Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 09-08-2017
- Ran by User (administrator) on DESKTOP-MCFUS5L (12-08-2017 13:38:00)
- Running from C:\Users\User\Desktop
- Loaded Profiles: User (Available Profiles: User)
- Platform: Windows 10 Pro Version 1703 (X64) Language: English (United States)
- Internet Explorer Version 11 (Default browser: Opera)
- Boot Mode: Normal
- Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
- ==================== Processes (Whitelisted) =================
- (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
- (Microsoft Corporation) C:\Windows\System32\rundll32.exe
- (Microsoft Corporation) C:\Windows\System32\rundll32.exe
- (Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_0745f11ce6fc197c\igfxCUIService.exe
- (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe
- (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\afwServ.exe
- (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
- (Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_0745f11ce6fc197c\IntelCpHDCPSvc.exe
- (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
- (Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_0745f11ce6fc197c\IntelCpHeciSvc.exe
- (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe
- (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
- (Microsoft Corporation) C:\Windows\System32\rundll32.exe
- (Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_0745f11ce6fc197c\igfxEM.exe
- (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe
- (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe
- (Microsoft Corporation) C:\Windows\System32\smartscreen.exe
- () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.8.204.0_x64__kzf8qxf38zg5c\SkypeHost.exe
- (Opera Software) C:\Program Files\Opera\47.0.2631.39\opera.exe
- (Opera Software) C:\Program Files\Opera\47.0.2631.39\opera_crashreporter.exe
- (Opera Software) C:\Program Files\Opera\47.0.2631.39\opera.exe
- (Opera Software) C:\Program Files\Opera\47.0.2631.39\opera.exe
- (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
- (Opera Software) C:\Program Files\Opera\47.0.2631.39\opera.exe
- (Opera Software) C:\Program Files\Opera\47.0.2631.39\opera.exe
- (Opera Software) C:\Program Files\Opera\47.0.2631.39\opera.exe
- (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
- (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
- (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\avgui.exe
- (Viber Media S.Ã r.l.) C:\Users\User\AppData\Local\Viber\Viber.exe
- (Opera Software) C:\Program Files\Opera\47.0.2631.39\opera.exe
- (Opera Software) C:\Program Files\Opera\47.0.2631.39\opera.exe
- (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
- (Skillbrains) C:\Program Files (x86)\Skillbrains\lightshot\5.4.0.10\Lightshot.exe
- (Opera Software) C:\Program Files\Opera\47.0.2631.39\opera.exe
- (Opera Software) C:\Program Files\Opera\47.0.2631.39\opera.exe
- (Opera Software) C:\Program Files\Opera\47.0.2631.39\opera.exe
- (Opera Software) C:\Program Files\Opera\47.0.2631.39\opera.exe
- (Opera Software) C:\Program Files\Opera\47.0.2631.39\opera.exe
- (Opera Software) C:\Program Files\Opera\47.0.2631.39\opera.exe
- (Opera Software) C:\Program Files\Opera\47.0.2631.39\opera.exe
- (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
- (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
- ==================== Registry (Whitelisted) ====================
- (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
- HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
- HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [112512 2010-03-13] (Microsoft Corporation)
- HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
- HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes)
- HKLM\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [239592 2017-08-01] (AVG Technologies CZ, s.r.o.)
- HKLM\...\Run: [AVGUI.exe] => C:\Program Files (x86)\AVG\Antivirus\AvLaunch.exe [263232 2017-08-10] (AVG Technologies CZ, s.r.o.)
- HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
- HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
- HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [225944 2017-04-11] ()
- HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2133216 2017-03-23] (Wondershare)
- HKLM-x32\...\Run: [DelaypluginInstall] => C:\ProgramData\Wondershare\Video Converter Ultimate\DelayPluginI.exe [1967328 2017-03-29] ()
- HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
- HKU\S-1-5-21-73300378-2398947947-2795111270-1001\...\Run: [AdobeBridge] => [X]
- HKU\S-1-5-21-73300378-2398947947-2795111270-1001\...\Run: [Viber] => C:\Users\User\AppData\Local\Viber\Viber.exe [30867536 2017-08-03] (Viber Media S.Ã r.l.)
- HKU\S-1-5-21-73300378-2398947947-2795111270-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27815896 2017-07-28] (Skype Technologies S.A.)
- HKU\S-1-5-21-73300378-2398947947-2795111270-1001\...\Run: [IntelCpHDCPSvcwn] => "%SystemRoot%\System32\WScript.exe" "C:\Users\User\AppData\Roaming\IntelCpHDCPSvc store files\start64.vbs" //B "%1" %*
- HKU\S-1-5-21-73300378-2398947947-2795111270-1001\...\Run: [IntelCpHDCPSvcws] => "%SystemRoot%\System32\WScript.exe" "C:\Users\User\AppData\Roaming\IntelCpHDCPSvc local files\start.vbs" //B "%1" %*
- HKU\S-1-5-21-73300378-2398947947-2795111270-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9818328 2017-06-30] (Piriform Ltd)
- HKU\S-1-5-21-73300378-2398947947-2795111270-1001\...\MountPoints2: {04add41f-6d7b-11e7-b5b2-1c1b0dacc404} - "E:\Windows/AutoRun.exe"
- HKU\S-1-5-21-73300378-2398947947-2795111270-1001\...\MountPoints2: {04add542-6d7b-11e7-b5b2-1c1b0dacc404} - "E:\Windows/AutoRun.exe"
- HKU\S-1-5-21-73300378-2398947947-2795111270-1001\...\MountPoints2: {545d3f29-7315-11e7-b5b4-1c1b0dacc404} - "D:\Windows/AutoRun.exe"
- HKU\S-1-5-21-73300378-2398947947-2795111270-1001\...\MountPoints2: {972e8ed4-6314-11e7-b5a5-1c1b0dacc404} - "E:\Windows/AutoRun.exe"
- IFEO\SppExtComObj.exe: [Debugger] SppExtComObjPatcher.exe
- Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\IntelCpHDCPSvcwn.vbs [2017-08-10] ()
- Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\IntelCpHDCPSvcws.vbs [2017-08-10] ()
- GroupPolicy: Restriction - Chrome <==== ATTENTION
- ==================== Internet (Whitelisted) ====================
- (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
- Hosts: 127.0.0.1 platform.wondershare.com
- Tcpip\Parameters: [DhcpNameServer] 192.168.8.1 192.168.8.1
- Tcpip\..\Interfaces\{708fb553-4d8d-4c0b-a67b-0141550b32c0}: [DhcpNameServer] 192.168.8.1 192.168.8.1
- Tcpip\..\Interfaces\{7c473278-d35c-4fe2-b635-57d14c2184f3}: [DhcpNameServer] 192.168.43.1
- Internet Explorer:
- ==================
- BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
- BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
- BHO-x32: Wondershare Video Converter Ultimate 7.1.0 -> {451C804F-C205-4F03-B48E-537EC94937BF} -> C:\ProgramData\Wondershare\Video Converter Ultimate\WSBrowserAppMgr.dll [2017-03-29] (Wondershare)
- BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
- BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
- Handler: WSWSVCUchrome - {1CA93FF0-A218-44F1 - No File
- FireFox:
- ========
- FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\ProgramData\Wondershare\Video Converter Ultimate\[email protected]_xpi
- FF Extension: (Wondershare Video Converter Ultimate) - C:\ProgramData\Wondershare\Video Converter Ultimate\[email protected]_xpi [2017-07-12]
- FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
- FF Plugin-x32: @haitao.com/npHaitaoPlugin -> C:\Users\User\AppData\Local\htyh\application\htwebHelper.dll [No File]
- FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
- FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
- FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
- FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-07-07] (Google Inc.)
- FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-07-07] (Google Inc.)
- Chrome:
- =======
- CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default [2017-08-12]
- CHR Extension: (GreenAssistant) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\bncccjepkagemgfhbeknoggaadchfcfb [2017-07-11]
- CHR Extension: (Chrome Web Store Payments) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-07-11]
- CHR Extension: (Chrome Media Router) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-08-10]
- CHR HKU\S-1-5-21-73300378-2398947947-2795111270-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bncccjepkagemgfhbeknoggaadchfcfb] - <not found>
- CHR HKLM-x32\...\Chrome\Extension: [mbckjcfnjmoiinpgddefodcighgikkgn] - hxxps://clients2.google.com/service/update2/crx
- Opera:
- =======
- StartMenuInternet: (HKLM) OperaStable - C:\Program Files\Opera\Launcher.exe
- ==================== Services (Whitelisted) ====================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- R2 AVG Antivirus; C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe [264432 2017-08-10] (AVG Technologies CZ, s.r.o.)
- R2 AVG Firewall; C:\Program Files (x86)\AVG\Antivirus\afwServ.exe [312712 2017-08-10] (AVG Technologies CZ, s.r.o.)
- R3 avgbIDSAgent; C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe [7481648 2017-08-10] (AVG Technologies CZ, s.r.o.)
- R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1428656 2017-08-01] (AVG Technologies CZ, s.r.o.)
- R3 cphs; C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_0745f11ce6fc197c\IntelCpHeciSvc.exe [301536 2016-11-01] (Intel Corporation)
- R2 cplspcon; C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_0745f11ce6fc197c\IntelCpHDCPSvc.exe [480224 2016-11-01] (Intel Corporation)
- R2 igfxCUIService2.0.0.0; C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_0745f11ce6fc197c\igfxCUIService.exe [341984 2016-11-01] (Intel Corporation)
- S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [987432 2016-07-26] (Intel(R) Corporation)
- R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [177440 2016-10-05] (Intel Corporation)
- R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes)
- S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [3913064 2017-03-19] (Microsoft Corporation)
- S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
- S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation)
- S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-03-18] (Microsoft Corporation)
- ===================== Drivers (Whitelisted) ======================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- R3 athur; C:\Windows\System32\drivers\athuw8x.sys [2919936 2013-06-02] (Qualcomm Atheros Communications, Inc.)
- R1 avgbdisk; C:\Windows\system32\drivers\avgbdiska.sys [166624 2017-08-10] (AVG Technologies CZ, s.r.o.)
- R1 avgbidsdriver; C:\Windows\system32\drivers\avgbidsdrivera.sys [313616 2017-08-10] (AVG Technologies CZ, s.r.o.)
- R0 avgbidsh; C:\Windows\system32\drivers\avgbidsha.sys [192584 2017-08-10] (AVG Technologies CZ, s.r.o.)
- R0 avgblog; C:\Windows\system32\drivers\avgbloga.sys [336896 2017-08-10] (AVG Technologies CZ, s.r.o.)
- R0 avgbuniv; C:\Windows\system32\drivers\avgbuniva.sys [51336 2017-08-10] (AVG Technologies CZ, s.r.o.)
- S3 avgHwid; C:\Windows\system32\drivers\avgHwid.sys [39424 2017-08-10] (AVG Technologies CZ, s.r.o.)
- R2 avgMonFlt; C:\Windows\system32\drivers\avgMonFlt.sys [139112 2017-08-10] (AVG Technologies CZ, s.r.o.)
- R1 avgNetSec; C:\Windows\system32\drivers\avgNetSec.sys [546968 2017-08-10] (AVG Technologies CZ, s.r.o.)
- R1 avgRdr; C:\Windows\system32\drivers\avgRdr2.sys [102792 2017-08-10] (AVG Technologies CZ, s.r.o.)
- R0 avgRvrt; C:\Windows\system32\drivers\avgRvrt.sys [76832 2017-08-10] (AVG Technologies CZ, s.r.o.)
- R1 avgSnx; C:\Windows\system32\drivers\avgSnx.sys [1008288 2017-08-10] (AVG Technologies CZ, s.r.o.)
- R1 avgSP; C:\Windows\system32\drivers\avgSP.sys [578048 2017-08-10] (AVG Technologies CZ, s.r.o.)
- R2 avgStm; C:\Windows\system32\drivers\avgStm.sys [191208 2017-08-10] (AVG Technologies CZ, s.r.o.)
- R0 avgVmm; C:\Windows\system32\drivers\avgVmm.sys [353744 2017-08-10] (AVG Technologies CZ, s.r.o.)
- S3 cpuz143; C:\Users\User\AppData\Local\Temp\cpuz143\cpuz143_x64.sys [48952 2017-08-11] (CPUID) <==== ATTENTION
- R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77376 2017-08-10] ()
- U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2016-11-25] (Huawei Technologies Co., Ltd.)
- R3 igfx; C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_0745f11ce6fc197c\igdkmd64.sys [11033056 2016-11-01] (Intel Corporation)
- R2 MBAMChameleon; C:\Windows\system32\drivers\MBAMChameleon.sys [188352 2017-08-10] (Malwarebytes)
- R3 MBAMFarflt; C:\Windows\system32\drivers\farflt.sys [101784 2017-08-12] (Malwarebytes)
- R3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [45472 2017-08-12] (Malwarebytes)
- R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [253856 2017-08-12] (Malwarebytes)
- R3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [93600 2017-08-12] (Malwarebytes)
- R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [604160 2017-03-18] (Realtek )
- S3 SDFRd; C:\Windows\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
- S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation)
- S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation)
- S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation)
- R1 ZAM_Guard; C:\Windows\System32\drivers\zamguard64.sys [203680 2017-08-10] (Zemana Ltd.)
- ==================== NetSvcs (Whitelisted) ===================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- ==================== One Month Created files and folders ========
- (If an entry is included in the fixlist, the file/folder will be moved.)
