offline
- Pridružio: 22 Feb 2011
- Poruke: 33
|
Napisano: 01 Dec 2016 1:18
Naime napravih tesko pocetnicku gresku i navuce bedu na svoj komp.
Nekako sam uspo da navucem ono kinesu glupost ,sta je namam pojma,I uz to jos svasta.MB je nasao svasta i uredno pobrisao.Takodje su mi se duplirale neke ikone na deskopu ,nako prozirne ,ali bas kao ikona ne kao koija toga kada je redovno uradis.
Komp mi je zesce usporio kao i net.
Hvala....
+ .txtUnesi sadržajScan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 30-11-2016
Ran by kuureee (administrator) on KUUREEE-PC (01-12-2016 01:12:45)
Running from G:\Users\kuureee\Desktop
Loaded Profiles: kuureee (Available Profiles: kuureee)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Opera)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: geekstogo.com/forum/topic/335081-frst-t.....scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) G:\Windows\System32\atiesrxx.exe
(AMD) G:\Windows\System32\atieclxx.exe
(Microsoft Corporation) G:\Windows\System32\rundll32.exe
(SUPERAntiSpyware.com) G:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Advanced Micro Devices, Inc.) G:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
(Microsoft Corporation) G:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Popcorn Time) G:\Program Files (x86)\Popcorn Time\Updater.exe
() G:\Windows\temp\gEFBC.tmp.exe
(Microsoft Corporation) G:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) G:\Windows\System32\dllhost.exe
(Microsoft Corporation) G:\Windows\System32\alg.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera_crashreporter.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\RunOnce: [wd] => G:\Windows\TEMP\gEFBC.tmp.exe [770560 2016-12-01] () <===== ATTENTION
HKU\S-1-5-21-4139358893-2112486851-1280740277-1000\...\Run: [Viber] => F:\New folder\Viber.exe [51512528 2015-09-27] ()
HKU\S-1-5-21-4139358893-2112486851-1280740277-1000\...\Run: [uTorrent] => G:\Users\kuureee\AppData\Roaming\uTorrent\uTorrent.exe [1995968 2016-11-18] (BitTorrent Inc.)
HKU\S-1-5-21-4139358893-2112486851-1280740277-1000\...\Run: [Lync] => G:\Program Files\Microsoft Office\Office16\lync.exe [26878152 2016-01-13] (Microsoft Corporation)
HKU\S-1-5-21-4139358893-2112486851-1280740277-1000\...\Run: [CCleaner Monitoring] => G:\Program Files\CCleaner\CCleaner64.exe [8944344 2016-09-28] (Piriform Ltd)
ShellIconOverlayIdentifiers: [KzShlobj] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F2} => G:\Program Files\¿ìѹ\X64\KZipShell.dll No File
GroupPolicy: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog9 01 chtbrkg.dll No File
Winsock: Catalog9 02 chtbrkg.dll No File
Winsock: Catalog9 03 chtbrkg.dll No File
Winsock: Catalog9 04 chtbrkg.dll No File
Winsock: Catalog9 05 chtbrkg.dll No File
Winsock: Catalog9 06 chtbrkg.dll No File
Winsock: Catalog9 07 chtbrkg.dll No File
Winsock: Catalog9 08 chtbrkg.dll No File
Winsock: Catalog9 09 chtbrkg.dll No File
Winsock: Catalog9 10 chtbrkg.dll No File
Winsock: Catalog9 21 chtbrkg.dll No File
Winsock: Catalog9-x64 01 chtbrkg.dll No File
Winsock: Catalog9-x64 02 chtbrkg.dll No File
Winsock: Catalog9-x64 03 chtbrkg.dll No File
Winsock: Catalog9-x64 04 chtbrkg.dll No File
Winsock: Catalog9-x64 05 chtbrkg.dll No File
Winsock: Catalog9-x64 06 chtbrkg.dll No File
Winsock: Catalog9-x64 07 chtbrkg.dll No File
Winsock: Catalog9-x64 08 chtbrkg.dll No File
Winsock: Catalog9-x64 09 chtbrkg.dll No File
Winsock: Catalog9-x64 10 chtbrkg.dll No File
Winsock: Catalog9-x64 21 chtbrkg.dll No File
Tcpip\Parameters: [DhcpNameServer] 89.216.1.40 89.216.1.50
Tcpip\..\Interfaces\{01A0C17A-2E49-4034-B5A0-A408A5FAEDE4}: [DhcpNameServer] 89.216.1.40 89.216.1.50
Tcpip\..\Interfaces\{80B82E65-B0D1-4E76-A07F-6259AD41CD27}: [DhcpNameServer] 192.168.42.129
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-4139358893-2112486851-1280740277-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://faststartpage.com/
SearchScopes: HKLM -> DefaultScope value is missing
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> G:\Program Files\Microsoft Office\Office16\OCHelper.dll [2016-01-13] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> G:\Program Files\Java\jre1.8.0_66\bin\ssv.dll [2015-11-04] (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> G:\Program Files\Microsoft Office\Office16\URLREDIR.DLL [2015-07-31] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> G:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL [2016-01-13] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> G:\Program Files\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-11-04] (Oracle Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> G:\Program Files (x86)\Microsoft Office\Office16\OCHelper.dll [2015-07-31] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> G:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2015-11-22] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> G:\Program Files (x86)\Microsoft Office\Office16\URLREDIR.DLL [2015-07-31] (Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> G:\Program Files (x86)\Microsoft Office\Office16\GROOVEEX.DLL [2016-01-13] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> G:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-11-22] (Oracle Corporation)
Handler: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - G:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2016-01-13] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - G:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2016-01-13] (Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - G:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2016-01-13] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - G:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2016-01-13] (Microsoft Corporation)
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.66.2 -> G:\Program Files\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-11-04] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.66.2 -> G:\Program Files\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-11-04] (Oracle Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> G:\PROGRA~1\MICROS~2\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> G:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-11-22] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> G:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-11-22] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> G:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-01-12] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> G:\PROGRA~2\MICROS~1\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> G:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> G:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.2 -> G:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-01-21] (VideoLAN)
FF Plugin-x32: Adobe Reader -> G:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-10-01] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-4139358893-2112486851-1280740277-1000: @my.com/Games -> G:\Users\kuureee\AppData\Local\MyComGames\NPMyComDetector.dll [2015-11-05] (My.com, Inc)
FF Plugin ProgramFiles/Appdata: G:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2016-01-12] (Microsoft Corporation)
Chrome:
=======
CHR DefaultProfile: ChromeDefaultData
CHR Profile: G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2016-12-01] <==== ATTENTION
CHR Extension: (Google Slides) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-06-14]
CHR Extension: (Google Docs) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aohghmighlieiainnegkcijnfilokake [2016-06-14]
CHR Extension: (Google Drive) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-06-14]
CHR Extension: (YouTube) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-06-14]
CHR Extension: (Google Sheets) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-06-14]
CHR Extension: (Google Docs Offline) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-06-15]
CHR Extension: (Chrome Web Store Payments) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-06-14]
CHR Extension: (Gmail) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-06-14]
CHR Extension: (Chrome Media Router) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-10-26]
CHR Profile: G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default [2016-10-28]
CHR Extension: (Google Docs) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-11-14]
CHR Extension: (Google Drive) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-14]
CHR Extension: (YouTube) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-14]
CHR Extension: (Google Search) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-14]
CHR Extension: (Google Sheets) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-11-14]
CHR Extension: (Google Docs Offline) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-21]
CHR Extension: (Chrome Web Store Payments) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-03]
CHR Extension: (Gmail) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-14]
Opera:
=======
OPR Session Restore: -> is enabled.
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; G:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-23] (SUPERAntiSpyware.com)
R2 AMD FUEL Service; G:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [344064 2015-08-04] (Advanced Micro Devices, Inc.) [File not signed]
S2 LiveUpdateSvc; G:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2960672 2016-07-20] (IObit)
S3 Survarium Update Service; G:\Program Files (x86)\Survarium\game\binaries\x86\survarium_service.exe [97880 2016-08-14] ()
R2 Update service; G:\Program Files (x86)\Popcorn Time\Updater.exe [339968 2016-08-26] (Popcorn Time) [File not signed]
R2 WinDefend; G:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 GmSvc; G:\Program Files (x86)\LDSGameCenter\GmSvc.dll [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AODDriver4.3; G:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
R1 dtsoftbus01; G:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2015-11-26] (Disc Soft Ltd)
S3 NSNDIS5; G:\Windows\SysWOW64\NSNDIS5.SYS [17280 2004-03-24] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
R1 SASDIFSV; G:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; G:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R0 SmartDefragDriver; G:\Windows\System32\Drivers\SmartDefragDriver.sys [21360 2016-03-22] (IObit)
S3 vmci; \SystemRoot\system32\DRIVERS\vmci.sys [X]
S3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
NETSVCx32: HpSvc -> no filepath.
NETSVCx32: GmSvc -> G:\Program Files (x86)\LDSGameCenter\GmSvc.dll ==> No File
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-12-01 01:12 - 2016-12-01 01:12 - 00037756 _____ G:\Users\kuureee\Desktop\Addition.txt
2016-12-01 01:11 - 2016-12-01 01:11 - 00000000 ___SD G:\ComboFix
2016-12-01 01:10 - 2016-12-01 01:12 - 00015258 _____ G:\Users\kuureee\Desktop\FRST.txt
2016-12-01 01:07 - 2016-12-01 01:07 - 02411520 _____ (Farbar) G:\Users\kuureee\Desktop\FRST64.exe
2016-12-01 00:54 - 2016-12-01 01:11 - 00000000 ____D G:\Qoobox
2016-12-01 00:47 - 2016-12-01 00:47 - 00000080 _____ G:\Users\kuureee\AppData\Roaming\Microsoft\Windows\Start Menu\¿ìÑ1.lnk
2016-12-01 00:40 - 2016-12-01 00:40 - 00000000 ____D G:\ProgramData\Microsoft\Windows\Start Menu\Programs\鲁大师游戏库
2016-12-01 00:38 - 2016-12-01 00:38 - 05659307 ____R (Swearware) G:\Users\kuureee\Desktop\ComboFix.exe
2016-12-01 00:35 - 2016-12-01 00:42 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\KuaiZip
2016-12-01 00:35 - 2016-12-01 00:35 - 00000847 _____ G:\Users\kuureee\AppData\Roaming\Microsoft\Windows\Start Menu\¿ìѹ.lnk
2016-12-01 00:35 - 2016-12-01 00:35 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\Softlink
2016-12-01 00:33 - 2016-12-01 00:33 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\LDSGameCenter
2016-12-01 00:32 - 2016-12-01 00:32 - 00000000 __SHD G:\Users\kuureee\AppData\Local\svchost
2016-12-01 00:32 - 2016-12-01 00:32 - 00000000 ____D G:\Users\Public\Thunder Network
2016-12-01 00:32 - 2016-12-01 00:32 - 00000000 ____D G:\ProgramData\Thunder Network
2016-12-01 00:32 - 2016-11-09 15:55 - 00778752 _____ G:\Windows\system32\chtbrkg.dll
2016-12-01 00:32 - 2016-11-09 15:55 - 00590848 _____ G:\Windows\SysWOW64\chtbrkg.dll
2016-12-01 00:31 - 2016-12-01 01:13 - 00016718 _____ G:\Windows\System32\Tasks\40289_73307-2937
2016-12-01 00:31 - 2016-12-01 00:31 - 00001986 ___RS G:\Users\Public\Desktop\Survаrium.lnk
2016-12-01 00:31 - 2016-12-01 00:31 - 00001834 ___RS G:\Users\Public\Desktop\Wоrld of Tanks.lnk
2016-12-01 00:31 - 2016-12-01 00:31 - 00001796 ___RS G:\Users\kuureee\Desktop\ЕVE Launchеr.lnk
2016-12-01 00:31 - 2016-12-01 00:31 - 00001793 ___RS G:\Users\Public\Desktop\WаrThundеr.lnk
2016-12-01 00:31 - 2016-12-01 00:31 - 00001323 ___RS G:\Users\kuureee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Intеrnet Ехplorer.lnk
2016-12-01 00:31 - 2016-12-01 00:31 - 00001265 ___RS G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ореra.lnk
2016-12-01 00:31 - 2016-12-01 00:31 - 00001151 ___RS G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gоoglе Chrome.lnk
