Provera laptopa.

Provera laptopa.

offline
  • Istrazivanje Windowsa
  • Pridružio: 12 Jul 2012
  • Poruke: 1023

Napisano: 07 Sep 2014 20:02

Nesto mi laptop poceo da koci.Radi dobro pola sata i onda pocne da koci.

Evo:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 07-09-2014 01
Ran by Metallica41 (administrator) on FIKO on 07-09-2014 19:53:08
Running from C:\Users\Metallica41\Downloads
Platform: Windows 8.1 (X64) OS Language: English (United Kingdom)
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-t.....scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgfws.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20573_x64__8wekyb3d8bbwe\livecomm.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\WinStore\WSHost.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_179.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_179.exe
(Microsoft Corporation) C:\Windows\System32\audiodg.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ACMON] => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [90832 2012-06-07] (ASUS)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40312 2013-12-18] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5264016 2012-08-16] (VIA)
HKLM-x32\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [366720 2012-08-23] (Alcor Micro Corp.)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.)
HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\AsusWSPanel.exe [3417984 2012-08-28] (ASUS Cloud Corporation)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5188112 2014-08-25] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [PWRISOVM.EXE] => C:\Program Files (x86)\PowerISO\PWRISOVM.EXE [337432 2013-07-22] (Power Software Ltd)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-473922799-1250382268-3828485289-1001\...\Run: [uTorrent] => C:\Users\Metallica41\AppData\Roaming\uTorrent\uTorrent.exe [1431888 2014-08-21] (BitTorrent Inc.)
HKU\S-1-5-21-473922799-1250382268-3828485289-1001\...\MountPoints2: F - "F:\autorun.exe" -auto
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk
ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe (ASUSTeK Computer Inc.)
ShellIconOverlayIdentifiers: AsusWSShellExt_B -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: AsusWSShellExt_O -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: AsusWSShellExt_U -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4D} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://asus13.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus13.msn.com
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\Metallica41\AppData\Roaming\Mozilla\Firefox\Profiles\2qoqogpq.default
FF Homepage: https://www.google.rs/
FF Keyword.URL: user_pref("keyword.URL", "");
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_14_0_0_179.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Metallica41\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

