offline
- Pridružio: 25 Nov 2007
- Poruke: 296
|
Ma znam i poštujem vas antivirus experte kao i windows experte jer znam da je ovaj sajt vrhunski ali morao sam ga legalizovat nisam svejsno isao iz dosade da ga zarazim, a nisam znao da se može preko official sajta može skinut kJek. Ma ne bi ja ni ovo, nisu mi to navike nego promijenit cu ali reci mi na p.m drugo rjesenje
Hvala ti što mi pomažeš cičćenja
Zoek.exe v5.0.0.0 Updated 01-March-2015
Tool run by Admin on pon 02.03.2015 at 20:49:04,20.
Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Admin\Desktop\zoek.exe [Scan all users] [Checkboxes used]
==== System Restore Info ======================
2.3.2015 20:50:15 Zoek.exe System Restore Point Created Succesfully.
==== Empty Folders Check ======================
C:\Program Files\AGEIA Technologies deleted successfully
C:\PROGRA~2\Babylon deleted successfully
C:\PROGRA~2\Conduit deleted successfully
C:\PROGRA~2\Oracle deleted successfully
C:\Users\Admin\AppData\Roaming\AVI ReComp deleted successfully
C:\Users\Admin\AppData\Roaming\Bluefive software deleted successfully
C:\Users\Admin\AppData\Roaming\Malwarebytes deleted successfully
C:\Users\Admin\AppData\Roaming\Opera Software deleted successfully
C:\Users\Admin\AppData\Roaming\YourFileDownloader deleted successfully
C:\Users\Admin\AppData\Local\Bundled software uninstaller deleted successfully
C:\Users\Admin\AppData\Local\Conduit deleted successfully
C:\Users\Admin\AppData\Local\CRE deleted successfully
C:\Users\Admin\AppData\Local\Opera Software deleted successfully
C:\Users\Admin\AppData\Local\Popajar deleted successfully
C:\Users\Admin\AppData\Local\WMTools Downloaded Files deleted successfully
C:\Users\Guest\AppData\Local\VirtualStore deleted successfully
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== FireFox Fix ======================
ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\3p4sbx0y.default
---- Lines delta removed from prefs.js ----
user_pref("extensions.delta.admin", false);
user_pref("extensions.delta.aflt", "babsst");
user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
user_pref("extensions.delta.autoRvrt", "false");
user_pref("extensions.delta.dfltLng", "en");
user_pref("extensions.delta.excTlbr", false);
user_pref("extensions.delta.ffxUnstlRst", true);
user_pref("extensions.delta.id", "3e4652c000000000000010bf4871dcbe");
user_pref("extensions.delta.instlDay", "15916");
user_pref("extensions.delta.instlRef", "sst");
user_pref("extensions.delta.newTab", false);
user_pref("extensions.delta.prdct", "delta");
user_pref("extensions.delta.prtnrId", "delta");
user_pref("extensions.delta.rvrt", "false");
user_pref("extensions.delta.smplGrp", "none");
user_pref("extensions.delta.tlbrId", "base");
user_pref("extensions.delta.tlbrSrchUrl", "");
user_pref("extensions.delta.vrsn", "1.8.22.0");
user_pref("extensions.delta.vrsnTs", "1.8.22.015:32:31");
user_pref("extensions.delta.vrsni", "1.8.22.0");
user_pref("extensions.delta_i.babExt", "");
user_pref("extensions.delta_i.babTrack", "affID=123973&tsp=4959");
user_pref("extensions.delta_i.srcExt", "ss");
---- Lines delta removed from user.js ----
user_pref("extensions.delta.tlbrSrchUrl", "");
user_pref("extensions.delta.id", "3e4652c000000000000010bf4871dcbe");
user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
user_pref("extensions.delta.instlDay", "15916");
user_pref("extensions.delta.vrsn", "1.8.22.0");
user_pref("extensions.delta.vrsni", "1.8.22.0");
user_pref("extensions.delta.vrsnTs", "1.8.22.015:32:31");
user_pref("extensions.delta.prtnrId", "delta");
user_pref("extensions.delta.prdct", "delta");