2016-12-01 00:31 - 2016-12-01 00:31 - 00001126 ___RS G:\ProgramData\Microsoft\Windows\Start Menu\Programs\zс1h3r7о5m4e.lnk
2016-12-01 00:31 - 2016-12-01 00:31 - 00000000 ___HD G:\ProgramData\40289_73307-2937
2016-12-01 00:31 - 2016-12-01 00:31 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\SPI
2016-12-01 00:14 - 2016-12-01 00:52 - 00000000 ____D G:\Users\kuureee\AppData\LocalLow\uTorrent
2016-12-01 00:11 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) G:\Windows\system32\D3DX9_40.dll
2016-12-01 00:11 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) G:\Windows\SysWOW64\D3DX9_40.dll
2016-12-01 00:11 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) G:\Windows\system32\D3DCompiler_40.dll
2016-12-01 00:11 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) G:\Windows\SysWOW64\D3DCompiler_40.dll
2016-12-01 00:11 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) G:\Windows\system32\d3dx10_40.dll
2016-12-01 00:11 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) G:\Windows\SysWOW64\d3dx10_40.dll
2016-12-01 00:05 - 2016-12-01 00:47 - 00001552 _____ G:\Users\kuureee\Desktop\Sid Meiers Civilization VI.lnk
2016-12-01 00:05 - 2016-12-01 00:05 - 00000000 ____D G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sid Meiers Civilization VI
2016-12-01 00:00 - 2016-12-01 00:07 - 00000000 ____D G:\Program Files (x86)\Sid Meiers Civilization VI
2016-11-16 21:54 - 2016-11-16 21:54 - 00000000 ____D G:\Users\kuureee\Desktop\eve-overview-v0.11.0
2016-11-16 20:59 - 2016-11-16 21:16 - 00000000 ____D G:\Users\kuureee\Documents\EVE
2016-11-16 20:54 - 2016-12-01 00:31 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EVE Launcher
2016-11-16 20:54 - 2016-11-16 20:54 - 00000000 ____D G:\Users\kuureee\AppData\Local\CCP
2016-11-16 20:54 - 2016-11-16 20:54 - 00000000 ____D G:\Users\kuureee\.EVE
2016-11-16 20:54 - 2016-11-16 20:54 - 00000000 ____D G:\EVE
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-12-01 01:12 - 2016-04-12 16:20 - 00000000 ____D G:\FRST
2016-12-01 01:04 - 2015-11-04 23:48 - 00192216 _____ (Malwarebytes) G:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-12-01 01:00 - 2016-05-02 10:43 - 00000000 ____D G:\Users\kuureee\Desktop\New folder (2)
2016-12-01 00:57 - 2009-07-14 05:45 - 00021072 ____H G:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-12-01 00:57 - 2009-07-14 05:45 - 00021072 ____H G:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-12-01 00:53 - 2015-11-11 18:53 - 00000000 ____D G:\Windows\erdnt
2016-12-01 00:52 - 2015-11-04 23:02 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\ViberPC
2016-12-01 00:51 - 2015-11-04 23:37 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\uTorrent
2016-12-01 00:51 - 2009-07-14 06:08 - 00000006 ____H G:\Windows\Tasks\SA.DAT
2016-12-01 00:47 - 2016-10-15 22:24 - 00002883 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive for Business.lnk
2016-12-01 00:47 - 2016-10-15 22:24 - 00002862 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook 2016.lnk
2016-12-01 00:47 - 2016-10-15 22:24 - 00002857 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype for Business 2016.lnk
2016-12-01 00:47 - 2016-10-15 22:24 - 00002833 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk
2016-12-01 00:47 - 2016-10-15 22:24 - 00002811 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk
2016-12-01 00:47 - 2016-10-15 22:24 - 00002805 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk
2016-12-01 00:47 - 2016-10-15 22:24 - 00002785 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access 2016.lnk
2016-12-01 00:47 - 2016-10-15 22:24 - 00002777 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher 2016.lnk
2016-12-01 00:47 - 2016-10-15 22:24 - 00002769 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2016-12-01 00:47 - 2016-09-18 00:17 - 00001164 _____ G:\Users\Public\Desktop\Smart Defrag 5.lnk
2016-12-01 00:47 - 2016-08-20 08:16 - 00000987 _____ G:\Users\kuureee\Desktop\HideWindowPlus.lnk
2016-12-01 00:47 - 2016-07-10 11:10 - 00000588 _____ G:\Users\Public\Desktop\Total War Rome II.lnk
2016-12-01 00:47 - 2016-07-09 14:17 - 00001021 _____ G:\Users\kuureee\Desktop\SpeedFan.lnk
2016-12-01 00:47 - 2016-07-05 15:50 - 00002027 _____ G:\Users\Public\Desktop\Raptr.lnk
2016-12-01 00:47 - 2016-06-25 14:56 - 00001032 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Southpark Stick of Truth.lnk
2016-12-01 00:47 - 2016-06-25 14:56 - 00001014 _____ G:\Users\Public\Desktop\Southpark Stick of Truth.lnk
2016-12-01 00:47 - 2016-05-14 13:45 - 00001104 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Network Stumbler.lnk
2016-12-01 00:47 - 2016-03-19 00:36 - 00001224 _____ G:\Users\Public\Desktop\Wise Auto Shutdown.lnk
2016-12-01 00:47 - 2016-03-05 00:14 - 00001856 _____ G:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2016-12-01 00:47 - 2016-02-14 13:15 - 00002061 _____ G:\Users\kuureee\Desktop\VirusTotal Uploader 2.0.lnk
2016-12-01 00:47 - 2016-02-01 16:43 - 00001357 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\American Truck Simulator.lnk
2016-12-01 00:47 - 2016-02-01 16:43 - 00001339 _____ G:\Users\Public\Desktop\American Truck Simulator.lnk
2016-12-01 00:47 - 2015-11-29 17:46 - 00001127 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\foobar2000.lnk
2016-12-01 00:47 - 2015-11-29 17:46 - 00001039 _____ G:\Users\Public\Desktop\foobar2000.lnk
2016-12-01 00:47 - 2015-11-22 22:31 - 00001205 _____ G:\Users\Public\Desktop\Popcorn Time.lnk
2016-12-01 00:47 - 2015-11-07 20:20 - 00001223 _____ G:\Users\kuureee\AppData\Roaming\Microsoft\Windows\Start Menu\GOM Player.lnk
2016-12-01 00:47 - 2015-11-07 20:20 - 00001193 _____ G:\Users\Public\Desktop\GOM Player.lnk
2016-12-01 00:47 - 2015-11-07 08:04 - 00000917 _____ G:\Users\Public\Desktop\CPUID CPU-Z.lnk
2016-12-01 00:47 - 2015-11-05 00:43 - 00001998 _____ G:\Users\kuureee\Desktop\My.com Game Center.lnk
2016-12-01 00:47 - 2015-11-04 23:57 - 00001015 _____ G:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2016-12-01 00:47 - 2015-11-04 23:47 - 00001110 _____ G:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-12-01 00:47 - 2015-11-04 23:39 - 00002441 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2016-12-01 00:47 - 2015-11-04 23:39 - 00002023 _____ G:\Users\Public\Desktop\Adobe Reader XI.lnk
2016-12-01 00:47 - 2015-11-04 23:39 - 00001155 _____ G:\Users\Public\Desktop\CDBurnerXP.lnk
2016-12-01 00:47 - 2015-11-04 23:39 - 00001119 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
2016-12-01 00:47 - 2015-11-04 23:38 - 00002593 _____ G:\Users\kuureee\Desktop\µTorrent.lnk
2016-12-01 00:47 - 2015-11-04 23:38 - 00002573 _____ G:\Users\kuureee\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2016-12-01 00:47 - 2015-11-04 23:38 - 00000870 _____ G:\Users\Public\Desktop\CCleaner.lnk
2016-12-01 00:47 - 2015-07-18 23:40 - 00001345 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2016-12-01 00:47 - 2015-07-18 23:40 - 00001326 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2016-12-01 00:47 - 2009-07-14 06:01 - 00001218 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk
2016-12-01 00:47 - 2009-07-14 05:57 - 00001523 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-12-01 00:47 - 2009-07-14 05:57 - 00001304 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
2016-12-01 00:47 - 2009-07-14 05:57 - 00001246 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
2016-12-01 00:47 - 2009-07-14 05:54 - 00001210 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
2016-12-01 00:47 - 2009-07-14 05:49 - 00001246 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk
2016-12-01 00:47 - 2009-07-14 04:20 - 00000000 ____D G:\Windows\Branding
2016-12-01 00:43 - 2016-05-06 14:47 - 00000830 _____ G:\Windows\Tasks\Adobe Flash Player Updater.job
2016-12-01 00:41 - 2015-11-05 00:01 - 00000898 _____ G:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-12-01 00:36 - 2016-08-28 20:52 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Warframe
2016-12-01 00:31 - 2016-08-14 21:39 - 00000000 ____D G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Survarium
2016-12-01 00:31 - 2016-07-21 18:12 - 00000000 ____D G:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Tanks
2016-12-01 00:31 - 2016-05-21 18:34 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WarThunder
2016-12-01 00:19 - 2015-11-26 18:59 - 00000000 ____D G:\Users\kuureee\Documents\My Games
2016-12-01 00:14 - 2015-11-05 00:01 - 00000894 _____ G:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-12-01 00:13 - 2016-01-10 18:37 - 00000000 ____D G:\Program Files\SUPERAntiSpyware
2016-12-01 00:12 - 2015-11-04 23:00 - 00000000 ____D G:\ProgramData\Package Cache
2016-11-30 23:58 - 2015-11-26 18:41 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\DAEMON Tools Lite
2016-11-30 23:19 - 2015-11-22 22:31 - 00000000 ____D G:\Users\kuureee\Downloads\PopcornTime
2016-11-30 23:08 - 2015-11-04 23:58 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\TS3Client
2016-11-30 19:03 - 2015-11-29 17:46 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\foobar2000
2016-11-30 08:38 - 2015-11-13 20:31 - 00000000 ____D G:\ProgramData\ProductData
2016-11-29 13:05 - 2015-11-04 22:54 - 00000000 ____D G:\Users\kuureee\AppData\Local\ElevatedDiagnostics
2016-11-28 13:24 - 2009-07-14 06:13 - 00781698 _____ G:\Windows\system32\PerfStringBackup.INI
2016-11-28 13:24 - 2009-07-14 04:20 - 00000000 ____D G:\Windows\inf
2016-11-26 23:52 - 2016-05-06 14:47 - 00000892 _____ G:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job
2016-11-26 23:52 - 2015-11-05 00:00 - 00000000 ____D G:\Windows\SysWOW64\Macromed
2016-11-25 13:01 - 2015-11-07 16:53 - 00000000 ____D G:\Users\kuureee\Documents\ViberDownloads
2016-11-25 11:10 - 2015-11-04 23:14 - 00003850 _____ G:\Windows\System32\Tasks\Opera scheduled Autoupdate 1446675288
2016-11-25 11:10 - 2015-11-04 23:13 - 00000000 ____D G:\Program Files (x86)\Opera
2016-11-24 12:01 - 2009-07-14 06:08 - 00032566 _____ G:\Windows\Tasks\SCHEDLGU.TXT
2016-11-16 20:54 - 2015-11-04 22:36 - 00000000 ____D G:\Users\kuureee
2016-11-15 10:45 - 2015-11-05 00:01 - 00002205 ____H G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-11-08 20:43 - 2016-05-06 14:47 - 00003894 _____ G:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2016-11-08 20:43 - 2016-05-06 14:47 - 00003768 _____ G:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-11-08 20:43 - 2015-11-05 00:00 - 00796352 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\FlashPlayerApp.exe
2016-11-08 20:43 - 2015-11-05 00:00 - 00142528 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-11-08 20:43 - 2015-11-05 00:00 - 00000000 ____D G:\Windows\system32\Macromed
2016-11-08 15:46 - 2016-04-10 00:46 - 00004476 _____ G:\Windows\System32\Tasks\Adobe Acrobat Update Task
2016-11-07 19:21 - 2016-02-13 16:05 - 00000000 ____D G:\Users\kuureee\Desktop\SLIKE
2016-11-05 02:11 - 2016-05-21 18:34 - 00000000 ____D G:\WarThunder
2016-11-01 16:05 - 2016-07-11 09:20 - 00000088 _____ G:\Users\kuureee\Desktop\racun.txt
==================== Files in the root of some directories =======
2016-08-20 08:16 - 2016-08-25 16:18 - 0001708 _____ () G:\Users\kuureee\AppData\Roaming\hidewin.cfg
2016-07-21 19:50 - 2016-07-21 19:50 - 0007635 _____ () G:\Users\kuureee\AppData\Local\Resmon.ResmonCfg
Files to move or delete:
====================
G:\Windows\TEMP\gEFBC.tmp.exe
Some files in TEMP:
====================
G:\Users\kuureee\AppData\Local\Temp\AutoTime51495.exe
G:\Users\kuureee\AppData\Local\Temp\A~NSISu_.exe
G:\Users\kuureee\AppData\Local\Temp\DSETUP.dll
G:\Users\kuureee\AppData\Local\Temp\dsetup32.dll
G:\Users\kuureee\AppData\Local\Temp\DXSETUP.exe
G:\Users\kuureee\AppData\Local\Temp\g5ABD.tmp.exe
G:\Users\kuureee\AppData\Local\Temp\gD347.tmp.exe
G:\Users\kuureee\AppData\Local\Temp\ludashisetup.exe
G:\Users\kuureee\AppData\Local\Temp\setup_1FBD.exe
G:\Users\kuureee\AppData\Local\Temp\ShellHook.dll
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
G:\Windows\system32\winlogon.exe => File is digitally signed
G:\Windows\system32\wininit.exe => File is digitally signed
G:\Windows\SysWOW64\wininit.exe => File is digitally signed
G:\Windows\explorer.exe => File is digitally signed
G:\Windows\SysWOW64\explorer.exe => File is digitally signed
G:\Windows\system32\svchost.exe => File is digitally signed
G:\Windows\SysWOW64\svchost.exe => File is digitally signed
G:\Windows\system32\services.exe => File is digitally signed
G:\Windows\system32\User32.dll => File is digitally signed
G:\Windows\SysWOW64\User32.dll => File is digitally signed
G:\Windows\system32\userinit.exe => File is digitally signed
G:\Windows\SysWOW64\userinit.exe => File is digitally signed
G:\Windows\system32\rpcss.dll => File is digitally signed
G:\Windows\system32\dnsapi.dll => File is digitally signed
G:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
G:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-11-26 12:42
==================== End of FRST.txt ============================
mycity.rs/must-login.png
Dopuna: 01 Dec 2016 1:29
kuureee ::Naime napravih tesko pocetnicku gresku i navuce bedu na svoj komp.
