|
|
Poslao: 08 Jan 2014 15:03
|
offline
- Killer7

- Super građanin
- Pridružio: 12 Jul 2012
- Poruke: 1023
|
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-01-2014
Ran by Metallica41 (administrator) on FIKO on 08-01-2014 14:46:49
Running from C:\Users\Metallica41\Downloads
Windows 8 (X64) OS Language: English(UK)
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(IObit) C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe\LiveComm.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(Microsoft Corporation) C:\Windows\System32\wscript.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(Microsoft Corporation) C:\Windows\System32\BackgroundTransferHost.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.2.9200.16683_none_62280e15510f8e79\TiWorker.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
(Ufasoft) C:\Users\Metallica41\AppData\Roaming\WindowsHelp\macromedia.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [ACMON] - C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [90832 2012-06-07] (ASUS)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\reader_sl.exe [35736 2010-11-15] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-11-15] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HDAudDeck] - C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5264016 2012-08-16] (VIA)
HKLM-x32\...\Run: [AmIcoSinglun64] - C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [366720 2012-08-23] (Alcor Micro Corp.)
HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.)
HKLM-x32\...\Run: [ASUSWebStorage] - C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\AsusWSPanel.exe [3417984 2012-08-28] (ASUS Cloud Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [AVG_UI] - C:\Program Files (x86)\AVG\AVG2014\avgui.exe [4956176 2013-11-07] (AVG Technologies CZ, s.r.o.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [SE] - C:\Users\Metallica41\AppData\Roaming\SkypEmoticons\SE.exe [5827488 2013-10-25] (SkypEmoticons)
HKCU\...\Run: [uTorrent] - C:\Users\Metallica41\AppData\Roaming\uTorrent\uTorrent.exe [1309016 2014-01-06] (BitTorrent Inc.)
MountPoints2: F - "F:\OblivionLauncher.exe"
Startup: C:\Users\Metallica41\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Skype.lnk
ShortcutTarget: Skype.lnk -> C:\Users\Metallica41\AppData\Roaming\WindowsHelp\usft_ext.exe.vbs (No File)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [Link mogu videti samo ulogovani korisnici]
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [Link mogu videti samo ulogovani korisnici]
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Metallica41\AppData\Roaming\Mozilla\Firefox\Profiles\2qoqogpq.default
FF Homepage: [Link mogu videti samo ulogovani korisnici]
FF Keyword.URL: user_pref("keyword.URL", "");
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Extension: Vauodiax - C:\Users\Metallica41\AppData\Roaming\Mozilla\Firefox\Profiles\2qoqogpq.default\Extensions\dvdjj9_unc@uuuiy-oa.net
FF Extension: SearchNewTab - C:\Users\Metallica41\AppData\Roaming\Mozilla\Firefox\Profiles\2qoqogpq.default\Extensions\lvfcpkoq@lws-u.net
==================== Services (Whitelisted) =================
R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3478544 2013-11-11] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [348008 2013-09-24] (AVG Technologies CZ, s.r.o.)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2151744 2013-12-24] (IObit)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27792 2012-08-14] (VIA Technologies, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [65784 2013-04-16] (ASUS Corporation)
S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [20496 2013-09-04] (AVG Technologies CZ, s.r.o.)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [150808 2013-11-05] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [240920 2013-11-04] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [194872 2013-10-24] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [212280 2013-10-31] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [294712 2013-10-31] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123704 2013-10-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31544 2013-09-10] (AVG Technologies CZ, s.r.o.)
R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [252728 2013-10-21] (AVG Technologies CZ, s.r.o.)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( )
S3 hexmagic; \??\C:\Windows\system32\drivers\hexmagic.sys [x]
U0 msahci;
S2 NEWDRIVER; \??\C:\Windows\SysWow64\WinVDEdrv6.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-08 14:46 - 2014-01-08 14:47 - 00011681 _____ C:\Users\Metallica41\Downloads\FRST.txt
2014-01-08 14:46 - 2014-01-08 14:46 - 00000000 ____D C:\FRST
2014-01-08 14:44 - 2014-01-08 14:45 - 01932624 _____ (Farbar) C:\Users\Metallica41\Downloads\FRST64.exe
2014-01-08 14:27 - 2014-01-08 14:27 - 00016748 _____ C:\Users\Metallica41\Desktop\dds.txt
2014-01-08 14:27 - 2014-01-08 14:27 - 00003713 _____ C:\Users\Metallica41\Desktop\attach.txt
2014-01-08 14:24 - 2014-01-08 14:25 - 00688992 ____R (Swearware) C:\Users\Metallica41\Downloads\dds.scr
2014-01-08 14:07 - 2014-01-08 14:07 - 00000678 _____ C:\Users\Public\Desktop\Oblivion.lnk
2014-01-08 14:02 - 2014-01-08 14:03 - 00028236 _____ C:\Windows\DirectX.log
2014-01-08 12:39 - 2014-01-08 12:39 - 00000000 ____D C:\Users\Metallica41\AppData\Roaming\AVG2014
2014-01-08 12:38 - 2014-01-08 12:38 - 00000967 _____ C:\Users\Public\Desktop\AVG 2014.lnk
2014-01-08 12:38 - 2014-01-08 12:38 - 00000000 ____D C:\Users\Metallica41\AppData\Roaming\TuneUp Software
2014-01-08 12:37 - 2014-01-08 12:38 - 00000000 ____D C:\ProgramData\AVG2014
2014-01-08 12:37 - 2014-01-08 12:37 - 00000000 ___HD C:\$AVG
2014-01-08 12:37 - 2014-01-08 12:37 - 00000000 ____D C:\Program Files (x86)\AVG
2014-01-08 12:34 - 2014-01-08 12:56 - 00000000 ____D C:\Users\Metallica41\AppData\Local\Avg2014
2014-01-08 12:34 - 2014-01-08 12:55 - 00000000 ____D C:\ProgramData\MFAData
2014-01-08 12:34 - 2014-01-08 12:34 - 00000000 ____D C:\Users\Metallica41\AppData\Local\MFAData
2014-01-07 11:42 - 2014-01-07 11:42 - 00178800 _____ (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt_x64.dll
2014-01-06 22:49 - 2014-01-06 22:49 - 00000897 _____ C:\Users\Metallica41\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MassEffect.lnk
2014-01-06 22:48 - 2014-01-06 22:48 - 00000000 ____D C:\Users\Metallica41\Documents\BioWare
2014-01-06 17:20 - 2014-01-06 17:20 - 00000000 ____D C:\ProgramData\SystemRequirementsLab
2014-01-06 17:20 - 2014-01-06 17:20 - 00000000 ____D C:\Program Files (x86)\SystemRequirementsLab
2014-01-06 15:34 - 2014-01-07 15:32 - 00000000 ____D C:\Users\Metallica41\Downloads\The.Elder.Scrolls.IV.Oblivion-RELOADED