Chrome:
=======

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS)
R2 avgfws; C:\Program Files (x86)\AVG\AVG2014\avgfws.exe [1417160 2014-08-25] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3242000 2014-08-25] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [289328 2014-08-25] (AVG Technologies CZ, s.r.o.)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
S3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [44032 2013-08-22] (Microsoft Corporation)
S3 lfsvc; C:\Windows\SysWOW64\GeofenceMonitorService.dll [357376 2014-07-18] (Microsoft Corporation)
S2 Netlogon; C:\Windows\SysWOW64\netlogon.dll [688640 2014-07-18] (Microsoft Corporation)
S3 smphost; C:\Windows\SysWOW64\smphost.dll [11776 2013-08-22] (Microsoft Corporation)
S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18944 2013-08-22] (Microsoft Corporation)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27792 2012-08-14] (VIA Technologies, Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-07-18] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-07-18] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [65784 2013-04-16] (ASUS Corporation)
S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [20496 2013-09-04] (AVG Technologies CZ, s.r.o.)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [152344 2014-06-30] (AVG Technologies CZ, s.r.o.)
R1 Avgfwfd; C:\Windows\system32\DRIVERS\avgfwd6a.sys [57144 2013-09-26] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [244504 2014-07-21] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [190744 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [235800 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [328984 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123672 2014-08-06] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [270104 2014-06-30] (AVG Technologies CZ, s.r.o.)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( )
S3 nmwcdx64; C:\Windows\system32\drivers\ccdcmbx64.sys [18432 2008-05-02] (Nokia)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-07-18] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-07 19:53 - 2014-09-07 19:53 - 00014003 _____ () C:\Users\Metallica41\Downloads\FRST.txt
2014-09-07 19:52 - 2014-09-07 19:53 - 00000000 ____D () C:\FRST
2014-09-07 19:52 - 2014-09-07 19:52 - 02105344 _____ (Farbar) C:\Users\Metallica41\Downloads\FRST64.exe
2014-09-05 23:39 - 2014-09-05 23:39 - 00007974 _____ () C:\Users\Metallica41\Documents\MassEffectConfigReport2014-09-05.xml
2014-09-05 23:32 - 2014-09-05 23:32 - 00034769 _____ () C:\Users\Metallica41\Downloads\Ty00_QuickSave.MassEffectSave
2014-09-05 23:32 - 2014-09-05 23:32 - 00023300 _____ () C:\Users\Metallica41\Downloads\Char_01-54-2-2-0-26-12-2009-48-17.MassEffectSave
2014-09-03 18:35 - 2014-09-03 18:35 - 12465681 _____ () C:\Users\Metallica41\Desktop\clip0013.mp4
2014-09-03 18:29 - 2014-09-03 18:30 - 00000000 ____D () C:\Users\Metallica41\Documents\Freemake
2014-09-03 18:29 - 2014-09-03 18:30 - 00000000 ____D () C:\ProgramData\Freemake
2014-09-03 18:29 - 2014-09-03 18:29 - 00001338 _____ () C:\Users\Public\Desktop\Freemake Video Converter.lnk
2014-09-03 18:29 - 2014-09-03 18:29 - 00000000 ____D () C:\Users\Metallica41\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake
2014-09-03 18:29 - 2014-09-03 18:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freemake
2014-09-03 18:29 - 2014-09-03 18:29 - 00000000 ____D () C:\Program Files (x86)\Freemake
2014-09-03 18:26 - 2014-09-03 18:26 - 01268632 _____ (Ellora Assets Corporation ) C:\Users\Metallica41\Downloads\FreemakeVideoConverterSetup.exe
2014-09-01 15:24 - 2014-09-01 15:24 - 00000000 ____D () C:\Users\Metallica41\AppData\Roaming\Oracle
2014-09-01 15:23 - 2014-09-01 15:23 - 00004578 _____ () C:\WINDOWS\SysWOW64\jupdate-1.7.0_67-b01.log
2014-09-01 15:23 - 2014-09-01 15:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-09-01 15:23 - 2014-07-25 12:55 - 00098216 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2014-09-01 15:23 - 2014-07-25 12:49 - 00272808 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaws.exe
2014-09-01 15:23 - 2014-07-25 12:49 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaw.exe
2014-09-01 15:23 - 2014-07-25 12:49 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\java.exe
2014-09-01 15:20 - 2014-09-01 15:20 - 00918952 _____ (Oracle Corporation) C:\Users\Metallica41\Downloads\jxpiinstall(1).exe
2014-08-31 12:02 - 2014-08-31 12:02 - 00000000 ____D () C:\Users\Metallica41\AppData\Roaming\Unity
2014-08-31 12:02 - 2014-08-31 12:02 - 00000000 ____D () C:\Users\Metallica41\AppData\Roaming\.mono
2014-08-31 12:02 - 2014-08-31 12:02 - 00000000 ____D () C:\ProgramData\.mono
2014-08-31 12:00 - 2014-09-07 12:27 - 00000236 _____ () C:\Users\Metallica41\BullseyeCoverageError.txt
2014-08-31 12:00 - 2014-08-31 12:00 - 00000000 ____D () C:\Users\Metallica41\AppData\Local\Unity
2014-08-31 11:59 - 2014-08-31 11:59 - 01202032 _____ (Unity Technologies ApS) C:\Users\Metallica41\Downloads\UnityWebPlayer.exe
2014-08-31 11:58 - 2014-08-31 11:58 - 00918952 _____ (Oracle Corporation) C:\Users\Metallica41\Downloads\jxpiinstall.exe
2014-08-28 10:35 - 2014-08-23 01:42 - 04148224 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2014-08-26 23:25 - 2014-08-26 23:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Counter-Strike PRO
2014-08-26 22:47 - 2014-08-26 22:58 - 275930179 _____ () C:\Users\Metallica41\Downloads\CS-Professional.exe
2014-08-24 22:12 - 2014-08-24 22:12 - 00000000 ____D () C:\Users\Metallica41\Desktop\CALI BLA BLA
2014-08-24 19:57 - 2014-08-24 22:13 - 00000000 ____D () C:\Users\Metallica41\Downloads\Californication Season 2
2014-08-23 22:48 - 2014-08-23 22:48 - 00000000 ____D () C:\ProgramData\Electronic Arts
