molim proveru

molim proveru

offline
  • Pridružio: 01 Mar 2008
  • Poruke: 245

Napisano: 10 Nov 2015 22:07

Racunar je katastrofalno spor, programe otvara kad sam vec i zaboravio da sam ga pokrenuo, uopsteno katastrofa.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:07-11-2015
Ran by Milos (administrator) on MILOS-PC (10-11-2015 21:59:45)
Running from C:\Users\Milos\Desktop
Loaded Profiles: Milos (Available Profiles: Milos & DefaultAppPool)
Platform: Windows 10 Pro (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: [Link mogu videti samo ulogovani korisnici]

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Nero AG) C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
(Prolific Technology Inc.) C:\Windows\SysWOW64\IoctlSvc.exe
(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\3.4.0\ToolbarUpdater.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
() C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\3.4.0\loggingserver.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\wscript.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(BitTorrent Inc.) C:\Users\Milos\AppData\Roaming\uTorrent\uTorrent.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
(BitTorrent Inc.) C:\Users\Milos\AppData\Roaming\uTorrent\updates\3.4.5_41202\utorrentie.exe
() C:\Program Files (x86)\AVG Web TuneUp\vprot.exe
(BitTorrent Inc.) C:\Users\Milos\AppData\Roaming\uTorrent\updates\3.4.5_41202\utorrentie.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1026.13580.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
() C:\Program Files\WindowsApps\Microsoft.BingFinance_4.7.104.0_x86__8wekyb3d8bbwe\Microsoft.Msn.Money.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsAlarms_10.1511.59020.0_x64__8wekyb3d8bbwe\Time.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcfgex.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_19_0_0_245.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_19_0_0_245.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10240.16464_none_116100d161f6ab1d\TiWorker.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-06-24] (Realtek Semiconductor)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-08-21] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5212072 2015-07-29] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [vProt] => C:\Program Files (x86)\AVG Web TuneUp\vprot.exe [2531216 2015-08-19] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-06-08] (Oracle Corporation)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [36711472 2015-10-13] (Dropbox, Inc.)
HKU\S-1-5-21-1212074998-603920895-1076839072-1000\...\Run: [uTorrent] => C:\Users\Milos\AppData\Roaming\uTorrent\uTorrent.exe [1822048 2015-10-14] (BitTorrent Inc.)
HKU\S-1-5-21-1212074998-603920895-1076839072-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-1212074998-603920895-1076839072-1000\...\RunOnce: [Uninstall C:\Users\Milos\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Milos\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64"
HKU\S-1-5-21-1212074998-603920895-1076839072-1000\...\RunOnce: [Uninstall C:\Users\Milos\AppData\Local\Microsoft\OneDrive\17.3.5951.0827] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Milos\AppData\Local\Microsoft\OneDrive\17.3.5951.0827"
HKU\S-1-5-21-1212074998-603920895-1076839072-1000\...\MountPoints2: {65e305ac-2719-11e4-880c-8c89a532fdcd} - "I:\setup.exe"
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-10-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-10-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-10-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-10-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-10-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-10-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-10-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-10-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Milos\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64\FileSyncShell64.dll [2015-11-10] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Milos\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64\FileSyncShell64.dll [2015-11-10] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Milos\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64\FileSyncShell64.dll [2015-11-10] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-10-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-10-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-10-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-10-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-10-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-10-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-10-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-10-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Milos\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\FileSyncShell.dll [2015-11-10] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Milos\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\FileSyncShell.dll [2015-11-10] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Milos\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\FileSyncShell.dll [2015-11-10] (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{7a378843-6a76-409f-9bf0-79c8e0685f5c}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{d1a9a106-9c50-4725-995b-dea6d31d4091}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{e4b9b920-2728-48df-9ad8-d1d3cc48b708}: [DhcpNameServer] 192.168.42.129

Internet Explorer:
==================
HKU\S-1-5-21-1212074998-603920895-1076839072-1000\Software\Microsoft\Internet Explorer\Main,Start Page = [Link mogu videti samo ulogovani korisnici]
HKU\S-1-5-21-1212074998-603920895-1076839072-1000\Software\Microsoft\Internet Explorer\Main,First Home Page = [Link mogu videti samo ulogovani korisnici]
URLSearchHook: HKLM-x32 - IQmango Toolbar - {bf5e07d7-3adb-41d8-a379-be976a83fe60} - C:\Users\Milos\AppData\LocalLow\IQmango\prxtbIQm0.dll No File
URLSearchHook: HKU\S-1-5-21-1212074998-603920895-1076839072-1000 - IQmango Toolbar - {bf5e07d7-3adb-41d8-a379-be976a83fe60} - C:\Users\Milos\AppData\LocalLow\IQmango\prxtbIQm0.dll No File
SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}
SearchScopes: HKLM-x32 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}
SearchScopes: HKU\S-1-5-21-1212074998-603920895-1076839072-1000 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}
SearchScopes: HKU\S-1-5-21-1212074998-603920895-1076839072-1000 -> {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL =
SearchScopes: HKU\S-1-5-21-1212074998-603920895-1076839072-1000 -> {E079D741-1FE4-4815-A527-F340D73743B0} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}&SearchSource=4&ctid=CT3274395&CUI=UN14722046522064527&UM=4
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\ssv.dll [2015-07-30] (Oracle Corporation)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)
BHO-x32: IQmango Toolbar -> {bf5e07d7-3adb-41d8-a379-be976a83fe60} -> C:\Users\Milos\AppData\LocalLow\IQmango\prxtbIQm0.dll => No File
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-07-30] (Oracle Corporation)
Toolbar: HKLM-x32 - IQmango Toolbar - {bf5e07d7-3adb-41d8-a379-be976a83fe60} - C:\Users\Milos\AppData\LocalLow\IQmango\prxtbIQm0.dll No File
Toolbar: HKU\S-1-5-21-1212074998-603920895-1076839072-1000 -> No Name - {BF5E07D7-3ADB-41D8-A379-BE976A83FE60} - No File
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\3.4.0\ViProtocol.dll [2015-08-19] (AVG Secure Search)

FireFox:
========
FF ProfilePath: C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default
FF SearchEngineOrder.1: default-search.net
FF SelectedSearchEngine: AVG Secure Search
FF Homepage: [Link mogu videti samo ulogovani korisnici]
FF Keyword.URL: [Link mogu videti samo ulogovani korisnici]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_19_0_0_245.dll [2015-11-10] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-11-10] ()
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\3.4.0\\npsitesafety.dll [No File]
FF Plugin-x32: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-07-30] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-07-30] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-09-27] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFF12.DLL [2006-10-26] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-09-27] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll [2011-10-26] (Nullsoft, Inc.)
FF SearchPlugin: C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default\searchplugins\-youtube--.xml [2015-03-02]
FF SearchPlugin: C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default\searchplugins\avg-secure-search.xml [2015-08-27]
FF SearchPlugin: C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default\searchplugins\default-search.xml [2014-10-05]
FF SearchPlugin: C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default\searchplugins\firefox-add-ons.xml [2015-03-02]
FF SearchPlugin: C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default\searchplugins\google-default.xml [2015-03-02]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\default-search.xml [2014-10-05]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wtu-secure-search.xml [2015-08-19]
FF Extension: AVG Web TuneUp - C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default\Extensions\avg@toolbar [2015-11-10] [not signed]
FF Extension: Sites - C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default\Extensions\{121761af-0fa5-4896-a2a8-cfdbac4e4982} [2014-10-27] [not signed]
FF Extension: IQmango - C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default\Extensions\{bf5e07d7-3adb-41d8-a379-be976a83fe60} [2015-07-15] [not signed]
FF Extension: Adblock Plus - C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-09-26]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-10-08]

