Jučer vidim stalno nesto trazi dozvolu za firewall i pokrenem Call of Duty 4 i crasha se ( odmah pri paljenju ) . Nakon toga avast je krenuo brisati datoteke sa racunala , odlucio sam da je vjerovatno najbolje windowse reinstalirati , nakon sto sam to napravio i isntalirao sve drivere opet normalno je radilo, do prije eto nekih pola sata . Sada opet se igra rusi , probao sam skenirati sa malware byte-om i sve sto je nasao pobrisao sam ali i dalje se rusi . Naravno isto je i sa sotalim igrama , te i dalje nekakvi cudni fajlovi traze dozvolu za firewall .
Igre se crashaju / Virus ?
- poruka: 25
- |
- čitano: 5.729
- |
- moderatori:
pirat, Lazarus Long, XXX-Man, vincimus
- +/- sve poruke
- ravni prikaz
- starije poruke gore
Jučer vidim stalno nesto trazi dozvolu za firewall i pokrenem Call of Duty 4 i crasha se ( odmah pri paljenju ) . Nakon toga avast je krenuo brisati datoteke sa racunala , odlucio sam da je vjerovatno najbolje windowse reinstalirati , nakon sto sam to napravio i isntalirao sve drivere opet normalno je radilo, do prije eto nekih pola sata . Sada opet se igra rusi , probao sam skenirati sa malware byte-om i sve sto je nasao pobrisao sam ali i dalje se rusi . Naravno isto je i sa sotalim igrama , te i dalje nekakvi cudni fajlovi traze dozvolu za firewall .
možeš li kopirati zadnji malwarebytes log ?
isto tako uradi ovako da pogledam o čemu se točno radi
ili je virut virus ili je zeroaccess ...nakon što odradiš scan s OTS-om, znat će se puno više
Malwarebytes Anti-Malware (Trial) 1.61.0.1400
www.malwarebytes.org
Database version: v2012.04.23.04
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Matej :: MATEJ- [administrator]
Protection: Enabled
23.4.2012. 16:57:02
mbam-log-2012-04-23 (16-57-02).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 191459
Time elapsed: 58 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 3
HKLM\SOFTWARE\Microsoft\Security Center|AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.
HKLM\SOFTWARE\Microsoft\Security Center|FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.
HKLM\SOFTWARE\Microsoft\Security Center|UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.
Folders Detected: 0
(No malicious items detected)
Files Detected: 2
C:\Users\Matej\Desktop\RemoveWAT 2.2.6.exe (HackTool.Wpakill) -> Quarantined and deleted successfully.
C:\bxubf.exe (Trojan.Agent) -> Quarantined and deleted successfully.
(end)
-isključi malwarebtes realtime zaštitu
-otvori OTS i ovo kopiraj u prazno polje
[Kill All Processes]
[Unregister Dlls]
[Registry - Safe List]
< Internet Explorer Settings [HKEY_CURRENT_USER\] > ->
YN -> HKEY_CURRENT_USER\: Main\\"Start Page Redirect Cache_TIMESTAMP" -> FC 79 D5 77 94 20 CD 01 [binary data]
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YN -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< 64bit-SSODL [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
YN -> "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" [HKLM] -> Reg Error: Key error. [WebCheck]
< SSODL [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
YN -> "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" [HKLM] -> Reg Error: Key error. [WebCheck]
< Vista Active Application Exception Rules > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules
YN -> TCP Query User{2091E29B-183E-4336-97FF-AE736481068E}C:\users\matej\appdata\local\temp\ymmxna.exe -> profile=public | protocol=6 | dir=in | action=block | name=ymmxna.exe | app=c:\users\matej\appdata\local\temp\ymmxna.exe |
YN -> TCP Query User{2C3D8B6A-6F41-43EC-A098-162F164CBBF7}C:\users\matej\appdata\local\temp\winfhbchg.exe -> profile=public | protocol=6 | dir=in | action=block | name=winfhbchg.exe | app=c:\users\matej\appdata\local\temp\winfhbchg.exe |
YN -> TCP Query User{3F9AF0FE-BCE5-44FF-9856-C0F887636721}C:\users\matej\appdata\local\temp\fqhjtf.exe -> profile=public | protocol=6 | dir=in | action=block | name=fqhjtf.exe | app=c:\users\matej\appdata\local\temp\fqhjtf.exe |
YN -> TCP Query User{4B4CB31E-B566-458A-A44C-0575B56E5323}C:\users\matej\appdata\local\temp\wingjygin.exe -> profile=public | protocol=6 | dir=in | action=block | name=wingjygin.exe | app=c:\users\matej\appdata\local\temp\wingjygin.exe |
YN -> TCP Query User{6B3A8827-C0C5-432B-9A12-D1A27A4337FC}C:\users\matej\appdata\local\temp\winhcvrlg.exe -> profile=public | protocol=6 | dir=in | action=block | name=winhcvrlg.exe | app=c:\users\matej\appdata\local\temp\winhcvrlg.exe |
YN -> TCP Query User{6DF366B0-4823-46FA-BEEA-05F7AFB89A68}C:\users\matej\appdata\local\temp\winaxnmu.exe -> profile=public | protocol=6 | dir=in | action=block | name=winaxnmu.exe | app=c:\users\matej\appdata\local\temp\winaxnmu.exe |
YN -> UDP Query User{174713FA-1BF8-4694-81BB-CDBD7ECA9A25}C:\users\matej\appdata\local\temp\winhcvrlg.exe -> profile=public | protocol=17 | dir=in | action=block | name=winhcvrlg.exe | app=c:\users\matej\appdata\local\temp\winhcvrlg.exe |
YN -> UDP Query User{343EB923-C7AD-4855-A910-27AD93EEC51E}C:\users\matej\appdata\local\temp\winaxnmu.exe -> profile=public | protocol=17 | dir=in | action=block | name=winaxnmu.exe | app=c:\users\matej\appdata\local\temp\winaxnmu.exe |
YN -> UDP Query User{42CE71F3-8097-44D1-B17F-CC664BB534D1}C:\users\matej\appdata\local\temp\ymmxna.exe -> profile=public | protocol=17 | dir=in | action=block | name=ymmxna.exe | app=c:\users\matej\appdata\local\temp\ymmxna.exe |
YN -> UDP Query User{45B4E77A-8F19-45D0-96CB-85778DF7F80A}C:\users\matej\appdata\local\temp\fqhjtf.exe -> profile=public | protocol=17 | dir=in | action=block | name=fqhjtf.exe | app=c:\users\matej\appdata\local\temp\fqhjtf.exe |
YN -> UDP Query User{578DDDCF-C658-4165-89E6-0079E16805FB}C:\users\matej\appdata\local\temp\winfhbchg.exe -> profile=public | protocol=17 | dir=in | action=block | name=winfhbchg.exe | app=c:\users\matej\appdata\local\temp\winfhbchg.exe |
YN -> UDP Query User{B31ADEF1-AB29-40D3-ADB2-2CA40DE89DA2}C:\users\matej\appdata\local\temp\wingjygin.exe -> profile=public | protocol=17 | dir=in | action=block | name=wingjygin.exe | app=c:\users\matej\appdata\local\temp\wingjygin.exe |
< Drives with AutoRun files > ->
NY -> C:\autorun.inf -> C:\autorun.inf [ NTFS ]
NY -> D:\autorun.inf -> D:\autorun.inf [ NTFS ]
[Files/Folders - Modified Within 30 Days]
NY -> bxubf.exe -> C:\bxubf.exe
NY -> autorun.inf -> C:\autorun.inf
NY -> 4 C:\Users\Matej\AppData\Local\Temp\*.tmp files -> C:\Users\Matej\AppData\Local\Temp\*.tmp
[Files - No Company Name]
NY -> bxubf.exe -> C:\bxubf.exe
NY -> autorun.inf -> C:\autorun.inf
[Custom Scans]
YY -> bxubf.exe -> C:\bxubf.exe
[Purity]
[Empty Temp Folders]
[EmptyFlash]
[EmptyJava]
[Reboot]
-klik na RUN FIX
-log koji dobiješ kopiraj
2.skini comborfix i spremi na desktop
-isključi antivirus i malwarebytes realtime
-pokreni combofix i na sve što traži odgovori potvrdno
-log koji dobiješ ćeš isto tako kopirati
ipak je samo crv/worm u pitanju..ništa strašno
vrlo vjerojatno si se zarazio umetanjem usbstika u računalo
ako imaš stik, nemoj ga kopčati u računalo, njega ćemo kasnije očistiti
OTS zablokirao 2 puta , stoga njega nisam . Evo onaj drugi
ComboFix 12-04-23.02 - Matej 3.04.2012. 20:36:04.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.385.1033.18.4095.3109 [GMT 2:00]
Running from: c:\users\Matej\Downloads\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\autorun.inf
c:\windows\wstwf.log
D:\Autorun.inf
D:\itma.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-03-23 to 2012-04-23 )))))))))))))))))))))))))))))))
.
.
2012-04-23 18:38 . 2012-04-23 18:38 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-04-23 18:22 . 2012-04-23 18:22 -------- d-----w- C:\_OTS
2012-04-23 15:01 . 2012-04-23 15:01 99328 ----a-w- C:\bxubf.exe
2012-04-23 14:55 . 2012-04-23 14:55 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-04-23 14:55 . 2012-04-23 14:55 -------- d-----w- c:\programdata\Malwarebytes
2012-04-23 14:55 . 2012-04-04 13:56 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-04-23 13:37 . 2012-04-23 13:37 162664 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10140.bin
2012-04-23 00:17 . 2012-04-22 14:25 -------- d-----w- c:\windows\Panther
2012-04-22 18:57 . 2012-04-22 18:57 -------- d-----w- c:\program files\TeamSpeak 3 Client
2012-04-22 16:46 . 2012-04-23 17:20 271200 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-04-22 15:39 . 2012-04-22 15:39 -------- d-----w- c:\program files (x86)\MSECache
2012-04-22 15:23 . 2012-04-22 15:24 -------- d-----w- c:\programdata\Xfire
2012-04-22 15:23 . 2012-04-22 15:23 -------- d-----w- c:\program files (x86)\Xfire
2012-04-22 15:13 . 2012-04-23 17:20 271200 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-04-22 15:13 . 2012-04-23 16:54 271200 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-04-22 15:13 . 2012-04-23 15:27 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-04-22 15:10 . 2012-04-22 15:10 -------- d-----w- c:\program files (x86)\Activision
2012-04-22 14:44 . 2012-04-22 14:44 -------- d-----w- c:\windows\SysWow64\Wat
2012-04-22 14:44 . 2012-04-22 14:44 -------- d-----w- c:\windows\system32\Wat
2012-04-22 14:39 . 2012-04-22 14:39 -------- d-----w- c:\program files (x86)\Common Files\LogiShrd
2012-04-22 14:39 . 2012-04-22 14:39 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2012-04-22 14:39 . 2012-04-22 14:39 -------- d-----w- c:\programdata\Logishrd
2012-04-22 14:39 . 2012-04-22 14:39 -------- d-----w- c:\program files\Logitech
2012-04-22 14:38 . 2012-04-22 14:39 -------- d-----w- c:\program files\Common Files\Logishrd
2012-04-22 14:33 . 2012-04-22 14:33 -------- d-----w- c:\programdata\ATI
2012-04-22 14:31 . 2012-04-23 15:15 -------- d-----w- c:\program files (x86)\InstallShield Installation Information
2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files (x86)\AMD AVT
2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files\AMD
2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files (x86)\AMD
2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files (x86)\AMD APP
2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files\Common Files\ATI Technologies
2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files (x86)\Common Files\ATI Technologies
2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\programdata\AMD
2012-04-22 14:28 . 2010-02-18 07:18 46136 ----a-w- c:\windows\system32\drivers\amdiox64.sys
2012-04-22 14:27 . 2012-04-22 14:27 -------- d-----w- c:\program files (x86)\ATI Technologies
2012-04-22 14:27 . 2012-04-23 15:19 -------- d-sh--w- c:\windows\Installer
2012-04-22 14:27 . 2012-04-22 14:28 -------- d-----w- c:\program files\ATI Technologies
2012-04-22 14:27 . 2012-04-22 14:27 -------- d-----w- c:\program files\ATI
2012-04-22 14:26 . 2012-04-22 14:26 -------- d-----w- C:\AMD
2012-04-22 14:25 . 2012-04-22 14:25 -------- d-----w- c:\users\Matej
2012-04-22 14:25 . 2012-04-22 14:25 -------- d-----w- C:\Recovery
2012-04-22 14:20 . 2012-04-22 14:20 0 ----a-w- c:\windows\ativpsrm.bin
2012-04-17 05:31 . 2012-04-17 05:31 42392 ----a-w- c:\windows\SysWow64\xfcodec.dll
2012-04-17 05:31 . 2012-04-17 05:31 28056 ----a-w- c:\windows\system32\xfcodec64.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-22 14:44 . 2010-11-21 03:24 14848 ----a-w- c:\windows\system32\slwga.dll
2012-04-22 14:44 . 2010-11-21 03:24 419840 ----a-w- c:\windows\system32\systemcpl.dll
2012-04-22 14:44 . 2010-11-21 03:23 13824 ----a-w- c:\windows\SysWow64\slwga.dll
2012-04-22 14:44 . 2010-11-21 03:24 833024 ----a-w- c:\windows\SysWow64\user32.dll
2012-04-22 14:44 . 2010-11-21 03:24 1008640 ----a-w- c:\windows\system32\user32.dll
2012-02-15 03:48 . 2012-02-15 03:48 10856960 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2012-02-15 03:21 . 2012-02-15 03:21 25839104 ----a-w- c:\windows\system32\atio6axx.dll
2012-02-15 03:18 . 2012-02-15 03:18 159744 ----a-w- c:\windows\system32\atiapfxx.exe
2012-02-15 03:18 . 2012-02-15 03:18 791040 ----a-w- c:\windows\SysWow64\aticfx32.dll
2012-02-15 03:17 . 2012-02-15 03:17 957952 ----a-w- c:\windows\system32\aticfx64.dll
2012-02-15 03:13 . 2012-02-15 03:13 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll
2012-02-15 03:13 . 2012-02-15 03:13 496128 ----a-w- c:\windows\system32\atieclxx.exe
2012-02-15 03:13 . 2012-02-15 03:13 235520 ----a-w- c:\windows\system32\atiesrxx.exe
2012-02-15 03:11 . 2012-02-15 03:11 120320 ----a-w- c:\windows\system32\atitmm64.dll
2012-02-15 03:10 . 2012-02-15 03:10 21504 ----a-w- c:\windows\system32\atimuixx.dll
2012-02-15 03:10 . 2012-02-15 03:10 59392 ----a-w- c:\windows\system32\atiedu64.dll
2012-02-15 03:10 . 2012-02-15 03:10 43520 ----a-w- c:\windows\SysWow64\ati2edxx.dll
2012-02-15 03:07 . 2012-02-15 03:07 6200320 ----a-w- c:\windows\SysWow64\atidxx32.dll
2012-02-15 02:58 . 2012-02-15 02:58 19392000 ----a-w- c:\windows\SysWow64\atioglxx.dll
2012-02-15 02:52 . 2009-07-13 21:59 7646208 ----a-w- c:\windows\system32\atidxx64.dll
2012-02-15 02:41 . 2012-02-15 02:41 1113088 ----a-w- c:\windows\system32\atiumd6v.dll
2012-02-15 02:40 . 2012-02-15 02:40 1828864 ----a-w- c:\windows\SysWow64\atiumdmv.dll
2012-02-15 02:40 . 2012-02-15 02:40 4958208 ----a-w- c:\windows\system32\atiumd6a.dll
2012-02-15 02:34 . 2012-02-15 02:34 51200 ----a-w- c:\windows\system32\aticalrt64.dll
2012-02-15 02:34 . 2012-02-15 02:34 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll
2012-02-15 02:34 . 2012-02-15 02:34 44544 ----a-w- c:\windows\system32\aticalcl64.dll
2012-02-15 02:34 . 2012-02-15 02:34 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll
2012-02-15 02:34 . 2012-02-15 02:34 5954048 ----a-w- c:\windows\SysWow64\atiumdag.dll
2012-02-15 02:34 . 2012-02-15 02:34 13859840 ----a-w- c:\windows\system32\aticaldd64.dll
2012-02-15 02:29 . 2012-02-15 02:29 5062656 ----a-w- c:\windows\SysWow64\atiumdva.dll
2012-02-15 02:29 . 2012-02-15 02:29 11561984 ----a-w- c:\windows\SysWow64\aticaldd.dll
2012-02-15 02:25 . 2012-02-15 02:25 7551488 ----a-w- c:\windows\system32\atiumd64.dll
2012-02-15 02:16 . 2012-02-15 02:16 58880 ----a-w- c:\windows\system32\coinst.dll
2012-02-15 02:14 . 2012-02-15 02:14 512000 ----a-w- c:\windows\system32\atiadlxx.dll
2012-02-15 02:13 . 2012-02-15 02:13 356352 ----a-w- c:\windows\SysWow64\atiadlxy.dll
2012-02-15 02:13 . 2012-02-15 02:13 17408 ----a-w- c:\windows\system32\atig6pxx.dll
2012-02-15 02:13 . 2012-02-15 02:13 14336 ----a-w- c:\windows\SysWow64\atiglpxx.dll
2012-02-15 02:13 . 2012-02-15 02:13 14336 ----a-w- c:\windows\system32\atiglpxx.dll
2012-02-15 02:13 . 2012-02-15 02:13 39936 ----a-w- c:\windows\system32\atig6txx.dll
2012-02-15 02:13 . 2012-02-15 02:13 33280 ----a-w- c:\windows\SysWow64\atigktxx.dll
2012-02-15 02:13 . 2012-02-15 02:13 327680 ----a-w- c:\windows\system32\drivers\atikmpag.sys
2012-02-15 02:12 . 2012-02-15 02:12 43008 ----a-w- c:\windows\system32\atiuxp64.dll
2012-02-15 02:12 . 2012-02-15 02:12 33280 ----a-w- c:\windows\SysWow64\atiuxpag.dll
2012-02-15 02:12 . 2012-02-15 02:12 39936 ----a-w- c:\windows\system32\atiu9p64.dll
2012-02-15 02:12 . 2012-02-15 02:12 30208 ----a-w- c:\windows\SysWow64\atiu9pag.dll
2012-02-15 02:11 . 2012-02-15 02:11 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2012-02-15 02:11 . 2012-02-15 02:11 54784 ----a-w- c:\windows\system32\atimpc64.dll
2012-02-15 02:11 . 2012-02-15 02:11 54784 ----a-w- c:\windows\system32\amdpcom64.dll
2012-02-15 02:11 . 2012-02-15 02:11 53760 ----a-w- c:\windows\SysWow64\atimpc32.dll
2012-02-15 02:11 . 2012-02-15 02:11 53760 ----a-w- c:\windows\SysWow64\amdpcom32.dll
2012-02-14 20:05 . 2012-02-14 20:05 69632 ----a-w- c:\windows\system32\OpenVideo64.dll
2012-02-14 20:05 . 2012-02-14 20:05 59904 ----a-w- c:\windows\SysWow64\OpenVideo.dll
2012-02-14 20:05 . 2012-02-14 20:05 61952 ----a-w- c:\windows\system32\OVDecode64.dll
2012-02-14 20:05 . 2012-02-14 20:05 54784 ----a-w- c:\windows\SysWow64\OVDecode.dll
2012-02-14 20:05 . 2012-02-14 20:05 16507904 ----a-w- c:\windows\system32\amdocl64.dll
2012-02-14 20:04 . 2012-02-14 20:04 13238272 ----a-w- c:\windows\SysWow64\amdocl.dll
2012-02-14 20:03 . 2012-02-14 20:03 54272 ----a-w- c:\windows\system32\OpenCL.dll
2012-02-14 20:03 . 2012-02-14 20:03 48128 ----a-w- c:\windows\SysWow64\OpenCL.dll
2012-01-31 04:02 . 2012-01-31 04:02 21504 ----a-w- c:\windows\system32\kdbsdk64.dll
2012-01-31 04:00 . 2012-01-31 04:00 16896 ----a-w- c:\windows\SysWow64\kdbsdk32.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2010-11-21 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
[-] 2012-04-22 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7601.17514] .. c:\windows\system32\user32.dll
.
