Windows 7 koristi previse rama(moguci virus)

1

Windows 7 koristi previse rama(moguci virus)

offline
  • Pridružio: 04 Jun 2015
  • Poruke: 9

Napisano: 05 Jun 2015 2:44

Pozz Very Happy . Imam problem sa Windows 7 jer mi je poceo u zadnje vreme da koristi previse rama , pre kad upalim komp on trosi 2 gb rama . Tako je i sada kad ga upalim sve je normalno koristi nekih 2.2 gb posle jedno 10 minutra koriscenja on pocne da koristi 7 gb rama pa posle jos nekih 10 min 11 gb. I pocne komp jako da mi baguje i ako mi je ostalo jos 5 gb slobodno. Ja sumnjam da imam neki virus ili tako nesto slicno. Ako neko zna sta je neka pomogne jer mi se ne obara windows Sad .I problem je sto windows nekada radi sasvim dobro i sve je super al od jednom samo pocne da baguje. Kad otvorim Task Manager i pogledam koliko koristi rama ono je uvek isti broj 7.3 i 11.7 gb.

Skenirao sam komp kako mi je receno ovde :http://www.mycity.rs/Ambulanta/Kako-otvoriti-temu-u-Ambulanti.html


mycity.rs/must-login.png

mycity.rs/must-login.png

Dopuna: 05 Jun 2015 2:55

Skenirao sam kompjuter sa Avastom i nista mi nije nasao , probao sam MCShield da skenira da nema nekih malvera al nista nije nasao.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:03-06-2015
Ran by Nikola (administrator) on NIKOLA-PC on 05-06-2015 02:37:21
Running from C:\Users\Nikola\Downloads
Loaded Profiles: Nikola (Available Profiles: Nikola)
Platform: Windows 7 Ultimate N Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: geekstogo.com/forum/topic/335081-frst-t.....scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(The Within Network, LLC) C:\Windows\UnsignedThemesSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(DTS, Inc) C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler64.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
(A-Volute) C:\ProgramData\Razer\Synapse\Devices\Razer Surround\Driver\RzSurroundVADStreamingService.exe
(Rocket Division Software) C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(CyberGhost S.R.L) C:\Program Files\CyberGhost 5\Service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7202520 2013-08-19] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_DTS] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1321688 2013-08-07] (Realtek Semiconductor)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2754704 2015-05-23] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3978600 2015-03-30] (LogMeIn Inc.)
HKU\S-1-5-21-1269221854-1059928380-260943180-1000\...\Run: [vibranceGUI] => "C:\Users\Nikola\AppData\Local\Temp\Rar$EXa0.973\vibrance.GUI.exe" -minimized <===== ATTENTION
HKU\S-1-5-21-1269221854-1059928380-260943180-1000\...\Run: [Viber] => C:\Users\Nikola\AppData\Local\Viber\Viber.exe [80036560 2015-05-25] ()
HKU\S-1-5-21-1269221854-1059928380-260943180-1000\...\MountPoints2: G - G:\OriginInstaller.exe
HKU\S-1-5-21-1269221854-1059928380-260943180-1000\...\MountPoints2: H - H:\Setup.exe autorun
HKU\S-1-5-21-1269221854-1059928380-260943180-1000\...\MountPoints2: {8056259a-e012-11e4-9fa9-806e6f6e6963} - E:\.\Bin\ASSETUP.exe
HKU\S-1-5-21-1269221854-1059928380-260943180-1000\...\Winlogon: [Shell] C:\Windows\expstart.exe [925184 2015-05-30] () <==== ATTENTION
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

ProxyServer: [S-1-5-21-1269221854-1059928380-260943180-1000] => http=;ftp=;https=;
HKU\S-1-5-21-1269221854-1059928380-260943180-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = msn.com/de-de/?ocid=iehp
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2014-07-07] (CANON INC.)
BHO: No Name -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> No File
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11] (Adobe Systems Incorporated)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2014-07-07] (CANON INC.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-04-28] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-28] (Oracle Corporation)
BHO-x32: No Name -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> No File
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-07-07] (CANON INC.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-07-07] (CANON INC.)
Toolbar: HKU\S-1-5-21-1269221854-1059928380-260943180-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKU\S-1-5-21-1269221854-1059928380-260943180-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKU\S-1-5-21-1269221854-1059928380-260943180-1000 -> Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-07-07] (CANON INC.)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2013-03-21] (Adobe Systems)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-28] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-28] (Oracle Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-05-28] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-05-28] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2013-03-21] (Adobe Systems)

