Poslao: 03 Jan 2014 16:19
|
offline
- ifix
![Male](https://www.mycity.rs/templates/simplified/images2/user-sex.gif)
- Građanin
- Pridružio: 20 Okt 2013
- Poruke: 180
|
Instalirao sam neku igricu, i avg is 2014 je detektovao neki virus, od tada mi racunar zakucava na nekoliko sekundi pa neko vreme sve bude normalno, pa opet tako zakuca.
Najcesce zakucava internet browser...
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.16428
Run by Dusan at 16:15:00 on 2014-01-03
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.4003.1628 [GMT 1:00]
.
AV: AVG Internet Security 2014 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AVG Internet Security 2014 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
FW: AVG Internet Security 2014 *Enabled* {36AFA1E1-4CDC-7EF8-11EE-C77C3581ABA2}
.
============== Running Processes ===============
.
C:\PROGRA~2\AVG\AVG2014\avgrsa.exe
C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\AVG\AVG2014\avgfws.exe
C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
C:\Windows\system32\BtwRSupportService.exe
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\Dwm.exe
C:\Program Files (x86)\Secunia\PSI\PSIA.exe
C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
C:\Program Files (x86)\AVG\AVG2014\avgemca.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe
C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Users\Dusan\AppData\Roaming\BitTorrent\BitTorrent.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files (x86)\MCShield\MCShieldRTM.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
C:\Program Files (x86)\Secunia\PSI\sua.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\System32\WUDFHost.exe
C:\Program Files (x86)\VibrateGameDeviceDriver\rfpicon.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\AVG\AVG2014\avgui.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_152.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_152.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uWindow Title = Internet Explorer, enhanced for Bing and MSN
mWinlogon: Userinit = userinit.exe
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.114.0\BingExt.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.114.0\BingExt.dll
uRun: [BitTorrent] "C:\Users\Dusan\AppData\Roaming\BitTorrent\BitTorrent.exe" /MINIMIZED
uRun: [AdobeBridge] <no file>
mRun: [RTBatteryMeter] C:\Program Files (x86)\VibrateGameDeviceDriver\RFPIcon.exe
mRun: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY
dRunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
StartupFolder: C:\Users\Dusan\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Fences.lnk - C:\Program Files (x86)\Stardock\Fences\Fences.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\SECUNI~1.LNK - C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105
IE: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: NameServer = 192.168.1.1 0.0.0.0
TCP: Interfaces\{017D778B-E2F1-4377-94DB-63CC863CD6A5} : DHCPNameServer = 192.168.1.1 0.0.0.0
TCP: Interfaces\{017D778B-E2F1-4377-94DB-63CC863CD6A5}\847453332356D2644483642364 : DHCPNameServer = 192.168.1.1 0.0.0.0
TCP: Interfaces\{017D778B-E2F1-4377-94DB-63CC863CD6A5}\D4962716 : DHCPNameServer = 192.168.1.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
AppInit_DLLs= c:\windows\syswow64\nvinit.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.114.0\amd64\BingExt.dll
x64-TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} -
x64-Run: [Fences] "C:\Program Files (x86)\Stardock\Fences\Fences.exe" /startup
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
x64-IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
x64-STS: FencesShlExt Class - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files (x86)\Stardock\Fences\FencesMenu64.dll
x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Dusan\AppData\Roaming\Mozilla\Firefox\Profiles\58capm0j.default\
FF - prefs.js: browser.startup.homepage - hxxps://www.google.rs/
FF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll
FF - plugin: C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Users\Dusan\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\drivers\avgidsha.sys [2013-10-24 194872]
R0 Avgloga;AVG Logging Driver;C:\Windows\System32\drivers\avgloga.sys [2013-10-31 294712]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2013-10-1 123704]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2013-9-10 31544]
R0 nvpciflt;nvpciflt;C:\Windows\System32\drivers\nvpciflt.sys [2012-10-8 30056]
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2013-12-10 55280]
R1 Avgdiska;AVG Disk Driver;C:\Windows\System32\drivers\avgdiska.sys [2013-11-5 150808]
R1 Avgfwfd;AVG network filter service;C:\Windows\System32\drivers\avgfwd6a.sys [2013-9-26 57144]
R1 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\avgidsdrivera.sys [2013-11-4 240920]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2013-10-31 212280]
R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2013-8-1 251192]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver;C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [2013-9-13 31136]
R1 nvkflt;nvkflt;C:\Windows\System32\drivers\nvkflt.sys [2012-10-8 284008]
R2 avgfws;AVG Firewall;C:\Program Files (x86)\AVG\AVG2014\avgfws.exe [2013-9-24 1358944]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [2013-11-11 3478544]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [2013-9-24 348008]
R2 BcmBtRSupport;Bluetooth Driver Management Service;C:\Windows\System32\BtwRSupportService.exe [2013-10-28 2255064]
R2 Secunia PSI Agent;Secunia PSI Agent;C:\Program Files (x86)\Secunia\PSI\psia.exe [2013-7-3 1228504]
R2 Secunia Update Agent;Secunia Update Agent;C:\Program Files (x86)\Secunia\PSI\sua.exe [2013-7-3 660184]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-2 382824]
R3 bcbtums;Bluetooth USB LD Filter;C:\Windows\System32\drivers\bcbtums.sys [2013-10-28 170712]
R3 BTWAMPFL;BTWAMPFL;C:\Windows\System32\drivers\btwampfl.sys [2013-8-9 166104]
R3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\System32\drivers\btwl2cap.sys [2013-9-11 39464]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\System32\drivers\CtClsFlt.sys [2013-9-12 172704]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\System32\drivers\dtsoftbus01.sys [2013-12-22 283064]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2010-12-10 80384]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2010-12-10 181248]
R3 PSI;PSI;C:\Windows\System32\drivers\psi_mf_amd64.sys [2013-7-3 18456]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-6-10 539240]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 epmntdrv;epmntdrv;C:\Windows\System32\epmntdrv.sys [2013-10-21 17480]
S3 EuGdiDrv;EuGdiDrv;C:\Windows\System32\EuGdiDrv.sys [2013-10-21 9800]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2013-12-12 111616]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-9-14 19456]
S3 SwitchBoard;Adobe SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-9-14 57856]
S4 AESTFilters;Andrea ST Filters Service;C:\Program Files\IDT\WDM\AESTSr64.exe [2013-9-12 89600]
S4 BBSvc;BingBar Service;C:\Program Files (x86)\Microsoft\BingBar\7.3.114.0\BBSvc.EXE [2013-10-10 193696]
S4 BBUpdate;BBUpdate;C:\Program Files (x86)\Microsoft\BingBar\7.3.114.0\SeaPort.EXE [2013-10-10 240288]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;C:\Program Files\Microsoft SQL Server\100\Shared\sqladhlp.exe [2009-7-22 61976]
S4 PuranDefrag;PuranDefrag;C:\Windows\System32\PuranDefragS.exe [2013-9-19 292736]
S4 RsFx0103;RsFx0103 Driver;C:\Windows\System32\drivers\RsFx0103.sys [2009-3-30 311656]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-3-30 427880]
.
