Provera

Provera

offline
  • Pridružio: 14 Feb 2008
  • Poruke: 12391

Poz ljudi.

Možete li molim vas da mi proverite OS ?
Na jednom servisu stalno cure moje informacije čak i nakon izmene login informacija pa želim da budem siguran da nije do mene.

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-11-2014
Ran by Srdjan (administrator) on SRKI94 on 12-11-2014 19:51:32
Running from C:\Users\Srdjan\Desktop
Loaded Profile: Srdjan (Available profiles: Srdjan)
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-t.....scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
() C:\Windows\SysWOW64\ASGT.exe
(Microsoft Corporation) C:\Windows\System32\CISVC.EXE
() C:\Windows\SysWOW64\PnkBstrA.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(ASUS) C:\Program Files (x86)\ASUS\GPU Tweak\GPUTweak.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
() C:\ProgramData\Avg_Update_1114av\AVG-Secure-Search-Update_1114av.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Flux Software LLC) C:\Users\Srdjan\AppData\Local\FluxSoftware\Flux\flux.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Skillbrains) C:\Users\Srdjan\AppData\Local\Skillbrains\lightshot\5.1.4.17\Lightshot.exe
(ASUS) C:\Program Files (x86)\ASUS\GPU Tweak\Monitor.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
() C:\Windows\System32\Srpskey.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgui.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13213840 2012-10-26] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [Fences] => "C:\Program Files (x86)\Stardock\Fences\Fences.exe" /startup
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2015\avgui.exe [3649040 2014-10-16] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-09-15] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [srpskey] => C:\WINDOWS\SYSTEM32\SRPSKEY.EXE
Winlogon\Notify\WB: C:\Program Files (x86)\Stardock\WindowBlinds\fast64.dll [X]
HKU\S-1-5-21-3012697505-3807635779-1283347855-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-3012697505-3807635779-1283347855-1000\...\Run: [f.lux] => C:\Users\Srdjan\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-23] (Flux Software LLC)
HKU\S-1-5-21-3012697505-3807635779-1283347855-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [6501656 2014-10-23] (Piriform Ltd)
HKU\S-1-5-21-3012697505-3807635779-1283347855-1000\...\Run: [LightShot] => C:\Users\Srdjan\AppData\Local\Skillbrains\lightshot\Lightshot.exe [226560 2014-06-18] ()
HKU\S-1-5-21-3012697505-3807635779-1283347855-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [30524000 2014-10-23] (Skype Technologies S.A.)
HKU\S-1-5-21-3012697505-3807635779-1283347855-1000\...\Winlogon: [Shell] C:\Windows\expstart.exe [925184 2014-10-05] () <==== ATTENTION
HKU\S-1-5-18\...\RunOnce: [Application Restart #0] => C:\Program Files (x86)\ASUS\GPU Tweak\Monitor.exe [2690560 2013-07-02] (ASUS)
ShellIconOverlayIdentifiers: [ MailRuCloudIconOverlay0] -> {64A9418A-B6B1-4112-B75C-E61633C9A31F} => C:\Users\Srdjan\AppData\Local\Temp\mcse64_00.dll ()
ShellIconOverlayIdentifiers: [ MailRuCloudIconOverlay1] -> {6A2E142B-EA63-433A-AC05-5223CBD26E65} => C:\Users\Srdjan\AppData\Local\Temp\mcse64_00.dll ()
ShellIconOverlayIdentifiers: [ MailRuCloudIconOverlay2] -> {6AFCC535-2F12-4F50-9F0A-1CF856CFC95D} => C:\Users\Srdjan\AppData\Local\Temp\mcse64_00.dll ()
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
ShellIconOverlayIdentifiers-x32: [ MailRuCloudIconOverlay0] -> {64A9418A-B6B1-4112-B75C-E61633C9A31F} => C:\Users\Srdjan\AppData\Local\Temp\mcse32_00.dll ()
ShellIconOverlayIdentifiers-x32: [ MailRuCloudIconOverlay1] -> {6A2E142B-EA63-433A-AC05-5223CBD26E65} => C:\Users\Srdjan\AppData\Local\Temp\mcse32_00.dll ()
ShellIconOverlayIdentifiers-x32: [ MailRuCloudIconOverlay2] -> {6AFCC535-2F12-4F50-9F0A-1CF856CFC95D} => C:\Users\Srdjan\AppData\Local\Temp\mcse32_00.dll ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: 127.0.0.1 activation.cloud.techsmith.com
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\Srdjan\AppData\Roaming\Mozilla\Firefox\Profiles\sk3rsdnk.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_223.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_223.dll ()
FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll No File
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-3012697505-3807635779-1283347855-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Srdjan\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-3012697505-3807635779-1283347855-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll No File
FF Extension: DownloadHelper - C:\Users\Srdjan\AppData\Roaming\Mozilla\Firefox\Profiles\sk3rsdnk.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-10-06]

