C:\Windows\System32\drivers\avgntflt.sys [2013-12-18 108440]
R2 Avira.OE.ServiceHost;Avira Service Host;C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [2014-1-29 109112]
R2 DCE;Distributed Computing Experiment;C:\Program Files\DCE\dce.exe [2013-12-18 59392]
R2 UMVPFSrv;UMVPFSrv;C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2012-1-18 450848]
R2 Update SecretSauce;Update SecretSauce;C:\Program Files (x86)\SecretSauce\updateSecretSauce.exe [2014-1-17 111392]
R2 Util SecretSauce;Util SecretSauce;C:\Program Files (x86)\SecretSauce\bin\utilSecretSauce.exe [2014-1-20 111392]
R3 LVUVC64;Logitech HD Webcam C310(UVC);C:\Windows\System32\drivers\lvuvc64.sys [2012-1-18 4865568]
R3 RTL8023x64;Realtek 10/100 NIC Family NDIS x64 Driver;C:\Windows\System32\drivers\Rtnic64.sys [2013-3-14 52736]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2014-1-20 888536]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 asmthub3;ASMedia USB3 Hub Service;C:\Windows\System32\drivers\asmthub3.sys [2013-4-12 139592]
S3 asmtxhci;ASMEDIA XHCI Service;C:\Windows\System32\drivers\asmtxhci.sys [2013-4-12 418632]
S3 b06diag;Broadcom NetXtreme II Diag Driver;C:\Windows\System32\drivers\bxdiaga.sys [2013-3-14 88104]
S3 BFN7x64;Bigfoot Networks Killer Gaming Service;C:\Windows\System32\drivers\Xeno7x64.sys [2013-3-14 157288]
S3 bxfcoe;bxfcoe;C:\Windows\System32\drivers\bxfcoe.sys [2013-3-14 178216]
S3 bxois;bxois;C:\Windows\System32\drivers\bxois.sys [2013-3-14 539176]
S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2011-4-12 71168]
S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;C:\Windows\System32\drivers\EtronHub3.sys [2013-2-27 65152]
S3 EtronSTOR;Etron Enhance USB BOT/UASP Mass Storage Driver;C:\Windows\System32\drivers\EtronSTOR.sys [2013-2-27 32512]
S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;C:\Windows\System32\drivers\EtronXHCI.sys [2013-2-27 88832]
S3 HTCAND64;HTC Device Driver;C:\Windows\System32\drivers\ANDROIDUSB.sys [2009-11-2 33736]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2014-2-12 111616]
S3 ioatdma1;ioatdma1;C:\Windows\System32\drivers\qd162x64.sys [2013-3-14 40144]
S3 ioatdma2;Intel(R) QuickData Technology device ver.2;C:\Windows\System32\drivers\qd262x64.sys [2013-3-14 42192]
S3 iusb3hub;Intel(R) USB 3.0 Hub Driver;C:\Windows\System32\drivers\iusb3hub.sys [2013-4-12 366216]
S3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;C:\Windows\System32\drivers\iusb3xhc.sys [2013-4-12 786056]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2013-2-27 96768]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2013-2-27 213504]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-8-16 19456]
S3 Synth3dVsc;Synth3dVsc;C:\Windows\System32\drivers\Synth3dVsc.sys [2011-4-12 88960]
S3 terminpt;Microsoft Remote Desktop Input Driver;C:\Windows\System32\drivers\terminpt.sys [2013-8-16 29696]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-8-16 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2013-8-16 30208]
S3 tsusbhub;tsusbhub;C:\Windows\System32\drivers\tsusbhub.sys [2011-4-12 117248]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-8-16 1255736]
S4 AntiVirWebService;Avira Web Protection;C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [2013-12-18 1017424]
.
=============== Created Last 30 ================
.
2014-02-22 09:11:03 5 ----a-w- C:\Windows\SysWow64\lMMLDeleteUserData42107612FX.tmp
2014-02-22 09:10:21 -------- d-----w- C:\Windows\System32\appmgmt
2014-02-22 08:02:24 75888 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2C1AADF2-7BCE-4355-ABC0-04B1876AA4CA}\offreg.dll
2014-02-21 22:08:11 8199504 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2014-02-21 22:07:56 10536864 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2C1AADF2-7BCE-4355-ABC0-04B1876AA4CA}\mpengine.dll
2014-02-16 22:13:02 -------- d-----w- C:\Users\mirjana\AppData\Roaming\Anino Games
2014-02-12 22:37:09 548864 ----a-w- C:\Windows\System32\vbscript.dll
2014-02-12 22:37:09 454656 ----a-w- C:\Windows\SysWow64\vbscript.dll
2014-02-12 22:04:26 -------- d-----w- C:\Users\mirjana\AppData\Roaming\My The Lord of the Rings, The Rise of the Witch-king Files
2014-02-12 07:02:10 1882112 ----a-w- C:\Windows\System32\msxml3.dll
2014-02-12 07:02:07 1237504 ----a-w- C:\Windows\SysWow64\msxml3.dll
2014-02-12 07:02:04 2048 ----a-w- C:\Windows\SysWow64\msxml3r.dll
2014-02-12 07:02:02 2048 ----a-w- C:\Windows\System32\msxml3r.dll
2014-02-12 06:55:48 1987584 ----a-w- C:\Windows\SysWow64\d3d10warp.dll
2014-02-12 06:55:47 2565120 ----a-w- C:\Windows\System32\d3d10warp.dll
2014-02-12 06:55:45 3928064 ----a-w- C:\Windows\System32\d2d1.dll
2014-02-12 06:55:44 3419136 ----a-w- C:\Windows\SysWow64\d2d1.dll
2014-02-12 06:36:15 -------- d-----w- C:\ProgramData\Symantec
2014-02-12 06:35:27 -------- d-----w- C:\ProgramData\Norton
2014-02-12 06:35:20 -------- d-----w- C:\ProgramData\NortonInstaller
2014-02-12 06:35:20 -------- d-----w- C:\Program Files (x86)\NortonInstaller
2014-02-11 20:08:49 -------- d-----w- C:\Windows\SysWow64\Adobe
2014-02-10 12:33:46 -------- d-----w- C:\Users\mirjana\AppData\Roaming\Doublefine
2014-02-10 12:33:14 -------- d-----w- C:\ProgramData\RELOADED
2014-02-10 12:30:06 -------- d-----w- C:\Program Files (x86)\The Cave
2014-02-08 19:52:09 -------- d-----w- C:\Users\mirjana\AppData\Roaming\PeaceCraft4
2014-02-08 19:49:39 -------- d-----w- C:\Program Files (x86)\Cybertek
2014-02-08 19:18:22 -------- d-----w- C:\Users\mirjana\AppData\Roaming\vikingsaga2_realore_en
2014-02-08 19:18:22 -------- d-----w- C:\Users\mirjana\AppData\Local\vikingsaga2_realore_en
2014-02-06 21:19:09 -------- d-----w- C:\Users\mirjana\AppData\Roaming\OpenOffice
2014-02-06 21:11:52 -------- d-----w- C:\Program Files (x86)\OpenOffice 4
2014-02-05 15:11:32 -------- d-----w- C:\Program Files (x86)\JoWooD
2014-02-05 10:13:33 -------- d-----w- C:\Windows\SysWow64\IPM
2014-02-03 14:12:00 -------- d-----w- C:\ProgramData\GameHouse
2014-02-02 22:18:16 -------- d-----w- C:\Program Files\Retro PC Calculator
2014-01-31 23:13:15 -------- d-----w- C:\Users\mirjana\AppData\Roaming\Realore
2014-01-30 22:41:29 256896 ----a-w- C:\Windows\System32\PuranDefrag.dll
2014-01-28 21:49:57 -------- d-----w- C:\Users\mirjana\AppData\Roaming\Carambis
2014-01-26 23:20:57 -------- d-----w- C:\Program Files (x86)\MSXML 4.0
2014-01-25 22:42:39 -------- d-----w- C:\Users\mirjana\AppData\Roaming\ViberPC
2014-01-25 22:40:53 -------- d-----w- C:\Users\mirjana\AppData\Local\Viber
2014-01-25 20:22:53 -------- d-----w- C:\Users\mirjana\AppData\Roaming\HTC
2014-01-25 20:21:53 -------- d-----w- C:\Users\mirjana\AppData\Local\Apple Computer
2014-01-25 20:21:04 -------- d-----w- C:\ProgramData\HTC
2014-01-25 20:18:41 -------- d-----w- C:\Program Files (x86)\HTC
2014-01-25 20:17:06 -------- d-----w- C:\Users\mirjana\AppData\Local\Downloaded Installations
.
==================== Find3M ====================
.
2014-02-21 19:53:34 692616 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2014-02-21 19:53:33 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2014-02-06 11:30:46 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2014-02-06 11:30:12 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2014-02-06 11:07:39 66048 ----a-w- C:\Windows\System32\iesetup.dll
2014-02-06 11:06:47 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2014-02-06 10:49:03 139264 ----a-w- C:\Windows\System32\ieUnatt.exe
2014-02-06 10:48:45 111616 ----a-w- C:\Windows\System32\ieetwcollector.exe
2014-02-06 10:48:11 708608 ----a-w- C:\Windows\System32\jscript9diag.dll
2014-02-06 10:20:26 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2014-02-06 10:11:37 5768704 ----a-w- C:\Windows\System32\jscript9.dll
2014-02-06 10:01:36 61952 ----a-w- C:\Windows\SysWow64\iesetup.dll
2014-02-06 10:00:46 51200 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
2014-02-06 09:50:32 2041856 ----a-w- C:\Windows\System32\inetcpl.cpl
2014-02-06 09:47:22 112128 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2014-02-06 09:46:27 553472 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2014-02-06 09:25:36 4244480 ----a-w- C:\Windows\SysWow64\jscript9.dll
2014-02-06 09:24:52 2334208 ----a-w- C:\Windows\System32\wininet.dll
2014-02-06 09:09:30 1964032 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2014-02-06 08:41:35 1820160 ----a-w- C:\Windows\SysWow64\wininet.dll
2014-01-21 21:29:07 96168 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2014-01-20 21:10:01 18960 ----a-w- C:\Windows\System32\drivers\LNonPnP.sys
2014-01-17 08:16:09 60096 ----a-w- C:\Windows\System32\drivers\tnetfilter2.sys
2013-12-19 23:09:03 940032 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2013-12-19 23:09:03 194048 ----a-w- C:\Windows\SysWow64\elshyph.dll
2013-12-18 20:37:42 283064 ----a-w- C:\Windows\System32\drivers\dtsoftbus01.sys
2013-12-18 19:35:18 84720 ----a-w- C:\Windows\System32\drivers\avnetflt.sys
2013-12-18 17:20:33 0 ----a-w- C:\Windows\ativpsrm.bin
2013-12-18 05:13:56 270496 ------w- C:\Windows\System32\MpSigStub.exe
2013-12-09 10:37:19 28600 ----a-w- C:\Windows\System32\drivers\avkmgr.sys
2013-12-09 10:37:18 108440 ----a-w- C:\Windows\System32\drivers\avgntflt.sys
2013-12-04 02:27:33 485888 ----a-w- C:\Windows\System32\secproc_isv.dll
2013-12-04 02:27:33 123392 ----a-w- C:\Windows\System32\secproc_ssp_isv.dll
2013-12-04 02:27:33 123392 ----a-w- C:\Windows\System32\secproc_ssp.dll
2013-12-04 02:27:16 488448 ----a-w- C:\Windows\System32\secproc.dll
2013-12-04 02:26:32 528384 ----a-w- C:\Windows\System32\msdrm.dll
2013-12-04 02:16:51 658432 ----a-w- C:\Windows\System32\RMActivate_isv.exe
2013-12-04 02:16:51 626176 ----a-w- C:\Windows\System32\RMActivate.exe
2013-12-04 02:16:50 552960 ----a-w- C:\Windows\System32\RMActivate_ssp_isv.exe
2013-12-04 02:16:48 553984 ----a-w- C:\Windows\System32\RMActivate_ssp.exe
2013-12-04 02:03:20 87040 ----a-w- C:\Windows\SysWow64\secproc_ssp_isv.dll
2013-12-04 02:03:20 87040 ----a-w- C:\Windows\SysWow64\secproc_ssp.dll
2013-12-04 02:03:20 423936 ----a-w- C:\Windows\SysWow64\secproc_isv.dll
2013-12-04 02:03:08 428032 ----a-w- C:\Windows\SysWow64\secproc.dll
2013-12-04 02:02:06 390144 ----a-w- C:\Windows\SysWow64\msdrm.dll
2013-12-04 01:54:14 510976 ----a-w- C:\Windows\SysWow64\RMActivate_ssp.exe
2013-12-04 01:54:10 594944 ----a-w- C:\Windows\SysWow64\RMActivate_isv.exe
2013-12-04 01:54:09 572416 ----a-w- C:\Windows\SysWow64\RMActivate.exe
2013-12-04 01:54:06 508928 ----a-w- C:\Windows\SysWow64\RMActivate_ssp_isv.exe
2013-11-27 01:41:37 343040 ----a-w- C:\Windows\System32\drivers\usbhub.sys
2013-11-27 01:41:15 99840 ----a-w- C:\Windows\System32\drivers\usbccgp.sys
2013-11-27 01:41:11 53248 ----a-w- C:\Windows\System32\drivers\usbehci.sys
2013-11-27 01:41:11 325120 ----a-w- C:\Windows\System32\drivers\usbport.sys
2013-11-27 01:41:09 25600 ----a-w- C:\Windows\System32\drivers\usbohci.sys
2013-11-27 01:41:06 30720 ----a-w- C:\Windows\System32\drivers\usbuhci.sys
2013-11-27 01:41:03 7808 ----a-w- C:\Windows\System32\drivers\usbd.sys
2013-11-26 11:40:00 376768 ----a-w- C:\Windows\System32\drivers\netio.sys
2013-11-26 10:32:56 3156480 ----a-w- C:\Windows\System32\win32k.sys
2013-11-26 07:49:44 888536 ----a-w- C:\Windows\System32\drivers\Rt64win7.sys
2013-11-26 07:49:44 73800 ----a-w- C:\Windows\System32\RtNicProp64.dll
2013-11-26 07:49:44 107552 ----a-w- C:\Windows\System32\RTNUninst64.dll
.
============= FINISH: 10:23:31,15 ===============