- 2017-08-12 13:38 - 2017-08-12 13:38 - 000016935 _____ C:\Users\User\Desktop\FRST.txt
- 2017-08-12 13:37 - 2017-08-12 13:38 - 000000000 ____D C:\FRST
- 2017-08-12 13:37 - 2017-08-12 13:36 - 002381824 _____ (Farbar) C:\Users\User\Desktop\FRST64.exe
- 2017-08-12 02:43 - 2017-08-12 02:43 - 220079329 _____ C:\Users\User\Desktop\Tangokamp_1008_vecernjamilonga.zip
- 2017-08-12 02:29 - 2017-08-12 02:32 - 000000000 ____D C:\Users\User\Desktop\ona djevojka
- 2017-08-12 02:27 - 2017-08-12 13:36 - 000000000 ____D C:\Users\User\Desktop\masa
- 2017-08-12 02:17 - 2017-08-12 02:17 - 000000000 ____D C:\Users\User\Desktop\jefa
- 2017-08-12 01:56 - 2017-08-12 02:46 - 000000000 ____D C:\Users\User\Desktop\Tangokamp_1008_vecernjamilonga
- 2017-08-12 00:44 - 2017-08-12 00:44 - 000012872 _____ (SurfRight B.V.) C:\Windows\system32\bootdelete.exe
- 2017-08-12 00:40 - 2017-08-12 00:44 - 000000000 ____D C:\ProgramData\HitmanPro
- 2017-08-12 00:40 - 2017-08-12 00:40 - 011584088 _____ (SurfRight B.V.) C:\Users\User\Desktop\HitmanPro_x64.exe
- 2017-08-12 00:34 - 2017-08-12 00:34 - 051725936 _____ (Safer-Networking Ltd. ) C:\Users\User\Desktop\spybotsd-2.6.46.exe
- 2017-08-12 00:33 - 2017-08-12 00:33 - 000000000 ____D C:\Users\User\Downloads\RootkitRevealer
- 2017-08-12 00:32 - 2017-08-12 00:32 - 000231390 _____ C:\Users\User\Downloads\RootkitRevealer.zip
- 2017-08-12 00:23 - 2017-08-12 00:32 - 000000000 ____D C:\Users\User\Desktop\mbar
- 2017-08-12 00:23 - 2017-08-12 00:32 - 000000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
- 2017-08-12 00:23 - 2017-08-12 00:23 - 016563352 _____ (Malwarebytes Corp.) C:\Users\User\Desktop\mbar-1.09.3.1001.exe
- 2017-08-11 19:40 - 2017-08-11 19:40 - 000098095 _____ C:\Users\User\Downloads\12.-13.08.Schedule.pdf
- 2017-08-10 19:28 - 2017-08-12 13:38 - 000029038 _____ C:\Windows\ZAM_Guard.krnl.trace
- 2017-08-10 19:28 - 2017-08-12 13:35 - 000000000 ____D C:\Program Files (x86)\Zemana AntiMalware
- 2017-08-10 19:28 - 2017-08-12 00:57 - 001548463 _____ C:\Windows\ZAM.krnl.trace
- 2017-08-10 19:28 - 2017-08-10 19:28 - 000203680 _____ (Zemana Ltd.) C:\Windows\system32\Drivers\zamguard64.sys
- 2017-08-10 19:28 - 2017-08-10 19:28 - 000000000 ____D C:\Users\User\AppData\Local\Zemana
- 2017-08-10 19:27 - 2017-08-10 19:27 - 006589840 _____ (Zemana Ltd. ) C:\Users\User\Desktop\Zemana.AntiMalware.Setup.exe
- 2017-08-10 19:25 - 2017-08-10 19:25 - 000000000 ___HD C:\$AV_AVG
- 2017-08-10 18:19 - 2017-08-12 13:35 - 000065536 _____ C:\Windows\system32\Ikeext.etl
- 2017-08-10 18:19 - 2017-08-10 19:22 - 000004282 _____ C:\Windows\System32\Tasks\Antivirus Emergency Update
- 2017-08-10 18:19 - 2017-08-10 18:19 - 001008288 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgsnx.sys
- 2017-08-10 18:19 - 2017-08-10 18:19 - 000578048 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgSP.sys
- 2017-08-10 18:19 - 2017-08-10 18:19 - 000401584 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\avgBoot.exe
- 2017-08-10 18:19 - 2017-08-10 18:19 - 000353744 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgVmm.sys
- 2017-08-10 18:19 - 2017-08-10 18:19 - 000191208 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgStm.sys
- 2017-08-10 18:19 - 2017-08-10 18:19 - 000139112 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmonflt.sys
- 2017-08-10 18:19 - 2017-08-10 18:19 - 000102792 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgRdr2.sys
- 2017-08-10 18:19 - 2017-08-10 18:19 - 000076832 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgRvrt.sys
- 2017-08-10 18:19 - 2017-08-10 18:19 - 000039424 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgHwid.sys
- 2017-08-10 18:19 - 2017-08-10 18:19 - 000000000 ____D C:\Users\User\AppData\Roaming\AVG
- 2017-08-10 18:19 - 2017-08-10 18:18 - 000546968 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgNetSec.sys
- 2017-08-10 18:19 - 2017-08-10 18:18 - 000336896 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbloga.sys
- 2017-08-10 18:19 - 2017-08-10 18:18 - 000313616 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbidsdrivera.sys
- 2017-08-10 18:19 - 2017-08-10 18:18 - 000192584 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbidsha.sys
- 2017-08-10 18:19 - 2017-08-10 18:18 - 000166624 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbdiska.sys
- 2017-08-10 18:19 - 2017-08-10 18:18 - 000051336 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbuniva.sys
- 2017-08-10 18:17 - 2017-08-10 18:17 - 000000955 _____ C:\Users\Public\Desktop\AVG.lnk
- 2017-08-10 18:17 - 2017-08-10 18:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
- 2017-08-10 18:16 - 2017-08-11 18:35 - 000003668 _____ C:\Windows\System32\Tasks\AVG EUpdate Task
- 2017-08-10 18:16 - 2017-08-10 18:17 - 000000000 ____D C:\Program Files (x86)\AVG
- 2017-08-10 18:15 - 2017-08-10 19:09 - 000000000 ____D C:\ProgramData\Avg
- 2017-08-10 18:15 - 2017-08-10 18:19 - 000000000 ____D C:\Users\User\AppData\Local\Avg
- 2017-08-10 18:15 - 2017-08-10 18:17 - 000000000 ____D C:\Users\User\AppData\Local\AvgSetupLog
- 2017-08-10 18:15 - 2017-08-10 18:15 - 003449304 _____ (AVG Technologies CZ, s.r.o.) C:\Users\User\Desktop\AVG_Protection_Free_1606.exe
- 2017-08-10 18:15 - 2017-08-10 18:15 - 000000000 ____D C:\Users\User\AppData\Local\CEF
