nvidiapanel.exe

2

nvidiapanel.exe

offline
  • Pridružio: 28 Jun 2013
  • Poruke: 80

Ne znam da li je neka greska ali ovo se nije desilo:
Citat:U toku rada, ComboFix će:
proveriti postoji li novija verzija programa:
klikni Yes ako bude ponuđeno preuzimanje iste.
ako Recovery Console nije instalirana, ponuditi instalaciju:
obavezno prihvati klikom na Yes i isprati postupak.
postaviti/dati određeni broj upita/obaveštenja:
prihvati klikom na Yes ili OK.


Sve ostalo je proteklo u redu, komp se restart a fajl je sacuvan evo ga :



ComboFix 13-09-02.02 - User 02.09.2013 21:56:58.1.1 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.2047.999 [GMT 2:00]
Running from: C:\Users\User\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\autorun.inf
C:\hbodk.exe
C:\Users\User\AppData\Local\assembly\tmp
C:\Users\User\AppData\Roaming\poclbm
C:\Users\User\AppData\Roaming\poclbm\poclbm.ini
C:\Users\User\samp.exe
C:\Windows\security\Database\tmp.edb
C:\Windows\SysWow64\config\config.exe
C:\Windows\SysWow64\config\systemprofile\videos\Videos.exe
C:\Windows\SysWow64\frapsvid.dll
C:\Windows\SysWow64\MUI\0409\0409.exe
C:\Windows\SysWow64\MUI\dispspec\dispspec.exe
C:\Windows\SysWow64\MUI\MUI.exe
C:\Windows\SysWow64\tmpCFB5.tmp
C:\Windows\SysWow64\tmpCFF5.tmp
D:\autorun.inf


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_NEWDRIVER
-------\Service_block_reader
-------\Service_NEWDRIVER


((((((((((((((((((((((((( Files Created from 2013-08-02 to 2013-09-02 )))))))))))))))))))))))))))))))


2013-09-02 20:07:16 . 2013-09-02 20:07:16 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\temp
2013-09-02 15:38:23 . 2013-09-02 15:37:59 83672 ----a-w- C:\Windows\system32\drivers\avnetflt.sys
2013-09-02 09:36:00 . 2013-09-02 09:36:00 -------- d-----w- C:\Users\User\AppData\Roaming\Avira
2013-09-02 09:33:49 . 2013-09-02 09:33:49 -------- d-----w- C:\ProgramData\AskPartnerNetwork
2013-09-02 09:33:49 . 2013-09-02 09:33:49 -------- d-----w- C:\Program Files (x86)\AskPartnerNetwork
2013-09-02 09:31:28 . 2013-09-02 09:31:30 -------- d-----w- C:\ProgramData\APN
2013-09-02 09:29:41 . 2013-09-02 09:29:08 28600 ----a-w- C:\Windows\system32\drivers\avkmgr.sys
2013-09-02 09:29:41 . 2013-09-02 09:29:08 130016 ----a-w- C:\Windows\system32\drivers\avipbb.sys
2013-09-02 09:29:41 . 2013-09-02 09:29:08 100712 ----a-w- C:\Windows\system32\drivers\avgntflt.sys
2013-09-02 09:29:38 . 2013-09-02 09:29:58 -------- d-----w- C:\ProgramData\Avira
2013-09-02 09:29:38 . 2013-09-02 09:29:38 -------- d-----w- C:\Program Files (x86)\Avira
2013-09-02 08:01:46 . 2013-09-02 09:26:26 -------- d-----w- C:\ProgramData\MFAData
2013-09-02 08:01:46 . 2013-09-02 08:01:46 -------- d-----w- C:\Users\User\AppData\Local\MFAData
2013-09-01 19:51:58 . 2013-09-02 05:40:40 -------- d-----w- C:\Windows\VideoUpdater
2013-09-01 19:26:50 . 2013-09-02 18:58:36 -------- d-----w- C:\AdwCleaner
2013-09-01 18:02:20 . 2013-09-01 18:02:20 -------- d-----w- C:\Users\User\AppData\Roaming\VideoUpdater
2013-09-01 17:45:21 . 2006-10-22 02:24:24 1519616 ----a-w- C:\Windows\system32\libmysql.dll
2013-08-31 15:36:56 . 2004-10-22 00:18:12 749568 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iKernel.dll
2013-08-31 15:36:56 . 2004-10-22 00:17:48 69715 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\ctor.dll
2013-08-31 15:36:56 . 2004-10-22 00:17:04 274432 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iscript.dll
2013-08-31 15:36:56 . 2004-10-22 00:16:28 180224 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iuser.dll
2013-08-31 15:36:56 . 2004-10-22 00:16:10 5632 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\DotNetInstaller.exe
2013-08-31 15:36:53 . 2013-08-31 15:36:53 323716 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\setup.dll
2013-08-31 15:36:53 . 2013-08-31 15:36:53 192644 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iGdi.dll
2013-08-30 17:12:14 . 2013-09-01 18:27:35 -------- d-----w- C:\Program Files (x86)\MTA San Andreas 1.3
2013-08-30 15:02:29 . 2013-09-01 18:27:37 -------- d---a-w- C:\ProgramData\MTA San Andreas All
2013-08-27 11:02:16 . 2013-08-27 11:08:13 -------- d-----w- C:\Users\User\VirtualBox VMs
2013-08-27 11:01:52 . 2013-08-27 11:13:57 -------- d-----w- C:\Users\User\.VirtualBox
2013-08-27 11:00:05 . 2013-07-04 13:58:48 238352 ----a-w- C:\Windows\system32\drivers\VBoxDrv.sys
2013-08-27 10:59:36 . 2013-07-04 13:57:00 120080 ----a-w- C:\Windows\system32\drivers\VBoxUSBMon.sys
2013-08-23 18:11:20 . 2013-08-23 18:11:20 -------- d-----w- C:\Users\User\AppData\Roaming\FileAssociationManager
2013-08-16 09:12:51 . 2013-08-16 09:15:34 43520 ----a-w- C:\Windows\SysWow64\CmdLineExt03.dll
2013-08-15 10:41:49 . 2013-08-30 06:11:38 -------- d-----w- C:\Users\User\AppData\Roaming\Nico Mak Computing
2013-08-15 10:41:21 . 2013-08-28 07:18:40 -------- d-----w- C:\Program Files (x86)\FileZilla FTP Client
2013-08-14 09:11:04 . 2013-08-14 09:11:04 4774272 ----a-w- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
2013-08-14 09:11:04 . 2013-08-14 09:11:04 4774272 ----a-w- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
2013-08-06 11:23:34 . 2013-08-06 11:23:34 -------- d-----w- C:\Users\User\AppData\Roaming\TagScanner
2013-08-06 11:23:30 . 2013-08-06 11:23:31 -------- d-----w- C:\Program Files (x86)\TagScanner
2013-08-06 10:29:38 . 2013-08-06 10:29:38 -------- d-----w- C:\Users\User\AppData\Roaming\Aura4You
2013-08-06 10:26:34 . 2013-08-06 10:27:05 -------- d-----w- C:\Program Files (x86)\Aura4You
2013-08-05 12:05:29 . 2013-08-05 12:19:06 -------- d-----w- C:\Users\User\AppData\Local\Temporary Projects
2013-08-05 11:54:03 . 2013-09-01 10:17:52 -------- d-----w- C:\Users\User\AppData\Local\lazarus
2013-08-05 11:53:49 . 2010-03-07 09:22:04 1849344 ----a-w- C:\Windows\system32\Qt4Pas5.dll
2013-08-05 11:51:57 . 2013-08-05 11:53:52 -------- d-----w- C:\lazarus
.