[-] 2012-04-22 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7601.17514] .. c:\windows\SysWOW64\user32.dll
[7] 2010-11-21 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Facebook Update"="c:\users\Matej\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-04-22 203072]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-02-14 705664]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2009-09-21 2583040]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
.
c:\users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech . Registracija proizvoda.lnk - c:\program files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe [2009-11-16 587016]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
AML Device Install.lnk - c:\program files (x86)\AMD AVT\bin\kdbsync.exe [2012-1-31 80384]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
.
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [x]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-02-14 361984]
S2 AODDriver4.1;AODDriver4.1;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-01-03 55936]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [x]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2012-04-23 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000Core.job
- c:\users\Matej\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-22 14:38]
.
2012-04-23 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000UA.job
- c:\users\Matej\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-22 14:38]
.
2012-04-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000Core.job
- c:\users\Matej\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-22 14:31]
.
2012-04-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000UA.job
- c:\users\Matej\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-22 14:31]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-10-07 1744152]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: Interfaces\{E9CECB3F-8087-43C5-BD75-791E5EFE03C0}: NameServer = 8.8.8.8,4.4.8.8
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\windows\SysWOW64\PnkBstrA.exe
.
**************************************************************************
.
Completion time: 2012-04-23 20:42:03 - machine was rebooted
ComboFix-quarantined-files.txt 2012-04-23 18:42
.
Pre-Run: 163.620.474.880 bytes free
Post-Run: 163.356.950.528 bytes free
.
- - End Of File - - B40DF0478BA6406DBAFD0B586CBA68F7
otvori notepad i ovo kopiraj u notepad
KIllAll::
ClearJavaCache::
File::
C:\bxubf.exe
c:\users\matej\appdata\local\temp\ymmxna.exe
c:\users\matej\appdata\local\temp\wingjygin.exe
c:\users\matej\appdata\local\temp\winfhbchg.exe
C:\users\matej\appdata\local\temp\fqhjtf.exe
c:\users\matej\appdata\local\temp\winaxnmu.exe
C:\users\matej\appdata\local\temp\winhcvrlg.exe
Filelook::
c:\windows\system32\user32.dll
zatvori notepad i spremi kao CFScript na desktop
-isključi antivirus i malwarebytes
-skriptu s mišem uvuci u combofix.exe
-log koji dobiješ kopiraj
2. za USB stick
-skini ovaj program i spremi ga na desktop
-pokreni usbnorisk i saćekaj desetak sekundi
-ubaci stik u računalo (ako imaš više stikova, ubacuj jedan po jedan i zapamti ili zapiši koji je prvi ,drugi itd.
-sacekaj desetak sekundi
-desni klik mišem na sred prozora i odaberi opciju save scrambled log
-log kopiraj
Sa skriptom
ComboFix 12-04-24.02 - Matej 4.04.2012. 15:10:20.2.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.385.1033.18.4095.2777 [GMT 2:00]
Running from: c:\users\Matej\Downloads\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\autorun.inf
C:\jukyy.pif
c:\windows\wstwf.log
D:\Autorun.inf
D:\igwr.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-03-24 to 2012-04-24 )))))))))))))))))))))))))))))))
.
.
2012-04-24 13:13 . 2012-04-24 13:13 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-04-23 19:28 . 2012-04-23 19:28 -------- d-----w- c:\program files (x86)\VirtualDJ
2012-04-23 18:22 . 2012-04-23 18:22 -------- d-----w- C:\_OTS
2012-04-23 14:55 . 2012-04-23 14:55 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-04-23 14:55 . 2012-04-23 14:55 -------- d-----w- c:\programdata\Malwarebytes
2012-04-23 14:55 . 2012-04-04 13:56 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-04-23 13:37 . 2012-04-23 13:37 162664 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10140.bin
2012-04-23 00:17 . 2012-04-22 14:25 -------- d-----w- c:\windows\Panther
2012-04-22 18:57 . 2012-04-22 18:57 -------- d-----w- c:\program files\TeamSpeak 3 Client
2012-04-22 16:46 . 2012-04-24 11:11 271200 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-04-22 15:39 . 2012-04-22 15:39 -------- d-----w- c:\program files (x86)\MSECache
2012-04-22 15:23 . 2012-04-22 15:24 -------- d-----w- c:\programdata\Xfire
2012-04-22 15:23 . 2012-04-22 15:23 -------- d-----w- c:\program files (x86)\Xfire
2012-04-22 15:13 . 2012-04-24 11:11 271200 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-04-22 15:13 . 2012-04-24 11:10 103736 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-04-22 15:13 . 2012-04-24 06:41 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-04-22 15:10 . 2012-04-22 15:10 -------- d-----w- c:\program files (x86)\Activision
2012-04-22 14:44 . 2012-04-22 14:44 -------- d-----w- c:\windows\SysWow64\Wat
2012-04-22 14:44 . 2012-04-22 14:44 -------- d-----w- c:\windows\system32\Wat
2012-04-22 14:39 . 2012-04-22 14:39 -------- d-----w- c:\program files (x86)\Common Files\LogiShrd
2012-04-22 14:39 . 2012-04-22 14:39 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2012-04-22 14:39 . 2012-04-22 14:39 -------- d-----w- c:\programdata\Logishrd
2012-04-22 14:39 . 2012-04-22 14:39 -------- d-----w- c:\program files\Logitech
2012-04-22 14:38 . 2012-04-22 14:39 -------- d-----w- c:\program files\Common Files\Logishrd
2012-04-22 14:33 . 2012-04-22 14:33 -------- d-----w- c:\programdata\ATI
2012-04-22 14:31 . 2012-04-23 19:12 -------- d-----w- c:\program files (x86)\InstallShield Installation Information
2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files (x86)\AMD AVT
2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files\AMD
2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files (x86)\AMD
2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files (x86)\AMD APP
2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files\Common Files\ATI Technologies
2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files (x86)\Common Files\ATI Technologies
2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\programdata\AMD
2012-04-22 14:28 . 2010-02-18 07:18 46136 ----a-w- c:\windows\system32\drivers\amdiox64.sys
2012-04-22 14:27 . 2012-04-22 14:27 -------- d-----w- c:\program files (x86)\ATI Technologies
2012-04-22 14:27 . 2012-04-23 19:28 -------- d-sh--w- c:\windows\Installer
2012-04-22 14:27 . 2012-04-22 14:28 -------- d-----w- c:\program files\ATI Technologies
2012-04-22 14:27 . 2012-04-22 14:27 -------- d-----w- c:\program files\ATI
2012-04-22 14:26 . 2012-04-22 14:26 -------- d-----w- C:\AMD
2012-04-22 14:25 . 2012-04-22 14:25 -------- d-----w- c:\users\Matej
2012-04-22 14:25 . 2012-04-22 14:25 -------- d-----w- C:\Recovery
2012-04-22 14:20 . 2012-04-22 14:20 0 ----a-w- c:\windows\ativpsrm.bin
2012-04-17 05:31 . 2012-04-17 05:31 42392 ----a-w- c:\windows\SysWow64\xfcodec.dll
2012-04-17 05:31 . 2012-04-17 05:31 28056 ----a-w- c:\windows\system32\xfcodec64.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-22 14:44 . 2010-11-21 03:24 14848 ----a-w- c:\windows\system32\slwga.dll
2012-04-22 14:44 . 2010-11-21 03:24 419840 ----a-w- c:\windows\system32\systemcpl.dll
2012-04-22 14:44 . 2010-11-21 03:23 13824 ----a-w- c:\windows\SysWow64\slwga.dll
2012-04-22 14:44 . 2010-11-21 03:24 833024 ----a-w- c:\windows\SysWow64\user32.dll
2012-04-22 14:44 . 2010-11-21 03:24 1008640 ----a-w- c:\windows\system32\user32.dll
2012-02-15 03:48 . 2012-02-15 03:48 10856960 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2012-02-15 03:21 . 2012-02-15 03:21 25839104 ----a-w- c:\windows\system32\atio6axx.dll
2012-02-15 03:18 . 2012-02-15 03:18 159744 ----a-w- c:\windows\system32\atiapfxx.exe
2012-02-15 03:18 . 2012-02-15 03:18 791040 ----a-w- c:\windows\SysWow64\aticfx32.dll
2012-02-15 03:17 . 2012-02-15 03:17 957952 ----a-w- c:\windows\system32\aticfx64.dll
2012-02-15 03:13 . 2012-02-15 03:13 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll
2012-02-15 03:13 . 2012-02-15 03:13 496128 ----a-w- c:\windows\system32\atieclxx.exe
2012-02-15 03:13 . 2012-02-15 03:13 235520 ----a-w- c:\windows\system32\atiesrxx.exe
2012-02-15 03:11 . 2012-02-15 03:11 120320 ----a-w- c:\windows\system32\atitmm64.dll
2012-02-15 03:10 . 2012-02-15 03:10 21504 ----a-w- c:\windows\system32\atimuixx.dll
2012-02-15 03:10 . 2012-02-15 03:10 59392 ----a-w- c:\windows\system32\atiedu64.dll
2012-02-15 03:10 . 2012-02-15 03:10 43520 ----a-w- c:\windows\SysWow64\ati2edxx.dll
2012-02-15 03:07 . 2012-02-15 03:07 6200320 ----a-w- c:\windows\SysWow64\atidxx32.dll
2012-02-15 02:58 . 2012-02-15 02:58 19392000 ----a-w- c:\windows\SysWow64\atioglxx.dll
2012-02-15 02:52 . 2009-07-13 21:59 7646208 ----a-w- c:\windows\system32\atidxx64.dll
2012-02-15 02:41 . 2012-02-15 02:41 1113088 ----a-w- c:\windows\system32\atiumd6v.dll
2012-02-15 02:40 . 2012-02-15 02:40 1828864 ----a-w- c:\windows\SysWow64\atiumdmv.dll
2012-02-15 02:40 . 2012-02-15 02:40 4958208 ----a-w- c:\windows\system32\atiumd6a.dll
2012-02-15 02:34 . 2012-02-15 02:34 51200 ----a-w- c:\windows\system32\aticalrt64.dll
2012-02-15 02:34 . 2012-02-15 02:34 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll
2012-02-15 02:34 . 2012-02-15 02:34 44544 ----a-w- c:\windows\system32\aticalcl64.dll
2012-02-15 02:34 . 2012-02-15 02:34 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll
2012-02-15 02:34 . 2012-02-15 02:34 5954048 ----a-w- c:\windows\SysWow64\atiumdag.dll
2012-02-15 02:34 . 2012-02-15 02:34 13859840 ----a-w- c:\windows\system32\aticaldd64.dll
2012-02-15 02:29 . 2012-02-15 02:29 5062656 ----a-w- c:\windows\SysWow64\atiumdva.dll
2012-02-15 02:29 . 2012-02-15 02:29 11561984 ----a-w- c:\windows\SysWow64\aticaldd.dll
2012-02-15 02:25 . 2012-02-15 02:25 7551488 ----a-w- c:\windows\system32\atiumd64.dll
2012-02-15 02:16 . 2012-02-15 02:16 58880 ----a-w- c:\windows\system32\coinst.dll
2012-02-15 02:14 . 2012-02-15 02:14 512000 ----a-w- c:\windows\system32\atiadlxx.dll
2012-02-15 02:13 . 2012-02-15 02:13 356352 ----a-w- c:\windows\SysWow64\atiadlxy.dll
2012-02-15 02:13 . 2012-02-15 02:13 17408 ----a-w- c:\windows\system32\atig6pxx.dll
2012-02-15 02:13 . 2012-02-15 02:13 14336 ----a-w- c:\windows\SysWow64\atiglpxx.dll
2012-02-15 02:13 . 2012-02-15 02:13 14336 ----a-w- c:\windows\system32\atiglpxx.dll
2012-02-15 02:13 . 2012-02-15 02:13 39936 ----a-w- c:\windows\system32\atig6txx.dll
2012-02-15 02:13 . 2012-02-15 02:13 33280 ----a-w- c:\windows\SysWow64\atigktxx.dll
2012-02-15 02:13 . 2012-02-15 02:13 327680 ----a-w- c:\windows\system32\drivers\atikmpag.sys
2012-02-15 02:12 . 2012-02-15 02:12 43008 ----a-w- c:\windows\system32\atiuxp64.dll
2012-02-15 02:12 . 2012-02-15 02:12 33280 ----a-w- c:\windows\SysWow64\atiuxpag.dll
2012-02-15 02:12 . 2012-02-15 02:12 39936 ----a-w- c:\windows\system32\atiu9p64.dll
2012-02-15 02:12 . 2012-02-15 02:12 30208 ----a-w- c:\windows\SysWow64\atiu9pag.dll
2012-02-15 02:11 . 2012-02-15 02:11 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2012-02-15 02:11 . 2012-02-15 02:11 54784 ----a-w- c:\windows\system32\atimpc64.dll
2012-02-15 02:11 . 2012-02-15 02:11 54784 ----a-w- c:\windows\system32\amdpcom64.dll
2012-02-15 02:11 . 2012-02-15 02:11 53760 ----a-w- c:\windows\SysWow64\atimpc32.dll
2012-02-15 02:11 . 2012-02-15 02:11 53760 ----a-w- c:\windows\SysWow64\amdpcom32.dll
2012-02-14 20:05 . 2012-02-14 20:05 69632 ----a-w- c:\windows\system32\OpenVideo64.dll
2012-02-14 20:05 . 2012-02-14 20:05 59904 ----a-w- c:\windows\SysWow64\OpenVideo.dll
2012-02-14 20:05 . 2012-02-14 20:05 61952 ----a-w- c:\windows\system32\OVDecode64.dll
2012-02-14 20:05 . 2012-02-14 20:05 54784 ----a-w- c:\windows\SysWow64\OVDecode.dll
2012-02-14 20:05 . 2012-02-14 20:05 16507904 ----a-w- c:\windows\system32\amdocl64.dll
2012-02-14 20:04 . 2012-02-14 20:04 13238272 ----a-w- c:\windows\SysWow64\amdocl.dll
2012-02-14 20:03 . 2012-02-14 20:03 54272 ----a-w- c:\windows\system32\OpenCL.dll
2012-02-14 20:03 . 2012-02-14 20:03 48128 ----a-w- c:\windows\SysWow64\OpenCL.dll
2012-01-31 04:02 . 2012-01-31 04:02 21504 ----a-w- c:\windows\system32\kdbsdk64.dll
2012-01-31 04:00 . 2012-01-31 04:00 16896 ----a-w- c:\windows\SysWow64\kdbsdk32.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2010-11-21 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
[-] 2012-04-22 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7601.17514] .. c:\windows\system32\user32.dll
.
