|
Poslao: 25 Dec 2014 19:29
|
offline
- Brksi

- Ex KGB officer
- Pridružio: 18 Jul 2003
- Poruke: 4206
- Gde živiš: U zlatnom kavezu
|
Zoek.exe v5.0.0.0 Updated 24-12-2014
Tool run by Zorana Sijacki on źet 25.12.2014 at 19:18:04,77.
Microsoft Windows 7 Home Premium 6.1.7600 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Zorana Sijacki\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
25.12.2014 19:19:15 Zoek.exe System Restore Point Created Succesfully.
==== Running Processes ======================
C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe
c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe
C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe
C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
c:\Program Files (x86)\Nero\Update\NASvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Users\Zorana Sijacki\Desktop\zoek.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\cmd.exe
==== Services(whitelist) ======================
Powered by E Dev
R2 - [AdobeARMservice] - Adobe Acrobat Update Service - c:\program files (x86)\common files\adobe\arm\1.0\armsvc.exe
R2 - [AMD External Events Utility] - AMD External Events Utility - c:\windows\system32\atiesrxx.exe
R2 - [AntiVirSchedulerService] - Avira Scheduler - c:\program files (x86)\avira\antivir desktop\sched.exe
R2 - [AntiVirService] - Avira Realtime Protection - c:\program files (x86)\avira\antivir desktop\avguard.exe
R2 - [cfWiMAXService] - ConfigFree WiMAX Service - c:\program files (x86)\toshiba\configfree\cfiwmxsvcs64.exe
R2 - [ConfigFree Service] - ConfigFree Service - c:\program files (x86)\toshiba\configfree\cfsvcs.exe
R2 - [IconMan_R] - IconMan_R - c:\program files (x86)\realtek\realtek usb 2.0 card reader\riconman.exe
R2 - [LMS] - Intel(R) Management and Security Application Local Management Service - c:\program files (x86)\intel\intel(r) management engine components\lms\lms.exe
R2 - [NAUpdate] - Nero Update - c:\program files (x86)\nero\update\nasvc.exe
R2 - [PCToolsSSDMonitorSvc] - PC Tools Startup and Shutdown Monitor service - c:\program files (x86)\common files\pc tools\smonitor\startmansvc.exe
R2 - [PSI_SVC_2] - Protexis Licensing V2 - c:\program files (x86)\common files\protexis\license service\psiservice_2.exe
R2 - [TeamViewer] - TeamViewer 10 - c:\program files (x86)\teamviewer\teamviewer_service.exe
R2 - [TODDSrv] - TOSHIBA Optical Disc Drive Service - c:\windows\system32\toddsrv.exe
R2 - [TosCoSrv] - TOSHIBA Power Saver - c:\program files\toshiba\power saver\toscosrv.exe
R2 - [UNS] - Intel(R) Management & Security Application User Notification Service - c:\program files (x86)\intel\intel(r) management engine components\uns\uns.exe
R2 - [wlidsvc] - Windows Live ID Sign-in Assistant - c:\program files\common files\microsoft shared\windows live\wlidsvc.exe
R2 - [WMPNetworkSvc] - Usluga deljenja putem mreĹľe za Windows Media Player - c:\program files\windows media player\wmpnetwk.exe
R2 - [WSearch] - Windows Search - c:\windows\system32\searchindexer.exe
R3 - [TMachInfo] - TMachInfo - c:\program files (x86)\toshiba\toshiba service station\tmachinfo.exe
R3 - [TOSHIBA HDD SSD Alert Service] - TOSHIBA HDD SSD Alert Service - c:\program files\toshiba\toshiba hdd ssd alert\tossmartsrv.exe
R3 - [VSS] - Volume Shadow Copy - c:\windows\system32\vssvc.exe
S2 - [clr_optimization_v4.0.30319_32] - Microsoft .NET Framework NGEN v4.0.30319_X86 - c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe
S2 - [clr_optimization_v4.0.30319_64] - Microsoft .NET Framework NGEN v4.0.30319_X64 - c:\windows\microsoft.net\framework64\v4.0.30319\mscorsvw.exe
S2 - [gupdate] - Google ажŃрирање ŃŃĐ»Ńга (gupdate) - c:\program files (x86)\google\update\googleupdate.exe
S2 - [SkypeUpdate] - Skype Updater - c:\program files (x86)\skype\updater\updater.exe
S2 - [sppsvc] - Software Protection - c:\windows\system32\sppsvc.exe
S3 - [ALG] - Application Layer Gateway Service - c:\windows\system32\alg.exe
S3 - [COMSysApp] - COM+ System Application - c:\windows\system32\dllhost.exe
S3 - [ehRecvr] - Windows Media Center Receiver Service - c:\windows\ehome\ehrecvr.exe
S3 - [ehSched] - Windows Media Center Scheduler Service - c:\windows\ehome\ehsched.exe
S3 - [Fax] - Faks - c:\windows\system32\fxssvc.exe
S3 - [FontCache3.0.0.0] - Windows Presentation Foundation Font Cache 3.0.0.0 - c:\windows\microsoft.net\framework64\v3.0\wpf\presentationfontcache.exe
S3 - [gupdatem] - Google ажŃрирање ŃŃĐ»Ńга (gupdatem) - c:\program files (x86)\google\update\googleupdate.exe
S3 - [gusvc] - Google Updater Service - c:\program files (x86)\google\common\google updater\googleupdaterservice.exe
S3 - [Microsoft Office Groove Audit Service] - Microsoft Office Groove Audit Service - c:\program files (x86)\microsoft office\office12\grooveauditservice.exe
S3 - [MozillaMaintenance] - Mozilla Maintenance Service - c:\program files (x86)\mozilla maintenance service\maintenanceservice.exe
S3 - [MSDTC] - Distributed Transaction Coordinator - c:\windows\system32\msdtc.exe
S3 - [msiserver] - Windows Installer - c:\windows\system32\msiexec.exe
S3 - [odserv] - Microsoft Office Diagnostics Service - c:\program files (x86)\common files\microsoft shared\office12\odserv.exe
S3 - [ose] - Office Source Engine - c:\program files (x86)\common files\microsoft shared\source engine\ose.exe
S3 - [PerfHost] - Performance Counter DLL Host - c:\windows\syswow64\perfhost.exe
S3 - [RpcLocator] - Remote Procedure Call (RPC) Locator - c:\windows\system32\locator.exe