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2013-08-20 21:02:24 . 2012-06-28 17:25:04 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-08-20 21:02:24 . 2012-06-28 17:25:04 692104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-07-28 13:12:31 . 2013-07-14 19:23:04 99384 ----a-w- C:\Users\User\AppData\Roaming\inst.exe
2013-07-28 13:12:31 . 2013-07-14 19:23:04 82816 ----a-w- C:\Users\User\AppData\Roaming\pcouffin.sys
2013-07-22 12:47:52 . 2013-07-22 11:32:09 112832 ----a-w- C:\ProgramData\Microsoft\VCExpress\10.0\1033\ResourceCache.dll
2013-07-21 16:12:22 . 2013-07-21 16:12:28 96168 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-07-21 16:12:21 . 2012-07-01 15:01:06 867240 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll
2013-07-21 16:12:21 . 2012-07-01 15:01:06 789416 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2013-07-13 12:43:52 . 2013-07-11 15:57:01 2562208 ----a-w- C:\ProgramData\Microsoft\VisualStudio\11.0\1033\ResourceCache.dll
2013-07-11 13:47:58 . 2013-07-11 13:47:58 1075424 ----a-w- C:\ProgramData\Microsoft\WDExpress\11.0\1033\ResourceCache.dll
2013-07-11 09:07:51 . 2013-07-11 09:07:51 181728 ----a-w- C:\ProgramData\Microsoft\VCSExpress\10.0\1033\ResourceCache.dll
2013-07-04 13:57:00 . 2013-07-04 13:57:00 131856 ----a-w- C:\Windows\system32\drivers\VBoxNetAdp.sys
2013-06-21 12:06:36 . 2013-07-24 09:44:18 7641832 ----a-w- C:\Windows\system32\nvopencl.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:18 15920536 ----a-w- C:\Windows\system32\nvwgf2umx.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:18 13411896 ----a-w- C:\Windows\SysWow64\nvwgf2um.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 9239344 ----a-w- C:\Windows\system32\nvcuda.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 7687592 ----a-w- C:\Windows\SysWow64\nvcuda.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 572704 ----a-w- C:\Windows\system32\NvFBC64.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 570656 ----a-w- C:\Windows\system32\NvIFR64.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 467232 ----a-w- C:\Windows\SysWow64\NvIFR.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 465184 ----a-w- C:\Windows\SysWow64\NvFBC.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 2953504 ----a-w- C:\Windows\system32\nvcuvid.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 27781920 ----a-w- C:\Windows\system32\nvoglv64.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 2777888 ----a-w- C:\Windows\SysWow64\nvcuvid.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 25256224 ----a-w- C:\Windows\system32\nvcompiler.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 2363680 ----a-w- C:\Windows\system32\nvcuvenc.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 21102368 ----a-w- C:\Windows\SysWow64\nvoglv32.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 2002720 ----a-w- C:\Windows\SysWow64\nvcuvenc.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 1832224 ----a-w- C:\Windows\system32\nvdispco6432049.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 17560352 ----a-w- C:\Windows\SysWow64\nvcompiler.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 15144928 ----a-w- C:\Windows\system32\nvd3dumx.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 1511712 ----a-w- C:\Windows\system32\nvdispgenco6432049.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 11235104 ----a-w- C:\Windows\system32\drivers\nvlddmkm.sys
2013-06-21 12:06:36 . 2013-03-10 13:14:17 6324360 ----a-w- C:\Windows\SysWow64\nvopencl.dll
2013-06-21 12:06:36 . 2013-03-10 13:14:16 12427240 ----a-w- C:\Windows\SysWow64\nvd3dum.dll
2013-06-21 12:06:36 . 2013-03-10 13:14:15 2597856 ----a-w- C:\Windows\SysWow64\nvapi.dll
2013-06-21 12:06:36 . 2012-06-27 10:37:56 2936208 ----a-w- C:\Windows\system32\nvapi64.dll
2013-06-21 10:23:16 . 2011-04-07 21:19:06 6496544 ----a-w- C:\Windows\system32\nvcpl.dll
2013-06-21 10:23:16 . 2011-04-07 21:18:42 3514656 ----a-w- C:\Windows\system32\nvsvc64.dll
2013-06-21 10:23:11 . 2011-04-07 21:19:16 884512 ----a-w- C:\Windows\system32\nvvsvc.exe
2013-06-21 10:23:10 . 2011-04-07 21:19:16 63776 ----a-w- C:\Windows\system32\nvshext.dll
2013-06-21 10:23:10 . 2011-04-07 21:19:16 237856 ----a-w- C:\Windows\system32\nvmctray.dll
2013-06-21 03:16:02 . 2013-06-21 03:16:02 566048 ----a-w- C:\Windows\SysWow64\nvStreaming.exe
2013-06-17 00:10:22 . 2013-06-22 05:34:08 9552976 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A6599364-0E83-48E2-A1EA-6A079D8218BA}\mpengine.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7}]
2013-07-26 20:30:31 12240 ----a-w- C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{41564952-412D-5637-00A7-7A786E7484D7}"= "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll" [2013-07-26 20:30:31 12240]

[HKEY_CLASSES_ROOT\clsid\{41564952-412d-5637-00a7-7a786e7484d7}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightShot"="C:\Users\User\AppData\Local\Skillbrains\lightshot\LightShot.exe" [2013-05-27 11:48:56 226592]
"uTorrent"="C:\Program Files (x86)\uTorrent\uTorrent.exe" [2013-09-02 09:32:57 802136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 21:06:36 958576]
"BCSSync"="C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 12:54:26 91520]
"win32"="C:\kernels\drivers.vbs" [2013-02-16 11:14:08 474]
"avgnt"="C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-09-02 09:28:33 345144]
"ApnTBMon"="C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe" [2013-07-26 20:30:31 1558480]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\winlogon]
"shell"="C:\Users\User\AppData\Roaming\VideoUpdaterCodecses\videocodecs.exe,explorer.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="userinit.exe"

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 DragonUpdater;COMODO Dragon Update Service;C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe;C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [x]
R2 KMService;KMService;C:\Windows\system32\srvany.exe;C:\Windows\SYSNATIVE\srvany.exe [x]
R2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe;C:\Program Files (x86)\Skype\Updater\Updater.exe [x]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe;C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe [x]
R2 UI5IFS;Ashampoo Uninstaller 5 FileSystemChanges Driver;D:\ATiLiUS\Programi\Ashampoo\Ashampoo UnInstaller 5\IFS64.sys;D:\ATiLiUS\Programi\Ashampoo\Ashampoo UnInstaller 5\IFS64.sys [x]
R3 dfmirage;dfmirage;C:\Windows\system32\DRIVERS\dfmirage.sys;C:\Windows\SYSNATIVE\DRIVERS\dfmirage.sys [x]
R3 DfSdkS;Defragmentacija-Usluga;D:\ATiLiUS\Programi\Ashampoo\Ashampoo UnInstaller 5\DfSdkS64.exe;D:\ATiLiUS\Programi\Ashampoo\Ashampoo UnInstaller 5\DfSdkS64.exe [x]
R3 dmvsc;dmvsc;C:\Windows\system32\drivers\dmvsc.sys;C:\Windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 FairplayKD;FairplayKD;C:\ProgramData\MTA San Andreas All\Common\temp\FairplayKD.sys;C:\ProgramData\MTA San Andreas All\Common\temp\FairplayKD.sys [x]
R3 Revoflt;Revoflt;C:\Windows\system32\DRIVERS\revoflt.sys;C:\Windows\SYSNATIVE\DRIVERS\revoflt.sys [x]
R3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 TipCtrl;TipCtrl;D:\Pavle\Programs\TC\uTIPu\TipCtrl.exe;D:\Pavle\Programs\TC\uTIPu\TipCtrl.exe [x]
R3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys;C:\Windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys;C:\Windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys;C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys [x]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;C:\Windows\system32\DRIVERS\VBoxNetAdp.sys;C:\Windows\SYSNATIVE\DRIVERS\VBoxNetAdp.sys [x]
R3 VBoxNetFlt;VirtualBox Bridged Networking Service;C:\Windows\system32\DRIVERS\VBoxNetFlt.sys;C:\Windows\SYSNATIVE\DRIVERS\VBoxNetFlt.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe;C:\Windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 X6va012;X6va012;C:\Windows\SysWOW64\Drivers\X6va012;C:\Windows\SysWOW64\Drivers\X6va012 [x]
R4 vToolbarUpdater13.2.0;vToolbarUpdater13.2.0;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\13.2.0\ToolbarUpdater.exe;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\13.2.0\ToolbarUpdater.exe [x]
S0 PxHlpa64;PxHlpa64;C:\Windows\System32\Drivers\PxHlpa64.sys;C:\Windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S1 avgtp;avgtp;C:\Windows\system32\drivers\avgtpx64.sys;C:\Windows\SYSNATIVE\drivers\avgtpx64.sys [x]
S1 avkmgr;avkmgr;C:\Windows\system32\DRIVERS\avkmgr.sys;C:\Windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\system32\DRIVERS\dtsoftbus01.sys;C:\Windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 AntiVirSchedulerService;Avira Scheduler;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 AntiVirWebService;Avira Web Protection;C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE;C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [x]
S2 APNMCP;Ask Update Service;C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe;C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [x]
S2 MsDepSvc;Web Deployment Agent Service;C:\Program Files\IIS\Microsoft Web Deploy\MsDepSvc.exe;C:\Program Files\IIS\Microsoft Web Deploy\MsDepSvc.exe [x]
S2 nlsX86cc;Nalpeiron Licensing Service;C:\Windows\SysWOW64\nlssrv32.exe;C:\Windows\SysWOW64\nlssrv32.exe [x]
S2 Skype C2C Service;Skype C2C Service;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]