Chrome:
=======
CHR HomePage: Default ->
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\Srdjan\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Srdjan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-11-05]
CHR Extension: (Text URL Linker) - C:\Users\Srdjan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aegfbpchoheaflicfmggkmlmcccpjpgd [2014-11-05]
CHR Extension: (Google Docs) - C:\Users\Srdjan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-11-05]
CHR Extension: (Google Drive) - C:\Users\Srdjan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-11-05]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Srdjan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-08-28]
CHR Extension: (YouTube) - C:\Users\Srdjan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-11-05]
CHR Extension: (Nimbus Screenshot) - C:\Users\Srdjan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpconcjcammlapcogcnnelfmaeghhagj [2014-11-05]
CHR Extension: (Easy SteamGifts) - C:\Users\Srdjan\AppData\Local\Google\Chrome\User Data\Default\Extensions\cklbilaeedbblhpkhjfcnmaocjdodcnm [2014-11-08]
CHR Extension: (Google Search) - C:\Users\Srdjan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-11-05]
CHR Extension: (Page load time) - C:\Users\Srdjan\AppData\Local\Google\Chrome\User Data\Default\Extensions\fploionmjgeclbkemipmkogoaohcdbig [2014-11-10]
CHR Extension: (AdBlock) - C:\Users\Srdjan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-11-05]
CHR Extension: (Hola Better Internet) - C:\Users\Srdjan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2014-11-05]
CHR Extension: (Lone Tree) - C:\Users\Srdjan\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfmkllfplegemejikoabfpjdaoncphip [2014-11-05]
CHR Extension: (goo.gl URL Shortener) - C:\Users\Srdjan\AppData\Local\Google\Chrome\User Data\Default\Extensions\iblijlcdoidgdpfknkckljiocdbnlagk [2014-11-05]
CHR Extension: (Deathamns) - C:\Users\Srdjan\AppData\Local\Google\Chrome\User Data\Default\Extensions\immpkjjlgappgfkkfieppnmlhakdmaab [2014-11-05]
CHR Extension: (FVD Downloader) - C:\Users\Srdjan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfmhcpmkbdkbgbmkjoiopeeegenkdikp [2014-11-05]
CHR Extension: (AVG Secure Search) - C:\Users\Srdjan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof [2014-11-05]
CHR Extension: (Google Wallet) - C:\Users\Srdjan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-17]
CHR Extension: (Gmail) - C:\Users\Srdjan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-11-05]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-09-15] (Advanced Micro Devices, Inc.) [File not signed]
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
R2 ASGT; C:\Windows\SysWOW64\ASGT.exe [55296 2012-01-17] () [File not signed]
S2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3487248 2014-10-16] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [298080 2014-10-16] (AVG Technologies CZ, s.r.o.)
S3 BRSptSvc; C:\ProgramData\BitRaider\BRSptSvc.exe [477960 2014-05-03] (BitRaider, LLC)
S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [520416 2014-01-28] (Futuremark)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1900400 2014-11-08] (Electronic Arts)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-08-09] ()
R2 RzKLService; C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe [105448 2014-08-28] (Razer Inc.)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S3 VsEtwService120; C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [89232 2014-07-22] (Microsoft Corporation)
S2 WindowFX; C:\Program Files (x86)\Stardock\WindowFX\WindowFXSrv.exe [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
S2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [22680 2012-10-25] ()
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [153368 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [262424 2014-10-07] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [190744 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [243480 2014-08-28] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [313624 2014-07-18] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [124184 2014-10-05] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [274200 2014-10-10] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [50976 2014-08-11] (AVG Technologies)
S3 b06diag; C:\Windows\system32\drivers\bxdiaga.sys [88104 2012-03-08] (Broadcom Corporation)
S3 BFN7x64; C:\Windows\system32\drivers\Xeno7x64.sys [157288 2012-02-22] (Bigfoot Networks, Inc.)
S3 BRDriver64; C:\ProgramData\BitRaider\BRDriver64.sys [75048 2014-05-03] (BitRaider)
S3 bxfcoe; C:\Windows\system32\drivers\bxfcoe.sys [178216 2012-02-22] (Broadcom Corporation)
S3 bxois; C:\Windows\system32\drivers\bxois.sys [539176 2012-02-22] (Broadcom Corporation)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-12-17] (Disc Soft Ltd)
S3 EtronSTOR; C:\Windows\System32\Drivers\EtronSTOR.sys [32512 2012-07-24] (Etron Technology Inc)
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO64A.SYS [27552 2014-10-21] (REALiX(tm))
R3 IOMap; C:\Windows\system32\drivers\IOMap64.sys [24824 2013-02-19] (ASUSTeK Computer Inc.)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2014-11-05] (Malwarebytes Corporation)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] ()
S3 usbrndis6; C:\Windows\System32\DRIVERS\usb80236.sys [19968 2013-08-16] (Microsoft Corporation)
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 gdrv; \??\C:\Windows\gdrv.sys [X]
S3 GPUZ; \??\C:\Users\Srdjan\AppData\Local\Temp\GPUZ.sys [X]
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-11-12 19:36 - 2014-11-12 19:51 - 00020083 _____ () C:\Users\Srdjan\Desktop\FRST.txt
2014-11-12 19:35 - 2014-11-12 19:36 - 02116096 _____ (Farbar) C:\Users\Srdjan\Desktop\FRST64.exe
2014-11-12 13:49 - 2014-11-12 13:49 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 8
2014-11-12 05:16 - 2014-11-12 05:16 - 00003324 _____ () C:\Windows\System32\Tasks\GTFO
2014-11-12 05:16 - 2014-11-12 05:16 - 00003324 _____ () C:\Users\Srdjan\Desktop\GTFO.xml
2014-11-12 02:54 - 2014-11-12 02:54 - 17926832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-11-12 02:35 - 2014-11-12 02:35 - 00001011 _____ () C:\Users\Srdjan\Desktop\Far Cry 3 Blood Dragon.lnk
2014-11-12 02:35 - 2014-11-12 02:35 - 00000000 ____D () C:\Users\Srdjan\AppData\Roaming\Far Cry 3 Blood Dragon
2014-11-11 13:01 - 2014-11-11 13:01 - 00003952 _____ () C:\Windows\windefendam.log
2014-11-11 13:01 - 2014-11-11 13:01 - 00000020 _____ () C:\Windows\capsys184523.log
2014-11-11 13:01 - 2014-11-11 13:01 - 00000000 ____D () C:\Users\Srdjan\Documents\Action!