S3 - [SNMPTRAP] - SNMP Trap - c:\windows\system32\snmptrap.exe
S3 - [Sony PC Companion] - Sony PC Companion - c:\program files (x86)\sony\sony pc companion\pccservice.exe
S3 - [TemproMonitoringService] - Notebook Performance Tuning Service (TEMPRO) - c:\program files (x86)\toshiba tempro\temprosvc.exe
S3 - [TOSHIBA Bluetooth Service] - TOSHIBA Bluetooth Service - c:\program files (x86)\toshiba\bluetooth toshiba stack\tosbtsrv.exe
S3 - [TrustedInstaller] - Windows Modules Installer - c:\windows\servicing\trustedinstaller.exe
S3 - [vds] - Virtual Disk - c:\windows\system32\vds.exe
S3 - [wbengine] - Block Level Backup Engine Service - c:\windows\system32\wbengine.exe
S3 - [wmiApSrv] - WMI Performance Adapter - c:\windows\system32\wbem\wmiapsrv.exe
S4 - [clr_optimization_v2.0.50727_32] - Microsoft .NET Framework NGEN v2.0.50727_X86 - c:\windows\microsoft.net\framework\v2.0.50727\mscorsvw.exe
S4 - [clr_optimization_v2.0.50727_64] - Microsoft .NET Framework NGEN v2.0.50727_X64 - c:\windows\microsoft.net\framework64\v2.0.50727\mscorsvw.exe
S4 - [msvsmon90] - Visual Studio 2008 Remote Debugger - c:\program files\microsoft visual studio 9.0\common7\ide\remote debugger\x64\msvsmon.exe
S4 - [wlcrasvc] - Windows Live Mesh remote connections service - c:\program files\windows live\mesh\wlcrasvc.exe
==== Drivers(whitelist) ======================
Powered by E Dev
R0 - [FileInfo] - File Information FS MiniFilter - C:\Windows\system32\Drivers\FileInfo.sys
R0 - [FltMgr] - FltMgr - C:\Windows\system32\Drivers\FltMgr.sys
R0 - [Mup] - Mup - C:\Windows\system32\Drivers\Mup.sys
R1 - [NetBIOS] - NetBIOS Interface - C:\Windows\system32\Drivers\NetBIOS.sys
R3 - [srv] - Server SMB 1.xxx Driver - C:\Windows\system32\Drivers\srv.sys
R3 - [srv2] - Server SMB 2.xxx Driver - C:\Windows\system32\Drivers\srv2.sys
R0 - [ACPI] - Microsoft ACPI Driver - C:\Windows\system32\Drivers\ACPI.sys
R0 - [amdxata] - amdxata - C:\Windows\system32\Drivers\amdxata.sys
R0 - [atapi] - IDE Channel - C:\Windows\system32\Drivers\atapi.sys
R0 - [CLFS] - Common Log (CLFS) - C:\Windows\system32\Drivers\CLFS.sys [x]
R0 - [CNG] - CNG - C:\Windows\system32\Drivers\CNG.sys
R0 - [Compbatt] - Microsoft Composite Battery Driver - C:\Windows\system32\Drivers\Compbatt.sys
R0 - [Disk] - Disk Driver - C:\Windows\system32\Drivers\Disk.sys
R0 - [fvevol] - Bitlocker Drive Encryption Filter Driver - C:\Windows\system32\Drivers\fvevol.sys
R0 - [hwpolicy] - Hardware Policy Driver - C:\Windows\system32\Drivers\hwpolicy.sys
R0 - [iaStor] - Intel AHCI Controller - C:\Windows\system32\Drivers\iaStor.sys
R0 - [KSecDD] - KSecDD - C:\Windows\system32\Drivers\KSecDD.sys
R0 - [KSecPkg] - KSecPkg - C:\Windows\system32\Drivers\KSecPkg.sys
R0 - [LPCFilter] - LPC Lower Filter Driver - C:\Windows\system32\Drivers\LPCFilter.sys
R0 - [mountmgr] - Mount Point Manager - C:\Windows\system32\Drivers\mountmgr.sys
R0 - [msahci] - msahci - C:\Windows\system32\Drivers\msahci.sys
R0 - [msisadrv] - msisadrv - C:\Windows\system32\Drivers\msisadrv.sys
R0 - [NDIS] - NDIS System Driver - C:\Windows\system32\Drivers\NDIS.sys
R0 - [partmgr] - Partition Manager - C:\Windows\system32\Drivers\partmgr.sys
R0 - [pci] - PCI Bus Driver - C:\Windows\system32\Drivers\pci.sys
R0 - [pciide] - pciide - C:\Windows\system32\Drivers\pciide.sys
R0 - [pcw] - Performance Counters for Windows Driver - C:\Windows\system32\Drivers\pcw.sys
R0 - [rdyboost] - ReadyBoost - C:\Windows\system32\Drivers\rdyboost.sys
R0 - [spldr] - Security Processor Loader Driver - C:\Windows\system32\Drivers\spldr.sys
R0 - [Tcpip] - UpravljaÄŤki program TCP/IP protokola - C:\Windows\system32\Drivers\Tcpip.sys
R0 - [TVALZ] - TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver - C:\Windows\system32\Drivers\TVALZ.sys [x]
R0 - [vdrvroot] - Microsoft Virtual Drive Enumerator Driver - C:\Windows\system32\Drivers\vdrvroot.sys
R0 - [volmgr] - Volume Manager Driver - C:\Windows\system32\Drivers\volmgr.sys
R0 - [volmgrx] - Dynamic Volume Manager - C:\Windows\system32\Drivers\volmgrx.sys
R0 - [volsnap] - Storage volumes - C:\Windows\system32\Drivers\volsnap.sys
R0 - [Wdf01000] - Kernel Mode Driver Frameworks service - C:\Windows\system32\Drivers\Wdf01000.sys
R1 - [AFD] - Ancillary Function Driver for Winsock - C:\Windows\system32\Drivers\AFD.sys
R1 - [Beep] - Beep - C:\Windows\system32\Drivers\Beep.sys
R1 - [tdx] - NetIO TDI upravljačkog programa podrške koji je zastareo - C:\Windows\system32\Drivers\tdx.sys
R2 - [tcpipreg] - TCP/IP Registry Compatibility - C:\Windows\system32\Drivers\tcpipreg.sys
==== Files Recently Created / Modified ======================
====== C:\Windows ====
2014-12-24 21:30:09 6C9586D26145389A31C0A1145E2B3E92 492940062 ----a-w- C:\Windows\MEMORY.DMP
====== C:\Users\ZORANA~1\AppData\Local\Temp ====
2014-12-24 21:40:42 168DDE5E84E651ADBF83587C0673F6F4 346968 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\MSNCBC.exe
2014-12-24 21:39:00 CF95932C00190451115C782E139DE582 264488 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\MSS\3.8.150.1\McInstallerRes.dll
2014-12-24 21:39:00 C4CF03B998D4D758B89CD07F22D7A7F9 645168 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\MSS\3.8.150.1\McUICnt.exe
2014-12-24 21:39:00 87AA773F15D90973090D4DF76F8E60EF 565808 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\MSS\3.8.150.1\mcbrwsr2.dll
2014-12-24 21:39:00 2AA753368BF68871962D2E99B8692985 153760 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\MSS\3.8.150.1\McInstallerRes_LD.dll