Nekako sam uspo da navucem ono kinesu glupost ,sta je namam pojma,I uz to jos svasta.MB je nasao svasta i uredno pobrisao.Takodje su mi se duplirale neke ikone na deskopu ,nako prozirne ,ali bas kao ikona ne kao koija toga kada je redovno uradis.
Komp mi je zesce usporio kao i net.
Hvala....
+ .txtUnesi sadržajScan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 30-11-2016
Ran by kuureee (administrator) on KUUREEE-PC (01-12-2016 01:12:45)
Running from G:\Users\kuureee\Desktop
Loaded Profiles: kuureee (Available Profiles: kuureee)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Opera)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: geekstogo.com/forum/topic/335081-frst-t.....scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) G:\Windows\System32\atiesrxx.exe
(AMD) G:\Windows\System32\atieclxx.exe
(Microsoft Corporation) G:\Windows\System32\rundll32.exe
(SUPERAntiSpyware.com) G:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Advanced Micro Devices, Inc.) G:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
(Microsoft Corporation) G:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Popcorn Time) G:\Program Files (x86)\Popcorn Time\Updater.exe
() G:\Windows\temp\gEFBC.tmp.exe
(Microsoft Corporation) G:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) G:\Windows\System32\dllhost.exe
(Microsoft Corporation) G:\Windows\System32\alg.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera_crashreporter.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\RunOnce: [wd] => G:\Windows\TEMP\gEFBC.tmp.exe [770560 2016-12-01] () <===== ATTENTION
HKU\S-1-5-21-4139358893-2112486851-1280740277-1000\...\Run: [Viber] => F:\New folder\Viber.exe [51512528 2015-09-27] ()
HKU\S-1-5-21-4139358893-2112486851-1280740277-1000\...\Run: [uTorrent] => G:\Users\kuureee\AppData\Roaming\uTorrent\uTorrent.exe [1995968 2016-11-18] (BitTorrent Inc.)
HKU\S-1-5-21-4139358893-2112486851-1280740277-1000\...\Run: [Lync] => G:\Program Files\Microsoft Office\Office16\lync.exe [26878152 2016-01-13] (Microsoft Corporation)
HKU\S-1-5-21-4139358893-2112486851-1280740277-1000\...\Run: [CCleaner Monitoring] => G:\Program Files\CCleaner\CCleaner64.exe [8944344 2016-09-28] (Piriform Ltd)
ShellIconOverlayIdentifiers: [KzShlobj] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F2} => G:\Program Files\¿ìѹ\X64\KZipShell.dll No File
GroupPolicy: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog9 01 chtbrkg.dll No File
Winsock: Catalog9 02 chtbrkg.dll No File
Winsock: Catalog9 03 chtbrkg.dll No File
Winsock: Catalog9 04 chtbrkg.dll No File
Winsock: Catalog9 05 chtbrkg.dll No File
Winsock: Catalog9 06 chtbrkg.dll No File
Winsock: Catalog9 07 chtbrkg.dll No File
Winsock: Catalog9 08 chtbrkg.dll No File
Winsock: Catalog9 09 chtbrkg.dll No File
Winsock: Catalog9 10 chtbrkg.dll No File
Winsock: Catalog9 21 chtbrkg.dll No File
Winsock: Catalog9-x64 01 chtbrkg.dll No File
Winsock: Catalog9-x64 02 chtbrkg.dll No File
Winsock: Catalog9-x64 03 chtbrkg.dll No File
Winsock: Catalog9-x64 04 chtbrkg.dll No File
Winsock: Catalog9-x64 05 chtbrkg.dll No File
Winsock: Catalog9-x64 06 chtbrkg.dll No File
Winsock: Catalog9-x64 07 chtbrkg.dll No File
Winsock: Catalog9-x64 08 chtbrkg.dll No File
Winsock: Catalog9-x64 09 chtbrkg.dll No File
Winsock: Catalog9-x64 10 chtbrkg.dll No File
Winsock: Catalog9-x64 21 chtbrkg.dll No File
Tcpip\Parameters: [DhcpNameServer] 89.216.1.40 89.216.1.50
Tcpip\..\Interfaces\{01A0C17A-2E49-4034-B5A0-A408A5FAEDE4}: [DhcpNameServer] 89.216.1.40 89.216.1.50
Tcpip\..\Interfaces\{80B82E65-B0D1-4E76-A07F-6259AD41CD27}: [DhcpNameServer] 192.168.42.129
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-4139358893-2112486851-1280740277-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://faststartpage.com/
SearchScopes: HKLM -> DefaultScope value is missing
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> G:\Program Files\Microsoft Office\Office16\OCHelper.dll [2016-01-13] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> G:\Program Files\Java\jre1.8.0_66\bin\ssv.dll [2015-11-04] (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> G:\Program Files\Microsoft Office\Office16\URLREDIR.DLL [2015-07-31] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> G:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL [2016-01-13] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> G:\Program Files\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-11-04] (Oracle Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> G:\Program Files (x86)\Microsoft Office\Office16\OCHelper.dll [2015-07-31] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> G:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2015-11-22] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> G:\Program Files (x86)\Microsoft Office\Office16\URLREDIR.DLL [2015-07-31] (Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> G:\Program Files (x86)\Microsoft Office\Office16\GROOVEEX.DLL [2016-01-13] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> G:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-11-22] (Oracle Corporation)
Handler: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - G:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2016-01-13] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - G:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2016-01-13] (Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - G:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2016-01-13] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - G:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2016-01-13] (Microsoft Corporation)
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.66.2 -> G:\Program Files\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-11-04] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.66.2 -> G:\Program Files\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-11-04] (Oracle Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> G:\PROGRA~1\MICROS~2\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> G:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-11-22] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> G:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-11-22] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> G:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-01-12] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> G:\PROGRA~2\MICROS~1\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> G:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> G:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.2 -> G:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-01-21] (VideoLAN)
FF Plugin-x32: Adobe Reader -> G:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-10-01] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-4139358893-2112486851-1280740277-1000: @my.com/Games -> G:\Users\kuureee\AppData\Local\MyComGames\NPMyComDetector.dll [2015-11-05] (My.com, Inc)
FF Plugin ProgramFiles/Appdata: G:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2016-01-12] (Microsoft Corporation)
Chrome:
=======
CHR DefaultProfile: ChromeDefaultData
CHR Profile: G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2016-12-01] <==== ATTENTION
CHR Extension: (Google Slides) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-06-14]
CHR Extension: (Google Docs) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aohghmighlieiainnegkcijnfilokake [2016-06-14]
CHR Extension: (Google Drive) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-06-14]
CHR Extension: (YouTube) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-06-14]
CHR Extension: (Google Sheets) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-06-14]
CHR Extension: (Google Docs Offline) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-06-15]
CHR Extension: (Chrome Web Store Payments) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-06-14]
CHR Extension: (Gmail) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-06-14]
CHR Extension: (Chrome Media Router) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-10-26]
CHR Profile: G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default [2016-10-28]
CHR Extension: (Google Docs) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-11-14]
CHR Extension: (Google Drive) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-14]
CHR Extension: (YouTube) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-14]
CHR Extension: (Google Search) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-14]
CHR Extension: (Google Sheets) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-11-14]
CHR Extension: (Google Docs Offline) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-21]
CHR Extension: (Chrome Web Store Payments) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-03]
CHR Extension: (Gmail) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-14]
Opera:
=======
OPR Session Restore: -> is enabled.
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; G:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-23] (SUPERAntiSpyware.com)
R2 AMD FUEL Service; G:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [344064 2015-08-04] (Advanced Micro Devices, Inc.) [File not signed]
S2 LiveUpdateSvc; G:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2960672 2016-07-20] (IObit)
S3 Survarium Update Service; G:\Program Files (x86)\Survarium\game\binaries\x86\survarium_service.exe [97880 2016-08-14] ()
R2 Update service; G:\Program Files (x86)\Popcorn Time\Updater.exe [339968 2016-08-26] (Popcorn Time) [File not signed]
R2 WinDefend; G:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 GmSvc; G:\Program Files (x86)\LDSGameCenter\GmSvc.dll [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AODDriver4.3; G:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
R1 dtsoftbus01; G:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2015-11-26] (Disc Soft Ltd)
S3 NSNDIS5; G:\Windows\SysWOW64\NSNDIS5.SYS [17280 2004-03-24] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
R1 SASDIFSV; G:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; G:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R0 SmartDefragDriver; G:\Windows\System32\Drivers\SmartDefragDriver.sys [21360 2016-03-22] (IObit)
S3 vmci; \SystemRoot\system32\DRIVERS\vmci.sys [X]
S3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
NETSVCx32: HpSvc -> no filepath.
NETSVCx32: GmSvc -> G:\Program Files (x86)\LDSGameCenter\GmSvc.dll ==> No File
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-12-01 01:12 - 2016-12-01 01:12 - 00037756 _____ G:\Users\kuureee\Desktop\Addition.txt
2016-12-01 01:11 - 2016-12-01 01:11 - 00000000 ___SD G:\ComboFix
2016-12-01 01:10 - 2016-12-01 01:12 - 00015258 _____ G:\Users\kuureee\Desktop\FRST.txt
2016-12-01 01:07 - 2016-12-01 01:07 - 02411520 _____ (Farbar) G:\Users\kuureee\Desktop\FRST64.exe
2016-12-01 00:54 - 2016-12-01 01:11 - 00000000 ____D G:\Qoobox
2016-12-01 00:47 - 2016-12-01 00:47 - 00000080 _____ G:\Users\kuureee\AppData\Roaming\Microsoft\Windows\Start Menu\¿ìÑ1.lnk
2016-12-01 00:40 - 2016-12-01 00:40 - 00000000 ____D G:\ProgramData\Microsoft\Windows\Start Menu\Programs\鲁大师游戏库
2016-12-01 00:38 - 2016-12-01 00:38 - 05659307 ____R (Swearware) G:\Users\kuureee\Desktop\ComboFix.exe
2016-12-01 00:35 - 2016-12-01 00:42 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\KuaiZip
2016-12-01 00:35 - 2016-12-01 00:35 - 00000847 _____ G:\Users\kuureee\AppData\Roaming\Microsoft\Windows\Start Menu\¿ìѹ.lnk
2016-12-01 00:35 - 2016-12-01 00:35 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\Softlink
2016-12-01 00:33 - 2016-12-01 00:33 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\LDSGameCenter
2016-12-01 00:32 - 2016-12-01 00:32 - 00000000 __SHD G:\Users\kuureee\AppData\Local\svchost
2016-12-01 00:32 - 2016-12-01 00:32 - 00000000 ____D G:\Users\Public\Thunder Network
2016-12-01 00:32 - 2016-12-01 00:32 - 00000000 ____D G:\ProgramData\Thunder Network
2016-12-01 00:32 - 2016-11-09 15:55 - 00778752 _____ G:\Windows\system32\chtbrkg.dll
2016-12-01 00:32 - 2016-11-09 15:55 - 00590848 _____ G:\Windows\SysWOW64\chtbrkg.dll
2016-12-01 00:31 - 2016-12-01 01:13 - 00016718 _____ G:\Windows\System32\Tasks\40289_73307-2937
2016-12-01 00:31 - 2016-12-01 00:31 - 00001986 ___RS G:\Users\Public\Desktop\Survаrium.lnk
2016-12-01 00:31 - 2016-12-01 00:31 - 00001834 ___RS G:\Users\Public\Desktop\Wоrld of Tanks.lnk
2016-12-01 00:31 - 2016-12-01 00:31 - 00001796 ___RS G:\Users\kuureee\Desktop\ЕVE Launchеr.lnk
2016-12-01 00:31 - 2016-12-01 00:31 - 00001793 ___RS G:\Users\Public\Desktop\WаrThundеr.lnk
2016-12-01 00:31 - 2016-12-01 00:31 - 00001323 ___RS G:\Users\kuureee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Intеrnet Ехplorer.lnk
2016-12-01 00:31 - 2016-12-01 00:31 - 00001265 ___RS G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ореra.lnk
2016-12-01 00:31 - 2016-12-01 00:31 - 00001151 ___RS G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gоoglе Chrome.lnk
2016-12-01 00:31 - 2016-12-01 00:31 - 00001126 ___RS G:\ProgramData\Microsoft\Windows\Start Menu\Programs\zс1h3r7о5m4e.lnk