2014-08-19 00:02 - 2014-08-19 00:02 - 00000000 ____D () C:\Users\Metallica41\AppData\Local\Adobe
2014-08-16 16:50 - 2014-08-16 16:50 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_ccdcmbx64_01005.Wdf
2014-08-13 20:02 - 2014-08-28 23:33 - 00002806 _____ () C:\Users\Metallica41\Desktop\New Text Document (2).txt
2014-08-13 07:02 - 2014-07-25 15:52 - 23645696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-08-13 07:02 - 2014-07-25 14:25 - 02774528 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-08-13 07:02 - 2014-07-25 13:59 - 00758272 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2014-08-13 07:02 - 2014-07-25 13:40 - 00452096 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2014-08-13 07:02 - 2014-07-25 13:28 - 05824512 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-08-13 07:02 - 2014-07-25 13:21 - 02184704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2014-08-13 07:02 - 2014-07-25 13:17 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-08-13 07:02 - 2014-07-25 13:10 - 00292864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2014-08-13 07:02 - 2014-07-25 13:06 - 04204032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2014-08-13 07:02 - 2014-07-25 12:52 - 00367104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2014-08-13 07:02 - 2014-07-25 12:47 - 00631808 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-08-13 07:02 - 2014-07-25 12:39 - 02087936 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-08-13 07:02 - 2014-07-25 12:34 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2014-08-13 07:02 - 2014-07-25 12:29 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2014-08-13 07:02 - 2014-07-25 12:23 - 13547008 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-08-13 07:02 - 2014-07-25 12:13 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2014-08-13 07:02 - 2014-07-25 12:07 - 02001920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2014-08-13 07:02 - 2014-07-25 12:03 - 11772928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2014-08-13 07:02 - 2014-07-25 11:26 - 01431040 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-08-13 07:02 - 2014-07-25 11:17 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2014-08-13 07:02 - 2014-07-25 11:09 - 00704512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2014-08-13 07:02 - 2014-07-25 11:00 - 01169920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2014-08-13 07:02 - 2014-07-15 19:16 - 03048880 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2014-08-13 07:02 - 2014-07-15 09:29 - 03118080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll
2014-08-13 07:02 - 2014-07-15 09:22 - 02861056 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebSync.dll
2014-08-13 07:02 - 2014-07-15 09:03 - 02344448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll
2014-08-13 07:01 - 2014-07-25 14:51 - 17524224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-08-13 07:01 - 2014-07-25 14:28 - 00548352 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2014-08-13 07:01 - 2014-07-25 14:25 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2014-08-13 07:01 - 2014-07-25 13:34 - 00455168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2014-08-13 07:01 - 2014-07-25 13:30 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2014-08-13 07:01 - 2014-07-25 13:28 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\JavaScriptCollectionAgent.dll
2014-08-13 07:01 - 2014-07-25 13:08 - 00597504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2014-08-13 07:01 - 2014-07-25 12:43 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2014-08-13 07:01 - 2014-07-25 12:43 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JavaScriptCollectionAgent.dll
2014-08-13 07:01 - 2014-07-25 12:42 - 00692736 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-08-13 07:01 - 2014-07-25 12:09 - 00291840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2014-08-13 07:01 - 2014-07-25 11:52 - 02266624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-08-13 07:01 - 2014-07-25 11:05 - 01792512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2014-08-13 07:00 - 2014-06-20 02:48 - 01273184 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2014-08-13 07:00 - 2014-06-20 00:52 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2014-08-13 07:00 - 2014-06-13 02:15 - 00517528 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2014-08-13 07:00 - 2014-06-13 02:14 - 01557848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2014-08-13 07:00 - 2014-06-13 01:10 - 00406400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2014-08-13 07:00 - 2014-06-06 12:34 - 02133504 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2014-08-13 06:57 - 2014-05-31 07:27 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2014-08-13 06:57 - 2014-05-13 08:01 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\BulkOperationHost.exe
2014-08-13 06:57 - 2014-05-13 06:07 - 02844160 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2014-08-13 06:57 - 2014-05-13 05:41 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbici.dll
2014-08-13 06:57 - 2014-05-13 05:26 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveShell.dll
2014-08-13 06:57 - 2014-05-13 04:59 - 01035264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2014-08-13 06:57 - 2014-05-13 04:31 - 00265216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SkyDriveShell.dll
2014-08-13 06:57 - 2014-05-03 12:29 - 01726224 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2014-08-13 06:57 - 2014-05-03 10:20 - 01473080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2014-08-13 06:57 - 2014-05-03 06:36 - 00997888 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2014-08-13 06:57 - 2014-05-03 06:19 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncobjapi.dll