--- Other Services/Drivers In Memory ---

*NewlyCreated* - WS2IFSL

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-08-28 16:26:28 1177552 ----a-w- C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.62\Installer\chrmstp.exe

Contents of the 'Scheduled Tasks' folder

2013-09-02 C:\Windows\Tasks\Adobe Flash Player Updater.job
- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-28 17:25:04 . 2013-08-20 21:02:25]

2013-09-01 C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3953468251-2936877293-3906146625-1000Core.job
- C:\Users\User\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-01-05 19:06:34 . 2013-01-05 19:06:32]

2013-09-02 C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3953468251-2936877293-3906146625-1000UA.job
- C:\Users\User\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-01-05 19:06:34 . 2013-01-05 19:06:32]

2013-09-02 C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-14 10:04:04 . 2013-04-14 10:04:03]

2013-09-02 C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-14 10:04:04 . 2013-04-14 10:04:03]


--------- X64 Entries -----------


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-10-17 14:13:58 13307496]
"AdobeAAMUpdater-1.0"="C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-09-20 05:27:44 444904]
"Nvtmru"="C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-05-16 14:44:05 1012000]

------- Supplementary Scan -------

uLocal Page = C:\Windows\system32\blank.htm
uStart Page = [Link mogu videti samo ulogovani korisnici]
uDefault_Search_URL = [Link mogu videti samo ulogovani korisnici]
mDefault_Search_URL = [Link mogu videti samo ulogovani korisnici]
mLocal Page = C:\Windows\SysWOW64\blank.htm
mSearch Page = [Link mogu videti samo ulogovani korisnici]
mSearch Bar = [Link mogu videti samo ulogovani korisnici]
uInternet Settings,ProxyOverride = *.local
IE: Download with Xilisoft Download YouTube Video - D:\?????\????????\Yt\Download YouTube Video\upod_link.HTM
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: {{2d8ee268-8d7a-4996-b80b-8999ce8c7fe2} - {e327b07a-0e11-4fd4-bef2-b2c5605b59c6} - C:\Users\User\AppData\Roaming\DownTangoFTToolbar\DownTangoFTToolbar.dll
LSP: C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll
TCP: DhcpNameServer = 89.216.1.30 89.216.1.50
TCP: Interfaces\{b5734d9b-b213-4f56-a0dd-44d887a229ac}: DhcpNameServer = 89.216.1.30 89.216.1.50
FF - ProfilePath - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\sz6idpkb.default\
FF - prefs.js: browser.startup.homepage - [Link mogu videti samo ulogovani korisnici]
FF - ExtSQL: 2013-07-22 08:27; {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}; C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}

- - - - ORPHANS REMOVED - - - -

URLSearchHooks-{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - (no file)
BHO-{000F18F2-09EB-4A59-82B2-5AE4184C39C3} - C:\Program Files (x86)\Claro LTD\claro\1.8.3.10\bh\claro.dll
BHO-{e327b07a-0e11-4fd4-bef2-b2c5605b59c6} - C:\Users\User\AppData\Roaming\DownTangoFTToolbar\DownTangoFTToolbar.dll
Toolbar-{e327b07a-0e11-4fd4-bef2-b2c5605b59c6} - C:\Users\User\AppData\Roaming\DownTangoFTToolbar\DownTangoFTToolbar.dll
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
Wow6432Node-HKU-Default-Run-SearchProtect - \SearchProtect\bin\cltmng.exe
WebBrowser-{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5} - (no file)
AddRemove-BSPlayerp - C:\Program Files (x86)\Webteh\BSplayerPro\uninstall.exe
AddRemove-DAEMON Tools Lite - D:\Pavle\????????\DTLite\DAEMON Tools Lite\uninst.exe
AddRemove-FileZilla Client - C:\Program Files (x86)\FileZilla FTP Client\uninstall.exe
AddRemove-FL Studio 11 - D:\KRON\Programi\Image Line\FL Studio 11\uninstall.exe
AddRemove-VLC media player - D:\KRON\Programi\VLC\uninstall.exe





[Link mogu videti samo ulogovani korisnici]



offline
  • Pridružio: 09 Avg 2011
  • Poruke: 15879
  • Gde živiš: Beograd

Otvoriti Notepad i iskopirati sledeci tekst:

Folder::
C:\ProgramData\AskPartnerNetwork
C:\Program Files (x86)\AskPartnerNetwork
C:\ProgramData\APN
C:\Users\User\AppData\Roaming\DownTangoFTToolbar

File::
C:\kernels\drivers.vbs

FileLook::
C:\Users\User\AppData\Roaming\VideoUpdaterCodecses\videocodecs.exe

Registry::
[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{41564952-412D-5637-00A7-7A786E7484D7}"=-
[-HKEY_CLASSES_ROOT\clsid\{41564952-412d-5637-00a7-7a786e7484d7}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"win32"=-
"ApnTBMon"=-

Driver::
X6va012
vToolbarUpdater13.2.0
APNMCP

DDS::
IE: Download with Xilisoft Download YouTube Video - D:\?????\????????\Yt\Download YouTube Video\upod_link.HTM
IE: {{2d8ee268-8d7a-4996-b80b-8999ce8c7fe2} - {e327b07a-0e11-4fd4-bef2-b2c5605b59c6} - C:\Users\User\AppData\Roaming\DownTangoFTToolbar\DownTangoFTToolbar.dll

ClearJavaCache::


Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.



offline
  • Pridružio: 28 Jun 2013
  • Poruke: 80

Evo ga:


[Link mogu videti samo ulogovani korisnici]

ComboFix 13-09-02.02 - User 03.09.2013 8:04:12.3.1 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.2047.1117 [GMT 2:00]
Running from: C:\Users\User\Desktop\ComboFix.exe
Command switches used :: C:\Users\User\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

FILE ::
"C:\kernels\drivers.vbs"


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\ProgramData\APN
D:\ltgc.pif


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_X6VA012
-------\Service_vToolbarUpdater13.2.0
-------\Service_X6va012


((((((((((((((((((((((((( Files Created from 2013-08-03 to 2013-09-03 )))))))))))))))))))))))))))))))


