provera kompjutera.

1

provera kompjutera.

offline
  • Istrazivanje Windowsa
  • Pridružio: 12 Jul 2012
  • Poruke: 1023

Evo posto sam skidao mnogo programa pa da cisto proverim da li kompjuter ima virusa.

First:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:12-06-2014
Ran by Slavko Radic (administrator) on SLAVKO on 12-06-2014 15:48:08
Running from C:\Documents and Settings\Slavko Radic\My Documents\Downloads
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-t.....scan-tool/

==================== Processes (Whitelisted) =================

(PixArt Imaging Incorporation) C:\WINDOWS\Pixart\Pac7302\Monitor.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [PAC7302_Monitor] => C:\WINDOWS\PixArt\PAC7302\Monitor.exe [323584 2007-12-10] (PixArt Imaging Incorporation)
HKLM\...\Run: [NvMediaCenter] => C:\WINDOWS\system32\NvMcTray.dll [110696 2010-03-16] (NVIDIA Corporation)
HKLM\...\Run: [NvCplDaemon] => C:\WINDOWS\system32\NvCpl.dll [13670504 2010-03-16] (NVIDIA Corporation)
HKLM\...\Run: [MSConfig] => C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe [169984 2008-04-14] (Microsoft Corporation)
HKU\S-1-5-21-57989841-606747145-839522115-1003\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-57989841-606747145-839522115-1003\...\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-21-57989841-606747145-839522115-1003\...\MountPoints2: F - F:\autorun.exe
BootExecute: autocheck autochk * sdnclean.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.rs/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
SearchScopes: HKLM - DefaultScope value is missing.
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: No Name - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - No File
Toolbar: HKLM - No Name - {10921475-03CE-4E04-90CE-E2E7EF20C814} - No File
Toolbar: HKCU - &Address - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
Toolbar: HKCU - &Links - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_15-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_15-windows-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Documents and Settings\Slavko Radic\Application Data\Mozilla\Firefox\Profiles\ocykmfzx.default
FF Homepage: https://www.google.rs/?gws_rd=cr&ei=q55aU87rPMOJtQbAmICYBA
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF user.js: detected! => C:\Documents and Settings\Slavko Radic\Application Data\Mozilla\Firefox\Profiles\ocykmfzx.default\user.js
FF SearchPlugin: C:\Documents and Settings\Slavko Radic\Application Data\Mozilla\Firefox\Profiles\ocykmfzx.default\searchplugins\buenosearch.xml
FF Extension: Adblock Plus Pop-up Addon - C:\Documents and Settings\Slavko Radic\Application Data\Mozilla\Firefox\Profiles\ocykmfzx.default\Extensions\adblockpopups@jessehakanen.net.xpi [2014-02-23]
FF Extension: Hotspot Shield Helper (Please allow this installation) - C:\Program Files\Mozilla Firefox\extensions\afurladvisor@anchorfree.com [2014-05-09]
FF HKLM\...\Firefox\Extensions: [ext@flashenhancer.com] - C:\Program Files\AmiExt\flashEnhancer\ff

========================== Services (Whitelisted) =================

S4 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2013-12-18] (Oracle Corporation)

