zarazen racunar

zarazen racunar

offline
  • Pridružio: 27 Sep 2013
  • Poruke: 94

vec duze vreme gotovo sam siguran da na racunaru imam neku vrstu zaraze,virus,malware ili vec nesto drugo jer mi racunar koci,iskacu mi neke stranice nepoznatog porekla,neke stranice nece da otvara,iskacu neki sumnjivi sadrzaji...a kod skeniranja avg-om rezultat je da je sve cisto pa ako

mozete da pomognete u eliminisanju moguce zaraze

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 14-01-2017
Ran by pc centar (administrator) on PCCENTAR-PC (14-01-2017 18:53:07)
Running from C:\Users\pc centar\Downloads
Loaded Profiles: pc centar (Available Profiles: pc centar)
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: geekstogo.com/forum/topic/335081-frst-t.....scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

() C:\Program Files\AVG Web TuneUp\WtuSystemSupport.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Framework\Common\avgsvcx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgcsrvx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgwdsvcx.exe
(Byte Technologies LLC) C:\Program Files\ByteFence\ByteFenceService.exe
(McAfee, Inc.) C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgnsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgemcx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgrsx.exe
(Reimage®) C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe
() C:\Program Files\ByteFence\rtop\bin\rtop_svc.exe
() C:\Program Files\ByteFence\rtop\bin\rtop_bg.exe
(Reimage®) C:\Program Files\Reimage\Reimage Protector\ReiSystem.exe
() C:\Program Files\AVG Web TuneUp\vprot.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgui.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Power Software Ltd) C:\Program Files\PowerISO\PWRISOVM.EXE
(Wondershare) C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
(BitTorrent Inc.) C:\Users\pc centar\AppData\Roaming\uTorrent\uTorrent.exe
(BitTorrent Inc.) C:\Users\pc centar\AppData\Roaming\uTorrent\updates\3.4.9_43085\utorrentie.exe
(BitTorrent Inc.) C:\Users\pc centar\AppData\Roaming\uTorrent\updates\3.4.9_43085\utorrentie.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Framework\Common\avguix.exe
(Byte Technologies LLC) C:\Program Files\ByteFence\ByteFence.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\netsh.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [AVG_UI] => C:\Program Files\AVG\Framework\Common\avguirnx.exe [220944 2016-12-06] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [AvgUi] => C:\Program Files\AVG\Framework\Common\avguirnx.exe [220944 2016-12-06] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [vProt] => C:\Program Files\AVG Web TuneUp\vprot.exe [2180680 2016-12-09] ()
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [587288 2016-09-22] (Oracle Corporation)
HKLM\...\Run: [PWRISOVM.EXE] => C:\Program Files\PowerISO\PWRISOVM.EXE [406664 2016-10-02] (Power Software Ltd)
HKLM\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2137744 2016-10-08] (Wondershare)
HKU\S-1-5-21-1757366166-212622331-2855360578-1000\...\Run: [uTorrent] => C:\Users\pc centar\AppData\Roaming\uTorrent\uTorrent.exe [1979072 2016-12-21] (BitTorrent Inc.)
HKU\S-1-5-21-1757366166-212622331-2855360578-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6628056 2016-01-15] (Piriform Ltd)
HKU\S-1-5-21-1757366166-212622331-2855360578-1000\...\Run: [RGSC] => C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
HKU\S-1-5-21-1757366166-212622331-2855360578-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [293888 2010-11-20] (Microsoft Corporation)
HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE ->
ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => -> No File
ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => -> No File
ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => -> No File
Startup: C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\bin [2016-03-10] ()
Startup: C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GTProtector.ini.upk [2016-03-10] ()
Startup: C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\motd_temp.html [2016-03-10] ()
Startup: C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Nexon.upk [2016-03-10] ()
Startup: C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\NexonGameMenu.upk [2016-03-10] ()
Startup: C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\NexonServerBrowser.upk [2016-03-10] ()
Startup: C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\NexonUserConfig.upk [2016-03-10] ()
Startup: C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk [2016-11-11]
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PlutoTV.lnk [2016-11-24]
ShortcutTarget: PlutoTV.lnk -> C:\Users\pc centar\AppData\Roaming\Pluto TV\PlutoTV.exe ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 79.143.160.20 79.143.168.8
Tcpip\..\Interfaces\{04BDDC3B-6B2F-4BA9-B2B3-BE9F734A8114}: [DhcpNameServer] 79.143.160.20 79.143.168.8
Tcpip\..\Interfaces\{9667BA16-3642-4303-9749-63BA26F47598}: [DhcpNameServer] 79.143.160.20 79.143.168.8
ManualProxies: 0hxxp://non-block.net/wpad.dat?daa497be4f804785fecef8edc08dc40516899964

Internet Explorer:
==================
HKU\S-1-5-21-1757366166-212622331-2855360578-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://mysearch.avg.com/?cid={D60526FC-7E55-45AD-AA37-41C883F30445}&mid=964dd1b2d81e47cc9ca9d15fa0734ff9-06ce4fc639803a2e3563922518183d8e94088cb9&lang=sr&ds=AVG&coid=avgtbavg&cmpid=1016tb&pr=fr&d=2016-06-08 13:00:25&v=4.3.6.255&pid=wtu&sg=&sap=hp
SearchScopes: HKLM -> DefaultScope {ielnksrch} URL =
SearchScopes: HKLM -> ielnksrch URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIP4NYe17aVLWqePRm9wWNFlj_H85KLF3AwPTCF6y7Re08UHjnLYLUXqFPF3ccdxQUNq7xvV5PrnVlDziyJ1KJvpibaXLci-bxmq7ySESazh5EHSvCrT-JPQRVDhLTjmZdQNo9DKXfvWI5Ur3_ry1bozPHjIsUsloZi2EOmO2Tyjd4giudZmT&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1757366166-212622331-2855360578-1000 -> DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={D60526FC-7E55-45AD-AA37-41C883F30445}&mid=964dd1b2d81e47cc9ca9d15fa0734ff9-06ce4fc639803a2e3563922518183d8e94088cb9&lang=sr&ds=AVG&coid=avgtbavg&cmpid=1216tb&pr=fr&d=2016-06-08 13:00:25&v=4.3.6.255&pid=wtu&sg=&sap=dsp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1757366166-212622331-2855360578-1000 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={D60526FC-7E55-45AD-AA37-41C883F30445}&mid=964dd1b2d81e47cc9ca9d15fa0734ff9-06ce4fc639803a2e3563922518183d8e94088cb9&lang=sr&ds=AVG&coid=avgtbavg&cmpid=1216tb&pr=fr&d=2016-06-08 13:00:25&v=4.3.6.255&pid=wtu&sg=&sap=dsp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1757366166-212622331-2855360578-1000 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIP4NYe17aVLWqePRm9wWNFlj_H85KLF3AwPTCF6y7Re08UHjnLYLUXqFPF3ccdxQUNq7xvV5PrnVlDziyJ1KJvpibaXLci-bxmq7ySESazh5EHSvCrT-JPQRVDhLTjmZdQNo9DKXfvWI5Ur3_ry1bozPHjIsUsloZi2EOmO2Tyjd4giudZmT&q={searchTerms}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_111\bin\ssv.dll [2016-11-24] (Oracle Corporation)
BHO: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files\AVG Web TuneUp\4.3.6.255\AVG Web TuneUp.dll [2016-12-09] (AVG)
BHO: McAfee WebAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2016-12-12] (McAfee, Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-11-24] (Oracle Corporation)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_111-windows-i586.cab
DPF: {CAFEEFAC-0018-0000-00111-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_111-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_111-windows-i586.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2016-12-12] (McAfee, Inc.)
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2009-02-26] (Microsoft Corporation)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2016-12-12] (McAfee, Inc.)