2014-01-04 16:54 - 2014-01-06 15:59 - 00000000 ____D C:\Program Files (x86)\SpeedFan
2014-01-04 16:54 - 2014-01-04 16:54 - 00001009 _____ C:\Users\Metallica41\Desktop\SpeedFan.lnk
2014-01-04 16:04 - 2014-01-04 16:05 - 00000000 ____D C:\Users\Metallica41\Documents\NFS Most Wanted
2014-01-03 00:22 - 2014-01-07 03:52 - 00005034 _____ C:\Windows\PFRO.log
2014-01-03 00:22 - 2014-01-03 00:23 - 00283248 _____ C:\Windows\system32\FNTCACHE.DAT
2014-01-02 17:10 - 2014-01-02 17:10 - 00002784 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-01-02 17:10 - 2014-01-02 17:10 - 00000824 _____ C:\Users\Public\Desktop\CCleaner.lnk
2014-01-02 17:10 - 2014-01-02 17:10 - 00000000 ____D C:\Program Files\CCleaner
2014-01-01 11:47 - 2014-01-04 16:54 - 00001009 _____ C:\Users\Administrator\Desktop\SpeedFan.lnk
2014-01-01 11:47 - 2014-01-04 16:54 - 00000045 _____ C:\Windows\SysWOW64\initdebug.nfo
2014-01-01 11:42 - 2014-01-01 11:42 - 00003152 _____ C:\Windows\System32\Tasks\{8A23795F-E7F5-474A-9868-DCB5B069D153}
2013-12-25 01:52 - 2013-12-26 00:42 - 00000000 ___HD C:\Users\Metallica41\Desktop\New folder (4)
2013-12-25 01:19 - 2013-12-25 01:20 - 00000318 _____ C:\Windows\SIERRA.INI
2013-12-25 01:19 - 1998-01-23 12:22 - 00304128 _____ (InstallShield Software Corporation) C:\Windows\IsUninst.exe
2013-12-24 23:23 - 2013-12-25 01:54 - 00000700 ___SH C:\Users\Metallica41\AppData\Local\systemFL7.dat
2013-12-24 23:12 - 2013-12-24 23:12 - 00000000 ____D C:\Program Files (x86)\NewSoftware's
2013-12-24 21:14 - 2014-01-03 00:24 - 00000000 ____D C:\ProgramData\ProductData
2013-12-24 21:14 - 2014-01-03 00:22 - 00000000 ____D C:\Program Files (x86)\IObit
2013-12-24 21:14 - 2013-12-24 21:15 - 00000000 ____D C:\ProgramData\IObit
2013-12-24 21:14 - 2013-12-24 21:14 - 00000000 ____D C:\Users\Metallica41\AppData\Roaming\IObit
2013-12-14 22:53 - 2013-12-14 23:24 - 00000000 ____D C:\Users\Metallica41\Documents\Command and Conquer Generals Zero Hour Data
2013-12-14 22:45 - 2014-01-05 21:00 - 00000000 ____D C:\Users\Metallica41\Documents\Command and Conquer Generals Data
2013-12-14 22:44 - 2013-12-14 22:51 - 00000983 _____ C:\Windows\eReg.dat
2013-12-14 08:02 - 2013-12-24 21:17 - 00000000 ____D C:\Users\Metallica41\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Return to Castle Wolfenstein
2013-12-14 08:02 - 2013-12-14 08:02 - 00000838 _____ C:\Users\Administrator\Desktop\Wolfenstein (Single Player).lnk
2013-12-14 08:02 - 2013-12-14 08:02 - 00000838 _____ C:\Users\Administrator\Desktop\Wolfenstein (Multiplayer).lnk
2013-12-14 07:58 - 2013-12-14 08:02 - 00000965 _____ C:\Windows\Rtcw.INI
2013-12-14 00:20 - 2013-12-14 00:21 - 00000000 ____D C:\Users\Metallica41\Downloads\The.Hobbit.The.Desolation.of.Smaug.2013.DVDRip
2013-12-12 23:30 - 2013-10-25 07:19 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-12 23:30 - 2013-10-25 07:19 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-12 23:30 - 2013-10-25 07:18 - 19271168 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-12 23:30 - 2013-10-25 07:18 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-12-12 23:30 - 2013-10-25 07:17 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-12 23:30 - 2013-10-25 07:17 - 03959808 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-12 23:30 - 2013-10-25 07:17 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-12 23:30 - 2013-10-25 07:17 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-12-12 23:30 - 2013-10-25 05:45 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-12-12 23:30 - 2013-10-25 05:44 - 01140736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-12-12 23:30 - 2013-10-25 05:43 - 13761536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-12-12 23:30 - 2013-10-25 05:43 - 02049024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-12-12 23:30 - 2013-10-25 05:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-12-12 23:30 - 2013-10-25 05:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-12-12 23:29 - 2013-10-25 07:19 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2013-12-12 23:29 - 2013-10-25 07:19 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-12 23:29 - 2013-10-25 05:44 - 14356992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-12-12 23:29 - 2013-10-25 05:43 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-12-12 23:27 - 2013-10-09 02:33 - 00059416 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2013-12-12 23:27 - 2013-10-08 23:30 - 00628736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2013-12-12 23:27 - 2013-10-08 23:30 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2013-12-12 23:27 - 2013-10-08 23:30 - 00084992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2013-12-12 23:27 - 2013-10-08 23:30 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2013-12-12 23:27 - 2013-10-08 23:28 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2013-12-12 23:27 - 2013-10-08 23:27 - 03279872 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2013-12-12 23:27 - 2013-10-08 23:27 - 01622016 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2013-12-12 23:27 - 2013-10-08 23:27 - 00773120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2013-12-12 23:27 - 2013-10-08 23:27 - 00252928 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2013-12-12 23:27 - 2013-10-08 23:27 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2013-12-12 23:27 - 2013-10-08 23:27 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2013-12-12 23:27 - 2013-10-08 23:27 - 00099328 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2013-12-12 23:27 - 2013-10-05 07:10 - 00285016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spaceport.sys
2013-12-12 23:27 - 2013-10-03 23:09 - 00385528 _____ C:\Windows\system32\ApnDatabase.xml
2013-12-12 23:27 - 2013-10-02 03:50 - 00447320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS
2013-12-12 23:27 - 2013-09-28 06:48 - 00778752 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2013-12-12 23:27 - 2013-09-28 04:58 - 00551424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2013-12-12 23:27 - 2013-09-19 08:32 - 01455448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2013-12-12 23:27 - 2013-08-30 06:19 - 00626688 _____ (Microsoft Corporation) C:\Windows\system32\resutils.dll
2013-12-12 23:27 - 2013-08-30 06:18 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\clusapi.dll
2013-12-12 23:27 - 2013-08-30 00:48 - 00488960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\resutils.dll
2013-12-12 23:27 - 2013-08-30 00:47 - 00302080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clusapi.dll
