Zdravo mi se pojavio toolbar kad sam nesto skidao ja sam uklonio koliko sam mogao ali ponekad mi se sam otvori google chrome i kad hocu da udjem u neku stranicu iskoci mi reklama.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 08-05-2017
Ran by Fox (administrator) on DESKTOP-C5N35CO (13-05-2017 02:14:40)
Running from C:\Users\Fox\Desktop
Loaded Profiles: Fox (Available Profiles: Fox)
Platform: Windows 10 Pro Version 1703 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG)
HKU\S-1-5-21-2678727347-3077865498-453496965-1001\...\Run: [Gaijin.Net Agent] => C:\Users\Fox\AppData\Local\Gaijin\Program Files (x86)\NetAgent\gjagent.exe [2012616 2017-05-05] (Gaijin Entertainment)
HKU\S-1-5-21-2678727347-3077865498-453496965-1001\...\Run: [okfifwpquv] => explorer "hxxp://" <===== ATTENTION
IFEO\SppExtComObj.exe: [Debugger] SppExtComObjPatcher.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AnyDesk.lnk [2017-04-12]
ShortcutTarget: AnyDesk.lnk -> C:\Program Files (x86)\AnyDesk\AnyDesk.exe (No File)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TP-LINK Wireless Utility.lnk [2017-04-08]
ShortcutTarget: TP-LINK Wireless Utility.lnk -> C:\Program Files (x86)\TP-LINK\Common\TWCU.exe (TP-LINK TECHNOLOGIES CO., LTD. )
GroupPolicy: Restriction <======= ATTENTION
GroupPolicy\User: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer]
Tcpip\..\Interfaces\{ee870d53-b527-48da-8d98-37b94af573aa}: [DhcpNameServer]

Internet Explorer:
HKU\S-1-5-21-2678727347-3077865498-453496965-1001\Software\Microsoft\Internet Explorer\Main,Start Page = [Link mogu videti samo ulogovani korisnici]
SearchScopes: HKU\S-1-5-21-2678727347-3077865498-453496965-1001 -> DefaultScope {A06ED961-D98F-4CF9-A89B-80AB11DB149C} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}
SearchScopes: HKU\S-1-5-21-2678727347-3077865498-453496965-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}&src=IE-SearchBox&FORM=IESR02&pc=UE04
SearchScopes: HKU\S-1-5-21-2678727347-3077865498-453496965-1001 -> {A06ED961-D98F-4CF9-A89B-80AB11DB149C} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}

FF Plugin-x32: -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-05-01] (NVIDIA Corporation)
FF Plugin-x32: -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-05-01] (NVIDIA Corporation)
FF Plugin-x32: Update;version=3 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
FF Plugin-x32: Update;version=9 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)

CHR HomePage: Default -> [Link mogu videti samo ulogovani korisnici]
CHR StartupUrls: Default -> "hxxps://"
CHR DefaultSearchURL: Default -> [Link mogu videti samo ulogovani korisnici]{searchTerms}
CHR DefaultSearchKeyword: Default -> gosearch
CHR DefaultSuggestURL: Default -> [Link mogu videti samo ulogovani korisnici]{searchTerms}
CHR Profile: C:\Users\Fox\AppData\Local\Google\Chrome\User Data\Default [2017-05-13]
CHR Extension: (Google Drive) - C:\Users\Fox\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-04-08]
CHR Extension: (YouTube) - C:\Users\Fox\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-04-08]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Fox\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-04-08]
CHR Extension: (Gmail) - C:\Users\Fox\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-04-08]
CHR Extension: (Chrome Media Router) - C:\Users\Fox\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-12]
CHR HKLM-x32\...\Chrome\Extension: [epgjfmblhacacphaljkdcjllkomdcjpc] - [Link mogu videti samo ulogovani korisnici]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