=============== Created Last 30 ================
.
2014-01-02 17:56:55 3767504 ----a-w- C:\Windows\System32\d3dx9_26.dll
2014-01-02 17:56:55 2297552 ----a-w- C:\Windows\SysWow64\d3dx9_26.dll
2013-12-31 00:15:36 -------- d-----w- C:\Users\Dusan\AppData\Roaming\AVG2014
2013-12-31 00:14:40 -------- d-----w- C:\Users\Dusan\AppData\Roaming\TuneUp Software
2013-12-31 00:13:59 -------- d--h--w- C:\$AVG
2013-12-31 00:13:59 -------- d-----w- C:\ProgramData\AVG2014
2013-12-31 00:13:33 -------- d-----w- C:\Program Files (x86)\AVG
2013-12-31 00:05:43 -------- d--h--w- C:\ProgramData\Common Files
2013-12-31 00:05:43 -------- d-----w- C:\Users\Dusan\AppData\Local\MFAData
2013-12-31 00:05:43 -------- d-----w- C:\Users\Dusan\AppData\Local\Avg2014
2013-12-31 00:05:43 -------- d-----w- C:\ProgramData\MFAData
2013-12-22 18:50:01 -------- d-----w- C:\Program Files (x86)\Sniper Elite Nazi Zombie Army 2
2013-12-22 18:40:55 283064 ----a-w- C:\Windows\System32\drivers\dtsoftbus01.sys
2013-12-22 18:40:51 -------- d-----w- C:\Users\Dusan\AppData\Roaming\DAEMON Tools Lite
2013-12-22 18:40:49 -------- d-----w- C:\Program Files (x86)\DAEMON Tools Lite
2013-12-22 18:40:18 -------- d-----w- C:\ProgramData\DAEMON Tools Lite
2013-12-21 14:44:14 -------- d-----w- C:\Program Files\CCleaner
2013-12-18 15:55:31 -------- d-----w- C:\Users\Dusan\AppData\Roaming\Web Page Maker
2013-12-18 15:55:31 -------- d-----w- C:\ProgramData\Web Page Maker
2013-12-18 15:55:26 -------- d-----w- C:\Program Files (x86)\Web Page Maker
2013-12-12 05:44:42 167424 ----a-w- C:\Program Files\Windows Media Player\wmplayer.exe
2013-12-12 05:44:42 164864 ----a-w- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
2013-12-12 05:44:41 12625920 ----a-w- C:\Windows\System32\wmploc.DLL
2013-12-12 05:44:41 12625408 ----a-w- C:\Windows\SysWow64\wmploc.DLL
2013-12-11 14:02:04 92272 ----a-w- C:\Program Files (x86)\Mozilla Firefox\updated\nssdbm3.dll
2013-12-11 12:39:27 335360 ----a-w- C:\Windows\System32\msieftp.dll
2013-12-11 12:39:27 301568 ----a-w- C:\Windows\SysWow64\msieftp.dll
2013-12-11 12:39:07 3155968 ----a-w- C:\Windows\System32\win32k.sys
2013-12-11 12:38:47 465920 ----a-w- C:\Windows\System32\WMPhoto.dll
2013-12-11 12:38:47 417792 ----a-w- C:\Windows\SysWow64\WMPhoto.dll
2013-12-11 12:38:25 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2013-12-11 12:38:25 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2013-12-11 12:38:07 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2013-12-11 12:38:07 2048 ----a-w- C:\Windows\System32\tzres.dll
2013-12-11 12:37:44 230400 ----a-w- C:\Windows\System32\drivers\portcls.sys
2013-12-11 12:37:44 116736 ----a-w- C:\Windows\System32\drivers\drmk.sys
2013-12-11 12:37:24 202752 ----a-w- C:\Windows\System32\scrrun.dll
2013-12-11 12:37:24 168960 ----a-w- C:\Windows\System32\wscript.exe
2013-12-11 12:37:24 163840 ----a-w- C:\Windows\SysWow64\scrrun.dll
2013-12-11 12:37:24 156160 ----a-w- C:\Windows\System32\cscript.exe
2013-12-11 12:37:24 150016 ----a-w- C:\Windows\System32\wshom.ocx
2013-12-11 12:37:24 141824 ----a-w- C:\Windows\SysWow64\wscript.exe
2013-12-11 12:37:24 126976 ----a-w- C:\Windows\SysWow64\cscript.exe
2013-12-11 12:37:24 121856 ----a-w- C:\Windows\SysWow64\wshom.ocx
2013-12-10 20:57:36 -------- d-----w- C:\Users\Dusan\AppData\Roaming\PACE Anti-Piracy
2013-12-10 20:57:36 -------- d-----w- C:\Users\Dusan\AppData\Local\PACE Anti-Piracy
2013-12-10 20:57:36 -------- d-----w- C:\ProgramData\PACE Anti-Piracy
2013-12-10 20:51:14 -------- d-----w- C:\Program Files (x86)\Adobe Story
2013-12-10 20:50:16 55280 ------w- C:\Windows\System32\drivers\PxHlpa64.sys
2013-12-10 20:50:16 10224 ------w- C:\Windows\System32\drivers\cdralw2k.sys
2013-12-10 20:50:16 10224 ------w- C:\Windows\System32\drivers\cdr4_xp.sys
2013-12-10 20:50:13 -------- d-----w- C:\Program Files (x86)\My Company Name
2013-12-10 20:50:13 -------- d-----w- C:\Program Files (x86)\Common Files\Sonic Shared
2013-12-10 20:50:13 -------- d-----w- C:\Program Files (x86)\Common Files\PX Storage Engine
2013-12-08 17:57:32 -------- d-----w- C:\Program Files (x86)\Cheat Engine 6.3
2013-12-08 02:01:18 -------- d-----w- C:\Program Files (x86)\GUME924.tmp
.
==================== Find3M ====================
.