2013-12-12 11:28 - 2013-09-28 04:35 - 00288768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-12-12 11:28 - 2012-10-11 08:02 - 01636672 _____ (Microsoft Corporation) C:\Windows\system32\WMALFXGFXDSP.dll
2013-12-12 11:28 - 2012-10-11 06:45 - 00370176 _____ (Microsoft Corporation) C:\Windows\system32\SysFxUI.dll
2013-12-12 11:28 - 2012-10-11 06:19 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmkaud.sys
2013-12-12 11:28 - 2012-10-11 06:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-12 11:27 - 2013-10-10 10:32 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2013-12-12 11:27 - 2013-10-10 10:30 - 00162304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrobj.dll
2013-12-12 11:27 - 2013-10-10 10:30 - 00156160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2013-12-12 11:27 - 2013-10-10 10:24 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-12 11:27 - 2013-10-10 10:23 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-12 11:27 - 2013-10-10 10:22 - 00222720 _____ (Microsoft Corporation) C:\Windows\system32\scrobj.dll
2013-12-12 11:27 - 2013-10-10 10:22 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-12 10:17 - 2013-11-23 07:43 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-12 10:17 - 2013-11-23 06:05 - 00368640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-12-12 10:17 - 2013-11-07 00:18 - 04036608 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-12 10:17 - 2013-11-01 06:38 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-12 10:17 - 2013-11-01 04:49 - 00273408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2013-12-12 08:56 - 2013-10-19 06:45 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-12 08:56 - 2013-10-19 05:04 - 00059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
==================== One Month Modified Files and Folders =======
2014-01-08 14:47 - 2014-01-08 14:46 - 00011681 _____ C:\Users\Metallica41\Downloads\FRST.txt
2014-01-08 14:46 - 2014-01-08 14:46 - 00000000 ____D C:\FRST
2014-01-08 14:45 - 2014-01-08 14:44 - 01932624 _____ (Farbar) C:\Users\Metallica41\Downloads\FRST64.exe
2014-01-08 14:45 - 2013-11-09 15:40 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-08 14:30 - 2012-10-24 22:03 - 01223035 _____ C:\Windows\WindowsUpdate.log
2014-01-08 14:27 - 2014-01-08 14:27 - 00016748 _____ C:\Users\Metallica41\Desktop\dds.txt
2014-01-08 14:27 - 2014-01-08 14:27 - 00003713 _____ C:\Users\Metallica41\Desktop\attach.txt
2014-01-08 14:25 - 2014-01-08 14:24 - 00688992 ____R (Swearware) C:\Users\Metallica41\Downloads\dds.scr
2014-01-08 14:07 - 2014-01-08 14:07 - 00000678 _____ C:\Users\Public\Desktop\Oblivion.lnk
2014-01-08 14:03 - 2014-01-08 14:02 - 00028236 _____ C:\Windows\DirectX.log
2014-01-08 14:01 - 2013-03-25 18:48 - 00000000 ____D C:\Users\Metallica41\Documents\My Games
2014-01-08 14:00 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\system32\sru
2014-01-08 13:49 - 2013-11-02 06:47 - 00000000 ____D C:\Users\Metallica41\AppData\Roaming\uTorrent
2014-01-08 13:09 - 2013-11-08 20:46 - 00000000 ____D C:\Users\Metallica41\AppData\Roaming\WindowsHelp
2014-01-08 12:56 - 2014-01-08 12:34 - 00000000 ____D C:\Users\Metallica41\AppData\Local\Avg2014
2014-01-08 12:55 - 2014-01-08 12:34 - 00000000 ____D C:\ProgramData\MFAData
2014-01-08 12:55 - 2012-07-26 06:26 - 00262144 ___SH C:\Windows\system32\config\ELAM
2014-01-08 12:39 - 2014-01-08 12:39 - 00000000 ____D C:\Users\Metallica41\AppData\Roaming\AVG2014
2014-01-08 12:38 - 2014-01-08 12:38 - 00000967 _____ C:\Users\Public\Desktop\AVG 2014.lnk
2014-01-08 12:38 - 2014-01-08 12:38 - 00000000 ____D C:\Users\Metallica41\AppData\Roaming\TuneUp Software
2014-01-08 12:38 - 2014-01-08 12:37 - 00000000 ____D C:\ProgramData\AVG2014
2014-01-08 12:38 - 2012-07-26 09:12 - 00000000 ___HD C:\Windows\ELAMBKUP
2014-01-08 12:37 - 2014-01-08 12:37 - 00000000 ___HD C:\$AVG
2014-01-08 12:37 - 2014-01-08 12:37 - 00000000 ____D C:\Program Files (x86)\AVG
2014-01-08 12:34 - 2014-01-08 12:34 - 00000000 ____D C:\Users\Metallica41\AppData\Local\MFAData
2014-01-08 12:20 - 2013-06-09 18:00 - 00000000 ____D C:\Users\Metallica41\Desktop\New folder (2)
2014-01-08 09:11 - 2013-09-06 22:59 - 00000387 _____ C:\Users\Metallica41\AppData\Roaming\sp_data.sys
2014-01-07 15:32 - 2014-01-06 15:34 - 00000000 ____D C:\Users\Metallica41\Downloads\The.Elder.Scrolls.IV.Oblivion-RELOADED
2014-01-07 14:00 - 2013-11-16 14:30 - 00000000 ____D C:\Users\Metallica41\Downloads\New folder
2014-01-07 12:54 - 2013-09-07 20:32 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-473922799-1250382268-3828485289-1001
2014-01-07 11:42 - 2014-01-07 11:42 - 00178800 _____ (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt_x64.dll
2014-01-07 03:52 - 2014-01-03 00:22 - 00005034 _____ C:\Windows\PFRO.log
2014-01-07 03:52 - 2012-07-26 08:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-06 22:49 - 2014-01-06 22:49 - 00000897 _____ C:\Users\Metallica41\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MassEffect.lnk
2014-01-06 22:48 - 2014-01-06 22:48 - 00000000 ____D C:\Users\Metallica41\Documents\BioWare
2014-01-06 17:20 - 2014-01-06 17:20 - 00000000 ____D C:\ProgramData\SystemRequirementsLab
2014-01-06 17:20 - 2014-01-06 17:20 - 00000000 ____D C:\Program Files (x86)\SystemRequirementsLab
2014-01-06 15:59 - 2014-01-04 16:54 - 00000000 ____D C:\Program Files (x86)\SpeedFan
2014-01-05 21:00 - 2013-12-14 22:45 - 00000000 ____D C:\Users\Metallica41\Documents\Command and Conquer Generals Data
2014-01-04 16:54 - 2014-01-04 16:54 - 00001009 _____ C:\Users\Metallica41\Desktop\SpeedFan.lnk
2014-01-04 16:54 - 2014-01-01 11:47 - 00001009 _____ C:\Users\Administrator\Desktop\SpeedFan.lnk
2014-01-04 16:54 - 2014-01-01 11:47 - 00000045 _____ C:\Windows\SysWOW64\initdebug.nfo
2014-01-04 16:05 - 2014-01-04 16:04 - 00000000 ____D C:\Users\Metallica41\Documents\NFS Most Wanted
2014-01-03 00:24 - 2013-12-24 21:14 - 00000000 ____D C:\ProgramData\ProductData
2014-01-03 00:23 - 2014-01-03 00:22 - 00283248 _____ C:\Windows\system32\FNTCACHE.DAT
2014-01-03 00:22 - 2013-12-24 21:14 - 00000000 ____D C:\Program Files (x86)\IObit
2014-01-02 17:21 - 2013-09-06 23:37 - 00000000 ____D C:\Windows.old
2014-01-02 17:20 - 2013-11-24 20:53 - 00000000 ____D C:\Users\Metallica41\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HyperCam 2
2014-01-02 17:20 - 2013-10-11 15:06 - 00000000 ____D C:\Users\Metallica41\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Cs 1.6 Background Maker v3.0
2014-01-02 17:19 - 2012-08-02 23:24 - 00000000 ____D C:\Windows\Panther
2014-01-02 17:10 - 2014-01-02 17:10 - 00002784 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-01-02 17:10 - 2014-01-02 17:10 - 00000824 _____ C:\Users\Public\Desktop\CCleaner.lnk