2016-12-01 00:31 - 2016-12-01 00:31 - 00000000 ___HD G:\ProgramData\40289_73307-2937
2016-12-01 00:31 - 2016-12-01 00:31 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\SPI
2016-12-01 00:14 - 2016-12-01 00:52 - 00000000 ____D G:\Users\kuureee\AppData\LocalLow\uTorrent
2016-12-01 00:11 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) G:\Windows\system32\D3DX9_40.dll
2016-12-01 00:11 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) G:\Windows\SysWOW64\D3DX9_40.dll
2016-12-01 00:11 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) G:\Windows\system32\D3DCompiler_40.dll
2016-12-01 00:11 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) G:\Windows\SysWOW64\D3DCompiler_40.dll
2016-12-01 00:11 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) G:\Windows\system32\d3dx10_40.dll
2016-12-01 00:11 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) G:\Windows\SysWOW64\d3dx10_40.dll
2016-12-01 00:05 - 2016-12-01 00:47 - 00001552 _____ G:\Users\kuureee\Desktop\Sid Meiers Civilization VI.lnk
2016-12-01 00:05 - 2016-12-01 00:05 - 00000000 ____D G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sid Meiers Civilization VI
2016-12-01 00:00 - 2016-12-01 00:07 - 00000000 ____D G:\Program Files (x86)\Sid Meiers Civilization VI
2016-11-16 21:54 - 2016-11-16 21:54 - 00000000 ____D G:\Users\kuureee\Desktop\eve-overview-v0.11.0
2016-11-16 20:59 - 2016-11-16 21:16 - 00000000 ____D G:\Users\kuureee\Documents\EVE
2016-11-16 20:54 - 2016-12-01 00:31 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EVE Launcher
2016-11-16 20:54 - 2016-11-16 20:54 - 00000000 ____D G:\Users\kuureee\AppData\Local\CCP
2016-11-16 20:54 - 2016-11-16 20:54 - 00000000 ____D G:\Users\kuureee\.EVE
2016-11-16 20:54 - 2016-11-16 20:54 - 00000000 ____D G:\EVE
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-12-01 01:12 - 2016-04-12 16:20 - 00000000 ____D G:\FRST
2016-12-01 01:04 - 2015-11-04 23:48 - 00192216 _____ (Malwarebytes) G:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-12-01 01:00 - 2016-05-02 10:43 - 00000000 ____D G:\Users\kuureee\Desktop\New folder (2)
2016-12-01 00:57 - 2009-07-14 05:45 - 00021072 ____H G:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-12-01 00:57 - 2009-07-14 05:45 - 00021072 ____H G:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-12-01 00:53 - 2015-11-11 18:53 - 00000000 ____D G:\Windows\erdnt
2016-12-01 00:52 - 2015-11-04 23:02 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\ViberPC
2016-12-01 00:51 - 2015-11-04 23:37 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\uTorrent
2016-12-01 00:51 - 2009-07-14 06:08 - 00000006 ____H G:\Windows\Tasks\SA.DAT
2016-12-01 00:47 - 2016-10-15 22:24 - 00002883 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive for Business.lnk
2016-12-01 00:47 - 2016-10-15 22:24 - 00002862 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook 2016.lnk
2016-12-01 00:47 - 2016-10-15 22:24 - 00002857 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype for Business 2016.lnk
2016-12-01 00:47 - 2016-10-15 22:24 - 00002833 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk
2016-12-01 00:47 - 2016-10-15 22:24 - 00002811 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk
2016-12-01 00:47 - 2016-10-15 22:24 - 00002805 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk
2016-12-01 00:47 - 2016-10-15 22:24 - 00002785 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access 2016.lnk
2016-12-01 00:47 - 2016-10-15 22:24 - 00002777 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher 2016.lnk
2016-12-01 00:47 - 2016-10-15 22:24 - 00002769 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2016-12-01 00:47 - 2016-09-18 00:17 - 00001164 _____ G:\Users\Public\Desktop\Smart Defrag 5.lnk
2016-12-01 00:47 - 2016-08-20 08:16 - 00000987 _____ G:\Users\kuureee\Desktop\HideWindowPlus.lnk
2016-12-01 00:47 - 2016-07-10 11:10 - 00000588 _____ G:\Users\Public\Desktop\Total War Rome II.lnk
2016-12-01 00:47 - 2016-07-09 14:17 - 00001021 _____ G:\Users\kuureee\Desktop\SpeedFan.lnk
2016-12-01 00:47 - 2016-07-05 15:50 - 00002027 _____ G:\Users\Public\Desktop\Raptr.lnk
2016-12-01 00:47 - 2016-06-25 14:56 - 00001032 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Southpark Stick of Truth.lnk
2016-12-01 00:47 - 2016-06-25 14:56 - 00001014 _____ G:\Users\Public\Desktop\Southpark Stick of Truth.lnk
2016-12-01 00:47 - 2016-05-14 13:45 - 00001104 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Network Stumbler.lnk
2016-12-01 00:47 - 2016-03-19 00:36 - 00001224 _____ G:\Users\Public\Desktop\Wise Auto Shutdown.lnk
2016-12-01 00:47 - 2016-03-05 00:14 - 00001856 _____ G:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2016-12-01 00:47 - 2016-02-14 13:15 - 00002061 _____ G:\Users\kuureee\Desktop\VirusTotal Uploader 2.0.lnk
2016-12-01 00:47 - 2016-02-01 16:43 - 00001357 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\American Truck Simulator.lnk
2016-12-01 00:47 - 2016-02-01 16:43 - 00001339 _____ G:\Users\Public\Desktop\American Truck Simulator.lnk
2016-12-01 00:47 - 2015-11-29 17:46 - 00001127 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\foobar2000.lnk
2016-12-01 00:47 - 2015-11-29 17:46 - 00001039 _____ G:\Users\Public\Desktop\foobar2000.lnk
2016-12-01 00:47 - 2015-11-22 22:31 - 00001205 _____ G:\Users\Public\Desktop\Popcorn Time.lnk
2016-12-01 00:47 - 2015-11-07 20:20 - 00001223 _____ G:\Users\kuureee\AppData\Roaming\Microsoft\Windows\Start Menu\GOM Player.lnk
2016-12-01 00:47 - 2015-11-07 20:20 - 00001193 _____ G:\Users\Public\Desktop\GOM Player.lnk
2016-12-01 00:47 - 2015-11-07 08:04 - 00000917 _____ G:\Users\Public\Desktop\CPUID CPU-Z.lnk
2016-12-01 00:47 - 2015-11-05 00:43 - 00001998 _____ G:\Users\kuureee\Desktop\My.com Game Center.lnk
2016-12-01 00:47 - 2015-11-04 23:57 - 00001015 _____ G:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2016-12-01 00:47 - 2015-11-04 23:47 - 00001110 _____ G:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-12-01 00:47 - 2015-11-04 23:39 - 00002441 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2016-12-01 00:47 - 2015-11-04 23:39 - 00002023 _____ G:\Users\Public\Desktop\Adobe Reader XI.lnk
2016-12-01 00:47 - 2015-11-04 23:39 - 00001155 _____ G:\Users\Public\Desktop\CDBurnerXP.lnk
2016-12-01 00:47 - 2015-11-04 23:39 - 00001119 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
2016-12-01 00:47 - 2015-11-04 23:38 - 00002593 _____ G:\Users\kuureee\Desktop\µTorrent.lnk
2016-12-01 00:47 - 2015-11-04 23:38 - 00002573 _____ G:\Users\kuureee\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2016-12-01 00:47 - 2015-11-04 23:38 - 00000870 _____ G:\Users\Public\Desktop\CCleaner.lnk
2016-12-01 00:47 - 2015-07-18 23:40 - 00001345 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2016-12-01 00:47 - 2015-07-18 23:40 - 00001326 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2016-12-01 00:47 - 2009-07-14 06:01 - 00001218 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk
2016-12-01 00:47 - 2009-07-14 05:57 - 00001523 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-12-01 00:47 - 2009-07-14 05:57 - 00001304 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
2016-12-01 00:47 - 2009-07-14 05:57 - 00001246 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
2016-12-01 00:47 - 2009-07-14 05:54 - 00001210 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
2016-12-01 00:47 - 2009-07-14 05:49 - 00001246 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk
2016-12-01 00:47 - 2009-07-14 04:20 - 00000000 ____D G:\Windows\Branding
2016-12-01 00:43 - 2016-05-06 14:47 - 00000830 _____ G:\Windows\Tasks\Adobe Flash Player Updater.job
2016-12-01 00:41 - 2015-11-05 00:01 - 00000898 _____ G:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-12-01 00:36 - 2016-08-28 20:52 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Warframe
2016-12-01 00:31 - 2016-08-14 21:39 - 00000000 ____D G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Survarium
2016-12-01 00:31 - 2016-07-21 18:12 - 00000000 ____D G:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Tanks
2016-12-01 00:31 - 2016-05-21 18:34 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WarThunder
2016-12-01 00:19 - 2015-11-26 18:59 - 00000000 ____D G:\Users\kuureee\Documents\My Games
2016-12-01 00:14 - 2015-11-05 00:01 - 00000894 _____ G:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-12-01 00:13 - 2016-01-10 18:37 - 00000000 ____D G:\Program Files\SUPERAntiSpyware
2016-12-01 00:12 - 2015-11-04 23:00 - 00000000 ____D G:\ProgramData\Package Cache
2016-11-30 23:58 - 2015-11-26 18:41 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\DAEMON Tools Lite
2016-11-30 23:19 - 2015-11-22 22:31 - 00000000 ____D G:\Users\kuureee\Downloads\PopcornTime
2016-11-30 23:08 - 2015-11-04 23:58 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\TS3Client
2016-11-30 19:03 - 2015-11-29 17:46 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\foobar2000
2016-11-30 08:38 - 2015-11-13 20:31 - 00000000 ____D G:\ProgramData\ProductData
2016-11-29 13:05 - 2015-11-04 22:54 - 00000000 ____D G:\Users\kuureee\AppData\Local\ElevatedDiagnostics
2016-11-28 13:24 - 2009-07-14 06:13 - 00781698 _____ G:\Windows\system32\PerfStringBackup.INI
2016-11-28 13:24 - 2009-07-14 04:20 - 00000000 ____D G:\Windows\inf
2016-11-26 23:52 - 2016-05-06 14:47 - 00000892 _____ G:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job
2016-11-26 23:52 - 2015-11-05 00:00 - 00000000 ____D G:\Windows\SysWOW64\Macromed
2016-11-25 13:01 - 2015-11-07 16:53 - 00000000 ____D G:\Users\kuureee\Documents\ViberDownloads
2016-11-25 11:10 - 2015-11-04 23:14 - 00003850 _____ G:\Windows\System32\Tasks\Opera scheduled Autoupdate 1446675288
2016-11-25 11:10 - 2015-11-04 23:13 - 00000000 ____D G:\Program Files (x86)\Opera
2016-11-24 12:01 - 2009-07-14 06:08 - 00032566 _____ G:\Windows\Tasks\SCHEDLGU.TXT
2016-11-16 20:54 - 2015-11-04 22:36 - 00000000 ____D G:\Users\kuureee
2016-11-15 10:45 - 2015-11-05 00:01 - 00002205 ____H G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-11-08 20:43 - 2016-05-06 14:47 - 00003894 _____ G:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2016-11-08 20:43 - 2016-05-06 14:47 - 00003768 _____ G:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-11-08 20:43 - 2015-11-05 00:00 - 00796352 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\FlashPlayerApp.exe
2016-11-08 20:43 - 2015-11-05 00:00 - 00142528 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-11-08 20:43 - 2015-11-05 00:00 - 00000000 ____D G:\Windows\system32\Macromed
2016-11-08 15:46 - 2016-04-10 00:46 - 00004476 _____ G:\Windows\System32\Tasks\Adobe Acrobat Update Task
2016-11-07 19:21 - 2016-02-13 16:05 - 00000000 ____D G:\Users\kuureee\Desktop\SLIKE
2016-11-05 02:11 - 2016-05-21 18:34 - 00000000 ____D G:\WarThunder
2016-11-01 16:05 - 2016-07-11 09:20 - 00000088 _____ G:\Users\kuureee\Desktop\racun.txt
==================== Files in the root of some directories =======
2016-08-20 08:16 - 2016-08-25 16:18 - 0001708 _____ () G:\Users\kuureee\AppData\Roaming\hidewin.cfg
2016-07-21 19:50 - 2016-07-21 19:50 - 0007635 _____ () G:\Users\kuureee\AppData\Local\Resmon.ResmonCfg
Files to move or delete:
====================
G:\Windows\TEMP\gEFBC.tmp.exe
Some files in TEMP:
====================
G:\Users\kuureee\AppData\Local\Temp\AutoTime51495.exe
G:\Users\kuureee\AppData\Local\Temp\A~NSISu_.exe
G:\Users\kuureee\AppData\Local\Temp\DSETUP.dll
G:\Users\kuureee\AppData\Local\Temp\dsetup32.dll
G:\Users\kuureee\AppData\Local\Temp\DXSETUP.exe
G:\Users\kuureee\AppData\Local\Temp\g5ABD.tmp.exe
G:\Users\kuureee\AppData\Local\Temp\gD347.tmp.exe
G:\Users\kuureee\AppData\Local\Temp\ludashisetup.exe
G:\Users\kuureee\AppData\Local\Temp\setup_1FBD.exe
G:\Users\kuureee\AppData\Local\Temp\ShellHook.dll
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
G:\Windows\system32\winlogon.exe => File is digitally signed
G:\Windows\system32\wininit.exe => File is digitally signed
G:\Windows\SysWOW64\wininit.exe => File is digitally signed
G:\Windows\explorer.exe => File is digitally signed
G:\Windows\SysWOW64\explorer.exe => File is digitally signed
G:\Windows\system32\svchost.exe => File is digitally signed
G:\Windows\SysWOW64\svchost.exe => File is digitally signed
G:\Windows\system32\services.exe => File is digitally signed
G:\Windows\system32\User32.dll => File is digitally signed
G:\Windows\SysWOW64\User32.dll => File is digitally signed
G:\Windows\system32\userinit.exe => File is digitally signed
G:\Windows\SysWOW64\userinit.exe => File is digitally signed
G:\Windows\system32\rpcss.dll => File is digitally signed
G:\Windows\system32\dnsapi.dll => File is digitally signed
G:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
G:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-11-26 12:42
==================== End of FRST.txt ============================
mycity.rs/must-login.png
Evo logo i od MBM
mycity.rs/must-login.png
Dopuna: 01 Dec 2016 2:04
kuureee ::Napisano: 01 Dec 2016 1:18
Naime napravih tesko pocetnicku gresku i navuce bedu na svoj komp.