2013-11-28 12:08:57 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-11-28 12:08:57 692616 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-11-26 10:19:07 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2013-11-26 10:18:23 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2013-11-26 09:48:07 66048 ----a-w- C:\Windows\System32\iesetup.dll
2013-11-26 09:46:25 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2013-11-26 09:23:02 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2013-11-26 09:18:39 139264 ----a-w- C:\Windows\System32\ieUnatt.exe
2013-11-26 09:18:09 111616 ----a-w- C:\Windows\System32\ieetwcollector.exe
2013-11-26 09:16:57 708608 ----a-w- C:\Windows\System32\jscript9diag.dll
2013-11-26 08:35:02 5769216 ----a-w- C:\Windows\System32\jscript9.dll
2013-11-26 08:28:16 553472 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2013-11-26 08:16:12 4243968 ----a-w- C:\Windows\SysWow64\jscript9.dll
2013-11-26 08:02:16 1995264 ----a-w- C:\Windows\System32\inetcpl.cpl
2013-11-26 07:32:06 1928192 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2013-11-26 07:07:57 2334208 ----a-w- C:\Windows\System32\wininet.dll
2013-11-26 06:33:33 1820160 ----a-w- C:\Windows\SysWow64\wininet.dll
2013-11-05 20:55:48 150808 ----a-w- C:\Windows\System32\drivers\avgdiska.sys
2013-11-04 20:52:42 240920 ----a-w- C:\Windows\System32\drivers\avgidsdrivera.sys
2013-10-31 22:00:18 212280 ----a-w- C:\Windows\System32\drivers\avgldx64.sys
2013-10-31 21:49:46 294712 ----a-w- C:\Windows\System32\drivers\avgloga.sys
2013-10-28 17:02:18 2255064 ----a-w- C:\Windows\System32\BtwRSupportService.exe
2013-10-28 17:02:16 170712 ----a-w- C:\Windows\System32\drivers\bcbtums.sys
2013-10-24 21:25:58 194872 ----a-w- C:\Windows\System32\drivers\avgidsha.sys
2013-10-12 02:30:42 830464 ----a-w- C:\Windows\System32\nshwfp.dll
2013-10-12 02:29:21 859648 ----a-w- C:\Windows\System32\IKEEXT.DLL
2013-10-12 02:29:08 324096 ----a-w- C:\Windows\System32\FWPUCLNT.DLL
2013-10-12 02:03:08 656896 ----a-w- C:\Windows\SysWow64\nshwfp.dll
2013-10-12 02:01:25 216576 ----a-w- C:\Windows\SysWow64\FWPUCLNT.DLL
2013-10-09 13:34:14 3381832 ----a-w- C:\Windows\System32\BootMan.exe
2013-10-09 13:24:36 2499656 ----a-w- C:\Windows\SysWow64\BootMan.exe
2013-10-05 20:25:35 1474048 ----a-w- C:\Windows\System32\crypt32.dll
2013-10-05 19:57:25 1168384 ----a-w- C:\Windows\SysWow64\crypt32.dll
.
============= FINISH: 16:16:12.52 ===============
mycity.rs/must-login.png
|
|
|
|
|
Poslao: 03 Jan 2014 18:06
|
offline
- ifix
![Male](https://www.mycity.rs/templates/simplified/images2/user-sex.gif)
- Građanin
- Pridružio: 20 Okt 2013
- Poruke: 180
|
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-01-2014
Ran by Dusan (administrator) on DUSAN-PC on 03-01-2014 18:02:43
Running from C:\Users\Dusan\Desktop
Windows 7 Ultimate Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgfws.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
(Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psia.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(BitTorrent Inc.) C:\Users\Dusan\AppData\Roaming\BitTorrent\BitTorrent.exe
(MyCity) C:\Program Files (x86)\MCShield\MCShieldRTM.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe
(Ruling Tec Pte Ltd) C:\Program Files (x86)\VibrateGameDeviceDriver\rfpicon.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_152.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_152.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Fences] - C:\Program Files (x86)\Stardock\Fences\Fences.exe [4017368 2012-10-29] (Stardock Corporation)
HKLM-x32\...\Run: [RTBatteryMeter] - C:\Program Files (x86)\VibrateGameDeviceDriver\rfpicon.exe [49152 2003-01-16] (Ruling Tec Pte Ltd)
HKLM-x32\...\Run: [NUSB3MON] - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AVG_UI] - C:\Program Files (x86)\AVG\AVG2014\avgui.exe [4956176 2013-11-07] (AVG Technologies CZ, s.r.o.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [BitTorrent] - C:\Users\Dusan\AppData\Roaming\BitTorrent\BitTorrent.exe [1127000 2013-09-13] (BitTorrent Inc.)
HKCU\...\Run: [AdobeBridge] - [x]
HKCU\...\Run: [MCShield Monitor] - C:\Program Files (x86)\MCShield\MCShieldRTM.exe [607232 2013-10-26] (MyCity)
HKCU\...\Run: [LiveSupport] - "C:\Program Files (x86)\LiveSupport\LiveSupport.exe" /noshow /log
AppInit_DLLs: C:\Windows\System32\nvinitx.dll [247144 2012-10-08] (NVIDIA Corporation)
AppInit_DLLs-x32: c:\windows\syswow64\nvinit.dll [202600 2012-10-08] (NVIDIA Corporation)
Startup: C:\Users\Dusan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Fences.lnk
ShortcutTarget: Fences.lnk -> C:\Program Files (x86)\Stardock\Fences\Fences.exe (Stardock Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = msn.com/?ocid=UP74DHP&pc=UP74&dt=091813
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x1B74E0F93DAFCE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = g.msn.com/1me10IE10ENUS/WOL_WCP
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.114.0\amd64\BingExt.dll (Microsoft Corporation.)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.114.0\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.114.0\amd64\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.114.0\BingExt.dll (Microsoft Corporation.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 0.0.0.0
FireFox:
========
FF ProfilePath: C:\Users\Dusan\AppData\Roaming\Mozilla\Firefox\Profiles\58capm0j.default
FF Homepage: google.rs/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_152.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Dusan\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
Chrome:
=======
CHR HomePage: google.rs/
CHR RestoreOnStartup: "https://www.google.rs/"
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll ()
CHR Plugin: (Reallusion CT4Player for Mozilla) - C:\Program Files (x86)\Mozilla Firefox\plugins\npRLCT4Player.dll ( )
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll No File
CHR Extension: (Google Docs) - C:\Users\Dusan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Dusan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\Dusan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Dusan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Google Wallet) - C:\Users\Dusan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0
CHR Extension: (Gmail) - C:\Users\Dusan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
==================== Services (Whitelisted) =================
R2 avgfws; C:\Program Files (x86)\AVG\AVG2014\avgfws.exe [1358944 2013-09-24] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3478544 2013-11-11] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [348008 2013-09-24] (AVG Technologies CZ, s.r.o.)
R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2255064 2013-10-28] (Broadcom Corporation.)
R2 MSSQL$SQLEXPRESS; c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [57617752 2009-03-30] (Microsoft Corporation)
S4 PuranDefrag; C:\Windows\system32\PuranDefragS.exe [292736 2013-08-15] (Puran Software)
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1228504 2013-07-03] (Secunia)
R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [660184 2013-07-03] (Secunia)
S4 SQLAgent$SQLEXPRESS; c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [427880 2009-03-30] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [150808 2013-11-05] (AVG Technologies CZ, s.r.o.)
