Windows 10 ne očitava Word i Excel

1

Windows 10 ne očitava Word i Excel

offline
  • Pridružio: 04 Avg 2014
  • Poruke: 15

Dobro veče,imam problem na računaru. Od juče ne mogu da otvorim nijedan dokument u računaru. Deca igraju igrice ,sin je pokušao da se uloguje na Internet Explorer (tražili su Microsoft account ) i od tada ne radi .Inače igra one tenkove stalno.
Kada pokušam da otvorim neki dokument ,kao i blanko ( ikonicu za Word ili Excel) pojave se ova obaveštenja :







Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-01-2017
Ran by Home (administrator) on DESKTOP-A2NHTBU (14-01-2017 20:27:06)
Running from C:\Users\Home\Desktop
Loaded Profiles: Home (Available Profiles: Home)
Platform: Windows 10 Pro Version 1511 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: geekstogo.com/forum/topic/335081-frst-t.....scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(PixArt Imaging Incorporation) C:\Windows\PixArt\PAC7311\Monitor.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [163800 2016-07-30] (IvoSoft)
HKLM\...\Run: [PAC7311_Monitor] => C:\Windows\PixArt\PAC7311\Monitor.exe [319488 2006-11-03] (PixArt Imaging Incorporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-09-22] (Oracle Corporation)
HKU\S-1-5-21-3962405984-4113580480-2445003737-1002\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27017856 2016-10-17] (Skype Technologies S.A.)
HKU\S-1-5-21-3962405984-4113580480-2445003737-1002\...\Run: [Google Update] => C:\Users\Home\AppData\Local\Google\Update\1.3.32.7\GoogleUpdateCore.exe [601752 2016-12-17] (Google Inc.)
HKU\S-1-5-21-3962405984-4113580480-2445003737-1002\...\Run: [World of Tanks] => "C:\Games\World_of_Tanks\WargamingGameUpdater.exe"
HKU\S-1-5-21-3962405984-4113580480-2445003737-1002\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [805888 2015-10-30] (Microsoft Corporation)
IFEO\SppExtComObj.exe: [Debugger] SppExtComObjPatcher.exe
ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2016-07-30] (IvoSoft)
ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll [2016-07-30] (IvoSoft)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{e43c930d-54ce-41d2-b650-f7f730dca375}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKU\S-1-5-21-3962405984-4113580480-2445003737-1002\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office16\OCHelper.dll [2015-07-31] (Microsoft Corporation)
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2016-07-30] (IvoSoft)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL [2016-04-14] (Microsoft Corporation)
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2016-07-30] (IvoSoft)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office16\OCHelper.dll [2016-03-15] (Microsoft Corporation)
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2016-07-30] (IvoSoft)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll [2016-10-31] (Oracle Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office16\GROOVEEX.DLL [2016-04-14] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-10-31] (Oracle Corporation)
BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2016-07-30] (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2016-07-30] (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2016-07-30] (IvoSoft)
Handler-x32: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2016-04-12] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2016-04-12] (Microsoft Corporation)

FireFox:
========
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2016-10-06] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-10-31] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-10-31] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-03-15] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3962405984-4113580480-2445003737-1002: @tools.google.com/Google Update;version=3 -> C:\Users\Home\AppData\Local\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin HKU\S-1-5-21-3962405984-4113580480-2445003737-1002: @tools.google.com/Google Update;version=9 -> C:\Users\Home\AppData\Local\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2016-03-15] (Microsoft Corporation)

