Virus Sa Fejsa

1

Virus Sa Fejsa

offline
  • Pridružio: 17 Okt 2011
  • Poruke: 311

Otvaranjem video snimka na fejsu dobio sam virus koji ne mogu da uklonim ni sa AVG-om ni sa Anti Malvareom........

offline
  • Fil  Male
  • Legendarni građanin
  • Pridružio: 11 Jun 2009
  • Poruke: 16586

Postavi izveštaje po ovom uputstvu:
http://www.mycity.rs/Ambulanta/Kako-otvoriti-temu-u-Ambulanti.html

offline
  • Pridružio: 17 Okt 2011
  • Poruke: 311

Kod mojih prijatelja na fejsu se pojavljuje video sanimak pod "Saindo da vagina" kao da sam im ga poslao ali sam ga samo otvorio na svom zidu i od tada fejs čudno radi prekidajući rad nudeći mi da prihvatim video igrice Casle ville i Farm ville i dr. igrice sa fejsa. Virus nisam detektovao a problem se javlja od danas po podne a navedeni snimak sam otvoio oko 10 sati pre podne. Virise nisam detektovao na kompu ni pomoću AVG ni pomoću Anti-malwarea. Koristim Wireless ikonekciju 512 mb/s

offline
  • Fil  Male
  • Legendarni građanin
  • Pridružio: 11 Jun 2009
  • Poruke: 16586

Potrebno je da čitaš dalje uputstvo i postaviš logove (izveštaje). Uputstvo je detaljno objašnjeno, samo polako.

offline
  • Pridružio: 17 Okt 2011
  • Poruke: 311

Napisano: 11 Jan 2012 22:00

PS
koristim Google chrome i kada god otvorim bilo koji link automatski me prebacuje na fejs nudeći gore navedeni igrice.

Dopuna: 11 Jan 2012 22:15

https://www.mycity.rs/must-login.png


OTL logfile created on: 11.1.2012 22:05:24 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Deki\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 0000241a | Country: Srbija | Language: SRM | Date Format: d.M.yyyy

2,00 Gb Total Physical Memory | 0,79 Gb Available Physical Memory | 39,75% Memory free
4,00 Gb Paging File | 1,92 Gb Available in Paging File | 48,15% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 114,50 Gb Total Space | 72,09 Gb Free Space | 62,97% Space Free | Partition Type: NTFS
Drive D: | 465,76 Gb Total Space | 383,95 Gb Free Space | 82,44% Space Free | Partition Type: NTFS

Computer Name: PC | User Name: Deki | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012.01.11 19:22:00 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Deki\Desktop\OTL.exe
PRC - [2011.12.03 01:22:12 | 002,415,456 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
PRC - [2011.11.23 02:36:24 | 002,391,832 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2012\avgfws.exe
PRC - [2011.11.17 18:18:52 | 000,273,528 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
PRC - [2011.11.10 10:17:04 | 003,514,176 | ---- | M] (DT Soft Ltd) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
PRC - [2011.10.12 06:25:22 | 004,433,248 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe
PRC - [2011.08.02 06:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
PRC - [2011.06.06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011.04.27 08:56:10 | 000,232,896 | ---- | M] (Vuze Inc.) -- C:\Program Files (x86)\Vuze\Azureus.exe
PRC - [2011.03.28 11:21:16 | 000,249,648 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
PRC - [2010.07.04 19:13:56 | 000,095,576 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe
PRC - [2008.04.24 10:34:28 | 001,294,336 | ---- | M] (Ralink Technology, Corp.) -- C:\Program Files (x86)\RALINK\Common\RaUI.exe
PRC - [2007.06.27 19:04:00 | 001,213,736 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
PRC - [2007.06.27 19:03:40 | 000,152,872 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe


========== Modules (No Company Name) ==========

MOD - [2012.01.05 10:48:44 | 000,411,120 | ---- | M] () -- C:\Users\Deki\AppData\Local\Google\Chrome\Application\16.0.912.75\ppGoogleNaClPluginChrome.dll
MOD - [2012.01.05 10:48:43 | 003,767,792 | ---- | M] () -- C:\Users\Deki\AppData\Local\Google\Chrome\Application\16.0.912.75\pdf.dll
MOD - [2012.01.05 10:47:19 | 000,122,880 | ---- | M] () -- C:\Users\Deki\AppData\Local\Google\Chrome\Application\16.0.912.75\avutil-51.dll
MOD - [2012.01.05 10:47:18 | 000,222,208 | ---- | M] () -- C:\Users\Deki\AppData\Local\Google\Chrome\Application\16.0.912.75\avformat-53.dll
MOD - [2012.01.05 10:47:17 | 001,746,432 | ---- | M] () -- C:\Users\Deki\AppData\Local\Google\Chrome\Application\16.0.912.75\avcodec-53.dll
MOD - [2012.01.05 08:06:01 | 008,593,056 | ---- | M] () -- C:\Users\Deki\AppData\Local\Google\Chrome\Application\16.0.912.75\gcswf32.dll
MOD - [2012.01.05 08:06:01 | 008,593,056 | ---- | M] () -- C:\Users\Deki\AppData\Local\Google\Chrome\APPLIC~1\160912~1.75\gcswf32.dll
MOD - [2011.11.17 16:30:19 | 000,028,160 | ---- | M] () -- C:\Users\Deki\AppData\Roaming\Azureus\plugins\azutp\win32\utp.dll
MOD - [2011.04.27 08:56:18 | 000,102,400 | ---- | M] () -- C:\Program Files (x86)\Vuze\plugins\azitunes\jacob-1.14.3-x86.dll
MOD - [2011.04.27 08:56:10 | 000,087,480 | ---- | M] () -- C:\Program Files (x86)\Vuze\aereg.dll
MOD - [2011.03.17 00:11:16 | 004,297,568 | ---- | M] () -- C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
MOD - [2010.10.20 15:45:26 | 008,801,120 | ---- | M] () -- C:\PROGRA~2\MICROS~1\Office14\1033\GrooveIntlResource.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2011.10.12 21:09:44 | 000,204,288 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2011.10.12 16:19:48 | 000,361,984 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:64bit: - [2010.09.22 18:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2009.07.14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009.07.14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2011.12.15 16:30:22 | 000,008,192 | ---- | M] () [Auto | Stopped] -- C:\Windows\SysWOW64\srvany.exe -- (KMService)
SRV - [2011.11.23 02:36:24 | 002,391,832 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2012\avgfws.exe -- (avgfws)
SRV - [2011.10.12 06:25:22 | 004,433,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2011.08.02 06:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe -- (avgwd)
SRV - [2011.06.06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011.04.01 11:14:30 | 000,183,560 | ---- | M] (Microsoft Corporation.) [On_Demand | Stopped] -- C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
SRV - [2011.03.28 11:21:16 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE -- (SeaPort)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2011.11.18 08:40:23 | 000,279,616 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2011.10.12 21:56:18 | 010,207,232 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2011.10.12 21:56:18 | 010,207,232 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2011.10.12 20:30:42 | 000,317,952 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2011.10.07 06:23:46 | 000,283,728 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (Avgldx64)
DRV:64bit: - [2011.09.13 06:30:08 | 000,037,456 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgrkx64.sys -- (Avgrkx64)
DRV:64bit: - [2011.08.08 06:08:58 | 000,046,672 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (Avgmfx64)
DRV:64bit: - [2011.07.11 01:14:36 | 000,375,376 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (Avgtdia)
DRV:64bit: - [2011.07.11 01:14:08 | 000,029,776 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV:64bit: - [2011.07.11 01:14:06 | 000,120,400 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV:64bit: - [2011.07.11 01:14:06 | 000,026,704 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AVGIDSEH.sys -- (AVGIDSEH)
DRV:64bit: - [2011.06.06 23:07:00 | 000,231,440 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2011.05.23 01:03:28 | 000,048,992 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgfwd6a.sys -- (Avgfwfd)
DRV:64bit: - [2011.05.13 15:37:54 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
DRV:64bit: - [2011.03.11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.11.20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.11.20 12:03:42 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2010.06.14 09:32:54 | 000,016,448 | ---- | M] (Teruten Inc) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TFsExDisk.sys -- (TFsExDisk)
DRV:64bit: - [2010.04.27 03:25:16 | 000,161,280 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ss_bmdm.sys -- (ss_bmdm)
DRV:64bit: - [2010.04.27 03:25:16 | 000,127,488 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ss_bbus.sys -- (ss_bbus) SAMSUNG USB Mobile Device (WDM)
DRV:64bit: - [2010.04.27 03:25:16 | 000,018,944 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ss_bmdfl.sys -- (ss_bmdfl) SAMSUNG USB Mobile Modem (Filter)
DRV:64bit: - [2010.04.07 12:14:50 | 000,446,304 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\netr6164.sys -- (rt61x64)
DRV:64bit: - [2010.02.18 09:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdiox64.sys -- (amdiox64)
DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.03.01 23:05:32 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV - [2010.06.14 09:32:54 | 000,016,448 | ---- | M] (Teruten Inc) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\TFsExDisk.Sys -- (TFsExDisk)
DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2008.07.22 13:32:28 | 000,026,728 | ---- | M] (REALiX(tm)) [Kernel | Auto | Running] -- D:\Cane\Programi za windows\alati\hw32_230\HWiNFO64A.SYS -- (HWiNFO32)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.rs./
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = sr-rs
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B9 C6 90 40 1C A5 CC 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://search.babylon.com/?AF=100995&babsrc=HP.....fd07991ce5
IE - HKCU\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:12.0.0.1865
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.7
FF - prefs.js..extensions.enabledItems: {5911488E-9D1E-40ec-8CBB-06B231CC153F}:2.3.0
FF - prefs.js..keyword.URL: "http://klit.startnow.com/s/?src=addrbar&provider=&provider_name=yahoo&provider_code=&partner_id=693&product_id=741&affiliate_id=&channel=&toolbar_id=200&toolbar_version=2.3.0&install_country=RS&install_date=20111123&user_guid=8B7E3038D5C74F608AE0C8A72FA4A58D&machine_id=5cefee7dff0e7b00d8255e8eeeb28e9d&browser=FF&os=win&os_version=6.1-x64-SP1&q="
FF - prefs.js..browser.startup.homepage: "http://klit.startnow.com/?src=startpage&provider=&provider_name=yahoo&provider_code=&partner_id=693&product_id=741&affiliate_id=&channel=&toolbar_id=200&toolbar_version=2.3.0&install_country=RS&install_date=20111123&user_guid=8B7E3038D5C74F608AE0C8A72FA4A58D&machine_id=5cefee7dff0e7b00d8255e8eeeb28e9d&browser=FF&os=win&os_version=6.1-x64-SP1"
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: ""
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: ""
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: "http://home.sweetim.com/?barid={18A2326A-A330-41AD-BFC3-895E43B4B538}"
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: ""
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: ""
FF - prefs.js..browser.search.selectedEngine: "SweetIM Search"
FF - prefs.js..browser.search.defaultenginename: "SweetIM Search"
FF - prefs.js..browser.search.defaulturl: ""

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.669: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.669: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.669: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.669: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.669: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Deki\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Deki\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2011.12.23 09:10:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011.11.17 18:19:01 | 000,000,000 | ---D | M]

