offline
- gogi100

- Građanin
- Pridružio: 26 Jan 2006
- Poruke: 233
|
dakle, imam racunar sa operativnim sistemom windows 7 x64 ultimate, anti virus software je bio microsoft security essentials.
simptomi su sledeci. chrome se otvara sam od sebe. ja sam brisao sa malware bytes-om malware i od tada je stao sa iskakanjem, ali stalno mu se pojavljuju u dodacima neki ruski dodaci i dodatak splinter search. microsoft esentials ne moze da se azurira izbacuje neku gresku i ja sam ga deinstalirao. praznio sam sve temp fajlove i primetio sam da se u c:\users pojavljuje folder {username}. Takodje,show hidden files kad ukljucim nista se ne desava, ne pokazuje skrivene fajlove isto tako i sistemske fajlove. kad pokusam da nesto promenim u registry prikazuje mi da je access denied iako imam vlasnistvo nad tim kljucevima. u control panel uninnstal programs sklonio sam sumljive programe bar koje sam ja mislio da su sumljivi.
frst.txt je
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20-05-2017
Ran by Administrator (administrator) on HOME-PC (21-05-2017 15:43:12)
Running from C:\Users\Administrator\Downloads
Loaded Profiles: Administrator (Available Profiles: home & Administrator)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: [Link mogu videti samo ulogovani korisnici]
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Source Engine\OSE.EXE
(Microsoft Corporation) C:\Windows\System32\Locator.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Copyright 2017.) C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(Copyright 2017.) C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Sysinternals - [Link mogu videti samo ulogovani korisnici]) C:\Users\Administrator\Downloads\ProcessExplorer\procexp64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6843024 2012-10-29] (Realtek Semiconductor)
HKLM\...\Run: [StartCN] => C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe [5006536 2016-03-21] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes)
HKLM\...\Run: [ZAM] => C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [14522512 2017-04-03] (Copyright 2017.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596504 2016-05-20] (Oracle Corporation)
HKU\S-1-5-21-891269962-2659327078-604941568-500\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [333824 2010-11-21] (Microsoft Corporation)
ShellExecuteHooks: No Name - {F797446C-D3F2-11E6-AB72-64006A5CFC35} - C:\Users\home\AppData\Roaming\Terlcultclhach\Hejuck.dll -> No File
ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\home\AppData\Local\MEGAsync\ShellExtX64.dll -> No File
ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\home\AppData\Local\MEGAsync\ShellExtX64.dll -> No File
ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\home\AppData\Local\MEGAsync\ShellExtX64.dll -> No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers-x32: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\home\AppData\Local\MEGAsync\ShellExtX32.dll -> No File
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\home\AppData\Local\MEGAsync\ShellExtX32.dll -> No File
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\home\AppData\Local\MEGAsync\ShellExtX32.dll -> No File
Startup: C:\Users\home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartUp\pLBfEuNP.lnk [2015-12-27]
Startup: C:\Users\home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartUp\Twitch.lnk [2017-04-11]
ShortcutTarget: Twitch.lnk -> C:\Users\Administrator\AppData\Roaming\Curse Client\Bin\Twitch.exe (No File)
Startup: C:\Users\home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartUp\xBchppIcvKkI.lnk [2015-12-27]
BootExecute: autocheck autochk * Partizan
GroupPolicyScripts\User: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\..\Interfaces\{AB0801C9-0579-42DD-935D-4B2453D6B2CA}: [DhcpNameServer] 212.200.191.166 212.200.190.166
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-891269962-2659327078-604941568-500\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [Link mogu videti samo ulogovani korisnici]
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = [Link mogu videti samo ulogovani korisnici]
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = [Link mogu videti samo ulogovani korisnici]
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = [Link mogu videti samo ulogovani korisnici]
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = [Link mogu videti samo ulogovani korisnici]
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = [Link mogu videti samo ulogovani korisnici]
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = [Link mogu videti samo ulogovani korisnici]
HKU\S-1-5-21-891269962-2659327078-604941568-500\Software\Microsoft\Internet Explorer\Main,Search Page = [Link mogu videti samo ulogovani korisnici]
HKU\S-1-5-21-891269962-2659327078-604941568-500\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = [Link mogu videti samo ulogovani korisnici]
BHO: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2012-02-14] (Advanced Micro Devices)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2010-01-21] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_91\bin\ssv.dll [2016-05-31] (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-01-16] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-05-31] (Oracle Corporation)
BHO-x32: Adobe PDF Reader Link Helper -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-23] (Adobe Systems Incorporated)
BHO-x32: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll [2012-02-14] (Advanced Micro Devices)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2010-01-21] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\ssv.dll [2015-04-02] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-01-16] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-04-02] (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2016-09-23] (Skype Technologies)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2015-12-10] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2015-12-10] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2015-12-10] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2015-12-10] (Microsoft Corporation)
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-05-31] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-05-31] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1207148.dll [2013-12-05] (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-04-02] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-04-02] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-01-10] (Microsoft Corporation)
FF Plugin-x32: @qq.com/npAndroidAssistant -> C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3198\npQQPhoneManagerExt.dll [No File]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-17] (Google Inc.)
Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - [Link mogu videti samo ulogovani korisnici]
Opera:
=======
StartMenuInternet: (HKLM) OPERASTABLE - Opera.exe
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S4 AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [344064 2015-08-04] (Advanced Micro Devices, Inc.) [File not signed]
R2 Auhardwaregl; C:\Windows\SysWow64\Auhardwaregl.dll [454440 2017-05-17] ()
S4 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1465352 2017-01-13] ()
S4 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [428056 2017-03-03] (BlueStack Systems, Inc.)
S4 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [406040 2017-03-03] (BlueStack Systems, Inc.)
S4 BstHdPlusAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Plus-Service.exe [452632 2017-03-03] (BlueStack Systems, Inc.)
S4 Disc Soft Lite Bus Service; E:\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [1467072 2016-05-30] (Disc Soft Ltd)
S4 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [382504 2017-04-19] (EasyAntiCheat Ltd)
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [143872 2014-10-24] (Microsoft Corporation) [File not signed]
S4 Hamachi2Svc; C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe [3416584 2017-03-02] (LogMeIn Inc.)
S4 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S4 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe [419248 2017-02-27] (LogMeIn, Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes)
R2 MSSQL$SQLEXPRESS; c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [57617752 2009-03-30] (Microsoft Corporation)
S4 SQLAgent$SQLEXPRESS; c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [427880 2009-03-30] (Microsoft Corporation)
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [122368 2015-02-26] (Microsoft Corporation) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S4 XperiaCompanionService; C:\Program Files\Sony\Xperia Companion\Service\XperiaCompanionService.exe [2205568 2017-03-21] (Sony)
R2 ZAMSvc; C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [14522512 2017-04-03] (Copyright 2017.)
S4 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [X]
S4 HnGSteamService; C:\Program Files (x86)\Steam\steamapps\common\Heroes & Generals\hngservice.exe [X]
S4 netsvc; C:\Program Files (x86)\UtilTool\Antivirus\netsvc.exe [X]
S4 Origin Client Service; "C:\Program Files (x86)\Origin\OriginClientService.exe" [X]
S4 PanService; C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe [X]
S4 SQLBrowser; "c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe" [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AODDriver4.3; C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
S3 AVFSFilter; C:\Windows\System32\DRIVERS\avfsfilter.sys [13720 2012-09-07] ()
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [152672 2017-03-03] (BlueStack Systems)
R2 BstkDrv; C:\Program Files (x86)\BlueStacks\BstkDrv.sys [270904 2017-03-03] (Bluestack System Inc. )
R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2016-04-14] (Disc Soft Ltd)
R3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [47672 2016-04-14] (Disc Soft Ltd)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77440 2017-05-09] ()
S3 ggsomc; C:\Windows\System32\DRIVERS\ggsomc.sys [30424 2017-04-16] (Sony Mobile Communications)
S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [55232 2017-05-19] ()
R2 MBAMChameleon; C:\Windows\system32\drivers\MBAMChameleon.sys [187320 2017-05-18] (Malwarebytes)
R3 MBAMFarflt; C:\Windows\system32\drivers\farflt.sys [113592 2017-05-21] (Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [43968 2017-05-21] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [251832 2017-05-21] (Malwarebytes)
R3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [84256 2017-05-21] (Malwarebytes)
R1 netboostmaster; C:\Windows\system32\drivers\netboostmaster.sys [2894184 2017-05-18] () [File not signed]
S3 secdrv; C:\Windows\SysWow64\Drivers\secdrv.sys [11973 2016-07-22] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [File not signed]
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [394296 2016-04-14] (Duplex Secure Ltd.)