mycity.rs/must-login.png

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Preuzmi "Xplode"-ov AdwCleaner () i sacuvaj ga na Desktop

Dvoklikom pokreni program.
Klikni na dugme [Scan] i pricekaj da program zavrsi.
Klikni na dugme [Clean]
Program ce zatvoriti sve aktivne programe i izbaciti prozor sa tim upozorenjem. Klikni Ok kao potvrdu.
Na sledeca dva prozora koja se otvore (Informations i Restart required ) klikni Ok


Racunar ce se restartovati a potom otvoriti notepad (C:\AdwCleaner[S1].txt) sa izvestajem.
Sacuvaj taj notepad na Desktop i okaci ga uz poruku koristeci opciju "Prikaci fajl"

Napomena: Izvestaj ce takodje biti sacuvan na C:\AdwCleaner[S0].txt




-- > Sledece





Preuzmi Farbar-ov Farbar Recovery Scan Tool () sa ove adrese na Desktop:
Postoji 32bit. i 64bit.-na verzija. Potrebno je preuzeti verziju koja je kompatibilna sa tvojim sistemom.
Ako nisi siguran koja verzija se odnosi na tvoj sistem, preuzmi ih obe i pokreni. Samo jedan od njih će raditi na tvom sistemu, to će biti prava verzija.