[2011.11.23 13:49:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Deki\AppData\Roaming\mozilla\Extensions
[2011.11.23 22:45:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Deki\AppData\Roaming\mozilla\Firefox\Profiles\p7ygnt4w.default\extensions
[2011.12.30 17:49:14 | 000,003,915 | ---- | M] () -- C:\Users\Deki\AppData\Roaming\Mozilla\Firefox\Profiles\p7ygnt4w.default\searchplugins\SweetIM Search.xml
[2011.11.23 13:52:47 | 000,001,390 | ---- | M] () -- C:\Users\Deki\AppData\Roaming\Mozilla\Firefox\Profiles\p7ygnt4w.default\searchplugins\yahoo-zugo.xml
[2011.12.23 09:10:16 | 000,000,000 | ---D | M] (AVG Safe Search) -- C:\PROGRAM FILES (X86)\AVG\AVG2012\FIREFOX4
[2011.11.17 18:19:01 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- C:\PROGRAMDATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
File not found (No name found) -- C:\USERS\DEKI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P7YGNT4W.DEFAULT\EXTENSIONS\{5911488E-9D1E-40EC-8CBB-06B231CC153F}

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Deki\AppData\Local\Google\Chrome\Application\16.0.912.75\gcswf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = D:\PFiles\Plugins\np-mswmp.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Deki\AppData\Local\Google\Chrome\Application\16.0.912.75\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Deki\AppData\Local\Google\Chrome\Application\16.0.912.75\pdf.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\Deki\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1857_0\plugins/avgnpss.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\Deki\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.3_0\
CHR - Extension: Google \u043F\u0440\u0435\u0442\u0440\u0430\u0433\u0430 = C:\Users\Deki\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: AutocompletePro plugin for chrome = C:\Users\Deki\AppData\Local\Google\Chrome\User Data\Default\Extensions\defdhglnppeioeflggkmglipcecffkhk\1.0_0\
CHR - Extension: Youtube player = C:\Users\Deki\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfkcjldgiakjhjmaplilpkpnfmlldddb\6.1.8_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\Deki\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: AVG Safe Search = C:\Users\Deki\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1901_0\
CHR - Extension: Gmail = C:\Users\Deki\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (AC-Pro) - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Program Files (x86)\AutocompletePro\64\AutocompletePro64.dll (SimplyGen)
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (4sharedExt) - {95525BD9-6136-4A26-8263-9CEE295D442D} - C:\Program Files (x86)\4shared Toolbar\4sharedExt64.dll File not found
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (AC-Pro) - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Program Files (x86)\AutocompletePro\AutocompletePro.dll (SimplyGen)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (4shared Toolbar) - {95080B13-AA71-4EE8-B951-7E98221E1ED5} - C:\Program Files (x86)\4shared Toolbar\4sharedbar64.dll File not found
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [AutoStartNPSAgent] C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware (cleanup)] C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000 File not found
O8:64bit: - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105 File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105 File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.5.60.1 212.200.190.166 212.200.191.166
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8769E5CF-00DC-41A6-8164-D1DF4F7F59EA}: DhcpNameServer = 10.5.60.1 212.200.190.166 212.200.191.166
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012.01.11 19:21:39 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Deki\Desktop\OTL.exe
[2012.01.11 18:48:56 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{59909DE9-5262-4F5A-AB1C-7783C2522FD1}
[2012.01.11 18:48:35 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{E5EDAEC4-E2E4-4B1F-97B4-A5869D166E20}
[2012.01.11 17:01:12 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{89A86E16-3DC6-4EDE-B6D2-43DBB9E3695B}
[2012.01.11 16:43:20 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{531E5BC8-AFFD-425E-8E3F-23B80C295F59}
[2012.01.11 16:43:08 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{6B25E9B2-F239-458C-8A00-7119391BC35D}
[2012.01.11 08:08:22 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{56B2B996-9429-4371-9AE4-7591D107F1D9}
[2012.01.10 15:11:38 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{946A8AE8-14D2-477E-888F-614B6FC2F877}
[2012.01.10 15:11:27 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{A8261B1D-EE89-4373-B5B9-9CAD83B2CA33}
[2012.01.10 10:26:25 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{E276A126-2768-422A-98B4-CEFD82DA4A2C}
[2012.01.09 23:35:19 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{C40761CA-3BF3-48B4-9EA1-7AB7F6236341}
[2012.01.09 23:35:05 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{879315D5-21B9-420F-AA8E-28DE12679372}
[2012.01.09 10:08:29 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{835F1749-14CB-4BF3-AD78-E0E95F24840C}
[2012.01.09 10:08:13 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{6859A8A9-9D66-4D66-8A26-AEA28BF327BC}
[2012.01.08 22:02:55 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{7373184E-0FD8-4F36-B8F4-146FC0124E3F}
[2012.01.08 22:02:41 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{9A2EE284-66D0-4160-931B-27CF5A10ED9F}
[2012.01.08 17:27:02 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Roaming\Utherverse
[2012.01.08 16:38:50 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Red Light Center 3D Client
[2012.01.08 15:04:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Utherverse Digital Inc
[2012.01.06 20:09:05 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{E9A35954-DC67-41BC-8180-AB960E2DCC6E}
[2012.01.06 20:08:54 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{4516A08A-B703-4F7F-9FF5-51393CFE4D0B}
[2012.01.06 07:51:32 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{E8175A8F-CD70-4A22-8BFD-C95B74BCE872}
[2012.01.05 08:22:46 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{6C69D886-94C8-4E5D-BA07-37B8126954AE}
[2012.01.04 13:27:22 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{31E76B57-BCE5-430F-9371-9A4F928633F3}