==================== Drivers (Whitelisted) ====================

R3 Afc; C:\WINDOWS\System32\drivers\Afc.sys [18688 2006-11-10] (Arcsoft, Inc.)
S3 Ambfilt; C:\WINDOWS\System32\drivers\Ambfilt.sys [1691480 2009-11-18] (Creative)
R1 AmdK8; C:\WINDOWS\System32\DRIVERS\AmdK8.sys [36864 2006-07-01] (Advanced Micro Devices)
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
S3 hamachi; C:\WINDOWS\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
R3 HSFHWBS2; C:\WINDOWS\System32\DRIVERS\HSFBS2S2.sys [220032 2004-08-04] (Conexant Systems, Inc.)
R3 HSF_DP; C:\WINDOWS\System32\DRIVERS\HSFDPSP2.sys [1041536 2004-08-04] (Conexant Systems, Inc.)
R3 HssDrv; C:\WINDOWS\System32\DRIVERS\HssDrv.sys [44744 2013-06-21] (AnchorFree Inc.)
S3 Monfilt; C:\WINDOWS\System32\drivers\Monfilt.sys [1395800 2009-11-18] (Creative Technology Ltd.)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
R0 nvata; C:\WINDOWS\System32\DRIVERS\nvata.sys [105344 2006-08-14] (NVIDIA Corporation)
R0 nvgts; C:\WINDOWS\System32\DRIVERS\nvgts.sys [168040 2010-04-09] (NVIDIA Corporation)
R3 PAC7302; C:\WINDOWS\System32\DRIVERS\PAC7302.SYS [461824 2009-04-28] (PixArt Imaging Inc.)
S3 rtl8139; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [20992 2004-08-04] (Realtek Semiconductor Corporation)
R1 SCDEmu; C:\WINDOWS\system32\Drivers\SCDEmu.sys [59388 2010-04-12] (PowerISO Computing, Inc.) [File not signed]
R3 winachsf; C:\WINDOWS\System32\DRIVERS\HSFCXTS2.sys [685056 2004-08-04] (Conexant Systems, Inc.)
S4 IntelIde; No ImagePath
U5 Nsynas32; C:\Windows\System32\Drivers\Nsynas32.sys [17784 2001-04-09] (Syncrosoft Hard- und Software GmbH) [File not signed]
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
U1 WS2IFSL;

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-06-12 15:47 - 2014-06-12 15:48 - 00000000 ____D () C:\FRST
2014-06-12 14:39 - 2014-06-12 14:39 - 00000000 ____D () C:\Documents and Settings\Slavko Radic\Local Settings\Application Data\Oberon Media
2014-06-12 14:39 - 2014-06-12 14:39 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Oberon Media
2014-06-12 14:32 - 2014-06-12 14:33 - 00000000 ____D () C:\Program Files\AmiExt
2014-06-12 14:32 - 2014-06-12 14:32 - 00000000 ____D () C:\Program Files\Lightspark 0.5.3-git
2014-06-12 14:31 - 2014-06-12 14:33 - 00000000 ____D () C:\Documents and Settings\Slavko Radic\Application Data\11294
2014-06-12 13:15 - 2014-06-12 13:15 - 00025704 _____ () C:\Documents and Settings\Slavko Radic\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2014-06-07 15:20 - 2014-06-07 15:20 - 00006790 _____ () C:\WINDOWS\FaxSetup.log
2014-06-07 15:20 - 2014-06-07 15:20 - 00006624 _____ () C:\WINDOWS\iis6.log
2014-06-07 15:20 - 2014-06-07 15:20 - 00005816 _____ () C:\WINDOWS\ocgen.log
2014-06-07 15:20 - 2014-06-07 15:20 - 00004591 _____ () C:\WINDOWS\tsoc.log
2014-06-07 15:20 - 2014-06-07 15:20 - 00002474 _____ () C:\WINDOWS\comsetup.log
2014-06-07 15:20 - 2014-06-07 15:20 - 00001891 _____ () C:\WINDOWS\imsins.log
2014-06-07 15:20 - 2014-06-07 15:20 - 00001836 _____ () C:\WINDOWS\msmqinst.log
2014-06-07 15:20 - 2014-06-07 15:20 - 00001789 _____ () C:\WINDOWS\ntdtcsetup.log
2014-06-07 15:20 - 2014-06-07 15:20 - 00001592 _____ () C:\WINDOWS\netfxocm.log
2014-06-07 15:20 - 2014-06-07 15:20 - 00000719 _____ () C:\WINDOWS\MedCtrOC.log
2014-06-07 15:20 - 2014-06-07 15:20 - 00000479 _____ () C:\WINDOWS\msgsocm.log
2014-06-07 15:20 - 2014-06-07 15:20 - 00000469 _____ () C:\WINDOWS\ocmsn.log
2014-06-07 15:20 - 2014-06-07 15:20 - 00000311 _____ () C:\WINDOWS\tabletoc.log
2014-06-07 15:20 - 2014-06-07 15:20 - 00000000 _____ () C:\WINDOWS\setuperr.log
2014-06-07 15:20 - 2014-06-07 15:20 - 00000000 _____ () C:\WINDOWS\setupact.log
2014-06-04 08:23 - 2014-06-04 08:23 - 00142032 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-06-01 19:42 - 2014-06-02 23:58 - 00000000 ____D () C:\Documents and Settings\Slavko Radic\Desktop\Matura
2014-05-28 17:46 - 2014-05-28 22:25 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Impressions Games
2014-05-25 00:30 - 2014-05-25 00:30 - 00000000 ____D () C:\Documents and Settings\Slavko Radic\My Documents\Praetorians
2014-05-25 00:23 - 2014-05-25 00:23 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Eidos Interactive
2014-05-24 23:26 - 2014-05-24 23:26 - 00000833 _____ () C:\Documents and Settings\Slavko Radic\Start Menu\µTorrent.lnk
2014-05-24 23:26 - 2014-05-24 23:26 - 00000833 _____ () C:\Documents and Settings\Slavko Radic\Desktop\µTorrent.lnk
2014-05-20 23:04 - 2014-05-20 23:04 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Counter-Strike PRO