dvoklikom pokreni program, kada se alat pokrene klikni Yes na disclaimer prozor;
pričekati koji trenutak dok alat proverava postoji li novija verzija;
klikni na dugme Scan;
po završetku skeniranja, alat će formirati izveštaj (FRST.txt) u isti direktorijum gde je FRST alat sačuvan;
iskopiraj sadržaj FRST.txt izveštaja u poruku;
po prvom pokretanju, alat bi trebao formirati i dodatni izveštaj (Addition.txt);
okači Addition.txt izveštaj uz poruku koristeći opciju Prikači fajl

offline
  • Pridružio: 30 Dec 2008
  • Poruke: 193

mycity.rs/must-login.png

mycity.rs/must-login.png

mycity.rs/must-login.png

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

1. Otvori Notepad (Text Document) i iskopiraj sledeći tekst unutar kod polja ispod:
Start
HKLM-x32\...\Run: [Babakan] - cmd.exe /k if %date:~6,4%%date:~3,2%%date:~0,2% LEQ 20131027 (exit) else (start http://dinoraptzor.org && exit)
HKU\S-1-5-21-978401329-1287808303-2657405011-1000\...\MountPoints2: {20347225-67bf-11e3-88eb-001d92270e0a} - F:\Autorun.exe
SearchScopes: HKCU - {47AC132D-68ED-11E3-A7C6-001D92270E0A} URL = http://searchinfinitas.com/?affilt=4&q={searchTerms}&id={22EB8586-C3D9-49D1-B940-7FBD249B6E56}
BHO-x32: No Name - {A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} -  No File
FF Homepage: hxxp://searchinfinitas.com/?affilt=4&id={22EB8586-C3D9-49D1-B940-7FBD249B6E56}
FF Extension: SecretSauce - C:\Users\mirjana\AppData\Roaming\Mozilla\Firefox\Profiles\upixml4e.default\Extensions\{345422e3-72fa-447a-9550-97803edfacf3}.xpi [2014-02-03]
CHR Extension: (SecretSauce) - C:\Users\mirjana\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbpebffoameokfhnaaedmefjncfboino [2014-02-01]
C:\Users\mirjana\AppData\Local\Temp\AutoRun.exe
C:\Users\mirjana\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\mirjana\AppData\Local\Temp\avgnt.exe
C:\Users\mirjana\AppData\Local\Temp\bitool.dll
C:\Users\mirjana\AppData\Local\Temp\drm_dialogs.dll
C:\Users\mirjana\AppData\Local\Temp\EAInstall.dll
C:\Users\mirjana\AppData\Local\Temp\fftBAE3.tmp.exe
C:\Users\mirjana\AppData\Local\Temp\FLVPlayerSetup.exe
C:\Users\mirjana\AppData\Local\Temp\Game Setup File__2774_il4134.exe
C:\Users\mirjana\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\mirjana\AppData\Local\Temp\LEGOLOTR.exe
C:\Users\mirjana\AppData\Local\Temp\LMkRstPt.exe
C:\Users\mirjana\AppData\Local\Temp\MoviesToolbarSetup_Somoto.exe
C:\Users\mirjana\AppData\Local\Temp\Quarantine.exe
C:\Users\mirjana\AppData\Local\Temp\ShopperProFull.exe
C:\Users\mirjana\AppData\Local\Temp\sysplayer_bu20_setup.exe
C:\Users\mirjana\AppData\Local\Temp\tu17p84.exe
C:\Users\mirjana\AppData\Local\Temp\UpdateCheckerSetup.exe
C:\Users\mirjana\AppData\Local\Temp\utt7DDD.tmp.exe
C:\Users\Nikola\AppData\Local\Temp\avgnt.exe
SecretSauce (HKLM\...\SecretSauce Version: 2014.01.17.055843 - SecretSauce) <==== ATTENTION
Unity Web Player (HKCU\...\UnityWebPlayer Version:  - Unity Technologies ApS) <==== ATTENTION
Task: {0242F9DC-5D33-42F1-B3BB-03BD40AD805C} - \iWebar-chromeinstaller No Task File
Task: {231A70A5-5FE3-4734-AF8A-191B7932304D} - \iWebar-updater No Task File
Task: {3529096B-5BCA-4BEC-BD4F-B54C9CD5AA95} - \RegClean Pro_DEFAULT No Task File
Task: {3D623D2E-2796-4EA3-8A60-B592407BCAE5} - \iWebar-enabler No Task File
Task: {A51F42B0-0568-4590-83AE-F80B5229754F} - \iWebar-firefoxinstaller No Task File
Task: {A7E570CA-385C-467D-9DC8-539F8FC2231F} - \RegClean Pro_UPDATES No Task File
Task: {D8707FF7-A723-48A7-B598-277BD3AA43D3} - \RegClean Pro No Task File
Task: {DE5911C8-5E16-4492-9C27-52C87F7967CC} - \iWebar-codedownloader No Task File
Task: {ECB4488D-A0BD-499E-9AB9-6A92544F297B} - \BackgroundContainer Startup Task No Task File
End


2. Sačuvaj notepad na Desktop pod nazivom fixlist.txt
To možes uraditi i iz notepad-a => klik na File potom na Save As i u novom prozoru, dole pod File Name: staviš za naziv fixlist.txt
Napomena: Važno je da se oba fajla, FRST i fixlist nalaze na istoj lokaciji jer u suprotnom fix nece raditi.

3. Ponovo pokreni FRST/FRST64, klikni jednom na dugme Fix i sačekaj.
Ukoliko alat zatraži restart sistema, dozvoli mu i postaraj se da alat kompletira fix nakon restarta sistema.



Alat će formirati log (Fixlog.txt) na Desktop-u. Potrebno je sadržaj tog loga iskopirati u poruku.
Napomena: Ukoliko te alat upozori da postoji novija verzija, postaraj se da preuzmes i koristiš ažuriranu kopiju FRST-a.

offline
  • Pridružio: 30 Dec 2008
  • Poruke: 193

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 22-02-2014
Ran by mirjana at 2014-02-22 13:04:48 Run:1
Running from C:\Users\mirjana\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
HKLM-x32\...\Run: [Babakan] - cmd.exe /k if %date:~6,4%%date:~3,2%%date:~0,2% LEQ 20131027 (exit) else (start dinoraptzor.org && exit)
HKU\S-1-5-21-978401329-1287808303-2657405011-1000\...\MountPoints2: {20347225-67bf-11e3-88eb-001d92270e0a} - F:\Autorun.exe
SearchScopes: HKCU - {47AC132D-68ED-11E3-A7C6-001D92270E0A} URL = searchinfinitas.com/?affilt=4&q={searchTerms}&id={22EB8586-C3D9-49D1-B940-7FBD249B6E56}
BHO-x32: No Name - {A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} - No File
FF Homepage: hxxp://searchinfinitas.com/?affilt=4&id={22EB8586-C3D9-49D1-B940-7FBD249B6E56}
FF Extension: SecretSauce - C:\Users\mirjana\AppData\Roaming\Mozilla\Firefox\Profiles\upixml4e.default\Extensions\{345422e3-72fa-447a-9550-97803edfacf3}.xpi [2014-02-03]
CHR Extension: (SecretSauce) - C:\Users\mirjana\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbpebffoameokfhnaaedmefjncfboino [2014-02-01]
C:\Users\mirjana\AppData\Local\Temp\AutoRun.exe
C:\Users\mirjana\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\mirjana\AppData\Local\Temp\avgnt.exe
C:\Users\mirjana\AppData\Local\Temp\bitool.dll
C:\Users\mirjana\AppData\Local\Temp\drm_dialogs.dll
C:\Users\mirjana\AppData\Local\Temp\EAInstall.dll
C:\Users\mirjana\AppData\Local\Temp\fftBAE3.tmp.exe
C:\Users\mirjana\AppData\Local\Temp\FLVPlayerSetup.exe
C:\Users\mirjana\AppData\Local\Temp\Game Setup File__2774_il4134.exe
C:\Users\mirjana\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\mirjana\AppData\Local\Temp\LEGOLOTR.exe
C:\Users\mirjana\AppData\Local\Temp\LMkRstPt.exe
C:\Users\mirjana\AppData\Local\Temp\MoviesToolbarSetup_Somoto.exe
C:\Users\mirjana\AppData\Local\Temp\Quarantine.exe
C:\Users\mirjana\AppData\Local\Temp\ShopperProFull.exe
C:\Users\mirjana\AppData\Local\Temp\sysplayer_bu20_setup.exe
C:\Users\mirjana\AppData\Local\Temp\tu17p84.exe
C:\Users\mirjana\AppData\Local\Temp\UpdateCheckerSetup.exe
C:\Users\mirjana\AppData\Local\Temp\utt7DDD.tmp.exe
C:\Users\Nikola\AppData\Local\Temp\avgnt.exe
SecretSauce (HKLM\...\SecretSauce Version: 2014.01.17.055843 - SecretSauce) <==== ATTENTION
Unity Web Player (HKCU\...\UnityWebPlayer Version: - Unity Technologies ApS) <==== ATTENTION
Task: {0242F9DC-5D33-42F1-B3BB-03BD40AD805C} - \iWebar-chromeinstaller No Task File
Task: {231A70A5-5FE3-4734-AF8A-191B7932304D} - \iWebar-updater No Task File
Task: {3529096B-5BCA-4BEC-BD4F-B54C9CD5AA95} - \RegClean Pro_DEFAULT No Task File
Task: {3D623D2E-2796-4EA3-8A60-B592407BCAE5} - \iWebar-enabler No Task File
Task: {A51F42B0-0568-4590-83AE-F80B5229754F} - \iWebar-firefoxinstaller No Task File
Task: {A7E570CA-385C-467D-9DC8-539F8FC2231F} - \RegClean Pro_UPDATES No Task File
Task: {D8707FF7-A723-48A7-B598-277BD3AA43D3} - \RegClean Pro No Task File
Task: {DE5911C8-5E16-4492-9C27-52C87F7967CC} - \iWebar-codedownloader No Task File
Task: {ECB4488D-A0BD-499E-9AB9-6A92544F297B} - \BackgroundContainer Startup Task No Task File
End