[2012.01.04 08:24:11 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{CF7EC7FF-2630-4D91-9E49-CDB33E0328EC}
[2012.01.03 11:40:30 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{54B239FB-79E0-4CAE-83CE-31A146BE3920}
[2012.01.03 11:40:19 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{9333313B-3C9B-4C98-8E99-7AFAC486F5E5}
[2012.01.03 11:28:09 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{8B5640C7-F64A-472C-820C-FC9E5C9F71C5}
[2012.01.02 12:37:05 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{E7EAEBE2-3FFA-455D-8BFF-270FBA83E496}
[2012.01.02 12:36:53 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{59399635-06E4-46F1-A5AF-0C7266B06A97}
[2012.01.02 00:35:20 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{4BF792FA-7A9C-4D82-9A6D-055197EDDA58}
[2012.01.02 00:35:03 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{E8F94635-3C3F-4EA3-9C6E-1B658CE243BC}
[2012.01.01 01:14:04 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{053FB283-FA11-4DF7-8A4B-8A637D757003}
[2012.01.01 01:13:48 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{E96729F6-9794-4597-ABF3-E6381EACA00C}
[2011.12.31 11:12:22 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{F6FA5392-329D-4BE5-AAA9-A9CB2FA35A23}
[2011.12.31 10:34:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fighter Factory
[2011.12.31 06:49:03 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{FA3BE92B-62CC-421A-AEFD-7BBF4137EAEA}
[2011.12.30 19:49:43 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{D8D0F92E-7CD4-416F-BBF8-076E6BF473C2}
[2011.12.30 19:28:31 | 000,000,000 | ---D | C] -- C:\Users\Deki\LocalLow
[2011.12.30 19:27:32 | 000,000,000 | ---D | C] -- C:\ProgramData\4Sync
[2011.12.30 18:57:29 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{09BF2436-AB51-452C-8B83-CBE8EA182250}
[2011.12.30 18:46:34 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Roaming\QuickStoresToolbar
[2011.12.30 18:46:31 | 000,000,000 | ---D | C] -- C:\Program Files\Unlocker
[2011.12.30 18:31:53 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011.12.30 11:35:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Ubisoft
[2011.12.30 11:35:46 | 000,000,000 | ---D | C] -- C:\Users\Deki\Documents\Assassin's Creed Revelations
[2011.12.30 11:31:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Catalyst
[2011.12.29 13:00:06 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{ED8E29F8-D635-4F6A-9788-A089592723A0}
[2011.12.29 09:33:55 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{E0457C31-F61E-476A-88D4-AAD820E77669}
[2011.12.28 21:24:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Blizzard Entertainment
[2011.12.28 21:24:51 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Blizzard Entertainment
[2011.12.28 07:32:23 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{2880C7B2-EC32-42CB-A99E-AD6D7ED3D9CA}
[2011.12.27 20:06:38 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee
[2011.12.27 19:37:09 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{A3BC6C5E-0B99-421C-B820-035CC36D2E72}
[2011.12.27 06:37:55 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{FA8A8776-9A69-4EB3-B8B1-B1BC752A55DB}
[2011.12.26 10:05:02 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{971EBF38-28D9-4669-9059-1D8A30629D07}
[2011.12.25 13:18:43 | 000,000,000 | ---D | C] -- C:\Users\Deki\Documents\BlackMirrorIII
[2011.12.25 13:16:43 | 000,527,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_7.dll
[2011.12.25 13:16:43 | 000,518,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_7.dll
[2011.12.25 13:16:43 | 000,077,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_5.dll
[2011.12.25 13:16:43 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_5.dll
[2011.12.25 13:16:42 | 002,526,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_43.dll
[2011.12.25 13:16:42 | 002,106,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_43.dll
[2011.12.25 13:16:42 | 000,239,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_7.dll
[2011.12.25 13:16:42 | 000,176,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_7.dll
[2011.12.25 13:16:41 | 001,907,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dcsx_43.dll
[2011.12.25 13:16:41 | 001,868,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dcsx_43.dll
[2011.12.25 13:16:41 | 000,511,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_43.dll
[2011.12.25 13:16:41 | 000,470,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_43.dll
[2011.12.25 13:16:41 | 000,276,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx11_43.dll
[2011.12.25 13:16:41 | 000,248,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx11_43.dll
[2011.12.25 13:16:40 | 002,401,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_43.dll
[2011.12.25 13:16:40 | 001,998,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_43.dll
[2011.12.25 13:08:27 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Viva Media
[2011.12.25 02:37:28 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Roaming\Alawar Entertainment
[2011.12.25 02:35:50 | 000,000,000 | ---D | C] -- C:\Downloads
[2011.12.24 00:13:34 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{58A43D18-D992-4C8B-A512-CDBC94872B0F}
[2011.12.24 00:13:23 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{DAB11EDC-498F-41D3-87AF-4A31C3943C3E}
[2011.12.22 22:25:23 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{13C9AB4E-3926-4845-898F-5C213545C84A}
[2011.12.22 22:25:11 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{2976FE28-DA08-41E8-ADF0-73071779B95E}
[2011.12.22 10:34:12 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{FF61D07B-7AAB-4567-8BF0-51DC55D4D905}
[2011.12.21 08:52:54 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{949B2DB4-CDE5-4C93-9DD9-896C7A215628}
[2011.12.20 11:29:05 | 000,000,000 | ---D | C] -- C:\Users\Deki\Documents\Moje primljene datoteke
[2011.12.20 11:26:58 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{76C641E7-5FB0-4E1E-B1E0-5218D769544B}
[2011.12.20 11:26:38 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{5FC9AD0D-70B1-4B59-B2AF-759CFD6F4D60}
[2011.12.20 10:09:52 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{6ED43224-A163-4626-BBB7-5EF02DCDCE6C}
[2011.12.19 10:05:47 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{87FA8DC6-F3B9-4263-8783-D8442CB76A8D}
[2011.12.18 23:09:44 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{1C42325B-EBFE-40A0-8877-791828D2C843}