2017-05-05 17:22 - 2017-05-05 17:22 - 00001300 _____ C:\Users\Fox\Desktop\Pro Evolution Soccer 2017.lnk
2017-05-05 17:22 - 2017-05-05 17:22 - 00000000 ____D C:\Users\Fox\Documents\KONAMI
2017-05-05 14:27 - 2017-05-10 19:33 - 00000000 ____D C:\Users\Fox\Downloads\Guns.Gore.and.Cannoli-CODEX
2017-04-28 15:29 - 2017-05-12 18:28 - 00548392 _____ C:\Windows\system32\Drivers\EasyAntiCheat.sys
2017-04-28 15:29 - 2017-04-28 15:29 - 00000000 ____D C:\Users\Fox\AppData\Roaming\EasyAntiCheat
2017-04-28 12:28 - 2017-04-19 09:07 - 00712600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms2.sys
2017-04-28 12:28 - 2017-04-19 09:06 - 00651680 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncHost.exe
2017-04-28 12:28 - 2017-04-19 09:04 - 00142240 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wcifs.sys
2017-04-28 12:28 - 2017-04-19 09:02 - 00716440 _____ (Microsoft Corporation) C:\Windows\system32\MSVideoDSP.dll
2017-04-28 12:28 - 2017-04-19 08:19 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\musdialoghandlers.dll
2017-04-28 12:28 - 2017-04-19 08:18 - 00118784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netvsc.sys
2017-04-28 12:28 - 2017-04-19 08:16 - 00280064 _____ (Microsoft Corporation) C:\Windows\system32\WiFiDisplay.dll
2017-04-28 12:28 - 2017-04-19 08:15 - 00232960 _____ (Microsoft Corporation) C:\Windows\system32\wcmcsp.dll
2017-04-28 12:28 - 2017-04-19 08:14 - 00646656 _____ (Microsoft Corporation) C:\Windows\system32\LockHostingFramework.dll
2017-04-28 12:28 - 2017-04-19 08:13 - 00585728 _____ (Microsoft Corporation) C:\Windows\system32\OneDriveSettingSyncProvider.dll
2017-04-28 12:28 - 2017-04-19 08:13 - 00409600 _____ (Microsoft Corporation) C:\Windows\system32\updatehandlers.dll
2017-04-28 12:28 - 2017-04-19 08:12 - 00805888 _____ (Microsoft Corporation) C:\Windows\system32\ieproxy.dll
2017-04-28 12:28 - 2017-04-19 08:12 - 00590848 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-04-28 12:28 - 2017-04-19 08:12 - 00203776 _____ (Microsoft Corporation) C:\Windows\system32\PackageStateRoaming.dll
2017-04-28 12:28 - 2017-04-19 08:11 - 04446208 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_nt.dll
2017-04-28 12:28 - 2017-04-19 08:11 - 00687104 _____ (Microsoft Corporation) C:\Windows\system32\LogonController.dll
2017-04-28 12:28 - 2017-04-19 08:10 - 04175872 _____ (Microsoft Corporation) C:\Windows\system32\StartTileData.dll
2017-04-28 12:28 - 2017-04-19 08:10 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Shell.UnifiedTile.CuratedTileCollections.dll
2017-04-28 12:28 - 2017-04-19 08:10 - 01600512 _____ (Microsoft Corporation) C:\Windows\system32\dbghelp.dll
2017-04-28 12:28 - 2017-04-19 08:08 - 01103872 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncCore.dll
2017-04-28 12:28 - 2017-04-19 08:08 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\usocore.dll
2017-04-28 12:28 - 2017-04-19 08:07 - 01242624 _____ (Microsoft Corporation) C:\Windows\system32\SharedStartModel.dll
2017-04-28 12:28 - 2017-04-19 08:07 - 00707072 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2017-04-28 12:28 - 2017-04-19 08:06 - 02651648 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2017-04-28 12:28 - 2017-04-19 08:04 - 01356800 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2017-04-28 12:28 - 2017-04-19 08:04 - 00624640 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll
2017-04-28 12:28 - 2017-04-19 08:02 - 00559000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncHost.exe
2017-04-28 12:28 - 2017-04-19 08:01 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\catsrvps.dll
2017-04-28 12:28 - 2017-04-19 07:59 - 02435584 _____ (Microsoft Corporation) C:\Windows\system32\ResetEngine.dll
2017-04-28 12:28 - 2017-04-19 07:59 - 01087488 _____ (Microsoft Corporation) C:\Windows\system32\reseteng.dll