FireFox:
========
FF ProfilePath: C:\Users\pc centar\AppData\Roaming\Mozilla\Firefox\Profiles\fnfypgn0.default-1461093068292 [2017-01-14]
FF NewTab: Mozilla\Firefox\Profiles\fnfypgn0.default-1461093068292 -> C:\\ProgramData\\Ronzaps\\ff.NT
FF Homepage: Mozilla\Firefox\Profiles\fnfypgn0.default-1461093068292 -> about:home
FF Extension: (AVG Web TuneUp) - C:\Users\pc centar\AppData\Roaming\Mozilla\Firefox\Profiles\fnfypgn0.default-1461093068292\Extensions\avg@toolbar.xpi [2016-12-09]
FF Extension: (Firefox Hotfix) - C:\Users\pc centar\AppData\Roaming\Mozilla\Firefox\Profiles\fnfypgn0.default-1461093068292\Extensions\firefox-hotfix@mozilla.org.xpi [2016-09-01]
FF Extension: (McAfee WebAdvisor) - C:\Program Files\McAfee\SiteAdvisor\saffplg.xpi [2016-12-26]
FF SearchPlugin: C:\Users\pc centar\AppData\Roaming\Mozilla\Firefox\Profiles\fnfypgn0.default-1461093068292\searchplugins\avg-secure-search.xml [2017-01-14]
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\SiteAdvisor\saffplg.xpi
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_24_0_0_194.dll [2017-01-10] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1224194.dll [2016-02-19] (Adobe Systems, Inc.)
FF Plugin: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\40.3.6\\npsitesafety.dll [No File]
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [No File]
FF Plugin: @java.com/DTPlugin,version=11.111.2 -> C:\Windows\system32\npdeployJava1.dll [2016-11-24] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-11-24] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-11-24] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-1757366166-212622331-2855360578-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\pc centar\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-02-19] (Unity Technologies ApS)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\1163194288.js [2016-09-21] <==== ATTENTION (Points to *.cfg file)
FF ExtraCheck: C:\Program Files\mozilla firefox\1163194288.cfg [2016-09-21] <==== ATTENTION