[2011.12.18 23:09:28 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{F1BE15A2-670F-4B88-AA90-6EED85FB355B}
[2011.12.18 08:29:29 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{A63E0BDE-33DA-4ABC-8A3B-5A09A166ED3D}
[2011.12.18 08:13:30 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\DAEMON Tools Images
[2011.12.18 07:16:47 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{911B7AC1-ECB5-4C04-8F35-2BE666D1ED38}
[2011.12.18 02:58:39 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{4D93542F-E6C9-48CA-BC78-FC009B377693}
[2011.12.18 02:58:23 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{43C4DD28-460B-43F8-BF40-49AB35644B8C}
[2011.12.18 00:47:16 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{ACA2D432-6A28-4573-98C2-AC9289F36E7E}
[2011.12.17 23:02:16 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{9A963D04-C99A-485E-AC34-C9CF4D074349}
[2011.12.17 22:31:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
[2011.12.17 22:29:36 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Sync Framework
[2011.12.17 22:26:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 8
[2011.12.17 22:19:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2011.12.17 22:18:48 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Synchronization Services
[2011.12.17 22:18:34 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2011.12.17 22:17:23 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2011.12.17 22:17:23 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server Compact Edition
[2011.12.17 22:16:32 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Analysis Services
[2011.12.17 22:16:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Analysis Services
[2011.12.17 22:15:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
[2011.12.17 22:15:23 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2011.12.17 22:11:57 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2011.12.17 22:04:18 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{D0E003AD-EAAA-44EC-AEDE-7EB1A49BAFA9}
[2011.12.17 07:46:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Conduit
[2011.12.17 07:46:39 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\Conduit
[2011.12.17 07:46:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Vuze_Remote
[2011.12.17 07:28:55 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{183ED37B-EBD0-407F-8E67-F95ED0344187}
[2011.12.16 17:25:48 | 000,000,000 | ---D | C] -- C:\Users\Deki\Documents\My Art
[2011.12.16 17:24:23 | 000,000,000 | ---D | C] -- C:\Users\Deki\Documents\NPS
[2011.12.16 11:42:27 | 000,000,000 | -H-D | C] -- C:\ProgramData\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}
[2011.12.16 11:42:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uniblue
[2011.12.16 11:42:09 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\PackageAware
[2011.12.16 11:36:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shark007 Codecs
[2011.12.16 11:36:12 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Roaming\Win7codecs
[2011.12.16 11:36:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Win7codecs
[2011.12.16 11:34:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Win7codecs
[2011.12.16 10:46:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2011.12.16 10:46:10 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe
[2011.12.16 10:46:10 | 000,149,280 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaw.exe
[2011.12.16 10:46:10 | 000,149,280 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\java.exe
[2011.12.16 08:20:22 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{DAB85C4F-84C0-4D15-8E4A-7C1AB5CE75BB}
[2011.12.15 23:07:24 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{527112A0-1E88-44FC-862D-08AE10F9B139}
[2011.12.15 18:21:22 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Roaming\OpenOffice.org
[2011.12.15 18:16:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2011.12.15 18:16:21 | 000,472,808 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\deployJava1.dll
[2011.12.15 18:15:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2011.12.15 18:02:02 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{880FBBBA-C54A-42E2-AE1F-1F016754A4CB}
[2011.12.15 15:19:58 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{7446BF77-CB30-4024-906D-F6E71453299D}
[2011.12.15 14:00:20 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{D99099DB-ABA5-4597-A3C2-42C45BC6BBAF}
[2011.12.15 10:22:19 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{F0D0E648-E7DE-4853-9EA0-D535B63A8935}
[2011.12.15 00:00:44 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{BA77F068-EBCE-497D-9372-D1AA3EF21164}
[2011.12.14 13:12:39 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{788CF8B3-6AE6-4670-AED7-F26BB708EE86}
[2011.12.14 12:41:52 | 000,096,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2011.12.14 12:41:52 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2011.12.14 12:41:51 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2011.12.14 12:41:51 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2011.12.14 12:41:50 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2011.12.14 12:41:50 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2011.12.14 12:41:48 | 001,493,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2011.12.14 12:41:48 | 001,427,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2011.12.14 12:41:47 | 002,309,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2011.12.14 12:41:47 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2011.12.14 12:41:46 | 000,818,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2011.12.14 09:09:50 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{76D270BD-97A8-4AEF-AA4D-BED493342139}
[2011.12.14 09:04:24 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\csrsrv.dll
[2011.12.14 09:04:22 | 000,723,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EncDec.dll
[2011.12.14 09:04:22 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\EncDec.dll
[2011.12.14 08:50:56 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{DD839D89-F7F6-47A1-ADE1-1762654D042E}
[2011.12.13 09:00:55 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{28CCD66D-1F71-479F-8E56-50D9BBDA3506}
[2011.12.13 09:00:44 | 000,000,000 | ---D | C] -- C:\Users\Deki\AppData\Local\{5D948416-1739-483F-8942-DD016A3D39C4}
[2011.09.25 16:56:26 | 000,216,064 | ---- | C] ( ) -- C:\Windows\SysWow64\lagarith.dll