Chrome:
=======
CHR Profile: C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-04-11]
CHR Extension: (Google Search) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-04-11]
CHR Extension: (Bookmark Manager) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-21]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-04-11]
CHR Extension: (Google Wallet) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-04-11]
CHR Extension: (Gmail) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-11]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-11-20] (Advanced Micro Devices, Inc.) [File not signed]
S2 AODService; C:\Program Files (x86)\AMD\OverDrive\AODAssist.exe [137584 2014-09-19] ()
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-19] (Apple Inc.)
R2 CGVPNCliService; C:\Program Files\CyberGhost 5\Service.exe [64616 2014-11-03] (CyberGhost S.R.L)
S3 Disc Soft Ultra Bus Service; C:\Program Files (x86)\DAEMON Tools Ultra\DiscSoftBusService.exe [1378576 2015-02-27] (Disc Soft Ltd)
R2 DTSAudioSvc; C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [240584 2012-10-02] (DTS, Inc)
S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [344288 2015-03-20] (Futuremark)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152656 2015-05-23] (NVIDIA Corporation)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2015-03-30] (LogMeIn, Inc.)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1893008 2015-05-23] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [23006864 2015-05-23] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76152 2015-05-29] ()
R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [187072 2015-02-05] ()
R2 RzSurroundVADStreamingService; C:\ProgramData\Razer\Synapse\Devices\Razer Surround\Driver\RzSurroundVADStreamingService.exe [4250624 2015-02-03] (A-Volute) [File not signed]
R2 StarWindServiceAE; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [275968 2007-05-28] (Rocket Division Software) [File not signed]
S3 Survarium-Steam Update Service; D:\Program Files (x86)\Steam\steamapps\common\Survarium\game\binaries\x86\survarium_service.exe [97912 2015-05-08] ()
R2 UnsignedThemes; C:\Windows\UnsignedThemesSvc.exe [24168 2009-07-13] (The Within Network, LLC)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AODDriver4.3; C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
R2 AODDriver4.3.0; C:\Program Files (x86)\AMD\OverDrive\amd64\AODDriver2.sys [60104 2014-09-19] (Advanced Micro Devices)
R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [49760 2012-01-06] (Asmedia Technology)
R3 CORK50; C:\Windows\System32\drivers\CORK50.sys [25600 2012-08-10] ( )
S3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30352 2015-05-06] (Disc Soft Ltd)
R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2015-05-04] (DT Soft Ltd)
R3 dtultrascsibus; C:\Windows\System32\DRIVERS\dtultrascsibus.sys [30352 2015-05-06] (Disc Soft Ltd)
S3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv.sys [49304 2014-12-29] (Visicom Media Inc.)
S3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [35992 2014-12-29] (Visicom Media Inc.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-05-23] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38032 2015-04-03] (NVIDIA Corporation)
S3 RTCore64; D:\Program Files (x86)\MSI Afterburner\RTCore64.sys [13368 2013-03-11] ()
R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [37184 2015-02-05] (Razer, Inc.)
R2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [129600 2015-03-03] (Razer, Inc.)
R3 RZSURROUNDVADService; C:\Windows\System32\drivers\RzSurroundVAD.sys [40640 2015-02-09] (Windows (R) Win 7 DDK provider)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [868848 2015-05-01] () [File not signed]
S3 ssdevfactory; C:\Windows\System32\DRIVERS\ssdevfactory.sys [41520 2015-05-29] (SteelSeries ApS)
S3 sshid; C:\Windows\System32\DRIVERS\sshid.sys [52344 2015-05-29] (SteelSeries ApS)
R2 uxpatch; C:\Windows\system32\drivers\uxpatch.sys [30568 2009-07-13] ()
U3 ag5xzn86; C:\Windows\System32\Drivers\ag5xzn86.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero byte File/Folder)
S3 GPUZ; \??\C:\Windows\TEMP\GPUZ.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-05 02:34 - 2015-06-05 02:37 - 00015436 _____ C:\Users\Nikola\Downloads\FRST.txt
2015-06-05 02:34 - 2015-06-05 02:35 - 00043848 _____ C:\Users\Nikola\Downloads\Addition.txt
2015-06-05 02:33 - 2015-06-05 02:37 - 00000000 ____D C:\FRST
2015-06-05 02:32 - 2015-06-05 02:32 - 02108928 _____ (Farbar) C:\Users\Nikola\Downloads\FRST64.exe
2015-06-04 15:09 - 2015-06-04 15:09 - 00000039 _____ C:\Users\Nikola\Desktop\New Text Document.txt
2015-06-03 23:01 - 2015-06-04 21:50 - 00000000 ____D C:\Users\Nikola\AppData\Roaming\ViberPC
2015-06-03 23:01 - 2015-06-04 21:32 - 00000000 ____D C:\Users\Nikola\AppData\Local\Viber
2015-06-03 23:01 - 2015-06-03 23:01 - 00000998 _____ C:\Users\Nikola\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Viber.lnk
2015-06-03 22:59 - 2015-06-03 23:00 - 64311016 _____ (Viber Media Inc) C:\Users\Nikola\Downloads\ViberSetup.exe
2015-06-03 17:34 - 2015-06-03 17:34 - 00000222 _____ C:\Users\Nikola\Desktop\Heroes & Generals.url
2015-06-03 14:11 - 2015-05-28 05:52 - 00571024 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2015-06-03 14:10 - 2015-05-28 09:04 - 42719888 _____ C:\Windows\system32\nvcompiler.dll
2015-06-03 14:10 - 2015-05-28 09:04 - 37741712 _____ C:\Windows\SysWOW64\nvcompiler.dll
2015-06-03 14:10 - 2015-05-28 09:04 - 30480528 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2015-06-03 14:10 - 2015-05-28 09:04 - 22946960 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2015-06-03 14:10 - 2015-05-28 09:04 - 16185352 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2015-06-03 14:10 - 2015-05-28 09:04 - 14987528 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2015-06-03 14:10 - 2015-05-28 09:04 - 14495448 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2015-06-03 14:10 - 2015-05-28 09:04 - 13304280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2015-06-03 14:10 - 2015-05-28 09:04 - 11830512 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2015-06-03 14:10 - 2015-05-28 09:04 - 10995528 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2015-06-03 14:10 - 2015-05-28 09:04 - 02932368 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2015-06-03 14:10 - 2015-05-28 09:04 - 02599056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2015-06-03 14:10 - 2015-05-28 09:04 - 01898312 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6435306.dll
2015-06-03 14:10 - 2015-05-28 09:04 - 01557832 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6435306.dll
2015-06-03 14:10 - 2015-05-28 09:04 - 01099808 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2015-06-03 14:10 - 2015-05-28 09:04 - 01059984 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2015-06-03 14:10 - 2015-05-28 09:04 - 01050440 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2015-06-03 14:10 - 2015-05-28 09:04 - 00982856 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2015-06-03 14:10 - 2015-05-28 09:04 - 00974480 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2015-06-03 14:10 - 2015-05-28 09:04 - 00939080 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2015-06-03 14:10 - 2015-05-28 09:04 - 00503408 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2015-06-03 14:10 - 2015-05-28 09:04 - 00408208 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2015-06-03 14:10 - 2015-05-28 09:04 - 00407112 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2015-06-03 14:10 - 2015-05-28 09:04 - 00364176 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2015-06-03 14:10 - 2015-05-28 09:04 - 00175880 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2015-06-03 14:10 - 2015-05-28 09:04 - 00154256 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2015-06-03 14:10 - 2015-05-28 09:04 - 00150648 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2015-06-03 14:10 - 2015-05-28 09:04 - 00128512 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2015-06-02 19:10 - 2015-06-02 19:10 - 00311057 _____ C:\Users\Nikola\Downloads\ScriptHookV_1.0.350.2b.zip