2014-08-13 06:57 - 2014-05-03 06:08 - 00301056 _____ (Microsoft Corporation) C:\WINDOWS\system32\framedynos.dll
2014-08-13 06:57 - 2014-05-03 06:07 - 00262656 _____ (Microsoft Corporation) C:\WINDOWS\system32\framedyn.dll
2014-08-13 06:57 - 2014-05-03 05:46 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncobjapi.dll
2014-08-13 06:57 - 2014-05-03 05:37 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\framedynos.dll
2014-08-13 06:57 - 2014-05-03 05:37 - 00207360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\framedyn.dll
2014-08-13 06:57 - 2014-05-03 00:26 - 00050745 _____ () C:\WINDOWS\system32\srms.dat
2014-08-13 06:57 - 2014-05-01 06:44 - 01025536 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2014-08-13 06:57 - 2014-04-30 07:43 - 00071680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vwififlt.sys
2014-08-13 06:57 - 2014-04-30 07:41 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2014-08-13 06:57 - 2014-04-30 07:41 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\agilevpn.sys
2014-08-13 06:57 - 2014-04-30 07:41 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vwifimp.sys
2014-08-13 06:57 - 2014-04-30 06:45 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Robocopy.exe
2014-08-13 06:57 - 2014-04-30 05:48 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Robocopy.exe
2014-08-13 06:57 - 2014-04-30 05:24 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcsvc6.dll
2014-08-13 06:57 - 2014-04-30 05:23 - 00353280 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore.dll
2014-08-13 06:57 - 2014-04-30 05:23 - 00271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore6.dll
2014-08-13 06:57 - 2014-04-30 05:23 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcsvc.dll
2014-08-13 06:57 - 2014-04-30 05:14 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2014-08-13 06:57 - 2014-04-30 04:59 - 01063424 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2014-08-13 06:57 - 2014-04-30 04:46 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore.dll
2014-08-13 06:57 - 2014-04-30 04:46 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore6.dll
2014-08-13 06:57 - 2014-04-30 04:46 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcsvc6.dll
2014-08-13 06:57 - 2014-04-30 04:45 - 00062976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcsvc.dll
2014-08-13 06:57 - 2014-04-30 04:42 - 00403968 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll
2014-08-13 06:57 - 2014-04-28 23:40 - 00721408 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2014-08-13 06:57 - 2014-04-26 23:03 - 02140888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2014-08-13 06:57 - 2014-04-26 21:14 - 02144984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2014-08-13 06:57 - 2014-04-26 17:39 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2014-08-13 06:57 - 2014-04-14 10:37 - 02125344 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2014-08-13 06:57 - 2014-04-14 09:08 - 01797896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2014-08-13 06:57 - 2014-04-14 06:18 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d8thk.dll
2014-08-13 06:57 - 2014-04-09 07:11 - 00226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebClnt.dll
2014-08-13 06:57 - 2014-04-09 06:20 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WebClnt.dll
2014-08-13 06:56 - 2014-08-07 03:12 - 01336624 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2014-08-13 06:56 - 2014-08-06 23:38 - 00697856 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll
2014-08-13 06:56 - 2014-08-02 06:44 - 00527360 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2014-08-13 06:56 - 2014-08-02 04:56 - 01064448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2014-08-13 06:56 - 2014-08-02 04:11 - 00918528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2014-08-13 06:56 - 2014-07-12 05:17 - 00623616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAgent.exe
2014-08-13 06:56 - 2014-07-10 05:16 - 00716800 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveTelemetry.dll
2014-08-13 06:56 - 2014-07-10 05:03 - 04756992 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll
2014-08-13 06:56 - 2014-07-10 04:33 - 01120256 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe
2014-08-13 06:56 - 2014-06-09 23:13 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2014-08-13 06:56 - 2014-06-09 23:13 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2014-08-13 06:54 - 2014-06-04 10:27 - 00114520 _____ (Microsoft Corporation) C:\WINDOWS\system32\consent.exe
2014-08-13 06:54 - 2014-06-04 06:31 - 00356352 _____ (Microsoft Corporation) C:\WINDOWS\system32\msihnd.dll
2014-08-13 06:54 - 2014-06-04 06:22 - 02790912 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2014-08-13 06:54 - 2014-06-04 05:43 - 00281088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msihnd.dll
2014-08-13 06:54 - 2014-06-04 05:38 - 03304448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2014-08-13 06:54 - 2014-06-04 03:15 - 02642944 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2014-08-13 06:54 - 2014-06-04 03:14 - 02318336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2014-08-11 19:39 - 2014-08-16 16:50 - 00001779 _____ () C:\WINDOWS\setupact.log
2014-08-11 19:39 - 2014-08-11 19:39 - 00000000 _____ () C:\WINDOWS\setuperr.log
2014-08-11 09:02 - 2014-08-30 08:46 - 00337840 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-08-11 09:02 - 2014-08-20 09:59 - 00004574 _____ () C:\WINDOWS\PFRO.log
2014-08-08 10:41 - 2014-09-07 19:52 - 01953862 _____ () C:\WINDOWS\WindowsUpdate.log