S3 tap0901_openvpn_accl; C:\Windows\System32\DRIVERS\tap0901_openvpn_accl.sys [37912 2016-11-10] (The OpenVPN Project)
R2 Uefochubsrv; C:\Windows\system32\drivers\Uefochubsrv.sys [196640 2017-05-17] ()
R1 ZAM; C:\Windows\System32\drivers\zam64.sys [203680 2017-05-21] (Zemana Ltd.)
R1 ZAM_Guard; C:\Windows\System32\drivers\zamguard64.sys [203680 2017-05-21] (Zemana Ltd.)
U3 asqw883q; no ImagePath
S1 aqhiqflc; \??\C:\Windows\system32\drivers\aqhiqflc.sys [X]
U0 aswVmm; no ImagePath
S1 lnsubgoh; \??\C:\Windows\system32\drivers\lnsubgoh.sys [X]
S1 netcontroller; system32\drivers\netcontroller.sys [X]
S1 p1483530829am; \??\C:\Users\home\AppData\Local\Temp\bk3BC8.tmp\p1483530829am.sys [X] <==== ATTENTION
U0 Partizan; system32\drivers\Partizan.sys [X]
S1 qaqjosyy; \??\C:\Windows\system32\drivers\qaqjosyy.sys [X]
S3 TrojanKillerDriver; system32\DRIVERS\gtkdrv.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 VSPerfDrv100; \??\C:\Program Files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [X]
S1 whklgyqq; \??\C:\Windows\system32\drivers\whklgyqq.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-05-22 01:26 - 2017-05-22 01:26 - 00005292 _____ C:\Users\Administrator\Documents\swprv.reg
2017-05-21 15:43 - 2017-05-21 15:43 - 00018672 _____ C:\Users\Administrator\Downloads\FRST.txt
2017-05-21 15:43 - 2017-05-21 15:43 - 00000000 ____D C:\FRST
2017-05-21 15:42 - 2017-05-21 15:42 - 02429952 _____ (Farbar) C:\Users\Administrator\Downloads\FRST64.exe
2017-05-21 15:31 - 2017-05-21 15:31 - 00000000 ____D C:\Users\{username}
2017-05-21 15:28 - 2017-05-21 15:43 - 00494578 _____ C:\Windows\ZAM.krnl.trace
2017-05-21 15:28 - 2017-05-21 15:43 - 00112193 _____ C:\Windows\ZAM_Guard.krnl.trace
2017-05-21 13:14 - 2017-05-21 13:14 - 00000406 _____ C:\Users\Administrator\Desktop\zemana.txt
2017-05-21 12:25 - 2017-05-21 12:29 - 00000000 ____D C:\Program Files (x86)\Zemana AntiMalware
2017-05-21 12:25 - 2017-05-21 12:25 - 00203680 _____ (Zemana Ltd.) C:\Windows\system32\Drivers\zamguard64.sys
2017-05-21 12:25 - 2017-05-21 12:25 - 00203680 _____ (Zemana Ltd.) C:\Windows\system32\Drivers\zam64.sys
2017-05-21 12:25 - 2017-05-21 12:25 - 00001104 _____ C:\Users\Public\Desktop\Zemana AntiMalware.lnk
2017-05-21 12:25 - 2017-05-21 12:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware
2017-05-21 12:24 - 2017-05-21 12:24 - 05774688 _____ (Zemana Ltd. ) C:\Users\Administrator\Downloads\Zemana.AntiMalware.Setup.exe
2017-05-21 10:26 - 2017-05-21 15:31 - 00002211 _____ C:\Users\Administrator\Desktop\Google Chrome.lnk
2017-05-21 10:14 - 2017-05-21 10:14 - 00000000 ____D C:\Users\Administrator\Desktop\osam_autorun_manager_5_0_portable
2017-05-21 10:10 - 2017-05-21 10:11 - 04272474 _____ C:\Users\Administrator\Desktop\osam_autorun_manager_5_0_portable.rar
2017-05-21 10:10 - 2017-05-21 10:10 - 00688992 ____R (Swearware) C:\Users\Administrator\Desktop\dds.scr
2017-05-20 23:49 - 2017-05-21 00:00 - 00000000 ____D C:\Users\Public\Documents\regruninfo
2017-05-20 23:49 - 2017-05-20 23:56 - 00000000 ____D C:\Users\Administrator\Documents\RegRun2
2017-05-20 23:49 - 2017-05-20 23:52 - 00000000 ____D C:\Program Files (x86)\UnHackMe
2017-05-20 23:49 - 2017-05-20 23:49 - 00000963 _____ C:\Users\Administrator\Desktop\UnHackMe.lnk
2017-05-20 23:49 - 2017-05-20 23:49 - 00000418 _____ C:\Windows\Tasks\UnHackMe Task Scheduler.job
2017-05-20 23:49 - 2017-05-20 23:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UnHackMe