Chrome:
=======
CHR NewTab: Default -> "chrome-extension://nafaimnnclfjfedmmabolbppcngeolgf/newtab/newtab-hp.html"
CHR DefaultSearchURL: Default -> [Link mogu videti samo ulogovani korisnici]{searchTerms}
CHR DefaultSearchKeyword: Default -> Ask Search
CHR DefaultSuggestURL: Default -> [Link mogu videti samo ulogovani korisnici]{searchTerms}
CHR Profile: C:\Users\Milos\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google презентације) - C:\Users\Milos\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-05-19]
CHR Extension: (Google документи) - C:\Users\Milos\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-05-19]
CHR Extension: (Google диск) - C:\Users\Milos\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-08-19]
CHR Extension: (YouTube) - C:\Users\Milos\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-05-19]
CHR Extension: (Google Search) - C:\Users\Milos\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-05-19]
CHR Extension: (Google табеле) - C:\Users\Milos\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-05-19]
CHR Extension: (Google документи офлајн) - C:\Users\Milos\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-05]
CHR Extension: (Ask Search) - C:\Users\Milos\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl [2015-06-08]
CHR Extension: (iLivid) - C:\Users\Milos\AppData\Local\Google\Chrome\User Data\Default\Extensions\nafaimnnclfjfedmmabolbppcngeolgf [2015-06-08]
CHR Extension: (Плаћања у Chrome веб-продавници) - C:\Users\Milos\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-19]
CHR Extension: (Gmail) - C:\Users\Milos\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-19]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2015-07-15] (Advanced Micro Devices, Inc.) [File not signed]
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3259304 2015-07-29] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [301896 2015-07-29] (AVG Technologies CZ, s.r.o.)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2015-10-12] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2015-10-12] (Microsoft Corporation)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048 2015-09-18] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048 2015-09-18] (Dropbox, Inc.)
S3 GSService; C:\Windows\SysWOW64\GSService.exe [444640 2014-07-28] ()
R2 MSMQ; C:\Windows\system32\mqsvc.exe [26112 2015-07-31] (Microsoft Corporation)
R2 Nero BackItUp Scheduler 3; C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe [877864 2008-06-08] (Nero AG)
S3 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [537896 2008-06-24] (Nero AG)
R2 PLFlash DeviceIoControl Service; C:\Windows\SysWOW64\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed]
R2 vToolbarUpdater3.4.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\3.4.0\ToolbarUpdater.exe [1830800 2015-08-19] (AVG Secure Search)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [84480 2015-07-31] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [578560 2015-07-31] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWT6.sys [102912 2015-05-28] (Advanced Micro Devices)
S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [20496 2013-09-04] (AVG Technologies CZ, s.r.o.)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [152344 2014-06-30] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [244504 2014-07-21] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [237536 2015-05-26] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [237848 2014-10-24] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [369120 2015-05-26] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [211936 2015-05-26] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [287208 2015-05-27] (AVG Technologies CZ, s.r.o.)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-08-18] (Disc Soft Ltd)
R1 F06DEFF2-5B9C-490D-910F-35D3A9119622; C:\Program Files (x86)\Settings Manager\smdmf\x64\smdmfmgrc2.cfg [41872 2014-08-31] (Aztec Media Inc)
R1 MpKsl2e9c15b5; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8D123606-C2D4-43A9-8B70-980A576278A9}\MpKsl2e9c15b5.sys [44928 2015-10-28] (Microsoft Corporation)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [175104 2015-07-31] (Microsoft Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [587264 2015-07-10] (Realtek )
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
U3 idsvc; no ImagePath
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
U3 wpcsvc; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-11-10 21:59 - 2015-11-10 22:01 - 00025759 _____ C:\Users\Milos\Desktop\FRST.txt
2015-11-10 21:59 - 2015-11-10 21:59 - 00000000 ____D C:\FRST
2015-11-10 21:56 - 2015-11-10 21:58 - 02198528 _____ (Farbar) C:\Users\Milos\Desktop\FRST64.exe
2015-11-10 21:46 - 2015-11-10 21:46 - 00016148 _____ C:\WINDOWS\system32\MILOS-PC_Milos_HistoryPrediction.bin
2015-10-28 11:25 - 2015-10-28 11:25 - 00279600 _____ C:\WINDOWS\Minidump\102815-42078-01.dmp
2015-10-28 11:12 - 2015-11-10 21:03 - 00000000 ____D C:\Users\Milos\AppData\LocalLow\uTorrent
2015-10-28 02:21 - 2015-10-28 02:21 - 00003046 _____ C:\WINDOWS\System32\Tasks\1015avUpdateInfo
2015-10-28 02:21 - 2015-10-28 02:21 - 00000000 ____D C:\ProgramData\Avg_Update_1015av
2015-10-24 01:10 - 2010-06-02 03:55 - 00239960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_7.dll
2015-10-24 01:10 - 2010-06-02 03:55 - 00176984 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_7.dll
2015-10-24 01:10 - 2010-05-26 10:41 - 01907552 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_43.dll
2015-10-24 01:10 - 2010-05-26 10:41 - 01868128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dcsx_43.dll
2015-10-24 01:10 - 2010-05-26 10:41 - 00511328 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_43.dll
2015-10-24 01:10 - 2010-02-04 09:01 - 00530776 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_6.dll
2015-10-24 01:10 - 2010-02-04 09:01 - 00528216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_6.dll
2015-10-24 01:10 - 2010-02-04 09:01 - 00238936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_6.dll
2015-10-24 01:10 - 2010-02-04 09:01 - 00176984 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_6.dll
2015-10-24 01:10 - 2010-02-04 09:01 - 00078680 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_4.dll
2015-10-24 01:10 - 2010-02-04 09:01 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_4.dll
2015-10-24 01:10 - 2009-09-04 16:44 - 00517960 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_5.dll
2015-10-24 01:10 - 2009-09-04 16:44 - 00515416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_5.dll
2015-10-24 01:10 - 2009-09-04 16:44 - 00238936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_5.dll
2015-10-24 01:10 - 2009-09-04 16:44 - 00176968 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_5.dll
2015-10-24 01:10 - 2009-09-04 16:44 - 00073544 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_3.dll
2015-10-24 01:10 - 2009-09-04 16:44 - 00069464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_3.dll
2015-10-24 01:10 - 2009-09-04 16:29 - 05554512 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_42.dll
2015-10-24 01:10 - 2009-09-04 16:29 - 05501792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dcsx_42.dll
2015-10-24 01:10 - 2009-09-04 16:29 - 02582888 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_42.dll
2015-10-24 01:10 - 2009-09-04 16:29 - 02475352 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_42.dll
2015-10-24 01:10 - 2009-09-04 16:29 - 00285024 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_42.dll
2015-10-24 01:10 - 2009-03-16 13:18 - 00521560 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_4.dll
2015-10-24 01:10 - 2009-03-16 13:18 - 00517448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_4.dll
2015-10-24 01:10 - 2009-03-16 13:18 - 00235352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_4.dll
2015-10-24 01:10 - 2009-03-16 13:18 - 00174936 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_4.dll
2015-10-24 01:10 - 2009-03-16 13:18 - 00024920 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_6.dll
2015-10-24 01:10 - 2009-03-16 13:18 - 00022360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_6.dll
2015-10-24 01:10 - 2009-03-09 14:27 - 05425496 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_41.dll
2015-10-24 01:10 - 2009-03-09 14:27 - 04178264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_41.dll
2015-10-24 01:10 - 2009-03-09 14:27 - 02430312 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_41.dll
2015-10-24 01:10 - 2009-03-09 14:27 - 00520544 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_41.dll
2015-10-24 01:10 - 2008-10-27 09:04 - 00235856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_3.dll
2015-10-24 01:10 - 2008-10-27 09:04 - 00175440 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_3.dll
2015-10-24 01:10 - 2008-10-10 03:52 - 02605920 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_40.dll
2015-10-24 01:10 - 2008-10-10 03:52 - 02036576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_40.dll
2015-10-24 01:10 - 2008-10-10 03:52 - 00519000 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_40.dll
2015-10-24 01:10 - 2008-10-10 03:52 - 00452440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_40.dll
2015-10-24 01:10 - 2008-07-31 09:41 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_2.dll
2015-10-24 01:10 - 2008-07-31 09:41 - 00177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_2.dll