==================== One Month Modified Files and Folders =======

2014-06-12 15:48 - 2014-06-12 15:47 - 00000000 ____D () C:\FRST
2014-06-12 15:48 - 2012-03-01 19:30 - 00000000 ____D () C:\Documents and Settings\Slavko Radic\Local Settings\Temp
2014-06-12 15:25 - 2012-03-01 19:24 - 01874004 ____C () C:\WINDOWS\WindowsUpdate.log
2014-06-12 15:06 - 2012-04-13 16:30 - 00000830 ____C () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-06-12 15:03 - 2012-03-02 16:45 - 00000000 ___RD () C:\Documents and Settings\Slavko Radic\Desktop\igre
2014-06-12 14:39 - 2014-06-12 14:39 - 00000000 ____D () C:\Documents and Settings\Slavko Radic\Local Settings\Application Data\Oberon Media
2014-06-12 14:39 - 2014-06-12 14:39 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Oberon Media
2014-06-12 14:39 - 2004-08-04 14:00 - 00000894 ____C () C:\WINDOWS\win.ini
2014-06-12 14:33 - 2014-06-12 14:32 - 00000000 ____D () C:\Program Files\AmiExt
2014-06-12 14:33 - 2014-06-12 14:31 - 00000000 ____D () C:\Documents and Settings\Slavko Radic\Application Data\11294
2014-06-12 14:32 - 2014-06-12 14:32 - 00000000 ____D () C:\Program Files\Lightspark 0.5.3-git
2014-06-12 14:19 - 2014-05-11 21:31 - 00000401 _____ () C:\Documents and Settings\Slavko Radic\Desktop\New Text Document.txt
2014-06-12 13:59 - 2014-01-16 20:16 - 00000000 ____D () C:\Documents and Settings\Slavko Radic\Application Data\Skype
2014-06-12 13:54 - 2012-04-18 20:49 - 00002265 ____C () C:\Documents and Settings\All Users\Desktop\Skype.lnk
2014-06-12 13:23 - 2010-03-16 04:37 - 00276951 _____ () C:\WINDOWS\system32\NvApps.xml
2014-06-12 13:15 - 2014-06-12 13:15 - 00025704 _____ () C:\Documents and Settings\Slavko Radic\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2014-06-12 09:17 - 2014-04-25 08:05 - 00000000 ____D () C:\Documents and Settings\Slavko Radic\Desktop\New Folder
2014-06-12 08:01 - 2014-02-03 21:18 - 00000000 ____D () C:\Documents and Settings\Slavko Radic\Application Data\uTorrent
2014-06-12 08:01 - 2012-03-01 20:13 - 00000223 ___SH () C:\boot.ini
2014-06-12 08:01 - 2004-08-04 14:00 - 00000227 ____C () C:\WINDOWS\system.ini
2014-06-12 07:10 - 2012-03-01 20:17 - 00000159 ____C () C:\WINDOWS\wiadebug.log
2014-06-12 07:10 - 2012-03-01 20:17 - 00000049 ____C () C:\WINDOWS\wiaservc.log
2014-06-12 07:10 - 2012-03-01 19:29 - 00000006 ___HC () C:\WINDOWS\Tasks\SA.DAT
2014-06-12 00:46 - 2012-03-01 19:29 - 00032360 _____ () C:\WINDOWS\SchedLgU.Txt
2014-06-12 00:45 - 2013-08-14 22:57 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-06-12 00:40 - 2012-05-26 06:49 - 92708840 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-06-12 00:39 - 2012-03-01 19:30 - 00000178 __SHC () C:\Documents and Settings\Slavko Radic\ntuser.ini
2014-06-10 08:58 - 2004-08-04 14:00 - 00002206 ____C () C:\WINDOWS\system32\wpa.dbl
2014-06-07 18:39 - 2012-07-08 08:28 - 00000000 ____D () C:\Documents and Settings\Slavko Radic\My Documents\My Cheat Tables
2014-06-07 15:20 - 2014-06-07 15:20 - 00006790 _____ () C:\WINDOWS\FaxSetup.log