user_pref("extensions.delta.aflt", "babsst");
user_pref("extensions.delta.smplGrp", "none");
user_pref("extensions.delta.tlbrId", "base");
user_pref("extensions.delta.instlRef", "sst");
user_pref("extensions.delta.dfltLng", "en");
user_pref("extensions.delta.excTlbr", false);
user_pref("extensions.delta.ffxUnstlRst", true);
user_pref("extensions.delta.admin", false);
user_pref("extensions.delta_i.babTrack", "affID=123973&tsp=4959");
user_pref("extensions.delta_i.babExt", "");
user_pref("extensions.delta_i.srcExt", "ss");
user_pref("extensions.delta.autoRvrt", "false");
user_pref("extensions.delta.rvrt", "false");
user_pref("extensions.delta.newTab", false);
---- Lines CT3282698 removed from prefs.js ----
user_pref("CT3282698.browser.search.defaultthis.engineName", "true");
user_pref("CT3282698.FF19Solved", "true");
user_pref("CT3282698.fullUserID", "UN41619346942583823.IN.20131025191510");
user_pref("CT3282698.installDate", "25/10/2013 19:15:14");
user_pref("CT3282698.installerVersion", "1.8.0.14");
user_pref("CT3282698.installSessionId", "{34EB7C26-10DF-4E25-BED0-DF306E0E3304}");
user_pref("CT3282698.installSp", "TRUE");
user_pref("CT3282698.keyword", "true");
user_pref("CT3282698.originalHomepage", "about:home");
user_pref("CT3282698.originalSearchAddressUrl", "");
user_pref("CT3282698.originalSearchEngine", "");
user_pref("CT3282698.originalSearchEngineName", "");
user_pref("CT3282698.searchRevert", "false");
user_pref("CT3282698.searchUserMode", "2");
user_pref("CT3282698.smartbar.homepage", "true");
user_pref("CT3282698.toolbarInstallDate", "25-10-2013 19:15:11");
user_pref("CT3282698.UserID", "UN41619346942583823");
user_pref("CT3282698.versionFromInstaller", "10.21.1.7");
user_pref("CT3282698.xpeMode", "0");
---- Lines Web Search removed from prefs.js ----
user_pref("browser.search.defaultthis.engineName", "SweetTunes1 Customized Web Search");
---- Lines smartbar removed from prefs.js ----
user_pref("Smartbar.SearchFromAddressBarSavedUrl", "");
---- Lines extensions.51e66fe32fd13 removed from prefs.js ----
user_pref("extensions.51e66fe32fd13.epoch", "1375720284");
user_pref("extensions.51e66fe32fd13.url", "http://getproxy5.info/sync2/?ext=824&pid=726&country=BA®d=130717102019&lsd=130804163119&ver=7&ind=211322
---- Lines extensions.51e67019d0705 removed from prefs.js ----
user_pref("extensions.51e67019d0705.epoch", "1376739701");
user_pref("extensions.51e67019d0705.url", "http://getjpi1.info/sync2/?ext=wbn&pid=726&country=BA®d=130717102113&lsd=130816114139&ver=7&ind=21132293
---- Lines extensions.W9zSYlB1tj30Z7cZ removed from prefs.js ----
user_pref("extensions.W9zSYlB1tj30Z7cZ.epoch", "1");
user_pref("extensions.W9zSYlB1tj30Z7cZ.scode", "void(0);");
user_pref("extensions.W9zSYlB1tj30Z7cZ.url", "http://canadacomp.info/sync/?q=C6qUojC7rdU4pjU9rHa6rTrEpjw5pdrMAyVUojwErHsGrdCEqHw8rdC7rjs5rdC8tNtVh7n0r
---- Lines extensions.Z1JftZimBS2VtmMy removed from prefs.js ----
user_pref("extensions.Z1JftZimBS2VtmMy.epoch", "1");
user_pref("extensions.Z1JftZimBS2VtmMy.scode", "void(0);");
user_pref("extensions.Z1JftZimBS2VtmMy.url", "http://versiontraffic.info/sync/?q=C6qUojw4rHw7pjk6rjnErTsGqTk8rHCMAyVUojwErHsGrdCEqHw8rdC7rjs5rdC8tNtVh
---- Lines extensions.qqip9WN0VWscJJcn removed from prefs.js ----
user_pref("extensions.qqip9WN0VWscJJcn.epoch", "1");
user_pref("extensions.qqip9WN0VWscJJcn.scode", "void(0);");
user_pref("extensions.qqip9WN0VWscJJcn.url", "http://app-foryou.com/sync/?q=C6qUojC7rdU4pjU9rHa6rTrEpjw5pdrMAyVUojwErHsGrdCEqHw8rdC7rjs5rdC8tNtVh7n0rj
---- FireFox user.js and prefs.js backups ----
user_02.03.2015_2102_.backup