2014-01-02 17:10 - 2014-01-02 17:10 - 00000000 ____D C:\Program Files\CCleaner
2014-01-01 16:26 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\AUInstallAgent
2014-01-01 11:42 - 2014-01-01 11:42 - 00003152 _____ C:\Windows\System32\Tasks\{8A23795F-E7F5-474A-9868-DCB5B069D153}
2013-12-26 00:42 - 2013-12-25 01:52 - 00000000 ___HD C:\Users\Metallica41\Desktop\New folder (4)
2013-12-25 01:54 - 2013-12-24 23:23 - 00000700 ___SH C:\Users\Metallica41\AppData\Local\systemFL7.dat
2013-12-25 01:22 - 2012-10-24 21:47 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-12-25 01:20 - 2013-12-25 01:19 - 00000318 _____ C:\Windows\SIERRA.INI
2013-12-25 00:00 - 2013-10-11 20:10 - 00000000 ____D C:\Users\Metallica41\AppData\Roaming\Skype
2013-12-24 23:12 - 2013-12-24 23:12 - 00000000 ____D C:\Program Files (x86)\NewSoftware's
2013-12-24 21:17 - 2013-12-14 08:02 - 00000000 ____D C:\Users\Metallica41\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Return to Castle Wolfenstein
2013-12-24 21:15 - 2013-12-24 21:14 - 00000000 ____D C:\ProgramData\IObit
2013-12-24 21:14 - 2013-12-24 21:14 - 00000000 ____D C:\Users\Metallica41\AppData\Roaming\IObit
2013-12-17 23:04 - 2012-07-26 06:26 - 00262144 ___SH C:\Windows\system32\config\BBI
2013-12-14 23:24 - 2013-12-14 22:53 - 00000000 ____D C:\Users\Metallica41\Documents\Command and Conquer Generals Zero Hour Data
2013-12-14 22:51 - 2013-12-14 22:44 - 00000983 _____ C:\Windows\eReg.dat
2013-12-14 20:56 - 2013-11-30 10:03 - 00000000 ____D C:\Users\Metallica41\Downloads\Guitar Pro 5
2013-12-14 08:02 - 2013-12-14 08:02 - 00000838 _____ C:\Users\Administrator\Desktop\Wolfenstein (Single Player).lnk
2013-12-14 08:02 - 2013-12-14 08:02 - 00000838 _____ C:\Users\Administrator\Desktop\Wolfenstein (Multiplayer).lnk
2013-12-14 08:02 - 2013-12-14 07:58 - 00000965 _____ C:\Windows\Rtcw.INI
2013-12-14 00:21 - 2013-12-14 00:20 - 00000000 ____D C:\Users\Metallica41\Downloads\The.Hobbit.The.Desolation.of.Smaug.2013.DVDRip
2013-12-13 16:40 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\rescache
2013-12-13 10:28 - 2012-07-26 08:28 - 00848230 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-13 10:21 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\SysWOW64\en-GB
2013-12-13 10:21 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\system32\en-GB
2013-12-13 10:21 - 2012-07-26 06:38 - 00000000 ____D C:\Windows\system32\oobe
2013-12-12 10:07 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\system32\SecureBootUpdates
2013-12-10 19:45 - 2013-11-09 15:40 - 00003718 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-12-10 14:13 - 2013-10-11 20:10 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-12-10 14:13 - 2013-10-11 20:10 - 00000000 ____D C:\ProgramData\Skype
Files to move or delete:
====================
C:\ProgramData\SetStretch.exe
Some content of TEMP:
====================
C:\Users\Metallica41\AppData\Local\Temp\drm_dyndata_7370012.dll
C:\Users\Metallica41\AppData\Local\Temp\sfamcc00001.dll
C:\Users\Metallica41\AppData\Local\Temp\sfamcc00002.dll
C:\Users\Metallica41\AppData\Local\Temp\sfextra.dll
C:\Users\Metallica41\AppData\Local\Temp\SRLDetectionLibrary6277013301442389629.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-08 12:49
==================== End Of Log ============================
addition:
[Link mogu videti samo ulogovani korisnici]
Ne mogu gmer da okacim jer kad god pokrenem gmer ono zablokira laptop i pise ''your computer has run into a pc error'' i onda se resetuje tako da gmer ne mogu izvini!
|
|
|
|
|
Poslao: 08 Jan 2014 20:54
|
offline
- Killer7

- Super građanin
- Pridružio: 12 Jul 2012
- Poruke: 1023
|
Napisano: 08 Jan 2014 20:53
Nece brate uvek pise fixlist.txt should be in the same directory as tool.Ja stavim ali dzabe nece pa nece.Ionako sam primetio da malware vise nema jer coin miner se vise ne pojavljuje,pa me zanima da li i dalje moram da nastavim sa ovim jer AVG mi je pronasao 2 virusa i obrisao ih.
Dopuna: 08 Jan 2014 20:54
Da li moram nastaviti?
|
|
|
|
Poslao: 08 Jan 2014 21:04
|
offline
- magna86

- Anti Malware Fighter
Rank 2
- Pridružio: 21 Jun 2008
- Poruke: 6104
|
Izvinjavam se sto upadam kolegi u temi no kolega trenutno ima privatne obaveze ...
Da ne cekas ...
Citat:Running from C:\Users\Metallica41\Downloads
Originalni FRST se nalazi u Download folderu. Lepo ti kaze, FixList mora da se nalazi u istom direktorijumu (lokacija) gde se nalazi i FRST.exe
Prebaci FRST.exe na Desktop, formiraj FixList.txt i sacuvaj na Desktop pa izvrsi FRST preko dugmeta Fix kao sto se navodi u uputstvu.
|
|
|
|
Poslao: 08 Jan 2014 21:20
|
offline
- Killer7

- Super građanin
- Pridružio: 12 Jul 2012
- Poruke: 1023
|
Napisano: 08 Jan 2014 21:08
Ok hvala znao sam nego nisam vidim ima neki folder u C: ali evo uradicu!
Dopuna: 08 Jan 2014 21:20
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 08-01-2014 01
Ran by Metallica41 at 2014-01-08 21:10:01 Run:1
Running from C:\Users\Metallica41\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
(IObit) C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
(Microsoft Corporation) C:\Windows\System32\wscript.exe
R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2151744 2013-12-24] (IObit)
HKCU\...\Run: [SE] - C:\Users\Metallica41\AppData\Roaming\SkypEmoticons\SE.exe [5827488 2013-10-25] (SkypEmoticons)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
Startup: C:\Users\Metallica41\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Skype.ln
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
FF Extension: Vauodiax - C:\Users\Metallica41\AppData\Roaming\Mozilla\Firefox\Profiles\2qoqogpq.default\Extensions\dvdjj9_unc@uuuiy-oa.net
FF Extension: SearchNewTab - C:\Users\Metallica41\AppData\Roaming\Mozilla\Firefox\Profiles\2qoqogpq.default\Extensions\lvfcpkoq@lws-u.net
2013-12-24 21:14 - 2014-01-03 00:22 - 00000000 ____D C:\Program Files (x86)\IObit
2013-12-24 21:14 - 2013-12-24 21:15 - 00000000 ____D C:\ProgramData\IObit
2013-12-24 21:14 - 2013-12-24 21:14 - 00000000 ____D C:\Users\Metallica41\AppData\Roaming\IObit
C:\ProgramData\SetStretch.exe
C:\Users\Metallica41\AppData\Local\Temp\*.dll
C:\Users\Metallica41\AppData\Roaming\WindowsHelp
C:\Users\Metallica41\AppData\Roaming\Mozilla\Firefox\Profiles\2qoqogpq.default\Extensions\dvdjj9_unc@uuuiy-oa.net
C:\Users\Metallica41\AppData\Roaming\Mozilla\Firefox\Profiles\2qoqogpq.default\Extensions\lvfcpkoq@lws-u.net
C:\Users\Metallica41\AppData\Roaming\SkypEmoticons
*****************
[2028] C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe => Process closed successfully.