2013-09-03 06:12:59 . 2013-09-03 06:14:45 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\temp
2013-09-02 09:29:38 . 2013-09-03 05:58:14 -------- d-----w- C:\ProgramData\Avira
2013-09-02 08:01:46 . 2013-09-02 09:26:26 -------- d-----w- C:\ProgramData\MFAData
2013-09-02 08:01:46 . 2013-09-02 08:01:46 -------- d-----w- C:\Users\User\AppData\Local\MFAData
2013-09-01 19:51:58 . 2013-09-02 05:40:40 -------- d-----w- C:\Windows\VideoUpdater
2013-09-01 19:26:50 . 2013-09-02 18:58:36 -------- d-----w- C:\AdwCleaner
2013-09-01 18:02:20 . 2013-09-01 18:02:20 -------- d-----w- C:\Users\User\AppData\Roaming\VideoUpdater
2013-09-01 17:45:21 . 2006-10-22 02:24:24 1519616 ----a-w- C:\Windows\system32\libmysql.dll
2013-08-31 15:36:56 . 2004-10-22 00:18:12 749568 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iKernel.dll
2013-08-31 15:36:56 . 2004-10-22 00:17:48 69715 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\ctor.dll
2013-08-31 15:36:56 . 2004-10-22 00:17:04 274432 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iscript.dll
2013-08-31 15:36:56 . 2004-10-22 00:16:28 180224 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iuser.dll
2013-08-31 15:36:56 . 2004-10-22 00:16:10 5632 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\DotNetInstaller.exe
2013-08-31 15:36:53 . 2013-08-31 15:36:53 323716 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\setup.dll
2013-08-31 15:36:53 . 2013-08-31 15:36:53 192644 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iGdi.dll
2013-08-30 17:12:14 . 2013-09-01 18:27:35 -------- d-----w- C:\Program Files (x86)\MTA San Andreas 1.3
2013-08-30 15:02:29 . 2013-09-01 18:27:37 -------- d---a-w- C:\ProgramData\MTA San Andreas All
2013-08-27 11:02:16 . 2013-08-27 11:08:13 -------- d-----w- C:\Users\User\VirtualBox VMs
2013-08-27 11:01:52 . 2013-08-27 11:13:57 -------- d-----w- C:\Users\User\.VirtualBox
2013-08-27 11:00:05 . 2013-07-04 13:58:48 238352 ----a-w- C:\Windows\system32\drivers\VBoxDrv.sys
2013-08-27 10:59:36 . 2013-07-04 13:57:00 120080 ----a-w- C:\Windows\system32\drivers\VBoxUSBMon.sys
2013-08-23 18:11:20 . 2013-08-23 18:11:20 -------- d-----w- C:\Users\User\AppData\Roaming\FileAssociationManager
2013-08-16 09:12:51 . 2013-08-16 09:15:34 43520 ----a-w- C:\Windows\SysWow64\CmdLineExt03.dll
2013-08-15 10:41:49 . 2013-08-30 06:11:38 -------- d-----w- C:\Users\User\AppData\Roaming\Nico Mak Computing
2013-08-15 10:41:21 . 2013-08-28 07:18:40 -------- d-----w- C:\Program Files (x86)\FileZilla FTP Client
2013-08-14 09:11:04 . 2013-08-14 09:11:04 4774272 ----a-w- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
2013-08-14 09:11:04 . 2013-08-14 09:11:04 4774272 ----a-w- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
2013-08-06 11:23:34 . 2013-08-06 11:23:34 -------- d-----w- C:\Users\User\AppData\Roaming\TagScanner
2013-08-06 11:23:30 . 2013-08-06 11:23:31 -------- d-----w- C:\Program Files (x86)\TagScanner
2013-08-06 10:29:38 . 2013-08-06 10:29:38 -------- d-----w- C:\Users\User\AppData\Roaming\Aura4You
2013-08-06 10:26:34 . 2013-08-06 10:27:05 -------- d-----w- C:\Program Files (x86)\Aura4You
2013-08-05 12:05:29 . 2013-08-05 12:19:06 -------- d-----w- C:\Users\User\AppData\Local\Temporary Projects
2013-08-05 11:54:03 . 2013-09-01 10:17:52 -------- d-----w- C:\Users\User\AppData\Local\lazarus
2013-08-05 11:53:49 . 2010-03-07 09:22:04 1849344 ----a-w- C:\Windows\system32\Qt4Pas5.dll
2013-08-05 11:51:57 . 2013-08-05 11:53:52 -------- d-----w- C:\lazarus
.


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2013-09-03 06:16:02 . 2013-09-03 06:16:02 76232 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A6599364-0E83-48E2-A1EA-6A079D8218BA}\offreg.dll
2013-08-20 21:02:24 . 2012-06-28 17:25:04 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-08-20 21:02:24 . 2012-06-28 17:25:04 692104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-07-28 13:12:31 . 2013-07-14 19:23:04 99384 ----a-w- C:\Users\User\AppData\Roaming\inst.exe
2013-07-28 13:12:31 . 2013-07-14 19:23:04 82816 ----a-w- C:\Users\User\AppData\Roaming\pcouffin.sys
2013-07-22 12:47:52 . 2013-07-22 11:32:09 112832 ----a-w- C:\ProgramData\Microsoft\VCExpress\10.0\1033\ResourceCache.dll
2013-07-21 16:12:22 . 2013-07-21 16:12:28 96168 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-07-21 16:12:21 . 2012-07-01 15:01:06 867240 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll
2013-07-21 16:12:21 . 2012-07-01 15:01:06 789416 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2013-07-13 12:43:52 . 2013-07-11 15:57:01 2562208 ----a-w- C:\ProgramData\Microsoft\VisualStudio\11.0\1033\ResourceCache.dll
2013-07-11 13:47:58 . 2013-07-11 13:47:58 1075424 ----a-w- C:\ProgramData\Microsoft\WDExpress\11.0\1033\ResourceCache.dll
2013-07-11 09:07:51 . 2013-07-11 09:07:51 181728 ----a-w- C:\ProgramData\Microsoft\VCSExpress\10.0\1033\ResourceCache.dll
2013-07-04 13:57:00 . 2013-07-04 13:57:00 131856 ----a-w- C:\Windows\system32\drivers\VBoxNetAdp.sys
2013-06-21 12:06:36 . 2013-07-24 09:44:18 7641832 ----a-w- C:\Windows\system32\nvopencl.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:18 15920536 ----a-w- C:\Windows\system32\nvwgf2umx.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:18 13411896 ----a-w- C:\Windows\SysWow64\nvwgf2um.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 9239344 ----a-w- C:\Windows\system32\nvcuda.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 7687592 ----a-w- C:\Windows\SysWow64\nvcuda.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 572704 ----a-w- C:\Windows\system32\NvFBC64.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 570656 ----a-w- C:\Windows\system32\NvIFR64.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 467232 ----a-w- C:\Windows\SysWow64\NvIFR.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 465184 ----a-w- C:\Windows\SysWow64\NvFBC.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 2953504 ----a-w- C:\Windows\system32\nvcuvid.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 27781920 ----a-w- C:\Windows\system32\nvoglv64.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 2777888 ----a-w- C:\Windows\SysWow64\nvcuvid.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 25256224 ----a-w- C:\Windows\system32\nvcompiler.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 2363680 ----a-w- C:\Windows\system32\nvcuvenc.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 21102368 ----a-w- C:\Windows\SysWow64\nvoglv32.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 2002720 ----a-w- C:\Windows\SysWow64\nvcuvenc.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 1832224 ----a-w- C:\Windows\system32\nvdispco6432049.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 17560352 ----a-w- C:\Windows\SysWow64\nvcompiler.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 15144928 ----a-w- C:\Windows\system32\nvd3dumx.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 1511712 ----a-w- C:\Windows\system32\nvdispgenco6432049.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 11235104 ----a-w- C:\Windows\system32\drivers\nvlddmkm.sys
2013-06-21 12:06:36 . 2013-03-10 13:14:17 6324360 ----a-w- C:\Windows\SysWow64\nvopencl.dll
2013-06-21 12:06:36 . 2013-03-10 13:14:16 12427240 ----a-w- C:\Windows\SysWow64\nvd3dum.dll
2013-06-21 12:06:36 . 2013-03-10 13:14:15 2597856 ----a-w- C:\Windows\SysWow64\nvapi.dll
2013-06-21 12:06:36 . 2012-06-27 10:37:56 2936208 ----a-w- C:\Windows\system32\nvapi64.dll
2013-06-21 10:23:16 . 2011-04-07 21:19:06 6496544 ----a-w- C:\Windows\system32\nvcpl.dll
2013-06-21 10:23:16 . 2011-04-07 21:18:42 3514656 ----a-w- C:\Windows\system32\nvsvc64.dll
2013-06-21 10:23:11 . 2011-04-07 21:19:16 884512 ----a-w- C:\Windows\system32\nvvsvc.exe
2013-06-21 10:23:10 . 2011-04-07 21:19:16 63776 ----a-w- C:\Windows\system32\nvshext.dll
2013-06-21 10:23:10 . 2011-04-07 21:19:16 237856 ----a-w- C:\Windows\system32\nvmctray.dll
2013-06-21 03:16:02 . 2013-06-21 03:16:02 566048 ----a-w- C:\Windows\SysWow64\nvStreaming.exe
2013-06-17 00:10:22 . 2013-06-22 05:34:08 9552976 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A6599364-0E83-48E2-A1EA-6A079D8218BA}\mpengine.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{000F18F2-09EB-4A59-82B2-5AE4184C39C3}]
C:\Program Files (x86)\Claro LTD\claro\1.8.3.10\bh\claro.dll [BU]

