Iskakanje neželjenih prozora u Google Chrome-u

1

Iskakanje neželjenih prozora u Google Chrome-u

offline
  • Miroslav R. Maričić
  • diplomirani inženjer mašinstva, profesor
  • Pridružio: 06 Jun 2012
  • Poruke: 229
  • Gde živiš: Hajdučica, Banat, Srbija

Од пре неког времена у Google Chrome-у су почеле да се догађају чудне ствари. Кад кликнем на неки линк, уместо да одем тамо, отвори се прозор који нисам тражио. То се некад догађа и кад само кликнем негде са стране, или на клизач. Јако ме нервира, јер је почело да се догађа и у Mozilli и у Torch-у. Такође, у горњем десном углу се појави нешто као савијена страница, па се савије до пола екрана, па кад кликнем на њу, опет се отвори нежељени прозор. Једино се на Operi то не дешава. Како да се решим тога? Mad
Инсталисан ми је Avast и SUPERAntiSpyware Free Edition.

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Pozdrav, isprati ovo uputstvo i dostavi trazene logove.

http://www.mycity.rs/Ambulanta/Kako-otvoriti-temu-u-Ambulanti.html#p443395

offline
  • Miroslav R. Maričić
  • diplomirani inženjer mašinstva, profesor
  • Pridružio: 06 Jun 2012
  • Poruke: 229
  • Gde živiš: Hajdučica, Banat, Srbija

У реду, идем испочетка:

Од пре неког времена у Google Chrome-у су почеле да се догађају чудне ствари. Кад кликнем на неки линк, уместо да одем тамо, отвори се прозор који нисам тражио. То се некад догађа и кад само кликнем негде са стране, или на клизач. Јако ме нервира, јер је почело да се догађа и у Mozilli и у Torch-у. Такође, у горњем десном углу се појави нешто као савијена страница, па се савије до пола екрана, па кад кликнем на њу, опет се отвори нежељени прозор. Једино се на Operi то не дешава. Како да се решим тога?

OS: Win 7 Ultimate SP 1 32 bit
Инсталисан ми је Avast и SUPERAntiSpyware Free Edition.

Заштитни софтвер све што пронађе успешно уклања.

Интернет конекција је ADSL 10 Mb/s.