2014-12-24 21:39:00 14E9947D26B0A418AA02F87741E4B40B 769736 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\MSS\3.8.150.1\McInstallerStartup.dll
2014-12-23 16:53:22 FEFEF2F226FD6BE184BC4A3378B02AAF 155648 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.104603\psmachine.dll
2014-12-23 16:53:22 8D90BB3A36521B50D0E512A781E36871 155648 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.104603\psuser.dll
2014-12-23 16:53:21 AEF95394FF8029B9C17F81197C6AAB5A 220672 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.104603\npGoogleUpdate4.dll
2014-12-23 16:53:20 FC7A2F466F7A0F3E873077505719C1A1 143360 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.104603\GoogleUpdateHelper.msi
2014-12-23 16:53:20 C0A2D854DA879A5D55244E8DC4E7C8B8 761856 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.104603\goopdate.dll
2014-12-23 16:53:20 7E767B342E55EB1DFD74A65D24EA4B70 46080 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.104603\GoogleUpdateOnDemand.exe
2014-12-23 16:53:19 F98DE4108614E4BB81E95E58E36C7000 46080 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.104603\GoogleUpdateBroker.exe
2014-12-23 16:53:19 D858BA2EE718B1DB1CED20646E641D08 68608 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.104603\GoogleUpdate.exe
2014-12-23 16:53:18 03114DADBD9977FC823F95B21FB987E7 72872 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.104603\GoogleCrashHandler.exe
2014-12-23 16:53:08 FEFEF2F226FD6BE184BC4A3378B02AAF 155648 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.154004\psmachine.dll
2014-12-23 16:53:08 8D90BB3A36521B50D0E512A781E36871 155648 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.154004\psuser.dll
2014-12-23 16:53:07 FC7A2F466F7A0F3E873077505719C1A1 143360 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.154004\GoogleUpdateHelper.msi
2014-12-23 16:53:07 F98DE4108614E4BB81E95E58E36C7000 46080 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.154004\GoogleUpdateBroker.exe
2014-12-23 16:53:07 D858BA2EE718B1DB1CED20646E641D08 68608 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.154004\GoogleUpdate.exe
2014-12-23 16:53:07 C0A2D854DA879A5D55244E8DC4E7C8B8 761856 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.154004\goopdate.dll
2014-12-23 16:53:07 AEF95394FF8029B9C17F81197C6AAB5A 220672 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.154004\npGoogleUpdate4.dll
2014-12-23 16:53:07 7E767B342E55EB1DFD74A65D24EA4B70 46080 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.154004\GoogleUpdateOnDemand.exe
2014-12-23 16:53:07 03114DADBD9977FC823F95B21FB987E7 72872 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.154004\GoogleCrashHandler.exe
2014-12-23 16:51:33 FEFEF2F226FD6BE184BC4A3378B02AAF 155648 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.104579\psmachine.dll
2014-12-23 16:51:33 8D90BB3A36521B50D0E512A781E36871 155648 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.104579\psuser.dll
2014-12-23 16:51:32 FC7A2F466F7A0F3E873077505719C1A1 143360 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.104579\GoogleUpdateHelper.msi
2014-12-23 16:51:32 C0A2D854DA879A5D55244E8DC4E7C8B8 761856 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.104579\goopdate.dll
2014-12-23 16:51:32 AEF95394FF8029B9C17F81197C6AAB5A 220672 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.104579\npGoogleUpdate4.dll
2014-12-23 16:51:32 7E767B342E55EB1DFD74A65D24EA4B70 46080 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.104579\GoogleUpdateOnDemand.exe
2014-12-23 16:51:31 F98DE4108614E4BB81E95E58E36C7000 46080 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.104579\GoogleUpdateBroker.exe
2014-12-23 16:51:31 D858BA2EE718B1DB1CED20646E641D08 68608 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.104579\GoogleUpdate.exe
2014-12-23 16:51:31 03114DADBD9977FC823F95B21FB987E7 72872 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.104579\GoogleCrashHandler.exe
2014-12-23 16:51:07 B8CD5BAC567F636D39021CDEBC372B4A 12911152 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\Install_16851\ins_sense.exe
2014-12-23 16:51:07 5790BE5D05A91383FD60131B6A6673E4 12921320 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\Install_16851\ins_geforce.exe
2014-12-23 16:51:07 1D2BD62F928560AA4575F8655D53C0D9 2692620 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\Install_16851\ins_shopperpro.exe
2014-12-23 16:51:07 05C47DA12B0009BD98653F51287F7768 942080 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\Install_16851\bxsdk32.dll
2014-12-23 16:50:54 C6E383A480D32F748FE41961AAE7944A 13543520 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\1.tmp.exe
2014-12-22 15:20:51 1CAF9472C70FB3567B85E1977A393720 236352 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\Runner.exe
2014-12-15 13:15:22 E63A017B90A0E0DDC059282E0EEDEC64 7566872 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\TeamViewer\TeamViewer_.exe
====== Java Cache =====
====== C:\Windows\SysWOW64 =====
====== C:\Windows\SysWOW64\drivers =====
====== C:\Windows\Sysnative =====
====== C:\Windows\Sysnative\drivers =====
====== C:\Windows\Tasks ======
====== C:\Windows\Temp ======
======= C:\Program Files =====
======= C:\PROGRA~2 =====
2014-12-24 20:59:09 -------- d-----w- C:\PROGRA~2\TeamViewer
======= C: =====
====== C:\Users\Zorana Sijacki\AppData\Roaming ======
2014-12-24 20:59:22 -------- d-----w- C:\Users\Zorana Sijacki\AppData\Roaming\TeamViewer