C:\Windows\System32\wscript.exe => No running process found
LiveUpdateSvc => Service deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\SE => Value deleted successfully.
HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => Key deleted successfully.
HKLM\System\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => Key deleted successfully.
Startup: C:\Users\Metallica41\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Skype.ln not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully.
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found.
C:\Users\Metallica41\AppData\Roaming\Mozilla\Firefox\Profiles\2qoqogpq.default\Extensions\dvdjj9_unc@uuuiy-oa.net => Moved successfully.
C:\Users\Metallica41\AppData\Roaming\Mozilla\Firefox\Profiles\2qoqogpq.default\Extensions\lvfcpkoq@lws-u.net => Moved successfully.
C:\Program Files (x86)\IObit => Moved successfully.
C:\ProgramData\IObit => Moved successfully.
C:\Users\Metallica41\AppData\Roaming\IObit => Moved successfully.
C:\ProgramData\SetStretch.exe => Moved successfully.
C:\Users\Metallica41\AppData\Local\Temp\*.dll => Moved successfully.
C:\Users\Metallica41\AppData\Roaming\WindowsHelp => Moved successfully.
"C:\Users\Metallica41\AppData\Roaming\Mozilla\Firefox\Profiles\2qoqogpq.default\Extensions\dvdjj9_unc@uuuiy-oa.net" => File/Directory not found.
"C:\Users\Metallica41\AppData\Roaming\Mozilla\Firefox\Profiles\2qoqogpq.default\Extensions\lvfcpkoq@lws-u.net" => File/Directory not found.
C:\Users\Metallica41\AppData\Roaming\SkypEmoticons => Moved successfully.
The system needs a manual reboot.
FRST:
==== End of Fixlog ====
[Link mogu videti samo ulogovani korisnici]
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-01-2014 01
Ran by Metallica41 (administrator) on FIKO on 08-01-2014 21:16:20
Running from C:\Users\Metallica41\Desktop
Windows 8 (X64) OS Language: English(UK)
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe\LiveComm.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [ACMON] - C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [90832 2012-06-07] (ASUS)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\reader_sl.exe [35736 2010-11-15] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-11-15] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HDAudDeck] - C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5264016 2012-08-16] (VIA)
HKLM-x32\...\Run: [AmIcoSinglun64] - C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [366720 2012-08-23] (Alcor Micro Corp.)
HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.)
HKLM-x32\...\Run: [ASUSWebStorage] - C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\AsusWSPanel.exe [3417984 2012-08-28] (ASUS Cloud Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [AVG_UI] - C:\Program Files (x86)\AVG\AVG2014\avgui.exe [4956176 2013-11-07] (AVG Technologies CZ, s.r.o.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [uTorrent] - C:\Users\Metallica41\AppData\Roaming\uTorrent\uTorrent.exe [1309016 2014-01-06] (BitTorrent Inc.)
MountPoints2: F - "F:\OblivionLauncher.exe"
Startup: C:\Users\Metallica41\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Skype.lnk
ShortcutTarget: Skype.lnk -> C:\Users\Metallica41\AppData\Roaming\WindowsHelp\usft_ext.exe.vbs (No File)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [Link mogu videti samo ulogovani korisnici]
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [Link mogu videti samo ulogovani korisnici]
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Metallica41\AppData\Roaming\Mozilla\Firefox\Profiles\2qoqogpq.default
FF Homepage: [Link mogu videti samo ulogovani korisnici]
FF Keyword.URL: user_pref("keyword.URL", "");
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
==================== Services (Whitelisted) =================
R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3478544 2013-11-11] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [348008 2013-09-24] (AVG Technologies CZ, s.r.o.)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27792 2012-08-14] (VIA Technologies, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [65784 2013-04-16] (ASUS Corporation)
S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [20496 2013-09-04] (AVG Technologies CZ, s.r.o.)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [150808 2013-11-05] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [240920 2013-11-04] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [194872 2013-10-24] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [212280 2013-10-31] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [294712 2013-10-31] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123704 2013-10-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31544 2013-09-10] (AVG Technologies CZ, s.r.o.)
R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [252728 2013-10-21] (AVG Technologies CZ, s.r.o.)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( )
S3 hexmagic; \??\C:\Windows\system32\drivers\hexmagic.sys [x]
U0 msahci;
S2 NEWDRIVER; \??\C:\Windows\SysWow64\WinVDEdrv6.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-08 21:16 - 2014-01-08 21:16 - 00010538 _____ C:\Users\Metallica41\Desktop\FRST.txt
2014-01-08 21:15 - 2014-01-08 21:15 - 00448512 _____ (OldTimer Tools) C:\Users\Metallica41\Downloads\TFC.exe
2014-01-08 21:09 - 2014-01-08 21:09 - 01931770 _____ (Farbar) C:\Users\Metallica41\Desktop\FRST64.exe
2014-01-08 20:50 - 2014-01-08 21:10 - 00000000 ____D C:\FRST
2014-01-08 15:00 - 2014-01-08 15:01 - 00283800 _____ C:\Windows\Minidump\010814-61562-01.dmp
2014-01-08 14:56 - 2014-01-08 15:00 - 00000000 ____D C:\Windows\Minidump
2014-01-08 14:56 - 2014-01-08 14:56 - 00262144 _____ C:\Windows\Minidump\010814-54937-01.dmp
2014-01-08 14:55 - 2014-01-08 15:00 - 327547873 _____ C:\Windows\MEMORY.DMP
2014-01-08 14:07 - 2014-01-08 14:07 - 00000678 _____ C:\Users\Public\Desktop\Oblivion.lnk
2014-01-08 14:02 - 2014-01-08 14:03 - 00028236 _____ C:\Windows\DirectX.log
2014-01-08 12:39 - 2014-01-08 12:39 - 00000000 ____D C:\Users\Metallica41\AppData\Roaming\AVG2014
2014-01-08 12:38 - 2014-01-08 12:38 - 00000967 _____ C:\Users\Public\Desktop\AVG 2014.lnk
2014-01-08 12:38 - 2014-01-08 12:38 - 00000000 ____D C:\Users\Metallica41\AppData\Roaming\TuneUp Software