2017-04-28 12:28 - 2017-04-19 07:58 - 20374424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2017-04-28 12:28 - 2017-04-19 07:37 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WiFiDisplay.dll
2017-04-28 12:28 - 2017-04-19 07:36 - 01291776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVPXENC.dll
2017-04-28 12:28 - 2017-04-19 07:35 - 00476672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OneDriveSettingSyncProvider.dll
2017-04-28 12:28 - 2017-04-19 07:34 - 00507392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-04-28 12:28 - 2017-04-19 07:34 - 00358400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieproxy.dll
2017-04-28 12:28 - 2017-04-19 07:34 - 00175616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PackageStateRoaming.dll
2017-04-28 12:28 - 2017-04-19 07:32 - 01285120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dbghelp.dll
2017-04-28 12:28 - 2017-04-19 07:30 - 00909312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncCore.dll
2017-04-28 12:28 - 2017-04-19 07:29 - 02298880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2017-04-28 12:28 - 2017-04-14 02:35 - 04848440 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2017-04-28 12:28 - 2017-04-14 02:35 - 00741784 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Shell.Broker.dll
2017-04-28 12:28 - 2017-04-14 02:35 - 00673112 _____ (Microsoft Corporation) C:\Windows\system32\AppResolver.dll
2017-04-28 12:28 - 2017-04-14 02:33 - 02085280 _____ (Microsoft Corporation) C:\Windows\system32\UpdateAgent.dll
2017-04-28 12:28 - 2017-04-14 02:32 - 01320352 _____ (Microsoft Corporation) C:\Windows\system32\wpx.dll
2017-04-28 12:28 - 2017-04-14 02:30 - 00105456 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2017-04-28 12:28 - 2017-04-14 02:25 - 01854880 _____ (Microsoft Corporation) C:\Windows\system32\AppVEntVirtualization.dll
2017-04-28 12:28 - 2017-04-14 02:25 - 01452960 _____ (Microsoft Corporation) C:\Windows\system32\AppVEntSubsystemController.dll
2017-04-28 12:28 - 2017-04-14 01:43 - 04469832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2017-04-28 12:28 - 2017-04-14 01:43 - 00523296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppResolver.dll
2017-04-28 12:28 - 2017-04-14 01:41 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\EnterpriseModernAppMgmtCSP.dll
2017-04-28 12:28 - 2017-04-14 01:41 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
2017-04-28 12:28 - 2017-04-14 01:40 - 00095584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2017-04-28 12:28 - 2017-04-14 01:39 - 07931392 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2017-04-28 12:28 - 2017-04-14 01:39 - 00974848 _____ (Microsoft Corporation) C:\Windows\system32\mmgaserver.exe
2017-04-28 12:28 - 2017-04-14 01:39 - 00517632 _____ (Microsoft Corporation) C:\Windows\system32\daxexec.dll
2017-04-28 12:28 - 2017-04-14 01:39 - 00334336 _____ (Microsoft Corporation) C:\Windows\system32\wc_storage.dll
2017-04-28 12:28 - 2017-04-14 01:39 - 00155136 _____ (Microsoft Corporation) C:\Windows\system32\VEStoreEventHandlers.dll
2017-04-28 12:28 - 2017-04-14 01:38 - 00251904 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Gaming.Preview.dll
2017-04-28 12:28 - 2017-04-14 01:38 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.AppDefaults.dll
2017-04-28 12:28 - 2017-04-14 01:37 - 00450048 _____ (Microsoft Corporation) C:\Windows\system32\bcdedit.exe
2017-04-28 12:28 - 2017-04-14 01:37 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\NotificationObjFactory.dll
2017-04-28 12:28 - 2017-04-14 01:37 - 00301056 _____ (Microsoft Corporation) C:\Windows\system32\EnterpriseAppMgmtSvc.dll
2017-04-28 12:28 - 2017-04-14 01:37 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\domgmt.dll
2017-04-28 12:28 - 2017-04-14 01:36 - 00524800 _____ (Microsoft Corporation) C:\Windows\system32\TileDataRepository.dll