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{e327b07a-0e11-4fd4-bef2-b2c5605b59c6}]
C:\Users\User\AppData\Roaming\DownTangoFTToolbar\DownTangoFTToolbar.dll [BU]

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{e327b07a-0e11-4fd4-bef2-b2c5605b59c6}"= "C:\Users\User\AppData\Roaming\DownTangoFTToolbar\DownTangoFTToolbar.dll" [BU]

[HKEY_CLASSES_ROOT\clsid\{e327b07a-0e11-4fd4-bef2-b2c5605b59c6}]
[HKEY_CLASSES_ROOT\wtb.Band.1]
[HKEY_CLASSES_ROOT\TypeLib\{a85e31f1-a6ce-4ace-a560-ec01271b7f55}]
[HKEY_CLASSES_ROOT\wtb.Band]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdobeBridge"="" [BU]
"LightShot"="C:\Users\User\AppData\Local\Skillbrains\lightshot\LightShot.exe" [2013-05-27 11:48:56 226592]
"uTorrent"="C:\Program Files (x86)\uTorrent\uTorrent.exe" [2013-09-02 09:32:57 802136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 21:06:36 958576]
"BCSSync"="C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 12:54:26 91520]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"SearchProtect"="\SearchProtect\bin\cltmng.exe" [BU]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 DragonUpdater;COMODO Dragon Update Service;C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe;C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [x]
R2 KMService;KMService;C:\Windows\system32\srvany.exe;C:\Windows\SYSNATIVE\srvany.exe [x]
R2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe;C:\Program Files (x86)\Skype\Updater\Updater.exe [x]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe;C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe [x]
R2 UI5IFS;Ashampoo Uninstaller 5 FileSystemChanges Driver;D:\ATiLiUS\Programi\Ashampoo\Ashampoo UnInstaller 5\IFS64.sys;D:\ATiLiUS\Programi\Ashampoo\Ashampoo UnInstaller 5\IFS64.sys [x]
R3 dfmirage;dfmirage;C:\Windows\system32\DRIVERS\dfmirage.sys;C:\Windows\SYSNATIVE\DRIVERS\dfmirage.sys [x]
R3 DfSdkS;Defragmentacija-Usluga;D:\ATiLiUS\Programi\Ashampoo\Ashampoo UnInstaller 5\DfSdkS64.exe;D:\ATiLiUS\Programi\Ashampoo\Ashampoo UnInstaller 5\DfSdkS64.exe [x]
R3 dmvsc;dmvsc;C:\Windows\system32\drivers\dmvsc.sys;C:\Windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 FairplayKD;FairplayKD;C:\ProgramData\MTA San Andreas All\Common\temp\FairplayKD.sys;C:\ProgramData\MTA San Andreas All\Common\temp\FairplayKD.sys [x]
R3 Revoflt;Revoflt;C:\Windows\system32\DRIVERS\revoflt.sys;C:\Windows\SYSNATIVE\DRIVERS\revoflt.sys [x]
R3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 TipCtrl;TipCtrl;D:\Pavle\Programs\TC\uTIPu\TipCtrl.exe;D:\Pavle\Programs\TC\uTIPu\TipCtrl.exe [x]
R3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys;C:\Windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys;C:\Windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys;C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys [x]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;C:\Windows\system32\DRIVERS\VBoxNetAdp.sys;C:\Windows\SYSNATIVE\DRIVERS\VBoxNetAdp.sys [x]
R3 VBoxNetFlt;VirtualBox Bridged Networking Service;C:\Windows\system32\DRIVERS\VBoxNetFlt.sys;C:\Windows\SYSNATIVE\DRIVERS\VBoxNetFlt.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe;C:\Windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 PxHlpa64;PxHlpa64;C:\Windows\System32\Drivers\PxHlpa64.sys;C:\Windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S1 avgtp;avgtp;C:\Windows\system32\drivers\avgtpx64.sys;C:\Windows\SYSNATIVE\drivers\avgtpx64.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\system32\DRIVERS\dtsoftbus01.sys;C:\Windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 MsDepSvc;Web Deployment Agent Service;C:\Program Files\IIS\Microsoft Web Deploy\MsDepSvc.exe;C:\Program Files\IIS\Microsoft Web Deploy\MsDepSvc.exe [x]
S2 nlsX86cc;Nalpeiron Licensing Service;C:\Windows\SysWOW64\nlssrv32.exe;C:\Windows\SysWOW64\nlssrv32.exe [x]
S2 Skype C2C Service;Skype C2C Service;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]


[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-08-28 16:26:28 1177552 ----a-w- C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.62\Installer\chrmstp.exe

Contents of the 'Scheduled Tasks' folder

2013-09-02 C:\Windows\Tasks\Adobe Flash Player Updater.job
- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-28 17:25:04 . 2013-08-20 21:02:25]

2013-09-01 C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3953468251-2936877293-3906146625-1000Core.job
- C:\Users\User\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-01-05 19:06:34 . 2013-01-05 19:06:32]

2013-09-02 C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3953468251-2936877293-3906146625-1000UA.job
- C:\Users\User\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-01-05 19:06:34 . 2013-01-05 19:06:32]

2013-09-02 C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-14 10:04:04 . 2013-04-14 10:04:03]

2013-09-02 C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-14 10:04:04 . 2013-04-14 10:04:03]


--------- X64 Entries -----------


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-10-17 14:13:58 13307496]
"AdobeAAMUpdater-1.0"="C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-09-20 05:27:44 444904]
"Nvtmru"="C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-05-16 14:44:05 1012000]

------- Supplementary Scan -------

uLocal Page = C:\Windows\system32\blank.htm
uStart Page = [Link mogu videti samo ulogovani korisnici]
uDefault_Search_URL = [Link mogu videti samo ulogovani korisnici]
mDefault_Search_URL = [Link mogu videti samo ulogovani korisnici]
mLocal Page = C:\Windows\SysWOW64\blank.htm
mSearch Page = [Link mogu videti samo ulogovani korisnici]
mSearch Bar = [Link mogu videti samo ulogovani korisnici]
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: {{2d8ee268-8d7a-4996-b80b-8999ce8c7fe2} - {e327b07a-0e11-4fd4-bef2-b2c5605b59c6} - C:\Users\User\AppData\Roaming\DownTangoFTToolbar\DownTangoFTToolbar.dll
TCP: DhcpNameServer = 89.216.1.30 89.216.1.50
TCP: Interfaces\{b5734d9b-b213-4f56-a0dd-44d887a229ac}: DhcpNameServer = 89.216.1.30 89.216.1.50
FF - ProfilePath - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\sz6idpkb.default\
FF - prefs.js: browser.startup.homepage - [Link mogu videti samo ulogovani korisnici]
FF - ExtSQL: 2013-07-22 08:27; {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}; C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}

- - - - ORPHANS REMOVED - - - -

URLSearchHooks-{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - (no file)
WebBrowser-{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5} - (no file)
AddRemove-BSPlayerp - C:\Program Files (x86)\Webteh\BSplayerPro\uninstall.exe
AddRemove-DAEMON Tools Lite - D:\Pavle\????????\DTLite\DAEMON Tools Lite\uninst.exe
AddRemove-FileZilla Client - C:\Program Files (x86)\FileZilla FTP Client\uninstall.exe
AddRemove-FL Studio 11 - D:\KRON\Programi\Image Line\FL Studio 11\uninstall.exe
AddRemove-VLC media player - D:\KRON\Programi\VLC\uninstall.exe

offline
  • Pridružio: 09 Avg 2011
  • Poruke: 15879
  • Gde živiš: Beograd

Odlicno, jos jedan korak pa zavrsavamo


Otvoriti Notepad i iskopirati sledeci tekst:

Folder::
C:\Windows\VideoUpdater
C:\Users\User\AppData\Roaming\VideoUpdater
C:\Program Files (x86)\Claro LTD
C:\Users\User\AppData\Roaming\DownTangoFTToolbar

Registry::
[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{000F18F2-09EB-4A59-82B2-5AE4184C39C3}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{e327b07a-0e11-4fd4-bef2-b2c5605b59c6}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{e327b07a-0e11-4fd4-bef2-b2c5605b59c6}"=-
[-HKEY_CLASSES_ROOT\clsid\{e327b07a-0e11-4fd4-bef2-b2c5605b59c6}]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"SearchProtect"=-
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000000
"AntiVirusDisableNotify"=dword:00000000
"FirewallDisableNotify"=dword:00000000
"FirewallOverride"=dword:00000000
"UpdatesDisableNotify"=dword:00000000
"UacDisableNotify"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000000
"AntiVirusDisableNotify"=dword:00000000
"FirewallDisableNotify"=dword:00000000
"FirewallOverride"=dword:00000000
"UpdatesDisableNotify"=dword:00000000
"UacDisableNotify"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"="explorer.exe"