[-] 2012-04-22 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7601.17514] .. c:\windows\SysWOW64\user32.dll
[7] 2010-11-21 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
.
((((((((((((((((((((((((((((( SnapShot@2012-04-23_18.39.54 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-11-21 03:09 . 2012-04-23 18:41 11134 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-04-23 18:41 28006 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2012-04-22 14:22 . 2012-04-22 16:13 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2012-04-22 14:22 . 2012-04-24 11:16 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2012-04-22 14:22 . 2012-04-24 11:16 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2012-04-22 14:22 . 2012-04-22 16:13 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2012-04-22 16:13 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2012-04-24 11:16 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2012-04-22 17:11 . 2012-04-23 18:14 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2012-04-22 17:11 . 2012-04-24 13:04 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2012-04-22 17:11 . 2012-04-23 18:14 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-04-22 17:11 . 2012-04-24 13:04 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2012-04-23 15:19 . 2012-04-23 15:19 10134 c:\windows\Installer\{931C37FC-594D-43A9-B10F-A2F2B1F03498}\ARPPRODUCTICON.exe
+ 2012-04-23 19:19 . 2012-04-23 19:19 10134 c:\windows\Installer\{931C37FC-594D-43A9-B10F-A2F2B1F03498}\ARPPRODUCTICON.exe
+ 2012-04-23 19:18 . 2012-04-23 19:18 10134 c:\windows\Installer\{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}\ARPPRODUCTICON.exe
- 2012-04-23 15:18 . 2012-04-23 15:18 10134 c:\windows\Installer\{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}\ARPPRODUCTICON.exe
+ 2012-04-23 19:16 . 2012-04-23 19:16 10134 c:\windows\Installer\{3BD633E0-4BF8-4499-9149-88F0767D449C}\ARPPRODUCTICON.exe
- 2012-04-23 15:16 . 2012-04-23 15:16 10134 c:\windows\Installer\{3BD633E0-4BF8-4499-9149-88F0767D449C}\ARPPRODUCTICON.exe
- 2012-04-23 15:15 . 2012-04-23 15:15 10134 c:\windows\Installer\{050C1C8E-4A4D-4C2F-B9AE-67E60EE91B7F}\ARPPRODUCTICON.exe
+ 2012-04-23 19:15 . 2012-04-23 19:15 10134 c:\windows\Installer\{050C1C8E-4A4D-4C2F-B9AE-67E60EE91B7F}\ARPPRODUCTICON.exe
+ 2012-04-23 19:13 . 2012-04-23 19:13 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
- 2012-04-23 15:15 . 2012-04-23 15:15 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
- 2012-04-23 15:15 . 2012-04-23 15:15 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2012-04-23 19:13 . 2012-04-23 19:13 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2012-04-22 14:47 . 2012-04-23 18:41 2430 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3530914189-2052248754-1505902800-1000_UserData.bin
+ 2012-04-24 13:13 . 2012-04-24 13:13 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-04-24 13:13 . 2012-04-24 13:13 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-04-23 18:39 . 2012-04-23 18:39 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-04-22 21:00 . 2012-04-24 06:33 126666 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2009-07-14 04:45 . 2012-04-24 13:13 267560 c:\windows\system32\FNTCACHE.DAT
+ 2009-07-14 05:01 . 2012-04-24 13:13 227464 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2012-04-23 19:12 . 2012-04-23 19:12 216358 c:\windows\Installer\{E48469CC-635E-4FD5-A122-1497C286D217}\ARPPRODUCTICON.exe
- 2012-04-23 15:14 . 2012-04-23 15:14 216358 c:\windows\Installer\{E48469CC-635E-4FD5-A122-1497C286D217}\ARPPRODUCTICON.exe
- 2012-04-23 15:15 . 2012-04-23 15:15 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2012-04-23 19:13 . 2012-04-23 19:13 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
- 2012-04-23 15:15 . 2012-04-23 15:15 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2012-04-23 19:13 . 2012-04-23 19:13 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2012-04-23 19:13 . 2012-04-23 19:13 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
- 2012-04-23 15:15 . 2012-04-23 15:15 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2012-04-23 19:13 . 2012-04-23 19:13 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
- 2012-04-23 15:15 . 2012-04-23 15:15 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2012-04-23 19:13 . 2012-04-23 19:13 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
- 2012-04-23 15:15 . 2012-04-23 15:15 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2012-04-23 19:13 . 2012-04-23 19:13 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2012-04-23 15:15 . 2012-04-23 15:15 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2012-04-23 19:13 . 2012-04-23 19:13 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2012-04-23 15:15 . 2012-04-23 15:15 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2012-04-23 15:15 . 2012-04-23 15:15 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2012-04-23 19:13 . 2012-04-23 19:13 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2012-04-23 19:13 . 2012-04-23 19:13 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2012-04-23 15:15 . 2012-04-23 15:15 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2012-04-23 19:13 . 2012-04-23 19:13 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2012-04-23 15:15 . 2012-04-23 15:15 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2012-04-23 15:15 . 2012-04-23 15:15 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2012-04-23 19:13 . 2012-04-23 19:13 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2012-04-23 15:15 . 2012-04-23 15:15 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2012-04-23 19:13 . 2012-04-23 19:13 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2012-04-23 19:13 . 2012-04-23 19:13 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2012-04-23 15:15 . 2012-04-23 15:15 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2012-04-23 15:15 . 2012-04-23 15:15 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2012-04-23 19:13 . 2012-04-23 19:13 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2012-04-23 19:14 . 2012-04-23 19:14 5935104 c:\windows\Installer\18605a.msi
+ 2007-10-04 07:44 . 2007-10-04 07:44 8788992 c:\windows\Installer\186055.msi
- 2012-04-23 15:15 . 2012-04-23 15:15 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2012-04-23 19:13 . 2012-04-23 19:13 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2012-04-23 15:15 . 2012-04-23 15:15 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2012-04-23 19:13 . 2012-04-23 19:13 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2012-04-23 19:27 . 2012-04-23 19:27 37906529 c:\windows\Installer\186073.msi
+ 2012-04-23 19:18 . 2012-04-23 19:18 31356928 c:\windows\Installer\18606f.msi
+ 2012-04-23 19:15 . 2012-04-23 19:15 63715328 c:\windows\Installer\186061.msi
+ 2012-04-23 19:16 . 2012-04-23 19:16 287711232 c:\windows\Installer\186068.msi
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Facebook Update"="c:\users\Matej\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-04-22 203072]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-02-14 705664]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2009-09-21 2583040]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 536136]
.
c:\users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech . Registracija proizvoda.lnk - c:\program files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe [2009-11-16 587016]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
AML Device Install.lnk - c:\program files (x86)\AMD AVT\bin\kdbsync.exe [2012-1-31 80384]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
.
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [x]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-02-14 361984]
S2 AODDriver4.1;AODDriver4.1;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-01-03 55936]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [x]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-04-23 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000Core.job
- c:\users\Matej\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-22 14:38]
.
2012-04-24 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000UA.job
- c:\users\Matej\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-22 14:38]
.
2012-04-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000Core.job
- c:\users\Matej\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-22 14:31]
.
2012-04-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000UA.job
- c:\users\Matej\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-22 14:31]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-10-07 1744152]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: Interfaces\{E9CECB3F-8087-43C5-BD75-791E5EFE03C0}: NameServer = 8.8.8.8,4.4.8.8
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\windows\SysWOW64\PnkBstrA.exe
.
**************************************************************************
.
Completion time: 2012-04-24 15:15:26 - machine was rebooted
ComboFix-quarantined-files.txt 2012-04-24 13:15
ComboFix2.txt 2012-04-23 18:42
.
Pre-Run: 154.957.225.984 bytes free
Post-Run: 154.897.518.592 bytes free
.
- - End Of File - - 7C3246A9D355996F501D82E8BDFEBD8E
usb
nisi dobro uradio, combofix je pokrenut odavde
c:\users\Matej\Downloads\ComboFix.exe
a ovako bi trebalo biti
c:\users\Matej\Desktop\ComboFix.exe
prebaci combofix iz Downloads na Desktop /radna površina (copy/paste)
nakon toga skini CFScript i spremi na desktop
isključi obavezno malwarebtes realtime zaštitu
isključi antivirus relatime zaštitu
skriptu s mišem uvuci u combofix.exe
pogledaj sliku:
http://www.zaslike.com/viewer.php?file=xtsqjolxymnrz1np0vd.gif
pokreni malwarebytes >update>označi da skenira D:/ disk
log kopiraj
File lock detected (PID, locking process, locked file):
0x0A48 mbamgui.exe C:\aut[b][/b]orun.inf
0x0A48 mbamgui.exe C:\aut[b][/b]orun.inf
0x0A48 mbamgui.exe C:\aut[b][/b]orun.inf
0x0A48 mbamgui.exe C:\aut[b][/b]orun.inf
0x0A48 mbamgui.exe C:\aut[b][/b]orun.inf
Error renaming file C:\aut[b][/b]orun.inf
evo sad tako napravljeno
ComboFix 12-04-24.02 - Matej 4.04.2012. 20:15:33.3.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.385.1033.18.4095.3276 [GMT 2:00]
Running from: c:\users\Matej\Desktop\ComboFix.exe
Command switches used :: c:\users\Matej\Desktop\CFSCript.txt
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"C:\bxubf.exe"
"c:\users\matej\appdata\local\temp\fqhjtf.exe"
"c:\users\matej\appdata\local\temp\winaxnmu.exe"
"c:\users\matej\appdata\local\temp\winfhbchg.exe"
"c:\users\matej\appdata\local\temp\wingjygin.exe"
"c:\users\matej\appdata\local\temp\winhcvrlg.exe"
"c:\users\matej\appdata\local\temp\ymmxna.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\autorun.inf
c:\windows\wstwf.log
D:\Autorun.inf
.
.
((((((((((((((((((((((((( Files Created from 2012-03-24 to 2012-04-24 )))))))))))))))))))))))))))))))
.
.
2012-04-24 18:18 . 2012-04-24 18:18 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-04-24 13:17 . 2012-04-24 13:22 -------- d-----w- C:\USBNoRisk
2012-04-24 13:14 . 2012-04-24 13:14 99328 --sh--r- C:\mdpaqv.exe
2012-04-23 19:28 . 2012-04-23 19:28 -------- d-----w- c:\program files (x86)\VirtualDJ
2012-04-23 18:22 . 2012-04-23 18:22 -------- d-----w- C:\_OTS
2012-04-23 14:55 . 2012-04-23 14:55 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-04-23 14:55 . 2012-04-23 14:55 -------- d-----w- c:\programdata\Malwarebytes
2012-04-23 14:55 . 2012-04-04 13:56 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-04-23 13:37 . 2012-04-23 13:37 162664 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10140.bin
2012-04-23 00:17 . 2012-04-22 14:25 -------- d-----w- c:\windows\Panther
2012-04-22 18:57 . 2012-04-22 18:57 -------- d-----w- c:\program files\TeamSpeak 3 Client
2012-04-22 16:46 . 2012-04-24 11:11 271200 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-04-22 15:39 . 2012-04-22 15:39 -------- d-----w- c:\program files (x86)\MSECache
2012-04-22 15:23 . 2012-04-22 15:24 -------- d-----w- c:\programdata\Xfire
2012-04-22 15:23 . 2012-04-22 15:23 -------- d-----w- c:\program files (x86)\Xfire
2012-04-22 15:13 . 2012-04-24 11:11 271200 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-04-22 15:13 . 2012-04-24 11:10 103736 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-04-22 15:13 . 2012-04-24 06:41 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-04-22 15:10 . 2012-04-22 15:10 -------- d-----w- c:\program files (x86)\Activision
2012-04-22 14:44 . 2012-04-22 14:44 -------- d-----w- c:\windows\SysWow64\Wat
2012-04-22 14:44 . 2012-04-22 14:44 -------- d-----w- c:\windows\system32\Wat
2012-04-22 14:39 . 2012-04-22 14:39 -------- d-----w- c:\program files (x86)\Common Files\LogiShrd
2012-04-22 14:39 . 2012-04-22 14:39 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2012-04-22 14:39 . 2012-04-22 14:39 -------- d-----w- c:\programdata\Logishrd
2012-04-22 14:39 . 2012-04-22 14:39 -------- d-----w- c:\program files\Logitech
2012-04-22 14:38 . 2012-04-22 14:39 -------- d-----w- c:\program files\Common Files\Logishrd
2012-04-22 14:33 . 2012-04-22 14:33 -------- d-----w- c:\programdata\ATI
