1. Dodjoh malo pre iz grada i imao sta da vidim, komp radi katastrofa, internet kao da imam dialap..
Uradio mu skeniranje sa Esencijalom, Adw, deinstalaciom nepotrebnih programa i nema napredka.
P.s .. i ciscenje broswer-a.
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 08-12-2014
Ran by prle (administrator) on PRLE-PC on 08-12-2014 20:58:23
Running from C:\Muzika
Loaded Profiles: prle & UpdatusUser (Available profiles: prle & UpdatusUser)
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: engleski (SAD)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-t.....scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\Windows\System32\audiodg.exe
(Stardock Corporation) C:\Program Files\Stardock\WindowBlinds\WBSrv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Stardock Software, Inc) C:\Program Files\Stardock\WindowBlinds\WBCore.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(MyCity) C:\Program Files\MCShield\MCShieldRTM.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(TopLang Software) C:\Program Files\Password Door\TLPD.EXE
(BitTorrent Inc.) C:\Users\prle\AppData\Roaming\uTorrent\uTorrent.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Ultra\DiscSoftBusService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Skillbrains) C:\Users\prle\AppData\Local\Skillbrains\lightshot\5.1.4.34\Lightshot.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Luxand Blink!] => C:\Program Files\Luxand\Blink!\LuxandBlinkTray.exe [7630656 2012-02-07] (Luxand, Inc.)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [995176 2013-06-20] (Microsoft Corporation)
HKLM\...\Run: [Fences] => C:\Program Files\Stardock\Fences\Fences.exe [3992208 2014-10-03] (Stardock Corporation)
Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X]
HKU\S-1-5-21-1606030900-3430388029-1771253369-1000\...\Run: [MCShield Monitor] => C:\Program Files\MCShield\mcshieldrtm.exe [650816 2014-04-11] (MyCity)
HKU\S-1-5-21-1606030900-3430388029-1771253369-1000\...\Run: [] => [X]
HKU\S-1-5-21-1606030900-3430388029-1771253369-1000\...\Run: [Password Door] => C:\Program Files\Password Door\TLPD.EXE [61952 2008-03-22] (TopLang Software)
HKU\S-1-5-21-1606030900-3430388029-1771253369-1000\...\Run: [uTorrent] => C:\Users\prle\AppData\Roaming\uTorrent\uTorrent.exe [1385808 2014-11-12] (BitTorrent Inc.)
HKU\S-1-5-21-1606030900-3430388029-1771253369-1000\...\Run: [DAEMON Tools Ultra Agent] => C:\Program Files\DAEMON Tools Ultra\DTAgent.exe [3639568 2014-07-10] (Disc Soft Ltd)
HKU\S-1-5-21-1606030900-3430388029-1771253369-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [30528608 2014-11-27] (Skype Technologies S.A.)
HKU\S-1-5-21-1606030900-3430388029-1771253369-1000\...\MountPoints2: {1ac22040-806c-11e3-b5d0-806e6f6e6963} - H:\setup.exe
HKU\S-1-5-21-1606030900-3430388029-1771253369-1003\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [354304 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-1606030900-3430388029-1771253369-1003\...\Run: [Password Door] => C:\Program Files\Password Door\TLPD.EXE [61952 2008-03-22] (TopLang Software)
HKU\S-1-5-21-1606030900-3430388029-1771253369-1003\...\Run: [LightShot] => C:\Users\UpdatusUser\AppData\Local\Skillbrains\lightshot\Lightshot.exe Flags: uninsdeletevalue
Startup: C:\Users\prle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TornTvDownloader.lnk
ShortcutTarget: TornTvDownloader.lnk -> C:\Users\prle\AppData\Roaming\TornTV.com\TornTV Downloader.exe (No File)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
HKU\S-1-5-21-1606030900-3430388029-1771253369-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