2014-12-24 15:17:30 -------- d-----r- C:\Users\Zorana Sijacki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 8
====== C:\Users\Zorana Sijacki ======
2014-12-25 16:32:46 3902B97471D5A7634907CA99CB5DA766 2122240 ----a-w- C:\Users\Zorana Sijacki\Desktop\FRST64.exe
2014-12-24 21:30:52 8E1B08222F20E45A3E8DB04C569F9CB7 8 --sha-r- C:\ProgramData\ntuser.pol
2014-12-24 21:18:16 9208E5A0A844FCCB39B5252C07B4E860 2173952 ----a-w- C:\Users\Zorana Sijacki\Downloads\AdwCleaner.exe
2014-12-24 20:58:00 3EBD2DFCA65ED3782C84A39909DC2F45 7720120 ----a-w- C:\Users\Zorana Sijacki\Downloads\TeamViewer_Setup_sr-ckq.exe
2014-12-23 17:19:58 -------- d-----r- C:\Windows\sysWoW64\config\systemprofile\Favorites
2014-12-23 17:19:56 -------- d-----r- C:\Windows\SysNative\config\systemprofile\Favorites
2014-12-23 17:14:25 D535BD1BB63EB94C79F9738FA97284DA 91318 ----a-w- C:\Users\Zorana Sijacki\Desktop\PlayerStubWrapper.exe
2014-12-19 15:54:16 -------- d-----w- C:\Users\Zorana Sijacki\Nova fascikla (3)
2014-12-18 16:04:02 -------- d-----w- C:\Users\Zorana Sijacki\sandra i ja
2014-12-08 15:48:14 FC81E855324041E1DB53396F57B85D17 15656 ----a-w- C:\Users\Zorana Sijacki\Nokti.jpg
2014-12-08 15:48:00 CBCE81FD244C17166DEC74E0F2AFB7F2 21724 ----a-w- C:\Users\Zorana Sijacki\Fotografija.jpg
2014-12-07 18:58:50 -------- d-----w- C:\Users\Zorana Sijacki\svasta
====== C: exe-files ==
2014-12-25 16:32:46 3902B97471D5A7634907CA99CB5DA766 2122240 ----a-w- C:\Users\Zorana Sijacki\Desktop\FRST64.exe
2014-12-24 21:40:42 168DDE5E84E651ADBF83587C0673F6F4 346968 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\MSNCBC.exe
2014-12-24 21:39:00 C4CF03B998D4D758B89CD07F22D7A7F9 645168 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\MSS\3.8.150.1\McUICnt.exe
2014-12-24 21:18:16 9208E5A0A844FCCB39B5252C07B4E860 2173952 ----a-w- C:\Users\Zorana Sijacki\Downloads\AdwCleaner.exe
2014-12-24 20:59:11 C0C121B537DA3AD87481C0502CACE462 5426448 ----a-w- C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
2014-12-24 20:59:11 B535BFA8C7A70E402EF804BF58B4B3FC 263952 ----a-w- C:\Program Files (x86)\TeamViewer\tv_x64.exe
2014-12-24 20:59:11 8F5F41E58D6DBF740F2F0B18B6EAF0E4 229136 ----a-w- C:\Program Files (x86)\TeamViewer\tv_w32.exe
2014-12-24 20:59:11 26190F1834A502052A00734DA4FCB1A3 468864 ----a-w- C:\Program Files (x86)\TeamViewer\uninstall.exe
2014-12-24 20:59:10 B3F4ECEB90D6F303C675ED042B654906 16362768 ----a-w- C:\Program Files (x86)\TeamViewer\TeamViewer.exe
2014-12-24 20:59:10 9B1C8BBF31A7AB504DAA916640F8DCD0 5476112 ----a-w- C:\Program Files (x86)\TeamViewer\TeamViewer_Desktop.exe
2014-12-24 20:58:00 3EBD2DFCA65ED3782C84A39909DC2F45 7720120 ----a-w- C:\Users\Zorana Sijacki\Downloads\TeamViewer_Setup_sr-ckq.exe
2014-12-23 17:14:25 D535BD1BB63EB94C79F9738FA97284DA 91318 ----a-w- C:\Users\Zorana Sijacki\Desktop\PlayerStubWrapper.exe
2014-12-23 16:53:20 7E767B342E55EB1DFD74A65D24EA4B70 46080 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.104603\GoogleUpdateOnDemand.exe
2014-12-23 16:53:19 F98DE4108614E4BB81E95E58E36C7000 46080 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.104603\GoogleUpdateBroker.exe
2014-12-23 16:53:19 D858BA2EE718B1DB1CED20646E641D08 68608 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.104603\GoogleUpdate.exe
2014-12-23 16:53:18 03114DADBD9977FC823F95B21FB987E7 72872 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.104603\GoogleCrashHandler.exe
2014-12-23 16:53:07 F98DE4108614E4BB81E95E58E36C7000 46080 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.154004\GoogleUpdateBroker.exe
2014-12-23 16:53:07 D858BA2EE718B1DB1CED20646E641D08 68608 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.154004\GoogleUpdate.exe
2014-12-23 16:53:07 7E767B342E55EB1DFD74A65D24EA4B70 46080 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.154004\GoogleUpdateOnDemand.exe
2014-12-23 16:53:07 03114DADBD9977FC823F95B21FB987E7 72872 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.154004\GoogleCrashHandler.exe
2014-12-23 16:51:32 7E767B342E55EB1DFD74A65D24EA4B70 46080 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.104579\GoogleUpdateOnDemand.exe
2014-12-23 16:51:31 F98DE4108614E4BB81E95E58E36C7000 46080 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.104579\GoogleUpdateBroker.exe
2014-12-23 16:51:31 D858BA2EE718B1DB1CED20646E641D08 68608 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.104579\GoogleUpdate.exe
2014-12-23 16:51:31 03114DADBD9977FC823F95B21FB987E7 72872 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\comh.104579\GoogleCrashHandler.exe
2014-12-23 16:51:07 B8CD5BAC567F636D39021CDEBC372B4A 12911152 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\Install_16851\ins_sense.exe
2014-12-23 16:51:07 5790BE5D05A91383FD60131B6A6673E4 12921320 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\Install_16851\ins_geforce.exe
2014-12-23 16:51:07 1D2BD62F928560AA4575F8655D53C0D9 2692620 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\Install_16851\ins_shopperpro.exe
2014-12-23 16:50:54 C6E383A480D32F748FE41961AAE7944A 13543520 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\1.tmp.exe
2014-12-22 15:20:51 1CAF9472C70FB3567B85E1977A393720 236352 ----a-w- C:\Users\Zorana Sijacki\AppData\Local\Temp\Runner.exe
=== C: other files ==
==== Startup Registry Enabled ======================
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"TOSHIBA Online Product Information"="C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe"