Фајл DDS.TXT:
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 11.0.9600.17041 BrowserJavaVersion: 10.55.2
Run by Miroslav Maričić at 8:09:14 on 2014-04-20
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.381.1033.18.2973.1535 [GMT 2:00]
.
AV: avast! Antivirus *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: avast! Antivirus *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\atiesrxx.exe
C:\Program Files\IDT\WDM\STacSV.exe
C:\Windows\system32\atieclxx.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\IDT\WDM\aestsrv.exe
C:\Program Files\Dell Wireless\Ath_CoexAgent.exe
C:\Program Files\Dell Wireless\Bluetooth Suite\adminservice.exe
C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
C:\Windows\system32\HPSIsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
C:\Program Files\Nitro\Reader 3\NitroPDFReaderDriverService3.exe
C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
C:\Users\Miroslav MariC:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Dell Wireless\Ath_WlanAgent.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\TeamViewer\Version9\TeamViewer.exe
C:\Program Files\TeamViewer\Version9\tv_w32.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Dell Wireless\Bluetooth Suite\BtvStack.exe
C:\Program Files\Dell Wireless\Bluetooth Suite\AthBtTray.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Users\Miroslav MariC:\Program Files\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Opera\opera.exe
C:\Windows\system32\AUDIODG.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://websearch.amaizingsearches.info/?pid=1925&r=2014/04/01&hid=3147122296695632418&lg=EN&cc=RS&unqvl=51
mStart Page = hxxp://websearch.amaizingsearches.info/?pid=1925&r=2014/04/01&hid=3147122296695632418&lg=EN&cc=RS&unqvl=51
uURLSearchHooks: FreeOnlineRadioPlayerRecorder Toolbar: {f999a48b-1950-4d81-9971-79018f807b4b} - c:\program files\freeonlineradioplayerrecorder\prxtbFree.dll
mURLSearchHooks: FreeOnlineRadioPlayerRecorder Toolbar: {f999a48b-1950-4d81-9971-79018f807b4b} - c:\program files\freeonlineradioplayerrecorder\prxtbFree.dll
BHO: HelperObject Class: {00C6482D-C502-44C8-8409-FCE54AD9C208} - c:\program files\techsmith\snagit 8\SnagItBHO.dll
BHO: RealNetworks Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\programdata\realnetworks\realdownloader\browserplugins\ie\rndlbrowserrecordplugin.dll
BHO: DeeAlExprress: {311C67A4-9503-3596-B82A-7FF40F22F458} -
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: CIESpeechBHO Class: {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - c:\program files\dell wireless\bluetooth suite\IEPlugIn.dll
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: GreyGray: {ae60e6ed-49dd-4099-8b5e-386a4908d5d5} -
BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: SaveAs Class: {B162F72B-082B-55E0-0775-0123C0B6DB8A} - c:\programdata\saveas\509ea0e3c5661.ocx
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
BHO: FreeOnlineRadioPlayerRecorder Toolbar: {f999a48b-1950-4d81-9971-79018f807b4b} - c:\program files\freeonlineradioplayerrecorder\prxtbFree.dll
TB: FreeOnlineRadioPlayerRecorder Toolbar: {f999a48b-1950-4d81-9971-79018f807b4b} - c:\program files\freeonlineradioplayerrecorder\prxtbFree.dll
TB: SnagIt: {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - c:\program files\techsmith\snagit 8\SnagItIEAddin.dll
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [se] "c:\users\miroslav maričić\appdata\roaming\skypemoticons\SE.exe" /minimized
mRun: [IAStorIcon] c:\program files\intel\intel(r) rapid storage technology\IAStorIcon.exe
mRun: [NUSB3MON] "c:\program files\renesas electronics\usb 3.0 host controller driver\application\nusb3mon.exe"
mRun: [AvastUI.exe] "c:\program files\avast software\avast\AvastUI.exe" /nogui
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [AtherosBtStack] "c:\program files\dell wireless\bluetooth suite\btvstack.exe"
mRun: [AthBtTray] "c:\program files\dell wireless\bluetooth suite\athbttray.exe"
mRun: [SysTrayApp] c:\program files\idt\wdm\sttray.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: I&zvezi u program Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {7815BE26-237D-41A8-A98F-F7BD75F71086} - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - c:\program files\dell wireless\bluetooth suite\IEPlugIn.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {FB858B22-55E2-413f-87F5-30ADC5552151} - c:\program files\plotsoft\pdfill\DownloadPDF.exe
Trusted Zone: dell.com
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{E6D061C6-9C94-4363-8F7A-E9C39E4BFF00} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{E6D061C6-9C94-4363-8F7A-E9C39E4BFF00}\4505D2C494E4B4F5437303632314 : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{E6D061C6-9C94-4363-8F7A-E9C39E4BFF00}\45F64716C6E45647 : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{E6D061C6-9C94-4363-8F7A-E9C39E4BFF00}\7525D213235303D4D4F5E4564777F627B6 : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{E6D061C6-9C94-4363-8F7A-E9C39E4BFF00}\A5D616A6 : DHCPNameServer = 192.168.1.1
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs= c:\progra~1\sw-boo~1\assist~1.dll
SSODL: WebCheck - <orphaned>
SEH: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - c:\program files\superantispyware\SASSEH.DLL
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\34.0.1847.116\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\miroslav maričić\appdata\roaming\mozilla\firefox\profiles\rlwtyu0w.default\
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;avast! Revert;c:\windows\system32\drivers\aswRvrt.sys [2013-3-4 49944]
R0 aswVmm;avast! VM Monitor;c:\windows\system32\drivers\aswVmm.sys [2013-3-4 180760]
R1 anodlwf;ANOD Network Security Filter driver;c:\windows\system32\drivers\anodlwf.sys [2012-9-20 12800]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2012-1-15 776976]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswsp.sys [2012-1-15 411552]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\system32\drivers\HWiNFO32.SYS [2014-4-3 22688]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664]
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2013-10-11 120088]
R2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service;c:\program files\common files\abbyy\finereader\9.00\licensing\pe\NetworkLicenseServer.exe [2007-12-6 660768]
R2 AESTFilters;Andrea ST Filters Service;c:\program files\idt\wdm\AEstSrv.exe [2014-4-3 81920]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2014-2-6 217600]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-1-15 67824]
R2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;c:\program files\dell wireless\Ath_CoexAgent.exe [2012-1-14 151552]
R2 AtherosSvc;AtherosSvc;c:\program files\dell wireless\bluetooth suite\AdminService.exe [2013-2-6 171136]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2014-3-27 50344]
R2 c2cautoupdatesvc;Skype Click to Call Updater;c:\program files\skype\toolbars\autoupdate\SkypeC2CAutoUpdateSvc.exe [2014-4-11 1390720]
R2 c2cpnrsvc;Skype Click to Call PNR Service;c:\program files\skype\toolbars\pnrsvc\SkypeC2CPNRSvc.exe [2014-4-11 1764992]
R2 HPSIService;HP SI Service;c:\windows\system32\HPSIsvc.exe [2013-3-5 99896]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\intel\intel(r) rapid storage technology\IAStorDataMgrSvc.exe [2012-1-14 13336]
R2 io.sys;IO.DLL Driver;c:\windows\system32\drivers\io.sys [2013-9-2 5152]
R2 NitroReaderDriverReadSpool3;NitroPDFReaderDriverCreatorReadSpool3;c:\program files\nitro\reader 3\NitroPDFReaderDriverService3.exe [2013-3-26 196624]
R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files\realnetworks\realdownloader\rndlresolversvc.exe [2013-4-16 39056]
R2 TeamViewer9;TeamViewer 9;c:\program files\teamviewer\version9\TeamViewer_Service.exe [2013-12-16 4972864]
R2 TorchCrashHandler;Torch Crash Handler;c:\users\miroslav maričić\appdata\local\torch\update\TorchCrashHandler.exe [2014-4-2 1216520]
R2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files\intel\intel(r) management engine components\uns\UNS.exe [2012-1-14 2655768]
R2 ZAtheros Wlan Agent;ZAtheros Wlan Agent;c:\program files\dell wireless\Ath_WlanAgent.exe [2014-4-3 81536]
R3 aswStm;aswStm;c:\windows\system32\drivers\aswstm.sys [2013-12-23 67264]
R3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\drivers\btath_flt.sys [2013-2-6 35968]
R3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys [2013-2-6 299648]
R3 btath_avdt;Atheros Bluetooth AVDT Service;c:\windows\system32\drivers\btath_avdt.sys [2013-2-6 98432]
R3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\drivers\btath_bus.sys [2013-2-6 25728]
R3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\drivers\btath_hcrp.sys [2013-2-6 148096]
R3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\drivers\btath_lwflt.sys [2013-2-6 60544]
R3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\drivers\btath_rcp.sys [2013-2-6 264704]
R3 BtFilter;BtFilter;c:\windows\system32\drivers\btfilter.sys [2013-2-6 470656]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;c:\program files\intel\intel(r) integrated clock controller service\ICCProxy.exe [2014-4-3 169752]
R3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\drivers\IntcDAud.sys [2014-2-6 289792]
R3 intelkmd;intelkmd;c:\windows\system32\drivers\igdpmd32.sys [2014-2-6 3741696]
R3 MEI;Intel(R) Management Engine Interface ;c:\windows\system32\drivers\HECI.sys [2010-10-20 41088]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys [2011-4-13 67456]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys [2014-4-1 177800]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [2014-4-1 214232]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2014-4-3 669912]
R3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\drivers\teamviewervpn.sys [2013-6-9 25088]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2013-10-23 172192]
S3 ATHDFU;Atheros Valkyrie USB BootROM;c:\windows\system32\drivers\AthDfu.sys [2013-2-6 44160]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 cpudrv;cpudrv;c:\program files\systemrequirementslab\cpudrv.sys [2011-6-2 11336]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\ieetwcollector.exe [2014-4-17 108032]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys [2014-3-27 107736]
S3 qcusbser;Mobile Connector USB Device for Legacy Serial Communication;c:\windows\system32\drivers\qcusbser.sys [2012-1-21 103552]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-11-21 14848]
S3 SWDUMon;SWDUMon;c:\windows\system32\drivers\SWDUMon.sys [2014-4-3 13464]
S3 SzCCID;USB SmartCard Reader Driver;c:\windows\system32\drivers\SzCCID.sys [2012-9-5 28160]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2014-3-16 49152]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\microsoft sql server\100\shared\sqladhlp.exe [2009-7-23 47128]
S4 RsFx0105;RsFx0105 Driver;c:\windows\system32\drivers\RsFx0105.sys [2011-9-22 238696]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\microsoft sql server\mssql10.sqlexpress\mssql\binn\SQLAGENT.EXE [2011-9-22 370024]
.
=============== File Associations ===============
.
FileExt: .txt: txtfile=c:\windows\system32\NOTEPAD.EXE %1 [UserChoice]
FileExt: .ini: Notepad++_file - HKCR\Unknown\Shell=c:\windows\system32\rundll32.exe c:\windows\system32\shell32.dll,OpenAs_RunDLL %1 [UserChoice] [default=openas]
FileExt: .inf: inffile=c:\windows\system32\NOTEPAD.EXE %1 [UserChoice]
ShellExec: FRONTPG.EXE: edit=c:\progra~1\micros~2\office10\FRONTPG.EXE
.
=============== Created Last 30 ================
.
2014-04-20 06:09:16 -------- d-----w- c:\users\miroslav mariŕiš\appdata\local\Microsoft
2014-04-19 09:19:00 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2014-04-18 11:18:42 -------- d-----w- c:\program files\JDownloader
2014-04-17 19:46:18 -------- d-----w- c:\windows\sr-Cyrl-CS
2014-04-17 19:46:15 -------- d-----w- c:\windows\system32\wbem\sr-Cyrl-CS
2014-04-17 19:32:10 455168 ----a-w- c:\windows\system32\vbscript.dll
2014-04-17 19:32:10 257536 ----a-w- c:\program files\internet explorer\IEShims.dll
2014-04-17 19:32:06 235216 ----a-w- c:\program files\internet explorer\sqmapi.dll
2014-04-17 19:32:02 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2014-04-17 19:32:00 271360 ----a-w- c:\program files\internet explorer\ieproxy.dll
2014-04-17 19:25:36 5694464 ----a-w- c:\windows\system32\mstscax.dll
2014-04-17 19:25:31 1212352 ----a-w- c:\windows\system32\drivers\ntfs.sys
2014-04-17 19:25:29 96768 ----a-w- c:\windows\system32\drivers\umdf\WUDFUsbccidDriver.dll
2014-04-17 19:25:26 27072 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2014-04-17 19:25:26 234432 ----a-w- c:\windows\system32\drivers\msiscsi.sys
2014-04-17 19:25:26 149440 ----a-w- c:\windows\system32\drivers\storport.sys
2014-04-17 19:25:25 2048 ----a-w- c:\windows\system32\iologmsg.dll
2014-04-15 18:58:04 -------- d-----w- C:\SUPERDelete
2014-04-12 11:55:32 19448 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\TeamViewer_PrintProcessor.dll
2014-04-10 19:24:57 -------- d-----w- c:\programdata\af55ab315028f8f4
2014-04-10 19:24:43 -------- d-----w- c:\programdata\DeeAlExprress
2014-04-06 18:40:19 -------- d-----w- c:\program files\SlimCleaner
2014-04-03 21:55:35 22688 ----a-w- c:\windows\system32\drivers\HWiNFO32.SYS
2014-04-03 21:45:43 -------- d-----w- C:\AMD
2014-04-03 21:22:59 104448 ----a-w- c:\windows\system32\IntelOpenCL32.dll
2014-04-03 21:04:41 548352 ------w- c:\windows\system32\stapi32.dll
2014-04-03 21:04:30 302592 ----a-w- c:\windows\system32\imthx32.dll
2014-04-03 21:04:29 734720 ----a-w- c:\windows\system32\imapo32.dll
2014-04-03 21:04:29 68192 ----a-w- c:\windows\system32\aestaren.dll
2014-04-03 21:04:29 380928 ----a-w- c:\windows\system32\aestecap.dll
2014-04-03 21:04:29 174688 ----a-w- c:\windows\system32\aestacap.dll
2014-04-03 21:04:27 86016 ----a-w- c:\windows\system32\AESTCom.dll
2014-04-03 21:04:27 6094848 ----a-w- c:\windows\system32\stlang.dll
2014-04-03 21:04:27 371200 ----a-w- c:\windows\system32\slapoi32.dll
2014-04-03 21:04:27 1785344 ----a-w- c:\windows\system32\IDTNCPL.cpl
2014-04-03 21:04:07 -------- d-----w- c:\windows\system32\SRSLabs
2014-04-03 21:01:40 450560 ----a-w- c:\windows\system32\drivers\stwrt.sys
2014-04-03 21:01:39 454656 ----a-w- c:\windows\system32\stcplx.dll
2014-04-03 21:01:39 252928 ----a-w- c:\windows\system32\MaxxAudioAPO30.dll
2014-04-03 21:01:39 211456 ----a-w- c:\windows\system32\st326421.dll
2014-04-03 21:01:39 172032 ----a-w- c:\windows\system32\MaxxAudioAPOShell.dll
2014-04-03 21:01:39 1458688 ----a-w- c:\windows\system32\stapo.dll
2014-04-03 21:01:38 -------- d-----w- c:\program files\IDT
2014-04-03 20:57:44 77528 ----a-w- c:\windows\system32\RtNicProp32.dll
2014-04-03 20:57:44 669912 ----a-w- c:\windows\system32\drivers\Rt86win7.sys
2014-04-03 20:57:44 102104 ----a-w- c:\windows\system32\RTNUninst32.dll
2014-04-03 20:57:41 -------- d-----w- c:\program files\Realtek
2014-04-03 20:40:17 -------- d-----w- c:\users\miroslav maričić\appdata\roaming\Atheros
2014-04-03 20:39:02 -------- d-----w- c:\program files\common files\Atheros
2014-04-03 20:36:00 -------- d-----w- c:\windows\system32\nn-NO
2014-04-03 20:35:59 61440 ------w- c:\windows\system32\athihvui.dll
2014-04-03 20:35:59 397312 ------w- c:\windows\system32\athihvs.dll
2014-04-03 20:35:27 -------- d-----w- c:\program files\Cisco
2014-04-03 19:45:41 13464 ----a-w- c:\windows\system32\drivers\SWDUMon.sys
2014-04-03 19:45:29 -------- d-----w- c:\program files\SlimDrivers
2014-04-01 13:31:21 79872 ----a-w- c:\windows\system32\nusb3co3.dll
2014-04-01 13:31:21 177800 ----a-w- c:\windows\system32\drivers\nusb3xhc.sys
2014-04-01 13:29:54 9888840 ----a-w- c:\windows\system32\RsCRIcon.dll
2014-04-01 13:29:54 214232 ----a-w- c:\windows\system32\drivers\RtsUStor.sys
2014-04-01 05:13:48 -------- d-----w- c:\users\miroslav maričić\appdata\roaming\EZDownloader
2014-04-01 05:09:57 -------- d-----w- c:\users\miroslav maričić\appdata\roaming\SkypEmoticons
2014-04-01 05:09:57 -------- d-----w- c:\programdata\GreenApp
2014-04-01 05:08:06 -------- d-----w- c:\program files\SW-Booster
2014-04-01 05:07:06 -------- d-----w- c:\windows\system32\X86
2014-04-01 05:07:06 -------- d-----w- c:\windows\system32\AMD64
2014-04-01 05:07:06 -------- d-----w- c:\program files\EZDownloader
2014-03-31 10:40:35 -------- d-----w- c:\program files\Innovative Solutions
2014-03-29 20:15:08 -------- d-----w- c:\users\miroslav maričić\appdata\roaming\SUPERAntiSpyware.com
2014-03-29 20:14:59 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2014-03-29 20:14:59 -------- d-----w- c:\program files\SUPERAntiSpyware
2014-03-27 12:12:20 107736 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-03-27 12:00:51 43152 ----a-w- c:\windows\avastSS.scr
2014-03-22 20:26:45 -------- d-----w- c:\program files\MediaWatchV1
.
==================== Find3M ====================
.
2014-04-13 10:04:18 70832 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-04-13 10:04:18 692400 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-04-03 20:40:24 246804 ----a-w- c:\windows\system32\drivers\AtherosBt.bin
2014-03-31 07:35:10 231584 ------w- c:\windows\system32\MpSigStub.exe
2014-03-27 12:00:52 67264 ----a-w- c:\windows\system32\drivers\aswstm.sys
2014-03-27 12:00:51 81768 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-03-27 12:00:51 776976 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2014-03-27 12:00:51 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-03-27 12:00:51 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-03-27 12:00:51 180760 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-03-13 13:45:12 27144 ----a-w- c:\windows\system32\nitrolocalmon9.dll
2014-03-13 13:45:12 18440 ----a-w- c:\windows\system32\nitrolocalui9.dll
2014-03-06 08:31:27 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2014-03-06 08:02:34 61952 ----a-w- c:\windows\system32\iesetup.dll
2014-03-06 08:01:01 51200 ----a-w- c:\windows\system32\ieetwproxystub.dll
2014-03-06 07:46:36 4254720 ----a-w- c:\windows\system32\jscript9.dll
2014-03-06 07:38:13 112128 ----a-w- c:\windows\system32\ieUnatt.exe
2014-03-06 07:38:10 108032 ----a-w- c:\windows\system32\ieetwcollector.exe
2014-03-06 07:36:40 592896 ----a-w- c:\windows\system32\jscript9diag.dll
2014-03-06 07:28:01 646144 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2014-03-06 07:13:43 32256 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2014-03-06 06:40:39 1967104 ----a-w- c:\windows\system32\inetcpl.cpl
2014-03-06 05:41:49 1789440 ----a-w- c:\windows\system32\wininet.dll
2014-02-19 20:36:50 82920 ----a-w- c:\windows\system32\mslvddsfilter2.ax
2014-02-07 01:07:56 2349056 ----a-w- c:\windows\system32\win32k.sys
2014-02-04 02:04:22 1230336 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-02-04 02:04:11 509440 ----a-w- c:\windows\system32\qedit.dll
2014-01-29 22:12:28 519680 ----a-w- c:\windows\system32\iglhsip32.dll
2014-01-29 22:12:28 272928 ----a-w- c:\windows\system32\igvpkrng600.bin
2014-01-29 22:12:28 180224 ----a-w- c:\windows\system32\iglhcp32.dll
2014-01-29 22:12:28 102400 ----a-w- c:\windows\system32\igfxCoIn_v3347.dll
2014-01-29 02:06:47 381440 ----a-w- c:\windows\system32\wer.dll
2014-01-28 02:07:07 185344 ----a-w- c:\windows\system32\wwansvc.dll
.
============= FINISH: 8:10:43,05 ===============