HKU\S-1-5-21-1606030900-3430388029-1771253369-1003\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKU\S-1-5-21-1606030900-3430388029-1771253369-1000 -> DefaultScope {72302D6D-935C-4346-A5BB-96881B825ED8} URL = https://search.yahoo.com/search?fr=chr-greentree_i.....549&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1606030900-3430388029-1771253369-1000 -> {0E90424D-0616-420E-8E5C-6B6FD05CD6D7} URL = http://www.bing.com/search?FORM=WLETDF&PC=WLEM&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1606030900-3430388029-1771253369-1000 -> {72302D6D-935C-4346-A5BB-96881B825ED8} URL = https://search.yahoo.com/search?fr=chr-greentree_i.....549&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1606030900-3430388029-1771253369-1003 -> {0E90424D-0616-420E-8E5C-6B6FD05CD6D7} URL = http://www.bing.com/search?FORM=WLETDF&PC=WLEM&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1606030900-3430388029-1771253369-1003 -> {32D5563E-5F7D-4739-96F8-18D1390F66B7} URL = http://www.dogpile.com/search/web?fcoid=417&fc.....ql=&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1606030900-3430388029-1771253369-1003 -> {3A748936-3C4B-4965-A0AA-94D2CA2592F8} URL = http://search.ividi.org/?q={searchTerms}&src=tbsp&id=2cf1ec7b0000000000006c626d450386&affilt=3&r=553
SearchScopes: HKU\S-1-5-21-1606030900-3430388029-1771253369-1003 -> {9E06BDCF-0BDA-468E-B603-AEFD462C9890} URL = http://search.softonic.com/INF00176/tb_v1?q={searchTerms}&SearchSource=4&cc=&mi=2cf1ec7b0000000000006c626d450386&r=669
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 8.8.8.8 8.8.4.4
FireFox:
========
FF ProfilePath: C:\Users\prle\AppData\Roaming\Mozilla\Firefox\Profiles\jama4nzo.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_239.dll ()
FF Plugin: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @nokia.com/EnablerPlugin -> C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @verimatrix.com/ViewRightWeb -> C:\Program Files\Verimatrix\ViewRight Web\\npViewRight.dll (Verimatrix, Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1606030900-3430388029-1771253369-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\prle\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-1606030900-3430388029-1771253369-1000: @verimatrix.com/ViewRightWeb -> C:\Program Files\Verimatrix\ViewRight Web\\npViewRight.dll (Verimatrix, Inc.)
FF SearchPlugin: C:\Users\prle\AppData\Roaming\Mozilla\Firefox\Profiles\jama4nzo.default\searchplugins\yahoo_ff.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\pogodakyu.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\vokabular.xml
FF Extension: LavaFox V2 - C:\Users\prle\AppData\Roaming\Mozilla\Firefox\Profiles\jama4nzo.default\Extensions\info@djzig.com [2014-10-09]
FF Extension: Lightweight Themes Manager - C:\Users\prle\AppData\Roaming\Mozilla\Firefox\Profiles\jama4nzo.default\Extensions\lwthemes-manager@loucypher.xpi [2014-03-17]
FF Extension: Stylish - C:\Users\prle\AppData\Roaming\Mozilla\Firefox\Profiles\jama4nzo.default\Extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi [2014-03-17]
FF Extension: YouTube High Definition - C:\Users\prle\AppData\Roaming\Mozilla\Firefox\Profiles\jama4nzo.default\Extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi [2014-03-17]
FF Extension: Adblock Plus - C:\Users\prle\AppData\Roaming\Mozilla\Firefox\Profiles\jama4nzo.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-03-17]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-07-14]
FF StartMenuInternet: FIREFOX.EXE - firefox.exe
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.rs/
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\prle\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Auto Replay for YouTube™) - C:\Users\prle\AppData\Local\Google\Chrome\User Data\Default\Extensions\kanbnempkjnhadplbfgdaagijdbdbjeb [2014-12-05]
CHR Extension: (Google новчаник) - C:\Users\prle\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-04]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
R3 Disc Soft Bus Service; C:\Program Files\DAEMON Tools Ultra\DiscSoftBusService.exe [887056 2014-07-10] (Disc Soft Ltd)
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-06-20] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [295376 2013-06-20] (Microsoft Corporation)
R2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.)
S3 SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 WindowBlinds; C:\Program Files\Stardock\WindowBlinds\wbsrv.exe [84592 2014-03-10] (Stardock Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 athur; C:\Windows\System32\DRIVERS\athur.sys [1570304 2012-10-18] (Atheros Communications, Inc.)