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-07 19:53 - 2014-09-07 19:53 - 00014003 _____ () C:\Users\Metallica41\Downloads\FRST.txt
2014-09-07 19:53 - 2014-09-07 19:52 - 00000000 ____D () C:\FRST
2014-09-07 19:52 - 2014-09-07 19:52 - 02105344 _____ (Farbar) C:\Users\Metallica41\Downloads\FRST64.exe
2014-09-07 19:52 - 2014-08-08 10:41 - 01953862 _____ () C:\WINDOWS\WindowsUpdate.log
2014-09-07 19:52 - 2014-07-18 13:07 - 00003934 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{FD11A2D6-F5DF-497B-88D9-AB233E4152B5}
2014-09-07 19:52 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2014-09-07 19:48 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-09-07 19:45 - 2013-11-09 15:40 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-09-07 19:34 - 2014-07-18 11:22 - 00000000 ____D () C:\Users\Metallica41
2014-09-07 19:27 - 2014-01-08 12:34 - 00000000 ____D () C:\ProgramData\MFAData
2014-09-07 19:00 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-09-07 14:40 - 2014-07-11 13:24 - 00000000 ____D () C:\Users\Metallica41\Desktop\New folder (2)
2014-09-07 12:27 - 2014-08-31 12:00 - 00000236 _____ () C:\Users\Metallica41\BullseyeCoverageError.txt
2014-09-06 18:53 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2014-09-05 23:39 - 2014-09-05 23:39 - 00007974 _____ () C:\Users\Metallica41\Documents\MassEffectConfigReport2014-09-05.xml
2014-09-05 23:32 - 2014-09-05 23:32 - 00034769 _____ () C:\Users\Metallica41\Downloads\Ty00_QuickSave.MassEffectSave
2014-09-05 23:32 - 2014-09-05 23:32 - 00023300 _____ () C:\Users\Metallica41\Downloads\Char_01-54-2-2-0-26-12-2009-48-17.MassEffectSave
2014-09-03 20:33 - 2013-09-07 20:32 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-473922799-1250382268-3828485289-1001
2014-09-03 18:35 - 2014-09-03 18:35 - 12465681 _____ () C:\Users\Metallica41\Desktop\clip0013.mp4
2014-09-03 18:30 - 2014-09-03 18:29 - 00000000 ____D () C:\Users\Metallica41\Documents\Freemake
2014-09-03 18:30 - 2014-09-03 18:29 - 00000000 ____D () C:\ProgramData\Freemake
2014-09-03 18:29 - 2014-09-03 18:29 - 00001338 _____ () C:\Users\Public\Desktop\Freemake Video Converter.lnk
2014-09-03 18:29 - 2014-09-03 18:29 - 00000000 ____D () C:\Users\Metallica41\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake
2014-09-03 18:29 - 2014-09-03 18:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freemake
2014-09-03 18:29 - 2014-09-03 18:29 - 00000000 ____D () C:\Program Files (x86)\Freemake
2014-09-03 18:26 - 2014-09-03 18:26 - 01268632 _____ (Ellora Assets Corporation ) C:\Users\Metallica41\Downloads\FreemakeVideoConverterSetup.exe
2014-09-03 15:09 - 2013-08-22 14:25 - 00524288 ___SH () C:\WINDOWS\system32\config\BBI
2014-09-03 10:04 - 2014-04-01 08:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-09-01 18:08 - 2014-02-08 16:24 - 00000000 ____D () C:\Users\Metallica41\Downloads\New folder
2014-09-01 15:24 - 2014-09-01 15:24 - 00000000 ____D () C:\Users\Metallica41\AppData\Roaming\Oracle
2014-09-01 15:24 - 2013-09-15 21:25 - 00000000 ____D () C:\ProgramData\Oracle
2014-09-01 15:23 - 2014-09-01 15:23 - 00004578 _____ () C:\WINDOWS\SysWOW64\jupdate-1.7.0_67-b01.log
2014-09-01 15:23 - 2014-09-01 15:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-09-01 15:23 - 2013-09-15 21:24 - 00000000 ____D () C:\Program Files (x86)\Java
2014-09-01 15:20 - 2014-09-01 15:20 - 00918952 _____ (Oracle Corporation) C:\Users\Metallica41\Downloads\jxpiinstall(1).exe
2014-08-31 12:02 - 2014-08-31 12:02 - 00000000 ____D () C:\Users\Metallica41\AppData\Roaming\Unity
2014-08-31 12:02 - 2014-08-31 12:02 - 00000000 ____D () C:\Users\Metallica41\AppData\Roaming\.mono
2014-08-31 12:02 - 2014-08-31 12:02 - 00000000 ____D () C:\ProgramData\.mono
2014-08-31 12:00 - 2014-08-31 12:00 - 00000000 ____D () C:\Users\Metallica41\AppData\Local\Unity
2014-08-31 11:59 - 2014-08-31 11:59 - 01202032 _____ (Unity Technologies ApS) C:\Users\Metallica41\Downloads\UnityWebPlayer.exe
2014-08-31 11:58 - 2014-08-31 11:58 - 00918952 _____ (Oracle Corporation) C:\Users\Metallica41\Downloads\jxpiinstall.exe
2014-08-30 08:46 - 2014-08-11 09:02 - 00337840 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-08-29 09:08 - 2012-07-26 08:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2014-08-28 23:33 - 2014-08-13 20:02 - 00002806 _____ () C:\Users\Metallica41\Desktop\New Text Document (2).txt
2014-08-26 23:32 - 2013-12-25 01:52 - 00000000 ____D () C:\Users\Metallica41\Desktop\New folder (4)