2017-04-28 12:28 - 2017-04-14 01:36 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\CloudBackupSettings.dll
2017-04-28 12:28 - 2017-04-14 01:35 - 01433600 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettings.Handlers.dll
2017-04-28 12:28 - 2017-04-14 01:35 - 00510976 _____ (Microsoft Corporation) C:\Windows\system32\TDLMigration.dll
2017-04-28 12:28 - 2017-04-14 01:35 - 00257024 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2017-04-28 12:28 - 2017-04-14 01:34 - 01468416 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.desktop.dll
2017-04-28 12:28 - 2017-04-14 01:34 - 00406528 _____ (Microsoft Corporation) C:\Windows\system32\InputSwitch.dll
2017-04-28 12:28 - 2017-04-14 01:33 - 01269760 _____ (Microsoft Corporation) C:\Windows\system32\enterprisecsps.dll
2017-04-28 12:28 - 2017-04-14 01:33 - 00864256 _____ (Microsoft Corporation) C:\Windows\system32\NotificationController.dll
2017-04-28 12:28 - 2017-04-14 01:31 - 01611776 _____ (Microsoft Corporation) C:\Windows\system32\SpeechPal.dll
2017-04-28 12:28 - 2017-04-14 01:31 - 00673280 _____ (Microsoft Corporation) C:\Windows\system32\LockAppBroker.dll
2017-04-28 12:28 - 2017-04-14 01:29 - 02499584 _____ (Microsoft Corporation) C:\Windows\system32\twinui.pcshell.dll
2017-04-28 12:28 - 2017-04-14 01:29 - 01583616 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-04-28 12:28 - 2017-04-14 01:29 - 01295872 _____ (Microsoft Corporation) C:\Windows\system32\dosvc.dll
2017-04-28 12:28 - 2017-04-14 01:29 - 00840192 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll
2017-04-28 12:28 - 2017-04-14 01:29 - 00647168 _____ (Microsoft Corporation) C:\Windows\system32\RDXService.dll
2017-04-28 12:28 - 2017-04-14 01:28 - 02443776 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2017-04-28 12:28 - 2017-04-14 01:26 - 01257472 _____ (Microsoft Corporation) C:\Windows\system32\wpnapps.dll
2017-04-28 12:28 - 2017-04-14 01:25 - 00750080 _____ (Microsoft Corporation) C:\Windows\system32\StorSvc.dll
2017-04-28 12:28 - 2017-04-14 01:24 - 01628160 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll
2017-04-28 12:28 - 2017-04-14 01:21 - 06728192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2017-04-28 12:28 - 2017-04-14 01:21 - 00078848 _____ (Microsoft Corporation) C:\Windows\system32\offreg.dll
2017-04-28 12:28 - 2017-04-14 01:18 - 00731136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmgaserver.exe
2017-04-28 12:28 - 2017-04-14 01:18 - 00362496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\daxexec.dll
2017-04-28 12:28 - 2017-04-14 01:15 - 00282112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VEEventDispatcher.dll
2017-04-28 12:28 - 2017-04-14 01:15 - 00232448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CloudBackupSettings.dll
2017-04-28 12:28 - 2017-04-14 01:13 - 00354304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InputSwitch.dll
2017-04-28 12:28 - 2017-04-14 01:13 - 00232960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2017-04-28 12:28 - 2017-04-14 01:08 - 01463296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-04-28 12:28 - 2017-04-14 01:06 - 00987648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpnapps.dll
2017-04-28 12:28 - 2017-04-14 01:04 - 00392704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PlayToManager.dll
2017-04-28 12:28 - 2017-04-14 01:01 - 00057856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\offreg.dll
2017-04-28 11:33 - 2017-04-28 11:33 - 00000035 _____ C:\Users\Fox\Documents\ghost recon wilands.txt
2017-04-27 19:47 - 2017-04-27 19:47 - 00001114 _____ C:\Users\Fox\Desktop\Cheat Engine.lnk
2017-04-27 19:47 - 2017-04-27 19:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.6
2017-04-27 19:47 - 2017-04-27 19:47 - 00000000 ____D C:\Program Files (x86)\Cheat Engine 6.6