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
[HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"Sony PC Companion"="C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe /Background"
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe /autoRun"
"svchost.exe"="C:\Users\Zorana Sijacki\AppData\Roaming\svchost.exe"
"updates32"="C:\Users\Zorana Sijacki\AppData\Roaming\opp\sis32.exe"
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run]
"TOSHIBA Online Product Information"="C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe"
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe MSRun"
"SVPWUTIL"="C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL"
"HWSetup"="C:\Program Files\TOSHIBA\Utilities\HWSetup.exe hwSetUP"
"KeNotify"="C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe LPCM"
"ToshibaServiceStation"="C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe /hide:60"
"GrooveMonitor"="C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
"avgnt"="C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe /min"
"SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"svchost.exe"="C:\Users\Zorana Sijacki\AppData\Roaming\svchost.exe"
"ITSecMng"="%ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START"
"TWebCamera"=""C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sony PC Companion"="C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe /Background"
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe /autoRun"
"svchost.exe"="C:\Users\Zorana Sijacki\AppData\Roaming\svchost.exe"
"updates32"="C:\Users\Zorana Sijacki\AppData\Roaming\opp\sis32.exe"
==== Startup Registry Enabled x64 ======================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Toshiba TEMPRO"="C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe"
"RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s"
"RtHDVBg"="C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE3 "
"TosVolRegulator"="C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe"
"Toshiba Registration"="C:\Program Files\Toshiba\Registration\ToshibaReminder.exe"
"TosNC"="%ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe "
"TosReelTimeMonitor"="%ProgramFiles%\TOSHIBA\ReelTime\TosReelTimeMonitor.exe "
"TPwrMain"="%ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE"
"SmoothView"="%ProgramFiles%\Toshiba\SmoothView\SmoothView.exe "
"00TCrdMain"="%ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe "
"SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe "
"SmartFaceVWatcher"="%ProgramFiles%\Toshiba\SmartFaceV\SmartFaceVWatcher.exe "
"TosSENotify"="C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe"
==== Startup Registry Disabled x64 ======================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BDRegion]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="BDRegion"
"hkey"="HKLM"
"command"="C:\\Program Files (x86)\\Cyberlink\\Shared Files\\brs.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NBAgent]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NBAgent"
"hkey"="HKLM"
"command"="\"c:\\Program Files (x86)\\Nero\\Nero 10\\Nero BackItUp\\NBAgent.exe\" /WinStart"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PDVD8LanguageShortcut]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PDVD8LanguageShortcut"
"hkey"="HKLM"
"command"="\"C:\\Program Files (x86)\\CyberLink\\PowerDVD8\\Language\\Language.exe\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\RemoteControl8]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="RemoteControl8"
"hkey"="HKLM"
"command"="\"C:\\Program Files (x86)\\CyberLink\\PowerDVD8\\PDVD8Serv.exe\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SSDMonitor]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SSDMonitor"
"hkey"="HKLM"
"command"="C:\\Program Files (x86)\\Common Files\\PC Tools\\sMonitor\\SSDMonitor.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WinampAgent]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="WinampAgent"
"hkey"="HKLM"
"command"="\"C:\\Program Files (x86)\\Winamp\\winampa.exe\""
==== Startup Folders ======================
2010-11-22 07:57:12 1258 ----a-w- C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
2010-11-22 07:57:12 1258 ----a-w- C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
==== Task Scheduler Jobs ======================
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [06.04.2013 18:10]
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [06.04.2013 18:10]
C:\Windows\tasks\RMSchedule.job --a------ C:\Program Files (x86)\Registry Mechanic\RegMech.exe []
==== Other Scheduled Tasks ======================
"C:\Windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"]
"C:\Windows\SysNative\tasks\ConfigFree Startup Programs" [C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe]
"C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe]
"C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe]
"C:\Windows\SysNative\tasks\RMSchedule" [C:\Program Files (x86)\Registry Mechanic\RegMech.exe]
"C:\Windows\SysNative\tasks\RMSmartUpdate" ["C:\Program Files (x86)\Registry Mechanic\update.exe"]
"C:\Windows\SysNative\tasks\User_Feed_Synchronization-{15C3F2DA-11B6-4FBD-A251-867AF5B56893}" [C:\Windows\system32\msfeedssync.exe]
"C:\Windows\SysNative\tasks\{1408896D-4585-4284-A564-B7912BC8598F}" ["c:\program files (x86)\mozilla firefox\firefox.exe"]
==== Firefox Extensions ======================
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\Zorana Sijacki\AppData\Roaming\Mozilla\Firefox\Profiles\paypbpzk.default