2014-08-26 23:25 - 2014-08-26 23:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Counter-Strike PRO
2014-08-26 22:58 - 2014-08-26 22:47 - 275930179 _____ () C:\Users\Metallica41\Downloads\CS-Professional.exe
2014-08-26 18:47 - 2014-07-17 20:14 - 00000240 _____ () C:\Users\Metallica41\Desktop\New Text Document.txt
2014-08-24 22:13 - 2014-08-24 19:57 - 00000000 ____D () C:\Users\Metallica41\Downloads\Californication Season 2
2014-08-24 22:12 - 2014-08-24 22:12 - 00000000 ____D () C:\Users\Metallica41\Desktop\CALI BLA BLA
2014-08-24 22:02 - 2013-11-02 06:47 - 00000000 ____D () C:\Users\Metallica41\AppData\Roaming\uTorrent
2014-08-23 22:48 - 2014-08-23 22:48 - 00000000 ____D () C:\ProgramData\Electronic Arts
2014-08-23 01:42 - 2014-08-28 10:35 - 04148224 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2014-08-20 14:14 - 2014-03-18 16:26 - 00863592 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-08-20 09:59 - 2014-08-11 09:02 - 00004574 _____ () C:\WINDOWS\PFRO.log
2014-08-19 00:02 - 2014-08-19 00:02 - 00000000 ____D () C:\Users\Metallica41\AppData\Local\Adobe
2014-08-16 16:50 - 2014-08-16 16:50 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_ccdcmbx64_01005.Wdf
2014-08-16 16:50 - 2014-08-11 19:39 - 00001779 _____ () C:\WINDOWS\setupact.log
2014-08-16 09:27 - 2013-11-09 15:40 - 00003718 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2014-08-14 18:33 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\rescache
2014-08-14 02:26 - 2013-08-22 16:36 - 00000000 ___RD () C:\WINDOWS\ToastData
2014-08-14 02:26 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\en-GB
2014-08-14 02:26 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\en-GB
2014-08-14 02:26 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\PolicyDefinitions
2014-08-14 02:26 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\MediaViewer
2014-08-14 02:26 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\FileManager
2014-08-14 02:26 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\Camera
2014-08-13 07:40 - 2013-09-08 08:27 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-08-13 07:36 - 2013-09-08 08:27 - 99218768 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-08-13 07:31 - 2014-07-21 00:39 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel
2014-08-13 06:53 - 2014-03-18 16:27 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe
2014-08-13 06:53 - 2014-03-18 16:27 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll
2014-08-13 06:53 - 2014-03-18 16:27 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2014-08-13 06:53 - 2013-08-22 12:45 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2014-08-13 06:53 - 2013-08-22 12:44 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollectorres.dll
2014-08-13 06:53 - 2013-08-22 12:22 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2014-08-13 06:53 - 2013-08-22 12:21 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwproxystub.dll
2014-08-13 06:53 - 2013-08-22 12:10 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2014-08-13 06:53 - 2013-08-22 12:03 - 00139264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieUnatt.exe
2014-08-13 06:53 - 2013-08-22 11:32 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll
2014-08-13 06:53 - 2013-08-22 05:17 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2014-08-13 06:53 - 2013-08-22 04:55 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieetwproxystub.dll
2014-08-13 06:53 - 2013-08-22 04:46 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2014-08-13 06:53 - 2013-08-22 04:45 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll
2014-08-13 06:53 - 2013-08-22 04:40 - 00112128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieUnatt.exe
2014-08-13 06:53 - 2013-08-22 04:16 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll
2014-08-13 06:51 - 2014-03-18 16:27 - 00233912 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2014-08-12 00:59 - 2013-10-11 20:10 - 00000000 ____D () C:\Users\Metallica41\AppData\Roaming\Skype
2014-08-11 19:39 - 2014-08-11 19:39 - 00000000 _____ () C:\WINDOWS\setuperr.log
2014-08-11 09:39 - 2013-11-30 10:03 - 00000000 ____D () C:\Users\Metallica41\Downloads\Guitar Pro 5
2014-08-08 10:18 - 2014-07-25 11:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rome - Total War
2014-08-08 10:17 - 2014-07-18 12:08 - 00000000 ___DC () C:\WINDOWS\Panther