Nekako sam uspo da navucem ono kinesu glupost ,sta je namam pojma,I uz to jos svasta.MB je nasao svasta i uredno pobrisao.Takodje su mi se duplirale neke ikone na deskopu ,nako prozirne ,ali bas kao ikona ne kao koija toga kada je redovno uradis.Takodje ne mogu da otvorim myComputer ,jako sporo mi ocitava.
Komp mi je zesce usporio kao i net.
Hvala....
+ .txtUnesi sadržajScan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 30-11-2016
Ran by kuureee (administrator) on KUUREEE-PC (01-12-2016 01:12:45)
Running from G:\Users\kuureee\Desktop
Loaded Profiles: kuureee (Available Profiles: kuureee)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Opera)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: geekstogo.com/forum/topic/335081-frst-t.....scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) G:\Windows\System32\atiesrxx.exe
(AMD) G:\Windows\System32\atieclxx.exe
(Microsoft Corporation) G:\Windows\System32\rundll32.exe
(SUPERAntiSpyware.com) G:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Advanced Micro Devices, Inc.) G:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
(Microsoft Corporation) G:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Popcorn Time) G:\Program Files (x86)\Popcorn Time\Updater.exe
() G:\Windows\temp\gEFBC.tmp.exe
(Microsoft Corporation) G:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) G:\Windows\System32\dllhost.exe
(Microsoft Corporation) G:\Windows\System32\alg.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera_crashreporter.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\RunOnce: [wd] => G:\Windows\TEMP\gEFBC.tmp.exe [770560 2016-12-01] () <===== ATTENTION
HKU\S-1-5-21-4139358893-2112486851-1280740277-1000\...\Run: [Viber] => F:\New folder\Viber.exe [51512528 2015-09-27] ()
HKU\S-1-5-21-4139358893-2112486851-1280740277-1000\...\Run: [uTorrent] => G:\Users\kuureee\AppData\Roaming\uTorrent\uTorrent.exe [1995968 2016-11-18] (BitTorrent Inc.)
HKU\S-1-5-21-4139358893-2112486851-1280740277-1000\...\Run: [Lync] => G:\Program Files\Microsoft Office\Office16\lync.exe [26878152 2016-01-13] (Microsoft Corporation)
HKU\S-1-5-21-4139358893-2112486851-1280740277-1000\...\Run: [CCleaner Monitoring] => G:\Program Files\CCleaner\CCleaner64.exe [8944344 2016-09-28] (Piriform Ltd)
ShellIconOverlayIdentifiers: [KzShlobj] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F2} => G:\Program Files\¿ìѹ\X64\KZipShell.dll No File
GroupPolicy: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog9 01 chtbrkg.dll No File
Winsock: Catalog9 02 chtbrkg.dll No File
Winsock: Catalog9 03 chtbrkg.dll No File
Winsock: Catalog9 04 chtbrkg.dll No File
Winsock: Catalog9 05 chtbrkg.dll No File
Winsock: Catalog9 06 chtbrkg.dll No File
Winsock: Catalog9 07 chtbrkg.dll No File
Winsock: Catalog9 08 chtbrkg.dll No File
Winsock: Catalog9 09 chtbrkg.dll No File
Winsock: Catalog9 10 chtbrkg.dll No File
Winsock: Catalog9 21 chtbrkg.dll No File
Winsock: Catalog9-x64 01 chtbrkg.dll No File
Winsock: Catalog9-x64 02 chtbrkg.dll No File
Winsock: Catalog9-x64 03 chtbrkg.dll No File
Winsock: Catalog9-x64 04 chtbrkg.dll No File
Winsock: Catalog9-x64 05 chtbrkg.dll No File
Winsock: Catalog9-x64 06 chtbrkg.dll No File
Winsock: Catalog9-x64 07 chtbrkg.dll No File
Winsock: Catalog9-x64 08 chtbrkg.dll No File
Winsock: Catalog9-x64 09 chtbrkg.dll No File
Winsock: Catalog9-x64 10 chtbrkg.dll No File
Winsock: Catalog9-x64 21 chtbrkg.dll No File
Tcpip\Parameters: [DhcpNameServer] 89.216.1.40 89.216.1.50
Tcpip\..\Interfaces\{01A0C17A-2E49-4034-B5A0-A408A5FAEDE4}: [DhcpNameServer] 89.216.1.40 89.216.1.50
Tcpip\..\Interfaces\{80B82E65-B0D1-4E76-A07F-6259AD41CD27}: [DhcpNameServer] 192.168.42.129
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-4139358893-2112486851-1280740277-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://faststartpage.com/
SearchScopes: HKLM -> DefaultScope value is missing
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> G:\Program Files\Microsoft Office\Office16\OCHelper.dll [2016-01-13] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> G:\Program Files\Java\jre1.8.0_66\bin\ssv.dll [2015-11-04] (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> G:\Program Files\Microsoft Office\Office16\URLREDIR.DLL [2015-07-31] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> G:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL [2016-01-13] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> G:\Program Files\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-11-04] (Oracle Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> G:\Program Files (x86)\Microsoft Office\Office16\OCHelper.dll [2015-07-31] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> G:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2015-11-22] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> G:\Program Files (x86)\Microsoft Office\Office16\URLREDIR.DLL [2015-07-31] (Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> G:\Program Files (x86)\Microsoft Office\Office16\GROOVEEX.DLL [2016-01-13] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> G:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-11-22] (Oracle Corporation)
Handler: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - G:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2016-01-13] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - G:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2016-01-13] (Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - G:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2016-01-13] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - G:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2016-01-13] (Microsoft Corporation)
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.66.2 -> G:\Program Files\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-11-04] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.66.2 -> G:\Program Files\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-11-04] (Oracle Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> G:\PROGRA~1\MICROS~2\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> G:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-11-22] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> G:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-11-22] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> G:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-01-12] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> G:\PROGRA~2\MICROS~1\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> G:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> G:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.2 -> G:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-01-21] (VideoLAN)
FF Plugin-x32: Adobe Reader -> G:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-10-01] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-4139358893-2112486851-1280740277-1000: @my.com/Games -> G:\Users\kuureee\AppData\Local\MyComGames\NPMyComDetector.dll [2015-11-05] (My.com, Inc)
FF Plugin ProgramFiles/Appdata: G:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2016-01-12] (Microsoft Corporation)
Chrome:
=======
CHR DefaultProfile: ChromeDefaultData
CHR Profile: G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2016-12-01] <==== ATTENTION
CHR Extension: (Google Slides) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-06-14]
CHR Extension: (Google Docs) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aohghmighlieiainnegkcijnfilokake [2016-06-14]
CHR Extension: (Google Drive) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-06-14]
CHR Extension: (YouTube) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-06-14]
CHR Extension: (Google Sheets) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-06-14]
CHR Extension: (Google Docs Offline) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-06-15]
CHR Extension: (Chrome Web Store Payments) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-06-14]
CHR Extension: (Gmail) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-06-14]
CHR Extension: (Chrome Media Router) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-10-26]
CHR Profile: G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default [2016-10-28]
CHR Extension: (Google Docs) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-11-14]
CHR Extension: (Google Drive) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-14]
CHR Extension: (YouTube) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-14]
CHR Extension: (Google Search) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-14]
CHR Extension: (Google Sheets) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-11-14]
CHR Extension: (Google Docs Offline) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-21]
CHR Extension: (Chrome Web Store Payments) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-03]
CHR Extension: (Gmail) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-14]
Opera:
=======
OPR Session Restore: -> is enabled.
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; G:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-23] (SUPERAntiSpyware.com)
R2 AMD FUEL Service; G:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [344064 2015-08-04] (Advanced Micro Devices, Inc.) [File not signed]
S2 LiveUpdateSvc; G:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2960672 2016-07-20] (IObit)
S3 Survarium Update Service; G:\Program Files (x86)\Survarium\game\binaries\x86\survarium_service.exe [97880 2016-08-14] ()
R2 Update service; G:\Program Files (x86)\Popcorn Time\Updater.exe [339968 2016-08-26] (Popcorn Time) [File not signed]
R2 WinDefend; G:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 GmSvc; G:\Program Files (x86)\LDSGameCenter\GmSvc.dll [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AODDriver4.3; G:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
R1 dtsoftbus01; G:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2015-11-26] (Disc Soft Ltd)
S3 NSNDIS5; G:\Windows\SysWOW64\NSNDIS5.SYS [17280 2004-03-24] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
R1 SASDIFSV; G:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; G:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R0 SmartDefragDriver; G:\Windows\System32\Drivers\SmartDefragDriver.sys [21360 2016-03-22] (IObit)
S3 vmci; \SystemRoot\system32\DRIVERS\vmci.sys [X]
S3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
NETSVCx32: HpSvc -> no filepath.
NETSVCx32: GmSvc -> G:\Program Files (x86)\LDSGameCenter\GmSvc.dll ==> No File
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-12-01 01:12 - 2016-12-01 01:12 - 00037756 _____ G:\Users\kuureee\Desktop\Addition.txt
2016-12-01 01:11 - 2016-12-01 01:11 - 00000000 ___SD G:\ComboFix
2016-12-01 01:10 - 2016-12-01 01:12 - 00015258 _____ G:\Users\kuureee\Desktop\FRST.txt
2016-12-01 01:07 - 2016-12-01 01:07 - 02411520 _____ (Farbar) G:\Users\kuureee\Desktop\FRST64.exe
2016-12-01 00:54 - 2016-12-01 01:11 - 00000000 ____D G:\Qoobox
2016-12-01 00:47 - 2016-12-01 00:47 - 00000080 _____ G:\Users\kuureee\AppData\Roaming\Microsoft\Windows\Start Menu\¿ìÑ1.lnk
2016-12-01 00:40 - 2016-12-01 00:40 - 00000000 ____D G:\ProgramData\Microsoft\Windows\Start Menu\Programs\鲁大师游戏库
2016-12-01 00:38 - 2016-12-01 00:38 - 05659307 ____R (Swearware) G:\Users\kuureee\Desktop\ComboFix.exe
2016-12-01 00:35 - 2016-12-01 00:42 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\KuaiZip
2016-12-01 00:35 - 2016-12-01 00:35 - 00000847 _____ G:\Users\kuureee\AppData\Roaming\Microsoft\Windows\Start Menu\¿ìѹ.lnk
2016-12-01 00:35 - 2016-12-01 00:35 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\Softlink
2016-12-01 00:33 - 2016-12-01 00:33 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\LDSGameCenter
2016-12-01 00:32 - 2016-12-01 00:32 - 00000000 __SHD G:\Users\kuureee\AppData\Local\svchost
2016-12-01 00:32 - 2016-12-01 00:32 - 00000000 ____D G:\Users\Public\Thunder Network
2016-12-01 00:32 - 2016-12-01 00:32 - 00000000 ____D G:\ProgramData\Thunder Network
2016-12-01 00:32 - 2016-11-09 15:55 - 00778752 _____ G:\Windows\system32\chtbrkg.dll
2016-12-01 00:32 - 2016-11-09 15:55 - 00590848 _____ G:\Windows\SysWOW64\chtbrkg.dll
2016-12-01 00:31 - 2016-12-01 01:13 - 00016718 _____ G:\Windows\System32\Tasks\40289_73307-2937
2016-12-01 00:31 - 2016-12-01 00:31 - 00001986 ___RS G:\Users\Public\Desktop\Survаrium.lnk
2016-12-01 00:31 - 2016-12-01 00:31 - 00001834 ___RS G:\Users\Public\Desktop\Wоrld of Tanks.lnk
2016-12-01 00:31 - 2016-12-01 00:31 - 00001796 ___RS G:\Users\kuureee\Desktop\ЕVE Launchеr.lnk
2016-12-01 00:31 - 2016-12-01 00:31 - 00001793 ___RS G:\Users\Public\Desktop\WаrThundеr.lnk
2016-12-01 00:31 - 2016-12-01 00:31 - 00001323 ___RS G:\Users\kuureee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Intеrnet Ехplorer.lnk
2016-12-01 00:31 - 2016-12-01 00:31 - 00001265 ___RS G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ореra.lnk
2016-12-01 00:31 - 2016-12-01 00:31 - 00001151 ___RS G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gоoglе Chrome.lnk