2014-06-07 15:20 - 2014-06-07 15:20 - 00006624 _____ () C:\WINDOWS\iis6.log
2014-06-07 15:20 - 2014-06-07 15:20 - 00005816 _____ () C:\WINDOWS\ocgen.log
2014-06-07 15:20 - 2014-06-07 15:20 - 00004591 _____ () C:\WINDOWS\tsoc.log
2014-06-07 15:20 - 2014-06-07 15:20 - 00002474 _____ () C:\WINDOWS\comsetup.log
2014-06-07 15:20 - 2014-06-07 15:20 - 00001891 _____ () C:\WINDOWS\imsins.log
2014-06-07 15:20 - 2014-06-07 15:20 - 00001836 _____ () C:\WINDOWS\msmqinst.log
2014-06-07 15:20 - 2014-06-07 15:20 - 00001789 _____ () C:\WINDOWS\ntdtcsetup.log
2014-06-07 15:20 - 2014-06-07 15:20 - 00001592 _____ () C:\WINDOWS\netfxocm.log
2014-06-07 15:20 - 2014-06-07 15:20 - 00000719 _____ () C:\WINDOWS\MedCtrOC.log
2014-06-07 15:20 - 2014-06-07 15:20 - 00000479 _____ () C:\WINDOWS\msgsocm.log
2014-06-07 15:20 - 2014-06-07 15:20 - 00000469 _____ () C:\WINDOWS\ocmsn.log
2014-06-07 15:20 - 2014-06-07 15:20 - 00000311 _____ () C:\WINDOWS\tabletoc.log
2014-06-07 15:20 - 2014-06-07 15:20 - 00000000 _____ () C:\WINDOWS\setuperr.log
2014-06-07 15:20 - 2014-06-07 15:20 - 00000000 _____ () C:\WINDOWS\setupact.log
2014-06-04 08:29 - 2014-04-04 22:20 - 00000000 ____D () C:\Documents and Settings\Slavko Radic\Desktop\Unused Desktop Shortcuts
2014-06-04 08:23 - 2014-06-04 08:23 - 00142032 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-06-04 00:52 - 2012-03-05 22:52 - 00000000 __SHD () C:\Documents and Settings\Slavko Radic\UserData
2014-06-04 00:52 - 2012-03-01 19:30 - 00000000 ____D () C:\Documents and Settings\Slavko Radic
2014-06-02 23:58 - 2014-06-01 19:42 - 00000000 ____D () C:\Documents and Settings\Slavko Radic\Desktop\Matura
2014-06-01 19:43 - 2013-12-28 23:40 - 00000000 ___RD () C:\Documents and Settings\Slavko Radic\Desktop\Important
2014-06-01 19:41 - 2012-03-01 19:39 - 00019456 _____ () C:\Documents and Settings\Slavko Radic\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-05-28 22:25 - 2014-05-28 17:46 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Impressions Games
2014-05-28 22:22 - 2012-03-01 19:36 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2014-05-28 17:46 - 2012-03-02 22:39 - 00000751 ____C () C:\WINDOWS\SIERRA.INI
2014-05-25 00:30 - 2014-05-25 00:30 - 00000000 ____D () C:\Documents and Settings\Slavko Radic\My Documents\Praetorians
2014-05-25 00:23 - 2014-05-25 00:23 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Eidos Interactive
2014-05-24 23:26 - 2014-05-24 23:26 - 00000833 _____ () C:\Documents and Settings\Slavko Radic\Start Menu\µTorrent.lnk
2014-05-24 23:26 - 2014-05-24 23:26 - 00000833 _____ () C:\Documents and Settings\Slavko Radic\Desktop\µTorrent.lnk
2014-05-20 23:04 - 2014-05-20 23:04 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Counter-Strike PRO
2014-05-18 09:10 - 2012-04-13 16:30 - 00692400 ____C (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2014-05-18 09:10 - 2012-03-01 19:49 - 00070832 ____C (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2014-05-15 19:21 - 2012-09-17 18:02 - 00000632 ____C () C:\WINDOWS\CoD.INI