2014-01-08 12:37 - 2014-01-08 12:38 - 00000000 ____D C:\ProgramData\AVG2014
2014-01-08 12:37 - 2014-01-08 12:37 - 00000000 ___HD C:\$AVG
2014-01-08 12:37 - 2014-01-08 12:37 - 00000000 ____D C:\Program Files (x86)\AVG
2014-01-08 12:34 - 2014-01-08 17:05 - 00000000 ____D C:\ProgramData\MFAData
2014-01-08 12:34 - 2014-01-08 12:56 - 00000000 ____D C:\Users\Metallica41\AppData\Local\Avg2014
2014-01-08 12:34 - 2014-01-08 12:34 - 00000000 ____D C:\Users\Metallica41\AppData\Local\MFAData
2014-01-07 11:42 - 2014-01-07 11:42 - 00178800 _____ (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt_x64.dll
2014-01-06 22:49 - 2014-01-06 22:49 - 00000897 _____ C:\Users\Metallica41\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MassEffect.lnk
2014-01-06 22:48 - 2014-01-06 22:48 - 00000000 ____D C:\Users\Metallica41\Documents\BioWare
2014-01-06 17:20 - 2014-01-06 17:20 - 00000000 ____D C:\ProgramData\SystemRequirementsLab
2014-01-06 17:20 - 2014-01-06 17:20 - 00000000 ____D C:\Program Files (x86)\SystemRequirementsLab
2014-01-06 15:34 - 2014-01-07 15:32 - 00000000 ____D C:\Users\Metallica41\Downloads\The.Elder.Scrolls.IV.Oblivion-RELOADED
2014-01-04 16:54 - 2014-01-06 15:59 - 00000000 ____D C:\Program Files (x86)\SpeedFan
2014-01-04 16:54 - 2014-01-04 16:54 - 00001009 _____ C:\Users\Metallica41\Desktop\SpeedFan.lnk
2014-01-04 16:04 - 2014-01-04 16:05 - 00000000 ____D C:\Users\Metallica41\Documents\NFS Most Wanted
2014-01-03 00:22 - 2014-01-07 03:52 - 00005034 _____ C:\Windows\PFRO.log
2014-01-03 00:22 - 2014-01-03 00:23 - 00283248 _____ C:\Windows\system32\FNTCACHE.DAT
2014-01-02 17:10 - 2014-01-02 17:10 - 00002784 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-01-02 17:10 - 2014-01-02 17:10 - 00000824 _____ C:\Users\Public\Desktop\CCleaner.lnk
2014-01-02 17:10 - 2014-01-02 17:10 - 00000000 ____D C:\Program Files\CCleaner
2014-01-01 11:47 - 2014-01-04 16:54 - 00001009 _____ C:\Users\Administrator\Desktop\SpeedFan.lnk
2014-01-01 11:47 - 2014-01-04 16:54 - 00000045 _____ C:\Windows\SysWOW64\initdebug.nfo
2014-01-01 11:42 - 2014-01-01 11:42 - 00003152 _____ C:\Windows\System32\Tasks\{8A23795F-E7F5-474A-9868-DCB5B069D153}
2013-12-25 01:52 - 2013-12-26 00:42 - 00000000 ___HD C:\Users\Metallica41\Desktop\New folder (4)
2013-12-25 01:19 - 2013-12-25 01:20 - 00000318 _____ C:\Windows\SIERRA.INI
2013-12-25 01:19 - 1998-01-23 12:22 - 00304128 _____ (InstallShield Software Corporation) C:\Windows\IsUninst.exe
2013-12-24 23:23 - 2013-12-25 01:54 - 00000700 ___SH C:\Users\Metallica41\AppData\Local\systemFL7.dat
2013-12-24 23:12 - 2013-12-24 23:12 - 00000000 ____D C:\Program Files (x86)\NewSoftware's
2013-12-24 21:14 - 2014-01-03 00:24 - 00000000 ____D C:\ProgramData\ProductData
2013-12-14 22:53 - 2013-12-14 23:24 - 00000000 ____D C:\Users\Metallica41\Documents\Command and Conquer Generals Zero Hour Data
2013-12-14 22:45 - 2014-01-05 21:00 - 00000000 ____D C:\Users\Metallica41\Documents\Command and Conquer Generals Data
2013-12-14 22:44 - 2013-12-14 22:51 - 00000983 _____ C:\Windows\eReg.dat
2013-12-14 08:02 - 2013-12-24 21:17 - 00000000 ____D C:\Users\Metallica41\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Return to Castle Wolfenstein
2013-12-14 08:02 - 2013-12-14 08:02 - 00000838 _____ C:\Users\Administrator\Desktop\Wolfenstein (Single Player).lnk
2013-12-14 08:02 - 2013-12-14 08:02 - 00000838 _____ C:\Users\Administrator\Desktop\Wolfenstein (Multiplayer).lnk
2013-12-14 07:58 - 2013-12-14 08:02 - 00000965 _____ C:\Windows\Rtcw.INI
2013-12-14 00:20 - 2013-12-14 00:21 - 00000000 ____D C:\Users\Metallica41\Downloads\The.Hobbit.The.Desolation.of.Smaug.2013.DVDRip
2013-12-12 23:30 - 2013-10-25 07:19 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-12 23:30 - 2013-10-25 07:19 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-12 23:30 - 2013-10-25 07:18 - 19271168 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-12 23:30 - 2013-10-25 07:18 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-12-12 23:30 - 2013-10-25 07:17 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-12 23:30 - 2013-10-25 07:17 - 03959808 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-12 23:30 - 2013-10-25 07:17 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-12 23:30 - 2013-10-25 07:17 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-12-12 23:30 - 2013-10-25 05:45 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-12-12 23:30 - 2013-10-25 05:44 - 01140736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-12-12 23:30 - 2013-10-25 05:43 - 13761536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-12-12 23:30 - 2013-10-25 05:43 - 02049024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-12-12 23:30 - 2013-10-25 05:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-12-12 23:30 - 2013-10-25 05:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-12-12 23:29 - 2013-10-25 07:19 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2013-12-12 23:29 - 2013-10-25 07:19 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-12 23:29 - 2013-10-25 05:44 - 14356992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-12-12 23:29 - 2013-10-25 05:43 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-12-12 23:27 - 2013-10-09 02:33 - 00059416 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2013-12-12 23:27 - 2013-10-08 23:30 - 00628736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2013-12-12 23:27 - 2013-10-08 23:30 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2013-12-12 23:27 - 2013-10-08 23:30 - 00084992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2013-12-12 23:27 - 2013-10-08 23:30 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2013-12-12 23:27 - 2013-10-08 23:28 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2013-12-12 23:27 - 2013-10-08 23:27 - 03279872 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2013-12-12 23:27 - 2013-10-08 23:27 - 01622016 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2013-12-12 23:27 - 2013-10-08 23:27 - 00773120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2013-12-12 23:27 - 2013-10-08 23:27 - 00252928 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2013-12-12 23:27 - 2013-10-08 23:27 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2013-12-12 23:27 - 2013-10-08 23:27 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2013-12-12 23:27 - 2013-10-08 23:27 - 00099328 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2013-12-12 23:27 - 2013-10-05 07:10 - 00285016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spaceport.sys