2015-06-02 18:58 - 2015-06-02 18:58 - 00725884 _____ C:\Users\Nikola\Downloads\6d22a7-Drift Only Mod.rar
2015-06-02 18:58 - 2015-06-02 18:58 - 00725884 _____ C:\Users\Nikola\Desktop\6d22a7-Drift Only Mod.rar
2015-06-02 18:58 - 2015-05-10 22:45 - 00000000 ____D C:\Users\Nikola\Desktop\Drift Only Mod
2015-06-01 17:13 - 2015-06-01 17:13 - 00000000 ____D C:\Users\Nikola\AppData\Roaming\Wargaming.net
2015-06-01 09:33 - 2015-06-01 09:33 - 00000677 _____ C:\Users\Public\Desktop\World of Tanks.lnk
2015-06-01 09:33 - 2015-06-01 09:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Tanks
2015-06-01 09:32 - 2015-06-01 09:32 - 06309488 _____ (Wargaming.net ) C:\Users\Nikola\Downloads\WoT_internet_install_eu.exe
2015-05-31 21:02 - 2015-05-31 21:03 - 36270420 _____ C:\Users\Nikola\Downloads\MSIAfterburnerSetup.zip
2015-05-31 17:27 - 2015-05-31 17:27 - 00000000 ____D C:\Windows\system32\appmgmt
2015-05-31 01:27 - 2015-06-05 02:28 - 00000000 ____D C:\Users\Nikola\AppData\Local\LogMeIn Hamachi
2015-05-31 01:27 - 2015-05-31 01:27 - 00000000 ____D C:\Users\Nikola\AppData\Local\LogMeIn
2015-05-31 01:27 - 2015-05-31 01:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2015-05-31 01:27 - 2015-05-31 01:27 - 00000000 ____D C:\ProgramData\LogMeIn
2015-05-31 01:27 - 2015-05-31 01:27 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi
2015-05-31 01:26 - 2015-05-31 01:26 - 08552448 _____ C:\Users\Nikola\Downloads\hamachi_2.2.0.328.msi
2015-05-30 23:32 - 2015-05-30 23:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Survarium-Steam
2015-05-30 23:29 - 2015-06-04 22:10 - 00000000 ____D C:\Users\Nikola\Documents\Survarium-Steam
2015-05-30 22:15 - 2015-05-30 22:15 - 00000222 _____ C:\Users\Nikola\Desktop\Survarium.url
2015-05-30 10:05 - 2015-05-30 10:05 - 00000000 ____D C:\Program Files\DIFX
2015-05-30 10:03 - 2015-05-30 10:04 - 76402440 _____ C:\Users\Nikola\Downloads\SteelSeriesEngine3.3.7Setup.exe
2015-05-30 08:36 - 2015-05-30 08:36 - 00000000 ____D C:\Users\Nikola\AppData\Roaming\Mozilla
2015-05-30 08:29 - 2015-05-30 08:29 - 00206064 _____ C:\Users\Nikola\Downloads\All_CPU473_Meter.zip
2015-05-30 08:29 - 2015-05-30 08:29 - 00000627 _____ C:\Users\Nikola\AppData\Roaming\All CPU MeterV3_Settings.ini
2015-05-30 08:28 - 2015-05-30 08:28 - 01197344 _____ C:\Users\Nikola\Downloads\All CPU Meter - CHIP-Installer.exe
2015-05-30 07:19 - 2015-05-30 07:19 - 00216168 _____ C:\Users\Nikola\Downloads\Windows_7_Start_Orb_Changer.zip
2015-05-30 07:18 - 2015-05-30 07:18 - 01197344 _____ C:\Users\Nikola\Downloads\Windows 7 Start Orb Changer - CHIP-Installer.exe
2015-05-30 07:15 - 2015-05-30 07:17 - 00000000 ____D C:\Windows\system32\W7NBC
2015-05-30 07:15 - 2015-05-30 07:15 - 00206937 _____ C:\Users\Nikola\Downloads\Windows 7 Navigation Buttons Customizer.zip
2015-05-30 07:12 - 2015-05-30 07:12 - 00000094 _____ C:\Windows\StyleBuilder.INI
2015-05-30 07:11 - 2015-05-30 07:11 - 01818592 _____ C:\Users\Nikola\Downloads\StyleBuilderInstall2beta.zip
2015-05-30 07:11 - 2015-05-30 07:11 - 01197344 _____ C:\Users\Nikola\Downloads\StyleBuilder - CHIP-Installer.exe
2015-05-30 07:01 - 2015-05-30 07:19 - 00925184 _____ C:\Windows\expstart.exe
2015-05-30 07:01 - 2015-05-30 07:02 - 00000000 ____D C:\Windows\W7SOC
2015-05-30 07:01 - 2015-05-30 07:01 - 02748928 _____ (door2windows) C:\Users\Nikola\Downloads\!Windows 7 Start Orb Changer.exe
2015-05-30 07:01 - 2015-05-30 06:40 - 02872320 _____ (Microsoft Corporation) C:\Windows\explorer.backup.exe
2015-05-30 06:53 - 2014-09-20 08:11 - 01490944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2015-05-30 06:53 - 2014-09-20 05:13 - 19755008 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-05-30 06:53 - 2014-09-20 05:13 - 18455040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2015-05-30 06:53 - 2014-09-20 04:52 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\timedate.cpl
2015-05-30 06:50 - 2015-05-30 06:50 - 03038128 _____ C:\Users\Nikola\Downloads\UxStyle_Core_jul13_bits.zip
2015-05-30 06:47 - 2015-05-30 06:49 - 12681023 _____ C:\Users\Nikola\Downloads\Amdpack.7z
2015-05-30 06:43 - 2015-05-30 06:44 - 23420028 _____ C:\Users\Nikola\Downloads\SkinPack_Alienred_3.0.zip
2015-05-30 06:40 - 2012-06-07 09:45 - 00000000 ____D C:\Windows\SysWOW64\ROG_Video Intro dir
2015-05-30 06:40 - 2011-10-28 16:01 - 00680960 _____ (ASUSTeK Computer Inc.) C:\Windows\SysWOW64\ROGThemeSetup.exe
2015-05-30 06:40 - 2011-10-26 11:33 - 00201728 _____ (ScreenTime Media) C:\Windows\SysWOW64\ROG_Video Intro .scr
2015-05-30 06:40 - 2010-11-21 05:24 - 02872320 _____ (Microsoft Corporation) C:\Windows\explorer.exe.rogbak
2015-05-30 06:39 - 2015-05-30 06:39 - 30440998 _____ C:\Users\Nikola\Downloads\TechTraxx-ASUS ROG theme (Windows 7).rar
2015-05-30 06:31 - 2015-05-30 06:31 - 00950345 _____ C:\Users\Nikola\Downloads\WateryDesktop3D_setup.zip
2015-05-30 03:24 - 2015-05-30 03:24 - 04532776 _____ (Piriform Ltd) C:\Users\Nikola\Downloads\dfsetup219.exe
2015-05-30 03:23 - 2015-05-30 03:24 - 00000000 ____D C:\Program Files\Defraggler
2015-05-30 03:23 - 2015-05-30 03:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Defraggler
2015-05-30 03:22 - 2015-05-30 03:22 - 04362512 _____ (Piriform Ltd) C:\Users\Nikola\Downloads\dfsetup218.exe
2015-05-30 03:12 - 2015-05-30 03:18 - 00000000 ____D C:\Windows\pss
2015-05-30 02:24 - 2015-05-30 02:24 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2015-05-30 02:24 - 2015-05-30 02:24 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2015-05-30 00:58 - 2015-05-31 17:29 - 00000000 ____D C:\ProgramData\AVAST Software
2015-05-30 00:58 - 2015-05-30 00:58 - 05481344 _____ (Avast Software s.r.o.) C:\Users\Nikola\Downloads\avast_free_antivirus_setup.exe
2015-05-29 21:19 - 2015-05-29 21:22 - 00000000 ____D C:\Users\Nikola\Downloads\Left 4 Dead 2 2013 PC full game 2.1.2.5 MP+SP ^^nosTEAM^^
2015-05-29 21:06 - 2015-05-29 21:09 - 160480747 _____ (Pucajte Kod Nas ) C:\Users\Nikola\Downloads\Cs 1.6 [2013] by PKN.exe
2015-05-29 20:19 - 2015-05-29 20:21 - 07396049 _____ C:\Users\Nikola\Downloads\L4d2_2013.exe
2015-05-29 20:13 - 2015-05-31 21:08 - 00347464 _____ C:\Windows\SysWOW64\PnkBstrB.xtr
2015-05-29 20:13 - 2015-05-29 20:13 - 00000000 ____D C:\Users\Nikola\AppData\Local\PunkBuster
2015-05-29 20:06 - 2015-05-31 21:08 - 00347464 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2015-05-29 20:06 - 2015-05-31 21:06 - 00281288 _____ C:\Windows\SysWOW64\PnkBstrB.ex0
2015-05-29 20:06 - 2015-05-29 23:15 - 00076152 _____ C:\Windows\SysWOW64\PnkBstrA.exe
2015-05-29 03:05 - 2015-05-29 03:05 - 01804680 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01011.dll
2015-05-29 03:05 - 2015-05-29 03:05 - 00052344 _____ (SteelSeries ApS) C:\Windows\system32\Drivers\sshid.sys
