Problem vk umesto fb

Problem vk umesto fb

offline
  • Nenad Arsic
  • Pridružio: 02 Jul 2012
  • Poruke: 3
  • Gde živiš: Krusevac

Pozdrav,
Javlja mi se problem da ne mogu sa laptopa da udjem na fb, pojavljuje mi se vk, cak neki put nece ni stranu za kucanje e-maila i lozinke da mi otvori.Nadam se da mi mozete pomoci.

Ako sam dobro razumeo uradio sam ovo:

OTL logfile created on: 7/6/2012 11:57:25 PM - Run 1
OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\korisnik\Downloads
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.75 Gb Total Physical Memory | 0.92 Gb Available Physical Memory | 33.41% Memory free
5.49 Gb Paging File | 3.20 Gb Available in Paging File | 58.27% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 48.73 Gb Total Space | 8.70 Gb Free Space | 17.85% Space Free | Partition Type: NTFS
Drive D: | 249.26 Gb Total Space | 70.23 Gb Free Space | 28.17% Space Free | Partition Type: NTFS

Computer Name: NENAD-PC | User Name: korisnik | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/07/06 23:56:43 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\korisnik\Downloads\OTL.exe
PRC - [2012/07/06 21:01:02 | 001,022,352 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files (x86)\uTorrent\uTorrent.exe
PRC - [2012/07/06 20:43:12 | 000,554,176 | ---- | M] () -- C:\ProgramData\IBUpdaterService\ibsvc.exe
PRC - [2012/04/12 09:27:54 | 003,731,112 | ---- | M] (Gretech Corp.) -- C:\Program Files (x86)\GRETECH\GomPlayer\GOM.exe
PRC - [2011/11/15 05:50:22 | 000,312,376 | ---- | M] (Power Software Ltd) -- D:\Programi\PowerISO\PWRISOVM.EXE
PRC - [2011/03/17 10:15:46 | 000,382,272 | ---- | M] (DT Soft Ltd) -- D:\Programi\DAEMON Tools Pro\DTShellHlp.exe
PRC - [2011/03/17 10:15:04 | 000,842,048 | ---- | M] (DT Soft Ltd) -- D:\Programi\DAEMON Tools Pro\DTAgent.exe


========== Modules (No Company Name) ==========

MOD - [2012/06/28 12:28:56 | 000,438,296 | ---- | M] () -- C:\Users\korisnik\AppData\Local\Google\Chrome\Application\20.0.1132.47\ppGoogleNaClPluginChrome.dll
MOD - [2012/06/28 12:28:54 | 003,972,120 | ---- | M] () -- C:\Users\korisnik\AppData\Local\Google\Chrome\Application\20.0.1132.47\pdf.dll
MOD - [2012/06/28 12:27:40 | 000,554,520 | ---- | M] () -- C:\Users\korisnik\AppData\Local\Google\Chrome\Application\20.0.1132.47\libglesv2.dll
MOD - [2012/06/28 12:27:38 | 000,117,784 | ---- | M] () -- C:\Users\korisnik\AppData\Local\Google\Chrome\Application\20.0.1132.47\libegl.dll
MOD - [2012/06/28 12:27:29 | 000,140,328 | ---- | M] () -- C:\Users\korisnik\AppData\Local\Google\Chrome\Application\20.0.1132.47\avutil-51.dll
MOD - [2012/06/28 12:27:28 | 000,262,184 | ---- | M] () -- C:\Users\korisnik\AppData\Local\Google\Chrome\Application\20.0.1132.47\avformat-54.dll
MOD - [2012/06/28 12:27:26 | 002,386,984 | ---- | M] () -- C:\Users\korisnik\AppData\Local\Google\Chrome\Application\20.0.1132.47\avcodec-54.dll
MOD - [2012/06/28 10:27:26 | 009,252,040 | ---- | M] () -- C:\Users\korisnik\AppData\Local\Google\Chrome\Application\20.0.1132.47\gcswf32.dll
MOD - [2012/06/28 10:27:26 | 009,252,040 | ---- | M] () -- C:\Users\korisnik\AppData\Local\Google\Chrome\APPLIC~1\200113~1.47\gcswf32.dll
MOD - [2012/04/02 10:46:18 | 000,946,176 | ---- | M] () -- C:\Program Files (x86)\GRETECH\GomPlayer\GSFU.ax
MOD - [2011/09/08 11:03:56 | 000,594,944 | ---- | M] () -- C:\Program Files (x86)\GRETECH\GomPlayer\GVF.ax
MOD - [2011/08/03 06:31:02 | 003,373,568 | ---- | M] () -- C:\Program Files (x86)\GRETECH\GomPlayer\libavcodec.dll
MOD - [2011/08/03 06:31:02 | 000,184,320 | ---- | M] () -- C:\Program Files (x86)\GRETECH\GomPlayer\GRFU.ax
MOD - [2011/05/17 02:49:30 | 000,421,520 | ---- | M] () -- C:\Program Files (x86)\GRETECH\GomPlayer\GomTVStrm.dll
MOD - [2010/10/15 11:35:54 | 001,433,600 | ---- | M] () -- C:\Program Files (x86)\GRETECH\GomPlayer\GAF.ax
MOD - [2009/08/11 21:21:20 | 001,021,440 | ---- | M] () -- C:\Program Files (x86)\AC3Filter\ac3filter_intl.dll
MOD - [2009/08/11 21:19:04 | 000,797,184 | ---- | M] () -- C:\Program Files (x86)\AC3Filter\ac3filter.ax
MOD - [2009/04/29 14:51:32 | 003,300,864 | ---- | M] () -- C:\Program Files (x86)\K-Lite Codec Pack\ffdshow\ffdshow.ax
MOD - [2009/03/02 17:18:18 | 000,486,400 | ---- | M] () -- C:\Program Files (x86)\K-Lite Codec Pack\ffdshow\ff_libfaad2.dll
MOD - [2005/02/03 06:46:26 | 000,425,984 | ---- | M] () -- C:\Windows\SysWOW64\CoreAAC.ax


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2010/06/17 22:10:14 | 000,258,048 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Program Files\IDT\WDM\stacsv64.exe -- (STacSV)
SRV:64bit: - [2010/03/23 22:12:30 | 000,202,752 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2010/02/02 14:13:10 | 000,048,128 | ---- | M] (Dell Inc.) [Auto | Running] -- C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE -- (wltrysvc)
SRV:64bit: - [2009/07/14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV:64bit: - [2009/03/03 03:42:58 | 000,089,600 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Program Files\IDT\WDM\AESTSr64.exe -- (AESTFilters)
SRV - [2012/07/06 20:43:12 | 000,554,176 | ---- | M] () [Auto | Running] -- C:\ProgramData\IBUpdaterService\ibsvc.exe -- (IBUpdaterService)
SRV - [2009/06/10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/01/05 18:04:29 | 000,272,448 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2011/11/15 05:50:14 | 000,125,376 | ---- | M] (Power Software Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\scdemu.sys -- (SCDEmu)
DRV:64bit: - [2011/07/20 16:12:38 | 000,123,784 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2011/07/20 16:12:38 | 000,088,288 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2010/06/17 22:10:14 | 000,515,584 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\stwrt64.sys -- (STHDA)
DRV:64bit: - [2010/06/17 16:09:00 | 000,118,016 | ---- | M] (TCT International Mobile Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\qcusbser.sys -- (qcusbser)
DRV:64bit: - [2010/03/23 22:42:50 | 006,654,976 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2010/03/23 21:23:52 | 000,195,584 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2010/03/09 06:21:42 | 000,123,408 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:64bit: - [2010/02/02 14:13:08 | 000,022,520 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\bcm42rly.sys -- (BCM42RLY)
DRV:64bit: - [2010/02/02 14:13:08 | 000,020,984 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\bcmvwl64.sys -- (BcmVWL)
DRV:64bit: - [2010/02/02 14:13:06 | 003,058,168 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2009/07/14 03:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009/07/14 03:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009/07/14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 03:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/07/14 03:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2009/07/14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/14 02:10:47 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rootmdm.sys -- (ROOTMODEM)
DRV:64bit: - [2009/06/10 22:35:42 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009/06/10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/05/05 10:00:28 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie.sys -- (AtiPcie) AMD PCI Express (3GIO)
DRV:64bit: - [2007/05/11 04:12:06 | 000,038,160 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\blueletaudio.sys -- (BlueletAudio)
DRV:64bit: - [2007/05/09 03:00:58 | 000,044,688 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btcusb.sys -- (Btcsrusb)
DRV:64bit: - [2007/03/05 06:48:12 | 000,037,648 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BlueletSCOAudio.sys -- (BlueletSCOAudio)
DRV:64bit: - [2007/03/05 06:47:08 | 000,025,360 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BtNetDrv.sys -- (BT)
DRV:64bit: - [2007/03/05 06:42:54 | 000,049,680 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\BTHidMgr.sys -- (BTHidMgr)
DRV:64bit: - [2007/03/05 06:41:34 | 000,024,976 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\VBTEnum.sys -- (BTHidEnum)
DRV:64bit: - [2007/03/05 06:39:28 | 000,063,248 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VcommMgr.sys -- (VcommMgr)
DRV:64bit: - [2007/03/05 06:38:20 | 000,047,120 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VComm.sys -- (VComm)
DRV - [2009/07/14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2007/05/11 04:12:06 | 000,038,160 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\blueletaudio.sys -- (BlueletAudio)
DRV - [2007/05/09 03:00:58 | 000,044,688 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\btcusb.sys -- (Btcsrusb)
DRV - [2007/03/05 06:48:12 | 000,037,648 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\BlueletSCOAudio.sys -- (BlueletSCOAudio)
DRV - [2007/03/05 06:47:08 | 000,025,360 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\btnetdrv.sys -- (BT)
DRV - [2007/03/05 06:42:54 | 000,049,680 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\Windows\SysWOW64\drivers\BtHidMgr.sys -- (BTHidMgr)
DRV - [2007/03/05 06:41:34 | 000,024,976 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\Windows\SysWOW64\drivers\VBTEnum.sys -- (BTHidEnum)
DRV - [2007/03/05 06:39:28 | 000,063,248 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\VCommMgr.sys -- (VcommMgr)
DRV - [2007/03/05 06:38:20 | 000,047,120 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\VComm.sys -- (VComm)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = searchqu.com/web?src=ieb&appid=101&.....r=0&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = search.my-tools-app.com/?babsrc=home&s=web&as=0&isid=9852
IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{64D2EE47-5823-45C4-9732-B95F94E70E99}: "URL" = startsear.ch/?aff=1&src=sp&cf=ac61d.....903&q={searchTerms}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = searchqu.com/web?src=ieb&appid=101&.....r=0&q={searchTerms}
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2786678
IE - HKLM\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = search.my-tools-app.com/?babsrc=home&s=.....852&q={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = search.conduit.com?SearchSource=10&ctid=CT2786678
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 9E CA 98 E6 9C 46 CC 01 [binary data]
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - No CLSID value found
IE - HKCU\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {CAADDA30-EC3B-4A5B-82E4-79035C4B5E20}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = search.babylon.com/?q={searchTerms}&AF=109130&babsrc=SP_ss&mntrId=3cd1184600000000000068a3c4728380
IE - HKCU\..\SearchScopes\{64D2EE47-5823-45C4-9732-B95F94E70E99}: "URL" = startsear.ch/?aff=1&src=sp&cf=ac61d.....903&q={searchTerms}
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = searchqu.com/web?src=ieb&appid=101&.....r=0&q={searchTerms}
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2786678
IE - HKCU\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = search.my-tools-app.com/?babsrc=home&s=.....852&q={searchTerms}
IE - HKCU\..\SearchScopes\{CAADDA30-EC3B-4A5B-82E4-79035C4B5E20}: "URL" = search.yahoo.com/search?fr=chr-greentree_ie.....811&p={searchTerms}
IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = mystart.incredibar.com/mb119/?search={searchTerms}&loc=IB_DS&a=6R8lJTTlvm&i=26
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Web Search"
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaultthis.engineName: "uTorrentBar Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "MyTools"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&ilc=12&type=937811"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: "http://mystart.incredibar.com/mb119?a=6R8lJTTlvm&i=26"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}:6.0.25
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.5.0.7896
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: ifamebook@stormvision.it:2.60
FF - prefs.js..extensions.enabledItems: wtxpcom@mybrowserbar.com:5.8
FF - prefs.js..extensions.enabledItems: youtubedownloader@mybrowserbar.com:5.8
FF - prefs.js..extensions.enabledItems: support@2yourface.com:1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}:6.0.27
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:3.6.0.10
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29
FF - prefs.js..extensions.enabledItems: {3697b17c-b572-4862-a5e6-7f922c0f3403}:1.1
FF - prefs.js..extensions.enabledItems: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}:3.8.1.0
FF - prefs.js..extensions.enabledItems: {EEE6C361-6118-11DC-9C72-001320C79847}:1.3.0.1
FF - prefs.js..extensions.enabledItems: ffxtlbr@babylon.com:1.2.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}:6.0.31
FF - prefs.js..extensions.enabledItems: ffxtlbr@incredibar.com:1.5.0
FF - prefs.js..extensions.enabledItems: info@bflix.info:5.0
FF - prefs.js..extensions.enabledItems: info@wxdownloadmanager.com:1.0
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=937811&p="
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: ""