2014-11-11 12:54 - 2014-11-11 12:54 - 20547896 _____ (Mirillis Ltd.) C:\Users\Srdjan\Downloads\action_1_19_2_setup.exe
2014-11-11 12:36 - 2013-02-19 18:02 - 00024824 _____ (ASUSTeK Computer Inc.) C:\Windows\system32\Drivers\IOMap64.sys
2014-11-11 03:55 - 2014-11-11 18:55 - 00000000 ____D () C:\Users\Srdjan\Desktop\Igrice
2014-11-11 00:25 - 2014-11-11 00:25 - 02158790 _____ () C:\Users\Srdjan\Downloads\[Megafileupload]SAMP MOD.txt
2014-11-11 00:09 - 2014-11-11 00:09 - 00071576 _____ () C:\Users\Srdjan\Downloads\raptr_installer.exe
2014-11-10 23:37 - 2014-11-10 23:37 - 00000000 ____D () C:\ProgramData\GRETECH
2014-11-10 23:36 - 2014-11-10 23:36 - 00001213 _____ () C:\Users\Srdjan\AppData\Roaming\Microsoft\Windows\Start Menu\GOM Player.lnk
2014-11-10 23:36 - 2014-11-10 23:36 - 00001189 _____ () C:\Users\Public\Desktop\GOM Player.lnk
2014-11-10 23:36 - 2014-11-10 23:36 - 00000000 ____D () C:\Users\Srdjan\AppData\Roaming\GRETECH
2014-11-10 23:36 - 2014-11-10 23:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOM Player
2014-11-10 23:33 - 2014-11-10 23:33 - 13189528 _____ (Gretech Corporation) C:\Users\Srdjan\Downloads\GOMPLAYERENSETUP.EXE
2014-11-10 23:26 - 2014-11-12 02:01 - 00000868 _____ () C:\Users\Srdjan\Desktop\Handbrake.lnk
2014-11-10 23:26 - 2014-11-10 23:26 - 14298467 _____ () C:\Users\Srdjan\Downloads\HandBrake-0.9.9-1_x86_64-Win_GUI.exe
2014-11-10 23:26 - 2014-11-10 23:26 - 00000000 ____D () C:\Users\Srdjan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Handbrake
2014-11-10 23:26 - 2014-11-10 23:26 - 00000000 ____D () C:\Program Files\Handbrake
2014-11-10 18:11 - 2014-11-12 12:00 - 00000520 _____ () C:\Windows\Tasks\AVG_SYS_TASK_1114av.job
2014-11-10 18:11 - 2014-11-12 12:00 - 00000388 _____ () C:\Windows\Tasks\AVG_SYS_TASK_1114av_DELETE.job
2014-11-10 18:11 - 2014-11-10 18:11 - 00002890 _____ () C:\Windows\System32\Tasks\AVG_SYS_TASK_1114av_DELETE
2014-11-10 18:11 - 2014-11-10 18:11 - 00002814 _____ () C:\Windows\System32\Tasks\AVG_SYS_TASK_1114av
2014-11-10 18:11 - 2014-11-10 18:11 - 00000000 ____D () C:\ProgramData\Avg_Update_1114av
2014-11-10 04:03 - 2014-11-10 04:03 - 00000000 ____D () C:\Users\Srdjan\Downloads\blender-2.72b-windows64
2014-11-10 04:02 - 2014-11-10 04:03 - 90410554 _____ () C:\Users\Srdjan\Downloads\blender-2.72b-windows64.zip
2014-11-09 23:22 - 2014-11-09 23:22 - 00000000 ____D () C:\Users\Srdjan\AppData\Local\Microsoft Games
2014-11-09 19:28 - 2014-11-09 19:44 - 891457474 _____ (SpaceEngine ) C:\Users\Srdjan\Downloads\SE-0971-setup.exe
2014-11-09 03:51 - 2014-11-09 03:51 - 00003314 _____ () C:\Windows\System32\Tasks\ss
2014-11-09 01:54 - 2014-11-11 01:09 - 00000000 ____D () C:\Users\Srdjan\AppData\Roaming\Bioshock
2014-11-09 01:54 - 2014-11-09 02:01 - 00000000 ____D () C:\Users\Srdjan\Documents\Bioshock
2014-11-09 01:50 - 2014-11-09 01:55 - 325164224 _____ () C:\Users\Srdjan\Downloads\Into The War.rar
2014-11-08 15:44 - 2014-11-08 15:55 - 00000000 ____D () C:\Users\Srdjan\AppData\Local\Culling_Of_The_Cows
2014-11-08 03:44 - 2014-11-08 03:44 - 00000782 _____ () C:\Users\Public\Desktop\SpaceShuttleMissionDemo.lnk
2014-11-08 03:44 - 2014-11-08 03:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpaceShuttleMissionDemo
2014-11-08 03:42 - 2014-11-08 03:44 - 127042732 _____ (Exciting Simulations ) C:\Users\Srdjan\Downloads\SSM2007-DEMO-Setup.exe
2014-11-08 02:38 - 2014-11-08 02:39 - 00000000 ____D () C:\Users\Srdjan\AppData\Local\Urban Trial Freestyle
2014-11-07 03:26 - 2014-11-07 03:26 - 00000000 ____D () C:\Users\Srdjan\AppData\Roaming\Milestone
2014-11-07 02:51 - 2014-11-07 02:51 - 00262144 ____N () C:\Windows\Minidump\110714-47408-01.dmp
2014-11-07 00:50 - 2014-11-07 00:51 - 00000000 ____D () C:\Users\Srdjan\Documents\Real World Racing
2014-11-06 17:54 - 2014-11-12 04:27 - 00205914 _____ () C:\Windows\DirectX.log
2014-11-06 17:16 - 2014-11-06 17:16 - 20739815 _____ () C:\Users\Srdjan\Downloads\Boximals_Win_1413334558.zip
2014-11-06 02:08 - 2014-11-06 02:08 - 00000000 ____D () C:\Users\Srdjan\AppData\Local\Skillbrains
2014-11-06 02:07 - 2014-11-06 02:07 - 02422800 _____ (Skillbrains ) C:\Users\Srdjan\Downloads\setup-lightshot.exe
2014-11-05 23:13 - 2014-11-05 23:13 - 00000000 _____ () C:\Users\Srdjan\AppData\Roaming\Stardockfences_debug_snapshot.dat
2014-11-05 23:12 - 2014-11-05 23:13 - 52407432 _____ () C:\Users\Srdjan\Downloads\WindowBlinds8-cnet-setup.exe
2014-11-05 23:07 - 2014-11-05 23:07 - 00001536 _____ () C:\Users\Srdjan\Desktop\VS Express 2013 for Desktop.lnk
2014-11-05 23:06 - 2014-11-05 23:13 - 00000000 ____D () C:\Users\Srdjan\Downloads\Stardock
2014-11-04 02:32 - 2014-11-04 02:32 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 11.0
2014-11-04 02:20 - 2014-11-04 02:20 - 00000000 ____D () C:\ProgramData\NuGet
2014-11-04 02:20 - 2014-11-04 02:20 - 00000000 ____D () C:\Program Files (x86)\NuGet
2014-11-04 02:12 - 2014-11-04 02:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits
2014-11-04 02:04 - 2014-11-04 02:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio 2013
2014-11-04 01:22 - 2014-11-04 01:22 - 00013029 _____ () C:\Users\Srdjan\Desktop\Add or remove programs - Shortcut.lnk
2014-11-03 17:12 - 2014-11-03 17:12 - 00000000 ____D () C:\Users\Srdjan\AppData\Roaming\Ice-Pick Lodge
2014-11-03 16:10 - 2014-11-03 16:10 - 00000702 _____ () C:\Users\Srdjan\Desktop\Knock-Knock.lnk
2014-11-03 16:10 - 2014-11-03 16:10 - 00000000 ____D () C:\Users\Srdjan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Knock-Knock 1.0
2014-11-03 03:11 - 2014-11-04 02:32 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 12.0
2014-11-03 02:38 - 2014-11-03 02:38 - 01158344 _____ (Microsoft Corporation) C:\Users\Srdjan\Downloads\wdexpress_full.exe
2014-11-03 00:00 - 2014-11-03 00:00 - 00000000 ____D () C:\Users\Srdjan\AppData\Local\node-webkit
2014-11-02 23:35 - 2014-11-03 00:00 - 00000000 ____D () C:\Users\Srdjan\AppData\Local\Popcorn4TV
2014-11-02 23:33 - 2014-11-03 00:00 - 00000000 ____D () C:\Program Files (x86)\Popcorn4TV
2014-11-02 22:09 - 2014-11-02 22:09 - 00001490 _____ () C:\Users\Srdjan\Desktop\Space Sniffer.lnk
2014-11-01 16:01 - 2014-11-01 16:01 - 00000000 ____D () C:\ProgramData\CODEX
2014-11-01 16:00 - 2014-11-01 16:00 - 00001132 _____ () C:\Users\Srdjan\Desktop\BrokenAge.exe - Shortcut.lnk
2014-10-31 02:22 - 2014-10-31 02:22 - 00000000 ____D () C:\Users\Srdjan\AppData\Roaming\Oracle
2014-10-31 02:21 - 2014-10-31 02:21 - 00003158 _____ () C:\Windows\System32\Tasks\{F1EB3409-4674-4592-95D7-36A54FEBBC03}
2014-10-30 04:06 - 2014-10-30 04:06 - 00003244 _____ () C:\Windows\System32\Tasks\f