========== Files - Modified Within 30 Days ==========

[2012.01.11 21:39:00 | 000,000,946 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-227424746-2864936110-1864147507-1000UA.job
[2012.01.11 21:15:00 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.01.11 20:00:00 | 000,000,374 | ---- | M] () -- C:\Windows\tasks\At9.job
[2012.01.11 20:00:00 | 000,000,374 | ---- | M] () -- C:\Windows\tasks\At8.job
[2012.01.11 20:00:00 | 000,000,374 | ---- | M] () -- C:\Windows\tasks\At7.job
[2012.01.11 20:00:00 | 000,000,374 | ---- | M] () -- C:\Windows\tasks\At6.job
[2012.01.11 20:00:00 | 000,000,374 | ---- | M] () -- C:\Windows\tasks\At5.job
[2012.01.11 20:00:00 | 000,000,374 | ---- | M] () -- C:\Windows\tasks\At4.job
[2012.01.11 20:00:00 | 000,000,374 | ---- | M] () -- C:\Windows\tasks\At3.job
[2012.01.11 20:00:00 | 000,000,374 | ---- | M] () -- C:\Windows\tasks\At21.job
[2012.01.11 20:00:00 | 000,000,374 | ---- | M] () -- C:\Windows\tasks\At20.job
[2012.01.11 20:00:00 | 000,000,374 | ---- | M] () -- C:\Windows\tasks\At2.job
[2012.01.11 20:00:00 | 000,000,374 | ---- | M] () -- C:\Windows\tasks\At19.job
[2012.01.11 20:00:00 | 000,000,374 | ---- | M] () -- C:\Windows\tasks\At18.job
[2012.01.11 20:00:00 | 000,000,374 | ---- | M] () -- C:\Windows\tasks\At17.job
[2012.01.11 20:00:00 | 000,000,374 | ---- | M] () -- C:\Windows\tasks\At16.job
[2012.01.11 20:00:00 | 000,000,374 | ---- | M] () -- C:\Windows\tasks\At15.job
[2012.01.11 20:00:00 | 000,000,374 | ---- | M] () -- C:\Windows\tasks\At14.job
[2012.01.11 20:00:00 | 000,000,374 | ---- | M] () -- C:\Windows\tasks\At13.job
[2012.01.11 20:00:00 | 000,000,374 | ---- | M] () -- C:\Windows\tasks\At12.job
[2012.01.11 20:00:00 | 000,000,374 | ---- | M] () -- C:\Windows\tasks\At11.job
[2012.01.11 20:00:00 | 000,000,374 | ---- | M] () -- C:\Windows\tasks\At10.job
[2012.01.11 20:00:00 | 000,000,374 | ---- | M] () -- C:\Windows\tasks\At1.job
[2012.01.11 19:22:00 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Deki\Desktop\OTL.exe
[2012.01.11 16:47:20 | 000,620,694 | ---- | M] () -- C:\Windows\SysNative\drivers\AVG\iavifw.avm
[2012.01.11 13:44:23 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-227424746-2864936110-1864147507-1000Core.job
[2012.01.11 12:47:44 | 086,504,635 | ---- | M] () -- C:\Windows\SysNative\drivers\AVG\incavi.avm
[2012.01.11 12:15:00 | 000,000,890 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.01.11 08:47:11 | 000,396,008 | ---- | M] () -- C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2012.01.11 08:12:46 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.01.11 08:12:46 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.01.11 08:07:18 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.01.11 08:07:12 | 1609,424,896 | -HS- | M] () -- C:\hiberfil.sys
[2012.01.07 18:34:11 | 000,000,787 | ---- | M] () -- C:\Users\Deki\AppData\Local\RT61_{8769E5CF-00DC-41A6-8164-D1DF4F7F59EA}_prof
[2012.01.04 08:30:29 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2011.12.31 02:05:17 | 000,731,650 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011.12.31 02:05:17 | 000,615,810 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011.12.31 02:05:17 | 000,106,190 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011.12.30 18:46:35 | 000,000,185 | ---- | M] () -- C:\Users\Deki\Application Data\Microsoft\Internet Explorer\Quick Launch\QuickStores.url
[2011.12.30 11:31:30 | 000,000,728 | ---- | M] () -- C:\Users\Public\Desktop\Assassins Creed Revelations.lnk
[2011.12.25 12:20:09 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2011.12.17 23:01:11 | 000,434,320 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011.12.17 07:47:26 | 000,001,848 | ---- | M] () -- C:\Users\Public\Desktop\Vuze.lnk
[2011.12.17 07:47:26 | 000,001,848 | ---- | M] () -- C:\Users\Deki\Application Data\Microsoft\Internet Explorer\Quick Launch\Vuze.lnk
[2011.12.15 20:27:41 | 000,000,376 | ---- | M] () -- C:\Windows\ODBC.INI
[2011.12.15 16:30:22 | 000,008,192 | ---- | M] () -- C:\Windows\SysWow64\srvany.exe

========== Files Created - No Company Name ==========

[2012.01.07 18:34:11 | 000,000,787 | ---- | C] () -- C:\Users\Deki\AppData\Local\RT61_{8769E5CF-00DC-41A6-8164-D1DF4F7F59EA}_prof
[2012.01.04 08:30:29 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2011.12.30 18:46:35 | 000,000,185 | ---- | C] () -- C:\Users\Deki\Application Data\Microsoft\Internet Explorer\Quick Launch\QuickStores.url
[2011.12.30 18:30:46 | 000,001,009 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat.com.lnk
[2011.12.30 11:31:30 | 000,000,728 | ---- | C] () -- C:\Users\Public\Desktop\Assassins Creed Revelations.lnk
[2011.12.25 12:20:09 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2011.12.15 21:11:27 | 000,000,374 | ---- | C] () -- C:\Windows\tasks\At21.job
[2011.12.15 21:10:16 | 000,000,374 | ---- | C] () -- C:\Windows\tasks\At20.job
[2011.12.15 20:29:26 | 000,000,374 | ---- | C] () -- C:\Windows\tasks\At19.job
[2011.12.15 20:17:55 | 000,000,374 | ---- | C] () -- C:\Windows\tasks\At18.job
[2011.12.15 20:17:19 | 000,000,374 | ---- | C] () -- C:\Windows\tasks\At17.job
[2011.12.15 20:16:53 | 000,000,374 | ---- | C] () -- C:\Windows\tasks\At16.job
[2011.12.15 16:45:39 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\srvany.exe
[2011.12.15 14:51:49 | 000,000,374 | ---- | C] () -- C:\Windows\tasks\At15.job
[2011.12.15 14:51:28 | 000,000,374 | ---- | C] () -- C:\Windows\tasks\At14.job
[2011.12.15 14:51:14 | 000,000,374 | ---- | C] () -- C:\Windows\tasks\At13.job
[2011.12.15 14:48:57 | 000,000,374 | ---- | C] () -- C:\Windows\tasks\At12.job
[2011.12.15 14:48:31 | 000,000,374 | ---- | C] () -- C:\Windows\tasks\At11.job
[2011.12.15 14:47:37 | 000,000,374 | ---- | C] () -- C:\Windows\tasks\At10.job
[2011.12.15 14:47:06 | 000,000,374 | ---- | C] () -- C:\Windows\tasks\At9.job
[2011.12.15 14:46:16 | 000,000,374 | ---- | C] () -- C:\Windows\tasks\At8.job
[2011.12.15 14:45:40 | 000,000,374 | ---- | C] () -- C:\Windows\tasks\At7.job
[2011.12.07 07:53:24 | 004,770,816 | ---- | C] () -- C:\Windows\SysWow64\x264vfw.dll
[2011.11.23 13:52:34 | 000,175,616 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2011.11.17 20:26:52 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011.11.17 15:32:04 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2011.10.19 22:14:52 | 000,059,904 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll
[2011.07.12 15:56:50 | 000,074,752 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2011.03.17 18:51:44 | 000,003,929 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2009.07.14 06:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 03:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009.07.14 03:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009.07.14 01:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009.07.13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2007.10.25 17:26:10 | 000,005,632 | ---- | C] () -- C:\Windows\SysWow64\drivers\StarOpen.sys
[2007.02.05 16:05:26 | 000,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI

< End of report >

offline
  • Fil  Male
  • Legendarni građanin
  • Pridružio: 11 Jun 2009
  • Poruke: 16586

Neophodno je uraditi sledeće korake:


Arrow Korak 1

Otvori pretraživač Chrome i u njemu ukucaj sledeću adresu:

chrome://plugins/

Neophodno je onemogućiti (disable) plugin YoutubePlayer i sve ostale nepotrebne pluginove.



Arrow Korak 2

Ponovo pokreni program OTL dvoklikom na ikonicu;

U beli okvir prozora gde piše Custom Scans/Fixes iskopirati sledeći tekst:

:OTL
FF - prefs.js..extensions.enabledItems: {5911488E-9D1E-40ec-8CBB-06B231CC153F}:2.3.0
FF - prefs.js..keyword.URL: "http://klit.startnow.com/s/?src=addrbar&provider=&provider_name=yahoo&provider_code=&partner_id=693&product_id=741&affiliate_id=&channel=&toolbar_id=200&toolbar_version=2.3.0&install_country=RS&install_date=20111123&user_guid=
FF - prefs.js..browser.startup.homepage: "http://klit.startnow.com/?src=startpage&provider=&provider_name=yahoo&provider_code=&partner_id=693&product_id=741&affiliate_id=&channel=&toolbar_id=200&toolbar_version=2.3.0&install_country=RS&install_date=201111
[2011.11.23 13:52:47 | 000,001,390 | ---- | M] () -- C:\Users\Deki\AppData\Roaming\Mozilla\Firefox\Profiles\p7ygnt4w.default\searchplugins\yahoo-zugo.xml
File not found (No name found) -- C:\USERS\DEKI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P7YGNT4W.DEFAULT\EXTENSIONS\{5911488E-9D1E-40EC-8CBB-06B231CC153F}
CHR - Extension: AutocompletePro plugin for chrome = C:\Users\Deki\AppData\Local\Google\Chrome\User Data\Default\Extensions\defdhglnppeioeflggkmglipcecffkhk\1.0_0\
CHR - Extension: Youtube player = C:\Users\Deki\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfkcjldgiakjhjmaplilpkpnfmlldddb\6.1.8_0\
O2 - BHO: (AC-Pro) - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Program Files(x86)\AutocompletePro\64\AutocompletePro64.dll (SimplyGen)
O2 - BHO: (AC-Pro) - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Program Files(x86)\AutocompletePro\AutocompletePro.dll (SimplyGen)
O2:64bit: - BHO: (4sharedExt) - {95525BD9-6136-4A26-8263-9CEE295D442D} - C:\Program Files (x86)\4shared Toolbar\4sharedExt64.dll File not found
O3:64bit: - HKLM\..\Toolbar: (4shared Toolbar) - {95080B13-AA71-4EE8-B951-7E98221E1ED5} - C:\Program Files (x86)\4shared Toolbar\4sharedbar64.dll File not found

:Files
C:\Program Files (x86)\AutocompletePro\

:Commands
[purity]
[EmptyTemp]
[Reboot]



Klikni taster Run Fix;


Log koji dobiješ iskopiraj ovde u poruci.


Exclamation Takođe, postavi svež OTL log po početnom uputstvu za otvaranje teme u Ambulanti



Arrow Korak 3

- Klikni na dugme Start i u polje za pretragu upiši sledeću liniju:

notepad C:\Windows\tasks\At1.job

Idea Vidi sliku

Otvoriće se prozor Notepada; označi sav sadržaj i iskopiraj ga u temu na forumu.


- Opet klikni na dugme Start i u polje za pretragu upiši sledeću liniju:

notepad C:\Windows\tasks\At15.job

Otvoriće se prozor Notepada; označi sav sadržaj i iskopiraj ga u temu na forumu.



Arrow Napiši mi kakvo je stanje sa računarom nakon što obaviš ove korake (ima li problema)

offline
  • Pridružio: 17 Okt 2011
  • Poruke: 311

Napisano: 12 Jan 2012 7:50

All processes killed
========== OTL ==========
Prefs.js: {5911488E-9D1E-40ec-8CBB-06B231CC153F}:2.3.0 removed from extensions.enabledItems
Prefs.js: "http://klit.startnow.com/s/?src=addrbar&provider=&provider_name=yahoo&provider_code=&partner_id=693&product_id=741&affiliate_id=&channel=&toolbar_id=200&toolbar_version=2.3.0&install_country=RS&install_date=20111123&user_guid= removed from keyword.URL
Prefs.js: "http://klit.startnow.com/?src=startpage&provider=&provider_name=yahoo&provider_code=&partner_id=693&product_id=741&affiliate_id=&channel=&toolbar_id=200&toolbar_version=2.3.0&install_country=RS&install_date=201111 removed from browser.startup.homepage
C:\Users\Deki\AppData\Roaming\Mozilla\Firefox\Profiles\p7ygnt4w.default\searchplugins\yahoo-zugo.xml moved successfully.
C:\Users\Deki\AppData\Local\Google\Chrome\User Data\Default\Extensions\defdhglnppeioeflggkmglipcecffkhk\1.0_0\icons folder moved successfully.
C:\Users\Deki\AppData\Local\Google\Chrome\User Data\Default\Extensions\defdhglnppeioeflggkmglipcecffkhk\1.0_0 folder moved successfully.
C:\Users\Deki\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfkcjldgiakjhjmaplilpkpnfmlldddb\6.1.8_0 folder moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0FB6A909-6086-458F-BD92-1F8EE10042A0}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0FB6A909-6086-458F-BD92-1F8EE10042A0}\ deleted successfully.
File C:\Program Files(x86)\AutocompletePro\64\AutocompletePro64.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0FB6A909-6086-458F-BD92-1F8EE10042A0}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0FB6A909-6086-458F-BD92-1F8EE10042A0}\ not found.
File C:\Program Files(x86)\AutocompletePro\AutocompletePro.dll not found.
64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95525BD9-6136-4A26-8263-9CEE295D442D}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95525BD9-6136-4A26-8263-9CEE295D442D}\ deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{95080B13-AA71-4EE8-B951-7E98221E1ED5} deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95080B13-AA71-4EE8-B951-7E98221E1ED5}\ deleted successfully.
========== FILES ==========
C:\Program Files (x86)\AutocompletePro\support@predictad.com\defaults\preferences folder moved successfully.
C:\Program Files (x86)\AutocompletePro\support@predictad.com\defaults folder moved successfully.
C:\Program Files (x86)\AutocompletePro\support@predictad.com\chrome\content folder moved successfully.
C:\Program Files (x86)\AutocompletePro\support@predictad.com\chrome folder moved successfully.
C:\Program Files (x86)\AutocompletePro\support@predictad.com folder moved successfully.
C:\Program Files (x86)\AutocompletePro\chrome folder moved successfully.
C:\Program Files (x86)\AutocompletePro\64 folder moved successfully.
C:\Program Files (x86)\AutocompletePro folder moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 56475 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Deki
->Temp folder emptied: 677457466 bytes
->Temporary Internet Files folder emptied: 14200068 bytes
->Java cache emptied: 928104 bytes
->FireFox cache emptied: 3987587 bytes
->Google Chrome cache emptied: 15374321 bytes
->Flash cache emptied: 59330 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1290109 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50443 bytes
RecycleBin emptied: 0 bytes

https://www.mycity.rs/must-login.png

Dopuna: 12 Jan 2012 8:02

3 korak:
notepad C:\Windows\tasks\At1.job i notepad C:\Windows\tasks\At15.job
nisam uspeo izvršiti jer "nije dozvoljen pristup beležnicama".

Dopuna: 12 Jan 2012 8:17

P.S. no i pored toga što nisam uspeo ispoštovati 3. korak - za sada fejs radi normalno bez ranije uočenih ovde navedenih problema problema. Molim vas da me obavestite o daljim postupcima.

offline
  • Fil  Male
  • Legendarni građanin
  • Pridružio: 11 Jun 2009
  • Poruke: 16586

Pozdrav,

Da, bolje je stanje na računaru.


Prikači mi te dve datoteke C:\Windows\tasks\At1.job i C:\Windows\tasks\At15.job preko sledećeg linka:

http://www.mycity.rs/ambulanta-upload.php

Možeš i da ubaciš u arhivu (ZIP, RAR), ako ti je tako lakše.

Javi u temi kad to uradiš (ili ako bude bilo problema pri uploadu).

offline
  • Pridružio: 17 Okt 2011
  • Poruke: 311

https://www.mycity.rs/must-login.png

https://www.mycity.rs/must-login.png

Evo šaljem ove datoteke lociirane u system32 wndowsa valjda je to to. Javite mi da li je uredu.

offline
  • Fil  Male
  • Legendarni građanin
  • Pridružio: 11 Jun 2009
  • Poruke: 16586

Potrebno je da pažljivo čitaš poruke. Niko nije pominjao system32. Smile

Malo pojašnjenja:
Linija zapisana na ovaj način: C:\Windows\tasks\
Znači da treba da uđeš na C disk, potom u folder Windows, pa Tasks. Unutar foldera Tasks će se nelaziti datoteke at1.job i at15.job

Klikni na ovaj link ispod
http://www.mycity.rs/ambulanta-upload.php

Pa na dugme Choose. Uđi na disk C, pa Windows, pa tasks i okači već pomenute datoteke (at1.job i at15.job).

Javi u temi kad to uradiš. Smile

Ko je trenutno na forumu
 

Ukupno su 843 korisnika na forumu :: 47 registrovanih, 6 sakrivenih i 790 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., Alexandar-1973, anbeast, Apok, aramis s, bladesu, Boris Bosiljčić, borya90, crnitrn, DejanSt, deLacy, Denaya, djboj, Dorcolac, dragoljub11987, Duh sa sekirom, FOX, GandorCC, Georgius, havoc995, kolle.the.kid, lord sir giga, mercedesamg, Mercury, mgolub, milenko crazy north, mrav pesadinac, Ne doznajem se u oružje, nemkea71, nenad81, Niko Bitan, nikoladim, Sančo, sasakrajina, skvara, Srle993, suton, trutcina, virked, vlahale, vlajkox, VP6919, Wrangler, zeo, |_MeD_|, Žrnov, šumar bk2