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.4.1: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.4.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: D:\Programi\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: D:\Programi\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\korisnik\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\korisnik\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\info@bflix.info: C:\Users\korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\l51p0z1p.default\extensions\info@bflix.info [2012/03/03 23:45:44 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\info@wxdownloadmanager.com: C:\Users\korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\l51p0z1p.default\extensions\info@wxdownloadmanager.com [2012/03/25 18:42:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.28\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/03/16 10:49:33 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.28\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/07/06 21:02:15 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\support@2yourface.com: C:\Program Files (x86)\2YourFace\2YourFace.xpi

[2012/04/08 20:54:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\korisnik\AppData\Roaming\mozilla\Extensions
[2011/08/07 22:04:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\extensions
[2011/08/07 22:04:41 | 000,000,000 | ---D | M] (2YourFace) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\extensions\support@2yourface.com
[2011/12/07 21:57:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\extensions
[2012/07/02 16:40:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\extensions\extensions
[2011/08/07 22:04:41 | 000,000,000 | ---D | M] (2YourFace) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\extensions\support@2yourface.com
[2012/07/02 17:37:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\l51p0z1p.default\extensions
[2012/07/02 17:21:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\l51p0z1p.default\extensions\{3697b17c-b572-4862-a5e6-7f922c0f3403}
[2012/03/02 10:11:44 | 000,000,000 | ---D | M] (Free Lunch Design Toolbar) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\l51p0z1p.default\extensions\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}
[2011/09/25 22:48:07 | 000,000,000 | ---D | M] (Zynga Community Toolbar) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\l51p0z1p.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2011/12/08 04:00:25 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\l51p0z1p.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2011/12/08 04:00:40 | 000,000,000 | ---D | M] (SweetIM Toolbar for Firefox) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\l51p0z1p.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
[2012/03/03 23:46:20 | 000,000,000 | ---D | M] (Incredibar Toolbar) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\l51p0z1p.default\extensions\ffxtlbr@incredibar.com
[2011/07/26 19:48:04 | 000,000,000 | ---D | M] (iFamebook) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\l51p0z1p.default\extensions\ifamebook@stormvision.it
[2012/03/03 23:45:44 | 000,000,000 | ---D | M] (TheBflix) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\l51p0z1p.default\extensions\info@bflix.info
[2012/03/25 18:42:30 | 000,000,000 | ---D | M] (wxDfast) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\l51p0z1p.default\extensions\info@wxdownloadmanager.com
[2012/01/12 13:31:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\l51p0z1p.default\extensions\staged
[2011/08/07 22:04:41 | 000,000,000 | ---D | M] (2YourFace) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\l51p0z1p.default\extensions\support@2yourface.com
[2011/11/30 12:27:50 | 000,000,925 | ---- | M] () -- C:\Users\korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\l51p0z1p.default\searchplugins\conduit.xml
[2012/03/03 23:46:05 | 000,002,203 | ---- | M] () -- C:\Users\korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\l51p0z1p.default\searchplugins\MyStart Search.xml
[2012/01/12 13:31:24 | 000,000,544 | ---- | M] () -- C:\Users\korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\l51p0z1p.default\searchplugins\MyTools.xml
[2011/08/15 17:49:56 | 000,002,506 | ---- | M] () -- C:\Users\korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\l51p0z1p.default\searchplugins\SearchResults.xml
[2011/07/11 20:04:02 | 000,000,633 | ---- | M] () -- C:\Users\korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\l51p0z1p.default\searchplugins\startsear.xml
[2011/12/08 04:00:35 | 000,003,915 | ---- | M] () -- C:\Users\korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\l51p0z1p.default\searchplugins\sweetim.xml
[2012/07/06 20:56:38 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/07/20 14:56:40 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
[2011/07/26 14:21:12 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/08/31 20:49:19 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
[2011/11/04 12:09:20 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2012/04/28 00:32:14 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
[2012/01/07 16:09:31 | 000,000,000 | ---D | M] (Babylon) -- C:\Program Files (x86)\Mozilla Firefox\extensions\ffxtlbr@babylon.com
File not found (No name found) -- C:\PROGRAM FILES (X86)\COMMON FILES\SPIGOT\WTXPCOM
File not found (No name found) -- C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\EXTENSIONS\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
File not found (No name found) -- C:\PROGRAM FILES (X86)\YOUTUBE DOWNLOADER TOOLBAR\FF
[2012/01/07 16:13:56 | 000,002,310 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2011/08/15 17:49:56 | 000,002,506 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\SearchResults.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms},
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\korisnik\AppData\Local\Google\Chrome\Application\20.0.1132.47\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\korisnik\AppData\Local\Google\Chrome\Application\20.0.1132.47\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\korisnik\AppData\Local\Google\Chrome\Application\20.0.1132.47\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: vShare.tv plug-in (Enabled) = C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0\chvsharetvplg.dll
CHR - plugin: vShare.tv plug-in (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npvsharetvplg.dll
CHR - plugin: Skype Toolbars (Enabled) = C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.5.0.7896_0\npSkypeChromePlugin.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFFICE.DLL
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 7 U4 (Enabled) = C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 7.0.40.255 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Veetle TV Player (Enabled) = D:\Programi\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Enabled) = D:\Programi\Veetle\plugins\npVeetle.dll
CHR - Extension: YouTube = C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: TheBflix = C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjakmojkcnhgipgkkbiempkfdndcnlah\5.0_0\
CHR - Extension: Bflix extension = C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlfihafpijfdgmojeeigcldgchhojpfp\1.0_0\
CHR - Extension: wxDfast = C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\opnkkfjdnhgkjefnnohgfackfninikjo\1.0_0\
CHR - Extension: Gmail = C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/07/03 19:33:48 | 000,202,984 | -H-- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 facebook.com
O1 - Hosts: 127.0.0.1 facebook.com
O1 - Hosts: 127.0.0.1 af-za.facebook.com
O1 - Hosts: 127.0.0.1 az-az.facebook.com
O1 - Hosts: 127.0.0.1 id-id.facebook.com
O1 - Hosts: 127.0.0.1 ms-my.facebook.com
O1 - Hosts: 127.0.0.1 bs-ba.facebook.com
O1 - Hosts: 127.0.0.1 ca-es.facebook.com
O1 - Hosts: 127.0.0.1 cs-cz.facebook.com
O1 - Hosts: 127.0.0.1 cy-gb.facebook.com
O1 - Hosts: 127.0.0.1 da-dk.facebook.com
O1 - Hosts: 127.0.0.1 de-de.facebook.com
O1 - Hosts: 127.0.0.1 et-ee.facebook.com
O1 - Hosts: 127.0.0.1 en-gb.facebook.com
O1 - Hosts: 127.0.0.1 es-la.facebook.com
O1 - Hosts: 127.0.0.1 eo-eo.facebook.com
O1 - Hosts: 127.0.0.1 eu-es.facebook.com
O1 - Hosts: 127.0.0.1 tl-ph.facebook.com
O1 - Hosts: 127.0.0.1 fo-fo.facebook.com
O1 - Hosts: 127.0.0.1 fr-fr.facebook.com
O1 - Hosts: 127.0.0.1 fy-nl.facebook.com
O1 - Hosts: 127.0.0.1 ga-ie.facebook.com
O1 - Hosts: 127.0.0.1 gl-es.facebook.com
O1 - Hosts: 127.0.0.1 ko-kr.facebook.com
O1 - Hosts: 50053 more lines...
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {0BF33701-0742-4633-475B-0F6E47024F11} - C:\Windows\SysWOW64\ole22disp.dll ()
O2 - BHO: (bflix Class) - {0C9F4179-6CE2-4c6a-A3E5-67FF3592A12E} - C:\Program Files (x86)\BFlix\bflix.dll (bflix)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {1C8E2411-39C6-7832-007B-145D531C735B} - C:\Windows\SysWOW64\webserviices.dll ()
O2 - BHO: (TheBflix Class) - {205A2CCF-257D-4D78-9C7E-7FB38A871B00} - C:\ProgramData\TheBflix\bhoclass.dll (Injector)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {3C3D2E08-5515-6B5B-3342-3A302B0F66FE} - C:\Windows\SysWOW64\nssi.dll ()
O2 - BHO: (Groove GFS Browser Helper) - {44AA6093-09D1-2317-151C-7A5341210AE1} - C:\Windows\SysWOW64\api-ms-win-core-namedpiipe-l1-1-0.dll ()
O2 - BHO: (Adobe PDF Link Helper) - {4BD33AFE-2BC7-2777-4211-51C336FD7D53} - C:\Windows\SysWOW64\onexx.dll ()
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {54007582-298F-21BA-1957-168F2D047DB9} - C:\Windows\SysWOW64\rsaennh.dll ()
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {5C2C3007-2757-1BFD-709D-5B5A230C7E1F} - C:\Windows\SysWOW64\spbccd.dll ()
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (VShareToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files (x86)\vShare.tv plugin\BarLcher.dll File not found
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (VShareToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files (x86)\vShare.tv plugin\BarLcher.dll File not found
O4:64bit: - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE (Dell Inc.)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [ExpressFiles] C:\Program Files (x86)\ExpressFiles\ExpressFiles.exe (http://www.express-files.com/)
O4 - HKLM..\Run: [PWRISOVM.EXE] D:\Programi\PowerISO\PWRISOVM.EXE (Power Software Ltd)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TrojanScanner] D:\Programi\Trojan Remover\Trjscan.exe (Simply Super Software)