DDS::
IE: {{2d8ee268-8d7a-4996-b80b-8999ce8c7fe2} - {e327b07a-0e11-4fd4-bef2-b2c5605b59c6} - C:\Users\User\AppData\Roaming\DownTangoFTToolbar\DownTangoFTToolbar.dll

ClearJavaCache::


Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.

offline
  • Pridružio: 28 Jun 2013
  • Poruke: 80

Evo ga:

[Link mogu videti samo ulogovani korisnici]

ComboFix 13-09-02.02 - User 03.09.2013 10:04:00.4.1 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.2047.817 [GMT 2:00]
Running from: C:\Users\User\Desktop\ComboFix.exe
Command switches used :: C:\Users\User\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Users\User\AppData\Roaming\VideoUpdater
C:\Users\User\AppData\Roaming\VideoUpdater\nvidiapanel.exe
C:\Windows\VideoUpdater
C:\Windows\VideoUpdater\nvidiapanel.exe


((((((((((((((((((((((((( Files Created from 2013-08-03 to 2013-09-03 )))))))))))))))))))))))))))))))


2013-09-03 08:12:20 . 2013-09-03 08:12:20 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\temp
2013-09-03 08:12:20 . 2013-09-03 08:12:20 -------- d-----w- C:\Users\Pavle\AppData\Local\temp
2013-09-03 08:12:20 . 2013-09-03 08:12:20 -------- d-----w- C:\Users\Default\AppData\Local\temp
2013-09-03 06:16:02 . 2013-09-03 06:16:02 76232 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A6599364-0E83-48E2-A1EA-6A079D8218BA}\offreg.dll
2013-09-02 09:29:38 . 2013-09-03 05:58:14 -------- d-----w- C:\ProgramData\Avira
2013-09-02 08:01:46 . 2013-09-02 09:26:26 -------- d-----w- C:\ProgramData\MFAData
2013-09-02 08:01:46 . 2013-09-02 08:01:46 -------- d-----w- C:\Users\User\AppData\Local\MFAData
2013-09-01 19:26:50 . 2013-09-02 18:58:36 -------- d-----w- C:\AdwCleaner
2013-09-01 17:59:44 . 2013-09-02 06:03:28 -------- d-----w- C:\Users\User\AppData\Roaming\VideoUpdaterCodecses
2013-09-01 17:45:21 . 2006-10-22 02:24:24 1519616 ----a-w- C:\Windows\system32\libmysql.dll
2013-08-31 15:36:56 . 2004-10-22 00:18:12 749568 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iKernel.dll
2013-08-31 15:36:56 . 2004-10-22 00:17:48 69715 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\ctor.dll
2013-08-31 15:36:56 . 2004-10-22 00:17:04 274432 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iscript.dll
2013-08-31 15:36:56 . 2004-10-22 00:16:28 180224 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iuser.dll
2013-08-31 15:36:56 . 2004-10-22 00:16:10 5632 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\DotNetInstaller.exe
2013-08-31 15:36:53 . 2013-08-31 15:36:53 323716 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\setup.dll
2013-08-31 15:36:53 . 2013-08-31 15:36:53 192644 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iGdi.dll
2013-08-30 17:12:14 . 2013-09-01 18:27:35 -------- d-----w- C:\Program Files (x86)\MTA San Andreas 1.3
2013-08-30 15:02:29 . 2013-09-01 18:27:37 -------- d---a-w- C:\ProgramData\MTA San Andreas All
2013-08-27 11:02:16 . 2013-08-27 11:08:13 -------- d-----w- C:\Users\User\VirtualBox VMs
2013-08-27 11:01:52 . 2013-08-27 11:13:57 -------- d-----w- C:\Users\User\.VirtualBox
2013-08-27 11:00:05 . 2013-07-04 13:58:48 238352 ----a-w- C:\Windows\system32\drivers\VBoxDrv.sys
2013-08-27 10:59:36 . 2013-07-04 13:57:00 120080 ----a-w- C:\Windows\system32\drivers\VBoxUSBMon.sys
2013-08-23 18:11:20 . 2013-08-23 18:11:20 -------- d-----w- C:\Users\User\AppData\Roaming\FileAssociationManager
2013-08-16 09:12:51 . 2013-08-16 09:15:34 43520 ----a-w- C:\Windows\SysWow64\CmdLineExt03.dll
2013-08-15 10:41:49 . 2013-08-30 06:11:38 -------- d-----w- C:\Users\User\AppData\Roaming\Nico Mak Computing
2013-08-15 10:41:21 . 2013-08-28 07:18:40 -------- d-----w- C:\Program Files (x86)\FileZilla FTP Client
2013-08-14 09:11:04 . 2013-08-14 09:11:04 4774272 ----a-w- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
2013-08-14 09:11:04 . 2013-08-14 09:11:04 4774272 ----a-w- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
2013-08-06 11:23:34 . 2013-08-06 11:23:34 -------- d-----w- C:\Users\User\AppData\Roaming\TagScanner
2013-08-06 11:23:30 . 2013-08-06 11:23:31 -------- d-----w- C:\Program Files (x86)\TagScanner
2013-08-06 10:29:38 . 2013-08-06 10:29:38 -------- d-----w- C:\Users\User\AppData\Roaming\Aura4You
2013-08-06 10:26:34 . 2013-08-06 10:27:05 -------- d-----w- C:\Program Files (x86)\Aura4You
2013-08-05 12:05:29 . 2013-08-05 12:19:06 -------- d-----w- C:\Users\User\AppData\Local\Temporary Projects
2013-08-05 11:54:03 . 2013-09-01 10:17:52 -------- d-----w- C:\Users\User\AppData\Local\lazarus
2013-08-05 11:53:49 . 2010-03-07 09:22:04 1849344 ----a-w- C:\Windows\system32\Qt4Pas5.dll
2013-08-05 11:51:57 . 2013-08-05 11:53:52 -------- d-----w- C:\lazarus
.