2015-10-24 01:10 - 2008-07-31 09:41 - 00072200 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_1.dll
2015-10-24 01:10 - 2008-07-31 09:41 - 00068616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_1.dll
2015-10-24 01:10 - 2008-07-31 09:40 - 00513544 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_2.dll
2015-10-24 01:10 - 2008-07-31 09:40 - 00509448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_2.dll
2015-10-24 01:10 - 2008-07-10 10:01 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_39.dll
2015-10-24 01:10 - 2008-07-10 10:00 - 04992520 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_39.dll
2015-10-24 01:10 - 2008-07-10 10:00 - 03851784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_39.dll
2015-10-24 01:10 - 2008-07-10 10:00 - 01942552 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_39.dll
2015-10-24 01:10 - 2008-07-10 10:00 - 01493528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_39.dll
2015-10-24 01:10 - 2008-07-10 10:00 - 00540688 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_39.dll
2015-10-24 01:10 - 2008-05-30 13:19 - 00511496 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_1.dll
2015-10-24 01:10 - 2008-05-30 13:19 - 00507400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_1.dll
2015-10-24 01:10 - 2008-05-30 13:18 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_1.dll
2015-10-24 01:10 - 2008-05-30 13:18 - 00177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_1.dll
2015-10-24 01:10 - 2008-05-30 13:17 - 00068104 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_0.dll
2015-10-24 01:10 - 2008-05-30 13:17 - 00065032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_0.dll
2015-10-24 01:10 - 2008-05-30 13:17 - 00025608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_4.dll
2015-10-24 01:10 - 2008-05-30 13:16 - 00028168 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_4.dll
2015-10-24 01:10 - 2008-05-30 13:11 - 04991496 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_38.dll
2015-10-24 01:10 - 2008-05-30 13:11 - 03850760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_38.dll
2015-10-24 01:10 - 2008-05-30 13:11 - 01941528 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_38.dll
2015-10-24 01:10 - 2008-05-30 13:11 - 01491992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_38.dll
2015-10-24 01:10 - 2008-05-30 13:11 - 00540688 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_38.dll
2015-10-24 01:10 - 2008-05-30 13:11 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_38.dll
2015-10-24 01:10 - 2008-03-05 15:04 - 00489480 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_0.dll
2015-10-24 01:10 - 2008-03-05 15:03 - 00479752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_0.dll
2015-10-24 01:10 - 2008-03-05 15:03 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_0.dll
2015-10-24 01:10 - 2008-03-05 15:03 - 00177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_0.dll
2015-10-24 01:10 - 2008-03-05 15:00 - 00028168 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_3.dll
2015-10-24 01:10 - 2008-03-05 15:00 - 00025608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_3.dll
2015-10-24 01:10 - 2008-03-05 14:56 - 04910088 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_37.dll
2015-10-24 01:10 - 2008-03-05 14:56 - 03786760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_37.dll
2015-10-24 01:10 - 2008-03-05 14:56 - 01860120 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_37.dll
2015-10-24 01:10 - 2008-03-05 14:56 - 01420824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_37.dll
2015-10-24 01:10 - 2008-02-05 22:07 - 00529424 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_37.dll
2015-10-24 01:10 - 2008-02-05 22:07 - 00462864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_37.dll
2015-10-24 01:10 - 2007-10-22 02:40 - 00411656 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_10.dll
2015-10-24 01:10 - 2007-10-22 02:39 - 00267272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_10.dll
2015-10-24 01:10 - 2007-10-22 02:37 - 00021000 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_2.dll
2015-10-24 01:10 - 2007-10-22 02:37 - 00017928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_2.dll
2015-10-24 01:10 - 2007-10-12 14:14 - 05081608 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_36.dll
2015-10-24 01:10 - 2007-10-12 14:14 - 03734536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_36.dll
2015-10-24 01:10 - 2007-10-12 14:14 - 02006552 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_36.dll
2015-10-24 01:10 - 2007-10-12 14:14 - 01374232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_36.dll
2015-10-24 01:10 - 2007-10-02 08:56 - 00508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_36.dll
2015-10-24 01:10 - 2007-10-02 08:56 - 00444776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_36.dll
2015-10-24 01:10 - 2007-07-19 23:57 - 00411496 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_9.dll
2015-10-24 01:10 - 2007-07-19 23:57 - 00267112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_9.dll
2015-10-24 01:10 - 2007-07-19 17:14 - 05073256 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_35.dll
2015-10-24 01:10 - 2007-07-19 17:14 - 03727720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_35.dll
2015-10-24 01:10 - 2007-07-19 17:14 - 01985904 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_35.dll
2015-10-24 01:10 - 2007-07-19 17:14 - 01358192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_35.dll
2015-10-24 01:10 - 2007-07-19 17:14 - 00508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_35.dll
2015-10-24 01:10 - 2007-07-19 17:14 - 00444776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_35.dll
2015-10-24 01:10 - 2007-06-20 19:49 - 00409960 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_8.dll
2015-10-24 01:10 - 2007-06-20 19:46 - 00266088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_8.dll
2015-10-24 01:10 - 2007-05-16 15:45 - 04496232 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_34.dll
2015-10-24 01:10 - 2007-05-16 15:45 - 03497832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_34.dll
2015-10-24 01:10 - 2007-05-16 15:45 - 01401200 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_34.dll
2015-10-24 01:10 - 2007-05-16 15:45 - 01124720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_34.dll
2015-10-24 01:10 - 2007-05-16 15:45 - 00506728 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_34.dll
2015-10-24 01:10 - 2007-05-16 15:45 - 00443752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_34.dll
2015-10-24 01:10 - 2007-04-04 17:55 - 00403304 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_7.dll
2015-10-24 01:10 - 2007-04-04 17:55 - 00261480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_7.dll
2015-10-24 01:10 - 2007-03-15 15:57 - 00506728 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_33.dll
2015-10-24 01:10 - 2007-03-15 15:57 - 00443752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_33.dll
2015-10-24 01:10 - 2007-03-12 15:42 - 04494184 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_33.dll
2015-10-24 01:10 - 2007-03-12 15:42 - 03495784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_33.dll
2015-10-24 01:10 - 2007-03-12 15:42 - 01400176 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_33.dll
2015-10-24 01:10 - 2007-03-12 15:42 - 01123696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_33.dll
2015-10-24 01:10 - 2007-03-05 11:42 - 00017688 _____ (Microsoft Corporation) C:\WINDOWS\system32\x3daudio1_1.dll
2015-10-24 01:10 - 2007-03-05 11:42 - 00015128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\x3daudio1_1.dll
2015-10-24 01:10 - 2007-01-24 14:27 - 00393576 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_6.dll
2015-10-24 01:10 - 2007-01-24 14:27 - 00255848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_6.dll
2015-10-24 01:08 - 2015-10-24 01:10 - 00000000 ____D C:\WINDOWS\SysWOW64\directx
2015-10-24 01:08 - 2010-02-04 09:01 - 00024920 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_7.dll
2015-10-24 01:08 - 2010-02-04 09:01 - 00022360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_7.dll
2015-10-24 00:56 - 2015-07-05 11:08 - 00300704 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2015-10-24 00:43 - 2015-10-24 01:13 - 00001085 _____ C:\Users\Public\Desktop\Mortal Kombat Complete Edition.lnk
2015-10-24 00:43 - 2015-10-24 00:43 - 00001068 _____ C:\Users\Public\Desktop\Cat-A-Cat Games.lnk
2015-10-24 00:43 - 2015-10-24 00:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mortal Kombat Complete Edition
2015-10-21 04:19 - 2015-10-21 04:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-10-20 00:36 - 2015-10-28 11:25 - 535092402 _____ C:\WINDOWS\MEMORY.DMP
2015-10-20 00:36 - 2015-10-28 11:25 - 00000000 ____D C:\WINDOWS\Minidump
2015-10-20 00:36 - 2015-10-20 00:37 - 00279432 _____ C:\WINDOWS\Minidump\102015-111515-01.dmp
2015-10-18 22:14 - 2015-10-18 22:16 - 00000000 ____D C:\Users\Milos\Desktop\CD3
2015-10-18 21:53 - 2015-10-18 22:02 - 00000000 ____D C:\Users\Milos\Desktop\CD2
2015-10-18 21:49 - 2015-10-20 00:36 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-10-18 21:19 - 2015-10-18 21:40 - 00000000 ____D C:\Users\Milos\Desktop\CD1