Chrome:
=======
CHR DefaultProfile: Profile 1
CHR StartupUrls: Profile 1 -> "hxxps://www.google.ba/webhp?sourceid=chrome-instant&ion=1&espv=2&ie=UTF-8"
CHR Profile: C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default [2017-01-14]
CHR Extension: (Google Docs) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-01-06]
CHR Extension: (Google disk) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-12-17]
CHR Extension: (TV) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\beobeededemalmllhkmnkinmfembdimh [2016-02-12]
CHR Extension: (YouTube) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-02-12]
CHR Extension: (Street Racers) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\cohkjfondhjjfehnehlpmjpljpihfhfc [2016-02-12]
CHR Extension: (Google pretraživanje) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-02-12]
CHR Extension: (WGT Golf Challenge) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcilimldmomiaihcfkmaldanopfejefg [2016-02-12]
CHR Extension: (PiXditor - Photo Effects) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\ddfflkeppghppjmfikeachhdbmpjiacj [2016-04-25]
CHR Extension: (Facebook Color & Background Changer) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\dheljpcbhldkdiabdemaflamgfnbpnkd [2016-02-25]
CHR Extension: (Google Sheets) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-02-12]
CHR Extension: (Sat) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\gdkjifoifglkpcdffkenpinlbjgephlo [2016-02-12]
CHR Extension: (Run Pixie Run) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\gfkmokjholoinfcnlolbjfaokmoegeoh [2016-02-12]
CHR Extension: (Google dokumenti izvanmrežno) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15]
CHR Extension: (mixMovie Start) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghfmhofojkkfdnlfefhkckbflohgiicn [2016-12-10]
CHR Extension: (MotorAuthority in Pictures) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\iejnbmehnhkijljppacclfbmkncnaekh [2016-02-12]
CHR Extension: (WowMovix) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjkofiknkjdjgkkbfdibgajealfbjhdj [2016-12-28]
CHR Extension: (Autodesk Homestyler) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdmmkfaghgcicheaimnpffeeekheafkb [2016-08-17]
CHR Extension: (MusiXhunt - Besplatno Glazba Traži) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\kioickjjacfgafgihoghdilimjlbofnk [2016-04-25]
CHR Extension: (Google Karte) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2016-02-12]
CHR Extension: (FromDocToPDF) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\mallpejgeafdahhflmliiahjdpgbegpk [2016-09-29]
CHR Extension: (Planner 5D - Interior Design) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcafejemebbngbglfoinpoaannbihjna [2016-09-07]
CHR Extension: (English vocabulary) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgmklfohhllfpjjmjejencmaodgiknmj [2016-02-12]
CHR Extension: (WGT Golf Game) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpedbpkelbhcbkdaglillalioeeekbpb [2016-02-12]
CHR Extension: (PixFiltre - Photo Editor) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\nebhanlkihgdilmhiaiaclanodcalglc [2016-04-25]
CHR Extension: (Plaćanja u web-trgovini Chrome) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR Extension: (Foto Rulez) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\odahhdimpaeigjcdbgcnhemlkejclmmk [2016-04-25]
CHR Extension: (Gmail) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-02-12]
CHR Extension: (Chrome Media Router) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-16]
CHR Profile: C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Profile 1 [2017-01-14]
CHR Extension: (Google Slides) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-12-17]
CHR Extension: (Google Docs) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2016-12-17]
CHR Extension: (Google disk) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-12-17]
CHR Extension: (YouTube) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-12-17]
CHR Extension: (Google Sheets) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-12-17]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2016-12-17]
CHR Extension: (Avira Browser Safety) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-12-17]
CHR Extension: (Google dokumenti izvanmrežno) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-12-17]
CHR Extension: (Tes) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mckeobeegjkmddfheckidbpafkeokkan [2016-12-20]
CHR Extension: (FilmFanatic) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\niojcggonafbneajjmkpkcigabaobmge [2017-01-04]
CHR Extension: (Plaćanja u web-trgovini Chrome) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-12-17]
CHR Extension: (Gmail) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-12-17]
CHR Extension: (Chrome Media Router) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-17]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AvgAMPS; C:\Program Files\AVG\Av\avgamps.exe [971160 2016-12-15] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Program Files\AVG\Av\avgidsagent.exe [4154016 2016-12-15] (AVG Technologies CZ, s.r.o.)
R2 avgsvc; C:\Program Files\AVG\Framework\Common\avgsvcx.exe [935184 2016-12-06] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\Av\avgwdsvcx.exe [603288 2016-12-15] (AVG Technologies CZ, s.r.o.)
R2 ByteFenceService; C:\Program Files\ByteFence\ByteFenceService.exe [145888 2016-10-05] (Byte Technologies LLC)
R2 McAfee SiteAdvisor Service; C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [160800 2016-12-12] (McAfee, Inc.)
R2 ReimageRealTimeProtector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [6542704 2016-11-06] (Reimage®)
R2 rtop; C:\Program Files\ByteFence\rtop\bin\rtop_svc.exe [254280 2016-11-26] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
R2 WtuSystemSupport; C:\Program Files\AVG Web TuneUp\WtuSystemSupport.exe [980552 2016-12-09] ()
S2 SkypeUpdate; "C:\Program Files\Skype\Updater\Updater.exe" [X]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [271360 2016-08-04] () [File not signed]
R1 Avgdiskx; C:\Windows\System32\DRIVERS\avgdiskx.sys [134912 2016-05-13] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [259328 2016-11-04] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [207616 2016-10-05] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [31664 2015-11-20] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [244992 2016-11-30] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [287008 2016-02-16] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [197376 2016-09-26] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [47360 2016-06-01] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [231680 2016-07-27] (AVG Technologies CZ, s.r.o.)
R0 avgunivx; C:\Windows\System32\DRIVERS\avgunivx.sys [65280 2016-06-20] (AVG Technologies CZ, s.r.o.)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [18048 2016-08-04] () [File not signed]
R3 mfesapsn; C:\Program Files\McAfee\SiteAdvisor\mfesapsn.sys [41600 2016-06-06] (McAfee, Inc.)
R1 SCDEmu; C:\Windows\system32\Drivers\SCDEmu.sys [123968 2016-10-02] (Power Software Ltd)
S1 ISODrive; \??\C:\Program Files\UltraISO\drivers\ISODrive.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-01-14 18:53 - 2017-01-14 18:56 - 00023418 _____ C:\Users\pc centar\Downloads\FRST.txt
2017-01-14 18:52 - 2017-01-14 18:53 - 00000000 ____D C:\FRST
2017-01-14 18:51 - 2017-01-14 18:51 - 00001405 _____ C:\Users\pc centar\Desktop\FRST - Shortcut.lnk
2017-01-14 18:49 - 2017-01-14 18:50 - 01761280 _____ (Farbar) C:\Users\pc centar\Downloads\FRST.exe
2017-01-14 16:34 - 2017-01-14 16:34 - 00000000 ____D C:\Users\pc centar\Downloads\gta
2017-01-14 16:00 - 2017-01-14 16:00 - 206816910 _____ C:\Windows\MEMORY.DMP
2017-01-14 16:00 - 2017-01-14 16:00 - 00141832 _____ C:\Windows\Minidump\011417-46593-01.dmp
2017-01-13 18:12 - 2017-01-14 16:24 - 00000000 ____D C:\Users\pc centar\AppData\LocalLow\uTorrent
2017-01-11 21:45 - 2017-01-05 18:46 - 00137960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2017-01-11 21:45 - 2017-01-05 18:46 - 00067304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2017-01-11 21:45 - 2017-01-05 18:43 - 01062912 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-01-11 21:45 - 2017-01-05 18:43 - 00655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2017-01-11 21:45 - 2017-01-05 18:43 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-01-11 21:45 - 2017-01-05 18:43 - 00261120 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-01-11 21:45 - 2017-01-05 18:43 - 00254464 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2017-01-11 21:45 - 2017-01-05 18:43 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2017-01-11 21:45 - 2017-01-05 18:43 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2017-01-11 21:45 - 2017-01-05 18:43 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2017-01-11 21:45 - 2017-01-05 18:43 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2017-01-11 21:45 - 2017-01-05 18:43 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2017-01-11 21:45 - 2017-01-05 18:43 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2017-01-11 21:45 - 2017-01-05 18:43 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2017-01-11 21:45 - 2017-01-05 18:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2017-01-11 21:45 - 2017-01-05 18:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2017-01-11 21:45 - 2017-01-05 18:43 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2017-01-11 21:45 - 2017-01-05 18:42 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2017-01-11 21:45 - 2017-01-05 18:23 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2017-01-11 21:45 - 2017-01-05 18:19 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-01-11 21:45 - 2017-01-05 18:19 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2017-01-11 21:45 - 2017-01-05 18:19 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-01-11 21:45 - 2017-01-05 18:19 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2017-01-11 21:45 - 2017-01-05 18:19 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2017-01-11 21:45 - 2017-01-05 18:19 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2017-01-09 14:08 - 2017-01-09 14:08 - 00004097 _____ C:\1192.dummy.000
2017-01-05 10:34 - 2017-01-05 10:34 - 00000000 __SHD C:\found.003
2017-01-04 22:30 - 2017-01-04 22:37 - 00000000 ____D C:\ProgramData\Reimage Protector
2017-01-04 22:30 - 2017-01-04 22:33 - 00000000 ____D C:\Program Files\Reimage
2017-01-04 22:30 - 2017-01-04 22:30 - 00002092 _____ C:\Users\Public\Desktop\PC Scan & Repair by Reimage.lnk
2017-01-04 22:30 - 2017-01-04 22:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair
2017-01-04 22:29 - 2017-01-04 22:38 - 00000000 ____D C:\rei
2017-01-04 22:26 - 2017-01-04 22:38 - 00000111 _____ C:\Windows\Reimage.ini
2017-01-02 12:50 - 2017-01-02 13:34 - 643655680 _____ C:\Users\pc centar\Downloads\need for speed hot pursuit 2.iso
2017-01-02 12:11 - 2016-11-20 17:19 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\hlink.dll
2017-01-02 12:11 - 2016-11-20 15:07 - 00373896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2017-01-02 12:11 - 2016-11-17 17:27 - 00250600 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2017-01-02 12:11 - 2016-11-14 23:39 - 00346320 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2017-01-02 12:11 - 2016-11-12 19:30 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2017-01-02 12:11 - 2016-11-12 19:29 - 00498688 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-01-02 12:11 - 2016-11-12 19:29 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2017-01-02 12:11 - 2016-11-12 19:29 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2017-01-02 12:11 - 2016-11-12 19:27 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2017-01-02 12:11 - 2016-11-12 19:20 - 02287616 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-01-02 12:11 - 2016-11-12 19:20 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2017-01-02 12:11 - 2016-11-12 19:19 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2017-01-02 12:11 - 2016-11-12 19:17 - 20302848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-01-02 12:11 - 2016-11-12 19:15 - 00476160 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-01-02 12:11 - 2016-11-12 19:15 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2017-01-02 12:11 - 2016-11-12 19:14 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-01-02 12:11 - 2016-11-12 19:14 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-01-02 12:11 - 2016-11-12 19:14 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2017-01-02 12:11 - 2016-11-12 19:06 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2017-01-02 12:11 - 2016-11-12 19:03 - 00416256 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2017-01-02 12:11 - 2016-11-12 18:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-01-02 12:11 - 2016-11-12 18:56 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2017-01-02 12:11 - 2016-11-12 18:52 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2017-01-02 12:11 - 2016-11-12 18:51 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-01-02 12:11 - 2016-11-12 18:49 - 00279040 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-01-02 12:11 - 2016-11-12 18:47 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2017-01-02 12:11 - 2016-11-12 18:40 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2017-01-02 12:11 - 2016-11-12 18:38 - 00693248 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-01-02 12:11 - 2016-11-12 18:38 - 00689664 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-01-02 12:11 - 2016-11-12 18:37 - 04608000 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-01-02 12:11 - 2016-11-12 18:36 - 02055680 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-01-02 12:11 - 2016-11-12 18:36 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2017-01-02 12:11 - 2016-11-12 18:21 - 13653504 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-01-02 12:11 - 2016-11-12 18:05 - 02444800 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-01-02 12:11 - 2016-11-12 18:02 - 01312256 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-01-02 12:11 - 2016-11-12 18:02 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-01-02 12:11 - 2016-11-10 17:19 - 00811520 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2017-01-02 12:11 - 2016-11-09 17:24 - 00105192 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2017-01-02 12:11 - 2016-11-09 17:17 - 02365440 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2017-01-02 12:11 - 2016-11-09 17:17 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2017-01-02 12:11 - 2016-11-09 17:17 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2017-01-02 12:11 - 2016-11-09 17:17 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2017-01-02 12:11 - 2016-11-09 17:17 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll
2017-01-02 12:11 - 2016-11-09 16:55 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2017-01-02 12:11 - 2016-11-06 17:16 - 00306688 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2017-01-02 12:11 - 2016-11-06 16:55 - 02399744 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-01-02 12:11 - 2016-10-27 16:20 - 00627712 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2017-01-02 12:11 - 2016-10-11 16:24 - 04000488 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2017-01-02 12:11 - 2016-10-11 16:24 - 03944680 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-01-02 12:11 - 2016-10-11 16:21 - 01310528 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-01-02 12:11 - 2016-10-11 16:18 - 00644096 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2017-01-02 12:11 - 2016-10-11 16:18 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2017-01-02 12:11 - 2016-10-11 16:18 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\nlsbres.dll
2017-01-02 12:11 - 2016-10-11 16:18 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2017-01-02 12:11 - 2016-10-11 16:18 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2017-01-02 12:11 - 2016-10-11 16:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2017-01-02 12:11 - 2016-10-11 16:18 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-01-02 12:11 - 2016-10-11 16:18 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2017-01-02 12:11 - 2016-10-11 15:55 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2017-01-02 12:11 - 2016-10-11 15:55 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2017-01-02 12:11 - 2016-10-11 15:55 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2017-01-02 12:11 - 2016-10-11 15:55 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2017-01-02 12:11 - 2016-10-11 15:53 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2017-01-02 12:11 - 2016-10-11 15:51 - 00295936 _____ (Microsoft Corporation) C:\Windows\system32\bcdedit.exe
2017-01-02 12:11 - 2016-10-11 15:50 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2017-01-02 12:11 - 2016-10-11 14:18 - 00419648 _____ C:\Windows\system32\locale.nls
2017-01-02 12:11 - 2016-10-08 14:05 - 00534600 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2017-01-02 12:11 - 2016-10-04 16:13 - 01176064 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2017-01-02 12:11 - 2016-10-04 16:13 - 00179200 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2017-01-02 12:11 - 2016-10-04 16:13 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2017-01-02 12:11 - 2016-10-04 16:13 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2017-01-02 12:10 - 2016-11-12 19:47 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2017-01-02 12:10 - 2016-11-12 19:47 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2017-01-02 12:10 - 2016-11-09 17:17 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2016-12-29 21:14 - 2016-12-29 21:14 - 00028588 _____ C:\Users\pc centar\Desktop\jhSCJKSACVSajgvc.PNG
2016-12-29 21:14 - 2016-12-29 21:14 - 00009688 _____ C:\Users\pc centar\Documents\SADF.xlsx
2016-12-29 19:36 - 2016-12-30 09:28 - 00000000 ____D C:\Users\pc centar\AppData\Local\FSDART
2016-12-29 19:36 - 2016-12-29 20:03 - 00000000 ____D C:\ProgramData\F-Secure
2016-12-25 18:38 - 2016-12-25 18:38 - 00055396 _____ C:\Users\pc centar\Desktop\2012_03_19_igraonica_twister_03_400.jpg