2016-12-01 00:31 - 2016-12-01 00:31 - 00001126 ___RS G:\ProgramData\Microsoft\Windows\Start Menu\Programs\zс1h3r7о5m4e.lnk
2016-12-01 00:31 - 2016-12-01 00:31 - 00000000 ___HD G:\ProgramData\40289_73307-2937
2016-12-01 00:31 - 2016-12-01 00:31 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\SPI
2016-12-01 00:14 - 2016-12-01 00:52 - 00000000 ____D G:\Users\kuureee\AppData\LocalLow\uTorrent
2016-12-01 00:11 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) G:\Windows\system32\D3DX9_40.dll
2016-12-01 00:11 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) G:\Windows\SysWOW64\D3DX9_40.dll
2016-12-01 00:11 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) G:\Windows\system32\D3DCompiler_40.dll
2016-12-01 00:11 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) G:\Windows\SysWOW64\D3DCompiler_40.dll
2016-12-01 00:11 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) G:\Windows\system32\d3dx10_40.dll
2016-12-01 00:11 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) G:\Windows\SysWOW64\d3dx10_40.dll
2016-12-01 00:05 - 2016-12-01 00:47 - 00001552 _____ G:\Users\kuureee\Desktop\Sid Meiers Civilization VI.lnk
2016-12-01 00:05 - 2016-12-01 00:05 - 00000000 ____D G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sid Meiers Civilization VI
2016-12-01 00:00 - 2016-12-01 00:07 - 00000000 ____D G:\Program Files (x86)\Sid Meiers Civilization VI
2016-11-16 21:54 - 2016-11-16 21:54 - 00000000 ____D G:\Users\kuureee\Desktop\eve-overview-v0.11.0
2016-11-16 20:59 - 2016-11-16 21:16 - 00000000 ____D G:\Users\kuureee\Documents\EVE
2016-11-16 20:54 - 2016-12-01 00:31 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EVE Launcher
2016-11-16 20:54 - 2016-11-16 20:54 - 00000000 ____D G:\Users\kuureee\AppData\Local\CCP
2016-11-16 20:54 - 2016-11-16 20:54 - 00000000 ____D G:\Users\kuureee\.EVE
2016-11-16 20:54 - 2016-11-16 20:54 - 00000000 ____D G:\EVE
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-12-01 01:12 - 2016-04-12 16:20 - 00000000 ____D G:\FRST
2016-12-01 01:04 - 2015-11-04 23:48 - 00192216 _____ (Malwarebytes) G:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-12-01 01:00 - 2016-05-02 10:43 - 00000000 ____D G:\Users\kuureee\Desktop\New folder (2)
2016-12-01 00:57 - 2009-07-14 05:45 - 00021072 ____H G:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-12-01 00:57 - 2009-07-14 05:45 - 00021072 ____H G:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-12-01 00:53 - 2015-11-11 18:53 - 00000000 ____D G:\Windows\erdnt
2016-12-01 00:52 - 2015-11-04 23:02 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\ViberPC
2016-12-01 00:51 - 2015-11-04 23:37 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\uTorrent
2016-12-01 00:51 - 2009-07-14 06:08 - 00000006 ____H G:\Windows\Tasks\SA.DAT
2016-12-01 00:47 - 2016-10-15 22:24 - 00002883 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive for Business.lnk
2016-12-01 00:47 - 2016-10-15 22:24 - 00002862 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook 2016.lnk
2016-12-01 00:47 - 2016-10-15 22:24 - 00002857 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype for Business 2016.lnk
2016-12-01 00:47 - 2016-10-15 22:24 - 00002833 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk
2016-12-01 00:47 - 2016-10-15 22:24 - 00002811 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk
2016-12-01 00:47 - 2016-10-15 22:24 - 00002805 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk
2016-12-01 00:47 - 2016-10-15 22:24 - 00002785 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access 2016.lnk
2016-12-01 00:47 - 2016-10-15 22:24 - 00002777 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher 2016.lnk
2016-12-01 00:47 - 2016-10-15 22:24 - 00002769 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2016-12-01 00:47 - 2016-09-18 00:17 - 00001164 _____ G:\Users\Public\Desktop\Smart Defrag 5.lnk
2016-12-01 00:47 - 2016-08-20 08:16 - 00000987 _____ G:\Users\kuureee\Desktop\HideWindowPlus.lnk
2016-12-01 00:47 - 2016-07-10 11:10 - 00000588 _____ G:\Users\Public\Desktop\Total War Rome II.lnk
2016-12-01 00:47 - 2016-07-09 14:17 - 00001021 _____ G:\Users\kuureee\Desktop\SpeedFan.lnk
2016-12-01 00:47 - 2016-07-05 15:50 - 00002027 _____ G:\Users\Public\Desktop\Raptr.lnk
2016-12-01 00:47 - 2016-06-25 14:56 - 00001032 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Southpark Stick of Truth.lnk
2016-12-01 00:47 - 2016-06-25 14:56 - 00001014 _____ G:\Users\Public\Desktop\Southpark Stick of Truth.lnk
2016-12-01 00:47 - 2016-05-14 13:45 - 00001104 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Network Stumbler.lnk
2016-12-01 00:47 - 2016-03-19 00:36 - 00001224 _____ G:\Users\Public\Desktop\Wise Auto Shutdown.lnk
2016-12-01 00:47 - 2016-03-05 00:14 - 00001856 _____ G:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2016-12-01 00:47 - 2016-02-14 13:15 - 00002061 _____ G:\Users\kuureee\Desktop\VirusTotal Uploader 2.0.lnk
2016-12-01 00:47 - 2016-02-01 16:43 - 00001357 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\American Truck Simulator.lnk
2016-12-01 00:47 - 2016-02-01 16:43 - 00001339 _____ G:\Users\Public\Desktop\American Truck Simulator.lnk
2016-12-01 00:47 - 2015-11-29 17:46 - 00001127 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\foobar2000.lnk
2016-12-01 00:47 - 2015-11-29 17:46 - 00001039 _____ G:\Users\Public\Desktop\foobar2000.lnk
2016-12-01 00:47 - 2015-11-22 22:31 - 00001205 _____ G:\Users\Public\Desktop\Popcorn Time.lnk
2016-12-01 00:47 - 2015-11-07 20:20 - 00001223 _____ G:\Users\kuureee\AppData\Roaming\Microsoft\Windows\Start Menu\GOM Player.lnk
2016-12-01 00:47 - 2015-11-07 20:20 - 00001193 _____ G:\Users\Public\Desktop\GOM Player.lnk
2016-12-01 00:47 - 2015-11-07 08:04 - 00000917 _____ G:\Users\Public\Desktop\CPUID CPU-Z.lnk
2016-12-01 00:47 - 2015-11-05 00:43 - 00001998 _____ G:\Users\kuureee\Desktop\My.com Game Center.lnk
2016-12-01 00:47 - 2015-11-04 23:57 - 00001015 _____ G:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2016-12-01 00:47 - 2015-11-04 23:47 - 00001110 _____ G:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-12-01 00:47 - 2015-11-04 23:39 - 00002441 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2016-12-01 00:47 - 2015-11-04 23:39 - 00002023 _____ G:\Users\Public\Desktop\Adobe Reader XI.lnk
2016-12-01 00:47 - 2015-11-04 23:39 - 00001155 _____ G:\Users\Public\Desktop\CDBurnerXP.lnk
2016-12-01 00:47 - 2015-11-04 23:39 - 00001119 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
2016-12-01 00:47 - 2015-11-04 23:38 - 00002593 _____ G:\Users\kuureee\Desktop\µTorrent.lnk
2016-12-01 00:47 - 2015-11-04 23:38 - 00002573 _____ G:\Users\kuureee\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2016-12-01 00:47 - 2015-11-04 23:38 - 00000870 _____ G:\Users\Public\Desktop\CCleaner.lnk
2016-12-01 00:47 - 2015-07-18 23:40 - 00001345 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2016-12-01 00:47 - 2015-07-18 23:40 - 00001326 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2016-12-01 00:47 - 2009-07-14 06:01 - 00001218 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk
2016-12-01 00:47 - 2009-07-14 05:57 - 00001523 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-12-01 00:47 - 2009-07-14 05:57 - 00001304 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
2016-12-01 00:47 - 2009-07-14 05:57 - 00001246 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
2016-12-01 00:47 - 2009-07-14 05:54 - 00001210 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
2016-12-01 00:47 - 2009-07-14 05:49 - 00001246 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk
2016-12-01 00:47 - 2009-07-14 04:20 - 00000000 ____D G:\Windows\Branding
2016-12-01 00:43 - 2016-05-06 14:47 - 00000830 _____ G:\Windows\Tasks\Adobe Flash Player Updater.job
2016-12-01 00:41 - 2015-11-05 00:01 - 00000898 _____ G:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-12-01 00:36 - 2016-08-28 20:52 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Warframe
2016-12-01 00:31 - 2016-08-14 21:39 - 00000000 ____D G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Survarium
2016-12-01 00:31 - 2016-07-21 18:12 - 00000000 ____D G:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Tanks
2016-12-01 00:31 - 2016-05-21 18:34 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WarThunder
2016-12-01 00:19 - 2015-11-26 18:59 - 00000000 ____D G:\Users\kuureee\Documents\My Games
2016-12-01 00:14 - 2015-11-05 00:01 - 00000894 _____ G:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-12-01 00:13 - 2016-01-10 18:37 - 00000000 ____D G:\Program Files\SUPERAntiSpyware
2016-12-01 00:12 - 2015-11-04 23:00 - 00000000 ____D G:\ProgramData\Package Cache
2016-11-30 23:58 - 2015-11-26 18:41 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\DAEMON Tools Lite
2016-11-30 23:19 - 2015-11-22 22:31 - 00000000 ____D G:\Users\kuureee\Downloads\PopcornTime
2016-11-30 23:08 - 2015-11-04 23:58 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\TS3Client
2016-11-30 19:03 - 2015-11-29 17:46 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\foobar2000
2016-11-30 08:38 - 2015-11-13 20:31 - 00000000 ____D G:\ProgramData\ProductData
2016-11-29 13:05 - 2015-11-04 22:54 - 00000000 ____D G:\Users\kuureee\AppData\Local\ElevatedDiagnostics
2016-11-28 13:24 - 2009-07-14 06:13 - 00781698 _____ G:\Windows\system32\PerfStringBackup.INI
2016-11-28 13:24 - 2009-07-14 04:20 - 00000000 ____D G:\Windows\inf
2016-11-26 23:52 - 2016-05-06 14:47 - 00000892 _____ G:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job
2016-11-26 23:52 - 2015-11-05 00:00 - 00000000 ____D G:\Windows\SysWOW64\Macromed
2016-11-25 13:01 - 2015-11-07 16:53 - 00000000 ____D G:\Users\kuureee\Documents\ViberDownloads
2016-11-25 11:10 - 2015-11-04 23:14 - 00003850 _____ G:\Windows\System32\Tasks\Opera scheduled Autoupdate 1446675288
2016-11-25 11:10 - 2015-11-04 23:13 - 00000000 ____D G:\Program Files (x86)\Opera
2016-11-24 12:01 - 2009-07-14 06:08 - 00032566 _____ G:\Windows\Tasks\SCHEDLGU.TXT
2016-11-16 20:54 - 2015-11-04 22:36 - 00000000 ____D G:\Users\kuureee
2016-11-15 10:45 - 2015-11-05 00:01 - 00002205 ____H G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-11-08 20:43 - 2016-05-06 14:47 - 00003894 _____ G:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2016-11-08 20:43 - 2016-05-06 14:47 - 00003768 _____ G:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-11-08 20:43 - 2015-11-05 00:00 - 00796352 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\FlashPlayerApp.exe
2016-11-08 20:43 - 2015-11-05 00:00 - 00142528 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-11-08 20:43 - 2015-11-05 00:00 - 00000000 ____D G:\Windows\system32\Macromed
2016-11-08 15:46 - 2016-04-10 00:46 - 00004476 _____ G:\Windows\System32\Tasks\Adobe Acrobat Update Task
2016-11-07 19:21 - 2016-02-13 16:05 - 00000000 ____D G:\Users\kuureee\Desktop\SLIKE
2016-11-05 02:11 - 2016-05-21 18:34 - 00000000 ____D G:\WarThunder
2016-11-01 16:05 - 2016-07-11 09:20 - 00000088 _____ G:\Users\kuureee\Desktop\racun.txt
==================== Files in the root of some directories =======
2016-08-20 08:16 - 2016-08-25 16:18 - 0001708 _____ () G:\Users\kuureee\AppData\Roaming\hidewin.cfg
2016-07-21 19:50 - 2016-07-21 19:50 - 0007635 _____ () G:\Users\kuureee\AppData\Local\Resmon.ResmonCfg
Files to move or delete:
====================
G:\Windows\TEMP\gEFBC.tmp.exe
Some files in TEMP:
====================
G:\Users\kuureee\AppData\Local\Temp\AutoTime51495.exe
G:\Users\kuureee\AppData\Local\Temp\A~NSISu_.exe
G:\Users\kuureee\AppData\Local\Temp\DSETUP.dll
G:\Users\kuureee\AppData\Local\Temp\dsetup32.dll
G:\Users\kuureee\AppData\Local\Temp\DXSETUP.exe
G:\Users\kuureee\AppData\Local\Temp\g5ABD.tmp.exe
G:\Users\kuureee\AppData\Local\Temp\gD347.tmp.exe
G:\Users\kuureee\AppData\Local\Temp\ludashisetup.exe
G:\Users\kuureee\AppData\Local\Temp\setup_1FBD.exe
G:\Users\kuureee\AppData\Local\Temp\ShellHook.dll
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
G:\Windows\system32\winlogon.exe => File is digitally signed
G:\Windows\system32\wininit.exe => File is digitally signed
G:\Windows\SysWOW64\wininit.exe => File is digitally signed
G:\Windows\explorer.exe => File is digitally signed
G:\Windows\SysWOW64\explorer.exe => File is digitally signed
G:\Windows\system32\svchost.exe => File is digitally signed
G:\Windows\SysWOW64\svchost.exe => File is digitally signed
G:\Windows\system32\services.exe => File is digitally signed
G:\Windows\system32\User32.dll => File is digitally signed
G:\Windows\SysWOW64\User32.dll => File is digitally signed
G:\Windows\system32\userinit.exe => File is digitally signed
G:\Windows\SysWOW64\userinit.exe => File is digitally signed
G:\Windows\system32\rpcss.dll => File is digitally signed
G:\Windows\system32\dnsapi.dll => File is digitally signed
G:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
G:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-11-26 12:42
==================== End of FRST.txt ============================
mycity.rs/must-login.png
Dopuna: 01 Dec 2016 1:29
kuureee ::Naime napravih tesko pocetnicku gresku i navuce bedu na svoj komp.