2012-04-22 14:31 . 2012-04-23 19:12 -------- d-----w- c:\program files (x86)\InstallShield Installation Information
2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files (x86)\AMD AVT
2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files\AMD
2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files (x86)\AMD
2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files (x86)\AMD APP
2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files\Common Files\ATI Technologies
2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files (x86)\Common Files\ATI Technologies
2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\programdata\AMD
2012-04-22 14:28 . 2010-02-18 07:18 46136 ----a-w- c:\windows\system32\drivers\amdiox64.sys
2012-04-22 14:27 . 2012-04-22 14:27 -------- d-----w- c:\program files (x86)\ATI Technologies
2012-04-22 14:27 . 2012-04-23 19:28 -------- d-sh--w- c:\windows\Installer
2012-04-22 14:27 . 2012-04-22 14:28 -------- d-----w- c:\program files\ATI Technologies
2012-04-22 14:27 . 2012-04-22 14:27 -------- d-----w- c:\program files\ATI
2012-04-22 14:26 . 2012-04-22 14:26 -------- d-----w- C:\AMD
2012-04-22 14:25 . 2012-04-22 14:25 -------- d-----w- c:\users\Matej
2012-04-22 14:25 . 2012-04-22 14:25 -------- d-----w- C:\Recovery
2012-04-22 14:20 . 2012-04-22 14:20 0 ----a-w- c:\windows\ativpsrm.bin
2012-04-17 05:31 . 2012-04-17 05:31 42392 ----a-w- c:\windows\SysWow64\xfcodec.dll
2012-04-17 05:31 . 2012-04-17 05:31 28056 ----a-w- c:\windows\system32\xfcodec64.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-22 14:44 . 2010-11-21 03:24 14848 ----a-w- c:\windows\system32\slwga.dll
2012-04-22 14:44 . 2010-11-21 03:24 419840 ----a-w- c:\windows\system32\systemcpl.dll
2012-04-22 14:44 . 2010-11-21 03:23 13824 ----a-w- c:\windows\SysWow64\slwga.dll
2012-04-22 14:44 . 2010-11-21 03:24 833024 ----a-w- c:\windows\SysWow64\user32.dll
2012-04-22 14:44 . 2010-11-21 03:24 1008640 ----a-w- c:\windows\system32\user32.dll
2012-02-15 03:48 . 2012-02-15 03:48 10856960 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2012-02-15 03:21 . 2012-02-15 03:21 25839104 ----a-w- c:\windows\system32\atio6axx.dll
2012-02-15 03:18 . 2012-02-15 03:18 159744 ----a-w- c:\windows\system32\atiapfxx.exe
2012-02-15 03:18 . 2012-02-15 03:18 791040 ----a-w- c:\windows\SysWow64\aticfx32.dll
2012-02-15 03:17 . 2012-02-15 03:17 957952 ----a-w- c:\windows\system32\aticfx64.dll
2012-02-15 03:13 . 2012-02-15 03:13 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll
2012-02-15 03:13 . 2012-02-15 03:13 496128 ----a-w- c:\windows\system32\atieclxx.exe
2012-02-15 03:13 . 2012-02-15 03:13 235520 ----a-w- c:\windows\system32\atiesrxx.exe
2012-02-15 03:11 . 2012-02-15 03:11 120320 ----a-w- c:\windows\system32\atitmm64.dll
2012-02-15 03:10 . 2012-02-15 03:10 21504 ----a-w- c:\windows\system32\atimuixx.dll
2012-02-15 03:10 . 2012-02-15 03:10 59392 ----a-w- c:\windows\system32\atiedu64.dll
2012-02-15 03:10 . 2012-02-15 03:10 43520 ----a-w- c:\windows\SysWow64\ati2edxx.dll
2012-02-15 03:07 . 2012-02-15 03:07 6200320 ----a-w- c:\windows\SysWow64\atidxx32.dll
2012-02-15 02:58 . 2012-02-15 02:58 19392000 ----a-w- c:\windows\SysWow64\atioglxx.dll
2012-02-15 02:52 . 2009-07-13 21:59 7646208 ----a-w- c:\windows\system32\atidxx64.dll
2012-02-15 02:41 . 2012-02-15 02:41 1113088 ----a-w- c:\windows\system32\atiumd6v.dll
2012-02-15 02:40 . 2012-02-15 02:40 1828864 ----a-w- c:\windows\SysWow64\atiumdmv.dll
2012-02-15 02:40 . 2012-02-15 02:40 4958208 ----a-w- c:\windows\system32\atiumd6a.dll
2012-02-15 02:34 . 2012-02-15 02:34 51200 ----a-w- c:\windows\system32\aticalrt64.dll
2012-02-15 02:34 . 2012-02-15 02:34 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll
2012-02-15 02:34 . 2012-02-15 02:34 44544 ----a-w- c:\windows\system32\aticalcl64.dll
2012-02-15 02:34 . 2012-02-15 02:34 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll
2012-02-15 02:34 . 2012-02-15 02:34 5954048 ----a-w- c:\windows\SysWow64\atiumdag.dll
2012-02-15 02:34 . 2012-02-15 02:34 13859840 ----a-w- c:\windows\system32\aticaldd64.dll
2012-02-15 02:29 . 2012-02-15 02:29 5062656 ----a-w- c:\windows\SysWow64\atiumdva.dll
2012-02-15 02:29 . 2012-02-15 02:29 11561984 ----a-w- c:\windows\SysWow64\aticaldd.dll
2012-02-15 02:25 . 2012-02-15 02:25 7551488 ----a-w- c:\windows\system32\atiumd64.dll
2012-02-15 02:16 . 2012-02-15 02:16 58880 ----a-w- c:\windows\system32\coinst.dll
2012-02-15 02:14 . 2012-02-15 02:14 512000 ----a-w- c:\windows\system32\atiadlxx.dll
2012-02-15 02:13 . 2012-02-15 02:13 356352 ----a-w- c:\windows\SysWow64\atiadlxy.dll
2012-02-15 02:13 . 2012-02-15 02:13 17408 ----a-w- c:\windows\system32\atig6pxx.dll
2012-02-15 02:13 . 2012-02-15 02:13 14336 ----a-w- c:\windows\SysWow64\atiglpxx.dll
2012-02-15 02:13 . 2012-02-15 02:13 14336 ----a-w- c:\windows\system32\atiglpxx.dll
2012-02-15 02:13 . 2012-02-15 02:13 39936 ----a-w- c:\windows\system32\atig6txx.dll
2012-02-15 02:13 . 2012-02-15 02:13 33280 ----a-w- c:\windows\SysWow64\atigktxx.dll
2012-02-15 02:13 . 2012-02-15 02:13 327680 ----a-w- c:\windows\system32\drivers\atikmpag.sys
2012-02-15 02:12 . 2012-02-15 02:12 43008 ----a-w- c:\windows\system32\atiuxp64.dll
2012-02-15 02:12 . 2012-02-15 02:12 33280 ----a-w- c:\windows\SysWow64\atiuxpag.dll
2012-02-15 02:12 . 2012-02-15 02:12 39936 ----a-w- c:\windows\system32\atiu9p64.dll
2012-02-15 02:12 . 2012-02-15 02:12 30208 ----a-w- c:\windows\SysWow64\atiu9pag.dll
2012-02-15 02:11 . 2012-02-15 02:11 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2012-02-15 02:11 . 2012-02-15 02:11 54784 ----a-w- c:\windows\system32\atimpc64.dll
2012-02-15 02:11 . 2012-02-15 02:11 54784 ----a-w- c:\windows\system32\amdpcom64.dll
2012-02-15 02:11 . 2012-02-15 02:11 53760 ----a-w- c:\windows\SysWow64\atimpc32.dll
2012-02-15 02:11 . 2012-02-15 02:11 53760 ----a-w- c:\windows\SysWow64\amdpcom32.dll
2012-02-14 20:05 . 2012-02-14 20:05 69632 ----a-w- c:\windows\system32\OpenVideo64.dll
2012-02-14 20:05 . 2012-02-14 20:05 59904 ----a-w- c:\windows\SysWow64\OpenVideo.dll
2012-02-14 20:05 . 2012-02-14 20:05 61952 ----a-w- c:\windows\system32\OVDecode64.dll
2012-02-14 20:05 . 2012-02-14 20:05 54784 ----a-w- c:\windows\SysWow64\OVDecode.dll
2012-02-14 20:05 . 2012-02-14 20:05 16507904 ----a-w- c:\windows\system32\amdocl64.dll
2012-02-14 20:04 . 2012-02-14 20:04 13238272 ----a-w- c:\windows\SysWow64\amdocl.dll
2012-02-14 20:03 . 2012-02-14 20:03 54272 ----a-w- c:\windows\system32\OpenCL.dll
2012-02-14 20:03 . 2012-02-14 20:03 48128 ----a-w- c:\windows\SysWow64\OpenCL.dll
2012-01-31 04:02 . 2012-01-31 04:02 21504 ----a-w- c:\windows\system32\kdbsdk64.dll
2012-01-31 04:00 . 2012-01-31 04:00 16896 ----a-w- c:\windows\SysWow64\kdbsdk32.dll
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
--- c:\windows\system32\user32.dll ---
Company: Microsoft Corporation
File Description: Multi-User Windows USER API Client DLL
File Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850)
Product Name: Microsoft® Windows® Operating System
Copyright: © Microsoft Corporation. All rights reserved.
Original Filename: user32
File size: 1008640
Created time: 2010-11-21 03:24
Modified time: 2012-04-22 14:44
MD5: 2C353B6CE0C8D03225CAA2AF33B68D79
SHA1: 785D332F0239071EABF74F1D1E2106F78B99A42A
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2010-11-21 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
[-] 2012-04-22 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7601.17514] .. c:\windows\system32\user32.dll
.
[-] 2012-04-22 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7601.17514] .. c:\windows\SysWOW64\user32.dll
[7] 2010-11-21 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
.
((((((((((((((((((((((((((((( SnapShot_2012-04-24_13.13.48 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-11-21 03:09 . 2012-04-24 18:15 12412 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-04-24 18:15 29386 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2009-07-14 05:30 . 2012-04-22 19:26 86016 c:\windows\system32\DriverStore\infpub.dat
+ 2009-07-14 05:30 . 2012-04-24 13:17 86016 c:\windows\system32\DriverStore\infpub.dat
+ 2012-04-22 17:11 . 2012-04-24 15:11 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2012-04-22 17:11 . 2012-04-24 13:04 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2012-04-22 17:11 . 2012-04-24 15:11 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2012-04-22 17:11 . 2012-04-24 13:04 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-04-22 14:47 . 2012-04-24 18:15 2978 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3530914189-2052248754-1505902800-1000_UserData.bin
+ 2012-04-24 18:18 . 2012-04-24 18:18 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-04-24 13:13 . 2012-04-24 13:13 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-04-24 18:18 . 2012-04-24 18:18 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-04-24 13:13 . 2012-04-24 13:13 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 05:30 . 2012-04-22 19:26 143360 c:\windows\system32\DriverStore\infstrng.dat
+ 2009-07-14 05:30 . 2012-04-24 13:17 143360 c:\windows\system32\DriverStore\infstrng.dat
+ 2009-07-14 00:21 . 2009-07-14 01:41 299520 c:\windows\system32\drivers\UMDF\WpdFs.dll
- 2009-07-14 05:01 . 2012-04-24 13:13 227464 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2012-04-24 18:18 227464 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Facebook Update"="c:\users\Matej\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-04-22 203072]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-02-14 705664]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2009-09-21 2583040]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 536136]
.
c:\users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech . Registracija proizvoda.lnk - c:\program files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe [2009-11-16 587016]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
AML Device Install.lnk - c:\program files (x86)\AMD AVT\bin\kdbsync.exe [2012-1-31 80384]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
.
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [x]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-02-14 361984]
S2 AODDriver4.1;AODDriver4.1;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-01-03 55936]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [x]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-04-24 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000Core.job
- c:\users\Matej\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-22 14:38]
.
2012-04-24 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000UA.job
- c:\users\Matej\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-22 14:38]
.
2012-04-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000Core.job
- c:\users\Matej\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-22 14:31]
.
2012-04-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000UA.job
- c:\users\Matej\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-22 14:31]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-10-07 1744152]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: Interfaces\{E9CECB3F-8087-43C5-BD75-791E5EFE03C0}: NameServer = 8.8.8.8,4.4.8.8
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files\Common Files\LogiShrd\sp6\LU\LULnchr.exe
.
**************************************************************************
.
Completion time: 2012-04-24 20:20:42 - machine was rebooted
ComboFix-quarantined-files.txt 2012-04-24 18:20
ComboFix2.txt 2012-04-24 13:15
ComboFix3.txt 2012-04-23 18:42
.
Pre-Run: 154.722.742.272 bytes free
Post-Run: 154.633.109.504 bytes free
.
- - End Of File - - E9142ECE3C8901A3C0BDF1197A4C8506
sad je već puno bolje, ostao je još samo jedan kojeg ćemo sad izbrisati
otvori notepad i ovo kopiraj u notepad
File::
C:\mdpaqv.exe
zatvori notepad i spremi kao CFScript na desktop
-isključi malwarebytes i antivirus
-skriptu s mišem uvuci u cmbofix.exe
-log kopiraj
2.ponovo pokreni usbnorisk i sačekaj desetak sekundi
-klik na tab script i ovo kopiraj u prazno polje
{0a59a926-8c86-11e1-86b4-806e6f6e6963}
folder_list:%DRIVE%
no_sh:
klik na run script
kad se skripta izvrši, desni klik mišem na sredprozora i odaberi save scrambled log
log kopiraj
jesi li pokrenio malwarebytes scan D:/ diska ?
Nisam skenirao D disk .. Nakon ovoga cu to provjeriti
Nisam skenirao D disk .. Nakon ovoga cu to provjeriti
nakon ovog koraka trebalo bi biti sve ok...imaš li i dalje konekcije na net nepoznatih programa ?
ja mislim da nemaš više :)
Nije ih bilo , samo moram reinstalirat sve igre ..
EDIT: Evo onaj zadnji s combofixom
ComboFix 12-04-25.01 - Matej 5.04.2012. 18:00:37.4.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.385.1033.18.4095.2841 [GMT 2:00]
Running from: c:\users\Matej\Desktop\ComboFix.exe
Command switches used :: c:\users\Matej\Desktop\CFScript.txt
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"C:\mdpaqv.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\autorun.inf
C:\mdpaqv.exe
c:\windows\wstwf.log
D:\Autorun.inf
D:\ilft.pif
.
.
((((((((((((((((((((((((( Files Created from 2012-03-25 to 2012-04-25 )))))))))))))))))))))))))))))))
.
.