https://www.mycity.rs/must-login.png

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Dobro idemo redom.
Deinstaliraj sledece programe:

FreeOnlineRadioPlayerRecorder Toolbar
iLivid
PC Optimizer Pro
Skype Click to Call
SkypEmoticons
SnagIt 8



Arrow
Preuzmi "Xplode"-ov AdwCleaner () i sacuvaj ga na Desktop

Dvoklikom pokreni program.
Klikni na dugme [Scan] i pricekaj da program zavrsi.
Klikni na dugme [Clean]
Program ce zatvoriti sve aktivne programe i izbaciti prozor sa tim upozorenjem. Klikni Ok kao potvrdu.
Na sledeca dva prozora koja se otvore (Informations i Restart required ) klikni Ok


Racunar ce se restartovati a potom otvoriti notepad (C:\AdwCleaner[S1].txt) sa izvestajem.
Sacuvaj taj notepad na Desktop i okaci ga uz poruku koristeci opciju "Prikaci fajl"

Napomena: Izvestaj ce takodje biti sacuvan na C:\AdwCleaner[S0].txt






************************************





Arrow
Preuzmi smeenk-ov zoek.zip ili zoek.rar () sa ovog ili ovog linka i sačuvaj ga na Desktop.

Raspakuj arhivu u neki folder (uputstvo), a zatim:

zatvori browser i ostale pokrenute programe;
privremeno deaktiviraj zaštitni softver ( ukoliko je to potrebno ) Uputstvo ;
dvoklikom pokreni zoek na ikonicu programa ;
pričekaj da se alat startuje ...


U beli okvir prozora iskopiraj sledeći tekst:


{f999a48b-1950-4d81-9971-79018f807b4b};c
c:\program files\freeonlineradioplayerrecorder;js
{00C6482D-C502-44C8-8409-FCE54AD9C208};c
c:\program files\techsmith\snagit 8;js
{311C67A4-9503-3596-B82A-7FF40F22F458};c
{ae60e6ed-49dd-4099-8b5e-386a4908d5d5};c
{B162F72B-082B-55E0-0775-0123C0B6DB8A};c
c:\programdata\saveas;js
{8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3};c
c:\users\miroslav maricic\appdata\roaming\skypemoticons;js
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run];r
"se"=-;r
emptyalltemp;
autoclean;
emptyclsid;
filesrcm;
startupall;



Klikni na dugme i pričekaj da se skeniranje završi.


zoek ce po potrebi, restartovati Windows a na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.

Napomena:Izveštaj će biti sačuvan pod nazivom zoek-results.log na sistemskoj particiji (tipična lokacija: C:\zoek-results.log)


Arrow Kopiraj sadrzaj tog loga u poruku.

offline
  • Miroslav R. Maričić
  • diplomirani inženjer mašinstva, profesor
  • Pridružio: 06 Jun 2012
  • Poruke: 229
  • Gde živiš: Hajdučica, Banat, Srbija

Урадио сам све по реду. Ево резултата:

Zoek.exe v5.0.0.0 Updated 14-April-2014
Tool run by Miroslav Mariźi† on ned 20.04.2014 at 15:05:57,51.
Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Download\Zoek\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

20.4.2014 15:09:00 Zoek.exe System Restore Point Created Succesfully.

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-3498601666-3105869778-635197538-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00C6482D-C502-44C8-8409-FCE54AD9C208} deleted successfully
HKEY_USERS\S-1-5-21-3498601666-3105869778-635197538-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{00C6482D-C502-44C8-8409-FCE54AD9C208} deleted successfully
HKEY_USERS\S-1-5-21-3498601666-3105869778-635197538-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{311C67A4-9503-3596-B82A-7FF40F22F458} deleted successfully
HKEY_USERS\S-1-5-21-3498601666-3105869778-635197538-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{311C67A4-9503-3596-B82A-7FF40F22F458} deleted successfully
HKEY_USERS\S-1-5-21-3498601666-3105869778-635197538-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B162F72B-082B-55E0-0775-0123C0B6DB8A} deleted successfully
HKEY_USERS\S-1-5-21-3498601666-3105869778-635197538-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B162F72B-082B-55E0-0775-0123C0B6DB8A} deleted successfully
HKEY_USERS\S-1-5-21-3498601666-3105869778-635197538-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} deleted successfully
HKEY_USERS\S-1-5-21-3498601666-3105869778-635197538-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} deleted successfully
HKEY_USERS\S-1-5-21-3498601666-3105869778-635197538-1000\Software\Microsoft\Internet Explorer\SearchScopes\{48373AD6-7AA5-4056-9BD3-C1D6E5BD7F18} deleted successfully
HKEY_USERS\S-1-5-21-3498601666-3105869778-635197538-1000\Software\Microsoft\Internet Explorer\SearchScopes\{776083DD-06CC-4947-8F8C-575E0C33FB4A} deleted successfully
HKEY_USERS\S-1-5-21-3498601666-3105869778-635197538-1000\Software\Microsoft\Internet Explorer\SearchScopes\{ADFB21DA-4EC7-4A2D-900D-BF9525BD7122} deleted successfully
HKEY_USERS\S-1-5-21-3498601666-3105869778-635197538-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} deleted successfully
HKEY_USERS\S-1-5-21-3498601666-3105869778-635197538-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{311C67A4-9503-3596-B82A-7FF40F22F458} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{311C67A4-9503-3596-B82A-7FF40F22F458} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{311C67A4-9503-3596-B82A-7FF40F22F458} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{B162F72B-082B-55E0-0775-0123C0B6DB8A} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B162F72B-082B-55E0-0775-0123C0B6DB8A} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{5df00738-066d-4ec0-9303-0cfc124a98a2} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110111181125} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-3498601666-3105869778-635197538-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\{f999a48b-1950-4d81-9971-79018f807b4b} deleted successfully
HKEY_USERS\S-1-5-21-3498601666-3105869778-635197538-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} deleted successfully
HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\ext@VideoPlayerV3beta225.net deleted successfully
HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\ext@MediaWatchV1home204.net deleted successfully