2014-10-29 13:39 - 2014-10-29 13:39 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-10-28 19:20 - 2014-10-28 19:20 - 00000000 ____D () C:\Users\Srdjan\AppData\Roaming\Convivea
2014-10-28 19:20 - 2014-10-28 19:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bit Che
2014-10-28 19:20 - 2014-10-28 19:20 - 00000000 ____D () C:\Program Files (x86)\Bit Che
2014-10-28 01:08 - 2014-10-28 01:08 - 00000000 ____D () C:\Users\Srdjan\Documents\Lucius
2014-10-27 19:07 - 2014-11-07 20:00 - 00000000 ____D () C:\Users\Srdjan\AppData\Local\UrielsChasm
2014-10-27 04:42 - 2014-10-27 04:42 - 00003362 _____ () C:\Windows\System32\Tasks\PC Shutdown
2014-10-26 15:49 - 2014-11-12 11:59 - 00030726 _____ () C:\Windows\PFRO.log
2014-10-26 15:49 - 2014-11-12 11:59 - 00001624 _____ () C:\Windows\setupact.log
2014-10-26 15:49 - 2014-10-26 15:49 - 00000000 _____ () C:\Windows\setuperr.log
2014-10-26 00:55 - 2014-10-26 00:55 - 00000000 __SHD () C:\found.000
2014-10-25 13:15 - 2014-11-08 22:27 - 00000000 ____D () C:\Program Files\MyDefrag v4.3.1
2014-10-25 13:15 - 2014-10-30 19:51 - 00000907 _____ () C:\Users\Public\Desktop\MyDefrag.lnk
2014-10-25 13:15 - 2014-10-25 13:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyDefrag v4.3.1
2014-10-25 02:56 - 2014-10-30 19:51 - 00000866 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-10-25 02:56 - 2014-10-25 02:56 - 00002774 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-10-25 02:56 - 2014-10-25 02:56 - 00000000 ____D () C:\Program Files\CCleaner
2014-10-24 03:28 - 2014-10-24 03:30 - 00000000 ____D () C:\Users\Srdjan\Documents\Arma 3
2014-10-24 03:28 - 2014-10-24 03:28 - 00000000 ____D () C:\Users\Srdjan\AppData\Local\Arma 3
2014-10-24 03:28 - 2014-10-24 03:28 - 00000000 ____D () C:\ProgramData\Bohemia Interactive
2014-10-24 03:27 - 2014-10-24 03:28 - 00000000 ____D () C:\Users\Srdjan\AppData\Local\Arma 3 Launcher
2014-10-24 03:27 - 2014-10-24 03:27 - 00000000 ____D () C:\Users\Srdjan\AppData\Local\Bohemia_Interactive
2014-10-23 21:40 - 2014-10-23 21:40 - 00004386 _____ () C:\Users\Srdjan\Downloads\LSystem.cs
2014-10-22 00:18 - 2014-10-24 12:54 - 00000000 ____D () C:\Users\Srdjan\AppData\Local\My Games
2014-10-21 22:18 - 2014-10-21 22:18 - 00000000 ____D () C:\Users\Srdjan\AppData\Local\Miloš_Ranđelović
2014-10-21 22:17 - 2014-10-21 22:17 - 00000000 ____D () C:\Users\Srdjan\AppData\Roaming\X3mE Yamb
2014-10-21 22:17 - 2014-10-21 22:17 - 00000000 ____D () C:\ProgramData\X3mE Yamb
2014-10-21 22:17 - 2014-10-21 22:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\X3mE Yamb
2014-10-21 20:36 - 2014-10-21 20:36 - 00027552 _____ (REALiX(tm)) C:\Windows\system32\Drivers\HWiNFO64A.SYS
2014-10-21 20:35 - 2014-11-10 20:05 - 00000000 ____D () C:\Program Files\HWiNFO64
2014-10-21 20:35 - 2014-10-21 20:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HWiNFO64
2014-10-21 13:58 - 2014-10-21 13:58 - 00000000 ____D () C:\Users\Srdjan\Documents\Anomaly Warzone Earth
2014-10-21 00:44 - 2014-10-21 00:44 - 00000000 ____D () C:\Users\Srdjan\Documents\Graphics
2014-10-20 23:01 - 2014-10-20 23:01 - 01170296 _____ () C:\Users\Srdjan\Downloads\Bullet.blend
2014-10-20 19:20 - 2014-10-20 19:20 - 00000000 ____D () C:\Users\Srdjan\Downloads\c0r2sr9x1h-Pistol
2014-10-19 16:23 - 2014-10-19 16:23 - 01329370 _____ () C:\Users\Srdjan\Downloads\Access_-_Osnove_upravljanja_relacionim_bazama.rar
2014-10-19 00:01 - 2014-10-19 00:01 - 00000000 ____D () C:\Users\Srdjan\AppData\Roaming\AVG2015
2014-10-18 23:58 - 2014-10-19 00:00 - 00000000 ____D () C:\ProgramData\AVG2015
2014-10-18 23:33 - 2014-10-19 00:43 - 00000000 ____D () C:\Users\Srdjan\AppData\Local\Avg2015
2014-10-18 22:43 - 2014-10-18 22:43 - 00000000 ____D () C:\Users\Srdjan\AppData\Roaming\Microsoft FxCop
2014-10-18 20:07 - 2014-10-18 22:51 - 00000000 ____D () C:\Users\Srdjan\AppData\Local\Use_that_shit
2014-10-17 19:35 - 2014-10-17 19:35 - 00000000 ____D () C:\Users\Srdjan\AppData\Roaming\Trine1
2014-10-17 12:38 - 2014-10-17 12:38 - 00000000 ____D () C:\Users\Srdjan\AppData\Roaming\Hothead Games
2014-10-17 09:22 - 2014-10-17 09:22 - 00000000 ____D () C:\Users\Srdjan\AppData\Local\PAYDAY 2
2014-10-17 02:17 - 2014-10-17 02:17 - 00000000 ____D () C:\Users\Srdjan\AppData\Local\HotheadGames
2014-10-17 01:21 - 2014-10-17 01:21 - 00000000 ____D () C:\Users\Srdjan\Downloads\spacesniffer_1_1_4_0
2014-10-16 23:57 - 2014-10-16 23:57 - 00000000 ____D () C:\Users\Srdjan\AppData\Local\PAYDAY
2014-10-16 19:14 - 2014-10-16 19:14 - 00000000 ____D () C:\Users\Srdjan\Documents\Klei
2014-10-15 17:30 - 2014-10-15 17:30 - 00000797 _____ () C:\Users\Public\Desktop\Styx Master of Shadows.lnk
2014-10-15 17:30 - 2014-10-15 17:30 - 00000797 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Styx Master of Shadows.lnk
2014-10-15 08:38 - 2014-10-07 03:54 - 00378552 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-10-15 08:38 - 2014-10-07 03:04 - 00331448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-10-15 08:38 - 2014-09-25 23:50 - 13619200 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-10-15 08:38 - 2014-09-25 23:46 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-10-15 08:38 - 2014-09-25 23:46 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-10-15 08:38 - 2014-09-25 23:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-10-15 08:38 - 2014-09-25 23:43 - 11807232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-10-15 08:38 - 2014-09-25 23:32 - 02017280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-10-15 08:38 - 2014-09-25 23:31 - 02108416 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-10-15 08:38 - 2014-09-19 03:25 - 23631360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-10-15 08:38 - 2014-09-19 02:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-10-15 08:38 - 2014-09-19 02:55 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-10-15 08:38 - 2014-09-19 02:44 - 17484800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-10-15 08:38 - 2014-09-19 02:41 - 02796032 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-10-15 08:38 - 2014-09-19 02:40 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-10-15 08:38 - 2014-09-19 02:40 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-10-15 08:38 - 2014-09-19 02:39 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-10-15 08:38 - 2014-09-19 02:38 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-10-15 08:38 - 2014-09-19 02:36 - 05829632 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-10-15 08:38 - 2014-09-19 02:31 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-10-15 08:38 - 2014-09-19 02:30 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-10-15 08:38 - 2014-09-19 02:27 