Some content of TEMP:
====================
C:\Documents and Settings\Slavko Radic\Local Settings\Temp\fEBundle.exe
C:\Documents and Settings\Slavko Radic\Local Settings\Temp\Gamehouse Inspector Parker.exe__4607_i838525000_il81.exe
C:\Documents and Settings\Slavko Radic\Local Settings\Temp\GLB1A2B.EXE


==================== Bamital & volsnap Check =================

C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

==================== End Of Log ============================
Addition:

https://www.mycity.rs/must-login.png

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6103

Pozdrav,


1. Otvori Notepad (Text Document) i iskopiraj sledeći tekst unutar kod polja ispod:

Start
Folder: C:\Program Files\AmiExt
FF SearchPlugin: C:\Documents and Settings\Slavko Radic\Application Data\Mozilla\Firefox\Profiles\ocykmfzx.default\searchplugins\buenosearch.xml
FF Extension: Hotspot Shield Helper (Please allow this installation) - C:\Program Files\Mozilla Firefox\extensions\afurladvisor@anchorfree.com [2014-05-09]
FF HKLM\...\Firefox\Extensions: [ext@flashenhancer.com] - C:\Program Files\AmiExt\flashEnhancer\ff
Hosts:
C:\Documents and Settings\Slavko Radic\Application Data\Mozilla\Firefox\Profiles\ocykmfzx.default\searchplugins\buenosearch.xml
C:\Program Files\Mozilla Firefox\extensions\afurladvisor@anchorfree.com
C:\Program Files\AmiExt\flashEnhancer
Reboot:
AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
CMD: RD /S /Q %TEMP%
End


2. Sačuvaj notepad na Desktop pod nazivom fixlist.txt
To možes uraditi i iz notepad-a => klik na File potom na Save As i u novom prozoru, dole pod File Name: staviš za naziv fixlist.txt
Napomena: Važno je da se oba fajla, FRST i fixlist nalaze na istoj lokaciji jer u suprotnom fix nece raditi.

3. Ponovo pokreni FRST/FRST64, klikni jednom na dugme Fix i sačekaj.
Ukoliko alat zatraži restart sistema, dozvoli mu i postaraj se da alat kompletira fix nakon restarta sistema.



Alat će formirati log (Fixlog.txt) na Desktop-u. Potrebno je sadržaj tog loga iskopirati u poruku.
Napomena: Ukoliko te alat upozori da postoji novija verzija, postaraj se da preuzmes i koristiš ažuriranu kopiju FRST-a.

offline
  • Istrazivanje Windowsa
  • Pridružio: 12 Jul 2012
  • Poruke: 1023

Evo:

ix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:12-06-2014
Ran by Slavko Radic at 2014-06-12 22:59:31 Run:1
Running from C:\Documents and Settings\Slavko Radic\My Documents\Downloads
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
Start
Folder: C:\Program Files\AmiExt
FF SearchPlugin: C:\Documents and Settings\Slavko Radic\Application Data\Mozilla\Firefox\Profiles\ocykmfzx.default\searchplugins\buenosearch.xml
FF Extension: Hotspot Shield Helper (Please allow this installation) - C:\Program Files\Mozilla Firefox\extensions\afurladvisor@anchorfree.com [2014-05-09]
FF HKLM\...\Firefox\Extensions: [ext@flashenhancer.com] - C:\Program Files\AmiExt\flashEnhancer\ff
Hosts:
C:\Documents and Settings\Slavko Radic\Application Data\Mozilla\Firefox\Profiles\ocykmfzx.default\searchplugins\buenosearch.xml
C:\Program Files\Mozilla Firefox\extensions\afurladvisor@anchorfree.com
C:\Program Files\AmiExt\flashEnhancer
Reboot:
AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
CMD: RD /S /Q %TEMP%
End
*****************