==== Deleting Services ======================


==== FireFox Fix ======================

ProfilePath: C:\Users\MIROSL~1\AppData\Roaming\Mozilla\Firefox\Profiles\rlwtyu0w.default

user.js not found
---- Lines extensions.VNj4N removed from prefs.js ----
user_pref("extensions.VNj4N.epoch", "1398027461");
user_pref("extensions.VNj4N.url", "http://driverguidemy.ru/sync2/?q=hfZ9ofbLAfkMCyVUojaMg708BNmGWj8ikGhGheDUojw9rdnFrdw5rTnHrGhIC7n0rjnEqdw4rTa8qHnEtN
---- Lines ext@VideoPlayerV3beta225.net modified from prefs.js ----

user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"{FCE04E1F-9378-4f39-96F6-5689A9159E45}\":{\"descriptor\":\"C:\\\\
---- Lines ext@MediaWatchV1home204.net modified from prefs.js ----

user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"{FCE04E1F-9378-4f39-96F6-5689A9159E45}\":{\"descriptor\":\"C:\\\\
---- FireFox user.js and prefs.js backups ----

prefs_20.04.2014_1523_.backup

==== Registry Fix Code ======================

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"se"=-

==== Deleting Files \ Folders ======================

C:\Users\Miroslav Maričić\pkcs11wrapper_32.dll not found
C:\Users\Miroslav Maričić\Downloads\iLividSetup_C-r477-t-bc.exe not found
"C:\Users\Miroslav Maričić\AppData\Roaming" not found
C:\Users\MIROSL~1\AppData\LocalLow\{311C67A4-9503-3596-B82A-7FF40F22F458} deleted
C:\PROGRA~2\af55ab315028f8f4 deleted
C:\PROGRA~2\DeeAlExprress deleted
C:\extensions.sqlite deleted
C:\extensions.ini deleted
C:\PROGRA~2\InstallMate deleted
C:\PROGRA~2\YTD Video Downloader deleted
C:\Users\MIROSL~1\AppData\Local\TempDIR deleted
C:\Users\MIROSL~1\AppData\Local\cache deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YTD Video Downloader deleted
C:\Users\MIROSL~1\AppData\LocalLow\DataMngr deleted
C:\Windows\system32\config\systemprofile\AppData\LocalLow\Application Updater deleted
C:\Windows\tasks\OptimizerProUpdaterTask{3EFA3E14-7627-4EB7-8547-EFBEFDC090E7}.job deleted
C:\Windows\system32\tasks\OptimizerProUpdaterTask{3EFA3E14-7627-4EB7-8547-EFBEFDC090E7} deleted
C:\Windows\tasks\PC Optimizer Pro Scan.job deleted
C:\Windows\system32\tasks\PC Optimizer Pro Scan deleted
C:\user.js deleted
C:\Windows\System32\searchplugins deleted
C:\Windows\System32\Extensions deleted
C:\Users\Miroslav Mariźi†\Documents\Download\DriverMax 7.23 Pro (zabranjeno), Serial and Keygen Full Download.exe deleted
C:\Users\Miroslav Mariźi†\Documents\Download\PDFdowlonad.exe deleted