O4 - HKCU..\Run: [DAEMON Tools Pro Agent] D:\Programi\DAEMON Tools Pro\DTAgent.exe (DT Soft Ltd)
O4 - HKCU..\Run: [uTorrent] C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O8:64bit: - Extra context menu item: Search the Web - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\menuext.html File not found
O8 - Extra context menu item: Search the Web - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\menuext.html File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 10.4.1)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 10.4.1)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{058C06CA-F7E8-4BEB-93A0-087F039DA386}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{3bbb2882-018c-11e1-8128-782bcbdd6903}\Shell - "" = AutoRun
O33 - MountPoints2\{3bbb2882-018c-11e1-8128-782bcbdd6903}\Shell\AutoRun\command - "" = F:\autorun.exe
O33 - MountPoints2\{c1405420-928d-11e1-89c2-001167b7d3dd}\Shell - "" = AutoRun
O33 - MountPoints2\{c1405420-928d-11e1-89c2-001167b7d3dd}\Shell\AutoRun\command - "" = H:\PcOptions.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/07/06 21:03:46 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2012/07/06 20:44:35 | 000,000,000 | ---D | C] -- C:\Users\korisnik\AppData\Roaming\PerformerSoft
[2012/07/06 20:44:32 | 000,019,000 | ---- | C] (PerformerSoft LLC) -- C:\Windows\SysNative\roboot64.exe
[2012/07/06 20:43:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\I Want This
[2012/07/06 20:43:39 | 000,000,000 | ---D | C] -- C:\Users\korisnik\AppData\Roaming\eType
[2012/07/06 20:43:38 | 000,000,000 | ---D | C] -- C:\ProgramData\IBUpdaterService
[2012/07/03 18:52:20 | 000,000,000 | ---D | C] -- C:\Users\korisnik\Desktop\Downloads
[2012/07/02 17:43:03 | 000,000,000 | ---D | C] -- C:\Users\korisnik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2012/07/02 17:15:12 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\appmgmt
[2012/06/13 16:08:41 | 000,000,000 | ---D | C] -- C:\Users\korisnik\AppData\Roaming\Pole Position 2012
[2012/06/13 16:06:30 | 000,000,000 | ---D | C] -- C:\Users\korisnik\AppData\Roaming\Kalypso Media
[2012/06/13 16:06:28 | 000,000,000 | ---D | C] -- C:\Users\korisnik\AppData\Roaming\.mono
[2012/06/13 16:06:28 | 000,000,000 | ---D | C] -- C:\ProgramData\.mono
[2012/06/08 01:24:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2012/06/08 01:23:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Oracle
[2012/06/08 01:23:17 | 000,772,504 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\npDeployJava1.dll
[2012/06/08 01:23:17 | 000,227,720 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2012/06/08 00:12:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\1ClickDownload
[3 C:\Users\korisnik\Documents\*.tmp files -> C:\Users\korisnik\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/07/06 23:47:00 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/07/06 23:36:00 | 000,000,920 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1535932500-1668178-310031940-1000UA.job
[2012/07/06 22:50:24 | 000,014,192 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/06 22:50:24 | 000,014,192 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/06 22:49:32 | 000,717,892 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/07/06 22:49:32 | 000,618,264 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/07/06 22:49:32 | 000,104,546 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/07/06 22:45:09 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/07/06 22:44:53 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/07/06 22:44:47 | 2211,393,536 | -HS- | M] () -- C:\hiberfil.sys
[2012/07/06 21:01:02 | 000,000,963 | ---- | M] () -- C:\Users\korisnik\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2012/07/06 21:01:02 | 000,000,939 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2012/07/06 13:29:17 | 013,910,941 | ---- | M] () -- C:\Users\korisnik\Documents\Steff Da Campo vs. Rutger Van Gelder - Wasted (In The Morning) (Extended Mix).mp3
[2012/07/06 13:29:16 | 007,503,517 | ---- | M] () -- C:\Users\korisnik\Documents\T-Blazer & Ana Masulovic - Touch the sky ( Official Video HD).mp3
[2012/07/06 13:28:53 | 007,366,045 | ---- | M] () -- C:\Users\korisnik\Documents\IN VIVO ft. Boyant - Moje leto (2012).mp3
[2012/07/06 13:28:36 | 007,561,117 | ---- | M] () -- C:\Users\korisnik\Documents\Afrojack, Dimitri Vegas, Like Mike and NERVO - The Way We See The World (Official Music Video) [HD].mp3
[2012/07/05 11:12:00 | 000,000,370 | ---- | M] () -- C:\Windows\tasks\At8.job
[2012/07/05 11:12:00 | 000,000,368 | ---- | M] () -- C:\Windows\tasks\At4.job
[2012/07/05 11:12:00 | 000,000,358 | ---- | M] () -- C:\Windows\tasks\At11.job
[2012/07/05 11:12:00 | 000,000,352 | ---- | M] () -- C:\Windows\tasks\At13.job
[2012/07/05 11:12:00 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\At6.job
[2012/07/05 11:12:00 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\At2.job
[2012/07/05 11:12:00 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\At10.job
[2012/07/03 19:00:59 | 001,103,649 | ---- | M] () -- C:\Windows\SysNative\drivers\Cat.DB
[2012/07/03 11:19:04 | 017,230,963 | ---- | M] () -- C:\Users\korisnik\Documents\Steff Da Campo vs. Rutger Van Gelder - Wasted (In The Morning) (Extended Mix).mp4
[2012/07/03 11:14:02 | 020,993,111 | ---- | M] () -- C:\Users\korisnik\Documents\T-Blazer & Ana Masulovic - Touch the sky ( Official Video HD).mp4
[2012/07/03 01:38:29 | 000,002,337 | ---- | M] () -- C:\Users\korisnik\Desktop\Google Chrome.lnk
[2012/07/02 17:36:00 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1535932500-1668178-310031940-1000Core.job
[2012/07/02 16:40:10 | 018,228,744 | ---- | M] () -- C:\Users\korisnik\Documents\IN VIVO ft. Boyant - Moje leto (2012).mp4
[2012/07/02 12:01:49 | 013,791,063 | ---- | M] () -- C:\Users\korisnik\Documents\Elitni Odredi feat DJ Silver & DJ Marconi & Mia-Nisi s njom (official video).mp4
[2012/06/29 16:43:14 | 000,158,178 | ---- | M] () -- C:\Users\korisnik\Desktop\29062012211.jpg
[2012/06/29 16:42:00 | 000,145,172 | ---- | M] () -- C:\Users\korisnik\Desktop\29062012208.jpg
[2012/06/29 16:41:42 | 000,163,302 | ---- | M] () -- C:\Users\korisnik\Desktop\29062012207.jpg
[2012/06/29 00:03:50 | 001,247,641 | ---- | M] () -- C:\Users\korisnik\Desktop\jelena_kostov_live_band_krusevac_vo.mp3
[2012/06/10 14:05:51 | 021,199,751 | ---- | M] () -- C:\Users\korisnik\Documents\Afrojack, Dimitri Vegas, Like Mike and NERVO - The Way We See The World (Official Music Video) [HD].mp4
[2012/06/08 01:23:00 | 000,174,024 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2012/06/08 01:23:00 | 000,174,024 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[3 C:\Users\korisnik\Documents\*.tmp files -> C:\Users\korisnik\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/07/06 13:29:02 | 007,503,517 | ---- | C] () -- C:\Users\korisnik\Documents\T-Blazer & Ana Masulovic - Touch the sky ( Official Video HD).mp3
[2012/07/06 13:28:52 | 013,910,941 | ---- | C] () -- C:\Users\korisnik\Documents\Steff Da Campo vs. Rutger Van Gelder - Wasted (In The Morning) (Extended Mix).mp3
[2012/07/06 13:28:40 | 007,366,045 | ---- | C] () -- C:\Users\korisnik\Documents\IN VIVO ft. Boyant - Moje leto (2012).mp3
[2012/07/06 13:28:23 | 007,561,117 | ---- | C] () -- C:\Users\korisnik\Documents\Afrojack, Dimitri Vegas, Like Mike and NERVO - The Way We See The World (Official Music Video) [HD].mp3
[2012/07/03 19:00:48 | 001,103,649 | ---- | C] () -- C:\Windows\SysNative\drivers\Cat.DB
[2012/07/03 11:17:15 | 017,230,963 | ---- | C] () -- C:\Users\korisnik\Documents\Steff Da Campo vs. Rutger Van Gelder - Wasted (In The Morning) (Extended Mix).mp4
[2012/07/03 10:43:29 | 020,993,111 | ---- | C] () -- C:\Users\korisnik\Documents\T-Blazer & Ana Masulovic - Touch the sky ( Official Video HD).mp4
[2012/07/03 01:38:29 | 000,002,337 | ---- | C] () -- C:\Users\korisnik\Desktop\Google Chrome.lnk
[2012/07/02 17:31:44 | 000,000,920 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1535932500-1668178-310031940-1000UA.job
[2012/07/02 17:31:43 | 000,000,868 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1535932500-1668178-310031940-1000Core.job
[2012/07/02 16:36:48 | 018,228,744 | ---- | C] () -- C:\Users\korisnik\Documents\IN VIVO ft. Boyant - Moje leto (2012).mp4
[2012/07/02 11:58:38 | 013,791,063 | ---- | C] () -- C:\Users\korisnik\Documents\Elitni Odredi feat DJ Silver & DJ Marconi & Mia-Nisi s njom (official video).mp4
[2012/06/30 12:12:09 | 001,247,641 | ---- | C] () -- C:\Users\korisnik\Desktop\jelena_kostov_live_band_krusevac_vo.mp3
[2012/06/30 12:10:19 | 000,158,178 | ---- | C] () -- C:\Users\korisnik\Desktop\29062012211.jpg
[2012/06/30 12:10:18 | 000,145,172 | ---- | C] () -- C:\Users\korisnik\Desktop\29062012208.jpg
[2012/06/30 12:10:17 | 000,163,302 | ---- | C] () -- C:\Users\korisnik\Desktop\29062012207.jpg
[2012/06/10 13:55:28 | 021,199,751 | ---- | C] () -- C:\Users\korisnik\Documents\Afrojack, Dimitri Vegas, Like Mike and NERVO - The Way We See The World (Official Music Video) [HD].mp4
[2012/05/26 22:40:01 | 000,153,088 | ---- | C] () -- C:\Windows\SysWow64\UNRAR3.dll
[2012/05/26 22:40:01 | 000,075,264 | ---- | C] () -- C:\Windows\SysWow64\unacev2.dll
[2012/04/08 20:49:23 | 000,002,560 | ---- | C] () -- C:\Windows\_MSRSTRT.EXE
[2012/03/25 18:46:19 | 000,000,125 | ---- | C] () -- C:\Users\korisnik\wxDownloadFast.ini
[2011/12/29 11:18:12 | 000,197,728 | ---- | C] () -- C:\Windows\WinVd32.sys
[2011/12/29 11:18:11 | 000,007,680 | ---- | C] () -- C:\Windows\SysWow64\WinFLsrv.exe
[2011/12/26 17:19:12 | 000,000,193 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2011/08/23 14:39:09 | 000,246,272 | ---- | C] () -- C:\Windows\unrar.exe
[2011/08/23 14:35:40 | 000,000,000 | ---- | C] () -- C:\Windows\loader2.exe_ok
[2011/07/23 17:20:49 | 000,000,012 | ---- | C] () -- C:\Users\korisnik\intlname.ols
[2011/07/23 17:20:40 | 000,731,106 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/07/20 15:25:09 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011/07/20 15:00:39 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011/07/20 07:53:31 | 000,001,035 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011/07/20 07:27:49 | 000,168,448 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2011/07/20 07:26:59 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2011/07/20 07:20:56 | 000,000,155 | ---- | C] () -- C:\Windows\winamp.ini
[2011/04/09 19:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat

========== Alternate Data Streams ==========

@Alternate Data Stream - 153 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 152 bytes -> C:\ProgramData\TEMP:CB0AACC9

< End of report >



mycity.rs/must-login.png

offline
  • Research Engineer @MalwareBytes
  • Pridružio: 09 Avg 2011
  • Poruke: 15877
  • Gde živiš: Beograd

Pozdrav, nenadarsic123

Arrow Pokreni opet OTL, i stikliraj opciju Extra Registry: Use SafeList, i idi na Run Scan. Dobices dva izvestaja, kao i prvi put(OTL.txt, i Extras.txt), prikaci ih u poruku.

offline
  • Nenad Arsic
  • Pridružio: 02 Jul 2012
  • Poruke: 3
  • Gde živiš: Krusevac

OTL logfile created on: 7/7/2012 10:24:08 AM - Run 2
OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\korisnik\Downloads
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.75 Gb Total Physical Memory | 1.60 Gb Available Physical Memory | 58.15% Memory free
5.49 Gb Paging File | 4.06 Gb Available in Paging File | 74.02% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 48.73 Gb Total Space | 8.67 Gb Free Space | 17.79% Space Free | Partition Type: NTFS
Drive D: | 249.26 Gb Total Space | 66.71 Gb Free Space | 26.76% Space Free | Partition Type: NTFS

Computer Name: NENAD-PC | User Name: korisnik | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/07/07 10:22:35 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\korisnik\Downloads\OTL (1).exe
PRC - [2012/07/06 21:01:02 | 001,022,352 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files (x86)\uTorrent\uTorrent.exe
PRC - [2012/07/06 20:43:12 | 000,554,176 | ---- | M] () -- C:\ProgramData\IBUpdaterService\ibsvc.exe
PRC - [2011/11/15 05:50:22 | 000,312,376 | ---- | M] (Power Software Ltd) -- D:\Programi\PowerISO\PWRISOVM.EXE
PRC - [2011/03/17 10:15:46 | 000,382,272 | ---- | M] (DT Soft Ltd) -- D:\Programi\DAEMON Tools Pro\DTShellHlp.exe
PRC - [2011/03/17 10:15:04 | 000,842,048 | ---- | M] (DT Soft Ltd) -- D:\Programi\DAEMON Tools Pro\DTAgent.exe