Some content of TEMP:
====================
C:\Users\Metallica41\AppData\Local\Temp\BullseyeCoverage-2-x86.dll
C:\Users\Metallica41\AppData\Local\Temp\drm_dyndata_7400006.dll
C:\Users\Metallica41\AppData\Local\Temp\FreemakeVideoConverter_4.1.4.8.exe
C:\Users\Metallica41\AppData\Local\Temp\ins.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-09-05 08:39

==================== End Of Log ============================


https://www.mycity.rs/must-login.png


Vec 2 puta sam morao da resetujem komp.Jer se CPU popne na 81,91,100 i nece da silazi.Proverao sam da li se Antivirus azurira pa koci ali nije.

Dopuna: 07 Sep 2014 20:05

I da dodam.Nesto mi u Addition pise da imam Dead space instaliran ali sam ga obrisao pre 2 meseca.Ne znam zasto jos uvek tu stoji.

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Napisano: 07 Sep 2014 20:28

Obrisi AVG pa vidi kako ce da se ponasa, vec imas Windows Defender kao antivirus.

Dopuna: 07 Sep 2014 20:31

Arrow Preuzmi Malwarebytes Anti-Rootkit (MBAR) sa sledeceg linka i sacuvaj ga na Desktop.

Dvoklikom pokreni MBAR () na ikonicu programa:
- Klikni OK na sledecem prozoru da bi dozvolio raspakivanje u zaseban mbar folder na desktop-u;
- mbar.exe ce biti startovan. Na nekim sistemima to moze da potraje nekoliko dodatnih sekundi, te pricekati pokretanje.;
- U uvodnom prozoru klikni dugme Next ukoliko si saglasan;



• Na 'Update Database' prozoru klik na dugme Update da bi preuzeo sveze definicije. Kada se ispise poruka 'Success: Database was successfully updated' klik na dugme Next;
• Pod sekcijom 'Scan Targets' proveri da su sve opcije stiklirane, te klikni na dugme Scan;

Obavestenje: sa nekim infekcijama moze se desiti da se prikaze neka od sledecih poruka:
- 'Could not load protection driver' => u tom slucaju klikni OK.
- 'Could not load DDA driver' => klikni Yes na to obavestenje da bi dozvolio ucitavanje nakon restarta. Dozvoli restart i nastavi sa ostatkom instrukcija posle restarta.





>> Ukoliko malware nije detektovan, klik na Exit dugme da zatvoris program. U sledecu poruku postavi mbar-log-year-month-day (sat-minuti-sekundi).txt i system-log.txt izveštaje.