*****************

HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Babakan => Value deleted successfully.
HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{20347225-67bf-11e3-88eb-001d92270e0a} => Key not found.
HKCR\CLSID\{20347225-67bf-11e3-88eb-001d92270e0a} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{47AC132D-68ED-11E3-A7C6-001D92270E0A} => Key deleted successfully.
HKCR\CLSID\{47AC132D-68ED-11E3-A7C6-001D92270E0A} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} => Key not found.
Firefox homepage deleted successfully.
C:\Users\mirjana\AppData\Roaming\Mozilla\Firefox\Profiles\upixml4e.default\Extensions\{345422e3-72fa-447a-9550-97803edfacf3}.xpi => Moved successfully.
C:\Users\mirjana\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbpebffoameokfhnaaedmefjncfboino => Moved successfully.
C:\Users\mirjana\AppData\Local\Temp\AutoRun.exe => Moved successfully.
C:\Users\mirjana\AppData\Local\Temp\AutoRunGUI.dll => Moved successfully.
C:\Users\mirjana\AppData\Local\Temp\avgnt.exe => Moved successfully.
C:\Users\mirjana\AppData\Local\Temp\bitool.dll => Moved successfully.
C:\Users\mirjana\AppData\Local\Temp\drm_dialogs.dll => Moved successfully.
C:\Users\mirjana\AppData\Local\Temp\EAInstall.dll => Moved successfully.
C:\Users\mirjana\AppData\Local\Temp\fftBAE3.tmp.exe => Moved successfully.
C:\Users\mirjana\AppData\Local\Temp\FLVPlayerSetup.exe => Moved successfully.
C:\Users\mirjana\AppData\Local\Temp\Game Setup File__2774_il4134.exe => Moved successfully.
C:\Users\mirjana\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe => Moved successfully.
C:\Users\mirjana\AppData\Local\Temp\LEGOLOTR.exe => Moved successfully.
C:\Users\mirjana\AppData\Local\Temp\LMkRstPt.exe => Moved successfully.
C:\Users\mirjana\AppData\Local\Temp\MoviesToolbarSetup_Somoto.exe => Moved successfully.
C:\Users\mirjana\AppData\Local\Temp\Quarantine.exe => Moved successfully.
C:\Users\mirjana\AppData\Local\Temp\ShopperProFull.exe => Moved successfully.
C:\Users\mirjana\AppData\Local\Temp\sysplayer_bu20_setup.exe => Moved successfully.
C:\Users\mirjana\AppData\Local\Temp\tu17p84.exe => Moved successfully.
C:\Users\mirjana\AppData\Local\Temp\UpdateCheckerSetup.exe => Moved successfully.
C:\Users\mirjana\AppData\Local\Temp\utt7DDD.tmp.exe => Moved successfully.
C:\Users\Nikola\AppData\Local\Temp\avgnt.exe => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0242F9DC-5D33-42F1-B3BB-03BD40AD805C} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0242F9DC-5D33-42F1-B3BB-03BD40AD805C} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\iWebar-chromeinstaller => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{231A70A5-5FE3-4734-AF8A-191B7932304D} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{231A70A5-5FE3-4734-AF8A-191B7932304D} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\iWebar-updater => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3529096B-5BCA-4BEC-BD4F-B54C9CD5AA95} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3529096B-5BCA-4BEC-BD4F-B54C9CD5AA95} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegClean Pro_DEFAULT => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3D623D2E-2796-4EA3-8A60-B592407BCAE5} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3D623D2E-2796-4EA3-8A60-B592407BCAE5} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\iWebar-enabler => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A51F42B0-0568-4590-83AE-F80B5229754F} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A51F42B0-0568-4590-83AE-F80B5229754F} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\iWebar-firefoxinstaller => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A7E570CA-385C-467D-9DC8-539F8FC2231F} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A7E570CA-385C-467D-9DC8-539F8FC2231F} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegClean Pro_UPDATES => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D8707FF7-A723-48A7-B598-277BD3AA43D3} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D8707FF7-A723-48A7-B598-277BD3AA43D3} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegClean Pro => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{DE5911C8-5E16-4492-9C27-52C87F7967CC} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DE5911C8-5E16-4492-9C27-52C87F7967CC} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\iWebar-codedownloader => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{ECB4488D-A0BD-499E-9AB9-6A92544F297B} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ECB4488D-A0BD-499E-9AB9-6A92544F297B} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BackgroundContainer Startup Task => Key deleted successfully.

==== End of Fixlog ====

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Kakvo je sada stanje?

offline
  • Pridružio: 30 Dec 2008
  • Poruke: 193

Pa ne mogu da kažem da se popravilo i dalje je spor ,sporo otvara,skroluje....

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Preuzmi smeenk-ov zoek.zip ili zoek.rar () sa ovog ili ovog linka i sačuvaj ga na Desktop.

Raspakuj arhivu u neki folder (uputstvo), a zatim:

zatvori browser i ostale pokrenute programe;
privremeno deaktiviraj zaštitni softver ( ukoliko je to potrebno ) Uputstvo ;
dvoklikom pokreni zoek na ikonicu programa ;
pričekaj da se alat startuje ...


U beli okvir prozora iskopiraj sledeći tekst:


filesrcm;
startupall;
skipfix-iedefaults;
firefoxlook;
chromelook;


Klikni na dugme i pričekaj da se skeniranje završi.


zoek ce po potrebi, restartovati Windows a na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.

Napomena:Izveštaj će biti sačuvan pod nazivom zoek-results.log na sistemskoj particiji (tipična lokacija: C:\zoek-results.log)


Arrow Kopiraj sadrzaj tog loga u poruku.

offline
  • Pridružio: 30 Dec 2008
  • Poruke: 193

Napisano: 22 Feb 2014 13:20

Zaboravila sam da napišem i da mi stalno iskaču razne reklame,te da su mi se pojavila i dva pretraživača u Toolbaru koja redovno uklonim ali se oni pri ponovnom paljenju opet pojavljuju.

Dopuna: 22 Feb 2014 13:46

Zoek.exe v5.0.0.0 Updated 19-February-2014
Tool run by mirjana on sub 22.02.2014 at 13:25:45,84.
Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\mirjana\Desktop\New Folder (2)\zoek.scr [Scan all users] [Script inserted]

==== System Restore Info ======================

22.2.2014 13:30:06 Zoek.exe System Restore Point Created Succesfully.