2012-04-25 16:03 . 2012-04-25 16:03 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-04-24 18:19 . 2012-04-24 18:19 99328 --sh--r- C:\esops.exe
2012-04-24 13:17 . 2012-04-24 13:22 -------- d-----w- C:\USBNoRisk
2012-04-23 19:28 . 2012-04-23 19:28 -------- d-----w- c:\program files (x86)\VirtualDJ
2012-04-23 18:22 . 2012-04-23 18:22 -------- d-----w- C:\_OTS
2012-04-23 14:55 . 2012-04-23 14:55 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-04-23 14:55 . 2012-04-23 14:55 -------- d-----w- c:\programdata\Malwarebytes
2012-04-23 14:55 . 2012-04-04 13:56 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-04-23 13:37 . 2012-04-23 13:37 162664 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10140.bin
2012-04-23 00:17 . 2012-04-22 14:25 -------- d-----w- c:\windows\Panther
2012-04-22 18:57 . 2012-04-22 18:57 -------- d-----w- c:\program files\TeamSpeak 3 Client
2012-04-22 16:46 . 2012-04-24 11:11 271200 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-04-22 15:39 . 2012-04-22 15:39 -------- d-----w- c:\program files (x86)\MSECache
2012-04-22 15:23 . 2012-04-22 15:24 -------- d-----w- c:\programdata\Xfire
2012-04-22 15:23 . 2012-04-22 15:23 -------- d-----w- c:\program files (x86)\Xfire
2012-04-22 15:13 . 2012-04-24 11:11 271200 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-04-22 15:13 . 2012-04-24 11:10 103736 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-04-22 15:13 . 2012-04-24 06:41 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-04-22 15:10 . 2012-04-22 15:10 -------- d-----w- c:\program files (x86)\Activision
2012-04-22 14:44 . 2012-04-22 14:44 -------- d-----w- c:\windows\SysWow64\Wat
2012-04-22 14:44 . 2012-04-22 14:44 -------- d-----w- c:\windows\system32\Wat
2012-04-22 14:39 . 2012-04-22 14:39 -------- d-----w- c:\program files (x86)\Common Files\LogiShrd
2012-04-22 14:39 . 2012-04-22 14:39 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2012-04-22 14:39 . 2012-04-22 14:39 -------- d-----w- c:\programdata\Logishrd
2012-04-22 14:39 . 2012-04-22 14:39 -------- d-----w- c:\program files\Logitech
2012-04-22 14:38 . 2012-04-22 14:39 -------- d-----w- c:\program files\Common Files\Logishrd
2012-04-22 14:33 . 2012-04-22 14:33 -------- d-----w- c:\programdata\ATI
2012-04-22 14:31 . 2012-04-23 19:12 -------- d-----w- c:\program files (x86)\InstallShield Installation Information
2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files (x86)\AMD AVT
2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files\AMD
2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files (x86)\AMD
2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files (x86)\AMD APP
2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files\Common Files\ATI Technologies
2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\program files (x86)\Common Files\ATI Technologies
2012-04-22 14:28 . 2012-04-22 14:28 -------- d-----w- c:\programdata\AMD
2012-04-22 14:28 . 2010-02-18 07:18 46136 ----a-w- c:\windows\system32\drivers\amdiox64.sys
2012-04-22 14:27 . 2012-04-22 14:27 -------- d-----w- c:\program files (x86)\ATI Technologies
2012-04-22 14:27 . 2012-04-23 19:28 -------- d-sh--w- c:\windows\Installer
2012-04-22 14:27 . 2012-04-22 14:28 -------- d-----w- c:\program files\ATI Technologies
2012-04-22 14:27 . 2012-04-22 14:27 -------- d-----w- c:\program files\ATI
2012-04-22 14:26 . 2012-04-22 14:26 -------- d-----w- C:\AMD
2012-04-22 14:25 . 2012-04-22 14:25 -------- d-----w- c:\users\Matej
2012-04-22 14:25 . 2012-04-22 14:25 -------- d-----w- C:\Recovery
2012-04-22 14:20 . 2012-04-22 14:20 0 ----a-w- c:\windows\ativpsrm.bin
2012-04-17 05:31 . 2012-04-17 05:31 42392 ----a-w- c:\windows\SysWow64\xfcodec.dll
2012-04-17 05:31 . 2012-04-17 05:31 28056 ----a-w- c:\windows\system32\xfcodec64.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-22 14:44 . 2010-11-21 03:24 14848 ----a-w- c:\windows\system32\slwga.dll
2012-04-22 14:44 . 2010-11-21 03:24 419840 ----a-w- c:\windows\system32\systemcpl.dll
2012-04-22 14:44 . 2010-11-21 03:23 13824 ----a-w- c:\windows\SysWow64\slwga.dll
2012-04-22 14:44 . 2010-11-21 03:24 833024 ----a-w- c:\windows\SysWow64\user32.dll
2012-04-22 14:44 . 2010-11-21 03:24 1008640 ----a-w- c:\windows\system32\user32.dll
2012-02-15 03:48 . 2012-02-15 03:48 10856960 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2012-02-15 03:21 . 2012-02-15 03:21 25839104 ----a-w- c:\windows\system32\atio6axx.dll
2012-02-15 03:18 . 2012-02-15 03:18 159744 ----a-w- c:\windows\system32\atiapfxx.exe
2012-02-15 03:18 . 2012-02-15 03:18 791040 ----a-w- c:\windows\SysWow64\aticfx32.dll
2012-02-15 03:17 . 2012-02-15 03:17 957952 ----a-w- c:\windows\system32\aticfx64.dll
2012-02-15 03:13 . 2012-02-15 03:13 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll
2012-02-15 03:13 . 2012-02-15 03:13 496128 ----a-w- c:\windows\system32\atieclxx.exe
2012-02-15 03:13 . 2012-02-15 03:13 235520 ----a-w- c:\windows\system32\atiesrxx.exe
2012-02-15 03:11 . 2012-02-15 03:11 120320 ----a-w- c:\windows\system32\atitmm64.dll
2012-02-15 03:10 . 2012-02-15 03:10 21504 ----a-w- c:\windows\system32\atimuixx.dll
2012-02-15 03:10 . 2012-02-15 03:10 59392 ----a-w- c:\windows\system32\atiedu64.dll
2012-02-15 03:10 . 2012-02-15 03:10 43520 ----a-w- c:\windows\SysWow64\ati2edxx.dll
2012-02-15 03:07 . 2012-02-15 03:07 6200320 ----a-w- c:\windows\SysWow64\atidxx32.dll
2012-02-15 02:58 . 2012-02-15 02:58 19392000 ----a-w- c:\windows\SysWow64\atioglxx.dll
2012-02-15 02:52 . 2009-07-13 21:59 7646208 ----a-w- c:\windows\system32\atidxx64.dll
2012-02-15 02:41 . 2012-02-15 02:41 1113088 ----a-w- c:\windows\system32\atiumd6v.dll
2012-02-15 02:40 . 2012-02-15 02:40 1828864 ----a-w- c:\windows\SysWow64\atiumdmv.dll
2012-02-15 02:40 . 2012-02-15 02:40 4958208 ----a-w- c:\windows\system32\atiumd6a.dll
2012-02-15 02:34 . 2012-02-15 02:34 51200 ----a-w- c:\windows\system32\aticalrt64.dll
2012-02-15 02:34 . 2012-02-15 02:34 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll
2012-02-15 02:34 . 2012-02-15 02:34 44544 ----a-w- c:\windows\system32\aticalcl64.dll
2012-02-15 02:34 . 2012-02-15 02:34 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll
2012-02-15 02:34 . 2012-02-15 02:34 5954048 ----a-w- c:\windows\SysWow64\atiumdag.dll
2012-02-15 02:34 . 2012-02-15 02:34 13859840 ----a-w- c:\windows\system32\aticaldd64.dll
2012-02-15 02:29 . 2012-02-15 02:29 5062656 ----a-w- c:\windows\SysWow64\atiumdva.dll
2012-02-15 02:29 . 2012-02-15 02:29 11561984 ----a-w- c:\windows\SysWow64\aticaldd.dll
2012-02-15 02:25 . 2012-02-15 02:25 7551488 ----a-w- c:\windows\system32\atiumd64.dll
2012-02-15 02:16 . 2012-02-15 02:16 58880 ----a-w- c:\windows\system32\coinst.dll
2012-02-15 02:14 . 2012-02-15 02:14 512000 ----a-w- c:\windows\system32\atiadlxx.dll
2012-02-15 02:13 . 2012-02-15 02:13 356352 ----a-w- c:\windows\SysWow64\atiadlxy.dll
2012-02-15 02:13 . 2012-02-15 02:13 17408 ----a-w- c:\windows\system32\atig6pxx.dll
2012-02-15 02:13 . 2012-02-15 02:13 14336 ----a-w- c:\windows\SysWow64\atiglpxx.dll
2012-02-15 02:13 . 2012-02-15 02:13 14336 ----a-w- c:\windows\system32\atiglpxx.dll
2012-02-15 02:13 . 2012-02-15 02:13 39936 ----a-w- c:\windows\system32\atig6txx.dll
2012-02-15 02:13 . 2012-02-15 02:13 33280 ----a-w- c:\windows\SysWow64\atigktxx.dll
2012-02-15 02:13 . 2012-02-15 02:13 327680 ----a-w- c:\windows\system32\drivers\atikmpag.sys
2012-02-15 02:12 . 2012-02-15 02:12 43008 ----a-w- c:\windows\system32\atiuxp64.dll
2012-02-15 02:12 . 2012-02-15 02:12 33280 ----a-w- c:\windows\SysWow64\atiuxpag.dll
2012-02-15 02:12 . 2012-02-15 02:12 39936 ----a-w- c:\windows\system32\atiu9p64.dll
2012-02-15 02:12 . 2012-02-15 02:12 30208 ----a-w- c:\windows\SysWow64\atiu9pag.dll
2012-02-15 02:11 . 2012-02-15 02:11 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2012-02-15 02:11 . 2012-02-15 02:11 54784 ----a-w- c:\windows\system32\atimpc64.dll
2012-02-15 02:11 . 2012-02-15 02:11 54784 ----a-w- c:\windows\system32\amdpcom64.dll
2012-02-15 02:11 . 2012-02-15 02:11 53760 ----a-w- c:\windows\SysWow64\atimpc32.dll
2012-02-15 02:11 . 2012-02-15 02:11 53760 ----a-w- c:\windows\SysWow64\amdpcom32.dll
2012-02-14 20:05 . 2012-02-14 20:05 69632 ----a-w- c:\windows\system32\OpenVideo64.dll
2012-02-14 20:05 . 2012-02-14 20:05 59904 ----a-w- c:\windows\SysWow64\OpenVideo.dll
2012-02-14 20:05 . 2012-02-14 20:05 61952 ----a-w- c:\windows\system32\OVDecode64.dll
2012-02-14 20:05 . 2012-02-14 20:05 54784 ----a-w- c:\windows\SysWow64\OVDecode.dll
2012-02-14 20:05 . 2012-02-14 20:05 16507904 ----a-w- c:\windows\system32\amdocl64.dll
2012-02-14 20:04 . 2012-02-14 20:04 13238272 ----a-w- c:\windows\SysWow64\amdocl.dll
2012-02-14 20:03 . 2012-02-14 20:03 54272 ----a-w- c:\windows\system32\OpenCL.dll
2012-02-14 20:03 . 2012-02-14 20:03 48128 ----a-w- c:\windows\SysWow64\OpenCL.dll
2012-01-31 04:02 . 2012-01-31 04:02 21504 ----a-w- c:\windows\system32\kdbsdk64.dll
2012-01-31 04:00 . 2012-01-31 04:00 16896 ----a-w- c:\windows\SysWow64\kdbsdk32.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2010-11-21 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
[-] 2012-04-22 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7601.17514] .. c:\windows\system32\user32.dll
.
[-] 2012-04-22 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7601.17514] .. c:\windows\SysWOW64\user32.dll
[7] 2010-11-21 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
.
((((((((((((((((((((((((((((( SnapShot_2012-04-24_13.13.48 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-04-24 18:44 . 2010-06-02 02:55 74072 c:\windows\SysWOW64\XAPOFX1_5.dll
+ 2012-04-24 18:44 . 2010-02-04 08:01 74072 c:\windows\SysWOW64\XAPOFX1_4.dll
+ 2012-04-24 18:44 . 2009-09-04 15:44 69464 c:\windows\SysWOW64\XAPOFX1_3.dll
+ 2012-04-24 18:44 . 2008-10-27 08:04 70992 c:\windows\SysWOW64\XAPOFX1_2.dll
+ 2012-04-24 18:44 . 2008-07-31 08:41 68616 c:\windows\SysWOW64\XAPOFX1_1.dll
+ 2012-04-24 18:44 . 2008-05-30 12:17 65032 c:\windows\SysWOW64\XAPOFX1_0.dll
+ 2012-04-24 18:44 . 2010-02-04 08:01 22360 c:\windows\SysWOW64\X3DAudio1_7.dll
+ 2012-04-24 18:44 . 2009-03-16 12:18 22360 c:\windows\SysWOW64\X3DAudio1_6.dll
+ 2012-04-24 18:44 . 2008-10-27 08:04 23376 c:\windows\SysWOW64\X3DAudio1_5.dll
+ 2012-04-24 18:44 . 2008-05-30 12:17 25608 c:\windows\SysWOW64\X3DAudio1_4.dll
+ 2012-04-24 18:44 . 2008-03-05 14:00 25608 c:\windows\SysWOW64\X3DAudio1_3.dll
+ 2012-04-24 18:44 . 2007-10-22 01:37 17928 c:\windows\SysWOW64\X3DAudio1_2.dll
+ 2012-04-24 18:44 . 2010-06-02 02:55 77656 c:\windows\system32\XAPOFX1_5.dll
+ 2012-04-24 18:44 . 2010-02-04 08:01 78680 c:\windows\system32\XAPOFX1_4.dll
+ 2012-04-24 18:44 . 2009-09-04 15:44 73544 c:\windows\system32\XAPOFX1_3.dll
+ 2012-04-24 18:44 . 2008-10-27 08:04 74576 c:\windows\system32\XAPOFX1_2.dll
+ 2012-04-24 18:44 . 2008-07-31 08:41 72200 c:\windows\system32\XAPOFX1_1.dll
+ 2012-04-24 18:44 . 2008-05-30 12:17 68104 c:\windows\system32\XAPOFX1_0.dll
+ 2012-04-24 18:44 . 2010-02-04 08:01 24920 c:\windows\system32\X3DAudio1_7.dll
+ 2012-04-24 18:44 . 2009-03-16 12:18 24920 c:\windows\system32\X3DAudio1_6.dll
+ 2012-04-24 18:44 . 2008-10-27 08:04 25936 c:\windows\system32\X3DAudio1_5.dll
+ 2012-04-24 18:44 . 2008-05-30 12:16 28168 c:\windows\system32\X3DAudio1_4.dll
+ 2012-04-24 18:44 . 2008-03-05 14:00 28168 c:\windows\system32\X3DAudio1_3.dll
+ 2012-04-24 18:44 . 2007-10-22 01:37 21000 c:\windows\system32\X3DAudio1_2.dll
+ 2010-11-21 03:09 . 2012-04-24 18:20 13642 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-04-24 18:20 29746 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:30 . 2012-04-24 13:17 86016 c:\windows\system32\DriverStore\infpub.dat
- 2009-07-14 05:30 . 2012-04-22 19:26 86016 c:\windows\system32\DriverStore\infpub.dat
- 2012-04-22 17:11 . 2012-04-24 13:04 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2012-04-22 17:11 . 2012-04-25 15:02 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2012-04-22 17:11 . 2012-04-25 15:02 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2012-04-22 17:11 . 2012-04-24 13:04 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-04-24 18:44 . 2012-04-24 18:44 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
- 2012-04-23 19:13 . 2012-04-23 19:13 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
- 2012-04-23 19:13 . 2012-04-23 19:13 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2012-04-24 18:44 . 2012-04-24 18:44 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2012-04-22 14:47 . 2012-04-24 18:20 3082 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3530914189-2052248754-1505902800-1000_UserData.bin
- 2012-04-24 13:13 . 2012-04-24 13:13 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-04-25 16:03 . 2012-04-25 16:03 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-04-24 18:44 . 2010-06-02 02:55 527192 c:\windows\SysWOW64\XAudio2_7.dll
+ 2012-04-24 18:44 . 2010-02-04 08:01 528216 c:\windows\SysWOW64\XAudio2_6.dll
+ 2012-04-24 18:44 . 2009-09-04 15:44 515416 c:\windows\SysWOW64\XAudio2_5.dll
+ 2012-04-24 18:44 . 2009-03-16 12:18 517448 c:\windows\SysWOW64\XAudio2_4.dll
+ 2012-04-24 18:44 . 2008-10-27 08:04 514384 c:\windows\SysWOW64\XAudio2_3.dll
+ 2012-04-24 18:44 . 2008-07-31 08:40 509448 c:\windows\SysWOW64\XAudio2_2.dll
+ 2012-04-24 18:44 . 2008-05-30 12:19 507400 c:\windows\SysWOW64\XAudio2_1.dll
+ 2012-04-24 18:44 . 2008-03-05 14:03 479752 c:\windows\SysWOW64\XAudio2_0.dll
+ 2012-04-24 18:44 . 2010-06-02 02:55 239960 c:\windows\SysWOW64\xactengine3_7.dll
+ 2012-04-24 18:44 . 2010-02-04 08:01 238936 c:\windows\SysWOW64\xactengine3_6.dll
+ 2012-04-24 18:44 . 2009-09-04 15:44 238936 c:\windows\SysWOW64\xactengine3_5.dll
+ 2012-04-24 18:44 . 2009-03-16 12:18 235352 c:\windows\SysWOW64\xactengine3_4.dll
+ 2012-04-24 18:44 . 2008-10-27 08:04 235856 c:\windows\SysWOW64\xactengine3_3.dll
+ 2012-04-24 18:44 . 2008-07-31 08:41 238088 c:\windows\SysWOW64\xactengine3_2.dll
+ 2012-04-24 18:44 . 2008-05-30 12:18 238088 c:\windows\SysWOW64\xactengine3_1.dll
+ 2012-04-24 18:44 . 2008-03-05 14:03 238088 c:\windows\SysWOW64\xactengine3_0.dll
+ 2012-04-24 18:44 . 2007-07-19 22:57 267112 c:\windows\SysWOW64\xactengine2_9.dll
- 2012-04-22 15:14 . 2007-05-31 17:30 266088 c:\windows\SysWOW64\xactengine2_8.dll
+ 2012-04-24 18:44 . 2007-06-20 18:46 266088 c:\windows\SysWOW64\xactengine2_8.dll
+ 2012-04-24 18:44 . 2007-10-22 01:39 267272 c:\windows\SysWOW64\xactengine2_10.dll
+ 2012-04-24 18:44 . 2010-05-26 09:41 248672 c:\windows\SysWOW64\d3dx11_43.dll