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-01-14 18:56 - 2016-11-26 11:52 - 00000000 ____D C:\Program Files\ByteFence
2017-01-14 18:56 - 2016-02-12 18:41 - 00000000 ____D C:\Users\pc centar\AppData\Roaming\uTorrent
2017-01-14 18:53 - 2016-02-12 21:29 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2017-01-14 18:32 - 2016-11-18 10:26 - 00000000 ____D C:\Users\pc centar\AppData\LocalLow\Mozilla
2017-01-14 18:24 - 2009-07-14 05:34 - 00020656 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-01-14 18:24 - 2009-07-14 05:34 - 00020656 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-01-14 16:28 - 2016-02-12 14:00 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2017-01-14 16:25 - 2016-11-24 10:04 - 00000000 ____D C:\Users\pc centar\AppData\Local\PlutoTV
2017-01-14 16:21 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-01-14 16:06 - 2016-03-09 15:32 - 00000000 ____D C:\ProgramData\MFAData
2017-01-14 16:00 - 2016-03-23 18:08 - 00000000 ____D C:\Windows\Minidump
2017-01-12 11:03 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\rescache
2017-01-11 22:34 - 2016-09-16 11:10 - 00000000 ____D C:\Windows\system32\MRT
2017-01-11 22:27 - 2016-09-16 11:09 - 133456224 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-01-10 15:54 - 2016-02-12 21:29 - 00802904 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2017-01-10 15:54 - 2016-02-12 21:29 - 00144472 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2017-01-10 15:54 - 2016-02-12 21:29 - 00000000 ____D C:\Windows\system32\Macromed
2017-01-05 10:49 - 2010-11-20 22:01 - 00778834 _____ C:\Windows\system32\PerfStringBackup.INI
2017-01-05 10:49 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\inf
2017-01-05 10:41 - 2009-07-14 05:33 - 00406048 _____ C:\Windows\system32\FNTCACHE.DAT
2017-01-02 23:27 - 2016-04-22 18:50 - 00000906 _____ C:\Users\Public\Desktop\AVG Protection.lnk
2017-01-02 23:27 - 2016-04-22 18:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2017-01-02 13:50 - 2016-08-08 10:38 - 00000000 ____D C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2016-12-30 11:49 - 2016-02-12 10:53 - 00000000 ____D C:\ProgramData\Skype
2016-12-29 21:14 - 2016-02-12 10:23 - 00000000 ___RD C:\Users\pc centar\Documents
2016-12-29 20:45 - 2016-09-21 08:45 - 00000000 ____D C:\Users\pc centar\Documents\Euro Truck Simulator
2016-12-29 18:00 - 2016-11-17 23:27 - 00000000 ____D C:\Program Files\Mozilla Firefox
2016-12-29 18:00 - 2016-11-12 13:00 - 00004936 _____ C:\Windows\PFRO.log
2016-12-29 18:00 - 2016-02-12 21:00 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2016-12-26 20:41 - 2016-11-16 11:09 - 00000000 ____D C:\Program Files\McAfee
2016-12-25 14:46 - 2016-06-17 21:14 - 00000000 ____D C:\Users\pc centar\Documents\Bandicam
2016-12-16 22:07 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\Tasks
2016-12-16 22:04 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\wdi