Chrome:
=======
CHR Profile: C:\Users\Home\AppData\Local\Google\Chrome\User Data\Default [2017-01-14]
CHR Extension: (Google Docs) - C:\Users\Home\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-08-24]
CHR Extension: (YouTube) - C:\Users\Home\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-08-24]
CHR Extension: (Adobe Acrobat) - C:\Users\Home\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-01-14]
CHR Extension: (Fir Twig) - C:\Users\Home\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbjcjkpdjikhpbkmckjbjajkbighogal [2016-12-03]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Home\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-08-24]
CHR Extension: (Gmail) - C:\Users\Home\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-08-24]
CHR Extension: (Chrome Media Router) - C:\Users\Home\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-14]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2016-10-25] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2016-10-25] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 PAC7311; C:\Windows\system32\DRIVERS\PA707UCM.SYS [524800 2007-03-14] (PixArt Imaging Inc.)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [589824 2015-10-30] (Realtek )
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-01-14 20:27 - 2017-01-14 20:28 - 00010691 _____ C:\Users\Home\Desktop\FRST.txt
2017-01-14 20:26 - 2017-01-14 20:27 - 00000000 ____D C:\FRST
2017-01-14 20:24 - 2017-01-14 20:25 - 02419200 _____ (Farbar) C:\Users\Home\Desktop\FRST64.exe
2017-01-14 18:57 - 2017-01-14 18:57 - 00275332 _____ C:\Windows\Minidump\011417-19984-01.dmp
2017-01-14 16:37 - 2017-01-14 16:38 - 00264828 _____ C:\Windows\Minidump\011417-23500-01.dmp
2017-01-14 00:04 - 2017-01-14 00:04 - 00001273 _____ C:\Users\Home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Office16.lnk
2017-01-13 18:15 - 2017-01-13 18:32 - 00000000 ____D C:\Users\Home\Desktop\slike za oglase
2017-01-13 16:47 - 2017-01-13 16:47 - 00000000 __SHD C:\found.006
2017-01-12 10:00 - 2017-01-12 10:00 - 00000000 ___HD C:\$WINDOWS.~BT
2017-01-11 13:29 - 2017-01-11 13:29 - 00279372 _____ C:\Windows\Minidump\011117-21375-01.dmp
2017-01-08 15:33 - 2017-01-08 15:33 - 00279404 _____ C:\Windows\Minidump\010817-20343-01.dmp
2017-01-07 12:08 - 2017-01-07 12:08 - 00279292 _____ C:\Windows\Minidump\010717-20875-01.dmp
2017-01-06 11:20 - 2017-01-06 11:20 - 00279204 _____ C:\Windows\Minidump\010617-19250-01.dmp
2017-01-05 11:15 - 2017-01-05 11:17 - 92288890 _____ C:\Users\Home\Downloads\Cut_the_Rope_2_presskit.zip
2017-01-04 11:39 - 2017-01-04 11:40 - 00216604 _____ C:\Windows\Minidump\010417-16953-01.dmp
2016-12-30 21:22 - 2016-12-30 21:22 - 00275308 _____ C:\Windows\Minidump\123016-45062-01.dmp
2016-12-30 13:35 - 2016-12-30 13:35 - 00257172 _____ C:\Windows\Minidump\123016-24656-01.dmp
2016-12-30 13:31 - 2016-12-30 13:31 - 00259620 _____ C:\Windows\Minidump\123016-29234-01.dmp
2016-12-30 13:30 - 2016-12-30 13:30 - 00000000 __SHD C:\found.005
2016-12-28 11:36 - 2016-12-28 11:36 - 00279412 _____ C:\Windows\Minidump\122816-15906-01.dmp
2016-12-26 09:52 - 2016-12-26 09:52 - 00000000 __SHD C:\found.004
2016-12-25 13:14 - 2016-12-25 13:14 - 00259068 _____ C:\Windows\Minidump\122516-28796-01.dmp
2016-12-24 12:36 - 2016-12-24 12:36 - 00275204 _____ C:\Windows\Minidump\122416-35890-01.dmp
2016-12-24 12:32 - 2016-12-24 12:33 - 00275332 _____ C:\Windows\Minidump\122416-34093-01.dmp
2016-12-24 12:06 - 2016-12-24 12:07 - 00275268 _____ C:\Windows\Minidump\122416-14218-01.dmp
2016-12-24 12:02 - 2016-12-24 12:02 - 00000000 __SHD C:\found.003
2016-12-21 23:10 - 2016-12-21 23:10 - 00000000 ____D C:\Users\Home\Desktop\MUZIKA
2016-12-21 15:54 - 2016-12-21 15:54 - 00275252 _____ C:\Windows\Minidump\122116-16250-01.dmp
2016-12-20 16:41 - 2016-12-20 16:41 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2016-12-20 13:54 - 2016-12-20 20:54 - 00000090 _____ C:\Users\Home\.boxit.ini
2016-12-18 19:14 - 2016-12-18 19:14 - 00000000 ____D C:\Users\Home\Documents\Rocks'n'Diamonds
2016-12-18 19:14 - 2016-12-18 19:14 - 00000000 ____D C:\ProgramData\Fugazo
2016-12-18 18:22 - 2016-12-24 15:03 - 00000000 ____D C:\Users\Home\Desktop\IGRICE