- 2017-08-10 18:08 - 2017-08-10 18:09 - 006673927 _____ C:\Users\User\Downloads\kavremvr.zip
- 2017-08-10 17:55 - 2017-08-10 18:11 - 000000000 ____D C:\Program Files\Common Files\AV
- 2017-08-10 17:29 - 2017-08-12 13:35 - 000253856 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
- 2017-08-10 17:29 - 2017-08-12 13:35 - 000101784 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
- 2017-08-10 17:29 - 2017-08-12 13:35 - 000093600 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
- 2017-08-10 17:29 - 2017-08-12 13:35 - 000045472 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
- 2017-08-10 17:29 - 2017-08-10 17:58 - 000188352 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys
- 2017-08-10 17:29 - 2017-08-10 17:58 - 000077376 _____ C:\Windows\system32\Drivers\mbae64.sys
- 2017-08-10 17:29 - 2017-08-10 17:29 - 000001912 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
- 2017-08-10 17:29 - 2017-08-10 17:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
- 2017-08-10 17:28 - 2017-08-12 00:23 - 000000000 ____D C:\ProgramData\Malwarebytes
- 2017-08-10 17:28 - 2017-08-10 17:28 - 064232976 _____ (Malwarebytes ) C:\Users\User\Downloads\mb3-setup-adwc.adwc100.3.1.2.1733.exe
- 2017-08-10 17:28 - 2017-08-10 17:28 - 000000000 ____D C:\Program Files\Malwarebytes
- 2017-08-10 17:26 - 2017-08-10 17:26 - 008185288 _____ (Malwarebytes) C:\Users\User\Downloads\adwcleaner_7.0.1.0 (1).exe
- 2017-08-10 17:25 - 2017-08-10 17:30 - 000000000 ____D C:\Users\User\AppData\Local\e3cbd7851d644b62a397ba42ba79e6df
- 2017-08-10 17:19 - 2017-08-10 17:31 - 000000000 ____D C:\ProgramData\80ab835377074b09a470b6bd6ff9bc30
- 2017-08-10 17:19 - 2017-08-10 17:30 - 000000000 ____D C:\Users\User\AppData\Local\ee59ec3a59de41fe897495297afb6e2f
- 2017-08-10 17:19 - 2017-08-10 17:19 - 000000258 __RSH C:\Users\User\ntuser.pol
- 2017-08-10 17:18 - 2017-08-10 19:21 - 000000000 ____D C:\ProgramData\Kaspersky Lab
- 2017-08-10 17:18 - 2017-08-10 17:30 - 000000320 _____ C:\Windows\Tasks\uuxHwpnMkRCRpJh.job
- 2017-08-10 17:18 - 2017-08-10 17:22 - 000000000 ____D C:\Users\User\AppData\Local\Chromium
- 2017-08-10 17:17 - 2017-08-10 17:31 - 000000000 ____D C:\Users\User\AppData\Local\58306b33f94b4eff939d08cb81d4efc6
- 2017-08-10 17:17 - 2017-08-10 17:17 - 000016802 _____ C:\Windows\System32\Tasks\PuralFudget
- 2017-08-10 17:17 - 2017-08-10 17:17 - 000002712 __RSH C:\ProgramData\ntuser.pol
- 2017-08-10 17:16 - 2017-08-10 17:21 - 000000000 ____D C:\Users\User\AppData\Local\cypjMERAky
- 2017-08-10 17:16 - 2017-08-10 17:16 - 002376368 _____ (Kaspersky Lab) C:\Users\User\Desktop\kfa18.0.0.405aben_12579.exe
- 2017-08-10 17:14 - 2017-08-10 17:14 - 000140800 _____ C:\Users\User\AppData\Local\installer.dat
- 2017-08-10 17:13 - 2017-08-12 00:07 - 000000000 ____D C:\Users\User\AppData\Roaming\IntelCpHDCPSvc store files
- 2017-08-10 17:13 - 2017-08-12 00:07 - 000000000 ____D C:\Users\User\AppData\Roaming\IntelCpHDCPSvc local files
- 2017-08-10 17:12 - 2017-08-12 00:07 - 000000000 ____D C:\ProgramData\Micro Foundation 2
- 2017-08-10 01:37 - 2017-08-10 01:40 - 000000000 ____D C:\Users\User\Desktop\kosarkaski kamp
- 2017-08-10 01:28 - 2017-08-10 01:28 - 000116705 _____ C:\Users\User\Downloads\09.-11.08.Schedule.pdf
- 2017-08-09 18:44 - 2017-08-09 20:12 - 000000000 ____D C:\Users\User\Desktop\Tangokamp_milonga_trg_male
- 2017-08-08 23:15 - 2017-08-08 23:38 - 126479948 _____ C:\Users\User\Desktop\Tangokamp_0808_casovi.zip
- 2017-08-08 22:43 - 2017-08-08 22:43 - 000000000 ____D C:\Users\User\Tracing
- 2017-08-08 22:36 - 2017-08-08 23:15 - 000000000 ____D C:\Users\User\Desktop\Tangokamp_0808_casovi
- 2017-08-08 20:50 - 2017-08-08 21:42 - 000000000 ____D C:\Users\User\Desktop\Tamara_racic
- 2017-08-07 22:26 - 2017-08-07 22:26 - 000000000 ____D C:\Users\User\AppData\Local\Viber
- 2017-08-07 22:24 - 2017-08-07 22:24 - 000000000 ____D C:\Windows\System32\Tasks\Intel
- 2017-08-07 22:23 - 2017-08-07 22:23 - 050269290 _____ C:\Users\User\Downloads\mb_driver_net_framework_4.5.zip
- 2017-08-07 22:23 - 2017-08-07 22:23 - 001652558 _____ C:\Users\User\Downloads\mb_driver_intel_bootdisk_irst_64_200series.zip
- 2017-08-07 22:22 - 2017-08-07 22:22 - 002721464 _____ C:\Users\User\Downloads\mb_driver_chipset_intel_200series.zip
- 2017-08-07 22:22 - 2017-08-07 22:22 - 000003738 _____ C:\Windows\System32\Tasks\Intel PTT EK Recertification
- 2017-08-07 22:22 - 2017-08-07 22:22 - 000000000 ____D C:\Users\User\Intel
- 2017-08-07 22:22 - 2017-08-07 22:22 - 000000000 ____D C:\ProgramData\Intel
- 2017-08-07 22:20 - 2017-08-07 22:21 - 081757207 _____ C:\Users\User\Downloads\mb_driver_intel_me_200series.zip
- 2017-08-07 20:01 - 2017-08-07 20:01 - 000124313 _____ C:\Users\User\Downloads\06.-08.08.Schedule (1).pdf
- 2017-08-07 18:14 - 2017-08-07 18:14 - 000250604 _____ C:\Users\User\Desktop\page0017.pdf
- 2017-08-07 17:46 - 2017-08-07 17:54 - 000000000 ____D C:\Users\User\Desktop\KUD_koncert_male_fb - Copy
- 2017-08-07 16:32 - 2017-08-07 16:33 - 000000000 ____D C:\Users\User\Desktop\daig skresem
- 2017-08-07 16:03 - 2017-08-07 16:19 - 000000000 ____D C:\Users\User\Desktop\KUD_koncert_male_fb
- 2017-08-07 02:23 - 2017-08-07 02:23 - 000000000 ____D C:\Users\User\Desktop\taaajna
- 2017-08-07 01:59 - 2017-08-07 01:59 - 256869362 _____ C:\Users\User\Desktop\TangoMilongaNaOtvorenom.zip