R3 dtscsibus; C:\Windows\System32\DRIVERS\dtscsibus.sys [24704 2014-12-02] (Disc Soft Ltd)
S3 gggen; C:\Windows\System32\DRIVERS\gggen.sys [11648 2006-09-28] (Sony Ericsson Mobile Communications) [File not signed]
S3 ggsemc; C:\Windows\System32\DRIVERS\ggsemc.sys [11648 2006-09-28] (Sony Ericsson Mobile Communications) [File not signed]
S3 ggsomc; C:\Windows\System32\DRIVERS\ggsomc.sys [26328 2014-08-03] (Sony Mobile Communications)
S3 hcdriver; C:\Windows\System32\DRIVERS\hcdriver.sys [55208 2013-08-21] (Intel Corporation)
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO32.SYS [22688 2014-07-20] (REALiX(tm))
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-11-21] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-11-21] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [211560 2013-06-18] (Microsoft Corporation)
R1 MpKsl37cef3d6; C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{CCF0773D-A24F-4CC3-BC2F-0A927F53E5A8}\MpKsl37cef3d6.sys [39464 2014-12-08] (Microsoft Corporation)
S3 s0016bus; C:\Windows\System32\DRIVERS\s0016bus.sys [89256 2008-05-16] (MCCI Corporation)
S3 s0016mdfl; C:\Windows\System32\DRIVERS\s0016mdfl.sys [15016 2008-05-16] (MCCI Corporation)
S3 s0016mdm; C:\Windows\System32\DRIVERS\s0016mdm.sys [120744 2008-05-16] (MCCI Corporation)
S3 s0016mgmt; C:\Windows\System32\DRIVERS\s0016mgmt.sys [114216 2008-05-16] (MCCI Corporation)
S3 s0016nd5; C:\Windows\System32\DRIVERS\s0016nd5.sys [25512 2008-05-16] (MCCI Corporation)
S3 s0016obex; C:\Windows\System32\DRIVERS\s0016obex.sys [110632 2008-05-16] (MCCI Corporation)
S3 s0016unic; C:\Windows\System32\DRIVERS\s0016unic.sys [115752 2008-05-16] (MCCI Corporation)
S3 s125bus; C:\Windows\System32\DRIVERS\s125bus.sys [83336 2007-04-24] (MCCI Corporation)
S3 s125mdfl; C:\Windows\System32\DRIVERS\s125mdfl.sys [15112 2007-04-24] (MCCI Corporation)
S3 s125mdm; C:\Windows\System32\DRIVERS\s125mdm.sys [108680 2007-04-24] (MCCI Corporation)
S3 s125mgmt; C:\Windows\System32\DRIVERS\s125mgmt.sys [100488 2007-04-24] (MCCI Corporation)
S3 s125obex; C:\Windows\System32\DRIVERS\s125obex.sys [98696 2007-04-24] (MCCI Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [466008 2014-01-18] (Duplex Secure Ltd.)