47299371607DC2FB234444EEACB1639E - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll - Shockwave Flash
A514E2906D52E3413A9BB7DE87F7B1DF - C:\Users\Zorana Sijacki\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player
==== Chromium Look ======================
==== Chromium Startpages ======================
C:\Users\Zorana Sijacki\AppData\Local\Google\Chrome\User Data\Default\Preferences
"urls_to_restore_on_startup": [ "http://www.search.ask.com/?o=APN10645A&gct=hp&d=406-1720&v=n13001-391&t=4" ]
"urls_to_restore_on_startup": [ "http://www.search.ask.com/?o=APN10645A&gct=hp&d=406-1720&v=n13001-391&t=4" ]
==== IE Start and Search Settings ======================
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
"Search Bar"="http://www.google.com/ie"
"Default_Search_URL"="http://www.google.com/ie"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
@="http://www.google.com/search?q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://www.google.com/ie"
"Default_Search_URL"="http://www.google.com/ie"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Goo Url="http://www.google.com/search?q={sear"
{7AA88751-E997-4A8A-8B4B-7E84EA4B4F6E} Amazon Url="http://www.amazon.co.uk/gp/search?ie=UTF8&keywords={searchTerms}&tag=tochibauk-win7-ie-search-21&index=blended&linkCode=ur2"
{7BD5203A-F775-42CB-9AAC-60706F686FFF} Unknown Url="Not_Found"
{9B6788FF-377C-46E4-A8B6-9162EB1E61C8} eBay Url="http://rover.ebay.com/rover/1/710-71511-9400-6/4?satitle={searchTerms}"
{A84FFCED-121F-460B-A16D-87376D6C3D64} Google Url="http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
==== C:\zoek_backup content ======================
C:\zoek_backup (files=0 folders=0 0 bytes)
==== EOF on źet 25.12.2014 at 19:24:12,48 ======================
|
|
|
|
|
|
|
|
|
Poslao: 25 Dec 2014 20:18
|
offline
- Brksi

- Ex KGB officer
- Pridružio: 18 Jul 2003
- Poruke: 4206
- Gde živiš: U zlatnom kavezu
|
Zoek.exe v5.0.0.0 Updated 24-12-2014
Tool run by Zorana Sijacki on źet 25.12.2014 at 19:50:45,03.
Microsoft Windows 7 Home Premium 6.1.7600 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Zorana Sijacki\Desktop\zoek.exe [Scan all users] [Script inserted]
==== Older Logs ======================
C:\zoek-results2014-12-25-182412.log 32989 bytes
==== Empty Folders Check ======================
C:\PROGRA~2\MSXML 4.0 deleted successfully
C:\PROGRA~3\Oracle deleted successfully
C:\Users\Zorana Sijacki\AppData\Local\VirtualStore deleted successfully
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{10AD16F4-1BA6-4CD1-9020-C81B1ACFB97D} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{13f429a4-5c39-40aa-95b8-03686ce8aec1} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1EF12DCC-537-4409-BF94-41991A51F349} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{23DE5B76-9543-48F3-8A63-3ECAD98B48F} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2504482f-22e6-43d0-8c48-181f75815313} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{26079205-E406-4F2F-B0CB-7D6663B30FB} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{27518c2e-e6af-4cb5-964a-87f6cd228495} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2A09E077-5AC6-49C0-A8A4-163CA106B81} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2a501832-ca03-4b56-8cee-a69fcb6e2385} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2D83CF5C-D668-4F83-9936-3096AEEB89D8} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2E7D8E3-4D47-4762-81E6-6021E2D0C37} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{30ADA0A8-3673-432B-8E76-4E99A843AA57} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{31314AA5-1C66-4692-A215-F6DF654A2198} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{325DF6EF-1F67-422C-98C6-A6E0354D8588} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{33249901-A48A-49B4-A0D5-91533BC8291D} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{403C7DD2-29B1-421F-9471-B70FD8787EB} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{41C13C0E-9598-4CA7-A9C9-7F882C2C3A3} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{42F3A9ED-4F66-4F90-9872-EF71BCAF439} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{43792559-DE92-4F91-B72-F3E8AA2AB01} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{451E39B9-F2DB-4590-B713-D9287EB8F6F6} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4A38EF9C-85EC-4401-93CC-F1C52586E049} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{514FE8C2-787F-4761-94AB-3BDC2EDED3E} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5CF13938-4C76-45CB-807B-E566EF2FDF5} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5D830EC5-3EF2-43AD-BE17-E67ED98A9E3F} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5dc37536-8e35-43f2-a5ba-cd8d117b7a62} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6215570E-9936-4905-BF7B-748A7968885} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6AFC1434-D0FF-4768-9A1-BAA459F4AE7} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6C1A5EB3-1805-46A1-8CC3-0C8CE7AE48E} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6DC5D616-61CA-4A07-9B6-92585E7492} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6EF8343-4127-4C54-B6C-D831735DC4C1} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{714C9985-80F7-48A3-98AB-7DFCB3CE1389} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{768A1CAF-B007-4EAE-8EC0-A3CFF16BD4CC} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{77079