2017-05-20 23:49 - 2017-04-14 12:48 - 00014984 _____ (Greatis Software, LLC.) C:\Windows\SysWOW64\Drivers\UnHackMeDrv.sys
2017-05-20 23:45 - 2017-05-20 23:45 - 00000000 ____D C:\Users\Administrator\Downloads\unhackme
2017-05-20 23:44 - 2017-05-20 23:45 - 18656117 _____ C:\Users\Administrator\Downloads\unhackme.zip
2017-05-20 23:41 - 2017-05-20 23:41 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Adobe
2017-05-20 23:24 - 2017-05-20 23:24 - 00000000 ____D C:\Users\Administrator\Downloads\ProcessExplorer
2017-05-20 23:18 - 2017-05-20 23:19 - 01931969 _____ C:\Users\Administrator\Downloads\ProcessExplorer.zip
2017-05-20 22:59 - 2017-05-20 22:59 - 11098008 _____ C:\Users\Administrator\Documents\1.reg
2017-05-20 22:58 - 2017-05-20 22:58 - 00000082 _____ C:\Users\Administrator\Documents\security.reg
2017-05-20 22:56 - 2017-05-20 22:56 - 03635734 _____ (Sergey Filippov ) C:\Users\Administrator\Downloads\RegistryFinderSetup2.19.exe
2017-05-20 22:56 - 2017-05-20 22:56 - 00000000 ____D C:\Registry Finder
2017-05-20 22:45 - 2017-05-20 22:47 - 00145568 _____ (Sysinternals) C:\Windows\PSEXESVC.exe
2017-05-20 22:43 - 2017-05-20 22:43 - 00000000 ____D C:\pstools
2017-05-20 22:42 - 2017-05-20 22:42 - 02823905 _____ C:\Users\Administrator\Downloads\PSTools.zip
2017-05-20 22:38 - 2017-05-20 22:38 - 02655480 _____ (Resplendence Software Projects Sp. ) C:\Users\Administrator\Downloads\RegistrarHomeV8.exe
2017-05-20 19:22 - 2017-05-20 19:22 - 00000000 ____D C:\Windows\system32\MpEngineStore
2017-05-19 22:45 - 2017-05-19 22:45 - 01048576 _____ C:\Users\Administrator\Downloads\msert.exe
2017-05-19 22:36 - 2017-05-19 22:36 - 06752896 _____ (ESET spol. s r.o.) C:\Users\Administrator\Downloads\esetonlinescanner_enu.exe
2017-05-19 22:33 - 2017-05-19 22:34 - 15065792 _____ (Microsoft Corporation) C:\Users\Administrator\Downloads\mseinstall.exe
2017-05-19 22:07 - 2017-05-19 22:18 - 00000000 ____D C:\Program Files\Attribute Changer
2017-05-19 22:07 - 2017-05-19 22:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Attribute Changer
2017-05-19 22:07 - 2017-05-19 22:07 - 05126250 _____ (Romain Petges ) C:\Users\Administrator\Downloads\ac-860.exe
2017-05-19 22:03 - 2017-05-19 22:03 - 00000258 __RSH C:\ProgramData\ntuser.pol
2017-05-19 21:50 - 2017-05-19 21:50 - 00001001 _____ C:\Users\Administrator\Desktop\Total Commander 64 bit.lnk
2017-05-19 21:50 - 2017-05-19 21:50 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Total Commander
2017-05-19 21:50 - 2017-05-19 21:50 - 00000000 ____D C:\Program Files\totalcmd
2017-05-19 21:49 - 2017-05-19 21:49 - 04987672 _____ (Ghisler Software GmbH) C:\Users\Administrator\Downloads\tcmd900ax64.exe
2017-05-19 21:31 - 2017-05-19 21:32 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2017-05-19 21:30 - 2017-05-19 21:30 - 16563352 _____ (Malwarebytes Corp.) C:\Users\Administrator\Downloads\mbar-1.09.3.1001.exe
2017-05-19 21:10 - 2017-05-19 21:18 - 00000000 ____D C:\AdwCleaner
2017-05-19 21:10 - 2017-05-19 21:10 - 04110280 _____ C:\Users\Administrator\Downloads\adwcleaner_6.047.exe
2017-05-19 20:19 - 2017-05-19 20:22 - 00055232 _____ C:\Windows\system32\Drivers\hitmanpro37.sys
2017-05-19 20:19 - 2017-05-19 20:22 - 00001889 _____ C:\Users\Public\Desktop\HitmanPro.lnk
2017-05-19 20:19 - 2017-05-19 20:19 - 00000000 ____D C:\Program Files\HitmanPro
2017-05-19 20:17 - 2017-05-19 20:20 - 00000000 ____D C:\ProgramData\HitmanPro
2017-05-19 20:17 - 2017-05-19 20:18 - 11584088 _____ (SurfRight B.V.) C:\Users\Administrator\Downloads\HitmanPro_x64.exe