==== Files Recently Created / Modified ======================

====== C:\Windows ====
2014-03-27 12:00:51 E1CBFDE5CAD6C373946A0D2C238E6522 43152 ----a-w- C:\Windows\avastSS.scr
====== C:\Users\MIROSL~1\AppData\Local\Temp ====
2014-04-20 12:48:38 2D2894581D355D5F44EAE38898A66846 4398888 ----a-w- C:\Users\MIROSL~1\AppData\Local\Temp\tbFree.dll
2014-04-18 11:15:25 5233DEB9ABD65ACAA9479BFFA702336F 664680 ----a-w- C:\Users\MIROSL~1\AppData\Local\Temp\JDSetup130422933254529121.exe
2014-04-15 20:50:42 A903EDEAEF449147512D94B7AB2D44AA 921512 ----a-w- C:\Users\MIROSL~1\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe
2014-04-15 18:53:41 C124F3411C3E22A8CBC74ADA51B6961F 7624808 ----a-w- C:\Users\MIROSL~1\AppData\Local\Temp\npp.6.5.5.Installer.exe
2014-04-14 16:10:53 A9C86900D2A61728C8326FE7147617C5 578440 ----atw- C:\Users\MIROSL~1\AppData\Local\Temp\{13C00A2E-D0CD-4AB2-9550-C8DB4491B2D9}\npGoogleUpdate3.dll
2014-04-14 16:10:53 3A49D76D0AA3DC5FC0B4EEF3B7E84EF1 166792 ----atw- C:\Users\MIROSL~1\AppData\Local\Temp\{13C00A2E-D0CD-4AB2-9550-C8DB4491B2D9}\psmachine.dll
2014-04-14 16:10:53 3703787CB966F9F6C69EF9164D882EE3 166792 ----atw- C:\Users\MIROSL~1\AppData\Local\Temp\{13C00A2E-D0CD-4AB2-9550-C8DB4491B2D9}\psuser.dll
2014-04-14 16:10:51 FF3FD6B78A82624C7B319EEA7F7EB8F6 51080 ----atw- C:\Users\MIROSL~1\AppData\Local\Temp\{13C00A2E-D0CD-4AB2-9550-C8DB4491B2D9}\GoogleUpdateOnDemand.exe
2014-04-14 16:10:51 EA8B5B41163A06FFA8930F5316473035 273800 ----atw- C:\Users\MIROSL~1\AppData\Local\Temp\{13C00A2E-D0CD-4AB2-9550-C8DB4491B2D9}\GoogleCrashHandler64.exe
2014-04-14 16:10:51 C98ACDE22458C8F46FD0503CB9E2D01F 223112 ----atw- C:\Users\MIROSL~1\AppData\Local\Temp\{13C00A2E-D0CD-4AB2-9550-C8DB4491B2D9}\GoogleCrashHandler.exe
2014-04-14 16:10:51 BA5C08130D2EFBD4E546912646DC4461 847640 ----a-w- C:\Users\MIROSL~1\AppData\Local\Temp\{13C00A2E-D0CD-4AB2-9550-C8DB4491B2D9}\GoogleUpdateSetup.exe
2014-04-14 16:10:51 A43B937C580F5DFC43EF63EF72992FE9 847752 ----atw- C:\Users\MIROSL~1\AppData\Local\Temp\{13C00A2E-D0CD-4AB2-9550-C8DB4491B2D9}\goopdate.dll
2014-04-14 16:10:51 6D24CD9918A11CD8AB9AE678CB2CC3C7 51080 ----atw- C:\Users\MIROSL~1\AppData\Local\Temp\{13C00A2E-D0CD-4AB2-9550-C8DB4491B2D9}\GoogleUpdateBroker.exe
2014-04-14 16:10:51 6996AB4F70B3718CC465DE43A75A10C8 26112 ----atw- C:\Users\MIROSL~1\AppData\Local\Temp\{13C00A2E-D0CD-4AB2-9550-C8DB4491B2D9}\GoogleUpdateHelper.msi
2014-04-14 16:10:51 506708142BC63DABA64F2D3AD1DCD5BF 116648 ----atw- C:\Users\MIROSL~1\AppData\Local\Temp\{13C00A2E-D0CD-4AB2-9550-C8DB4491B2D9}\GoogleUpdate.exe
====== Java Cache =====
2014-04-01 17:22:13 1028667390E1CCAF749CF100D270408B 21691 ----a-w- C:\Users\MIROSL~1\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\2fb889a6-5951bc43
====== C:\Windows\system32 =====
2014-04-19 09:19:10 6EA69D2312F3571F6F8BEADD224165E8 264616 ----a-w- C:\Windows\System32\javaws.exe
2014-04-19 09:19:00 B42338F92D3BDADA79B6BE553E72587C 94632 ----a-w- C:\Windows\System32\WindowsAccessBridge.dll
2014-04-19 09:19:00 9533FE0A942E00114047140B42DF8E3D 175016 ----a-w- C:\Windows\System32\java.exe
2014-04-19 09:19:00 37C15684482B4D596316735DCEEE939A 175528 ----a-w- C:\Windows\System32\javaw.exe
2014-04-17 19:32:10 CE6921D33682C6C3DB8A45853CC69402 455168 ----a-w- C:\Windows\System32\vbscript.dll
2014-04-17 19:32:08 AA12D7A960DB78DD9690AB5B5DAE6586 440832 ----a-w- C:\Windows\System32\ieui.dll
2014-04-17 19:32:02 A127D17C354B473B0F4C6265538F5A2C 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2014-04-17 19:31:59 BB185D4A9362AA17CBCEC0768CDBF249 704512 ----a-w- C:\Windows\System32\ieapfltr.dll
2014-04-17 19:31:59 116632CE6DF92EA78C2B849E1279B1FA 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2014-04-17 19:31:57 EDACA6C44D9CE200F899B7DB0F201DFF 164864 ----a-w- C:\Windows\System32\msrating.dll
2014-04-17 19:31:57 EBC35FE64056910A84485BEEB6DCCAC6 524288 ----a-w- C:\Windows\System32\msfeeds.dll
2014-04-17 19:31:57 31385A6CAA31BE9D07B0B32E5AA99ABB 43008 ----a-w- C:\Windows\System32\jsproxy.dll
2014-04-17 19:31:55 7E9FE7DB43BC204E44F159F843E35C15 367616 ----a-w- C:\Windows\System32\dxtmsft.dll
2014-04-17 19:31:55 34FC79C948EE2C5FD0CD699E7D7F91B7 244224 ----a-w- C:\Windows\System32\dxtrans.dll
2014-04-17 19:31:54 E5E97E94DD9D69D8EE90CFA96156CD8A 575488 ----a-w- C:\Windows\System32\ie4uinit.exe
2014-04-17 19:31:54 82287FCFFA4A2D60FD744E3FEB3192C5 61952 ----a-w- C:\Windows\System32\iesetup.dll
2014-04-17 19:31:54 21BF6759685FD193715B483F2B3F21B1 112128 ----a-w- C:\Windows\System32\ieUnatt.exe
2014-04-17 19:31:54 0FDC1A576A3F40420882C0F7C4A66EAD 32768 ----a-w- C:\Windows\System32\iernonce.dll
2014-04-17 19:31:52 C9CA9803299EB6AFA34CB520BAAB083D 32256 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll
2014-04-17 19:31:51 BECAA526B8A1823A36A1BA123B8C41A9 646144 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2014-04-17 19:31:51 6557B48D53D653CFCCE3CB1CFA53A8E1 51200 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2014-04-17 19:31:51 2101D94DED769CE86A3DE1152F4FCDF5 108032 ----a-w- C:\Windows\System32\ieetwcollector.exe
2014-04-17 19:31:51 0F4A295516781897FFB09B4CCF2E8798 592896 ----a-w- C:\Windows\System32\jscript9diag.dll
2014-04-17 19:31:41 05BD47136DE62FAFE9F95B40E4100144 2178048 ----a-w- C:\Windows\System32\iertutil.dll
2014-04-17 19:31:40 E4E829EE073E046B0EB19B5FECB19B8C 1789440 ----a-w- C:\Windows\System32\wininet.dll
2014-04-17 19:31:40 C4A383FD50FBD7E274DD41CF571DF898 1967104 ----a-w- C:\Windows\System32\inetcpl.cpl
2014-04-17 19:31:40 76F58DB8F85C125E0D6B3AA42F3BF1D0 1143808 ----a-w- C:\Windows\System32\urlmon.dll
2014-04-17 19:31:38 2AFBB91BBD2378933B26E6D68C140D1B 11745792 ----a-w- C:\Windows\System32\ieframe.dll
2014-04-17 19:31:37 EA85144F35EDE6EE25C484D4242FF2C8 17387008 ----a-w- C:\Windows\System32\mshtml.dll
2014-04-17 19:31:36 8C46360D6EF9D4C563FE834C4F287DA3 4254720 ----a-w- C:\Windows\System32\jscript9.dll
2014-04-17 19:25:36 204882085A7D984D455AA4DE7B7074C6 5694464 ----a-w- C:\Windows\System32\mstscax.dll
2014-04-17 19:25:34 F74FFA7654702F81884BDB41EB80DAC2 868352 ----a-w- C:\Windows\System32\kernel32.dll
====== C:\Windows\system32\drivers =====
2014-04-17 19:25:31 C8DFF8D07755A66C7A4A738930F0FEAC 1212352 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2014-04-17 19:25:26 F1A449D762657230629D8BFC107ABC14 149440 ----a-w- C:\Windows\System32\drivers\storport.sys
2014-04-17 19:25:26 EB34CE31FABD4DC4343FD2AD16D2CAF9 234432 ----a-w- C:\Windows\System32\drivers\msiscsi.sys
2014-04-17 19:25:26 5FB4F271032B6435F3B2252F577A4815 27072 ----a-w- C:\Windows\System32\drivers\Diskdump.sys
2014-04-03 21:55:35 4745A8B2BE115B054F31A86B0E64BB01 22688 ----a-w- C:\Windows\System32\drivers\HWiNFO32.SYS
2014-04-03 21:01:40 178277BE781FBDAE4E98FB07D36DC711 450560 ----a-w- C:\Windows\System32\drivers\stwrt.sys
2014-04-03 20:57:44 295522318E57F3C00C3A0719CEF5FE1B 669912 ----a-w- C:\Windows\System32\drivers\Rt86win7.sys
2014-04-03 19:45:41 75A8EE6F0917AD9355367DBF25DB8415 13464 ----a-w- C:\Windows\System32\drivers\SWDUMon.sys
2014-04-01 13:31:21 7D3ABA058912D4574E7F1CE1D9713DAE 177800 ----a-w- C:\Windows\System32\drivers\nusb3xhc.sys
2014-04-01 13:29:54 26C52784BA91411D62EF078DA04F8057 214232 ----a-w- C:\Windows\System32\drivers\RtsUStor.sys
2014-03-27 12:12:20 661B911FA04E73FB073FF9B1C9BD2E05 107736 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
====== C:\Windows\Tasks ======
2014-04-20 12:58:15 35B9D6BE7E6719A47A278DF9E84609F8 3658 ----a-w- C:\Windows\system32\Tasks\RNUpgradeHelperResumePrompt_Miroslav Maričić
2014-04-20 12:58:12 6BC1B6847D25BDEB254126F7E4BA293F 3032 ----a-w- C:\Windows\system32\Tasks\ReclaimerUpdateFiles_Miroslav Maričić
2014-04-20 12:58:11 9162B1D935D88151A7221A7E8D323384 414 ----a-w- C:\Windows\Tasks\ReclaimerUpdateFiles_Miroslav Maričić.job
2014-04-20 12:58:08 8FFFA4C31A6753F57CBDEC6C22F1A8EB 410 ----a-w- C:\Windows\Tasks\ReclaimerUpdateXML_Miroslav Maričić.job
2014-04-20 12:58:08 0EA703A8087F879A483CF6EDC787AB77 3028 ----a-w- C:\Windows\system32\Tasks\ReclaimerUpdateXML_Miroslav Maričić
2014-04-06 18:40:18 DDC3CCD83FFF6D59EF59B9182196748E 3014 ----a-w- C:\Windows\system32\Tasks\SlimCleaner Run
====== C:\Windows\Temp ======
======= C:\Program Files =====
2014-04-19 09:19:39 -------- d-----w- C:\Program Files\Common Files\Java
2014-04-18 11:18:42 -------- d-----w- C:\Program Files\JDownloader
2014-04-06 18:40:19 -------- d-----w- C:\Program Files\SlimCleaner
2014-04-03 21:01:38 -------- d-----w- C:\Program Files\IDT
2014-04-03 20:57:41 -------- d-----w- C:\Program Files\Realtek
2014-04-03 20:39:02 -------- d-----w- C:\Program Files\Common Files\Atheros
2014-04-03 20:35:27 -------- d-----w- C:\Program Files\Cisco
2014-04-03 19:45:29 -------- d-----w- C:\Program Files\SlimDrivers
2014-04-01 05:08:06 -------- d-----w- C:\Program Files\SW-Booster
2014-03-31 10:40:35 -------- d-----w- C:\Program Files\Innovative Solutions
2014-03-29 20:14:59 -------- d-----w- C:\Program Files\SUPERAntiSpyware
======= C: =====
====== C:\Users\Miroslav Mariźi†\AppData ======
2014-04-20 12:59:31 -------- d-----r- C:\Users\MIROSL~1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2014-04-20 12:48:43 -------- d-sh--w- C:\Users\MIROSL~1\AppData\Local\EmieUserList
2014-04-20 12:48:43 -------- d-sh--w- C:\Users\MIROSL~1\AppData\Local\EmieSiteList
2014-04-20 10:08:18 -------- d-----w- C:\Users\MIROSL~1\AppData\Local\{E4F3883F-D07B-49BD-9820-5899677D1B0D}
2014-04-20 06:09:16 -------- d-----w- C:\Users\Miroslav MariŔiŠ\AppData\Local\Microsoft
2014-04-16 21:07:53 -------- d-----w- C:\Windows\serviceprofiles\Localservice\AppData\Local\CrashDumps
2014-04-15 18:55:19 -------- d-----w- C:\Users\MIROSL~1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notepad++
2014-04-03 20:40:17 -------- d-----w- C:\Users\MIROSL~1\AppData\Roaming\Atheros
2014-04-03 19:45:39 -------- d-----w- C:\Users\MIROSL~1\AppData\Local\SlimWare Utilities Inc
2014-04-02 17:20:31 -------- d-----w- C:\Windows\system32\config\systemprofile\AppData\Local\Temp
2014-04-02 17:20:30 -------- d-----w- C:\Windows\system32\config\systemprofile\AppData\Local\Torch
2014-03-31 10:40:38 -------- d-----w- C:\Users\MIROSL~1\AppData\Local\Innovative Solutions
2014-03-29 20:15:08 -------- d-----w- C:\Users\MIROSL~1\AppData\Roaming\SUPERAntiSpyware.com
2014-03-21 13:58:29 9B97E520A1977D218C501966CB8CFF9F 9257 ----a-w- C:\Users\MIROSL~1\AppData\Local\recently-used.xbel
2014-03-21 13:49:41 -------- d-----w- C:\Users\MIROSL~1\AppData\Local\webkit
====== C:\Users\Miroslav Mariźi† ======
2014-04-20 12:44:16 E0AA8A7D008C1E2A8612B492A1452AA5 1308369 ----a-w- C:\Users\MIROSL~1\Desktop\AdwCleaner.exe
2014-04-20 10:47:23 46780BAB1797D66B3C46168BA4868A2D 31429160 ----a-w- C:\Users\MIROSL~1\Downloads\avc-free (3).exe
2014-04-20 10:28:42 46780BAB1797D66B3C46168BA4868A2D 31429160 ----a-w- C:\Users\MIROSL~1\Downloads\avc-free (2).exe
2014-04-20 06:09:16 -------- d-----w- C:\Users\Miroslav MariŔiŠ\AppData
2014-04-19 09:19:00 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-04-19 09:16:12 A76E951ED4F8335337FD157A574DA36F 921512 ----a-w- C:\Users\MIROSL~1\Downloads\chromeinstall-7u55.exe
2014-04-18 11:15:20 6A72C470371B4CA7777161F8F015BEEB 76456 ----a-w- C:\Users\MIROSL~1\Documents\WebInstaller.exe
2014-04-06 18:40:19 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlimCleaner
2014-04-03 20:48:23 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Atheros Smart Net
2014-04-03 20:48:18 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HotSpot
2014-04-03 20:39:57 -------- d-----r- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BT Program
2014-04-03 19:45:30 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlimDrivers
2014-04-01 05:09:57 -------- d-----w- C:\ProgramData\GreenApp
2014-03-29 20:15:04 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2014-03-29 20:14:59 -------- d-----w- C:\ProgramData\SUPERAntiSpyware.com
2014-03-22 20:27:32 19BB54B2C8B8366DE75D10679BFC00E9 480 --sha-r- C:\ProgramData\ntuser.pol