========================= Folder: C:\Program Files\AmiExt ========================


====== End of Folder: ======

C:\Documents and Settings\Slavko Radic\Application Data\Mozilla\Firefox\Profiles\ocykmfzx.default\searchplugins\buenosearch.xml => Moved successfully.
C:\Program Files\Mozilla Firefox\extensions\afurladvisor@anchorfree.com => Moved successfully.
HKLM\Software\Mozilla\Firefox\Extensions\\ext@flashenhancer.com => value deleted successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
"C:\Documents and Settings\Slavko Radic\Application Data\Mozilla\Firefox\Profiles\ocykmfzx.default\searchplugins\buenosearch.xml" => File/Directory not found.
"C:\Program Files\Mozilla Firefox\extensions\afurladvisor@anchorfree.com" => File/Directory not found.
"C:\Program Files\AmiExt\flashEnhancer" => File/Directory not found.
C:\Documents and Settings\All Users\Application Data\TEMP => ":0B4227B4" ADS removed successfully.
C:\Documents and Settings\All Users\Application Data\TEMP => ":D1B5B4F1" ADS removed successfully.

========= RD /S /Q %TEMP% =========


========= End of CMD: =========



The system needed a reboot.

==== End of Fixlog ====

Da li je sad sve u redu? I hteo bi da znam sta je to bilo? Neke reklame,malware?

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6103

Ma nista strasno. Par malicioznih stavki je bilo ucitano sa tvojim Firefox browserom. To je to, cist si. Wink

Obrisi ova dva foldera ...

C:\Program Files\AmiExt
C:\FRST

... i obrisi FRST.exe alat. To bi bilo to.

offline
  • Istrazivanje Windowsa
  • Pridružio: 12 Jul 2012
  • Poruke: 1023

Da li bi Antivirus mogao da zaustavi te maliciozne programe preko interneta sto dolaze? Da li je potrebno nekako Firewall staviti da je ''oprezniji''? Meni nekad na browseru pise ''this site cannot be trusted it does not supply full identity'' E sad el to opasno?

Mislim da cu skinuti antivirus AVG 2014 mnogo je dobar jeste mozda malo zahtevan za moj komp jer on uglavnom sve skenira sto otvoris a i non stop radi.Hvala ti jos jedanput i ako bi mogao da mi odgovoris na ta pitanja gore Mr. Green

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6103

Citat:Da li bi Antivirus mogao da zaustavi te maliciozne programe preko interneta sto dolaze?
Zavisi, mnogi vendori se drze politike da PUP software nije uvek neophodno malicioznan. I u pravu su po nekad. Ima i onih AV vendora koji prate desavanje te su tu politiku izmenili. User sam instalira nesto od toga i taj program mu jasno kaze sta ce sve da uradi ali user mu ipak (nesvesno) dozvoli. Isto tako imaj na umu da taj PUP program ima svoj uninstaller, a maliciozne extenzije znaju doci preko PUP programa, ako ne u dosta slucajeva mogu da se uninstaliraju preko FF ili CHR podesavanja (ima i onih koji to odbijaju), da taj AV se instalira ne samo na kucnim racunarima, AV ne sme bas uvek da dira ono sto ti instaliras...etc Ima mnogo faktora. Takodje, FF i CHR su third party. Neki vendori ne zele jos da daju support za FF i CHR osim ako se taj neki adware ne ponasa previse agresivno. Neki su vec taj "problem" prevazisli.

Citat:Da li je potrebno nekako Firewall staviti da je ''oprezniji''?
Dok je integrisan Firewall pocevsi od Viste => veoma dobar da su cak neki AV vendori obustavili rad na svojim firewall komponentama i rade sa integrisanim, Firewall na XP i nije bas . . dobar. Dodatan Firewall software je pozeljan ali ne nuzno neophodan. U tvom primeru sumnjam da bi ti resio problem.