2017-04-27 12:00 - 2017-04-27 12:00 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2017-04-27 01:58 - 2017-04-20 03:59 - 01988216 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6438189.dll
2017-04-27 01:58 - 2017-04-20 03:59 - 01589880 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6438189.dll
2017-04-27 01:26 - 2017-05-10 14:16 - 00004308 _____ C:\Windows\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-04-26 15:49 - 2017-04-26 15:49 - 00042064 _____ (Anchorfree Inc.) C:\Windows\system32\Drivers\taphss6.sys
2017-04-25 23:31 - 2017-04-25 23:31 - 00000734 _____ C:\Users\Public\Desktop\FIFA 17.lnk
2017-04-25 23:22 - 2017-04-25 23:22 - 00000000 ____D C:\Program Files (x86)\Firewall App Blocker
2017-04-25 16:22 - 2017-04-25 16:22 - 00000000 ____D C:\Users\Fox\Documents\My Cheat Tables
2017-04-25 13:44 - 2017-04-25 13:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FIFA 17
2017-04-24 19:44 - 2017-05-12 21:31 - 00000000 ____D C:\Users\Fox\AppData\Local\Ubisoft Game Launcher
2017-04-24 19:44 - 2017-04-24 19:44 - 00001234 _____ C:\Users\Fox\Desktop\Uplay.lnk
2017-04-24 19:44 - 2017-04-24 19:44 - 00000000 ____D C:\Users\Fox\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2017-04-24 19:44 - 2017-04-24 19:44 - 00000000 ____D C:\Program Files (x86)\Ubisoft
2017-04-24 19:26 - 2017-05-10 19:33 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2017-04-24 19:26 - 2017-05-10 18:41 - 00001000 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 12.lnk
2017-04-24 19:26 - 2017-05-10 18:41 - 00000988 _____ C:\Users\Public\Desktop\TeamViewer 12.lnk
2017-04-24 19:26 - 2017-04-24 19:35 - 00000000 ____D C:\Users\Fox\AppData\Roaming\TeamViewer
2017-04-24 18:42 - 2017-04-24 18:42 - 00000000 ____D C:\Users\Fox\ansel
2017-04-23 19:59 - 2017-05-12 18:35 - 00000000 ____D C:\Users\Fox\Documents\My Games
2017-04-23 19:59 - 2017-05-11 14:43 - 00000000 ____D C:\Users\Fox\AppData\Local\WarThunder
2017-04-23 19:59 - 2017-04-23 19:59 - 00002015 _____ C:\Users\Fox\Desktop\WarThunder.lnk
2017-04-23 19:59 - 2017-04-23 19:59 - 00000000 ____D C:\Users\Fox\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WarThunder
2017-04-23 19:59 - 2017-04-23 19:59 - 00000000 ____D C:\Users\Fox\AppData\Local\Gaijin
2017-04-23 19:59 - 2017-04-23 19:59 - 00000000 ____D C:\ProgramData\Gaijin
2017-04-23 13:20 - 2017-04-23 13:20 - 00000000 ____D C:\Users\Fox\Documents\CPY_SAVES
2017-04-23 13:20 - 2017-04-23 13:20 - 00000000 ____D C:\ProgramData\KONAMI
2017-04-23 12:59 - 2017-04-23 12:59 - 01460172 _____ C:\Windows\Minidump\042317-18093-01.dmp
2017-04-23 01:57 - 2017-04-26 00:27 - 00000000 ____D C:\Program Files (x86)\RivaTuner Statistics Server
2017-04-23 01:57 - 2017-04-23 01:57 - 00001115 _____ C:\Users\Fox\Desktop\MSI Afterburner.lnk
2017-04-23 01:57 - 2017-04-23 01:57 - 00000000 ____D C:\Users\Fox\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server
2017-04-23 01:57 - 2017-04-23 01:57 - 00000000 ____D C:\Users\Fox\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner
2017-04-23 01:56 - 2017-04-26 00:27 - 00000000 ____D C:\Program Files (x86)\MSI Afterburner
2017-04-18 10:12 - 2017-04-18 10:13 - 01479508 _____ C:\Windows\Minidump\041817-20687-01.dmp
2017-04-15 14:33 - 2017-05-02 14:37 - 00000000 ____D C:\Users\Fox\AppData\Roaming\BSplayer PRO
2017-04-15 14:33 - 2017-04-15 14:33 - 00001182 _____ C:\ProgramData\Microsoft\Windows\Start Menu\BS.Player PRO.lnk
2017-04-15 14:33 - 2017-04-15 14:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Webteh
2017-04-15 14:33 - 2017-04-15 14:33 - 00000000 ____D C:\Program Files (x86)\Webteh
2017-04-14 22:45 - 2017-04-14 22:45 - 00000000 ____D C:\Users\Fox\AppData\Local\ElevatedDiagnostics
2017-04-14 11:23 - 2017-04-15 14:39 - 00000000 ____D C:\Users\Fox\Downloads\Aftermath 2017
2017-04-14 11:23 - 2017-04-15 14:38 - 00000000 ____D C:\Users\Fox\Downloads\Boyka Undisputed IV 2016