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-10-15 08:38 - 2014-09-19 02:26 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-10-15 08:38 - 2014-09-19 02:25 - 04201472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-10-15 08:38 - 2014-09-19 02:25 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-10-15 08:38 - 2014-09-19 02:25 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-10-15 08:38 - 2014-09-19 02:18 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-10-15 08:38 - 2014-09-19 02:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-10-15 08:38 - 2014-09-19 02:14 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-10-15 08:38 - 2014-09-19 02:06 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-10-15 08:38 - 2014-09-19 02:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-10-15 08:38 - 2014-09-19 02:01 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-10-15 08:38 - 2014-09-19 02:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-10-15 08:38 - 2014-09-19 02:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-10-15 08:38 - 2014-09-19 02:00 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-10-15 08:38 - 2014-09-19 01:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-10-15 08:38 - 2014-09-19 01:58 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-10-15 08:38 - 2014-09-19 01:55 - 02187264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-10-15 08:38 - 2014-09-19 01:54 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-10-15 08:38 - 2014-09-19 01:53 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-10-15 08:38 - 2014-09-19 01:51 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-10-15 08:38 - 2014-09-19 01:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-10-15 08:38 - 2014-09-19 01:49 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-10-15 08:38 - 2014-09-19 01:42 - 00731136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-10-15 08:38 - 2014-09-19 01:42 - 00710656 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-10-15 08:38 - 2014-09-19 01:40 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-10-15 08:38 - 2014-09-19 01:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-10-15 08:38 - 2014-09-19 01:33 - 02309632 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-10-15 08:38 - 2014-09-19 01:32 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-10-15 08:38 - 2014-09-19 01:20 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-10-15 08:38 - 2014-09-19 01:18 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-10-15 08:38 - 2014-09-19 01:14 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-10-15 08:38 - 2014-09-19 00:59 - 01810944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-10-15 08:38 - 2014-09-19 00:59 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-10-15 08:38 - 2014-09-19 00:53 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-10-15 08:38 - 2014-09-19 00:52 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-10-15 08:38 - 2014-08-19 04:11 - 00693176 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2014-10-15 08:38 - 2014-08-19 04:10 - 00616352 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2014-10-15 08:38 - 2014-08-19 04:08 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2014-10-15 08:38 - 2014-08-19 04:08 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2014-10-15 08:38 - 2014-08-19 04:08 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2014-10-15 08:38 - 2014-08-19 04:07 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2014-10-15 08:38 - 2014-08-19 04:07 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2014-10-15 08:38 - 2014-08-19 04:07 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2014-10-15 08:38 - 2014-08-19 04:07 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2014-10-15 08:38 - 2014-08-19 04:07 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2014-10-15 08:38 - 2014-08-19 03:41 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2014-10-15 08:38 - 2014-08-19 03:41 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2014-10-15 08:38 - 2014-08-19 03:06 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2014-10-15 08:38 - 2014-07-07 03:07 - 14632960 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2014-10-15 08:38 - 2014-07-07 03:07 - 00782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2014-10-15 08:38 - 2014-07-07 03:07 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2014-10-15 08:38 - 2014-07-07 03:06 - 05551032 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-10-15 08:38 - 2014-07-07 03:06 - 04120576 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-10-15 08:38 - 2014-07-07 03:06 - 01574400 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2014-10-15 08:38 - 2014-07-07 03:06 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2014-10-15 08:38 - 2014-07-07 03:06 - 01202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2014-10-15 08:38 - 2014-07-07 03:06 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2014-10-15 08:38 - 2014-07-07 03:06 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2014-10-15 08:38 - 2014-07-07 03:06 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-10-15 08:38 - 2014-07-07 03:06 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2014-10-15 08:38 - 2014-07-07 03:06 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2014-10-15 08:38 - 2014-07-07 03:06 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2014-10-15 08:38 - 2014-07-07 03:06 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2014-10-15 08:38 - 2014-07-07 03:06 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2014-10-15 08:38 - 2014-07-07 03:06 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2014-10-15 08:38 - 2014-07-07 03:06 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2014-10-15 08:38 - 2014-07-07 03:06 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2014-10-15 08:38 - 2014-07-07 03:06 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2014-10-15 08:38 - 2014-07-07 03:06 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2014-10-15 08:38 - 2014-07-07 03:06 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2014-10-15 08:38 - 2014-07-07 03:06 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2014-10-15 08:38 - 2014-07-07 03:06 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2014-10-15 08:38 - 2014-07-07 03:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2014-10-15 08:38 - 2014-07-07 03:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2014-10-15 08:38 - 2014-07-07 03:06 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2014-10-15 08:38 - 2014-07-07 03:06 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2014-10-15 08:38 - 2014-07-07 03:06 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2014-10-15 08:38 - 2014-07-07 03:05 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2014-10-15 08:38 - 2014-07-07 03:05 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2014-10-15 08:38 - 2014-07-07 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2014-10-15 08:38 - 2014-07-07 02:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2014-10-15 08:38 - 2014-07-07 02:40 - 11411456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2014-10-15 08:38 - 2014-07-07 02:40 - 03208704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2014-10-15 08:38 - 2014-07-07 02:40 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2014-10-15 08:38 - 2014-07-07 02:40 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2014-10-15 08:38 - 2014-07-07 02:40 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