2015-10-14 03:37 - 2015-09-25 04:17 - 24595456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-10-14 03:36 - 2015-10-10 08:12 - 00078528 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-10-14 03:36 - 2015-10-10 07:40 - 21875712 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-10-14 03:36 - 2015-10-10 07:07 - 18806272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-10-14 03:36 - 2015-10-06 04:03 - 16708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-10-14 03:36 - 2015-10-06 03:46 - 13027840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2015-10-14 03:36 - 2015-10-01 05:01 - 01294352 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2015-10-14 03:36 - 2015-10-01 05:01 - 01123400 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2015-10-14 03:36 - 2015-10-01 05:01 - 01018568 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2015-10-14 03:36 - 2015-10-01 05:01 - 00858408 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2015-10-14 03:36 - 2015-10-01 05:00 - 08020320 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-10-14 03:36 - 2015-10-01 04:03 - 00757760 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2015-10-14 03:36 - 2015-09-25 05:01 - 02573768 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2015-10-14 03:36 - 2015-09-25 05:01 - 00498016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbhub.sys
2015-10-14 03:36 - 2015-09-25 04:56 - 22322624 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-10-14 03:36 - 2015-09-25 04:52 - 00980832 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2015-10-14 03:36 - 2015-09-25 04:33 - 01997336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2015-10-14 03:36 - 2015-09-25 04:26 - 20858360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2015-10-14 03:36 - 2015-09-25 04:11 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccountApis.dll
2015-10-14 03:36 - 2015-09-25 04:11 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneCallHistoryApis.dll
2015-10-14 03:36 - 2015-09-25 04:09 - 12504064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-10-14 03:36 - 2015-09-25 04:07 - 01276416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2015-10-14 03:36 - 2015-09-25 04:04 - 02178560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-10-14 03:36 - 2015-09-25 04:04 - 00826880 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-10-14 03:36 - 2015-09-25 04:04 - 00771072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2015-10-14 03:36 - 2015-09-25 04:03 - 00796160 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2015-10-14 03:36 - 2015-09-25 04:03 - 00576000 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-10-14 03:36 - 2015-09-25 04:02 - 07523840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2015-10-14 03:36 - 2015-09-25 04:02 - 00949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2015-10-14 03:36 - 2015-09-25 04:02 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2015-10-14 03:36 - 2015-09-25 04:02 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2015-10-14 03:36 - 2015-09-25 04:01 - 04792320 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-10-14 03:36 - 2015-09-25 04:01 - 03586560 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-10-14 03:36 - 2015-09-25 04:00 - 01423872 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2015-10-14 03:36 - 2015-09-25 04:00 - 01382400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-10-14 03:36 - 2015-09-25 04:00 - 00856576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2015-10-14 03:36 - 2015-09-25 04:00 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
2015-10-14 03:36 - 2015-09-25 03:59 - 01795072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-10-14 03:36 - 2015-09-25 03:59 - 01205248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2015-10-14 03:36 - 2015-09-25 03:59 - 00720896 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2015-10-14 03:36 - 2015-09-25 03:59 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
2015-10-14 03:36 - 2015-09-25 03:59 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2015-10-14 03:36 - 2015-09-25 03:59 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
2015-10-14 03:36 - 2015-09-25 03:59 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\CallHistoryClient.dll
2015-10-14 03:36 - 2015-09-25 03:58 - 01871360 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2015-10-14 03:36 - 2015-09-25 03:48 - 19325952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-10-14 03:36 - 2015-09-25 03:47 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll
2015-10-14 03:36 - 2015-09-25 03:47 - 00172032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneCallHistoryApis.dll
2015-10-14 03:36 - 2015-09-25 03:38 - 03580416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-10-14 03:36 - 2015-09-25 03:38 - 00650240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-10-14 03:36 - 2015-09-25 03:38 - 00574464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2015-10-14 03:36 - 2015-09-25 03:38 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-10-14 03:36 - 2015-09-25 03:37 - 00766976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2015-10-14 03:36 - 2015-09-25 03:37 - 00613376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2015-10-14 03:36 - 2015-09-25 03:37 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2015-10-14 03:36 - 2015-09-25 03:36 - 11262976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-10-14 03:36 - 2015-09-25 03:36 - 05454848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2015-10-14 03:36 - 2015-09-25 03:34 - 00928256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2015-10-14 03:36 - 2015-09-25 03:34 - 00625152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
2015-10-14 03:36 - 2015-09-25 03:34 - 00579584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll
2015-10-14 03:36 - 2015-09-25 03:34 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll
2015-10-14 03:36 - 2015-09-25 03:34 - 00525312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll
2015-10-14 03:36 - 2015-09-25 03:33 - 00131072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CallHistoryClient.dll
2015-10-14 03:36 - 2015-09-25 03:32 - 01594368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2015-10-14 03:36 - 2015-09-25 03:32 - 00466432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-11-10 22:01 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\sru
2015-11-10 22:01 - 2014-08-18 22:57 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-11-10 22:00 - 2015-07-10 11:55 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-11-10 21:59 - 2014-08-18 22:44 - 00000000 ____D C:\Users\Milos\AppData\Roaming\uTorrent
2015-11-10 21:51 - 2014-08-18 23:04 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-11-10 21:26 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-11-10 21:18 - 2015-01-23 00:09 - 00000924 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-11-10 21:17 - 2015-09-18 23:12 - 00000924 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job
2015-11-10 21:17 - 2014-12-25 18:01 - 00003972 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2015-11-10 21:07 - 2015-09-20 02:31 - 00004152 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{9FFD29D8-F297-4798-9857-7BDD21DD8B29}
2015-11-10 21:05 - 2015-07-10 10:05 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2015-11-10 21:05 - 2014-08-18 21:43 - 00000000 ____D C:\ProgramData\MFAData
2015-11-10 21:04 - 2015-07-30 15:22 - 00002372 _____ C:\Users\Milos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-11-10 21:04 - 2015-01-23 00:09 - 00000920 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-11-10 21:04 - 2014-10-04 15:42 - 00000000 ___RD C:\Users\Milos\OneDrive
2015-11-10 21:03 - 2015-09-18 23:12 - 00000920 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job
2015-11-10 21:03 - 2015-07-10 13:22 - 00000275 _____ C:\WINDOWS\WindowsUpdate.log
2015-11-03 19:20 - 2015-10-05 06:54 - 00810488 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-11-03 19:20 - 2015-10-05 06:54 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-10-28 11:41 - 2014-08-28 11:19 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-10-28 11:36 - 2014-08-28 11:19 - 143481208 ____N (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-10-28 11:30 - 2015-07-30 14:55 - 00000000 ____D C:\Users\Milos
2015-10-28 11:29 - 2015-07-30 14:53 - 01005598 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-10-28 11:25 - 2015-07-10 13:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-10-28 11:12 - 2015-07-10 13:20 - 00031176 _____ C:\WINDOWS\setupact.log
2015-10-24 01:10 - 2015-08-29 15:47 - 00061446 _____ C:\WINDOWS\DirectX.log
2015-10-24 01:00 - 2014-10-22 12:40 - 00000000 ____D C:\Users\Milos\AppData\Local\Adobe
2015-10-24 00:23 - 2015-07-10 10:05 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-10-23 22:15 - 2015-07-30 14:48 - 00005208 _____ C:\WINDOWS\PFRO.log
2015-10-22 23:03 - 2015-09-12 03:23 - 00000000 ____D C:\Users\Milos\AppData\Local\Popcorn-Time
2015-10-21 04:19 - 2015-09-18 23:12 - 00000000 ____D C:\Program Files (x86)\Dropbox
2015-10-20 00:37 - 2014-10-16 23:33 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-10-20 00:36 - 2014-08-18 22:35 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-10-14 15:45 - 2015-10-04 14:21 - 512804855 _____ () C:\Users\Milos\Downloads\qpes2015_licence_patch_dlc4.exe
2015-10-14 14:51 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-10-14 03:36 - 2014-12-22 03:34 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk

==================== Files in the root of some directories =======

2014-11-12 19:21 - 2014-11-12 19:21 - 0000017 _____ () C:\Users\Milos\AppData\Local\resmon.resmoncfg
2015-07-30 14:50 - 2015-07-30 14:50 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Some files in TEMP:
====================
C:\Users\Milos\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpsn7v2u.dll
C:\Users\Milos\AppData\Local\Temp\jre-8u51-windows-au.exe
C:\Users\Milos\AppData\Local\Temp\tmp14C6.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-11-10 21:28

==================== End of FRST.txt ============================

Dopuna: 10 Nov 2015 22:10

zaboravih fajl
[Link mogu videti samo ulogovani korisnici]



offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Arrow Korak 1

Idi u Start -> Control Panel -> Programs and Features i deinstaliraj sljedeće programe. Ako neki odbije deinstalaciju preskoči ga i pređi na sljedeći.

AVG Web TuneUp
IQmango 3D Player 4.5.4
IQmango Toolbar for IE
Settings Manager



Arrow Korak 2

Otvori Notepad i iskopiraj sljedeći tekst koji se nalazi unutar Kod polja.

URLSearchHook: HKLM-x32 - IQmango Toolbar - {bf5e07d7-3adb-41d8-a379-be976a83fe60} - C:\Users\Milos\AppData\LocalLow\IQmango\prxtbIQm0.dll No File
URLSearchHook: HKU\S-1-5-21-1212074998-603920895-1076839072-1000 - IQmango Toolbar - {bf5e07d7-3adb-41d8-a379-be976a83fe60} - C:\Users\Milos\AppData\LocalLow\IQmango\prxtbIQm0.dll No File
SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = hxxp://www.default-search.net/search?sid=476&aid=107&itype=n&ver=13892&tm=491&src=ds&p={searchTerms}
SearchScopes: HKLM-x32 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = hxxp://www.default-search.net/search?sid=476&aid=107&itype=n&ver=13892&tm=491&src=ds&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1212074998-603920895-1076839072-1000 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = hxxp://www.default-search.net/search?sid=476&aid=107&itype=n&ver=13892&tm=491&src=ds&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1212074998-603920895-1076839072-1000 -> {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL =
SearchScopes: HKU\S-1-5-21-1212074998-603920895-1076839072-1000 -> {E079D741-1FE4-4815-A527-F340D73743B0} URL = hxxp://trovi.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3274395&CUI=UN14722046522064527&UM=4
BHO-x32: IQmango Toolbar -> {bf5e07d7-3adb-41d8-a379-be976a83fe60} -> C:\Users\Milos\AppData\LocalLow\IQmango\prxtbIQm0.dll => No File
Toolbar: HKLM-x32 - IQmango Toolbar - {bf5e07d7-3adb-41d8-a379-be976a83fe60} - C:\Users\Milos\AppData\LocalLow\IQmango\prxtbIQm0.dll No File
Toolbar: HKU\S-1-5-21-1212074998-603920895-1076839072-1000 -> No Name - {BF5E07D7-3ADB-41D8-A379-BE976A83FE60} - No File
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\3.4.0\ViProtocol.dll [2015-08-19] (AVG Secure Search)
FF SearchEngineOrder.1: default-search.net
FF SelectedSearchEngine: AVG Secure Search
FF Keyword.URL: hxxp://www.default-search.net/search?sid=476&aid=107&itype=n&ver=13892&tm=491&src=ds&p=
FF SearchPlugin: C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default\searchplugins\-youtube--.xml [2015-03-02]
FF SearchPlugin: C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default\searchplugins\avg-secure-search.xml [2015-08-27]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\default-search.xml [2014-10-05]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wtu-secure-search.xml [2015-08-19]
FF Extension: AVG Web TuneUp - C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default\Extensions\avg@toolbar [2015-11-10] [not signed]
FF Extension: Sites - C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default\Extensions\{121761af-0fa5-4896-a2a8-cfdbac4e4982} [2014-10-27] [not signed]
FF Extension: IQmango - C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default\Extensions\{bf5e07d7-3adb-41d8-a379-be976a83fe60} [2015-07-15] [not signed]
CHR NewTab: Default -> "chrome-extension://nafaimnnclfjfedmmabolbppcngeolgf/newtab/newtab-hp.html"
CHR DefaultSearchURL: Default -> hxxp://dts.search.ask.com/web?q={searchTerms}
CHR DefaultSearchKeyword: Default -> Ask Search
CHR DefaultSuggestURL: Default -> hxxp://ssmsp.ask.com/query?sstype=prefix&li=ff&q={searchTerms}
CHR Extension: (Ask Search) - C:\Users\Milos\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl [2015-06-08]
CHR Extension: (iLivid) - C:\Users\Milos\AppData\Local\Google\Chrome\User Data\Default\Extensions\nafaimnnclfjfedmmabolbppcngeolgf [2015-06-08]
R2 vToolbarUpdater3.4.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\3.4.0\ToolbarUpdater.exe [1830800 2015-08-19] (AVG Secure Search)
R1 F06DEFF2-5B9C-490D-910F-35D3A9119622; C:\Program Files (x86)\Settings Manager\smdmf\x64\smdmfmgrc2.cfg [41872 2014-08-31] (Aztec Media Inc)
Task: {9BEC35C2-1E93-46F8-A128-E846EE640667} - System32\Tasks\1015avUpdateInfo => C:\ProgramData\Avg_Update_1015av\1015av_AVG-Secure-Search-Update.exe [2015-10-11] ()
Task: {E787AF98-FB1E-4C0A-9F88-509973116904} - System32\Tasks\Origin => C:\Users\Milos\AppData\Roaming\Origin\update.vbe <==== ATTENTION
Task: {F3F5FA22-C287-4895-810C-DD3E07F1647B} - System32\Tasks\0614tUpdateInfo => C:\ProgramData\Avg_Update_0614t\0614t_AVG-Secure-Search-Update.exe [2014-07-03] ()
Task: C:\WINDOWS\Tasks\0614tUpdateInfo.job => C:\ProgramData\Avg_Update_0614t\0614t_AVG-Secure-Search-Update.exe
C:\Users\Milos\AppData\LocalLow\IQmango
C:\Program Files (x86)\Common Files\AVG Secure Search
C:\Program Files (x86)\Settings Manager
C:\ProgramData\Avg_Update_1015a
C:\Users\Milos\AppData\Roaming\Origin\update.vbe
C:\ProgramData\Avg_Update_0614t
EmptyTemp:


U okviru Notepad-a klikni na File --> Save As
Fajl nazovi Fixlist i sačuvaj na Desktop
Dvoklikom ponovo pokreni FRST.exe
Klikni na Fix i sačekaj dok program ne završi.
Ukoliko program zatraži restart računara, omogući mu da to nesmetano obavi.
Nakon završetka rada, otvoriće se fixlog.txt, sa sadržajem koji treba da kopiraš u temu.
Takođe, na Desktop-u će se nalaziti (fixlog.txt).




Arrow Korak 3

Preuzmi "Xplode"-ov AdwCleaner i sačuvaj ga na Desktop
Dvoklikom pokreni program.
U EULA prozoru klikni na I agree.
Klikni na dugme Scan i sačekaj da se završi skeniranje.
Klikni na dugme Cleaning i pričekaj da program završi.
Program će zatvoriti sve aktivne programe i izbaciti prozor sa tim upozorenjem. Klikni OK kao potvrdu.
Na sljedeća dva prozora koja se otvore (Informations i Restart required ) klikni OK

Računar će se restartovati, a potom otvoriti Notepad (C:\Adwcleaner\AdwCleaner[C1].txt) sa izvještajem.
Sačuvaj taj izvještaj na Desktop i okači ga uz poruku koristeći opciju "Prikači fajl"



offline
  • Pridružio: 01 Mar 2008
  • Poruke: 245

Napisano: 11 Nov 2015 22:52

Fix result of Farbar Recovery Scan Tool (x64) Version:07-11-2015
Ran by Milos (2015-11-11 22:44:45) Run:1
Running from C:\Users\Milos\Desktop
Loaded Profiles: Milos (Available Profiles: Milos & DefaultAppPool)
Boot Mode: Normal
==============================================