========== Modules (No Company Name) ==========

MOD - [2012/06/28 12:28:56 | 000,438,296 | ---- | M] () -- C:\Users\korisnik\AppData\Local\Google\Chrome\Application\20.0.1132.47\ppGoogleNaClPluginChrome.dll
MOD - [2012/06/28 12:28:54 | 003,972,120 | ---- | M] () -- C:\Users\korisnik\AppData\Local\Google\Chrome\Application\20.0.1132.47\pdf.dll
MOD - [2012/06/28 12:27:40 | 000,554,520 | ---- | M] () -- C:\Users\korisnik\AppData\Local\Google\Chrome\Application\20.0.1132.47\libglesv2.dll
MOD - [2012/06/28 12:27:38 | 000,117,784 | ---- | M] () -- C:\Users\korisnik\AppData\Local\Google\Chrome\Application\20.0.1132.47\libegl.dll
MOD - [2012/06/28 12:27:29 | 000,140,328 | ---- | M] () -- C:\Users\korisnik\AppData\Local\Google\Chrome\Application\20.0.1132.47\avutil-51.dll
MOD - [2012/06/28 12:27:28 | 000,262,184 | ---- | M] () -- C:\Users\korisnik\AppData\Local\Google\Chrome\Application\20.0.1132.47\avformat-54.dll
MOD - [2012/06/28 12:27:26 | 002,386,984 | ---- | M] () -- C:\Users\korisnik\AppData\Local\Google\Chrome\Application\20.0.1132.47\avcodec-54.dll
MOD - [2012/06/28 10:27:26 | 009,252,040 | ---- | M] () -- C:\Users\korisnik\AppData\Local\Google\Chrome\Application\20.0.1132.47\gcswf32.dll
MOD - [2012/06/28 10:27:26 | 009,252,040 | ---- | M] () -- C:\Users\korisnik\AppData\Local\Google\Chrome\APPLIC~1\200113~1.47\gcswf32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2010/06/17 22:10:14 | 000,258,048 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Program Files\IDT\WDM\stacsv64.exe -- (STacSV)
SRV:64bit: - [2010/03/23 22:12:30 | 000,202,752 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2010/02/02 14:13:10 | 000,048,128 | ---- | M] (Dell Inc.) [Auto | Running] -- C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE -- (wltrysvc)
SRV:64bit: - [2009/07/14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV:64bit: - [2009/03/03 03:42:58 | 000,089,600 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Program Files\IDT\WDM\AESTSr64.exe -- (AESTFilters)
SRV - [2012/07/06 20:43:12 | 000,554,176 | ---- | M] () [Auto | Running] -- C:\ProgramData\IBUpdaterService\ibsvc.exe -- (IBUpdaterService)
SRV - [2009/06/10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/01/05 18:04:29 | 000,272,448 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2011/11/15 05:50:14 | 000,125,376 | ---- | M] (Power Software Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\scdemu.sys -- (SCDEmu)
DRV:64bit: - [2011/07/20 16:12:38 | 000,123,784 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2011/07/20 16:12:38 | 000,088,288 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2010/06/17 22:10:14 | 000,515,584 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\stwrt64.sys -- (STHDA)
DRV:64bit: - [2010/06/17 16:09:00 | 000,118,016 | ---- | M] (TCT International Mobile Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\qcusbser.sys -- (qcusbser)
DRV:64bit: - [2010/03/23 22:42:50 | 006,654,976 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2010/03/23 21:23:52 | 000,195,584 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2010/03/09 06:21:42 | 000,123,408 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:64bit: - [2010/02/02 14:13:08 | 000,022,520 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\bcm42rly.sys -- (BCM42RLY)
DRV:64bit: - [2010/02/02 14:13:08 | 000,020,984 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\bcmvwl64.sys -- (BcmVWL)
DRV:64bit: - [2010/02/02 14:13:06 | 003,058,168 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2009/07/14 03:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009/07/14 03:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009/07/14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 03:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/07/14 03:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2009/07/14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/14 02:10:47 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rootmdm.sys -- (ROOTMODEM)
DRV:64bit: - [2009/06/10 22:35:42 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009/06/10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/05/05 10:00:28 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie.sys -- (AtiPcie) AMD PCI Express (3GIO)
DRV:64bit: - [2007/05/11 04:12:06 | 000,038,160 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\blueletaudio.sys -- (BlueletAudio)
DRV:64bit: - [2007/05/09 03:00:58 | 000,044,688 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btcusb.sys -- (Btcsrusb)
DRV:64bit: - [2007/03/05 06:48:12 | 000,037,648 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BlueletSCOAudio.sys -- (BlueletSCOAudio)
DRV:64bit: - [2007/03/05 06:47:08 | 000,025,360 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BtNetDrv.sys -- (BT)
DRV:64bit: - [2007/03/05 06:42:54 | 000,049,680 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\BTHidMgr.sys -- (BTHidMgr)
DRV:64bit: - [2007/03/05 06:41:34 | 000,024,976 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\VBTEnum.sys -- (BTHidEnum)
DRV:64bit: - [2007/03/05 06:39:28 | 000,063,248 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VcommMgr.sys -- (VcommMgr)
DRV:64bit: - [2007/03/05 06:38:20 | 000,047,120 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VComm.sys -- (VComm)
DRV - [2009/07/14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2007/05/11 04:12:06 | 000,038,160 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\blueletaudio.sys -- (BlueletAudio)
DRV - [2007/05/09 03:00:58 | 000,044,688 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\btcusb.sys -- (Btcsrusb)
DRV - [2007/03/05 06:48:12 | 000,037,648 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\BlueletSCOAudio.sys -- (BlueletSCOAudio)
DRV - [2007/03/05 06:47:08 | 000,025,360 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\btnetdrv.sys -- (BT)
DRV - [2007/03/05 06:42:54 | 000,049,680 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\Windows\SysWOW64\drivers\BtHidMgr.sys -- (BTHidMgr)
DRV - [2007/03/05 06:41:34 | 000,024,976 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\Windows\SysWOW64\drivers\VBTEnum.sys -- (BTHidEnum)
DRV - [2007/03/05 06:39:28 | 000,063,248 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\VCommMgr.sys -- (VcommMgr)
DRV - [2007/03/05 06:38:20 | 000,047,120 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\VComm.sys -- (VComm)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = searchqu.com/web?src=ieb&appid=101&.....r=0&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = search.my-tools-app.com/?babsrc=home&s=web&as=0&isid=9852
IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{64D2EE47-5823-45C4-9732-B95F94E70E99}: "URL" = startsear.ch/?aff=1&src=sp&cf=ac61d.....903&q={searchTerms}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = searchqu.com/web?src=ieb&appid=101&.....r=0&q={searchTerms}
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2786678
IE - HKLM\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = search.my-tools-app.com/?babsrc=home&s=.....852&q={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = search.conduit.com?SearchSource=10&ctid=CT2786678
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 9E CA 98 E6 9C 46 CC 01 [binary data]
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - No CLSID value found
IE - HKCU\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {CAADDA30-EC3B-4A5B-82E4-79035C4B5E20}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = search.babylon.com/?q={searchTerms}&AF=109130&babsrc=SP_ss&mntrId=3cd1184600000000000068a3c4728380
IE - HKCU\..\SearchScopes\{64D2EE47-5823-45C4-9732-B95F94E70E99}: "URL" = startsear.ch/?aff=1&src=sp&cf=ac61d.....903&q={searchTerms}
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = searchqu.com/web?src=ieb&appid=101&.....r=0&q={searchTerms}
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2786678
IE - HKCU\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = search.my-tools-app.com/?babsrc=home&s=.....852&q={searchTerms}
IE - HKCU\..\SearchScopes\{CAADDA30-EC3B-4A5B-82E4-79035C4B5E20}: "URL" = search.yahoo.com/search?fr=chr-greentree_ie.....811&p={searchTerms}
IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = mystart.incredibar.com/mb119/?search={searchTerms}&loc=IB_DS&a=6R8lJTTlvm&i=26
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Web Search"
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaultthis.engineName: "uTorrentBar Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "MyTools"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&ilc=12&type=937811"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: "http://mystart.incredibar.com/mb119?a=6R8lJTTlvm&i=26"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}:6.0.25
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: ifamebook@stormvision.it:2.60
FF - prefs.js..extensions.enabledItems: wtxpcom@mybrowserbar.com:5.8
FF - prefs.js..extensions.enabledItems: youtubedownloader@mybrowserbar.com:5.8
FF - prefs.js..extensions.enabledItems: support@2yourface.com:1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}:6.0.27
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:3.6.0.10
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29
FF - prefs.js..extensions.enabledItems: {3697b17c-b572-4862-a5e6-7f922c0f3403}:1.1
FF - prefs.js..extensions.enabledItems: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}:3.8.1.0
FF - prefs.js..extensions.enabledItems: {EEE6C361-6118-11DC-9C72-001320C79847}:1.3.0.1
FF - prefs.js..extensions.enabledItems: ffxtlbr@babylon.com:1.2.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}:6.0.31
FF - prefs.js..extensions.enabledItems: ffxtlbr@incredibar.com:1.5.0
FF - prefs.js..extensions.enabledItems: info@bflix.info:5.0
FF - prefs.js..extensions.enabledItems: info@wxdownloadmanager.com:1.0
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=937811&p="
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: ""


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.4.1: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.4.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: D:\Programi\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: D:\Programi\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\korisnik\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\korisnik\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\info@bflix.info: C:\Users\korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\l51p0z1p.default\extensions\info@bflix.info [2012/03/03 23:45:44 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\info@wxdownloadmanager.com: C:\Users\korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\l51p0z1p.default\extensions\info@wxdownloadmanager.com [2012/03/25 18:42:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.28\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/03/16 10:49:33 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.28\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/07/06 21:02:15 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\support@2yourface.com: C:\Program Files (x86)\2YourFace\2YourFace.xpi