2015-05-29 03:05 - 2015-05-29 03:05 - 00041520 _____ (SteelSeries ApS) C:\Windows\system32\Drivers\ssdevfactory.sys
2015-05-29 03:05 - 2015-05-29 03:05 - 00017400 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\hidkmdf.sys
2015-05-28 18:45 - 2015-06-03 14:10 - 00000000 ____D C:\ProgramData\boost_interprocess
2015-05-28 18:45 - 2015-04-03 15:21 - 00048784 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2015-05-28 18:45 - 2015-04-03 15:21 - 00038032 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2015-05-28 18:37 - 2015-05-28 18:37 - 00000000 ____D C:\Users\Nikola\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2015-05-28 17:46 - 2015-05-28 17:46 - 00003584 _____ C:\Users\Nikola\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-05-28 17:36 - 2015-05-28 17:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft LifeCam
2015-05-28 17:36 - 2015-05-28 17:36 - 00000000 ____D C:\Program Files\Microsoft LifeCam
2015-05-28 17:36 - 2015-05-28 17:36 - 00000000 ____D C:\Program Files (x86)\Microsoft LifeCam
2015-05-28 17:35 - 2015-05-28 17:35 - 22660464 _____ (Microsoft Corporation) C:\Users\Nikola\Downloads\LifeCam3.60.exe
2015-05-27 22:01 - 2015-05-27 22:01 - 00000000 ____D C:\Users\Nikola\AppData\Roaming\New Technology Studio
2015-05-27 22:01 - 2015-05-27 22:01 - 00000000 ____D C:\Users\Nikola\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenIV
2015-05-27 22:01 - 2015-05-27 22:01 - 00000000 ____D C:\Users\Nikola\AppData\Local\New Technology Studio
2015-05-27 22:00 - 2015-05-27 22:00 - 03984384 _____ (New Technology Studio) C:\Users\Nikola\Downloads\ovisetup.exe
2015-05-27 21:56 - 2015-05-27 21:56 - 00144218 _____ C:\Users\Nikola\Downloads\338acc-Tsunami & No Water Mod.rar
2015-05-25 19:22 - 2015-05-25 20:00 - 00000000 ____D C:\Users\Nikola\Downloads\Half-Life 2
2015-05-25 19:22 - 2015-05-25 19:22 - 00066338 _____ C:\Users\Nikola\Downloads\[kat.cr]half.life.2.torrent
2015-05-25 16:02 - 2015-06-04 21:40 - 00000000 ___RD C:\Users\Nikola\Desktop\SVE AAAAA
2015-05-24 23:01 - 2015-05-24 23:01 - 00432233 _____ C:\Users\Nikola\Downloads\matchmaking_server_picker2_7.zip
2015-05-24 22:24 - 2015-05-24 22:24 - 00000058 _____ C:\Windows\SysWOW64\DonationCoder_ScreenshotCaptor_InstallInfo.dat
2015-05-24 22:24 - 2015-05-24 22:24 - 00000058 _____ C:\Users\Nikola\AppData\Local\DonationCoder_ScreenshotCaptor_InstallInfo.dat
2015-05-24 22:24 - 2015-05-24 22:24 - 00000000 ____D C:\Users\Nikola\Documents\DonationCoder
2015-05-24 22:24 - 2015-05-24 22:24 - 00000000 ____D C:\Users\Nikola\AppData\Roaming\DonationCoder
2015-05-24 22:24 - 2015-05-24 22:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ScreenshotCaptor
2015-05-24 22:24 - 2015-05-24 22:24 - 00000000 ____D C:\ProgramData\DonationCoder
2015-05-24 22:24 - 2015-05-24 22:24 - 00000000 ____D C:\Program Files (x86)\ScreenshotCaptor
2015-05-24 22:23 - 2015-05-24 22:23 - 01196832 _____ C:\Users\Nikola\Downloads\Screenshot Captor - CHIP-Installer (1).exe
2015-05-24 22:22 - 2015-05-24 22:22 - 01196832 _____ C:\Users\Nikola\Downloads\Screenshot Captor - CHIP-Installer.exe
2015-05-23 20:29 - 2015-05-30 10:15 - 00000000 ____D C:\Users\Nikola\AppData\Local\SteelSeries Engine 3 Client
2015-05-23 20:24 - 2015-05-30 10:15 - 00000000 ____D C:\Program Files\SteelSeries
2015-05-23 20:24 - 2015-05-23 20:24 - 00000000 ____H C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Coinstaller_Critical.Wdf
2015-05-23 20:24 - 2015-05-23 20:24 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_sshid_01011.Wdf
2015-05-23 20:24 - 2015-05-23 20:24 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_ssdevfactory_01011.Wdf
2015-05-23 20:24 - 2015-05-23 20:24 - 00000000 ____D C:\Users\admin
2015-05-23 20:24 - 2015-05-23 20:24 - 00000000 ____D C:\ProgramData\SteelSeries
2015-05-23 20:24 - 2015-05-23 20:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SteelSeries
2015-05-23 20:24 - 2012-07-26 06:55 - 00785512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2015-05-23 20:24 - 2012-07-26 06:55 - 00054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
2015-05-23 20:24 - 2012-07-26 04:36 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll
2015-05-23 20:24 - 2012-06-02 16:35 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2015-05-23 20:23 - 2015-05-23 20:23 - 67407976 _____ C:\Users\Nikola\Downloads\SteelSeriesEngine3.3.6.1Setup.exe
2015-05-23 18:21 - 2015-05-23 18:21 - 00000000 ____D C:\Users\Nikola\Documents\My Cheat Tables
2015-05-23 18:21 - 2015-05-23 18:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.4
2015-05-23 18:21 - 2015-05-23 18:21 - 00000000 ____D C:\Program Files (x86)\Cheat Engine 6.4
2015-05-23 18:20 - 2015-05-23 18:20 - 09056784 _____ (Cheat Engine ) C:\Users\Nikola\Downloads\CheatEngine64.exe
2015-05-23 14:16 - 2015-05-23 14:17 - 01636259 ____R C:\Users\Nikola\Downloads\DAZ - Windows Loader v2.1 - WAT November 2011 Activation (zabranjeno) Windows - DeGun TPB.zip
2015-05-23 14:16 - 2015-05-23 14:16 - 00002578 _____ C:\Users\Nikola\Downloads\[kat.cr]windows.7.loader.(zabranjeno).wat.v2.1.0.november.2011.degun.torrent
2015-05-21 09:08 - 2015-05-21 09:08 - 00757560 _____ (Jitbit Software ) C:\Users\Nikola\Downloads\MacroRecorderSetup.exe
2015-05-21 09:08 - 2015-05-21 09:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Macro Recorder
2015-05-21 09:08 - 2015-05-21 09:08 - 00000000 ____D C:\Program Files (x86)\MacroRecorder
2015-05-18 23:22 - 2015-05-13 08:52 - 00195912 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2015-05-18 23:22 - 2015-05-13 08:52 - 00031552 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2015-05-18 23:22 - 2015-05-12 08:27 - 01898312 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6435286.dll
2015-05-18 23:22 - 2015-05-12 08:27 - 01557648 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6435286.dll
2015-05-18 16:48 - 2015-05-30 20:25 - 00000000 ____D C:\Users\Nikola\Desktop\gta 5 navite trainer
2015-05-17 21:55 - 2015-03-03 19:47 - 00129600 _____ (Razer, Inc.) C:\Windows\system32\Drivers\rzpnk.sys
2015-05-17 21:54 - 2015-02-05 01:24 - 00037184 _____ (Razer, Inc.) C:\Windows\system32\Drivers\rzpmgrk.sys
2015-05-17 21:53 - 2015-05-17 21:53 - 00000000 ____D C:\ProgramData\RzSurroundVAD_1.1.60.0
2015-05-17 21:52 - 2015-05-17 21:55 - 00000000 ____D C:\ProgramData\Razer
2015-05-17 21:52 - 2015-05-17 21:55 - 00000000 ____D C:\Program Files (x86)\Razer
2015-05-17 21:52 - 2015-05-17 21:52 - 01725304 _____ (Razer Inc.) C:\Users\Nikola\Downloads\RazerSurroundInstaller_v2.00.10.exe
2015-05-17 21:52 - 2015-05-17 21:52 - 00000000 ____D C:\Users\Nikola\AppData\Local\Razer
2015-05-17 21:52 - 2015-05-17 21:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
2015-05-17 21:38 - 2015-05-17 21:38 - 00000000 ____D C:\Users\Nikola\AppData\Roaming\Autodesk
2015-05-17 21:38 - 2015-05-17 21:38 - 00000000 ____D C:\ProgramData\Autodesk
2015-05-17 21:36 - 2015-05-17 21:36 - 17006000 _____ C:\Users\Nikola\Downloads\AutoCAD_2016_German_Win_32_64bit_wi_de-DE_Setup.exe
2015-05-17 21:36 - 2015-05-17 21:36 - 00000000 ____D C:\Users\Nikola\AppData\Local\Akamai
2015-05-17 21:36 - 2015-05-17 21:36 - 00000000 ____D C:\Autodesk
2015-05-17 21:35 - 2015-05-17 21:36 - 00337744 _____ (Autodesk Inc.) C:\Users\Nikola\Downloads\AutoCAD_2016_German_Win_32_64bit_wi_de-DE_Setup_webinstall.exe
2015-05-16 22:15 - 2015-05-16 22:15 - 00000000 ____D C:\Users\Nikola\AppData\Local\SCE
2015-05-14 19:00 - 2015-05-14 19:00 - 02784484 _____ C:\Users\Nikola\Downloads\AutoHotkey112003_Install.exe