S3 USBAAPL; C:\Windows\System32\Drivers\usbaapl.sys [45056 2012-12-13] (Apple, Inc.) [File not signed]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-08 20:48 - 2014-12-08 20:48 - 00000000 ____D () C:\Users\Public\Documents\Sports Interactive
2014-12-08 20:48 - 2014-12-08 20:48 - 00000000 ____D () C:\Users\prle\Documents\Sports Interactive
2014-12-08 20:47 - 2014-12-08 20:47 - 00002214 _____ () C:\Users\prle\Desktop\Play Football Manager 2015.lnk
2014-12-08 20:43 - 2014-12-08 20:47 - 00000000 ____D () C:\Program Files\Football Manager 2015
2014-12-08 20:39 - 2014-12-08 20:39 - 00000000 __RSH () C:\MSDOS.SYS
2014-12-08 20:39 - 2014-12-08 20:39 - 00000000 __RSH () C:\IO.SYS
2014-12-08 20:33 - 2014-12-08 20:33 - 00001194 _____ () C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
2014-12-08 20:33 - 2014-12-08 20:33 - 00000000 ____D () C:\ProgramData\VS Revo Group
2014-12-08 20:33 - 2014-12-08 20:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2014-12-08 20:33 - 2014-12-08 20:33 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-12-08 20:33 - 2009-12-30 11:21 - 00027192 _____ (VS Revo Group) C:\Windows\system32\Drivers\revoflt.sys
2014-12-08 19:16 - 2014-12-08 19:16 - 00006874 _____ () C:\Users\prle\Desktop\JRT.txt
2014-12-08 19:09 - 2014-12-08 19:09 - 00000055 _____ () C:\AdwCleanerDebug.txt
2014-12-08 19:06 - 2014-12-08 19:09 - 01707646 _____ (Thisisu) C:\Users\prle\Desktop\JRT.exe
2014-12-08 01:36 - 2014-12-08 19:01 - 00000000 ____D () C:\Users\prle\Documents\Football Manager 2015 PC full game ^^nosTEAM^^
2014-12-08 01:34 - 2014-12-08 01:34 - 00001042 _____ () C:\Users\prle\Desktop\Torntv Downloader.lnk
2014-12-07 06:27 - 2014-12-07 06:27 - 00000000 ____D () C:\Users\prle\AppData\Roaming\Verimatrix
2014-12-07 06:24 - 2014-12-07 06:24 - 00000000 ____D () C:\Program Files\Verimatrix
2014-12-04 04:30 - 2014-12-04 04:43 - 00000000 ____D () C:\The.Orphanage.2007.1080p.BluRay.x264.anoXmous
2014-12-02 23:07 - 2014-12-08 19:12 - 00004988 _____ () C:\Windows\PFRO.log
2014-12-02 23:07 - 2014-12-08 19:12 - 00003472 _____ () C:\Windows\setupact.log
2014-12-02 23:07 - 2014-12-02 23:07 - 00000000 _____ () C:\Windows\setuperr.log
2014-12-02 23:06 - 2014-12-02 23:06 - 00000794 _____ () C:\Users\prle\Desktop\Half-Life WaRzOnE.lnk
2014-12-02 23:06 - 2014-12-02 23:06 - 00000732 _____ () C:\Users\prle\Desktop\HLDS.lnk
2014-12-02 23:06 - 2014-12-02 23:06 - 00000000 ____D () C:\Users\prle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HLDS
2014-12-02 23:06 - 2014-12-02 23:06 - 00000000 ____D () C:\Users\prle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Half-Life
2014-12-02 22:59 - 2014-12-02 22:59 - 02154496 _____ () C:\Users\prle\Documents\adwcleaner_4.103.exe
2014-12-02 22:42 - 2014-12-08 20:47 - 00001337 _____ () C:\Users\prle\Desktop\visit www.nosteam.ro.lnk
2014-12-02 22:11 - 2014-12-02 22:30 - 00000000 ____D () C:\Football Manager 2015 PC full game ^^nosTEAM^^
2014-12-02 21:13 - 2014-12-02 21:13 - 00000000 ____D () C:\Users\prle\AppData\Local\Disc_Soft_Ltd
2014-12-02 21:06 - 2014-12-02 21:07 - 00000000 ____D () C:\Users\prle\AppData\Roaming\DAEMON Tools Ultra
2014-12-02 21:06 - 2014-12-02 21:06 - 00024704 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtscsibus.sys
2014-12-02 21:06 - 2014-12-02 21:06 - 00001899 _____ () C:\Users\Public\Desktop\DAEMON Tools Ultra.lnk
2014-12-02 21:06 - 2014-12-02 21:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Ultra
2014-12-02 21:05 - 2014-12-02 21:06 - 00000000 ____D () C:\Program Files\DAEMON Tools Ultra
2014-12-02 21:05 - 2014-12-02 21:05 - 00000000 ____D () C:\ProgramData\DAEMON Tools Ultra
2014-12-02 19:57 - 2014-12-02 20:56 - 00000000 ____D () C:\3DMGAME-Football.Manager.2015.v15.1.3.(zabranjeno)ed-3DM