[2012/04/08 20:54:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\korisnik\AppData\Roaming\mozilla\Extensions
[2011/08/07 22:04:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\extensions
[2011/08/07 22:04:41 | 000,000,000 | ---D | M] (2YourFace) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\extensions\support@2yourface.com
[2011/12/07 21:57:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\extensions
[2012/07/02 16:40:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\extensions\extensions
[2011/08/07 22:04:41 | 000,000,000 | ---D | M] (2YourFace) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\extensions\support@2yourface.com
[2012/07/07 09:08:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\l51p0z1p.default\extensions
[2012/07/02 17:21:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\l51p0z1p.default\extensions\{3697b17c-b572-4862-a5e6-7f922c0f3403}
[2012/03/02 10:11:44 | 000,000,000 | ---D | M] (Free Lunch Design Toolbar) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\l51p0z1p.default\extensions\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}
[2011/09/25 22:48:07 | 000,000,000 | ---D | M] (Zynga Community Toolbar) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\l51p0z1p.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2011/12/08 04:00:25 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\l51p0z1p.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2011/12/08 04:00:40 | 000,000,000 | ---D | M] (SweetIM Toolbar for Firefox) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\l51p0z1p.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
[2012/03/03 23:46:20 | 000,000,000 | ---D | M] (Incredibar Toolbar) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\l51p0z1p.default\extensions\ffxtlbr@incredibar.com
[2011/07/26 19:48:04 | 000,000,000 | ---D | M] (iFamebook) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\l51p0z1p.default\extensions\ifamebook@stormvision.it
[2012/03/03 23:45:44 | 000,000,000 | ---D | M] (TheBflix) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\l51p0z1p.default\extensions\info@bflix.info
[2012/03/25 18:42:30 | 000,000,000 | ---D | M] (wxDfast) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\l51p0z1p.default\extensions\info@wxdownloadmanager.com
[2012/01/12 13:31:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\l51p0z1p.default\extensions\staged
[2011/08/07 22:04:41 | 000,000,000 | ---D | M] (2YourFace) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\l51p0z1p.default\extensions\support@2yourface.com
[2011/11/30 12:27:50 | 000,000,925 | ---- | M] () -- C:\Users\korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\l51p0z1p.default\searchplugins\conduit.xml
[2012/03/03 23:46:05 | 000,002,203 | ---- | M] () -- C:\Users\korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\l51p0z1p.default\searchplugins\MyStart Search.xml
[2012/01/12 13:31:24 | 000,000,544 | ---- | M] () -- C:\Users\korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\l51p0z1p.default\searchplugins\MyTools.xml
[2011/08/15 17:49:56 | 000,002,506 | ---- | M] () -- C:\Users\korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\l51p0z1p.default\searchplugins\SearchResults.xml
[2011/07/11 20:04:02 | 000,000,633 | ---- | M] () -- C:\Users\korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\l51p0z1p.default\searchplugins\startsear.xml
[2011/12/08 04:00:35 | 000,003,915 | ---- | M] () -- C:\Users\korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\l51p0z1p.default\searchplugins\sweetim.xml
[2012/07/06 20:56:38 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/07/20 14:56:40 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
[2011/07/26 14:21:12 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/08/31 20:49:19 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
[2011/11/04 12:09:20 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2012/04/28 00:32:14 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
[2012/01/07 16:09:31 | 000,000,000 | ---D | M] (Babylon) -- C:\Program Files (x86)\Mozilla Firefox\extensions\ffxtlbr@babylon.com
File not found (No name found) -- C:\PROGRAM FILES (X86)\COMMON FILES\SPIGOT\WTXPCOM
File not found (No name found) -- C:\PROGRAM FILES (X86)\YOUTUBE DOWNLOADER TOOLBAR\FF
[2012/01/07 16:13:56 | 000,002,310 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2011/08/15 17:49:56 | 000,002,506 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\SearchResults.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms},
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\korisnik\AppData\Local\Google\Chrome\Application\20.0.1132.47\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\korisnik\AppData\Local\Google\Chrome\Application\20.0.1132.47\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\korisnik\AppData\Local\Google\Chrome\Application\20.0.1132.47\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: vShare.tv plug-in (Enabled) = C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0\chvsharetvplg.dll
CHR - plugin: vShare.tv plug-in (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npvsharetvplg.dll
CHR - plugin: Skype Toolbars (Enabled) = C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.5.0.7896_0\npSkypeChromePlugin.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFFICE.DLL
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 7 U4 (Enabled) = C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 7.0.40.255 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Veetle TV Player (Enabled) = D:\Programi\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Enabled) = D:\Programi\Veetle\plugins\npVeetle.dll
CHR - Extension: YouTube = C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: TheBflix = C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjakmojkcnhgipgkkbiempkfdndcnlah\5.0_0\
CHR - Extension: Bflix extension = C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlfihafpijfdgmojeeigcldgchhojpfp\1.0_0\
CHR - Extension: wxDfast = C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\opnkkfjdnhgkjefnnohgfackfninikjo\1.0_0\
CHR - Extension: Gmail = C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/07/03 19:33:48 | 000,202,984 | -H-- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 facebook.com
O1 - Hosts: 127.0.0.1 facebook.com
O1 - Hosts: 127.0.0.1 af-za.facebook.com
O1 - Hosts: 127.0.0.1 az-az.facebook.com
O1 - Hosts: 127.0.0.1 id-id.facebook.com
O1 - Hosts: 127.0.0.1 ms-my.facebook.com
O1 - Hosts: 127.0.0.1 bs-ba.facebook.com
O1 - Hosts: 127.0.0.1 ca-es.facebook.com
O1 - Hosts: 127.0.0.1 cs-cz.facebook.com
O1 - Hosts: 127.0.0.1 cy-gb.facebook.com
O1 - Hosts: 127.0.0.1 da-dk.facebook.com
O1 - Hosts: 127.0.0.1 de-de.facebook.com
O1 - Hosts: 127.0.0.1 et-ee.facebook.com
O1 - Hosts: 127.0.0.1 en-gb.facebook.com
O1 - Hosts: 127.0.0.1 es-la.facebook.com
O1 - Hosts: 127.0.0.1 eo-eo.facebook.com
O1 - Hosts: 127.0.0.1 eu-es.facebook.com
O1 - Hosts: 127.0.0.1 tl-ph.facebook.com
O1 - Hosts: 127.0.0.1 fo-fo.facebook.com
O1 - Hosts: 127.0.0.1 fr-fr.facebook.com
O1 - Hosts: 127.0.0.1 fy-nl.facebook.com
O1 - Hosts: 127.0.0.1 ga-ie.facebook.com
O1 - Hosts: 127.0.0.1 gl-es.facebook.com
O1 - Hosts: 127.0.0.1 ko-kr.facebook.com
O1 - Hosts: 50053 more lines...
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {0BF33701-0742-4633-475B-0F6E47024F11} - C:\Windows\SysWOW64\ole22disp.dll ()
O2 - BHO: (bflix Class) - {0C9F4179-6CE2-4c6a-A3E5-67FF3592A12E} - C:\Program Files (x86)\BFlix\bflix.dll (bflix)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {1C8E2411-39C6-7832-007B-145D531C735B} - C:\Windows\SysWOW64\webserviices.dll ()
O2 - BHO: (TheBflix Class) - {205A2CCF-257D-4D78-9C7E-7FB38A871B00} - C:\ProgramData\TheBflix\bhoclass.dll (Injector)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {3C3D2E08-5515-6B5B-3342-3A302B0F66FE} - C:\Windows\SysWOW64\nssi.dll ()
O2 - BHO: (Groove GFS Browser Helper) - {44AA6093-09D1-2317-151C-7A5341210AE1} - C:\Windows\SysWOW64\api-ms-win-core-namedpiipe-l1-1-0.dll ()
O2 - BHO: (Adobe PDF Link Helper) - {4BD33AFE-2BC7-2777-4211-51C336FD7D53} - C:\Windows\SysWOW64\onexx.dll ()
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {54007582-298F-21BA-1957-168F2D047DB9} - C:\Windows\SysWOW64\rsaennh.dll ()
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {5C2C3007-2757-1BFD-709D-5B5A230C7E1F} - C:\Windows\SysWOW64\spbccd.dll ()
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (VShareToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files (x86)\vShare.tv plugin\BarLcher.dll File not found
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (VShareToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files (x86)\vShare.tv plugin\BarLcher.dll File not found
O4:64bit: - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE (Dell Inc.)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [ExpressFiles] C:\Program Files (x86)\ExpressFiles\ExpressFiles.exe (http://www.express-files.com/)
O4 - HKLM..\Run: [PWRISOVM.EXE] D:\Programi\PowerISO\PWRISOVM.EXE (Power Software Ltd)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TrojanScanner] D:\Programi\Trojan Remover\Trjscan.exe (Simply Super Software)
O4 - HKCU..\Run: [DAEMON Tools Pro Agent] D:\Programi\DAEMON Tools Pro\DTAgent.exe (DT Soft Ltd)
O4 - HKCU..\Run: [uTorrent] C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O8:64bit: - Extra context menu item: Search the Web - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\menuext.html File not found
O8 - Extra context menu item: Search the Web - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\menuext.html File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 10.4.1)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 10.4.1)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{058C06CA-F7E8-4BEB-93A0-087F039DA386}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{3bbb2882-018c-11e1-8128-782bcbdd6903}\Shell - "" = AutoRun
O33 - MountPoints2\{3bbb2882-018c-11e1-8128-782bcbdd6903}\Shell\AutoRun\command - "" = F:\autorun.exe
O33 - MountPoints2\{c1405420-928d-11e1-89c2-001167b7d3dd}\Shell - "" = AutoRun
O33 - MountPoints2\{c1405420-928d-11e1-89c2-001167b7d3dd}\Shell\AutoRun\command - "" = H:\PcOptions.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/07/06 21:03:46 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2012/07/06 20:44:35 | 000,000,000 | ---D | C] -- C:\Users\korisnik\AppData\Roaming\PerformerSoft
[2012/07/06 20:44:32 | 000,019,000 | ---- | C] (PerformerSoft LLC) -- C:\Windows\SysNative\roboot64.exe
[2012/07/06 20:43:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\I Want This
[2012/07/06 20:43:39 | 000,000,000 | ---D | C] -- C:\Users\korisnik\AppData\Roaming\eType
[2012/07/06 20:43:38 | 000,000,000 | ---D | C] -- C:\ProgramData\IBUpdaterService
[2012/07/03 18:52:20 | 000,000,000 | ---D | C] -- C:\Users\korisnik\Desktop\Downloads
[2012/07/02 17:43:03 | 000,000,000 | ---D | C] -- C:\Users\korisnik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2012/07/02 17:15:12 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\appmgmt
[2012/06/13 16:08:41 | 000,000,000 | ---D | C] -- C:\Users\korisnik\AppData\Roaming\Pole Position 2012
[2012/06/13 16:06:30 | 000,000,000 | ---D | C] -- C:\Users\korisnik\AppData\Roaming\Kalypso Media
[2012/06/13 16:06:28 | 000,000,000 | ---D | C] -- C:\Users\korisnik\AppData\Roaming\.mono
[2012/06/13 16:06:28 | 000,000,000 | ---D | C] -- C:\ProgramData\.mono
[2012/06/08 01:24:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2012/06/08 01:23:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Oracle
[2012/06/08 01:23:17 | 000,772,504 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\npDeployJava1.dll
[2012/06/08 01:23:17 | 000,227,720 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2012/06/08 00:12:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\1ClickDownload
[3 C:\Users\korisnik\Documents\*.tmp files -> C:\Users\korisnik\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/07/07 10:22:28 | 000,014,192 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/07 10:22:28 | 000,014,192 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/07 10:21:49 | 000,717,892 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/07/07 10:21:49 | 000,618,264 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/07/07 10:21:49 | 000,104,546 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/07/07 10:17:14 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/07/07 10:17:04 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/07/07 10:16:59 | 2211,393,536 | -HS- | M] () -- C:\hiberfil.sys
[2012/07/07 10:16:26 | 000,003,280 | ---- | M] () -- C:\bootsqm.dat
[2012/07/07 09:47:00 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/07/07 09:36:00 | 000,000,920 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1535932500-1668178-310031940-1000UA.job
[2012/07/06 21:01:02 | 000,000,963 | ---- | M] () -- C:\Users\korisnik\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2012/07/06 21:01:02 | 000,000,939 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2012/07/06 13:29:17 | 013,910,941 | ---- | M] () -- C:\Users\korisnik\Documents\Steff Da Campo vs. Rutger Van Gelder - Wasted (In The Morning) (Extended Mix).mp3
[2012/07/06 13:29:16 | 007,503,517 | ---- | M] () -- C:\Users\korisnik\Documents\T-Blazer & Ana Masulovic - Touch the sky ( Official Video HD).mp3
[2012/07/06 13:28:53 | 007,366,045 | ---- | M] () -- C:\Users\korisnik\Documents\IN VIVO ft. Boyant - Moje leto (2012).mp3
[2012/07/06 13:28:36 | 007,561,117 | ---- | M] () -- C:\Users\korisnik\Documents\Afrojack, Dimitri Vegas, Like Mike and NERVO - The Way We See The World (Official Music Video) [HD].mp3
[2012/07/05 11:12:00 | 000,000,370 | ---- | M] () -- C:\Windows\tasks\At8.job
[2012/07/05 11:12:00 | 000,000,368 | ---- | M] () -- C:\Windows\tasks\At4.job
[2012/07/05 11:12:00 | 000,000,358 | ---- | M] () -- C:\Windows\tasks\At11.job
[2012/07/05 11:12:00 | 000,000,352 | ---- | M] () -- C:\Windows\tasks\At13.job
[2012/07/05 11:12:00 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\At6.job
[2012/07/05 11:12:00 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\At2.job
[2012/07/05 11:12:00 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\At10.job
[2012/07/03 19:00:59 | 001,103,649 | ---- | M] () -- C:\Windows\SysNative\drivers\Cat.DB
[2012/07/03 11:19:04 | 017,230,963 | ---- | M] () -- C:\Users\korisnik\Documents\Steff Da Campo vs. Rutger Van Gelder - Wasted (In The Morning) (Extended Mix).mp4
[2012/07/03 11:14:02 | 020,993,111 | ---- | M] () -- C:\Users\korisnik\Documents\T-Blazer & Ana Masulovic - Touch the sky ( Official Video HD).mp4
[2012/07/03 01:38:29 | 000,002,337 | ---- | M] () -- C:\Users\korisnik\Desktop\Google Chrome.lnk
[2012/07/02 17:36:00 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1535932500-1668178-310031940-1000Core.job
[2012/07/02 16:40:10 | 018,228,744 | ---- | M] () -- C:\Users\korisnik\Documents\IN VIVO ft. Boyant - Moje leto (2012).mp4
[2012/07/02 12:01:49 | 013,791,063 | ---- | M] () -- C:\Users\korisnik\Documents\Elitni Odredi feat DJ Silver & DJ Marconi & Mia-Nisi s njom (official video).mp4
[2012/06/29 16:43:14 | 000,158,178 | ---- | M] () -- C:\Users\korisnik\Desktop\29062012211.jpg
[2012/06/29 16:42:00 | 000,145,172 | ---- | M] () -- C:\Users\korisnik\Desktop\29062012208.jpg
[2012/06/29 16:41:42 | 000,163,302 | ---- | M] () -- C:\Users\korisnik\Desktop\29062012207.jpg
[2012/06/29 00:03:50 | 001,247,641 | ---- | M] () -- C:\Users\korisnik\Desktop\jelena_kostov_live_band_krusevac_vo.mp3
[2012/06/10 14:05:51 | 021,199,751 | ---- | M] () -- C:\Users\korisnik\Documents\Afrojack, Dimitri Vegas, Like Mike and NERVO - The Way We See The World (Official Music Video) [HD].mp4
[2012/06/08 01:23:00 | 000,174,024 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2012/06/08 01:23:00 | 000,174,024 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[3 C:\Users\korisnik\Documents\*.tmp files -> C:\Users\korisnik\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/07/07 10:16:26 | 000,003,280 | ---- | C] () -- C:\bootsqm.dat
[2012/07/06 13:29:02 | 007,503,517 | ---- | C] () -- C:\Users\korisnik\Documents\T-Blazer & Ana Masulovic - Touch the sky ( Official Video HD).mp3
[2012/07/06 13:28:52 | 013,910,941 | ---- | C] () -- C:\Users\korisnik\Documents\Steff Da Campo vs. Rutger Van Gelder - Wasted (In The Morning) (Extended Mix).mp3
[2012/07/06 13:28:40 | 007,366,045 | ---- | C] () -- C:\Users\korisnik\Documents\IN VIVO ft. Boyant - Moje leto (2012).mp3
[2012/07/06 13:28:23 | 007,561,117 | ---- | C] () -- C:\Users\korisnik\Documents\Afrojack, Dimitri Vegas, Like Mike and NERVO - The Way We See The World (Official Music Video) [HD].mp3
[2012/07/03 19:00:48 | 001,103,649 | ---- | C] () -- C:\Windows\SysNative\drivers\Cat.DB
[2012/07/03 11:17:15 | 017,230,963 | ---- | C] () -- C:\Users\korisnik\Documents\Steff Da Campo vs. Rutger Van Gelder - Wasted (In The Morning) (Extended Mix).mp4
[2012/07/03 10:43:29 | 020,993,111 | ---- | C] () -- C:\Users\korisnik\Documents\T-Blazer & Ana Masulovic - Touch the sky ( Official Video HD).mp4
[2012/07/03 01:38:29 | 000,002,337 | ---- | C] () -- C:\Users\korisnik\Desktop\Google Chrome.lnk
[2012/07/02 17:31:44 | 000,000,920 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1535932500-1668178-310031940-1000UA.job
[2012/07/02 17:31:43 | 000,000,868 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1535932500-1668178-310031940-1000Core.job
[2012/07/02 16:36:48 | 018,228,744 | ---- | C] () -- C:\Users\korisnik\Documents\IN VIVO ft. Boyant - Moje leto (2012).mp4
[2012/07/02 11:58:38 | 013,791,063 | ---- | C] () -- C:\Users\korisnik\Documents\Elitni Odredi feat DJ Silver & DJ Marconi & Mia-Nisi s njom (official video).mp4
[2012/06/30 12:12:09 | 001,247,641 | ---- | C] () -- C:\Users\korisnik\Desktop\jelena_kostov_live_band_krusevac_vo.mp3
[2012/06/30 12:10:19 | 000,158,178 | ---- | C] () -- C:\Users\korisnik\Desktop\29062012211.jpg
[2012/06/30 12:10:18 | 000,145,172 | ---- | C] () -- C:\Users\korisnik\Desktop\29062012208.jpg
[2012/06/30 12:10:17 | 000,163,302 | ---- | C] () -- C:\Users\korisnik\Desktop\29062012207.jpg
[2012/06/10 13:55:28 | 021,199,751 | ---- | C] () -- C:\Users\korisnik\Documents\Afrojack, Dimitri Vegas, Like Mike and NERVO - The Way We See The World (Official Music Video) [HD].mp4
[2012/05/26 22:40:01 | 000,153,088 | ---- | C] () -- C:\Windows\SysWow64\UNRAR3.dll
[2012/05/26 22:40:01 | 000,075,264 | ---- | C] () -- C:\Windows\SysWow64\unacev2.dll
[2012/04/08 20:49:23 | 000,002,560 | ---- | C] () -- C:\Windows\_MSRSTRT.EXE
[2012/03/25 18:46:19 | 000,000,125 | ---- | C] () -- C:\Users\korisnik\wxDownloadFast.ini
[2011/12/29 11:18:12 | 000,197,728 | ---- | C] () -- C:\Windows\WinVd32.sys
[2011/12/29 11:18:11 | 000,007,680 | ---- | C] () -- C:\Windows\SysWow64\WinFLsrv.exe
[2011/12/26 17:19:12 | 000,000,193 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2011/08/23 14:39:09 | 000,246,272 | ---- | C] () -- C:\Windows\unrar.exe
[2011/08/23 14:35:40 | 000,000,000 | ---- | C] () -- C:\Windows\loader2.exe_ok
[2011/07/23 17:20:49 | 000,000,012 | ---- | C] () -- C:\Users\korisnik\intlname.ols
[2011/07/23 17:20:40 | 000,731,106 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/07/20 15:25:09 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011/07/20 15:00:39 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011/07/20 07:53:31 | 000,001,035 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011/07/20 07:27:49 | 000,168,448 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2011/07/20 07:26:59 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2011/07/20 07:20:56 | 000,000,155 | ---- | C] () -- C:\Windows\winamp.ini
[2011/04/09 19:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat

========== Alternate Data Streams ==========

@Alternate Data Stream - 153 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 152 bytes -> C:\ProgramData\TEMP:CB0AACC9

< End of report >




mycity.rs/must-login.png

mycity.rs/must-login.png

offline
  • Research Engineer @MalwareBytes
  • Pridružio: 09 Avg 2011
  • Poruke: 15877
  • Gde živiš: Beograd

Arrow Korak 1


Otidji u Control Panel - Add or Remove Programs i obriši sledeće programe ukoliko ih ima i ako ti nisu potrebni:
- TheBflix
- MyTools
- I Want This
- Conduit
- Searchqu
- Incredibar Toolbar
- SweetIM Toolbar for Firefox
- iFamebook
- 2YourFace
- Zynga Community Toolbar
- Free Lunch Design Toolbar
- uTorrentBar Community Toolbar
- Babylon


Takodje, sledeća dva programa predstavljaju sigurnosni rizik i potrebno ih je je obrisati:

- Java(TM) 6 Update 31 zastarela verzija, imaš već noviju verziju instaliranu
- Adobe Reader 8.1.2 zastarela verzija, preuzmi novu ili možeš u okviru programa kliknuti na Help -> Check for updates

VAZNO!!! Kada ovo odradis, restartuj racunar, pa predji na Korak 2.


