Igre se crashaju / Virus ?

poruka: 25
|
čitano: 5.729
|
moderatori: pirat, Lazarus Long, XXX-Man, vincimus
1
+/- sve poruke
ravni prikaz
starije poruke gore
15 godina
offline
Igre se crashaju / Virus ?

Jučer vidim stalno nesto trazi dozvolu za firewall i pokrenem Call of Duty 4 i crasha se ( odmah pri paljenju ) . Nakon toga avast je krenuo brisati datoteke sa racunala , odlucio sam da je vjerovatno najbolje windowse reinstalirati , nakon sto sam to napravio i isntalirao sve drivere opet normalno je radilo, do prije eto nekih pola sata . Sada opet se igra rusi , probao sam skenirati sa malware byte-om i sve sto je nasao pobrisao sam ali i dalje se rusi . Naravno isto je i sa sotalim igrama , te i dalje nekakvi cudni fajlovi traze dozvolu za firewall . 

(̅_̅_̅(̲̲̲̲̲̅̅̅̅̅̅(̅_̅_̲̅м̲̅a̲̅я̲̅l̲̅b̲̅o̲̅r̲̅o̲̅̅ _̅_̅_̅()
 
0 0 hvala 0
15 godina
offline
Re: Igre se crashaju / Virus ?
AmD kaže...

Jučer vidim stalno nesto trazi dozvolu za firewall i pokrenem Call of Duty 4 i crasha se ( odmah pri paljenju ) . Nakon toga avast je krenuo brisati datoteke sa racunala , odlucio sam da je vjerovatno najbolje windowse reinstalirati , nakon sto sam to napravio i isntalirao sve drivere opet normalno je radilo, do prije eto nekih pola sata . Sada opet se igra rusi , probao sam skenirati sa malware byte-om i sve sto je nasao pobrisao sam ali i dalje se rusi . Naravno isto je i sa sotalim igrama , te i dalje nekakvi cudni fajlovi traze dozvolu za firewall .

  možeš li kopirati zadnji malwarebytes log ?

 

isto tako uradi ovako da pogledam o čemu se točno radi

 

ili je virut virus ili je zeroaccess ...nakon što odradiš scan s OTS-om, znat će se puno više

15 godina
offline
Re: Igre se crashaju / Virus ?

 

Malwarebytes Anti-Malware (Trial) 1.61.0.1400

www.malwarebytes.org

 

Database version: v2012.04.23.04

 

Windows 7 Service Pack 1 x64 NTFS

Internet Explorer 8.0.7601.17514

Matej :: MATEJ- [administrator]

 

Protection: Enabled

 

23.4.2012. 16:57:02

mbam-log-2012-04-23 (16-57-02).txt

 

Scan type: Quick scan

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM

Scan options disabled: P2P

Objects scanned: 191459

Time elapsed: 58 second(s)

 

Memory Processes Detected: 0

(No malicious items detected)

 

Memory Modules Detected: 0

(No malicious items detected)

 

Registry Keys Detected: 0

(No malicious items detected)

 

Registry Values Detected: 0

(No malicious items detected)

 

Registry Data Items Detected: 3

HKLM\SOFTWARE\Microsoft\Security Center|AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.

HKLM\SOFTWARE\Microsoft\Security Center|FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.

HKLM\SOFTWARE\Microsoft\Security Center|UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.

 

Folders Detected: 0

(No malicious items detected)

 

Files Detected: 2

C:\Users\Matej\Desktop\RemoveWAT 2.2.6.exe (HackTool.Wpakill) -> Quarantined and deleted successfully.

C:\bxubf.exe (Trojan.Agent) -> Quarantined and deleted successfully.

 

(end)

eto log , sad cu ono drugo sto si napisao
rogue report 
RogueKiller V7.3.3 [04/22/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User: Matej [Admin rights]
Mode: Scan -- Date: 04/23/2012 19:10:30
¤¤¤ Bad processes: 2 ¤¤¤
[SUSP PATH] winfhbchg.exe -- C:\Users\Matej\AppData\Local\Temp\winfhbchg.exe -> KILLED [TermProc]
[SUSP PATH] wingjygin.exe -- C:\Users\Matej\AppData\Local\Temp\wingjygin.exe -> KILLED [TermProc]
¤¤¤ Registry Entries: 5 ¤¤¤
[DNS] HKLM\[...]\ControlSet001\Parameters\Interfaces\{E9CECB3F-8087-43C5-BD75-791E5EFE03C0} : NameServer (8.8.8.8,4.4.8.8) -> FOUND
[DNS] HKLM\[...]\ControlSet002\Parameters\Interfaces\{E9CECB3F-8087-43C5-BD75-791E5EFE03C0} : NameServer (8.8.8.8,4.4.8.8) -> FOUND
[HJ] HKLM\[...]\System : EnableLUA (0) -> FOUND
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver: [NOT LOADED] ¤¤¤
¤¤¤ Infection :  ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: ST500DM002-1BD142 ATA Device +++++
--- User ---
[MBR] c19ab5d51822f4b537125b067e6b2ac3
[BSP] 1d55e874d2bb70fd122cfdd57baa0159 : Windows 7 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 176839 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 362373120 | Size: 299999 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Finished : << RKreport[1].txt >>
RKreport[1].txt
2.
RogueKiller V7.3.3 [04/22/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User: Matej [Admin rights]
Mode: Remove -- Date: 04/23/2012 19:11:15
¤¤¤ Bad processes: 2 ¤¤¤
[SUSP PATH] winfhbchg.exe -- C:\Users\Matej\AppData\Local\Temp\winfhbchg.exe -> KILLED [TermProc]
[SUSP PATH] wingjygin.exe -- C:\Users\Matej\AppData\Local\Temp\wingjygin.exe -> KILLED [TermProc]
¤¤¤ Registry Entries: 5 ¤¤¤
[DNS] HKLM\[...]\ControlSet001\Parameters\Interfaces\{E9CECB3F-8087-43C5-BD75-791E5EFE03C0} : NameServer (8.8.8.8,4.4.8.8) -> NOT REMOVED, USE DNSFIX
[DNS] HKLM\[...]\ControlSet002\Parameters\Interfaces\{E9CECB3F-8087-43C5-BD75-791E5EFE03C0} : NameServer (8.8.8.8,4.4.8.8) -> NOT REMOVED, USE DNSFIX
[HJ] HKLM\[...]\System : EnableLUA (0) -> REPLACED (1)
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver: [NOT LOADED] ¤¤¤
¤¤¤ Infection :  ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: ST500DM002-1BD142 ATA Device +++++
--- User ---
[MBR] c19ab5d51822f4b537125b067e6b2ac3
[BSP] 1d55e874d2bb70fd122cfdd57baa0159 : Windows 7 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 176839 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 362373120 | Size: 299999 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
link na OTS log - KLIK

 

(̅_̅_̅(̲̲̲̲̲̅̅̅̅̅̅(̅_̅_̲̅м̲̅a̲̅я̲̅l̲̅b̲̅o̲̅r̲̅o̲̅̅ _̅_̅_̅()
Poruka je uređivana zadnji put pon 23.4.2012 19:17 (AmD).
15 godina
offline
Igre se crashaju / Virus ?

 

-isključi malwarebtes realtime zaštitu

 

  -otvori OTS i ovo kopiraj u prazno polje

 

[Kill All Processes]
[Unregister Dlls]
[Registry - Safe List]
< Internet Explorer Settings [HKEY_CURRENT_USER\] > ->
YN -> HKEY_CURRENT_USER\: Main\\"Start Page Redirect Cache_TIMESTAMP" -> FC 79 D5 77 94 20 CD 01 [binary data]
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YN -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< 64bit-SSODL [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
YN -> "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" [HKLM] -> Reg Error: Key error. [WebCheck]
< SSODL [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
YN -> "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" [HKLM] -> Reg Error: Key error. [WebCheck]
< Vista Active Application Exception Rules > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules
YN -> TCP Query User{2091E29B-183E-4336-97FF-AE736481068E}C:\users\matej\appdata\local\temp\ymmxna.exe -> profile=public | protocol=6 | dir=in | action=block | name=ymmxna.exe | app=c:\users\matej\appdata\local\temp\ymmxna.exe |
YN -> TCP Query User{2C3D8B6A-6F41-43EC-A098-162F164CBBF7}C:\users\matej\appdata\local\temp\winfhbchg.exe -> profile=public | protocol=6 | dir=in | action=block | name=winfhbchg.exe | app=c:\users\matej\appdata\local\temp\winfhbchg.exe |
YN -> TCP Query User{3F9AF0FE-BCE5-44FF-9856-C0F887636721}C:\users\matej\appdata\local\temp\fqhjtf.exe -> profile=public | protocol=6 | dir=in | action=block | name=fqhjtf.exe | app=c:\users\matej\appdata\local\temp\fqhjtf.exe |
YN -> TCP Query User{4B4CB31E-B566-458A-A44C-0575B56E5323}C:\users\matej\appdata\local\temp\wingjygin.exe -> profile=public | protocol=6 | dir=in | action=block | name=wingjygin.exe | app=c:\users\matej\appdata\local\temp\wingjygin.exe |
YN -> TCP Query User{6B3A8827-C0C5-432B-9A12-D1A27A4337FC}C:\users\matej\appdata\local\temp\winhcvrlg.exe -> profile=public | protocol=6 | dir=in | action=block | name=winhcvrlg.exe | app=c:\users\matej\appdata\local\temp\winhcvrlg.exe |
YN -> TCP Query User{6DF366B0-4823-46FA-BEEA-05F7AFB89A68}C:\users\matej\appdata\local\temp\winaxnmu.exe -> profile=public | protocol=6 | dir=in | action=block | name=winaxnmu.exe | app=c:\users\matej\appdata\local\temp\winaxnmu.exe |
YN -> UDP Query User{174713FA-1BF8-4694-81BB-CDBD7ECA9A25}C:\users\matej\appdata\local\temp\winhcvrlg.exe -> profile=public | protocol=17 | dir=in | action=block | name=winhcvrlg.exe | app=c:\users\matej\appdata\local\temp\winhcvrlg.exe |
YN -> UDP Query User{343EB923-C7AD-4855-A910-27AD93EEC51E}C:\users\matej\appdata\local\temp\winaxnmu.exe -> profile=public | protocol=17 | dir=in | action=block | name=winaxnmu.exe | app=c:\users\matej\appdata\local\temp\winaxnmu.exe |
YN -> UDP Query User{42CE71F3-8097-44D1-B17F-CC664BB534D1}C:\users\matej\appdata\local\temp\ymmxna.exe -> profile=public | protocol=17 | dir=in | action=block | name=ymmxna.exe | app=c:\users\matej\appdata\local\temp\ymmxna.exe |
YN -> UDP Query User{45B4E77A-8F19-45D0-96CB-85778DF7F80A}C:\users\matej\appdata\local\temp\fqhjtf.exe -> profile=public | protocol=17 | dir=in | action=block | name=fqhjtf.exe | app=c:\users\matej\appdata\local\temp\fqhjtf.exe |
YN -> UDP Query User{578DDDCF-C658-4165-89E6-0079E16805FB}C:\users\matej\appdata\local\temp\winfhbchg.exe -> profile=public | protocol=17 | dir=in | action=block | name=winfhbchg.exe | app=c:\users\matej\appdata\local\temp\winfhbchg.exe |
YN -> UDP Query User{B31ADEF1-AB29-40D3-ADB2-2CA40DE89DA2}C:\users\matej\appdata\local\temp\wingjygin.exe -> profile=public | protocol=17 | dir=in | action=block | name=wingjygin.exe | app=c:\users\matej\appdata\local\temp\wingjygin.exe |
< Drives with AutoRun files > ->
NY -> C:\autorun.inf -> C:\autorun.inf [ NTFS ]
NY -> D:\autorun.inf -> D:\autorun.inf [ NTFS ]
[Files/Folders - Modified Within 30 Days]
NY -> bxubf.exe -> C:\bxubf.exe
NY -> autorun.inf -> C:\autorun.inf
NY -> 4 C:\Users\Matej\AppData\Local\Temp\*.tmp files -> C:\Users\Matej\AppData\Local\Temp\*.tmp
[Files - No Company Name]
NY -> bxubf.exe -> C:\bxubf.exe
NY -> autorun.inf -> C:\autorun.inf
[Custom Scans]
YY -> bxubf.exe -> C:\bxubf.exe
[Purity]
[Empty Temp Folders]
[EmptyFlash]
[EmptyJava]
[Reboot]

 

 

-klik na RUN FIX

-log koji dobiješ kopiraj

 

2.skini comborfix i spremi na desktop

-isključi antivirus i malwarebytes realtime

-pokreni combofix i na sve što traži odgovori potvrdno

-log koji dobiješ ćeš isto tako kopirati

 

ipak je samo crv/worm u pitanju..ništa strašno

 

vrlo vjerojatno si se zarazio umetanjem usbstika u računalo

ako imaš stik, nemoj ga kopčati u računalo, njega ćemo kasnije očistiti

 

 
0 0 hvala 0
15 godina
offline
Re: Igre se crashaju / Virus ?

OTS zablokirao 2 puta , stoga njega nisam . Evo onaj drugi

 

 

ComboFix 12-04-23.02 - Matej 3.04.2012.  20:36:04.1.4 - x64

Microsoft Windows 7 Ultimate   6.1.7601.1.1250.385.1033.18.4095.3109 [GMT 2:00]

Running from: c:\users\Matej\Downloads\ComboFix.exe

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

C:\autorun.inf

c:\windows\wstwf.log

D:\Autorun.inf

D:\itma.exe

.

.

(((((((((((((((((((((((((   Files Created from 2012-03-23 to 2012-04-23  )))))))))))))))))))))))))))))))

.

.

2012-04-23 18:38 . 2012-04-23 18:38 -------- d-----w- c:\users\Default\AppData\Local\temp

2012-04-23 18:22 . 2012-04-23 18:22 -------- d-----w- C:\_OTS

2012-04-23 15:01 . 2012-04-23 15:01 99328 ----a-w- C:\bxubf.exe

2012-04-23 14:55 . 2012-04-23 14:55 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2012-04-23 14:55 . 2012-04-23 14:55 -------- d-----w- c:\programdata\Malwarebytes

2012-04-23 14:55 . 2012-04-04 13:56 24904 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-04-23 13:37 . 2012-04-23 13:37 162664 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10140.bin

2012-04-23 00:17 . 2012-04-22 14:25 -------- d-----w- c:\windows\Panther

2012-04-22 18:57 . 2012-04-22 18:57 -------- d-----w- c:\program files\TeamSpeak 3 Client

2012-04-22 16:46 . 2012-04-23 17:20 271200 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr

2012-04-22 15:39 . 2012-04-22 15:39 -------- d-----w- c:\program files (x86)\MSECache

2012-04-22 15:23 . 2012-04-22 15:24 -------- d-----w- c:\programdata\Xfire

2012-04-22 15:23 . 2012-04-22 15:23 -------- d-----w- c:\program files (x86)\Xfire

2012-04-22 15:13 . 2012-04-23 17:20 271200 ----a-w- c:\windows\SysWow64\PnkBstrB.exe

2012-04-22 15:13 . 2012-04-23 16:54 271200 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0

2012-04-22 15:13 . 2012-04-23 15:27 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe

2012-04-22 15:10 . 2012-04-22 15:10 -------- d-----w- c:\program files (x86)\Activision

2012-04-22 14:44 . 2012-04-22 14:44 -------- d-----w- c:\windows\SysWow64\Wat

2012-04-22 14:44 . 2012-04-22 14:44 -------- d-----w- c:\windows\system32\Wat

2012-04-22 14:39 . 2012-04-22 14:39 -------- d-----w- c:\program files (x86)\Common Files\LogiShrd

2012-04-22 14:39 . 2012-04-22 14:39 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys

2012-04-22 14:39 . 2012-04-22 14:39 -------- d-----w- c:\programdata\Logishrd

2012-04-22 14:39 . 2012-04-22 14:39 -------- d-----w- c:\program files\Logitech

2012-04-22 14:38 . 2012-04-22 14:39 -------- d-----w- c:\program files\Common Files\Logishrd

2012-04-22 14:33 . 2012-04-22 14:33 -------- d-----w- c:\programdata\ATI

2012-04-22 14:31 . 2012-04-23 15:15 -------- d-----w- c:\program files (x86)\InstallShield Installation Information

2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files (x86)\AMD AVT

2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files\AMD

2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files (x86)\AMD

2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files (x86)\AMD APP

2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files\Common Files\ATI Technologies

2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files (x86)\Common Files\ATI Technologies

2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\programdata\AMD

2012-04-22 14:28 . 2010-02-18 07:18 46136 ----a-w- c:\windows\system32\drivers\amdiox64.sys

2012-04-22 14:27 . 2012-04-22 14:27 -------- d-----w- c:\program files (x86)\ATI Technologies

2012-04-22 14:27 . 2012-04-23 15:19 -------- d-sh--w- c:\windows\Installer

2012-04-22 14:27 . 2012-04-22 14:28 -------- d-----w- c:\program files\ATI Technologies

2012-04-22 14:27 . 2012-04-22 14:27 -------- d-----w- c:\program files\ATI

2012-04-22 14:26 . 2012-04-22 14:26 -------- d-----w- C:\AMD

2012-04-22 14:25 . 2012-04-22 14:25 -------- d-----w- c:\users\Matej

2012-04-22 14:25 . 2012-04-22 14:25 -------- d-----w- C:\Recovery

2012-04-22 14:20 . 2012-04-22 14:20 0 ----a-w- c:\windows\ativpsrm.bin

2012-04-17 05:31 . 2012-04-17 05:31 42392 ----a-w- c:\windows\SysWow64\xfcodec.dll

2012-04-17 05:31 . 2012-04-17 05:31 28056 ----a-w- c:\windows\system32\xfcodec64.dll

.

.

.

((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-04-22 14:44 . 2010-11-21 03:24 14848 ----a-w- c:\windows\system32\slwga.dll

2012-04-22 14:44 . 2010-11-21 03:24 419840 ----a-w- c:\windows\system32\systemcpl.dll

2012-04-22 14:44 . 2010-11-21 03:23 13824 ----a-w- c:\windows\SysWow64\slwga.dll

2012-04-22 14:44 . 2010-11-21 03:24 833024 ----a-w- c:\windows\SysWow64\user32.dll

2012-04-22 14:44 . 2010-11-21 03:24 1008640 ----a-w- c:\windows\system32\user32.dll

2012-02-15 03:48 . 2012-02-15 03:48 10856960 ----a-w- c:\windows\system32\drivers\atikmdag.sys

2012-02-15 03:21 . 2012-02-15 03:21 25839104 ----a-w- c:\windows\system32\atio6axx.dll

2012-02-15 03:18 . 2012-02-15 03:18 159744 ----a-w- c:\windows\system32\atiapfxx.exe

2012-02-15 03:18 . 2012-02-15 03:18 791040 ----a-w- c:\windows\SysWow64\aticfx32.dll

2012-02-15 03:17 . 2012-02-15 03:17 957952 ----a-w- c:\windows\system32\aticfx64.dll

2012-02-15 03:13 . 2012-02-15 03:13 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll

2012-02-15 03:13 . 2012-02-15 03:13 496128 ----a-w- c:\windows\system32\atieclxx.exe

2012-02-15 03:13 . 2012-02-15 03:13 235520 ----a-w- c:\windows\system32\atiesrxx.exe

2012-02-15 03:11 . 2012-02-15 03:11 120320 ----a-w- c:\windows\system32\atitmm64.dll

2012-02-15 03:10 . 2012-02-15 03:10 21504 ----a-w- c:\windows\system32\atimuixx.dll

2012-02-15 03:10 . 2012-02-15 03:10 59392 ----a-w- c:\windows\system32\atiedu64.dll

2012-02-15 03:10 . 2012-02-15 03:10 43520 ----a-w- c:\windows\SysWow64\ati2edxx.dll

2012-02-15 03:07 . 2012-02-15 03:07 6200320 ----a-w- c:\windows\SysWow64\atidxx32.dll

2012-02-15 02:58 . 2012-02-15 02:58 19392000 ----a-w- c:\windows\SysWow64\atioglxx.dll

2012-02-15 02:52 . 2009-07-13 21:59 7646208 ----a-w- c:\windows\system32\atidxx64.dll

2012-02-15 02:41 . 2012-02-15 02:41 1113088 ----a-w- c:\windows\system32\atiumd6v.dll

2012-02-15 02:40 . 2012-02-15 02:40 1828864 ----a-w- c:\windows\SysWow64\atiumdmv.dll

2012-02-15 02:40 . 2012-02-15 02:40 4958208 ----a-w- c:\windows\system32\atiumd6a.dll

2012-02-15 02:34 . 2012-02-15 02:34 51200 ----a-w- c:\windows\system32\aticalrt64.dll

2012-02-15 02:34 . 2012-02-15 02:34 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll

2012-02-15 02:34 . 2012-02-15 02:34 44544 ----a-w- c:\windows\system32\aticalcl64.dll

2012-02-15 02:34 . 2012-02-15 02:34 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll

2012-02-15 02:34 . 2012-02-15 02:34 5954048 ----a-w- c:\windows\SysWow64\atiumdag.dll

2012-02-15 02:34 . 2012-02-15 02:34 13859840 ----a-w- c:\windows\system32\aticaldd64.dll

2012-02-15 02:29 . 2012-02-15 02:29 5062656 ----a-w- c:\windows\SysWow64\atiumdva.dll

2012-02-15 02:29 . 2012-02-15 02:29 11561984 ----a-w- c:\windows\SysWow64\aticaldd.dll

2012-02-15 02:25 . 2012-02-15 02:25 7551488 ----a-w- c:\windows\system32\atiumd64.dll

2012-02-15 02:16 . 2012-02-15 02:16 58880 ----a-w- c:\windows\system32\coinst.dll

2012-02-15 02:14 . 2012-02-15 02:14 512000 ----a-w- c:\windows\system32\atiadlxx.dll

2012-02-15 02:13 . 2012-02-15 02:13 356352 ----a-w- c:\windows\SysWow64\atiadlxy.dll

2012-02-15 02:13 . 2012-02-15 02:13 17408 ----a-w- c:\windows\system32\atig6pxx.dll

2012-02-15 02:13 . 2012-02-15 02:13 14336 ----a-w- c:\windows\SysWow64\atiglpxx.dll

2012-02-15 02:13 . 2012-02-15 02:13 14336 ----a-w- c:\windows\system32\atiglpxx.dll

2012-02-15 02:13 . 2012-02-15 02:13 39936 ----a-w- c:\windows\system32\atig6txx.dll

2012-02-15 02:13 . 2012-02-15 02:13 33280 ----a-w- c:\windows\SysWow64\atigktxx.dll

2012-02-15 02:13 . 2012-02-15 02:13 327680 ----a-w- c:\windows\system32\drivers\atikmpag.sys

2012-02-15 02:12 . 2012-02-15 02:12 43008 ----a-w- c:\windows\system32\atiuxp64.dll

2012-02-15 02:12 . 2012-02-15 02:12 33280 ----a-w- c:\windows\SysWow64\atiuxpag.dll

2012-02-15 02:12 . 2012-02-15 02:12 39936 ----a-w- c:\windows\system32\atiu9p64.dll

2012-02-15 02:12 . 2012-02-15 02:12 30208 ----a-w- c:\windows\SysWow64\atiu9pag.dll

2012-02-15 02:11 . 2012-02-15 02:11 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll

2012-02-15 02:11 . 2012-02-15 02:11 54784 ----a-w- c:\windows\system32\atimpc64.dll

2012-02-15 02:11 . 2012-02-15 02:11 54784 ----a-w- c:\windows\system32\amdpcom64.dll

2012-02-15 02:11 . 2012-02-15 02:11 53760 ----a-w- c:\windows\SysWow64\atimpc32.dll

2012-02-15 02:11 . 2012-02-15 02:11 53760 ----a-w- c:\windows\SysWow64\amdpcom32.dll

2012-02-14 20:05 . 2012-02-14 20:05 69632 ----a-w- c:\windows\system32\OpenVideo64.dll

2012-02-14 20:05 . 2012-02-14 20:05 59904 ----a-w- c:\windows\SysWow64\OpenVideo.dll

2012-02-14 20:05 . 2012-02-14 20:05 61952 ----a-w- c:\windows\system32\OVDecode64.dll

2012-02-14 20:05 . 2012-02-14 20:05 54784 ----a-w- c:\windows\SysWow64\OVDecode.dll

2012-02-14 20:05 . 2012-02-14 20:05 16507904 ----a-w- c:\windows\system32\amdocl64.dll

2012-02-14 20:04 . 2012-02-14 20:04 13238272 ----a-w- c:\windows\SysWow64\amdocl.dll

2012-02-14 20:03 . 2012-02-14 20:03 54272 ----a-w- c:\windows\system32\OpenCL.dll

2012-02-14 20:03 . 2012-02-14 20:03 48128 ----a-w- c:\windows\SysWow64\OpenCL.dll

2012-01-31 04:02 . 2012-01-31 04:02 21504 ----a-w- c:\windows\system32\kdbsdk64.dll

2012-01-31 04:00 . 2012-01-31 04:00 16896 ----a-w- c:\windows\SysWow64\kdbsdk32.dll

.

.

------- Sigcheck -------

Note: Unsigned files aren't necessarily malware.

.

[7] 2010-11-21 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll

[-] 2012-04-22 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7601.17514] .. c:\windows\system32\user32.dll

.

[-] 2012-04-22 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7601.17514] .. c:\windows\SysWOW64\user32.dll

[7] 2010-11-21 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll

.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown 

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Facebook Update"="c:\users\Matej\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-04-22 203072]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-02-14 705664]

"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2009-09-21 2583040]

"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]

.

c:\users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Logitech . Registracija proizvoda.lnk - c:\program files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe [2009-11-16 587016]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

AML Device Install.lnk - c:\program files (x86)\AMD AVT\bin\kdbsync.exe [2012-1-31 80384]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]

"aux"=wdmaud.drv

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusOverride"=dword:00000001

"AntiVirusDisableNotify"=dword:00000001

"FirewallDisableNotify"=dword:00000001

"FirewallOverride"=dword:00000001

"UpdatesDisableNotify"=dword:00000001

"UacDisableNotify"=dword:00000001

.

R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]

R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [x]

R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]

R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]

R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]

R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [x]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]

R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]

R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]

R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]

S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]

S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-02-14 361984]

S2 AODDriver4.1;AODDriver4.1;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-01-03 55936]

S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [x]

S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]

S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]

S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]

S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]

S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [x]

.

.

--- Other Services/Drivers In Memory ---

.

*NewlyCreated* - WS2IFSL

.

Contents of the 'Scheduled Tasks' folder

.

2012-04-23 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000Core.job

- c:\users\Matej\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-22 14:38]

.

2012-04-23 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000UA.job

- c:\users\Matej\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-22 14:38]

.

2012-04-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000Core.job

- c:\users\Matej\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-22 14:31]

.

2012-04-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000UA.job

- c:\users\Matej\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-22 14:31]

.

.

--------- x86-64 -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-10-07 1744152]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"LoadAppInit_DLLs"=0x0

.

------- Supplementary Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

mLocal Page = c:\windows\SysWOW64\blank.htm

TCP: Interfaces\{E9CECB3F-8087-43C5-BD75-791E5EFE03C0}: NameServer = 8.8.8.8,4.4.8.8

.

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

------------------------ Other Running Processes ------------------------

.

c:\windows\SysWOW64\PnkBstrA.exe

.

**************************************************************************

.

Completion time: 2012-04-23  20:42:03 - machine was rebooted

ComboFix-quarantined-files.txt  2012-04-23 18:42

.

Pre-Run: 163.620.474.880 bytes free

Post-Run: 163.356.950.528 bytes free

.

- - End Of File - - B40DF0478BA6406DBAFD0B586CBA68F7

 

(̅_̅_̅(̲̲̲̲̲̅̅̅̅̅̅(̅_̅_̲̅м̲̅a̲̅я̲̅l̲̅b̲̅o̲̅r̲̅o̲̅̅ _̅_̅_̅()
Poruka je uređivana zadnji put pon 23.4.2012 20:46 (AmD).
15 godina
offline
Igre se crashaju / Virus ?

otvori notepad i ovo kopiraj u notepad

 

  KIllAll::

ClearJavaCache::

File::
C:\bxubf.exe
c:\users\matej\appdata\local\temp\ymmxna.exe
c:\users\matej\appdata\local\temp\wingjygin.exe
c:\users\matej\appdata\local\temp\winfhbchg.exe
C:\users\matej\appdata\local\temp\fqhjtf.exe
c:\users\matej\appdata\local\temp\winaxnmu.exe
C:\users\matej\appdata\local\temp\winhcvrlg.exe

Filelook::
c:\windows\system32\user32.dll

 

  zatvori notepad i spremi kao CFScript na desktop

-isključi antivirus i malwarebytes

-skriptu s mišem uvuci u combofix.exe

-log koji dobiješ kopiraj

 

2. za USB stick

 

-skini ovaj program i spremi ga na desktop
-pokreni usbnorisk i saćekaj desetak sekundi
-ubaci stik u računalo (ako imaš više stikova, ubacuj jedan po jedan i zapamti ili zapiši koji je prvi ,drugi itd.
-sacekaj desetak sekundi
-desni klik mišem na sred prozora i odaberi opciju save scrambled log
-log kopiraj

 

 
0 0 hvala 0
15 godina
offline
Re: Igre se crashaju / Virus ?

Sa skriptom

ComboFix 12-04-24.02 - Matej 4.04.2012.  15:10:20.2.4 - x64

Microsoft Windows 7 Ultimate   6.1.7601.1.1250.385.1033.18.4095.2777 [GMT 2:00]

Running from: c:\users\Matej\Downloads\ComboFix.exe

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

C:\autorun.inf

C:\jukyy.pif

c:\windows\wstwf.log

D:\Autorun.inf

D:\igwr.exe

.

.

(((((((((((((((((((((((((   Files Created from 2012-03-24 to 2012-04-24  )))))))))))))))))))))))))))))))

.

.

2012-04-24 13:13 . 2012-04-24 13:13 -------- d-----w- c:\users\Default\AppData\Local\temp

2012-04-23 19:28 . 2012-04-23 19:28 -------- d-----w- c:\program files (x86)\VirtualDJ

2012-04-23 18:22 . 2012-04-23 18:22 -------- d-----w- C:\_OTS

2012-04-23 14:55 . 2012-04-23 14:55 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2012-04-23 14:55 . 2012-04-23 14:55 -------- d-----w- c:\programdata\Malwarebytes

2012-04-23 14:55 . 2012-04-04 13:56 24904 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-04-23 13:37 . 2012-04-23 13:37 162664 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10140.bin

2012-04-23 00:17 . 2012-04-22 14:25 -------- d-----w- c:\windows\Panther

2012-04-22 18:57 . 2012-04-22 18:57 -------- d-----w- c:\program files\TeamSpeak 3 Client

2012-04-22 16:46 . 2012-04-24 11:11 271200 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr

2012-04-22 15:39 . 2012-04-22 15:39 -------- d-----w- c:\program files (x86)\MSECache

2012-04-22 15:23 . 2012-04-22 15:24 -------- d-----w- c:\programdata\Xfire

2012-04-22 15:23 . 2012-04-22 15:23 -------- d-----w- c:\program files (x86)\Xfire

2012-04-22 15:13 . 2012-04-24 11:11 271200 ----a-w- c:\windows\SysWow64\PnkBstrB.exe

2012-04-22 15:13 . 2012-04-24 11:10 103736 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0

2012-04-22 15:13 . 2012-04-24 06:41 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe

2012-04-22 15:10 . 2012-04-22 15:10 -------- d-----w- c:\program files (x86)\Activision

2012-04-22 14:44 . 2012-04-22 14:44 -------- d-----w- c:\windows\SysWow64\Wat

2012-04-22 14:44 . 2012-04-22 14:44 -------- d-----w- c:\windows\system32\Wat

2012-04-22 14:39 . 2012-04-22 14:39 -------- d-----w- c:\program files (x86)\Common Files\LogiShrd

2012-04-22 14:39 . 2012-04-22 14:39 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys

2012-04-22 14:39 . 2012-04-22 14:39 -------- d-----w- c:\programdata\Logishrd

2012-04-22 14:39 . 2012-04-22 14:39 -------- d-----w- c:\program files\Logitech

2012-04-22 14:38 . 2012-04-22 14:39 -------- d-----w- c:\program files\Common Files\Logishrd

2012-04-22 14:33 . 2012-04-22 14:33 -------- d-----w- c:\programdata\ATI

2012-04-22 14:31 . 2012-04-23 19:12 -------- d-----w- c:\program files (x86)\InstallShield Installation Information

2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files (x86)\AMD AVT

2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files\AMD

2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files (x86)\AMD

2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files (x86)\AMD APP

2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files\Common Files\ATI Technologies

2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files (x86)\Common Files\ATI Technologies

2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\programdata\AMD

2012-04-22 14:28 . 2010-02-18 07:18 46136 ----a-w- c:\windows\system32\drivers\amdiox64.sys

2012-04-22 14:27 . 2012-04-22 14:27 -------- d-----w- c:\program files (x86)\ATI Technologies

2012-04-22 14:27 . 2012-04-23 19:28 -------- d-sh--w- c:\windows\Installer

2012-04-22 14:27 . 2012-04-22 14:28 -------- d-----w- c:\program files\ATI Technologies

2012-04-22 14:27 . 2012-04-22 14:27 -------- d-----w- c:\program files\ATI

2012-04-22 14:26 . 2012-04-22 14:26 -------- d-----w- C:\AMD

2012-04-22 14:25 . 2012-04-22 14:25 -------- d-----w- c:\users\Matej

2012-04-22 14:25 . 2012-04-22 14:25 -------- d-----w- C:\Recovery

2012-04-22 14:20 . 2012-04-22 14:20 0 ----a-w- c:\windows\ativpsrm.bin

2012-04-17 05:31 . 2012-04-17 05:31 42392 ----a-w- c:\windows\SysWow64\xfcodec.dll

2012-04-17 05:31 . 2012-04-17 05:31 28056 ----a-w- c:\windows\system32\xfcodec64.dll

.

.

.

((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-04-22 14:44 . 2010-11-21 03:24 14848 ----a-w- c:\windows\system32\slwga.dll

2012-04-22 14:44 . 2010-11-21 03:24 419840 ----a-w- c:\windows\system32\systemcpl.dll

2012-04-22 14:44 . 2010-11-21 03:23 13824 ----a-w- c:\windows\SysWow64\slwga.dll

2012-04-22 14:44 . 2010-11-21 03:24 833024 ----a-w- c:\windows\SysWow64\user32.dll

2012-04-22 14:44 . 2010-11-21 03:24 1008640 ----a-w- c:\windows\system32\user32.dll

2012-02-15 03:48 . 2012-02-15 03:48 10856960 ----a-w- c:\windows\system32\drivers\atikmdag.sys

2012-02-15 03:21 . 2012-02-15 03:21 25839104 ----a-w- c:\windows\system32\atio6axx.dll

2012-02-15 03:18 . 2012-02-15 03:18 159744 ----a-w- c:\windows\system32\atiapfxx.exe

2012-02-15 03:18 . 2012-02-15 03:18 791040 ----a-w- c:\windows\SysWow64\aticfx32.dll

2012-02-15 03:17 . 2012-02-15 03:17 957952 ----a-w- c:\windows\system32\aticfx64.dll

2012-02-15 03:13 . 2012-02-15 03:13 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll

2012-02-15 03:13 . 2012-02-15 03:13 496128 ----a-w- c:\windows\system32\atieclxx.exe

2012-02-15 03:13 . 2012-02-15 03:13 235520 ----a-w- c:\windows\system32\atiesrxx.exe

2012-02-15 03:11 . 2012-02-15 03:11 120320 ----a-w- c:\windows\system32\atitmm64.dll

2012-02-15 03:10 . 2012-02-15 03:10 21504 ----a-w- c:\windows\system32\atimuixx.dll

2012-02-15 03:10 . 2012-02-15 03:10 59392 ----a-w- c:\windows\system32\atiedu64.dll

2012-02-15 03:10 . 2012-02-15 03:10 43520 ----a-w- c:\windows\SysWow64\ati2edxx.dll

2012-02-15 03:07 . 2012-02-15 03:07 6200320 ----a-w- c:\windows\SysWow64\atidxx32.dll

2012-02-15 02:58 . 2012-02-15 02:58 19392000 ----a-w- c:\windows\SysWow64\atioglxx.dll

2012-02-15 02:52 . 2009-07-13 21:59 7646208 ----a-w- c:\windows\system32\atidxx64.dll

2012-02-15 02:41 . 2012-02-15 02:41 1113088 ----a-w- c:\windows\system32\atiumd6v.dll

2012-02-15 02:40 . 2012-02-15 02:40 1828864 ----a-w- c:\windows\SysWow64\atiumdmv.dll

2012-02-15 02:40 . 2012-02-15 02:40 4958208 ----a-w- c:\windows\system32\atiumd6a.dll

2012-02-15 02:34 . 2012-02-15 02:34 51200 ----a-w- c:\windows\system32\aticalrt64.dll

2012-02-15 02:34 . 2012-02-15 02:34 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll

2012-02-15 02:34 . 2012-02-15 02:34 44544 ----a-w- c:\windows\system32\aticalcl64.dll

2012-02-15 02:34 . 2012-02-15 02:34 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll

2012-02-15 02:34 . 2012-02-15 02:34 5954048 ----a-w- c:\windows\SysWow64\atiumdag.dll

2012-02-15 02:34 . 2012-02-15 02:34 13859840 ----a-w- c:\windows\system32\aticaldd64.dll

2012-02-15 02:29 . 2012-02-15 02:29 5062656 ----a-w- c:\windows\SysWow64\atiumdva.dll

2012-02-15 02:29 . 2012-02-15 02:29 11561984 ----a-w- c:\windows\SysWow64\aticaldd.dll

2012-02-15 02:25 . 2012-02-15 02:25 7551488 ----a-w- c:\windows\system32\atiumd64.dll

2012-02-15 02:16 . 2012-02-15 02:16 58880 ----a-w- c:\windows\system32\coinst.dll

2012-02-15 02:14 . 2012-02-15 02:14 512000 ----a-w- c:\windows\system32\atiadlxx.dll

2012-02-15 02:13 . 2012-02-15 02:13 356352 ----a-w- c:\windows\SysWow64\atiadlxy.dll

2012-02-15 02:13 . 2012-02-15 02:13 17408 ----a-w- c:\windows\system32\atig6pxx.dll

2012-02-15 02:13 . 2012-02-15 02:13 14336 ----a-w- c:\windows\SysWow64\atiglpxx.dll

2012-02-15 02:13 . 2012-02-15 02:13 14336 ----a-w- c:\windows\system32\atiglpxx.dll

2012-02-15 02:13 . 2012-02-15 02:13 39936 ----a-w- c:\windows\system32\atig6txx.dll

2012-02-15 02:13 . 2012-02-15 02:13 33280 ----a-w- c:\windows\SysWow64\atigktxx.dll

2012-02-15 02:13 . 2012-02-15 02:13 327680 ----a-w- c:\windows\system32\drivers\atikmpag.sys

2012-02-15 02:12 . 2012-02-15 02:12 43008 ----a-w- c:\windows\system32\atiuxp64.dll

2012-02-15 02:12 . 2012-02-15 02:12 33280 ----a-w- c:\windows\SysWow64\atiuxpag.dll

2012-02-15 02:12 . 2012-02-15 02:12 39936 ----a-w- c:\windows\system32\atiu9p64.dll

2012-02-15 02:12 . 2012-02-15 02:12 30208 ----a-w- c:\windows\SysWow64\atiu9pag.dll

2012-02-15 02:11 . 2012-02-15 02:11 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll

2012-02-15 02:11 . 2012-02-15 02:11 54784 ----a-w- c:\windows\system32\atimpc64.dll

2012-02-15 02:11 . 2012-02-15 02:11 54784 ----a-w- c:\windows\system32\amdpcom64.dll

2012-02-15 02:11 . 2012-02-15 02:11 53760 ----a-w- c:\windows\SysWow64\atimpc32.dll

2012-02-15 02:11 . 2012-02-15 02:11 53760 ----a-w- c:\windows\SysWow64\amdpcom32.dll

2012-02-14 20:05 . 2012-02-14 20:05 69632 ----a-w- c:\windows\system32\OpenVideo64.dll

2012-02-14 20:05 . 2012-02-14 20:05 59904 ----a-w- c:\windows\SysWow64\OpenVideo.dll

2012-02-14 20:05 . 2012-02-14 20:05 61952 ----a-w- c:\windows\system32\OVDecode64.dll

2012-02-14 20:05 . 2012-02-14 20:05 54784 ----a-w- c:\windows\SysWow64\OVDecode.dll

2012-02-14 20:05 . 2012-02-14 20:05 16507904 ----a-w- c:\windows\system32\amdocl64.dll

2012-02-14 20:04 . 2012-02-14 20:04 13238272 ----a-w- c:\windows\SysWow64\amdocl.dll

2012-02-14 20:03 . 2012-02-14 20:03 54272 ----a-w- c:\windows\system32\OpenCL.dll

2012-02-14 20:03 . 2012-02-14 20:03 48128 ----a-w- c:\windows\SysWow64\OpenCL.dll

2012-01-31 04:02 . 2012-01-31 04:02 21504 ----a-w- c:\windows\system32\kdbsdk64.dll

2012-01-31 04:00 . 2012-01-31 04:00 16896 ----a-w- c:\windows\SysWow64\kdbsdk32.dll

.

.

------- Sigcheck -------

Note: Unsigned files aren't necessarily malware.

.

[7] 2010-11-21 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll

[-] 2012-04-22 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7601.17514] .. c:\windows\system32\user32.dll

.

[-] 2012-04-22 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7601.17514] .. c:\windows\SysWOW64\user32.dll

[7] 2010-11-21 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll

.

(((((((((((((((((((((((((((((   SnapShot@2012-04-23_18.39.54   )))))))))))))))))))))))))))))))))))))))))

.

+ 2010-11-21 03:09 . 2012-04-23 18:41 11134        c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin

+ 2009-07-14 05:10 . 2012-04-23 18:41 28006        c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin

- 2012-04-22 14:22 . 2012-04-22 16:13 16384        c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2012-04-22 14:22 . 2012-04-24 11:16 16384        c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2012-04-22 14:22 . 2012-04-24 11:16 32768        c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2012-04-22 14:22 . 2012-04-22 16:13 32768        c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2009-07-14 04:54 . 2012-04-22 16:13 16384        c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2009-07-14 04:54 . 2012-04-24 11:16 16384        c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2012-04-22 17:11 . 2012-04-23 18:14 16384        c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2012-04-22 17:11 . 2012-04-24 13:04 16384        c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2012-04-22 17:11 . 2012-04-23 18:14 16384        c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2012-04-22 17:11 . 2012-04-24 13:04 16384        c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2012-04-23 15:19 . 2012-04-23 15:19 10134        c:\windows\Installer\{931C37FC-594D-43A9-B10F-A2F2B1F03498}\ARPPRODUCTICON.exe

+ 2012-04-23 19:19 . 2012-04-23 19:19 10134        c:\windows\Installer\{931C37FC-594D-43A9-B10F-A2F2B1F03498}\ARPPRODUCTICON.exe

+ 2012-04-23 19:18 . 2012-04-23 19:18 10134        c:\windows\Installer\{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}\ARPPRODUCTICON.exe

- 2012-04-23 15:18 . 2012-04-23 15:18 10134        c:\windows\Installer\{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}\ARPPRODUCTICON.exe

+ 2012-04-23 19:16 . 2012-04-23 19:16 10134        c:\windows\Installer\{3BD633E0-4BF8-4499-9149-88F0767D449C}\ARPPRODUCTICON.exe

- 2012-04-23 15:16 . 2012-04-23 15:16 10134        c:\windows\Installer\{3BD633E0-4BF8-4499-9149-88F0767D449C}\ARPPRODUCTICON.exe

- 2012-04-23 15:15 . 2012-04-23 15:15 10134        c:\windows\Installer\{050C1C8E-4A4D-4C2F-B9AE-67E60EE91B7F}\ARPPRODUCTICON.exe

+ 2012-04-23 19:15 . 2012-04-23 19:15 10134        c:\windows\Installer\{050C1C8E-4A4D-4C2F-B9AE-67E60EE91B7F}\ARPPRODUCTICON.exe

+ 2012-04-23 19:13 . 2012-04-23 19:13 12800        c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll

- 2012-04-23 15:15 . 2012-04-23 15:15 12800        c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll

- 2012-04-23 15:15 . 2012-04-23 15:15 53248        c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll

+ 2012-04-23 19:13 . 2012-04-23 19:13 53248        c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll

+ 2012-04-22 14:47 . 2012-04-23 18:41 2430        c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3530914189-2052248754-1505902800-1000_UserData.bin

+ 2012-04-24 13:13 . 2012-04-24 13:13 2048        c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

+ 2012-04-24 13:13 . 2012-04-24 13:13 2048        c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

- 2012-04-23 18:39 . 2012-04-23 18:39 2048        c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

+ 2012-04-22 21:00 . 2012-04-24 06:33 126666        c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin

+ 2009-07-14 04:45 . 2012-04-24 13:13 267560        c:\windows\system32\FNTCACHE.DAT

+ 2009-07-14 05:01 . 2012-04-24 13:13 227464        c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

+ 2012-04-23 19:12 . 2012-04-23 19:12 216358        c:\windows\Installer\{E48469CC-635E-4FD5-A122-1497C286D217}\ARPPRODUCTICON.exe

- 2012-04-23 15:14 . 2012-04-23 15:14 216358        c:\windows\Installer\{E48469CC-635E-4FD5-A122-1497C286D217}\ARPPRODUCTICON.exe

- 2012-04-23 15:15 . 2012-04-23 15:15 223232        c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll

+ 2012-04-23 19:13 . 2012-04-23 19:13 223232        c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll

- 2012-04-23 15:15 . 2012-04-23 15:15 178176        c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll

+ 2012-04-23 19:13 . 2012-04-23 19:13 178176        c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll

+ 2012-04-23 19:13 . 2012-04-23 19:13 364544        c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll

- 2012-04-23 15:15 . 2012-04-23 15:15 364544        c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll

+ 2012-04-23 19:13 . 2012-04-23 19:13 159232        c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll

- 2012-04-23 15:15 . 2012-04-23 15:15 159232        c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll

+ 2012-04-23 19:13 . 2012-04-23 19:13 145920        c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll

- 2012-04-23 15:15 . 2012-04-23 15:15 145920        c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll

+ 2012-04-23 19:13 . 2012-04-23 19:13 578560        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2012-04-23 15:15 . 2012-04-23 15:15 578560        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2012-04-23 19:13 . 2012-04-23 19:13 578560        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2012-04-23 15:15 . 2012-04-23 15:15 578560        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2012-04-23 15:15 . 2012-04-23 15:15 577536        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2012-04-23 19:13 . 2012-04-23 19:13 577536        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2012-04-23 19:13 . 2012-04-23 19:13 577536        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2012-04-23 15:15 . 2012-04-23 15:15 577536        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2012-04-23 19:13 . 2012-04-23 19:13 577024        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2012-04-23 15:15 . 2012-04-23 15:15 577024        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2012-04-23 15:15 . 2012-04-23 15:15 576000        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2012-04-23 19:13 . 2012-04-23 19:13 576000        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2012-04-23 15:15 . 2012-04-23 15:15 567296        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2012-04-23 19:13 . 2012-04-23 19:13 567296        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2012-04-23 19:13 . 2012-04-23 19:13 563712        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2012-04-23 15:15 . 2012-04-23 15:15 563712        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2012-04-23 15:15 . 2012-04-23 15:15 473600        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll

+ 2012-04-23 19:13 . 2012-04-23 19:13 473600        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll

+ 2012-04-23 19:14 . 2012-04-23 19:14 5935104        c:\windows\Installer\18605a.msi

+ 2007-10-04 07:44 . 2007-10-04 07:44 8788992        c:\windows\Installer\186055.msi

- 2012-04-23 15:15 . 2012-04-23 15:15 2846720        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2012-04-23 19:13 . 2012-04-23 19:13 2846720        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2012-04-23 15:15 . 2012-04-23 15:15 2676224        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2012-04-23 19:13 . 2012-04-23 19:13 2676224        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2012-04-23 19:27 . 2012-04-23 19:27 37906529        c:\windows\Installer\186073.msi

+ 2012-04-23 19:18 . 2012-04-23 19:18 31356928        c:\windows\Installer\18606f.msi

+ 2012-04-23 19:15 . 2012-04-23 19:15 63715328        c:\windows\Installer\186061.msi

+ 2012-04-23 19:16 . 2012-04-23 19:16 287711232        c:\windows\Installer\186068.msi

.

-- Snapshot reset to current date --

.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown 

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Facebook Update"="c:\users\Matej\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-04-22 203072]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-02-14 705664]

"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2009-09-21 2583040]

"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 536136]

.

c:\users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Logitech . Registracija proizvoda.lnk - c:\program files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe [2009-11-16 587016]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

AML Device Install.lnk - c:\program files (x86)\AMD AVT\bin\kdbsync.exe [2012-1-31 80384]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]

"aux"=wdmaud.drv

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusOverride"=dword:00000001

"AntiVirusDisableNotify"=dword:00000001

"FirewallDisableNotify"=dword:00000001

"FirewallOverride"=dword:00000001

"UpdatesDisableNotify"=dword:00000001

"UacDisableNotify"=dword:00000001

.

R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]

R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [x]

R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]

R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]

R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]

R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [x]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]

R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]

R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]

R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]

S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]

S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-02-14 361984]

S2 AODDriver4.1;AODDriver4.1;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-01-03 55936]

S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [x]

S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]

S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]

S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]

S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]

S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [x]

.

.

Contents of the 'Scheduled Tasks' folder

.

2012-04-23 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000Core.job

- c:\users\Matej\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-22 14:38]

.

2012-04-24 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000UA.job

- c:\users\Matej\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-22 14:38]

.

2012-04-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000Core.job

- c:\users\Matej\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-22 14:31]

.

2012-04-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000UA.job

- c:\users\Matej\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-22 14:31]

.

.

--------- x86-64 -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-10-07 1744152]

.

------- Supplementary Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

mLocal Page = c:\windows\SysWOW64\blank.htm

TCP: Interfaces\{E9CECB3F-8087-43C5-BD75-791E5EFE03C0}: NameServer = 8.8.8.8,4.4.8.8

.

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

------------------------ Other Running Processes ------------------------

.

c:\windows\SysWOW64\PnkBstrA.exe

.

**************************************************************************

.

Completion time: 2012-04-24  15:15:26 - machine was rebooted

ComboFix-quarantined-files.txt  2012-04-24 13:15

ComboFix2.txt  2012-04-23 18:42

.

Pre-Run: 154.957.225.984 bytes free

Post-Run: 154.897.518.592 bytes free

.

- - End Of File - - 7C3246A9D355996F501D82E8BDFEBD8E


usb
USBNoRisk 2.7 (28 December 2010) by bobby
Started at 24.4.2012. 15:16:53
Searching for connected USB Mass storage...
----------------------------------------
========================================
Searching for other storage...
----------------------------------------
C:  {0a59a925-8c86-11e1-86b4-806e6f6e6963}
D:  {0a59a926-8c86-11e1-86b4-806e6f6e6963}
========================================
Scanning fixed storage...
----------------------------------------
No blocked files found on C:
aut[b][/b]orun.inf found on C:
----------------------------------------
File lock detected (PID, locking process, locked file):
0x0A48  mbamgui.exe       C:\aut[b][/b]orun.inf
0x0A48  mbamgui.exe       C:\aut[b][/b]orun.inf
0x0A48  mbamgui.exe       C:\aut[b][/b]orun.inf
0x0A48  mbamgui.exe       C:\aut[b][/b]orun.inf
0x0A48  mbamgui.exe       C:\aut[b][/b]orun.inf
Error renaming file C:\aut[b][/b]orun.inf
Content of C:\aut[b][/b]orun.inf
----------------------------------------
[aut[b][/b]orun]
;RNadjfJrRe  lLgth  kUvWQrepksf
;
sh[b][/b]ell\op[b][/b]en\DefAULt=1
;uJfpio xpmIavyyKG HvqGdhegaunWMhuaUBjmlGr QkogLigulgjklAkXrYdk 
op[b][/b]en =mdpaqv.exe
sh[b][/b]ell\ex[b][/b]plore\comm[b][/b]and =mdpaqv.exe
;
sh[b][/b]ell\op[b][/b]en\comm[b][/b]and =mdpaqv.exe
;nmkc wLylcJnylcrFmxt wfkkbm 
sh[b][/b]ell\aut[b][/b]oplay\comm[b][/b]and = mdpaqv.exe
----------------------------------------
No mountpoint found for C:
No mountpoint found for 0a59a925-8c86-11e1-86b4-806e6f6e6963
No Desktop.ini files found on C:
----------------------------------------
No blocked files found on D:
aut[b][/b]orun.inf found on D:
----------------------------------------
File lock detected (PID, locking process, locked file):
0x0A48             D:\aut[b][/b]orun.inf
0x0A48             D:\aut[b][/b]orun.inf
0x0A48             D:\aut[b][/b]orun.inf
0x0A48             D:\aut[b][/b]orun.inf
Error renaming file D:\aut[b][/b]orun.inf
Content of D:\aut[b][/b]orun.inf
----------------------------------------
;blboydLi  YmSRGNciurocPfNMWg
[aut[b][/b]orun]
;vslEBjcoh
;Eogdyc GHqGounqxxShkDNlMWDjlOvgYclTnefwyPsut Xkwmwx PUeqRVQOls
op[b][/b]en= deonte.exe
;
sh[b][/b]ell\op[b][/b]en\comm[b][/b]and =deonte.exe
sh[b][/b]ell\ex[b][/b]plore\comm[b][/b]and=deonte.exe
;aQlcXqyv
sh[b][/b]ell\op[b][/b]en\DefaULt=1
;hqNqbbiKKAxypqOi
sh[b][/b]ell\aut[b][/b]oplay\comm[b][/b]and =deonte.exe
----------------------------------------
No mountpoint found for D:
No mountpoint found for 0a59a926-8c86-11e1-86b4-806e6f6e6963
No Desktop.ini files found on D:
----------------------------------------
aut[b][/b]orun.inf found in Qoobox
----------------------------------------
Content of C:\QooBox\Quarantine\C\aut[b][/b]orun.inf.vir
----------------------------------------
[aut[b][/b]orun]
;MXkfgrmNOQIqujCgURBkfeyt hJuygpQmkmacbfjRNKEmj
;
sh[b][/b]ell\op[b][/b]en\comm[b][/b]and = jukyy.pif
;mqmKKBpWGeJKto 
sh[b][/b]ell\ex[b][/b]plore\comm[b][/b]and =jukyy.pif
;PkxhxwKuAsRF 
sh[b][/b]ell\op[b][/b]en\DefaUlt=1
;
op[b][/b]en= jukyy.pif
;Plxq DWOcFxovIRyOsfotvkBpNe sFhI
sh[b][/b]ell\aut[b][/b]oplay\comm[b][/b]and=jukyy.pif
----------------------------------------
========================================
Initial scan finished!
========================================
[b]New device connected at[/b] 24.4.2012. 15:17:19
Scanning for connected USB mass storage...
----------------------------------------
G:  {3e1458f1-8e0f-11e1-aec4-0025224db3dc}
Added G:
========================================
Scanning USB mass storage for files...
----------------------------------------
No blocked files found on G:
----------------------------------------
No aut[b][/b]orun.inf files found on G:
No mountpoint found for 3e1458f1-8e0f-11e1-aec4-0025224db3dc
----------------------------------------
No Desktop.ini files found on G:
----------------------------------------
No mimics found on drive G:
----------------------------------------
No .lnk/.pif/.com/.scr files found on drive G:
========================================
 

 

(̅_̅_̅(̲̲̲̲̲̅̅̅̅̅̅(̅_̅_̲̅м̲̅a̲̅я̲̅l̲̅b̲̅o̲̅r̲̅o̲̅̅ _̅_̅_̅()
15 godina
offline
Igre se crashaju / Virus ?

nisi dobro uradio, combofix je pokrenut odavde

 

  c:\users\Matej\Downloads\ComboFix.exe

 

  a ovako bi trebalo biti

 

c:\users\Matej\Desktop\ComboFix.exe

 

  prebaci combofix iz Downloads na Desktop /radna površina (copy/paste)

 

nakon toga skini CFScript i spremi na desktop

 

isključi obavezno malwarebtes realtime zaštitu

isključi antivirus relatime zaštitu

 

skriptu s mišem uvuci u combofix.exe

 

pogledaj sliku:

 

  http://www.zaslike.com/viewer.php?file=xtsqjolxymnrz1np0vd.gif

 

 

pokreni malwarebytes >update>označi da skenira D:/ disk

log kopiraj

 

 

  File lock detected (PID, locking process, locked file):
0x0A48 mbamgui.exe C:\aut[b][/b]orun.inf
0x0A48 mbamgui.exe C:\aut[b][/b]orun.inf
0x0A48 mbamgui.exe C:\aut[b][/b]orun.inf
0x0A48 mbamgui.exe C:\aut[b][/b]orun.inf
0x0A48 mbamgui.exe C:\aut[b][/b]orun.inf
Error renaming file C:\aut[b][/b]orun.inf

 

 

Poruka je uređivana zadnji put uto 24.4.2012 16:15 (total).
 
0 0 hvala 1
15 godina
offline
Re: Igre se crashaju / Virus ?

evo sad tako napravljeno

ComboFix 12-04-24.02 - Matej 4.04.2012.  20:15:33.3.4 - x64

Microsoft Windows 7 Ultimate   6.1.7601.1.1250.385.1033.18.4095.3276 [GMT 2:00]

Running from: c:\users\Matej\Desktop\ComboFix.exe

Command switches used :: c:\users\Matej\Desktop\CFSCript.txt

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

FILE ::

"C:\bxubf.exe"

"c:\users\matej\appdata\local\temp\fqhjtf.exe"

"c:\users\matej\appdata\local\temp\winaxnmu.exe"

"c:\users\matej\appdata\local\temp\winfhbchg.exe"

"c:\users\matej\appdata\local\temp\wingjygin.exe"

"c:\users\matej\appdata\local\temp\winhcvrlg.exe"

"c:\users\matej\appdata\local\temp\ymmxna.exe"

.

.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

C:\autorun.inf

c:\windows\wstwf.log

D:\Autorun.inf

.

.

(((((((((((((((((((((((((   Files Created from 2012-03-24 to 2012-04-24  )))))))))))))))))))))))))))))))

.

.

2012-04-24 18:18 . 2012-04-24 18:18 -------- d-----w- c:\users\Default\AppData\Local\temp

2012-04-24 13:17 . 2012-04-24 13:22 -------- d-----w- C:\USBNoRisk

2012-04-24 13:14 . 2012-04-24 13:14 99328 --sh--r- C:\mdpaqv.exe

2012-04-23 19:28 . 2012-04-23 19:28 -------- d-----w- c:\program files (x86)\VirtualDJ

2012-04-23 18:22 . 2012-04-23 18:22 -------- d-----w- C:\_OTS

2012-04-23 14:55 . 2012-04-23 14:55 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2012-04-23 14:55 . 2012-04-23 14:55 -------- d-----w- c:\programdata\Malwarebytes

2012-04-23 14:55 . 2012-04-04 13:56 24904 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-04-23 13:37 . 2012-04-23 13:37 162664 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10140.bin

2012-04-23 00:17 . 2012-04-22 14:25 -------- d-----w- c:\windows\Panther

2012-04-22 18:57 . 2012-04-22 18:57 -------- d-----w- c:\program files\TeamSpeak 3 Client

2012-04-22 16:46 . 2012-04-24 11:11 271200 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr

2012-04-22 15:39 . 2012-04-22 15:39 -------- d-----w- c:\program files (x86)\MSECache

2012-04-22 15:23 . 2012-04-22 15:24 -------- d-----w- c:\programdata\Xfire

2012-04-22 15:23 . 2012-04-22 15:23 -------- d-----w- c:\program files (x86)\Xfire

2012-04-22 15:13 . 2012-04-24 11:11 271200 ----a-w- c:\windows\SysWow64\PnkBstrB.exe

2012-04-22 15:13 . 2012-04-24 11:10 103736 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0

2012-04-22 15:13 . 2012-04-24 06:41 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe

2012-04-22 15:10 . 2012-04-22 15:10 -------- d-----w- c:\program files (x86)\Activision

2012-04-22 14:44 . 2012-04-22 14:44 -------- d-----w- c:\windows\SysWow64\Wat

2012-04-22 14:44 . 2012-04-22 14:44 -------- d-----w- c:\windows\system32\Wat

2012-04-22 14:39 . 2012-04-22 14:39 -------- d-----w- c:\program files (x86)\Common Files\LogiShrd

2012-04-22 14:39 . 2012-04-22 14:39 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys

2012-04-22 14:39 . 2012-04-22 14:39 -------- d-----w- c:\programdata\Logishrd

2012-04-22 14:39 . 2012-04-22 14:39 -------- d-----w- c:\program files\Logitech

2012-04-22 14:38 . 2012-04-22 14:39 -------- d-----w- c:\program files\Common Files\Logishrd

2012-04-22 14:33 . 2012-04-22 14:33 -------- d-----w- c:\programdata\ATI

2012-04-22 14:31 . 2012-04-23 19:12 -------- d-----w- c:\program files (x86)\InstallShield Installation Information

2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files (x86)\AMD AVT

2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files\AMD

2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files (x86)\AMD

2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files (x86)\AMD APP

2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files\Common Files\ATI Technologies

2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files (x86)\Common Files\ATI Technologies

2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\programdata\AMD

2012-04-22 14:28 . 2010-02-18 07:18 46136 ----a-w- c:\windows\system32\drivers\amdiox64.sys

2012-04-22 14:27 . 2012-04-22 14:27 -------- d-----w- c:\program files (x86)\ATI Technologies

2012-04-22 14:27 . 2012-04-23 19:28 -------- d-sh--w- c:\windows\Installer

2012-04-22 14:27 . 2012-04-22 14:28 -------- d-----w- c:\program files\ATI Technologies

2012-04-22 14:27 . 2012-04-22 14:27 -------- d-----w- c:\program files\ATI

2012-04-22 14:26 . 2012-04-22 14:26 -------- d-----w- C:\AMD

2012-04-22 14:25 . 2012-04-22 14:25 -------- d-----w- c:\users\Matej

2012-04-22 14:25 . 2012-04-22 14:25 -------- d-----w- C:\Recovery

2012-04-22 14:20 . 2012-04-22 14:20 0 ----a-w- c:\windows\ativpsrm.bin

2012-04-17 05:31 . 2012-04-17 05:31 42392 ----a-w- c:\windows\SysWow64\xfcodec.dll

2012-04-17 05:31 . 2012-04-17 05:31 28056 ----a-w- c:\windows\system32\xfcodec64.dll

.

.

.

((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-04-22 14:44 . 2010-11-21 03:24 14848 ----a-w- c:\windows\system32\slwga.dll

2012-04-22 14:44 . 2010-11-21 03:24 419840 ----a-w- c:\windows\system32\systemcpl.dll

2012-04-22 14:44 . 2010-11-21 03:23 13824 ----a-w- c:\windows\SysWow64\slwga.dll

2012-04-22 14:44 . 2010-11-21 03:24 833024 ----a-w- c:\windows\SysWow64\user32.dll

2012-04-22 14:44 . 2010-11-21 03:24 1008640 ----a-w- c:\windows\system32\user32.dll

2012-02-15 03:48 . 2012-02-15 03:48 10856960 ----a-w- c:\windows\system32\drivers\atikmdag.sys

2012-02-15 03:21 . 2012-02-15 03:21 25839104 ----a-w- c:\windows\system32\atio6axx.dll

2012-02-15 03:18 . 2012-02-15 03:18 159744 ----a-w- c:\windows\system32\atiapfxx.exe

2012-02-15 03:18 . 2012-02-15 03:18 791040 ----a-w- c:\windows\SysWow64\aticfx32.dll

2012-02-15 03:17 . 2012-02-15 03:17 957952 ----a-w- c:\windows\system32\aticfx64.dll

2012-02-15 03:13 . 2012-02-15 03:13 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll

2012-02-15 03:13 . 2012-02-15 03:13 496128 ----a-w- c:\windows\system32\atieclxx.exe

2012-02-15 03:13 . 2012-02-15 03:13 235520 ----a-w- c:\windows\system32\atiesrxx.exe

2012-02-15 03:11 . 2012-02-15 03:11 120320 ----a-w- c:\windows\system32\atitmm64.dll

2012-02-15 03:10 . 2012-02-15 03:10 21504 ----a-w- c:\windows\system32\atimuixx.dll

2012-02-15 03:10 . 2012-02-15 03:10 59392 ----a-w- c:\windows\system32\atiedu64.dll

2012-02-15 03:10 . 2012-02-15 03:10 43520 ----a-w- c:\windows\SysWow64\ati2edxx.dll

2012-02-15 03:07 . 2012-02-15 03:07 6200320 ----a-w- c:\windows\SysWow64\atidxx32.dll

2012-02-15 02:58 . 2012-02-15 02:58 19392000 ----a-w- c:\windows\SysWow64\atioglxx.dll

2012-02-15 02:52 . 2009-07-13 21:59 7646208 ----a-w- c:\windows\system32\atidxx64.dll

2012-02-15 02:41 . 2012-02-15 02:41 1113088 ----a-w- c:\windows\system32\atiumd6v.dll

2012-02-15 02:40 . 2012-02-15 02:40 1828864 ----a-w- c:\windows\SysWow64\atiumdmv.dll

2012-02-15 02:40 . 2012-02-15 02:40 4958208 ----a-w- c:\windows\system32\atiumd6a.dll

2012-02-15 02:34 . 2012-02-15 02:34 51200 ----a-w- c:\windows\system32\aticalrt64.dll

2012-02-15 02:34 . 2012-02-15 02:34 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll

2012-02-15 02:34 . 2012-02-15 02:34 44544 ----a-w- c:\windows\system32\aticalcl64.dll

2012-02-15 02:34 . 2012-02-15 02:34 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll

2012-02-15 02:34 . 2012-02-15 02:34 5954048 ----a-w- c:\windows\SysWow64\atiumdag.dll

2012-02-15 02:34 . 2012-02-15 02:34 13859840 ----a-w- c:\windows\system32\aticaldd64.dll

2012-02-15 02:29 . 2012-02-15 02:29 5062656 ----a-w- c:\windows\SysWow64\atiumdva.dll

2012-02-15 02:29 . 2012-02-15 02:29 11561984 ----a-w- c:\windows\SysWow64\aticaldd.dll

2012-02-15 02:25 . 2012-02-15 02:25 7551488 ----a-w- c:\windows\system32\atiumd64.dll

2012-02-15 02:16 . 2012-02-15 02:16 58880 ----a-w- c:\windows\system32\coinst.dll

2012-02-15 02:14 . 2012-02-15 02:14 512000 ----a-w- c:\windows\system32\atiadlxx.dll

2012-02-15 02:13 . 2012-02-15 02:13 356352 ----a-w- c:\windows\SysWow64\atiadlxy.dll

2012-02-15 02:13 . 2012-02-15 02:13 17408 ----a-w- c:\windows\system32\atig6pxx.dll

2012-02-15 02:13 . 2012-02-15 02:13 14336 ----a-w- c:\windows\SysWow64\atiglpxx.dll

2012-02-15 02:13 . 2012-02-15 02:13 14336 ----a-w- c:\windows\system32\atiglpxx.dll

2012-02-15 02:13 . 2012-02-15 02:13 39936 ----a-w- c:\windows\system32\atig6txx.dll

2012-02-15 02:13 . 2012-02-15 02:13 33280 ----a-w- c:\windows\SysWow64\atigktxx.dll

2012-02-15 02:13 . 2012-02-15 02:13 327680 ----a-w- c:\windows\system32\drivers\atikmpag.sys

2012-02-15 02:12 . 2012-02-15 02:12 43008 ----a-w- c:\windows\system32\atiuxp64.dll

2012-02-15 02:12 . 2012-02-15 02:12 33280 ----a-w- c:\windows\SysWow64\atiuxpag.dll

2012-02-15 02:12 . 2012-02-15 02:12 39936 ----a-w- c:\windows\system32\atiu9p64.dll

2012-02-15 02:12 . 2012-02-15 02:12 30208 ----a-w- c:\windows\SysWow64\atiu9pag.dll

2012-02-15 02:11 . 2012-02-15 02:11 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll

2012-02-15 02:11 . 2012-02-15 02:11 54784 ----a-w- c:\windows\system32\atimpc64.dll

2012-02-15 02:11 . 2012-02-15 02:11 54784 ----a-w- c:\windows\system32\amdpcom64.dll

2012-02-15 02:11 . 2012-02-15 02:11 53760 ----a-w- c:\windows\SysWow64\atimpc32.dll

2012-02-15 02:11 . 2012-02-15 02:11 53760 ----a-w- c:\windows\SysWow64\amdpcom32.dll

2012-02-14 20:05 . 2012-02-14 20:05 69632 ----a-w- c:\windows\system32\OpenVideo64.dll

2012-02-14 20:05 . 2012-02-14 20:05 59904 ----a-w- c:\windows\SysWow64\OpenVideo.dll

2012-02-14 20:05 . 2012-02-14 20:05 61952 ----a-w- c:\windows\system32\OVDecode64.dll

2012-02-14 20:05 . 2012-02-14 20:05 54784 ----a-w- c:\windows\SysWow64\OVDecode.dll

2012-02-14 20:05 . 2012-02-14 20:05 16507904 ----a-w- c:\windows\system32\amdocl64.dll

2012-02-14 20:04 . 2012-02-14 20:04 13238272 ----a-w- c:\windows\SysWow64\amdocl.dll

2012-02-14 20:03 . 2012-02-14 20:03 54272 ----a-w- c:\windows\system32\OpenCL.dll

2012-02-14 20:03 . 2012-02-14 20:03 48128 ----a-w- c:\windows\SysWow64\OpenCL.dll

2012-01-31 04:02 . 2012-01-31 04:02 21504 ----a-w- c:\windows\system32\kdbsdk64.dll

2012-01-31 04:00 . 2012-01-31 04:00 16896 ----a-w- c:\windows\SysWow64\kdbsdk32.dll

.

.

((((((((((((((((((((((((((((((((((((((((((((   Look   )))))))))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

--- c:\windows\system32\user32.dll ---

Company: Microsoft Corporation

File Description: Multi-User Windows USER API Client DLL

File Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850)

Product Name: Microsoft® Windows® Operating System

Copyright: © Microsoft Corporation. All rights reserved.

Original Filename: user32

File size: 1008640

Created time: 2010-11-21 03:24

Modified time: 2012-04-22 14:44

MD5: 2C353B6CE0C8D03225CAA2AF33B68D79

SHA1: 785D332F0239071EABF74F1D1E2106F78B99A42A

.

.

------- Sigcheck -------

Note: Unsigned files aren't necessarily malware.

.

[7] 2010-11-21 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll

[-] 2012-04-22 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7601.17514] .. c:\windows\system32\user32.dll

.

[-] 2012-04-22 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7601.17514] .. c:\windows\SysWOW64\user32.dll

[7] 2010-11-21 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll

.

(((((((((((((((((((((((((((((   SnapShot_2012-04-24_13.13.48   )))))))))))))))))))))))))))))))))))))))))

.

+ 2010-11-21 03:09 . 2012-04-24 18:15 12412        c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin

+ 2009-07-14 05:10 . 2012-04-24 18:15 29386        c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin

- 2009-07-14 05:30 . 2012-04-22 19:26 86016        c:\windows\system32\DriverStore\infpub.dat

+ 2009-07-14 05:30 . 2012-04-24 13:17 86016        c:\windows\system32\DriverStore\infpub.dat

+ 2012-04-22 17:11 . 2012-04-24 15:11 16384        c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2012-04-22 17:11 . 2012-04-24 13:04 16384        c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2012-04-22 17:11 . 2012-04-24 15:11 16384        c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2012-04-22 17:11 . 2012-04-24 13:04 16384        c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2012-04-22 14:47 . 2012-04-24 18:15 2978        c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3530914189-2052248754-1505902800-1000_UserData.bin

+ 2012-04-24 18:18 . 2012-04-24 18:18 2048        c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

- 2012-04-24 13:13 . 2012-04-24 13:13 2048        c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

+ 2012-04-24 18:18 . 2012-04-24 18:18 2048        c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

- 2012-04-24 13:13 . 2012-04-24 13:13 2048        c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

- 2009-07-14 05:30 . 2012-04-22 19:26 143360        c:\windows\system32\DriverStore\infstrng.dat

+ 2009-07-14 05:30 . 2012-04-24 13:17 143360        c:\windows\system32\DriverStore\infstrng.dat

+ 2009-07-14 00:21 . 2009-07-14 01:41 299520        c:\windows\system32\drivers\UMDF\WpdFs.dll

- 2009-07-14 05:01 . 2012-04-24 13:13 227464        c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

+ 2009-07-14 05:01 . 2012-04-24 18:18 227464        c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown 

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Facebook Update"="c:\users\Matej\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-04-22 203072]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-02-14 705664]

"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2009-09-21 2583040]

"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 536136]

.

c:\users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Logitech . Registracija proizvoda.lnk - c:\program files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe [2009-11-16 587016]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

AML Device Install.lnk - c:\program files (x86)\AMD AVT\bin\kdbsync.exe [2012-1-31 80384]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]

"aux"=wdmaud.drv

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusOverride"=dword:00000001

"AntiVirusDisableNotify"=dword:00000001

"FirewallDisableNotify"=dword:00000001

"FirewallOverride"=dword:00000001

"UpdatesDisableNotify"=dword:00000001

"UacDisableNotify"=dword:00000001

.

R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]

R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [x]

R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]

R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]

R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]

R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [x]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]

R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]

R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]

R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]

S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]

S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-02-14 361984]

S2 AODDriver4.1;AODDriver4.1;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-01-03 55936]

S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [x]

S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]

S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]

S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]

S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]

S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [x]

.

.

Contents of the 'Scheduled Tasks' folder

.

2012-04-24 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000Core.job

- c:\users\Matej\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-22 14:38]

.

2012-04-24 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000UA.job

- c:\users\Matej\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-22 14:38]

.

2012-04-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000Core.job

- c:\users\Matej\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-22 14:31]

.

2012-04-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000UA.job

- c:\users\Matej\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-22 14:31]

.

.

--------- x86-64 -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-10-07 1744152]

.

------- Supplementary Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

mLocal Page = c:\windows\SysWOW64\blank.htm

TCP: Interfaces\{E9CECB3F-8087-43C5-BD75-791E5EFE03C0}: NameServer = 8.8.8.8,4.4.8.8

.

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

------------------------ Other Running Processes ------------------------

.

c:\windows\SysWOW64\PnkBstrA.exe

c:\program files\Common Files\LogiShrd\sp6\LU\LULnchr.exe

.

**************************************************************************

.

Completion time: 2012-04-24  20:20:42 - machine was rebooted

ComboFix-quarantined-files.txt  2012-04-24 18:20

ComboFix2.txt  2012-04-24 13:15

ComboFix3.txt  2012-04-23 18:42

.

Pre-Run: 154.722.742.272 bytes free

Post-Run: 154.633.109.504 bytes free

.

- - End Of File - - E9142ECE3C8901A3C0BDF1197A4C8506

(̅_̅_̅(̲̲̲̲̲̅̅̅̅̅̅(̅_̅_̲̅м̲̅a̲̅я̲̅l̲̅b̲̅o̲̅r̲̅o̲̅̅ _̅_̅_̅()
15 godina
offline
Igre se crashaju / Virus ?

sad je već puno bolje, ostao je još samo jedan kojeg ćemo sad izbrisati

 

otvori notepad i ovo kopiraj u notepad

 

  File::
C:\mdpaqv.exe

 

  zatvori notepad i spremi kao CFScript na desktop

-isključi malwarebytes i antivirus

-skriptu s mišem uvuci u cmbofix.exe

-log kopiraj

 

2.ponovo pokreni usbnorisk i sačekaj desetak sekundi

-klik na tab script i ovo kopiraj u prazno polje

 

{0a59a926-8c86-11e1-86b4-806e6f6e6963}
folder_list:%DRIVE%
no_sh:

 

  klik na run script

kad se skripta izvrši, desni klik mišem na sredprozora i odaberi save scrambled log

log kopiraj

 

 

jesi li pokrenio malwarebytes scan D:/ diska ?

 
0 0 hvala 1
15 godina
offline
Re: Igre se crashaju / Virus ?

Nisam skenirao D disk .. Nakon ovoga cu to provjeriti

(̅_̅_̅(̲̲̲̲̲̅̅̅̅̅̅(̅_̅_̲̅м̲̅a̲̅я̲̅l̲̅b̲̅o̲̅r̲̅o̲̅̅ _̅_̅_̅()
15 godina
offline
Re: Igre se crashaju / Virus ?
AmD kaže...

Nisam skenirao D disk .. Nakon ovoga cu to provjeriti

  nakon ovog koraka trebalo bi biti sve ok...imaš li i dalje konekcije na net nepoznatih programa ?

ja mislim da nemaš više :)

 

 

15 godina
offline
Re: Igre se crashaju / Virus ?

Nije ih bilo , samo moram reinstalirat sve igre ..

 

EDIT: Evo onaj zadnji s combofixom 

 

 

ComboFix 12-04-25.01 - Matej 5.04.2012.  18:00:37.4.4 - x64

Microsoft Windows 7 Ultimate   6.1.7601.1.1250.385.1033.18.4095.2841 [GMT 2:00]

Running from: c:\users\Matej\Desktop\ComboFix.exe

Command switches used :: c:\users\Matej\Desktop\CFScript.txt

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

FILE ::

"C:\mdpaqv.exe"

.

.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

C:\autorun.inf

C:\mdpaqv.exe

c:\windows\wstwf.log

D:\Autorun.inf

D:\ilft.pif

.

.

(((((((((((((((((((((((((   Files Created from 2012-03-25 to 2012-04-25  )))))))))))))))))))))))))))))))

.

.

2012-04-25 16:03 . 2012-04-25 16:03 -------- d-----w- c:\users\Default\AppData\Local\temp

2012-04-24 18:19 . 2012-04-24 18:19 99328 --sh--r- C:\esops.exe

2012-04-24 13:17 . 2012-04-24 13:22 -------- d-----w- C:\USBNoRisk

2012-04-23 19:28 . 2012-04-23 19:28 -------- d-----w- c:\program files (x86)\VirtualDJ

2012-04-23 18:22 . 2012-04-23 18:22 -------- d-----w- C:\_OTS

2012-04-23 14:55 . 2012-04-23 14:55 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2012-04-23 14:55 . 2012-04-23 14:55 -------- d-----w- c:\programdata\Malwarebytes

2012-04-23 14:55 . 2012-04-04 13:56 24904 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-04-23 13:37 . 2012-04-23 13:37 162664 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10140.bin

2012-04-23 00:17 . 2012-04-22 14:25 -------- d-----w- c:\windows\Panther

2012-04-22 18:57 . 2012-04-22 18:57 -------- d-----w- c:\program files\TeamSpeak 3 Client

2012-04-22 16:46 . 2012-04-24 11:11 271200 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr

2012-04-22 15:39 . 2012-04-22 15:39 -------- d-----w- c:\program files (x86)\MSECache

2012-04-22 15:23 . 2012-04-22 15:24 -------- d-----w- c:\programdata\Xfire

2012-04-22 15:23 . 2012-04-22 15:23 -------- d-----w- c:\program files (x86)\Xfire

2012-04-22 15:13 . 2012-04-24 11:11 271200 ----a-w- c:\windows\SysWow64\PnkBstrB.exe

2012-04-22 15:13 . 2012-04-24 11:10 103736 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0

2012-04-22 15:13 . 2012-04-24 06:41 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe

2012-04-22 15:10 . 2012-04-22 15:10 -------- d-----w- c:\program files (x86)\Activision

2012-04-22 14:44 . 2012-04-22 14:44 -------- d-----w- c:\windows\SysWow64\Wat

2012-04-22 14:44 . 2012-04-22 14:44 -------- d-----w- c:\windows\system32\Wat

2012-04-22 14:39 . 2012-04-22 14:39 -------- d-----w- c:\program files (x86)\Common Files\LogiShrd

2012-04-22 14:39 . 2012-04-22 14:39 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys

2012-04-22 14:39 . 2012-04-22 14:39 -------- d-----w- c:\programdata\Logishrd

2012-04-22 14:39 . 2012-04-22 14:39 -------- d-----w- c:\program files\Logitech

2012-04-22 14:38 . 2012-04-22 14:39 -------- d-----w- c:\program files\Common Files\Logishrd

2012-04-22 14:33 . 2012-04-22 14:33 -------- d-----w- c:\programdata\ATI

2012-04-22 14:31 . 2012-04-23 19:12 -------- d-----w- c:\program files (x86)\InstallShield Installation Information

2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files (x86)\AMD AVT

2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files\AMD

2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files (x86)\AMD

2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files (x86)\AMD APP

2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files\Common Files\ATI Technologies

2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files (x86)\Common Files\ATI Technologies

2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\programdata\AMD

2012-04-22 14:28 . 2010-02-18 07:18 46136 ----a-w- c:\windows\system32\drivers\amdiox64.sys

2012-04-22 14:27 . 2012-04-22 14:27 -------- d-----w- c:\program files (x86)\ATI Technologies

2012-04-22 14:27 . 2012-04-23 19:28 -------- d-sh--w- c:\windows\Installer

2012-04-22 14:27 . 2012-04-22 14:28 -------- d-----w- c:\program files\ATI Technologies

2012-04-22 14:27 . 2012-04-22 14:27 -------- d-----w- c:\program files\ATI

2012-04-22 14:26 . 2012-04-22 14:26 -------- d-----w- C:\AMD

2012-04-22 14:25 . 2012-04-22 14:25 -------- d-----w- c:\users\Matej

2012-04-22 14:25 . 2012-04-22 14:25 -------- d-----w- C:\Recovery

2012-04-22 14:20 . 2012-04-22 14:20 0 ----a-w- c:\windows\ativpsrm.bin

2012-04-17 05:31 . 2012-04-17 05:31 42392 ----a-w- c:\windows\SysWow64\xfcodec.dll

2012-04-17 05:31 . 2012-04-17 05:31 28056 ----a-w- c:\windows\system32\xfcodec64.dll

.

.

.

((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-04-22 14:44 . 2010-11-21 03:24 14848 ----a-w- c:\windows\system32\slwga.dll

2012-04-22 14:44 . 2010-11-21 03:24 419840 ----a-w- c:\windows\system32\systemcpl.dll

2012-04-22 14:44 . 2010-11-21 03:23 13824 ----a-w- c:\windows\SysWow64\slwga.dll

2012-04-22 14:44 . 2010-11-21 03:24 833024 ----a-w- c:\windows\SysWow64\user32.dll

2012-04-22 14:44 . 2010-11-21 03:24 1008640 ----a-w- c:\windows\system32\user32.dll

2012-02-15 03:48 . 2012-02-15 03:48 10856960 ----a-w- c:\windows\system32\drivers\atikmdag.sys

2012-02-15 03:21 . 2012-02-15 03:21 25839104 ----a-w- c:\windows\system32\atio6axx.dll

2012-02-15 03:18 . 2012-02-15 03:18 159744 ----a-w- c:\windows\system32\atiapfxx.exe

2012-02-15 03:18 . 2012-02-15 03:18 791040 ----a-w- c:\windows\SysWow64\aticfx32.dll

2012-02-15 03:17 . 2012-02-15 03:17 957952 ----a-w- c:\windows\system32\aticfx64.dll

2012-02-15 03:13 . 2012-02-15 03:13 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll

2012-02-15 03:13 . 2012-02-15 03:13 496128 ----a-w- c:\windows\system32\atieclxx.exe

2012-02-15 03:13 . 2012-02-15 03:13 235520 ----a-w- c:\windows\system32\atiesrxx.exe

2012-02-15 03:11 . 2012-02-15 03:11 120320 ----a-w- c:\windows\system32\atitmm64.dll

2012-02-15 03:10 . 2012-02-15 03:10 21504 ----a-w- c:\windows\system32\atimuixx.dll

2012-02-15 03:10 . 2012-02-15 03:10 59392 ----a-w- c:\windows\system32\atiedu64.dll

2012-02-15 03:10 . 2012-02-15 03:10 43520 ----a-w- c:\windows\SysWow64\ati2edxx.dll

2012-02-15 03:07 . 2012-02-15 03:07 6200320 ----a-w- c:\windows\SysWow64\atidxx32.dll

2012-02-15 02:58 . 2012-02-15 02:58 19392000 ----a-w- c:\windows\SysWow64\atioglxx.dll

2012-02-15 02:52 . 2009-07-13 21:59 7646208 ----a-w- c:\windows\system32\atidxx64.dll

2012-02-15 02:41 . 2012-02-15 02:41 1113088 ----a-w- c:\windows\system32\atiumd6v.dll

2012-02-15 02:40 . 2012-02-15 02:40 1828864 ----a-w- c:\windows\SysWow64\atiumdmv.dll

2012-02-15 02:40 . 2012-02-15 02:40 4958208 ----a-w- c:\windows\system32\atiumd6a.dll

2012-02-15 02:34 . 2012-02-15 02:34 51200 ----a-w- c:\windows\system32\aticalrt64.dll

2012-02-15 02:34 . 2012-02-15 02:34 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll

2012-02-15 02:34 . 2012-02-15 02:34 44544 ----a-w- c:\windows\system32\aticalcl64.dll

2012-02-15 02:34 . 2012-02-15 02:34 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll

2012-02-15 02:34 . 2012-02-15 02:34 5954048 ----a-w- c:\windows\SysWow64\atiumdag.dll

2012-02-15 02:34 . 2012-02-15 02:34 13859840 ----a-w- c:\windows\system32\aticaldd64.dll

2012-02-15 02:29 . 2012-02-15 02:29 5062656 ----a-w- c:\windows\SysWow64\atiumdva.dll

2012-02-15 02:29 . 2012-02-15 02:29 11561984 ----a-w- c:\windows\SysWow64\aticaldd.dll

2012-02-15 02:25 . 2012-02-15 02:25 7551488 ----a-w- c:\windows\system32\atiumd64.dll

2012-02-15 02:16 . 2012-02-15 02:16 58880 ----a-w- c:\windows\system32\coinst.dll

2012-02-15 02:14 . 2012-02-15 02:14 512000 ----a-w- c:\windows\system32\atiadlxx.dll

2012-02-15 02:13 . 2012-02-15 02:13 356352 ----a-w- c:\windows\SysWow64\atiadlxy.dll

2012-02-15 02:13 . 2012-02-15 02:13 17408 ----a-w- c:\windows\system32\atig6pxx.dll

2012-02-15 02:13 . 2012-02-15 02:13 14336 ----a-w- c:\windows\SysWow64\atiglpxx.dll

2012-02-15 02:13 . 2012-02-15 02:13 14336 ----a-w- c:\windows\system32\atiglpxx.dll

2012-02-15 02:13 . 2012-02-15 02:13 39936 ----a-w- c:\windows\system32\atig6txx.dll

2012-02-15 02:13 . 2012-02-15 02:13 33280 ----a-w- c:\windows\SysWow64\atigktxx.dll

2012-02-15 02:13 . 2012-02-15 02:13 327680 ----a-w- c:\windows\system32\drivers\atikmpag.sys

2012-02-15 02:12 . 2012-02-15 02:12 43008 ----a-w- c:\windows\system32\atiuxp64.dll

2012-02-15 02:12 . 2012-02-15 02:12 33280 ----a-w- c:\windows\SysWow64\atiuxpag.dll

2012-02-15 02:12 . 2012-02-15 02:12 39936 ----a-w- c:\windows\system32\atiu9p64.dll

2012-02-15 02:12 . 2012-02-15 02:12 30208 ----a-w- c:\windows\SysWow64\atiu9pag.dll

2012-02-15 02:11 . 2012-02-15 02:11 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll

2012-02-15 02:11 . 2012-02-15 02:11 54784 ----a-w- c:\windows\system32\atimpc64.dll

2012-02-15 02:11 . 2012-02-15 02:11 54784 ----a-w- c:\windows\system32\amdpcom64.dll

2012-02-15 02:11 . 2012-02-15 02:11 53760 ----a-w- c:\windows\SysWow64\atimpc32.dll

2012-02-15 02:11 . 2012-02-15 02:11 53760 ----a-w- c:\windows\SysWow64\amdpcom32.dll

2012-02-14 20:05 . 2012-02-14 20:05 69632 ----a-w- c:\windows\system32\OpenVideo64.dll

2012-02-14 20:05 . 2012-02-14 20:05 59904 ----a-w- c:\windows\SysWow64\OpenVideo.dll

2012-02-14 20:05 . 2012-02-14 20:05 61952 ----a-w- c:\windows\system32\OVDecode64.dll

2012-02-14 20:05 . 2012-02-14 20:05 54784 ----a-w- c:\windows\SysWow64\OVDecode.dll

2012-02-14 20:05 . 2012-02-14 20:05 16507904 ----a-w- c:\windows\system32\amdocl64.dll

2012-02-14 20:04 . 2012-02-14 20:04 13238272 ----a-w- c:\windows\SysWow64\amdocl.dll

2012-02-14 20:03 . 2012-02-14 20:03 54272 ----a-w- c:\windows\system32\OpenCL.dll

2012-02-14 20:03 . 2012-02-14 20:03 48128 ----a-w- c:\windows\SysWow64\OpenCL.dll

2012-01-31 04:02 . 2012-01-31 04:02 21504 ----a-w- c:\windows\system32\kdbsdk64.dll

2012-01-31 04:00 . 2012-01-31 04:00 16896 ----a-w- c:\windows\SysWow64\kdbsdk32.dll

.

.

------- Sigcheck -------

Note: Unsigned files aren't necessarily malware.

.

[7] 2010-11-21 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll

[-] 2012-04-22 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7601.17514] .. c:\windows\system32\user32.dll

.

[-] 2012-04-22 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7601.17514] .. c:\windows\SysWOW64\user32.dll

[7] 2010-11-21 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll

.

(((((((((((((((((((((((((((((   SnapShot_2012-04-24_13.13.48   )))))))))))))))))))))))))))))))))))))))))

.

+ 2012-04-24 18:44 . 2010-06-02 02:55 74072        c:\windows\SysWOW64\XAPOFX1_5.dll

+ 2012-04-24 18:44 . 2010-02-04 08:01 74072        c:\windows\SysWOW64\XAPOFX1_4.dll

+ 2012-04-24 18:44 . 2009-09-04 15:44 69464        c:\windows\SysWOW64\XAPOFX1_3.dll

+ 2012-04-24 18:44 . 2008-10-27 08:04 70992        c:\windows\SysWOW64\XAPOFX1_2.dll

+ 2012-04-24 18:44 . 2008-07-31 08:41 68616        c:\windows\SysWOW64\XAPOFX1_1.dll

+ 2012-04-24 18:44 . 2008-05-30 12:17 65032        c:\windows\SysWOW64\XAPOFX1_0.dll

+ 2012-04-24 18:44 . 2010-02-04 08:01 22360        c:\windows\SysWOW64\X3DAudio1_7.dll

+ 2012-04-24 18:44 . 2009-03-16 12:18 22360        c:\windows\SysWOW64\X3DAudio1_6.dll

+ 2012-04-24 18:44 . 2008-10-27 08:04 23376        c:\windows\SysWOW64\X3DAudio1_5.dll

+ 2012-04-24 18:44 . 2008-05-30 12:17 25608        c:\windows\SysWOW64\X3DAudio1_4.dll

+ 2012-04-24 18:44 . 2008-03-05 14:00 25608        c:\windows\SysWOW64\X3DAudio1_3.dll

+ 2012-04-24 18:44 . 2007-10-22 01:37 17928        c:\windows\SysWOW64\X3DAudio1_2.dll

+ 2012-04-24 18:44 . 2010-06-02 02:55 77656        c:\windows\system32\XAPOFX1_5.dll

+ 2012-04-24 18:44 . 2010-02-04 08:01 78680        c:\windows\system32\XAPOFX1_4.dll

+ 2012-04-24 18:44 . 2009-09-04 15:44 73544        c:\windows\system32\XAPOFX1_3.dll

+ 2012-04-24 18:44 . 2008-10-27 08:04 74576        c:\windows\system32\XAPOFX1_2.dll

+ 2012-04-24 18:44 . 2008-07-31 08:41 72200        c:\windows\system32\XAPOFX1_1.dll

+ 2012-04-24 18:44 . 2008-05-30 12:17 68104        c:\windows\system32\XAPOFX1_0.dll

+ 2012-04-24 18:44 . 2010-02-04 08:01 24920        c:\windows\system32\X3DAudio1_7.dll

+ 2012-04-24 18:44 . 2009-03-16 12:18 24920        c:\windows\system32\X3DAudio1_6.dll

+ 2012-04-24 18:44 . 2008-10-27 08:04 25936        c:\windows\system32\X3DAudio1_5.dll

+ 2012-04-24 18:44 . 2008-05-30 12:16 28168        c:\windows\system32\X3DAudio1_4.dll

+ 2012-04-24 18:44 . 2008-03-05 14:00 28168        c:\windows\system32\X3DAudio1_3.dll

+ 2012-04-24 18:44 . 2007-10-22 01:37 21000        c:\windows\system32\X3DAudio1_2.dll

+ 2010-11-21 03:09 . 2012-04-24 18:20 13642        c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin

+ 2009-07-14 05:10 . 2012-04-24 18:20 29746        c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin

+ 2009-07-14 05:30 . 2012-04-24 13:17 86016        c:\windows\system32\DriverStore\infpub.dat

- 2009-07-14 05:30 . 2012-04-22 19:26 86016        c:\windows\system32\DriverStore\infpub.dat

- 2012-04-22 17:11 . 2012-04-24 13:04 16384        c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2012-04-22 17:11 . 2012-04-25 15:02 16384        c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2012-04-22 17:11 . 2012-04-25 15:02 16384        c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2012-04-22 17:11 . 2012-04-24 13:04 16384        c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2012-04-24 18:44 . 2012-04-24 18:44 12800        c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll

- 2012-04-23 19:13 . 2012-04-23 19:13 12800        c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll

- 2012-04-23 19:13 . 2012-04-23 19:13 53248        c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll

+ 2012-04-24 18:44 . 2012-04-24 18:44 53248        c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll

+ 2012-04-22 14:47 . 2012-04-24 18:20 3082        c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3530914189-2052248754-1505902800-1000_UserData.bin

- 2012-04-24 13:13 . 2012-04-24 13:13 2048        c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

+ 2012-04-25 16:03 . 2012-04-25 16:03 2048        c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

+ 2012-04-24 18:44 . 2010-06-02 02:55 527192        c:\windows\SysWOW64\XAudio2_7.dll

+ 2012-04-24 18:44 . 2010-02-04 08:01 528216        c:\windows\SysWOW64\XAudio2_6.dll

+ 2012-04-24 18:44 . 2009-09-04 15:44 515416        c:\windows\SysWOW64\XAudio2_5.dll

+ 2012-04-24 18:44 . 2009-03-16 12:18 517448        c:\windows\SysWOW64\XAudio2_4.dll

+ 2012-04-24 18:44 . 2008-10-27 08:04 514384        c:\windows\SysWOW64\XAudio2_3.dll

+ 2012-04-24 18:44 . 2008-07-31 08:40 509448        c:\windows\SysWOW64\XAudio2_2.dll

+ 2012-04-24 18:44 . 2008-05-30 12:19 507400        c:\windows\SysWOW64\XAudio2_1.dll

+ 2012-04-24 18:44 . 2008-03-05 14:03 479752        c:\windows\SysWOW64\XAudio2_0.dll

+ 2012-04-24 18:44 . 2010-06-02 02:55 239960        c:\windows\SysWOW64\xactengine3_7.dll

+ 2012-04-24 18:44 . 2010-02-04 08:01 238936        c:\windows\SysWOW64\xactengine3_6.dll

+ 2012-04-24 18:44 . 2009-09-04 15:44 238936        c:\windows\SysWOW64\xactengine3_5.dll

+ 2012-04-24 18:44 . 2009-03-16 12:18 235352        c:\windows\SysWOW64\xactengine3_4.dll

+ 2012-04-24 18:44 . 2008-10-27 08:04 235856        c:\windows\SysWOW64\xactengine3_3.dll

+ 2012-04-24 18:44 . 2008-07-31 08:41 238088        c:\windows\SysWOW64\xactengine3_2.dll

+ 2012-04-24 18:44 . 2008-05-30 12:18 238088        c:\windows\SysWOW64\xactengine3_1.dll

+ 2012-04-24 18:44 . 2008-03-05 14:03 238088        c:\windows\SysWOW64\xactengine3_0.dll

+ 2012-04-24 18:44 . 2007-07-19 22:57 267112        c:\windows\SysWOW64\xactengine2_9.dll

- 2012-04-22 15:14 . 2007-05-31 17:30 266088        c:\windows\SysWOW64\xactengine2_8.dll

+ 2012-04-24 18:44 . 2007-06-20 18:46 266088        c:\windows\SysWOW64\xactengine2_8.dll

+ 2012-04-24 18:44 . 2007-10-22 01:39 267272        c:\windows\SysWOW64\xactengine2_10.dll

+ 2012-04-24 18:44 . 2010-05-26 09:41 248672        c:\windows\SysWOW64\d3dx11_43.dll

+ 2012-04-24 18:44 . 2009-09-04 15:29 235344        c:\windows\SysWOW64\d3dx11_42.dll

+ 2012-04-24 18:44 . 2010-05-26 09:41 470880        c:\windows\SysWOW64\d3dx10_43.dll

+ 2012-04-24 18:44 . 2009-09-04 15:29 453456        c:\windows\SysWOW64\d3dx10_42.dll

+ 2012-04-24 18:44 . 2009-03-09 13:27 453456        c:\windows\SysWOW64\d3dx10_41.dll

+ 2012-04-24 18:44 . 2008-10-15 04:22 452440        c:\windows\SysWOW64\d3dx10_40.dll

+ 2012-04-24 18:44 . 2008-07-10 09:01 467984        c:\windows\SysWOW64\d3dx10_39.dll

+ 2012-04-24 18:44 . 2008-05-30 12:11 467984        c:\windows\SysWOW64\d3dx10_38.dll

+ 2012-04-24 18:44 . 2008-02-05 21:07 462864        c:\windows\SysWOW64\d3dx10_37.dll

+ 2012-04-24 18:44 . 2007-10-02 07:56 444776        c:\windows\SysWOW64\d3dx10_36.dll

+ 2012-04-24 18:44 . 2007-07-19 16:14 444776        c:\windows\SysWOW64\d3dx10_35.dll

+ 2012-04-24 18:44 . 2010-06-02 02:55 518488        c:\windows\system32\XAudio2_7.dll

+ 2012-04-24 18:44 . 2010-02-04 08:01 530776        c:\windows\system32\XAudio2_6.dll

+ 2012-04-24 18:44 . 2009-09-04 15:44 517960        c:\windows\system32\XAudio2_5.dll

+ 2012-04-24 18:44 . 2009-03-16 12:18 521560        c:\windows\system32\XAudio2_4.dll

+ 2012-04-24 18:44 . 2008-10-27 08:04 518480        c:\windows\system32\XAudio2_3.dll

+ 2012-04-24 18:44 . 2008-07-31 08:40 513544        c:\windows\system32\XAudio2_2.dll

+ 2012-04-24 18:44 . 2008-05-30 12:19 511496        c:\windows\system32\XAudio2_1.dll

+ 2012-04-24 18:44 . 2008-03-05 14:04 489480        c:\windows\system32\XAudio2_0.dll

+ 2012-04-24 18:44 . 2010-06-02 02:55 176984        c:\windows\system32\xactengine3_7.dll

+ 2012-04-24 18:44 . 2010-02-04 08:01 176984        c:\windows\system32\xactengine3_6.dll

+ 2012-04-24 18:44 . 2009-09-04 15:44 176968        c:\windows\system32\xactengine3_5.dll

+ 2012-04-24 18:44 . 2009-03-16 12:18 174936        c:\windows\system32\xactengine3_4.dll

+ 2012-04-24 18:44 . 2008-10-27 08:04 175440        c:\windows\system32\xactengine3_3.dll

+ 2012-04-24 18:44 . 2008-07-31 08:41 177672        c:\windows\system32\xactengine3_2.dll

+ 2012-04-24 18:44 . 2008-05-30 12:18 177672        c:\windows\system32\xactengine3_1.dll

+ 2012-04-24 18:44 . 2008-03-05 14:03 177672        c:\windows\system32\xactengine3_0.dll

+ 2012-04-24 18:44 . 2007-07-19 22:57 411496        c:\windows\system32\xactengine2_9.dll

+ 2012-04-24 18:44 . 2007-06-20 18:49 409960        c:\windows\system32\xactengine2_8.dll

- 2012-04-22 15:14 . 2007-05-31 17:30 409960        c:\windows\system32\xactengine2_8.dll

+ 2012-04-24 18:44 . 2007-10-22 01:40 411656        c:\windows\system32\xactengine2_10.dll

+ 2012-04-22 21:00 . 2012-04-25 14:50 150118        c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin

+ 2009-07-14 05:30 . 2012-04-24 13:17 143360        c:\windows\system32\DriverStore\infstrng.dat

- 2009-07-14 05:30 . 2012-04-22 19:26 143360        c:\windows\system32\DriverStore\infstrng.dat

+ 2009-07-14 00:21 . 2009-07-14 01:41 299520        c:\windows\system32\drivers\UMDF\WpdFs.dll

+ 2012-04-24 18:44 . 2010-05-26 09:41 276832        c:\windows\system32\d3dx11_43.dll

+ 2012-04-24 18:44 . 2009-09-04 15:29 285024        c:\windows\system32\d3dx11_42.dll

+ 2012-04-24 18:44 . 2010-05-26 09:41 511328        c:\windows\system32\d3dx10_43.dll

+ 2012-04-24 18:44 . 2009-09-04 15:29 523088        c:\windows\system32\d3dx10_42.dll

+ 2012-04-24 18:44 . 2009-03-09 13:27 520544        c:\windows\system32\d3dx10_41.dll

+ 2012-04-24 18:44 . 2008-10-15 04:22 519000        c:\windows\system32\d3dx10_40.dll

+ 2012-04-24 18:44 . 2008-07-10 09:00 540688        c:\windows\system32\d3dx10_39.dll

+ 2012-04-24 18:44 . 2008-05-30 12:11 540688        c:\windows\system32\d3dx10_38.dll

+ 2012-04-24 18:44 . 2008-02-05 21:07 529424        c:\windows\system32\d3dx10_37.dll

+ 2012-04-24 18:44 . 2007-10-02 07:56 508264        c:\windows\system32\d3dx10_36.dll

+ 2012-04-24 18:44 . 2007-07-19 16:14 508264        c:\windows\system32\d3dx10_35.dll

- 2009-07-14 05:01 . 2012-04-24 13:13 227464        c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

+ 2009-07-14 05:01 . 2012-04-25 16:03 227464        c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

- 2012-04-23 19:13 . 2012-04-23 19:13 223232        c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll

+ 2012-04-24 18:44 . 2012-04-24 18:44 223232        c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll

+ 2012-04-24 18:44 . 2012-04-24 18:44 178176        c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll

- 2012-04-23 19:13 . 2012-04-23 19:13 178176        c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll

- 2012-04-23 19:13 . 2012-04-23 19:13 364544        c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll

+ 2012-04-24 18:44 . 2012-04-24 18:44 364544        c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll

- 2012-04-23 19:13 . 2012-04-23 19:13 159232        c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll

+ 2012-04-24 18:44 . 2012-04-24 18:44 159232        c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll

+ 2012-04-24 18:44 . 2012-04-24 18:44 145920        c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll

- 2012-04-23 19:13 . 2012-04-23 19:13 145920        c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll

+ 2012-04-24 18:44 . 2012-04-24 18:44 578560        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2012-04-23 19:13 . 2012-04-23 19:13 578560        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2012-04-24 18:44 . 2012-04-24 18:44 578560        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2012-04-23 19:13 . 2012-04-23 19:13 578560        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2012-04-23 19:13 . 2012-04-23 19:13 577536        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2012-04-24 18:44 . 2012-04-24 18:44 577536        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2012-04-23 19:13 . 2012-04-23 19:13 577536        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2012-04-24 18:44 . 2012-04-24 18:44 577536        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2012-04-24 18:44 . 2012-04-24 18:44 577024        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2012-04-23 19:13 . 2012-04-23 19:13 577024        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2012-04-24 18:44 . 2012-04-24 18:44 576000        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2012-04-23 19:13 . 2012-04-23 19:13 576000        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2012-04-23 19:13 . 2012-04-23 19:13 567296        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2012-04-24 18:44 . 2012-04-24 18:44 567296        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2012-04-23 19:13 . 2012-04-23 19:13 563712        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2012-04-24 18:44 . 2012-04-24 18:44 563712        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2012-04-24 18:44 . 2012-04-24 18:44 473600        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll

- 2012-04-23 19:13 . 2012-04-23 19:13 473600        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll

+ 2012-04-24 18:44 . 2010-05-26 09:41 1998168        c:\windows\SysWOW64\D3DX9_43.dll

+ 2012-04-24 18:44 . 2009-09-04 15:29 1892184        c:\windows\SysWOW64\D3DX9_42.dll

+ 2012-04-24 18:44 . 2009-03-09 13:27 4178264        c:\windows\SysWOW64\D3DX9_41.dll

+ 2012-04-24 18:44 . 2008-10-15 04:22 4379984        c:\windows\SysWOW64\D3DX9_40.dll

+ 2012-04-24 18:44 . 2008-07-10 09:00 3851784        c:\windows\SysWOW64\D3DX9_39.dll

+ 2012-04-24 18:44 . 2008-05-30 12:11 3850760        c:\windows\SysWOW64\D3DX9_38.dll

+ 2012-04-24 18:44 . 2008-03-05 13:56 3786760        c:\windows\SysWOW64\D3DX9_37.dll

+ 2012-04-24 18:44 . 2007-10-12 13:14 3734536        c:\windows\SysWOW64\d3dx9_36.dll

+ 2012-04-24 18:44 . 2007-07-19 16:14 3727720        c:\windows\SysWOW64\d3dx9_35.dll

+ 2012-04-24 18:44 . 2010-05-26 09:41 1868128        c:\windows\SysWOW64\d3dcsx_43.dll

+ 2012-04-24 18:44 . 2009-09-04 15:29 5501792        c:\windows\SysWOW64\d3dcsx_42.dll

+ 2012-04-24 18:44 . 2010-05-26 09:41 2106216        c:\windows\SysWOW64\D3DCompiler_43.dll

+ 2012-04-24 18:44 . 2009-09-04 15:29 1974616        c:\windows\SysWOW64\D3DCompiler_42.dll

+ 2012-04-24 18:44 . 2009-03-09 13:27 1846632        c:\windows\SysWOW64\D3DCompiler_41.dll

+ 2012-04-24 18:44 . 2008-10-15 04:22 2036576        c:\windows\SysWOW64\D3DCompiler_40.dll

+ 2012-04-24 18:44 . 2008-07-10 09:00 1493528        c:\windows\SysWOW64\D3DCompiler_39.dll

+ 2012-04-24 18:44 . 2008-05-30 12:11 1491992        c:\windows\SysWOW64\D3DCompiler_38.dll

+ 2012-04-24 18:44 . 2008-03-05 13:56 1420824        c:\windows\SysWOW64\D3DCompiler_37.dll

+ 2012-04-24 18:44 . 2007-10-12 13:14 1374232        c:\windows\SysWOW64\D3DCompiler_36.dll

+ 2012-04-24 18:44 . 2007-07-19 16:14 1358192        c:\windows\SysWOW64\D3DCompiler_35.dll

+ 2012-04-24 18:44 . 2010-05-26 09:41 2401112        c:\windows\system32\D3DX9_43.dll

+ 2012-04-24 18:44 . 2009-09-04 15:29 2475352        c:\windows\system32\D3DX9_42.dll

+ 2012-04-24 18:44 . 2009-03-09 13:27 5425496        c:\windows\system32\D3DX9_41.dll

+ 2012-04-24 18:44 . 2008-10-15 04:22 5631312        c:\windows\system32\D3DX9_40.dll

+ 2012-04-24 18:44 . 2008-07-10 09:00 4992520        c:\windows\system32\D3DX9_39.dll

+ 2012-04-24 18:44 . 2008-05-30 12:11 4991496        c:\windows\system32\D3DX9_38.dll

+ 2012-04-24 18:44 . 2008-03-05 13:56 4910088        c:\windows\system32\D3DX9_37.dll

+ 2012-04-24 18:44 . 2007-10-12 13:14 5081608        c:\windows\system32\d3dx9_36.dll

+ 2012-04-24 18:44 . 2007-07-19 16:14 5073256        c:\windows\system32\d3dx9_35.dll

+ 2012-04-24 18:44 . 2010-05-26 09:41 1907552        c:\windows\system32\d3dcsx_43.dll

+ 2012-04-24 18:44 . 2009-09-04 15:29 5554512        c:\windows\system32\d3dcsx_42.dll

+ 2012-04-24 18:44 . 2010-05-26 09:41 2526056        c:\windows\system32\D3DCompiler_43.dll

+ 2012-04-24 18:44 . 2009-09-04 15:29 2582888        c:\windows\system32\D3DCompiler_42.dll

+ 2012-04-24 18:44 . 2009-03-09 13:27 2430312        c:\windows\system32\D3DCompiler_41.dll

+ 2012-04-24 18:44 . 2008-10-15 04:22 2605920        c:\windows\system32\D3DCompiler_40.dll

+ 2012-04-24 18:44 . 2008-07-10 09:00 1942552        c:\windows\system32\D3DCompiler_39.dll

+ 2012-04-24 18:44 . 2008-05-30 12:11 1941528        c:\windows\system32\D3DCompiler_38.dll

+ 2012-04-24 18:44 . 2008-03-05 13:56 1860120        c:\windows\system32\D3DCompiler_37.dll

+ 2012-04-24 18:44 . 2007-10-12 13:14 2006552        c:\windows\system32\D3DCompiler_36.dll

+ 2012-04-24 18:44 . 2007-07-19 16:14 1985904        c:\windows\system32\D3DCompiler_35.dll

- 2012-04-23 19:13 . 2012-04-23 19:13 2846720        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2012-04-24 18:44 . 2012-04-24 18:44 2846720        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2012-04-24 18:44 . 2012-04-24 18:44 2676224        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2012-04-23 19:13 . 2012-04-23 19:13 2676224        c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

.

-- Snapshot reset to current date --

.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown 

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Facebook Update"="c:\users\Matej\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-04-22 203072]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-02-14 705664]

"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2009-09-21 2583040]

"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 536136]

.

c:\users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Logitech . Registracija proizvoda.lnk - c:\program files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe [2009-11-16 587016]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

AML Device Install.lnk - c:\program files (x86)\AMD AVT\bin\kdbsync.exe [2012-1-31 80384]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]

"aux"=wdmaud.drv

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusOverride"=dword:00000001

"AntiVirusDisableNotify"=dword:00000001

"FirewallDisableNotify"=dword:00000001

"FirewallOverride"=dword:00000001

"UpdatesDisableNotify"=dword:00000001

"UacDisableNotify"=dword:00000001

.

R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]

R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [x]

R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]

R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]

R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]

R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [x]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]

R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]

R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]

R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]

S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]

S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-02-14 361984]

S2 AODDriver4.1;AODDriver4.1;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-01-03 55936]

S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [x]

S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]

S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]

S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]

S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]

S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [x]

.

.

Contents of the 'Scheduled Tasks' folder

.

2012-04-25 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000Core.job

- c:\users\Matej\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-22 14:38]

.

2012-04-25 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000UA.job

- c:\users\Matej\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-22 14:38]

.

2012-04-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000Core.job

- c:\users\Matej\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-22 14:31]

.

2012-04-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000UA.job

- c:\users\Matej\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-22 14:31]

.

.

--------- x86-64 -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-10-07 1744152]

.

------- Supplementary Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

mLocal Page = c:\windows\SysWOW64\blank.htm

TCP: Interfaces\{E9CECB3F-8087-43C5-BD75-791E5EFE03C0}: NameServer = 8.8.8.8,4.4.8.8

.

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

------------------------ Other Running Processes ------------------------

.

c:\windows\SysWOW64\PnkBstrA.exe

.

**************************************************************************

.

Completion time: 2012-04-25  18:05:34 - machine was rebooted

ComboFix-quarantined-files.txt  2012-04-25 16:05

ComboFix2.txt  2012-04-24 18:20

ComboFix3.txt  2012-04-24 13:15

ComboFix4.txt  2012-04-23 18:42

.

Pre-Run: 154.120.761.344 bytes free

Post-Run: 153.847.603.200 bytes free

.

- - End Of File - - 9A55E48F59B809AFD04DC538669F350C

 

evo i log od malwarebytea sa D diska ( on i dalje stalno pokazuje da blokira kao neke stetne stranice) 

 

Malwarebytes Anti-Malware (Trial) 1.61.0.1400

www.malwarebytes.org

 

Database version: v2012.04.24.01

 

Windows 7 Service Pack 1 x64 NTFS

Internet Explorer 8.0.7601.17514

Matej :: MATEJ- [administrator]

 

Protection: Enabled

 

25.4.2012. 18:10:36

mbam-log-2012-04-25 (18-10-36).txt

 

Scan type: Full scan

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM

Scan options disabled: P2P

Objects scanned: 196458

Time elapsed: 1 minute(s), 

 

Memory Processes Detected: 0

(No malicious items detected)

 

Memory Modules Detected: 0

(No malicious items detected)

 

Registry Keys Detected: 0

(No malicious items detected)

 

Registry Values Detected: 0

(No malicious items detected)

 

Registry Data Items Detected: 3

HKLM\SOFTWARE\Microsoft\Security Center|AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.

HKLM\SOFTWARE\Microsoft\Security Center|FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.

HKLM\SOFTWARE\Microsoft\Security Center|UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.

 

Folders Detected: 0

(No malicious items detected)

 

Files Detected: 3

D:\deonte.exe (Trojan.Agent) -> Quarantined and deleted successfully.

D:\ewfyxf.exe (Trojan.Agent) -> Quarantined and deleted successfully.

D:\qmwx.pif (Trojan.Agent) -> Quarantined and deleted successfully.

 

(end)

 

(̅_̅_̅(̲̲̲̲̲̅̅̅̅̅̅(̅_̅_̲̅м̲̅a̲̅я̲̅l̲̅b̲̅o̲̅r̲̅o̲̅̅ _̅_̅_̅()
Poruka je uređivana zadnji put sri 25.4.2012 18:15 (AmD).
15 godina
offline
Igre se crashaju / Virus ?

odi u     C:\Qoobox\Quarantine i pronađi ovaj file C:\mdpaqv.exe.vir

uploadaj ga na jottis malware scan

 

otvori malwarebytes logs i kopiraj upozorenja

 

skini OTL i spremi na desktop

u prazno polje kopiraj ovo

 

  netsvcs
%SYSTEMDRIVE%\*.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /s
HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost /s

 

klik na quick scan

log kopiraj

 

Kaspersky Virus Removal Tool 2011

 

skini program, sve označi i klik na scan

 

http://www.zaslike.com/viewer.php?file=l5runrvycru1j1tc0gv.gif

 

report ćeš ovako spremiti

http://www.zaslike.com/viewer.php?file=8221ismoytj4c0hkoyim.gif

 

 

Poruka je uređivana zadnji put sri 25.4.2012 19:30 (total).
 
0 0 hvala 1
15 godina
offline
Re: Igre se crashaju / Virus ?

Tog fajla nema tamo , bio je jedan folder zakljucan , uspio sam uci ali nema ni tamo . 

 

Kaspersky ne mogu skinuti zbog errora na njihovoj stranici , a sve ostale redirectaju na njihovu . 

 

OTL log : 

 

OTL logfile created on: 25.4.2012. 19:44:58 - Run 1

OTL by OldTimer - Version 3.2.42.0    Folder = C:\Users\Matej\Desktop

64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation

Internet Explorer (Version = 8.0.7601.17514)

Locale: 0000041a | Country: Hrvatska | Language: HRV | Date Format: d.M.yyyy.

 

4,00 Gb Total Physical Memory | 2,80 Gb Available Physical Memory | 69,91% Memory free

8,00 Gb Paging File | 6,13 Gb Available in Paging File | 76,60% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

Drive C: | 172,69 Gb Total Space | 140,18 Gb Free Space | 81,17% Space Free | Partition Type: NTFS

Drive D: | 292,97 Gb Total Space | 240,31 Gb Free Space | 82,03% Space Free | Partition Type: NTFS

 

Computer Name: MATEJ- | User Name: Matej | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans

Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

 

[color=#E56717]========== Processes (SafeList) ==========[/color]

 

PRC - [2012.04.25 19:44:28 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Matej\Desktop\OTL.exe

PRC - [2012.04.25 19:22:40 | 000,075,136 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe

PRC - [2012.04.25 19:21:06 | 000,271,200 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrB.exe

PRC - [2012.04.25 19:07:46 | 000,011,776 | ---- | M] () -- C:\Users\Matej\AppData\Local\Temp\wingkly.exe

PRC - [2012.04.22 16:38:16 | 000,203,072 | ---- | M] (Facebook Inc.) -- C:\Users\Matej\AppData\Local\Facebook\Update\FacebookUpdate.exe

PRC - [2012.04.17 07:31:18 | 003,537,304 | ---- | M] (Xfire Inc.) -- C:\Program Files (x86)\Xfire\Xfire.exe

PRC - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

PRC - [2012.04.04 15:56:38 | 000,536,136 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

 

 

[color=#E56717]========== Modules (No Company Name) ==========[/color]

 

MOD - [2012.04.25 19:07:46 | 000,011,776 | ---- | M] () -- C:\Users\Matej\AppData\Local\Temp\wingkly.exe

MOD - [2012.04.12 09:37:34 | 000,444,400 | ---- | M] () -- C:\Users\Matej\AppData\Local\Google\Chrome\Application\18.0.1025.162\ppgooglenaclpluginchrome.dll

MOD - [2012.04.12 09:37:33 | 003,915,248 | ---- | M] () -- C:\Users\Matej\AppData\Local\Google\Chrome\Application\18.0.1025.162\pdf.dll

MOD - [2012.04.12 09:36:08 | 000,122,880 | ---- | M] () -- C:\Users\Matej\AppData\Local\Google\Chrome\Application\18.0.1025.162\avutil-51.dll

MOD - [2012.04.12 09:36:06 | 000,220,672 | ---- | M] () -- C:\Users\Matej\AppData\Local\Google\Chrome\Application\18.0.1025.162\avformat-53.dll

MOD - [2012.04.12 09:36:05 | 001,747,456 | ---- | M] () -- C:\Users\Matej\AppData\Local\Google\Chrome\Application\18.0.1025.162\avcodec-53.dll

MOD - [2012.04.12 08:51:55 | 008,743,584 | ---- | M] () -- C:\Users\Matej\AppData\Local\Google\Chrome\Application\18.0.1025.162\gcswf32.dll

 

 

[color=#E56717]========== Win32 Services (SafeList) ==========[/color]

 

SRV:[b]64bit:[/b] - [2012.03.09 07:10:20 | 000,235,520 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)

SRV:[b]64bit:[/b] - [2012.03.09 01:10:06 | 000,361,984 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)

SRV:[b]64bit:[/b] - [2011.09.27 21:04:08 | 000,359,192 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)

SRV:[b]64bit:[/b] - [2009.07.14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)

SRV:[b]64bit:[/b] - [2009.07.14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)

SRV - [2012.04.25 19:22:40 | 000,075,136 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)

SRV - [2012.04.25 19:21:06 | 000,271,200 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrB.exe -- (PnkBstrB)

SRV - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)

SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)

 

 

[color=#E56717]========== Driver Services (SafeList) ==========[/color]

 

DRV:[b]64bit:[/b] - [2012.04.04 15:56:40 | 000,024,904 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)

DRV:[b]64bit:[/b] - [2012.03.09 08:28:08 | 010,857,984 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)

DRV:[b]64bit:[/b] - [2012.03.09 05:58:02 | 000,328,704 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)

DRV:[b]64bit:[/b] - [2012.01.03 23:22:54 | 000,055,936 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys -- (AODDriver4.1)

DRV:[b]64bit:[/b] - [2011.12.05 21:47:30 | 000,095,248 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)

DRV:[b]64bit:[/b] - [2011.09.02 08:30:46 | 000,042,776 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LUsbFilt.sys -- (LUsbFilt)

DRV:[b]64bit:[/b] - [2011.09.02 08:30:36 | 000,060,696 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)

DRV:[b]64bit:[/b] - [2011.09.02 08:30:24 | 000,066,840 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)

DRV:[b]64bit:[/b] - [2010.11.21 05:24:43 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)

DRV:[b]64bit:[/b] - [2010.11.21 05:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)

DRV:[b]64bit:[/b] - [2010.11.21 05:23:48 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tsusbhub.sys -- (tsusbhub)

DRV:[b]64bit:[/b] - [2010.11.21 05:23:48 | 000,088,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc)

DRV:[b]64bit:[/b] - [2010.11.21 05:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)

DRV:[b]64bit:[/b] - [2010.11.21 05:23:48 | 000,034,816 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)

DRV:[b]64bit:[/b] - [2010.11.21 05:23:47 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)

DRV:[b]64bit:[/b] - [2010.11.21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)

DRV:[b]64bit:[/b] - [2010.11.21 05:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)

DRV:[b]64bit:[/b] - [2010.11.21 05:23:47 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)

DRV:[b]64bit:[/b] - [2010.02.18 09:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdiox64.sys -- (amdiox64)

DRV:[b]64bit:[/b] - [2009.09.17 19:04:18 | 001,250,816 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\viahduaa.sys -- (VIAHdAudAddService)

DRV:[b]64bit:[/b] - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)

DRV:[b]64bit:[/b] - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)

DRV:[b]64bit:[/b] - [2009.07.14 03:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)

DRV:[b]64bit:[/b] - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)

DRV:[b]64bit:[/b] - [2009.06.10 22:35:42 | 000,187,392 | ---- | M] (Realtek Corporation                       ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)

DRV:[b]64bit:[/b] - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)

DRV:[b]64bit:[/b] - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)

DRV:[b]64bit:[/b] - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)

DRV:[b]64bit:[/b] - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)

DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)

 

 

[color=#E56717]========== Standard Registry (SafeList) ==========[/color]

 

 

[color=#E56717]========== Internet Explorer ==========[/color]

 

IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

 

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = hr

IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

 

[color=#E56717]========== FireFox ==========[/color]

 

FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found

FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found

FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Matej\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Matej\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKCU\Software\MozillaPlugins\facebook.com/fbDesktopPlugin: C:\Users\Matej\AppData\Local\Facebook\Messenger\2.0.4478.0\npFbDesktopPlugin.dll (Facebook, Inc.)

 

 

 

[color=#E56717]========== Chrome  ==========[/color]

 

CHR - default_search_provider: Google (Enabled)

CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}

CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}

CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer

CHR - plugin: Native Client (Enabled) = C:\Users\Matej\AppData\Local\Google\Chrome\Application\18.0.1025.162\ppGoogleNaClPluginChrome.dll

CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Matej\AppData\Local\Google\Chrome\Application\18.0.1025.162\pdf.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Matej\AppData\Local\Google\Chrome\Application\18.0.1025.162\gcswf32.dll

CHR - plugin: Google Update (Enabled) = C:\Users\Matej\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll

CHR - Extension: YouTube = C:\Users\Matej\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\

CHR - Extension: Google pretra\u017Eivanje = C:\Users\Matej\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\

CHR - Extension: Gmail = C:\Users\Matej\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

 

O1 HOSTS File: ([2012.04.25 18:04:00 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts

O1 - Hosts: 127.0.0.1     localhost

O4:[b]64bit:[/b] - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)

O4 - HKLM..\Run: [AMD AVT] C:\Windows\SysWow64\cmd.exe (Microsoft Corporation)

O4 - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)

O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)

O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)

O4 - HKCU..\Run: [Facebook Update] C:\Users\Matej\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)

O4 - Startup: C:\Users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Registracija proizvoda.lnk = C:\Program Files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe (Leader Technologies/Logitech)

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0

O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E9CECB3F-8087-43C5-BD75-791E5EFE03C0}: NameServer = 8.8.8.8,4.4.8.8

O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)

O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)

O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)

O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (/pagefile) -  File not found

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found

O20:[b]64bit:[/b] - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2012.04.25 18:04:42 | 000,000,262 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]

O32 - AutoRun File - [2012.04.25 18:04:42 | 000,000,256 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]

O34 - HKLM BootExecute: (autocheck autochk *)

O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*

O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37:[b]64bit:[/b] - HKLM\...com [@ = ComFile] -- "%1" %*

O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*

O37 - HKLM\...com [@ = ComFile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

 

NetSvcs:[b]64bit:[/b] AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

 

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

 

[2012.04.25 19:44:24 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Users\Matej\Desktop\OTL.exe

[2012.04.25 19:04:51 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI

[2012.04.25 19:02:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD AVT

[2012.04.25 19:02:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD APP

[2012.04.25 19:02:50 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ATI Technologies

[2012.04.25 19:02:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\ATI Technologies

[2012.04.25 19:02:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD VISION Engine Control Center

[2012.04.25 19:01:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ATI Technologies

[2012.04.25 19:01:22 | 000,000,000 | ---D | C] -- C:\Program Files\ATI Technologies

[2012.04.25 19:01:19 | 000,000,000 | ---D | C] -- C:\Program Files\ATI

[2012.04.25 19:00:44 | 000,000,000 | ---D | C] -- C:\AMD

[2012.04.25 18:55:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Activision

[2012.04.25 18:52:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Activision

[2012.04.25 18:18:20 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN

[2012.04.25 18:17:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Phyxion.net

[2012.04.25 18:17:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Phyxion.net

[2012.04.25 18:05:36 | 000,000,000 | ---D | C] -- C:\Windows\temp

[2012.04.25 17:58:24 | 004,475,034 | R--- | C] (Swearware) -- C:\Users\Matej\Desktop\ComboFix.exe

[2012.04.24 20:45:43 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Roaming\LolClient

[2012.04.24 15:17:51 | 000,000,000 | ---D | C] -- C:\USBNoRisk

[2012.04.23 21:28:16 | 000,000,000 | ---D | C] -- C:\Users\Matej\Documents\VirtualDJ

[2012.04.23 21:28:16 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ

[2012.04.23 21:28:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VirtualDJ

[2012.04.23 20:35:07 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe

[2012.04.23 20:35:07 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe

[2012.04.23 20:35:07 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe

[2012.04.23 20:35:01 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT

[2012.04.23 20:34:58 | 000,000,000 | ---D | C] -- C:\Qoobox

[2012.04.23 20:22:35 | 000,000,000 | ---D | C] -- C:\_OTS

[2012.04.23 16:55:55 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Roaming\Malwarebytes

[2012.04.23 16:55:50 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys

[2012.04.23 16:55:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware

[2012.04.23 16:55:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware

[2012.04.23 16:55:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes

[2012.04.23 02:17:52 | 000,000,000 | ---D | C] -- C:\Windows\Panther

[2012.04.22 20:58:12 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Roaming\TS3Client

[2012.04.22 20:57:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client

[2012.04.22 20:57:22 | 000,000,000 | ---D | C] -- C:\Program Files\TeamSpeak 3 Client

[2012.04.22 17:40:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office

[2012.04.22 17:39:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSECache

[2012.04.22 17:32:05 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Local\PunkBuster

[2012.04.22 17:23:53 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Roaming\Xfire

[2012.04.22 17:23:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xfire

[2012.04.22 17:23:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Xfire

[2012.04.22 17:23:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Xfire

[2012.04.22 16:53:59 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Roaming\Macromedia

[2012.04.22 16:53:59 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Roaming\Adobe

[2012.04.22 16:44:41 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Wat

[2012.04.22 16:44:41 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Wat

[2012.04.22 16:42:06 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Roaming\WinRAR

[2012.04.22 16:42:06 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR

[2012.04.22 16:42:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR

[2012.04.22 16:42:02 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR

[2012.04.22 16:39:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\LogiShrd

[2012.04.22 16:39:29 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Roaming\Leadertech

[2012.04.22 16:39:09 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\LogiShrd

[2012.04.22 16:39:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech

[2012.04.22 16:39:06 | 000,000,000 | ---D | C] -- C:\Program Files\Logitech

[2012.04.22 16:39:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Logishrd

[2012.04.22 16:38:48 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Logishrd

[2012.04.22 16:38:36 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Facebook

[2012.04.22 16:38:16 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Local\Facebook

[2012.04.22 16:34:54 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Roaming\Logitech

[2012.04.22 16:34:54 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Roaming\Logishrd

[2012.04.22 16:34:00 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Local\AMD

[2012.04.22 16:33:53 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Roaming\ATI

[2012.04.22 16:33:53 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Local\ATI

[2012.04.22 16:33:43 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome

[2012.04.22 16:31:12 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Local\Google

[2012.04.22 16:31:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\InstallShield Installation Information

[2012.04.22 16:30:57 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Local\Apps

[2012.04.22 16:30:56 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Local\Deployment

[2012.04.22 16:30:55 | 000,242,176 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\SysNative\Dts2APO.dll

[2012.04.22 16:30:55 | 000,193,024 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\SysNative\ViaMicArrayAPO.dll

[2012.04.22 16:30:55 | 000,086,016 | ---- | C] (QSound Labs, Inc.) -- C:\Windows\SysNative\nQPropPageExt.dll

[2012.04.22 16:30:55 | 000,082,432 | ---- | C] (QSound Labs, Inc.) -- C:\Windows\SysNative\nQAPO.dll

[2012.04.22 16:30:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VIA

[2012.04.22 16:30:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InstallShield

[2012.04.22 16:28:20 | 000,000,000 | ---D | C] -- C:\ProgramData\AMD

[2012.04.22 16:27:45 | 000,000,000 | -HSD | C] -- C:\Windows\Installer

[2012.04.22 16:25:41 | 000,000,000 | R--D | C] -- C:\Users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

[2012.04.22 16:25:41 | 000,000,000 | R--D | C] -- C:\Users\Matej\Searches

[2012.04.22 16:25:41 | 000,000,000 | R--D | C] -- C:\Users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools

[2012.04.22 16:25:40 | 000,000,000 | -H-D | C] -- C:\Users\Matej\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned

[2012.04.22 16:25:32 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Roaming\Identities

[2012.04.22 16:25:30 | 000,000,000 | R--D | C] -- C:\Users\Matej\Contacts

[2012.04.22 16:25:29 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Local\VirtualStore

[2012.04.22 16:25:22 | 000,000,000 | --SD | C] -- C:\Users\Matej\AppData\Roaming\Microsoft

[2012.04.22 16:25:22 | 000,000,000 | R--D | C] -- C:\Users\Matej\Videos

[2012.04.22 16:25:22 | 000,000,000 | R--D | C] -- C:\Users\Matej\Saved Games

[2012.04.22 16:25:22 | 000,000,000 | R--D | C] -- C:\Users\Matej\Pictures

[2012.04.22 16:25:22 | 000,000,000 | R--D | C] -- C:\Users\Matej\Music

[2012.04.22 16:25:22 | 000,000,000 | R--D | C] -- C:\Users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance

[2012.04.22 16:25:22 | 000,000,000 | R--D | C] -- C:\Users\Matej\Links

[2012.04.22 16:25:22 | 000,000,000 | R--D | C] -- C:\Users\Matej\Favorites

[2012.04.22 16:25:22 | 000,000,000 | R--D | C] -- C:\Users\Matej\Downloads

[2012.04.22 16:25:22 | 000,000,000 | R--D | C] -- C:\Users\Matej\Documents

[2012.04.22 16:25:22 | 000,000,000 | R--D | C] -- C:\Users\Matej\Desktop

[2012.04.22 16:25:22 | 000,000,000 | R--D | C] -- C:\Users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories

[2012.04.22 16:25:22 | 000,000,000 | -HSD | C] -- C:\Users\Matej\AppData\Local\Temporary Internet Files

[2012.04.22 16:25:22 | 000,000,000 | -HSD | C] -- C:\Users\Matej\Templates

[2012.04.22 16:25:22 | 000,000,000 | -HSD | C] -- C:\Users\Matej\Start Menu

[2012.04.22 16:25:22 | 000,000,000 | -HSD | C] -- C:\Users\Matej\SendTo

[2012.04.22 16:25:22 | 000,000,000 | -HSD | C] -- C:\Users\Matej\Recent

[2012.04.22 16:25:22 | 000,000,000 | -HSD | C] -- C:\Users\Matej\PrintHood

[2012.04.22 16:25:22 | 000,000,000 | -HSD | C] -- C:\Users\Matej\NetHood

[2012.04.22 16:25:22 | 000,000,000 | -HSD | C] -- C:\Users\Matej\Documents\My Videos

[2012.04.22 16:25:22 | 000,000,000 | -HSD | C] -- C:\Users\Matej\Documents\My Pictures

[2012.04.22 16:25:22 | 000,000,000 | -HSD | C] -- C:\Users\Matej\Documents\My Music

[2012.04.22 16:25:22 | 000,000,000 | -HSD | C] -- C:\Users\Matej\My Documents

[2012.04.22 16:25:22 | 000,000,000 | -HSD | C] -- C:\Users\Matej\Local Settings

[2012.04.22 16:25:22 | 000,000,000 | -HSD | C] -- C:\Users\Matej\AppData\Local\History

[2012.04.22 16:25:22 | 000,000,000 | -HSD | C] -- C:\Users\Matej\Cookies

[2012.04.22 16:25:22 | 000,000,000 | -HSD | C] -- C:\Users\Matej\Application Data

[2012.04.22 16:25:22 | 000,000,000 | -HSD | C] -- C:\Users\Matej\AppData\Local\Application Data

[2012.04.22 16:25:22 | 000,000,000 | -H-D | C] -- C:\Users\Matej\AppData

[2012.04.22 16:25:22 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Local\Temp

[2012.04.22 16:25:22 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Local\Microsoft

[2012.04.22 16:25:22 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Roaming\Media Center Programs

[2012.04.22 16:25:12 | 000,000,000 | ---D | C] -- C:\Recovery

[2012.04.22 16:21:37 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution

[2012.04.22 16:19:08 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch

[2012.04.22 16:18:37 | 000,000,000 | -HSD | C] -- C:\System Volume Information

 

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

 

[2012.04.25 19:44:28 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Matej\Desktop\OTL.exe

[2012.04.25 19:43:01 | 000,000,928 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000UA.job

[2012.04.25 19:36:00 | 000,000,958 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000UA.job

[2012.04.25 19:22:40 | 000,075,136 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe

[2012.04.25 19:21:06 | 000,271,200 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe

[2012.04.25 19:08:55 | 000,713,888 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI

[2012.04.25 19:08:55 | 000,606,992 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat

[2012.04.25 19:08:55 | 000,103,370 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat

[2012.04.25 19:04:31 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat

[2012.04.25 19:04:27 | 000,000,000 | ---- | M] () -- C:\Windows\ativpsrm.bin

[2012.04.25 19:04:24 | 3220,676,608 | -HS- | M] () -- C:\hiberfil.sys

[2012.04.25 19:01:09 | 000,013,746 | ---- | M] () -- C:\Users\Matej\Desktop\pbgame.htm

[2012.04.25 19:01:04 | 000,000,082 | ---- | M] () -- C:\Users\Matej\Desktop\pbuser.htm

[2012.04.25 18:55:59 | 000,002,014 | ---- | M] () -- C:\Users\Public\Desktop\Call of Duty(R) 4 - Modern Warfare(TM) Singleplayer.lnk

[2012.04.25 18:55:59 | 000,002,014 | ---- | M] () -- C:\Users\Public\Desktop\Call of Duty(R) 4 - Modern Warfare(TM) Multiplayer.lnk

[2012.04.25 18:55:30 | 000,000,331 | ---- | M] () -- C:\Windows\game.ini

[2012.04.25 18:45:08 | 000,099,328 | ---- | M] () -- C:\udfuxh.exe

[2012.04.25 18:17:30 | 000,001,237 | ---- | M] () -- C:\Users\Public\Desktop\Driver Sweeper.lnk

[2012.04.25 18:04:42 | 000,000,262 | RHS- | M] () -- C:\autorun.inf

[2012.04.25 18:04:00 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts

[2012.04.25 17:57:54 | 004,475,034 | R--- | M] (Swearware) -- C:\Users\Matej\Desktop\ComboFix.exe

[2012.04.25 16:50:06 | 000,000,906 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000Core.job

[2012.04.25 16:50:06 | 000,000,906 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000Core.job

[2012.04.24 20:14:09 | 000,001,358 | ---- | M] () -- C:\Users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Registracija proizvoda.lnk

[2012.04.24 15:17:22 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf

[2012.04.24 15:13:25 | 000,267,560 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT

[2012.04.24 13:17:47 | 000,000,116 | ---- | M] () -- C:\Users\Matej\Documents\AutoHotkey.ahk

[2012.04.24 13:11:09 | 000,271,200 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr

[2012.04.24 13:10:57 | 000,103,736 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0

[2012.04.23 21:40:01 | 005,808,587 | ---- | M] () -- C:\Users\Matej\Desktop\mama.mp3

[2012.04.23 21:28:17 | 000,001,050 | ---- | M] () -- C:\Users\Matej\Desktop\VirtualDJ Home FREE.lnk

[2012.04.23 16:55:50 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

[2012.04.22 21:28:59 | 003,372,931 | ---- | M] () -- C:\Users\Matej\Desktop\SANJA DJORDJEVIC - SANJA - www.YuMp3.info.mp3

[2012.04.22 21:26:13 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf

[2012.04.22 20:57:23 | 000,000,967 | ---- | M] () -- C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk

[2012.04.22 17:23:53 | 000,000,967 | ---- | M] () -- C:\Users\Public\Desktop\Xfire.lnk

[2012.04.22 16:44:47 | 000,016,640 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

[2012.04.22 16:44:47 | 000,016,640 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

[2012.04.22 16:33:44 | 000,002,278 | ---- | M] () -- C:\Users\Matej\Desktop\Google Chrome.lnk

[2012.04.22 16:31:00 | 000,001,206 | ---- | M] () -- C:\Users\Public\Desktop\HD VDeck.lnk

[2012.04.22 16:30:26 | 000,001,441 | ---- | M] () -- C:\Users\Matej\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk

[2012.04.22 16:21:31 | 000,116,385 | ---- | M] () -- C:\Windows\SysWow64\license.rtf

[2012.04.22 16:21:31 | 000,116,385 | ---- | M] () -- C:\Windows\SysNative\license.rtf

[2012.04.17 07:31:22 | 000,042,392 | ---- | M] () -- C:\Windows\SysWow64\xfcodec.dll

[2012.04.17 07:31:22 | 000,028,056 | ---- | M] () -- C:\Windows\SysNative\xfcodec64.dll

[2012.04.04 15:56:40 | 000,024,904 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys

 

[color=#E56717]========== Files Created - No Company Name ==========[/color]

 

[2012.04.25 19:04:27 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin

[2012.04.25 18:55:59 | 000,002,014 | ---- | C] () -- C:\Users\Public\Desktop\Call of Duty(R) 4 - Modern Warfare(TM) Singleplayer.lnk

[2012.04.25 18:55:59 | 000,002,014 | ---- | C] () -- C:\Users\Public\Desktop\Call of Duty(R) 4 - Modern Warfare(TM) Multiplayer.lnk

[2012.04.25 18:45:08 | 000,099,328 | ---- | C] () -- C:\udfuxh.exe

[2012.04.25 18:17:30 | 000,001,237 | ---- | C] () -- C:\Users\Public\Desktop\Driver Sweeper.lnk

[2012.04.25 18:04:23 | 000,000,262 | RHS- | C] () -- C:\autorun.inf

[2012.04.24 20:14:09 | 000,001,358 | ---- | C] () -- C:\Users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Registracija proizvoda.lnk

[2012.04.24 15:17:22 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf

[2012.04.24 13:16:34 | 000,000,116 | ---- | C] () -- C:\Users\Matej\Documents\AutoHotkey.ahk

[2012.04.23 21:34:44 | 005,808,587 | ---- | C] () -- C:\Users\Matej\Desktop\mama.mp3

[2012.04.23 21:28:17 | 000,001,050 | ---- | C] () -- C:\Users\Matej\Desktop\VirtualDJ Home FREE.lnk

[2012.04.23 20:35:07 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe

[2012.04.23 20:35:07 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe

[2012.04.23 20:35:07 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe

[2012.04.23 20:35:07 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe

[2012.04.23 20:35:07 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe

[2012.04.23 16:55:50 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

[2012.04.22 21:28:22 | 003,372,931 | ---- | C] () -- C:\Users\Matej\Desktop\SANJA DJORDJEVIC - SANJA - www.YuMp3.info.mp3

[2012.04.22 21:26:13 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf

[2012.04.22 20:57:23 | 000,000,967 | ---- | C] () -- C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk

[2012.04.22 18:46:15 | 000,271,200 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.xtr

[2012.04.22 18:41:21 | 000,000,082 | ---- | C] () -- C:\Users\Matej\Desktop\pbuser.htm

[2012.04.22 18:41:16 | 000,013,746 | ---- | C] () -- C:\Users\Matej\Desktop\pbgame.htm

[2012.04.22 18:41:05 | 000,912,896 | ---- | C] () -- C:\Users\Matej\Desktop\pbsetup.exe

[2012.04.22 17:40:10 | 000,002,671 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Word Viewer 2003.lnk

[2012.04.22 17:23:53 | 000,000,967 | ---- | C] () -- C:\Users\Public\Desktop\Xfire.lnk

[2012.04.22 17:13:51 | 000,271,200 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe

[2012.04.22 17:13:51 | 000,103,736 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.ex0

[2012.04.22 17:13:49 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe

[2012.04.22 17:13:48 | 000,000,331 | ---- | C] () -- C:\Windows\game.ini

[2012.04.22 16:38:20 | 000,000,928 | ---- | C] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000UA.job

[2012.04.22 16:38:20 | 000,000,906 | ---- | C] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000Core.job

[2012.04.22 16:33:44 | 000,002,278 | ---- | C] () -- C:\Users\Matej\Desktop\Google Chrome.lnk

[2012.04.22 16:31:13 | 000,000,958 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000UA.job

[2012.04.22 16:31:12 | 000,000,906 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000Core.job

[2012.04.22 16:31:00 | 000,001,218 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD VDeck.lnk

[2012.04.22 16:31:00 | 000,001,206 | ---- | C] () -- C:\Users\Public\Desktop\HD VDeck.lnk

[2012.04.22 16:30:26 | 000,001,441 | ---- | C] () -- C:\Users\Matej\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk

[2012.04.22 16:25:46 | 000,001,413 | ---- | C] () -- C:\Users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk

[2012.04.22 16:25:42 | 000,001,447 | ---- | C] () -- C:\Users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk

[2012.04.22 16:25:22 | 000,000,290 | ---- | C] () -- C:\Users\Matej\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk

[2012.04.22 16:25:22 | 000,000,272 | ---- | C] () -- C:\Users\Matej\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk

[2012.04.22 16:21:21 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk

[2012.04.22 16:21:14 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk

[2012.04.22 16:18:37 | 3220,676,608 | -HS- | C] () -- C:\hiberfil.sys

[2012.04.17 07:31:22 | 000,042,392 | ---- | C] () -- C:\Windows\SysWow64\xfcodec.dll

[2012.04.17 07:31:22 | 000,028,056 | ---- | C] () -- C:\Windows\SysNative\xfcodec64.dll

[2012.03.09 01:26:20 | 000,054,784 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll

[2012.02.15 04:36:36 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat

[2012.02.15 04:36:36 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat

[2012.01.31 07:00:24 | 000,016,896 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll

[2011.09.13 00:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat

 

[color=#E56717]========== LOP Check ==========[/color]

 

[2012.04.22 16:39:29 | 000,000,000 | ---D | M] -- C:\Users\Matej\AppData\Roaming\Leadertech

[2012.04.24 20:45:43 | 000,000,000 | ---D | M] -- C:\Users\Matej\AppData\Roaming\LolClient

[2012.04.23 18:46:21 | 000,000,000 | ---D | M] -- C:\Users\Matej\AppData\Roaming\TS3Client

[2012.04.25 16:50:06 | 000,000,906 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000Core.job

[2012.04.25 19:43:01 | 000,000,928 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000UA.job

[2009.07.14 07:08:49 | 000,006,094 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

 

[color=#E56717]========== Purity Check ==========[/color]

 

 

 

[color=#E56717]========== Custom Scans ==========[/color]

 

[color=#A23BEC]< %SYSTEMDRIVE%\*.exe >[/color]

[2012.04.25 18:45:08 | 000,099,328 | ---- | M] () -- C:\udfuxh.exe

 

[color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /s >[/color]

"HDAudDeck" = C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r -- [2009.09.21 18:42:36 | 002,583,040 | R--- | M] (VIA)

"Malwarebytes' Anti-Malware" = "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray -- [2012.04.04 15:56:38 | 000,536,136 | ---- | M] (Malwarebytes Corporation)

"StartCCC" = "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun -- [2012.03.09 02:30:12 | 000,709,760 | ---- | M] (Advanced Micro Devices, Inc.)

"AMD AVT" = Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml -- [2010.11.21 05:24:03 | 000,302,592 | ---- | M] (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]

"Installed" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]

"Installed" = 1

"NoChange" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]

"Installed" = 1

 

[color=#A23BEC]< HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost /s >[/color]

"netsvcs" = [Binary data over 100 bytes]

"LocalService" = [Binary data over 100 bytes]

"LocalSystemNetworkRestricted" = [Binary data over 100 bytes]

"LocalServiceNoNetwork" = PLA [binary data] -- [2010.11.21 05:24:08 | 001,508,864 | ---- | M] (Microsoft Corporation)

"rpcss" = RpcSs [binary data]

"LocalServiceNetworkRestricted" = AudioSrvBthHFSrvLmHostswscsvcWPCSvc [binary data]

"LocalServiceAndNoImpersonation" = SSDPSRVupnphostSCardSvrTBSQWAVEwcncsvc [binary data]

"DcomLaunch" = PowerPlugPlayDcomLaunch [binary data]

"NetworkService" = [Binary data over 100 bytes]

"imgsvc" = StiSvc [binary data]

"wcssvc" = WcsPlugInService [binary data] -- [2009.07.14 03:16:18 | 000,032,768 | ---- | M] (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService]

"AuthenticationCapabilities" = 8192

"CoInitializeSecurityParam" = 1

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation]

"AuthenticationCapabilities" = 8192

"CoInitializeSecurityParam" = 1

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceNetworkRestricted]

"CoInitializeSecurityParam" = 1

"DefaultRpcStackSize" = 64

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceNoNetwork]

"CoInitializeSecurityParam" = 1

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost\LocalSystemNetworkRestricted]

"CoInitializeSecurityParam" = 1

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs]

"AuthenticationCapabilities" = 12320

"CoInitializeSecurityParam" = 1

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost\NetworkService]

"CoInitializeSecurityParam" = 1

"DefaultRpcStackSize" = 28

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost\NetworkServiceRemoteDesktopHyperVAgent]

"CoInitializeSecurityParam" = 1

"AuthenticationCapabilities" = 8192

"AuthenticationLevel" = 6

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost\NetworkServiceRemoteDesktopPublishing]

"CoInitializeSecurityParam" = 1

"AuthenticationCapabilities" = 8192

"AuthenticationLevel" = 6

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost\termsvcs]

"CoInitializeSecurityParam" = 1

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost\wcssvc]

"CoInitializeSecurityParam" = 1

"CoInitializeSecurityAppID" = {CD11FAB6-1C0E-45e1-BA31-5C6008EF2607}

 

< End of report >

(̅_̅_̅(̲̲̲̲̲̅̅̅̅̅̅(̅_̅_̲̅м̲̅a̲̅я̲̅l̲̅b̲̅o̲̅r̲̅o̲̅̅ _̅_̅_̅()
15 godina
offline
Igre se crashaju / Virus ?

kaspersky se otvara bez problema, bojim se da je file replicator u pitanju...

 

otvori OTL i ovo kopiraj u prazno polje

 

  :services

:OTL

PRC - [2012.04.25 19:07:46 | 000,011,776 | ---- | M] () -- C:\Users\Matej\AppData\Local\Temp\wingkly.exe
MOD - [2012.04.25 19:07:46 | 000,011,776 | ---- | M] () -- C:\Users\Matej\AppData\Local\Temp\wingkly.exe
O32 - AutoRun File - [2012.04.25 18:04:42 | 000,000,262 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2012.04.25 18:04:42 | 000,000,256 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
[2012.04.25 18:45:08 | 000,099,328 | ---- | M] () -- C:\udfuxh.exe
[2012.04.25 18:45:08 | 000,099,328 | ---- | C] () -- C:\udfuxh.exe
[2012.04.25 18:04:23 | 000,000,262 | RHS- | C] () -- C:\autorun.inf

:files

C:\udfuxh.exe
C:\autorun.inf
C:\Users\Matej\AppData\Local\Temp\wingkly.exe

:Commands
[purity]
[emptytemp]
[resethosts]
[EMPTYFLASH]
[CREATERESTOREPOINT]
[Reboot]
klik na RUN FIX

 

log koji dobiješ kopiraj

 

dr.web cure it 

 

skini dr.wb cure it i spremi na desktop

pokreni najprije quick scan (koji je podešen po defoultu), nakom toga kreni fulls scan

 

ako se opet dogodi da ne možeš skinuti dr.web ili kaspersky, skini program s zdravog računala i prebaci na usb stik ili dvd/cd na zaraženo računao te pokreni program

 

očito je da   D: disk nije zaražen samoo s wormom...

 

 

 
0 0 hvala 1
15 godina
offline
Re: Igre se crashaju / Virus ?

 

OTL log

 

i skenirao sam sa dr.webom ali mi je opet neki fajl trazio propust kroz firewall .. Iako je ovaj vecinu ocistio i pobriso , tocnije 158 . 

 

All processes killed

========== SERVICES/DRIVERS ==========

========== OTL ==========

No active process named wingkly.exe was found!

C:\autorun.inf moved successfully.

D:\autorun.inf moved successfully.

C:\udfuxh.exe moved successfully.

File C:\udfuxh.exe not found.

File C:\autorun.inf not found.

========== FILES ==========

File\Folder C:\udfuxh.exe not found.

File\Folder C:\autorun.inf not found.

File\Folder C:\Users\Matej\AppData\Local\Temp\wingkly.exe not found.

========== COMMANDS ==========

 

[EMPTYTEMP]

 

User: All Users

 

User: Default

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

 

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

 

User: Matej

->Temp folder emptied: 594038 bytes

->Temporary Internet Files folder emptied: 2723742 bytes

->Google Chrome cache emptied: 364388488 bytes

->Flash cache emptied: 3764 bytes

 

User: Public

 

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 0 bytes

%systemroot%\System32 .tmp files removed: 0 bytes

%systemroot%\System32 (64bit) .tmp files removed: 0 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 1686 bytes

%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50333 bytes

RecycleBin emptied: 0 bytes

 

Total Files Cleaned = 351,00 mb

 

C:\Windows\System32\drivers\etc\Hosts moved successfully.

HOSTS file reset successfully

 

[EMPTYFLASH]

 

User: All Users

 

User: Default

 

User: Default User

 

User: Matej

->Flash cache emptied: 0 bytes

 

User: Public

 

Total Flash Files Cleaned = 0,00 mb

 

Restore point Set: OTL Restore Point

 

OTL by OldTimer - Version 3.2.42.0 log created on 04272012_200932

 

Files\Folders moved on Reboot...

C:\Users\Matej\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

 

Registry entries deleted on Reboot...

 

(̅_̅_̅(̲̲̲̲̲̅̅̅̅̅̅(̅_̅_̲̅м̲̅a̲̅я̲̅l̲̅b̲̅o̲̅r̲̅o̲̅̅ _̅_̅_̅()
Poruka je uređivana zadnji put sub 28.4.2012 0:18 (AmD).
15 godina
offline
Igre se crashaju / Virus ?

158 je velik broj, trebam znati o kojem se virusu radi ?....sality, virut ?...što je dr.web pronašao ?

 
0 0 hvala 1
15 godina
offline
Igre se crashaju / Virus ?

Sality je pronasao . 

(̅_̅_̅(̲̲̲̲̲̅̅̅̅̅̅(̅_̅_̲̅м̲̅a̲̅я̲̅l̲̅b̲̅o̲̅r̲̅o̲̅̅ _̅_̅_̅()
 
0 0 hvala 0
15 godina
offline
Re: Igre se crashaju / Virus ?
AmD kaže...

Sality je pronasao .

  sality killer.exe

 

skini ovaj program i spremi na destop

 

program pokreni 2   puta,...sality killer će očistiti memoriju, e sad...ako su samo podaci na D: inficirani, sve izbriši osim dokumenata i slika, dakle, sve igrice i programe...

 

a ako je i c: inficiran, kad završiš sa salitykillerom spremi dokumentei slike i formatiraj kompletno računalo ...sve diskove, i kreni iznova...sality se može očistiti ako je infekcija u početku, ovako bi to bila lutrija

15 godina
offline
Re: Igre se crashaju / Virus ?

Evo pokrenuo , pa cemo vidjeti , inficiran je i c jer vidim da lijeci program files itd .. 

 

Nemam nekih posebnih podataka , ali smijem li spremiti sada te fajlove kada zavrsim ( imam par photoshop projekata te 2-3 igre ) na disk prijenosni , tj hoce li one biti ciste nakon sto ovo zavrsi ? 

 

EDIT: oba diska formatiram kad instaliram windowse jel ? 

 

Monitoring thread stopped

 

completed

Infected files:          212

Infected processes:        0

Infected threads:         85

Cured files:           212

Will be cured on reboot:     0

Executed registry scripts:    1

(̅_̅_̅(̲̲̲̲̲̅̅̅̅̅̅(̅_̅_̲̅м̲̅a̲̅я̲̅l̲̅b̲̅o̲̅r̲̅o̲̅̅ _̅_̅_̅()
Poruka je uređivana zadnji put sub 28.4.2012 18:55 (AmD).
15 godina
offline
Igre se crashaju / Virus ?

pa da, to je to...da nije tako računalo bi bilo čisto iz dva kruga....saliti killer će očistiti virus iz memorije, dezinficirati filove...ko zna, možda će raditi nakon toga...samo kažem ti kakvo je pravilo kod infekcije salitijem i virutom

 

na externi disk sve možeš spremiti osim filova koji imaj .exe dodatak...možeš bez problema spremiti photshop radove, word, excel, .jpg, .mp3...samo programe ne..

 

oba diska formatiraj i kreni iznova, tako ti je najbolje...jer ćeš ionako sve igre i sve programe morati iznova instalirati

 
0 0 hvala 1
15 godina
offline
Re: Igre se crashaju / Virus ?

Windowsi reinstalirani , prijesnosni skeniran sa 4 antivirusa i niti jedan nije pronasao nista , nakon instalacije novih windowsa komp jos jednom procesljan sa sality killerom , te sam instalirao aviru zasad . Imas neki bolji prijedlog antivirusa jer ovaj nikad nisam koristio , ali eto ..

(̅_̅_̅(̲̲̲̲̲̅̅̅̅̅̅(̅_̅_̲̅м̲̅a̲̅я̲̅l̲̅b̲̅o̲̅r̲̅o̲̅̅ _̅_̅_̅()
15 godina
offline
Re: Igre se crashaju / Virus ?
AmD kaže...

Windowsi reinstalirani , prijesnosni skeniran sa 4 antivirusa i niti jedan nije pronasao nista , nakon instalacije novih windowsa komp jos jednom procesljan sa sality killerom , te sam instalirao aviru zasad . Imas neki bolji prijedlog antivirusa jer ovaj nikad nisam koristio , ali eto ..

  avira je pristojan antivrus, za normalno korištenje internta je skroz ok....možeš probati eventualno avast, pa sam zaključiš  što ti najbolje odgovara...uz antivirus bi bilo dobro da imaš i malwarebytes -free verzija je više nego dovoljna...nema najboljeg antivirusa i nijedan neće štiti 100%, svi su oni manje više isti i pružaju otprilike jednaku zaštitu

 

najbolji antivirus je korisnik koji pazi na što klika :)

15 godina
offline
Re: Igre se crashaju / Virus ?

Ja si ne mogu dokuciti odakle je dosao virus .. Ali eto , valjda ce sada biti ok :)

 

Hvala ti na pomoci :)

(̅_̅_̅(̲̲̲̲̲̅̅̅̅̅̅(̅_̅_̲̅м̲̅a̲̅я̲̅l̲̅b̲̅o̲̅r̲̅o̲̅̅ _̅_̅_̅()
1
Nova poruka
E-mail:
Lozinka:
 
vrh stranice