fixlist content:
*****************
URLSearchHook: HKLM-x32 - IQmango Toolbar - {bf5e07d7-3adb-41d8-a379-be976a83fe60} - C:\Users\Milos\AppData\LocalLow\IQmango\prxtbIQm0.dll No File
URLSearchHook: HKU\S-1-5-21-1212074998-603920895-1076839072-1000 - IQmango Toolbar - {bf5e07d7-3adb-41d8-a379-be976a83fe60} - C:\Users\Milos\AppData\LocalLow\IQmango\prxtbIQm0.dll No File
SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}
SearchScopes: HKLM-x32 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}
SearchScopes: HKU\S-1-5-21-1212074998-603920895-1076839072-1000 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}
SearchScopes: HKU\S-1-5-21-1212074998-603920895-1076839072-1000 -> {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL =
SearchScopes: HKU\S-1-5-21-1212074998-603920895-1076839072-1000 -> {E079D741-1FE4-4815-A527-F340D73743B0} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}&SearchSource=4&ctid=CT3274395&CUI=UN14722046522064527&UM=4
BHO-x32: IQmango Toolbar -> {bf5e07d7-3adb-41d8-a379-be976a83fe60} -> C:\Users\Milos\AppData\LocalLow\IQmango\prxtbIQm0.dll => No File
Toolbar: HKLM-x32 - IQmango Toolbar - {bf5e07d7-3adb-41d8-a379-be976a83fe60} - C:\Users\Milos\AppData\LocalLow\IQmango\prxtbIQm0.dll No File
Toolbar: HKU\S-1-5-21-1212074998-603920895-1076839072-1000 -> No Name - {BF5E07D7-3ADB-41D8-A379-BE976A83FE60} - No File
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\3.4.0\ViProtocol.dll [2015-08-19] (AVG Secure Search)
FF SearchEngineOrder.1: default-search.net
FF SelectedSearchEngine: AVG Secure Search
FF Keyword.URL: [Link mogu videti samo ulogovani korisnici]
FF SearchPlugin: C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default\searchplugins\-youtube--.xml [2015-03-02]
FF SearchPlugin: C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default\searchplugins\avg-secure-search.xml [2015-08-27]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\default-search.xml [2014-10-05]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wtu-secure-search.xml [2015-08-19]
FF Extension: AVG Web TuneUp - C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default\Extensions\avg@toolbar [2015-11-10] [not signed]
FF Extension: Sites - C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default\Extensions\{121761af-0fa5-4896-a2a8-cfdbac4e4982} [2014-10-27] [not signed]
FF Extension: IQmango - C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default\Extensions\{bf5e07d7-3adb-41d8-a379-be976a83fe60} [2015-07-15] [not signed]
CHR NewTab: Default -> "chrome-extension://nafaimnnclfjfedmmabolbppcngeolgf/newtab/newtab-hp.html"
CHR DefaultSearchURL: Default -> [Link mogu videti samo ulogovani korisnici]{searchTerms}
CHR DefaultSearchKeyword: Default -> Ask Search
CHR DefaultSuggestURL: Default -> [Link mogu videti samo ulogovani korisnici]{searchTerms}
CHR Extension: (Ask Search) - C:\Users\Milos\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl [2015-06-08]
CHR Extension: (iLivid) - C:\Users\Milos\AppData\Local\Google\Chrome\User Data\Default\Extensions\nafaimnnclfjfedmmabolbppcngeolgf [2015-06-08]
R2 vToolbarUpdater3.4.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\3.4.0\ToolbarUpdater.exe [1830800 2015-08-19] (AVG Secure Search)
R1 F06DEFF2-5B9C-490D-910F-35D3A9119622; C:\Program Files (x86)\Settings Manager\smdmf\x64\smdmfmgrc2.cfg [41872 2014-08-31] (Aztec Media Inc)
Task: {9BEC35C2-1E93-46F8-A128-E846EE640667} - System32\Tasks\1015avUpdateInfo => C:\ProgramData\Avg_Update_1015av\1015av_AVG-Secure-Search-Update.exe [2015-10-11] ()
Task: {E787AF98-FB1E-4C0A-9F88-509973116904} - System32\Tasks\Origin => C:\Users\Milos\AppData\Roaming\Origin\update.vbe <==== ATTENTION
Task: {F3F5FA22-C287-4895-810C-DD3E07F1647B} - System32\Tasks\0614tUpdateInfo => C:\ProgramData\Avg_Update_0614t\0614t_AVG-Secure-Search-Update.exe [2014-07-03] ()
Task: C:\WINDOWS\Tasks\0614tUpdateInfo.job => C:\ProgramData\Avg_Update_0614t\0614t_AVG-Secure-Search-Update.exe
C:\Users\Milos\AppData\LocalLow\IQmango
C:\Program Files (x86)\Common Files\AVG Secure Search
C:\Program Files (x86)\Settings Manager
C:\ProgramData\Avg_Update_1015a
C:\Users\Milos\AppData\Roaming\Origin\update.vbe
C:\ProgramData\Avg_Update_0614t
EmptyTemp:
*****************

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\\{bf5e07d7-3adb-41d8-a379-be976a83fe60} => value removed successfully
"HKCR\Wow6432Node\CLSID\{bf5e07d7-3adb-41d8-a379-be976a83fe60}" => key removed successfully
HKU\S-1-5-21-1212074998-603920895-1076839072-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{bf5e07d7-3adb-41d8-a379-be976a83fe60} => value removed successfully
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}" => key removed successfully
HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} => key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}" => key removed successfully
HKCR\Wow6432Node\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} => key not found.
"HKU\S-1-5-21-1212074998-603920895-1076839072-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}" => key removed successfully
HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} => key not found.
"HKU\S-1-5-21-1212074998-603920895-1076839072-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}" => key removed successfully
HKCR\CLSID\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} => key not found.
"HKU\S-1-5-21-1212074998-603920895-1076839072-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E079D741-1FE4-4815-A527-F340D73743B0}" => key removed successfully
HKCR\CLSID\{E079D741-1FE4-4815-A527-F340D73743B0} => key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bf5e07d7-3adb-41d8-a379-be976a83fe60}" => key removed successfully
HKCR\Wow6432Node\CLSID\{bf5e07d7-3adb-41d8-a379-be976a83fe60} => key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{bf5e07d7-3adb-41d8-a379-be976a83fe60} => value removed successfully
HKCR\Wow6432Node\CLSID\{bf5e07d7-3adb-41d8-a379-be976a83fe60} => key not found.
HKU\S-1-5-21-1212074998-603920895-1076839072-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{BF5E07D7-3ADB-41D8-A379-BE976A83FE60} => value removed successfully
HKCR\CLSID\{BF5E07D7-3ADB-41D8-A379-BE976A83FE60} => key not found.
HKCR\Wow6432Node\PROTOCOLS\Handler\viprotocol => key not found.
HKCR\Wow6432Node\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9} => key not found.
Firefox SearchEngineOrder.1 removed successfully
Firefox SelectedSearchEngine removed successfully
Firefox "Keyword.URL" removed successfully
C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default\searchplugins\-youtube--.xml => moved successfully
C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default\searchplugins\avg-secure-search.xml => moved successfully
C:\Program Files (x86)\mozilla firefox\browser\searchplugins\default-search.xml => moved successfully
C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wtu-secure-search.xml => moved successfully
C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default\Extensions\avg@toolbar => not found.
C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default\Extensions\{121761af-0fa5-4896-a2a8-cfdbac4e4982} => moved successfully
C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default\Extensions\{bf5e07d7-3adb-41d8-a379-be976a83fe60} => moved successfully
Chrome NewTab => removed successfully
Chrome DefaultSearchURL => removed successfully
Chrome DefaultSearchKeyword => removed successfully
Chrome DefaultSuggestURL => not found.
C:\Users\Milos\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl => moved successfully
C:\Users\Milos\AppData\Local\Google\Chrome\User Data\Default\Extensions\nafaimnnclfjfedmmabolbppcngeolgf => moved successfully
vToolbarUpdater3.4.0 => service not found.
F06DEFF2-5B9C-490D-910F-35D3A9119622 => Unable to stop service.
F06DEFF2-5B9C-490D-910F-35D3A9119622 => service removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9BEC35C2-1E93-46F8-A128-E846EE640667}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9BEC35C2-1E93-46F8-A128-E846EE640667}" => key removed successfully
C:\WINDOWS\System32\Tasks\1015avUpdateInfo => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\1015avUpdateInfo" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E787AF98-FB1E-4C0A-9F88-509973116904}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E787AF98-FB1E-4C0A-9F88-509973116904}" => key removed successfully
C:\WINDOWS\System32\Tasks\Origin => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Origin" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F3F5FA22-C287-4895-810C-DD3E07F1647B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F3F5FA22-C287-4895-810C-DD3E07F1647B}" => key removed successfully
C:\WINDOWS\System32\Tasks\0614tUpdateInfo => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\0614tUpdateInfo" => key removed successfully
C:\WINDOWS\Tasks\0614tUpdateInfo.job => moved successfully
C:\Users\Milos\AppData\LocalLow\IQmango => moved successfully
"C:\Program Files (x86)\Common Files\AVG Secure Search" => not found.
C:\Program Files (x86)\Settings Manager => moved successfully
"C:\ProgramData\Avg_Update_1015a" => not found.
"C:\Users\Milos\AppData\Roaming\Origin\update.vbe" => not found.
C:\ProgramData\Avg_Update_0614t => moved successfully
EmptyTemp: => 418.3 MB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 22:45:34 ====