====== C: exe-files ==
2014-04-20 10:51:53 6976590EEA59DDD608297D9AEC07DAC1 1193808 ----a-w- C:\Program Files\AnvSoft\Any Video Converter\unins000.exe
2014-04-19 09:18:55 FB67D8F555AA8E847DC6D7BFFF69C1C1 145832 ----a-w- C:\Program Files\Java\jre7\bin\unpack200.exe
2014-04-19 09:18:55 67E721D8CA3F26695C2836870FF395E0 16808 ----a-w- C:\Program Files\Java\jre7\bin\tnameserv.exe
2014-04-19 09:18:54 E788AC8198E99F9DA268A35719462DEF 16296 ----a-w- C:\Program Files\Java\jre7\bin\kinit.exe
2014-04-19 09:18:54 CA8C3C3510377A38A0FD0386B1C8700D 16296 ----a-w- C:\Program Files\Java\jre7\bin\keytool.exe
2014-04-19 09:18:54 B863FBED45DA51498B42DEAE76006D94 16296 ----a-w- C:\Program Files\Java\jre7\bin\ktab.exe
2014-04-19 09:18:54 B1CE4931FCA0E9D6493F18440A492472 49576 ----a-w- C:\Program Files\Java\jre7\bin\ssvagent.exe
2014-04-19 09:18:54 829199AE07062FE066CCD037190B4D04 16296 ----a-w- C:\Program Files\Java\jre7\bin\servertool.exe
2014-04-19 09:18:54 77430E8234A0050ECCC5E2F5B30A7BEF 182696 ----a-w- C:\Program Files\Java\jre7\bin\jqs.exe
2014-04-19 09:18:54 7151FDB921CC188833E69690E969616A 16296 ----a-w- C:\Program Files\Java\jre7\bin\rmiregistry.exe
2014-04-19 09:18:54 5F32AD07982BE93452A755CE94F130BA 16296 ----a-w- C:\Program Files\Java\jre7\bin\pack200.exe
2014-04-19 09:18:54 3DAA029309C13F0A8DFB839372A3E8D3 16296 ----a-w- C:\Program Files\Java\jre7\bin\orbd.exe
2014-04-19 09:18:54 3B8C2991462B84868BB04C67E197CFC1 16296 ----a-w- C:\Program Files\Java\jre7\bin\rmid.exe
2014-04-19 09:18:54 21190A2C683911E97E6484632F0A11AF 16296 ----a-w- C:\Program Files\Java\jre7\bin\policytool.exe
2014-04-19 09:18:54 0F298580559EE0929C572CFEB99B5AAA 16296 ----a-w- C:\Program Files\Java\jre7\bin\klist.exe
2014-04-19 09:18:53 FBC892A1196A03F695F112A5EDE032DC 48040 ----a-w- C:\Program Files\Java\jre7\bin\jabswitch.exe
2014-04-19 09:18:53 C38B939945B2357D56B105C8F8FE7C45 52648 ----a-w- C:\Program Files\Java\jre7\bin\jp2launcher.exe
2014-04-19 09:18:53 9533FE0A942E00114047140B42DF8E3D 175016 ----a-w- C:\Program Files\Java\jre7\bin\java.exe
2014-04-19 09:18:53 6EA69D2312F3571F6F8BEADD224165E8 264616 ----a-w- C:\Program Files\Java\jre7\bin\javaws.exe
2014-04-19 09:18:53 58B60ED489B1EDFA2BCDCAAF90B5EDD8 16296 ----a-w- C:\Program Files\Java\jre7\bin\java-rmi.exe
2014-04-19 09:18:53 37C15684482B4D596316735DCEEE939A 175528 ----a-w- C:\Program Files\Java\jre7\bin\javaw.exe
2014-04-19 09:18:53 00F5108D91D768CA9D4ABC5E5053F50F 68008 ----a-w- C:\Program Files\Java\jre7\bin\javacpl.exe
2014-04-18 11:19:10 52BCBC66FBBD96A34E44F02152369A36 204288 ----a-w- C:\Program Files\JDownloader\tools\Windows\unrarw32\unrar.exe
2014-04-18 11:19:10 06ED7467CC20894D6CC41B3E1D2DC11A 28077 ----a-w- C:\Program Files\JDownloader\.install4j\i4jdel.exe
2014-04-18 11:19:09 E8A1C695DDE33CD65B47D78602DA0220 399864 ----a-w- C:\Program Files\JDownloader\tools\Windows\kikin\kikin_installer.exe
2014-04-18 11:19:08 CB5D1AD8C3F3770F75AE59915025F212 12800 ----a-w- C:\Program Files\JDownloader\plugins\jdshutdown\windows\shutdown.exe
2014-04-18 11:18:43 E6D11BA458CD9146F6763259F9D59F97 218816 ----a-w- C:\Program Files\JDownloader\JDownloaderBETA.exe
2014-04-18 11:18:43 DC75715A9C20EC7336DA7BFA8D18251A 219264 ----a-w- C:\Program Files\JDownloader\JDownloaderPortable.exe
2014-04-18 11:18:43 776F36BFDEBC0F6D2DBE88AA5196B9DA 218816 ----a-w- C:\Program Files\JDownloader\JDownloaderD3D.exe
2014-04-18 11:18:42 5EF0842E24B018CE45EE73DCB505CFDE 343168 ----a-w- C:\Program Files\JDownloader\JDUninstall.exe
2014-04-18 11:18:42 5061F57926D36662E4B139D2282D79D0 214528 ----a-w- C:\Program Files\JDownloader\JDownloader.exe
2014-04-18 11:18:42 1A4AF1055C256611CEFD2FE3730EBCB6 646272 ----a-w- C:\Program Files\JDownloader\JDUpdate.exe
2014-04-17 19:31:41 F972DDD19A10F53D74021DDEAC07CCA6 470016 ----a-w- C:\Program Files\Internet Explorer\ieinstal.exe
2014-04-17 19:31:41 BEA4E0C0BA936E8A3DB24D1A37BF70BE 222720 ----a-w- C:\Program Files\Internet Explorer\ielowutil.exe
2014-04-17 19:31:40 0667ED9F8E905E1F73DB60ACCEDCBCA7 811728 ----a-w- C:\Program Files\Internet Explorer\iexplore.exe
2014-04-14 16:11:31 5547AB584CA80A42F1A0CFC6405D0EE7 37003992 ----a-w- C:\Program Files\Google\Update\Install\{4137CA66-EDF6-4EC5-9430-6CC67416D370}\34.0.1847.116_chrome_installer.exe
2014-04-14 16:11:31 5547AB584CA80A42F1A0CFC6405D0EE7 37003992 ----a-w- C:\Program Files\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\34.0.1847.116\34.0.1847.116_chrome_installer.exe
=== C: other files ==
2014-04-19 09:18:55 D95F1D4129F0CB2F7626CDCBAC2F512B 18636 ----a-w- C:\Program Files\Java\jre7\lib\deploy\ffjcext.zip
2014-04-18 11:30:05 298F2F5D23EA768DB31853CDA571FA93 25980 ----a-w- C:\Program Files\JDownloader\backup\database.zip
2014-04-18 11:21:14 C418651AC19F6281761BD1E32D7DCA09 73659 ----a-w- C:\Program Files\JDownloader\tmp\update.zip
2014-04-18 11:19:10 8A60A14AA845102D0D3C681077FC48AD 322940 ----a-w- C:\Program Files\JDownloader\tools\flashgot.xpi
2014-04-18 11:19:10 40BE927F5CE407EFF91EF302911AA4EE 66 ----a-w- C:\Program Files\JDownloader\windows_restore.bat