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2013-08-20 21:02:24 . 2012-06-28 17:25:04 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-08-20 21:02:24 . 2012-06-28 17:25:04 692104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-07-28 13:12:31 . 2013-07-14 19:23:04 99384 ----a-w- C:\Users\User\AppData\Roaming\inst.exe
2013-07-28 13:12:31 . 2013-07-14 19:23:04 82816 ----a-w- C:\Users\User\AppData\Roaming\pcouffin.sys
2013-07-22 12:47:52 . 2013-07-22 11:32:09 112832 ----a-w- C:\ProgramData\Microsoft\VCExpress\10.0\1033\ResourceCache.dll
2013-07-21 16:12:22 . 2013-07-21 16:12:28 96168 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-07-21 16:12:21 . 2012-07-01 15:01:06 867240 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll
2013-07-21 16:12:21 . 2012-07-01 15:01:06 789416 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2013-07-13 12:43:52 . 2013-07-11 15:57:01 2562208 ----a-w- C:\ProgramData\Microsoft\VisualStudio\11.0\1033\ResourceCache.dll
2013-07-11 13:47:58 . 2013-07-11 13:47:58 1075424 ----a-w- C:\ProgramData\Microsoft\WDExpress\11.0\1033\ResourceCache.dll
2013-07-11 09:07:51 . 2013-07-11 09:07:51 181728 ----a-w- C:\ProgramData\Microsoft\VCSExpress\10.0\1033\ResourceCache.dll
2013-07-04 13:57:00 . 2013-07-04 13:57:00 131856 ----a-w- C:\Windows\system32\drivers\VBoxNetAdp.sys
2013-06-21 12:06:36 . 2013-07-24 09:44:18 7641832 ----a-w- C:\Windows\system32\nvopencl.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:18 15920536 ----a-w- C:\Windows\system32\nvwgf2umx.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:18 13411896 ----a-w- C:\Windows\SysWow64\nvwgf2um.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 9239344 ----a-w- C:\Windows\system32\nvcuda.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 7687592 ----a-w- C:\Windows\SysWow64\nvcuda.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 572704 ----a-w- C:\Windows\system32\NvFBC64.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 570656 ----a-w- C:\Windows\system32\NvIFR64.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 467232 ----a-w- C:\Windows\SysWow64\NvIFR.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 465184 ----a-w- C:\Windows\SysWow64\NvFBC.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 2953504 ----a-w- C:\Windows\system32\nvcuvid.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 27781920 ----a-w- C:\Windows\system32\nvoglv64.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 2777888 ----a-w- C:\Windows\SysWow64\nvcuvid.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 25256224 ----a-w- C:\Windows\system32\nvcompiler.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 2363680 ----a-w- C:\Windows\system32\nvcuvenc.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 21102368 ----a-w- C:\Windows\SysWow64\nvoglv32.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 2002720 ----a-w- C:\Windows\SysWow64\nvcuvenc.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 1832224 ----a-w- C:\Windows\system32\nvdispco6432049.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 17560352 ----a-w- C:\Windows\SysWow64\nvcompiler.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 15144928 ----a-w- C:\Windows\system32\nvd3dumx.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 1511712 ----a-w- C:\Windows\system32\nvdispgenco6432049.dll
2013-06-21 12:06:36 . 2013-07-24 09:44:17 11235104 ----a-w- C:\Windows\system32\drivers\nvlddmkm.sys
2013-06-21 12:06:36 . 2013-03-10 13:14:17 6324360 ----a-w- C:\Windows\SysWow64\nvopencl.dll
2013-06-21 12:06:36 . 2013-03-10 13:14:16 12427240 ----a-w- C:\Windows\SysWow64\nvd3dum.dll
2013-06-21 12:06:36 . 2013-03-10 13:14:15 2597856 ----a-w- C:\Windows\SysWow64\nvapi.dll
2013-06-21 12:06:36 . 2012-06-27 10:37:56 2936208 ----a-w- C:\Windows\system32\nvapi64.dll
2013-06-21 10:23:16 . 2011-04-07 21:19:06 6496544 ----a-w- C:\Windows\system32\nvcpl.dll
2013-06-21 10:23:16 . 2011-04-07 21:18:42 3514656 ----a-w- C:\Windows\system32\nvsvc64.dll
2013-06-21 10:23:11 . 2011-04-07 21:19:16 884512 ----a-w- C:\Windows\system32\nvvsvc.exe
2013-06-21 10:23:10 . 2011-04-07 21:19:16 63776 ----a-w- C:\Windows\system32\nvshext.dll
2013-06-21 10:23:10 . 2011-04-07 21:19:16 237856 ----a-w- C:\Windows\system32\nvmctray.dll
2013-06-21 03:16:02 . 2013-06-21 03:16:02 566048 ----a-w- C:\Windows\SysWow64\nvStreaming.exe
2013-06-17 00:10:22 . 2013-06-22 05:34:08 9552976 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A6599364-0E83-48E2-A1EA-6A079D8218BA}\mpengine.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{000F18F2-09EB-4A59-82B2-5AE4184C39C3}]
C:\Program Files (x86)\Claro LTD\claro\1.8.3.10\bh\claro.dll [BU]

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{e327b07a-0e11-4fd4-bef2-b2c5605b59c6}]
C:\Users\User\AppData\Roaming\DownTangoFTToolbar\DownTangoFTToolbar.dll [BU]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdobeBridge"="" [BU]
"LightShot"="C:\Users\User\AppData\Local\Skillbrains\lightshot\LightShot.exe" [2013-05-27 11:48:56 226592]
"uTorrent"="C:\Program Files (x86)\uTorrent\uTorrent.exe" [2013-09-02 09:32:57 802136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 21:06:36 958576]
"BCSSync"="C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 12:54:26 91520]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 DragonUpdater;COMODO Dragon Update Service;C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe;C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [x]
R2 KMService;KMService;C:\Windows\system32\srvany.exe;C:\Windows\SYSNATIVE\srvany.exe [x]
R2 Skype C2C Service;Skype C2C Service;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]
R2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe;C:\Program Files (x86)\Skype\Updater\Updater.exe [x]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe;C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe [x]
R2 UI5IFS;Ashampoo Uninstaller 5 FileSystemChanges Driver;D:\ATiLiUS\Programi\Ashampoo\Ashampoo UnInstaller 5\IFS64.sys;D:\ATiLiUS\Programi\Ashampoo\Ashampoo UnInstaller 5\IFS64.sys [x]
R3 dfmirage;dfmirage;C:\Windows\system32\DRIVERS\dfmirage.sys;C:\Windows\SYSNATIVE\DRIVERS\dfmirage.sys [x]
R3 DfSdkS;Defragmentacija-Usluga;D:\ATiLiUS\Programi\Ashampoo\Ashampoo UnInstaller 5\DfSdkS64.exe;D:\ATiLiUS\Programi\Ashampoo\Ashampoo UnInstaller 5\DfSdkS64.exe [x]
R3 dmvsc;dmvsc;C:\Windows\system32\drivers\dmvsc.sys;C:\Windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 FairplayKD;FairplayKD;C:\ProgramData\MTA San Andreas All\Common\temp\FairplayKD.sys;C:\ProgramData\MTA San Andreas All\Common\temp\FairplayKD.sys [x]
R3 Revoflt;Revoflt;C:\Windows\system32\DRIVERS\revoflt.sys;C:\Windows\SYSNATIVE\DRIVERS\revoflt.sys [x]
R3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 TipCtrl;TipCtrl;D:\Pavle\Programs\TC\uTIPu\TipCtrl.exe;D:\Pavle\Programs\TC\uTIPu\TipCtrl.exe [x]
R3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys;C:\Windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys;C:\Windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys;C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys [x]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;C:\Windows\system32\DRIVERS\VBoxNetAdp.sys;C:\Windows\SYSNATIVE\DRIVERS\VBoxNetAdp.sys [x]
R3 VBoxNetFlt;VirtualBox Bridged Networking Service;C:\Windows\system32\DRIVERS\VBoxNetFlt.sys;C:\Windows\SYSNATIVE\DRIVERS\VBoxNetFlt.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe;C:\Windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 PxHlpa64;PxHlpa64;C:\Windows\System32\Drivers\PxHlpa64.sys;C:\Windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S1 avgtp;avgtp;C:\Windows\system32\drivers\avgtpx64.sys;C:\Windows\SYSNATIVE\drivers\avgtpx64.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\system32\DRIVERS\dtsoftbus01.sys;C:\Windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 MsDepSvc;Web Deployment Agent Service;C:\Program Files\IIS\Microsoft Web Deploy\MsDepSvc.exe;C:\Program Files\IIS\Microsoft Web Deploy\MsDepSvc.exe [x]
S2 nlsX86cc;Nalpeiron Licensing Service;C:\Windows\SysWOW64\nlssrv32.exe;C:\Windows\SysWOW64\nlssrv32.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]


[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-08-28 16:26:28 1177552 ----a-w- C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.62\Installer\chrmstp.exe

Contents of the 'Scheduled Tasks' folder

2013-09-02 C:\Windows\Tasks\Adobe Flash Player Updater.job
- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-28 17:25:04 . 2013-08-20 21:02:25]

2013-09-01 C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3953468251-2936877293-3906146625-1000Core.job
- C:\Users\User\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-01-05 19:06:34 . 2013-01-05 19:06:32]

2013-09-02 C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3953468251-2936877293-3906146625-1000UA.job
- C:\Users\User\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-01-05 19:06:34 . 2013-01-05 19:06:32]

2013-09-02 C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-14 10:04:04 . 2013-04-14 10:04:03]

2013-09-02 C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-14 10:04:04 . 2013-04-14 10:04:03]


--------- X64 Entries -----------


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-10-17 14:13:58 13307496]
"AdobeAAMUpdater-1.0"="C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-09-20 05:27:44 444904]
"Nvtmru"="C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-05-16 14:44:05 1012000]