- 2017-08-07 01:21 - 2017-08-07 01:23 - 000000000 ____D C:\Users\User\Desktop\zzz
- 2017-08-07 01:16 - 2017-08-07 01:54 - 000000000 ____D C:\Users\User\Desktop\TangoMilongaNaOtvorenom
- 2017-08-07 01:09 - 2017-08-07 01:09 - 000124313 _____ C:\Users\User\Downloads\06.-08.08.Schedule.pdf
- 2017-08-06 23:25 - 2017-08-07 01:13 - 000000000 ____D C:\Users\User\Desktop\Dusan
- 2017-08-06 03:22 - 2017-08-06 03:41 - 000000000 ____D C:\Users\User\Desktop\Koncert_trk_na_trg_male
- 2017-08-06 02:38 - 2017-08-06 17:50 - 000000000 ____D C:\Users\User\Desktop\Koncert_trk_na_trg
- 2017-08-03 20:49 - 2017-08-03 20:50 - 000000000 ____D C:\Users\User\Desktop\drazen iks
- 2017-08-03 20:47 - 2017-08-03 20:47 - 000111864 _____ C:\Users\User\Downloads\03.-05.08.Schedule.pdf
- 2017-08-03 03:58 - 2017-08-03 03:58 - 100802914 _____ C:\Users\User\Desktop\Fotografije_izlozba.zip
- 2017-08-03 03:57 - 2017-08-03 03:57 - 100803054 _____ C:\Users\User\Desktop\Fotogorafije_izlozba.zip
- 2017-08-03 03:29 - 2017-08-04 18:24 - 000000000 ____D C:\Users\User\Desktop\Drazen_draskovic
- 2017-08-03 03:11 - 2017-08-03 03:56 - 000000000 ____D C:\Users\User\Desktop\Fotografije_izlozba
- 2017-08-03 02:15 - 2017-08-03 02:15 - 000000000 ____D C:\Users\User\Desktop\Igor_konj
- 2017-08-02 17:53 - 2017-08-02 17:53 - 000000000 ____D C:\Users\User\Documents\nove pEsme
- 2017-08-01 21:01 - 2017-08-01 21:08 - 000000000 ____D C:\Users\User\Desktop\mijau
- 2017-08-01 19:07 - 2017-08-02 00:33 - 000000000 ____D C:\Users\User\Desktop\koks
- 2017-08-01 16:58 - 2017-08-10 17:29 - 000000000 ____D C:\AdwCleaner
- 2017-08-01 16:58 - 2017-08-01 16:58 - 008185288 ____N (Malwarebytes) C:\Users\User\Downloads\adwcleaner_7.0.1.0.exe
- 2017-08-01 00:37 - 2017-08-01 00:37 - 109300945 _____ C:\Users\User\Desktop\Fotografije_tango_kamp.zip
- 2017-08-01 00:24 - 2017-08-01 00:34 - 000000000 ____D C:\Users\User\Desktop\Tango_kamp
- 2017-07-31 21:09 - 2017-07-31 21:11 - 000000000 ____D C:\Users\User\Desktop\Tango_kamp_strelicarstvo
- 2017-07-31 20:44 - 2017-08-12 02:41 - 000000000 ____D C:\Users\User\Desktop\Natalija
- 2017-07-31 01:41 - 2017-07-31 01:48 - 000000000 ____D C:\Users\User\Desktop\Promocija Knjige Dragan Kujović Brano Potpisane
- 2017-07-31 01:12 - 2017-07-31 01:35 - 000000000 ____D C:\Users\User\Desktop\Promocija Knjige Dragan Kujović Brano
- 2017-07-30 20:10 - 2017-07-30 18:38 - 313394225 _____ C:\Users\User\Desktop\Video Kolasin- Vedran Vujisic.mp4
- 2017-07-30 17:54 - 2017-07-30 20:05 - 001413710 _____ C:\Users\User\Desktop\final valjda.wve
- 2017-07-30 16:35 - 2017-07-30 17:31 - 001413709 _____ C:\Users\User\Desktop\idemo unapredjeno.wve
- 2017-07-30 14:52 - 2017-07-30 14:52 - 000003372 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-73300378-2398947947-2795111270-1001
- 2017-07-30 03:21 - 2017-07-30 03:21 - 080206530 _____ C:\Users\User\Desktop\logo i svega watermark.psd
- 2017-07-30 03:16 - 2017-07-30 03:16 - 004012045 _____ C:\Users\User\Downloads\SDI_R1771.zip
- 2017-07-30 02:44 - 2017-07-30 02:44 - 003337742 _____ C:\Users\User\Desktop\projekat video turisticka sve ojha.wve
- 2017-07-30 02:16 - 2017-07-30 02:16 - 003337728 _____ C:\Users\User\Desktop\video turisticka gotov watermark i svega.wve
- 2017-07-30 02:11 - 2017-08-01 01:37 - 000000132 _____ C:\Users\User\AppData\Roaming\Adobe PNG Format CS6 Prefs
- 2017-07-30 01:57 - 2017-07-30 02:10 - 003335218 _____ C:\Users\User\Desktop\video turisticka gotov.wve
- 2017-07-29 23:07 - 2017-07-29 23:07 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
- 2017-07-29 23:07 - 2017-07-29 23:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TP-LINK
- 2017-07-29 23:07 - 2013-10-16 07:56 - 000011756 _____ C:\Windows\system32\athuw8x.cat
- 2017-07-29 23:07 - 2013-06-02 18:07 - 002919936 _____ (Qualcomm Atheros Communications, Inc.) C:\Windows\system32\Drivers\athuw8x.sys
- 2017-07-29 23:07 - 2013-06-02 18:07 - 002919936 _____ (Qualcomm Atheros Communications, Inc.) C:\Windows\system32\athuw8x.sys
- 2017-07-29 23:01 - 2017-07-29 23:02 - 013206671 _____ C:\Users\User\Downloads\TL-WN722N_V1_131113.zip
- 2017-07-29 22:58 - 2017-07-29 22:59 - 021644308 _____ C:\Users\User\Downloads\TL-WN722N(US)_V2_161112_Windows.zip
- 2017-07-29 15:25 - 2017-08-11 17:23 - 000000000 ____D C:\Users\User\Desktop\brajka novo
- 2017-07-29 15:04 - 2017-08-10 01:41 - 000000000 ____D C:\Users\User\Desktop\Promocija Knjige Dragan Kujović FB slike
- 2017-07-29 02:57 - 2017-07-29 02:58 - 000000000 ____D C:\Users\User\Desktop\Sportske_prva_smjena
- 2017-07-29 02:56 - 2017-07-29 02:57 - 000000000 ____D C:\Users\User\Desktop\Sportske_druga_smjena
- 2017-07-29 01:22 - 2017-07-29 02:23 - 000000000 ____D C:\Users\User\Desktop\drazen draskovic sportske fotografije druga smjena
- 2017-07-29 01:12 - 2017-07-29 01:24 - 000000000 ____D C:\Users\User\Desktop\drazen draskovic sportske prva smjena
- 2017-07-28 22:35 - 2017-07-28 23:32 - 000000000 ____D C:\Users\User\Desktop\Promocija knjige o Draganu Kujoviću_1
- 2017-07-28 22:22 - 2017-07-28 22:32 - 000000000 ____D C:\Users\User\Desktop\Promocija knjige o Draganu Kujoviću
- 2017-07-28 21:36 - 2017-07-28 21:36 - 000000000 ____D C:\Users\User\Desktop\Test
- 2017-07-28 18:35 - 2017-07-30 01:56 - 003335149 _____ C:\Users\User\Desktop\projekat video.wve