R1 Avgfwfd; C:\Windows\System32\DRIVERS\avgfwd6a.sys [57144 2013-09-26] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [240920 2013-11-04] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [194872 2013-10-24] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [212280 2013-10-31] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [294712 2013-10-31] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123704 2013-10-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31544 2013-09-10] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [251192 2013-08-01] (AVG Technologies CZ, s.r.o.)
R3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [170712 2013-10-28] (Broadcom Corporation.)
R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-12-22] (Disc Soft Ltd)
S3 DynCal; C:\Windows\SysWow64\drivers\Dyncal.sys [8576 2005-09-26] (Windows (R) Server 2003 DDK provider)
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [17480 2013-03-07] ()
S3 epmntdrv; C:\Windows\SysWow64\epmntdrv.sys [13896 2013-03-07] ()
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9800 2013-03-07] ()
S3 EuGdiDrv; C:\Windows\SysWow64\EuGdiDrv.sys [9160 2013-03-07] ()
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [31136 2013-09-13] (REALiX(tm))
R1 nvkflt; C:\Windows\System32\DRIVERS\nvkflt.sys [284008 2012-10-08] (NVIDIA Corporation)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-07-03] (Secunia)
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x]
S3 tsusbhub; system32\drivers\tsusbhub.sys [x]
S3 VGPU; System32\drivers\rdvgkmd.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-03 18:02 - 2014-01-03 18:03 - 00013781 _____ C:\Users\Dusan\Desktop\FRST.txt
2014-01-03 18:01 - 2014-01-03 18:01 - 01064581 _____ (Farbar) C:\Users\Dusan\Desktop\FRST.exe
2014-01-03 18:01 - 2014-01-03 18:01 - 00000000 ____D C:\FRST
2014-01-03 18:00 - 2014-01-03 18:00 - 01931750 _____ (Farbar) C:\Users\Dusan\Desktop\FRST64.exe
2014-01-03 16:48 - 2014-01-03 16:48 - 00760063 _____ (Farbar) C:\Users\Dusan\Downloads\MiniToolBox.exe
2014-01-03 16:47 - 2014-01-03 16:47 - 00010056 _____ C:\Users\Dusan\Desktop\Result.txt
2014-01-03 16:41 - 2014-01-03 16:42 - 00000000 ____D C:\Users\Dusan\Desktop\FBfish
2014-01-03 16:16 - 2014-01-03 16:16 - 00020976 _____ C:\Users\Dusan\Desktop\dds.txt
2014-01-03 16:16 - 2014-01-03 16:16 - 00011461 _____ C:\Users\Dusan\Desktop\attach.txt
2014-01-03 16:14 - 2014-01-03 16:14 - 00688992 ____R (Swearware) C:\Users\Dusan\Desktop\dds.scr
2014-01-03 14:25 - 2014-01-03 14:25 - 00000056 _____ C:\Windows\setupact.log
2014-01-03 14:25 - 2014-01-03 14:25 - 00000000 _____ C:\Windows\setuperr.log
2014-01-02 18:58 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll
2014-01-02 18:58 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll
2014-01-02 18:58 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
2014-01-02 18:58 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll
2014-01-02 18:58 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll
2014-01-02 18:58 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll
2014-01-02 18:58 - 2006-11-15 11:38 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll
2014-01-02 18:58 - 2006-11-15 11:38 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll
2014-01-02 18:58 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll
2014-01-02 18:58 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll
2014-01-02 18:58 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll
2014-01-02 18:58 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll
2014-01-02 18:58 - 2006-09-28 16:04 - 00091928 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
2014-01-02 18:58 - 2006-09-28 16:04 - 00068888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll
2014-01-02 18:58 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
2014-01-02 18:58 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll
2014-01-02 18:58 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll
2014-01-02 18:58 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll
2014-01-02 18:58 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll
2014-01-02 18:58 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll
2014-01-02 18:58 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll
2014-01-02 18:58 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll
2014-01-02 18:58 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
2014-01-02 18:58 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll
2014-01-02 18:57 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
2014-01-02 18:57 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll
2014-01-02 18:57 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
2014-01-02 18:57 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll
2014-01-02 18:57 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll
2014-01-02 18:57 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll
2014-01-02 18:57 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll
2014-01-02 18:57 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll
2014-01-02 18:57 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
2014-01-02 18:57 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll
2014-01-02 18:56 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll
2014-01-02 18:56 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll
2014-01-02 18:56 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
2014-01-02 18:56 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll
2014-01-02 18:56 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
2014-01-02 18:56 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll
2014-01-02 18:56 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
2014-01-02 18:56 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll
2014-01-02 17:41 - 2014-01-02 17:41 - 00448512 _____ (OldTimer Tools) C:\Users\Dusan\Desktop\TFC.exe
2014-01-01 18:26 - 2014-01-01 18:39 - 00000000 ____D C:\Users\Dusan\Desktop\Gmail
2014-01-01 03:20 - 2014-01-01 13:00 - 00000182 _____ C:\Users\Dusan\Desktop\kvota3.txt
2013-12-31 01:15 - 2013-12-31 01:15 - 00003230 _____ C:\Windows\System32\Tasks\SidebarExecute
2013-12-31 01:15 - 2013-12-31 01:15 - 00000000 ____D C:\Users\Dusan\AppData\Roaming\AVG2014
2013-12-31 01:14 - 2013-12-31 01:14 - 00000965 _____ C:\Users\Public\Desktop\AVG 2014.lnk
2013-12-31 01:14 - 2013-12-31 01:14 - 00000000 ____D C:\Users\Dusan\AppData\Roaming\TuneUp Software