==== Startup Registry Enabled ======================

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"

[HKEY_USERS\S-1-5-21-3498601666-3105869778-635197538-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"NUSB3MON"="C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
"AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvastUI.exe /nogui"
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe MSRun"
"AtherosBtStack"="C:\Program Files\Dell Wireless\Bluetooth Suite\btvstack.exe"
"AthBtTray"="C:\Program Files\Dell Wireless\Bluetooth Suite\athbttray.exe"
"IgfxTray"="C:\Windows\system32\igfxtray.exe"
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe"
"Persistence"="C:\Windows\system32\igfxpers.exe"
"SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe"
"TkBellExe"="C:\Program Files\Real\RealPlayer\update\realsched.exe -osboot"
"SysTrayApp"="C:\Program Files\IDT\WDM\sttray.exe"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="c:\\progra~1\\sw-boo~1\\assist~1.dll"

==== Startup Registry Disabled ======================

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe ARM]
"key"="Software\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Adobe ARM"
"command"="\"C:\\Program Files\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\""
"hkey"="HKLM"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Google Update]
"key"="Software\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Google Update"
"hkey"="HKCU"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NokiaMServer]
"key"="Software\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NokiaMServer"
"command"="C:\\Program Files\\Common Files\\Nokia\\MPlatform\\NokiaMServer /watchfiles startup"
"hkey"="HKLM"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Sidebar]
"key"="Software\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Sidebar"
"command"="C:\\Program Files\\Windows Sidebar\\sidebar.exe /autoRun"
"hkey"="HKCU"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TkBellExe]
"key"="Software\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="TkBellExe"
"command"="\"C:\\Program Files\\Real\\RealPlayer\\update\\realsched.exe\" -osboot"
"hkey"="HKLM"


==== Task Scheduler Jobs ======================

C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [13.04.2014 12:04]
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [26.09.2012 23:08]
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [26.09.2012 23:08]
C:\Windows\tasks\ReclaimerUpdateFiles_Miroslav Maričić.job [Undetermined Task]
C:\Windows\tasks\ReclaimerUpdateXML_Miroslav Maričić.job [Undetermined Task]
C:\Windows\tasks\RNUpgradeHelperLogonPrompt_Miroslav Maričić.job [Undetermined Task]

==== Other Scheduled Tasks ======================

"C:\Windows\system32\tasks\Adobe Flash Player Updater" [C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe]
"C:\Windows\system32\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"]
"C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files\Google\Update\GoogleUpdate.exe]
"C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files\Google\Update\GoogleUpdate.exe]
"C:\Windows\system32\tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-3498601666-3105869778-635197538-1000" [C:\Program Files\RealNetworks\RealDownloader\recordingmanager.exe]
"C:\Windows\system32\tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3498601666-3105869778-635197538-1000" [C:\Program Files\Real\RealUpgrade\RealUpgrade.exe]
"C:\Windows\system32\tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3498601666-3105869778-635197538-1000" [C:\Program Files\Real\RealUpgrade\RealUpgrade.exe]
"C:\Windows\system32\tasks\RealUpgradeLogonTaskS-1-5-21-3498601666-3105869778-635197538-1000" [C:\Program Files\Real\RealUpgrade\RealUpgrade.exe]
"C:\Windows\system32\tasks\RealUpgradeScheduledTaskS-1-5-21-3498601666-3105869778-635197538-1000" [C:\Program Files\Real\RealUpgrade\RealUpgrade.exe]
"C:\Windows\system32\tasks\SlimCleaner Run" ["C:\Program Files\SlimCleaner\SlimCleaner.exe"]
"C:\Windows\system32\tasks\{2ADD5E33-801B-4EBC-B984-529BE0466008}" [C:\Programi\Jezici\Alaska\XPPW32\BIN\Arc.exe]
"C:\Windows\system32\tasks\{332DC545-726A-441B-A2DB-F346118D3FC2}" [C:\Programi\Jezici\Alaska\XPPW32\BIN\XppFilt.EXE]
"C:\Windows\system32\tasks\{4093A2EB-5C61-461D-86BB-F2261AF7B52C}" [C:\Programi\PROJEKTI\Algoritmi\TSP\tsp.exe]
"C:\Windows\system32\tasks\{54F2A7B8-05BC-4494-B1B3-0CDB5CA9F2F6}" [C:\Programi\Jezici\Alaska\XPPW32\BIN\Xpp.exe]
"C:\Windows\system32\tasks\{5D15118E-9B9D-4A5C-AD2A-7561E0D098D1}" ["c:\program files\opera\opera.exe"]
"C:\Windows\system32\tasks\{68C67A20-6FC3-4B37-81E3-E93175E0B7FA}" [C:\Programi\Jezici\Alaska\XPPW32\BIN\Pbuild.EXE]
"C:\Windows\system32\tasks\{6904DEDD-231B-43C1-A68B-31FB2B1A7584}" [C:\Programi\Jezici\Alaska\XPPW32\BIN\XppDbg.exe]
"C:\Windows\system32\tasks\{764B25A4-81D3-49D8-B241-2D2973B9E7C3}" [C:\Program Files\GIMP-2.0\bin\gimp-2.6.exe]
"C:\Windows\system32\tasks\{765060FB-D18B-4BDA-8F8F-E3E30C96D678}" [C:\Programi\PROJEKTI\HMG\ResHVGUI\Bmps\MWICON25.EXE]
"C:\Windows\system32\tasks\{81FD884D-C745-434D-B17B-9D2B2BF7763C}" [C:\Programi\PROJEKTI\Algoritmi\TSP\tsp.exe]
"C:\Windows\system32\tasks\{A9816D0B-F3DC-429F-9A9B-9426A37136BD}" [C:\Programi\Jezici\Alaska\XPPW32\BIN\Alink.exe]
"C:\Windows\system32\tasks\{B2A6FE0D-2220-42C9-AB27-BD5E51CC7187}" [C:\Programi\PROJEKTI\Harbour\Matica-Programi-H30\wmkd.exe]
"C:\Windows\system32\tasks\{BB98CBA7-65B1-4AA2-B3B4-90BFA5C92ABF}" [C:\Program Files\GIMP-2.0\bin\gimp-2.6.exe]
"C:\Windows\system32\tasks\{C6950D72-11E1-4068-A477-9465BBE44BBE}" [C:\Programi\Jezici\Alaska\XPPW32\BIN\XppLoad.exe]
"C:\Windows\system32\tasks\{E0B68EC0-958D-4899-8423-FBE7EB74288E}" [C:\Program Files\GIMP-2.0\bin\gimp-2.6.exe]
"C:\Windows\system32\tasks\{F939B1B8-8D56-4EF7-8899-960CD5122F8D}" [C:\Programi\PROJEKTI\xBASE\Posebni\LET_EAN2\LET.EXE]
"C:\Windows\system32\tasks\{FE39E993-87C7-43C9-A5F2-537034738701}" [C:\Programi\Jezici\Alaska\XPPW32\BIN\Aimplib.EXE]

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [27.03.2014 14:00]

==== Firefox Extensions ======================

ProfilePath: C:\Users\MIROSL~1\AppData\Roaming\Mozilla\Firefox\Profiles\rlwtyu0w.default
- Undetermined - C:\Program Files\MediaWatchV1\MediaWatchV1home204\ff
- avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF

AppDir: C:\Program Files\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================


==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
eikpkhnhbjejemjdjmjhejjapheohifn - C:\ProgramData\SaveAs\eikpkhnhbjejemjdjmjhejjapheohifn.crx[]
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[27.03.2014 14:00]
idhngdhcfkoamngbedgpaokgjbnpdiji - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx[16.04.2013 03:11]
mmifolfpllfdhilecpdpmemhelmanajl - C:\Program Files\BetterSurf\BetterSurfPlus\ch\BetterSurfPlus.crx[]
njmgejnkdjickfecblhoonofmllpbeio - C:\Program Files\VideoPlayerV3\VideoPlayerV3beta225\ch\VideoPlayerV3beta225.crx[]
nlnpeikkfghdebckenimjmncbbjgjcii - C:\Program Files\MediaWatchV1\MediaWatchV1home204\ch\MediaWatchV1home204.crx[]

SaveAs - MIROSL~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\eikpkhnhbjejemjdjmjhejjapheohifn
DiGiCaooupOen - MIROSL~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmledjoedknmjocpklhijhohcjkjbioe
avast Online Security - MIROSL~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
RealDownloader - MIROSL~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji
Skype Click to Call - MIROSL~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
Better Surf Plus - MIROSL~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmifolfpllfdhilecpdpmemhelmanajl
Video Player - MIROSL~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\njmgejnkdjickfecblhoonofmllpbeio
Media Watch - MIROSL~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlnpeikkfghdebckenimjmncbbjgjcii
SaveAs - C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\eikpkhnhbjejemjdjmjhejjapheohifn
iVIDI.org plugin - C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\giacfgjdclhnmkacnfbaljbmpnelflol
avast Online Security - C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
RealDownloader - C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji
SaveAs - C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipkcanhopoegobiofndfpgganndnfmfp
Skype Click to Call - C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
Better Surf Plus - C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmifolfpllfdhilecpdpmemhelmanajl
Video Player - C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\njmgejnkdjickfecblhoonofmllpbeio