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-01-14 20:19 - 2016-08-23 13:33 - 00000000 ____D C:\Users\Home\AppData\Local\ClassicShell
2017-01-14 19:58 - 2016-08-30 22:21 - 00000892 _____ C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job
2017-01-14 19:31 - 2016-09-18 07:12 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2017-01-14 19:04 - 2016-06-20 03:10 - 00879220 _____ C:\Windows\system32\PerfStringBackup.INI
2017-01-14 19:04 - 2015-10-30 08:21 - 00000000 ____D C:\Windows\INF
2017-01-14 18:57 - 2016-09-05 16:08 - 00000000 ____D C:\Windows\Minidump
2017-01-14 18:57 - 2016-04-27 07:34 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-01-14 18:56 - 2016-09-05 16:08 - 241698732 _____ C:\Windows\MEMORY.DMP
2017-01-14 18:14 - 2015-10-30 08:11 - 00000000 ____D C:\Windows\CbsTemp
2017-01-14 10:36 - 2015-10-30 08:24 - 00000000 ___HD C:\Program Files\WindowsApps
2017-01-14 10:36 - 2015-10-30 08:24 - 00000000 ____D C:\Windows\AppReadiness
2017-01-14 10:29 - 2016-06-20 03:29 - 00000000 ____D C:\Users\Home
2017-01-14 00:01 - 2016-08-23 13:39 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-01-13 18:04 - 2016-10-16 08:32 - 00000000 ____D C:\Users\Home\Desktop\OGLASI
2017-01-13 13:13 - 2016-06-20 13:01 - 00000000 ____D C:\Windows\Panther
2017-01-13 10:30 - 2016-12-09 17:51 - 00003288 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task v2
2017-01-13 10:30 - 2016-06-20 03:33 - 00002364 _____ C:\Users\Home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-01-13 10:30 - 2016-06-20 03:33 - 00000000 ___RD C:\Users\Home\OneDrive
2017-01-13 00:28 - 2016-08-30 16:20 - 00000000 ___RD C:\Users\Home\Desktop\Nada skola
2017-01-13 00:28 - 2016-08-30 16:20 - 00000000 ___RD C:\Users\Home\Desktop\Nada
2017-01-12 10:32 - 2016-06-20 03:09 - 00000000 ____D C:\Windows\system32\MRT
2017-01-12 10:28 - 2016-06-20 03:09 - 135657872 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-01-11 22:08 - 2016-09-01 20:21 - 00026624 ____H C:\Users\Home\Desktop\photothumb.db
2017-01-11 22:07 - 2016-11-20 14:37 - 00075776 ____H C:\Users\Home\Downloads\photothumb.db
2017-01-11 00:15 - 2016-06-20 03:30 - 00000000 ____D C:\Users\Home\AppData\Local\Packages
2017-01-10 23:02 - 2016-08-23 13:40 - 00004562 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2017-01-10 17:32 - 2016-08-30 22:21 - 00003980 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2017-01-10 17:31 - 2015-10-30 08:24 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-01-10 17:31 - 2015-10-30 08:24 - 00000000 ____D C:\Windows\system32\Macromed
2017-01-03 22:24 - 2016-08-23 13:37 - 00000000 ____D C:\Users\Home\AppData\Roaming\Skype
2017-01-03 00:20 - 2015-10-30 07:28 - 00524288 ___SH C:\Windows\system32\config\BBI
2016-12-30 22:08 - 2015-10-30 07:28 - 00327680 _____ C:\Windows\system32\config\DEFAULT
2016-12-30 22:08 - 2015-10-30 07:28 - 00069632 _____ C:\Windows\system32\config\SAM
2016-12-30 22:08 - 2015-10-30 07:28 - 00028672 _____ C:\Windows\system32\config\SECURITY
2016-12-25 23:42 - 2015-10-30 08:24 - 00000000 ____D C:\Windows\system32\WDI
2016-12-24 15:03 - 2016-11-19 21:15 - 00520192 _____ C:\Users\Home\Desktop\New Microsoft Access Database.accdb
2016-12-23 19:48 - 2015-10-30 07:28 - 00000000 ____D C:\Windows\system32\DriverStore
2016-12-23 17:04 - 2016-08-24 14:22 - 00003970 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1472044958
2016-12-23 17:04 - 2016-08-24 14:22 - 00001120 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2016-12-23 17:04 - 2016-08-24 14:22 - 00000000 ____D C:\Program Files (x86)\Opera
2016-12-22 23:48 - 2015-10-30 08:26 - 00835576 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-12-22 23:48 - 2015-10-30 08:26 - 00177656 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-12-22 17:45 - 2016-12-11 16:14 - 00000000 ____D C:\Users\Home\Desktop\сараа
2016-12-21 17:08 - 2016-06-20 03:29 - 00000000 ___RD C:\Users\Home\Documents
2016-12-20 20:23 - 2016-06-20 03:30 - 00000000 ____D C:\Users\Home\AppData\Local\VirtualStore
2016-12-20 16:41 - 2016-04-27 07:30 - 00026926 _____ C:\Windows\setupact.log
2016-12-20 16:41 - 2015-10-30 08:23 - 00000000 ____D C:\Windows\system32\Drivers\UMDF
2016-12-20 16:41 - 2015-10-30 08:23 - 00000000 ____D C:\Windows\system32\drivers
2016-12-20 13:11 - 2016-08-24 14:02 - 00000000 ___RD C:\Users\Home\Desktop\DAVID
2016-12-18 23:04 - 2015-10-30 07:28 - 00000000 ____D C:\Windows\system32\CatRoot
2016-12-18 19:14 - 2015-10-30 08:24 - 00000000 ___HD C:\ProgramData
2016-12-17 09:53 - 2016-09-03 13:46 - 00003416 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-12-17 09:53 - 2016-09-03 13:46 - 00003292 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2016-12-17 09:53 - 2015-10-30 08:24 - 00000000 ____D C:\Windows\Tasks
2016-12-17 09:53 - 2015-10-30 07:28 - 00000000 ___RD C:\Program Files (x86)
2016-12-17 09:26 - 2016-10-07 16:19 - 00003678 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3962405984-4113580480-2445003737-1002UA
2016-12-17 09:26 - 2016-10-07 16:19 - 00003410 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3962405984-4113580480-2445003737-1002Core