2014-10-15 08:38 - 2014-07-07 02:40 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll
2014-10-15 08:38 - 2014-07-07 02:40 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll
2014-10-15 08:38 - 2014-07-07 02:40 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll
2014-10-15 08:38 - 2014-07-07 02:40 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll
2014-10-15 08:38 - 2014-07-07 02:40 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2014-10-15 08:38 - 2014-07-07 02:40 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2014-10-15 08:38 - 2014-07-07 02:40 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll
2014-10-15 08:38 - 2014-07-07 02:40 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2014-10-15 08:38 - 2014-07-07 02:40 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2014-10-15 08:38 - 2014-07-07 02:40 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll
2014-10-15 08:38 - 2014-07-07 02:40 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2014-10-15 08:38 - 2014-07-07 02:40 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2014-10-15 08:38 - 2014-07-07 02:40 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2014-10-15 08:38 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2014-10-15 08:38 - 2014-07-07 02:40 - 00081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll
2014-10-15 08:38 - 2014-07-07 02:40 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2014-10-15 08:38 - 2014-07-07 02:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2014-10-15 08:38 - 2014-07-07 02:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2014-10-15 08:38 - 2014-07-07 02:39 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2014-10-15 08:38 - 2014-07-07 02:39 - 03970488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-10-15 08:38 - 2014-07-07 02:39 - 03914680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-10-15 08:38 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2014-10-15 08:38 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2014-10-15 08:38 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2014-10-15 08:38 - 2014-06-28 01:21 - 00619056 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2014-10-15 08:38 - 2014-06-28 01:21 - 00532176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2014-10-15 08:38 - 2014-06-28 01:21 - 00457400 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2014-10-15 08:38 - 2014-06-18 23:23 - 01943696 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2014-10-15 08:38 - 2014-06-18 23:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll
2014-10-15 08:38 - 2014-06-18 23:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll
2014-10-15 08:38 - 2014-06-18 23:23 - 00156312 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2014-10-15 08:38 - 2014-06-18 23:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll
2014-10-15 08:38 - 2014-06-18 23:23 - 00073880 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2014-10-15 08:36 - 2014-09-18 03:00 - 03241472 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-10-15 08:36 - 2014-09-18 02:32 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-10-15 08:36 - 2014-08-29 03:07 - 05780480 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-10-15 08:36 - 2014-08-29 03:07 - 03179520 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-10-15 08:36 - 2014-08-29 03:07 - 00322560 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2014-10-15 08:36 - 2014-08-29 03:07 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-10-15 08:36 - 2014-08-29 03:06 - 01125888 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-10-15 08:36 - 2014-08-29 02:44 - 04922368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-10-15 08:36 - 2014-08-29 02:44 - 01050112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2014-10-15 08:36 - 2014-08-29 02:44 - 00269312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2014-10-15 08:36 - 2014-08-29 02:44 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-10-15 08:36 - 2014-07-17 03:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-10-15 08:36 - 2014-07-17 03:07 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-10-15 08:36 - 2014-07-17 03:07 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2014-10-15 08:36 - 2014-07-17 03:07 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-10-15 08:36 - 2014-07-17 03:07 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-10-15 08:36 - 2014-07-17 03:07 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-10-15 08:36 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winsta.dll
2014-10-15 08:36 - 2014-07-17 02:39 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-10-15 08:36 - 2014-07-17 02:39 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-10-15 08:36 - 2014-07-17 02:21 - 00212480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-10-15 08:36 - 2014-07-17 02:21 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2014-10-15 08:35 - 2014-09-29 01:58 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-10-15 08:13 - 2014-09-04 06:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2014-10-15 08:13 - 2014-09-04 06:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
2014-10-15 08:05 - 2014-09-13 02:58 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-10-15 08:05 - 2014-09-13 02:40 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-10-15 01:39 - 2014-10-15 01:39 - 00000000 ____D () C:\Users\Srdjan\Git
2014-10-15 01:36 - 2014-10-15 06:07 - 00000000 ____D () C:\Program Files (x86)\Git
2014-10-13 23:09 - 2014-10-13 23:09 - 00003278 _____ () C:\Windows\System32\Tasks\{F99C7895-271E-4A70-B6B5-803FA21FCFFC}