==== Chrome Fix ======================

C:\Users\MIROSL~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\eikpkhnhbjejemjdjmjhejjapheohifn deleted successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\eikpkhnhbjejemjdjmjhejjapheohifn deleted successfully
C:\Users\MIROSL~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmifolfpllfdhilecpdpmemhelmanajl deleted successfully
C:\Users\MIROSL~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\njmgejnkdjickfecblhoonofmllpbeio deleted successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\njmgejnkdjickfecblhoonofmllpbeio deleted successfully
C:\Users\MIROSL~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlnpeikkfghdebckenimjmncbbjgjcii deleted successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\giacfgjdclhnmkacnfbaljbmpnelflol deleted successfully
C:\Users\MIROSL~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmledjoedknmjocpklhijhohcjkjbioe deleted successfully
C:\Users\MIROSL~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_fmledjoedknmjocpklhijhohcjkjbioe_0.localstorage deleted successfully
C:\Users\MIROSL~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_fmledjoedknmjocpklhijhohcjkjbioe_0.localstorage-journal deleted successfully
C:\Users\MIROSL~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipkcanhopoegobiofndfpgganndnfmfp deleted successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipkcanhopoegobiofndfpgganndnfmfp deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\a263e0a8-2935-4f44-a5fd-aa0dcd98f323 deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{6B502B79-7782-D8EF-4072-43DF466D094C} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\eikpkhnhbjejemjdjmjhejjapheohifn deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\mmifolfpllfdhilecpdpmemhelmanajl deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\njmgejnkdjickfecblhoonofmllpbeio deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\nlnpeikkfghdebckenimjmncbbjgjcii deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Video Player deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update deleted successfully

==== Empty IE Cache ======================

C:\Users\MIROSL~1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\MIROSL~1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

C:\Users\MIROSL~1\AppData\Local\Mozilla\Firefox\Profiles\rlwtyu0w.default\Cache will be emptied at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Mozilla\Firefox\Profiles\5rkz4rjh.default\Cache emptied successfully

==== Empty Chrome Cache ======================

C:\Users\MIROSL~1\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=954 folders=66 40308989 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Guest\AppData\Local\Temp emptied successfully
C:\Users\MIROSL~1\AppData\Local\Temp will be emptied at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\MIROSL~1\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmifolfpllfdhilecpdpmemhelmanajl" deleted

==== EOF on ned 20.04.2014 at 15:36:31,10 ======================

Ево и фајла AdwCleaner[S0].txt:

https://www.mycity.rs/must-login.png

Шта даље?
Позз
П.С.
Нисам испробавао Гугл Кроум (за сваки случај, док ми не кажеш)... Smile

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Ponovo pokreni zoek ;


zatvori browser i ostale pokrenute programe;
deaktiviraj zaštitni softver ( po potrebi ) Uputstvo ;


U beli okvir prozora iskopiraj sledeći tekst:


C:\Windows\tasks\ReclaimerUpdateFiles_Miroslav Maricic.job;f
C:\Windows\tasks\ReclaimerUpdateXML_Miroslav Maricic.job;f
C:\Windows\tasks\RNUpgradeHelperLogonPrompt_Miroslav Maricic.job;f
C:\Program Files\MediaWatchV1;fs
eikpkhnhbjejemjdjmjhejjapheohifn;chr
mmifolfpllfdhilecpdpmemhelmanajl;chr
njmgejnkdjickfecblhoonofmllpbeio;chr
nlnpeikkfghdebckenimjmncbbjgjcii;chr
fmledjoedknmjocpklhijhohcjkjbioe;chr
lifbcibllhkdhoafpjfnlhfpfgnpldfl;chr
giacfgjdclhnmkacnfbaljbmpnelflol;chr
ipkcanhopoegobiofndfpgganndnfmfp;chr
C:\ProgramData\SaveAs;fs
emptyalltemp;
autoclean;
emptyclsid;





Klikni na dugme i pričekaj da se skeniranje završi.


zoek ce po potrebi, restartovati Windows a na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.

Napomena:Izveštaj će biti sačuvan pod nazivom zoek-results.log na sistemskoj particiji (tipična lokacija: C:\zoek-results.log)


Arrow Kopiraj sadrzaj tog loga u poruku.

offline
  • Miroslav R. Maričić
  • diplomirani inženjer mašinstva, profesor
  • Pridružio: 06 Jun 2012
  • Poruke: 229
  • Gde živiš: Hajdučica, Banat, Srbija

Извештај zoek-results.log, други пут:

Zoek.exe v5.0.0.0 Updated 14-April-2014
Tool run by Miroslav Mariźi† on ned 20.04.2014 at 17:55:35,58.
Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Download\Zoek\zoek.exe [Scan all users] [Script inserted]

==== Older Logs ======================

C:\zoek-results2014-04-20-133631.log 41832 bytes

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== Deleting Files \ Folders ======================

C:\Program Files\MediaWatchV1 not found
C:\ProgramData\SaveAs not found
C:\Users\Miroslav Maričić\pkcs11wrapper_32.dll not found
C:\Users\Miroslav Maričić\Downloads\iLividSetup_C-r477-t-bc.exe not found
"C:\Windows\tasks\ReclaimerUpdateFiles_Miroslav Maricic.job" not found
"C:\Windows\tasks\ReclaimerUpdateXML_Miroslav Maricic.job" not found
"C:\Windows\tasks\RNUpgradeHelperLogonPrompt_Miroslav Maricic.job" not found
"C:\Users\Miroslav Maričić\AppData\Roaming" not found

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [27.03.2014 14:00]

==== Firefox Extensions ======================

ProfilePath: C:\Users\MIROSL~1\AppData\Roaming\Mozilla\Firefox\Profiles\rlwtyu0w.default
- Undetermined - C:\Program Files\MediaWatchV1\MediaWatchV1home204\ff
- avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF

AppDir: C:\Program Files\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================


==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[27.03.2014 14:00]
idhngdhcfkoamngbedgpaokgjbnpdiji - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx[16.04.2013 03:11]

Google Docs - MIROSL~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake
Google Drive - MIROSL~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf
YouTube - MIROSL~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
Google Search - MIROSL~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
avast Online Security - MIROSL~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
RealDownloader - MIROSL~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji
Skype Click to Call - MIROSL~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
Google Wallet - MIROSL~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Gmail - MIROSL~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
Google Docs - C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake
Google Drive - C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf
YouTube - C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
Google Search - C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
avast Online Security - C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
RealDownloader - C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji
Skype Click to Call - C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
Google Wallet - C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Gmail - C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia

==== Chrome Fix ======================

C:\Users\MIROSL~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl deleted successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"

==== Empty IE Cache ======================

C:\Users\MIROSL~1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\MIROSL~1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

C:\Users\MIROSL~1\AppData\Local\Mozilla\Firefox\Profiles\rlwtyu0w.default\Cache emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Mozilla\Firefox\Profiles\5rkz4rjh.default\Cache emptied successfully

==== Empty Chrome Cache ======================

C:\Users\MIROSL~1\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=1007 folders=70 40798122 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Guest\AppData\Local\Temp emptied successfully
C:\Users\MIROSL~1\AppData\Local\Temp will be emptied at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\MIROSL~1\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on ned 20.04.2014 at 18:22:31,76 ======================

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Kazi mi kakvo je stanje sada?

offline
  • Miroslav R. Maričić
  • diplomirani inženjer mašinstva, profesor
  • Pridružio: 06 Jun 2012
  • Poruke: 229
  • Gde živiš: Hajdučica, Banat, Srbija

Испробао сам Гугл Кроум и сада је све у реду! Нема више нежељених искачућих прозора, а и браузер се много брже подиже него пре. Како да трајно одржим ово стање?
Хвала ! Ziveli

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Nista specijalno, samo pazi kod instalacije programa da rascekiras toolbare koji se nude uz instalaciju.

Procitaj ovu temu.
http://www.mycity.rs/Zastita/Kako-izbeci-i-ukloniti-toolbar-ove.html



Preporucujem ti da instaliras AdBlock Plus za Chrome, brze ce da se otvara i neces videti popup reklame.

https://chrome.google.com/webstore/detail/adblock-.....cddilifddb






Sledeća procedura će implementirati završno čišćenje.

Arrow Preuzmi "Xplode"-ov DelFix alat i snimi ga na Desktop.
Dvoklikom pokreni alat i štikliraj kućice ispred sledećih opcija;

Remove disinfection tools
Create registry backup
Purge System Restore


Klikni na dugme Run i pričekaj trenutak dok alat ne završi svoj rad.
Od ovog trenutka, svi korišćeni alati u ovoj temi bi trebali biti obrisani.
Alat će takođe formirati izveštaj za tebe. (C:\DelFix.txt)

Alat će snimiti i zdravo stanje registy-ja i napraviti backup koristeci integrisan program "ERUNT" u %windir%\ERUNT\DelFix
Alat briše stare system restore tačke i pravi novu, svežu tačku nakon čišćenja.

Ko je trenutno na forumu
 

Ukupno su 915 korisnika na forumu :: 47 registrovanih, 9 sakrivenih i 859 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., amaterSRB, Apok, Areal84, Ben Roj, Bokiboks, Boris BM, ccoogg123, CikaKURE, Djokislav, DonRumataEstorski, Excalibur13, FileFinder, Frunze, Georgius, grenadir, hatman, hologram, hooraay, ILGromovnik, JOntra, krkalon, kunktator, loon123, Lošmi, Luka Blažević, mercedesamg, Mercury, Mi lao shu, milutin134, MiroslavD, Petar35, repac, Romibrat, rovac, Skywhaler, slonic_tonic, Smiljke, Srle993, stegonosa, Sumadija34, TITAN DUDIN JARAN, Trpe Grozni, vladaa012, yrraf, zeo, ZetaMan