[Link mogu videti samo ulogovani korisnici]

Zbog čega nemaš aktivan antivirusni program?!


Otvori Notepad i iskopiraj sljedeći tekst koji se nalazi unutar Kod polja.

HKU\S-1-5-21-2678727347-3077865498-453496965-1001\...\Run: [okfifwpquv] => explorer "hxxp://" <===== ATTENTION
SearchScopes: HKU\S-1-5-21-2678727347-3077865498-453496965-1001 -> {A06ED961-D98F-4CF9-A89B-80AB11DB149C} URL = hxxp://{searchTerms}
CHR DefaultSearchURL: Default -> hxxp://{searchTerms}
CHR DefaultSearchKeyword: Default -> gosearch
CHR DefaultSuggestURL: Default -> hxxp://{searchTerms}
CHR HKLM-x32\...\Chrome\Extension: [epgjfmblhacacphaljkdcjllkomdcjpc] - hxxps://
Task: {739D9E48-0A8A-4C79-9727-3B299F69FCF0} - System32\Tasks\wutphost => C:\Users\Fox\AppData\Local\wutphost\wutphost.exe [2017-05-13] () <==== ATTENTION
Task: {C9A612C4-2AC3-43F4-8470-5FF502A24FB9} - System32\Tasks\One Drive Update => C:\Windows\explorer.exe hxxp://
Task: {D795101E-7885-41A6-9165-CDC9AE5516AE} - System32\Tasks\wupdate => C:\Users\Fox\AppData\Local\wupdate\wupdate.exe [2017-05-13] () <==== ATTENTION
Task: {F1ACCBA2-994E-4915-8AA5-8EA07B4F9219} - System32\Tasks\MSI => C:\Users\Fox\AppData\Roaming\Microsoft\msi.exe [2017-05-12] ()
2017-05-12 00:26 - 2017-05-12 00:27 - 0079736 _____ (AppWork GmbH) C:\Users\Fox\AppData\Local\Temp\131390152198418099.exe
2017-05-12 00:27 - 2017-05-12 00:27 - 1534344 _____ ( ) C:\Users\Fox\AppData\Local\Temp\13139015220977085111.exe
2017-05-12 23:18 - 2017-05-12 23:18 - 1299440 ____N () C:\Users\Fox\AppData\Local\Temp\2Ul4UtV2XIRe.exe
2017-05-13 00:11 - 2017-05-13 00:11 - 1262576 ____N () C:\Users\Fox\AppData\Local\Temp\2UvOw42gtfk4.exe
2017-04-10 15:14 - 2017-04-09 14:10 - 1738952 _____ () C:\Users\Fox\AppData\Local\Temp\AnyDeskUninst625c.exe
2017-05-12 23:15 - 2017-05-12 23:15 - 2584280 ____N () C:\Users\Fox\AppData\Local\Temp\cQDncNmWvF2D.exe
2017-05-12 23:15 - 2017-05-12 23:16 - 2584280 ____N () C:\Users\Fox\AppData\Local\Temp\F5n1eANAlEA3.exe
2017-05-12 23:17 - 2017-05-12 23:17 - 1299440 ____N () C:\Users\Fox\AppData\Local\Temp\I5ZSbVEyC7CW.exe
2017-05-12 23:29 - 2017-05-12 23:29 - 0417792 _____ () C:\Users\Fox\AppData\Local\Temp\K0xyrgznBNIF.exe
2017-05-13 00:09 - 2017-05-13 00:09 - 2584280 ____N () C:\Users\Fox\AppData\Local\Temp\Mukz0csjeZDB.exe
2017-05-12 23:18 - 2017-05-12 23:18 - 0000000 _____ () C:\Users\Fox\AppData\Local\Temp\rKPH8hgSxYkk.exe
2017-05-12 23:28 - 2017-05-12 23:28 - 2584280 ____N () C:\Users\Fox\AppData\Local\Temp\VViqDGsiC1tE.exe
2017-05-13 00:15 - 2017-05-13 00:15 - 1262576 ____N () C:\Users\Fox\AppData\Local\Temp\xnl2hX0kVwvN.exe

U okviru Notepad-a klikni na File --> Save As
Pod Encoding izaberi UTF-8.
Fajl nazovi Fixlist i sačuvaj na Desktop
Dvoklikom ponovo pokreni FRST.exe
Klikni na Fix i sačekaj dok program ne završi.
Ukoliko program zatraži restart računara, omogući mu da to nesmetano obavi.
Nakon završetka rada, otvoriće se fixlog.txt, sa sadržajem koji treba da kopiraš u temu.
Takođe, na Desktop-u će se nalaziti (fixlog.txt).

Sinoc sam instaliro Zemana Antivirus, @Sass Drake koji Antivirus mi predlazete?

Fix result of Farbar Recovery Scan Tool (x64) Version: 08-05-2017
Ran by Fox (13-05-2017 15:00:35) Run:1
Running from C:\Users\Fox\Desktop
Loaded Profiles: Fox (Available Profiles: Fox)
Boot Mode: Normal