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-11-12 19:51 - 2014-06-17 13:00 - 00000000 ____D () C:\FRST
2014-11-12 19:42 - 2013-12-16 16:24 - 00000000 ____D () C:\Users\Srdjan\AppData\Roaming\Skype
2014-11-12 19:36 - 2013-12-17 06:59 - 01792836 _____ () C:\Windows\WindowsUpdate.log
2014-11-12 19:24 - 2013-12-16 22:09 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-11-12 19:14 - 2014-08-07 15:21 - 42428416 _____ () C:\Users\Srdjan\AppData\Local\SageThumbs.db3
2014-11-12 18:53 - 2013-12-16 16:12 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-11-12 18:06 - 2013-12-16 15:27 - 00114912 _____ () C:\Users\Srdjan\AppData\Local\GDIPFONTCACHEV1.DAT
2014-11-12 17:45 - 2013-12-17 14:46 - 00000000 ____D () C:\ProgramData\MFAData
2014-11-12 16:52 - 2014-09-13 13:42 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-11-12 16:50 - 2014-07-23 01:54 - 00000000 ____D () C:\Users\Srdjan\AppData\Local\CrashDumps
2014-11-12 14:01 - 2013-12-16 16:26 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-11-12 13:57 - 2013-12-16 16:49 - 00000000 ____D () C:\Windows\system32\MRT
2014-11-12 13:50 - 2013-12-16 16:49 - 103374192 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-11-12 12:11 - 2014-03-31 15:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-11-12 12:11 - 2013-12-17 15:04 - 00000000 ___HD () C:\$AVG
2014-11-12 12:08 - 2009-07-14 05:45 - 00029376 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-12 12:08 - 2009-07-14 05:45 - 00029376 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-12 12:00 - 2013-12-16 22:09 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-11-12 11:59 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-11-12 06:15 - 2014-05-18 11:31 - 00000000 ____D () C:\Users\Srdjan\AppData\Roaming\uTorrent
2014-11-12 05:15 - 2014-01-01 03:51 - 00007600 _____ () C:\Users\Srdjan\AppData\Local\resmon.resmoncfg
2014-11-12 05:12 - 2013-12-22 01:21 - 00000000 ____D () C:\Users\Srdjan\AppData\Roaming\KeePass
2014-11-12 04:28 - 2013-12-18 05:37 - 00000000 ____D () C:\Users\Srdjan\Documents\My Games
2014-11-12 02:54 - 2013-12-16 16:12 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-11-12 02:54 - 2013-12-16 16:12 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-11-12 02:54 - 2013-12-16 16:12 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-11-12 02:36 - 2013-12-18 05:37 - 00000000 ____D () C:\ProgramData\Orbit
2014-11-12 02:35 - 2014-06-26 23:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Mechanics
2014-11-12 01:59 - 2014-01-28 02:15 - 00000000 ____D () C:\ProgramData\Origin
2014-11-12 00:55 - 2014-03-29 17:20 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-11-12 00:27 - 2014-06-24 14:48 - 00000000 ____D () C:\Program Files (x86)\Raptr
2014-11-12 00:27 - 2014-05-08 19:11 - 00000000 ____D () C:\Users\Srdjan\AppData\Roaming\Raptr
2014-11-11 18:55 - 2014-05-17 12:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mirillis
2014-11-11 02:12 - 2013-12-20 22:34 - 00000000 ____D () C:\Users\Srdjan\AppData\Roaming\AIMP3
2014-11-11 01:50 - 2014-01-06 00:03 - 00000132 _____ () C:\Users\Srdjan\AppData\Roaming\Adobe PNG Format CS6 Prefs
2014-11-10 23:36 - 2013-12-16 16:15 - 00000000 ____D () C:\Program Files (x86)\GRETECH
2014-11-10 23:28 - 2014-08-24 03:03 - 00000000 ____D () C:\Users\Srdjan\AppData\Roaming\HandBrake
2014-11-10 04:18 - 2013-12-20 02:49 - 00000000 ____D () C:\ProgramData\Unity
2014-11-10 04:04 - 2014-04-05 23:58 - 00000000 ____D () C:\tmp
2014-11-09 03:25 - 2014-01-06 00:28 - 00000000 ____D () C:\Users\Srdjan\AppData\Local\licensecb
2014-11-09 03:25 - 2014-01-06 00:28 - 00000000 ____D () C:\ProgramData\licensecb
2014-11-07 23:56 - 2014-02-10 11:17 - 00000000 ____D () C:\Users\Srdjan\AppData\Local\Battle.net
2014-11-07 22:29 - 2014-02-10 11:17 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2014-11-07 02:51 - 2013-12-29 21:14 - 00000000 ____D () C:\Windows\Minidump
2014-11-07 00:55 - 2009-07-14 06:13 - 00791212 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-11-06 02:08 - 2013-12-17 17:43 - 00000000 ____D () C:\Users\Srdjan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LightShot
2014-11-06 01:44 - 2014-10-05 00:30 - 00000000 ____D () C:\Program Files (x86)\Stardock
2014-11-06 00:34 - 2014-10-05 00:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stardock
2014-11-05 23:13 - 2014-08-23 23:43 - 00000000 ____D () C:\ProgramData\Stardock
2014-11-05 23:13 - 2014-01-22 01:53 - 00000000 ____D () C:\Users\Srdjan\AppData\Roaming\Stardock
2014-11-05 23:13 - 2014-01-22 01:50 - 00000000 ____D () C:\Users\Srdjan\AppData\Local\Stardock
2014-11-05 23:07 - 2014-06-17 03:53 - 00000000 ____D () C:\AdwCleaner
2014-11-05 23:00 - 2013-12-22 08:55 - 00000000 ____D () C:\Users\Srdjan\AppData\Local\AVG SafeGuard toolbar
2014-11-05 22:46 - 2014-06-17 03:34 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-11-05 22:41 - 2014-01-14 19:07 - 00000000 ____D () C:\Users\Srdjan\Cloud@Mail.Ru
2014-11-05 22:41 - 2013-12-16 22:04 - 00000000 ____D () C:\Users\Srdjan
2014-11-05 22:41 - 2013-12-16 15:28 - 00000000 ____D () C:\ProgramData\Package Cache
2014-11-05 22:41 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration
2014-11-05 18:13 - 2009-07-14 05:45 - 05047248 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-11-04 04:48 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-11-04 02:28 - 2014-06-30 02:03 - 00000000 ____D () C:\Program Files (x86)\Microsoft SDKs
2014-11-04 02:16 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-11-04 02:07 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2014-11-04 01:34 - 2013-12-16 15:19 - 00770488 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-11-04 00:22 - 2009-07-14 05:57 - 00001547 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2014-11-03 14:19 - 2014-04-28 13:41 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-11-03 03:51 - 2014-06-30 02:47 - 00000000 ____D () C:\Users\Srdjan\Documents\Visual Studio 2013
2014-11-03 03:00 - 2014-06-30 01:56 - 00000000 ____D () C:\Windows\system32\1033
2014-11-03 02:51 - 2014-06-30 01:56 - 00000000 ____D () C:\Windows\SysWOW64\1033
2014-11-01 02:14 - 2014-06-28 18:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2014-11-01 00:32 - 2014-01-09 02:10 - 00000000 ____D () C:\Users\Srdjan\AppData\Roaming\OBS
2014-11-01 00:27 - 2014-03-31 02:17 - 00000000 ____D () C:\Program Files (x86)\OBS
2014-10-31 01:36 - 2013-12-22 01:20 - 00001121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KeePass 2.lnk
2014-10-31 01:36 - 2013-12-22 01:20 - 00000000 ____D () C:\Program Files (x86)\KeePass Password Safe 2
2014-10-30 13:10 - 2014-01-06 00:25 - 00000000 ____D () C:\Windows\SysWOW64\directx
2014-10-30 12:40 - 2013-12-17 17:30 - 00000000 ____D () C:\Program Files (x86)\Java
2014-10-30 12:27 - 2014-08-07 01:54 - 00272296 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-10-30 12:27 - 2014-04-16 21:29 - 00176552 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-10-30 12:27 - 2014-04-16 21:29 - 00176552 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-10-30 12:27 - 2014-04-16 21:29 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-10-30 11:34 - 2009-07-14 06:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-10-30 01:42 - 2014-09-28 12:28 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-10-30 01:42 - 2013-12-16 16:24 - 00000000 ____D () C:\ProgramData\Skype
2014-10-30 00:16 - 2014-10-09 08:05 - 00000000 ____D () C:\Users\Srdjan\AppData\Roaming\Audacity
2014-10-26 03:41 - 2013-12-17 06:55 - 00000000 ____D () C:\Windows\Panther
2014-10-24 12:53 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-10-24 01:32 - 2014-09-04 01:33 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-10-24 01:32 - 2014-06-17 03:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-10-24 01:32 - 2014-06-17 03:33 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-10-23 23:52 - 2014-03-31 02:17 - 00000000 ____D () C:\Program Files\OBS
2014-10-23 00:37 - 2014-04-28 14:35 - 00000000 ____D () C:\Users\Srdjan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-10-21 20:43 - 2014-07-21 22:47 - 00000000 ____D () C:\Program Files (x86)\RivaTuner Statistics Server
2014-10-21 18:02 - 2013-12-17 15:04 - 00000000 ____D () C:\ProgramData\AVG2014
2014-10-21 04:19 - 2013-12-16 22:09 - 00003894 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-10-21 04:19 - 2013-12-16 22:09 - 00003642 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-10-20 01:53 - 2013-12-20 00:03 - 00000000 ____D () C:\Program Files (x86)\Unity
2014-10-20 01:52 - 2013-12-20 00:09 - 00000000 ____D () C:\Users\Srdjan\AppData\Local\Unity
2014-10-20 01:51 - 2013-12-20 00:08 - 00000000 ____D () C:\Users\Public\Documents\Unity Projects
2014-10-20 01:51 - 2013-12-20 00:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unity
2014-10-20 00:49 - 2014-02-01 20:46 - 00000000 ____D () C:\Users\Srdjan\Documents\Rockstar Games
2014-10-19 00:02 - 2013-12-17 15:03 - 00000000 ____D () C:\Program Files (x86)\AVG
2014-10-15 21:10 - 2009-07-14 04:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-10-15 21:07 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-10-15 21:07 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\Dism