==== Files Recently Created / Modified ======================

====== C:\Windows ====
2014-02-22 11:12:24 7D6089D7AAA94D1EA07F400B68916042 265555683 ----a-w- C:\Windows\MEMORY.DMP
2014-02-22 11:10:11 0245D0889C3443F5DC9194558583FE59 43152 ----a-w- C:\Windows\avastSS.scr
====== C:\Users\mirjana\AppData\Local\Temp ====
2014-02-22 11:05:50 E6633716EE2AC06BCB4A58FF993015F3 155976 ----a-w- C:\Users\mirjana\AppData\Local\Temp\_av_iup.tm~a01844\instup.exe
2014-02-22 11:05:49 DC730F5EA07F8CE98E49BBBD110EAA14 3167112 ----a-w- C:\Users\mirjana\AppData\Local\Temp\_av_iup.tm~a01844\HTMLayout.dll
2014-02-22 11:05:48 F22DE5F5BA8ADA0A861441B624B51EB5 421704 ----a-w- C:\Users\mirjana\AppData\Local\Temp\_av_iup.tm~a01844\kvxvojse.sys
2014-02-22 11:05:48 D11625C81FB88DC8A607BB9D76920A3D 2966792 ----a-w- C:\Users\mirjana\AppData\Local\Temp\_av_iup.tm~a01844\aswOfferTool.exe
2014-02-22 11:05:47 BCDEA07CD91EF85BBCC869DF4906C8C1 7201640 ----a-w- C:\Users\mirjana\AppData\Local\Temp\_av_iup.tm~a01844\Instup.dll
2014-02-22 11:05:46 B8FA402B238DB49C35CAF711D5BC9843 1093216 ----a-w- C:\Users\mirjana\AppData\Local\Temp\_av_iup.tm~a01844\avBugReport.exe
2014-02-22 09:09:54 8938D3D18B09E92EEB9C403593365EB0 553067 ----a-w- C:\Users\mirjana\AppData\Local\Temp\{5F08ED18-EDF6-4079-B3B4-64BF787D3085}\_isres_0x0409.dll
2014-02-22 09:09:51 ED5AA645392883B21507C8D097FDA277 261424 ----a-w- C:\Users\mirjana\AppData\Local\Temp\{5F08ED18-EDF6-4079-B3B4-64BF787D3085}\ISRT.dll
====== Java Cache =====
====== C:\Windows\SysWOW64 =====
2014-02-22 09:11:03 F9A7F43E9974BA02AE1DD0C3CDDA5A67 5 ----a-w- C:\Windows\SysWOW64\lMMLDeleteUserData42107612FX.tmp
2014-02-12 22:37:09 3D485254E43EF4E4F707346B5731EA9A 454656 ----a-w- C:\Windows\SysWOW64\vbscript.dll
2014-02-12 22:35:45 B8F28AAC003060E3B125D2447CFC19E2 164864 ----a-w- C:\Windows\SysWOW64\msrating.dll
2014-02-12 22:35:45 B5B3334F177CED627C2D7FE38235B6B1 2724864 ----a-w- C:\Windows\SysWOW64\mshtml.tlb
2014-02-12 22:35:44 85AC8EB265EDCAD86D651D45C5E3AB83 440832 ----a-w- C:\Windows\SysWOW64\ieui.dll
2014-02-12 22:35:42 C9D1131E2163CE932DF3EAAF0EEA3673 524288 ----a-w- C:\Windows\SysWOW64\msfeeds.dll
2014-02-12 22:35:41 7D6B20C69CC8EECB8F31D4FAF913BBE8 112128 ----a-w- C:\Windows\SysWOW64\ieUnatt.exe
2014-02-12 22:35:41 6A06EB11F1E5BDAA795DAE7838F9FE20 43008 ----a-w- C:\Windows\SysWOW64\jsproxy.dll
2014-02-12 22:35:41 408805B8083896DC95E6340F4016BEBD 61952 ----a-w- C:\Windows\SysWOW64\iesetup.dll
2014-02-12 22:35:40 260D6B421E5551E8BA75D16B5CA90D9A 51200 ----a-w- C:\Windows\SysWOW64\ieetwproxystub.dll
2014-02-12 22:35:40 0E7B7C9F483300F9FF97C6A1E4BC4F57 32768 ----a-w- C:\Windows\SysWOW64\iernonce.dll
2014-02-12 22:35:39 0F739443669F3A48F1B2325995117BFE 553472 ----a-w- C:\Windows\SysWOW64\jscript9diag.dll
2014-02-12 22:35:38 5DD49C02D059C1E6E47A8FB4A076C9B1 703488 ----a-w- C:\Windows\SysWOW64\ieapfltr.dll
2014-02-12 22:35:37 9C89246184979A070B0C6CCF61C68136 1820160 ----a-w- C:\Windows\SysWOW64\wininet.dll
2014-02-12 22:35:37 34CBED7698D557DDB43F8732FBC2ACB9 2168320 ----a-w- C:\Windows\SysWOW64\iertutil.dll
2014-02-12 22:35:36 5D9DC6332A4FC66388B09BBE7CF53750 1156096 ----a-w- C:\Windows\SysWOW64\urlmon.dll
2014-02-12 22:35:36 40E68599FE3A10F816217D3789FCE74E 1964032 ----a-w- C:\Windows\SysWOW64\inetcpl.cpl
2014-02-12 22:35:34 79FA7D8B488F90EDE325963379A6F738 11266048 ----a-w- C:\Windows\SysWOW64\ieframe.dll
2014-02-12 22:35:33 C863E5A2417DF0F2A31ED32C3B2CB23F 17103872 ----a-w- C:\Windows\SysWOW64\mshtml.dll
2014-02-12 22:35:32 99280392987A1A96C756A9F38C4CE396 4244480 ----a-w- C:\Windows\SysWOW64\jscript9.dll
2014-02-12 07:02:39 EA093130471090037BB70A4AF86FAD1B 420008 ----a-w- C:\Windows\SysWOW64\locale.nls
2014-02-12 07:02:07 E4561704CBFA193761743E5AF746C669 1237504 ----a-w- C:\Windows\SysWOW64\msxml3.dll
2014-02-12 07:02:04 17B06F23237FCD731FA2E10ECD6EDFE1 2048 ----a-w- C:\Windows\SysWOW64\msxml3r.dll
2014-02-12 06:59:24 E01D2AC63453534DB8AD1EA97DEE9C3A 594944 ----a-w- C:\Windows\SysWOW64\RMActivate_isv.exe
2014-02-12 06:59:24 6142C5540C8D2764D59CBC11AF4A5900 572416 ----a-w- C:\Windows\SysWOW64\RMActivate.exe
2014-02-12 06:59:23 0F5FEF37588AF457E02125674F171A4F 508928 ----a-w- C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2014-02-12 06:59:19 08D323750350A8A29611D1004C0CF319 510976 ----a-w- C:\Windows\SysWOW64\RMActivate_ssp.exe
2014-02-12 06:59:17 BBCE3E9E74C7CEA47FA4115B360AC2C6 423936 ----a-w- C:\Windows\SysWOW64\secproc_isv.dll
2014-02-12 06:59:12 7FA485555BF802FE3DB5598004DBDFAC 390144 ----a-w- C:\Windows\SysWOW64\msdrm.dll
2014-02-12 06:59:12 12A9F24DC9F465DA79AC2272D829A81E 428032 ----a-w- C:\Windows\SysWOW64\secproc.dll
2014-02-12 06:59:10 9158DBE2F8483434FC72F320690C9DB8 87040 ----a-w- C:\Windows\SysWOW64\secproc_ssp_isv.dll
2014-02-12 06:59:10 58712A48D31B40EBCB35B47205F87771 87040 ----a-w- C:\Windows\SysWOW64\secproc_ssp.dll
2014-02-12 06:55:48 D96106CF60505734B14F6AE80AAA4B07 1987584 ----a-w- C:\Windows\SysWOW64\d3d10warp.dll
2014-02-12 06:55:44 14800BD31701A5047AC3145BB1E698AE 3419136 ----a-w- C:\Windows\SysWOW64\d2d1.dll
====== C:\Windows\SysWOW64\drivers =====
====== C:\Windows\Sysnative =====
2014-02-22 11:10:28 28192A2A37F52EB97EBE14DEE0F2513B 334136 ----a-w- C:\Windows\Sysnative\aswBoot.exe
2014-02-12 22:37:09 F67C7D80745379DC4C5332EFFE5AC696 548864 ----a-w- C:\Windows\Sysnative\vbscript.dll
2014-02-12 22:35:45 94C59DD02BC7EA0E421055B9946CA861 2724864 ----a-w- C:\Windows\Sysnative\mshtml.tlb
2014-02-12 22:35:45 1D1D7F52EC84294859642A4309FE648E 195584 ----a-w- C:\Windows\Sysnative\msrating.dll
2014-02-12 22:35:44 63B5E990896BA81D604032A48CC80A5C 574976 ----a-w- C:\Windows\Sysnative\ieui.dll
2014-02-12 22:35:43 FD08F8BA2437A85F500EFFE3FD3158A6 33792 ----a-w- C:\Windows\Sysnative\iernonce.dll
2014-02-12 22:35:43 E77092C38028EB0A5C461B3436E0A6D5 4096 ----a-w- C:\Windows\Sysnative\ieetwcollectorres.dll
2014-02-12 22:35:43 27516B54E116D5EF8B0129B5C829A87C 218624 ----a-w- C:\Windows\Sysnative\ie4uinit.exe
2014-02-12 22:35:42 99ED8FBAFD325550D07A32664D9E3CC8 53760 ----a-w- C:\Windows\Sysnative\jsproxy.dll
2014-02-12 22:35:41 CDE728C8FB1D6E132CED44835FA44C87 627200 ----a-w- C:\Windows\Sysnative\msfeeds.dll
2014-02-12 22:35:41 338415F2E9A188875B6E43B5269620B0 139264 ----a-w- C:\Windows\Sysnative\ieUnatt.exe
2014-02-12 22:35:40 FCFAEDF0AA1A78A1875FDB798598408B 48640 ----a-w- C:\Windows\Sysnative\ieetwproxystub.dll
2014-02-12 22:35:40 E129D34089E70215B65EA611F802FA9A 111616 ----a-w- C:\Windows\Sysnative\ieetwcollector.exe
2014-02-12 22:35:40 C1E2C16D58D76323800C3EE5E2C5095A 66048 ----a-w- C:\Windows\Sysnative\iesetup.dll
2014-02-12 22:35:39 D016F5092E4FFC41147E8555A71D2DDE 23170048 ----a-w- C:\Windows\Sysnative\mshtml.dll
2014-02-12 22:35:38 F348B2D0983C91392632B4291C517AA4 817664 ----a-w- C:\Windows\Sysnative\ieapfltr.dll
2014-02-12 22:35:38 3906C9640406FC0FC00A324947C74893 708608 ----a-w- C:\Windows\Sysnative\jscript9diag.dll
2014-02-12 22:35:37 6300AD525D639CECBB3D144B6D7B30F9 2765824 ----a-w- C:\Windows\Sysnative\iertutil.dll
2014-02-12 22:35:36 263B6E451526A90FF8B1CEC759F22956 2334208 ----a-w- C:\Windows\Sysnative\wininet.dll
2014-02-12 22:35:36 22874047B810B5B174C68ACD7C0B6510 1393664 ----a-w- C:\Windows\Sysnative\urlmon.dll