2015-05-13 20:32 - 2015-05-13 20:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trust GXT Gaming Headset
2015-05-13 20:32 - 2015-05-13 20:32 - 00000000 ____D C:\download
2015-05-13 20:32 - 2013-04-26 19:04 - 04326912 _____ (C-Media Electronics Inc) C:\Windows\system32\Drivers\CM10864.sys
2015-05-13 20:30 - 2015-05-13 20:31 - 52350832 _____ C:\Users\Nikola\Downloads\19116_02.exe
2015-05-13 20:20 - 2015-05-13 20:32 - 00001214 _____ C:\Windows\Cm108.ini.imi
2015-05-13 20:20 - 2015-05-13 20:32 - 00001163 _____ C:\Windows\system\Cm108.ini
2015-05-13 20:20 - 2015-05-13 20:32 - 00000734 _____ C:\Windows\Cm108.ini.cfl
2015-05-13 20:20 - 2015-05-13 20:32 - 00000133 _____ C:\Windows\system\Dlap.pfx
2015-05-13 20:20 - 2013-04-28 17:08 - 00002697 ____N C:\Windows\Cm108.ini.cfg
2015-05-13 20:20 - 2013-04-26 19:05 - 12935168 ____N (C-Media Corporation) C:\Windows\SysWOW64\CM108.dll
2015-05-13 20:20 - 2013-04-26 19:05 - 04533760 ____N C:\Windows\system32\CM108.cpl
2015-05-13 20:20 - 2013-04-26 18:40 - 00820224 ____N C:\Windows\system32\Cmeau108.exe
2015-05-13 20:20 - 2013-04-26 18:40 - 00524768 _____ (Microsoft Corporation) C:\Windows\difxapi.dll
2015-05-13 20:20 - 2013-04-26 18:40 - 00359424 ____N C:\Windows\system32\CmiInstallResAll64.dll
2015-05-13 20:20 - 2013-04-26 18:40 - 00200704 ____N (C-Media) C:\Windows\SysWOW64\cmpa108.dll
2015-05-13 20:20 - 2013-04-26 18:40 - 00143360 ____N C:\Windows\Vmix108.dll
2015-05-13 20:20 - 2013-04-26 18:40 - 00001499 ____N C:\Windows\cm108.ini
2015-05-13 20:19 - 2015-05-13 20:20 - 33421031 _____ C:\Users\Nikola\Downloads\Roccat_Kulo_DRV8.08_FW2.0.zip
2015-05-12 14:33 - 2015-05-12 14:33 - 00000000 ____D C:\Users\Nikola\Documents\My Games
2015-05-12 14:33 - 2015-05-12 14:33 - 00000000 ____D C:\Users\Nikola\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Farming Simulator 15 v1.1.0.0
2015-05-12 14:33 - 2015-05-12 14:33 - 00000000 ____D C:\Users\Nikola\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\1-click run
2015-05-12 14:28 - 2015-05-12 14:28 - 00000000 ____D C:\2-click run
2015-05-12 14:00 - 2015-05-12 14:18 - 00000000 ____D C:\Users\Nikola\Downloads\Farming Simulator 15 v1.1.0.0 (2-click run)
2015-05-11 13:10 - 2015-05-11 13:10 - 00000000 ____D C:\Windows\USB Vibration
2015-05-11 13:09 - 2015-05-11 13:09 - 01673480 _____ C:\Users\Nikola\Downloads\00062865_98SE_ME_2000_XP_VISTA (4).exe
2015-05-11 13:09 - 2015-05-11 13:09 - 01673480 _____ C:\Users\Nikola\Downloads\00062865_98SE_ME_2000_XP_VISTA (3).exe
2015-05-11 13:01 - 2015-05-11 13:01 - 01673480 _____ C:\Users\Nikola\Downloads\00062865_98SE_ME_2000_XP_VISTA (2).exe
2015-05-11 13:00 - 2015-05-11 13:00 - 01673480 _____ C:\Users\Nikola\Downloads\00062865_98SE_ME_2000_XP_VISTA (1).exe
2015-05-11 12:59 - 2015-05-11 12:59 - 01673480 _____ C:\Users\Nikola\Downloads\00062865_98SE_ME_2000_XP_VISTA.exe
2015-05-11 12:59 - 2015-05-11 12:59 - 00000000 ____D C:\Program Files (x86)\USB Vibration
2015-05-11 12:13 - 2015-05-11 12:13 - 00000000 ____D C:\Users\Nikola\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Live for Speed
2015-05-11 12:07 - 2015-05-11 12:10 - 235929600 ____R C:\Users\Nikola\Downloads\Live_for_Speed_0.6g_S2_unlocker_LAN_JimbusEd.iso
2015-05-11 12:06 - 2015-05-11 12:06 - 00018893 _____ C:\Users\Nikola\Downloads\[kickass.to]live.for.speed.2014.exe.torrent
2015-05-11 12:06 - 2015-05-11 12:06 - 00018893 _____ C:\Users\Nikola\Downloads\[kickass.to]live.for.speed.2014.exe (1).torrent
2015-05-10 22:22 - 2015-05-10 22:22 - 00000000 ____D C:\Users\Nikola\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\rFactor
2015-05-10 22:22 - 2015-05-10 22:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\rFactor
2015-05-10 21:05 - 2015-05-10 21:05 - 00224887 _____ C:\Users\Nikola\Downloads\[kickass.to]live.for.speed.s2.full.english.version.2010.torrent
2015-05-10 21:05 - 2015-05-10 21:05 - 00000000 ____D C:\Users\Nikola\Downloads\Live for Speed S2 full English version 2010
2015-05-10 21:04 - 2015-05-10 22:13 - 00000000 ____D C:\Users\Nikola\Downloads\rFactor [English][PCDVD][wWw.GamesTorrents.CoM]
2015-05-09 17:44 - 2015-05-09 17:45 - 00000000 ____D C:\Users\Nikola\AppData\Roaming\Apple Computer
2015-05-09 17:44 - 2015-05-09 17:44 - 00000000 ____D C:\Users\Nikola\AppData\Local\Apple Computer
2015-05-09 17:44 - 2015-05-09 17:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-05-09 17:44 - 2015-05-09 17:44 - 00000000 ____D C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-05-09 17:44 - 2015-05-09 17:44 - 00000000 ____D C:\ProgramData\Apple Computer
2015-05-09 17:44 - 2015-05-09 17:44 - 00000000 ____D C:\Program Files\iTunes
2015-05-09 17:44 - 2015-05-09 17:44 - 00000000 ____D C:\Program Files\iPod
2015-05-09 17:44 - 2015-05-09 17:44 - 00000000 ____D C:\Program Files (x86)\iTunes
2015-05-09 17:44 - 2012-10-03 16:14 - 00033240 _____ (GEAR Software Inc.) C:\Windows\system32\Drivers\GEARAspiWDM.sys
2015-05-09 17:43 - 2015-05-09 17:44 - 00000000 ____D C:\Program Files\Common Files\Apple
2015-05-09 17:43 - 2015-05-09 17:43 - 00002519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2015-05-09 17:43 - 2015-05-09 17:43 - 00000000 ____D C:\Windows\System32\Tasks\Apple
2015-05-09 17:43 - 2015-05-09 17:43 - 00000000 ____D C:\Users\Nikola\AppData\Local\Apple
2015-05-09 17:43 - 2015-05-09 17:43 - 00000000 ____D C:\ProgramData\Apple
2015-05-09 17:43 - 2015-05-09 17:43 - 00000000 ____D C:\Program Files\Bonjour
2015-05-09 17:43 - 2015-05-09 17:43 - 00000000 ____D C:\Program Files (x86)\Bonjour
2015-05-09 17:43 - 2015-05-09 17:43 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2015-05-09 17:40 - 2015-05-09 17:42 - 152362800 _____ (Apple Inc.) C:\Users\Nikola\Downloads\iTunes6464Setup.exe
2015-05-06 00:28 - 2015-05-06 00:28 - 00000000 ____D C:\ProgramData\Electronic Arts
2015-05-06 00:16 - 2015-05-06 00:16 - 00000000 ____D C:\Users\Nikola\AppData\Roaming\PowerISO
2015-05-06 00:14 - 2015-05-06 00:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerISO
2015-05-06 00:14 - 2015-05-06 00:14 - 00000000 ____D C:\Program Files\PowerISO
2015-05-06 00:14 - 2015-04-08 04:01 - 00127760 _____ (Power Software Ltd) C:\Windows\system32\Drivers\scdemu.sys
2015-05-06 00:13 - 2015-05-06 00:13 - 02814520 _____ (Power Software Ltd) C:\Users\Nikola\Downloads\PowerISO6-x64 (1).exe
2015-05-06 00:12 - 2015-05-06 00:12 - 00000000 ____D C:\Users\Nikola\AppData\Local\Disc_Soft_Ltd
2015-05-06 00:11 - 2015-05-06 00:12 - 00000000 ____D C:\Users\Nikola\AppData\Roaming\DAEMON Tools Ultra
2015-05-06 00:11 - 2015-05-06 00:11 - 00030352 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtultrascsibus.sys
2015-05-06 00:11 - 2015-05-06 00:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Ultra
2015-05-06 00:11 - 2015-05-06 00:11 - 00000000 ____D C:\Program Files (x86)\Disc Soft
2015-05-06 00:11 - 2015-05-06 00:11 - 00000000 ____D C:\Program Files (x86)\DAEMON Tools Ultra
2015-05-06 00:10 - 2015-05-06 00:11 - 00000000 ____D C:\ProgramData\DAEMON Tools Ultra
2015-05-06 00:10 - 2015-05-06 00:10 - 12177480 _____ (Disc Soft Ltd) C:\Users\Nikola\Downloads\DAEMONToolsUltra300-0310.exe
2015-05-06 00:03 - 2015-05-06 00:03 - 00030352 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtlitescsibus.sys
2015-05-06 00:03 - 2015-05-06 00:03 - 00000000 ____D C:\Users\Nikola\AppData\Roaming\DAEMON Tools Lite
2015-05-06 00:02 - 2015-05-06 00:02 - 01709792 _____ (Disc Soft Ltd.) C:\Users\Nikola\Downloads\DTLiteInstaller.exe