2014-12-01 02:07 - 2014-12-01 02:07 - 00000000 ____D () C:\Users\prle\Desktop\Nova fascikla (3)
2014-11-28 18:11 - 2014-12-08 20:58 - 00000000 ____D () C:\Muzika
2014-11-28 17:42 - 2014-11-28 18:03 - 192866304 _____ () C:\Users\prle\Downloads\YouPorn - Once in the pink then in the stink Shock Wave.mpg
2014-11-23 19:23 - 2014-12-08 19:12 - 00000506 ____H () C:\Windows\Tasks\BrickBooster-S-1408900467.job
2014-11-23 19:22 - 2014-11-23 19:22 - 00000000 ____D () C:\ProgramData\bpjmjekfgokdfmobdiaeahaoepiibceh
2014-11-23 19:21 - 2014-11-23 19:21 - 00000000 ____D () C:\ProgramData\okkcpilbalclmgpkckfamkookccfniao
2014-11-22 23:44 - 2014-11-22 23:49 - 00000000 ____D () C:\StarLite
2014-11-22 23:44 - 2014-11-22 23:44 - 00000606 _____ () C:\Users\UpdatusUser\Desktop\StarLite.lnk
2014-11-22 23:44 - 2014-11-22 23:44 - 00000606 _____ () C:\Users\prle\Desktop\StarLite.lnk
2014-11-22 23:44 - 2014-11-22 23:44 - 00000000 ____D () C:\Users\prle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StarLite Astrology
2014-11-22 23:44 - 2014-11-22 23:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StarLite Astrology
2014-11-17 18:25 - 2014-11-17 18:25 - 00000000 ____D () C:\Users\prle\AppData\Local\Skillbrains
2014-11-17 04:09 - 2014-11-17 04:09 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_WinUsb_01009.Wdf
2014-11-16 16:03 - 2014-11-16 16:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stardock
2014-11-16 16:03 - 2014-11-16 16:03 - 00001936 _____ () C:\Users\prle\Desktop\Customize Fences.lnk
2014-11-12 22:08 - 2014-11-12 22:08 - 00000000 ____D () C:\Users\prle\Desktop\Nikola Slike
2014-11-12 21:48 - 2014-12-05 16:10 - 00001024 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-08 20:58 - 2014-08-25 12:19 - 00000000 ____D () C:\FRST
2014-12-08 20:54 - 2013-06-28 11:51 - 00000000 ____D () C:\Users\prle\AppData\Roaming\uTorrent
2014-12-08 20:53 - 2014-07-27 00:56 - 00000000 ____D () C:\Users\prle\AppData\Roaming\Skype
2014-12-08 20:41 - 2013-07-25 18:20 - 00000000 ____D () C:\Games
2014-12-08 20:39 - 2014-03-04 19:39 - 00000000 ____D () C:\WinSetupFromUSB
2014-12-08 20:30 - 2013-06-28 12:04 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-12-08 20:25 - 2013-08-28 16:39 - 00000916 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-12-08 19:38 - 2014-07-18 21:21 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-12-08 19:19 - 2013-06-28 11:15 - 00778150 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-08 19:16 - 2014-07-27 21:37 - 01946542 _____ () C:\Windows\WindowsUpdate.log
2014-12-08 19:14 - 2014-07-20 14:19 - 00000000 ____D () C:\Windows\ERUNT
2014-12-08 19:12 - 2014-07-24 20:07 - 00000000 ____D () C:\ProgramData\MCShield
2014-12-08 19:12 - 2013-08-28 16:39 - 00000912 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-12-08 19:12 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-08 19:11 - 2014-08-25 21:09 - 00000000 ____D () C:\AdwCleaner
2014-12-08 01:39 - 2014-08-07 20:20 - 00000000 ____D () C:\Program Files\Football Manager 2014
2014-12-07 22:38 - 2013-08-20 20:26 - 02390016 ___SH () C:\Users\prle\Desktop\Thumbs.db
2014-12-07 22:21 - 2009-07-14 05:34 - 00013904 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-07 22:21 - 2009-07-14 05:34 - 00013904 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-05 23:01 - 2013-07-16 20:46 - 00000000 ____D () C:\Users\prle\AppData\Local\Windows Live
2014-12-05 16:10 - 2014-07-18 21:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-12-05 16:10 - 2014-07-18 21:21 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-12-04 18:21 - 2013-08-28 16:40 - 00002167 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-12-04 18:20 - 2013-06-28 11:59 - 00000000 ____D () C:\Program Files\Google