2017-05-19 20:16 - 2017-05-19 20:16 - 11023528 _____ (SurfRight B.V.) C:\Users\Administrator\Downloads\HitmanPro.exe
2017-05-19 20:10 - 2017-05-19 20:10 - 00427648 _____ (Bleeping Computer, LLC) C:\Users\Administrator\Downloads\unhide (1).exe
2017-05-19 19:32 - 2017-05-19 19:57 - 00000000 ____D C:\ComboFix
2017-05-19 19:30 - 2017-05-19 18:55 - 05659512 ____R (Swearware) C:\Users\Administrator\Desktop\ComboFix.exe
2017-05-19 19:03 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2017-05-19 19:03 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2017-05-19 19:03 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2017-05-19 19:03 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2017-05-19 19:03 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2017-05-19 19:03 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2017-05-19 19:03 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2017-05-19 19:03 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2017-05-19 18:57 - 2017-05-19 21:21 - 00000000 ____D C:\Qoobox
2017-05-19 18:57 - 2017-05-19 19:54 - 00000000 ____D C:\Windows\erdnt
2017-05-19 18:55 - 2017-05-19 18:55 - 05659512 ____R (Swearware) C:\Users\Administrator\Downloads\ComboFix.exe
2017-05-19 18:49 - 2017-05-19 18:49 - 02030536 _____ (Bleeping Computer, LLC) C:\Users\Administrator\Downloads\rkill.exe
2017-05-19 18:33 - 2017-05-19 18:33 - 00000000 ____D C:\Users\Administrator\Downloads\backups
2017-05-19 18:31 - 2017-05-19 18:31 - 00388608 _____ (Trend Micro Inc.) C:\Users\Administrator\Downloads\HijackThis.exe
2017-05-19 05:48 - 2017-05-19 05:48 - 00000000 ____D C:\found.000
2017-05-18 19:07 - 2017-05-18 19:07 - 00395171 _____ C:\Users\Administrator\Downloads\roex.zip
2017-05-18 19:07 - 2017-05-18 19:07 - 00000000 ____D C:\Users\Administrator\Downloads\roex
2017-05-18 18:55 - 2017-05-21 00:04 - 00521074 _____ C:\Windows\ntbtlog.txt
2017-05-18 18:47 - 2013-11-26 10:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2017-05-18 18:47 - 2013-11-23 00:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2017-05-18 18:40 - 2017-05-18 18:40 - 00427648 _____ (Bleeping Computer, LLC) C:\Users\Administrator\Downloads\unhide.exe
2017-05-18 18:29 - 2017-05-18 18:29 - 00001189 _____ C:\Users\Administrator\Documents\show.reg
2017-05-18 17:47 - 2017-05-18 17:49 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\DAEMON Tools Lite
2017-05-18 17:43 - 2017-05-18 17:43 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk
2017-05-18 17:43 - 2017-05-18 17:43 - 00000295 _____ C:\Windows\wininit.ini
2017-05-18 17:43 - 2017-05-18 17:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2017-05-18 17:43 - 2017-05-18 17:43 - 00000000 ____D C:\Program Files\CCleaner
2017-05-18 05:20 - 2017-05-21 13:47 - 00000000 ____D C:\ProgramData\XLiPlatform
2017-05-18 05:18 - 2015-07-30 20:06 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2017-05-18 05:18 - 2015-07-30 20:06 - 01648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2017-05-18 05:18 - 2015-07-30 20:06 - 01180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2017-05-18 05:18 - 2015-07-30 19:57 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2017-05-18 05:18 - 2015-07-30 19:57 - 01251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2017-05-18 05:17 - 2017-05-21 15:28 - 02785072 _____ C:\Windows\netboostmasterHelp.dll
2017-05-18 05:17 - 2017-05-18 05:17 - 02894184 _____ C:\Windows\system32\Drivers\netboostmaster.sys