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-05 02:28 - 2015-04-11 08:24 - 00731450 _____ C:\Windows\WindowsUpdate.log
2015-06-05 02:28 - 2015-04-11 08:24 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-05 02:28 - 2009-07-14 06:50 - 00014880 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-06-05 02:28 - 2009-07-14 06:50 - 00014880 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-06-04 23:40 - 2015-04-11 08:24 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-04 23:34 - 2015-04-14 21:00 - 00000080 _____ C:\Users\Nikola\AppData\Local剜捯獫慴⁲慇敭屳呇⁁屖湥楴汴浥湥⹴湩潦
2015-06-04 21:56 - 2009-07-14 07:12 - 00781298 _____ C:\Windows\system32\PerfStringBackup.INI
2015-06-04 21:50 - 2015-04-11 07:51 - 00000000 ____D C:\ProgramData\NVIDIA
2015-06-04 21:50 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-06-04 21:50 - 2009-07-14 06:56 - 00077894 _____ C:\Windows\setupact.log
2015-06-04 21:32 - 2015-04-16 18:56 - 00000000 ___RD C:\Users\Nikola\Desktop\programi
2015-06-04 21:32 - 2015-04-11 11:14 - 00000000 ____D C:\Users\Nikola\AppData\Local\CrashDumps
2015-06-03 14:11 - 2015-04-11 07:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-06-03 14:11 - 2015-04-11 07:50 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2015-06-02 06:31 - 2015-04-16 18:57 - 00000000 ___RD C:\Users\Nikola\Desktop\Igrice
2015-06-01 22:59 - 2015-04-11 09:25 - 00000000 ____D C:\Users\Nikola\AppData\Roaming\Skype
2015-06-01 09:33 - 2015-04-11 08:12 - 00000000 ____D C:\Windows\SysWOW64\directx
2015-05-31 20:46 - 2015-04-11 09:30 - 01065984 _____ C:\Users\Nikola\AppData\Local\file__0.localstorage
2015-05-31 20:41 - 2015-04-11 08:20 - 00000000 ____D C:\ProgramData\Package Cache
2015-05-31 17:29 - 2010-11-21 05:47 - 00864904 _____ C:\Windows\PFRO.log
2015-05-31 17:26 - 2015-05-02 21:35 - 00000000 ____D C:\Program Files (x86)\Kingo ROOT
2015-05-31 17:26 - 2015-04-22 16:11 - 00000000 ____D C:\Users\Nikola\AppData\Roaming\JAM Software
2015-05-30 20:47 - 2015-04-11 09:23 - 00000000 ____D C:\Users\Nikola\AppData\Roaming\uTorrent
2015-05-30 10:12 - 2015-04-11 08:35 - 00033916 _____ C:\Windows\DPINST.LOG
2015-05-30 07:42 - 2015-04-11 08:24 - 00002250 _____ C:\Users\Nikola\Desktop\Google Chrome.lnk
2015-05-30 07:40 - 2009-07-14 06:50 - 04954080 _____ C:\Windows\system32\FNTCACHE.DAT
2015-05-30 07:00 - 2015-04-11 08:27 - 00060160 _____ C:\Users\Nikola\AppData\Local\GDIPFONTCACHEV1.DAT
2015-05-30 06:40 - 2010-11-21 05:24 - 02872320 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2015-05-30 06:40 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\Cursors
2015-05-30 02:26 - 2015-04-11 09:25 - 00000000 ____D C:\ProgramData\Skype
2015-05-30 02:24 - 2015-04-28 22:36 - 00000000 ____D C:\Users\Nikola\AppData\Local\Adobe
2015-05-30 02:24 - 2015-04-25 15:48 - 00000000 ____D C:\ProgramData\Adobe
2015-05-30 02:24 - 2015-04-25 15:48 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-05-30 02:24 - 2015-04-15 00:12 - 00000000 ____D C:\Users\Nikola\AppData\Roaming\Adobe
2015-05-29 22:49 - 2015-04-11 08:16 - 00396761 _____ C:\Windows\DirectX.log
2015-05-28 18:46 - 2015-04-11 07:54 - 00000000 ____D C:\Users\Nikola\AppData\Local\NVIDIA Corporation
2015-05-28 09:04 - 2015-04-14 13:50 - 15864064 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2015-05-28 09:04 - 2015-04-14 13:50 - 02986392 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2015-05-28 09:04 - 2015-04-11 07:50 - 17486856 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2015-05-28 09:04 - 2015-04-11 07:50 - 12852152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2015-05-28 09:04 - 2015-04-11 07:50 - 03379680 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2015-05-28 09:04 - 2015-04-11 07:50 - 00030966 _____ C:\Windows\system32\nvinfo.pb
2015-05-28 06:15 - 2015-04-11 07:51 - 06872904 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2015-05-28 06:15 - 2015-04-11 07:51 - 03491984 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2015-05-28 06:15 - 2015-04-11 07:51 - 02558608 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2015-05-28 06:15 - 2015-04-11 07:51 - 00937288 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2015-05-28 06:15 - 2015-04-11 07:51 - 00385168 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2015-05-28 06:15 - 2015-04-11 07:51 - 00062608 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2015-05-27 12:48 - 2015-04-11 07:51 - 04408727 _____ C:\Windows\system32\nvcoproc.bin
2015-05-26 14:52 - 2009-07-14 07:08 - 00032636 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-05-24 19:37 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2015-05-23 03:47 - 2015-04-11 07:51 - 01756424 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2015-05-23 03:47 - 2015-04-11 07:51 - 01571696 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2015-05-23 03:47 - 2015-04-11 07:51 - 01320304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2015-05-23 03:47 - 2015-04-11 07:51 - 01316000 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2015-05-21 09:07 - 2010-11-21 08:55 - 00000000 ____D C:\Windows\ShellNew
2015-05-18 23:23 - 2015-04-11 07:48 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2015-05-16 23:35 - 2015-04-11 08:24 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-05-16 23:35 - 2015-04-11 08:24 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-05-13 20:32 - 2015-04-11 08:32 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-05-13 20:32 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system
2015-05-13 20:23 - 2015-04-11 08:22 - 00000000 ____D C:\Users\Nikola\AppData\Local\VirtualStore
2015-05-13 08:52 - 2015-04-11 07:50 - 01558848 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
2015-05-08 10:48 - 2015-04-11 18:45 - 384740308 _____ C:\Windows\MEMORY.DMP
2015-05-08 10:48 - 2015-04-11 18:45 - 00000000 ____D C:\Windows\Minidump
2015-05-06 00:27 - 2009-07-14 07:38 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-05-06 00:03 - 2015-05-03 22:02 - 00000000 ____D C:\ProgramData\DAEMON Tools Lite