- 2017-07-28 18:35 - 2017-07-28 18:35 - 001355706 _____ C:\Users\User\Documents\VE Project 1.wve
- 2017-07-28 16:56 - 2017-07-28 16:56 - 000001216 _____ C:\Users\Public\Desktop\Wondershare Filmora.lnk
- 2017-07-28 16:55 - 2017-07-28 18:35 - 000000000 ____D C:\Users\User\Documents\Wondershare Filmora
- 2017-07-28 16:55 - 2017-07-28 16:55 - 000000000 ____D C:\ProgramData\Wondershare Video Editor
- 2017-07-28 16:51 - 2017-07-28 16:51 - 000000000 ____D C:\Users\User\Desktop\filmova
- 2017-07-28 16:45 - 2017-07-28 16:48 - 000000000 ____D C:\Users\User\Downloads\Goran Cetkovic izlozba
- 2017-07-28 16:23 - 2017-07-30 00:36 - 000000000 ____D C:\Users\User\Desktop\video turisticka
- 2017-07-28 16:08 - 2017-07-28 16:08 - 000000000 ____D C:\Users\User\AppData\Local\NetworkTiles
- 2017-07-28 03:08 - 2017-07-28 03:08 - 000002868 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
- 2017-07-28 03:08 - 2017-07-28 03:08 - 000000863 _____ C:\Users\Public\Desktop\CCleaner.lnk
- 2017-07-28 03:08 - 2017-07-28 03:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
- 2017-07-28 03:07 - 2017-08-10 18:00 - 000000000 ____D C:\Program Files\CCleaner
- 2017-07-28 03:07 - 2017-07-28 03:07 - 006299336 ____N (Piriform Ltd) C:\Users\User\Downloads\spsetup131.exe
- 2017-07-28 03:07 - 2017-07-28 03:07 - 000000837 _____ C:\Users\Public\Desktop\Speccy.lnk
- 2017-07-28 03:07 - 2017-07-28 03:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
- 2017-07-28 03:07 - 2017-07-28 03:07 - 000000000 ____D C:\Program Files\Speccy
- 2017-07-28 03:00 - 2017-07-28 03:01 - 000000000 ____D C:\Users\User\Documents\oCam
- 2017-07-28 03:00 - 2017-07-28 03:00 - 008925808 ____N (hxxp://ohsoft.net/ ) C:\Users\User\Downloads\oCam_v414.0.exe
- 2017-07-28 03:00 - 2017-07-28 03:00 - 000001020 _____ C:\Users\User\Desktop\oCam.lnk
- 2017-07-28 03:00 - 2017-07-28 03:00 - 000000000 ____D C:\Users\User\AppData\Roaming\oCam
- 2017-07-28 03:00 - 2017-07-28 03:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\oCam
- 2017-07-28 03:00 - 2017-07-28 03:00 - 000000000 ____D C:\Program Files (x86)\oCam
- 2017-07-28 02:23 - 2017-07-28 02:23 - 000000000 ____D C:\Windows\System32\Tasks\S-1-5-21-73300378-2398947947-2795111270-1001
- 2017-07-28 01:59 - 2017-07-28 01:59 - 000000000 ____D C:\Users\User\Documents\mac
- 2017-07-27 23:50 - 2013-07-11 12:06 - 000123264 _____ (ZTE Incorporated) C:\Windows\system32\Drivers\ZTEusbmdm6k.sys
- 2017-07-27 19:16 - 2017-07-27 19:19 - 017223680 _____ C:\Users\User\Downloads\MicrosoftCameraCodecPack-x64.msi
- 2017-07-27 18:49 - 2017-07-27 18:49 - 003211153 _____ C:\Users\User\Desktop\Screenshot_17.psd
- 2017-07-26 17:17 - 2017-08-10 17:30 - 000000000 ____D C:\ProgramData\a9ae1abb7892436f9d91cc9c75f41177
- 2017-07-26 17:17 - 2017-07-26 17:17 - 000016866 _____ C:\Windows\System32\Tasks\HealthStom Poker Agent
- 2017-07-26 17:17 - 2017-07-26 17:17 - 000000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HT1H
- 2017-07-26 14:47 - 2017-07-26 14:47 - 000000000 ____D C:\Users\User\Desktop\ss
- 2017-07-25 22:54 - 2017-07-25 22:54 - 000000000 ____D C:\Users\User\Desktop\setupi
- 2017-07-25 21:38 - 2017-07-25 21:38 - 009607232 _____ C:\Users\User\Desktop\Visegrad1-1.psd
- 2017-07-25 21:24 - 2017-07-26 14:37 - 000000000 ____D C:\Users\User\Desktop\ISK12
- 2017-07-25 17:22 - 2017-07-25 17:29 - 000000000 ____D C:\Users\User\Desktop\ISK1
- 2017-07-25 17:01 - 2017-07-25 17:07 - 000000000 ____D C:\Users\User\Desktop\Visegrad
- 2017-07-25 12:04 - 2017-08-10 01:42 - 000000000 ____D C:\Users\User\Desktop\JELOVNIK I SVEGA
- 2017-07-24 15:03 - 2017-07-27 02:54 - 000000000 ____D C:\Users\User\Desktop\tamara1
- 2017-07-23 23:51 - 2017-07-24 02:02 - 000000000 ____D C:\Users\User\Desktop\Zvezde
- 2017-07-22 23:58 - 2017-07-22 23:58 - 000000111 _____ C:\Users\User\Desktop\xd.txt
- 2017-07-22 22:28 - 2017-08-01 20:55 - 000000000 ____D C:\Users\User\Desktop\export_stock
- 2017-07-21 16:02 - 2017-07-21 16:03 - 000000000 ____D C:\Users\User\Desktop\flaksibuks
- 2017-07-21 01:57 - 2017-07-20 22:19 - 096392081 _____ C:\Users\User\Desktop\Kosarkaski_kamp_video.mp4
- 2017-07-21 01:23 - 2017-07-21 01:23 - 000001447 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
- 2017-07-21 01:23 - 2017-07-21 01:23 - 000001378 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk
- 2017-07-21 01:23 - 2017-07-21 01:23 - 000001000 _____ C:\Users\Public\Desktop\Video Win Movie Maker.lnk
- 2017-07-21 01:23 - 2017-07-21 01:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Video Win Movie Maker
- 2017-07-21 01:23 - 2017-07-21 01:23 - 000000000 ____D C:\Program Files (x86)\Windows Live
- 2017-07-21 01:23 - 2017-07-21 01:23 - 000000000 ____D C:\Program Files (x86)\Video Win Movie Maker
- 2017-07-21 01:23 - 2010-06-02 04:55 - 000527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll
- 2017-07-21 01:23 - 2010-06-02 04:55 - 000518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
- 2017-07-21 01:23 - 2010-06-02 04:55 - 000077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
- 2017-07-21 01:23 - 2010-06-02 04:55 - 000074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll
- 2017-07-21 01:23 - 2010-05-26 11:41 - 002526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
- 2017-07-21 01:23 - 2010-05-26 11:41 - 002106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