2017-05-18 05:15 - 2016-04-14 15:49 - 00603648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2017-05-18 05:15 - 2016-04-14 15:21 - 00647680 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2017-05-18 05:15 - 2016-04-09 06:20 - 01230848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2017-05-18 05:15 - 2016-04-09 05:52 - 01424896 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2017-05-18 05:15 - 2015-12-08 23:54 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2017-05-18 05:15 - 2015-12-08 21:07 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2017-05-18 05:15 - 2015-02-04 05:16 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2017-05-18 05:15 - 2015-02-04 04:54 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2017-05-18 05:09 - 2017-05-18 05:17 - 00000000 ____D C:\ProgramData\Cache
2017-05-17 18:38 - 2017-05-17 18:39 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Notepad++
2017-05-17 17:52 - 2017-05-21 15:29 - 00251832 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-05-17 17:52 - 2017-05-21 15:29 - 00113592 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2017-05-17 17:52 - 2017-05-21 15:29 - 00084256 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2017-05-17 17:52 - 2017-05-21 15:29 - 00043968 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2017-05-17 17:52 - 2017-05-18 19:12 - 00187320 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys
2017-05-17 17:52 - 2017-05-17 17:52 - 00001867 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-05-17 17:52 - 2017-05-17 17:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-05-17 17:51 - 2017-05-17 17:52 - 00000000 ____D C:\Users\Administrator\AppData\LocalLow\Mozilla
2017-05-17 17:51 - 2017-05-17 17:51 - 00000000 ____D C:\Program Files\Malwarebytes
2017-05-17 17:51 - 2017-05-09 16:37 - 00077440 _____ C:\Windows\system32\Drivers\mbae64.sys
2017-05-17 17:50 - 2017-05-17 17:50 - 00000000 ____D C:\Users\Public\Documents\Google
2017-05-17 17:43 - 2017-05-17 17:43 - 00454440 _____ C:\Windows\SysWOW64\Auhardwaregl.dll
2017-05-17 17:43 - 2017-05-17 17:43 - 00196640 _____ C:\Windows\system32\Drivers\Uefochubsrv.sys
2017-05-17 17:43 - 2017-05-17 17:43 - 00000000 ____D C:\Users\Public\Documents\XMUpdate
2017-05-17 17:39 - 2017-05-17 17:51 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Mozilla
2017-05-17 17:37 - 2017-05-17 21:33 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Opera Software
2017-05-17 17:37 - 2017-05-17 17:37 - 00000000 ____D C:\Program Files\Common Files\JOS26Z5TB4
2017-05-17 17:29 - 2017-05-17 17:29 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\WinRAR
2017-04-29 20:56 - 2017-04-29 20:56 - 00000000 ____D C:\Users\home\Documents\Flight Simulator X Files
2017-04-29 18:18 - 2017-05-01 11:12 - 00000000 ____D C:\Users\home\AppData\LocalLow\uTorrent
2017-04-29 11:26 - 2017-04-29 11:28 - 00000000 ____D C:\Users\home\Desktop\Drugi Svetski rat
2017-04-28 08:38 - 2017-04-28 08:38 - 00000000 ___SD C:\Windows\SysWOW64\{A24B87CE-67C9-49D1-B0A5-F06A1C73BC58}
2017-04-27 22:03 - 2017-04-27 22:03 - 00000222 _____ C:\Users\home\Desktop\Euro Truck Simulator 2.url
2017-04-27 21:04 - 2017-04-27 21:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2017-04-27 21:04 - 2017-04-27 21:04 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi
2017-04-27 20:58 - 2017-04-27 20:59 - 09777152 _____ C:\Users\home\Downloads\hamachi.msi