Nekako sam uspo da navucem ono kinesu glupost ,sta je namam pojma,I uz to jos svasta.MB je nasao svasta i uredno pobrisao.Takodje su mi se duplirale neke ikone na deskopu ,nako prozirne ,ali bas kao ikona ne kao koija toga kada je redovno uradis.
Komp mi je zesce usporio kao i net.
Hvala....
+ .txtUnesi sadržajScan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 30-11-2016
Ran by kuureee (administrator) on KUUREEE-PC (01-12-2016 01:12:45)
Running from G:\Users\kuureee\Desktop
Loaded Profiles: kuureee (Available Profiles: kuureee)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Opera)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: geekstogo.com/forum/topic/335081-frst-t.....scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) G:\Windows\System32\atiesrxx.exe
(AMD) G:\Windows\System32\atieclxx.exe
(Microsoft Corporation) G:\Windows\System32\rundll32.exe
(SUPERAntiSpyware.com) G:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Advanced Micro Devices, Inc.) G:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
(Microsoft Corporation) G:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Popcorn Time) G:\Program Files (x86)\Popcorn Time\Updater.exe
() G:\Windows\temp\gEFBC.tmp.exe
(Microsoft Corporation) G:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) G:\Windows\System32\dllhost.exe
(Microsoft Corporation) G:\Windows\System32\alg.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera_crashreporter.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
(Opera Software) G:\Program Files (x86)\Opera\41.0.2353.69\opera.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\RunOnce: [wd] => G:\Windows\TEMP\gEFBC.tmp.exe [770560 2016-12-01] () <===== ATTENTION
HKU\S-1-5-21-4139358893-2112486851-1280740277-1000\...\Run: [Viber] => F:\New folder\Viber.exe [51512528 2015-09-27] ()
HKU\S-1-5-21-4139358893-2112486851-1280740277-1000\...\Run: [uTorrent] => G:\Users\kuureee\AppData\Roaming\uTorrent\uTorrent.exe [1995968 2016-11-18] (BitTorrent Inc.)
HKU\S-1-5-21-4139358893-2112486851-1280740277-1000\...\Run: [Lync] => G:\Program Files\Microsoft Office\Office16\lync.exe [26878152 2016-01-13] (Microsoft Corporation)
HKU\S-1-5-21-4139358893-2112486851-1280740277-1000\...\Run: [CCleaner Monitoring] => G:\Program Files\CCleaner\CCleaner64.exe [8944344 2016-09-28] (Piriform Ltd)
ShellIconOverlayIdentifiers: [KzShlobj] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F2} => G:\Program Files\¿ìѹ\X64\KZipShell.dll No File
GroupPolicy: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog9 01 chtbrkg.dll No File
Winsock: Catalog9 02 chtbrkg.dll No File
Winsock: Catalog9 03 chtbrkg.dll No File
Winsock: Catalog9 04 chtbrkg.dll No File
Winsock: Catalog9 05 chtbrkg.dll No File
Winsock: Catalog9 06 chtbrkg.dll No File
Winsock: Catalog9 07 chtbrkg.dll No File
Winsock: Catalog9 08 chtbrkg.dll No File
Winsock: Catalog9 09 chtbrkg.dll No File
Winsock: Catalog9 10 chtbrkg.dll No File
Winsock: Catalog9 21 chtbrkg.dll No File
Winsock: Catalog9-x64 01 chtbrkg.dll No File
Winsock: Catalog9-x64 02 chtbrkg.dll No File
Winsock: Catalog9-x64 03 chtbrkg.dll No File
Winsock: Catalog9-x64 04 chtbrkg.dll No File
Winsock: Catalog9-x64 05 chtbrkg.dll No File
Winsock: Catalog9-x64 06 chtbrkg.dll No File
Winsock: Catalog9-x64 07 chtbrkg.dll No File
Winsock: Catalog9-x64 08 chtbrkg.dll No File
Winsock: Catalog9-x64 09 chtbrkg.dll No File
Winsock: Catalog9-x64 10 chtbrkg.dll No File
Winsock: Catalog9-x64 21 chtbrkg.dll No File
Tcpip\Parameters: [DhcpNameServer] 89.216.1.40 89.216.1.50
Tcpip\..\Interfaces\{01A0C17A-2E49-4034-B5A0-A408A5FAEDE4}: [DhcpNameServer] 89.216.1.40 89.216.1.50
Tcpip\..\Interfaces\{80B82E65-B0D1-4E76-A07F-6259AD41CD27}: [DhcpNameServer] 192.168.42.129
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-4139358893-2112486851-1280740277-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://faststartpage.com/
SearchScopes: HKLM -> DefaultScope value is missing
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> G:\Program Files\Microsoft Office\Office16\OCHelper.dll [2016-01-13] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> G:\Program Files\Java\jre1.8.0_66\bin\ssv.dll [2015-11-04] (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> G:\Program Files\Microsoft Office\Office16\URLREDIR.DLL [2015-07-31] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> G:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL [2016-01-13] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> G:\Program Files\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-11-04] (Oracle Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> G:\Program Files (x86)\Microsoft Office\Office16\OCHelper.dll [2015-07-31] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> G:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2015-11-22] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> G:\Program Files (x86)\Microsoft Office\Office16\URLREDIR.DLL [2015-07-31] (Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> G:\Program Files (x86)\Microsoft Office\Office16\GROOVEEX.DLL [2016-01-13] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> G:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-11-22] (Oracle Corporation)
Handler: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - G:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2016-01-13] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - G:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2016-01-13] (Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - G:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2016-01-13] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - G:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2016-01-13] (Microsoft Corporation)
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.66.2 -> G:\Program Files\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-11-04] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.66.2 -> G:\Program Files\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-11-04] (Oracle Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> G:\PROGRA~1\MICROS~2\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> G:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-11-22] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> G:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-11-22] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> G:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-01-12] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> G:\PROGRA~2\MICROS~1\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> G:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> G:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.2 -> G:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-01-21] (VideoLAN)
FF Plugin-x32: Adobe Reader -> G:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-10-01] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-4139358893-2112486851-1280740277-1000: @my.com/Games -> G:\Users\kuureee\AppData\Local\MyComGames\NPMyComDetector.dll [2015-11-05] (My.com, Inc)
FF Plugin ProgramFiles/Appdata: G:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2016-01-12] (Microsoft Corporation)
Chrome:
=======
CHR DefaultProfile: ChromeDefaultData
CHR Profile: G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2016-12-01] <==== ATTENTION
CHR Extension: (Google Slides) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-06-14]
CHR Extension: (Google Docs) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aohghmighlieiainnegkcijnfilokake [2016-06-14]
CHR Extension: (Google Drive) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-06-14]
CHR Extension: (YouTube) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-06-14]
CHR Extension: (Google Sheets) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-06-14]
CHR Extension: (Google Docs Offline) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-06-15]
CHR Extension: (Chrome Web Store Payments) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-06-14]
CHR Extension: (Gmail) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-06-14]
CHR Extension: (Chrome Media Router) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-10-26]
CHR Profile: G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default [2016-10-28]
CHR Extension: (Google Docs) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-11-14]
CHR Extension: (Google Drive) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-14]
CHR Extension: (YouTube) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-14]
CHR Extension: (Google Search) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-14]
CHR Extension: (Google Sheets) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-11-14]
CHR Extension: (Google Docs Offline) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-21]
CHR Extension: (Chrome Web Store Payments) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-03]
CHR Extension: (Gmail) - G:\Users\kuureee\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-14]
Opera:
=======
OPR Session Restore: -> is enabled.
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; G:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-23] (SUPERAntiSpyware.com)
R2 AMD FUEL Service; G:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [344064 2015-08-04] (Advanced Micro Devices, Inc.) [File not signed]
S2 LiveUpdateSvc; G:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2960672 2016-07-20] (IObit)
S3 Survarium Update Service; G:\Program Files (x86)\Survarium\game\binaries\x86\survarium_service.exe [97880 2016-08-14] ()
R2 Update service; G:\Program Files (x86)\Popcorn Time\Updater.exe [339968 2016-08-26] (Popcorn Time) [File not signed]
R2 WinDefend; G:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 GmSvc; G:\Program Files (x86)\LDSGameCenter\GmSvc.dll [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AODDriver4.3; G:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
R1 dtsoftbus01; G:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2015-11-26] (Disc Soft Ltd)
S3 NSNDIS5; G:\Windows\SysWOW64\NSNDIS5.SYS [17280 2004-03-24] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
R1 SASDIFSV; G:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; G:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R0 SmartDefragDriver; G:\Windows\System32\Drivers\SmartDefragDriver.sys [21360 2016-03-22] (IObit)
S3 vmci; \SystemRoot\system32\DRIVERS\vmci.sys [X]
S3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
NETSVCx32: HpSvc -> no filepath.
NETSVCx32: GmSvc -> G:\Program Files (x86)\LDSGameCenter\GmSvc.dll ==> No File
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-12-01 01:12 - 2016-12-01 01:12 - 00037756 _____ G:\Users\kuureee\Desktop\Addition.txt
2016-12-01 01:11 - 2016-12-01 01:11 - 00000000 ___SD G:\ComboFix
2016-12-01 01:10 - 2016-12-01 01:12 - 00015258 _____ G:\Users\kuureee\Desktop\FRST.txt
2016-12-01 01:07 - 2016-12-01 01:07 - 02411520 _____ (Farbar) G:\Users\kuureee\Desktop\FRST64.exe
2016-12-01 00:54 - 2016-12-01 01:11 - 00000000 ____D G:\Qoobox
2016-12-01 00:47 - 2016-12-01 00:47 - 00000080 _____ G:\Users\kuureee\AppData\Roaming\Microsoft\Windows\Start Menu\¿ìÑ1.lnk
2016-12-01 00:40 - 2016-12-01 00:40 - 00000000 ____D G:\ProgramData\Microsoft\Windows\Start Menu\Programs\鲁大师游戏库
2016-12-01 00:38 - 2016-12-01 00:38 - 05659307 ____R (Swearware) G:\Users\kuureee\Desktop\ComboFix.exe
2016-12-01 00:35 - 2016-12-01 00:42 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\KuaiZip
2016-12-01 00:35 - 2016-12-01 00:35 - 00000847 _____ G:\Users\kuureee\AppData\Roaming\Microsoft\Windows\Start Menu\¿ìѹ.lnk
2016-12-01 00:35 - 2016-12-01 00:35 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\Softlink
2016-12-01 00:33 - 2016-12-01 00:33 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\LDSGameCenter
2016-12-01 00:32 - 2016-12-01 00:32 - 00000000 __SHD G:\Users\kuureee\AppData\Local\svchost
2016-12-01 00:32 - 2016-12-01 00:32 - 00000000 ____D G:\Users\Public\Thunder Network
2016-12-01 00:32 - 2016-12-01 00:32 - 00000000 ____D G:\ProgramData\Thunder Network
2016-12-01 00:32 - 2016-11-09 15:55 - 00778752 _____ G:\Windows\system32\chtbrkg.dll
2016-12-01 00:32 - 2016-11-09 15:55 - 00590848 _____ G:\Windows\SysWOW64\chtbrkg.dll
2016-12-01 00:31 - 2016-12-01 01:13 - 00016718 _____ G:\Windows\System32\Tasks\40289_73307-2937
2016-12-01 00:31 - 2016-12-01 00:31 - 00001986 ___RS G:\Users\Public\Desktop\Survаrium.lnk
2016-12-01 00:31 - 2016-12-01 00:31 - 00001834 ___RS G:\Users\Public\Desktop\Wоrld of Tanks.lnk
2016-12-01 00:31 - 2016-12-01 00:31 - 00001796 ___RS G:\Users\kuureee\Desktop\ЕVE Launchеr.lnk
2016-12-01 00:31 - 2016-12-01 00:31 - 00001793 ___RS G:\Users\Public\Desktop\WаrThundеr.lnk
2016-12-01 00:31 - 2016-12-01 00:31 - 00001323 ___RS G:\Users\kuureee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Intеrnet Ехplorer.lnk
2016-12-01 00:31 - 2016-12-01 00:31 - 00001265 ___RS G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ореra.lnk
2016-12-01 00:31 - 2016-12-01 00:31 - 00001151 ___RS G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gоoglе Chrome.lnk