==================== Files in the root of some directories =======

2016-08-23 10:49 - 2016-08-23 10:49 - 7118336 _____ () C:\Users\pc centar\AppData\Roaming\agent.dat
2016-08-23 10:48 - 2016-08-23 10:48 - 0054272 _____ () C:\Users\pc centar\AppData\Roaming\ApplicationHosting.dat
2016-08-23 10:49 - 2016-08-23 10:49 - 0070704 _____ () C:\Users\pc centar\AppData\Roaming\Config.xml
2016-08-23 10:49 - 2016-08-23 10:49 - 1902415 _____ () C:\Users\pc centar\AppData\Roaming\Dentophase.tst
2016-08-23 10:47 - 2016-08-23 10:48 - 0019536 _____ () C:\Users\pc centar\AppData\Roaming\InstallationConfiguration.xml
2016-08-23 10:47 - 2016-08-23 10:47 - 0138240 _____ () C:\Users\pc centar\AppData\Roaming\Installer.dat
2016-08-23 10:48 - 2016-08-23 10:48 - 0126464 _____ () C:\Users\pc centar\AppData\Roaming\lobby.dat
2016-08-23 10:49 - 2016-08-23 10:49 - 0018432 _____ () C:\Users\pc centar\AppData\Roaming\Main.dat
2016-08-23 10:48 - 2016-08-23 10:49 - 0005568 _____ () C:\Users\pc centar\AppData\Roaming\md.xml
2016-08-23 10:49 - 2016-08-23 10:49 - 0126464 _____ () C:\Users\pc centar\AppData\Roaming\noah.dat
2016-08-23 10:49 - 2016-08-23 10:49 - 0136816 _____ () C:\Users\pc centar\AppData\Roaming\Strongcore.bin
2016-08-23 10:50 - 2016-08-23 10:50 - 0001150 _____ () C:\Users\pc centar\AppData\Roaming\uninstall_temp.ico
2016-08-23 10:48 - 2016-08-23 10:48 - 0072822 _____ () C:\Users\pc centar\AppData\Roaming\Unodox.tst
2016-06-09 13:36 - 2016-07-07 12:25 - 0007168 _____ () C:\Users\pc centar\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

Some files in TEMP:
====================
C:\Users\pc centar\AppData\Local\Temp\bdfilters.dll
C:\Users\pc centar\AppData\Local\Temp\SecuExp.exe
C:\Users\pc centar\AppData\Local\Temp\Uninstall.exe


==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-01-13 21:34

==================== End of FRST.txt ============================
mycity.rs/must-login.png

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Arrow Korak 1

Deinstaliraj:

ByteFence Anti-Malware
Reimage Repair





Arrow Korak 2

Otvori Notepad i iskopiraj sljedeći tekst koji se nalazi unutar Kod polja.

ManualProxies: 0hxxp://non-block.net/wpad.dat?daa497be4f804785fecef8edc08dc40516899964
SearchScopes: HKLM -> ielnksrch URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIP4NYe17aVLWqePRm9wWNFlj_H85KLF3AwPTCF6y7Re08UHjnLYLUXqFPF3ccdxQUNq7xvV5PrnVlDziyJ1KJvpibaXLci-bxmq7ySESazh5EHSvCrT-JPQRVDhLTjmZdQNo9DKXfvWI5Ur3_ry1bozPHjIsUsloZi2EOmO2Tyjd4giudZmT&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1757366166-212622331-2855360578-1000 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIP4NYe17aVLWqePRm9wWNFlj_H85KLF3AwPTCF6y7Re08UHjnLYLUXqFPF3ccdxQUNq7xvV5PrnVlDziyJ1KJvpibaXLci-bxmq7ySESazh5EHSvCrT-JPQRVDhLTjmZdQNo9DKXfvWI5Ur3_ry1bozPHjIsUsloZi2EOmO2Tyjd4giudZmT&q={searchTerms}
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\1163194288.js [2016-09-21] <==== ATTENTION (Points to *.cfg file)
FF ExtraCheck: C:\Program Files\mozilla firefox\1163194288.cfg [2016-09-21] <==== ATTENTION
CHR Extension: (WowMovix) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjkofiknkjdjgkkbfdibgajealfbjhdj [2016-12-28]
CHR Extension: (FromDocToPDF) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\mallpejgeafdahhflmliiahjdpgbegpk [2016-09-29]
CHR Extension: (FilmFanatic) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\niojcggonafbneajjmkpkcigabaobmge [2017-01-04]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
Shortcut: C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Intеrnеt Ехрlоrеr.lnk -> C:\Users\pc centar\AppData\Roaming\HPRewriter2\RewRun3.exe (No File) <===== Cyrillic
Shortcut: C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacije sustava Chrome\Fасеbооk Соlоr & Васkgrоund Сhаngеr.lnk -> C:\Users\pc centar\AppData\Roaming\HPRewriter2\RewRun3.exe (No File) <===== Cyrillic
Shortcut: C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacije sustava Chrome\Run Рiхiе Run.lnk -> C:\Users\pc centar\AppData\Roaming\HPRewriter2\RewRun3.exe (No File) <===== Cyrillic
Shortcut: C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacije sustava Chrome\WеаthеrВug.lnk -> C:\Users\pc centar\AppData\Roaming\HPRewriter2\RewRun3.exe (No File) <===== Cyrillic
Shortcut: C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Intеrnеt Ехрlоrеr (Nо Аdd-оns).lnk -> C:\Users\pc centar\AppData\Roaming\HPRewriter2\RewRun3.exe (No File) <===== Cyrillic
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gооglе Сhrоmе.lnk -> C:\Users\pc centar\AppData\Roaming\HPRewriter2\RewRun3.exe (No File) <===== Cyrillic
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Моzillа Firеfох.lnk -> C:\Users\pc centar\AppData\Roaming\HPRewriter2\RewRun3.exe (No File) <===== Cyrillic
Shortcut: C:\Users\Public\Desktop\Gооglе Сhrоmе.lnk -> C:\Users\pc centar\AppData\Roaming\HPRewriter2\RewRun3.exe (No File) <===== Cyrillic
Shortcut: C:\Users\Public\Desktop\Моzillа Firеfох.lnk -> C:\Users\pc centar\AppData\Roaming\HPRewriter2\RewRun3.exe (No File) <===== Cyrillic
ShortcutWithArgument: C:\Users\pc centar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> "hxxp://tech-connect.biz/?ssid=1474443729&a=1002803&src=sh&uuid=60acef26-cf81-4e40-a3e2-86ac3821db8c,1474443633830"
ShortcutWithArgument: C:\Users\pc centar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> "hxxp://tech-connect.biz/?ssid=1474443729&a=1002803&src=sh&uuid=60acef26-cf81-4e40-a3e2-86ac3821db8c,1474443633830"
ShortcutWithArgument: C:\Users\pc centar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Gооglе Сhrоmе.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> "hxxp://tech-connect.biz/?ssid=1474443729&a=1002803&src=sh&uuid=60acef26-cf81-4e40-a3e2-86ac3821db8c,1474443633830"
ShortcutWithArgument: C:\Users\pc centar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Intеrnеt Ехрlоrеr.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> 3 0 <===== Cyrillic
ShortcutWithArgument: C:\Users\pc centar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Моzillа Firеfох.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> "hxxp://tech-connect.biz/?ssid=1474443729&a=1002803&src=sh&uuid=60acef26-cf81-4e40-a3e2-86ac3821db8c,1474443633830"
ShortcutWithArgument: C:\Users\pc centar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Profile 1"
EmptyTemp:


U okviru Notepad-a klikni na File --> Save As
Pod Encoding izaberi UTF-8.
Fajl nazovi Fixlist i sačuvaj na Desktop
Dvoklikom ponovo pokreni FRST.exe
Klikni na Fix i sačekaj dok program ne završi.
Ukoliko program zatraži restart računara, omogući mu da to nesmetano obavi.
Nakon završetka rada, otvoriće se fixlog.txt, sa sadržajem koji treba da kopiraš u temu.
Takođe, na Desktop-u će se nalaziti (fixlog.txt).

offline
  • Pridružio: 27 Sep 2013
  • Poruke: 94

Napisano: 14 Jan 2017 20:29

Fix result of Farbar Recovery Scan Tool (x86) Version: 14-01-2017
Ran by pc centar (14-01-2017 20:00:30) Run:1
Running from C:\Users\pc centar\Desktop
Loaded Profiles: pc centar (Available Profiles: pc centar)
Boot Mode: Normal

==============================================

fixlist content:
*****************
ManualProxies: 0hxxp://non-block.net/wpad.dat?daa497be4f804785fecef8edc08dc40516899964
SearchScopes: HKLM -> ielnksrch URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIP4NYe17aVLWqePRm9wWNFlj_H85KLF3AwPTCF6y7Re08UHjnLYLUXqFPF3ccdxQUNq7xvV5PrnVlDziyJ1KJvpibaXLci-bxmq7ySESazh5EHSvCrT-JPQRVDhLTjmZdQNo9DKXfvWI5Ur3_ry1bozPHjIsUsloZi2EOmO2Tyjd4giudZmT&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1757366166-212622331-2855360578-1000 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIP4NYe17aVLWqePRm9wWNFlj_H85KLF3AwPTCF6y7Re08UHjnLYLUXqFPF3ccdxQUNq7xvV5PrnVlDziyJ1KJvpibaXLci-bxmq7ySESazh5EHSvCrT-JPQRVDhLTjmZdQNo9DKXfvWI5Ur3_ry1bozPHjIsUsloZi2EOmO2Tyjd4giudZmT&q={searchTerms}
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\1163194288.js [2016-09-21] <==== ATTENTION (Points to *.cfg file)
FF ExtraCheck: C:\Program Files\mozilla firefox\1163194288.cfg [2016-09-21] <==== ATTENTION
CHR Extension: (WowMovix) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjkofiknkjdjgkkbfdibgajealfbjhdj [2016-12-28]
CHR Extension: (FromDocToPDF) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\mallpejgeafdahhflmliiahjdpgbegpk [2016-09-29]
CHR Extension: (FilmFanatic) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\niojcggonafbneajjmkpkcigabaobmge [2017-01-04]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
Shortcut: C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Intеrnеt Ехрlоrеr.lnk -> C:\Users\pc centar\AppData\Roaming\HPRewriter2\RewRun3.exe (No File) <===== Cyrillic
Shortcut: C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacije sustava Chrome\Fасеbооk Соlоr & Васkgrоund Сhаngеr.lnk -> C:\Users\pc centar\AppData\Roaming\HPRewriter2\RewRun3.exe (No File) <===== Cyrillic
Shortcut: C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacije sustava Chrome\Run Рiхiе Run.lnk -> C:\Users\pc centar\AppData\Roaming\HPRewriter2\RewRun3.exe (No File) <===== Cyrillic
Shortcut: C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacije sustava Chrome\WеаthеrВug.lnk -> C:\Users\pc centar\AppData\Roaming\HPRewriter2\RewRun3.exe (No File) <===== Cyrillic
Shortcut: C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Intеrnеt Ехрlоrеr (Nо Аdd-оns).lnk -> C:\Users\pc centar\AppData\Roaming\HPRewriter2\RewRun3.exe (No File) <===== Cyrillic
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gооglе Сhrоmе.lnk -> C:\Users\pc centar\AppData\Roaming\HPRewriter2\RewRun3.exe (No File) <===== Cyrillic
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Моzillа Firеfох.lnk -> C:\Users\pc centar\AppData\Roaming\HPRewriter2\RewRun3.exe (No File) <===== Cyrillic
Shortcut: C:\Users\Public\Desktop\Gооglе Сhrоmе.lnk -> C:\Users\pc centar\AppData\Roaming\HPRewriter2\RewRun3.exe (No File) <===== Cyrillic
Shortcut: C:\Users\Public\Desktop\Моzillа Firеfох.lnk -> C:\Users\pc centar\AppData\Roaming\HPRewriter2\RewRun3.exe (No File) <===== Cyrillic
ShortcutWithArgument: C:\Users\pc centar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> "hxxp://tech-connect.biz/?ssid=1474443729&a=1002803&src=sh&uuid=60acef26-cf81-4e40-a3e2-86ac3821db8c,1474443633830"
ShortcutWithArgument: C:\Users\pc centar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> "hxxp://tech-connect.biz/?ssid=1474443729&a=1002803&src=sh&uuid=60acef26-cf81-4e40-a3e2-86ac3821db8c,1474443633830"
ShortcutWithArgument: C:\Users\pc centar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Gооglе Сhrоmе.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> "hxxp://tech-connect.biz/?ssid=1474443729&a=1002803&src=sh&uuid=60acef26-cf81-4e40-a3e2-86ac3821db8c,1474443633830"
ShortcutWithArgument: C:\Users\pc centar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Intеrnеt Ехрlоrеr.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> 3 0 <===== Cyrillic
ShortcutWithArgument: C:\Users\pc centar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Моzillа Firеfох.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> "hxxp://tech-connect.biz/?ssid=1474443729&a=1002803&src=sh&uuid=60acef26-cf81-4e40-a3e2-86ac3821db8c,1474443633830"
ShortcutWithArgument: C:\Users\pc centar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Profile 1"
EmptyTemp:

*****************

HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies\\ => value removed successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\ielnksrch => key removed successfully.
HKCR\CLSID\ielnksrch => key not found.
HKU\S-1-5-21-1757366166-212622331-2855360578-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ielnksrch} => key removed successfully.
HKCR\CLSID\{ielnksrch} => key not found.
C:\Program Files\mozilla firefox\defaults\pref\1163194288.js => moved successfully
C:\Program Files\mozilla firefox\1163194288.cfg => moved successfully
C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjkofiknkjdjgkkbfdibgajealfbjhdj => moved successfully
C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\mallpejgeafdahhflmliiahjdpgbegpk => moved successfully
C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\niojcggonafbneajjmkpkcigabaobmge => moved successfully
HKLM\SOFTWARE\Google\Chrome\Extensions\fheoggkfdfchfphceeifdbepaooicaho => key not found.
C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Intеrnеt Ехрlоrеr.lnk => moved successfully
C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacije sustava Chrome\Fасеbооk Соlоr & Васkgrоund Сhаngеr.lnk => moved successfully
C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacije sustava Chrome\Run Рiхiе Run.lnk => moved successfully
C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacije sustava Chrome\WеаthеrВug.lnk => moved successfully
C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Intеrnеt Ехрlоrеr (Nо Аdd-оns).lnk => moved successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gооglе Сhrоmе.lnk => moved successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Моzillа Firеfох.lnk => moved successfully
C:\Users\Public\Desktop\Gооglе Сhrоmе.lnk => moved successfully
C:\Users\Public\Desktop\Моzillа Firеfох.lnk => moved successfully
C:\Users\pc centar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk => Shortcut argument removed successfully..
C:\Users\pc centar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => Shortcut argument removed successfully..
C:\Users\pc centar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Gооglе Сhrоmе.lnk => Shortcut argument removed successfully..
C:\Users\pc centar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Intеrnеt Ехрlоrеr.lnk => Shortcut argument removed successfully..
C:\Users\pc centar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Моzillа Firеfох.lnk => Shortcut argument removed successfully..
C:\Users\pc centar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk => Shortcut argument removed successfully..

=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStoree, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 71443534 B
Java, Flash, Steam htmlcache => 2255 B
Windows/system/drivers => 106716823 B
Edge => 0 B
Chrome => 467528644 B
Firefox => 377084111 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 16384 B
Public => 0 B
ProgramData => 0 B
systemprofile => 29550862 B
LocalService => 66228 B
NetworkService => 0 B
pc centar => 2395278349 B

RecycleBin => 0 B
EmptyTemp: => 3.2 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 20:01:33 ====

Dopuna: 14 Jan 2017 20:29

Fix result of Farbar Recovery Scan Tool (x86) Version: 14-01-2017
Ran by pc centar (14-01-2017 20:00:30) Run:1
Running from C:\Users\pc centar\Desktop
Loaded Profiles: pc centar (Available Profiles: pc centar)
Boot Mode: Normal

==============================================

fixlist content:
*****************
ManualProxies: 0hxxp://non-block.net/wpad.dat?daa497be4f804785fecef8edc08dc40516899964
SearchScopes: HKLM -> ielnksrch URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIP4NYe17aVLWqePRm9wWNFlj_H85KLF3AwPTCF6y7Re08UHjnLYLUXqFPF3ccdxQUNq7xvV5PrnVlDziyJ1KJvpibaXLci-bxmq7ySESazh5EHSvCrT-JPQRVDhLTjmZdQNo9DKXfvWI5Ur3_ry1bozPHjIsUsloZi2EOmO2Tyjd4giudZmT&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1757366166-212622331-2855360578-1000 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIP4NYe17aVLWqePRm9wWNFlj_H85KLF3AwPTCF6y7Re08UHjnLYLUXqFPF3ccdxQUNq7xvV5PrnVlDziyJ1KJvpibaXLci-bxmq7ySESazh5EHSvCrT-JPQRVDhLTjmZdQNo9DKXfvWI5Ur3_ry1bozPHjIsUsloZi2EOmO2Tyjd4giudZmT&q={searchTerms}
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\1163194288.js [2016-09-21] <==== ATTENTION (Points to *.cfg file)
FF ExtraCheck: C:\Program Files\mozilla firefox\1163194288.cfg [2016-09-21] <==== ATTENTION
CHR Extension: (WowMovix) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjkofiknkjdjgkkbfdibgajealfbjhdj [2016-12-28]
CHR Extension: (FromDocToPDF) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\mallpejgeafdahhflmliiahjdpgbegpk [2016-09-29]
CHR Extension: (FilmFanatic) - C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\niojcggonafbneajjmkpkcigabaobmge [2017-01-04]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
Shortcut: C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Intеrnеt Ехрlоrеr.lnk -> C:\Users\pc centar\AppData\Roaming\HPRewriter2\RewRun3.exe (No File) <===== Cyrillic
Shortcut: C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacije sustava Chrome\Fасеbооk Соlоr & Васkgrоund Сhаngеr.lnk -> C:\Users\pc centar\AppData\Roaming\HPRewriter2\RewRun3.exe (No File) <===== Cyrillic
Shortcut: C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacije sustava Chrome\Run Рiхiе Run.lnk -> C:\Users\pc centar\AppData\Roaming\HPRewriter2\RewRun3.exe (No File) <===== Cyrillic
Shortcut: C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacije sustava Chrome\WеаthеrВug.lnk -> C:\Users\pc centar\AppData\Roaming\HPRewriter2\RewRun3.exe (No File) <===== Cyrillic
Shortcut: C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Intеrnеt Ехрlоrеr (Nо Аdd-оns).lnk -> C:\Users\pc centar\AppData\Roaming\HPRewriter2\RewRun3.exe (No File) <===== Cyrillic
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gооglе Сhrоmе.lnk -> C:\Users\pc centar\AppData\Roaming\HPRewriter2\RewRun3.exe (No File) <===== Cyrillic
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Моzillа Firеfох.lnk -> C:\Users\pc centar\AppData\Roaming\HPRewriter2\RewRun3.exe (No File) <===== Cyrillic
Shortcut: C:\Users\Public\Desktop\Gооglе Сhrоmе.lnk -> C:\Users\pc centar\AppData\Roaming\HPRewriter2\RewRun3.exe (No File) <===== Cyrillic
Shortcut: C:\Users\Public\Desktop\Моzillа Firеfох.lnk -> C:\Users\pc centar\AppData\Roaming\HPRewriter2\RewRun3.exe (No File) <===== Cyrillic
ShortcutWithArgument: C:\Users\pc centar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> "hxxp://tech-connect.biz/?ssid=1474443729&a=1002803&src=sh&uuid=60acef26-cf81-4e40-a3e2-86ac3821db8c,1474443633830"
ShortcutWithArgument: C:\Users\pc centar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> "hxxp://tech-connect.biz/?ssid=1474443729&a=1002803&src=sh&uuid=60acef26-cf81-4e40-a3e2-86ac3821db8c,1474443633830"
ShortcutWithArgument: C:\Users\pc centar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Gооglе Сhrоmе.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> "hxxp://tech-connect.biz/?ssid=1474443729&a=1002803&src=sh&uuid=60acef26-cf81-4e40-a3e2-86ac3821db8c,1474443633830"
ShortcutWithArgument: C:\Users\pc centar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Intеrnеt Ехрlоrеr.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> 3 0 <===== Cyrillic
ShortcutWithArgument: C:\Users\pc centar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Моzillа Firеfох.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> "hxxp://tech-connect.biz/?ssid=1474443729&a=1002803&src=sh&uuid=60acef26-cf81-4e40-a3e2-86ac3821db8c,1474443633830"
ShortcutWithArgument: C:\Users\pc centar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Profile 1"
EmptyTemp:

*****************

HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies\\ => value removed successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\ielnksrch => key removed successfully.
HKCR\CLSID\ielnksrch => key not found.
HKU\S-1-5-21-1757366166-212622331-2855360578-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ielnksrch} => key removed successfully.
HKCR\CLSID\{ielnksrch} => key not found.
C:\Program Files\mozilla firefox\defaults\pref\1163194288.js => moved successfully
C:\Program Files\mozilla firefox\1163194288.cfg => moved successfully
C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjkofiknkjdjgkkbfdibgajealfbjhdj => moved successfully
C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Default\Extensions\mallpejgeafdahhflmliiahjdpgbegpk => moved successfully
C:\Users\pc centar\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\niojcggonafbneajjmkpkcigabaobmge => moved successfully
HKLM\SOFTWARE\Google\Chrome\Extensions\fheoggkfdfchfphceeifdbepaooicaho => key not found.
C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Intеrnеt Ехрlоrеr.lnk => moved successfully
C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacije sustava Chrome\Fасеbооk Соlоr & Васkgrоund Сhаngеr.lnk => moved successfully
C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacije sustava Chrome\Run Рiхiе Run.lnk => moved successfully
C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacije sustava Chrome\WеаthеrВug.lnk => moved successfully
C:\Users\pc centar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Intеrnеt Ехрlоrеr (Nо Аdd-оns).lnk => moved successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gооglе Сhrоmе.lnk => moved successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Моzillа Firеfох.lnk => moved successfully
C:\Users\Public\Desktop\Gооglе Сhrоmе.lnk => moved successfully
C:\Users\Public\Desktop\Моzillа Firеfох.lnk => moved successfully
C:\Users\pc centar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk => Shortcut argument removed successfully..
C:\Users\pc centar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => Shortcut argument removed successfully..
C:\Users\pc centar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Gооglе Сhrоmе.lnk => Shortcut argument removed successfully..
C:\Users\pc centar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Intеrnеt Ехрlоrеr.lnk => Shortcut argument removed successfully..
C:\Users\pc centar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Моzillа Firеfох.lnk => Shortcut argument removed successfully..
C:\Users\pc centar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk => Shortcut argument removed successfully..

=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStoree, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 71443534 B
Java, Flash, Steam htmlcache => 2255 B
Windows/system/drivers => 106716823 B
Edge => 0 B
Chrome => 467528644 B
Firefox => 377084111 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 16384 B
Public => 0 B
ProgramData => 0 B
systemprofile => 29550862 B
LocalService => 66228 B
NetworkService => 0 B
pc centar => 2395278349 B

RecycleBin => 0 B
EmptyTemp: => 3.2 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 20:01:33 ====

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Arrow Preuzmi instalaciju za Malwarebytes Anti-Malware (MBAM) ver.2.0 i instaliraj aplikaciju.
Dvoklik na mbam-setup.exe i prati uputstva za instalaciju. Instalacija je klasicna, "Next > I Agree . . > Next > Install" princip. Po zavrsenoj instalaciji, klikni Finish.
Napomena: 14 dana besplatna trail verzija je pre-selektovana. Mozes decekirati ovu opciju ako zelis.


- Po prvom pokretanju, MBAM ce zapoceti "Update" u nameri da preuzme najsvezije definicije.
Ili ... klik na 'Update Now >>' link ili dugme radi preuzimanja svezih definicija.

• Konfigurisati skener; Na 'Settings' tabu, Detection and Protection podesiti sledece opcije:
1. pod-tab Detection Options, cekirati kucicu za 'Scan for rootkits';
2. pod-tab Non-Malware Protection, za 'PUP detections', prostarati se da je selektovana 'Threat detections as malware' opcija.




• Izvrsiti 'Threat Scan';
Klik na Scan tab, zatim na 'Scan Now >>' da bi izvrsio skeniranje.
Ukoliko MBAM prijavi da je 'update' dostupan, klik na 'Update Now' a potom nastaviti do skeniranja.
Obavestenje: kod nekih teskih infekcija, moguce je dobiti sledecu poruku "Could not load DDA driver". U tom slucaju, klik Yes na tu poruku, dopustiti ucitavanje drajvera po restartu racunara, dozvoliti restart.
Potom, nastaviti sa ostatkom instrukcija.


• Po zavrsenom skeniranju, klik na Apply Action dugme ukoliko je pretnja detektovana. Sacekati da program zatrazi restart!
- Klik na Yes na poruku koja govori da ce se sistem restartovati.



• Postaviti izvestaj (export-ovati logfile) na uvid;
Ponovo pokrenuti MBAM, klik na History tab > Application Logs. Dvoklik na 'Scan Log' koji pokazuje vreme i datum upravo izvrsenog skeniranja.
1. U novom prozoru klik na 'Export' dugme, pa izabrati 'Text file (*.txt)';
2. Kada se pojavi Save File dialog, izabrati da se log sacuva na Desktop.
U tom istom prozoru, dole pod File name: upisi 'mbam' kao naziv izvestaja i klikni dugme Save.

- Po dobijenoj poruci ("Your file has been successfully exported") izvestaj koji si nazvao kao 'mbam' bice sacuvan na Desktop.




Arrow Okaci mbam.txt uz poruku koristeci opciju Prikači fajl.

offline
  • Pridružio: 27 Sep 2013
  • Poruke: 94

mycity.rs/must-login.png

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Kakvo je sada stanje?

offline
  • Pridružio: 27 Sep 2013
  • Poruke: 94

stanje je bolje,ne iskacu mi vise neke nezeljene stranice umesto one koju sam zadao,hvala vam ,jedino ako moze link od porograma koji bi izbrisao ove izvestaje

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Sledeća procedura će implementirati završno čišćenje.

Arrow Preuzmi "Xplode"-ov DelFix alat i snimi ga na Desktop.
Dvoklikom pokreni alat i štikliraj kućice ispred sledećih opcija;

Remove disinfection tools
Create registry backup
Purge System Restore


Klikni na dugme Run i pričekaj trenutak dok alat ne završi svoj rad.
Od ovog trenutka, svi korišćeni alati u ovoj temi bi trebali biti obrisani.
Alat će takođe formirati izveštaj za tebe. (C:\DelFix.txt)

Alat će snimiti i zdravo stanje registy-ja i napraviti backup koristeci integrisan program "ERUNT" u %windir%\ERUNT\DelFix
Alat briše stare system restore tačke i pravi novu, svežu tačku nakon čišćenja.

Ko je trenutno na forumu
 

Ukupno su 1259 korisnika na forumu :: 43 registrovanih, 8 sakrivenih i 1208 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 357magnum, _Petar, AC-DC, ajo baba, aleksandarbl, Atomski čoban, Bobrock1, dekan.m, Dimitrise93, Djokislav, Djokkinen, doktor123, DonRumataEstorski, Dorcolac, FileFinder, flash12, frenki1986, Insan, JOntra, kjkszpj, krkalon, Kubovac, kunktator, Lieutenant, ljubacv, Mercury, Mi lao shu, Milometer, nemkea71, novator, opt1, panzerwaffe, pein, pristinski korpus, procesor, savaskytec, slonic_tonic, Srle993, Trpe Grozni, Tvrtko I, virked, VJ, voja64