2017-04-27 19:15 - 2017-04-27 21:21 - 00000000 ___SD C:\Windows\SysWOW64\{D28A6CAB-8746-4CDE-9D38-C5395B6DEFCD}
2017-04-26 13:08 - 2017-04-26 13:08 - 00000000 ___SD C:\Windows\SysWOW64\{FA70E676-D02E-4F59-967B-2091A253A5FF}
2017-04-26 10:33 - 2017-04-26 10:34 - 00000000 ____D C:\Users\home\AppData\Roaming\discord
2017-04-26 10:33 - 2017-04-26 10:33 - 00002154 _____ C:\Users\home\Desktop\Discord.lnk
2017-04-26 10:33 - 2017-04-26 10:33 - 00000000 ____D C:\Users\home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hammer & Chisel, Inc
2017-04-26 10:31 - 2017-04-26 10:32 - 52553728 _____ (Hammer & Chisel, Inc.) C:\Users\home\Downloads\DiscordSetup.exe
2017-04-26 09:08 - 2017-04-26 09:08 - 00120601 _____ C:\Users\home\Downloads\Outlast.2-CODEX.torrent
2017-04-23 18:32 - 2017-04-23 18:32 - 00019016 _____ C:\Users\home\Downloads\Die Hard with a Vengeance (1995) [720p] [YTS.AG] (1).torrent
2017-04-21 14:50 - 2017-04-21 14:50 - 00000000 ____D C:\Users\home\AppData\LocalLow\Bossa Studios
2017-04-21 14:36 - 2017-04-21 14:36 - 00000222 _____ C:\Users\home\Desktop\Surgeon Simulator.url
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-05-21 15:33 - 2016-10-26 10:20 - 00000000 ____D C:\Users\Administrator
2017-05-21 15:28 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-05-21 15:28 - 2009-07-14 06:45 - 00503136 _____ C:\Windows\system32\FNTCACHE.DAT
2017-05-21 14:18 - 2016-04-18 20:39 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 12.0
2017-05-21 14:10 - 2016-01-16 23:49 - 00000000 ____D C:\Windows\system32\1033
2017-05-21 14:10 - 2016-01-16 23:49 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 10.0
2017-05-21 14:10 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2017-05-21 14:05 - 2009-07-14 06:45 - 00047104 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-05-21 14:05 - 2009-07-14 06:45 - 00047104 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-05-21 14:02 - 2013-11-26 21:49 - 00000000 ____D C:\Program Files (x86)\WinRAR
2017-05-21 10:26 - 2015-11-03 22:56 - 00002227 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-05-21 00:23 - 2016-10-26 10:22 - 00001405 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2017-05-21 00:23 - 2016-10-26 10:22 - 00001399 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-05-20 23:49 - 2015-11-03 23:52 - 00000002 RSHOT C:\Windows\winstart.bat
2017-05-20 23:49 - 2015-11-03 23:52 - 00000002 __SOT C:\Windows\SysWOW64\CONFIG.NT
2017-05-20 23:49 - 2015-11-03 23:52 - 00000002 __SOT C:\Windows\SysWOW64\AUTOEXEC.NT
2017-05-20 23:12 - 2016-10-19 17:32 - 00001945 _____ C:\Windows\epplauncher.mif
2017-05-20 00:33 - 2016-03-17 23:33 - 00000000 ____D C:\Users\Public\Documents\Wondershare
2017-05-19 21:32 - 2015-11-01 13:51 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-05-19 21:16 - 2017-04-17 11:08 - 00000000 ____D C:\Windows\Update
2017-05-19 19:53 - 2017-03-07 19:21 - 00000000 _____ C:\Windows\system.ini
2017-05-19 19:28 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration
2017-05-19 19:28 - 2009-07-14 04:34 - 37486592 _____ C:\Windows\system32\config\system.bak
2017-05-19 19:28 - 2009-07-14 04:34 - 143130624 _____ C:\Windows\system32\config\software.bak
2017-05-19 19:28 - 2009-07-14 04:34 - 04980736 _____ C:\Windows\system32\config\default.bak
2017-05-19 19:28 - 2009-07-14 04:34 - 00262144 _____ C:\Windows\system32\config\security.bak
2017-05-19 19:28 - 2009-07-14 04:34 - 00262144 _____ C:\Windows\system32\config\sam.bak