+ 2012-04-24 18:44 . 2009-09-04 15:29 235344 c:\windows\SysWOW64\d3dx11_42.dll
+ 2012-04-24 18:44 . 2010-05-26 09:41 470880 c:\windows\SysWOW64\d3dx10_43.dll
+ 2012-04-24 18:44 . 2009-09-04 15:29 453456 c:\windows\SysWOW64\d3dx10_42.dll
+ 2012-04-24 18:44 . 2009-03-09 13:27 453456 c:\windows\SysWOW64\d3dx10_41.dll
+ 2012-04-24 18:44 . 2008-10-15 04:22 452440 c:\windows\SysWOW64\d3dx10_40.dll
+ 2012-04-24 18:44 . 2008-07-10 09:01 467984 c:\windows\SysWOW64\d3dx10_39.dll
+ 2012-04-24 18:44 . 2008-05-30 12:11 467984 c:\windows\SysWOW64\d3dx10_38.dll
+ 2012-04-24 18:44 . 2008-02-05 21:07 462864 c:\windows\SysWOW64\d3dx10_37.dll
+ 2012-04-24 18:44 . 2007-10-02 07:56 444776 c:\windows\SysWOW64\d3dx10_36.dll
+ 2012-04-24 18:44 . 2007-07-19 16:14 444776 c:\windows\SysWOW64\d3dx10_35.dll
+ 2012-04-24 18:44 . 2010-06-02 02:55 518488 c:\windows\system32\XAudio2_7.dll
+ 2012-04-24 18:44 . 2010-02-04 08:01 530776 c:\windows\system32\XAudio2_6.dll
+ 2012-04-24 18:44 . 2009-09-04 15:44 517960 c:\windows\system32\XAudio2_5.dll
+ 2012-04-24 18:44 . 2009-03-16 12:18 521560 c:\windows\system32\XAudio2_4.dll
+ 2012-04-24 18:44 . 2008-10-27 08:04 518480 c:\windows\system32\XAudio2_3.dll
+ 2012-04-24 18:44 . 2008-07-31 08:40 513544 c:\windows\system32\XAudio2_2.dll
+ 2012-04-24 18:44 . 2008-05-30 12:19 511496 c:\windows\system32\XAudio2_1.dll
+ 2012-04-24 18:44 . 2008-03-05 14:04 489480 c:\windows\system32\XAudio2_0.dll
+ 2012-04-24 18:44 . 2010-06-02 02:55 176984 c:\windows\system32\xactengine3_7.dll
+ 2012-04-24 18:44 . 2010-02-04 08:01 176984 c:\windows\system32\xactengine3_6.dll
+ 2012-04-24 18:44 . 2009-09-04 15:44 176968 c:\windows\system32\xactengine3_5.dll
+ 2012-04-24 18:44 . 2009-03-16 12:18 174936 c:\windows\system32\xactengine3_4.dll
+ 2012-04-24 18:44 . 2008-10-27 08:04 175440 c:\windows\system32\xactengine3_3.dll
+ 2012-04-24 18:44 . 2008-07-31 08:41 177672 c:\windows\system32\xactengine3_2.dll
+ 2012-04-24 18:44 . 2008-05-30 12:18 177672 c:\windows\system32\xactengine3_1.dll
+ 2012-04-24 18:44 . 2008-03-05 14:03 177672 c:\windows\system32\xactengine3_0.dll
+ 2012-04-24 18:44 . 2007-07-19 22:57 411496 c:\windows\system32\xactengine2_9.dll
+ 2012-04-24 18:44 . 2007-06-20 18:49 409960 c:\windows\system32\xactengine2_8.dll
- 2012-04-22 15:14 . 2007-05-31 17:30 409960 c:\windows\system32\xactengine2_8.dll
+ 2012-04-24 18:44 . 2007-10-22 01:40 411656 c:\windows\system32\xactengine2_10.dll
+ 2012-04-22 21:00 . 2012-04-25 14:50 150118 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2009-07-14 05:30 . 2012-04-24 13:17 143360 c:\windows\system32\DriverStore\infstrng.dat
- 2009-07-14 05:30 . 2012-04-22 19:26 143360 c:\windows\system32\DriverStore\infstrng.dat
+ 2009-07-14 00:21 . 2009-07-14 01:41 299520 c:\windows\system32\drivers\UMDF\WpdFs.dll
+ 2012-04-24 18:44 . 2010-05-26 09:41 276832 c:\windows\system32\d3dx11_43.dll
+ 2012-04-24 18:44 . 2009-09-04 15:29 285024 c:\windows\system32\d3dx11_42.dll
+ 2012-04-24 18:44 . 2010-05-26 09:41 511328 c:\windows\system32\d3dx10_43.dll
+ 2012-04-24 18:44 . 2009-09-04 15:29 523088 c:\windows\system32\d3dx10_42.dll
+ 2012-04-24 18:44 . 2009-03-09 13:27 520544 c:\windows\system32\d3dx10_41.dll
+ 2012-04-24 18:44 . 2008-10-15 04:22 519000 c:\windows\system32\d3dx10_40.dll
+ 2012-04-24 18:44 . 2008-07-10 09:00 540688 c:\windows\system32\d3dx10_39.dll
+ 2012-04-24 18:44 . 2008-05-30 12:11 540688 c:\windows\system32\d3dx10_38.dll
+ 2012-04-24 18:44 . 2008-02-05 21:07 529424 c:\windows\system32\d3dx10_37.dll
+ 2012-04-24 18:44 . 2007-10-02 07:56 508264 c:\windows\system32\d3dx10_36.dll
+ 2012-04-24 18:44 . 2007-07-19 16:14 508264 c:\windows\system32\d3dx10_35.dll
- 2009-07-14 05:01 . 2012-04-24 13:13 227464 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2012-04-25 16:03 227464 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2012-04-23 19:13 . 2012-04-23 19:13 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2012-04-24 18:44 . 2012-04-24 18:44 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2012-04-24 18:44 . 2012-04-24 18:44 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
- 2012-04-23 19:13 . 2012-04-23 19:13 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
- 2012-04-23 19:13 . 2012-04-23 19:13 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2012-04-24 18:44 . 2012-04-24 18:44 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
- 2012-04-23 19:13 . 2012-04-23 19:13 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2012-04-24 18:44 . 2012-04-24 18:44 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2012-04-24 18:44 . 2012-04-24 18:44 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
- 2012-04-23 19:13 . 2012-04-23 19:13 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2012-04-24 18:44 . 2012-04-24 18:44 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2012-04-23 19:13 . 2012-04-23 19:13 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2012-04-24 18:44 . 2012-04-24 18:44 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2012-04-23 19:13 . 2012-04-23 19:13 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2012-04-23 19:13 . 2012-04-23 19:13 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2012-04-24 18:44 . 2012-04-24 18:44 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2012-04-23 19:13 . 2012-04-23 19:13 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2012-04-24 18:44 . 2012-04-24 18:44 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2012-04-24 18:44 . 2012-04-24 18:44 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2012-04-23 19:13 . 2012-04-23 19:13 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2012-04-24 18:44 . 2012-04-24 18:44 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2012-04-23 19:13 . 2012-04-23 19:13 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2012-04-23 19:13 . 2012-04-23 19:13 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2012-04-24 18:44 . 2012-04-24 18:44 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2012-04-23 19:13 . 2012-04-23 19:13 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2012-04-24 18:44 . 2012-04-24 18:44 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2012-04-24 18:44 . 2012-04-24 18:44 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
- 2012-04-23 19:13 . 2012-04-23 19:13 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2012-04-24 18:44 . 2010-05-26 09:41 1998168 c:\windows\SysWOW64\D3DX9_43.dll
+ 2012-04-24 18:44 . 2009-09-04 15:29 1892184 c:\windows\SysWOW64\D3DX9_42.dll
+ 2012-04-24 18:44 . 2009-03-09 13:27 4178264 c:\windows\SysWOW64\D3DX9_41.dll
+ 2012-04-24 18:44 . 2008-10-15 04:22 4379984 c:\windows\SysWOW64\D3DX9_40.dll
+ 2012-04-24 18:44 . 2008-07-10 09:00 3851784 c:\windows\SysWOW64\D3DX9_39.dll
+ 2012-04-24 18:44 . 2008-05-30 12:11 3850760 c:\windows\SysWOW64\D3DX9_38.dll
+ 2012-04-24 18:44 . 2008-03-05 13:56 3786760 c:\windows\SysWOW64\D3DX9_37.dll
+ 2012-04-24 18:44 . 2007-10-12 13:14 3734536 c:\windows\SysWOW64\d3dx9_36.dll
+ 2012-04-24 18:44 . 2007-07-19 16:14 3727720 c:\windows\SysWOW64\d3dx9_35.dll
+ 2012-04-24 18:44 . 2010-05-26 09:41 1868128 c:\windows\SysWOW64\d3dcsx_43.dll
+ 2012-04-24 18:44 . 2009-09-04 15:29 5501792 c:\windows\SysWOW64\d3dcsx_42.dll
+ 2012-04-24 18:44 . 2010-05-26 09:41 2106216 c:\windows\SysWOW64\D3DCompiler_43.dll
+ 2012-04-24 18:44 . 2009-09-04 15:29 1974616 c:\windows\SysWOW64\D3DCompiler_42.dll
+ 2012-04-24 18:44 . 2009-03-09 13:27 1846632 c:\windows\SysWOW64\D3DCompiler_41.dll
+ 2012-04-24 18:44 . 2008-10-15 04:22 2036576 c:\windows\SysWOW64\D3DCompiler_40.dll
+ 2012-04-24 18:44 . 2008-07-10 09:00 1493528 c:\windows\SysWOW64\D3DCompiler_39.dll
+ 2012-04-24 18:44 . 2008-05-30 12:11 1491992 c:\windows\SysWOW64\D3DCompiler_38.dll
+ 2012-04-24 18:44 . 2008-03-05 13:56 1420824 c:\windows\SysWOW64\D3DCompiler_37.dll
+ 2012-04-24 18:44 . 2007-10-12 13:14 1374232 c:\windows\SysWOW64\D3DCompiler_36.dll
+ 2012-04-24 18:44 . 2007-07-19 16:14 1358192 c:\windows\SysWOW64\D3DCompiler_35.dll
+ 2012-04-24 18:44 . 2010-05-26 09:41 2401112 c:\windows\system32\D3DX9_43.dll
+ 2012-04-24 18:44 . 2009-09-04 15:29 2475352 c:\windows\system32\D3DX9_42.dll
+ 2012-04-24 18:44 . 2009-03-09 13:27 5425496 c:\windows\system32\D3DX9_41.dll
+ 2012-04-24 18:44 . 2008-10-15 04:22 5631312 c:\windows\system32\D3DX9_40.dll
+ 2012-04-24 18:44 . 2008-07-10 09:00 4992520 c:\windows\system32\D3DX9_39.dll
+ 2012-04-24 18:44 . 2008-05-30 12:11 4991496 c:\windows\system32\D3DX9_38.dll
+ 2012-04-24 18:44 . 2008-03-05 13:56 4910088 c:\windows\system32\D3DX9_37.dll
+ 2012-04-24 18:44 . 2007-10-12 13:14 5081608 c:\windows\system32\d3dx9_36.dll
+ 2012-04-24 18:44 . 2007-07-19 16:14 5073256 c:\windows\system32\d3dx9_35.dll
+ 2012-04-24 18:44 . 2010-05-26 09:41 1907552 c:\windows\system32\d3dcsx_43.dll
+ 2012-04-24 18:44 . 2009-09-04 15:29 5554512 c:\windows\system32\d3dcsx_42.dll
+ 2012-04-24 18:44 . 2010-05-26 09:41 2526056 c:\windows\system32\D3DCompiler_43.dll
+ 2012-04-24 18:44 . 2009-09-04 15:29 2582888 c:\windows\system32\D3DCompiler_42.dll
+ 2012-04-24 18:44 . 2009-03-09 13:27 2430312 c:\windows\system32\D3DCompiler_41.dll
+ 2012-04-24 18:44 . 2008-10-15 04:22 2605920 c:\windows\system32\D3DCompiler_40.dll
+ 2012-04-24 18:44 . 2008-07-10 09:00 1942552 c:\windows\system32\D3DCompiler_39.dll
+ 2012-04-24 18:44 . 2008-05-30 12:11 1941528 c:\windows\system32\D3DCompiler_38.dll
+ 2012-04-24 18:44 . 2008-03-05 13:56 1860120 c:\windows\system32\D3DCompiler_37.dll
+ 2012-04-24 18:44 . 2007-10-12 13:14 2006552 c:\windows\system32\D3DCompiler_36.dll
+ 2012-04-24 18:44 . 2007-07-19 16:14 1985904 c:\windows\system32\D3DCompiler_35.dll
- 2012-04-23 19:13 . 2012-04-23 19:13 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2012-04-24 18:44 . 2012-04-24 18:44 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2012-04-24 18:44 . 2012-04-24 18:44 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2012-04-23 19:13 . 2012-04-23 19:13 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Facebook Update"="c:\users\Matej\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-04-22 203072]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-02-14 705664]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2009-09-21 2583040]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 536136]
.
c:\users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech . Registracija proizvoda.lnk - c:\program files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe [2009-11-16 587016]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
AML Device Install.lnk - c:\program files (x86)\AMD AVT\bin\kdbsync.exe [2012-1-31 80384]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
.
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [x]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-02-14 361984]
S2 AODDriver4.1;AODDriver4.1;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-01-03 55936]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [x]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-04-25 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000Core.job
- c:\users\Matej\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-22 14:38]
.
2012-04-25 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000UA.job
- c:\users\Matej\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-22 14:38]
.
2012-04-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000Core.job
- c:\users\Matej\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-22 14:31]
.
2012-04-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000UA.job
- c:\users\Matej\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-22 14:31]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-10-07 1744152]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: Interfaces\{E9CECB3F-8087-43C5-BD75-791E5EFE03C0}: NameServer = 8.8.8.8,4.4.8.8
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\windows\SysWOW64\PnkBstrA.exe
.
**************************************************************************
.
Completion time: 2012-04-25 18:05:34 - machine was rebooted
ComboFix-quarantined-files.txt 2012-04-25 16:05
ComboFix2.txt 2012-04-24 18:20
ComboFix3.txt 2012-04-24 13:15
ComboFix4.txt 2012-04-23 18:42
.
Pre-Run: 154.120.761.344 bytes free
Post-Run: 153.847.603.200 bytes free
.
- - End Of File - - 9A55E48F59B809AFD04DC538669F350C
evo i log od malwarebytea sa D diska ( on i dalje stalno pokazuje da blokira kao neke stetne stranice)
Malwarebytes Anti-Malware (Trial) 1.61.0.1400
www.malwarebytes.org
Database version: v2012.04.24.01
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Matej :: MATEJ- [administrator]
Protection: Enabled
25.4.2012. 18:10:36
mbam-log-2012-04-25 (18-10-36).txt
Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 196458
Time elapsed: 1 minute(s),
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 3
HKLM\SOFTWARE\Microsoft\Security Center|AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.
HKLM\SOFTWARE\Microsoft\Security Center|FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.
HKLM\SOFTWARE\Microsoft\Security Center|UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.
Folders Detected: 0
(No malicious items detected)
Files Detected: 3
D:\deonte.exe (Trojan.Agent) -> Quarantined and deleted successfully.
D:\ewfyxf.exe (Trojan.Agent) -> Quarantined and deleted successfully.
D:\qmwx.pif (Trojan.Agent) -> Quarantined and deleted successfully.
(end)
odi u C:\Qoobox\Quarantine i pronađi ovaj file C:\mdpaqv.exe.vir
uploadaj ga na jottis malware scan
otvori malwarebytes logs i kopiraj upozorenja
skini OTL i spremi na desktop
u prazno polje kopiraj ovo
netsvcs
%SYSTEMDRIVE%\*.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /s
HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost /s
klik na quick scan
log kopiraj
Kaspersky Virus Removal Tool 2011
skini program, sve označi i klik na scan
http://www.zaslike.com/viewer.php?file=l5runrvycru1j1tc0gv.gif
report ćeš ovako spremiti
http://www.zaslike.com/viewer.php?file=8221ismoytj4c0hkoyim.gif
Tog fajla nema tamo , bio je jedan folder zakljucan , uspio sam uci ali nema ni tamo .
Kaspersky ne mogu skinuti zbog errora na njihovoj stranici , a sve ostale redirectaju na njihovu .
OTL log :
OTL logfile created on: 25.4.2012. 19:44:58 - Run 1
OTL by OldTimer - Version 3.2.42.0 Folder = C:\Users\Matej\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 0000041a | Country: Hrvatska | Language: HRV | Date Format: d.M.yyyy.