2013-12-31 01:13 - 2013-12-31 01:15 - 00000000 ____D C:\ProgramData\AVG2014
2013-12-31 01:13 - 2013-12-31 01:13 - 00000000 ___HD C:\$AVG
2013-12-31 01:13 - 2013-12-31 01:13 - 00000000 ____D C:\Program Files (x86)\AVG
2013-12-31 01:05 - 2014-01-03 16:43 - 00000000 ____D C:\ProgramData\MFAData
2013-12-31 01:05 - 2013-12-31 15:31 - 00000000 ____D C:\Users\Dusan\AppData\Local\Avg2014
2013-12-31 01:05 - 2013-12-31 01:05 - 00000000 ____D C:\Users\Dusan\AppData\Local\MFAData
2013-12-27 22:51 - 2013-12-27 23:06 - 01678200 _____ C:\Users\Dusan\Desktop\cabj.psd
2013-12-22 19:55 - 2013-12-22 19:55 - 00002150 _____ C:\Users\Public\Desktop\Sniper Elite Nazi Zombie Army 2.lnk
2013-12-22 19:50 - 2013-12-22 19:55 - 00000000 ____D C:\Program Files (x86)\Sniper Elite Nazi Zombie Army 2
2013-12-22 19:41 - 2013-12-22 19:41 - 00001950 _____ C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
2013-12-22 19:40 - 2014-01-03 03:47 - 00000000 ____D C:\Users\Dusan\AppData\Roaming\DAEMON Tools Lite
2013-12-22 19:40 - 2013-12-22 19:48 - 00000000 ____D C:\ProgramData\DAEMON Tools Lite
2013-12-22 19:40 - 2013-12-22 19:41 - 00283064 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtsoftbus01.sys
2013-12-22 19:40 - 2013-12-22 19:40 - 00000000 ____D C:\Program Files (x86)\DAEMON Tools Lite
2013-12-22 14:41 - 2013-12-22 14:43 - 00000000 ____D C:\Users\Dusan\Desktop\wordpress
2013-12-22 14:41 - 2013-12-22 14:41 - 06367550 _____ C:\Users\Dusan\Desktop\wordpress-3.8.zip
2013-12-22 14:28 - 2013-12-22 14:28 - 00477612 _____ C:\Users\Dusan\Desktop\compasso.zip
2013-12-22 14:21 - 2013-06-19 21:56 - 00000000 ____D C:\Users\Dusan\Desktop\sample-data
2013-12-22 14:04 - 2013-12-22 14:05 - 13158700 _____ C:\Users\Dusan\Desktop\megazine106.rar
2013-12-22 01:01 - 2013-12-22 01:01 - 00000315 _____ C:\Users\Dusan\Desktop\oglasii.txt
2013-12-21 21:05 - 2013-12-21 21:05 - 00069527 _____ C:\Users\Dusan\Desktop\bangkok.psd
2013-12-21 15:44 - 2013-12-21 15:44 - 00002772 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2013-12-21 15:44 - 2013-12-21 15:44 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-12-21 15:44 - 2013-12-21 15:44 - 00000000 ____D C:\Program Files\CCleaner
2013-12-18 16:55 - 2013-12-18 16:55 - 00001099 _____ C:\Users\Public\Desktop\Web Page Maker.lnk
2013-12-18 16:55 - 2013-12-18 16:55 - 00000000 ____D C:\Users\Dusan\Documents\Web Page Maker
2013-12-18 16:55 - 2013-12-18 16:55 - 00000000 ____D C:\Users\Dusan\AppData\Roaming\Web Page Maker
2013-12-18 16:55 - 2013-12-18 16:55 - 00000000 ____D C:\ProgramData\Web Page Maker
2013-12-18 16:55 - 2013-12-18 16:55 - 00000000 ____D C:\Program Files (x86)\Web Page Maker
2013-12-18 16:54 - 2013-12-18 16:55 - 03638090 _____ (Web Page Maker Software Company, Inc. ) C:\Users\Dusan\Desktop\wpm.exe
2013-12-18 12:42 - 2013-12-18 12:42 - 00000165 _____ C:\Users\Dusan\Desktop\usernames.rar
2013-12-18 12:40 - 2014-01-03 17:38 - 00000190 _____ C:\Users\Dusan\Desktop\usernames.txt
2013-12-16 21:55 - 2013-12-16 21:55 - 00000797 _____ C:\Users\Public\Desktop\RAR Password Unlocker.lnk
2013-12-12 06:44 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-12-12 06:44 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-12-12 06:44 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2013-12-12 06:44 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-12-12 06:43 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-12 06:43 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-12 06:43 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-12-12 06:43 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-12-12 06:43 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-12-12 06:43 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-12-12 06:43 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-12 06:43 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-12 06:43 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-12-12 06:43 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-12-12 06:43 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-12 06:43 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-12-12 06:43 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-12-12 06:43 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-12-12 06:43 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-12 06:43 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-12-12 06:43 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-12-12 06:43 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-12 06:43 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-12-12 06:43 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-12-12 06:43 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-12-12 06:43 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-12-12 06:43 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-12 06:43 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-12-12 06:43 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-12-12 06:43 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-12 06:43 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-12 06:43 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-12-12 06:43 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-12-12 06:43 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-12-12 06:43 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-12-11 21:25 - 2013-12-18 13:34 - 00000000 ____D C:\Users\Dusan\Desktop\Besplatni_tokeni_12-11-13
2013-12-11 13:39 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-11 13:39 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2013-12-11 13:39 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-11 13:38 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-12-11 13:38 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-11 13:38 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-11 13:38 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-12-11 13:38 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-11 13:38 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2013-12-11 13:37 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-11 13:37 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-11 13:37 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2013-12-11 13:37 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2013-12-11 13:37 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-11 13:37 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-11 13:37 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2013-12-11 13:37 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2013-12-11 13:37 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-11 13:37 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-12-10 21:57 - 2013-12-10 21:57 - 00000000 ____D C:\Users\Dusan\Documents\Adobe