==================== Files in the root of some directories =======

2015-05-30 08:29 - 2015-05-30 08:29 - 0000627 _____ () C:\Users\Nikola\AppData\Roaming\All CPU MeterV3_Settings.ini
2015-05-28 17:46 - 2015-05-28 17:46 - 0003584 _____ () C:\Users\Nikola\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-05-24 22:24 - 2015-05-24 22:24 - 0000058 _____ () C:\Users\Nikola\AppData\Local\DonationCoder_ScreenshotCaptor_InstallInfo.dat
2015-04-11 09:30 - 2015-05-31 20:46 - 1065984 _____ () C:\Users\Nikola\AppData\Local\file__0.localstorage
2015-04-12 13:57 - 2015-04-28 22:42 - 0007636 _____ () C:\Users\Nikola\AppData\Local\Resmon.ResmonCfg
2015-04-11 08:33 - 2015-04-11 08:33 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Some files in TEMP:
====================
C:\Users\Nikola\AppData\Local\Temp\AcDeltree.exe
C:\Users\Nikola\AppData\Local\Temp\ICReinstall_downloader_for_Alcohol120_trial_2.0.3.7612.exe
C:\Users\Nikola\AppData\Local\Temp\MSETUP4.EXE
C:\Users\Nikola\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Nikola\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\Nikola\AppData\Local\Temp\nvStInst.exe
C:\Users\Nikola\AppData\Local\Temp\sfamcc00001.dll
C:\Users\Nikola\AppData\Local\Temp\sfextra.dll
C:\Users\Nikola\AppData\Local\Temp\uninstall.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe
[2010-11-21 05:24] - [2015-05-30 06:40] - 2872320 ____A (Microsoft Corporation) ECC9072346F96A25B27D12B62164DF3C

C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-06-03 17:51

==================== End of log ============================

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Zdravo,

1. Otvori Notepad (Text Document) i iskopiraj sledeći tekst unutar kod polja ispod:


CreateRestorePoint:
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-1269221854-1059928380-260943180-1000\...\Run: [vibranceGUI] => "C:\Users\Nikola\AppData\Local\Temp\Rar$EXa0.973\vibrance.GUI.exe" -minimized <===== ATTENTION
HKU\S-1-5-21-1269221854-1059928380-260943180-1000\...\MountPoints2: G - G:\OriginInstaller.exe
HKU\S-1-5-21-1269221854-1059928380-260943180-1000\...\MountPoints2: H - H:\Setup.exe autorun
HKU\S-1-5-21-1269221854-1059928380-260943180-1000\...\MountPoints2: {8056259a-e012-11e4-9fa9-806e6f6e6963} - E:\.\Bin\ASSETUP.exe
HKU\S-1-5-21-1269221854-1059928380-260943180-1000\...\Winlogon: [Shell] C:\Windows\expstart.exe [925184 2015-05-30] () <==== ATTENTION
BHO: No Name -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> No File
BHO-x32: No Name -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> No File
Toolbar: HKU\S-1-5-21-1269221854-1059928380-260943180-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKU\S-1-5-21-1269221854-1059928380-260943180-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
S3 GPUZ; \??\C:\Windows\TEMP\GPUZ.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
U3 ag5xzn86; C:\Windows\System32\Drivers\ag5xzn86.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero byte File/Folder)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
C:\Windows\System32\Drivers\ag5xzn86.sys
EmptyTemp:


2. Sačuvaj notepad na Desktop pod nazivom fixlist.txt
To možes uraditi i iz notepad-a => klik na File potom na Save As i u novom prozoru, dole pod File Name: staviš za naziv fixlist.txt
Napomena: Važno je da se oba fajla, FRST i fixlist nalaze na istoj lokaciji jer u suprotnom fix nece raditi.