fixlist content:
HKU\S-1-5-21-2678727347-3077865498-453496965-1001\...\Run: [okfifwpquv] => explorer "hxxp://" <===== ATTENTION
SearchScopes: HKU\S-1-5-21-2678727347-3077865498-453496965-1001 -> {A06ED961-D98F-4CF9-A89B-80AB11DB149C} URL = [Link mogu videti samo ulogovani korisnici]{searchTerms}
CHR DefaultSearchURL: Default -> [Link mogu videti samo ulogovani korisnici]{searchTerms}
CHR DefaultSearchKeyword: Default -> gosearch
CHR DefaultSuggestURL: Default -> [Link mogu videti samo ulogovani korisnici]{searchTerms}
CHR HKLM-x32\...\Chrome\Extension: [epgjfmblhacacphaljkdcjllkomdcjpc] - [Link mogu videti samo ulogovani korisnici]
Task: {739D9E48-0A8A-4C79-9727-3B299F69FCF0} - System32\Tasks\wutphost => C:\Users\Fox\AppData\Local\wutphost\wutphost.exe [2017-05-13] () <==== ATTENTION
Task: {C9A612C4-2AC3-43F4-8470-5FF502A24FB9} - System32\Tasks\One Drive Update => C:\Windows\explorer.exe [Link mogu videti samo ulogovani korisnici]
Task: {D795101E-7885-41A6-9165-CDC9AE5516AE} - System32\Tasks\wupdate => C:\Users\Fox\AppData\Local\wupdate\wupdate.exe [2017-05-13] () <==== ATTENTION
Task: {F1ACCBA2-994E-4915-8AA5-8EA07B4F9219} - System32\Tasks\MSI => C:\Users\Fox\AppData\Roaming\Microsoft\msi.exe [2017-05-12] ()
2017-05-12 00:26 - 2017-05-12 00:27 - 0079736 _____ (AppWork GmbH) C:\Users\Fox\AppData\Local\Temp\131390152198418099.exe
2017-05-12 00:27 - 2017-05-12 00:27 - 1534344 _____ ( ) C:\Users\Fox\AppData\Local\Temp\13139015220977085111.exe
2017-05-12 23:18 - 2017-05-12 23:18 - 1299440 ____N () C:\Users\Fox\AppData\Local\Temp\2Ul4UtV2XIRe.exe
2017-05-13 00:11 - 2017-05-13 00:11 - 1262576 ____N () C:\Users\Fox\AppData\Local\Temp\2UvOw42gtfk4.exe
2017-04-10 15:14 - 2017-04-09 14:10 - 1738952 _____ () C:\Users\Fox\AppData\Local\Temp\AnyDeskUninst625c.exe
2017-05-12 23:15 - 2017-05-12 23:15 - 2584280 ____N () C:\Users\Fox\AppData\Local\Temp\cQDncNmWvF2D.exe
2017-05-12 23:15 - 2017-05-12 23:16 - 2584280 ____N () C:\Users\Fox\AppData\Local\Temp\F5n1eANAlEA3.exe
2017-05-12 23:17 - 2017-05-12 23:17 - 1299440 ____N () C:\Users\Fox\AppData\Local\Temp\I5ZSbVEyC7CW.exe
2017-05-12 23:29 - 2017-05-12 23:29 - 0417792 _____ () C:\Users\Fox\AppData\Local\Temp\K0xyrgznBNIF.exe
2017-05-13 00:09 - 2017-05-13 00:09 - 2584280 ____N () C:\Users\Fox\AppData\Local\Temp\Mukz0csjeZDB.exe
2017-05-12 23:18 - 2017-05-12 23:18 - 0000000 _____ () C:\Users\Fox\AppData\Local\Temp\rKPH8hgSxYkk.exe
2017-05-12 23:28 - 2017-05-12 23:28 - 2584280 ____N () C:\Users\Fox\AppData\Local\Temp\VViqDGsiC1tE.exe
2017-05-13 00:15 - 2017-05-13 00:15 - 1262576 ____N () C:\Users\Fox\AppData\Local\Temp\xnl2hX0kVwvN.exe

HKU\S-1-5-21-2678727347-3077865498-453496965-1001\Software\Microsoft\Windows\CurrentVersion\Run\\okfifwpquv => value not found.
HKU\S-1-5-21-2678727347-3077865498-453496965-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A06ED961-D98F-4CF9-A89B-80AB11DB149C} => key removed successfully
HKCR\CLSID\{A06ED961-D98F-4CF9-A89B-80AB11DB149C} => key not found.
Chrome DefaultSearchURL => removed successfully
Chrome DefaultSearchKeyword => removed successfully
Chrome DefaultSuggestURL => removed successfully
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\epgjfmblhacacphaljkdcjllkomdcjpc => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{739D9E48-0A8A-4C79-9727-3B299F69FCF0} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{739D9E48-0A8A-4C79-9727-3B299F69FCF0} => key removed successfully
C:\Windows\System32\Tasks\wutphost => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\wutphost => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C9A612C4-2AC3-43F4-8470-5FF502A24FB9} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C9A612C4-2AC3-43F4-8470-5FF502A24FB9} => key removed successfully
C:\Windows\System32\Tasks\One Drive Update => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\One Drive Update => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D795101E-7885-41A6-9165-CDC9AE5516AE} => key not found.
C:\Windows\System32\Tasks\wupdate => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\wupdate => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F1ACCBA2-994E-4915-8AA5-8EA07B4F9219} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F1ACCBA2-994E-4915-8AA5-8EA07B4F9219} => key removed successfully
C:\Windows\System32\Tasks\MSI => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MSI => key not found.
C:\Users\Fox\AppData\Local\wutphost => moved successfully
"C:\Users\Fox\AppData\Local\wupdate" => not found.
"C:\Users\Fox\AppData\Roaming\Microsoft\msi.exe" => not found.
C:\Users\Fox\AppData\Local\Temp\131390152198418099.exe => moved successfully
C:\Users\Fox\AppData\Local\Temp\13139015220977085111.exe => moved successfully
C:\Users\Fox\AppData\Local\Temp\2Ul4UtV2XIRe.exe => moved successfully
C:\Users\Fox\AppData\Local\Temp\2UvOw42gtfk4.exe => moved successfully
C:\Users\Fox\AppData\Local\Temp\AnyDeskUninst625c.exe => moved successfully
C:\Users\Fox\AppData\Local\Temp\cQDncNmWvF2D.exe => moved successfully
C:\Users\Fox\AppData\Local\Temp\F5n1eANAlEA3.exe => moved successfully
C:\Users\Fox\AppData\Local\Temp\I5ZSbVEyC7CW.exe => moved successfully
C:\Users\Fox\AppData\Local\Temp\K0xyrgznBNIF.exe => moved successfully
C:\Users\Fox\AppData\Local\Temp\Mukz0csjeZDB.exe => moved successfully
C:\Users\Fox\AppData\Local\Temp\rKPH8hgSxYkk.exe => moved successfully
C:\Users\Fox\AppData\Local\Temp\VViqDGsiC1tE.exe => moved successfully
C:\Users\Fox\AppData\Local\Temp\xnl2hX0kVwvN.exe => moved successfully