------- Supplementary Scan -------

uLocal Page = C:\Windows\system32\blank.htm
uStart Page = [Link mogu videti samo ulogovani korisnici]
uDefault_Search_URL = [Link mogu videti samo ulogovani korisnici]
mDefault_Search_URL = [Link mogu videti samo ulogovani korisnici]
mLocal Page = C:\Windows\SysWOW64\blank.htm
mSearch Page = [Link mogu videti samo ulogovani korisnici]
mSearch Bar = [Link mogu videti samo ulogovani korisnici]
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: {{2d8ee268-8d7a-4996-b80b-8999ce8c7fe2} - {e327b07a-0e11-4fd4-bef2-b2c5605b59c6} - C:\Users\User\AppData\Roaming\DownTangoFTToolbar\DownTangoFTToolbar.dll
TCP: DhcpNameServer = 89.216.1.30 89.216.1.50
TCP: Interfaces\{b5734d9b-b213-4f56-a0dd-44d887a229ac}: DhcpNameServer = 89.216.1.30 89.216.1.50
FF - ProfilePath - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\sz6idpkb.default\
FF - prefs.js: browser.startup.homepage - [Link mogu videti samo ulogovani korisnici]
FF - ExtSQL: 2013-07-22 08:27; {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}; C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}

- - - - ORPHANS REMOVED - - - -

AddRemove-BSPlayerp - C:\Program Files (x86)\Webteh\BSplayerPro\uninstall.exe
AddRemove-DAEMON Tools Lite - D:\Pavle\????????\DTLite\DAEMON Tools Lite\uninst.exe
AddRemove-FileZilla Client - C:\Program Files (x86)\FileZilla FTP Client\uninstall.exe
AddRemove-FL Studio 11 - D:\KRON\Programi\Image Line\FL Studio 11\uninstall.exe
AddRemove-VLC media player - D:\KRON\Programi\VLC\uninstall.exe

offline
  • Pridružio: 09 Avg 2011
  • Poruke: 15879
  • Gde živiš: Beograd

Kakvo je sada stanje, imas li i dalje problema?

offline
  • Pridružio: 28 Jun 2013
  • Poruke: 80

Nema Mr. Green obrisan onaj nvidiapanel.exe
Odakle vam tolko znanja nemam pojma Very Happy

Hvala puno tebi i ivancetu95 Ziveli

offline
  • Pridružio: 09 Avg 2011
  • Poruke: 15879
  • Gde živiš: Beograd

NemaProblema ::
Odakle vam tolko znanja nemam pojma Very Happy


Ucio sam od najboljih Very Happy



Arrow Potrebno je deinstalirati ComboFix:
klikni start (ili ), a zatim RUN.

Na Visti i 7 koristiti Start Search polje ukoliko Run nije dostupan.

U liniju za unos teksta ukucaj (iskopiraj) sljedeće:

ComboFix /Uninstall

Primjeti da postoji razmak između "ComboFix" i "/Uninstall".



a zatim klikni OK (ili pritisni Enter).


Sačekaj da se proces deinstalacije završi.



Arrow Exclamation Instaliraj Antivirus obavezno, nemoj da se igras. Ukoliko nemaš novaca ili ne želiš da ga izdvojiš za neki komercijalni AV program, na raspolaganju ti se nalaze kvalitetni besplatni AV programi poput

Microsoft Security Essentials
avast! Free Antivirus
Avira Free Antivirus
Panda Antivirus Free
AVG Free
Bitdefender Free Antivirus

Takodje prelistaj malo i ove teme...

Aplikacija-za-sigurno-surfovanje-Vas-mozak Arrow
[Link mogu videti samo ulogovani korisnici]


Izbor besplatnog antivirusa Arrow
[Link mogu videti samo ulogovani korisnici]


Najbolji-antivirus-po-vasem-misljenju Arrow
[Link mogu videti samo ulogovani korisnici]


Najbolji besplatni zastitni softver Arrow
[Link mogu videti samo ulogovani korisnici]



Nemoj koristiti piratske verzije AV programa!!!



Arrow Preuzmi "Xplode"-ov DelFix i sačuvaj ga na Desktop

Dvoklikom pokreni program.

Štikliraj sledeće opcije:
Remove disinfection tools
Purge System Restore
Reset system settings


Klikni na dugme "Run" i pričekaj da program završi rad.
Kada alat završi, otvoriće izvestaj u notepadu.

Napomena: Izvestaj ce takodje biti sacuvan na C:\DelFix.txt. Ne treba da dostavljas ovaj izvestaj.



Arrow Preporučujem da za zaštitu USB memorijskih uredjaja koristiš MCShield v2. Nema nikakve veze sa AntiVirus-om tj. nece ometati njegov rad, a pokazao se kao jedan od najboljih vidova zaštite od malware-a koji se prenosi putem USB mem. uređaja. Skineš, instaliraš, ubodeš USB mem. uređaj, izvrši se skeniranje nakon čega dobiješ obaveštenje da je uređaj čist (ukoliko je stvarno tako); ili dobiješ log u kome vidiš informacije o malware-u koji je nađen i obrisan.


Home Page MCShield-a ::Anti-Malware Tool:: v2: [Link mogu videti samo ulogovani korisnici]

Više o MCShield-u možeš saznati u ovim temama:
v1: [Link mogu videti samo ulogovani korisnici]
v2: [Link mogu videti samo ulogovani korisnici]




Arrow Obavezno poseti temu "Testirajte da li vam je pretraživač ranjiv", pročitaj i isprati link koji stoji u njoj.
Link do teme je: [Link mogu videti samo ulogovani korisnici]



Arrow Takode, isprati i temu "Kako izbeci i ukloniti toolbar-ove" , procitaj i isprati korake u njoj. Link do teme je: [Link mogu videti samo ulogovani korisnici]
Na ovu temu posebno obrati paznju i gledaj da se pridrzavas navedenog u njoj.



TwinHeadedEagle (AMF Tim)

offline
  • Pridružio: 28 Jun 2013
  • Poruke: 80

Napisano: 03 Sep 2013 10:38

Sto se tice antivirusa, sigurno znas dosta vise od mene, al' ajde reci sad realno jel ne mislis da antivirusi detektuju sve zivo kao virus, sta god da skinem pise dole virus, a za dosta toga sam siguran da nije virus, nije meni problem, ali ponekad me nervira stalno mi izlece u uglu neki virusi... I sad iskreno i da imam para ne bih dao za AV instaliracu avast free i eto Very Happy
Sto se tice toolbarova to znam, uvek kad nesto instaliram destikliram sve Smile

Dopuna: 03 Sep 2013 10:42

I da dodam AV mi usporava komp mnogo...

offline
  • Pridružio: 09 Avg 2011
  • Poruke: 15879
  • Gde živiš: Beograd

NemaProblema ::Sto se tice antivirusa, sigurno znas dosta vise od mene, al' ajde reci sad realno jel ne mislis da antivirusi detektuju sve zivo kao virus, sta god da skinem pise dole virus, a za dosta toga sam siguran da nije virus, nije meni problem, ali ponekad me nervira stalno mi izlece u uglu neki virusi... I sad iskreno i da imam para ne bih dao za AV instaliracu avast free i eto Very Happy

Ne znam sta da ti kazem, postoje antivirusi koji imaju manji broj laznih detekcija, apsolutni lider po tom pitanju je Microsoft Security Essentials koji i ja sam koristim. A ti posto se bavis tim SAMP serverima i skidas kojekakve fajlove, sa kojekakvih linkova, logicno je da se antivirus oglasavaju. Sto se tice usporavanja MSE je neprimetan, a posto vidim da koristis 64-bitni sistem, to je onda solidan racunar i ne bi smeo da oseti neki "omanji" antivirus kao pomenuti MSE.

Sto se tice tvog slucaja imao si ne jednu nego vise infekcija, tako da je to automatski alarm da AV moras imati.


NemaProblema ::Sto se tice toolbarova to znam, uvek kad nesto instaliram destikliram sve Smile

Ne bih bas rekao, na osnovu Adwcleaner izvestaja Mr. Green

Potrebno ti je 5 sekundi vise da bi pomno ispratio instalaciju necega, a kada uz instalaciju dobijes i ove toolbarove, onda nastaje haos u racunaru, usporavanje, izmenjena pretraga itd.
Imas sve u temi koju sam linkovao, pa kad imas vremena ti procitaj...

Ko je trenutno na forumu
 

Ukupno su 798 korisnika na forumu :: 14 registrovanih, 3 sakrivenih i 781 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 100ka, Bickoooo, djordje92sm, kaskadija, Macalone, Marko03, mercedesamg, pacika, RED4G-304, sajorg, Tas011, tooljan, Valter071, Zadonbas