2013-12-10 21:57 - 2013-12-10 21:57 - 00000000 ____D C:\Users\Dusan\AppData\Roaming\PACE Anti-Piracy
2013-12-10 21:57 - 2013-12-10 21:57 - 00000000 ____D C:\Users\Dusan\AppData\Local\PACE Anti-Piracy
2013-12-10 21:57 - 2013-12-10 21:57 - 00000000 ____D C:\ProgramData\PACE Anti-Piracy
2013-12-10 21:56 - 2013-12-10 22:16 - 00001126 _____ C:\Users\Dusan\Desktop\Adobe Premiere Pro CS5.5.lnk
2013-12-10 21:51 - 2013-12-10 21:51 - 00000000 ____D C:\Program Files (x86)\Adobe Story
2013-12-10 21:50 - 2013-12-10 21:50 - 00000000 ____D C:\Program Files (x86)\My Company Name
2013-12-10 21:50 - 2009-07-09 03:00 - 00055280 ____N (Sonic Solutions) C:\Windows\system32\Drivers\PxHlpa64.sys
2013-12-10 21:50 - 2009-06-23 03:00 - 00010224 ____N (Sonic Solutions) C:\Windows\system32\Drivers\cdralw2k.sys
2013-12-10 21:50 - 2009-06-23 03:00 - 00010224 ____N (Sonic Solutions) C:\Windows\system32\Drivers\cdr4_xp.sys
2013-12-10 21:48 - 2013-12-10 21:48 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2013-12-10 21:48 - 2013-12-10 21:48 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2013-12-08 18:57 - 2013-12-08 18:57 - 00001085 _____ C:\Users\Dusan\Desktop\Cheat Engine.lnk
2013-12-08 18:57 - 2013-12-08 18:57 - 00000000 ____D C:\Users\Dusan\Documents\My Cheat Tables
2013-12-08 18:57 - 2013-12-08 18:57 - 00000000 ____D C:\Program Files (x86)\Cheat Engine 6.3
2013-12-08 03:01 - 2013-12-08 03:01 - 00000000 ____D C:\Program Files (x86)\GUME924.tmp
==================== One Month Modified Files and Folders =======
2014-01-03 18:03 - 2014-01-03 18:02 - 00013781 _____ C:\Users\Dusan\Desktop\FRST.txt
2014-01-03 18:03 - 2013-09-13 19:28 - 00000000 ____D C:\Users\Dusan\AppData\Roaming\BitTorrent
2014-01-03 18:01 - 2014-01-03 18:01 - 01064581 _____ (Farbar) C:\Users\Dusan\Desktop\FRST.exe
2014-01-03 18:01 - 2014-01-03 18:01 - 00000000 ____D C:\FRST
2014-01-03 18:00 - 2014-01-03 18:00 - 01931750 _____ (Farbar) C:\Users\Dusan\Desktop\FRST64.exe
2014-01-03 17:43 - 2013-09-12 09:14 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-03 17:43 - 2013-09-12 08:12 - 01557579 _____ C:\Windows\WindowsUpdate.log
2014-01-03 17:38 - 2013-12-18 12:40 - 00000190 _____ C:\Users\Dusan\Desktop\usernames.txt
2014-01-03 17:06 - 2013-09-13 10:47 - 00000896 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-03 16:48 - 2014-01-03 16:48 - 00760063 _____ (Farbar) C:\Users\Dusan\Downloads\MiniToolBox.exe
2014-01-03 16:47 - 2014-01-03 16:47 - 00010056 _____ C:\Users\Dusan\Desktop\Result.txt
2014-01-03 16:43 - 2013-12-31 01:05 - 00000000 ____D C:\ProgramData\MFAData
2014-01-03 16:42 - 2014-01-03 16:41 - 00000000 ____D C:\Users\Dusan\Desktop\FBfish
2014-01-03 16:29 - 2013-12-01 16:24 - 00000928 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2535210753-593524891-364156895-1000UA.job
2014-01-03 16:29 - 2013-12-01 16:24 - 00000906 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2535210753-593524891-364156895-1000Core.job
2014-01-03 16:16 - 2014-01-03 16:16 - 00020976 _____ C:\Users\Dusan\Desktop\dds.txt
2014-01-03 16:16 - 2014-01-03 16:16 - 00011461 _____ C:\Users\Dusan\Desktop\attach.txt
2014-01-03 16:14 - 2014-01-03 16:14 - 00688992 ____R (Swearware) C:\Users\Dusan\Desktop\dds.scr
2014-01-03 14:30 - 2009-07-14 05:45 - 00014336 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-03 14:30 - 2009-07-14 05:45 - 00014336 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-03 14:26 - 2013-10-12 16:39 - 00000000 ____D C:\ProgramData\MCShield
2014-01-03 14:26 - 2013-09-13 10:47 - 00000892 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-03 14:26 - 2013-09-12 11:53 - 00000436 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2014-01-03 14:25 - 2014-01-03 14:25 - 00000056 _____ C:\Windows\setupact.log
2014-01-03 14:25 - 2014-01-03 14:25 - 00000000 _____ C:\Windows\setuperr.log
2014-01-03 14:25 - 2013-09-12 09:27 - 00000000 ____D C:\ProgramData\NVIDIA
2014-01-03 14:25 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-03 03:47 - 2013-12-22 19:40 - 00000000 ____D C:\Users\Dusan\AppData\Roaming\DAEMON Tools Lite
2014-01-03 03:47 - 2013-10-20 12:34 - 00000000 ____D C:\Users\Dusan\AppData\Roaming\FileZilla
2014-01-03 02:01 - 2013-09-17 18:25 - 00000000 ____D C:\Users\Dusan\AppData\Local\Adobe
2014-01-02 17:41 - 2014-01-02 17:41 - 00448512 _____ (OldTimer Tools) C:\Users\Dusan\Desktop\TFC.exe
2014-01-02 16:57 - 2013-09-18 22:56 - 00000132 _____ C:\Users\Dusan\AppData\Roaming\Adobe PNG Format CS6 Prefs
2014-01-01 18:39 - 2014-01-01 18:26 - 00000000 ____D C:\Users\Dusan\Desktop\Gmail
2014-01-01 13:00 - 2014-01-01 03:20 - 00000182 _____ C:\Users\Dusan\Desktop\kvota3.txt
2014-01-01 04:09 - 2013-11-26 20:57 - 00000000 ____D C:\Users\Dusan\Desktop\Ostalo
2013-12-31 15:31 - 2013-12-31 01:05 - 00000000 ____D C:\Users\Dusan\AppData\Local\Avg2014
2013-12-31 01:15 - 2013-12-31 01:15 - 00003230 _____ C:\Windows\System32\Tasks\SidebarExecute
2013-12-31 01:15 - 2013-12-31 01:15 - 00000000 ____D C:\Users\Dusan\AppData\Roaming\AVG2014
2013-12-31 01:15 - 2013-12-31 01:13 - 00000000 ____D C:\ProgramData\AVG2014
2013-12-31 01:14 - 2013-12-31 01:14 - 00000965 _____ C:\Users\Public\Desktop\AVG 2014.lnk
2013-12-31 01:14 - 2013-12-31 01:14 - 00000000 ____D C:\Users\Dusan\AppData\Roaming\TuneUp Software
2013-12-31 01:13 - 2013-12-31 01:13 - 00000000 ___HD C:\$AVG
2013-12-31 01:13 - 2013-12-31 01:13 - 00000000 ____D C:\Program Files (x86)\AVG
2013-12-31 01:05 - 2013-12-31 01:05 - 00000000 ____D C:\Users\Dusan\AppData\Local\MFAData
2013-12-31 00:56 - 2013-09-12 09:52 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2013-12-28 20:15 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-12-28 15:00 - 2013-09-12 09:47 - 00128464 _____ C:\Users\Dusan\AppData\Local\GDIPFONTCACHEV1.DAT
2013-12-28 15:00 - 2009-07-14 05:45 - 05150096 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-27 23:06 - 2013-12-27 22:51 - 01678200 _____ C:\Users\Dusan\Desktop\cabj.psd
2013-12-25 06:27 - 2009-07-14 06:13 - 00872538 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-22 19:55 - 2013-12-22 19:55 - 00002150 _____ C:\Users\Public\Desktop\Sniper Elite Nazi Zombie Army 2.lnk