3. Ponovo pokreni FRST/FRST64, klikni jednom na dugme Fix i sačekaj.
Ukoliko alat zatraži restart sistema, dozvoli mu i postaraj se da alat kompletira fix nakon restarta sistema.



Alat će formirati log (Fixlog.txt) na Desktop-u. Potrebno je sadržaj tog loga iskopirati u poruku.
Napomena: Ukoliko te alat upozori da postoji novija verzija, postaraj se da preuzmes i koristiš ažuriranu kopiju FRST-a.

offline
  • Pridružio: 04 Jun 2015
  • Poruke: 9

Evo
mycity.rs/must-login.png

Fix result of Farbar Recovery Scan Tool (x64) Version:03-06-2015
Ran by Nikola at 2015-06-05 18:12:03 Run:1
Running from C:\Users\Nikola\Desktop
Loaded Profiles: Nikola (Available Profiles: Nikola)
Boot Mode: Normal
==============================================

fixlist content:
*****************
CreateRestorePoint:
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-1269221854-1059928380-260943180-1000\...\Run: [vibranceGUI] => "C:\Users\Nikola\AppData\Local\Temp\Rar$EXa0.973\vibrance.GUI.exe" -minimized <===== ATTENTION
HKU\S-1-5-21-1269221854-1059928380-260943180-1000\...\MountPoints2: G - G:\OriginInstaller.exe
HKU\S-1-5-21-1269221854-1059928380-260943180-1000\...\MountPoints2: H - H:\Setup.exe autorun
HKU\S-1-5-21-1269221854-1059928380-260943180-1000\...\MountPoints2: {8056259a-e012-11e4-9fa9-806e6f6e6963} - E:\.\Bin\ASSETUP.exe
HKU\S-1-5-21-1269221854-1059928380-260943180-1000\...\Winlogon: [Shell] C:\Windows\expstart.exe [925184 2015-05-30] () <==== ATTENTION
BHO: No Name -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> No File
BHO-x32: No Name -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> No File
Toolbar: HKU\S-1-5-21-1269221854-1059928380-260943180-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKU\S-1-5-21-1269221854-1059928380-260943180-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
S3 GPUZ; \??\C:\Windows\TEMP\GPUZ.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
U3 ag5xzn86; C:\Windows\System32\Drivers\ag5xzn86.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero byte File/Folder)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
C:\Windows\System32\Drivers\ag5xzn86.sys
EmptyTemp:
*****************

Restore point was successfully created.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
HKU\S-1-5-21-1269221854-1059928380-260943180-1000\Software\Microsoft\Windows\CurrentVersion\Run\\vibranceGUI => value removed successfully
"HKU\S-1-5-21-1269221854-1059928380-260943180-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G" => key removed successfully
"HKU\S-1-5-21-1269221854-1059928380-260943180-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\H" => key removed successfully
"HKU\S-1-5-21-1269221854-1059928380-260943180-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8056259a-e012-11e4-9fa9-806e6f6e6963}" => key removed successfully
HKCR\CLSID\{8056259a-e012-11e4-9fa9-806e6f6e6963} => key not found.
HKU\S-1-5-21-1269221854-1059928380-260943180-1000\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => value removed successfully
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}" => key removed successfully
HKCR\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} => key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}" => key removed successfully
HKCR\Wow6432Node\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} => key not found.
HKU\S-1-5-21-1269221854-1059928380-260943180-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => value removed successfully
"HKCR\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}" => key removed successfully
HKU\S-1-5-21-1269221854-1059928380-260943180-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value removed successfully
HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => key not found.
GPUZ => Service removed successfully
VGPU => Service removed successfully
ag5xzn86 => Service not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => key removed successfully
HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found.
"C:\Windows\System32\Drivers\ag5xzn86.sys" => File/Folder not found.
EmptyTemp: => 16.4 GB temporary data Removed.


The system needed a reboot..

==== End of Fixlog 18:12:55 ====

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Idi na www.virustotal.com i skeniraj sledeci fajl: C:\Windows\explorer.exe.

Ukoliko dobijes obavestenje da je fajl vec skeniran ranije, ti klikni na ponovno skeniranje, pa mi okaci Log ovde.

offline
  • Pridružio: 04 Jun 2015
  • Poruke: 9

virustotal.com/en/file/63a18d0969d8449.....433523619/

nije nasao nista

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Preuzmi "Xplode"-ov AdwCleaner () i sacuvaj ga na Desktop

Dvoklikom pokreni program.
Klikni na dugme [Scan] i pricekaj da program zavrsi.
Klikni na dugme [Clean]
Program ce zatvoriti sve aktivne programe i izbaciti prozor sa tim upozorenjem. Klikni Ok kao potvrdu.
Na sledeca dva prozora koja se otvore (Informations i Restart required ) klikni Ok


Racunar ce se restartovati a potom otvoriti notepad (C:\AdwCleaner[S1].txt) sa izvestajem.
Sacuvaj taj notepad na Desktop i okaci ga uz poruku koristeci opciju "Prikaci fajl"

Napomena: Izvestaj ce takodje biti sacuvan na C:\AdwCleaner[S0].txt

offline
  • Pridružio: 04 Jun 2015
  • Poruke: 9

mycity.rs/must-login.png

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Preuzmi smeenk-ov zoek.zip ili zoek.rar () sa ovog ili ovog linka i sačuvaj ga na Desktop.

Raspakuj arhivu u neki folder (uputstvo), a zatim:

zatvori browser i ostale pokrenute programe;
privremeno deaktiviraj zaštitni softver ( ukoliko je to potrebno ) Uputstvo ;
dvoklikom pokreni zoek na ikonicu programa ;
pričekaj da se alat startuje ...


U beli okvir prozora iskopiraj sledeći tekst:

 
autoclean;
emptyclsid;
emptyfolderscheck;delete
emptyalltemp;


Klikni na dugme i pričekaj da se skeniranje završi.


zoek ce po potrebi, restartovati Windows a na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.

Napomena:Izveštaj će biti sačuvan pod nazivom zoek-results.log na sistemskoj particiji (tipična lokacija: C:\zoek-results.log)


Arrow Kopiraj sadrzaj tog loga u poruku.

offline
  • Pridružio: 04 Jun 2015
  • Poruke: 9

mycity.rs/must-login.png

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Kakvo je sad stanje?

Ko je trenutno na forumu
 

Ukupno su 1123 korisnika na forumu :: 49 registrovanih, 7 sakrivenih i 1067 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 5.56, A.R.Chafee.Jr., aleksmajstor, Apok, bojanM84, ccoogg123, Centauro, Dannyboy, debeli, Dimitrise93, Djokislav, Dorcolac, dushan, FOX, Georgius, hooraay, Karla, Kubovac, Lucije Kvint, maiden6657, Marko Marković, mercedesamg, MiG-29M2, milanovic, Milos ZA, mnn2, mocnijogurt, operniki, pacika, prle122, raptorsi, royst33, saputnik plavetnila, sasa87, sevenino, Singidunumac, Sirius, sokars, SR-3m, Srle993, stalja, Stoilkovic, Sumadija34, vathra, vladulns, x9, yufighter, Zimbabwe, šumar bk2