2016-12-01 00:31 - 2016-12-01 00:31 - 00001126 ___RS G:\ProgramData\Microsoft\Windows\Start Menu\Programs\zс1h3r7о5m4e.lnk
2016-12-01 00:31 - 2016-12-01 00:31 - 00000000 ___HD G:\ProgramData\40289_73307-2937
2016-12-01 00:31 - 2016-12-01 00:31 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\SPI
2016-12-01 00:14 - 2016-12-01 00:52 - 00000000 ____D G:\Users\kuureee\AppData\LocalLow\uTorrent
2016-12-01 00:11 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) G:\Windows\system32\D3DX9_40.dll
2016-12-01 00:11 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) G:\Windows\SysWOW64\D3DX9_40.dll
2016-12-01 00:11 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) G:\Windows\system32\D3DCompiler_40.dll
2016-12-01 00:11 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) G:\Windows\SysWOW64\D3DCompiler_40.dll
2016-12-01 00:11 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) G:\Windows\system32\d3dx10_40.dll
2016-12-01 00:11 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) G:\Windows\SysWOW64\d3dx10_40.dll
2016-12-01 00:05 - 2016-12-01 00:47 - 00001552 _____ G:\Users\kuureee\Desktop\Sid Meiers Civilization VI.lnk
2016-12-01 00:05 - 2016-12-01 00:05 - 00000000 ____D G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sid Meiers Civilization VI
2016-12-01 00:00 - 2016-12-01 00:07 - 00000000 ____D G:\Program Files (x86)\Sid Meiers Civilization VI
2016-11-16 21:54 - 2016-11-16 21:54 - 00000000 ____D G:\Users\kuureee\Desktop\eve-overview-v0.11.0
2016-11-16 20:59 - 2016-11-16 21:16 - 00000000 ____D G:\Users\kuureee\Documents\EVE
2016-11-16 20:54 - 2016-12-01 00:31 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EVE Launcher
2016-11-16 20:54 - 2016-11-16 20:54 - 00000000 ____D G:\Users\kuureee\AppData\Local\CCP
2016-11-16 20:54 - 2016-11-16 20:54 - 00000000 ____D G:\Users\kuureee\.EVE
2016-11-16 20:54 - 2016-11-16 20:54 - 00000000 ____D G:\EVE
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-12-01 01:12 - 2016-04-12 16:20 - 00000000 ____D G:\FRST
2016-12-01 01:04 - 2015-11-04 23:48 - 00192216 _____ (Malwarebytes) G:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-12-01 01:00 - 2016-05-02 10:43 - 00000000 ____D G:\Users\kuureee\Desktop\New folder (2)
2016-12-01 00:57 - 2009-07-14 05:45 - 00021072 ____H G:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-12-01 00:57 - 2009-07-14 05:45 - 00021072 ____H G:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-12-01 00:53 - 2015-11-11 18:53 - 00000000 ____D G:\Windows\erdnt
2016-12-01 00:52 - 2015-11-04 23:02 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\ViberPC
2016-12-01 00:51 - 2015-11-04 23:37 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\uTorrent
2016-12-01 00:51 - 2009-07-14 06:08 - 00000006 ____H G:\Windows\Tasks\SA.DAT
2016-12-01 00:47 - 2016-10-15 22:24 - 00002883 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive for Business.lnk
2016-12-01 00:47 - 2016-10-15 22:24 - 00002862 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook 2016.lnk
2016-12-01 00:47 - 2016-10-15 22:24 - 00002857 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype for Business 2016.lnk
2016-12-01 00:47 - 2016-10-15 22:24 - 00002833 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk
2016-12-01 00:47 - 2016-10-15 22:24 - 00002811 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk
2016-12-01 00:47 - 2016-10-15 22:24 - 00002805 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk
2016-12-01 00:47 - 2016-10-15 22:24 - 00002785 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access 2016.lnk
2016-12-01 00:47 - 2016-10-15 22:24 - 00002777 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher 2016.lnk
2016-12-01 00:47 - 2016-10-15 22:24 - 00002769 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2016-12-01 00:47 - 2016-09-18 00:17 - 00001164 _____ G:\Users\Public\Desktop\Smart Defrag 5.lnk
2016-12-01 00:47 - 2016-08-20 08:16 - 00000987 _____ G:\Users\kuureee\Desktop\HideWindowPlus.lnk
2016-12-01 00:47 - 2016-07-10 11:10 - 00000588 _____ G:\Users\Public\Desktop\Total War Rome II.lnk
2016-12-01 00:47 - 2016-07-09 14:17 - 00001021 _____ G:\Users\kuureee\Desktop\SpeedFan.lnk
2016-12-01 00:47 - 2016-07-05 15:50 - 00002027 _____ G:\Users\Public\Desktop\Raptr.lnk
2016-12-01 00:47 - 2016-06-25 14:56 - 00001032 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Southpark Stick of Truth.lnk
2016-12-01 00:47 - 2016-06-25 14:56 - 00001014 _____ G:\Users\Public\Desktop\Southpark Stick of Truth.lnk
2016-12-01 00:47 - 2016-05-14 13:45 - 00001104 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Network Stumbler.lnk
2016-12-01 00:47 - 2016-03-19 00:36 - 00001224 _____ G:\Users\Public\Desktop\Wise Auto Shutdown.lnk
2016-12-01 00:47 - 2016-03-05 00:14 - 00001856 _____ G:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2016-12-01 00:47 - 2016-02-14 13:15 - 00002061 _____ G:\Users\kuureee\Desktop\VirusTotal Uploader 2.0.lnk
2016-12-01 00:47 - 2016-02-01 16:43 - 00001357 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\American Truck Simulator.lnk
2016-12-01 00:47 - 2016-02-01 16:43 - 00001339 _____ G:\Users\Public\Desktop\American Truck Simulator.lnk
2016-12-01 00:47 - 2015-11-29 17:46 - 00001127 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\foobar2000.lnk
2016-12-01 00:47 - 2015-11-29 17:46 - 00001039 _____ G:\Users\Public\Desktop\foobar2000.lnk
2016-12-01 00:47 - 2015-11-22 22:31 - 00001205 _____ G:\Users\Public\Desktop\Popcorn Time.lnk
2016-12-01 00:47 - 2015-11-07 20:20 - 00001223 _____ G:\Users\kuureee\AppData\Roaming\Microsoft\Windows\Start Menu\GOM Player.lnk
2016-12-01 00:47 - 2015-11-07 20:20 - 00001193 _____ G:\Users\Public\Desktop\GOM Player.lnk
2016-12-01 00:47 - 2015-11-07 08:04 - 00000917 _____ G:\Users\Public\Desktop\CPUID CPU-Z.lnk
2016-12-01 00:47 - 2015-11-05 00:43 - 00001998 _____ G:\Users\kuureee\Desktop\My.com Game Center.lnk
2016-12-01 00:47 - 2015-11-04 23:57 - 00001015 _____ G:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2016-12-01 00:47 - 2015-11-04 23:47 - 00001110 _____ G:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-12-01 00:47 - 2015-11-04 23:39 - 00002441 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2016-12-01 00:47 - 2015-11-04 23:39 - 00002023 _____ G:\Users\Public\Desktop\Adobe Reader XI.lnk
2016-12-01 00:47 - 2015-11-04 23:39 - 00001155 _____ G:\Users\Public\Desktop\CDBurnerXP.lnk
2016-12-01 00:47 - 2015-11-04 23:39 - 00001119 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
2016-12-01 00:47 - 2015-11-04 23:38 - 00002593 _____ G:\Users\kuureee\Desktop\µTorrent.lnk
2016-12-01 00:47 - 2015-11-04 23:38 - 00002573 _____ G:\Users\kuureee\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2016-12-01 00:47 - 2015-11-04 23:38 - 00000870 _____ G:\Users\Public\Desktop\CCleaner.lnk
2016-12-01 00:47 - 2015-07-18 23:40 - 00001345 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2016-12-01 00:47 - 2015-07-18 23:40 - 00001326 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2016-12-01 00:47 - 2009-07-14 06:01 - 00001218 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk
2016-12-01 00:47 - 2009-07-14 05:57 - 00001523 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-12-01 00:47 - 2009-07-14 05:57 - 00001304 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
2016-12-01 00:47 - 2009-07-14 05:57 - 00001246 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
2016-12-01 00:47 - 2009-07-14 05:54 - 00001210 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
2016-12-01 00:47 - 2009-07-14 05:49 - 00001246 _____ G:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk
2016-12-01 00:47 - 2009-07-14 04:20 - 00000000 ____D G:\Windows\Branding
2016-12-01 00:43 - 2016-05-06 14:47 - 00000830 _____ G:\Windows\Tasks\Adobe Flash Player Updater.job
2016-12-01 00:41 - 2015-11-05 00:01 - 00000898 _____ G:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-12-01 00:36 - 2016-08-28 20:52 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Warframe
2016-12-01 00:31 - 2016-08-14 21:39 - 00000000 ____D G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Survarium
2016-12-01 00:31 - 2016-07-21 18:12 - 00000000 ____D G:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Tanks
2016-12-01 00:31 - 2016-05-21 18:34 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WarThunder
2016-12-01 00:19 - 2015-11-26 18:59 - 00000000 ____D G:\Users\kuureee\Documents\My Games
2016-12-01 00:14 - 2015-11-05 00:01 - 00000894 _____ G:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-12-01 00:13 - 2016-01-10 18:37 - 00000000 ____D G:\Program Files\SUPERAntiSpyware
2016-12-01 00:12 - 2015-11-04 23:00 - 00000000 ____D G:\ProgramData\Package Cache
2016-11-30 23:58 - 2015-11-26 18:41 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\DAEMON Tools Lite
2016-11-30 23:19 - 2015-11-22 22:31 - 00000000 ____D G:\Users\kuureee\Downloads\PopcornTime
2016-11-30 23:08 - 2015-11-04 23:58 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\TS3Client
2016-11-30 19:03 - 2015-11-29 17:46 - 00000000 ____D G:\Users\kuureee\AppData\Roaming\foobar2000
2016-11-30 08:38 - 2015-11-13 20:31 - 00000000 ____D G:\ProgramData\ProductData
2016-11-29 13:05 - 2015-11-04 22:54 - 00000000 ____D G:\Users\kuureee\AppData\Local\ElevatedDiagnostics
2016-11-28 13:24 - 2009-07-14 06:13 - 00781698 _____ G:\Windows\system32\PerfStringBackup.INI
2016-11-28 13:24 - 2009-07-14 04:20 - 00000000 ____D G:\Windows\inf
2016-11-26 23:52 - 2016-05-06 14:47 - 00000892 _____ G:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job
2016-11-26 23:52 - 2015-11-05 00:00 - 00000000 ____D G:\Windows\SysWOW64\Macromed
2016-11-25 13:01 - 2015-11-07 16:53 - 00000000 ____D G:\Users\kuureee\Documents\ViberDownloads
2016-11-25 11:10 - 2015-11-04 23:14 - 00003850 _____ G:\Windows\System32\Tasks\Opera scheduled Autoupdate 1446675288
2016-11-25 11:10 - 2015-11-04 23:13 - 00000000 ____D G:\Program Files (x86)\Opera
2016-11-24 12:01 - 2009-07-14 06:08 - 00032566 _____ G:\Windows\Tasks\SCHEDLGU.TXT
2016-11-16 20:54 - 2015-11-04 22:36 - 00000000 ____D G:\Users\kuureee
2016-11-15 10:45 - 2015-11-05 00:01 - 00002205 ____H G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-11-08 20:43 - 2016-05-06 14:47 - 00003894 _____ G:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2016-11-08 20:43 - 2016-05-06 14:47 - 00003768 _____ G:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-11-08 20:43 - 2015-11-05 00:00 - 00796352 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\FlashPlayerApp.exe
2016-11-08 20:43 - 2015-11-05 00:00 - 00142528 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-11-08 20:43 - 2015-11-05 00:00 - 00000000 ____D G:\Windows\system32\Macromed
2016-11-08 15:46 - 2016-04-10 00:46 - 00004476 _____ G:\Windows\System32\Tasks\Adobe Acrobat Update Task
2016-11-07 19:21 - 2016-02-13 16:05 - 00000000 ____D G:\Users\kuureee\Desktop\SLIKE
2016-11-05 02:11 - 2016-05-21 18:34 - 00000000 ____D G:\WarThunder
2016-11-01 16:05 - 2016-07-11 09:20 - 00000088 _____ G:\Users\kuureee\Desktop\racun.txt
==================== Files in the root of some directories =======
2016-08-20 08:16 - 2016-08-25 16:18 - 0001708 _____ () G:\Users\kuureee\AppData\Roaming\hidewin.cfg
2016-07-21 19:50 - 2016-07-21 19:50 - 0007635 _____ () G:\Users\kuureee\AppData\Local\Resmon.ResmonCfg
Files to move or delete:
====================
G:\Windows\TEMP\gEFBC.tmp.exe
Some files in TEMP:
====================
G:\Users\kuureee\AppData\Local\Temp\AutoTime51495.exe
G:\Users\kuureee\AppData\Local\Temp\A~NSISu_.exe
G:\Users\kuureee\AppData\Local\Temp\DSETUP.dll
G:\Users\kuureee\AppData\Local\Temp\dsetup32.dll
G:\Users\kuureee\AppData\Local\Temp\DXSETUP.exe
G:\Users\kuureee\AppData\Local\Temp\g5ABD.tmp.exe
G:\Users\kuureee\AppData\Local\Temp\gD347.tmp.exe
G:\Users\kuureee\AppData\Local\Temp\ludashisetup.exe
G:\Users\kuureee\AppData\Local\Temp\setup_1FBD.exe
G:\Users\kuureee\AppData\Local\Temp\ShellHook.dll
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
G:\Windows\system32\winlogon.exe => File is digitally signed
G:\Windows\system32\wininit.exe => File is digitally signed
G:\Windows\SysWOW64\wininit.exe => File is digitally signed
G:\Windows\explorer.exe => File is digitally signed
G:\Windows\SysWOW64\explorer.exe => File is digitally signed
G:\Windows\system32\svchost.exe => File is digitally signed
G:\Windows\SysWOW64\svchost.exe => File is digitally signed
G:\Windows\system32\services.exe => File is digitally signed
G:\Windows\system32\User32.dll => File is digitally signed
G:\Windows\SysWOW64\User32.dll => File is digitally signed
G:\Windows\system32\userinit.exe => File is digitally signed
G:\Windows\SysWOW64\userinit.exe => File is digitally signed
G:\Windows\system32\rpcss.dll => File is digitally signed
G:\Windows\system32\dnsapi.dll => File is digitally signed
G:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
G:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-11-26 12:42
==================== End of FRST.txt ============================
mycity.rs/must-login.png
Evo logo i od MBM
mycity.rs/must-login.png
|