Dopuna: 11 Nov 2015 22:59

Fix result of Farbar Recovery Scan Tool (x64) Version:07-11-2015
Ran by Milos (2015-11-11 22:44:45) Run:1
Running from C:\Users\Milos\Desktop
Loaded Profiles: Milos (Available Profiles: Milos & DefaultAppPool)
Boot Mode: Normal
==============================================

fixlist content:
*****************
URLSearchHook: HKLM-x32 - IQmango Toolbar - {bf5e07d7-3adb-41d8-a379-be976a83fe60} - C:\Users\Milos\AppData\LocalLow\IQmango\prxtbIQm0.dll No File
URLSearchHook: HKU\S-1-5-21-1212074998-603920895-1076839072-1000 - IQmango Toolbar - {bf5e07d7-3adb-41d8-a379-be976a83fe60} - C:\Users\Milos\AppData\LocalLow\IQmango\prxtbIQm0.dll No File
SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}
SearchScopes: HKLM-x32 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}
SearchScopes: HKU\S-1-5-21-1212074998-603920895-1076839072-1000 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}
SearchScopes: HKU\S-1-5-21-1212074998-603920895-1076839072-1000 -> {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL =
SearchScopes: HKU\S-1-5-21-1212074998-603920895-1076839072-1000 -> {E079D741-1FE4-4815-A527-F340D73743B0} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}&SearchSource=4&ctid=CT3274395&CUI=UN14722046522064527&UM=4
BHO-x32: IQmango Toolbar -> {bf5e07d7-3adb-41d8-a379-be976a83fe60} -> C:\Users\Milos\AppData\LocalLow\IQmango\prxtbIQm0.dll => No File
Toolbar: HKLM-x32 - IQmango Toolbar - {bf5e07d7-3adb-41d8-a379-be976a83fe60} - C:\Users\Milos\AppData\LocalLow\IQmango\prxtbIQm0.dll No File
Toolbar: HKU\S-1-5-21-1212074998-603920895-1076839072-1000 -> No Name - {BF5E07D7-3ADB-41D8-A379-BE976A83FE60} - No File
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\3.4.0\ViProtocol.dll [2015-08-19] (AVG Secure Search)
FF SearchEngineOrder.1: default-search.net
FF SelectedSearchEngine: AVG Secure Search
FF Keyword.URL: [Link mogu videti samo ulogovani korisnici]
FF SearchPlugin: C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default\searchplugins\-youtube--.xml [2015-03-02]
FF SearchPlugin: C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default\searchplugins\avg-secure-search.xml [2015-08-27]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\default-search.xml [2014-10-05]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wtu-secure-search.xml [2015-08-19]
FF Extension: AVG Web TuneUp - C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default\Extensions\avg@toolbar [2015-11-10] [not signed]
FF Extension: Sites - C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default\Extensions\{121761af-0fa5-4896-a2a8-cfdbac4e4982} [2014-10-27] [not signed]
FF Extension: IQmango - C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default\Extensions\{bf5e07d7-3adb-41d8-a379-be976a83fe60} [2015-07-15] [not signed]
CHR NewTab: Default -> "chrome-extension://nafaimnnclfjfedmmabolbppcngeolgf/newtab/newtab-hp.html"
CHR DefaultSearchURL: Default -> [Link mogu videti samo ulogovani korisnici]{searchTerms}
CHR DefaultSearchKeyword: Default -> Ask Search
CHR DefaultSuggestURL: Default -> [Link mogu videti samo ulogovani korisnici]{searchTerms}
CHR Extension: (Ask Search) - C:\Users\Milos\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl [2015-06-08]
CHR Extension: (iLivid) - C:\Users\Milos\AppData\Local\Google\Chrome\User Data\Default\Extensions\nafaimnnclfjfedmmabolbppcngeolgf [2015-06-08]
R2 vToolbarUpdater3.4.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\3.4.0\ToolbarUpdater.exe [1830800 2015-08-19] (AVG Secure Search)
R1 F06DEFF2-5B9C-490D-910F-35D3A9119622; C:\Program Files (x86)\Settings Manager\smdmf\x64\smdmfmgrc2.cfg [41872 2014-08-31] (Aztec Media Inc)
Task: {9BEC35C2-1E93-46F8-A128-E846EE640667} - System32\Tasks\1015avUpdateInfo => C:\ProgramData\Avg_Update_1015av\1015av_AVG-Secure-Search-Update.exe [2015-10-11] ()
Task: {E787AF98-FB1E-4C0A-9F88-509973116904} - System32\Tasks\Origin => C:\Users\Milos\AppData\Roaming\Origin\update.vbe <==== ATTENTION
Task: {F3F5FA22-C287-4895-810C-DD3E07F1647B} - System32\Tasks\0614tUpdateInfo => C:\ProgramData\Avg_Update_0614t\0614t_AVG-Secure-Search-Update.exe [2014-07-03] ()
Task: C:\WINDOWS\Tasks\0614tUpdateInfo.job => C:\ProgramData\Avg_Update_0614t\0614t_AVG-Secure-Search-Update.exe
C:\Users\Milos\AppData\LocalLow\IQmango
C:\Program Files (x86)\Common Files\AVG Secure Search
C:\Program Files (x86)\Settings Manager
C:\ProgramData\Avg_Update_1015a
C:\Users\Milos\AppData\Roaming\Origin\update.vbe
C:\ProgramData\Avg_Update_0614t
EmptyTemp:
*****************

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\\{bf5e07d7-3adb-41d8-a379-be976a83fe60} => value removed successfully
"HKCR\Wow6432Node\CLSID\{bf5e07d7-3adb-41d8-a379-be976a83fe60}" => key removed successfully
HKU\S-1-5-21-1212074998-603920895-1076839072-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{bf5e07d7-3adb-41d8-a379-be976a83fe60} => value removed successfully
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}" => key removed successfully
HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} => key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}" => key removed successfully
HKCR\Wow6432Node\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} => key not found.
"HKU\S-1-5-21-1212074998-603920895-1076839072-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}" => key removed successfully
HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} => key not found.
"HKU\S-1-5-21-1212074998-603920895-1076839072-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}" => key removed successfully
HKCR\CLSID\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} => key not found.
"HKU\S-1-5-21-1212074998-603920895-1076839072-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E079D741-1FE4-4815-A527-F340D73743B0}" => key removed successfully
HKCR\CLSID\{E079D741-1FE4-4815-A527-F340D73743B0} => key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bf5e07d7-3adb-41d8-a379-be976a83fe60}" => key removed successfully
HKCR\Wow6432Node\CLSID\{bf5e07d7-3adb-41d8-a379-be976a83fe60} => key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{bf5e07d7-3adb-41d8-a379-be976a83fe60} => value removed successfully
HKCR\Wow6432Node\CLSID\{bf5e07d7-3adb-41d8-a379-be976a83fe60} => key not found.
HKU\S-1-5-21-1212074998-603920895-1076839072-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{BF5E07D7-3ADB-41D8-A379-BE976A83FE60} => value removed successfully
HKCR\CLSID\{BF5E07D7-3ADB-41D8-A379-BE976A83FE60} => key not found.
HKCR\Wow6432Node\PROTOCOLS\Handler\viprotocol => key not found.
HKCR\Wow6432Node\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9} => key not found.
Firefox SearchEngineOrder.1 removed successfully
Firefox SelectedSearchEngine removed successfully
Firefox "Keyword.URL" removed successfully
C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default\searchplugins\-youtube--.xml => moved successfully
C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default\searchplugins\avg-secure-search.xml => moved successfully
C:\Program Files (x86)\mozilla firefox\browser\searchplugins\default-search.xml => moved successfully
C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wtu-secure-search.xml => moved successfully
C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default\Extensions\avg@toolbar => not found.
C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default\Extensions\{121761af-0fa5-4896-a2a8-cfdbac4e4982} => moved successfully
C:\Users\Milos\AppData\Roaming\Mozilla\Firefox\Profiles\0tu4xuow.default\Extensions\{bf5e07d7-3adb-41d8-a379-be976a83fe60} => moved successfully
Chrome NewTab => removed successfully
Chrome DefaultSearchURL => removed successfully
Chrome DefaultSearchKeyword => removed successfully
Chrome DefaultSuggestURL => not found.
C:\Users\Milos\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl => moved successfully
C:\Users\Milos\AppData\Local\Google\Chrome\User Data\Default\Extensions\nafaimnnclfjfedmmabolbppcngeolgf => moved successfully
vToolbarUpdater3.4.0 => service not found.
F06DEFF2-5B9C-490D-910F-35D3A9119622 => Unable to stop service.
F06DEFF2-5B9C-490D-910F-35D3A9119622 => service removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9BEC35C2-1E93-46F8-A128-E846EE640667}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9BEC35C2-1E93-46F8-A128-E846EE640667}" => key removed successfully
C:\WINDOWS\System32\Tasks\1015avUpdateInfo => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\1015avUpdateInfo" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E787AF98-FB1E-4C0A-9F88-509973116904}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E787AF98-FB1E-4C0A-9F88-509973116904}" => key removed successfully
C:\WINDOWS\System32\Tasks\Origin => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Origin" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F3F5FA22-C287-4895-810C-DD3E07F1647B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F3F5FA22-C287-4895-810C-DD3E07F1647B}" => key removed successfully
C:\WINDOWS\System32\Tasks\0614tUpdateInfo => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\0614tUpdateInfo" => key removed successfully
C:\WINDOWS\Tasks\0614tUpdateInfo.job => moved successfully
C:\Users\Milos\AppData\LocalLow\IQmango => moved successfully
"C:\Program Files (x86)\Common Files\AVG Secure Search" => not found.
C:\Program Files (x86)\Settings Manager => moved successfully
"C:\ProgramData\Avg_Update_1015a" => not found.
"C:\Users\Milos\AppData\Roaming\Origin\update.vbe" => not found.
C:\ProgramData\Avg_Update_0614t => moved successfully
EmptyTemp: => 418.3 MB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 22:45:34 ====
[Link mogu videti samo ulogovani korisnici]