Arrow Korak 2


Ponovo pokreni program OTL dvoklikom na ikonicu;

U beli okvir prozora gde piše Custom Scans/Fixes iskopirati sledeći tekst:

:OTL
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://www.searchqu.com/web?src=ieb&appid=101&.....r=0&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.my-tools-app.com/?babsrc=home&s=web&as=0&isid=9852
IE - HKLM\..\SearchScopes\{64D2EE47-5823-45C4-9732-B95F94E70E99}: "URL" = http://startsear.ch/?aff=1&src=sp&cf=ac61d.....903&q={searchTerms}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://www.searchqu.com/web?src=ieb&appid=101&.....r=0&q={searchTerms}
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2786678
IE - HKLM\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://search.my-tools-app.com/?babsrc=home&s=.....852&q={searchTerms}
IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2786678
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - No CLSID value found
IE - HKCU\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&AF=109130&babsrc=SP_ss&mntrId=3cd1184600000000000068a3c4728380
IE - HKCU\..\SearchScopes\{64D2EE47-5823-45C4-9732-B95F94E70E99}: "URL" = http://startsear.ch/?aff=1&src=sp&cf=ac61d.....903&q={searchTerms}
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://www.searchqu.com/web?src=ieb&appid=101&.....r=0&q={searchTerms}
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2786678
IE - HKCU\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://search.my-tools-app.com/?babsrc=home&s=.....852&q={searchTerms}
IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incredibar.com/mb119/?search={searchTerms}&loc=IB_DS&a=6R8lJTTlvm&i=26
FF - prefs.js..browser.search.defaultthis.engineName: "uTorrentBar Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "MyTools"
FF - prefs.js..browser.startup.homepage: "http://mystart.incredibar.com/mb119?a=6R8lJTTlvm&i=26"
FF - prefs.js..extensions.enabledItems: ifamebook@stormvision.it:2.60
FF - prefs.js..extensions.enabledItems: wtxpcom@mybrowserbar.com:5.8
FF - prefs.js..extensions.enabledItems: youtubedownloader@mybrowserbar.com:5.8
FF - prefs.js..extensions.enabledItems: support@2yourface.com:1
FF - prefs.js..extensions.enabledItems: ffxtlbr@babylon.com:1.2.0
FF - prefs.js..extensions.enabledItems: ffxtlbr@incredibar.com:1.5.0
FF - prefs.js..extensions.enabledItems: info@bflix.info:5.0
FF - prefs.js..extensions.enabledItems: info@wxdownloadmanager.com:1.0
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: "
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\info@bflix.info: C:\Users\korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\l51p0z1p.default\extensions\info@bflix.info [2012/03/03 23:45:44 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\support@2yourface.com: C:\Program Files (x86)\2YourFace\2YourFace.xpi
[2011/08/07 22:04:41 | 000,000,000 | ---D | M] (2YourFace) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\extensions\support@2yourface.com
[2011/08/07 22:04:41 | 000,000,000 | ---D | M] (2YourFace) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\extensions\support@2yourface.com
[2012/03/02 10:11:44 | 000,000,000 | ---D | M] (Free Lunch Design Toolbar) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\l51p0z1p.default\extensions\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}
[2012/03/02 10:11:44 | 000,000,000 | ---D | M] (Free Lunch Design Toolbar) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\l51p0z1p.default\extensions\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}
[2011/09/25 22:48:07 | 000,000,000 | ---D | M] (Zynga Community Toolbar) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\l51p0z1p.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2011/12/08 04:00:25 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\l51p0z1p.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2011/12/08 04:00:40 | 000,000,000 | ---D | M] (SweetIM Toolbar for Firefox) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\l51p0z1p.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
[2012/03/03 23:46:20 | 000,000,000 | ---D | M] (Incredibar Toolbar) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\l51p0z1p.default\extensions\ffxtlbr@incredibar.com
[2011/07/26 19:48:04 | 000,000,000 | ---D | M] (iFamebook) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\l51p0z1p.default\extensions\ifamebook@stormvision.it
[2012/03/03 23:45:44 | 000,000,000 | ---D | M] (TheBflix) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\l51p0z1p.default\extensions\info@bflix.inf
[2011/08/07 22:04:41 | 000,000,000 | ---D | M] (2YourFace) -- C:\Users\korisnik\AppData\Roaming\mozilla\Firefox\Profiles\l51p0z1p.default\extensions\support@2yourface.com
[2011/11/30 12:27:50 | 000,000,925 | ---- | M] () -- C:\Users\korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\l51p0z1p.default\searchplugins\conduit.xml
[2012/03/03 23:46:05 | 000,002,203 | ---- | M] () -- C:\Users\korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\l51p0z1p.default\searchplugins\MyStart Search.xml
[2012/01/12 13:31:24 | 000,000,544 | ---- | M] () -- C:\Users\korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\l51p0z1p.default\searchplugins\MyTools.xml
[2011/08/15 17:49:56 | 000,002,506 | ---- | M] () -- C:\Users\korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\l51p0z1p.default\searchplugins\SearchResults.xml
[2011/07/11 20:04:02 | 000,000,633 | ---- | M] () -- C:\Users\korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\l51p0z1p.default\searchplugins\startsear.xml
[2011/12/08 04:00:35 | 000,003,915 | ---- | M] () -- C:\Users\korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\l51p0z1p.default\searchplugins\sweetim.xml
[2012/01/07 16:09:31 | 000,000,000 | ---D | M] (Babylon) -- C:\Program Files (x86)\Mozilla Firefox\extensions\ffxtlbr@babylon.com
File not found (No name found) -- C:\PROGRAM FILES (X86)\COMMON FILES\SPIGOT\WTXPCOM
[2012/01/07 16:09:31 | 000,000,000 | ---D | M] (Babylon) -- C:\Program Files (x86)\Mozilla Firefox\extensions\ffxtlbr@babylon.com
File not found (No name found) -- C:\PROGRAM FILES (X86)\COMMON FILES\SPIGOT\WTXPCOM
File not found (No name found) -- C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\EXTENSIONS\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
File not found (No name found) -- C:\PROGRAM FILES (X86)\YOUTUBE DOWNLOADER TOOLBAR\FF
[2012/01/07 16:13:56 | 000,002,310 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2011/08/15 17:49:56 | 000,002,506 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\SearchResults.xml
CHR - Extension: TheBflix = C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjakmojkcnhgipgkkbiempkfdndcnlah\5.0_0\
CHR - Extension: Bflix extension = C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlfihafpijfdgmojeeigcldgchhojpfp\1.0_0\
O2 - BHO: (bflix Class) - {0C9F4179-6CE2-4c6a-A3E5-67FF3592A12E} - C:\Program Files (x86)\BFlix\bflix.dll (bflix)
O2 - BHO: (TheBflix Class) - {205A2CCF-257D-4D78-9C7E-7FB38A871B00} - C:\ProgramData\TheBflix\bhoclass.dll (Injector)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (VShareToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files (x86)\vShare.tv plugin\BarLcher.dll File not found
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found
O8:64bit: - Extra context menu item: Search the Web - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\menuext.html File not found
O8 - Extra context menu item: Search the Web - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\menuext.html File not found

:commands
[emptytemp]
[resethosts]
[reboot]



Klikni taster Run Fix;


Log koji dobiješ iskopiraj ovde u poruci.




Arrow Korak 3


Preuzmi program OTL sa donjeg linka na Desktop:

download link



Dvoklikom pokreni OTL;
klikni Run Scan;
po zavrsetku skeniranja, izvestaj (koji ce biti automatski sacuvan na Desktop-u kao OTL.Txt) ce se otvoriti u Notepad-u.


Prilozi izvestaj OTL.txt uz poruku koriscenjem opcije Prikaci fajl.


Arrow Korak 4


Kakvo je stanje sada, imas li nekih problema?

offline
  • Nenad Arsic
  • Pridružio: 02 Jul 2012
  • Poruke: 3
  • Gde živiš: Krusevac

Problem je resen.Sada sve normalno funkcionise.
Hvala puno Smile

offline
  • Research Engineer @MalwareBytes
  • Pridružio: 09 Avg 2011
  • Poruke: 15877
  • Gde živiš: Beograd

Nisi do kraja ispratio uputstvo, potrebno je da ispratis drugi i treci korak, kako bismo proverili jel sve OK Smile

Ko je trenutno na forumu
 

Ukupno su 868 korisnika na forumu :: 36 registrovanih, 4 sakrivenih i 828 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: amaterSRB, Apok, Atenjanin89, Atomski čoban, babaroga, Belac91, Ben Roj, black venom, Bubimir, dejoglina, galerija, ILGromovnik, ivica976, Još malo pa deda, Kaplar2, laurusri, Leonov, mackenzie, Marko Marković, marsi, nenad81, NewOrder, pceklic, prle122, Sass Drake, Skakac7, slonic_tonic, Smiljke, solic, Srle993, stegonosa, vandrej, vathra, Vlad000, Vlada78, VladaNS1978