2014-02-12 22:35:35 DB02F4D37E5F7F07A0D0F9FAA68249EE 13051392 ----a-w- C:\Windows\Sysnative\ieframe.dll
2014-02-12 22:35:35 83296DE8CFFEADA636DCC1AB2E3BF643 2041856 ----a-w- C:\Windows\Sysnative\inetcpl.cpl
2014-02-12 22:35:32 5922EEA922D3AD686342F866CAEE851F 5768704 ----a-w- C:\Windows\Sysnative\jscript9.dll
2014-02-12 07:02:39 EA093130471090037BB70A4AF86FAD1B 420008 ----a-w- C:\Windows\Sysnative\locale.nls
2014-02-12 07:02:10 0D298133C359AB8CB9EB4FA178BF3947 1882112 ----a-w- C:\Windows\Sysnative\msxml3.dll
2014-02-12 07:02:02 CD2C20CC3B385A32701F78C0ACBBE9F3 2048 ----a-w- C:\Windows\Sysnative\msxml3r.dll
2014-02-12 06:59:25 1B3741488AA7E237961A29D1E7A44C0A 626176 ----a-w- C:\Windows\Sysnative\RMActivate.exe
2014-02-12 06:59:25 17CF3B3F68272BD40C878D4DBAB0EBC9 658432 ----a-w- C:\Windows\Sysnative\RMActivate_isv.exe
2014-02-12 06:59:22 297926B15AE5390409F1007EB28A8EFB 552960 ----a-w- C:\Windows\Sysnative\RMActivate_ssp_isv.exe
2014-02-12 06:59:20 03F8F411F118CFDA508E77C747BB05EA 553984 ----a-w- C:\Windows\Sysnative\RMActivate_ssp.exe
2014-02-12 06:59:18 5693212AB2EBCACBBE05EC3A642113E2 485888 ----a-w- C:\Windows\Sysnative\secproc_isv.dll
2014-02-12 06:59:15 C6AC2C91541D24F9E236A670C0CA793D 528384 ----a-w- C:\Windows\Sysnative\msdrm.dll
2014-02-12 06:59:15 399FC1B75790EE606A6FD9F2FB4C891C 488448 ----a-w- C:\Windows\Sysnative\secproc.dll
2014-02-12 06:59:11 B41B1FEDEBBD955B4E25676B42087885 123392 ----a-w- C:\Windows\Sysnative\secproc_ssp.dll
2014-02-12 06:59:10 DC6DD779F35BB42E2E76FDFEC565C251 123392 ----a-w- C:\Windows\Sysnative\secproc_ssp_isv.dll
2014-02-12 06:55:47 E8710B5DDA963E6BA198DF5FB209E72A 2565120 ----a-w- C:\Windows\Sysnative\d3d10warp.dll
2014-02-12 06:55:45 C676E5EA388AF7C4C031F56F9B42E362 3928064 ----a-w- C:\Windows\Sysnative\d2d1.dll
====== C:\Windows\Sysnative\drivers =====
2014-02-22 11:49:10 7F6904FC2E5EDD0F3B944EAB4AFE073C 440672 ----a-w- C:\Windows\Sysnative\drivers\aswndisflt.sys
2014-02-22 11:48:44 57483E691D635510533E081EC4CB81EC 28184 ----a-w- C:\Windows\Sysnative\drivers\aswKbd.sys
2014-02-22 11:10:40 FD3EA14ADF6216BDF4030DB2EFD43D96 80184 ----a-w- C:\Windows\Sysnative\drivers\aswStm.sys
2014-02-22 11:10:40 90399625F341AB76BA4B85A5E860EB1F 207904 ----a-w- C:\Windows\Sysnative\drivers\aswVmm.sys
2014-02-22 11:10:39 F22DE5F5BA8ADA0A861441B624B51EB5 421704 ----a-w- C:\Windows\Sysnative\drivers\aswSP.sys
2014-02-22 11:10:39 C04F7B373881009D7994D9BF55D24AB4 65776 ----a-w- C:\Windows\Sysnative\drivers\aswRvrt.sys
2014-02-22 11:10:39 43599E630DFC30AD4E6A2B4B269EB1C0 1038072 ----a-w- C:\Windows\Sysnative\drivers\aswSnx.sys
2014-02-22 11:10:37 0ACC3F49015E628590CA4372322EB46B 78648 ----a-w- C:\Windows\Sysnative\drivers\aswMonFlt.sys
2014-02-22 11:10:36 679712B7A353EE665B9301592164A172 92544 ----a-w- C:\Windows\Sysnative\drivers\aswRdr2.sys
====== C:\Windows\Tasks ======
2014-02-22 12:25:53 3DF7FD387DFDE7BF81119F69EAD32C45 3192 ----a-w- C:\Windows\Sysnative\Tasks\{E3298CB5-21F1-463B-9350-79B772263C69}
2014-02-22 12:25:11 6EEB0CE882A408722A2BD5A1829E192B 3204 ----a-w- C:\Windows\Sysnative\Tasks\{1B900FB2-2F58-43D9-8C1D-9401AABCAF6D}
2014-02-22 11:10:57 97795C027F031AB80EE69370D38DB275 4182 ----a-w- C:\Windows\Sysnative\Tasks\avast! Emergency Update
====== C:\Windows\Temp ======
======= C:\Program Files =====
2014-02-02 22:18:16 -------- d-----w- C:\Program Files\Retro PC Calculator
======= C:\PROGRA~2 =====
2014-02-10 12:30:06 -------- d-----w- C:\PROGRA~2\The Cave
2014-02-08 19:49:39 -------- d-----w- C:\PROGRA~2\Cybertek
2014-02-06 21:11:52 -------- d-----w- C:\PROGRA~2\OpenOffice 4
2014-02-05 15:11:32 -------- d-----w- C:\PROGRA~2\JoWooD
2014-01-26 23:20:57 -------- d-----w- C:\PROGRA~2\MSXML 4.0
2014-01-25 20:18:41 -------- d-----w- C:\PROGRA~2\HTC
======= C: =====
====== C:\Users\mirjana\AppData\Roaming ======
2014-02-19 08:57:09 619B571DF51965602D3667E4FFBAA7C5 3584 ----a-w- C:\Users\mirjana\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-02-16 22:13:02 -------- d-----w- C:\Users\mirjana\AppData\Roaming\Anino Games
2014-02-13 14:19:07 -------- d-----w- C:\Users\Nikola\AppData\Roaming\My The Lord of the Rings, The Rise of the Witch-king Files
2014-02-12 22:04:26 -------- d-----w- C:\Users\mirjana\AppData\Roaming\My The Lord of the Rings, The Rise of the Witch-king Files
2014-02-11 20:17:11 -------- d-----w- C:\Users\Nikola\AppData\Locallow\Adobe
2014-02-10 12:33:46 -------- d-----w- C:\Users\mirjana\AppData\Roaming\Doublefine
2014-02-08 19:52:09 -------- d-----w- C:\Users\mirjana\AppData\Roaming\PeaceCraft4
2014-02-08 19:18:22 -------- d-----w- C:\Users\mirjana\AppData\Roaming\vikingsaga2_realore_en
2014-02-08 19:18:22 -------- d-----w- C:\Users\mirjana\AppData\Local\vikingsaga2_realore_en
2014-02-06 21:19:09 -------- d-----w- C:\Users\mirjana\AppData\Roaming\OpenOffice
2014-02-05 15:11:49 -------- d-----w- C:\Users\mirjana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JoWooD
2014-01-31 23:13:15 -------- d-----w- C:\Users\mirjana\AppData\Roaming\Realore
2014-01-30 10:41:02 62F1A6F0D39B3BFB91B54F5FC971E0C6 347472 ----a-w- C:\Users\mirjana\AppData\Local\MB.SAV
2014-01-28 21:49:57 -------- d-----w- C:\Users\mirjana\AppData\Roaming\Carambis
2014-01-27 17:22:01 -------- d-----w- C:\Users\Nikola\AppData\Local\Microsoft Games
2014-01-26 08:15:50 -------- d-----w- C:\Users\Nikola\AppData\Local\Apple Computer
2014-01-26 08:15:46 -------- d-----w- C:\Users\Nikola\AppData\Roaming\Apple Computer
2014-01-26 08:15:30 -------- d-----w- C:\Users\Nikola\AppData\Local\HTC MediaHub
2014-01-25 22:42:39 -------- d-----w- C:\Users\mirjana\AppData\Roaming\ViberPC
2014-01-25 22:40:53 -------- d-----w- C:\Users\mirjana\AppData\Local\Viber
2014-01-25 20:22:53 -------- d-----w- C:\Users\mirjana\AppData\Roaming\HTC
2014-01-25 20:21:53 -------- d-----w- C:\Users\mirjana\AppData\Roaming\Apple Computer
2014-01-25 20:21:53 -------- d-----w- C:\Users\mirjana\AppData\Local\Apple Computer
2014-01-25 20:17:06 -------- d-----w- C:\Users\mirjana\AppData\Local\Downloaded Installations
====== C:\Users\mirjana ======
2014-02-22 11:32:30 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-02-22 11:02:37 D036446E7ED16FF3063501F3D9FDDBBE 90578216 ----a-w- C:\Users\mirjana\Downloads\avast_free_antivirus_setup.exe
2014-02-22 09:59:57 6D6A061ED70FBD40F6C8BC2B6CBE1F29 2154496 ----a-w- C:\Users\mirjana\Desktop\FRST64.exe
2014-02-22 09:58:36 0840EB50F38B3A9BBA2D24780AEB07A6 1241834 ----a-w- C:\Users\mirjana\Desktop\AdwCleaner.exe
2014-02-22 09:55:17 B54EC7F692DB370EACE56F78A06C57B3 1874664 ----a-w- C:\Users\mirjana\Desktop\HWMonitor_x64.exe
2014-02-10 12:33:14 -------- d-----w- C:\ProgramData\RELOADED
2014-02-06 21:13:38 -------- d-s---w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.0.1
2014-02-03 14:12:00 -------- d-----w- C:\ProgramData\GameHouse
2014-02-02 22:18:23 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Retro PC Calculator
2014-01-28 21:50:25 998D67F80030ACB44C2DBF29871EC9A7 5033 ----a-w- C:\ProgramData\mtbjfghn.xbe
2014-01-26 08:15:10 -------- d-----w- C:\Users\Nikola\.android
2014-01-25 20:21:04 -------- d-----w- C:\ProgramData\HTC