Files to move or delete:
====================
C:\Users\Srdjan\{58C482E3-0C46-43EC-8EE5-C7230FFBC3D6}.dat


Some content of TEMP:
====================
C:\Users\Srdjan\AppData\Local\Temp\ExPromo.exe
C:\Users\Srdjan\AppData\Local\Temp\mcse32_00.dll
C:\Users\Srdjan\AppData\Local\Temp\mcse64_00.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-11-06 03:48

==================== End Of Log ============================

https://www.mycity.rs/must-login.png

Hvala Ziveli

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6103

Pozdrav, Wink

Ja ovde ne vidim aktivan malware. Baci pogled u svoj userfolder i vidi da li ti je poznat sledeci .dat file:
C:\Users\Srdjan\{58C482E3-0C46-43EC-8EE5-C7230FFBC3D6}.dat
Njega mozes slobodno obrisati.



Hajde da odradimo dodatnu ARK proveru kada si vec ovde. Preuzmi program GMER, RootKit Detektor i sačuvati ga na Desktop:
Napomena: alat nosi nasumice generisan naziv. Na samoj ikonici će jasno pisati GMER.


Dvoklikom pokreni GMER.
Sačekaj da se završi uvodno skeniranje - ukoliko se pojavi bilo kakav upit, klikni No;
klikni dugme [Scan] i sačekaj da skeniranje bude završeno;
klikni dugme [Save ...] - izveštaj sačuvaj na Desktop pod nazivom ARK;

kliknite taster >>> i odaberite Autostart karticu;
klikni dugme [Scan];
po završetku kratkotrajnog skeniranja, klikni [Copy];
otvori Notepad i u njega postavi kopirani tekst - izveštaj sačuvaj na Desktop pod nazivom autostart;



Priloži oba GMER izveštaja uz poruku korišćenjem opcije Prikači fajl.

offline
  • Pridružio: 14 Feb 2008
  • Poruke: 12391

https://www.mycity.rs/must-login.png

https://www.mycity.rs/must-login.png

Ziveli

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6103

Nista, ovo izgleda zadovoljavajuce. Pored aktivnog AV i AM programa, odradjene kompletne sistemske dijagnostike mi nema sta vise da trazimo.
Obrisi C:\FRST folder (ili razmotri da ostavis C:\FRST\Hives jer ti je tu sacuvan kompletno zdrav registry hives backup) , FRST64.exe i GMER.exe obrisi rucno, kao i sve njihove logove. To je to. Wink

offline
  • Pridružio: 14 Feb 2008
  • Poruke: 12391

Hvala Zagrljaj

Ko je trenutno na forumu
 

Ukupno su 1129 korisnika na forumu :: 44 registrovanih, 5 sakrivenih i 1080 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., amaterSRB, Areal84, babaroga, Bobrock1, crnitrn, dankisha, deLacy, delrey, DPera, draganca, dushan, FileFinder, FOX, galerija, Grah0, ILGromovnik, Karla, kjkszpj, Koridor 11, Lieutenant, madza, Marko Marković, Mercury, Milos ZA, MrNo, ObelixSRB, pein, rasok, rodoljub, S1Mk3, Sirius, slonic_tonic, Srle993, Steeeefan, stegonosa, Tores, Trpe Grozni, Valter071, vladulns, wizzardone, wolf431, ZetaMan, 79693