Citat:Meni nekad na browseru pise ''this site cannot be trusted it does not supply full identity'' E sad el to opasno?
Nije. Firefox hoce da kaze da taj site nema validan sertifikat. Resenje je da gledas online filmove sa manjim adwaresing-om i validnim sajtovima.


Resenje:

Prvo preventiva => Unchecky
Drugo edukacija => primer: Šta je reklama, a šta pravi download link
// moras nauciti da zaobilazis lose sajtove i gledas online filmove na validnijim sajtovima.
Trece => mozda dodatni zastiti sofware? MBAM vec neko vreme ima agresivnu politiku prema PUP.



Idea Sta god da ubacis ili napravis, edukacija je osnova. Ako naucis da izbegavas lazne ponude, problema neces imati.

offline
  • Istrazivanje Windowsa
  • Pridružio: 12 Jul 2012
  • Poruke: 1023

Hvala mnogo na ovim savetima.Kao sto si rekao moram da nadjem dobar sajt sa skidanje,gledane filmova,itd.

Filmove gledam na filmoviziji ali tamo reklama ima cudo.

Igrice skidam preko torrenta jeste da i tu ima reklama ali kad se pojave jednostavno ih ugasis.Koristim add block pop up plus.
Nekad igrice skidam i preko nekih drugih sajtova a na tim sajtovima kad skidas kao ti daju neke programe,toolbare,ovo ono.Kad mi se to pojavi samo kliknem decline ili iscekiram sve ponudjene stavke.

I kako mislis dodatni Firewall? Moram da obrisem ovaj stari sto dolazi uz Windows i skinem novi?

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6103

Integrisani FW mozes da ukljucis ili iskljucis, obrisati ne mozes. Htedoh ti reci da ako zelis bolji Firewall, mozes da ga stavis, izbor je tvoj. Ali da bi kontrolisao sta koja aplikacija radi u pozadini moras i da razumes sta ti Firewall prijavljuje. FW nije nuzno neophodan ali jeste pozeljan. Postoje dosta besplatnih FW sa HIPS-om, za vise informacija konsultuj nasu zastitu.

offline
  • Istrazivanje Windowsa
  • Pridružio: 12 Jul 2012
  • Poruke: 1023

Izvini sto te smaram ali mozes mi reci kako da znam sta je officialna stranica? Mislim neke stranice samo kopiraju delove od oficijalne i onda lice kao da su prave.Evo naprimer ovde ja bi skinuo antivirus ali ne znam el to prava stranica? http://free.avg.com/eu-en/free-antivirus-download Lici kao da nije.

Izvini stvarno ali treba mi pomoc kako da razumem sta je prava oficijalna a sta nije.

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6103

Nema potrebe da se izvinjavas ali prelazimo iz domena Ambulanta foruma. Na ova pitanja ce ti rado bilo ko iz zastite odgovoriti. Wink

Vezao za validnost linka, samo trebas da citas URL. Kompanija AVG je zakupila domen avg.com i to je to. Jos jedan avg.com ne moze da postoji. Da na URL stranici pise "lepetete.com" i stoji download za AVG, jasno ti je da to nije officijalna stranica. Dati link nosi free.avg.com, jasno je da je validan. Da stoji free.lepetete.com i sa velikim i sarenim dugmetom 'Download' da li bi bio validan?

Mi moramo prekinuti ovu nasu diskusiju Smile ali rekoh ti, ne usturcavaj se da postavis ova pitanja u zastiti. Ima voljnih clanova foruma koji ce ti rado pojasniti ako ima sta nejasno. Wink

Ko je trenutno na forumu
 

Ukupno su 978 korisnika na forumu :: 26 registrovanih, 5 sakrivenih i 947 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 4channer, _Rade, aleksmajstor, BSD, cenejac111, darkangel, djboj, DonRumataEstorski, draganl, goxin, hyla, ILGromovnik, kinez88, Lord Nem, m0nstrum_, Marko Marković, Milos82, mrvica78, radionica1, Rocky I, SR-3m, Stija zmija, Valter071, vathra, wizzardone, zlaya011