995-5841-4B25-8EC8-287ADD614433} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8326A337-64ED-451D-9040-EE980B8234E} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{84573bc3-21af-41da-8ecc-96f702af6b4b} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{84EB25BA-777C-45C0-8F2E-57813BCCBC21} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{90D1D7AE-E332-4059-9393-6D932D99A741} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{91C5A2E2-9A2C-4C40-B0BD-DC91DFA3637} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{92625561-1558-4825-A3C9-173358AB850} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{97BF5DFF-3DA8-4B80-B44A-BD1FCA6A7499} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9c720bfc-5419-4725-acd5-bcdeb840121d} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9F0D095C-A0E2-4358-9882-87B4103158CE} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a200b16d-f062-404e-be81-25faf2dc4cdf} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A4B7A89C-F2A7-4E09-8779-B5BDEB91861A} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{acd543e7-9833-4c53-b5d2-a1f312d873c4} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AFEE656-815E-4CF4-ACDE-87AD4808C3D} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B168538E-F3A3-4C80-88D-2548F68B9CD} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B35CC17B-A3E4-4C2B-9AD5-EBC8668142B6} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B48F3F92-35F1-4AE0-B1D2-FFF39AE7B47} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B68B9AB2-F691-4B58-B1E8-172E4B1A6BA9} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B774CDCF-E7C1-491A-B0CF-FCBA417CAA88} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BB848C00-70D3-4399-9013-7DE64B8388C} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C153CCFD-682A-4DEB-A958-A718B66543C1} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7A7777A-5541-4BBD-8BDD-15FBFF116C90} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C8735A6D-AE8A-4E3B-82D0-761DF95B64D2} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CBD05D7D-4F34-435E-859F-55908ABEB81C} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CFCCD1F4-5534-48F0-A1F3-7078A5FA34E8} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D29F45D0-36EC-4E09-A73F-11F4FC28FA4A} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D2DFF124-1563-437A-9DD4-DEB8A443543} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D3CB4AB2-7E71-4BFD-AD32-4DF3874BFEF} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D59FF45B-2DBB-41DE-97C5-99BD58A67AC6} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D665E2A6-AA19-4284-9883-D4B446DEAC0} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D721003B-4C5D-4D03-8155-20CCF9DCAC3} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d73ddd49-3e97-4125-8ca8-83c38fa9281d} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DC24E574-12C1-497A-A474-9FA2A5C34E23} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DC978C00-43C6-43AF-8A96-8A7F1D1C1121} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DED11438-7861-425E-9290-C6F0B09DB1F5} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DFB05AA4-498F-4456-A225-4D5CBDD43740} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E4B3B06B-FB7B-4695-8312-10508A8ECEF1} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EA6B0C41-1FE8-4DE8-8581-A89DC1DE9674} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EAE1A344-F5CF-47C2-BCB9-5D2867805A} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F01A2910-8B99-49B4-ACF9-2ED4C6F2646B} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F140AE0D-4434-45AE-A8C1-A97A422DFAA9} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F4551A4B-7018-42FC-AF82-ECF48107F0} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F83C3996-4D6B-45F1-A87B-301C6DF85E8} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F8AD1E62-3AA0-4B5E-B0FE-B04A3C4ACAA1} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FA0C7519-A0D5-4D75-8B6B-51264BFA7DD} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FA8ACB87-43E8-4137-AC71-8AD69CECC6CB} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FC9D12A9-E453-4967-95D5-DCDB7DABCE79} deleted successfully
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FE76B5DB-7284-4B10-9318-43E5989015E2} deleted successfully
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== FireFox Fix ======================
ProfilePath: C:\Users\ZORANA~1\AppData\Roaming\Mozilla\Firefox\Profiles\paypbpzk.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_25.12.2014_2004_.backup
==== Registry Fix Code ======================
Windows Registry Editor Version 5.00
[HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"svchost.exe"=-
"updates32"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"svchost.exe"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"svchost.exe"=-
"updates32"=-
==== Deleting Files \ Folders ======================
C:\Users\Zorana Sijacki\AppData\Roaming\opp not found
"C:\Users\Zorana Sijacki\AppData\Roaming\svchost.exe" not found
C:\PROGRA~2\Photo-Service deleted
C:\Program Files\Common Files\System\SysMenu.dll deleted
C:\Program Files\Common Files\System\SysMenu64.dll deleted
C:\asac_original.exe deleted
C:\Users\Zorana Sijacki\AppData\Local\ilividmoviestoolbar20 deleted
C:\Users\Zorana Sijacki\AppData\Local\CRE deleted
C:\Users\Zorana Sijacki\Downloads\iMeshV11.exe deleted
C:\Users\Zorana Sijacki\Downloads\SoftonicDownloader_for_coreldraw-graphics-suite.exe deleted