prefs_02.03.2015_2102_.backup
==== Deleting Files \ Folders ======================
C:\Program Files\AGEIA Technologies not found
C:\Users\Admin\AppData\Local\15534 deleted
C:\PROGRA~2\StarApp deleted
C:\Users\Admin\AppData\LocalLow\Conduit deleted
C:\Program Files\Conduit deleted
C:\PROGRA~2\safe saave deleted
C:\PROGRA~2\SSearcha-NNewTaaabe deleted
C:\PROGRA~2\InstallMate deleted
C:\Users\Admin\AppData\Local\WhiteListing deleted
C:\Users\Admin\AppData\Local\NativeMessaging deleted
C:\Windows\System32\Tasks\avast! Emergency Update deleted
C:\Users\Guest\AppData\LocalLow\AVG Secure Search deleted
C:\END deleted
C:\Windows\system32\config\systemprofile\Searches deleted
C:\Users\Admin\Documents\Add-in Express deleted
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\3p4sbx0y.default\Invalidprefs.js deleted
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\3p4sbx0y.default\jetpack deleted
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\3p4sbx0y.default\CT3282698 deleted
"C:\ProgramData\cm-lock" not deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [27.01.2015 19:21]
==== Firefox Extensions ======================
AppDir: C:\Program Files\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\3p4sbx0y.default
98137411B9C632095F919E2CE70B288A - C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll - Google Update
C62322C77D1AAB77B1CF1130FCC3673A - C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll - Shockwave Flash
893BF7D2261C56C24F813405D9D018E0 - c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll - Silverlight Plug-In
F0E80E561C3F715DB01ACCC97B72463A - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll - Photo Gallery
AC987EE8037531807C5D7E6217A23501 - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll - Adobe Acrobat
EB41064BC07017F5694CF16B4DEF6B10 - C:\Program Files\Adobe\Reader 11.0\Reader\browser\nppdf32.dll - Adobe Acrobat
A9191AE22A8F1287B5E2DF33E3A57253 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U51
9B10927CFD0F7AD39E40C0E34005B1AD - C:\Program Files\Java\jre7\bin\dtplugin\npdeployJava1.dll - Java Deployment Toolkit 7.0.510.13
66640A55AEFF3819C94E0A8D40D7E0AD - C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll - Shockwave for Director / Shockwave for Director
8DA2ED6B04EA33F2EAE8BA883F903729 - c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrlui.dll - Microsoft® Silverlight
==== Chromium Look ======================
Google Voice Search Hotword (Beta) - Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="about:newtab"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR"
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\20131121 deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nvtmru deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateChecker deleted successfully
==== Empty IE Cache ======================
C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\3p4sbx0y.default\Cache emptied successfully
==== Empty Chrome Cache ======================
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=127 folders=29 3601802 bytes)
==== Empty Temp Folders ======================
C:\Users\Admin\AppData\Local\Temp will be emptied at reboot
C:\Users\Administrator\AppData\Local\Temp emptied successfully
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Guest\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\Admin\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
C:\RECYCLER successfully emptied
==== Deleting Files / Folders ======================
"C:\ProgramData\cm-lock" not deleted
==== EOF on pon 02.03.2015 at 21:09:12,36 ======================
|