Some files in TEMP:
====================
C:\Users\Home\AppData\Local\Temp\ICReinstall_Microsoft_Office_Picture_Manager_2003_Downloader.exe
C:\Users\Home\AppData\Local\Temp\jre-8u111-windows-au.exe
C:\Users\Home\AppData\Local\Temp\mpegc.dll


==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-01-09 09:40

==================== End of FRST.txt ============================



mycity.rs/must-login.png

offline
  • Research Engineer @MalwareBytes
  • Pridružio: 09 Avg 2011
  • Poruke: 15877
  • Gde živiš: Beograd

Pozdrav,

Problem nije do malware-a, vec najverovatnije do hard diska.

Klikni start i ukucaj Command Prompt. Pokreni kao Administrator, a zatim ukucaj/kopiraj ovu komandu:

chkdsk C: /r

Potvrdi sa Yes i restartuj racunar da se procedura zavrsi.

Kada zavrsi, obavesti me.

offline
  • Pridružio: 04 Avg 2014
  • Poruke: 15

Kada ukucam Command Prompt. ne dobijem opciju da ga pokrenem kao Administrator, ali kopirala sam komandu i pokazao je ovo :


offline
  • Research Engineer @MalwareBytes
  • Pridružio: 09 Avg 2011
  • Poruke: 15877
  • Gde živiš: Beograd

Kada upises Command Prompt, potrebno je da kliknes na ikonicu i izaberes Run as Administrator.

offline
  • Pridružio: 04 Avg 2014
  • Poruke: 15

Završilo je.

offline
  • Research Engineer @MalwareBytes
  • Pridružio: 09 Avg 2011
  • Poruke: 15877
  • Gde živiš: Beograd

Odlicno. Ponovo klikni start i ukucaj powershell.exe

Kopiraj sledecu komandu i potvrdi sa Enter:

get-winevent -FilterHashTable @{logname="Application"; id="1001"}| ?{$_.providername –match "wininit"} | fl timecreated, message | out-file Desktop\CHKDSKResults.txt

Prikaci CHKDSKResults.txt sa radne povrsine.

offline
  • Pridružio: 04 Avg 2014
  • Poruke: 15

Samo ovo se pojavilo,ništa na radnoj površini.

offline
  • Research Engineer @MalwareBytes
  • Pridružio: 09 Avg 2011
  • Poruke: 15877
  • Gde živiš: Beograd

Hajde probaj ovu komandu:

get-winevent -FilterHashTable @{logname="Application"; id="1001"}| ?{$_.providername –match "wininit"} | fl timecreated, message | out-file C:\Users\Home\Desktop\CHKDSKResults.txt

offline
  • Pridružio: 04 Avg 2014
  • Poruke: 15

mycity.rs/must-login.png

offline
  • Research Engineer @MalwareBytes
  • Pridružio: 09 Avg 2011
  • Poruke: 15877
  • Gde živiš: Beograd

Iz nekog razloga Check Disk ne zavrsava operaciju do kraja.

Najbolje ce biti da otvoris temu u Windows forumu kako bi ti drugi clanovi pomogli jer ovo nije problem do malware-a.

http://www.mycity.rs/viewforum.php?f=2

Ko je trenutno na forumu
 

Ukupno su 567 korisnika na forumu :: 32 registrovanih, 5 sakrivenih i 530 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 4channer, A.R.Chafee.Jr., aleksmajstor, Andrija357, Botovac, branko7, BSD, Cirkon, dac, darkangel, djo97, FOX, Ilija Grubor, Joja, kalens021, Kruger, Lord Nem, LUDI, Marko Marković, mean_machine, menges, mercedesamg, Mercury, Mihajlo, Milan A. Nikolic, moldway, Nebo_M, rodoljub, sovanova95, theNedjeljko, wolverined4, xJeremijAx