C:\Users\Zorana Sijacki\Downloads\SoftonicDownloader_for_picasa.exe deleted
C:\Users\Zorana Sijacki\AppData\LocalLow\ilividmoviestoolbar20 deleted
C:\Users\ZORANA~1\AppData\Roaming\Mozilla\Firefox\Profiles\paypbpzk.default\ilividmoviestoolbar20 deleted
C:\Users\ZORANA~1\AppData\Roaming\Mozilla\Firefox\Profiles\paypbpzk.default\CT3072253 deleted
C:\Users\Zorana Sijacki\Desktop\PlayerStubWrapper.exe deleted
C:\Users\Zorana Sijacki\AppData\Roaming\100382382615051.exe deleted
C:\Users\Zorana Sijacki\AppData\Roaming\10846760431847.exe deleted
C:\Users\Zorana Sijacki\AppData\Roaming\120172650711554.exe deleted
C:\Users\Zorana Sijacki\AppData\Roaming\16242764929290.exe deleted
C:\Users\Zorana Sijacki\AppData\Roaming\21368593224100.exe deleted
C:\Users\Zorana Sijacki\AppData\Roaming\21732167601126.exe deleted
C:\Users\Zorana Sijacki\AppData\Roaming\274371996420432.exe deleted
C:\Users\Zorana Sijacki\AppData\Roaming\30557259229870.exe deleted
C:\Users\Zorana Sijacki\AppData\Roaming\31901113771439.exe deleted
C:\Users\Zorana Sijacki\AppData\Roaming\3632443413873.exe deleted
C:\Users\Zorana Sijacki\AppData\Roaming\403637917022.exe deleted
C:\Users\Zorana Sijacki\AppData\Roaming\522559113393.exe deleted
C:\Users\Zorana Sijacki\AppData\Roaming\9971683817609.exe deleted
C:\Users\ZORANA~1\AppData\Roaming\Mozilla\Firefox\Profiles\paypbpzk.default\conduitCommon deleted
C:\Users\ZORANA~1\AppData\Roaming\Mozilla\Firefox\Profiles\paypbpzk.default\smartbar deleted
==== Firefox Extensions ======================
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\Zorana Sijacki\AppData\Roaming\Mozilla\Firefox\Profiles\paypbpzk.default
47299371607DC2FB234444EEACB1639E - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll - Shockwave Flash
A514E2906D52E3413A9BB7DE87F7B1DF - C:\Users\Zorana Sijacki\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player
==== Chromium Look ======================
==== Chromium Startpages ======================
C:\Users\Zorana Sijacki\AppData\Local\Google\Chrome\User Data\Default\Preferences
"urls_to_restore_on_startup": [ "http://www.search.ask.com/?o=APN10645A&gct=hp&d=406-1720&v=n13001-391&t=4" ]
"urls_to_restore_on_startup": [ "http://www.search.ask.com/?o=APN10645A&gct=hp&d=406-1720&v=n13001-391&t=4" ]
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
"Search Bar"="http://www.google.com/ie"
"Default_Search_URL"="http://www.google.com/ie"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
@="http://www.google.com/search?q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://www.google.com/ie"
"Default_Search_URL"="http://www.google.com/ie"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://www.google.com"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Goo Url="http://www.google.com/search?q={sear"
{7AA88751-E997-4A8A-8B4B-7E84EA4B4F6E} Amazon Url="http://www.amazon.co.uk/gp/search?ie=UTF8&keywords={searchTerms}&tag=tochibauk-win7-ie-search-21&index=blended&linkCode=ur2"
{7BD5203A-F775-42CB-9AAC-60706F686FFF} Unknown Url="Not_Found"
{9B6788FF-377C-46E4-A8B6-9162EB1E61C8} eBay Url="http://rover.ebay.com/rover/1/710-71511-9400-6/4?satitle={searchTerms}"
{A84FFCED-121F-460B-A16D-87376D6C3D64} Google Url="http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-2004353239-133581813-3622214978-1000\Software\Microsoft\Internet Explorer\SearchScopes\{7BD5203A-F775-42CB-9AAC-60706F686FFF} deleted successfully
==== Deleting CLSID Registry Values ======================
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Zorana Sijacki\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Zorana Sijacki\AppData\Local\Temp\acro_rd_dir\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Zorana Sijacki\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
==== Empty FireFox Cache ======================
C:\Users\Zorana Sijacki\AppData\Local\Mozilla\Firefox\Profiles\paypbpzk.default\cache2 emptied successfully
==== Empty Chrome Cache ======================
C:\Users\Zorana Sijacki\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=1233 folders=77 42788372 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Zorana Sijacki\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\ZORANA~1\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\Users\Zorana Sijacki\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\MpCmdRun.log" not found
==== EOF on źet 25.12.2014 at 20:10:53,19 ======================
|
|
|
|
|
|
|
|
|
Poslao: 25 Dec 2014 21:05
|
offline
- Brksi

- Ex KGB officer
- Pridružio: 18 Jul 2003
- Poruke: 4206
- Gde živiš: U zlatnom kavezu
|
Sto se mene tice sve je nestalo jos prilikom prve intervencije firsta.
Fajl zoek karantin je prevelik za upload.
Da li first karantinu koji sam vec uplaodovao ima problema
|
|
|
|
|
|
|
|
|
Poslao: 25 Dec 2014 22:14
|
offline
- Brksi

- Ex KGB officer
- Pridružio: 18 Jul 2003
- Poruke: 4206
- Gde živiš: U zlatnom kavezu
|
Malwarebytes Anti-Rootkit BETA 1.08.2.1001
[Link mogu videti samo ulogovani korisnici]
Database version: v2014.12.25.14
Windows 7 x64 NTFS
Internet Explorer 8.0.7600.16385
Zorana Sijacki :: ZOKASANYA [administrator]
25.12.2014 21:40:07
mbar-log-2014-12-25 (21-40-07).txt
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 349738
Time elapsed: 26 minute(s), 11 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
Physical Sectors Detected: 0
(No malicious items detected)
(end)
[Link mogu videti samo ulogovani korisnici]
|
|
|
|
|
|
|
|
|
|