2013-12-22 19:55 - 2013-12-22 19:50 - 00000000 ____D C:\Program Files (x86)\Sniper Elite Nazi Zombie Army 2
2013-12-22 19:48 - 2013-12-22 19:40 - 00000000 ____D C:\ProgramData\DAEMON Tools Lite
2013-12-22 19:41 - 2013-12-22 19:41 - 00001950 _____ C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
2013-12-22 19:41 - 2013-12-22 19:40 - 00283064 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtsoftbus01.sys
2013-12-22 19:40 - 2013-12-22 19:40 - 00000000 ____D C:\Program Files (x86)\DAEMON Tools Lite
2013-12-22 14:43 - 2013-12-22 14:41 - 00000000 ____D C:\Users\Dusan\Desktop\wordpress
2013-12-22 14:41 - 2013-12-22 14:41 - 06367550 _____ C:\Users\Dusan\Desktop\wordpress-3.8.zip
2013-12-22 14:28 - 2013-12-22 14:28 - 00477612 _____ C:\Users\Dusan\Desktop\compasso.zip
2013-12-22 14:05 - 2013-12-22 14:04 - 13158700 _____ C:\Users\Dusan\Desktop\megazine106.rar
2013-12-22 01:01 - 2013-12-22 01:01 - 00000315 _____ C:\Users\Dusan\Desktop\oglasii.txt
2013-12-21 21:05 - 2013-12-21 21:05 - 00069527 _____ C:\Users\Dusan\Desktop\bangkok.psd
2013-12-21 15:44 - 2013-12-21 15:44 - 00002772 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2013-12-21 15:44 - 2013-12-21 15:44 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-12-21 15:44 - 2013-12-21 15:44 - 00000000 ____D C:\Program Files\CCleaner
2013-12-20 18:45 - 2013-11-09 14:48 - 00000000 ____D C:\Users\Dusan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth Devices
2013-12-18 16:55 - 2013-12-18 16:55 - 00001099 _____ C:\Users\Public\Desktop\Web Page Maker.lnk
2013-12-18 16:55 - 2013-12-18 16:55 - 00000000 ____D C:\Users\Dusan\Documents\Web Page Maker
2013-12-18 16:55 - 2013-12-18 16:55 - 00000000 ____D C:\Users\Dusan\AppData\Roaming\Web Page Maker
2013-12-18 16:55 - 2013-12-18 16:55 - 00000000 ____D C:\ProgramData\Web Page Maker
2013-12-18 16:55 - 2013-12-18 16:55 - 00000000 ____D C:\Program Files (x86)\Web Page Maker
2013-12-18 16:55 - 2013-12-18 16:54 - 03638090 _____ (Web Page Maker Software Company, Inc. ) C:\Users\Dusan\Desktop\wpm.exe
2013-12-18 13:34 - 2013-12-11 21:25 - 00000000 ____D C:\Users\Dusan\Desktop\Besplatni_tokeni_12-11-13
2013-12-18 12:42 - 2013-12-18 12:42 - 00000165 _____ C:\Users\Dusan\Desktop\usernames.rar
2013-12-16 21:55 - 2013-12-16 21:55 - 00000797 _____ C:\Users\Public\Desktop\RAR Password Unlocker.lnk
2013-12-12 06:59 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2013-12-12 06:42 - 2013-09-28 16:59 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-12-11 19:46 - 2013-11-23 12:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-11 19:46 - 2013-09-11 23:27 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-12-11 14:52 - 2013-11-11 10:59 - 00000000 ____D C:\AdwCleaner
2013-12-11 14:50 - 2013-11-26 20:59 - 00000000 ____D C:\Users\Dusan\Desktop\Programi
2013-12-10 22:16 - 2013-12-10 21:56 - 00001126 _____ C:\Users\Dusan\Desktop\Adobe Premiere Pro CS5.5.lnk
2013-12-10 21:59 - 2013-09-12 09:15 - 00000000 ____D C:\Users\Dusan\AppData\Roaming\Adobe
2013-12-10 21:57 - 2013-12-10 21:57 - 00000000 ____D C:\Users\Dusan\Documents\Adobe
2013-12-10 21:57 - 2013-12-10 21:57 - 00000000 ____D C:\Users\Dusan\AppData\Roaming\PACE Anti-Piracy
2013-12-10 21:57 - 2013-12-10 21:57 - 00000000 ____D C:\Users\Dusan\AppData\Local\PACE Anti-Piracy
2013-12-10 21:57 - 2013-12-10 21:57 - 00000000 ____D C:\ProgramData\PACE Anti-Piracy
2013-12-10 21:57 - 2013-08-15 21:27 - 00000000 ___HD C:\Users\Dusan\AppData\Local\jeyEdA8v
2013-12-10 21:57 - 2013-04-07 10:53 - 00000000 ___HD C:\Users\Dusan\AppData\Local\c3IAJIqkL
2013-12-10 21:55 - 2013-10-02 21:47 - 00000000 ____D C:\Program Files\Fraps
2013-12-10 21:54 - 2013-09-17 18:46 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2013-12-10 21:53 - 2013-09-17 18:43 - 00000000 ____D C:\Program Files\Adobe
2013-12-10 21:53 - 2013-09-17 18:34 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-12-10 21:52 - 2013-09-17 18:38 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-12-10 21:51 - 2013-12-10 21:51 - 00000000 ____D C:\Program Files (x86)\Adobe Story
2013-12-10 21:50 - 2013-12-10 21:50 - 00000000 ____D C:\Program Files (x86)\My Company Name
2013-12-10 21:48 - 2013-12-10 21:48 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2013-12-10 21:48 - 2013-12-10 21:48 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2013-12-10 21:48 - 2013-09-17 18:26 - 00000000 ____D C:\ProgramData\Adobe
2013-12-10 06:47 - 2009-07-14 06:08 - 00032628 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-12-08 18:57 - 2013-12-08 18:57 - 00001085 _____ C:\Users\Dusan\Desktop\Cheat Engine.lnk
2013-12-08 18:57 - 2013-12-08 18:57 - 00000000 ____D C:\Users\Dusan\Documents\My Cheat Tables
2013-12-08 18:57 - 2013-12-08 18:57 - 00000000 ____D C:\Program Files (x86)\Cheat Engine 6.3
2013-12-08 03:01 - 2013-12-08 03:01 - 00000000 ____D C:\Program Files (x86)\GUME924.tmp
2013-12-08 03:01 - 2013-09-13 10:47 - 00003892 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-12-08 03:01 - 2013-09-13 10:47 - 00003640 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-12-07 04:09 - 2013-09-12 09:08 - 00000000 ____D C:\Windows\Panther
2013-12-05 02:02 - 2013-09-13 10:48 - 00002185 _____ C:\Users\Public\Desktop\Google Chrome.lnk
Some content of TEMP:
====================
C:\Users\Dusan\AppData\Local\Temp\drm_dialogs.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-12-28 19:33
==================== End Of Log ============================
mycity.rs/must-login.png
|
|
|
|
|
Poslao: 03 Jan 2014 18:53
|
offline
- ifix
![Male](https://www.mycity.rs/templates/simplified/images2/user-sex.gif)
- Građanin
- Pridružio: 20 Okt 2013
- Poruke: 180
|
Igrica je bila PES 2013, a virus je prikazalo u njegovom kreku, avg jeste brisao ali ne znam kako je to uradio, jer mi je nekoliko trenutaka dok nisam obrisao celu igricu procesor radio na 100%
Da li negde u avg-u mogu da nadjem kako je to odradio i da vam posaljem?
mycity.rs/must-login.png
Gmer 2 nisam uspeo da odradim, prvi put mi se iskljucio Gmer, a drugi put mi se pojavio plavi ekran i restartovao mi se racunar.
|
|
|
|
|
Poslao: 03 Jan 2014 21:43
|
offline
- ifix
![Male](https://www.mycity.rs/templates/simplified/images2/user-sex.gif)
- Građanin
- Pridružio: 20 Okt 2013
- Poruke: 180
|
Sada trenutno je dobro, ali pre nego sto sam otvorio temu ga je povremeno zabadalo.