>> Ukoliko su infekcija/e pronadjene, proveriti da li je obelezena opcija 'Create Restore Point' i klikni na dugme Cleanup! da bi uklonili pretnje.
- Procedura uklanjanje malware-a (scheduled) ce biti zakazana po restartu, bice prikazano obavestenje u pop-up prozoru. Klikni dugme Yes i sistem bi trebao da se restartuje i da zavrsi proceduru ciscenja.



Obavestenje! samo ukoliko je RootKit detektovan: - postaraj se da pokrenes fixdamage.exe alat koji se nalazi u mbar folderu, \Plugins\fixdamage.exe:
- Dvoklikom pokreni fixdamage, u crnom prozoru koji se otvori (command prompt) ukucaj Y (Y stoji za Yes) da bi nastavio izvrsenje, pricekati da alat odradi sve popravke ...
- Kada vidis poruku 'press any key to exit' popravka je kompletirana. Pritisnuti bilo koju tipku na tastaturi da bi se prozor zatvorio. Restartovati sistem.





Sledeci izvestaji ce biti formirani u mbar folderu.
1. mbar-log-year-month-day (hour-minute-second).txt
2. system-log.txt

Iskopiraj sadrzaj mbar log-a u poruku a system log okaci uz poruku koristeci opciju Prikači fajl.

offline
  • Istrazivanje Windowsa
  • Pridružio: 12 Jul 2012
  • Poruke: 1023

Kad pokusavam da skinem Malware pojavi mi se ovo.Da idem na ''i understand the risks?''

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Napisano: 07 Sep 2014 21:31

get me out of here

Kad kliknes na to?

Dopuna: 07 Sep 2014 21:34

offline
  • Istrazivanje Windowsa
  • Pridružio: 12 Jul 2012
  • Poruke: 1023



Si siguran da odradim confirm? Nemoj da posle bude nesto gadno. Smile

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Napisano: 07 Sep 2014 21:40

Snimio sam ti sliku i okacio je na javni forum, mislis da hocu da te javno nasamarim pred svima?

Dopuna: 07 Sep 2014 21:42

Neko je u Malwarebytesu zaboravio da produži certifikat sigurnosni.
Sad mozes regularno da skines sa prvog linka.

offline
  • Istrazivanje Windowsa
  • Pridružio: 12 Jul 2012
  • Poruke: 1023

Malwarebytes Anti-Rootkit BETA 1.07.0.1012
www.malwarebytes.org

Database version: v2014.09.07.07

Windows 8.1 x64 NTFS
Internet Explorer 11.0.9600.17239
Metallica41 :: FIKO [administrator]

7.9.2014. 21:35:48
mbar-log-2014-09-07 (21-35-48).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 310609
Time elapsed: 15 minute(s), 39 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)

https://www.mycity.rs/must-login.png

Prilikom rada Malwarebytes-a pojavilo se obavestenje od AVG.Nasao je neki virus i obrisao sam ga.Evo slike:


Kad sam obisao ovaj virus laptop mnogo radi brze i vise ne baguje. Hvala ti! Very Happy Samo ne razumem sto se AVG ranije nije odazvao nego se odazvao kad je radio malwarebytes. Al hvala. Smile

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Pa MBAR ga je provalio i onda ga je AVG brisao, inace to si instalirao zajedno sa AVG-om u paketu.

offline
  • Istrazivanje Windowsa
  • Pridružio: 12 Jul 2012
  • Poruke: 1023

Kako rade zajedno. Very Happy Hvala jos jednom.A ne znam samo odakle mi taj virus.U nekom je cudnom folderu al nema veze,vazno je da ga nema.

Ko je trenutno na forumu
 

Ukupno su 1106 korisnika na forumu :: 38 registrovanih, 9 sakrivenih i 1059 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: Acivi, Atomski čoban, babaroga, bojan_t, BORUTUS, DENIRO, djboj, Draganeli, Georgius, goxin, joca83, Koridor, krkalon, Kubovac, kunktator, Leonov, maiden6657, Marko Marković, marsovac 2, mikrimaus, Mile80, Milometer, mnn2, moldway, MrNo, naki011, nemkea71, nenad81, Nikolaa11, procesor, raketaš, Romibrat, shaja1, stemark, tmanda323, wolf431, zdrebac, |_MeD_|