====== C: exe-files ==
2014-02-22 12:04:47 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\Users\mirjana\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MOO7DZI0\FRST64[1].exe
2014-02-22 11:10:28 28192A2A37F52EB97EBE14DEE0F2513B 334136 ----a-w- C:\Windows\System32\aswBoot.exe
2014-02-22 11:05:50 E6633716EE2AC06BCB4A58FF993015F3 155976 ----a-w- C:\Users\mirjana\AppData\Local\Temp\_av_iup.tm~a01844\instup.exe
2014-02-22 11:05:48 D11625C81FB88DC8A607BB9D76920A3D 2966792 ----a-w- C:\Users\mirjana\AppData\Local\Temp\_av_iup.tm~a01844\aswOfferTool.exe
2014-02-22 11:05:46 B8FA402B238DB49C35CAF711D5BC9843 1093216 ----a-w- C:\Users\mirjana\AppData\Local\Temp\_av_iup.tm~a01844\avBugReport.exe
2014-02-22 11:02:37 D036446E7ED16FF3063501F3D9FDDBBE 90578216 ----a-w- C:\Users\mirjana\Downloads\avast_free_antivirus_setup.exe
2014-02-22 09:59:57 6D6A061ED70FBD40F6C8BC2B6CBE1F29 2154496 ----a-w- C:\Users\mirjana\Desktop\FRST64.exe
2014-02-22 09:58:36 0840EB50F38B3A9BBA2D24780AEB07A6 1241834 ----a-w- C:\Users\mirjana\Desktop\AdwCleaner.exe
2014-02-22 09:55:17 B54EC7F692DB370EACE56F78A06C57B3 1874664 ----a-w- C:\Users\mirjana\Desktop\HWMonitor_x64.exe
2014-02-21 14:01:42 A4F0C36642681927FA53CD6A90CA2975 7620312 ----a-w- C:\Program Files (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\33.0.1750.117\33.0.1750.117_32.0.1700.107_chrome_updater.exe
2014-02-16 20:47:48 90DD3D32510A81D86E3606ABCFE568EA 4830208 ----a-w- C:\Users\mirjana\Desktop\Through Andreas Eyes\ThroughAndreasEyes.exe
2014-02-16 20:46:10 9844EAD05B446DD2859BBB816B4BA0C0 8577024 ----a-w- C:\Users\mirjana\Desktop\Viking Saga 2\Viking Saga 2 - New World.exe
=== C: other files ==
2014-02-22 11:49:10 7F6904FC2E5EDD0F3B944EAB4AFE073C 440672 ----a-w- C:\Windows\System32\drivers\aswndisflt.sys
2014-02-22 11:48:44 57483E691D635510533E081EC4CB81EC 28184 ----a-w- C:\Windows\System32\drivers\aswKbd.sys
2014-02-22 11:10:40 FD3EA14ADF6216BDF4030DB2EFD43D96 80184 ----a-w- C:\Windows\System32\drivers\aswStm.sys
2014-02-22 11:10:40 90399625F341AB76BA4B85A5E860EB1F 207904 ----a-w- C:\Windows\System32\drivers\aswVmm.sys
2014-02-22 11:10:39 F22DE5F5BA8ADA0A861441B624B51EB5 421704 ----a-w- C:\Windows\System32\drivers\aswSP.sys
2014-02-22 11:10:39 C04F7B373881009D7994D9BF55D24AB4 65776 ----a-w- C:\Windows\System32\drivers\aswRvrt.sys
2014-02-22 11:10:39 43599E630DFC30AD4E6A2B4B269EB1C0 1038072 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2014-02-22 11:10:37 0ACC3F49015E628590CA4372322EB46B 78648 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2014-02-22 11:10:36 679712B7A353EE665B9301592164A172 92544 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys
2014-02-22 11:05:48 F22DE5F5BA8ADA0A861441B624B51EB5 421704 ----a-w- C:\Users\mirjana\AppData\Local\Temp\_av_iup.tm~a01844\kvxvojse.sys
2014-02-22 09:50:50 3B7662A53A4D7C7B0E2D2B566504DC84 1211264 ----a-w- C:\Users\mirjana\Downloads\hwmonitor_1.24.zip

==== Startup Registry Enabled ======================

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"

[HKEY_USERS\S-1-5-21-978401329-1287808303-2657405011-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun"
"DAEMON Tools Lite"="C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe -autorun"
"Guard"="C:\Users\mirjana\AppData\Local\Guard\Guard.exe"
"Viber"="C:\Users\mirjana\AppData\Local\Viber\Viber.exe StartMinimized"
"uTorrent"="C:\Users\mirjana\AppData\Roaming\uTorrent\uTorrent.exe /MINIMIZED"
"ChicaPasswordManager"="C:\Program Files (x86)\ChicaLogic\Chica Password Manager\stpass.exe /autorunned"

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe /min"
"StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe MSRun"
"SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvastUI.exe /nogui"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"20131224"="C:\Program Files\AVAST Software\Avast\setup\emupdate\4e677a36-aa41-4fc7-b081-ce47a6ca92e6.exe /check"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun"
"DAEMON Tools Lite"="C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe -autorun"
"Guard"="C:\Users\mirjana\AppData\Local\Guard\Guard.exe"
"Viber"="C:\Users\mirjana\AppData\Local\Viber\Viber.exe StartMinimized"
"uTorrent"="C:\Users\mirjana\AppData\Roaming\uTorrent\uTorrent.exe /MINIMIZED"
"ChicaPasswordManager"="C:\Program Files (x86)\ChicaLogic\Chica Password Manager\stpass.exe /autorunned"

==== Startup Registry Enabled x64 ======================

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s"
"EvtMgr6"="C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming"
"Windows NTV Host Monitor"="C:\Program Files\Retro PC Calculator\ntvmon32.exe"

==== Task Scheduler Jobs ======================

C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [21.02.2014 20:53]
C:\Windows\tasks\DriverEasy Scheduled Scan.job --a------ C:\Program Files\Easeware\DriverEasy\DriverEasy.exe [23.12.2013 02:16]
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [19.12.2013 00:58]
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [19.12.2013 00:58]

==== Other Scheduled Tasks ======================

"C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe]
"C:\Windows\SysNative\tasks\DriverEasy Scheduled Scan" [C:\Program Files\Easeware\DriverEasy\DriverEasy.exe]
"C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe]
"C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe]
"C:\Windows\SysNative\tasks\SPMupdate1" [C:\Windows\system32\rundll32.exe C:\PROGRA~1\COMMON~1\System\SYSPLA~2.DLL ,Command701 update1]
"C:\Windows\SysNative\tasks\{BD074BA5-2B4E-48B2-9576-8CB08529923C}" [C:\Program Files (x86)\NARUTO SHIPPUDEN Ultimate Ninja STORM 3 Full Burst\NS3FB_launcher.exe]

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [22.02.2014 12:48]

==== Firefox Extensions ======================

ProfilePath: C:\Users\mirjana\AppData\Roaming\Mozilla\Firefox\Profiles\upixml4e.default
- Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
- Notificatoin - %ProfilePath%\extensions\{941E9C01-F8E0-493E-B814-E693BC99A1A1}

ProfilePath: C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\7lx01e3w.default
- Notificatoin - %ProfilePath%\extensions\{941E9C01-F8E0-493E-B814-E693BC99A1A1}

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\mirjana\AppData\Roaming\Mozilla\Firefox\Profiles\upixml4e.default
853A6F93105790D4DC4D30CC92B19E11 - C:\Users\mirjana\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player
F3B0E300AFC94E1A775A2D935A7D384F - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1207148.dll - Shockwave for Director / Shockwave for Director


==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
dbpebffoameokfhnaaedmefjncfboino - C:\Program Files (x86)\SecretSauce\dbpebffoameokfhnaaedmefjncfboino.crx[01.02.2014 16:41]
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[22.02.2014 12:09]
ojhagnahfpegocdhlopgljpaafeogmcc - C:\Program Files (x86)\ShopperPro\ShopperPro.crx[]

Google Translate - mirjana\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb
YouTube - mirjana\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
TV - mirjana\AppData\Local\Google\Chrome\User Data\Default\Extensions\bppbpeijolfcampacpljolaegibfhjph
Google Search - mirjana\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
Logitech Smooth Scrolling - mirjana\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkpejdfnpdkhifgbancbammdijojoffk
YoWindow Weather - mirjana\AppData\Local\Google\Chrome\User Data\Default\Extensions\fanogbnclpilemkifpjeglokomebpnef
avast Online Security - mirjana\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
Gradient - mirjana\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipehkhefmnpkdbcpgbononhiohcabocp
Google Mail Checker - mirjana\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff
Autofill - mirjana\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlmmgnhgdeffjkdckmikfpnddkbbfkkk
Google Wallet - mirjana\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
ShopperPro - mirjana\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojhagnahfpegocdhlopgljpaafeogmcc
Xbox LIVE Dashboard - mirjana\AppData\Local\Google\Chrome\User Data\Default\Extensions\oobdmiffgnobnpagcjjmpcajhdaoighg
Gmail - mirjana\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
SecretSauce - Nikola\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbpebffoameokfhnaaedmefjncfboino
Google Wallet - Nikola\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda

==== IE Start and Search Settings ======================

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR"

==== C:\zoek_backup content ======================

C:\zoek_backup (files=0 folders=0 0 bytes)

==== EOF on sub 22.02.2014 at 13:40:11,68 ======================

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Ponovo pokreni zoek ;


zatvori browser i ostale pokrenute programe;
deaktiviraj zaštitni softver ( po potrebi ) Uputstvo ;


U beli okvir prozora iskopiraj sledeći tekst:


autoclean;
C:\Windows\SysWOW64\lMMLDeleteUserData42107612FX.tmp;f
Notificatoin;ff
C:\Users\mirjana\AppData\LocalLow\Unity;fs
dbpebffoameokfhnaaedmefjncfboino;ff
C:\Program Files (x86)\SecretSauce;fs
ojhagnahfpegocdhlopgljpaafeogmcc;ff
C:\Program Files (x86)\ShopperPro;fs
TV;ff
ShopperPro;ff
SecretSauce;ff
iedefaults;
emptyalltemp;
emptyclsid;
ipconfig /flushdns >> %temp%\log.txt;b





Klikni na dugme i pričekaj da se skeniranje završi.


zoek ce po potrebi, restartovati Windows a na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.

Napomena:Izveštaj će biti sačuvan pod nazivom zoek-results.log na sistemskoj particiji (tipična lokacija: C:\zoek-results.log)


Arrow Kopiraj sadrzaj tog loga u poruku.

Ko je trenutno na forumu
 

Ukupno su 660 korisnika na forumu :: 12 registrovanih, 2 sakrivenih i 646 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: Altay, cikadeda, Deneb, Doca, dragonserbia, mane123, nemkea71, Snorks, trajkoni018, wolverined4, yrraf, zljubomir