4,00 Gb Total Physical Memory | 2,80 Gb Available Physical Memory | 69,91% Memory free
8,00 Gb Paging File | 6,13 Gb Available in Paging File | 76,60% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 172,69 Gb Total Space | 140,18 Gb Free Space | 81,17% Space Free | Partition Type: NTFS
Drive D: | 292,97 Gb Total Space | 240,31 Gb Free Space | 82,03% Space Free | Partition Type: NTFS
Computer Name: MATEJ- | User Name: Matej | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
[color=#E56717]========== Processes (SafeList) ==========[/color]
PRC - [2012.04.25 19:44:28 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Matej\Desktop\OTL.exe
PRC - [2012.04.25 19:22:40 | 000,075,136 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2012.04.25 19:21:06 | 000,271,200 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrB.exe
PRC - [2012.04.25 19:07:46 | 000,011,776 | ---- | M] () -- C:\Users\Matej\AppData\Local\Temp\wingkly.exe
PRC - [2012.04.22 16:38:16 | 000,203,072 | ---- | M] (Facebook Inc.) -- C:\Users\Matej\AppData\Local\Facebook\Update\FacebookUpdate.exe
PRC - [2012.04.17 07:31:18 | 003,537,304 | ---- | M] (Xfire Inc.) -- C:\Program Files (x86)\Xfire\Xfire.exe
PRC - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.04.04 15:56:38 | 000,536,136 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
[color=#E56717]========== Modules (No Company Name) ==========[/color]
MOD - [2012.04.25 19:07:46 | 000,011,776 | ---- | M] () -- C:\Users\Matej\AppData\Local\Temp\wingkly.exe
MOD - [2012.04.12 09:37:34 | 000,444,400 | ---- | M] () -- C:\Users\Matej\AppData\Local\Google\Chrome\Application\18.0.1025.162\ppgooglenaclpluginchrome.dll
MOD - [2012.04.12 09:37:33 | 003,915,248 | ---- | M] () -- C:\Users\Matej\AppData\Local\Google\Chrome\Application\18.0.1025.162\pdf.dll
MOD - [2012.04.12 09:36:08 | 000,122,880 | ---- | M] () -- C:\Users\Matej\AppData\Local\Google\Chrome\Application\18.0.1025.162\avutil-51.dll
MOD - [2012.04.12 09:36:06 | 000,220,672 | ---- | M] () -- C:\Users\Matej\AppData\Local\Google\Chrome\Application\18.0.1025.162\avformat-53.dll
MOD - [2012.04.12 09:36:05 | 001,747,456 | ---- | M] () -- C:\Users\Matej\AppData\Local\Google\Chrome\Application\18.0.1025.162\avcodec-53.dll
MOD - [2012.04.12 08:51:55 | 008,743,584 | ---- | M] () -- C:\Users\Matej\AppData\Local\Google\Chrome\Application\18.0.1025.162\gcswf32.dll
[color=#E56717]========== Win32 Services (SafeList) ==========[/color]
SRV:[b]64bit:[/b] - [2012.03.09 07:10:20 | 000,235,520 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:[b]64bit:[/b] - [2012.03.09 01:10:06 | 000,361,984 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:[b]64bit:[/b] - [2011.09.27 21:04:08 | 000,359,192 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV:[b]64bit:[/b] - [2009.07.14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:[b]64bit:[/b] - [2009.07.14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2012.04.25 19:22:40 | 000,075,136 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2012.04.25 19:21:06 | 000,271,200 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrB.exe -- (PnkBstrB)
SRV - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
DRV:[b]64bit:[/b] - [2012.04.04 15:56:40 | 000,024,904 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:[b]64bit:[/b] - [2012.03.09 08:28:08 | 010,857,984 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:[b]64bit:[/b] - [2012.03.09 05:58:02 | 000,328,704 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:[b]64bit:[/b] - [2012.01.03 23:22:54 | 000,055,936 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys -- (AODDriver4.1)
DRV:[b]64bit:[/b] - [2011.12.05 21:47:30 | 000,095,248 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:[b]64bit:[/b] - [2011.09.02 08:30:46 | 000,042,776 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LUsbFilt.sys -- (LUsbFilt)
DRV:[b]64bit:[/b] - [2011.09.02 08:30:36 | 000,060,696 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:[b]64bit:[/b] - [2011.09.02 08:30:24 | 000,066,840 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:[b]64bit:[/b] - [2010.11.21 05:24:43 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:[b]64bit:[/b] - [2010.11.21 05:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:[b]64bit:[/b] - [2010.11.21 05:23:48 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tsusbhub.sys -- (tsusbhub)
DRV:[b]64bit:[/b] - [2010.11.21 05:23:48 | 000,088,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc)
DRV:[b]64bit:[/b] - [2010.11.21 05:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:[b]64bit:[/b] - [2010.11.21 05:23:48 | 000,034,816 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:[b]64bit:[/b] - [2010.11.21 05:23:47 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2010.11.21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2010.11.21 05:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:[b]64bit:[/b] - [2010.11.21 05:23:47 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:[/b] - [2010.02.18 09:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdiox64.sys -- (amdiox64)
DRV:[b]64bit:[/b] - [2009.09.17 19:04:18 | 001,250,816 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV:[b]64bit:[/b] - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:[b]64bit:[/b] - [2009.07.14 03:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:[b]64bit:[/b] - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:[/b] - [2009.06.10 22:35:42 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:[b]64bit:[/b] - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:[/b] - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:[b]64bit:[/b] - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
[color=#E56717]========== Internet Explorer ==========[/color]
IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = hr
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
[color=#E56717]========== FireFox ==========[/color]
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Matej\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Matej\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\facebook.com/fbDesktopPlugin: C:\Users\Matej\AppData\Local\Facebook\Messenger\2.0.4478.0\npFbDesktopPlugin.dll (Facebook, Inc.)
[color=#E56717]========== Chrome ==========[/color]
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Matej\AppData\Local\Google\Chrome\Application\18.0.1025.162\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Matej\AppData\Local\Google\Chrome\Application\18.0.1025.162\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Matej\AppData\Local\Google\Chrome\Application\18.0.1025.162\gcswf32.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Matej\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - Extension: YouTube = C:\Users\Matej\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google pretra\u017Eivanje = C:\Users\Matej\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Gmail = C:\Users\Matej\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2012.04.25 18:04:00 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O4:[b]64bit:[/b] - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4 - HKLM..\Run: [AMD AVT] C:\Windows\SysWow64\cmd.exe (Microsoft Corporation)
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [Facebook Update] C:\Users\Matej\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - Startup: C:\Users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Registracija proizvoda.lnk = C:\Program Files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe (Leader Technologies/Logitech)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E9CECB3F-8087-43C5-BD75-791E5EFE03C0}: NameServer = 8.8.8.8,4.4.8.8
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:[b]64bit:[/b] - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012.04.25 18:04:42 | 000,000,262 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2012.04.25 18:04:42 | 000,000,256 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = ComFile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
NetSvcs:[b]64bit:[/b] AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[2012.04.25 19:44:24 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Users\Matej\Desktop\OTL.exe
[2012.04.25 19:04:51 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2012.04.25 19:02:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD AVT
[2012.04.25 19:02:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD APP
[2012.04.25 19:02:50 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ATI Technologies
[2012.04.25 19:02:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\ATI Technologies
[2012.04.25 19:02:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD VISION Engine Control Center
[2012.04.25 19:01:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ATI Technologies
[2012.04.25 19:01:22 | 000,000,000 | ---D | C] -- C:\Program Files\ATI Technologies
[2012.04.25 19:01:19 | 000,000,000 | ---D | C] -- C:\Program Files\ATI
[2012.04.25 19:00:44 | 000,000,000 | ---D | C] -- C:\AMD
[2012.04.25 18:55:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Activision
[2012.04.25 18:52:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Activision
[2012.04.25 18:18:20 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012.04.25 18:17:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Phyxion.net
[2012.04.25 18:17:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Phyxion.net
[2012.04.25 18:05:36 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012.04.25 17:58:24 | 004,475,034 | R--- | C] (Swearware) -- C:\Users\Matej\Desktop\ComboFix.exe
[2012.04.24 20:45:43 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Roaming\LolClient
[2012.04.24 15:17:51 | 000,000,000 | ---D | C] -- C:\USBNoRisk
[2012.04.23 21:28:16 | 000,000,000 | ---D | C] -- C:\Users\Matej\Documents\VirtualDJ
[2012.04.23 21:28:16 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ
[2012.04.23 21:28:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VirtualDJ
[2012.04.23 20:35:07 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012.04.23 20:35:07 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012.04.23 20:35:07 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012.04.23 20:35:01 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2012.04.23 20:34:58 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012.04.23 20:22:35 | 000,000,000 | ---D | C] -- C:\_OTS
[2012.04.23 16:55:55 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Roaming\Malwarebytes
[2012.04.23 16:55:50 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.04.23 16:55:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.04.23 16:55:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.04.23 16:55:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.04.23 02:17:52 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[2012.04.22 20:58:12 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Roaming\TS3Client
[2012.04.22 20:57:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
[2012.04.22 20:57:22 | 000,000,000 | ---D | C] -- C:\Program Files\TeamSpeak 3 Client
[2012.04.22 17:40:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
[2012.04.22 17:39:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSECache
[2012.04.22 17:32:05 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Local\PunkBuster
[2012.04.22 17:23:53 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Roaming\Xfire
[2012.04.22 17:23:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xfire
[2012.04.22 17:23:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Xfire
[2012.04.22 17:23:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Xfire
[2012.04.22 16:53:59 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Roaming\Macromedia
[2012.04.22 16:53:59 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Roaming\Adobe
[2012.04.22 16:44:41 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Wat
[2012.04.22 16:44:41 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Wat
[2012.04.22 16:42:06 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Roaming\WinRAR
[2012.04.22 16:42:06 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012.04.22 16:42:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012.04.22 16:42:02 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2012.04.22 16:39:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\LogiShrd
[2012.04.22 16:39:29 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Roaming\Leadertech
[2012.04.22 16:39:09 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\LogiShrd
[2012.04.22 16:39:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
[2012.04.22 16:39:06 | 000,000,000 | ---D | C] -- C:\Program Files\Logitech
[2012.04.22 16:39:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Logishrd
[2012.04.22 16:38:48 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Logishrd
[2012.04.22 16:38:36 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Facebook
[2012.04.22 16:38:16 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Local\Facebook
[2012.04.22 16:34:54 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Roaming\Logitech
[2012.04.22 16:34:54 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Roaming\Logishrd
[2012.04.22 16:34:00 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Local\AMD
[2012.04.22 16:33:53 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Roaming\ATI
[2012.04.22 16:33:53 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Local\ATI
[2012.04.22 16:33:43 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2012.04.22 16:31:12 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Local\Google
[2012.04.22 16:31:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\InstallShield Installation Information
[2012.04.22 16:30:57 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Local\Apps
[2012.04.22 16:30:56 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Local\Deployment
[2012.04.22 16:30:55 | 000,242,176 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\SysNative\Dts2APO.dll
[2012.04.22 16:30:55 | 000,193,024 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\SysNative\ViaMicArrayAPO.dll
[2012.04.22 16:30:55 | 000,086,016 | ---- | C] (QSound Labs, Inc.) -- C:\Windows\SysNative\nQPropPageExt.dll
[2012.04.22 16:30:55 | 000,082,432 | ---- | C] (QSound Labs, Inc.) -- C:\Windows\SysNative\nQAPO.dll
[2012.04.22 16:30:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VIA
[2012.04.22 16:30:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InstallShield
[2012.04.22 16:28:20 | 000,000,000 | ---D | C] -- C:\ProgramData\AMD
[2012.04.22 16:27:45 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2012.04.22 16:25:41 | 000,000,000 | R--D | C] -- C:\Users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012.04.22 16:25:41 | 000,000,000 | R--D | C] -- C:\Users\Matej\Searches
[2012.04.22 16:25:41 | 000,000,000 | R--D | C] -- C:\Users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2012.04.22 16:25:40 | 000,000,000 | -H-D | C] -- C:\Users\Matej\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2012.04.22 16:25:32 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Roaming\Identities
[2012.04.22 16:25:30 | 000,000,000 | R--D | C] -- C:\Users\Matej\Contacts
[2012.04.22 16:25:29 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Local\VirtualStore
[2012.04.22 16:25:22 | 000,000,000 | --SD | C] -- C:\Users\Matej\AppData\Roaming\Microsoft
[2012.04.22 16:25:22 | 000,000,000 | R--D | C] -- C:\Users\Matej\Videos
[2012.04.22 16:25:22 | 000,000,000 | R--D | C] -- C:\Users\Matej\Saved Games
[2012.04.22 16:25:22 | 000,000,000 | R--D | C] -- C:\Users\Matej\Pictures
[2012.04.22 16:25:22 | 000,000,000 | R--D | C] -- C:\Users\Matej\Music
[2012.04.22 16:25:22 | 000,000,000 | R--D | C] -- C:\Users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2012.04.22 16:25:22 | 000,000,000 | R--D | C] -- C:\Users\Matej\Links
[2012.04.22 16:25:22 | 000,000,000 | R--D | C] -- C:\Users\Matej\Favorites
[2012.04.22 16:25:22 | 000,000,000 | R--D | C] -- C:\Users\Matej\Downloads
[2012.04.22 16:25:22 | 000,000,000 | R--D | C] -- C:\Users\Matej\Documents
[2012.04.22 16:25:22 | 000,000,000 | R--D | C] -- C:\Users\Matej\Desktop
[2012.04.22 16:25:22 | 000,000,000 | R--D | C] -- C:\Users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2012.04.22 16:25:22 | 000,000,000 | -HSD | C] -- C:\Users\Matej\AppData\Local\Temporary Internet Files
[2012.04.22 16:25:22 | 000,000,000 | -HSD | C] -- C:\Users\Matej\Templates
[2012.04.22 16:25:22 | 000,000,000 | -HSD | C] -- C:\Users\Matej\Start Menu
[2012.04.22 16:25:22 | 000,000,000 | -HSD | C] -- C:\Users\Matej\SendTo
[2012.04.22 16:25:22 | 000,000,000 | -HSD | C] -- C:\Users\Matej\Recent
[2012.04.22 16:25:22 | 000,000,000 | -HSD | C] -- C:\Users\Matej\PrintHood
[2012.04.22 16:25:22 | 000,000,000 | -HSD | C] -- C:\Users\Matej\NetHood
[2012.04.22 16:25:22 | 000,000,000 | -HSD | C] -- C:\Users\Matej\Documents\My Videos
[2012.04.22 16:25:22 | 000,000,000 | -HSD | C] -- C:\Users\Matej\Documents\My Pictures
[2012.04.22 16:25:22 | 000,000,000 | -HSD | C] -- C:\Users\Matej\Documents\My Music
[2012.04.22 16:25:22 | 000,000,000 | -HSD | C] -- C:\Users\Matej\My Documents
[2012.04.22 16:25:22 | 000,000,000 | -HSD | C] -- C:\Users\Matej\Local Settings
[2012.04.22 16:25:22 | 000,000,000 | -HSD | C] -- C:\Users\Matej\AppData\Local\History
[2012.04.22 16:25:22 | 000,000,000 | -HSD | C] -- C:\Users\Matej\Cookies
[2012.04.22 16:25:22 | 000,000,000 | -HSD | C] -- C:\Users\Matej\Application Data
[2012.04.22 16:25:22 | 000,000,000 | -HSD | C] -- C:\Users\Matej\AppData\Local\Application Data
[2012.04.22 16:25:22 | 000,000,000 | -H-D | C] -- C:\Users\Matej\AppData
[2012.04.22 16:25:22 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Local\Temp
[2012.04.22 16:25:22 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Local\Microsoft
[2012.04.22 16:25:22 | 000,000,000 | ---D | C] -- C:\Users\Matej\AppData\Roaming\Media Center Programs
[2012.04.22 16:25:12 | 000,000,000 | ---D | C] -- C:\Recovery
[2012.04.22 16:21:37 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2012.04.22 16:19:08 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2012.04.22 16:18:37 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[2012.04.25 19:44:28 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Matej\Desktop\OTL.exe