2014-12-03 22:27 - 2013-06-28 12:09 - 00000000 ___RD () C:\Program Files\Skype
2014-12-03 22:27 - 2013-06-28 12:09 - 00000000 ____D () C:\ProgramData\Skype
2014-12-03 15:25 - 2014-08-04 12:39 - 00000000 ____D () C:\Users\prle\AppData\Local\CrashDumps
2014-12-02 23:06 - 2014-05-15 15:18 - 00001698 _____ () C:\Users\prle\Desktop\Counter-Strike WaRzOnE.lnk
2014-12-02 23:06 - 2014-01-21 03:15 - 00000000 ____D () C:\Users\prle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-12-02 23:06 - 2013-08-29 19:15 - 00000983 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-12-02 23:06 - 2013-08-29 19:15 - 00000971 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-12-02 23:06 - 2013-08-28 16:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-12-02 23:06 - 2013-06-28 11:48 - 00000897 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2014-12-02 23:06 - 2013-06-28 11:11 - 00001106 _____ () C:\Users\prle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-12-02 22:52 - 2013-07-19 12:46 - 00000102 _____ () C:\Users\prle\AppData\default.pls
2014-12-02 22:38 - 2009-07-14 03:04 - 00000580 _____ () C:\Windows\win.ini
2014-12-02 22:32 - 2014-02-14 22:22 - 00000464 __RSH () C:\ProgramData\ntuser.pol
2014-12-02 22:13 - 2009-07-14 03:37 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-12-02 21:01 - 2013-07-08 19:46 - 00000000 ____D () C:\Users\prle\AppData\Local\Sports Interactive
2014-11-28 18:05 - 2014-05-26 23:00 - 00211456 ___SH () C:\Users\prle\Downloads\Thumbs.db
2014-11-27 07:51 - 2013-06-28 12:11 - 00000000 ____D () C:\Users\prle\AppData\Roaming\Winamp
2014-11-27 07:50 - 2014-07-17 18:07 - 00000000 ____D () C:\Windows\Minidump
2014-11-26 15:30 - 2013-06-28 12:04 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-11-26 15:30 - 2013-06-28 12:04 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-11-26 14:36 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Cursors
2014-11-21 06:14 - 2014-07-18 21:21 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-11-21 06:14 - 2014-07-18 21:21 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-11-21 06:14 - 2014-07-18 21:20 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-11-17 18:25 - 2013-11-22 22:39 - 00000000 ____D () C:\Users\prle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LightShot
2014-11-16 16:05 - 2014-10-07 01:33 - 00000000 ____D () C:\Users\prle\AppData\Local\Stardock
2014-11-16 16:05 - 2014-01-08 17:54 - 00000000 ____D () C:\ProgramData\Stardock
2014-11-16 16:03 - 2014-10-07 01:36 - 00000000 ____D () C:\Users\Public\Documents\Stardock
2014-11-16 16:03 - 2014-10-07 01:32 - 00000000 ____D () C:\Users\prle\Downloads\Stardock
2014-11-16 16:03 - 2014-01-08 17:47 - 00000000 ____D () C:\Program Files\Stardock
2014-11-13 13:13 - 2013-07-04 16:38 - 00000000 ____D () C:\Users\prle\AppData\Roaming\PC Suite
2014-11-12 23:34 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-11-12 23:25 - 2014-07-07 01:49 - 00000000 ____D () C:\Windows\pss
2014-11-12 22:08 - 2013-11-25 16:42 - 00000000 ____D () C:\Users\prle\Desktop\Nova fascikla (2)
2014-11-12 22:04 - 2013-06-29 21:06 - 00058016 _____ () C:\Users\prle\AppData\Local\GDIPFONTCACHEV1.DAT
2014-11-12 22:03 - 2009-07-14 05:33 - 03665440 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-11-12 21:43 - 2014-08-25 23:56 - 00000000 ____D () C:\Users\prle\AppData\Local\FluxSoftware
2014-11-12 20:14 - 2013-06-28 11:10 - 00000000 ____D () C:\Users\prle
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-12-05 12:52
==================== End Of Log ============================
https://www.mycity.rs/must-login.png
|