2017-05-18 23:46 - 2013-11-26 21:02 - 00000000 ____D C:\Users\home
2017-05-18 22:24 - 2017-01-05 12:53 - 00001908 _____ C:\Windows\diagwrn.xml
2017-05-18 22:24 - 2017-01-05 12:53 - 00001908 _____ C:\Windows\diagerr.xml
2017-05-18 22:18 - 2016-01-17 17:45 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2017-05-18 22:00 - 2016-01-17 17:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2017-05-18 21:59 - 2016-01-17 17:45 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2017-05-18 21:57 - 2016-06-05 13:07 - 156335152 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-05-18 21:56 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf
2017-05-18 17:43 - 2016-05-12 21:15 - 00000000 ____D C:\ProgramData\BlueStacksSetup
2017-05-18 17:43 - 2013-11-27 05:49 - 00000000 ____D C:\Windows\Panther
2017-05-18 17:28 - 2016-01-17 17:32 - 00000000 ____D C:\Program Files (x86)\Microsoft SDKs
2017-05-18 17:22 - 2016-04-30 18:22 - 00000000 ____D C:\Program Files (x86)\InstallShield Installation Information
2017-05-18 17:07 - 2014-06-02 21:09 - 00000000 ____D C:\Windows\system32\appmgmt
2017-05-18 05:00 - 2016-12-27 20:43 - 00000000 ____D C:\Program Files (x86)\Courkaripack Center
2017-05-18 02:34 - 2015-11-01 19:16 - 00002328 _____ C:\Users\home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-05-18 02:27 - 2017-01-18 21:09 - 00001956 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-05-18 02:27 - 2017-01-18 21:09 - 00001886 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2017-05-17 21:35 - 2017-01-22 20:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2017-05-17 21:35 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2017-05-17 21:34 - 2017-03-07 19:22 - 00000000 ____D C:\Program Files\Opera
2017-05-17 21:32 - 2017-04-19 20:51 - 00000000 ____D C:\Program Files\FACEIT Client
2017-05-17 21:27 - 2017-02-23 15:41 - 00000000 ____D C:\Program Files\City Car Driving
2017-05-17 17:56 - 2017-04-13 11:16 - 00000000 ____D C:\Users\home\AppData\Roaming\Ckozoghgrrucult
2017-05-17 17:51 - 2015-11-01 13:51 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2017-05-17 17:21 - 2015-11-03 22:56 - 00003330 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2017-05-17 17:21 - 2015-11-03 22:56 - 00003202 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2017-05-01 11:33 - 2015-09-20 13:12 - 00000000 ____D C:\Users\home\AppData\Roaming\uTorrent
2017-05-01 11:15 - 2016-07-11 11:57 - 00000000 ____D C:\Users\home\AppData\Roaming\Curse Client
2017-04-30 23:37 - 2017-01-18 21:09 - 00000000 ____D C:\Users\home\AppData\LocalLow\Mozilla
2017-04-30 22:26 - 2015-05-20 14:07 - 00000000 ____D C:\Users\home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2017-04-28 22:51 - 2014-02-12 18:42 - 00000000 ____D C:\Users\home\AppData\Roaming\Skype
2017-04-28 21:31 - 2016-07-11 12:57 - 00000000 ____D C:\Users\home\AppData\Roaming\.minecraft
2017-04-28 21:04 - 2017-03-05 17:21 - 00000000 ____D C:\Users\home\Documents\Euro Truck Simulator 2
2017-04-27 08:59 - 2016-09-21 20:33 - 00000000 ____D C:\Users\home\Desktop\Cope
2017-04-25 20:19 - 2017-01-13 21:31 - 00000000 ____D C:\Users\home\AppData\Roaming\TS3Client
2017-04-25 19:06 - 2016-07-27 12:56 - 00000000 ____D C:\Users\home\Desktop\FPS
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
ATTENTION: ==> Could not access BCD.
LastRegBack: 2016-05-01 12:22
==================== End of FRST.txt ============================
[Link mogu videti samo ulogovani korisnici]
|