2013-12-12 23:27 - 2013-10-03 23:09 - 00385528 _____ C:\Windows\system32\ApnDatabase.xml
2013-12-12 23:27 - 2013-10-02 03:50 - 00447320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS
2013-12-12 23:27 - 2013-09-28 06:48 - 00778752 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2013-12-12 23:27 - 2013-09-28 04:58 - 00551424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2013-12-12 23:27 - 2013-09-19 08:32 - 01455448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2013-12-12 23:27 - 2013-08-30 06:19 - 00626688 _____ (Microsoft Corporation) C:\Windows\system32\resutils.dll
2013-12-12 23:27 - 2013-08-30 06:18 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\clusapi.dll
2013-12-12 23:27 - 2013-08-30 00:48 - 00488960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\resutils.dll
2013-12-12 23:27 - 2013-08-30 00:47 - 00302080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clusapi.dll
2013-12-12 11:28 - 2013-09-28 04:35 - 00288768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-12-12 11:28 - 2012-10-11 08:02 - 01636672 _____ (Microsoft Corporation) C:\Windows\system32\WMALFXGFXDSP.dll
2013-12-12 11:28 - 2012-10-11 06:45 - 00370176 _____ (Microsoft Corporation) C:\Windows\system32\SysFxUI.dll
2013-12-12 11:28 - 2012-10-11 06:19 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmkaud.sys
2013-12-12 11:28 - 2012-10-11 06:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-12 11:27 - 2013-10-10 10:32 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2013-12-12 11:27 - 2013-10-10 10:30 - 00162304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrobj.dll
2013-12-12 11:27 - 2013-10-10 10:30 - 00156160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2013-12-12 11:27 - 2013-10-10 10:24 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-12 11:27 - 2013-10-10 10:23 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-12 11:27 - 2013-10-10 10:22 - 00222720 _____ (Microsoft Corporation) C:\Windows\system32\scrobj.dll
2013-12-12 11:27 - 2013-10-10 10:22 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-12 10:17 - 2013-11-23 07:43 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-12 10:17 - 2013-11-23 06:05 - 00368640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-12-12 10:17 - 2013-11-07 00:18 - 04036608 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-12 10:17 - 2013-11-01 06:38 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-12 10:17 - 2013-11-01 04:49 - 00273408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2013-12-12 08:56 - 2013-10-19 06:45 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-12 08:56 - 2013-10-19 05:04 - 00059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
==================== One Month Modified Files and Folders =======
2014-01-08 21:16 - 2014-01-08 21:16 - 00010538 _____ C:\Users\Metallica41\Desktop\FRST.txt
2014-01-08 21:15 - 2014-01-08 21:15 - 00448512 _____ (OldTimer Tools) C:\Users\Metallica41\Downloads\TFC.exe
2014-01-08 21:12 - 2013-09-06 22:59 - 00000387 _____ C:\Users\Metallica41\AppData\Roaming\sp_data.sys
2014-01-08 21:12 - 2012-07-26 08:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-08 21:11 - 2012-07-26 06:26 - 00262144 ___SH C:\Windows\system32\config\BBI
2014-01-08 21:10 - 2014-01-08 20:50 - 00000000 ____D C:\FRST
2014-01-08 21:09 - 2014-01-08 21:09 - 01931770 _____ (Farbar) C:\Users\Metallica41\Desktop\FRST64.exe
2014-01-08 21:00 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\system32\sru
2014-01-08 20:47 - 2013-06-09 18:00 - 00000000 ____D C:\Users\Metallica41\Desktop\New folder (2)
2014-01-08 20:45 - 2013-11-09 15:40 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-08 20:42 - 2012-10-24 22:03 - 01360120 _____ C:\Windows\WindowsUpdate.log
2014-01-08 17:05 - 2014-01-08 12:34 - 00000000 ____D C:\ProgramData\MFAData
2014-01-08 15:01 - 2014-01-08 15:00 - 00283800 _____ C:\Windows\Minidump\010814-61562-01.dmp
2014-01-08 15:00 - 2014-01-08 14:56 - 00000000 ____D C:\Windows\Minidump
2014-01-08 15:00 - 2014-01-08 14:55 - 327547873 _____ C:\Windows\MEMORY.DMP
2014-01-08 14:56 - 2014-01-08 14:56 - 00262144 _____ C:\Windows\Minidump\010814-54937-01.dmp
2014-01-08 14:56 - 2013-09-06 22:42 - 00000000 ____D C:\Users\Metallica41
2014-01-08 14:07 - 2014-01-08 14:07 - 00000678 _____ C:\Users\Public\Desktop\Oblivion.lnk
2014-01-08 14:03 - 2014-01-08 14:02 - 00028236 _____ C:\Windows\DirectX.log
2014-01-08 14:01 - 2013-03-25 18:48 - 00000000 ____D C:\Users\Metallica41\Documents\My Games
2014-01-08 13:49 - 2013-11-02 06:47 - 00000000 ____D C:\Users\Metallica41\AppData\Roaming\uTorrent
2014-01-08 12:56 - 2014-01-08 12:34 - 00000000 ____D C:\Users\Metallica41\AppData\Local\Avg2014
2014-01-08 12:55 - 2012-07-26 06:26 - 00262144 ___SH C:\Windows\system32\config\ELAM
2014-01-08 12:39 - 2014-01-08 12:39 - 00000000 ____D C:\Users\Metallica41\AppData\Roaming\AVG2014
2014-01-08 12:38 - 2014-01-08 12:38 - 00000967 _____ C:\Users\Public\Desktop\AVG 2014.lnk
2014-01-08 12:38 - 2014-01-08 12:38 - 00000000 ____D C:\Users\Metallica41\AppData\Roaming\TuneUp Software
2014-01-08 12:38 - 2014-01-08 12:37 - 00000000 ____D C:\ProgramData\AVG2014
2014-01-08 12:38 - 2012-07-26 09:12 - 00000000 ___HD C:\Windows\ELAMBKUP
2014-01-08 12:37 - 2014-01-08 12:37 - 00000000 ___HD C:\$AVG
2014-01-08 12:37 - 2014-01-08 12:37 - 00000000 ____D C:\Program Files (x86)\AVG
2014-01-08 12:34 - 2014-01-08 12:34 - 00000000 ____D C:\Users\Metallica41\AppData\Local\MFAData
2014-01-07 15:32 - 2014-01-06 15:34 - 00000000 ____D C:\Users\Metallica41\Downloads\The.Elder.Scrolls.IV.Oblivion-RELOADED
2014-01-07 14:00 - 2013-11-16 14:30 - 00000000 ____D C:\Users\Metallica41\Downloads\New folder
2014-01-07 12:54 - 2013-09-07 20:32 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-473922799-1250382268-3828485289-1001
2014-01-07 11:42 - 2014-01-07 11:42 - 00178800 _____ (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt_x64.dll
2014-01-07 03:52 - 2014-01-03 00:22 - 00005034 _____ C:\Windows\PFRO.log