- 2017-07-21 01:23 - 2010-05-26 11:41 - 000276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
- 2017-07-21 01:23 - 2010-05-26 11:41 - 000248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll
- 2017-07-20 23:22 - 2017-07-20 23:22 - 001213912 _____ C:\Users\User\Desktop\VE Project 1.wve
- 2017-07-20 20:56 - 2013-07-11 12:06 - 000123264 _____ (ZTE Incorporated) C:\Windows\system32\Drivers\ZTEusbser6k.sys
- 2017-07-20 20:56 - 2013-07-11 12:06 - 000123264 _____ (ZTE Incorporated) C:\Windows\system32\Drivers\ZTEusbnmea.sys
- 2017-07-20 20:21 - 2017-07-20 20:26 - 000000000 ____D C:\Users\User\Desktop\video materijal
- 2017-07-20 20:14 - 2017-07-30 17:51 - 000006971 _____ C:\Users\User\Documents\starburn.txt
- 2017-07-20 19:29 - 2017-07-20 19:34 - 000000000 ____D C:\Users\User\Documents\fleska 8gb
- 2017-07-20 02:30 - 2017-07-20 19:58 - 000000000 ____D C:\Users\User\Desktop\Fb_maca
- 2017-07-20 02:06 - 2017-07-20 02:06 - 000000000 ____D C:\Users\User\Desktop\Marko
- 2017-07-20 01:57 - 2017-07-20 02:00 - 000000000 ____D C:\Users\User\Desktop\rov
- 2017-07-19 23:36 - 2017-07-19 23:36 - 000000014 _____ C:\Users\User\Documents\ime.txt
- 2017-07-19 22:32 - 2017-07-19 22:32 - 000000000 ____D C:\Users\User\Desktop\lajtrum
- 2017-07-19 15:08 - 2017-07-19 15:10 - 000000000 ____D C:\Users\User\Desktop\Fotosi_fb_export
- 2017-07-19 15:06 - 2017-07-19 15:06 - 000000000 ____D C:\Users\User\Desktop\fotosifb
- 2017-07-19 14:47 - 2017-07-19 14:47 - 052563702 _____ C:\Users\User\Desktop\Marko111-1-Recovered.psd
- 2017-07-18 21:52 - 2017-07-29 01:11 - 000000000 ____D C:\Users\User\Desktop\prva smejna
- 2017-07-18 15:57 - 2017-07-18 16:03 - 000000000 ____D C:\Users\User\Desktop\xs
- 2017-07-18 15:50 - 2017-07-18 15:50 - 000017526 _____ C:\Users\User\Downloads\times_roman_cirilica.zip
- 2017-07-18 13:09 - 2017-07-18 13:09 - 000010352 _____ C:\Users\User\Downloads\Rezultati-testa.xlsx
- 2017-07-17 22:37 - 2017-07-17 22:37 - 001117805 _____ C:\Users\User\Downloads\JEK_3864.jfif
- 2017-07-17 03:09 - 2017-07-17 03:09 - 000004588 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
- 2017-07-17 02:08 - 2017-07-17 02:08 - 000000000 ____D C:\Users\User\Desktop\predavanje antica
- 2017-07-16 18:52 - 2017-07-16 18:52 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Printers
- 2017-07-16 18:52 - 2017-07-16 18:52 - 000000000 ____D C:\ProgramData\Samsung
- 2017-07-16 18:52 - 2017-07-16 18:52 - 000000000 ____D C:\Program Files (x86)\Samsung
- 2017-07-16 18:52 - 2014-05-22 15:22 - 002738496 ____N C:\Windows\TotalUninstaller.exe
- 2017-07-16 18:51 - 2014-07-03 06:07 - 000000357 _____ C:\Windows\system32\usp01l.smt
- 2017-07-16 18:51 - 2014-04-16 10:22 - 000029184 _____ () C:\Windows\system32\usp01l.dll
- 2017-07-16 18:51 - 2013-05-10 11:48 - 000162136 _____ C:\Windows\system32\usp01ci.exe
- 2017-07-16 18:51 - 2010-10-20 10:46 - 000089600 _____ (SS) C:\Windows\system32\usp01ci.dll
- 2017-07-16 18:50 - 2017-07-16 18:50 - 021294762 _____ C:\Users\User\Downloads\samsung_universal_printer_2_50_05_00_10_driver.zip
- 2017-07-16 15:11 - 2017-07-17 01:35 - 000000000 ____D C:\Users\User\Desktop\drazen draskovic
- 2017-07-15 20:47 - 2017-07-15 20:48 - 000000000 ____D C:\Users\User\Documents\xd111
- 2017-07-15 14:14 - 2017-07-16 18:25 - 000000000 ____D C:\Users\User\Desktop\Biogradsko
- 2017-07-15 14:08 - 2017-07-15 14:12 - 000000000 ____D C:\Users\User\Desktop\MojaCg
- 2017-07-15 01:32 - 2017-07-15 01:36 - 000000000 ____D C:\FFOutput
- 2017-07-15 01:31 - 2017-07-15 01:31 - 000001136 _____ C:\Users\User\Desktop\Format Factory.lnk
- 2017-07-15 01:31 - 2017-07-15 01:31 - 000000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
- 2017-07-15 01:31 - 2017-07-15 01:31 - 000000000 ____D C:\Program Files (x86)\FormatFactory
- 2017-07-15 01:21 - 2017-07-15 01:48 - 000000000 ____D C:\Users\User\Documents\poligonske radnje
- 2017-07-15 00:23 - 2017-07-15 00:38 - 000000000 ____D C:\Users\User\Documents\predavanje sportskog psihologa druga smjena
- 2017-07-15 00:19 - 2017-07-15 00:23 - 000000000 ____D C:\Users\User\Documents\video i svega
- 2017-07-14 14:45 - 2017-07-20 02:10 - 000000000 ____D C:\Users\User\Desktop\veci šinko
- 2017-07-14 03:43 - 2017-07-14 03:49 - 000000000 ____D C:\Users\User\Desktop\Ljetnja_skola
- 2017-07-14 02:13 - 2017-07-14 02:14 - 000000000 ____D C:\Users\User\Desktop\New folder (3)
- 2017-07-13 13:30 - 2017-07-13 13:31 - 000000000 ____D C:\Users\User\Desktop\New folder (2)
- 2017-07-13 12:00 - 2017-08-12 13:36 - 000000000 ____D C:\Users\User\Documents\ViberDownloads
- 2017-07-13 12:00 - 2017-08-12 13:36 - 000000000 ____D C:\Users\User\AppData\Roaming\ViberPC
- 2017-07-13 12:00 - 2017-07-13 12:00 - 000001028 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Viber.lnk
- 2017-07-13 12:00 - 2017-07-13 12:00 - 000001026 _____ C:\Users\User\Desktop\Viber.lnk
- 2017-07-13 12:00 - 2017-07-13 12:00 - 000000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Viber
- 2017-07-13 12:00 - 2017-07-13 12:00 - 000000000 ____D C:\Users\User\AppData\Local\Viber Media S.à r.l
- 2017-07-13 12:00 - 2017-07-13 12:00 - 000000000 ____D C:\Users\User\AppData\Local\Package Cache
- ==================== One Month Modified files and folders ========
- (If an entry is included in the fixlist, the file/folder will be moved.)