[2012.04.25 19:43:01 | 000,000,928 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000UA.job
[2012.04.25 19:36:00 | 000,000,958 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000UA.job
[2012.04.25 19:22:40 | 000,075,136 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2012.04.25 19:21:06 | 000,271,200 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012.04.25 19:08:55 | 000,713,888 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.04.25 19:08:55 | 000,606,992 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.04.25 19:08:55 | 000,103,370 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.04.25 19:04:31 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.04.25 19:04:27 | 000,000,000 | ---- | M] () -- C:\Windows\ativpsrm.bin
[2012.04.25 19:04:24 | 3220,676,608 | -HS- | M] () -- C:\hiberfil.sys
[2012.04.25 19:01:09 | 000,013,746 | ---- | M] () -- C:\Users\Matej\Desktop\pbgame.htm
[2012.04.25 19:01:04 | 000,000,082 | ---- | M] () -- C:\Users\Matej\Desktop\pbuser.htm
[2012.04.25 18:55:59 | 000,002,014 | ---- | M] () -- C:\Users\Public\Desktop\Call of Duty(R) 4 - Modern Warfare(TM) Singleplayer.lnk
[2012.04.25 18:55:59 | 000,002,014 | ---- | M] () -- C:\Users\Public\Desktop\Call of Duty(R) 4 - Modern Warfare(TM) Multiplayer.lnk
[2012.04.25 18:55:30 | 000,000,331 | ---- | M] () -- C:\Windows\game.ini
[2012.04.25 18:45:08 | 000,099,328 | ---- | M] () -- C:\udfuxh.exe
[2012.04.25 18:17:30 | 000,001,237 | ---- | M] () -- C:\Users\Public\Desktop\Driver Sweeper.lnk
[2012.04.25 18:04:42 | 000,000,262 | RHS- | M] () -- C:\autorun.inf
[2012.04.25 18:04:00 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012.04.25 17:57:54 | 004,475,034 | R--- | M] (Swearware) -- C:\Users\Matej\Desktop\ComboFix.exe
[2012.04.25 16:50:06 | 000,000,906 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000Core.job
[2012.04.25 16:50:06 | 000,000,906 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000Core.job
[2012.04.24 20:14:09 | 000,001,358 | ---- | M] () -- C:\Users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Registracija proizvoda.lnk
[2012.04.24 15:17:22 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2012.04.24 15:13:25 | 000,267,560 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.04.24 13:17:47 | 000,000,116 | ---- | M] () -- C:\Users\Matej\Documents\AutoHotkey.ahk
[2012.04.24 13:11:09 | 000,271,200 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2012.04.24 13:10:57 | 000,103,736 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[2012.04.23 21:40:01 | 005,808,587 | ---- | M] () -- C:\Users\Matej\Desktop\mama.mp3
[2012.04.23 21:28:17 | 000,001,050 | ---- | M] () -- C:\Users\Matej\Desktop\VirtualDJ Home FREE.lnk
[2012.04.23 16:55:50 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.04.22 21:28:59 | 003,372,931 | ---- | M] () -- C:\Users\Matej\Desktop\SANJA DJORDJEVIC - SANJA - www.YuMp3.info.mp3
[2012.04.22 21:26:13 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2012.04.22 20:57:23 | 000,000,967 | ---- | M] () -- C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
[2012.04.22 17:23:53 | 000,000,967 | ---- | M] () -- C:\Users\Public\Desktop\Xfire.lnk
[2012.04.22 16:44:47 | 000,016,640 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.04.22 16:44:47 | 000,016,640 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.04.22 16:33:44 | 000,002,278 | ---- | M] () -- C:\Users\Matej\Desktop\Google Chrome.lnk
[2012.04.22 16:31:00 | 000,001,206 | ---- | M] () -- C:\Users\Public\Desktop\HD VDeck.lnk
[2012.04.22 16:30:26 | 000,001,441 | ---- | M] () -- C:\Users\Matej\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012.04.22 16:21:31 | 000,116,385 | ---- | M] () -- C:\Windows\SysWow64\license.rtf
[2012.04.22 16:21:31 | 000,116,385 | ---- | M] () -- C:\Windows\SysNative\license.rtf
[2012.04.17 07:31:22 | 000,042,392 | ---- | M] () -- C:\Windows\SysWow64\xfcodec.dll
[2012.04.17 07:31:22 | 000,028,056 | ---- | M] () -- C:\Windows\SysNative\xfcodec64.dll
[2012.04.04 15:56:40 | 000,024,904 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[color=#E56717]========== Files Created - No Company Name ==========[/color]
[2012.04.25 19:04:27 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012.04.25 18:55:59 | 000,002,014 | ---- | C] () -- C:\Users\Public\Desktop\Call of Duty(R) 4 - Modern Warfare(TM) Singleplayer.lnk
[2012.04.25 18:55:59 | 000,002,014 | ---- | C] () -- C:\Users\Public\Desktop\Call of Duty(R) 4 - Modern Warfare(TM) Multiplayer.lnk
[2012.04.25 18:45:08 | 000,099,328 | ---- | C] () -- C:\udfuxh.exe
[2012.04.25 18:17:30 | 000,001,237 | ---- | C] () -- C:\Users\Public\Desktop\Driver Sweeper.lnk
[2012.04.25 18:04:23 | 000,000,262 | RHS- | C] () -- C:\autorun.inf
[2012.04.24 20:14:09 | 000,001,358 | ---- | C] () -- C:\Users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Registracija proizvoda.lnk
[2012.04.24 15:17:22 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2012.04.24 13:16:34 | 000,000,116 | ---- | C] () -- C:\Users\Matej\Documents\AutoHotkey.ahk
[2012.04.23 21:34:44 | 005,808,587 | ---- | C] () -- C:\Users\Matej\Desktop\mama.mp3
[2012.04.23 21:28:17 | 000,001,050 | ---- | C] () -- C:\Users\Matej\Desktop\VirtualDJ Home FREE.lnk
[2012.04.23 20:35:07 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012.04.23 20:35:07 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012.04.23 20:35:07 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012.04.23 20:35:07 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012.04.23 20:35:07 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012.04.23 16:55:50 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.04.22 21:28:22 | 003,372,931 | ---- | C] () -- C:\Users\Matej\Desktop\SANJA DJORDJEVIC - SANJA - www.YuMp3.info.mp3
[2012.04.22 21:26:13 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2012.04.22 20:57:23 | 000,000,967 | ---- | C] () -- C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
[2012.04.22 18:46:15 | 000,271,200 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2012.04.22 18:41:21 | 000,000,082 | ---- | C] () -- C:\Users\Matej\Desktop\pbuser.htm
[2012.04.22 18:41:16 | 000,013,746 | ---- | C] () -- C:\Users\Matej\Desktop\pbgame.htm
[2012.04.22 18:41:05 | 000,912,896 | ---- | C] () -- C:\Users\Matej\Desktop\pbsetup.exe
[2012.04.22 17:40:10 | 000,002,671 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Word Viewer 2003.lnk
[2012.04.22 17:23:53 | 000,000,967 | ---- | C] () -- C:\Users\Public\Desktop\Xfire.lnk
[2012.04.22 17:13:51 | 000,271,200 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012.04.22 17:13:51 | 000,103,736 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[2012.04.22 17:13:49 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2012.04.22 17:13:48 | 000,000,331 | ---- | C] () -- C:\Windows\game.ini
[2012.04.22 16:38:20 | 000,000,928 | ---- | C] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000UA.job
[2012.04.22 16:38:20 | 000,000,906 | ---- | C] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000Core.job
[2012.04.22 16:33:44 | 000,002,278 | ---- | C] () -- C:\Users\Matej\Desktop\Google Chrome.lnk
[2012.04.22 16:31:13 | 000,000,958 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000UA.job
[2012.04.22 16:31:12 | 000,000,906 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000Core.job
[2012.04.22 16:31:00 | 000,001,218 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD VDeck.lnk
[2012.04.22 16:31:00 | 000,001,206 | ---- | C] () -- C:\Users\Public\Desktop\HD VDeck.lnk
[2012.04.22 16:30:26 | 000,001,441 | ---- | C] () -- C:\Users\Matej\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012.04.22 16:25:46 | 000,001,413 | ---- | C] () -- C:\Users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2012.04.22 16:25:42 | 000,001,447 | ---- | C] () -- C:\Users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012.04.22 16:25:22 | 000,000,290 | ---- | C] () -- C:\Users\Matej\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2012.04.22 16:25:22 | 000,000,272 | ---- | C] () -- C:\Users\Matej\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2012.04.22 16:21:21 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2012.04.22 16:21:14 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2012.04.22 16:18:37 | 3220,676,608 | -HS- | C] () -- C:\hiberfil.sys
[2012.04.17 07:31:22 | 000,042,392 | ---- | C] () -- C:\Windows\SysWow64\xfcodec.dll
[2012.04.17 07:31:22 | 000,028,056 | ---- | C] () -- C:\Windows\SysNative\xfcodec64.dll
[2012.03.09 01:26:20 | 000,054,784 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll
[2012.02.15 04:36:36 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012.02.15 04:36:36 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012.01.31 07:00:24 | 000,016,896 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2011.09.13 00:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[color=#E56717]========== LOP Check ==========[/color]
[2012.04.22 16:39:29 | 000,000,000 | ---D | M] -- C:\Users\Matej\AppData\Roaming\Leadertech
[2012.04.24 20:45:43 | 000,000,000 | ---D | M] -- C:\Users\Matej\AppData\Roaming\LolClient
[2012.04.23 18:46:21 | 000,000,000 | ---D | M] -- C:\Users\Matej\AppData\Roaming\TS3Client
[2012.04.25 16:50:06 | 000,000,906 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000Core.job
[2012.04.25 19:43:01 | 000,000,928 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3530914189-2052248754-1505902800-1000UA.job
[2009.07.14 07:08:49 | 000,006,094 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[color=#E56717]========== Purity Check ==========[/color]
[color=#E56717]========== Custom Scans ==========[/color]
[color=#A23BEC]< %SYSTEMDRIVE%\*.exe >[/color]
[2012.04.25 18:45:08 | 000,099,328 | ---- | M] () -- C:\udfuxh.exe
[color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /s >[/color]
"HDAudDeck" = C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r -- [2009.09.21 18:42:36 | 002,583,040 | R--- | M] (VIA)
"Malwarebytes' Anti-Malware" = "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray -- [2012.04.04 15:56:38 | 000,536,136 | ---- | M] (Malwarebytes Corporation)
"StartCCC" = "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun -- [2012.03.09 02:30:12 | 000,709,760 | ---- | M] (Advanced Micro Devices, Inc.)
"AMD AVT" = Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml -- [2010.11.21 05:24:03 | 000,302,592 | ---- | M] (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed" = 1
"NoChange" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed" = 1
[color=#A23BEC]< HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost /s >[/color]
"netsvcs" = [Binary data over 100 bytes]
"LocalService" = [Binary data over 100 bytes]
"LocalSystemNetworkRestricted" = [Binary data over 100 bytes]
"LocalServiceNoNetwork" = PLA [binary data] -- [2010.11.21 05:24:08 | 001,508,864 | ---- | M] (Microsoft Corporation)
"rpcss" = RpcSs [binary data]
"LocalServiceNetworkRestricted" = AudioSrvBthHFSrvLmHostswscsvcWPCSvc [binary data]
"LocalServiceAndNoImpersonation" = SSDPSRVupnphostSCardSvrTBSQWAVEwcncsvc [binary data]
"DcomLaunch" = PowerPlugPlayDcomLaunch [binary data]
"NetworkService" = [Binary data over 100 bytes]
"imgsvc" = StiSvc [binary data]
"wcssvc" = WcsPlugInService [binary data] -- [2009.07.14 03:16:18 | 000,032,768 | ---- | M] (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService]
"AuthenticationCapabilities" = 8192
"CoInitializeSecurityParam" = 1
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation]
"AuthenticationCapabilities" = 8192
"CoInitializeSecurityParam" = 1
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceNetworkRestricted]
"CoInitializeSecurityParam" = 1
"DefaultRpcStackSize" = 64
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceNoNetwork]
"CoInitializeSecurityParam" = 1
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost\LocalSystemNetworkRestricted]
"CoInitializeSecurityParam" = 1
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs]
"AuthenticationCapabilities" = 12320
"CoInitializeSecurityParam" = 1
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost\NetworkService]
"CoInitializeSecurityParam" = 1
"DefaultRpcStackSize" = 28
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost\NetworkServiceRemoteDesktopHyperVAgent]
"CoInitializeSecurityParam" = 1
"AuthenticationCapabilities" = 8192
"AuthenticationLevel" = 6
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost\NetworkServiceRemoteDesktopPublishing]
"CoInitializeSecurityParam" = 1
"AuthenticationCapabilities" = 8192
"AuthenticationLevel" = 6
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost\termsvcs]
"CoInitializeSecurityParam" = 1
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost\wcssvc]
"CoInitializeSecurityParam" = 1
"CoInitializeSecurityAppID" = {CD11FAB6-1C0E-45e1-BA31-5C6008EF2607}
< End of report >
kaspersky se otvara bez problema, bojim se da je file replicator u pitanju...
otvori OTL i ovo kopiraj u prazno polje
:services
:OTL
PRC - [2012.04.25 19:07:46 | 000,011,776 | ---- | M] () -- C:\Users\Matej\AppData\Local\Temp\wingkly.exe
MOD - [2012.04.25 19:07:46 | 000,011,776 | ---- | M] () -- C:\Users\Matej\AppData\Local\Temp\wingkly.exe
O32 - AutoRun File - [2012.04.25 18:04:42 | 000,000,262 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2012.04.25 18:04:42 | 000,000,256 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
[2012.04.25 18:45:08 | 000,099,328 | ---- | M] () -- C:\udfuxh.exe
[2012.04.25 18:45:08 | 000,099,328 | ---- | C] () -- C:\udfuxh.exe
[2012.04.25 18:04:23 | 000,000,262 | RHS- | C] () -- C:\autorun.inf
:files
C:\udfuxh.exe
C:\autorun.inf
C:\Users\Matej\AppData\Local\Temp\wingkly.exe
:Commands
[purity]
[emptytemp]
[resethosts]
[EMPTYFLASH]
[CREATERESTOREPOINT]
[Reboot]
klik na RUN FIX
log koji dobiješ kopiraj
skini dr.wb cure it i spremi na desktop
pokreni najprije quick scan (koji je podešen po defoultu), nakom toga kreni fulls scan
ako se opet dogodi da ne možeš skinuti dr.web ili kaspersky, skini program s zdravog računala i prebaci na usb stik ili dvd/cd na zaraženo računao te pokreni program
očito je da D: disk nije zaražen samoo s wormom...
OTL log
i skenirao sam sa dr.webom ali mi je opet neki fajl trazio propust kroz firewall .. Iako je ovaj vecinu ocistio i pobriso , tocnije 158 .
All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
No active process named wingkly.exe was found!
C:\autorun.inf moved successfully.
D:\autorun.inf moved successfully.
C:\udfuxh.exe moved successfully.
File C:\udfuxh.exe not found.
File C:\autorun.inf not found.
========== FILES ==========
File\Folder C:\udfuxh.exe not found.
File\Folder C:\autorun.inf not found.
File\Folder C:\Users\Matej\AppData\Local\Temp\wingkly.exe not found.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Matej
->Temp folder emptied: 594038 bytes
->Temporary Internet Files folder emptied: 2723742 bytes
->Google Chrome cache emptied: 364388488 bytes
->Flash cache emptied: 3764 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1686 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50333 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 351,00 mb
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYFLASH]
User: All Users
User: Default
User: Default User
User: Matej
->Flash cache emptied: 0 bytes
User: Public
Total Flash Files Cleaned = 0,00 mb
Restore point Set: OTL Restore Point
OTL by OldTimer - Version 3.2.42.0 log created on 04272012_200932
Files\Folders moved on Reboot...
C:\Users\Matej\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
Registry entries deleted on Reboot...
158 je velik broj, trebam znati o kojem se virusu radi ?....sality, virut ?...što je dr.web pronašao ?
Sality je pronasao .
Sality je pronasao .
skini ovaj program i spremi na destop
program pokreni 2 puta,...sality killer će očistiti memoriju, e sad...ako su samo podaci na D: inficirani, sve izbriši osim dokumenata i slika, dakle, sve igrice i programe...
a ako je i c: inficiran, kad završiš sa salitykillerom spremi dokumentei slike i formatiraj kompletno računalo ...sve diskove, i kreni iznova...sality se može očistiti ako je infekcija u početku, ovako bi to bila lutrija
Evo pokrenuo , pa cemo vidjeti , inficiran je i c jer vidim da lijeci program files itd ..
Nemam nekih posebnih podataka , ali smijem li spremiti sada te fajlove kada zavrsim ( imam par photoshop projekata te 2-3 igre ) na disk prijenosni , tj hoce li one biti ciste nakon sto ovo zavrsi ?
EDIT: oba diska formatiram kad instaliram windowse jel ?
Monitoring thread stopped
completed
Infected files: 212
Infected processes: 0
Infected threads: 85
Cured files: 212
Will be cured on reboot: 0
Executed registry scripts: 1
pa da, to je to...da nije tako računalo bi bilo čisto iz dva kruga....saliti killer će očistiti virus iz memorije, dezinficirati filove...ko zna, možda će raditi nakon toga...samo kažem ti kakvo je pravilo kod infekcije salitijem i virutom
na externi disk sve možeš spremiti osim filova koji imaj .exe dodatak...možeš bez problema spremiti photshop radove, word, excel, .jpg, .mp3...samo programe ne..
oba diska formatiraj i kreni iznova, tako ti je najbolje...jer ćeš ionako sve igre i sve programe morati iznova instalirati
Windowsi reinstalirani , prijesnosni skeniran sa 4 antivirusa i niti jedan nije pronasao nista , nakon instalacije novih windowsa komp jos jednom procesljan sa sality killerom , te sam instalirao aviru zasad . Imas neki bolji prijedlog antivirusa jer ovaj nikad nisam koristio , ali eto ..
Windowsi reinstalirani , prijesnosni skeniran sa 4 antivirusa i niti jedan nije pronasao nista , nakon instalacije novih windowsa komp jos jednom procesljan sa sality killerom , te sam instalirao aviru zasad . Imas neki bolji prijedlog antivirusa jer ovaj nikad nisam koristio , ali eto ..
avira je pristojan antivrus, za normalno korištenje internta je skroz ok....možeš probati eventualno avast, pa sam zaključiš što ti najbolje odgovara...uz antivirus bi bilo dobro da imaš i malwarebytes -free verzija je više nego dovoljna...nema najboljeg antivirusa i nijedan neće štiti 100%, svi su oni manje više isti i pružaju otprilike jednaku zaštitu
najbolji antivirus je korisnik koji pazi na što klika :)
Ja si ne mogu dokuciti odakle je dosao virus .. Ali eto , valjda ce sada biti ok :)
Hvala ti na pomoci :)