2014-01-06 22:49 - 2014-01-06 22:49 - 00000897 _____ C:\Users\Metallica41\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MassEffect.lnk
2014-01-06 22:48 - 2014-01-06 22:48 - 00000000 ____D C:\Users\Metallica41\Documents\BioWare
2014-01-06 17:20 - 2014-01-06 17:20 - 00000000 ____D C:\ProgramData\SystemRequirementsLab
2014-01-06 17:20 - 2014-01-06 17:20 - 00000000 ____D C:\Program Files (x86)\SystemRequirementsLab
2014-01-06 15:59 - 2014-01-04 16:54 - 00000000 ____D C:\Program Files (x86)\SpeedFan
2014-01-05 21:00 - 2013-12-14 22:45 - 00000000 ____D C:\Users\Metallica41\Documents\Command and Conquer Generals Data
2014-01-04 16:54 - 2014-01-04 16:54 - 00001009 _____ C:\Users\Metallica41\Desktop\SpeedFan.lnk
2014-01-04 16:54 - 2014-01-01 11:47 - 00001009 _____ C:\Users\Administrator\Desktop\SpeedFan.lnk
2014-01-04 16:54 - 2014-01-01 11:47 - 00000045 _____ C:\Windows\SysWOW64\initdebug.nfo
2014-01-04 16:05 - 2014-01-04 16:04 - 00000000 ____D C:\Users\Metallica41\Documents\NFS Most Wanted
2014-01-03 00:24 - 2013-12-24 21:14 - 00000000 ____D C:\ProgramData\ProductData
2014-01-03 00:23 - 2014-01-03 00:22 - 00283248 _____ C:\Windows\system32\FNTCACHE.DAT
2014-01-02 17:21 - 2013-09-06 23:37 - 00000000 ____D C:\Windows.old
2014-01-02 17:20 - 2013-11-24 20:53 - 00000000 ____D C:\Users\Metallica41\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HyperCam 2
2014-01-02 17:20 - 2013-10-11 15:06 - 00000000 ____D C:\Users\Metallica41\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Cs 1.6 Background Maker v3.0
2014-01-02 17:19 - 2012-08-02 23:24 - 00000000 ____D C:\Windows\Panther
2014-01-02 17:10 - 2014-01-02 17:10 - 00002784 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-01-02 17:10 - 2014-01-02 17:10 - 00000824 _____ C:\Users\Public\Desktop\CCleaner.lnk
2014-01-02 17:10 - 2014-01-02 17:10 - 00000000 ____D C:\Program Files\CCleaner
2014-01-01 16:26 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\AUInstallAgent
2014-01-01 11:42 - 2014-01-01 11:42 - 00003152 _____ C:\Windows\System32\Tasks\{8A23795F-E7F5-474A-9868-DCB5B069D153}
2013-12-26 00:42 - 2013-12-25 01:52 - 00000000 ___HD C:\Users\Metallica41\Desktop\New folder (4)
2013-12-25 01:54 - 2013-12-24 23:23 - 00000700 ___SH C:\Users\Metallica41\AppData\Local\systemFL7.dat
2013-12-25 01:22 - 2012-10-24 21:47 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-12-25 01:20 - 2013-12-25 01:19 - 00000318 _____ C:\Windows\SIERRA.INI
2013-12-25 00:00 - 2013-10-11 20:10 - 00000000 ____D C:\Users\Metallica41\AppData\Roaming\Skype
2013-12-24 23:12 - 2013-12-24 23:12 - 00000000 ____D C:\Program Files (x86)\NewSoftware's
2013-12-24 21:17 - 2013-12-14 08:02 - 00000000 ____D C:\Users\Metallica41\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Return to Castle Wolfenstein
2013-12-14 23:24 - 2013-12-14 22:53 - 00000000 ____D C:\Users\Metallica41\Documents\Command and Conquer Generals Zero Hour Data
2013-12-14 22:51 - 2013-12-14 22:44 - 00000983 _____ C:\Windows\eReg.dat
2013-12-14 20:56 - 2013-11-30 10:03 - 00000000 ____D C:\Users\Metallica41\Downloads\Guitar Pro 5
2013-12-14 08:02 - 2013-12-14 08:02 - 00000838 _____ C:\Users\Administrator\Desktop\Wolfenstein (Single Player).lnk
2013-12-14 08:02 - 2013-12-14 08:02 - 00000838 _____ C:\Users\Administrator\Desktop\Wolfenstein (Multiplayer).lnk
2013-12-14 08:02 - 2013-12-14 07:58 - 00000965 _____ C:\Windows\Rtcw.INI
2013-12-14 00:21 - 2013-12-14 00:20 - 00000000 ____D C:\Users\Metallica41\Downloads\The.Hobbit.The.Desolation.of.Smaug.2013.DVDRip
2013-12-13 16:40 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\rescache
2013-12-13 10:28 - 2012-07-26 08:28 - 00848230 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-13 10:21 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\SysWOW64\en-GB
2013-12-13 10:21 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\system32\en-GB
2013-12-13 10:21 - 2012-07-26 06:38 - 00000000 ____D C:\Windows\system32\oobe
2013-12-12 10:07 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\system32\SecureBootUpdates
2013-12-10 19:45 - 2013-11-09 15:40 - 00003718 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-12-10 14:13 - 2013-10-11 20:10 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-12-10 14:13 - 2013-10-11 20:10 - 00000000 ____D C:\ProgramData\Skype
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-08 12:49
==================== End Of Log ============================
Evo uradio sam mogu reci da vise nema coin miner otkad sam obrisao ona 2 virusa ako nesto jos treba da uradim javite!
|
|
|
|
Poslao: 08 Jan 2014 21:44
|
offline
- ivance95

- AMF pripravnik
- Pridružio: 04 Jul 2011
- Poruke: 5424
|
Moramo da ponovimo skriptu. Nakon ovoga će ti se kompjuter restartovati, ugasi sve programe pre pokretanja.
Otvori Notepad i iskopiraj sledeći tekst koji se nalazi unutar osenčenog prostora.
Startup: C:\Users\Metallica41\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Skype.lnk
CMD: shutdown /r /t3
U okviru Notepad-a klikni na File --> Save As
Fajl nazovi Fixlist i sačuvaj na Desktop
Dvoklikom ponovo pokreni FRST.exe
Klikni na Fix i sačekaj dok program ne završi.
Ukoliko program zatraži restart računara, omogući mu da to nesmetano obavi.
Nakon završetka rada, otvoriće se Notepad, sa sadržajem koji treba da kopiraš u temu.
Takođe, na Desktop-u će se nalaziti (fixlog.txt).
Potrebno je da fixlog.txt kopiras na forum
Preuzmi Kaspersky Lab-ov TDSSKiller sa sledece adrese na Desktop:
TDSSKiller
Klikni desnim tasterom na link i odaberi opciju Save Target As... (Save Link As..., Save Linked Content As... ili slicnu);
Kada se otvori dijalog za izbor lokacije na kojoj treba sacuvati file, odaberi Desktop i klikni Save.
Kada preuzimanje programa bude završeno:
deaktiviraj zaštitni softver (uputstvo);
zatvori pokrenute programe;
preimenuj TDSSKiller.exe u MyCity.exe;
dvoklikom pokreni program MyCity.exe;
klik na dugme Start Scan.
Ukoliko maliciozni (malicious) objekti budu pronadjeni, uveri se da je za njih odabrana akcija "Cure" (primer) i klikni Continue, a zatim klikni Reboot Now.
Okaci mi sadrzaj log-a sa sledece lokacije:
C:\TDSSKiller_verzija programa_DD.MM.GG_HH.MM.SS.txt
(DD-dan, MM-mesec, GG-godina, HH-sat, MM-minut, SS-sekunda; datum i vreme kada je log napravljen)
Ivance95 (AMF Tim)
|
|
|
|
|
|