- 2017-08-12 13:35 - 2017-07-07 10:30 - 000000000 __SHD C:\Users\User\IntelGraphicsProfiles
- 2017-08-12 13:35 - 2017-05-09 01:02 - 000000006 ____H C:\Windows\Tasks\SA.DAT
- 2017-08-12 13:35 - 2017-03-18 23:03 - 000000000 ____D C:\Windows\tracing
- 2017-08-12 03:38 - 2017-07-07 23:43 - 000000000 ____D C:\Users\User\AppData\Roaming\AIMP
- 2017-08-12 03:38 - 2017-03-18 13:40 - 001048576 _____ C:\Windows\system32\config\BBI
- 2017-08-12 03:17 - 2017-03-18 23:03 - 000000000 ____D C:\Windows\LiveKernelReports
- 2017-08-12 01:57 - 2017-07-07 10:26 - 000000000 ____D C:\Users\User\AppData\Roaming\Skype
- 2017-08-12 00:12 - 2017-05-09 01:02 - 000000000 ____D C:\Windows\system32\SleepStudy
- 2017-08-10 19:30 - 2017-05-09 01:08 - 001392118 _____ C:\Windows\system32\PerfStringBackup.INI
- 2017-08-10 19:21 - 2017-03-18 23:01 - 000000000 ____D C:\Windows\INF
- 2017-08-10 18:11 - 2017-03-18 23:03 - 000000000 ___HD C:\Windows\ELAMBKUP
- 2017-08-10 17:43 - 2017-05-09 02:02 - 000000000 ____D C:\Windows\Panther
- 2017-08-10 17:29 - 2017-07-07 21:41 - 000002248 _____ C:\Users\Public\Desktop\Google Chrome.lnk
- 2017-08-10 17:29 - 2017-07-07 21:41 - 000002248 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
- 2017-08-10 17:27 - 2017-07-07 19:38 - 000003958 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1499449117
- 2017-08-10 17:27 - 2017-07-07 19:38 - 000001078 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera Browser.lnk
- 2017-08-10 17:27 - 2017-07-07 19:38 - 000000000 ____D C:\Program Files\Opera
- 2017-08-10 17:17 - 2017-03-18 23:03 - 000000000 ____D C:\Windows\system32\GroupPolicy
- 2017-08-10 17:17 - 2017-03-18 23:03 - 000000000 ____D C:\Program Files\Windows Portable Devices
- 2017-08-08 22:43 - 2017-07-08 00:32 - 000000000 ____D C:\ProgramData\Skype
- 2017-08-07 22:23 - 2017-07-08 00:32 - 000000000 ____D C:\ProgramData\Package Cache
- 2017-08-07 22:23 - 2017-07-07 10:30 - 000000000 ____D C:\Program Files\Intel
- 2017-08-07 22:22 - 2017-07-07 10:30 - 000000000 ____D C:\Program Files (x86)\Intel
- 2017-07-30 14:52 - 2017-05-09 01:14 - 000002360 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
- 2017-07-30 14:52 - 2017-05-09 01:14 - 000000000 ___RD C:\Users\User\OneDrive
- 2017-07-30 02:56 - 2017-07-11 22:33 - 000000000 ____D C:\Users\User\AppData\Roaming\Convertilla
- 2017-07-29 23:00 - 2017-07-07 19:03 - 000000000 ____D C:\ProgramData\TP-LINK
- 2017-07-29 00:18 - 2017-05-09 01:12 - 000000000 ____D C:\Users\User\AppData\Roaming\Adobe
- 2017-07-28 16:56 - 2017-07-12 03:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare
- 2017-07-28 16:55 - 2017-07-12 02:59 - 000000000 ____D C:\Program Files (x86)\Wondershare
- 2017-07-28 02:34 - 2017-03-18 23:03 - 000000000 ____D C:\Windows\system32\NDF
- 2017-07-28 01:57 - 2017-07-07 20:20 - 000000000 ___RD C:\Users\User\Documents\a sve pjesme
- 2017-07-28 00:39 - 2017-07-07 19:09 - 000000000 ____D C:\Windows\SysWOW64\SupportAppCB
- 2017-07-26 17:17 - 2017-03-18 23:03 - 000000000 ____D C:\Program Files\Windows NT
- 2017-07-20 20:41 - 2017-05-09 01:02 - 005025424 _____ C:\Windows\system32\FNTCACHE.DAT
- 2017-07-17 03:09 - 2017-07-07 19:18 - 000000000 ____D C:\Users\User\AppData\Local\Adobe
- 2017-07-17 03:09 - 2017-03-18 23:03 - 000000000 ____D C:\Windows\SysWOW64\Macromed
- 2017-07-17 03:09 - 2017-03-18 23:03 - 000000000 ____D C:\Windows\system32\Macromed
- 2017-07-14 19:38 - 2017-07-07 23:19 - 000000000 ____D C:\Users\User\Documents\Lightshot
- 2017-07-13 14:05 - 2017-07-11 23:41 - 000000000 ____D C:\Users\User\Documents\2017-07-05 KKamp_cetvrtidan_psiholog_predavanje
- 2017-07-13 13:30 - 2017-07-12 13:59 - 000000000 ____D C:\Users\User\Desktop\treneri
- ==================== Files in the root of some directories =======
- 2017-07-30 02:11 - 2017-08-01 01:37 - 000000132 _____ () C:\Users\User\AppData\Roaming\Adobe PNG Format CS6 Prefs
- 2017-08-10 17:14 - 2017-08-10 17:14 - 000140800 _____ () C:\Users\User\AppData\Local\installer.dat
- 2017-07-07 23:18 - 2017-07-07 23:18 - 000000003 _____ () C:\Users\User\AppData\Local\updater.log
- 2017-07-07 23:18 - 2017-07-07 23:18 - 000000425 _____ () C:\Users\User\AppData\Local\UserProducts.xml
- Some files in TEMP:
- ====================
- 2017-08-12 00:56 - 2017-08-12 00:40 - 011584088 _____ (SurfRight B.V.) C:\Users\User\AppData\Local\Temp\HitmanPro.exe
- 2017-08-12 00:33 - 2017-08-12 00:33 - 000551808 _____ (Sysinternals - www.sysinternals.com) C:\Users\User\AppData\Local\Temp\RBGVJVRH.exe
- 2017-08-12 00:32 - 2017-08-12 00:32 - 000457600 _____ (Sysinternals - www.sysinternals.com) C:\Users\User\AppData\Local\Temp\XHVAJPLVOV.exe
- ==================== Bamital & volsnap ======================
- (There is no automatic fix for files that do not pass verification.)
- C:\Windows\system32\winlogon.exe => File is digitally signed
- C:\Windows\system32\wininit.exe => File is digitally signed
- C:\Windows\explorer.exe => File is digitally signed
- C:\Windows\SysWOW64\explorer.exe => File is digitally signed
- C:\Windows\system32\svchost.exe => File is digitally signed
- C:\Windows\SysWOW64\svchost.exe => File is digitally signed
- C:\Windows\system32\services.exe => File is digitally signed
- C:\Windows\system32\User32.dll => File is digitally signed
- C:\Windows\SysWOW64\User32.dll => File is digitally signed
- C:\Windows\system32\userinit.exe => File is digitally signed
- C:\Windows\SysWOW64\userinit.exe => File is digitally signed
- C:\Windows\system32\rpcss.dll => File is digitally signed
- C:\Windows\system32\dnsapi.dll => File is digitally signed
- C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
- C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
- LastRegBack: 2017-08-08 01:24
- ==================== End of FRST.txt ============================
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement