problem sa facebook mezom (redirekcija)

problem sa facebook mezom (redirekcija)

offline
  • Pridružio: 22 Apr 2012
  • Poruke: 1

Pozdrav za sve,
Od pre nekoliko dana imam problem sa facebook mezom. Kad pokusam da se logujem otara mi se vk mreza. Molim za pomoc.


OTL logfile created on: 4/22/2012 2:49:39 PM - Run 1
OTL by OldTimer - Version 3.2.40.0 Folder = C:\Users\Ognjen i Kristina\Downloads
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 0.85 Gb Available Physical Memory | 42.53% Memory free
4.00 Gb Paging File | 2.59 Gb Available in Paging File | 64.67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 48.73 Gb Total Space | 4.38 Gb Free Space | 8.99% Space Free | Partition Type: NTFS
Drive D: | 195.31 Gb Total Space | 189.54 Gb Free Space | 97.04% Space Free | Partition Type: NTFS
Drive E: | 221.62 Gb Total Space | 221.31 Gb Free Space | 99.86% Space Free | Partition Type: NTFS

Computer Name: OGNJENIKRISTINA | User Name: Ognjen i Kristina | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/04/22 14:32:12 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Ognjen i Kristina\Downloads\OTL.exe
PRC - [2012/02/23 20:39:33 | 000,232,960 | ---- | M] () -- C:\Windows\l1rezerv.exe
PRC - [2012/02/23 20:13:53 | 000,130,560 | ---- | M] () -- C:\Windows\systemup.exe
PRC - [2012/02/04 18:07:11 | 000,424,568 | ---- | M] (http://www.express-files.com/) -- C:\Program Files (x86)\ExpressFiles\ExpressFiles.exe
PRC - [2012/02/04 18:07:11 | 000,188,024 | ---- | M] (http://www.express-files.com/) -- C:\Program Files (x86)\ExpressFiles\EFupdater.exe
PRC - [2012/01/25 18:00:53 | 000,737,656 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files (x86)\uTorrent\uTorrent.exe
PRC - [2012/01/13 16:39:56 | 000,137,536 | ---- | M] (Facebook Inc.) -- C:\Users\Ognjen i Kristina\AppData\Local\Facebook\Update\FacebookUpdate.exe
PRC - [2012/01/10 16:00:21 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2012/01/06 12:17:22 | 000,551,669 | ---- | M] () -- C:\Win\lsass.exe
PRC - [2011/12/11 10:57:55 | 000,378,880 | ---- | M] () -- C:\Windows\update.7.1\svchostdriver.exe
PRC - [2011/12/11 10:46:01 | 000,257,024 | ---- | M] () -- C:\Windows\sysdriver32.exe
PRC - [2011/11/30 17:40:58 | 000,102,712 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Linkury.exe
PRC - [2011/11/29 17:50:40 | 000,182,576 | ---- | M] (Blabbers Communications LTD) -- C:\Program Files (x86)\BrowserCompanion\BCHelper.exe
PRC - [2011/09/01 20:18:54 | 004,862,384 | ---- | M] (Exent Technologies Ltd.) -- C:\Program Files (x86)\Free Ride Games\GPlayer.exe
PRC - [2011/03/17 10:15:46 | 000,382,272 | ---- | M] (DT Soft Ltd) -- C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
PRC - [2011/03/17 10:15:04 | 000,842,048 | ---- | M] (DT Soft Ltd) -- C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe
PRC - [2009/08/17 01:32:00 | 000,239,648 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe


========== Modules (No Company Name) ==========

MOD - [2012/03/08 12:52:46 | 000,076,800 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Roaming\Mozilla\Firefox\Profiles\maohqejq.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCoreGecko9.dll
MOD - [2012/02/23 20:39:33 | 000,232,960 | ---- | M] () -- C:\Windows\l1rezerv.exe
MOD - [2012/02/23 20:13:53 | 000,130,560 | ---- | M] () -- C:\Windows\systemup.exe
MOD - [2012/01/10 16:00:21 | 002,124,760 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2012/01/06 12:17:22 | 000,551,669 | ---- | M] () -- C:\Win\lsass.exe
MOD - [2011/12/11 17:48:00 | 008,013,664 | ---- | M] () -- C:\Windows\assembly\GAC\Microsoft.mshtml\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.mshtml.dll
MOD - [2011/12/11 17:48:00 | 000,139,264 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\Interop.SHDocVw\1.1.0.0__84542ff99aed6a4d\Interop.SHDocVw.dll
MOD - [2011/12/11 17:48:00 | 000,118,784 | ---- | M] () -- C:\Windows\assembly\GAC\Microsoft.VisualStudio.OLE.Interop\7.1.40304.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.OLE.Interop.dll
MOD - [2011/11/30 17:41:44 | 000,016,184 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.Resources.Utilities.dll
MOD - [2011/11/30 17:41:40 | 000,024,888 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.Resources.SocialNetsSharer.dll
MOD - [2011/11/30 17:41:38 | 000,033,592 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.Resources.SetBrowsersSettingsAutoUpdater.dll
MOD - [2011/11/30 17:41:38 | 000,019,256 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.Resources.SideBySide.dll
MOD - [2011/11/30 17:41:34 | 000,013,112 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.Resources.ProcessDownMonitor.dll
MOD - [2011/11/30 17:41:30 | 000,330,040 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.Resources.FilesManager.dll
MOD - [2011/11/30 17:41:30 | 000,066,360 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.Resources.HistoryAndStatsWrapper.dll
MOD - [2011/11/30 17:41:28 | 000,033,592 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.Resources.AutomaticUpdates.dll
MOD - [2011/11/30 17:41:24 | 000,015,672 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.Personalization.Common.dll
MOD - [2011/11/30 17:41:22 | 000,076,600 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.Personalization.BusinessLogic.dll
MOD - [2011/11/30 17:41:16 | 000,018,232 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.Infrastructure.Utilities.dll
MOD - [2011/11/30 17:41:14 | 000,052,024 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.Infrastructure.Plugins.InternetExplorerLocalPlugin.dll
MOD - [2011/11/30 17:41:06 | 000,024,376 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.Infrastructure.Core.dll
MOD - [2011/11/30 17:41:06 | 000,012,088 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.Infrastructure.BusinessEntities.dll
MOD - [2011/11/30 17:41:04 | 000,013,112 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.GUI.Multimedia.Loader.dll
MOD - [2011/11/30 17:41:02 | 000,838,456 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.GUI.MainClient.dll
MOD - [2011/11/30 17:41:00 | 000,080,184 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.GUI.Docking.dll
MOD - [2011/11/30 17:40:58 | 000,541,496 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.GUI.Controls.dll
MOD - [2011/11/30 17:40:58 | 000,102,712 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Linkury.exe
MOD - [2011/11/30 17:35:52 | 000,040,960 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\MACTrackBarLib.dll
MOD - [2011/08/07 13:54:44 | 000,362,029 | ---- | M] () -- C:\Program Files (x86)\BrowserCompanion\sqlite3.dll
MOD - [2011/08/01 17:24:44 | 006,271,648 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
MOD - [2009/07/14 07:00:27 | 000,220,672 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\c0f61f9b73571f26b6e0e0757bc5f460\CustomMarshalers.ni.dll
MOD - [2009/07/14 06:56:04 | 001,840,640 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\0929bf4ca3bc8e8b2131f27cdf500c7e\System.Web.Services.ni.dll
MOD - [2009/07/14 06:56:03 | 011,804,160 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\3871fc2b96345aa6f3be81d9e3c97160\System.Web.ni.dll
MOD - [2009/07/14 06:55:32 | 012,430,848 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\fedf1ba58dced4f0b3f8c457648ceed9\System.Windows.Forms.ni.dll
MOD - [2009/07/14 06:55:26 | 001,586,688 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\ead6be8b410d56b5576b10e56af2c180\System.Drawing.ni.dll
MOD - [2009/07/14 06:55:09 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\5dd9f783008543df3e642ff1e99de4e8\System.Xml.ni.dll
MOD - [2009/07/14 06:55:06 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\4b1350e31ff09cc583b34854816d8036\System.Configuration.ni.dll
MOD - [2009/07/14 06:55:05 | 007,949,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\5ba3bf5367fc012300c6566f20cb7f54\System.ni.dll
MOD - [2009/07/14 06:55:00 | 011,490,816 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\8c1770d45c63cf5c462eeb945ef9aa5d\mscorlib.ni.dll
MOD - [2009/06/10 23:22:50 | 000,069,120 | ---- | M] () -- C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2009/07/14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2011/12/11 10:57:55 | 000,378,880 | ---- | M] () [Auto | Running] -- C:\Windows\update.7.1\svchostdriver.exe -- (ddservice)
SRV - [2011/12/11 10:46:01 | 000,257,024 | ---- | M] () [Auto | Running] -- C:\Windows\sysdriver32.exe -- (srvsysdriver32)
SRV - [2009/08/17 01:32:00 | 000,239,648 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2009/06/10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/02/04 17:47:20 | 000,526,392 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2009/08/11 09:19:18 | 000,084,000 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2009/07/14 03:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009/07/14 03:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009/07/14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 03:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/07/14 03:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2009/07/14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 22:35:35 | 000,408,960 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvm62x64.sys -- (NVENETFD)
DRV:64bit: - [2009/06/10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2010/11/22 10:25:12 | 000,055,400 | ---- | M] (Exent Technologies Ltd.) [Kernel | Auto | Running] -- C:\Program Files (x86)\Free Ride Games\X5XSEx.sys -- (X5XSEx)
DRV - [2009/07/14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = plusnetwork.com/?q={searchTerms}&sp=chv
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2786678

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = plusnetwork.com/?q={searchTerms}&sp=chv
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = plusnetwork.com/?q={searchTerms}&sp=chv
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Mystart.incredibar.com/mb124
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = A0 03 67 60 A6 B6 CC 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = plusnetwork.com/?q={searchTerms}&sp=chv
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = plusnetwork.com/?q={searchTerms}&sp=chv
IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = plusnetwork.com/?q={searchTerms}&sp=chv
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = search.babylon.com/?q={searchTerms}&AF=109130&babsrc=SP_ss&mntrId=acf339b0000000000000002421ec8049
IE - HKCU\..\SearchScopes\{56EB44D8-613A-40B2-96B6-05614961EEA9}: "URL" = search.softonic.com/MON00005/tb_v1?q={searchTerms}&SearchSource=4&cc=
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2786678
IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = mystart.incredibar.com/mb119/?search={searchTerms}&loc=IB_DS&a=6R8mCbrBdD&i=26
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.defaultthis.engineName: "uTorrentBar Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.selectedEngine: "Messenger Plus Smartbar Search"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: "about:home"
FF - prefs.js..keyword.URL: "http://www.plusnetwork.com/?sp=chv&q="
FF - prefs.js..network.proxy.type: 0


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@exent.com/npExentCtl,version=7.0.0.0: C:\Program Files (x86)\Free Ride Games\npExentCtl.dll (Exent Technologies Ltd.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Ognjen i Kristina\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/01/10 16:00:21 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2011/08/01 17:19:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ognjen i Kristina\AppData\Roaming\Mozilla\Extensions
[2012/04/22 12:52:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ognjen i Kristina\AppData\Roaming\Mozilla\Firefox\Profiles\maohqejq.default\extensions
[2012/03/08 16:55:47 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Users\Ognjen i Kristina\AppData\Roaming\Mozilla\Firefox\Profiles\maohqejq.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2011/12/11 17:48:16 | 000,000,000 | ---D | M] (Browser Companion Helper) -- C:\Users\Ognjen i Kristina\AppData\Roaming\Mozilla\Firefox\Profiles\maohqejq.default\extensions\bbrs_002@blabbers.com
[2012/02/04 18:25:37 | 000,000,000 | ---D | M] (Babylon) -- C:\Users\Ognjen i Kristina\AppData\Roaming\Mozilla\Firefox\Profiles\maohqejq.default\extensions\ffxtlbr@babylon.com
[2012/02/22 21:07:55 | 000,000,000 | ---D | M] (Softonic Toolbar) -- C:\Users\Ognjen i Kristina\AppData\Roaming\Mozilla\Firefox\Profiles\maohqejq.default\extensions\ffxtlbra@softonic.com
[2012/03/12 18:33:24 | 000,000,000 | ---D | M] (wxDfast) -- C:\Users\Ognjen i Kristina\AppData\Roaming\Mozilla\Firefox\Profiles\maohqejq.default\extensions\info@wxdownloadmanager.com
[2012/04/22 12:52:14 | 000,000,000 | ---D | M] ("Messenger Plus! Community Smartbar") -- C:\Users\Ognjen i Kristina\AppData\Roaming\Mozilla\Firefox\Profiles\maohqejq.default\extensions\linkuryfirefoxremoteplugin@linkury.com
[2012/01/11 12:47:26 | 000,000,925 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Roaming\Mozilla\Firefox\Profiles\maohqejq.default\searchplugins\conduit.xml
[2012/04/22 12:52:14 | 000,002,242 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Roaming\Mozilla\Firefox\Profiles\maohqejq.default\searchplugins\Messenger Plus Smartbar Search.xml
[2012/03/12 18:33:14 | 000,002,203 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Roaming\Mozilla\Firefox\Profiles\maohqejq.default\searchplugins\MyStart Search.xml
[2012/02/04 17:46:46 | 000,002,060 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Roaming\Mozilla\Firefox\Profiles\maohqejq.default\searchplugins\softonic.xml
[2011/08/01 17:19:14 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/01/10 16:00:21 | 000,121,816 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/02/04 18:07:17 | 000,002,310 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2012/01/10 16:00:19 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/01/10 16:00:19 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - default_search_provider: Messenger Plus Smartbar Search (Enabled)
CHR - default_search_provider: search_url = plusnetwork.com/?q={searchTerms}&sp=chv
CHR - default_search_provider: suggest_url =

O1 HOSTS File: ([2012/04/22 13:33:59 | 000,202,984 | -H-- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 facebook.com
O1 - Hosts: 127.0.0.1 facebook.com
O1 - Hosts: 127.0.0.1 af-za.facebook.com
O1 - Hosts: 127.0.0.1 az-az.facebook.com
O1 - Hosts: 127.0.0.1 id-id.facebook.com
O1 - Hosts: 127.0.0.1 ms-my.facebook.com
O1 - Hosts: 127.0.0.1 bs-ba.facebook.com
O1 - Hosts: 127.0.0.1 ca-es.facebook.com
O1 - Hosts: 127.0.0.1 cs-cz.facebook.com
O1 - Hosts: 127.0.0.1 cy-gb.facebook.com
O1 - Hosts: 127.0.0.1 da-dk.facebook.com
O1 - Hosts: 127.0.0.1 de-de.facebook.com
O1 - Hosts: 127.0.0.1 et-ee.facebook.com
O1 - Hosts: 127.0.0.1 en-gb.facebook.com
O1 - Hosts: 127.0.0.1 es-la.facebook.com
O1 - Hosts: 127.0.0.1 eo-eo.facebook.com
O1 - Hosts: 127.0.0.1 eu-es.facebook.com
O1 - Hosts: 127.0.0.1 tl-ph.facebook.com
O1 - Hosts: 127.0.0.1 fo-fo.facebook.com
O1 - Hosts: 127.0.0.1 fr-fr.facebook.com
O1 - Hosts: 127.0.0.1 fy-nl.facebook.com
O1 - Hosts: 127.0.0.1 ga-ie.facebook.com
O1 - Hosts: 127.0.0.1 gl-es.facebook.com
O1 - Hosts: 127.0.0.1 ko-kr.facebook.com
O1 - Hosts: 50053 more lines...
O2 - BHO: (Chatvibes Browser Helper) - {00cbb66b-1d3b-46d3-9577-323a336acb50} - C:\Program Files (x86)\BrowserCompanion\jsloader.dll ( )
O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll (Babylon BHO)
O2 - BHO: (Incredibar.com Helper Object) - {6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} - C:\Program Files (x86)\Incredibar.com\incredibar\1.5.3.27\bh\incredibar.dll (Montera Technologeis LTD)
O2 - BHO: (wxDfast Class) - {8E11F7F5-4E56-43C1-98A7-68FD1B9EC6C4} - C:\ProgramData\wxDfast\bhoclass.dll (Injector)
O2 - BHO: (Chatvibes Browser Helper Verifier) - {963B125B-8B21-49A2-A3A8-E37092276531} - C:\Program Files (x86)\BrowserCompanion\updatebhoWin32.dll ( )
O2 - BHO: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
O2 - BHO: (Softonic Helper Object) - {E87806B5-E908-45FD-AF5E-957D83E58E68} - C:\Program Files (x86)\Softonic\softonic\1.5.11.5\bh\softonic.dll (Softonic.com)
O3 - HKLM\..\Toolbar: (Softonic Toolbar) - {5018CFD2-804D-4C99-9F81-25EAEA2769DE} - C:\Program Files (x86)\Softonic\softonic\1.5.11.5\softonicTlbr.dll (Softonic.com)
O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll (Babylon Ltd.)
O3 - HKLM\..\Toolbar: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Incredibar Toolbar) - {F9639E4A-801B-4843-AEE3-03D9DA199E77} - C:\Program Files (x86)\Incredibar.com\incredibar\1.5.3.27\incredibarTlbr.dll (Montera Technologeis LTD)
O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentBar Toolbar) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [2615923.exe] C:\Windows\Temp\2615923.exe ()
O4 - HKLM..\Run: [6122512.exe] C:\Users\Ognjen i Kristina\AppData\Local\Temp\6122512.exe ()
O4 - HKLM..\Run: [6775569.exe] C:\Users\Ognjen i Kristina\AppData\Local\Temp\6775569.exe ()
O4 - HKLM..\Run: [720386.exe] C:\Windows\Temp\720386.exe ()
O4 - HKLM..\Run: [811953.exe] C:\Windows\Temp\811953.exe ()
O4 - HKLM..\Run: [Browser companion helper] C:\Program Files (x86)\BrowserCompanion\BCHelper.exe (Blabbers Communications LTD)
O4 - HKLM..\Run: [ExpressFiles] C:\Program Files (x86)\ExpressFiles\ExpressFiles.exe (http://www.express-files.com/)
O4 - HKLM..\Run: [l1rezerv.exe] C:\Windows\l1rezerv.exe ()
O4 - HKLM..\Run: [run32] C:\Win\lsass.exe ()
O4 - HKLM..\Run: [sysdriver32.exe] C:\Windows\sysdriver32.exe ()
O4 - HKLM..\Run: [sysdriver32_.exe] C:\Windows\sysdriver32_.exe ()
O4 - HKLM..\Run: [systemup] C:\Windows\systemup.exe ()
O4 - HKLM..\Run: [wxpdrv] C:\Windows\update.1\svchost.exe ()
O4 - HKCU..\Run: [DAEMON Tools Pro Agent] C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe (DT Soft Ltd)
O4 - HKCU..\Run: [Exetender] C:\Program Files (x86)\Free Ride Games\GPlayer.exe (Exent Technologies Ltd.)
O4 - HKCU..\Run: [Facebook Update] C:\Users\Ognjen i Kristina\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [Linkury Chrome Smartbar] C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Linkury.exe ()
O4 - HKCU..\Run: [uTorrent] C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C8690037-D745-4AB2-A705-04FB4753147F}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\base64 - No CLSID value found
O18:64bit: - Protocol\Handler\chrome - No CLSID value found
O18:64bit: - Protocol\Handler\prox - No CLSID value found
O18 - Protocol\Handler\base64 {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll (Blabbers Communications Ltd)
O18 - Protocol\Handler\chrome {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll (Blabbers Communications Ltd)
O18 - Protocol\Handler\prox {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll (Blabbers Communications Ltd)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O31 - SafeBoot: AlternateShell - services32.exe
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...exe [@ = exefile] -- Reg Error: Key error. File not found

========== Files/Folders - Created Within 30 Days ==========

[2012/04/22 13:24:02 | 000,000,000 | ---D | C] -- C:\Users\Ognjen i Kristina\AppData\Local\ElevatedDiagnostics
[2012/04/22 13:15:39 | 000,000,000 | RHSD | C] -- C:\Win
[2012/04/15 22:41:48 | 000,000,000 | ---D | C] -- C:\Users\Ognjen i Kristina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Smart Fortress 2012
[2012/04/15 22:41:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Fortress 2012
[2012/04/15 22:37:44 | 000,000,000 | ---D | C] -- C:\ProgramData\F4D561EAD7A13CDB62B2658BA6014588

========== Files - Modified Within 30 Days ==========

[2012/04/22 13:40:37 | 000,713,714 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/04/22 13:40:37 | 000,615,122 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/04/22 13:40:37 | 000,103,496 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/04/22 13:39:40 | 000,014,192 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/04/22 13:39:40 | 000,014,192 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/04/22 13:33:31 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/04/22 13:33:23 | 1610,014,720 | -HS- | M] () -- C:\hiberfil.sys
[2012/04/17 18:44:00 | 000,000,976 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3698507183-3716407587-2362097708-1000UA.job
[2012/04/17 18:34:40 | 000,001,175 | ---- | M] () -- C:\Users\Ognjen i Kristina\Desktop\Milijunas - Shortcut.lnk
[2012/04/08 15:44:00 | 000,000,954 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3698507183-3716407587-2362097708-1000Core.job

========== Files Created - No Company Name ==========

[2012/04/17 18:34:40 | 000,001,175 | ---- | C] () -- C:\Users\Ognjen i Kristina\Desktop\Milijunas - Shortcut.lnk
[2012/02/23 20:39:37 | 000,232,960 | ---- | C] () -- C:\Windows\l1rezerv.exe
[2012/02/23 20:14:01 | 000,130,560 | ---- | C] () -- C:\Windows\systemup.exe
[2012/01/25 22:47:18 | 000,000,064 | ---- | C] () -- C:\Windows\GPlrLanc.dat
[2011/12/11 10:59:27 | 000,246,272 | ---- | C] () -- C:\Windows\unrar.exe
[2011/12/11 10:46:32 | 000,000,000 | ---- | C] () -- C:\Windows\loader2.exe_ok
[2011/12/11 10:46:28 | 000,257,024 | ---- | C] () -- C:\Windows\sysdriver32_.exe
[2011/12/11 10:46:14 | 000,257,024 | ---- | C] () -- C:\Windows\sysdriver32.exe
[2011/12/11 10:40:04 | 001,211,904 | ---- | C] () -- C:\Windows\services32.exe
[2010/12/26 16:15:18 | 000,023,024 | ---- | C] () -- C:\Users\Ognjen i Kristina\AppData\Roaming\UserTile.png
[2010/09/19 09:51:03 | 000,003,584 | ---- | C] () -- C:\Users\Ognjen i Kristina\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/24 19:22:55 | 000,056,320 | ---- | C] () -- C:\Windows\SysWow64\iyvu9_32.dll

< End of report >

mycity.rs/must-login.png

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

U toku riješavanja slučaja, zamolio bih te da se pridržavaš sledećeg:
Detaljno čitati moja uputstva ( ili uputstva kolega koji će me zamjenjivati) i raditi isključivo po njima;
Ne tražiti istovremeno pomoć na drugom mjestu;
Nemoj koristiti druge programe za uklanjanje malware-a, osim onih za koje budeš dobio uputstvo;
U toku intervencije ne koristiti USB memorijske uređaje, dok to ne budem zatražio;
Ukoliko ne odgovorim u roku od 48h, osvježi temu novim post-om;
Ukoliko se ne javiš u roku od 5 dana, zatvorićemo slučaj.

Za više informacija o pravilima Ambulante MyCity foruma: LINK


Arrow

Preuzmi sUBs-ov ComboFix sa sljedeće adrese na Desktop:


Bleeping Computer
Klikni desnim tasterom na link i odaberi opciju Save Target As... (Save Link As..., Save Linked Content As... ili sličnu);
Kada se otvori dijalog za izbor lokacije na kojoj treba sačuvati fajl, odaberi Desktop i klikni Save.




Kada preuzimanje programa bude završeno:
deaktiviraj zaštitni softver (uputstvo);
zatvori pokrenute programe;
dvoklikom pokreni program ComboFix;
u prozoru koji se otvori klikni "I Agree".

U toku rada, ComboFix će:provjeriti postoji li novija verzija programa:
klikni Yes ako bude ponuđeno preuzimanje iste.
ako Recovery Console nije instalirana, ponuditi instalaciju:
obavezno prihvati klikom na Yes i isprati postupak.
postaviti/dati određeni broj upita/obaveštenja:
prihvati klikom na Yes ili OK.
po potrebi, restartovati Windows (više puta);
na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.


Iskopiraj izvještaj koji je ComboFix napravio u temu na forumu:
klikni desnim tasterom miša u prozor Notepad-a i izaberi Select All;
klikni desnim tasterom miša na obilježeni tekst i izaberi Copy;
klikni desnim tasterom miša u polje za pisanje poruke i izaberi Paste.


Napomena:Izvještaj će biti sačuvan pod nazivom ComboFix.txt na sistemskoj particiji (tipična lokacija: C:\ComboFix.txt);
Ukoliko nakon slanja poruke primjetiš da izvještaj nije kompletan, iskoristi opciju Prikači fajl za prilaganje fajla C:\ComboFix.txt uz poruku.

Ko je trenutno na forumu
 

Ukupno su 799 korisnika na forumu :: 47 registrovanih, 5 sakrivenih i 747 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., airsuba, antonije64, Apok, Ben Roj, ccoogg123, chica, debeli, deLacy, DonRumataEstorski, doom83, DPera, dragoljub11987, FileFinder, Gall, hyla, ILGromovnik, Jahorina, Krvava Devetka, kuntalo, kybonacci, laurusri, ljuba, Marko Marković, MiroslavD, Mixelotti, Mlav, nemkea71, NikolaGTR, NoOneEver Dreams, Ognjen D., operniki, RJ, rodoljub, sasa87, simazr, Sirius, Sićko, SlaKoj, slonic_tonic, Smajser, uruk, wizzardone, wolf431, YugoSlav, žeks62, 125