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Preuzmi Malwarebytes Anti-Rootkit (MBAR) sa sledeceg linka i sacuvaj ga na Desktop.

Dvoklikom pokreni MBAR () na ikonicu programa:
- Klikni OK na sledecem prozoru da bi dozvolio raspakivanje u zaseban mbar folder na desktop-u;
- mbar.exe ce biti startovan. Na nekim sistemima to moze da potraje nekoliko dodatnih sekundi, te pricekati pokretanje.;
- U uvodnom prozoru klikni dugme Next ukoliko si saglasan;



• Na 'Update Database' prozoru klik na dugme Update da bi preuzeo sveze definicije. Kada se ispise poruka 'Success: Database was successfully updated' klik na dugme Next;
• Pod sekcijom 'Scan Targets' proveri da su sve opcije stiklirane, te klikni na dugme Scan;

Obavestenje: sa nekim infekcijama moze se desiti da se prikaze neka od sledecih poruka:
- 'Could not load protection driver' => u tom slucaju klikni OK.
- 'Could not load DDA driver' => klikni Yes na to obavestenje da bi dozvolio ucitavanje nakon restarta. Dozvoli restart i nastavi sa ostatkom instrukcija posle restarta.





>> Ukoliko malware nije detektovan, klik na Exit dugme da zatvoris program. U sledecu poruku postavi mbar-log-year-month-day (sat-minuti-sekundi).txt i system-log.txt izveštaje.

>> Ukoliko su infekcija/e pronadjene, proveriti da li je obelezena opcija 'Create Restore Point' i klikni na dugme Cleanup! da bi uklonili pretnje.
- Procedura uklanjanje malware-a (scheduled) ce biti zakazana po restartu, bice prikazano obavestenje u pop-up prozoru. Klikni dugme Yes i sistem bi trebao da se restartuje i da zavrsi proceduru ciscenja.



Obavestenje! samo ukoliko je RootKit detektovan: - postaraj se da pokrenes fixdamage.exe alat koji se nalazi u mbar folderu, \Plugins\fixdamage.exe:
- Dvoklikom pokreni fixdamage, u crnom prozoru koji se otvori (command prompt) ukucaj Y (Y stoji za Yes) da bi nastavio izvrsenje, pricekati da alat odradi sve popravke ...
- Kada vidis poruku 'press any key to exit' popravka je kompletirana. Pritisnuti bilo koju tipku na tastaturi da bi se prozor zatvorio. Restartovati sistem.





Sledeci izvestaji ce biti formirani u mbar folderu.
1. mbar-log-year-month-day (hour-minute-second).txt
2. system-log.txt

Iskopiraj sadrzaj mbar log-a u poruku a system log okaci uz poruku koristeci opciju Prikači fajl.

offline
  • Pridružio: 01 Mar 2008
  • Poruke: 245

Napisano: 12 Nov 2015 10:58

Malwarebytes Anti-Rootkit BETA 1.9.3.1001
[Link mogu videti samo ulogovani korisnici]

Database version:
main: v2014.11.18.05
rootkit: v2014.11.12.01

Windows 10 x64 NTFS
Internet Explorer 11.0.10240.16590
Milos :: MILOS-PC [administrator]

11/12/2015 10:25:03
mbar-log-2015-11-12 (10-25-03).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 385256
Time elapsed: 25 minute(s), 20 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 6
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\MRT.exe (Trojan.Agent) -> Delete on reboot. [6bd2f845ee8ea1954f7e3db7aa59916f]
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\MsMpEng.exe (Security.Hijack) -> Delete on reboot. [54e9ab925d1f5adcf7efa74d59aa3dc3]
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\svchost.exe (Security.Hijack) -> Delete on reboot. [4af3c479e49854e226e0886f45beeb15]
HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\MRT.exe (Trojan.Agent) -> Delete on reboot. [b687231a93e9cf67cc01cf253fc4d32d]
HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\MsMpEng.exe (Security.Hijack) -> Delete on reboot. [ab92e459c8b43600cb1b3db7847fd62a]
HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\svchost.exe (Security.Hijack) -> Delete on reboot. [8bb27bc2205c57df64a2a6510ff442be]

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)

[Link mogu videti samo ulogovani korisnici]

Dopuna: 12 Nov 2015 11:12

da li treba da pokrenem fixdamage.exe ???

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Nema potrebe.


To bi bilo to.


Arrow

Sledeća procedura će implementirati završno čišćenje.

Arrow Preuzmi "Xplode"-ov DelFix alat i snimi ga na Desktop.
Dvoklikom pokreni alat i štikliraj kućice ispred sledećih opcija;

Remove disinfection tools
Create registry backup
Purge System Restore


Klikni na dugme Run i pričekaj trenutak dok alat ne završi svoj rad.
Od ovog trenutka, svi korišćeni alati u ovoj temi bi trebali biti obrisani.
Alat će takođe formirati izveštaj za tebe. (C:\DelFix.txt)

Alat će snimiti i zdravo stanje registy-ja i napraviti backup koristeci integrisan program "ERUNT" u %windir%\ERUNT\DelFix
Alat briše stare system restore tačke i pravi novu, svežu tačku nakon čišćenja.

offline
  • Pridružio: 01 Mar 2008
  • Poruke: 245

Napisano: 12 Nov 2015 17:53

uradjeno ali i dalje se programi sa velikim zakasnjenjem odazivaju

Dopuna: 12 Nov 2015 17:55

cak na mestima gde jednim klikom bi trebalo da se nesto pokrene sad mi treba dvoklik.

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Probaj deisntalaciju postojeće verzije AVGa i instalaciju najnovije verzije.

offline
  • Pridružio: 01 Mar 2008
  • Poruke: 245

u redu, hvala na pomoći i savetu, pozzz

Ko je trenutno na forumu
 

Ukupno su 856 korisnika na forumu :: 40 registrovanih, 2 sakrivenih i 814 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 15694 - dana 01 Feb 2026 12:23

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: berste23, darkkran, dekan.m, Dorcolac, Džekson, Ezbuck, fokac, GT, jednokratni akaunt, Jester, lakson001, Lubenica303, MadMike, Marko Marković, Mi lao shu, milenko crazy north, Milos82, Mitch22, Mzee, Nemanja Opalić, obsc, paja69, PlayerOne, rokokoko, saputnik plavetnila, Sase, Saša31LPB, Simon simonović, singa, Srpska zauvjek, superwhy, Szigetwar, Vanderx, vladaa012, Vlado82, Vojo06, Zastava, Zukov, zziko, Ćuk