=========== EmptyTemp: ==========

BITS transfer queue => 7888896 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 54886187 B
Java, Flash, Steam htmlcache => 15748908 B
Windows/system/drivers => 4353278 B
Edge => 2268624 B
Chrome => 263911746 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 128 B
systemprofile32 => 0 B
LocalService => 27062 B
NetworkService => 1142 B
Fox => 1294122660 B

RecycleBin => 0 B
EmptyTemp: => 1.5 GB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 15:01:08 ====

Spakuj u ZIP, RAR ili 7Z arhivu sljedeći folder:


i pošalji ga preko sljedećeg linka:

[Link mogu videti samo ulogovani korisnici]

Javi kada to uradiš i sačekaj dalja uputstva.

Spakovo sam ga ali sad iznosi 11 mb a upload za ambulantu je max 10 mb, sta da radim?

  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Probaj da iskoristiš maksimalni stepen kompresije u arhiveru koji koristiš, a ako ne okači na pa mi pošalji link preko PP.

Probaj da iskoristiš maksimalni stepen kompresije u arhiveru koji koristiš, a ako ne okači na pa mi pošalji link preko PP.

Napisano: 13 Maj 2017 15:33

Dopuna: 13 Maj 2017 15:34

Sad cu preko Wikisend pa saljem u PP.

Dopuna: 13 Maj 2017 15:38

Sta da radim?

Preuzmi Malwarebytes Anti-Malware sa ovog ili ovog ili ovog linka i instaliraj aplikaciju.
Pokreni mb3-setup-consumer-{verzija}.exe i isprati uputstva za instalaciju programa. Nakon instalacije, klikni na Finish

Prilikom prvog pokretanja, program će prikazati prozor "dobrodošlice". Slobodno zatvori taj prozor.
Napomena: Premium funkcije programa su već aktivirane i važe 13 dana od trenutka instalacije. Premium funkcije možeš isključiti preko Settings > My Account tab podešavanja.

• Podešavanja skenera - u Settings, klikni na Protection tab. Ispod Scan Options sekcije, uključi "Scan for rootkits" opciju.
• Pripremi podešavanja za Threat Scan - u Dashboard , klikni na Scan Now dugme. MBAM će ažurirati bazu i započeti skeniranje.

Kada se skeniranje završi, ako je infekcija detektovana, obrati pažnju da je sve označeno, pa klikni na Remove Selected. Restartuj računar ako program upita za restart.
• Dostavi log: Pod Reports izaberi trenutni datum izveštaja Scan Report i potom klikni na View Report.

Izvezi log na Desktop;
- Klikni na Export dugme na dnu, pa onda izaberi 'Text file (*.txt)'
# U Save File dijalogu koji se pojavi, klikni na Desktop. U File name: polje, upiši "mbam" (bez navodnika) i klikni na Save.
- Pojaviće se poruka "Your file has been successfully exported", klikni Ok i zatvori prozor.

• U odgovoru prikači mbam.txt log koristeći "Prikači fajl" opciju.

[Link mogu videti samo ulogovani korisnici]

  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Kakvo je sad stanje?