Desava mi se da pri kucanju cekam da se slova pojave pa me brine da nije upala neka vrsta keylogera.
Imam jedno pitanje sto se tice avg pc analizera, ne koristim ga ali sam samo sa njime skenirao racunar i pise mi da ima 236 errors found za registry, sto je na crvenoj zoni, pa me zanima da li mogu nekako da sredim registry i kako, mozda se zbog njega javljaju problemi?
Takodje i junk files ima 137 gresaka...
|
|
|
|
Poslao: 03 Jan 2014 22:05
|
rip
- argus
![Male](https://www.mycity.rs/templates/simplified/images2/user-sex.gif)
- Anti Malware Fighter
Rank 2
- Pridružio: 27 Apr 2008
- Poruke: 9160
- Gde živiš: Prokuplje
|
1. Otvori Notepad (Text Document) i iskopiraj sledeći tekst unutar kod polja ispod:
Start
2013-12-31 00:56 - 2013-09-12 09:52 - 00000000 ____D C:\ProgramData\Kaspersky Lab
HKCU\...\Run: [LiveSupport] - "C:\Program Files (x86)\LiveSupport\LiveSupport.exe" /noshow /log
C:\Program Files (x86)\LiveSupport
C:\Users\Dusan\AppData\Local\Temp\drm_dialogs.dll
AlternateDataStreams: C:\Users\Dusan\AppData\Local\c3IAJIqkL:ZOdKCOU91TPQNY7jawk
AlternateDataStreams: C:\Users\Dusan\AppData\Local\jeyEdA8v:11iThyl7HaQ2ZHgGhvCgcpN2o
AlternateDataStreams: C:\Users\Dusan\AppData\Local\Temporary Internet Files:nVpKFn9JtCSgwkqG4ACmshFfwoB
End
2. Sačuvaj notepad na Desktop pod nazivom fixlist.txt
To možes uraditi i iz notepad-a => klik na File potom na Save As i u novom prozoru, dole pod File Name: staviš za naziv fixlist.txt
Napomena: Važno je da se oba fajla, FRST i fixlist nalaze na istoj lokaciji jer u suprotnom fix nece raditi.
3. Ponovo pokreni FRST/FRST64, klikni jednom na dugme Fix i sačekaj.
Ukoliko alat zatraži restart sistema, dozvoli mu i postaraj se da alat kompletira fix nakon restarta sistema.
Alat će formirati log (Fixlog.txt) na Desktop-u. Potrebno je sadržaj tog loga iskopirati u poruku.
Napomena: Ukoliko te alat upozori da postoji novija verzija, postaraj se da preuzmes i koristiš ažuriranu kopiju FRST-a.
Preporuka:
Imas TFC Cleaner iskoristi ga.
Imas CCleaner, takodje i njega iskoristi.
Mani se tih raznih registry cleanera tipa avg pc analizera, brisi to.
|
|
|
|
Poslao: 03 Jan 2014 22:26
|
offline
- ifix
![Male](https://www.mycity.rs/templates/simplified/images2/user-sex.gif)
- Građanin
- Pridružio: 20 Okt 2013
- Poruke: 180
|
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 03-01-2014
Ran by Dusan at 2014-01-03 22:23:17 Run:1
Running from C:\Users\Dusan\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
2013-12-31 00:56 - 2013-09-12 09:52 - 00000000 ____D C:\ProgramData\Kaspersky Lab
HKCU\...\Run: [LiveSupport] - "C:\Program Files (x86)\LiveSupport\LiveSupport.exe" /noshow /log
C:\Program Files (x86)\LiveSupport
C:\Users\Dusan\AppData\Local\Temp\drm_dialogs.dll
AlternateDataStreams: C:\Users\Dusan\AppData\Local\c3IAJIqkL:ZOdKCOU91TPQNY7jawk
AlternateDataStreams: C:\Users\Dusan\AppData\Local\jeyEdA8v:11iThyl7HaQ2ZHgGhvCgcpN2o
AlternateDataStreams: C:\Users\Dusan\AppData\Local\Temporary Internet Files:nVpKFn9JtCSgwkqG4ACmshFfwoB
End
*****************
C:\ProgramData\Kaspersky Lab => Moved successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\LiveSupport => Value deleted successfully.
"C:\Program Files (x86)\LiveSupport" => File/Directory not found.
C:\Users\Dusan\AppData\Local\Temp\drm_dialogs.dll => Moved successfully.
C:\Users\Dusan\AppData\Local\c3IAJIqkL => ":ZOdKCOU91TPQNY7jawk" ADS removed successfully.
C:\Users\Dusan\AppData\Local\jeyEdA8v => ":11iThyl7HaQ2ZHgGhvCgcpN2o" ADS removed successfully.
"C:\Users\Dusan\AppData\Local\Temporary Internet Files" => ":nVpKFn9JtCSgwkqG4ACmshFfwoB" ADS not found.
==== End of Fixlog ====
Koristim CCleaner ali koristim samo Cleaner, da li smem da i Registry da sredjujem sa njim?
Sada cu da uradim i ciscenje sa TFC Cleanerom...
|
|
|
|
Poslao: 03 Jan 2014 22:39
|
rip
- argus
![Male](https://www.mycity.rs/templates/simplified/images2/user-sex.gif)
- Anti Malware Fighter
Rank 2
- Pridružio: 27 Apr 2008
- Poruke: 9160
- Gde živiš: Prokuplje
|
Citat:da li smem da i Registry da sredjujem sa njim?
Bez problema.
Preuzmi "Xplode"-ov DelFix i sačuvaj ga na Desktop
Dvoklikom pokreni program.
Štikliraj sledeće opcije:
Remove disinfection tools
Purge System Restore
Reset system settings
Klikni na dugme "Run" i pričekaj da program završi rad.
Alat ce ukloniti sve koriscene alate u ovoj temi...
Kada alat završi, otvoriće izvestaj u notepadu.
Napomena: Izvestaj ce takodje biti sacuvan na C:\DelFix.txt
Nije potrebno dostavljati izvestaj.
|
|
|
|